Blog

  • Reflections on a Career in Safety, Part 3

    Reflections on a Career in Safety, Part 3

    In ‘Reflections on a Career in Safety, Part 3’ I continue talking about different kinds of Safety, moving onto…

    Projects and Products

    Then moving on to the project side, where teams of people were making sure a new aeroplane, a new radio, a new whatever it might be, was going to work in service; people were going to be able to use it, easily, support it, get it replaced or repaired if they had to. So it was a much more technical job – so lots of software, lots of people, lots of process and more people.

    Moving to the software team was a big shock to me. It was accidental. It wasn’t a career move that I had chosen, but I enjoyed it when I got there.  For everything else in the Air Force, there was a rule. There was a process for doing this. There were rules for doing that. Everything was nailed down. When I went to the software team, I discovered there are no rules in software, there are only opinions.

    The ‘H’ is software development is for ‘Happiness’

    So straight away, it became a very people-focused job because if you didn’t know what you were doing, then you were a bit stuck.  I had to go through a learning curve, along with every other technician who was on the team. And the thing about software with it being intangible is that it becomes all about the process. If a physical piece of kit like the display screen isn’t working, it’s pretty obvious. It’s black, it’s blank, nothing is happening. It’s not always obvious that you’ve done something wrong with software when you’re developing it.

    So we were very heavily reliant on process; again, people have got to decide what’s the right process for this job? What are we going to do? Who’s going to do it? Who’s able to do it? And it was interesting to suddenly move into this world where there were no rules and where there were some prima donnas.

    Photo by Sandy Millar on Unsplash

    We had a handful of really good programmers who could do just about anything with the aeroplane, and you had to make the best use of them without letting them get out of control.  Equally, you had people on the other end of the scale who’d been posted into the software team, who really did not want to be there. They wanted to get their hands dirty, fixing aeroplanes. That’s what they wanted to do. Interesting times.

    From the software team, I moved on to big projects like Eurofighter, that’s when I got introduced to:

    Systems Engineering

    And I have no problem with plugging systems engineering because as a safety engineer, I know [that] if there is good systems engineering and good project management, I know my job is going to be so much easier. I’ve turned up on a number of projects as a consultant or whatever, and I say, OK, where’s the safety plan? And they say, oh, we want you to write it. OK, yeah, I can do that. Whereas the project management plan or where’s the systems engineering management plan?

    If there isn’t one or it’s garbage – as it sometimes is – I’m sat there going, OK, my just my job just got ten times harder, because safety is an emergent property. So you can say a piece of kit is on or off. You can say it’s reliable, but you can’t tell whether it’s safe until you understand the context. What are you asking it to do in what environment? So unless you have something to give you that wider and bigger picture and put some discipline on the complexity, it’s very hard to get a good result.

    Photo by Sam Moqadam on Unsplash

    So systems engineering is absolutely key, and I’m always glad to work with the good systems engineer and all the artifacts that they’ve produced. That’s very important. So clarity in your documentation is very helpful. Being [involved], if you’re lucky, at the very beginning of a program, you’ve got an opportunity to design safety, and all the other qualities you want, into your product. You’ve got an opportunity to design in that stuff from the beginning and make sure it’s there, right there in the requirements.

    Also, systems engineers doing the requirements, working out what needs to be done, what you need the product to do, and just as importantly, what you need it not to do, and then passing that on down the chain. That’s very important. And I put in the title “managing at a distance” because, unlike in the operations world where you can say “that’s broken, can you please go and fix it”.

    Managing at a Distance

    It’s not as direct as that.  You’re looking at your process, you’re looking at the documentation, you’re working with, again, lots and lots of people, not all of whom have the same motivation that you do.

    Photo by Bonneval Sebastien on Unsplash

    Industry wants to get paid. They want to do the minimum work to get paid, [in order] to maximize their profit. You want the best product you can get. The pilots want something that punches holes in the sky and looks flash and they don’t really care much about much else, because they’re quite inoculated to risk.

    So you’ve got people with competing motivations and everything has got to be worked indirectly. You don’t get to control things directly. You’ve got to try and influence and put good things in place, in almost an act of faith that, [you put] good things in place and good things will result.  A good process will produce a good product. And most of the time that’s true. So (my last slide on work), I ended up doing consultancy, first internally and then externally.

    Part 4 will follow next week!

    New to System Safety? Then start here. There’s more about The Safety Artisan here. Subscribe for free regular emails here.

  • Reflections on a Career in Safety, Part 2

    Reflections on a Career in Safety, Part 2

    In ‘Reflections on a Career in Safety, Part 2’ I move on to …

    Different Kinds of Safety

    So I’m going to talk a little bit about highlights, that I hope you’ll find useful.  I went straight from university into the Air Force and went from this kind of [academic] environment to heavy metal, basically.  I guess it’s obvious that wherever you are if you’re doing anything in industry, workplace health and safety is important because you can hurt people quite quickly. 

    Workplace Health and Safety

    In my very first job, we had people doing welding, high voltage electrics, heavy mechanical things; all [the equipment was] built out of centimeter-thick steel. It was tough stuff and people still managed to bend it. So the amount of energy that was rocking around there, you could very easily hurt people.  Even the painters – that sounds like a safe job, doesn’t it? – but aircraft paint at that time a cyanoacrylate. It was a compound of cyanide that we used to paint aeroplanes with.

    All the painters and finishers had to wear head-to-toe protective equipment and breathing apparatus. If you’re giving people air to breathe, if you get that wrong, you can hurt people quite quickly. So even managing the hazards of the workplace introduced further hazards that all had to be very carefully controlled.

    Photo by Ömer Yıldız on Unsplash

    And because you’re in operations, all the decisions about what kind of risks and hazards you’re going to face, they’ve already been made long before.  Decisions that were made years ago, when a new plane or ship or whatever it was, was being bought and being introduced [into service]. Decisions made back then, sometimes without realizing it, meant that we were faced with handling certain hazards and you couldn’t get rid of them. You just had to manage them as best you could.

    Overall, I think we did pretty well. Injuries were rare, despite the very exciting things that we were dealing with sometimes.  We didn’t have too many near misses – not that we heard about anyway. Nevertheless, that [risk] was always there in the background. You’re always trying to control these things and stop them from getting out of control.

    One of the things about a workplace in operations and support, whether you’re running a fleet of aeroplanes or you’re servicing some kit for somebody else and then returning it to them, it tends to be quite a people-centric job. So, large groups of people doing the job, supervision, organization, all that kind of stuff.  And that can all seem very mundane, a lot of HR-type stuff. But it’s important and it’s got to be dealt with.

    So the real world of managing people is a lot of logistics. Making sure that everybody you need is available to do the work, making sure that they’ve got all the kit, all the technical publications that tell them what to do, the information that they need.  It’s very different to university – a lot of seemingly mundane stuff – but it’s got to be got right because the consequences of stuffing up can be quite serious.

    Safe Systems of Work

    So moving on to some slightly different topics, when I got onto working with Aeroplanes, there was an emphasis on a safe system of work, because doing maintenance on a very complex aeroplane was quite an involved process and it had to be carefully controlled. So we would have what’s usually referred to as a Permit to Work system where you very tightly control what people are allowed to do to any particular plane. It doesn’t matter whether it’s a plane or a big piece of mining equipment or you’re sending people in to do maintenance on infrastructure; whatever it might be, you’ve got to make sure that the power is disconnected before people start pulling it apart, et cetera, et cetera.

    Photo by Leon Dewiwje on Unsplash

    And then when you put it back together again, you’ve got to make sure that there aren’t any bits leftover and everything works before you hand it back to the operators because they’re going to go and do some crazy stuff with it. You want to make sure that the plane works properly. So there was an awful lot of process in that. And in those days, it was a paperwork process. These days, I guess a lot would be computerized, but it’s still the same process.

    If you muck up the process, it doesn’t matter whether [it is paper-based or not].  If you’ve got a rubbish process, you’re going to get rubbish results and it [computerization] doesn’t change that. You just stuff up more quickly because you’ve got a more powerful tool. And for certain things we had to take, I’ve called it special measures. In my case, we were a strike squadron, which meant our planes would carry nuclear weapons if they had to.

    Special Processes for Special Risks

    So if the Soviets charged across the border with 20,000 tanks and we couldn’t stop them, then it was time to use – we called them buckets of sunshine. Sounds nice, doesn’t it? Anyway, so there were some fairly particular processes and rules for looking after buckets of sunshine. And I’m glad to say we only ever used dummies. But when you when the convoy arrived and yours truly has to sign for the weapon and then the team starts loading it, then that does concentrate your mind as an engineer. I think I was twenty-two, twenty-three at the time.  

    Photo by Oscar Ävalos on Unsplash

    Somebody on [our Air Force] station stuffed up on the paperwork and got caught. So that was two careers of people my age, who I knew, that were destroyed straight away, just by not being too careful about what they were doing. So, yeah, that does concentrate the mind.  If you’re dealing with, let’s say you’re in a major hazard facility, you’re in a chemical plant where you’ve got perhaps thousands of tonnes of dangerous chemicals, there are some very special risk controls, which you have to make sure are going to work most of the time.

    And finally, there is ‘airworthiness’: decisions about whether we could fly an aeroplane, even though some bits of it were not working. So that was a decision that I got to make once I got signed off to do it. But it’s a team job. You talk to the specialists who say, this bit of the aeroplane isn’t working, but it doesn’t matter as long as you don’t do “that”.

    Photo by Eric Bruton on Unsplash

    So you have to make sure that the pilots knew, OK, this isn’t working.  This is the practical effect from your [operator’s] point of view. So you don’t switch this thing on or rely on this thing working because it isn’t going to work. There were various decisions about [airworthiness] that were an exciting part of the job, which I really enjoyed.  That’s when you had to understand what you were doing, not on your own, because there were people who’d been there a lot longer than me.  But we had to make things work as best we could – that was life.

    Part 3 will follow next week!

    New to System Safety? Then start here. There’s more about The Safety Artisan here. Subscribe for free regular emails here.

  • Reflections on a Career in Safety, Part 1

    Reflections on a Career in Safety, Part 1

    This is Part 1 of my ‘Reflections on a Career in Safety’, from “Safety for Systems Engineering and Industry Practice”, a lecture that I gave to the University of Adelaide in May 2021. My thanks to Dr. Kim Harvey for inviting me to do this and setting it up.

    The Lecture, Part 1

    Hi, everyone, my name Simon Di Nucci and I’m an engineer, I actually – it sounds cheesy – but I got into safety by accident. We’ll talk about that later. I was asked to talk a little bit about career stuff, some reflections on quite a long career in safety, engineering, and other things, and then some stuff that hopefully you will find interesting and useful about safety work in industry and working for government.

    Context: my Career Summary

    I’ve got three areas to talk about, operations and support, projects and product development, and consulting.

    I have been on some very big projects, Eurofighter, Future Submarine Programme, and some others that have been huge multi-billion-dollar programs, but also some quite small ones as well. They’re just as interesting, sometimes more so. In the last few years, I’ve been working in consultancy. I have some reflections on those topics and some brief reflections on a career in safety.

    Starting Out in the Air Force

    So a little bit about my career to give you some context. I did 20 years in the Royal Air Force in the U.K., as you can tell from my accent, I’m not from around here. I started off fresh out of university, with a first degree in aerospace systems engineering. And then after my Air Force training, my first job was as an engineering manager on ground support equipment: in General Engineering Flight, it was called.

    We had people looking after the electrical and hydraulic power rigs that the aircraft needed to be maintained on the ground. And we had painters and finishers and a couple of carpenters and a fabric worker and some metal workers and welders, that kind of stuff. So I went from a university where we were learning about all this high-tech stuff about what was yet to come in the aerospace industry. It was a bit of the opposite end to go to, a lot of heavy mechanical engineering that was quite simple.

    And then after that, we had a bit of excitement because six weeks after I started, in my very first job, the Iraqis invaded Kuwait.  I didn’t go off to war, thank goodness, but some of my people did. We all got ready for that: a bit of excitement.

    Photo by Jacek Dylag on Unsplash

    After that, I did a couple of years on a squadron, on the front line. We were maintaining and fixing the aeroplanes and looking after operations. And then from there, I went for a complete change. Actually, I did three years on a software maintenance team and that was a very different job, which I’ll talk about later. I had the choice of two unpleasant postings that I really did not want, or I could go to the software maintenance team.

    Into Software by accident as well!

    I discovered a burning passion to do software to avoid going to these other places. And that’s how I ended up there. I had three, fantastic years there and really enjoyed that. Then, I was thinking of going somewhere down south to be in the UK, to be near family, but we went further north. That’s the way things happen in the military.

    I got taken on as the rather grandly titled Systems and Software Specialist Officer on the Typhoon Field Team. The Eurofighter Typhoon wasn’t in service at that point. (That didn’t come in until 2003 when I was in my last Air Force job, actually.)  We had a big team of handpicked people who were there to try and make sure that the aircraft was supportable when it came into service.

    One of the big things about the new aircraft was it had tons of software on board.  There were five million lines of code on board, which was a lot at the time, and a vast amount of data. It was a data hog; it ate vast amounts of data and it produced vast amounts of data and that all needed to be managed. It was on a scale beyond anything we’d seen before. So it was a big shock to the Air Force.

    More Full-time Study

    Photo by Mike from Pexels

    Then after that, I was very fortunate.  (This is a picture of York, with the minister in the background.) I spent a year full-time doing the safety-critical systems engineering course at York, which was excellent.  It was a privilege to be able to have a year to do that full-time. I’ve watched a lot of people study part-time when they’ve got a job and a family, and it’s really tough. So I was very, very pleased that I got to do that.

    After that, I went to do another software job where this time we were in a small team and we were trying to drive software supportability into new projects coming into service, all kinds of stuff, mainly aircraft, but also other things as well.  That was almost like an internal consultancy job. The only difference was we were free, which you would think would make it easier to sell our services. But the opposite is the case.

    Finally, in my last Air Force job, I was part of the engineering authority looking after the Typhoon aircraft as it came into service, which is always a fun time. We just got the plane into service. And then one of the boxes that I was responsible for malfunctioned. So the undercarriage refused to come down on the plane, which is not what you want. We did it did get down safely in the end, but then the whole fleet was grounded and we had to fix the problem. So some more excitement there. Not always of the kind that you want, but there we go. So that took me up to 2006.

    At that point, I transitioned out of the Air Force and I became a consultant

    So, I always regarded consultants with a bit of suspicion up until then, and now I am one. I started off with a firm called QinetiQ, which is also over here. And I was doing safety mainly with the aviation team. But again, we did all sorts, vehicles, ships, network logistics stuff, all kinds of things. And then in 2012, I joined Frazer-Nash in order to come to Australia.

    So we appeared in Australia in November 2012. And we’ve been here in Adelaide all almost all that time. And you can’t get rid of us now because we’re citizens. So you’re stuck with us. But it’s been lovely. We love Adelaide and really enjoy, again, the varied work here.

    Adelaide CBD, photo by Simon Di Nucci

    Part 2 will follow next week!

    New to System Safety? Then start here. There’s more about The Safety Artisan here. Subscribe for free regular emails here.

  • Functional Safety

    Functional Safety

    The following is a short, but excellent, introduction to the topic of ‘Functional Safety’ by the United Kingdom Health and Safety Executive (UK HSE). It is equally applicable outside the UK, and the British Standards (‘BS EN’) are versions of international ISO/IEC standards – e.g. the Australian version (‘AS/NZS’) is often identical to the British standard.

    My comments and explanations are shown [thus].

    [Functional Safety]

    “Functional safety is the part of the overall safety of plant and equipment that depends on the correct functioning of safety-related systems and other risk reduction measures such as safety instrumented systems (SIS), alarm systems and basic process control systems (BPCS).

    [Functional Safety is popular, in fact almost ubiquitous, in the process industry, where large amounts of flammable liquids and gasses are handled. That said, the systems and techniques developed by and for the process industry have been so successful that they are found in many other industrial, transport and defence applications.]

    SIS [Safety Instrumented Systems]

    SIS are instrumented systems that provide a significant level of risk reduction against accident hazards.  They typically consist of sensors and logic functions that detect a dangerous condition and final elements, such as valves, that are manipulated to achieve a safe state.

    The general benchmark of good practice is BS EN 61508, Functional safety of electrical/electronic/programmable electronic safety related systems. BS EN 61508 has been used as the basis for application-specific standards such as:

    • BS EN 61511: process industry
    • BS EN 62061: machinery
    • BS EN 61513: nuclear power plants

    BS EN 61511, Functional safety – Safety instrumented systems for the process industry sector, is the benchmark standard for the management of functional safety in the process industries. It defines the safety lifecycle and describes how functional safety should be managed throughout that lifecycle. It sets out many engineering and management requirements, however, the key principles of the safety lifecycle are to:

    • use hazard and risk assessment to identify requirements for risk reduction
    • allocate risk reduction to SIS or to other risk reduction measures (including instrumented systems providing safety functions of low / undefined safety integrity)
    • specify the required function, integrity and other requirements of the SIS
    • design and implement the SIS to satisfy the safety requirements specification
    • install, commission and validate the SIS
    • operate, maintain and periodically proof-test the SIS
    • manage modifications to the SIS
    • decommission the SIS

    BS EN 61511 also defines requirements for management processes (plan, assess, verify, monitor and audit) and for the competence of people and organisations engaged in functional safety.  An important management process is Functional Safety Assessment (FSA) which is used to make a judgement as to the functional safety and safety integrity achieved by the safety instrumented system.

    Alarm Systems

    Alarm systems are instrumented systems designed to notify an operator that a process is moving out of its normal operating envelope to allow them to take corrective action.  Where these systems reduce the risk of accidents, they need to be designed to good practice requirements considering both the E,C&I design and human factors issues to ensure they provide the necessary risk reduction.

    In certain limited cases, alarm systems may provide significant accident risk reduction, where they also might be considered as a SIS. The general benchmark of good practice for management of alarm systems is BS EN 62682.

    BPCS [Basic Process Control Systems]

    BPCS are instrumented systems that provide the normal, everyday control of the process.  They typically consist of field instrumentation such as sensors and control elements like valves which are connected to a control system, interfaced, and could be operated by a plant operator.  A control system may consist of simple electronic devices like relays or complicated programmable systems like DCS (Distributed Control System) or PLCs (Programmable Logic Controllers).

    BPCS are normally designed for flexible and complex operation and to maximize production rather than to prevent accidents.  However, it is often their failure that can lead to accidents, and therefore they should be designed to good practice requirements. The general benchmark of good practice for instrumentation in process control systems is BS 6739.”

    [To be honest, I would have put this the other way around. The BCPS came first, although they were just called ‘control systems’, and some had alarms to get the operators’ attention. As the complexity of these control systems increased, then cascading alarms became a problem and alarms had to be managed as a ‘thing’. Finally, the process industry used additional systems, when the control system/alarm system combo became inadequate, and thus the terms SIS and BCPS were born.]

    [It’s worth noting that for very rapid processes where a human either cannot intervene fast enough or lacks the data to do so reliably, the SIS becomes an automatic protection system, as found in rail signaling systems, or ‘autonomous’ vehicles. Also for domains where there is no ‘fail-safe’ state, for example in aircraft flight control systems, the tendency has been to engineer multiple, redundant, high-integrity control systems, rather than use a BCPS/SIS combo.]

    Copyright

    The above text is reproduced under Creative Commons Licence from the UK HSE’s webpage. The Safety Artisan complies with such licensing conditions in full.

    [Functional Safety – END]

    Back to Home Page

  • How to Understand Safety Standards

    How to Understand Safety Standards

    Learn How to Understand Safety Standards with this FREE session from The Safety Artisan.

    In this module, Understanding Your Standard, we’re going to ask the question: Am I Doing the Right Thing, and am I Doing it Right? Standards are commonly used for many reasons. We need to understand our chosen system safety engineering standard, in order to know: the concepts, upon which it is based; what it was designed to do, why and for whom; which kinds of risk it addresses; what kinds of evidence it produces; and it’s advantages and disadvantages.

    Understand Safety Standards : You’ll Learn to

    • List the hazard analysis tasks that make up a program; and
    • Describe the key attributes of Mil-Std-882E. 
    Understanding Your Standard

    Topics:  Understand Safety Standards

    Aim: Am I Doing the Right Thing, and am I Doing it Right?

    • Standards: What and Why?
    • System Safety Engineering pedigree;
    • Advantages – systematic, comprehensive, etc:
    • Disadvantages – cost/schedule, complexity & quantity not quality.

    Transcript: Understand Safety Standards

    Click here for the Transcript on Understanding Safety Standards

    In Module Three, we’re going to understand our Standard. The standard is the thing that we’re going to use to achieve things – the tool. And that’s important because tools designed to do certain things usually perform well. But they don’t always perform well on other things. So we’re going to ask ‘Are we doing the right thing?’ And ‘Are we doing it right?’

    What and Why?

    So, what are we going to do, and why are we doing it? First of all, the use of standards in safety is very common for lots of reasons. It helps us to have confidence that what we’re doing is good enough. We’ve met a standard of performance in the absolute sense. It helps us to say, ‘We’ve achieved standardization or commonality in what we’re doing’. And we can also use it to help us achieve a compromise. That can be a compromise across different stakeholders or across different organizations. And standardization gives us some of the other benefits as well. If we’re all doing the same thing rather than we’re all doing different things, it makes it easier to train staff. This is one example of how a standard helps.

    However, we need to understand this tool that we’re going to use. What it does, what it’s designed to do, and what it is not designed to do. That’s important for any standard or any tool. In safety, it’s particularly important because safety is in many respects intangible. This is because we’re always looking to prevent a future problem from occurring. In the present, it’s a little bit abstract. It’s a bit intangible. So, we need to make sure that in concept what we’re doing makes sense and is coherent. That it works together. If we look at those five bullet points there, we need to understand the concept of each standard. We need to understand the basis of each one.

    And they’re not all based on the same concept. Thus some of them are contradictory or incompatible. We need to understand the design of the standard. What the standard does, what the aim of the standard is, why it came into existence. And who brought it into existence. To do what for who – who’s the ultimate customer here?

    And for risk analysis standards, we need to understand what kind of risks it addresses. Because the way you treat a financial risk might be very different from a safety risk. In the world of finance, you might have a portfolio of products, like loans. These products might have some risks associated with them. One or two loans might go bad and you might lose money on those. But as long as the whole portfolio is making money that might be acceptable to you. You might say, ‘I’m not worried about that 10% of my loans have gone south and all gone wrong. I’m still making plenty of profit out of the other 90%’. It doesn’t work that way with safety. You can’t say ‘It’s OK that I’ve killed a few people over here because all this a lot over here are still alive!’. It doesn’t work like that!

    Also, what kind of evidence does the standard produce? Because in safety, we are very often working in a legal framework that requires us to do certain things. It requires us to achieve a certain level of safety and prove that we have done so. So, we need certain kinds of evidence. In different jurisdictions and different industries, some evidence is acceptable. Some are not. You need to know which is for your area.

    And then finally, let’s think about the pros and cons of the standard, what does it do well? And what does it do not so well?

    System Safety Pedigree

    We’re going to look at a standard called Military Standard 882E. Many decades ago, this standard developed was created by the US government and military to help them bring into service complex-cutting edge military equipment. Equipment that was always on the cutting edge. That pushed the limits of what you could achieve in performance.

    That’s a lot of complexity. Lots of critical weapon systems, and so forth. And they needed something that could cope with all that complexity. It’s a system safety engineering standard. It’s used by engineers, but also by many other specialists. As I said, it’s got a background from military systems. These days you find these principles used pretty much everywhere. So, all the approaches to System Safety that 882 introduced are in other standards. They are also in other countries.

    It addresses risks to people, equipment, and the environment, as we heard earlier. And because it’s an American standard, it’s about system safety. It’s very much about identifying requirements. What do we need to happen to get safety? To do that, it produces lots of requirements. It performs analyses in all those requirements and generates further requirements. And it produces requirements for test evidence. We then need to fulfill these requirements. It’s got several important advantages and disadvantages. We’re going to discuss these in the next few slides.

    Comprehensive Analysis

    Before we get to that, we need to look at the key feature of this standard. The strengths and weaknesses of this standard come from its comprehensive analysis. And the chart (see the slide) is meant to show how we are looking at the system from lots of different perspectives. (It’s not meant to be some arcane religious symbol!) So, we’re looking at a system from 10 different perspectives, in 10 different ways.

    Going around clockwise, we’ve got these ten different hazard analysis tasks. First of all, we start off with preliminary hazard identification. Then preliminary hazard analysis. We do some system requirements hazard analysis. So, we identify the safety requirements that the system is going to meet so that we are safe. We look at subsystem and system hazard analysis. At operating and support hazard analysis – people working with the system. Number seven, we look at health hazard analysis – Can the system cause health problems for people? Functional hazard analysis, which is all about what it does. We’re thinking of sort of source software and data-driven functionality. Maybe there’s no physical system, but it does stuff. It delivers benefits or risks. System of systems hazard analysis – we could have lots of different and/or complex systems interacting. And then finally, the tenth one – environmental hazard analysis.

    If we use all these perspectives to examine the system, we get a comprehensive analysis of the system. From this analysis, we should be confident that we have identified everything we need to. All the hazards and all the safety requirements that we need to identify. Then we can confidently deliver an appropriate safe system. We can do this even if the system is extremely complex. The standard is designed to deal with big, complex cutting-edge systems.

    Advantages #1

    In fact, as we move on to advantages, that’s the number one advantage of this standard. If we use it and we use all 10 of those tasks, we can cope with the largest and the most demanding programs. I spent much of my career working on the Eurofighter Typhoon. It was a multi-billion-dollar program. It cost hundreds of billions of dollars, four different nations worked together on it. We used a derivative of Mil. Standard 882 to look at safety and analyze it. And it coped. It was powerful enough to deal with that gigantic program. I spent 13 years of my life on and off on that program so I’d like to think that I know my stuff when we’re talking about this.

    As we’ve already said, it’s a systematic approach to safety. Systems, safety, engineering. And we can start very early. We can start with early requirements – discovery. We don’t even need a design – we know that we have a need. So we can think about those needs and analyze them.

    And it can cover us right through until final disposal. And it covers all kinds of elements that you might find in a system. Remember our definition of ‘system’? It’s something that consists of hardware, software, data, human beings, etc. The standard can cope with all the elements of a system. In fact, it’s designed into the standard. It was specifically designed to look at all those different elements. Then to get different insights from those elements. It’s designed to get that comprehensive coverage. It’s really good at what it does. And it involves, not just engineers, but people from all kinds of other disciplines. Including operators, maintainers, etc, etc.

    I came from a maintenance background. I was either directly or indirectly supporting operators. I was responsible for trying to help them get the best out of their system. Again, that’s a very familiar world to me. And rigorous standards like this can help us to think rigorously about what we’re doing. And so get results even in the presence of great complexity, which is not always a given, I must say.

    So, we can be confident by applying the standard. We know that we’re going to get a comprehensive and thorough analysis. This assures us that what we’re doing is good.

    Advantages #2

    So, there’s another set of advantages. I’ve already mentioned that we get assurance. Assurance is ‘justified confidence’. So we can have high confidence that all reasonably foreseeable hazards will be identified and analyzed. And if you’re in a legal jurisdiction where you are required to hit a target, this is going to help you hit that target.

    The standard was also designed for use in contracts. It’s designed to be applied to big programs. We’d define that as where we are doing the development of complex high-performance systems. So, there are a lot of risks. It’s designed to cope with those risks.

    Finally, the standard also includes requirements for contracting, for interfaces with other systems, for interfaces with systems engineering. This is very important for a variety of disciplines. It’s important for other engineering and technical disciplines. It’s important for non-technical disciplines and for analysis and recordkeeping. Again, all these things are important, whether it is for legal reasons or not. We need to do recordkeeping. We need to liaise with other people and consult with them. There are legal requirements for that in many countries. This standard is going to help us do all those things.

    But, of course, in a standard everything has pros and cons and Mil. Standard 882 is no exception. So, let’s look at some of the disadvantages.

    Disadvantages #1

    First of all, a full system safety program might be overkill for the system that you want to use, or that you want to analyze.  The Cold War, thank goodness, is over; generally speaking, we’re not in the business of developing cutting-edge high-performance killing machines that cost billions and billions of dollars and are very, very risky. These days, we tend to reduce program risk and cost by using off-the-shelf stuff and modifying it. Whether that be for military systems, infrastructure in the chemical industry, transportation, whatever it might be. Very much these days we have a family of products and we reuse them in different ways. We mix and match to get the results that we want.

    And of course, all this comprehensive analysis is not cheap and it’s not quick. It may be that you’ve got a program that is schedule-constrained. Or you want to constrain the cost and you cannot afford the time and money to throw a full 882 program at it. So, that’s a disadvantage.

    The second family of problems is that these kinds of safety standards have often been applied prescriptively. The customer would often say, ‘Go away and go and do this. I’m going to tell you what to do based on what I think reduces my risk’. Or at least it covers their backside. So, contractors got used to being told to do certain things by purchasers and customers. The customers didn’t understand the standards that they were applying and insisting upon. So, the customers did not understand how to tailor a safety standard to get the result that they wanted. So they asked for dumb things or things that didn’t add value. And the contractors got used to working in that kind of environment. They got used to being told what to do and doing it because they wouldn’t get paid if they didn’t. So, you can’t really blame them.

    But that’s not great, OK? That can result in poor behaviors. You can waste a lot of time and money doing stuff that doesn’t actually add value. And everybody recognizes that it doesn’t add value. So you end up bringing the whole safety program into disrepute and people treat it cynically. They treat it as a box-ticking exercise. They don’t apply creativity and imagination to it. Much less determination and persistence. And that’s what you need for a good effective system safety program. You need creativity. You need imagination. You need people to be persistent and dedicated to doing a good job. You need that rigor so that you can have the confidence that you’re doing a good job because it’s intangible.

    Disadvantages #2

    Let’s move onto the second kind of family of disadvantages. And this is the one that I’ve seen the most, actually, in the real world. If you do all 10 tasks and even if you don’t do all 10, you can create too many hazards. If you recall the graphic from earlier, we have 10 tasks. Each task looks at the system from a different angle. What you can get is lots and lots of duplication in hazard identification. You can have essentially the same hazards identified over and over again in each task. And there’s a problem with that, in two ways.

    First of all, quality suffers. We end up with a fragmented picture of hazards. We end up with lots and lots of hazards in the hazard log, but not only that. We get fragments of hazards rather than the real thing. Remember I said those tests for what a hazard really is? Very often you can get causes masquerading as hazards. Or other things that that exacerbating factors that make things worse. They’re not a hazard in their own right, but they get recorded as hazards. And that problem results in people being unable to see the big picture of risk. So that undermines what we’re trying to do. And as I say, we get lots of things misidentified and thrown into the pot. This also distracts people. You end up putting effort into managing things that don’t make a difference to safety. They don’t need to be managed. Those are the quality problems.

    And then there are quantity problems. And from personal experience, having too many hazards is a problem in itself.  I’ve worked on large programs where we were managing 250 hazards or thereabouts. That is challenging even with a sizable, dedicated team. That is a lot of work in trying to manage that number of hazards effectively. And there’s always the danger that it will slide into becoming a box-ticking exercise. Superficial at best.

    I’ve also seen projects that have two and a half thousand hazards or even 4000 hazards in the hazard log. Now, once you get up to that level, that is completely unmanageable. People who have thousands of hazards in a hazard log and they think they’re managing safety are kidding themselves. They don’t understand what safety is if they think that’s going to work. So, you end up with all these items in your hazard log, which become a massive administrative burden. So people end up taking shortcuts and the real hazards are lost. The real issues that you want to focus on are lost in the sea of detail that nobody will ever understand. You won’t be able to control them.

    Unfortunately, Mil. Standard 882 is good at generating these grotesque numbers of hazards. If you don’t know how to use the standard and don’t actively manage this issue, it gets to this stage. It can go and does go, badly wrong. This is particularly true on very big programs. And you really need clarity on big projects.

    Summary of Module

    Let’s summarize what we’ve done with this module. The aim was to help us understand whether we’re doing the right thing and whether we’ve done it right. And standards are terrific for helping us to do that. They help us to ensure we’re doing the right thing. That we’re looking at the right things. And they help us to ensure that we’re doing it rigorously and repeatedly. All the good quality things that we want. And Mil. Standard 882E that we’re looking at is a system safety engineering standard. So it’s designed to deal with complexity and high-performance and high-risk. And it’s got a great pedigree. It’s been around for a long time.

    Now that gives advantages. So, we have a system safety program with this standard that helps us to deal with complexity. That can cope with big programs, with lots of risks. That’s great.

    The disadvantages of this standard are that if we don’t know how to tailor or manage it properly, it can cost a lot of money. It can take a lot of time to give results which can cause problems for the program. And ultimately, you can accidentally ignore safety if you don’t deliver on time. And it can generate complexity. And it can generate a quantity of data that is so great that it actually undermines the quality of the data. It undermines what we’re trying to achieve. In that, we get a fragmented picture in which we can’t see the true risks. And so we can’t manage them effectively. If we get it wrong with this standard, we can get it really wrong. And that brings us to the end of this module.

    This is Module 3 of SSRAP

    This is Module 3 from the System Safety Risk Assessment Program (SSRAP) Course. Risk Analysis Programs – Design a System Safety Program for any system in any application. You can access the full course here.

    You can find more introductory lessons at Start Here.

  • Why Call it The Safety Artisan?

    Why Call it The Safety Artisan?

    Why did I call my business The Safety Artisan?

    artisan/ˈɑːtɪzan,ɑːtɪˈzan/Learn to pronounce noun

    A worker in a skilled trade, especially one that involves making things by hand. “street markets where local artisans display handwoven textiles, painted ceramics, and leather goods”

    Why Call it The Safety ‘Artisan’?

    Why The Safety ‘Artisan’?

    Hi, everyone. When I was choosing a name for my business, I thought of quite a lot of alternatives, but I settled on The Safety Artisan for three reasons. First, I liked the meaning of the word, the idea of an individual person pursuing their craft and trying to do it to the very best of their abilities.

    Second, I liked the application because I’ve worked on a lot of very large, even multi-billion-dollar projects; but we’re still knowledge workers. We’re still individuals who have to be competent at what we do in order to deliver a safe result for people.

    And third, I liked the idea, the image of the cottage industry, the artisan working at home as I am now, and delivering goods and services that other people can use wherever they are. And indeed, you might be home or you might be on your mobile phone listening to this.

    So I liked all three of those things. I thought, yes, that’s what I’m about. That’s what I believe in and want to do. And if that sounds good to you, too, then please check out The Safety Artisan, where I provide #safety #engineering #training.

    Meet the Author

    Learn safety engineering with me, an industry professional with 25 years of experience, I have:

    •Worked on aircraft, ships, submarines, ATMS, trains, and software;

    •Tiny programs to some of the biggest (Eurofighter, Future Submarine);

    •In the UK and Australia, on US and European programs;

    •Taught safety to hundreds of people in the classroom, and thousands online;

    •Presented on safety topics at several international conferences.

    Learn more about me here.

  • System Safety Risk Assessment

    System Safety Risk Assessment

    Learn about System Safety Risk Assessment with The Safety Artisan.

    In this module, we’re going to look at how we deal with the complexity of the real world. We do a formal risk analysis because real-world scenarios are complex. The Analysis helps us to understand what we need to do to keep people safe. Usually, we have some moral and legal obligation to do it as well. We need to do it well to protect people and prevent harm to people.

    You Will Learn to:

    • Explain what a system safety approach is and does; and
    • Define what a risk analysis program is; 
    System Safety Risk Analysis.

    Topics: System Safety Risk Assessment

    Aim: How do we deal with real-world complexity?

    • What is System Safety?
    • The Need for Process;
    • A Realistic, Useful, Powerful process:
      • Context, Communication & Consultation; and
      • Monitoring & Review, Risk Treatment.
    • Required Risk Reduction.

    Transcript: System Safety Risk Assessment

    Click here for the Transcript on System Safety Risk Assessment

    In this module, on System Safety Risk Assessment, we’re going to look at how we deal with the complexity of the real world. We do a formal risk analysis because real-world scenarios are complex. The Analysis helps us to understand what we need to do to keep people safe. Usually, we have some moral and legal obligation to do it as well. We need to do it well to protect people and prevent harm to people.

    What is System Safety?

    To start with, here’s a little definition of system safety. System safety is the application of engineering and management principles, criteria, and techniques to achieve acceptable risk within a wider context. This wider context is operational effectiveness – We want our system to do something. That’s why we’re buying it or making it. The system has got to be suitable for its use. We’ve got some time and cost constraints and we’ve got a life cycle. We can imagine we are developing something from concept, from cradle to grave.

    And what are we developing? We’re developing a system. An organization of hardware, (or software) material, facilities, people, data and services. All these pieces will perform a designated function within the system. The system will work within a stated or defined operating environment. It will work with the intention to produce specified results.

    We’ve got three things there. We’ve got a system. We’ve got the operating environment within which it works- or designed to work. And we have the thing that it’s supposed to produce; its function or its application. Why did we buy it, or make, it in the first place? What’s it supposed to do? What benefits is it supposed to bring humankind? What does it mean in the context of the big picture?

    That’s what a system is. I’m not going to elaborate on systems theory or anything like that. That’s a whole big subject on its own. But we’re talking about something complex. We’re not talking about a toaster. It’s not consumer goods. It’s something complicated that operates in the real world. And as I say, we need to understand those three things – system, environment, purpose – to work out Safety.

    We Need A Process

    We’ve sorted our context. How is all this going to happen? We need a process. In the standard that we’re going to look at in the next module, we have an eight-element process. As you can see there, we start with documenting our approach. Then we identify and document hazards. We document everything according to the standard so forget that.

    We assess risk. We plan how we’re going to mitigate the risk. We identify risk mitigation measures or controls as there are often known. Then we apply those controls to reduce risk. We verify and confirm that the risk reduction that we have achieved, or that we believe we will achieve. And then we got to get somebody to accept that risk. In other words, to say that it is an acceptable level of risk. That we can put up with this level of risk in exchange for the benefits that the system is going to give us. Finally, we need to manage risk through the entire lifecycle of the system until we finally get rid of it.

    The key point about this is whatever process we follow, we need to approach it with rigor. We stick to a systematic process. We take a structured and rigorous approach to looking at our system.

    And as you can see there from the arrows, every step in the eight-element sequence flows into the next step. Each step supports and enables the following steps. We document the results as we go. However, even this example is a little bit too simple.

    A More Realistic Process

    So, let’s get a more realistic process. What we’ve got here are the same things we’ve had before. We’ve established the context at the beginning. Next, there’s risk assessment. Risk assessment consists of risk identification, risk analysis, and risk evaluation. It asks ‘Where are we?’ in relation to a yardstick or framework that categorizes risk. The category determines whether a risk is acceptable or not.

    After determining whether the risk is acceptable or not, we may need to apply some risk treatment. Risk Treatment will reduce the risk further. By then we should have the risk down to an acceptable level.

    So, that’s the straight-through process, once through. In the real world, we may have to go around this path several times. Having treated the risk over a period of time, we need to monitor and review it. We need to make sure that the risk turns out, in reality, to be what we estimated it to be. Or at least no worse. If it turns out to be better- Well, that’s great!

    And on that monitoring and review cycle, maybe we even need to go back because the context has changed. These changes could include using the system to do something it was not designed to do. Or modifying the system to operate in a wider variety of environments. Whatever it might be, the context has changed. So, we need to look again at the risk assessment and go round that loop again.

    And while we’re doing all that, we need to communicate with other people. These other people include end-users, stakeholders, other people who have safety responsibilities. We need to communicate with the people who we have to work with. And we have to consult people. We may have to consult workers. We may have to consult the public, people that we put at risk, other duty holders who hold a duty to manage risk. That’s our cycle. That’s more realistic. In my experience as a safety engineer, this is much more realistic. A once-through process often doesn’t cut it.

    Required Risk Reduction

    We’re doing all this to drive risk down to an acceptable level. Well, what do we mean by that? Well, there are several different ways that we can do this, and I’ve got to illustrate it here. On the left-hand side of the slide, we have what’s usually known as the ALARP triangle. It’s this thing that looks a bit like a carrot where the width of the triangle indicates the amount of risk. So, at the top of the triangle, we’ve got lots of risks. And if you’re in the UK or Australia where I live, this is the way it’s done. So there will be some level of risk that is intolerable. Then if the risk isn’t intolerable, we can only tolerate it or accept it if it is ALARP or SFARP. And ALARP means that we’ve reduced the risk as low as reasonably practicable. And SFARP means so far as is reasonably practicable. Essentially, they’re the same thing – reasonably practical.

    We must ensure that we have applied all reasonably practicable risk reduction measures. And once we’ve done so, if we’re in this tolerable or acceptable region, then we can live with the risk. The law allows us to do that.

    That’s how it’s done in the UK and Australia. But in other jurisdictions, like the USA, you might need to use a different approach. A risk matrix approach as we can see on the right-hand side of this slide. This particular risk matrix is from the standard we’re about to look at. And we could take that and say, ‘We’ve determined what the risk is. There is no absolute limit on how much risk we can accept. But the higher the risk, the more senior level of sign-off from management we need’. In effect, you are prioritizing the risk. So you only bring the worst risks to the attention of senior management. You are asking  ‘Will you accept this? Or are you prepared to spend the money? Or will you restrict the operational system to reduce the risk?’. This is good because it makes people with authority consider risks. They are responsible and need to make meaningful decisions.

    In short, different approaches are legal in different jurisdictions.

    Summary of Module

    In Module Two, we’ve asked ourselves, ‘How can we deal with real-world complexity?’. And one way that’s developed to do that is System Safety. System Safety is where we take a systematic approach to safety. This approach applies to both the system itself – the product – and the process of System Safety.

    We address product and process. We need that rigorous process to give us confidence that what we’ve done is good enough. We have a realistic, useful and powerful process that enables us to put things in context. It helps us to communicate with everyone we need to, to consult with those that we have a duty to consult with. And also, we put around the basic risk process, this monitoring and review. And of course, we analyze risk to reduce it to acceptable levels. So we’ve got to treat the risk or reduce it or control it in some way to get it to those acceptable levels. In the end, it’s all about getting that required risk reduction to work. That reduction makes the risk acceptable to expose human beings to, for the benefit that it will give us.

    This is Module 2 of SSRAP

    This is Module 2 from the System Safety Risk Assessment Program (SSRAP) Course. Risk Analysis Programs – Design a System Safety Program for any system in any application. You can access the full course here.

    You can find more introductory lessons at Start Here.

  • Risk Analysis Programs

    Risk Analysis Programs

    Risk Analysis Programs – Design a System Safety Program for any system in any application.

    Introduction to the System Safety Risk Analysis Programs Course.

    Risk Analysis Programs: Learning Objectives

    At the end of this course, you will be able to:

    • Describe fundamental risk concepts;
    • Explain what a system safety approach is and does;
    • Define what a risk analysis program is;
    • List the hazard analysis tasks that make up a program;
    • Select tasks to meet your needs;
    • Design a tailored analysis program for any application; and
    • Know how to get more information and resources.

    Risk Analysis Programs: Transcript

    Introduction

    Hello and welcome to this course on Systems Safety Risk Analysis Programs. I’m Simon Di Nucci, The Safety Artisan, and I’ve been a safety engineer and consultant for over 20 years.

    I’ve worked on a wide range of safety programs doing risk analysis on all kinds of things. Ships, planes, trains, air traffic management systems, software systems, you name it. I’ve worked in the U.K., in Australia, and on many systems from the US.

    I’ve also trained hundreds of people on safety. And now I’ve
    got the opportunity to share some of that knowledge with you online.

    So, what are the benefits of this course?

    First of all, you will learn about basic concepts. About system safety, what it is, and what it does. You will know how to apply a risk analysis program to a very complex system and how to manage that complexity. So, that’s what you’ll know.

    At the end of the course, you will also be able to do things that you might not have been able to do before. You will be able to take the elements of a risk analysis program and the different tasks. Select the right tasks and form a program to suit your application, whatever it might be.

    You might have a full, high-risk bespoke development system. Or take a commercial system off the shelf and do something new with it. You might be taking a product and using it in a new application or a new location. Whatever it might be, you will learn how to tailor your risk analysis program.

    This program will give you the analyses you need, to meet your legal and regulatory requirements. Once you’ve learned how to do this, you can apply it to almost any system.

    Finally, you will feel confident doing this. I will be interpreting the terminology used in the tasks and applying my experience. So, instead of reading the standard and being unsure of your interpretation, you can be sure of what you need to do. Also, I will show you how you can get good results and avoid some of the pitfalls.

    So, these are the three benefits of the program:

    • You will know what to do.
    • You will be able to do things, and …
    • You’ll be feeling confident doing the tasks.

    At the end of the course, I will also show you where to find further resources. There are free resources to choose from. But there are also paid resources for those who want to take their studies to the next level. I hope you enjoy the course.

    Get the supporting safety analysis courses here.

    Meet the Author

    Learn safety engineering with me, an industry professional with 25 years of experience, I have:

    •Worked on aircraft, ships, submarines, ATMS, trains, and software;

    •Tiny programs to some of the biggest (Eurofighter, Future Submarine);

    •In the UK and Australia, on US and European programs;

    •Taught safety to hundreds of people in the classroom, and thousands online;

    •Presented on safety topics at several international conferences.

  • Welcome to the New Website!

    Welcome to the New Website!

    Welcome to the New Website! It has been professionally redesigned to provide a much better user experience by the awesome Sam Jusaitis. My thanks to him for doing such a great job.

    The Main Pages

    You can now browse through the main pages, which give you all the content that you might need, in the order that you choose it:

    • Topics. This page showcases the main safety topics that I cover, so far they are:
      • Start Here. Mostly free introductory videos for those new to safety;
      • Safety Analysis. A complete and in-depth suite of lessons on this subject; and
      • Work Health & Safety. All you need to know about Australian WHS legislation and practice.
    • About. Some information about The Safety Artisan – why you would choose safety tuition from me.
    • Connect. Here, you can sign up for free email newsletters, subscribe to our YouTube Channel, and follow us on social media.
    • Frequently Asked Questions. The most commonly Googled questions are here, with links to posts and videos that answer them.
    • Checkout. You’ll get there if you purchase any of the downloadable videos and content – but there’s plenty of free stuff too!

    Welcome to the New Website Logo

    Sam also designed the new logo, which reminds some people of the human eye. It was actually derived from the shapes of various warning signs, as shown below. Clever, eh?

    Meet the Author

    Learn safety engineering with me, an industry professional with 25 years of experience, I have:

    •Worked on aircraft, ships, submarines, ATMS, trains, and software;

    •Tiny programs to some of the biggest (Eurofighter, Future Submarine);

    •In the UK and Australia, on US and European programs;

    •Taught safety to hundreds of people in the classroom, and thousands online;

    •Presented on safety topics at several international conferences.

  • Consultation, Cooperation & Coordination CoP

    Consultation, Cooperation & Coordination CoP

    In this 30-minute session, we look at the Consultation, Cooperation & Coordination Code of Practice (CC&C CoP). We cover the Commonwealth and Model versions of the CoP, appendices & a summary of detailed requirements; and further commentary. This CoP is one of the two that are generally applicable.

    This is the three-minute demo of the full, 30-minute video.

    Consultation, Cooperation & Coordination CoP: Topics

    • CC&C in the Federal or Commonwealth CoP;
    • Extra CC&C in the Model CoP;
    • (Watch out for Jurisdiction);
    • Further commentary; and
    • Where to get more information.

    Consultation, Cooperation & Coordination CoP: Transcript

    Click Here for the Transcript

    Consultation, Cooperation & Coordination CoP

    Hello, everyone, and welcome to The Safety Artisan. I’m Simon and today we’re going to be talking about a very useful subject, which is Codes of Practice. And one Code of Practice in particular, which is the Code of Practice for Consultation, Cooperation and Coordination. And it doesn’t sound like the most exciting subject, I’ll admit, but this is one of only two Codes of Practice that you must be aware of if operating in Australia, or exporting to Australia, or importing stuff to Australia, whatever it might be. The other Code of Practice that you must be aware of is the Risk Management Code of Practice. There are a lot more Code of Practices than these two, but they don’t always apply. So, I mean if you’re not doing anything to do with asbestos, you don’t have to worry about what it says in the Asbestos Code of Practice. But this one you do because it applies to everything.

    Topics for this Session

    And I’ve used this Code of Practice to help clients and to do particular things and help everybody understand what we have to do, and it’s very useful. And in this session, I will be explaining how to get the best out of this Code of Practice and, at the end, where to get more information. So, I hope you’ll find that useful. So we’re going to be talking about the – I’m just going to call it the C, C & C CoP for short because it’s a dreadful mouthful, isn’t it? We’re going to be looking at the federal or Commonwealth Code of Practice and then we’re going to look at some extras in the Model Code of Practice. So just to explain that briefly, the Model Code of Practice is on the Safe Work Australia website, and that is the Model from which all other CoPs are developed. However, Safe Work Australia is not a regulator. So individual regulators and the example I’m using is the Commonwealth one- or Comcare, as it’s known- they have chosen to edit the Model CoP and change it and remove quite a bit of material. Now, why they chose to do that, I do not know. So, you have to be careful which jurisdiction you’re operating in, in Australia. If you are in a Commonwealth workplace, then you need to apply the Commonwealth or the federal version of WHS, including this CoP. And if you’re in a state or territory workplace, or a commercial workplace in a state or territory, you need to apply the relevant one there. And just to complicate matters, Western Australia has not yet introduced WHS and Victoria has no plans to do so. So, of course, in Australia, we like to make life simple for ourselves, don’t we? Oh no, we don’t!

    So after I’ve gone through some basics of what’s in the CoP, because you’ll see there’s an awful lot of material in there that I’m not going to talk about. I produced some commentary that I think you will find helpful and where to get more information, as I promised. So, let’s get on with it!

    When to Consult

    So, first of all- and you’ll notice that I’m only including those bits really that say when you must do something. So, this is quoting Section 49 of the WHS Act, which says that if you’re conducting a business or some kind of undertaking- so it’s not just a commercial business, but anything- you must consult with your workers when identifying hazards and assessing risks, making decisions about how you’re going to control those risks, making decisions about the adequacy of facilities for welfare, proposing changes that affect health and safety, and making decisions about procedures for consulting with workers, providing information and training, and so on and so forth. So, there’s a whole raft of things that you have to consult your workers on. So, this is all workplace so far. Now, in my role as a safety consultant, I’m often working with people who are introducing they’re buying bits of kit, or designing or importing bits of kit, and there is no work yet, so there’s no workers. But we always try and get a representative of the end-user involved because that really does help you do good quality safety work and avoid- to be honest- wasting time and money on things that are theoretically possible or theoretically sound problematic but in reality, it just doesn’t arise for whatever reason. So, I really do recommend getting those end-user representatives involved.

    Effective Consultation

    And if we go on to Section 48- for some reason, the cop quotes these things in reverse order- to be effective in consultation, we require information to be shared. Workers have got to have a reasonable opportunity to express their views. They’ve got to have a reasonable opportunity to contribute to decisions. Their views must be taken into account and they must be advised of the outcomes of consultation. So, all good common-sense stuff, I would think. Nothing controversial about this and that- to be honest- that’s a feature of CoPs. They tell you to do things that you think, “Yeah, I really ought to be doing that!”.

    Consultation Procedures

    Continuing with the countdown, we’re on to Section 47. Consultation procedures, again more basic common sense. If you’ve agreed to procedures for consultation, you must follow those procedures. It’s not rocket science, is it, folks? Let’s move on.

    Sections 16 & 46

    OK, now this is a bit more interesting, I think. This is getting into the real guts of this Code of Practice because where consultation, cooperation and coordination really come into play is where you’ve got multiple stakeholders, multiple duty holders- that is to say, those with a duty to protect the health and safety of people. Where multiple stakeholders, duty holders, have to get together and work together in order to come up with a solution. So the law says- Section 16 says where more than one person has a duty for the same thing, for the same matter, each person retains that responsibility. You cannot wriggle out of your responsibility just because you only control a bit over here and not over here. So, the two duty holders who have control here and here, they have to work together. The law says so. And so this is really the guts of this Code of Practice. And they must work together to discharge their duties to the extent to which they can. And the extent to which you can is the extent to which you influence and control the matter. So, WHS law is very big about control. If you have control of the bit, you’ve got to do your bit and you must work with people who have control of other things. You might be designing or buying a piece of kit. Other people might control the workplace. There might be another group of people who represent the operators, and then another group who represent the maintainers, and so on and so forth. They’ve all got to be involved if they’re relevant to managing risk. And of course, as risk in WHS is cradle to grave, then pretty much everyone is involved.

    So, Section 46, and in these situations where you have got multiple duty holders, each person with a duty must, so far as is reasonably practicable, consult, cooperate and coordinate with all other persons. And I’m going to do a session quite soon on so far as is reasonably practicable, or SOFARP, and in it, I will tell you that SOFARP is an objective test and the law sets objective expectations for what a reasonable person would do. So, you can’t just say, “Well, I’ll decide what is reasonable or not reasonable.”. The law has already done it for you and there’s guidance out there to help you so follow it. So, we will do something on that guidance, about what is reasonable and what is reasonably practicable. But we’ve got to work with each other SOFARP. For the greater good! Sorry, that’s a quote from one of my favourite comedy films, by the way.

    CoP Appendices

    So, appendices to the CoP. If we look at the appendices in the federal or Commonwealth CoP, there are only three. So, they’ve got some examples of arrangements. They’ve got a consultation checklist, and they’ve got an appendix on C, C and C activities, which is all good. That’s all good stuff. In addition, if you go back to the Model Code of Practice, you will find that there’s also a glossary. Yes, they’ve got the consultation checklist. And then in Appendix E, you’ve got a summary of all the consultation requirements in the WHS regulations, which is really useful. So even if in the CoP that applies to you, your version of the CoP doesn’t have the appendix, I would recommend going and having a look in the Model CoP. And if you’re not aware what you got, if you’ve got a high-risk business, then you’re going to find some extra requirements in the regulations. So, I would go and have a look at Appendix E if you’re doing anything that could kill one or more people. So, if you’re dealing with more serious risks, then I would go and have a look at that just to- as a good lead in to the regulations. If you already know the regulations backwards, then great, you don’t need to bother. But there are over 600 regulations in WHS, so it’s always worth checking up to make sure you haven’t missed anything.

    Extras in the Model CoP

    We’ve kind of started already, but now we’ve really started we’re going to talk about the extras in the Model Code of Practice.

    Further Duties of PCBUs

    In the modal Code of Practice, we get a reminder that designers, manufacturers, importers and suppliers have got safety responsibilities to ensure, so far as is reasonably practicable, that the plant’s substance or structure that they are designing, etc, etc, is without risks to health and safety. And they’ve got a duty to carry out testing and analysis and to provide specific safety-related information about plant or substance. So there’s a good reminder in there that we all, wherever we are in the supply chain, we’ve all got these responsibilities. And to assist in meeting these duties, the WHS regulations require manufacturers to consult with designers, importers to consult with designers and manufacturers, and whoever commissions construction work to consult with the designer of the structure, for example. There’s a lot of useful extra pointers in the Model Code of Practice, which may not be in the version that, technically speaking/strictly speaking, you have to follow. So, worth a look.

    Officers (of the PCBU)

    And then there’s also a reminder to officers of the business or undertaking. Basically, officers says- for example, company directors, those kinds of people, have a duty to exercise due diligence. And you have to go look at due diligence to see what that is. There are basically six bullet points in the act that describe due diligence. Again, it’s all good common-sense stuff. There’s nothing esoteric in there or objectionable. And that due diligence includes taking reasonable steps to ensure that you’ve got appropriate processes for complying with the duty to consult as well as to duty- with workers sorry, as well as consulting, cooperating and coordinating with other duty holders. And there’s further guidance on what’s an officer in that interpretive guideline and under Section 27 of the law.

    Principal Contractors

    And then here is one I picked out. I’ve not got all of the requirements, but here’s a useful one. There’s a particular regulation, number 309, that says if you’re doing construction work the principal contractor for a construction project has a specific duty under WHS regulations to document in their WHS management plan the arrangements for consultation, cooperation and coordination. Now that’s not unique, as we’ve just seen, to construction, but there is a specific requirement in there for a principal contractor. And WHS assumes a particular structure where you’ve got a prime contractor, or a principal contractor, who is leading the construction for the customer. So, have a look at that. There’s also a CoP on the construction of structures so if you’re in that game you’ll find that useful too.

    Major Hazard Facilities

    And then I’ve got one slide on major hazard facilities. Now, a major hazard facility, strictly speaking, is a facility where you’ve got enough of a dangerous chemical- and it might be flammable, it might be toxic, it might be explosive, whatever it is. There’s a whole list of chemicals in the regulations and it says if you’ve got so many tons of this or that, you’ve hit the threshold and you are operating a major hazard facility. There’s a whole raft of extra regulations that apply to MHFs. And it says, for example, regulation 552 requires a major facility- sorry, a major hazard facilities safety case outline- so a safety case report by another name- to include a description of the consultation with workers that’s been undertaken in the preparation of the safety case. Again, you’ve got a very specific requirement to consult with workers and to document it. Which, interestingly enough, generally, you don’t have a duty to do that. It’s not mandatory to document consultation. It’s recommended. It’s a good idea but you don’t, strictly speaking, have to do it unless you’re operating an MHF. And as it says there, there’s a whole bunch of regulations that cover consultation about MHFs. But as I said, if you look at Appendix E of the Model Code of Practice, it’s got them all listed, which is very helpful.

    Detailed Requirements

    A quick word about detailed requirements. Every Code of Practice contains detailed requirements that follow this formula. So, there are three words that indicate a legal requirement that must be complied with. And those three words are ‘must’, ‘requires’- or variations on that word-, and ‘mandatory’. So, any instances of those words- Probably not always, because they occasionally you come across a usage of ‘must’ or ‘requires’ where you go “Actually, that’s just an English use-“ (if you know what I mean)-  “That’s just an English use of those words! It’s not really indicating a mandatory requirement”. But most of them do. So, in the Commonwealth Code of Practice, we have 41 instances of ‘must’. So, you’ve got to comply with those. You have 46 instances of ‘require’ and you’ve got to comply with those by law. Now, interestingly, in the Model Code of Practice, those numbers go up to 71 and 58, respectively. So, there’re a lot more requirements in the Model Code of Practice. So, again, do make sure you’ve got the right Code of Practice that’s been issued by the regulator for your jurisdiction. Because otherwise you might miss something you need to comply with or you might be complying with something that, strictly speaking, you don’t have to. Although, of course, it’s not a bad thing to do that but you don’t have to.

    Then there’s the use of the word ‘should’, which is a recommended course of action, and ‘may’, suggests something that is optional. And again, in the Commonwealth Code of Practice, there are 62 instances of ‘should’ and 86 of ‘may’. Although I note that one of those instances of may, at least one, refers to the month of May when that Code of Practice was published. So, you’ve got to go through and make sure that they are relevant. And then it’s slightly more in the Model Code of Practice. It’s 66 and 90, respectively. But the difference is not so great for the mandatory stuff. Now as I’ve said before, and in the risk management Code of Practice, my advice to you is you must comply with ‘musts’ and ‘required’s. ‘Should’ is recommendation so I would suggest complying with that unless you’ve got a good reason not to. In which case, I would document the fact that you’ve got a good reason not to and why you’re not going to. And then ‘may’ is optional. You can do it if you want to and you can record the fact that you’ve considered those things and reject them if you want to but they are only options. So, I think there’s- effectively we’ve got three tiers here. We’ve got ‘must comply’, ‘recommended’, and ‘you can do this if you think it’s a good idea’.

    And so the comment at the bottom, CoPs are not huge documents that typically a few tens of pages long. They will repay careful reading because you do have to comply with quite a lot of stuff that’s in there and that’s very clearly signposted, by the way. And also, of course, this particular Code of Practice is very useful for safety management plans. If you’ve got to write a safety management plan and you want to know what you have to include in it, then look in this Code of Practice and look in the Risk Management Code of Practice and make sure you include everything that is mandatory or ‘must’ or ‘requires’ and look at all the other stuff as well. And why not? If the copyright permits you to do so, which it usually does- not always, but usually. If the copyright permits you to do so and just copy and paste the stuff into your plan and then you know that you’ve got what you need. Then you can change the wording if you need to. But it will save you a lot of bother if you’ve got to write a safety management plan. It’ll help you to make sure you’ve got everything you need to and it will save you a lot of effort. So, I recommend that I’ve done that myself.

    Commentary #1

    I think I’ve just got a couple of slides of commentary. It’s worth reiterating that Codes of Practice are for all Australian industry. Whether it be a sole trader like myself operating out of our study or their garage or something, or whether it be a small operation- a family-run garage or shop, or whether it be the biggest corporation in Australia, whoever that is- if you’re running a major mining operation. So, Codes of Practice provide minimum requirements. These are the things that you must comply with. In high-risk industries, you’re probably going to have to do a lot more. And they do have a workplace application. So, they are written for the workplace. They’re not really written for the designer, manufacturer, importer, supplier, etc. But nevertheless, it is very, very helpful if you are those people to look at the CoP in order to get an idea of what your customers have got to comply with and therefore what you’re going to have to supply.

    And as I’ve already said, CoP will repay careful reading because whilst they are guidance, they are really more than guidance. If you are ignorant of CoP and you don’t do what they say you are exposing yourself to prosecution. So, see my introduction to Codes of Practice where I talk about that. There are three reasons why you must be aware of Codes of Practice. And this is one of those two Codes of Practice that everyone must be aware of. The others- if you’re working with asbestos or welding or whatever it might be then there are specific Codes of Practice that you must be aware of for those activities. But this is one of those ones that applies to absolutely everybody, potentially. And as I’ve said before, the Model CoP has more detail than maybe some of the regulator-enforced Codes of Practice, which you will, I think, find helpful for higher risk applications. Whether legally you’ve got an MHF or not.

    Commentary #2

    And in fact, that’s my point in slide two. So, not everyone is required to have a formal safety management system for managing safety risk in a- while something is in service, while it’s being used. So, this CoP does not require us to have a formal safety management system, but it is required for major hazard facilities. It will be required for large and complex, say, defence systems and facilities and certain regulators do require you to have a safety management system. For example, if you’re operating offshore oil and gas platform, the NOPSEMA regulator requires you to have a formal SMS. As does the national rail regulator. And they’ll require you to follow CENELEC standards and all the other good stuff, depending on exactly what you’re doing. But they will require you to have a formal SMS and there will be others as well. So do check up with your regulator, some of whom are regionally or depending on where you are. Others, depending on whether it’s Commonwealth and others are depending on what kind of thing you do. If you’re in the rail industry or that these particular industries, I’m guessing you probably know already.

    But if you don’t or you’re thinking of importing stuff. If you’re based outside of Australia and you want to know how we do things, do look it up. Do look up the regulator and see what they require because it’s the regulator that has the final say. So, do look at standards of good practice and do consult the regulator. It’s perfectly OK to ring up the regulator and ask questions and get them to give you an answer. And a good regulator will work hard in order to achieve clarity and help you to comply and do all the right things. Now, if you don’t have specific requirements from a regulator or you’re just not sure, but you think you’re working in a high-risk area where you could kill one or more people. And by the way, high-risk plant includes stuff like amusement rides and things like that. So, it’s not necessarily, all sort of radiation and poisonous stuff and things. It can be all kinds of stuff.

    But if you’ve got the potential to really hurt lots of people, then I do recommend looking at the suite of guidance that is published for major hazard facilities which is excellent. And it will walk you through process, documentation- good things to do. So, if you work in those kinds of industries, do have a look at the MHF guidance because it’s really helpful. As I say, the regulator has the final say, but if you haven’t received any specific guidance I would suggest having a look at the MHF stuff. It’s on the Safe Work Australia website.

    Copyright & Attribution

    So just to let you know, I’ve quoted information from Safe Work Australia. I’ve also quoted information from the Commonwealth Register of Legislation. And I’ve done so in accordance with the requirements of the copyright license that those organisations impose on people who use their stuff, basically. So, I’ve got the statement there for the Federal Register of Legislation. If you go on the website- on SafetyArtisan.com, you’ll also find the relevant statement for Safe Work Australia or you can go to their website and look at the copyright statement and you will see that I complied with the requirements and been very careful to do so. As I said, you can go to the website and there’s more stuff there.

    For More…

    And if you want more information, then I heartily recommend that you subscribe to the Safety Artisan channel on YouTube, which is free. And if you do that, every time I issue a new free video- and I do short free versions of all the paid videos as well.- every time one comes up you will receive an email telling you that it’s come out and been released. So, I recommend subscribing.

    And for all other lessons and resources, there’s lots of stuff available, please go to www.safetyartisan.com. As you can see, it’s a secure site, so you should be nice and safe browsing there.

    End

    Well, that is the end of this session on what I have to say on the consultation, cooperation and coordination Code of Practice. But do you remember I haven’t given you all the information you do need to read the CoP still. But hopefully, my- this session will have equipped you to do so effectively and make the best use in the minimum time.

    So, all that remains for me to do is to say thank you very much for watching and supporting the Safety Artisan and I’ll see you next time. Goodbye.

    End: Consultation, Cooperation & Coordination

    Back to the WHS Topic Page.