“Operator Rounds” in a PSM/RMP Covered Process

In many chemical processes around the world, operators are making their rounds checking on those items that have been deemed “critical to process safety”.  These rounds usually include checking pressure, temperature, tell-tale gauges, tank levels, heat tracing, taking samples, etc.  But in many instances involving these checklists, one item is painfully obvious after an incident– the operator was never provided with safe upper and lower limits of those items they were checking so that they could IMMEDIATELY recognize a process deviation.  We have all seen these checklists… it’s a copy of a copy, of a copy, of a copy, and about ¼ of the items are scratched out as they no longer apply.  The date on the bottom right of the checklist is 15 years ago (meaning the last official update was 15 years ago!).  But each shift, like clockwork, an operator heads out the door, grabs the clipboard with the checklist, and like he/she has done hundreds of times, if not thousands of times, makes their rounds filling in the blanks on the items we have deemed critical to our process safety.  Sound familiar?  Here are some suggestions to move forward with your “rounds checklist.”

Using a “rounds checklist” is a GREAT place to begin an analysis of the process’s consequences of deviation, as well as a means to develop steps to correct the deviation and avoid the consequences.  In this article, I hope to show how this simple checklist can be used as a necessary building block to take our process safety efforts to the next level.

First let’s look at the checklist itself. 

Without a doubt, this checklist MUST contain the safe upper and lower limits for EACH CRITICAL ITEM the operator will be tasked with checking/inspecting.  Very rarely do we come across a “rounds checklist” that contains this critical data directly on the checklist, but it is my professional opinion it is a MUST HAVE.  We have been involved in more than one investigation where had the operator known IMMEDIATELY that the process was outside its Safe Operating Envelope (SOE), he/she could have taken the appropriate action(s).  I can think of three incidents we have been involved with in the past two years where the operator wrote down the data, and 8 or 12 hours later, it was caught by an engineer or supervisor who happened to be looking at something else on the checklist and noticed the deviation.   If the facility has a clear definition of which items on the checklist are “critical to process safety”, the checklist MUST contain the SAFE UPPER and LOWER LIMITS for these items.  This way, when the operator is writing down their readings, they can IMMEDIATELY identify a deviation from the SOE and not rely on some checklist review hours later by someone else with the hopes the deviation will be noticed in time.

This leads us to the next step… Establishing the actions for the operator(s) to correct the deviation and avoid the consequence(s).  This CRITICAL ACTION should have already been done in the original PHA and the drafting of the operating procedures. Still, it is not uncommon for us to find items on the “rounds checklist” that everyone agrees is CRITICAL to process safety, yet somehow the items fell through the cracks in the early days.  Using the checklist, we can now systematically review those items that have been deemed critical to process safety.  I usually start with the first item on the sheet and work my way through all the items, in order of their appearance on the checklist.  Each item is challenged regarding its validity of being on the checklist and why it is deemed CRITICAL to process safety.  Once it has been established to be critical, we review the SAFE UPPER and LOWER LIMITS for the item. (Please refer to my article Establishing Safe Upper and Lower Limits for more on how to rationally establish safe upper and lower limits for your critical process parameters).  The checklist is then revised to document this SOE for the item so it will IMMEDIATELY notify the operator of any deviation. 

Now we must provide the operator(s) with the necessary steps to correct this deviation, as well as inform them of the consequences of this deviation and the steps to take to avoid those deviations.  At this point, I always like to look to the most recent PHA for assistance in determining the consequences of deviation, but don’t be surprised if the PHA is void of this information.  This is especially true if the “What-If” or “What-if Checklist” methodology was used for the analysis.  These two methodologies just are not systematic enough to dig down deep into all the process parameters critical to process safety; it is not that they are wrong or bad methods; they are just not as in-depth as, say, the Hazard and Operability (HAZOP) methodology (NOTE: Please read my CCPS book, Hazard Evaluation Techniques, 3rd Edition for more explanation on PHA methodologies).  So at this point, we may be required to conduct our own mini-PHA to determine the consequences of this deviation.  Here is one way this could go…

The checklist item looks like this….  TK-101 Level =  99% (SOE = 10-90%)

Clearly, the process has exceeded its SAFE UPPER LIMIT by 9%.  We now ask, what are the consequences or potential consequences with the tank level in this state?  By the way, the material in this tank (and it is a pressure tank) is a highly volatile toxic, and flammable material that is stored as a liquid under pressure.  It is determined that without adequate head space in this tank, a release of the material is imminent through the pressure safety valve.  So we now have the consequence of deviation, and it AIN’T GOOD!

So what is the operator to do when he/she comes across this scenario?  This is where we MUST HAVE the right people involved in this exercise as we HAVE TO GET THIS RIGHT!  So as the facilitator of the exercise, our job is to challenge the status quo.  To get the ball rolling, just ask the operator what he/she would do in this instance; regardless if the answer they give us is right or wrong, we have a starting point to begin discussions and the analysis.  The first thing we need to do in our scenario is to STOP flow into this tank, but we also MUST ask, “what happens if we stop flow into this tank”?  In many processes, stopping a prescribed flow in one spot may make matters worse in another spot that is not as well designed to handle the deviation (e.g., having a spill in a contained and electrically classified area vs. having the spill in an uncontained and unclassified area).  NOTE:  I always like to use my PHA to review the NO FLOW parameter in the node involving the tank.  If the team determines that flow can be SAFELY stopped to this tank, then we need to specifically and systematically document how this operator will carry out this task.  And folks, we need CLEARLY DEFINED actions and not this stuff like “contact your supervisor”!!!!  It may be as easy as closing a single valve, or it may be a timely and challenging task (which would warrant an entirely different analysis and discussion with the engineering group!).  Either way, the operator is going to be provided with the well-defined steps he/she must take to avoid the consequences of this deviation in the level of this tank.

But we are still not done!  We now have to provide the operator with the steps to CORRECT this deviation so the process can return to it SAFE OPERATING ENVELOP.  In the paragraph above, we were AVOIDING THE CONSEQUENCE(S); now we have to CORRECT THE DEVIATION, as we still have a process outside its SOE.  So we have a tank that is nearly 100% full of highly volatile, toxic, and flammable material stored under pressure as a liquid.  We have to get the tank BACK TO its SOE as soon as possible because if we do not, the valve we closed to ensure we do not overflow this tank may take the entire process into an automated emergency shutdown (which has its own inherent risks).  In this situation, I like to have the operator check some other critical parameters associated with this tank, namely the pressure of this tank to ensure we are not exceeding that safe upper limit.  I would also STRONGLY suggest that if we have exceeded BOTH the LEVEL and PRESSURE SOE for this tank that this in itself is grounds for activating the emergency shutdown procedure.  NOTE we MUST have this ESD trigger in our SOPs to comply with PSM/RMP.  If the pressure is within its SOE, we would then provide the operator with the necessary steps to lower the level in this tank so that the LEVEL can return to its SOE and the operator can then open the fill valve that he was instructed to close when AVOIDING the consequence of this deviation.

These procedures to “correct the deviation and avoid the consequences” MUST be incorporated into the official operating procedures.  What I have always done, and there are other ways to do it, is to have an operating procedure for “making rounds”.  I like to get down to the finest level of detail in that we would even prescribe the order in which to make the rounds, the time of shift to make the rounds, and even that no single operator could make back-to-back rounds.  At one facility, we even prescribed a time period for the rounds to be completed, and this was based on a previous incident. After all, we all have some employees that may start their “round” at the beginning of their shift and in the last 30 minutes of their 12-hour shift write down the last reading and turn in the data before they leave.  In this scenario, did the round data do ANYONE ANY GOOD? 

So on our new rounds checklist, we will number each checklist item, and corresponding to each checklist number will be an operating procedure task that will define the steps to correct the deviation and/or to avoid the consequence(s).  Our  “making rounds” checklist would now look something like this:

TK-101 Level = 99% (SOE = 10-90%) 12

The operator could easily and quickly turn to “Task 12” in the “Making Rounds” procedure and there he/she would find the prescribed steps to take and any additional PPE or tools they may need.

As I said earlier, there are a lot of different ways to use a “rounds checklist” in your process safety program.  But one thing is COMMON to all “rounds checklist” – having an ill informed operator writing down numbers that he/she has no idea are bad numbers is inviting a consequence we work so hard to avoid!  Each and every operator qualified to make the “rounds” MUST have a CLEAR understanding of the safe upper and lower limits of the items they are checking/inspecting.  Final Tip… a well versed OSHA/EPA inspector will know how they can use your “rounds checklist” to interview operators.  If your checklist is void of the safe upper and lower limits and there is NO requirement in any procedure that the data be evaluated against the SOE’s, you may be in for a LONG six months with your neighborhood EPA/OSHA CSHO.

A couple of footnotes to consider when dealing with your “operator rounds”:

1) Don’t try and split hairs in your mini-analysis!  I have had engineers try and justify that on a cold winter night, being at 99% level in this tank may not be an issue.  Folks, we are already requiring our operators to be SUPER STARS, do we really want to have “seasonal” SOE’s?!?!?!?!  ALL of our SOE’s need to be established so they can handle the worst process scenario, worst atmospheric conditions, worst staffing levels, etc. 

2) If after reviewing your “rounds checklist” you find that there are several items that “fell through the cracks” in the early PHAs, it may be time to revisit your entire PHA and the methodology being used.  Don’t be surprised if this is the case and don’t be mad, just take advantage of the data and revisit your PHA – it happens to EVERYONE and is just part of process safety!  But don’t wait until your 5-year reval comes due; it may be too late then!

3) Any checklist used in process safety, MUST BE included within a documented and annually certified operating procedure.  It should NEVER be a standalone document that is copied from shift to shift and revised on the fly by operators and supervisors without the aid of an MOC.

4) Facilities should review the frequency in which they conduct their rounds.  If it is determined that rounds need to occur every 12 hours, then front-line supervisors need to ensure this is being met.  A common finding is that rounds are being made once a shift, but not every 12 hours.  We have to have procedures in place to ensure that Shift 1 is not doing their rounds at the beginning of their shift and Shift 2 is doing their rounds at the end of their shift – this translates into a 23 hour gap between rounds.

5) Facilities should AUDIT their “rounds procedures” and practices.  A “rounds checklist” that has a lot of “N/A” noted may be a sign of an out of date checklist.  If changes have been made in the field that impact the “rounds checklist”, this checklist MUST be updated via the MOC used to change the equipment in the field.  I have found months of inspections done by operators who were never informed of a change who were pencil whipping their inspections.  How did we know this… the equipment had been removed, yet they were still writing down a pressure reading as if it was still in place!  Sadly, this also told us the supervisors and engineers were not reviewing the “checklist” as they had been instructed to do!

6) Facilities should conduct an engineering review to ensure that any process safety critical item on the checklist is included in the safety instrumented system (SIS) program and to ensure that the operator making the rounds is NOT the only means to identify the deviation.  In other words, we should NEVER have a scenario where the ONLY process feedback of a process safety critical item is a “rounds checklist”.  This checklist is ONLY meant to be a validation of the SIS data and not the primary means to identify the deviation.

Scroll to Top