Human reliability: tasks, context and opportunities for recovery

Analyze human reliability through task steps, realistic timing, performance conditions, dependent recovery and system improvements.

On this page

Human reliability analysis asks whether people can perform a required task successfully in the conditions where it matters. It becomes misleading when it reduces an incident to “operator error” or assigns a universal probability to a job title. The useful unit of analysis is a defined action in a defined context, including opportunities to detect and recover from mistakes. This educational guide develops original hypothetical shipboard examples. It is not a staffing assessment, medical evaluation, disciplinary tool or approved emergency procedure.

Start with the required safety function

Define what must happen, who is expected to do it, what information is available and when success becomes too late. “Respond to alarm” is incomplete. A meaningful task statement might be “recognize the specified abnormal condition, select the correct approved response and achieve the required final state before the consequence can no longer be prevented.” The actual response and limits must come from the vessel’s authorized procedures and engineering basis.

The HSE’s human-factors risk-assessment guidance emphasizes understanding real tasks, involving workers and designing for prevention and recovery. Its general principles do not supply a universal marine error rate. The practical starting point is to observe and discuss how work is performed, rather than assume that the written procedure describes every interruption, communication and physical constraint encountered during a watch.

Decompose the task without losing its purpose

A task analysis can identify information gathering, diagnosis, decision, communication, access, action and verification. Each step should have a recognizable success condition. For a hypothetical pump-changeover response, noticing a warning is different from identifying the affected service, selecting the intended equipment and confirming that the required flow was restored. Pressing the correct control does not establish successful recovery if the final function remains unavailable.

Avoid decomposing every tiny movement into an artificial independent event. The analysis should be detailed enough to identify consequential failure mechanisms and controls. Closely linked steps can share the same misunderstanding or misleading cue. Conversely, grouping the whole task as “crew action” hides where a better interface, a clearer identifier or an automatic verification could help. Choose the level of detail according to the decision the analysis needs to support.

Distinguish error mechanisms from judgments about people

A slip may involve selecting the wrong control despite a correct intention. A lapse may omit a remembered step. A mistaken diagnosis can lead to a coherent but inappropriate action. Deliberate departure from a procedure needs investigation of why the departure occurred; it is not automatically evidence of malicious intent. These distinctions matter because different mechanisms need different controls. More classroom instruction may do little to prevent a control-selection slip caused by nearly identical labels.

HSE’s managing human failures guidance cautions against assuming perfect detection, immediate action or immunity to error through motivation and training. Use that principle to examine system conditions. An investigation should ask what information the person had at the time, which alternatives appeared reasonable and which constraints shaped the decision. Knowledge available after an incident must not be silently inserted into the earlier operator’s perspective.

Examine the conditions that shape performance

Relevant conditions can include workload, fatigue, interface clarity, alarm presentation, communication, competence, access, environmental noise and available time. Their importance depends on the task. A dim display might matter for reading a value; ambiguous equipment naming might matter more for selection. The analysis should connect each condition to a plausible failure mechanism rather than assign a long generic checklist of “human factors” to every task.

Ask whether several demands arrive together. A person expected to communicate with another station, diagnose a machinery warning and maintain an unrelated essential watch may have competing priorities. Do not assume that a person nominally on duty is continuously available for every credited response. Review the actual task allocation and foreseeable disturbances. Any conclusion about sufficient staffing requires the appropriate competent assessment and applicable maritime requirements, not a headcount inferred from this article.

Build a timeline before assigning a probability

Assume a hypothetical abnormal condition has a 90-second window before the selected consequence becomes unavoidable. Suppose reliable detection takes 15 seconds, diagnosis and decision take 25, movement or access takes 20, and final action takes 20. If these steps are sequential, nominal completion takes 80 seconds, leaving 10 seconds. These invented figures demonstrate the reasoning; they are not allowable response times for any real ship system.

The apparent margin is fragile if the earliest cue is uncertain, communication is required or movement is impeded. Some actions can overlap; others cannot start until a preceding decision is complete. Model those relationships rather than summing everything indiscriminately. The key output is whether the task is feasible under credible conditions and what determines the margin. An infeasible task cannot be made reliable by assigning a smaller human-error probability in a spreadsheet.

Analyze recovery as a separate opportunity with dependence

A check can catch an earlier error, but it is not automatically independent. The same person may reread the same ambiguous display and repeat the same interpretation. A second person may rely on the first person’s verbal conclusion rather than independent evidence. Define what new information or perspective makes recovery possible, how much time remains and whether the checker has authority to stop the operation.

For an original probability illustration, assume the chance of an initial task error is 0.05. Assume the probability that a later check misses that error, conditional on the error having occurred, is 0.2. The residual probability is 0.05 × 0.2 = 0.01. Multiplying 0.05 by an unrelated generic check-error probability of 0.02 would give 0.001 and imply ten times stronger protection. Neither set of values is empirical; the lesson is to use the conditional relationship actually being claimed.

Use quantitative methods within their evidence limits

Quantitative HRA can support a wider probabilistic model when the task, context and data justify it. It requires documented assumptions about the human failure event, relevant performance factors, dependencies and uncertainty. Selecting a named method does not automatically validate its transfer to another sector. Differences in interfaces, crew organization, emergency cues and operating conditions can matter as much as the nominal task description.

The NRC’s SPAR-H report description, NUREG/CR-6883, identifies a nuclear-industry method with explicit treatment of dependency and uncertainty. It is cited as a primary example of structured HRA, not as a source of shipboard default probabilities. No SPAR-H parameter is applied in this article. A marine application needs a justified method choice and evidence that its assumptions fit the task being assessed.

Prefer changes that address the failure mechanism

If the issue is wrong-equipment selection, distinguishable identification and better physical or interface design may be more relevant than another reminder to be careful. If the task requires acting before any reliable cue appears, redesign the detection or protective function. If communication is ambiguous, examine the message content, acknowledgment and shared understanding. The improvement should match the mechanism identified in the task analysis.

Procedures and training remain important, but they should support a feasible task. HSE’s procedure guidance connects task analysis, user involvement, usability and competence. For the hypothetical response, test whether the procedure helps the user identify the condition and verify the final function without excessive searching. A longer procedure is not automatically a better one. Additional detail can obscure the critical decision when the available time is short.

Verify improvements under representative conditions

A demonstration should evaluate the relevant task rather than only recall of a written instruction. Approved drills, simulation or controlled walkthroughs can reveal confusing cues, access problems and unanticipated coordination. Define what will be observed, how time is measured and which conditions are represented. Keep the exercise safe and consistent with the vessel’s authorized training arrangements; do not create a real hazardous condition merely to make the test realistic.

A small set of successful demonstrations establishes limited evidence of feasibility, not an extremely low failure probability. Participants may know the scenario in advance, have fewer competing tasks or receive clearer cues than during an actual event. Document those differences. Record unsuccessful attempts and the reasons without turning the exercise into blame. If reporting is discouraged, the analysis loses precisely the information needed to improve the task and its protection.

Include maintenance and restoration work

Human reliability is not confined to emergency response. Incorrect assembly, missed restoration, wrong settings and incomplete handover can leave protection unavailable for long periods. These actions may occur far from the eventual demand, making their connection to an incident easy to overlook. Analyze the work boundary, equipment identification, isolation state, verification and communication that restore the required function after a task is completed.

A second signature is useful only when it represents a meaningful check with appropriate information and independence. If both maintainers use the same incorrect reference, dual sign-off does not solve the underlying problem. Determine what evidence demonstrates the final state and how deviations are escalated. The work order’s administrative closure should not be mistaken for confirmation that the system’s safety function is available under the relevant operating conditions.

Use findings to improve the system, not score individuals

HRA findings should identify task vulnerabilities, control requirements, residual uncertainty and improvement priorities. They are not a defensible basis for ranking individual workers by an invented error probability. Protect the integrity of observations and separate learning from unsupported personal judgments. A task that repeatedly challenges competent people is evidence to examine its design and context, not merely a reason to demand greater vigilance.

A useful deliverable includes the task boundary, critical steps, cues, timeline, performance conditions, potential failures, recovery opportunities, dependencies and verification evidence. State which changes require further approval and what would trigger reassessment, such as a new interface, revised staffing arrangement or different operating mode. Human reliability becomes actionable when the analysis explains how the work can succeed reliably and how the system can tolerate and recover from foreseeable mistakes.

Sources