Taking from the “Five Themes for Excellence in Safety Management Systems (SMS)”, we can look at a facility’s ability to assess and manage risks through this lens of excellence and measure the maturity of the safety culture. To recap the progression, here are the five levels:
- Ad-Hoc
- Managed
- Standardized
- Predictable
- Excellence
Using an organization’s ability to assess and manage risks, we can see where they lie on the path to SMS Excellence.
AD-HOC – There is widespread evidence that the risk control hierarchy is not understood by employees at many levels in the organization. Managers/supervisors think it is someone else’s job to carry out risk assessments. Employees see risk assessment as a bureaucratic process getting in the way of them doing their job.
- Risk assessments are not completed or used to develop effective risk controls relevant to the hazards associated with the organization’s operations.
- There is no process to identify the risk profile associated with the organization or to develop and review risk controls.
- Risk assessments are inappropriate for their intended use.
- Health risks are not considered by the organization.
- The hierarchy of risk control is poorly used and there is over-reliance on the use of information, instruction, and training.
- No evidence of collaboration over the improved control of shared risks.
MANAGED – Managers recognize that risk assessment is their responsibility, but they frequently use risk assessment to demonstrate that controls already in place are adequate, or to justify not doing more. There is some involvement of employees in the risk assessment process and some understanding by employees as to why it is important.
- Risk assessments are completed, but there is a lack of consistency in how risk assessments are conducted, with some managers doing better than others.
- There is a process for risk assessment, but it is not applied consistently across the organization.
- There is some coordination of risk control, but the focus is on operational risks and not the complete risk profile.
- The organization uses a range of risk assessment techniques, but not always appropriate to the risk profile.
- Control measures within an activity do not always include the measures identified by the risk assessment.
- Health risk controls rely on lower-level controls from the hierarchy such as personal protective equipment (PPE) and training.
- There is evidence that the organization cooperates with other organizations to identify and control shared risks, but not consistently.
STANDARDIZED – Employees understand the purpose of risk assessment, they are actively involved and see the value of risk assessment in controlling hazards and ensuring their H&S.
- The organization has clear policies on using risk assessments.
- The organization’s risk profile has been established.
- There is a clear understanding of what risks will be tolerated.
- Risk management of system/process risks, as well as individual risk, is used in a consistent way in different parts of the organization using quantitative and qualitative techniques proportionate to the risk profile.
- Control measures in place are those that have been identified by risk assessment.
- The effectiveness of control measures for both H&S risks is evaluated and proportionate corrective action is taken.
- The organization makes effective use of the risk control hierarchy and there is evidence that some risks have been eliminated at the source.
- There is evidence of collaboration with other organizations, where the control of risk requires action by more than one party.
PREDICTABLE – Risk assessments, including removing risk at its source, are part of the culture of the organization; “Risk assessment is how we do things round here”.
- Risk assessments are integrated throughout the organization to make sure there is a systematic approach to risk control, even during periods of change.
- The approach to risk management is embedded and applied consistently throughout the organization and enables effective collaboration with stakeholders.
- The risk assessment review cycle is prioritized on a risk basis.
- Risk management principles are intelligently applied at all levels.
- Removing risk at its source is part of a consistent approach and is reflected in the organization’s policies.
- There is evidence of participation in cross-industry risk reduction programs.
EXCELLENCE – Employees at all levels seek to learn from others and readily share their knowledge and experience, knowing that this will lead to improved risk control, within their own organization and collaborating partners.
- Risk assessment is used to drive continual improvement in the risk profile of the organization.
- The organization strives for continuous improvement in risk assessment processes by looking at alternative techniques, which challenge the effectiveness of risk controls, by working with other organizations in their own and other industry sectors.
- The organization maintains an external view to identifying effective risk controls from other organizations and other industry sectors.
- The organization’s adoption of new and novel techniques in risk management has led to significant risk reductions.
- The organization is recognized as an industry leader in risk management.
- The organization leads cross-industry risk reduction programs.
- Appropriate risk assessment processes are used to make strategic choices related to the totality of the rail infrastructure.
Source: Source: RM3, 2019 – The Risk Management Maturity Model (UK’s HSE)

