Method note
MADS-MOSAR, thirty years on: what still works
The French systemic-risk method got the ontology right: source, flux, target, barrier. What it never had was a way to stay current. That part is now solvable.
2 April 2026 · 9 min · Quetzal team
MADS-MOSAR is not fashionable. It is a two-module method from French industrial safety practice: decompose a facility into sub-systems, identify how danger flows from sources to targets through defined fluxes, link scenarios into logical trees, then rank and barrier them. Generations of études de dangers were built on it.
Its deep insight is ontological. By insisting that every hazard be expressed as source → flux → target, the method forces cascade thinking: any struck target is a candidate source for the next link. Escalation is not an afterthought. It is the grammar.
Its weakness was always operational. A MOSAR study is a workshop artifact: expensive to produce, frozen at signature, and quietly falsified by every management-of-change file that follows. The method describes a living network; the deliverable is a binder.
Our position is that the method was waiting for its execution layer. The decomposition, the pairing rules and the flux taxonomy are computable structures. The scenario generation step, historically limited by which failure modes the workshop could imagine, is exactly where a mechanism-trained model earns its keep. And the loop, where the target becomes the source until closure, is what machines do without fatigue at hour nine of a workshop.
Aegis is, in one sentence, MADS-MOSAR made continuous: the same grammar, re-derived against the current state of the system, every time the system changes.
