Escolar Documentos
Profissional Documentos
Cultura Documentos
Erik Hollnagel Professor & Industrial Safety Chair MINES Paris e!h, C"C So#hia $nti#olis, %ran!e Professor II N N& rondhei', Nor(ay
Erik Hollnagel, 2010
E)'ail* erik+hollnagel,!r!+ens'#+fr
$!!ident analysis
"isk assess'ent
E.#laining and Predi!ting (hat understanding (hat has 'ay ha##en ha##ened /a!tual !auses0 /#ossi1le !onse2uen!es0 Ho( !an (e kno( (hat did go (rongEli'ination or redu!tion of attri1uted !auses Eli'ination or #re3ention of #otential risks Ho( !an (e #redi!t (hat 'ay go (rong-
In order to a!hie3e freedo' fro' risks, 'odels, !on!e#ts and 'ethods 'ust 1e !o'#ati1le, and 1e a1le to des!ri1e 4reality5 in an ade2uate fashion+
Erik Hollnagel, 2010
1670
2000
I "e3olution
I "e3olution
If a!!idents ha##en like this +++ Co'1inations of a!ti3e failures and latent !onditions+ Gook for ho( degraded 1arriers or defen!es !o'1ined (ith an a!ti3e /hu'an0 failure+
Gikelihood of (eakened defenses, !o'1inations Single failures !o'1ined (ith latent !onditions, leading to degradation of 1arriers and defen!es+
Erik Hollnagel, 2010
2006 16;1 $% <<: %ault tree analysis 16:6 I hree Mile 2009 "e3olution Island Colu'1ia
Erik Hollnagel, 2010
C I Maintenance o ersight O I
Aircraft design knowledge
Maintenance o ersight
O I
Aircraft design knowledge
Certification
R T
Inter al a!!ro als
Aircraft
P T
R C
High workload
C
Procedures
Aircraft design
O
Redundant design
&nd%!la( checking
O
Allowable end%!la(
R
Controlled stabili"er #o e#ent
R
Li#ited stabili"er #o e#ent
M echanics
T
&)ui!#ent High workload &'!ertise &'cessi e end%!la(
O I R P
Procedures Lubrication
Lubrication
R
G rease
$ackscrew re!lace#ent
Certification
R T
Inter al a!!ro als
Aircraft
P T
R C
High workload
C
Procedures
Aircraft design
O
Redundant design
&nd%!la( checking
O
Allowable end%!la(
R
Controlled stabili"er # o e#ent
R
Li# ited stabili"er # o e#ent
Mechanics
T
&)ui!#ent High workload &'!ertise &'cessi e end%!la(
O I R P
Procedures Lubrication
Lubrication
R
Grease
$ackscrew re!lace#ent
P
&'!ertise
R
&'!ertise
&ne.#e!ted !o'1inations /resonan!e0 of 3aria1ility of nor'al #erfor'an!e+ Syste's at risk are intra!ta1le rather than tra!ta1le+
&ne.#e!ted !o'1inations /resonan!e0 of 3aria1ility of nor'al #erfor'an!e+ he esta1lished assu'#tions therefore ha3e to 1e re3ised
Erik Hollnagel, 2010
%or'al, e.#li!it Standardised, 3alidated Mode of o#eration* Bell)defined Stru!tural sta1ility* High /#er'anent0 %un!tional sta1ility* High
&nkno(n, inferred Mostly unkno(n Mainly analogies S#e!ulati3e, un#ro3en Faguely defined Faria1le &sually relia1le
Progra''ati! Partly unkno(n Se'i)for'al, $d ho!, un#ro3en Goosely defined Se'i)sta1le Hood /lagging0+
Erik Hollnagel, 2010
Positi3e
Good luck
Neutral
Incidents Accidents
Near misses
Negati3e
Disasters
Fery lo(
Mishaps
Fery high Predi!ta1ility
Erik Hollnagel, 2010
Positi3e
Serendipity
Good luck
Neutral
Incidents Accidents
Near misses
Negati3e
Disasters
Fery lo(
*+.
Mishaps
*+*+,
Serendipity
Positi3e
Good luck
Neutral
Negati3e
Incidents
*+.
Mishaps
*+*+,
Bhy only look at (hat goes (rongSafety K "edu!ed nu'1er of ad3erse e3ents+ %o!us is on (hat goes (rong+ Gook for failures and 'alfun!tions+ ry to eli'inate !auses and i'#ro3e 1arriers+ Safety and !ore 1usiness !o'#ete for resour!es+ Gearning only uses a fra!tion of the data a3aila1le 10)< *K 1 failure in 10+000 e3ents Safety K $1ility to su!!eed under 3arying !onditions+ %o!us is on (hat goes right+ &se that to understand nor'al #erfor'an!e, to do 1etter and to 1e safer+ Safety and !ore 1usiness hel# ea!h other+ Gearning uses 'ost of the data a3aila1le
%ailures or su!!essesBhen so'ething goes (rong, e+g+, 1 e3ent out of 10+000 /10E)<0, hu'ans are assu'ed to 1e res#onsi1le in 80)60L of the !ases+ Bhen so'ething goes right, e+g+, 6+666 e3ents out of 10+000, are hu'ans also res#onsi1le in 80)60L of the !ases-
Bho or (hat are res#onsi1le for the re'aining 10)20LIn3estigation of failures is a!!e#ted as i'#ortant+
Bho or (hat are res#onsi1le for the re'aining 10)20LIn3estigation of su!!esses is rarely undertaken+
Erik Hollnagel, 2010
I'#ro3e resilien!e+
Many so!io)te!hni!al syste's are intra!ta1le+ he Su!!ess !onditions of (ork therefore ne3er !o'#letely 'at!h Perfor'an!e (hat has 1een s#e!ified or #res!ri1ed+ 3aria1ility Indi3iduals, grou#s, and organisations nor'ally %ailure adNust their #erfor'an!e to 'eet e.isting !onditions /resour!es, de'ands, !onfli!ts, interru#tions0+ Ee!ause resour!es /ti'e, 'an#o(er, infor'ation, et!+0 al(ays are finite, su!h adNust'ents (ill in3aria1ly 1e a##ro.i'ate rather than e.a!t+
Erik Hollnagel, 2010
Colle!ti3e /organisation0
Negati3e re#orting "edu!e redundan!y Meet C#rodu!tionD targets "edu!e unne!essary !ost ?ou1le)1ind "eNe!t !onfli!ting infor'ation
%or'al a!!ident in3estigations usually start (ith an assu'#tion that the o#erator 'ust ha3e failed, and if this attri1ution !an 1e 'ade, that is the end of serious in2uiry+ (Perrow (1984). Normal Accidents)
Erik Hollnagel, 2010
O T C
a.i to run(ay
P R
O T C
I T C P I
AGEQ $ C !learan!e
O I R P
N SE !on!lusion* +++ the #ro1a1le !ause of this a!!ident (as the flight !re('e'1ers5 failure to use a3aila1le !ues and aids +++
Erik Hollnagel, 2010
Con!lusions
"isk assess'ent 1ased on !ause)effe!t relations $!!idents e.#lained as a result of failures and 'alfun!tions $nalysis* $nalysis look for !auses that e.#lain the out!o'e Predi!tion* Predi!tion ?eter'ine ho( failures #ro#agate through syste' Cal!ulate failure #ro1a1ility Identify !ause)effe!t relations and !ause)effe!t !hains Model !o'1inations of a!ti3e and #assi3e /latent0 failures+ "isk assess'ent 1ased on fun!tional resonan!e $!!idents e.#lained as a result of fun!tional !ou#lings $nalysis* $nalysis look for fun!tional !ou#lings #resent in the situation Predi!tion* Predi!tion find #otential fun!tional !ou#lings for the task@a!ti3ity
T C
FAA
Maintenance o ersight
Certification
Aircraft
High workload
Aircraft design
Procedures
&nd%!la( checking
Redundant design
Allowable end%!la(
Mechanics
R
Li#ited stabili"er #o e#ent
&)ui!#ent
&'!ertise
High workload
&'cessi e end%!la(
Procedures
Lubrication
Lubrication
$ackscrew re!lace#ent
Grease
P
&'!ertise
?eter'ine ho( fun!tions are !ou#led ?eter'ine (hen #erfor'an!e 3aria1ility is likely ?eter'ine ho( 3aria1ility 'ay e.#ress itself
Erik Hollnagel, 2010
he #resent is unlike the #ast, and the future is unlike the #resent
Nor1ert Biener /167;0
Erik Hollnagel, 2010
$ny 2uestions-