Incidents occur when required operating states (ROS) are compromised by credible failure modes because the business inputs that should prevent or mitigate the compromised are:

  • inadequate (poor design and/or poor specification
  • Inadequately implemented (people do not understand business input requirements)
  • Not being applied (monitoring of business input status is inadequate)

Credible Failure mode is addressed by:

  • BI.00.23 Incident Reporting, Investigation and assigning Corrective Actions that improve business processes.
  • BI.01.05 Response to alarms and other vehicle notifications – information prepared for operators


