This regulatory requirement is often mismanaged, which oftentimes results in many other related issues within a process safety management system. In this article, I will discuss a methodology a facility can apply in establishing its “safe upper and lower limits.” In this example, I will use process pressure, as it is the easiest to illustrate, but this same methodology can be applied to establishing safe upper and lower limits for all critical process parameters.
OSHA Process Safety Management and EPA’s Risk Management Plan require the employer to establish Safe Upper and Lower Limits for items such as temperatures, pressures, flows, compositions, levels, pH, viscosity, purity, etc. We must establish a safe upper and lower limit for ALL CRITICAL process parameters. Although OSHA/EPA does not explicitly mention parameters such as level, pH, viscosity, and purity, if a deviation in these process parameters can lead to a process upset, they become a CRITICAL PARAMETER. Thus, we must establish a safe upper and lower limit for them.
Too often, facilities establish their safe upper limit for pressure(s) by using the Maximum Allowed Working Pressure (MAWP) of their vessel(s). Then, to compound this mistake, they have their pressure safety valves (PSV) set at the same pressure as the MAWP. The object of establishing a Safe Upper Limit is to ensure that the highly hazardous chemical (HHC) does not escape the process due to an operational error. The PSV set point at the MAWP and the safe upper limit set at this same pressure do not allow operator intervention to correct the deviation to prevent the release of an HHC.
I was raised to call this range a “safe operating envelope” (SOE); there are other names, but I will use the term SOE for this article. As long as the operator maintains the process within the SOE, the process is in “NORMAL OPERATION.” The high end of the SOE is the safe upper limit, and the low end is the safe lower limit. Let’s look at the safe upper limit and how we would set this on a pressure vessel, considering that the lower safe limit may be as critical as the upper safe limit.
My vessel has an MAWP of 300 psi. It vents to some safety system (e.g., diffuser tank, flare, scrubber, etc.) through a header system. Because of this, the relief system design basis has to be such that back pressure on other relief devices on the header system is not compromised. This usually will result in some safety factor of, let’s say, 10% between the MAWP and the PSV set point. This means our PSV set point will not be 300 psi but 270 psi. Yet still, we do not just want to establish our SOE at 270 psi. In reviewing process parameters, we see that 99% of the time, the process operates at 120 psi. We also see that during start-up, the pressure rises to 160-165 psi for a short time, but as the process levels out, the pressure falls back to 120 psi. So 120 psi seems to be the operational norm, but we do not want to set our safe upper limit at our operational norm as this leaves the operators no “wiggle room” in controlling a process.
The next thing I would like to do is to check with the Quality Control department and ask if there is a critical pressure that would cause QC issues. If there is, then this set point needs to be considered, as we would not want a safe upper limit that would cause a quality issue. We may be safe, but we would be out of business before too long with a process that produces out-of-spec products!
The next step is to review how fast the pressure can increase from 120 psi (the operational norm) to 270 psi (PSV set point). This effort ensures that we set the safe upper limit far enough below the PSV set point to allow an operator ample time to correct the pressure deviation. Let’s say that in the increased pressure scenario, the operator needs at least 5 minutes to take the necessary actions to control the pressure, and the pressure rise can be at a rate of 1.0 psi per minute; we would NOT want to set our safe upper limit at 265 psi as this would NOT leave ample time for the operator to intervene before the PSV lifted at 270 psi.
So now we are at least 265 psi as our safe upper limit. Often, we want to establish some safety margins with this methodology. So, my next step is to ask the operational team what would happen if we set our safe upper limit at 175 psi. Where did 175 psi come from???? Thin air; I just threw it out as a starting point for the operational team to consider. If they say 175 psi OK, then I begin to push the envelope LOWER. How about 165 psi? At this set point, some operators state that during start-ups during the summer months, the start-up pressure can hit 165 psi; we know why this occurs in the summer months, and we also know that it is well within the established design intent of the process. So, by default, I have just established my safe upper limit… 170 psi. Everyone agrees that if the process pressure rises to 170 psi, something is WRONG, and operators MUST TAKE IMMEDIATE action. So, with this in mind, it makes sense that we need an alarm to notify operators that their process has deviated from the established SOE. We will also use this established safe upper limit in our operating procedures, including the actions to be taken when this process deviation occurs.
In our operating procedures, we will establish a “trigger” for when the EMERGENCY SHUTDOWN procedure or system will be activated. Along the same lines of thinking, we do NOT wait for the PSV to lift before initiating our emergency shutdown procedures. We see all too often that the emergency shutdown procedure trigger is a release of the HHC! If we have a release of our HHC, we have FAILED in a SERIOUS way. So let’s look at what this “trigger” would look like… understanding that this trigger will also be the PSV set point BELOW.
So we have a PSV set at 270 psi and an established safe upper limit of 170 psi – needless to say, our trigger pressure will be somewhere between these two pressures. I like to determine how long it will take an operator to complete ALL the troubleshooting steps in the annually certified operating procedure that are intended to correct the deviation when the process exceeds 170 psi (SOE). If it takes him/her 15 minutes to complete the steps, I will normally double the time for my safety margin to 30 minutes (considering inclement weather, staffing issues, etc.). This establishes TWO MEASURABLE CRITICAL PARAMETERS for emergency shutdown activation: 1) Time and 2) Pressure. We should ALWAYS, and I mean ALWAYS, use the trigger that if the operator completes all of their “troubleshooting” steps prescribed in the annually certified operating procedure AND the process is still outside the SOE, we INITIATE the EMERGENCY SHUTDOWN PROCEDURE. This is based on the premise that we have an “out of control” process, which MUST be brought to a safe state – even if our process pressure is well below the PSV set point!!! Do NOT, and I mean NEVER EVER, allow freelancing by anyone (i.e., operators, supervisors, engineers, managers)! Any additional actions that are not prescribed in the annually certified operating procedure MUST go through the EMERGENCY MOC process before being taken!!!! So this takes care of the “time” parameter for the most part, but what if, for whatever reason, the operator can not complete all the troubleshooting steps within the established time limits or the pressure rise rate is faster than anticipated? There may be times when the rate of rise is too fast, and the process pressure would lift the PSV before the operator has ample time to complete his/her troubleshooting tasks. This means we need to have a set trigger pressure that I call the “point of no return.” This set pressure would be our set point for our automatic shutdown systems. In the scenario we have been using, I would most likely set mine somewhere between 225-250 psi. This is, of course, assuming that the pressure rise would cease immediately when these emergency shutdown systems activate. If the pressure rise continues to increase after the activation of the emergency shutdown systems, then we would need to incorporate some buffer to ensure that we would not reach the PSV set point; this means we may have to lower the set point of our emergency shutdown system activation.
As you can see in this article, we NEVER set our safe upper limit at or near our PSV set point. PSV(s) are truly a LAST LINE of DEFENSE to prevent a catastrophic vessel failure. If we have an incident where we have activated our last line of defense, we have had a VERY SERIOUS incident. Our actions must be designed to ensure that we NEVER reach the point where a pressure relief device activates, even when we have another layer of protection such as a diffuser tank, flare or scrubber. All of our actions and safety systems MUST BE designed to ensure we never reach this point. I continually get the argument that our process parameters are much tighter than the example I laid out in this article. For example, a process has a normal operating pressure of 250 psi instead of the 120 psi I used. With all the process parameters remaining equal, I would argue that the DESIGN of the process is INADEQUATE. If we have a process with a normal operating pressure of 250 psi, we would need a process vessel rated higher than the 300 psi used in the example. A normal process pressure of 250 psi and a MAWP of 300 psi is just WAY TOO TIGHT of a design parameter. It would indicate a process design issue (e.g., the process does not meet a Recognized and Generally Accepted Good Engineering Practice – 1910.119(d)(3)(ii).
I hope this provides insight to those struggling to establish safe upper and lower limits. Remember, we can use this same methodology for all of our critical parameters. If your safe upper and lower limits were improperly set in the beginning, using the MAWP of the vessels, it might be wise to revisit your PHA after you have completed this exercise. You may be surprised at what was accepted as “safe” in previous PHAs.
