Engineering the Decision Out of Machine Safety

By:

Engineering the Decision Out of Machine Safety

Less dependence on perfect human behavior. More dependable protection.

Machine safety often begins with a simple response to an identified hazard:

Put up a sign. Write a procedure. Train the operator.

Those measures have a place. Warning signs communicate hazards. Procedures establish expectations. Training helps employees understand how to work safely.

But they all have something in common:

They depend on a person making the right decision at the right time.

Engineered safety takes a different approach.

Instead of continually asking, “How do we get the operator to avoid this hazard?” it asks:

“How can we change the machine or the interaction, so the operator has less opportunity to be exposed to the hazard in the first place?”

That distinction is at the heart of effective machine risk reduction.

Administrative Safety Depends on Human Decisions

Consider a machine with an exposed hazard and a warning sign telling employees to keep their hands clear.

engineered-vs-admin-controls-infographic.png?Revision=mcP&Timestamp=7m4DQ8

For that sign to protect someone, several things have to happen:

Hazard → See the warning → Understand the risk → Remember the training → Follow the procedure → Make the right decision → Avoid exposure.

Most experienced safety professionals understand the challenge.

People get distracted.

Production pressures change behavior.

Experienced operators become comfortable around equipment.

New employees may not recognize hazards the same way experienced employees do.

Procedures can gradually become tribal knowledge.

And even a well-trained employee can make a mistake.

This does not mean signs, procedures, or training do not work or are not necessary. It means their effectiveness depends heavily on human behavior.

When a serious machine hazard exists, the better question is whether we can reduce that dependency.

Engineered Safety Changes the Equation

Now consider the same hazard behind a properly designed fixed guard.

The operator does not need to see a warning sign and decide not to reach into the hazard.

The guard physically prevents access.

Or perhaps production requires regular access to the machine. A fixed guard may not be practical, so an interlocked guard is used.

Opening the guard initiates the designed safety function.

Another application might use a light curtain, safety scanner, pressure-sensitive device, two-hand control, safe-speed function, or another engineered safeguarding method.

The exact solution depends on the machine, hazard and required interaction.

But the philosophy remains the same:

Hazard → Engineered protection → Reduced exposure

We have removed several human decisions from the safety equation.

How Many Decisions Have to Go Right?

This is a useful question for Safety Directors evaluating machine risk:

How many correct human decisions have to occur before this employee is protected?

Imagine an operator approaching a hazardous area.

If protection depends on the operator remembering six different things, following a procedure correctly and choosing not to take a shortcut, there are multiple human dependencies between that employee and the hazard.

Now compare that with a properly designed safeguard that prevents access or detects entry and initiates a safety function.

The employee is still responsible for following procedures and using the machine correctly.

But the machine's primary protection no longer depends entirely on that decision.

That is an important distinction.

Good safety culture and good engineering should not compete with each other.

They should reinforce each other.

From "Don't Reach In" to "Can't Reach In"

One of the easiest ways to understand engineered risk reduction is to compare two approaches.

Administrative approach:

Do not reach into the machine.

Engineered approach:

Design the safeguarding system so the person cannot readily reach the hazard during normal operation.

The first communicates an expectation.

The second changes the physical relationship between the person and the hazard.

That is why the hierarchy of controls generally places engineering controls above administrative controls.

Whenever feasible, the objective is to control the hazard closer to its source rather than relying solely on someone downstream to avoid it.

But Machines Still Need People

This is where machine safety becomes more complicated than simply saying, “Guard everything.”

Operators have to interact with machines.

They may need to:

  • Load and unload material.
  • Position parts
  • Change tooling.
  • Make adjustments.
  • Clear routine obstructions
  • Perform setup.
  • Observe a process.
  • Troubleshoot equipment.
  • Clean and maintain machinery.

This is particularly challenging with legacy equipment that was designed decades before today's safeguarding technologies and expectations.

Sometimes completely eliminating access to a hazard is not reasonably achievable while still allowing the machine to perform its intended function.

That is where risk reduction becomes engineering rather than simply guarding.

The Goal Is Not Always Zero Interaction

The objective of a machine safety project should not be to install the largest enclosure possible and declare the problem solved.

The objective is to understand:

What is the hazard?

Who needs access?

Why do they need access?

When do they need access?

What hazardous motion or energy exists during that interaction?

What feasible engineering measures can reduce the risk?

A machine that requires frequent operator interaction may need a very different solution than a fully automated process.

For example, the answer could involve combinations of physical guarding, interlocked access, presence sensing, safe stopping, safe speed, control-reliable safety functions, redesigned material handling, or changes to the operating sequence.

Only after those opportunities are evaluated should the remaining residual risk be addressed through appropriate awareness, procedures, training, and other administrative measures.

Signs Still Matter

This is an important distinction.

Engineered safety does not eliminate the need for signs.

A properly safeguarded machine can still contain hazards.

Warning labels and signs can communicate residual risks that cannot reasonably be eliminated through design or safeguarding.

Training teaches employees how the safeguarding system works.

Procedures define proper operation, setup, maintenance, and other activities.

Lockout/tagout may still be required for servicing activities.

Administrative controls therefore remain part of a complete safety strategy.

The difference is what we are asking them to accomplish.

A warning sign should not become a convenient substitute for feasible engineering.

Engineer the hazard where feasible. Communicate the residual risk that remains.

Legacy Machines Make This Especially Important

Older machines frequently accumulate layers of administrative controls over their lifetime.

A hazard is identified.

A warning label gets added.

An incident or near miss occurs.

A procedure gets written.

Another employee is trained.

A sign gets added.

Eventually the organization may have years of institutional knowledge surrounding a machine that still has essentially the same physical hazard it had decades earlier.

That creates another problem:

What happens when the experienced operator leaves?

If safe operation depends heavily on knowing all the unwritten rules surrounding a machine, some of the safety system effectively walks out the door when experienced employees retire or leave the organization.

Engineered solutions can help convert some of that institutional knowledge into physical and control-system protections that remain with the machine.

Engineering Doesn't Replace Safety Culture

There is also a danger in taking this concept too far.

No safeguarding system makes human behavior irrelevant.

Employees can defeat guards.

Interlocks can be bypassed.

Safety devices can be improperly maintained.

Changes to machinery can introduce new hazards.

This is why engineered safeguards need to be accompanied by training, inspection, maintenance, management support and validation.

The objective is not to remove people from the safety program.

It is to avoid making perfect human performance the primary safeguard against a serious machine hazard.

A Better Machine Safety Question

When evaluating an existing machine, do not stop with:

“Do we have a sign?”

Or:

“Have the operators been trained?”

Ask another question:

Could we engineer one of these decisions out?

Could access be physically prevented?

Could hazardous motion stop when someone enters?

Could material be loaded differently?

Could the operator perform the task farther from the hazard?

Could a safety function supervise the interaction?

Could the machine be redesigned so exposure is not necessary?

Every time a practical engineering solution removes one critical human dependency, the safety strategy becomes less reliant on someone being perfect every time.

From Compliance to Risk Reduction

Compliance establishes important requirements.

But mature machine safety programs go beyond checking whether a warning label, training record or written procedure exists.

They look at the entire interaction between the person, machine, task, and hazard.

Then they ask where engineering can make that interaction safer.

That is the difference between simply identifying risk and actually reducing it.

Assessment identifies the problem.

Engineering determines how to reduce it.

Fabrication and integration turn that solution into reality.

Validation provides evidence that the safeguarding system performs as intended.

Administrative controls remain an important part of that system—but they should not automatically become the first or only answer.

The Practical Takeaway

People will always make decisions around machinery.

The goal is not to eliminate human decision-making from manufacturing.

The goal is to identify the decisions where one mistake could put someone in contact with a serious hazard and determine whether engineering can reduce or eliminate that dependency.

A simple question can change the conversation:

How many things does this employee have to do right before the machine protects them?

If the answer is too many, it may be time to stop adding another sign or procedure and start looking at the machine itself.

Do not just train people to avoid hazards. Engineer opportunities for exposure out of the process wherever reasonably feasible.

Author