D4 · Publication Volume 20

Safety, Health and Risk

hazards, risk controls, critical controls and change management

Learning objectives

By the end of this lesson, the learner should be able to distinguish hazard, exposure, risk and control; frame risk assessment around credible events; apply a hierarchy of controls; define critical-control performance and verification; use bow-tie logic without confusing it with quantitative proof; integrate health, emergency and change management; and communicate uncertainty and stop-work conditions.

Safety boundary and rights

Safety and health obligations arise from applicable law, approved systems and the rights and duties of people at work. This tutorial does not define legal compliance or authorise work. Where a learner encounters an uncontrolled serious hazard, the correct response is to follow the applicable stop, withdraw, report and emergency arrangements—not to complete an academic calculation.

Risk language must support action. A hazard is a source or situation with potential harm. Exposure describes contact or opportunity. Risk concerns likelihood and consequence under stated controls and context. A control changes the event pathway or exposure. A warning label is not equivalent to elimination or engineered prevention.

Define credible unwanted events

Start with a specific event: loss of ground into an occupied area, mobile-equipment collision, inrush, fire, loss of ventilation, explosive atmosphere, uncontrolled energy or harmful chronic exposure. Define location, activity, people or receptors, operating state and consequence. Broad labels such as “geotechnical risk” hide pathways.

Use evidence from observations, incidents, near misses, task analysis, change, monitoring and specialist models. Consider normal, startup, shutdown, maintenance, upset and emergency states. Include contractors and overlapping work. Do not use absence of prior harm as proof of acceptable risk.

Hierarchy of controls

Prefer eliminating the hazard, then substitution or engineered separation, followed by administrative controls and personal protection according to the applicable framework. Real systems often use several layers. Evaluate whether each control is independent, reliable, available, used and able to withstand foreseeable variation.

Administrative controls can be essential, but they depend on information, competence, workload, communication and supervision. Personal protective equipment has fit, compatibility and maintenance limits. Avoid transferring a design deficiency to worker behaviour.

Bow-tie and barrier logic

A bow-tie places threats and preventive controls before a top event, then consequences and mitigative controls after it. It helps expose pathways and dependencies. Define escalation factors that weaken a control and the controls that manage them. Use one coherent event, not a diagram crowded with unrelated hazards.

The diagram is a qualitative argument, not a probability calculation or proof that controls work. Link each barrier to a performance requirement and evidence. Common-mode failures—loss of power, inaccurate survey, flooding, communication outage—can defeat several apparent layers simultaneously.

Critical controls and performance standards

A critical control is one whose absence or failure materially increases the risk of a fatal or other high-consequence event. Define its objective, owner by role, performance requirement, activation, availability, reliability, inspection or verification, data, failure response and change control. Limit the set to controls truly critical to the event.

Verification asks whether the control is present and effective now. Audit asks whether the management system supports it over time. Outcome statistics alone are insufficient because rare events may not occur during a weak-control period. Use leading evidence tied to performance.

Risk assessment and uncertainty

Choose a method proportionate to the decision, from field-level checks to formal task, design or major-hazard analysis. State participants, evidence, assumptions, existing controls, uncertainty and action authority. Matrix categories can prioritise work but should not create false arithmetic or allow low-consequence frequent events to mask catastrophic scenarios.

Sensitivity matters when likelihood is uncertain. Use credible worst case and degraded-control scenarios. If uncertainty prevents assurance of a critical control, restrict or pause exposure until evidence improves. “More data required” must include a safe interim state.

Occupational health and chronic exposure

Health hazards can have long latency and weak immediate signals. Dust, noise, vibration, heat, chemicals, diesel emissions, radiation, ergonomics and fatigue require exposure assessment, engineering controls, health surveillance where applicable and protection of personal information. Production data rarely substitute for exposure data.

Use representative similar-exposure groups, task and time information, instrument quality and uncertainty. Investigate peak and cumulative exposure. Health controls should be designed with workers and reviewed when process, material, equipment or schedule changes.

Emergency preparedness and resilience

Emergency plans connect credible scenarios to detection, alarm, communication, command, withdrawal, refuge, rescue, medical support and external coordination. Plans require current mine geometry, access, services and people information. Exercises test assumptions and reveal response delays.

Resilience includes redundancy, protected systems, alternative routes, backup power and recovery. Avoid relying on one communications channel or one person. Record lessons and close actions; an exercise is not successful merely because it was completed.

Management of change

Change includes design, geology, method, equipment, automation, staffing, schedule, material, contractor, control, software, regulation and temporary workaround. Screen changes before implementation for affected hazards and controls. Temporary changes need expiry, ownership and restoration.

Link change records to source objects and communicate to affected roles. Verify controls after implementation. Cumulative small changes can cross a design boundary even when each appears minor. Trigger a broader review when assumptions or common systems change.

Learning, reporting and just culture

Reports should capture conditions, decisions and system factors, not search only for individual error. Preserve evidence and distinguish fact, inference and allegation. Protect people from retaliation consistent with law and policy while maintaining accountability for deliberate disregard.

Analyse successful recoveries and weak signals as well as harm. Actions should address causal controls, have owners and verification, and be reviewed for unintended effects. Closing an action in a database does not prove risk reduction.

Synthetic worked example

A synthetic development heading approaches an uncertain old void. The top event is uncontrolled water and material inflow into an occupied heading. Threats include wrong void position, failed probe coverage and unexpected hydraulic connection. Preventive controls include exclusion geometry, independently checked survey, probe design and response criteria; mitigative controls include remote operation, drainage capacity, withdrawal and emergency communication.

Verification finds that the survey is current but the probe record lacks orientation and hole-completion evidence. Because a critical preventive control is not demonstrated, the heading is paused within the established safe stand-off. The missing evidence is corrected and independently reviewed; the risk score is not simply reduced by adding a warning.

A critical-control model links threats, top event, consequences, barriers, degradation factors, verification and change.
A critical-control model links threats, top event, consequences, barriers, degradation factors, verification and change.

Practice and control record

Choose one synthetic high-consequence event. Build a compact bow-tie with three threats, three consequences, at least two preventive and two mitigative controls, one common-mode factor and one verification failure. Write performance standards for two critical controls and state the safe response when assurance is lost.

A passing record uses no real incident or named person, respects reporting and stop-work arrangements, and distinguishes a diagrammed barrier from verified field performance.

Sources