📦 Resource pdf

HMI Handover Procedure SOP (AS/NZS 4024.1-2018 Aligned)

The HMI Handover Procedure SOP (AS/NZS 4024.1-2018 Aligned) is a standardized, safety-critical operational protocol governing the controlled transfer of human-machine interface (HMI) control authority between autonomous haulage system (AHS) vehicles and human operators during transitions such as system startup, fault recovery, or manual intervention. It ensures compliance with AS/NZS 4024.1-2018 — Safety of machinery — General principles for design — Risk assessment and risk reduction — by embedding hazard identification, risk mitigation, and verification steps into every handover step. The SOP mandates explicit operator acknowledgement, real-time system state validation, and fail-safe default behaviours to prevent unauthorised or unsafe control transfers.

📖 Overview

The HMI Handover Procedure SOP is a cornerstone of safe human-autonomy collaboration in mining and heavy industrial environments deploying Autonomous Haulage Systems (AHS). Rooted in the risk-based design philosophy of AS/NZS 4024.1-2018, it treats handover not as a simple UI toggle but as a formal safety function requiring rigorous validation of preconditions — including vehicle kinematic state (e.g., speed ≤ 0 km/h, brake applied), environmental readiness (e.g., GPS integrity, obstacle clearance), and operator situational awareness (e.g., confirmed visual verification, HMI focus confirmation via biometric or interaction telemetry). Each handover event is time-stamped, logged with contextual diagnostics, and subject to dual-channel verification: one from the AHS control layer (e.g., autonomy stack status) and another from the safety-critical monitoring layer (e.g., SIL2-certified watchdog subsystem). The SOP further prescribes graded handover modes — 'supervised', 'semi-autonomous', and 'full manual' — each with distinct authority boundaries, feedback modalities (e.g., haptic alerts, colour-coded status bars), and mandatory timeout/reversion protocols to prevent operator complacency or automation surprises. Compliance is verified through periodic third-party audits, functional safety assessments (per AS/NZS 61508), and integration testing against ISO 13849-1 PL requirements.

📑 Key Components

1 Pre-handover System Readiness Verification
2 Operator Acknowledgement & Situational Awareness Confirmation
3 Dual-Channel Authority Transfer Logging & Fail-Safe Reversion

🎯 Applications

  • AHS fleet deployment in open-pit mining operations
  • Remote operations centre (ROC) shift handovers involving multiple operators
  • Emergency intervention scenarios during autonomy degradation or network partition

📐 Key Formulas

Handover Time-to-Completion (HTC)

HTC = t_ack − t_init

Calculates the elapsed time from handover initiation signal (t_init) to verified operator acknowledgement (t_ack); used to enforce maximum allowable handover duration per AS/NZS 4024.1-2018 Clause 6.3.2

Risk Reduction Factor (RRF) for Handover Mode

RRF = (P_hazard × C_consequence) / P_residual

Quantifies the effectiveness of handover safeguards in reducing residual risk; derived from AS/NZS 4024.1-2018 Annex B risk estimation methodology

🔗 Related Concepts

Functional Safety (IEC 61508) Human Factors Engineering (ISO 6385) Autonomy Level Transition Integrity (SAE J3016 Level 4–5 handover protocols)

📚 References

#autonomous-haulage #functional-safety #human-machine-interface