Push Button A or is it B? Alarming design Real consequences for - - PowerPoint PPT Presentation

push button a or is it b alarming design real
SMART_READER_LITE
LIVE PREVIEW

Push Button A or is it B? Alarming design Real consequences for - - PowerPoint PPT Presentation

Push Button A or is it B? Alarming design Real consequences for real people If you are delivering a system or product, you should set up a register of hazards containing information about each hazard. 16.2.2 a Can we find some hazards?


slide-1
SLIDE 1

Push Button A … or is it B? Alarming design

slide-2
SLIDE 2

Real consequences for real people

slide-3
SLIDE 3

If you are delivering a system or product, you should set up a register of hazards containing information about each hazard. 16.2.2 a

slide-4
SLIDE 4

Can we find some hazards?

slide-5
SLIDE 5

Can we find some hazards?

 Broadcast emergency call not made

 Driver didn’t log on Train had not been registered for this trip  New train controller registered trailing loco  No communication with driver to confirm  Train controller didn’t use backup system  Train controller didn’t have phone numbers  Incident was not given priority  Repeat of similar incidents.

slide-6
SLIDE 6

Can we find some hazards?

 Broadcast emergency call not made  Driver didn’t log on  Trailing loco logged on from previous day  Trailing loco shown on screen as leading  No communication with driver to confirm  Train controller didn’t use backup system  Train controller didn’t have phone numbers  Incident was not given priority  Repeat of similar incidents.

slide-7
SLIDE 7

Can we find some hazards?

 Broadcast emergency call not made  Driver didn’t log on  Trailing loco logged on from previous day  Trailing loco shown on screen as leading  No communication with driver to register  Train controller didn’t make broadcast call  Train controller didn’t have phone numbers  Incident was not given priority  Repeat of similar incidents.

slide-8
SLIDE 8

Can we find some hazards?

 Broadcast emergency call not made  Driver didn’t log on  Trailing loco logged on from previous day  Trailing loco shown on screen as leading  No communication with driver to confirm  Train controller didn’t make broadcast call  Train controller didn’t have phone numbers  Incident was not given priority  Repeat of similar incidents.

slide-9
SLIDE 9

Can we find some hazards?

 Broadcast emergency call not made  Driver didn’t log on  Trailing loco logged on from previous day  Trailing loco shown on screen as leading  No communication with driver to confirm  Train controller didn’t use backup system  Train controller didn’t have phone numbers  Incident was not given priority  Repeat of similar incidents.

slide-10
SLIDE 10

Can we find some hazards?

 Broadcast emergency call not made  Driver didn’t log on  Trailing loco logged on from previous day  Trailing loco shown on screen as leading  No communication with driver to confirm  Train controller didn’t use backup system  Train controller didn’t have phone numbers  Incident was not given priority  Repeat of similar incidents.

slide-11
SLIDE 11

Can we find some hazards?

 Radio active in trailing locomotive  Driver didn’t log on  Train controller didn’t register train  New train controller registered trailing loco  No communication with driver to confirm  Train controller didn’t use backup system  Train controller didn’t have phone numbers  Incident was not given priority  Repeat of similar incidents.

slide-12
SLIDE 12

Can we find some hazards?

 Broadcast emergency call not made  Driver didn’t log on  Trailing loco logged on from previous day  Trailing loco shown on screen as leading  No communication with driver to confirm  Train controller didn’t use backup system  Train controller didn’t have phone numbers  Incident was not given priority by controller  Repeat of similar incidents.

slide-13
SLIDE 13

Can we find some hazards?

 Radio active in trailing locomotive  Driver didn’t log on  Trailing loco logged on from previous day  Trailing loco shown on screen as leading  No communication with driver to confirm  Train controller didn’t use backup system  Train controller didn’t have phone numbers  Incident was not given priority  Repeat of similar incidents at same centre

slide-14
SLIDE 14

Can we find some hazards?

 Radio active in trailing locomotive  Driver didn’t log on  Trailing loco logged on from previous day  Trailing loco shown on screen as leading  No communication with driver to confirm  Train controller didn’t use backup system  Train controller didn’t have phone numbers  Incident was not given priority  Repeat of similar incidents at same centre

slide-15
SLIDE 15

Can we find some hazards?

 Radio active in trailing locomotive  Driver didn’t log on  Train controller didn’t register train  New train controller registered trailing loco  No communication with driver to register  Train controller didn’t make broadcast call  Train controller didn’t have phone numbers  Incident was not given priority  Repeat of similar incidents.

slide-16
SLIDE 16

If you are delivering a system or product, you should actively manage the hazards to closure. 16.2.2 b

slide-17
SLIDE 17
slide-18
SLIDE 18

Everyone wanted to work safely. Everyone thought they had. No one did.

slide-19
SLIDE 19

The entire system had drifted. Drifted into failure.

slide-20
SLIDE 20

If you have set up a register of hazards, you should keep it up-to-date as new information becomes available. 16.2.2 c

slide-21
SLIDE 21
slide-22
SLIDE 22

Incident Investigation Reports

slide-23
SLIDE 23

Packenham Radio emergency call failed. Cellular only available medium. Situation noted but no comment from investigator.

slide-24
SLIDE 24

SPAD!

slide-25
SLIDE 25

North Strathfield No response to radio call. No broadcast call. Signallers vigorously wave flags and flash lights from balcony.

slide-26
SLIDE 26

SPAD!

slide-27
SLIDE 27

Homebush

slide-28
SLIDE 28

Lewes

slide-29
SLIDE 29

Lewes

Stop train All trains stop

slide-30
SLIDE 30

Lewes

Stop train All trains stop Enter train no. _ _ _ _

slide-31
SLIDE 31

Hexham

slide-32
SLIDE 32

“training in the application of every documented procedure that may be required.” Hexham

slide-33
SLIDE 33

“the capacity to think effectively in emergencies e.g. recognising hazards other than those explicitly identified.” Hexham

slide-34
SLIDE 34

Design feature

slide-35
SLIDE 35

Or unforseen hazard

slide-36
SLIDE 36
slide-37
SLIDE 37

A great convenience,

  • r a lethal distraction?
slide-38
SLIDE 38

Used in some countries …

slide-39
SLIDE 39

Banned in other countries …

slide-40
SLIDE 40

except if convenient for the railway.

slide-41
SLIDE 41

We have changed.

slide-42
SLIDE 42

We cannot hold back the tide. Embrace change and make it safe!

slide-43
SLIDE 43

What is different?

slide-44
SLIDE 44

Traditional Radio Mobile Phone Formal Informal Structured Spontaneous Open Channel Closed Channel Situation awareness Just the two of us

slide-45
SLIDE 45

Independent check Credibility Monitored, recorded May not be recorded Press to talk Find number, dial, wait Anyone can answer Correct connection? Static configuration Numbers change

slide-46
SLIDE 46

This could be dangerous!

slide-47
SLIDE 47

New Hamburg Cellular privacy used to cover error, created hazard. Grawlin Plains Incident report by phone, phone numbers not given. Asta Imminent collision, phone numbers not

  • known. 19 Dead.
slide-48
SLIDE 48
slide-49
SLIDE 49

Recommendations for Success

slide-50
SLIDE 50

Understand the system

slide-51
SLIDE 51

Ensure documentation is accurate

slide-52
SLIDE 52

Train and rehearse

slide-53
SLIDE 53

Make it second nature

slide-54
SLIDE 54
  • Train in realistic situations
  • Use simulators
  • Test a range of scenarios
  • Practice until it is natural
  • Assess regularly.

Recommendations for Success

slide-55
SLIDE 55
  • Train in realistic situations
  • Use simulators
  • Test a range of scenarios
  • Practice until it is natural
  • Assess regularly.

Recommendations for Success

slide-56
SLIDE 56
  • Train in realistic situations
  • Use simulators
  • Test a range of scenarios
  • Practice until it is natural
  • Assess regularly.

Recommendations for Success

slide-57
SLIDE 57
  • Train in realistic situations
  • Use simulators
  • Test a range of scenarios
  • Practice until it is natural
  • Assess regularly.

Recommendations for Success

slide-58
SLIDE 58
  • Train in realistic situations
  • Use simulators
  • Test a range of scenarios
  • Practice until it is natural
  • Assess regularly.

Recommendations for Success

slide-59
SLIDE 59
  • Put designers through the

training simulations to verify that the system is what they think they designed.

  • Assess regularly.

Recommendations for Success

slide-60
SLIDE 60
  • Put designers through the training

simulations to verify that the system is what they think they designed.

  • Assess regularly.

Recommendations for Success

slide-61
SLIDE 61
  • Check the rule books and

procedures are relevant and accurate.

  • Are they being used?
  • Assess regularly.

Recommendations for Success

slide-62
SLIDE 62
  • Check the rule books and

procedures are relevant and accurate.

  • Are they being used?
  • Assess regularly.

Recommendations for Success

slide-63
SLIDE 63
  • Check the rule books and

procedures are relevant and accurate.

  • Are they being used?
  • Assess regularly.

Recommendations for Success

slide-64
SLIDE 64
slide-65
SLIDE 65
slide-66
SLIDE 66

JJA.com.au Aitken & Partners