“Lessons Learned” potentials from Japan’s Nuclear Problems

So far we do NOT have all the facts of what happened at the Nuclear Power Plant in Japan when the earthquake and tsunami hit, but we have gotten some insight into what is supposedly occurring in the aftermath of these concurrent disasters, which very well may lead to even a larger disaster with much longer impact than the earthquake and the tsunami combined!

I find it hard to imagine that a nuclear power plant would be built to withstand a certain natural disaster, but the safety systems to be utilized when such an event occurs would not be built to the same standard!!! There are some that make the argument that this earthquake, followed by a 30’ tsunami could not have been planned for.  Really, you mean an island (e.g. surrounded by ocean) that is located in the most active earthquake region on this planet figured that an earthquake and tsunami would never occur or that the “likelihood” was so far remote that it would not be wise to plan for.  I will grant you this, not every earthquake creates a tsunami…but the ones that occur under bodies of water (e.g. oceans) have a very good chance.  So when we look at this chain of events, we see one of the links being a high probability (e.g. earthquake and it does not have to be a 9.0) and since we are an island nation, surrounded by the ocean the tsunami scenario should have been viewed as at least a moderate probability.  But things are looking like they did not consider back up emergency power.  Yesterday the power company spoke of the hopes in completing a new power line installation to be in place soon to power up the cooling pumps.  How big are these pumps?  I have seen an entire chemical process be started up using diesel generators the size of semi-trucks that can be in place in hours.

Did their emergency generators get knocked out in the concurrent disasters or did they not have adequate “layers of protection”.  One thing I see quite often in my PHAs on conceptual drawings is that engineers will build the physical process (tanks, pipes, etc.) to withstand Z, but the safety systems on them are designed to withstand X.  So I always ask the question no one wants to discuss, as we all know “Safety is #1”…why are we building a process to withstand a Cat 5 Hurricane, but all the safety systems could not withstand a five-year-old with a super soaker!!!!  You’ve designed the process to be at a level for the worst possible storm surge of 20’, yet the emergency generator that would power all of your cooling water is on a 8” slab at ground level and the underground fuel tank vent stack is only 10’.  You get some funny looks and then the slamming begins…”you safety people just do not get it”, “we cannot plan for the end of the world”, “ok lets pull the safety guy out of the clouds and back down to earth”, etc. I just start typing a recommendation that further analysis is needed on the facility siting and design of the emergency power systems to ensure their ability to operate within the same scenario that the process is being built to.  Now they are really fired up and request that I withdraw the recommendation as it is not valid – my response, just close it out and say the safety engineer was an idiot and that the recommendation had no merit.  We move on and we come to a scenario that the PHA team claims the emergency generator would be a safeguard.  My position is, no I am sorry, you have not designed that safeguard to withstand the same conditions and reliability as the process so I am not allowing it to be listed as a safeguard and point them back to my original recommendation that they all got so mad about.

I am very proud of the fact that when this study was completed I received a formal letter that hangs on my office wall from the Sr. VP of Operations (an old boss of mine) for identifying this design flaw. The company instituted an emergency Capital Project to provide funds to all facilities within 50 miles of a coast or in a flood-prone location (the company actually defined this) so that they could design their emergency power supply to the same scenario they built the process too.  The PHA we were doing was just a HAZOP, but safety professionals need to always challenge the status quo.  We are not emotionally attached to the process as so many engineers, operators, and managers are.  Sort of like we are emotional when an audit finds a flaw in our safe work practices!!! We should NEVER allow a “safeguard” to reduce risks if that safeguard is NOT designed, installed, operated, and maintained 100% by the book.  If the so-called safeguard is not in the formal mechanical integrity program and its never tested, inspected, calibrated, etc. then why would we think we can take credit for it. 

Another discussion for a rainy day is the “Operator Training” safeguard!  I have the opportunity in some cases to not only have the privilege of doing the PSM/RMP audit for a business, but they call us back to help with the next PHA revalidation.  Now I know how they fared in their audit a few months prior and know that many operators had not received training on the actual SOPs and those that did had not received refresher training on the SOPs within 3 years.  Yet as we started the HAZOP revalidation I said we take this safeguard away, based of the fact that operators were not being trained on the consequence of this deviation and the steps to correct or avoid the deviation.  Take the safeguard away and the risk increases, sometimes to the highest level, if it was the only safeguard for the scenario. Yet for years the facility felt very comfortable about what they were doing and they felt a lot of what they were doing was in fact “overkill”.

Scroll to Top