HAZARD IDENTIFICATION
(a)Hazard identification — General
(1)Hazard identification may include the following factors and processes:
(i)design factors, including equipment and task design;
(ii)procedures and operating practices, including their documentation and checklists, and their validation under actual operating conditions;
(iii)communications, including means, terminology, and language;
(iv)personnel factors, such as company policies for recruitment, training, remuneration, and allocation of resources;
(v)organisational factors, such as the compatibility of production and safety goals, the allocation of resources, operating pressures, and the corporate safety culture;
(vi)work environment factors, such as ambient noise and vibration, temperature, lighting, and the availability of protective equipment and clothing;
(vii)regulatory oversight factors, including the applicability and enforceability of regulations, the certification of equipment, personnel, and procedures, and the adequacy of oversight;
(viii)defences, including such factors as the provision of adequate detection and warning systems, the error tolerance of equipment, and the resilience of equipment to errors and failures; and
(ix)human performance, restricted to medical conditions and physical limitations.
(2)Hazard identification may use internal and external sources.
(i)Internal sources:
(A)voluntary occurrence reporting schemes;
(B)safety surveys;
(C)safety audits;
(D)normal operations monitoring schemes;
(E)trend analysis;
(F)feedback from training; and
(G)investigation and follow-up of incidents
(ii)External sources:
(A)accident reports;
(B)state mandatory occurrence reporting system; and
(C)state voluntary reporting system.
(3)The methods used for hazard identification depends on the resources and constraints of each particular aerodrome operator, and on the size and the complexity of the operations. Nevertheless, hazard identification, regardless of implementation, complexity and size, is part of the aerodrome operator’s safety documentation. Under mature safety management practices, hazard identification is a continuous, on-going daily activity. It is an integral part of the aerodrome operator’s processes. There are three specific conditions under which special attention to hazard identification should be paid. These three conditions should trigger more in depth and far reaching hazard identification activities and include:
(i)any time that the aerodrome operator experiences an unexplained increase in safety related events or regulatory infractions;
(ii)any time major operational changes are foreseen, including changes to key personnel or other major equipment or systems; and
(iii)before and during periods of significant organisational change, including rapid growth or contraction, corporate mergers, acquisitions, or downsizing.
(4)Hazard identification may use the following tools and techniques:
(i)brainstorming which is an unbounded but facilitated discussion with a group of experts;
(ii)Hazard and Operability (HAZOP) Study which is a systematic and structured approach using parameter and deviation guidewords. This technique relies on a very detailed system description being available for study, and usually involves breaking down the system into well-defined subsystems and functional or process flows between subsystems. Each element of the system is then subject to discussion within a multidisciplinary group of experts, against the various combinations of the guidewords and deviations;
(iii)checklists, which are lists of known hazards or hazard causes that have been derived from past experience. The past experience could be previous risk assessments, or similar systems, or operations, or from actual incidents that have occurred in the past. The technique involves the systematic use of an appropriate checklist, and the consideration of each item on the checklist for possible applicability to a particular system. Checklists should always be validated for applicability prior to use;
(iv)Failure Modes and Effects Analysis (FMEA), which is a ‘bottom up’ technique, used to consider ways in which the basic components of a system can fail to perform their design intent. The technique relies on a detailed system description, and considers the ways in which each sub-component of the system could fail to meet its design intent, and what the consequences could be for the overall system. For each sub-component of a system the FMEA should consider:
(A)all the potential ways that the component could fail;
(B)the effects that each of these failures would have on the system behaviour;
(C)the possible causes of the various failure modes; and
(D)how the failures might be mitigated within the system or its environment. The system level at which the analysis is applied can vary, and is determined by the level of detail of the system description used to support the analysis. Depending on the nature and complexity of the system, the analysis could be undertaken by an individual system expert, or by a team of system experts acting in group sessions.
(v)the Structured What-If Technique (SWIFT) is a simple and effective alternative technique to HAZOP and involves a multidisciplinary team of experts. It is a facilitated brainstorming group activity, but is typically carried out on a higher level system description, having fewer sub-elements, than for HAZOP and with a reduced set of prompts.
(5)Identified hazards should be registered in a hazard log (hazard register). The nature and format of such a hazard log may vary from a simple list of hazards to a more sophisticated relational database linking hazards to mitigations, responsibilities, and actions. The following information should be included in the hazard log:
(i)unique hazard reference number against each hazard;
(ii)hazard description;
(iii)indication of the potential causes of the hazard;
(iv)qualitative assessment of the possible outcomes and severities of consequences arising from the hazard;
(v)qualitative assessment of the risk associated with the possible consequences of the hazard;
(vi)description of the existing risk controls for the hazard; description of additional actions that are required to reduce safety risks, as well as target date of completion; and
(vii)indication of responsibilities in relation to the management of risk controls.
(6)Additionally, the following information may also be included in the hazard log:
(i)a quantitative assessment of the risk associated with the possible consequences of the hazard;
(ii)record of actual incidents or events related to the hazard, or its causes;
(iii)risks tolerability statement;
(iv)statement of formal system monitoring requirements;
(v)indication of how the hazard was identified;
(vi)hazard owner;
(vii)assumptions; and
(viii)third party stakeholders.
(b)Hazard identification — Indicators
(1)Reactive (lagging) indicators: Metrics that measure events that have already occurred and that impact on safety performance. As reactive indicators only reflect system failures, their use can only result in determining a reactive response. Although they do measure failure to control hazards, they do not normally reveal why the system failed, or if there are any latent hazards.
(2)Proactive (leading) indicators: Metrics that measure inputs to the safety system (either within an organisation, a sector, or across the total aviation system) to manage and improve safety performance. Proactive indicators indicate good safety practices being introduced, developed, and adapted which by their inclusion seek to establish a proactive safety environment that engenders continuous improvement. They provide useful information when accident and incident rates are low to identify latent hazards and potential threats, and consequent opportunities for improvement. There should always be a connection between a proactive indicator and the unwanted outcomes (or reactive indicators) that their monitoring is intended to warn against.
(3)Predictive indicators (precursor events): These metrics can be considered as indicators that do not manifest themselves in accidents or serious incidents. They indicate less severe system failures or ‘near misses’ which when combined with other events may lead to an accident or serious incident. In a large organisation, a mature safety management system should include all of these measures. Risk management effort, however, should be targeted at leading indicators and precursor events.