Published 13 August 2026 by the RLM Consult Certify Comply team
The Office of the National Rail Safety Regulator (ONRSR) used its Insight publication on 10 August 2026 to explain the new Rail Safety Regulation Model it has recently released, and to publish the 20 critical risks that sit at the heart of it. The Critical Risk Compliance Program that began on 1 July is the model in action. For accredited rail infrastructure managers and rolling stock operators, and for the contractors who work under their safety management systems, this is the clearest statement in years of what the regulator will ask about and how it will judge the answer.
What the new model changes
ONRSR has always regulated through accreditation, audit and inspection against the safety management system. The new model keeps those tools and changes their focus. Instead of reviewing a safety management system as a whole, regulatory activity is organised around a defined set of critical risks, the events with the greatest potential for multiple fatalities or catastrophic harm. For each critical risk relevant to an operator, ONRSR wants to see the controls, the assurance that the controls are in place and effective, and the evidence.
The practical consequences for an operator are three. Audits will be narrower and deeper. The people ONRSR wants to talk to are the ones who own the controls, not only the safety manager. And the quality of your assurance activities, the checking that controls actually work on the ground, becomes the thing that is judged.
The 20 critical risks
The list covers the events the industry has always feared, among them collisions between trains, derailments, collisions at level crossings, incidents at the platform train interface, harm to track workers, rolling stock runaways, and failures of structures and signalling. It also captures the risks that have grown with the industry: the interfaces created by construction on operational railways, security and unauthorised access, and the human factors and fatigue that underlie most of the others. Every accredited operator should be able to say which of the 20 apply to its operations and, for each, point to the controls and the assurance in its system.
What this means for rail contractors
Contractors who work under an accredited operator’s safety management system are not audited by ONRSR directly, but they own several of the controls the regulator will examine. Worksite protection, plant operation near the track, possession management, competency of rail safety workers and interface arrangements between the construction site and the operational railway are contractor controls that appear in the operator’s assurance. When the operator is asked for evidence, it will ask you. A contractor whose competency records, pre start checks and worksite protection plans are current and retrievable is a low risk supplier under the new model. One whose records live in a site shed is not.
Aligning a safety management system to the model
- Tag the critical risks. In the risk register, identify the risks that correspond to ONRSR’s critical risks and mark them. Auditors should be able to filter the register to them in seconds.
- Define the critical controls. For each, name the small number of controls that actually prevent the event or limit its consequence, and the person accountable for each.
- Build assurance around the controls. Inspections, verification activities and audits should test whether the critical controls are in place, not whether the procedure exists. Record the result and act on failures.
- Report it upwards. Management review and board reporting should show the state of the critical controls, so that officers can demonstrate due diligence in the regulator’s terms.
- Flow it down. Contractor and interface agreements should identify which critical controls the contractor owns and how the operator verifies them.
This is the structure we have used to build safety management systems for operators such as Webuild’s rail infrastructure manager accreditation and to support maintenance contractors on Sydney’s network. The new model rewards it.
Timing
The Critical Risk Compliance Program has been running since 1 July, so operators with audits scheduled in the second half of 2026 should expect it to shape the audit plan. The Rail Safety National Law review, which closed for submissions in May, is likely to reinforce the same approach in whatever amendments follow. There is no deadline attached to the model, and that is the point: it is how ONRSR regulates now.
Frequently asked questions
What is ONRSR’s Rail Safety Regulation Model?
A regulatory approach released by the Office of the National Rail Safety Regulator in 2026 that organises its audits, inspections and engagement around 20 critical risks, focusing on the controls operators have for those risks and the assurance that the controls are effective.
What are ONRSR’s 20 critical risks?
The 20 critical risks are the rail safety events with the greatest potential for catastrophic outcomes, including collisions, derailments, level crossing incidents, platform train interface incidents, harm to track workers and rolling stock runaways. ONRSR published the full list on 10 August 2026.
Does the new model apply to contractors?
Contractors working under an accredited operator’s safety management system are not directly regulated, but they own many of the controls ONRSR will examine, such as worksite protection and worker competency, and the operator will seek evidence from them.
When did the Critical Risk Compliance Program start?
The Critical Risk Compliance Program commenced on 1 July 2026 and is the practical application of the new regulation model.