PHAs and the consequences of engineering and administrative controls failing

“Now there’s something you don’t see every day” is the quote I will never forget when the OSHA CSHO began looking over the PHA. When we asked what sparked his comment, he showed us…

Both PSM and RMP standards require that the Process Hazards Analysis consider the “consequences of a failure of engineering and administrative controls”.

1910.119(e)(3)(iv) Consequences of failure of engineering and administrative controls

However, we do come across some PHA’s that take WAY TOO MUCH for granted and do not consider the consequences of engineering and administrative controls failing. This usually manifest itself from an unqualified facilitator leading the analysis and usually looks something like this…

Studying the deviation “NO FLOW” has several causes and MANY of these have undesired consequences. However, an untrained facilitator will fall into the trap that “NO FLOW” may only result in “loss of production” or “production issues only” and not consider the consequences of “Loss of Primary Containment” (LOPC) as being a serious release of the HHC/EHS. It is WAY TOO EASY for a team to say that “NO FLOW” of the HHC/EHS just means we have no product flowing and not consider the product is actually flowing, just not to where it is intended to be flowing (e.g. onto the ground!). So in the PHA it states “NO FLOW” results in “N/A” (not applicable). This will certainly get the attention of someone knowledgeable in PHA methodologies!

These days, so many PHAs quantify the risk(s) with each scenario that it is rare not to see the consideration of-of engineering and administrative controls failing. EACH deviation, along with EACH cause, should list the consequences WITHOUT considering any of the engineering controls or administrative controls. In other words, ALWAYS ASSUME that the tank can be overfilled and consider those consequences; NEVER assume that the safeguards will always work and that operators do exactly as required of them. The analysis should walk us through the safeguards we have in place to PREVENT, PROTECT, and MITIGATE and we can take credit for those items that we OFFICIALLY have in place (proper design, installation, operation, training, and maintenance). For example:

TOO MUCH LEVEL in Tank 101 is the deviation (i.e. overflow the tank).
Consequences could look something like this: Operator Exposure/Injury, Fire/Explosion, Off-site impact.
Safe Guards: Hi Level Alarm; Hi-Hi Interlock; Tank Dike; Area is a Class I Div. 2 area; Unloading SOP and tank level indicators; Area requires FRCs

Merely resting on our laurels and stating that all of these safeguards will work as designed is just setting us up for a major awakening!!!! We can take “credit” for these controls in REDUCING our risks, we just can not say it will NEVER happen… we MUST consider the consequences of our engineering and administrative controls failing.

 

Scroll to Top