1. INTRODUCTION
Contemporary safety and security challenges, environmental incidents, health emergencies, financial pressures, and critical infrastructure failures are increasingly interconnected. Addressing them requires risk management approaches that reflect the actual complexity of human ecosystems, including aviation [1,2]. Risk management is well established in civil aviation, particularly in flight safety and aviation security [1], but business entities are also exposed to risks arising from other operational areas and from external influences. Understanding this wider risk landscape depends on embedding a safety culture at all levels of management, which allows risks and their impacts to be managed in a coordinated way [2].
Since the 1970s, the risk management field has undergone substantial methodological change. Classical approaches defined risk primarily as a combination of the probability of harm and the severity of its consequences. After 2009, ISO 31000 [3] redefined risk as the effect of uncertainty on objectives, shifting the risk management context from an event-oriented basis to a goal-oriented one. Under this standard [3], the risk management context comprises the external and internal conditions within which an organization defines and achieves its objectives, and identifies, analyzes, evaluates, and treats risk.
The function of this “new” context is operational rather than descriptive. It sets the boundaries of the risk management process and establishes the rules for interpreting events, consequences, and acceptable levels of risk. An event is classified as a risk only when its potential effect on the achievement of objectives falls within the established risk acceptance criteria, not because of any inherent physical or ontological property of the event itself.
Risk criteria give this context its practical form. They determine what counts as acceptable or unacceptable risk, how risks are prioritized, and which treatment methods are applied. For this reason, ISO 31000 [3] treats the definition of scope, context, and criteria as a methodological precondition for the risk analysis techniques set out in ISO 31010 [4].
Reducing the aviation accident rate depends on this kind of risk-oriented approach. In practice, though, safety continues to be declared an independent goal in its own right, particularly in public administration and critical infrastructure security, an approach that has nonetheless proven effective in high-technology production sectors such as building construction [5] and aircraft manufacturing [6]. Treating safety as an end in itself in this way is inconsistent with the logic of ISO 31000 [3], with contemporary constitutionalism [7], with social systems theory [8], and with organizational theory [9].
Safety is a fundamental human right, necessary for health, peace, justice, and well-being, which are themselves prerequisites for human development [2]. It denotes a state in which the hazards and conditions capable of causing physical, psychological, or material harm are controlled in order to protect the health and well-being of individuals and communities. Safety results from a continuous process of interaction between people and their physical, social, cultural, technological, political, economic, and organizational environment. Analytical modeling of system safety and risk, for instance, is used to describe the causes, hazards, and effects of aircraft traffic impact under different aviation development scenarios [1]. The associated risk assessments proceed through hazard identification linked to the probability and consequences of adverse events, with particular emphasis placed on noise annoyance [10].
Under contemporary constitutionalism, the purpose of the state is to protect and guarantee human rights and freedoms. The purpose of sociotechnical organizations and systems operating under dynamic conditions, by contrast, is to achieve socially or systemically significant outcomes through the sustained performance of their core function.
Safety can therefore be understood only as an instrumental condition for achieving a system’s objectives, not as an autonomous end. Treating safety as an autonomous objective produces a methodological disconnect: it inverts the hierarchy of objectives, brings functional performance into conflict with safety requirements, and drives the system toward zero risk, or “absolute safety,” despite inherent uncertainty.
The consequence is a loss of functional effectiveness and resilience in sociotechnical systems, offset by an illusion of risk controllability based on formal indicators that lack any real goal-oriented justification. The underlying methodological problem is the absence of a risk management context that distinguishes a system’s objectives from the instrumental characteristics of its state, while still treating uncertainty as the fundamental source of risk.
Addressing this problem is a prerequisite for advancing risk-informed management and for supporting the sustainable development agenda [9], given how complex, dynamic, and sociotechnical contemporary systems have become.
As the aviation system becomes more interconnected and complex, risk is no longer confined to individual areas: measures taken to address risk in one area can affect outcomes in others, producing unintended consequences, competing priorities, or cascading effects across the aviation ecosystem [10,11]. Aviation risk management has historically been most developed in the safety domain [1], although increasingly mature approaches are now being applied elsewhere, reflecting how operational, organizational, and sustainability considerations shape the broader risk landscape across flight safety, aviation and information security, environmental and occupational protection, economics, and the facilitation of formalities.
The aim of this study, therefore, is to formulate the risk management context within a goal-oriented framework, in which safety is treated as an instrumental attribute reflecting the adequacy of risk treatment measures, including safety measures, relative to predefined risk acceptance criteria and their contribution to achieving the system’s overall objective in potentially hazardous processes, including those in aviation.
2. MATERIALS AND METHODS
This study adopts a conceptual and theoretical approach to risk management. The risk management context is treated not as the product of arbitrary construction, but as a methodologically grounded interpretation of objective reality, developed to support decision-making under conditions of uncertainty. Following the logic of DSTU ISO 31000:2018 [3], context is defined as the set of internal and external factors that constitute the environment within which an organization seeks to achieve its objectives.
Under this standard [3], context is not a static background but a fundamental prerequisite for the validity of every stage of the risk management process (Fig. 1). Because establishing the context is the initial stage of that process, risk cannot be identified or assessed independently of it. On this basis, the teleologization of safety is treated in this study not as a simple practical misconception but as a systemic consequence of neglecting the goal-oriented nature of risk – one that inevitably drives the pursuit of zero risk despite the existence of inherent uncertainty.
When a system’s objective is omitted from this conceptual framework, the safety of the object itself tends to be erroneously redefined as the system’s primary objective.

Fig. 1.
Risk management process.
Two cases illustrate this oversimplification of the system objective:
managing risk within a healthcare system without first establishing whether the primary objective is species survival, the quality of life of the individual, or the rapid return of a particular employee to work;
protecting a house without determining whether the highest priority is the property, the occupants, or the land on which it is situated.
Table 1 summarizes the principal vulnerabilities associated with treating safety as an autonomous system objective and provides the diagnostic framework applied to the cases examined in the Results section below.
Table 1.
Methodological Consequences of Treating Safety as an Autonomous System Objective.
| Safety declared as an autonomous objective | System objective: sustainable fulfilment of the primary function | Analytical aspect |
|---|---|---|
| Primary differences | Primary differences | Primary differences |
| Safety occupies the highest level in the hierarchy of objectives, displacing the substantive objective of the system | Safety is regarded as an instrumental characteristic of the system state, subordinate to the achievement of the defined objective | Status in the hierarchy of objectives |
| Risk is reduced to a set of hazards and treated as an absolute concept | Risk is interpreted as the effect of uncertainty on objectives [1] | Interpretation of risk |
| Any activity or change is interpreted as an undesirable source of risk | Activities and changes are permitted provided that the level of risk remains acceptable within the established context | Attitude toward activities and change |
| No criterion for the adequacy of safety is established | The adequacy of safety is determined by the acceptability of risk relative to the system's objectives and values | Criteria for the adequacy of safety |
| A methodological disconnect emerges, manifested in the pursuit of zero risk and the slowing of system development | An adaptive system is formed, capable of operating under conditions of inherent uncertainty | System-level consequence |
| Related differences | Related differences | Related differences |
| Decisions are dominated by prohibitions, rigid regulation, and operational shutdowns | Decisions balance operational effectiveness with system constraints | Type of management decisions |
| Resource expenditure lacks objective-based justification | Optimized with respect to the system objective | Resource allocation |
| Operational paralysis or excessive formalism | A resilient and adaptive system | System effect |
| Illusion of control without real safety | Achievement of the system objective while maintaining an acceptable level of risk | Long-term outcome |
3. RESULTS
3.1. Evidence of safety teleologization in practice
The vulnerabilities set out in Table 1 are borne out by several well-documented cases in which treating safety as an autonomous objective produced adverse outcomes.
In 2011, the assumption that a severe accident was inconceivable – the “absolute safety” doctrine applied to Japanese nuclear power plants – left the industry inadequately prepared for the tsunami that struck the Fukushima Daiichi plant. This assumption contributed to a decline in safety culture and an underestimation of external hazards, and ultimately to the Fukushima Daiichi nuclear disaster [12]. The subsequent IAEA investigation found that treating safety as an end in itself, without balancing it against operational resilience, produced the same methodological disconnect described in Table 1: a reduction in the system’s adaptive capacity.
A comparable pattern is evident in the response to the COVID-19 pandemic. WHO recommendations and national strategies at various stages of the pandemic placed strong emphasis on minimizing infection risk through lockdowns, strict mobility restrictions, and other containment measures. These measures did not prevent the long-term spread of the virus, and they were associated with substantial deterioration in the quality of life and mental health of large segments of the population, as well as with increased global economic instability [13,14]. As in the Fukushima case, the result was a reduction in the overall effectiveness and resilience of both the healthcare system and society, illustrating the same methodological risk inherent in treating safety as an autonomous objective.
3.2. A goal-oriented model of safety
Within a goal-oriented risk management framework, context functions as a teleological operator, linking uncertainty, risk, and risk management decisions to the achievement of system objectives.
In this study, safety (S) is defined as a quantitative or qualitative characteristic of a system that reflects its degree of protection against the realization of identified risks – undesirable events associated with sources of uncertainty – considering their potential impact on system objectives and the residual effectiveness of the controls or barriers in place [15].
The model proceeds from the assumption that any system, regardless of its nature, complexity, or the observer’s perspective, operates by virtue of a dynamic equilibrium among opposing factors, shaped by internal and external influences. System safety is determined by the relationship between the probability of threats occurring and the probability that preventive measures will compensate for them; a disruption of this balance constitutes a threat to system safety. Any system possesses a defined set of relative-equilibrium (safety) states, which differ in duration, characteristics, and the mechanisms that sustain them. For any identified threat, adequate safety measures always exist, and the significance of an event is determined not by its nature per se, but by the adequacy and timeliness of the safety measures applied to it, given the current understanding of the problem and the needs of the system. This constitutes the Principle of Probability Adequacy [16].
Both contemporary risk research and the practical experience of aviation professionals confirm the methodological gap that this principle addresses [16]. Dynamic Probabilistic Risk Assessment (DPRA) and Safety Management Systems (SMS) each assess risk or identify shortcomings in management systems, but neither places the balance between the probability of threats and the probability of countermeasure effectiveness at the center of its analysis. DPRA models the dynamics of hazardous states without accounting for the compensatory effect of safety measures, while SMS identifies and formalizes organizational constraints without quantitatively assessing their adequacy [17,18]. Within a goal-oriented framework, safety should therefore be treated not as an autonomous objective but as an instrumental attribute: a measure of how adequately risk treatment measures meet established risk acceptance criteria and support the system’s objective.
Let u ∈ [0,1] denote the aggregated measure of identified sources of uncertainty, i ∈ [0,1] the normalized measure of their impact on the achievement of system objectives, and e ∈ [0,1] the integrated measure of the effectiveness of the risk treatment measures in place, including safety measures. The nominal risk, prior to treatment, is then R = u⋅i, where R ∈ [0,1]. The attained level of safety, S, is subsequently defined as a function of the relationship between the effectiveness of the implemented risk treatment measures and the nominal risk:
where f : ℝ+ → [0, 1] denotes a continuous monotone increasing function.Conversely, the projected level of safety, Sp, given that both threats and the effectiveness of safety measures are subject to forecasting, should be determined based on the reciprocal relationship between the predicted effectiveness of the projected measures, ep, and the expected impact of threats, u⋅i:
The division-by-zero indeterminacy in Eqs. (1) and (2) does not arise in practice, since a state of absolute absence of threat (u⋅i = 0) is impossible in real-world sociotechnical systems, where the complete absence of threat or hazard is unattainable. When normalizing u and i, this is handled by introducing minimum threshold values (artificial lower bounds) for probabilities, reflecting the fact that absolute safety cannot be achieved.
In this framework, improving safety means not pursuing the complete elimination of risk, but improving the quality of risk management decisions relative to established risk acceptance criteria. Risk treatment measures do not eliminate uncertainty; they redistribute its effects relative to the system’s objectives. Both the occurrence of hazards and the effectiveness of treatment measures are therefore inherently stochastic – which is precisely why actual safety (S) and predicted safety (Sp) need to be treated as distinct quantities within the framework.
3.3. Operationalizing the model: an aviation maintenance example
In applied contexts, S should be operationalized within the risk management process defined by DSTU ISO 31000:2018 [3], with specific assessment methods selected according to DSTU EN IEC 31010:2022 [4]. Sources of uncertainty may be identified using HAZID, HAZOP, and SWIFT. The uncertainty measure, u, can be assessed using Fault Tree Analysis (FTA); the impact measure, i, using Event Tree Analysis (ETA) combined with consequence modeling; and the overall effectiveness of barriers, e, using Layers of Protection Analysis (LOPA) and barrier analysis within the Bow-Tie model. More generally, ranking and acceptability assessment may draw on probability–consequence matrices, F–N curves, and the acceptable-risk criteria established under Order No. 637 of the State Committee for Supervision of Occupational Safety (4 December 2002) [19], applying the ALARP principle.
For aviation maintenance, these methods need to be specified for the particular object of analysis. Consider, as an illustrative example, a hazardous maintenance event involving the failure to detect a fatigue crack in a load-bearing structural element during a scheduled inspection. At the identification stage, Functional Hazard Assessment (FHA), combined with HAZOP, yields a list of potential failure modes and their corresponding severity classifications. The uncertainty measure, u, can be derived using FTA, drawing on input data such as the reliability of non-destructive inspection, the probability of human error, and inspection intervals. The impact measure, i, is obtained using ETA, which assigns the consequences of the top event to the corresponding severity category in the Safety Management System (SMS) risk matrix.
The effectiveness of barriers, e, is assessed using LOPA as the aggregate probability of failure on demand across independent barriers – among them repeated inspections, structural health monitoring, and prescribed operational limitations. The normalized values of u, i, and e are then substituted into R = u·i and S = f (e/(u·i)), and the resulting value of S is compared against the acceptability threshold S*, defined according to SMS criteria and the Order No. 637 methodology. The applicability of the model in this case is limited by the quality of the underlying failure statistics and by the assumption of barrier independence, both of which are themselves sources of uncertainty in the assessment.
The impact measure (and its predicted counterpart, ip) can take primary values in monetary terms (e.g., UAH or USD), fatalities, energy (J), emissions (t/year), or other domain-specific metrics. For aggregation within the model, however, these values need to be normalized – for example, against the maximum acceptable harm or a predefined target level.
3.4. A revised definition of the risk management context
Just as risk acceptance criteria need to be established with reference to a system’s objectives, it is equally important to define criteria for the adequacy of the risk treatment measures – including safety measures – applied against those objectives.
On this basis, the risk management context can be reformulated within a goal-oriented framework as follows:
The risk management context is the formalized set of internal and external conditions within which an organization:
defines its teleological objectives;
establishes risk acceptance criteria for hazardous events with respect to those objectives;
establishes criteria for the adequacy of risk treatment measures relative to the accepted levels of risk and the defined objectives;
establishes rules for interpreting the results of risk assessment and the evaluation of safety measures.
Within this framework, safety is not an end in itself, but an instrumental attribute of the quality of risk management.
This formulation removes the methodological disconnect associated with the teleologization of safety, prevents the distortion of the system’s hierarchy of objectives, and avoids the pursuit of zero risk under conditions of inherent uncertainty. It thereby maintains an appropriate balance between functional effectiveness, the resilience of sociotechnical systems, and irreducible uncertainty.
4. PRACTICAL IMPLICATIONS
The proposed goal-oriented approach addresses the methodological shortcomings that arise from the teleologization of safety by treating safety as an instrumental attribute – a reflection of how adequate risk management decisions are – rather than as an autonomous system objective. This reframing supports more rational resource allocation, a better balance between functional effectiveness and acceptable risk, greater resilience in sociotechnical systems, and progress toward sustainable development under conditions of inherent uncertainty.
As with any management system, effective implementation also requires defining the principles and culture needed for it to function – in this context, a safety culture. Four core principles support effective risk management governance and implementation in the aviation sector: entity-wide governance and integration; a systematic risk management approach applied consistently across the entity; sustained coordination and communication among domains and resilience functions; and ongoing monitoring, review, learning, adaptation, and improvement [20,21].
5. RESEARCH LIMITATIONS
The principal limitation of this study is its conceptual and theoretical nature: the proposed model (Eqs. 1 and 2) has not yet been empirically validated against data from real sociotechnical systems. Its practical application will require further applied research to calibrate and validate the framework.
6. DIRECTIONS FOR FUTURE RESEARCH
Future work should focus on:
developing specific methods for normalizing the uncertainty measure u and the impact measure i;
empirically validating the proposed model S = f (...) by applying it to real-world case studies, such as critical infrastructure, construction, and healthcare systems;
integrating the proposed framework with the concepts of Resilience Engineering developed by Erik Hollnagel [22] and with models of adaptive capacity.
7. CONCLUSIONS
This study set out to formulate the risk management context within a goal-oriented framework, in which safety is treated as an instrumental attribute of the adequacy of risk management measures rather than as an autonomous goal. The following conclusions follow from this reconceptualization.
This study has demonstrated that the teleologization of safety is a systemic consequence of replacing an objective-oriented interpretation of risk with a simple list of hazards – the pattern set out in Table 1, and borne out by cases such as the Fukushima Daiichi accident and the COVID-19 pandemic response, where the safety of the object itself was allowed to displace the system’s substantive objective. This shift produces a methodological gap marked by a replacement of the hierarchy of system goals, a conflict between functional work and safety requirements, and an orientation toward zero risk despite inherent uncertainty. As a result, the functional efficiency and sustainability of sociotechnical systems are reduced.
This paper has proposed a new definition of safety – formalized as a function of the balance between the probability of threats and the effectiveness of risk treatment measures (Eqs. 1–2) – as an instrumental attribute reflecting the adequacy of these measures relative to established risk acceptance criteria and their effectiveness in supporting achievement of the system goal. This definition clearly separates safety from the system goals, treating it as a property of the quality of risk management rather than an autonomous goal.
This study has shown that there is a need to introduce criteria for the adequacy of risk treatment measures as a symmetrical counterpart to risk acceptance criteria – a distinction built directly into the reformulated risk management context, which requires an organization to establish both sets of criteria side by side. Risk treatment measures do not eliminate uncertainty; rather, they change its probability distribution relative to the system objectives. Their effectiveness is therefore inherently stochastic, and their adequacy should be assessed probabilistically within the established risk assessment context.
For the first time, this paper has developed a focused conceptualization of the risk management context – formalized as the set of conditions within which an organization defines its objectives, establishes risk acceptance criteria, establishes criteria for the adequacy of risk treatment measures, and establishes rules for interpreting the results of risk assessment – in which safety is viewed as an instrumental attribute of risk management quality, rather than an autonomous goal.
Together, these conclusions reframe safety as a property of risk management quality rather than a goal in its own right, and provide a methodological basis for improving risk-oriented management – supporting more rational resource allocation, a better balance between functional effectiveness and acceptable risk, and greater resilience across aviation and other sociotechnical systems operating under uncertainty.