Professional Documents
Culture Documents
Vol1
Vol1
Vol1
Volume I- Thesis
October 1997
by
Johari Basri
B. E. (Universiti Teknologi Malaysia, 1977),
M. Sc. (University of Manchester, UK, 1984)
The research described in this thesis provides a comparative study of the impact
of
Process Safety ManagementSystem(PSMS) performanceand Human Error rates on
off-site risk from two major hazardssites in Malaysia. One of the sites was built and
run by a multinational company until a few years ago while the other was built and
run by a local company since its inception. The sites handle bulk quantities of
ammonia for downstreamdistribution. The study considers:
operations
assessingthe impact of site PSMS and humanerror potential on off-site risk from
the sites
investigating the possibility of linking the assessmentof site PSMS performance
of humanerror potential
site specificPSMS performanceaudit with the assessment
was found to be inadequate to describeall the influenceswhich will be exertedon the
reliability of individualtasks involvinghumanerror potential.
opsis
operations
e assessingthe impact of site specific safety managementperformance and human
error potentialon off-siterisk from the sites
investigating the possibility of linking the assessmentof site specific safety
The Process Safety Management Systems(PSMS) at three major hazard sites were
specific study on this subject was also conducted in an attempt to explore its
relationship with the PSMS performancefor each site. For this purpose ammonia
filling operationsat Site A and Site B were assessed,
basedon physical inspectionsof
the filling system, interviews with the operators, analysing work procedures and
observation of critical tasks with the help of video taping. A human error analysis
technique, SLIM was used for the analysis,which identified a number of critical
tasks that provide major contributions to human error potential in ammonia filling
setting the target filling weight for the road tanker were found among the most
critical to humanerror.
rates in the form of IHEPsfrom a SLIM assessment were used as an input for the
QRA. This approach models the effect of the site specific PIFs on human error
rates. Additional runs were then conductedusing nominal IHEP values from T]HERP
and BEART databasesto compare the off-site risk results using these values which
represent generic human error rates. A number of sensitivity runs were also
conducted using IHEPsderived from SLIM using different sets of calibration points to
analysethe impact of selectingthe different calibration points which representone of
the main uncertainties of using the technique.
Results from these two different approaches highlight the effect of PSMS
performance and human error on off-site risk. The effect of considering site specific
PSMS performance in conducting the QRA increasesthe off-site risk distance to a
specified individual risk level of IOE-06 by a factor of 2 and 1.2 for Site A and
Site B respectively, while the effect of considering individual human error
results show that both approachespredict similar effects for the influence of site
specific PSMS performance and the site specific human error rates on off-site risk.
The results also suggest that despite its global approach, the PREVA technique is
The study found that the site specific PSMS performance provided significant
influence on off-site risk at the two major hazard sites. This suggested the need to
where there exist significant difference in PSMS performances, for example between
locally owned and multinational sites. The PSMS laid down by the multinational
error through better training, the retention of experienced personnel and good
system failure rates, people also provided mechanismsfor recovery in the event of
hardware failures.
The study also found that the PRIMA audit approach, the human error analysis
technique SLIM and the QRA tool RISKAT were all suitable to be used for a
developing country like Malaysia, with only minor modifications. It also found that
QRA requires good site specific weather data as this strongly influencesthe outcome
of the risk results, especially for toxic materials. It therefore stressedthe need to
develop good weather data which is quite scarcein developing countries.
An analysis was also made to link the results of the PRIMA audit with the
assessmentof human error. The aim was to utilise valuable information gathered
through the structured audit technique for the quantification of site specific human
error potential. However it was found that the PRIMA audit information can only
assessperformance at global or organisationallevel, and is inadequateto describe all
the PIFs which will have an effect on the reliability of individual tasks which involve
human error.
Finally the research has involved the application of knowledge from three distinct
on off-site risk. The comparative study conducted on two major hazard installations
I would to take the opportunity here to expressmy gratitude to everybody that has
helped to made this researcha reality. In the U. K. special mention is made to
my
supervisor Dr. Martin Pitt of The University of Sheffield, my external advisors Dr.
Nick Hurst and Ms. Jill Wilday of Health and Safety Laboratory, and Dr. David
Embrey of Human Reliability Associatesfor their invaluableguidanceand support. In
Malaysia I would like to thank the The Government of Malaysia for sponsoring my
study, The Department of Occupational Safety and Health for granting me the study
leave, The Major Hazard Division officers for assisting me in conducting the field
Moral support from my family has been instrumental in completing the research and
they deservemy deepestlove and gratitude. For my wife Ibah for her patience and
perseverance. For my three children Juriana,Ilyana and Izzaty for keeping the house
lively with their antics and I hoped they have enjoyed their stay here in Sheffield and
4.1 Introduction 75
.............................................................................................
4.2 The PRRvfA Audit 75
...................................................................................
4.3 Conducting PRHv1Aaudits in Malaysia 77
....................................................
4.3.1 Conducting training for the Malaysia audit team 77
................................
4.3.2 Providing keywords to PRIMA audit questionnaires 78
...........................
4.3.3 Preparing a structured answersheets 78
.................................................
4.3.3 SelectingMH11for PRIMA audits 78
......................................................
4.3.4 Pre -Audit plant familiarisation 84
..........................................................
4.4 Conducting PRIMA Audits 85
......................................................................
4.4.1 Managementbriefing 85
........................................................................
4.4.2 Plant familiarisation 85
...........................................................................
4.4.3 Conducting interview 86
........................................................................
4.4.3 Document verification 88
.......................................................................
4.4.4 Site inspection 88
..................................................................................
4.4.5 Formed judgement 89
............................................................................
4.4.6 Post audit managementbriefing 89
.........................................................
4.4.7 Audits duration 92
.................................................................................
4.5 PREqA audit results 92
...............................................................................
4.5.1 PSMS Control Loops for the 3 sites 92
..................................................
4.5.2 Summaryof PSMS audit results for the 3 sites 97
..................................
4.5.3 Comparisonof PSMS audit resultsbetween Sites 99
..............................
4.6 PRIMA Modification Factors 100
...................................................................
4.7 Strengths and Shortcomings of PRHVIA 104
...............................................
4.7.1 Strengths 104
..........................................................................................
4.7.2 Shortcornings 105
....................................................................................
4.8 Recommendationto improve PRDJA 105
......................................................
4.8.1 The methodology 105
..............................................................................
4.8.2 The audit tools 106
..................................................................................
4.8.3 Usage of PREN4Aaudit 106
.....................................................................
4.9 Conclusions 107
.............................................................................................
6.6.4.3 The impact of assessedand nominal IHEPson QRA results ......... 229
6.7 Conclusions 230
..............................................................................................
CHAPTER 7 Using PRIMA as an integrated audit for PSMS
and HEA
7.1 Introduction 232
.............................................................................................
A PhD Thesisby J.Basri
x
7.2 Common attributes that are essentialfor both PSMS and BEA 233
..................
7.3 How PRIMA Audit assessedthe attributes 233
..............................................
7.4 Examining the possibility of assessingPIFs for BEA using PRIMA Audit.. 233
7.5 A simple method to quantify PIFs rating 237
..................................................
7.6 Conclusion 241
..............................................................................................
CHAPTER 8 Discussions, Conclusions and Suggestions for
Further Work
8.1 Introduction 242
.............................................................................................
8.2 Findings 242
...................................................................................................
8.2.1 PSMS performance differs between the 3 sites 242
..................................
8.2.2 Strengths and weaknesses of PSMS of locally owned site 243
..................
8.2.3 Strengths and weaknesses of PSMS sites owned by multinational 244
.......
8.2.4 Multinational influence on site PSMS 245
................................................
8.2.5 The effectiveness of ammonia road tanker loading task differs
between the two sites 246
......................................................................
8.2.6 PIFs situation at Site A is better than Site B 246
......................................
8.2.7 Critical task predicted by PIHEA is similar for the two sites 248
..............
8.2.8 IHEPs value strongly influenced by PIFs 248
............................................
8.2.9 Calibration points influenced IHEPs calculated using SLIM 248
................
8.2.10 Site A has higher IHEPs as compared to Site B 249
................................
8.2.11 Site specific PSMS performance increase the off-site risk for Site A.. 249
8.2.12 Site specific PSMS performance does not affect off-site risk for
Site B 249
.............................................................................................
8.2.13 Site specific weather data is a dominant factor in QRA 250
....................
8.2.14 Site specific PSMS performances have positive impact on 1HEPs 250
.....
8.4 Conclusions 252
.............................................................................................
8.3 Suggestions for Further Work 253
..................................................................
8.4.1 PSMS Auditing 254
.................................................................................
8.4.2 Human Error Analysis 255
.......................................................................
8.4.3 Quantitative Risk Assessment 256
...........................................................
8.4.4 Integrating PSMS and Human Error Analysis 257
..................................
References 258
..................................................................................................
Appendix 12
Input for QRA using RepresentativeFailuresApproach 377
...........................
Appendix 13
IHEPsNominal Data from TIHERPand BEART Data base 380
..............................
Appendix 14
Fault Tree Diagrams for Site A and Site B 383
......................................................
Appendix 15
Input for QRA using Fault Tree Approach-GenericFailure Rates and I-1EPs 412
....
Appendix 18
Eliciting PIFs from PRRVIAAudit 431
..........................................................
at Site A 356
....................................................................................
Figure A8.2. Piping Arrangementfor Ammonia Road Tanker Loading
at Site A 356
.....................................................................................
Figure A8.3. Ammonia Road Tanker Loading In Progressat Site A 357
...............
Figure A8.4. Ammonia Bulk StorageTanks at Site A 357
....................................
Figure A8.5. MaintenanceFitter ConnectingFlexible Hoses for Ammonia
Road Tanker Loading at Site B 358
..................................................
Figure A8.6. Operator OpensRoad Tanker Filling Valves To Commence
Ammonia Filling at Site B 358
..........................................................
Figure A8.7. Chiksan Ann and Flexible Hoses Connection at Site B .............. 359
Figure A8.8. Piping Arrangementfrom Road Tanker Loading Bay to
Ammonia Bulk Tanks at Site B 359
.................................................
Table 5.15. Summaryof findings from PIFs analysisat site A and Site B ......... 144
PSMS ProcessSafetyManagementAudit
QRA Quantitative Risk Assessment
RISKAT Risk AssessmentTechnique
SAM SystemAction Management
Introduction
1.2 Background
As Malaysiamovesrapidlytowardsindustrializationtherewill be growing numbersof
large chemicals,petrochemicalsand petroleumprocessingplants known as Major
HazardInstallation(MHI) beingbuilt in the country.This rapid growth unfortunately
will bring about a very significantincreasein the numberof people,including both
workers and membersof the public who will be subjectedto risk from major
accidentsarisingfrom the plantsoperation.Major accidentsof this naturehavetaken
place all over the world suchas at Flixborough,U. K (28 peoplekilled) Bhopal,
India (2000 peoplekilled) andMexico City, Mexico (500 peoplekilled) as mentioned
by Cox (1991). In Malaysiaitself a numberof similarincidentshavealso occurred,
suchas at SungaiBuluh, Selangor (23 peoplekilled) (MHLG 1992) and Perlabuhan
Klang, Selangor(13 killed) (MHLG 1994).
The Department of Occupational Safety and Health (DOSH) of Malaysia which was
formerly known as The Factories and Machinery Department (FMD) of Malaysia is
currently given the responsibility to regulate the operations of IWE in the country
with the overall objective of ensuringan acceptablerisk exposure to workers and the
given to the planning authorities to not allow the plant to be built at the present site,
that would meanthey have to look for a more suitable site, failing which it would not
be allowed to built at all. As for existing installations order will be given to carry out
risk will put human lives and limbs at risk while an overestimates will deprive
investors of suitable locations to locate their plants, resulting in loss of much needed
investment and job opportunities in the country. Balancing both aspects has never
been easy even in industrialized countries in Europe and the U. S. While risk
assessmentresult is only one of the criteria in making the final decision, efforts to
make the technique more accurate and transparentto the decision makers is always
worth pursuing.
style affects the risk from specific plant (Hurst, 1989). In the hardware only
approach of conducting QRA the issue of human factors is only being considered
implicitly, i. e. by assumingthe plant is manned and operated to so-called 'industry
is
standard' which supposedto be monitored by a regulatory body in a particular area.
A PhDThesis
byJ.Basri 2
In reality though the so called 'industry standard' may vary significantly as the
enforcementactivity andproceduresdiffer. Most of the timesit fails to differentiate
the contributionof humanfactorsboth from humanerror and from the management
stylepoint of view.
Hence there exists an immediateneedto consider human factors, i. e. the human error
and the organisational and managementfactors in QRA. Currently there are few
are applicable to developing countries which have different safety cultures is left
unanswered. At the same time human error has been incorporated in fault trees for
worthwhile. Finally, if the contribution of both human error and safety management
in developing countries like Malaysia, it could provide further evidence that the
assumptionthat all MIU is operated and mannedto the so called "industry standard"
is not true. It would also serve as a meansto validate whatever PSMS quantification
is being in different system climate of a developing
technique used, this time a
country.
of the techniques
arenot in the public domainso the proposed has
research to rely on
of between
exists
memorandum understanding thetwo that
parties allowsresearchers
made it possible to use two HSE in-house tools namely RISKAT and PRIMA for
research purposes. Similarly a private consultant that has links with the University
has agreed to allow the use of its proprietary human reliability quantification
The quantification of risk from major hazard installations using generic failure rate
does not explicitly take into account the different performance of Process Safety
Management System(PSMS) which exists at such plants. Since in reality there exist
differences in PSMS performancesbetween major hazard installations especially in
developing countries like Malaysia, such an approach will result inaccurate
quantification of risk of a particular installation. This will lead to inaccurate input
made available to the decision makers (for example on siting issues for land use
planning). More detrimental is the failures to identify weakness in a major
installation's PSMS componentsthat provide major contributions to the overall level
a) To the
compare contributionof site specificPSMS performance on QRA of two
WH in Malaysiathat handled similarly hazardousmaterialbut with significantly
different style of management.
one of the most hazardous activity carried out, i. e. loading and unloading of
hazardousmaterialsat both WH.
process of carrying out a similar hazardous operational activity between the two
humanerror quantificationtechnique.
WH asquantifiedby an established
3. The off-site risk level of WH that has a better PSMS performance is lower as
4. There exist a linkage between site specific PSMS performance and Human Error
Probabilities that could be assessedthrough a same site audit that allowed their
impactto off-site risk to be assessed
together.
aregivenasfollows;
its implementation.Theseassumptions
a) The to the
threetechniquesselected conduct researchnamely PRIMA, SLIM and
RISKAT representprovenandreliabletechniquesthat havebeenadequatelytestedin
a developed i.
country, e. in the U.K.
d) The processsystemsat both WH are quite similar and almost at the samelevel of
technology even though the capacity and manninglevel might differ significantly
.
e) Both MM ammonia loading systemare quite similar and almost at the samelevel
of technology even though the capacityand manninglevel might differ significantly.
0 Both NffU has beenbuilt in the last ten years and has been continuously operated in
the last ten years. This ensuresthat they were not subjected to a nat.ionwide siting
policy that has only beenintroduced lately with regardsto land use planning.
g) Both NEM are not subjectedto changesof ownership for the last three years. This
ensuresa continuous managementstyle that has reacheda maturity stage.
the necessary information and data, and the analysis of data using established
techniques for Process Safety Management System (PSMS), Human Error Analysis
(BEA) and Quantitative Risk Assessment (QRA). The selection of specific
the subject areas will be compared within each site using the sensitivity analysis.
They will also be comparedbetween the two sites to look for evidence or indications
as to how the site specific PSMS performance and Human Error influence the
quantification off-site risk at the two sites. This evidencewill provide some answer
on problem statementsthat provided the foundation of the research.
Chapter I started with the current status of major hazard control in developed
in
countriesespecially Europe is
which currently at the forefront in this area. It then
focusesto the developingcountries,Malaysiain particular where it is just at the
infancystagedespiterapid growth in the production,handlingandutilisationof large
major hazards are then discussed. The issueof usingrisk assessment as a predictive
tool for decision in
makingespecially landuseplanning is then discussed.One of the
of the three siteswas madebased on a numberof criteria that would facilitate the
the sites. For comparing the influenceof human error a similar hazardous
activity
numberof criteria being set the ammonialoading operationto road tanker activity
for As
was selected comparison. only two sitescarry out this activity, comparison
be
will madebetweenthesetwo sites.
audit (Hurst et al, 1996) was selectedto assesssite specific PSMS performance in the
form of a quantitative measurecalled ManagementFactor at the three sites. As for
the human error the SLIM technique (Embrey, 1984) was used. As for the QRA the
RISKAT software (Nusseyet al, 1993) was chosen.
After identifying the sites and selecting appropriate techniques for analysis a field
three major hazard sites in Malaysia. The audits were conducted using a PSMS audit
tool called PRIMA. The audits were carried out to fulfill a number of objectives
which include the suitability and effectivenessof PRIMA, which was developed in
Europe, to be use in developing countries like Malaysia. It is used to assessthe
PSMS on the three major hazard sites and to identify their strengths and weaknesses
as a Modification Factor has been determinedfor each site to modify generic failure
rates for Quantitative Risk Assessment(QRA). In generalPRIMA was found to be a
useful tool to assessthe PSMS at major hazard sites in Malaysia. The structured
questionnaireswere comprehensiveenough to draw out relevant information for a
critical assessmentof the PSMS. This information can be combined with a thorough
site inspection and document verification to obtain a view of the overall situation of
the site's PSMS and can be representedin the form of a control loop. The control
loop enabled the state of the PSMS on each site to be summarised in a simple
diagrammatic form that highlighted its strength and weaknesses. Key areas of
strengths and weaknessesof the PSMS of each site will be briefly discussed. The
study also identified some problems and shortcomingsof PRIMA as an auditing tool
for major hazard sites in developing countries like Malaysia. This included the need
0 to off-site
estimate risk to of
members the public the
surrounding site
managementcontributions
andvessel
o estimating' the frequency (failure rate) of the Top Event which was associated
with major releasesusing fault tree analysis
modifying the generic failure rate vvith site specific ManagementFactors (W) as
obtained from PRRVIAaudits
incorporating key human failure rate in the form of Human Error Probability
(BEP) together with equipmentfailure rate in fault tree analysis
The analytical techniqueused for the analysisincludesFault Tree Analysis using Fault
Tree Manager (AEA, 1994) computer code - for event frequency estimation,
RISKAT Computer Code for QRA which facilitates the calculation for releaserates,
gas dispersion analysis,hazard ranges and fatality probability (Hurst et al, 1989) and
the PRRvIA Audit technique to calculate the Modification Factor for generic failure
rate.
QRA runs using FTA that takes into considerationthe hardwarefailures and
IHEPsshowed a lower off-site risk valueas comparedthosewhich only consider
hardwarefailures.
and HEA
This chapter describedan analysisthat looked into the possibility of integrating PSMS
audit and Human Error Analysis using the PRIMA technique. The analysislooked at
some common attributes that essentialsfor both PSMS Audit and HEA, mainly in the
form of some organisational factors such as procedures, training, stress,
communication and feedback, and hardware factors such as operator/equipment
interfaces, personal protective equipment (PPE) and process safety system. As the
the dedicated PIF analysissuch that has been carried out in Chapter 5. However for
the purpose of quantification using the SLIM technique, such information is adequate
to assistin assigningappropriate weighting of the overall PIFs influence on each site.
Further investigation is neededto look at the existing PRIMA Audit structure to find
The attempt to link the PSMS audit results with IHEPsanalysisfound difficulties as
the audit could only assessthe site specific PIFs at the management(global) level.
As PIFs influenced differently for a different task a global assessmentof PIFs was
found to be inadequate.
Conclusions derived from the study are centered around the main objective of the
is
study that to compare and contrast the managementand human error influence on
off-site risk between the two sites that has a quite different PSMS system and
performance. Finding from the study found that both factors provided signiflcant
influences on off-site risks for the two sites. This finding supports the need to
consider the two factors explicitly when conducting QRA for off-site risk at major
hazard sites. Other conclusion related to the suitability of a number assessment
A PhDThesisbyJ.Basri 15
technique that are primarily developed for usage in the developed countries
performedin a developingcountry environment. The PRIMA techniqueused to
determinethe PSMSperformance,
the SLIM techniqueusedto analyseHumanError
and The RISKAT computercode used to conductthe QRA which were develop
primarilyfor usagein the Europeantheatrewasfoundequally suitableto be usedin a
developingcountrylike Malaysia,albeitwith somemodifications.Finally the attempt
to integratePSMS andBEA auditthroughPIF from the PRIMA audit is only partly
successfulat the globallevelPIFs
Literature Review
2.1 Introduction
Essentially the proposed research is expected to cover three distinct subject areas,
namely PSMS, BEA and QRA, each of which on its own is a very comprehensive
subject. So the literature review will not attempt to discuss each subject in its
entirety, but to highlight the links that exist between them, the gaps that still exist and
the future direction of researchareasas indicated by various researchers.This chapter
mainly provides critical reviews of the current situation which deals with PSMS, BEA
and QRA with the emphasison the incorporation of management
and human error
influencesto risk assessment.Such review aims to set the scenario of the proposed
new Safety
Occupational and HealthAct 1994(DOSH, 1994)which is basedon the
UX Health and SafetyAt Work etc Act (HASEWA) (HSE, 1974) the safety and
healthof workers at work beingregulatedthroughoutthe country. There are many
safety report to the authority, i. e. DOSH before given the approval to operate.
However the Malaysian CIMAH Regulations require the owner of such installations
to consult a competent person or a competent company which is authorised by the
authority in the preparation of the safety case. This requirement is to ensurethat the
owner or the operator of a major hazard installation will be given proper assessment
of their sites by a responsibleexpert, especiallythose run by small time operators.
other countries like the U.K, is direct involvement of the authority in ensuring the
safety at potentially hazardous plant and equipment, such as boilers, reactors,
distillation towers and other pressurevessels. This is being carried out by reviewing
and carrying out annual inspectionson each vessel for 'fitness for purpose'. Such a
to
systemensures a certain extent the integrity of suchvesselson the aspect of design,
fabrication, operation and maintenance. Records showed that such an inspection
However there are other areaswhich are not regulatedin such an explicit manner,
good system will benefit from good PSMS performance while those who have not
not.
A PhD Thesisby J.Basri 18
2.3 The Application of QRA for Major Hazards
Control
The unfortunate events resulting from major hazardsincidents that occurred around
the world have prompted the need for an effective control system. The major
accidentsthat have took place in Saveso,Flixborough, Bhopal and Mexico City, and
Piper Alpha has increasedthe public awarenesswhich in turn have put pressureson
to
various governments provide legislative to
measures prevent such accident from
taking place.
In Europe, the EC Directive (CEC, 1982) provided the basisfor such legislation. The
Directive requires that safety studies of major hazards have to be carried out. In
some European countries like the Netherlands the safety studies must include
quantified risk estimates (Jensen, 1992). Other countries like Germany do not use
the U. K uses tolerability criteria of risk for land planning purposes (HSE, 1989).
They have used QRA in a number of studies involving major hazard sites such as
Canvey Island (HSE, 1978). They also carried out studies on the transportation of
hazardousgoods by rail, road and water that involved QRA (Purdy, 1993). After the
Piper Alpha incident, Safety Casesfor off-shore installations became compulsory in
Norway, The UX and The Netherlands(Jensen,1992). In the U. K. for example the
HSE use quantitative risk estimates to advise the Local Planning Authorities on
planning permission (HSE, 1989). Other European countries like Portugal and
Greece do not specify specific requirementsfor QRA (CEC, 1995).
methodology entails the construction of possible chains of events called 'event tree'
the analysis
3. Hazard Identification: identifying hazardsthat could arise from the system using
5. Selection:selectingsignificantincidentsandidentifyingincidentsoutcome
from
outcomes incidents
all selected to providea measureof risk
For large plant with complex process and technology the execution of QRA
components that has been describedabove becomestedious and time consuming.
Hencethere a needto developcomputerizedmethodsto acceleratethe derivationof
RISKAT (Nusseyet al, 1993)was developedby HSE initially for majortoxic hazards
The procedure which is used by RISKAT to calculate risk from major hazards can be
broken down into a number of steps(Papeand Nussey, 1985);
L Analysis of the major hazard plant, its control and safety system, and
numberof hypotheticalreleases
operationalproceduresso that a representative
with the potential to affect workers and the neighbouringpopulationscan be
identified.
I For each hypothetical releasethe chance that such an event will occur in a
given time period is determined either from historical failure statistics (so-called
generic failure rate data) or by synthesisfrom basic component failure rate data
within a drifting or
cloud plumeof flammablematerialand the likelihood of an
ignition sourcebeingencountered.
v. Thesedispersion,
explosionand flammablecalculationsenablethe spatial and
radiation, extent of fire zone and overpressureof the hazardsto be mapped out.
applying QRA to a specific operation, a specific data base for the study must be
created from new and existing data bases. The types of data bases required include
equipment failure rate, human error, toxicity, ignition, external event, meteorology,
and location specific data of the nearbypopulation (AIChE, 1989). These data could
be obtained from a number of sources such as from existing data banks, from plant
the U. K. the National Centre of System Reliability (NCSR, 1990) is the largest
reliability data bank which contains failure rates for various failure modes, time
dependenciesof failure rate and the predicted effect of preventive maintenance or
For accident and incident data the NIMAS maintained by
condition monitoring.
AEA TechnologyU.K. (previouslySafety and Reliability Directorate) and FACT
countries as they are mostly obtained from developed countries which have different
operating conditions, level of inspection and maintenance, and operator skill and
experience. So ideally a comprehensivecountry specific data base would be the best
sources of data. While the accuracyof the QRA may not be significantly affected for
certain data bases like the failure rate, the effect of not using local weather data could
be severe,for examplefor toxic releases(Marshall et al, 1995).
compliance, as well as for general safety purposes such as land siting and
environmentalimpact statements.The techniquehas been used extensivelyin the
aerospace,electronics,nuclear and chemicalprocess industries to quantify the
likelihood of either a specificincidentof event of a sequenceof event (Cox et al,
1992)
There are a numberof weaknesses in the current approachof QRA. They can be
divided into technicallimitationsand management limitations (AIChE, 1989). The
technicallimitationsis mainly dueto the manysourcesof uncertaintyat all stagesof
the risk assessmentprocess.They include incompleteenumerationof incidents,
improper selectionof incidents,unavailabilityof requireddata, and uncertaintyin
relate human error to PSMS, and PSMS to risk analysis,it would allow more
accurateassessment of risk from a hazardous
plant to be carriedout.
companiesdespite differences
management when carrying out the QRA. It is
The MANAGER audit technique (Pitblado et al, 1990) was the early solution to this
problem and was based on consideration of major causesof accident where system
failure had occurred. It is based on audit questions that have been developed under
major causal categories, experience and data gathered from various sources. The
are covered. The results of applying NUNAGER have produced findings indicating
that PSMS influencescould reducerisk estimatesbasedon generic failure rate data.
The quantitative technique developedby Health and Safety Laboratory of HSE which
hereafter is called PRIMA, is based on an audit system with a demonstrable
statistical and theoretical basisto quantify the quality of PSMS at a plant and link this
into the QRA being carried out (CEC, 1995). The statistical basis is based on an
Model of the effects of PSMS, and the general climate within which it operates on
failure rates. It explores increasingly remote system failures through engineering
PRIMA have been used by HSE Factory Inspectors to audit PSMS and to quantify it
b) Modificationof releaseparameter.
Hurst (1989) described two approachesin modifying the generic failure rate. They
are;
This approach assumesthat the installation is mannedat least to the average standard
that is supposedto be monitored by regulatory agencies.QRA is then carried out on
hardware only using generic failure rate data which incorporates component failure
generic failure rate to the condition found at the plant. Assessors might include an
adjustment to failure rate to allow for some deviation from 'average' of the overall
quality of the safety managementat the installations.
rates.The risk figure is then 'modified' in a formal way on the basisof a site specific
audit to take accountof wider issues.Essentially
this formalizes
the methodof using
engineering judgement. This methodimproves the 'transparency' of QRA by making
the assumptionsin the methodexplicit and thus enablesa broader consistencyof
approachto be adopted. It also allows the cost and benefitsof improvement
to be
of a potentialpreventivemechanism.
While the quantificationof PSMS has been carried out on quite a number of
installationsusing various techniquessuch as PRRvfA and MANAGER, very few
effectivenessof two technically similar major hazard site using MANAGER. The sites
utilities and INRO, that 36% of root causesof incidentsare due to human error.
Even root causescategoriesunder proceduraland equipmentfailures have human
contribution. Hurst (1993),in a studyon causalcontributionof safetymanagement
failures basedon an extensivedatabaseand pipework failure, found out that the
contributionof humanfailuresfrom operationand maintenance
activitiesis between
25% to 30% of the overall causesof failures. The many exampleshas prompted
WatsonandOakes(1988)to concludethat humanreliabilityandits quantificationis a
centralandimportantaspectof reliabilityandrisk assessment.
Sincerisk assessment
is now widely beingusedto assessthe potentialhazardsposed
by NIM, any attemptto evaluatethe contributionof humanerror would increasethe
error which is a direct cause of failure leading to loss of containment, and a safety
managementfailure which may be both an underlying causeof failure or the failure of
a potential preventive mechanism.
According to Watson and Oakes (1988) the ten-n "human error" is used to cover
root causes in the Three Mile Island Incident. Kletz (1985) has also provided
numerous case studies which illustrate the ways which human error at various levels
Bhopal, Chernobyl and Piper Alpha, have showed the importance of managerial and
causesa hazardous stateof the systemor is the direct initiator of a chain of event
which rapidly leadsto the undesirablestate.The latent failures on the other handcan
occur at the level design
of engineering policy.
or management
error is one of the principal determining factors in deciding the level of analysis
required (Kirwan, 1994). If the systemcritically depends on human reliability for safe
operation, and which involves potentially large lossese.g. in term of lives, then a full
reliability assessmentsas being described by Hagen and May (1981). Here human
is
error treated as a factor in systemreliability and needsto be seenas a process itself
Probability data on required task performancewere feed into conventional fault tree
of a human to act
performa presented (or the performanceof a prohibitedact) within
specified limits of accuracy,sequence,or time, which could result in damaged
equipmentand property, or disruptionof scheduledoperation (Hagen and Mays,
1991). While Park (1981) definedit as the probability of error free performance
community in assessingwork place reliability (Cox and Tait, 1991). Norman (1988)
highlights two fundamentalcategoriesof error; slips and mistakes. Slips are results
of automatic and routine action under subconscious control, while mistakes are
results from conscious deliberation. Although a number of cognitive models have
been developed, Rasmussen'sis probably the only model that has achieved wide
spread acceptance(Kirwan, 1994). This approach goes beyond the EEM and look
further at the 'internal' mode of human error which is known as Psychological Error
Mode (PEM). Human error taxonomy basedon this approach has been proposed by
HSE (1989) which comprised of 5 types of human error namely; misperception,
mistake priorities, attentional lapse, mistake action and willfulness, and finally
violation and sabotage.
Reason (1990) extended the SRK framework to form the basis of a generic error
However, concern for the reliability of specific systems (more generally the
3. Cognitive SystemEngineering
4. Sociotechnical Systems
sub-module and human error analysis sub-module. However this technique is quite
new and still not availablein the public domain. As such there is not enough practical
application to show its effectiveness.
the
reducing probabilityof these error. In the areaof risk assessmentthe framework
be
could used to identify a critical task with high risk potentialwhich subsequently
be
could usedas input for QRA.
human interaction with a process system which in the event of error occur could
in
result significant risk. The screeningprocessensurethat all possible sourcesof risk
on a site are identified. Decisions could be made with regard to whether the risks
Detailed Predictive Error Analysis made up Phase 2 of the SPEAR system. The
process evaluates errors that could arise in the subset of tasks that have been
identified by the screeningprocess. The evaluation is carried out in three stages.The
first stage is the Hierarchical Task Analysis (HTA) which describes in detail the
structure of tasks and the plans which determine the order in which the task step is
performed. The secondstageis the Predictive Human Error Analysis (PBEA) where
each of the task stepsidentified in the task analysisis evaluatedfor its error potential.
The last stage of Phase 2 is the ConsequenceAnalysis which specifies possible
consequencesfrom errors that have been identified in term of the severity of the
consequenceand the frequencythat it could happen.
The final phaseof SPEAR is Error ManagementControl Analysis. The first stage of
Phase3 involves the evaluationof the factors which determinethe probability of error
known as PerformanceInfluencing Factors (PIFs). These factors such the quality of
reduction strategies that has been identified are implemented on site and their
is
effectiveness verified over time.
2. Paired Comparison(PC)
the generic IHEP need to be multiplied by the EPC multiplier provided, which will
yield the final IHEP. A set of practical error reduction strategiesare also provided by
the technique.
basedmethodsuseexpertsto generate
As the namesuggestedthe ExpertJudgement
humanprobabilitiesdirectly. It may occur in variousforms, from the single expert
to
assessor, the use of a larger group of individualswho may work together, or
be
whose estimatesmay mathematicalaggregated. one As of such techniques APJ
quantitativeform.
a techniqueof definingpreferences
amongsta set of items, in this casehumanerror
quality of the procedures, time available, quality of the operator interface, etc. It
creates a relative scale representing the likelihood of errors, called the Success
Likelihood Index (SLI). This index can be "calibrated" to generate human error
Roafaat and Abduoni (1987) developedan expert systemon human reliability analysis
is
which modelled on three previously listed techniquesi. e. THERP, SLIM and APJ.
The main intention of developing an expert system in this area was to reduce the
dependenceon the human factors and ergonomic analystjudgement required in the
current method and technique. Although the system was primarily designed for
nuclear and process plant, it can be adapted for other industrial and occupational
situations.
1) Laboratorystudies.
2) Task simulators.
3) Operational observations.
The Work Process Analysis Model (WPAM) (Davoudian et al, 1994), as the name
these tasks. The bottom layer of these organisationalfactors is made up of the plant
specific culture such as organisational culture, ownership, and safety culture. The
organisational factors can influence the quality and efficiency of a given work process
equipment performance.
power plant safety by accounting for the dependenceof these factors introduced
among probabilistic safety assessmentparameters. WPAM framework is geared
towards capturing the common-cause effect of organisational factor on NPP. It
OF
UNVERSITY
SHEFFIELD
The diamond tree is a structured top-down, successoriented tree that can describe a
plant functional hierarchy and its operation. The functional hierarchy shows how the
function of the systeminfluencesand fiilfil a system objective. The development of a
diamond trees involves firstly identifying the plant's principal objective in this case
would be plant safety. Secondly,identifying the plant's function that must be met in
order to achievethat objective. Thesefunctions then will be examinedin detail which
will describe the plant in term of its functional requirement for operation. By
developing the tree further the relationshipsbetween hardware components and the
plant function which they support can be identified and shown in the form of success
tree or successpath. These relationship provide a basisto identify aspectsof the plant
operation which are essentialto safety. The complete tree then will be able to show
the relationships between human activities and hardware performance. This is
achieved by recognising the fact that human actions affecting the hardware
performance and the same affecting the quality of various activities under plant
programme such as maintenance activities. And since the plant programme are
implemented and monitored by the managementsome form of relationship could be
worker's reliabilityandproductivity.
could be calculated. However the need to define measuresof influence and develop
method of estimation is not an easy task. For this purpose the author proposed
converting the entire framework into a digraph representation and measure the
propagating degree of influence through the model using special mathematical rules
such as Mason's rule from Signal Graph Theory.
The strength of the proposed framework is that it uses two separatemodels, i. e. the
diamond trees and the organisation field model. The diamond model depicts a fairly
yield a useful framework that could provide qualitative and quantitative assessment
of organisationalinfluenceson safety.
of influence are not defined and the method for estimation was not mentioned. Only
the method to propagate this influence from basic elements to the higher level of
or completing the task. Traditionally the PSFs being used are those that directly
influence the outcome of specific task such as the quality of training, operating
points as starting point for the subsequentestimation of weight of evidence for other
influencing factors. Lastly the 5 groups of organisational factors used is based on
NPP historical data (incident assessment)which will be significantly different in non-
auditing, monitoring and system design. The influences are in the form of 'many to
many mapping' or 'many to many pattern of influence' that has been described by
other researcher(Davoudian, 1993).
of influences.
In fact the be
model could used to incorporatedirectly the effects of
managementand organisationalvariablesin the quantificationof both human and
hardwarefailures.
to
computerprogramwasused elicit the diagnostic
modelwhich depictsthe modelas
the network
betweeneventsthat arecausallyrelated
(b) Linkages- patternof connections
as opposed to events that causally lead to other events in MACHINE. This in turn
influences the likelihood of events active or latent error of hardware failures. The
Influence Diagram methodology could be used to quantify these influences. And as
these influence links are probabilistic in nature the outcomes could be easily
incorporated into probabilistic risk assessment.
The strength of MACHINE is that the model is supposedto be generic in nature since
it is based on information gathered from analysis of real accident or near-miss
particular error.
which normally involve influencesof low level tasks was not illustrated.
affects the physical systemonly through human decisionsand actions. It uses PRA as
the processesthat affect it. SAM was claimed to offer an analytical approach for
modelling the risk associatedwith a specific system as the structure of human and
application of the technique was illustrated in three case studies of failures of three
diverse systems, i. e. operation and fire risk on-board offshore platforms, the
managementof heat shield of the NASA spaceshuttle orbiter, and the root of patient
risks in anesthesia.Despite the diversity of the system under study some common
traits were found be
which could useful in designing risk managementstrategies for a
complex system.For examplethey found too much emphasisis often put on technical
rather than organisational risk mitigation measures and found that operators are
opinion. Bad decisions may involve errors of reasoning, excessive risk taking, or
unwarranted optimism. Thus organisational errors encompasssome of the classical
human error and other factors, such as communication and incentive problems that
means.
corporate goals), and the reward system Oob appraisal, wage increases, incentives,
etc.). In turn these factors are rooted in the structure, the procedures, and the culture
of an organisation which contributed to safety of the site operation.
They proposed a taxonomy of operator error which can relate the individual decisions
to organisational features such as information and reward systems. The taxonomy
Strengths of this approach are that it looks at errors rooted at organisational level
scheduling to reduce time pressures. Using offshore platforms as case study the
approach was shown to be able to comparedifferent approachesto risk management.
It was also able to highlight the contribution of low-severity error which provides
significant contribution to system failure. This type of error normally hidden by the
which may not follow such global representation.Secondlyon the use of expert
opinionsin the form judgement
of an absolute for all humanerror data. While it is
a plant and link this into the QRA being carried out (Hurst, 1993). The statistical
basis is taken from an analysis of reported incidents involving failure of fixed
control and system climate. This theoretical model is based on authoritative texts on
chemical plant risk management,conventional organization and managementtheory,
and managementof quality and consideration of major accidents and system failures
(Hurst, 1991). The technique has been used by HSE Factory Inspectors to audit
PSMS and to quantify it for QRA of a number chemical plant in the UX It is also
.
being used on a trial basis by a number of European countries under EEC funding
(Hurst et al, 1993)
.
Experience gathered from audit trials in the U.K and other European Countries has
led to further development of the technique, primarily revising the question set and
the judgement for various anchor points (CEC, 1995). The final audit version is then
called PRIMA ( Process RIsk ManagementAudit). PRIMA is an audit tool for the
* Checking/supervision
of operations(OP/CHECK)
The following tools are availableto assistthe auditor in carrying the audit;
eA question set
9 An audit manual
Strengths of PRIMA;
Weaknessesof PRIMA;
smallersitewith simpleprocess
2.11 Conclusions
The literaturereviewhasshownthe emergence
of QRA as a decisionmakingtool for
Major Hazard control in somedevelopedcountries(Pasman,1995) and to certain
extentin few developingcountries(ELO,1992). The contributionof QRA doesnot
lie squarelyon the numberthat they producebut throughthe processitself which is
nuclear industry (Davoudian et al, 1994) while in Europe is more prominent in the
chemical process industries (CEC, 1995). The situation in developing countries is
more or less uncharted for (Basri, 1996), even though this is the place where the
organisational differencesare more pronounceddue to side by side existenceof local
and multinational major hazard sites. Any attempt to address this situation is
consideredtimely as risk reduction effort through organisational changesrequire less
resourceswhich is of major concernin developing countries (ILO, 1992).
Research Methodology
3.1 Introduction
on risk from major accidents of two MFH in Malaysia which handles similarly
hazardous material but with a significant difference in safety management
performance. The comparative study will be carried out using the established
technique of QRA and the PSMS quantification. Further attempts would then be
reserves in the last decade has seen many large petroleum, chemical and
petrochemical plants being built throughout the country. At the sametime small and
medium size downstream industries started to be established. While the large
that exist probably in the form of following the operational and maintenance
procedures and guidelines as laid down by the process hardware suppliers which
mostly come from developedcountries.
Similarly the scenario also offers good opportunity to explore and investigate the
vessels.
vessels. This is carried out by reviewing the design, checking the fabrications,
conducting hydrostatic tests, witnessing commissioning and carrying out annual
inspection on eachvesselfor 'fitness of purpose'. This direct involvement ensuredto
a certain extent the integrity of such in vesselat the design and fabrication stages,and
continue through its operation and maintenancecycle. It will be interesting to find
out whether this sort of arrangement benefits the PSMS of both MFH under
investigation especially in auditing the design integrity and maintenance aspect of
pressuresystems.
Still there are other areasthat are not regulatedthoroughly,yet that could contribute
significantlyto the overallrisk of the installations.The operator'squalificationsand
skill, accidentstatisticsmonitoring system,managementof human error and the
overall systemreliability still much left to the operatorsto implementas long as it
The secondfactor that will be assessed is the humanerror on one of the activities
that it is expectedto providethe highestrisk contributorin the plant operations.This
activity will be identified during the baseline QRA and
assessment supported by
historical data on the plant failures. As this aspect is not adequately or explicitly
system context. In this approach human error will be treated as part of the overall
systemreliability. As one of the factors in systemreliability, human error is expected
to be seen as a process itself rather than of causation-kind effect and recovery. This
error. The is
next step to detennine be
whetherthis error could recovered,and if it
Results from the analysis of PSMS and Human Error on the two MIR will be
that contributed to the outcome of QRA between the two plants. Factors that
provide significant contributions to the plant's QRA then will be scrutinised to look
for effective mean to reduce their impact to the overall risk level on both MHL
Findings from this researchon meansto reduce the off-site risk then could probably
unified approachto assessthe impactof the quality of PSMS andthe stateof human
error in a particularMIR plant througha commonsite audit. The interplaybetween
humanfactors, organisationalstructureand managementis expectedto be clearly
defined,analysedandassessed
in a systematicmanner.
In theory the methods to carry out research of this nature falls under one of the
following categories;
o Expefimental
* Quasi-experimental
* Correlational
* Causal-comparative
o Survey
This research which compared PSMS and Human Error contributions to QRA and
coming up with a method to link assessmentof the two factors basedfrom results and
knowledge gained from conducting the exercisesis expectedto fall under the causal-
comparative category. Under this category specific factors i.e. PSMS and Human
Error will be used to compare and contrast off-site risk associatedwith the operations
will allow valid comparisonsto be made between the two sites. The research design
formulatedfor this researchis givenasfollows;
As the main goal of the researchis to compare and contrast, the proper selection of
MHI is of a paramount importance. Statistical representationis not critical since the
study looked at specific factors i.e. PSMS and Human Error in great details rather
than looking at basic correlation between many samples. The two MHI selected
proposed research
The activity selectedfor Human Error analysisshould be made available at both MEL
It is decided the activity should be a hazardousoperational activity that forms part
and parcel of the plants' normal operation. Operational activity is selected against
it
other plant's activity such as maintenanceand repairs since representsthe highest
* Historical data has shown that such activity is one of the highest contributor
of processplant failures.
techniques such as MORT and CHASE only provide qualitative results while others
as ISRS, MANAGER and PRIMA provide mean to convert qualitative results to
quantitative ones. As the researchis aimed towards QRA it would be necessaryto
select only those techniques that are capable of giving quantitative results. After
conducting thorough evaluations from available literature it was found that the
PRIMA (Hurst et al, 1996) is the most appropriate technique that could fulfill the
managementtheory.
the quantitative part of the technique is basedon a good set of historical data
includehumanfactors
b) QRA Technique
Conducting full QRA on medium size MEI requires a lot of resources and time
two software namely RISKAT developedby HSE (Nussey et al, 1993) and SAFETI
developed by TECHNICA Ltd. (Technica, 1994). Evaluation made based on
available literature showed very little to separatebetween the two. Finally RISKAT
et al 1993)
Some of the techniques such as THERP (Swain and Guttman,1983) and HEART
(Williams, 1986) are in public domain while others like SLIM (Embrey, 1984) and
JHEDI are propriety owned. Selecting one appropriate technique for this research
based upon available literature proved to be quite difficult. Validation exercisesthat
have been conducted by a number of researcherssuch as Humphreys (1988) and
Kirwan (1988) provided some guidelines. Finally the SLIM technique was selected
for use for the following reasons;
the technique to
capable assess Human Error Probability (HEP) at system,
0 fairly accuratetechnique
e maturity - has been in existenceand used for quite sometime in the chemical
process industry
available as computer code that would speed up the analysis and permit
greater degreeof sensitivity analysisto be carried out.
The research procedures are described in the following paragraph. Step by step
description of the proceduresis given as follows;
The first step is to study and analysethe background of MHI in Malaysia. Such an
that governs safety and health aspectsand land siting policy in Malaysia would be
scrutinised. Information by
made available such analysiswould be in
valuable setting
populated area as to
compared another installation.
The Malaysian government policy to attract foreign investment has resulted many
plants for the water treatment. These mixtures of plant's managementstyle, would
affect the safety managementsystem of the plant to certain extent and this could
provide a fertile ground to investigate the 'managementfactor' influence on overall
risk.
Similarly the absenceof any form of curriculum be it at the national or state level for
plant operator's basic theoretical knowledge and skill has resulted in a quite big
difference in terms of the operator's skill operating major hazard installations
eventhough for those using hardware of the same technology. There are instance
where due to the requirement to provide job opportunities to people surrounding a
newly built major hazard installation, the company has to recruit locals who were
mainly with fishing or agricultural skill to operate a highly sophisticated process. In
such situation the local operator will be given an ad-hoc 'crash' training programme
that sometimes involved short attachment with a foreign installation followed by
and how they contributed to humanreliability in each plant or installation. Also how
further training, incentives, safety and quality management on-site contributes to
human reliability especiallyon hazardoustasks or activities.
The second step involving the selectionof two major hazard installations where a full
scaleanalysisof QRA. PSMS audit and Human Error analysiswill be carried out. As
the research does not intend to prove statistical significance but to compare and
Conducting 'baseline' QRA on both installations will serve two purposes. One is to
determine the risk level on both plants using generic failure rate without considering
the impact of PSMS. Second is to determine which activity within the plant that
represent one of the highest risk contributor to the overall plants risk level. This
activity then will be consideredto be subjectedto humanreliability analysis.
The QRA will be conducted using RISKAT software which was developed by HSE.
Necessaryinput for the analysiswould be madeavailablethrough physical inspection,
Necessary steps will be taken to ensurethose input data to RISKAT are compatible
it
since was being developed basically for use in the U. K. Certain input like the
weather data, site-map grid and population density from Malaysia probably need to
be modified to make it compatible with RISKAT. Another factor that needs to be
considered is on various built models that being utilized by the software for
air gas dispersion model utilized by RISKAT is suitable to be used in a humid climate
like in Malaysia.
conducting the is
analysis needed. For this purpose a checklist will be developed to
assumptionsbeing made in the processof carrying out the analysis. In the event of
The PRIMA audit technique utilises formal questions set covering nineteen functions
" Maintenance/Checking(MAINT/CHEC)
" Maintenance/Routine(MAINT/ROUT)
" Operation/Checking(OP/HAZ)
The audit will involve conducting interviews with senior managers, line managers,
sampling technique will be used to look at 'horizontal' and 'vertical' slices of the site's
organisation that ensure that opinion will be obtained from a cross section of
arrangementsand managing the relevant system and procedures. The vertical slice
involved interviewing those individuals in the chain of command who are responsible
for delivery of engineering reliability and operator competence including foreman,
A number of visits to each NMI are expectedto be carried out to complete the audit
process. The availability of subjects for interviews especially the senior managers
make it difficult to really estimate the actual duration of the auditing process.
Similarly looking for the right documents for review will be another factors to be
A Management Factor (MF) obtained from safety management audit from each
installation will be used to modify the generic failures rate. The use of modified failure
rate will be better able to reflect the actual performanceof safety managementsystem
to
as compared using the implicit approach. PRIMA provides the option to use the
audit results to modify generic failure rate used in QRA. This will be done by directly
accidentsand incidents.
This step requires QPLAto be conducted on both installations using modified generic
failure rates that have been determined as in Section 3.6.5 using the same QR-A
assessmenttool RISKAT. Other inputs needed for the analysis such as weather
made will remain the same. This will ensurethat all the other factors remain constant
except the modified generic failure rate is used for analysis. A number of sensitivity
analyseswill be conductedto evaluatethe effect of a number of input parameters
The next step is analysing and comparing results of QRA conducted on both
installations. The QRA results are expected to be in the form of individual risk,
societal risk and some critical hazard ranges. The effect of different management
factor value (MF) between the two installations is expected to be reflected in the
QRA results. This comparison will show how QRA is going to be affected by
This step represents an attempt to investigatethe effect of human error on PSMS and
the overall risk from major hazard installations. To achieve this objective it is
expected to provide a 'snap shot' on the state of human error managementof the
or activities. Concentrating on only one activity will reduce task diversity, differences
to
skill requirement carry out such activity safely and efficiently. It will also make the
investigation and the following analysismore manageablewithin the scope and time
available to conduct the research. Providing common background for the selected
activity for both installations will minimise the influence from other variables that are
not directly related to humanerror.
The next step is to conduct human error assessmenton the selectedactivity using an
Once again close cooperation from the plant's managementis essential, especially
from the operators which carry out the designatedtask. A briefing sessionwill be
This step involves the analysis of results on human error analysis for both
installations. Due to significant differences in areas like operational procedures,
In this step the contribution of humanerror and PSMS and the overall plant risk level
will be investigated. The contribution of two human factors areas in PSMS auditing
namely OP/HF and MAINT/HF will provide a good starting point to investigate a
possible correlation between PSMS and Human error. However the two factors only
representa portion of a complex interaction between the two. While human error has
significant contributions to PSMS it also has direct contribution to QRA on its own.
proposed by Cox (1991) and Embrey (1992). Specific attempts will be made to link
the contribution of human reliability with the site specific PSMS. Results of the
PRIMA audit and Human Error analysis as well as experiencedin conducting both
The final step is looking at the possibility of linking the assessmentof PSMS and
Human Error at a particular site. This representsan initial attempt to follow through
The research involved the application of knowledge from three distinct types of
there have been many attempts to look at it from developed countries' perspectives
(mainly in the nuclear industry) this study is believed the first one to address the
4.1 Introduction
The majority of MH1 in Malaysia were built after the discovery of large quantities of
gas and petroleum in the eighties. They comprise mainly of gas processing plants,
petroleum refineries, petrochemical complexes and some related downstream
chemical plants. These MHI are operated by large companies, either belonging to
multinationals or large national corporations. Having significant experiencein dealing
with hazardous operations these companiesnormally have good PSMS installed on
site. They have proper safety organisations and adequate resources in place to
managethe risk associatedwith the sites'operations(Nanyan, 1987).
However there are also small numbers of MEI which are operated by small
companies, mainly locals. These sites operate simple processes such as chemical
blending operations, bulking and bottling operations of chemicals and petroleum
PRIMA is an audit tool for the assessmentof PSMS performance(Hurst et al, 1996).
The technique was initially developedto incorporate site specific safety management
system quality into quantitative risk assessment.Since then it has undergone further
development including on the audit materials, primarily the question sets and anchor
e Checking/supervisionof construction/installation(CON/CHEC)
* Checking/supervisionof operations(OP/CHEC)
The following tools have been developed for PRIMA which could be used to assist
the auditor in carrying out the audit,
9A question set
o An audit manual
experiences,this study set out to see if it could work in developing countries like
such countries allows analysisto be carried out to compare and contrast the PSMS
management performance between the two. Strengths and weaknesses in the
The auditors were made up of three DOSH Inspectors with Major Hazards auditing
experiencebetween three to eight years. The training was conducted by the author
and lasted for about two weeks. It covered the theoretical aspectsof the technique
and practical aspectsof its application. The theoretical aspectsinclude explaining the
sociotechnical approach used to develop PRIMA and the statistical background that
provided the weightings for the Modification Factor used for the quantification of
PSMS performance. The practical aspectscovered previous experienceconducting
the audit by a number of researchersin the U. K. and Europe (Hurst et al, 1996).
Due to time constraint no specific pilot audit was conducted, however a considerable
time was allocated for practice on the first day of the actual audit at Site A.
The existing audit questionnaireswere found to be quite lengthy and were judged not
suitable to be asked in their entirety in a country where English is not the first
language. It was felt necessaryto simplify the questionnairesby providing keywords
for each question and posing them using simpler sentences.This arrangementhelped
both the auditors and the interviewee to focus quickly on the gist of the questions
using short sentences. For the category of personnel like fitters and operators a
translation to Malay, the local language was found to be necessary. A sample of
keyword for the audit questionnairesis shown in Appendix 1.
The requirementsto conduct the horizontal and vertical slices during the audit meant
space for this purposes a structured answer sheet was developed to facilitate the
process. This arrangement facilitated quick cross references to be made between
responsesfrom various personnelon a particular question and assistedthe judgement
making process. It also allowed each member of the audit team to note down the
answersgiven by an interviewee systematicallyand facilitate the comparison of notes
between team memberswhen makingjudgement on a particular key issue. A sample
Three MIHI sites were selectedfor the audits. Two of the sites handle ammonia for
downstream distribution while the other uses ammonia as feedstock to make
compound fertilizers. The main risk from the three sites is from toxic releases of
ammonia gas. Such similarity provides common background as far as the type of risk
is concerned. This allowed the comparison of PSMS performance to be made on
about 12,000 metric tonnes per year with sales value close to 4 Million Pounds
Sterling. It basically runs ammonia bulking and bottling activities and has been in
operation since 1985. Ammonia is brought into the terminal via low pressure
refrigerated ships from producers and pumped into onshore pressurisedstorage tanks
through a dedicated pipeline running along the berthing jetty. The two 225 metric
tons (MT) capacity storagetanks near the jetty area serve as holding tanks where the
whole load of the ship could be discharged in one go. The ammonia is then
transferred on demand using road tankers to two 125 MT storage tanks at the
bottling plant located about three kilometers from the jetty. At this location the bulk
ammonia is filled into smaller skid tanks, cylinders and dedicated road tankers to be
sent then to customers throughout Malaysia and the neighbouring countfies like
Singapore, Indonesia and Sri Lanka. Customers consist mainly of rubber latex
The bottling and bulking process is fairly straight forward using simple technology
and a high degree of manual operations.The plant was designedand constructed with
minimum automation and process control. There are about twenty process workers
and five office staffs headedby a Plant Manager. The plant operates only during the
day, except for ammonia unloading from the ship which may be carried out at night
depending on the availability of time for berthing at the Tanjung Bruas Port jetty.
The managementstyle adopted by the sites could be describedas typical of a family
10
ol
.C
ii) Site B
Site B was commissionedin 1989 and was part of Site C until the last two years
where major businessrestructuring has turned this plant into a separateprofit centre.
The plant throughput currently standsat 34,000 MT of anhydrousammonia valued at
about 10 Million Pounds Sterling yearly. Unlike Site A, this plant is located within a
port areawhere bulk ammoniacould be pumped straight from reffigerated ship tanker
via dedicated pipeline straight to the plant's four pressurisedstorage tanks each with
125 MIT capacity. Sixty percent of the ammoniais sent via pressurisedrail tankers to
Site C located about 30 krn away where it is used as feedstock for compound
fertilisers. The rest of the ammonia is sold to customersin anhydrous form through
road tankers and cylinders. A small amount is turned into ammonia solution and sold
in drums or small containers. The customersare mainly rubber latex producers, food
ship unloadingand rail tanker loadingof ammoniawhile cylinders bottling and road
tankerloadingis only carried out on day shift. The managementinheritedthe style
from the multinational company especially for the PSMS. The management
iii) Site C
a local management buy out, where the majority of the equity is held by former
September 1966 as the first compound fertiliser plant in Malaysia that used the ICI
process technology at that time. Now the plant is fully managed by locals but still
t
cts
tf)
C14
tI,
CA
m
C rA (L) 00
-
4C
Cd ed
(U cis
to Ic:
ed 0 4) (A U,
*4= I-
cd crj 0
cd
ce 2 Z) V
Cd
cd
Ln C
I
-1 CA
1-
m
cqs (A t2.
0
CA
6.
C02
U.
u 0
W cis
to
e:l o
to
.0
4-
CO r. co
rN
CO
co
r.
cqs
04E-u (U
0
.ý
-t rA
4-
Cd
r_
cis
Cd
()
>1
cd
un
.0
0
4ý
U, tz:
; L4 -C
follows very closely the safety management style inherited from the previous
multinational owner. The works currently consistsof the following plants on its site;
The operation of each plant is headedby a Plant Manager supported by the so called
Ammonia that is used as feedstock for the nitric acid plant is supplied by its sister
company Site B at Port Mang by pressurisedrail tanker each with 50 NIT capacity.
The liquid ammonia is then stored in a pressurised600 Nff sphere which is semi-
reffigerated. The nitric acid is then converted into ammonium nitrate which is then
to
mixed with other compounds make the fertilisers. The fertiliser plant uses almost
20 years old ICI technology but the level of automation and process control is
The three NflU sites selectedare registeredwork placesunder the OSHA, and DOSH
have kept records of each site which includes hazardous inventory, process layout,
critical vessels and piping diagram, accident records, up to date safety and health
A PhDThesisbyJ.Basri 84
familiarisation.This did shortenthe time requiredfor the actualsite familiarisation.So
more time could be spent on the interview, task observation and assessingprocedures
This briefing was to explain to the managementthe purposes and objective of the
action. This was essentialas the audit team consisted of enforcement officers from
DOSH. The site managementwas askedto give a short briefing on the current PSMS
organisation and issues,and activities carried out at the site. This was to ensure that
the audit would take into considerationthe latest site situation. The managementand
In essencethe briefing was trying to convince the managementand workers that the
site PSMS. This briefing also provided essentialsafety and security arrangements that
to
needed be adheredto by the auditteam.
The interview was conducted using the PRRAA questionnaires set which has been
improved to facilitate the process in view of the local situation as mentioned in
requirements.
As it would not be practical to interview all workers, only a number of them were
selectedfor interview. The selectionis madebasedon the site work organisation and
was made as such to representthe so called 'horizontal slice' and 'vertical slice' of the
organisation as suggested by PRIMA audit manual. The horizontal slice involved
carrying out formal interviews with managerswho have influence and duties in the
areas of forming and implementing policy in relation to the activities under scrutiny
for example establishing organisational arrangements and managing the relevant
systems and procedures. For the vertical slice individuals in the chain of command
For the vertical slice the same sets of questions were asked to the shift manager,
which neededto be in
analysed detail. As the
an example shift manager feels very
but
strongly the need to adherestrictly to operatingprocedures, the shop floor
carrying out the operations. This vertical slice approach was able to highlight
conflictswithin a in
department trying to to
adhere the PSMSinstalledon site.
personnel who are responsible in the areas of forming and implementing policy in
different departments. For example questions on the implementation of permit to
to
maintenancecrew check certain operational equipment, the answersobtained from
the two managerswere able to highlight whether there existed conflicts in the use of
work permit system between the two departments.This horizontal slice approach is
represented the best representation of each site's PSMS. At the top of the site
management hierarchy the Managing Director or the Works Manager was
interviewed. The vertical slice is made up of personnel from the Operation
Department becauseit has the largest hierarchy on site and they performed critical
tasks that were judged would give significant impact on off-site risk. For the
horizontal slice purpose personnel from other department such as the Maintenance,
the Technical Services and Safety personnel were interviewed depending on the
the site's PSMS. This includes safety policy and organisation, operating procedures,
Site inspection carried out differed from site familiarisation in terms of details. For
safety systems installed and personal protective equipment provided on site were
inspected in detail. Observation of critical tasks carried out on site also included
ammonia to road tanker. The time required to complete a critical task gave some
indication of time pressureto carry out the task given the production target set by the
revealedwhat actuallyhappened
on the A
ground. certaindegreeof biaswas detected
for exampledue to operatorconsciousness when work under observation. Audit
Culminating the PRIMA audit exercise was making judgement on the site PSMS
performance. Judgementswere made basedon the information gathered from all the
steps described above. The judgement formed for each key audit area is translated
into PRIMA managementcontrol loops. For this purpose the audit team had to sit
down together shifting through answers from questionnaires, refer to related
documents, recall site observations and inspections' findings. At all times the
process had to refer to the various anchor points that made up the PRIMA audit
control loop as shown in Figure 4.4. Our experience shown that this is the most
difficult part of the audit and adequatetime needsto be set aside. Sometimesfurther
audit manual, the ideal model of a PSMS control loop and the definition of anchor
points provided as shown in Figure 4.5, a reasonablejudgement was reachedbetween
the audit team members. Managementcontrol loops for each key audit areas were
drawn up at the end of this judgement making exercise.
This post audit briefing is aimed to let the managementand worker representatives
know the results of the PRIMA audit. The briefing was broad in nature and mainly
outlined the key strengths and weaknessesof the PSMS. The managementcontrol
loops of the eight audit key areas were shown and explained to them. Some
suggestionsfor improvement were given. Great care had to be taken in making the
presentation as not to create issues that could be exploited by other parties to
jeopardise the site's industrial relations.
Lavrl 2
3 -* 2
c=pew, m of
pýMXUA
2-0-3
I Auo=ant o
ol!l'CT'ie*3cm-=frc6'
(training, offodivwe"
imoemontcdion
pracedums, Le-,
-J 3
A 3
SettingofýVcs LayelA Rayisionof
standards,g4
)d V es -t: -:-.
'.
polides,an 8 pnonfies,oqlcn,
SITE
--- ---------------- SYSTEM
5 CUMATE
Regulafions,
,r2uiclance,
ustry norin
u
acmomics an
resource fodors
1. GOOD
2. AVERAGE
by the diagram
9 On the wholethe PSMSis represented
9 Someevidenceof weaknesses
within the systemcomponents
or links
3. POOR
The time neededto conduct the PRIMA audit for each site varies primarily due to the
size of site under review. However from our experiencethe learning curve from the
first site audit will cut short the time required to do the next audit. This was especially
true when the audit team is relatively new to the technique. A summary of the
duration taken to carry out various stagesof the audit activities for each site are given
in Table 4.1.
Discussion on PREVIA audits results for the 3 sites are made based on the PSMS
control loops constructed from the audit team judgement for the eight key audit
areas. In making the judgement, findings from the audit team members were
discussedand summarised for eachkey audit area, as samplesshown in Appendix 2.
Detailed discussionof the results are given as follows;
The PRIMA management control loops of all key audit areasfor the three sitesare
shown in Figure4.6 to Figure4.8. The constructionof the control loops for the three
siteswere made based on PRIMA PSMS Anchoring Control Loop shown in Figure
4.4 and the definition of anchorpoints for control loop as shown in Figure 4.5.
These diagrammaticalpresentationsare madeof boxes and arrows that show the
linkages. The existenceof boxes meansthat there is evidencethat the PSMS
regularlybeing used.A thin arrow line indicatesa weak link, i. e. that they are only
occasionally being used. The advantage of representing the state of PSMS
lit-INiAN FACTORS OF I
HAZARD REVIEW OF MAINTENANCE - I'm
DESIGN - Poor
I:
[1II
II
II
[HAZARD REVIEW OF
CHECKING AND SUPERVISION
OF OPERATIONS -A verage I OPERATIONS - Poor
KEY t
Lim
Weak link-present
HAZARD REVIEWOF
HUMAN FACTORS OF
DESIGN - Average
I%IAINI'I-'N..
XNCF -. -Iverage
II
1.1
I.
CHECKING AND SUPERVISION I ROUTINE INSPECTION AND
OF MAINTENANCE - Avffage MAINTENANCE -. 4verage
ýHAZARD ---7--l
REVIEW OF
CHECKING AND SUPERVISION
OF OPERATIONS - AveraRe OPERATIONS - Average
0
1.
KEY t
Link, prewnt
Weak link prewnt
KEY t
Link present
Weak link prm-nt
The summary of PRIMA audit results on eight key audit areas for all the sites is
shown in Table 4.2. The rating Poor, Average and Good in PRIMA audit rating were
assessedfrom the definition of anchor points for control loops as shown in Figure
4.2. PRRAA audit derived these ratings were from statistical analysis of loss of
containment incidents (Hurst, 1994). The rating Poor in a simple term meansthat
they are below the industrial average,Average meansabout equal to the industrial
average while Good means they are better than the industrial average. Closer
examinations show that Site A fared the worst among the three sites, i. e. with
highest number of key audit areasrated Poor.
components.
i) Site A
ii) Site B
Even though Site A and Site B carry out a similar processi.e. handlingof bulk
iii) Site C
The best amongthe three sites,noneof Site C key audit areaswere rated poor. In
fact two areasi.e. DES/HAZ and MAINT/ROUT were rated good while the rest
ratedas average.This sitewas built andrun by a well-knownEuropeanmultinational
for
chemicalcompany nearly twenty-five years. Even thoughit hasbeenbought by a
local companyrecentlythe new owner has retainedthe PSMS laid down by the
potential problemsthat could degradethe PSMS in the near future that includes
downsizingof the workforce that will reducethe numberof experiencedoperators
By examiningthe PRD4A audit resultsof the three sites the following comparisons
could be made;
e Site B and Site C hadbenefitedfrom good PSMS laid down by the previous
multinationalowner.
o Lack of written PSMS document is the most glaring difference between Site
A and Site C. The strong emphasison written documentationby PREAA audit
makethe differencemoreobvious
9 Weaknesses
in communicationand feedback(level 3) were apparentat all
sites,reinforcingthe needfor better communicationwithin the organisation.
This area was found to be a low priority in each site PSMS as it needs
adequateresourcesto implementwith low immediatereturnsas comparedto
productionimprovements.
Ratings made on judgement of various key audit areas at each site provides a
quantitativeoutput calledPRIMA ModificationFactor. The factor can be used to
calculatea failure rate which explicitly includesthe assessed PSMS performance. A
summaryof ratings judged for various key audit areasfor the three sitesis shownin
Table4.2.
These qualitative ratings made during PRIMA audit are converted into a quantitative
scaleusing findings from statistical analysisof a failure rate data databasethat covers
some vessels and pipes (Hurst et al, 1994). The failure rate data is found to be
where;
LogfailGiS the(-loglo)unmodifiedgenericfailurerate
is
A samplecalculation shown in Table 4.3. The to
calculation referred rating for key
audit areas for Site A as given in Table 4.2 and their associatedweighted based on
Substituting values of a(i) and x(i) from Table 4.3 into equation (1);
i-8
Logfail sms= LogfailG+ a(i)x(i) equation(1)
.........
4xlO'7 /m /yea
Altematively;
Assume a generic pipework guillotine failure rate (Logfail sms)of IxlO*7 /m /year
Then the corrected failure rate (LogfailG) becomes;
Modified failurerate= genericfailureratexW
= IxIO'7x4
0-7 /m /year
= 4xl
of loss of containment data base as shown in Table 4.4. They show a difference of
about a factor of ten between the worst site, i.e. Site A and the best site, i.e. Site C.
This emphasisesthe need to consider site specific PSMS performance when carrying
Data basefor
weighting Site A Site B Site C
Throughout the whole audit exercisewe have identified a number of strengths and
4.7.1 Strengths
The technique was developed basedon sound theoretical and statistical basis.
4o
However the loss of containmentdata baseneedsupdating.
questionnaires could be used for other purposes for example to carry out
human error analysis.
4.7.2 Shortcomings
e The questionnaires
do not addressexplicitlythe aspectof on-siteand off-site
emergencyresponseplanswhich are crucial for major hazard sites PSMS.
* The time required to complete the whole audit exerciseis quite long i. e. from
14 days for a smallestsite (Site A) to 17 days for the largest site (Site
Based on the experiencein conducting PRRVIAaudit at the three sites the following
e There is to
a need updatethe database
usedto detenninethe weightsusedto
calculate the PRIMA Modification Factors. ideally it should base on quite a
largedatabaseof lossof containmentfrom developingcountriesto reflect the
design,construction,operationandmaintenance
standardsof suchcountries.
needto be streamlined.
result that takes into account a site specificPSMS quality will greatly assistthe
decisionmakingprocess,for examplefor land-useplanningto ensurethe safety of
5.1 Introduction
Controllingthe risk from major hazardsitesrequiresthe assessment
of potentialrisk
from the sites using a suitableapproachsuch the QuantitativeRisk Assessment
will identify, evaluateandquantifyrisks associatedwith
(QRA). Suchan assessment
the siteoperationfrom possiblefailuresof the planthardwaresuchas processvessels
and piping. Of late the assessmenthas been extended to 'software' failures that
includehuman,management failures
and organisational. (Tweeddle, 1992). This is
dueto the fact that humanerror contributesto the high percentagecausesof failures
process
at chemical plants (HSE, 1989). The analysisof humanerror will provide a
betterdescriptionof the humancontributionto risk andidentifywaysto reducethem
(Gertman,1994).
Theselection
of ammonia bulkterminals
for the studywasmadebasedon two main
reasons.Firstly, the risk from majortoxic is
gas releasesuchas ammonia time
dependentandcouldreachwiderpopulationthatmakesit a criticalinputin landused
Secondly
planning. ammoniais usedverywidelyin therubberandfertiliserindustries
in Malaysia.Also ammonia
bulkingactivitiesin Malaysiais currentlybeingcarried
out by bothbig multinational local
andsmall operators the
usingabout samelevelof
hardwaretechnology.The last reasonprovidesa uniquescenarioto exploreand
the
compare influences
of management on humanerror.
andorganisational
i) Site A
The plant was built loosely based on Japanesetechnology but most of the critical
vessels e.g. storage tanks and piping system were fabricated locally. It is totally
the company and responsiblefor the overall control of the company. As he also runs
a number of other companiesthe day to day running of the plant is carried out by the
Plant Manager. During the audit period the Plant Manager had just resigned so his
byJ.Basri
A PhDThesis 109
responsibility was taken by the existing plant engineerwho will eventually take over
the vacantpost.
There are three main work sectionsat the sites,divided by the types of work that
eachcarriesout. The operationsectioncarriesout the ammonialoadingfrom andto
the road tanker, filling of ammoniacylindersand skid tanks and filling the liquid
ammonia solution (aqueous ammonia) into plastic containers and drums. The
maintenancesection carries out inspectionson the integrity of oncoming empty
cylinders,drums, skid tanks and their fittings
associated to ensurethat they are in
good condition for filling. They are also carry out scheduled and breakdown
The workforce of this plant mainlyconsistsof ablemenin their late twenties. They
Site B is another bulking terminal with an annual throughput of about 34,000 MT.
The plant was commissionedin 1989 and served mainly as an import terminal for a
large compound fertiliser plant located about 30 km inland. Liquid ammonia is
discharged through dedicated pipeline straight from the ship tanker to the site's four
storage tanks each with 125 MT capacity. Sixty percent of this load is immediately
transferred to the fertiliser plant using pressurised rail tankers. The remaining
ammonia is stored on-site and filled into road tankers, skid tanks and cylinders for
downstream distribution. A small amount of ammonia is turned into ammonia
The plant was designed, built and run by a European multinational until a local
managementbuy out about two years ago. The process is basically similar to Site A
and uses about the samelevel of technology. The difference mainly lies on the level
of processautomation and capacitywhich is slightly higher than Site B.
of the Plant Manager. He has the overall responsibilityon the site personnel,
production,safetyand administration.He is authorisedto spenda certainamountof
moneyfor the but
site expenditure needsapprovalof the Works Manageron works
that involvelargesumsof moneysuchas majorrepairs,modiricationsor replacement
of systemof equipmentwhich require large capital outlay. The Works Manager
the
oversees site throughfortnightlyvisitsand reports postedto him everyweek.
Training for new workers is conducted through the on the job method where they
learn through observation and hands-on involvement under the supervision of
experiencedworkers and supervisors. For new workers and outside contractors there
are compulsory safety and emergencytraining. The basic training lasted about six
months. The plant manager and supervisor assesswhether they are ready to do
A PhDThesisbyJ.Basri III
certainjobs throughobservationsandinterview. After the basictraining the workers
are assignedto specifictask i.e. operations,maintenanceor servicesthat becomes
their long term careerwith the company. While this approachpromotesworker
specialisationit wasfoundthat it alsocreateddiscontentamongthem. Over the year
workers from the operationsdepartmenti.e. the operator have a better chanceof
counterparts.They could rise to the post
promotionascomparedto their maintenance
of Shift Managerwhile the maintenance
could only moveup to fill few maintenance
supervisor posts. The low turnover of workers aggravatesthe situation. Post
employmenttraining is only given to those ranking as supervisorsand on courses
mainlyrelatedto qualityandproductivity andoccasionallyon healthandsafety.
analysis depend on the objectives of conducting such analysis. For the purposes of
this researchthe qualitative humanerror analysishave involved the following;
9 Selectionof hazardoustasks
" PerformanceInfluencingFactorAnalysis(PIF)
" Consequences
Analysis
involvement
9 high degreeof humanfoperator
9 regularlyconducted
There are a number of separateactivities that are carried out at both sites that could
result in the release of ammonia. These included bottling operation, ship unloading
operations, rail tanker loading operation, and, road tanker loading and unloading
operation. However for comparison purposesonly one activity needsto be selected
for the Human Error Analysis. The method used for the selection is SPEAR the
to
processwhich could yield significant sourcesof fisk if errors take place. A detailed
all sources of risk on the plant and to reduce the amount of effort In applying other
techniques by focusing on risks arising from operator involvement. The site visit
are:
Thesethreefactorswere assessed
using a seriesof to
questions produce an index in
The result of PREI calculations for main activities at Site A is shown in Table 5.2.
The ammonia loading activity to road tanker is ranked first with a PREI value of 0.88,
followed closely second by the activity of filling ammonia into cylinders and drums
with a PREI value of 0.81. The result of PREI calculations for main activities at Site
B is shown in Table 5.3. The ammonia loading activity to road tanker is ranked first
with a PREI value of 0.81. The calculations showed that the ammonia loading
activity is with the highest PREI, suggesting that detailed analysis of the activity
should be given the top priority. The use of the PREI was found to be useful in
selecting critical activity that has high risk exposure to human error. The alternative
approach like in the Dow Index looking at the potential risk solely from process point
particular activity.
Discussionwith the management and operators at the two sites also indicated this
is
operation quite critical and could lead to major release. In fact there has been
major releaseat Site A during the loading operations of a lorry mounted tanker
(FMD, 1992). In this incidentabout I metric ton of ammoniaescapedfrom a skid
tank during filling operationdue to burstingof filling hose. The resultingammonia
travelled downwind more than a kilometreinjuring about forty people living in the
surroundingareas.
C
00 - e'1
00 00 *(
r-_, 7ý
r-
*(A
11
Pro
CA
I I 1
C; c; C5
I'
C5
C14
---
C
r.
-0
CO
C-i
W)
cr
4)
0
E- 9) öü -m r. 10
. +ý
Co
F--4 "o
CA C
C) 0ce E
+,
cn-
10 W
E 2)
9 r_ +-
u -0
Z r-
cu x m
Gn
Co
ýx öü GA rA cn
.a ce 4.
tý Zu im
.0
't ceCU
0
Z
cr
=
>%m
9)
<
>
-
L.
+
loý v cN 00
0
1 441 11111
Ei
r-
"I I
.4 Pro
Oý clý
0
00 "a 0.4
cd
CD CD
ll-ý
U. 0
Cd C
r. r_ Ici
Ici E Gn E en
(A -a u ý2 2 r_ fi
oý
Z W_ý il; :1 -0 ce
-0
= Cd
1-.
u r. 'ö
r. 4) g
r- w-i
4) Z$ 9)
-ci 0
9) Ici ý2 .0
= u
22
,e
u
Analysis of historical data on loss of containmentof hazardousmaterials by a number
of researchersalso indicated that the loading operations of road tanker represent one
of the main causesof loss of containment(HSE, 1989 and Embrey et al, 1994).
Using the SPEAR screeningmethod the road tanker filling operation at both sites was
found to be the activity where the risk is heavily influenced by human error. This is
further supported by judgement made by the auditor based on information gathered
and accident records on each site and findings from other studies that has been
mentioned above.
necessarydocument.
Even though Site B was designedand equippedwith Chiksanhard loading arm for
top loadingit could not be usedas intendeddueto the differentconfigurationof the
current road tanker valve inlet that is for
designed bottom loading. So additional
the bottom
flexible hoseshadto be fixed to the endof Chiksanarm to accommodate
loading.
HTA representsa wide approachto task analysiswhere the analyst needsto establish
the sequenceof various subtasksto be carried out to meet a system'sgoal. For this
operatingprocedures.
would reduce the amount of analysisneededto addresshuman error that posed little
significance to off-site risk from the operation. For this purpose the SPEAR
screening process was applied again to identify the critical tasks that involve human
error that could lead to the releasesof a large amount of ammonia.
Results of the second screeninganalysison tasks that made up the ammonia loading
activity is shown in Table 5.5 for Site A. The analysisidentified the task of filling the
ammonia road tanker with a PREI ranking of 0.88 as most critical in terms of the
contribution of human error to off-site risk from ammonialoading operations. This is
followed by the task of disconnectingroad tanker from plant with a PREI ranking of
0.83. The task of connecting road tanker is third with a PREI ranking of 0.59.
These three tasks will be subjectedto detailedPIHEA analysisas they are subjectedto
high degree of human error that could result in major releasesof ammonia at Site A.
Results of the second screeninganalysison tasks that made up the ammonia loading
is
activity shown in Table 5.6 for Site B. The analysisidentified the task of filling the
ammonia road tanker and disconnectingtanker from plant, both with a PREI ranking
of 0.79 as the most critical in terms of the contribution of human error to off-site risk
from ammonia loading operations. This is followed by the task of preparing the road
tanker from plant with a PREI ranking of 0.55. Similarly only these three tasks will
be subjectedto detailedPHEA analysisasthey are subjectedto high degreeof human
in at
of ammonia
error which could result majorreleases SiteB.
Details of HTA conducted for Site A and Site B is shown in Appendix 4. The
tn +
0T
-t
tn tn 00 00
>-ý -0
'I'll
10
Oý1-1
-1-1-1 -1 "0 0
Ln
N
0
10. > Cq cq ýo ol
0-0
6 C; 60C;
llýl
ID
--
000
(A
11
rA
ce
>
(A CA
*Gn
-0
ce
e 0
Gn
CZ
0
Ci. m. 2p *a 0
eq
eq
P-4
1r41-I Wý
I-
Iw ,It
(A N ON t- ON t-
(. 0 r-
ri)
0
10 ", 1
ei Ilý1e1Ilý1
CD (D CD 0 CD
c71
1.2 "
l'
ssss o t'
.2 odó
0
rA C14
(::5
r_ m 0
ce 0
r4
4ý pý 'Z u 40) vý Ln
ce
r_ , P-
ýTZ2ý
CD.. Z.
The road tanker ammonia loading bay is not fitted with a weighbridge. Hence the
loading bay cannot be fitted with weight trip system and the operator has to rely on
observing the road tanker content gauge to ensurethe tanker is not being overfilled.
This situation could easily lead to human error as the operator may not be around
throughout the filling duration.
The HTA results are also used to highlight major differences on the task loading of
ammonia to road tanker between the two sites through its structured step by step
format. Discussion of the differencesbetween the two sites and how they influences
human error on each site is presentedin Table 5.7.
0
0
w -ige0
ei)
1
-83 ý: j 0 ý:IU, -.
i. AA ý 0
Z
0, ýM:
cn 09
20
to
2ý,
la cn u lu Z
0 c2. .
§ cn JE -2 r2 -,3 c-.e 0Zg -
co. Z ýý08
A . >
5ý
C) cn
-ci
lu
:i
0
'j Ei -2
E9 to 5 0W
9.0
0
9 +ý
+ý E 48 e
= ..
rA ce
'CJ :5 9)
0 4- - 8 jz
0. 15
. A050
0 r.
U e8o0
A-- s2 )g
-0
Gn
0
0
-2
78 *:, g Ei ý L, "g 8.
Z
0
lý tz
L) -Z -ý =0
C2.u- 0, Ei .
4)
5 '
-cs 0>>,
;e 9 -;e -w =0 4ý '0 0
rA , :g > * Q)
E Z-0 .'A Q)
li
0.8l
r. ..
cn
Z 0 0' 12 Cli
r_ eägr. -
Z. 2
"
U n
2 iß 0
r, - s rn 0
cj - :-
m 75 0 -2O
>
=0
,. 9. 0
M0
r-L Gn
0
Z:
0
cn
0 on
+ý 0 1-. to-
. im
9.1
0 ce 82
5
0
15
c2. 0 -CJ
-9
0 :i
A c)
ýg
.-
Gn
0
9
.
2:1
to -2
ýs: cn '5 t2
t. 8ý
14
. 0e ä9 -5 *E
cu
0
M 00U
'; 00 0 ,5l?
cli t. 'U.
Le 0
0
ce Gn
f5
1 g 0 2,
0 0
'9
c2
.
e%
0l ;
0»
li
;3 nö
0 8
Gn 0 ie Z 0
to
0 9.1
0 19n)
> u2
4)
c03 0 0
-
1-13
ýCO: >% Gn
2
.m. -ýI
8 co,2 "r=
1.
) 9
0
to 2 u CJ U9 -ý tý -2
2 U==0 0
ce
1
t) ce
ci , ý . 0 ý IZ
g)
0
4: n-
1
u
(D E00
= 2
4 >i
14c2.0
ri--
F- Z?.
E-
.
-0
:1
4= r.
0Q0 .- 0E <-
8 1
0ä? >if 92. 0>0
0 -:S
týZ 9
>
ýä
IU- = o
.43 c2..
gt 4;z
:2 .E
=3
esZ8
-ri -C9
;rn =9
14-- -ci
to >
r-
a -
u
il E>s
:j-
KZ..=a.
- -
..
c42 ýq 2
8
Z
..
v
=,
-5
p.
Ei ÖD
c2.2
ý '0 ý--G--
0-
0
cetz
rz
r cn
2 ZO:2= 8
2=ý
m .500
2
0
In En 0 =0
A. 0
cu 0 -2
ý ,2,2'.
.5 tn b
1
"ý
to .J-3
e 0---a
--2
1
4 1 8.,
-(L) , u
-u . ,
-
rA +ý 91-0
28A U-.
m,0-0 +5 . LD 0
& 1--i 31s <UJ
ý: .42 ,-0- E
i rz -e O>
*25- - A 0
. -
.2ga)0 E
.E-. , >
>
20 0
0r IK
to 0
0e
g) (4-4
)
ig.
914 Ei $Z. 0
4)
0 0 2 * 0
-bd U) q-
ch lUl ý0 -0W
8 c2.r. -Ei-
.2> .82 = "ID E9
W
iß E5
, . -
""
e 0
0 e 1,
- -5,
> ý)-- ic> E u2 0
.2 12 Z
. rA
>b
ID
0
e 5 E
0 -cs 0 -g-o
0 .15
Z.
e ZJ
0 r,-, :i*
0 ;3
90 9Z8
_ý g2.Ici tu m r. ý e. , ö. 8.
E 1- 1. >
0 0
01
141)
00
0 0
to - 0
0.
+ý 0=
j1
0: 0 -ci
.4-ce 'U 'E 2
"8 0
to .2. se lu
9
*r. 0 200 C)
cz
5 .
ý. -8 c2. -4- LIJ +-
to
e
-2
=
. "e
t. 4 Ici
ul
.5 ce
9.9
; EI 0
2
1
"ti 0 >o li Cl.
8,4 1
0 CL
g-
c 08
8. e
0 .a
Ir.
in
PA
Table 5.8 - EEM Category used for PHEA
The consequencesanalysis was then carried out on human error that has been
identified. In this analysisthe consequencesof all predicted errors were considered.
This reduced the chance of discounting certain errors from quantitative analysis
before considering its consequences.Errors with low probability of manifestation but
active failures and latent failures. The one that has immediate consequencesto
is
personnel, plant or process called active failure. While latent failures are those
actions or decisionsthat generatevulnerableconditions which, in combination of with
subsequentoperating errors or operational conditions, give rise to accidents.
Two types of ratings were included in the consequencesanalysis. The first rating was
for the severity of the consequences,while the second is for the likelihood that the
casesthe rating usesthe classificationof 'high', 'medium', and 'low'. The consequences
Uonsequences
Detailed PHEA for the two sites is shown in Appendix 5. The results identified a set
of critical tasks that are heavily influencedby human error. These critical tasks were
5.11 and Table 5.12 respectively. The judgement high, medium and low were made
Table 5.11 Critical tasks that are strongly influencedby human error
at Site A as identified through PHEA.
could lead to major releasesof ammoniaon Site A. The errors consisted of two types
of error i. e. planning error and operation error.
The planning errors identified through the PBEA at Site A include two critical
planning errors. First is the planning error where the incorrect plan executed. The
correct plan requires the weight of ammoniaremainingin the incoming road tanker to
be established before filling. This is to ensure that the tanker will not be filled
exceeding the permissible ullage level based on the tanker volumetric capacity that
could lead to catastrophic failure of the tanker. Such a failure would result in large
releasesof ammonia with high severity high off-site risk. As the existing procedures
to establish the tanker empty weight at Sight A is poor, the frequency of such error
to taking place is expectedto be high.
severityoff-site risk.
There are a number of operation errors that have been identified through the PIHEA.
Under this category of error there are several tasks that were found to be under
strong influence of human error. The EEM error types are mainly under action error
i. e. action omitted. The tasks that have been identified using the consequences
(frequencyand severity)includeddriving the road tanker, putting chocks to road
tankerwheels,establishingthe permissibleammoniafilling weight, wearingPPE and
connectingand disconnecting
flexible loading hoses to road tanker. The tasks
selected were judged to have at least one of the i.
consequence component, e.
frequency or severity, in high category.
The planning errors identified through the PHEA at Site B included two critical
planningerrors. First is the planningerror whereincorrectplan executed. The plan
for ammonialoadingto road tankerrequiresthe incomingtanker emptyweight to be
determinedin order to check for remainingammoniainside before filling. This is
important especiallysince Site A uses the contractor or customer tankers for
downstreamdistribution. If this stepof the loadingplan is omitted, eithervoluntary
The PIHEA also identified a number of critical operation errors that could be
in
committed carrying out the road tanker loading operations at Site B. Similarly the
consequence'scriteria based on frequency and severity was used to identify tasks that
are strongly influenced by human error. Tasks that has been identified included
establishing road tanker empty weight, deduce the correct filling weight, connecting
and disconnecting road tanker to plant, putting wheel chocks to prevent hose pull
the
awayand wearingof PPEfor the drivers
operators, crew.
andmaintenance
made up of frequency and severity, tasks that are under strong influence of human
error could be identified. The consequences
approach was found to be appropriate
for the research as the study is looking at major releases of ammonia with high
consequencesthat could give rise to off-site risk. The limitation of such an approach
is lack of transparencyin makingjudgement as to what should fall under the low, high
and medium scalefor both the frequency and severity. Site specific incident and near
miss records could be used to support the judgement, but unfortunately they were not
sufficient for both sitesunder study.
and Table 5.14, the PHEA could be extendedto include strategiesto reducethe
impact of human error on tasks that madeup the ammoniaroad tanker loading
operation.
could be reduced or minimised. Second providing the linkage to the site specific
PSMS on means to implement the recommendederror reduction strategies. When
for linkages be directed further
using PPJMA technique PSMS evaluation such could
to include the relevant key audit areasand the control loop audit levels. The analysis
in both tables is carried out only on tasks that under strong influence of human
shown
error using PBEA for Site A and Site B as shown in Table 5.13 and Table 5.14
respectively.
r_ u t.
,Wd rq CU
(V (A
=
CJ M
r ý4 2 Co 0
4. ce
ce 10 10
*W 21 5 " - cl
-
uw = rn
(V
2ý
==
0
0
c. =U
-bd "ýý >
Q
tu
sý
ý..
ZI &)
(6-4
,.
4 C) EA 4- Co
000 1-. -0
" (V
ý c2. tu cn- g) iD
ti-- a-,
12.4 0 r-
n
0 Co -
r_r 4-
0 0r = r- 4) 00
W öo r-
Gn 8
ce -0
V tz. cr
03
1 0
'CJ 9
ce
= (L
ö ß
zi ) lu m
. 5.
cqj r.
Z.
- 4) 4Co- =
-
lý2
r- vi
cl)
C
0
,
r. 0
Z
ý: t9 -,Z
, rA -2,
10 G
0
r- ý2Ä
öz cdz =s = X
*z
E-0
0
öü
L. r- >, -0
(J U
-ö u 45). -5
g2, ý.
Q
0
.-Co r 0 =j
0 .
0 O
ý- ý- c2
A a . . . U
.
0
.Z +ý 4)
+- rn iD
Co :3 (4.
gj
=m 0 Gn öo 0 tio
tn
c (bý w .-
Z c2. r
4) 0 "0 r- 0 .-
Z r-i. :3 (A r-
- ce ce
to :30 IIW>,
r- 0 g> 0u &) >
= ci (A
rA "C Q
CD.2
t. Co (V ,0 4) r- -tia -0
iý +ý ý. :j
(L) -ýd Z 4) Ln
'u bo-ci
.- .
.Z-
in
0 0 4-
r.
-
(A 0 v
Gn
eu
ci
t. - t)4 ce r_ tm -ci 4-
cl
0- 0- 0
'CJ
4.) = r- r- m-a(V '0 t-
r_ -
-
E (zu0 r=1 UuZ -
=0Q Z, En
F-
(L) M
rj Co
E 0 *- ca
.0
Z E 4
cgi -0 40
oj
ce
I')
-
A- r. :i> ý
*Z 110 -a 1-.
0 ý4 za - 00
M rn 4)
r
"ýg u Gn
E Ci. uý 0 O =0
1. ci
0 u
%- ,0= CJ
gL9 0 E +ý
(V r= 0 - =
+ý
.2 C0 >
-5 "lý Z to Md r_
0 (V 0
Z (D CZ
0 U Gn
1-. >" 1 ý-
'ö - 0« ci r
(L) C2. -0 (V
ce 4) .-= m
Gn r- >
eQ ZU-ý m 12ý2 r-
Gn rn " Z r- -ci
LA
aw -ý
;4-
0
Ut ce
i. =
0mu iz
.,::
i->
(L)
4ý 0
00
.+ý-
Z
m
-ö 5 :2 72
E
u
9)
ý eu 0ý-)
ý: mö 1Z2
-0
rA eu
:3" .
52 *ý ce
.ý . >
cu t
CU
2 4241-ýzüi.ý= W 2- '00> ý'20 2 0 c2.
.1 . c,
ei .1w.
(V
ci tz
EE -5 Ir.
>
U 0
lu v «s -0
Gw >ý 0 c2. >ý Q
x 44
AE 4) rA
0 '.'
rA 0 ý
0.
Cl
J, 0
u -X
ci CA :j
2 *05: ýA 2 a ý. e Q)
rA
,
ci 0 *4m
ýc 5: CA
04 4ý 0 00
' 't -0
A .E
c 4) c( = Z: u)
Z 0
E 1> ( L) Z ej
0
U ce u 4) r-
ce 62 Gn -
0
E
cM-, cu
A 2 E-
ý- t)re > -a %4., u Co"0
b- 19 (V 9)
1 -
-6, " ý.. Co
*Z b4
ce (V
*C '0 0 cj CU -0 E r
coi ý r-
_X bo.E
0Z
=0 Ei
ew
<0
'In
rA
F-
in
ic
%0
r. = Z
"Ci
ý4 r.
lu 0 iz 4ý 0 2 '0 A0 JD t-: 0 '
W 2
(-) M- u cu , C.)
CA
-2
t-:
g) Lii ld tQ t.
ce 0
m
W zz
0 tw
U
94
-
0
0
&) 4) to
ci ce
ce
ci
4) -ý
=O- tn
U
U
0 r. - -c ý
0
rA
cz.
= P.
j--
CJ
4
0
r_
(V 0 E (6-4
0E
r. r_
0 (V 0 e0= CD
0 r_
r1. -1- 1 U c2. cu (V *- 1 CL) Q
"
1
u2
Q 0 0 tn 7EL
w =$ x--
ce %. cn = ei t.. +- r3,
cz Qý .
rA
(V
ce
=
CKS0
ce 0 cu -ýd
(V cl. == p4
1-- CU
(V
f-
(L)
+ý M Ze. '- , CA
rj Co
-ý tue
, r
u - u »
-läd
u2
ce
+ý
.at to- - 0 - 0 4-
"Ci t *
(L) r. ýZ --
.10
t' to .
-- 1-.
0 j:
-C
.
w t
ý
-CJ 1 t4 4- 'Cu
u3
m (L)
c5ýi > ý> -
:3
.
.
< cu 4) 0
> ý
(L) .6. +J tn n. En U
0. 0 0 :1
a 0 cn x c m
) : ' 2
0. g> 0 r. r-
-o
cn .. C02 .
>, 1-. p4 ce -C r. W 0
:j
=
:-2 12.4 Q Z
0 Ln
0 P.,
CJ .2 1-.
0
0
,-o 2 =0. r- (L) :. ý..
0 LA (L) = ce
Ln
ei
E! Q)
= ce
%.. I' ,
0
&.. bo '5
ýA *5: +ý 0
9) 2
-1 ýa
M 0
+Z - r-
rn
Co 0
(L) :j -0 .
2-0
0
"CJ (V 0 91 ce 2
... n a
Q) 0.
+,
0
0 cu
t) .> tu
0
1
>
0
(L) .- W
0
(L)
ce
15 .- iý Z -
14-
0 0
2
A
Gn
-5--:
3) r.
9)
Ln 0 r. .2
CU 12 0
-2
m 0
F-4 (L) 0
0
0
+"
1-. 0 -0 W
Co bb
43 (6-4
0w
, i:1, ?- =
Q)
e
- U 0
tz 0 4-- 0 0
42
1-. (V 1- 9) 1-. 0 1-.
cz$ , 4 0
,
ca -0
9) (V 2
ce (1) cu
... > A c2.
-tr. CD cn
0
4ý
=s
Q. 0 vl
0 0 cv cz« j--
-d -0 0 zi 0
-0
0 0
< 2
0
rA
W
"0
4)
to _A
rA
w t 0
%ý
i-- cd (L) tr; 0
ch i: 3 ý: -0
r.u 0 .M
.- 0. *ý u
w. to Ici gj
ce 4) 0 (V .-
c2ý ý, 0 -4- 1 E. t .-:3cr ul
g=
r 0
i ci w w r-; Ei. m==
t-
en
". 4
0
+ý 0
+ý
t -0 %. '0-
t;; Iti
+ý
"0 c4 tn (4-4 l= Gn +- 0
Uu9 0 ' = (L) 0 c2. 4-
=0 cu t. (1)
Q) -tý = 0 CA"0 0 '0
ly 8 4ý t) tý (V U jz i.
c2.t 2 0 l=
0 0
r
0
0
-rs c-. 0 -CJ r- (U
2ýýcz
(L) 0 ci
CO
00
0 n
d
0
%..
00
0. +ý
+,
E
t.
Jl, tm ý
Z ý.
ce
0 0 0 C: r 0
10 ti
. zj
:, - Z
Q CD.. 4)
0 -ý4
0
(L) .2 (L) +Z In Z"
0
+ý
E2 CU +ý
cqj 0 -bd
ce
C:r CZ
(V t. Q)
W Q)
0- 0Z- cu JW
"Ci Q
&v0 t>
e,
0
0= fi 0
-3 0 ri
0
li m cu c)
cu - CD., 0
0 CU (L)
ci -ci > c:L,
15 0* ie
J--
EI)tu .- 0 .2 w .2
0 4)
Gn =s
k5*0iý -
b4 - g)
>
cu 0
(L) E g-e ce e A
Co -ci
Z
CU
c) -u(1)-ö E Ei fi
u2
II 2
Q)
0
u
%. m ce cu
0 0
-CJ rA rA
(L) -,ýd 0
(V =
0
2
1
1
i-- ,2 5.9
0 <0
0 (iýI
W2 rA (Z
CA
-1.4
CO
00
mý
V.A
4ý Co
-0 u
E- CU %.. =
c
qj
4)
ci
rA -
tw, ID -0 Co ý-
r.
U1 ,j cu
-ö 0= cu
la. CD000
C:L.
000Z
W t.
(D E0
c2.
«0 Ln
o gL4 ý:2 'ut
4ý
CU
ewrý c2. c2.
si
r- ý, -0 4) '. c-
E1- ý.- %Z ce 4)
cu Z > e>4 c1
ce c2.-E
0=0 4) - 'Uv
mm rj :j .e
4.
cd
4-
cl.
o
(V (V cu ch 0
0
ýo e Gn r- Co
cýi
44
< rq 52 = Z$
0 -0 00
CA 4'
,u> . 2 4- '0 "ýý
cis 4) ce Co m
>0 2 r-
-&) r_ U ý-. >ý >
00U
r- %. CL 9) 9)
0 052 c2.0
M.
4 0 zi
(A
Z., M
,
,0 -CJ
r- 7@)
CA
ý, - -F I.. ý ,6
V 1
4) 0
r.
6c 4) Z3
.
Cd 0 c:
Cd
C4
-0 -E C AD
ý.1 cd o
0
E-,ý Cd
0 k-
U,
-C
0 IZ JD gý CJ CU
z2
rA
t-; 0
(V
10
ce Gn 0
r- 0
cu
15 ri -0
CDZt. jý to r_
-ýd
cj ce 0 5 ZW 0 cu (V
ýz . ril
o
t. = Q E0A %.. =Q E 4-
=
-- Co cu
w 0 0 C) 0
0 t2.
bo. 1-1-n- =W Gn CJ n
%. r.
U u2 - = (U Gn A- t) Ln 0*
r.
Z
cqj
ce = =
ce -0 "- i-- zu ce CJ 0 4-
cu b. ms (L) .a
b)
0
0 Co, . *-0 c)
%. 4ý
0' ou ý- 0 1. vý g> %.
ý *cu *ý -g 0
cn -5 > :3
-ci ce
; 2. c--1 En
4) i-. -M (L) Q)
Q=
iz
:J (-q
(L)
2 w
ch
c.. g)
*2 ce-r-
0 -010
;2
< -0 -0
ýqt
`
:1 Q
ýI
,v
(U (L)
C:L
0
c",
Z
.E J--
rA =
U,
(L)
(V
Z
(V +,
> b Q +Z En -d c)
>, ý- 2 cn 0
E
= (A . ý
W.
rA
(L) >-% .
>
0 P. 4 -0 _kd %. C)
, Z:) ý P., 1. 0
ci tr-4
r- Z.- c - Pi 0 rA (0
0
0 Q iz t)
r.
bo r-
; -i öz - >ý 0
ý4- tý s. r.
cu ci Q) 0 9.
ce
r. fi
m cu
*.. 5ý , E a
cu
t.
c2. 0
0 ci F--4
c
Z! 9.1 -fý
rA
m
t.
r_
ce
+ý = ce r.
4)
CO] Ei
0 +ý 0 r 0
Ci (L) 0 *m
t; z e +ý CJ
0
j--
tn 4-- r- -ce
r-
+ý «2 Cl.
> >
(L) -
E t)o 9.1
Gn Ei (L)
jý,
0 -2
cu
Q) " (L)
EA
cz 42 CU ci 0 -g (V(L) (L) E c
O -
29 .5 +, t2
Z$ t)
Z 0
tu
v c2. ;2
>
Gn
- c«
*ý
e
= LZ
- r
u
x ce
A 0 .
.
CU g. CU -0 1-. 0
,e .ý IJ - t0 4)
-0 , r_ cn *;:3 (L) 2 (V v
t) ý' A
15-ci m-ýA 0
r. 00
cn
= tu
U
+ý
1-.
0
5
(V
924
c2.
92-.
t.
(V 0(L)
c14j -
ý ý: te
i--
4ý .; a
10
-5 ,0 tý:19
Z . 1. 0 *- (L)
0
JW
0 0
Ln
-0 ý: ý (L)
>
Ic
0 - c2
0 . (L) - C
+ý :3
ce rA th tr; =, r. 11ý4 rA .-ý 0
0 *C ce ms -ci . rý Cd ý: 0 2 = *P 0
Cl-
.4
-ci
lu r.
(L) r-
ce
c2
.'
co
..
0 ce V - t.;
0 15 2D
0
4 W :i r.
2ýw U rA (L) Q 0
u
.r.
r. -24 0 1
N V) "0
l ,- Q 94 I 2 0
15 1-4
m P. ý - ý: clu
l. P. 0
mo
ý flý
W
E ei ý Ee rý C ri
.- cn 55
r t) +-
i
0 0 0 0 ce (L)
+ý
Ici ci tu m «2
> 10 r- 2: -CJ
r.
>%
ti) JD
ch Q) u2 = rA
JD 1. = JD W .- 114
U
.-0 u -0 00 = 00 *ýýQ
r_ 92.Q
(L) -
y
ýz öz :j0 = =ý
Z$ 4)
p4 44 0
0 =
.4 En 94 ruý rA
=4- '5
=-
0 0 0
W 0 Z
0 -1-
9) -
w >, 0 cn >, = e-%
rA re
,U ;2 (A ce Z u2 m
cli
(L)
(L) 52 Co (V
r-
;e 4) t en 92-
ý.. 5 t2 1- = 4Q-- (V r-
.
52 -b-
rn .-
; 2. C,1
4) 4-
0 1.
4)
= 2u
2) c2. +ý
0 ý
,
a t
;i. ,t, u=
W
"CJ
=0 ci
- ör-
0
4-
cn
.4c5 w --t cle,
> >0
0 t. E
.
cu
0
.ý -(L) 0Z. =(A(V öo
-ci >, ý:
z ce ý
-6-
>. %-
r.
r.
2p
>%*C
4) r- 10
CU CA "V
.=i al) -
X.
Im ýo :s Z =$ lý rý-
cz
0*5 -2 0, 0
t5
0 Co
r_
5 ýf- . Im.
. 9)
Q r. Co
6,
,va . 0
rn -6ý
%.
0 pý w CZ p U
j
U0 0
:1 --cu
u2 r2.
ns En ci
z r. +- -2..
5
CA C: -0 -
0 ce
C: 9 Arzog iu d
(L) > ,Z = .- (L) ce
rA
=
41)
(V 0
9.
(L)
ýo -02
4ý
cii
c) en -W r_ -
ce 4)
ce
.
(L)
1-. 4..-
Cl. 0 m -rA 0 CJ t4 -4-4
=
CU CU 0
cu
fa 7D "p Q
to
r 0
= Gn
0 4) e * Q 0
ci 0
Z 0 2 - ce
0 "Ci E
0
? 0 Q) r- e c4-, ie M
ý4 5 9r . ce
lý 0 4 "0 u
w tu cu 4
s ci ZA 0 ý .-
r_ r_
tu li.
4-
-
ä2
=i
= "0
W r , r.
9.
0 0 .- 0
1-. 7D
CK3
0
ý5
0 - 00r.
+ý
e CA '*ýg cn ýu ý ký Ln -
cn (V ce
Gn = cn
ci.*@
" 9) ce "0 cn
CI.'2 -2 c2.ýE
(V "0 Ci.
C 0 4-
- c2ý r_ 0
0 0 "Ci-u m-4.1
.-0 0
"-, -d
4) IC 10 .- zi
CD
Q r. *c
15 J-- "C .
ä e
.bo
Cli t CU= m
: i En ed
+,
+ý
4- 9 u in -2 >, r- -a0
4)
(L)
CA
r
W- .2
0
p4 Q
U D c2.
c2. = 0
rA
CD.
tn CU
Cl% (V
ý.
1-4 .2
toi
Co Q
9
Task number 3.7, i. e. setting weight trips on road tanker weighbridge is an example
of a task that could be subjectedto operation error. The omission to set the weight
trip system could result in overfilling of road tanker. The recommended error
reduction strategy calls for fonnalising of the use of checklist and reference tables to
assist the operator. Such recommendation falls under the PRDv1A audit area of
OP/CHECK. It lies in Level 4 -> 3 of the PRRvfA control loop under the component
This step involved the evaluationof factors associatedwith a task which could
influencethe likelihoodof errorsidentifiedin Step5.4.2and 5.2.3. Thesefactorsare
errors made by the operatorswho are not aware of the changes,which in some
situationscould lead to accidentalreleasesof ammonia. This illustrated that the
quality of PIFs at the operationallevel, in this caseoutdatedoperatingprocedures,
Findingsof this assessmentfor the SiteA andSiteB are shownin Appendix6. Such
qualitativeanalysisprovidedimportantinformationon the statusof site specificPIFs
and theirs influenceson human error. As an examplefor PIF on operating
experience,the majorityof operatorsat SiteA havelessthanfive yearsof experience
due to high workforce turnover. Whereasfor Site B the majority of the operator
havemore thanten yearsexperienceworking with ammoniarelatedfacilities. Better
operators.The availability
workforce turnover,enableSite A to retainit experienced
of experiencedoperatorsto carry out hazardoustaskssuchas ammoniaroad tanker
loadingwill reducethe chanceof humanerror.
In terms of job aids and procedures,Site A was found to be lacking. The majority
of the tasks performedon site are without written procedures.Proceduresthat are
availablefor certaintasks like ammoniaroad tanker loading operationwere poorly
written andinadequate. SiteB howeverinheriteda good set of operatingprocedures
and job aids from the previousmultinationalowner and they are well written and
regularly being used. The usage of good operating proceduresin carrying out
hazardoustaskswill reducethe chancesof humanerror andincreasethe likelihood of
successfullycompletingthe tasks.
shown in Table 5.15. The analysisprovides site specific assessmenton the current
situation of main PIFs that are judged to exert strong influence on human error.
However the assessmentonly provided for the overall PIFs situation at the
organisational level (or global level) of each site. Apart from identifying strengths
and weaknessesof managementcontrol, the results of the assessmentare used to
assignweighting of eachPIFs for humanerror quantification later.
Table 5.15 Summaryof findings from PIFs analysisat Site A and Site B
For individual task steps they have to be analysed in more detailed as each PIFs
influenced specific errors in different manner and with varying degree of influence
depending on the nature of the task. As an example, one of the PIF under
at any level of details, i. e. whole tasks, subtasks, task steps down to individual error
The basis of SLIM technique is that the probability of error at any level of task is a
function of Performance Influencing Factors (PIFs) in the situation. The PIFs which
have direct influences on error such as the quality of procedures,the level of training,
and the degree of feedback is used to numerically rate the tasks. The combined
ratings of PIFs influence on each task yields an index called the SuccessLikelihood
Index (SLI). Using a general relationship between SLI and a task with known error
consists of two modules. The first module called SLIM is used to analyse the
likelihood of successof a set of task based on the evaluation and contributions of
important PIFs that could affect the human reliability in performing the tasks. The
study is as input to failure model of ammonia road tanker loading operation. This
study used Fault Tree Analysis (FTA) to depict the failure models that show the
contribution of both hardware failures and human errors to the overall system failure,
i. e. loading of ammonia to road tanker. Human errors reduce the likelihood of
quantified using the SLIM technique. The FTA which depicts the critical tasks that
made up the failure model of ammonia road tanker loading operations for the two
sites is shown in Appendix 14. Incidentally some of the tasks identified using the
FTA were also predicted to be under strong influence of human error as indicated
from PHEA results in Section 5.4.3.
operation the situation involved the execution of several tasks by human, i. e. the
operators which required interfacing with the hardware. For this study such
information is gathered through observations, interviews, studying operating
only those which were judged to have direct and major influenceson errors in
performingthe taskwereselected(AChEI, 1994).
Using this approach four PIFs were selected for the quantification purposes. They
are;
* Experience
9 Procedures
0 Stress
o Feedback
The four PIFs belong to operational level factors that have a direct effect on
PIFs Description
1
O>
ý m e* 811
ci, -2,0
0
b-4 to
O=c
R
a
-0*,0 ;ä to .2
u :10
1-.8 9) 3
Ei 5
ýM ., . 0 Z
tý, 0
0t u
-NI
'cl ýý CZ
. 0
c> 24 -
L
C ic 0. ;ä0 =8
0 m
r.
ö
= .ý', Z. ý2 0
,0 8.
Co, u = ri
cli
0 1Z8 ý '; e0
0
0
5:
Z,
ý2-x.,
r- (2 s-.E c2.
b' r. 2
t.
ä
tA
>
O8 gmý
U)
Ei
r, ' Z
-2 ,e>22
-5 -1 8 ? W
= le
u0 92- g) -0
+ ý >,
ce -Uo
= (n 2 Z$ . -in
.5 tZ
ce .-
i2 2 t 0
ne to Ici
0
1
.2ý
A22to.
Ei
=0.0
5: ý 08
--g) Z rz
M 0
c).8 cý
m ce "ö
c2. 9
1,0
ce 'e
R
-ö
ce
(2 c
c2. 10
ý2
cu cu b- 4Q
Ln
CD
V)
2 1. 0. ri
124!2 W1
0ä
g,
ýo r- r- t-
1
F-
r.
0
0
0 0
0
0
0
LU
ý K
(D C)
00 c9
Ln E- Z ý- -1
F-
.0 iz iz 0 .0 -4
1--1 r, 1 1--1 N
9
0.) 0
bo 0 9.
tb
cs 0
1 Iti c4.d Ici
0
-
>
o ln 00
42
e A
m ý: 0>,8U 8 l ý.
0.)
u Ei
2 Ion -8 . +ý W 2 c4.-4
ý= CL4 -2
U)
9.1 ö .2
-3 LZ a Ei
0
gcli -8 t ce
t) ý2=e Cm
.
.2 i-b 0 0 rx.
m
:i ci .3
C, 9-
=
ý X
0. > U E0 "0
n85u8
,0 8ý -8 ýgý 0
) ti-4
C. 0 0 0
lu- 8 ,
-0 r. -0 c2.
0g - v iz g)=
to %:
ý, =u 2 - >,= - 018. ý 2p -ci
1 .2
,8 108e 7. 0 Mjw 9)
g ri4
2g5ý ei ýa
W
LE cz.2e
vi >
c2.u -2 %
:b 0 "2
4ý
H
0 .2
.5M
iä
im
*
00
E;.
>b
-0
- bd
Ji Igil
CD
00.
Z ýA
c4.4
%0 ce
> j> m
0> ch 23
0 m (1) ÖD
"22 -8 ip C
2 We - ce >, --;>0Z -5
vi ýi
0 21), -ß -5
+i
2
0 m.
(U
E
rA =E
5
%1
(A
g Qý10 En u2
.9>
%10 -4
In C>
Itý
CD CD
"0
0
0
0
4ý Gn
te =2 0 0 92.
0 0
0
> 0
cz 0 0
.io 0
12 U
Z
tu =u E, le
0 =
0 U
0>
9-)
22,
0 92
*r.
"0
-0
.
IRt
(1)
>, .2
0 C.) ce
1. tw
(L)
e
M
0
Q00
l
o
1--
E ce 0-5
.0 ý9
'n Z0
ý
la 0 1-8 0 ,9
10 .2ý . 2
UN (40 Ü
0.9 fi
ce4.
0$-to0- 0
ge
ce c:lý Z0--
55
w
d 'e A ö,
ý2 -ý J. . .-2 iMt;-. 8 ýZe
1--4 rq r- r- r-
9
C,
CD
rIlý
c>
lIci \Icý \Icý
(Z CD C>
\O ýD 4-ý V) V)
\o ýo %D ýo
1 10
1
cn -
m .2S
A
to
tz
w -,
ý ccz 1
u
ý ci)
1211
Z
8 gri = 0
0
W 2 25e ba
r. .2
0ý
'g "8 to ý. 0
0 0 Ue
1 1 - -2 Gn
5 1-
412
ý5 8
b.
+d
rn
-rn
+d
9.8
0 4? &ý U 9.
0
-A 2 0
-=1
0 u
0 CD 9) 5? '
- CD-0 CDe2
T
W,
Oa r,01
Z
.0
rq 1-4 1--9
ýoq --4
cli
"-t
ýo
. -1
-. 4 1---l
ýQ
..
r, 1 (N
r-,1 c--1 --4 C,1 --4 ('4
> >
kn
tf)
"0
.0.
to =
ý: >0
0w
(n
? (U
m
8
-
rz.2' 2 Ei
0A
c) 0 c92
o
-Z
1. E2 m 22 E ll'n ý 2 ýa > -8 ýq r,
ý3 .!::
10 cl
-
.ý -9 0cli ce 9 e N. =o ll-'
ý
C-) 12n ÖP
0 +ý
c2. 5
r) e cu o ro--' 0
rn -- 0
3 v 'CJ tz
L, *0-, M 8 e
r14 '=
r. En
09
CA
0 0
2
"j
.
02=
1- g's ce 5k2 i' zi z ul
140.
2
0Q
2 V *5 C,
c122.
ý
ý;
2
-
ce .0
:1
,
ýe g
=2 .
2ý, -,
ýe :5
,0 ,
cn - (U 4)
ID e ce
2
0=
.2 p4 0
'-
0
s
5 "8 23-
2pezo'= 2: . 3
L, 5j
= -ci ? 5
*5 0 >
U- 0-
ce .g : gýu
. M . 28
za u9 U
4'o
(N4 E
j r-L 1 u to
:5 0
OA
.r
0 +g
5
a.
=
4)
0 -
-2
u W0 C) .
r_ e. 8 ce e
8-r.
. - -a
ýD .tDA-. .
23 0
208
9 (n
E 9- .ý % r5 .2
m
t! rA 2 - ý:
0j 0
4-ý
-2 %.
e)
JE --
-2
E2 ý
,,5
c26..20 g. -
10 ,S -e A .u-ý,
u 1 E2
ti -
0, g 8
-
En
Le 2 .-.;
'n
-)
.5 rl.
9)
ý9 "2
m ro-
ý2
M
9
ý
0 5 Z (1) ý
,
4.4
1
r-
%ýze
-. r>-5
4) m -ci cn 0
u4 . - 92. 1-- ýM. (D r-.
ýo
u
lu
'
0
l -'
u CM -.s
ce ri rq 00
00
c; C>
U2
0 %0 \O
tn %0 %D \D r- 00
rA
00
0
-0
m
E--4 0 0 ce, 0
0
m In. oý .-
2 s. 0 0 cu0
9 =
0.) JL)
tn .5
rn A1
-41111 -8 -8 s5
> *Z:
V2
0
ri
ý- to
00
>
0
*
ro- 0
,0
0
ol- PZ
ý3 20Z 00
CA A
2
,0
0 O. ID ;2
iz
1--4 iz
-4 rq r9 rq Oa
JD iD
--4
clý rq r-i ri
cq
%c
s. ce
ce 0 (6-4
0
A 0
ce -,4 c)
to
>
Z
0
-2W ce
0Ur. 0
1
C0 0
19 9)
>
"0 (1) 2 E00 9
,zi ig j= 111
00
*ge
le > Z
rA 00
(1) tn (n Z. 0
g
"Ci 0 C) ýa
CU c3
0
gL4
4) -cu 0 0 :S0
Z 2, ýa
to'. 2N 2u a 2 -A ýEa- ý.' -3
A 0
e 2 o ä 0 ý:
%. .g -ý r, 0 . -x
C'4 ci 0,0U
gt ce 4ý
0
is
e.) tu
0
.*
C> (D
CD C) (D (D (D
1
%Z %0 %D %0 %A
1 -
\.0 %0 10 %0 \io
00 00 00 00 00 00 00
kl CW)
=
.0ci 924
m>
0e 13
0
U
-8 -8 ý- 11) e
59 =O
45
'0
(42 58
ö 0
10 röll
eO
(L) CL= c2..
5 0 e
c c2ý 1 2ý E 0 0
e
9)
CD.. Ü.
0
-2
-
:1
.
0
cz
-4A
=U
cz10
(Dý
- E
0. - 01 -
ý9 0 ei ti.-
*c
lý
cc
rq rq
.0
:;: --4 iD 0
r-i
1-4
.. 4
-4
rq N
-d
--1 Zý r-i
-. 4 -4 mN
-g
4 -4
rq
F.
, --4
>
91
>
A
4 4
5.5.3.4 Assigning weight to selectedPIFs
relative influence that each PIF exerts on all the tasks being evaluated. It could be
done based on the analyst's experience or error theory (AChIE, 1994). The
assignmentof weight is not mandatoryin SLIM. The technique assumesthat all PIFs
are of equal importance in their contribution to the overall likelihood of successif the
weights are not used. For this study attempt was made to assignthe weight for each
PIFs basedon the qualitative assessmentmadepreviously as shown in Table 5.19.
PlFs Weight
1. Expefience 0.4
2. Procedures 0.2
3. Stress 0.2
4. Feedback 0.2
analysiswas carried out using equal weight to all the PIFs (or not assigningweight)
to see the difference on results of HEPs. It was found that the use of weighted and
unweighted PIFs only introduced small differences in the HEPs values as shown in
Based on rating and weight assignedto each task, the SLI were calculated using the
following expressions;
SLIj =I Wi
.R ij
Results of SLI calculation using the SLIM software is shown in Table 5.17 and Table
5.18 for Site A and Site B respectively.
carried out to turn it into probability of failure, i. e. in the form of Human Error
Probability (HEP). To transform into HEP, the SLI scalewas calibrated for each task
under consideration. For this purposes the relationship between SLI and BEP
followed a log-linear relationship (Embrey et al, 1984) in the form of;
Embrey et al, (1984) provides some theoretical justification and gives experimental
data to support the validity of this relationship in SLIM's context. Such relationship
equations were produced using the two calibration points from equation (1) to
calculate the value for the constants. By substituting the values of these constantsto
equation (1), a general calibration equation for converting SLIs values to IHEPs is
made. The SLI values for the remaining tasks were then converted to IHEPs using
this formula. The SLIM computer code calculatesthese FIEPs and converts them to
IHEPsvalues automatically.
are mainly on simpleand basictasks(Kirwan et al, 1990) which did not adequately
represent the actual tasks under consideration. The use of published data from other
analYstswas also found not that feasiblebecauseeither they originated from the
nuclear industry or they utilised PIFs that did not match the PIFs selected for the
current analysis. Finally the absoluteprobabilityjudgementmethod was used for
calibration points that takes into considerationon site specific situation such the
influence of relevant PIFs, the processsafety systeminstalled, and accident records.
BEPsvaluesderivedusingthesecalibrationpointsservedasbaselinevaluesfor QRA.
Additional analysisusing calibrationpoints taken from study on chlorine loading
operation (HSE, 1989) to
was also conducted check the difference in BEPs values
arising from the use of different set of calibration points. The report is used as
referenceasit was conductedon similarloadingoperation,but for differentchemical,
i.e. chlorine. Summaryof the calibrationpointsusedfor the SLIM analysisis shown
in Table 5.20.
The calibrationpoints taken from HSE study (HSE, 1989)were madeusing expert
judgementmadeby the auditorswho preparesthe report then. If thesevaluesare
CD 0 0 0
4) 00
rn c>
-
00
CY\ E ýýZ N rn m 00
-
00 1-4 00
cu
ce
0 C) 0
40. 15:
ý '-, r- c> m (n w 0ý
(L) 0
CA -ý zr, >. nZ
ý24 ei
't od zi zi m m
5
0 cn ý
t. jz ýý z (1q N (1q ri le P-4
0
Cd
0
""
lzný =* 5EAr..- ýh
Z ýh
m
ig ýh 9
cn 0
1-ýI .:s ..'
ý-Z
J-- -0
Jz 4) -
ce
.0
r-. K-Z-
Ln cz. ý ýý --
ýZ ýx >-4
ýZ :i
9) %Z
rq
t1q
cq
10
N
"0
N 1(>
V.,
(L) :j +- 9
=ce .5
0 Cz' 00 00 00
Cd
ce ji
0
W (L) =
92. C) 0
r. %.. +ý
:3 c2. Cz. (L)
0 0 0 -4- r1.
4s fi 0
tu
0 0> 0
. 4- 0
2p
4ý Z
14-
cq 0
Ln 0 -0 "0 -0 > 0 .- "Ci
cq > 52 tr,
.
0 Ei «,
0
iz J-- 0 00 0 0
cu 0
E- > 0
(L) u
E2 4) t. W (9
t2
cn ný
CD *C
VI
4) u cli CNI le le
cu
9
P4
C14
10
1-4
m V) m en en en en m m m m
a C) 0 0 0 0 0 0 0 0 C)
I 1 1
C4'j
;4
en WI
00 WI W W m
W
1-4 00 en cn cn
C14 ýo
N N N C% cli
W
t4f)
I-
Cý
tf)
14
ýo
ci
a4
In
li
en
C14
C-4 N N eq en cq N en
C) 0 0 C) 0 0 0 C)
00
-4
ýo
N
00 Cý 00 ýo
C-4
00 Nr
1.4
00
-4
- ýg
C'4 m
rA 1ý
cn - to 14. 1.
E! 0.) =1 ) Iu
4) (U r. cr , (U r. ,4
0 .- == 0 > = J
(A En
0 r-
+ý
0 0 -Cýt=
- +6
EL tn
0 4--0
.
(U iýEi
izi -0 - (L) > 4)"0
I. =
-
:3
CL. 1
,E
4- 0 CL. 'o
to j! -0 P. oc
0 C)t4
4ý r
0.
1.14 o o 0=
vm 1
0 0 .5
r-
zc" 41 Or-
-EL 5
= 8 6 0
:z
.6. 4ý 1. 4- 5 *15 1.
.
Cw. 0
I- .-
(L) >-. C)
+ý 1:0 1 "o Q 0
S. 0 .0
t.4
-;
En .0 0 0 0 Q
> - o0 -14 V
4")
0
-6ý - COL,
I. o- . I-
o 4
t. 1. 0 crj ,-(L)
E 0 0
0 ry) o 2: o ,-.
-
4)
4) Cl
0 .
4) "
. o
Cc 1ý Cd d) Cd
. C', 4) 4) t
:: I ým
4) b& .> C) ý cd Cd ^
> S..
-Y. " -&ý I. I. , t-. -= 0
4) Cd Q
5. 0
Qý Cd C: L. =0
(L)
"
4)
r- .
v=
C: J. 4ý
-5
tn
o 4) 0
- cd 0
00
-
Cý, 0
a-)Cl (v I--
Cý, ",
tML
r-1,0
Qtr. 0U 0 -a oRI. . cd Edo
0 > o > Tlt
C14 N
N 10 10 .0
(14 ýq
CN It In N -4 -4 N .0
19T 1-4 lt
4 -4 -4 -4 C*4 lt
ý4 -4
cq cl l--4 -4 N
4 > >
1. ý4 ý4 I-
en
en N
C) C>
--4 en en -4 -4
C14 en en CA C14
C) C> C> 0 C)
ýh Vý a5
ýh Vý
Clq en V) cq cq
C14 N (14 m
C) 0 0 0
ýh
Cý
00 00 00
C14 N C14
C) C) C) 0
C> C) C)
Ci ei Ci Ci
tn tn kn kn kil
en en m
IRt 9 0
C) w 4
Ci Ci Ci
ýh Cn cn
w
kn
C-4
C?
Ci eli Ci Ci Ci
t1l tn tn
4.)
E :ý W= Q r. Ew9
0
.1
to
15
o
.4-
ý:
0 CQ
-0 np
(U 4) 4)
"o 0=
as
.20
0.0
(L)
týl 0 tfý4" a! Co 0 -;
5
1.
0
U
Ch
6.
0 E
4)
"0
0
S.
0
u
.5
0
0
.4
_0
01 0 4) al 5p In
ý1. c:,.-ý 0C:
w.(0)
-
.
0.2 (L)
.g .
lt
in
.0
1-4 .0
1ý --4 .0 1-4
N v"
-4
cq
4 C-4 C14 N c"I
cli C11 N eq
i- E-
I I- I E-
- I i
0.4
le
%0
V-4
0
A4
C)
IT
00
cn cn 00 00 cn 00
0
.
Cý ý'o
9 m
as
t. 00
-4
Cý
-4
cd cd
0 A4 cq C14 C14 C14 en C14
ED CA
m .0 0 C) C) C>
1ý PL4
C\
00 m en
en en ItT
C)
CA En
tn tf)
cl
i
Nt IT
0 C) C)
=6 \, -0 .5
0 m w w w ýh w w
C7 -W ý-, Cli
rA t- Clq
12
0 .2
E! ca.o -s 'it
>, r. c1:
1 W t.
I m IT 141, tn I*
Gn
4- 0
-J:ý ,ý .0
I-- Cf) 0 0 0
CL)
.
bo 4 0
.0aý:
JZ
en ý 00 00
.0 .-Mý:
. ID
E!
0 al C)
(D oq clq
Ln =
m
-R *aý 41) til ti) C'n 1.4
cd -Cd :; ý
0 04
Cd
Q) V tr4 0
CIS 0.) r- =s 0.
t"0 ;; P. 0 0 u
-9
0 0 0 0
crj
9.1 .4-
"o .- C's
-x:l >
CL. . -co
0 -14
U -
'm = Cýj cd
.0ce
F--4 4) "0
CL
0
>
0 0 0 0
En 0 ts '. 0
Cd > :5
> r. 00 0 W0 CL
r. = ". I"" " 0. cn
o
Q rz 0 0 0> cz C)
T
-4 -4
-4 cq >1
.0
-4 -4 .0 10
C14 C14 IRT V')
Cd
Cl
.E-4
tn
en V) m m
m m Cn en en
0 C-) 0 0 0 0 C> Co 0 C>
4
M
ý4
en
ý4
00
ý4
en
Lý
00
;4
cn
ý4
1-4 L4
00
L4
M
14
C4)
N C14 N N C*4 cq en
C) C) C)
4
C*4 C, 4 cq M cq M V)
;h
C14
lh
clq cn
til en en en
C'n en NT IT
c> 9 c) 9 C) C>
CS 00 en C%
Cý
en en en
C)
4 C) 0 C) C)
I
C14 C14 N lh ýh
4
C, C14 ýo 00 en cl
t-: cli t/i C-i
en R C) It
C> C>
w w 4 ýh
00 t- 00 ON 00 ON
en en 0 0 C> C) C) C>
c) 4 4 4
ýh 00 00 ON ýh 00 C7%
rA
:3 tm) o
-
ýa
0
1!
ic
0
-
(D
1J.
Cl.
-0
r-
Q .-
Ln
al
.-
=
r
. +ý
.4.
.2
t. 1
CA 4) = Z
W Cz S. +ý o > as
ca.
C..
0
CL vi 11-1.
0
cl. tc En >
0
0
0 -0
Q 0 (1) 4)
.2
cd 0
+ý
0
0
0
.4. r.
0 r-
Z: cl. zcd 0
4ý
0 =w 0 1.. -0 C,
E ý
rj)
(L).-
ý -(D 0 E 00 IN e 4) ý
rz. CL) ý0 N)
-. E
ce
0
>
th to :n o tth
0
0 o 0
r
o>
o o
o
0 0
0
0
0 0
0 4
t. Z4
b
>
4 z
o m (D 4) Cd>cd cd 00
t. :st ý R- 0 0 0 E
rL 0 CL (1)= 4) = _
o 0
Q.
Cd
"= CL. 1,- 0 0 O
CdL
J > 0 0 0 u 0 0 > 0
B
C14 Jn
.0
cl cli
.0 .0
cq
> >
4 4
0- ý- 1 I
P-4 Aq 44 P-4
0.4
ýo
140
". 4
eq C14 m en C14 N
0
clq en en N m
9
N N m
en
9
17ý Cý Cý
00 00 00 00 00 00
en m M en m m
0 0
C> C>
to to
bo rA
0 id 0. a o 5p 9
. 4- 4- .0 0
W (2) .- .- C's ý ýE
-,
to "> 0 I.,
C. c5- Cýý j-- 0 -g
o 0 4) 00 0
0
V 4) cts
f. 'n cc 4)
ý. >
0 KI )
(L cp
41)2 U
M.2 m.-p c: -4
L. C:
). Cl.0
0 0 o C) Cd 0 to 0 JD
1 .4- cz I
-
.0 .0 .0 .0 JD JD
N4 1"
cq
"-4
-4 -4
-4 cq C11
cq
.M
cq cq C*q
0 0
1 1 1
-
E-4 E- I F.
p. 4
Results of IHEPscalculationsfor Site A are shown in Table 5.22. The results showed
the differences of IHEP values obtained using 6 different calibration points for each
tasks under consideration. For example the BEP for task No BL121b, i. e. driver
moves tanker while filling operation is in progresscould range from the highest value
of 4.3E-02, using calibration points from HSE report (HSE, 1989) to the lowest
value of 3E-03, using calibration points from TBERP nominal data (Swain and
Guttman, 1984), a difference of about a factor of 10. Given large uncertainties
associated with data base use for human error and risk assessmentthe difference
shown by this analysis is very reasonable. The effect of using weighted and
unweighted PIFs for the task is also small. The BEP value for this task using equal
weight for PIFs is 1.8E-02 and when using weighted PIFs from Table 5.22 is 2.6E-
02, a difference about a factor 2. Using the APJ with two calibration points the
BEP value the task under considerationis 1.8E-02, while when using three calibration
is
points 3.6E-03, a difference of about a factor of 5. This small difference shows that
the use of three calibration points over two calibration points in calculating the
BEPs is not as significant as suggestedby Kirwan (1994).
Table 5.23 shows the results of HEPs calculations for Site B. Similarly the results
each tasks under consideration. The BEP for task No HL12lb i. e. driver moves
tanker while filling operation is in progress range from the highest value of 2E-02,
using calibration points from HEART nominal data (Williams, 1986) to the lowest
value of IE-03, using calibration points from using the APJ, a difference of about a
factor of 10. The difference shown by this analysisis considered acceptablegiven
large uncertainties associatedwith data baseuse for human error and risk assessment
(Hurst et al, 1992). The effect of using weighted and unweighted PIFs showed for
the task is also small. The IHEP value for this task using equal weight for PIFs is
IE-03 and when using weighted PIFs from Table 5.23 is 5.2E-03, a difference of
about a factor 5. The analysis also shows small difference using the auditor
judgement of APJ with two calibration points the BEP value the task under
significant.
The IHEPvalue of the taskNo. IHL21b, i.e. operatorfailed to isolateleak for Site A
is 7.3E-03 (Table 22 column3) and for Site B is UE-03 (Table 23 column 3), a
differenceof about a factor of 7. The result showedthat PIFs at Site A provided
greater influence in reducingthe likelihood of successin executingthe task as
comparedto SiteB. A similartrend alsoexistsfor other tasksunderconsideration.
For examplecomparingIHEPsresultscalculatedusingunweightedcalibrationpoints
madethroughAPJ in column3 in Table22 andTable23 showedthat BEPs valuesof
similartasksat SiteA are higherthan SiteB. Their differencesrangedfrom a factor
of about 30 for task No. IHL41I lb and to a factor of about 7 for task No.]HL21b.
Evenwhen comparingthe IHEPsvaluesobtainedusingthe samecalibrationpointsfor
the two sites,(i.e. Site A-Table22. Column3 and Site B-Table 23. Column 5), the
trend persistsbut with muchsmallermarginof differences. Basedon theseresultsit
could be concludedin this studythat SiteA is subjectedto higherIHEPsas compared
to SiteB in ammoniaroadtankerloadingoperation.
5.6 Conclusions
Resultsfrom the qualitativehumanerror analysisfor the two siteshas indicatedthe
following;
to carry out the filling hose connection and disconnection increases the
duration of filling as compared to Site A due to waiting period for their
resulted the needto modify the Chiksanarm for bottom loading to road tanker
by adding flexible hose connection.That arrangementmakes the task to vent-
severity and frequency provides a simple and effective mean to predict tasks
that are under strong influence of human error. However lack of site specific
information on the two attributes, e.g. from accidents or near miss records
forced the use of expertjudgement which at best lacks transparency. Forboth
the establishmentof correct filling weight to prevent overfilling and the on-site
movement of road tanker which could resulted to collisions and hose pull
Results of PIFs analysis at the two sites have systematically identified the
not practical to consider the influences of all PIFs that has been identified)
Results of IHEPs calculated using SLIM techniques showed that Site A has
higher value of IHEPsas comparedto Site B for identical tasks. This finding
that
suggested in ammoniaroad tanker loadingoperationSite A is subjected
to higherinfluenceof humanerror ascomparedto SiteB.
t, napter
6.1 Introduction
Risk associated
with ammoniabulkingoperationwould be major releasesof ammonia
that could affectthe surroundingpopulation.In the eventof a major releasecloud of
ammoniacould travel over a long distancein the downwind direction. People
engulfedby the could be exposeto variousconcentrations
of ammonia. The amount
of ammoniaconcentrationexposedand the durationof exposureis known as 'toxic
load' (Nusseyet al, 1990). Above a certain level of toxic load people could get
injured from ammoniaexposure. A very high level of toxic load could result in
fatality. Consequences
from suchreleasescould be consideredin term of possible
'injury' or 'fatality' to an individualor the population due to exposureof certain
amountof toxic load of ammonia.
error' (comparable to generic hardware failure rate) on the system failure rate and
eventually the off-site risk values from ammonia loading operation. Sensitivity
analysis using different IHEPsvalues from SLIM technique is also carried out. The
primary aim is to addressthe main weaknesseson the usageof such technique, i. e. the
selection of calibration points to convert the SuccessfulLikelihood Index (SLI) into
BEPs (Kirwan, 1994). For this purpose two sets of calibration points were derived.
The first set is derived using Absolute Probabilistic Judgement(APJ) values based on
site specific situation. The second set of values is obtained from existing HSE
Report (HSE, 1989) on risk assessmentof a similar activity. The flow chart of QRA
The other objective is to comparethe off-site risk posed by the two sites in carrying
out a similar activity, i. e. the loading of ammonia to road tanker. Using the same
failure scenarios at both sites their off-site risks were calculated. Since the level of
technology for this activity is almost identical at both sites, differencesin off-site risk
values between the two siteswill reflect to some degreethe influences of site specific
PSMS performance and Human Error performance influences. Along the same line
of argument the contribution of human error to the overall system off-site risk was
compared between the two sites. Since the two sites belong to two different types
of ownership (one locally owned while the other ex-multinational) the results could
provide some insight into the influence of site specific ownership on process safety
managementsystem performanceand on the control of human error. Admittedly the
off-site risk results from the two sites under consideration could not be taken
"Ci A:
6.1.2 Types of ammonia releasesthat can lead to off-site risk
could also result from humanerror. For examplethe operator may fail to connect
the liquid transferhosebut continue pumpingthe ammoniathat could lead to a full
bore spillage(error of omission).The operatormight also inadvertentlydisconnect
the filling hoseswhile the loadingoperationis in progressresultingin a release(error
of commission).In the caseof storagetankssuchreleasescould arisefrom rupture
of the tanks. Ruptures below the tank liquid level resulted to liquid releases.
Rupturesabove the tank liquid level gave vapour releases. For a same size of
rupture hole liquid releaseswill have a higher releaserate comparedto vapour
releasesdueto the highermassdensityof liquid ammonia.
After identifyingthe type of releasesthat could most likely lead to off-siteAsk the
The first evaluation was madeusing Expert Judgementmethod. This technique was
A PhDThesisbyJ.Basri 174
ammonia. The audit teamthat analysedthe systemalso had considerableexperience
in the design,operationand conductingaccidentinvestigationof similar systems.In
time at eachsite to observeand inspectthe
additionthe teamalsospentconsiderable
system.
The secondmethodis Fault Tree modelling. Using this methodthe chain of sub-
eventsthat could leadto majorreleases top
of ammoniawere constructed down in a
hierarchicalmanneruntil it reachedthe so-calledbase events.These base events
representa seriesof componentsor actionsthat could initiate the top event, i.e.
major releasesof ammonia.The next step is to determinethe frequencyof such
eventstaking place. For components
or hardwarefailuresthesevalueswere obtained
from historical data. As for the human error these values were obtained from
historical data or evaluatedin the form of humanerror probabilities(BEPs). These
IHEPsvaluewere calculatedusinga numberof techniquessuchas TBERP, BEART
or SLIM. Failure frequenciesor failure probabilitieswere assignedto each of the
base componentsor actions.Using mathematicalmanipulationthese values were
and exposure time referred to as 'dose'. For the land planning purposes the toxic
load criteria in RISKAT used the HSE 'dangerous dose' criteria which could resulted
in severe distress to almost everyone exposed, a substantial fraction requiring
medical attention, some of those seriously injured requiring prolong treatment, and
highly susceptiblepeople possibly being killed (HSE, 1989). The broad criterion is
only (Fairhurst and Turner, 1993). Such criteria is adopted for this study.
the rubber industry ammonia is used as anti-coagulant agent for rubber latex. As
there is no ammonia producing plant in West Malaysia where the majority of the
A PhDThesisbyJ.Basri 176
product of urea production from the synthesisof natural gas which is abundant in the
two areas.
6.2.1 Site A
The bottling and bulking process is fairly straight forward using simple technology
with high degree of manual operations. The simplified line diagram for road tanker
loading is shown as Figure A7.1 in Appendix 7. The empty road tanker arrived at
the site will be physically check for fitness of purposes. The target filling weigh is
then determined by the capacity of the road tanker and the permissible ullage. The
tanker is then connected to the plant's liquid and vapour return line using flexible
transfer hoses. Liquid ammoniais pumped from the storage tank into the road tanker
under the watchful eyesof the operators. Once the target filling weigh is reachedthe
pump is stopped. The remaining ammoniainside the flexible transfer hoses is vented
to the scrubber before being disconnected.The road tanker is once again checked for
A PhDThesisbyJ.Basri 177
abnormalitiesand allowed to drive-off afler the relevant paper work has been
completed.
6.2.2 Site B
with a weighbridge fitted with weigh trip system. The tanker is weighed to determine
its empty weight. The target filling weight is set by calculating capacity of the road
tanker and the permissibleleague. The alarm for the weigh trip system is set at 10%
below the target filling weight. The tanker is then connectedto the plant's liquid and
vapour return line using flexible transfer hoses attached to the end of the Chiksan
arms. Liquid ammonia is then pumped from the storage tank into the road tanker
under the supervision of the operator. Once the trip is
weigh reached the pump is
automatically stopped and the tripped alarm sounded. The operator then needs to
reset the alarm to allow the pumping to proceed until the target filling weight is
reached. After the pumping stops ammonia remaining inside the Chiksan arm and
flexible transfer hoses is vented to a catchpot before the hosesare disconnectedfrom
the road tanker. The tanker is once again checked for abnormalities and allowed to
drive off after the relevant paper work hasbeencompleted.
The main effort in conductingQRA on the two major hazard sites involved the
collection and gathering of site specific information such as plant layout, major
vesselsand piping data, safetysysteminstalled,failure rate data base,population
data, meteorologicaldata and frequencyof road loading operations. For this
purpose a variety of tasks have been carried out which include site inspections,
interviewingworkersandmanagement,
observingthe road tankerloadingoperations,
visiting populatedareassurroundingthe sites, visiting a numberof Government
agenciesfor population data, site maps and meteorologicaldata. Such activities
consumedbulk of the field studythat spanover almost6 weeksdurationfor the two
sites. The populationdataandmeteorologicaldatathen were modifiedto fit into the
requirementsof the QRA computercodeRISKAT.
the computer code used to calculate 2-phase flow. The source term output is then
called DENZ which deals with instantaneousor 'puff type dispersion. The other is
called CRUNCH which models the continuous dispersion of heavier than air gases.
Both models are able to predict the gasesdownwind concentration at given distances.
The dispersion's calculations rely heavily on the weather data input such as the
shortereffect distance.
Risk assessment
conducted in Malaysia that
currentlyusedstabilityclasses are based
on assessors
own judgement made basedon limited local weatherdata. Someeven
not only be useful for the author's currentresearchbut also for future usedby the
public, e.g. for consequences in
analysis emergencyplanning. The format for the
requiredstability classeswas givento them andthey were requestedto analysethe
last 10yearsweatherdata.
However due to cost and other job priorities the MSD only managedto analyse
weatherdatafrom i.
oneairport, e. Alor Star in the format It for
requested. gives the
first time the stability classesinformationderivedfrom the actual data rather than
basedon individualestimates.The analysedweatherdatafor this airport is shownin
Appendix8. Summaryof the 10 year datais shownin Table6.1. This data is used
asinput for RISKAT runsin this study. Eventhoughit is not the actualdatafor the
two sites,in the author's opinion it is a better representationof Malaysianweather
dataas comparedto individualestimatesor the useof availabledata from developed
As shown in Table 6.1 atmosphericstability category A and B dominate the day time
with a combined contribution of about 92% of the day time stability classes.
Referring to atmospheric stability classificationin Appendix 9, such situation reflects
very unstable conditions normally associatedwith warm and sunny weather with light
wind and cloudless skies. The rate of change of temperature with height known as
'lapse rate' is high in the atmosphere.Thus any gas releasesin this type of weather
will be quickly diluted due to strong mixing with air and dispersedupward following
the rise of warm air from the ground. As a result the toxic gas cloud that being
releasedis quickly diluted and would not travel over a very long distance downwind.
The area under toxic concentration will not be large and in a populated area less
at risk.
Directional
Daytime Data (0700-1900)
Sector
AI m/s A2 m/s B3 m/s D5 m/s D7 m/s F m/s TOTAL
N 7.35 4.12 1.09 0.26 0.00 0.00 12.82
NNE 2.19 3.83 1.42 0.37 0.00 0.00 7.82
NE 1.95 5.82 4.60 1.62 0.03 0.00 14.02
ENE 1.54 2.82 2.68 1.27 0.02 1 0.00 8.33
E 1.87 2.17 0.39 0.19 0.00 0.00 4.62
ESE 1.03 1.51 0.15 0.01 0.01 0.00 2.72
SE 0.87 1.72 0.28 0.03 0.00 0.00 2.91
SSE 0.68 1.79 0.37 0.07 0.00 0.00 2.92
s 0.96 2.44 1.06 0.30 0.01 0.00 4.77
SSW 0.59 143 0.96 0.31 0.01 0.00 3.31
sw 0.90 2.54 2.19 0.61 0.02 0.00 6.27
WSW 1.02 3.62 3.50 1.14 0.04 0.00 9.32
w 1.64 4.77 3.72 1.07 0.03 0.00 ll.. 22
WNW 0.83 1.95 0.86 0.23 0.01 0.00 3.89
NW 0.76 1.36 0.41 0.08 0.00 0.00 2.61
NNW 0.89 1.29 0.23 0.04 0 00 0.00 2.46
.
TOTAL 25.09 43.19 23.92 7.61 0.19 0.00 100.00
Directional
Nighttime Data (0700-1900)
Sector
A1 mIs A2 mIs B3 m/s D5 m/s D7 m/s F m/s TOTAL
N 0.00 0.00 0.00 0.28 0.00 18.05 18.33
NNE 0.00 0.00 0.00 0.00 0.00 13.14 13.14
NE 0.00 0.00 0.00 0.05 0.00 26.29 26.34
ENE 0.00 0.00 0.00 0.24 0.00 9.50 9.74
E 0.00 0.00 0.00 0.03 0.00 3.49 3.52
ESE 0.00 0.00 0.00 0.00 0.00 4.00 4.00
SE 0.00 0.00 0.00 0.16 0.00 4.33 4.49
SSE 0.00 0.00 0.00 0.15 0.00 3.17 3.32
s 0.00 0.00 0.00 0.10 0.00 2.65 2.75
SSW 0.00 0.00 0.00 0.10 0.02 0.73 0.85
sw 0.00 0.00 0.00 0.17 0.00 1.03 1.10
0.00 0.00 0.00 0.16 0.00 1.33 1.49
-WSW
w 0.00 0.00 0.03 2.31 2.60
0.00 0.26
WNW 0.00 0.00 0.00 0.06 0.00 2.13 2.19
NW 0.00 0.00 0.00 0.08 0.00 2.93 3.01
NNW 0.00 0.00 0.00 0.00 0.00 3.04 3.04
LIOO.
TOTAL 0.00 0.00 0.00 1.84 0.05 98.10 OOJ
risk distanceor risk contour that could reach the populatedarea. Alternatively it
be
could assessed
of using Societal
Risk in the form (F-N)
Frequency-Number curve
which givesthe frequency N
of eventscausing or more fatalities,injuriesor exposure
(AlChE, 1989).
For this study the population density for the two sites was obtained from the
StatisticalDepartmentof Malaysia(SDM). It is basedon the 1991 nation-wide
survey on population density (SDM, 1991). The population density map for a
particular district wasmappedbasedon the total numberof peoplesurveyedwithin a
definedarea. The populationdensityfor the two sitesusedfor this studyis shownin
Appendix 10. The populationdensitymapis capableof giving an indicationof areas
A PhDThesis
byJ.Basri 184
various data banks or literature availableworld wide. Large multinational companies
areresortto in-housedatabankswhencarryingthe QRA.
This situation posed difficulties for a regulating agency like DOSH in Malaysia in
interpreting the risk results for decision making. It is not practical to standardisethe
use of hardware failure rate sincenone of the data banks is truly generic and could be
regulatory and advisory purposes, e.g. advising the local authority on land use
planning matters.
the analysis. In the absenceof specifichardwaredata from the list data from HSE
(HSE, 1989)is used. In the event particulardatais not availablefrom both list the
handbookon processsafetyto (Lees, 1990)is referred.When availablethe DOSH
data is alwaysusedeventhoughthereis differentdata available in HSE data base
and the reference handbook. This approachwill provide some consistencyin the
selectionof generichardwarefailures.
Nominal IHEPs values from TIHERP (Swain and Guttmans, 1983) data base and
BEART (Williams, 1986) data base were also used as input to the FTA. The
also were used as input to the FTA and eventually for the QRA. Results of the QRA
run using BEPs obtained through this method could provide some indication of the
effect of considering Performance Shaping Factor (PSFs) in determining the BEPs.
Sets of nominal BEPs values obtained from the TBERP data base and those
The goal of the study is to estimatepublic risk arising from the handlingof bulk
quantitiesof toxic gas,i.e. anhydrousammoniaat the two sites. Resultsof the risk
estimatesare to be comparedwith a specifiedpublic risk criteria which in this case
will be the probability of fatality to individual (individual risk) and to the public
(societalrisk).
e to estimate the impact of site specific PSMS performance to off-site risk using
PRRvIA Modification Factors
9 Fault Tree Analysis using Fault Tree Manager computer code - for event
frequency estimation and minimum cut set importance (AEA, 1994)
9 RISKAT Computer Code - for release rates, gas dispersion analysis, hazard
rangesand fatality probability (Hurst et al, 1989)
exampleseveralliquid leaks be
can groupedtogether, andseveralvapour leaksplaced
in anothergroup.
results into effect on people in terms of injury or deaths or dangerous dose which
combinesthe two (Nussey et al, 1993). The facility to include mitigating factors such
as sheltering and evacuation,which in real life can reduce the magnitude of the effects
of such incidents provides by RISKAT were also being utilised.
1. Managementbriefing
3. Reviewingdocuments
e operatingprocedures
o maintenance
schedules
0 accidentandnearmissreports
* emergencyresponseplan
process
It is consideredappropriateto use this approachfor the QRA in this study for the
following reasons:
The representative failure set that has been identified using expert judgement that
could lead to off-site risk for the two sitesis shown in Table 6.3 respectively. As can
be seen from the table failures from ammonia storage tanks on-site are not
vehicles are remote. Secondly these tanks are fixed and so not subjected to fatigue
loading from road abuse unlike the road tankers. The tanks are also fitted with
additional safety features such as non-return valves, excess flow valves and
adequately sized pressure relief valves. The steel plate construction with sufficient
notch toughnessproperties also greatly reducedthe possibility of fast fracture. While
it will be essentialto analysethese tank failures in overall risk assessmentfor the site,
it was judged not to be within the risk assessmentboundary of road tanker loading
operation.
3. Guillotine failures of liquid The plant piping arrangementat the two sites made
filling line this type of failures quite credible.Ile most likely
probably due to impact loading from moving
vehiclessuchas lorry and other road tanker as well
asstrengthdegradation of piping.
4. Guillotine failures of vapour Similarly the plant piping arrangementat the two
return line sites madeguillotine failures of vapour return lines
It
possible. could be due to impact loading from
movingvehiclessuchas lorry and other road tanker
andstrengthdegradation of piping
6. Rupture of road tanker above Apart from failures due to impact loading from
liquid line collision as describedabove,the road tanker could
also fail from loss of strengthdue to corrosionor
fatigue. As internalinspectiononly conductedevery
5 years it is quite likely weakeningof the tanker
integrity left undetected. However this type of
failures is more likely to have resultedin hole-type
failures rather than catastrophicrupture of the road
tanker.
For the purpose of the study, hardwarefailure baseevents are made up of component
failures due to physical defects. As an example a faulty content gauge is considered
a hardware failure even though it may be due human error in fixing or calibrating the
gauge.
In essencethe modelling of the failure scenariosusing the FTA was to identify the
influence of human and hardware failures to the overall system failures. The main
objective is to measurethe contribution of both types of error that could lead to large
releases of ammonia which capable of creating off-site risk to the surrounding
population.
Fault tree diagramsfor site A are shown in Appendix 14. Diagrams A14.1 shows the
fault tree for system failure (guillotine failures) due to both hardware failures and
A PhDThesis
byJ.Basri 194
human error failures. Diagrams A14.2 shows the fault tree for system failures due to
hardware failures only. Thesediagramsprovide the basisto compare the contribution
Fault tree diagramsfor site B are shown in Appendix 14. Diagram 14A.3 shows the
fault tree systemfailures of Site B from baseeventswhich are made up of hardware
failures and human error. The top-down decomposition of base events showed
similarity with fault tree for Site A. This is due to the fact that the tasks involved in
the ammonia loading activity at both sites are very similar. Despite being designed
and built by a multinational company the level of automation and safety system
installed for this site is not much higher than Site A. The main difference lies in the
road tanker weighing systemwhich uses a weighbridge equipped with a weight trip
system. This provides an additional safety feature to the system in preventing
overfilling. Diagram 14A.4 shows the system fault tree due to base events from
hardware failures only. The human error contribution to the overall system failure
Results of fault tree analysisusing FTM software for Site A are shown in Table 6.4.
while Table 6.5 shows the result of fault tree analysisfor Site B. The Mnimurn Cut
Set (MCS) importance analysisfor the two sites is shown in Appendix 16. The base
events contribution and some suggestionsfor error reduction for the two sites is
shown in Appendix 17.
Analysisof resultsfor both siteswill be discussedat the systemlevel, i.e. for the
overall system failure from road tanker loading operations, and at sub-systemlevel,
i.e. the majorfailurecomponents
that contributedto the overallsystemfailure.
1. FTA using the BEART and TIHERP nominal human failure rate data yields
higher overall systemfailure rate as compared to those assessedusing SLIM
technique for the humanfailure rate. This suggestedthat the site specific PIFs
that are the major determinantof IHEPsshould be taken into consideration in
determining the systemfailure rate.
2. Results of FTA using PIFs with equal weight and assessedweight in SLIM
4. Minimum Cut Set (MCS) analysis of Site A fault trees shows 3 MCSs
provided the highest contributions to the system failures. The 3 MCS made
up to more than 96% of the contribution to the system failures as shown in
Table A16.1 in Appendix 16. Referring the fault trees for Site A in Diagram
A14.1 show that the baseeventsthat made up these MCSs belong to the sub-
cm
cm
-C
-C
5. At the component level the failure rates of flexible hoses failures were found
to be much higher than tanker and piping failures. Analysing the tree further
showed that guillotine failures of hosesthat could release ammonia from the
road tanker could be not easily isolated by hardware or human intervention.
Operator failures to isolate such releases could arise from the need to
manually shut-off the road tanker valves in the event of guillotine failures of
the hoses. Such action would be likely to have a low degree of successas the
operator would need to work inside the ammonia cloud. Wearing inadequate
PPE like gas mask without air supply, the operator would most likely abandon
the task when he comes under threat of large releases of ammonia from
of the highest contributors for the system failure is base event no. BL21b
which representsthe operator failure in isolating possible leak from guillotine
failure of the flexible liquid hose. This failure scenario would be from the
return valve as it is supposedto receive and to deliver ammonia via the same
valves system. The samebase event also provided the highest contribution of
system failure for the rest of the sensitivity runs. This provides valuable
information when attempting to reducethe off-site risk from the systembased
event of guillotine failure of flexible liquid hose the non-return valve could
prevent ammoniareleasesfrom the road tanker being filled. From the human
error point of view further analysis could provide more insight on how and
why the operator fail to isolate such releasesin the event of hose failures.
The audit interview and site observation revealed that the main reason could
Results of system and sub-system failure rates for Site B calculated using FTM are
1. FTA using the ]HEART and TBERP nominal human failure rate data yields
higher overall system failure rate as compared to those assessedusing SLIM
technique.
2. FTA using hardware only data gives lower systemfailure rate as compared to
thosebeingdecomposed
furtherto hardwareandhumanerror components.It
appearsthe presenceof humanactivitiesincreasesthe likelihood of failure.
This finding reinforcedthe needto considerthe impact of human error in
conductingthe QRA.
3. At the componentlevel the failure rate of flexible hosesis much higher than
road tanker and piping failures. Analysingthe tree further showed that
guillotine failures of hose are difficult to isolate by hardware or human
intervention. This is due to the likelihoodthat the operatorwould haveto
±2
.Z
A
Wi
.
ý_o
4. Similarly Nfinimurn Cut Set (MCS) analysis of Site B fault trees in Table
A16.2 in Appendix 16 showed 3 MCSs that provided the highest
guillotine failure of the flexible liquid hose. Such failure would result in
reverse flow of ammonia from the road tanker to the atmosphere via the
ruptured flexible hose that would be difficult to isolate.
6. The need to limit to External Error Mode (EEM) when comparing the
importance of base events prevented severaltasks being decomposedfurther
to include more sub-components. Treating the human error further into the
Psychological Error Mode (PEM) such as 'memory lapse' would introduce
more uncertainty and make the comparison between the two sites more
difficult.
to Site B. Taking into considerationthat the error factor in the generic hardware
failure rate of vesselsand pipeworks is about by a factor of an order of magnitude
(Hurst et al, 1992) and BEPs which about is about a factor of 3 (Swain and Guttman,
1997) this difference is quite significant.
The two sites possessthe same level of hardware technology so far as ammonia
loading operations to road tanker is concerned. Site B, despite having a more
sophisticated safety system for the rest of the bulking operation, e.g. for rail tanker
and cylinder filling, has a road tanker loading systemequippedwith only basic safety
system. The only major difference in safety systems is the used of a weighbridge
equipped with a weight trip alann that could reduce the likelihood of overfilling.
Comparison of failure probability due to hardware contribution only (as shown in
item no.4 in Table 6.6) shows a very small difference, i. e. of only 0.04. So factors
that created these large differences in the likelihood of the ammonia road tanker
system failures must have been contributed by the non-hardware items, i. e. PSMS
performance or Human Error or both.
2. At the two sites the probabilities of flexible hoses failure provide the highest
contributor to the overall systemfailures. This is due to the fact that hardware failure
rate of flexible hoses from historical data base is higher as compared to piping and
road tanker. The underlying cause of hose failures is because they are of inferior
construction material which make them more susceptibleto rupture due human error,
e.g. and tanker pull-away and due to strength degradation.
Frequency 1780
3.95E-01 2.21E-04
(per year)
Frequency 0.04
LOOE-01 2.34E-02
(per year)
Frequency
6.04E-01 1.28E-01 4.72
(per year)
Frequency
8.69E-02 4.32E-03 0.2
(per year)
Two types of QRA were conducted for both sites. The first run used the
The second RISKAT run for the Site QRA used Fault Tree Modelling. In this
approach major releasesof ammonia that could lead to off-site risk were modelled
using the top-down approach. Using Fault Tree Analysis the top event was
decomposeddown to the base events that could trigger the event. The base events
identified are made of hardware failures such as line valves sticking open, and human
error failures such as the operator failing to close road tanker valves. Hardware
failures values for base eventswere obtainedfrom generic failure rate data from
various sources. The main sourceof datawill be the MalaysianDOSH failure rate
databasethat providesmostof the failureratevalues. In the absenceof certainfailure
rate from this data,failure ratevaluesfrom other sourcessuchasthe U.K. HSE and
SRDData bankareused. As for the humanerror failuresthe SLIM techniqueis used
to generatethe failureprobabilitiesin the form of the BEPs.
Two types of QRA were conductedfor Site A, one using the representativefailure
approachwhile anotherusing the fault tree modelling. Result of QRA runs using
RISKAT softwarefor Site A are shownin Table 6.7. The discussionsof the QRA
resultsfor each type of the analysisaregivenin the following paragraphs.
9 Baseline QRA (Run No. AI) using generic failure rate, i. e. without Modification
Factor show a maximumdistance200 metresto the individual risk values of
IOE-06. This indicatesthe off-site risk to public did go beyond the site's
boundarywhich is approximatelyabout70 metresfrom the loadingbay and will
rA C) C) C)
rn r- Ilt
C)
C) C) C) I Cý I C>
0 0 C> tf) C>
cq 'IT
en IT
tn
o
"0 CD
ý4 00 C)
r- M r-
C>
1.0.
Cy
(4ý
0
.0
6
Z
rA
,I-
CD CD CD 0
CD CD alý CD
00 r- e V')
r-1
(Z C) 0 0
M "0 llt (C)
V ') ri
't le
CD C> C>
00 00
=
ý2L4 r_ 0r_ r- CA
.
4)
t1.
ce
,E.
ýn E
0 .-.
rA
1.0
rn
E: e - E E
x 0 tu lu
:1 0ý c
_ 0. iz-
*U c7 fi-
.ý
- Co
CY
(4-
0
CA
04
01)
< "CJ
< r- r_ <m
90
1-. w) Q ce
(A um
.=
4) m2 .
.
F-
< <
< E, 15 2
>, M Z >% c) 122ý
1. :, (;Z
>Q t; ý,
-
.0 (U 6 ID . S.
vý
m. 1.
Q cn
-ý 0.
h-o r rA
.
CY
00
<
.M
ll,
41
.C
9 Modifying the failure rate using PRR%IAPoor Modification Factor for hoses,
* Result for SocietalRisk for Site A is shownin Table 6.14. The baselineQRA
(Run no. AI) shows a value of F=30E-06, N=20. This suggestedthat there is
thirty times in a million years risk that ammonia releasefrom Site A will lead to
The results of the RISKAT run for Site A are shown in Table 6.7. Discussion on
showed that the IOE-06 level extendedto 400 metres from the loading position of
the road tanker. For Site A this meansthat the a number of factories surrounding
the site will be affected. As the site is located within a light industrial area such
level is consideredto meet the off-site risk criteria. The IOE-07 risk level which is
the criteria for sensitive population, e.g. the school children and elderly extended
to about 630 metres, well away from the nearestpopulation centre located about
1.5 kilometre away from the site.
* QRA sensitivity runs using nominal IHEPsvalues from TBERP (Run No. A5) and
HEART (Run No. A6) data basesshow about the same distance covered by the
IOE-06 risk level as compared to baselineQRA runs, i. e. by about 100 metres. It
appears to suggest that the use of nominal HEI's values without taking into
considerationsthe site specific PIFs do not really affect the off-site QRA result for
Site A.
error components,the QRA results (Run No.A7) also show much longer
individual risk distance. For the IOE-06 risk level the differenceis about 130
metresas comparedto the baseline QRA runs. This suggestedthat the use of
hardwareonly dataresultedin overpredictionof off-siterisk by morethan 30% It
-
appearsthat the introduction of human error componentsinto the Fault Tree
Analysisgavelower failure probability. It could be that human, i.e. the operator
providedsomeform of recoveryfrom hardwarefailures.
calibration points obtained from an HSE study (Run No. A8) showed slight
difference with the baseline QRA results. At IOE-06 level the individual risk
distanceis 460 metresas comparedto 400 metres for the baselinerun, a difference
9A QRA sensitivity run using three APJ calibrationpoints (Run No.A9) was
conductedto checkwhetherthe use of more calibrationpoints would make the
BEPs value more reliable as comparedto the minimumtwo calibration points
suggestedby Kirwan (1994). Resultsshowedfor Site A the differenceis quite
small. At the IOE-06 and IOE-07 risk level the differenceis only about 10%
respectively. At leastfor Site A the useof threecalibrationpoints did not really
resultin significantdifferenceto the off-siterisk.
rate which could dispersethe ammonia rapidly into the upper atmosphere
(Marshallet al, 1995). This is the reasonwhy the baselineQRA showinsignificant
risk level beyondthe 750 metresdistanceas shownin Table 6.8. While the U.K.
weathertendsto be equallydivided in term of weatherclassstability. The day
prevails which representcalm weather where an ammonia cloud could travel over
long distance before natural process of mixing with air reduces its lethal
* Table 6.8 showed that the individual risk distance using the U. K weather data
exceeds the 2 km. The result of this sensitivity run showed the importance of
using site specific weather data. Using another country weather data in the
absenceof local data might result in a significantly wrong estimate of off-site risk
distance.
Societal Risk results for Site A using FTA modelling are shown in Table 6.9. The
baselineQRA (Run No. A4) shows a value of F=150E-06, N=20. This suggested
releasesfrom Site A will lead to dangerous dose exposure that will affect 20
personsor more.
000
Ix
C4
; 0.
.4--a
0
ý.
ow
-0
Wý
=
"o
.- 0
C)
. ce
40
Q
rA
ij
0
i'.'
0
.tl
1.0.
CY
W,
W)
W-4
f4
CD CD
"0 0
CD
0 CD
u U- 11 CD
0 (Z k/) (Z
4
ý4 4
Z'
-,
t. -m9
t. E-0.
GA
:i
9) JX
1.. o
6. 6.-
0
+ý
CJ Z0
-- 9==in,
w ce -- ý: 0
CM-v
a2 l E
.. ý
ci d.-
0>
0
P., 0r .
-
2
ý
ýo 0.ý u
:3 '-, D; 0
CA
(A
o.
'. cy. 2 ci [-,
Co u.
rA
0 v +ý
< =
r_ c: >
00
.0
0
Z
4 ll% b'n b-
f4
6.6.2. Discussionon QRA Resultsfor Site B
Two types of QRA were conductedfor Site B, one used the representativefailure
approachwhile anotherusing the fault tree modelling.Results of QRA run using
RISKAT softwarefor Site A are shownin Table6.10. The discussionsof the QRA
resultsfor eachtype of the analysisaregivenin the following paragraphs.
4P As the PSMS perfonnance of Site B was assessedto be Average, the QRA result
(Run No. 131) using the generic failure rate, i. e. without Modification Factor is
portioned of the Animal Feedmill factory next door. However the level of risk
did not go beyond the industrial estate to the populated area that are located
At IOE-07 individual risk level the contour almost reacheda half kilometre
distance.Howeverthis distancestill fell shortof the populatedareaasthe nearest
housingestatewheretherearechildrenandelderlyis about3 km from the site.
* Table 6.12 shows the results of Societal Risk for Site B. The baseline QRA
(Run No. BI) shows a value of F=70E-06, N=30. This suggested that there
e Societal risk for the Modified QRA using Poor W (Run No. B2) shows an
increase in frequency (F) by about a factor of 2. As this supposed to be the
actual risk value for Site B after taking into considerationsite specific W, the use
of generic failure rate resulted an underprediction off-site risk by a factor of two
from the societal risk point of view.
Results of the RISKAT run using the approachis given in Table 6.10. Discussion of
* Baseline QRA run (Run No. B4) using HEPs generatedfrom SLIM using APJ
The IOE-07 risk level which is the criteria for sensitivepopulation, e.g. the
schoolchildrenand elderlyextendedto about half a kilometrewell away from
the nearestpopulationlocatedabout3 kilometresawayfrom the site risk.
(A
4-.
to
CY
td.
0
GO2
4)
iz
.0
.m
CN
V-4
r14
m
9)
40.
rA
I
QRA runs using nominal IHEPsvalues from THERP (Run No. BS) and BEART
(Run No. B6) data bases show much longer distance covered by the IOE-06
individual risk level as comparedto baselineQRA runs, i. e. by about 100 metres or
40%. This indicates that the IHEPsvalue has considerableinfluence on the QRA
results. It also suggeststhat the use of nominal BEPs values without taking into
metresas comparedto the baseline QRA runs. This suggeststhat the use of
hardwareonly data resultedan overpredictionof off-sitc risk by about 45%. It
9A QRA sensitivity run (Run No. B8) using BEPs value derived from SLIM
techniquesusing APJ calibration points obtainedfrom an HSE study (HSE,
1989c)showedsomedifferencewith the baselineQRA results. At IOE-06 level
the individual risk distanceis 310 metresas comparedto 270 metres for the
baselineruns,a differenceof about40 metresor about 13%. This suggeststhat
the calibrationpointsjudged usingAPJ methodfor the baseline QRA was not far
out from thosejudgedby the expertsconductingthe HSE study.
eA QRA sensitivity run using three APJ calibration points (Run No. B9) was
conductedto checkwhetherthe use of more calibrationpoints would make the
IHEPsvalueasderivedfrom SLIM morereliableascomparedto the minimumtwo
calibrationpointsas suggested by Kirwan (1994). Resultsshowedfor Site B the
differenceis quite small. At the IOE-06risk level the differenceis only about 10
metresor a mere2%. As for Site A the use of three calibrationpoints did not
reallyresultin significantdifferenceto the off-site risk for SiteB.
using this weather data show a very significant difference as compared to the
baseline QRA using Malaysian weather data. While the distance to the IOE-05
risk level differs only by about 7%, the IOE-06 risk level differs by 275 metres or
a factor of 2. The differenceto IOE-07 risk level distanceis even higher which is
about 750 metres or about by a factor of 8. These differences are comparable to
that of Site A. This showed a consistentimpact of using the U. K. weather data for
the two sites. As discussedearlier the Malaysian weather data were dominated by
Class A and B which indicates very unstable weather conditions with high lapse
rate that could disperse the ammonia rapidly into the upper atmosphere. That
explained why the baseline QRA show insignificant risk level beyond the 750
metres distance as shown in Table 6.11. The U. K. weather tends to be equally
representedin term of weatherclassstability. ClassA to D dominatedthe day
time weathercategorieswhich promoterapid dispersionof ammonia. During the
night calmweatherpersists,i.e. ClassE to G weathercategory,where ammonia
cloud could travel over a long distancebeforenaturalprocessof mixing with air
reducesits toxic concentration.Table6.18 showedthat the I OE-06individualrisk
distanceusing the UX weatherdata could reachedI km from the releasepoint.
Result of this sensitivity run once again showedthe importanceof using site
CD
CD CD 0 0
CD C)
(Z
CD CD C) 0
CD
CD CD
CD
C>
m C CD
CD
cc; c;
00 e aN
CD 0
CD 0 CD
ý2.
CD CD
CD
JW rn - CD
Gn
c;
V') M
l= (=) all
coi cý
\Z tA
f4.
0
rA
5 r- tu
= (A
(1) . 0 . 92
GeýGA
'Z
M ce
ZM
E ý9
ei
-0 U- ,ýd CU
-b-
iz
"Z
*-
" 0 CZ
:1 Q)
91 "ri
0 &) 4)
2
"0
tQ Gn
,im 10
00 (L)
(A
ý-
m *0
0 Z 5 E.
ýý
rA
0
*d
X
:1 r. -GA
:s t. '
t. *,r-
7;
ý
)..
=$
< 2 En
CY
GA
ý- *2E
21
[-. =Em
w. a-0C
fi 1. 9) 10 4 0
C. *
Gn C:6 (V : . ttz -7i
X -Z ý.
a r
- 0
0
Zc>
6
V*
l'C
11.1
m
eq
0.
t.
Ici
Gn
.0
. r6
an
.0
22
19
IT
eq
40.
CA
(L)
JD
11.3
Societalrisk results for SiteB usingFTA modellingis shownin Table 6.12. The
baselineQRA (Runno. B4) showsa valueof F=2.3E-03,N=30. This suggeststhat
therewould be 23 incidentsin ten thousandyearsthat ammoniareleasesfrom Site
B will leadexposureto dangerousdoseaffectingpersonsor more. Comparingthis
figure with baselineQRA using representative
failuresapproach(Run no.B I) of
70E-06 shows a difference of about a factor of about 30.
represent the failure rate of an averageplant. However the PR1MA Audit results
show that Site A PSMS performance fall under Poor category hence a Poor
Management Factor (W) should be applied to the generic failure rate. The QRA
results of the two scenarios(Run No. A2 for Site A and Run No. BI for Site B)
would represent the 'true' off-site risk level, i. e. after considering the site specific
PSMS performance. Analysing the QRA results between the two shows a
significant difference. At individual risk levels of I OE-05, I OE-06 and I OE-07 the
risk values of Site A are higher than Site B by about 60%, 35% and 23%
respectively. Theseresults suggestthat the off-site risk from ammonia road tanker
loading operations posed by Site A is higher than Site B. Given an almost similar
level of hardware technology, the factor that influencesthe QRA results would be
the site specific PSMA performance. The results provide a positive indication on
the needto consider the influence of site specific PSMS performanceto the off-site
risk.
Analysing the QRA results for Site A and Site B using this approach yields a number
9 Comparing the base line runs for the two sites shows that the overall individual
risk level distancefor Site A (Run No. A4) is higher than Site B (Run No.B4).
The risk valuesof Site A arehigherthan SiteB in term of individualrisk level at
IOE-05, IOE-06and IOE-07by about90%, 30% and 30% respectively. These
results suggestthat off-site risk from Site A is slightly higher than Site B. As
mentionedearliergiven the sametype of activity conductedat the two sitesand
the use of almost similar hardwaretechnologythese results pointed out to
possibledifferencesin the levelof IHEPs.The IHEPsvaluesare largelyinfluenced
by site specificPIFs suchthe quality of operatingprocedures,experienceand
training which alsofactorsthat influencethe site specificPSMS performance.As
9 The QRA runs using nominalHEPs from THERP and HEART data basesshow
smalldifferencesbetweenthe two sites.UsingTHERP databaserate (RunNo.A5
and B5) the differencein individualrisk level at IOE-05, IOE-06 and IOE-07 is
only 21%, 8% and 12% respectively.As for the HEART data base rate (Run
No.A6 andB6) the differencein individualrisk level at I OE-05,I OE-06and I OE-
07 is only 18%, 2% and 23% respectively.Sincethe samevaluesof BEPs are
used for both sites the differencesin the off-site risk would be most likely
contributedby the genericfailurerate.
* The final runs using the baselineQRA but with U.K. weatherdata also indicate
that Site A off-site risk is higherthan SiteB. In fact this QRA run providesthe
biggestdifferenceon the individualrisk level distance.At individualrisk level of
IOE-05, IOE-06 and IOE-07 the risk value of Site A is higher than Site B by
about 80%, 58%, and 50% respectively.The results support the need to give
priority in developingmoreaccuratesitespecificor countryspecificweatherdata
asits impacton off-site risk is morepronounced.
"0
(A
ý4
ý5 --, 42
14
.
10
M
1.
6.6.4.1 The impact of PSMS performance on QRA results
The analysisNo. 1 and 2 in Table 6.13 showed that the difference of QRA results
of 4 for generic failure rate of pipework for Site A (Table 4.5, page 104 in Chapter
4) is translated into a difference of a factor of 2 in the QRA results.
As for Site B the differenceof the QRA results is about a factor of 1.2. The
differenceof ManagementFactor of abouta factor of 1.2 for genericfailure rate of
comparing results as shown in analysisNo. 3 and No. 4 in Table 6.13. For Site A the
analysis that did not take into consideration of Human Error in carrying out the
ammonia road tanker loading operation provided higher off-site risk than the one that
does, by a factor of about 1.2. The result implies that Human Error provides positive
As for Site B the QRA result is higherby a factor of about 1.2 when considering
HumanError as baseeventsbesidethe hardwarefailures in Fault Tree Modelling.
Similarlyone possibleexplanationis that the higherlevel of processautomationfor
6.7 Conclusions
* THERP and HEART nominal data bases provide an equivalent of the generic
humanerror rates or humanerror probabilityor IHEPs,while SLIM generated
IHEPsis a meansto explicitly consideredthe site specific managementand
organisationalinfluenceson BEPs. As shownin Table 6.13 results of off-site
risk using these'generichumanerror rates' for Site A is lower as comparedto
the oneusingSLIM generatedhumanerror rates. While resultsof QRA run using
these'generichumanerror rates'for Site B showedalmostthe sameoff-site risk
valuesascomparedto usingSLIM generatedhumanerror rates. Eventhoughfar
from conclusivethe resultscouldimply a neutralto negativeeffect (not a positive
7.1 Introduction
PSMS are made up of comprehensive set of policies, procedures, and practices
designedto ensure that barrier to process incidents are in place, in use and effective
(AIM, 1993). This implied the requirement for an effective interaction between
procedures, human and organisation. As such some form of site specific common
factors will influence both the PSMS and human performance. The interplay between
these factors is fairly complex as its involved the multiple interaction at many levels
(Moieni, 1993) in a fonnat known as 'many to many mappings' (Embrey, 1992 ).
For example ineffective feedback from operational experience could not only affect
the quality of training programme but it also could make the existing operating
considered in assessingits performance for a particular site. As for the BEA these
factors are called PerformanceInfluencing Factors that influence the human/operators
for successful execution of a particular task. Assessing both attributes using a
common field auditing technique such as PRRVfA would enable the efficient use of
resources,which is critical in developing countries.
gathered through other means such as site inspection and document reviews. This
enabled the comprehensivenessof the PREWA audit questionnaires to be examined
independently, minus the expert judgement input that needed to form the PSMS
control loops. To find out the feasibility of such approach PIFs that have been
selectedfor the quantification of Human Error of the two sites namely Experience,
Procedures, Stress and Feedback study were analysed. Results of the analysis using
information gathered through PRIMA questionnairesfor Site A and for Site B is
>
<
2 g2 E i2 EI L'
...
< 12. <<- 0. iz. 0. < 0. J.
ý
c,
>
< <ý<
92
>
Z<
Z< Z
LLý v
9) ý utn ZK A (4) = '
ZK 45 (A <<
C 2
n.
=
:>:
0 4)
>- Z::
9) (U
>.
0
Z >. ::
9) uu uu
ý
>« ý :
12.e m :
cis
00u 9) 0 0u (A = vi
00u
ZZ :ZZ ZZ :Z:
"a
fA tA
U02
(A Z<<
lý
Kn
u
ý-
V)
uýý
(A Z
'ý
u0u0=A=
fA rA
000
Z : ZZ :ZZZ
rA
ýjo -2 -
(u - 91> zm - 9) - u -U -0 mzzz -u -u -u -u
r. >>> > >>
0
21
.8
0
rA
j3 .5
rA <<<
ZZ <<< Z<<<
CJ2 Gn r. ? ýýý ýý1. jý ý
U. -- r.
0
:Z .Z
JD (A 0 2>2 2.
(n 3e .2
-' -2
u OUO
t
rA
GA
z<
0
b. w U
10
en
Lo (14
gi
0 000 ho 0
EEE! ILI
= (A (A ýto =
00
fA (A
4)
(A
4)
Z. ýZ, 2. O=j
0-
It m C14 to'l It m t14 W) It m C14 tn qt en C4
--- ---- ---- ----
r_
.2 -8
I.T. E
zzzzzz 000
.0
(A *2
tn
1,, II,, Ii,, IIII
-t m C-4 wl ,tm C-4 wl --t m-., -ýt m C-4
----------------
8p=
rA
(V
rA
rA
ce
000
12. '. >2 ZZZ
0
.1
>.ZZ >ý
w
Iýt C.) r4
5,0.8
(A0
IV
M
ce
<<<
=- <<<Z<<
"' , un
,0u -0 v) z. '.' r. .. 0
"0
.-'M
,' 'm .-
(A m=
9
:J=u9
,2H=uZ -12
12 a«
m9=
9e1ýg
1
"0 rr V
z< .0
22
t
c
,2U&.
w (i Z I1
uZ00w
PIFs rating obtained using this approach is then compared with PIFs assessedsolely
using auditor judgement as obtained from Table 5.15 Section 5.4.4 in Chapter 5 and
shown in Table 7.3. As can be seen from the table PEFsrating as assessedusing
PRIMA Audit results differs on Stressfor Site A and on Experience for Site B. Even
that the differenceis smalli.e. from Averageto Poor for Stress(Site A) and Good to
Averagefor Experience(Site B). This indicatesthat basedon the four PIFs under
i. Feedbackand Stress,the informationmade
consideration e. Experience,Procedures,
available in PRIMA Audit results is quite adequate to rate the site specific PIE
However the four PlFs under considerationi.e. Experience,Procedures,Feedback
and Stressare commonfactors that influencehumanerror on majority of tasks in
chemical process engineering environment. It remains to be seen whether PRIMA
audit resultscould also provide similar informationfor other PIFs such Distraction
andTaskComplexity.
Table 7.3. Comparing PIFs assessedusing PRRVIAAudit results with PIF assessed
using auditor'sjudgement
PlFs Rating from PlFs Rating PIFs Rating from PlFs Rating
PRIMA Audit using auditor PRIMA Audit using auditor
iudgement judgement
Experience Average Average Average Good
operator alert but not created undue stress) and the lowest would be I (too little
stress that to keep the operator alert). The ideal values for SLIM used by Gertman
(1994) and Chien (1992) is shown in Figure 7.1.
By using the ideal value as the maximum value for 'good' and the associate lowest
range of scale as maximum value for 'poor', a quantitative scale could be made from
the qualitative input as shown in the Figure 7.1. This quantitative scale then could be
used for example for apportioning weighting of PIFs contribution in SLIM technique.
However difficulty arised when deciding the scale for stress as it has a different ideal
method for Site A is shown in Table 7.4. For example the qualitative rating of
Procedures for Site A is judged to be Poor indicating that it will have small
successin executing a particular task. In this case the weighting for Experience on
SLI is higher as reflected by a value of 0.36.
00 00 00 00 00 00
\o %D ýo IND %D ýo
E- \o
vi &A kn V) Vlb kn
vl
,Z
m m m
4) m M
10
0
402
Ici
0 u
(4-4
0
J.,
0
L.
.2 L) E
P.4 b 8
-0
-i a to 8 U 0
Ei 0 c)
A -
Ei
8
1 L, I<ci 2
P.4 F- cn 10
_-; cli cl; 1.2: kei %d r.:
Z)
9
For comparison purposes the weighting obtained using the quantification of PIFs
rating from PRIMA Audit results is compared with the weighted assignedfor these
PIFs using expert judgement as describein Section 5.5.4 of Chapter 5 (Table 5.19) as
in
given the last column of Table 7.4. The difference for PIFs weighting is quite small
for all the PEFsindicating someform of agreementbetween the two approaches.
method for Site B is shown in Table 7.5. For comparisonthe weighting assignedfor
thesePIFs using expertjudgementas describein Section5.5.4 of Chapter5 (Table
5.19) Chapter 5 is given in the last column of Table 7.5. Similarly the difference for
PIFs weighting is also quite small. However between the two approaches, at for
least for the four PIFs under consideration,the conversionmethod using PRIMA
Audit resultsprovidebettertransparencyas it is basedon all the informationgathered
throughthe audit questionnaires.
assessment. This is due to the fact that each task comes under a different degree of
influences from eachPlFs as being discussin detail under the topic of PIF analysis in
Chapter S. Thus the usefulnessof PIF analysis using PRIMA Audit questionnaires
7.6 Conclusions
In conclusion the PRIMA audit questionnairewas found able to address a number of
areasthat could provide basic information to determine the overall or 'global' PIFs
influence, at least for the four PIFs under consideration. However it is less rigorous
as compared to the dedicated PIF analysissuch that has been carried out in Section
8.1 Introduction
This chapterpresentsthe outcomeof the overallresearch.The outcomeis presented
underthreedifferentheadings
namelyfinding, for
suggestions further work and finally
the conclusions.
8.2 Findings
A discussionof the salientpointsfrom findingsof the overallresearchis given below.
The discussionis madeundereachmajorheadingof the researchcomponentfor ease
of explanation.The aim of this discussionis to highlightkey researchfindingsbased
on findingsfrom the threedifferent namely
researchareas PSMS,BEA and QRA.
Results from the analysis of PSMS for the 3 sites using the PRIMA technique show
A PhDThesisbyJ.Basri 242
owner,
multinational recentmanagement structurechangehas deprivedthe site with
the resourcesneededto maintainan aboveaveragePSMS. This is especiallytrue in
term of the absenceof dedicated Safety Department specialistssuch as the
instrumentationandelectricaltechnicians.
The best PSMS performance among the 3 sites is Site A. This site was assessedto
have a ManagementFactor of 0.4 using the PRROA assessment.This site was able to
retain most of the Safety Management structure and human resources laid down by
the previous multinational owner. The key contribution to the site's good PSMS
supporting technicians.
The main strengths and weaknessesof the locally owned plant, i. e. Site A as assessed
using PRRvIA technique are given below. Evidence of these findings is given in
Strength
Weaknesses
* fairly high turnover of operator and supporting staff due tight labour market,
experiencedworkers move to new sites which offer better wages and less
hazardousworking conditions, e.g. at electronic componentsassembly.
The main strengthsand weaknessesof PSMS Sites owned by multinational are given
below. Evidence of these finding could be found in Section 4.5.2(ii) and 4.5.2(iii) in
Chapter 4 and in Table 5.15 Section 5.4.4 in Chapter 5.
Strengths
0 Possesses
well trainedpersonnelwhich havestayedwith the companysince its
inception
Weaknesses
personnel including safety in the near future. The policy of not replacing retired
work standardandbecame
traininggroundof manytechnical who
personnel work for
At the same time the company also introduced a fixed division of work into
departmentslike operation and technical support which includes project, maintenance,
electrical and instrumentation and safety. Technical personnel who joined the
company are put under apprenticeshipstyle of training under the specific department
for a lifetime long career. This type of training producesworkers with good specialist
knowledge and worked well in large scaleorganisationwith non-competitive business
Despite carrying out a similar task, i. e. ammonia road tanker loading operation the
effectivenessof the plan and proceduresused to execute the task is different between
the two sites. Evidence to support the findings can be seenfrom the summary of PIF
The Hierarchical Task Analysis (HTA) has revealedthat Site B has a better work plan
availability.
The research showed that PIFs situations differ on the two sites. Evidence to
support the findings can be seen from the summary of PIF analysis in Table 5.15,
the detailed PIF analysis in Appendix 6 and PSMS audit results in Section 4.5.2 of
Chapter 4. The difference for eachof PIF under considerationis given as follows;
o Experience
SiteB operatorhasbetterexperience
than Site A. Good training programme,low
turnoverfrom job securityandjob specialisationof operatorat SiteB contributed
to this factor. Howeverthe multi-skillingapproachbeing implementedon Site A
0 Procedure
effort to up date the resourcesregularly. It was also noted that this trend
beginningto take placeat SightB.
0 Stress
* Feedback
manual operations.
Results from the PIHEA conducted showed that use of consequences(i. e. severity
and frequency) provides a simple and effective means to predict tasks that under
strong influence of human error. However lack of site specific information on the
two attributes, e.g. from accidents or near miss records forced the use of expert
judgement which at best lacks transparency. For both sites tasks associatedwith the
reduce the impact of human error through the appropriate error reduction strategies.
The recommendationsmade vary for the two sites depending on PSMS available on
each site as shown in Table 5.13 and Table 5.14. Using PRRVIA technique the
relevant key audit areas and the control loop levels within the PSMS for each site
could be determined. This approach also indicated one possible means to integrate
human error with PSMS.
Proper selection of PIFs is important as they provided the basis for determining the
IHEPsvalues. Assigning appropriate rating of these PIFs for each tasks also needs
careful judgement as shown in Table 5.17 and Table 5.18. This could only make
possible by a thorough qualitative analysis prior to human error quantification
exercises.Evidence to support the findings can be seenin Table 5.22 and Table 5.23.
Selecting appropriate calibration points for IHEPscalculation using SLIM was found
runs using calibration points obtained from various sources showed a maximum
difference is about a factor of 30 for the values of IHEPscalculated as shown in Table
Results of BEPs calculated using SLIM techniques in Table 5.22 and Table 5.23
showed that Site A has higher value of IHEPs,as compared to Site B for identical
tasks. This finding suggestedthat the ammoniaroad tanker loading operation Site A
is subject to a higher influence of humanerror as comparedto Site B.
8.2.11 Site specific PSMS performance increases off-site risk for Site A
Results of QRA run using RISKAT software are shown in Table 6.16 for Site A and
Table 6.18 for Site B. Analysis of the results yield the following findings:
Off-site risk calculatedby RISKAT using generic failure rate for Site A was less when
shown in Table 6.16. The difference of risk results between baseline QRA using
generic failure rate, i. e. without Modification Factor (Run No. AI) and the one using
Poor Modification (Run No. A2) is about a factor of 2 or 200% based on individual
risk distance of 10E-06. As Site A is judged to have poor PSMS performance, the
use of generic failure rate for QRA underestimatedthe actual risk posed by ammonia
road tanker loading operation.
8.2.12 Site specific PSMS performance does not affect off-site risk for Site B
rate for QRA is appropriate. These mean that site specific PSMS performance does
not affect off-site risk for Site B. This evidenceis shown in Table 6.16. However any
attempt to equate its PSMS performance with Site C which belongs to same owner
will have resulted in underestimatingthe actual risk posed by ammonia road tanker
loading operation by about a factor of almost 4. This can be seen when comparing
the difference of risk results between baseline QRA using generic failure rate, i. e.
without Modification Factor (Run No. B I) and the one using Good Modification
(Run No. B3) which is about a factor of 4 based on individual risk distance of
IOE-06. This showed that even though the two sites belong to the same owner they
A PhD Thesisby J.Basrl 249
not necessarilypossessimilarPSMS performance. So there is a needto conduct a
separatePSMS audit for eachsite to avoid making a wrong assumption.
The site specific weather data is one the most dominant factor influencing the off-site
risk level at the two sites. The evidence can be seen at individual risk distance of
IOE-06 from in Table 6.16 for Site A and from in Table 6.19 for Site B. For Site A
the use of UX weather data (Run No. AlO) resulted an overprediction by a factor of
3 when compared to baselineQRA using FTA approach in Run No. A4. Meanwhile
for Site B the use of UX weather data (Run No. B 10) resulted an overprediction by a
factor of about 2 when compared to baseline QRA using FTA approach in Run
No. B4. So more resources should be allocated in establishing such data if fairly
accurate and reliable QRA results need to be used to assist decision making, e.g. for
land use planning. This finding seemsto agreewith findings by other researchersuch
as Kukkonen (Kukkonen et al, 1993) and Marshall (Marshall et al, 1995). This is
especiallytrue in developing countries with a lack of reliable weather data for QRA in
place. Any developing country still without the necessarylocal weather data should
make its development of top priority when QRA is used as a tool to assist decision
TIHERP and HEART nominal data baseprovides an equivalent of the generic human
such as work stress, training and experience of personnel and availability of good
operating procedures on IHEPs.Result of QRA runs using these 'generic human error
rates' for Site A showed a higher off-site risk values by a factor of about 1.2 as
compared to using SLIM generatedhuman error rates. However result of QRA runs
using these 'generic human error rates' for Site B showed almost the same off-site
risk values as comparedto using SLIM generatedhuman error rates. Such evidences
can be seenin Table 6.7 (Runs No. A5 and A6) for Site A and Table 6.10 (Runs No.
B5 and B6) for Site B and their summaryin Table 6.13. Eventhough the difference is
site specific generic failure rate which takes into account the site specific PSMS
performance. Results of QRA using these factors showed a significant difference of
off-site risk for Site A which was assessedto have a Poor PSMS performance in
term of individual risk, increasedby a about a factor of 2. Site B which was assessed
to have an Average PSMS performance in term of individual risk showed only a
Similarly the SLIM calculatedBEPs that takes into considerationthe site specific
factors that influencedhuman error rates. While TIHERPand BEART databases
providedthe generichumanerror rates. Comparingthe off-site risk resultsfor site A
using the genericandsite specificBEPs showed a differenceof about a factor of 1.2
while Site B showedinsignificantdifferences.The resultsshowedthat similarto site
specificPSMS performance,the site specifichumanerror ratesalso affect the QRA
results(increasethe risk) eventhoughlesspronouncesthan the former.
As such the results appearto suggestthat despite its simplistic approach, the PRIMA
Audit technique seem capable of predicting the direction of effect of site specific
-p PRIMA audit, SLIM and RISKA T were found suilable to be usedfor developing
partly successfulat least at the organisational (global) level, which could be used
to provide 'weighting' (as in SLIM) for an overall PIF influence. However the
The following further works are suggestedfor PSMS audit using PRIMA;
complex process system) than ammonia loading operations will provide similar
results. Secondlywhether NEM ownedby big Malaysiannational corporationPSMS
performanceis similarto thoseownedby the multinational.Thirdly by what marginis
the risk from MFH that handlesflammableand explosive hazards(such as gas
by
processingplant) would affected PSMSperformance.So by conductingmore
be
audits on a cross sectionof other WH installationssome of the above mentioned
questionscouldbe answered.
Modification factors used in PRRvfA to modify generic failure rate currently is based
Malaysia the percentageof contribution of eachkey audit area may differ significantly
as suggestedthe current data base. This could be due to different quality of design,
The contributionof humanerror on off-site risk in the study was obtainedusing the
SLIM technique.Theuseof othertechniquesuchasBEART or TIHERPwill provide
different set of IHEPsvalueson humanactivity associatedwith ammoniaroad tanker
loading operations.These IHEPsvalues then could be comparedwith the ones
obtainedusing SLIM techniqueand checkingthe differencesof off-site risk results
whenusingthesevaluesasinput for QRA.
c. Compare ORA results using PSMS Management Factor and QRA using vdth
site specific failure rate using processsafejy hardware approach
HSE has carried out an initial study where the site specificfailure rate is modified
The current research look at the possibility of linking the PSMS assessmentwith
Human Errror assessmentthrough Performance Influencing Factor (PIFs). Site
specific PIFs are shaped by the characteristicsof people, tasks and organisation that
influence human performance. As PRRVIA audit also looks for similar factors to
assesssite specific PSMS performance this information could be used to evaluate the
Engineers.New York.
Allum, S. and Wells, G.F. (1993). Short-Cut Risk Assessment. Trans IChemE, Vol
71, Part B, August 1993.
Barnes, M. (1990). TheHinkeley Point Public Inquires, Vol.6, The risk of accidents
Bellamy, L. J., Geyer T. A. W., and Astley J.A. (1989). Evaluation of the Hunian
a SafetyManagement
Auditfor Incorporationinto QuantitativeRiskAssessment.
In InternationalProcessSafetyManagement
Workshop,22-24 September.
A PhD Thesisby J.Basri 258
CEC(1995). Auditing and Safety Managementfor Safe Operations and Land Use
Planning: A Cross-National Comparison and Validation Exercises. A Report
for the Commissionof the European Community. 20 December 1995.
Comer, M. K., Kozinsky, E. J., Eckel, J.S. and Miller D. P. Human reliability Data
Bank for Nuclear Power Plant Operation:A Data Batik Conceptand System
Description. NUREG/CR-3518. UNRC. Washington D. C.
Cullen, S.J. (1994). Health and Safety: A Burden on Business?. Process Safety and
Environmental Protection Journal, VoL 72, No Bl. p3-9. February 1994.
Deshotels, R., and Dejmek, M. (1995). Choosing the Level of Detail for Hazard
Identification. ProcessSafetyProgress.Vol. 14, No. 3. July 1995. pp218-224
DOP (1990). Risk Criteriafor land UsePlanning. New South Wales Department of
Planning (DOP).
DOSH (1994). The Occupational Safety and Health at Work Act 1994. Malaysian
Government. Government's Printer 1994.
DOSH(1996) StatislikPembaikaiiDatidatigdatiPetigatidiiiigTekatiatiTakBerapi
Ibu Pejabat 1990 - 1996 (Repair of Boilers and Unfired Pressure Vessels -
DOSHHQ Statistics1990-1996.Departmentof OccupationalSafetyand Health,
Malaysia.
Embrey, D. E., Humphreys, P.C., Rosa, E. A., Kirwan, N., and Rea, K. (1984). SLIM-
MAUD: An Approach to AssessingHuman Error Probabilities Using Structured
Expert Judgement.NUREGICR-3518. USNCR. Washington D. C.
Instituteof Chen-dcal
Engineers,New York.
FMD (1967). Yhe Factories and Machinery Act 1967. Malaysian Govemment.
Goverment's Printer 1970.
HSE (1974). Health and Safety Work etc, Act 1974. HMSO Publication. London.
HSE (1989). Risk Criteriafor Land UsePlanning in the Vicinity ofMajor Industrial
Hazards.HMSO PublicationsLondon.
HSE (1989b). Human Factors in Industrial Safety. HSE Safety Booklet HS(G)48.
HMSO Publications London.
HSE (1989c). Risk Assessmentof the Chlorine Road Tanker Loading Operation at
Hays Chemical Lid, Sandbach Cheshire. HSE Internal Report No.
HSE/SRD/8/l/89.
Hurst, N. W. (1992). N. W.Hurst, R.K. S Hankin, J.A. Wilkinson, C.Nussey and J.C.
Hurst, N. W., Stephen,Y., Donald. I., Gibson, H., Muysellar, A. (1996). Measures
Kukkonen, A. L., Savolainen, A. L., Valkarna, I., S. Junto., and T. Vesala., (1993).
Long-rangeTransportof AmmoniaReleasedin Major Chemical Accidentsat
Ionava, Lithuania. Journal of HazardousMaterials, 35 (1993). Elsivier Science
PublishersB.V., Amsterdam
Kirwan, B., Martin B., Rycraft, H., and Smith, A (1990). Human Error Data
MEHLG (1992). Royal Enquiry on Bright Sparkler Fire and aplosion Report.
Ministry of HousingandLocal Goverment of Malaysia.
MIHLG (1994). Public Enquiry on Shell Dram Kimia Fire and aplosion Report.
Ministry of Housing and Local Goverment of Malaysia
Nussey. C., Pantony, M. F., Smallwood, R.J. (1993). Health and Safety aecutives
Risk AssessmentTool RISKA T. Trans IChernE, Vol 7 1, Part B, February 1993.
pp29-40.
Pape, R.P. and Nussey C., (1985). Assessmentof Control of Major Hazards.
IChemE SymposiumSeriesNo. 93
andMaintainability.Volume4.
and Rail. Joumal of Hazardous Materials Vol. 33 No. 2. February 1993. pp229-
259
p311-335.
Taylor, J.R. (1994). Risk Analysisfor Plant, Pipelines and Transport. London:
Turner, R.M. and Fairhurst, S., 1989, HSE, Specialist Inspector Report No.21,
Bootle U.K.