The Regulator's Unhappy Lot 183
And they possess the investigative access and sanctions necessary to
enforce their decisions.
What regulators often lack, however, are the tools, training and the
resources to confront the all-important human and organizational
factors and to monitor the insidious accumulation of the latent con-
ditions that can subsequently combine to penetrate the system's
defences. The same also applies to the policy-makers. The past dec-
ade has seen isolated flurries of post-disaster legislation, when what
was needed were the statutory and regulatory structures necessary
to forestall future accidents rather than trying to prevent the pre-
vious ones.
This penultimate section draws heavily on the principles and tech-
niques presented in Chapters 6 and 7 in order to sketch out a model
for a regulatory process that, it is believed, could be effective in
limiting the occurrence of organizational accidents. The regulatory
model outlined below is shaped by three concerns:
• How can regulators deploy their limited resources in the most
cost-effective and targeted manner?
• How can regulators bring about the organizational reforms
necessary to achieve, and then sustain, optimum levels of 'safety
health' on the part of the complex well defended organizations
that they oversee?
• Since the absolute criteria for safe operation are rarely known
in advance, how can we design a regulatory process that will
enable the policy-maker, the regulator and the regulated all to
be integral parts of an effective learning cycle?
Figure 8.1 summarizes the basic elements of the regulatory process
as they might appear to front-line inspectors. Site visits generate
various indicators, such as instances of non-compliance or devi-
ations from safe working practices. These are the raw data of the
regulatory process. They could include, for example, badly main-
tained or unsuitable items of equipment, lack of briefing or drills, a
poor permit-to-work system or an unsatisfactory shift handover ar-
rangement. Each instance generates two kinds of action item: those
on the regulated organization to put them right (the dark octagons),
and those on the regulator to monitor their rectification and, if this is
not done satisfactorily, to impose some sanction (the white octa-
gons).
Figure 8.2 shows the next stage of model development. Here, the
basic elements of regulation have been extended to identify the up-
stream organizational and managerial (O & M) determinants of the
local instances. The precise nature of these O & M factors will vary
from industry to industry, but the assessed factors will always be less
184 Managing the Risks of Organizational Acciden ts
WSBBBBBfflBSffî
Local indicators,
instances, etc.
i^vl iTtyrH-rrlTi-iyij'i'.Hffi
Figure 8.1 The basic elements of the regulatory process
than the total number of possible factors (as discussed in Chapter 7).
In this case, only seven O & M factors (represented by the dark
rectangles) are considered in the analysis. If, for example, the regu-
lated organization were a small airline, the O M factors could
include crew factors, operational management, maintenance man-
agement, safety management, organizational structure, commercial
and operational pressures.
It is presumed that each instance is the product of different contri-
butions from each of the O & M factors. The circular nodes in the
lower half of the figure are points at which the regulator is required
to make an assessment of the impact of each O & M factor on that
particular instance. The regulator rates the relative contributions of
each O &: M factor to each instance on a five-point scale, where 1 -
very little influence and 5 = very considerable influence. The associ-
ated white rectangles are action items on the regulator to monitor
and, if necessary, to assist with any reforms.
These ratings are then summed over all the instances in that par-
ticular collection (either from a single inspection or several) to generate
an Organizational Factor Profile (see Figure 8.3). The purpose of the
profile is to indicate—to both the regulator and the regulated—which
of the various upstream factors is most in need of urgent reform. As
discussed in Chapter 7, we cannot expect any organization to deal
The Regulator's Unhappy Lot 185
Ratings of the relative contribution of
each organizational factor to each instance
Figure 8.2 Addition of the organizational and managerial (O &
M) factors to the basic elements of the regulatory
process
Whereas individual instances generate local repair
issues, the action items (on both the regulated and the
regulator) generated by the O & M factors require more
fundamental systemic reforms. The dark rectangles in
the upper half represent action items on the regulated
organization to reform a specific O & M factor. The asso-
ciated white rectangles are action items on the regulator
to monitor and, if necessary, to assist with these reforms
effectively with all of its problems at once. Later inspections will
yield further instances that, in turn, will generate more organiz-
ational factor profiles. A succession of these profiles will allow both
the regulator and the regulated to track the progress of remedial
efforts.
186 Managing the Risks of Organizational Acciden ts
Organizational factor profile showing
the relative cause for concern of each
organizational & management factor
Reform
issues
Priority
factors
Figure 8.3 An Organizational Factor Profile generated from the
ratings summed over all the instances
The purpose of the profile is to identify those two or
three factors most in need of reform by the organization
(and subsequent close monitoring by the regulator).
Finally, Figure 8.4 attempts to show how the regulatory process
modelled here could form part of a wider learning cycle, involving
legislators, regulators, and hazardous technologies. The systemic im-
provements generated by these focused organizational reforms will,
it is hoped, come to represent new standards of health and safety at
work. This could be incorporated into new legislation which, in turn,
would change the regulator's inspection and surveillance criteria—
and so on. It will be seen that the local repairs required of regulated
organizations become relegated to a subordinate loop. The main em-
phasis throughout is upon the continuing reform of the source factors
influencing a system's intrinsic resistance to its operational hazards.
The philosophy underlying this model is identical to that described
for Tripod-Delta (see Chapter 7). Local instances, such as unsafe acts,
are merely symptoms of the underlying organizational and manage-
The Regulator's Unhappy Lot 187
/ Organizational / \
Regulatory
factor
^ profiling y
Surveillance and Inspection and
monitoring surveillance
criteria /
Figure 8.4 The regulatory process integrated into a wider
learning cycle
rial pathology. Removing the instances one-by-one will not improve
the organization's safety health. That can only be achieved by curing
the source problems.
As noted in Chapter 6, maintaining safety, like life, is 'one damn
thing after another'. It is to be expected that while each targeted O &
M factor is being reformed others will be deteriorating. Nevertheless,
the model provides a principled way of tracking these changes and
of addressing the latest 'big problems' as each is revealed by the
prevailing pattern of local indicators.
The Regulator Deserves a Better Deal
Judging by the failures presented in the first part of the chapter,
regulatory authorities are not always able to prevent organizational
188 Managing the Risks of Organizational Acciden ts
accidents. But a closer examination shows that they, like other people
in the front-line of the safety war, are more often victims than vil-
lains. Yes, they make mistakes. But why should they be any different
from the rest of the human race? And, like other people, they do not
make their errors in isolation. As this chapter has tried to show, the
majority of regulatory shortcomings have their origins far upstream
from the individual inspector.
Given the current trend of searching for increasingly more remote
contributions to organizational accidents, it is inevitable that the regu-
lator's alleged deficiencies should be judged by those with 20:20
hindsight as making significant contributions to a major disaster. The
regulators' position vis â vis the affected organization means that
they are likely to attract blame from all directions. Standing as they
do on the organizational borders of all hazardous technologies, their
sphere of responsibility is bound to be implicated in a wide variety
of contributing factors. However, if regulators are to be other than
convenient scapegoats, they will have to be provided with the legis-
lation, the resources and the tools to do their jobs effectively. They
are potentially one of the most important defences against organiz-
ational accidents
Societies, just like the operators of hazardous systems, put produc-
tion before protection. As we have seen, safety legislation is enacted
in the aftermath of disasters, not before them. There is little or no
political kudos to be gained from bringing about a non-event, al-
though, in the long run, meeting this challenge successfully is likely
to be much more rewarding. Every society gets the disasters it de-
serves. Let's hope that, in the next millennium, the regulators are
seen to deserve something better than has so far been the case. Then,
perhaps, we will all be safer.
Notes
1 Report of the Presidential Commission on the Space Shuttle 'Challenger' Accident,
(Washington, DC: Government Printing Agency, 1986). See also the excellent
account by H.S.F. Cooper, 'A letter from the Space Center', The blew Yorker, 10
November 1987.
2 D. Vaughan, The Challenger Launch Decision, (Chicago: Chicago University Press,
1996). Malcolm Gladwell's article 'Blowup', The New Yorker, 22 January 1996
reviews this book and places it in its broader theoretical context. Her most
recent publication on this topic is 'The trickle-down effect: policy decisions,
risky work, and the Challenger tragedy', California Management Review, 39, 1997,
pp. 8 - 1 0 2 .
3 D. Vaughan, 'Autonomy, interdependence, and social control: NASA and the
Space Shuttle Challenger', Administrative Science Quarterly, 3 5 , 1 9 9 0 , pp. 225-33.
4 D. Fennell, Investigation into the King's Cross Underground Fire, (Department of
Transport, London: HMSO, 1988).
The Regulator's Unhappy Lot 189
5 Ibid., pp. 1 4 6 - 7 .
6 The Hon. Lord Cullen, Public Inquiry into the Piper Alpha Disaster, (Department
of Energy, London: HMSO, 1990).
7 Ibid., v o l . 1 , pp. 239-41.
8 Ibid., vol. l , p . 253.
9 Mr Justice V.P, Moshansky, Commission of Inquiry into the Air Ontario Crash at
Dryden, Ontario. Final Report, Vol. 1, (Ottawa: Ministry of Supply and Services,
1992), pp. 5 - 6 . See also the analysis by Captain Dan Maurino in D. Maurino et
al, Beyond Aviation Human Factors, (Aldershot: Avebury), 1995, pp. 5 7 - 8 5 .
10 Mr Justice VP. Moshansky, op. cit,, vol. 3., p. 914.
11 Ibid., vol. 1, p. xxviii.
12 Ibid., vol. 1, p. 7.
13 To avoid confusion with other civil aviation authorities, the Australian C A A
will be referred to as the A C A A in the text.
14 Bureau of Air Safety Investigation (BASI), Piper PA31-350 Chieftain Young NSW
11 June 1993, Investigation Report 9301743, (Canberra, ACT: Bureau of Air
Safety Investigation, 1994).
15 Editorial, The Sydney Morning Herald, 7 October 1994.
16 M. Riley, 'Police to investigate CAA link to Seaview', The Sydney Morning
Herald, 14 October 1994.
17 M. Taylor, 'Brereton strips C A A safety role', The Canberra Tunes, 13 October
1994.
18 Financial Review, 11 October 1994.
19 A. Bryant, 'Marginal safety: a special report', The Neu> York Times, 13 November
1995.
20 E. Pooley, 'Nuclear warriors', Time, 4 March 1996.
21 This can also be termed a 'pond', as in the UK, for example.
22 E. Pooley, op. cit.
23 The information relating to the decline in coupling accidents is taken from The
United States Law Week, 27 February 1996, 64, p. 4112. I am most grateful to
Michael Baram for sending it to me, although I am not sure that he would
entirely approve of the use to which I have put it.
24 D. Vaughan, 'Autonomy, interdependence, and social control: NASA and the
space shuttle Challenger', Administrative Science Quarterly, 35,1990, pp. 2 2 5 - 3 3 .
25 Ibid., p. 227.
26 M. Baram, 'The use of rules to achieve safety: introductory remarks', paper
presented to the Workshop on the Use of Rules to Achieve Safety, Bad Hom-
burg, Germany, 6 May 1993.
27 Ibid., p. 3.
28 S, Dawson, P Willman, M. Bamford and A. Clinton, Safety at Work: The Limits of
Self-Regulation, (Cambridge: Cambridge University Press, 1988).
29 The Hon, Lord Cullen, op. cit., p. 256.
30 The Hon. Lord Cullen, op. cit., p. 257.
31 The Hon. Lord Cullen, op. cit., p. 257.
32 Lord Robens, Safety and Health at Work, Report of the Committee 1970-72, Vol 1,
London: HMSO, 1972, p. 41.
33 The Hon. Lord Cullen, op. cit., vol. 1, p. 3.
34 Marine Safety Agency (MSA), Formal Safety Assessment of Shipping: Programme
Overview, (London: Marine Safety Agency, 15 September, 1995).
35 The Hon. Lord Cullen, op. cit., p. 277.
9 Engineering a Safety
Culture
The Scope of the Chapter
Few phrases occur more frequently in discussions about hazardous
technologies than safety culture. Few things are so sought after and
yet so little understood. However, should it be thought that the
current preoccupation with safety culture is just another passing fad,
consider the following facts. Commercial aviation is an industry that
possesses an unusual degree of uniformity worldwide. Airlines across
the globe fly much the same types of aircraft in comparable condi-
tions. Flight crews, air traffic controllers and maintenance engineers
are trained and licensed to very similar standards. Yet, in 1995, the
risks to passengers (the probability of becoming involved in an acci-
dent with at least one fatality) varied by a factor of 42 across the
world's air carriers, from a 1 in 260 000 chance of death or injury in
the worst cases to a 1 in 11 000 000 probability in the best cases. 1
While factors such as national and company resources will play their
part, there can be little doubt that differences in safety culture are
likely to contribute the lion's share to this enormous variation.
We first encountered the term 'safety culture' in Chapter 2 when
making the distinction between pathological, bureaucratic and gen-
erative organizations. It cropped up again in Chapter 6 in regard to
the motive forces that drive an organization towards a state of maxi-
mum resistance to its operational hazards. The present chapter focuses
mainly on three questions: What is an organizational culture? What
are the main ingredients of a safety culture? And, most importantly,
how can it be engineered? The term 'engineered' is deliberate. But it
is not meant in the traditional sense of developing more sophisti-
cated gadgetry. Rather, we will be discussing the application of social
engineering.
This book has sought to argue that most of the effective solutions
to human performance problems are more the province of the tech-
nical manager (and the regulator) than the psychologist since they
191
192 Managing the Risks of Organizational Acciden ts
concern the conditions under which people work rather than the
human condition itself. The main message of this chapter is that the
same general principle also applies to the acquisition of an effective
safety culture (hereafter, the phrase 'safety culture' will be taken to
mean an effective safety culture). Whereas national cultures arise
largely out of shared values, organizational cultures are shaped
mainly by shared practices (a claim that is developed in the next
section). And it is these practices that will be the focus of this
chapter.
Many people talk as if a safety culture can only be achieved through
some awesome transformation, akin to a religious experience. This
chapter takes the opposite view, arguing that a safety culture can be
socially engineered by identifying and fabricating its essential com-
ponents and then assembling them into a working whole. It is
undoubtedly true that a bad organizational accident can achieve
some dramatic conversions to the 'safety faith', but these are all too
often shortlived. A safety culture is not something that springs up
ready-made from the organizational equivalent of a near-death expe-
rience, rather it emerges gradually from the persistent and successful
application of practical and down-to-earth measures. There is noth-
ing mystical about it. Acquiring a safety culture is a process of
collective learning, like any other. Nor is it a single entity. It is made
up of a number of interacting elements, or ways of doing, thinking
and managing that have enhanced safety health as their natural
byproduct.
W h a t is an Organizational Culture?
To those with a 'hard' engineering background, many attempts to
describe the nature of organizational culture must seem to have the
definitional precision of a cloud. There is no standard definition, but
here is one that captures most of the essentials with the minimum of
fuss:
Shared values (what is important) and beliefs (how things work) that
interact with an organization's structures and control systems to pro-
duce behavioural norms (the way we do things around here). 2
Until the 1980s, 'culture' was a term applied more to nationalities
than to organizations. 'Organizational culture' became an essential
part of 'management speak' largely as the result of two widely read
books: Corporate Culture (by Terrence Deal and Allan Kennedy) 3 and
In Search of Excellence (by Thomas Peters and Robert Waterman), 4
both published in 1982.
Engineering a Safety Culture 193
The latter book introduced the notion of cultural strength, and ob-
served 'Without exception, the dominance and coherence of culture
proved to be an essential quality of the excellent companies'. 5 Fifteen
years later, there are some who might doubt this assertion (particu-
larly those laid off from the 'excellent' companies), but few would
argue with the idea that a strong culture is one in which all levels of
the organization share the same goals and values. To quote Peters
and Waterman again, 'In these [strong culture] companies, people
way down the line know what they are supposed to do in most
situations because the handful of guiding values is crystal clear'. 6
Organizational theorists have described a number of negative or
dysfunctional cultures. One such 'bad' culture is characterized by
what psychologists have termed learned helplessness, describing a con-
dition in which people learn that attempts to change their situation
are fruitless so that they simply give up trying: 'The energy and will
to resolve problems and attain goals drains away.' 7 Another counter-
productive organizational strategy is anxiety-avoidance. When such
an organization discovers a technique for reducing its collective
anxiety, it is likely to be repeated over and over again regardless of
its actual effectiveness.
The reason is that the learner will not willingly test the situation to
determine whether the cause of the anxiety is still operating. Thus all
rituals, patterns of thinking or feeling, and behaviours that may orig-
inally h a v e been motivated by a need to avoid a painful,
anxiety-provoking situation are going to be repeated, even if the causes
of the original pain are no longer acting, because the avoidance of
anxiety is, itself, positively reinforcing.8
Both learned helplessness and repetitive anxiety-avoidance are
likely to assist in driving the blame cycle, described in Chapter 7.
People feel helpless in the face of ever-present dangers and, while
the familiar reactions to incidents and events, such as 'write another
procedure' and 'blame and train/ may not actually make the system
more resistant to future organizational accidents, they at least serve
the anxiety-reducing function of being seen to do something—and
blaming those at the sharp end deflects blame from the organization
as a whole.
There is a controversy among social scientists as to whether a
culture is something an organization 'has' or whether it is something
an organization 'is'. The former view emphasizes management's
power to change culture through the introduction of new measures
and practices, while the latter sees culture as a global property that
emerges out of the values, beliefs and ideologies of the organiz-
ation's entire membership. The former approach is favoured by
194 Managing the Risks of Organizational Acciden ts
managers and management consultants, while the latter is preferred
by academics and social scientists. This chapter stands with the man-
agers and agrees with the organizational anthropologist, Geert
Hofstede, when he wrote:
On the basis of [our] research project, we propose that practices are
features an organization has. Because of the important role of practices
in organizational cultures, the ['has' approach] can be considered as
somewhat manageable. Changing collective values of adult people in
an intended direction is extremely difficult, if not impossible. Values
do change, but not according to someone's master plan. Collective
practices, however, depend on organizational characteristics like struc-
tures and systems, and can be influenced in more less predictable
ways by changing these.9
Although the idea of a safety culture has existed since 1980, it was
given an authoritative boost by the International Atomic Energy
Agency when they published a report in 1988, elaborating the con-
cept in detail. They defined safety culture as: '... that assembly of
characteristics and attitudes in organizations and individuals which
establishes that, as an overriding priority, nuclear plant safety issues
receive the attention warranted by their significance'. 10 Unfortunately,
this is something of a 'motherhood' statement specifying an ideal but
not the means to achieve it. A more useful definition, which is worth
quoting in full, has been given by the UK's Health and Safety Com-
mission in 1993:
The safety culture of an organization is the product of individual and
group values, attitudes, competencies, and patterns of behaviour that
determine the commitment to, and the style and proficiency of, an
organization's health and safety programmes. Organizations with a
positive safety culture are characterized by communications founded
on mutual trust, by shared perceptions of the importance of safety,
and by confidence in the efficacy of preventive measure. 11
While remaining in sympathy with this definition, this chapter em-
phasizes the critical importance of an effective safety information
system—the principal basis of an informed culture. It must be stressed
again that our primary concern in this book is not with traditional
health and safety measures that are directed, for the most part, at the
prevention of individual work accidents. Our focus is upon the limita-
tion of organizational accidents, and it is this that has shaped the
arguments set out below.
Engineering a Safety Culture 195
The Components of a Safety Culture
The main elements of a safety culture and their various interactions
are previewed below. Each subcomponent will be discussed more
fully in succeeding sections.
• As indicated in Chapter 6, an ideal safety culture is the engine
that continues to propel the system towards the goal of maxi-
mum safety health, regardless of the leadership's personality
or current commercial concerns. Such an ideal is hard to achieve
in the real world, but it is nonetheless a goal worth striving for.
• The power of this engine relies heavily upon a continuing re-
spect for the many entities that can penetrate and breach the
defences. In short, its power is derived from not forgetting to
be afraid.
• In the absence of bad outcomes, the best way—perhaps the
only way—to sustain a state of intelligent and respectful wari-
ness is to gather the right kinds of data. This means creating a
safety information system that collects, analyses and dissemi-
nates information from incidents and near-misses as well as
from regular proactive checks on the system's vital signs (see
Chapter 7). All of these activities can be said to make up an
informed culture—one in which those who manage and operate
the system have current knowledge about the human, tech-
nical, organizational and environmental factors that determine
the safety of the system as a whole. In most important respects,
an informed culture is a safety culture.
• Any safety information system depends crucially on the will-
ing participation of the workforce, the people in direct contact
with the hazards. To achieve this, it is necessary to engineer a
reporting culture—an organizational climate in which people
are prepared to report their errors and near-misses.
• An effective reporting culture depends, in turn, on how the
organization handles blame and punishment. A 'no-blame' cul-
ture is neither feasible nor desirable. A small proportion of
human unsafe acts are egregious (for example, substance abuse,
reckless non-compliance, sabotage and so on) and warrant sanc-
tions, severe ones in some cases. A blanket amnesty on all
unsafe acts would lack credibility in the eyes of the workforce.
More importantly, it would be seen to oppose natural justice.
What is needed is a just culture, an atmosphere of trust in which
people are encouraged, even rewarded, for providing essential
safety-related information—but in which they are also clear
about where the line must be drawn between acceptable and
unacceptable behaviour.
196 Managing the Risks of Organizational Acciden ts
• The evidence shows that high-reliability organizations—domain
leaders in health, safety and environmental issues—possess the
ability to reconfigure themselves in the face of high-tempo op-
erations or certain kinds of danger. A flexible culture takes a
number of forms, but in many cases it involves shifting from
the conventional hierarchical mode to a flatter professional struc-
ture, where control passes to task experts on the spot, and then
reverts back to the traditional bureaucratic mode once the emer-
gency has passed. Such adaptability is an essential feature of
the crisis-prepared organization and, as before, depends cru-
cially on respect—in this case, respect for the skills, experience
and abilities of the workforce and, most particularly, the first-
line supervisors. But respect must be earned, and this requires
a major training investment on the part of the organization.
• Finally, an organization must possess a learning culture—the
willingness and the competence to draw the right conclusions
from its safety information system, and the will to implement
major reforms when their need is indicated.
T h e preceding bullet points have identified four critical
subcomponents of a safety culture: a reporting culture, a. just culture, a
flexible culture and a learning culture. Together they interact to create
an informed culture which, for our purposes, equates with the term
'safety culture' as it applies to the limitation of organizational acci-
dents.
Engineering a Reporting Culture
On the face of it, persuading people to file critical incident and near-
miss reports is not an easy task, particularly when it may entail
divulging their own errors. Human reactions to making mistakes
take various forms, but frank confession does not usually come high
on the list. Even when such personal issues do not arise, potential
informants cannot always see the value in making reports, especially
if they are sceptical about the likelihood of management acting upon
the information. Is it worth the extra work when no good is likely to
come of it? Moreover, even when people are persuaded that writing
a sufficiently detailed account is justified and that some action will
be taken, there remains the overriding problem of trust. Will I get my
colleagues into trouble? Will I get into trouble?
There are some powerful disincentives to participating in a report-
ing scheme: extra work, scepticism, perhaps a natural desire to forget
that the incident ever happened, and—above all—lack of trust and,
with it, the fear of reprisals. Nonetheless, many highly effective re-
Engineering a Safety Culture 197
porting programmes do exist. What can we learn from them? How
have they engineered their success?
In what follows, we will briefly look at the 'social engineering'
details of two successful aviation reporting programmes, one operat-
ing at a national level and the other within a single airline. These are
NASA's Aviation Safety Reporting System (ASRS) and the British
Airways Safety Information System (BASIS). In this, we will rely
heavily on the work of two people—Dr Sheryl Chappell of NASA,
and Captain Mike O'Leary of British Airways 12 —each of whom has
been closely involved in the design and management of these pro-
grammes. Our purpose here is not to consider the programmes
themselves in any detail, but to abstract from them the 'best prac-
tices' for achieving a reporting culture. Throughout, we will
concentrate on the issue of how valid reporting may be promoted.
Although we are dealing exclusively with aviation reporting schemes,
the basic 'engineering' principles can be applied in any domain.
Indeed, reporting programmes in other domains—particularly in
medicine—are partly modelled on pioneering aviation schemes such
as critical incident reporting.
Examination of these successful programmes indicates that five
factors are important in determining both the quantity and the qual-
ity of incident reports. Some are essential in creating a climate of
trust, others are needed to motivate people to file reports. The factors
are:
• Indemnity against disciplinary proceedings—as far as it is prac-
ticable.
• Confidentiality or de-identification.
• The separation of the agency or department collecting and ana-
lysing the reports from those bodies with the authority to
institute disciplinary proceedings and impose sanctions.
• Rapid, useful, accessible and intelligible feedback to the report-
ing community.
• Ease of making the report.
The first three items are designed to foster a feeling of trust. O'Leary
and Chappell explain the need:
For any incident reporting programme to be effective in uncovering
the failures which contribute to an incident, it is paramount to earn
the trust of the reporters. This is even more important when there is a
candid disclosure of the reporter's own errors. Without such trust, the
report will be selective and will probably gloss over pivotal human
factors information. In the worst case—that in which potential report-
ers have no trust in the safety organization—there may be no report at
198 Managing the Risks of Organizational Acciden ts
all. Trust may not come quickly. Individuals may be hesitant to report
until the reporting system has proved that it is sensitive to reporters'
concerns. Trust is the most important foundation of a successful re-
porting programme, and it must be actively protected, even after many
years of successful operation. A single case of a reporter being disci-
plined as the result of a report could undermine trust and stop the
flow of useful reports. 13
The rationale for any reporting system—and a recurrent theme
throughout this book—is that valid feedback on the local and organ-
izational factors promoting errors and incidents is far more important
than assigning blame to individuals. To this end, it is essential to
protect informants and their colleagues as far as possible from disci-
plinary actions taken on the basis of their reports. But there will be
limits upon this indemnity. These limits are defined most clearly by
the Waiver of Disciplinary Action issued in relation to NASA's Avi-
ation Safety Reporting System. Below is an excerpt from the FAA
Advisory Circular (AC No. 00-46C) describing how the immunity
concept applies to pilots making incident reports.
The filing of a report with NASA concerning an incident or occurrence
involving a violation of the Act of the Federal Aviation Regulations is
considered by the FAA to be indicative of a constructive attitude. Such
an attitude will tend to prevent future violations. Accordingly,
although a finding of a violation may be made, neither a civil penalty
nor a certificate suspension will be imposed if:
• The violation was inadvertent and not deliberate;
• The violation did not involve a criminal offence, or accident or
... a lack of qualification or competency;
• The person has not been found in any prior FAA enforcement
action to have committed a violation of the Federal Aviation Act,
or of any regulation promulgated under the Act for a period of 5
years prior to the date of the occurrence; and
• The person proves that, within 10 days after the violation, he or
she completed and delivered or mailed a written report of the
incident or occurrence to NASA under ASRS. H
This formula appears to work. The ASRS reporting rate was high, even
at the outset. In the beginning, it averaged approximately 400 reports
per month. It now runs at around 650 reports per week and more than
2000 reports per month. In 1995 ASRS received over 30 000 reports.
BASIS has been extended over the years to cover a wide variety of
reporting schemes. All flight crew are required to report safety-re-
lated events using Air Safety Reports (ASRs). ASRs are not
anonymous. To encourage the filing of ASRs, British Airways Flight
Crew Order, No. 608 states:
Engineering a Safety Culture 199
It is not normally the policy of British Airways to institute disciplinary
proceedings in response to the reporting of any incident affecting air
safety. Only in rare circumstances where an employee has taken action
or risks which, in the Company's opinion, no reasonably prudent
employee with his/her training and experience would have taken,
will British Airways consider initiating such disciplinary action. 15
Again, the formula seems to work. Its success is suggested by two
statistics. First, the ASR filing rate more than trebled between its
inception in 1990 and 1995. Second, the combined number of reports
assigned to the severe and high risk categories has decreased by two-
thirds between the first six months of 1993 and the first half year of
1995. 16
Another important component of BASIS is the British Airways
Confidential Human Factors Reporting Programme, instituted in 1992.
While the ASRs provided good technical and procedural informa-
tion, a need was felt for an information channel that was more
sensitive to human factors issues. Each pilot filing an ASR is now
invited to complete a confidential human factors questionnaire relat-
ing to the incident. The return of the questionnaire is voluntary. The
following assurance was given by the senior manager in charge of
BA's Safety Services on the front page of the initial version:
I give an absolute assurance that any information you provide will be
treated confidentially by Safety Services and that this questionnaire
will be destroyed immediately after the data is processed. This pro-
gramme is accessible only to my Unit.
In its first year of operation, the human factors reporting programme
received 550 usable responses. 17 The issues raised in the reports are
communicated to management on a regular basis, but great care is
taken to separate the important safety issues from the incidents in
order to preserve the anonymity of the reports.
Another important input to BASIS comes from the Special Event
Search and Master Analysis (SESMA). This by-passes the need for
human reporting by monitoring directly the flight data recorders
(FDRs) of BA's various aircraft fleets, while at the same time guaran-
teeing the flight crews complete anonymity. The FDR for each flight
is scanned for events that are considered to lie outside safe norms.
All events are stored in a BASIS database and the more serious are
discussed at a monthly meeting of technical managers and the pilots'
union representatives. If the incident is considered to be sufficiently
serious, the union representative is required to discuss the matter
with the flight crew involved—while still withholding their identi-
ties from the management.
200 Managing the Risks of Organizational Acciden ts
When a report is received by NASA's ASRS staff it is processed in
the following manner, with great care being taken to preserve the
anonymity of the reporter.18
• An initial analysis screens out reports involving accidents, crimi-
nal behaviour, or those classified as 'no safety content'.
• The report is coded and the reporter de-identified. At this stage,
the reporter is also contacted by telephone to confirm receipt
and de-identification.
• After a quality check, the information is entered into the ASRS
database and the original report destroyed.
The most obvious way of ensuring confidentiality is to have the
reports filed anonymously. But, as O'Leary and Chappell point out,
this is not always possible or even desirable. 19 The main problems
with total anonymity are as follows:
• Analysts cannot contact the informant to resolve questions.
• It is more likely that some managers will dismiss anonymous
reports as the work of disaffected troublemakers.
• In small companies, it is almost impossible to guarantee anon-
ymity.
O'Leary and Chappell conclude that removing identities from re-
ports at a later stage—as described above for ASRS—is probably the
most workable means of maintaining confidentiality. At a national
level, complete de-identification means removing not only the peo-
ple's names, but also the date, the time, the flight number and the
airline name. The criteria for de-identification must be known and
understood by all potential reporters.
Another important measure for engendering trust is to separate
the organization receiving the reports from both the regulatory body
and from the employing company. As in the case of ASRS, the system
analysts should ideally have no legal or operational authority over
the potential reporters. Reporting systems run by disinterested third
parties—such as universities—can also help to earn the trust of re-
porters. If, like BASIS, the reporting system is internal to a company,
the receiving department should be perceived as being completely
independent of operational management, thus giving the necessary
assurance of confidentiality.
Apart from a lack (or loss) of trust, few things will stifle incident
reporting more than the perceived absence of any useful outcome.
Both the ASRS and BASIS place great emphasis on the rapid feed-
back of meaningful information to their respective communities. If
an ASRS report describes a continuing hazardous situation—for ex-
Engineering a Safety Culture 201
ample, a defective navigation aid, a confusing procedure, or an in-
correct chart—an alerting message is sent out immediately to the
appropriate authorities so that they can investigate the problem and
take the necessary remedial action. (As mentioned earlier, ASRS has
no legal or operational authority of its own.) Some 1700 alert bull-
etins and notices have been issued by the ASRS team since the
programme began in 1976. In 1994 there was a 65 per cent response
rate to alert bulletins and FYI notices.
The information assembled in the ASRS database is made avail-
able to the aviation and research communities in a variety of ways.
First, targeted searches can be carried out at the request of com-
panies, agencies or researchers. The information is also disseminated
via a newsletter, Callback, whose extended readership is estimated at
over 100 000, and other ASRS reports. Such newsletters describe safety
issues and highlight improvements that have been made as the result
of incident reporting. This serves the double function of both inform-
ing the reporters and congratulating them on their collective
contribution to aviation safety.
British Airways Safety Services also disseminate their BASIS infor-
mation in a variety of ways. In addition to unit reports and journal
articles, they issue Flywise, an 18-20 page monthly bulletin that in-
cludes trend analyses relating to selected events and brief accounts
of incidents broken down by fleets. Each incident is assigned both a
SEVERITY RISK MATRIX
A
HIGH C B
(severe)
B
MEDIUM D C
(high)
E D C
LOW
(minimal) (low) (medium)
LOW MEDIUM HIGH
PROBABILITY OF RECURRENCE
Figure 9.1 The British Airways risk management matrix used to
evaluate the future risk to the c o m p a n y of the
recurrence of an event
The matrix generates risk categories on a scale from A
(severe risk) to E (minimal risk).
202 Managing the Risks of Organizational Acciden ts
risk category (based on a risk matrix—see Figure 9.1) and one of the
following action categories:
• Active investigation—actions to prevent recurrence not fully
understood.
• Action required—preventive measures have been identified but
not yet implemented.
• Action monitored—preventive measures have been implemented
and their effects are being monitored.
• Report monitored—action taken without need for further inves-
tigation by Safety Services. Rates of occurrence are being
monitored.
The last factor to be considered here is ease of reporting. The
format, length and content of the reporting form or questionnaire are
extremely important, as is the context in which respondents are ex-
pected to make their report. Privacy and a labour-free returning
mechanism are all important incentives—or, to put it the other way
round, their absence could be a deterrent. O'Leary and Chappell
make the following observations regarding the design of the report-
ing form:
If a form is long and requires a great deal of time to complete, report-
ers are less likely to make the effort. If the form is too short, it is
difficult to obtain all the necessary information about the incident. In
general, the more specific the questions, the easier it is to complete the
questionnaire; however, the information provided will be limited by
the choice of the questions. More open questions about the reporter's
perceptions, judgements, decisions and actions are not subject to this
limitation and give the reporter a greater chance to tell the full story.
This method is more effective in gathering all the information about
an incident, but takes longer and usually requires more analytic re-
sources within die reporting system. 20
A certain amount of trial-and-error learning may be necessary be-
fore an organization hits upon a format that is best suited both to its
purpose and to its potential respondents. In this regard, we can learn
from the experience of British Airways Safety Services with their
confidential human factors questionnaire. In its initial form, it asked
a limited number of very specific questions. Some of the questions
sought to establish whether either a slip or a mistake had occurred
(see Chapter 4 for the technical descriptions of these unsafe acts)
and, if so, what were the contributing factors. The latter were listed
below each item and required 'yes/no' responses: in the case of
action slips and lapses, they included tiredness, time pressure, lack
of stimulation and flight deck ergonomics; in the case of mistakes,
Engineering a Safety Culture 203
they included misleading manuals, misleading displays, insufficient
training and crew cooperation.
Even though one of the questions asked what went right, several
respondents complained about the negative flavour of the questions
overall, and it was realized that this could well deter some potential
respondents from completing the questionnaire at all. In addition,
the BA analysts were unhappy with the validity of some of the data,
since the technical distinctions between slips, lapses and mistakes
were not well understood by the flight crew respondents. As a result,
BA Safety Services launched a new jargon-free questionnaire in 1995.
This asked open-ended questions covering a range of factors from
local flight deck influences to the effectiveness of training. O'Leary
gives two questions as examples of this new approach:
• How did you and the crew initially respond to the event, and
how did you establish what technical and personal issues were
involved?
• Was all the relevant flight, FMS and system information clearly
available and were all the controls and selectors useful and un-
ambiguous? If not, how could these be improved? 21
As O'Leary observes, this style of questioning moves the analytic
workload from the reporter to the human factors analysts. Although
the change has increased demand on the limited resources available
to process the data, it has made the questionnaire sensitive to a
variety of issues not previously covered. In addition, the reliability of
the analysis has improved dramatically: 'Previously, some 3500
pilots and engineers may report events idiosyncratically. Now we
use a team of only a dozen volunteer flight crew analysts'. 22
With the multiple choice format of the previous form of the human
factors questionnaire, it was relatively simple to convert 'yes/no'
responses directly into bar charts. With the second, more open-ended
version, the BA analysts had to develop an agreed classification struc-
ture in order to identify the issues with human factors significance.
They were interested in two major categories: crew performance and
the influences upon that behaviour. Crew behaviour was subdivided
into error descriptors (action slip or mistake), crew team skills and
task specifics, such as automatic or manual handling. Influences too
were divided into three groups: organizational factors (training, pro-
cedures, commercial pressure and the like), environmental factors
(airport facilities, weather conditions and the like) and personal fac-
tors (automation, complacency, morale and the like). Future
developments are directed at establishing causal links between the
various factors—a shift from addressing the 'what?' question to tack-
ling the 'why?' question. The aim here is to identify 'resident
204 Managing the Risks of Organizational Acciden ts
pathogens' that may contribute to a variety of different problems on
the flight deck.
Figure 9.2 gives an idea of what this development might yield in
the way of causal analysis. The figure summarizes a fictional inci-
dent involving a rejected takeoff. Here, operational stress was created
by a busy airfield and communicating with the company to establish
load-sheet figures while taxiing out. The climate on the flight deck
was poor. The co-pilot felt overloaded but was not able to communi-
cate this to the captain. He focused on one task at a time and did not
cross-check what the captain was doing. As a result, he omitted the
'before takeoff' checks. Takeoff clearance was given as the aircraft
approached the runway and, as takeoff power was set, the configura-
tion warning horn indicated that no flap had been selected and the
takeoff was aborted.
Finally in this context of engineering a reporting culture, it is worth
asking whether there is any scientific evidence to support the effi-
cacy of near-miss accident reporting. In one Swedish study,23 relating
Figure 9.2 Flow diagram of the rejected takeoff incident showing
judged causal linkages (after O'Leary) 24
Engineering a Safety Culture 205
primarily to individual accidents, the implementation of an incident
reporting scheme resulted in an increase in the number of remedial
suggestions from the workforce but no significant reduction in the
accident rate. In a follow-up study participants received training in
how to recognize and interpret critical incidents. This resulted in a 56
per cent reduction in the severity of injuries but no drop in the
accident frequency rate. The main message of these findings is that
potential respondents need to be very clear about what constitutes
an incident. In some situations, this is not always intuitively obvious.
Engineering a Just Culture
A wholly just culture is almost certainly an unattainable ideal. How-
ever, an organization in which the majority of its members share the
belief that justice will usually be dispensed is within the bounds of
possibility. Two things are clear at the outset. First, it would be quite
unacceptable to punish all errors and unsafe acts regardless of their
origins and circumstances. Second, it would be equally unacceptable
to give a blanket immunity from sanctions to all actions that could,
or did, contribute to organizational accidents. While this book has
strongly emphasized the situational and systemic factors leading to
the catastrophic breakdown of hazardous technologies, it would be
naive not to recognize that, on some relatively rare occasions, acci-
dents can happen as the result of the unreasonably reckless, negligent
or even malevolent behaviour of particular individuals. The diffi-
culty lies in discriminating between these few truly 'bad behaviours'
and the vast majority of unsafe acts to which the attribution of blame
is neither appropriate nor useful.
A prerequisite for engineering a just culture is an agreed set of
principles for drawing the line between acceptable and unacceptable
actions. To this end, we will start by outlining some of the psycho-
logical and legal issues that must be taken into account when making
this judgement. Figure 9.3 sets the scene.
All human actions involve three core elements:
• An intention that specifies an immediate goal and—where these
goal-related actions are not wholly automatic or habitual—the
behaviour necessary to achieve it.
• The actions triggered by this intention—which may or may not
conform to the action plan.
• The consequences of these actions—which may or may not
achieve the desired objective. The actions can be either success-
ful or unsuccessful in this respect.
206 Managing the Risks of Organizational Acciden ts
The feedforward arrows shown in Figure 9.3 indicate that, in for-
mulating an intention, actions are selected in the belief that they will
achieve the goal (or at least provide useful feedback to ensure the
success of future actions), but this belief is not always justified. The
feedback arrows complete the loop by providing information about
the success or otherwise of the preceding actions and their outcomes.
Human actions are embedded in a context that contains both the
immediate physical environment and the purpose of the behavioural
sequence of which a particular action forms a part. The historical
context is shown symbolically in Figure 9.3 by the three preceding
action frames in the background.
Both of these issues have a close bearing on individual responsibil-
ity. In the case of hazardous technologies it is inevitable that all
physical situations will contain an element of risk. But is also likely
that individual actors will have been—or should have been—trained
to foresee and to minimize these risks. This brings us back to the
distinction made in Chapter 4 between successful and unsuccessful
behaviour on the one hand, and correct and incorrect behaviour on
the other. Although success is determined solely by whether the
planned actions achieve their immediate objectives, success does not
necessarily mean correctness. Successful actions may be incorrect.
That is, they could achieve their local purpose and yet be either
reckless or negligent.
In the law, a person who acts recklessly is one who takes a deliber-
ate and unjustifiable risk (that is, one that is foreseeable, and where a
bad outcome is likely though not certain). However, as Smith and
Hogan point out:
The operator of aircraft, the surgeon performing an operation and the
promoter of a tightrope act in the circus must all foresee that their acts
might cause death; but we should not describe them as reckless, un-
Engineering a Safety Culture 207
less the risk taken was unjustifiable. Whether the risk is justifiable
depends on the social value of the activity involved, as well as on the
probability of the occurrence of the foreseen evil, 25
Negligence, on the other hand, involves bringing about a conse-
quence that a 'reasonable and prudent' person would have foreseen
and avoided. One can also be negligent with regard to a circum-
stance: 'A person acts negligently with respect to a circumstance
when a reasonable man would have been aware of the existence of
the circumstance and, because of its existence would have avoided
acting in that manner.' 26 In the latter case whether the person failed
to foresee the bad outcome and was unaware of the circumstance is
irrelevant. For example, X picks up a gun, believing it to be un-
loaded, points it at Y and pulls the trigger. If any reasonable person
would have realized that the gun might possibly be loaded, and thus
avoided acting in this way, then X was negligent with regard to
circumstance. If the gun was loaded and kills Y, then X was negligent
with regard to consequence. In a court of law, it is not necessary for
the prosecution to prove anything at all about the person's state of
mind at the time of the act. It is enough to establish that particular
actions were carried out in certain circumstances. Negligence is his-
torically a civil rather than a criminal law concept, and has a much
lower level of culpability than recklessness. 27
Those involved in the operation of hazardous technologies are
often perceived as carrying an additional burden of responsibility by
virtue of their training and of the great risks associated with human
failure. For example, in the case of Alidair v. Taylor in 1978, Lord
Denning ruled that:
There are activities in which the degree of professional skill which
must be required is so high, and the potential consequences of the
smallest departure of that high standard are so serious, that one fail-
ure to perform in accordance with those standards is enough to justify
dismissal. 28
This 'hang them all' judgement is unsatisfactory in many respects. It
ignores the ubiquity of error as well as the situational factors that
promote it. Nor is it sensitive to the varieties of human failure and
their differing psychological origins. Pushing this judgement to an
absurd conclusion, it could be claimed that, since all pilots, control
room operators and others with safety-critical jobs in hazardous tech-
nologies are fallible, they will all, at some time or another, inevitably
fall short of Lord Denning's 'high standards' and so should all be
sacked. Even wise and distinguished judges do not get it right all of
the time.
208 Managing the Risks of Organizational Acciden ts
A much sounder guideline is Neil Johnston's substitution test.29
This is in keeping with the principle that the best people can make
the worst errors. When faced with an accident or serious incident in
which the unsafe acts of a particular person were implicated, we
should perform the following mental test. Substitute the individual
concerned for someone else coming from the same domain of activ-
ity and possessing comparable qualifications and experience. Then
ask the following question: Tn the light of how events unfolded and
were perceived by those involved in real time, is it likely that this
new individual would have behaved any differently?' If the answer
is 'probably not' then, as Johnston put i t , ' . . . apportioning blame has
no material role to play, other than to obscure systemic deficiencies
and to blame one of the victims'. A useful addition to the substitution
test is to ask of the individual's peers: 'Given the circumstances that
prevailed at that time, could you be sure that you would not have
committed the same or similar type of unsafe act?' If the answer
again is 'probably not', then blame is inappropriate.
So much for the background. We will now turn to the task of
grading unsafe acts according to their blameworthiness. In this, as in
jurisprudence, a crucial discriminator is the nature of the intention. A
crime has two key elements: the mens rea, or 'guilty mind' and the
actus reus, or 'guilty act'. Both are necessary for its commission. Ex-
cept in very specific instances (as, for example, in the case of
negligence), the act without the mental element is not a crime. While,
for the most part, we are not concerned here with criminal behav-
iour, we will adopt the 'mental element' principle as a basic guideline.
But hereafter we will approach the issue more from a psychological
perspective than from a legal one.
Figure 9.4 sketches out the bare essentials of a decision tree for
discriminating the culpability of an unsafe act. It is assumed that the
actions under scrutiny have contributed either to an accident or to a
serious incident in which a bad outcome was only just averted. In an
organizational accident, there are likely to be a number of different
unsafe acts, and the decision tree is intended to be applied separately
to each of them. Our concern here is with individual unsafe acts
committed by either a single person or by different people at various
points in the accident sequence.
The key questions relate to intention. If both the actions and the
consequences were intended, then we are likely to be in the realm of
criminal behaviour and that is probably beyond the scope of the
organization to deal with internally. Unintended actions define slips
and lapses—in general, the least blameworthy of errors—while unin-
tended consequences cover mistakes and violations. The decision
tree usually treats the various error types in the same way, except
with regard to the violations question. For mistakes, the question
Engineering a Safety Culture 209
Knowingly
Put History
Were the
— NO
Unauthorised
NO
violating substitution - YES of unsafe
action! *u bs tanc e? safe operating tot? acta?
&i intended? procedures?
f —I— NO
YES
T n
NO YES YES NO
±
Dcficienciei
Were procedure* in training &
available, workable selection or
mtclligible and incx pen erice?
\r correct? ~r
Were the
consequences
ts intended?
YES
Sabotage,
malevolent
damage,
suicide, etc.
Figure 9.4 A decision tree for determining the culpability of
unsafe acts
reads as shown in Figure 9.4, but for slips and lapses, the question
relates to what the person was doing when the slip or lapse occurred.
If the individual was knowingly engaged in violating safe operating
procedures at that time, then the resulting error is more culpable
since it should have been realized that violating increases both the
likelihood of making an error and the chances of bad consequences
resulting (see Chapter 4).
The 'unauthorized substance' question seeks to establish whether
or not the individual was under the influence of alcohol or drugs
known to impair performance at the time the unsafe act was commit-
ted. Since the ingestion of unauthorized substances is usually a
voluntary act, their involvement would indicate a high level of culp-
ability. But the matter is not entirely straightforward. In 1975, during
a descent towards Nairobi, the co-pilot of a Boeing 747 misheard an
air traffic control instruction. Instead of 'seven five zero zero', he
heard 'five zero zero zero' and set the autopilot to level out at 5000
feet. 30 Unfortunately, that would have placed the aircraft in a tunnel-
ling mode since it was around 300 feet below the unusually high
210 Managing the Risks of Organizational Acciden ts
airfield. When the aircraft broke cloud, the flight crew saw the ground
a little more than 200 feet below them. Prompt action by the captain
prevented this from being the first major disaster involving a Boeing
'jumbo' jet. It later transpired that the co-pilot had picked up a large
tapeworm on a holiday in India and was dosing himself with un-
authorized drugs that had, among their side-effects, drowsiness and
nausea. Taking unauthorized medication as the result of a medical
condition, while clearly reprehensible, is less blameworthy than tak-
ing drugs or alcohol for 'recreational purposes' and, as such, in Figure
9.4 it has been assigned to the category of 'substance abuse with
mitigation'. The degree of mitigation will, of course, depend upon
the local circumstances.
Except when non-compliance has become a largely automatic way
of working (as sometimes happens in the case of routine short-cuts),
violations involve a conscious decision on the part of the perpetrator
to break or bend the rules. However, while the actions may be delib-
erate, the possible bad consequences are not—in contrast to sabotage
in which both the act and the consequences are intended. Most viola-
tions will be non-malevolent in terms of intent, so the degree to
which they are blameworthy will depend largely on the quality and
availability of the relevant procedures. These, as discussed in Chap-
ter 4, are not always appropriate for the particular situation. Where
this is judged to be the case—perhaps by a 'jury' of the perpetrator's
peers—the problem lies more with the system than with the indi-
vidual. However, when good procedures were readily accessible but
deliberately violated, the question must arise as to whether the be-
haviour was reckless in the legal sense of the term. Such actions are
clearly more culpable than 'necessary' violations—that is, non-com-
pliant actions necessary to get the job done when the relevant
procedures are either wrong, inappropriate or unworkable.
It seems appropriate to apply Johnston's substitution test once the
issues of possible substance abuse and deliberate non-compliance
have been settled, although something like it clearly has a part to
play in judging the culpability of system-induced violations (as indi-
cated by the dotted arrow in Figure 9.4). The issue is reasonably
straightforward. Could (or has) some well motivated, equally com-
petent and comparably qualified individual make (or made) the same
kind of error under those or very similar circumstances? If the
answer given by a 'jury' of peers is 'yes', then the error is probably
blameless. If the answer is 'no', then we have to consider whether
there were any system-induced deficiencies in the person's training,
selection or experience. If such latent conditions are not identified,
then the possibility of a negligent error must be considered. If they
are found, it is likely that the unsafe act was a largely blameless
system-induced error.
Engineering a Safety Culture 211
Such a category would apply to the technician whose miswiring of
a signal box significantly contributed to the Clapham Junction rail
disaster (see Chapter 5). His actions would not pass the substitution
test, since he was largely self-taught and had acquired his bad work
practices in the absence of adequate training and supervision. But, as
the Inquiry established, the underlying problems were those of the
system rather than the individual, who was hardworking and highly
motivated to do a good job.
In legal jargon, the last major question at the top right-hand corner
of Figure 9.4 could be rephrased as 'Any previous?'. People vary
widely and consistently in their liability to everyday slips and lapses.
For example, some individuals are considerably more absentminded
than others. If the person in question has a previous history of unsafe
acts, it does not necessarily bear upon the culpability of the error
committed on this particular occasion, but it does indicate the neces-
sity for corrective training or even career counselling along the lines
of 'Don't you think you would be doing everyone a favour if you
considered taking on some other job within the company?'. This is
the way that management acquires some of its most distinguished
members. Absentmindedness has nothing whatsoever to do with
ability or intelligence, but it is not a particularly helpful trait in a
pilot or control room operator.
So where should the line be drawn on Figure 9.4 between accept-
able and unacceptable behaviour? The most obvious point would be
between the two substance abuse categories. Both malevolent dam-
age and the dangerous use of alcohol or drugs are wholly unacceptable
and should receive very severe sanctions, possibly administered by
the courts rather than the organization. Between 'substance abuse
with mitigation' and 'possible negligent error' lies a grey area in
which careful judgement must be exercised. The remaining categ-
ories should be thought of as blameless—unless they involve
aggravating factors not considered here. Experience suggests that
the majority of unsafe acts—perhaps 90 per cent or more—fall into
this blameless category.
What should happen to the small proportion of individuals whose
unsafe acts are justly considered culpable? It is not within the com-
petence of this chapter to advise on the nature of the sanctions.
Although this is a matter for the organizations concerned, we can say
something about the value—or otherwise-^of punishments.
Unfortunately, a large amount of psychological research concerned
with the issues of reward and punishment has involved the white
rat, and is not especially relevant. Figure 9.5 summarizes in a very
simplified way what psychologists know about the effects of reward
and punishment in the workplace. 31 The principal issue here is the
effectiveness of 'sticks and carrots' in enhancing the likelihood of
212 Managing the Risks of Organizational Acciden ts
Immediate Delayed
Reward Positive Doubtful
effects effects
Punishment Doubtful Negative
effects effects
Figure 9.5 Summary of the effects of reward and punishment on
behavioural change in the workplace
desired behaviour and reducing the chances of unwanted behaviour.
Rewards are the most powerful means of changing behaviour, but
they are only effective if delivered close in time and place to the
behaviour that is desired. Delayed punishments have negative ef-
fects: they generally do not lead to improved behaviour and can
induce resentment in both the punished and the could-be-punished.
The cells labelled 'doubtful effects' mean that, in each case, there are
opposing forces at work. Hence, the results are uncertain.
But there are other factors that argue strongly in favour of punish-
ing the few who commit egregious unsafe acts. In most organizations
the people in the front line know very well who the 'cowboys' and
the habitual rule-benders are. Seeing them get away with it on a
daily basis does little for morale or for the credibility of the disciplin-
ary system. Watching them getting their 'come-uppance' is not only
satisfying, it also serves to reinforce where the boundaries of accept-
able behaviour lie. Moreover, outsiders are not the only potential
victims. Justified dismissal protects the offender's colleagues. Per-
haps more than other possible victims, they are likely to be endangered
by the person's repeated recklessness or negligence. Their departure
makes the work environment a safer place and also encourages the
workforce to perceive the organizational culture as just. Justice works
two ways. Severe sanctions for the few can protect the innocence of
the many.
David Marx, an aircraft engineer who was one of the principal
architects of the Boeing's Maintenance Error Decision Aid (see
Chapter 7), made the following comments on the relationship
between reporting and disciplinary systems. Though he is writing
about the aviation industry, the points are widely applicable:
Many of us have found today's disciplinary systems to be a significant
obstacle to asking an employee to come forward and talk about his or
Engineering a Safety Culture 213
her mistake. Consequently, as an industry, we have begun to reevalu-
ate the inter-relationship of employee discipline and event
investigation. Many programs have been developed, both internal to
an airline and in association with the FAA ... Whether it is called
immunity, amnesty or 'performance-related incentive'—each program
attempts to encourage the erring employee to come forward. Yet, as
more incentive programs enter the marketplace of ideas, the discipli-
nary landscape becomes increasingly complex and confusing. With all
the programs today, the individual employee needs to be a lawyer to
assess whether it is safe to come forward. 32
David Marx has recently taken a law degree and one of the most
interesting products of this marriage between engineering and the
law has been the computerized incident investigator, the Aurora
Mishap Management System (AMMS). AMMS has a number of el-
ements. For our present purposes, its most important aspect is a
structured methodology for establishing the applicability of discipli-
nary action. This investigative tool is used by an organization's
disciplinary review board to aid their decision-making. It applies a
common and consistent approach to the issue of determining whether
or not disciplinary action is warranted. To date, it has been used in
the field of aircraft maintenance by a number of US airlines and has
the backing of the Machinists Union.
Engineering a Flexible Culture
Organizational flexibility means possessing a culture capable of adapt-
ing effectively to changing demands. Flexibility is one of the defining
properties of what a highly influential Berkeley research group—led
by Todd La Porte, Karlene Roberts and Gene Rochlin—have termed
high-reliability organizations (HROs). The group has conducted field
research in a number of highly complex, technology-intensive or-
ganizations that must operate, as far as humanly possible, to a
failure-free standard. The systems of interest here are air traffic con-
trol and naval air operations at sea.
The operational challenges facing these (and comparable) organ-
izations are twofold:
• to manage complex, demanding technologies, making sure to
avoid major failures that could cripple, perhaps destroy, the or-
ganization;
• at the same time, to maintain the capacity for meeting periods of
very high, peak demand and production whenever these oc-
cur.33
214 Managing the Risks of Organizational Acciden ts
The organizations studied by the Berkeley group had the following
characteristics:
• They were large, internally dynamic and intermittently intensely
interactive.
• Each performed complex and exacting tasks under consider-
able time pressure.
• They have carried out these demanding activities with a very
low error rate and an almost complete absence of catastrophic
failure over a number of years.
On the face of it both of the organizations to be considered here—the
US Navy nuclear aircraft carrier and the air traffic control centre—
had highly bureaucratic and hierarchical organizational structures,
each with a clear line of authority and command. Both organizations
relied heavily on tested standard operating procedures (SOPs). Both
organizations invested a great deal of effort in training people in the
use of these procedures. It was almost the case that, under routine
operating conditions, the only decision necessary was which SOP to
apply.
Actions in these HROs were closely monitored so that immediate
investigations—termed 'hot washups' in the US Navy—were con-
ducted whenever errors occurred. Over the years, these organizations
have learned that there are particular kinds of error, often quite
minor, that can escalate rapidly into major, system-threatening fail-
ures. Trial-and-error learning in these critical areas was not
encouraged, as it was elsewhere, in case it should become 'habit-
forming.' Also, as La Porte and Consolini describe it: 'there is a
palpable sense that there are likely to be similar events that cannot be
foreseen clearly, and that may be beyond imagining. This is an ever-
present cloud over operations, a constant concern'. 34 In short, these
organizations suffer chronic unease. The following quotation from
the same source captures this intelligent wariness and its cultural
consequences very eloquently:
The people in these organizations know almost everything technical
about what they are doing—and fear being lulled into supposing that
they have prepared for any contingency. Yet even a minute failure of
intelligence, a bit of uncertainty, can trigger disaster. They are driven
to use a proactive, preventative decision making strategy Analysis
and search come before as well as after errors. They try to be synoptic
while knowing that they can never fully achieve it. In the attempt to
avoid the pitfalls in this struggle, decision making patterns appear to
support apparently contradictory production-enhancing and error-re-
duction strategies. The patterns encourage
Engineering a Safety Culture 215
• reporting errors without encouraging a lax attitude toward the
commission of errors;
• initiative to identify f l a w s in SOPs and nominate and validate
changes in those that prove to be inadequate;
• error avoidance without stifling initiative or (creating) operator
rigidity; and
• mutual monitoring without counter-productive loss of operator
confidence, autonomy and trust.35
So h o w do H R O s respond to bursts of high-tempo operations?
Lying in wait beneath the surface of the routine, bureaucratic, S O P -
driven m o d e is quite another pattern of organizational behaviour-
Here is w h a t h a p p e n e d aboard the aircraft carrier w h e n some 70 of
its 90 aircraft were flying off on missions:
Authority patterns shift to a basis of functional skill. Collegial author-
ity (and decision patterns) overlay bureaucratic ones as the tempo of
operations increases. Formai rank and status decline as a reason for
obedience. Hierarchical rank defers to technical expertise often held
by those of lower formal rank. Chiefs (senior non-commissioned offi-
cers) advise commanders, gently direct lieutenants and cow ensigns.
Criticality, hazards, and sophistication of operations prompt a kind of
functional discipline, a professionalization of the work teams. Feed-
back and (sometimes conflictual) negotiations increase in importance;
feedback about 'how goes it' is sought and valued. 36
A similar kind of flexibility was evident in the air traffic control
centre. Sudden w i n d shifts can impose a high additional burden on
already busy controllers. Reorienting the flight paths of a large n u m b e r
of aircraft in relation to what, in this instance, were three major
airports, two large military airbases and five smaller general aviation
airfields becomes a major programme for the controllers on duty. La
Porte and Consolini described what happened:
The tempo at the approach-control facility and the enroute center
increases, and controllers gather in small groups around relevant
radar screens, plotting the optima! ways to manage the traffic as the
shift in [wind] direction becomes imminent. Advicc is traded, sugges-
tions put forward, and the actual traffic is compared with the
simulations used in the long hours of training the controllers under-
go... . While there are general rules and controllers and supervisors
have formal authority, it is the team that rallies round the controllers
in 'the hot seats'. It will be the experienced controller virtuosos [rather
than the supervisors] who dominate the decision train. 'Losing sepa-
ration'—the key indicator of controller failure—is too awful to trust to
rules alone. 37
216 Managing the Risks of Organizational Acciden ts
When the high-tempo period slackens off, authority reverts seamlessly
to its previous bureaucratic, rank-determined form. A very similar
type of flexibility was evident in an anecdote which I came across
concerning one of the most highly rated US Army units of the
Korean War. The senior NCOs of the unit recognized that they lacked
the qualities to lead men in action. When the unit went into combat,
local command passed to a small group of enlisted men. Afterwards,
these 'combat leaders' were quite happy to follow the orders of the
NCOs, whose skills in everyday soldiering they fully recognized.
There is, then, convincing evidence that an organization's ability
to switch from a bureaucratic, centralized mode to a more decentral-
ized professional mode is an important determinant of reliability—or
even survival. But how can it be engineered? Karl Weick—whose
work has been cited at various points throughout this book—has
made a number of important observations in this regard. In order to
achieve effective decentralization—of the kind described earlier—
Weick argues that:
... you first have to centralise so that people are socialised to use
similar decision premises and assumptions so that when they operate
their own units, these decentralised operations are equivalent and co-
ordinated. This is precisely what culture does. It creates a homogeneous
set of assumptions and decision premises which, when they are in-
voked on a local and decentralised basis, preserve co-ordination and
centralisation. More important, when centralisation occurs via de-
cision premises and assumptions, compliance occurs without
surveillance. This is in sharp contrast to centralisation by rules and
regulations or centralisation by standardisation and hierarchy, both of
which require high surveillance. Furthermore, neither rules nor stan-
dardisation are well equipped to deal with emergencies for which
there is no precedent. 38
It is probably no coincidence that the HROs studied by the Berkeley
group were either military or had many key personnel with a mili-
tary background—this applies equally to the third HRO not discussed
above, a Californian nuclear power plant in which many operators
and supervisors had been in the nuclear Navy. The acceptance of a
disciplined approach to working, well founded trust in SOPs, and a
familiarity with the ways of rank-based structures would all help to
forge the shared values about reliability that permit effective decen-
tralized action when the occasion demands.
Weick makes another point of considerable relevance here. All
hazardous technologies face the problem of requisite variety—the
variety that exists in the system exceeds the variety of the people
who must control it (see Chapter 4). As a result, 'they miss important
information, their diagnoses are incomplete, and their remedies are
Engineering a Safety Culture 217
short-sighted and can magnify rather than reduce a problem'. But
this problem, can be reduced by a culture that encourages 'war
stories'. Since the nature of these systems allows little scope for
trial-and-error learning, maintaining reliability depends on develop-
ing alternatives for trial and error. These could include imagination,
vicarious experience, simulation, stories and story-telling.
A system that values stories and storytelling is potentially more reli-
able because people know more about their system, know more of the
potential errors that might occur, and they are more confident that
they can handle those errors that do occur because they know that
other people have already handled similar errors. 39
Other ways of reducing the gap between the variety of the system
and the variety of its human controllers include:
• A culture that favours face-to-face communication. 'One way to
describe (admittedly stereotype) engineers is as smart people
who don't talk. Since we know that people tend to devalue
what they don't do well, if high reliability systems need rich,
dense talk to maintain complexity, then they may find it hard
to generate this richness if talk is devalued or if people are
unable to find substitutes for talk (e.g., electronic mail may be a
substitute).' 40
• Work groups made up of divergent people. 'A team of divergent
individuals has more requisite variety than a team of homog-
eneous individuals.' 4 1 It matters less what makes up this
diversity—different speciality, different experience, different
gender, and the like—than the fact that it exists. 'If people look
for different things, when their observations are pooled they
collectively see more than any one of them alone would see.' 42
By the same token, groups made up of very similar people tend
to see very similar things, and so lack requisite variety.
The decentralization of authority under certain conditions was a
crucial feature of the German military concept of Auftragssystem—
(mission system) discussed in Chapter 4. Its essence was that a
subordinate commander, a subaltern or senior NCO, should be trained
to a level where he (or, very rarely, she) could achieve the tactical
goals of superior officers, with or without orders. Translating this
into a civilian context, it means selecting and training first-line
supervisors so that they are able to direct safe and productive work-
ing without the need for SOPs. Such a localized system of behavioural
guidance makes heavy demands on the personal qualities of the
supervisors. A prerequisite is an extensive experience of the jobs
218 Managing the Risks of Organizational Acciden ts
carried out in the workplace and the conditions under which they
are likely to be performed. Supervisors need to be 'sitewise' both to
the local productive demands and to the range of obvious and less
obvious hazards. Equally important is a personal authority derived
both from the respect of the workforce and the support of manage-
ment—a key feature in the success of the German Army.
Not all activities in hazardous technologies are carried out in
supervised groups. When people are relatively isolated, the onus shifts
from group to self-controls. Crucial among these are the techniques
designed to enhance hazard awareness and risk perception, These
are the measures that seek to promote 'correct' rather than merely
'successful' performance. A number of hazard evaluation programmes
are being developed or have already been implemented. However,
as Willem Albert Wagenaar has observed, 43 risk appraisal training is
of little value once the incorrect actions have become habitual. When
this happens, people are not taking risks deliberately, they are running
risks in a largely thoughtless and automatic fashion. To be effective,
such training must occur in the initial phase of employment and then
be consolidated and extended by on-the-spot supervisory guidance.
By the same token, it is mainly through local supervisory interven-
tions that long-established pattern of incorrect behaviour can be
modified.
In summary, high-reliability organizations are able to shift from
centralized control to a decentralized mode in which the guidance of
local operations depends largely upon the professionalism of first-
line supervisors. Paradoxically perhaps, the success of this
transformation depends on the prior establishment of a strong and
disciplined hierarchical culture. It is the shared values and assump-
tions created by this culture that permit the coordination of
decentralized work groups. Effective teams, capable of operating
autonomously when the circumstances demand it, need high-quality
leaders. This, in turn, requires that the organization invest heavily in
the quality, motivation and experience of its first-line supervisors.
Engineering a Learning Culture
Of all the 'subcultures' so far considered, a learning culture is prob-
ably the easiest to engineer but the most difficult to make work. Most
of its constituent elements have already been described—observing
(noticing, attending, heeding, tracking), reflecting (analysing, inter-
preting, diagnosing), creating (imagining, designing, planning) and
acting (implementing, doing, testing). The first three are not so diffi-
cult. It is the last one—acting—that is likely to cause most of the
problems. Echoing the rueful remark by the man from Barings Bank
Engineering a Safety Culture 219
after the collapse—there always seemed to be something more press-
ing to do.
Beyond what has already been written/ 4 there is little more that a
book can do to give top managers the will to put in place the reforms
indicated by their safety information systems, except to bring to their
attention the chilling observation of the organizational theorist, Peter
Senge:
Learning disabilities are tragic in children, but they are fatal in organ-
izations. Because of them, few corporations live even half as long as
the person—Most die before they reach the age of forty.45
Senior managers should not need to be reminded that an organiz-
ational accident can brutally cut short even that brief span.
Safety Culture: Far More than the Sum of its Parts
At this point, I have in mind an imaginary technical manager from
an organization with a good safety record (probably measured in
LTIFs) who starts to count off the cultural elements that have so far
been considered. Yes, he or she might decide, we have an incident
reporting system of sorts. Yes, we have a reasonably fair and straight-
forward method of deciding whether or not disciplinary action is
warranted. Yes, we have, on occasions, allowed our first-line super-
visors a good deal of latitude and backed up their decisions
afterwards—when things turn out all right, of course. And, yes, we
have implemented a number of fairly expensive safety improve-
ments on the basis of both reactive and proactive information, so it
could be said that we have a learning culture. Does all of this mean
that we have an informed culture—or, in more usual terms, a safety
culture?
As any engineer knows, assembling the parts of a machine is not
the same thing as making it work. And the same is even more true of
social engineering than of its more mechanical counterparts. In order
to answer our hypothetical manager, we would have to pose some
questions in return:
• Which board members have responsibility for organizational
safety—as opposed to conventional health and safety at work
concerns?
• Is information relating to organizational safety discussed at all
regular board meetings—or their high-level equivalent?
• What system, if any, do you have for costing the losses caused
by unsafe acts, incidents and accidents?
220 Managing the Risks of Organizational Acciden ts
• Who collates, analyses and disseminates information relating
to organizational safety? By how many reporting levels is this
individual separated from the CEO? What annual budget does
this person's department receive? How many staff does he or
she oversee?
• Is a safety-related appointment seen as rewarding talent (a
good career move) or as an organizational oubliette for spent
forces?
• How many specialists in human and organizational factors does
the company employ?
• Who decides what disciplinary action should be meted out?
Are the 'defendant's' peers and union representatives involved
in the judgement process? Is there any internal appeals proce-
dure?
The potential list is endless. The point is this—the mere possession of
the 'engineered' externals is not enough. A safety culture is far more
than the sum of its component parts. And here—perversely perhaps,
considering what was said at the beginning of the chapter—we must
acknowledge the force of the argument asserting that a culture is
something that an organization 'is' rather than something it 'has'.
But if it is to achieve anything approaching a satisfactory 'is' state, it
first has to 'have' the essential components. And these, as we have
tried to show, can be engineered. The rest is up to the organizational
chemistry. But using and doing—particularly in a technical organiz-
ation—lead to thinking and believing.
Finally, it is worth pointing out that if you are convinced that your
organization has a good safety culture, you are almost certainly mis-
taken. Like a state of grace, a safety culture is something that is
striven for but rarely attained. As in religion, the process is more
important than the product. The virtue—and the reward—lies in the
struggle rather than the outcome,
Postscript: National Culture
Every organizational culture is shaped by the national context in
which it exists—and this is especially true for multinational organ-
izations. It is not within the scope of this chapter to deal with the
differences in national culture. For this, the reader is directed to the
seminal books by Geert Hofstede. 46 The interested reader is also
strongly advised to seek out the work of Robert Helmreich 47 and his
colleagues at the University of Texas, and of Najmedin Meshkati 48 at
the University of Southern California.
Engineering a Safety Culture 221
Notes
1 Data from the Flight Safety Foundation Icarus Committee, cited by Skandia
International. I am grateful to Lars Hogberg of the Swedish Nuclear Power
Inspectorate (SKI) for sending me this information.
2 B. Uttal, 'The corporate culture vultures', Fortune, 17 October 1983.
3 T.E. Deal and A.A. Kennedy, Corporate Cultures: The Rites and Rituals of Cor-
porate Life, (Reading, MA: Addison-Wesley, 1982).
4 T.J. Peters and R.H. Waterman, In Search of Excellence: Lessons from America's
Best-Run Companies, (New York: Harper & Row, 1982).
5 Ibid.
6 Ibid., p. 76.
7 P. Bate, 'The impact of organizational culture on approaches to organizational
problem-solving', in G. Salaman (ed.), Human Resource Strategies, (London;
Sage, 1992), p. 229 cited by N. Thompson, S. Stradling, M. Murphy and P.
O'Neill, 'Stress and organizational culture', British Journal of Social Work, 26,
1996, pp. 647-65.
8 Cited by Thompson et «/., op. cit. p. 651.
9 G. Hofstede, Cultures and Organizations: Intercultural Cooperation and its Import-
ance for Survival, (London: Harper Collins, 1994), p. 199.
10 International Nuclear Safety Advisory Group (IAEA), Safety Culture, (Vienna:
IAEA, 1991).
11 Cited by R. Booth, 'Safety culture: concept, measurement and training implica-
tions', Proceedings of British Health and Safety Society Spring Conference: Safety
Culture and the Management of Risk, 19-20 April, 1993, p. 5.
12 M. O'Leary and S.L. Chappell, 'Confidential incident reporting systems create
vital awareness of safety problems', ICAO Journal, 51, 1996, pp. 11-13. Dr
Chappell is now Program Manager, H u m a n Factors Services, at TransQuest
Inc. in Atlanta, Georgia.
13 Ibid., p. 11.
14 S.L. Chappell, 'Aviation Safety Reporting System: program overview' in Report
of the Seventh ICAO Flight Safety and Human Factors Regional Seminar, Addis
Ababa, Ethiopia, 18-21 October, 1994, pp. 312-53.
15 J.A. Passmore, 'Air safety report form', Flight Deck, Spring 1995, pp. 3 - 4 .
16 M. O'Leary and N. Pidgeon, 'Too bad we have to have confidential reporting
programmes', Flight Deck, Summer 1995, pp. 11-16.
17 M. O'Leary and S. Fisher, British Airways Confidential Human Factors Reporting
Programme. First Year Report, April 1992-March 1993, (Hounslow: British Air-
w a y s Safety Services, 1993).
18 S. Chappell, op. cit.
19 M. O'Leary and S. Chappell, op. cit.
20 Ibid., p. 12.
21 M. O'Leary, 'New developments in the British Airways Confidential H u m a n
Factors Reporting Programme', Flight Deck, Summer 1996, pp. 19-22.
22 Ibid., p.21.
23 Cited by S.J. Guastello, 'Do we really know how well our occupational acci-
dent prevention programs work?', Safety Science, 16, 1993, pp. 445-63.
24 O'Leary, op. cit. 1996, p. 22.
25 J.C. Smith and B. Hogan, Criminal Law, (3rd edn), (London: Butterworths, 1975),
p. 45.
26 Ibid., pp. 4 5 - 6 .
27 D. Marx, Personal communication, 9 January 1997.1 am most grateful to David
222 Managing the Risks of Organizational Acciden ts
Marx for his helpful advice on the distinction between recklessness and negli-
gence.
28 Cited by M. O'Leary and N. Pidgeon, op. c i t , p. 16.
29 N. Johnston, 'Do blame and punishment have a role in organizational risk
management?', Flight Deck, Spring 1995, pp. 33-6.
30 Air Accident Investigation Branch (AAIB), Boeing 747-136 G-AWNJ. Report on
the Incident near Nairobi Airport, Kenya on 3 September 1974, Aircraft Accident
Report 1 4 / 7 5 , (London: HMSO, 1975).
31 J.M. George, 'Asymmetrical effects of rewards and punishment: the case of
social loafing', Journal of Occupational and Organizational Psychology, 68, 1995,
pp. 3 2 7 - 2 8 .
32 D. Marx, Personal communication, 1 October 1996.
33 T.R. LaPorte and P.M. Consolini, 'Working in practice but not in theory: theo-
retical c h a l l e n g e s of " h i g h - r e l i a b i l i t y " o r g a n i z a t i o n s ' , Journal of Public
Administration Research and Theory, 1 , 1 9 9 1 , p. 21.
34 Ibid., p. 27.
35 Ibid., p. 29.
36 Ibid., p. 32.
37 Ibid., p. 34,
38 K.E. Weick, 'Organizational culture as a source of high reliability', California
Management Review, 2 4 , 1 9 8 7 , pp. 112-27, see p. 124.
39 Ibid., p. 113.
40 Ibid., p. 115. See also K.M. Eisenhardt, J.L. Kahwajy and L.J. Bourgeois, 'Con-
flict and strategic choice: How top management teams disagree', California
Management Review, 3 9 , 1 9 9 7 , pp. 42-62.
41 K.E. Weick, op. cit., 1987, p. 116.
42 Ibid., p. 116.
43 W.A. Wagenaar, 'Risk-taking and accident causation' in J. Yates (ed.), Risk-
Taking Behaviour, (Chichester: Wiley, 1992).
44 The interested reader is recommended to start with: B. Toft and S. Reynolds,
Learning from Disaster: A Management Approach, ( L o n d o n : B u t t e r w o r t h s
Heinemann, 1994).
45 P.M. Senge, The Fifth Discipline: The Art and Practice of the Learning Organization,
(London: Century Business, 1990),
46 G. Hofstede, op. cit., 1994. See also G. Hostede, Culture's Consequences: Inter-
national Differences in Work-Related Values, (Beverly Hills, CA: Sage Publications,
1980).
47 R.L. Helmreich, A. Merritt and P. Sherman, 'Research project evaluates the
effect of national culture on flight crew behaviour', ICAO Journal, 5 1 , 1 9 9 6 , pp.
1 4 - 1 6 (and many other sources).
48 N. Meshkati, 'Cultural factors influencing safety need to be addressed in de-
sign and operation of technology', ICAO Journal, 51, 1996, pp. 1 7 - 1 8 (and many
other sources).
10 Reconciling the
Different Approaches
to Safety Management
Revisiting the Distinction Between Individual and Organizational
Accidents
Having recently tried out some of the book's ideas on safety profes-
sionals dealing with the day-to-day realities of North Sea oil
exploration and production, 1 I am conscious that there is something
of a gulf between their current focus on personal injury accidents
and my emphasis upon the larger-scale, but comparatively rare, or-
ganizational accidents. The professionals are, of course, fully aware
of the commercial, human and environmental dangers posed by ca-
tastrophes like Piper Alpha, but, for the last 15 years or so, the principal
metric for assessing safety in the oil industry, as in many other haz-
ardous domains, has been LTIF—lost-time injuries per million man
hours. 2 It therefore seems appropriate, in this final chapter, to reopen
the issue of the differences between individual and organizational
accidents that were discussed only briefly in Chapter 1.
Another problem that needs to be confronted is the belief held by
many technical managers that the main threat to the integrity of
their assets is posed by the behavioural and motivational shortcom-
ings of those at the 'sharp end'. For them, the oft-repeated statistic
that human errors are implicated in some 80-95 per cent of all
events generally means that individual human inadequacies and
errant actions are the principal causes of all accidents. What they
hope for in seeking the help of a human factors specialist is some-
one or something to 'fix' the psychological origins of these deviant
and unwanted behaviours. But this—as I hope is now clear—runs
counter to the main message of this book. Workplaces and organ-
izations are easier to manage than the minds of individual workers.
You cannot change the human condition, but you can change the
conditions under which people work. In short, the solutions to
223
224 Managing the Risks of Organizational Acciden ts
most human performance problems are technical rather than psy-
chological.
One way to begin to resolve these apparent conflicts is to recog-
nize that there are three distinct models for managing safety—the
person model, the engineering model and the organizational model—
and that each of them has a different perspective on human error.
These important distinctions were first made by Deborah Lucas, 3
now with the UK Health and Safety Executive.
The principal aim of this concluding chapter is to show that, de-
spite their differences in tradition, emphasis and domains of
application, there is no reason why these various models and their
associated practices should not coexist harmoniously within the same
organization—so long as the strengths and weaknesses of each ap-
proach are recognized.
Three Approaches to Safety Management
The Person Model
The person model is exemplified by the traditional occupational safety
approach. The main emphases are upon individual unsafe acts and
personal injury accidents. It views people as free agents capable of
choosing between safe and unsafe behaviour. This means that errors
are perceived as being shaped predominantly by psychological fac-
tors such as inattention, forgetfulness, poor motivation, carelessness,
lack of knowledge skills and experience, negligence and—on occa-
sions—culpable recklessness. Its principal applications are in those
domains involving close encounters with hazards. As such, it is the
most widely adopted of the three models. It is also the approach with
the longest history, stretching back to the beginnings of industrialis-
ation. It is usually policed by safety departments and safety
professionals, though—more recently—the accent has been upon per-
sonal responsibility.
The most widely used countermeasures are 'fear appeal' poster
campaigns, rewards and punishments, unsafe act auditing, writing
another procedure, training and selection. Progress is measured by
personal injury statistics, such as fatalities, lost-time injuries, medical
treatment cases, first aid cases, and the like. It is frequently under-
pinned by the 'iceberg' or 'pyramid' views of accident causation. The
empirical basis for such beliefs was provided by Frank Bird's analy-
sis of 1 753 498 accidents reported by 297 companies, representing 21
different industries. 4 This yielded the now widely used 1:10:30:600
ratio (see below), though other comparable ratios are also employed:
Reconciling the Different Approaches to Safety Management 225
• 1 serious or major injury
• 10 minor injuries
• 30 property damage accidents
• 600 incidents with no visible damage or injury.
The Engineering Model
The engineering model has its origins in reliability engineering, tra-
ditional ergonomics (and its modern variant—cognitive engineering)
risk management and human reliability assessment. Safety is viewed
as something that needs to be 'engineered' into the system and,
where possible, to be quantified as precisely as possible. Thus, the
focus is upon engineered system reliability, often expressed in
probabilistic terms. In contrast to the person model, human errors
are not regarded simply as the product of what goes on between an
individual's ears. Rather, they emerge from human-machine mis-
matches, or poor human engineering—that is, the failure on the part of
the system designers to tailor the system appropriately to the cogni-
tive strengths and weaknesses of its human controllers. Typically, the
model focuses on how the performance of front-line operators (for
example, control room operators and pilots) is influenced by the
characteristics of the workplace or, more specifically, by the informa-
tional properties of the human-machine interface. These issues were
discussed at some length in Chapter 3 in the context of 'clumsy
automation'.
Research in this area was originally supported by the nuclear power
industry, the military, the space agencies, the chemical process indus-
try and aviation—domains in which the safety of a system hinges
critically on the reliability of a small number of human controllers.
More recently, however, the requirement upon oil and gas companies
to produce formal safety assessments as part of their safety cases (see
Chapter 7) has greatly extended its area of application. The practical
applications of this approach include: hazard operability studies
(HAZOPS), hazard analysis studies (HAZANS), probabilistic risk
assessment (PRA), technical safety audits, reliability and maintain-
ability studies (RAMS), human reliability assessment (HRA), cognitive
task analyses, ergonomie guidelines, databases, and the application
of decision support systems. Excellent accounts of the nature and
application of these tools can be found in a number of recent texts. 5
The Organizational Model
If the organizational model, the newest of the three, has a disci-
plinary link, then it would probably be with crisis management.
Although not always apparent to its practitioners, it owes its intellec-
226 Managing the Risks of Organizational Acciden ts
tual origins to two books. The first was Man-Made Disaster by the late
(and greatly missed) Barry Turner, published in 1978. 6 The second
major influence was Charles Perrow's Normal Accidents7 In retro-
spect, credit must also go to the Hon. Peter Mahon for his remarkable
report upon the Mt. Erebus tragedy that occurred in 1979. 8 As Neil
Johnston has pointed out, the Mahon Report was ten years ahead of
its time. 9 Most of the accidents that have shaped our current thinking
about organizational factors had yet to happen. As indicated in Chap-
ter 8, Mr Justice Moshansky's extensive report on the Dryden tragedy
has provided a more recent endorsement of the organizational ap-
proach. 10
The organizational model views human error more as a conse-
quence than as a cause. Errors are the symptoms that reveal the
presence of latent conditions in the system at large. They are import-
ant only in so far as they adversely affect the integrity of the defences.
The model emphasises the necessity for proactive measures of 'safety
health' and the need for continual reforms of the system's basic
processes. As such, it has much in common with Total Quality Man-
agement. Indeed, the organizational model deliberately blurs the
distinction between safety-related and quality-determining factors.
Both are viewed as important for increasing the system's intrinsic
resistance to its operational hazards. Both are seen as being impli-
cated in organizational accidents.
In many respects, the organizational model is simply an extension
of the engineering model and is in no way incompatible with it.
Human-machine mismatches are seen as being the result of prior
decisions in the upper echelons of the system. And these, in turn, are
shaped by wider regulatory and societal factors.
This book has presented a mixture of the engineering and organiz-
ational approaches, with a somewhat greater emphasis on the latter.
However, it is quite clear that both are necessary for understanding
the aetiology of organizational accidents and for limiting their occur-
rence. Where there is a conflict, it is between both of these models
and the largely person-directed approach of the traditional occupa-
tional safety professionals. However, these differences are often more
a matter of circumstance than of substance.
Primary Risk Areas
For any hazardous technology there are potentially four primary risk
areas. These will, of course, vary in significance from domain to
domain.
Reconciling the Different Approaches to Safety Management 227
• Personal injury or damage risks. These are associated with activi-
ties in which the workforce is in close contact with the hazards.
The unwanted outcomes are either injury to the worker or
limited damage to some asset. In neither case, however, does
this involve extensive damage to an installation or to the sys-
tem at large. Such events were described in Chapter 1 as
individual accidents because they affect either individual work-
ers or individual items of equipment.
• Risks due to errors committed by key front-line controllers. These
are most closely associated with systems (or subsystems) in
which control is centralized in the hands of a relatively few
individuals. In modern systems there will almost certainly be
some measure of automation involved in the control activity.
The unwanted outcome could be an organizational accident
though, as indicated earlier, it is unlikely that such an event
could arise as the result of a single error on the part of the
operator(s).
• Risks due to the insidious accumulation of latent conditions within
the maintenance, managerial and organizational spheres. Such risks
are closely associated with systems possessing several defences-
in-depth. As discussed earlier, the unwanted outcome is the
breaching or bypassing of critical defences, bringing hazards
(which need not necessarily cause physical harm) into damag-
ing contact with people and/or assets to produce losses. Here,
an entire installation or system could be destroyed. These are
the quintessential organizational accidents.
• Risks to third parties. These are risks that threaten the lives,
livelihoods and the physical and mental well-being of indi-
viduals not directly employed by the organization, as well as
the likelihood of losses and damage to their assets or to the
environment at large. Such 'third parties' would include pas-
sengers, patients, investors, taxpayers, those living in the
neighbourhood of a hazardous installation, or indeed anyone
adversely affected by the operation of a particular technology,
financial activity (for example, banking, insurance, pension fund
management and the like) or public service (for example, the
military, the police force and the like).
These risk types fall into two groups. Personal injury risks are closely
identified with individual accidents and the person model. The re-
maining three risk types are all associated with organizational
accidents and are the main concerns of both the engineering and the
organizational models.
228 Managing the Risks of Organizational Acciden ts
The Preponderance of Risks in Different Domains
In some measure at least, all of these risks are present in all hazard-
ous operations. In that sense, all three safety management models
are applicable. But some risks are more salient than others, and the
balance between the risks varies from domain to domain (see Table
10.1). Moreover, this preponderance is not fixed once and for all by
the nature of the domain, it can also vary with technological and
even societal developments. Advanced manufacturing techniques,
for example, have shifted safety concerns from the slips, lapses, trips
and fumbles of individual workers on the conventional production
line to the costly mistakes of the few key operators who programme
computer-driven machine tools. In hospitals, the main worries were
once the well-being of patients and the safeguarding of staff from
contact with diseases, but societal changes have now forced risk
managers to consider the dangers posed by the increasing number of
physical assaults upon healthcare workers.
The history of modern technology is rich in instances of risk man-
agers being caught with their eyes on the wrong ball. In transport
systems, for example, the traditional emphasis has been upon the
safety of the passengers or cargo, and on the risks posed by the
fallibility of those at the sharp end—the pilots, the train drivers, and
the ships' crews. Only relatively recently, for instance, have airlines
become aware of the risks associated with maintenance, or of the
enormous losses caused by personal injuries to ground-based staff—
amounting to $30 million per year in some large US carriers. It took
the Clapham Junction disaster to make British Rail aware of the risks
associated with technical work on the signalling system. And only in
its aftermath did they begin to record the personal injury accidents
sustained by their infrastructure staff (for example, shunters and track
workers). Yet this was an organization with a 160-year tradition of
safety innovation in both the engineering and the human spheres
(where human equated to driver or signalman). Only in the last
decade has the nuclear power industry started to appreciate the risks
associated with low-power and shutdown conditions. The training
and procedures for control room operators were almost exclusively
geared to handling emergencies in the more typical full-power situation.
It took the King's Cross Underground tragedy to reveal that stations,
as well as trains, could be dangerous places for passengers and staff.
And it took the Cullen Inquiry to make many North Sea oil and gas
operators aware of formal safety assessment techniques, though they
had long been a staple item on the risk management agenda for the
military and for the nuclear power and chemical process industries.
Risk is a function of both the likelihood of an event occurring and
of the possible extent of its bad outcome. The estimates given in
Reconciling the Different Approaches to Safety Management 229
Table 10.1 vary widely in the ways in which a high (or very high) risk
rating can be achieved. In the personal accident column, for example,
the harmful consequences of an event will usually be limited to an
individual, to a small group or to their immediate surroundings.
Here, high risk ratings are assigned more on the basis of likelihood
than outcome—and this, of course, must also depend on the num-
bers of potential victims. But the reverse is true for, say, the 'very
high' rating given to the third-party risks associated with nuclear
Table 10.1 Comparison of estimates of the four risk types across
domains
Domain of Personal Errors of key Latent Third-party
operation injury risks operators conditions risks
Nuclear very low high high very high
power (normal state)
generation
Chemical low-moderate high high very high
process (normal state)
plants
Commercial moderate-high high high very high
aviation (ground staff)
Advanced very low high high variable
manufacturing
Oil exploration high high high very high
and production
Marine high high high very high
Railways high high high high
(infra-structure)
Construction very high moderate-high high high
Mining very high moderate-high high low-moderate
Medicine moderate very high high very high
Financial very low very high high high
services
Sports stadiums
and crowd
control high high high high
230 Managing the Risks of Organizational Acciden ts
power generation. Here, the likelihood of a major release of radioac-
tive materials is exceedingly small but its adverse consequences, in
the worst case, are very bad indeed.
Even if readers do not agree with the particular risk estimates
given in Table 10.1, one thing remains hard to dispute—there is less
variability between domains for the risks associated with latent con-
ditions than for the other risk types. All domains must be assessed as
at least 'high' in this regard. The reasons for this are not difficult to
find. The further one moves from a domain's front-line operations,
the more alike organizations become. Technical systems of whatever
kind inevitably share a large number of common processes: forecast-
ing, planning, scheduling, budgeting, specifying new equipment (and
sometimes designing and building it), operating, maintaining, man-
aging, communicating and the like. And it is within these processes
that the seeds of future disasters are sown—irrespective of the do-
main. In summary, all hazardous domains are threatened by
organizational accidents, but their individual accident risks are ex-
tremely variable. Nevertheless, the person model remains the most
widely used approach to safety management.
In addition there is a marked asymmetry of application between the
person model on the one hand, and the engineering and organiz-
ational models on the other. Whereas the latter two approaches can be
usefully applied to limiting personal injury risks (and hence prevent-
ing individual accidents), the person model is not at all helpful in
dealing with key operator error risks, latent conditions or third-party
risks—all of which fall squarely into the province of organizational
accidents. Indeed, its predominance in the minds of many technical
managers is a definite barrier to improved safety. When applied to the
appropriate risks, both the person approach and its tools have shown
themselves to be valuable. The difficulty lies in the failure on the part
of some managers to recognize that there are other types of risk and
other tools to deal with them. When all you possess is a hammer, then
almost everything looks like a nail. Or, to put it more directly, when
the person model is the only approach with which you feel comfort-
able, then every problem seems to be a person problem.
Why is the person model so seductive? It is worthwhile taking a
look at some of the reasons for the widespread appeal of the person-
oriented approach to safety management.
• It has been around a long time. Most senior managers grew up
with it and are comfortable with its doctrines. For many man-
agers, management equates to 'people management' so the
person-oriented approach fits the job description.
• Some organizations, notably Du Pont, have been conspicuously
successful in achieving very low LTIF rates. In 1990, for exam-
Reconciling the Different Approaches to Safety Management 231
pie, their worldwide and European lost-time injuries per 200 000
exposure hours (involving more than one day's absence from
work) were 0.032 and 0.023, respectively. That is 0.16 and 0.12
per million manhours, or 0.32 and 0.23 per 1000 employees. Du
Pont is justifiably seen as the market leader in this regard, and
a number of major companies have sought to emulate their
achievements, particularly in the domain of oil exploration and
production. These numbers provide a very clear target to aim
for, and such well defined goals are welcomed in the otherwise
rather nebulous business of safety management.
It is much easier to pin the legal responsibility for an accident
on the unsafe acts of those at the 'sharp end'. The connection
between these individual actions and the disastrous outcome is
far more readily demonstrated than are any possible links be-
tween earlier management decisions and the accident—see, for
example, the failed prosecution of the managers implicated (by
the Sheen Inquiry) 11 into the capsize of the Herald of Free Enter-
prise.12 In that case, Mr Justice Turner directed the jury to acquit
the defendants even before the defence gave evidence. He said
that there was no direct evidence that a 'reasonably prudent
person' occupying the position of any of the five defendants
would have perceived the risk was obvious or serious. It was
not enough, he added, to show failures; the defendants had to
have been reckless. There was no question, he said, of making a
corporation guilty of manslaughter by aggregating the acts of
individuals whose actions were not themselves reckless. In this,
English law runs counter to a 1988 Council of Europe recom-
mendation that acts of individuals should be accumulated when
deciding whether a corporation had committed an offence.
As mentioned in Chapter 7, we place a high value on personal
freedom, or the illusion of free will. Since we also impute this
to others, we have a strong tendency to assume that the unsafe
acts were committed because the individuals in question chose
an unsafe course of action. This, as indicated earlier, is com-
pounded by the fundamental attribution error—the universal belief
that bad acts are committed by bad people.
The person model also accords very closely with the way in
which people try to establish cause. This is not the place to get
embroiled in the philosophy of causation, but it is worth noting
what the experts on jurisprudence have had to say on the mat-
ter:
A causal explanation of a particular occurrence is brought to a
stop when it has been explained by a deliberate act, in the sense
that none of the antecedents will count as the cause of the
232 Managing the Risks of Organizational Acciden ts
occurrence. A deliberate human act is therefore most often a
barrier and a goal in tracing back causes ... it is often something
through which we do not trace the cause of a later event and
something to which we do trace the cause through intervening
causes of other kinds.13
• Finally, there are two other factors that help to clinch the pri-
macy of the person model in many people's minds. At an
individual level, we gain a good deal of emotional satisfaction
from blaming someone—rather than something—when things
go wrong. And, at the organizational level, there are obvious
financial and legal benefits in being able to uncouple indi-
vidual fallibility from corporate liability. Either way, there are
advantages in being able to limit culpability to specific people.
Can Personal Injuries Predict Organizational Accidents?
To remain true to the basic arguments expressed in this book, we
must readily acknowledge that both individual and organizational
accidents have their roots in upstream organizational and manage-
rial factors. Both types of event are due to latent conditions.
It is not hard to find examples of personal injuries having organiz-
ational causes. In his excellent book, An Engineer's View of Human Error,
Trevor Kletz14 divides his chapters into two groups—those in which
personal injury accidents were due to individual failings (slips, lack of
ability, lack of motivation and so on) and those arising from organiz-
ational shortcomings. Among the latter are accidents that could have
been prevented by better training or instructions, better design, better
construction, better maintenance and better methods of operation.
If both individual and organizational accidents have their roots in
common systemic processes, then it could be argued that LTIF rates—
or comparable personal injury statistics—are indicative of a system's
vulnerability (or resistance) to organizational accidents. The number
of personal injuries sustained in a given time period must surely be
diagnostic of the 'health' of the system as a whole. Unfortunately,
this is not so. The relationship is an asymmetrical one. An unusually
high LTIF is almost certainly the consequence of a 'sick' system that
could indeed be imminently liable to an organizational accident. But
the reverse is not necessarily true. A low LTI rate (of the order of 2-5
per million manhours)—which is the case in many well run hazard-
ous technologies—reveals very little about the likelihood of an
organizational accident.
There are two parts to this problem. First, such low and often
asymptotic LTIFs comprise more noise than signal. In one accounting
Reconciling the Different Approaches to Safety Management 233
period, for instance, a major part of all the recorded lost-time injuries
could reflect only that a member of the administrative staff fell off a
bicycle on an icy patch outside the office building and fractured a
wrist In the case of the oil and gas business, for example, what does
this say about the integrity of an offshore installation? Nothing. And
this brings us to the second problem. For the many concerned or-
ganizations who have reduced their personal injury events to what
could be an irreducible minimum (given the ever-present hazards of
the business), lost-time injuries are no longer any kind of indication
of where the real dangers lurk. At this point, non-injury events—
such as the number of leaks of combustible materials—are much
more diagnostic of the integrity of the system as a whole. It is these
precursor events, along with regular checks upon the quality of the
underlying processes (see Chapter 7), that show where the high-
potential risks are located.
Top-level commitment is a prerequisite for effective risk manage-
ment, but it is not sufficient. Indeed, a blinkered commitment to the
person model can be counterproductive. For example, a visitor to a
drilling rig (or a comparable installation) is usually confronted by a
large sign declaring that this site has had so many thousands of
hours without a lost-time injury—quite often these are near-thresh-
old values such as 999 970 hours. While such signs are clearly designed
to motivate the workforce to maintain their safe working practices,
they also convey two other, less helpful, messages. The first is that
this is a safe place—which it is not (as a Texan driller once told me,
'There ain't a damn thing on this site that can't hurt you'). The
second message is 'Woe betide the supervisor that reports a lost-time
injury now'. As argued in Chapter 6, commitment needs to be com-
bined with the other two 'Cs'—competence and cognisance. Together,
they add up to an intelligent and informed awareness both of the
varieties of risk and of the different ways to combat them.
Latent Conditions: The Universal Risk
Regardless of the personal hazards of the workplace, all organiz-
ations are vulnerable to latent conditions and to the breakdown of
their defences. In this respect, the organizational model presented
here, though derived largely from a study of physically damaging
events, has relevance to all domains. But this is not always appreci-
ated. In part, the problem is due to the close association in people's
minds between safety and personal injury risks—if their system is
not subject to physically harmful events, then they tend to be pro-
foundly uninterested in anything that has 'safety' in the title. As this
book has sought to demonstrate, however, both physical and econ-
234 Managing the Risks of Organizational Acciden ts
omic disasters have common causal pathways. The same basic prin-
ciples and countermeasures are as applicable to a bank or an insurance
company as they are to chemical process plants and oil companies.
Has the Pendulum Swung too Far?
The earlier criticisms of the person model should not be taken as
indicating that the organizational approach is problem-free. As dis-
cussed at several points throughout this book, the last 20 years have
seen an ever-widening search for the origins of major accidents. In-
vestigators and analysts have backtracked from the bad outcome,
through the proximal unsafe acts (if identified), the workplace and
organizational factors to the regulators and the system as a whole—
and, in some cases, to the economic climate and the nature of the
society at large. Figure 10.1 illustrates how some of these major events
stand with regard to this extended causal fallout.
The question posed in the heading of this section is prompted by a
suspicion that the pendulum may have swung too far in our present
attempts to track down possible error and accident contributions
that are widely separated in both time and place from the events
themselves. The relative worth of the various causal categories can
Pi er
P A Challenger
Young, NSW f
Figure 10.1 Map of the 'causal fallout' from recent organizational
accidents
Moving from the centre outwards, the 'bull's eye'
represents the front-line individuals, the 'inner' relates
to the workplace, the next circle corresponds to organ-
izational factors, the next to the regulators and the
overall system, and the outer ring corresponds to societal
factors.
Reconciling the Different Approaches to Safety Management 235
be evaluated by reference to three questions central to the pursuit of
system safety. To what extent does a consideration of individual,
contextual, organizational, systemic and societal factors add value
(see Figure 10,2):
• to our understanding of the causes of accidents and events?
• to our ability to predict the likelihood of future accidents and
events?
• and, most importantly, to our remedial efforts to reduce their
future occurrence?
Explanatory Predictive Remedial
value value value
Individuals
Workplace
Org. processes
Org. culture
Regulation
Society
Relative values (speculative)
Figure 10.2 The relative (highly speculative) values of various
types of possible causal factors for the explanatory,
predictive and remedial goals
Individual factors alone have only a small to moderate
value for all three goals and that, overall, workplace and
organizational factors contribute the most added value.
There are diminishing returns on more remote influ-
ences, particularly with regard to countermeasures and
risk management.
While it is clear that the present situation represents a significant
advance over knee-jerk 'human error' attributions, some concerns need
to be expressed about the theoretical and the practical utility of this
ever-spreading quest for contributing factors. We seem to have reached,
or even exceeded, the point of diminishing returns, particularly when
it comes to risk management. We also need to find some workable
middle ground that acknowledges both the psychological and the
contextual influences on human performance, as well as the interac-
tions between active failures and the latent conditions that serve, on
rare occasions, to breach the system's defences. Chapter 5, for instance,
236 Managing the Risks of Organizational Acciden ts
presented a strong case for giving much closer attention to mainte-
nance activities. Models of accident causation can only be judged by
the extent to which their applications enhance system safety. The econ-
omic and societal shortcomings, identified—for example—by Legasov
(see Chapter 1), are beyond the reach of system managers. From their
perspective, such problems are given and immutable, but our main
interest must be in the changeable and the controllable.
Some Problems with Latent Conditions
In earlier accounts, 15 these delayed-action 'time-bombs' were de-
scribed as latent errors or latent failures. But in the causal sense, the
term 'condition' is much more appropriate. Hart and Honore distin-
guished between 'causes' and 'conditions': causes are what 'made
the difference', 'Mere conditions', on the other hand, are:
... just those [things] that are present alike both in the case where
accidents occur and in the normal case where they do not; and it is
this consideration that leads us to reject them as the cause of the
accident, even though it is true that without them the accident would
not have occurred ... to cite factors that were present both in the case
of the disaster and in normal functioning would explain nothing: such
factors do not 'make the difference' ... ,u
In the case of a fire, for example, a 'mere condition' would be the
oxygen in the air. In a railway accident, 'they will be such factors as
the normal speed and load and weight of the train and the routine
stopping and acceleration'. Although the latent conditions we have
considered in this book are not quite of this character, they are present
within the system regardless of whether or not an accident occurs.
All systems harbour latent conditions; an accident simply makes
them manifest. In short, their presence does not discriminate be-
tween normal states and bad events. Moreover, the extent to which
they are revealed will depend not so much upon the 'sickness' of the
system, but on the resources available to the investigator. The more
exhaustive the inquiry the more latent conditions it will uncover.
So we are left with the following conclusion: only proximal events—
unsafe acts and local triggers—will determine whether or not an
accident occurs. If that is the case, why do we need to consider these
more distal factors at all? There are three compelling reasons why
latent conditions are important:
• They undoubtedly combine with local factors to breach de-
fences. In many cases, they are weakened or absent defences.
Reconciling the Different Approaches to Safety Management 237
• Resident 'pathogens' within the workplace and the organiz-
ation can be identified and removed before the event.
• Local triggers and unsafe acts are hard to anticipate and some
proximal factors are almost impossible to defend against (for
example, forge tfulness, inattention, and the like).
Thus, despite their inherent problems, identifying and eliminating
latent conditions proactively still offer the best routes to improving
system 'fitness'. But it has to be a continuous process. As one prob-
lem is being addressed, others will spring up in its place. There are
no final victories in the safety war.
The Price of Failure
In Chapter 5 we touched upon the costs of maintenance failures in
commercial aviation. Since the issues discussed in this chapter were
largely prompted by the oil industry, we will focus here upon the
costs of accidental losses as they affect this domain. Another good
reason for doing this is that the process of 'loss costing' has probably
been carried further in this area than elsewhere.
Table 10.2 The financial losses incurred by major events in the
petrochemical industry
Event Country Financial loss
Piper Alpha United Kingdom $2.5 billion*
Exxon Valdez USA $3.5 billion
Phillips 66 Pasadena USA $1.3 or $2.1 billion
Sleipner A Norway $300 million
Saga 2/4-14 Norway $250 million
La Mede France $260 million
Sodegaura Japan $171 million
G rangemouth United Kingdom $100 million
Croatzcoalcas Mexico $98 million
Pembroke United Kingdom $79 million
Dhaka Bangladesh $76 million
Ras Tan ura South Africa $35 million
* This does not include the incalculable cost of 167 fatalities. The HSE estimate
the total cost of Piper Alpha (less these unquantifiables) at £2.066 billion. More-
over, the associated disruption to North Sea production knocked at least a
percentage point off the growth rate of output during the affected period.
** The higher estimate was given by Dan Stover of Brown & Root Energy Services.
238 Managing the Risks of Organizational Acciden ts
Table 10.2 shows the estimated financial costs associated with a
number of major events in the petrochemical domain. The data were
provided by Eric Brandie, the Loss Prevention Manager for Chevron
UK Ltd. 17
A joint loss costing study was carried out by the HSE and Chevron
covering 13 weeks typical operations on one of the latter's platforms
in the North Sea. Although there were no serious incidents during
that period, the costs accruing from a whole range of minor classified
incidents amounted to £1 million. Projected on a field-wide annual
basis, this rose to £4 million—equivalent to the shutdown of a plat-
form for one day each week throughout the year.
In 1993, the HSE estimated that for every £1 of costs recoverable
through insurance, another £5 to £50 are added to the final bill through
a wide variety of other financial losses. Like an iceberg, for every
visible pound (recovered from the insurers), there are up to 50 times
that sum below the surface in indirect costs. These include:
• product and material damage
• plant damage
• building damage
• tool and equipment damage
• legal costs
• expenditure on emergency supplies
• clearing site
• production delays
• overtime working
• investigation time
• supervisors' time diverted
• cost of panels of inquiry
• clerical effort.
To these should also be added such intangibles as damage to the
company's reputation (probably reflected in the share price), loss of
business, recruitment difficulties and a general lowering of morale.
Accidents do not only cost lives, they are also economically disas-
trous. Very few organizations can sustain these levels of financial
loss.
The real question, of course, is not what safety costs us, but what it
saves. This book has described how organizational accidents arise
and has outlined practical measures for reducing the likelihood of
their occurrence. But such accidents can afflict even the best run
systems. It is therefore not enough simply to plan for their preven-
tion, it is also essential to plan for post-accident business recovery in
order to minimize these huge losses. Dan Stover 18 gives us an exam-
ple of what an effective loss recovery procedure can achieve. The
Reconciling the Different Approaches to Safety Management 239
consequences of the massive Bishopsgate bombing in the City of
London in 1993 were shared by many organizations. Among these,
the Saudi International Bank, was open for business as usual the
following Monday. This bank had in place a well conceived loss
recovery programme that had been tested by the bombing in the
nearby St Mary Axe. The total cost of this bombing was estimated at
£1.5 billion.
Finally, a sobering thought: four out of five organizations suffering
a major disaster without recovery procedures never reopen for busi-
ness. Furthermore, 80 per cent of disaster recovery plans do not work
the first time. 19 Recent studies 20 have shown that crisis-prepared or-
ganizations plan for at least five different types of crisis, and the
crisis plan's are closely linked to business recovery plans. In addition,
such organizations have a flexible and adaptive structure and are
low on both rationalizations and denial. As Denis Smith of Durham
University Business School put it, 'Any denial of the mainstream
nature of crisis management is a manifestation of a crisis-prone cul-
ture and, as such, becomes a suitable case for treatment'. 21
The Last Word
In this chapter we have sought to reconcile three different approaches
to safety management: the person model directed at reducing per-
sonal injury events; the engineering model focusing on the
human-machine interface and system reliability; and the organiz-
ational model that deals with the integrity of defences and the broader
systemic factors. Each has its own metrics and countermeasures. To
the extent that any domain is exposed to the risks of both individual
and organizational accidents, all of these models have their part to
play in the overall safety management programme.
Such conflicts that exist arise mainly from the predominance of the
person model in situations that demand a closer consideration of
technical and systemic factors. Whereas the engineering and organ-
izational models can be usefully applied to the reduction of individual
accidents, the person model alone (and especially the mindset that
goes with it) has very limited value in domains where the risks are
mainly derived from the insidious accumulation of latent conditions
and their rare conjunctions with local triggers to defeat the multi-
layered defences. This does not mean, of course, that we should
ignore the personal injury risks or the behaviour of individuals and
teams. But it does mean that risk managers should be aware of
the broader systemic origins of organizational accidents and of the
variety of techniques now available to thwart their development.
Effective risk management requires the application of different counter-
240 Managing the Risks of Organizational Acciden ts
measures targeted at different levels of the system at the same time—
and all the time. It takes only one organizational accident to put an
end to all worries about the bottom line.
Notes
1 I am particularly grateful to Andy Pearce of Shell Expro, Richard Clark of BP
Exploration and Rob Pinchbeck of Atlantic Power and Gas for making these
and other valuable contacts with the professionals possible.
2 When a work-related injury results in some absence from work, usually in
excess of 1 - 2 days.
3 D.A, Lucas, 'Wise men learn by others' harms, fools by their own: organiz-
ational barriers to learning the lessons from major accidents', Paper given to
the Safety & Reliability Society Symposium on 'Safety and Reliability in the
'90's: Will past experience or prediction meet our needs?', 1 9 - 2 0 September,
1990, Altrincham, Manchester. See also D.A. Lucas, 'Understanding the human
factor in disasters'. Interdisciplinary Science Reviews, 17, 1992, pp. 185-90. See
also Center for Chemical Process Safety, Guidelines for Preventing Human Error
in Process Safety, (New York: Center for Chemical Process Safety of the Ameri-
can Institute of Chemical Engineers, 1994), pp. 4 4 - 1 0 1 .
4 F. Bird Jr., Practical Loss Control Leadership, (Loganville, GA: International Loss
Control Institute, 1969).
5 E. Hollnagel, Human Reliability Analysis: Context and Control, (London: Aca-
demic Press, 1993); Center for Chemical Process Safety, op. cit. A.I. Glendon
and E.F. McKenna, Human Safety and Risk Management, (London: Chapman &
Hall, 1995); B. Kirwan, A Guide to Practical Human Reliability Assessment, (Lon-
don: Taylor & Francis, 1994), E,M. Dougherty Jr. and j.R. Fragola, Human
Reliability Analysis: A Systems Engineering Approach with Nuclear Power Plant
Applications, (New York: Wiley, 1988).
6 B. Turner, Man-Made Disaster, (London: Wykeham, 1978)—a second edition is
currently being prepared by Dr Nick Pidgeon of the University of Wales,
Bangor.
7 C. Perrow, Normal Accidents: Living with High-Risk Technologies, (New York:
Basic Books, 1984).
8 Report of the Royal Commission into the Crash on Mount Erebus, Antarctica, of a
DCIO Aircraft Operated by Air New Zealand Limited, (Wellington, 1981). See also
G. Vette, Impact Erebus, (Wellington: Aviation Consultants Ltd, 1983) and S.
McFarlane, The Erebus Papers, (Auckland: Avon Press, 1991).
9 D. Maurino, et al., Beyond Aviation Human Factors, (Aldershot: Avebury, 1995),
pp. 3 0 - 5 6 .
10 Mr Justice V.P. Moshansky, Commission of Inquiry into the Ontario Crash at
Dryden, Ontario. Final Report, Vol. 1 (Ottawa: Ministry of Supply and Ser-
vices, 1992).
11 Mr Justice Sheen, M.V. Herald of Free Enterprise. Report of Court No. 8074, (De-
partment of Transport, London: HMSO, 1987).
12 N. Cohen, 'Zeebrugge manslaughter prosecution collapses', The Independent, 20
October, 1990.
13 H.L.A. Hart and A. Honore, Causation in the Law, (2nd edn), (Oxford: The
Clarendon Press, 1985), p. 43.
14 T.A. Kletz, An Engineer's View of Human Error, (Rugby: The Institution of Chemi-
cal Engineers, 1985).
Reconciling the Different Approaches to Safety Management 241
15 J. Reason, Human Error, (Cambridge: Cambridge University Press, 1990), ch. 7,
16 H. Hart and A. Honore, op. cit., p. 34.
17 E.E Brandie, T h e cost of accidents—an operator's view', Paper given to the
1996 Safety Conference 'People & Changes, Costs & Challenges', Institute of
Petroleum, London, 26 September 1996.
18 D. Stover, The costs of failure. Proceedings of the 1996 Safety Conference, Institute
of Petroleum, London, 26 September 1996.
19 Ibid.
20 I, Mitroff, T. Pauchant, M. Finney and C. Pearson, 'Do some organizations
cause their own crises? The cultural profiles of crisis-prone vs. crisis-prepared
organizations', Industrial Crisis Quarterly, 3 , 1 9 8 9 , pp. 2 6 9 - 8 3 .
21 D. Smith, 'Crisis management and strategic management', Advances in Strategic
Management, 8 , 1 9 9 2 , p. 268.
Index
Accident analysts 15 mean numbers of problems
Accident inquiries 129,171 contributing to 116
Accident investigators 52 Aircraft maintenance system
Accident prevention 52-3 active failures and latent condi-
Accident rates 108, 111 tions 27
Accident reports 127 case study 22-8
Accident trajectory 11-13 ALARP approach 175
Accidents Alcohol 209, 210, 211
analysis 18 Alidair v. Taylor 2 0 7
are they necessary? 123-4 American Flight 191, Chicago
investigation 18 O'Hare 88
Actions Anxiety-avoidance 193
consequences of 205, 208 Apollo 13 8 6 - 7
intention of 205, 208 Armour as dangerous defence 41
triggered by intention 205 Ashby, Ross 74, 83 nlO
Active failures 10-11 Associated error probabilities and
Activities and their relative likeli- generic tasks 143-6
hood of performance problems Auftragssystem 217
91-2 Aurora Mishap Management
Activity space 69 System (AMMS) 213
Added protection versus improved Australian Civil Aviation Authority
production 6 (ACAA) 165,167,168
Administrative controls 61-4 Automated systems 8, 42-6
Aero Commander 167 Automatic control systems 43, 45, 69
Air Accident Investigation Branch Automatic mode of control 69
116 Aviation problems 43
Air disasters 56 Aviation Safety Reporting System
Air Ontario Fokker-28 crash, (ASRS) 197, 198, 201
Dryden, Ontario, case study
163-5 Bacon, Sir Francis 39 nl
Air Operators Certificates (AOC) Bainbridge, Lisanne 43, 59 n3
166 Bamford, M. 189 n28
Air Safety Reports (ASRs) 198, 200 Baring, Peter 32, 33
Air Services Australia 168 Barings Banking Group 13
Air traffic control 213 case study 28-34
Airbus Industrie 42 Barings Futures (Singapore) Pte
Aircraft accidents 52, 58, 79 Limited 29
243
244 Managing the Risks of Organizational Acciden ts
Barings Investment Bank 29 Clark, Richard 240 nl
Barings Securities Limited 29 Clean Air Act Amendments 176
Barriers 6 Cleveland, R.J. 124 n4
BASIS 201 Clinton, A. 189 n28
Bate, P. 221 n7 Cockpit Voice Recorder (CVR) 56
Bellamy, L.J. 60 n20 Cognisance 113
Bendell, A. 59 n9, nlO Cognitive processes involved in
Benson, Miles 155 nl6 omissions 96
Bentley, P. 154, n8 Cognitive task analyses 225
Bhopal disaster 12, 54, 89 Cohen, A. 124 n4
Bird, Frank 224, 240 n4 Cohen, H. 124 n4
Blame cycle 127-8 Cohen, N. 240 nl2
Boff, K. 20 n5 Cohen, William S. 169
Bolt-and-nuts example 93 Commitment 113
Booth, R. 221 n i l Communication problems 135
Bourgeois, L.J. 222 n40 Communications 166
Brandie, E.F. 241 n l 7 Comparative risk approach 175
Brereton, Mr 167-8 Competence 113
British Airways 197-203 Compliant action 72-3
British Airways Safety Informa- Computerized control systems 45
tion System (BASIS) 197-200 Confidential Human Factors Re-
British Airways Safety Services porting Programme 199
201-3 Confidentiality 197
British Rail Rule Book 49-50 Conflicting goals 165
Brown, S.C. 154 n5 Consequences of actions 205, 208
Bryant, A. 189 n l 9 Consolini 214, 215, 222 n33
Bureau of Air Safety Investigation Contracting Out and Deregulation
(BASI) 165 Bill 180
Bureaucratic culture 38 Control 166
Bureaucratic organizations 64 Control of Industrial Major Hazards
(CIMAH) Regulations 178,180
Control of Substances Hazardous to
Causal factors 235 Health (COSHH) Regulations
Causal independence 54 178-9
Central Research Institute for the Cooper, H.S.F. 188 nl
Electrical Power Industry Corporate Culture 192
(CRIEPI) 92 Correct compliance 75
Challenger spacecraft explosion 12, Correct improvisation 76
173 Correct/incorrect actions 73-4
case study 157-60 Correct performance 75
Chappell, Sheryl 197, 200, 202, 221 Correct violation 75
nl2, nl8, nl9 Crash helmets 173
Chernobyl reactor disaster 11,15- Crew Resource Management (CRM)
16,18, 76-7 130
Civil Aviation Authority 168 Crichton, Michael 105 n l 9
Civil Aviation Safety Authority Crisis management 225
168 Criticality question 91-2
Clapham Junction railway disaster Cullen, Lord 104 n7,154 n8.161-3,
13, 90, 211 189 n6, n29, n30, n31, n33, n35
Index 245
Cullen Report 138,173,179 Ergonomie guidelines 225
Cultural strength 193 Erroneous performance 75
Error containment 125
Damage risks 227 Error-enforcing conditions 134,136
Dangerous defences 41-60 Error management 125-55
Databases 225 components 125
Davis, R.A. 105 n20 comprehensive 130
Dawson, S. 189 n28 problems associated with 126
Deal, Terrence 192, 221 n3 resources 130
Decentralization of authority 217 situational approach 129
Decision support systems 225 tool box 129-32
Defence-related ironies and para- Error reduction 125
doxes 42 Error-producing conditions (EPCs)
Defences 21-40,135 142,146
functions 7 Error-producing factors 130-1
hard 8 , 1 9 Errors 54, 85, 226
hazards and losses 2 as consequences not causes 126-7
nature and variety of 7-8 types 72
neglecting 6 Estonia disaster 180
soft 8 , 1 9 European Commission Directive on
'Swiss Cheese' model of 9 Major Accident Hazards 178
Defences-in-depth 8, 19, 28, 54-6 Evans, Leonard 20 n3
dynamic nature of 9 Expected maintenance load 100
ideal and reality for 9 External controls 61-2
Deliberate weak links 57-8
Deming, W. Edwards 47 FAA Advisory Circular 198
De minimis approach 175 Face-to-face communication 217
Denning, Lord 207 Factories Act Model 176
Deregulation ideology 180 Failure costs 237-9
Design 134 Failure modes and effects analysis
Deterioration characteristics 101 (FMEA) 130
Deviant performance 64 Failure State Profile 137
Disciplinary proceedings 197 False alarms 56-7
Doran, J.A, 155 n l 6 Fay, Stephen 40 n9, n i l , n l 2 , n l 4 , n l 5
Dougherty, E.M. Jr. 240 n5 Federal Aviation Administration
Drugs 209-11 (FAA) 168-9,198
Du Pont 230 Feedback output control 63, 64
Duncan, K. 59 n3,105 n l 7 Feedforward control devices 53, 62,
64
80:20 problem 42 Feigenbaum, Armand 47
Eisenhardt, K.M. 222 n38 Fennell, Desmond 160,188 n4
Elliott, D. 20 n8 Financial losses 237
Embrey, D. 155 n l 4 Finch, D.F. 83 n9
Emergency Planning i r : C _- rnney, M. 241 n20
nity Right to Know Act I - :-r r'—St Futures 31
176 rischhoft, Baruch 40 n20
Engineering model 115 Fisher, S. 221 nl7
Engineer's View ofHurr-zr £ — - Fiske, S.T. 154 n3
232 [Link] culture 196, 213-18
246 Managing the Risks of Organizational Acciden ts
Flight Data Recorder (FDR) 56,199 Hazard and Effects Management
Flight deck automation 44 Process (HEMP) 152,153
Flight management system (FMS) Hazard and operability studies
44-5 (HAZOPs) 130, 225
Flixborough 87 Hazard awareness 218
Fhjiuise 201 Hazardous installations 180
Football stadium crushes 12 Hazardous substances 179
Forbidden acts 51 Hazardous systems 147
Formal Safety Analyses 146 Hazardous technologies 42, 51, 56,
Formal Safety Assessments (FSAs) 85, 86, 91,146,191, 207, 218, 226
180 Hazards 28, 74, 76
Fragola, J.R. 240 n5 containment and elimination 7
Free, R. 59 n i l , nl2, 83 n8 defences and losses 2
Frequency question 91-2 natural and manmade 6
Frost, P.J. 39 n2 Health and safety at work 177
Fumbles 71 Health and Safety at Work Act 1974
Fundamental attribution error 126, 173,176-9
127, 231 Health and Safety Commission
Fuse pins 57-8 (HSC) 177,180,194
Health and Safety Executive (HSE)
General Failure Types (GFTs) 132-4, 177,179,180
136-8,152 Health surveillance 179
Generative culture 38 Hefley, W. 59 n5
Generic tasks and associated error Helmreich, Robert 154 n7, 220, 222
probabilities 143-6 n47
Generic violation behaviours 145 Herald of Free Enterprise 12, 231
George, J.M. 222 n31 Hidden, A. 104 n8
Giles, L. 83 n l 5 High-reliability organizations
Gill, J. 82 nl (HROs) 37, 213-16, 218
Ginna event 53 Hofstede, Geert 194, 220, 221 n9,
Gladwell, Malcolm 188 n2 222 n46
Glendon, A.I. 154 n6,240 n5 Hogan, B. 206, 221 n25
Goal conflicts 135 Hogberg, Lars 221 nl
Graaf, G.C. van der 155 nl6 Hollnagel, E. 20 n3,154 n6, 240 n5
Graeber, R.C. 105 n22 Honore, A. 236, 240 nl3, 241 nl6
Groeneweg, Jop 39, 40 n21 Hopkin, D. 4 0 n l 9
Gruneberg, M. 105 n l 7 Home, A. 82 n4
Guastello, S.J. 221 n23 Horse kicks 108-10
Housekeeping 134-5
Haddon, W. 124 n2 Howard, R.W. 124 nl
'Hands on' question 91-2 Hughes, D. 59 n4, 59 n7
Hansman, R. John 59 n7 Human actions, core elements 205-6
Hardware 134 Human behaviour 49,107,128-9
Harle, Peter 40 n l 7 Human contribution 61-83
Hart, H. 236, 240 nl3, 241 nl6 Human controllers 8
Hawes, Tony 32 Human elements 18
Haynes, A1 79, 83 nl6 Human engineering 225
Hazard analysis studies (HAZANS) Human error 61, 71,126, 226
225 Human error analysis (HEA) 130
Index 247
Human error assessment and Japan Air Lines, Flight JL 123,
reduction technique (HEART) Mount Osutaka 89
142-6 Job, M. 60 n23,104 n4, n6
Human factors 61-2 Johnson, P. 82 nl
improvements 85 Johnston, Neil 39 n5,154 n7, 208,
Human failure probabilities 147 210, 222 n29, 226
Human failures 42 Juran, Joseph 47
Human fallibility 129 Just culture 195, 205-13
Human-machine interface 225
Human performance 64 Kahwajy, J.L. 222 n40
and its associated errors 91 Kanki, B. 154 n7
problems 85 Kaufman, L. 20 n5
Human reliability analysis (HRA) Keegan, John 59 nl
130 Kelly, A. 105 n23
Human reliability assessment Kelly, J. 59 n9
(HRA) 225 Kemeny, J. 60 nl8,104 n3
Kennedy, Ailan 192, 221 n3
Illusion of free will 127 Key-operator errors, risks due to
Implementation level 147 227
Impossible accidents 39 King's Cross Underground Station
Improved production versus added fire, case study 160-1
protection 6 Kirwan, B. 154 n6, 240 n5
In Search of Excellence 192 Kjellen, U. 124 n4
Incident reporting schemes 118-19 Klein, D. 124 n2
Individual accidents 1,18,173,194, Kletz, Trevor 104 n2, 232, 240 n l 4
223—4 Knowledge-based levels 68-70
Individual event 19 Knowledge-based mistakes 91
Inflight engine shutdowns (IFSDs) Korean War 216
94,103 Kompfer, P. 83 n9
Influence Diagram Approach (IDA)
146-9 La Porte, Todd 213, 214, 215, 222
Influencing factor level 147 n33
Informed culture 194,195 Lapses 71, 91, 209
Installation, vulnerability 93-4 Latent conditions 10-11, 36
Institute of Nuclear Power Opera- risks due to 227, 233-4, 236-7
tions (INPO) 92, 95 Lawton, R. 82 n2
Intention of actions 205, 208 Learned helplessness 193
Intermittent feedback loop 64 Learning culture 196, 218-19
Internal controls 61-2 Learning disabilities 219
International Air Transport Associa- Lee, R. 39 n5
tion 16 Leeson, Nick 28-34, 40 n8, n l 3
International Atomic Energy Lefcourt, H.M. 154 n5
Agency 194 Legasov, Valeri 15-16
International Civil Aviation Organi- Legislation 175,180
zation 16,116 and regulation 172-3
Investment in safety 123 Leplat, J. 59 n3
Ishikawa, Kaoru 47,154 n2 Lihou, D.A. 60 n20
Lihou, S.J. 60 n20
Janney, Eli J. 172 Line investigation 151
248 Managing the Risks of Organizational Acciden ts
Line maintenance 141 Mixed feedback and feedforward
Local workplace factors 121 controls 63
Lockwood, C.R. 83 n9 Mode confusions 46
London Underground fire 12,160-1 Morehouse, W. 104 n5
Losses, hazards and defences 2 Monarch 165-8
Lost-time injuries (LTIs) 132-3 Moray, N. 20 n5
LTIF 223, 232 Moshansky, Mr Justice 189 n9, nlO,
Lucas, Deborah 224,240 n3 226, 240 nlO
Motivation 113
McDonaid, N. 154 n7 Mount Erebus tragedy 226
McFarlane, S. 240 n8 Murphy, M. 221 n7
McKenna, E.F. 154 n6, 240 n5 Murray, D. 59 n5
Mahon, Peter 226 Muschara, Tony 83 n i l
Mahon Report 226
Maintenance 85-105 Nakina derailment, case study 34-5
errors committed during 102 NASA 158-60,197,198
rationale 100-3 National culture 220
Maintenance Error Decision Aid National Transport Safety Board
(MEDA) 151-3, 212 (NTSB) 168
Maintenance failures 85-90 Naval air operations at sea 213
Maintenance management 134 Navigational aids 116-18
Maintenance neglect 102-3 types of 117
Maintenance-related activities 86 Near-miss 118-19
Malevolent damage 211 Necessary violations 73
Management factors 122 Negative outcomes 108
Man-Made Disaster 226 Neglected maintenance 102
Mann, Nancy R. 59 nlO Negligence 207
Marine Safety Agency (MSA) 180 Non-compliance 210
Martin, J. 154 n5 Normal Accidents: Living with High-
Marx, David 212-13, 221 n27, 222 Risk Technologies 55, 226
n32 Norman, Don 105 nl3
Massachusetts Institute of Technol- Nuclear power plants 55
ogy 45 Nuclear Regulatory Commission
Master Car Builders Association (NRC) 169-71
172
Maurino, D. 39 n5, 189 n9, 240 n9 Occidental 162
Maycock, G. 83 n9 Offshore platform, design 136
Meister, D. 154 n5 Oil crisis 172
Merritt, A. 222 n47 O'Leary, Mike 197, 200, 202, 221
Merry, E. 59 n9 nl6, nl7, nl8, nl9, n21, n24,222
MESH program 131,138-42, 141 n28
Meshkati, Najmedin 104 n5, 220, Omission-prone task features 95-8
222 n47 Omissions
Military cultures 67-8 cognitive processes involved in 96
Mintzberg, H. 113,124 n3 prevalence 94-5
Mispliances 76, 78 O'Neill, P. 221 n7
Mistakes 55, 71,76-8 Operating procedures 166
Misventions 76-7 Operational challenges 213
Mitroft, I. 241 n20 Optimizing violations 73
Index 249
Organizational accidents 1-2, 85-90, Personal injury risks 227
173, 182,187-8, 194, 2 2 3 ^ Peters, Thomas 192,193, 221 n4
causal fallout from 234 Petrochemical industry 237
development stages 15,17 Phillips 66 Company Houston
history 13-15 Chemical Complex 90
hi-tech systems 18 Pidgeon, N. 221 nl6,222 n28,240 n6
investigation 17 Pinchbeck, Rob 240 nl
necessary condition for 11 Piper Alpha platform explosion 12,
personal injuries in prediction of 78, 89,138,179
232-3 case study 161-3
surface details 2 Piper Chieftain crash at Young,
Organizational activities 65-6 NSW, case study 165-8
Organizational and managerial Plan-Do-Check Action Cycle 47
(O&M) factors 183-7 Planning 165
Organizational culture 192-4 Poisson distribution 108
and safety information 38 Poisson, Simeon 108
Organizational deficiencies 135 Policy level 147
Organizational Factor Profile 184,186 Pollock, C. 82 n2
Organizational factors 121, 140-1 Pooley, E. 189 n20
Organizational flexibility 213 Positional paradox 113
Organizational functions 175 Pratt 105 n l 5
Organizational learning 65 Pressurized water reactors (PWRs)
Organizational levels 67 52
Organizational life history 64-5 Prevention, improved 19
Organizational model 225-6 Preventive maintenance 100-2
Organizational standards and Primrose, M. 154 n8
objectives 63 Proactive process measurement
Organizational trend analysis 151 116-17,120-2
Outcome knowledge 38 candidate areas 120
Outcome measures 107, 111, 112 Probabilistic risk assessment (PRA)
Output measures 64 225
Probabilistic safety assessment
Parent failures 121 (PSA) 130
Parker, D. 59 n i l , 82 n2, 83 n8 Procedural factors 122
Passmore, J.A. 221 nl5 Procedures 134
Pathological culture 38 Process measures 108
Patrick, J. 124 n7 Process subsystems 123
Pauchant, T. 241 n20 Production and protection 3 - 7 , 1 9
Pearce, Andy 20 nl, 240 nl Protection and production 3 - 7 , 1 9
Pearson, C. 241 n20 Protective measures 42
Performance-influencing factor Protective systems 54
(PIF) level 147 Punchard, Ed 78, 83 nl4
Performance levels 68-70 Punishment and reward 211-12
Perin, Constance 20 n4,104 n8
Perrow, Charles 40 n22,55, 65, 82 Quality assurance 46-9
n3, 226, 240 n7 Quality control 46-9
Person model 224 Qvale, T. 60 n21
Personal injuries in prediction of
organizational accidents 232-3 Radioactive waste 170
250 Managing the Risks of Organizational Acciden ts
Rail car coupling 172 Riley, M. 189 nl6
Railroad operations 172 Risk areas 226-7
Railton, Tony 32 Risk management 36
Railway inspectorate 160 Risk management matrix 201
Railway operations 140 Risk perception 218
Railway Problem Factors (RPFs) 140 Risks
Railworker accidents 172 due to key-operator errors 227
Rassmussen, J. 59 n3, n21, 82 n6,105 due to latent conditions 227, 233-
nl7 4, 236-7
Reactive measures 116-17 preponderance in different
Reactive technique 118 domains 228-32
Reason, J. 20 n6, 39 n5, 59 n i l , 60 Robens, Lord 189 n32
nl4, nl6, 82 n2, n7, 83 n8, nl2, Robens report 176-7
124 n7,154 n l , n8, nlO, 155 n i l , Roberts, Karlene 213
241 n l 5 Rochlin, Gene 213
Reassembly, error types associated Routine violations 73
with 86 Rule-based levels 68-70
Redundancy 55 Rule-based mistakes 91
Regulators Rule book additions 49
and legislation 172-3 Rule-related behaviours 75-6,81
information needs 174 Rules and procedures 64
investigative skills 174
need for better deal 187-8 Safeguards 6
problems facing 171 Safety, nature of 107-8
role of 157-89 Safety Appliance Act 1893 172
site visits 174 Safety Cases 178,180-2
under fire 168-71 Safety-critical errors 129
Regulatory process 157-89 Safety culture 191-222
autonomy and dependence as components 195-6
constraints 173-5 ideal 195
basic elements 183 questions to be posed 219-20
integration into wider learning Safety engine, driving forces 113-14
cycle 187 Safety goals 114-15,175
legislation 172-3 Safety health 116-18,121
model 182-7 Safety information and organiza-
see also Self-regulation tional cultures 38
Reliability and maintainability Safety information system 113,115,
studies (RAMS) 225 120
Reminders Safety laws 173
characteristics 98-100 Safety management 114^15, 223-41
presence of 99 approaches 224-6
Reporting culture 195-205 person-oriented approach 230
Requisite imagination 38 Safety measures 114, 122
Resistance-vulnerability continuum Safety procedures, effectiveness 74-
110 5
Resources 113,166 Safety Regulation and Standards
Responsibilities 165 Division 166
Review 131,138-42 Safety rules 75
Reward and punishment 211-12 Safety space 107-24
Index 251
concept of 110-11 Substance abuse 211
countervailing currents within with mitigation 210
111-12 Subramanian, M.A. 104 n5
factors involved in navigating 115 Substitution test 208, 210
organizations' position in 111 Successful compliance 77-8
Safety-specific factors 122 Successful improvization 79
Safety violations 72 Successful violations 78
Salam an, G. 221 n7 Suchman, E.A. 124 n2
Sarter, Nadine 45-6 Supervisors 218
Seat belts 173 'Swiss Cheese' model of defences 9
Seaview Air 167
Self-regulation 175-32 Takano, K. 105 n l 2
move towards 175-80 Takeoff monitor 52
pluses and minuses of move 181— Taylor, M. 189 n l 7
2 Taylor, S.E. 154 n3
Senge, Peter 219, 222 n45 Team-related measures 130
Seveso Directive 178 Technical factors 122
Sheen, Mr Justice 240 n i l Technical faults 54
Sheen Inquiry 231 Technical safety audits 225
Shell Exploration and Production 152 Test to destruction 115-16
Sherman, P. 222 n47 Third party risks 227
Shewhart, Walter 47 Thomas, J. 20 n5
Shipping 180 Thompson, N. 221 n7, n8
Shrinkage of allowable action 49 Three Mile Island 12, 52, 53, 87-8
Shrivastava, P. 104 n5 Tick-off phenomenon 114
Shunters 49-50 Total quality management (TQM)
Sims, F. 59 n9 47,126, 226
Singapore International Monetary Tozer, S. 154 nlO
Exchange (SIMEX) 29 Training 1 2 2 , 1 2 3 , 1 3 0 , 1 3 5
Skill-based levels 68-70 and procedures trade-off 67-8
Skill-based slips and lapses 91 Transport Canada 163-5
Sleigh, John 124 n6 Trial-and-error learning 64, 214
Slips 71, 91, 209 Tripod-Beta 152-3
Smith, Denis 20 n8, 241 n21 Tripod-Delta 131-8,186
Smith, J.C. 206, 221 n25 development 132
Smith, M.J. 124 n4 elements 132
Social engineering 191, 219 Failure State Profile 137
Speed limits 172-3 history 132
Spent-fuel pool 169 indicators 139
Stager, P. 40 n l 9 key to using 138
Standard operating procedures software 137
(SOPs) 214-17 structure 133
Starter, N.B. 59 n5 n8 Trips 71
Statistical process control (SPC) 47 Tuckey, Andrew 33
Stradling, S. 221 n7 Turner, Barry 226, 240 n6
Strategic apex 113 Turner, Mr Justice 231
Strategic goals 67
Stephens, D. 124 n5 Unauthorized medication 210
Stover, D. 241 n l 8 Unauthorized substance 209
252 Managing the Risks of Organizational Acciden ts
Unconditional probability 149,150 Waterman, Robert 192,193,221 n4
Unsafe acts 120-1, 231 Weick, Karl 21-2, 37, 39 n2,40 nl8,
culpability of 209, 211 216,222 n38, n41
Uttal, B. 221 n2 Westrum, Ron 37, 40 nl9
Whitney 105 nl5
Vaughan, Diane 158,173,174,188 Wiener, Earl 45,59 n6,154 n7
n2, n3,189 n24 Wilde, G.J.S 20 n3
Vette, G. 240 n8 Williams, Jerry 146,155 nl2, nl3
Wise, J. 40 nl9
Violation-producing conditions
(VPCs) 142,146 Woods, David 20 n7, 45-6, 59 n5, n8
nl9
Violations 51, 72-3, 210 Work accidents 172
Visser, J. 154 n8 Work groups 217
Wagenaar, Willem Albert 39, 40 n21, Yates, J. 222 n43
154 n8, 218, 222 n43
Waiver of Disciplinary Action 198 Zero maintenance 100
Wallis, D. 105 nl7 Zero-risk approach 175
Other titles from Ashgate
Beyond Aviation Human Factors
by Daniel E. Maurino, James Reason, Neil Johnston and Rob B. Lee
1995 181 pages illustrated 0 291 3 9 8 2 2 7
A systematic organizational approach to safety can replace the hitherto piecemeal
approaches. The book uses four linked case studies to enable readers to achieve
this. It introduces Reason's Model and applies it to the flight deck, aviation mainte-
nance and air traffic control.
" . . . compulsory reading near every accident investigator and for safety officers of
any technology-based organisation" Aerospace
Decision Making under Stress: Emerging Themes
and Applications
edited by Rhona Filn, Eduardo Salas, Michael H. Strub, Lynne Martin
1997 3 4 8 pages illustrated 0 291 3 9 8 5 6 1
This book deals with some of the latest theoretical and practical developments in
the psychology of decision making under stress from a naturalistic perspective.
Innovation and Automation
by Paul M. Satchell
1998 2 4 0 pages illustrated 1 84014 315 0
The coexistence of innovation and automation in organisations is complicated by
the prevailing approaches to automation which hamper creativity. This book shifts
human-machine interactions from the current, tcchnology-centercd approach to
one where sharing is evolved and creativity is no longer supressed.
Culture at Work in Aviation and Medicine
National, Organizational, and Professional Influences
by Robert L. Helmrich and Ashleigh C. Merritt
1998 3 3 2 pages illustrated 0 291 3 9 8 5 3 7
Draws on research into the impact and interaction of culture - national, organiza-
tional, and professional - on performance in high technology, high stakes environ-
ment, with data on leadership, teamwork, human performance, and automation.
Discusses an organizational blueprint of culture-sensitive strategies for enhancing
efficiency and safety.
ASHGATE
Ashgate Publishing Limited
Wey Court East, Union Road,
Farnham, Surrey,
GU9 7PT, England
[Link] 9