Safety, Social Performance and Talent Management 1
Health and Safety Leadership, Risks and Critical Controls 2
Quantum Potential Index – Qpi: Measuring What Cpuld Have Happened Applied to Fatigue and Drowsiness in 24/7 Mining Haulage Systems WA Lino, Proposed by the author Department of Occupational Health and Safety, Las Bambas Mining, Peru (Presenting author: walter.lino@mmg.com) Abstract Fatigue and drowsiness remain critical factors in high-potential events within continuously operating, heavy-duty mining haulage systems. Although in-cab monitoring systems allow for real-time detection of fatigue states, their application is predominantly reactive and focused on the individual. This study presents a conceptual application of the Quantum Potential Index Applied to Fatigue (QPIFAT) aimed at anticipating high-potential systemic states associated with fatigue and drowsiness before critical alarms occur. Conceptually inspired by state superposition principles, QPIFAT integrates observable, latent, human, and environmental variables to represent preventative configurations prior to operational collapse. The approach is currently in the design and pilot planning phase, with trials scheduled to begin in 2026. This version describes the theoretical framework, the proposed methodology, and a conceptual simulation based on representative patterns of the OAS (Operator Alert System) currently in use at Minera Las Bambas, maintaining technical neutrality and without premature empirical conclusions. Keywords Fatigue, drowsiness, mining haulage, potential states, predictive risk, SIF-P. 1. INTRODUCTION Fatigue management in the mining industry has evolved significantly over the last decade through the incorporation of in-cab detection systems and continuously operating (24/7) control centers. These systems have enabled the real-time identification of drowsiness and the activation of intervention protocols at the individual level. However, despite these advances, high-potential fatigue-related events continue to occur, primarily as a result of the systemic accumulation of operational stresses that are not always immediately or readily apparent. In this context, the need arises to complement predominantly reactive approaches with models capable of anticipating dangerous system states before they collapse into critical events. Fatigue thus ceases to be understood exclusively as an individual condition and is addressed as an emergent phenomenon of the work system, influenced by multiple variables that interact simultaneously. The operational context analyzed corresponds to a large-scale mining operation characterized by: 3
● Two open pits in simultaneous operation. ● A haulage system that operates continuously (24/7), with day and night shifts. ● More than 1,100 operators exposed, including 178 mining truck operators. ● A dispatch center that monitors the fatigue alert system in real time. ● The presence of risk-amplifying factors, such as long ramps, mixed traffic, presence of water on the runway, and variability in the experience and age of the operators. The OAS system classifies fatigue events into different severity levels and activates pause and control protocols from the control center. However, historical analysis of its reports reveals limitations inherent in an event-centric approach, such as: ● Repeat offenses by operators with multiple fatigue alerts. ● Concentration of alarms at certain times, shifts and months. ● Persistence of events despite the application of active breaks. ● Occurrence of events in critical time windows. These findings highlight that, while the system effectively detects the manifestation of the event, it does not provide an explicit reading of the accumulated state of the system or the probability of occurrence of future high-energy events, reinforcing the need for an anticipatory approach at the systemic level. 2. PROBLEM DEFINITION Modern mining continues to manage risk primarily by measuring past events, such as incidents, deviations, operational failures, critical exposures, or performance losses. While traditional statistical models allow for the analysis of historical trends and the estimation of probabilities, these approaches have structural limitations when dealing with complex, dynamic, and constantly evolving systems. In particular, three main limitations are identified: 2.1.Dependence on the past Conventional models require significant volumes of historical data for calibration, which do not always represent emerging conditions, unprecedented configurations, or accelerated changes in operating systems. 2.2.Exclusion of unobservable states Many critical system configurations never materialize as reportable incidents or events. However, these configurations may contain significant operational stresses that increase the potential for high-energy events, remaining invisible to traditional indicators. 2.3.Limited anticipatory capacity Most indicators considered “predictive” rely on indirect proxies, such as behavioral reports, inspections, or observed unsafe conditions, which offer limited and, in many cases, late anticipation of dangerous system states. 4
As a result, risk management tends to maintain a retrospective and reactive character, with low sensitivity to detect emerging states or unprecedented combinations of variables that have not yet been previously experienced. In the specific area of fatigue and drowsiness, current systems allow for the real-time identification of fatigued operators; however, they have structural limitations in anticipating systemic configurations prior to the event's manifestation. The recurrence of alerts, their concentration by shift, route, or specific periods, and the persistence of events despite the implementation of active breaks, demonstrate that fatigue must be addressed as an emergent phenomenon of the work system, and not solely as an individual condition. In this context, the Quantum Potential Index Applied to Fatigue (QPIFAT) proposes to incorporate unobserved potential states within a formal structure, with the purpose of anticipating possible futures before their materialization, thus complementing traditional detection and control approaches. 3. STATE OF THE ART Globally, research in predictive mining has focused on: ● Machine learning models based on supervised and historical training. ● Predictive maintenance systems. ● Equipment reliability models. ● Bayesian probability applied to security events. ● Discrete event simulation models. ● Predictive indicators derived from human behavior. Although these approaches offer value, they share a common limitation: none explicitly incorporates the concept of overlapping possible futures, understood as the simultaneous coexistence of multiple preventative configurations before the materialization of an event. A similar conceptual framework can be found in: ● Intrinsically Safe Design (ISI). ● Early hazard identification (EN-HazID) in process engineering. ● Models of complex systems in aviation and petrochemicals. ● Advanced “leading indicators” approaches. However, none of them formalize the representation of simultaneous potential states. The QPIFAT seeks to fill this methodological gap. At the industrial level, fatigue management relies on work-rest rules, physiological monitoring, statistical analysis of alarms, and probabilistic models. While these approaches offer value, none formalizes the simultaneous coexistence of multiple possible futures before an event occurs, nor does any structuredly integrate latent and human variables within an anticipatory framework. 4. FOUNDATIONS OF QPIFAT The Quantum Potential Index Applied to Fatigue is a conceptual model inspired by principles of quantum physics, used metaphorically to represent the behavior of complex organizational systems. The use of the term “quantum” does not imply the direct application of quantum mechanical equations but rather serves as an analogy to describe the coexistence of multiple possible operational futures before an event occurs. 5
The model is based on two fundamental conceptual principles: 4.1.Overlap of states Before an event materializes, the operating system can simultaneously exist in multiple potential configurations. Each of these configurations possesses a distinct level of operational energy, systemic tension, and materialization potential, even though not all are directly observable through traditional indicators. ( 1, 2,…, ) From this perspective, fatigue is not manifested solely as a single event, but as a result of the dynamic interaction of multiple variables that coexist in the system before its explicit manifestation. 4.2.System collapses due to decision or condition When the operation selects a specific course of action, or when a critical condition occurs (for example, a high-severity fatigue alert), the system collapses into a single observable state. At this point, the event ceases to be potential and becomes part of operational history. The QPIFAT is geared towards observing and quantifying the system before this collapse, when it is still possible to intervene in a preventive and less disruptive way. The QPIFAT proposes to represent potential states using: ● Observable precursor variables (O): frequency and severity of fatigue alerts, recurrence rates, operational response times. ● Latent variables not directly measurable (L): Trends in accumulated fatigue, operational pressure, actual effectiveness of recovery actions. ● Dynamic human factors (H): level of experience, overtime, rotation patterns and shift adaptation. ● Environmental and energy conditions (E): night operation, visibility, presence of water, track geometry and physical-environmental condition of the cabin (vibration, temperature, dust and noise). These families allow the representation of both explicit signals and underlying conditions that contribute to the accumulation of potential before the occurrence of high-impact events. A conceptual function is preliminarily defined: QPIFAT = ∑ (Ψᵢ · Wᵢ) Where: ● Ψᵢ = Potential state i expressed as a preventative vector. ● Wᵢ = Mathematical weight associated with criticality and operational energy. This formulation is conceptual and exploratory in nature, and will be refined, calibrated, and validated during the pilot phase using real data from the fatigue monitoring system. 5. CURRENT CAPABILITIES OF OAS SYSTEMS Operator alertness monitoring and alerting systems (OAS) are currently one of the most widely implemented technological controls for managing the risk associated with fatigue in large-scale mining operations. These systems allow for continuous, real-time monitoring of operator alertness by detecting physiological and behavioral indicators associated with fatigue during equipment operation. 6
The main contribution of OAS systems lies in their ability to identify fatigue events at the individual level, enabling immediate alerts and short-term interventions, consistent with established fatigue management protocols. In this context, OAS acts as a reactive, event-based safety control, supporting operational decision-making the moment detectable fatigue symptoms appear. However, while OAS improves situational awareness at the operational level, its analytical scope remains limited to the operator's current state. The system does not intrinsically assess the broader operational context, cumulative exposure, or latent conditions that may influence system vulnerability before observable indicators of fatigue become apparent. 5.1.Structural Limitations of Event-Based Fatigue Monitoring Despite their operational value, OAS systems have inherent structural limitations when analyzed from a systemic risk anticipation perspective. Specifically, these systems are designed to detect fatigue manifestations rather than anticipate pre-failure systemic states associated with high-potential energy transfer. OAS outputs are primarily interpreted as discrete events, triggering localized responses such as task reassignments, rest breaks, or temporary equipment shutdowns. While these actions are necessary and effective at the operational level, they do not address the latent accumulation of risk factors that may be developing throughout shifts, production cycles, or operational interfaces. Furthermore, OAS systems do not inherently integrate contextual variables such as operational pace, exposure density, task criticality, or accumulated system stress. Consequently, they provide limited visibility into whether the operational system is approaching a critical threshold where a fatigue-induced loss of control could lead to a high-severity event. This structural limitation highlights a significant gap between fatigue detection and fatigue risk anticipation, reinforcing the need for a complementary framework capable of transforming existing OAS data into an anticipatory representation of risk at a systemic level. 5.2.QPI redesign using OAS as the backbone (integrated model) 5.2.1. New Potential Systemic State S-FAT-OAS Status High-energy event potential arising from fatigue/drowsiness in haulage, before the critical alarm occurs. 5.2.2. Construction of the ΨFAT vector using REAL variables of the system A.Observable precursor variables (O) – directly from the system Clear and defensible examples: ▪ O1: OAS alarm rate per 1,000 driving hours ▪ O2: % of moderate + critical alarms ▪ O3: number of operators with ≥2 events in the same shift 7
▪ O4: average response time of the control center ▪ O5: monthly upward trend (negative slope) All of this is already in the report B.Latent variables (L) – inferred from the system Here is the conceptual leap in the representation of the system state: ▪ L1: accumulated fatigue (proxy: monthly recurrence per operator) ▪ L2: operational pressure (proxy: months with higher event density) ▪ L3: reliability of the human-technical system (repetition despite pauses) ▪ L4: poor physiological adaptation to shift work (day/night) These variables are not explicit, but the system reveals them indirectly. C.Dynamic human factors (H) Based on cross-referencing the current system + HR: ▪ Percentage of operators with little experience in heavy tonnage ▪ Percentage of events concentrated in certain groups/contractors ▪ Operators who "pass the protocol" but raise another alarm days later ▪ real effectiveness of the active break (does it reduce recurrence or not?) D.Environmental and energy conditions (E) Derived from the aforementioned operational context: ▪ night driving ▪ Water on the track ▪ long ramps ▪ Mixed traffic (light vehicles + trucks) ▪ intersections ▪ presence of fog These conditions do not cause fatigue, but they amplify it energetically. 6.QPIFAT SIMULATION WITH OAS DATA “The numerical values presented are illustrative only and do not represent calibrated system thresholds.” The simulation considers the integration of variables from four main families: observable precursor variables, latent variables, dynamic human factors, and environmental and energy conditions, consistent with the conceptual framework described above. The observable precursor variables (O) were associated with the rate, severity, and recurrence of fatigue alerts, as well as the operational response times recorded by the system. The latent variables (L) represented the accumulation of fatigue over time, inferred from annual trends and recurrence patterns. Dynamic human factors (H) included differences in experience, shift rotation, and prolonged exposure, while environmental and energy conditions (E) 8
incorporated factors such as nighttime operation, prolonged ramps, the presence of water on the runway, dust, and cabin vibration. The normalized values used in the simulation were as follows: ● O = 0.68, corresponding to a high rate and recurrence of fatigue alerts. ● L = 0.60, associated with an accumulated fatigue evident in historical trends. ● H = 0.55, representative of recidivism combined with heterogeneity in the experience of the operators. ● E = 0.45, related to the combination of night operation, demanding geometric conditions, presence of water, dust and vibration. It should be noted that, although the variables are derived from real data structures of the system, the numerical values used correspond to a conceptual simulation and not to empirically measured or validated results. The simulation was performed using initial coefficients: α = {0.35, 0.25, 0.25, 0.15} Ψ = ∝ . +∝ . +∝ . +∝ . These coefficients were defined through structured expert judgment, based on operational experience in large-scale mining haulage systems. They will be recalibrated during the pilot phase. The potential preventive state associated with fatigue was calculated as: Ψ = 0. 35(0. 68) + 0. 25(0. 60) + 0. 25(0. 55) + 0. 15(0. 45) Obtaining a value of: = 0.594 Ψ For direct management purposes, and considering a unit weight, the operational fatigue index is expressed as: = 1. 0 = 100×0. 594 = 59. 4 This value does not represent an individual operator in a state of fatigue but indicates that the haulage system is operating in a state of high latent potential, characterized by the coexistence of multiple conditions that increase the probability of occurrence of high energy events. The result suggests that, even in the absence of widespread critical alarms, the system may be in a configuration that warrants preventive attention at a systemic level, reinforcing the value of QPIFAT as an anticipatory complement to traditional detection approaches. A high QPIFAT value does not indicate that an accident will occur, but rather that the system is operating in a configuration where multiple high-potential futures coexist, and where early preventive intervention is more effective and less disruptive. When can it be stated that there is NO latent high potential state? Preliminarily, and under the conceptual framework of QPIFAT, it can be stated that there is no state of high latent potential when: ● The index value remains below 45, and 9
● no sustained upward trend is observed over time, and ● Latent and human variables remain decoupled from environmental conditions. In these cases, the system may experience isolated fatigue alerts without these representing a dangerous systemic configuration. “For interpretative purposes, preliminary threshold bands were defined and discussed in Section 12” 7. WHAT RADICALLY CHANGES WITH QPIFAT + OAS? Aspect OAS today OAS + QPIFAT Approach Reagent Predictive Analysis unit Operator System + shifts + routes Horizon Minutes Days / weeks Decision Pause Shift redesign, staffing, routes Strategic value Complian ce Anticipation of SIF-P (Potential Fatalities and Serious Injuries) Aspect Traditional Approach QPIFAT Horizon Reagent Anticipatory Analysis unit Operator System Time of intervention Post-alarm Pre-alarm 8. METHODOLOGY Although the focus is conceptual at this stage, it follows a clear procedural sequence that allows for its consistent application in comparable operational contexts. The methodology consists of the following stages: 8.1.Definition of data sources Existing operational data streams that will serve as inputs for the Q-SiD framework are identified and selected. These sources include, but are not limited to, outputs from fatigue monitoring systems, operational exposure indicators, work-rest patterns, and contextual operational parameters already available within the organization. No additional sensors or new data acquisition systems are required. 8.2.Selection and normalization of variables Key precursor variables associated with fatigue and exposure to high-potential energy are selected using expert judgment, ensuring their alignment with critical risk pathways. To allow comparability between heterogeneous variables, all are normalized to a common scale, enabling their integration within a single systemic representation. 10
8.3.Assignment of weights (expert judgment) Relative weights are assigned to each variable to reflect its contribution to the overall state of the system. The weighting is determined through a structured expert judgment process, considering operational experience, historical incident patterns, and the potential severity of energy transfer in the event of a loss of control. 8.4.Calculation of the index The normalized and weighted variables are aggregated to generate a composite indicator called the Integrated Quantum Fatigue Anticipation Threshold (QPIFAT). This index represents the system's potential state with respect to fatigue-related risk, rather than a direct measurement of the probability of incidents occurring. 8.5.Thresholds of interpretation Interpretation bands are defined to support decision-making. These thresholds do not represent absolute safety limits, but rather anticipatory states that indicate an increase in system vulnerability and the need to implement preventive or corrective actions. The threshold values used in this study are for reference and are geared toward the pilot validation phase. 9. PROPOSED APPLICATION (PILOT) In accordance with the WMC 2026 guidelines, the pilot will be implemented in mining operations during the first quarter of 2026. At the time of delivery of this document: ● The pilot project is currently in the design phase. ● No empirical data is available yet. ● The graphs, tables, and results will be incorporated into the final version (before March 2, 2026). Sections reserved for future results ● Tables, graphs, and comparative analysis will be completed with the results after the pilot is finished. 10.EXPECTED IMPACT In general, QPI seeks to add a new layer of anticipation to preventive systems through: ● Early identification of critical configurations. ● Increased sensitivity to unobserved states. ● Better prioritization in operational intervention. ● Reduction of high-potential events (conceptual projection). ● Greater alignment with future mining based on data and complex systems. Specifically, QPIFAT is expected to bring a new layer of anticipation to fatigue management by identifying critical configurations early, better prioritizing interventions, and reducing the risk of high-potential events, aligning with the principles of mining for the future. These estimates will be empirically validated during the pilot phase. 11
11.SCALABILITY This scalability positions QPIFAT not as a site-specific tool, but as a transferable, anticipatory framework for high-energy mining systems globally. 12.DISCUSSION The conceptual simulation developed allows for the analysis of the behavior of the Quantum Potential Index applied to fatigue (QPIFAT) as a systemic indicator oriented towards anticipating high-potential states, rather than directly predicting events. The value obtained (59.4) should be interpreted as a measure of the level of accumulation of conditions that increase the potential for occurrence of high-energy events associated with fatigue and drowsiness. The QPIFAT is conceived as a continuous indicator, where increasing values reflect greater convergence among observable variables, latent conditions, human factors, and environmental conditions. In the case analyzed, the value of 59.4 falls within a preliminary range of high latent potential, indicating that the haulage system could be operating under a configuration that warrants preventive attention at a systemic level, even in the absence of widespread critical alarms. For interpretive purposes, and considering the conceptual nature of the model, exploratory QPIFAT ranges are proposed. Values below 30 would represent a state of low latent potential, while values between 30 and 45 would indicate moderate potential requiring enhanced monitoring. Values between 45 and 60 would reflect a state of high latent potential, and values above 60 would suggest a critical condition approaching systemic collapse thresholds. Preliminarily, it can be stated that a state of high latent potential does not exist when the QPIFAT remains below 45, without a sustained upward trend. It is important to note that these ranges are exploratory and not normative and will be calibrated during the pilot phase using real system data. The main contribution of QPIFAT is not to replace existing fatigue detection systems, but to complement them by providing an anticipatory reading of the system's state before observable events occur and supporting earlier and more systematic preventative management. This approach allows for a shift in fatigue management from a predominantly reactive approach to a systemic and preventative one, aligned with the challenges of large-scale mining and with the goal of building safer, more resilient, and sustainable operations. 13.ACKNOWLEDGMENTS Vice Presidency of Operations, Vice Presidency of SHE, Vice Presidency of HR, Mine Operations Management, Mine Management Superintendence, Mine Management Engineers, Operational Excellence Management, Safety and Health Team of Minera Las Bambas. 14.CONCLUSIONS ● The Quantum Potential Index applied to fatigue and drowsiness is a conceptual proposal aimed at anticipating high potential states in mining haulage systems before their operational manifestation. 12
● Current fatigue monitoring systems fail to detect fatigue once the event has occurred; QPIFAT complements this approach by observing the state of the system prior to collapse, when it is still possible to intervene preventively and in a less disruptive manner. ● While the current system focuses on managing individual conditions, QPIFAT is oriented towards managing the systemic state, integrating observable, latent, human and environmental variables. ● The proposal does not require the incorporation of new hardware, but rather a reorganization of the existing intelligence and data already available in the operation. ● This version describes the theoretical framework, methodology and a conceptual application, in line with the WMC 2026 guidelines; empirical validation and coefficient calibration will be developed during the pilot phase according to the official schedule. ● No claims of risk reduction or performance improvement are made at this stage. REFERENCES Reason, J. (1997). Managing the Risks of Organizational Accidents. Ashgate. Hollnagel, E. (2014). Safety-I and Safety-II. Ashgate. American Psychological Association (2009). Publication Manual of the APA (6th ed.). 13
Bringing Together Health and Safety Management Systems, Risk Management and Critical Control Management *L. Humphries 1Minerals Industry Safety and Health Centre, University of Queensland, Australia, (*Presenting author: e.humphries@uq.edu.au) Abstract Mining organisations implement health and safety systems in markedly different ways, particularly in how those systems connect with Operational Risk Management (ORM). Based on my personal observations, professional interactions, audits, workshops, and implementation experience across multiple sites and sectors, I have identified common patterns in how system design decisions, often implicit, shape frontline control of potentially fatal risks. Where the system architecture is unclear, inconsistent, or fragmented, it becomes extremely difficult for supervisors and crews to access credible, area-specific information about the status of critical controls, and the system struggles to function effectively where work occurs. This paper clarifies the kinds of design decisions organisations make (knowingly or unknowingly), illustrates how those choices shape operational reality, and offers a practical set of decision-point questions that attendees can use to evaluate their own systems and reinforce risk control at the point of work. Keywords World Mining Congress, safety management systems, critical controls, risk management 1. SCOPE AND CONTEXT The paper examines variation in how health and safety management systems are designed and operated across mining organisations, with particular attention to their relationship with Operational Risk Management (ORM) and to the mechanisms used to define, verify, and communicate controls for potentially fatal hazards. The focus is not on promoting a single “best” architecture, but on revealing how different architectures create different outcomes, especially for frontline decision-making and assurance. 2. SOURCE OF EVIDENCE Findings derived from my personal observations and lessons learned through audits, operational workshops, system implementations, and engagement with professionals across multiple organisations with frontline supervisors, operational leaders, and senior managers. Evidence includes facilitated discussions, and reviews of real organisational artefacts such as 14
procedures, risk assessments, investigation outputs, and performance reports. These experiences span different commodities, operational models, and regulatory contexts. 3. STATE OF PRACTICE: HOW SYSTEMS DIFFER AND WHY IT MATTERS Across organisations, health and safety systems range from fully integrated with ORM to deliberately separate frameworks with occasional touchpoints. Some adopt a single taxonomy and risk matrix across operations, safety, and health; others maintain separate definitions, thresholds, and reporting lines. Variation in itself is not a problem: different designs can work when implementation choices are explicit, coherent, and well-communicated. The difficulty arises when the design rationale is undocumented or forgotten, leaving people to make local interpretations that gradually diverge. Over time, language, thresholds, and assurance routines slip out of alignment. A recurrent barrier is information architecture: critical‑control definitions, verifications, and status evidence are often scattered across risk registers, safety applications, work management systems, and spreadsheets. Without a clear single source of truth and stable identifiers, supervisors cannot be certain that the control information they are viewing is the latest version for today’s work area. At the frontline, this often presents as uncertainty about which controls matter most, who is responsible for verifying them, and where the evidence is kept. A second recurring pattern concerns the way risk assessments operate across different layers of the organisation. At the organisational level, risk assessments focus on material unwanted events, risk registers, and bowtie analyses. These artefacts are often technically robust, but frontline workers and supervisors are rarely involved in their development. As a result, the insights generated at this level, particularly around critical controls, do not always flow clearly to the people expected to apply them in daily operations. At the project or change-management layer, involvement from workers and supervisors is generally stronger, yet variability persists in how risk tools are selected and applied. Some organisations mandate a single method, while others allow multiple approaches depending on project scope or contractor preference. This flexibility enables projects to select the tools most suited to identifying potentially catastrophic scenarios, promoting deeper analysis and better engagement. Without deliberate integration mechanisms, valuable learning captured during projects can remain isolated rather than informing routine work. At the task-based layer, tools such as Job Safety Analysis (JSA)s are widely used, but many templates begin as a blank page and provide limited connection to the organisational risk assessments above them. In many cases, the design of the JSA form itself has not been approached with human-centred design principles in mind. Critical information such as the key controls identified at the organisational or project levels is not accessible or scaffolded within the tool. Workers are therefore required to reconstruct risk understanding from scratch, relying on memory or local norms, and to hunt across multiple systems for the “right” information without certainty that what they find is the most up‑to‑date control specification, which increases the likelihood that important controls are overlooked or inconsistently described. A recurring challenge at the frontline is the lack of clarity about whether the frontline tool (e.g. SLAM, Take 5) being used is intended as a genuine risk assessment or as a verification activity. If the tool is meant to function as a risk assessment, there must be a clear understanding 15
of how it interacts with the task-based JSA process: when a JSA is required, how the frontline assessment builds on the analysis already completed, and what information should flow down from earlier layers so workers are not expected to recreate organisational risk understanding on the spot. If, instead, the tool is intended as a verification step, then its design should focus on confirming the presence and effectiveness of the controls that matter most for the specific task, particularly those that prevent single or multiple fatalities, rather than defaulting to generic checks or low-consequence hazards. In the absence of explicit design decisions, frontline tools often sit uncomfortably between these two purposes, resulting in inconsistent application, variable quality, and reduced confidence that the final check is actually assuring the controls that keep people safe. 4. MECHANISM: HOW LOST OR IMPLICIT DESIGN DECISIONS AFFECT FATAL-RISK CONTROL When organisations do not acknowledge or refresh foundational design decisions around how health and safety connect to ORM, how risk criteria are defined and reconciled, where control information is stored and accessed, where critical controls live and how they are verified and how investigations feed back into the information chain. Governance reports may present confidence, while supervisors lack reliable, area-specific signals of control status. Investigations can generate corrective actions without updating the risk profile or control standards. KPIs drift toward counting activity rather than testing effectiveness. In this environment, managing potentially fatal risks becomes inconsistent because the system’s intent is not mirrored in what the frontline can see and verify. 5. METHOD This paper synthesises patterns identified through direct professional experience: recurring issues observed during system reviews, control-verification activities, audits, and collaborative safety workshops. These reflections highlight practical system behaviours rather than theoretical constructs, drawing on insights from frontline workers, supervisors, managers, Site Senior Executives (SSEs), and Subject-Matter Experts (SMEs). 6. FINDINGS Across organisations, several consistent patterns emerge. Variation in system design is normal, but when the rationale for that variation is not captured and refreshed, clarity erodes and people begin to work from different assumptions. Loss of organisational memory is a central mechanism in this drift: the original design decisions, whether to integrate or deliberately separate health and safety processes from other operational systems such as work management, planning, maintenance, or process control, often become implicit, undocumented, or forgotten. As those decisions fade from view, taxonomies and thresholds evolve locally, and the definitions used to identify and prioritise material unwanted events diverge. These design choices extend to the selection and shaping of tools. Decisions about which tools are used at different layers and how they are designed, particularly task-based tools such as 16
JSAs and frontline checks are frequently underpinned by assumptions that are not made explicit to users. Where the tools have not been developed with human-centred design principles, templates tend to start blank, provide limited scaffolding from higher-level analyses, and do not surface the specific controls that matter most for the task at hand. Frontline processes labelled as risk assessments often function as verification steps, yet without clear intent or reliable inputs they may focus on low-consequence hazards while under-testing the controls that prevent single or multiple fatalities. The cumulative effect is that supervisors and crews lack timely, task-relevant information about control status, investigations struggle to drive visible updates to improve control effectiveness, and governance signals drift toward activity counts rather than evidence that critical controls are present and functioning where work occurs. Across these cases, uncertainty about storage location, access pathways, and version currency is a consistent contributor: without a single, authoritative source in the tools supervisors actually use, frontline confidence in “what is current” remains fragile. 7. PRACTICAL OUTPUT: DECISION-POINT QUESTIONS TO USE BACK AT SITE The purpose is to equip leaders with practical questions that surface design decisions and test whether the system consistently delivers what matters most to the point of work: clear, task relevant visibility of critical controls that prevent fatal and severe harm, and confidence that those controls are in place and functioning before work begins. 1. Role clarity & competency Is it straightforward for supervisors and frontline workers to know exactly which controls/critical controls they own, what “effective” looks like for each? 2. Risk criteria & like for like responses Do current risk definitions and matrices produce consistent escalation for fatal and severe harm across sites and functions (no matter which tool is used), so that like for like risks receive like for like responses? 3. Integration of health and safety with operations Whether safety and health are integrated or deliberately separate, are there defined pathways that ensure exposure controls, monitoring results, and investigation learnings flow into operational planning, permits, and prestart briefings in language that supervisors and crews can act on? 4. Single source of truth for critical controls Where do critical controls “live” (risk register, safety system, work management, operational planning), what is the single source of truth, and are identifiers stable and consistent so verification evidence can be traced from the field to governance without re translation? How is this source made visible inside the tools supervisors actually use? 5. Frontline information before work starts What specific, area relevant information reaches supervisors about material unwanted events, the controls that matter most for today’s tasks, who verifies them, the time stamp of last verification, and where evidence is stored? Is the information pulled from a single, current, repository and presented in a format accessible at the point of work (not buried in multiple systems)? 6. Design of task-based tools (JSA) 17
Do task-based risk assessments (e.g., JSAs) embed human centred design? For example, prepopulating the known critical controls from higher layers, using plain terminology, and prompting for control effectiveness rather than generic hazard lists so workers aren’t starting from a blank page. 7. Frontline checks: risk assessment or verification? Is the frontline tool (e.g., quick check/last minute tool) explicitly defined as a risk assessment or as a verification activity? If it is a risk assessment, when is a JSA required and how do the two processes interact? If it is verification, does it confirm the presence and functioning of the few controls that prevent fatal and severe harm for the specific task (not just low consequence hazards)? 8. Learning loops & organisational memory When investigations or weak signals indicate control failures or design gaps, how are risk profiles, control standards, and verification routines updated, communicated, and anchored in the system? 9. Assurance that tests effectiveness, not activity Which KPIs and sampling approaches directly test control effectiveness (evidence that controls are present and working) rather than activity counts? Are results reviewed for quality and fed back to supervisors and crews in a way that improves day to day decisions? 10.Decision rights & capability at each level Who holds authority to make or change system design decisions (definitions, tool selection, data architecture), and what competencies are required for frontline workers, supervisors, managers, SSEs, and SMEs to sustain those decisions through role changes? 11.Version control & currency at the point of work How do workers and supervisors know they are viewing the latest control specification for this task and area (e.g., visible version labels, effective date banners, last verified indicators)? What prevents local downloads or shadow copies from becoming the de facto source? When a control standard changes, how is the update propagated into JSAs, permits, and frontline checks so the new requirements are immediately visible? 8. DOCUMENTING VARIATION AND ITS EFFECTS To ground discussion, Table 1 captures common system-design variants and the operational effects most often reported by participants. The intent is not to declare one pattern “right,” but to show how different choices predictably shape frontline experience. Table 1 - Examples of design variants and observed frontline effects 18
Design choice (variant) Typical rationale Observed effect at the frontline Single, enterprise-wide risk matrix vs. multiple matrices (enterprise/corporate/site) Comparability vs. technical nuance A single matrix can strengthen consistency, improve understanding of escalation thresholds, and provide clarity on what constitutes “high” or “critical.” Multiple matrices can support technical specificity where needed, but when poorly reconciled they create confusion as thresholds and colour conventions diverge. This leads to inconsistent escalation decisions, uncertainty about required controls, and disagreement over risk priority. Health integrated with safety vs. separate health framework Unified reporting vs. specialist focus When integrated well, frontline personnel receive a unified picture of exposure and injury risks, making pre-start discussions more coherent. When health is separate but clearly linked, specialist knowledge is preserved and controls can be more targeted. However, if separation is poorly linked, exposure controls and monitoring results do not reliably reach supervisors, health-related learnings move slowly across boundaries, and workers may miss critical information about noise, dust, vibration, or psychosocial risks relevant to today’s tasks. 19
Design choice (variant) Typical rationale Observed effect at the frontline Critical controls stored in safety tool vs. operational planning vs. ORM Ownership clarity vs. system constraints When critical controls have a clearly defined single source of truth frontline leaders gain confidence in verification requirements, and evidence can be traced through planning, execution, and governance cycles. When controls are distributed across tools without alignment, verification evidence becomes fragmented or duplicated, making it difficult to confirm whether controls are in place. This reduces confidence, delays decisions, and complicates conversations about control effectiveness. Document-centric assurance vs. control-effectiveness assurance Ease of auditing vs. operational realism Control-effectiveness assurance helps supervisors and crews understand whether controls actually work under current conditions, strengthening trust and decision-making. A document-centric approach can shift conversations toward completing forms rather than confirming the functionality of controls, weakening the link between system intent and operational practice. 9. LIMITATIONS The paper reports practice-based, qualitative insights rather than a single controlled study. Sites differ in technology, regulation, and workforce composition. Nevertheless, the patterns appear consistently across multiple cohorts, companies, and contexts. Examples have been generalised and anonymised to protect confidentiality while preserving learning value. 10. CONCLUSION Health and safety systems are shaped by design choices that often become invisible over time. When those choices are explicit, coherent, and well-communicated, integrated or separated 20
frameworks can both perform. When they are implicit or forgotten, gaps open in the information chain, and the burden of interpretation falls on the frontline, precisely where certainty is most needed to manage potentially fatal risks. By using the decision-point questions provided here, organisations can recover the “why” behind their systems, reconcile differences that matter, and restore the flow of credible control information from governance to the point of work. ADDITIONAL RECOMMENDED READINGS Selected articles relevant to learning systems, supervisor capability, and critical control management: Macmahon, S., Corbett, B., Hassall, M., Humphries, L., Carroll, A., & Deboer, R. (2025). “Passion, style, and smarts”: Industry perspectives on supervisor competencies in the mining industry. Journal of Workplace Learning, 37(9), 132–151. https://doi.org/10.1108/JWL-03-2025-0052 Hassall, M., & Lant, P. (2023). Fundamentals of risk management for process industry engineers. Elsevier. https://doi.org/10.1016/C2019-0-01193-4 REFERENCES Standards Australia/Standards New Zealand. (2018). Occupational health and safety management systems—Requirements with guidance for use (AS/NZS ISO 45001:2018). https://www.standards.govt.nz/shop/asnzs-iso-450012018 International Council on Mining and Metals. (2015). Health and safety critical control management: Good practice guide. https://www.icmm.com/en-gb/guidance/health-safety/2015/ccm-good-practice-guide NSW Department of Trade and Investment, Regional Infrastructure and Services. (2015). NSW code of practice: Safety management systems in mines. https://www.resources.nsw.gov.au/sites/default/files/documents/nsw-code-of-practice-safetymanagment-systems-in-mines.pdf Hassall, M., Joy, J., Doran, C., & Punch, M. (2023). Selection and optimisation of risk controls (ACARP Project No. C23007). Australian Coal Association Research Program. https://www.acarp.com.au/abstracts.aspx?repId=C23007 21
Assessing Situation Awareness In Automated Mining Systems To Improve Safety And Productivity *Loreto Codoceo-Contreras1, Maureen Hassall1 and Danellie Lynas1 1Minerals Industry Safety and Health Centre, Sustainable Minerals Institute, University of Queensland, Australia, (*Presenting author: l.codoceo@uq.edu.au) Abstract The safety benefits of automation are undeniable when humans are removed from hazardous and hostile areas around machinery and unstable ground. However, crucial safety-critical aspects of human-system interaction are often overlooked in the adoption of automation in the mining industry. This is evident in the incidents reported in Australia between 2010 and 2021 involving autonomous haul trucks and surface blast-hole drills. These events were associated with a loss of situational awareness (SA), communication failures, over-trust, increased workload, and complex interactions. All these issues involved human interaction with technology. Contributing to this problem is the fact that the existing global standards and guidelines for the safe implementation of automation in mining are insufficient from a human-centred design perspective. This research involved case studies of mining systems (automated loaders, autonomous trucks, longwall automation, and autonomous drills) with different levels of automation. Site visits were undertaken to mines in Australia and Chile, specifically where automated systems have been implemented. Participants included field and control room operators, managers, supervisors, and engineering personnel. Documentation review, interviews and observations were selected as research methods. The semi-structured interviews were conducted to collect data on automation transition, decision-making, data processing, and communication. Then, observations and audio recordings of the tasks were used to capture all types of communication (between operators and equipment) within the system. The proposed research sought to discover what human factors are significant for ensuring the successful implementation of automation. Two significant insights to come from the research were the identification of SA-related deficiencies and the critical elements of information exchange between system agents. Keywords Situation awareness, automation, communications, trust in automation 1. INTRODUCTION Automation has become imperative to improve productivity and safety in the mining sector, particularly for addressing rising demand, incremental operational costs, and competitive pressure. It is also acknowledged that ongoing automation and digitalisation are crucial for 22
sustainable mine development and it is changing the mining ecosystems and revolutionising its traditional value chain (Jang & Topal, 2020). Mines of the future that adopt automation and digitalisation will improve safety, environmental performance, productivity, and energy efficiency, but also will bring new roles for people who will remain fundamental to the process (Bearne, 2014). In different contexts, implementing automated systems has been successful (Woods et al., 1997). In mining, for example, automation can reduce operators’ exposure to injury risks (Kramer et al., 2019), thereby improving safety by removing workers from hazardous mine sites (Chirgwin, 2021). However, developing new technologies and digitalisation also bring new challenges that must be appropriately identified and managed (Atkins & Ritchie, 2019). The benefits of automation in safety are undeniable, as it removes humans from hazardous and hostile areas around machinery and unstable ground. However, crucial aspects have been overlooked in the implementation of the automation processes in the mining industry. Automation does not remove the need for human involvement. It changes it, and in some cases, it can be reduced. Automation may have unforeseen impacts on systems' safety and productivity unless the role of humans is carefully considered (Horberry et al., 2016). Lessons from other industries, such as aviation and medicine (where this is common), have been introduced with the belief that human error will be eliminated and operator workload reduced. However, automation can introduce new errors and, in some cases, increase mental workload rather than reduce it (Wickens et al., 2021). A diverse range of authors has expanded the understanding of the effects of automation on situation awareness across different domains. These studies have mainly focused on aviation, medical, and military contexts. However, less is known about this phenomenon in other hazardous industries, such as mining, where errors can cause serious or fatal accidents. To address this gap, this research aimed to provide insights into how autonomous and automated systems affect situation awareness, identifying the aspects to be considered to support automation implementation and ensure safety. This study contributes to the conference theme of Health, Safety and Well-being by examining how automation influences workers’ situation awareness and the associated implications for safe systems of work in mining. 2. BACKGROUND Human factor issues at individual, team and organisational levels have far-reaching implications for safety, productivity, and organisational culture. Findings from studies on automation in aviation, land transportation, and process control indicate that the rise in automation may lead to unforeseen consequences for system safety and efficiency unless the human element is systematically incorporated. In mining, incidents regarding the interaction between human operators and automated systems will continue to occur or increase as automation becomes increasingly complex (Burgess-Limerick, 2020). According to Endsley (2017), automated systems affect situation awareness through three 23
RkJQdWJsaXNoZXIy MTM0Mzk2