MODULE 4 — ENGINEERS’ RESPONSIBILITY TOWARDS
SAFETY AND RISK (COMPLETE NOTES)
HM-EE401 | Every syllabus topic covered, in syllabus order
Syllabus line: The Concept of Safety – Safety and Risk – Types of Risks – Voluntary v/s Involuntary Risk –
Consequences – Risk Assessment – Accountability – Liability – Reversible Effects – Threshold Levels of Risk – Delayed
v/s Immediate Risk – Safety and the Engineer – Designing for Safety – Risk-Benefit Analysis – Accidents
1. THE CONCEPT OF SAFETY
Absolute safety — zero risk — is unattainable; every product and activity carries some risk. Hence safety is defined
relatively:
William W. Lowrance: “A thing is safe if its risks are judged to be acceptable.”
Safety therefore = acceptable risk, and judging acceptability combines facts (probability, magnitude of harm —
objective) with values (what individuals and society will tolerate — subjective);
Objective vs subjective safety: a thing may be safer than it feels (flying vs driving) or feel safer than it is (one’s
own driving) — perception and reality both matter to the engineer, because public acceptance depends on
perceived safety;
Safety judgments are relative to persons and contexts: a voltage safe for a trained lineman with PPE is lethal to
a child; “how safe is safe enough?” always asks: acceptable to whom, informed how, in exchange for what benefit?
2. SAFETY AND RISK
Risk is the potential that something unwanted and harmful may occur — expressed as:
Risk = Probability of occurrence × Severity (magnitude) of consequence
Safety and risk are inversely related: reducing risk raises safety;
Risk is inherent in engineering because engineering is experimentation with partial knowledge — new materials,
loads, environments, users;
The engineer’s task is not to promise zero risk (impossible) but to identify, quantify, reduce and honestly
communicate risk until it is acceptable — and to keep it there through the product’s life.
3. TYPES OF RISKS
Pair Meaning Examples
Voluntary vs Involuntary Chosen knowingly vs imposed without Smoking, biking vs industrial pollution,
consent contaminated water
Immediate vs Delayed Harm at once vs harm long after exposure Electric shock, explosion vs asbestos, low-
dose radiation
Known vs Unknown Quantified, understood hazards vs Grid fault levels vs long-term effects of a
uncertainties of new technology new chemical
On-the-job vs Public Risk to workers vs risk to society at large Lineman’s occupational risk vs consumers’
appliance risk
Reversible vs Irreversible Harm that heals/can be undone vs Temporary hearing loss vs death, genetic
permanent harm damage, extinction
Each pair changes what acceptability demands: involuntary, delayed, unknown, public and irreversible risks all
require stricter control than their opposites.
4. VOLUNTARY v/s INVOLUNTARY RISK
Basis Voluntary Risk Involuntary Risk
Meaning Knowingly and willingly accepted by the Imposed without the person’s knowledge
person or consent
Control Person chooses and partly controls No choice or control
exposure
Examples Smoking, mountaineering, motorbiking, Factory emissions over a town, unsafe
sky-diving water supply, nuclear fallout
Acceptability People tolerate roughly 1000× higher Even small involuntary risks provoke
voluntary risk (Chauncey Starr’s studies) public outrage
Engineer’s duty Honest information so the choice is Minimize strictly; seek the public’s
genuinely informed informed consent; fair distribution of risk
vs benefit
Key insight: the same statistical risk is judged completely differently depending on consent and control — which is
why plants near residential areas face (rightly) far stricter standards than adventure sports.
5. CONSEQUENCES
Assessing risk requires assessing consequences — the nature, magnitude and distribution of the harm if things go
wrong:
Magnitude: how many people, how severely — injury, death, property loss, environmental damage; a low-
probability/high-consequence event (dam burst, reactor meltdown) can outweigh frequent minor mishaps;
Who bears them: workers, users, bystanders, future generations? Justice demands that those bearing the risk
share the benefit and, where possible, consent;
Dread and catastrophe factor: society fears one accident killing 1000 far more than 1000 accidents killing one
each — catastrophic potential lowers acceptability disproportionately;
Secondary consequences: beyond direct harm — evacuation, unemployment, litigation, loss of public trust in the
technology (post-Chernobyl nuclear retreat);
Engineer’s duty: trace consequences imaginatively and honestly to their full extent (Bhopal’s designers should
have asked: what if MIC escapes over a sleeping city?), and design so that even failure has tolerable consequences
(safe exit).
6. RISK ASSESSMENT
Risk assessment is the systematic process of estimating and evaluating risk:
1. Hazard identification: what can go wrong? (checklists, past failures, HAZOP studies);
2. Probability estimation: how likely? — historical failure data, testing, fault-tree analysis (top event traced back
to combinations of component failures) and event-tree analysis (consequences traced forward from an initiating
fault);
3. Consequence estimation: how bad, to whom? (Topic 5);
4. Risk evaluation: compare estimated risk against acceptability criteria — standards, threshold limits, public
tolerance, risk-benefit balance;
5. Risk reduction: eliminate the hazard → guard against it → warn of it (in that order of preference);
6. Monitoring and review: risks change with wear, modification and use — assessment is continuous, not one-time.
Difficulties: scarce failure data for new designs; human error hard to quantify; testing to destruction is costly; and
the final “acceptable?” question is a value judgment, not a calculation.
7. ACCOUNTABILITY
Accountability is the moral readiness to answer for one’s decisions and their consequences — to explain, justify,
and submit one’s conduct to scrutiny, accepting blame where due.
Broader than law: an engineer is accountable for foreseeable harms even where no court convicts;
The accountability gap in organizations: large projects fragment work so that “everyone was responsible, so
no one was” — ethics rejects this: each engineer answers for their own contribution and for warnings not given;
Marks of the accountable engineer: signs only what they have verified, documents decisions, admits errors
promptly, never hides behind superiors’ orders (“I was told to” is an explanation, not an excuse, when public safety
was at stake).
8. LIABILITY
Liability is legal responsibility — the enforceable obligation to compensate for harm or face punishment.
Forms relevant to engineers: - Negligence liability: failing the standard of care a reasonable professional would
exercise (unchecked design → collapse); - Product liability: manufacturer’s responsibility for defective products
harming users; - Strict/absolute liability: for inherently hazardous activities, liability without proof of negligence
— Indian law after M.C. Mehta v. Union of India (1987, oleum gas leak) imposes absolute liability on hazardous
enterprises; - Criminal liability: culpable negligence causing death (Bhopal prosecutions).
Accountability vs liability: liability is the legal shadow of moral accountability; ethics demands accountability even
where liability can be legally evaded (blaming contractors, jurisdictional escapes) — the responsible engineer never
hides behind “not legally liable.”
9. REVERSIBLE EFFECTS
A reversible effect can be undone or healed once exposure stops — temporary hearing loss, minor pollution an
ecosystem absorbs, a recoverable financial loss;
An irreversible effect is permanent — death, genetic damage, species extinction, aquifer contamination, lost
glaciers;
Ethical weight: irreversibility multiplies moral seriousness — a reversible mistake teaches; an irreversible one
forecloses futures and victimizes those who never consented (future generations);
This grounds the precautionary principle: where an activity threatens serious irreversible harm, lack of full
scientific certainty is no excuse for delay in prevention (climate change, nuclear waste, biodiversity);
Design duty: prefer technologies whose failures are recoverable; build in reversibility (recall-ability, containment,
remediation plans) wherever possible.
10. THRESHOLD LEVELS OF RISK
The threshold level is the exposure level of a hazard below which no harmful effect occurs (or harm is negligible
and repairable) — the “safe dose” concept.
Examples: permissible limits of pollutants (CPCB norms), occupational noise limits (90 dB/8 hr), radiation dose
limits (AERB), safe touch-voltage and let-go current levels in electrical safety, TLVs for workplace chemicals;
Standards bodies (BIS, WHO, OSHA, AERB) codify thresholds from toxicological and epidemiological data;
Design rule: keep exposures well below threshold with a margin of safety — thresholds carry uncertainty and
individuals vary (children, patients, sensitized workers);
Caution: for some agents — many carcinogens, ionizing radiation under the linear no-threshold model — no truly
safe threshold may exist; there the rule becomes ALARA: As Low As Reasonably Achievable.
11. DELAYED v/s IMMEDIATE RISK
Basis Delayed Risk Immediate Risk
Meaning Harmful effect appears long after Harmful effect appears at once
exposure
Perception Underestimated, ignored (“it hasn’t hurt Feared more; triggers instant caution
me yet”)
Examples Smoking → cancer decades later; asbestos; Electric shock, machine accident,
low-level radiation; groundwater structural collapse, gas explosion
contamination
Cause-tracing Hard — victims may never link harm to Obvious cause; clear liability
source; liability diffuse
Engineer’s duty Long-term testing, lifecycle analysis, Guards, interlocks, alarms, fail-safe
exposure monitoring, honest warning of design, emergency systems
future effects
Ethical trap: because delayed harms are invisible today, cost pressure tempts organizations to discount them —
knowingly doing so (tobacco-industry style) is among the gravest professional wrongs.
12. SAFETY AND THE ENGINEER
The engineer stands in a special relation to safety:
1. Paramountcy: every major code (NSPE Canon 1, IEEE) makes public safety, health and welfare the engineer’s
first obligation — above employer, client, self;
2. Competence and vigilance: know the standards; keep current; check and re-check; assume Murphy’s law in
design;
3. Honest communication: report hazards up the line in writing; never certify what has not been verified; inform
users of residual risks and correct operation;
4. Resisting pressure: cost and schedule never justify shipping known unsafe products — the Challenger’s lesson;
escalate, refuse, and as a last resort blow the whistle;
5. The engineer’s own safety: occupational safety (training, PPE, safe procedures) is simultaneously the engineer’s
right as an employee and duty as a supervisor of others;
6. Whole-life responsibility: safety duties run through design, construction, operation, maintenance and even
decommissioning — an engineer’s signature follows the structure for its lifetime.
13. DESIGNING FOR SAFETY
Safety must be built into the design, not patched on later. The methodology:
1. Define the problem including safety specifications — codes, standards, worst-case environments and misuse;
2. Identify hazards and analyze risks at the drawing-board stage (fault trees, HAZOP, FMEA);
3. Inherent safety first: eliminate the hazard where possible (substitute the toxic solvent; use extra-low voltage) —
the safest hazard is the absent one;
4. Margins/factors of safety: design strength comfortably above expected worst loads to absorb uncertainty in
materials, loads and workmanship;
5. Fail-safe design: on failure the system moves to a safe state — fuses and circuit breakers, dead-man’s handle,
spring-closed valves, brakes that engage on air loss;
6. Redundancy: duplicate critical components/paths (dual brake circuits, backup power for hospitals, parallel
protection relays);
7. Guards, interlocks, alarms, emergency stops — protect against residual and human-error risks;
8. Testing: prototypes tested under and beyond worst-case conditions; quality control in production;
9. Warnings, manuals and training for hazards that cannot be designed out;
10. Safe exit: even when everything fails, people must be able to escape — lifeboats, fire exits, containment,
evacuation plans;
11. Monitor in service — feedback, inspection, recall and repair close the loop.
14. RISK-BENEFIT ANALYSIS (RBA)
RBA is the systematic weighing of a project’s or product’s risks against its benefits to decide whether it is worth
undertaking: is the product worth the risk it creates?
Method: identify risks (probability × severity, in injuries/deaths/losses) → identify benefits (lives saved, economic and
social gains) → express both, where possible, in comparable terms → proceed only if benefits clearly outweigh risks
and residual risk is acceptable.
Conditions for ethical RBA: 1. Fair distribution: those who bear the risks should share the benefits (a plant
risking a village must benefit that village) — otherwise the analysis justifies exploitation; 2. Informed consent of
risk-bearers wherever feasible; 3. Honest, complete accounting — no hiding delayed or diffuse harms; 4. Both risks
and benefits are estimates and value-laden: pricing a human life or an ecosystem is ethically fraught — RBA guides
judgment, it does not replace it; 5. Explore the alternative that gets the benefit at lower risk before accepting the
risk analyzed. (Related: cost-benefit analysis compares money costs to benefits; RBA specifically foregrounds harm
probabilities.)
15. ACCIDENTS
An accident is an unintended, unforeseen event causing harm. Studying their types shows where responsibility lies:
1. Procedural accidents: caused by human error or violation of procedures — wrong operation, skipped
checklist, ignored alarm (many road and industrial accidents). Remedy: training, discipline, human-factors design,
supervision;
2. Engineered accidents: caused by flaws in design or materials — under-designed structures, defective
components, untested assumptions (Titanic’s brittle steel and inadequate lifeboats; hyatt Regency walkway design
change). Remedy: better design, testing, margins, review;
3. Systemic accidents: arise from the complex, tightly-coupled interaction of many components and
organizations, where no single error explains the whole (Charles Perrow’s “normal accidents”) — Bhopal and
Chernobyl combined design flaws, disabled safeties, poor maintenance, untrained staff and management failure.
Remedy: simplify and de-couple systems, defense-in-depth, safety culture across the whole organization.
Lessons: most accidents give warnings first (near-misses, small leaks, prior anomalies) — a reporting culture that
treats near-misses as free lessons prevents disasters; blaming the last operator alone usually hides deeper design and
management causes.
MODULE 4 — RAPID REVISION BOX
Topic One-line recall
Concept of safety Lowrance: “safe if risks judged acceptable”; objective vs
perceived safety
Safety & risk Risk = probability × severity; inverse relation; engineering =
experimentation
Types of risks Voluntary/Involuntary, Immediate/Delayed, Known/Unknown,
Job/Public, Reversible/Irreversible
Voluntary vs involuntary Consent & control decide acceptability; ~1000× tolerance gap
(Starr)
Consequences Magnitude, who bears them, dread factor, secondary effects; safe
exit
Risk assessment Identify → probability (fault/event trees) → consequence →
evaluate → reduce → monitor
Accountability Moral answerability; no hiding in the organizational crowd
Liability Legal responsibility: negligence, product, strict/absolute (M.C.
Mehta), criminal
Reversible effects Irreversibility multiplies seriousness → precautionary principle
Threshold levels Safe-dose limits (TLV, dB, dose); margins below; ALARA where
no threshold
Delayed vs immediate Later harms underestimated; honest lifecycle warning is duty
Safety & the engineer Paramountcy, vigilance, honest reporting, resisting pressure,
whole-life duty
Designing for safety Eliminate → margins → fail-safe → redundancy → guards → test →
warn → safe exit
Risk-benefit analysis Benefits must clearly outweigh risks, fairly distributed, honestly
counted
Accidents Procedural (human), Engineered (design), Systemic (complex
interaction — Perrow)
LIKELY QUESTIONS FROM THIS MODULE
1. Describe briefly about safety. [15M] [PYQ] appeared
2. Voluntary vs involuntary risk; delayed vs immediate risk; safety of an engineer. [5+5+5M] [PYQ] appeared
3. Relationship between safety-risk-cost-price. [5M] [PYQ] appeared (full answer in PYQ file, Paper 3 Q3)
4. Types of risks; risk-benefit analysis. [3+2/5M] [PYQ] appeared (old paper)
5. Distinguish accountability and liability. [5M]
6. Threshold levels of risk / reversible effects / precautionary principle. [5M]
7. Explain designing for safety. [5/15M]
8. Risk assessment — steps and difficulties (fault-tree/event-tree). [5/15M]
9. Types of accidents with examples (procedural, engineered, systemic). [5/15M]
10. Define safety in engineering ethics context. [1M] [PYQ] appeared