Further written evidence from Sanjeev Appicharla (IRW0064)

1         Introduction

1.1       General

 

This Written Evidence III is in response to the House of Commons Transport Select Committee call for Evidences to the inquiry on the theme of Investing in the Railways with regard to non- high speed railway lines. Author kindly requests that the Additional Written Evidence II submitted earlier in the day may not be considered and be discarded.

Author expresses thanks to the Hon. Chair and Members of Transport Select Committee for the opportunity to contribute to the Inquiry. Author expresses gratitude to the readers for sparing their time, and effort in reading the paper. Readers may kindly note that this paper did not have the benefit of independent proof reading and checking. Author apologises for any typographical errors that remain in the Submission as a civil engineering Professor, Henry Petroski observed in 1992 that typographical errors in an essay may evade its author’s attention (Petroski, 1992)This Submission has been made under very stressful circumstances faced by the author.

Author was awarded an under-graduate degree in electrical (power) engineering in 1983 from Karnataka Regional Engineering College, Surathkal, India (Rao, 7th July 1983).

Author became British national in 2006 after entering the country on a four year work permit issued by Alstom Transport, UK in 2000. In 2003, author obtained a High Skilled Migrant Work Permit and obtained Permanent Residency in 2005.

Author was awarded a Letter of gratitude by the Chairman of the IET’s Health and Safety Policy Advisory Group Professor Richard Taylor ,  for the input given by author  to the IET Trustees Response to the UK HSE Strategy Consultation  “ The Health and Safety of Great Britain” \\ Be a part of the Solution” in  2009.

Additional Written Evidence draws upon author’s work experience as a former employee of RSSB as CCS Engineer (Systems Engineer) from 2004 till 2010, Network Rail Principle Distribution Engineer designate (briefly 2004), Principle System Engineer with Alstom Transport Signalling (2000-2003), as Business Segment Manager managing bids and projects from £ 2 million to £25 million with Alstom India (formerly, CEGELEC India, which was a part of French MNC Firm Alcatel) from 1995 to1998. Prior to 1995, author was a senior manager delivering extra high voltage( EHV)  substation and plant electric systems and automation projects for two years and earlier to that was engaged in supervising designs of EHV sub-stations and plant electric systems .

 

 

 

1.2       Executive Summary

 

Evidences gathered from recent NAO Autumn Report 2014 are collated together with evidences drawn from Prof Andrew Hale of Delft University 2000 paper and Eric Schlosser’s 2013 Publication on Command Control System Structure  to support the hypotheses stated in 2006 and 2014 that GB Railways senior managers are unaware of the latent causes of unwanted ( economic or safety  outcome(s) and this lack of ability leads to cost overruns as well as unsafe outcomes in programme planning and delivery activity. The example of Thameslink Programme is taken up to discuss the implications (Appicharla, 2006), (Appicharla, 2014).   The purpose is to show that railway domain engineers and managers do not think and reason well about benefits of capacity and safety.

The key insight that emerges from the literature on human behaviour over the last 40 years is that cognitive ability of human beings is limited and emotions play a crucial role in decision making. Psychologists have discovered several kinds of cognitive biases at work in the problem solving and decision making process and these lead to human error in planning, and execution of the selected plans. The strategic type of decisions are prone to error and were labelled by Prof Jens Rasmussen and his co-authors as latent conditions or errors that manifest their effects after a long period of time after the decision is taken and active errors are those errors who effects are felt immediately. This classification was followed by Prof James Reason in his work on Human Error to investigate the psychological factors leading to accidents in various domains such as Railways, Nuclear, Chemical and Space industries at the level of skills, rules and knowledge based mistakes (Reason, 1990), (Rasmussen, et al., 1994).

The result of research findings were organised by Prof James Reason into what is known as Swiss Cheese Model and author has shared the results of application of the model into the theme of Investing into the Railways[1],[2]. The failures in forecasting of large railway projects are due to knowledge based mistakes and the biases that influence these mistakes were presented in the Written Submissions cited in the foot notes 1 and 2.

Author pointed out in his past Submissions that current methods of practice for measuring safety like RSSB Safety Risk Model do not take into account these knowledge based( latent error) mistakes and there is no wish to taken them into account (Jack, 18th May 2010). This may be politically influenced as the High Level Output Specification in 2007 specified in the clause 2.9 that Government supports the work of RSSB Safety Risk Model for the England and Welsh railways (Department of Transport, 2007). Author thinks that this is the reason as to why Anson Jack, Senior Director, RSSB expressed willingness to use the SIRI Methodology in the meeting with author if the Government had agreed to it despite the fact his deputy, Andrew Sharpe, suffering from anchoring bias lent support to the Yellow Book despite the fact that Yellow Book has no provision for taking into account the organisational elements. The same bias afflicts Transport of London and major parts of mainline railway refuse to abandon the Yellow Book approach.

Whereas Swiss Cheese Model helps a decision analyst to think about the decisions made by others, Prof Meredith Belbin work helps analyse the teams whether they ‘re having homogenous views and having similar characters leading to problems in team working (Krogerus & Tschappeler, 2011). Based upon his observations of individuals and roles they play he classified individuals along action –orientation (do-er, implementer, perfectionist), communication oriented (co-ordinator, team player, trailbrazer). Knowledge oriented (innovator, observer, specialist).

In terms of activity in decision making terms, problem solvers and decision makers, as per Prof Jens Rasmussen and his co-authors model of the Decision Ladder, uses of the decision making process follows a structured sequence of steps: activation of attention, gathering information, situation analysis, and diagnosis of the present state of affairs, evaluation of goals and options available which are all analytical processes. Next, an option is selected amongst all options, from which task to be carried out is selected for planning, and procedures for planning are selected for execution (Rasmussen, et al., 1994). The decision criteria for the goals may be set by the statutory authority or industry wide consensus or by legal judgements or by engineering personnel.

Author wishes to draw to attention of the Chair and Members of House of Commons Transport Select Committee that the process of decision making needs a robust analytical methodology but it would be useless unless decision makers decide to pay attention to it reason Prof Dan Lovallo, and Olivier Sibony, in their Mckinsey& Company Report in 2010 (Sibony, March 2010). Again in June 2011, along with Nobel Laureate Daniel Kahneman, they argued in the Harvard Business Review article that there is a case for executives to take into account the impact of cognitive biases ( such as confirmation bias, anchoring, and loss aversion have on their decision making process, and the distortions in judgements they lead to (Daniel Kahneman, June 2011)Unless the admission of past mistakes in decision making is made, the next decision how to remedy the past mistakes will not emerge observes Daniel Goleman and his co-authors Prof Richard Boyatzis and Prof Annie Mckee (Daniel Goleman, 2002).

Author wishes to draw to attention of the Chair and Members of House of Commons Transport Select Committee cognitive differences in thinking and reasoning based upon concepts of assets and systems as well.  Author advances the thesis that this difference leads to various mental mistakes (technically called cognitive errors) that occur when thinking and reasoning about the properties of installed capacity and safety of passengers, staff and members of public on the non-high speed railway Lines at the planning stages of the complex projects. Reasoning on how these differences arise is discussed as well and proposal on how to integrate both kinds of thinking into coherent whole.

Author hopes that this Written Submission finds a receptive audience in the persons of the Chair and Members of 2010 UK Transport Select Committee with whom author shares a list of problems involving competencies of railway engineers and managers and traces them to the cognitive (latent errors) in the conventional railways seen in planning and delivery of railway programmes. The problems with the economic case and safety cases/changes to certificates associated with these programmes trace to the problem of latent errors inherent in the railway programmes.

Author presents couple of case studies of latent errors to illustrate the phenomena.

2         Two Step Planning Process

 

Author wishes to draw to the attention of the 2010 UK Chair and Members of Transport Select Committee that the 2010 UK House of Commons Public Commons Committee is currently inquiring into the NAO Report on the Lessons Learned from Major Rail Infrastructure Projects[3] as well as inquiring into Procuring Trains[4].

From a system perspective, author considers that the issues of procuring trains, investing into the railway infrastructure, investing into modern signalling technology and transport benefits as a sub-system as the wider economic benefits cannot be included into engineering calculations unless the means(assets) for the delivery of transport benefits such as trains, railway infrastructure, signalling technology, electrification, stations  and communication systems are managed by duty-holders and their safety management systems ) together with people involved  in planning, designing, and delivering the assets are considered as a coherent whole called railway transport system in an abstract manner. Assets (train, track, signalling system, rules and regulations, stations, cost –benefit analyses) alone cannot deliver a railway service to the user unless users, people involved in the planning and delivery are considered part of the railway transport system.                     

This is the first step of technical planning which has to be succeeded by the second step of economic planning which will include housing developers and other stakeholder organisations able to participate alongside railway projects and deliver wider economic benefits sought by the Central and Local Governments. 

The skills needed for the first phase of planning are within the remit of cognitive systems engineering activity. The skills needed for the second phase of planning lies within the remit of economic planning , an activity which cognitive systems engineering activity can provide inputs and help understand what GB railway industry and trains market can delivery.

The scope of this Written Submission and definitions used are within the definitions of terms used in the Guide to Railways and Other Guided Transport Systems (Safety Regulations) 2006[5] re-issued in 2014. The reason for drawing attention to the Legislation is that the SIRI Methodology was conceived by author at RSSB in 2005 in response to the changes to legislation and started with a definition of a railway system composed by of Railway Undertaking (RU) and an Infrastructure Manager (IM) and the demand for methodology to help to identify hazards, and risks shared at their organisational boundaries.  These concepts were articulated at the IET Lecture delivered by author on 7th June 2006[6]. Thus, the explanation of every significant event in terms of the wanted( success ) or unwanted outcomes ( failures) in the world of GB Railways they leads to arises from the Duty holder’s RU, IM acting alone or due to interactions at their shared interfaces at the organisational as well as logical and physical boundaries.

Within this submission, author uses a graphical model to represent the ideas mapping the current concerns to a matrix form to display them in a coherent and consistent view to help visualise the changes that can be made to improve the current working of the mainline railway Industry.

The logical model to guide thinking of the author in his Submission derives from Prof James Reason models of generic error modelling system (GEMS) and Accident Causation (Swiss Cheese Model) as frameworks. These framework(s) presuppose Prof Jens Rasmussen’s Skill-Rules-Knowledge Framework as representation of human performance. The final outcome of application of SIRI Methodology can be represented either with Management Oversight and Risk Tree or Swiss Cheese Models listing all the events that directly or indirectly contribute to the final significant event. All these human factors frameworks presuppose cybernetic tradition and framework developed by Norbert Weiner, Ashby, Shannon and others[7]. Thus, the use of system approach to safety is drawn justified as it relies upon accepted technical and scientific concepts within cybernetic domain and these concepts apply to organisational behaviour as well (Buchanan, 1985).

3         Enterprise Risk Management

 

There is no such thing as perfect safety in transport

But a life is a life, however you travel 

Sir Alistair Morton, 5th December 1995[8]

Sixth Westminster Lecture on Transport Safety, London

Christian Wolmar in his obituary acknowledged Sir Alistair Morton worthy contribution to the GB Railways in the form of rescuing Channel Tunnel Project[9]. Author agrees to the idea that system analysis and such similar practices called systems engineering were limited to process industries like nuclear, chemical or military complexes and enterprise wide risk management process was not widely practised. The idea promoted by the UK HSE that safety standards shall be different for different transport modes was opposed by Sir Alistair Morton. A robust set of safety standards are still outside the grasp of GB Railway Industry as Section 3.2 would show.

Author agrees with the first three conclusions of Mckinsey & Company’s 52nd Working Paper on Risk Report on Risk Management Approach to A Successful Infrastructure Project[10].

Author’s agreement with the Report’s findings arises these findings agree with author’s own research findings. The failures on the part of senior managers of the GB Railway Industry to learn lessons from past failures of safety risk management and led the author to arrive at various cognitive biases that impede learning safety lessons from accidents. Author’s research papers were peer reviewed and published at IET System Safety Conferences in 2006, 2010, 2011, 2012 and 2013 as well as made Submissions to UK Law Commission, 2010 UK House of Commons Transport Select Committee and House of Lords Digital Skills Committee[11] (Appicharla, 2006), (Appicharla, 2010), (Appicharla, 2010), (Appicharla, 2011), (Appicharla, 2012), (Appicharla, 2013), (Appicharla, 2014), (The UK House of Lords Select Committee, October 2014).

However, author does not agree to the Mckinsey & Company’s asset based project lifecycle model as author’s model of risk management maps to the IEC 61508 generic safety standard model that relies upon a system based definition, model and method of analysis. Based upon the evidences presented in the paper, author  concludes that macroscopic view of costs and risks is required to be synthesised with the micro-scope view of hazards that arise from the inter-action between two delivery units of the GB Railway System, namely Infrastructure Manager and Railway Undertakings. It is to be noted that risk management is not simply a matter of a communicating risk figures in a better manner to stakeholders as some business commentators have written in the wake of Japanese nuclear accidents (Ekekwe, 2011). To realise the failure scenarios that can afflict a large programme, design and planning concepts have to be challenged. A procedure called pre-mortem analysis was suggested by Nobel Laureate Daniel Kahneman (Kahneman, 2011). Apart from the economic risks, author is of the firm opinion that safety risk scenarios must be elicited as well. This theme is taken up for further illustration in Section 4.3.

By definition, a system is made up of various assets like rails, trains, signals, stations, people, engineering and managerial processes for design, manufacture and delivery of assets and operates them on a system basis rather than on asset basis. The physical assets may fail due to wear and tear, or dysfunctional interactions between them, but human failings arise from less than adequate understanding of risk inherent in the states of the world.

Any errors, faults, deviations and inherent risks are reasoned with the help of Prof Jens Rasmussen 1984 classification of human errors into latent and active failures of understanding and Prof James Reason’s Swiss Cheese Model[12] (1990,2000) and William Johnson’s  1974 Management oversight and Risk tree ( MORT) within author’s System Approach to Safety[13] described in general at the Wikipedia site. Readers may note that there is an alternative interpretation of System Approach to Safety[14] by Prof Nancy Leveson of MIT and other US Universities. Both of these works trace backwards to Prof Jens Rasmussen and Prof James Reason’s work but as an academic safety scientist, Prof Nancy Leveson, moved ahead with her own discovery and invention. Author decided to integrate his work with the behavioural approach to economics to indicate how reversals in risk behaviour occur.

In interacting with the two states of the world (benign or otherwise), a person or group of persons can generate the decision matrix having two strategies of status quo bias (i.e. null hypothesis or alternative hypothesis) leading them to think about four resulting  cells represented into a dichotomy of two good and two bad decisions. 

The simple decision matric with a single aim of keeping oneself from getting wet is shown hereafter.

Strategies

States of the World

Safe( not raining) R(+)

Unsafe( raining) Not R(-)

S1: Carry umbrella (+)

Bad decision -active human error( S1,R)++

Good decision( S2,Not R)+-

S2: Do not carry umbrella(-)

Good decision( S2,R) -+

Bad decision -latent human error(S1, Not R)--

Table 1:  Simple Decision Making Matrix

The foregoing matrix is very familiar to those who live in London but it may not be so to those who are not familiar with London’s weather. Upon reading the literature of Nobel Laureate Gary Baker, author introduces the following decision making matrix to illustrate the ideas of human error in terms of theory of rational economic behaviour (Baker, 1964).

Strategies ↓

States of the World↓

Domain of Gains, R(+)

Domain of Losses , Not R(-)

S1: Risk averse (+)

Active human error( S1,R)++

Good decision( S2,Not R)+-

S2: Risk Seeking(-)

Good decision( S2,R) -+

Latent human error(S1, Not R)--

Table 2Expected Utility Theory Decision Making Matrix

However, when decisions involving risk to self, or near and dear ones are involved, Nobel Laureate Daniel Kahneman and his co-author Amos Tversky, suggested that experimental audience of American parents in the 1980s were willing to pay 339 times the baseline price for eliminating the risk of child poisonings for every 10,000 bottles of insect spray(pp316-317) (Kahneman, 2011).  This behaviour is shown in Table 3.

Strategies ↓

States of the World↓

Domain of Gains, R(+)

Domain of Losses , Not R(-)

S1:High Probability ( Certainty Effect)

Good decision( S2,R) -+

Sure gain, settle out of court in a dispute

Latent human error,  willing to pay excess to avoid surgical disasters or child poisonings

(S1, Not R)

S2: Low Probability (Possibility Effect)

Active human error( S1,R)++

Buy lottery ticket to seek large gains

Good decision( S2,Not R)+-

Buy insurance against small probability of losses

Table 3:  Prospect Theory, Emotional Decision Making Matrix

The Table 3 shows a surprising reversal in decision making strategy ie seeking risk due to negative emotions at work. This reversal in risk preferences does not align with rational theory of economic behaviour shown in Table 2. Moreover, as per Prospect Theory there is greater sensitivity to risk at either end of probability scale where the decision weights of utilities are overweighed or underweighted with insensitivity in the middle of the scale.

Readers may kindly note that variation of risks amongst US and UK population are different for the dreaded risk of cancer which is .001% and .025% respectively for the populations of US/UK. The quantum of risks of death at level crossings and death due to cancer works out to 0.000016% and 0.253% respectively. For the UK population this means 10 deaths for the former and 161,283[15] deaths in 2012 for the latter. Despite the quantum of risks known from different causes author follows the suggestions of Nobel Laureate Daniel Kahneman that in democracy the availability ( the ease and frequency of risk scenarios ) and affect heuristics ( making judgements and decisions by consulting emotions: do I like it? hate it? How strongly I feel about it? )  play a dominating role and have positive effect on the size of the risk reduction budget for public safety as opposed to ALARP heuristic (Appicharla, 2014). Author notes that judgements and decisions are made by one who is consciously aware as per British philosopher Alfred North Whitehead’s logic but the risk of ignorance from epistemic perspective still remains (Audi, 1998). The idea of conscious awareness that it is only in the state of awareness that discrimination between what is real and what is not real is possible can be learnt from the writings of theologians, philosophers, and scientists (Nikhilananda, 1944), (Whitehead, 1927/1978), (Valerie, 2003), (Kock, 1998), (Eliade, 1963), (Schrödinger, 1944). The idea behind these discussions is to disregard the idea of unconscious mind that is involved in making decisions.

Author does not wish to use the word Nature to avoid the interpretation that above decision matrices represent games against Nature[16] as it is done by some economists. Bayesian games and job market signalling are themes that have attracted sufficient interest because of Noble prizes were awarded in these areas. However, a long string of letters after someone’s name does not assure the author that the bearer of those letters understands the true nature of risk.

The foregoing fact is learnt by author from reading the works of signalling specialist Stanley Hall (Hall, 1990), (Hall.S & Mark, 2008). However, from a competence perspective in the job market, it is possible for an employee with skills in signalling engineering to seek a certificate of training from a professional engineering institution as an indication that employee is qualified to demonstrate to the employer requisite technical competence in the area[17]. This is how author reckons that the demand in the current job market in the railways for signalling and safety engineering is distorted towards those who are Yellow Book and IRSE Licensed HND and HNCs has arisen. It is a myth that safety critical competences can be improved with the procedures of licensing and certification as the reality of level crossing accidents and train -to -train collisions suggest to the author the idea that the certificate holders do not contemplate the facts of ontology of a system and history of accidents to inform their awareness (Eliade, 1963). Relying upon such certificates may mis-lead the analyst to think that the experts are confident and are aware of the safety and risk properties of the systems they use.

Author has come across in his work experience few IRSE past presidents who do not know how to reason about risk of technology but yet remain votaries of ERTMS/ETCS technology. For discussions on the philosophy of risk and technology, readers may refer to the Stanford article[18]. This philosophical discussion is necessary as Prof James Reason’s work on Human Error excluded certain academic disciplines of religion, philosophy from his study. Any enterprise risk management strategy must be able to elicit multiple perspectives on risk.

To those readers who are unfamiliar with the term Systems Engineering and it is hoped that the discussions to follow should help to make it intelligible as the paper proceeds.

Based upon the evidences of large scale intelligence failures( to follow) presented in the paper, author concludes that allocation of measures between Railway Operator and Infrastructure Manager is to be carried out by a System Agency to reduce the cognitive burden upon the specification and delivery agencies and stop introducing fallible signalling technologies. There is a serious need to educate and raise awareness of senior managers of the GB Railway Industry as well as rail regulator of the concept of Human Error in drawing up system and safety specification, risk regulation, and safety standards.

 

3.1       Stakeholders and responsibilities

 

Graphical models can help generate information on how a proposed or existing system is structured to work. These graphical models are called the Architecture Context Diagram within the SIRI system of drawings (Appicharla, 2006). However, the ACDs do not generate the necessary information on the functional interfaces and behaviours at the organisational interfaces. Nor the ACD is able to capture other relevant information for which reason author had developed other diagrams to represent and capture the empirical equations and functions that govern the physical phenomena at the interfaces called Parameters Diagram (Appicharla, 2006). The ACD in author’s language can be seen from the extract of NAO study published in 2010 (National Audit Office , 2010).

Figure 1: The Structure of Passenger Industry 

For example, the benefits to the passengers and the wider economy result from use of freight trains, housing developments, and better use of signalling, communications and electric systems are not listed in the above diagram. This is not to critique the NAO diagram but to introduce to the readers the idea that more work needs to be done to represent stakeholder relationships and functions in a coherent manner through system analysis as a part of cognitive systems engineering activity to bring out into the open the concerns that may become obstacles to deliver the outcomes that are desired and to prevent the undesired outcomes.

Moreover, if we consider the facts available from Case Study I of ERTMS/ETCS technology Discussed in the NAO’s 2007 study of the West Coast Mainline, and the role of ROSCOS, RSSB, Signalling Suppliers, European Railway Agency, train manufacturers and other bodies involved in the certification of the trains then it raises the problem of complexity and hazards arising at the interface of the ROSCOs/Railway Undertakings/Network Rail because the ERTMS/ETCS Technology is still not proven for the last eight years and may pose risks to passengers, other members of public, and railway staff working on or near the tracks  (National Audit Office, 2006). The above structure has no competent body to solve the problem of hazards and therefore, the task of assuring system safety still remains. This is despite the fact the Rail Delivery Group has been formed and RAIB/RSSB are existing organisations performing independent accident investigation, research and safety risk modelling of the operational railway.

The sheer number of organisations involved in the GB Railways that are not included in the above diagram namely RSSB with around 60 group members promoting standards, Railway Industry Association (RIA) with around 60 member organisations promoting technology suppliers, UIC with around 200 members of organisations promoting ERTMS/ETCS Technology and other railway related standards are unable to identify the gaps in their understanding and question themselves as to how the ideas they promote would translate into practice? If we do not invest into the ERTMS/ETCS[19] Technology simultaneously equipping the track and trains then how could the benefits of technology come about at the same time?

The activity of defining the changes by way of generating a system definition, identifying and analysing the hazards as per the Common Safety Method requires inputs from the ROSCOs, train manufacturers, signalling suppliers, civil (track), electrification, and communication engineering design organisations, and the national and European Regulations are to be collated and synthesised to develop a system specification such that it can be delivered. This can only be delivered by a System Agency. This System Agency can function in an independent manner or RSSB has to be upgraded to include the systems engineering capability which it lacks at the current time.

3.2       Work experience related to the Theme of “Investing into the Railways

 

3.2.1        Less than adequate ERTMS/ETCS Safety Standards

 

Author worked as a Control-Command Signalling Engineer (Systems Engineering) from June 2004 till 2010 at RSSB, briefly at Network Rail in 2004 for West Coast Route Modernisation Auto-transformer Project and at Alstom Transport (2000-2003) for West Coast Route Modernisation Train Control Project (WCRM-TCS) implementing ERTMS/ETCS Technology (Jack, 18th May 2010).

This work experience has informed author on the lack of expertise on the part of GB railway domain experts to think and reason about safety measures afforded by present signalling systems or future ERTMS/ETCS signalling system(s). Author realised this fact when the Design Authority of the WCRM had asked author to report the differences between the CENELEC Railway Specific Standards namely, 50126/50128/50129 and the parent generic safety standard IEC 61508 and state reasons why the UK HSE as an Acceptance Authority are asking the safety department of the WRCM –TCS Project to provide a safety case for the Train Control System-Level 2 Solution in accordance with the IEC 61508 standard. Author did not know why the professionals in the Safety Department failed to know the answer.

In 2002, based upon the reading of the IEC 61508 generic safety standard as well as railway specific CENELEC 50126/50129/50128 standards and relying upon his own expertise in the management of design and other types of teams, author concluded that CENELEC standards do not provide adequate resources to an analyst to develop a safety case for signalling systems. At that time author judged that a process methodology to comply with the IEC 61508 generic safety standards is needed for the implementing ERTMS/ETCS Technology. Because there is no conceptual or graphical design representation for the three vital steps in the activity of system definition, hazard identification and analysis as per the demand of the IEC 61508 standard to generate safety requirements and claim compliance with the safety requirements to argue the case that signalling system does not pose harm when it is deployed and is safe to operate and maintain. Further, author noted that compliance with the requirements of the Railway Group Standards (RGS standards) is mandatory for the WRCM Programme but the requirements within the Railway Group Standards, CENELEC Standards and IEC 61508 do not harmonise. RSSB has subsequently revised its Guidance on the Common Safety Method in March 2014 by Multi-Functional Standards Committee but it does not satisfy the requirements in the IEC 61508 generic standards. Readers may have to refer to clauses A4.1.1 1 of CENELEC 50129 dated 2003 or Clause 2.3.1 Appendix A of Railway Group Standard GE/GN 8641 dated June 2014[20]) to look for the evidence. The IEC maintains that IEC 61508 is applicable to railway signalling systems including moving block signalling on its Website in the Clause A3 of the FAQ Section[21]. The key difference between IEC 61508 and railway specific Common Safety Method is that the idea of eliminating the identified hazards at source requires to be considered by the IEC 61508 standard but no guidance is given as to how it should be done is stated in the Clause F2[22]. Similar consideration of eliminating hazards on the part of neither specifier nor developer is required by the railway specific CENELEC standards. This gap between requirements in the standards has remained so far and this is one of latent errors involved which is driving the cost and time factors of programmes higher when the safety requirements to eliminate the hazard at source are not considered at the planning stage. The consideration of hazards at the planning stage will force attention to the particular design risks instead of relying upon a generalised hazards list.

Author confesses to the idea that he was ignorant of dichotomy of latent and active errors in 2002 and these concepts became part of author’s awareness since 2005. Author was aware of managerial mistakes from his first year of employment. The idea came to him first when his senior manager asked to expedite a task in an electrical project temporarily in an unsafe manner to meet the deadline of the project to show that investment is completed to the deadlines of cost and time to the company auditors. Author was replaced for the short duration of the project but was recalled later on when the senior manager realised the lack of design skills in the team.  

Author’s judgements on safety cases were made prior to the 2003 publication of comments on the question number 12 of the Technical Review of the UK HSE Review of the ERTMS/ETCS Project Work[23]. Author is aware that current 2014 risk regulation regime does not require submission of safety case as per Common Safety Method. This theme is taken up in the context of conventional signalling systems again.

3.2.2        Less than adequate Systems Engineering[24] Standards and Human Error

 

IEEE Std 1223 Guide for Developing System Requirements Specification in 1998 stated the well-formed requirement (a statement for functionality a transportation system shall provide) in the Clause no 7.2 as under (IEEE, 1998).

The system shall move people between Los Angeles and New York at an optimal cruising speed of 200 km/hr with a maximum speed of 300 km/hr.

However, the relation between system safety, capability, cost requirements and system definition requirements remain unclear in the above statement. The 2011 version of the modified standard IEC 29148[25] makes an effort to bridge the gap in standards guiding systems engineering, safety engineering, human factors engineering, and risk management by including reference to the IEC 15288 (systems engineering) and IEC 61085 ( safety engineering ) standards.

The scope or boundary of a transport system can be extended beyond the above requirement statement to include the whole economy apart from transport benefits (journey time improvements and capacity improvements) by making them part of the total benefits desired from the programme. This can be seen from National Audit Report HC 1834 on the theme of HS1 Sale (National Audit Office , 28 March 2012).

Such political and social requirements cannot be handled by a systems engineering process that does not include the representation of a transportation system as a collection of all organisations as entities forming part of whole transport system to shape its outcome.

Graphical representation of participating stakeholder organisations in a system can range from simple to complex ones. The simple representation can be seen in the Appendix 2 of the NAO Report HC 33 or complex one that makes reading difficult can be seen in the representation of Obama Healthcare System in Figure 1 of 2011 Adam Howard’s Thesis[26] .

From the perspective of Human Error, the harm arising out of transport operations naturally induce a system engineer to reflect upon human errors occurring at various stages of planning and delivery of the system. This is the essence of the cognitive systems engineering whereby a system engineer looks to improve the system by taking into account various perspectives of common sense, scientist, attorney, human reliability analyst, and designer as stakeholders. The common sense perspective may illustrate the tendency of scapegoating the persons involved in the dynamic flow of events that resulted in an abnormal event, or scientific perspective may look for a person who lost control of the chain of events, or legal perspective may look for a responsible person to be punished who allowed such work conditions which can induce error or reliability perspective may analyse human behaviour at the task by looking how reliably it is  performed or systems perspective by looking at the mis-matches between requirements for the system, human cognitive abilities and worst case risk scenarios to make changes to improve the system are suggested by Prof Jens Rasmussen and others( pp135-159) (Rasmussen, et al., 1994).

The boundaries to cost, risk, safety, and acceptable performance may emerge from the cognitive analysis of the work situation and may inform the process of migration of work towards unsafe boundaries. Prof Jens Rasmussen and others noted that the shift in perspective required is akin to the shift from Newtonian particle dynamics to thermodynamics in the cited chapter. The ideas of goodness and well-being are not new. Reading Plato’s Republic author notes that ancient Greek literature contained the idea that God is the cause, not of all things, but only of Good[27] (pp135) (Plato, 375 BC/1955). Author notes that the shift from Newtonian particle dynamics to thermodynamics to Albert Einstein’s theories of relativity is difficult without help and can be navigated by means of works of Nobel Laureate Bertrand Russell and philosopher, Alfred North Whitehead (Whitehead, 1927/1978), (Russell, 1945).

The lack of a process to combine concepts of human errors, system safety, human factors engineering, systems engineering and risk management into a coherent process impedes the benefits to be realised out of the transport system. This insight challenges views of the suppliers, computer scientists, safety engineers, human factor and systems engineers who claim that a safety case for a transport system can be written and accepted in a multi-stakeholder environment using the existing processes and no change is needed in the way the organisations operate the current non- ERTMS signalling systems controlling the trains on non-high speed lines to be converted to cab signalling schemes or replacing route relay interlocking’s with digital interlocking . The reasons advanced are that Safety Management Systems of RU and IM can handle the process or if the change is significant the Common Safety method applies.  Both of these arguments are refuted in the Submission.

Prior to the examination of the safety standards on a comparative basis in 2003, the Design Authority of the WRCM –TCS Project had asked author to investigate as to why a European train computer system cannot provide location information automatically to the European trackside computer system without human intervention? This problem is known within the ERTMS/ETCS community of engineers and managers as “Train Awakening Problem”. After due research, author recommended huge change is needed to the current version of the ERTMS/ETCS Specification as it does not cater to this requirement. The Design Authority of the WCRM TCS Project, Network Rail’s Systems Engineer or its Project Director did not grasp the twin problems of the Safety Case for ERTMS/ETCS and the Train Awakening issue and did not connect how the location error in the train position data may jeopardise the safety of passengers, staff (train drivers) and others.

Author confesses to the ignorance of concepts of “learning organisations” and “Learning and Transferring Lessons from Project Failures “during the period 1983 till 1991. These concepts were subsequently learnt and applied by author during the period 1992 till 1988.  Concepts of “Inherently Safe Design”, “Learning Organisations” and Learning Lessons and transferring them” can be seen in the UK HSE 1996 Document as well[28] .

4         The possibility of Social Choice: selection of options from alternatives

4.1       Social decision making and risk analysis by Committees in Organisations

 

The economic and ecological perspectives are discussed in a brief manner in the context of the above theme.

 

4.2       Economic perspective

 A camel, it has been said, is a horse designed by committee

…… Nobel Laureate Amartya Sen (8th December 1998)

Nobel Laureate Amartya Sen drew attention of his listeners on the occasion of his Nobel Prize lecture whilst carefully noting that the above saying is a telling example of deficiencies in committee based decision making process (Sen, 1998). Prof Amartya Sen observed that in actuality committees trying to design a horse to satisfy the desires of its different members can verily produce less harmonious; perhaps centaur of Greek mythology, a mercurial creation combining savagery with confusion.

Author interprets the foregoing from a systems engineering perspective that Prof Amartya Sen compared briefly the features (emergent properties in systems engineering language) of a horse (speed) and a camel as a useful and harmonious animal (well-co-ordinated body to travel long distances without food and water).  Prof Amartya Sen noted that story of economics can be traced back to ancient Greek or Indian periods in his 1998 lecture. From an academic perspective, Prof Amartya Sen pioneered the Capability Approach to well-being. More details can be read from this link[29]. From the perspective of critical economist Dr Schumacher, author does not think that a railway transport system between cities or rural areas can attain economy from pursuing the idea of Small is Beautiful. The idea of community railway transport system is not excluded by rejection of this idea. The existing community railway schemes can be seen from this link[30].

From author’s perspective, Prof Amartya Sen work supports two conclusions author drew from his research work before. First, decision making in committees in the GB Railway industry are prone to Group-think bias and these decisions are taken without paying attention to the hazards they may give rise which in turn lead to accidents if no barriers intervene in the flow of hazardous events (Appicharla, 2010). Second, a from technological perspective, the Capability afforded by new technology or a changed signalling system may give rise to harm for some people (Appicharla, 2013). Philosopher of technology, Prof Sven Ove Hansson states that modern social decision theory derived from Noble Laureate Kenneth Arrow’s Impossibility Theorem shows that no voting rule for a social choice can emerge if there are four reasonable criteria (Hansson, 1994), (The Concise Encyclopedia of Economics, 2008). Prof Amartya Sen has discussed Kenneth Arrows’ Impossibility Theorem in his Nobel Prize lecture. Author does not follow the traditions of economic liberalism to negate the idea of welfare or behavioural economics.

The insight from Nobelist economists that some rationality demands on Social Choice Decision Theory may not be met applies to public issues like nuclear power is argued by Prof Sven Ove Hansson. He discussed a scenario whereby groups of people organise themselves into environmentalists, ethicists, and economists to debate over what the methods of nuclear disposal to be used. Most lay persons as well as academic sociologists like Charles Perrow argue that inherent risk of nuclear plants is intolerable and therefore these plants should be closed (Perrow, 1984/1999). This argument may have gained credibility due to recent Japanese accident.

Author’s representation of the Japanese accident using SIRI Methodology based upon the evidence drawn from the Japanese Accident Investigation Report revealed a string of failures (safety measures). These measures like failure to control the chain reaction, decision aids failing to predict future states, failure of cooling water systems shows that this accident exposed the inherent risk of the design of the nuclear plant (Appicharla, 2013). The question of residual risk of the spent nuclear fuel is not resolved even if the contentious debate over nuclear power is closed after the decision to close the nuclear plants is taken.

From a Social Choice perspective, the three groups of ethicists, environmentalists, and economists will form coalition and may change their position from time to time and argue against each other without a solution in sight. Further, management procedures like risk analysis, evaluation and risk management which form part of philosophy of technology were found less than adequate due to differing perceptions amongst the operator, regulator and supplier of the nuclear reactor as well as the gaps in understanding of risks between the engineers and managers of the plant on the quantum of risk emerged (Appicharla, 2013).

The evidence on the Wikipedia article shows that around 99 accidents have taken place world-wide in the last 60 years or so[31]. In the wake of Japanese accident, the UK Office of Nuclear Regulator (ONR) seeks to revise its standards and therefore, author wishes to terminate the discussions on the theme of UK nuclear plants[32].

Those who may have visited any power generating plant anytime may wonder at the huge and complex machinery that is needed to produce electric power. However, the actual scenarios  to tackle the dangerous station black out (SBO) accident with a total loss of emergency power and cooling facilities (no illumination at the site and in total darkness to control the nuclear radiation from escaping) with full fury of Nature against them that has led to melting of three cores is nothing less than a miracle[33]. Thanks to God’s Glory and Grace, the plant personnel were able to navigate the plant in darkness and started to flood the cores with sea water within 2-3 days of the initiating event.

However, author finds it very strange on the part of RSSB Operational Specialist, Greg Morse[34], to speculate on the various lessons to be learnt for wider rail industry in a post-hosted on RSSB. The contradiction with the ideas expressed in web posting with the idea that RSSB did not think the societal concerns( multiple fatality accidents)  are within its remit as per RSSB 2009 Taking Safe Decisions document has escaped Greg Morse’s attention as well as 2014 Taking Safe Decisions Document[35] (Bearfield, 2009). Further, failure to learn lessons again seems to have escaped RSSB and Greg Morse’s attention because of the denial culture operating in conjunction with the idea that the decisions on risk to public are within Government remit does not square well with idea that RSSB is paying attention to public risk.

Author is of the firm opinion based upon RSSB’s analysis of Fukushima accident and their lack of understanding of Swiss cheese model, RSSB senior managers and its staff may require rigorous training on logical system( inherited from Aristotle’s philosophical and logical tradition) on how to apply syllogism and detect errors with the analysis of statements. The consensus based decision making process by RSSB is not of a scientific nature and author’s suggestion is that lack of skills and abilities to take system approach to safety produces this kind of response.

Note 1: Author wishes the Chair and Members of Transport Select Committee to note that GB Industry’s consensus of each individual firm who are members of RSSB as stated in its 2014 document is that each firm RU/IM is responsible for its own risks and various types of multiple-fatality accidents that are caused by interactions of RU/IM system failures are not envisaged in the design of regulation as argued in the Annex 1[36].

The advocates of risk analysis, assessment and risk management may find and use evidence from safety study at the EPRI to argue that the process of risk management provides criteria for rational decision making[37]. The core damage frequency of these three GE BWR reactors was worked out in 1995 to be within a range of 10E-04 and 10E-7[38] in another study. In real terms, the core damage frequency ie the mean time between failures is around 20,000 years under the assumption there are 500 reactors world-wide. However, readers can verify that three reactors failed in 60 years in a single accident and this failure evidence negates the thesis of risk informed rational decision making process in large organisations works; organisations are able to plan and mitigate risk events with serious consequences[39]. A news report published by Reuters on August 2014 claimed that there are social tensions prevailing in the nearby city where the accident taken place[40]. The nuclear operator TEPCO has paid $41 billion as compensation so far. 

 

Author draws an insight from the foregoing phenomena that reliable operations of any plant are different from the safe operation of the same plant and both of them need to be approached from different perspectives.  Further, the idea of Base Rate Fallacy advanced by Nobel Laureate Daniel Kahneman as regarding risk analysis is relevant from the foregoing discussions (Kahneman, 2011). The idea of mis-information about the real causes of 2011 nuclear accident abound as the analysis of the accident report(s) are subject to mis-conceptions that are not informed by the actual circumstances of the accident. Regulatory and managerial oversights compound the problem of unsafe designs by preventing suitable measures to be taken by encouraging a denial culture is noted by Prof James Reason (Reason, 1990). Author had presented his own case in the previous Written Submission to the Transport Select Committee as an example of denial culture.

The relevance of risk analysis performed in the nuclear industry to the discussions on Investing to the Railways is due to the fact that Safety Case Regime introduced in 1994 led to recruitment of several professionals from the nuclear industry to the railway industry. This is to help the industry gain work experience from the nuclear industry’s experience. Experts from nuclear industry joined in the GB Railway Industry in 2000 first at Railway Safety and subsequently transferred to RSSB. From his interactions with these individuals from 2006 till 2009, author had felt that these individuals did not possess any kind of wider systems engineering or design engineering expertise and felt that he had to look for more basic schemes to help him with a process to implement approaching legislative changes that devolved safety management and safety certificates to individual duty holders[41].

The 2009 presentation from the UK Department of Transport on safety case regime and its modification confirms these changes[42]. Certain mis-conceptions are described here. The presenter, Chris Carr, has failed to understand the following concepts and this is a common failure across the government, regulator and the industry

a)      Inter-operability cannot be wider than safety

 

Because inter-operability deals with the ERTMS/ETCS signalling system which excludes national signalling assets, attaining the inter-operability certification shows that economic goals may be attained but the safety goal of zero fatalities presently met by the AWS+TPWS train protection system for the train to train collision events cannot be attained unless ERTMS/ETCS is designed in different ways (Winter, 2009).

 

Overlaying of the cab signalling is not possible because train driver cannot be presented with movement information from two different systems. This may lead the train driver into a decision making process and introduce delays in train driver’s information processing response to emergency. Further applications of ERTMS/ETCS with automatic train functionality requires a new systems safety analysis for non-high speed metro operations and no credit can be taken from the existing European Safety Analysis as the behaviour new system is not modelled at the European Level or the hazards may be different from those assumed to be controlled in the design by the European System Safety Analysis.

 

The decision to use ERTMS/ETCS/ATO as an integrated system for Thameslink Programme is proposed by the professionals who have no experience of performing system safety studies. Author is able to state this information with confidence because author was interviewed by a Head-hunter acting on behalf of Network Rail for the role of Principal Design Engineer to lead all strategic technical direction and leadership for Systems Engineering Activities within the Thameslink Programme in November 2006. Author had made it clear to the Head-hunter that unless author, as a job holder, in the role is allowed to carry out an objective examination of the case that the technology affords the evidence that 24 train paths per hour target can be attained and no hazards are likely to occur in the operations or if they do occur they‘re controlled or eliminated. Otherwise, author will not be in a position to assume the responsibility of the job (Undisclosed , November 2006). Of course, the Head-hunter found more willing persons to do the job and the project moved ahead before hitting the problem of cost and time overruns. This concern is taken up in Section 3.1.5 where latent errors in planning of large railway programmes is examined using the evidence drawn from the National Audit Report dated October 2014.

 

ERTMS/ETCS Signalling Technology is designed for High Speed Operations and failure of WRCM TCS Project is an obvious sign that knowledge base necessary for drawing safety case is simply not available. It is pretty unfortunate situation that author has ability to integrate human error, and other engineering disciplines into coherent scheme to identify and detect hazards arising out of latent failures but the culture of the GB Railway Industry poses stiff resistance.

 

b)      ERTMS/ETCS Signalled Lines cannot be applied on classical railway routes with level crossing because incidents and accidents are prone to occur because design of ERTMS/ETCS excluded level crossing functionality. There is no European evidence to support the counter thesis that ERTMS/ETCS Signalled Lines can deal with risks posed by level crossings. This is an issue which author has been shouting into the ears of those within hearing range since 2003 apart from the technical issues discussed in the section 1.2

c)       A duty holder cannot claim that the Safety Management System is in working order when accidents are taking place on the railway lines every year. The premise that SMS is working is not supported by the evidence drawn from the RAIB Investigations[43].                                                                                          

Academic professors teaching logic, sociology, and organisational behaviour will be startled to find the logic propounded in modern times by railway domain professionals (M.Copi & Cohen, 1998), (Perrow, 1984/1999), (Buchanan, 1985). Basic geometry classes learnt at the school are still relevant despite the advances made in modern physics is an idea that many people tend to forget. Physicists who discuss the ideas of geometry relevant to modern times is available from these works (Penrose, 2004), (Hawking, 2005).

The insight from Nobel Laureate Daniel Kahneman and Amartya Sen works applies to complex technologies like standardised computer and radio based cab signalling technology called ERTMS/ETCS[44] when cost, reliability, availability, performance and safety decision criteria of ERMTS/ETCS technology are to be taken into account.

The decision to replace the current signalling system made up of line side signalling and AWS and TPWS Train Protection Systems in the case of classic railway lines throws up conflict between capacity and safety. This conflict may not allow the design to be settled unless the design and development approach is centralised is not recognised by System Authorities like European Railway Agency or the UK Rail Regulator ORR who tend to promote the European System. The Glossary for the ERTMS/ETCS signalling systems is available on the Network Rail Website[45].

Author has found a GB Railway Industry workshop document[46] dated July 2013 that does not recognise the evidence that academics at Delft University of Netherlands and Swedish Lund University in 2007 have drawn attention towards the problems with the concepts of ERTMS/ETCS systems with regard to worst case scenario of degraded operations resulting in increased cognitive burden on the trackside signalling controller and the train driver in the absence of line side signalling. Train driver has no mental image to support operations during the emergency in a cab signalling emergency situation. This difficultly is apart from the value conflicts that will arise during the planning and designs stages of ERTMS/ETCS Technology solution[47]. Readers may please note that clicking the footnote will download the paper automatically.

The latest optimistic assumption by the GB Railway industry experts is that all designers will look at the same drawings and software architecture through the BIM models and therefore, debates and disputes and values seen in the projects will be a thing of past. The lack of recognition that regulator, government and industry have different perspectives on risk, cost, safety and other parameters is noted in the 2007 Delft paper. This situation is represented in a decision matrix after taking a digression to introduce ecological point of view.

4.3       Ecological perspective and Case Studies of Latent Errors

 

Given the fact all animals need food, water (energy as material cause and begetting as formal cause) to survive and reproduce their own kind (mother as material cause, father as efficient cause) from ecological perspective, it is an amazing fact to find a species of animals adapted to their environment and both constituting inseparable pair. From the perspective of ecological approach, terms animal and environment imply each other. However, the world of physics which uses concepts of space, time, matter, energy does not lead to concepts of organism and environment or to the concept of species and its habitat. The sense organs of animals and the visual perceptual systems are not capable of detecting atoms and galaxies with direct perception without the aid of microscopes and telescopes as instruments of indirect perception. Photographs and pictures serve as indirect perception mode as well. Speech and writing are higher modes of apprehension. The concern of psychology from the ecological perspective is the animal in its environment which persists in some respects and changes in some respects (pp7-15) (Gibson, 1986). Bishop Berkeley in 1709 suggested that the chief end of vision was for animals “to foresee the benefit or injury which is like to ensue upon the application of their bodies to this or that body which is at a distance”. In other words, it is foresight. From the ecological approach to visual perception Prof James J. Gibson named the concept of foresight as the concept of affordance of benefit or harm (pp232) (Gibson, 1986).

Since the ancient times definitions of individual human being and human nature are discussed and studied. Modern Cartesian view of a person as a union of two differing substances i.e. mind and body poses a great difficulty as to how these two differing substances interact and give rise to the properties seen in the world.  For a greater detail on the theory of knowledge, readers may consult Prof Robert Audi’s work (Audi, 1998). For the purposes of this work, an individual human being is treated as a knower of the field made up of 24 elements composed of five great elements of ether, air, fire, water, and earth as evolved in their subtle form, I consciousness, understanding and the unmainifested; ten senses (five of perception, and action), the mind, the five objects of senses as described in the verses 13.5 and 13.6 of the Bhagavad Gita by Swami Nikhilanada (Nikhilananda, 1944). This model of human factors is adequate and justified is learnt by the author after reading the more formal works of Nobel Laureates Sir Francis Crick, Daniel Kahneman, Albert Einstein and Erwin Schrodinger as well as systems engineering academics and cognitive system scientists (Gopnik & Schulz, 2007), (Buchanan, 1985), (Kock, 1998), (Einstein, 1920), (Schrödinger, 1944), (Rasmussen, et al., 1994), (J.Fabrcky & S.Blanchard, 2005).

In order to make right investments into the Railways it is necessary to select the right options from competing proposals to make investment. This is a task faced by specification as well as delivery agencies. In the context of the foregoing passage, the choice of technology in its application to the delivery of railway services (an action taken by engineers for the benefit of people who use railway transport for personal as well as freight transport) requires engineers and managers to reflect the features of the technology in their interaction with the features of the environment as well as features of immediate and end users as well.

It is possible to critic the foregoing paragraphs by saying that Delivery Agency and Duty-holders with the help of market are able to co-operate and generate the best option that can serve the interests of people and there is no need for a state regulator to be aware of the technological features that may interact in a dysfunctional manner with its environment and may pose harm to its immediate and end users. By definition, if philosophy is defined as an attempt to “understand how things work”, then technology needs to be examined from a psychological, physical as well as philosophical perspective due to its affordance of harm or benefit. Mental habits or heuristics that shape the behaviour of experts from behaviourism perspective were described in the previous Submission[48].

 

Railway senior managers may object to the foregoing that author is labouring the point unnecessarily given the fact that environmental, human factors, safety engineering, and systems engineering disciplines already address the issues raised. The argument runs thus. We deploy numerous working groups and committees composed of experts to elicit information on risk, model and analyse it and make informed judgements.

Investment into rail transport yield greatest benefits to the wider economy and an objection to railway investment into digital technology is ill founded and is compounded by lack of awareness (ignorance of process used for decision making) and distracts attention from the time and effort needed to plan for large scale investments.

The pool of talent of experts in systems engineering, safety engineering, human factors engineering, risk analysis, operational, signalling, electrification, communication, civil, mechanical and other disciplines are able to co-ordinate their work with the help and guidance of senior managers to attain efficient outcomes in a timely manner.

At this juncture, author wishes to introduce evidences drawn from GB Railway domain experts to illustrate evidences to counter the above argument and support author’s hypothesis that senior managers do not comprehend the root causes of railway accidents (Appicharla, 2006).

Author presents a brief history of the evolution of railway signalling drawn from the 1982 works of G.  Freeman Allen. This work was endorsed by Sir Peter Parker MVO, the then Chairman of British Rail.  Consideration of the history reveals lack of understanding on the part of British Railways on how to communicate information to the train drivers on the status of route ahead. Two case studies are presented in the format used by Prof James Reason in his publication on Human Error.

4.3.1        Latent Error in Railway Safety Signalling Principles discovered in 1876 with occurrence of an unfortunate accident: Case Study I Train Collision Protection

 

The traditional approach of Design and Construct amongst GB Railway P-Way designers is clearly demonstrated by visual inspection of   P-way designer Ian Ellis’s document on the Staging process to drive the Interdisciplinary design co-ordination activity by means of certificate (IDCC) hosted by him on his website[49]. At first sight, his effort to bring discipline into the design process is laudable. However, if we take into account the factor of lack of awareness of EU Standards of Inter-operability, the need for harmonising the national GB standards, the lack of attention to system safety aspects in the IDCC Certificate then the IDCC Certificate is an clear indication of the cultural phenomena of lack of understanding of concepts of system and system safety. Author had shown that there is a regulatory requirement to adopt EU Inter-operability standards in his first Written Evidence which has been published by the 2010 Transport Select Committee.

G. Freeman Allen noted that the railways signalling system evolved from manual traffic control of passenger carrying traffic by means of a system of flags used by policemen to signal trains using a sand-timer to maintain a prescribed time-interval between trains to a space interval block system using block instruments, levers and semaphore signals. This system further evolved into modern track circuited, four aspect optical signalling system to inform the train driver of the status of track ahead (pp140-151) (Allen, 1982). The modern day four aspect signalling system with its colour aspects of Green, Double Yellow, Yellow and Red meaning Green means Go, Double Yellow Ready for Caution, Yellow Caution and Red means Stop did not have the same meanings in 19th century.

When semaphore signals were first designed by Charles Hutton Gregory in 1841 to convey all three signalling aspects by means of one signal arm he drew ideas from Chappes’ overland relay signalling chain that originated in France.  The graphical representation of the signal arms from Figures 2.1, 2.2 and 2.3 can be seen from the railsigns.uk website[50].

Case Study I: Abbots Ripton Accident involving double collisions resulting in loss of 13 passengers and 35 passengers were injured on the Great Northern Railway, on 21st January 1876. A coal train was hit by an Express train

Selected Latent Failures

Origins

Evidence

  1. System errors

 

 

The Regulation of Railways Act 1871 did not require railway companies to consider inherent risk in the working of railways

Government /Management

Page 41 (Hall, 1990)

Railway inspector’s recommendation for continuous brakes on the trains ignored

Government /Management

Page 41 (Hall, 1990),

 

Page 28, Accident Report

 

http://www.railwaysarchive.co.uk/documents/BoT_AbbottsRipton1876.pdf

 

 

 

 

 

Railway inspector’s recommendation on safety precautions of detention of slow trains,  platelayers at signals and cabin signals to be applied in bad weather conditions neglected

Government /Management

Page 28, Accident Report

 

 

Cause number 8 of the Accident Report

 

Plate layers could have secured distant signal showing false all clear sign due to snow

 

http://www.railwaysarchive.co.uk/documents/BoT_AbbottsRipton1876.pdf

 

  1. Design errors

 

 

Recession of lower quadrant semaphore arms in slotted signal post

Management and engineering error

Cause number 2 and 5 of the Accident Report, Page 143 (Allen, 1982)

 

 

http://www.railwaysarchive.co.uk/documents/BoT_AbbottsRipton1876.pdf

 

Mechanical design changed after the accident to centrally pivoted arm located clear of the post

False assurance of all clear aspect by obscuring lower quadrant semaphore arm by signal

Management and engineering error

British signalling practice of obscuring signals as assurance of clear road ahead for forty years had to change as distant signal did not raise the semaphore arm  when the home signal was at danger

 

Cause number 2 of the Accident Report, Page 143 (Allen, 1982)

 

Cause number 11  of the Accident Report,

http://www.railwaysarchive.co.uk/documents/BoT_AbbottsRipton1876.pdf

 

 

Non-provision of telegraph block instruments in the signal cabins at Conington and Wood-Walton

Management and engineering error

Cause number 4 of the Accident Report

The coal train driver could have been warned

 

http://www.railwaysarchive.co.uk/documents/BoT_AbbottsRipton1876.pdf

 

 

Emergency planning of Great Northern Railway did not respond to the first accident

Management and engineering error

Cause number 9 of the Accident Report

http://www.railwaysarchive.co.uk/documents/BoT_AbbottsRipton1876.pdf

 

Station master at Holme did not act   upon the information given to him by signalman at Holme about the coal train and state of signals

Operator error

Cause number 3 of the Accident Report

 

Scotch express train driver could have been forewarned

http://www.railwaysarchive.co.uk/documents/BoT_AbbottsRipton1876.pdf

 

Wikipedia report:

http://en.wikipedia.org/wiki/Abbots_Ripton_rail_accident

 

Wood Walton signalman did not put detonators down or exhibiting a red handlamp to the Scotsman

 

Operator error

Cause number 6 of the Accident Report

 

 

Wikipedia report:

http://en.wikipedia.org/wiki/Abbots_Ripton_rail_accident

 

Huntington signalman did not accept Holme signal man’s message to prevent second collision by

Operator error

Cause number10  of the Accident Report

Leeds train driver could have been stopped

http://www.railwaysarchive.co.uk/documents/BoT_AbbottsRipton1876.pdf

Wikipedia report:

http://en.wikipedia.org/wiki/Abbots_Ripton_rail_accident

 

 

The information in the above table showed that railway inspectors had warned of risk of danger both to the Royal Devon Commission as well as Railway Companies. The case study also reflects lack of proactive approach to system safety inherent in the railway signalling practices and demonstrated that Clapham and Southall type of accidents did occur before due to weaknesses in the railway signalling practices. Further, it demonstrates the fact that social choices as well as individual choices are subject to availability of risk scenarios and their acceptance or rejection by railway companies to amend their management and engineering practices (Kahneman, 2011). Those who think that the station master should have been tried for man-slaughter forget the fact that the Holmes station master is capable of thinking of the hypothesis of 20th century that space is homogenous (same everywhere) and isotropic (an object with property same in all directions) in nature and how can he perceive that all signals are alike in their behaviour? If it rains in some parts of London then it does not mean it rains in all parts of London is known to anyone who is familiar with weather in London.

The 1876 case study demonstrates that 19th century accident investigation process was largely unbiased and investigators looked for both direct and indirect causes of the accident of train collisions. This accident led to changes in the GB Railway Signalling Practices, mechanical design of Signals, and meaning of aspects ie from White means All Clear to Green Means Go to default state of information being Red means Danger. The Railways Regulation Act 1889 concluded the safety issues that had dogged the railways since 1842 by mandating the Absolute Block Signalling System, and associated rules and regulations[51] (Hall, 2010).

4.3.2        Latent Error in Railway Safety Operational Principles discovered in 2005 in Hazop Workshop: Case Study II Train Worker Protection

 

Further, promulgation of the 1889 Act shows that Signalling Principles are not like the principles of Nature that are immutable. This false belief entertained by current generation of railway signalling engineers and operators who perhaps entered service from the 60s onwards or later.

The Natural principles can be learnt from the works of philosophers Arthur Schopenhauer, Nobel Laureates Albert Einstein, Erwin Schrodinger, Bertrand Russell and Sir Roger Penrose (Einstein, 1920), (Penrose, 2004), (Schrödinger, 1944), (Schopenhauer, 1813/2006), (Russell, 1945) . For example, the Railway Safety Principle[52] 1.5 issued in 2007 states that signallers should be reminded that of the presence of trains when they are detained at the end of movement authority on running lines. The Railway Group Standard GK02/0212[53] was issued by Signalling Standards Committee in 2007 despite the fact that an operational situation can emerge when the train is detained on a running line for cleaning purposes and a key has been issued by infrastructure manager personnel ie signaller to the railway undertaking personnel ie cleaner without interlocking the issue of key with the protection signal preventing a signalled movement of another train into the defined protection area.

The signaller may forget the fact that he may have issued the key and because of lack of interlocking of the withdrawal of the key and protecting signal, the signaller may issue a movement authority to another train into the protected area where the train may be under cleaning. This hazard scenario emerged from the application of SIRI Process and the result was placed before Signalling Standards Committee with an objection that the safety integrity level of the interlocking has no role to play in affording protection to the railway undertaking personnel working on the train as defined in clause no 2.1.6. Further, signalling engineers in the Hazop workshop falsely believed that lamp provided on the lock system had a role to play to afford protection to the train worker as the key has been issued and a lamp on the signaller’s control panel will be lit and thus, no signalled move can be allowed into the protection area.

Case Study II: Potential Train Worker Protection Study 2005: A train is stabled at the platform on a running line. A train worker or group of workers obtain clearance through a key lockout mechanism that illuminates a lamp on signaller’s display to indicate the status of the keys. 

Selected Latent Failures

Origins

Evidence

  1. System errors

 

 

EC Regulation No 352/2009 requires application of Common Safety Method. But the changes to lock out standard are not significant so no risk assessment is necessary   

Government /Management

Clause 1.2 of ORR Guidance

 

Clause 1 Annex 1

 

Expert judgement will fail to recognise the changes to the standards and operating methods as the design of lock out system remains the same. Active error on the part of signaller cannot be mitigated.

Normal requirements of Safety Management Systems will apply. Compliance with GB Signalling Standards will apply.

 

http://orr.gov.uk/__data/assets/pdf_file/0006/3867/common_safety_method_guidance.pdf

 

HMRI Safety Principle 1.5 : when trains are detained at the end of their movement authority on running lines, signallers should be

reminded of their presence after a suitable period of time and should not allow other trains to use the

occupied portion of line, except where authorised. Procedures should be designed to prevent the signaller

overriding interlocking systems in error to permit trains to enter portions of line already occupied by

detained trains.

Signalling engineers falsely believe that lamp on the signaller’s panel is sufficient to provide warning to the signaller that a train is stationed behind the signal. However, a failure of the lamp does give rise to chance that signaller may forget and route a train into the protection area. Failure of lamp cannot be ruled out and the HMRI Principle does not recognise the fact signalling engineer’s false belief in the lamp provided on the signaller’s panel affords sufficient protection against error. A reminder device is necessary to guard against failure of lamp.

 

Government /Management

Clause 1.5 a) and b) HMRI Signalling Principles

 

 

The latent failure on the part of experts to fail to grasp the scenario by which situational awareness of the signaller may be obscured due to lack of discrimination of whether key is released or not of the lamp fails on the signaller’s panel.

 

 

http://webarchive.nationalarchives.gov.uk/20131001175041/http://www.rail-reg.gov.uk/upload/pdf/rsp3-smot-210507.pdf

 

The foregoing scenarios emerged from SIRI Hazop study in 2005.

 

 

Page 15 of IET 2006 System Safety Conference Publication (Appicharla, 2006)

 

 

 

Signalling Standard Committee rejects reminder appliances

RSSB /Duty holder Management(s)

Railway Group Standard GK/RT 0212 dated 2007

http://www.rgsonline.co.uk/Railway_Group_Standards/Control%20Command%20and%20Signalling/Railway%20Group%20Standards/GKRT0212%20Iss%201.pdf

Evidence of Group-think bias , IET Publication 2010

(Appicharla, 2010) 

  1. Design errors

 

 

 

False assurance of track worker protection by means of fallible lamp 2.1.6

Management and engineering error

No requirement in the HMRI and RSSB documents calling for action against failures on the part of equipment.

 

The lamp failure can bring about a change in mental awareness of the signaller. Rules focus on active failure rather than take into account latent failures as well as per Swiss Cheese Model.

 

http://www.rgsonline.co.uk/Railway_Group_Standards/Control%20Command%20and%20Signalling/Railway%20Group%20Standards/GKRT0212%20Iss%201.pdf

 

http://en.wikipedia.org/wiki/Swiss_cheese_model

 

Non-provision of reminder device on the signaller’s panel and interlocking the protecting signal

Management and engineering error

Same as above

Signaller routes a train into the protection area in the absence of reminder appliance 

Operator error

There is no evidence available to author at the time of a  failed component of lock out system. However, there is evidence that a signaller can authorise a train driver to pass a signal at danger when a component of GSM-R system has failed. Logically these situations place the signaller under the same cognitive strain. Signaller is unaware of the actual scenes of train movements as the sites are away from line of sight. 

 

http://www.rssb.co.uk/Library/improving-industry-performance/2012-report-ncn5-issue-86-additional-report.pdf

Signalled train driver fails to stop ahead of the collision

 

Operator error

There is plenty evidence that such possibility exists because a train driver assumes the route ahead is clear for the train and will experience a nasty surprise to find it occupied. 

 

In conjunction with the earlier published Written Evidences presented, and the Staging process discussed hereafter and the two case studies presented within this submission, author concludes that proactive approach to system safety management Is lacking in the GB Railway Signalling Practices due to neglect of latent failures at engineering and management levels of the GB Railway Industry. GB Railway Industry blames front line staff or others for accidents that occur (Whittingham, 2004) (The BBC News, 12 August 2011).

Author had shown in 2010 that Decision Making Process used at RSSB Signalling Standards Committee is prone to Group-think bias (Appicharla, 2010). The question of hindsight bias does not arise in the studies of 1876 and hypothetical train worker accident(s) as all the information was available in 1876 and 2007. Prof James Reason’s Swiss Cheese Model helps to classify the available information into latent and active failures amongst the actors themselves. Latent failures can be practices driven by industry or firm’s culture together with the prevailing risk regulating culture.

 

4.3.3        Latent Errors in Safety Standards regulating Train-wheel Interface discovered in 2004 with unfortunate occurrence of Northern Line Train Accident

 

This case study was presented in the IET 2006 System Safety Conference Publication (Appicharla, 2006). The same model elicited errors in safety standards of London Transport. However, author is unable to present evidence online for comparison as London Transport has removed the case study from the Web for obvious reasons.

 

4.3.4        Latent Errors in Design and safety assurance of Command Control Signalling Systems

 

Getting the design right does not mean simply getting the signalling, p-way, electrification, s& t staff and operators to check each other designs to arrive at a common layout as Ian Ellis believes but it requires putting the initial as well as final design to a full scale review process of the hazards that may be involved in the concepts.

Instead of charting techniques used by computer scientists to elicit causes from accident investigation reports to identify biases inherent in the Report as per Nature’2003 article[54] author has found that application of Management Oversight and Risk Tree and/or Swiss Cheese Model enables author to overcome subjective biases in the accident report as well as engineering documents and enable learn right lessons from them on the presence or absence of latent failures (Appicharla, 2013). However, recipients of such Reports do not welcome such bad news is shared with the readers in his previous Written Evidences to the present Inquiry. Further, evidence from neuroscientists published in Nature 1999 article[55] suggest our language processing ability is more complex than usually thought and therefore, author finds charting techniques are more likely to be of help in processing information in a logical manner to avoid generating biased responses.

The UK HSE’s Safety Guidance 238 Out of Control document hosted on its Website discusses the specification and other errors that when corrected may prevent future failures of control systems[56]. Though, the document does not discuss the errors classifying them into latent and active errors but for the purpose of this Submission the intent of the UK HSE document is interpreted by the author as dealing with as systematic( management or engineering process ) errors as well as random hardware failures.

Now, let us consider three hypothetical decision makers ie Government, Industry and Regulator are trying to settle the question of ERTMS/ETCS Technology via the proposition of whether ERTMS/ETCS technology provides safety benefits equivalent to the combination of AWS/TPWS System?

Prior to constructing the decision matrix for the ERTMS/ETCS Technology, let us consider the example of Euclidean Geometry for the purpose of logical analysis.

Decision Maker

P is a right angled triangle

If P then Q

If P is right angled triangle then Q diagonals of quadrilateral are incommensurable

Q diagonals are incommensurable so sides of quadrilateral are equal 

Sage Pythagoras

True

True

True

Philosopher Aristotle

True

True

True

Scientist Sir Issac Newton

True

True

True

Nobel Laureate Albert Einstein

True

True

False

Decision

True

True

True

Table 4: Decision Matrix on Euclidean Geometry

The Decision matric based upon the foregoing ERTMS/ETCS Technology decision situation emerges as follows.

Decision Maker

P,  ERTMS/ETCS provides safety

If P then Q

ERTMS/ETCS provides safety then TPWS can be decommissioned

Q, AWS/TPWS can be decommissioned

Government

True

True

True

Risk Regulator

False

True

False

Industry

True

False

True

Decision

True

True

True

Table 5: ERTMS/ETCS Decision Scenario

Assumptions in the above hypothetical scenarios are as follows:

a)      Risk regulator is aware of the issues connected with ERTMS/ETCS Technology but has to integrate safety and economic concerns.

b)      Industry seeks introduction of digital technology to lower costs and provide enhanced performance to its clients, and

c)       Government seeks to lower the cost and enhance train travel to meet the challenges of Climate Change and assumes it is duty –holders who are better placed to take decisions on risks they pose to the society

The above decision scenarios do indicate the fact that conflicts between decision criteria of cost, safety, performance and varying interests of the groups involved in the decision making scenario may lead to unsafe choice for the passengers and customers. But RSSB/RAIB as well as RU/IM managements think that it is the duty of Government and regulator to take care of risks to public. So, in the words of Noble Laureate Albert Einstein we have run into a logical circle.

20th century Philosopher Alfred North Whitehead observed that judgements are made with conscious awareness and 19th century philosopher Arthur Schopenhauer observed that subject and object of knowledge is one (Whitehead, 1927/1978), (Schopenhauer, 1813/2006). In other words, errors in judgements may arise due to theory induced blindness as argued by Nobel Laureate Daniel Kahneman (Kahneman, 2011).

Neither conventional safety management systems nor Common Safety Method of regulating risk can handle the cases of cognitive errors as these may be rationalised to be behaviour problems of the front line staff (Hayes, 1994), (Gopnik & Schulz, 2007), (Daniels & Henry, 1998), (Hall, 2010), (Hall.S & Mark, 2008), (Kahneman, 2011).

The only way to escape the logical circle is to pay attention to latent failures of understanding and making changes to the incomplete designs of ERTMS/ETCS Technology to be applied to the conventional railway lines.

Conclusion: Comparison of the above decision scenario with that of 1876 and 2005 scenarios reveals to the author that computation of harm or benefit to the society demands elicitation of cognitive errors involved in the process of assessing technology.

Whether 13 people lose their lives or a single person loses life is immaterial when the examination of designs (conceptual and logical designs) reveals latent errors inherent in them. Author had disclosed several latent errors in the level crossing designs to the Inquiry on Safety at Level Crossings where the GB railway industry professionals from RSSB/RAIB/ORR/RU and IM Managements falsely believe that road user knows the decision point from where a decision to cross the railway line safely is to be made. Nor the road user has line of sight of the train movement in several cases of accidents. Given these two premises the question of road user being responsible for level crossing accidents does not arise.

5         Denial Culture

 

It is important to bring to the attention of the UK 2010 Chair and Members of House of Commons Transport Select Committee that author, as an employees of RSSB, was set twin objectives amongst others to develop safety requirements at the duty-holders organisational interface in 2009 for the Cambrian ERTMS Programme and conduct safety analysis on the interlocking standard. Readers are requested to note that ERTMS/ETCS technology along with interlocking system for Level 2 Radio based configuration are safety critical systems and therefore, analyst has to take into account the role of latent errors and active errors through the methodology of system definition, identification of hazard and hazard analysis to assess the safety risk when setting out the safety requirements.

However, when the author had described the work that is needed to be done to deliver the twin objectives by taking into economic, social and technical perspectives, the manager of New System Department responded in March 2010 that such work has not been funded by client, Cambrian ERTMS Programme, and he found that the level of work being carried out by author and the practical requirements of the Cambrian ERTMS Programme are not consistent and therefore, there is a need to improve effectiveness in author’s work.  Author was transferred back to the CCS Department in April 2010 and was told immediately that there was no need for any Systems Engineer. After three months period in June 2010 author was made redundant after consultations by citing that there was no need for systems engineer. Author had shared the RSSB’s Director Letter in his previous Written Submission (Jack, 18th May 2010).

When meeting author prior to writing the letter, Mr Anson Jack, did say verbally that he did not have any objection to the SIRI Methodology if the Government encouraged such process methodology. Author is not aware of Director’s intention but infers that RSSB Director did find the methodology useful but was constrained by the industry culture and therefore, made such a remark. Author confesses that in June 2010 he was unaware of the fact that UK House of Commons Transport Select Committee had existed and that author could make a Written Submission seeking its approval.

The National Audit Office in 2007 when inquiring into the West Coast Main Line Route Modernisation noted in its case study I in Appendix Three and case study 14 in Appendix Five that Network Rail faced risk with computer based interlocking and ERTMS/ETCS technologies from being innovative technologies as they are safety critical systems. ERTMS/ETCS technology was removed from the WCML Project and transferred to the National ERTMS Project in 2003(National Audit Office, 2006). UIC, an international organisation with 202 members has noted in its website information in April 2013 that it started a European Interlocking project in 1999 and it is necessary to build a specification. The question naturally arises if the UIC is still developing the interlocking specification for the radio based ERTMS/ETCS Technology then author is unclear as to how the HLOS in 2007 deemed that ERTMS/ETCS Technology is ready for implementation? (Department of Transport, 2007).

However, the changes in the way the GB Railway risk regulating regime has changed from Railways Safety Case Regulations to ROTS to Common Safety Method and the errors they induce is not recognised by system safety engineering professionals or by the Directors of RSSB.  The peer review committee of the IET System Safety 2007 Conference made the following comment on author ‘submission that the SIRI Methodology is to be described in six pages and the description is very abstract and high level difficult to understand without background on SIRI. The paper should give concise application of the concept instead of too much theory, frameworks, and processes. Pros and cons should be clearly pointed out w.r.t to current technology (IET System Safety Conference 2007, 2007). Dr Jeff Allan, Head of CCS and ENE Department and the Director of Standards and Technical Services, Andrew Sharpe informed Helen Goodman, Director of Business Service in 2010 that there is no need for Systems Engineer post in the CCS or New Systems Department when author appealed against his role of systems engineer being made unfair selection for redundancy when there is need for a systems engineer under the changes are being made to HSE regulations.

In 2010, RSSB like the IET System Safety Conference Rail Group Experts in 2007 were clear that they will be in a position to apply the Yellow Book as Guide for Engineering Safety Management and hence, there is no need for change (Helen Goodman, June 2010).  Readers will note that it has come to author’s attention that RSSB has changed its mind and advertised for Systems Engineer as well as System Safety Engineer[57],[58] in recent times.

Due to the anchoring bias of train paths per hour at the middle level of railway management and at these levels they do not comprehend the dangers from the application of the Yellow Book and the due to lack of awareness of latent errors at the senior level of railway management and the conjunction of these factors with author’s own lack of judgment of social resistance to latent errors, author has found himself in a very strange situation that lesser qualified professionals are able to find work in Crossrail, HS2 and other Network Rail projects.

These projects suffer from repeated mistakes of cost and time overruns is no surprise to the author. Author had shared the similar ideas on the failures of system analysis with the Digital Skills Committee which they have kindly published (The UK House of Lords Select Committee, October 2014).

 

6         Conclusions

 

The issue of cost and time overruns in the large programme were discussed in the context of latent and active errors committed by stakeholders. The investment into the railways made at the planning stage ignores the risk inherent in the design and operations of the railway technology. These latent errors surface at a later time prompting intervention from the Government in the form of Legislations.  The Railways Act promulgated in 1889, 1994, 1999 to enhance safety of the passengers establish a pattern of reactive approach to safety by the GB Railway Industry as well as the Government.

There is a need to establish the behaviour of technology at the outset to prevent loss of precious lives as well as investment. Author demonstrated how the narratives in the accident reports or the safety standards can be used to elicit latent and active errors.

Author appeals to the Chair and Members of the Transport Select Committee to endorse the approach taken in the paper to help stem the rising costs and risk  inherent in the design of signalling and other systems. 

November 2014

7         References

 

2010 UK Parliament Transport Select Committee, 7 th March 2014. Safety at Level Crossings, London: UK Parliament .

Allen, G. F., 1982. Railways, Past, Present & Future. London: Orbis Publishing Ltd.

Appicharla, S., 2006. System for Investigation of Railway Interfaces. London, Institution of Engineering and Technology, pp. pp.7-16.

Appicharla, S., 2009. SIRI Analysis of risk Associated with Level crossing operations of ABCL Type, London: Unpublished RSSB Report.

Appicharla, S., 2010. System for Investigation of Railway Interfaces. Manchester, Institution of Engineering and Technology, p. 6.

Appicharla, S., 2011. Analysis and modelling of the Herefordshire Accident using MORT Method. Birmingham, Institution of Engineering and Technology, p. 10.

Appicharla, S., 2012. Analysis and Modelling of NASA Space Shuttle Challenger Accident Using Management and Oversight Risk Tree. Edinburgh, IET, p. 8.

Appicharla, S., 2013. Technical Review of Common Safety Method using System for Investigating Railway Interfaces( SIRI) Methodology, Cardiff: IET International System Safety Conference 2013.

Appicharla, S., 2014. Written Evidence from Sanjeev Kumar Appicharla (IRW0059). [Online]
Available at: http://data.parliament.uk/writtenevidence/committeeevidence.svc/evidencedocument/transport-committee/investing-in-the-railway/written/13649.pdf
[Accessed 5th November 2014].

Appicharla, S., April 1999. Alstom Cegelec India. Noidal, Delhi: Private Fax Message.

Appicharla, S. K., 2010. Response to the Consultation on Level Crossings , UK Law Commission , London: Unpublished draft.

Appicharla, S. K., 2013. Analysis and Modelling of the Fukushima Nuclear Accident 2011 using System for Investigation of Railway Interfaces, Cardiff: Eigth IET International System Safety Conference.

Audi, R., 1998. Epistemlogy. 2002 ed. London: Routledge.

Baker, B. S., 1964. Human Capital. London: The University of Chicago Press.

Bearfield, G., 2009. “Taking Safe Decisions, Railway Industry ALARP Guidance”. Newcastle : The Safety Critical Systems Club Newsletter.

Buchanan, D. A. H., 1985. Organisational Behaviour, an introductory text. Hemel Hampstead: Prentice Hall, Europe.

Clifton, E. I. .. A., 2005. Hazard Analysis Techniques for System Safety. New Jersey: Wiley& Sons.

Daniel Goleman, R. B. A. M., 2002. The New Leaders, London: Little Brown.

Daniel Kahneman, D. L. O. S., June 2011. The Big Idea: Before You Make That Big Decision, Boston: Harvard Business Review .

Daniels, K. & Henry, J., 1998. Strategy Reader: A Cognitive Perspective. 2nd Edition ed. Oxford: Blackell Publishers.

Department of Transport, 2007. Delivering a Sustainable Railway, London: The UK Government.

E.F.Schumacher, 1974/1990. Small is Beautiful. Indian ed. Calcutta : Rupa & Co.

Einstein, A., 1920. Relativity. London: Routledge.

Ekekwe, N., 2011. Better Risk Communication. [Online]
Available at: http://blogs.hbr.org/cs/2011/05/better_risk_communication.html
[Accessed 29 September 2011].

Eliade, M., 1963. Myth and Reality. New York: Harper Torch Books.

G.J.Bearfield; R.Short, 2011. Standardising Safety Engineering Approaches in the UK Railway. Birmingham, The Institution of Engineering and Technology, p. 5.

Gibson, J., 1986. The Ecological Approach to Visual Perception. New Jersey: Lawrence Erlbaum Association.

Gopnik, A. & Schulz, L., 2007. Causal Learning, Psychology, Philosophy, Computation. New York: Oxford Unvisersity Press.

Haddon-Cave, S. C., 2009. The NIMROD Review, London: Her Majesty Stationary Office.

Hall.S & Mark, P. V. D., 2008. Level Crossings. Hersham: Ian Allan Publishing.

Hall, S., 1990. Railway Detectives. London : Ian Hall.

Hall, S., 2010. Modern Signalling Handbook. Surrey: Ian Hall Publishing Limited.

Hansson, S. O., 1994. Decision Theory, Stockholm: Royal Institute of Technology ( KTH) .

Hansson, S. O., 2011. Risk, The Stanford Encyclopedia of Philosophy (Winter 2012 Edition). [Online]
Available at: http://plato.stanford.edu/entries/risk/
[Accessed 03 Jan 2014].

Hawking, S., 2005. A briefer History of Time. London: Transworld Publishers.

Hayes, N., 1994. Understand Psychology. 2010 ed. London: The McGraw Hill Publishers.

Helen Goodman, June 2010. Appeal Against Unfair Selection for redundancy, London: RSSB.

Hubbard, D. W., 2009. The Failure of Risk Management. First ed. New Jersey : John Wiley& Sons .

IEEE, 1998. Guide for Developing System Requirement Specifications. 1998 ed. New York: IEEE, New York .

IET System Safety Conference 2007, 2007. Peer Review Comments, London: s.n.

J.Fabrcky, W. & S.Blanchard, B., 2005. Systems Engineering and Analysis. s.l.:Prentice Hall.

Jack, A., 18th May 2010. Defence of RSSB'S Function , London: RSSB .

Kahneman, D., 2011. Thinking Fast and Slow. London: Penguin Group .

Kock, F. C. a. C., 1998. Consciousness and Neuro-science. Cerebral Cortex, 8(3), pp. 97-107.

Krogerus, M. & Tschappeler, R., 2011. Decision Book. London: Profile Books Limited.

Leveson, N., 2003. A New Accident Model for Engineering Safer Systems. Safety Science 42, pp. 237-230.

M.Copi, I. & Cohen, C., 1998. Introduction to Logic. New Delhi: Pearson Education.

National Audit Office , 2010. Increasing passenger rail capacity HC 33, London : National Audit Office .

National Audit Office , 28 March 2012. The completion and sale of High Speed 1 HC 1834, London : National Audit Office .

National Audit Office, 2006. The Modernisation of the West Coast Main Line HC 33, London: The UK House of Commons .

National Audit Office, 2013. Over-optimisn in Government Projects, London: National Audit Office.

Nikhilananda, S., 1944. The Bhagavad Gita. New York: Ramakrishna-Vivekananda Center.

Penrose, S. R., 2004. The Road to Reality. London: Jonathan Cape.

Perrow, C., 1984/1999. Normal Accidents. 1999 ed. New Jersey: Princeton University Press.

Petroski, H., 1992. To Engineer is Human. New York: Vintage Books.

Plato, 375 BC/1955. The Republic. London: Penguin Books.

Prabhupada, H. D. G. A. B. S., 1997. The Quest for Enlightenment. Borehamwood: International Society for Krishna Consciouness.

Rao, P. M. S., 7th July 1983. Certificate, Mangalore: Karnatake Regional Engineering College Surathkal.

Rasmussen, J., Pejtersen, A. M. & Goodstein, L. P., 1994. Cognitive Systems Engineering. First Edition ed. New York: John Wiley& Sons, Inc.

Reason, J., 1990. Human Error. 17th ed. New York: Cambridge University Press.

Russell, B., 1945. The History of Western Philosophy, New York: Simon Schuster.

Schopenhauer, A., 1813/2006. On the Principle of Sufficient Reason. New York: Prometheus Books.

Schrödinger, E., 1944. What is Life. [Online]
Available at: http://whatislife.stanford.edu/LoCo_files/What-is-Life.pdf
[Accessed 05 11 2012].

Sen, A., 1998. Choice, The Possibility of Social. [Online]
Available at: http://www.nobelprize.org/nobel_prizes/economic-sciences/laureates/1998/sen-lecture.pdf
[Accessed 10 11 2014].

Sibony, D. L. O., March 2010. The Case for Behavorial Strategy , New York: McKinsey&Company.

Simon, H., 1972. Theories of Bounded Rationality. In: Decision and Organisation . s.l.:North Holland Publishing Company , pp. 161-176.

The Concise Encyclopedia of Economics, 2008. Kenneth Arrow. [Online]
Available at: http://www.econlib.org/library/Enc/bios/Arrow.html
[Accessed 12 11 2014].

The National Diet of Japan, 2012. Fukushiman Nuclear Accident Investigation Commission. [Online]
Available at: http://warp.da.ndl.go.jp/info:ndljp/pid/3856371/naiic.go.jp/en/
[Accessed 2013 July 2013].

The UK House of Lords Select Committee, October 2014. Digital Skills Committe -Oral and Written Evidence, London: UK Parliament.

TTAC Limited, 2012. ORR Health and safety strategy. [Online]
Available at: http://www.rail-reg.gov.uk/server/show/nav.1243
[Accessed 30 October 2012].

Undisclosed , November 2006. Email Correspondence regading Thames Link Principle Desing Engineer Job Specification , London : s.n.

Valerie, R., 2003. The Upanisads. London: Penguin Books.

Whitehead, A. N., 1927/1978. Process and Reality. 1985 ed. New York: The First Free Press.

Winter, P., 2009. Compendium on ERTMS. Hamburg: DVV Media Group GmbH.

 


[1] http://data.parliament.uk/writtenevidence/committeeevidence.svc/evidencedocument/transport-committee/investing-in-the-railway/written/14219.pdf

[2] http://data.parliament.uk/writtenevidence/committeeevidence.svc/evidencedocument/transport-committee/investing-in-the-railway/written/13649.pdf

[3] http://www.parliamentlive.tv/Main/Player.aspx?meetingId=16431

[4] http://data.parliament.uk/writtenevidence/committeeevidence.svc/evidencedocument/public-accounts-committee/procuring-new-trains/oral/14576.pdf

[5] http://orr.gov.uk/__data/assets/pdf_file/0020/2567/rogs-guidance.pdf

[6] http://tv.theiet.org/technology/transport/999.cfm

[7] http://pespmc1.vub.ac.be/asc/cybernetics.html

[8]

[9] http://www.theguardian.com/business/2004/sep/03/obituaries.guardianobituaries

[10] http://www.mckinsey.com/client_service/risk/latest_thinking/working_papers_on_risk

[11] http://www.parliament.uk/documents/lords-committees/digital-skills/Digital-Skills-Committee-Evidence.pdf

[12] http://www.ncbi.nlm.nih.gov/pmc/articles/PMC1117770/

[13] http://en.wikipedia.org/wiki/System_safety

[14] http://psas.scripts.mit.edu/home/

[15] http://www.cancerresearchuk.org/cancer-info/cancerstats/mortality/uk-cancer-mortality-statistics

[16] http://en.wikipedia.org/wiki/Bayesian_game

[17] http://en.wikipedia.org/wiki/Bayesian_game

[18] http://plato.stanford.edu/entries/risk/

[19] http://orr.gov.uk/what-and-how-we-regulate/health-and-safety/guidance-and-research/infrastructure-safety/train-protection/ertms

[20] http://www.rgsonline.co.uk/Railway_Group_Standards/Control%20Command%20and%20Signalling/Guidance%20Notes/GEGN8641%20Iss%201.pdf 

[21] http://www.iec.ch/functionalsafety/faq-ed2/page1.htm

[22] http://www.iec.ch/functionalsafety/faq-ed2/page6.htm

[23] http://www.hse.gov.uk/research/rrpdf/rr067.pdf

[24] http://en.wikipedia.org/wiki/Systems_engineering

[25] http://www.computer.org/portal/documents/82129/160549/IEEE+29148-2011.pdf

[26] http://repository.cmu.edu/cgi/viewcontent.cgi?article=1012&context=theses

[27] http://en.wikipedia.org/wiki/Form_of_the_Good

[28] http://www.hse.gov.uk/research/othpdf/500-599/oth521.pdf

[29] http://plato.stanford.edu/entries/capability-approach/

[30] http://www.acorp.uk.com/

[31] http://en.wikipedia.org/wiki/Nuclear_and_radiation_accidents_and_incidents 

[32] http://www.onr.org.uk/tagsrevision.htm

[33] http://www.world-nuclear.org/info/Safety-and-Security/Safety-of-Plants/Fukushima-Accident/

[34] http://www.rssb.co.uk/Library/risk-analysis-and-safety-reporting/2011-report-fukushima-operational-feedback-update.pdf

[35] http://www.rssb.co.uk/Library/risk-analysis-and-safety-reporting/2014-guidance-taking-safe-decisions.pdf

[36] http://www.rssb.co.uk/Library/risk-analysis-and-safety-reporting/2014-guidance-taking-safe-decisions.pdf

[37] http://mydocs.epri.com/docs/CorporateDocuments/SectorPages/Portfolio/Nuclear/Safety_and_Operational_Benefits_1016308.pdf

[38] http://en.wikipedia.org/wiki/Core_damage_frequency

[39] http://www.hq.nasa.gov/office/codeq/doctree/NASA_SP2010576.pdf

[40] http://uk.reuters.com/article/2014/08/31/uk-japan-nuclear-resentment-idUKKBN0GV02W20140831

[41] http://www.hse.gov.uk/consult/disdocs/railwaydd.pdf

[42] http://ec.europa.eu/transport/modes/rail/events/doc/ppt_presentations/uk_rail_safety_and_supervision.pdf

[43] http://www.raib.gov.uk/cms_resources.cfm?file=/141027_AR2013_Section_1.pdf

[44] http://www.era.europa.eu/Core-Activities/ERTMS/Pages/home.aspx 

[45] http://ertmsonline.com/wp-content/uploads/2014/06/ETCS-The-future-of-signaling-is-here_Brochure.pdf

[46] https://www.ucl.ac.uk/resilience-research/research/railwaysignal/UCLWorkshop19Jun2013RSSB

[47]

https://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web&cd=2&cad=rja&uact=8&ved=0CDUQFjAB&url=http%3A%2F%2Frepository.tudelft.nl%2Fassets%2Fuuid%3A433a0dd7-c2fd-4b14-a2eb-f02e5862bf13%2FMTS_123973590776790665%5B1%5D.pdf&ei=27FnVJuMDvGZsQTUoILICQ&usg=AFQjCNFvkrZ05kqVyMkllRHzzy7THJP6Xg&sig2=Hcvm7OEp55GFyLTvXkqixA&bvm=bv.79142246,d.cWc

[48] http://data.parliament.uk/writtenevidence/committeeevidence.svc/evidencedocument/transport-committee/investing-in-the-railway/written/14219.pdf

[49] http://www.iainellis.com/devil.pdf

[50] http://www.railsigns.uk/sect2page1/sect2page1.html

[51] http://www.legislation.gov.uk/ukpga/1889/57/pdfs/ukpga_18890057_en.pdf

[52] http://webarchive.nationalarchives.gov.uk/20131001175041/http://www.rail-reg.gov.uk/upload/pdf/rsp3-smot-210507.pdf

[53] http://www.rgsonline.co.uk/Railway_Group_Standards/Control%20Command%20and%20Signalling/Railway%20Group%20Standards/GKRT0212%20Iss%201.pdf

[54] http://www.nature.com/news/2003/030815/full/news030811-9.html

[55] http://www.nature.com/news/1999/991118/full/news991118-2.html

[56] http://www.hse.gov.uk/pubns/books/hsg238.htm

[57] https://www.linkedin.com/jobs2/view/19049712

[58] http://www.rssb.co.uk/Library/about-rssb/2014-09-vacancy-system-safety-engineer.pdf