<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.3.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Root Cause Analysis</title>
	<link>http://root-cause-analysis.info</link>
	<description>Root Cause Analysis</description>
	<pubDate>Thu, 02 Jul 2009 17:59:10 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.2</generator>
	<language>en</language>
			<item>
		<title>Italian Train Explosion</title>
		<link>http://root-cause-analysis.info/2009/07/02/italian-train-explosion/</link>
		<comments>http://root-cause-analysis.info/2009/07/02/italian-train-explosion/#comments</comments>
		<pubDate>Thu, 02 Jul 2009 17:59:10 +0000</pubDate>
		<dc:creator>Ksmiley</dc:creator>
		
		<category><![CDATA[Root Cause Analysis - Incident Investigation]]></category>

		<guid isPermaLink="false">http://root-cause-analysis.info/2009/07/02/italian-train-explosion/</guid>
		<description><![CDATA[On the evening of June 29, a train carrying liquefied natural gas derailed and exploded in the town of Viareggio, in western Italy.  Search and rescue operations are still ongoing, and the cause for the derailment is not yet known.  Although that means we are lacking some information, we can still begin our root cause [...]]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://www.thinkreliability.com/InstructorBlogs/Blog-ItalyTrainExplosion.pdf" title="High Level Cause Map"><img hspace="10" vspace="10" border="0" src="http://www.thinkreliability.com/graphics/download_PDF.gif" alt="Download PDF" align="right" height="30" width="94" /></a><img hspace="10" vspace="10" border="0" src="http://thinkreliability.com/graphics/download_PDF.gif" alt="Download PDF" align="right" height="1" width="1" />On the evening of June 29, a train carrying liquefied natural gas derailed and exploded in the town of Viareggio, in western Italy.  Search and rescue operations are still ongoing, and the cause for the derailment is not yet known.  Although that means we are lacking some information, we can still begin our <a target="_blank" href="http://www.thinkreliability.com " title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis </a>investigation, in the form of a Cause Map.  A thorough root cause analysis built as a Cause Map can capture all of the causes in a simple, intuitive format that fits on one page. </p>
<p>The benefit to beginning a root cause analysis investigation before all the information is known is to provide a framework for the investigation to build on.  People find it much easier to comment on a partially finished Cause Map than to piece together the investigation from scratch. </p>
<p><img hspace="10" vspace="10" border="0" src="http://upload.wikimedia.org/wikipedia/commons/6/6a/2009_Viareggio_train_explosion_fire.jpg" alt="Italian Train Explosion" align="right" height="263" width="394" />The first step of the investigation is to fill out the outline.  Don&#8217;t leave any blanks in the outline; if you don&#8217;t know something, put a question mark.  The first line is the &#8216;what&#8217; or the problem.  Rather than spending time debating what &#8216;the problem&#8217; is, we can put a number of things.  For example, the problem here could be defined as a gas leak, an explosion, and a train derailment.  We put all these things on the problem line.  The rest of the information is known, though we may add more detail later, except for differences.  Differences can be key to an investigation.  For example, if you have a process that works for 30 straight sunny days, then fails the day it rains, it is worth looking into the impact of the rain on the process.  Here, no differences are immediately coming to mind, so we&#8217;ll put a question mark in this blank.</p>
<p>Once we&#8217;ve defined the problem, we can define the problem with respect to the impact to the goals.  We don&#8217;t know how many people, overall, were killed or injured, but we can just put &#8220;at least&#8221; to show that the numbers aren&#8217;t exact.  We know that the environmental goal was impacted, because of the gas leak, the community goal was impacted because of the required evacuation, and the material/labor goal was impacted because of the collapsed houses, and the damage to the train.</p>
<p>Now we begin the analysis.  We begin with the impacted goals and ask &#8220;why&#8221; questions, moving to the right.  When we can&#8217;t answer the &#8220;why&#8221; question, we can use a question mark, or put some possibilities (theories) that have been presented.  For example, we&#8217;re not yet sure why the train derailed.  Some of the possibilities that have been presented are damage to the tracks, a problem with the braking system, or malfunctioning wagon locks.  The Cause Map (so far) is shown in the downloadable PDF (to download, click &#8220;Download PDF&#8221; above.)  As you can see, there is a lot of information present, even though we don&#8217;t know all of what happened yet.</p>
<p>As more information is available, we can update the Cause Map.  As with any <a target="_blank" href="http://www.thinkreliability.com/Root-Cause-Analysis-CM-Basics.aspx" title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis</a>, the level of detail in the analysis is based on the impact of the incident on the organization&#8217;s overall goals.</p>
]]></content:encoded>
			<wfw:commentRss>http://root-cause-analysis.info/2009/07/02/italian-train-explosion/feed/</wfw:commentRss>
		</item>
		<item>
		<title>UPDATE: D.C. Metro Train Collision</title>
		<link>http://root-cause-analysis.info/2009/06/24/update-dc-metro-train-collision/</link>
		<comments>http://root-cause-analysis.info/2009/06/24/update-dc-metro-train-collision/#comments</comments>
		<pubDate>Wed, 24 Jun 2009 17:24:40 +0000</pubDate>
		<dc:creator>Agriffith</dc:creator>
		
		<category><![CDATA[Root Cause Analysis - Incident Investigation]]></category>

		<guid isPermaLink="false">http://root-cause-analysis.info/2009/06/24/update-dc-metro-train-collision/</guid>
		<description><![CDATA[Yesterday I posted a blog about the Metro train collision in Washington, D.C. More information on the accident has been released today, so we can use this information to update the Cause Map (visual root cause analysis). (The PDF, which can be opened by clicking on &#8220;Download PDF&#8221; shows these changes.)First, the injury count has [...]]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://www.thinkreliability.com/InstructorBlogs/Blog-MetroCollision2009Pt2.pdf" title="High Level Cause Map"><img border="0" align="right" width="94" src="http://www.thinkreliability.com/graphics/download_PDF.gif" hspace="10" alt="Download PDF" height="30" /></a>Yesterday I posted a <a target="_blank" href="http://root-cause-analysis.info/2009/06/23/dc-metro-train-collision/" title="Previous blog">blog</a> about the Metro train collision in Washington, D.C. More information on the accident has been released today, so we can use this information to update the Cause Map (visual <a target="_blank" href="http://www.thinkreliability.com/" title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis</a>). (The PDF, which can be opened by clicking on &#8220;Download PDF&#8221; shows these changes.)First, the injury count has increased to at least 80, so we update the outline. Also, we have discovered that the lead car in the train was a &#8220;B&#8221; car. (Metro cars are put in pairs, with the lead car ordinarily being an &#8220;A&#8221; car.) While this might be a cause of the accident, we don&#8217;t yet have enough information to link it on our Cause Map. Instead, we can add it to the outline as a &#8220;difference&#8221;.</p>
<p>Additionally, more information has come to light about the lack of retrofitting or replacement of the old cars, which were not considered crashworthy by NTSB. The reason given for not retrofitting or replacing the cars is because it would be too expensive, as Metro is without dedicated funds (the only major transit system in the country to operate this way).</p>
<p>Investigators have discovered that the operator had successfully engaged the emergency brake. Our previous information, obtained from the unofficial testimony of passengers on the train, was that there was no attempt to stop or slow the train. Now that new evidence contradicts the old evidence, we can remove &#8220;No attempt to stop/slow train&#8221; as a cause. Instead, the cause for &#8220;Train rear-ended stopped train&#8221; is &#8220;Striking train did not stop&#8221;.</p>
<p>One of the causes for &#8220;striking train did not stop&#8221; is that the emergency brake was ineffective. It was ineffective because it was pulled too late, because the operator was not aware of the stopped train, or because the braking system was not functioning, or both. The causes for &#8220;operator unaware of stopped train&#8221; have not changed (yet) since our previous version. However, it has been released that the crash happened on a curve, which is a possible cause for the operator being unable to see the other train. Right now there is no evidence to show that the operator was otherwise distracted.</p>
<p>As far as &#8220;brake system not functioning&#8221;, we now have evidence that the first two cars of the striking train were two months overdue for brake maintenance. We&#8217;ll add that as a cause.</p>
<p>We have moved ineffective mechanical override as a cause for the train not stopping. This sytem should have automatically sensed that the two trains were getting too close and stopped the train. One of the causes we had previously was that the operator had overridden the mechanical override, due to operating in manual mode. The investigation has shown that this was not the case, so we can cross out this cause. (We do not delete it from the map so that we know it&#8217;s been considered.)</p>
<p>Another potential cause of the ineffective mechanical override is sensor failure. The Metro General Manager has stated that there is no indication of sensor failure; however, there is no evidence that they were functioning properly so we leave it on our map while we wait for more information.</p>
<p>One other new piece of information has been presented. The speed limit at the location of the accident was 59 m.p.h. We&#8217;ll add that as a cause of &#8220;train moving at considerable speed.&#8221; (We still don&#8217;t know how fast the train was actually moving, as the train was not equipped with a data recorder.)</p>
<p>Click on &#8220;download PDF&#8221; to see how the changes were incorporated into the visual <a target="_blank" href="http://www.thinkreliability.com/Root-Cause-Workshops.aspx" title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis</a> (Cause Map). The Cause Map continues to change throughout an investigation.</p>
]]></content:encoded>
			<wfw:commentRss>http://root-cause-analysis.info/2009/06/24/update-dc-metro-train-collision/feed/</wfw:commentRss>
		</item>
		<item>
		<title>D.C. Metro Train Collision</title>
		<link>http://root-cause-analysis.info/2009/06/23/dc-metro-train-collision/</link>
		<comments>http://root-cause-analysis.info/2009/06/23/dc-metro-train-collision/#comments</comments>
		<pubDate>Tue, 23 Jun 2009 18:59:01 +0000</pubDate>
		<dc:creator>Ksmiley</dc:creator>
		
		<category><![CDATA[Root Cause Analysis - Incident Investigation]]></category>

		<guid isPermaLink="false">http://root-cause-analysis.info/2009/06/23/dc-metro-train-collision/</guid>
		<description><![CDATA[On June 22, 2009, the Washington, D.C. area suffered its first fatal Metro train crash since 1982.  A transit train smashed into another train that was stopped on the tracks.  There has been an apparent increase in crashes in large city&#8217;s transit systems over the last several months, causing some to question whether enough is [...]]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://www.thinkreliability.com/InstructorBlogs/Blog-MetroCollision2009.pdf" title="High Level Cause Map"><img hspace="10" vspace="10" border="0" src="http://www.thinkreliability.com/graphics/download_PDF.gif" alt="Download PDF" align="right" height="30" width="94" /></a>On June 22, 2009, the Washington, D.C. area suffered its first fatal Metro train crash since 1982.  A transit train smashed into another train that was stopped on the tracks.  There has been an apparent increase in crashes in large city&#8217;s transit systems over the last several months, causing some to question whether enough is being done to ensure an attitude of safety.  Robert Lauby, a former NTSB investigator, said:</p>
<blockquote><p>&#8220;Just because you had them doesn&#8217;t mean there&#8217;s a specific issue that caused them.&#8221;</p></blockquote>
<p>Actually, that&#8217;s exactly what it means.  If something happens (an effect), there has to be a cause.  Usually there&#8217;s more than one cause.  We can look at this incident in a <a target="_blank" href="http://www.thinkreliability.com/Root-Cause-Analysis.aspx " title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis</a> to determine what some of the causes were.  A thorough root cause analysis built as a Cause Map can capture all of the causes in a simple, intuitive format that fits on one page.</p>
<p>The official investigation is still in its infant stages, but we can still put together a pretty thorough Cause Map.  (See the Cause Map by clicking on &#8220;Download PDF&#8221; above.)  We can add more detail to this Cause Map as the investigation continues. As with any investigation the level of detail in the analysis is based on the impact of the incident on the organization&#8217;s overall goals.</p>
<p>First we define the problem.  Here, it&#8217;s that two trains crashed.  We also enter the other identifying information (date, location and process.)  Then we frame the problem with respect to the impacts to the goals.  Here, the safety goal was impacted because at least 9 people were killed and at least 76 were injured.  The material goal was impacted because of severe damage to the trains. </p>
<p>Next, we do the <a target="_blank" href="http://www.thinkreliability.com/Root-Cause-Analysis-CM-Basics.aspx" title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis</a>.  We begin with the impacted goals and ask &#8220;why&#8221; questions to find all the causes of the incident.  People were killed and injured because of the damage to the trains.  The trains were damaged because of a train, which was moving at a &#8220;considerable speed&#8221;  rear-ending a stopped train, and because of the  inadequate crashworthiness of the moving train.</p>
<p>The train was not adequately crashworthy because it was old, and not replaced (despite an NTSB recommendation to replace or retrofit the older cars to increase safety in a crash).  Why weren&#8217;t they replaced?  We don&#8217;t know yet, but the NTSB will be talking to Metro&#8217;s administration to find out.</p>
<p>The two trains collided because the train that was rear-ended was stopped on the tracks, waiting for another train to move.  The train that struck it did not stop or slow down.  The striking train was not equipped with a data recorder and the operator was killed in the incident, so we don&#8217;t have a very good idea of what happened.  But we can come up with some theories and then refine or reject them as evidence permits.  Since the train didn&#8217;t stop, it&#8217;s either because there was no attempt to stop, or the braking system malfunctioned.  From the information we have available, it appears that a train would not attempt to stop if the operator was unaware of the train, because she couldn&#8217;t see it and because the sensor system was not working properly,  AND if the mechanical override system was not working.  The sensor system not working might cause the mechanical override system to not work, OR the system could have been overridden by either the dispatcher or the operator.  (Apparently having the train in manual may turn off the mechanical override.)</p>
<p>We can continue to add to our root cause analysis as we get more information on the accident.</p>
]]></content:encoded>
			<wfw:commentRss>http://root-cause-analysis.info/2009/06/23/dc-metro-train-collision/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Preventing Runway Incursions at LAX</title>
		<link>http://root-cause-analysis.info/2009/06/18/preventing-runway-incursions-at-lax/</link>
		<comments>http://root-cause-analysis.info/2009/06/18/preventing-runway-incursions-at-lax/#comments</comments>
		<pubDate>Thu, 18 Jun 2009 17:38:12 +0000</pubDate>
		<dc:creator>Ksmiley</dc:creator>
		
		<category><![CDATA[Root Cause Analysis - Incident Investigation]]></category>

		<guid isPermaLink="false">http://root-cause-analysis.info/2009/06/18/preventing-runway-incursions-at-lax/</guid>
		<description><![CDATA[Enterprising companies know that finding new, effective solutions to problems makes good business sense.  Finding new solutions can be the difficult part.  A root cause analysis can help find new, effective solutions.  To demonstrate this capability, we&#8217;ll look at the problem of runway incursions at Los Angeles International Airport (LAX).  In 2007, there were 21 [...]]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://www.thinkreliability.com/InstructorBlogs/Blog-RunwayIncursion.pdf" title="High Level Cause Map"><img hspace="10" vspace="10" border="0" src="http://www.thinkreliability.com/graphics/download_PDF.gif" alt="Download PDF" align="right" height="30" width="94" /></a>Enterprising companies know that finding new, effective solutions to problems makes good business sense.  Finding new solutions can be the difficult part.  A <a target="_blank" href="http://www.thinkreliability.com" title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis</a> can help find new, effective solutions.  To demonstrate this capability, we&#8217;ll look at the problem of runway incursions at Los Angeles International Airport (LAX).  In 2007, there were 21 incursions at LAX.  Perhaps the problem was discussed, and it was determined that one of the causes of these incursions was that the taxiways intersected the runways.  This is shown below in a Cause Map, or visual root cause analysis.</p>
<p style="text-align: center"><img hspace="10" vspace="10" border="0" src="http://www.thinkreliability.com/InstructorBlogs/blog-runwayincursion-cm1.gif" alt="Runway CM1" height="78" width="256" /></p>
<p>A potential solution, then, is to install a taxiway between the runways, so that they don&#8217;t intersect.</p>
<p style="text-align: center"><img hspace="10" vspace="10" border="0" src="http://www.thinkreliability.com/InstructorBlogs/blog-runwayincursion-cause1.gif" alt="Runway CM2" height="123" width="120" /></p>
<p>This solution has been implemented at LAX, with the result of runway incursions dropping to 5 so far this year.  However, LAX officials would like that number to fall even further.  So they started looking for new solutions.  Finding new solutions may mean adding more detail to the Cause Map.  For example, what if we add another cause for runway incursions?</p>
<p style="text-align: center"><img hspace="10" vspace="10" border="0" src="http://www.thinkreliability.com/InstructorBlogs/blog-runwayincursion-cm2.gif" alt="Runway CM 3" height="167" width="258" /></p>
<p>This gives us another cause that we can try to &#8220;solve&#8221;.  Here, the solution being implemented at LAX is radar-equipped warning lights.  Essentially, if the system senses a plane or vehicle that could lead to a potential collision on a runway or taxiway, the runway lights turn red.  If not, they are green.  The plane still has to request clearance from traffic control, but it adds another layer of protection<em>. </em></p>
<p style="text-align: center"><img hspace="10" vspace="10" border="0" src="http://www.thinkreliability.com/InstructorBlogs/blog-runwayincursion-cause2.gif" alt="Runway CM 4" height="133" width="126" /></p>
<p>Officials at LAX hope this will continue to decrease the number of incursions at LAX.  If not, the <a target="_blank" href="http://www.thinkreliability.com/Root-Cause-Workshops.aspx" title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis</a> can be built into even more detail, and more solutions can be found.</p>
]]></content:encoded>
			<wfw:commentRss>http://root-cause-analysis.info/2009/06/18/preventing-runway-incursions-at-lax/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Loss of submarine KURSK</title>
		<link>http://root-cause-analysis.info/2009/06/10/loss-of-submarine-kursk/</link>
		<comments>http://root-cause-analysis.info/2009/06/10/loss-of-submarine-kursk/#comments</comments>
		<pubDate>Wed, 10 Jun 2009 17:50:14 +0000</pubDate>
		<dc:creator>Ksmiley</dc:creator>
		
		<category><![CDATA[Root Cause Analysis - Incident Investigation]]></category>

		<guid isPermaLink="false">http://root-cause-analysis.info/2009/06/10/loss-of-submarine-kursk/</guid>
		<description><![CDATA[On August 12, 2000, a torpedo exploded on KURSK, leading to the eventual loss of the submarine and all on board.  We can demonstrate the causes of the KURSK tragedy by performing a visual root cause analysis, or Cause Map.  A thorough root cause analysis built as a Cause Map can capture all of the [...]]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://www.thinkreliability.com/InstructorBlogs/Blog-Kursk.pdf" title="High Level Cause Map"><img hspace="10" vspace="10" border="0" src="http://www.thinkreliability.com/graphics/download_PDF.gif" alt="Download PDF" align="right" height="30" width="94" /></a>On August 12, 2000, a torpedo exploded on KURSK, leading to the eventual loss of the submarine and all on board.  We can demonstrate the causes of the KURSK tragedy by performing a visual <a target="_blank" href="http://www.thinkreliability.com/Root-Cause-Analysis.aspx " title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis</a>, or Cause Map.  A thorough <a target="_blank" href="http://www.thinkreliability.com/OurServices.aspx" title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis </a>built as a Cause Map can capture all of the causes in a simple, intuitive format that fits on one page. First we define the problem(s).  Here, the problems include a torpedo explosion and submarine sinking.  This is the &#8220;what&#8221;.  The initial explosion on KURSK ocurred at 11:28 a.m. on August 12, 2000.  This is the &#8220;when&#8221;.  The KURSK (a Russian attack submarine) was in the southern Barents Sea, performing a torpedo firing drill.   This is the &#8220;where&#8221;.  We&#8217;ll also frame this incident with respect to the impact to the goals.  The safety goal was impacted because all 118 sailors on board were killed.   The materials goal was impacted because of the loss of the submarine.  There are other goals that were impacted, but for our basic analysis, we will stop here.</p>
<p>Next we perform the analysis portion of the root cause analysis. We can begin by using the &#8220;5-Whys&#8221; technique.  We start with the impact to the safety goal, and ask &#8220;why&#8221; 5 times.  For example: Why was the safety goal impacted?  Because 118 sailors died.  Why?  Because of the explosion of missiles and torpedo fuel.  Why did the missiles and torpedo fuel explode?   Because of the impact when the submarine hit the bottom of the ocean.  Why did the submarine sink? A torpedo exploded, breaching the hull.  Why?   A fuel leak on the torpedo.  The resulting Cause Map is shown on the downloadable PDF.  Though the resulting Cause Map is accurate, it&#8217;s not complete. </p>
<p>We can add additional causes to make our map more complete.  For example, although 95 sailors were killed directly by the explosion, the remaining 23 sailors actually died from carbon monoxide poisoning because they were trapped in the aft compartment due to the submarine sinking. </p>
<p>A higher detail Cause Map is also shown on the downloadable PDF.  Even more detail can be added as the<a target="_blank" href="http://www.thinkreliability.com/Consulting.aspx" title="Root Cause Analysis :: ThinkReliability :: Cause Mapping"> root cause analysis </a>investigation continues.  The level of detail in a Cause Map is determined by the impact to the organization&#8217;s goals.  Because of the tragically high number of deaths in this incident, it will be worked to a very high detail.  The highest detail level Cause Map has more than 150 causes.</p>
]]></content:encoded>
			<wfw:commentRss>http://root-cause-analysis.info/2009/06/10/loss-of-submarine-kursk/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Eschede Train Derailment</title>
		<link>http://root-cause-analysis.info/2009/06/04/eschede-train-derailment/</link>
		<comments>http://root-cause-analysis.info/2009/06/04/eschede-train-derailment/#comments</comments>
		<pubDate>Thu, 04 Jun 2009 18:52:15 +0000</pubDate>
		<dc:creator>Ksmiley</dc:creator>
		
		<category><![CDATA[Root Cause Analysis - Incident Investigation]]></category>

		<guid isPermaLink="false">http://root-cause-analysis.info/2009/06/04/eschede-train-derailment/</guid>
		<description><![CDATA[June 3, 1998, a train derailed and crashed into a bridge near Eschede, Germany, killing 101 people, including 2 engineers who had been working on the bridge.  A thorough root cause analysis built as a Cause Map can capture all of the causes of this tragedy in a simple, intuitive format that fits on one page.We [...]]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://www.thinkreliability.com/InstructorBlogs/Blog%20-%20Eschede%20Train%20Derailment.pdf" title="High Level Cause Map"><img hspace="10" vspace="10" border="0" src="http://thinkreliability.com/graphics/download_PDF.gif" alt="Download PDF" align="right" height="30" width="94" /></a>June 3, 1998, a train derailed and crashed into a bridge near Eschede, Germany, killing 101 people, including 2 engineers who had been working on the bridge.  A thorough <a target="_blank" href="http://www.thinkreliability.com" title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis </a>built as a Cause Map can capture all of the causes of this tragedy in a simple, intuitive format that fits on one page.We can begin our analysis with the &#8220;5 Whys&#8221; technique, asking &#8220;Why&#8221; 5 times.  1) Why did the train crash into a bridge?  It derailed.  2) Why did it derail?  A tire embedded in the railcar changed the switch.  3) Why was the tire embedded?  It had come off the wheel.  4) Why did the tire come off the wheel?  The tire broke.  5) Why did the tire break?  Fatigue cracking.  This forms the beginning of a root cause analysis investigation.</p>
<p>As we continue the investigation, we can create a more detailed <a target="_blank" href="http://www.thinkreliability.com/OurServices.aspx" title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis</a>.  We begin by defining the problem in terms of the impacts to the organization&#8217;s goals.  The safety goal was impacted because of the 101 deaths, and 88 injuries.  Also, the train suffered serious damage, resulting in an impact to the materials/labor cost goal.  These impacts to the goals form the basis for our Cause Map.</p>
<p>The goals were all impacted due to the destruction of the rear railcars.  This occurred because the train crashed into a bridge at 200 km/hour.  The train was not stopped or slowed because of company policy to investigate an  issue first.  The train crashed into the bridge because it had derailed because a tire embedded in the railcar collided with a switch guard rail.  The tire became embedded because it broke, due to fatigue cracking from wear and inadequate inspections, and an insufficient design.  The design was insufficient because the prototypes were not physically tested and dynamic repetitive forces were not considered in the modeling.</p>
<p>Even more detail can be added to this Cause Map as the analysis continues. As with any investigation the level of detail in the analysis is based on the impact of the incident on the organization&#8217;s overall goals.  Once the Cause Map is completed to the desired level of detail, solutions can be found for any of the cause boxes.  Solutions are then shown with the cause they control.</p>
]]></content:encoded>
			<wfw:commentRss>http://root-cause-analysis.info/2009/06/04/eschede-train-derailment/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Lexington Plane Crash</title>
		<link>http://root-cause-analysis.info/2009/05/27/lexington-plane-crash/</link>
		<comments>http://root-cause-analysis.info/2009/05/27/lexington-plane-crash/#comments</comments>
		<pubDate>Wed, 27 May 2009 18:41:44 +0000</pubDate>
		<dc:creator>Agriffith</dc:creator>
		
		<category><![CDATA[Root Cause Analysis - Incident Investigation]]></category>

		<guid isPermaLink="false">http://root-cause-analysis.info/2009/05/27/lexington-plane-crash/</guid>
		<description><![CDATA[On the morning of August 23, 2006, a Comair flight scheduled to travel to Atlanta International Airport from Blue Grass Airport in Lexington, Kentucky attempted to take off  from the wrong runaway.  The runway used was too short and the flight crashed near the end of the runway.  There were 49 people killed and the [...]]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://www.thinkreliability.com/InstructorBlogs/Blog%20-%20Lexington%202.pdf" title="High Level Cause Map"><img hspace="10" vspace="10" border="0" src="http://www.thinkreliability.com/graphics/download_PDF.gif" alt="Download Blog" align="right" height="30" width="94" /></a>On the morning of August 23, 2006, a Comair flight scheduled to travel to Atlanta International Airport from Blue Grass Airport in Lexington, Kentucky attempted to take off  from the wrong runaway.  The runway used was too short and the flight crashed near the end of the runway.  There were 49 people killed and the single survivor was seriously injured.  The plane was destroyed by impact forces and fire.A <a target="_blank" href="http://root-cause-analysis.info/2008/03/28/lexington-plane-crash-2006/" title="Previous Lexington Plane Crash Blog">previous blog</a> discussed this accident and included a very high level 5-box Cause Map.  An intermediate level Cause Map is available for download that contains more information.</p>
<p>A <a target="_blank" href="http://www.thinkreliability.com" title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis </a>shows that there are a number of causes for this accident.  When reviewing the Cause Map, the most obvious causes are that the pilots believed they were on the correct runway and that the air traffic controller didn&#8217;t stop the plane prior to the take off attempt on the wrong runway.</p>
<p>The investigation determined that the pilots had all the correct information during the taxi and take off attempt.  They knew the correct runway, had the correct magnetic headings and all markings on the taxi route met standards.  It isn&#8217;t exactly clear where the runway confusion occurred.</p>
<p>One piece of data that is available is that the pilot and copilot where having a personal discussion during the taxi, which is against regulations.  This isn&#8217;t necessarily the only reason for the runway confusion, but it most likely contributed to the accident.</p>
<p>Even with the runway mistake if the controller had realized that the plane was positioned on the runway prior to take off, the accident would have been prevented.  There are a number of reasons that the controller didn&#8217;t realize the runway mistake.  The first is the layout of the runways.  To get to the correct runway, you had to pass the hold position for the incorrect runway.  If the controller only quickly glanced out the window, the plane would appear to be on route to the correct destination when in fact it was lined up to take off from the wrong runway.</p>
<p>There was also only one controller on duty at the time of the accident.  He had to split his attention between tower tasks and radio duty.  There was no chance for watch team back up with only one controller in the tower.</p>
<p>The controller also didn&#8217;t believe it was necessary to watch the plane the entire taxi and take off.  There was no history of take off attempts on the wrong runway, multiple planes had already safety departed that morning and there was no other traffic on the runway. </p>
<p>As with any accident, a <a target="_blank" href="http://www.thinkreliability.com/OurServices.aspx" title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis</a> shows that there are many causes that contributed to the outcome.  Even in a situation like this one where it is difficult create a solution that addresses every cause, the Cause Map shows that there are still ways to mitigate the risk.  Changing the way the controller monitors planes could help prevent similar future problems, even if the initial runway mistake occurred again. </p>
]]></content:encoded>
			<wfw:commentRss>http://root-cause-analysis.info/2009/05/27/lexington-plane-crash/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Pool Safety</title>
		<link>http://root-cause-analysis.info/2009/05/21/pool-safety/</link>
		<comments>http://root-cause-analysis.info/2009/05/21/pool-safety/#comments</comments>
		<pubDate>Thu, 21 May 2009 18:02:47 +0000</pubDate>
		<dc:creator>Ksmiley</dc:creator>
		
		<category><![CDATA[Root Cause Analysis - Incident Investigation]]></category>

		<guid isPermaLink="false">http://root-cause-analysis.info/2009/05/21/pool-safety/</guid>
		<description><![CDATA[Many of the examples of Cause Maps are investigations of an incident that has already taken place.  However, cause maps are also very useful as a proactive, preventative tool.  A thorough root cause analysis built as a Cause Map can capture all of the potential causes of concern in a simple, intuitive format that fits [...]]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://www.thinkreliability.com/InstructorBlogs/Blog%20-%20Pool%20Safety%20PDF.pdf" title="High Level Cause Map"><img border="0" vspace="10" align="right" width="94" src="http://www.thinkreliability.com/graphics/download_PDF.gif" hspace="10" alt="Download PDF" height="30" /></a>Many of the examples of Cause Maps are investigations of an incident that has already taken place.  However, cause maps are also very useful as a proactive, preventative tool.  A thorough <a target="_blank" href="http://www.thinkreliability.com" title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis</a> built as a Cause Map can capture all of the potential causes of concern in a simple, intuitive format that fits on one page.  Let&#8217;s say you have decided to get a pool for your household.  A Cause Map can help you identify the potential hazards of pool ownership, provide solutions for them when possible, and ensure that your pool experience is as safe as possible.  </p>
<p>Preventing pool injuries is extremely important.  About 43,000 people each year are injured in and around swimming pools and 600 people drown.  Of the 600, approximately 260 are children under the age of 5.  Half of pool drownings occur in the yards of single-family homes.  Obviously, drowning is a concern when discussing pool safety, but the other top causes of injuries around pools are head injuries, slipping, and electrocution.  Some solutions to these problems are listed below, and are based on causes derived from the Cause Map. (To see the Cause Map, click on &#8220;Download PDF&#8221; above.)</p>
<p>POOL SAFETY SOLUTIONS:</p>
<p>1) Control access to the pool by using a self-latching, self-locking fence that is at least 4&#8242; tall, that can&#8217;t be climbed.  Ensure the doors open outward from the pool and have a latch out of children&#8217;s reach.   Use a safety cover when the pool is not in use.<br />
2) Employ drain safety devices such as pumps that shut off automatically when the pipes are obstructed.<br />
3) Keep children within arm&#8217;s reach when near a pool.  Don&#8217;t put in a pool for your family until your children are at least 5.<br />
4) Keep lifesaving equipment near the pool, including a hook and an approved life-saving flotation device.<br />
5) Don&#8217;t drink &amp; swim, and don&#8217;t let those who have consumed alcohol near the pool.<br />
6) Take your whole family to swimming lessons.<br />
7) Never swim alone.  Don&#8217;t let anybody else swim alone.<br />
8) Use a pool alarm that senses water motion to determine if someone has entered the pool.  Make sure it is always turned on when the pool is not in use.<br />
9) If a child is missing, look first in the pool (most children who drown are found after 10 minutes). <br />
10) Keep a telephone, and emergency numbers, near the pool at all times.<br />
11) Check the water depth before diving, or don&#8217;t allow diving in your pool.<br />
12) Learn CPR.  Take your whole family (when they&#8217;re old enough) to CPR lessons, too.<br />
13) Don&#8217;t allow running near the pool.<br />
14) Use an absorbent material to surround the pool.<br />
15) Use rough material around the pool (such as cement instead of tile).<br />
16) Stay out of the pool during rain or lightning storms.<br />
17) Keep electrical appliances away from the pool (they can cause electrocution even if they are not turned on).</p>
]]></content:encoded>
			<wfw:commentRss>http://root-cause-analysis.info/2009/05/21/pool-safety/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Emergency Landing of American Airlines Flight 268</title>
		<link>http://root-cause-analysis.info/2009/05/14/emergency-landing-of-american-airlines-flight-268/</link>
		<comments>http://root-cause-analysis.info/2009/05/14/emergency-landing-of-american-airlines-flight-268/#comments</comments>
		<pubDate>Thu, 14 May 2009 18:20:30 +0000</pubDate>
		<dc:creator>Ksmiley</dc:creator>
		
		<category><![CDATA[Root Cause Analysis - Incident Investigation]]></category>

		<guid isPermaLink="false">http://root-cause-analysis.info/2009/05/14/emergency-landing-of-american-airlines-flight-268/</guid>
		<description><![CDATA[On September 22, 2008 American Airlines Flight 268 en-route from Seattle to JFK Airport made an emergency landing at Chicago&#8217;s O&#8217;Hare Airport.  Nobody was injured, although the landing gear sustained some damage.  In order to determine what went wrong, we will perform a root cause analysis.  A thorough root cause analysis built as a Cause [...]]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://www.thinkreliability.com/InstructorBlogs/Blog%20-%20AA%20Flight%20268.pdf" title="High Level Cause Map"><img hspace="10" vspace="10" border="0" src="http://www.thinkreliability.com/graphics/download_PDF.gif" alt="Downlaod PDF" align="right" height="30" width="94" /></a>On September 22, 2008 American Airlines Flight 268 en-route from Seattle to JFK Airport made an emergency landing at Chicago&#8217;s O&#8217;Hare Airport.  Nobody was injured, although the landing gear sustained some damage.  In order to determine what went wrong, we will perform a root cause analysis.  A thorough <a target="_blank" href="http://www.thinkreliability.com/" title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis</a> built as a Cause Map can capture all of the causes in a simple, intuitive format that fits on one page.First we&#8217;ll look at the impact to the goals.  An emergency landing is an impact to the customer service and production/schedule goal.  Additionally, the damage to the landing gear is an impact to the material/labor cost goal. We begin with the impacts to the goals, then ask &#8220;Why&#8221; questions to fill out the Cause Map.  For example, the damage to the landing gear occurred because the pilot steered the plane off the side of the runway.  The pilot steered the plane off the runway because of an obstruction at the end, and because of control issues, which occurred because of a failure of multiple cockpit systems.  The failure of these systems also caused the emergency landing.</p>
<p>The failure of the cockpit systems was caused by the battery power being depleted and not being recharged.  This occurred because the battery was powering four systems, and was disconnected from the main battery charger.  This happened because the standby power selector switch was moved to the &#8220;BAT&#8221; (or battery) position.  The standby selection switch was moved to battery because that is what procedure called for when the &#8220;Standby Power Bus OFF&#8221; light is illuminated.  The light was illuminated due to a relay failure, of unknown cause. </p>
<p>At this point, a problem becomes clear.  A pilot following procedure should not result in an emergency landing for a plane.  Thus, we have a procedural problem.  We will use a Process Map to draw out a procedure for more clarity to see where the specific issue lies.</p>
<p>Based on general information presented by the National Transportation Safety Board (NTSB), the illumination of the &#8220;Standby Power Bus OFF&#8221; light indicates a loss of power to the standby AC or DC bus.  If this occurs, the standby power selection knob should be turned to &#8220;BAT&#8221; (battery).  The battery should provide standby bus power. If the &#8220;Standby Power Bus OFF&#8221; light goes out, the standby power selection knob should be turned to &#8220;AUTO&#8221; which restores the battery charger. </p>
<p>Written in a paragraph, it can be difficult to see where the issue is.  But if we put it in a Process Map, we see a decision box for &#8220;Standby Power Bus OFF light remains illuminated.  If the answer is yes, we follow the procedure outlined above.  But if the answer is no, there is no procedure to follow.  This is the position the pilot of Flight 268 was in.  The &#8220;Standby Power Bus OFF&#8221; light went out, so the pilot left the standby power selection knob on &#8220;BAT&#8221;.  This drained the battery, resulting in the failure of various cockpit systems, as discussed above. </p>
<p>Even more detail can be added to this Cause Map as the <a target="_blank" href="http://www.thinkreliability.com/OurServices.aspx" title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis </a>continues. As with any investigation the level of detail in the analysis is based on the impact of the incident on the organization&#8217;s overall goals.</p>
]]></content:encoded>
			<wfw:commentRss>http://root-cause-analysis.info/2009/05/14/emergency-landing-of-american-airlines-flight-268/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Salmonella Contamination in Peanut Products</title>
		<link>http://root-cause-analysis.info/2009/05/07/salmonella-contamination-in-peanut-products/</link>
		<comments>http://root-cause-analysis.info/2009/05/07/salmonella-contamination-in-peanut-products/#comments</comments>
		<pubDate>Thu, 07 May 2009 19:14:47 +0000</pubDate>
		<dc:creator>Ksmiley</dc:creator>
		
		<category><![CDATA[Root Cause Analysis - Incident Investigation]]></category>

		<guid isPermaLink="false">http://root-cause-analysis.info/2009/05/07/salmonella-contamination-in-peanut-products/</guid>
		<description><![CDATA[In January, 2009, health officials discovered Salmonella typhimurium in a jar of peanut butter.  The Food and Drug Administration (FDA) was able to trace the contamination back to the Peanut Corporation of America (PCA)&#8217;s  Blakely, Georgia plant.   A root cause analysis built as a Cause Map can show the causes of this tragic, preventable incident in [...]]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://www.thinkreliability.com/InstructorBlogs/Blog%20-%20peanut%20contamination.pdf" title="High Level Cause Map"><img hspace="10" vspace="10" border="0" src="http://www.thinkreliability.com/graphics/download_PDF.gif" alt="Download PDF" align="right" height="30" width="94" /></a>In January, 2009, health officials discovered <em>Salmonella typhimurium </em>in a jar of peanut butter.  The Food and Drug Administration (FDA) was able to trace the contamination back to the Peanut Corporation of America (PCA)&#8217;s  Blakely, Georgia plant.   A <a target="_blank" href="http://www.thinkreliability.com" title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis</a> built as a Cause Map can show the causes of this tragic, preventable incident in a simple, intuitive format that fits on one page.</p>
<p>To begin our <a target="_blank" href="http://www.thinkreliability.com/Root-Cause-Analysis.aspx" title="Root Cause Analysis :: ThinkReliability :: Cause Mapping">root cause analysis</a>, we start with the impact to the goals.  The peanut products contaminated with salmonella resulted in 700 reported illnesses.  This is an impact to the safety goal.   Also, PCA received a $14.6 million fine for shipping products contaminated with <em>Salmonella</em>.  This is an impact to the regulatory goal.  There are other goals that were impacted as well, but we will begin with these two.</p>
<p>People were sicked and PCA was fined because peanut products contaminated with <em>Salmonella</em> were shipped to consumers.  These products were able to be shipped because they were retested for <em>Salmonella</em> until the results were negative (this is illegal, by the way) and several lots of product were contaminated.</p>
<p>The product lots were contaminated because the processing line was exposed to <em>Salmonella</em> and was not cleaned after the contamination.  The two likely ways that the line was contaminated is either by exposure to rain (which can carry <em>Salmonella</em>) or by cross-contamination of finished product (which should have any microorganisms destroyed in the roasting process) and raw product (which hasn&#8217;t).  Additionally, the roasting process in the Blakely plant was inadequate to kill Salmonella.</p>
<p>The plant suffered from inadequate cleaning, which resulted from a line that was not able to be adequately sanitized, and from inadequate supervision.  The FDA had last inspected the plant in 2001, which is typical due to understaffing.   However, they might have visited sooner if the <em>Salmonella</em> test results (the ones that were re-done to get negative values) were shared with the FDA.  These results were not shared with the FDA, which is common industry practice.    State inspectors found only minor issues.</p>
<p>None of PCA&#8217;s customers appeared to have visited the site, possibly because they relied on an audit firm&#8217;s &#8220;superior&#8221; ranking.  This audit firm was paid by PCA.  There was also inadequate supervision due to inadequate leadership at the plant, which had no plant manager for a portion of 2008, and was missing a quality manager for four months.</p>
<p>Even more detail can be added to this Cause Map as the analysis continues. As with any investigation the level of detail in the analysis is based on the impact of the incident on the organization&#8217;s overall goals. </p>
]]></content:encoded>
			<wfw:commentRss>http://root-cause-analysis.info/2009/05/07/salmonella-contamination-in-peanut-products/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
