An overview of Human Performance Management

Screen_Shot_2022-08-31_at_9.32.00_PM.png

Human factors are concerned with optimizing human performance in all tasks and in major hazard workplaces; the primary intention is to achieve safe performance. These high-risk workplaces should have conducted risk assessments and established a range of controls to prevent major accidents. Still, they should also focus on human performance issues to eliminate or reduce human failures.

An organization’s safety management system (SMS) can be considered the organization’s integrated set of processes that support human performance. The SMS implements policies, organizes resources, and measures performance. Safety culture affects the way management and the workforce approach safety and has a direct influence on the success of the SMS.

A good starting point for developing an understanding of human factors, safety management, and safety culture issues is the Energy Institute’s Human Factors briefing notes and the UK’s HSE Managing Human Performance briefing notes. 

There is a clear link between:

  1. Human Factors,
  2. Safety Management Systems, and
  3. Safety Culture

All are concerned with optimizing human performance. For example, a key influence on task performance is personnel competence. The SMS should include all selection, training, assessment, and development processes necessary to ensure competence. The organization’s safety culture directly influences the effective functioning of the SMS in that if management regards training as simply a means for meeting legal requirements for competence, then the system would not work as well as if there were a more positive attitude to staff development.

To make sense of the information gathered in an incident investigation and, in particular, to develop appropriate recommendations for improvement, at least the basics of human error should be understood. This article provides an outline only of the principles involved. If more in-depth analysis of these issues is required, further information should be read or a human factors specialist consulted. The basics are:

  • there are different recognizable types of human error, and
  • numerous factors affect human error

These basic facts are important in making improvements. For example, if an incident occurred because someone took a reading from the wrong gauge and this resulted from confusion because the gauge was next to the one that he should have read, retraining the person in reading these devices would be less effective than re-designing or repositioning the gauge. This illustrates that different types of human failure require DIFFERENT RESPONSES to secure improvements and that solutions from higher up the HIERARCHY OF CONTROL need to be considered. This would entail asking:

  • Can the hazard be removed?
  • Can the human element be eliminated (e.g., by automation)?
  • Can the consequences of human failure be prevented (e.g., by additional barriers in the system)?
  • Can human performance be assured by using interlocks or other engineered means?
  • Can the performance shaping factors be changed to be more positive?

HSE’s document, HSG 48: Reducing error: Influencing behavior describes the well-known categories of human error:

  • Slips,
  • Lapses and
  • Mistakes

Note also that violations fall into several categories, from deliberate sabotage (rare) to routine everyday breaches of procedure.

Further information on this can be found in theHearts and Minds: material on the Energy Institute’s website at:

http://www.energyinst.org.uk/heartsandminds/rule.cfm

In general, errors result in either:

  • An error of OMISSIONSomething is not done that needs to be done
  • An error of COMMISSION – Something is done but is done incorrectly

In addition, it should be noted that an ERROR OF COMMISSION, such as operating the wrong device, would also involve an ERROR OF OMISSION because the device that should have been operated is not operated.  A distinction is also often made between “active” failures – those that have an immediate and usually visible effect; and “latent” failures – those that “lie in wait” in the system, sometimes for many months before causing a problem.

Generally, any safety-critical system intended for human use should be designed to provide multiple defenses. This is sometimes referred to as a “failing safely” system. In such a system, a single human error SHOULD NOT lead to a serious incident; in some cases, there would be no effective recovery.

NOTE: a safety-critical system is any part of an installation whose failure could contribute substantially to a major accident or whose purpose is to prevent or limit the effects of such accidents.

An important tool in proactively reducing human errors is a “risk assessment”. According to HSE’s document,  Five Steps to Risk Assessment,

a risk assessment is nothing more than a careful examination of what, in your work, could cause harm to people, so that you can weigh up whether you have taken enough precautions or should do more to prevent harm.”

An effective risk assessment should determine which tasks are the most critical and require additional or more effective barriers.  By contrast, the incident investigation seeks to retrospectively identify where barriers have failed and make improvements based on the experience gained.

 

FAILURE MODEL

Table 5 is based on the work of Dr. James Reason. It illustrates how a human-machine system can fail and introduces the main ideas about human errors that would be useful in understanding the origins of incidents and accidents. In this context, a human-machine system is one in which technology and human beings have specific functions but work together towards common goals.

Any accident can be considered a “hazard” harming a “target.”

Examples of hazards are toxic chemicals, heavy objects, sparks or flames, and high pressure in some form of containment.

Example targets are plant and equipment, people, products, and the environment.

 

Origins of incidents and accidents

The direction of Events  →

Screen_Shot_2022-08-31_at_9.32.00_PM.png

←  The Direction of Analysis

 

Working from right to left:

Consequences:

The damage caused to the target by the hazard (e.g., crude oil is accidentally spilled into the sea, killing marine life). In the case of a near miss, the concern is for the potential consequence (e.g., a fitter working up a ladder drops a 2 pound hammer that narrowly misses a small bore fuel line).

 

Barriers:

Physical barriers:

  • fences,
  • guards,
  • dikes,
  • protective clothing,
  • safety devices

or

Administrative Barriers:

  • checking procedures,
  • permits-to-work,
  • supervision

For example, A pipe is depressurized and drained before removing a pump. A drip tray is placed under the pipe in case of leaks. Also, the permit-to-work requires a second fitter to ensure that the pipe is isolated and drained and to sign the permit-to-work when he has completed the check. 

From the above, it is clear that there are two types of barriers:

  1. those designed to prevent incidents and accidents and
  2. those designed to counteract or reduce the consequences of an accident

Accident:

The event itself.

Operational disturbances:

These are events where an action (or inaction) by the person reduces the level of control over a task; such a disturbance could result in an incident or accident.

For example, a small pump was being lifted by a sling attached to an eyebolt on the pump. This was a “blind lift,” and the load snagged, causing the eyebolt to fail and the pump to drop several feet. The decision to use the eyebolt to lift the pump and the decision to conduct a blind lift were both sub-standards acts leading to the operational disturbance of lifting the load in this manner. An incident may not have occurred in this instance, but it did.

 

Unsafe/sub-standard acts:

these are the human behaviors that lead to operational disturbance. In the original human error model derived by Reason, there is no intermediary stage ‘operational disturbance’: an unsafe act can lead to a challenge to a barrier. If the barrier is ineffective, then an accident or incident ensues.

 

Psychological precursors:

The person’s state of mind would determine the type of unsafe/sub-standard act carried out. It is impossible to know their state of mind at any given time, but certain factors could affect a person’s state of mind more than others: time pressure, lack of competence, etc.

 

Latent Failures:

In contrast to active failures that lead to an immediate consequence, latent failures can remain dormant in a system until some later event reveals them. More deep-rooted latent failures are those that stem from faulty organizational decisions (see below). These can create conditions from which errors later emerge. Such conditions include poor selection or design of plant and equipment, inadequate training of personnel, ineffective supervisory practices, inaccurate communications, poor team structuring, etc.


Organizational Decisions:

Within this model, decisions made within the organization about managing all the tasks carried out are the ultimate root cause of incidents and accidents at the “sharp end.” The ultimate root causes may thus be the factors that affect those management decisions, but this is a level of complexity that we do not need to touch on here.

Scroll to Top