Over the years I have facilitated and participated in hundreds of PHAs from toxics to flammables and even some explosives (although not my thing!). And in doing so, one thing that drives me crazy is the lack of structure in how process deviations are identified and studied/analyzed. I love the HAZOP methodology and hate the What-if methodology for this very reason. But I also go crazy when I am a guest in a client’s PHA and someone else is facilitating the study and never challenges any of the “safe guards” – even when the safe guard is not documented in the PSI, SOPs or Training records. But if you want to push me over the edge, go through a scenario and assume the “alarm” will be 100% successful in avoiding/correcting the deviation; even when the facility does not have the alarm set point defined in the PSI or the specific steps included in the SOP for dealing with this “alarm”! Now I am not disparaging any of the PHA methodologies, but I am hoping to open some eyes in how we should be approaching our PHA(s), regardless of the methodology used. In this article I will sort of touch on the new PHA methodology being pushed by some state OSHA plans, but this posting is NOT trying to explain those methodologies. The basis for this post is to address Federal OSHA’s and EPA’s existing PHA requirement…
1910.119(e)(3)(iv) Consequences of failure of engineering and administrative controls
SAFTENG members may remember my 2013 article, PHAs and the consequences of engineering and administrative controls failing, this is Part II – better late than never.
When we come to a scenario such as “High Pressure” we need to think about our Safeguards in the order of:
PREVENT → PROTECT → MITIGATE
And in each one of those groupings, we need to apply our traditional hierarchy of controls:
ELIMINATION/SUBSTITUTION
↓
ENGINEERING CONTROLS
↓
ADMINISTRATIVE CONTROLS
↓
PERSONAL PROTECTIVE EQUIPMENT
SAFTENG members can see this graphically displayed @
http://www.safteng.net/index.php/free-section/safety-info-posts/chemical-process-safety-psmrmp/5192-what-does-a-hierarchy-of-hazard-controls-analysis-hca-look-like
For example, we have a pressure vessel with a MAWP of 300 psi. Our PHA scenario identifies a high-pressure event leading to an LOPC event via the RV. So we ask ourselves, what do we have in place that would PREVENT the HI PRESSURE scenario regarding engineering controls and administrative controls?
Our first layer of protection would be the local PSI gauge on the vessel. Maybe we even have a remote readout. But what if there is not an operator watching the gauge or the remote readout and the pressure continues to rise?
What would be our next line of defense (e.g., a layer of protection)? Would it be our high-pressure alarm we have on the vessel? Let’s say this alarm is set to sound at 250 psi. This alarm sounds locally at the vessel, remotely, and even on a call-out system (e.g., to phones and radios). We would also have a certified SOP that contains BOTH the consequences of deviating over 250 psi AND the steps to AVOID hitting the “safe upper limit” of 275 psi. But for the administrative layer to actually “count” as a safe guard, the SOP has to provide SPECIFIC steps in how the operator can control the pressure and thus AVOID hitting the safe UPPER LIMIT.
But what if no one responds to the alarm or the alarm fails to sound? Do we have another layer of protection? Let ‘s say we have a safety interlock that will shutdown the steam to the vessel, open the cooling water valves, and a pressure control valve will open to begin venting to a control/destruction device at 275 psi.
SPECIAL NOTE I need to make here… BOTH the alarm and the safety interlock are “safety systems” and need to be defined in the PSI and listed in the SOP, so the operator(s) understand how they interact with their activities. The safety interlock MUST BE VIEWED as a last line of defense – NOT the Relief Valve (RV), as once the RV lifts we have an LOPC event.
But what if the alarm condition(s) are not responded to AND the safety interlock fails to shutdown the process AND our SOP “steps to avoid and correct the deviations” failed to control the process? Well, our last hope to prevent us from launching this vessel is the RV(s) on the vessel which discharges to a control/destruction device (or maybe even the atmosphere/safe location).
Where a lot of studies will go off track is the assumption that the “event” will never occur “because operators watch the process like a hawk and they’re trained on how to deal with high pressure.” As noted above, OSHA (and EPA) require us to study the “consequences of the failure of engineering and administrative controls,” and we need to document these failures in our PHA report.
I prefer to do this in my “safe guard” section, by listing each layer of protection (I am NOT doing a LOPA, but rather a traditional HAZOP). It looks something like this:
| High-Pressure | LOPC event via RV leading to flammable/toxic cloud |
|
There are a lot of different ways to document your PHA, some are complaint – some fall short of compliance – and those that fall short are those that do NOT document the engineering controls and administrative controls available for EACH SPECIFIC process deviation. By this I mean, do not list “SOP/Training” as an “administrative control” if the SOP does not contain SPECIFIC PROCEDURES to follow to AVOID/CORRECT the process deviation (e.g. high pressure in that specific vessel)! And folks, these steps need to be a tad more detailed than:
Deviation: High Pressure in R-1
Steps to Avoid: Lower Pressure
Steps to Correct: Lower Pressure
And that is not a joke, “Lower Pressure” is a very popular phrase we find during our assessments, audits and investigations. And remember, “steps to avoid” are those procedural steps that we take BEFORE we exceed the SAFE UPPER LIMIT; “steps to correct” are actually emergency procedures as we have deviated outside our safe operating envelope and the next stage is our LOPC event. When we are operating OUTSIDE our defined safe operating envelope and using our “emergency operating procedures”, the steps in these emergency procedures are our attempt to CORRECT a serious process deviation! When we exhaust ALL of our “steps to correct” AND we are still in a deviated state, WE MUST VIEW this as an “out of control” process and this is a “trigger” to begin “emergency shutdown” procedures – BEFORE we have our RV lift to the atmosphere (e.g. the LOPC event)!
We should not be counting our engineering controls if they are not SPECIFICALLY LISTED AND DEFINED in our PSI or if they are NOT in an inspection/testing program. We should not be counting administrative controls that are not part of a MANAGEMENT REVIEW, AND CERTIFICATION PROCESS and/or the facility is not training on these administrative controls. In other words, DO NOT TAKE CREDIT for a safe guard that is NOT:
- engineered
- installed/implemented, and
- managed as a “safe guard.”
In a process handling an HHC/EHS. And we should be able to find all this information/documentation in our PSI, SOPs, SWP’s and Training program during the PHA.
Anyone should be able to look at a PHA and understand
- the cause(s) of the deviation,
- the consequence(s) of the deviation, and
- the safeguards in place to PREVENT, PROTECT, and MITIGATE the event and its consequences.
These safeguards should be listed out by their intent:
PREVENT the event from initiating by having engineering controls and administrative controls in place;
once the event has begun, what is in place to PROTECT assets by having engineering controls and administrative controls in place; and
once we have the LOPC event begin, what is in place to MITIGATE the consequences of the release.
