Skip to content

Road tunnel safety — in operation and in design

Know the risk in every tunnel you operate
— and every one you design.

A living, PIARC-based risk model for road tunnels — structured assessment, directive compliance, prioritised measures. It covers tunnels in service, new tunnels on the drawing board, and upgrades of existing ones. Built in Norway, made for tunnels everywhere.

  • PIARC
    Methodological framework
  • EU 2004/54/EC
    European compliance layer
  • National layers
    Regulations and road data

What it is for

Three jobs, one model

Every tunnel gets one structured model that is kept up to date — not a report that is written once and then ages on a shared drive.

01

Understand your risk

Scenario analysis with explainable scores and full traceability from source value to result.

  • A standard scenario library: traffic accidents, heavy-goods vehicle fires, dangerous goods incidents, technical failures, evacuation.
  • Barrier modelling per scenario — what reduces the risk, and by how much.
  • Every input carries its own provenance: where the value came from, who registered it and when.
  • Where data is missing, the model says so. It does not quietly substitute an assumption.
  • Quantitative where the data carries it, qualitative where it does not — and the result is labelled with which one produced it.

Supporting capability

RAMS — reliability, availability, maintainability and safety for tunnel systems, including SIL classification and proof-test tracking.

02

Document compliance

EU Directive 2004/54/EC plus the national layer that applies to you, requirement by requirement.

  • Status per requirement — met, partially evidenced, deviation, or not applicable with the reason stated.
  • Evidence is read from the registered data, not asserted in free text.
  • Design basis and current standard are evaluated separately, so a tunnel built correctly for its time is not confused with one that falls short of what it was built for.
  • Approved deviations are carried with their case reference.

Supporting capability

Reporting — structured assessment reports generated from the model, with the method and sources cited.

03

Prioritise with confidence

Portfolio ranking and measures ordered by risk reduction per euro, with before-and-after tracking.

  • Rank the whole portfolio by absolute risk, regulatory gap and data quality.
  • Compare measures on what they actually buy you in risk reduction, not on what they cost alone.
  • Track implementation and see the modelled effect once a measure is in place.
  • Carry the model forward to the next revision instead of starting over.

Supporting capability

Life cycle cost — net-present-value comparison of investment options across long horizons.

Across the tunnel lifecycle

One model, three situations

The same structured model serves a tunnel in daily operation, a tunnel still being designed, and an existing tunnel being brought up to standard. What changes is which questions it answers first.

Tunnels in operation

Keep the risk picture current between revisions, and know what to fix next.

  • A living model that is updated as data changes, rather than a report reissued every few years.
  • Compliance status that follows the registered data.
  • Operational records — inspections, exercises, preparedness and system condition — in the same place as the risk model.
  • Prioritised measures with the modelled effect of each.

New tunnels in design

Test the safety concept while it is still cheap to change.

  • Compare design options against the same risk model the finished tunnel will be measured by.
  • See which requirements a proposed cross-section, length or equipment level actually triggers.
  • Document the risk basis for the chosen concept, with its assumptions written down.
  • Hand the model over to operations at commissioning instead of starting a new one.

Upgrades and refurbishment

Show what an upgrade buys, before it is committed to.

  • Establish the design basis the tunnel was built to, and the gap against the current standard.
  • Model alternative upgrade packages and rank them by risk reduction per euro.
  • Keep the before-and-after picture so the effect can be shown after the work is done.
  • Carry approved deviations and their reasoning through the project.

Day-to-day operations

When a fan is out, is closing the tunnel the safer choice?

A tunnel rarely fails all at once. It degrades — a jet fan out of service, a pump down, a camera dark — and someone has to decide, often within the hour, whether it stays open.

Closing a tunnel does not remove the traffic. It moves it — onto a road that may be undivided, longer, unlit and busier with vulnerable road users. A closure can lower the risk inside the tunnel and raise the total risk of the journey.

The tunnel, in its degraded state

Not the tunnel as designed — the tunnel as it is right now.

  • Which barriers are actually available, and which are out of service.
  • What that does to the scenarios the barrier was there to handle.
  • How long the degraded state is expected to last, and what that means over the period rather than for one moment.
  • Whether the deficiency is the thing driving the decision, or merely present while something else is.

The detour, as it would actually be driven

The road the traffic transfers to, modelled as a road — not assumed to be safe because it is not a tunnel.

  • Where the traffic goes, and how much of it transfers rather than disappears.
  • The exposure that transfer creates: added distance, road standard, and who is on that road.
  • Whether one-tube two-way operation of the tunnel itself is an option, and whether the tunnel is registered as capable of it.
  • Dangerous goods separately — a detour that is acceptable for cars is not automatically acceptable for a tanker.

Rule-based and risk-based, kept apart

The regulation says what must happen at a given equipment level. That is a rule, it is binding, and the model does not argue with it — what the rule requires is shown as what the rule requires.

The risk figures answer a different question: what each option would actually cost in expected harm. Shown separately, and never dressed up as the rule.

The value is in the cases where the two disagree. That disagreement is the decision — and it is the thing an operator has to be able to justify afterwards, to a supervisory authority or to an inquiry.

So the model records it: what was decided, on which basis, with which data, and what the alternative was estimated to cost. A decision that can be explained a year later is worth more than one that was merely fast.

How the comparison works

How it works

From a static report to a living model

Five steps. The first is data, the last is a report — and unlike a report, the model is still there afterwards.

  1. 01

    Bring in tunnel data

    Import from a national road database where one is available — NVDB in Norway is the first supported source — or register the tunnel directly. The system builds a structured profile and scores how complete it is.

  2. 02

    Validate and enrich

    Review the imported values, correct what needs correcting, and add what only your organisation knows: barrier condition, inspections, emergency response, operational constraints.

  3. 03

    Run the analysis

    The model generates the standard scenarios and calculates risk from frequency, consequence and barriers — showing which inputs drive each result and where uncertainty affects confidence.

  4. 04

    Prioritise measures

    See which measures give the greatest risk reduction for the money, across one tunnel or the whole portfolio. Record what is decided and track it to completion.

  5. 05

    Report — and keep the model

    Generate a structured assessment report with method and sources cited. The underlying model stays live and becomes the starting point for the next revision.

Methodology

Four layers, in order

The method is layered deliberately: a global framework first, then the European compliance layer, then the national rules that apply where the tunnel is, and finally the data sources that feed it. Each layer sits on the one above it.

  1. 1

    Global framework

    PIARC — World Road Association

    The methodological foundation for road tunnel risk assessment: scenario-based analysis, barrier modelling, and the separation of frequency from consequence. PIARC is international, which is why the model is not tied to any one country's practice.

    • PIARC Road Tunnels Manual
    • PIARC quantitative risk analysis and evaluation reports
    • PIARC/OECD dangerous-goods quantitative risk model
  2. 2

    European compliance layer

    EU Directive 2004/54/EC

    The minimum safety requirements for tunnels in the trans-European road network, and the reference most national regulations in Europe are written against. Compliance is evaluated requirement by requirement.

  3. 3

    National regulations

    The rules that apply where the tunnel is

    National regulations and technical standards are added as their own layer on top of the directive, per country. They are never mixed into the global framework — a national threshold is not a method.

    • Norway — see the country page
    • Further countries on request
  4. 4

    Data layer

    National road databases

    Where a country maintains a national road database, tunnel geometry, traffic and equipment can be imported from it rather than typed in. Norway's NVDB is the first supported source; the model does not depend on any single one.

How a risk score is composed

risk =
  exposure
  × frequency
  × consequence
  × barrier effect
  × uncertainty

Every score can be opened up: which inputs drove it, which barriers reduced it, which values are registered and which are assumed. A number you cannot take apart is a number you cannot defend.

Read the methodology

Quantitative and qualitative — both, and labelled

Tunnel risk work is not one or the other. Some questions have enough data behind them to be counted; others have to be judged by people who know tunnels. A model that only does the first is quietly narrow. A model that does both without saying which is which is worse.

Quantitative

Where the data carries a number, the model calculates one.

  • Scenario frequencies and consequences computed from registered tunnel, traffic and equipment data.
  • Barrier effects applied per scenario, so a measure is credited where it actually works.
  • Sensitivity and uncertainty carried alongside the result, not stripped off it.
  • Comparable across a portfolio, because the same method produced every figure.

Qualitative

Where a number would be false precision, the model asks for judgement — and structures it.

  • Risk-indicating characteristics assessed as their own question: indicated, ruled out, or must be assessed — never averaged into a score.
  • Expert and owner judgement recorded as a decision with its reasoning, not as an anonymous input.
  • Hazards that are real but not countable are carried as findings rather than dropped because they resist quantification.
  • Some requirements are organisational rather than physical. They are evaluated as such.

Every value carries the class of evidence behind it: verified source, owner estimate, expert judgement, or not quantifiable. That label travels with the number into the report. It is what lets a reader tell a measurement from an assessment — and it is the difference between a model you can defend and one you can only present.

Where it applies

Built in Norway, made for tunnels everywhere

The method is global; the compliance layer is European; the rules and the data are national. That separation is what makes the model portable.

PIARC is the World Road Association, and its road tunnel methodology is used far beyond Europe. Tunnel Control is built on that framework, which is why the analysis is not specific to any one country.

EU Directive 2004/54/EC sits on top as the European compliance layer. Where a tunnel is subject to it, the model evaluates it requirement by requirement.

National regulations and national road databases are added per country, as their own layers. Norway is the first — because that is where the product was built and where its regulatory mapping is deepest — and further countries are added as content, not as new code.

NorwayNorge

National regulations, technical standards and the national road database. Page in Norwegian.

Further country layers are added on request. Because the national rules and data sources are separate layers, adding a country is a matter of mapping its regulations — not of rebuilding the method.

Who you are talking to

A software company with tunnel people behind it

The product is the model, and we build software. But a risk model for tunnels is not a general-purpose tool with a domain skin on it — it has to be built by people who have stood in tunnels, argued about ventilation strategies, and answered to a supervisory authority.

We are a software company

We do not sell hours, and the goal is not to make you dependent on us. You get a model your own organisation owns and operates.

That shapes what we build: everything is traceable, everything is explainable, and the report can be produced without us in the room.

With a tunnel expert group behind it

Behind the software is a group of tunnel specialists — the people whose judgement is built into the method, and who are available when a question needs a person rather than a calculation.

When you get in touch, you are not routed to a sales desk. The first conversation is with people who know tunnels, and it is the same expertise that decides how the model treats a hard case.

This matters most exactly where the numbers stop: a degraded tunnel with an awkward detour, an old tunnel with an unclear design basis, a deviation someone has to be willing to sign.

Contact

Talk to us about your tunnels

Tell us what you operate or what you are designing, and we will show you how the model would handle it. You will be talking to people who know tunnels, not to a sales desk.