<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>SIL Safe</title>
	<atom:link href="https://silsafe.net/feed/" rel="self" type="application/rss+xml" />
	<link>https://silsafe.net</link>
	<description>Safer Communities, Resilient Operations.</description>
	<lastBuildDate>Sat, 18 Jul 2026 01:10:30 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://silsafe.net/wp-content/uploads/2025/07/cropped-SIL-Safe-Logo-master-white-favicon-square-150x150.png</url>
	<title>SIL Safe</title>
	<link>https://silsafe.net</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>The Haldia Naphtha Pipeline Fire: What We Know So Far</title>
		<link>https://silsafe.net/haldia-naphtha-pipeline-fire/</link>
					<comments>https://silsafe.net/haldia-naphtha-pipeline-fire/#respond</comments>
		
		<dc:creator><![CDATA[mamerten]]></dc:creator>
		<pubDate>Tue, 14 Jul 2026 01:41:54 +0000</pubDate>
				<category><![CDATA[Advanced]]></category>
		<guid isPermaLink="false">https://silsafe.net/?p=7658</guid>

					<description><![CDATA[In June 2026, a naphtha pipeline caught fire at Haldia Petrochemicals in West Bengal, India, burning outward into homes, a railway, and a neighbouring LPG line. The suspected cause is an illegal tap, an initiating event sitting outside the protection IEC 61511 was built to specify. Here is what is known so far.]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">In June 2026, a naphtha pipeline caught fire at Haldia Petrochemicals Limited (HPL) in West Bengal, India. The fire did not move inward into the plant. It moved outward: into houses on the other side of the fence, onto a nearby railway, and onto a neighbouring company&#8217;s LPG line.</p>



<p class="wp-block-paragraph">Reports put the injured at roughly 20 to more than 35, and the dead at somewhere between one and six. Both plant workers and residents were hurt.</p>



<p class="wp-block-paragraph">No cause has been established, and nothing here is a root cause analysis. HPL&#8217;s preliminary statement points at an unauthorized naphtha theft point near the line, an illegal tap, and Reuters reports the fire happened at a place where naphtha has been stolen from before. That one detail puts the incident outside the boundary most functional safety engineers work inside.</p>



<h2 class="wp-block-heading">What is Haldia Petrochemicals, and where does it sit?</h2>



<p class="wp-block-paragraph">HPL runs a naphtha-based petrochemical complex at Haldia, an industrial port town in West Bengal, in eastern India. The heart of the complex is a naphtha cracker: a furnace that heats naphtha with steam until the larger molecules break apart into smaller ones, mainly ethylene and propylene, the feedstock for plastics. It is rated at roughly 700,000 tonnes per year of ethylene.</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1200" height="729" src="https://silsafe.net/wp-content/uploads/2026/07/Haldia-Naphtha-Pipeline-Fire.webp" alt="The Haldia Petrochemicals complex in West Bengal, India, showing above-ground pipe racks of the kind involved in the 2026 naphtha pipeline fire" class="wp-image-7656" srcset="https://silsafe.net/wp-content/uploads/2026/07/Haldia-Naphtha-Pipeline-Fire.webp 1200w, https://silsafe.net/wp-content/uploads/2026/07/Haldia-Naphtha-Pipeline-Fire-300x182.webp 300w, https://silsafe.net/wp-content/uploads/2026/07/Haldia-Naphtha-Pipeline-Fire-1024x622.webp 1024w, https://silsafe.net/wp-content/uploads/2026/07/Haldia-Naphtha-Pipeline-Fire-768x467.webp 768w" sizes="(max-width: 1200px) 100vw, 1200px" /><figcaption class="wp-element-caption">The Haldia Petrochemicals complex, photographed in 2018 — not an image of the June 2026 fire. Photo by খাঁ শুভেন্দু via Wikimedia Commons, <a href="https://creativecommons.org/licenses/by-sa/4.0" rel="nofollow noopener" target="_blank">CC BY-SA 4.0</a>.</figcaption></figure>



<p class="wp-block-paragraph">Haldia is a dense industrial port cluster. A refinery, an LPG import terminal, storage terminals, and the pipelines that move product between them all sit within a few square kilometres of each other, and houses sit directly against that infrastructure.</p>



<h2 class="wp-block-heading">What is naphtha, and what is the hazard?</h2>



<p class="wp-block-paragraph">Naphtha is a liquid hydrocarbon mixture that boils in roughly the gasoline range and serves as the cracker&#8217;s feedstock.</p>



<p class="wp-block-paragraph">Its flash point sits below normal ambient temperature, so it gives off an ignitable vapor with no heating at all. A puddle of it at room temperature is already producing fuel.</p>



<p class="wp-block-paragraph">The vapor is denser than air. It settles at grade, runs downhill, spreads along the ground, and burns back to the source when it finds an ignition source. Even by the standards of the process industry, naphtha is a very dangerous substance.</p>



<h2 class="wp-block-heading">What happened in June?</h2>



<p class="wp-block-paragraph">Reporting conflicts on the details, and the conflicts are worth naming rather than smoothing over.</p>



<p class="wp-block-paragraph">Residents told local reporters they had been smelling naphtha since the night before. If that holds, the release ran for hours before it ignited.</p>



<p class="wp-block-paragraph">Fire was first spotted on the naphtha pipeline in the small hours of the morning, preceded by an explosion residents heard from their homes. Accounts of the first alarm range from around 2:45 a.m. to around 4:30 a.m. The fire crossed the plant boundary into Chiranjibpur, the neighbourhood outside, destroying homes. It damaged overhead electrical equipment on a nearby railway line and suspended train services. The source was isolated early, but the fire could not be extinguished until the inventory left inside the pipeline burned itself out.</p>



<p class="wp-block-paragraph">Casualty reporting is inconsistent. Injury counts run from roughly 20 to more than 35. Some outlets describe the injured as primarily factory workers, others as mostly local residents; two HPL security personnel are named among them. The death toll is reported anywhere from one to six.</p>



<h2 class="wp-block-heading">How far the fire actually spread</h2>



<p class="wp-block-paragraph">The fire never significantly entered the process plant. HPL reported operations unaffected. It went outward instead, into houses, onto the railway, and onto the LPG line of the neighbouring IndianOil Petronas terminal (IPPL), a separate company operating an LPG import and bottling facility next door. HPL&#8217;s own statement says the pipe leakage spread to IPPL&#8217;s LPG line and hampered its services.</p>



<p class="wp-block-paragraph">Flame impingement on an LPG line is the precursor condition for the worst outcome available at a site like this. It did not go. There is no report of a secondary release or explosion at IPPL.</p>



<p class="wp-block-paragraph">That makes this a near-miss sitting inside an incident, and near-misses are the most instructive events in process safety precisely because the consequence did not arrive to distract from the mechanism.</p>



<p class="wp-block-paragraph">For any reader with a fence line: a release on one operator&#8217;s asset can put flame on another operator&#8217;s inventory, and neither hazard study is likely to contain the other&#8217;s scenario.</p>



<h2 class="wp-block-heading">What caused the release?</h2>



<p class="wp-block-paragraph">The reporting keeps collapsing two separate questions: what opened the line, and what lit it. They have different answers and different owners. Three accounts are in circulation, and only two of them are about the release.</p>



<h3 class="wp-block-heading">An illegal tap</h3>



<p class="wp-block-paragraph">HPL&#8217;s preliminary statement identifies an unauthorized naphtha theft point near the line as the suspected location, and says it suspects the fire started while people were attempting to steal product by damaging the pipeline.</p>



<p class="wp-block-paragraph">Reuters reports the fire occurred at a place where naphtha has been stolen from in the past, and HPL added that it has repeatedly warned local communities against unauthorized handling of petroleum products. Illegal tapping was a known, recurring condition at this location.</p>



<p class="wp-block-paragraph">A thief wants product in a hose, not product on the ground. A fire means the tap was botched, or was never under control to begin with.</p>



<h3 class="wp-block-heading">A mechanical leak or rupture</h3>



<p class="wp-block-paragraph">Police and several outlets describe a pipe leakage or rupture as the starting point, without reference to theft. This is the mechanical integrity story: corrosion, external damage, weld or flange failure, and the inspection program that should have caught it. It is the account that stands if the theft point turns out to be incidental to the release.</p>



<p class="wp-block-paragraph">HPL&#8217;s own statement says the incident occurred due to a pipe leakage, and in the same breath says it suspects the fire started during an attempt to steal product by damaging the pipeline. On HPL&#8217;s telling, these are not two hypotheses. They are one hypothesis described from opposite ends.</p>



<h3 class="wp-block-heading">Lightning was hypothesized, but it does not explain the release</h3>



<p class="wp-block-paragraph">The state fire service suggested early on that a lightning strike during heavy rain and thunderstorms may have started the fire.</p>



<p class="wp-block-paragraph">Lightning is a credible ignition source for a flammable atmosphere. It is a poor explanation for the release, unless a release was already underway. It does not compete with the other two. A release from any cause, ignited by any source, produces the same fire.</p>



<h2 class="wp-block-heading">How common are illegal taps?</h2>



<p class="wp-block-paragraph">Illegal tapping is unfortunately more common than people realize, and it is not a developing-world problem. Concawe, the European oil industry&#8217;s research body, has tracked spillages on European cross-country pipelines since 1971. Theft-related spillages numbered 28 across the entire period from 1971 to 2012. Then came 18 in 2013, 54 in 2014, and 87 in 2015. In 2016, 60 of the 66 recorded spillages were theft-related. In 2023, six of eight were. Enforcement has pushed the totals down since the peak, but in several recent years theft has caused the majority of all recorded spillages on European oil pipelines.</p>



<p class="wp-block-paragraph">Method spans a wide range of skill, from a coupling welded onto the live line and drawn from quietly for years, down to an angle grinder or a metal spike. Every version is unpermitted hot work or mechanical breach on a live, pressurized hydrocarbon line. <strong>The illegal tap carries its own ignition source.</strong></p>



<p class="wp-block-paragraph">The crude end is where the fires come from. A well-made tap does not burn, it draws. A fire during the act, which is what HPL describes, points to the other end of the range, and Concawe records that thieves faced with a large leak commonly flee and leave the line open.</p>



<p class="wp-block-paragraph">The consequences are on the record. A 2019 pipeline explosion in Mexico linked to fuel thieves killed more than 130 people. Haldia is not an outlier. It is a category.</p>



<h3 class="wp-block-heading">A sophisticated example</h3>



<p class="wp-block-paragraph">Mexican fuel theft, run at industrial scale by organised crime, is the most heavily documented version of the problem. Authorities have found taps reached by tunnels dug toward Pemex lines, and taps installed in pairs.</p>



<p class="wp-block-paragraph">One tap draws fuel out. The other pumps water in, holding the line pressure where the monitoring system expects to see it, so the pressure-drop alarm never fires. The thief is not evading the monitoring system. He is feeding it false data so it reports normal.</p>



<h3 class="wp-block-heading">Buried lines and above-ground lines</h3>



<p class="wp-block-paragraph">Cross-country pipelines are buried as standard, and burial is partly a security measure in its own right: it puts the pipe out of reach and out of sight. Most illegal taps target buried lines anyway, and the theft starts with excavation.</p>



<p class="wp-block-paragraph">Above-ground lines, common inside plants and terminals on racks and sleepers, are easier to reach and easier to see, which pushes the theft toward the crude end. No published data separates theft on buried lines from theft on above-ground lines, so treat the split as unquantified. What is not in doubt is that burial is not protection.</p>



<h3 class="wp-block-heading">The pattern in India</h3>



<p class="wp-block-paragraph">In July 2026, Indian Oil Corporation found an illegal valve and a 40-foot buried offtake line spliced into a crude pipeline in Tonk district, Rajasthan. It was discovered only after engineers chased down an abnormal pressure drop that had been developing for weeks.</p>



<h2 class="wp-block-heading">Was this a process safety failure?</h2>



<p class="wp-block-paragraph">Possibly, and it is hard to say without more information. What is more likely is that it was not a safety instrumented system (SIS) failure.</p>



<h3 class="wp-block-heading">An illegal tap is not a process deviation</h3>



<p class="wp-block-paragraph">A safety instrumented function (SIF) detects a defined process condition crossing a defined limit and drives the process to a safe state. Someone cutting into a transfer line from the outside produces no such condition. Pressure barely moves, flow barely moves, and nothing crosses a trip point until the line is already open to atmosphere and the fire has started.</p>



<p class="wp-block-paragraph">IEC 61511 draws this line in its own definitions. Human error is defined as action or inaction producing an inappropriate result, and the standard states plainly that malicious action is excluded from it.</p>



<p class="wp-block-paragraph">The standard&#8217;s security requirements, in Clause 8.2.4, require a security risk assessment of the SIS itself. That covers threats to the instrumented system. It is not a physical security requirement for hydrocarbon pipework, and it does not reach an illegal tap.</p>



<h3 class="wp-block-heading">The thief works below, or around, the detection threshold</h3>



<p class="wp-block-paragraph">Pipeline leak detection works mostly by mass balance: meter what goes into the line, meter what comes out, correct for the inventory in the pipe, and alarm when the numbers stop agreeing. The alarm threshold has to sit above flowmeter uncertainty, or the system alarms constantly on measurement noise.</p>



<p class="wp-block-paragraph">A draw small enough to hide inside meter error is invisible to it. The water-injection trick goes further and holds the measured pressure where the system expects it.</p>



<p class="wp-block-paragraph">Concawe found that automated leak detection was involved in detecting only about 15% of underground pipeline spillages across their full survey period, improving in recent years, while nearly half were first found by someone other than the operator, sometimes by the people who caused the leak. At Haldia, if the residents are right, the detection layer that worked was a human nose.</p>



<h3 class="wp-block-heading">The illegal tap creates a hazardous area that was not planned for</h3>



<p class="wp-block-paragraph">Area classification under IEC 60079-10-1 is driven by sources of release. The body of a pipeline is a sealed pressure envelope: welded joints, no gaskets, no packing, no moving seals, nothing to leak from. The classified zones live at the fittings, where the openings are, and the long runs between them are unclassified, correctly so.</p>



<p class="wp-block-paragraph">An illegal tap creates a source of release in an unclassified area. No Ex-rated equipment, no gas detection, no ignition-source control, because under any legitimate reading of the design there was nothing there to release.</p>



<p class="wp-block-paragraph">Then the thief cuts, welds, or drives a spike at that point. The same hot work inside the fence would need a hot work permit, gas testing, isolation, and a fire watch. And a sophisticated illegal tap is not a one-night event: it stays in the line, a standing source of release in an area no drawing classifies and no gas detector watches.</p>



<p class="wp-block-paragraph">The illegal tap did not defeat the protection. It relocated the hazard to a place the protection was never asked to look.</p>



<figure class="wp-block-image size-large"><img decoding="async" width="1200" height="720" src="https://silsafe.net/wp-content/uploads/2026/07/Illegal-Tap-Relocates-the-Hazard.webp" alt="Diagram showing a pipeline where the classified hazardous area sits at the flange while an illegal tap creates a source of release in the unclassified welded run" class="wp-image-7665" srcset="https://silsafe.net/wp-content/uploads/2026/07/Illegal-Tap-Relocates-the-Hazard.webp 1200w, https://silsafe.net/wp-content/uploads/2026/07/Illegal-Tap-Relocates-the-Hazard-300x180.webp 300w, https://silsafe.net/wp-content/uploads/2026/07/Illegal-Tap-Relocates-the-Hazard-1024x614.webp 1024w, https://silsafe.net/wp-content/uploads/2026/07/Illegal-Tap-Relocates-the-Hazard-768x461.webp 768w" sizes="(max-width: 1200px) 100vw, 1200px" /><figcaption class="wp-element-caption">Area classification follows sources of release. An illegal tap creates one in an area no drawing classifies and no gas detector watches.</figcaption></figure>



<h2 class="wp-block-heading">So where should the protection have come from?</h2>



<h3 class="wp-block-heading">How the pipeline industry defends against illegal taps</h3>



<p class="wp-block-paragraph">The pipeline industry has a name for this threat: <em>third party interference</em>. It covers everything from a careless excavator operator to an organised theft gang. Functional safety literature barely mentions it. Pipeline literature is full of it.</p>



<p class="wp-block-paragraph"><strong>Separation distance and land use planning.</strong> Passive, and it does not depend on anyone doing anything. It decides whether a pipeline fire stays an industrial event or becomes a housing fire. At Haldia the fire crossed the fence and burned homes.</p>



<p class="wp-block-paragraph"><strong>Physical security and surveillance.</strong> Right-of-way patrol, fencing, access control, aerial and drone survey, community engagement. The only layer that stops an illegal tap before it exists.</p>



<p class="wp-block-paragraph"><strong>Remotely operated shut-off valves.</strong> Sectionalising valves that shut in the source and bound the inventory available to feed a fire. The one instrumented layer in the set, and at Haldia it did its job.</p>



<p class="wp-block-paragraph"><strong>Leak detection.</strong> API RP 1130 covers computational pipeline monitoring and API RP 1175 covers leak detection program management. Beyond mass balance, negative pressure wave detection listens for the rarefaction wave that travels back up the line at the speed of sound when a rupture opens. All of these alarm to an operator. None is a SIF.</p>



<p class="wp-block-paragraph"><strong>Mechanical integrity.</strong> In-line inspection tools that run down the bore looking for metal loss, cathodic protection, wall thickness survey, right-of-way condition. These find the damage after the fact, and only if the illegal tap is metal and the tool can see it.</p>



<figure class="wp-block-image size-large"><img decoding="async" width="1200" height="720" src="https://silsafe.net/wp-content/uploads/2026/07/Where-the-Protection-Actually-Lives.webp" alt="Table of pipeline protection layers against illegal taps showing which stop the tap and which a LOPA can credit" class="wp-image-7666" srcset="https://silsafe.net/wp-content/uploads/2026/07/Where-the-Protection-Actually-Lives.webp 1200w, https://silsafe.net/wp-content/uploads/2026/07/Where-the-Protection-Actually-Lives-300x180.webp 300w, https://silsafe.net/wp-content/uploads/2026/07/Where-the-Protection-Actually-Lives-1024x614.webp 1024w, https://silsafe.net/wp-content/uploads/2026/07/Where-the-Protection-Actually-Lives-768x461.webp 768w" sizes="(max-width: 1200px) 100vw, 1200px" /><figcaption class="wp-element-caption">The layers most likely to have prevented Haldia are precisely the ones a LOPA cannot count.</figcaption></figure>



<h3 class="wp-block-heading">Where the H&amp;RA could have caught it</h3>



<p class="wp-block-paragraph">IEC 61511 Clause 8.2 requires the hazard and risk assessment (H&amp;RA) to identify hazardous events, the sequences that lead to them, and the risk reduction required, which is where an initiating event like third party interference would sit. However, the same standard excludes malicious action from its definition of human error, and scopes its security requirement to the SIS itself. <strong>It is a tricky situation.</strong></p>



<p class="wp-block-paragraph">A known, recurring condition should be evaluated. Naphtha had been stolen from this location before, and HPL had been warning communities off the line.</p>



<p class="wp-block-paragraph">None of which makes the analysis easy. Deliberate interference is a genuinely hard initiating event to carry. It is intelligent rather than random, so it does not respond to redundancy, and the frequency data a layer of protection analysis (LOPA) depends on does not exist for it in any usable form. An engineer trying to put a number on the tapping rate at this site would be guessing, and would know it.</p>



<h2 class="wp-block-heading">What regulations apply?</h2>



<h3 class="wp-block-heading">Who regulates process safety in India?</h3>



<p class="wp-block-paragraph">The Factories Act 1948, amended after Bhopal to add Sections 41A through 41H, is the foundation. The Manufacture, Storage and Import of Hazardous Chemicals (MSIHC) Rules 1989, made under the Environment (Protection) Act 1986, carry the major-accident duties: safety reports, notification, on-site and off-site emergency plans, and accident reporting above threshold quantities.</p>



<p class="wp-block-paragraph">Enforcement sits at state level, through the Chief Inspector of Factories or the Directorate of Industrial Safety and Health, which here means West Bengal. There is no single unified statute equivalent to OSHA PSM or COMAH.</p>



<h3 class="wp-block-heading">Who regulates the pipeline?</h3>



<p class="wp-block-paragraph">The Petroleum and Explosives Safety Organisation (PESO) licenses petroleum installations under the Petroleum Act 1934 and the Petroleum Rules 2002. The Oil Industry Safety Directorate (OISD) publishes the sector&#8217;s technical safety standards and runs third-party audits. The Petroleum and Natural Gas Regulatory Board (PNGRB) sets the Technical Standards and Specifications including Safety Standards (T4S) for petroleum and petroleum product pipelines, which adopt ASME B31.4.</p>



<p class="wp-block-paragraph">Whether this naphtha line falls under the pipeline regime or is treated as in-plant piping under the Factories Act has not been publicly established, and it determines who owns the finding.</p>



<h3 class="wp-block-heading">Does India require functional safety and IEC 61511?</h3>



<p class="wp-block-paragraph">Not by a statute that names it, which is the same pattern seen in Qatar. IEC 61511 arrives through engineering standards, OISD standards, owner specifications, and procurement, as the recognized good engineering practice for a SIS rather than as a cited legal requirement.</p>



<p class="wp-block-paragraph">The functional safety work at an Indian cracker looks like the functional safety work anywhere. What differs is who checks it and how the requirement reaches the engineer.</p>



<h3 class="wp-block-heading">Who investigates an incident like this?</h3>



<p class="wp-block-paragraph">The illegal tap hypothesis makes this messy. If it was theft, it is a police matter, and a criminal investigation asks different questions than a process safety investigation. One wants to know who did it. The other wants to know why the site was exposed to it.</p>



<p class="wp-block-paragraph">India has no independent national accident investigation board comparable to the US Chemical Safety Board, so findings are released at the discretion of the operator and the state, if at all. That is why incidents like this generate a great deal of news coverage and very little transferable learning.</p>



<h2 class="wp-block-heading">What we do not know at the time of writing (July 2026)</h2>



<ul class="wp-block-list">
<li>Whether the release came from an illegal tap, a mechanical failure, or something else, and whether lightning played any role at all.</li>



<li>Whether an illegal tap was found, what it looked like, and how long it had been there.</li>



<li>Whether the line at the fire location was buried or above ground.</li>



<li>How long the release ran before it ignited, and whether anything other than a resident&#8217;s nose detected it.</li>



<li>The casualty count, which still varies widely across sources, and whether those hurt were mainly workers or mainly residents.</li>



<li>Whether third party interference appeared as an initiating event in HPL&#8217;s hazard study, and whether any investigation report will ever be published.</li>
</ul>



<h2 class="wp-block-heading">Frequently Asked Questions</h2>



<h4 class="wp-block-heading">I had never heard of illegal pipeline taps before this. How common are they, really?</h4>



<p class="wp-block-paragraph">Common enough that in several recent years they have caused most of the recorded spillages on European oil pipelines, which is not the answer most engineers expect. Concawe logged 28 theft-related spillages across the whole of 1971 to 2012, then 87 in 2015 alone and 60 out of 66 in 2016. Enforcement has knocked the peak down since, but Europe is the well-policed end of this problem, not the bad end. If your line runs through populated ground, assume someone has looked at it.</p>



<h4 class="wp-block-heading">How should a functional safety engineer think about illegal taps?</h4>



<p class="wp-block-paragraph">Start by admitting there is no clean answer. IEC 61511 appears to exempt this, since it excludes malicious action from its definition of human error and scopes its security requirement to the SIS itself rather than to the pipework. That reading is debatable, and reasonable engineers argue it. Whether a HAZOP or a LOPA ought to carry deliberate interference at all is unsettled, and the frequency data you would need to do it properly does not exist.</p>



<p class="wp-block-paragraph">What you can do is name the boundary out loud. Put third party interference on the table in the hazard study, say plainly that no SIF covers it, and record where the protection actually lives. That is worth more than letting everyone assume an instrumented function has it handled.</p>



<h4 class="wp-block-heading">This fire could clearly have been far worse. Is that a process safety win?</h4>



<p class="wp-block-paragraph">To some extent, yes. Isolation worked. The source was shut in, so the fire burned down to the inventory already trapped in the line rather than being fed indefinitely. That is the difference between a bad night and a catastrophe, and it is worth saying out loud even while the rest of the picture looks poor.</p>



<h4 class="wp-block-heading">If leak detection can&#8217;t take IPL credit, why do we bother having it?</h4>



<p class="wp-block-paragraph">Because it is not a prevention layer, it is a consequence-limiting one. Leak detection alarms to an operator, it does not act, so it does not clear the bar for an independent protection layer (IPL). What it does do is shorten the release duration, and release duration sets the size of the cloud, the size of the fire, and how far the fire reaches. A LOPA cannot count it. That has nothing to do with whether it is worth having. Do not confuse &#8220;no IPL credit&#8221; with &#8220;no value.&#8221;</p>



<h4 class="wp-block-heading">How do I justify spending on right-of-way security when the LOPA can&#8217;t credit it?</h4>



<p class="wp-block-paragraph">This is the uncomfortable part. The layers most likely to have prevented Haldia are precisely the ones a LOPA cannot count: the patrols, the fence, the community engagement, the surveillance. A LOPA is a tool for allocating instrumented risk reduction, not a complete account of what keeps a plant safe, and treating it as the latter is how a site ends up defending against the hazards it can quantify instead of the ones it has.</p>



<h2 class="wp-block-heading">Further Reading</h2>



<p class="wp-block-paragraph"><strong>From SIL Safe</strong></p>



<ul class="wp-block-list">
<li><a href="https://silsafe.net/functional-safety-for-the-process-industry/">Functional Safety for the Process Industry</a></li>



<li><a href="https://silsafe.net/qatar-gas-plant-explosion/">The Qatar Gas Plant Explosion: What We Know So Far</a></li>



<li><a href="https://silsafe.net/longview-chemical-tank-implosion/">The Longview Chemical Tank Implosion: What We Know So Far</a></li>



<li><a href="https://silsafe.net/garden-grove-chemical-incident/">The Garden Grove Chemical Incident: What We Know So Far</a></li>



<li><a href="https://silsafe.net/houston-recycling-fire/">Houston Recycling Fire: When Is a Recycling Center a Process Facility?</a></li>
</ul>



<p class="wp-block-paragraph"><strong>External resources</strong></p>



<p class="wp-block-paragraph">News coverage of the Haldia fire:</p>



<ul class="wp-block-list">
<li><a href="https://www.hydrocarbonprocessing.com/news/2026/06/several-injured-in-fire-at-haldia-petrochemicals-plant-in-eastern-india/" target="_blank" rel="noopener">Several injured in fire at Haldia Petrochemicals&#8217; plant in eastern India (Reuters via Hydrocarbon Processing)</a></li>



<li><a href="https://www.millenniumpost.in/amp/bengal/haldia-pipeline-fire-leaves-one-dead-over-25-injured-666385" target="_blank" rel="noopener">Haldia pipeline fire leaves one dead, over 25 injured (Millennium Post)</a></li>



<li><a href="https://www.theweek.in/news/india/2026/06/30/what-caused-the-fire-at-the-haldia-oil-refinery-in-bengal-several-injured.amp.html" target="_blank" rel="noopener">What caused the fire at the Haldia Petrochemical refinery in Bengal (The Week)</a></li>



<li><a href="https://tv9bangla.com/west-bengal/purba-medinipur/fire-breaks-out-at-haldia-petrochemical-1327012.html" target="_blank" rel="noopener">হলদিয়া পেট্রোকেমিক্যালে বিধ্বংসী আগুন (TV9 Bangla)</a></li>



<li><a href="https://bangla.asianetnews.com/west-bengal/fire-breaks-out-at-haldia-petrochemical-station-many-people-injured-absc/articleshow-mvrxy2b" target="_blank" rel="noopener">হলদিয়া পেট্রোকেমিক্যালে বিধ্বংসী আগুন, ঝলসে গেল অনেকে (Asianet News Bangla)</a></li>
</ul>



<p class="wp-block-paragraph">Standards, data, and background:</p>



<ul class="wp-block-list">
<li><a href="https://www.concawe.eu/publication/successfully-limiting-product-theft-from-european-oil-pipelines/" target="_blank" rel="noopener">Concawe: Successfully limiting product theft from European oil pipelines</a></li>



<li><a href="https://www.concawe.eu/publication/performance-of-european-cross-country-oil-pipelines-statistical-summary-of-reported-spillages-in-2023-and-since-1971/" target="_blank" rel="noopener">Concawe: Performance of European cross-country oil pipelines, spillages since 1971</a></li>



<li><a href="https://www.api.org/news-policy-and-issues/news/2022/04/28/api-enhances-pipeline-safety-with-two-updated-standards" target="_blank" rel="noopener">API: Enhanced pipeline safety through RP 1130 and RP 1175</a></li>



<li><a href="https://www.pipeline-journal.net/news/fuel-theft-illegal-tapping-ask-experts-questions-answered" target="_blank" rel="noopener">Pipeline Technology Journal: Fuel Theft and Illegal Tapping</a></li>



<li><a href="https://pgjonline.com/news/2026/february/mexican-authorities-uncover-tunnel-tapping-pemex-pipeline-in-fuel-theft-crackdown" target="_blank" rel="noopener">Pipeline &amp; Gas Journal: Mexican authorities uncover tunnel tapping Pemex pipeline</a></li>



<li><a href="https://insightcrime.org/news/underground-tunnels-discovered-mexico-reveal-sophistication-oil-theft-networks/" target="_blank" rel="noopener">InsightCrime: Underground tunnels reveal the sophistication of oil theft networks</a></li>



<li><a href="https://www.etvbharat.com/en/state/illegal-valve-found-in-indian-oil-pipeline-in-tonk-thieves-drilled-underground-pipeline-enn26071004134" target="_blank" rel="noopener">Illegal valve found in an Indian Oil pipeline in Tonk, Rajasthan (separate incident)</a></li>



<li><a href="https://ifbgoa.goa.gov.in/sites/default/files/Manufacture_Storage&amp;Import_of_Hazardous_Chemical_Rules%201989.pdf" target="_blank" rel="noopener">MSIHC Rules 1989 (full text)</a></li>



<li><a href="https://pngrb.gov.in/eng-web/regulation-t4s.html" target="_blank" rel="noopener">PNGRB: Technical Standards and Specifications including Safety Standards (T4S)</a></li>
</ul>



<p class="wp-block-paragraph">Functional safety is complex, and the stakes are high. If you have questions about your SIS design, SIL verification, or where to start with IEC 61511, the team at SIL Safe is here to help. Reach out to us today.</p>



<p class="wp-block-paragraph"><em>Image credits: the satellite view of the Haldia complex contains modified Copernicus Sentinel data (2025), Sentinel-2 cloudless by <a href="https://s2maps.eu" rel="nofollow noopener" target="_blank">EOX IT Services</a> (<a href="https://creativecommons.org/licenses/by/4.0" rel="nofollow noopener" target="_blank">CC BY 4.0</a>), with labels © OpenStreetMap contributors. The photograph of the Haldia Petrochemicals complex is by খাঁ শুভেন্দু via <a href="https://commons.wikimedia.org/wiki/File:Haldia_Petrochemicals_WP_20180710_20_28_49_Pro.jpg" target="_blank" rel="noopener">Wikimedia Commons</a>, licensed <a href="https://creativecommons.org/licenses/by-sa/4.0" rel="nofollow noopener" target="_blank">CC BY-SA 4.0</a>; it shows the complex in 2018 and is not an image of the June 2026 fire.</em></p>



<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "I had never heard of illegal pipeline taps before this. How common are they, really?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Common enough that in several recent years they have caused most of the recorded spillages on European oil pipelines, which is not the answer most engineers expect. Concawe logged 28 theft-related spillages across the whole of 1971 to 2012, then 87 in 2015 alone and 60 out of 66 in 2016. Enforcement has knocked the peak down since, but Europe is the well-policed end of this problem, not the bad end. If your line runs through populated ground, assume someone has looked at it."
      }
    },
    {
      "@type": "Question",
      "name": "How should a functional safety engineer think about illegal taps?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Start by admitting there is no clean answer. IEC 61511 appears to exempt this, since it excludes malicious action from its definition of human error and scopes its security requirement to the SIS itself rather than to the pipework. That reading is debatable, and reasonable engineers argue it. Whether a HAZOP or a LOPA ought to carry deliberate interference at all is unsettled, and the frequency data you would need to do it properly does not exist. What you can do is name the boundary out loud. Put third party interference on the table in the hazard study, say plainly that no SIF covers it, and record where the protection actually lives. That is worth more than letting everyone assume an instrumented function has it handled."
      }
    },
    {
      "@type": "Question",
      "name": "This fire could clearly have been far worse. Is that a process safety win?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "To some extent, yes. Isolation worked. The source was shut in, so the fire burned down to the inventory already trapped in the line rather than being fed indefinitely. That is the difference between a bad night and a catastrophe, and it is worth saying out loud even while the rest of the picture looks poor."
      }
    },
    {
      "@type": "Question",
      "name": "If leak detection can't take IPL credit, why do we bother having it?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Because it is not a prevention layer, it is a consequence-limiting one. Leak detection alarms to an operator, it does not act, so it does not clear the bar for an independent protection layer (IPL). What it does do is shorten the release duration, and release duration sets the size of the cloud, the size of the fire, and how far the fire reaches. A LOPA cannot count it. That has nothing to do with whether it is worth having. Do not confuse \"no IPL credit\" with \"no value.\""
      }
    },
    {
      "@type": "Question",
      "name": "How do I justify spending on right-of-way security when the LOPA can't credit it?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "This is the uncomfortable part. The layers most likely to have prevented Haldia are precisely the ones a LOPA cannot count: the patrols, the fence, the community engagement, the surveillance. A LOPA is a tool for allocating instrumented risk reduction, not a complete account of what keeps a plant safe, and treating it as the latter is how a site ends up defending against the hazards it can quantify instead of the ones it has."
      }
    }
  ]
}
</script>

]]></content:encoded>
					
					<wfw:commentRss>https://silsafe.net/haldia-naphtha-pipeline-fire/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Houston Recycling Fire: When Is a Recycling Center a Process Facility?</title>
		<link>https://silsafe.net/houston-recycling-fire/</link>
					<comments>https://silsafe.net/houston-recycling-fire/#respond</comments>
		
		<dc:creator><![CDATA[mamerten]]></dc:creator>
		<pubDate>Fri, 03 Jul 2026 22:16:44 +0000</pubDate>
				<category><![CDATA[Beginner]]></category>
		<guid isPermaLink="false">https://silsafe.net/?p=7302</guid>

					<description><![CDATA[A tire fire at a Houston recycling yard raises a sharper question for functional safety practitioners: is a recycling center a process facility, was the fire a process safety event, and would PSM, RMP, or IEC 61511 ever apply? For a scrap and tire yard, almost never, and what decides it is the chemistry on site.]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">On June 22, 2026, a fire tore through a pile of scrap tires and debris at Mammoth Metal Recycling in Houston. It drew roughly 200 firefighters, pushed black smoke across the city for miles, and burned close enough to a neighborhood that crews worked to keep it from jumping a tree line into homes. No one was hurt, and no structures were lost. The Houston Fire Department (HFD), HazMat teams, and air-quality monitors from city and state agencies responded, with early official readings below the National Ambient Air Quality Standard (NAAQS) level of concern.</p>



<p class="wp-block-paragraph">The cause is still under investigation, so what follows is based on publicly available information and is not a root cause analysis. For functional safety practitioners, the fire raises three cleaner questions:</p>



<ul class="wp-block-list">
<li>Is a place like this a process facility?</li>


<li>Was the fire a process safety event?</li>


<li>Would IEC 61511, OSHA&#8217;s Process Safety Management (PSM) standard, or the EPA&#8217;s Risk Management Program (RMP) ever reach it?</li>

</ul>



<p class="wp-block-paragraph">A scrap tire and metal yard is almost certainly none of those things, and walking through why draws a clean line around what functional safety actually governs.</p>



<h2 class="wp-block-heading">What happened at the Mammoth Metal Recycling fire</h2>



<p class="wp-block-paragraph">The fire was reported in the early afternoon of June 22, 2026, burning in a debris field roughly the size of a football field behind a warehouse. Scrap tires were the primary fuel, and the rubber made the fire slow to extinguish, so HFD escalated to a multi-alarm response of about 200 firefighters. No injuries were reported, and no evacuations were ordered, though the fire burned close to homes and crews worked to keep it from spreading past a tree line into the neighborhood.</p>


<div class="wp-block-image">
<figure class="alignright size-full is-resized"><img loading="lazy" decoding="async" width="500" height="500" src="https://silsafe.net/wp-content/uploads/2026/07/epa-logo.png" alt="US Environmental Protection Agency (EPA) logo" class="wp-image-7119" style="width:120px" srcset="https://silsafe.net/wp-content/uploads/2026/07/epa-logo.png 500w, https://silsafe.net/wp-content/uploads/2026/07/epa-logo-300x300.png 300w, https://silsafe.net/wp-content/uploads/2026/07/epa-logo-150x150.png 150w" sizes="auto, (max-width: 500px) 100vw, 500px" /></figure>
</div>


<p class="wp-block-paragraph">The cause remained under investigation by HFD arson investigators at the time of writing, with no determination of accidental or intentional origin. Early official air monitoring by the Houston Health Department and the Texas Commission on Environmental Quality (TCEQ) reported particulate levels below the NAAQS level of concern, though a local air-quality group disputed how fully the plume was captured. The EPA was notified the same day and opened an on-scene coordinator response for the fire, with no report made to the National Response Center. EPA later confirmed no offsite air detections and no impact to Brays Bayou.</p>



<h2 class="wp-block-heading">Is a recycling center a process facility?</h2>



<p class="wp-block-paragraph">&#8220;Recycling&#8221; names an end goal, material recovery, not a process type. It covers everything from a shredder yard to a chemical plant, so the label by itself says nothing about whether a site is a process facility.</p>



<p class="wp-block-paragraph">A process facility continuously or in batches transforms, separates, or reacts materials. It usually holds hazardous inventories under pressure or temperature and relies on instrumented systems, including a safety instrumented system (SIS), to keep the process inside safe limits. That is the world IEC 61511, PSM, and RMP were written for. Whether a given recycling center belongs in it depends entirely on what happens on the pad.</p>



<h3 class="wp-block-heading">Recycling that is not a process facility</h3>



<p class="wp-block-paragraph">The everyday picture of recycling, aluminum cans, cardboard, and bottles sorted and baled at a material recovery facility, is mechanical and optical separation with no chemical process anywhere in it. Scrap tire operations sit in the same category: collection, shredding, and crumb rubber production, where the hazard is a large combustible solid pile rather than a contained chemical reaction. So does scrap metal shredding, shearing, and baling, the smasher-and-cutter operation driven by hydraulics and motors with no hazardous chemical inventory.</p>



<p class="wp-block-paragraph">The common thread across all of these is mechanical size reduction and sorting. There is no process holding a hazardous inventory, and nothing a safety instrumented function (SIF) would protect.</p>



<h3 class="wp-block-heading">Recycling that is a process facility</h3>



<p class="wp-block-paragraph">Other recycling operations are process plants in every meaningful sense. Solvent recovery and reclamation distills and re-separates spent solvents in a continuous chemical process, holding flammable and toxic inventories. Used-oil re-refining runs distillation and hydrotreating steps that put it closer to a small refinery than a scrap yard. Plastics pyrolysis and other advanced, or chemical, recycling thermally crack feedstock into oils and gases under heat and pressure. Lithium-ion battery recycling pairs shredding with chemical leaching, solvent extraction, and thermal steps, and the cell chemistry itself adds fire and toxic-release hazards.</p>



<p class="wp-block-paragraph">These operations run reactors and separation equipment on hazardous inventories and can carry SIFs, which puts them squarely inside the process facility definition. The same word on the sign, a completely different regulatory world. What decides it is the chemistry on site, not the &#8220;recycling&#8221; label.</p>



<h2 class="wp-block-heading">Was the Houston recycling fire a process safety event?</h2>



<p class="wp-block-paragraph">A process safety event, in the API RP 754 and Center for Chemical Process Safety (CCPS) sense, is a loss of primary containment of a hazardous material from a process. It is structured into Tier 1 through Tier 4 indicators used at refining, petrochemical, and similar process facilities.</p>



<p class="wp-block-paragraph">The Houston fire falls outside that definition on two independent counts:</p>



<ul class="wp-block-list">
<li>The site was not a process facility, so there was no process for a hazardous material to be released from.</li>


<li>Even if it had been, nothing was lost from primary containment; the tires burned as an open-air stored pile, not a contained inventory.</li>

</ul>



<p class="wp-block-paragraph">The event is better classified as an industrial or waste fire with an air-quality dimension, which is why the responders were fire, environmental, and public-health bodies rather than process safety regulators.</p>



<h2 class="wp-block-heading">Do process safety regulations apply to recycling centers?</h2>



<p class="wp-block-paragraph">Yes, but only when the recycling center is a process facility. The trigger is the chemicals a site holds, not the word &#8220;recycling,&#8221; so the same question has different answers for a shredder yard and a solvent recovery plant.</p>



<h3 class="wp-block-heading">OSHA PSM and EPA RMP in the United States</h3>



<p class="wp-block-paragraph">OSHA&#8217;s PSM standard is triggered by threshold quantities of listed highly hazardous chemicals, including flammable gases and liquids above 10,000 lb. The EPA&#8217;s RMP applies the same threshold logic to regulated substances tied to offsite consequence. A recycling operation can hold enough regulated inventory to cross these thresholds when it does real chemistry: solvent recovery, used-oil re-refining, or chemical recycling with significant flammable or toxic storage are the usual candidates.</p>



<h3 class="wp-block-heading">Seveso and COMAH in Europe and the United Kingdom</h3>



<p class="wp-block-paragraph">The Seveso III Directive across the EU and the Control of Major Accident Hazards (COMAH) Regulations in the UK apply the same establishment-and-threshold logic, catching any site, recycling included, that holds dangerous substances above listed quantities. Chemical recycling, solvent handling, or large flammable storage can put a recycling site into a lower or upper tier under these regimes. The framework names and thresholds change by jurisdiction, but the underlying test, a hazardous chemical inventory versus mechanical handling, travels unchanged.</p>



<h3 class="wp-block-heading">Where IEC 61511 fits</h3>



<p class="wp-block-paragraph">A recycling operation that is a process facility, pyrolysis, re-refining, battery reprocessing, runs the kind of process IEC 61511 was written for.</p>



<h2 class="wp-block-heading">The rules that applied to the Mammoth site</h2>


<div class="wp-block-image">
<figure class="alignright size-full is-resized"><img loading="lazy" decoding="async" width="316" height="316" src="https://silsafe.net/wp-content/uploads/2026/07/tceq-logo.webp" alt="Texas Commission on Environmental Quality (TCEQ) logo" class="wp-image-7305" style="width:120px" srcset="https://silsafe.net/wp-content/uploads/2026/07/tceq-logo.webp 316w, https://silsafe.net/wp-content/uploads/2026/07/tceq-logo-300x300.webp 300w, https://silsafe.net/wp-content/uploads/2026/07/tceq-logo-150x150.webp 150w" sizes="auto, (max-width: 316px) 100vw, 316px" /></figure>
</div>


<p class="wp-block-paragraph">TCEQ&#8217;s scrap tire program required registration, the City of Houston&#8217;s scrap tire ordinance required a permit, and open-burning prohibitions, Clean Air Act air-quality standards, and the fire code covered the rest. Reporting indicated the operator held neither a TCEQ scrap tire registration nor a city scrap tire permit, and had been cited for illegal burning in the weeks before the fire.</p>



<p class="wp-block-paragraph">The company carried a broader run of recent trouble as well: a delinquent property-tax suit and a federal fraud case tied to affiliated recycling companies, unrelated to the fire but part of the operator&#8217;s recent record. Emergency response ran through HFD, HazMat, and the EPA on-scene coordinator, with cleanup coordinated by the City rather than any process safety authority. A site can pose a real hazard to a neighboring community and still sit entirely outside process safety law.</p>



<h2 class="wp-block-heading">What we do not know at the time of writing (July 2026)</h2>



<p class="wp-block-paragraph">Several things were still open at the time of writing:</p>



<ul class="wp-block-list">
<li>What ignited the pile: HFD arson investigators had not established a cause, and no accidental-versus-intentional determination had been made.</li>


<li>Any longer-term or independent assessment of neighborhood exposure, beyond the response-phase monitoring that reported no significant detections.</li>


<li>Any residual soil contamination at the site from the pyrolytic oil that tire fires generate; EPA reported no impact to Brays Bayou.</li>


<li>The site&#8217;s regulatory and cleanup path forward, with the TCEQ investigation open and the permit and property status unresolved.</li>

</ul>



<h2 class="wp-block-heading">Frequently Asked Questions</h2>



<h4 class="wp-block-heading">What&#8217;s the formal definition of a process facility, and what says it?</h4>



<p class="wp-block-paragraph">No single standard defines &#8220;process facility&#8221; as a stand-alone term, which trips people up. The load-bearing definitions come from three places:</p>



<ul class="wp-block-list">
<li>OSHA&#8217;s PSM rule defines a &#8220;process&#8221; as any activity involving a highly hazardous chemical: its use, storage, manufacturing, handling, or on-site movement.</li>


<li>API RP 754 and CCPS define the process safety event, anchored to loss of primary containment from a process.</li>


<li>IEC 61511 frames the &#8220;process industry&#8221; for functional safety.</li>

</ul>



<p class="wp-block-paragraph">So when you ask for the definition of a process facility, you&#8217;re really asking whether there&#8217;s a process handling hazardous chemicals, and each framework answers that in its own way.</p>



<h4 class="wp-block-heading">There&#8217;s a municipal recycling center near me that only takes glass, cardboard, and plastic. Do you think that&#8217;s a process facility?</h4>



<p class="wp-block-paragraph">Almost certainly not. Sorting and baling glass, cardboard, and plastic is mechanical and optical separation with no chemical process and no hazardous inventory. There&#8217;s nothing a SIF would protect, so it sits outside PSM, RMP, and IEC 61511.</p>



<h4 class="wp-block-heading">I dropped off a pile of old lithium-ion batteries for recycling. Is wherever they end up likely a &#8220;process facility&#8221;?</h4>



<p class="wp-block-paragraph">More likely than the glass-and-cardboard center, yes. Lithium-ion recycling usually pairs shredding with chemical steps: leaching, solvent extraction, and sometimes thermal processing. Add the cell chemistry&#8217;s own fire and toxic-release hazards, and a full-scale battery recycler can hold enough regulated material to look and behave like a process facility. A simple collection point that only stages batteries for shipment somewhere else would not.</p>



<h4 class="wp-block-heading">Our recycling site handles solvents and we&#8217;re in Europe. Should we be looking at Seveso?</h4>



<p class="wp-block-paragraph">Possibly, and it&#8217;s worth checking rather than assuming. Seveso, and COMAH in the UK, turns on how much dangerous substance you hold at once, not on whether you call yourself a recycler. If your solvent inventory crosses the lower-tier threshold, you&#8217;re a Seveso establishment with notification and major-accident-prevention duties, and the upper-tier threshold pulls in a full safety report. Add up your maximum on-site inventory, including what&#8217;s in process and sitting in pipework, and compare it against the Annex thresholds.</p>



<h2 class="wp-block-heading">Further Reading</h2>



<p class="wp-block-paragraph"><strong>From SIL Safe</strong></p>



<ul class="wp-block-list">
<li><a href="https://silsafe.net/functional-safety-for-the-process-industry/">Functional Safety for the Process Industry</a></li>



<li><a href="https://silsafe.net/functional-safety-vs-occupational-safety/">Functional Safety Is Not the Same as Occupational Safety</a></li>



<li><a href="https://silsafe.net/longview-chemical-tank-implosion/">Longview Chemical Tank Implosion</a></li>



<li><a href="https://silsafe.net/garden-grove-chemical-incident/">Garden Grove Chemical Incident</a></li>
</ul>



<p class="wp-block-paragraph"><strong>External resources</strong></p>



<ul class="wp-block-list">
<li><a href="https://response.epa.gov/site/site_profile.aspx?site_id=17336" target="_blank" rel="noopener">EPA Emergency Response site for the Houston tire fire</a></li>



<li><a href="https://archive.epa.gov/epawaste/conserve/materials/tires/web/html/fires.html" target="_blank" rel="noopener">US EPA: Tire Fires (hazards, cleanup, why they are hard to fight)</a></li>



<li><a href="https://www.fox26houston.com/news/what-we-know-about-company-behind-massive-southeast-houston-fire" target="_blank" rel="noopener">FOX 26 Houston: background on the company behind the fire</a></li>



<li><a href="https://www.api.org/-/media/files/oil-and-natural-gas/refining/process%20safety/api-guide-to-report-pses-2022.pdf" target="_blank" rel="noopener">API guide to reporting process safety events (API RP 754 definition)</a></li>
</ul>



<p class="wp-block-paragraph">Functional safety is complex, and the stakes are high. If you have questions about your SIS design, SIL verification, or where to start with IEC 61511, the team at SIL Safe is here to help. Reach out to us today.</p>



<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "What's the formal definition of a process facility, and what says it?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No single standard defines \"process facility\" as a stand-alone term, which trips people up. The load-bearing definitions come from three places: OSHA's PSM rule defines a \"process\" as any activity involving a highly hazardous chemical: its use, storage, manufacturing, handling, or on-site movement. API RP 754 and CCPS define the process safety event, anchored to loss of primary containment from a process. IEC 61511 frames the \"process industry\" for functional safety. So when you ask for the definition of a process facility, you're really asking whether there's a process handling hazardous chemicals, and each framework answers that in its own way."
      }
    },
    {
      "@type": "Question",
      "name": "There's a municipal recycling center near me that only takes glass, cardboard, and plastic. Do you think that's a process facility?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Almost certainly not. Sorting and baling glass, cardboard, and plastic is mechanical and optical separation with no chemical process and no hazardous inventory. There's nothing a SIF would protect, so it sits outside PSM, RMP, and IEC 61511."
      }
    },
    {
      "@type": "Question",
      "name": "I dropped off a pile of old lithium-ion batteries for recycling. Is wherever they end up likely a \"process facility\"?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "More likely than the glass-and-cardboard center, yes. Lithium-ion recycling usually pairs shredding with chemical steps: leaching, solvent extraction, and sometimes thermal processing. Add the cell chemistry's own fire and toxic-release hazards, and a full-scale battery recycler can hold enough regulated material to look and behave like a process facility. A simple collection point that only stages batteries for shipment somewhere else would not."
      }
    },
    {
      "@type": "Question",
      "name": "Our recycling site handles solvents and we're in Europe. Should we be looking at Seveso?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Possibly, and it's worth checking rather than assuming. Seveso, and COMAH in the UK, turns on how much dangerous substance you hold at once, not on whether you call yourself a recycler. If your solvent inventory crosses the lower-tier threshold, you're a Seveso establishment with notification and major-accident-prevention duties, and the upper-tier threshold pulls in a full safety report. Add up your maximum on-site inventory, including what's in process and sitting in pipework, and compare it against the Annex thresholds."
      }
    }
  ]
}
</script>
]]></content:encoded>
					
					<wfw:commentRss>https://silsafe.net/houston-recycling-fire/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Who Certifies Functional Safety Equipment, and Who Accepts It</title>
		<link>https://silsafe.net/who-certifies-functional-safety-equipment/</link>
					<comments>https://silsafe.net/who-certifies-functional-safety-equipment/#respond</comments>
		
		<dc:creator><![CDATA[mamerten]]></dc:creator>
		<pubDate>Sun, 28 Jun 2026 00:53:12 +0000</pubDate>
				<category><![CDATA[Beginner]]></category>
		<guid isPermaLink="false">https://silsafe.net/?p=7030</guid>

					<description><![CDATA[A practitioner’s map of who certifies functional safety equipment and who accepts it: the manufacturer’s own documents, the certification body and the accreditation body behind it, Global ACI at the top, then the NRTL, CE marking, Notified Body and authority having jurisdiction, and how the hazardous-area certificate fits in.]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Engineering runs on a mix of organizations, certificates, and marks. Who does what, when, and which document proves it is rarely obvious. A Safety Integrity Level (SIL) certificate sitting on an instrument datasheet is the everyday version of that question: who confirms the rating is real, and who on your site has to accept it? The certificate is a global document tied to the part type, while the manufacturer’s own Declaration of Conformity rides along in the part’s paperwork. The certification body that issues the certificate sits inside a chain that runs up through an accreditation body to a single global body at the top, and that chain is separate from the regulatory authority that decides whether your installation is legal. It is easiest to untangle from the narrow end, the certificate in your hand, and work up.</p>



<h2 class="wp-block-heading">The manufacturer and its own documents</h2>



<p class="wp-block-paragraph">The manufacturer designs and builds the device, so it is where the paperwork chain starts, but it cannot independently certify its own product. What it can do is issue its own documents. The SIL Declaration of Conformity is the manufacturer’s own statement that the device conforms. The Product Safety Manual carries the constraints you have to honor in service: the proof test, the proof test interval (TI), and the useful life. Both usually arrive with the physical item, in the box or the shipping package. And both are self-issued by the party with an interest in selling the device, which is exactly why the rating that carries real weight has to come from somewhere independent.</p>



<h2 class="wp-block-heading">The certification body that issues the certificate</h2>



<p class="wp-block-paragraph">A certification body (CB) is the independent organization a manufacturer hires to assess the device against IEC 61508 and issue the SIL certificate. That certificate is the independent artifact: it states the device meets IEC 61508 to a stated SIL or systematic capability (SC), and it carries the failure-rate data and assumptions that later feed a probability of failure on demand (PFDavg) calculation. It generally covers a product group or family rather than an individual unit by serial number, so it applies to the model, not the specific item in your hand. Names you will see include TÜV Rheinland, Exida, and UL. None of this is legal permission to sell or install anything. A SIL certificate is third-party evidence that the device is capable, sought to satisfy customers and specifications rather than because any law demands it.</p>



<h3 class="wp-block-heading">What a certification body checks</h3>



<p class="wp-block-paragraph">The CB performs or reviews the failure modes, effects and diagnostic analysis (FMEDA), the systematic-capability case, and the failure-rate numbers, then issues the certificate to a stated SIL or SC for a defined instrument and its safe-state assumptions. It also assesses the manufacturer’s functional safety management system and re-audits it on a cycle, so the certificate reflects an ongoing capability rather than a one-time test. How much of this applies depends on the route taken and the part’s history: a device with real field history can go a proven-in-use route, while a clean-sheet design gets the full assessment.</p>



<h3 class="wp-block-heading">Why one certifier’s certificate is trusted</h3>



<p class="wp-block-paragraph">A certificate is only as good as the body that signed it, and a body earns that standing by being accredited. An unaccredited certificate is a logo with no chain behind it. The body that grants that standing is the accreditation body.</p>



<h2 class="wp-block-heading">The accreditation body behind the certifier</h2>



<p class="wp-block-paragraph">An accreditation body (AB) does not certify products. It assesses and authorizes the certification bodies themselves, confirming they are competent to certify against standards like IEC 61508. The ABs work to ISO/IEC 17011 while the CBs work to ISO/IEC 17065, and the same certification body is often accredited by more than one.</p>



<h3 class="wp-block-heading">Regional accreditation bodies</h3>



<p class="wp-block-paragraph">Accreditation bodies are regional. ANAB is the dominant one in the United States, DAkkS the largest in Europe, with UKAS in the United Kingdom and the Standards Council of Canada (SCC) in Canada, plus COFRAC, ENAC, INAB, SWEDAC, and DANAK across other European countries. The Middle East generally leans on US and European bodies. Which one sits behind a given certificate is usually a matter of market, tradition, or law rather than any technical difference.</p>



<h3 class="wp-block-heading">What accreditation proves and what it does not</h3>



<p class="wp-block-paragraph">Accreditation confirms the certifier is competent and consistent. It does not confirm that any single certified device is the right choice for your application. That judgment stays with you, at selection and during verification.</p>


<div class="wp-block-image">
<figure class="alignright size-full is-resized"><img loading="lazy" decoding="async" width="600" height="339" src="https://silsafe.net/wp-content/uploads/2026/06/global-aci-logo.png" alt="Global ACI logo, the Global Accreditation Cooperation Incorporated" class="wp-image-7011" style="width:200px" srcset="https://silsafe.net/wp-content/uploads/2026/06/global-aci-logo.png 600w, https://silsafe.net/wp-content/uploads/2026/06/global-aci-logo-300x170.png 300w" sizes="auto, (max-width: 600px) 100vw, 600px" /></figure>
</div>


<h2 class="wp-block-heading">Global ACI at the top of the chain</h2>



<p class="wp-block-paragraph">One tier sits above the accreditation bodies: the Global Accreditation Cooperation Incorporated, which operates as Global ACI and began on 1 January 2026, after the former IAF (which covered certification) and ILAC (testing, calibration, and inspection) merged into it. Global ACI does not accredit certification bodies directly. It runs the mutual-recognition arrangements among the accreditation bodies and peer-evaluates them, which is what lets a SIL certificate from an accredited body in one country be honored in another. It is the cap on the chain that ultimately stands behind the rating on the datasheet.</p>



<h2 class="wp-block-heading">The United States product-listing route: the NRTL</h2>



<p class="wp-block-paragraph">A Nationally Recognized Testing Laboratory (NRTL) is a lab that the US Occupational Safety and Health Administration (OSHA) recognizes to test and list products against US safety standards. UL, FM, and Intertek are examples. The listing is usually to the specific product-family standard that applies, a dedicated standard for molded-case circuit breakers, say, rather than to one generic safety standard. This is product-level conformity work that sits alongside the certification body, but it covers product and electrical safety, not functional safety. An NRTL-listed device is not SIL-certified by virtue of that listing, and the two say nothing about each other.</p>



<h3 class="wp-block-heading">UL listing versus the NRTL category</h3>



<p class="wp-block-paragraph">&#8220;UL listed&#8221; gets used as if it meant &#8220;NRTL listed,&#8221; but UL is one NRTL among several, not the category itself. UL also writes standards, which doubles the confusion: another lab such as Intertek can certify a product to a UL standard, so &#8220;to a UL standard&#8221; does not mean &#8220;by the company that is UL.&#8221; The clean way to say it is that a part is certified to a particular standard by a lab on the NRTL program, and that is the &#8220;listed&#8221; running through US codes like the National Electrical Code (NEC).</p>


<div class="wp-block-image">
<figure class="alignright size-full is-resized"><img loading="lazy" decoding="async" width="960" height="686" src="https://silsafe.net/wp-content/uploads/2026/06/ce-marking-logo.png" alt="The official CE marking conformity symbol" class="wp-image-6983" style="width:120px" srcset="https://silsafe.net/wp-content/uploads/2026/06/ce-marking-logo.png 960w, https://silsafe.net/wp-content/uploads/2026/06/ce-marking-logo-300x214.png 300w, https://silsafe.net/wp-content/uploads/2026/06/ce-marking-logo-768x549.png 768w" sizes="auto, (max-width: 960px) 100vw, 960px" /></figure>
</div>


<h2 class="wp-block-heading">CE marking and market access in Europe</h2>



<p class="wp-block-paragraph">CE marking is the manufacturer’s self-declaration that a product meets every European Union directive that applies to it, backed by a technical file and a signed EU Declaration of Conformity, which lets it move freely across the European Economic Area (EEA). For low-risk products the manufacturer self-assesses; for higher-risk safety equipment under the Machinery Directive or ATEX, a Notified Body has to assess conformity before the mark goes on. But CE marking is about legal access to the EU market, not IEC 61508. A device can be SIL-certified and CE-marked independently, and neither one implies the other.</p>



<p class="wp-block-paragraph">A near-identical mark, with the two letters set closer together and often called the “China Export” mark, turns up on some imported products; it is easy to mistake for the CE mark but carries no EU conformity meaning.</p>


<div class="wp-block-image">
<figure class="alignright size-full is-resized"><img loading="lazy" decoding="async" width="960" height="960" src="https://silsafe.net/wp-content/uploads/2026/06/ukca-marking-logo.png" alt="The official UKCA marking conformity symbol" class="wp-image-6984" style="width:100px" srcset="https://silsafe.net/wp-content/uploads/2026/06/ukca-marking-logo.png 960w, https://silsafe.net/wp-content/uploads/2026/06/ukca-marking-logo-300x300.png 300w, https://silsafe.net/wp-content/uploads/2026/06/ukca-marking-logo-150x150.png 150w, https://silsafe.net/wp-content/uploads/2026/06/ukca-marking-logo-768x768.png 768w" sizes="auto, (max-width: 960px) 100vw, 960px" /></figure>
</div>


<h3 class="wp-block-heading">UKCA and Great Britain</h3>



<p class="wp-block-paragraph">UKCA, the UK Conformity Assessed marking, is the Great Britain counterpart, handled by UK approved bodies accredited by UKAS. As of 2026, Great Britain accepts CE marking indefinitely for most goods, so UKCA is available rather than a hard switchover for general products. Medical devices, construction products, and marine equipment are the live exceptions, and Northern Ireland still follows the EU and CE route.</p>



<h2 class="wp-block-heading">The accepting authority, region by region</h2>



<p class="wp-block-paragraph">The chain so far tells you a device is capable. A different set of bodies decides whether your specific installation is legal and acceptable, and which body that is depends on where in the world you are. The four cases below are the common ones; the same pattern repeats elsewhere with local marks and authorities, such as the RCM mark in Australia.</p>



<h3 class="wp-block-heading">Europe: the Notified Body</h3>



<p class="wp-block-paragraph">A Notified Body (NB) is designated by an EU member state to carry out the conformity assessment a directive requires before a product or installation can legally wear the CE mark. On a European project it gets embedded enough that, to the working engineers, it can feel like a member of the project: reviewing and approving specific deliverables, paid by the project, operating at the level of regulatory compliance rather than SIL determination. TÜV Rheinland, for instance, acts as a Notified Body under the Pressure Equipment Directive.</p>



<h3 class="wp-block-heading">The United States: the authority having jurisdiction (AHJ)</h3>



<p class="wp-block-paragraph">The AHJ enforces the locally adopted codes and accepts the installation. In the US it is often a city or county authority, and occasionally OSHA. It is rarely as involved as a European Notified Body, and it leans on product listings and certificates as evidence rather than producing any of its own. Its functional safety knowledge varies a lot by region: an AHJ somewhere with little oil and gas may know little or nothing about functional safety, while in the refinery-heavy southern states such as Texas, Louisiana, and Mississippi the AHJ is often very fluent in it.</p>



<h3 class="wp-block-heading">The United Kingdom</h3>



<p class="wp-block-paragraph">For a major-hazard process site, the regulator is the Control of Major Accident Hazards (COMAH) Competent Authority, the Health and Safety Executive (HSE) acting jointly with the relevant environment agency. Unlike a variable US AHJ, this regulator is fluent in functional safety; HSE and CDOIF guidance is built directly on IEC 61508 and IEC 61511. Product conformity runs through UK approved bodies accredited by UKAS, under the UKCA route above.</p>


<div class="wp-block-image">
<figure class="alignright size-full is-resized"><img loading="lazy" decoding="async" width="150" height="150" src="https://silsafe.net/wp-content/uploads/2026/06/ccsa-mark.png" alt="The cCSAus certification mark, indicating CSA Group certification for Canada and the United States" class="wp-image-7033" style="width:124px;height:auto"/></figure>
</div>


<h3 class="wp-block-heading">Canada</h3>



<p class="wp-block-paragraph">In Canada, electrical equipment has to be certified by an SCC-accredited certification body and carry a recognized Canadian mark, with SCC as the national accreditation body. Enforcement is provincial: electrical safety authorities act as the AHJ and look for an SCC-accredited mark rather than a particular brand. The Canadian “c” tells the story. A cUL or cCSAus mark covers Canada, while a US-only UL mark without the c, or a CE mark on its own, does not.</p>


<div class="wp-block-image">
<figure class="alignright size-full is-resized"><img loading="lazy" decoding="async" width="960" height="832" src="https://silsafe.net/wp-content/uploads/2026/06/ex-mark-atex.png" alt="The Ex explosion protection mark used on ATEX-certified equipment" class="wp-image-7006" style="width:100px" srcset="https://silsafe.net/wp-content/uploads/2026/06/ex-mark-atex.png 960w, https://silsafe.net/wp-content/uploads/2026/06/ex-mark-atex-300x260.png 300w, https://silsafe.net/wp-content/uploads/2026/06/ex-mark-atex-768x666.png 768w" sizes="auto, (max-width: 960px) 100vw, 960px" /></figure>
</div>


<h2 class="wp-block-heading">Hazardous areas and the second certification stream</h2>



<p class="wp-block-paragraph">Process functional safety often involves flammable or explosive gases, vapors, and liquids, so the instruments and valves running a safety function frequently sit in a hazardous area and need a second, separate certification for explosion protection. IECEx is the global scheme for that, ATEX is its EU directive counterpart, and North America runs its own route through the NEC and NRTL listings. A field instrument therefore commonly carries two certifications at once: a SIL certificate for its functional safety, and an Ex certificate for the area it lives in.</p>



<p class="wp-block-paragraph">Behind the Ex certificate sits its own series of standards: internationally that is mainly the IEC 60079 series for explosive atmospheres, with a separate set used in the United States, not covered here. Hazardous-area compliance runs on its own standards and its own paperwork, parallel to the functional safety chain rather than part of it.</p>



<h2 class="wp-block-heading">Conformity assessment and the conformity assessment body</h2>



<p class="wp-block-paragraph">Everything above is a form of conformity assessment, the umbrella term for showing that a product or system meets a standard through testing, inspection, and certification. Functional safety certification to IEC 61508 is one corner of it.</p>



<p class="wp-block-paragraph">A conformity assessment body (CAB) is the catch-all name for any organization doing that testing or certifying, so the certification body, the NRTL, and the Ex certification body (ExCB) are all conformity assessment bodies. The accreditation bodies and Global ACI sit above them all, vouching for the assessors rather than assessing products.</p>



<h2 class="wp-block-heading">Common mistakes</h2>



<ul class="wp-block-list">
<li>The functional safety team designs the safety functions, a different team rates the hazardous areas, and the two never compare notes. The instrument then shows up without the hazardous-area rating it needed, or wearing an expensive Ex rating it never did.</li>



<li>Reading a device’s SIL certificate as the SIL of the whole loop. A SIL-certified instrument does not make your safety instrumented function (SIF) that SIL. Element capability is one input, and the SIF’s actual SIL comes from its architecture, its PFDavg, and its proof testing.</li>



<li>Treating a CE mark as proof a device is SIL-certified. It says nothing about functional safety.</li>



<li>Taking a China Export mark, the kind with the letters spaced tighter, as a genuine CE mark.</li>



<li>Assuming an NRTL or UL listing covers functional safety, when it covers product and electrical safety.</li>



<li>Accepting a vendor certificate at face value with no accreditation body anywhere behind it.</li>
</ul>



<h2 class="wp-block-heading">Summary of bodies and documents</h2>



<h3 class="wp-block-heading">Bodies and organizations</h3>



<ul class="wp-block-list">
<li><strong>Manufacturer:</strong> makes the device and self-declares conformity.</li>



<li><strong>Certification body (CB):</strong> independent issuer of the SIL certificate against IEC 61508 (TÜV, Exida, UL, CSA Group).</li>



<li><strong>Accreditation body (AB):</strong> authorizes and oversees the certification bodies; regional (ANAB, UKAS, DAkkS, SCC).</li>



<li><strong>Global ACI:</strong> single international body over the accreditation bodies, running mutual recognition.</li>



<li><strong>NRTL:</strong> OSHA-recognized US lab that tests and lists products for product and electrical safety.</li>



<li><strong>Notified Body (NB):</strong> EU-designated body for the conformity assessment behind CE marking, often project-embedded; the UK equivalent is the UK approved body.</li>



<li><strong>Authority having jurisdiction (AHJ):</strong> the authority that accepts the installation, local city or county in the US, provincial in Canada, and the COMAH Competent Authority (HSE) for UK major-hazard sites.</li>



<li><strong>ExCB:</strong> certification body that issues Ex certificates under IECEx.</li>
</ul>



<h3 class="wp-block-heading">Documents in play</h3>



<ul class="wp-block-list">
<li><strong>SIL certificate:</strong> third-party evidence a device meets IEC 61508 to a stated SIL or SC.</li>



<li><strong>SIL Declaration of Conformity:</strong> the manufacturer’s own conformity statement.</li>



<li><strong>Product Safety Manual:</strong> the manufacturer’s constraints on proof test, TI, and useful life.</li>



<li><strong>EU Declaration of Conformity:</strong> the manufacturer’s signed declaration behind a CE mark.</li>



<li><strong>North American listing mark:</strong> an NRTL, UL, or Canadian SCC-accredited mark (CSA, cUL, cETL) for product and electrical safety.</li>



<li><strong>Ex certificate:</strong> IECEx or ATEX evidence for use in a hazardous area.</li>
</ul>



<h2 class="wp-block-heading">Frequently Asked Questions</h2>



<h4 class="wp-block-heading">A supplier sent a SIL certificate with a logo I don’t recognize. How do I tell whether it actually means anything?</h4>



<p class="wp-block-paragraph">Start with whether there’s an accreditation body behind it. A real SIL certificate from a real CB carries the mark of the accreditation body that backs that CB, ANAB, UKAS, DAkkS, and the like, and you can look the CB up with that body. If you cannot find any accreditation behind the logo, treat the certificate as the vendor’s claim, not independent evidence. The logo on its own proves nothing; the chain behind it is the whole point.</p>



<h4 class="wp-block-heading">The vendor only gave me a Declaration of Conformity, not a third-party certificate. Is that enough to justify the device in my SIF?</h4>



<p class="wp-block-paragraph">Assuming the vendor isn’t being unethical, it’s likely that something just got twisted up somewhere. If a SIL Declaration of Conformity exists, the device is probably SIL certified and there’s a SIL certificate out there; you may simply not have a copy of it. So ask the manufacturer for it, and check their website, since most of them post their certificates. As a last-ditch effort, go to the certification bodies common in your industry and search their databases. The declaration on its own isn’t the independent certificate you want behind a SIF, but its existence usually means the real one isn’t far away.</p>



<h4 class="wp-block-heading">I’m the design manager for a pressure instrument that’s been in the field for decades, and I want a SIL certificate to widen its market. What’s my first step?</h4>



<p class="wp-block-paragraph">Get help early, because this gets tricky fast, and it’s the kind of work we do at SIL Safe. But the real first move is opening a relationship with a certification body, because the CB is who you ultimately have to prove the requirements to. Your decades of field history are an asset here; they may open a proven-in-use route rather than a full clean-sheet assessment. The CB will tell you which evidence they need, and that shapes everything you do next.</p>



<h4 class="wp-block-heading">An AHJ told me this breaker can’t be used because it has no UL logo. Is that right?</h4>



<p class="wp-block-paragraph">Assuming this is in the United States, most likely you can still use it. What the code calls for is a listing by an NRTL, and UL is only one lab on that program. If your breaker is listed by FM or Intertek, often to a UL standard at that, it meets the same requirement. It’s a common mix-up, since “UL” and “listed” get treated as the same thing. Show the AHJ the NRTL listing mark and the standard it was tested to, and you’re usually on solid ground.</p>



<p class="wp-block-paragraph">It is possible this breaker came via a bizarre procurement path, such as for maritime or overseas.  In that case, the AHJ may be right.</p>



<h4 class="wp-block-heading">I need a solenoid valve for an automated final element in a Zone 2 area at SIL 2, for a site in the UK. What do I actually need to line up?</h4>



<p class="wp-block-paragraph">Three things, and they’re separate. For the SIL 2 part, you want a valve with a SIL certificate showing it’s fit for SIL 2, or a prior-use case, and you verify it in the context of the whole SIF, not just the valve on its own. For Zone 2, you need the explosion-protection certification for that area, an ATEX or IECEx Ex certificate, which is a different document from the SIL certificate. And for the UK, you’re under the COMAH Competent Authority rather than a US-style AHJ, so expect a regulator that knows functional safety well, and confirm the conformity marking works for the Great Britain market. None of the three substitutes for the others.</p>



<h2 class="wp-block-heading">Further Reading</h2>



<p class="wp-block-paragraph"><strong>From SIL Safe</strong></p>



<ul class="wp-block-list">
<li><a href="https://silsafe.net/functional-safety-for-the-process-industry/">Functional Safety for the Process Industry: 10 Core Concepts Every Engineer Should Know</a></li>



<li><a href="https://silsafe.net/sil-verification-three-gates/">SIL Verification: The Three Gates Every SIF Must Clear</a></li>
</ul>



<p class="wp-block-paragraph"><strong>External resources</strong></p>



<ul class="wp-block-list">
<li><a href="https://global-aci.org/en/home/" target="_blank" rel="noopener">Global ACI</a></li>



<li><a href="https://www.osha.gov/nationally-recognized-testing-laboratory-program/current-list-of-nrtls" target="_blank" rel="noopener">OSHA: Current List of NRTLs</a></li>



<li><a href="https://single-market-economy.ec.europa.eu/single-market/ce-marking_en" target="_blank" rel="noopener">European Commission: CE marking</a></li>



<li><a href="https://www.gov.uk/guidance/placing-ukca-or-ce-marked-products-on-the-market-in-great-britain" target="_blank" rel="noopener">gov.uk: Placing UKCA or CE marked products on the market in Great Britain</a></li>



<li><a href="https://www.hse.gov.uk/comah/" target="_blank" rel="noopener">HSE: Control of Major Accident Hazards (COMAH)</a></li>



<li><a href="https://scc-ccn.ca/resources/publications/recognized-canadian-electrical-product-and-equipment-approval-marks" target="_blank" rel="noopener">Standards Council of Canada: Recognized Canadian approval marks</a></li>



<li><a href="https://www.iecex.com/" target="_blank" rel="noopener">IECEx</a></li>



<li><a href="https://www.nfpa.org/news-blogs-and-articles/blogs/2020/10/16/a-better-understanding-of-nfpa-70e-what-makes-someone-an-authority-having-jurisdiction" target="_blank" rel="noopener">NFPA: Who is responsible for enforcing NFPA 70E</a> &#8211; great article on explaining an AHJ</li>



<li><a href="https://www.tuv.com/usa/en/functional-safety-product-certification.html" target="_blank" rel="noopener">TÜV Rheinland: Functional safety product certification</a></li>
</ul>



<p class="wp-block-paragraph">Functional safety is complex, and the stakes are high. If you have questions about your SIS design, SIL verification, or where to start with IEC 61511, the team at SIL Safe is here to help. Reach out to us today.</p>



<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "A supplier sent a SIL certificate with a logo I don't recognize. How do I tell whether it actually means anything?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Start with whether there's an accreditation body behind it. A real SIL certificate from a real CB carries the mark of the accreditation body that backs that CB, ANAB, UKAS, DAkkS, and the like, and you can look the CB up with that body. If you cannot find any accreditation behind the logo, treat the certificate as the vendor's claim, not independent evidence. The logo on its own proves nothing; the chain behind it is the whole point."
      }
    },
    {
      "@type": "Question",
      "name": "The vendor only gave me a Declaration of Conformity, not a third-party certificate. Is that enough to justify the device in my SIF?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Assuming the vendor isn't being unethical, it's likely that something just got twisted up somewhere. If a SIL Declaration of Conformity exists, the device is probably SIL certified and there's a SIL certificate out there; you may simply not have a copy of it. So ask the manufacturer for it, and check their website, since most of them post their certificates. As a last-ditch effort, go to the certification bodies common in your industry and search their databases. The declaration on its own isn't the independent certificate you want behind a SIF, but its existence usually means the real one isn't far away."
      }
    },
    {
      "@type": "Question",
      "name": "I'm the design manager for a pressure instrument that's been in the field for decades, and I want a SIL certificate to widen its market. What's my first step?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Get help early, because this gets tricky fast. The real first move is opening a relationship with a certification body, because the CB is who you ultimately have to prove the requirements to. Your decades of field history are an asset here; they may open a proven-in-use route rather than a full clean-sheet assessment. The CB will tell you which evidence they need, and that shapes everything you do next."
      }
    },
    {
      "@type": "Question",
      "name": "An AHJ told me this breaker can't be used because it has no UL logo. Is that right?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Assuming this is in the United States, most likely you can still use it. What the code calls for is a listing by an NRTL, and UL is only one lab on that program. If your breaker is listed by FM or Intertek, often to a UL standard at that, it meets the same requirement. Show the AHJ the NRTL listing mark and the standard it was tested to, and you're usually on solid ground."
      }
    },
    {
      "@type": "Question",
      "name": "I need a solenoid valve for an automated final element in a Zone 2 area at SIL 2, for a site in the UK. What do I actually need to line up?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Three things, and they're separate. For the SIL 2 part, you want a valve with a SIL certificate showing it's fit for SIL 2, or a prior-use case, and you verify it in the context of the whole SIF. For Zone 2, you need the explosion-protection certification for that area, an ATEX or IECEx Ex certificate. And for the UK, you're under the COMAH Competent Authority, so expect a regulator that knows functional safety well, and confirm the conformity marking works for the Great Britain market. None of the three substitutes for the others."
      }
    }
  ]
}
</script>



<style>
/* Dark mode fix: invert black-on-transparent logos */
.color-scheme--alt .wp-image-6983,
.color-scheme--alt .wp-image-6984,
.color-scheme--alt .wp-image-7006 {
  filter: invert(1);
}
</style>
]]></content:encoded>
					
					<wfw:commentRss>https://silsafe.net/who-certifies-functional-safety-equipment/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The Qatar Gas Plant Explosion: What We Know So Far</title>
		<link>https://silsafe.net/qatar-gas-plant-explosion/</link>
					<comments>https://silsafe.net/qatar-gas-plant-explosion/#respond</comments>
		
		<dc:creator><![CDATA[mamerten]]></dc:creator>
		<pubDate>Fri, 26 Jun 2026 01:51:28 +0000</pubDate>
				<category><![CDATA[Beginner]]></category>
		<guid isPermaLink="false">https://silsafe.net/?p=6960</guid>

					<description><![CDATA[In June 2026, an explosion tore through the Barzan gas plant at Qatar's Ras Laffan during a restart after months of maintenance, killing 13 and injuring 66. Here is what is known so far, how Qatar's unusual operator-as-regulator framework works, and why start-up is the most dangerous phase a plant runs.]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">On the evening of June 21, 2026, an explosion and fire tore through the Barzan gas plant inside Qatar&#8217;s Ras Laffan Industrial City. Thirteen workers were killed and 66 injured, and the blast was felt across Doha, about 70 km away. It happened during start-up, as crews brought the plant back online after an extended maintenance shutdown.</p>



<p class="wp-block-paragraph">For anyone who works in process safety, that one detail carries weight. Start-up is the riskiest phase in a plant&#8217;s life, and a restart after a long outage is the sharpest test of start-up safety there is. The investigation has only just opened and no cause has been established, so nothing here is a root cause analysis.</p>



<h2 class="wp-block-heading">What is the Barzan plant, and where does it sit?</h2>



<p class="wp-block-paragraph">Ras Laffan Industrial City, often shortened to Ras Laffan, is a city-sized industrial complex on Qatar&#8217;s northeast coast, about 70 km north of Doha, where roughly 115,000 people work. The whole city is owned and managed by QatarEnergy, Qatar&#8217;s state-owned national oil company, and the individual plants inside it are run by QatarEnergy-led joint ventures with partners such as ExxonMobil and Shell. The site hosts the LNG (liquefied natural gas) trains that produce Qatar&#8217;s LNG for export, gas-to-liquids plants, a refinery, petrochemical units, a port, and the Barzan gas plant.</p>



<p class="wp-block-paragraph">An LNG train is a single, complete processing line that chills and liquefies natural gas into LNG, and Ras Laffan runs about 14 of them. They are separate facilities from Barzan. They share the same industrial city, and that is the whole of the connection.</p>



<p class="wp-block-paragraph">Barzan itself is a gas plant that supplies Qatar&#8217;s domestic market: roughly 1.4 billion standard cubic feet per day of sales gas (treated, pipeline-ready natural gas) for local power and desalination, plus liquefied petroleum gas (LPG) and condensate, a light hydrocarbon liquid rather than water. It was commissioned in 2022 as a QatarEnergy and ExxonMobil joint venture. It is not an LNG train, and it is not a petrochemical unit.</p>



<h2 class="wp-block-heading">What does the plant process, and what is the hazard?</h2>



<p class="wp-block-paragraph">Barzan takes raw natural gas from the North Field and turns it into marketable products: sales gas, condensate, LPG, and recovered sulphur. It cleans, separates, and conditions the gas rather than building it into anything new.</p>



<p class="wp-block-paragraph">The hazard that defines a plant like this is flammable hydrocarbon gas and liquids held under pressure. Lose containment, find an ignition source, and the result is a fire or an explosion. That is what decides where the protection goes.</p>



<h2 class="wp-block-heading">What occurred on June 21, 2026?</h2>



<p class="wp-block-paragraph">The sequence matters more than any single moment.</p>



<ul class="wp-block-list">
<li>December 2025: Barzan was taken offline for maintenance. Energy Minister and QatarEnergy CEO Saad al-Kaabi has said production was intentionally stopped to meet maintenance requirements.</li>



<li>March 2026: Iranian missile strikes hit other parts of Ras Laffan, damaging LNG Trains 4 and 6 and Shell&#8217;s Pearl gas-to-liquids plant, and cutting roughly 17% of Qatar&#8217;s LNG export capacity. Barzan was already down for maintenance and was not the unit struck.</li>



<li>June 19, 2026: two days before the explosion, crews began restarting Barzan.</li>



<li>June 21, 2026, about 22:30 local time: an explosion and fire broke out during what QatarEnergy called the start-up of operations. Emergency teams brought the fire under control.</li>



<li>The toll: 13 killed and 66 injured. The workers who died were foreign nationals, reported as 12 Indian and one Pakistani; the injured spanned several nationalities, with none in life-threatening condition.</li>



<li>The cause: not established publicly. QatarEnergy ruled out sabotage and hostile action, and a formal investigation is underway. Anything past that is speculation.</li>
</ul>



<h2 class="wp-block-heading">Why is start-up the dangerous part?</h2>



<p class="wp-block-paragraph">Start-up is, statistically, the most dangerous mode a plant runs in. A refining or petrochemical facility spends less than 10% of its operating time in transient operations like start-up and shutdown, yet those windows account for more than half of its process safety incidents. The Center for Chemical Process Safety (CCPS) has put the gap more sharply still: incidents are roughly five times more likely during start-up than during normal running. A restart after a months-long outage sits at the worst end of that range.</p>



<p class="wp-block-paragraph">The reason is not complicated. Protection is thinnest exactly when the plant is least stable. Trips and alarms get bypassed or are not yet reading in their normal ranges, and the process is running outside the steady-state envelope it was designed around.</p>



<p class="wp-block-paragraph">This is where start-up safety becomes a functional safety problem rather than a general one. Start-up is precisely where IEC 61511 bypass management, management of change (MOC), and the pre-start-up safety review (PSSR) earn their keep.</p>



<h2 class="wp-block-heading">What regulations apply?</h2>



<p class="wp-block-paragraph">This is a Qatari facility, so the framework is Qatar&#8217;s, and it differs structurally from what engineers in the US or Europe are used to, starting with who does the regulating.</p>



<h3 class="wp-block-heading">Who regulates process safety in Qatar?</h3>



<p class="wp-block-paragraph">In Qatar, the operator is also the regulator. QatarEnergy runs Ras Laffan Industrial City and, at the same time, serves as the petroleum sector&#8217;s health, safety and environment (HSE) regulator. A 1977 decree gave Qatar Petroleum, now QatarEnergy, that regulatory mandate, and its HSE Regulations and Enforcement Directorate formalized the role across the sector in 2005.</p>



<p class="wp-block-paragraph">That arrangement makes more sense once you see the ownership. QatarEnergy is Qatar&#8217;s wholly state-owned national oil company, the country&#8217;s equivalent of Saudi Aramco. It is a state corporation rather than a government ministry, and it owns and controls essentially all of Qatar&#8217;s oil and gas, with international companies such as ExxonMobil, Shell, and TotalEnergies holding minority stakes in joint ventures.</p>



<p class="wp-block-paragraph">There is no single comprehensive national HSE law. The requirements sit across environmental and labour legislation and are consolidated in QatarEnergy&#8217;s own HSE framework, with international good practice filling the gaps. The contrast with the West is clean. In the US, the regulator (OSHA, EPA), and in the UK and EU, the competent authorities under COMAH and Seveso, are independent of the operators they oversee. Qatar&#8217;s is not.</p>



<h3 class="wp-block-heading">Does Qatar have a major-accident regime?</h3>



<p class="wp-block-paragraph">Yes. QatarEnergy&#8217;s Major Accident Hazards Management (MAHM) standard requires major hazards to be identified, assessed, and reduced to as low as reasonably practicable (ALARP) across the plant life-cycle, using tools like HAZID, HAZOP, and bow-tie analysis. Tenants in the industrial cities, including Ras Laffan and Mesaieed, have to run formal process safety management (PSM) systems.</p>



<h3 class="wp-block-heading">Does Qatar require functional safety and IEC 61511?</h3>



<p class="wp-block-paragraph">Yes, but through engineering standards and procurement rather than statute. QatarEnergy mandates compliance with the international standards (IEC, ISA, API, ISO), so a safety instrumented system (SIS) has to be designed and verified to IEC 61508 and IEC 61511 for safety integrity level (SIL), with equipment flowing through approved-vendor lists. The North Field Expansion is driving a wave of new SIS installations on exactly that basis. IEC 61511 therefore plays the same role in Qatar that it plays globally, as the recognized and generally accepted good engineering practice (RAGAGEP) for an SIS. The only difference is how it arrives: through the operator&#8217;s standards and contracts rather than a regulation that names it.</p>



<h3 class="wp-block-heading">Who investigates an incident like this?</h3>



<p class="wp-block-paragraph">The investigation is operator- and state-led. QatarEnergy, whose CEO Saad al-Kaabi confirmed the inquiry, is leading it alongside the Interior Ministry. There is no independent national investigation board the way the US has the Chemical Safety Board (CSB), so the findings will be released at the state&#8217;s discretion and on its timeline.</p>



<h2 class="wp-block-heading">What we do not know at the time of writing (June 2026)</h2>



<p class="wp-block-paragraph">A great deal is still open:</p>



<ul class="wp-block-list">
<li>What actually initiated the explosion during start-up: the specific unit, the operation underway, and the failure that started it.</li>



<li>Whether any safety instrumented functions (SIFs) or other protection layers were bypassed or overridden for the restart, and how they performed.</li>



<li>What condition the plant was in after roughly six months down, and whether the restart procedures and MOC accounted for that.</li>



<li>When the investigation will report, and how much of it will be made public.</li>



<li>Any longer-term or localized impact.</li>
</ul>



<h2 class="wp-block-heading">Frequently Asked Questions</h2>



<h4 class="wp-block-heading">The coverage calls Ras Laffan a petrochemical plant. Is an LNG or gas plant actually petrochemical?</h4>



<p class="wp-block-paragraph">No. The difference is what the plant does to the hydrocarbons. Gas processing and LNG physically clean, separate, and liquefy natural gas; the molecules that go in are the molecules that come out. A petrochemical plant chemically converts those hydrocarbons into new compounds. In industry terms, gas processing and LNG are midstream, petrochemicals are downstream. Ras Laffan does run some petrochemical units, but Barzan is gas processing. It matters because the hazard set, flammable-gas loss of containment and overpressure, is what decides where the SIFs go.</p>



<h4 class="wp-block-heading">I&#8217;m a chemical engineer at a gas plant a lot like this one. What should I take away from this incident?</h4>



<p class="wp-block-paragraph">Not much that is specific to Barzan yet, since the cause has not been released. The durable takeaway is the one that was already true before this explosion: start-up after a long outage is your highest-risk window, so that is where your pre-start-up safety review, your bypass control, and your management of change need to be tightest.</p>



<h4 class="wp-block-heading">We bypass trips on every start-up just to get the plant running. Is that even allowed?</h4>



<p class="wp-block-paragraph">Yes, within limits. Bypassing a trip to bring a plant up is normal practice, but IEC 61511 expects that bypass to be authorized, time-limited to the window your PFDavg (<a href="https://silsafe.net/pfdavg-explained/" data-type="post" data-id="184">average probability of failure on demand</a>) calculation assumed, and backed by a compensating measure while it is in place, whether that is an extra watch or a manual safeguard that covers the gap. The problem is never the bypass itself. It is the bypass that becomes routine: open-ended, undocumented, with nobody tracking when it comes back out.</p>



<h4 class="wp-block-heading">I&#8217;m a FuSa engineer in the US, and Qatar&#8217;s regulatory setup sounds different from ours. What is their structure?</h4>



<p class="wp-block-paragraph">It is different, in three ways that matter. First, the operator and the regulator are the same body: QatarEnergy runs the plants and regulates the sector. Second, major-hazard control is built on ALARP and a safety-case-style major-hazards report, which is far closer to the UK&#8217;s COMAH than to the prescriptive PSM and risk management program (RMP) regime you work under. Third, IEC 61511 is not pulled in by a statute; it is enforced through QatarEnergy&#8217;s engineering standards and procurement. The functional safety work itself, the safety requirements specification, the verification, the <a href="https://silsafe.net/proof-testing-of-sifs/" data-type="post" data-id="33">proof testing</a>, looks the same. What changes is who is checking it and how the requirement reaches you.</p>



<h4 class="wp-block-heading">I heard the explosion was partly caused by the Iranian missile strikes. Is that true?</h4>



<p class="wp-block-paragraph">No. The March strikes hit the LNG trains and a gas-to-liquids plant, not Barzan. Barzan was down for maintenance at the time, and the explosion happened months later, during its restart. QatarEnergy has ruled out sabotage and any hostile action. The cause has not been established, but there is no established link to the strikes, and that distinction is worth keeping straight while the investigation is open.</p>



<h2 class="wp-block-heading">Further Reading</h2>



<p class="wp-block-paragraph"><strong>From SIL Safe</strong></p>



<ul class="wp-block-list">
<li><a href="https://silsafe.net/functional-safety-for-the-process-industry/" data-type="post" data-id="6100">Functional Safety for the Process Industry</a></li>



<li><a href="https://silsafe.net/longview-chemical-tank-implosion/" data-type="post" data-id="6777">The Longview Chemical Tank Implosion: What We Know So Far</a></li>



<li><a href="https://silsafe.net/garden-grove-chemical-incident/" data-type="post" data-id="6633">The Garden Grove Chemical Incident: What We Know So Far</a></li>



<li><a href="https://silsafe.net/houston-recycling-fire/" data-type="post" data-id="7302">Houston Recycling Fire: When Is a Recycling Center a Process Facility?</a></li>



<li><a href="https://silsafe.net/sil-verification-three-gates/" data-type="post" data-id="6515">SIL Verification &#8211; the Three Gates</a> </li>
</ul>



<p class="wp-block-paragraph"><strong>External resources</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.qatarenergy.qa/en/Sustainability/Pages/OperationalResponsibility.aspx" target="_blank" rel="noopener">QatarEnergy: Operational Responsibility</a></li>



<li><a href="https://en.wikipedia.org/wiki/2026_Ras_Laffan_explosion" target="_blank" rel="noopener">2026 Ras Laffan explosion (Wikipedia)</a></li>



<li><a href="https://www.aljazeera.com/economy/2026/6/22/qatar-lng-factory-explosion-injures-54-leaves-18-missing-govt-says" target="_blank" rel="noopener">Al Jazeera: explosion coverage</a></li>



<li><a href="https://www.aiche.org/ccps/resources/publications/books/guidelines-process-safety-during-transient-operating-mode-managing-risks-during-process-start-ups" target="_blank" rel="noopener">CCPS / AIChE: Guidelines for Process Safety During the Transient Operating Mode</a></li>



<li><a href="https://www.hse.gov.uk/comah/" target="_blank" rel="noopener">HSE (UK): COMAH</a></li>
</ul>



<p class="wp-block-paragraph">Functional safety is complex, and the stakes are high. If you have questions about your SIS design, SIL verification, or where to start with IEC 61511, the team at SIL Safe is here to help. Reach out to us today.</p>



<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "The coverage calls Ras Laffan a petrochemical plant. Is an LNG or gas plant actually petrochemical?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No. The difference is what the plant does to the hydrocarbons. Gas processing and LNG physically clean, separate, and liquefy natural gas; the molecules that go in are the molecules that come out. A petrochemical plant chemically converts those hydrocarbons into new compounds. In industry terms, gas processing and LNG are midstream, petrochemicals are downstream. Ras Laffan does run some petrochemical units, but Barzan is gas processing. It matters because the hazard set, flammable-gas loss of containment and overpressure, is what decides where the SIFs go."
      }
    },
    {
      "@type": "Question",
      "name": "I'm a chemical engineer at a gas plant a lot like this one. What should I take away from this incident?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Not much that is specific to Barzan yet, since the cause has not been released. The durable takeaway is the one that was already true before this explosion: start-up after a long outage is your highest-risk window, so that is where your pre-start-up safety review, your bypass control, and your management of change need to be tightest."
      }
    },
    {
      "@type": "Question",
      "name": "We bypass trips on every start-up just to get the plant running. Is that even allowed?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Yes, within limits. Bypassing a trip to bring a plant up is normal practice, but IEC 61511 expects that bypass to be authorized, time-limited to the window your PFDavg (average probability of failure on demand) calculation assumed, and backed by a compensating measure while it is in place, whether that is an extra watch or a manual safeguard that covers the gap. The problem is never the bypass itself. It is the bypass that becomes routine: open-ended, undocumented, with nobody tracking when it comes back out."
      }
    },
    {
      "@type": "Question",
      "name": "I'm a FuSa engineer in the US, and Qatar's regulatory setup sounds different from ours. What is their structure?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "It is different, in three ways that matter. First, the operator and the regulator are the same body: QatarEnergy runs the plants and regulates the sector. Second, major-hazard control is built on ALARP and a safety-case-style major-hazards report, which is far closer to the UK's COMAH than to the prescriptive PSM and risk management program (RMP) regime you work under. Third, IEC 61511 is not pulled in by a statute; it is enforced through QatarEnergy's engineering standards and procurement. The functional safety work itself, the safety requirements specification, the verification, the proof testing, looks the same. What changes is who is checking it and how the requirement reaches you."
      }
    },
    {
      "@type": "Question",
      "name": "I heard the explosion was partly caused by the Iranian missile strikes. Is that true?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No. The March strikes hit the LNG trains and a gas-to-liquids plant, not Barzan. Barzan was down for maintenance at the time, and the explosion happened months later, during its restart. QatarEnergy has ruled out sabotage and any hostile action. The cause has not been established, but there is no established link to the strikes, and that distinction is worth keeping straight while the investigation is open."
      }
    }
  ]
}
</script>
]]></content:encoded>
					
					<wfw:commentRss>https://silsafe.net/qatar-gas-plant-explosion/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Functional Safety Assessment (FSA) vs. Audit: What&#8217;s the Difference?</title>
		<link>https://silsafe.net/functional-safety-assessment-vs-audit/</link>
					<comments>https://silsafe.net/functional-safety-assessment-vs-audit/#respond</comments>
		
		<dc:creator><![CDATA[mamerten]]></dc:creator>
		<pubDate>Mon, 15 Jun 2026 15:12:10 +0000</pubDate>
				<category><![CDATA[Beginner]]></category>
		<guid isPermaLink="false">https://silsafe.net/?p=6810</guid>

					<description><![CDATA[A functional safety assessment and an audit get used interchangeably, but they answer different questions and sit at different points in the IEC 61511 life-cycle. One judges whether the required functional safety was achieved; the other checks whether you followed your procedures. Confusing the two has real consequences.]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A functional safety assessment (FSA) and a functional safety audit get treated as the same thing in conversation, in scopes of work, in audit findings. They are not. The two are easy to confuse, and the mix-up is common, but they answer different questions, happen at different points in the life-cycle, and carry different obligations under IEC 61511.</p>



<p class="wp-block-paragraph">An FSA is a design and engineering activity that judges whether the required functional safety was actually achieved. An audit is an operations activity that checks whether you followed your own procedures. Confuse them, and a facility can pass one while wrongly believing it has satisfied the other.</p>



<h2 class="wp-block-heading">What a functional safety assessment is</h2>



<p class="wp-block-paragraph">A functional safety assessment is an evidence-based investigation that judges the functional safety achieved by a safety instrumented system (SIS) and any other protection layers it relies on. It confirms the engineering was done properly and the required risk reduction was actually reached. In IEC 61511 it lives at Clause 5.2.6.1.</p>



<p class="wp-block-paragraph">An FSA is a design and engineering activity, and most of the effort lands in the design and installation phases, where the SIS is being built and an independent look has the most leverage. The question an FSA answers is about the result: was the required functional safety achieved, and does the evidence behind it hold up.</p>



<p class="wp-block-paragraph">There are five FSA stages spanning the life-cycle, from just after the hazard and risk assessment (H&#038;RA) through to decommissioning. Each happens at the boundary between blocks of work rather than continuously.</p>



<p class="wp-block-paragraph">Two things sit at the center of a credible FSA:</p>



<ul class="wp-block-list">

<li><strong>Competence.</strong> The team has to be competent for the application, carrying the technical, application, and operations expertise the system demands. This is the requirement companies most often back with formal functional safety certification, a TÜV functional safety engineer certificate or a Certified Functional Safety Expert (CFSE) credential, as documented evidence the assessor is qualified.</li>


<li><strong>Independence.</strong> The assessment has to be led by someone senior who was not part of the team that did the work. Independence does not mean a third party by default; in practice it scales with the risk. A highly standardized change at a low safety integrity level (SIL) can be judged by someone from elsewhere in the organization, while a high-SIL or first-of-a-kind design pushes toward a fully independent or third-party assessor.</li>

</ul>



<p class="wp-block-paragraph">Independence is where many operators get stuck. Small and mid-size firms often do not have enough qualified people to assemble a team genuinely separate from the one that did the design or runs the plant. That is why facilities so often hand both their FSAs and their audits to an outside consultancy: a firm like SIL Safe sits outside the project and operations teams by definition, which is the cleanest way to clear the independence bar, particularly on higher-SIL or first-of-a-kind work.</p>



<p class="wp-block-paragraph">Companies may split a stage into two where it helps, an early Stage 1 around the first P&#038;IDs and a later one once supplier details firm up, or a Stage 3 split across installation and site acceptance testing. That adds assessments; it does not change the five-stage framework.</p>



<h2 class="wp-block-heading">What a functional safety audit is</h2>



<p class="wp-block-paragraph">A functional safety audit, usually just called an audit, is a systematic, independent examination of whether your functional safety procedures match the plan, are being implemented, and are working. In IEC 61511 it lives at Clause 5.2.6.2. In practice an audit reviews documents and records to confirm your functional safety program is in place, current, and being followed.</p>



<p class="wp-block-paragraph">If you have sat through an ISO 9001 quality audit or a nuclear program audit, you already know the shape of it. Someone independent checks that you have the procedures, that they say what you claimed they say, and that you are doing what they describe. They are not judging whether the design is any good.</p>



<p class="wp-block-paragraph">An audit does not judge whether functional safety has been achieved; that judgment belongs to the FSA. An audit also cannot run until the procedures exist to audit against, which makes it an operations-phase activity, working from training and competency records, management of change, proof-test records, and maintenance logs.</p>



<p class="wp-block-paragraph">The standard sets no fixed audit interval. How often you audit is generally the program&#8217;s decision, set in the functional safety management program. Some jurisdictions impose a floor: in the US, OSHA Process Safety Management (PSM) and EPA Risk Management Program (RMP) require a program compliance audit at least every three years, and the functional safety one usually rides along with it. Other regimes, COMAH in the UK and Seveso across the EU, set their own expectations.</p>



<p class="wp-block-paragraph">On a large program, audits scale by splitting rather than swelling: one auditor takes the training program, another management of change, another proof-test records, instead of one monolithic pass.</p>



<h2 class="wp-block-heading">Assessment vs. audit: the core difference</h2>



<p class="wp-block-paragraph">Take the functional safety assessment first, since it comes earlier in the life-cycle:</p>



<ul class="wp-block-list">

<li>An FSA evaluates the work products and conclusions. Is the result actually safe? Did the H&#038;RA and layer of protection analysis (LOPA) classify the risk correctly? Does the analysis hold up? It answers &#8220;did you get the right outcome?&#8221;</li>


<li>An audit evaluates the process. Did you follow the defined steps, in order, with the right inputs, outputs, and competencies? It answers &#8220;did you work the right way?&#8221;</li>

</ul>



<p class="wp-block-paragraph">The two overlap in operation, where assessing a phase is largely a matter of examining whether procedures are being followed. What keeps them distinct is the question each ultimately answers, and the fact that the independence requirement attaches to the FSA.</p>



<figure class="wp-block-table"><table><thead><tr><th>Dimension</th><th>FSA</th><th>Audit</th></tr></thead><tbody><tr><td>What it examines</td><td>Whether the required functional safety was achieved (the result)</td><td>Whether your procedures are being followed (the process)</td></tr><tr><td>Core question</td><td>Has the required functional safety been achieved?</td><td>Are the procedures being followed?</td></tr><tr><td>Primary life-cycle window</td><td>Design and installation</td><td>Long-term operations</td></tr><tr><td>Independence basis</td><td>Senior competent person off the team that did the work; third party scales with risk</td><td>Independent person not working on the SIS</td></tr><tr><td>Frequency</td><td>Tied to life-cycle milestones</td><td>Program&#8217;s decision (US regulations: at least every three years)</td></tr><tr><td>Typical evidence</td><td>Safety requirements specification (SRS), SIL verification, validation results</td><td>Records, procedures, competency, change logs</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">Where each sits in the life-cycle</h2>



<p class="wp-block-paragraph">Both activities sit under the management of functional safety in IEC 61511, Clause 5, but they enter the life-cycle at different points and for different reasons.</p>



<h3 class="wp-block-heading">Functional safety assessments</h3>



<p class="wp-block-paragraph">Each functional safety assessment sits at a phase boundary. A block of work, design, installation, or commissioning, is finished, an independent assessor judges it, and only then does the project move to the next phase or to startup. The five stages, by the phase each one follows:</p>



<ul class="wp-block-list">

<li>Stage 1: after the H&#038;RA, once the protection layers are identified and the SRS is developed</li>


<li>Stage 2: after the SIS is designed</li>


<li>Stage 3: after installation, pre-commissioning, and final validation, the pre-startup FSA</li>


<li>Stage 4: after operating and maintenance experience has been gained</li>


<li>Stage 5: after a modification, and before decommissioning</li>

</ul>



<p class="wp-block-paragraph">Of these, only the pre-startup FSA at Stage 3 is a hard, point-in-time requirement, due before the identified hazards are present, which in practice means before the process material or gas is introduced. A periodic FSA during operation is also required, and a modification triggers its own. The rest, and the depth of each, are a planning decision.</p>



<h3 class="wp-block-heading">Audits</h3>



<p class="wp-block-paragraph">An audit is not a gate the way a functional safety assessment is. It recurs through the operating life at whatever interval the program sets, and its findings feed back as improvements to the program.</p>



<h2 class="wp-block-heading">Common mistakes</h2>



<ul class="wp-block-list">

<li>Merging the two concepts, treating one as if it discharges the other. A facility runs its functional safety assessments and assumes that covers the audit, or runs faithful audits and never commissions an FSA. They are separate obligations; doing one does not satisfy the other.</li>


<li>Not having the functional safety management plan (FSMP) define how FSAs and audits get done. The FSMP should be the thing that sets how your assessments and audits are run, at what stages, in what depth, with what independence, and how often, within a single project, across the projects in your program, and over the life of the SIS. When that is missing, each one gets scoped ad hoc, and the inconsistency is what an audit flags.</li>


<li>Treating the SIL verification calculation as the FSA. The probability of failure on demand average (PFDavg) and risk reduction factor (RRF) numbers are an input the FSA reviews, not the assessment itself.</li>


<li>Using reviewers who are not independent of the team that did the work. The reverse error shows up too: paying for a third-party assessor on a low-SIL, standardized change where a competent in-house reviewer would have met the requirement.</li>

</ul>



<h2 class="wp-block-heading">Frequently Asked Questions</h2>



<h4 class="wp-block-heading">An audit sounds a lot like a verification, and verification sounds like a validation. What&#8217;s the actual difference between an audit, an assessment, a verification, and a validation?</h4>



<p class="wp-block-paragraph">Four different things, and the quickest way to keep them straight is what each one looks at:</p>



<ul class="wp-block-list">

<li><strong>Verification</strong> is the per-phase check that the outputs of a phase meet the requirements set for it: did the design meet the SRS, does the SIL verification show the target is met.</li>


<li><strong>Validation</strong> is the big end-to-end proof, done before startup, that the installed SIS does what the SRS says in every respect.</li>


<li><strong>A functional safety assessment</strong> is the independent judgment that functional safety was achieved across the relevant phases, leaning on the verification and validation results as evidence.</li>


<li><strong>An audit</strong> checks whether you followed your procedures, not whether the system is any good.</li>

</ul>



<p class="wp-block-paragraph">The first three judge the system; the audit judges the process.</p>



<h4 class="wp-block-heading">Our SIS has run for 10 years with minimal changes and no real problems. We&#8217;ve kept up our audits but never done a functional safety assessment since the original design. Is that okay?</h4>



<p class="wp-block-paragraph">Likely not. The standard expects a periodic FSA during operation, not just audits. Your audits confirmed you were following your procedures, which is worth something, but nobody has stood back and judged whether the SIS still achieves its required risk reduction against ten years of actual proof-test results, real demand history, and field failures. That is what an operational FSA is for, and you are most likely overdue. &#8220;Minimal changes&#8221; is doing some quiet work in that sentence, too: any modification over those ten years should have triggered its own FSA at the time.</p>



<h4 class="wp-block-heading">A consultancy we used ran our functional safety assessments and audits together as one exercise. You&#8217;re telling me they&#8217;re different things, so did we get it wrong?</h4>



<p class="wp-block-paragraph">It is probably fine. Running them together is common and usually sensible, for a couple of reasons:</p>



<ul class="wp-block-list">

<li>The two genuinely overlap, especially once you are in operation, where assessing a phase is mostly a matter of checking that procedures are being followed.</li>


<li>IEC 61511 lets an audit be carried out as part of an FSA, so folding them into one mobilization is efficient rather than wrong.</li>

</ul>



<p class="wp-block-paragraph">The one thing worth checking is independence. It attaches to the assessment, so if what they called an &#8220;assessment&#8221; was really a procedure-conformance checklist run alongside your design team, you got an audit with an assessment&#8217;s label on it, and that falls short on the independence an FSA requires.</p>



<h4 class="wp-block-heading">How much operating experience do we need before the first operational functional safety assessment, and how often after that?</h4>



<p class="wp-block-paragraph">There is no fixed number in the standard, and that is deliberate. The real gate is data, and data takes time to accumulate. An operational FSA earns its keep by testing the assumptions the design was built on, the demand rates, the failure rates, the protection-layer effectiveness, and you can only test those against what the plant actually produces: the demand signals the SIF has seen, and completed proof tests. Demands are usually rare, and proof tests only come around on the proof-test interval (TI), so you need enough operating time behind you to have a meaningful set of both. Run the first one too early, with almost no demands logged and barely a proof test done, and there is nothing to assess. After that, the periodic FSA tends to land somewhere around every one to three years, usually pinned to whatever audit or hazard-study revalidation cycle the site already runs, and it is also triggered whenever new hazards turn up or the system is modified.</p>



<h4 class="wp-block-heading">We&#8217;re a small facility with only a handful of safety instrumented functions (SIFs). Do we really need all this assessment and audit overhead?</h4>



<p class="wp-block-paragraph">Yes, but scaled to your risk. The effort scales with the same planning parameters as everything else, so a small, low-SIL, standardized site does less, and does it with a documented rationale, rather than nothing. The pre-startup functional safety assessment and the periodic operational FSA still apply; they are just lighter in scope. At low SIL you can usually meet the independence requirement with a competent reviewer from elsewhere in your own organization instead of an outside firm. &#8220;Small&#8221; changes the size of the exercise, not whether you do it.</p>



<h4 class="wp-block-heading">We inherited an old SIS that never had a formal functional safety assessment. Where do we start?</h4>



<p class="wp-block-paragraph">With an operational FSA, the Stage 4 kind, which reviews all the prior life-cycle stages at once for a system that is already running. You are not going to reconstruct a greenfield paper trail that was never created, and you do not need to. You assess what is actually in front of you against the design intent, demand rates, failure history, proof-test results, and how well the protection layers are performing, and you work the gaps from there. Guidance written specifically for installed and legacy systems, like the CDOIF functional safety management guideline, is built around exactly this situation.</p>



<h2 class="wp-block-heading">Further Reading</h2>



<p class="wp-block-paragraph"><strong>From SIL Safe</strong></p>



<ul class="wp-block-list">
<li><a href="https://silsafe.net/functional-safety-for-the-process-industry/">Functional Safety for the Process Industry</a>, for where assessments and audits sit in the wider safety life-cycle</li>



<li><a href="https://silsafe.net/sil-verification-three-gates/">SIL Verification: Three Gates</a>, for how verification differs from assessment</li>



<li><a href="https://silsafe.net/hazard-and-risk-assessment-hra/">Hazard and Risk Assessment</a>, the input to the Stage 1 assessment</li>



<li><a href="https://silsafe.net/functional-safety-assessment/">Third-Party Functional Safety Assessment</a>, SIL Safe&#8217;s assessment service</li>
</ul>



<p class="wp-block-paragraph"><strong>External resources</strong></p>



<ul class="wp-block-list">
<li><a href="http://www.p-s-f2.org.uk/wp-content/uploads/Functional-Safety-Management-of-Installed-Safety-Instrumented-Systems-1.pdf" target="_blank" rel="noopener">CDOIF Guideline: Functional Safety Management of Installed Safety Instrumented Systems</a>, covering both assessment and audit, with checklists, for operating and legacy plants</li>



<li><a href="https://webstore.iec.ch/en/publication/24241" target="_blank" rel="noopener">IEC 61511-1:2016</a>, the standard itself</li>



<li><a href="https://www.isa.org/standards-and-publications/isa-standards/isa-84-standards" target="_blank" rel="noopener">ISA-84 Series of Standards</a>, the ANSI/ISA adoption and supporting technical reports</li>



<li><a href="https://www.methodfs.com/functional-safety-lifecycle/functional-safety-assessments.php" target="_blank" rel="noopener">Method Functional Safety: The 5 Functional Safety Assessment Stages</a>, a practitioner walkthrough of the five stages</li>



<li><a href="https://efunctionalsafety.com/functional-safety-assessment-fsa/" target="_blank" rel="noopener">eFunctional Safety: Functional Safety Assessment</a>, a practitioner take on how audit and assessment relate</li>
</ul>



<p class="wp-block-paragraph">Functional safety is complex, and the stakes are high. If you have questions about your SIS design, SIL verification, or where to start with IEC 61511, the team at SIL Safe is here to help. Reach out to us today.</p>



<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "An audit sounds a lot like a verification, and verification sounds like a validation. What's the actual difference between an audit, an assessment, a verification, and a validation?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Four different things, and the quickest way to keep them straight is what each one looks at: Verification is the per-phase check that the outputs of a phase meet the requirements set for it: did the design meet the SRS, does the SIL verification show the target is met. Validation is the big end-to-end proof, done before startup, that the installed SIS does what the SRS says in every respect. A functional safety assessment is the independent judgment that functional safety was achieved across the relevant phases, leaning on the verification and validation results as evidence. An audit checks whether you followed your procedures, not whether the system is any good. The first three judge the system; the audit judges the process."
      }
    },
    {
      "@type": "Question",
      "name": "Our SIS has run for 10 years with minimal changes and no real problems. We've kept up our audits but never done a functional safety assessment since the original design. Is that okay?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Likely not. The standard expects a periodic FSA during operation, not just audits. Your audits confirmed you were following your procedures, which is worth something, but nobody has stood back and judged whether the SIS still achieves its required risk reduction against ten years of actual proof-test results, real demand history, and field failures. That is what an operational FSA is for, and you are most likely overdue. \"Minimal changes\" is doing some quiet work in that sentence, too: any modification over those ten years should have triggered its own FSA at the time."
      }
    },
    {
      "@type": "Question",
      "name": "A consultancy we used ran our functional safety assessments and audits together as one exercise. You're telling me they're different things, so did we get it wrong?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "It is probably fine. Running them together is common and usually sensible, for a couple of reasons: The two genuinely overlap, especially once you are in operation, where assessing a phase is mostly a matter of checking that procedures are being followed. IEC 61511 lets an audit be carried out as part of an FSA, so folding them into one mobilization is efficient rather than wrong. The one thing worth checking is independence. It attaches to the assessment, so if what they called an \"assessment\" was really a procedure-conformance checklist run alongside your design team, you got an audit with an assessment's label on it, and that falls short on the independence an FSA requires."
      }
    },
    {
      "@type": "Question",
      "name": "How much operating experience do we need before the first operational functional safety assessment, and how often after that?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "There is no fixed number in the standard, and that is deliberate. The real gate is data, and data takes time to accumulate. An operational FSA earns its keep by testing the assumptions the design was built on, the demand rates, the failure rates, the protection-layer effectiveness, and you can only test those against what the plant actually produces: the demand signals the SIF has seen, and completed proof tests. Demands are usually rare, and proof tests only come around on the proof-test interval (TI), so you need enough operating time behind you to have a meaningful set of both. Run the first one too early, with almost no demands logged and barely a proof test done, and there is nothing to assess. After that, the periodic FSA tends to land somewhere around every one to three years, usually pinned to whatever audit or hazard-study revalidation cycle the site already runs, and it is also triggered whenever new hazards turn up or the system is modified."
      }
    },
    {
      "@type": "Question",
      "name": "We're a small facility with only a handful of safety instrumented functions (SIFs). Do we really need all this assessment and audit overhead?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Yes, but scaled to your risk. The effort scales with the same planning parameters as everything else, so a small, low-SIL, standardized site does less, and does it with a documented rationale, rather than nothing. The pre-startup functional safety assessment and the periodic operational FSA still apply; they are just lighter in scope. At low SIL you can usually meet the independence requirement with a competent reviewer from elsewhere in your own organization instead of an outside firm. \"Small\" changes the size of the exercise, not whether you do it."
      }
    },
    {
      "@type": "Question",
      "name": "We inherited an old SIS that never had a formal functional safety assessment. Where do we start?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "With an operational FSA, the Stage 4 kind, which reviews all the prior life-cycle stages at once for a system that is already running. You are not going to reconstruct a greenfield paper trail that was never created, and you do not need to. You assess what is actually in front of you against the design intent, demand rates, failure history, proof-test results, and how well the protection layers are performing, and you work the gaps from there. Guidance written specifically for installed and legacy systems, like the CDOIF functional safety management guideline, is built around exactly this situation."
      }
    }
  ]
}
</script>
]]></content:encoded>
					
					<wfw:commentRss>https://silsafe.net/functional-safety-assessment-vs-audit/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The Longview Chemical Tank Implosion: What We Know So Far</title>
		<link>https://silsafe.net/longview-chemical-tank-implosion/</link>
					<comments>https://silsafe.net/longview-chemical-tank-implosion/#respond</comments>
		
		<dc:creator><![CDATA[mamerten]]></dc:creator>
		<pubDate>Sat, 06 Jun 2026 03:51:31 +0000</pubDate>
				<category><![CDATA[Advanced]]></category>
		<guid isPermaLink="false">https://silsafe.net/?p=6777</guid>

					<description><![CDATA[On May 26, 2026, a 900,000-gallon white liquor tank imploded at the Nippon Dynawave mill in Longview, Washington, killing eleven workers. This piece covers the facility, the chemical, and why the tank likely sat outside OSHA PSM and EPA RMP, plus what the Longview chemical tank implosion reveals about tank vacuum protection.]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">On May 26, 2026, a tank holding roughly 900,000 gallons of white liquor imploded at the Nippon Dynawave Packaging mill in Longview, Washington, killing eleven workers. The Longview chemical tank implosion is now under investigation by the US Chemical Safety Board (CSB). It also raises a practical question for anyone running process equipment: how do the major US process safety regulations apply to a tank like this, and what can be said while the investigation is still open? The CSB review has only just begun, and nothing here is a root cause analysis.</p>



<h2 class="wp-block-heading">What is the Nippon Dynawave facility?</h2>



<p class="wp-block-paragraph">The mill sits in Longview, Washington, in the Columbia River industrial corridor about 50 miles north of Portland, Oregon, sharing that stretch of riverfront with other timber, paper, and chemical operations. This is an industrial area, not a residential one, and no surrounding neighborhood was evacuated after the failure. Longview itself is a city of roughly 38,000.</p>



<p class="wp-block-paragraph">Nippon Dynawave runs a kraft pulp and paper mill that produces bleached paperboard, the stiff stock used in milk cartons, beverage containers, cups, plates, and food packaging, plus kraft pulp for tissue and printing paper. Around 1,000 people work in the facility, roughly 550 in the pulp and paper mill and 450 in the packaging plant. The site is a US subsidiary of Japan-based Nippon Paper, which bought it in 2016.</p>



<p class="wp-block-paragraph">The Longview site has made pulp since 1931, and this paperboard mill has run since 1953, originally built by Weyerhaeuser. The infrastructure is roughly seven decades old. The age of the specific tank that imploded is not publicly known.</p>



<h2 class="wp-block-heading">What is white liquor?</h2>



<p class="wp-block-paragraph">White liquor is the cooking chemical kraft mills pump into their digesters to break wood chips down into pulp. It dissolves lignin, the natural binder that holds wood fibers together, so the cellulose fibers can be freed and turned into paper. The name is standard industry shorthand, one of a set: white liquor is the fresh cooking chemical, black liquor is the spent liquor after cooking, and green liquor is the intermediate in the chemical recovery cycle.</p>



<p class="wp-block-paragraph">Chemically, it is a water-based solution of sodium hydroxide (NaOH), sodium sulfide (Na2S), and sodium carbonate (Na2CO3). The combination of high temperature and high alkalinity does the cooking work.</p>



<p class="wp-block-paragraph">White liquor is strongly caustic, meaning basic. It is not a solvent like paint thinner, and it is not flammable: no flash point, no flammable vapor. The danger it carries is corrosivity, severe caustic burns on contact and damage to eyes, skin, and lungs on exposure.</p>



<h2 class="wp-block-heading">What occurred on May 26, 2026?</h2>



<p class="wp-block-paragraph">Around 7:15 AM local time, the tank imploded, collapsing inward on itself under vacuum. It did not explode.</p>



<p class="wp-block-paragraph">That distinction matters, and the early public account struggled with it. In the first day, authorities and reporters reached for three different words: explosion, then implosion, then rupture. Implosion is the accurate one. The tank failed under underpressure, a vacuum pulling its walls inward, not under the outward force of an overpressure or a blast.</p>



<p class="wp-block-paragraph">The timing made it worse. A shift change about fifteen minutes earlier had put an unusually large number of workers in the immediate area, across operations, an administrative space, and a break room. It is now the deadliest industrial disaster in Washington state since 1930.</p>



<p class="wp-block-paragraph">The cause of the vacuum has not been established publicly, and there is no way to know it with certainty until the investigation runs its course.</p>



<p class="wp-block-paragraph">Sadly, eleven workers were killed. Eight others were injured, seven workers and one responding firefighter, with chemical burns and inhalation injuries.</p>



<h2 class="wp-block-heading">What causes a tank to implode?</h2>



<p class="wp-block-paragraph">A white liquor storage tank is almost certainly an atmospheric tank. In kraft mills, white liquor is held at close to ambient pressure, in tanks built for the narrow band near atmospheric, not in pressure vessels and not in vacuum vessels. &#8220;Atmospheric&#8221; is a pressure rating, not a description of the lid. Plenty of atmospheric tanks are fully enclosed, with fixed roofs, vents, and conservation devices. The term describes how much pressure the shell can hold, which is very little.</p>



<p class="wp-block-paragraph">That last point is the whole story of an implosion. An atmospheric tank is far weaker against vacuum than against pressure. A few inches of water column of underpressure, a trivial amount, can buckle a fixed-roof tank inward. Modest internal pressure it shrugs off; modest vacuum it cannot.</p>



<p class="wp-block-paragraph">Vacuum builds in a storage tank through ordinary mechanisms: pumping liquid out faster than air can flow back in through the vent, the contents cooling and contracting, condensation after a steam-out, or a vent that is simply blocked or frozen shut.</p>



<p class="wp-block-paragraph">Tank vacuum protection, the vacuum-relief side of a tank&#8217;s venting, is what stands between routine operation and a collapse like this. The consensus standard for sizing it, alongside the pressure side, is API Standard 2000, &#8220;Venting Atmospheric and Low-Pressure Storage Tanks.&#8221; In practice, the vacuum side tends to get less attention than the overpressure side, both when the venting is first sized and in the maintenance that follows. The standard covers both cases. Field habits often do not.</p>



<p class="wp-block-paragraph">This is also where process hazard analysis (PHA) could fall short, a gap SIL Safe often sees in hazard study reviews. A hazard and operability study (HAZOP) or a layer of protection analysis (LOPA) could give overpressure scenarios full rigor and treat low pressure as less likely. Vacuum is exactly the low-frequency, high-consequence scenario those studies exist to catch.</p>



<h2 class="wp-block-heading">What regulations apply?</h2>



<p class="wp-block-paragraph">This is a US incident, so the analysis below is US-specific; readers elsewhere operate under their own frameworks. One thread runs through all of it: being regulated and being hazardous are not the same thing.</p>



<h3 class="wp-block-heading">Does OSHA PSM apply to the white liquor tank?</h3>



<p class="wp-block-paragraph">OSHA&#8217;s Process Safety Management (PSM) standard (29 CFR 1910.119) reaches a process through one of two doors: a chemical on its Appendix A list at or above a threshold quantity, or a flammable liquid or gas at or above 10,000 pounds.</p>



<p class="wp-block-paragraph">White liquor opens neither. Appendix A names 137 highly hazardous chemicals, and white liquor&#8217;s constituents, sodium hydroxide, sodium sulfide, and sodium carbonate, are not among them. OSHA has said so directly: its published interpretations confirm that sodium hydroxide is not an Appendix A chemical. The other two are not listed either. And because white liquor is aqueous and non-flammable, the flammable threshold never comes into play.</p>



<p class="wp-block-paragraph">OSHA PSM does not reach the white liquor tank.</p>



<h3 class="wp-block-heading">Does EPA RMP apply?</h3>



<p class="wp-block-paragraph">EPA&#8217;s Risk Management Program (RMP) rule (40 CFR 68.130) works off its own lists: regulated toxic substances and regulated flammable substances. White liquor&#8217;s components appear on neither. The toxic list is built around inhalation hazards, gases and volatile toxics such as chlorine (Cl2), ammonia (NH3), hydrogen sulfide (H2S), and methyl isocyanate. The flammable list covers flammable gases and volatile flammable liquids. A non-volatile, non-flammable aqueous caustic fits none of that.</p>



<p class="wp-block-paragraph">EPA RMP does not apply.</p>



<h3 class="wp-block-heading">Do paper mills fall under PSM and RMP?</h3>



<p class="wp-block-paragraph">Often, yes, but not because of white liquor. A kraft mill usually does have PSM-covered and RMP-covered processes, and they sit in the bleach plant and the chlorine dioxide generation area, not on the white liquor side. The chemicals that trigger coverage are chlorine dioxide (ClO2), chlorine, sulfur dioxide (SO2), and methanol. Chlorine dioxide is unstable and is typically generated on-site from sodium chlorate (NaClO3), methanol, and sulfuric acid (H2SO4); methanol is flammable. Those are what put a mill under federal coverage.</p>



<p class="wp-block-paragraph">The obvious follow-up: if part of the mill is covered, isn&#8217;t all of it? Under OSHA&#8217;s interpretations, an interconnected process is treated as a single process, and if any part of it holds a listed chemical above the threshold, the whole interconnected process is covered. But in a kraft mill, the white liquor system and the bleach plant are not interconnected in that sense. They are linked by pulp moving from the cook side to the bleach side, not by any PSM-listed chemical flowing between them. So even where the bleach plant is covered, the white liquor tank generally falls outside that covered process. That said, this is an interpretation of federal law, and a lawyer should weigh in on any specific case.</p>



<p class="wp-block-paragraph">The practical read: it is more likely than not that this part of the plant was not covered by PSM or RMP at all.</p>



<p class="wp-block-paragraph">Two federal duties still apply regardless. The OSHA General Duty Clause, Section 5(a)(1), requires employers to keep a workplace free of recognized hazards whether or not a chemical is listed. The EPA Clean Air Act General Duty Clause, Section 112(r)(1), requires facilities handling hazardous substances to design and maintain a safe operation, listed or not. Those are the backstop when a tank falls outside both PSM and RMP on a listing technicality.</p>



<h3 class="wp-block-heading">Any additional requirements in the State of Washington</h3>



<p class="wp-block-paragraph">Washington enforces workplace safety itself, as a state-plan state, through the Department of Labor and Industries (L&amp;I) and its Division of Occupational Safety and Health (DOSH), not federal OSHA. It has its own rule modeled on federal PSM, WAC 296-67, with the same listed-chemical structure and thresholds, but no separate state list of additional regulated chemicals the way California does with CalARP, its accidental-release program. So the state PSM rule pulls the white liquor tank in no further than the federal one does.</p>



<p class="wp-block-paragraph">Where Washington does reach this facility directly is through WAC 296-79, &#8220;Safety standards for pulp, paper, and paperboard mills,&#8221; an industry-specific standard that applies regardless of PSM coverage. The Department of Ecology also holds dangerous-waste and spill authority, and is already engaged in the environmental response.</p>



<h3 class="wp-block-heading">Does this trigger functional safety via IEC 61511?</h3>



<p class="wp-block-paragraph">Likely no, not through regulation. This tank sits outside both PSM and RMP, and its white liquor system most likely isn&#8217;t part of any covered process at the mill. Since PSM and RMP are the route by which US regulation pulls in IEC 61511, the recognized and generally accepted good engineering practice (RAGAGEP) for safety instrumented systems (SIS), a tank that neither rule reaches isn&#8217;t pulled into IEC 61511 by them either. That is a regulatory point, not an engineering one: if a facility chose to guard a tank like this with a safety instrumented function (SIF) rather than a mechanical relief device, IEC 61511 would still be the standard to design, verify, and proof test it to. It just isn&#8217;t compelled here.</p>



<h2 class="wp-block-heading">What we do not know at the time of writing (June 2026)</h2>



<p class="wp-block-paragraph">Until more comes out, most likely through the CSB investigation, the important questions stay open.</p>



<ul class="wp-block-list">
<li>What pulled the tank into vacuum. A blocked or plugged vent, pump-out outrunning the make-up air, thermal contraction, or condensation after a steam-out could each do it.</li>



<li>The condition of the tank: its corrosion history in caustic service, when it was last inspected, and the age of the specific tank that failed.</li>



<li>Whether the tank vacuum protection was present and working. Whether a pressure and vacuum relief device or vacuum breaker was installed, sized per API 2000, and maintained, and whether the vacuum scenario was ever identified in the facility&#8217;s PHA.</li>



<li>The longer-term environmental and health impact of the white liquor that escaped into the site&#8217;s storm-drain and dike system.</li>
</ul>



<h2 class="wp-block-heading">Frequently Asked Questions</h2>



<h4 class="wp-block-heading">I used to work at a paper mill and it definitely had a functional safety program. You&#8217;re telling me this tank may not have been covered? Why is that?</h4>



<p class="wp-block-paragraph">Both things can be true. Your mill almost certainly did have a functional safety program, and it was almost certainly built around the bleach plant and chlorine dioxide generation, where the listed chemicals live and where PSM requires it. The white liquor system is a separate process. It is tied to the rest of the mill by pulp, not by any PSM-listed chemical, so it usually sits outside the covered process even at a mill that takes PSM seriously everywhere it applies. The program you remember was real. It just was likely not pointed at this tank, because the rules that drive those programs were not pointed there either.</p>



<h4 class="wp-block-heading">Why do so many states have extra regulations on top of PSM and RMP? Is that just a US thing?</h4>



<p class="wp-block-paragraph">To a large degree, yes. The US splits authority between federal and state government, and occupational and process safety is one of the areas where states are allowed to run their own show. About half the states operate their own OSHA-approved safety programs instead of deferring to federal OSHA, and they can be stricter than the federal floor, never weaker. On top of that, a few states have built their own chemical-accident programs, California&#8217;s CalARP being the best known, that add requirements beyond federal RMP.</p>



<p class="wp-block-paragraph">Most other countries run process safety through a single national framework, so the patchwork across US states is, in fact, fairly distinctive.</p>



<h4 class="wp-block-heading">My plant has atmospheric tanks of non-flammable caustic. After reading this, what should I be checking on Monday morning?</h4>



<p class="wp-block-paragraph">Start with the vent path. For each tank, confirm there is a vacuum relief device, that it is sized for your worst-case outflow plus thermal effects per API 2000, and that it is actually maintained, not painted over, corroded shut, or screened off by a bird guard nobody has looked at in years. Then check pump-out rates against that vent capacity, because the fastest way to pull a vacuum is to draw liquid out faster than air can come back in. Last, pull the PHA and see whether vacuum or low pressure shows up as a deviation with a credited safeguard. If the study spent ten pages on overpressure and one line on vacuum, that is your gap. None of this needs the CSB report.</p>



<h4 class="wp-block-heading">I work with safety instrumented systems for a living. Could a SIF have prevented this?</h4>



<p class="wp-block-paragraph">Possibly, and it is the right question to ask, though not automatically the right answer. The first line of defense against tank vacuum is mechanical: a properly sized, properly maintained vacuum relief device. That is simpler and more reliable than instrumentation for the basic breathing case, and it is what API 2000 is built around. A safety instrumented function earns its place when the mechanical layer cannot cover the credible scenarios on its own, say a pump-out rate that can outrun any practical vent, where you might credit a vacuum or low-pressure instrument that trips the outflow before the tank is endangered.</p>



<p class="wp-block-paragraph">Functional safety is complex, and the stakes are high. If you have questions about your SIS design, SIL verification, or where to start with IEC 61511, the team at SIL Safe is here to help. Reach out to us today.</p>



<h2 class="wp-block-heading">Further Reading</h2>



<p class="wp-block-paragraph"><strong>From SIL Safe</strong></p>



<ul class="wp-block-list">
<li><a href="https://silsafe.net/hazard-and-risk-analysis-methods/">Hazard and Risk Analysis Methods: How HAZOP, What-If, LOPA, Risk Graph, FTA, ETA, and Bowtie Fit Together</a></li>



<li><a href="https://silsafe.net/layer-of-protection-analysis-lopa/">Layer of Protection Analysis (LOPA): The Engineer&#8217;s Guide to SIL Selection</a></li>



<li><a href="https://silsafe.net/hazard-and-risk-assessment-hra/">Hazard and Risk Assessment (H&amp;RA): The Foundation of Functional Safety</a></li>



<li><a href="https://silsafe.net/qatar-gas-plant-explosion/" data-type="post" data-id="6960">The Qatar Gas Plant Explosion: What We Know So Far</a></li>
</ul>



<p class="wp-block-paragraph"><strong>External resources</strong></p>



<ul class="wp-block-list">
<li><a href="https://ecology.wa.gov/spills-cleanup/spills/spill-preparedness-response/responding-to-spill-incidents/spill-incidents/nippon-dynawave-industrial-incident" target="_blank" rel="noopener">Washington Department of Ecology, Nippon Dynawave Longview incident page</a></li>



<li><a href="https://www.csb.gov/us-chemical-safety-board-opens-investigation-into-fatal-chemical-tank-implosion-at-nippon-dynawave-paper-mill-in-washington/" target="_blank" rel="noopener">US Chemical Safety Board, investigation announcement</a></li>



<li><a href="https://en.wikipedia.org/wiki/2026_Longview,_Washington_paper_mill_implosion" target="_blank" rel="noopener">Wikipedia, &#8220;2026 Longview, Washington paper mill implosion&#8221;</a></li>



<li><a href="https://www.pbs.org/newshour/nation/crews-recover-remains-of-6-of-9-workers-missing-after-chemical-tank-rupture-in-washington" target="_blank" rel="noopener">PBS NewsHour (Associated Press), recovery and casualty coverage</a></li>



<li><a href="https://www.osha.gov/laws-regs/oshact/section5-duties" target="_blank" rel="noopener">OSHA, OSH Act Section 5 (General Duty Clause)</a></li>



<li><a href="https://lawfilesext.leg.wa.gov/law/WACArchive/2013/WAC-296-79-CHAPTER.pdf" target="_blank" rel="noopener">Washington L&amp;I, WAC 296-79, &#8220;Safety standards for pulp, paper, and paperboard mills&#8221;</a></li>
</ul>



<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "I used to work at a paper mill and it definitely had a functional safety program. You're telling me this tank may not have been covered? Why is that?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Both things can be true. Your mill almost certainly did have a functional safety program, and it was almost certainly built around the bleach plant and chlorine dioxide generation, where the listed chemicals live and where PSM requires it. The white liquor system is a separate process. It is tied to the rest of the mill by pulp, not by any PSM-listed chemical, so it usually sits outside the covered process even at a mill that takes PSM seriously everywhere it applies. The program you remember was real. It just was likely not pointed at this tank, because the rules that drive those programs were not pointed there either."
      }
    },
    {
      "@type": "Question",
      "name": "Why do so many states have extra regulations on top of PSM and RMP? Is that just a US thing?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "To a large degree, yes. The US splits authority between federal and state government, and occupational and process safety is one of the areas where states are allowed to run their own show. About half the states operate their own OSHA-approved safety programs instead of deferring to federal OSHA, and they can be stricter than the federal floor, never weaker. On top of that, a few states have built their own chemical-accident programs, California's CalARP being the best known, that add requirements beyond federal RMP."
      }
    },
    {
      "@type": "Question",
      "name": "My plant has atmospheric tanks of non-flammable caustic. After reading this, what should I be checking on Monday morning?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Start with the vent path. For each tank, confirm there is a vacuum relief device, that it is sized for your worst-case outflow plus thermal effects per API 2000, and that it is actually maintained, not painted over, corroded shut, or screened off by a bird guard nobody has looked at in years. Then check pump-out rates against that vent capacity, because the fastest way to pull a vacuum is to draw liquid out faster than air can come back in. Last, pull the PHA and see whether vacuum or low pressure shows up as a deviation with a credited safeguard. If the study spent ten pages on overpressure and one line on vacuum, that is your gap. None of this needs the CSB report."
      }
    },
    {
      "@type": "Question",
      "name": "I work with safety instrumented systems for a living. Could a SIF have prevented this?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Possibly, and it is the right question to ask, though not automatically the right answer. The first line of defense against tank vacuum is mechanical: a properly sized, properly maintained vacuum relief device. That is simpler and more reliable than instrumentation for the basic breathing case, and it is what API 2000 is built around. A safety instrumented function earns its place when the mechanical layer cannot cover the credible scenarios on its own, say a pump-out rate that can outrun any practical vent, where you might credit a vacuum or low-pressure instrument that trips the outflow before the tank is endangered."
      }
    }
  ]
}
</script>
]]></content:encoded>
					
					<wfw:commentRss>https://silsafe.net/longview-chemical-tank-implosion/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Functional Safety Is Not the Same as Occupational Safety</title>
		<link>https://silsafe.net/functional-safety-vs-occupational-safety/</link>
					<comments>https://silsafe.net/functional-safety-vs-occupational-safety/#respond</comments>
		
		<dc:creator><![CDATA[mamerten]]></dc:creator>
		<pubDate>Sat, 30 May 2026 19:43:25 +0000</pubDate>
				<category><![CDATA[Beginner]]></category>
		<guid isPermaLink="false">https://silsafe.net/?p=6690</guid>

					<description><![CDATA[Occupational safety, process safety, and functional safety are not the same discipline, and treating them as interchangeable is a common mistake at process facilities. Different training, different credentials, different daily work. Where the boundaries blur, the resulting errors are predictable and costly.]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Suppose a facility realizes functional safety applies to them. Maybe an auditor flagged it. Maybe a corporate directive came down. Maybe a near-miss made it impossible to ignore. The reaction is predictable: the Health, Safety, and Environment (HSE) team will handle it. It sounds reasonable on the face of it. Both have &#8220;safety&#8221; in the name. Both involve hazards. Both involve compliance. It is also wrong.</p>



<h2 class="wp-block-heading">The Disciplines Are Not the Same</h2>



<p class="wp-block-paragraph"><u>Occupational safety</u> is a discipline and a professional track. <u>Process safety</u> is an engineering discipline. <u>Functional safety</u> is an engineering discipline that follows a specific set of standards (IEC 61511 and IEC 61508) to implement risk reduction within process safety.</p>



<ul class="wp-block-list">
<li><strong>Occupational safety</strong> protects workers from workplace hazards: falls, struck-by, chemical exposure, ergonomics, noise, confined spaces, electrical contact.</li>



<li><strong>Process safety</strong> is the engineering discipline for preventing major accidents from the process itself, such as releases, fires, explosions, and runaway reactions.</li>



<li><strong>Functional safety</strong> sits inside process safety as the standards-based engineering discipline (IEC 61511 and IEC 61508) for reducing process risk through instrumented protective functions.</li>
</ul>



<p class="wp-block-paragraph">A Venn diagram makes the relationship clear. Occupational safety is a separate circle. Process safety is a larger circle. Functional safety is a circle inside process safety.</p>



<p class="wp-block-paragraph">Functional safety does not overlap with occupational safety as disciplines, though the two are adjacent and several site activities bring them together. They differ at the technical level, and skill sets do not transfer between them.</p>



<h2 class="wp-block-heading">The Professionals and Their Backgrounds</h2>



<p class="wp-block-paragraph">The discipline distinction shows up cleanly in who does the work, where they train, and what credentials or certifications they hold.</p>



<h3 class="wp-block-heading">Occupational safety professionals</h3>



<p class="wp-block-paragraph">The job type or discipline goes by several names depending on company and region: HSE (Health, Safety, and Environment), EHS (Environment, Health, and Safety), SHE (Safety, Health, and Environment), and HSSE (with Security added). The people doing the work carry an even longer list of job titles:</p>



<ul class="wp-block-list">
<li>Safety Manager</li>



<li>Safety Engineer</li>



<li>Safety Specialist</li>



<li>Safety Coordinator</li>



<li>HSE / EHS Manager</li>



<li>Health and Safety Officer</li>



<li>Industrial Hygienist</li>



<li>Occupational Health Specialist</li>



<li>Director of EHS / HSE</li>
</ul>



<p class="wp-block-paragraph">At SIL Safe, we refer to all of these roles collectively as occupational safety. Backgrounds run through occupational health and safety, industrial hygiene, environmental health, and sometimes engineering or kinesiology. Industrial hygiene is the field that figures out what workers are being exposed to on the job (chemicals, dust, noise, heat) and gets the exposure down to safe levels.</p>



<p class="wp-block-paragraph">Professional bodies include the Board of Certified Safety Professionals (BCSP), the American Industrial Hygiene Association (AIHA), the UK Institution of Occupational Safety and Health (IOSH), the British Occupational Hygiene Society (BOHS), and the International Occupational Hygiene Association (IOHA) as the global umbrella.</p>



<p class="wp-block-paragraph">Credentials include the Certified Safety Professional (CSP), the Certified Industrial Hygienist (CIH), and the Chartered Member of IOSH (CMIOSH).</p>



<p class="wp-block-paragraph">Day-to-day work is workplace chemical exposure monitoring (airborne contaminants, dust, vapors), Personal Protective Equipment (PPE) programs, ergonomic assessments, incident investigation for personnel injuries, and regulatory compliance for worker protection.</p>



<h3 class="wp-block-heading">Process safety professionals</h3>



<p class="wp-block-paragraph">Backgrounds are typically chemical engineering, though mechanical, electrical and controls, and other engineering disciplines with relevant process experience are also represented.</p>



<p class="wp-block-paragraph">Professional bodies include the Center for Chemical Process Safety (CCPS, part of the American Institute of Chemical Engineers, AIChE), the Institution of Chemical Engineers (IChemE) in the UK, and the Mary Kay O&#8217;Connor Process Safety Center on the academic side.</p>



<p class="wp-block-paragraph">Credentials include the Certified Process Safety Professional (CCPSC) via CCPS, IChemE professional registration, and often a Professional Engineer license (PE in the United States, P.Eng in Canada, CEng in the UK) in chemical, electrical, or other relevant engineering field.</p>



<p class="wp-block-paragraph">Day-to-day work is Hazard and Operability (HAZOP) and Layer of Protection Analysis (LOPA) facilitation, mechanical integrity programs, management of change, and Process Hazard Analysis (PHA) revalidation.</p>



<h3 class="wp-block-heading">Functional safety professionals</h3>



<p class="wp-block-paragraph">Functional safety professionals come from the same engineering backgrounds as process safety professionals, with deeper instrumentation, controls, and reliability engineering experience. The same professional bodies apply (AIChE, IChemE, and equivalents cover functional safety to a degree), with additional bodies that focus directly on it: TÜV Rheinland, TÜV SÜD, Exida, and the CFSE Governance Board.</p>



<p class="wp-block-paragraph">The directly relevant credentials are the Certified Functional Safety Expert (CFSE) and Certified Functional Safety Professional (CFSP) from Exida, and TÜV FS Eng. Additionally, the International Society of Automation (ISA) and Underwriters Laboratories (UL) offer certifications.</p>



<p class="wp-block-paragraph">Day-to-day work spans the full life-cycle: Safety Instrumented System (SIS) design and verification, proof testing oversight, functional safety audits, training, procedure maintenance, and competency matrix management, all governed by IEC 61511.</p>



<p class="wp-block-paragraph">Occupational safety credentials and process / functional safety credentials do not cross. A CIH is not on a track to become a CFSE. The training, the math, and the body of standards are different worlds. Process safety and functional safety credentials, on the other hand, do cross. The underlying engineering background is the same, and many practitioners hold both. A CCPSC who is also a CFSE is a common and useful profile.</p>



<h2 class="wp-block-heading">Where Functional Safety Meets Occupational Safety</h2>



<p class="wp-block-paragraph">The disciplines are not sealed off from each other.</p>



<ul class="wp-block-list">
<li><strong>Hazardous area classification.</strong> Process safety defines the zones (Class I Div 1/2, Zone 0/1/2) based on the flammable inventory and release sources. Occupational safety enforces the consequences in the field: no uncertified tools, no non-intrinsically-safe radios, no work without the right PPE and procedures. A worker cannot walk into a Zone 1 area with an off-the-shelf iPad or their phone in their pocket. The classification is a process safety output. The daily enforcement is an occupational discipline.</li>



<li><strong>Personal gas monitors (flammable gas / Lower Explosive Limit, hydrogen sulfide, oxygen).</strong> A worker wearing a personal monitor is an occupational control protecting that worker from a process hazard. The hazard originated in the process. The control is occupational. Both disciplines have a stake.</li>



<li><strong>Confined space entry.</strong> Occupational program (permits, attendants, retrieval), but the atmosphere being tested exists because of process residues and the equipment being entered is process equipment. The entry decision depends on understanding the process chemistry: what was last in the vessel, what reactions are possible, what residual hazards remain after isolation.</li>
</ul>



<p class="wp-block-paragraph">Overlap at the activity level is real and common practice in a healthy organization. Overlap at the competency level is minimal. The HSE professional running the confined space program is not qualified to verify a Safety Integrity Level 2 (SIL 2) Safety Instrumented Function (SIF). The functional safety engineer verifying that SIF is not qualified to write the confined space program. The activities cross. The competencies do not.</p>



<h2 class="wp-block-heading">Common Mistakes</h2>



<p class="wp-block-paragraph"><strong>Strong personnel safety record interpreted as process safety health.</strong> A facility logs years without a recordable injury, leadership concludes the safety program is working, and a major release blindsides them six months later. Texas City, Buncefield, and Jaipur all happened at facilities with strong personnel safety records. The Baker Panel report after Texas City made this pattern explicit: BP had been managing personal safety while neglecting process safety. Personnel injury rate measures slips, trips, hand cuts, and ergonomic strains. None of those metrics tell you anything about whether the SIS will work on demand or whether the relief valves are adequately sized.</p>



<ul class="wp-block-list">
<li><strong>Leadership asking for process safety KPIs and getting handed occupational ones.</strong> Boards and executives ask &#8220;how safe are we?&#8221; and HSE shows them Total Recordable Incident Rate (TRIR), Lost Time Incident Rate (LTIR), and Days Away, Restricted, or Transferred (DART) trending down. The metrics are real and the trend may be real, but they answer a different question. Process safety health is measured by leading indicators tied to Process Safety Management (PSM) and Risk-Based Process Safety (RBPS) elements: management of change (MOC) backlog, PHA action items overdue, proof test completion rate, SIF demand rate. Personnel injury statistics are not those indicators.</li>



<li><strong>Putting functional safety under the HSE function.</strong> Org chart logic (&#8220;safety is safety, put it under the safety guy&#8221;) or cost pressure pushes functional safety, the Safety Requirements Specification (SRS), and the Hazard and Risk Assessment (H&amp;RA) under HSE ownership. The work either gets skipped or gets done badly by someone with the wrong training, and the deliverables end up in the wrong hands organizationally.</li>
</ul>



<h2 class="wp-block-heading">Frequently Asked Questions</h2>



<h4 class="wp-block-heading">My boss says our safety manager can handle the SIL stuff. What do I tell him?</h4>



<p class="wp-block-paragraph">Tell him that your safety manager is properly an Occupational Safety Manager by role, even though the actual title varies (Safety Manager, HSE Manager, EHS Director, and so on). An occupational safety professional is fundamentally a different animal than a functional safety engineer. The safety manager probably runs PPE programs, exposure monitoring, ergonomic assessments, and injury investigations. SIL work is a different domain: IEC 61511, SIS architecture, failure modes, reliability mathematics, proof testing. The training does not transfer, and the credentials do not overlap. A CSP is not on a track to a CFSE, and a few hours of online refresher will not bridge the gap.</p>



<p class="wp-block-paragraph">In the safety manager&#8217;s defense, occupational safety professionals carry a confusing array of job titles, and the word &#8220;safety&#8221; appearing in both disciplines does not help. The conflation is understandable. The substitution is not. The two roles can sit in the same organization and respect each other, but one cannot substitute for the other.</p>



<h4 class="wp-block-heading">Isn&#8217;t process safety just functional safety at a bigger scale?</h4>



<p class="wp-block-paragraph">It is the other way around. Process safety is the broader engineering discipline. Functional safety is a subset of process safety, tied to the standards (IEC 61511 and IEC 61508) that govern instrumented protective functions. HAZOP, LOPA, mechanical integrity, management of change, and Pre-Startup Safety Review are all process safety activities that are not functional safety.</p>



<h4 class="wp-block-heading">We have an excellent TRIR. Doesn&#8217;t that mean our process safety program is working?</h4>



<p class="wp-block-paragraph">No, but there is some overlap. A process safety incident with injuries does show up in TRIR. The metric itself is dominated by occupational events, though: slips, trips, hand cuts, strains. A facility can drive TRIR to industry-leading levels while its SIS portfolio is overdue for proof testing, its MOC backlog is unmanaged, and its layers of protection have eroded. The Baker Panel report after Texas City documented exactly that pattern at BP. TRIR is a useful occupational metric. It is not a leading indicator of functional safety or process safety health.</p>



<h4 class="wp-block-heading">If a personal gas monitor protects a worker from a process release, why isn&#8217;t it a LOPA credit?</h4>



<p class="wp-block-paragraph">A personal gas monitor can sometimes meet IPL (Independent Protection Layer) criteria within a functional safety LOPA, but the claim is often made without testing them. An IPL must satisfy three requirements:</p>



<ul class="wp-block-list">
<li><strong>Independence.</strong> The protection layer cannot share failure modes with the initiating cause or with other claimed layers.</li>



<li><strong>Specificity to the scenario.</strong> The monitor must detect the specific release and give the wearer enough time to act before harm.</li>



<li><strong>Auditability.</strong> Calibration records, bump test records, and battery and gas check records must be in place and reviewable.</li>
</ul>



<p class="wp-block-paragraph">Take two scenarios:</p>



<ul class="wp-block-list">
<li><strong>Slow flange leak detected on a routine round.</strong> The wearer has time to back away, and an audited monitor program can credibly support an IPL claim for that scenario.</li>



<li><strong>Line rupture that puts the wearer in a vapor cloud within seconds.</strong> The same monitor cannot stand as an IPL, because the detection-to-action time is not there.</li>
</ul>



<p class="wp-block-paragraph">The other common failures are claiming credit against the wrong consequence type (the monitor does nothing about equipment damage, fire escalation, or fence-line population) and double-counting the same monitor across multiple scenarios where independence does not hold. A personal gas monitor is a real occupational control that saves lives. It is not, by default, a LOPA credit, and the judgment can be tricky.</p>



<h4 class="wp-block-heading">Does the functional safety person need to work with and talk to the HSE / occupational safety team?</h4>



<p class="wp-block-paragraph">Absolutely, they should be considered colleagues. Hazardous area classification needs both sides aligned: process safety defines the zones, and HSE enforces the field consequences. Personal gas monitor programs cross both disciplines, with the monitor itself an occupational control protecting against a process hazard. Confined space work that involves SIS equipment needs functional safety input on bypass and recovery procedures, while the HSE program owns the entry permit itself. The relationship is collaborative, not hierarchical. Each side owns its discipline.</p>



<h2 class="wp-block-heading">Further Reading</h2>



<p class="wp-block-paragraph"><strong>From SIL Safe</strong></p>



<ul class="wp-block-list">
<li><a href="https://silsafe.net/hazard-and-risk-assessment-hra/">Hazard and Risk Assessment (H&amp;RA): The Foundation of Functional Safety</a></li>



<li><a href="https://silsafe.net/layer-of-protection-analysis-lopa/">Layer of Protection Analysis (LOPA): The Engineer&#8217;s Guide to SIL Selection</a></li>



<li><a href="https://silsafe.net/sil-verification-three-gates/">SIL Verification: The Three Gates Every SIF Must Clear</a></li>
</ul>



<p class="wp-block-paragraph"><strong>External resources</strong></p>



<ul class="wp-block-list">
<li><a href="https://webstore.iec.ch/en/publication/5527" target="_blank" rel="noopener">IEC 61511 standard page (IEC)</a></li>



<li><a href="https://www.hse.gov.uk/comah/" target="_blank" rel="noopener">UK Health and Safety Executive: Control of Major Accident Hazards (COMAH)</a></li>



<li><a href="https://www.aiha.org/ih-careers/discover-industrial-hygiene" target="_blank" rel="noopener">American Industrial Hygiene Association: Discover Industrial Hygiene</a></li>



<li><a href="https://ioha.net/" target="_blank" rel="noopener">International Occupational Hygiene Association (IOHA)</a></li>
</ul>



<p class="wp-block-paragraph">Functional safety is complex, and the stakes are high. If you have questions about your SIS design, SIL verification, or where to start with IEC 61511, the team at SIL Safe is here to help. Reach out to us today.</p>



<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "My boss says our safety manager can handle the SIL stuff. What do I tell him?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Tell him that your safety manager is properly an Occupational Safety Manager by role, even though the actual title varies (Safety Manager, HSE Manager, EHS Director, and so on). An occupational safety professional is fundamentally a different animal than a functional safety engineer. The safety manager probably runs PPE programs, exposure monitoring, ergonomic assessments, and injury investigations. SIL work is a different domain: IEC 61511, SIS architecture, failure modes, reliability mathematics, proof testing. The training does not transfer, and the credentials do not overlap. A CSP is not on a track to a CFSE, and a few hours of online refresher will not bridge the gap."
      }
    },
    {
      "@type": "Question",
      "name": "Isn't process safety just functional safety at a bigger scale?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "It is the other way around. Process safety is the broader engineering discipline. Functional safety is a subset of process safety, tied to the standards (IEC 61511 and IEC 61508) that govern instrumented protective functions. HAZOP, LOPA, mechanical integrity, management of change, and Pre-Startup Safety Review are all process safety activities that are not functional safety."
      }
    },
    {
      "@type": "Question",
      "name": "We have an excellent TRIR. Doesn't that mean our process safety program is working?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No, but there is some overlap. A process safety incident with injuries does show up in TRIR. The metric itself is dominated by occupational events, though: slips, trips, hand cuts, strains. A facility can drive TRIR to industry-leading levels while its SIS portfolio is overdue for proof testing, its MOC backlog is unmanaged, and its layers of protection have eroded. The Baker Panel report after Texas City documented exactly that pattern at BP. TRIR is a useful occupational metric. It is not a leading indicator of functional safety or process safety health."
      }
    },
    {
      "@type": "Question",
      "name": "If a personal gas monitor protects a worker from a process release, why isn't it a LOPA credit?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "A personal gas monitor can sometimes meet IPL (Independent Protection Layer) criteria within a functional safety LOPA, but the claim is often made without testing them. An IPL must satisfy three requirements:"
      }
    },
    {
      "@type": "Question",
      "name": "Does the functional safety person need to work with and talk to the HSE / occupational safety team?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Absolutely, they should be considered colleagues. Hazardous area classification needs both sides aligned: process safety defines the zones, and HSE enforces the field consequences. Personal gas monitor programs cross both disciplines, with the monitor itself an occupational control protecting against a process hazard. Confined space work that involves SIS equipment needs functional safety input on bypass and recovery procedures, while the HSE program owns the entry permit itself. The relationship is collaborative, not hierarchical. Each side owns its discipline."
      }
    }
  ]
}
</script>
]]></content:encoded>
					
					<wfw:commentRss>https://silsafe.net/functional-safety-vs-occupational-safety/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The Garden Grove Chemical Incident: What We Know So Far</title>
		<link>https://silsafe.net/garden-grove-chemical-incident/</link>
					<comments>https://silsafe.net/garden-grove-chemical-incident/#respond</comments>
		
		<dc:creator><![CDATA[mamerten]]></dc:creator>
		<pubDate>Tue, 26 May 2026 22:02:23 +0000</pubDate>
				<category><![CDATA[Advanced]]></category>
		<guid isPermaLink="false">https://silsafe.net/?p=6633</guid>

					<description><![CDATA[A tank of methyl methacrylate at a GKN Aerospace facility in Garden Grove, California has been the center of a multi-day chemical emergency. This article walks through the facility, the chemistry of the hazard, and the US regulatory analysis of whether OSHA PSM, EPA RMP, and California's CalARP apply.]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A tank of methyl methacrylate (MMA) at a GKN Aerospace facility in Garden Grove, California has been the center of a multi-day chemical emergency that displaced tens of thousands of residents and put roughly nine square miles of Orange County under evacuation. The situation is active as of writing, and what follows is a US regulatory and functional safety perspective, not a root cause analysis.</p>



<h2 class="wp-block-heading">What is the GKN Aerospace facility?</h2>



<p class="wp-block-paragraph">The site is operated by GKN Aerospace Transparency Systems Inc., a subsidiary of GKN Aerospace, and sits on roughly 15.5 acres in Garden Grove, California. GKN has been at this location since 2004.</p>



<p class="wp-block-paragraph">The facility makes the windows and canopies of major aircraft. The Garden Grove site designs and produces cockpit canopies, fighter canopies, and passenger windows, including the F-35 canopy and transparencies for the Boeing 787 and 737, the Airbus A350, HondaJet, and the Bombardier C-Series. Those transparencies are made from polymethyl methacrylate (PMMA, also known as acrylic, Plexiglas, or Lucite), and that is why a substantial inventory of MMA is on site. MMA is the monomer feedstock for making the polymer.</p>



<h2 class="wp-block-heading">The tank and the chemical</h2>



<p class="wp-block-paragraph">Methyl methacrylate is a colorless flammable liquid monomer with a fruity odor. Its flash point is 36°F (2°C), which puts it in the same general &#8220;ignites at room temperature&#8221; category as gasoline (flash point roughly -45°F). For context on the other end of the common fuels, diesel sits around 125°F. The boiling point of MMA is 214°F (101°C), so it stays liquid through any realistic ambient condition.</p>



<p class="wp-block-paragraph">The tank has a capacity of approximately 34,000 gallons; reporting indicates an MMA inventory of 6,000 to 7,000 gallons at the time of the incident. From photos circulating in news coverage, the tank appears to be fully enclosed, fixed-roof construction with external insulation that has since been removed by responders to aid cooling. Enclosure alone does not determine whether the tank is &#8220;atmospheric&#8221; in the regulatory sense, which has a specific technical meaning that matters for the PSM analysis.</p>



<p class="wp-block-paragraph">The reason MMA is stored with care is that it is a reactive monomer. If temperature control is lost or if the inhibitor (typically methyl ether of hydroquinone, MEHQ, at low ppm) is depleted, MMA can undergo exothermic polymerization, where the chemical reacts with itself to form the polymer. That reaction releases heat, which accelerates the reaction, which releases more heat. That is the runaway pattern, and once it starts there is no easy way to stop it. It is the central hazard of bulk MMA storage and the reason a tank of this material is taken so seriously.</p>



<h2 class="wp-block-heading">What occurred in May 2026</h2>



<p class="wp-block-paragraph">The incident began on May 21, 2026, when the storage tank started overheating and venting vapors. Orange County Fire Authority responded that afternoon, and over the next several days the Garden Grove chemical incident escalated. The evacuation zone started as a roughly one-mile radius around the facility, then expanded to cover approximately nine square miles, ultimately displacing somewhere between 44,000 and 50,000 residents. The Governor of California declared a state of emergency.</p>



<p class="wp-block-paragraph">As of writing, stabilization efforts are ongoing. Reports indicate that a crack in the tank may have vented pressure and reduced the immediate explosion risk, but the data is preliminary. The Orange County District Attorney has opened a tip line for information related to GKN&#8217;s operations.</p>



<p class="wp-block-paragraph">The cause of the temperature excursion has not been publicly established, and we do not speculate.</p>



<h2 class="wp-block-heading">What regulations apply?</h2>



<p class="wp-block-paragraph">The Garden Grove chemical incident plays out under three US frameworks: OSHA&#8217;s Process Safety Management (PSM) standard, EPA&#8217;s Risk Management Program (RMP), and California&#8217;s CalARP. International readers will be familiar with frameworks like Seveso (EU) and COMAH (UK), which operate on a different basis and are not within scope here.</p>



<h3 class="wp-block-heading">Does OSHA PSM apply?</h3>



<p class="wp-block-paragraph">PSM (29 CFR 1910.119) has two pathways for coverage. One is the list of specifically named highly hazardous chemicals in Appendix A. MMA is not on that list. The other pathway, in 1910.119(a)(1)(ii), covers any process involving a flammable liquid with a flash point below 100°F in quantities of 10,000 lb or more at one location.</p>



<p class="wp-block-paragraph">MMA clears both criteria easily:</p>



<ul class="wp-block-list">
<li>Flash point of 36°F is well below the 100°F threshold.</li>



<li>At a density of 0.94 g/cm³, even the lower-end reported inventory of 6,000 gallons is roughly 47,000 lb.</li>
</ul>



<p class="wp-block-paragraph">The MMA storage at GKN satisfies the PSM flammable liquid trigger. The standard has an important exemption.</p>



<p class="wp-block-paragraph">The atmospheric tank exemption in 1910.119(a)(1)(ii)(B) excludes flammable liquids stored in atmospheric tanks kept below their normal boiling point without chilling or refrigeration. Two things to get right here:</p>



<ul class="wp-block-list">
<li>&#8220;Atmospheric tank&#8221; is a pressure-rating definition, not a description of the lid. Many atmospheric tanks have fixed roofs, vents, and conservation devices. A tank can be fully enclosed and still be atmospheric.</li>



<li>The &#8220;below normal boiling point without chilling&#8221; condition is satisfied by ordinary ambient storage of MMA. MMA boils at 214°F and an unrefrigerated tank at typical ambient temperature is well below that.</li>
</ul>



<p class="wp-block-paragraph">On the pressure-rating side, the GKN tank is almost certainly atmospheric. Bulk MMA storage in industry is standard atmospheric tank service. The vapor pressure of MMA at typical storage temperature is low, and there is no operational reason to put MMA in a pressure-rated vessel. The major MMA producers describe atmospheric storage practice on their technical data sheets. So the pressure-rating element of the test is not the issue. The issue, as covered further below, is the chilling and refrigeration clause.</p>



<p class="wp-block-paragraph">The atmospheric tank exemption is the reason every gas station in the US is not subject to PSM and RMP. OSHA&#8217;s view was that ordinary atmospheric storage of flammable liquids is adequately covered by NFPA 30, API 650, OSHA&#8217;s own 1910.106 flammable liquids standard, and local fire code.</p>



<p class="wp-block-paragraph">Interconnection cuts the other direction. If something else on the GKN site triggers PSM (a covered process, a covered chemical inventory elsewhere), and the MMA tank is interconnected to it through piping, the MMA tank gets pulled into scope by virtue of that connection. So even if the MMA tank by itself qualifies for the atmospheric tank exemption, the tank may still be PSM-covered through the rest of the facility. Whether that is the case at GKN depends on facility details that are not public.</p>



<h4 class="wp-block-heading">Regulatory uncertainty of a chiller</h4>



<p class="wp-block-paragraph">One more wrinkle, and this is where engineering ends and law begins. According to OCFA statements during the response, the MMA tank had an active cooling system designed to keep the contents at around 50°F, and the failure of that cooling system was central to the incident. The atmospheric tank exemption requires storage &#8220;kept below their normal boiling point without benefit of chilling or refrigeration.&#8221; That clause supports two reads:</p>



<ul class="wp-block-list">
<li>&#8220;No chilling of any kind.&#8221; Any chilling on the tank disqualifies the exemption.</li>



<li>&#8220;No chilling needed to keep below boiling.&#8221; Only chilling that exists to manage boiling point disqualifies the exemption. Chilling for other purposes (polymerization control, viscosity control) does not.</li>
</ul>



<p class="wp-block-paragraph">MMA boils at 214°F and would stay well below boiling at any reasonable ambient temperature with no cooling at all. The cooling system at GKN was almost certainly there to suppress the polymerization reaction, not to keep the liquid below boiling. So a refrigerated MMA tank sits squarely in the gap between those two readings. This is the kind of question engineers end up handing to lawyers, because regulatory interpretation isn&#8217;t an engineering call.</p>



<h3 class="wp-block-heading">Does EPA RMP apply?</h3>



<p class="wp-block-paragraph">EPA&#8217;s Risk Management Program (RMP, 40 CFR Part 68) works differently from PSM. Rather than a generic flammable-liquid trigger, RMP applies only to a curated list of regulated substances in 40 CFR 68.130. MMA is not on that list.</p>



<p class="wp-block-paragraph">The reason MMA is not on the list comes down to chemistry. EPA built Table 3 (the flammable substances portion) using the criteria for a flammability rating of 4 on the NFPA 704 fire diamond, which require flash point below 73°F AND boiling point below 100°F. MMA&#8217;s flash point of 36°F clears the first hurdle, but its boiling point of 214°F fails the second by a wide margin. The substances that did make Table 3 are predominantly gases or near-gases at ambient: propane, ethylene, butadiene, methane. These are the materials that flash to vapor on release and produce expanding vapor clouds. MMA does not fit that profile.</p>



<p class="wp-block-paragraph">Therefore, RMP does not apply to MMA storage at GKN.</p>



<h3 class="wp-block-heading">California regulation: CalARP</h3>



<p class="wp-block-paragraph">California has a state-level analog called CalARP (California Accidental Release Prevention Program, Title 19 CCR §5130.6). MMA is not on any CalARP table, so CalARP does not apply either.</p>



<p class="wp-block-paragraph">Even if any of these regulations did apply, none of them directly require IEC 61511. They require &#8220;recognized and generally accepted good engineering practices&#8221; (RAGAGEP) for safety-critical systems, and IEC 61511 is the RAGAGEP for safety instrumented systems in the process industry. The hook into functional safety is by reference, not by name.</p>



<h2 class="wp-block-heading">Was OSHA PSM actually being applied at GKN?</h2>



<p class="wp-block-paragraph">There is no way to know with certainty from outside the fence line.</p>



<p class="wp-block-paragraph">OSHA does not maintain a public registry of PSM-covered facilities. Coverage is self-determining; an operator evaluates its own processes against the standard, and verification happens through inspections.</p>



<p class="wp-block-paragraph">Prior OSHA inspections and worker complaints at the Garden Grove site have been reported in recent coverage, along with a 2018 California Department of Industrial Relations penalty involving machinery and fabrication concerns. None of that confirms whether PSM applied to the MMA storage. Those inspections may have addressed occupational safety topics like machine guarding, lockout-tagout, and fall protection rather than process safety. The two are distinct disciplines, often handled by different teams inside a facility and inspected against different standards.</p>



<p class="wp-block-paragraph">GKN&#8217;s public statement says the company &#8220;follows all standard safety protocols and processes and is regularly audited by numerous state and federal agencies.&#8221; The statement does not specifically address PSM coverage of the MMA storage.</p>



<h2 class="wp-block-heading">Is there evidence GKN has a functional safety program?</h2>



<p class="wp-block-paragraph">Not publicly. Functional safety programs (IEC 61511 SIS implementations, SIL verifications, safety requirements specifications) are not typically disclosed publicly by operators. They live in internal documentation and are reviewed by regulators or third-party assessors, not posted on company websites.</p>



<p class="wp-block-paragraph">The Orange County DA tip line and ongoing investigations suggest authorities are looking at safety system adequacy, but no findings are public.</p>



<h2 class="wp-block-heading">Has the CSB said anything?</h2>



<p class="wp-block-paragraph">The US Chemical Safety and Hazard Investigation Board (CSB) is an independent federal agency that investigates industrial chemical accidents. As of writing, the CSB has not publicly announced a deployment to the Garden Grove chemical incident.</p>



<h2 class="wp-block-heading">What we do not know at the time of writing (May 2026)</h2>



<ul class="wp-block-list">
<li>The cause of the temperature excursion. Public reporting has not established what initiated the runaway, and we do not speculate.</li>



<li>What safety systems were in place at GKN, and how they performed.</li>



<li>Whether GKN&#8217;s specific tank configuration qualifies for the atmospheric tank exemption. That requires facility data not in public reporting.</li>



<li>Long-term health and environmental impact in the affected zone.</li>



<li>Anything that would require information held by GKN, OSHA, EPA, or the Orange County Fire Authority but not yet released publicly.</li>
</ul>



<h2 class="wp-block-heading">Frequently Asked Questions</h2>



<h4 class="wp-block-heading">What is MMA and why is it stored in tanks like this?</h4>



<p class="wp-block-paragraph">MMA is methyl methacrylate, a flammable liquid organic compound. It is a monomer, meaning a small molecule that chemically links with copies of itself to form a long-chain polymer. The polymer in MMA&#8217;s case is polymethyl methacrylate (PMMA, also called acrylic or Plexiglas). Bulk MMA storage is common anywhere PMMA is manufactured.</p>



<h4 class="wp-block-heading">Is methyl methacrylate covered by OSHA PSM?</h4>



<p class="wp-block-paragraph">Possibly. MMA is not on the OSHA PSM Appendix A list of named highly hazardous chemicals, but PSM has a separate pathway for flammable liquids with flash point below 100°F in quantities of 10,000 lb or more. MMA meets both criteria. The complication is the atmospheric tank exemption, which excludes flammable liquids in atmospheric tanks kept below boiling point without chilling or refrigeration. For an unrefrigerated MMA tank at ordinary ambient conditions, the exemption likely applies. For a refrigerated MMA tank like the one at GKN, applicability is genuinely unsettled and depends on how the chilling clause is interpreted.</p>



<h4 class="wp-block-heading">The tank at GKN has a lid on it. Doesn&#8217;t that mean it&#8217;s not an atmospheric tank under PSM?</h4>



<p class="wp-block-paragraph">No. &#8220;Atmospheric tank&#8221; in 1910.119 is a pressure-rating definition, not a description of whether the tank is open to the air. Most atmospheric tanks have fixed roofs, vents, manways, and conservation devices. A tank can be fully enclosed and still be atmospheric. What disqualifies a tank from being atmospheric is being designed and rated for higher internal pressure than atmospheric service. The presence of a lid is not the deciding factor.</p>



<h4 class="wp-block-heading">Do engineers ever need lawyers to interpret regulatory language?</h4>



<p class="wp-block-paragraph">More often than people outside the field would guess. Regulations like PSM are written in language that looks straightforward but contains clauses with multiple defensible readings. The atmospheric tank exemption is a good example: the phrase &#8220;kept below their normal boiling point without benefit of chilling or refrigeration&#8221; can mean &#8220;no chilling of any kind&#8221; or &#8220;no chilling needed for boiling-point control,&#8221; and a tank that is refrigerated for a non-boiling-point reason sits squarely in the gap between those two readings. Engineers can describe the tank, the chemistry, and how the system operates. Whether those facts add up to the exemption applying or not is a regulatory interpretation question, and that is lawyer territory. On material questions, engineering and legal teams have to work together — the engineer establishes what the system is, and the lawyer establishes what the regulation says about it.</p>



<h2 class="wp-block-heading">Further Reading</h2>



<p class="wp-block-paragraph"><strong>From SIL Safe</strong></p>



<ul class="wp-block-list">
<li><a href="https://silsafe.net/hazard-and-risk-assessment-hra/">Hazard and Risk Assessment (H&amp;RA): The Foundation of Functional Safety</a></li>



<li><a href="https://silsafe.net/layer-of-protection-analysis-lopa/">Layer of Protection Analysis (LOPA): The Engineer&#8217;s Guide to SIL Selection</a></li>



<li><a href="https://silsafe.net/qatar-gas-plant-explosion/" data-type="post" data-id="6960">The Qatar Gas Plant Explosion: What We Know So Far</a></li>
</ul>



<p class="wp-block-paragraph"><strong>External resources</strong></p>



<ul class="wp-block-list">
<li><a href="https://en.wikipedia.org/wiki/Garden_Grove_chemical_leak" target="_blank" rel="noopener">Garden Grove chemical leak — Wikipedia</a></li>



<li><a href="https://www.npr.org/2026/05/24/nx-s1-5833165/california-chemical-tank-malfunction-leak-explode-emergency-evacuate" target="_blank" rel="noopener">California chemical tank has cracked, causing state of emergency, thousands to evacuate — NPR</a></li>



<li><a href="https://www.nbclosangeles.com/news/local/live-updates-garden-grove-chemical-tank-emergency/3894473/" target="_blank" rel="noopener">Live updates: Garden Grove chemical tank emergency — NBC Los Angeles</a></li>



<li><a href="https://calepa.ca.gov/california-accidental-release-prevention/" target="_blank" rel="noopener">CalEPA — California Accidental Release Prevention (CalARP) Program</a></li>



<li><a href="https://www.csb.gov/" target="_blank" rel="noopener">US Chemical Safety and Hazard Investigation Board</a></li>



<li><a href="https://www.cdc.gov/niosh/npg/npgd0426.html" target="_blank" rel="noopener">CDC/NIOSH Pocket Guide — Methyl Methacrylate</a></li>
</ul>



<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "What is MMA and why is it stored in tanks like this?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "MMA is methyl methacrylate, a flammable liquid organic compound. It is a monomer, meaning a small molecule that chemically links with copies of itself to form a long-chain polymer. The polymer in MMA's case is polymethyl methacrylate (PMMA, also called acrylic or Plexiglas). Bulk MMA storage is common anywhere PMMA is manufactured."
      }
    },
    {
      "@type": "Question",
      "name": "Is methyl methacrylate covered by OSHA PSM?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Possibly. MMA is not on the OSHA PSM Appendix A list of named highly hazardous chemicals, but PSM has a separate pathway for flammable liquids with flash point below 100°F in quantities of 10,000 lb or more. MMA meets both criteria. The complication is the atmospheric tank exemption, which excludes flammable liquids in atmospheric tanks kept below boiling point without chilling or refrigeration. For an unrefrigerated MMA tank at ordinary ambient conditions, the exemption likely applies. For a refrigerated MMA tank like the one at GKN, applicability is genuinely unsettled and depends on how the chilling clause is interpreted."
      }
    },
    {
      "@type": "Question",
      "name": "The tank at GKN has a lid on it. Doesn't that mean it's not an atmospheric tank under PSM?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No. \"Atmospheric tank\" in 1910.119 is a pressure-rating definition, not a description of whether the tank is open to the air. Most atmospheric tanks have fixed roofs, vents, manways, and conservation devices. A tank can be fully enclosed and still be atmospheric. What disqualifies a tank from being atmospheric is being designed and rated for higher internal pressure than atmospheric service. The presence of a lid is not the deciding factor."
      }
    },
    {
      "@type": "Question",
      "name": "Do engineers ever need lawyers to interpret regulatory language?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "More often than people outside the field would guess. Regulations like PSM are written in language that looks straightforward but contains clauses with multiple defensible readings. The atmospheric tank exemption is a good example: the phrase \"kept below their normal boiling point without benefit of chilling or refrigeration\" can mean \"no chilling of any kind\" or \"no chilling needed for boiling-point control,\" and a tank that is refrigerated for a non-boiling-point reason sits squarely in the gap between those two readings. Engineers can describe the tank, the chemistry, and how the system operates. Whether those facts add up to the exemption applying or not is a regulatory interpretation question, and that is lawyer territory. On material questions, engineering and legal teams have to work together — the engineer establishes what the system is, and the lawyer establishes what the regulation says about it."
      }
    }
  ]
}
</script>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
					<wfw:commentRss>https://silsafe.net/garden-grove-chemical-incident/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>SIL Verification: The Three Gates Every SIF Must Clear</title>
		<link>https://silsafe.net/sil-verification-three-gates/</link>
					<comments>https://silsafe.net/sil-verification-three-gates/#respond</comments>
		
		<dc:creator><![CDATA[mamerten]]></dc:creator>
		<pubDate>Sun, 10 May 2026 19:42:39 +0000</pubDate>
				<category><![CDATA[Advanced]]></category>
		<guid isPermaLink="false">https://silsafe.net/?p=6515</guid>

					<description><![CDATA[SIL verification under IEC 61511 is three independent gates, all of which must pass: PFDavg, systematic capability, and architectural constraints. The gate that gets the most attention rarely fails an audit. This article walks through each gate, where each one fails, and three worked scenarios that show how auditors actually catch problems.]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">When practitioners say &#8220;SIL verification,&#8221; they almost always mean one specific process: design-phase verification of a Safety Instrumented Function (SIF) against the three independent requirements in IEC 61511 Clause 11. Three gates, all independent, all of which must pass.</p>



<p class="wp-block-paragraph">The three gates are:</p>



<ol class="wp-block-list">
<li><strong>PFDavg / PFH</strong> — the quantitative gate. The SIF&#8217;s failure probability must meet its allocated SIL band.</li>



<li><strong>Systematic capability</strong> — every device in the SIF must be fit for the required SIL, by certification or by prior use.</li>



<li><strong>Architectural constraints</strong> — the SIF&#8217;s hardware fault tolerance must be sufficient for its target SIL.</li>
</ol>



<p class="wp-block-paragraph">A SIF that nails its PFDavg but fails on systematic capability or architecture is not verified. The gate that gets the most attention, PFDavg, is rarely the one that fails an audit.</p>



<p class="wp-block-paragraph">A note on terminology before going further. &#8220;Verification&#8221; in IEC 61511 is broader than what this article covers. It spans the whole life-cycle: H&amp;RA, SRS, design, FAT, operations. &#8220;SIL verification&#8221; is the industry shorthand for the design-phase SIF verification specifically, and that is what this article covers.</p>



<p class="wp-block-paragraph">The three worked scenarios at the end show the gates working together: one clean pass and two failure cases that mirror what auditors actually find.</p>



<h2 class="wp-block-heading">Gate 1: PFDavg / PFH</h2>



<p class="wp-block-paragraph">This is the quantitative gate, defined in IEC 61511 Clause 11.9. The SIF&#8217;s calculated probability of failing to act on demand must meet or exceed its allocated SIL band.</p>



<p class="wp-block-paragraph">Demand mode determines which metric applies. Low demand, where the SIF is called on less than once per year, covers most process industry shutdown SIFs and uses Probability of Failure on Demand average (PFDavg). High demand and continuous mode, more frequent than once per year, cover some compressor protection, fired equipment trips, and machinery safety, and use Probability of Failure per Hour (PFH). High demand and continuous are treated together for SIL verification purposes.</p>



<p class="wp-block-paragraph">This article is not a PFDavg tutorial. For depth on inputs and methods, see the dedicated PFDavg article in Further Reading.</p>



<h3 class="wp-block-heading">Why this is the gate everyone fixates on</h3>



<p class="wp-block-paragraph">It produces a number, and numbers feel definitive. Tools automate it. The other two gates require judgment, evidence, and documentation. The PFDavg report is the tangible deliverable a manager can hold up and point to.</p>



<p class="wp-block-paragraph">The trap is that it&#8217;s also the gate easiest to engineer to pass on paper while the SIF still fails on Gates 2 or 3.</p>



<h3 class="wp-block-heading">Where this gate fails</h3>



<p class="wp-block-paragraph">The PFDavg calculation is only as honest as its inputs and architecture assumptions. The same calculation can produce a false pass or a false fail depending on which way the assumptions lean.</p>



<ul class="wp-block-list">
<li><strong>False pass:</strong> optimistic TI, overstated Cpt, generic failure rates that don&#8217;t match the real device. The number passes, but real-world risk reduction is lower than the report claims.</li>



<li><strong>False fail:</strong> overly conservative inputs reject a SIF that would actually meet its target. The design ends up over-engineered relative to the real risk.</li>



<li><strong>Wrong architecture:</strong> sometimes the architecture is just wrong for the target SIL. No amount of input tweaking saves a wrong-fit architecture.</li>
</ul>



<h2 class="wp-block-heading">Gate 2: Systematic Capability</h2>



<p class="wp-block-paragraph">This gate is about whether the components of the SIF have an applicable level of quality and design rigor for the required SIL. It comes from IEC 61511 Clause 11.5, with the prior use path specifically governed by Clause 11.5.3, and the systematic capability concept itself defined in IEC 61508-2. Systematic capability is a property of the device, not the loop. It addresses systematic faults (design errors, software bugs, manufacturing defects) that redundancy can&#8217;t solve.</p>



<p class="wp-block-paragraph">The systematic capability rating of every device must equal or exceed the SIF&#8217;s SIL.</p>



<p class="wp-block-paragraph">There are two paths to demonstrate it.</p>



<h3 class="wp-block-heading">IEC 61508 certification (manufacturer-side)</h3>



<p class="wp-block-paragraph">The manufacturer has had the device assessed against IEC 61508 by a <a href="https://silsafe.net/who-certifies-functional-safety-equipment/">certification body</a>. The outcome is a SIL Certificate stating the systematic capability rating, typically expressed as SC 2, SC 3, etc.</p>



<p class="wp-block-paragraph">Inside IEC 61508, certification can be achieved through different S routes. Route 1S (design-process rigor) is the most common. Route 2S (proven in use) is less common. Route 3S applies to software.</p>



<p class="wp-block-paragraph">For the facility verifier, what matters is the systematic capability rating on the certificate. The route the manufacturer used to achieve it is documented in the SIL Certificate. Software systematic capability is handled by Route 3S, applied to embedded firmware and application software during certification of devices like logic solvers. For a facility verifier using a certified logic solver, this is captured by the SC rating on the certificate. No separate software analysis required at the facility level.</p>



<h3 class="wp-block-heading">IEC 61511 prior use (facility-side)</h3>



<p class="wp-block-paragraph">This is IEC 61511&#8217;s alternative path when no IEC 61508 certification exists for the device, governed by Clause 11.5.3.</p>



<p class="wp-block-paragraph">The owner-operator demonstrates suitability through documented field history under similar operating conditions. No certificate of conformance is involved. Prior use is a facility-side justification, not a third-party attestation. The deliverable is a documented prior use file evaluated by the facility&#8217;s functional safety engineer and audited by an FSA team.</p>



<p class="wp-block-paragraph">It requires evidence of:</p>



<ul class="wp-block-list">
<li>Manufacturer quality management</li>



<li>Device identification and version control</li>



<li>Performance in similar operating environments</li>



<li>Sufficient volume of operating experience</li>
</ul>



<p class="wp-block-paragraph">Generally a more difficult and document-heavy path than using a certified component.</p>



<h3 class="wp-block-heading">Terminology traps to watch for</h3>



<p class="wp-block-paragraph"><strong>Prior use vs. proven in use.</strong> Prior use is the IEC 61511 facility-side path. Proven in use is a specific IEC 61508 route (Route 2S) used by manufacturers seeking certification without a full FMEDA-driven path. Even Goble&#8217;s books and many practitioners use &#8220;proven in use&#8221; loosely to describe both. Be precise in your own documentation.</p>



<p class="wp-block-paragraph"><strong>The H/S route split.</strong> The H routes (1H, 2H) belong to architectural constraints (Gate 3). The S routes (1S, 2S, 3S) belong to systematic capability (Gate 2). The H/S split distinguishes what kind of capability is being demonstrated, not which subsystem the route applies to. Practitioners regularly try to apply S routes to Gate 3 or H routes to Gate 2. Keep them separate.</p>



<h3 class="wp-block-heading">Where this gate fails</h3>



<ul class="wp-block-list">
<li>Legacy field devices with no certificate and no defensible prior use file. &#8220;We&#8217;ve used it for years&#8221; claimed without documentation, version control, or operating-condition records is the typical pattern.</li>



<li>Mismatched systematic capability rating, like using an SC 2 device in a SIL 3 SIF.</li>
</ul>



<h2 class="wp-block-heading">Gate 3: Architectural Constraints (Hardware Fault Tolerance)</h2>



<p class="wp-block-paragraph">This gate is about the inherent redundancy of the SIF: does it have enough fault tolerance to survive a single dangerous failure at its required SIL. It comes from IEC 61511 Clause 11.4, with route definitions inherited from IEC 61508-2 Clause 7.4.4.</p>



<p class="wp-block-paragraph">Hardware fault tolerance (HFT) is the number of dangerous failures a subsystem can tolerate before losing its safety function. A 1oo1 subsystem has no hardware fault tolerance (HFT = 0). A 1oo2 subsystem has HFT = 1.</p>



<p class="wp-block-paragraph">Two H routes are available, applied per element. Different elements in the same SIF can use different routes.</p>



<h3 class="wp-block-heading">Route 1H</h3>



<p class="wp-block-paragraph">Route 1H is based on Safe Failure Fraction (SFF) and Type A vs. Type B classification, using IEC 61508-2 Tables 2 and 3. It requires FMEDA-grade failure data to compute SFF.</p>



<p class="wp-block-paragraph">Type A devices have simple, well-understood failure modes (most mechanical devices). Type B devices are complex with embedded software or microprocessors. The Route 1H tables apply different SFF thresholds to each. Type A is treated more leniently than Type B at the same SIL.</p>



<p class="wp-block-paragraph">This is the most common route for modern certified components, particularly logic solvers, smart instruments, and modern positioners with documented FMEDAs.</p>



<p class="wp-block-paragraph">A note on diagnostics. SFF improves when diagnostics catch dangerous failures, but high SFF doesn&#8217;t strictly <em>require</em> diagnostics. A device with intrinsically safe failure modes (for example, a spring-return solenoid where loss of power drives the safe state) can hit high SFF with no diagnostics at all. In practice, though, most devices that achieve high SFF on Route 1H do so because of diagnostic coverage.</p>



<p class="wp-block-paragraph"><strong>Route 1H — Type A devices (IEC 61508-2 Table 2)</strong></p>



<figure class="wp-block-table"><table><thead><tr><th>SFF</th><th>HFT = 0</th><th>HFT = 1</th><th>HFT = 2</th></tr></thead><tbody><tr><td>&lt; 60%</td><td>SIL 1</td><td>SIL 2</td><td>SIL 3</td></tr><tr><td>60% to &lt; 90%</td><td>SIL 2</td><td>SIL 3</td><td>SIL 4</td></tr><tr><td>90% to &lt; 99%</td><td>SIL 3</td><td>SIL 4</td><td>SIL 4</td></tr><tr><td>≥ 99%</td><td>SIL 3</td><td>SIL 4</td><td>SIL 4</td></tr></tbody></table></figure>



<p class="wp-block-paragraph"><strong>Route 1H — Type B devices (IEC 61508-2 Table 3)</strong></p>



<figure class="wp-block-table"><table><thead><tr><th>SFF</th><th>HFT = 0</th><th>HFT = 1</th><th>HFT = 2</th></tr></thead><tbody><tr><td>&lt; 60%</td><td>Not allowed</td><td>SIL 1</td><td>SIL 2</td></tr><tr><td>60% to &lt; 90%</td><td>SIL 1</td><td>SIL 2</td><td>SIL 3</td></tr><tr><td>90% to &lt; 99%</td><td>SIL 2</td><td>SIL 3</td><td>SIL 4</td></tr><tr><td>≥ 99%</td><td>SIL 3</td><td>SIL 4</td><td>SIL 4</td></tr></tbody></table></figure>



<h3 class="wp-block-heading">Route 2H</h3>



<p class="wp-block-paragraph">Route 2H is based on hardware structural resilience and field reliability data. It does not require SFF and uses simpler tables driven by SIL alone.</p>



<p class="wp-block-paragraph">This is effectively the route IEC 61511 uses on its own. IEC 61511&#8217;s architectural constraint table is derived from IEC 61508 Route 2H, and Goble notes the two are essentially identical.</p>



<p class="wp-block-paragraph">Route 2H is most common for mechanical devices with no or minimal diagnostics (rack-and-pinion actuators, manual valves), legacy equipment that predates IEC 61508, and any device where FMEDA data is not available.</p>



<p class="wp-block-paragraph">Prior use data can contribute to other parts of the verification, most directly to Gate 2 systematic capability. The same field history that supports a Route 2H argument for hardware integrity may also support a prior use justification under Clause 11.5.3.</p>



<p class="wp-block-paragraph"><strong>Route 2H — minimum HFT by SIL</strong></p>



<figure class="wp-block-table"><table><thead><tr><th>SIL</th><th>Minimum HFT</th></tr></thead><tbody><tr><td>1</td><td>0</td></tr><tr><td>2</td><td>1 for high-demand or continuous mode, 0 for low-demand mode</td></tr><tr><td>3</td><td>2</td></tr><tr><td>4</td><td>Special requirements per IEC 61508</td></tr></tbody></table></figure>



<h3 class="wp-block-heading">Choosing an H route</h3>



<p class="wp-block-paragraph">For new SIFs designed with modern equipment, the route appears on the SIL Certificate for certified components, typically labeled &#8220;Route 2H Device&#8221; or similar. This is the most common situation a facility verifier will encounter.</p>



<p class="wp-block-paragraph">The decision is per-element and driven by available evidence:</p>



<ul class="wp-block-list">
<li>Devices with FMEDA data and meaningful diagnostics generally go Route 1H.</li>



<li>Devices without FMEDA data, or mechanical devices where diagnostics can&#8217;t catch the dominant failure modes, go Route 2H.</li>
</ul>



<p class="wp-block-paragraph">Both routes are legitimate. Route 2H is not a fallback or a downgrade. It is the appropriate route for hardware where the SFF-based approach doesn&#8217;t fit, and either route is acceptable evidence for SIL verification at the target SIL.</p>



<h3 class="wp-block-heading">Where this gate fails</h3>



<ul class="wp-block-list">
<li>Claiming Route 1H without the FMEDA data to back it.</li>



<li>Selecting a 1oo1 architecture for a device whose SFF and Type combination can&#8217;t reach the target SIL because of required HFT.</li>



<li>Using a Route 2H legacy device in a SIL 3 application where Route 2H can&#8217;t get there regardless of redundancy.</li>



<li>Mixing route claims across elements without verifying each element&#8217;s evidence stands on its own.</li>
</ul>



<h2 class="wp-block-heading">Worked SIL Verification Examples</h2>



<p class="wp-block-paragraph">Three scenarios to make the three-gate framing concrete. Each zooms in on a single component (or two in Scenario 2) within an otherwise-passing SIF. Each scenario opens with a scope statement, then walks through all three gates in whichever order makes the component&#8217;s story easiest to follow. These are SIL verification scenario walkthroughs, not PFDavg calculation tutorials.</p>



<h3 class="wp-block-heading">Scenario 1: A straightforward verification</h3>



<p class="wp-block-paragraph">For this scenario we focus on a smart pressure instrument on a SIL 2 SIF, used in a 1oo1 architecture. Assume the rest of the SIF verifies cleanly.</p>



<ul class="wp-block-list">
<li><strong>Gate 2:</strong> The device is IEC 61508 certified, with an SC 2 rating on the SIL Certificate. SC 2 matches the SIF&#8217;s required SIL — <strong>passes</strong>.</li>



<li><strong>Gate 1:</strong> The certificate provides manufacturer failure rate data. This instrument&#8217;s contribution to the SIF-level PFDavg, combined with the rest of the SIF&#8217;s components, clears the SIL 2 band — <strong>passes</strong>.</li>



<li><strong>Gate 3:</strong> The SIL Certificate confirms Route 1H, Type B, and a documented SFF of 93% (in the 90% to &lt;99% band). The Route 1H Type B table allows SIL 2 at HFT 0, so the 1oo1 architecture clears — <strong>passes</strong>.</li>
</ul>



<p class="wp-block-paragraph">The rest of the SIF (final element and logic solver) verifies via the same logic. This is what a modern and clean SIL verification looks like: a certified component, a matching SC rating, an architecture that fits the route&#8217;s table, and a PFDavg that lands in band.</p>



<h3 class="wp-block-heading">Scenario 2: A trickier case</h3>



<p class="wp-block-paragraph">For this scenario we focus on two components (a final element and an instrument) on a SIL 2 SIF in low-demand mode. Assume the rest of the SIF verifies cleanly, including the SIF-level PFDavg contribution from other components.</p>



<p class="wp-block-paragraph"><strong>Final element walkthrough, non-certified valve in a 1oo2 architecture:</strong></p>



<ul class="wp-block-list">
<li><strong>Gate 2:</strong> Non-certified valve with no IEC 61508 certificate. The facility attempted prior use, but the operating-history records don&#8217;t meet Clause 11.5.3 documentation requirements — <strong>fails</strong>.</li>



<li><strong>Gate 1:</strong> Failure rate data sourced from OREDA for this device class, applied to the SIF-level PFDavg — <strong>passes</strong>.</li>



<li><strong>Gate 3:</strong> Route 2H requires minimum HFT 0 for SIL 2 in low-demand mode. The 1oo2 architecture provides HFT 1, which exceeds the minimum — <strong>passes</strong>.</li>
</ul>



<p class="wp-block-paragraph"><strong>Instrument walkthrough, certified instrument in a 1oo1 architecture:</strong></p>



<ul class="wp-block-list">
<li><strong>Gate 2:</strong> The device is IEC 61508 certified with an SC 2 rating — <strong>passes</strong>.</li>



<li><strong>Gate 1:</strong> Failure rate from the SIL Certificate plugs into the SIF-level PFDavg — <strong>passes</strong>.</li>



<li><strong>Gate 3:</strong> Type B smart instrument with documented SFF in the 60% to &lt;90% band, in a 1oo1 architecture, is capped at SIL 1 by the Route 1H Type B table — <strong>fails</strong>.</li>
</ul>



<p class="wp-block-paragraph">Two components, two unrelated gate failures, both blocking SIL verification of the SIF as a whole. The final element passes its architecture check but fails systematic capability. The instrument passes systematic capability but fails its architecture check. This is why the gates are treated as independent: a SIF doesn&#8217;t get partial credit for clearing two of three on any given component, and clearing all three on most components doesn&#8217;t help if one element fails one gate.</p>



<h3 class="wp-block-heading">Scenario 3: The hardest one to catch</h3>



<p class="wp-block-paragraph">For this scenario we focus on a non-certified globe valve, used in a 1oo1 architecture. Assume the rest of the SIF verifies cleanly.</p>



<p class="wp-block-paragraph">The engineer specified this valve from a familiar vendor because it was the right size, available, and had been used in non-safety service at the site for years. To populate the verification report, the engineer pulled an SFF figure from the SIL-rated version of the same product family, same vendor, same valve series, but a different model.</p>



<ul class="wp-block-list">
<li><strong>Gate 2:</strong> No IEC 61508 certificate for the actual valve installed. The non-safety service history doesn&#8217;t qualify for prior use under Clause 11.5.3 — <strong>fails</strong>.</li>



<li><strong>Gate 1:</strong> PFDavg calculation passes using the borrowed SFF and a generic failure rate from a database — <strong>passes</strong>.</li>



<li><strong>Gate 3:</strong> Both Route 1H and Route 2H were considered. Route 1H requires FMEDA-grade failure data for the actual device installed. The borrowed SFF from a sibling SIL-rated model doesn&#8217;t qualify, and no FMEDA exists for this valve. Route 2H doesn&#8217;t require SFF, but does require documented hardware reliability evidence, and the non-safety service history doesn&#8217;t meet that bar either — <strong>fails</strong>.</li>
</ul>



<p class="wp-block-paragraph">The rest of the SIF verifies cleanly. One bad component sinks the SIL verification.</p>



<p class="wp-block-paragraph">The lesson here is that the gates are independent in principle but often connected in practice. A device with no certificate and no defensible field history typically fails on Gate 2 <em>and</em> leaves Gate 3 with no defensible route. And route claims on Gate 3 must be defended with evidence that&#8217;s specific to the device installed, not borrowed from a similar product.</p>



<h2 class="wp-block-heading">Life-cycle Placement</h2>



<p class="wp-block-paragraph">SIL verification sits in the design phase of the IEC 61511 safety life-cycle.</p>



<p class="wp-block-paragraph"><strong>What comes before:</strong> H&amp;RA and LOPA produce the SIL allocation for each SIF. The SRS captures the safety requirements. Conceptual SIS design proposes a candidate architecture and equipment selection. SIL verification then takes those inputs and tests them against the three gates.</p>



<p class="wp-block-paragraph"><strong>What comes after:</strong> continued detailed design, FAT, installation and commissioning. The verification report is a key input to the Functional Safety Assessment and to operational handover.</p>



<h2 class="wp-block-heading">Common Mistakes</h2>



<p class="wp-block-paragraph">The mistakes that surface during SIL verification audits are rarely about the math. They are about evidence, judgment, and which gate the engineer treated as optional.</p>



<ul class="wp-block-list">
<li><strong>Treating PFDavg as the only gate.</strong> The calculation passes, often using manufacturer numbers without scrutiny, and the audit fails on Gate 2 or Gate 3. This is the most common pattern, and it&#8217;s the spine of most of the failures below.</li>



<li><strong>Claiming prior use without the documentation to defend it.</strong> &#8220;We&#8217;ve run this valve for 15 years&#8221; is not a prior use file. Clause 11.5.3 wants quality management, version control, and operating-condition records, not informal recollection.</li>



<li><strong>Confusing prior use with proven in use,</strong> then defending neither correctly when challenged.</li>



<li><strong>Not realizing a route was claimed at all.</strong> Accepting whichever H route the calculation tool defaulted to without checking whether the device&#8217;s evidence supports it.</li>
</ul>



<p class="wp-block-paragraph">Most of these share a root cause: engineers default to whichever gate they&#8217;re most comfortable with and underweight the other two.</p>



<h2 class="wp-block-heading">Frequently Asked Questions</h2>



<h4 class="wp-block-heading">I thought PFDavg was all we had to do. What&#8217;s the deal?</h4>



<p class="wp-block-paragraph">PFDavg is one of three independent gates, not the whole verification. IEC 61511 Clause 11 also requires systematic capability (the device is fit for the SIL by certification or prior use) and architectural constraints (the hardware fault tolerance is sufficient for the SIL). A SIF can have a beautiful PFDavg report and still fail SIL verification. PFDavg gets the attention because it produces a number and tools automate it, but the other two gates are where audits most often turn up problems.</p>



<h4 class="wp-block-heading">I heard we have to use SIL-certified devices. Is that correct?</h4>



<p class="wp-block-paragraph">Certified devices make your life easier and are recommended, but not strictly required. IEC 61511 also allows prior use as an alternative path under Clause 11.5.3. Prior use is harder and document-heavy. That is the trade-off for skipping certification. Most facilities find the cost of building defensible prior use files component by component exceeds the price premium on certified equipment. SIL Safe defaults to certified components on every project for exactly this reason.</p>



<h4 class="wp-block-heading">I&#8217;ve been using this family of PLCs for years and they&#8217;re great. Never had a problem. How can I use this in a SIF?</h4>



<p class="wp-block-paragraph">Possible in theory, expensive in practice, scrutinized at all three gates of SIL verification. On Gate 2, prior use under Clause 11.5.3 needs more than a track record. It needs documented manufacturer quality management, version control, and operating-environment records. On Gate 3, general-purpose PLCs typically lack the diagnostic coverage and architectural features that certified safety PLCs are designed around, so SFF and HFT arguments get hard to defend.</p>



<p class="wp-block-paragraph">On Gate 1, manufacturer failure rate data is rarely available for non-safety PLCs, and generic database values may not match the actual hardware. The same field history that might support prior use only contributes to the failure rate argument if the facility has safety-grade failure recording, which most general-purpose PLC installations don&#8217;t. Add it up and a certified safety PLC almost always wins on total cost.</p>



<h4 class="wp-block-heading">We just did all this work to use a valve under prior use, and I thought that was it. Now I need to calculate PFDavg too. Where does that data come from?</h4>



<p class="wp-block-paragraph">Prior use clears Gate 2 only. Gate 1 still needs failure rate data to support the PFDavg calculation. For a non-certified valve, that typically means industry databases (OREDA, Exida&#8217;s data handbook, or similar) applied to the device class. The data is generally more conservative than what an FMEDA would produce on a certified device, which is one of the practical reasons certified components ease SIL verification across all three gates simultaneously.</p>



<h4 class="wp-block-heading">Our FuSa engineer says we need 2oo3 voting on this SIF instead of a single instrument, which is going to triple our hardware cost. The PFDavg calculation passes fine on a 1oo1, so why do we need 2oo3?</h4>



<p class="wp-block-paragraph">PFDavg and HFT are independent gates. The PFDavg calculation can pass on a 1oo1 architecture, but Gate 3 is a separate check that the architecture has enough hardware fault tolerance to be trusted at the target SIL. If the instrument&#8217;s SFF and Type combination requires HFT ≥ 1 to reach the target SIL per the Route 1H tables, a 1oo1 architecture (HFT 0) is insufficient regardless of what the PFDavg math says.</p>



<p class="wp-block-paragraph">Two paths through this:</p>



<ul class="wp-block-list">
<li>Pick an instrument with higher SFF (typically smart, fail-safe-designed, or with stronger diagnostics) so 1oo1 clears Gate 3.</li>



<li>Accept the redundancy.</li>
</ul>



<p class="wp-block-paragraph">The expensive smart instrument frequently beats three cheaper instruments plus the wiring, I/O, and proof-testing overhead once total cost is accounted for.</p>



<h4 class="wp-block-heading">How do we at SIL Safe advise our clients on this topic?</h4>



<p class="wp-block-paragraph">Use IEC 61508-certified components wherever possible. It is the simplest path through all three gates.</p>



<p class="wp-block-paragraph">Gate 1 is easier because the manufacturer provides failure rate data, and that data is typically less conservative than generic database values for the same equipment type. The FMEDA process produces a component-specific number rather than a worst-case estimate across a heterogeneous population.</p>



<p class="wp-block-paragraph">Gate 2 collapses to a check that the SC rating matches the SIL.</p>



<p class="wp-block-paragraph">Gate 3 collapses to a check of the architecture against what the certificate documents (route, SFF where applicable, and Type). SFF on certified components tends to be relatively high because the FMEDA process and the certification market push toward devices with strong diagnostics, which makes the table lookup more likely to clear at the target SIL.</p>



<h4 class="wp-block-heading">Does the standard clearly state these three gates in those exact terms?</h4>



<p class="wp-block-paragraph">No. The three-gate framing for SIL verification is shorthand extracted from various clauses (11.4, 11.5, 11.9). The standard treats the requirements as separate within the design phase. The framing is a teaching device, not a quoted structure.</p>



<h2 class="wp-block-heading">Further Reading</h2>





<p class="wp-block-paragraph"><strong>From SIL Safe</strong></p>



<ul class="wp-block-list">
<li><a href="https://silsafe.net/layer-of-protection-analysis-lopa/">Layer of Protection Analysis (LOPA): The Engineer&#8217;s Guide to SIL Selection</a></li>



<li><a href="https://silsafe.net/hazard-and-risk-analysis-methods/">Hazard and Risk Analysis Methods: How HAZOP, What-If, LOPA, Risk Graph, FTA, ETA, and Bowtie Fit Together</a></li>



<li><a href="https://silsafe.net/pfdavg-explained/">PFDavg Explained: 6 Essentials for Getting Started with SIL Calculations</a></li>



<li><a href="https://silsafe.net/functional-safety-assessment-vs-audit/">Functional Safety Assessment (FSA) vs. Audit: What&#8217;s the Difference?</a></li>
</ul>



<p class="wp-block-paragraph"><strong>External resources</strong></p>



<ul class="wp-block-list">
<li><a href="https://webstore.iec.ch/en/publication/24241" target="_blank" rel="noopener">IEC 61511-1:2016+A1:2017 — official IEC publication page</a></li>



<li><a href="https://www.hse.gov.uk/eci/functional.htm" target="_blank" rel="noopener">HSE — Functional safety (BS EN 61511 reference page)</a></li>



<li><a href="https://www.isa.org/standards-and-publications/isa-standards/isa-84-standards" target="_blank" rel="noopener">ISA-84 Series of Standards</a></li>



<li><a href="https://61508.org/wp-content/uploads/2023/11/T6A024_Technical_Guide_-_Proven_in_Use_V8_-_e012023.pdf" target="_blank" rel="noopener">The 61508 Association — Proven in Use technical guide</a></li>
</ul>



<h2 class="wp-block-heading">Closing Synthesis</h2>



<p class="wp-block-paragraph">SIL verification is three independent gates, all of which must pass. Most failures come from underweighting two of the three, usually because the third produces a clean number on a report. Treat them as separate checks, defend each one with its own evidence, and the verification holds up under audit.</p>



<p class="wp-block-paragraph">Functional safety is complex, and the stakes are high. If you have questions about your SIS design, SIL verification, or where to start with IEC 61511, the team at SIL Safe is here to help. Reach out to us today.</p>



<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "I thought PFDavg was all we had to do. What's the deal?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "PFDavg is one of three independent gates, not the whole verification. IEC 61511 Clause 11 also requires systematic capability (the device is fit for the SIL by certification or prior use) and architectural constraints (the hardware fault tolerance is sufficient for the SIL). A SIF can have a beautiful PFDavg report and still fail SIL verification. PFDavg gets the attention because it produces a number and tools automate it, but the other two gates are where audits most often turn up problems."
      }
    },
    {
      "@type": "Question",
      "name": "I heard we have to use SIL-certified devices. Is that correct?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Certified devices make your life easier and are recommended, but not strictly required. IEC 61511 also allows prior use as an alternative path under Clause 11.5.3. Prior use is harder and document-heavy. That is the trade-off for skipping certification. Most facilities find the cost of building defensible prior use files component by component exceeds the price premium on certified equipment. SIL Safe defaults to certified components on every project for exactly this reason."
      }
    },
    {
      "@type": "Question",
      "name": "I've been using this family of PLCs for years and they're great. Never had a problem. How can I use this in a SIF?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Possible in theory, expensive in practice, scrutinized at all three gates of SIL verification. On Gate 2, prior use under Clause 11.5.3 needs more than a track record. It needs documented manufacturer quality management, version control, and operating-environment records. On Gate 3, general-purpose PLCs typically lack the diagnostic coverage and architectural features that certified safety PLCs are designed around, so SFF and HFT arguments get hard to defend."
      }
    },
    {
      "@type": "Question",
      "name": "We just did all this work to use a valve under prior use, and I thought that was it. Now I need to calculate PFDavg too. Where does that data come from?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Prior use clears Gate 2 only. Gate 1 still needs failure rate data to support the PFDavg calculation. For a non-certified valve, that typically means industry databases (OREDA, Exida's data handbook, or similar) applied to the device class. The data is generally more conservative than what an FMEDA would produce on a certified device, which is one of the practical reasons certified components ease SIL verification across all three gates simultaneously."
      }
    },
    {
      "@type": "Question",
      "name": "Our FuSa engineer says we need 2oo3 voting on this SIF instead of a single instrument, which is going to triple our hardware cost. The PFDavg calculation passes fine on a 1oo1, so why do we need 2oo3?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "PFDavg and HFT are independent gates. The PFDavg calculation can pass on a 1oo1 architecture, but Gate 3 is a separate check that the architecture has enough hardware fault tolerance to be trusted at the target SIL. If the instrument's SFF and Type combination requires HFT ≥ 1 to reach the target SIL per the Route 1H tables, a 1oo1 architecture (HFT 0) is insufficient regardless of what the PFDavg math says."
      }
    },
    {
      "@type": "Question",
      "name": "How do we at SIL Safe advise our clients on this topic?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Use IEC 61508-certified components wherever possible. It is the simplest path through all three gates."
      }
    },
    {
      "@type": "Question",
      "name": "Does the standard clearly state these three gates in those exact terms?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No. The three-gate framing for SIL verification is shorthand extracted from various clauses (11.4, 11.5, 11.9). The standard treats the requirements as separate within the design phase. The framing is a teaching device, not a quoted structure."
      }
    }
  ]
}
</script>
]]></content:encoded>
					
					<wfw:commentRss>https://silsafe.net/sil-verification-three-gates/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hazard and Risk Analysis Methods: How HAZOP, What-If, LOPA, Risk Graph, FTA, ETA, and Bowtie Fit Together</title>
		<link>https://silsafe.net/hazard-and-risk-analysis-methods/</link>
					<comments>https://silsafe.net/hazard-and-risk-analysis-methods/#respond</comments>
		
		<dc:creator><![CDATA[mamerten]]></dc:creator>
		<pubDate>Sun, 03 May 2026 23:36:16 +0000</pubDate>
				<category><![CDATA[Advanced]]></category>
		<guid isPermaLink="false">https://silsafe.net/?p=6468</guid>

					<description><![CDATA[A practitioner's orientation to the methods that make up an IEC 61511 hazard and risk assessment — HAZOP, What-If, LOPA, risk graph, FTA, ETA, and bowtie — and how they fit together.]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Most engineers learn hazard and risk analysis methods one at a time, in the order their careers happened to expose them. HAZOP in a class. LOPA when they joined a site that used it. Bowtie in a corporate training deck. Years pass and they end up fluent in a handful of methods without ever assembling a clean mental model of how the methods fit together.</p>



<p class="wp-block-paragraph">That gap creates real problems. Teams default to whatever their site does and can&#8217;t articulate why, can&#8217;t recognize when the wrong tool is being used, and outgrow their methodology without realizing it. IEC 61511 requires a hazard and risk assessment (H&#038;RA) but is method-agnostic. The choice of hazard and risk analysis methods is on you, and the right choice depends on your facility, your scenarios, and the depth of analysis your risk picture demands.</p>



<h2 class="wp-block-heading">The Two Halves of Hazard and Risk Assessment</h2>



<p class="wp-block-paragraph">Clause 8 of IEC 61511 requires both halves of an H&#038;RA: hazard identification and risk assessment.</p>



<p class="wp-block-paragraph"><strong>Hazard identification</strong> is discovery work: <em>what can go wrong here?</em> The output is a list of credible scenarios with causes, consequences, and existing safeguards.</p>



<p class="wp-block-paragraph"><strong>Risk assessment</strong> is evaluation work: <em>for each identified hazard, how bad is it, how likely is it, and how much risk reduction is needed to make it tolerable?</em> The output is a defensible determination of required risk reduction, often expressed as a Safety Integrity Level (SIL) when the reduction is allocated to a Safety Instrumented Function (SIF).</p>



<p class="wp-block-paragraph">Most method confusion comes from not recognizing which half a given tool serves. HAZOP is hazard identification. LOPA is mostly risk assessment. They do different cognitive work, and they aren&#8217;t interchangeable.</p>



<p class="wp-block-paragraph">Another source of confusion: some methods are treated differently by different practitioners. The same method can be identification-only at one site and identification-plus-assessment at another. This article names the common patterns, but your facility may run them differently.</p>



<h2 class="wp-block-heading">Hazard Identification Methods</h2>



<p class="wp-block-paragraph">The hazard and risk analysis methods in this section are collectively known as Process Hazard Analysis (PHA) methods in much of industry practice. PHA usually refers to the identification activity specifically, while H&#038;RA is the IEC 61511 phrasing for the full activity covering both halves.</p>



<h3 class="wp-block-heading">HAZOP</h3>



<p class="wp-block-paragraph">A Hazard and Operability Study (HAZOP) is a hazard identification method by design, but in practice it often extends into risk assessment. Two patterns are worth recognizing:</p>



<ul class="wp-block-list">

<li><strong>HAZOP-as-identification:</strong> the team identifies hazards, applies a risk ranking for prioritization, and hands the scenarios off to LOPA or risk graph for assessment. Cleaner pattern, dominant at larger facilities.</li>


<li><strong>HAZOP-as-everything:</strong> the team identifies hazards and uses a calibrated risk matrix to determine SIL requirements directly, with no separate risk assessment step. Common at smaller facilities and in revalidations.</li>

</ul>



<p class="wp-block-paragraph">The workshop mechanics are the same either way. A multidisciplinary team works node-by-node through the process, applying parameter and guideword combinations (no flow, more pressure, reverse flow) to surface deviations from design intent. HAZOP is time-intensive, depends heavily on facilitator skill, and works best on continuous processes.</p>



<h3 class="wp-block-heading">What-If (Typically Run as What-If/Checklist)</h3>



<p class="wp-block-paragraph">What-If is a hazard identification method. A team works through the process asking open-ended <em>what if</em> questions and brainstorms consequences and safeguards.</p>



<p class="wp-block-paragraph">In practice almost nobody runs pure What-If — the risk of missing something obvious is too high. What sites actually do is What-If/Checklist: the team brainstorms freely, then uses a backing checklist as a safety net to catch what was missed. When practitioners say &#8220;we did a What-If,&#8221; they almost always mean What-If/Checklist.</p>



<p class="wp-block-paragraph">What-If/Checklist is the practical alternative to HAZOP for smaller, simpler, or batch processes. It&#8217;s accepted under major regulatory frameworks (OSHA Process Safety Management in the US, COMAH in the UK, Seveso in the EU) and is the right call for Management of Change (MOC) reviews, Pre-Startup Safety Reviews, and revalidations of well-understood operations.</p>



<h3 class="wp-block-heading">Pure Checklist</h3>



<p class="wp-block-paragraph">Pure checklist is verification, not discovery — the team walks through a pre-built list of standard hazards or design conditions for that process type and confirms each one is addressed. It&#8217;s used for screening reviews, very simple operations, or as an MOC tool for minor changes.</p>



<p class="wp-block-paragraph">Example: a process safety engineer is evaluating a proposed minor MOC. They walk through a standard checklist (does it change relief valve sizing, introduce new hazardous materials, affect classified area boundaries, touch a SIF), and the checklist confirms whether a fuller PHA review is needed.</p>



<h3 class="wp-block-heading">Related but Out of Scope: FMEA and FMEDA</h3>



<p class="wp-block-paragraph">Failure Modes and Effects Analysis (FMEA) and Failure Modes, Effects and Diagnostic Analysis (FMEDA) don&#8217;t belong in the H&#038;RA toolkit. Equipment-level FMEA and FMEDA belong to device certification under IEC 61508, the manufacturer&#8217;s domain, with outputs consumed by IEC 61511 users during SIS design and SIL verification. Process FMEA exists as a hazard identification method in adjacent industries (pharma, food, automotive) but isn&#8217;t standard in the process industry. Not covered further.</p>



<h2 class="wp-block-heading">Risk Assessment Methods</h2>



<h3 class="wp-block-heading">LOPA</h3>



<p class="wp-block-paragraph">Layer of Protection Analysis (LOPA) is a risk assessment method. It serves the assessment half of the H&#038;RA, but it straddles the Clause 8 / Clause 9 boundary of IEC 61511. The analytical work is risk assessment under Clause 8, while the output feeds SIL allocation under Clause 9. That dual nature is why LOPA gets described both ways depending on context.</p>



<p class="wp-block-paragraph">The mechanics are semi-quantitative and scenario-based. For each scenario, the team multiplies the initiating event frequency by the probability of failure on demand of each Independent Protection Layer (IPL) credited against the scenario, then compares the residual risk to the tolerable risk criterion. Where residual risk exceeds tolerable, the gap defines the required risk reduction factor (RRF) and corresponding SIL.</p>



<p class="wp-block-paragraph">LOPA is the most widely adopted risk assessment method globally, the default tool for most facilities. Its strengths are visible math, defensible documentation, and scalability across hundreds of scenarios. Its limitations are real: order-of-magnitude resolution can hide meaningful differences, and IPL crediting requires real discipline. Sloppy IPL crediting produces inflated risk reduction credit and leaves real gaps.</p>



<h3 class="wp-block-heading">Risk Graph</h3>



<p class="wp-block-paragraph">Risk graph is a risk assessment method. A calibrated decision tree uses four parameters: consequence severity (C), frequency or exposure (F), possibility of avoidance (P), and demand rate (W). The path through the tree lands on a SIL.</p>



<p class="wp-block-paragraph">Risk graph compresses risk assessment and SIL selection into a single traversal: consequence severity, exposure, avoidance, and tolerable risk comparison are all baked into the calibrated tree. It&#8217;s common in European-influenced practice, in oil &#038; gas globally, and in machinery safety; it remains a fully legitimate IEC 61511-3 method.</p>



<p class="wp-block-paragraph">Strengths: speed, no failure rate data required for IPLs, easy to teach. Limitations: calibration is everything, sensitivity is poor, qualitative judgments hide assumptions that LOPA forces explicit.</p>



<h3 class="wp-block-heading">LOPA and Risk Graph Are Alternatives, Not Complements</h3>



<p class="wp-block-paragraph">Both methods occupy the same workflow slot: risk assessment with a SIL output. Running both on the same scenario set creates conflicting answers and an unauditable documentation trail. Sites pick one or the other as their site standard and apply it consistently.</p>



<h2 class="wp-block-heading">The Quantitative Deep-Dive Methods</h2>



<p class="wp-block-paragraph">FTA, ETA, and bowtie are risk assessment tools, not hazard identification tools. Like LOPA and risk graph, they require an upstream identification activity to define what gets analyzed. They cannot tell you what hazards you forgot to consider.</p>



<h3 class="wp-block-heading">Fault Tree Analysis (FTA)</h3>



<p class="wp-block-paragraph">FTA works top-down and deductively. Start with a top event and work backward through the failure combinations that produce it using Boolean logic. Logic gates (AND, OR), basic events with failure rates, and minimal cut sets give a quantified frequency for the top event.</p>



<p class="wp-block-paragraph">Strengths: rigorous quantification, handles complex failure logic, identifies common cause failure (CCF) contributors. Limitation: FTA only analyzes the top event you defined. It cannot surface hazards nobody named.</p>



<h3 class="wp-block-heading">Event Tree Analysis (ETA)</h3>



<p class="wp-block-paragraph">ETA is the structural mirror of FTA: bottom-up and inductive. Start with an initiating event and work forward through outcome paths, assigning branching probabilities at each protection layer or conditional modifier (ignition / no ignition, immediate vs. delayed, occupancy at the time).</p>



<p class="wp-block-paragraph">The output is the full consequence space mapped quantitatively. Limitation: ETA is only as good as the initiating event you picked.</p>



<h3 class="wp-block-heading">Bowtie Analysis: The Integrating Visual</h3>



<p class="wp-block-paragraph">A bowtie puts the hazardous event in the middle, with threats and causes on the left (FTA territory), consequences on the right (ETA territory), and barriers across both sides. It can be qualitative (illustrative) or quantitative (backed by FTA/ETA data).</p>



<p class="wp-block-paragraph">Bowtie&#8217;s strength is communication: management, operations, and maintenance can read a bowtie even if they can&#8217;t read a fault tree. It&#8217;s also powerful for barrier management, making preventive and mitigative barriers visible together. Limitation: a bowtie is only as rigorous as the analysis behind it. A whiteboard sketch is not an H&#038;RA.</p>



<h2 class="wp-block-heading">How a Complete H&#038;RA Comes Together</h2>



<p class="wp-block-paragraph">A complete H&#038;RA combines hazard and risk analysis methods from both halves: one for identification, one for assessment. Several pairings are common in practice.</p>



<h3 class="wp-block-heading">The Common Pairing: HAZOP + LOPA</h3>



<p class="wp-block-paragraph">HAZOP plus LOPA is the dominant H&#038;RA pairing globally. HAZOP identifies, LOPA assesses, with a clean handoff between the two halves. The pairing extends one step beyond H&#038;RA. LOPA&#8217;s output feeds Clause 9 SIL allocation directly.</p>



<h3 class="wp-block-heading">The Alternative Pairing: HAZOP + Risk Graph</h3>



<p class="wp-block-paragraph">Same handoff structure, different risk assessment tool. Common in European-influenced practice. Site-wide methodology choice. Risk graph outputs a SIL directly, also feeding Clause 9 allocation.</p>



<h3 class="wp-block-heading">The Quantitative Pairing: Identification + FTA/ETA + Bowtie</h3>



<p class="wp-block-paragraph">Reserved for high-consequence facilities or specific scenarios within an otherwise LOPA-based program. Identification can be HAZOP or another systematic method, but the upstream identification step cannot be skipped. The Common Mistakes section below walks through what happens when it is.</p>



<h3 class="wp-block-heading">The Small-Facility Pattern: What-If/Checklist (or HAZOP) + Calibrated Risk Matrix</h3>



<p class="wp-block-paragraph">A single workshop does identification, assessment, and SIL determination using a calibrated matrix. The identification method is What-If/Checklist for smaller operations; some sites use HAZOP and run it the same way. The matrix serves double duty: both the tolerable risk reference and the SIL determination output. Common at facilities that don&#8217;t have the scenario count to justify a separate LOPA program. The matrix&#8217;s resolution caps how defensible higher-SIL determinations can be.</p>



<h3 class="wp-block-heading">Why You Can&#8217;t Skip Hazard Identification</h3>



<p class="wp-block-paragraph">FTA and ETA both start from a known event. LOPA and risk graph both evaluate scenarios they&#8217;re given. None of them can tell you what hazards you forgot to analyze. Identification and assessment are different cognitive tasks, and skipping the identification step doesn&#8217;t reduce the rigor of the H&#038;RA. It produces a different activity that happens to share vocabulary with one.</p>



<h2 class="wp-block-heading">Common Mistakes</h2>



<p class="wp-block-paragraph">The mistakes below show up across all the hazard and risk analysis methods covered in this article. They&#8217;re field-grounded patterns, not generic warnings about following the standard.</p>



<p class="wp-block-paragraph"><strong>1. Doing a high-quality assessment on a hazard while forgetting that not all hazards have been identified.</strong></p>



<p class="wp-block-paragraph">A specialty chemical facility decides to do a quantitative analysis on a 50,000-gallon flammable solvent tank. The team builds a rigorous fault tree on loss of containment, an event tree on ignition and consequences, and a bowtie that ties it all together. The analysis is technically excellent. A SIL is assigned to the overfill protection SIF.</p>



<p class="wp-block-paragraph">Six months later, an operator opens a sample valve that sticks open. Several thousand gallons release into a containment area not designed for that volume, and an uncoordinated maintenance activity provides the ignition source. None of it was in the analysis. Nobody ever did systematic hazard identification. The team jumped straight to &#8220;tank fire&#8221; as the assumed hazard and built outward.</p>



<p class="wp-block-paragraph">FTA and ETA are powerful at analyzing hazards you&#8217;ve already named. They cannot tell you what hazards you forgot to name. That&#8217;s HAZOP&#8217;s job.</p>



<p class="wp-block-paragraph"><strong>2. Mixing LOPA and risk graph on the same scenario set.</strong> Two methods occupying the same workflow slot produces conflicting answers and unauditable documentation.</p>



<p class="wp-block-paragraph"><strong>3. Crediting IPLs in LOPA without independence and auditability discipline.</strong> Loose IPL crediting inflates risk reduction credit and leaves real gaps. Independence, auditability, and access integrity have to be earned, not assumed.</p>



<p class="wp-block-paragraph"><strong>4. Drawing a bowtie without the underlying analysis.</strong> A diagram with barriers in marker is a communication tool, not an assessment.</p>



<p class="wp-block-paragraph"><strong>5. Defaulting to whatever the site has always done.</strong> Methodology should match process complexity and scenario severity, not just inherit.</p>



<p class="wp-block-paragraph"><strong>6. Treating FTA and ETA as substitutes for HAZOP.</strong> They analyze hazards deeply. They don&#8217;t discover them.</p>



<h2 class="wp-block-heading">Frequently Asked Questions</h2>



<h4 class="wp-block-heading">I sometimes hear PHA and sometimes H&#038;RA. Are they the same thing?</h4>



<p class="wp-block-paragraph">PHA is the umbrella term most practitioners use, particularly in CCPS-influenced documentation, and usually refers to the hazard identification activity specifically. H&#038;RA is the IEC 61511 phrasing for the full activity covering both identification and assessment. Practitioners sometimes use PHA loosely to mean the whole exercise, which is part of where the confusion comes from.</p>



<h4 class="wp-block-heading">How do I know if my site is using the wrong H&#038;RA method?</h4>



<p class="wp-block-paragraph">This is a hard question and often needs the judgment of experienced professionals to answer well. Some clues:</p>



<ul class="wp-block-list">

<li><strong>Mismatch:</strong> a small facility running a full quantitative program for routine scenarios is using more methodology than the risk profile warrants; a complex high-consequence facility relying on a calibrated risk matrix for SIL determination is using less methodology than the risk profile warrants</li>


<li><strong>Inconsistency:</strong> scenarios assessed by different methods with no documented basis for the choice, or IPLs credited differently across similar scenarios</li>

</ul>



<h4 class="wp-block-heading">Can FTA and ETA satisfy IEC 61511&#8217;s H&#038;RA requirement on their own?</h4>



<p class="wp-block-paragraph">No. FTA and ETA take hazardous events as a design input. The methods cannot generate the events themselves. Something upstream has to identify them, which is the work of a hazard identification method like HAZOP. Without that step, the quantitative analysis is rigorous about whatever events the team happened to think of, and silent about everything else.</p>



<h4 class="wp-block-heading">Is risk graph an acceptable method, or do I have to use LOPA?</h4>



<p class="wp-block-paragraph">Risk graph is a fully legitimate IEC 61511-3 method. The standard does not mandate LOPA. The right choice depends on facility context. Risk graph is common in European-influenced practice, oil &#038; gas globally, and machinery safety; LOPA dominates in many regulatory contexts, particularly under PSM/RMP. What&#8217;s not acceptable is mixing the two on the same scenario set.</p>



<h4 class="wp-block-heading">My boss says HAZOP takes too many people for too many days and costs too much. Why can&#8217;t we just do a What-If/Checklist?</h4>



<p class="wp-block-paragraph">Sometimes you can. What-If/Checklist is a legitimate hazard identification method, accepted under OSHA PSM, COMAH, Seveso, and similar frameworks. It&#8217;s the right tool for smaller, simpler, or batch processes, for MOC reviews, and for revalidations of well-understood operations. The choice should be based on process complexity and consequence severity, not on cost alone. Cost is a real factor, and not every scope warrants a full HAZOP. As process complexity, scenario count, or consequence severity increase, the cost-benefit shifts back toward HAZOP. Using What-If/Checklist on a scope that genuinely needs HAZOP is how facilities miss hazards that come back to bite them later.</p>



<h4 class="wp-block-heading">Where does LOPA actually sit in the IEC 61511 life-cycle, Clause 8 or Clause 9?</h4>



<p class="wp-block-paragraph">Both. The analytical work is risk assessment under Clause 8. The output (required risk reduction expressed as a SIL) is consumed by Clause 9 for protection layer allocation. LOPA spans the boundary, which is why it&#8217;s described both as an H&#038;RA method and a SIL determination method.</p>



<h4 class="wp-block-heading">Do I need a bowtie for every hazardous event?</h4>



<p class="wp-block-paragraph">No. Bowtie is most valuable for high-consequence scenarios where barrier management and stakeholder communication justify the effort. For routine scenarios handled in a HAZOP and LOPA workflow, a bowtie adds little beyond what the LOPA worksheet documents.</p>



<h2 class="wp-block-heading">Further Reading</h2>



<p class="wp-block-paragraph"><strong>From SIL Safe</strong></p>



<ul class="wp-block-list">
<li>SIL Safe: <a href="https://silsafe.net/hazard-and-risk-assessment-hra/">Hazard and Risk Assessment (H&#038;RA): The Foundation of Functional Safety</a></li>



<li>SIL Safe: <a href="https://silsafe.net/layer-of-protection-analysis-lopa/">Layer of Protection Analysis (LOPA): The Engineer&#8217;s Guide to SIL Selection</a></li>
</ul>



<p class="wp-block-paragraph"><strong>External resources</strong></p>



<ul class="wp-block-list">
<li><a href="https://webstore.iec.ch/en/publication/25480" target="_blank" rel="noopener">IEC 61511-3:2016</a>: informative annex on risk assessment methods</li>



<li>CCPS, <a href="https://www.aiche.org/resources/publications/books/guidelines-hazard-evaluation-procedures-3rd-edition" target="_blank" rel="noopener"><em>Guidelines for Hazard Evaluation Procedures, 3rd Edition</em></a></li>



<li>CCPS, <a href="https://ccps.aiche.org/publications/books/layer-protection-analysis-simplified-process-risk-assessment" target="_blank" rel="noopener"><em>Layer of Protection Analysis: Simplified Process Risk Assessment</em></a></li>



<li><a href="https://www.osha.gov/laws-regs/regulations/standardnumber/1910/1910.119" target="_blank" rel="noopener">OSHA PSM 29 CFR 1910.119</a>: PHA requirements for US-regulated facilities (paragraph (e))</li>



<li><a href="https://www.hse.gov.uk/comah/index.htm" target="_blank" rel="noopener">HSE COMAH guidance</a>: UK regulatory framework for major accident hazards</li>
</ul>



<p class="wp-block-paragraph">Functional safety is complex, and the stakes are high. If you have questions about your SIS design, SIL verification, or where to start with IEC 61511-1, the team at SIL Safe is here to help. Reach out to us today.</p>



<script type="application/ld+json">
{
  "@context": "https://schema.org",
  "@type": "FAQPage",
  "mainEntity": [
    {
      "@type": "Question",
      "name": "I sometimes hear PHA and sometimes H&RA. Are they the same thing?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "PHA is the umbrella term most practitioners use, particularly in CCPS-influenced documentation, and usually refers to the hazard identification activity specifically. H&RA is the IEC 61511 phrasing for the full activity covering both identification and assessment. Practitioners sometimes use PHA loosely to mean the whole exercise, which is part of where the confusion comes from."
      }
    },
    {
      "@type": "Question",
      "name": "How do I know if my site is using the wrong H&RA method?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "This is a hard question and often needs the judgment of experienced professionals to answer well. Some clues: Mismatch — a small facility running a full quantitative program for routine scenarios is using more methodology than the risk profile warrants; a complex high-consequence facility relying on a calibrated risk matrix for SIL determination is using less methodology than the risk profile warrants. Inconsistency — scenarios assessed by different methods with no documented basis for the choice, or IPLs credited differently across similar scenarios."
      }
    },
    {
      "@type": "Question",
      "name": "Can FTA and ETA satisfy IEC 61511's H&RA requirement on their own?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No. FTA and ETA take hazardous events as a design input. The methods cannot generate the events themselves. Something upstream has to identify them, which is the work of a hazard identification method like HAZOP. Without that step, the quantitative analysis is rigorous about whatever events the team happened to think of, and silent about everything else."
      }
    },
    {
      "@type": "Question",
      "name": "Is risk graph an acceptable method, or do I have to use LOPA?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Risk graph is a fully legitimate IEC 61511-3 method. The standard does not mandate LOPA. The right choice depends on facility context. Risk graph is common in European-influenced practice, oil & gas globally, and machinery safety; LOPA dominates in many regulatory contexts, particularly under PSM/RMP. What's not acceptable is mixing the two on the same scenario set."
      }
    },
    {
      "@type": "Question",
      "name": "My boss says HAZOP takes too many people for too many days and costs too much. Why can't we just do a What-If/Checklist?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Sometimes you can. What-If/Checklist is a legitimate hazard identification method, accepted under OSHA PSM, COMAH, Seveso, and similar frameworks. It's the right tool for smaller, simpler, or batch processes, for MOC reviews, and for revalidations of well-understood operations. The choice should be based on process complexity and consequence severity, not on cost alone. Cost is a real factor, and not every scope warrants a full HAZOP. As process complexity, scenario count, or consequence severity increase, the cost-benefit shifts back toward HAZOP. Using What-If/Checklist on a scope that genuinely needs HAZOP is how facilities miss hazards that come back to bite them later."
      }
    },
    {
      "@type": "Question",
      "name": "Where does LOPA actually sit in the IEC 61511 life-cycle, Clause 8 or Clause 9?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Both. The analytical work is risk assessment under Clause 8. The output (required risk reduction expressed as a SIL) is consumed by Clause 9 for protection layer allocation. LOPA spans the boundary, which is why it's described both as an H&RA method and a SIL determination method."
      }
    },
    {
      "@type": "Question",
      "name": "Do I need a bowtie for every hazardous event?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "No. Bowtie is most valuable for high-consequence scenarios where barrier management and stakeholder communication justify the effort. For routine scenarios handled in a HAZOP and LOPA workflow, a bowtie adds little beyond what the LOPA worksheet documents."
      }
    }
  ]
}
</script>

]]></content:encoded>
					
					<wfw:commentRss>https://silsafe.net/hazard-and-risk-analysis-methods/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Minified using Disk

Served from: silsafe.net @ 2026-07-23 20:21:45 by W3 Total Cache
-->