A Dynamic Positioning (DP) system enables vessels and rigs to accurately maintain a predetermined position and heading or track. It enables precise operations under harsh environmental conditions. DP is used for a variety of purposes; however, the role of the DP operator (DPO) is considered the same regardless of type of operation: to monitor and keep the vessel in position. Some of the decisions that the DPO makes are safety critical, for example, decisions about the set-up of the system can prevent the vessel from colliding with an offshore oil and gas platform. Applied cognitive task analysis (ACTA) is performed to analyze how the different operational settings influence the role and decision-making of the DPO. Two DPOs with experience from five different operation types were interviewed. The results from the ACTA for the different operation types are compared with respect to technical steps, cues, the cognitive steps and components, actions, and decisions. The contextual factors are evaluated using an adapted version of Rasmussen's dynamic safety model. The results of the comparison are used to evaluate the current role of the DPO, in light of the DP system and different DP operations. Recommendations for the improvement of safety, the design of the DP system, training and set-up of DP operations are formulated.
This paper's objective is to analyze the main real-time risks in operation of autonomous marine systems, which follow from various levels of autonomy (LoA). High reliability management (HRM) is an established framework for assessing real-time operator performance in complex infrastructures. In this paper, the framework is applied to two cases representing different uses and autonomy levels: one on marine underwater robotics focusing on remotely operated vehicles (ROVs) and subsea intervention, and the other addressing operation of a complex marine surface vessel with a dynamic positioning (DP) system. Usually, autonomous systems are associated with unmanned systems, but several manned systems (for example, ships with complex automation and DP systems) have specific control functionality that can be characterized as autonomous. This paper focuses on manned and unmanned systems with different levels of autonomy and major hazard potential. The most important research finding is having identified multiple, different operational states that vary across two or three LoAs, each state of operations having significantly different risks to be managed in real time. The application of the HRM framework highlights the importance of enabling reliable operator control and online risk management in the development of next generation autonomous marine systems.
Monitoring the mechanical integrity (MI) of offshore oil and gas facilities is important. It enables early fault detection of emerging failure conditions and allows more time for planning and preparing remedial actions, which reduces revenue losses resulting from unnecessary and poorly coordinated maintenance actions. Static equipment, such as heat exchangers, constitutes crucial parts of offshore processing facilities. Heat exchangers are challenging to maintain, especially in ageing facilities, and major maintenance problems are the result of (a) poor designs, (b) poor utilization of process information, (c) poor interpretation of results, and (d) poor development and management of high‐quality maintenance and MI programs. This article addresses the most important technological, human and organizational challenges concerning monitoring of MI of shell and tube heat exchangers, and discusses recommendations for future improvements. A good MI program benefits the operation and maintenance of heat exchangers, and will lead to improved safety and reduced costs. © 2011 American Institute of Chemical Engineers Process Saf Prog, 2011
Shore control center (SCC) operators of maritime autonomous surface ships (MASS) may be allocated with complex responsibilities within different degrees of autonomy (DoA), from remote control to remote supervision, and the role of human in-the-loop is significant. In the current research on MASS, however, the safety of interactions between humans and systems are not sufficiently considered. Hence, this paper proposes a system-theoretic approach to safety analysis for human-system collaboration. The novelty of the approach is the definition of operational contexts of MASS and the integration of a human cognitive model into the system theoretic process analysis (STPA), called STPA-Cog. The method is demonstrated in two case studies of MASS: (i) remote control mode (RCM) and (ii) remote supervision mode (RSM), focusing on two types of navigational accidents (i.e., collision and grounding). The analysis results are derived by comparing the human-related and technical-related causal scenarios in RCM and in RSM. The findings can assist in human-oriented design and operational planning for SCC of MASS. Further, the proposed approach also has the potential to be used and extended to systemic safety analysis in other intelligent transportation systems.
Climatic degradation of equipment, in combination with stringent requirements for human safety and minimalistic environmental impact, need to be addressed through improved risk assessment in vulnerable areas, such as the Arctic. The performance of technologies and risk related to its utilization, for example in terms of autonomous operations, significantly impact future requirements for oil and gas exploration and production. An interdisciplinary and systemic approach integrating both risk to the environment and to humans is needed as the challenges related to operation in extreme environments directly impact risk, costs, and the general societal acceptance of the activities. Development of such an approach focusing on autonomous underwater vehicles (AUV) and operations is addressed in this paper.
This article presents a new risk model for estimating the probability of allision risk (the impact between a ship under way and a stationary installation) from passing vessels on the Norwegian Continental Shelf (NCS). Offshore petroleum operators on the NCS are required by the Norwegian Petroleum Safety Authority (PSA) to perform risk assessments to estimate the probability of impacts between ships and offshore installations, both for field related and passing (merchant) vessels. This has typically been done using the aging industry standard COLLIDE risk model, but this article presents a new risk model based on a Bayesian Belief Network (BBN) that can replace the old COLLIDE model for passing vessels. The new risk model incorporates a wider range of risk influencing factors (RIFs) and enables a holistic and detailed analysis of risk factors, barrier elements and dependencies. Even though the risk of allision with passing vessels is very small, the potential consequences can be critical. The new risk model is more transparent and provides a better understanding of the mechanisms behind allision risk calculations. The results from the new model are aligned with industry expectations, indicating an overall satisfactory performance. The article discusses several key elements, such as the use of expert judgement to estimate RIFs when no empirical data is available, model sensitivity, and a comparative assessment of the new risk model to the old COLLIDE model.
Human-autonomy collaboration plays a pivotal role in the development of Maritime autonomous surface ships (MASS), as Shore control center (SCC) operators may engage in the control loop by directly operating the MASS, or, in the supervisory loop, monitoring the MASS and taking over control when needed. Thus, efficient human performance during takeover control and operation is crucial for the safety of MASS operations. However, since the MASS is still in the early phase of development, the mechanism of human errors is unknown, and the data on human-autonomy collaborative operation is scarce. Human reliability analysis (HRA) aims to assess human errors qualitatively and quantitatively, and is widely used in various complex systems to help safety analysis. This study is dedicated to incorporating advanced HRA methods elements to identify and quantify human errors during taking over control and operation of a MASS in collision avoidance scenarios. It presents virtual experimental results, combined with theoretical human error identification and assessment methods. At first, we apply the Human-System Interaction in Autonomy (H-SIA) method to identify potential human errors; secondly, we identify relevant Performance Shaping Factors (PSFs) including Experience, Boredom, Task complexity, Available time and Pre-warning, and performance measures of the human errors, and implement them in the virtual experiment based on a full-scale autonomous ferry research vessel called milliAmpere2. Finally, we build a Bayesian Network (BN) to present causal and probabilistic relationships between PSFs and human errors through experimental data. The results show that available time has the highest impact on takeover performance of operators, followed by task complexity and pre-warning. Boredom does not present a significant sole impact unless combined with available time. Experience does not show a significant impact on human performance. In addition to the relevance of the human errors analysis to the safe development and operational design of MASS, the developed method benefits other human-autonomy collaborative systems. The developed BN model shows adaptability to assess human error probabilities, and the practical significance of integrating experimental data into the existing HRA methodologies for complex systems.
Online risk assessmentOnline risk assessment methods confront multiple challengesChallenges when applied to complex automated and autonomousAutonomous systems. This chapter addresses the main challengesChallenges with online risk assessmentOnline risk assessment, related to methodology, data collectionData collection, uncertaintiesUncertainty, complexityComplexity and execution timeExecution time, and application for decision supportDecision support.
No abstract is provided for this article.
An emergency is a situation that poses an immediate riskRisk to health, life, property, or environment. Most emergencies require urgent intervention to prevent a worsening of the situation, although in some situations, mitigation may not be possible, and agents may only be able to offer alleviating care for the aftermath. Online risk assessmentOnline risk assessment in emergencies should be performed in real-time, which means that dynamic probabilistic riskRisk should be assessed in a very short execution timeExecution time.
On 16th April 2014, the MV SEWOL capsized in South Korea, and 304 persons died or went missing. This article describes the accident and finds causes from four different theoretical points of view: the energy-barrier model, Turner’s man-made disasters model, Rasmussen’s conflicting objectives perspective, and high reliability organizations theory. The results show that the theories together point out a total of 23 different causes to the accident. Different causes are identified from different theories and they complement each other. Finally, this article discusses a possible combination of the perspectives for improving both accident investigation and accident prevention.
An important question with respect to the Macondo blowout is whether the accident is a symptom of systemic safety problems in the deepwater drilling industry. An answer to such a question is hard to obtain unless the risk level of the oil and gas (O&G) industry is monitored and evaluated over time. This article presents information and indicators from the Risk Level Project (RNNP) in the Norwegian O&G industry related to safety climate, barriers and undesired incidents, and discusses the relevance for deepwater drilling. The main focus of the major hazard indicators in RNNP is on production installations, whereas only a limited number of incident indicators and barrier indicators are related to mobile drilling units. The number of kicks is an important indicator for the whole drilling industry, because it is an incident with the potential to cause a blowout. Currently, the development and monitoring of safety indicators in the O&G industry seems to be limited to a short list of “accepted” indicators, but there is a need for more extensive monitoring and understanding. This article suggests areas of extensions of the indicators in RNNP for drilling based on experience from the Macondo blowout. The areas are related to schedule and cost, well planning, operational aspects, well incidents, operators’ well response, operational aspects and status of safety critical equipment. Indicators are suggested for some of the areas. For other areas, more research is needed to identify the indicators and their relevance and validity.