A Process Hazard(s) Analysis is a thorough, orderly, and systematic approach for identifying, evaluating, and controlling the hazards of processes involving highly hazardous chemicals. The facility shall perform a process hazard analysis on all processes covered by EPA’s RMP rule and/or OSHA’s PSM standard. The process hazard analysis methodology selected must be appropriate to the complexity of the process and must identify, evaluate, and control the hazards involved in the process. The facility must determine and document the priority order for conducting process hazard analyses based on a rationale that includes such considerations as the extent of the process hazards, the number of potentially affected employees, the age of the process, and the operating history of the process. The process hazard analyses should be conducted as soon as possible. The facility shall use one or more of the following methods, as appropriate, to determine and evaluate the hazards of the process being analyzed:
- What-if,
- Checklist,
- What-if/checklist,
- Hazard and operability study (HAZOP),
- Failure mode and effects analysis (FMEA),
- Fault tree analysis, or
- An appropriate equivalent methodology.
Whichever method(s) are used, the process hazard analysis shall address the following:
- The hazards of the process;
- The identification of any previous incident that had a likely potential for catastrophic consequences;
- Engineering and administrative controls applicable to the hazards and their interrelationships, such as appropriate application of detection methodologies to provide early warning of releases.
- Consequences of failure of engineering and administrative controls;
- Stationary source siting;
- Human factors; and
- A qualitative evaluation of a range of the possible safety and health effects of failure of controls.
Checklists
Checklists are primarily used for processes that are covered by standards, codes, and industry practices— for example, storage tanks designed to ASME standards, ammonia handling covered by OSHA (29 CFR 1910.111), propane facilities subject to NFPA-58. Checklists are easy to use and can help familiarize new staff with the process equipment. AIChE/CCPS states that checklists are a highly cost-effective way to identify customarily recognized hazards. Checklists are dependent on the experience of the people who develop them; if the checklist is not complete, the analysis may not identify hazardous situations.
Checklists are created by taking the applicable standards and practices and using them to generate a list of questions that seek to identify any differences or deficiencies. If a checklist for a process does not exist, an experienced person must develop one based on standards, practices, and facility or equipment experience. A completed checklist usually provides “yes,” “no,” “not applicable,” and “need more information” answers to each item. A checklist analysis involves touring the process area and comparing equipment to the list.
AIChE/CCPS estimates that for a small or simple system a checklist will take 2 to 4 hours to prepare, 4 to 8 hours to evaluate the process, and 4 to 8 hours to document the results. For larger or more complex processes, a checklist will take 1 to 3 days to prepare, 3 to 5 days to evaluate, and 2 to 4 days to document.
What-If
A What-If is a brainstorming approach in which a group of people familiar with the process ask questions about possible deviations or failures. These questions may be framed as What-If, as in “What if the pump fails?” or may be expressions of more general concern, as in “I worry about contamination during unloading.” A scribe or recorder takes down all of the questions on flip charts or a computer. The questions are then divided into specific areas of investigation, usually related to consequences of interest. Each area is then addressed by one or more team members.
What-If analyses are intended to identify hazards, hazardous situations, or accident scenarios. The team of experienced people identifies accident scenarios, consequences, and existing safeguards, then suggests possible risk reduction alternatives. The method can be used to examine deviations from design, construction, modification, or operating intent. It requires a basic understanding of the process and an ability to combine possible deviations from design intent with outcomes. AIChE describes this as a powerful procedure if the staff are experienced; “otherwise, the results are likely to be incomplete.”
A What-If usually reviews the entire process, from the introduction of the chemicals to the end. The analysis may focus on particular consequences of concern. AIChE provides the following example of a What-If question: “What if the raw material is the wrong concentration?” The team would then try to determine how the process would respond: “If the concentration of acid were doubled, the reaction could not be controlled and a rapid exothermic would result.” The team might then recommend steps to prevent feeding wrong concentrations or to stop the feed if the reaction could not be controlled.
A What-If of simple systems can be done by one or two people; a more complex process requires a larger team and longer meetings. AIChE/CCPS estimates that for a small or simple system a What-If analysis will take 4 to 8 hours to prepare, 1 to 3 days to evaluate the process, and 1 to 2 days to document the results. For larger or more complex processes, a What-If will take 1 to 3 days to prepare, 4 to 7 days to evaluate, and 4 to 7 days to document.
What-If/Checklist
A What-If/Checklist combines the creative, brainstorming aspects of the What-If with the systematic approach of the Checklist. The combination of techniques can compensate for the weaknesses of each. The What-If part of the process can help the team identify hazards and accident scenarios that are beyond the experience of the team members. The checklist provides a more detailed systematic approach that can fill in gaps in the brainstorming process. The technique is generally used to identify the most common hazards that exist in a process. AIChE states that it is often the first PHA conducted on a process, with subsequent analyses using more detailed approaches.
The purpose of a What-If/Checklist is to identify hazards and the general types of accidents that could occur, evaluate qualitatively the affects of the effects, and determine whether safeguards are adequate. Usually the What-If brainstorming precedes the use of the checklist, although the order can be reversed.
The technique usually is performed by a team experienced in the design, operation, and maintenance of the process. The number of people required depends on the complexity of the process. AIChE/CCPS estimates that for a small or simple system a What If/Checklist analysis will take 6 to 12 hours to prepare, 6 to 12 hours to evaluate the process, and 4 to 8 hours to document the results. For larger or more complex processes, a WhatIf/Checklist will take 1 to 3 days to prepare, 4 to 7 days to evaluate, and 1 to 3 weeks to document.
HAZOP
The Hazard and Operability Analysis (HAZOP) was originally developed to identify both hazards and operability problems at chemical process plants, particularly for processes using technologies with which the plant was not familiar. The technique has been found to be useful for existing processes as well. A HAZOP requires an interdisciplinary team and an experienced team leader.
The purpose of a HAZOP is to review a process or operation systematically to identify whether process deviations could lead to undesirable consequences. AIChE states that the technique can be used for continuous or batch processes and can be adapted to evaluate written procedures. It can be used at any stage in the life of a process.
HAZOPs usually require a series of meetings in which, using process drawings, the team systematically evaluates the impact of deviations. The team leader uses a fixed set of guide words and applies them to process parameters at each point in the process. Guide words include “No,” “More,” “Less,” “Part of,” “As well as,” “Reverse,” and “Other than.” Process parameters considered include flow, pressure, temperature, level, composition, pH, frequency, and voltage. As the team applies the guide words to each process step, they record the deviation, with its causes, consequences, safeguards, and actions needed, or the need for more information to evaluate the deviation.
HAZOPs require more resources than simpler techniques. AIChE states that a simple process or a review with a narrow scope may be done by as few as three or four people, if they have the technical skills and experience. A large or complex process usually requires a team of five to seven people. AIChE/CCPS estimates that for a small or simple system a HAZOP analysis will take 8 to 12 hours to prepare, 1 to 3 days to evaluate the process, and 2 to 6 days to document the results. For larger or more complex processes, a HAZOP will take 2 to 4 days to prepare, 1 to 3 weeks to evaluate, and 2 to 6 weeks to document.
Failure Mode and Effects Analysis (FMEA)
A Failure Mode and Effects Analysis (FMEA) evaluates the ways in which equipment fails and the system’s response to the failure. The focus of the FMEA is on single equipment failures and system failures. An FMEA usually generates recommendations for increasing equipment reliability. FMEA does not examine human errors directly, but will consider the impact on equipment of human error. AIChE states that FMEA is “not efficient for identifying an exhaustive list of combinations of equipment failures that lead to accidents.”
An FMEA produces a qualitative, systematic list of equipment, failure modes, and effects. The analysis can easily be updated for design or system changes. The FMEA usually produces a table that, for each item of equipment, includes a description, a list of failure modes, the effects of each failure, safeguards that exist, and actions recommended to address the failure. For example, for pump operating normal, the failure modes would include fails to stop when required, stops when required to run, seal leaks or ruptures, and pump case leaks or ruptures. The effects would detail both the immediate effect and the impact on other equipment. Generally, when analyzing impacts, analysts assume that existing safeguards do not work. AIChE states that “more optimistic assumptions may be satisfactory as long as all equipment failure modes are analyzed on the same basis.”
An FMEA requires an equipment list or P&ID, knowledge of the equipment, knowledge of the system, and responses to equipment failure. AIChE states that on average, an hour is sufficient to analyze two to four pieces of equipment. AIChE/CCPS estimates that for a small or simple system an FMEA will take 2 to 6 hours to prepare, 1 to 3 days to evaluate the process, and 1 to 3 days to document the results. For larger or more complex processes, an FMEA will take 1 to 3 days to prepare, 1 to 3 weeks to evaluate, and 2 to 4 weeks to document.
Fault Tree Analysis (FTA)
A Fault Tree Analysis (FTA) is a deductive technique that focuses on a particular accident or main system failure and provides a method for determining causes of the event. The fault tree is a graphic that displays the combinations of equipment failures and human errors that can result in the accident. The FTA starts with the accident and identifies the immediate causes. Each immediate cause is examined to determine its causes until the basic causes of each are identified. AIChE states that the strength of FTA is its ability to identify combinations of basic equipment and human failures that can lead to an accident, allowing the analyst to focus preventive measures on significant basic causes. AIChE states that FTA is well suited for analyses of highly redundant systems. For systems vulnerable to single failures that can lead to accidents, FMEA or HAZOP are better techniques to use. FTA is often used when another technique has identified an accident that requires more detailed analysis. The FTA looks at component failures (malfunctions that require that the component be repaired) and faults (malfunctions that will remedy themselves once the conditions change). Failures and faults are divided into three groups: primary failures and faults occur when the equipment is operating in the environment for which it was intended; secondary failures and faults occur when the system is operating outside of intended environment; and command faults and failures are malfunctions where the equipment performed as designed but the system that commanded it malfunctioned.
An FTA requires a detailed knowledge of how the plant or system works, detailed process drawings and procedures, and knowledge of component failure modes and effects. AIChE states that FTAs need well trained and experienced analysts. Although a single analyst can develop a fault tree, input and review from others is needed.
AIChE/CCPS estimates that for a small or simple system an FTA will take 1 to 3 days to prepare, 3 to 6 days for model construction, 2 to 4 days to evaluate the process, and 3 to 5 days to document the results. For larger or more complex processes, an FTA will take 4 to 6 days to prepare, 2 to 3 weeks for model constructions, 1 to 4 weeks to evaluate, and 3 to 5 weeks to document.
Other Techniques
The RMP rule allows you to use other techniques if they are functionally equivalent. The AIChE Guidelines include descriptions of a number of other techniques including Preliminary Hazard Review, Cause-Consequence Analysis, Event Tree Analysis, and Human Reliability Analysis. You may also develop a hybrid technique that combines features of several techniques or apply more than one technique.
Selecting a PHA Technique
Table 1 is adapted from the AIChE Guidelines and indicates which techniques are appropriate for particular phases in a process design and operation.

Factors in Selecting a Technique
Type of process will affect your selection of a technique. AIChE states that most of the techniques can be used for any process, but some are better suited for certain processes than others. FMEA efficiently analyzes the hazards associated with computer and electronic systems; HAZOPs do not work as well with these. Processes or storage units designed to industry or government standards can be handled with checklists.
AIChE lists What-If, What-If/Checklist, and HAZOP as better able to handle batch processes than FTA or FMEA because the latter do not easily deal with the need to evaluate the time-dependent nature of batch operations. Analysis of multiple failure situations is best handled by FTA. Single-failure techniques, such as HAZOP and FMEA, are not normally used to handle these although they can be extended to evaluate a few simple accident situations involving more than one event.
AIChE states that when a process has operated relatively free of accidents for a long time, the potential for high consequence events is low, and if there have been few changes to invalidate the experience base, the less exhaustive techniques, such as a Checklist, can be used. When the opposite is true, the more rigorous techniques are more appropriate.
A final factor in selecting a technique is time required for various techniques. Table 2 below summarizes AIChE’s estimates of the time required for various steps. The full team is usually involved in the evaluation step; for some techniques, only the team leader and scribe are involved in the preparation and documentation steps.

Source: US EPA Region 10, 2008 Newsletter
NOTE: this source link above has tons of other material that can be very useful!!!!
