HAZARD IDENTIFICATION
(a)Completeness of hazard identification In order to achieve completeness in the identification of hazards, it might be beneficial to aggregate hazards and to formulate them in a more abstract way, e.g. at the service level. This might in turn have drawbacks when analysing and evaluating the risk of the hazards. The appropriate level of detail in the set of hazards and their formulation, therefore, depends on the change and the way the safety assessment is executed. Only credible hazards need to be identified. A credible hazard is one that has a material effect on the risk assessment. A hazard will not be considered credible when it is either highly improbable that the hazard will occur or that the accident trajectories it initiates will materialise. In other words, a hazard need not be considered if it can be shown that it induces an insignificant risk.
(b)Sources of hazards
(1)Hazards introduced by failures or nominal operations of the ATM/ANS functional systems may include the following factors and processes:
(i)design factors, including equipment, procedural and task design;
(ii)operating practices, including the application of procedures under actual operating conditions and the unwritten ways of operating;
(iii)communications, including means, terminology, order, timing and language and including human–human, human–machine and machine–machine communications;
(iv)installation issues;
(v)equipment and infrastructure, including failures, outages, error tolerances, nuisance alerts, defect defence systems and delays; and
(vi)human performance, including restrictions due to fatigue and medical conditions, and physical limitations, when considered relevant to the change assessment.
(2)Hazards introduced in the context in which the ATM/ANS functional system operates may include the following factors and processes:
(i)wrong, insufficient or delayed information and inadequate services delivered by third parties;
(ii)personnel factors, including working conditions, company policies for and actual practice of recruitment, training and allocation of resources, when considered relevant to the change;
(iii)organisational factors, including the incompatibility of production and safety goals, the allocation of resources, operating pressures and the safety culture;
(iv)work environment factors such as ambient noise, temperature, lighting, annoyance, ergonomics and the quality of man–machine interfaces; and
(v)external threats such as fire, electromagnetic interference and sources of distraction, when considered relevant to the change.
(3)The hazards introduced in the context in which the ATM/ANS services are delivered may include the following factors and processes:
(i)errors, failures, non-compliance and misunderstandings between the airborne and ground domains;
(ii)traffic complexity, including traffic growth, fleet mix and different types of traffic, when considered relevant to the change;
(iii)wrong, insufficient or delayed information delivered by third parties;
(iv)inadequate service provisioning by third parties; and
(v)external physical factors, including terrain, weather phenomena, volcanoes and animal behaviour, when considered relevant to the change.
(c)Methods to identify hazards
(1)The air traffic services provider may use a combination of tools and techniques, including functional analysis, what if techniques, brainstorming sessions, expert judgement, literature search (including accident and incident reports), queries of accident and incident databases in order to identify hazards.
(2)The air traffic services provider needs to make sure that the method is appropriate for the change and produces (either individually or in combination) a valid (necessary and sufficient) set of hazards. This may be aided by drawing up a list of the functions associated with part of the functional system being changed. The air traffic services provider needs to make sure their personnel that use these techniques are appropriately trained to apply these methods and techniques.