Risk! Engineers Talk Governance Podcast
Risk! Engineers Talk Governance is hosted by R2A Co-Directors, Richard Robinson and Gaye Francis, who discuss governance in an engineering context, with particular emphasis on due diligence, risk management, and workplace health and safety.
Bringing a distinctive approach to risk engineering, Richard and Gaye come from a common law viewpoint of what would be expected to be done in the event that something happens; which differs from just applying risk management standards. They combine common law principles with risk management to help organisations identify their risk issues and establish proper controls.
With over 60 episodes, the podcast explores a wide range of governance and engineering issues, and has received over 7,500 downloads.
Available on all major platforms including Apple, Spotify & Google Podcasts.
Hazard & Risk versus Threat & Vulnerability - Top down, Bottom up
Risk! Engineers Talk Governance
Season 8, Episode 6
In this episode of Risk! Engineers Talk Governance, due diligence engineers Richard Robinson and Gaye Francis discuss Hazard and Risk versus Threat and Vulnerability – Top Down, Bottom Up.
The podcast discussion includes:
How bottom-up techniques are creeping back into risk assessments, even though WHS legislation focuses on criticality and asks what is reasonable in the circumstances,
How prosecutions are shaping what "critical" means in practice,
Why cutting minor-incident rates doesn't remove fatality risk, and
Why the two methodologies each have a place if used at the right time.
If you'd like us to cover a specific topic or have any feedback we'd love to hear from you.
Timestamps
00:34 – Why revisit hazard and risk versus threat and vulnerability: a drift back to bottom-up techniques despite the WHS focus on criticality
01:13 – Prosecution patterns in Australia: SFAIRP is hard to prosecute, smaller organisations and repeat or multiple-fatality events get targeted
03:26 – WHS Codes of Practice are written around single-fatality hazards such as working at heights, and the language confusion that follows
04:03 – Bird and Heinrich's triangle, and the elimination of fatalities task force in underground mining
06:29 – WHS asks what controls are practicable and reasonable, not whether the risk is bad enough to act
07:18 – Hazard and risk as middle-management, bottom-up measures versus threat and vulnerability as national-interest, top-down thinking (the desalination plant and defence examples)
08:30 – Criticality in two bands: single or multiple fatalities versus rare mass-casualty events
09:16 – How major events change policy, and the New Zealand experience including the Port of Auckland prosecution
10:27 – Differing state approaches and the pending Safe Work Australia review
10:49 – Wrap-up: both methodologies have insight, so use each in the right place at the right time
Episode transcript
Megan (Producer) (00:00):
Welcome to Risk! Engineers Talk Governance. In this episode, due diligence engineers Richard Robinson and Gaye Francis discuss: Hazard and Risk versus Threat and Vulnerability - Top down, Bottom up.
(00:15):
We hope you enjoy the discussion. If you do, please support our work by giving us a rating and subscribing on your favourite podcast platform. And if you'd like more information on R2A, our newsletter and resources, or have any feedback or topic ideas, head to the website, www.r2a.com.au.
Gaye Francis (00:34):
Hi, Richard. Welcome to a podcast session.
Richard Robinson (00:37):
Hello Gaye.
Gaye Francis (00:38):
Today we're going to talk about, and we've talked about this probably an episode each of the seasons that we've done, but hazard and risk versus threat and vulnerability - top down versus bottom up. And the reason we're revisiting it is because we're sort of seeing that change again into more bottom up type techniques being used when they're looking at risk assessments. And even though the WHS legislation concentrates on criticality, which we've talked about in this podcast season as well, there's still that mismatch happening.
Richard Robinson (01:13):
Yeah. And there's a number of reasons for that. I think partly to do, remember we talked about the West Australian regulator who told us that one of the reasons why WA had taken so long to implement their Act was because they found prosecuting for SFAIRP to be difficult. And we've noticed that the prosecution for SFAIRP in Australia tends to be for smaller organisations and things like that, not for the big ones - the corporate veil still keeps working. But we have also noticed that the prosecutions seem to be, because there's two parts to this. I mean, first of all, what the legislation actually says, and then there's a propensity of whoever's going to prosecute to prosecute you. I mean, I believe you can still be prosecuted for being drunk in charge of a horse, but it doesn't happen very often, so nobody worries about it.
(01:55):
Now, what we've seen to be noticing is that the prosecutions are either to smaller organisations for a single fatality, or if it's a multiple fatality, then a larger organisation might be prosecuted. I mean, that's what happened with the volcano blowing up (in NZ).
Gaye Francis (02:11):
And we've seen a couple of cases of those in New Zealand, but I don't recall any in Australia being particularly done here.
Richard Robinson (02:17):
And the other one is where the same fatality incident has occurred sequentially -
Gaye Francis (02:24):
For the same organisation.
Richard Robinson (02:25):
For the same organization. So I mean, for example, the whole reason why the multiple fatalities, the raft flipped and the four young people got killed at Dreamworld, well, that's the multiple fatality situation. Now, what that effectively means, I think, is that from the point of view of Australian prosecutors at any rate, criticality is being defined as that multiple fatalities or a sequence. It's not just a single fatality unless you're a smaller organisation.
Gaye Francis (02:54):
Yes, it's a number of single fatalities within...
Richard Robinson (02:58):
Obviously, the Powerline Bushfire Safety Task Force, which we were on, there was 173 people got killed in the Victorian fires and South Australian fires. And that obviously created a great political outcry quite sensibly. And so fatality instance still seem to have that overflow, but what actually criticality means is becoming harder and harder to define from the point of view of probable prosecution.
Gaye Francis (03:26):
And I think you're right. And the WHS legislation is focusing on that single fatality type when they're doing up their Codes of Practice, they're typically for working at heights...
Richard Robinson (03:41):
Falling off a roof...
Gaye Francis (03:43):
Things like that. So things that are typically single fatalities at a time. So there's this, again, language thing, and we've addressed language in a number of our podcasts previously, but that confusion with language again and what terminology that's being used is creating a whole lot of confusion again.
Richard Robinson (04:03):
Yeah. Now the other reason why this sort of popped up, because we were talking about this in a threat and vulnerability, bottom up, top down. And this is an argument, far as I know, we used a very long time ago, Bird & Heinrich's triangle. Now Bird & Heinrich's triangle, basically, if you think of a triangle like that, what it's basically saying is a tenfold increase in consequences accompanied by a tenfold decrease in likelihood. Now, that's the same thing as the hyperbola, and I've talked mathematically how complicated trying to work out there under hyperbola is.
(04:33):
But one of the things which we didn't talk about then was, you see, and this partly arose because of the elimination of fatalities task force program when I was a member for the state mining engineer, WA, and they were investigating underground fatalities in WMC mines. And that is also the classic case where there's a series of fatalities. Remember they were killing one in a thousand employees per year in an underground mining explosion or event.
Gaye Francis (04:57):
That was before the WHS legislation came in.
Richard Robinson (05:02):
But that's where the political energy came in. Now, one of the strange things about the... I mean, it was a very popular philosophy there for a while. If you think of the triangle like that, the theory became that if you could decrease the... If that was a correct characterisation of how risk worked, then if you could cut your loss time frequency injury rate in half, then you'd shave half of the triangle, right? So where previously you would've had a hundred minor instance, 10 serious ones and one fatality. If you managed to chop that triangle in half, there would now be...
Gaye Francis (05:32):
One every two years or whatever it was.
Richard Robinson (05:34):
Well, you cut down the likelihood of this. If you can cut the likelihood of any small event down enough, then you prevent the big ones as well. And from my point of view, I think that the elimination of fatality task force, what it actually proved to me, that wasn't what actually happens. If you go for the lost time frequency injury rate, what you actually do is chop the sides of the triangle off and leave the pointy sharp bit where people are getting killed in place. And that's certainly what, at the time, the state mine engineer and WMC were focused on with their elimination fatality task force because they basically said: Well, okay, what kills people in underground mines and obviously is working under unsafe ground. You make the mine safe by putting rock bolts and shotcretes in to make sure the roof doesn't fall in on you, but we are actually mining, that's a problem. And so what they were basically doing is buying machines that you could work from safe ground into the unsafe ground. So if there was a collapse, it couldn't get you.
Gaye Francis (06:28):
You went there.
Richard Robinson (06:29):
Basically.
Gaye Francis (06:29):
And that's how technology's evolved over the years, isn't it? But it still is asking the question. I think that's where we've come to even where we are now is they're still asking the question: Is this bad enough that we need to do something about it? Rather than (what) the WHS legislation is saying: What are all the controls that you could put in place that are practical and which of those are reasonable in the circumstances? So you have to justify why you are not going to do things. But we've gone back to this bottom-up approach to say hazard and risk and the likelihood is discounting these critical events.
Richard Robinson (07:05):
That's right. Because if you've cut your likelihood down, you're good even though the fatality ones just stay put.
Gaye Francis (07:10):
And it doesn't change.
Richard Robinson (07:11):
It doesn't change.
Gaye Francis (07:12):
So we're still not looking from our perspective on what else could be done.
Richard Robinson (07:18):
And that's where this sort of language bit comes back again, because hazard and risk from our point of view is bottom up and focus of middle management for the things that happen a lot and therefore motivate middle management greatly because they can measure it and test it. Whereas threat and vulnerability, as I pointed out, ASIO basically do threat assessments. They don't do hazard assessments when you talk about the national interest, because from the point of view of the national interest, an individual fatality doesn't really make a difference. Whereas from the point of view of the national interest, World War III is absolutely critical.
(07:50):
And that example I used to give of the desalination plant in Victoria, why do we have one? We haven't taken any water from it and it's costing us $1.8 million a day and it's about $18 billion over the 25 year of the ownership of the thing. The answer was, well, we'd had 10 years drought and the cabinet of the day said: Well, if we have another 10 years drought we'd actually run out of water. And the answer to that was: We don't like that and we've got the resources to fix it. And that's the same thing with having a department of defense. If you don't ever fight a war, it's a complete waste of money, but when you need it, it's absolutely critical.
Gaye Francis (08:30):
I also think that what we've talked about in the office here is there's now criticality being separated into two bands in a way. There's those single fatalities and an event that can cause multiple fatalities like Dreamworld that we are talking about, that two, three, four. And then there's mass casualty events like we've seen in the natural events like flooding, train collision accidents, bushfires. So there is another level above that, but I think all of the...
Richard Robinson (09:01):
But that's very rare.
Gaye Francis (09:02):
Correct. Very rare. And there's only a small number of organisations that really have to concentrate on those sort of ones. And they're probably more... They're going to be looked at probably from a governance viewpoint.
Richard Robinson (09:16):
Well, it's one of the reasons I understand, just explained by railways people, the reason why New South Wales was always so keen on level crossings is because they'd had, I think it was in the 40s, a train ran into a bus load of school kids and the world changed.
Gaye Francis (09:31):
Yeah. So it was just something that they weren't going to ever have happen again.
Richard Robinson (09:35):
Well, they also are lumpier than Victoria, so it's easy to do.
Gaye Francis (09:38):
True, true. So I think there's this difficulty in language again, but the Work Health and Safety Codes of Practice and the Standards that New Zealand are introducing, they're sort of aimed at those single fatality band, isn't it?
Richard Robinson (09:56):
Well, it is interesting because they talked about simplifying the legislation in New Zealand for smaller organisations and they define more or less what criticality was, which means kill or maim for an individual organisation, for a smaller organisation. But then again, they went and successfully prosecuted the CEO of the Port of Auckland. But that was for the series of events, not just one.
Gaye Francis (10:16):
Correct. And I guess Australia's got a little bit more complexity in there in that we have different states and states are prosecuting in different ways as well.
Richard Robinson (10:27):
Yeah. And we haven't seen the final outcome of the health and safety review.
Gaye Francis (10:33):
No. So Safe Work Australia are doing a review and that was a report to go to the ministers in August and whatever feedback comes from that. We'll certainly update a podcast or do a podcast on that when we hear anything.
Richard Robinson (10:48):
Yep.
Gaye Francis (10:49):
All right. So I think just finishing off, hazard and risk versus threat and vulnerability, there is still a difference and both methodologies are being used out there.
Richard Robinson (11:01):
And both methodologies have insight, but you've got to make sure you use it the right place at the right time.
Gaye Francis (11:06):
Yeah. So just understand that, but also remember that the WHS legislation is really looking at here are good ideas, what is reasonable in the circumstances rather than the level of risk.
(11:19):
So thanks for joining us today, Richard, and we will see you next time.
Richard Robinson (11:23):
Thanks, Gaye.
Update: New Zealand’s Health & Safety at Work Amendment Bill (Receiving Royal Assent)
Risk! Engineers Talk Governance Podcast
Season 8, Episode 5
In this episode of Risk! Engineers Talk Governance, due diligence engineers Richard Robinson and Gaye Francis discuss New Zealand's Health and Safety at Work Amendment Bill, which received Royal Assent on 9 July and commences 1 April 2027.
They unpack the shift towards a focus on critical risks for small business and an expanded role for approved codes of practice, and question whether this makes the regime more prescriptive than the "reasonably practicable" standard intended. The conversation moves to a Wellington waterfront fatality case and the accountability questions it raises for local councils and their executives.
View the updated Act at https://www.worksafe.govt.nz/laws-and-regulations/acts/changes/understanding-the-changes-to-health-and-safety-law/
If you'd like us to cover a specific topic or have any feedback we'd love to hear from you. Email admin@r2a.com.au. For further information on Richard and Gaye's work with R2A, head to https://www.r2a.com.au.
Timestamps:
00:00 – Introduction
00:40 – NZ Health and Safety at Work Amendment Bill receives Royal Assent (9 July), effect from 1 April 2027
01:23 – Speed of the Bill through NZ Parliament compared to Australia
01:53 – Key changes: focus on critical events for small business; expanded role of approved codes of practice
02:34 – Tension between codes of practice as a "minimum standard" and the "reasonably practicable" objective
03:16 – R2A's process for testing and documenting what's reasonable in the circumstances
04:36 – Richard's two closing workshop questions, and using AI as a "watchdog" for critical issues
05:16 – Richard's experiment running local AI models on Mac hardware
06:15 – Controls evolve even when critical issues don't; AI as a possible future control or QA system
06:56 – Port automation, wearable tracking tech, and phone-based hazard alerts
08:04 – Recap: NZ's shift to criticality focus and increased use of codes of practice
08:38 – Port of Auckland CEO Tony Gibson prosecution and its link to the new amendment
09:13 – Case study: Wellington waterfront fatality (referred by NZ associate Frank Stocks)
09:41 – Details of the incident and the coronial inquiry
10:40 – Prior fatality two years earlier and unimplemented lighting/edge-protection recommendations
11:08 – Wellington council rejecting the recommendations
12:04 – Who bears liability — councillors vs council executive
12:50 – Parallel with Owners Corporation committees and volunteer liability in Australia
14:15 – Debate: should businesses be expected to know all their hazards?
14:49 – Prescriptive vs "reasonably practicable" regimes, and why WA delayed its own WHS Act
15:44 – Will Australia follow New Zealand's more prescriptive approach?
17:04 – Which legislation will apply if the Wellington case proceeds to prosecution
17:36 – Close
Risk, Uncertainty & Hallucinations
Risk! Engineers Talk Governance Podcast
Season 8, Episode 4
In this episode of Risk! Engineers Talk Governance, due diligence engineers Richard Robinson and (Risk Engineer Achievement Award winner!) Gaye Francis discuss Risk, Uncertainty, and Hallucinations.
Prompted by a recent course on AI and probability, Richards exaplins how large language models actually work as giant inference engines predicting the "most likely" next word, and why that's fundamentally different from genuine risk assessment.
They explore why AI can widen the number of scenarios you can process without ever solving the harder problem of criticality — the rare, high-consequence events that haven't happened before, but still need to be found and controlled by human judgement.
If you'd like us to cover a specific topic or have any feedback we'd love to hear from you: email admin@r2a.com.au.
For further information on Richard and Gaye's consulting work with R2A, head to https://www.r2a.com.au, where you'll also find their booklets (store) and a sign-up for the quarterly newsletter to keep informed of our latest news and events.
Apto PPE is also available via the R2A online store.
Show Notes
(00:56) Richard congratulates Gaye on winning the Risk Engineer Achievement Award at the Melbourne Engineering Excellence Awards, recognising 25+ years in risk due diligence, industry publications, podcasts, bushfire and public safety work, and advocacy for women in engineering
(02:27) Founding Apto (Women's) PPE and its impact at forcing the market to offer proper female PPE
(04:30) Setting up today's topic: why people still default to thinking about risk as consequence and likelihood, rather than criticality and control
(04:53) Richard's University of Helsinki AI course and the link between AI probability weighting and Markov chains, used at R2A for availability modelling
(05:32) Different types of probability — fixed-outcome events (a coin toss) versus genuine future uncertainty (geopolitical shocks, oil markets)
(06:18) How LLMs generate "hallucinations" (or Geoffrey Hinton's term, "confabulations"), tokenising context and predicting the statistically most likely next word, sometimes inventing plausible-sounding but false attributions
(07:16–08:16) AI as a Monte Carlo-style tool: useful for running large numbers of trials fast, but this doesn't eliminate criticality, it only shrinks the pool while critical outcomes still have to be identified
(09:08–09:42) The limits of AI's training cutoff; it can't flag risks that haven't happened before or reflect a rapidly changing context; identifying criticality still requires human judgement
(10:26–11:12) The risk of the next generation treating AI output as "gospel" without questioning it
(11:16–11:41) Wrap-up: risk as future uncertainty, AI as a tool for faster insight, but criticality and control remain R2A's core focus
Episode transcript
Megan (Producer) (00:00):
Welcome to Risk! Engineers Talk Governance. In this episode, due diligence engineers Richard Robinson and Gaye Francis discuss Risk, Uncertainty, and Hallucinations.
(00:14):
We hope you enjoy the discussion. If you do, please support our work by giving us a rating and subscribing on your favourite podcast platform. And if you'd like more information on R2A, our newsletter and resources, or have any feedback or topic ideas, please head to the website, www.r2a.com.au.
Gaye Francis (00:34):
Hello Richard. Welcome to another podcast session.
Richard Robinson (00:36):
Good to be here again, Gaye.
Gaye Francis (00:37):
It is good to be here. Today we're going to talk about risk uncertainty and hallucinations and also how it sort of relates to AI a little bit.
Richard Robinson (00:48):
And life in general, depending on what things you're thinking about.
Gaye Francis (00:51):
That is true. That is true. So yes, that's our topic for today.
Richard Robinson (00:56):
Yeah. Before I start, one of the things that did happen last week was that Gaye got to be announced as Risk Engineer of the Year, or more precisely I think it was, the Risk Engineer Achievement Award at the Engineering Excellence Awards in Melbourne. And the way it was expressed, so I'll just quote it: "Gaye was chosen in recognition of her distinguished contribution to risk engineering over more than 25 years. Her leadership in risk due diligence," (and note the due diligence part) "industry publications, educational podcasts, bushfire, and public safety initiatives, and work addressing risks faced by women in engineering has had significant and lasting impact on both the professional and broader community." Actually, that's actually probably truer than you realise Gaye because you sort of get embarrassed about these things.
Gaye Francis (01:41):
I do get embarrassed by these things because it's just what I do. It's a job I love doing.
Richard Robinson (01:45):
Yeah. In that sense, you do regard it slightly hallucinatory, even though that's not exactly what the subject of this thing was about.
Gaye Francis (01:51):
True.
Richard Robinson (01:52):
But I would just point out two things, because I don't even know actually if they understood this either, but when you worked in the Powerline Bushfire Safety Task Force and the continuing committee, and I do remember when you were doing it, because you asked whoever the chair was at the time saying, "Why I exactly am I here?" And I can't remember how they exactly expressed it, but they said, "You made everything work," or something like that.
Gaye Francis (02:18):
You could bring all the technical as well as the political elements and all of that aspect together and talk about in a due diligence or a risk context.
Richard Robinson (02:27):
But the other one was the Apto (Women's) PPE thing, which you genuinely undersell because of a whole lot of different reasons. But one thing we did always agree was if Apto PPE and you and Michelle and Larisse hadn't started and done it, because remember Engineers Australia tried to do it, but it couldn't work. So you actually started the company to make it happen.
Gaye Francis (02:46):
Correct.
Richard Robinson (02:46):
But the reason for doing it wasn't so much you were expecting to be a resounding financial success, which I can confirm it has not been.
Gaye Francis (02:52):
It has not been. <laughs>
Richard Robinson (02:54):
But what was to get the market and force the market to actually change their ways and take into account female PPE, which they have done.
Gaye Francis (03:01):
And I think they have, there's so many more options for females in our industry now than there was 13 years ago when we started it. And one of those is that many of our designs, well, a couple of our designs, including our maternity range, has been copied by the big guys.
Richard Robinson (03:17):
Reverse engineered I think is the technical expression Gaye.
Gaye Francis (03:21):
So yes, that's one of the things that I am proud of. But as I said, it was an honour to be recognised for it over very many years, but also a little bit, not embarrassing, but it's humbling because it's just recognition for a job that I love doing.
Richard Robinson (03:37):
Well, yeah. And we were talking before, I mean, once upon a time, and I can speak from history in here, under the Code of Ethics of Engineers Australia, you weren't meant to be self-laudatory. It was actually against the rules. And yet the world has changed so much, has it not? And those people who were sort of, shall I put it, in the old mold tend not to push themselves forward.
Gaye Francis (03:58):
That is true. That is true. And I think this award is a reflection of the R2A team in general. Over very, very many years, including yourself and past and present people that have worked through R2A. We've always worked with a pretty good group of people.
Richard Robinson (04:17):
Yes, we have. In fact, we've always enjoyed it too.
Gaye Francis (04:19):
Yeah, absolutely. So thank you for that. But yes, we might move on to the real podcast now while my cheeks settle from being a little bit red.
(04:30):
So risk, uncertainty and hallucination. And I think one of the reasons this came up was we delivered a course last week in particular and people talking about risk and as part of this award was they're still thinking about risk in terms of consequence and likelihood.
Richard Robinson (04:47):
Rather than criticality.
Gaye Francis (04:48):
So when we say due diligence, we're really talking about criticality and control.
Richard Robinson (04:53):
Yeah. Now part of the reason for this was, I can't remember if I'd said previous podcast, but I'd done that one day course from the University of Helsinki, which if you're interested in AI, you can go and do. And it was quite interesting, but they were talking about, and they were explaining how the probability and the weightings work and all those sorts of things for AI. But I was reading something a bit later and I suddenly realised they would start talking about Markov chains. Now Markov chains is something we use really for availability modeling at different times, but you can explain all this in terms of Markov chains and the probabilities. Now that sort of brought us the conversation a bit before we started the podcast about what constitutes risk and probabilities. And one of the difficulties we've always had is that there are different types of probabilities out there.
(05:32):
If you're just talking about flipping a coin toss, there are fixed outcomes. It's heads or tails. Some people have the misfortune of it landing on its edge, but there are actually only a fixed number of outcomes. When you look at the current world and you're looking at all the oil shocks and the Houthis and the different things happening in the Middle East and the things that are going on, you're looking at a future with uncertainty like that, that is a completely different kind of uncertainty. It's not just a mathematical one or the other. And this is then explaind in one way with this hallucinations things they talk about or confabulations, as Jeffrey Hinton put it, from the AI is coming because you get a lot of people using AI more or less as truth and gospel and sometimes it's not exactly precisely what's going on.
(06:18):
And the best way to explain it, I could think of it, was that if you think about it as a series of, I don't know if your memory about Markov chains is all the best, but basically it's a whole series of probabilities. In a sense, you could think of as falteries integrating below. But what it does, if you have a statement, you say, "In this context, I want you to answer this question." So it converts all the context into tokens and then that puts it into probabilities and then it looks at what the next word's going to be in terms of the question that you answer. But that means it's just acting as a giant inference engine. So if it thinks a certain author, for example, is normally for a question in that context, then it will suggest that this is the right author. And then it will say, "Well, this is what such an author would say in this context." The fact there's no particular reference to that author and that it's actually just made it up. It's just a consequence of it actually expressing the sheer probability outcome, this is the most likely thing to happen.
Gaye Francis (07:16):
And I think that's what we talked about, wasn't it? It's that risk in its context of likelihood and consequence. It will give you your most likely outcome, a bit like Monte Carlo simulations will give you your most likely outcome.
Richard Robinson (07:29):
Yes, that's correct. So it's not an error. But see, that was one of the other things that we sort of realised because the thing actually completely, I always find it incomprehensible, is in order to create these giant probability matrices of all these interlocking markov chains and put all the weights into all the vector and the numbers like that, the sheer quantum of that information, and that's why it can actually predict or say what it believes the right inference should be. My mind just basically just doesn't actually function. But in terms of the way it's working, because one of the comments we make about doing the probability add-ups and things like that is you've got to do a number of trials in order to find what the final probability distribution is. You can send an AI agent out there now to go and do those trials for you in effect.
(08:16):
And so where we previously commented that in order to find a one in a billion chance of three probability distributions, all the long tails summing together, theoretically now you've got to tell an AI agent to go and do that many trials. Now the consequence of all this though is that it doesn't actually eliminate the criticality question because you still got that. You may have reduced the size of the criticality pool, but in terms of the critical outcomes, they still just sit there waiting for you.
Gaye Francis (08:45):
So it does two things. I think the opposite is that it expands the number of cases it can look at because it can look at more scenarios faster. So the ability to process information and data is getting easier. But you're right. What it doesn't do is get rid of or be able to identify all those critical ones, which are the process...
(09:08):
Because it's doing from the background when it was last trained. I mean, Gemma four, I think it was last trained in January 25.
(09:15):
But it's no different to saying, "Oh, well, if it hasn't previously happened, then we don't know about it."
Richard Robinson (09:20):
Yes.
Gaye Francis (09:20):
But we know in projects and in organisation and in safety issues, there are some things that can happen that haven't happened for a very long time or haven't happened before because the context and our environment is changing so much. And so I think the criticality aspect of it, we still need to think. It still requires a human to think it through.
Richard Robinson (09:42):
I think that's what we keep coming back to. And the fact that if you're just using these probability things and it's a giant inference and just say this is what ought to be the case, that hasn't been the way the world's worked.
Gaye Francis (09:54):
No. And I think it's useful data, right? It's useful insight that you can, but you got to understand the limitations of it.
Richard Robinson (10:01):
Correct.
Gaye Francis (10:01):
Which is what we say about all the risk and due diligence tools that we have. They all have different purposes and provide different insights. And depending on the question you want to answer, depends on which...
Richard Robinson (10:12):
And the context of the question you want an answer on, that's correct.
Gaye Francis (10:16):
So I think, again, AI is great. It provides some insight, but you have to have an understanding of what that does.
Richard Robinson (10:26):
Well, I think it's going to be the problem is that from our point of view, so the next generation's going to adopt AI with this enthusiasm that perhaps the rest of us don't share.
Gaye Francis (10:36):
And I think we've talked about that in another podcast. I've got younger children, well, not so young anymore....
Richard Robinson (10:43):
They were both at the Excellence Awards and they both carried themselves very well, Gaye.
Gaye Francis (10:46):
Thank you, Richard. I was very proud of them. Mark (husband) and I were very proud of them. But AI is part of their life. And so if AI pops something up to them, they're taking it as gospel. And I think that's the scary thing about it, that the information's there, but how do you interpret what's real and what's not? And I don't know that we know the answer to that.
Richard Robinson (11:12):
Well, that's why being a parent's more complicated than you might think, Gaye.
Gaye Francis (11:16):
<laughs> Thanks, Richard, for that advice. So again, risk and uncertainty. We certainly use the term risk to mean future uncertainty.
Richard Robinson (11:26):
That's the way we use it. Yes.
Gaye Francis (11:27):
That's the way that R2A uses us. We still focus on that criticality and control.
Richard Robinson (11:32):
Correct.
Gaye Francis (11:33):
But tools such as AI is helping to give you more information faster, I guess.
Richard Robinson (11:41):
And spot trends and produce.
Gaye Francis (11:44):
So it's certainly providing great insight going forward. So I think we might wrap today's podcast up. Thank you for joining us, Richard, and we'll see you next time.
Richard Robinson (11:54):
Thanks, Gaye.
Reactive vs Proactive Due Diligence - What does R2A actually do?
Risk! Engineers Talk Governance Podcast
Season 8, Episode 3
In this episode of Risk! Engineers Talk Governance, due diligence engineers Richard Robinson and Gaye Francis discuss Proactive vs Reactive Due Diligence - what does R2A actually do?
In their chat they unpack why timing changes everything and that proactive work happens before problems occur, while reactive work (like expert witness testimony) occurs after something's already gone wrong, and by then it's often too late to fix cheaply.
Drawing on real examples, they explain why early engagement is cheaper, less adversarial, and allows genuine design fixes happen while there's still time.
Timestamps:
00:00 – Introduction
00:40 – Why this topic: R2A is often asked "what do you do?"
01:08 – The core frustration: being brought in for "proactive" due diligence too late in the project
01:39 – Why engineering-style thinking beats legal philosophy for avoiding mistakes
03:19 – Why lawyers and busy clients use R2A
03:54 – Bringing multiple stakeholders' views together into one structured conversation
04:22 – Case example: Brought in practively
05:24 – What proactive due diligence actually delivers: structured, defensible clarity
06:28 – Why proactive due diligence doesn't need to be difficult or expensive
06:58 – Aligning siloed stakeholders (commercial, legal, operational, regulatory)
08:12 – Why design-stage fixes disappear once a project reaches "practical completion"
09:23 – Case example: relocating a Queensland switch yard to design out a hazard early
10:00 – The payoff of early engagement: easier process, stakeholders on side
11:01 – Swinburne University postgrad unit on project due diligence
11:36 – Why some people grasp the criticality-and-control approach instantly — and others don't
12:00 – Wrap-up
Note, they mention discussing NZ Harbour in the last episode, this will be the next episode (#4).
If you'd like us to cover a specific topic or have any feedback we'd love to hear from you.
Episode transcript
Megan (Producer) (00:00):
Welcome to Risk! Engineers Talk Governance. In this episode, due diligence engineers Richard Robinson and Gaye Francis discuss Proactive versus Reactive Due Diligence - What does R2A actually do?
(00:15):
We hope you enjoy the chat. If you do, as always, please support our work by giving us a rating and subscribing on your favourite podcast platform. And if you'd like more information on R2A, our newsletter and resources, or have any feedback or topic ideas, head to the website, www.r2a.com.au.
Gaye Francis (00:35):
Hi, Richard. Welcome to today's podcast.
Richard Robinson (00:37):
Hello Gaye. Good to be here.
Gaye Francis (00:40):
The sun's shining, spring is springing, so that's always good.
Richard Robinson (00:43):
Spring has sprung, the grass is "ris". Yes, I know.
Gaye Francis (00:46):
Today we're going to talk about proactive versus reactive due diligence. And one of the reasons for it is we often get asked, "What do you do?" And I know that we've talked on our podcast around some expert witness stuff that we've done, but that's really not what we do on an everyday basis. That's probably 10% of what we do.
Richard Robinson (01:08):
Or less.
Gaye Francis (01:08):
Or less, correct. And one of our key frustrations is being invited to do what (organisations) intend to be proactive due diligence way too late in the game.
Richard Robinson (01:20):
Correct. It's either the events happened or it's the project's almost complete and they're trying to rush somebody in to fix things that should have been thought about a bit earlier. And obviously this is not a subject that we can talk about because people don't like to admit they needed people like us at that point.
Gaye Francis (01:35):
Correct. So it'll be a very general conversation. <laughs>
Richard Robinson (01:39):
But I think the point, if you ever wind up going to court, I mean from our point of view, it's...
Gaye Francis (01:44):
Too late.
Richard Robinson (01:45):
Too late. I mean, you've still got to go through the process, but I was reading David Howarth, the professor of law and public policy that we invited out to Melbourne before COVID, a long time ago now. But I was just reading, and this is on his profile in I think the law society of the UK. But he's just sort of making a couple of points about philosophy of law and the difficulty that judges have, because I've got to agree that the judges are in a really, really difficult position. So he's making the point that the philosophy of law is not particularly helpful when it comes to the fundamental legal objective of avoiding making mistakes. And that's his book, Law is Engineering, which is why we were interested in him.
(02:22):
He said: Engineering with its focus on not just design, but also safety is quite simply a better guide he thinks. Engineers are safer than lawyers because they must design with an eye to neighboring structures and the environment. Instead, in common law jurisdictions, it's left to the judges to manage all the resulting tensions. They need to have an eye on the case, an eye to the system as a whole, while deciding something very specific for the short term. Precedents direct our compliance, even though all our examples of laws that have, by definition, because they've entered in litigation in some way failed. And he considers this to be very unsatisfactory.
(02:57):
And I think we agree. I mean, we don't like being expert witnesses after the event. We'd much sooner have not had the situation arise in the first place.
Gaye Francis (03:06):
Correct.
Richard Robinson (03:07):
And most of the cases that I think we've dealt with, in hindsight, as far as we could tell, they could have all been avoided in some way or another.
Gaye Francis (03:16):
Well, there were other controls that could have been put in place, yes.
Richard Robinson (03:19):
Or other ways of thinking about things, which if everyone had been clever, that would've been the case. And so that's very frustrating for us. And what I guess surprises us, I mean the people who use us regularly, they're doing it because they're typically busy people, that's number one.
Gaye Francis (03:37):
Correct.
Richard Robinson (03:38):
They know they've got a concern, which they know if it doesn't go well, there's going to be difficult to handle, particularly in a legal sense.
Gaye Francis (03:45):
So that pink elephant syndrome...
Richard Robinson (03:47):
Yep.
Gaye Francis (03:48):
It (the pink elephant) might turn up.
Richard Robinson (03:49):
They know that we've talked to their lawyers and that whatever we do will keep the lawyers pretty much happy.
Gaye Francis (03:54):
The process will be diligent and seem to be diligent. And I think the other key thing is that there's often quite a number of stakeholders involved who have different opinions about the same issue. And so what our process does is it facilitates bringing all of that conversation together and having all of those views presented in a way that can then be talked through. And don't get me wrong, they're never always straightforward, are they?
Richard Robinson (04:22):
Nope.
Gaye Francis (04:22):
But it allows that robust discussion to happen and each party's views to be heard from their viewpoint. And what is the collective? And we've talked about this before, that collective and that cooperative approach gives you the results.
Richard Robinson (04:40):
Well, it's kind of interesting because I mean, we've talked about Wellington Harbour and the various drownings, and we can't really say who we've done it for, but we've done some recent work in New Zealand and what we were doing, and you went and visited, what we were doing is collecting all the different points of view. And remember we had a serious conversation with their lawyers up front making sure. And they were basically testing us to make sure that when R2A was doing all this material, we weren't setting anybody out for a fall, but it really would produce a robust, useful result that would satisfy hopefully in the increasingly unlikely event of a coronial inquiry, everyone would say, "Well, you, the council have done every reasonable practical thing we could. It's just life."
Gaye Francis (05:24):
So that's what we call the proactive due diligence aspect that we do. And I think that's where we bring the value is that it's part thought leadership, but it's also that clarity of thinking and taking people through a structured process in a way that everyone understands and can almost sign off on the due diligence decision that the organisation comes to for that particular issue.
Richard Robinson (05:48):
Correct. And it's like when we talk to the lawyers, we usually make that line. It's very difficult to get a lawyer to sign off on anything. But what you're really looking for is the lawyers to say, "Yeah, we see nothing wrong with what you propose." And when you finish the work, we do expect the lawyers to review it. And you might remember that the water board up north who said, the lawyer looked at us and said something to the effect that you people actually did what you say you were going to do, which I found completely irritating, but anyway.
Gaye Francis (06:17):
Well, you would hope you did what you said you were going to do, but apparently that's not always the case. No, you've lost me with it. <laughs>
(06:28):
So yeah, that proactive due diligence, it doesn't have to be difficult. It's a clear thinking exercise rather than, because people do know that the world's full of problems, as we said. There's some that you've got to make sure that you deal with and seem to be dealt with.
Richard Robinson (06:44):
It's the critical ones.
Gaye Francis (06:46):
Critical ones, absolutely. So by focusing on that, you can then focus on the controls that you're going to put in place, which is the key thing, and all your stakeholders that are then on the same page.
Richard Robinson (06:58):
That's correct. And I have noticed, and that's the other reason why people use us a lot. If you are in silos, you've got asset owners and operators and field staff...
Gaye Francis (07:09):
Maintenance people.
Richard Robinson (07:10):
All the different parties. Yes, the commercial people have an objective. The legal people have an objective. The operational people have an objective. The government's got regulations. I mean, you've been doing these regulatory reviews, particularly for ESVs for electrical networks. And they're trying to make sure all these things align in a constructive and useful way because it's self-evident. You can't afford to pay for everything. I had this discussion with my brother on the weekend about bushfires again, but he had observed that putting underground power lines in would stop bushfires just as a passing remark. I said, well, yep, we thought about that hard on the power line bushfire safety task force, but you're not going to abruptly underground all the power lines in Victoria because it's not commercially possible.
Gaye Francis (07:52):
Correct.
Richard Robinson (07:52):
But new estates and new houses, services are mostly underground these days.
Gaye Francis (07:59):
Yeah. And I think that's where it is. It depends on where you are in your project. And one of the frustrations for us is some of the issues that they've identified that have really quite simple controls that could be put in place, i.e. designed out.
Richard Robinson (08:12):
At the start.
Gaye Francis (08:13):
At the very, very start of a project, by the time you're at that terrible term, practical completion in inverted commas, there's no way that you can do that anymore. And so you've got this, we'd like to use pink elephant almost sitting there in the wings, potentially waiting to happen, that doesn't have a lot of controls that you can now put in place because you're so far into it.
Richard Robinson (08:38):
That's right. And it's a high consequence, low likelihood event. And so the likelihood is that it won't happen, but if you took all those places and all those projects, it will happen somewhere.
Gaye Francis (08:48):
Correct. So I think the value of the proactive due diligence, and it doesn't have to be an expensive exercise. You're not talking hundreds of thousands of dollars, you're talking tens of thousands of dollars, small tens of thousands of dollars that you could get a handle really of what your key issues are, what your controls are in place. And I think even sometimes it'd actually start thinking about would we actually go down that path if there were those potential showstoppers?
Richard Robinson (09:23):
Well, you might remember that, and it was a long time ago now, but in Queensland, the power company who had a switch yard next to the railway line, that was the proposal from a sighting and where the power lines were. But obviously earth return currents with metal rails around means you can propagate a hazard a long way unexpectedly. And in the end they just decided the easiest thing was to relocate it far enough away, sell the site, buy a new one a bit further away. Yes, you had to run power lines to and from it, but that hazard was basically gone. And that was a planning solution. And the only reason why it could happen is because they asked early.
Gaye Francis (10:00):
Yes. So I think for us, if you can do this due diligence stuff early in your project or early in your organisation and it's proactive rather than reactive, a lot easier to do. And you often got all your stakeholders on side as well. And it's a process that's then not in your face.
Richard Robinson (10:25):
Well, I always find it strange because we try to publish things, but the only things we're allowed to publish are the ones that went well by definition, because particularly if you're dealing with governments, they will never let you publish. And yet the ones we spend most of our time on, probably the government projects that haven't gone as well as they should. And yet the ones where we were involved early
Gaye Francis (10:45):
Just went smoothly.
Richard Robinson (10:47):
Anyway.
Gaye Francis (10:48):
And I think it is important that even though we help organisations facilitate the process in a proactive manner, the decisions that come out of it and the way forward, the organisation has to run with.
Richard Robinson (11:01):
I suppose we should actually mention in passing, we're still doing that classes at Swinburne Uni, the post-grad unit in engineering on project due diligence. You always slightly mystify the next time it pops up because it always happens in school holidays.
Gaye Francis (11:13):
It does happen during school holidays, but that's alright. So yeah, they've got students going through their post-grad course. It's an engineering course, isn't it?
Richard Robinson (11:23):
It's post-grad engineering.
Gaye Francis (11:24):
And we always do the project due diligence stuff with them and get them to do an assignment. So it's something that we certainly encourage and encourage our clients and our students to do in a proactive manner.
Richard Robinson (11:36):
And it always interests me because some of the students get it...
Gaye Francis (11:42):
Straight away.
Richard Robinson (11:42):
Straight away and it just becomes obvious to them. And other people, for example, try to use the Risk Management Standard, hazard and risk rather than criticality and control and come badly unstuck. Even though once we've explained it...
Gaye Francis (11:55):
It's so obvious.
Richard Robinson (11:56):
Well, we continue to think it's so obvious. <laughs>
Gaye Francis (11:58):
That's right. All right. So we just wanted to outline the difference between proactive and reactive due diligence today and that we are getting questions around what the value of doing some of the processes are. And as you can see, we still believe in them heavily. So thanks for joining us today, Richard, and we'll see you next time. Thank you everyone.
Richard Robinson (12:20):
Thanks Gaye.
Elimination Has Its Own Hierarchy Of Control
Risk! Engineers Talk Governance Podcast
Season 8, Episode 2
In this episode of Risk! Engineers Talk Governance, due diligence engineers Richard Robinson and Gaye Francis discuss how Elimination Has Its Own Hierarchy Of Control.
They unpack how the traditional hierarchy of controls (elimination, substitution, isolation, engineering, admin, PPE) collapses under WHS legislation into eliminate–prevent–mitigate, and why the elimination step can't be skipped until it's genuinely tested and ruled out. Using real examples, from rockfalls above a Sydney rail line to level crossings, they show that "eliminate" usually means choosing between stopping one activity, stopping another, or re-engineering the interaction entirely, and why that reasoning needs to be documented, not just assumed.
Timestamps:
00:00 – Intro: elimination and its own internal hierarchy of controls
01:03 – The traditional hierarchy of controls explained via a noisy machine example, plus WHS legislation's eliminate–prevent–mitigate structure
03:49 – Why elimination must be properly tested before moving on — illustrated through the Lapstone rockfall case (stopping trains vs a tunnel vs doing nothing)
06:15 – Level crossings as a three-way elimination choice (stop trains, stop cars, grade separation), plus the dam wall and airspace design examples
09:09 – The governance shift: formally documenting why eliminated options were ruled out, and using threat barrier diagrams to test reasonableness
11:31 – Wrap-up, including the Comeng trains example of an elimination option that's valid but cost-prohibitive
If you’d like us to cover a specific topic or have any feedback we’d love to hear from you.
Episode transcript
Megan (Producer) (00:00):
Welcome to Risk! Engineers Talk Governance. In this episode, due diligence engineers Richard Robinson and Gaye Francis discuss how elimination has its own hierarchy of control.
(00:12):
We hope you enjoyed the chat. If you do, please support our work by giving us a rating and subscribing on your favourite podcast platform. And if you'd like more information on R2A, our newsletter and resources, or have any feedback or topic ideas, head to the website, www.r2a.com.au.
Gaye Francis (00:33):
Hi Richard. Welcome to a podcast session.
Richard Robinson (00:33):
Good Morning, Gaye.
Gaye Francis (00:35):
Today we're going to talk about elimination and that it has its own hierarchy of controls and the way that people think about it when they're going through the elimination option. But I thought what we'd do is we go through what people traditionally think of the hierarchy of controls from the code of practice, how it also relates to safety and design, and then the hierarchy of controls in the WHS legislation, but then go to the elimination option.
Richard Robinson (01:03):
Yeah, that's right. And the reason why we talk about the hierarchy in the elimination option, from a criticality viewpoint, that's where you always want to start. So what I thought I'd do, just summarise what the code of practice for OHS/WHS hierarchy of control roughly is within a simple example. So I mean, most people remember we've got the elimination option, then you've got substitution isolation, engineering controls, then you've got admin and then PPE. That's the normal way of thinking about it. And that's been done for what you might call common hazards. A typical common hazard is a noisy machine. And so you don't want to get people hearing damage and you've got a particularly noisy machine around. Well, obviously the elimination option is to either throw the machine out altogether...
Gaye Francis (01:43):
Stop that process.
Richard Robinson (01:44):
Stop that process. Or you could substitute it with a quieter machine, which you could obviously do. You could isolate the machine and that could be done, depending on what you're talking about. If it's a vibration noise, you could isolate it with rubber mounts and things like that. Well, that's probably engineering controls. Or you could put an engineering control in which is typically, let's put an acoustic guard on this thing, just cover it up and just keep the noise inside the box.
(02:09):
Then you can go with the administrative control and administrative control would mean like putting somebody four hours in the noisy environment, four hours in the quiet environment. So the total noise exposure LEQ is 85 dBA, I think is the way it's normally expressed. Which would work. And then you can go with the hearing protection, which obviously is hard to make people wear properly. And you've got to have enforcement procedures and controls and actually quite hard work for the relative effectiveness of it. I mean, one of the reasons why people wear a lot of this stuff in industrial sites, hi vis and things like that, it's not so much because they're actually expecting it to be beneficial, I think. It's more a security thing. If somebody isn't wearing that stuff, who are you and what are you doing here?
Gaye Francis (02:51):
That's an interesting way to look at it. Yes.
Richard Robinson (02:54):
I've seen that done quite a lot.
Gaye Francis (02:55):
You have to have the right gear to be onsite.
Richard Robinson (02:57):
Because if you're just walking between somewhere, there's no noisy machines, there's nothing's going to fall on you. But once you go past that fence, if you're not wearing PPE, you're not one of us.
Gaye Francis (03:07):
Yep, that makes sense.
Richard Robinson (03:09):
Anyway, so that's the way it's traditionally expressed. Now, obviously the Work Health and Safety legislation's got a peculiar hierarchy because it says you've got eliminate, if you can't eliminate, then you reduce. And most people then use the hierarchy of control as that risk reduction.
(03:25):
We've noticed that the courts, which we've talked about many times, actually has a hierarchy of three. You eliminate, and if you can't eliminate, then you prevent, and then you can't prevent, then you mitigate and you can break those controls that I just talked into pretty much into those categories. But one of the things we have noticed is because we have this problem all the time, because when we're dealing with critical hazards, we always have to test that elimination option quite thoroughly.
(03:49):
And when you go through that, you sort of discover there is actually a hierarchy of options in the elimination category. And I don't think people think this thing through properly because you really can't go under the WHS legislation to the...
Gaye Francis (04:03):
Prevention options.
Richard Robinson (04:05):
All the reduction options until you've actually properly demonstrated that you've explored the elimination options.
Gaye Francis (04:10):
And I think just as a little aside before we go on to that, that often we see that not being done, especially in safety and design exercises.
Richard Robinson (04:18):
Yeah, it's right at the start.
Gaye Francis (04:20):
But the elimination option is often passed over very, very quickly.
Richard Robinson (04:24):
Well, that's right. Now we've sort of seen this over a long period of time. So I mean, some of the examples in our book, I mean, I don't know that we actually express it that particularly thoroughly. I mean, for example, remember we had the lapstone cutting and they had the rocks being manufactured off the cliff and we were particularly concerned because there's a photograph of a huge rock and we were allowed to publish that and we got permission from the legal authorities and so forth to do that. But there's this huge rock sitting on the track and it's big enough to (throw) a Sydney electric train into Lapstone Gorge. And as we've commented, I think there's probably, what, half of crush loading on, probably 700 people potentially.
Gaye Francis (05:00):
Potentially on the way back.
Richard Robinson (05:01):
And so in the end we got hauled in basically, I won't go through the whole story again, but we actually got hauled in affected by the asset manager with the lawyer's approval to try and resolve the situation. Now most people, when they think of the elimination option, they think of stop whatever you're doing. We've tried this in New South Wales suggesting that they stop running the trains.
Gaye Francis (05:23):
It's not successful.
Richard Robinson (05:25):
In fact, it's actually something of a social disaster.
Gaye Francis (05:28):
True.
Richard Robinson (05:29):
But you've got to explain why you couldn't, it's unreasonable to do it. But then the next option then becomes, well, how do you deal with this thing? Well, there were a number of design solutions, but the most obvious one is you go and put a tunnel in so you don't have this cliff face above you that can manufacture rocks.
Gaye Francis (05:43):
Well, it's the interaction, isn't it? You stop the interaction between the train and the rocks.
Richard Robinson (05:47):
That's right. So you just go into a tunnel and you don't have a problem. Now obviously the stopping the train option wasn't on the table. It got kiboshed pretty quickly. And then you sort of say, okay, well why can't...
Gaye Francis (05:56):
Well, it wasn't SFAIRP, Richard.
Richard Robinson (05:58):
No, it wasn't. Well, neither was putting a tunnel in because by the time you start, everyone can say, well, we could put a tunnel in for that particular cutting. But if you ever happen to deal with Sydney trains, there's got quite a few other cliffs and blue mountains that you have to fret about. So you'd have to start putting tunnels everywhere.
Gaye Francis (06:15):
And so you couldn't implement that as a policy level of control.
Richard Robinson (06:18):
That's correct. But historically in New South Wales, they have implemented a policy level. They've always had grade separation. Victoria never got big on it until recently, but (NSW) had. And I've never actually researched this, but I remember I was talking to somebody in railways in New South Wales and just asked the question. They said, oh, it was all because I think in the 1930s or 40s, I couldn't remember exactly when, but a busload of kids got hit by a train on a level crossing in New South Wales. And the horror of that was so great that the New South Wales government said, "We don't like level crossings." And because they're a lumpier place, getting rid of level crossings was actually easier for them. But as a principle, as a design concept, they just didn't build...
Gaye Francis (06:56):
Level crossings to prevent car and train interactions.
Richard Robinson (07:02):
And in Victoria, because we're basically a flatter place, and that's why we like broad-gauge and so forth and all these other things, we basically, until the traffic buildup was so great that we just couldn't handle it anymore, we didn't get rid of them. But in the hierarchy of control, that's the other thing. I mean, if you've got a level crossing that you don't like, well, what are your options? Stop the trains. That's one elimination option.
Gaye Francis (07:24):
Stop the cars.
Richard Robinson (07:25):
That's the second elimination option. What's the third one? Grade separation. And that actually exists just about everything we've ever done, those options always seem to exist. And I don't think people sort of think through that hierarchy. I've never seen it formally expressed anywhere. Although once you say it, it's sort of....
Gaye Francis (07:46):
Obvious that it follows a hierarchy, as you said.
Richard Robinson (07:50):
Yeah. But the other point about it is that stopping things, I mean, if you think something's prohibitively dangerous, you've got to stop it. You might recall, I forget which dam it was, but the tow of the dam wall was moving and the structural engineers, I think, and the dam safety guys thought that they had about a one in 300 year failure, I think, or something like that. And when they actually drained it and had a look, it was sort of a heck of a lot higher than that. And they were all sort of freaking out. But that one there, you have to actually re-engineer it. There's no other option. If you want to have a dam with all this water behind it that I think, I forget which one it was, but several times Port Phillip Bay's volume. If you want to flush the mouth of the Murray out, that would've done it. But a lot of the time, particularly when you're talking about interactions, you're talking about ships and aircraft and things like that, we talk about all these different options, but we never formally think it through and we never formally test it with the group.
Gaye Francis (08:46):
Of stopping the activity.
Richard Robinson (08:48):
Well, stopping the activity and what could you do and replace it with something else? I mean, when we talked about airspace design, you remember Tapau and those sorts of things like that. Obviously banning a particular user that's causing the grief is clearly an option every time. But nobody wants to do that. So it sort of gets thrown in the rubbish bin more or less immediately.
Gaye Francis (09:09):
I think the importance of some of those things now, and some of the examples we're talking about are quite old and potentially before the WHS legislation, but the importance of looking at those items now is you really do have to consider them and articulate why you are not going to do them. So it's a bit more formal. It's becoming a governance process of why you've considered those things and why you don't think that they're SFAIRP. And it often comes down to that utility of conduct, doesn't it?
Richard Robinson (09:38):
Correct.
Gaye Francis (09:39):
What other good things go missing because you adopt that course of action?
Richard Robinson (09:42):
Stopping Sydney trains because rocks could fall on the track is not really possible.
Gaye Francis (09:46):
No.
Richard Robinson (09:47):
And it didn't take much to come to that understanding, I might add. It was sort of self-evident.
Gaye Francis (09:51):
And I think we probably, everyone had it in their mind, but it wasn't articulated in a way and documented in a way.
Richard Robinson (09:58):
We never formally said this isn't practicable. We just moved on to the next option, which was, well, let's put a tunnel in and see how that goes. And everyone looked at each other and said, "Well, do you guys understand how much that's going to cost?" And then we've got to do it for all the other cliff faces and everyone goes, "Oh yeah, we're not going to do it."
Gaye Francis (10:14):
I think that's one of the beauties of the threat barrier diagrams that we use. And by putting all of the controls on the table, and this season is focused at criticality and control, what are all the controls? And that's what the WHS legislation asks you to do. What are all the possible controls and what are reasonable in the circumstances? So in the circumstances, stopping the trains was not considered reasonable.
Richard Robinson (10:39):
No, that's right. But it's like single line track and safe working systems. If you've got crossing loops, I mean obviously from a train efficiency movement and things like that, having two tracks, one going each way up and down, makes life relatively simple. Once you start to have single line track and you've got crossing loops, it suddenly gets really complicated. And if you don't want to have head-ons, go with two parallel tracks. That's really simple. Obviously, if you're talking about Australia and you're talking about going from here to somewhere, that can be having two tracks is very, very expensive. You might notice that they're going to put a train from up central through the Nordic countries and possibly across the Helsinki through the Sulwaki Gap. Because they want to get it done in a hurry, they're going for single line, but they're building it with a theory that it will be dual two-way running.
Gaye Francis (11:27):
Future-proofing, imagine that. <laughs>
(11:31):
So I think what we'd say in this that although you probably haven't formally though it through, there is a hierarchic controls in the elimination option, but we are still seeing the elimination option not being given a lot of thought, especially in safety and design exercises.
Richard Robinson (11:48):
And from a criticality viewpoint and what we understood the OHS Act and WHS legislation to be about.
Gaye Francis (11:55):
From a control viewpoint, you have to consider elimination first.
Richard Robinson (11:58):
And you have to explain why you're not going to do it, and you need to have thought through the option then said why you're not going to do it.
Gaye Francis (12:03):
So elimination, there may be a number of options available for elimination.
Richard Robinson (12:08):
Correct.
Gaye Francis (12:09):
As we've just discussed.
Richard Robinson (12:11):
I mean, I jumped on a comeng trains this morning. They're on the way out and they should be extinct. They've got a lot of problems. And obviously if you want attraction in locking on trains, the elimination option is get rid of comeng trains. But to abruptly do that costs a lot of money.
Gaye Francis (12:27):
And to keep providing the service that you want to provide and all of those sort of things. So there's reasons why it's not done, but you do have to explain why that is the case.
Richard Robinson (12:35):
Yes.
Gaye Francis (12:37):
Alright. Thanks for joining us today, Richard, and we will see you next time.
Richard Robinson (12:42):
Thanks, Gaye.
Criticality & Control and Pink Elephants
Risk! Engineers Talk Governance Podcast
Season 8, Episode 1
In this first episode of Season 8, due diligence engineers Richard Robinson and Gaye Francis look at "criticality and control", starting with the pink elephant problem: Why organisations that successfully prevent bad outcomes often end up defunding the very risk functions responsible for that success.
During their chat, they unpack the Port of Auckland conviction and what it reveals about the gap between Australian and New Zealand WHS enforcement, a local government case study on engineering versus insurance priorities, and why short-term commercial thinking clashes with the long timeframes in real risk management demands. They close with a preview of what's ahead this season, plus a few early thoughts on where AI does — and doesn't — belong in risk practice.
Timestamps:
00:36 – Season 8 introduction
01:07 – Port of Auckland conviction and NZ vs. Australia WHS enforcement
03:23 – Season 8 topics ahead
04:57 – The pink elephant story
07:47 – Local government case study
09:07 – Short-termism vs. long-term risk
09:41 – Bushfire risk and generational memory
12:01 – Closing thoughts on AI
If you’d like us to cover a specific topic or have any feedback we’d love to hear from you. Email admin@r2a.com.au.
For further information on Richard and Gaye’s consulting work with R2A, head to https://www.r2a.com.au, where you’ll also find their booklets (store) and a sign-up for their quarterly newsletter to keep informed of their latest news and events.
Episode transcript
Megan (Producer) 00:00
Welcome to Season 8 of Risk! Engineers Talk Governance. In this first episode of the season, due diligence engineers Richard Robinson and Gaye Francis discuss the season's theme of criticality and control and pink elephants. We hope you enjoy the chat. If you do, please support our work by giving us a rating and subscribing on your favourite podcast platform. And if you'd like more information on R2A, our newsletter and resources, or have any feedback or topic ideas, head to the website www.r2a.com.au.
Gaye Francis 00:36
Good morning, Richard. Welcome to episode on e, season eight.
Richard Robinson 00:38
It's a bit of a surprise, isn't it?
Gaye Francis 00:43
It is. It is. This season, we're going to talk about criticality and control. We've had a bit of a brain dump of some of the things that we might talk about, and so we'll just run through those today and do a little bit of an introduction on some of the topics. But we're going to focus on pink elephants today.
Richard Robinson 01:07
Well, that was an introductory sort of thing, just to explain. And this was part to do with the fact that it sort of puzzled us a bit. You know, we had that case in New Zealand, which has obviously got senior management a bit concerned, where the managing director of the ports got convicted.
Gaye Francis 01:22
Yeah, Port of Auckland.
Richard Robinson 01:23
Port of Auckland, and that conviction has been upheld on appeal, which has caused a fair bit of well concern in a legal sense. Even though somebody died, so obviously it's a pretty serious matter.
Gaye Francis 01:34
Yeah, I think the thing there is though that there was no criminal manslaughter provision, so he's been fined, and the individual's been fined. So there's been no jail time, though.
Richard Robinson 01:44
No, but I think that could have been done if they had so chosen. The judicial court had chosen to do so.
Gaye Francis 01:49
Right.
Richard Robinson 01:50
What what puzzles us a bit, the (New Zealand) started their legislation in 2015, and the way it works is that the Kiwis they have a no-fault accident compensation system, and so they never have much case law with regards to common law for workers' comp claims and things like that. Where Australia had this huge amount of case law, and so I think we all had an expectation when the WHS legislation came into Australia, or most jurisdictions around 2012, we'd expected that there was a reasonable chance there would be some prosecutions, and it doesn't seem to have happened. And it's been a bit of surprise to us that a smaller jurisdiction-I mean, they're based in the size of Victorian economic terms-seems to follow through the implications of their WHS or WHSA legislation a lot more robustly than it seems in Australia. And and we were wondering whether that was because of the corporate veil that you had that conference you attended with all the lawyers.
Gaye Francis 02:45
Yeah, so you know it still seems to be that some of the prosecutions that are happening in Australia, isn't it, that they're small to medium sized businesses and they're of lesser charges rather than the the higher penalty charges.
Richard Robinson 02:59
No, well, there's people like not smaller organisation being convicted, but not the big ones. Not not like the CEO of the Port of Auckland or something like that, which was a national impact. And I've got to say, it does seem to me that there's a consequence. That's the reason why the Kiwis look at modifying their legislation to say, for example, that if you comply with the the code of practice for whatever it is, then you've satisfied your duty.
Gaye Francis 03:23
And we talked about that criticality focus in one of our last podcasts last season.
Richard Robinson 03:29
Anyway.
Gaye Francis 03:29
This season focus on criticality and control, and I think bringing it back to those key parameters or those key focuses, and what people have to have to focus on, as I said. (Topics) we've got: Defense is cooperative competition is aggressive. Being is simple, thinking is complex, and change is hard - and we've definitely had some experience with that one. Again, hazard versus risk. I know we revisit this every time during each of our seasons of podcasts, but I think there's still some confusion creeping in, and that tendency to want to go down the risk characterisation and risk matrix type path of that's the way that you do risk assessment.
Richard Robinson 04:15
That's right, and you know for small day-to-day matters, where I don't think it's got any particular difficulty with that, but it's when you get the critical ones that you discount. You discount the the
Gaye Francis 04:26
likelihood.
Richard Robinson 04:26
You discount the likelihood so much that that you just say, well, we don't have to worry about it anymore.
Gaye Francis 04:31
Ethics and quality assurance. I think there's some really interesting observations around that. And today we might touch on just briefly the elimination option and the hierarchic controls within the elimination option. We've also got a thing about AI there. Richard's got a little bit of a bee in his bonnet about AI and his interest in that. My interest not so much, but I'm guessing I need to be educated on that.
Richard Robinson 04:57
Well, I mean, there are a number of aspects. They're giant inference engines rather than AI, I think, presently. I mean, I muttered I did that brief course the University of Helsinki got on it, and then I read that book from Tom Griffiths, The Laws of Thought which comes after George Boole and Boolean logic and all those sorts of good stuff. So, Gaye, we might have an enlightenment. If anybody cares, we did have a sort of very stimulating conversation just prior to this podcast, we gave us sort of expressing certain concerns about what was being said. But anyway. Now the point about the pink elephants was this popped up. It came from a long time ago now. One of the large electrical distributors. For a little while, there was this little theory that what you should do is you should you should actually get consultants in, and you should share with the consultants the savings that the consultants might achieve by giving advice. So, for example, there were consultants giving advice on maintenance, and the theory was that if the maintenance bill could be reduced and the availability could be increased, then the incentive for the consultant, rather than just being paid a fee, was to actually take a share of the of that savings.
Gaye Francis 06:00
Yep
Richard Robinson 06:00
Then we got a letter from one of these electrical people wanting to do the same thing for electrical safety of the network. Obviously, I'm not a super commercial person because I promptly wrote back and said, guys, we would be delighted as a consulting firm to take on a sharing arrangement for your risk management. Basically, what we'll do is we know you've had a program to this point, and that that will have kept some of the bad things that could happen away. And so, what we'll do is we'll go on your program for three years, and we'll spend absolutely nothing on risk management. We'll sack everybody who does any kind of risk function there, and we'll keep half the money. And the end of that three years, we'll walk, and we'll leave you with whatever degraded state your system is in, and that's the point at which the big bad things will start to happen, because that's the way the world works. Smallish things start to happen, and then after a little while, those smaller things build up.
Gaye Francis 06:53
Turn into the bigger things.
Richard Robinson 06:54
Remember we talked about the ideal risk curve (Season 7), and that that is if it's a hyperbola, and that you know if you didn't do risk management, and it's the the integral of a hyperbola is the natural logarithm that that likely things starting to go wrong probably is going to grow as a natural growth curve. That's certainly mathematically correct. Whether the reality follows, I don't know. Anyway, I wrote this often, and the guy wrote back and said, thanks, we agree with your assessment. If that's what we did, we'd have a degraded network at the end of three years and cost us a lot. But this actually gives rise to the pink elephant syndrome, which we've come across quite a few times, right? And this is where it's you know they haven't had a bad event happen for quite a while, right? As an organisation, so say we're doing really well. At which point they choose to reduce their risk management function.
Gaye Francis 07:47
Yeah.
Richard Robinson 07:47
The classic case I saw on this was with local government a long time ago. Did a lot of work with local government in New South Wales, and basically you've got the preventative people, which is usually the engineers and the engineering department and so forth, and then you've got the insurance people, which are typically the admin people used to be when they had shire engineers and and town clerks and so forth. Now the town clerks are always responsible for the insurance side of things. So what happens if things are going badly, your insurance claims start rocketing up, and then you know insurance premiums start rocketing up, and then that side of the system gets really cranky. It says, right, all the what's going on? Let's get some preventative people in and stop these things from happening in the first place. But what happens if you do a good job over there? Then all the insurance premiums decline, and then after a while, everybody says, why are you spending all this money on these preventative systems, because we're not having the claims.
Gaye Francis 08:34
And I think the question was, what's your job? And the response was...
Richard Robinson 08:37
My job is to keep bad things from happening. I I keep the pink elephants away. The things you didn't want to have happen, and the bloke sort of looks at you and says, but there aren't any pink elephants around here. You sort of go: oh, hey, what a good job I'm doing. So, the problem is then you've got these preventative people, and you can't actually work out whether they're really...
Gaye Francis 08:38
Making a difference or not.
Richard Robinson 08:40
If they weren't there, you're pretty sure bad things would happen, but it's pretty hard to tell just how effective they are, and whether they're spinning the wheels or they're really achieving stuff.
Gaye Francis 09:07
Yeah, and I think that's where we are now. No one's taking that longer term. Everything's being looked at shorter and shorter terms, isn't it?
Richard Robinson 09:14
It's all about commercial quick returns.
Gaye Francis 09:16
And, you know, it's 12 months, 18 months, two years. But you know, when you're looking at some of these engineering projects and engineering organisations. You have to look 5, 10, 15 years.
Richard Robinson 09:26
And the big projects?
Gaye Francis 09:28
Are taking that long to do as well.
Richard Robinson 09:30
And I don't think there being any, shall I put it, the overrun on big projects doesn't seem to have improved in the last five or 10 years from our point of view or observation.
Gaye Francis 09:41
So it's really interesting that these things sort of go in peaks and troughs. You know, yes, there's a lot of effort put on it, and and I think probably we've seen that observing that in the WHS space as well. There was a lot of effort put in when the legislation first came out in 2012.
Richard Robinson 09:58
Yep.
Gaye Francis 09:59
And maybe until... I can almost say COVID that 2019/2020 and the last three to five years it started to lax a little bit and I'm just wondering you know is there going to be a big accident really soon?
Richard Robinson 10:16
Well, it may be the way the world actually works. I mean, maybe I'm getting more cynical as I get older, but you know, if a bad thing hasn't happened in a generation, we all forget.
Gaye Francis 10:25
We do,
Richard Robinson 10:26
And that's the case with bushfires in Victoria.
Gaye Francis 10:29
We were just talking about that, weren't we? The Black Saturday was 2009, so we're coming up to a generation - 17 years. h
Richard Robinson 10:35
So everybody's moved into the bush again. Now we have actually done a whole lot of things, and because we're on the Power Line Bushfire Safety Task Force, and you're on the committee, and those mechanisms pretty much disappeared. I mean, what I do find interesting every time one of these bad things happen, there's a particular mechanism, like the spreaders stopping conductors clashing. Well, since that program went in I don't think fires from that mechanism happened.
Gaye Francis 11:00
But I think the reficials have only been installed in Victoria. It hasn't happened in any of the other eastern states.
Richard Robinson 11:05
Yeah, but fires from that source. But the problem with all this is that they're not the only thing to start bushfires. Kids with matches and hot bearings, you know, people trailing their trailer down the road, going wherever they're going, and they're pulling over while their bearings on fire. There are a lot of things that actually start fires, and unless you're actually not going to have bush that can burn, which I have to say seems difficult, then we're going to start fires. But they'll be less likely, and there's probably going to be a longer period between them.
Gaye Francis 11:34
Possibly, but the urban spread, you know, there seems to be more more people living in those urban spread on those fringes now.
Richard Robinson 11:40
We'll double the population of melbourne in what is it, 15 years or something astonishing?
Gaye Francis 11:45
Yes, they have to go somewhere.
Richard Robinson 11:47
Have to go somewhere.
Gaye Francis 11:48
Exactly. So that's sort of a quick overview of what we're going to talk about in season eight. I'm sure this will morph into other places as we go along during the season.
Richard Robinson 12:01
Judging on the prior conversation, AI is likely to pop up, and as I said, it's not really AI at the moment; it's something else. But you know, we're looking at putting small language models on our laptops and things like that.
Gaye Francis 12:11
Richard is looking at doing that. I am, but I've been
Richard Robinson 12:13
I'm slightly wary about it because loading a half a terabyte of something on your laptop, you've got to wonder who it could talk to and how it would do it, and when what you're actually trying to do is make it a secure system, so you don't have to keep talking to AI in the cloud.
Gaye Francis 12:27
Yeah, I think I'm a little bit more skeptical on how good this stuff is at the moment. So it is a tool in your toolkit, not the way to do it. But that's a personal opinion, and Richard and I'll have another discussion about that another time, but thanks for joining us. We hope you enjoy Season Eight, and look forward to seeing you next time. Thanks, Richard.
Richard Robinson 12:48
Thanks, Gaye.