49
What Makes a Task Safety Critical?
failures. Although developed with the intention of being applied to operational barrier elements, the roadmap can in principle be used for any safety critical task categorized as either Type B or Type C actions. However, for the purpose of ranking
the criticality of Type A actions, the definitions of consequence and dependency ( in
particular) would have to be significantly altered. As made famous by James Reason
( 1997), the “ Swiss Cheese” model of accident causation explains how most, if not all,
major accidents involve latent failures.
A case could be made that safety critical task and barrier management approaches
are not necessarily the most suitable concepts for managing risks associated with
Type A actions. Such actions are typically plentiful, but at the same time well hidden
inside tasks and operations with less than obvious criticality. Most systems nowadays are well defended by use of multiple layers of safeguards, such as interlocks.
Spotting critical details from the surface may therefore prove to be difficult. For the
same reasons, they would not only be resource demanding to identify and screen but
also f ollow-up in case they would fall under similar requirements as ( for example)
the PSA expects for operational barrier elements, which can be considered too strict
and comprehensive for such tasks. It is also possible that a safety critical task analysis
of such tasks would result in diminishing returns. The author has been involved in
performing detailed human error analysis of tasks identified as causes of hazardous
events logged during a HAZOP study. As it turned out, the causes mainly consisted
of Type A actions such as someone having left a valve in wrong position or failed to
reinstate an interlock after doing maintenance. These were often single actions and
commonly isolated from the overall goal of the task ( i.e. low on complexity). A great
deal of efforts was therefore spent analysing parts of the overall task which had little
or no risk attached to it.
It is argued here that other alternative methods may be more suitable for targeting Type A actions, both in terms of analysis and following up with improvements
in design, procedures and training. For example, most of the commonly used safety
studies and risk analysis methods can be applied in ways which allow systematic
considerations of human error and HF aspects. Techniques such as HAZID, HAZOP,
LOPA and failure mode, effect and criticality analysis ( FMECA) can all be used to
identify not only Type A and B actions as causes but also Type C actions as safeguards ( e.g. alarm responses). The same techniques also often include risk rankings
which will reveal the associated hazards degree of severity, e.g. by use of risk matrices or similar tools. This can be used to determine task criticality, without having
to do a separate screening covering all the safety critical tasks. Instead a criticality
ranking tool, such as the presented roadmap, could be used to assess the most critical
tasks. Following the argument above about Type A actions commonly being single
task steps detached from the overall operation, it would be particularly important to
consider the level of complexity. The results from such reviews could then be used to
apply basic HF principles for design of HMIs, local control panels, equipment layout,
etc., using simple- to-use tools such as checklists.
During operations, some faith must be put into the management systems’ and
leaders’ ability to ensure high quality procedures and training, strong safety cultures
and systematic use of maintenance and reliability programs. Not all safety critical
tasks should require HF analyses to be properly managed.
What Makes a Task Safety Critical?
failures. Although developed with the intention of being applied to operational barrier elements, the roadmap can in principle be used for any safety critical task categorized as either Type B or Type C actions. However, for the purpose of ranking
the criticality of Type A actions, the definitions of consequence and dependency ( in
particular) would have to be significantly altered. As made famous by James Reason
( 1997), the “ Swiss Cheese” model of accident causation explains how most, if not all,
major accidents involve latent failures.
A case could be made that safety critical task and barrier management approaches
are not necessarily the most suitable concepts for managing risks associated with
Type A actions. Such actions are typically plentiful, but at the same time well hidden
inside tasks and operations with less than obvious criticality. Most systems nowadays are well defended by use of multiple layers of safeguards, such as interlocks.
Spotting critical details from the surface may therefore prove to be difficult. For the
same reasons, they would not only be resource demanding to identify and screen but
also f ollow-up in case they would fall under similar requirements as ( for example)
the PSA expects for operational barrier elements, which can be considered too strict
and comprehensive for such tasks. It is also possible that a safety critical task analysis
of such tasks would result in diminishing returns. The author has been involved in
performing detailed human error analysis of tasks identified as causes of hazardous
events logged during a HAZOP study. As it turned out, the causes mainly consisted
of Type A actions such as someone having left a valve in wrong position or failed to
reinstate an interlock after doing maintenance. These were often single actions and
commonly isolated from the overall goal of the task ( i.e. low on complexity). A great
deal of efforts was therefore spent analysing parts of the overall task which had little
or no risk attached to it.
It is argued here that other alternative methods may be more suitable for targeting Type A actions, both in terms of analysis and following up with improvements
in design, procedures and training. For example, most of the commonly used safety
studies and risk analysis methods can be applied in ways which allow systematic
considerations of human error and HF aspects. Techniques such as HAZID, HAZOP,
LOPA and failure mode, effect and criticality analysis ( FMECA) can all be used to
identify not only Type A and B actions as causes but also Type C actions as safeguards ( e.g. alarm responses). The same techniques also often include risk rankings
which will reveal the associated hazards degree of severity, e.g. by use of risk matrices or similar tools. This can be used to determine task criticality, without having
to do a separate screening covering all the safety critical tasks. Instead a criticality
ranking tool, such as the presented roadmap, could be used to assess the most critical
tasks. Following the argument above about Type A actions commonly being single
task steps detached from the overall operation, it would be particularly important to
consider the level of complexity. The results from such reviews could then be used to
apply basic HF principles for design of HMIs, local control panels, equipment layout,
etc., using simple- to-use tools such as checklists.
During operations, some faith must be put into the management systems’ and
leaders’ ability to ensure high quality procedures and training, strong safety cultures
and systematic use of maintenance and reliability programs. Not all safety critical
tasks should require HF analyses to be properly managed.
