I had an interesting dissertation given to me on how to calculate “frequency” when analyzing a PHA scenario during a recent PHA. Although it sounded logical, it was completely off base and thus would have shown the facility at very low risk for all their scenarios. This is something we see from time to time so I thought I would provide my two cents on the matter.
1) PHA participants should NOT consider their personal methods of doing a task. It is difficult for all of us to view ourselves doing something “unsafe”, especially if we have been doing a task a certain way for decades and have NEVER experienced any negative feedback (e.g. accident). Participants need to view the scenario as a possibility then assign a “frequency” to the scenario. Here is the sticking point: if the scenario involves a human task, then the frequency should be based on the “frequency” of the task and NOT the frequency of the undesired consequences. If the team is studying a scenario that involves taking a caustic sample 3X per 8-hour shift, then the frequency should reflect this and not something like 1 in 100 years. Operators and maintenance personnel are very likely to say “that will never happen” because they can not see it happening to them. I like to use the “hit by the bus” scenario…if they were to get hit by a bus and were no longer available to do the job and the plant hired someone else to do it, what does this new person have in place to ensure they do it right. Hence we come back to a detailed SOP and Training program.
2) When considering safeguards in your scenario, MAKE CERTAIN they are in place and PROPERLY managed. In other words, we do not allow facilities to claim their instrumentation and interlocks if the equipment is not actually in the MI program and has never been inspected or tested. We do not allow “training” to be included if the task is not specifically trained on at least every three years. We do not allow SOPs to be included unless the facility actually has a specific SOP to cover the task, the deviation, the steps to correct or avoid, and the SOP is annually reviewed and certified. These actions would actually be recommendations for the scenario and not safeguards.
3) Chemical Process Safety can be explained in three stages: 1) Prevention, 2) Protection, and 3) Mitigation. In other words, we should be looking for ways to PREVENT the scenario from occurring, then look for ways to PROTECT assets once the event has been initiated, and thirdly we look for ways to MITIGATE the consequences stemming from the scenario. One of my projects the last couple of years is trying to figure out a weighing scale where more credit would be given to PREVENTION than PROTECTION and more for PROTECTION than for MITIGATION. This would drive facilities toward PREVENTING the activation of an event and less on protective and mitigating measures.
We see on occasion a PHA where the participants had figured out the more safeguards they listed, they lessened their overall risks, thus having no high-risk scenarios. This is a RED flag for any auditor, especially when the process involves 55 and 90-ton railcars of Chlorine. The team listed items such as “county hazmat teams and level A suits” as safeguards and this manipulated their overall risks to an acceptable level. When done properly, their risk was off the charts. We need to consider the way EPA allowed us to look at our WCS and ACS with regard to safeguards. We can count “passive” devices that require NO human interaction or power in our WCS. Then again, these passive safeguards MUST BE in the MI program and undergoing inspection and testing to assure they will function PROPERLY when called upon. If a team wants to use an interlock as a safeguard to prevent something like overfilling, then the entire interlock system, including the visual and audible alarms MUST be inspected and tested at the manufacturers’ recommended frequency or more often if process conditions dictate.
