Run to failure… Can it be done while achieving process safety?

In the past couple of months, I had several conversations with process safety professionals asking about “running equipment to failure” within a chemical process handling a highly hazardous chemical (HHC) or extremely hazardous substance (EHS). These discussions were often lively and I was actually called “a consultant” “that needed to walk a mile in my shoes”; as if I have I never fought this battle before whiling being a process safety professional in the petrochemical industry for 15 years. This is not a new battle in the process safety arena and I imagine it may never end until everyone is fundamentally on the same page with how a process should be managed. But as I sit here on my plane riding across this great nation and the memory of the recent plane crash in San Francisco, “run to failure” is CRYSTAL CLEAR right now. Here is how I see things, flying 500 mph at 36,000 ft…

Are there components within this airplane that I don’t mind failing? Sure there are… but those items are NOT mission critical to my safety objective… arriving in one piece! So yes, let me say this up front, there are components of a PSM/RMP program that may be run to failure and will NOT compromise process safety; however, much like with this airplane they are few and far between!

I was actually shocked that I got the phone calls as I actually had thought this battle had been laid to rest years ago. We have not been challenged in our work with this approach for several years and even then it was all about “staffing” rather than mechanical integrity. And that was the root of all our debates in years past… “you expect us to include every process component in our PM program???? that would take a small army to manage that”. When the discussion went to HAZARDS and RISKS the facility had little ground to argue, but Lord only knows they fought the fight like it was their last stand! Now it seems the economy is rekindling this argument, as facilities have laid off personnel and thus they are seeing an incremental increase in their past due work orders. This is driving businesses to increase their RISKS without fully understanding the HAZARDS they face.

So what can fail in this plane and still permit us to arrive safely at our destination? This has actually been defined it for us…

Flight Safety Critical Aircraft Part (FSCAP) – Any part, assembly, or installation containing a critical characteristic whose failure, malfunction or absence could cause a catastrophic failure resulting in loss or serious damage to the aircraft or an uncommanded engine shutdown resulting in an unsafe condition.

But hey, OSHA has also defined it for us as well in an LOI (1/31/08)

A process is defined in 29 CFR 1910.119(b) as any activity involving a highly hazardous chemical including any use, storage, manufacturing, handling, or the on-site movement of such chemicals, or a combination of these activities (emphasis added). In the preamble to the final rule, OSHA noted, specifically, that the standard, as written, reflects the intent of the Clean Air Act Amendments, which requires the standard to be designed to protect employees from hazards associated with accidental releases of highly hazardous chemicals in the workplace. 57 FR 6356, 6372 (February 24, 1992). As such, the proper safe functioning of all aspects of a process, whether they contain HHC or not, are important for the prevention and mitigation of catastrophic releases of HHC, due to their direct involvement in the overall functioning of the process.

As a result, it is OSHA’s position that if an employer determines that a utility system or any aspect or part of a process which does not contain an HHC but can affect or cause a release of HHC or interfere in the mitigation of the consequences of a release, then, relevant elements of PSM could apply to these aspects. OSHA’s position is that any engineering control, including utility systems, which meets the above criteria must be, at a minimum, evaluated, designed, installed, operated (training and procedures), changed, and inspected/tested/maintained4 per OSHA PSM requirements.

If an employer determines, through a PHA, that a component failure of a utility system can no longer affect or cause a release of HHC or interfere in the mitigation of the consequences of the release, then, the utility system, at that point, would no longer be considered part of the covered process. If an employer makes this determination, then, the employer must be able to proactively demonstrate why the utility system is no longer part of the covered process.

If the employer takes credit for other credible safeguards in the process, which will prevent and mitigate a release of an HHC in lieu of the subject utility system, then, they must assure that those safeguards are adequate. For example, an employer determines, through its PHA, that its electrical utility system needs to be relied upon for the safe operation of their covered process. In response, the employer determines that an uninterruptible power supply (UPS) would be a safeguard against the loss of electrical utility to the process equipment. With respect to this example, one scenario the employer would need to account for would be the need to assure that the on-site electrical distribution system, from the main power supply and the UPS, would not be compromised by an explosion or some other reason. In this case, if the electrical utility cannot function to safely operate the process because the electrical distribution system is compromised, the UPS safeguard would not be a credible safeguard for the process. Again, for aspects which do not contain HHCs, OSHA expects those other credited safeguards would, at a minimum, be evaluated, designed, installed, operated (training and procedures), changed, and inspected/tested/maintained per OSHA PSM requirements.

So this can be made VERY SIMPLE… if we have evidence from our PHA that the failure of a process component will NOT “affect or cause a release of HHC NOR interfere in the mitigation of the consequences of the release”, then, at that point, we would no longer need to consider that component part of the covered process. Yes the LOI was written to state OSHA’s position on the inclusion of “utilities” in a PSM program when an employer determines that a utility system or any aspect or part of a process which does not contain an HHC but can affect or cause a release of HHC or interfere in the mitigation of the consequences of a release, then, relevant elements of PSM could apply to these aspects.

We can look at the other way as well… any component that fails and this results in the release of the HHC, leads to the release of the HHC, or hampers the protection/mitigation systems then that component IS CRITICAL to process safety and MUST BE included in the MI program, thus NOT run to failure.

Let’s look at some real life examples to show some contrast between components.

Lighting
It would be hard to argue that lighting is not something used in the process in order to operate the process. Hence many would say they have several layers of lighting for their process safety:
1) structure lighting,
2) emergency lighting, and
3) personnel flashlights (properly rated for the hazardous atmospheres of course!).
However, would “LOSS of Lighting” be a deviation that would cause a direct release of the HHC or lead to its release? In other words, having structure lighting just makes good sense and allows personnel to work more efficiently and safely, but it is NOT directly related to process safety; although there are many that would make an argument that poor process lighting is a “human factors” issue that needs to be addressed – Just saying! But the main question we have to ask is that if we “LOOSE LIGHTING” what is the impact on process safety? Note I stated we lost lighting – NOT electric; an entirely different discussion. So ask yourself, what happens when the lights go out? From a PSM compliance perspective, do we have this deviation covered in our PHA, especially if the scenario resulted in a release? Do we have this deviation covered in our SOPs with the consequence of this deviation covered, as well as the steps to correct/avoid the deviation? I have yet to see this done for lighting; so why do most businesses state they have triple layers of protection for lighting? First I would make the argument they do NOT have 3 layers of process lighting. The structure lighting can be and has been enforced by OSHA using specific standards or the general duty clause (referencing ANSI standards). Emergency lighting is regulated by 1910.37 and is for emergency egress ONLY and should NEVER be used to operate a chemical process. The flashlights can NOT be considered a layer of protection against loss of lighting until there is some type of administrative control in place to ensure they are readily available when called for. In other words, there is a SOP that requires all personnel entering process areas to carry flashlights or there are flashlights strategically positioned throughout the process for use in the event of a loss of lighting (much like fire extinguishers, escape packs, etc.) I have yet to see either of these administrative controls implemented anywhere!

So have I made the case that lighting is a component that is needed to safely operate the process, it plays a role in mitigating emergency situations, and is all around a needed component? With this said, can we run a light bulb to failure within our process?

Piping
It would be near impossible to argue that piping integrity is not critical to process safety. Piping that is in direct contact with the HHC/EHS is an ABSOLUTE item that can NOT be run to failure and I use this example to demonstrate the varying degrees of process safety. API 570 instructs us to classify our piping based on the hazards associated with the “loss of primary containment” (LOPC). We may be able to classify our some of our lower risk piping as a Class 4; however, most of the piping in contact with our HHC/EHS will be a Class 1. API 570 requires us to put our Class 1 into a 5-year inspection frequency; certainly not a run to failure situation.

Vessels
Do I really need to make a case that we should not be running our process vessels to failure? If anyone wants to debate this RTF example, please find a new profession!

So I as I stated in the beginning, YES there are components in our process battery limits that can be run to failure. These are few, but they do exist. We MUST have strong engineering basis and documentation (via our PHAs) in order to be able to defend this practice. You can bet any inspector or investigator will be zeroing in on any failed component during an incident investigation. Lastly, let me point out one item that many may never consider running to failure, but it is more common than most realize… PEOPLE! We now know that the cockpit was alive with slow speed alarms during the approach to SF airport, yet all the pilots failed to acknowledge any of them. This plane crash is looking more and more like HUMAN FACTORS FAILURE than any mechanical failures. So “run to failure” has many faces! We need to recognize them all and ensure they are ALL properly managed within our process safety efforts.

Scroll to Top