©Erik Hollnagel 2006
Achieving System Safety byResilience Engineering
Erik HollnagelIndustrial Safety Chair, Écoledes Mines de Paris, FranceE-mail: erik.hollnagel@cindy.ensmp.fr
Professor, University of Linköping, SwedenE-mail: eriho@ida.liu.se
Accidents, incidents
Safety as a non-event
Dailyoperation(Status quo)Unwanted outcomenexpected eventPrevention ofunwanted eventsProtection againstunwanted outcomesSAFE SYSTEM = NOTHING UNWANTED HAPPENSReducelikelihood.Reduceconsequences.Safety management must prevent/protect against both KNOWN and UNKNOWN risks.Safety management requires THINKING about how accidents can HAPPEN
©Erik Hollnagel 2006
Looking into the futureooking at the past
What has happened? What may happen?
Accident modelSimple linearComplex linearNon-linear*
* outcomes are not proportional toinputs, and cannot be derived froma simple combination of inputs
Risk modelComponent failuresCombination of failuresand degraded defencesPerformance variabilitycoincidences
©Erik Hollnagel 2006
Simple, linear cause-effect model
Assumption: Accidents are the (natural) culmination of aseries of eventsor circumstances, which occur in a specific and recognisable order.Consequence:Accidents are prevented by finding andeliminatingpossible causes.Safety is ensured by improving the organisation’s ability torespond.
Domino model (Heinrich, 1930)
Hazards-risks:Due tocomponentfailures(technical, human, organisational), hence looking forfailure probabilities (event tree, PRA/HRA).

