Document g2zZRpbdR0yGXjg6jvyEXpw63

Management Approach to Safetyand Hazard Analyst CIRCULATE Qmene Barr Blades Bullock 'DutchakEddinger Handwerk Ikeda 'J0rmsby(.^5^) Repa Santay Swffc+r Thirion Wagaman by F.G. Joyce M.H. Vogel to selected customers of Air Products South iPTT) Limited at a Symposium held at . _ South Africa Tuesday, 2nd February, 1982 b.y lpotto AP000I7235 INDEX Page Introduction The Importance of Safety in Management.............................................. . 1 Air Product* Capabilities................................................................................. 1 Safety as a Management Objective................................................................. General fundamentals for Successful Safety Programme.................... 1 2 How we Measure Safety Progress and Performance................... ................... 3 Background to the introduction of Process Hazards Analysis...................... Hazards Identification.................................................................................... 5 6 Hazards Analysis............................................................................................. 8 Risk Criteria................................................... *................................. --........ . 8 Failure Rate Data................... ................. .................................................... 14 Conclusion APOOOI7236 INTRODUCTION We have called this Symposium address "Air Products' Management Approach to Safety and Hazard Analysis." We will tell you how we promote and manage safety worldwide and how we assess and evaluate possible hazards in our industry. We wish to acknowledge the helpful assistance received from our colleagues in Air Products during the preparation of this paper. APOOOI7237 ' 1 yv. importance of Safety in Management Management hat the responsibility for ensuring that Deduction operations are inherently safe or are adeaustely controlled against inadvertent mis-operation. its responsibility is to control work * both its human and physical elements - and accidents are caused by failure to control; they are not, at is often believed, the result of straightforward failures of technology; social, organisational and technical problems interact to produce them. Management must be sure that personnel will not be exposed to hazards which they are unaware of or are [ unable to control. Ideally, all hazards will be identl* f fied during the decision and building stages of a | process and appropriate controls will have been [ incorporated into the process prior to its startup. | However, new hazards may be introduced in response f to attempts to improve the efficiency or versatility of a process. Applied research and maintenance of a large complex process may introduce previously unrecognised process hazards. Complex technology demands high technical compet| ence in controlling risk, but even the highest techni: cal competence will not on its own ensure a consls1 tently safe place of work. There is a great deal more 1 to safety at work than providing the right physical i safeguards. There is the whole question of effective L and imaginative organisation for safety. I This point was sharply brought out in discussions and [ enquiries which followed the Three Mile island l nuclear incident in the U.S.A. Popular discussions of nuclear power plants tend to concentrate on questions of equipment safety but as the evidence accumulated it became clear that the fundamental problems were 'people-related problems' and not equipment prob lems. This example is not given to show the possible short comings of the nuclear energy industry in the U.S.A. but to point out that even in industries where the physical safeguards must be complex and sophis ticated, there is an overriding need for a safety organ[ isation which takes into account the way human [. beings actually behave in the situation in which the advanced technology places them.. Studies by the U.K. Accident Prevention Advisory Unit have shown that only a minority of fatal accidents in, for example, the steel industry are the results of the primary steelmaking process, the majority are associated with activities, such as hand ling and transportation, which are common to indus try in general. Some of the most recent industrial catastrophes have in die final analysis been found to be unrelated to the fundamental technology of the industry concerned. The primary cause of the incidents have been attrib uted to failure to follow established procedures, breakdown In craft skills, failure to work to approved or recognised design standards, or Introducing^esign changes without subjecting the proposed change to a thorough hazard review. Air Products Capabilities Air Products & Chemicals Incorporated today, found ed in 1940, is a S 1.6 billion multinational Company with 16,000 employees worldwide. In addition to these are about 5,000 temporary employees in our engineering and construction subsidiary, most of whom are construction workers employed locally for a relatively few months during a construction project. In addition to the design and construction of process plants and equipment, we operate industrial gas plants at more than 200 locations and chemical plants at 10 locations. Our plant operations extend to Canada, U.S.A. and South America, the Continent of Europe including the U.K., Belgium, France, Germany Holland, also South Africa and Korea - the list is not all Inclusive. We are therefore a truly international company and experienced in dealing with people of all nationalities, their laws, customs and governmen tal requirements. Our safety programmes are directed to our worldwide team of employees. We operate a fleet of 700 cryogenic liquid road tankers which haul liquid nitrogen, liquid oxygen, liquid hydrogen and liquid argon to 6,000 customers where the cryogenic liquid is stored in vacuum-insulated storage tanks of 500 to 20,000 gallons capacity on the customers premises. In our chemical operations we operate high temperature reformers, high pressure ammonia and methanol synthesis reactors, large high-pressure poly merisation reactors and toluene nitration facilities At our plant sites we store huge quantities of hazardous materials such as liquid oxygen, liquid ammonia, toluene and many others. Our safety problems are complex and technology intensive. We face the constant threat that oxygen in the liquid state or in the gaseous state at high pressure might ignite and burn the metal in the tank, or piping that contains it, or in the compressor which is compressing it. Over the years we have learned much of the art and science of avoiding ignition in metal oxygen systems but we just do not have the luxury of being able to keep the metal arid the oxygen separated. Safety as a Management Objective In Air Products we accept that safety is a manage ment function and the managers safety objectives need to be defined. The Chief Executive of our Corporation has the over all responsibility for the safety of Air Products employees and for the impact of its operations on our customers, people, plant, premises and the environ ment. He demands the highest performance, rewards superior performance and refuses to accept med iocrity. APOOOf 72J8 2 Managers are accountable in production and budge tary terms and are therefore accountable for safety performance in precisely the same manner. Achieve ment of safety goals is as rewarding as the achieve ment of sales and net income targets, production targets or any other business objective. We consider that the distribution and effective use of knowledge is a major management contribution to safety. We endeavour to pursue this course in Air Products. Our philosophy is based on four simple principles and they are: All injuries are preventable: Safety is a line-management responsibility: Safety is a condition of employment: Management Is responsible for the safety of its employees. To be a leading company in industrial safety requires a total commitment of the entire organisation to safe designs, and intense design reviews, to safe operation and intense operations reviews, to safety training, motivation and discipline, to putting safety first no shortcuts, no deviations from the first class way. It requires establishing a system of many checks and balances. It requires diligent investigation of all acci dents and near misses, with no tolerance of cover-ups. People do not easily accommodate to these disciplines - they require the strongest kind of leadership from the top. General Fundamentals for Successful Safety Programme The need to specify goals and have policy objectives and action plans is a fundamental requirement for a successful safety programme. The following may be regarded as the minimum standards: 1. Safety Policy The preparation in writing and up-dating as necessary of a basic safety policy statement by the Chief Executive which should be commun icated to all Managers and Employees and which emphasises: a) The commitment of Senior Management to injury reduction and acceptance of account ability. b) That safety performance is a line manage ment responsibility and can be managed, reviewed and monitored in the same way as other business functions by setting object ives and planning to meet these objectives. c) That all injuries are preventable. d) That alt accidents, near misses and dang erous occurrences can be regarded as symp toms of management failure and should b investigated. e) That production pressures and profits mus not compromise the basic responsibility fc safety. 2. Safety Goals Setting worthwhile and understandable goals fc safety at varying levels within an organisatior The strategic goals can be set by the manage ment and the successive operating levels ca identify and promulgate their own aims withi an overall strategy. ^ Generalised goals are not satisfactory. The should be graded as appropriate to meet th need and developed from experience. 3. Management Commitment & Example Management must demonstrate their continue), commitment to safety by sympathetic involve ment and encouragement, and showing concer end sensitivity to injury. They must obtain b motivation the commitment of all the emplo*1 ees. They must convince each person to accep responsibility for safety insofar as they contre it or need to contribute to group performano 4. Accident Reporting and Investigation All accidents, near misses and dangerous occu rencss to be reported and investigated. Lit* management to recognise the importance c a) Establishing accident reporting and inves igation procedures, * b) Ensure that accidents and near misses at reported immediately. c) Showing concern and responding rapidt d) Quick implementation of corrective actio e) Internal and external publication as ne essary to avoid repetition. 5. Analyse Safety Performance Review and analyse the last five years of ac< dent records to establish major problem are which may be either operational, behavioural technical. Use results to decide priority f action. 6. Safety Committees Establish the following committees: a) Executive Management Safety Policy Co' mittee. AP00017239 3 i dang* s symp* 3uld be ts must lity for oals for isation. -nanage-eta can ; within . They eet the tinuous involveconcern >tain by employ3 accept control rmance. bi Division or Group Safety Committee as appropriate. c) A Safety Committee at each Company location (senior member to be chairman). 7. Working Rules Establish for each Company location a set of working rules outlining the basic standards with which employees must comply, e.g. Housekeeping No smoking areas Safety control procedures Use of protective clothing and equipment Code of personal conduct Emergency plan. 8. First Aid Encourage operatives to qualify in first aid. Evidence exists that the higher the number of first aiders in worker groups the lower the accident rate. 9. Safety Audits Establish procedures for regular audits of Comp any locations by line management. Audits may be conducted to monitor one or more of the following: a) Behaviour of personnel regarding comp liance with safety rules. s occurd. Line ance of: d invest- b) Training needs. c)' Compliance with statutory regulations and company standards. d) Opportunity for injury i.e. general hazards. isses are e) Hazards of process equipment for either new or existing facilities. rapidly. 3 action, as nec- . of acciam areas ioural or jrity for icy Com Management when visiting locations should hold 'safety walk' with Manager and Supervisors. 10. Performance Measurement Establish programme for measuring performance of individuals. The setting of individual perfor mance standards and the regular monitoring and evaluation of progress. Appropriate approval or disapproval of the standard of safety achieved at the workplace should be made. 11. Performance Recognition Management to recognise good safety perfor mance by groups or individuals in the form of awards which should be of a non-monetary variety. Participate in all established award prog rammes. 12. Action Plans Houelnn action nlan< and ohlectives on both an longer term objectives for statistical injury per formance, to be monitored frequently and rev iewed each year. 13. Safety Information Ensure that adequate Information on safety matters is available to employees in the form of safety manuals, safety bulletins, data sheets, etc. 14. Training Comprehensive training programmes should be in a form to ensure that employees are instruc ted and informed how to carry out their job properly and safely. Refresher courses and a requalification of certain trade skills essential in maintaining high stan dards. 15. Safety Organisation Safety is primarily the responsibility of manage ment and cannot be delegated. There is a need for specialists to provide advice on specific topics and general strategy. 16.. Emergency Procedures Each Company location should have well con ceived and adequate procedures to deal with emergencies such as: -- Fire -- Explosion -- Major releases of potentially harmful sub stances -- Threat of harm or damage, sabotage, etc. 17. Progress Reports Senior management should arrange to receive regular progress reports on safety programmes .and action plans and encourage employees to seek management involvement in major issues on Safety and Health. 18. Maintenance Maintenance procedures to be subject to central review and direction of its scope and frequency. 19. Compliance with Statutory Regulations Ensure compliance with the statutory regulations and that these and our Company standards are widely accepted and applied as good working practices. How to Measure Safety Progress and Performance Air Products aims to be recognised as a safe company by its employees, by the public at large and by industry. We seek to be among the leaders in safety and to be on par with the top two or three world wide corporations in the area of lost time accident frequency, recordable injury frequency and injury AP00017240 4 of disabling injury and of fatalities. We believe that the statistical results truly reflect performance and we set statistical goals for worker groups both for the short and long term. We have made considerable progress worldwide to* wards this statistical goal in the last five years. We have seen e parallel reduction in our product liability costs and in our costs due to damage to plant and equipment. We have seen better morale, improved productivity and higher product quality. We remain convinced that a first-class approach to safety man agement Is a necessary ingredient of a first-class management system. We have still some way to go to match the best, but we are worldwide totally dedi cated to getting there. The first of the following charts illustrates the prog ress made in statistical terms within our Worldwide Corporation. During the period 1975 to 1981 (Fig.1.) there has been an overall fourfold improvement in the Corporation's performance. The improvement in per formance by some sections of the Corporation has been extremely dramatic. We, as a Corporation, find it beneficial to compare our performance and progress with that of Du Pont and Union Carbide, (Fig.2.) both multinational companies recognised as leaders in all fields of industrial and worker safety. In Fig.2. the average performance of the Chemical Manufacturing Association of America is also included. Air Products in Europe is a member of an industrial gas manufact urers association and In Fig.3. our European perform ance is compared with the average for the European gas industry. White Air Products in Europe is not the leading group in the Corporation on performance, we have seen a twelve-fold improvement in our safety performance during the past six years. Fig. 1. AIR PRODUCTS WORLDWIDE LOST TIME INCIDENCE RATE Fig. 2. U.S. CHEMICAL INDUSTRY LOSTTIME INCIDENCE RATE Noc CMA - CHEMICAL MANUFACTURING ASSOCIATION OF III Fig. 3. AIRPftODUCTICUROPf APOOO17241 5 Background to the introduction of Process Hazards Analysis During the last ten years, the chemical industry has been involved in explosions unprecedented in industrial history. As chemical facilities become larger and technically more complicated, our risks become larger snd our safety margin less secure. Air Products, and much of the chemical industry, turned toward the same sound technological base which was responsible for the industry's growth for the answers to the safety and loss prevention problem. The result has been the development of the philosophies and metho dologies of process hazards analysis. It is through comprehensive, detailed reviews of process operating conditions and Instructions that we may assure our selves that our facilities pose a minimal hazard to our employees, our neighbours (third parties) and our capital. It is our intent to provide our employees with this technology to properly exercise their safety respon sibility. Ail employees whether in design, construc tion, or operation of a facility are responsible for the safety of their area of responsibility. Explosions, energy releases, fires, vessel ruptures are all terms which we read in the various engineering journals every week, and feel fortunate that it wasn't our plant or our design. The Flixborough caprolactam plant explosion is the accident we all remember when the term explosion is used. This incident resulted in twenty-eight people killed, thirty-six injured and over 3 150 million dollars in property damage. The effects of the shock wave were felt eight miles from the facility. The explosive force was equivalent to fifteen tons of TNT. jt *4 C3tt*AMfc* This particular incident resulted from a failure to properly review a design change In the field. Sure, a pipe collapsed and released fifty (50) tons of cyclo hexane; but the real cause was that the man who made the change did not think it through; he did not review the safety of his work. In 1963, a hot oil-water emulsion broke in a slop oil tank in the Shell Nederiands refinery in Pernis, The Netherlands. The world's second largest refinery suffered over 3 28MM of damage over thirty (30) acres of the refinery. Improper review of the compstability of materials was the culprit here. Are we always sure of the reactivity of the materials we combine in vent headers or sumps or recycle systems? Ar-d Sometimes even the fluids we run through heat exchangers can cause problems. In Dow Chemicals' Plaquemine, Louisiana facility, a leak between the shell and tubes of a heat exchanger allowed air into the heat transfer system. This time a four-hour fire cost Dow SI 2,000,000 Mechanical failure is not a necessary part of an accident; sometimes we just place too much faith in our own engineering. The controls are foolproof) The process is the bestl The operators can handle any thing! Have we really examined ail the environmental factors, all the numerous assumptions we make? In Tokuyama, Japan, Idemitsu Chemical had an interrup tion in their instrument air system; it cost them their ethylene plant. The fire which followed the exo thermic reaction caused 314.8MM in damage. Air Products has not been immune to such incidents. The inoperability of a single check valve after a leak occurred in a heat exchanger resulted in a 3 1,000,000 loss at our Escambia nitric-acid plant. The inability to properly relieve an overpressure within a TDA check tank resulted in a 31.5MM loss. In August 1977, a reactor involved in the decomposi tion of ammonium nitrate to nitrous oxide exploded, leaving four men dead. Including the plant manager. The replaceable damage was over 3 2,000,000. The loss of life to employees was irreplaceable. The rate at which we hear of these Incidents has been increasing as has been the magnitude of the toss. Inflation has taken its toil, but other factors more actively influenced this trend. Our plants-are be coming larger and largerr The term 'world-scale' changes from year to year. They are single train; pipes are larger, flow rates are faster and chemical hold-up massive. Any hole in the armour can release tons of flammable liquid into the atmosphere. Our customers are requiring more assurance that their product will be continued in the event of plant problems and this necessitates large quantities of storage; both raw materials and products. Tank fail ures, vessel overfills and 'suck-ins' are all common failures in the industry which have led to disaster. While inflation has not been a major item leading to increased risk in our plants, its impact has been felt in the layout of our facilities. In order to reduce costs, we tend to shorten piperuns and construct a more compact unit. This tendency leads to a higher dollar density in a given area. Thus, a fire in a 200' square block will damage more equipment than a comparable fire ten years ago. Although certain spacing requirements exist by law (OSHA), by industry consensus (NFPA) and by internal agreement (Group/Division and Corporate Standards), there is room for trade offs among separa tion distance; fire protection and equipment; and process central instrumentation. Who must make these trade-off decisions? In the long run, we all make these type decisions in our daily activities. Whether it's a change in instruments, a bypass on a control or a change in a project layout, there is an impact on plant safety. It is the purpose of this seminar to discuss methods of analyzing these changes and deter mining their effect on plant safety. AP00017242 6 Hazards Identification The typical practice in the majority of chemical eng* Ineering companies for controlling the engineering development of a project from initial design right through to construction, revolves around the use of the Process and Instrumentation Flowhseet (P. & 1.0.) at all stages of the project. Usually a Project Manager is responsible for overail control of the P. & I.D, (issuing all flowsheet rev isions to the necessary departments, calling meetings, etc.). The P. & 1.0. Coordinator (usually a senior piping engineer) is responsible for ensuring the requirements of ail key departments are incorporated into sub sequent issues of the P. & I.D. Most projects have a minimum of five complete rev isions; (e.g. at A.P.L:-) Preliminary Revision 0 Revision 1 For Design For Construction Late design changes, e.g. during commissioning, have to be circulated to ail sections for approval using a 'P. & I.D. Change Note' before they can be imple mented. At all stages of review, each key department can make use of a P. & 1.0. checklist in searching the proposed flowsheet for safety related inadequacies. Company engineering standards also give guidance in this respect. Until recently, the above mentioned type of pro* cedure has proved adequate for examining a project for inadequacies. However, its structure inevitably means that attention is focused primarily on aspects with which each department is most knowledgeable. While this approach is acceptable for very simple systems involving conventional well established pro cesses and plant, it is likely to be far from adequate if the proposal is at ail complicated or novel. For such projects a much more rigorous, systematic and process-orientated examination is required. The most commonly used methods of systematic hazards identification are; (Fig.4.) a) "What-lf" Analysis b) Failure Mode and Effects Analysis (FMEA) c) Operability Study (I.C.I.) (Note: The above methods will only be very briefly discussed. Interested readers wishing to know further details of the application of either of the methods should consult the literature). HAZAHO IDENTIFICATION METHODS Of fIHOlNO OUT If WE HAVE A HAZARD METHODS Of DECIDING WHAT TO 00 AIOUT THE HAZARD I. OIVIOUS, x checklist HAZARDS X HAZANO IDENTIFICATION 4 "Whil-lf 01 F.MiA e) 0Mobility Snjdy ti.c.lj 1. OIVIOUS 2 CODE Of rRACTICE X UNAIDED JUMtHl 4. PREVIOUS EXFERIE X HAZARD ANALYSIS A. "What If' Analysis Perhaps the most successful technique in evaiuatir an idea is to have a co-worker take the position of tf devil's advocate. By questioning the basic assume tions for the idea, the reliability of die equipmen and the safety precautions utilized, one hopes tt unearth any hidden flaws in the design. The simpfest and easiest-to-use hazards analysis ted nique, 'What if' Analysis, is based on this methoc ology. 'What If' aims at forecasting scenarios and det ermining the hazard of their consequences. It is straight-forward tool and does not require a great d of time or sophistication. Ail employees should b using this basic toot as they perform their respecttvi job functions. The 'What If' technique is also quits useful in performing Preliminary Hazards Analyses or in reviewing a facility's operating procedures. The procedure is to: (1) define the system under study, {2} determine the underlying assumptions, (3) state the hazards in the system, (4) define the order of the review, (5) systematically ask What If questions of the system and its components, (6) gen erate recommendations, and (7) issue report to man agement. 'What If' questions can relate to: a state of nature - *What if lightning strikes?' an assumed condition - 'What if the wrong mal arial is delivered?* the reliability of an instrument or piece of equip ment *What if the valve sticks open?' a human reaction - 'What if the operator opera the wrong valve?', or combinations of events * 'What if the level ifr dicator is broken and we unload a trailer into the tank?' AP000I7243 7 * DECIDING OAIOUT 2AAO S * PRACTICE OJUDGEMENT uttxpimeNei 3 ANALYSIS g Failure Mode and Effect Analysis Method The Failure Mode and Effect Analysis (FMEA) method is used to evaluate systems in a manner which its name implies. That is, a particular item in a process is analyzed in its failure mode for its effect on other components and on the entire system. 6y definition, the FMEA method will evaluate aspects of an operition and determine the destructive potential of each hazard and of related hazards. This method is equip ment-oriented, and as such, it may not put enough emphasis on the operator's or operating procedures' role in running a process. The Y/hat If' Method, or, e$ will be discussed later, the fault tree analysis is more conducive to analyzing operating errors. C. The Operability Study Philosophy: The Operability Study is based upon the principle chat a problem can only arise when there is a devia tion from what is normally expected. evaluating lion of the 'C aseumpequipment, hopes to * lysis techts methodos and det-as. It is a * great deal should be respective ; also quite Analyses or as tern under j ptions, (3) | a the order { What If I ts, (6) genort to man- trikes?' wrong mat- Basic Procedure: Search the proposed scheme systematically for every conceivable DEVIATION and then look backwards for CAUSES and forwards for possible CONSE QUENCES. The scheme is examined line by line looking for in adequacies in design. A check list of guide words is applied to each stage of the process in turn, thereby generating DEVIATIONS opposite alt possible event ualities. Aspects considered are normal plant operation, start up and shut down, suitability of plant materials, equipment and instrumentation, provision for fail ure of plant services, provision of maintenance, safety. Before examining each section, make sure you under stand the function of the section, including normal process conditions and specifications if available. Keywords are applied only to lines joining pieces of equipment or to off-sites and not directly to the equipment itself. This is because any problem that could arise in a piece of equipment should show up as a cause or consequence of a deviation in a line lead ing to that piece of equipment. However the guide word 'OTHER' which has special significance for as pects other than normal operation, must be applied to the items of equipment as weli as the lines, Guidewords and their Meaning: ice of equip- rator opens -he level intrailer into WORD NONE MORE OF MEANING -- No flow, reverse flow -- Higher flow, temperature, pressure, viscosity, etc. PART OF -- Change in stream composition MORE THAN -- Impurities present, e.g. ingress of air, water. Extra phase present, e.g. vapour, liquid. OTHER - What else apart from normal oper ation can happen? e.g. start up, shut down, maintenance, catalyst or absorbent change, failure of plant services, safety. (Note: Implementation of an Operability Study through use of the above guideword system is ill ustrated in the example of a proposed olefin dimer ization unit in a paper by H.G, UWVLEY, l.C.t. Chemical Engineering Progress, April 1974). AP000I7244 8 Hazard Analysis (Fig,5.) Having carried out the identification of hazards on a proposed or existing plant design and having iden tified the existence of certain serious hazards, we may then wish to ask the question, 'How often will this hazard occur?'. The Hazard Analysis answers this question by relating logically the circumstances nec essary for the development of the potentially dan gerous situation (the hazard) and subsequently esti mating the probability that the hazard will occur (the hazard rate). The most commonly used method of hazard analysis logic is Fault Tree Analysis. S HAZARD AMALVS'S a branch of the tree and is developed indepdantly of the other branches. The cause shot be direct and immediate and reflect its fail state only on the sub-vent to which It is cc nected. Sub-events can be related to one anothe* through the use of "AND" or "OR" gates., single sub-event will cause the next higher ever to occur if the two events are connected by ar "OR" gate. The "AND" gate is used when the next higher event is the result of all sub-event: happening simultaneously. Construction of the tree continues until ail possible causes for each sub-event have been considered and the basic causes for each branch of the tree developed. Applying the fault tree method to calculate the hazard rate for a given undesired event is demon strated in the following example. (Figures.) I "WhM M" bJ FM.C.A. <) Ooab<l<fv Study N.C.U The method wes orginated by Belt Telephone in 1961, and further developed by the Boeing Company during the 1960's. Fault trees were initially limited to the aerospace field, but have since emerged within the chemicals industry. Fault tree analysis defines basic causes and their relationships in leading to a single, undesired event. The procedure for applying this method is as follows: a) Define the Undesired Event The fault tree is a logical sequence of events which could result in the undesired event, such as a vessel rupture or chemical spill. The undesired event will have been identified by use of the Operability Study, previous experience or other methods. The undesired event is placed at the top of the fault tree schematic. The main object ive in using this method is to determine how failures or actions, equipment, maintenance and personnel could result in an undesired event, b) Construct Fault Tree Having selected the undesired event, construct the fault tree using logic symbols to relate all possible event sequences to the undesired event The undesired event is placed at the top of die fault tree schematic. Then follows generation of possible causes of this event, called sub-events, in descending order of occurrence, building on the "stump" of the tree. Each sub-event form* Figure 6. Example of Hazard Rate Calculation System Description The system consists of a vessel (CfOl) fed by a high pressure gas source (limited to 8 bars.g.J. Pressure in C101 is controlled by a pressure control loop acting on an inlet control valve (PV--1). The vessel is pro tected by the relief valve PSV--1, An operator in tht control room has C101 pressure indication via PIC-1 and warning of high vessel pressure via alarm PAH-1. (CIO! design pressure is 1.0 bars.g.). System Hazard The hazard in the above system has been identified as vessel rupture. In order to quantify the hazard, it will be first necessary to draw up the fault tree for this hazard (See figure 7.). Quantification can then proceed subject to component failure rate data being available. - Rjsj try a* rate am' AP00017245 indepene should ts failed t is corv another gates. A ier event 'd by an /hen the b-events n of the for each he basic >ped. i late the ?9d6em.) on- 9 System Data Key failure rate data for this system is as follows; Faults/ year a) Pressure controller Q.20 b) Control Valve 0.15 c) Pressure transmitter 0.20 d) impulse line 0.10 e) Relief valve (overhauled every 2 years) 0.005 f) Operator Assume the operator will fail to intervene success* fully after a high pressure alarm with a probability of 0.1. If the alarm does not operate the probability will be only 0.5. ICI has been a leader in developing quantitative risk criteria for the chemical industry which they have applied and which has been widely published. The basis of their criteria is the fatal accident frequency rate (FAFR). The FAFR Is the number of fatalities per 100 million (10*) worker hours. This is roughly equivalent to the number of fatalities in a group of 1000 men over their working lifetimes. Typical FAFR's for various occupations calculated by Trevor Kletz of ICI are shown in Table I1 while FAFR's for non-occupational activities are shown In Table II1. Bulloch of ICI3 produced an interesting histogram (Figure 8) of the FAFR of various activities in daily life. Approximately half of the FAFR of 4 for the chem ical industry, which is considered good, is due to process related accidents (e.g. explosions, fires, etc.) while the other half is attributable to non-process related accidents (e.g. falling off a ladder). Kletz1 has argued that in a given plant no hazardous event should contribute more than 10% or 0.4 FAFR to the total FAFR. V-1 --DSO-- ation iy a high essure in op acting el is protor in the ia PIC-1 PAH-1. ntifled as rd, it will i for this can then iata being Risk Criteria Calculation of a hazard rate is the first step in any hazards analysis. However, unless there is a hazard rate goal there is no way to assess whether or not the amount of safety protection built into the process is Table I FAFR FOR VARIOUS INDUSTRIES Chemical Industry British Industry Steel Industry Fishing Coal Mining Railway Shunters Construction Workers Air Crew Professional Boxers Jockeys (Flat racing) 3. 4 8 35 40 45 67 '250 7,000 50,000 Table II FAFR FOR NON-OCCUPATIONAL ACTIVITIES Staying at home Travelling by bus Travelling by train Travelling by car Pedal cycling Travelling by air Moped riding Motor scooter driving Motorcycling Canoeing Rock climbing 3 3 5 57 96 240 260 310 660 1,000 4,000 An FAFR of 0.4 is equivalent to an average hazard rate of 3.5 x 10"* events/year. If this criteria is used APOOO17246 iff 10 Due to other causes Vessel Rupture 4 0.001/yr (Hazard Rate* t0*3/yr) Due to overpressure 0.001/yr Due to other control loop failures 0.035/yr Pressure rises above PSV setting 0.19/yr Relief system fdt - 0.005 Inadequate psv Stuck 0,005/yr shut. Alarm failed negligible Control failure 0.35/yr Control failure 0.3/yr Operator fails p 0.5 1 Operator failed p*0.1 PIC fails PV fails 0.15/yr 0.2/yr 0.2/yr Operator error neg. Impulse line fails 0.1 lyt KEY A -'OR'flite -'AND'8* * e.g. set-point altered AP00017247 n 4 to reduce the risk of significant in-plant hazards then the average FAFR should decrease over time. How ever, what appears to be a reasonable FAFR criteria in the chemical Industry may be very unrealistic for another {.eg. mining) industry. Even though criteria are used to establish the appropriate level of safety there may arise instances when it is impractical to reach the hazard rate goal. Gibson1 provides a poss ible way of analyzing this problem via a cost-benefit approach. The chart in Figure 9 explains this tech nique. However, a major problem occurs in trying to establish the number of people exposed. Society may be willing to accept a particular frequency for a single fatality but very unwilling to accept that same fre quency for multiple deaths. Risk analysis can be used to calculate this potential exposure. Figure 10 is an example from the Wash 1400 study to illustrate the risk to the public from exposure to 100 nuclear reactors. FIGURE 9 COST-BENEFIT ANALYSIS3 FIGURE 10 FREQUENCY VS. EARLY FATALITIES D neg. gate >' gate A Cost of Prevention B Material Damage Costs C Loss of Profit D Costs or Measures Taken After the Incident E Loss of Life F - Total Cost Risks to the population at large pose a more difficult problem. It has been suggested3 that a risk of death of 10"T per person per year (FAFR 0.001) may be acceptable as this level approaches a number of in voluntary event frequencies which the public has accepted without complaint (Table 111). AP00017248 FATAL ACCIDENT REOUENCV RATEf 12 FIGURE 8 HISTOGRAM OF FATAL ACCIDENTS RISKS . r*prtMnt> flapping tlmt b. r*pr#**nting vating, wnhing, drilling ate. at horn* C. rtpriuno driving to or from worK by ear d, raprewnta tbt day'* work a. rapraiantatltaluncb trek f. rapmamt motorcycling g. rapraiantt communal tntartalnmant, a.g. pub APOOO17249 13 Table III VOLUNTARY AND INVOLUNTARY RISKS COMPARED* Voluntary Activity Risk of Death Per Person Per Year Involuntary Activity Risk of Death Per Person Per Year Smoking (20 cigarettes/day) 500x10'* Run over by road vehicle (USA) 500x10"7 Drinking (1 bottie wine/day) 75x10'* Run over by road vehicle (UK) 600x10'1 Football 4x10** Floods (USA) 22 x10-' Car racing 120x10-* Earthquake (California) 17 x10'1 Rock climbing 4x 10-* Tornadoes (Mid-West USA) 22 x I0~'r Car driving 17x10'* Storms (US) 8 x 10'7 Motorcycling 200x10'* Lightning (UK) 1 x 10"7 i Taking contraceptive pills 2 x 10'* Falling aircraft (USA) 1 x 10-7 Falling aircraft (UK) 0.2 x 10'7 Explosion of pressure Vessel (USA) 0.5 x 10" 7 Release from atomic power station (at site boundary) (USA) 1 x 10-7 (at 1 km) (UK) 1 x 10-1 Flooding of dikes (Holland) 1 x 10-7 Bites of venomous creatures (UK) 2 x 10-7 Transport of petro & chemicals (USA) 0.5 x 10-' Transport of petro & chemicals (UK) Leukemia 0.2 x 10"' 800x10"' Influenza Meteorite 2000x10'' 6 x 10` Cosmic rays from explosion of supernovae 10-* - io-1 APOOOI7250 14 Failure Rate Oats A. Sources of Data In order to use reliability engineering methods, a source of data on equipment failure and repair, various peripheral events, and human resources are required. This necessary data can be obtained from three major sources: 1. Data Banks One of the principal data banks used by the chemical industry is that provided in the U.K. by the United Kingdom Atomic Energy Authority called the System Reliability Service (SRS). Normally, the facilities of the data banks are available to organisations through a subscrip* tion service. There are also many published sources of failure rate data in the literature. A great deal of this data has been incorporated into existing data banks. Selected data from Anyakora, Engel and Lees4 is presented at the end of this section (Table VI fI) for general reference. 2. Plant Experience Plant Experience can provide good failure data. A benefit is that environmental factors can auto matically become part of the data. However, there is a tremendous amount of effort involved in the collection of meaningful data. It is very difficult to get operations people to record the amount of data required and unless there is a large sample with many failures, then the con* fidence limits on the data will be extremely large. Event data can sometimes be obtained which can prove useful. For example, the number of times a particular relief valve has lifted can provide the demand rate directly for that relief valve. If the unit has had a large number of operating years experience, questioning the plant personnel or reviewing plant records can prove beneficial and supplement a fault tree analysis. 3. Prediction Prediction really means to apply failure rate data for the elemental parts to produce the failure rate of the instrument. Elemental parts include components such as contacts, relays, springs, connections, etc. {See figure 12.}. Fiflor* 12. An example of th* die technique of prediction i* iMoitraud Mow which the Uilu rau o* common lleeftliflht: c t Failure Rata ot Rnhlight 1 0.00088 + 0.002 * 0.06 * * <0,041 + OlOOOIS * 0.22/yr Lees1 has summarized, observed and predica instrument failure rate data shown inTablt' from various sources and there is generally * good agreement. .I Table IV Observed and Predicted Instrument Failure Instrument Failure Rate (Observed (Predici Fauits/y) Faultsj Control Valve!) Differential Pressure Transmitter3' Variable Area Flowmeter Transmitter!3) Temperature Trip Amplifier: Type A Type B Controller Pressure Switch Gas Analyzer Relay!3) fat -....... . 0.25 0.76 0.68 2.6 1.7 0.38 0.14 2.5 0.17 0.19 a<. a?; 2.8 2.1 or a 3.3 A* 1 AP00017251 T 15 vhlen p>t4cg - 0.00075v 0.00075 predicted nTable IV .rally very I. Instrument Failures There are many factor* which can influence instrument failure. Some of these are: 1. System Definition: Display/Controi Accuracy/Precision Response 2. Installation 3. Environmental Factors - Internal Material (Gas, Liquid, Solid) Cleanliness Temperature Pressure Corrosion Erosion 4. Environmental Factors External Control Room/Plant Temperature Humidity Dust Frost Vibration Impact 5. Operation Cycling 6. Maintenance le Rates5 late Predicted Faults/y) 0.19 0.45 0.7 2.8 . 2.1 0.87 0.13 3.3 0.35 1. Environmental Factors It is generally felt that environmental factors, in particular the types of materials that the instru ment is in contact with (both internal and exter nal), have the greatest impact on failure rate. From the same paper by Anyakora Engel and Lees* are the results of comparing similar instr uments in clean and dirty fluids (Table V). it is possible to assign correction factors for instrument failure rates in particularly dirty service if thought necessary. The instrument fail ure data at the end of this section in Table V include an environmental factor. To obtain a base failure rate divide the failure rate given by the environmental factor. Note also that the fail ure rate of the impulse lines should be added to the failure rate of the Instrument itself to obtain the total instrument failure rate. 2. Failure Modes There are normally a number of modes of failure for a given instrument. Lees* lists various fault moriM for a control valve which are presented in Table V EFFECT OF PROCESS FLUID CONDITIONS ON FAILURE RATES* Instrument No. At Risk Control Valve: Clean Fluid Dirty Fluids 214 T67 Differential Pressure Transmitter: Clean Fluids Dirty Fluids 27 90 No. of Faults 17 71 5 82 Failure Rate (Faults/ V) 0.17 0.89 0.39 1.91 Table VI FAILURE MODES OF A CONTROL VALVE* CONTROL VALVE NO. OF FAULTS Leakage Failure to Move Freely Sticking (But Moving) Siezed Up Not Opening Not Seating Blockage Failure to Shut Off Flow Glands Repacked/Tightened Diaphragm Fault Valve Greased General Faults 54 28 7 5 3 27 14 12 6 '5 27 It is important to know exactly what type of failure will be causing a potentially dangerous situation. Some of these modes are fail safe while others are fail dangerous and some occur over a period of time (slow) while others are instantaneous (sudden). In most applications, the sudden dangerous failure is the most serious. However, the failure data will normally not be sufficiently detailed to assess this failure rate for a dangerous mode. A rough rule of thumb is to consider that dangerous failures represent 2550% of total failures and sudden dangerous fail ures 10-25% of the total failures. 3. Problems of Data Collection Some of the problems in trying to collect plant failure data have been previously alluded to. Below is a more comprehensive list of items that must be considered when attempting to collect AP00017252 16 Application of the Equipment Environment (External) Failure Mode Preventive Maintenance Operating Time Physical and Chemical Properties of the Sys tem and the Process Medium Repair Time Total Plant Population The above list represents a vast information re quirement. Who will collect the data (e.g. a special staff?, maintenance personnel?) and how will it be stored and accessed (e.g. computer?) are all difficult problems to address. There is a balance necessary between the level of data coll ection and the perceived benefit. Few individual companies have elected to collect their own data. C. Human Error Human Error is an extremely complex subject. The actions of a human being are much more difficult to analyze because of variable factors such as: -- The work environment control room, plant layout -- Management attitudes -- Stress level of immediate situation -- Physical and mental state of operator -- Recovery factor The basic approach has been to examine human error on a failures per demand basis. For example, an operator may forget to close a valve after routine maintenance one out of every 100 times he is asked to perform that function. The probability of failure per demand is then 0.01. Beiow are estimates on human error based on the complexity of the task and the stress level. (Table VII). taoie mi HUMAN ERROR ESTIMATES ERECTION Of TM| ERROR MR OMMTtON OCCUR* COMTVtKITY Of TASK KVUO'lTKiSt NONE SIMRlIST 1 I04 ROUT INI A NO ROUTINE REQUIRES SIMPLE cut COMPUCATCO. NON *CWTlNt QTh OUTitS <oui*eo t 10 3 l.wr* o>i MOOERATI CUERCENCV HtOM truss 1 I 10 3 It t . 10 1 at i . iaJ OJi t 03 10 AP00017253 17 Table VIM INSTRUMENT FAILURE RATE OATA, ANYAKORA ENGEL AND LEES* Instrument No. Environ At Instrument ment No. of Risk Years Factor Faults Control Valve Power Cylinder Valve Positioner Solenoid Valve Current/Pressure Transducer Pressure Measurement Flow Measurement (Fluids): D ifferential Pressure Transducer Transmitting Variable Area Flowmeter Indicating Variable Area Flowmeter Magnetic F lowmeter Flow Measurement (Solids): Load Cell Belt Speed Measurement & Control Level Measurement (Liquids): Differential Pressure Transducer Float-Type Level Transducer Capacitance-Type Level Transducer Electrical Conductivity Probes Level Measurement (Solids) Temperature Measurement (excluding Pyrometers) Thermocouple Resistance Thermometer Mercury-in-steel Thermometer Vapour Pressure Bulb Temperature Transducer Radiation Pyrometer Optical Pyrometer Controller Pressure Switch Flow Switch Speed Switch Monitor Switch Flame Failure Detector 1531 98 334 252 200 233 1942 636 100 857 15 45 19 421 130 158 28 100 11 2579 772 479 1001 27 300 43 4 1192 549 9 6 16 45 747 39.9 158 113 87.3 87.9 943 324 47.7 409 5.98 17.9 7.58 193 62 75.3 13.4 39.8 4.38 1225 369 227 477 10.7 142 30.9 3.4 575 259 3.59 2.39 6.38 21.3 2 2 1 1 1 3 3 3 3 3 4 4 4 4 4 4 -- 3 3 3 2 4 3 4 4 1 2 -- -- -- 3 447 31 69 48 43 124 1069 559 48 137 13 67 116 327 106 124 3 94 30 425 191 92 13 4 124 67 33 164 87 4 0 0 36 Failure Rate (Faults/y) 0.60 0.78 0,44 0.42 0.49 1.41 1.14 1.73 1.01 0.34 2.18 3.75 15.3 1.70 1.71 1.64 0.22 2.36 6.86 0.35 0.52 0.41 0.027 0.37 0.88 2.17 9.70 0.29 0.34 1.12 -- _ 1.69 AP000I7254 CONCLUSION As stated in the Introduction, this Symposium address has dealt with Air Products' Management Approach to Safety and Hazard Analysis. Often it is wrongly assumed that one can separate the more traditional "Safety Management" concepts from the more novel "Hazard Analysis" techniques. It should now be obvious from the presentation that hazard analysis is necessary to fully understand and hence control possible hazards and in this respect is an extension of Safety Management. However, what must be emphasized is that the correct application of hazard analysis depends on there being effective Safety Management. This point was spelt out in a recent paper by Trevor Kletz:1 "It is an unwritten assumption when applying Hazard Analysis that the plant is designed, operated and maintained according to good engineering and management standards. If this is not true, hazard analysis is a waste of time. It is no use calculating the probability of unlikely events if serious incidents are probable as a result of a poor permit-to*work system, lack of instructions, "Heath Robinson" methods of mainten ance and so on. Hazard analysis is a sophisticated technique for good organisations who wish to allocate their resources sensibly and improve their standards. It should not be used until the basic management is satisfactory." References1 * 3 1. Klati, T.A., "Hazard Analysis - A Quantitative Approach to Safety". IChE Symposium Series No. 34, Institution of Chemical Engineers. London, 1971. Z. Bulloch, B.C.. "The Development and Application of Quantitative Risk Criteria for Chemical Processes", IChE Symposium Series No. 39a, Institution of Chemical Engin eer*. London,1974. 3. Gibson, S.B., "Risk Criteria in Hazard Analysis", CEP, Vol 72. No. 2. Feb 1970. 4. Anyakora, S.N., Engel, G.F.M., Lees, F.P., "Some Data oi the Reliability of Instrument in the Chemical Environment' The Chemical Engineer, Nov. 1971. 5. Lets, F.P.. Loss Prevention In the Chemical Process Industries, Vol 1, Butterworth, 1980. 6. U.S. Atomic Energy Commission, "Reactor Safety Study An Assessment of Accident Risks in U.S. Commercial Nuclear Power Plants," WASH-1400, Washington, O.C. 1974. 7. Ktetz, T.A. "Hazard Analysis The Manager and the Ex pert". Reliability Engineering2 (1981) 35-43. Other References of Risk Criteria Farmer, F.R., "Experience in the Reduction of Risk", IChE Symposium Series No. 34. Institution of Chemical Engineers, London,1970. Kletz, T.A., "The Application of Hazard Analysis to Risks to the Public at Large", World Congress of Chemical Engineering, Amsterdam, July 1976. AP00017255