This article explores two questions that can be answered by transforming major risk management systems into digital models. 1/ A pragmatic question: How can we successfully integrate the regulatory requirements, risk assessment and safety management of a Seveso plant into a non-static picture, in order to reduce the gap between risk studies and the ever-changing reality of installations and practices? 2/ An epistemological question: How can we ensure that this non-static picture is an intelligible and acceptable model (validity, veracity sufficient to make decisions)? The pragmatic question and the epistemological one are interlinked, as two sides of the same coin. They are born from a criticism of a certain bureaucracy which leads to be satisfied with a paper documentation of the control of the risks for the “administration”, that is static in nature and does not necessarily represent a true picture of the ground truth of safety. This article presents the result of a work started in the TOSCA project (Total Operations Management for Safety Critical Activities), a European Project funded within the context of the 7th Framework Programme (see Leva et al. 2019, Anzirsi et al. 2019). This project aimed at developing an innovative approach able to integrate method and IT tool for improving risk management in the field of environmental and major hazard issues. Within this project, in 2013, INERIS started a case study with the Service National des Oléoducs Interalliés (SNOI). SNOI is responsible for the French part of the NATO pipeline network in Central Europe (CEPS), known as the Common Defense Pipeline (ODC). It thus operates a network of 2,300 km of pipelines and 14 SEVESO depots, including 7 classified as high threshold, for a total capacity of 500,000 m3 distributed among more than 80 buried tanks. Since 2013, INERIS and SNOI continued to work together, every day, to develop a method and a web tool dedicated to the combined management and assessment of major risk, where the data from daily monitoring can also be integrated alongside the requirements from the regulations and the required inspections.
There are natural human cognitive biases that affect many aspects of our activities, including major risk management.Some of these have a common characteristic, namely the reification process related to our tendency to selectively seek or interpret information in a way that confirms our representations of reality, and which can lead to forgetting that our representations are in some way abstractions, or hypotheses, and as such, must be continually questioned, analysed and checked against reality.The moment we forget that the correspondence between our representations and reality is only a conditional truth and requires constant verification, is the moment when most human and organizational errors in major risk management can occur.How to fight against this?This is the question that preoccupied us during ten years of research, starting within the European Tosca project (see Leva et al. 2019, Anzirsi et al. 2019), and that still haunts us today.This article presents the problem to be solved and the envisaged solution, based on an IT tool allowing to organize the dialogue between the risk assessment and management stakeholders.This solution has been designed with the SNOI, which is responsible for the French part of the NATO pipeline network in Central Europe.
Risk analysis (RA) is at the heart of the risk management process and has been the subject of methodological, reflective or critical questions for many years. These questions challenge the foundations, practice and uses of risk analysis (Escande et al, 2016). Drawing on work in science and technology studies (STS), many authors emphasise the subjective, constructed and historically situated nature of risk analysis as opposed to a vision that would be objective and purely rational, detached from contexts. This methodological, reflective and critical knowledge is particularly important in a context of major global changes (Le Coze, 2020). In France, RA is framed by regulations which require operators to produce a safety case. The AZF accident (2001) changed the regulations (Bachelot law of 2003) integrating the probability and greater consideration of the territories and their issues through consultation mechanisms. For the past ten years or so, there have been few developments or questioning of these post-AZF developments. However, RA are confronted with new changes, this time no longer regulatory but digital and environmental. These changes tend to modify the threats, vulnerabilities, expectations and objectives of RA. The purpose of this text is to explore this new context. In the first part, critical work on RA is introduced in order to consider its limits. This clarification is followed by a presentation of initiatives that develop new perspectives on RA then by a discussion.
Cet article explore les implications des mutations actuelles sur la pratique et l’usage des analyses de risques (AR). Il introduit les dernieres evolutions des AR dans le domaine des ICPE et introduit la question des limites des AR. Ensuite, plusieurs themes et travaux associes menes a l’Ineris depuis quelques annees sont presentes. Ils concernent la cybersecurite, les natech (catastrophes naturelles ayant des effets sur les installations a risques), le management numerique de la securite, les consequences environnementales et les effets domino. Consideres ensemble, ces themes constituent des evolutions notables dont les implications pour la pratique et l’usage des AR sont discutees.
HAL is a multi-disciplinary open access archive for the deposit and dissemination of scientific research documents, whether they are published or not. The documents may come from teaching and research institutions in France or abroad, or from public or private research centers. L’archive ouverte pluridisciplinaire HAL, est destinée au dépôt et à la diffusion de documents scientifiques de niveau recherche, publiés ou non, émanant des établissements d’enseignement et de recherche français ou étrangers, des laboratoires publics ou privés. Development of the ATOS concept, analysis of technical and organisational safety Jean-Christophe Le Coze, Emmanuel Plot, Franck Prats, Olivier Salvi, A.S. Vince
Design documentation, safety and security analysis, environmental studies, studies on organizational factors, product characterization, etc., constitute the knowledge base each process plant, with a higher or lower detail, uses for plant management. Most of this knowledge is often lost inside an accumulation of formal documents that are not made available for practical use, while it should be disclosed and exploited within a living model of the plant (updated in real time), to which the various actors should refer to make their decisions throughout the lifecycle of the installations. How to give a shared representation of the factory (state, history, behavior), in order to improve the reliability and flow of decision-making, investment, prevention, protection, crisis management? A Risk monitoring systems and knowledge management to be integrated in the architectures of the company IoT has been proposed, developed and tested in French national institute for industrial environment and risks (INERIS). The initial risk modelling embedded in the knowledge management systems, based on the bow-tie methodology to identify the barriers for critical sequences to the Major accidents and to assess their availability, to be used for decision making, has been here integrated with the Integrated Dynamic Decision Analysis in order to obtain the critical sequences of events, that include the operator contribution (in terms of errors and recovery), the barrier effectiveness and the plant behavior. The representation of the plant in the shape of sequences allow a more user-friendly management of the information and thus a simplified control of the coherence of the risk assessment modelling with the real plant behavior, and an enhanced decision-making support in the definition of plant control measures, both technical and operational. It also allows an easier integration of the data coming from the field, with traditional or new technologies, as virtual and augmented reality. The proposed solution is exemplified through the application to an ammonia storage plant.
The aim of this paper is to present the framework for Total Safety Management through its application to a major hazards chemical plant, namely a pesticides producing unit. This framework was developed within the European Project entitled "Total Operation Management for Safety Critical Activities" (TOSCA) aiming at an innovative approach able to integrate and enhance safety, quality and productivity. The cornerstone of this framework is the "Common Operation Picture" notion, which involves a useful synthesis of the unit risk assessment, with the intention to provide understandable information to the relevant stakeholders and decision-makers. This framework has been applied to the storage area of a hazardous substance called dichloropropene, a flammable material used for pesticides production. The Fault Tree and the Bowtie methods have been used for the risk assessment of various accidental releases from the dichloropropene storage tanks. Production data, safety barrier information and results of risk analysis are stored in a database linked with accident sequences visualization tools. (C) 2017 Elsevier Ltd. All rights reserved.
The objective of our poster is to present the HOF research activities of INERIS. INERIS has been developing for 10 years researches on HOF in risk prevention, based on human and social sciences foundations. HOF in risk prevention can be divided in two complementary areas: Human Factors (mainly related to ergonomics) and Organizational Factors (mainly related to sociology). Because of a lack of shared definition among industrial and academics stakeholders, INERIS developed its own definition in order to share a common starting basis.
"BP released findings from its own internal investigation of the oil spill in the Gulf of Mexico, revealed inefficient Organization interfaces among BP management, the rig crew and well site leader. Also according to the investigation, one important contributor to the accident was inadequate guidelines for critical tests and operations". (Pires and Mosleh 2011)Over the recent past, the accumulation of major mishaps, crises and accidents have made it clear that organisations must still improve their capabilities to address safety "not as a stand-alone activity that is separate from the main activities and processes of the organization" but as an integrated part of total performance management. The requirements for safety management in existing and upcoming standards and regulations, as for example the ISO 31000 and or the Seveso II directive, call for a proactive strategic approach, anticipating risks and demonstrating a capacity to keep safety at the centre of changes driven by commercial competition, and ensuring that safety evidence itself becomes an effective driver of change. However there is often a gap between the state principles and an actual roadmap to their implementation. Furthermore organisations, especially the one dealing with safety critical operations, find it difficult to integrate their different functional units in a common programme of operations management or change; there is no clear consensus about what it means to be 'proactive': there is no integrated framework for analysing or managing all the human related functions in an operational system.Innovation may rely on assembling the best practices, tools and methods already available for functional analysis, risk assessment, interactive emergency scenarios analysis, performance monitoring, design review, training and knowledge management, in an integrated framework able to address safety management in the main aspects of a product or process lifecycle the cornerstone of which is the building of a common operational picture to support the capacity to perform more participatory and dynamic risk identification and solutions loops in:- Design (new plants, processes /procedures availing new visualization tools)- Ad hoc critical activities (management of change or scheduled overhaul)- Operations management (establishing of dynamic risk registers).This is the scope of a new EU funded research project called TOSCA and the present paper will introduce the current framework being built.
There are situation in the industry where the human actions are the main safety barriers to abnormal or accidental conditions. In order to maximize the reliability of good human and organizational barriers we need to ensure that the action-plans generated are based on a valid risk assessment of the situation to be addressed and informed by a relevant human factor analysis. This implies that the process needs to be participatory in nature, thus involving end user all the way through. In this paper we present a study in which a critical scenario of vessel overpressure was analyzed using a bowtie. The Bowtie was based on the information provided by a company that supplies industrial gases and services to various industries. The case study is the human and organizational factors that may cause truck drivers to overfill storage tanks on customer premises; the goal is to list proposals for improvement. It became clear that the only safety barrier currently available to avoid the risk of overfilling and possible consequent vessel overpressure is represented by the driver performance on the task. For the example proposed we involved the end user in reviewing the risk assessment and in suggesting possible improvements. The one to be selected were rated on the basis of their impact (in terms of risk reduction) and the difficulty/cost of implementation, The benefit of the approach impacts not only on the quality of the background information provided for the risk assessment but more importantly the involvement of the main end users of the system in assessing their own work performance and being proactively called to identify way of improving the reliability and safety of it
Industrial safety management systems are composed of a set of formal and informal rules. These rules are subject to constant negotiations among industrial staff concerned by these rules. The negotiation process needs to take into account the safety rules and the relevant elements of their application contexts. We propose to use a virtual environment to stimulate this process. The success of such negotiations (in virtual environments) depends on the identification of required knowledge for representing safety rules application contexts. In this paper we present our model and methodology MELISSA that aim at identifying this knowledge, and to share it within the virtual environment design team. We first describe the knowledge needed to represent a working situation. Then, we present elements required for the conception of such virtual environments. Finally, we discuss the interest of our approach.
Organization safeguards can never be entirely effective because the decision makers cannot foresee all the possible accident scenarios. Then, contributing factors originating at many levels of the system, in combination with local triggers, open a window of opportunity in which the hazards are allowed to pass unchecked through successive weaknesses in the so called defences in depth. This is why a good organization has a continuous improvement process, and why a good continuous improvement process has frontline teams playing the key role of the last line of defence against organizational gaps, weakness or failures. The paper introduced a way of using Virtual Reality focusing on frontline teams for improving organizational safeguards. It presents a methodology build up during the Virthualis project, able to address the following questions: How to design an organization which provides frontline teams with some mental skills that would help them to recognize and, if possible, contribute to avoid situations with a high error potential? How to design an organization for managing of learning and changes based on such frontline teams contribution? This methodology addresses the way safety rules are written (integrating roles and responsibilities, procedures & risk assessment). It defines a structured approach for designing and using virtual environments... making it possible to work, in a collaborative way, for the design and the implementation of good practices during nominal situations and in case of degraded, rare and/or dangerous situations. This methodology is still in a research and development phase. It has to be tested and improved.
VIRTHUALIS is a European Research Project on Industrial Safety with the overall objective of evaluating and, where possible, reducing the risk level in production plants and storage sites with the integration of Virtual Reality and Human Factors methods. For the estimation of Human Error Probabilities a specific tool has been developed named the Fuzzy Probability Estimator (FPE). The application of the FPE tool in a specific case study is presented in this paper. The specific case study aims at analyzing the start-up of a gas turbine used to drive the compressor of the butane/propane refrigeration section of an LPG storage and treatment complex. The example chosen is the case of oil leakage at the coupling of the turbine with the compressor. Specifically detailed through bow-tie analysis, the action it refers to is the operator visual check of the coupling area. Performance Shaping Factors (PSFs) that influence operators' reliability have been identified and rated for the specific site according to expert judgment and on site observations from human factor experts. The PSFs are linked to specific task deviations and, in relation to those and to the need to observe how they influence the task, the design of VIRTHUALIS simulation experiments is performed.
V3S (Virtual Reality for Safe Seveso Substractors) is an ANR/RNTL project (French national agency for research). In this project, we aim to design a tool allowing to scenarise hazardous working situations on SEVESO sites for risk prevention, training and decision making. The tool interprets a high level task and a related risk model. It is meant for a manager to help him/her to make decisions. The manager plays the scenario of an intervention anf manages a team of virtual operators (associated with autonomous agents) in the VERP (Virtual Environment for Risk Prevention) submitted to constraints. Depending on his/her decisions, the incurred risks are displayed in the virtual environment. Our architecture relies on a multi-agents platform (OMAS). In this paper we present some of the features of the tool through different scenarios. We present the organisational rules of our system, how it self-adapts to the technical competencies and the characteristics of the operators (human factors). We also present the working environment hosting our agents.
Domitile Lourdeaux合作论文数Heudiasyc Laboratory, UMR CNRS 6599, University of Technology of Compiegne,1