RM32019TheRiskManagementMaturityModelRM32019TheRiskManagementMaturityModelFirstpublished2011(astheRailwayManagementMaturityModel)Secondedition2017Thirdedition2019Formoreinformationcontactusatrm3@orr.gov.ukorvisitourwebsite:orr.gov.uk©CrownCopyright2019Foreword3ORRdevelopedtheRiskManagementMaturitymodel(RM),incollaborationwiththerailindustry,asatoolforassessinganorganisation’sabilitytosuccessfullymanagehealthandsafetyrisks,tohelpidentifyareasforimprovementandprovideabenchmarkforyearonyearcomparison.3RMhasprovidedguidancetotheindustryonexcellenceinhealthandsafetyriskmanagement.Bestperformingorganisationsarethosewhichhavefullyintegratedhealthandsafetypracticesintotheirculture.33RMsetsoutcriteriaforkeyelementsofahealthandsafetyriskmanagementsystem.RMidentifiesthestepstoevaluateacompany’sprogressthroughthefivelevelsofmaturity,fromad-hoctoexcellenthealthandsafetymanagementcapability.Itdefineswhatexcellentmanagementlookslike,including:•leadersinspiringconfidenceandcommitment,safelytakingtheirteamsthroughperiodsofchange;•makingfulluseofemployees’potentialandactivelyinvolvingthemtodevelopsharedvaluesandacultureoftrust,opennessandempowerment;and•thehealthandsafetystrategyisusedbytheorganisationtochallengeitselftoachievehealthandsafetyperformancewhichisinlinewiththebest-performingorganisations.3ORR,throughthecross-railindustrycollaborativeRMGovernanceBoardhascontinuedto3developRMtosupportwiderindustryachievementofexcellenceinhealthandsafetyriskmanagement.3WewanttoensurethatRMmaturesandcontinuestoreflectbestpracticeinriskmanagement.Wehavedrawnonstandards,includingBSISO45001;2018(OccupationalHealthandSafetyManagementSystems)andourexperiencefromtherailsector,andbeyond.Wehavealsoreflectedonrecommendationsfrominvestigationsintoaccidents,incidentsandotherfailuresofmanagementsystems.3ThiseditionofRM,writtenforandwiththesupportoftherailindustry,embracesthedevelopmentsinriskcontrolwhichhavetakenplacesincewefirstpublishedthemodelin2011.Itreinforcestheimportanceoforganisationalcultureinsuccessfulhealthandsafetymanagement.Userswillfindtheadditionalexamplesoftypicalevidencemakeiteasiertodeterminematuritylevels,butwillalsofindthatsomeofthecriteria,particularlyathigherlevelsofmaturity,aremorestretching,comparedwithpreviouseditions.Asindustryhealthandsafetycapability3develops,itisrightthatRMitselfmaturestosupportgreaterstretchandimprovement.Wehaveembracedtheimprovementsmadebytheindustrytodevelopthisnewedition.Wewantexcellentorganisationstoembedcollaborationandinnovationintotheirsystems.Weseetheseaskeyenablersincontinuouslyimprovingtowardsexcellenceinhealthandsafetyriskmanagement,IanProsserwherereasonablypracticable.DirectorofRailSafetyOfficeofRailandRoad12ContentsForeword1Introduction4Excellenceinhealthandsafetymanagementsystems6Healthandsafetypolicy,leadershipandboardgovernance9Organisingforcontrolandcommunication9Securingco-operation,competenceanddevelopmentofemployeesatalllevels9Planningandimplementingriskcontrolsthroughco-ordinatedmanagementarrangements9Monitoring,auditingandreview9Criteriadevelopment10Thegenericmaturitydescriptors10Collaboration11Usingthecriteria12TheRiskManagementMaturityModel(RM3)criteria15(seepanelopposite)Glossary81Annex182TheroleofindependentconfidentialreportingTheRiskManagementMaturityModel(RM3)criteriaHealthandsafetypolicy,leadershipandboardgovernanceSP1Leader...