HAZARD IDENTIFICATION
(a)Hazard identification — General
(1)Hazard identification may include the following factors and processes:
(i)design factors, including equipment and task design;
(ii)procedures and operating practices, including the related documentation and checklists, and their validation under actual operating conditions;
(iii)communications, including the means, terminology and language;
(iv)personnel factors, such as company policies for recruitment, training, remuneration, and allocation of resources;
(v)organisational factors, such as the compatibility of production and safety goals, the allocation of resources, operating pressure, and the corporate safety culture;
(vi)work environment factors, such as ambient noise and vibration, temperature, lighting, and the availability of protective equipment and clothing;
(vii)regulatory oversight factors, including the applicability and enforceability of regulations, the certification of equipment, personnel, and procedures, and the adequacy of oversight;
(viii)defences, including factors such as the provision of adequate detection and warning systems, the error tolerance of equipment, and the resilience of equipment to errors and failures; and
(ix)human performance, restricted to medical conditions and physical limitations.
(2)For hazard identification, internal and external sources may be used.
(i)Internal sources:
(A)voluntary occurrence-reporting schemes;
(B)safety surveys;
(C)safety audits;
(D)normal operations monitoring schemes;
(E)trend analysis;
(F)feedback from training; and
(G)investigation of incidents and follow-up.
(ii)External sources:
(A)accident reports;
(B)State mandatory occurrence-reporting system; and
(C)State voluntary occurrence-reporting system.
(3)The methods used for hazard identification depend on the resources and constraints of each particular organisation, and on the size and complexity of its operations. Nevertheless, hazard identification, regardless of implementation, complexity and size, is part of the organisation’s safety documentation. In the context of mature safety management practices, hazard identification is a continuous, daily activity. It is an integral part of the organisation’s processes. There are three specific conditions under which special attention to hazard identification should be paid. These three conditions should trigger more in-depth and far-reaching hazard identification activities, and include:
(i)any time the organisation experiences an unexplained increase in safety-related events or regulatory infractions;
(ii)any time major operational changes are foreseen, including changes to key personnel or other major equipment or systems; and
(iii)before and during periods of significant organisational changes, including rapid growth or contraction, corporate mergers, acquisitions, or downsizing.
(4)For hazard identification, the following tools and techniques may be used:
(i)brainstorming, which is an unbounded but facilitated discussion with a group of experts;
(ii)the hazard and operability (HAZOP) study, which is a systematic and structured approach using parameter and deviation guidewords. This technique relies on a very detailed system description being available for study, and usually involves breaking down the system into well-defined subsystems and functional or process flows between subsystems. Each element of the system is then subject to discussion within a multidisciplinary group of experts against the various combinations of the guidewords and deviations;
(iii)checklists, which are lists of known hazards or hazard causes that have been derived from past experience. Past experience could be previous risk assessments, or similar systems, or operations, or from actual incidents that have occurred in the past. This technique involves the systematic use of an appropriate checklist, and the consideration of each item on the checklist for possible applicability to a particular system. Checklists are always validated for applicability prior to use;
(iv)the failure modes and effects analysis (FMEA), which is a ‘bottom-up’ technique used to consider ways in which the basic components of a system can fail to perform their design intent. This technique relies on a detailed system description, and considers the ways in which each subcomponent of the system could fail to meet its design intent, and what the consequences could be for the overall system. For each subcomponent of a system, the FMEA considers:
(A)all the potential ways that the component could fail;
(B)the effects that each of these failures would have on the system behaviour;
(C)the possible causes of the various failure modes; and
(D)how the failures might be mitigated within the system or its environment. The system level at which the analysis is applied can vary, and is determined by the level of detail of the system description used to support the analysis. Depending on the nature and complexity of the system, the analysis could be undertaken by an individual system expert, or by a team of system experts that act in group sessions.
(v)the structured what-if technique (SWIFT) is a simple and effective technique, alternative to the HAZOP study, and involves a multidisciplinary team of experts. It is a facilitated brainstorming group activity, but is typically carried out on a higherlevel system description, having fewer sub-elements than the HAZOP study and with a reduced set of prompts.
(5)Identified hazards are registered in a hazard log (hazard register). The nature and format of such a hazard log may vary from a simple list of hazards to a more sophisticated relational database linking hazards to mitigations, responsibilities, and actions. The following information is included in the hazard log:
(i)unique hazard reference number against each hazard;
(ii)hazard description;
(iii)indication of the potential causes of the hazard;
(iv)qualitative assessment of the possible outcomes and severities of the consequences arising from the hazard;
(v)qualitative assessment of the risk associated with the possible consequences of the hazard;
(vi)description of the existing risk controls for the hazard; description of additional actions that are required to reduce safety risks, as well as target date of their completion; and
(vii)indication of responsibilities in relation to the management of risk controls.
(6)Additionally, the following information may also be included in the hazard log:
(i)a quantitative assessment of the risk associated with the possible consequences of the hazard;
(ii)record of actual incidents or events related to the hazard, or its causes;
(iii)risk-tolerability statement;
(iv)statement of formal system-monitoring requirements;
(v)indication of how the hazard was identified;
(vi)hazard owner;
(vii)assumptions; and
(viii)third-party stakeholders.
(b)Hazard identification — Indicators
(1)Reactive (lagging) indicators: Metrics that measure events which have already occurred and that impact on safety performance. As reactive (lagging) indicators only reflect system failures, their use can only result in determining a reactive response. Although they do measure failure to control hazards, they do not normally reveal why the system failed, or if there are any latent hazards.
(2)Proactive (leading) indicators: Metrics that measure inputs to the safety system (either within an organisation, a sector, or across the total aviation system) to manage and improve safety performance. Proactive (leading) indicators indicate good safety practices being introduced, developed and adapted, which, by their inclusion, seek to establish a proactive safety environment that engenders continuous improvement. They provide useful information when accident and incident rates are low to identify latent hazards and potential threats, and consequent opportunities for improvement. There should always be a connection between a proactive indicator and the unwanted outcomes (or reactive indicators) that their monitoring is intended to warn against.
(3)Predictive indicators (precursor events): These metrics can be considered as indicators that do not manifest themselves in accidents or serious incidents. They indicate less severe system failures or ‘near misses’ which, when combined with other events, may lead to an accident or a serious incident. In a large organisation, a mature safety management system includes all these measures. Risk-management efforts, however, are targeted at proactive (leading) indicators and predictive indicators (precursor events).