Monitoring the risk
It is important to understand that the concept of risk is dynamic and needs periodic and formal review.
The currency of identified risks needs to be regularly monitored. New risks and their impact on the organization may to be taken into account.
This step requires the description of how the outcomes of the treatment will be measured. Milestones or benchmarks for success and warning signs for failure need to be identified.
The review period is determined by the operating environment (including legislation), but as a general rule a comprehensive review every five years is an accepted industry norm. This is on the basis that all plant changes are subject to an appropriate change process including risk assessment.
The review needs to validate that the risk management process and the documentation is still valid. The review also needs to consider the current regulatory environment and industry practices which may have changed significantly in the intervening period.
The organisation, competencies and effectiveness of the safety management system should also be covered. The plant management systems should have captured these changes and the review should be seen as a ‘back stop’.
The assumptions made in the previous risk assessment (hazards, likelihood and consequence), the effectiveness of controls and the associated management system as well as people need to be monitored on an on-going basis to ensure risk are in fact controlled to the underlying criteria.
For an efficient risk control the analysis of risk interactions is necessary.
This ensures that the influences of one risk to another is identified and assessed. Usual method for that purpose are a cross impact analysis (cf. Fig. 6), Petri nets or simulation tools.
A framework needs to be in place that enables responsible officers to report on the following aspects of risk and its impact on organizations ́ operations:
− What are the key risks?
− How are they being managed?
− Are the treatment strategies effective?–If not,what else must be undertaken?
− Are there any new risks and what are the implications for the organization?