Safety Assessment of Casting Workshop by Cloud Model and Cause and Effect–LOPA to Protect Employee Health

Safety assessment of a casting workshop will provide a clearer understanding of the important safety level required for a foundry. The main purpose of this study was to construct a composite safety assessment method to protect employee health using the cloud model and cause and effect–Layer of Protection Analysis (LOPA). In this study, the weights of evaluation indicators were determined using the subjective analytic hierarchy process and objective entropy weight method respectively. Then, to obtain the preference coefficient of the integrated weight more precisely, a new algorithm was proposed based on the least square method. Next, the safety level of the casting workshop was presented based on the qualitative and quantitative analysis of the cloud model, which realized the uncertainty conversion between qualitative concepts and their corresponding quantitative values, as well as taking the fuzziness and randomness into account; the validity of cloud model evaluation was validated by grey relational analysis. In addition, cause and effect was used to proactively identify factors that may lead to accidents. LOPA was used to correlate corresponding safety measures to the identified risk factors. 6 causes and 19 sub-causes that may contribute to accidents were identified, and 18 potential remedies, or independent protection layers (IPLs), were described as ways to protect employee health in foundry operations. A mechanical manufacturing business in Hunan, China was considered as a case study to demonstrate the applicability and benefits of the proposed safety assessment approach.


Introduction
In recent decades, China's economy has developed rapidly and citizens' living standards have greatly improved [1][2][3]. With continued economic growth, China's foundry industry has achieved considerable development, making great contributions to the basic industry and machinery industry [4]. The casting process is used to obtain a part or workblank by pouring liquid metal into a cavity corresponding to the shape of the part, and then gradually cooling and solidifying it [5,6]. However, there are negative effects of the growing foundry industry, such as environment pollution [7-9] and casualties [10][11][12]. A severe explosion accident occurred in the Anshan Irion and Steel Group in China, killing 13 workers and injuring another 17 [10,12]. To improve the safe production of foundry operations and reduce the probability of accidents, it is necessary to strengthen foundry safety management. Strengthening the safety management of a foundry business will help to reduce unsafe behavior by employees. Assessment of safety management will allow workers to gain a clearer understanding of the safety level of a foundry business.

Framework of the Proposed Safety Assessment Method
The framework of the proposed safety assessment method for a casting workshop is shown in Figure 1. method. Cause and effect were used to identify potential causes of accidents, and LOPA was used to identify safety measures that could protect against the identified risk factors.

Framework of the Proposed Safety Assessment Method
The framework of the proposed safety assessment method for a casting workshop is shown in Figure 1. In order to determine the safety measures to be taken, the safety level of a casting workshop should be achieved first. A safety assessment is usually used to obtain the safety level of enterprises, and an assessment indicator system was established here, in which the sub-indicators mainly include educational training, safety input, dangerous and harmful factors control, hidden danger identification and security systems. After the subjective weights of the evaluated indicators were determined by analytic hierarchy process [25,26], and an appropriate safety situation was determined by experts for each evaluated indicator, the safety level of the casting workshop was preliminary assessed by the traditional fuzzy evaluation method [41]. However, the assessment process has two weaknesses: on the one hand, the fuzzy evaluation method does not reflect the randomness of assessment result; on the other hand, the subjective analytic hierarchy process does not take advantage of the objectivity of real data. The cloud model [22][23][24] was introduced to take randomness into consideration, the integrated weight method [33] was adopted, and a new algorithm was proposed to determine the preference coefficient of the integrated weight based on the least square method [35] in this study. To validate the cloud model and integrated weight algorithm for the safety assessment, grey relational analysis [16][17][18] was applied. Then, the causes and sub-causes of dangerous and harmful factors were identified by cause and effect analysis [36,37], and the causes mainly including dust, noise, toxic gas, mechanical injury, empyrosis and electric shock. In addition, In order to determine the safety measures to be taken, the safety level of a casting workshop should be achieved first. A safety assessment is usually used to obtain the safety level of enterprises, and an assessment indicator system was established here, in which the sub-indicators mainly include educational training, safety input, dangerous and harmful factors control, hidden danger identification and security systems. After the subjective weights of the evaluated indicators were determined by analytic hierarchy process [25,26], and an appropriate safety situation was determined by experts for each evaluated indicator, the safety level of the casting workshop was preliminary assessed by the traditional fuzzy evaluation method [41]. However, the assessment process has two weaknesses: on the one hand, the fuzzy evaluation method does not reflect the randomness of assessment result; on the other hand, the subjective analytic hierarchy process does not take advantage of the objectivity of real data. The cloud model [22][23][24] was introduced to take randomness into consideration, the integrated weight method [33] was adopted, and a new algorithm was proposed to determine the preference coefficient of the integrated weight based on the least square method [35] in this study. To validate the cloud model and integrated weight algorithm for the safety assessment, grey relational analysis [16][17][18] was applied. Then, the causes and sub-causes of dangerous and harmful factors were identified by cause and effect analysis [36,37], and the causes mainly including dust, noise, toxic gas, mechanical injury, empyrosis and electric shock. In addition, 18 appropriate safety measures were identified using LOPA [10,38] to protect employee health and improve the safety level of the foundry business.

Fuzzy Evaluation Method
The fuzzy evaluation method is derived from fuzzy mathematics, and the level of the project is evaluated by fuzzy transformation and maximum membership degree [41]. The detailed procedure of the fuzzy evaluation method is described below.
The matrix U = {u j } represents the set of evaluated indicators, where 1 ≤ j ≤ n and n is the number of indicators evaluated; the matrix V = {v i } is the set of evaluation levels, 1 ≤ i ≤ m and m is the number of evaluation levels. The fuzzy evaluation matrix of the project is R = {r ij }, where r ij is the membership of the jth indicator evaluated at the ith evaluation level. The membership of the evaluated indicator is determined by the membership function [36].
The weight of indicator is evaluated to be W = [w 1 , w 2 , · · · , w n ] . The fuzzy evaluation result is obtained by the following equation.
The safety level corresponding to the maximum b i is the final evaluation result according to the maximum membership principle.

Cloud Model
The cloud model is the specific uncertainty transformation between a qualitative concept and its corresponding quantitative value, in which the uncertainty transformation contains fuzziness and randomness, and the safety level of the casting workshop can be obtained by combining the qualitative and quantitative evaluation results [22][23][24]. A specific cloud model can be characterized by three numerical characteristics (Ex, En, He). The expectation Ex is the central value of the qualitative concept, the entropy En is the uncertain distribution of the qualitative concept, and the hyper entropy He is the fuzziness and randomness of En.

Forward Cloud Algorithm
The forward cloud algorithm is used to generate as many cloud drops as needed based on the given numerical characteristics (Ex, En, He). It can be easily qualitatively analyzed through mapping the cloud model and the standard cloud models of indicators evaluated into one cloud image.
Input: The numerical characteristics (Ex, En, He) of the qualitative concept, and the number of cloud drops n.
Output: The position in the domain and membership of each cloud drop.
(1) Generate a normal random number En with expectation En and standard deviation He.
(2) Generate a normal random number x with expectation Ex and standard deviation En .

Backward Cloud Algorithm
The backward cloud algorithm is used to calculate the numerical characteristics (Ex, En, He) from the given cloud drops.
Output. Numerical characteristics (Ex, En, He) of the cloud drops.
The standard cloud model is the standard for evaluating cloud models, and it is usually determined by the golden section method [22]. The standard cloud model is usually divided into an odd number, and is divided into five levels in this paper, including Safe C 1 (Ex 1 , En 1 , He 1 ), Relatively safe C 2 (Ex 2 , En 2 , He 2 ), Generally safe C 3 (Ex 3 , En 3 , He 3 ), Relatively dangerous C 4 (Ex 4 , En 4 , He 4 ), and Dangerous C 5 (Ex 5 , En 5 , He 5 ). For the indicators evaluated with two unilateral constraints [x min , x max ], the numerical characteristics of the standard cloud model can be calculated as follows based on the golden section method.
En 3 = 0.618 · En 2 (8) He 3 = k · En 3 (10) He 1 = He 5 = He 2 0.618 (12) where the parameter k in Equation (10) may be changed based on the fuzziness and randomness of the indicators evaluated [24]. A larger He, as mentioned above, indicates greater randomness of assessment indicators; a smaller He suggests less randomness of the assessment indicators and randomness that is more easily lost [42]. Usually, k is no more than one third, and we set k = 0.1 in this treatment according to reference [22].

Comprehensive Cloud Model
The cloud model of indicators evaluated is C i (Ex i , En i , He i ) and the final comprehensive cloud model is C (Ex, En, He), in which C i is the fundamental cloud model of C. The comprehensive cloud model C can be computed as follows.
where v i is the weight of the indicators evaluated and n is the number of indicators evaluated.

Similarity between the Cloud Model and Standard Cloud Model
Similarity is used to determine the quantitative evaluation result of the cloud model. By calculating the similarity between the cloud model of the indicator evaluated and its corresponding standard cloud models, the specific quantitative evaluation result can be obtained.
The similarity between the cloud model and standard cloud model can be characterized as follows [22].
where Ex is the cloud model expectation of the indicator evaluated, Ex j is the entropy of the jth standard cloud model, and En j is the hyper entropy of the jth standard cloud model. The level of the standard cloud model corresponding to the maximum similarity λ j is the quantitative evaluation result based on the maximum membership principle.

Grey Relational Analysis
Grey relational analysis is widely used in grey system theory [16][17][18], which is applied to calculate the grey relational degree among different evaluated indicators, and the safety level of the casting workshop can be achieved by grey relational degree. The detailed process of grey relational analysis is as follows.
If the original data matrix is Y = [y ij ], the optimal index set is D = [d 1 , d 2 , · · · , d n ], where d j is the optimal value of the jth evaluated indicator. For the larger the better indicator, d j is the maximum for the indicator.
The dimensionless nature of each indicator can be achieved as follows.
After becoming dimensionless, the original data matrix can be transferred into Z = [z ij ], and the optimal index set is transferred into If the optimal index set D * is the reference sequence and the matrix Z is the sequence compared, then the grey relational coefficient of the jth indicator evaluated for the ith evaluation level can be calculated as follows.
where ρ ∈ [0, 1] is the resolution coefficient, and is usually set to ρ = 0.5. Additionally, if the weight of the indicator evaluated is W = [w 1 , w 2 , · · · , w n ] then the grey relational degree of the indicator evaluated can be obtained as follows.
The larger the grey relational degree, the closer the evaluated indicator is to the optimal index set. Accordingly, the evaluation level of the project is confirmed.

Cause and Effect-LOPA
Once the safety level of the casting workshop is achieved, corresponding safety measures should be adopted. The cause and effect diagram clearly and comprehensively shows the causes of accidents in simple words, facilitating analysis [36,37]. LOPA is a semi-quantitative approach to assess accident scenarios that analyzes initiating events, consequences, and IPLs [10,38]. Cause and effect-LOPA identifies factors that may lead to accidents, and describes IPLs that could be applied to prevent accidents ( Figure 2).

Fuzzy Evaluation of Casting Workshop
A mechanical manufacturing business in Hunan, China was built in 1958, which covers an area of more than one point eight million square meters and has about five hundred workers. The registered capital of this mechanical manufacturing business is two billion yuan. The number of different types of equipment is more than 2800.
In recent years, this foundry business produced the first high performance driverless road roller in China, as well as the first environmentally friendly compacting machine for rubbish. Casting is a metal hot working process for producing components via mechanical manufacturing, which plays an important role in the national economy. Although it's a service in social development, casualty accidents still occur. This study aims at adopting corresponding counter measures based on the safety evaluation result.
Analysis of the foundry site revealed that the factors affecting safety management of a casting workshop mainly include educational training, safety input, control of dangerous and harmful factors, hidden danger identification, and security systems. Therefore, the set of evaluated indicators is U={educational training(ET), safety input(SI), dangerous and harmful factors control(DHFC), hidden danger identification(HDI), security system(SS)}. The set of evaluation levels can be divided into V={Safe, Relatively safe, Generally safe, Relatively dangerous, Dangerous}.

Fuzzy Evaluation of Casting Workshop
A mechanical manufacturing business in Hunan, China was built in 1958, which covers an area of more than one point eight million square meters and has about five hundred workers. The registered capital of this mechanical manufacturing business is two billion yuan. The number of different types of equipment is more than 2800.
In recent years, this foundry business produced the first high performance driverless road roller in China, as well as the first environmentally friendly compacting machine for rubbish. Casting is a metal hot working process for producing components via mechanical manufacturing, which plays an important role in the national economy. Although it's a service in social development, casualty accidents still occur. This study aims at adopting corresponding counter measures based on the safety evaluation result.
Analysis of the foundry site revealed that the factors affecting safety management of a casting workshop mainly include educational training, safety input, control of dangerous and harmful factors, hidden danger identification, and security systems. Therefore, the set of evaluated indicators is U={educational training(ET), safety input(SI), dangerous and harmful factors control(DHFC), hidden danger identification(HDI), security system(SS)}. The set of evaluation levels can be divided into V={Safe, Relatively safe, Generally safe, Relatively dangerous, Dangerous}.
After comparing the relative importance of evaluation indicators according to the analytic hierarchy process [25,26], the judgment matrix can be achieved as follows [43].
Based on reference [25,26], we can see that the degree of preference may reach up to 9 in extreme circumstances for different industries and different evaluation indicators. For the casting workshop of the foundry enterprise, there is not much difference among the importance of different evaluation indicators in Table 1. Taking ET and SI as an example, the scale of ET to SI is 2, indicating that the importance of ET is mildly (less than slightly) favored over SI. It should be noted that different weights of evaluation indicators can be achieved based on different degrees of preference. As mentioned in the Introduction, the weights achieved by the analytic hierarchy process mainly rely on subjective judgments from experts rather than actual data. Although the analytic hierarchy process might take full advantage of experts, different assessment results might be obtained from different experts. Table 1. Judgment matrix of evaluation indicator of a casting workshop.
The consistency index was CI = λ max −n n−1 = 0.0487, and the consistency ratio was CR = CI RI = 0.0487 1.12 = 0.0435 < 0.1, which indicates the judgment matrix was a consistent matrix [26]. The subjective weight can be calculated as follows after normalization. After experts vote on the level of each indicator evaluated, the evaluation matrix can be constructed by the vote ratio as follows [43].
For the evaluation matrix R, taking ET as an example, which means 12% of expert score 5, 20.1% of expert score 4, 35.4% of expert score 3, 20.7% of expert score 2 and 11.8% of expert score 1 for this indicator. The bigger the score, the higher the safety level of the casting workshop.
The fuzzy evaluation result can be obtained as follows, after application of Equation ( Therefore, the safety management evaluation result for the casting workshop was "Generally safe" based on the maximum membership principle.

Integrated Weight Determined by Least Square Method
The subjective weight method relies on the subjective judgments of experts, potentially resulting in variability in the assessment results. The objective weight method is based on actual data rather than expert judgments, but may not be exactly relevant to a given situation. The integrated weight method combines subjective and objective weight methods to include both expert judgments and data. The widely used integrated weight method is described as follows [33,44].
where, w I j , w S j and w O j indicate integrated, subjective, and objective weights, respectively; n is the number of indicators evaluated; δ ∈ [0, 1] is the preference coefficient.
For the preference coefficient δ, there is no explicit computational method. Thus, in this study, a new algorithm was proposed to determine the preference coefficient based on the least square method [35] as follows.
The error sum of square among integrated, subjective, and objective weights of the evaluated indicator can be calculated as shown below.
The least square method requires the least error sum of the square, so that Equation (21) achieves the minimum value.
Additionally, the method requires the derivation of the preference coefficient δ to allow Equation (20) to achieve the minimum value so that the derivative is 0, as shown in Equation (22).
In Equation (22), the polynomial n j=1 w S j − w O j 2 ≥ 0. For Equation (22) to be correct, the polynomial (2δ − 1) must be 0. Therefore, δ = 0.5. If we then input δ = 0.5 into Equation (20), we obtain Equation (23) Although Equation (23) has the same form as references [33,44], it has more explicit physical significance in this study due to application of the least square method, that is, the error sum of the square among integrated, subjective and objective weights achieve the minimum value.
The objective weights of the evaluation indicators can be achieved by the entropy weight method [28,29]  The findings results show that there is significant difference among different weights of evaluation indicators, such as the weight of DHFC is more than twice over ET. The objective entropy weight method is mainly based on real data rather than expert judgments, taking advantage of the objectivity of real data.
Therefore, the integrated weights of the indicator evaluated can be determined based on Equation (23)

Cloud Model Evaluation of Sub-indicators
If we set the numerical range of safety level as [1,5], then the corresponding standard cloud models can be achieved. Taking C 3 (Ex 3 , En 3 , He 3 ) as an example, the expectation Ex 3 can be calculated according to Equation (24) as follows.
The entropy En 3 can be calculated according to Equations (25) and (26) as follows.
The hyper entropy He 3 can be calculated according to Equation (27) as follows.
Then the standard cloud models of safety levels can be achieved in a similar way based on Equations (2)-(12), shown in Table 2. For the evaluation matrix, assuming that one thousand experts are taking part in the vote. Taking ET as an example, 120 experts score 5, 201 experts score 4, 354 experts score 3, 207 experts score 2 and 118 experts score 1 for this indicator. The cloud model of ET can be obtained via a backward cloud algorithm, the expectation Ex can be calculated as follows.
The entropy En can be calculated based on the backward cloud algorithm as follows.
The hyper entropy He can be calculated based on backward cloud algorithm as follows.
The cloud models of other evaluation indicators can be achieved in a similar way, with the help of MATLAB software (The MathWorks Inc. Natick, MA, USA), shown in Table 3. The qualitative evaluation result can be obtained by mapping the cloud model, and its corresponding standard cloud models of ET into a cloud picture, shown in Figure 3.  The qualitative evaluation result can be obtained by mapping the cloud model, and its corresponding standard cloud models of ET into a cloud picture, shown in Figure 3. As shown in Figure 3, the main cloud model of ET falls between the Relatively dangerous and Relatively safe standard cloud models, and the cloud drops of ET cloud model are most concentrated in the region of the Generally safe standard cloud model. Therefore, the qualitative evaluation result of ET was between Relatively dangerous and Relatively safe, and more inclined to Generally safe.
The assessment result of ET was the same in comparison against the expectation and corresponding safety levels ( Table 2), which was in line with Xu et al.'s intuitive understanding that the assessment result of the cloud model was mainly based on the expectation of the evaluation indicator [45]. Safety level was worse when the expectation of the evaluation indicator was poor, which confirms that the introduced cloud model yields an accurate safety assessment. A qualitative As shown in Figure 3, the main cloud model of ET falls between the Relatively dangerous and Relatively safe standard cloud models, and the cloud drops of ET cloud model are most concentrated in the region of the Generally safe standard cloud model. Therefore, the qualitative evaluation result of ET was between Relatively dangerous and Relatively safe, and more inclined to Generally safe.
The assessment result of ET was the same in comparison against the expectation and corresponding safety levels (Table 2), which was in line with Xu et al.'s intuitive understanding that the assessment result of the cloud model was mainly based on the expectation of the evaluation indicator [45]. Safety level was worse when the expectation of the evaluation indicator was poor, which confirms that the introduced cloud model yields an accurate safety assessment. A qualitative assessment was obtained by comparing the cloud model of ET and its corresponding standard cloud models. The cloud drops of ET, as discussed above, are a good example of this, as most of the cloud drops fall between Relatively dangerous and Relatively safe, and are more inclined to Generally safe. The qualitative assessment result indicates that the safety level of ET was between Relatively dangerous and Relatively safe, and more inclined to Generally safe. Greater cloud model coverage area also indicates greater fuzziness in determining the corresponding safety level; in other words, the safety evaluation data were scattered across a very wide range and had large changes in safety levels. Safety indicators with greater cloud thickness also showed greater randomness; that is to say, the same safe score may have different membership degrees. For example, the membership degrees of cloud drops belonging to Relatively dangerous were from 0.3 to 0.8 in the case of the safety indicator of ET at score 2 ( Figure 3).
From the above analysis, the qualitative evaluation result of ET is more likely to be Generally safe, indicating that the performance of ET is not very high, and corresponding safety measures should be adopted.
It is necessary to calculate the similarity between cloud model of ET and corresponding standard cloud models, to determine the specific safety level to which it belonged. Therefore, the similarities between this cloud model and corresponding standard cloud model can be obtained using Equation (16), shown in Table 4. λ 3 = 0.99992 was the maximum similarity of ET evaluation indicator, indicating the safe level of ET belonged to Generally safe. That is to say, the quantitative evaluation result of ET was Generally safe.
When determining the safety level of the evaluation indicator by the cloud model, the maximum similarity corresponding to the standard cloud model is the quantitative evaluation result based on the maximum membership principle. As shown in Table 4, not all the maximum similarities of evaluation indicators are close to 1, which reflected the uncertainty conversion between qualitative concepts and their corresponding quantitative values, and the uncertainty conversion containing fuzziness and randomness. Compared with the fuzzy evaluation method, although not all the maximum similarities of evaluation indicators are close to 1, the distinction degree of similarities is more remarkable (Table 4). Taking HDI as an example, although the maximum similarity is λ 3 = 0.127, which is about 488 and 24 times over λ 1 and λ 2 respectively.
The qualitative evaluation result of ET was between Relatively dangerous and Relatively safe, and more inclined to Generally safe. The quantitative evaluation result of ET was Generally safe. Therefore, by combining the qualitative and quantitative evaluation results, the evaluation result of ET was Generally safe.
The evaluation results of other sub-indicators can be obtained in a similar way, and the evaluation results of SI, DHFC, HDI and SS were all Generally safe.

Cloud Model Evaluation of Casting Workshop
The comprehensive cloud model of the casting workshop (CW) can be achieved via Equations (13)- (15), shown in Table 3.
The qualitative evaluation result can be obtained by mapping the cloud model of the CW, and the corresponding standard cloud model into a cloud image, shown in Figure 3.
As shown in Figure 3, the main cloud model of CW falls between the Relatively dangerous and Relatively safe standard cloud models, with the cloud drops of the CW cloud model being most concentrated in the region of the Generally safe standard cloud model. Therefore, the qualitative evaluation result of CW was between Relatively dangerous and Relatively safe, and more inclined to Generally safe.
It is necessary to calculate the similarity between cloud model of CW and the corresponding standard cloud models, to determine the specific safe level to which it belonged. Therefore, the similarities between this cloud model and the corresponding standard cloud model can be obtained using Equation (16), shown in Table 4. λ 3 = 0.60196 was the maximum similarity of CW evaluation indicator, indicating the safe level of CW belonged to Generally safe. That is to say, the quantitative evaluation result of CW was Generally safe.
The qualitative evaluation result of CW was between Relatively dangerous and Relatively safe, and more inclined to Generally safe. The quantitative evaluation result of CW was Generally safe. Therefore, by combining the qualitative and quantitative evaluation results, the evaluation result of CW was Generally safe.

Comparison by Grey Relational Analysis
To validate the integrated weight algorithm proposed in this study, we next used grey relational analysis to compare the safety assessment results [16][17][18] with the cloud model. The process of grey relational analysis is illustrated below.
The dimensionless matrix of the evaluated indicator can be achieved as follows based on Equation (31).
The optimal index set was transferred into D* = [11111]. The grey relational coefficient was achieved based on Equation (32).
The evaluation level for the casting workshop was "Generally safe" according to the grey relational degree.
The assessment result determined by grey relational analysis was the same as that obtained by the cloud model, in which indicator weights were determined using the revised integrated weight algorithm. Thus, the integrated weight method proposed and cloud model adopted in this study are feasible.

Cause and Effect-LOPA of Dangerous and Harmful Factors
The safety management assessment indicated conditions are likely to be Generally safe based on the above analysis. Accidents are probable in the foundry workplace, due to dangerous and potentially harmful conditions. Controlling potentially dangerous factors will help to improve the safe operation of the foundry. To do this, cause and effect-LOPA was applied to identify dangerous and harmful factors that contribute to accidents, as shown in Figure 4.
The evaluation level for the casting workshop was "Generally safe" according to the grey relational degree.
The assessment result determined by grey relational analysis was the same as that obtained by the cloud model, in which indicator weights were determined using the revised integrated weight algorithm. Thus, the integrated weight method proposed and cloud model adopted in this study are feasible.

Cause and effect-LOPA of Dangerous and Harmful Factors
The safety management assessment indicated conditions are likely to be Generally safe based on the above analysis. Accidents are probable in the foundry workplace, due to dangerous and potentially harmful conditions. Controlling potentially dangerous factors will help to improve the safe operation of the foundry. To do this, cause and effect-LOPA was applied to identify dangerous and harmful factors that contribute to accidents, as shown in Figure 4. As shown in Figure 4, the causes that may lead to accidents in the casting workshop mainly including dust, noise, toxic gas, mechanical injury, empyrosis and electric shock, and each cause contains several sub-causes. Taking dust as an example, whose sub-causes are sand mixing, modeling, shakeout and fettling, that is, from sub-causes 1 to 4. In other words, the dust in the casting workshop is likely to be caused by sub-causes 1-4. Similarly, sub-causes of noise are from 5 to 7, subcauses of toxic gas are from 8 to 10, sub-causes of mechanical injury are from 11 to 13, sub-causes of empyrosis are from 14 to 16, and sub-causes of electric shock are from 17 to 19. The causes and subcauses that may lead to accidents in the casting workshop are shown in Table 5.  As shown in Figure 4, the causes that may lead to accidents in the casting workshop mainly including dust, noise, toxic gas, mechanical injury, empyrosis and electric shock, and each cause contains several sub-causes. Taking dust as an example, whose sub-causes are sand mixing, modeling, shakeout and fettling, that is, from sub-causes 1 to 4. In other words, the dust in the casting workshop is likely to be caused by sub-causes 1-4. Similarly, sub-causes of noise are from 5 to 7, sub-causes of toxic gas are from 8 to 10, sub-causes of mechanical injury are from 11 to 13, sub-causes of empyrosis are from 14 to 16, and sub-causes of electric shock are from 17 to 19. The causes and sub-causes that may lead to accidents in the casting workshop are shown in Table 5. In Figure 4, to prevent accidents in the casting workshop and protect employee health, 18 IPLs should be adopted. Taking dust as an example, whose IPLs are wearing a mask, wet working and dust removal by ventilation, that is, from IPLs 1 to 3. In other words, the dust in the casting workshop can be eliminated by IPLs 1-3. Similarly, IPLs of noise are from 4 to 6, IPLs of toxic gas are from 7 to 9, IPLs of mechanical injury are from 10 to 12, IPLs of empyrosis are from 13 to 15, and IPLs of electric shock are from 16 to 18. The IPLs that can be adopted to prevent accidents and protect employee health are shown in Table 6. In this cause and effect-LOPA, foundry accidents were attributed to 6 causes and 19 sub-causes, and foundry accidents can be prevented by 18 IPLs. Causes 1 to 6 are all risk factors, which can lead to accidents in the casting workshop. Causes 1 and 2 may result in organ failure of the body and belong to low risk factors; Causes 3 to 6 can lead to serious casualties and belong to high risk factors. If the IPLs proposed in this study were not carried out, accidents may occur in the casting workshop. The safety level of the foundry can be improved by taking steps based on the cause and effect-LOPA identification of dangerous and harmful factors.
From the standpoint of safety management, to improve safe production in the casting workshop, management measures should also be adopted. First, improve the rules and regulations for the casting workshop. Second, strengthen the safety training. Third, the identification of dangerous and harmful factors and elimination of accident potential.

Discussion
As a traditional safety assessment method, the fuzzy evaluation method can deal with the fuzziness during conversion [14]. The safe production of a foundry business is affected by many factors, and the relationships between some factors may be uncertainty and even randomness. In this case, the fuzzy evaluation method is not suitable for determining the safety level of the foundry enterprise. The cloud model realized the uncertainty conversion between qualitative concepts and their corresponding quantitative values, as well as taking fuzziness and randomness into account [22][23][24]. By combining the qualitative and quantitative evaluation results, the evaluation result of the cloud model can be achieved. Therefore, the cloud model was introduced in the safety assessment of the foundry enterprise, and the validity of the cloud model evaluation was validated by grey relational analysis [16][17][18].
In order to perform a safety assessment of the foundry enterprise, the weights of the evaluation indicators must be known. For the preference coefficient of the integrated weight, there is no explicit computational method. To solve this issue, a new algorithm was proposed to determine the preference coefficient of the integrated weight based on the least square method [35] in this study. The integrated weight algorithm proposed in this study has more explicit physical significance due to application of the least square method, that is, the error sum of the square among integrated, subjective and objective weights achieves the minimum value.
Once the safety level for the foundry enterprise has been determined, corresponding safety measures should be adopted to protect employee health. Fault tree analysis [46,47], the traditional accident analysis method, can identify the causes of an accident, but cannot perform detailed analysis of identified risk factors. The cause and effect analysis method can identify the causes of the identified risk factors [36,37], and LOPA was applied to identify appropriate safety measures corresponding to the identified risk factors [10,38]. This study integrates these two methods into a cause and effect-LOPA method, which can identify in advance factors that may lead to accidents, and protect employee health using IPLs. The most representative research of occupational accidents analysis is safety barriers [39,40]. Safety barriers are an effective means against known risks, a way to prevent unwanted events from taking place and to protect against their consequences. The accident prevention measures that are adopted in this paper belong to safety barriers.
To simplify the discussion, the parameter k in Equation (10) was chosen as only 0.1. Future research should focus on the influence of this parameter on the safety evaluation result.

Conclusions
A composite safety assessment model for a casting workshop based on the cloud model and cause and effect-LOPA was proposed in this study to protect employee health. The main conclusions are shown below.
After the weights of evaluation indicators were determined using the subjective analytic hierarchy process and objective entropy weight method respectively, a new integrated weight algorithm was proposed based on the least square method. The integrated weight determined by the least square method has more explicit physical significance in this study, that is, the error sum of the square among integrated, subjective and objective weights achieves the minimum value.
The safety level of the casting workshop was Generally safe based on the qualitative and quantitative analysis of the cloud model, which realized the uncertainty conversion between qualitative concepts and their corresponding quantitative values, as well as taking fuzziness and randomness into account. The validity of the cloud model evaluation was validated by grey relational analysis.
The potentially dangerous and harmful factors were analyzed using cause and effect-LOPA, identifying 6 causes and 19 sub-causes that may lead to accidents and 18 IPLs that could prevent accidents in a casting workshop. The safety level of this foundry could thus be improved by applying the cause and effect-LOPA of potential risk factors.