2026-08-20 · 3 min read · SONIL EHS360
Why closed-loop matters
Open findings without verification create a false sense of control. A closed loop means every material finding becomes an owned action, evidence is attached, and someone other than the action owner confirms effectiveness before close.
In SONIL EHS360 the intended loop is:
Report → Investigate → CAPA → Verify → Close
Sources of CAPA
CAPA should enter from the same system of record as the finding:
- Incident and near-miss investigations
- Inspection and audit findings
- Risk assessments that require additional controls
- Permit or LMRA failures that expose a systemic gap
Avoid creating “orphan CAPA” rows that no investigation or inspection can explain.
Roles in the loop
| Step | Who | Product expectation | |---|---|---| | Report | Field / supervisor | Fast capture with site context | | Investigate | HSE / investigator | Facts, causes, accountable owners | | CAPA | Action owner | Corrective and preventive actions with due dates | | Verify | Independent verifier | Effectiveness check — not a rubber stamp by the owner | | Close | Governance role | Auditable trail retained in the tenant |
If your programme allows the same person to own and verify every action, you have weakened the control on purpose — document that exception carefully.
Writing actions that survive audit
Good CAPA statements are:
- Specific — what control changes, where, and by when
- Owned — a named person, not “Site team”
- Evidence-backed — photo, document, or inspection reference when the control is in place
- Preventive when needed — stop recurrence, not only repair the immediate defect
Weak CAPA statements (“Be more careful”, “Awareness training”) should be challenged in review.
Cadence that prevents spreadsheet drift
- Daily (site): new high-severity items and overdue actions visible to supervisors.
- Weekly (HSE): aging CAPA, verification backlog, recurring causes.
- Monthly (leadership): systemic themes across sites — not a dump of every open row.
Do not export to Excel as the master. Exports are for meetings; the tenant remains the system of record.
Verification of effectiveness
Verification asks: did the control work under real conditions?
Examples:
- Re-inspection of the same finding type after the due date
- Permit discipline spot-check after a PTW-related CAPA
- Near-miss trend in the same area after a corrective action
Closing on “work order completed” alone is incomplete when the risk remains.
Common failure modes
| Failure | Symptom | Fix | |---|---|---| | Dual systems | Excel and EHS360 disagree | Kill the spreadsheet master | | Owner inflation | Everyone is “Site HSE” | Named individuals + deputies | | Soft closes | Status jumps to Closed without verify | Enforce verify-by-other where configured | | Scope creep | Every observation becomes CAPA | Severity / risk triage | | Orphan actions | CAPA with no source record | Link back to incident/inspection |
How this maps to product surfaces
- Field: update status when the control is actually in place.
- Workspace: investigation, assignment, due dates, verification.
- Leadership analytics: overdue CAPA and open-loop aging — see Analytics for HSE leadership.
Contractor-related actions may reference the contractor company register. Do not assume a full contractor OS unless that depth is entitled and implemented for your tenant.