Understanding the Living, Driving, Proving Model for Operationalising ISO 45001 in the Real World
The Living, Driving, Proving (LDP) Framework is a diagnostic model for judging whether a safety management system is working in the real world. Process cycles such as PDCA describe how a system should be designed and improved. LDP asks a narrower and more awkward question: where is that system actually visible? It moves the test from what the documents say to what the operation does, which is where the difference between a compliant system and a working one becomes apparent.
The LDP Framework assesses whether a safety management system functions under real operational conditions. It shifts the question from "is there a system in place?" to "is the system working, and where would we see that?"
LDP evaluates performance across three interrelated spheres:
The three are not stages and do not run in sequence. A system can be strongly driven and barely lived, or thoroughly proven on paper while the frontline works around it. Reading all three together is what makes the framework diagnostic rather than descriptive.
A system is only meaningful if it is lived. The Living dimension examines how people engage with the system in real time, on the floor, in the field and during routine work. It looks past documentation to how procedures, controls and expectations translate into behaviour. In ISO 45001 it aligns with Clause 5.4, Consultation and Participation and Clause 8, Operational Planning and Control.
A system is lived when it shapes everyday thinking and action. Indicators include:
A system that is not actively driven will drift. The Driving dimension examines how leadership converts safety commitments into direction, resourcing and oversight, and whether safety is embedded in strategic decision-making rather than delegated as a function. It aligns with Clause 5.1, Leadership and Commitment and Clause 6, Planning.
A system is driven when leadership decisions give safety both traction and visibility. Signs include:
A system that cannot be proven cannot be improved. The Proving dimension examines whether performance is monitored, reviewed and acted on in a way that produces change. It concerns the quality of evidence rather than its volume, and aligns with Clause 9, Performance Evaluation and Clause 10, Improvement.
A system is proven when results can be tracked, analysed and acted upon. Evidence includes:
Proving the system means having the visibility to know what is working, what is changing and what still needs attention. It closes the loop and keeps the system honest.

Each dimension draws on a different part of the standard, which is what allows LDP to point at a specific clause when a system is failing in a specific way.
| Dimension | Principal clauses | Where the evidence sits |
|---|---|---|
| Living | 5.4, 7.2, 7.3, 8.1 | Observed work, briefings, worker accounts, permits in use |
| Driving | 5.1, 5.2, 5.3, 6.1, 6.2 | Objectives, resourcing decisions, management review inputs |
| Proving | 9.1, 9.2, 9.3, 10.2 | Audit findings, indicator trends, corrective action records |
The LDP Framework does not replace the PDCA cycle, it makes it visible. PDCA gives a structure for planning, executing, evaluating and improving. LDP tests whether those phases are happening anywhere other than in the documentation.
Each dimension interacts with PDCA phases rather than mapping onto one:
Used together the two form an adaptive loop. PDCA provides the structure; LDP establishes whether the structure is load-bearing.
A diagnostic framework has to be honest about its own failure modes, because each one turns LDP from a test into a reassurance exercise. The remedy follows each in italics.
The LDP Framework was developed in response to a persistent problem: systems that look sound on paper fail in practice, and the paper gives no warning. Informed by field-level audits, leadership gaps and inconsistent outcomes, it offers a way to assess whether a system is functioning where it matters, on site, in planning, and in performance.
LDP is the diagnostic framework used throughout Mission 45001, the SafetyRatios clause-by-clause examination of ISO 45001:2018, where each clause is read for where it is lived, driven and proven rather than for whether it is documented. It is most useful where:
By focusing on what is lived, driven and proven, LDP closes the gap between system design and system reality. It turns system principles into something observable, so safety is demonstrated rather than merely documented.
LDP is used to assess whether a safety management system is functioning in practice rather than merely existing. It asks three questions: is the system lived by the people doing the work, driven by leadership decisions, and proven by evidence. It is a reality check on a system that already exists, not a method for building one.
PDCA is a process cycle for planning, implementing, checking and improving a system. LDP is a diagnostic model that tests whether those phases are actually happening. PDCA builds the system logic; LDP looks for evidence that the logic reached the workplace.
A system is lived when it shapes how people actually work, not only what is written down. It shows in how risks are handled without prompting, how controls are referenced in routine conversation, and whether field-level feedback changes anything. It is the operational visibility of the system, mostly at the frontline.
A system is driven when leadership priorities are visibly shaping safety outcomes: safety is resourced, embedded in planning, and present in executive decisions rather than delegated downward. The test is whether safety appears in decisions that were not about safety.
Evidence that the system produced a result, as distinct from evidence that it exists. Audit findings, leading and lagging indicators, management review decisions and corrective actions traced to root cause all qualify. A document register does not.
At Proving, and in a specific way: evidence gets collected that the system operated rather than evidence that it worked. Completed audits, delivered training and closed actions all demonstrate activity. LDP is only diagnostic when the evidence answers whether anything changed as a result.