Two railway engineers are reviewing the same signalling hazard.
A train detection failure could potentially result in an unsafe movement. Engineer A classifies the risk as “Medium”. Engineer B, using what appears to be the same risk matrix, classifies it as “High.”
Neither engineer is necessarily wrong.
The difference may lie in how they interpret frequency, exposure, severity, existing controls and the assumptions behind the assessment.
This is the railway risk matrix trap.
What Is a Railway Risk Matrix?
A railway risk matrix is a structured tool used to combine two or more dimensions of risk—typically:
· Severity: How serious could the consequence be?
· Frequency/probability: How often could the hazardous event occur?
A matrix then maps these categories into risk levels such as Low, Medium, High or Intolerable.
The concept is simple:
Risk = Frequency/Probability × Consequence
But the engineering reality is considerably more complex.
How Are Risk Matrices Constructed?
Organisations define severity categories—for example:
· Minor injury or operational disruption
· Serious injury
· Single fatality
· Multiple fatalities/catastrophic consequences
They may also define frequency categories ranging from frequent to extremely improbable.
The intersection of these categories produces a risk classification.
However, the boundaries are not universal. Two railway organisations may use different definitions, numerical ranges, consequence thresholds and acceptance criteria.
Therefore, the same hazard can legitimately produce different classifications when assessed under different frameworks.
The Problem of Subjectivity
Consider a platform-train interface hazard.
Engineer A assumes that a particular platform gap occurs once every 100,000 passenger movements and considers existing platform markings and staff procedures effective.
Engineer B considers human non-compliance, degraded conditions and peak-hour exposure and estimates a significantly higher frequency.
Both engineers may have started with the same hazard.
Their assumptions changed the risk classification.
This is why risk assessment is not simply about selecting a colour on a matrix.
Hazard Identification vs Risk Evaluation
These are different activities.
Hazard identification asks:
What can go wrong?
Risk evaluation asks:
How likely is it, how severe could the consequence be, and is the resulting risk acceptable?
A weak hazard identification process cannot be rescued by a sophisticated risk matrix.
Why Calibration Matters
A risk matrix must be calibrated against the organisation's safety objectives, historical evidence, operational environment and risk acceptance criteria.
Calibration helps ensure that terms such as rare, unlikely, frequent or catastrophic have meaningful and consistent interpretations.
Without calibration, a matrix can create an illusion of precision while hiding substantial uncertainty.
Quantitative vs Qualitative Risk Assessment
A qualitative assessment might classify an event as:
“Unlikely + Catastrophic = High Risk.”
A quantitative assessment may instead estimate:
1 × 10⁻⁷ hazardous events per operating hour
and compare that value against defined safety targets.
Neither approach automatically makes engineering judgement unnecessary.
Quantitative analysis can introduce its own uncertainties through assumptions, incomplete data and model limitations.
What About ALARP?
ALARP — As Low As Reasonably Practicable — is a risk-management concept used in some railway safety frameworks and jurisdictions.
It does not simply mean “make everything as safe as possible regardless of cost.”
Its application depends on the applicable regulatory framework and risk acceptance philosophy. Where ALARP is relevant, the assessment generally requires consideration of whether further reasonably practicable risk reduction measures should be implemented.
It should therefore be treated as part of a defined risk acceptance framework, not as a substitute for one.
A Hypothetical CBTC Example
Imagine a CBTC system experiences intermittent communication loss between the train and wayside equipment.
The initial assessment considers:
· Frequency: 1 failure per 100,000 train movements
· Exposure: Moderate
· Potential severity: Multiple fatalities
· Mitigation: Automatic braking and operational procedures
The matrix produces Medium Risk.
Now change the assumptions:
· Communication loss occurs once per 10,000 movements
· The failure can persist longer than initially assumed
· Peak-hour exposure is higher
· Automatic braking coverage is not available in every degraded operating mode
The same hazard could now move into a High or unacceptable risk category, depending on the organisation's criteria.
The hazard did not change.
The assumptions changed.
That distinction is fundamental to railway safety assurance.
Why a Coloured Matrix Is Not Enough
A red, amber or green cell does not demonstrate that a risk assessment is technically sound.
Risk matrices can be misused when engineers:
· Treat category boundaries as absolute scientific truths
· Hide uncertainty inside broad probability bands
· Ignore exposure
· Double-count or overestimate mitigation
· Use historical absence of accidents as proof of safety
· Treat procedural controls as completely reliable
· Focus on the matrix result instead of the underlying hazard
A defensible assessment should explain why the selected severity, frequency, exposure and mitigation assumptions are credible.
Risk Matrix vs Engineering Judgement: What Should Come First?
Engineering judgement should come first; the matrix should structure and communicate that judgement.
The matrix is a decision-support tool—not the decision-maker.
Good railway risk assessment combines:
Hazard identification → causal analysis → consequence analysis → frequency/exposure assessment → risk evaluation → risk reduction → verification → safety acceptance.
This connects directly with RAMS, safety assurance and railway risk acceptance.
10 Questions to Ask Before Accepting a Railway Risk Assessment
1. What exactly is the hazard being assessed?
2. Are the initiating events clearly identified?
3. How was the frequency estimate established?
4. What assumptions determine the exposure?
5. Is the severity definition appropriate?
6. What evidence supports the probability category?
7. Have existing mitigations been independently justified?
8. Could human, environmental or degraded-mode factors change the result?
9. What risk acceptance criteria are being applied?
10. Has the assessment considered whether additional risk reduction is reasonably practicable?
The Bottom Line
A railway risk matrix can bring consistency to safety decision-making—but it cannot eliminate uncertainty, assumptions or engineering judgement.
Two engineers may look at the same hazard and reach different conclusions because they are using different evidence, assumptions or acceptance criteria.
The real question is therefore not:
“Which colour is the risk?”
It is:
“Can we demonstrate, with evidence and engineering reasoning, why this risk classification is justified?”
That is where credible railway RAMS, safety assurance and risk acceptance truly begin.




