📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

Mastering Critical Risk Management in Mining: A Step-by-Step Free Webinar

Impress Solutions•1:06:19

Transcription

So welcome. Um, we, I was just talking about before people joined. We, we thought we'd have a crack at putting in a quick webinar before the Christmas breaks because obviously this stuff, uh, never ends. So I appreciate your time. Uh, today is certainly not going to be a waste of time. Now, if you sat on my webinars before, pre-frame, if you can get rid of any distractions, um, you know, anything like that, how you're going to take notes. I am recording this as well, so we'll talk about at the end how you can get a copy of the notes and the slides. So don't get too distressed if you can't, um, you know, keep up and get yourself in state. So if you can turn your phone over, you know, you probably got alerts, emails, all that. We're going to go hard for the next 40 minutes and encourage you to, um, create the space you can and get in the right, the right frame here to, uh, soak up the information. And, uh, Nick, I think this is one of your prompts. So we've all used the chat. So to you, in either your experience or use your business, definition doesn't really matter. What is a critical risk? If you could sum it up in, you know, a single few words or, or a one-liner, what is a critical risk? What does it mean? What is it? Please spend about 30 seconds. So something in the chat. So I need a risk of death to one or many. So anything that could be a single fatality or worse. Um, or a large fiscal or financial loss. Yep. So we know it's not just necessarily related to safety. We could have other consequence types which could also be critical. Let's say anything above your materiality threshold. Um, excellent. I'm going to assume you already knew that before I made reference to it before. Um, absolutely. So there's an idea of what business considers something that's a materiality in terms of consequence. And if it's above this, then it could be classed as material, sorry, as critical. Um, could be environmental, financial, um, reputation. Absolutely. Can have reputation critical risks. Michelle, risk of severe impact, life-altering event. Yes. Um, Nicholas, if it's high likelihood and or high severity, yet can push you up into materiality, sorry, to critical. Uh, Grant, a risk if uncontrolled could result in injury or incident that would be classed as significant. Yeah. So we can see this theme here about significance and material. Just got to let someone else in. Um, and that's certainly something that we'll talk about a little bit later. Each business is going to be different, and it's about working out what is critical, what is significant, what is material for for you. And I give you the example when we run the training session. So think if I'm a, if I'm a BHP, then what my might be material for me in terms of financial threshold might be different to a small two-person workshop, um, with a local mechanic. So we can see that depending on the context of the business can influence what is classed as significant or material. That's good. Thank you for sharing. And good morning. Uh, who just joined? John, good morning. Good morning. How are you? I'm good, thank you. I'm good. So we just got started. Haven't missed anything. Um, so look, we talked in and around this. Um, we've given some examples there. I won't, won't ask the, the group. Um, so any risk, this is my layman's, layperson's terms, any risk that if realized, the consequence would be material to that business. I think someone mentioned, Michelle mentioned, you know, could be life-altering, either for the organization, um, or for an individual. So we, it's helping to frame up those types of things. So there's a question, well, um, what's the difference between fatal risk and critical risk? Well, that could be the same. You could have a fatal risk that's also classed as critical, if that makes sense. So if we have a, a criteria or a threshold, and anything above that, if it's a single fatality above that threshold, then it falls in the category of being critical, as would a significant environmental event, or a significant financial event, or significant community event. Okay. So where are we with, with critical risk management? What's, what's the problem? Um, well, the problem, as I see it, or as we see it, doing a lot of work across the industry, is we're not fully in control of our critical risk management process. And how do we know this to be true? Just look at the numbers of high potential incidents, significant incidents, critical control failures, you name it. And unfortunately, uh, fatalities, which are still occurring. And the promise, I, I'll make on this call, is we will cover off the foundation that if you get them in place and get them right, it really sets you a step ahead onto a pathway of, of a very comprehensive critical risk management framework. Um, for a few of you, I know I've seen you on calls before. For those that don't, um, about me in less than 15 seconds. I've been in mining safety for 23 years now. Um, I have Impress Solutions, which is a bespoke health and safety, um, services company. And we're all about saving lives at work. And in relation to critical risk, we have now done work across the big tier ones in terms of mining. Um, and I like to think therefore that what we've been able to pick up, apply, um, learn and share, is, is at the forefront. And certainly, we do a lot of work around critical risk training. And we've looked at oil and gas and a little bit of aviation and brought that into the mix too, in terms of, of what we do and who we are. So I'm working on it. When I, I think, uh, an, um, will, will come out. And while there's a picture of the push-ups, it's my daughter gets to watch the replays, and it's five push-ups. So every time it slips out, I'm working on it. Bear with me. Critical risk management is a bit of a mouthful, so I'll shorten it to CRM. Going to move fast. There's a lot to get through. So create space for questions at the end, and let's make it interactive. We, we've already done that, so that's great. The more feedback I can get from yourselves, the better I can tailor it, um, to what we need to focus on. So how the webinar is going to work. I will go through the fundamentals, um, which essentially is this framework here to the right-hand side as I look at the screen. I'm going to talk at each phase, um, what the objective is, what good looks like in terms of what an organization would have who was doing some, some work there. And at the end of each phase, there's going to be a self-assessment for you, either based on your, your knowledge of industry or for your particular business, is just where do you sit on the scale in relation to, to what good looks like. Um, move through that quickly so we can have plenty of time for Q&A. And this is, this is a massive framework. We do a two-day intensive course, and we still don't get through everything end to end. So I won't be able to cover everything. But at the end, I'll cover off what you can do to get more help or get more information if you need it. Uh, so stick around. As I mentioned, we, we release a copy of this recording. I can just see that's being spelled incorrectly. The slide pack, and there's also a free bonus as well that we'll make reference to here, which I think would help, help you. Okay. So the next question, in your experience or within your current business, what's the biggest challenge? What's the hardest part about getting critical risk management right? What's, what's the hurdle? What's the sticking point out of everything? I mean, because there could be lots, but what are you seeing right now in, in your world, is, is the biggest sticking point? And I'm inviting now, is spend, we allocate 30 seconds to jump in the chat and, um, just share. It'll be interesting to see if we see some of the same themes that are, are being shared. So the hardest thing, the biggest sticking point, thing that's just not working well, what, what are you seeing? Grant, verification activities to ensure they're not just a tick and flick. Uh, that is certainly not just particular, um, to, to you guys. That's a good one. Thank you. Michelle, definition of critical. I, when conducting a bow tie, the groups are divided and what is critical to the failure prevention. That's interesting. We won't unpack that one today, but that is an interesting challenge, that one, which certainly helps with how we scope out bow ties. Sean, want people's knowledge and understanding of CRM or fatal risk versus critical risk. Yes, that's, I think Michelle has talked about that one as well. That is an interesting one, and we see there's some knowledge gaps, um, even from people that design and build the system, like risk owners, control owners, people doing verifications, um, frontline workers as well. We, we see some knowledge gaps in, in lots of different parts. Anyone else? Anyone else got, um, something to share in terms of point, difficulty, pain point around, around the critical risk management process? Anyone else want to throw something up there? Am, setting realistic controls. I could get on my soap box about that one. Um, that is spot on. Um, and if we, we look at a lot of the fatality reports, certainly the Brady report, it's, it was all about controls just weren't effective. Uh, uh, John, high turnover, people in remote areas. So I'm going to guess that might, might come back to the training and skillset of those people applying the critical risk management process. And Grant, getting risk owners. So I'll interpret that as in finding them, giving people some, some risks, that's the way I'll interpret that one. Thank you for, for sharing, um, that. And feel free to put some stuff in there, um, around that. So thanks for the challenges. Um, we'll certainly be able to cover off off this. Um, now, as I mentioned, this, this is the framework we'll use and, and go through. And this has come from the International Council of Mining and Metals. So you can see these two little help guides down here. If you Google them, ICMM Critical Risk Management Framework, it'll return you back these help guides. And these things, um, so caveat on this, I mean, it's a good, good starting point. It was released in 2016, so it's, won't call it dated, but certainly the, um, the knowledge of applying critical risk management, the tools and things have evolved since this was released. So it's, it's a good starting point, but certainly don't think that, well, if I do these things like this guide tells me, that I'm, that I'm ticking all the boxes. Um, it's a bit light on the how, how you do some things, but it says what the outcome looks like. So we're going to work through these, these steps, um, pretty quickly in the next 20 minutes. All right. And we'll put a bit of context around it. So imagine, um, for those that aren't in, in Queensland, think a, think of a coal mine, a surface coal mine, so nothing underground. We got some big trucks walking around, driving around. We got some, some workshops, we got some main administration buildings. And let's say we got, I don't know, 400 people on, on shift, and they're all, all employees. So imagine in that, in that context, you're the safety, um, well, you don't have to be the safety person. Let's say you've been tasked with implementing a CRM process. And the surface fire risk is something that's come up, um, now and time and again. And therefore, there's this slant here about we making sure we cover off this critical risk around, around surface fire as part of that. So we'll go through this, and we'll, we'll keep coming back to, um, to that scenario where I can, to give some examples and put a bit of meat on the bones. So this, the first part here is around planning. Um, so the way this process was designed was pretty much, if you had no critical risk management framework at all, you got nothing about nothing. This guidance even says, okay, well, if you're going to put together a plan, here's some essential elements of a plan to go and implement a critical risk management framework. So talks a bit about that. Um, the one that I like to focus on is more the business as usual critical risk management process. So it's a pretty involved, pretty complex process. Therefore, what we'd expect to see, or what good looks like, is somewhere there's, there's a document or a clear description which describes how, what is a critical risk management process for you? Well, for your organization, what does it look like? We do this, we do this, we do this, we do this, we do this. This person does that. So a description. So sometimes it's a standalone document, sometimes it might be inside a risk management procedure, it might be something else. Um, so it's to iron out who does what, and what frequencies, what are the tools we use, um, as part of that. These ideas of risk owners and control owners understand this process because they've got a part to play. And organizations have defined their materiality criteria. So remember, we made reference to that a little bit further. There isn't any, what do I call it, arguments. We've, we've set the threshold, and it's pretty clear. If this thing, if we had a surface fire, it would either most likely result in this outcome, which is above our threshold, um, or it won't. There's no real grayness around that. So thinking about this, and this is the first question here around the planning and description of the process, how does your business perform right now? If you could give it a rating out of one, out of 10, so 10 based on what we described, look, it ticks all the boxes, pretty confident, covers off all of the aspects, or one, you know, it's got nothing. There's nothing here in terms of planning out a process, describing the process, um, you know, familiarizing people, overview of the process. Um, so you can jump in the chat and literally, it's just a number between one and 10. Where is your organization fit? Thinking about this. We got an eight. Need an eight. Sean, seven. We had a five. Right. Some others. Where does your organization sit when you look at the, what good looks like? Adam, six. Thank you, Adam. Good morning, by the way. Afternoon. Michelle, a five. Ben, an eight. What else? Anyone else in the line? Nick, you're five. Okay. Anyone else want to share? Okay, so everyone's kind of got something there. It looks like listening to the masses. And feel free to keep jumping in. So thinking about, we've, we've now described our process. We know what we're going to do. Um, this is how it's going to work. Our first step here is around, uh, in this particular framework, they called it identify material unwanted events. Let's just use the term interchangeably, critical risks, okay? So what are those things that are above our threshold? What are they? So our desired outcome is a defined, and I guess, agreed to list of critical risks. And I've jumped to a different slide here because in terms of what good looks like, and it's very interesting in Western Australia, I don't see a lot of these. Is most organizations have a broad brush risk assessment, or sometimes it's called a baseline risk assessment. What is that? It's a high-level, organization-wide or site-wide risk assessment, which is reviewed annually with the management group to say, okay, looking across our business, where are, or what are all of our critical risks? What are those things above our threshold? And going through a process, kind of using a risk matrix type template, which is an example pitched here. What are they? Likelihood, consequence, what's the maximum consequence? Um, what have we currently got in place? What do we need to put in place? What's our residual risk ranking? Also inside there is, well, who, who owns this risk? So for example, surface fire, that would be one of the line items here on, on this particular risk assessment. And for this business, surface fire is going to be owned by the, uh, I can't remember who I said in the example. Let's just say, let's say it's the emergency response coordinator, or something like that. Um, as part of going through that, we look at our safety and health management system to check, okay, if we have a critical risk, do we have a safety and health management system document that describes how we manage that critical risk? For example, our business said there's surface fire, therefore there's a fire management plan, which talks about how do we manage the risks associated with a, with a fire. So thinking about this, how does your business stack up here? Um, so think about what good looks like. So we'd be looking for an, an overarching risk assessment, reviewed well, hopefully annually. We know who risk owners are. Um, we know if the safety and health management system has documents related to the critical risk. What is, what does your business look like in this particular space? Uh, so Michelle, you shared a four. Okay. What are some other people got there? Adam, about a five. So again, halfway. What else? So think about what these things are, what good looks like. Sean, six. What else? Anyone else got to share? Ben, a six. Okay. Nick, a six. Okay. So everyone's indicating we've got some stuff there. There'll be about a five. Okay, that's good. Anyone else want to share quickly before we jump on to the next one? All right, keep moving forward. Thank you for sharing, guys. It's, it's really good for me because I can then think about later on, um, some of the questions and what we might focus on. All right, this looks a little bit busy. I'll explain it, and it hopefully it makes sense. So think about, we planned our process. We now have a list of our critical risks. Um, thank you, John, eight. We are now going to, and the bit here in black text with yellow background, this is where we, we move a little bit away from this framework. We analyze critical risks, don't we? So we identify a risk, then we need to analyze it. And within that analysis, we do what, um, this talked about here about identifying controls and critical controls. That's all bundled up here. And what I, what we class is analyzing the critical risk. So what's the objective? We want to do, we want to take, take each, um, risk. So let's say surface fire, and we want to identify through a specific risk analysis, what could cause a surface fire? What could be the consequences or impact of a surface fire? What are our specific, measurable, audible, realistic, timely controls that either prevent a surface fire or mitigate surface fire should it happen? For each of these controls, how effective are they? Um, for each of these controls, which would be classed as critical, uh, so the critical few that we need to make sure they are in place and working. And for those critical few, how could they fail? And what are we going to do about stopping them from, from failing? So what do people currently use, or what have you heard of, is the most popular risk assessment tool to analyze a critical risk? Who's seen something for here? Any risk assessment tools come to mind? Bow tie. Eletta, you hit the nail on the head. Um, thank you. Hopefully, a few of us were thinking about that. Um, again, not sure what your level of, of knowledge or experience in bow tie is, and this isn't really a bow tie webinar, but essentially, as a recap, we have our, our loss of control event in the middle. So this could be surface fire, loss of control of vehicle, etc. We have our causes of a loss of control of vehicle, and we have consequences or impacts should we have a loss of control of vehicle. Then we have our preventative. We have our preventative controls here. So we have, for example, for the cause of the driver unfit to drive, we have these four preventative controls that prevent driver unfit to drive leading to a loss of control of vehicle. Then we have mitigating controls. It's okay, well, if we, if we've lost control of the vehicle, we have two controls in place to help decrease how much damage we have to the vehicle. So we got crumple zones and we've got barriers on, on the roads, as an example. So within here, we can see we talked about the different aspects. We'd identify, um, each of these controls. We would then do a control effectiveness assessment, which I won't talk about here, we don't have the time. We test how effective are each of these specific controls in their pathway. And we'd also go through a process, which I'll talk about here, just quickly, around identifying critical controls. So this time and time again, and this might be relevant to your organization, is, uh, for some reason, we crit, identifying critical controls can become this big behemoth, and there's lots of debates and things like that. And generally, when, and that might be relevant, you might have been experienced or exposed to some of that. And generally, in those scenarios, it's one of the contributors is, is a lack of some type of criteria that can be applied to identify or to come up with which of these controls is critical and which are not. Um, so here's an example of a, of a control critical control selection flowchart that we use. Now, one of the things here, um, which a lot of people, well, a few selection flowcharts don't necessarily consider, is how effective is the control in and of itself. Thing about it, if we, if we took a, a standard administration control, um, you know, one, one of my bugbears is positive radio communications. If you put that onto an effectiveness chart, how effective would that control be? And if we say, okay, look, it's not that effective, then why would we then go and say, well, look, let's, let's make it critical and go and do all this work around, um, setting up performance standards and verification frameworks and everything like that for something that isn't really effective in the first place. Um, sometimes that's an uncomfortable conversation for some businesses. Okay. So summarizing this area around analyzing critical risks. So what good looks like, generally, what we see is we all see one bow tie or one specific risk assessment per critical risk. So surface fire, surface fire bow tie. The controls are smart, specific, measurable, audible, realistic, timely. So not, we don't have controls like induction or training, um, things like that. Um, the effectiveness of the controls have been assessed. Um, critical trials have been identified via an objective process, or more objective process. How they fail and what's going to, how we prevent that has been identified. And we have owners identified for critical controls and also for risks. So this was a bit, it's complex. We're just skimming across the top. How does your business compare on, on these ones? So thinking about the, what good looks like, analyzing critical risks, if you could rate your business out of 10, one being, you know, it's got nothing, 10, it's like full ticks, looks really good. How does your business, um, stack up here? So encourage you all, you got to do is just put a number into the chat. This is going to help everyone else understand, you know, where things are at. Eletta, three. Thank you. John, seven. Kurt, seven. Anita, seven. That's good. Michelle, four. Who else? Who else wants to, to share? Benner, six. Awesome. Who else? Chile, have you got anything here? You guys stack up or Daisy? Thank you for those who shared. Okay, Adam, six. Awesome. Thank you. Ben, six. Okay. I'll keep an eye on that. Thank you for sharing. There's a good self-reflection as well. All right. So think about what we've done. We've planned the process. We've identified our, our list of 30. For each of those, we've now done a bow tie, come up with critical controls, um, who owns the things. The next step here is around, for the critical controls, we wanted to define its performance. So the desired outcome here is define the required performance of each critical control on aspects such as, but not limited to, um, so what do we do to make sure the critical control is in place? So for example, if we said, uh, one of the, the critical controls is the fire, fire, uh, sprinkler system, then what are some things we do that just make sure the fire sprinkler system just stays in place? It could be, okay, we do monthly checks and this and that. So ownership, who owns the control? Training, so people need specific training related to fire sprinkler systems or training related to another type of critical control. How can it fail? We've called that out. TOS or or triggers. So if it gets to a certain threshold, what do we, what are we going to do to make sure it doesn't fail completely? And verification strategies, which is what a lot of us would be familiar with. Who's going to go and check what, at what frequency, to make sure this control is still in place and working? Um, now, it's kind of might have already given the game away, but what's, what is a popular tool used to define the critical control requirements? Anyone share that one? Except Eletta, because I think you've already asked about it, so you probably know the answer. Is anyone has anyone seen something out there that helps put all this in, all this information together that we've described here that we wanted to find? Does anyone know a tool that's seen or used that allows us to do that? You most hopefully, a few of you on the call might have them. Pretty control verification. Almost it comes out of the performance standard. Yes, um, but kind of the same. Thank you, Adam. So performance standard, critical control performance standard. Lots of words here. Don't worry about it. I'm not going to read it. So think about if we have a critical control for a fire sprinkler system, then my organization is going to do the work to consider all of these prompts here on the left-hand side, or all of these aspects related to a critical control, and is going to work out what do I need to put in place? What is the performance I expect? For example, availability. So if I got fire sprinklers, well, I'd want to have my requirement is 100% availability. And if that's the case, then what do I have within my business to ensure the fire sprinklers continue to be 100% available, as an example? And that's the work we do inside a performance standard. So an example here is a, is a template that we use for our, for our clients. Obviously, it is a bit of work to do. But you do it the first time, then you, you set up the system. So it also includes here, and Chile were making reference to this, is is the verification questions and who's going to do what and check some things. Okay. So think about for each critical control, we want to, what, what good looks like is answer as many of these aspects as possible, because we want to make sure that critical control stays in place and works over the lifetime of the control itself. And Chile was making reference to this, and some of you may be familiar with these, is the critical control verification strategies, which is, okay, now that we've defined the requirements in the performance standard, we're essentially going to audit these requirements. Um, and I've given some simplification here. Who checks what, how often? So we could have one performance standard for a critical control. Let's say the, the fire, the fire sprinkler system is here, and we could have multiple different checks all associated with a fire sprinkler system. So for example, one of our verifications, this one here, might be a ground training and competency. So we check that the people that maintain the fire sprinklers have the right competencies. And that could be the nature of a check here, where a second one could be around, um, because we know we do monthly checks on the fire sprinkler system, then we're going to do a verification sample every six months. Let's just go on sample and review the six months of, um, monthly work orders, and have they been completed? Was anything coming up that we had to take care of? Doing a bit of a sampling strategy, and so on. Okay. So looping back. So in this area around performance and reporting, what good looks like is we have a performance standard for each critical control. The performance standard covers off all of the essential elements, or way more than just one or two things. And we have critical control verification strategies are mapped back to the performance standard. So again, another self-assessment rating. So how does your business perform in relation to this particular, um, phase here of the critical risk management process? Is that one? Look, we really don't have much at all in relation to this. 10, we've got it all covered. Um, please share your figure between one and 10. Do your self-assessment. Kurt, you're an eight. That is really good. There's not many businesses, um, that would pump out an eight. An an eight. Well, that's good. Six. Adam. Michelle, three. Yep. Four. Eletta. Thank you. Daisy, three. John, eight. Ben, seven. I'm remarkably surprised here, in in a good way. In a good way. Sean, four. Anyone else want to share? That's, uh, good. Nick, two. Yep. There's, there's some businesses we work with that if there was a negative number, um, there would be, be classed as a negative. There. Thank you, everyone for sharing that. Okay. All right. Accountability. So to recap again, we've identified our material risks. We've analyzed them. We've got bow ties for each of those. We know what our critical controls are. For each critical control, we've identified a performance standard and verification activities. Uh, this step here, assign accountability, is pretty simple. It's, well, who's going to own the risks? Who's going to own the critical controls? Who's going to own the verification strategies? So all of this work that's falling out, who owns that? So examples of what good looks like. Say, the only thing is there's some formality around who is a risk owner. So it's not necessarily a name on a spreadsheet. It is, you are now accepting responsibility of a risk owner. This is your responsibilities mapped out. Sign that you accept this, and that goes into the management system. So that's like an appointment type thing, or authorization, what do you want to call it, but a formality there. Same with critical control owners. You know, being absolutely clear, what are your responsibilities? You need to accept this. Here's the things you own. You know, there's no back and forth. Um, and also on the training front. So if we know that these people who have ownership need a certain type of training or C level of training, let's say if I'm a critical control owner, there's some things that the critical risk management process requires of me. How do I know what those requirements are? You know, can someone train me in that? Or is there a little module I can go and watch or something like that? So this was a simple one, less medium than the previous one. So how does your business map up and stack up against this out of from 1 to 10? So around assigning accountability, knowing who's accountable for what, um, making sure those people are trained and mobilized. Nick, you guys are an eight. Kurt, a three. Ben, a seven. Ela, a five. Adam, 526, depending what day of the week it is. Nice. John, a seven. Uh, Grant, what if you're a small business who work in remote areas? How do you assign risk owners? Excellent question. And generally, small businesses, unfortunately, someone gets more than one or two or three. Um, I'll, I'll go deeper on that later in the questions, um, but essentially, that's what you need to do. Someone, some role within the organization needs to say that I'm the owner of this risk. And if you have critical controls, then I own this particular critical control. So sometimes it's the poor old safety manager, because everything's safety, uh, gets handed, but more mature organizations are able to divvy it up. Um, but then not to add more complexity, I'm just keeping an eye on time, is we're starting to get into this interesting space now around what competency, or what knowledge base do you need to have in order to be a owner of a particular risk? So where previously, let's say the older, older school of thought is, we could just say, look, we've got 30 risks. We've got managers. What's 30 divided by 8? I know what is that, 3 point something? Let's just divvy them up. That's yours, that's yours, that's yours, and just keep going around till it's all done. Um, now, certainly in Queensland mining, and I think it's a good thing, they're now saying, well, hang on, you need to check, is this person competent to own this particular risk? So I can't unpack that one here today. That's a whole another, another webinar. But that's just something to think about where industry is shifting. Happy to talk later, mate, on that one, um, and, and help you out on that. Will stand the line, definitely. All right. Implementation. So this is, um, if you remember right back at the start, said how this model was framed is if you don't have anything in place, before develop a plan, design out these things, and then go and implement them. Um, so generally, obviously the outcomes you want to implement it. Sometimes organizations do a take two, refresh everything, and then go again. Um, so anyway, whatever, whatever the case is, we're implementing some things. And we're also the actions from upstream activities. So think about if you've done 30 bow ties, there'll be a whole host of work that needs to be done in relation to those risk assessments. And, you know, things that need to be created, fixed, repaired, checked, all those sorts of things. So what good looks like, um, in this particular regard. So all actions from the broad brush risk assessment, so remember back here, we said, well, if we do this annual thing, we look across the business. So all actions from, from there, there has been implemented, or at least allocated and underway. All the actions from the bow ties have been documented, assigned, and hopefully implemented, or on their way to being implemented. We've got those verification programs which we've set up. So remember we said, who's going to go out and check by what, by when? So we go and create the work orders or those recurring actions for that to happen. Um, if we have to create new safety and health management system documents, so remember if we said, if there's all these critical risks, then we want to see something in safety health management system. So it could be creating some new, um, management plans, could be updating some management plans, some new forms. And we've done the training as well, you know, certainly down to the workforce, the frontline worker, what do we train them in? How often? What do they need to know? This is all some examples of what good looks like around implementation. Okay. Another self-assessment. How's your business stack up here? Thinking about just some examples of implementation and some things that would be in place for an optimal functioning CRM program. From BA, we got Adam's a five. Ben's a six. John's an eight. Okay. Kurt, seven. Sean, six. Who else? Anyone else want to share? How's your business doing with implementing the CRM process? Certainly one of the interesting questions is, does the frontline know what their critical risks are? Do they know what the critical controls are associated with the work they're about to perform? Anyone else want to share where your business stacks up there? Okay, we keep moving, conscious of time, and I know this is a lot of info. All right. So we've implemented the process. Obviously, now we want to just be checking it. Does that, does it make sense? So we want to be implementing verification activities where people are going out and checking things that we said we're going to check. And we want to be doing some reporting on the process. You know, how, how well is the process functioning? What's our risk profile doing? What's the status of our controls and critical controls? And could be a whole host of things that, that could be there in terms of, you know, when we go out and do a verification, what's our criteria of, if, what's our status? Is it, um, is this critical control at good effectiveness, satisfactory, is it inadequate? And then therefore, what do we need to do? I think this color coding is a little bit as about, um, do we have some dashboards in place that we can do some higher level, um, visibility on particular critical controls? And then if we go inside that, if something's red, we can go inside it and unpack and see what that is. Do we have some process metrics? So not just how's our safety going, or how's our risk going, but how well are we going? So for example, um, are we actually completing a verification in accordance with our schedule? Are we attaching evidence for our verifications, etcetera, etcetera? So we can measure the health of the process as well. So what good looks like here. So we've got some KPIs, so some performance measures set up, so some metrics and things. But we've also got some targets and in, and around that. And also, some of these targets are well thought out. They're not just, I think someone mentioned right back at the start, it's not just, um, driving more bureaucracy. So if we set ourselves a pretty aggressive target, let's say 10 verifications a day, if you really hit that hard with a hammer, you're going to get 10 verifications a day. But are they quality? Are they giving you any real value? So I'll call that well thought out KPIs. Um, we have verification activities completed in accordance with the schedule. There's evidence provided. And the business seems, sees the good things. Well, one, if a control fails, we can report that. There's a mechanism. It can be escalated, and it's actually seen as a good thing. Yeah, we're proactively identifying an issue with a critical control. We're not waiting for an incident. So self-assessment time again. How's your business look on this? So set up metrics, set up KPIs, verifications are happening. So need is a no. Look at the old ones. Kurt, an eight. Well, you guys are really kicking some goals. Eletta, four. Adam, five. Uh, I don't know how to pronounce that. Al a Beck, a one. That's really honest. John's an eight. N is an eight. Ben's a six. Okay. So it looks like some people have some stuff in place, which is good. Sean's a four. Excellent. All right. Keep an eye on that. And the final step in the framework, um, here is around responding to inadequate critical control performance. So we go do all these checks, we do all the reporting at step eight, then when we get some feedback about something's not working, what have we got in place to fix that or respond? So here, we want to make sure critical control owners, risk owners know about, have the intelligence of what's going on. And we want to make sure that any failure of critical control, we investigate, we understand it, and we put them, put some things in place to stop that from happening. Um, so it can get a little bit challenging because we might have critical controls that fail via an incident. We might have a hazard report pick them up, or we might just go out and do a verification. We might say, oh, look, the control hasn't failed, but there's an issue with it. So is that classed as a failure compared to if it's failed as an incident? And so what we've come up with is similar to what you do with incident, incident, um, analysis, where we just take whatever the prompt is throughout the critical control, and then ask ourselves, what was the actual or potential consequence of this? If it's something that could have been pretty bad, let's say a four or five, whatever is particular to you on your matrix, then go off and do what you'd normally do with a, if an incident of that nature, or or a high potential hazard that could have resulted in some of those things. If it was something less than that, it's like, yep, there was a little bit of an issue, but it wasn't going to be a big deal. Then part of our performance standard that we had defined, we say, what do we do if there's an issue? You know, a lower level thing? Well, someone does this. So it could be that, um, the critical control owner is informed. They make a determination. Is there anything else we need to do? And if no, happy days, move on. So what good looks like is businesses have got their head around how to evaluate failures, productive failures, um, which is what I'm talked about here. So what good looks like, critical control failure assessment process defined. The incident investigation process includes consideration of critical control. So when you have a high potential incident, does the investigation ask for, are there any critical controls associated with this particular event? And if there were, how did they perform? Did they do what they wanted to do, or they didn't do what we wanted them to do? And post investigation, is we then go update, when we have our learnings, we go back and update bow ties, broad brushes, causes, performance standards, whatever we need to update to learn and improve the system. So final self-assessment. How does your business stack up here? It's all about responding to when we identify things aren't all good about this critical control. So self-assessment, last one out of 10. What does it look like? So CTT's a three. Sean's a five. Uh, Anita is a nine. Wow. Okay. Adam, five. John, seven. Ela is a five. Who else? Anyone else want to share? Ben, seven. That's pretty good. I mean, anything over five, that's actually pretty good. I'm going to assume then a lot of people, their incident investigation process has been updated. Nick, three. Yep. Okay. So there's probably a few different reasons why people are showing up today. And certainly, you've shared some of the pain points, you know, fatal risk versus critical risk, um, I think someone mentioned about scoping out of bow ties, um, it could be confusion, what's critical risk? You got some stuff in place, but you're not sure where it sits in the scheme of things. Is this an issue? Do we need to improve this? You know, that controls could be improved. You know, that performance standards, you don't have any performance standards. You go, well, we need to do something in that space. Whole host of issues. So what we do know now, after going through that really quickly, is that multiple steps in the process, and each step builds on the previous. Hopefully, that's clear now. So if you get an upstream step wrong, then it can just create an absolute cluster. So an example is, some businesses don't have broad brush risk assessments, and there's critical risks which are within their business, but they haven't identified them and aren't managing them. And there's nothing in the safety and health management system, and therefore there's no critical controls for them, therefore there's no, you know, verifications, etcetera. And there are many activities and deliverables that need to be put in place. So there is some administration burden that comes with it. Obviously, the brings up time and time again, the obvious question, how do I do it? Um, you can do it the slow way, like I've been doing for the last seven, 10 years, trial and error, learn some stuff, apply some stuff, move it forwards. Or you can learn from someone who's done it a bunch of times. And so I mentioned at the start, what you can do to get some more information, um, or some more help. And one thing that we are offering, only for the next two weeks, is essentially a free gap analysis of your CRM process and supporting documents. So like that framework we just went through, we've got a tool there, and we can do a desktop review of what, what the organization looks like and give it some, um, intelligence there. And obviously, it's not for everyone. So if your CRM process is good, you're comfortable with your skillset, then it's not, not for your organization. But if you think, hang on, yeah, we probably have some gaps, we think that we know what they might be, but certainly could have some help. So if you think the process could be improved, you're on the fence about your knowledge base, then this is certainly a process, um, here that would support you guys on that. Um, why we do it, like our mission, I've been saying for the last four years, so that know us, it's all about saving lives at work. So if a through one review, we can help you identify some low-hanging fruit that can then plug a big gap or a small gap in the system, then that really ticks our boxes as well. And obviously, other thing, you know, we want to support as many businesses as possible. If you feel that we give you some good support from a free perspective, then when you might need some extra help, then, you know, you might think about us. So how it works, and lovely put our email address in the chat. It's

Pretty simple. Send us your stuff. We complete the review, and we have a 15-minute call. Obviously, post the holiday break, where we just walk through what we found and what the next steps are that you guys need to undertake to do so.

What's the benefit? Well, I wish I had this 10 years ago when I was doing this work on behalf of another organization. We do all the work, there's no cost to you. You can tap into our knowledge base. We've got a pretty big library now of stuff and a pretty good idea of what a good process looks like, and we can give you the low-hanging fruit. So, even as a result of that, it could just be some simple things you can do that then certainly is not a bad place to start. But for only two weeks, we're pretty busy across Christmas break. So if you're interested, then send us an email. The email address there, lovely's put in the chat. And then we can get the dialogue on the way and get it happening.

So that's one thing that you can do to get some more help. A second one is, we that process we just went through, remember we got to the step which is around analyze critical risk, where we start talking about bow tie and causes and critical controls. We find that's an area that a lot of businesses struggle with. So we're doing a specific webinar on that particular process. On what is that January 16th. Lovely will put in the chat there if you want to register and come and join us. We that's pretty much what we unpack bow tie and we go a bit deeper on how do you measure the effectiveness of a control, how do you identify how a critical control could fail. So that's what we're going to do in that particular webinar. So again, lovely's got the link in there if you're interested in that.

We're also unpacking psychosocial risk management. Now, I don't know, just a quick poll. Who's got psychosocial risks in their critical risk framework? Can you just give me a yes or no? So quick poll around the ground. Yes, you've got psychosocial risks integrated. No, you don't have yet. CT working on it. Michelle, yes. Eletta, no. Who else? Daisy, yes. That's good. Back, no. Nick, in progress. Sean, working on it. Who else? Adam, Chile, Grant, how you guys looking with psychosocial risks and bringing that in? Because this is certainly all the rage at the moment. Adam, not yet. Grant's not started yet. Chile, yes. Okay, good stuff. So we're seeing this is a real, real issue because businesses are almost starting to go and create a different framework to manage psychosocial risks compared to physical risks. And Nomi and I have, we're helping businesses now just say, hang on, you can bring them in the same critical risk management framework like we've just gone through here with a few little tweaks. I'm not breaking the process, just a few little considerations. So that's what we're doing on January 17th. Lovely will put the link to that one if you want to come along. Same type of thing, we just share some stuff and you can go away and become armed with more info.

So that's it. I've done pretty well and I'm happy to stay on the line afterwards. That was a lot of info. I can now take questions if anyone's got a burning question. Put in the chat. In the same time, if you want to take advantage of the CRM review, send us an email right now while we're doing the chat. You can also find the links there to jump on any of those webinars and register for them. But does anyone have a question right now that I can answer based on, or try to answer based on what we just went through? And I do apologize in advance, there was a lot of content, but I couldn't think of any other way to do it by the framework, it's in its entirety with as much as possible, just what are the critical few things moving in around. Has anyone got a question? If you do, throw it on the chat or a comment. If not, I'll go back to the front here and see.

Okay, fatal risk, critical risk. So I can't remember who was asking about, I think Michelle, fatal risk, critical risk. Are we more comfortable now in understanding that you can have a critical risk that is a risk that has a single fatality? You can have a critical risk that could have resulted in a multiple fatality? You can have a critical risk that could result in environmental impact. Like critical risk is the catch-all for anything that we class above our threshold is critical for our business. And inside that, there is single fatality, multiple fatality. Michelle, yes, it's just a challenge I face when getting my organization understand it understood. Feel free to throw a question in the chat. Otherwise, I'll look at what people mentioned right back at the start, looking for guidance and drafting a good critical risk performance standard. So hopefully, El beta, we covered off a little bit there within the slides now in terms of what we believe are the essential elements of the performance standard. And that's what we use to help clients build that out. And happy to M if you send us an email, we can give you a copy of that template. Just let us know.

Well, no one has another question at the moment. And I'll stay on the line after this if people want to just ask some questions. Now, also, as I mentioned, some freebies and where we can give you some info. So as I mentioned, we can perform an audit of your end-to-end critical risk management process. We also have a checklist that you could take that framework and do it yourself. So lovely, actually, no, the best way, easiest way is just email us. Ask us for a copy of that. Also, the slides and audio, email us, ask for that, and we'll give you the checklist. And then this recording, this is the first time we've run this one. Once we top and tail it, we'll also distribute the link to that to those that ask for that. So pretty much grab the email address, ask us for all that different stuff, send us your stuff, and then we can do the review. Everyone knows where to find me. I'm not really having a break across Christmas period. So that's all the content I've got to go through formally. I'm happy now to stay on the line. There are people that need to go. Thank you for joining us. Encourage you to reach out if you need some help about anything. Happy also if anyone has a burning question or comment, don't even wait for the chat, you can just unmute yourself and we can have a chat. So for those that have to go, thank you. Those who want to stay, then feel free to ask a question.

Thanks Sean. Appreciate that. Daisy, thank you. Thank you for that comment. Kurt, thank you. Adam, thank you. Chile, thanks mate. Ben, yes, you're welcome. Eletta, thank you for getting out really, really early. Go back to sleep. Grant, not a problem. Grant, will you ask me about what to do if there's not many people? I think thank you. Yes, you're welcome. Michelle. Grant, I remember you were talking about with lower numbers. Do you want to have a chat about that, mate? Well, if you got to go, you got to go. Yeah. All right. You want to unmute yourself and then we can hone in on what your specific challenges there. Evening. Unmute. Think the system still showing that. Can you hear me now? Christian? Yes, gotcha. How are you, mate? I'm good, thank you. Good, good. Yeah, so look, couple of things. I was about to start a role with SeqWater doing their CRM. That might be something that you might want to look into because I pulled out of that role and I don't think they've got anyone. And it's something that they've got a six-month delivery deadline. So you might just want to reach out to them and see if there's an opportunity for yourself there. Interesting. Yes. But yeah, look, I'm going to an engineering company which does geotechnical drilling. So, you know, only a few rigs out there, sort of thing. Very hard to assign, I suppose, a risk owner. You know, yeah, that sort of stuff. So in that context, you know, look, I suppose the program delivery manager would be the risk owner, I suppose. Potentially, if they've got supervisors out there, I'm not sure that they do. But that would be, I mean, who'd be in charge of controlling that risk would be that person. And yeah. Gotcha. So just wondering, you know, I know that when I talked to SeqWater, they didn't want to have risk owners for some reason. They didn't, they wanted something slightly different to the framework that we spoke about just now. I will flick you, I did a quick, in preparation for potentially doing that job, I did a quick project plan for it. A plan on a page. I can flick that to you. Things that I thought about. And that the stuff from today's webinar that I would be probably adding in there now and updating. But I'll flick that through to you at the moment. Yeah, no dramas. Okay, so you've got, you've got essentially satellite rigs which turn on, turn off, and move around the different places. Yes. Yes. And was it surface you might? Is it surface only? Yes, so it's geotechnical drilling for construction type activities. Yep. Yep. And roughly, roughly how many rigs are we talking about? I think currently they've only got five rigs, so there's not many. Yep. So it's a small business, but, you know, they're going through a big growth and buying people, etc., other drilling companies to help with their business growth. Gotcha. So let's say five, five rigs. Each rig essentially is the same activity, so the same risk. Yeah, pretty much. They will be here. Yep. And then, and then you've got a drill rig supervisor. I'm not sure yet. I haven't, I don't start till the 15th. Gotcha, gotcha. Yeah. Yep, that's fine. So it could be, or a leading hand, whoever, whoever the person is in charge on the job on the day. Yes. Type of thing. You would then have, I guess, a, to use the word, corporate function that's, yep, central program manager, sort of thing. Yes. Program. Okay, so program manager, which is similar like a mine manager. So they manage the program, who goes, what, where, and everything like that. And then you might have safety, HSSE, HR. Yep. Got HS as a B1 right for the business. Gotcha. Okay. Yep. So, so in that regard, there might be, I don't know, 10 critical risks. Yeah. Rough, rough guess. And the question is, for those 10, how do we, who owns them? Or what could be an ownership structure that enables the business? Cuz and also going to be critical Charles as well. I got at least two, an well, no, two things come to mind. One, the Chief, what's his title? People risk for Mitchell Services, Josh, is a really good friend of mine. He will be more than happy to chat how they've done it. So they've solved this one. Yep. So if you flick me a note saying, hey, here's my contact details, then I'll get in contact with Josh. I'll link you guys together. So I know one of the things he did to talk about solution first is they took, once they identified their critical controls, they identified the verification activities and said to themselves, well, hang on, if we have a drill rig supervisor who checks the whole drill rig and pad every day, let's take a lot of these verification things and move that over into the standard drill rig inspection thing. Yeah. So that was one of the ways they solved the load, the work associated verification was just piggyback off stuff that's already happening. Yep. I believe also they've, this is my belief, but don't take this 100%, that they have spread the pool of verification. So any role on the rig can take the checklist and go out and do verification stuff because it's all about sharing risk knowledge, learnings, and all that sort of stuff. Yep. That's at the end of the scale in terms of risk ownership. I'm going to guess that they kept it at the core. They didn't distract the drill rigs with risk ownership. What they focused on for the drill rigs is what are the RIS, what are critical controls, and are they in place or not? Yes. So kept it simple. Yeah. Hopefully that helps. No, I think yeah, that's what I was thinking. You know, just focus on, yeah, making sure that they understand the critical risks and, and doing, yeah, verification like pre-start verification activities. Yeah. And he combining it into that pre-start type site inspection that you would do. Yeah. So they, they really, which I really like, they've taken a really strong control focused. Yeah. The words of critical controls or whatever they've called them is really strong flavor. They stripped out trif from anywhere associated the workforce. It's all about, you know, proactive things they can measure and learn from. So I'll connect to you guys up as soon as you send me an email, mate. And he'll, he's very generous of his time, so be more than happy to help. Yeah, no, I'm the same. Look, if there's anything you need, reach out. I've got good contacts everywhere. Awesome. Yeah, well, certainly if that person at SeqWater, because it's a pretty big beast, that thing. I know of some people, but if you know there was someone that even I can just go through the LinkedIn world because if you know the name, then I can send you Jeremy Page's name. Page. Okay. Yeah. I'll flick that in an email. I'll just send it to the admin email. Yep. Send it to the admin, mate. And we'll take from there. Have you, have you used the, it was Bowtie software, was it? Bowtie XP? Yeah, no. Myos? No, it was an engineering company that's got one as well. Oh, okay. That Newcrest used to use all the time. Oh, okay. I've probably heard of it, to be frank. What, what we use in the work that we do, we just use an Excel spreadsheet. Yep. Yep. We keep it pretty simple. And that keeps us versatile. So sometimes we'll say, hey, this is what we use, and the client said, oh, no, can use Bowtie XP? Cool, happy to do that. Sometimes clients are like, oh, we've got this system, but it doesn't work. It's like, all right, well, let's just use the spreadsheet and let's just pull it together that way. Yeah. GHD, the company that, so there, yeah, that, there's some software that they have, yeah, that we've used when I was working for a mining company doing some stuff with Newcrest, etc. Gotcha. You, I've heard of those guys. Yeah. Yeah. All right. Let me flick you this stuff and I'll flick you Jeremy's details and hope to hear from you soon. Yeah, too easy. Thank you. Thanks for joining and have a good Christmas break. Hey, you too. Just say a couple more arms for your daughter, will you? That's right. I was gonna write it in there. My. Can you just say this line please? Six arms. She's on Twitter too. Good honor. All the best. Good on you. Thanks Grant. Bye bye.