Case study · Critical infrastructure

When the safety case assumed behaviors the training did not teach.

An Australian critical infrastructure operator replaced pass and click assessment with a hybrid verification program drawn from the framework its safety case already implied.

Chapter 01
The situation

A post incident review that named the training.

The trigger was not a fine and it was not a regulator. It was an incident, and the post incident review that followed. The review found no single cause, as reviews of this kind rarely do. It found a chain of small deviations that, individually, would have been considered acceptable practice by the crews involved. Collectively, they were not.

The review’s most uncomfortable finding was structural. The safety case (the document that justified the site’s license to operate) assumed specific operator behaviors. Micro decisions at defined points in the task. Those behaviors were not taught anywhere in the training program. Operators had learned the procedure and passed the assessment. The assessment had never been designed to verify the behaviors the safety case relied on.

The operator’s training was not deficient in the ordinary sense. It was deficient in the sense that it was not connected to the framework the safety case implied. Rewriting the training against the same missing structure would have produced the same disconnect, more efficiently.

Chapter 02
The framework work

Draw the framework the safety case already assumes.

Each safety case implies a competency framework. It names the behaviors that the risk controls depend on. Historically, that implied framework had never been made explicit on this site. The Foundry ingested the safety case, task risk assessments, operational procedures, and the ISO 45001 management system elements that governed them, and proposed the competency framework those documents together implied.

Coverage of the existing training was measured against that framework. Some nodes were fully covered. Some were partially covered. Several (including two of the precursor behaviors the post incident review had specifically named) were not covered at all. The gap was not a training gap in isolation. It was a gap between the safety case and the training system that was supposed to enact it.

“We had been assuring ourselves against training. We should have been assuring ourselves against the framework the safety case relies on. Once that was explicit, the gap was undeniable.”
General manager, safety and assurance, Australian critical infrastructure operator

Verification was rebuilt from the framework outwards. The program became hybrid by design: instructed content, scenarios of situational judgment that exercised the precursor behaviors specifically, observed performance in the field, and structured supervisor sign off. Each verification event carried a Foundry Hash back to the framework node and the safety case clause behind it. Each sign off was auditable to the risk control it served.

Chapter 03
The outcome

Verification that moved behavior, and the data to see it.

Six months after rollout, the operator reviewed hybrid verification pass rates alongside incident precursor rates in operations. Pass rates on the more stringent hybrid program rose above the pass rate the previous pass and click assessment had recorded on the same population, driven by repeat exposure to the situational judgment material. Independently, the incident precursor rate for the two behaviors specifically targeted by the redesigned verification fell over the follow up window.

The more important shift, according to the safety function, was epistemic. For the first time, the training system produced data that could be read against the safety case. When behavior drifted, the framework showed where. When behavior improved, the framework showed why.

0%
of competencies implied by the safety case mapped to explicit framework nodes
0
precursor behaviors from the post incident review closed under hybrid verification
0 mo
post implementation review confirming precursor rate decline

Illustrative outcomes drawn from typical engagement patterns. Specific program figures shared under NDA on request.

Chapter 04
What it means

A safety case without an explicit framework is a promise without a witness.

Each operator with a safety case is already carrying a competency framework. It is either explicit (auditable, traceable, and the source of verification) or implicit, hidden in the assumptions of the risk assessment. Implicit frameworks fail silently. The failure is not visible until a post incident review makes it visible, and by then the question is no longer whether the training worked. It is whether the safety case was ever enactable.

Making the framework explicit is not a documentation exercise. It is the mechanism by which a safety case becomes something an operator can defend, measure, and improve. For any Australian operator under ISO 45001 and an accepted safety case, this is not a training question. It is an assurance question.

For your organization

Bring the subject. Leave with the framework.

A 45-minute working session with our team on a real subject or program you own. You keep the framework the Foundry produces.