Can I count the activation of my safety system as an actual test of the system?

My hi level interlock just tripped on my vessel – can I count this trip as the scheduled quarterly/annual PM test?  This question is maybe in the top 10 questions we get from PSM/RMP clients and friends and without a doubt one of the top 5 MI questions of all time.   There is no argument to the logic that we just tested our safety system and it worked; but from a process safety engineering aspect there are many issues with taking this simplified approach to such a critical element of process safety.  In this article I will explain how we should NOT be counting this activation as a scheduled PM, but also the other activities that MUST TAKE PLACE to ensure process safety, as well as compliance with PSM/RMP when a safety system is activated.

I can not argue with the logic that your process deviation is a validation that your high level interlock worked as we hoped it would, but what we may not know right off hand is “did it work as designed”? Usually when a hi-level interlock is tripped, the personnel operating the system/process are not walking to all of the visual alarm stations and verifying that all the alarm lights were responsive to the activation of the hi-level switch, nor are they going to verify how the flow into the vessel was actually stopped. In our Process Safety Information (PSI), for those falling under PSM and RMP, we have to define our safety systems and this high level interlock would be a “safety system”.  In our safety system documentation we need to include the set point(s) and the actions taken by the safety system. So just knowing that the interlock shutdown a pump may not be a full “test” of the system per our chosen RAGAGEP and inspection/testing procedure.

YES, we know the flow stopped into the vessel, but we may not know if BOTH the inlet valve closed and/or the pump shutdown to stop the flow.  After all, how do we know the truck/railcar just did not go empty and that is why the flow stopped or maybe the pump just stopped working due to a safety switch in it for loss of flow.  In most cases, we will most likely not take the time to verify the remote visual alarms were activated as called for in the safety system’s definition. For those who have a “call-out system”, we should be able to determine that the call-out system worked, sent the correct message and did so within the time frame necessary. We will need to DOCUMENT all of this in our work-order preventive maintenance system for the actual trip to count towards our PM schedule, as we may need to REVISE the frequency of the next inspection – or just leave the schedule as is and do multiple inspection/test on the system within the originally prescribed time frame. 

We should SERIOUSLY consider this “process deviation” as a “Process Safety Incident” (e.g. PSM nearmiss) and investigate the deviation using our PSM/RMP Incident Investigation procedure to determine what failed in the system so that the operator(s) was not alerted to the rising level in the system such that he/she could intervene in a timely manner to correct/avoid this deviation. Many process safety professionals (me included) will view the hi-level interlock as a “last-line-of-defense” and the activation of this safety system would be considered as a very serious deviation/incident, even though it worked as we had hoped it would and prevented a release of the HHC/EHS.  We really need to know why our systems (i.e. layers of protection) in-line before this high level interlock failed to alert us and control the rising level in the vessel.  

Was it an operator issue?  

Did systems intended to respond before this last-line-of-defense respond properly?  

Is there a design flaw in our safety system for high-level?  

Is operator work load an issue that prevented ample response time by the operator(s)?  

Is there an issue with the operating procedure?  

Are the systems in-line before this last-line-of-defense not getting PM’ed as needed?  

Something failed and we MUST identify the failures in order for us not to SOLELY rely on this last-line-of-defense again.

Lastly, let us not forget that our inspection/testing of this hi-level interlock must follow a RAGAGEP of our choosing (1910.119(j)(4)(ii).  So if we just count the actual trip as our scheduled PM and do not fully test the entire safety system as prescribed within our RAGAGEP, maintenance procedure, and PSI safety system definition we are opening ourselves up to compliance issues at the very least.  Please do not forget that ALL inspections/tests must also meet 1910.119(j)(4)(iv)… 

The employer shall document each inspection and test that has been performed on process equipment. The documentation shall identify the date of the inspection or test, the name of the person who performed the inspection or test, the serial number or other identifier of the equipment on which the inspection or test was performed, a description of the inspection or test performed, and the results of the inspection or test.

I would personally challenge the practice of counting this “trip” as some form of inspection/testing and would ask the facility to show me in their chosen RAGAGEP how this actual trip is meeting the inspection/testing protocol(s) in their RAGAGEP.  I have yet to read any RAGAGEP that explicitly allows this type of thinking/rational towards inspection and testing.  We should be viewing this activation as SERIOUS incident and not be looking to take advantage of it as a scheduled PM!  There are processes out there that are routinely tripping safety systems because their process is taxed to it’s limit or personnel/management are routinely making conscious decisions to exceed the safe limits of the process.  And someone having the mind set that they can just count all these trips as their MI inspection and testing is certainly outside the scope of even the most basic process safety methodology and just scares the hell out of me! Multiple and frequent trips (more than 1 per year) would point to a design and/or load problem which would take us all the way back to the PHA and the design of the process (1910.119(d)(3)(ii) and in NO WAY should be merely counted as a PM task.  I know, everyone is saying I am taking this to an extreme – but ask the question amongst yourselves and see who on your team would feel comfortable taking this approach; you may be very surprised at what is going on within your PSM/RMP management programs.

Just some thing’s to consider if we count actual trips of our safety systems as our scheduled PM inspection/testing.

Scroll to Top