Does the title make you scratch your head? I usually get some strange looks when working with a client who is trying to understand what the PSM compliance cycle looks like. To start with, let’s look at what OSHA/EPA requires in our operating procedures:
1910.119(f)(1)(ii) Operating limits
1910.119(f)(1)(ii)(A) Consequences of deviation
1910.119(f)(1)(ii)(B) Steps required to correct or avoid deviation
1910.119(f)(1)(iv) Safety systems and their functions
If we look at just these four requirements, we can easily use our most recent PHA and do a check to ensure that all the deviations listed in the PHA that take us outside the Safe Operating Envelope (e.g. TOO MUCH Pressure, TOO MUCH Level, etc.) are covered in the Operating Procedures. We then take a look at the safeguards listed for that deviation scenario and ensure these safeguards (e.g. a high-pressure alarm set to sound well before the set point of the PSV for TOO MUCH pressure and a relief valve as the last layer of protection) and their purpose and function are covered in the Operating Procedures.
Lastly, we have an operator who when PROPERLY trained can begin “troubleshooting” these deviations in order to correct the deviation or AVOID the deviation altogether, which is what we are striving for, to begin with. This is where we need to devise the actions we want the operator to take to try and bring the process under control.
Our PHA is just sitting there with all the process deviations that are possible, so a lot of the work has already been done. All we need to do is review the PHA scenarios that result in a deviation from the SOE and the consequence of these deviations. Then we move over to the “SafeGuard” column and we can then list these safeguards as our “safety systems” in our SOPs. The ONLY thing we have left to do is determine what we want the Operator(s) to do in order to try and correct the deviation before we EXCEED the SOE.
This takes us full circle to my “Emergency Shutdown” post a couple of weeks ago. Basically, once the operator(s) has exhausted all of the “troubleshooting” steps in their attempt to correct the deviation and the steps are UNSUCCESSFUL in this correction, this is the TRIGGER to begin “emergency shutdown procedures” or to activate an engineered shutdown system.
There is not a whole lot of wiggle room in these actions. Our wiggle room comes into play when setting our SOE. We can have a wide SOE that allows for swings in critical parameters, but the UPPER LIMIT is a HARD LIMIT and once it is exceeded, we have to act QUICKLY and in a very CONTROLLED manner to attempt to correct this deviation. Once we have exhausted all of our troubleshooting procedures (remember these are ANNUALLY certified) then we have an out of control process that needs to be shut down the safest and quickest means possible. Keeping in mind that some of your troubleshooting attempts will be TIME DEPENDENT – meaning that in the SOP, it needs to be spelled out that the operator has X amount of time to complete these tasks. If the operator is unable to complete the tasks within the time period prescribed in the SOP then shutdown begins at the expiration of the time period and NOT after the last step is completed. An example of a situation where this may come into play…inclement weather. The operator has to travel some distance outside to close a valve then back to another area to open another valve then back to a PI gauge to see if pressure is dropping. Under normal weather, this is not a problem. With 12″ of snow and ice on the ground and their travel times may be considerably longer. Another deviation to consider is that the SOP troubleshooting guide is set up for two field operators and one-panel operator, but at lunchtime, there is only one field operator and this is when the deviation occurs. The sole field operator may not be able to complete all the required steps within the time frame and thus they would end up shutting down the process before all the steps are completed.
Not all troubleshooting will be time-dependent, but they will ALL have the UPPER-LEVEL trigger. Our time to respond is when we have exceeded our process upper level, which is BELOW the SAFE UPPER level. Depending on the time we have between these two parameters, we have to be reasonable in our expectations of our operators. We have seen some shut down procedures that when we actually “walked them down” with an operator it became clear that it would be an impossible feat for three operators, much less one!
Hope this makes sense.
