Safety and Operability Studies
An overview of techniques used to assess safety and/or operability of new or existing plants.
History
Safety and Operability have for a long time been considered together when reviewing a new or modified process plant. At the inception of Hazard and Operability reviews (HAZOP Studies) in the 1960s by Trevor Kletz at ICI in the UK, plant operation was largely controlled by manual intervention, with a few basic control loops.
It was therefore vital at that time to train plant operators in understanding the significance of any changes to operating conditions in particular those with safety implications.
These Hazop reviews were a key element in the training of plant operators - before the initial plant startup. Hazop studies or reviews soon became a key safety check on the design of new facilities, conducted once the design was more or less ‘frozen’ - subject to any adverse findings from the review.
Hazop Basics
The review team typically involved design ‘process engineers’ plus instrument and control engineers and other disciplines as appropriate, and was led by a safety specialist. The project manager could participte as an observer but his/her input was normally limited by their potential conflict of interest - control of project costs versus expensive additional features deemed to minimise risks.
The nature of these Hazop reviews was of necessity thorough and painstaking and they were designed from their beginnings to be appropriate for the level of training of the operators.
To carry out the pre-startup Hazop review using a coloured markup of the Piping and Instrumentation Flow Diagrams (P&ID), the process plant was ‘sliced’ into a number of small sections of piping or equipment, termed ‘nodes’. Then deviation keywords ‘more’ or ‘less’ and parameters such as pressure, temperature, level, composition were applied to each node to determine the consequences and whether this constituted a problem.
Evolution
In the ensuing decades automatic process control became widespread with the role of the plant operator becoming largely reduced to monitoring the plant from the control room and carrying out startup or load changes and such.
However, because of its rigor, and perhaps its catchy name, the HAZOP procedure had become well-entrenched as a key milestone in the implementation of a new project design and no single alternative was available to satisfy the plant owners and the safety regulators.
A plethora of other related safety studies did evolve - including HAZAN, QRA, Fault Trees, Cause Trees, FMEA, Bow tie diagrams, Risk graphs, LOP, SIL review and more.
Delving into these is beyond the scope of this overview article. They all have their place.
Practical approaches
To address the competing pressures of project deadlines, the time and cost required to carry out a comprehensive Hazop and the need to demonstrate that safety was adequately considered, many companies introduced what was called a ‘Coarse Hazop’ study. This would be done at an earlier stage in the project development to determine whether there were any unforeseen show-stoppers earlier in the design. It could be referred back to, as and when a full Hazop was conducted later.
Digital Twins
Another idea that is gaining traction, coincidentally with the development of artificial intelligence (AI) is the creation of a so-called digital twin of the process. This is a computer-based dynamic simulation model which replicates both the performance and responses of the plant equipment and its associated control system to any changes.
This model takes time and considerable expertise to build but can be carried out in parallel with the detailed process and mechanical design. As well as testing responseto plant upsets it can be used for operator training – in a similar manner to a flight simulator.
Should Hazard and Operability risks be considered together?
That ‘HAZOP’ incorporates the term ‘operability’ alongside hazard (i.e.safety) is questionable and there are arguments to consider addressing them separately.
However, The Digital Twin concept may be a useful tool for considering both of these issues. In fact, a steady state simulation model of a new plant design is a standard tool to develop and verify the heat and material balance for each operating case. Commercial steady state (SS) model toolkits are offered by companies such as HYSYS (AspenTech), UniSim (Honeywell), VMG-Sim / Synergy (Schlumberger) and others.
In general, the SS model can be enhanced by adding the features to convert it to a dynamic model, although this conversion is far from trivial.
What approach to adopt?
While each of the previously mentioned techniques for Identifying and quantifying hazards has its merits, the author considers that the most effective use of time and effort is to start with an initial High-level Safety Review which assesses real safety risks separately from operability challenges.
There may be some overlap, but this would be identified and noted.
NB. This would not preclude using the High-level study findings in a separate later more detailed review such as a HAZAN, for example to assess probabilities of the so-called’ top event’ in the light of the ‘layers of protection’ and whether the risk was deemed sufficiently remote to be accepted by the ultimate plnt owner/operating company.
High Level Safety Review – basic steps
Depending on the nature of the fluids being handled within the process certain hazards are or should be fairly obvious.
Examples are where a fluid can pose asphyxiation risk such as nitrogen or CO2 – particularly in a closed environment. Therefore, entry to a vessel that may have contained these gases is a strict ‘no-no’. Similarly the presence of toxic gases such as H2S even at low concentrations and CO.
High temperature equipment such as an adsorber regeneration heater or a compressor discharge system can suffer from accelerated corrosion.
High velocity flow through or near to small bore connections can lead to vibrations at the pipe’s resonant frequency with resulting fatigue failure in a relatively short time.
Cryogenic risks
Where a fluid is flammable – such as LNG or Hydrogen, access restriction, safe venting locations and appropriate non sparking equipment are mandatory.
Cryogenic fluids can cause serious ‘cold burns to bare skin.
A non-insulated pipe containing atmospheric LN2 at around 77K can condense air on the outside. The condensed liquid air is enriched in oxygen with a consequent fire hazard.
Ice formation on the outside of un-insulated overhead pipes can be danger if the ice falls off and when personnel can be beneath.
Carbon steel becomes brittle when cooled by contact with a cryogenic fluid such as LNG or liquid N2, LH2 or LHe. As a result, a small shock can potentially lead to brittle fracture of the steel, with metal projectiles and loss of containment of internal fluid, and potential knock-on hazards, such as fire.
A vacuum insulated Dewar containing cryogens liquid helium or liquid H2 relies on the high vacuum to minimise heat ingress. In the event of sudden loss of vacuum and air ingress, the air will condense (and freeze) on the cold inner vessel surface leading to very high heat flux into the contained liquid helium, and rapid boiling. If the inner vessel is closed or does not have adequate overpressure / vent capacity it can rupture catastrophically. Fortunately, sudden vacuum loss is rare and MLI in the interspace reduces heat flux.
High Pressure Risks
Where equipment contains gas at an elevated pressure, the contained energy can be a hazard if not controlled. Where a HP fluid can pass via a valve to an adjacent system having a lower mechanical design pressure, there is a potential risk of over-pressuring a component – pipe or vessel in the lower pressure system – which could fail with uncontrolled loss of containment. A safety relief valve should protect the LP system - provided it is properly sized and periodically tested.
Environmental and other Risks.
Earthquake, subsidence, fire, flooding, electric storm, terrorist attack, cyber-attack.
High Level Operability review – basic steps
This review is primarily aimed at identifying and managing risks or interruptions to the successful operation of the facility as distinct from safety risks.
The review team would comprise 3-4 engineers and a leader / scribe which would:
1. Examine each major process area or subsystem in turn to understand the functions of the process elements and the controls in that area.
This includes ‘safeguarding’ features - trips / alarms and interlocks
2. Consider major loss of utilities such as power, cooling water, instrument air, lack of feedstock.
3. Identify potential failures for each system element, the consequences, probabilities of the failure and any mitigations such as regular testing of trip instruments.
Identify the knock-on effects of any potential failure on connected systems.