Written evidence submitted by Sanjeev Kumar Appicharla (RTC0010)
I write in response to the 2016 Transport Select Committee Inquiry into Railway Technology inviting comments on the ERTMS-ETCS Signalling Technology and associated issues.
At the outset, I wish to thank the Hon. Chair and Members of Parliament for the occasion to contribute to the Inquiry.
My past Evidences published during October –December 2014, IRW 0059,, IRW 0060, IRW 0064 dated 2014, IRW 0065, IRW 0066, and IRW 0070 by the Inquiry on the Railway Investments had drawn attention to the facts of lack of cognitive competence at the knowledge based behaviour level on the part of decision makers in the Railways in dealing with complex systems. I thank the Hon. Chair and Members for publishing these Evidences.
What author has found in the intervening fifteen months period is that my published Evidences stated those heuristics that are under use and how they may lead to failures. The failures cannot be simply coincidences because decision process used to expect the failures was stated in the paper. The question of when these failures were to be expected was not stated. Author’s work experience and engagement with the organisations had informed his judgements.
Some of the content in the paper may be sound repetitive; I kindly request the Hon. Chair and Members to bear with discussions in the context of ERTMS-ETCS technology. In December 2014, I did not anticipate that there will be another Inquiry in fifteen months’ time and raised alarms in 2014 over the fate of many ERTMS-ETCS Programmes which suffer from common mode of failures.
The Submission provides a solution to some of the Questions raised on the ERTMS-ETCS Technology and provides additional information to inform the judgements of the Chair and Members on the significant issues of application of micro-processor based technology to railway traffic management, train control and protection systems as well.
The references are cited in the footnotes and where not cited in the paper can be found in the research papers appended to.
Our great defect is that we are so much drawn to the idea, the goal is much more enchanting, so much more alluring, so much bigger in our mental horizon, that we lose sight of the details altogether
-Swami Vivek-ananda, Indian monk, Los Angeles, California, January 4, 1900
In the professional opinion of the author, the discussion on the assurance of complex ERTMS-ETCS technology and GSM-R communication system by way of “design and engineering capability” and “technical know-how” after a decade and half of Sir David Davies February 2002 Report and twenty six years after Sir Anthony Hidden November 1989 Report remain still valid.
The reason for asserting the relevance and validity is that the quality of managerial problem solving and decision making as experienced within the domain assessed against behavioural decision (BDT), bounded rational manager (BRM) and engineering manager theories (EMT) suggests the idea that a systematic review of the standard life –cycle processes assumed in the mental models by reviewers for regulating the design and development of large complex systems should be under-taken.
During the early days of Sir David Davies Report, who implicitly subscribed to the EMT, we find discussions in a brief manner, on the role of human error in the design and engineering of the Automatic Train Protection system.
The concepts of applying Systems Engineering Strategies were not mature at that time. If we go by these early reports, by 2016, the idea of automatic train protection was to be done and dusted thing and GB Railways have entered in the post ERTMS-ETCS state. As this is not the current reality, there arises a need for reflection. Optimism fallacy advanced by cognitive psychologists and behavioural decision theorists provides answer to the dilemma.
In 2003, Mr. R. I Muttram, Chief Executive, Railway Safety and Mr Richard Bowker, Chairman, Strategic Rail Authority had thought there were three main reasons for the implementation of the ERTMS-ETCS.
First, Safety Objective: it is a means to provide the Automatic Train Protection to reduce the incidence and consequences of SPADs to comply with the requirement of Lord Cullen Inquiry.
Second, Inter-operability Objective: it enables trains to operate safely and effectively with control system supplied in part or whole by different companies resulting in greater mobility for trains across Europe.
Third, Capacity and Performance: to increase capacity particularly at bottlenecks, facilitate enhanced train performance and help support the 40% to 50% traffic growth envisages by 2010.
In terms of traffic light system, the demand function has turned to Green whereas the supply side function has turned to red.
Prof Jens Rasmussen would be surprised to learn that Chief Executive of Railway Safety who desired in 2000 that Railway Group’s Safety Plan should aim for the total absence of accidents, caused by factors within the control of Railway Group Members to gain the lost reputation of the Railway Industry, did not foresee that dysfunctional interactions of complex systems and side –effect s of good intentions may have unforeseen effects.
Lack of managerial oversight as a rick contributor is not seen in the Bow tie models of Network Rail and RSSB. In terms of communication protocol, and Artificial Intelligence languages, there is a greater difficulty in assessing performance mis-matches despite the greater exposure and availability of information about the research carried out in the defence sector. In the traditional human –technology interfaces, the human failings in the tasks could be ascertained from comparison of the role task specification found in the operating procedure derived from the requirements and functions of the equipment with which the human operator interfaced with. Or the designer of the equipment could be consulted with.
However, some larger failures programmes such as the Air Traffic Control ( ATC) Systems (latent errors in programmes and de-bugging activity takes 24 to 30 hours to sort the problem) or failings in the Eurostar Power Supply System leading to train cancellation every Christmas or holiday times may be statistically shown to be rare events, However, these failings have their origins in the design specifications ( in the case of software performance issues like the ATC failure that can be repaired ) or Eurostar failings ( in the case of power system failings the re-design cannot be worked out as the cost of re-fitting the electrification hardware and rolling stocking power devices all together may be costly and time consuming. If the case involves the safety incidents, the problem is more acute as the recommendations take 20 or more years to satisfy the safety specifications originating from the accident investigations.
The main point of discussion is that when we think about the safety standards, managerial behaviour and risk issues at the conceptual planning level, the available funds and time are more than the resources at a later stage and the acute sensitivity desired of programme managers, and directors is not forthcoming.
In fact, author speculates that during the last five years or so, Network Rail has re-organised itself so much that we have engineers and managers who do not know what RSSB does and what role does it play in the strategy of conflicting objectives between the railway undertakings and infrastructure managers.
Most of the sloganeering and championing of Design for Safety Concepts fall on deaf ears of most project managers (most of them do not have engineering degree), signalling programme managers and directors ( most of them with civil engineering degrees or experience without any power or control systems design experience) are leading the activity of introducing ERTMS-ETCS activity.
In 2003-4, the ERTMS Programme Board lacked understanding of what do the concepts of railway safety, capacity, and inter-operability meant. This assertion is explained by means of Prof Jens Rasmussen’s Abstract Hierarchy Framework.
Abstract Hierarchy Element | Railway Line Side Signalling System | Train driver |
Goal: purpose |
| Drive train safely as per the route knowledge and signalling commands; be vigilant to distractions; shift mental model upon taking charge of train driving |
Abstract function: information processing | Specify system model: detect train movements, status of infrastructure for the train movement, ascertain and check routes ahead and rear are clear, generate, verify, transmit and distribute movement authorities, select relevant mode of operation | Process information from the line-side signalling aspects, ground level posts, track worker, signaller, acknowledge warnings, seek movement authority, report irregularities , prepare train, perform safety checks, stable the train
|
Generalised functions: psychological mechanism: Cognitive, affective | System functional model: Obtain data from the time table, and sensors, identify the demands, map or relate the information, check against control conditions, compare the output conditions, signal clarity and states of equipment
| Drive according to the signal temporal aspects, and route knowledge. Recall rule conditions if the situation is not clear, plan for next state on the dynamic move, |
Physical functions: physiological functions | Equipment specifications for design, installation, testing and commissioning | Locate the physical device needed, operate the device , initiate start, coast, stopping patterns of movement |
Physical forms: anatomical structure | Flags, signal lamp posts , gantries, signs, track sensors, point mechanism etc | Power throttle, brake pedal, dead man handle, AWS buttons |
Figure 1: Example of showing Means-End Abstract Hierarchy with traffic light system for current goal-state
Figure I and II may be compared to learn about the differences in line side signalling and cab signalling principles at the higher levels.
Abstract Hierarchy Element | Railway Cab Signalling System | Train driver |
Goal: purpose |
| Drive train safely as per the route knowledge and signalling commands; be vigilant to distractions; shift mental model upon taking charge of train driving |
Abstract function: information processing | Specify system model: detect train movements: status of infrastructure for the train movement, ascertain and check routes ahead and rear are clear, generate, verify, transmit and distribute movement authorities, select relevant mode of operation | Process information from the line-side signalling aspects, ground level posts, track worker, signaller, acknowledge warnings, seek movement authority, report irregularities , prepare train, perform safety checks, stable the train
|
Generalised functions: psychological mechanism: Cognitive, affective | System functional model: Obtain data from the time table, and sensors, identify the demands, map or relate the information, check against control conditions, compare the output conditions, signal clarity and states of equipment |
|
Physical functions: physiological functions | Equipment specifications for design, installation, testing and commissioning | Locate the physical device needed, operate the device , initiate start, coast, stopping patterns of movement |
Physical forms: anatomical structure | Flags, signal lamp posts , gantries, signs, track sensors, point mechanism, GSM-R etc | Power throttle, brake pedal, dead man handle, AWS buttons |
Figure 2: Example of showing Means-End Abstract Hierarchy with traffic light system for current goal-state
The basis for the above traffic light classification is provided within the Report and attached research papers.
During the last decade and half, errors in the strategic choices of a) technology (from know what sub-systems it is composed of –capabilities); b) management process (know why of activity with its goals; and c) and know –how (psycho-social assumptions about –work system) with long-term consequences of the errors with their impact on the skills-knowledge, role of management types, productivity, profitability, employment levels etc. as final variables have emerged into both public and policy decision maker’s consciousness.
In 2005, author found himself, faced with a request to provide for formal Systems Engineering Methodology inputs to the railway signalling, communication, electrical and operators experience base, as a means to comprehend the interfaces between duty-holder organisations, from product perspective. Author researched the works of Prof Jens Rasmussen and Prof James Reason on the theme of Human error and furnished a system analysis process to analyse the interfaces into work of Railway Group Standards and a safety analysis process to show how the decisions made by the standards committee’s impact the future work system. The type of work systems may be completely automated; joint work system of computer and human operator; completely manual work system can be analysed using the Unified Scheme (Appendix I).
In 2005, the Professional Head of Control-Command –Signalling Engineering and a Lead Signalling Engineer at RSSB expressed doubts on whether the existing controls in the Railway Group Standards facilitated measures at the duty-holder organisation interfaces for safe interworking or not?.
The results for railway signalling safety studies chaired by author as a HAZOP Chair showed that the measures were less- the -adequate and practices need changing but management of RSSB Standard Directorate thought otherwise. The Professional Head of Control-Command-Signalling and the Lead Signalling Engineer who were not familiar with the process of risk assessment and concepts of Hazop process who made the original request thought that signalling engineers should not worry about how potential accident arise due to human error on the part of signalling engineers or those who draft the standards on technology, operating rules and regulations. The Technical Director thought the paradigm of Railtrack engineering management process called Yellow Book and practices of fault and event tree analysis suffice. No one reflected on the question: if Yellow Book as a Managerial Process and Techniques of Fault and event tree analysis should suffice for decision making then why the uneasy feeling of doubts over the Railway Group Standard arises? The same question arises with respect to Six Sigma Management Practice as well.
Similar feelings on management of standards were expressed by Rt. Hon Lord Cullen[1] (paragraphs 3.49 to 3.55 and Chapter 6) during the Ladbroke Grove Inquiry. The Report observes, “The system for the management of safety within the rail industry is dependent on the setting of, and compliance with, Railway Group Standards, and safety assurance based on auditing, together with the investigation of accidents and incidents and the taking of any necessary remedial action.
Railway Group Standards have their origin in the rules developed by British Railways for the discharge of their responsibilities. They should be distinguished from the more detailed Line Standards which are set by Railtrack Line for the purpose of achieving their own compliance with Railway Group Standards. Compliance with the Railway Group Standards is part of Network Licence Conditions. Railway Group Standards are mandatory for members of the Railway Group, although the Safety Case Regulations do not require the duty holder to comply with them. However, in the case of the TOCs, compliance with them is regarded as mandatory under their track access agreements with Railtrack, as well as their operating licences.
The Figure III gives the examples of interfaces at a higher level between the ERTMS-ETCS development and Programme Team. This can be expanded to any detail level.
Abstract Hierarchy Element | ERTMS-ETCS Design and Development | Programme Director |
Goal: purpose |
|
|
Abstract function: information processing | Systems specifications: modelling, analysis, testing and sub-systems functional modelling. Pre-programming decision algorithms, check information flow |
System designers, requirements managers, application designers, system analysts, verifiers, validators, programme planners, auditors, supporting staff, contract negotiations, standards, specifications , resolving risks, etc |
Generalised functions: psychological mechanism: Cognitive, affective | Memory and register related functions for data storage, recall, registry handling, BITS | Project managers, sub-system specifiers, procurers, assemblers, testers |
Physical functions: physiological functions | Electrical, and programmable circuits | Project managers, sub-system specifiers, procurers, assemblers, testers |
Physical forms: anatomical structure | Input –output devices ( virtual or physical devices) , rolling stock, track space, control rooms | Project team members, element engg: procurement, market engineers, designers, specifiers, installers, testers and commissioning, safety and assurance staff and supporting staff |
Figure 3: Example of ERTMS-ETCS Design and Development showing Means-End Abstract Hierarchy
In the case of Railtrack, it is a condition of their network licence. As from 1 October 1996 membership of the Railway Group was confined, as a result of a decision of Railtrack, to companies holding an accepted safety case. It may be noted that Group Standards also apply to the FOCs, Eurostar (UK), Heathrow Express, Hull Trains and LUL. Group Standards are enforceable directly by the Rail Regulator, by reason of their being a condition of the licence granted by him. They may also be enforceable indirectly by the HSE as the safety regulator where compliance with them is undertaken under the safety case. They are not enforceable by either the Rail Regulator or the HSE against other companies which do not have an operator’s licence or a RSC. The general import of the memorandum of understanding between the Rail Regulator and the HSE is that the latter would normally be ready to take action in respect of the safety element of a Group Standard, whereas, to the extent that it is a matter of a purely economic nature, the Rail Regulator would expect to take responsibility for its enforcement. Such standards may also be imposed by a member of the Railway Group as a condition of contract with a non-member, for example by Railtrack in their contracts with contractors working on the infrastructure.”
The safety culture described in the foregoing graphs are supported by Prof B. M Hutter’s (2001) finding that aim of the safety legislations is to manage risk rather eliminate it.
The question arises in the context: are the Railway Groups Standards do adequately cover the technologies and assets and take a pro-active approach to risk rather rely upon reactive safety risk management stated in the Ladbroke Inquiry Report? The Chief Inspector of Railways in 2001 thought rationalisation of standards by the Railtrack Safety Directorate was a commendable job (Para 6.4 of Ladbroke Inquiry Report). The Chief Inspector of Railway Accidents Investigation Branch in 2012 did not think highly of decision making on standards (see attached Research Report April 2016 on the Cambrian ERTMS-Safety Incident). The standards for Vehicle Acceptance and Certification Bodies to the Rolling Stock Acceptance cover conditions for acceptance but the risk of running a test train remains. The French TGV train derailment in November 2015 reflects the insight of Prof Jens Rasmussen that test experiments do carry cost and cost of the de-bugging of faults in the pre-programmed decisions cannot be accepted in terms of eleven (11) lives.
The ERTMS-ETCS Technology has few defined interfaces (and several others open ) as mandatory requirements between train borne and track-side computing elements and the architecture has several open points despite its development history over the period of eighteen years giving rise to safety concerns. Likewise, choices in the GSM-R architecture need to be made. Unless these are sorted out, the debates at the engineering level will continue if even if legislative intervention is sought.
The quality of risk assessments and decision making processes were a concern in 2001 and this paper shows that there is no progress has been made even after an interval of fifteen years. Prof Jens Rasmussen (1994) observed that control by trial-and-error strategy is effective when past experience is relevant for future operations and the cost of experiments is less the value of lessons learned. However, this insight, it appears, does not apply in the case of the ORR Case Team[2] approach to handling Cases from Duty-holders seeking deviation to the 1999 Railway Regulations Act revealed in the latest ORR Decision Letter[3] issued to Network Rail on the failure of the Crossrail ERTMS-ETCS Plan A.
The nature of pitfall in the “problem solving” and “decision making “activity of the Industry and Regulatory Assessment Process is that investment and risk decisions rather than following the activity of risk analysis and risk assessments tend to precede them. In practice, managers take fallible decisions to recover from failure condition(s) and justify them through “backup “risk assessments. The ORR March 2016 Decision Letter and Supporting Documents are Evidences of the claim just made.
For the purposes of the Evidence, following definitions shall apply.
System: A “system” is a construct or collection of different elements that together produce results unobtainable by the elements alone. The elements or parts, can include people, hardware, software, facilities, policies and documents; that is: all things required to produce system level results. In essence, the definition of a system is that whole is more than sum of its parts.
Emergent properties: properties that arise between the observing and observed system. The interface between the observer (subject) and observed (object) may be causal or acausal depending upon whether the interface is empirical or ideal or considered transcendental. Unlike the rationalist approach of French philosopher, Rene Descartes who divided the whole (body into mind and matter) into two different substances, the approach followed by author is by considering the unity of Subject and Object first described by German philosopher, Arthur Schopenhauer in 1813. How this system of thought applies to the GB Railway Domain that emerged later is illustrated.
Emergent property of train driver interfacing with the track during the early railways days was the perception of the policeman’s flag to inform the course of action to be taken if emergency conditions obtained on the track. Train drivers were exposed to the dangers of boiler explosions, axle breakdowns etc in addition to the danger of train collisions and derailments. Train drivers learnt that they do need to run to common time-tables but it took around twenty five years to accomplish that. Subsequently, train driver(s) learnt to expect guard’s lamp to inform about the stranded train ahead on the track. After several accidents, train drivers expected to see semaphore signals being set for or against them. Nearly twenty five years were spent debating about the fail- safe design configuration of the upper-lower quadrant signals before the design settled down to the lower quadrant version. At some places, train drivers came across monster designs of twelve or more semaphore posts posing serious difficulty in locating the signal that applied to them. Inventions in technology led the train driver to see electric light system replace the semaphore signalling systems and driving in accordance with the meaning of colour shown on the ground with the status of the route ahead.
After few accidents, drivers were blamed for passing signals against danger called (SPAD) at some locations and at some other locations at the start of the station known as SASPAD, investigators, human factors practitioners[4] and HMRI Inspectors accused the train drivers of dis-regarding, mis-judging, dis-regarding, not being vigilant, mis-communicating the signal to signallers and other causal factors leading to accidents[5]. Competence of train drivers and their training methods were questioned.
When we conduct post –mortem analysis, we let our imagination free and it is not easy to apply thoughts into a systematic framework to ascertain the role of situational, states of safety devices, rules and regulations, risk policies, signalling principles, competence of signalling engineers, process of decision making and other factors to arrive at a judgement on the nature of interventions to be made. On the question of governance, the time interval for interventions varies. On a longer term, legislators adjust laws every X years to correct for experience problems and to reflect their political intentions. Regulatory case teams operate on the short interval of time, the interaction between the regulated and regulatory organisations is faced with cognitive bounds and complexity of their firm position in the industry; the executives need to resort to heuristics and this kind of simplification may lead to severe biases. Use of heuristics cannot be banned but their use must be recognised.
From this perspective, the solution that emerges in discussions over choice of technology by senior managers (See Lord Cullen Inquiry Part -2 Report) is that for implementation of automatic train control system to attain multiple objectives of capacity and safety to self-finance the investment (safety or not-safety investment). Under the social system thinking that discourages safety investment for the sake of improving safety, we arrived at the option of the system called for ERTMS-ETCS Signalling System. Those who argue at length that TPWS can be regarded as an effective system do not take into account the fact that TPWS can trap trained drivers when its internal circuitry develops a rare problem as indicated by train driver without over 20 years experiences has given evidence noted in the UK HSE document[6] ( pp. 38 of 40).
Under such a system, the emergent property of successful delivery of ERTMS-ETCS Signalling System is dependent upon the System Observer and there is no System Observer appointed by the ORR or and neither have the railway firms to accepted the idea of a System Observer. Previous Evidences and published research by author attached hereto demonstrates a Unified View is necessary to specify and implement complex systems. This view should be auditable and amenable to discovery of resident pathogens in management practices.
Perception of red signal or End of Movement authority on the Driver’s Man-Machine interface is an example of emergent property in this social system. Market failures or programme failures can be modelled by the Swiss Cheese and Management Oversight and Risk Model as well.
Swiss cheese Model: As per Prof Jens Rasmussen (1994), a human factors and decision research scientist, Prof James reason has described a consistent theory for empirical identification of a safe margin to loss of control, and of the threats against this margin in terms of “resident pathogens” in management practice, derived from the analysis of past incidents. The large number of errors, violations and latent conditions interacting in unique way produce an accident. In this empirical risk management, control is focussed on the quality of defences related to with reference to general failure types.
SIRI Management Oversight & Risk Tree ( MORT) : As per Prof Jens Rasmussen(1994), an human factors and decision research scientist, MORT is an analysis tool developed by William Johnson(1980), US National Safety Council, can be used to identify a large repertoire of “less –adequate-conditions” empirically by the use of large number of complex and causal trees included therein. Analytical risk management focusses on monitoring availability of defences with reference to design.
The Management Oversight & Risk Tree upgraded by the author, herein called SIRI MORT, contains branches related to the lifecycle of development programme, notations for definitions of the interfaces of assets, human operators, models for energy –barrier-target analysis, scenario description tools such as event-causal-flow –analysis to generate Normal Concepts of Operations and show how resident pathogens can generate accidents from the Normal Concepts of Operations.
The industry specific heuristics and biases are developed and are shown in the form of logical tree to show how and why the loss or failure event has occurred. The Management Oversight and Risk Tree observations can be used alongside numerical estimates of future risk derived from the application of Prof Jens Rasmussen’s model. The inputs from decision research to establish a “ Virtual Vigilant Decision Maker” in the form of Management Oversight and Swiss Cheese Model can be used to inform judgements of decision makers.
Active errors: active errors are human errors, whose effects are felt almost immediately. For example, active error on the part of unaware road user who may enter a level crossing space when it is not safe to do so as in the case of the Herefordshire level crossing accident in 2011. This is possible if the road driver is located ahead of the signal post behind the barriers. These definitions are as per the UK HSE publications on Human Error.
Latent errors: Latent errors are human errors whose adverse consequences may lie dormant within the system for a long time, only becoming evident when they combine with other active factors to breach system (production) defences. For example, action of the signaller who raised the barrier needed a conjunction of events of a train and a road user entering the crossing space simultaneously to manifest the Herefordshire level crossing accident in 2011. However, the signaller is not root cause for the latent error will be realised as soon the failure to provide approach locking is found to be a decision made the project team earlier. The decision not to provide for approach locking based on the cost-benefit analysis in the renewal project is the final decision error.
These types of errors can be classed as latent or violations depending upon whether a Best Practice is available or not.
Violations: Non-compliance with the best practice or safety rules. This category of error is not solely limited to front –workers or middle management level. Author includes these into the latent error category as the effect of violation will come to the fore of public knowledge later.
For example, relying the area of Frequency of accident category and number of fatalities drawn on log-log graph for societal risk determination relying upon number of expected values of deaths per year or with deviations from the expected value of deaths per year is considered violation by the author as can be seen the UK HSE documentation in the risk analysis section. Further, the same violation can be seen in the case of ORR in its approval of comparison between the expected value of deaths per year for the Enhanced TPWS and ERTMS-ETCS Technology in December 2015.
Random error: This error which is a deviation from the intended action may be due to a chance event without any causal factor involved.
Risk Analysis: process of determining the risk of an activity as it is. Formally, it is measured as a product of frequency of a hazardous event and its severity. The data may be obtained from past accident(s) data as well as fault tree analysis of new functions or technology. This definition of risk is given in the 2001 UK HSE 2001 published document produced by DNV, a notified body. The meaning is valid for marine and off –shore gas industry. The determination of social risk tolerability relying upon the FN curves[7] is refuted by Prof Andrew Evans in another UK HSE document published in 2003. However, these definitions are not used by the GB Railway Industry can be seen from the definitions given by the ORR. This discussion leads the author to consider the idea that cultural attitudes in the Industry do enter risk analysis. Here is the URL to Prof John Adams[8] June 2015 article.
SPAD and Safety Control: Passing a Signal at Danger.
Most fatal accidents inquired by the public Courts of Inquiry in the UK state that the railway accidents were preceded by a train passing a signal at danger and colliding with another train that was given proceed authority. The data for SPAD analysis is available from the ORR website[9].
Using the description given by Lord Cullen in his Ladbroke Grove Inquiry and stated earlier can be described by way of Graphical model shown in the Figure 4 below. The model was used by Prof Jens Rasmussen in the nuclear plant risk domain. Bearing in mind that the nuclear plant operations bear no similarities to the railway operations, the model below is required to be tailored the model to railway operations. From the inspection of the diagram, it is clear that the calculated acceptable level of risk hinges upon the assumptions about social and technical conditions, risk contribution from defects in designs or models, risk contribution from management oversight and incomplete or misconceived models. Author uses Management Oversight and Risk Model to describe the socio-technical system inquiring into risk contributions from design, oversight and failures in risk management. The evidence for the modelling and analysis of the accident scenarios comes either from the author’s Hazop studies or the official accident investigation report.
Figure 4: Scope of Predictive Risk Analysis for apriori acceptance of the conceptual design of process (nuclear and chemical) plant must include of prediction of the performance of the operating staff, maintenance personnel, and managers (Jens Rasmussen, 1997).
With respect to the above model, I can provide the examples from Published Evidences to show the risk contributions from the cases of misconceived models.
First, Prof William Marsh, and Dr. George Bearfield, statistical experts and railway domain experts failed to consider the risk contributions of infrastructure manager’s signalling and electrification design of locating the masts and signals posts obstructing train driver’s view of the signal post. Another factor which missed their attention is the explanation for the Clapham Accident. Unless the cognitive competence at the skill and rules based behaviour displayed by the novice train driver to report the failure in sequence of signals was interpreted by the experienced train drivers as a decision on the part of the signaller. Thus, the physical cause was accidental contact of the wire generating false green but this fault alone did not bring about the accident but needed an helping hand from the agency of the novice train driver ( the idea is not to implicate the train driver) together with the absence of the automatic train protection system produced the accident. These actions of an electrician and a train driver in a region had widespread repercussions. But the active errors were not committed in isolation but were facilitated by the latent errors and violations.
Safety or Risk assessment: activity of determining the adequacy of barriers considering the potential hazard or introducing new risk controls to eliminate the hazard or control or mitigate the consequences.
Risk management: activity of on-going management of the risks by way of setting the policy for management for dangerous situations and actions to be taken, audit, review, and analysis of policy implementation and take corrective actions whenever required. For example, ancient Greek philosopher, Aristotle, noted despite their weakness in their numbers, citizen soldiers of Cornea in 353 BCE choose to defend the Temple of Hermes till death whereas professional soldiers who deemed the risk to be high deserted the battle field (pp132). (Aristotle, 350BC/1955). In modern times, differences in perception of risk in experimental situations or in surveys on risk are noted by Nobel Laureate Daniel Kahneman and R.L Maguire and C.J Brain as well (pp. 138) (Kahneman, 2011), (R.L Maguire, 2006).
Partial Explanations for railway accidents:
Here is a remarkable Case Study on safety competence of professionals engaged in the safety engineering and management activity.
It is not commonly known in the GB Railways domain that risk analysis of FRAME data- base events by Railtrack in 1997 of the Solid State Interlocking System revealed 1737 failure events (in the area of memory, data, communication, processor and protection systems) in 1997.
Statistics showed a mean failure rate of1.2E-01 per year with a confidence level of 95% failure rate for wrong- side failure of giving a wrong message at the output. This is an alarming feature for a safety critical asset. If wrong –side failures were involved and if the particular wrong side failure occurred at the same instant then Newton Accident cannot be explained as a SPAD Accident. Moreover, confirmation bias was not recognised by the Prof Ali. G Hessami, former Head of System Safety, Railtrack in 1997 and an author in the book, “Railway Research” published in December 2015.
Another alarming fact is that the Ladbroke Grove Inquiry did not record any statement about Solid State Interlocking Failures that preceded the accident. The scope of the paper is not to dwell upon complete list of human errors involved in the accident. Author had used Management Oversight and Risk Tree to generate the assurance questions and Swiss Cheese Model to model and analyse the various accidents to generate complete explanations for the 2011 Herefordshire Accident, and 2013 peer reviewed publication noted the latent errors in the design and development of the ERTMS-ETCS Technology so far. The papers are attached.
This is not exhaustive coverage of the literature survey of ideas of risk or safety critical systems.
In the month of December 2014, I had written to the Transport Select Committee Clerk after making a series of Written Evidences on Omissions and Oversights and Assumption of Risks in the GB Railway Investments Inquiry during the Last Parliament Session. In my past Evidences, I had expressed serious doubts over the capability of railway companies to execute major signalling programme using programmed devices to solve problems of capacity in a safe manner. This was due to the fact attention is not paid to latent errors in decision making at planning and implementation level.
I was requested to make new Submission, if I had concerns over the matter, after the elections but I had failed to do so. I offer my apologies for failing to keep my promise.
I responded to the Digital Skills Committee Inquiry raising the matter of lack of skills and knowledge to perceive the unsafe properties of ERTMS –ETCS System. The House of Lords Digital Skills Committee’s Report Make or Break[10],[11] did cite my Submission DSC 0042 (pp.32) and accepted the idea that there is shortage of digital skills at the under graduate level; but the message that the skills and knowledge required for producing Safety Case for the ERTMS-ETCS Technology are not available was not captured in the Citation.
Since the 1840s, the traditional railways disciplines involved in the planning and delivery of the railway programmes number around twenty or so. Author’s conjecture is that the cultural aspect of reactive safety risk management of railways engineering and management process does not pre-dispose the general and programme managers to actively seek and confront risks inherent in technology and assure themselves that the project managers and teams are able to perform activities of hazard identification, hazard and risk analysis for the project at hand and see to that they do not seed latent errors into projects that will manifest as an accident at a later stage.
Here is the text from the Ladbroke Grove Inquiry Part II, Paragraph 6.9:
“The formulation of a Group Standard may be based on detailed technical and scientific evaluation. The fact that, when this work has been done, it does not have to be repeated by individual operators mean that there is a common benefit to those to whom the Group Standard applies. A Railway Group Standard may be specifically concerned with the cause of a past accident, with a view to preventing its repetition. However, where this has been done, it is, as Entec observed, a reactive rather than a proactive approach to safety. It should not be the only way of achieving safety improvement.”
Developing an institution for the safety critical programmers whose pre- programmed decisions are to respond to the future stimuli of events from the external world and guide either the human or track side computer as an inter-mediary to input stimuli to the computer (interlocking) which allocates track spaces to trains as per route related speed profiles in a dynamic manner, shall be in a position to eliminate the conflicts that can arise from the preferences enforced due to interactions between the various computing sub-systems and external sub-systems via the interfaces.
The ability to determine the future state of the world as envisaged by the French mathematician Laplace is no longer feasible in an inter-connected complex world and if it is feasible to discover a complete theory, then British cosmologist and a Noble aspirant, Prof Stephen Hawking (2005) asserts that in time it can be understood by everyone, not just a few scientists. In other words, gaps in communications between scientists, philosophers, and just ordinary people are to be accepted till such a theory of everything is discovered.
The key element of the programmes for the automatic train protection system that rely upon pre-programmed decisions apart the algorithms is the language. The AI programming language ADA or any other sub-set of the safety critical language adapted for programming safety critical devices is imperfect for the scenarios that may require the resources of a super computer than an embedded computer. The history of programming languages dates back to 1950s whereas human language dates back to several thousand years is a fact forgotten by Dr. Peter Winter and other ERTMS-ETCS Signalling Experts who draw the analogy of ETCS Language with human language.
The errors in the pre-programmed decisions are either to be detected at the system analysis, design level, functional requirements level, source code level, at the editing time or the compile time or run time. The unsafe outcome of communication system failing to deliver the critical message to the recipient (either due to incorrect data, or lack of data bearing capacity, lack of coverage etc) may lead to unwanted accidents. The latest[12] French TGV train accident during the test run in November 2015 is a grim reminder of the failings of programmed technology. If carried out at run time, after going live then the error detection mechanism may fail to carry out the fail-safe action. The safety argument has to rest upon probabilistic arguments and this leads us straight away into human fallibility thesis when dealing with statistics and probabilities of rare events.
Dr. T.P Kelly and others, computing experts at York University in a peer reviewed published paper in accepted the idea at the IET International System Safety Conference that when developing safety cases to detect errors at run-time by means of safety decision support system to help inform the process control operator of the risk involved, the safety properties of the so called decision software are open to question.
As per Noble laureate and academic psychologist, and behavioural economist, Prof Daniel Kahneman (2011), we either overweight the rare events in our decisions or ignore the probability. This is a pessimistic conclusion but needs to be accepted. The idea is illustrated by means of a simple experiment. Let us imagine the NASA Managers had access to the program author is using. They wish to know whether the next fifth launch is going to fail? The failure probability is 16.63% and the screen shot for the distribution is captured below in the Figure 5. below.
Figure 5: Visual graph of the distribution of possible failure rates. Bayes prior varies between 0% and 100%.
If we make a small change to the Bayes prior from 0% to 100% to 1% to 99% then the probability distribution graph is not sensitive but the failure probability changes to 17.003%. This is shown in the Figure 6 below.
Figure 6: Visual graph of the distribution of possible failure rates. Bayes prior varies between 1% and 99%.
The theses in the above examples are that design reliability and testing of components are reliably carried out and no security issues are involved. The whole idea of 99% confidence interval falls apart when the variable of concern is outcome probability of 17% in small number of rocket launches of five.
The question boils down to this: What are the margins for errors from cost, schedule time and risk perspectives to be assumed for failures of the pre-programmed decisions? This is an important question to be answered by general and programme managers rather than the programmers themselves working at the signalling supplier firms as they‘ve entered the critical region of the programming environment when they’ve signed the contract from which they cannot extricate themselves or face business failure. The ideas in this paragraph emerged from author’s reflection on the recalled conversations he had with an expert railway safety critical programmer at the 2009 safety critical conference regarding the question of MIT Professor’s Nancy Leveson’s STAMP approach is the infallible management practice to adopt. The expert programmer agreed that architectural decisions and trade-off analysis of capacity and safety properties of the system are necessary.
I take this occasion to bring to the Inquiry’s attention that I experienced the aforementioned lack of capability of performing hazard and risk analysis with the Ada based Triple modular redundant safety critical operating system in 2000 when author was asked to conduct System Integration Tests on the Platform and it did not fail safe as required. The question was referred to an outside consultant and he thought the matter was a rare event and due to complexity of the programme. The same lack of competence surfaced subsequently with the ERTMS-ETCS Signalling Technology Programme in 2003 on the West Coast Route Modernisation Joint Train Control Programme to implement the ERTMS-ETCS Technology on the West Coast Route Modernisation.
I faced a life-changing situation with the ill-fated ERTMS-ETCS programme with my engagement with the inadequacies in the policy planning of the technology in 2003. My wish is that this problem should not be faced by anyone else. I take the opportunity to thank the prompt action taken by the medical staff of the NHS to restore my health. Since then one of my prime motives is to highlight the inadequacies in the planning of the software intensive complex safety critical system.
In 2004, I had produced a Master Systems Engineering Plan for the Cambrian ERTMS-ETCS Railway which included the full formal safety study. However, Network Rail informed that it would take up the System Integration Responsibility and the project halted.
Later, in 2004, I was asked to examine the Systems Engineering Master Plan produced by Network Rail for the Cambrian ERTMS-ETCS Programme by the Professional Head of Signalling Systems and Chair of GB Industry Signalling and Communications Standards Committee at RSSB and this plan did contain any activity for System Definition, hazard identification, risk analysis, risk assessment and risk management. So, it constituted as an error.
In 2005, the Professional Head of Signalling Systems and Chair of GB Industry Signalling and Communications Standards Committee at RSSB requested for a systems engineering technology to be developed to deal with the allocation of safety critical rules and regulations to the duty-holder organisations in 2005 was another additional cue to the lack of capability in the domain. I had developed the Systems Engineering Methodology called “System for investigation of Railway Interfaces –SIRI” to deal with the problem and chaired Hazop studies which showed that GB Railway domain Subject Matter Experts were biased. Peer reviewed papers published in 2006, and 2010 are attached.
To illustrate the problems of latent decision errors connected with the technology due to lack of design and engineering capability, I published a peer reviewed document at the IET International System Safety Conference in 2013 listing the eleven latent decision errors committed by several organisations such as signalling suppliers, railway administrations, Member States’ national authority and standard setting bodies as well. The definitions for latent and active were presented earlier. However, the research paper remains unnoticed and no actions on failings observed in the paper are taken.
Like all strategic decisions with signalling and telecommunications, the decisions on the originate with UIC as acting as a systems engineering organisation but without the capabilities of systems engineering to image the extant social –technical systems and the changes to those current practices that may be required as a result of the triggering event of technology change.
The National Roll-out of Digital Railway is expected to be completed by CP10[13]. During the current period, CP-5, the two major programmes are expected to be completed: Crossrail is planned to be completed by April 2017 and Thames-link by 2018.
However, the plans were not risk assessed. This evidence is shown by the recent disruption to the Crossrail ERTMS-ETCS Level 3 Moving Block Programme. It had been optimistically assumed in the original Plan A by the signalling supplier, the concerned railway administration and the programme sponsor that a combination of Automatic train operations (ATO) with ETCS and ERTMS can be utilised. This strategy of operating automatic train operation functionality over the ETCS functions was assumed by the UNISIG till November 2013. This can be discerned by the UNISIG Presentation made to the European Railway Agency[14] to attain the urban headways on the mainline or inter-city railways like Thameslink railways. However, it appears that this strategy was not attainable was discovered in 2014 that the technology may not be operationally ready for the passenger service to begin in 2018.
Since then frenetic efforts to plan for recovery as the Plan A has failed and lack of expertise to develop the ERTMS Application has been discovered and is admitted by Network Rail in its Application to the ORR in October 2015.
The URLs provided below give the access to the documentation filed by various actors and author’s objection to Plan B[15]. When author objected to the data provided by RSSB Safety Risk Model with regard to the SPAD fatal frequencies that suggested the idea that we should see a statistical fatality approximately 3.84 years in the Section 5.1 of the Application. Because no such fatality due to passenger trains SPAD is noticed on the Network during the last ten years.
Author speculates that frenetic efforts by RSSB, Network Rail and ORR were launched to commission a new Risk Assessment Report dated December 2015; this shows that the Enhanced TPWS (risk of hypothetical fatality of once in 81 years) is more safer than ERTMS-ETCS technology (risk of hypothetical fatality of @ once in 64 years) was produced to justify the decision already taken to go ahead with the idea of procuring enhanced TPWS.
However, the question arises as to how the train collision SPAD determined to be 3.84[16] years in October 2015 jumped to 64 years in the case of ERTMS-ETCS technology and 84 years in the case of Enhanced TWPS technology by December 2015.
What new information has been gained and how did the new information arise? The change in the risk level without any material change in the technology is clearly a violation given the professional opinion of the statistical expert, Prof Andrew Evans, stated in 2003. Recently, author has learnt that entire development team from Thameslink Programme has been shifted to the Crossrail programme and this means that Thameslink Central Section will see resource shortage and jeopardise the delivery date of 2016.
The Figure 7 shows the state of maturity of the capacity improvement programmes relying upon ERTMS-ETCS and CBTC technologies. There is no news about GWML programme kick started in the year 2008 and the ECML Route is be fitted in 2020 and is under planning. The Table shows that the process of delivering complex systems is at immature stage with only one programme completed, albeit, with safety problem. However, the question of safety risk still remains to be addressed on the Crossrail and Thameslink Programme because most of the resources deployed on the Thameslink are sourced from the Cambrian or failed WCRM ETCS Programme. In other words, there is no generation of functional capability to align the system and safety development lifecycles.
Author wishes the Inquiry Committee to kindly note that the Latent Errors Revealed in the Decision Making process adopted by the ORR, Network Rail and RSSB. Author’s recommendation is to install a National Hazards Committee made in 2010 to replace these separate decision making committees managed by RSSB as the problem of Group-think bias is active in the GB Railway Industry. Author had stated this recommendation in his October 2010 IET Paper. This was prior to the Value for Money Study Reports published in November 2010 and 2011.
The application of systems engineering methodology incorporating psychological insights from the decision research science enables tackle the problem of Group-think and other biases that affect decision making of executives. Cognitive competence of decision makers to tackle biases originating in the decision committees needs to be supported to enable them think in a counter intuitive manner. Author had raised concerns over competence in the past Submissions to the Transport Select Committee Inquiry on the Railway Investments in December 2014. In other words, author’s judgements are not influenced by the recent spate of Inquiries like Madame Bow Inquiry, Shaw Inquiry, and Nichol’s Inquiry.
The Rail Delivery Group that has been set up as a response to Recommendations of the 2011 Value for Money has failed to provide any leadership on the question of safety risk posed by ERTMS-ETCS Technology suggesting the idea that senior managers do not understand the AI technology.
Figure 7: Maturity of Capability to Deliver by the ERTMS-ETCS and Automatic Train Control Programmes
Automatic Train Control Programme Name and year of completion or failure | Automatic Train Control Programme Cost | Comments |
WRCM ERTMS-ETCS 1998 and 2003 | £250 million
| National Audit Office Report dated 2006[17] showed that WRCM ERTMS-ETCS 1998 and 2003 failures had consumed £250 million till 2003. |
Cambrian ERTMS-ETCS 2011 | £??? Costs not available to author | Violation discovered in 2004 by author; Cambrian ETCS[18] Programme failed to integrate the level crossing functionality and was investigated by the RAIB in 2012. ECTS Safety Case?? National signalling components excluded from the ETCS?? |
Bombardier 2011 Programme | £85 million |
|
Thales 2015 SSUP Programme | £ 250 million lost revenue per year for next five years. @ £1255 | Bombardier 2011 Programme[19] |
Siemens Crossrail Plan A for the ERTMS-ETCS Development 2018 | £ ??? Costs not available to author | Plan A has failed.
ETCS-ATO interface??, safety case?? |
Thameslink Plan for core section 2018 | £??? Costs not available to author | Plan under hold resources shifted to Crossrail. |
ECML 2020 | Under planning | ETCS-ATO interface??, safety case?? |
HS2 | Under planning | ETCS-ATO interface??, safety case?? |
The London Assembly in its March 2016 Report noted the failure of project, programme and general management practices in the assurance of Bombardier Contract. What is ironic in these situations of business failures of automatic train protection systems learnt from the Media Reports is that the said Director(s) involved in the Bombardier Contracts[20]’ [21]have found suitable placement on the Network Rail Board.
a) Problem of determining the train location from the track side:
When a railway professional thinks of automatic train protection they make twin hypotheses. First that the track side architecture is fail- safe as it is rarely implicated in the accident reports. Second, the train borne computing system being fail-safe the chances of an accident are remote. Therefore, the conclusion is that ERTMS-ETCS is a reliable and safe system. The question of latent errors in safety critical equipment like axle counters used for train detection, or errors in trackside or train borne interfaces with non –SIL4 interfaces are not understood or evaded.
In 2002, author was asked by the then Technical Director and the Design Authority of the West Coast Route Modernisation Programme to sort out the problem of train awakening functionality: this is the problem of determining location of the train remaining which was as an open point in the TSI Control-Command-Signalling Specification ERTMS-ETCS Level II without line side signals scheme. This is an open point still, as per author’s information.
After due investigation of the problem, author learnt that the solution to providing accurate information on train location can be solved in the same manner as it is done on the marine or aircraft or space vehicles.
In these applications a combination of dead reckoning and other types of position and speed sensors using a data fusion algorithm in the form of a stochastic solution are provided. However, this technology requires change to the train and track side architecture of the TSI Control-Command-Signalling Specification ERTMS-ETCS Level II and Level III as the accuracy of distance information required for safe separation in the case of railways is more stringent.
The accuracy provided by such dynamic positioning schemes relying upon satellite navigation cannot be brought less than two to three metres. Unless the trackside computer is confident that the train position report is accurate, the movement authority to be issued by the trackside computer on tracks without track circuits is bound to create errors in the movement authority issued. The problem of integrating the non-vital functions with vital function of train protection is likely to compromise the integrity of the train protection function. Therefore, author had asked for a Change Request.
The Client, Network Rail refused to grant Change Request as the cost of change was beyond budgeted and client asked for a cheaper solution to solve the problem of data loss of the train location after powering down. In response to the Client request, author suggested a non-vital circuit to determine whether the train has changed its position or not and the Client readily labelled the solution as Cold Movement Detector function and incorporated it into the National ERTMS Requirements.
Author assumes that GSM-R is able to operate reliably and is able to carry necessary data under all circumstances. This is an optimistic hypothesis.
Author does not think that railway professionals have given much thought to the problems of data entry, robust engineering process for hazard and risk analysis, resolving conflicts between performance and safety considerations, human error in risk management system that have impact on the creation and maintenance of System Safety Cases for the ERTMS-ETCS Safety Cases.
The Yellow Book, Six Sigma management practices do not take into account the outliers cases of wrong side failure units discussed earlier and therefore, do not form barriers. The idea that Bow –Tie Model of Risk Assessment provide assurance on the loss events is prone to out of –sight, out of mind bias. Managerial decision making errors cannot be represented in the Bow tie models. 2009 Nimrod Inquiry has made this point very clear[22]. Despite this, Network Rail has shown great interest in Bow Tie models is a violation.
Unless technology matures to a stage where the accuracy is granted the safety of the technology cannot be assured. Other nations like France, Spain, China and Japan have faced high speed accidents revealing latent errors in technology.
The choice is explicit to build a reliable railway meeting its needs and is safe to run. The risk of removal of TPWS and replacing it with ERTMS-ETCS Technology as per the ORR Decision Letter dated 15th March 2016 is that life of a statistical train user is cut-short by several years as admitted in the New Risk Assessment that has not distributed to those who had taken the objection.
The social tendency to evade difficult questions on risk assessments is not understandable on the question of individual and social risk. What is the probability of a major accident involving greater than 10 fatalities?
There are number of safety constraints that apply to the UK situation that may not apply to the non-European situations where lateral spacing between parallel tracks may be increased to overcome these constraints.
b) Problem of ERTMS ETCS System Safety Case: CENELEC vs UK HSE Safety Standard
In 2003, author was asked by the Design Authority to advise as to why the UK HSE as a Safety Case Acceptance authority is refusing the Safety Department’s strategy relying upon Yellow Book, an Railtrack approach to Engineering System Safety Management and showing Compliance with the railway specific safety standard CENELEC Standard 50129 Requirements to demonstrate the idea that ERTMS-ETCS train is safe to operate on the West Coast Mainline Route.
Upon investigating the UK HSE Safety standard IEC 61508 for its content, the difference in strategies became apparent to the author. Fifteen years ago prior to this problem in his earlier work experience, author had worked at onshore chemical and petro-chemical continuous processing plants as a Design Authority and design engineer. Therefore, it was a revelation to the author that Hazop study was not practiced in the GB Railways to identify the design weakness.
The Yellow Book and CENELEC standards rely upon the reliability data of operating components of the system to be used as inputs to cause-consequence (risk analysis) modelling to arrive at the risk. However, this data is not used to determine the safety integrity level of the ERTMS-ETCS Application. In the CENELEC standards safety is treated as a quality issue and argued there is no co-relation between current risk levels and the risk to be reduced by the ERTMS-ETCS Application.
A rough analogy drawn from the medical domain appropriate to illustrate the problem is given. If the patient is describing his symptoms, the General Practitioner prescribes a medication that bears no relation to the symptom that patient is having. The only remedy known to the GP is recommended. Author expects that it is futile to expect that the patient will recover.
The failure to take into account barrier model as required by Part 5 the IEC 61508 is another reason for the UK HSE to reject the Safety Case Strategy suggested by Safety Case Experts.
The problem of decision making and risk management persists can be seen from the above examples and the ORR Case Team in the Crossrail Decision as there is no change in the safety data but the decision has been made on revised estimates suggesting either the safety data is erroneous in the first instance or the process was in error. If it be assumed that RSSB Safety Risk Model Team discovered new data then the source of the data, competence of data providers and whether failing in the data is due to chance, if so what model was used? Reasonable doubts on the risk assessment model are natural because RSSB SORAT tool is developed from the algorithms developed a mathematician who attended Newton Accident Inquiry and failed to notice error in the arguments advanced by BR Head of Software Expert in 1990.
The investment of £ 500 million into the TPWS Programme by 2002 is the example of train protection strategy that is successful on the Mainline. The London Assembly March 2016 Report contains information stating that other lines recently upgraded as facing problems as well. Author has raised the errors in risk assessment in various engineering forums since 2005 till date. The price he had to pay with his job for drawing attention to managerial errors.
Given the fact of the above circumstances and the failure on the part of ORR, RSSB and Network Rail to adhere to the Best Practice of UK HSE[23] to avoid pitfalls in the risk analysis and assessment process suggests the fact learning from past failures is not a social tendency displayed by the railway firms and their regulator. This is the legacy of the railway firms turning a deaf ear to the improvement in safety requirements and strategy and the Inspectorate fails to press the point noted in the history of HMRI documented by Stanley Hall (1990).
The cost of risks of such fallible strategy have been demonstrated approximately to be running into £1,250 billion so far excluding the current costs of Crossrail and Thameslink disruptions.
There are few risk experts who think that co-relation is causation and CENELEC standards are better than generic IEC 61508 safety standard. We ‘ve seen earlier in the discussions on the software expertise and we have an academic expert Dr. T.P.Kelly expressing the view that safety of decision support systems can be doubted.
c) Problem of lifecycles models for programme development and interleaving risk management decisions: GRIP investment lifecycle, Vee-lifecycle and CENELEC safety standards, Nichol’s assurance lifecycle
I wish to draw the Chair and Member’s attention to the fact that Network Rail’s Guide to Railway Investment Projects Framework comprising of eight stages is known to Systems Engineering Experts as a simplified version of a complex life-cycle model of Programme Management ( depicted in the Annex 3 of the Bowe Report dated November 2015). This life-cycle model is depicted as a Vee-life cycle[24] in the programme work flow management and in the work flow of CENELEC[25] Safety Standards application as well regulating the production of Safety Systems Safety Case for the Railway Technology Signalling Systems as well as other sub-systems. These two lifecycle models do not align with each other is a cause for concern as a programme may proceed for years without the resolution of the safety problems. A German University which has taken lead in the CSM Review activities is of the view that lifecycles relating to the particular program like the Interlocking System itself and the Interlock Project risks need not align. Given the fact that the Interlocking is the heart of signalling system, the failure of programme risk is clearly depends on the component of hazard and risk analysis activity of the interlocking functions and ignoring this dependency is a latent error.
In 2009, author had proposed the Interlocking hazard and risk analysis at RSSB to be carried out and was told that Network Rail has no budget for the same. This is the third time (2003, 2004, 2009) that the Best Practice for Hazard and Risk Analysis that author has proposed to Network Rail and found that it has no budget for the same. The cost of implementing such a scheme at RSSB was next to nothing.
The Wikipedia link provided in the footnote 1 is an indication of work flow followed in the various industries drawing upon the same conceptual schema beginning with the definition of user’s need perceived by the programme developer, defining, developing and delivering the final technology to the clients at the end. However, failure to set criteria to make Go/No Go decisions relating to the work flow of the technology programme activity after every stage leads to flawed outputs that accumulate throwing up nasty surprises towards the end of the Programme.
This pattern of behaviour can be seen starting from the 1994 failure of Moving Block Train Control System Plan developed for the West Coast Route Modernisation by four management consulting companies like Back and Brown, Booze Allen and Hamilton, and Sir Alexander Gibbs and Partners and Railtrack. The Nichols’s Review (dated 31st July 2015[26]) of Assurance of Major Programmes for complex changes of Time-Table Part 2 sets out another life-cycle model of the Major Programme Delivery.
Concerns over the quality of decision making processes in economic organisations based upon the thesis that human beings are not optimal decision makers as postulated by the classical economics theory (Expected Utility Theory) when confronted with conflicting objectives, and behave as bounded rational managers adapting to search for local solutions and satisfying the immediate concerns of stakeholders is known as satisficing strategy.
These ideas of “bounded rational manager” and “satisficing behaviour” have fetched expert decision maker, Prof Herbert A. Simon, a Noble prize in 1978. Another great influence on decision making process of individuals as well as groups involved in decision making in organisations has been the work of 2002 Noble laureate Prof Daniel Kahneman and his co-worker, late Prof Amos Tversky. These ideas influenced the work of Prof Irving and Leon Mann (1977) who developed the concept of “Vigilant decision maker”. As if on cue from Prof Irving and Leon Mann, Prof Jens Rasmussen raised concerns over risk management in his 1997 publication[27]. In the section 10.1 of the paper, Prof Jens Rasmussen discusses the role of three decision research paradigms of normative, behavioural and prescriptive theories; organisational theories of bounded rational, learning, normal accident and highly reliable organisations.
Drawing upon this research, my researches into decision making, investment and risk management processes involved in setting up Clapham junction (2010), Space Shuttle Challenger (2012) and Cambrian ERTMS-ETCS Safety Incident (2015) suggest that the idea that bounded rational agency theory and satisficing behaviour are valid and deserve more attention and effort to tackle the problem of executive decision making in the industrial setting. Unlike the industrial practices, these ideas have become part and parcel of all industrial economists’ research continuing till date with Noble laureate Prof Jean Thirole Noble lecture[28] as well.
In other words, Railway Safety Management Model as evidenced by this Submission suggests that it violates the Best Practice Principle that decisions should follow risk analysis rather than use risk analysis to support fallible decision taken already. This has been done by the recent ORR decision on the Crossrail Exemption Application 2015.
The experimental test programme to replace GSM-R has met with failure in France. Author infers that it is the same TGC accident reported earlier. The GSM-R architecture was selected by the UIC in 1989 and the major decisions like that of ERTMS-ETCS do not allow for subsequent choices to be made by Member-States. The Member States Representative Inputs were bounded rational decisions.
In 2002, my colleague, an expert in telecommunications, reporting to me stated that GSM-R lacks capability to handle the data and timings requirements as per Network Rail Specifications. I told me that we will take up the matter as we sort out the Safety Strategy for the Programme. However, the Programmed was folded up by the Strategic Railway Authority in 2003.
In 2008, I attended the GSM-R Hazop conducted by Network Rail and attended by all industry experts. This procedure was incorrectly applied to the design assessment. The adaptation of the Hazop procedure to the task of design analysis in the Railways failed the original purpose of the study process. The Professional Head at RSSB involved in the case asked me not raise any problem notice.
In 2009, I discovered as being a member of the GSM-R Network Rail Strathclyde Trials Monitoring team that Network Rail did not produce a System Specification and relied upon the Supplier to write the specification. The Network Rail Reliability Team stated that there were under orders not to communicate with the train operating and freight operating companies. The problem of cab radios failing to register surfaced and I did not find any co-relation between the works carried out by the GSM-R Commissioning Team informed by the Hazop workshop proceedings.
In late 2012, it appears that RSSB was requested to provide help in the matter of GSM-R risk assessment[29] using the Industry’s Consensual Decision Making Process.
The lack of HAZOP process and lack of adequate consideration of emergent property of Communicate_ GSM_R Message by the GSM-R System was never considered and the key success factors that may enable the GSM_R system strengths and weaknesses to emerge was lost. There is a belief prevailing in the Industry that buffer stop and certain other situations may not be handled in an appropriate manner.
There is a direct proportionality of GSM-R on the Network Infrastructure as the track capacity is lost whilst trying to establish lost GSM-R connection. The actual parameters are not available to the author to state the numerical estimate.
The failures in the GSR_R system have to be modelled using a State_ Graph_ Method.
This is a Summary Extract of the Independent Reporter.
The ORR sought confidence that Network Rail’s major programmes are appropriately organised, governed and resourced to successfully enable the significant timetable changes planned in CP5 and beyond, principally in 2018 and 2019.
There are several significant timetable changes planned for CP5, many of which involve new or cascaded train fleets, combined with route-wide infrastructure upgrades. Network Rail (NR) has a critical role to play in delivering the infrastructure and operational capability to enable the new timetables to be introduced on time and to the right punctuality. Major cross industry rail programmes like West Coast Route Modernisation (WCRM), Thameslink and Great Western Modernisation (GWRM) have all needed mid-programme review, re-configuration and re-baselining because the complexity of these upgrades was underestimated. In the past this has sometimes led to significant cost escalation, programme delay and reputational damage to the industry. Nichols Group was appointed by the ORR and NR as an Independent Reporter (IR) to undertake a review in two parts: 1. To develop a set of generic assurance checks, through review of NR’s existing processes and best practice. 2. To assess NR’s approach and processes on selected CP5 programmes, using the assurance checklist and through constructive challenge of NR.
The results of the Review as far as this author can provide solution to the problem are described in the next Section together with previous attempts to draw attention of the concerned Directors of Signalling and Risk Analysis to the business problems.
ORR appointed an Independent Reporter, Nichols Group and the Group has produced two Reports in 2014 and 2015[30]. The following is the extract.
In Section 4.1 noted that no Green marks for the interfaces/interdependencies between projects in the programme are identified, understood and any impacts are planned for.
In Section 4.2 the Report identified black marks at the Interfaces/interdependencies between projects and existing assets/systems/operations are identified, understood and any impacts are planned for the activity they assessed.
The number of black marks and red marks against all five programmes they assessed shows that Network Rail lacks capability to identify the identify interfaces between assets, systems they form into and the latent errors or failings them may contain on the decisions taken on them.
Author’s System in its first phase directly addresses the point no 4.2 where the System Definition of the Work System Under Investigation is identified by systems diagrams to depict the assets and human actors involved and the various interfaces that arise in practice with a clear demarcation of the duty –holders involved.
The Nichols’ 2015 Review (Annex CN-31/A) failed to close this Open Point as it is not in possession of knowledge base of Prof Jens Rasmussen’s Cognitive Systems Engineering Practice. The Review suggested the Open Points 4.1 and 4.2 can be closed by Integrated schedule showing dependencies between the programme and the operation as done in the case of EGIP. However, Schedules do not capture the intricate details at the project and programme levels and programme managers relying upon metrics of budget spend cannot cope with the conflict, uncertainty, complexity of the choice situation.
In July 2014, author had conveyed to the Crossrail Design Team made up of Bechtel and Network Rail engineers that he had developed a System which will help remove the lack of Interface Management and Capability to identify hazards and perform Risk Analysis, a capability found to be lacking by the author at RSSB in 2005.
As noted earlier by author, he was professionally asked by the Professional Head of Signalling and Telecommunications and Chair of Signalling Standards Committee. The System Engineering Methodology developed and applied at RSSB and chaired by the author showed that Network Rail, as a policy does not want to change the HMRI Signalling Principles which it holds onto, irrespective of the fact that these Principles may no longer be required for ERTMS-ETCS Technology and the Signalling Engineers participating in the Signalling Standards Committee did not possess competence in planning and delivering the changes to the Schemes. The ERTMS-ETCS Specification needs updating by taking into account the Interfaces between assets belonging to different duty-holder organisations and generate interface hazards that set up the railway accidents. The whole of idea of Systems Approach was embedded into a single sheet known as RSSB System Safety Poster.
Author shared the RSSB System Safety Poster with the Crossrail Design Team as to how all ideas of asset management, hazard and risk policies, systems engineering, safety engineering and human factors engineering perspectives can be fitted together into a single sheet (See Appendix I). He also shared the idea that 90% of all railway programmes fail as per Oxford 2005 study. And there is a need to change the way programmes are managed by connecting the all these management practices together as Network Rail do not possess right practices. However, the Crossrail Design Team chose to not to fund the Cognitive Systems Engineering Management work of typing all the loose ends.
The whole idea of Systems View is articulated by author since 2006 and response of the railway firms is head-in –sand approach.
In terms of control system theory, the ERTMS-ETCS Programmes are running as “ open systems “ on a trial-and –error basis experimenting with tax payer’s funds every time rather than proceed with a coherent Systems Engineering Plan to integrate the System Development and Safety Issues in an integrated manner.
Author’s attempts to inform the Directors of Network Rail the above lack of capability and his ability to help them are met with either silence or rejection. In 2007, the author had support from RSSB Professional Head of Signalling and a signalling engineer to present it to the Signalling Director. In 2011 and 2012, the attempts were made through a Job interview and in response to IET Presentation.
Author had tried to raise the issue with Professional Systems Engineering Community, INCOSE, and found head-in-sand response in 2006[31]. This was the third occasion to raise the issue to integrate human factors concerns, safety engineering concerns, and systems engineering concerns in a cohesive manner to facilitate the resolution of the problems.
Figure 8: New Governance (partial) Proposal
Author proposes that the resolution of the hazards that were described in the paper for ERTMS-ETCS System and GSM-R system and several other issues which remain latent are to be addressed forming a huge block of work for specification and resolution of various of issues concerning train location algorithm, brake distance algorithms etc. be carried out with the help of a National Hazards Committee to create a sustainable knowledge base. Previous submissions have shown a System View. The present paper discusses a short summary. A full-fledged Master Systems Engineering Plan was written in 2010 by when employed at RSSB. However, declined the need for Systems Engineering Activity and made the author redundant.
Unlike RSSB, which does not possess competence in Systems Engineering, the New Hazards Committee can be equipped with this competence for which assistance can be provided by the author. Earlier Submissions made by the author to Railway Investments, Safety of Level Crossings, Bicycle safety and Safety of Off-shore helicopter Inquiries have shown the utility of the Systems Engineering Method over traditional engineering processes. The “design engineering “ and “ technical know-how” parts of knowledge base need to be improved to de-risk the complex technologies.
With a single organisation to manage complex ERTMS-ETCS system and related issues, risks concerning innovations and dangers they may spawn as a result of optimism bias and other biases require a pre-mortem analytical approach to be applied in a formal manner.
Several other Reviews (Madame Bowe Review, Nichol’s Review) have provided their recommendations on how to promote efficiency into the Programme with the adoption of the GRIP Life-cycle model. The idea of GRIP cycle viewed through the lens of BRM, BDT explanations suggest the idea that the managers of work packages, projects, programmes and investment assurance framework managers work without any guidance and feedback process and therefore, generate satisficing options.
The focus of attention on relations between the Sponsor, ORR, and Network Rail and Train and Freight Operating Firms cannot yield a comprehensive model of working between the firms without a common knowledge base, because, unpacking the sources of beliefs with respect to attitudes and preferences as these factors do influence the outcomes in regulatory situations. Noble laureates in economics do not share a common belief about the nature of economic man. This fact is illustrated by the Noble Lecture[32] delivered in 2001.
Economists have preferences and psychologists have attitudes is the common refrain (See Appendix II). However, what does real engineer (s) have? Author’s response is that engineers have both preferences and attitudes towards safety risk: eliminate the hazards from the initial plans downwards and transfer risk to those who can bear them.
How is that risk from management oversight, a violation in failing to train signalling engineers, HMRI Inspectors failing to foresee accident scenarios, persist till date?
The administrative barrier of relying upon HMRI Inspections prior to opening of the railways and the question of Government’s role in interfering in the running of railways with an aim to improve the “design engineering “and “technical know” of the designers to learn about their latent errors prior to transforming their designs into concrete structures and systems fails due to conflict of interest over the themes of safety and capacity date back to the 1870s. . This was argument since the Tay Bridge disaster of 1879 which was inspected and fore warnings about the design was made by Major General Hutchinson of HMRI.
This point is illustrated by a recent example.
For example, the formal authority to accept and approve the design rests with the ORR. However, the real authority, in terms of taking decision s for itself (in the language of Noble laureate Prof Jean Tirole and Prof Aghinon) laid with Network Rail where the regulated organisations, as a real authority, set out the sub-set of actions that can be taken by the ORR in the case of objections to their failing of Plan A arises. The Regulator power has been lost and the asymmetry of information ensured that the regulated monopoly went ahead with its plan despite the fact that its failings were not random in nature or were subject to laws of nature but the decisions were taken subject to laws of thinking. Even if Col. Rolland was to re-incarnate to persuade the railway firms their behaviour will be the same unless there is an intervention.
From the writings of Noble laureate Prof Herbert A. Simon, Prof Cyert March, Prof Mann, and Prof Henry Mintzberg, the idea that emerges to solve the problem of quality of decision making is retain a umbilical cord between the operative and innovative parts of the industry: the innovative parts of an industry such those as trying to create strategic programmes may be labouring under the belief that they are maximising rationalists but empirical research suggests they are actually bounded rational firm managers with an urge to jump at every available business opportunity for investment than create a sustainable future out of their interest( See Appendix I and II) .
From Madame Bowe’s Review, author learnt that the NW Electrification Programme was jump started on the basis of demands from local stakeholders, but did not feel was any need felt to co-ordinate internally between the signalling and electrification teams. This finding does not surprise the author as he had raised the problem in the past Evidences made to the Transport Select Committee Inquiry in December 2014 suggesting the idea that internal co-ordination between signalling and electrification teams is lacking and is a problem to be solved.
The parameters of capacity, signalling , communication and electrification are inter-dependant when long term time-table changes are planned and these may have unintended effects on accidents, and consequently, upon risk performance.
A large Programme like HS2 has suffered from base rate fallacy is an indication that executive rationality is prone to biases like ordinary human beings as in the case of Crossrail Decision Letter outlined on 15th March 2016. Therefore, the need for Cognitive Systems Engineering discipline is established again.
Recalling the evidences of ORR Crossrail decision ( March 2016), Dr.T. P Kelly (2013), Cambrian ERTMS Incident( 2012), WCRM –TCS( 1998,2003), Railtrack Yellow Book Practice( 1997, Stanley Hall (1990)on the attitude of safety regulator, lack of support in CENELEC standards to support qualitative decision making( 2003-2016), and research papers published by author strongly suggest lack of attention towards improvement in safety culture. Author’s published paper (December 2015) and corrected (April 2016) draw attention of the readers that complex major programme needs a systematic approach where these interventions have objectives beyond the Railway Industry and feed into the wider economy.
The user’s needs and adequacy of user’s requirements and capability of the technology to meet them need to be probed so that changes can be made safely. The problems of overweighting and probability neglect are major problems in decision making identified by the behavioural decision making research. Subject matter experts like medical experts (see attached paper April 2016 paper) have shown that they‘re prone to this problem and railway executives are no different.
The attached paper investigates heuristics and resulting biases that have led to Cambrian ERTMS-ETCS Safety Incident providing the argument for the bounded rational manager thesis and establishes the need of cognitive systems engineering methodology to probe the cognitive competence of the decision makers by means of Prof Jens Rasmussen’s Skill-Rules-Knowledge Framework.
The benefits of the Cognitive Systems Engineering Methodology are five-fold.
First, the common executive mistakes that escape attention are captured. The evidences for these claims are published peer reviewed studies at the IET International System Safety Conferences. The process of decision making needs to integrate both qualitative and quantitative analysis. The violations in management sector need to be tackled as well.
Second, errors in the strategies of executives and engineers’ thinking (Train Protection Group, Signalling Standards Decision Making Committees) due to Group-think bias can be revealed by probing into the grounds of the Concepts of Operations, the sources of market demand and dangers inherent in the technology that is being developed . By making the connection to the goal-state desired and the difference between the current states, the decision model can uncover the short cuts taken to reach decisions by means of high level Hazop studies.
Third, the argument expensive decision support systems cannot fulfil the integrity demands are accepted by an expert computing expert, Dr. T.P Kelly. Therefore, expensive investments into decision supports systems are not needed. The decisions together with the knowledge bases for those decisions can be stored electronically with care.
Optimism that technology can provide solutions to risk problems is refuted by Dr. T.P Kelly’s position, a York University expert on computerised safety decision making support. This applies to the System Safety Case for the decision support analysis as well as the ERTMS-ETCS, and GSM-R and other related technologies.
Fourth, early warnings on inadequacies of the investment planning can be raised saving labour at the later phases on fire-fighting the same issues. The evidence of base rate fallacy in the case of HS2 Business Case is evidence in support of the claim.
Fifth, in the context of programme life-cycle, the conceptual errors at the initial planning stage, the human factors and decision research inputs can be co-ordinated at this stage. Resident pathogens in management practices like Bow Tie model, Yellow Book, Six Sigma and Safety Risk Models can be identified through the MORT type of decision support methods. The interfaces between projects, programmes, assets, and human factors can be supported through logic diagrams to aid mathematical models as well. Evidences from research papers are attached. In other words, question of false beliefs, distorted perceptions and asymmetry of information can be tackled.
These benefits can be realised only under the auspices of National Hazards Committee. The benefits are not quantised in monetary terms but the effort in resolving commercial issues between railway operating firms and infrastructure manager on how the costs and benefits can be shared for the emerging benefits will be saved if a common frame of reference is established.
The moot question is whether the wider society is prepared to accept risk of social experiments to be carried out by railway administrations and rail regulator and allow them to deploy technologies that have not matured?
Author thinks the society is orientated towards risk averseness if the risk is not voluntary sought like skiing, and other adventurous sports.
The ambiguity effect of what probability distribution to apply to the given problem if the data is from an unknown distribution, the problem of resources unavailability and uncertainty in data can be tackled if the resources for development are grouped leaving behind the operational and maintenance activities to Network Rail operating, human resources, executive and other management apex parts of the industry.
Major programmes can be handled through National Hazards Committee after de-risking the planning and design phases they can be transferred to the Delivery Teams for implementation. The construction and testing phases are not free from risk is learn from the TGV accident. Therefore, risks those that are to be faced throughout life-cycle need to be checked for their accuracy and focus attention on the important matters.
The legacy of railway firms failing to implement Systems Engineering Methodology and failing to identify interfaces between physical assets, human operators, and the Railway Group standards that apply to them across organisational boundaries to assure that changes can be made safely and in an efficient manner is continuing. This has been demonstrated by way of examples.
The need has been expressed repeatedly by Professional Heads of Control –Command- Signalling and bounded to the Lineside Signalling Principles ethos fail to enable necessary transformation to the new environment of Cab Signalling. The lack of interfaces between projects, assets, human factors, and programmes were identified by Independent Reporter, High –level departmental Inquiry as well. The errors in the ORR Risk Assessments and failures in understanding of Common Safety Method (see April 2016 Paper) were discussed.
The recommendations to reform the resident pathogens in management practices and process of programme development in the form of National Hazards Committee have been made.
The attached diagram below provide a Conceptual Map link the various entities of Safety Plan, Policy, Measures, Vulnerabilities, Assets, System Specifications, Accidents and Design and Development Failures in an integrated form linked by verb clauses by author in 2006. Such a world-wide view can be used by all disciplines for setting the ground for discussions on inter-dependent parameters of safety, capacity and economics.
Figure 9: Figure showing how system are composed to form assets that combine to form a System to be deployed in a context of socio-technical system
The diagram below shows the factors that interact to generate the stated and revealed preferences. The black arrows point out to economist choices whereas white arrows related to consumer choices.
The concepts of perception, preferences, and process of choice making of consumers affect their willingness to pay and scales of risk aversion and risk seeking etc. can be approximated by approximate normal models of zero mean and single std. variation to reveal any outliers in the data assessments and raising warnings about errors in information processing on the part of consumers as well as technology providers. A further investigation into statistics is required. Thus, for strategic choices deep expertise in statistics may be required but modelling for preferences of consumers is required but the preferences of operators and engineers can be modelled into the logical MORT analysis. The Figure 10 is a Conceptual Schema for choice making. However, those biases that enter into decision making are noted by Professor McFadden.
With respect to this model, the behaviour of decision makers as per rational agent model (RAM), bounded rational model (BRM), behavioural decision theorist ( BDT) and engineering management EMM) model can be referenced.
Figure 10: Standard Model of Choice
7 April 2016
[1] http://orr.gov.uk/__data/assets/pdf_file/0020/5663/incident-ladbrokegrove-lgri2.pdf
[2] http://orr.gov.uk/__data/assets/pdf_file/0016/21292/crossrail-exemption-application-consultation-september-2015-decision-letter.pdf
[3] http://orr.gov.uk/__data/assets/pdf_file/0014/21290/crossrail-exemption-application-consultation-september-2015-responses-summary.pdf
[4] http://www.humanreliability.com/articles/Getting%20at%20the%20underlying%20causes%20of%20SPADs.pdf
[5] https://en.wikipedia.org/wiki/Signal_passed_at_danger
[6] http://www.hse.gov.uk/aboutus/meetings/hscarchive/2003/140103/c02.pdf
[7] http://www.citg.tudelft.nl/fileadmin/Faculteit/CiTG/Over_de_faculteit/Afdelingen/Afdeling_Waterbouwkunde/sectie_waterbouwkunde/people/personal/gelder/publications/papers/doc/paper10.pdf
[8] http://scholarworks.umt.edu/cgi/viewcontent.cgi?article=1331&context=tme
[9] http://dataportal.orr.gov.uk/displayreport/html/html/45fd875d-7ed7-450d-99e8-6f76c9727403
[10] http://www.parliament.uk/documents/lords-committees/digital-skills/Digital-Skills-Committee-Evidence.pdf
[11] http://www.parliament.uk/business/committees/committees-a-z/lords-select/digital-skills-committee/news/report-published/
[12] http://www.theguardian.com/world/2015/nov/15/french-train-crash-children-on-board-test-train-sncf
[13] http://digitalrailway.co.uk/wp-content/uploads/2015/11/Martin-Arter.pdf
[14] http://www.era.europa.eu/conferences/CCRCC%202013/Documents/ATO%20over%20ETCS%20-%20ERA%20-%20121113%20-%20v1%200.pdf
[15] http://orr.gov.uk/consultations/closed-consultations/railway-safety-consultations/crossrail-exemption-application-consultation
[16] http://orr.gov.uk/__data/assets/pdf_file/0007/19663/crossrail-exemption-application-consultation-tpsg.pdf
[17] https://www.nao.org.uk/wp-content/uploads/2006/11/060722es.pdf
[18] https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/410833/120627_R112012_Llanbadarn.pdf
[19] https://www.london.gov.uk/sites/default/files/transport_for_londons_signal_failure.pdf
[20] http://www.networkrailmediacentre.co.uk/news/network-rail-appoints-tube-upgrade-chief-to-spearhead-digital-railway
[21] http://www.networkrail.co.uk/news/2014/apr/New-managing-director-appointed-to-spearhead-%C2%A325bn-infrastructure-investment-programme/
[22] https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/229037/1025.pdf
[23] http://www.hse.gov.uk/research/rrpdf/rr151.pdf
[24] http://sebokwiki.org/wiki/System_Life_Cycle_Process_Models:_Vee
[25] http://www.iness.eu/IMG/pdf/psn_2009-09-29_baastad_2.2.pdf
[26] http://orr.gov.uk/__data/assets/pdf_file/0005/18851/cn031-nichols-assurance-for-major-programmes-part2-2015-07-31.pdf
[27] http://sunnyday.mit.edu/16.863/rasmussen-safetyscience.pdf
[28] http://www.ecgi.org/documents/sciback_ek_en_14.pdf
[29] http://www.rssb.co.uk/Library/improving-industry-performance/2013-report-risk-assessment-of-gsm-r-failures.pdf
[30] http://orr.gov.uk/__data/assets/pdf_file/0005/18851/cn031-nichols-assurance-for-major-programmes-part2-2015-07-31.pdf
[31] http://www.incoseonline.org.uk/Documents/Groups/Railway/RIG_061130_v1.pdf
[32] http://www.nobelprize.org/nobel_prizes/economic-sciences/laureates/2000/mcfadden-lecture.pdf