16 May 2016
Independent Safety Assessment and System Safety Update zyxwvutsrqponmlkjihgfedcbaZYXWVUTSRQPONMLKJIHGFEDCBA
Andy Tankard, Principal M anager Safety Quality Environment & Risk
zyxwvutsrqponmlkjihgfedcbaZYXWVUTSRQPONMLKJIHGFEDCBA Independent - - PowerPoint PPT Presentation
zyxwvutsrqponmlkjihgfedcbaZYXWVUTSRQPONMLKJIHGFEDCBA Independent Safety Assessment and System Safety Update Andy Tankard, Principal M anager Safety Quality Environment & Risk 16 May 2016 AEO Assessments Tara Naseri, Senior System
16 May 2016
Independent Safety Assessment and System Safety Update zyxwvutsrqponmlkjihgfedcbaZYXWVUTSRQPONMLKJIHGFEDCBA
Andy Tankard, Principal M anager Safety Quality Environment & Risk
zyxwvutsrqponmlkjihgfedcbaZYXWVUTSRQPONMLKJIHGFEDCBA
AEO Assessments
Tara Naseri, Senior System Safety Specialist
Image courtesy of Transport for NSW
Safety Technical Forum | 2
Safety Technical Forum | 3
Feedback
from current AEO assessment and audit activities
Safety Assurance throughout the assets lifecycle
Safety Assurance as Work Health and Safety (WHS)
the requirements based on the scope
safety standards for new
awareness
ISA involvement and its relevancy
inconsistent deployed project evidence
Safety Technical Forum | 4
Feedback
from current AEO assessment and audit activities
across all industries
to change and adaptability
Independent Safety Assessment zyxwvutsrqponmlkjihgfedcbaZYXWVUTSRQPONMLKJIHGFEDCBA
Richard Adams, Manager Safety & R isk Assurance
Safety Technical Forum | 5
Safety Technical Forum | 6
Asset Safety Assurance
Now an established technique in asset safety assurance A number of large projects are now actively under assessment or in the process
engaging ISAs Technical note issued in June 2015 so TfNSW can engage an ISA Currently no ISAs appointed in planning phase of projects – an area for future improvement Anecdotal evidence that ISA is driving improved rigor in the safety assurance of assets
Safety Technical Forum | 7
ISA AEOs
Currently three ISA AEOS Three currently under assessment Existing requirements duplicate a number of standard AEO requirements Too many ISA AEO requirements Revised set of requirements later this year with significant consolidation
Safety Technical Forum | 8
Risk Tolerability
TfNSW published internally risk tolerability criteria for all transport modes in 2015 Currently these are not applied in projects – need for guidance on how they should be applied is under development Quantified Risk Analysis (QRA) is now used extensively to support safety assurance and decision making. Has many benefits but also many drawbacks. Guide to Risk Tolerability and QRA will be published later in the year
Safety Technical Forum | 9
System Safety for New or Altered Assets
TS20001 will be updated in coming months to be non-mode specific Aligning with ASA moving to incorporate all transport modes Hazard Management remains an area of
Management is planned but likely later than TS20001 and Risk Tolerability
Guest speaker zyxwvutsrqponmlkjihgfedcbaZYXWVUTSRQPONMLKJIHGFEDCBA
Charles-Andre Bellini, Systems Assurance, Atkins Australia
Safety Technical Forum | 10
Safety Technical Forum | 11
Hazard Management zyxwvutsrqponmlkjihgfedcbaZYXWVUTSRQPONMLKJIHGFEDCBA
Richard Adams, Manager Safety and Risk Assurance
Safety Technical Forum | 12
May 2016
Safety Technical Forum | 13
Contents
Hazard Management
projects
Safety Technical Forum | 14
zyxwvutsrqponmlkjihgfedcbaZYXWVUTSRQPONMLKJIHGFEDCBA
Hazard Management in System Safety
TS20001 – System Safety for New or Altered Assets ‘System Safety The concurrent application of a systems based approach to safety engineering and of a risk management strategy covering the identification and analysis of hazards and the elimination, control or management of those hazards through out the life cycle of a system or asset’ NASA ‘A disciplined, systematic approach to the analysis of risks resulting from hazards that can effect humans, the environment and mission assets’
Safety Technical Forum | 15
zyxwvutsrqponmlkjihgfedcbaZYXWVUTSRQPONMLKJIHGFEDCBA
Hazard Management in System Safety
Hazard Management or Safety Risk Management is at the core of System Safety Safe Work Australia ‘Safe design means the integration of control measures early in the design process to eliminate or, if this is not reasonably practicable, minimise risk to health and safety throughout the lifecycle of the plant being designed’
Safety Technical Forum | 16
zyxwvutsrqponmlkjihgfedcbaZYXWVUTSRQPONMLKJIHGFEDCBA
Hazard Management in System Safety
Legislative duties to ensure safety SFAIRP necessitate safety risk management Key element of a safety argument is compliance with safety requirements – this can only be achieved through sound hazard management International good practice through international standards require hazard analysis as part of Safety Assurance e.g. EN50126, European Common Safety Method, DEF-STAN 00-56 ONRSR Guidance on SFAIRP – key is the reasonable level of knowledge
Safety Technical Forum | 17
Definitions
Hazard
physical situation or state of a system,
initiating event, that may lead to an accident (DEF-STAN 00-56)
condition that could lead to an accident (EN50126-2) Safety
from unacceptable risk
harm (EN50126) Risk
and incidents resulting in harm (caused by a hazard) and the degree of severity
harm (EN50126-2) Accident
cause harm (DEF-STAN 00-56)
Safety Technical Forum | 18
Current Issues in Hazard Management
Combining and confusing system hazards with project risks, construction risks and work health safety risks
in a System Assurance context is about safety risks that may arise in the operations and maintenance phase
transitional – they have minimal impact on the safety and integrity
e
health safety risks are very important but are also transitional
Safety Technical Forum | 19
Current Issues in Hazard Management
Too many hazards at too lower level
hundreds
entries – there should be tens even for complex systems
at such a detailed level they do not represent safety requirements
between causes and accidents / consequences
Safety Technical Forum | 20
Current Issues in Hazard Management
Absence of traceability
the centre
for all hazard management issues, safety requirements and V&V evidence
assurance artifact that provides ability to trace to all assurance evidence
how safety issues have been dealt with during a project – must link to the design and its records
Safety Technical Forum | 21
Current Issues in Hazard Management
Lack
maintained journal / records
change
a living document through the whole lifecycle. Changes through the lifecycle reflect the safety decisions made and are thus key assurance evidence
each hazard has been analysed through the design process. It is also an artifact of the requirements definition process
audit trail of hazards considered and the rationale for each hazard’s closure. Records the the decisions at reaching a demonstrable SFAIRP position
Safety Technical Forum | 22
Hazard Management and Risk Management
ISO31000 is the established international standard for Risk Management Hazard Management is essentially safety risk management. There are subtle differences
aimed at Enterprise Risk Management – managing risks and opportunities in an organisational environment
is a form
intrinsic to Safety Engineering
are similar but the recording and managing of hazards and controls take a different form – system safety and hazard management are engineering activities
Safety Technical Forum | 23
Hazard Logs versus Risk Registers
A Hazard Log is a form of Risk Register but a Risk Register is not necessarily a Hazard Log Risk Register Hazard Log
Includes all risks under consideration Includes all identified hazards (safety) of a system Documents all treatment and controls for risks Details all controls for hazards and links them to system safety requirements – applies hierarchy
Is a business management tool Is a Safety Engineering tool Assesses risk against criteria Assesses safety risk against safety criteria Provides SFAIRP justification Provides basis for auditing and management of controls and treatments Provides traceability to all verification and validation evidence Includes a journal Records the rationale for safety related design decisions
Safety Technical Forum | 24
Integration
into Design
Safety Technical Forum | 25
Integration
into Design
Hazard Analysis must inform and lead the design to the safest outcome reasonably practicable
requirements
evolves to represent design
engineers and designers collaborate around feasibility
risk elimination and control
all changes and design decisions
Safety Technical Forum | 26
Hazard Levels
Safety Technical Forum | 27
Hazard Levels – Bow Tie Representation
Safety Technical Forum | 28
Hazard Management in Complex Changes
Safety Technical Forum | 29
Hazard Management in Complex Changes
Safety Technical Forum | 30
Features of good Hazard Management
program of diverse hazard identification activities
complete and understood
assurance evidence
entire operational life – reflects why the system is as it is
Safety Technical Forum | 31
Features of good Hazard Management
Safety Technical Forum | 32
Features
Hazard Log
identifies all identified hazards at the same and appropriate level, i.e. system boundary
cause – hazard –
V&V evidence – design – as built system – safety assurance evidence
consequences and controls for all hazards
all operational modes and degraded mode
Hierarchy
Controls
a journal
a SFAIRP demonstration
why the asset / system is at it is (not just a representation
the hazards associated with the final design solution)
a living artefact spanning the entire asset lifecycle
– provides links to validation evidence as it becomes available
through the lifecyle
Safety Technical Forum | 33
Features of a good Hazard Log – Traceability
zyxwvutsrqponmlkjihgfedcbaZYXWVUTSRQPONMLKJIHGFEDCBA
Safety Technical Forum | 34
Safety Technical Forum | 35