Category: Blog

  • Risk Assessment Standards: How to Choose and Use Them

    Risk Assessment Standards: How to Choose and Use Them

    Risk Assessment Standards: How to Choose and Use Them. The standard is the thing that we’re going to use to achieve things – the tool. And that’s important because tools designed to do certain things usually perform well. But they don’t always perform well on other things. So we will ask, ‘Are we doing the right thing?’ And ‘Are we doing it right?’

    This post is part of a series:

    Video Highlights

    Understanding Your Standard: Highlights

    Transcript

    What and Why?

    So, what will we do and why are we doing it? First, the use of safety standards is very common for many reasons. It helps us to have confidence that what we’re doing is good enough. We’ve met a standard of performance in the absolute sense. It helps us to say, ‘We’ve achieved standardization or commonality in what we’re doing’.

    We can also use it to help us achieve a compromise. That can be a compromise across different stakeholders or different organizations. Standardization gives us some of the other benefits as well. If we’re all doing the same thing rather than we’re all doing different things, it makes it easier to train staff. This is one example of how a standard helps.

    However, we need to understand this tool that we’re going to use. What it does, what it’s designed to do, and what it is not designed to do. That’s important for any standard or any tool. In safety, it’s particularly important because safety is, in many respects, an intangible. This is because we’re always looking to prevent a future problem from occurring. In the present, it’s a little bit abstract. It’s a bit intangible. So, we need to make sure that conceptually what we’re doing makes sense and it’s coherent. That it works together. If we look at those five bullet points there, we need to understand the concept of each standard. We need to understand the basis of each one.

    They’re not all based on the same concept. Thus, some of them are contradictory or incompatible. We need to understand the design of the standard. What the standard does, what the aim of the standard is, and why it came into existence. And who brought it into existence. To do what for whom – who’s the ultimate customer here?

    For risk analysis standards, we need to understand what kind of risks they address. Because the way you treat a financial risk might be very different from a safety risk. In the world of finance, you might have a portfolio of products, like loans. These products might have some risks associated with them. One or two loans might go bad, and you might lose money on those. But as long as the whole portfolio is making money, that might be acceptable to you. You might say, ‘I’m not worried about that 10% of my loans have gone south and all gone wrong. I’m still making plenty of profit out of the other 90%.’ It doesn’t work that way with safety. You can’t say ‘It’s OK that I’ve killed a few people over here because all this a lot over here are still alive!’. It doesn’t work like that!

    Also, what kind of evidence does the standard produce? Because in safety, we are very often working in a legal framework that requires us to do certain things. It requires us to achieve a certain level of safety and prove that we have done so. So, we need certain kinds of evidence. In different jurisdictions and different industries, some evidence is acceptable. Some are not. You need to know which is for your area. And then finally, let’s think about the pros and cons of the standard. What does it do well? And what does it do not so well?

    System Safety Pedigree

    We’re going to look at a standard called Military Standard 882E. This standard was first developed several decades ago. It was created by the US government and military to help them bring into service complex, cutting-edge military equipment. Equipment that was always on the cutting edge. That pushes the limits of what you can achieve in performance.

    That’s a lot of complexity. Lots of critical weapon systems, and so forth. So they needed something that could cope with all that complexity. It’s a system safety engineering standard. It’s used by engineers, but also by many other specialists. As I said, it’s got a background in military systems. These days, you find these principles used pretty much everywhere. So, all the approaches to System Safety that 882 introduced are in other standards. They are also in other countries.

    It addresses risks to people, equipment, and the environment, as we heard earlier. And because it’s an American standard, it’s about system safety. It’s very much about identifying requirements. What do we need to happen to get safety? To do that, it produces lots of requirements. It performs analyses of all those requirements and generates further requirements. And it produces requirements for test evidence. We then need to fulfill these requirements. It’s got several important advantages and disadvantages. We’re going to discuss these in the next few slides…

    This is Module 3 of SSRAP

    ‘Understanding Your Risk Assessment Standard’ is Module 3 of the System Safety Risk Assessment Program (SSRAP) Course. Risk Analysis Programs – Design a System Safety Program for any system in any application.

    The full course comprises 15 lessons and 1.5 hours of video content, plus resources. It’s on pre-sale at HALF PRICE until September 1st, 2024. Check out all the free preview videos here and order using the coupon “Pre-order-Half-Price-SSRAP”. But don’t leave it too long because there are only 100 half-price courses available!

    Meet the Author

    Learn safety engineering with me, an industry professional with 25 years of experience. I have:

    •Worked on aircraft, ships, submarines, ATMS, trains, and software;

    •Tiny programs to some of the biggest (Eurofighter, Future Submarine);

    •In the UK and Australia, on US and European programs;

    •Taught safety to hundreds of people in the classroom, and thousands online;

    •Presented on safety topics at several international conferences.

  • Risk Management: Principles, Process and Techniques

    Risk Management: Principles, Process and Techniques

    Welcome to Risk Management: Principles, Process and Techniques, where we’re going to go through these basic concepts of risk management. We’re going to break it down into the constituent parts and then we’re going to build it up again and show you how it’s done. I’ve been involved in risk management, in project risk management, safety risk management, etc., for a long, long time.  I hope that I can put my experience to good use, helping you in whatever you want to do with this information.

    Maybe you’re getting an interview. Maybe you want to learn some basics and decide whether you want to know more about risk management or not.  Whatever it might be, I think you’ll find this short session really useful. I hope you enjoy it and thanks for watching.

    Welcome to Risk Management 101, where we’re going to…

    You can get the RM101 Course as part of the FREE Triple Learning Bundle.

    Risk Management 101, Topics

    • Hazard Identification;
    • Hazard Analysis;
    • Risk Estimation;
    • Risk [and ALARP] Evaluation;
    • Risk Reduction; and
    • Risk Acceptance.

    Risk Management 101, Transcript

    Introduction

    Hi everyone and welcome to Risk Management 101. We’re going to go through these basic concepts of risk management. We’re going to break it down into the constituent parts. Then we’re going to build it up again and show you how it’s done.

    My name is Simon Di Nucci and I have a lot of experience working in risk management, project risk management, safety risk management, etc.  I’m hoping that I can put my experience to good use, helping you in whatever you want to do with this information. Whether you’re going for an interview or you want to learn some basics. You can watch this video and decide if you want to know more about risk management or if you don’t need to.  Whatever it might be, you’ll find this short session useful. I hope you enjoy it and thanks for watching.

    Topics For This Session

    Risk Management 101. So what does it all mean? We’re going to break risk management down into we’ve got six constituent parts. I’m using a particular standard that breaks it down this way. Other standards will do this in different ways. We’ll talk about that later. Here we’ve got risk management broken down into; hazard identification, hazard analysis, risk estimation, risk evaluation (and ALARP), risk reduction, and risk acceptance.

    Risk Management

    Let’s get right on to that. Risk management – what is it? It’s defined as “the systematic application of management policies, procedures, and practices to the tasks of hazard identification, hazard analysis, risk estimation, risk and ALARP evaluation, risk reduction, and risk acceptance”.

    There are a couple of things to note here. We’re talking about management policies, procedures, and practices. The ‘how’ we do it. Whether it’s a high-level policy or low-level common practice. E.g. how things are done in our organization vs how the day-to-day tasks are done? And it’s also worth saying that when we talk about ‘hazards’, that’s a safety ‘ism’. If we were doing security risk management, we could be talking about ‘threats’. We can also be talking about ‘causes’ in day-to-day language. So, we can be talking about something causing a risk or leading to a risk. More on that later, but that’s an overview of what risk management is.

    Part 1

    Let’s look at it in a different way. For those of you who like a visual representation, here is a graph of the hierarchical breakdown. They need to happen in order, more or less, left to right. And as you can see, there’s a link between risk evaluation and risk reduction. We’ll come on to that. So, it’s not ‘or’ it’s a serial ‘this is what you have to do’. Sometimes they’re linked together more intimately.

    Hazard Identification

    First of all, hazard identification. So, this is the process where we identify and list hazards and accidents associated with the system. You may notice that some words here are in bold. Where a word is in bold, we are going to give the definition of what it is later.

    These hazards could lead to an accident but are only associated with the system. That’s the scope. If we were talking about a system that was an airplane, a ship, or a computer, we would have a very different scope. There would also be a different way that maybe accidents would happen.

    On a more practical level, how do we do hazard identification? I’m not going to go into any depth here, but there are certain classic ones. We can consult with our workers and inspect the workplace where they’re operating. In some countries, that’s a legal requirement (Including in Australia where I live). Another option is looking at historical data. And indeed, in some countries and in some industries, that’s a requirement. A requirement means we have to do that. And we can use special analysis techniques. Now, I’m not going to talk about any of those analysis techniques today. You can watch some other sessions on The Safety Artisan to see that.

    Hazard Analysis

    Having done hazard identification, we’ve asked ourselves ‘What could go wrong?’. We can put some more detail on and ask, ‘How could it go wrong? And how often?’. That kind of stuff. So, we want to go into more detail about the hazards and accidents associated with this particular system. And that will help us to define some accident sequences. We can start with something that creates a hazard and then the hazard may lead to an accident. And that’s what we’re talking about. Later, we will show that using graphics can be helpful.

    But again, more on terminology. In different industries, we call it different things. We tend to say ‘accident’ in the UK and Australia. In the U.S., they might call it a ‘mishap’, which is trying to get away from the idea that something was accidental. Nobody meant it to happen. Mishap is a more generic term that avoids that implication. We also talk about ‘losses’ or we talk about ‘breaches’ in the security world. We have some issues where somebody has been able to get in somewhere that they should not. And we can talk about accident sequences. Or, in a more common language, we call it a sequence of events. That’s all it is.

    Risk Estimation

    Now we’re talking about the risk estimation. We’ve thought about our hazards and accidents and how they might progress from one to another. Let’s think about, ‘How big is the risk of this actually happening?’. Again, we’ll unpack this further later at the next level. But for now, we’re going to talk about the systematic use of available information. Systematic- so, ordered. We’re following a process. This isn’t somebody on their own taking a subjective view ‘Look, I think it’s not that’. It’s a process that is repeatable. We want to do something systematic. It’s thorough, it’s repeatable, and so it’s defendable. We can justify the conclusions that we’ve come to because we’ve done it with some rigour. We’ve done it in a systematic way. That’s important. Particularly if we’re talking about harm coming to people or big losses.

    Risk and ALARP / SFARP Evaluation

    Now, risk evaluation is just taking that estimated risk just now and comparing it to something and saying, “How serious is this risk?”. Is it something that is very low? If it’s very insignificant then we’re not bothered about it. We can live with it. We can accept it. Or is it bigger than that? Do we need to do something more about it? Again, we want to be systematic. We want to determine whether risk reduction is necessary. Is this acceptable as it is or is it too high and we need to reduce it? That’s the core of risk evaluation.

    Tolerability

    In this UK-based standard – we’re using terminology is found in different forms around the world. But in the UK, they talk about ‘tolerability’. We’re talking about the absolute level of risk. There probably is an upper limit that’s allowed in the law or in our industry. And there’s a lower limit that we’re aiming for. In an ideal world, we’d like all our risks to be low-level risks. That would be terrific.

    So, that’s ‘tolerability’. And you might hear it called different things. And then within the UK system, there are three classes of ‘tolerability’ at risk. We could say it’s either ‘broadly acceptable’- it’s very low. It’s down in the target region where we like to get all our risks. It’s ‘tolerable’- we can expose people to this risk or we can live with this risk, but only if we’ve met certain other criteria. And then there’s the risk that it’s so big. It’s so far up there, that we can’t do that. We can’t have that under any circumstances. It’s unacceptable. You can imagine a traffic light system where we have categorized our risk.

    ALARP / SFARP

    And then there’s the test of whether our risk can be accepted in the UK. It’s called ALARP. We reduce the risk As Low As Reasonably Practicable. And in other places, you’ll see SFARP. We’ve eliminated or minimized the risk So Far As Is Reasonably Practicable. In the nuclear industry, they talk about ALARA: As Low As Reasonably Achievable. And then different laws use different tests. Whichever one you use, there’s a test that we have to say, “Can we accept the risk?” “Have we done enough risk reduction?”. And whatever you’ve put in those square brackets, that’s the test that you’re using. And that will vary from jurisdiction to jurisdiction. The basic concept of risk evaluation is estimating the level of risk. Then compare it to some standard or some regulation. Whatever it might be, that’s what we do. That’s risk evaluation.

    Risk Reduction

    We’ve asked, “Do we need to reduce risk further?”. And if we do, we need to do some risk reduction. Again, we’re being systematic. This is not some subjective thing where we go “I have done some stuff, it’ll be alright. That’s enough.”. We’re being a bit more rigorous than that. We’ve got a systematic process for reducing risk. And in many parts of the world, we’re directed to do things in a certain way.

    Elimination

    This is an illustration from an Australian regulation. In this regulation, we’re aiming to eliminate risk. We want to start with the most effective risk reduction measures. Elimination is “We’ve reduced the risk to zero”. That would be lovely if we could do that but we can’t always do that.

    Substitution

    What’s the next level? We could get rid of this risk by substituting something less risky. Imagine we’ve got a combustion engine powering something. The combustion engine needs flammable fuel and it produces toxic fumes. It could release carbon monoxide and CO2 and other things that we don’t want. We ask, “Can we get rid of that?”. Could we have an electric motor and have a battery instead? That might be a lot safer than the combustion engine. That is a substitution. There are still risks with electricity. But by doing this we’ve substituted something risky for something less risky.

    Isolation

    Or we could isolate the hazard. Let’s use the combustion engine as an example again. We can say, “I’ll put that in the fuel and the exhaust somewhere, a long way from people”. Then it’ll be a long way from where it can do harm or cause a loss.” And that’s another way of dealing with it.

    Engineering Controls

    Or we could say, “I’m going to reduce the risks through engineering controls”. We could put in something engineered. For example, we can put in a smoke detector. A very simple, therefore highly reliable, device. It’s certainly more reliable than a human. You can install one that can detect some noxious gases. It’s also good if it’s a carbon monoxide detector. Humans cannot detect carbon monoxide at all. (Except if you’ve got carbon monoxide poisoning, you’ll know about it. Carbon monoxide poisoning gives you terrible headaches and other symptoms.) But of course, that’s not a good way to detect that you’re breathing in poisonous gas. We do not want to do it that way.

    So, we can have an engineering control to protect people. Or we can use an interlock. We can isolate things in a building or behind a wall or whatever. And if somebody opens the door, then that forces the thing to cut out so it’s no longer dangerous. There are different things for engineering controls that we can introduce. They do not rely on people. They work regardless of what any person does.

    Administrative / Procedural Controls

    Next on the list, we could reduce exposure to the hazard by using administrative controls. That’s giving somebody some rules to follow a procedure. “Do this. Don’t do that.” Now, that’s all good. We can give people warning signs and warn people not to approach something. But, of course, sometimes people break the rules for good reasons. Maybe they don’t understand. Or, maybe they don’t know the danger. Perhaps they’ve got to do something or maybe the procedure that we’ve given them doesn’t work very well. It’s too difficult to get the job done, so people cut corners. So, procedural protection can be weak. And a bit hit-and-miss sometimes.

    Personal Protective Equipment

    Finally, we can give people personal protective equipment. We can give them some eye protection. I’m wearing glasses because I’m short-sighted. But you can get some goggles to protect your eyes from damage. Damage like splashes, flying fragments, sparks, etc. We can have a hard hat so that if we’re on a building site and something drops from above on us that protects the old brain box.

    It won’t stop the accident from happening, but it will help reduce the severity of the accident. That’s the least effective. We’re doing nothing to prevent the accident from happening. We’re reducing the severity in certain circumstances. For example, if you drop a ton of bricks on me, it doesn’t matter whether I’m wearing a hard hat or not. I’m still going to get crushed. But with one brick, I should be able to survive that if I’m wearing a hard hat.

    Risk Acceptance

    Let’s move on to risk acceptance. At some stage, if we have reduced the risk to a point where we can accept it. That is, we can live with it and we’ve decided that we’re going to need to do whatever it is that is exposing us to the risk. We need to use the system. For example, we want to get in our car to enable us to go from A to B quickly and independently. So, we’re going to accept the risk of driving in our car. We’ve decided we’re going to do that. We make risk-acceptance decisions every day, often without thinking about it. We get in a car every day on average and we don’t worry about the risk, but it’s always there. We’ve just decided to accept it.

    But in this example, it’s not an individual deciding to do something on the spur of the moment. Nor is it based on personal experience. We’ve got a systematic process where a bunch of people come together. The relevant stakeholders agree that a risk has been assessed or has been estimated and has been evaluated. They agree that the risk reduction is good enough and that we will accept that risk. There’s a bit more to it than you and I saying “That’ll be alright.”

    Part 2

    Let’s summarise where we’ve got to. We’ve talked about these six components of risk management. That’s terrific. And as you can see, they all go together. Risk evaluation and risk reduction are more tightly coupled. That’s because when we do some risk reduction, we then re-evaluate the risk. We ask ‘Can we accept it?’. If the answer is ‘No.’ we need to do some more work. Then we do some more risk reduction. So those tend to be a bit more coupled together at the end. That’s the level we’ve got to. We’re now going to go to the next level.

    So, we’re going to explain these things. We’ve talked about hazard identification and hazard analysis, but what is a hazard? And what is an accident? And what is an accident sequence? We’re going to unpack that a bit more. We’re going to take it to the next level. And throughout this, we’re talking about risk over and over again. Well, what is ‘risk’? We’re going to unpack that to the next level as well.

    This is a safety standard. We’re talking about harm to people. How likely is that harm and how severe might it be? But it might be something else. It might be a loss or a security breach. Or a financial loss, a negative result for our project. We might find ourselves running late. Or we’re running over budget. We might be failing to meet quality requirements. Or we’re failing to deliver the full functionality that we said we would. Whatever it might be.

    Hazard

    So, let’s unpack this at the next level. A hazard is a term that we use, particularly in safety. As I say, we call it other things in different realms. But in the safety world, it’s a physical situation or it’s a state of a system.

    As it says, it often follows from some initiating event that we may call a ‘cause’. The hazard may lead to an accident. However, the key thing to remember is once a hazard exists, an accident is possible, but it’s not certain. You can imagine the sort of cartoon banana skin on the pavement gag. Well, the banana skin is the hazard. In the cartoon, the cartoon character always steps on the banana skin. They always fall over the comic effect. But in the real world, nobody may tread on the banana skin and slip over. There could be nobody there to slip over all the banana skin. Or even if somebody does, they could catch themselves. Or they fall, but it’s on a soft surface and they don’t hurt themselves so there’s no harm.

    So, the accident isn’t certain. And in fact, we can have what we call ‘non-accident’ outcomes. We can have harmless consequences. A hazard is an important midway step. I heard it called an accident waiting to happen, which is a helpful definition. An accident waiting to happen, but it doesn’t mean that the accident is inevitable.

    Accident

    But accidents can happen. Again, the ‘accident’, ‘mishap’, or ‘unintended event’. Something we did not want or a sequence of events that caused harm. And in this case, we’re talking about harm to people. And as I say, it might be a security breach. It might be a financial loss or reputational damage. Something might happen that is very embarrassing for an organization or an individual. Or again, we could have a hiccup with our project.

    Harm

    But in this case, we’re talking about harm. With this kind of standard, we’re using what you might call a body count approach to the harm. We’re talking about actual death, physical injury, or damage to the health of people.

    This standard also considers the damage to property and the environment. Now, very often we are legally required to protect people and the environment from harm. Property less so. However, there will be financial implications of losses of property or damage to the systems. We don’t want that. But it’s not always criminally illegal to do that. Whereas usually, hurting people and damaging the environment is. So, this is ‘harm’. We do not want this thing to happen. We do not want this impact.

    Safety is a much tougher business in this instance. If we have a problem with our project, it’s embarrassing but we could recover it. It’s more difficult to do that when we hurt somebody.

    Risk

    And always in these terms, we’re talking about ‘risk’. What is ‘risk’? Risk is a combination of two things. It’s a combination of the likelihood of harm or loss and the severity of that harm or loss. It’s those two things together. And we’ve got a very simple illustration here, a little table. And they’re often known as a risk matrix but don’t worry about that too much. Whatever you want to call it. We’ve got a little two by two table here and we’ve got likelihood in the white text and severity in the black.

    Low Risk

    We can imagine where there’s a risk where we have a low likelihood of a ‘low harm’ or a ‘low impact’ accident or outcome. We say, ‘That’s unlikely to happen, and even if it does not much is going to happen.’ It’s going to be a very small impact. So, we’d say that that’s a low risk.

    Then at the other end of the spectrum, we can imagine something that has a high likelihood of happening. And that likelihood also has a high impact. Things that happen that we definitely do not want to happen. And we say, ‘That’s a high risk and that’s something that we are very, very concerned about.’

    Medium Risk

    And then in the middle, we could have a combination of an outcome that is quite likely, but it’s of low severity. Or it’s of high severity, but it’s unlikely to happen. And we say, ‘That’s a medium risk’.

    Now, this is a very simplified matrix for teaching purposes only. In the real world, you will see matrices that are four by four, five by five, or even six by six, or combinations thereof. And in security where they talk about threat and vulnerability and the outcomes. Here, you might see multiple matrices used. They use multiple matrices to progressively build up a picture of the risk. They use matrices as building blocks. So, it may not be only one matrix used in a more complex thing you’ve got to model. But here we’ve got a nice, simple example. This illustrates what risk is. It’s a combination of severity and likelihood of harm or loss. And that’s what risk is, fundamentally. And if we have a firm grasp of these fundamentals, it’ll help us to reason and deal with almost anything. With enough application.

    Accident Sequence

    Now, let’s move on and talk about accident sequences. We’re talking about a progression in this case. We’re imagining a left-to-right path. A progression of events that results in an accident. This diagram, which looks like a bow tie, is meant to represent the idea that we can have one hazard. There might be many causes that lead to this hazard. There might be many different things that could create the hazard or initiate the hazard. And the hazard may have many different consequences.

    Consequences

    As I’ve said before, nothing at all may happen. That might be the consequence of the hazard. Most of the time that’s what’s going to happen. But there may be a variety of consequences. Somebody might get a minor injury or there might be a more serious accident where one or more people are killed. A good example of this is fire. So, the hazard is the fire. The causes might be various. We could be dealing with flammable chemicals, or a lightning strike, or an electricity arc flash. Or we could be dealing with very high temperatures where things spontaneously burst into flames. Or we could have a chemical in the presence of pure oxygen. Some things will spontaneously burst into flames in the presence of pure oxygen. So there’re a variety of causes that lead to the fire.

    An Example

    And the fire might be very small and burn itself out. It causes very little damage and nobody gets hurt. Or it might lead to a much bigger fire that, in theory, could kill lots of people. So, there’s a huge range of consequences potentially from one hazard. But the accident sequence is how we would describe and capture this progression. From initiating events to the hazard to the possible consequences. And by modeling the accident sequence, of course, we can think about how we could interrupt it.

    Part 3

    We’ve broken risk management down into those six constituent parts. We’ve gone to the next level, in that we’ve sort of gone down to the concepts that underpin these things. These hazards, the accidents, and the accident sequence. We’ve talked about risk itself and what we don’t want to happen. The harm, the loss, the financial loss, the embarrassment, the failed or late or budget project, a security breach, the undesired event, etc. We had an objective which was to do something safely or to complete a project and the risk is that that won’t happen. That there’ll be an impact on what we were trying to do that is negative. That is undesirable.

    There are just only more concepts that we need to look at to complete the pattern, as you can see. We’ve been talking about the system. And we’ve been talking about doing things systematically. Then a system works in an operating environment. So, let’s unpack that.

    System

    First of all, we have a system. The system is going to be a combination of things. I wouldn’t call a pen or a pencil a system. It’s only got a couple of components. You could pull it apart. But it’s too simple to be worth calling it a system. We wouldn’t call it a pen system, would we? So, a system is something more complex. It’s a combination of things and we need to define the boundary. I’ll come back to that.

    But within this boundary, we’ve got some different elements in the system that work together. Or they’re used together within a defined operating environment. So, we’re going to expose this system to a range of conditions in which it is designed to work. The intention is the system is going to do whatever it does to perform a given task. It can do one defined task or achieve a specific purpose.

    I talked before about getting in our car. A car is complex enough to be called a system. We get in our car and we drive it on the roads. Or if we’ve got a four-wheel drive, we can drive Off-Road. Or we can use it in a more demanding operating environment to achieve a specific purpose. We want to transport ourselves, and sometimes some stuff, from A to B. That’s what we’re trying to do with the system.

    Within the System

    And within that system, we may have personnel/people, we may have procedures. A bunch of rules about how you drive a car legally in different countries. We’ve got materials and physical things – what the car is made of. We could have tools to repair it, and change wheels. We’ve got some other equipment, like a satnav. We’ve got facilities. We need to take a car somewhere to fill up with fuel or to recharge it. We’ve got services like garages, repairs, servicing, etc. And there could be some software in there as well. Of course, these days in the car, there’s software everywhere in most complex devices.

    So, our system is a combination of lots of different things. These things are working together to achieve some kind of goal or some kind of result. There’s somewhere we want to get to. And it’s designed to work in a particular operating environment. Cars work on roads really well. Off-road cars can work on tracks. Put them in deep water, they tend not to work so well. So, let’s talk about that operating environment.

    Operating Environment

    What we’ve got here, is the total set of all external, natural, and induced conditions. (That’s external to the system, so outside the boundary.) So, it might be these conditions-. It might be natural or it might be generated by something else, which a system is exposed to at any given moment. We need to get a good understanding of the system, the operating environment, and what we want it to do.

    If we have a good understanding of those three things, then we will be well on the way to being able to understand the risks associated with that system. That’s one of the key things with risk management. If you’ve got those three things, that’s crucial. You will not be able to do effective risk management if you don’t have a grasp of those things. And if you do have a thorough grasp of those things, it’s going to help you do effective risk management.

    Conclusion

    So, we’ve talked about risk management. We’ve broken it down into some big sections. Those six sections; the hazard identification; analysis; risk estimation; evaluation; reduction; and acceptance. We’ve seen how those things depend on only a few concepts. We’ve got the concepts of ‘hazards’, ‘risks’, and ‘accidents’. As well as the undesirable consequences that the risk might result in. The risk is measured based on the likelihood and severity of that harm or loss occurring.

    When we’re dealing with a more complex system, we need to understand that system and the environment in which it operates. Of course, we’ve put it in that environment for a purpose. And that unpacking has allowed us to break down quite a big concept, risk management. A lot of people, like myself, spend years and years learning how to do this. It takes time to gain experience because it’s a complex thing. But if we break it down, we can understand what we’re doing. We can work our way down the fundamentals. And then if we’ve got a good grasp of the fundamentals, that supports getting the more complex stuff right. So, that’s what risk management is all about. That’s your risk management 101 and I hope that you find that helpful.

    Copyright Statement

    I just need to say briefly that those quotations from the standard. I can do that under a Creative Commons license. The CC4.0. That allows me to do that within limits that I am careful to observe. But this video presentation is copyrighted by the Safety Artisan.

    For More…

    And you can see more like these at the Safety Artisan website. That’s www.safetyartisan.com. And as you can see, it’s a secure site so you can visit without fear of a security breach. So, do head over there. Subscribe to the monthly newsletter to get discounts on paid videos and regular updates of what’s coming up. both paid and free.

    So, it just remains for me to say thanks very much for watching and I look forward to catching up with you again very soon.

    End of Risk Management 101

    You can get the RM101 Course as part of the FREE Triple Learning Bundle. For more introductory sessions on this site start here.

    Meet the Author

    Learn safety engineering with me, an industry professional with 25 years of experience, I have:

    •Worked on aircraft, ships, submarines, ATMS, trains, and software;

    •Tiny programs to some of the biggest (Eurofighter, Future Submarine);

    •In the UK and Australia, on US and European programs;

    •Taught safety to hundreds of people in the classroom, and thousands online;

    •Presented on safety topics at several international conferences.

  • Artificial Intelligence: How Do We Use It Ethically?

    Artificial Intelligence: How Do We Use It Ethically?

    Let’s talk about Artificial Intelligence: How Do We Use It Ethically? There’s been a lot of interest in this topic recently, as well as quite a lot of emotion and misinformation.

    I wanted to set out how the Safety Artisan uses Artificial Intelligence, or AI, ethically. But to do that, we have to understand what the ethics are and the ethical questions around AI.

    Many of the arguments about AI centre around two questions:

    • First: are we infringing copyright, the intellectual property of other people, by using AI?  
    • Second: by using AI, are we putting people out of work?

    Copyright Law & AI Training

    So, let’s look at the first issue. Before we can make any judgment about what AI does we need to understand Copyright law and how AI is trained.

    First, we should note that not all published material is subject to copyright. Many US government publications are copyright-free on principle, because they were paid for by the American people and may be freely used by them. There is also lots of online material published under Creative Commons (CC) 3.0 or 4.0. CC 3.0 may be copied, changed and republished for non-commercial use, but CC 4.0 may be used in this way for commercial gain. Both usually require attribution to or acknowledgement of the original.

    Copyright law (or is it just convention?) says that we can quote copyright, provided that we attribute the information to our source. (Let’s skip the issue that when we quote somebody, we might be quoting a quote; the true originator might be somebody else entirely, but we might not know that.)

    If, however, we copied someone else’s work word for word without attribution, then that may be a civil offense. We have passed off somebody else’s work as ours, and we have infringed their copyright, their Intellectual Property (IP).

    Interestingly, it is not an offense to look at somebody else’s work and to write a précis or summary, or reword it – to use those ideas but to put them in our own words. That has always been legal. Indeed, this is the basis of reportage and criticism. Every time we write a book, an article, or a blog post, we are probably taking information from many sources and putting it together in a unique way, using our own unique words. That’s normal and ethical practice.

    What is curious is that different standards seem to be applied to AI. Perhaps it is because those who criticize it don’t understand how it works.

    How Does Artificial Intelligence Really Work?

    AIs, particularly Large Language Models (LLMs), are trained on vast data sets which are freely available online. The AI engine does not read and store or copy these sources, but learns from them. It is remarkably like the way humans learn, and sometimes deliberately so. AI adjusts itself depending on the information that it receives. Just as a brain is a complex neural net, AI is a complex set of algorithms; indeed, it may use an artificial neural net, deliberately aping the human brain.

    So, we can put aside the notion that AI is copying other people’s work. When an LLM is trained on billions of web pages, it would simply not be feasible to store all that information for the AI to refer to when we ask a question. Instead, the AI interprets the questions that we ask it and then it responds using the algorithms which have been trained on the real data.

    It looks like a reproduction because it is so lifelike, so incredibly realistic. We think it must be working from stored, i.e., copied, knowledge. But it isn’t.

    AI’s uncanny ability to process data does not come from real intelligence. Rather, it is Machine Learning, and it is a dumb machine. What it is really doing is using brute-force power to make up for its lack of intelligence. A single microprocessor can carry out hundreds of thousands of operations in a second. An AI model may be run on hundreds or even thousands of such microprocessors in a server farm.

    Using AI at The Safety Artisan

    So, let’s look at some practical examples. How do we use AI at The Safety Artisan?

    First, we use LLMs to help us generate some blog posts.

    A typical process is that I make a video where I’m talking live to camera, often without a script. I’ve got the knowledge of the subject to be able to do that, with structure from presentation slides that I’ve prepared. However, prose that works in spoken form – when you can see my face, hear my voice and interpret my words – doesn’t work so well when it’s text on a page.

    I use an AI to take my recorded video and extract my words into a raw transcript. I still use a tool called Pictory AI (https://pictory.ai) in order to edit my videos, which it does by manipulating the AI-generated transcript.

    I then used to pay my daughter, who is an English literature graduate, to edit this transcript. All through the COVID epidemic, she edited my work and then sent it back to me. I paid her to do this, and it supplemented her furlough payments while she was laid off.

    What I can do now is take that AI-extracted transcript and feed it to ChatGPT, an LLM (GPT stands for ‘General Purpose Transformer’). I ask it to improve the transcript and turn it into prose of whatever style I want (formal, conversational, whatever). It does an incredible job in seconds.

    Lately, I’ve been asking ChatGPT to turn my work into simplified English in accordance with an international standard, ASD-STE100 (Simplified Technical English). I know of this standard because it is used internationally in engineering and maintenance publications when parsing unambiguous user instructions for tasks, which may be safety-related. Of course, we want such instructions to be clear and easy to read!

    Another variation is to take an existing publication and to use ChatGPT to translate it. For example, I might take an excerpt from a safety standard or process guide, which may be written in dense and difficult language. I then ask ChatGPT to convert it into something more accessible and readable for a blog post article.

    This is legal and ethical on several levels:

    • First, the original source may be copyright-free, or it may be usable under CC 3.0 or 4.0. There is a huge amount of material online which is available in this way.
    • Second, the LLM is not copying the material; it is making a reworded precis or summary of the material, which is not an infringement of copyright.
    • Third, I give attribution to show where the information originally came from.

    The last point is not always strictly necessary, but I like to do it anyway. It shows that I am drawing on an authoritative source, which is important given that I’m teaching people how to do safety in accordance with legal requirements or standards.

    Another example is the use of Imagery

    When I started The Safety Artisan in 2018, I paid a graphic designer (https://www.linkedin.com/in/samjusaitis/) I knew to come up with a logo and colour scheme for the brand. I was very pleased with the result, and his advice on website design – thanks, Sam!

    Having done that, I might change that logo by feeding it again into ChatGPT and asking it to update the logo. Here’s the original and an example of ChatGPT content. I asked the LLM to come up with a ‘Millennial Minimalist’ version using Sam’s colour palette. (Why ‘Millennial Minimalist’? I asked Google what was popular with younger demographics, my target audience. How do I know what my target audience is? Because I did my homework.)

    Similarly, a former employer paid Iain Bond Photography to take headshots of me and my colleagues. The images belong to the photographer, but the firm bought the right to use the photos. Ownership is quite a complex issue in Australia – see this guidance from The National Library of Australia. (N.B. I haven’t researched the law in other jurisdictions – it may be different where you are.)

    I fed this original image into ChatGPT, which it manipulated. With mixed results, as you can see.

    The original photograph is on the left, and the obviously stylised version in the middle. So far, so good. The version on the right makes me look like someone else (my wife says Ewan McGregor, my daughter says Andy Burnham or Ronnie Corbett!) and I find it faintly unsettling. This is illuminating, isn’t it? Something that is obviously derivative and artificial looks fine. Conversely, something realistic, but not quite right, looks false and wrong. I guess it’s down to authenticity.   

    Another example is images I use in web pages and posts. I used to use pictures that I took myself, which were never very successful, as I’m not a very good photographer. Or I used to go to sites like Pexels.com and get free images there. I would then acknowledge the photographer who took the original pictures in the picture’s caption.

    Now I can use ChatGPT and just feed it the text that I’m going to use. The LLM will generate a suitable image for me to use with the material. Sure, I’m not paying any artist, but as a small business I couldn’t afford to pay a graphic designer or photographer for such images anyway. I would have done it myself in the free version of Canva, or some other online tool.

    Here are some examples of ChatGPT’s work.

    All I had to do was give it the address of a recent blog post, “Supporting a Vision Worth Sharing”, and it did the rest. First, I asked for a Millennial Minimalist version, then an art deco version, and, finally, one done in the style of a vintage British railway poster. Each one took only seconds to generate, and they are all quite lovely. (Incidentally, the LLM made up a new Safety Artisan logo, which I later asked it to replace.)

    Summary

    If we are going to use AI ethically, then I dare to suggest the following principles:

    • We need to understand copyright, Intellectual Property, Creative Commons Licences, and the conditions that the original creator imposes.
    • We need to understand how AI (Machine Learning) works and what it does and does not do.
    • Authenticity and openness about use of AI are key.
    • Successful use of AI requires skilful direction, which comes from knowing the subject and doing your research.
    • We still need to check the results from LLMs and other AIs.

    What do you think?

    Declaration: I dictated this article into my phone using Gmail voice recognition and edited it in Microsoft Word. I fed this article to ChatGPT asking it to suggest SEO hashtags for it. It did, but it also pointed out that I had incorrectly written “ASD-100STE”, whereas it is “ASD-STE100 (Simplified Technical English)”.

  • Safety Case Lifecycle: How to Develop a Safety Case

    Safety Case Lifecycle: How to Develop a Safety Case

    Safety Case Lifecycle: How to Develop a Safety Case is Part 4 of a four-part series on safety cases. In it, we look at timing issues and typical content through the safety case lifecycle.

    A Comprehensive Guide to Ensuring Project Safety

    When embarking on any significant project, ensuring safety isn’t just a step in the process—it’s the foundation of success. A Safety Case is the bedrock of this commitment, systematically building the evidence needed to demonstrate that a system is safe for use throughout its lifecycle. Here’s a vibrant, step-by-step guide to understanding and implementing Safety Cases effectively.

    Starting the Safety Journey: Initiation

    The moment that Safety Management activity kicks off, the Safety Case begins to take shape. Think of it as an evolving tapestry where each thread represents a layer of safety assurance.

    Milestone Checkpoints: Producing Safety Case Reports

    Safety Case Reports should be produced at pivotal milestones to maintain accountability and ensure progress. These reports not only showcase progress but also serve as vital checkpoints to align all stakeholders. Common milestones include:

    1. Approval of the Outline Business Case
    2. Approval of the Full Business Case
    3. Authorization to begin demonstration trials
    4. Completion of major design phases
    5. Commitment to production
    6. Testing, acceptance, and user trials
    7. System introduction to service
    8. Design or material state updates (e.g., midlife refresh)
    9. Operational changes
    10. Disposal of the system

    These reports should align with the Project Safety Management Plan, serving as contractual deliverables between the contractor and the project team.

    Keeping it Alive: Periodic Reviews

    Safety isn’t static. The Safety Case is a living document requiring ongoing updates, reviews, and configuration control. Regular reviews ensure it adapts to new challenges, emerging risks, and evolving system requirements.

    Gathering Insights: Required Inputs

    To build a robust Safety Case, a wealth of inputs is essential. These include data and outputs from key procedures such as hazard identification, risk estimation, risk reduction, and safety requirements. The journey is a collaborative effort where insights from all corners of the project feed into the evolving safety narrative.

    The Safety Case and Safety Case Report require inputs from:

    1. Outputs from Procedure SMP01 – Safety Initiation;
    2. Outputs from Procedure SMP02 – Safety Committee;
    3. Outputs from Procedure SMP03 – Safety Planning;
    4. Outputs from Procedure SMP04 – Preliminary Hazard Identification and Analysis;
    5. Outputs from Procedure SMP05 – Hazard Identification and Analysis;
    6. Outputs from Procedure SMP06 – Risk Estimation;
    7. Outputs from Procedure SMP07 – Risk and ALARP Evaluation;
    1. Outputs from Procedure SMP08 – Risk Reduction;
    2. Outputs from Procedure SMP09 – Risk Acceptance;
    3. Outputs from Procedure SMP10 – Safety Requirements and Contracts;
    4. Outputs from Procedure SMP11 – Hazard Log.

    Delivering Confidence: Required Outputs

    At its core, the Safety Case outputs are more than just documents—they are the backbone of confidence for all stakeholders. The primary outputs include:

    • Controlled documentation supporting the safety of the system
    • Detailed Safety Case Reports tailored to each project phase
    • Evidence-backed arguments showcasing tolerable risk levels

    Breaking It Down: Typical Safety Case Report Content

    An effective Safety Case Report doesn’t just inform; it assures. Here’s what it typically includes:

    • Executive Summary: Assurance of safety progress and stakeholder alignment
    • System Description: Boundaries, scope, and interface clarity
    • Assumptions: Factors underpinning safety requirements
    • Progress Assessment: Updates on safety activities and milestones
    • Risk Management: Documentation of hazards, risks, and mitigation strategies
    • Emergency and Contingency Plans: Preparedness for unforeseen circumstances
    • Operational Guidance: Practical safety insights for operators

    The Lifecycle Perspective: Safety Cases at Every Stage

    Concept Stage

    Here, safety begins with identifying risks early, crafting strategies, and ensuring feasibility. By the Outline Business Case, the safety vision should be clear, even if some areas remain undefined.

    Assessment Phase

    Building on the Concept Stage, this phase involves a deeper analysis of risks and strategies for mitigation, culminating in a Safety Case Report for the Full Business Case.

    Demonstration & Trials

    Safety during trials ensures a controlled environment for testing and evaluation. Detailed Safety Management Plans guide this phase, ensuring all involved parties understand their responsibilities.

    Introduction to Service

    At this stage, safety extends to operational readiness—ensuring support facilities, training, and logistic arrangements are in place.

    Disposal

    Disposal planning begins early, considering risks throughout the system’s life. Safety Cases for disposal ensure proper handling, whether through recycling, scrapping, or resale, minimizing liability and environmental impact.

    Conclusion

    The Safety Case is more than a procedural requirement—it’s a commitment to integrity, collaboration, and responsibility. By weaving together comprehensive safety practices at every stage, projects can achieve a level of confidence that benefits all stakeholders.

    Are you ready to take your Safety Case to the next level? Share your thoughts and experiences in the comments below!

    Meet the Author

    Learn safety engineering with me, an industry professional with 25 years of experience, I have:

    •Worked on aircraft, ships, submarines, ATMS, trains, and software;

    •Tiny programs to some of the biggest (Eurofighter, Future Submarine);

    •In the UK and Australia, on US and European programs;

    •Taught safety to hundreds of people in the classroom, and thousands online;

    •Presented on safety topics at several international conferences.

  • CISSP 2021: What’s New and How to Prepare

    CISSP 2021: What’s New and How to Prepare

    CISSP 2021: What’s New and How to Prepare? Let’s look at the significant changes made to the CISSP Official Exam Outline (the course syllabus).

    What You Can Learn

    • What’s new in the CISSP Curriculum, from May 1st, 2021 (next update in 2024)
    • There are still Eight Domains – D1, D3 & D7 are still broader in content than others.
    • Very small changes (+/-1%) to the weighting of two domains.
    • Notable changes to all domains, except D1.
    • As of late 2019, some of the changes were Already in Official Course (AOC), i.e. the Student (course) Guide; Study Guide; and Official Practice Tests.
    • D2: Resource types and data activities listed (AOC);
    • D3: Fourteen designs/solutions listed (50% AOC); and thirteen cryptanalytic attacks listed (some AOC);
    • D4: Lists several new network architectures;
    • D5: Additions to all existing sub-domains & new 5.6 on authentications systems;
    • D6: More detail on security test output and reporting;
    • D7: Minor changes to 6/15 sub-domains; and
    • D8: More detail added to all sub-domains.
    This is the Introduction & Foreword to the full three-hour course.

    Who is this Course for?

    Students wishing to become Certified Information Systems Security Professionals.

    Are there any Prerequisites?

    I designed this course to help students prepare for the current (2021-2024) version of the CISSP Exam. It does not replace the official ISC2 course materials, but it will help you get the most out of them.

    CISSP 2021: What’s New?

    I’ve just passed the new version of the CISSP Exam, and I created this Course to help you pass as well!

    This course describes the changes to the Certified Information Systems Security Professional Exam Outline. Now, CISSP has been around for quite some time and the previous version of the course syllabus was established in April 2018.  In 2021, ISC2 updated the Exam Outline significantly.  In this course, I’m going to go through all of that material for you and show you what has changed, in detail, to help you with your revision.

    Here, I give you an overview of what’s changed and how this material has been developed for you.

    In the course, we’re going to cover all eight domains from ‘Security and Risk Management’ all the way through to ‘Software Development Security.  The CISSP is a very broad course and it covers all sorts of things like physical security and fire prevention right through to some more detailed technical stuff on the workings of the Internet, software development, and security testing as well.

    There have been significant changes to all of those domains except one. (There’s a small change to number one, as we will see, but it’s not huge.) However, Domains 2 to 8 have all gone undergone significant changes.  (Some of those changes were already in the official course material, in the study guide and some were already in the official practice tests; we will cover that too.)

    Course Creation

    Also, I wanted to let you know what I’ve done to create this course.

    I went on the official five-day course, which cost about $2,500 (US), where we went through hundreds of slides per day.  You get a course guide with it, which is 800-pages long.  There is a lot of good material in there, an awful lot to learn.  In addition, I’ve also been through the official study guide, which is 1,000 pages and contains quite a lot of material that wasn’t in the official course. 

    Then there is the CISSP glossary, which is about 50 pages and that’s got over 400 definitions in.  (The glossary is not so much use. It seems to be quite out of date to me. There are a lot of definitions that you don’t need and quite a few that you do need that are missing.) 

    The bibliography lists 50+ references for you to read.  You shouldn’t have to read 50+ books and standards!

    Just the first two are 1,800 pages long.  So it’s an enormous hill to climb without some guidance to help you where to look.  I’ve included page numbers for the Official Study Guide – where it covers the material we’re going to talk about.  However, even the Study Guide doesn’t cover everything – as you will see.  So, I’ve been online and looked up the information to get you started.

    Links to CISSP 2021: What’s New?

    (Learn about my CISSP 2021 Exam Journey here. That course is also FREE.)

  • Supporting a Vision Worth Sharing

    Supporting a Vision Worth Sharing

    At The Safety Artisan, we recently received a Certificate of Appreciation from The Fred Hollows Foundation in recognition of our support. We are genuinely honoured to receive this acknowledgement. More importantly, we are proud to support an organisation whose work has transformed millions of lives around the world.

    Our Business is Improving Safety

    Our business is improving safety. Every day, we help organisations identify hazards, manage risk, and design systems that protect people. Although our work is focused on engineering, defence, transportation, and other safety-critical industries, our aim is always the same: use knowledge and expertise to improve people’s lives.

    The Fred Hollows Foundation embodies that same principle in a different but equally important field.

    The Fred Hollows Foundation

    Founded on the vision of Professor Fred Hollows, the Foundation works to eliminate avoidable blindness and vision impairment by providing high-quality eye care where it is needed most. Its work extends far beyond performing sight-restoring operations. The Foundation trains local doctors, nurses, and health workers, strengthens healthcare systems, improves access to affordable treatments, and works with communities to create sustainable eye-care services that continue long after individual projects have finished.

    The impact is extraordinary. Restoring someone’s sight does much more than improve their health. It enables children to return to school, adults to work and support their families, older people to regain their independence, and entire communities to benefit from increased opportunity and wellbeing. Few medical interventions have such an immediate and life-changing effect.

    One aspect of the Foundation’s work that particularly resonates with us is its emphasis on creating sustainable capability. Rather than simply providing short-term assistance, the Foundation invests in local people, local healthcare systems, and long-term solutions. This philosophy mirrors many of the principles we value in systems engineering and system safety. We create solutions that continue to deliver benefits well into the future.

    Supporting a Vision Worth Sharing

    Businesses of every size have an opportunity to contribute to causes that extend beyond their immediate commercial activities. Supporting organisations such as The Fred Hollows Foundation is one way that companies can help improve lives while contributing to stronger, healthier communities worldwide.

    We are therefore delighted to receive this Certificate of Appreciation. Our contribution is small, but we are pleased to play a role in supporting Fred’s remarkable mission.

    We would like to thank everyone at The Fred Hollows Foundation for their dedication, compassion, and tireless work. Their commitment has restored sight to millions of people and continues to create opportunities for countless others.

    We look forward to continuing our support. We humbly encourage others to learn more about the Foundation’s work and the difference it is making around the world.

    If you would like to know more about our work, please click here to receive regular email updates. You can find our suite of Courses here, now with Digital Certificates. Our free blog articles on System Safety are here.

    Drop a Question or Comment below:

  • ISSS Credentialing Initiative: System Safety Professionals

    ISSS Credentialing Initiative: System Safety Professionals

    The ISSS Credentialing Initiative: System Safety Professionals. Where is the Next Generation of System Safety Professionals? We need a Workforce Development Program for Safety-Critical Industries.

    The International System Safety Society (ISSS) is launching a major credentialing initiative designed to strengthen and expand system safety capability across Canada and the United States.

    Developed as a three-year industry partnership and sponsorship program, the initiative will create a structured pathway for professionals working with complex and safety-critical systems. The program combines modular learning, stackable micro-credentials, and verifiable digital certifications to help organizations build a stronger and more resilient safety workforce.

    The initiative is being led by an ISSS sub-committee including Jenn Downing, ISSS Director of Education and Professional Development, and Carol-Ann Haggarty.

    Why This Initiative Matters

    Organizations operating in safety-critical environments face increasing challenges in recruiting, developing, and retaining personnel with the skills required to manage system safety throughout the lifecycle of complex systems.

    Whether in defence, aerospace, transportation, energy, healthcare technology, telecommunications, or critical infrastructure, employers require practitioners who understand:

    • Hazard identification and analysis
    • Risk assessment and acceptance
    • Safety assurance and evidence generation
    • Lifecycle safety management
    • Safety-informed decision making

    The ISSS Credentialing Initiative addresses these challenges by creating a common, industry-recognized framework for developing and validating system safety competencies.

    A Three-Year Development and Trial Program

    The initiative will be delivered through a structured three-year model.

    Year 1 – Build

    The first year focuses on developing:

    • The credentialing framework
    • Course architecture and learning pathways
    • Pilot training materials
    • Instructor guidance
    • Digital credentialing mechanisms
    • Evaluation and assessment strategies

    Year 2 – Pilot

    Pilot courses will be delivered with industry, academic, and professional partners. Feedback will be collected to evaluate:

    • Learning effectiveness
    • Practical relevance
    • User experience
    • Workforce applicability

    Year 3 – Refine and Scale

    Following the pilot phase, the program will be refined and prepared for wider deployment across Canada and the United States. The goal is to establish a sustainable and scalable credentialing model that meets long-term workforce needs.

    Creating a Workforce Pipeline

    The credentialing pathway is designed to support professional development from entry into the workforce through to advanced practice.

    The model provides a clear progression:

    Students and Early-Career Professionals → ISSS Micro-Credentials → Verified Skills → Industry Deployment → Career Progression

    This approach helps organizations identify talent, validate competencies, and accelerate workforce readiness.

    Cross-Industry Applicability

    A key strength of the program is its portability across industries.

    The credentialing model is intended to be standards-aware while remaining industry-neutral, making it applicable to sectors including:

    • Defence and aerospace
    • Space systems
    • Nuclear and energy
    • Rail and public transit
    • Automotive and autonomous systems
    • Medical technology
    • Mining and industrial operations
    • Critical infrastructure
    • Software-intensive systems
    • Manufacturing and robotics
    • Telecommunications
    • Public-sector acquisition

    By focusing on disciplined safety thinking, evidence-based assurance, and risk management principles, the framework can support organizations operating under a wide range of regulatory and operational environments.

    Benefits for Industry Partners

    Industry participation is central to the success of the initiative.

    Partner organizations can help ensure that the credentialing framework remains practical, current, and aligned with real workforce requirements. Benefits include:

    Improved Workforce Readiness

    Employees gain foundational and applied knowledge in system safety principles, reducing training gaps and improving operational effectiveness.

    A Common Professional Language

    The program promotes alignment across safety, systems engineering, software engineering, quality assurance, human factors, compliance, and program management functions.

    Reduced Onboarding Costs

    Organizations gain access to personnel with a recognised baseline of knowledge and capability, reducing the need to repeatedly teach foundational concepts internally.

    Scalable Capability Development

    The modular structure allows organizations to support workforce development at scale while maintaining consistency across teams and locations.

    Inclusive Workforce Development

    The ISSS Credentialing Initiative is built upon Universal Design for Learning (UDL) principles.

    The program seeks to expand access to system safety careers for:

    • Students
    • Early-career professionals
    • Engineers transitioning between industries
    • Practitioners returning to the workforce

    Learning will be delivered through flexible formats, including self-paced modules, micro-learning approaches, and multiple assessment methods.

    This inclusive design helps broaden participation, improve learner confidence, and strengthen the long-term safety engineering talent pipeline across North America.

    Opportunities for Sponsorship and Partnership

    ISSS is currently seeking organizations willing to support the development and trial period through one or more of the following roles:

    Sponsors

    Provide financial support for:

    • Curriculum development
    • Pilot delivery
    • Evaluation activities
    • Accessible learning design
    • Launch preparation

    Partners

    Support the initiative by:

    • Nominating pilot participants
    • Reviewing course relevance
    • Providing structured feedback
    • Validating workforce outcomes

    Champions

    Help expand awareness by connecting ISSS with:

    • Industry networks
    • Professional societies
    • Academic institutions
    • Government stakeholders
    • Potential implementation partners

    Sponsors may also receive benefits including brand recognition, pilot course access, participation in feedback activities, and discounted access during the formal rollout phase.

    The Next Step

    The ISSS Credentialing Initiative represents an opportunity to build a sustainable and scalable system safety workforce development framework for North America.

    Organizations interested in shaping the future of system safety education and professional development are invited to:

    • Become a partner
    • Sponsor the initiative
    • Nominate pilot participants
    • Contribute subject matter expertise
    • Support long-term rollout and adoption

    By working together, industry, academia, government, and professional societies can help create a stronger pipeline of qualified professionals capable of supporting the increasingly complex and safety-critical systems upon which modern society depends.

    ISSS 2026 Summit & Training (Click on Link in Image)

    Hi, I’m Simon Di Nucci. I am a practicing system safety engineer and have been for the last 30 years. I’ve worked in all kinds of domains: aircraft, ships, submarines, sensors, and command-and-control systems, rail, air traffic management systems, and lots of software safety. So, I’ve done a lot of different things!

  • Navigating the Safety Case

    Navigating the Safety Case

    Navigating the Safety Case is Part 4 of a four-part series on safety cases. In it, we look at timing issues and typical content through the safety case lifecycle.

    A Comprehensive Guide to Ensuring Project Safety

    When embarking on any significant project, ensuring safety isn’t just a step in the process—it’s the foundation of success. A Safety Case is the bedrock of this commitment, systematically building the evidence needed to demonstrate that a system is safe for use throughout its lifecycle. Here’s a vibrant, step-by-step guide to understanding and implementing Safety Cases effectively.

    Starting the Safety Journey: Initiation

    The moment that Safety Management activity kicks off, the Safety Case begins to take shape. Think of it as an evolving tapestry where each thread represents a layer of safety assurance.

    Milestone Checkpoints: Producing Safety Case Reports

    Safety Case Reports should be produced at pivotal milestones to maintain accountability and ensure progress. These reports not only showcase progress but also serve as vital checkpoints to align all stakeholders. Common milestones include:

    1. Approval of the Outline Business Case
    2. Approval of the Full Business Case
    3. Authorization to begin demonstration trials
    4. Completion of major design phases
    5. Commitment to production
    6. Testing, acceptance, and user trials
    7. System introduction to service
    8. Design or material state updates (e.g., midlife refresh)
    9. Operational changes
    10. Disposal of the system

    These reports should align with the Project Safety Management Plan, serving as contractual deliverables between the contractor and the project team.

    Keeping it Alive: Periodic Reviews

    Safety isn’t static. The Safety Case is a living document requiring ongoing updates, reviews, and configuration control. Regular reviews ensure it adapts to new challenges, emerging risks, and evolving system requirements.

    Gathering Insights: Required Inputs

    To build a robust Safety Case, a wealth of inputs is essential. These include data and outputs from key procedures such as hazard identification, risk estimation, risk reduction, and safety requirements. The journey is a collaborative effort where insights from all corners of the project feed into the evolving safety narrative.

    The Safety Case and Safety Case Report require inputs from:

    1. Outputs from Procedure SMP01 – Safety Initiation;
    2. Outputs from Procedure SMP02 – Safety Committee;
    3. Outputs from Procedure SMP03 – Safety Planning;
    4. Outputs from Procedure SMP04 – Preliminary Hazard Identification and Analysis;
    5. Outputs from Procedure SMP05 – Hazard Identification and Analysis;
    6. Outputs from Procedure SMP06 – Risk Estimation;
    7. Outputs from Procedure SMP07 – Risk and ALARP Evaluation;
    1. Outputs from Procedure SMP08 – Risk Reduction;
    2. Outputs from Procedure SMP09 – Risk Acceptance;
    3. Outputs from Procedure SMP10 – Safety Requirements and Contracts;
    4. Outputs from Procedure SMP11 – Hazard Log.

    Delivering Confidence: Required Outputs

    At its core, the Safety Case outputs are more than just documents—they are the backbone of confidence for all stakeholders. The primary outputs include:

    • Controlled documentation supporting the safety of the system
    • Detailed Safety Case Reports tailored to each project phase
    • Evidence-backed arguments showcasing tolerable risk levels

    Breaking It Down: Typical Safety Case Report Content

    An effective Safety Case Report doesn’t just inform; it assures. Here’s what it typically includes:

    • Executive Summary: Assurance of safety progress and stakeholder alignment
    • System Description: Boundaries, scope, and interface clarity
    • Assumptions: Factors underpinning safety requirements
    • Progress Assessment: Updates on safety activities and milestones
    • Risk Management: Documentation of hazards, risks, and mitigation strategies
    • Emergency and Contingency Plans: Preparedness for unforeseen circumstances
    • Operational Guidance: Practical safety insights for operators

    The Lifecycle Perspective: Safety Cases at Every Stage

    Concept Stage

    Here, safety begins with identifying risks early, crafting strategies, and ensuring feasibility. By the Outline Business Case, the safety vision should be clear, even if some areas remain undefined.

    Assessment Phase

    Building on the Concept Stage, this phase involves a deeper analysis of risks and strategies for mitigation, culminating in a Safety Case Report for the Full Business Case.

    Demonstration & Trials

    Safety during trials ensures a controlled environment for testing and evaluation. Detailed Safety Management Plans guide this phase, ensuring all involved parties understand their responsibilities.

    Introduction to Service

    At this stage, safety extends to operational readiness—ensuring support facilities, training, and logistic arrangements are in place.

    Disposal

    Disposal planning begins early, considering risks throughout the system’s life. Safety Cases for disposal ensure proper handling, whether through recycling, scrapping, or resale, minimizing liability and environmental impact.

    Conclusion

    The Safety Case is more than a procedural requirement—it’s a commitment to integrity, collaboration, and responsibility. By weaving together comprehensive safety practices at every stage, projects can achieve a level of confidence that benefits all stakeholders.

    Are you ready to take your Safety Case to the next level? Share your thoughts and experiences in the comments below!

    Meet the Author

    Learn safety engineering with me, an industry professional with 25 years of experience, I have:

    •Worked on aircraft, ships, submarines, ATMS, trains, and software;

    •Tiny programs to some of the biggest (Eurofighter, Future Submarine);

    •In the UK and Australia, on US and European programs;

    •Taught safety to hundreds of people in the classroom, and thousands online;

    •Presented on safety topics at several international conferences.

  • The Lifelong Evolution of a Safety Case

    The Lifelong Evolution of a Safety Case

    Introduction

    In The Lifelong Evolution of a Safety Case, we look at how to Review and revise a Safety Case and Re-Issue a Safety Case Report.

    When it comes to ensuring safety throughout any Product, System, or Service lifecycle, reviewing and revising the Safety Case isn’t just a recommendation—it’s essential. The age or status of equipment isn’t simply about how old it is. Instead, it reflects an understanding of its condition, the effects of changes, and its performance in varying environments over time. Let’s dive into the key principles of maintaining and revising a Safety Case and the potential risks and strategies to avoid them.

    Why Review the Safety Case?

    Changes in operations, equipment condition, or organizational controls can disrupt the assumptions on which the original Safety Case was built. Recognizing when a review is needed ensures safety remains uncompromised.

    Here are examples of scenarios that demand attention:

    • Structural Modifications: Repairs or upgrades impacting safety.
    • New Activities: Introduction of new tasks or uses for the equipment.
    • Environmental Changes: Shifts in operational environments or equipment roles.
    • Incident Data: Insights from accidents or maintenance inspections.
    • System Evolution: Decommissioning, extended use, or technological upgrades.

    Figure: Relationship between the Safety Management System and Safety Case in terms of Age and Status

    Relationship between the Safety Management System and Safety Case

    Challenging Assumptions: The Foundation of Safety

    A Safety Case is never static—it evolves as evidence and conditions change. It’s vital to challenge existing arguments continually. If new evidence undermines the validity of the Safety Case, steps like obtaining further proof, implementing corrective actions, or, in extreme cases, halting operations may be necessary.

    Consider this: what was deemed safe at one time might become risky due to wear, updates, or new findings. Regular reviews ensure the Safety Case remains robust and relevant.

    Ownership and Administration: Who’s in Charge?

    The custodian of the Safety Case is the Project Safety Manager, the linchpin in ensuring safety throughout the lifecycle of the system. This individual must coordinate all safety activities, maintain the Safety Case, and oversee its interaction with the Safety Management System (SMS).

    While contractors may handle the technical details, the responsibility for ensuring the integrity and adequacy of the Safety Case rests with the appointed safety delegation holder.

    Records Matter: Documenting Safety

    Every decision, from hazard mitigation to safety strategy adjustments, must be meticulously recorded. Key documents feeding into this process include:

    • System Requirements Document: Detailing specific safety needs.
    • Customer-Supplier Agreement: Outlining deliverables.
    • Through-Life Management Plan: Ensuring continuity in safety oversight.

    A central part of this process is the Hazard Log, which serves as the repository of all identified risks and their management status. (see Procedure SMP11 – Hazard Log).

    Avoiding Pitfalls: The Warnings

    The warnings and project risks identified in all the other procedures, from SMP01 to SMP11 can manifest themselves through effects on the Safety Case, as it brings their outputs together. Also, there are other project risks specific to the Safety Case.

    Neglecting regular reviews or documentation can lead to significant issues, including:

    1. Delays in Safety Approvals: Failure to engage approval authorities early can result in unmet safety requirements and service delays.
    2. Outdated Safety Cases: A mismatch between documentation and the system’s current state undermines credibility.
    3. Inadequate Risk Analysis: Improper techniques during safety assessments may yield an incomplete Safety Case.
    4. Lost Records: Poor documentation management can erode trust in the safety process.

    Completing the Circle: The Role of Collaboration

    Maintaining a credible and effective Safety Case is a collective effort. Contractors, safety committees, and stakeholders must work in concert to identify and mitigate hazards. Sharing data, especially during transitions between contractors, is crucial to avoiding gaps in safety oversight.

    Wrapping Up

    The Safety Case is more than a set of documents—it’s a dynamic framework ensuring that safety risks are continuously managed throughout the lifecycle of a system. With proper reviews, updates, and collaboration, it provides confidence that safety remains a top priority, no matter the changes a system undergoes.

    This blog article is Part 3 of a series. It follows on from Part 2.

    Meet the Author of ‘The Lifelong Evolution of a Safety Case’

    Learn safety engineering with me, an industry professional with 25 years of experience, I have:

    •Worked on aircraft, ships, submarines, ATMS, trains, and software;

    •Tiny programs to some of the biggest (Eurofighter, Future Submarine);

    •In the UK and Australia, on US and European programs;

    •Taught safety to hundreds of people in the classroom, and thousands online;

    •Presented on safety topics at several international conferences.

  • The 2024 Blog Digest – Q3/Q4

    The 2024 Blog Digest – Q3/Q4

    The 2024 Blog Digest – Q3/Q4 brings you all of The Safety Artisan’s blog posts from the first six months of this year. I hope that you find this a useful resource!

    The 2024 Blog Digest – Q3/Q4: 18 Posts!

    Meet the Author

    Learn safety engineering with me, an industry professional with 25 years of experience. I have:

    •Worked on aircraft, ships, submarines, ATMS, trains, and software;

    •Tiny programs to some of the biggest (Eurofighter, Future Submarine);

    •In the UK and Australia, on US and European programs;

    •Taught safety to hundreds of people in the classroom, and thousands online;

    •Presented on safety topics at several international conferences.

    Hi, everyone, and welcome to The Safety Artisan. I’m Simon, and I just wanted to share with you briefly why I started this enterprise. I’ve had a career in safety, engineering, and safety consulting for over 25 years now. And in that time, I’ve seen customers make one of two mistakes quite often. First of all, I’ve seen customers not do some things that they should have been doing. This was usually because they were just ignorant of what their legal obligations were.

    And I guess that’s a fairly obvious mistake. That’s what you would expect me to say. But more often, I’ve seen customers do too much to try and achieve safety, which is surprising! I’ve seen people waste a lot of time, energy, and money doing things that just didn’t make a difference. Sometimes it actually got in the way of doing good safety work.

    And I think the reasons for those mistakes are, first of all, ignorance.

    Secondly, not knowing precisely what safety is and therefore not being able to work out how to get there. That’s why I started The Safety Artisan. I wanted to equip people with the knowledge of what safety really is and the tools to get there efficiently. To neither do too much nor too little. We want Safety, Just Right.