Most rail operators can tell you they manage fatigue. Far fewer can produce, on the day it is asked for, an account of how a particular person came to be rostered onto a particular shift and what was known about their fatigue exposure at the time.

That gap is where the difficulty lives. The duty is not new and it is not vague, but it is written in terms of outcomes, and outcomes have to be evidenced.

The duty is to control the risk, not to keep the records

Under the Railways and Other Guided Transport Systems (Safety) Regulations, an operator has to have arrangements in place to manage fatigue for staff carrying out safety critical work. The regulations do not tell you to keep a spreadsheet. They tell you the risk has to be controlled.

That distinction matters, because it means paperwork alone never satisfies anyone. An inspector is not looking for the existence of a fatigue policy. They are looking for evidence that the policy changed a decision: that a roster was altered, a shift refused, a pattern flagged before it became a problem.

If your fatigue management consists of a signed declaration at the start of a shift, you have a record of an assertion. You do not have evidence of control.

The common arrangement is that a worker declares they are fit for duty, sometimes alongside a note of hours worked elsewhere. It is quick, it is cheap, and it puts the assessment in the hands of the person least able to make it objectively.

There are three problems with it, and they compound:

  • People are poor judges of their own fatigue. This is well established, and it gets worse the more fatigued the person is.
  • The incentive runs the wrong way. Declaring yourself unfit costs you a shift.
  • It captures a moment, not a pattern. The risk usually comes from the sequence of shifts, not the one being declared.

A declaration is worth having. It is not worth relying on.

What a defensible assessment looks like

The factors that drive fatigue risk are not controversial. Any credible assessment weighs at least:

  • Time of day. A night shift is not equivalent to a day shift of the same length.
  • Shift length. Risk does not rise linearly with hours.
  • Cumulative hours. Across the week, not just the shift.
  • Recovery time. The gap between shifts, and whether it permitted actual sleep.
  • Consecutive nights. The penalty accumulates.

None of that is difficult to compute. What makes it defensible is that each factor is recorded alongside the result, so the score can be taken apart afterwards.

This is the part most systems skip. A number on its own invites the question “how did you arrive at that?”, and “the system calculated it” is not an answer that survives contact with an inspector.

The test to apply to your own arrangements

Pick a shift from four months ago, at random. Then try to answer, without phoning anyone:

  1. What was this person’s assessed fatigue exposure going into that shift?
  2. Which factors drove it, and what were their values?
  3. Was anything done differently as a result?
  4. Who saw the assessment, and when?

If answering takes more than a few minutes, or requires reconstructing anything from memory, the arrangement is not producing evidence. It is producing records, which is not the same thing.

Why this is a software problem

Fatigue management fails in practice for practical reasons rather than philosophical ones. The roster lives in one system, the hours worked elsewhere are declared on paper, the competence records are in a third place, and nothing reconciles until somebody asks a question that forces it.

Bringing those together is unglamorous work — the same person appearing three different ways across four systems is the usual starting point — but it is what turns a policy into something you can evidence.

We built RailGard AI to close exactly that gap: a scoring engine that assesses every shift rather than relying on a worker’s own estimate, with every contributing factor logged so the result can be explained line by line. It is multi-tenant, so each operator keeps its own data, branding and policy settings, and it is in live use as a fatigue risk management system.

The point is not the software. The point is that when someone asks how a number was reached, there is an answer.


If you are reviewing your own fatigue arrangements and want to talk it through, get in touch. More on how we work in this sector on our rail and infrastructure page.

← Back to the blog