📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

Critical Risk Management CCM A Practical Guide I Webinar | Investigations Differently

myosh53:57

Transcription

Good morning everyone. Well, good afternoon if you're in New Zealand. Um, welcome to today's webinar. My name's Sarah, I'm from Mayosh. Today's webinar is on critical risk management. It's a practical guide and it's going to be presented by Mark Alston, who has joined us before. Today's webinar, it's a very popular topic. Um, as with all our webinars, um, you can earn five CPD points by the Australian Institute of Health and Safety. The webinar will be recorded and shared later by a podcast, video, email. Later in the day, I will put some links during the webinar up to some of Mark's previous webinars that have been very well attended, so you can, um, have a look at what he's done before with us. And we'll have a Q&A session. You can ask those questions in the Q&A channel on your webinar software, and we'll get to them at the end.

Um, so today, um, most of you probably heard about Mark Olson. He's done a couple of webinars with us, um, utilizing his operational background. Mark's clients to develop programs unique to them that drive leadership and cultural change. His focus on these solutions combines a "safety differently" approach with the principles of human and organizational performance, working with frontline leadership to support employees at all levels. So, thank you so much for joining us, Mark. Over to you.

No worries. Um, welcome everyone. Thanks for joining me. I appreciate you taking your time out of today. Um, something, it's a topic that's been coming up a fair bit recently with a number of organizations that I work with, and they're just starting to get into this critical risk management. Now, it's nothing new. Critical risk management has been around. Jesus, it was, um, when I first was exposed was back with Rio Tinto, um, back in around 2010 maybe, um, when we were starting to really, really, really start looking for the first time. So, um, it's it's not new, but it is new for a lot of organizations, and it can seem quite daunting. So today is just a real quick, uh, snapshot of some practical steps that you can sort of, um, project plan with and move forward with. So I welcome any questions, um, and any any comments, and, um, just throw them up there in the Q&A, and, um, Sarah will look after that for us. So, welcome, and thanks, thanks for joining us.

So let's get into it. What is critical risk management? So it's, it's managing the risks of those material unwanted events. In other words, basically, critical risks. Now, we'll have a bit of a health and safety focus on this one today because, you know, we're mainly dealing with health and safety here, but it doesn't matter what the risk is. And they typically sit to the right of your risk matrix. Those, you know, it's either a fatality, multiple fatalities, or even, you know, total permanent disability. I've seen a lot of, a lot of clients, um, take that approach. But it's making sure that we have a systematic approach to many controls that they're in place and will be effective 100% of the time. Because at the end of the day, this is the stuff right at the front line, and it's that stops people getting killed or, you know, total disability. That's what we're looking for. So that this is the stuff that matters.

Um, now, in terms of building, building that business case, um, to put to do this in your organization, the question could be, why? Well, let's just have a look at some of the stats. You know, in 2020, 178 fatalities in workplace fatalities. 2019, 183. You know, 2018, 146. 17, 189. 186 fatalities in 2016. In the last 10 years, I think it's based to 2019. In the 10 years up to 2019, 2,718 workplace fatalities have occurred. It's 2,700 people, 18 people not going home that were just doing their job or were at work. Workplace related fatalities. So some of those were were bystanders. Top, top three, top four, 12, four from height. There's a lot of businesses at work that have worker types as a risk. 11, dropped objects. 12, hit by a moving object. And by far the largest of all for workplace fatalities, and no surprise, D1s is vehicle collision. So 37, over a third of workplace fatalities were to do with basically driving. Now, I've yet to work with any organization where driving isn't a risk, um, and will continue to be a risk until unless we can eliminate either cars or people, and or trucks and people. I think we're a long way from that.

So again, why do we need to separate these critical risks apart from obviously, you know, this is, this is, you know, the ultimate price that we people might pay. The other thing is, how much time do we have? You know, I, I've yet to work with anyone, any organization. So, you know, I do a lot of workshops and and facilitate a lot of, um, learning teams and things like that. And one of the questions I always ask is, does anyone walk up to you and say, "I'm going to give you less work to do and more time to do with him?" It just never happens, right? So risk assessments, um, you know, we're meant to assess risk on all the things that could be a hazard, right? That's the, that's been the standard. And we've all been in those. I mean, I can remember sitting in risk registers where we're looking at, you know, I don't know, people, um, replacing toner in in the in the photocopier at work, or, you know, making a cup of coffee and things like that, and sitting, you know, exhaustively in in developing risk registers for those. But we just don't have the time. So if you were to think in your own organization, how many risks do you have? How many risks, how many tasks do you have? How many risks would each of those tasks have? And then of those risks, of those tasks, how many controls there would be? Do you physically have the time to actually ensure they're 100% effective? Every single control? And the answer is no, you don't. We don't have the time. We've got limited access to people these days. You know, everyone's, we're just doing so much more with less. You know, we can even see now, and it's not going to get easier. There's a labor shortage happening in Australia right now, reportedly, you know, a labor shortage right around Australia right now. We cannot get people. So we're going to have less time to do these things. We'll have less access to our workforce to help us out. And, you know, one thing we can't do is put more time in the day, right? So we have to prioritize. And where should you prioritize your time? So, you know, when you're looking at building a business case, I'm going to talk about that in a minute. It's all about time, right? It's time management. Where do we want to focus our time? So this is, this is the why. It's the stuff that could kill our people. And if we've got, if we've got an unlimited number of hours in the day, well, we should focus on the most critical things.

So let's have a look at this, what I call a little roadmap here, um, and look, there's, you know, there's a number of different models around, but this is, I just think this is just easy to follow, right? The first thing we want to do is establish our framework. I'm just going to go through each of these. Establish our framework. That's, you know, processes, procedures, you know, get management commitment. Make sure, you know, committed to go for it. We've got to prepare for the workshops. I'm going to talk about that. Identify our critical risks, right? What are they? You know, and we'll talk about that. Cause and controls, you know, the hazards and controls. Whatever. I tend not to use too much risk language when I'm talking this stuff. I just talk, you know, like a human, not a risk person. You know, pick those critical controls. What are the most critical of those controls? Because it could be, you know, 60, 70 controls for one risk. But really, if we all break it down, all the controls, we get a lot of controls. But what are the most critical? We'll talk about. And we'll provide a definition. I know there's a number out there. And then we'll start to talk about where the rubber hits the road, and that control design, making sure it's robust, making sure it's resilient, making sure we've got those things in place. And then lastly, we'll talk about, you know, how we're going to verify that the controls are in place and effective. And, you know, so they'll work, right? So that's what we're after. So that's what we're going to run through for the rest of the short presentation this morning.

So let's start with one, establishing that framework. And the first thing we need to do is get management commitment, right? You need to build the business case, right? And by that, you need to demonstrate the need to the business that this work has to be done. The reason you need it, unless you have this, from my experience, unless you have it driven by the top down, you're playing at the edges, right? You will not get what you need, right? Risk assessments cost money, right? Now, it might be physical dollars, like you might be, you know, unless you're you're paying for for external facilitators or external consultants, right? But you can do this in the house, and most, a lot of companies do. Um, but they'll be lost production because you're going to need people who do the work. You're going to have to pull them out of production, right? You're going to need facilities, you're going to need time, you're going to need the time of the for the facilitator, you know, you're going to need someone to put this together. So this all takes money, right? Communications plans, all those sort of things cost money. You know, you might need some graphic design work, you might need some communication materials, you might need some training. So this is should be budgeted for, right? I've yet to see any, I shouldn't say any, but most organizations don't budget for two things when they're developing their health and safety strategy and working out what they, where they're going to put resources. They don't budget for incidents, for investigating incidents, and they don't budget for risk assessments and managing risk. How many risk assessments are going to need to do? How many people it's going to take? Prepare the business case. So two things, first, you need to do, demonstrate the need to managers, get their commitment, senior leadership. It has to come from the top down because if you don't have their commitment to release their people and pay what it costs to get this in place, you're not going to, it's not going to happen, right? You cannot ninja this. This needs to come in as a proper project and build the business case, sell it, and then undertake change management with it. Look for those risks in your business. I work with some organizations where this is quite simple because it's just one site. You know, you know, might have, you know, anywhere between 400 to 1,000 workers at one site. That's great. We can manage that in one site. But then I also work with clients with a diverse range of sites all over Australia, and some of those might have three or four or five people at it, right? How are we going to manage implementing critical risk management at those sites as opposed to the larger sites? Look for those risks of implementation. That's what I mean by change management. The risks of implementation. Do your change management and put the business case forward. So that's the first thing we need to do.

Then, once we've got that, it's pretty simple. Let's get the horse in front of the cart. Let's establish our framework, right? Let's get, make sure we know what our overarching process is going to be. And I'm going to walk through a process for the rest of today. You know, have the procedure, have the procedure ready to go, right? Make sure we define clear accountabilities and put those accountabilities into management's or whoever's role descriptions. And by accountabilities and role descriptions, I'm talking about terms like who's going to own the risk, critical control owners. If you're going to apply critical control ownership, can you do that? Are you, is your organization big enough to have these sort of roles? These are the decisions you need to make, right? But make sure it's clearly defined who has them. And then make sure that we train those people before we start what their roles are going to be. Don't make it up as you go along. If we're going to be a health and safety professional, if we're going to be a professional in our role, we treat this as a project. Let's plan, plan, do, check, act, right? Let's make sure we run through it. So part of this is having all this up, ready to go at the front end. Now, my version of this is the less is best, right? Less clutter. Use what you've already got where you can, um, and, you know, make it as slim line as you can, right? Don't add a heap of stuff into it that you don't need to. But make sure we're prepared. Make sure you're prepared for those answers you might need. And a communications plan is a great thing to do. You know, again, with a communications plan, pick your targets. Who you're gonna have to communicate to? Your senior leadership, you know, line, line management, so supervisors, not the workforce itself. You don't have to demonstrate the need to them, but they're going to have to see how this is important, how this will add value, and how it won't add work, right? And this is what we want to do. What training do we need? Have these things ready to go at the start. A little bit of time, a little bit of preparation here will really help, uh, down the track. What tools we're going to use? So when you're doing your risk assessment, so you're going to use like bird, bow ties, or simple cause control analysis. What are you, what tools will you use? Simple RAC tools are work well as well, you know, pick your facilitators. Make sure we have all this, this, this stuff ready to go, and then we pull the trigger, right?

So we move on to our next step. We prepare for the workshops. We do our research. And I'm going to go into the research a little bit more in the next slide. Select the team. So who's going to be involved in each of these workshops? So when we do critical risk workshops, we do our first workshop, and this is, this is my advice has practically worked for us. Is we do a workshop where, first workshops or series of workshops, we identify what our critical risks are. Then we basically do a separate risk assessment on each single subsequent, on each of the risks. So we might need a broad team for our first one, and then very focused teams the rest. And it might be more than one. We might need to do more than one to get everything we need. But we, but we need to select the team, all right? And the team's got to consist of people who do the work, right? People who currently do the work. It can't just be full of middle management and supervisors. It's got to be, if we're talking about critical risks that involve the people on the tools, it's the people on the tools that need to be in the room, right? Make sure the room's big enough, right? Make sure you've got the right facilities, whiteboards, flip charts, whatever you need. My advice, you know, and I teach this in our risk assessment mastery class, is do not use Excel spreadsheets up on a wall. The only time I use a projector when I'm doing any risk assessment workshop is maybe to help give context in terms of, you know, putting up videos of the work or photos of the work or the area, or or giving some of those sort of information. Then I turn it off, right? It's all about the conversations. That's where the information lies. Allow yourself enough time, right? Allowing yourself enough time. If you're going to do something like, allow yourself an afternoon. Don't try and do one of these workshops in half an hour, an hour, or two hours. You're going to be rushed. Now, if it takes two hours, awesome, right? You've done a great job, right? But allow yourself more time. And this gets back to building the business case, getting the management commitment so that people will be there, right? We've all sat in really poor risk assessments where there's no innovation, clearly any discussion, and then all of a sudden, we rush through. You get a heap of group think. Yes, yes, yes. Copy paste, copy paste. If this is what this turns into, you've wasted your time, right? So prepare, allow yourself enough time, get the right team, make sure the room's good, make sure you've got it, look for long enough, you know, so again, it's part of that plan, project planning, right?

I mentioned research. Research is vital here, right? So especially for that first workshop, and even the subsequent ones, it'll really come in handy. So do your internal research, right? Make sure you know, troll your databases, troll your spreadsheets, whatever you have, you know, look at other risk assessments, find the hazards with the critical potential, right? With a critical potential consequence. Get your high potential incidents, have a look at them. Get your risk register out, have a look at your tasks. What are all the tasks you do, right? Have that information handy. That's part of your job if you're going to help facilitate these workshops, especially that first one, right? Have a really good look at that. The second one is go external, right? Go external. One of the, one of the issues that got up brought up with Dreamworld with the regulator was that they didn't acknowledge the risks that the rest of the world was having with the similar or the same, right? Okay. And they didn't put that together, um, because they hadn't had, they had an experience in in Australia with their, right? But, you know, some of the, some of the commentary was about the fact that this, there were similar events that had happened over, over, um, in the states in Europe. So let's do our research, right? So I started today with, um, fatalities, fatality statistics. Now, Safe Work Australia has some great information there, right? And industry-specific associations are fantastic, including the state regulators, right? So each of the states puts out. So one of the things I do is I go through all the state alerts, safety alerts for the last, you know, five, ten years, pull them out. What, you know, all the high potentials, all the fatality stuff, how was it caused? What was the mechanism, right? These are all credible risks because either someone nearly, someone did, there was a fatality, or someone nearly died, right? So this information is never been more readily available for us. This helps drive what we call credible scenarios, right? Grab as much of that stuff as you can. As I said, the state regulators, both for like work safe type ones, and if you're in mining, the mining regulators, transport, they all have a lot of stuff that you can look at. So really encourage you to get as much data as you can. The bigger the net, the more credible you'll be with your scenarios.

So we've, we've put our business case, we've got our permission, right? We've, we've done our preparation, including our research, and we're rocking up for our first workshop, and this is the, this sets the tone for the rest, right? We identify our critical risks. Now, one of my preferred methods is just to brainstorm, right? Because we'll clear it up when we actually go into these individual risks themselves, if we've got some double up or if it's actually not credible. I've actually, we've thought we've had a critical risk in the first session, then when we actually did the workshop, we actually couldn't find a credible scenario for how we do the work where we're working. So brainstorming session, right? Again, if you've got an organization, trying as much breadth of experience, actually are people doing the work. Now, I'm not saying exclude management, right? But the people who do the work should be the majority of the people in the room, right? And look, the good thing about this is it doubles up. It's consultation, right? So it doubles up in their requirement there, and it's the right bloody thing to do because they have the knowledge, right? Use the research we've already got. It sets that scope, right? We may need more than one workshop, right? May need more than one, and that's cool, right? We might need a couple, depends on how big we are. But at the end of the day, once we've got, we've got all these risks, we can start to see some clear themes. Yeah, and I guarantee you, you know, if you're in, depending upon your industry, you'll have the common ones that will, these are generally known risks, right? Because they're so familiar to us because of the amount of fatalities either within our own industry, within our own organization, within our own country, or even even overseas. These are pretty known risks, you know, driving on, you know, driving or driving on public roads, like, you know, vehicles and pedestrians, working at heights, confined spaces, um, electrical, stored energy, right? Entanglement. These are pretty, ex, you know, broad risks that just about everyone has. Now, when I've done this with most organizations, we end up, and then, well, so in particularly, you know, we've ended up with something like, you know, above 15, 15 to 20. That's cool because it is what it is. Do not get sucked in that you, you've got too many, right? You can group some, and because we'll use those as a communication tool, but be very careful because they have to have the same controls, right? So similar risks for the same controls, that's what we're after at the end of the day. When we start to think, right, identify those credible risks, you know, what are we exposed to that could cause that workplace fatality? What is a critical risk?

So, um, so I put up a risk matrix, and anyone that knows me will know these are not my favorite things, right? Which is why I'm sort of having a laugh. Um, not my favorite things. However, they help prioritize, right? But to me, it's in the risk scenario. So I don't really need this, but for most organizations, your critical risks are going to be in this column five. It doesn't matter what the likelihood is. It doesn't matter if it's rare or almost certain. And I'm not talking about, um, inherent risk. I'm talking about your current residual risk, right? What's your current risk? Right? Any likelihood, because we don't live in a world with no controls, right? Any likelihood, what is your credible risk that which will have a critical outcome? So again, up to your organization. So I'm not going to tell you the right, you know, what's the best way to do this. Me personally, it's total permanent disability slash fatality. So anything that falls into those. So it actually might be, you know, major critical, it depends what, how you define critical risk, but that's what we're talking about. I'm not talking about an LTI, right? A lot of organizations just stick with fatality, right? Now, again, that's a health and safety thing. If it's, if you're looking at enterprise risk, it could be that if you suffered this, it would shut your organization down or severely damage your ability to operate, right? So we could look at, it could be a severe hit to your reputation, right? So it's anything you want to have that critical focus on, that's where we're looking for critical risk.

Now, you'll notice I keep talking about credible. Now, credible, what do we mean by credible? It's got to be believed or trusted, right? It's got to be plausible, right? It's able to be likely to be true, right? It's got to be reasonable, right? And we can only discover that when we're looking at the context of our work. And I'll talk about that when we look at the first, at the first actual risk assessment, um, where we're looking at the, the causes and controls. It must be in here, right? Don't go down the path of too many what-ifs. If we don't do a job this way, if no one could be exposed to it, you know, because we just, they're not there, that it would be like unbelievably unlikely that someone would be there, then it's not a critical risk, right? Be credible. Trust the people who do the work, and also trust the research you've done, because the research will tell you whether it's a risk or not as well, whether you could be exposed, right? So they could tell you, yeah, these, we're supposed to, and the people in the room will tell you whether it's credible that actually, yeah, that could happen to us, right? That could happen to us. Don't go down too many what-ifs. If you start stacking up, it's unlikely to be true, it's unlikely to be credible. We don't have enough time to focus on risks that aren't credible. It's one of my bugbears with investigations where we overclassify and we spend too much time investigating things which aren't credible high potential events. And I know there'd be a lot in not in your head, right? Then with that one, right? So let's get our credible risks right.

So we've identified a suite of credible risks, could be, you know, 10, 15, 20, whatever it is, right? Our next step is to pull each of those apart, right? So we do that series of workshops for each risk. So what we're looking to do firstly is discover the context of work. And I'll talk about that in a second. Identify credible causes, right? What could cause someone to fall from height? Well, might be that there's no edge protection, no, um, edge protection. Might be that their equipment, their working heights equipment was faulty, right? Um, there might be a whole range of things, right? A couple of tips, right? We don't need to assess the risk. We've already done it. We did it in the first workshop when we identified that it was credible that it was critical. So we don't need to go through that whole process, right? The other thing is, is we want real depth, right? We want to dig deep, right? And the last thing I want to say is, don't let whatever bloody tool you decide to use, and sorry, I shouldn't say that, any tool you decide to do, I don't care if it's bow tie, I don't care what my preference is, like just cause simple like cause and controls, I don't care what you use, I don't care how you develop it, don't let that process where you type it all up drive your conversation in the risk assessment workshop, right? I simply use a brainstorming session again, and I use whiteboards. So I'm sure you can probably see that. I think this one I did for a client with confined spaces, and I used whiteboards. What could cause it? What a credible, right? And we just brainstorm, right? And we're looking around, what's credible, right? We give everyone a voice, and we just, I use, I use, uh, these whiteboards or flip charts. I just simply take photos and then later on, I plug it into that template that we've built, right? We're looking for this. This is really good. Again, make sure, so if we're dealing with something like electrical, you want electricians in the room, and that are currently doing the work, right? And some of you, that might mean involving your contractors. Well, that's what you do. You involve your contractors. They've got a great depth of knowledge. So grab them, right? And you'll notice I keep talking about context. So context is the first thing I do with any, any of my risk assessments, and I'm looking for this. So this comes from Todd Conklin. And the context is all that information that surrounds how the work gets done, right? It's the circumstances, right? It's the big picture, right? If we look it down and we look at say, um, a shutdown for a factory, right? Where everyone's, you know, they're doing major maintenance overhaul. The amount of people that are involved in their individual tasks, yep, that's one thing, but it's the overall picture. We want everything from the supply chain, the logistics, to the review at the end of it. That's the context of work. We want everything involved.

So let's look at work, right? I'm just going to, for some of you that know me, you'll, you'll have seen my previous presentations, you'll see, you've seen me talk about this before. Work. So we call it this, the blue line. This is how work gets done over time. Now, normally we have a black line, right? So that black line is our procedure, is going to be straight across, um, written in ink, you know, swims, Swiss SAPs, whatever you want to call them, how we do the work. Work's never done that way. It's messy, right? Because of all these things that occur, right? And it's only when we drift to hazard or just to risk that we worry about it. But these are the things that could, that it drives our context, right? So the first thing I do with my workshop with people talking about tasks, and so it might be, um, excavation, right? That might be the risk we're exploring. You know, people getting engulfed in excavation. Well, tell me about excavation. When does it work? Well, when doesn't it work? Well, when, what sort of constraints do you have? Do you ever, you know, what happens if the machine breaks down, right? Do you always have all the people? What have, what, when's it go, when's things not work? I wanna, I don't wanna, I don't care about how the procedure says it all. I care about is how it's done in the field, because this is where I'm going to discover some uncertainty. This is when I'm going to discover some unknowns. This is the context, right? So have a look for the context of the work. Make sure this is the first thing you do when you're doing your risk assessments with people, apart from, you know, letting them know what they're, uh, letting them know what they're there for. But have these conversations. This is why I say again, invest the time. Do not rush them, because this takes time, right? You know, system weaknesses, right? When's, when's, you know, how's weather affected? What happens then, you know, um, what's, what's production pressure like, you know, what happens if we're not getting it done in time? You know, this is the uncertainty, and these are the things that drive our risks, right? So spend the time. So when I talk about context, make sure we capture that first. And from this, we'll start to get credible causes for our scenario. Um, I'll hit my last sentence, um, so, and it only comes from the people who do the work, right? So have the right people in the room. I cannot stress this enough.

So we get that. I'm going to just go back a bit, sorry. It's the first time I've, I've just put this together for this webinar. This, this pack. We get out, we get all our causes. And you can see on that, on the, in the left-hand whiteboard there, um, you know, I'm getting all our causes. What could, what could it cause, right? A confined space incident for this, for this area, right? Then we, then basically, all I do is go, okay, what controls do we have in place, right? That's what I go to next. What are our controls? But I want to be specific, right? This is for, and we again, we go through this in our master class. Not just PPE, right? Because at the end of the day, what we're going to end up with is a very detailed risk assessment with a lot of detail on our controls, because this is the information, right? We should be putting into our procedures, our purchasing, um, you know, database, our maintenance programs, our SWIS, our inductions. This is where it should come from too. Often it comes the other way around. We grab it from a piece of, grab it from an, um, a procedure, and we put in a risk assessment. No, wrong way to go around things. That's, we've done this for years. We've got the, the dog wagon, the tail, and this, that's, sorry, the tail wagging the dog in that area. This is where we should be getting it from. And it's really going to become specific, become important when we look at critical controls. So again, don't just put PPE, right? Be specific. Don't just put maintenance. What are you talking about maintenance of what? What frequency? So I'll give an example there of a mining car. So a vehicle used in underground mining, probably has, you know, checked the brakes every 10,000 kilometers. Well, that doesn't account for an underground vehicle in mining which does its whole life, um, in a high salt environment, stuck in third, in third gear, low range. I'm pretty sure we're going to want to check those brakes more often than every 10,000 kilometers, right? So how often, right? Let's be specific. This is where the detail is. And it doesn't matter if it's a critical control risk assessment or any risk assessment, my advice is all the same.

One of the things I do to assist with that is I prime the risk assessment team. So, uh, you can all read that, that that there is, um, and take a snippet of that or a photo of that. I know, um, Sarah's recording this and will be available to watch later. But this is a specific disclaimer that I put on all of my risk assessments because I'm sick of going through and asking for controls and I'll get, "Take five, supervision, induction, training," ad nauseam. It drives me nuts, right? So to stop that happening, I put a disclaimer as to say. So there's two things. Firstly, I'm not interested in generic controls that are site-wide for a number of risks, right? So if you use a pre-task risk assessment, like a take five, it would be for all your tasks, right? So it's not to the specific risk we're talking about, um, regardless of the whether or not they're not by work, it's just generic site-wide, right? We're not interested in that, and it certainly won't be a critical control. The other thing I do is we acknowledge some human factor causes. And by human factor causes, and rewrite that however you want, feel free to use it. I'm talking about things like fatigue, I'm talking, you know, fitness for work, um, error, human error, right? I'm not interested in, so, or human error, maybe if it's caused by some of our system issues. But those things like fatigue, fitness for work, you know, lack of training, those again are site-wide risks for just about every task we do, right? We should look at those just separately, and we would have separate controls. You all have drug and alcohol programs, you'll have fitness for work controls in place. Let's not cloud this specific risk with that extra stuff, right? Because otherwise, it just blows it out and it doesn't add value. Like, look at them separately. So I've used this quite successfully, and it primes the team because they can't sit there anymore and just rattle off the same controls they're used to rattling off in the hundred risk assessments they've done in the past, if they have, right? So this is why I do that. So we want to be specific. So we get all our controls. We're not at this stage, we're just looking at all controls for this, for this, you know, confined space, right? It could be, um, you know, gas monitoring, it could be, you know, isolation, and all that sort of thing, whatever, whatever we've got, right? Then when I do this, I actually make a point of going through all the controls and saying, right, can we eliminate this hazard for this? Can we eliminate this cause? Well, what could we do? Or could we limit the hazard, the cause, the, the human interaction? What could we do here? Force this on dimension. And then again, this is what I do for all risk assessments, actually use it as a process and go through the hierarchy of controls, right? And immediately, we've almost cancelled level three, right? So this comes from the code of practice. We've almost cancelled level three controls, that admin, PPE stuff, right? Because we're focused on a higher level already, because we've already said we're not interested in the lower stuff, right? Let's force it, right? And one of the tests I put to the team, once they've gone here, we've got it, we've got everything we need, I say, "Okay, if we take all the admin controls out, what's left? Is this enough?" Right? Is this enough? And that's, and that's what we want to have, right? Push, push, push, demand innovation. I push this to the to the level of discomfort, right? Um, some things I've done in in past workshops to really push things is I've had mechanical engineers, and I've primed them beforehand, and I've said, "Your job is to look for a mechanical engineering solution every single time. That's your job. I don't, for all that, I don't care about the other controls from you. All I want from you is, is there a mechanical engineering solution here?" And if you've got that internal capacity, that's fantastic. Why don't you use them, right? Why don't you use them? Yeah, there might not be an affordable mechanical engineering control, but at least we've had a look, right? We're actually having a dig and not just repeating what we've done in the past. But they're not all created equal, right? So if we look at all those controls, and say we have, say, let's say over 20 risks, and each one has say 10 controls, there's 200 controls there. Now, can we every day check that those controls are effective and working? Gonna be bloody hard, right? So we look for our critical controls and we select them.

So this is the definition that I like, um, for for a critical control. And sorry, I can't remember where I got it from. I wish I wish I could remember. But this is it: "Specific act, object, or technological system which of itself will prevent or mitigate an incident, but they're specifiable, they're measurable, they're auditable, right? And if we didn't have them, they significantly increased the potential for an unwanted event to occur." Right? I like that. I think it's quite good. I know there are other, there's decision trees and other things out there. Whatever works for you, right? Whatever works for you. I know the ICCM one, I'm not a big fan of theirs, although their other stuff I am, because it says it's got to apply over multiple events. I'm not interested in that. If it applies for one risk, I'm happy with that, right? The big thing is, right, critical controls are decided by the risk assessment team. I better hurry up. What's not a critical control? A procedure. Any procedure. Training. License and permits. They are not a critical control. They're an administrative process. The critical control can be described in those, but it's the specific act, object, or mechanism, right? So working at heights, it might be the physical act that they clock, they they they're restrained, they've applied for restraint. That's the critical control. It's not the procedure that tells them to do it. It's not the training that tells them to do it. It's not the permit license. It's what it is, right? So failing safely. Do our controls allow us to fail safely? There's a, there's a safety chain on the on the end of that. I put that on every single time, every single time. Even though I've never had a trailer come off my trailer come off, and I've towed for 30 years, I put it on because I know it could. Right? If the hitch fails, if the tow ball fails, I've got some control and hopefully it'll mitigate the damage. So one of the questions, do our controls allow us to safely fail? If something goes wrong, will it fail? Well, it's, will you be safe, right? That's what we're after.

So critical control design. This is where the rubber meets the road, right? It's objective, target performance, performance requirements, supporting management systems, monitoring, fitness. This is the detail. We only do it for critical controls. Now, most critical risks that I've been involved with have two to five critical controls maximum. Any more than that, I'd say you're pushing the friendship, right? You're probably going too broad with your definition, right? Critical control design. So this is, this is a really useful guide, right? The mining has been streets ahead of pretty much most other industries in critical control design. And the ICMM, the International Council of Mining and Minerals, introduced a couple of guides. One's a good practice guide, one's an implementation guide, right? And both of those have a design form for critical control designs. So you can just go to the ICMM website, you can download them for free, um, and I, I suggest you have a look at it. I think they're really cool things and and they're probably, um, they're probably, they're pretty straightforward and easy, easy to look at, right? Worth having a look at. So if we have a look at that, you can just put it into an Excel function, you can put it into, like, this is Marsh has these things in there in their critical risk management suite. And it has goes through our critical control design. So we don't have a lot of time left, so I'm going to go through this reasonably quickly. So we talk about the critical control performance requirements, right? This is where the detail is. This is what we, we need to be detailed in here. What is this? What is the objective of the critical control? What's it meant to do? What's it based on, right? We're putting what in standards, international standards, Australian standards, right? What's the objective? We've got to be very specific and detailed in here. What are the management systems we have to support it? If we don't have a management system to support it, then we need to have that, make sure that's in place, right? The procedure says, like, so this is one for wearing a life jacket. If it does, if we don't have a procedure that tells us where life jackets or when to buy the life jackets or when to inspect them, replace them, that should be in our procedures, right? We should have that system in place. And lastly, talks about there on that third column about what activities can we sample from to make sure it's in place, right? Is it effective? And in place and working? Will it, will it work if called on, right? What's the target performance? Right? Most of the time, it'll be a hundred percent, right? What's the trigger? What happens if it doesn't? What, what could trigger a shutdown, right? Or an investigation. Um, one thing I see, um, doesn't have is control failure prevention. And I really like this. How could the control fail? So in this one, the PFDs could be compromised through exposure to the sunlight, right? How do we do that? We make sure we store them outside of direct sun, right? And they're inspected immediately before use, right? And we've got replacement. Well, if life jacket's ready to go, right? How could the control fail? So I really think that's really cool. Monitoring must be planned, right? So remember that third column, we've got purchase request, inspection records. How are we going to make sure that these are in place, right? Do we do audits? Do we do inspections? Who's doing, how many? Everyone said, develop that framework at the start. This is what I'm talking about. Who's doing the monitoring? Make sure the accountability is there. Make sure we've got the tools, right? And I will give a plug to Miles here, so Marsh, you know, sponsoring today and putting it on. First, thanks. They do have a great critical control management part in their suite now, uh, module, and it allows you to design your critical risks and controls, and they have a suite of things, a suite of tools that you can do to feed back into and monitor your monitor your critical risks, right? It's in place and that's effective, right? And lastly, depending upon the size of your organization, how many critical risks, you might want to think about doing some sort of annual effectiveness test, right? Have the design standards changed, right? Are we still compliant? Have we done our planned tasks like we said we would have? Have there been control failures? Have there been audit findings? Have there been, you know, we've done inspections and observations, right? Are those things in place and have we done, right? Verify the controls are in place and it'll be effective. And if your target performance is 100%, then that's what we've got to check, right? Are they implied? Will they be 100% effective 100% of the time? So this is where, this is where the time takes in, right? This is why, this is why we're doing critical controls because we can't do this for every control, just impossible, right? So we look for our critical controls, those ones that really matter.

Quick quality checklist. Make sure the risks are credible, right? Make sure the right people participate in the risk assessment, right? People that do the work. And I cannot tell you how many risk assessments I've seen, and all I can see in the participants is being a safety advisor and supervisor. No, that's not a risk assessment. That's an administrative tick in the box.

Make sure the controls are specific to the wrists. The critical control designs are detailed. To be quite honest, it will take you just as long to do the design of each of the controls as it did to take the other stuff. It is resource-intensive to get that depth of detail.

And I did have a question before the webinar. They are critical control designs are very detailed, right? You must be specific, right? And those additional controls reduce the level of risk, right? Not administration. And that's what we're after.

So, I think Sarah, that about wraps us up. I think my time is just about done. Um, I've got one question there, I see from Samantha. And that question is, um, for someone new, why don't you like wrist matrices? Um, because we, I've think too many risk assessments, Samantha, where they just focused on, um, you know, the process of plugging where risks which fit in a risk matrix, and there's no empirical evidence that they actually serve any value. If you want to prioritize your risk, a good, a good, a good risk scenario will prioritize anyway, based on consequence, based on outcome, potential outcome.

Um, Chris Harris, is this process best done at project, business, or enterprise? Enterprise. Okay, so it depends, right? Um, yeah, you must take in. So Chris says, in this, is this process best done at project, business unit, or enterprise level? Particularly in diverse organizations, risks may be the same, but control is different. 100%, Chris. You must take into some of that, that local rationality. You might have two different factories or two different sites, and they actually don't have the same, um, equipment, um, and therefore the same controls wouldn't work. So, um, I would start at an enterprise level and then I would look to bring in local rationality. But in a diverse organization, if you can get as many people from those diverse business units, uh, or projects, and that's the way to go. But yeah, if you, you start enterprise, but then if you have to go lower, um, go further into the business.

Um, I guess you're reading these now. Do you want me to read them? Sorry, sorry Sarah. I saw, I saw him pop up. Um, right, so, uh, Rasa, I hope that's how I pronounce it. For the cause and control assessment workshop, other than the worker, I, the people who the jobs, any other member EGH C personnel should be invited in the risk assessment? Definitely. So, I, as I've already mentioned, engineers, and that's really hurts me because my daughter's an engineer, and, um, yep, that hurts. Um, yeah, engineers, engineers are good to have in there. Um, planners perhaps, um, supervisors, maybe a manager because they've got a depth of experience, they've been around a long time, so they're handy to have in there. But any other subject matter expert that you could put in there. Typically, a HSE person will be the person neither facilitating or scribing. And that's another tip too. You can't facilitate and scribe and do both jobs effectively, so don't try. Um, do one or the other. Um, so thanks, Rosa. Great question.

Um, Chris Harris again, also has a rule of thumb. How many critical controls per risk is getting too much to monitor effectively? Look, I would be very doubtful going above five. Rule of thumb, right? It depends how complex the risk is and how complex the work is. And probably goes back to your previous, um, question, Chris, about that local rationality. Um, I think sometimes, um, you know, we've got to be careful. Um, yeah. So, yeah, any more than five, I think, geez, um, you've got a lot of critical controls in there. I'd be very careful. I was muted.

All right, so that might be the end of the questions, but it normally isn't. So I have shared a lot of links in the chat panel, and they're Mark's previous webinars on subjects like investigations differently, incident classification differently, and risk assessments, a quick guide for managers. Um, so please check them out. If you weren't able to see the, Mark, I think there's another question if you want to. Yeah, thanks Gary. Thanks for for tuning in today, mate. Um, so hi Mark, great talk. Thanks. One of the things that I find in risk management is we are good at identifying hazards and controls, but we have a hit and miss approach on reviewing and monitoring controls. It seems your process brings this to a four, uh, and in particular for the critical ones. Yeah, Gary, that's the thing. We must plan it and design it when we design the critical control at very start. Um, and if we can, let's build it into existing tools. If you already have inspections, and you already have observations, you already have these existing processes, then use those. Uh, that's one of the reasons I like the Maya Shockwave because it actually can build in and feedback directly. Um, another shameless plug, but yeah, so plan it. So it's a plan, do, check, act, just like we do with any, any sort of project work where we're running it properly. So I think, thanks, Gary. Um, and thanks, Miss Fox. Yep. Awesome.

All right, okay. So, um, thanks for the shameless plugs, Mark. Um, I can't keep these things all, um, unbiased. No, um, I have, I do have to share a, a webinar next week. The Myosh team, Nigel, people might know him. He explains things really well. He's going to go through smart inspections, um, our new rules engine, and, and how that relates, how that can help with the critical control management process. So, um, probably about half an hour now, next Thursday. Um, and he's going to just show how our inspections are very feature-rich, and they include images, um, in the questions for context, and, um, all sorts of rule-based notifications and actions that can follow based on responses and conditional logics and all those sorts of things. So, um, hopefully people find that interesting, just to see how Myosh are doing it.

One more question, think Mark, if you've got a second. Yeah. Could you, yeah, yeah. Could you please, uh, could you advise what tools we can use for risk assessment from the Vibraham? Um, look, just, and your normal risk assessment tool does the job, right? Um, and then just create your own. I, I really, that ICCM or the ICMM, um, template will give you some good stuff. Um, but yeah, I just basically, you know, use, um, what, yeah, workplace risk system, risk assessment tool, a bow tie works, whatever, whatever works. You just really want to get those causes and controls. Um, but yeah, even, even, even if you just do basically go, these are things that could cause it, and these are our controls, just two columns, like you don't need to overthink it.

Um, and lastly, look, look, I'm on LinkedIn. Mark also LinkedIn. I've got my email address there, my website, investigationsdifferently.com.u, info at investigationsdifferently.com.u, my phone number's there. At any stage, look, read, ring, connect with me, reach out, touch base, just after some advice or anything. I'm, I'm happy to share and help where I can. So, um, yeah, everyone have a good day. Yeah, that was really top, um, information. Thanks, Mark. I've included that link to your website, um, in the final thing of the chat. Of course, those links will come out on the webinar has emailed later today with the podcast and the video recording. So thanks everyone for joining us once again, and hopefully, we'll see you again next week. Thanks everyone. Cheers. Bye.