Third-Party Interference (TPI)

Third-party interference (TPI) is damage to an asset caused by someone outside the operating organization: the excavator that hits a buried pipeline, a criminal attempting to steal material, vandal, the saboteur, and the fuel thief cutting an illegal tap. API Recommended Practice 1160 carries it as a pipeline threat, and ASME B31.8S classes third-party damage as time-independent, so it will not show up in a corrosion model. IEC 61511 never names it, so in a process safety lifecycle TPI arrives as an initiating event in the hazard and risk assessment, with a demand rate you have to argue from incident history rather than a failure-rate table.

Key Points

  • API RP 1160 and ASME B31.8S treat third-party damage as its own threat category; IEC 61511 does not name it at all.
  • Deliberate interference breaks the independence assumption behind LOPA credits, because one motivated person can defeat several layers at once.
  • The real controls are damage prevention, surveillance, and leak detection. A safety instrumented function answers process demands, not a thief with a drill.

Example

Mexico is the textbook case. Fuel thieves (huachicoleros) tap Pemex product lines by the thousands each year, and as surface taps got policed they literally went underground, digging tunnels and running buried hoses hundreds of metres to reach the pipe out of sight. In January 2019 a tap on the Tuxpan–Tula line at Tlahuelilpan geysered gasoline, a crowd gathered to collect it, and the ignition killed roughly 137 people. No safety instrumented function saw a demand, because the release point never existed in the design.

Go deeper: The Haldia Naphtha Pipeline Fire: What We Know So Far

See Also: initiating event, hazardous areas, mechanical integrity program

Cited Sources

Part Of: hazard and risk assessment category