Select Page
Why Systems Thinking Matters for Safety with Dr. Paul Salmon

LISTEN TO THE EPISODE: 

ABOUT THE EPISODE

Join us on The Safety Guru for a thought-provoking conversation with Dr Paul Salmon, professor and seasoned expert in applied human factors and systems science research. In this insightful episode, Paul breaks down how interconnected systems and both direct and indirect decision-making impact safety outcomes, and how every individual plays a role. He also explains the difference between the old and new views of safety, sharing real-world examples to deepen our understanding of complex systems. Discover why systems thinking matters for safety and learn how to apply it across your organization with practical, actionable strategies. Don’t miss this powerful episode!

READ THE EPISODE

Real leaders leave a legacy. They capture the hearts and minds of their teams. Their origin story puts the safety and well-being of their people first. Great companies ubiquitously have safe, yet productive operations. For those companies, safety is an investment, not a cost for the C-suite. It’s a real topic of daily focus. This is the Safety Guru with your host, Eric Michrowski, a globally recognized ops and safety guru, public speaker and author. Are you ready to leave a safety legacy? Your legacy success story begins now. 

Hi, and welcome to the Safety Guru. Today, I’m very excited to have with me Professor Paul Sammon. He’s from the University of Sunshine Coast. Paul, welcome to the show. Very excited to have you with me.

Hi, Eric. It’s great to be here. Thanks for having me.

Why don’t we get started with how you got into safety and some of your background because it’s quite fascinating.

Yeah, sure. It’s quite an interesting journey to where I am now. I’m a professor of human factors at the moment who doing a lot of safety work, but I actually started out life as a sports scientist. I did an undergraduate degree in sports science. During my studies there, I had access to things like Anthropometrics, and I became interested in football boot design. I knew about physical ergonomics and things that. And at the end of the degree, I saw a master’s degree in applied Ergonomics being advertised. I’d heard of ergonomics, and I was quite interested in doing further studies. I thought that would be interesting. So, I applied for that. And on that master’s degree, there was a module around accident causation investigation. And so, we did a case study. I remember it very clearly. It was on the Herald of Free enterprise, the Brugger disaster, where a roll-on-roll-off ferry capsized just after leaving Port and killing a number of people and crew. And we did a case study on that. We were exposed to reasons, Swiss cheese model, and I just I’m completely fascinated in accident causation and disasters and went from there, really. So that’s where it all started for me.

From sports science, football boot design through to major incidents.

Quite diverse set A lot of experiences, but it is the whole Swiss cheese and all that is incredibly fascinating from a safety standpoint. Which gets me to speak about one of the most critical parts that we’re starting to finally embrace in safety is really the systems thinking. Can you tell me a little bit more around why systems thinking is so critical to safety and maybe how you move to that perspective? 

Yeah, I mean, look, I think the movement to that perspective is another interesting story, so maybe I’ll talk about that first. Sure. After the master’s degree, I worked on a project with Professor Neville Stanton and Professor Don Harris, Brunell University and Cranfield University at the time. We were developing a human error, what’s called a human error identification technique. It was specifically for identifying potential pilot errors in cockpit certification processes. Sure. Through that, I was to things like reasons, generic error modeling system, Barry Kerwin’s work on human error identification, Sydney Decker’s work on the old and new views, and then methods like Sherpa, Tracer, and CREEM. So, I was I was working in the space of human error. I guess reading around all of that work, I became exposed to different models of error, different models of failure, and things like Rasmussen’s Risk Management Framework, Perro’s Normal Accident Theory, and so on. And I started, towards the end of that project, I started to get this idea that focusing on errors alone is actually quite misleading. And I became interested in what Factors are actually influencing people to make errors. And so, I started to really look at those systems issues.

But the real incident that really got me firmly into systems I was thinking was that I then was working in defense research. And so, I was asked to look at an incident which was a fratricide or blue on blue or friendly fire incident that you might call it, where UK tank had fired upon one of its own tanks, killing two crew members, and I think severely injuring another two. And what I found really interesting in this case was that no matter how you looked at the incident or no matter what analysis method you used, the decision to fire at the target always made sense. So, I couldn’t find any errors. The system was actually behaving exactly as it should, given the circumstances. And so, I started to question, is human Is there actually a real thing, or is it just a label that we’ve put on performance variability where factors across the system are interacting to influence behavior? And from then, I just really immerse myself in the models, the methods, and started applying them in all different contexts.

Interesting.

Yeah. And I think the reason why it is so critical as an approach is that it lets you actually understand what is driving behavior Rather than just looking at a behavior in of itself or a behavioral issue like human error or loss of situation awareness, it lets you understand all of the things across a broader socio-technical system that interacted to create that behavior. I think when you do that, you really get a very different understanding of why something happened in the way that it did.

Are you able to expand on why those decisions in that incident you mentioned all made sense? To give a bit of an illustration of… Because I think most people think there’s obviously somebody who made a mistake, and so it’s very easy to get to that. I don’t know if you’re able to share a little bit about the background that provides context where these decisions made sense.

Yeah, sure. In the circumstance, if we look at the decision to fire upon the target, I think there was a thermal signature that was representative of an enemy coming out of a weapons bunker. So, the signals being provided by the technology were that it was enemy. I think in the planning of the incident, there was no information given to the people involved that there would be other friendly forces in that area of the boundary. So, there was no prior communication around that. So, they were basically going through a process that had been gone through many times. They were getting the information that was telling them that there’s enemy, and the response to that in that circumstance was to fire upon the enemy. So whatever way you look at that, you can say the decision to fire is an error in hindsight. But actually, at the point in time, the decision to fire made perfect sense to the person who made it, given all of the information, all of the training, all of the planning, all of the things in the system that were present, that actually made sense to the individual. I think that’s one of the key aspects of systems thinking is rather than try to label something as a mistake or an error, what you’re actually doing is you’re saying, Well, why did this action make sense to the person that made it at the time?

Often you find that actually it’s not an error. They’re actually doing what is expected.

I think that ties in to touched on it a little bit before, but the view, old view versus new view of safety. Can you share a little bit more in terms of what it means, I think, to a lot of safety professionals, very common language, but it’s still fairly new in some circles in terms of the points of difference between this old view and new view?

Yeah, sure. The old view really is this idea that when systems fail, it’s typically caused by humans that have made an error or a mistake of some sort. It’s a view really that systems are really well designed. They fail because of unreliable or erratic human beings who make some error. Really the way to make systems safe is to use things like training, procedures, or appraisals to restrict human behavior so that they don’t make any errors. It takes this view, this interesting view that systems are really well designed, and its only unreliable people that break them. And the new view is very different. So, the new view actually says that actually systems are highly complex. They comprise humans interacting with things and technologies. They’re very brutal. They’re very prone to failure. Actually, humans are the glue that are keeping these systems together. And so when systems do fail, what instead we should be doing is going, what Sydney Decker says, go up and out into the broader system rather than down and in to the human in the decision and go up and out into the broader system and try and understand how all of the components interacted to get to the point of an error.

So why did the decision that we’re calling an error with hindsight makes sense to the person who made it at the time. Sure. Then in response to that, rather than these ideas of restricting human behavior through procedures, which paradoxically make the system far more complex and even more prone to failure, we need to understand what leverage points there are in the system. What is actually influencing behavior and what leverage points can we target with interventions that will actually influence behavior in a positive way? 

When you mentioned in the old view, you bring up basically systems are well-designed, but those systems are well-designed by humans that have been themselves in an area imperfect. That’s right. You can’t design a system that’s perfect.

Absolutely. I think everybody can reflect on their own occupations and say that systems are just not well-designed. They’re complex. They’re layered with processes that don’t work together. I think we’ve all experienced systems that don’t work particularly well.

I think there’s also quite a bit of arguments to say that systems have become much more complex as you start layering technologies, as you start layering specialization. The examples I’ve heard was even if you go back in history, for a doctor, you will need one specialist for a particular operation. Now, you need a whole team of experts. If it’s, for example, cancer treatment, even when you’re building a used to be a very simple design, but now you have lots of specialized expertise that are building it that all speak different languages.

That’s right. That’s absolutely right. I was presenting only the other day on AI safety and Liz Anne Bainbridge’s paper on the Ironies of Automation, which is, I think, was published in 1983. She talked about how introducing advanced technologies basically makes systems far more complex and brutal and more prone to failure. We’ve known about this for many years, and we can see it happening right now with AI, for example.

I think even I’m going to touch on aviation when you touch on the elements. If you think about the Air France crashes many moons ago, you had a system that was sending all sorts of alerts. You’re on autopilot, so you’re expecting things to be normal, and suddenly things go wrong. Even the 737 max, you have the system failing, and you’re hoping this human can figure a solution to something they’ve not been trained to.

Yeah, Air France 447 is a really great example of system syncing, and we use that a lot in our teachings and lecturing’s, just about the idea around why the action made sense to the individuals at the time. There are points in that unfolding scenario where the pilots, I think, don’t even know if they’re going up or down. The messages that they’re getting from the system are just not assisting them in any way, really.

You’ve got seconds to make decisions, and you’ve not been trained for the system failing around you. Same with the 737 max, where the autopilot was kicking and doing things that nobody could understand how to take off.

That’s right.

Absolutely. This view of systems thinking, I think, is one thing to understand the impact. I think more and more people are starting to realize the impact of the system and starting to bring a lot. But it’s a lot more complex in many ways because it’s very easy to blame the person who made a mistake. When you’re trying to do it proactively from a systems thinking standpoint, there’s a lot of decisions people that are, in some cases, unrelated to the work being performed that are in head offices that make decisions that ultimately impact the system. What are some of the ways that an organization can start looking at really driving this shift towards systems thinking?

Yeah, that’s a really interesting question. I think based on the experiences we’ve had. The first thing is there’s really an education piece. I think there’s an education piece where you have stakeholders from across whatever system you’re working in and you’re educating them on the philosophy, the principles, the approaches. I think one of the interesting things is often there’s an assumption that all we’re really trying to do is shift blame higher up into higher levels of the system. So, from the frontline workers to more people in managers and things like that. I think there’s an education piece about what it’s about, what its power is, and certainly in the work we’ve done, we’ve always had what we call our industry champions who are in the sector who are preaching and communicating the principles of system sinking. I think once the education piece starts to gain traction, I think then it’s really about the methods that are used for safety management. I lose count about the times when we’ve been doing work in sectors and the methods that they use just are not going to enable a shift towards systems thinking. I’m thinking about things like incident reporting and learning systems that would only let you report one cause of an incident that you’re reporting.

And so that just limits what you can learn. Or an accident investigation Delegation method that doesn’t look at contribute factors across the system and doesn’t look at interactions between contribute factors. So, it’s about then, I think, developing appropriate safety management methods and all of the training piece around that and implementing the methods and evaluating them to show that they actually are beneficial. I think the methods part is really critical because what we do see in most sectors is a significant research practice gap where the methods that are being used by researchers in our ivory towers all the time in the world to do this analysis, they haven’t really been effectively translated in practice. So, you have organizations who really are willing to embrace a system-sinking approach, but they just don’t have the methods to do it, which is a challenge. Sure.

This episode of the Safety Guru podcast is brought to you by Propulo Consulting, the leading safety and safety culture advisory firm. Whether you are looking to assess your safety culture, develop strategies to level up your safety performance, introduce human performance capabilities, re-energize your BBS program, enhance supervisory safety capabilities, or introduce unique safety leadership training and talent solutions, Propulo has you covered. Visit us at propulo.com.

It is, and I’d say the other part I’m also seeing in many organizations is it shifts from safety is the role of operations and safety to the entire organization really impacts the system. We haven’t necessarily educated in organizations for somebody in finance, as an example, to understand how you impact safety. But if you look at Deepwater Horizon as an example, or even Texas City, both traces back to financial decisions that were made and how they were interpreted by other decision-makers at the end of the day. I think there was a dollar called Every Dollar Counts. I have a program that was called Every Dollar Counts. My point, usually want to bring that up, is other oil and gas supermajors have also had cost-saving programs but didn’t have the same impact in the decision-making that came as a follow-on.

Yeah, absolutely. That’s really interesting because we We’ve written some pieces around this, and my view is systems thinking should be taught in schools. Because I think there’s an argument. I can’t remember who makes the argument, one of the prominent figures, I forget the name. But they say that we start life out as systems thinkers, and it’s actually driven out of us through the education system that we go through. It’s interesting to me that we could be teaching this very early on, and people could be coming out naturally as systems thinkers, and whatever role they’re in within organization, they’re able to apply that thinking.

That’s a really good observation because at the end of the day, systems thinking has a huge impact on safety. But it has impact on P&L. I remember even some executive I was talking about that was complaining about how somebody had cut some budget in marketing, and it reduced certain print materials, and it passed the dollars, magnified them by to the next group in the organization. You saved maybe a million dollars, and you created $2 millions of cost somewhere else.

Yeah, that’s right. A lot of the work that we do in the center, for example, applying systems thinking in sport, yes, we’ve been doing it, looking at injury management and things like that. But a key part of that is that it’s about performance optimization. So, you’re getting safety benefits, but you’re really getting benefits It’s across the board in terms of performance, cost saving, efficiencies, and things like that. I think it’s definitely a good skill to have.

I love your point about increasing awareness, about introducing even training or awareness around systems thinking. What are some of the approaches that organizations can look at to mitigate risk? And are there some things that could be done from a risk assessment standpoint that are more proactive? Because it’s easy after an event, and aviation has done very well in terms of doing really detailed investigations following an event that are not single-handedly laying blame in one place but also has pushed to see a lot more in your miss reporting overall. But that’s not something that’s common across all industry.

Yeah, no, that’s another great question. I think there’s no doubt that when I mentioned the research practice gap, prospective risk assessment methods are a very good example for that. You have whichever, I guess, domain you look in. We have very limited risk assessment methods currently being used where it’s based heavily on experience. We identify the risks that we’ve seen happen before, often brainstorming or a checklist or something like that. But really, a really good risk assessment method has some key parts to it that really not many have currently. And a good example of that is, you’re basing the risk assessment on a description of the work system. And it’s really interesting to me how few methods do that. So, if I think of something like, for example, Nancy Leveson’s stamp, SPA, prospective risk assessment or the networked hazard analysis risk management system that we’ve developed with myself, Claire Dalet and a few others. These methods, really, the first step in those approaches are to develop a model of the socio-technical system that understands, that describes and understands all of the interactions going on in that system. I think if you have a risk assessment method that doesn’t do that, you can’t get any handle on the likely risks that are going to emerge in that system.

I think that’s the first point. I think adopting these methods to actually build a model of the work system first is critical. I think then the most important thing is that the methods that you’re using, they look across the work system for risk. You could argue that we’ve got a very good understanding of the risks that might emerge in a cockpit, in a control room, in a train cabin. What these methods don’t do really is understand risks in the broader socio-technical system. They don’t look, for example, at risks that happen at the work design stage, risks that are present in policies and procedures, risks in training programs. They’re really missing a big part of the picture. A lot of the work we’ve done has shown that by looking at these broader socio-technical systems risks and how they interact, you really get a much better handle on what potentially can go wrong at the sharp end or whatever you want to call it. I think methods that do that are really important. Again, those are methods like stamp, STPA, net harms, and things like that. There are very few methods that do that, though.

Can you really wrap your head around the full system in the age of complexity we’re in? I’m thinking many organizations don’t even have a process map that tells them how the work is being done. Or the process map is outdated by 10 years.

That’s right.

The system can be incredibly complex.

That’s right. When I say a description of the full work system, I acknowledge that we’re never really describing the full system or getting a full handle on it. But I think at least you need to base your risk assessment on some model of the broader socio-technical system and how work is actually designed, planned, and then undertaken. I like the idea, for example, that organizations can have living, breathing models of the work system, and when they implement change, they can then update their models. We’ve looked at doing that thing like Nancy Leveson’s stamp control structure. I do acknowledge that that’s a big undertaking and you never fully getting to grips with what’s actually going on in the system. But I think at least some model of that allows you to get a better sense of all of these different risks that you need to manage.

Are there some additional pieces from a risk assessment standpoint in terms of, if I think about from a safety management system, management of change, trying to understand as you make decisions, how could it be layering in? There could be more steps where we’re forcing people to understand. I saw in one organization, they introduce a language, planning red flags whenever they’re introducing risk. Because in the Swiss cheese part, it’s the layering of the risk as well. So, one risk on its own may be a necessary evil of running business but understanding where we’re planning risk in a particular decision-making process.

Yeah. So, I think there’s more that people can do. And I think some of that, trying to understand about things that are being introduced and what potential unwanted consequences might emerge from that. It is a really good process for organizations to go through. And I think as we get more sophisticated with dynamic modeling tools, we can become better at that. So, we can become better at understanding how if we’re introducing a certain policy or a new procedure or new technology, what the knock-on effects of that are across the broader system. Some of the work that we’re doing at the minute, for example, is we’re using things like computational modeling to try and simulate the behavior of a system over time and see what happens when we introduce different interventions. Does it solve the problem we’re trying to solve, but does it also create unwanted effects elsewhere in the system? And that’s a very academic, again, ivory tower exercise. But as we get more advanced software programs and tools, I would think that would be something that organizations can start to do themselves.

I think, as you said, the first step is to understand that there is a system impact and understand, getting people to better understand how they impact indirectly decision making, where the rubber hits the road and start understanding, having the conversations around it to then be able to identify the risks that we’re introducing.

That’s right. A good example. I’ve mentioned Claire Dalet’s work, who was a PhD student of mine. Her work was in the space of led outdoor activities. Basically, when kids are taken on school camps and there’s an educational component, but they’re led by an instructor. We’ve done a lot of work in that sector. Her work involved developing the net harms prospective risk assessment method. But I think the most powerful piece of her PhD was actually she did what we call a hierarchical task analysis of how an organization sets up, plans, organizes, and delivers. I think it was a five-day hike for a school, a bunch of school kids, right? Sure. I think the most powerful part of her PhD was to say, look, there’s this whole system of work, and actually there are, I think, five times more risks in the planning and organization phase of the work than actually delivering the hike on the ground out in the wilderness. And that was such an education piece for the sector because it was really saying, yes, we can dynamically manage risks as they occur during the hike, and we have a good experience and knowledge of what those are.

But actually, all of the more powerful and difficult risks are in there before we even get out there. They’re in the organization when we’re planning and organizing this hike. So that was really a really powerful piece of work, I think, for that reason.

Another thought is, is there anything that can be done as well in terms of how we train, educate those that are in the field? Because there’s a system part. But if I think about the flight deck as an environment, a lot of it is really how do we get better decision making, how do we communicate in those circumstances versus what you mentioned before, the procedures tend to get you to think in a very linear way in a very complex system.

Yeah, I mean, absolutely. I think dynamic risk assessment, obviously, is something we can train. But I think really, I’m always reticent to fall back on the training argument because I’ve seen it as a solution proposed so many times to cover up problems in the design of the work and the design of the technologies that the people are using. So, I think really the key is joint optimization. If we’re really thinking about jointly optimizing humans, procedures, and technologies from the get-go, we’re not going to really need to step in with additional training programs to manage things. We’re going to be sorting these issues out through the design of the work and the technologies.

I think where it’s going is more the if I expect you to be a problem solver as opposed to following a procedure, then you may be more aware of the risk in front of you.

Absolutely.

But I agree, it’s not the end-all be-all solution because I’ve seen that as well, where something goes wrong and it’s retrained irrespective of what happened. Paul, thank you so much for joining me. Really insightful thoughts in terms of pushing people to really think about the system and how you can have events that really made sense to everyone at the time, and that we need to really start thinking organizationally in terms of, really, how do we start moving towards more of a systems thinking perspective? How do we get everybody realizing how they impact the system through their decision making?

It’s been great to chat, Eric, and there’s really interesting questions. Thank you for having me.

If somebody wants to get in touch with you, What’s the best way to do that?

You can flick me an email, [email protected] or just flick me a message on LinkedIn. You’ll find me on there as well.

Excellent. Thank you so much for joining me today, Paul.

Thanks, Eric.

Thank you for listening to The Safety Guru on C-suite Radio. Leave a legacy. Distinguish yourself from the past. Grow your success. Capture the hearts and minds of your teams. Elevate your safety. Like every successful athlete, top leaders continuously invest in their safety leadership with an expert coach to boost safety performance. Begin your journey at execsafetycoach.com. Come back in two weeks for the next episode with your host, Eric Michrowski. This podcast is powered by Propulo Consulting.

ABOUT THE GUEST

Dr Paul Salmon is a professor of Human Factors and creator of the Centre for Human Factors and Sociotechnical Systems at the University of the Sunshine Coast. He has almost 25 years’ experience of applied Human Factors and systems science research in a diverse set of domains. Paul has co-authored 23 books and over 300 peer-reviewed journal articles. His current research interests are focused on the application of Human Factors and systems science to manage societal and global risks. Paul has received several prestigious awards from the International, Australian, US, and UK Human Factors and Ergonomics societies, and for the past 5 years, The Australian has identified him as Australia’s field leader in the area of quality and reliability.

For more information: https://www.usc.edu.au/staff/professor-paul-salmon#research

RELATED EPISODE

STAY CONNECTED

The Safety Guru with Eric Michrowski

More Episodes: https://thesafetyculture.guru/

C-Suite Radio: https://c-suitenetwork.com/the-safety-guru/

Powered By Propulo Consulting: https://propulo.com/

Eric Michrowski: https://ericmichrowski.com

EXECUTIVE SAFETY COACHING

Like every successful athlete, top leaders continuously invest in their Safety Leadership with an expert coach to boost safety performance.

Safety Leadership coaching has been limited, expensive, and exclusive for too long.

As part of Propulo Consulting’s subscription-based executive membership, our coaching partnership is tailored for top business executives that are motivated to improve safety leadership and commitment.
Unlock your full potential with the only Executive Safety Coaching for Ops & HSE leaders available on the market.
Explore your journey with Executive Safety Coaching at https://www.execsafetycoach.com.
Executive Safety Coaching_Propulo