Tuesday, September 22, 2026

Safety Message: Using Enterprise Management Systems, Tools and Software

Enterprise management systems, tools and software (‘EMS’) are used to manage a range of elements common to modern safety management systems (SMS) such as those required of rail transport operators in complying with Rail Safety National Law (RSNL).

Enterprise management systems

These include asset management, health and fitness, training and instruction, risk management, engineering and operational requirements, reporting and management of notifiable occurrences.

With the increased use of EMS, ONRSR is reminding operators of key aspects that need to be considered to ensure safety and compliance with RSNL.

EMS, when effectively planned and implemented, provide a more efficient and effective means to access, update, store and retrieve safety-related information. While larger, commercial operators have used EMS for several years, they are also being adopted by some smaller operators, including tourist and heritage operators, who are planning to use, or already using, HOPS (Heritage Operations Processing System) – an online software-based tool developed in the UK.

The following is a non-exhaustive list of good practices to follow when implementing or transitioning to EMS as well as key issues and pitfalls. While many of the practices are interrelated, for simplicity, we discuss them under the following 3 topics:

  1. Recording keeping requirements
  2. Development of new EMS
  3. Management of change.

1. Understanding the RSNL record keeping requirements

Demonstrating compliance with RSNL includes having accurate, timely and auditable records. Many parts of the RSNL and Regulations contain specific requirements for record keeping that may not be provided for in off-the-shelf systems. For example, RSNL National Regulations Clause 7 Schedule 1: Document control arrangements and information management that includes requirements for the creation, maintenance, management, storage and retention of records and documents (such as maintaining adequate records of inspection, monitoring, measurements, maintenance and repairs). There are many other sections of the RSNL and Regulations that have implicit and explicit requirements for record keeping.

ONRSR recommends organisations analyse the detailed requirements of the RSNL to ensure that off-the-shelf systems are suitable and sufficient for the specific record keeping requirements.

The following are relevant areas of the SMS that have record keeping requirements. The list is not exhaustive, and operators are advised to review the RSNL requirements in more detail.

  • Risk assessments: Operators must keep detailed records of risk assessments including the risks, the likelihood, severity of consequences and control measures considered and reasons for selecting some controls and rejecting others.
  • Risks, controls and assurance processes: Operators must record all identified safety risks, control measures, and how those controls are monitored and updated.
  • Rail safety worker competence: Records must verify that rail safety workers have been assessed as having current skills, knowledge, and qualifications to perform their duties safely including records of the training received, organisation who conducted the training, level of qualifications and competencies attained, person who assessed the competence and date for any re-training or reassessment required.
  • Health assessments: Records must show rail safety worker category, medical fitness for duty determination by the examining health professional, date of assessment and due date for reassessment.
  • Asset management: Records must indicate inspection and maintenance frequency, defect logs, condition reports and maintenance/repair records.
  • Drug and Alcohol Management Program (DAMP): Records must include a DAMP policy and testing program and test records. Record keeping systems must ensure the confidentiality of personal information of rail safety workers in relation to testing, treatment or rehabilitation.
  • Incident and occurrence reporting: Records of notifiable occurrences, internal investigations, annual operational data and annual safety reports
  • Rail safety worker records of hours of work: Records must include sign on and sign off times and reports showing evidence of monitoring of hours of work including planned versus actual hours of work.

2. Development of a new EMS

When developing, procuring or configuring a new EMS the following should be considered:

  • Scope and requirements: Define a clear scope of what the system must do, what information needs to be captured, how outputs are presented and how the system will meet the requirements of the operator’s SMS and the RSNL. For example, if the software will assist with maintenance, ensure it meets requirements ONRSR has previously stipulated for maintenance:
    - Safety Message: Managing your track infrastructure assets
    - Safety Message: Managing your bridge assets
    - Safety Message: Managing your rolling stock assets
    - Safety Message: Managing your signalling assets
    - Safety Message: Human Factors in maintenance
  • Design and testing: Build and test the system in the environment where it is being used with end user involvement in each phase of testing.
  • Data integrity and migration: Plan and test the complete migration of data.
  • Integration and interfaces: Verify that systems interface correctly, and outputs required by the operator’s SMS are still able to be produced.
  • Human factors integration: Incorporate human factors into the design of user interfaces and workflows so that the interfaces are intuitive and support the user’s natural way of working. See AS 7470 Human Factors Integration and Technical Requirements for Rail Engineering Projects.
  • Training: Ensure training is provided for staff who use, configure or extract information from the system.
  • System lifecycle and support: Confirm technical support arrangements, and end-of-life plans.

3. Management of change

Implementing or upgrading to a new EMS represents a change in an operator’s railway operations. Operators need to ensure they follow their management of change processes to help identify any risks and implement controls to enable a safe transition.

Key issues that the management of change process should account for include:

  • system design errors impacting the availability of data or inadvertently altering data.
  • hardware compatibility issues – for example, when computer systems or hardware components do not function correctly with the system/software due system capacity, firmware issues, device version, device operating system, device obsolescence or other system/software operational requirements.
  • data migration issues – for example, if data moved between the exiting system and the new/upgraded system is lost or copied incorrectly.
  • training issues – for example, staff may not know how to manage, use or input data into the new system.
  • system downtime – for example, new systems suffering performance issues if not configured properly that lead to temporary disruptions.
  • integration issues – for example, the new system may not adequately ‘talk’ to other systems, data or spreadsheets that are currently part of an operator’s SMS.

Additionally, it is worth noting the following regarding an EMS, and compliance with RSNL:

  • During implementation, an operator’s existing SMS must remain effective – waiting for a new system to go live is not an acceptable reason for non-compliance.
  • Not undertaking a given activity or task related to an operator’s railway operations because the EMS ‘does not allow it’ is not an acceptable reason for non-compliance.
  • The operator’s EMS together with other systems, procedures, and standards, can together form part of the operator’s SMS.
  • While there is no requirement to contain the SMS in a single document or an online system, all railway operations for which an operator is accredite must be covered by their SMS.

Key documents and actions

Operators should review their SMS and EMS functionality to ensure the items discussed in this safety message are taken into account.

Guidance material that can assist includes:

After reading this message, will you review your operational procedures and/or processes?

Thanks for your feedback.

Last updated: Sep 22, 2026, 7:46:08 AM