Can adding more controls / barriers create new failure modes?
…maybe. Adding new controls doesn’t leave the surrounding work unchanged.
A control may prevent one event while obstructing another function, shifting risk elsewhere, or introducing byproducts that weren’t initially anticipated.
E.g. a barricade protecting plant / pedestrian collisions may also obstruct visibility, or an alarm can provide important warning info while contributing to cognitive overload.
Or, automation might remove a frequent, low-consequence failure while adding interactive complexity & tight coupling leading to rarer but larger failure modes.
In other words, controls can change workload, comms, coordination, recovery options & how people use other controls. Once people trust that a control will be there to protect them, when expected, they may also behave differently around it (* behavioural adaptation).
So, adding more layers doesn’t automatically create greater margins of safety.
When introducing control systems for major or safety-critical threats, we should consider:
· What threat does it address – initiation, escalation etc?
· What unanticipated interactions or vulnerabilities does it introduce?
· Could it transfer risk or restrict recovery options?
· How does it change behaviour or beliefs?
· What dependencies could jointly undermine several controls?
Part 4 of my Critical Control / Barrier YouTube series unpacks why control systems aren’t neutral processes sitting outside the work system – they can actively change it.
Check it out and let me know what you think. If you find my YouTube helpful then please consider subscribing and sharing with your network.
Series:
#ccm #criticalcontrol #safety #safetyscience