A quick look into a Risk Assessment for a Nuclear Power Plant

My newsletter this week has generated a lot of questions and feedback, both positive and negative.  Some of you thanked me for the ideas of what should be considered when looking at the design of your safeguards as it relates to the design of your process capabilities.  Most of the e-mails were surprised that we would actually design for earthquakes and tsunamis, seeing how they are “so rare”.


 

Earthquakes are actually a very common occurence, and large earthquakes that occur under deep water have a very high likelihood of setting off a tsunami.  My arguement, as offensive as it was to some, was that Japan should have considered these simultaneous since they are directly connected.  This is not like two random events occuring simutaneously, which is much more likely.

Those of you that have followed me for years, know that I am a big fan of the United Kingdom’s Health and Safety Executive (HSE).  Below is an exert from their “Safety Assessment Principles for Nuclear Facilities”.  As you can see below it is common practice to consider all naturally occuring disasters and the associated failures they may cause.  BTW…if you are intrested in learning more about risk assessments this is an EXCELLENT read.

Engineering principles: external and internal hazards

Analysis

EHA.6

Analyses should take into account simultaneous effects, common cause failure, defence in depth and consequential effects.

217 To achieve the above two principles the analysis should take into account that:

  1. certain internal or external hazards may not be independent of each other and may occur simultaneously or in a combination that it is reasonable to expect;
  2. an internal or external hazard may occur simultaneously with a facility fault, or when plant is out for maintenance;
  3. there is a significant potential for internal or external hazards to act as initiators of common cause failure, including loss of off-site power and other services;
  4. many internal and external hazards have the potential to threaten more than one level of defence in depth at once;
  5. internal hazards (eg fire) can arise as a consequence of faults internal or external to the site and should be included, therefore, in the relevant fault sequences; and
  6. the severity of the effects of the internal or external hazard experienced by the facility may be affected by facility layout, interaction, and building size and shape.

Engineering principles: external and internal hazards

Earthquakes

EHA.9

The seismology and geology of the area around the site and the geology of the site should be evaluated to derive a design basis earthquake (DBE).
220 The studies should:

  1. establish information on historical and instrumentally recorded earthquakes that have occurred in the region;
  2. be proportionate to the radiological hazard posed by the site, while covering those aspects that could affect the estimation of the seismic hazard at the site; and
  3. enable buildings, structures and plant in the nuclear facility to be designed to withstand safely the ground motions involved, if needed.
    221 An operating basis earthquake (OBE) should also be determined. No structure, system or component important to safety should be impaired by the repeated occurrence of ground motions at the OBE level. Where the appropriate response to an OBE is a facility shutdown, the facility should not be restarted until inspection has shown that it is safe to do so.
    222 In determining the effect of a seismic event on any facility, the simultaneous effect of that event on any other facility or installation in the vicinity, and on the safety of any system or service that may have a bearing on safety, should also be taken into account.

Engineering principles: external and internal hazards

Flooding

EHA.12

Nuclear facilities should withstand flooding conditions that meet the design basis event criteria.

227 The area around the site should be evaluated to determine the potential for flooding due to external hazards eg precipitation, high tides, storm surges, barometric effects, overflowing of rivers and upstream structures, coastal erosion, seiches and tsunamis.
228 The design basis flood should take account, as appropriate, of the combined effects of high tide, wind effects, wave actions, duration of the flood and flow conditions.

 

Engineering principles: heat transport systems

Coolant inventory and flow

EHT.2

Sufficient coolant inventory and flow should be provided to maintain cooling within the safety limits for operational states and design basis fault conditions.

460 The various sources of heat to be added to or removed from any system and its component parts under normal and fault conditions should be quantified, and the uncertainties estimated in each case.

461 Inherent cooling processes such as natural circulation can be taken into account in assessing the effectiveness of the heat transport system, providing they are shown to be effective in the conditions for which they are claimed.

462 In the case of liquid heat transport systems, there should be a margin against failure of the operating heat transfer regime under anticipated normal and fault conditions and procedures. The minimum value of this margin should be stated and justified with reference to the uncertainties in the data and in the calculational methods employed.

 

Safety systems

Engineering principles: safety systems

Requirement for safety systems

ESS.1

All nuclear facilities should be provided with safety systems that reduce the frequency or limit the consequences of fault sequences, and that achieve and maintain a defined safe state.

336 A reactor should be provided with safety systems that can shut it down safely in normal operating and fault conditions and maintain it in the shutdown condition. There should be a margin of reactivity that allows for systematic changes and uncertainties in nuclear characteristics, variations in plant state and other processes or mechanisms that might affect the reactivity of the core, even for the most reactive conditions of the core.

 

Engineering principles: control and instrumentation of safety-related systems

Power supplies

ESR.6

Safety-related system control and instrumentation should be operated from power supplies whose reliabilities and availabilities are consistent with the functions being performed.

367 In the cases of monitoring, warning and communication functions, the supplies should be uninterruptible.

Essential services

370 Essential services are those resources necessary to maintain the safety systems in an operational state at all times, and they may also provide supplies to safety-related systems. The services may include electricity, gas, water, compressed air, fuel and lubricants, and may need to satisfy two requirements. The first requirement is to provide a guaranteed, or non-interruptible short-term supply to ensure continuity until the long-term essential supply is established, and the second is to ensure that there is adequate capacity to supply the service until normal supplies can be restored. The following principles are additional to the safety system and safety-related instrumentation principles.

Engineering principles: essential services

Provision

EES.1

Essential services should be provided to ensure the maintenance of a safe plant state in normal operation and fault conditions.

Engineering principles: essential services

Sources external to the site

EES.2

Where a service is obtained from a source external to the nuclear site, that service should also be obtainable from a back-up source on the site.

Engineering principles: essential services

Capacity, duration, availability and reliability

EES.3

Each back-up source should have the capacity, duration, availability and reliability to meet the maximum requirements of its dependent systems.

371 It should provide that service for a sufficient period of time to allow the facility to be brought to a safe state and maintained in that state until such time as the normal supply is restored.

Scroll to Top