Thread Content
This post was last edited by xiouxingzhe on 2026-6-25 at 11:28. Seven stages of chemical technology from concept to industrialization (Issue 51/100) —— Technology finalization: The application of HAZOP analysis in the process package stage. Dear friends: Hello everyone! In the previous issue, we discussed instrument and interlock design; the interlock logic diagrams have been prepared, and the differences between SIS and DCS have also been clarified. In this issue, we’ll discuss a technique that is well-known to everyone but is often chosen at the wrong time: HAZOP analysis. HAZOP stands for Hazard and Operability Study, which is an analysis of hazards and operational aspects. This is one of the most fundamental systematic safety analysis methods in the chemical industry. However, many projects have a common misunderstanding regarding HAZOP: they think it is an activity that should be carried out only during the basic design or even detailed design phase, and that HAZOP is conducted only after the construction drawings have been completed. As a result, major safety hazards were identified—but the pipeline layout was already finalized, the equipment arrangement was set, and the interlock scheme was established; making any changes would have far-reaching consequences and come at a high cost. My approach is to conduct the first round of HAZOP analysis and SIL classification during the process package design phase. This is an important manifestation of the \"risk-first\" philosophy in the technology finalization stage. Identify critical hazard scenarios and embed countermeasures in PFDs and PID files, so that subsequent engineering designs have a safety benchmark to follow. I. Basic principles of HAZOP analysis The core idea of HAZOP analysis is to break down a complex process system into various “nodes,” and then, for each node, use a set of standardized “guiding words” to ask systematic questions in order to identify any “deviations” that could lead to hazards or operational problems. The causes, consequences, existing protective measures, and risk levels associated with these deviations are then analyzed one by one. Node division is primarily based on PFD and PID. A typical node can be a reactor along with its associated pipelines, it can be a section of a distillation column system, or it can be a pipeline segment from the pump outlet to the heat exchanger inlet. The principle for classification is: the process intent within a node is clear, and the material status is consistent, which facilitates systematic analysis using guiding terms. Guidewords are the core tool of HAZOP analysis. Common guiding words include: “None” – the design intent was not fulfilled at all, for example, a failure of the feed pump results in a feed flow rate of zero. “High” – the parameter value exceeds the design value; for example, the reactor temperature or pressure is too high. “Low” – the parameter value is below the design value; for example, the liquid level in the distillation tower is too low. “Reverse” – the flow direction is opposite to the intended one, such as backflow caused by a failed check valve at the pump outlet. “Accompanied by”——an additional event occurs alongside it, such as a reaction producing unintended by-products. “\"Partial\"” – the component or a part of the process is carried out, for example, the decrease in catalyst activity results in only partial conversion. For each trigger word associated with each node, the analysis team follows a logical chain: what is the deviation → what are the possible causes → how severe could the consequences be → what protective measures are in place → what is the risk level → are additional recommended measures needed. For example, regarding the parameter of reactor temperature, analyze the deviation of \"high temperature\". Possible reasons include insufficient cooling water supply, an imbalance in the feed ratio that leads to increased heat release from the reaction, or mixing problems that result in local hot spots. Possible consequences include uncontrolled reactions, overpressure, and even explosions—for high-risk reactions such as nitration and diazotization, high temperatures can have very serious effects. Existing protection measures include jacket cooling, DCS temperature alarms and operator intervention, as well as safety valves. But are these measures enough? The reliability of DCS alarms combined with operator intervention; if it does not meet the requirements of the SIL rating, an independent SIS interlock circuit must be added – this circuit will automatically shut off the feed when the reactor temperature is too high, open the coolant valves fully, and trigger an emergency release. The worst thing in a HAZOP analysis is not to identify many problems, but to find a bunch of \"no problems\". A complex chemical processing plant has at least dozens of nodes, and analyzing each node using multiple guiding words takes several days, rather than just a few hours. If systematic deficiencies in the safety design are identified at the process package stage and corrected immediately, the amount of work required for revisions is vastly less compared to discovering those issues through HAZOP after the detailed design is completed. II. Focus of HAZOP during the process package phase The HAZOP analysis in the process package phase has different focuses compared to that in the preliminary design phase. The two cannot replace each other, but the order cannot be reversed. The primary goal of HAZOP during the process package phase is not to identify safety hazards in every detail of the construction – that can only be done once the detailed design is completed and the specific layout of equipment and pipelines is determined. The primary goal at this stage is to identify all major hazardous scenarios, and to transform the safety requirements for dealing with these scenarios into specific interlock circuit requirements and design principles for relief systems, which are then incorporated into the PFD and PID. What are the major hazardous scenarios? Uncontrolled reaction – loss of control over temperature and pressure can lead to catastrophic consequences. A large release of toxic substances – with severe effects on people outside the factory area. Explosion – occurs when combustible gases or dusts accumulate to form an explosive mixture. Once such scenarios occur, the consequences can be catastrophic; they must be identified at the process package stage and effective protective measures taken. The second objective of the HAZOP during the process package phase is to examine the process design from an operability perspective. How to establish the liquid level while driving? Where should the materials be placed when parking? What intervention methods do operators have under abnormal operating conditions? If these practical issues are discovered only at the detailed design stage, when the pipelines have already been installed, the equipment layout has been finalized, and the platform has been designed, making changes will be very costly. It was found during the process package phase that by changing the pipeline routing on the PID, no waste would be generated at the site within half a day. Therefore, during this phase of HAZOP, in addition to safety considerations, considerable time is also spent examining the feasibility of operations and maintenance. III. Organization of the HAZOP analysis team: HAZOP analysis is not the responsibility of process engineers alone; it requires collaboration among multiple specialties. A complete HAZOP analysis team should include at least the following roles. HAZOP team leader: oversees the analysis meetings, controls the pace, and ensures the quality of the analysis. The team leader must receive professional training, have experience in leading HAZOP studies, and most importantly — must be independent of the project team. If the team leader is the process owner for this project, it is easy for him to unconsciously defend the designs he has created in his analysis, rather than objectively challenging them. An independent team leader does not develop an emotional attachment just because \"it was my design\"; he dares to ask questions and is good at doing so. Process engineers explain the intent behind process design, provide process parameters, and address the consequences of deviations from the design – they are those most familiar with PFDs and PID. Equipment engineers assess the capacity of equipment under abnormal conditions – whether the casing will crack under excessive pressure, or whether the seals will fail under high temperatures. Instrument control engineer: assess the adequacy of existing control schemes and interlocks – whether the DCS can detect such deviations, and whether the protective actions of the SIS are fast enough. Safety engineers assess risk levels and determine the adequacy of protective measures—whether the existing protective layers are sufficient, and which SIL level of safety instrumented functions is needed to supplement them. The operations representative provides practical experience in carrying out tasks and determines the feasibility of such operations – namely, what the operator can do when this deviation is detected and whether the reaction time is sufficient. The recorder documents the analysis process and conclusions, and prepares the HAZOP report – ensuring that every deviation, every cause, every consequence, and every recommended action is accurately recorded. It is very important that the team leader is independent of the project team. If the team leader is part of the project team, HAZOP can easily become a formality – reviewing oneself means that no major issues can be identified no matter how the review is conducted. An independent team leader is able to examine the design from a third-party perspective and raise those tough questions that it’s difficult to bring up within the project team itself. IV. The transition from HAZOP to SIL grading: After HAZOP identifies the hazardous scenarios that require protection through safety instrumented interlocks, the next step is to use LOPA – Layer of Protection Analysis – to conduct a quantitative assessment: Is the existing layer of protection sufficient? If it is insufficient, which SIL level of safety instrumented function is needed to supplement it? SIL, Safety Integrity Level, is classified from SIL1 to SIL4; the higher the level, the stricter the requirements for safety instrument functions. The common SIL levels in chemical processing units are SIL1 and SIL2; SIL3 is less common, while SIL4 is virtually non-existent—because reaching the SIL4 level usually indicates that the process itself is too dangerous, requiring a redesign of the process rather than relying on interlocks for protection. The logic of LOPA analysis is to start from the high-risk scenarios identified in HAZOP, and then list the initial event frequency for each such scenario as well as all the independent protection layers. Independent protection layers include basic process control alarms and operator intervention, physical protection devices such as safety valves and rupture disks, as well as passive protection facilities like fire dikes and blast walls. Calculate the occurrence frequency of this scenario under the existing protection layer. If the frequency remains above the acceptable threshold—for example, if the risk of casualties is higher than one in 100,000 per year—it is necessary to add a safety instrument function, and the SIL level is determined based on the required risk reduction factor. The advantage of completing the SIL classification during the process package phase is that the SIL level of the interlocks directly determines the design of the SIS system – SIL1 can involve a single channel, SIL2 usually requires redundant channels as well as stricter requirements for online testing, while SIL3 demands higher fault tolerance and faster response times. Actuators may also require a partial stroke testing function to meet SIL2 requirements. These requirements must be reflected when preparing the instrument data sheets and interlock logic diagrams. If it is not determined at the process package stage, the instrumentation team will be unable to carry out the SIS system design during the basic design phase; instead, they will have to seek additional data from the process team, which will delay the progress of the entire project. V. A complete closed loop: from HAZOP to interlock design. Taking a constant-pressure reactor with stirring as an example, it is heated by low-pressure steam through the jacket; meanwhile, the jacket can also be switched to cooling water for cooling. The reactor is equipped with instruments for monitoring temperature, pressure, and liquid level. This is a typical node. The HAZOP analysis identified a high-risk scenario resulting from an \"excessively high\" value for the \"temperature\" parameter: if the temperature in the reactor becomes too high and steam is not shut off promptly, it may cause the materials inside the reactor to decompose and generate gas, leading to overpressure or even an explosion. The existing protective measures are DCS temperature alarms and operator intervention. However, the reliability of DCS alarms and operator responses is usually only around 90% to 95%—the operator might happen to be on a patrol, the alarm could be overlooked due to noise, or the operator might make a mistake in judgment. For scenarios that could lead to catastrophic consequences, this layer of protection is not sufficient. The LOPA analysis confirmed that an additional independent SIS interlock circuit is required. Based on the required risk reduction factor, it is determined that this circuit needs to achieve SIL2. This means that the sensors need to be configured redundantly – two independent high-temperature sensors use a majority voting logic to reduce the risk of false stops while ensuring no false alarms are issued. The actuator requires separate shut-off valves and refrigerant valves, and cannot share them with the DCS. The entire circuit requires regular online testing to verify the availability requirements of SIL2. Based on this, the process engineer added the following logic to the interlock logic diagram: the input signal is the high-temperature sensor of the reactor, which is independent of the DCS temperature sensing elements; it features a dual-redundant configuration with a two-out-of-two logic. Logical function – Upon detection of a high temperature signal, it triggers two actions: closing the steam feed valve and opening the cooling water valve, while also issuing audible and visual alarms in both the control room and on-site. Reset method – Manual reset: After the operator confirms that the temperature has dropped to a safe level and the pressure has returned to normal, the reset button is pressed in the control room, thereby releasing the interlock. It can be seen that, starting from HAZOP analysis, moving on to LOPA classification, then to the design of interlock logic, and finally resulting in PID values and instrument data sheets – this forms a complete closed loop for process safety protection. This closed-loop system was completed before the process package was handed over to the basic design unit, providing clear input conditions for the instrumentation team to carry out the detailed SIS design. More importantly, once this closed loop is established, if anyone later wishes to modify the interlock logic—such as reducing redundant configurations in the detailed design phase to save costs—it will be necessary to re-examine the findings of HAZOP and LOPA to prove that the risks remain acceptable after the modifications. This itself constitutes a protective barrier against arbitrary modifications. VI. Common issues in HAZOP during the process package phase: Although HAZOP analysis seems logical in theory, it is easy to go off track when carrying it out. There are several common issues. One is that the node division is too coarse. A reactor, along with its inlet and outlet pipelines and heat exchange system, is treated as a single node; after asking guiding questions for half an hour, that’s it – such an approach fails to uncover deeper issues. The node division should be detailed to include each independently functional component; for a reactor, the feeding, reaction, discharging, cooling, and exhaust processes – each of these functions may have different deviation patterns, and therefore should constitute separate sub-nodes. Another issue is that the guiding words are not used fully. Only “high” and “low” were used; “none”, “reverse”, “associated”, and “partial” were not used. Many serious accidents are triggered precisely by a \"zero\" state – a disruption in flow or the absence of cooling water – or by a \"reverse\" situation – backflow caused by a failed check valve. The more guide words are used, the smaller the blind spots. Another issue is that the analysis of the protective layer is not thorough enough. ““What the operator will discover” cannot serve as an effective independent protection layer—the operator may be dealing with other alerts, may make mistakes in judgment, or may not have enough time to respond. The protection layer must be independent, effective, and auditable—safety valves, rupture disks, SIS interlocks, and fire and explosion prevention facilities are the true forms of protection. Operator intervention can only serve as an additional risk reduction measure, not as the primary layer of protection. Preview for the next issue: Issue 52 – SIL Classification: The Connection from HAZOP to LOPA. HAZOP identifies hazardous scenarios that require safety interlock protection. The next step is to determine the SIL level using the LOPA method. How to quantitatively calculate the initial event frequency and the failure probability of independent protection layers? How to determine whether it is SIL1, SIL2, or SIL3? How are the SIL classification results reflected in the instrument data sheet and interlock logic diagram? To be continued in the next issue.