Process hazard analysis (PHA) is one of the most commonly researched terms in process safety, and one of the loosest. At its core, a PHA is a structured, team-based study that identifies the hazards of a process and evaluates the risk they carry. But it isn’t a single, fixed thing. Which regulation drives it, and even whether “PHA” is the legal term at all, changes from one country to the next, and the same three letters carry meanings well outside process safety. The closest activity IEC 61511-1 defines is the Hazard and Risk Assessment (H&RA), where the operative word is assessment, not analysis.
Process Hazard Analysis in the United States
In the United States, process hazard analysis (PHA) is a defined legal term. Two of the best-known process safety regulations use the exact phrase:
- OSHA’s Process Safety Management (PSM) standard, 29 CFR 1910.119
- the EPA’s Risk Management Program (RMP) rule, 40 CFR 68.67
Neither actually defines what a PHA is. OSHA calls it a “hazard evaluation” once, in parentheses, and leaves it there. What the regulations do instead is spell out, in detail, what the analysis has to address and who has to be in the room. So a PHA in the US is a legal duty with a specified scope, not a single named technique.
The OSHA and EPA Requirement
OSHA is the one to work from: RMP’s PHA requirement mirrors it for the higher-hazard Program 3 processes and drops to a lighter “hazard review” for Program 2. RMP is the sibling rule, not a separate model, so OSHA carries the shape of both.
OSHA 1910.119(e) requires an initial process hazard analysis appropriate to the complexity of the process, one that identifies, evaluates, and controls its hazards. The rule even lists the methods you can use, at 1910.119(e)(2): What-If, Checklist, What-If/Checklist, hazard and operability study (HAZOP), failure mode and effects analysis (FMEA), fault tree analysis, or an appropriate equivalent.
The study has to cover the hazards of the process, any previous incident that could have turned catastrophic, engineering and administrative controls, the consequences of those controls failing, facility siting, human factors, and a qualitative look at the health effects on employees. The team needs engineering and process expertise, one member who knows the specific process, and one who knows the method being used. And the process hazard analysis has to be revalidated at least every five years.
What the H&RA Requires
IEC 61511-1 handles the same ground in Clause 8. The clause requires an H&RA, and Clause 8.2.1 sets out seven outputs it has to produce, with Clause 8.2.4 adding a security risk assessment of the safety instrumented system (SIS).
Where a process hazard analysis stays largely qualitative, the H&RA outputs push into numbers: the additional risk reduction the process needs (the risk gap), the assumptions behind that figure (demand rates on the protection layers, failure rates of the initiating sources), and which functions end up as safety instrumented functions (SIFs). The H&RA sizes the risk gap; it does not assign the safety integrity level (SIL) that closes it, which is Clause 9’s job. Everything on that list has to exist before SIS design can start.
The H&RA Versus the OSHA PHA
The two studies overlap on the basics: identifying hazards, judging consequences, and reviewing the controls already in place. They diverge in two directions:
- What a PHA covers that the H&RA doesn’t: facility siting, human factors, and the review of past incidents, all of which the H&RA leaves to other standards.
- What the H&RA covers that a PHA doesn’t: the quantitative work a compliance PHA rarely produces, the risk gap, the documented assumptions, the SIF identification, and the security assessment.
For the specific job of defining a SIS, the H&RA is the narrower and more rigorous of the two. Run a PHA purely to satisfy PSM or RMP and it will usually leave holes that surface later, when the SIS design has nothing to build on.
Process Hazard Analysis in the EU and the UK
Cross the Atlantic and the legal picture changes. In the EU, the Seveso III Directive governs major-accident hazards. It requires operators to identify those hazards and show they are controlled, with a full safety report at the higher-tier sites, but it never uses “PHA” as a defined term.
The UK’s COMAH Regulations 2015 (Control of Major Accident Hazards), built on Seveso III, work the same way: a safety report demonstrating that major-accident risks are as low as reasonably practicable (ALARP), and again no defined “PHA.” The term still gets used across Europe, by engineers and consultants and bodies such as the Chemical and Downstream Oil Industries Forum (CDOIF), but as shorthand for the hazard study feeding that safety report, not as a phrase in the law. The tie to IEC 61511-1 is exactly what it is in the US: the PHA is the broad process-safety study, the H&RA is the SIS-focused piece Clause 8 defines.
Process Hazard Analysis in India and Other Jurisdictions
India built its regime after the 1984 Bhopal disaster, mainly through the MSIHC Rules 1989 (Manufacture, Storage and Import of Hazardous Chemicals), backed by the Factories Act and environmental law. Those rules require operators to identify major accident hazards and keep a safety report; they do not name a “PHA.” In practice, Indian engineers call the work a PHA or a HAZOP, and HAZOP is increasingly expected at large facilities.
The same holds across the Gulf oil and gas sector and much of Asia, where “PHA” is the working term, carried worldwide more by Center for Chemical Process Safety (CCPS) guidance and OSHA-modeled practice than by any single global statute. The pattern is consistent: the US is unusual in writing process hazard analysis into the regulation itself. Most other jurisdictions require the underlying activity, the hazard identification and the safety report, and leave “PHA” to the people doing the work.
PHA in System Safety: Preliminary Hazard Analysis
“System safety” is a somewhat loose label for a separate engineering discipline, rooted in military and aerospace programs, that manages hazards across the whole life-cycle of a system: an aircraft, a weapon, a vehicle. It runs on its own standards, distinct from process safety.
Under MIL-STD-882, PHA there means a Preliminary Hazard Analysis: an early concept-phase activity that produces a first hazard list before detailed design, feeding the fuller analysis that follows. Automotive functional safety runs the same kind of early study under ISO 26262, but calls it the HARA (Hazard Analysis and Risk Assessment), not a PHA. Same three letters, different activity: a process engineer who picks up a defense document will find “PHA” pointing at something earlier and narrower than the study they run.
PHA as the Whole Study or Just the Identification Step
Even inside process safety, the term isn’t settled. Some use process hazard analysis for the whole hazard study, identification plus risk assessment. Others use it for the identification step alone, the HAZOP or What-If, and treat the risk assessment as a separate activity. CCPS-influenced documentation tends to use PHA as the umbrella for the entire exercise, which reinforces the broader usage. The result is that “we did a PHA” can mean a full risk assessment or just a hazard list, depending on who is saying it.
Other Meanings of PHA
Two more uses of PHA sit outside process safety entirely, and both inflate the search numbers for the term:
- Polyhydroxyalkanoate. In chemistry and materials, PHA is a family of biodegradable bioplastics grown by microbial fermentation. In a bioplastics or fermentation setting, “PHA” almost always means the polymer, not a hazard study.
- Public Health Assessment. The US Agency for Toxic Substances and Disease Registry (ATSDR) uses PHA for its structured evaluation of community exposure at contaminated sites.
Neither shares any functional safety content with the process-industry PHA. They just share the letters, which is part of why the term ranks so high.
Common Mistakes
The biggest mistake with this topic is treating “PHA” as if it means one fixed thing. It shifts by jurisdiction, by discipline, and by scope, and the moment two people assume the same meaning, they end up talking past each other.
The next two are mirror images. One is assuming a compliant IEC 61511-1 program already satisfies the PHA: a facility under PSM and RMP can run a strong SIS program and still miss the full PHA obligation and its reporting and documentation. The other is assuming the reverse, that a PHA done to the OSHA standard already meets IEC 61511-1. It won’t produce the quantitative outputs Clause 8 needs, the risk gap, the documented assumptions, the SIF identification, so the SIS work is left without its inputs.
A quieter one is the revalidation trigger. IEC 61511-1 wants the H&RA reviewed whenever a change affects it; PSM and RMP run a fixed five-year clock. Treat either as if it satisfies the other and something slips. These all sit at the boundary between the two studies; the H&RA has its own longer set of mistakes, which we cover in our guide to the Hazard and Risk Assessment.
Frequently Asked Questions
I run what I think is a solid, compliant IEC 61511-1 program at a US process facility, but I don’t really know the PHA requirements under PSM and RMP. Does a compliant 61511 program mean I’ve already met the PHA requirement?
No, and this catches a lot of people. A compliant IEC 61511-1 program gives you the H&RA under Clause 8, but that’s only the SIS-focused slice of a PHA. It doesn’t cover the rest of the PHA’s scope, and it does nothing for the PSM and RMP reporting and documentation that sit around it. You’ve done real work toward the PHA, but there are gaps, and they’re the parts a regulator looks for.
Our compliance department says we have to refresh our HAZOP every five years, but I can’t find that anywhere in IEC 61511-1. Where’s it coming from?
It’s not in IEC 61511-1, so you won’t find it there. The five-year clock is the PHA revalidation requirement under OSHA PSM and EPA RMP, which is what your compliance team is working from. The standard uses a different trigger: it wants the H&RA reviewed whenever a change could affect it, not on a fixed schedule. Both are legitimate; they’re just different requirements pointed at the same study.
In our functional safety procedures and documentation, should we call this a PHA or an H&RA?
SIL Safe generally recommends the IEC 61511-1 term, H&RA. It’s simpler to keep one vocabulary, and it matches the standard your program runs on. That’s our preference, and reasonable people land the other way. Whichever you pick, it’s worth a line in your procedures noting that where PSM and RMP apply, the H&RA also serves as your PHA, then actually closing the gaps between the two so that statement holds up.
A vendor sent me a document that refers to a “PHA,” but it’s for an automotive control system. Is that the same PHA we run at a process plant?
No. In that world, PHA is a Preliminary Hazard Analysis, an early concept-phase study from the system-safety tradition behind MIL-STD-882. It produces a first-pass hazard list before detailed design, which isn’t what your process-industry PHA does. If the vendor is working to ISO 26262, their equivalent risk study is actually called the HARA. Same three letters, different activity.
We ran a HAZOP. Does that mean we’ve done our PHA?
It depends on how your site and your regulator use the word. A HAZOP is the hazard-identification step. If your definition of PHA is the whole study, you’re not done: you still owe the risk assessment on top of the HAZOP, which is also what the IEC 61511-1 H&RA expects. If your site treats PHA as the identification step alone, then maybe, but confirm that before you close it out.
How does this split between engineering and the compliance department? At bigger companies, functional safety sits with engineering, and I think the PSM and RMP side sits with a compliance department. However, we’re small and don’t have a compliance department. So who owns the PHA?
In larger organizations that’s roughly how it works: the functional safety work, including the IEC 61511-1 H&RA, sits with engineering, and PSM and RMP compliance sits with a separate compliance group. The two coordinate so the H&RA feeds the PHA and every regulatory requirement is covered. At smaller facilities there’s often no compliance department at all, and engineering picks up the slack, owning both the H&RA and the PHA’s regulatory obligations.
We at SIL Safe are engineers, and we lean toward doing the engineering, not the compliance and reporting. It’s somewhat annoying, but honestly hard to get around. When it lands on engineering, the work doesn’t disappear, it just sits with fewer people, so it pays to be deliberate about covering the regulatory side.
Further Reading
From SIL Safe
- Hazard and Risk Assessment (H&RA): The Foundation of Functional Safety
- Hazard and Risk Analysis Methods: How HAZOP, What-If, LOPA, Risk Graph, FTA, ETA, and Bowtie Fit Together
- Layer of Protection Analysis (LOPA): The Engineer’s Guide to SIL Selection
- What is Functional Safety? (Functional Safety for the Process Industry)
External resources
- OSHA: Process Safety Management (overview)
- OSHA: Process Safety Management standard, 29 CFR 1910.119
- EPA: Risk Management Program (RMP) Rule
- EPA: Risk Management Program, 40 CFR 68.67
- CCPS: Guidelines for Hazard Evaluation Procedures, 3rd Edition
- HSE: Control of Major Accident Hazards (COMAH)
Functional safety is complex, and the stakes are high. If you have questions about your SIS design, SIL verification, or where to start with IEC 61511-1, the team at SIL Safe is here to help. Reach out to us today.
