Total Environmental Health and Safety

profilemarmaydec
out.pdf

34 PSJ PROFESSIONAL SAFETY DECEMBER 2021 assp.org

Bruce Lyon Bruce K. Lyon, P.E., CSP, SMS, ARM, CHMM, is vice president with Hays Cos. He is chair of the ISO 31000 U.S. Technical Advisory Group (TAG), vice chair of ANSI/ASSP Z590.3, advisory board chair to University of Cen- tral Missouri’s (UCM) Safety Sciences pro- gram, and a director of BCSP. Lyon is coauthor of Risk Assessment: A Practical Guide to Assessing Operational Risk and Risk Manage- ment Tools for Safety Professionals

Georgi Popov Georgi Popov, Ph.D., CSP, QEP, SMS, ARM, CMC, FAIHA is a pro- fessor in the School of Geoscience, Physics and Safety Sciences at UCM. He is coauthor of Risk Assessment: A Practical Guide to Assessing Operational Risk and Risk Manage- ment Tools for Safety Professionals. Popov is vice chair of ISO 31000 U.S. TAG and chair of ANSI/ASSP Z590.3.

PSJ: Let’s talk about the concept of as low as reasonably practicable (ALARP). What does this mean in the technical report and to OSH professionals? Bruce: This is an important concept that has not been well understood. The main thing to know as safety and risk professionals is that there’s no such thing as zero risk or risk-free. There’s always going to be some residual risk even after we treat a risk. The concept of ALARP is achieving a residual risk level that is considered as low as practicable at the time. It’s an acceptable level of risk to an organization at that time. It will change: As organizations get better at treating risk and become more mature in their risk manage- ment process, they will lower their acceptable risk level. ALARP is the concept of achieving that level.

I like to refer to it as the point of diminishing returns: where the residual risk is considered low and can further be reduced only through excessive expenditures. In other words, it is a balancing of the benefits and the costs in light of the existing risk level. Fred Manuele has written about this quite a bit, and he says that ALARP is applying available resources to obtain acceptable risk levels that are practicable and economical. In fact, in the investiga- tion report of the Deepwater Horizon event, the CSB refers to ALARP as a “realistic risk reduction goal,” since risk cannot be totally eliminated.

ALARP should be defined by the organization up front as part of the context and the risk criteria. Orga- nizations should be developing and establishing the risk levels that they consider acceptable, as well as the other categories of what is unacceptable, what needs to be a high priority risk, what is a moderate level risk and then what is considered acceptable. Essentially, ALARP is that categorization as well as the action levels that will be applied to those levels of risk in the organization. It’s part of the risk criteria that are estab- lished; it will be different for every organization based on the overall culture and the work environment, the industry that it operates in, as well as its internal and external stakeholders. So, just like all the risk criteria, it will depend on the organization, what they are com- fortable with, and what they are willing to accept as they define their levels and their ALARP concepts.

This is important to keep in mind: It’s not going to be the same for every organization. What is acceptable to one organization, such as in the oil and gas industry, may not be acceptable to another operation, such as a healthcare setting. You have to look at the context, the industry and the culture as they define these levels.

So, the ALARP concept is basically defining those risk levels—from unacceptable risk where there is im- mediate action to be taken and the work is not allowed to continue; the second level of high risks, which are given the highest priority for risk reduction; the third level of moderate risks, which require further risk reduction at the appropriate time; and the bottom level of acceptable or very low risks that should be monitored and reduced if feasible. That explains the concept and, as I mentioned, it is established up front and used in the risk evaluation phase of risk assess- ment where the risks are judged as to whether they are acceptable or unacceptable or in the middle.

PSJ: Another technique is risk hierarchy. How can organizations use this technique to organize the risks that exist in the workplace? Georgi: That is a nice continuation of what we just discussed with the ALARP concept. A risk hierarchy is a comprehensive risk portfolio used by the orga- nization to organize the risks by unit or division, by risk type, by geography or by strategic objective. This is often done in risk management systems. A risk profile represents the entire portfolio of risk facing an organization. Risk hierarchies can be used to roll up and drill down for analysis and reporting.

Once risks have been assessed and their interactions documented, the risk-based information is entered into a comprehensive portfolio for prioritizing risk responses and reporting. Some organizations with more mature enterprise risk management programs and quantitative capabilities may aggregate individual risk distribution into a bigger picture, cumulative loss probability distribution, and they refer to that as a risk profile. The risk profile should provide a complete listing of all the assessed risks by group or type. It will help us communicate risks to decision-makers. The risk profile typically does not allow for prioritization of risks unless we added that risk level.

After that, we must consider how we’re going to control the risks. We’re all familiar with the tradi- tional hierarchy of controls: engineering, adminis- trative and PPE. However, ever since the NIOSH’s Prevention Through Design initiative was launched in 2007, the hierarchy of controls was expanded to include elimination and substitution. Then the ASSP prevention through design standard expand- ed the hierarchy even further with the addition of avoidance and warnings.

The recently published technical report expanded the hierarchy of risk treatment even further than that.

The ASSP TR-31010-2020, Technical Report: Risk Management—Techniques for Safety Practitioners, provides a guide for applying risk assessment techniques to understand risk, reduce related uncertainty and obtain risk-based information to help organizations achieve their goals. Bruce Lyon and Georgi Popov, chair and vice chair of the ISO 31000 U.S. Technical Advisory Group, explain some of the concepts presented in the technical report.

IMPROVING RISK MANAGEMENT Q&A With Bruce Lyon & Georgi Popov

STANDARDS INSIDER

N U

TH A

W U

T SO

M SU

K /I

ST O

C K

/G ET

TY IM

A G

ES P

LU S

assp.org DECEMBER 2021 PROFESSIONAL SAFETY PSJ 35

Bruce mentioned the avoidance concept and how we must reduce the risk to ALARP levels; the reason we have to use the hierarchy of risk treatment now instead of the hierarchy of controls is because if you avoid the risk or you eliminate it, you don’t have to control it. That goes back to the ISO risk management model, where risk treatment is mentioned as the next step.

PSJ: Can you talk about causal mapping and how it applies to risk assessment and management in the workplace? Bruce: This is a method that more safety professionals may be familiar with. A couple of years ago, Georgi and I wrote an article in Professional Safety on causal factor analysis and the multiple methods that can be used to identify management system weaknesses and opportunities for improvement in management systems that would help reduce incidents. Causal mapping is one of the key methods. It’s an investiga- tion tool used in incident investigations and analysis; it’s a basic flowchart that maps out the events and conditions surrounding an incident. It’s a visual method that gives management a good view of what actually happened and how the sequence of events and secondary events occurred, as well as related con- ditions that may have influenced the events that led to the incident, and any existing controls, whether they functioned correctly or failed, all in an effort to better understand what led up to the incident.

The causal mapping process is used to under- stand what happened and what can be done to fix it or make it work better. It’s typically performed by a cross-functional team of knowledgeable, experi- enced members who are familiar with the subject. Facts are gathered about the events that have taken place. Sometimes interviewing the involved parties is part of the process. With investigations, you’re interviewing the involved parties for observations of the process itself to determine the sequence of events. This is something that can be done proactively before incidents occur, by observing the individual tasks that take place to create a particular job and studying those events and how they interact. It is an analysis of how events interact and play out in a scenario.

All of this information is gathered in the investi- gation and put into flowchart figures. Typically, an event is represented by a rectangular box, and you can put in as much detail or keep it as simple as you want. Then the conditions that would be attached to the event or involved with the sequence of events are placed in an oval. This process can be done on a whiteboard, on a computer or on paper, and you an- alyze and study it to determine the potential causal factors of the incident.

I like to use the plural form of that, because for ev- ery incident that occurs, there are typically multiple causal factors. We’re tempted to identify the direct causes and the ones that are simple to find. But we need to dig deeper and investigate what the root level causal factors are buried or embedded in the manage- ment system so that when we fix those, that incident won’t be as likely to occur if the management system

has been corrected. It’s not just going to correct the particular event that occurred.

So, causal mapping is a nice visual representa- tion of how something occurred and it can be used proactively, which is a good way to use it in the risk management process.

PSJ: Let’s talk about Ishikawa fishbone analysis, or cause-and-effect analysis. Can you explain what that is and the cause-and-effect relationship within risk analysis?  Bruce: The reason it’s referred to as the fishbone diagram is that it sort of looks like a fishbone. It was developed by an individual named Ishikawa, and also known as cause-and-effect analysis. The bottom line is that it’s a problem-solving tool. It’s been used in a lot of industries, the automotive industry, for example, often from a quality standpoint. One thing you’ll find with the methods in the technical report. They’re not just used specifically for safety and risk management. They can be used for other prob- lem-solving issues, whether quality, production or efficiency. That’s the nice thing about some of these tools. In a lot of organizations, their quality experts will understand these methods. When you start us- ing these methods that they use for quality and you involve them in a safety process, and they use a tool they’re familiar with, it becomes even more effective.

Fishbone diagramming really should be executed as a team-based approach. I like to do it on a whiteboard with a cross-functional team of individuals who are knowledgeable and experienced in the subject matter. The first step is identifying the problem statement or the scenario that you’re trying to solve: that is the head of the fish, or the intended outcome. That must be clearly defined for the group. From there, a structure is drawn or extended from the problem statement that has branches. Each branch is a category. You can have as many as you want to include or that are necessary, but typically it’s four to six categories of different contrib- uting factors. A category could be people, the process, the materials, the infrastructure or the environment. The focus is placed on each of these individually: start thinking about what could go wrong that would lead to this problem state that you want to avoid or solve.

Take, for example, a forklift incident. We have forklift operators, spotters watching for traffic or pedestrians, and there are going to be some elements that we need to consider for that category of con- tributing factors. That might be the operator’s ex- perience level, the training and the effectiveness of the training, and the spotter keeping an eye on the surrounding work area. Looking at the equipment, is the forklift equipped with all of the warnings and alarms that are necessary? Does it have the required safety features? Each of these is broken down in a branch or a bone, and off of that branch are the factors: anything that has an impact on what could have contributed to this stated problem.

So, what you end up having is a structure that has branches for each of these individual contributing factors that you can identify. What you end up with

“Causal mapping is a nice visual representa- tion of how something occurred and it can be used

proactively, which is a good way to use it

in the risk manage-

ment process.”

36 PSJ PROFESSIONAL SAFETY DECEMBER 2021 assp.org

is a very well-defined visual representation of all of the factors that come together that could lead to a problem. That allows for further analysis so you can go into specific areas within, for example, the infra- structure elements identified, and then a more pin- pointed risk assessment or analysis can take place.

It’s a pretty popular method of outlining and de- fining the specific factors that can come into play in a particular scenario. It helps identify things that maybe weren’t thought of, and you put them in the diagram for management to see and understand.

That is the first step of getting to the root levels of some of the causes. I do like to get as deep as I can in these and not leave it at the “employee is at fault” level, which tends to happen. When you talk about, for instance, employee training, that’s where we have to go a little deeper and find out what is the effectiveness of the training? What’s the retention of the training? How frequently is it pro- vided? Is there testing? This method gets into the deeper elements as to what could be going wrong or going better and gives you a better way to analyze that.

PSJ: Can you speak to the impact that risks can have on a business and how a business impact analysis can help improve risk management? Georgi: I’m glad that Bruce mentioned how some of these tools are actually used in quality analysis and that we have to do this together with other experts. So instead of using a silo approach, if we speak the same or similar language, we may be invited to dis- cuss some of the other aspects of risk.

This is a nice transition to the next tool you men- tioned, which is business impact analysis. This is a systematic method used to determine and evaluate the potential effects of an interruption to critical business operations as a result of a disaster, emergency or serious incident, and we can add pandemics as well. Business impact analysis provides an understanding of the critical process that enables the organization to achieve its objec- tives and provides information needed to plan for an or- ganization’s response to a disruptive event, for instance.

Specifically, a business impact analysis will pro- vide an understanding of what is critical for the business process functions and associated resourc- es, and the key interdependencies that exist for an organization. We must understand the business perspective and what it means for our organizations. We also have to clearly communicate how disrup- tive events will affect the capacity and capability of achieving critical business objectives. We also need to have an honest discussion with decision-makers about whether we have the capacity and capability needed to manage the impact of a disruption and recovery. That connects back to the ALARP concept and what is an acceptable risk for our organization.

Business impact analysis can be undertaken using different questionnaires, interviews or structured workshops, or a combination of all three. And we can use business impact analysis to determine the potential consequences of a disruption to an organization’s busi- ness. We can discuss the expected recovery time frame, and if that’s acceptable or not. We can add the informa-

tion needed to develop mitigation strategies. Potential business impact scenarios are considered during the risk assessment process. And this is how we can branch to other tools mentioned in the technical report. In some cases, we can include the scenario analysis that could be included in the business impact analysis. We also have to identify and evaluate the impact of busi- ness interruptions, and that will give us the basis for investment in mitigation strategies, as well as invest- ment in prevention and recovery measures. Business impact analysis can also be used as part of consequence analysis when we have to consider the consequences of operations interruptions, and the consequences then can be included in bow-tie risk assessment and risk management if the cascading bow ties are used.

As you can see, all these tools could be used in combination. You can start with one and add an- other one later. And if you need to analyze some different scenarios, you can add even more of the risk assessment and risk management tools that are discussed in the technical report. Bruce: Yeah, that’s excellent, Georgi. I was just going to mention that business impact analysis is being used a lot more recently because of the COVID-19 pandemic. We’ve had a lot of clients become much more interested in business continuity planning and doing business impact analysis as part of that to de- termine the level of threats to their critical functions.

And matter of fact, I was on a conference call with one of our clients that are a global provider of consulting and auditing services for the food industry, and they’ve gotten really into identifying their level one, two and three risks and using business impact analysis to help define that and all the potential scenarios that could create such levels that would impact their business. So, I think this is a method that is very timely and has a lot of application to all types of areas for businesses. Georgi: That’s a great example. We also provide a simple business impact analysis example, or tem- plate, in the technical report.

PSJ: Anything else to add? Bruce: I’d like to encourage safety professionals to take a look at the report. It has a lot of information in it, and it was designed for the safety professional from a North American perspective to bridge some of the gaps of the previous and current editions of ISO 31010. There are some things that we thought needed to be better explained to add more value to the user. I would encourage folks to look at what is in the report and try to start applying some of the concepts and methods that are available. Georgi: I would add that we expanded the number of methods included in the technical report that were not included in ISO 31010. We felt it was important to include some of these other methods because, as Bruce men- tioned, some of them can be integrated, some of them can be used together. You can start with something simple, but as you progress through your career, you can add more sophisticated tools and learn to speak the language of business and quality, and what’s used in your organiza- tion in the upper-level decision-making process. PSJ

“We have to do this together

with other experts.

Instead of using a silo approach, if we speak the same or similar language, we may

be invited to discuss some of

the other aspects of

risk.”

STANDARDS INSIDER

Download ASSP TR- 31010-2020, Technical Report: Risk Manage- ment—Techniques for Safety Practitioners, at https://assp.us/3n 0d4oQ.

Reproduced with permission of copyright owner. Further reproduction prohibited without permission.