Data validation and verification without DEFINING and QUANTIFYING the process – learning the hard way

As I rant on about validating and verifying our safety data and defining and quantifying our safety processes, I wanted to share another incident where we learned the hard way.  I managed a chemical facility with many corrosives; thus, eyewashes and safety showers were important items in the mitigation layer.  And as most of us have experienced, these items had a shady history of their weekly “inspections.”  So like any respecting safety pro, I instituted an audit process of these required weekly “inspections.”  The trend of these weekly inspections was going in the right direction, and we exceeded 90% on-time inspections, which was an improvement from the 40% we started with.  But then it happened. We had an acid exposure event, and when the employee used the shower, it did not work. 

The operator then traveled to the next shower, which did not work either.  Our EW/SS stations were alarmed, so the control panel operator got the shower alarm, sounded the unit alarm, and announced the shower number over the unit PA system and the ER radio channel.  But as you can guess, when help arrived at the shower that alarmed, no one was there; the shower was activated, but no water was flowing.  Was this a false alarm of some type?  So luckily, the ERT Commander ordered a unit headcount, and sure enough, one operator was missing. He was found 10 minutes later at another EW/SS unit. 

NOTE: the alarm system was ONLY capable of receiving a single alarm.  Thus when he pulled the shower at the 2nd station, the control panel operator had not reset the system; this prevented the system from alarming again at the control panel.

In the ensuing investigation, we wanted to understand the failure of the first safety shower/eyewash station.  This unit had been “inspected” weekly for the past several months, like clockwork, based on the inspection tag data and our audit data.  But we found a serious flaw in the “inspection” process and quickly recognized why this unit had no water flow.  The water valve to the unit was closed, and we traced this closure back to 11 weeks before the accident when the EW/SS had repairs made to it.  So how could a unit be inspected weekly for 11 weeks, and no one identifies no water flow – the most critical aspect of this safety device? 

Simple, we had not DEFINED or QUANTIFIED the inspection AND TESTING process.  100% of the unit operators who had performed a weekly inspection on this unit said they were told to “ensure the unit was not obstructed and ready for use” (as was written in the safety program).  The inspection process was just that, a visual inspection of the unit to ensure it was not obstructed.  NO functional testing (e.g., water flows) was done at any frequency on any of the units across the entire plant site. 

So yes, the EW/SS stations were being “inspected” weekly, but none had ever been tested using the funnel curtain, a 5-gallon bucket, and a stopwatch, which are the tools needed to QUANTIFY and VALIDATE the performance of a EW/SS.  So a lack of DEFINING the terms “inspection” and “test” and a lack of QUANTIFYING the performance expectations of the EW/SS unit left us with audit data telling us all was well with our EW/SS stations, and nothing could have been further from the truth!

So be careful relying on simple data as an indicator when the process that intends to produce the data we are auditing has not yet been DEFINED and QUANTIFIED! 

 

 

Scroll to Top