Professional Documents
Culture Documents
5-Risk Assessment Methods For Vapour-Cloud Explosions
5-Risk Assessment Methods For Vapour-Cloud Explosions
5-Risk Assessment Methods For Vapour-Cloud Explosions
00/0
Pergamon Press Ltd,, 1~80 Printed in Great Britain
167
168 L. CAVE
used extensively in the aerospace industries, and to a In this step it will be necessary to consider the
limited extent in the nuclear power industry (e.g. see risk to people separately from that to pro-
Ref. 2), there has been a marked reluctance on the part perty, and it may be desirable to consider the
of regulating bodies for other industries in most general public separately from the plant per-
countries to define their requirements in this fashion. sonnel, and the plant damage separately from
For example, in the United Kingdom it has taken some the damage to third-party property.
15 years to get some recognition of the need to define Step 6. Decide whether the estimated risk is ac-
the requirements for nuclear safety in this way, and ceptable, or whether the plant should be
even today those requirements are partially obscured modified.
by references to the need to achieve "that standard of
The methodology for each of these steps exists today
safety which is reasonably practicable". However, in
and is outlined in later parts of this paper. However, it
the chemical and petrochemical industries it does seem
will probably be obvious that for a complex, poten-
that the work of the Major Hazards Committee may
tially hazardous plant, the amount of analysis involved
lead to some clarification of requirements in the U.K. 3
could be very considerable, whereas for a relatively
In Holland, also, this approach has been adopted in
simple source of risk such as a natural gas pipeline, the
relation to some aspects of the chemical engineering
effort required could be less by a factor often or more.
industry. 4 The problems of defining an acceptable
In the nuclear-power field there have been several
standard of safety are discussed in Section 8, below.
studies of this type, some as "direct" risk assessments of
2. R I S K A S S E S S M E N T P R O C E D U R E S existing plants, such as the Rasmussen report referred
to above; others have been made for nuclear power
Although this paper is concerned primarily with the stations that have been fully developed without the use
risks presented by vapour-cloud explosions, it is of reliability analysis, but not yet constructed, and
desirable to look initially at the overall problem of risk there have been others of the "inverse" type in order to
assessment for complex installations, which could give define the design. The Rasmussen study took some
rise to a variety of harmful consequences, in order
three years and cost some $3 million. However, a large
to put those due to vapour-cloud explosions in
proportion of the results can be applied directly to the
perspective. evaluation of the risks from other nuclear plant of the
The main steps in a risk assessment are as follows : same type.
Step 1. Identify potential sources ofhazard to people, In the United States, studies of this type have now
property and the remainder of the plant. The become necessary to support planning applications for
more important effects which are likely to potentially hazardous non-nuclear installations such
need consideration are as follows: as L N G terminals: it has been said that risk assess-
(1) Blast due to internal explosion; ment in the L N G field has now become a multi-million
(2) Missiles ; dollar business. It might be considered that this is
(3) Ground shock ; carrying risk assessment to absurd lengths. However, it
(4) Fire; can be regarded as some measure of the resistance
(5) Toxic gases or vapours; mounted by the environmental lobby in the United
(6) Explosive gases or vapours. States.
Step 2. Determine the maximum distances at which In the United Kingdom there has been the major
the various types of damage could be caused study carried out by Safety and Reliability Directorate,
in the most adverse circumstances, including for the Health and Safety Executive, on Canvey
the effects of sequential damage to the plant Island. 5 This too was in the million-dollar class. Other,
itself. less extensive, studies have been made for installations
such as the proposed petrochemical complex at Moss
Step 3. Evaluate the consequences to people and
Moran, in Fifeshire, and its associated marine ter-
property located within the area defined at
minal. Some interesting studies have also been made of
Step 2 for a range of accidents of increasing
the interaction of individual complexes, such as re-
severity, up to the maximum severity postu-
fineries and steelworks on nuclear power stations,
lated at Step 2. In practice, "severity" can
since the effects of sequential damage to the nuclear
often be measured in terms of the numbers of
plant could be particularly serious.
units, such as storage tanks, involved in the
In addition to these very elaborate analyses, using
accidents.
the approach outlined above, the insurance industry
Step 4. Estimate the probability of occurrence for requires a quick and inexpensive method for estimat-
each of the accidents postulated at Step 3. ing the risk presented by a specific plant. Two methods
Step 5. Evaluate the risks to people and to property for doing this are described in Section 9, below.
for each of the accidents postulated at Step 3,
where "risk" is defined as above; i.e. 3. I D E N T I F I C A T I O N O F P O T E N T I A L S O U R C E S
all i OF HAZARD
Risk = ~ (probability of event i)
In principle, this should be the simplest part of the
x (consequence of event i). assessment. However, previous accidents such as those
Risk assessment methods for vapour-cloud explosions 169
the m a x i m u m distances at which dangerous concen- TABLE 1. Maximum distance from site at which significant
trations could arise. A further difficulty is that in most consequences could result from accidents involving 1000 tons
of material
practical cases the vapour will originate from the
flashing-off of superheated liquid due to the fracture of Maximum
a pressure vessel or from the evaporation of liquid spilt Effect distance
into bunds or on the ground. I-a these cases the rate of
emission may be difficult to estimate. In practice, Internal explosion
(causing 1 psi overpressure) about 2000 m
because of the large variation in these distances with Missiles 2000 m
weather conditions and wind direction, it is usually Ground shock less than 2000 m
necessary to treat this type of accident on a prob- Fire :
abilistic basis ; by this means, the difficulty in predict- (i) on site about 0.5 km
(2) drifting vapour-cloud about 5 km
ing the m a x i m u m distance at which dangerous con-
Toxic gases or vapour
centrations could occur becomes less important, since (e.g. Chlorine) over 10 km
it is only one of several uncertainties. Explosive vapour-cloud :
(1) on site about 1500 m
(2) drifting about 5 km
4.6. Explosive Gases or Vapours
Prediction of the m a x i m u m distance at which
significant damage could be caused by vapour-cloud empirically, on the n u m b e r of tank failures, e.g., which
explosions presents more difficulty than for any of the should be considered as the source term in any one
other consequences. Not only are there the same accident. In practice, for a complex installation, such
difficulties in predicting the m a x i m u m distance at as a chemical plant, which has a variety of potential
which dangerous concentrations can arise as are hazards, it is preferable to consider each type of
encountered with toxic gases but, in addition, there are potential hazard separately at this stage, as it is
the uncertainties associated with the magnitudes of the unlikely that there will be significant synergistic effects
blast overpressure and impulse which may be pro- between separate consequences. The question of
duced, their rate of decay with distance and the nature possible sequential effects within the installation, or on
of the target response to a pulse which may be very neighbouring installations, can be treated more satis-
different in shape from that due to a conventional high factorily as part of the probability estimating stage.
explosive.
However, in order to keep these difficulties in
IO
perspective, it should be noted that, so far as off-site
consequences are concerned, the hazards to the public
from burning o f a vapour cloud over a populated area
I
may be almost as severe as from its explosion.
Moreover, if there are moderately toxic chemicals
stored on the site, the hazard from these can extend to
IO-'
much greater distances, as the dangerous concen- ~ ' ~ iX \ % ,
tration may be lower by a factor of 100 or more.
olEI
I I
B
Pipe
A
break
Electric
power I
Fission
product
re moral
Contoinmen
integrity l
PE, PAxPo,
pE2 PAxPD,xPEZ
Initiating eventJ I p~xPq
Pc, ! p~x p¢,xpoz
Po P~,%
FIG. 3. Simplified event trees for a large LOCA (from Ref. 1).
question of sabotage on a large scale by terrorist plant such as emergency diesel generator sets suggests
groups. However, this factor is so dissimilar from the that typically the common cause component is be-
remainder of those considered in a reliability analysis tween 0.1 and 1% of the observed failure rate. As the
that it is better to treat it as a separate issue. The other
factors listed above merit some additional comment.
I Loss of electric I
power (EP) to
6.2.1. Common-modefauhs engineered safety
features (ESFs)
Typical causes of c o m m o n - m o d e faults, which may
be encountered, even in systems designed for very high
reliability, are :
(1) Environmental effects (e.g. corrosion due to excess-
ive humidity) affecting all the redundant systems
simultaneously. I I
(2) Mechanical damage (e.g. by missiles generated in Loss of AC Loss of DC
an accident) to all the redundant systems at the power to ESFs power to ESF's
time of the accident.
(3) Systematic errors in maintenance. £
(4) Loss of a c o m m o n electrical or water supply.
Opinion is still divided amongst analysts as to
the best way of identifying and treating potential
c o m m o n - m o d e faults. One method, which has the I I
I
merit of simplicity, is to assume that a proportion ofali Loss of J Loss of
observed faults in a particular type of subsystem are on - site AC [ off-site power
power to ESFs to ESFs
due to potential common causes. Thus, the observed
failure rates which are used in the reliability analysis J. 1
reflect this. Analysis of a substantial amount ofdata for FIG. 4. Illustration of'fault-tree development (from Re['. t).
Risk assessment methods for vapour-cloud explosions 173
common-mode fault can be represented by an element derived immediately from the combined standard
in series with, say, three parallel systems, it establishes deviations. More exact estimates can be made by the
an upper limit to the reliability which can be claimed. use of computer programmes developed specifically
This method is described in detail in Ref. 6. for this purpose (e.g. see Ref. 1).
Overall, it is unlikely that for a complex system the
6.2.2. Faults due to the human operator 909/0 confidence limits will be less than a factor of 10 on
either side of the "point value".
Not infrequently the analysis of accidents shows
that the primary cause was a human failure at some
stage in the chain of design, fabrication, inspection, 6.3. Treatment of the Effects of
operation and maintenance. Em, ironmental Conditions
To a large extent the use of field data as a basis for
Where the consequences for a given accident may
the failure rates employed in the reliability analysis
vary substantially with environmental conditions as
takes the effect of human failures into account.
well as with the size of the source term, it is desirable to
However, in the analysis ofcomplex systems, where the
use a set of simple probability distributions to rep-
response of the plant operator during an accident
resent each of these factors, so that for any one source
sequence may have a major effect on the outcome, it is
term (e.g. amount of vapour released initially) we
necessary to take more direct account of his actions,
obtain a set of consequences, each with an associated
bearing in mind that he will be in a state of stress at the
probability. In practice, the consequences may be zero
critical time. at most distances for several members of the set.
This aspect has been given increasing attention
during the past few years, both in the United States and
in Europe. A scheme suggested by one United States 7. ESTIMATE OF RISK
group (SANDIA Laboratory) for operator response to
When the consequences and probabilities have been
a severe but unlikely accident (estimated probability
evaluated for each of the range of accidents considered
about 10 -4 per year) is given in Ref. 7. This is as
there is, in principle, no difficulty in calculating the
follows :
individual risks and summing these to find the total
Chance of operator error risk for each type of consequence. However, although
at 5 min after accident = 0.9 the range of accidents to be considered can be so
Chance of operator error chosen that all possible sizes of explosion, or of releases
at 30 min after accident = 0.1 of toxic or flammable material, are covered, it is not
possible to guarantee that all the possible ways in
Chance of operator error
which such accidents could occur have been included.
at several hours after accident = 0.01
To some undefinable extent therefore, the calculated
This scheme may be compared with the results of an overall risk will tend to underestimate the actual risk.
evaluation of the ability of merchant marine officers to The extent of the error depends on the ability of the
take effective avoiding action when the radar display analyst to visualize the various ways in which the sub-
indicates that their ship is on a collision course. The systems can interact to cause accidents. In this respect,
investigation showed that successful action based on the systematic examination of the design in the failure
the radar observations would be taken in some 85% of modes and effects analysis and in the construction of
cases if the operator were faced with a single potential event trees and of fault trees serves to reduce the
collision course, but his performance would deterio- chance that significant sequences leading to severe
rate sharply if there were two or more such courses) accidents will be overlooked.
By putting a quantitative value on human life, or
loss of expectation of life due to injury, all the
6.2.3. Treatment of uncertainties in failure rates consequences could, if desired, be expressed in mon-
For the majority of mechanical and electrical sys- etary terms, so that a single figure could be used to
tems and components encountered in the reliability describe the total risk. This may be useful for com-
analysis of installations likely to give rise to major parative purposes.
hazards, the observed failure rates can be represented
by a median value and 90% confidence limits which are
8. ACCEPTABILITY OF RISK
a factor of between 3 and 10 on either side of the
median. The approach usually adopted in analysis of a Having completed the assessment of the risk from a
complex system is to use the median values alone to particular plant it may remain to determine whether or
obtain what is described as a "point value" for the not that risk is acceptable and, if not, how it might be
overall failure rate. The overall uncertainty is then reduced.
estimated separately. A first approximation can be In the absence of any clearly defined standards for
obtained by assuming that the underlying probability acceptability of risk, the adequacy of a particular plant
distributions for the failure rates are all normal or all in this respect is largely a matter for negotation with
log-normal, so that the resulting distribution are also the appropriate Government body and, in a de-
normal or log-normal, and the confidence limits can be mocratic society, to some extent with groups of private
174 L. CAvE
persons who are put at some additional risk by the author doubts whether arguments as to the accept-
presence of the plant. In principle it should not be ability of risk of one technology based on comparison
necessary to include in the negotiations pressure with other risks are likely to convince the public; on
groups whose members are not at risk and whose the whole they are much more interested in the benefits
opposition is frequently due to ulterior motives (e.g. than the attendant risks, but they may also be
resistance to economic growth), but in practice this concerned about the consequence of the worst fore-
tends to become a political problem. seeable accident. Nevertheless, it does seem to the
Increased safety may be costly in terms of the author that comparability of risk provides the best
additional material and financial resources required to available basis for decision-making, even though the
achieve an improvement. Thus, ideally society as a arguments have got to be put to the public in different
whole should ensure that the benefit, in terms of a ways.
reduction in risks, which would be obtained by the There will also be some level of risk which should
expenditure of a given amount of resources in one not be exceeded on purely economic grounds, in the
particular industry is as large, or larger, than could be sense that it is cheaper to reduce the chance of damage
obtained by the same expenditure elsewhere; i.e. it to the plant itself and of consequential damage (includ-
should have the maximum cost-effectiveness. ing the resulting loss of output) by improving its
In practice, of course, there is at present no means by reliability than to accept the higher risk. Studies of this
which the relative cost effectiveness of possible changes aspect for nuclear power plant indicate that the break-
can be judged. Consequently, the present standards of even point, for very severe accidents, which would lead
safety, and the extent of the pressure for improvement, to the release of large quantities of radioactive ma-
varies widely from one type of activity to another. terial, is about 10 -4 per year. 2 This is at least an order
Comparisons of the risks of everyday life and in of magnitude greater than the probability of such
different industries have been attempted by various accidents which would be considered acceptable from
bodies, notably the International Commission on the public safety point of view.
Radiological Protection (I.C.R.P.), who have stressed In the evaluation of the limiting economic risk for
the need for a cost-benefit approach to proposals for nuclear plant an important factor is the high differen-
reducing radiation risks in industry. These com- tial cost of the fossil fuel which would have to be used
parisons show that the average probability of ac- to replace the lost nuclear capacity. In other types of
cidental death in most developed countries is about plant this aspect may be less important ; consequently
10 -4 per year, as compared with an overall risk of the break-even point could be greater than 10 -4 per
death of about 10 -2 per year and a risk of death at year.
work in the safer industries of about 10- ~ per year. 9
In the United Kingdom nuclear industry, there is
some degree of agreement that to be acceptable to the
public, the incremental risk of death to those living 9. PROCEDURES FOR RISK ASSESSMENTS IN RELATION
TO VAPOUR-CLOUD EXPLOSIONS
near the station should not exceed 10 -6 per year.
Examination of the attitude of those connected profes-
sionally with other potentially hazardous industries 9.1. An Empirical Methodfor Assessment of Plant
suggests that death risks in the range 10-'*-10 -6 per Damage
year are considered to be acceptable. 1° However, it So far as the author is aware, a full quantitative risk
should be noted that public reaction to technological assessment, including an analysis of the process
risk varies over a wider range. If one judges by the hazards, has only been carried out for a few specialized
extent to which the section of the public directly plants (e.g. explosives production 11) and for some new
concerned campaigns for increased safety, the level of units in chemical plants, as part of the design process
death risk which is in fact accepted varies from about (e.g. see Ref. 12). In the Canvey study mentioned
10 -3 per year (for dams) to about 10 -8 per year (for above, 5 the probabilities of fires and explosions due to
nuclear power in the United States of America). In this failures of process control were not evaluated individu-
respect, the public's reaction depends largely on the ally. For insurance purposes, a much simpler method
extent to which the risk is "perceived", in the sense that may be sufficient.
information which is, in fact, publicly available in A simple empirical procedure, based on observation
professional journals and textbooks is more widely of the damage caused by vapour-cloud explosions at
disseminated by "the media". If the media choose to the Pernis refinery, Flixborough and elsewhere, has
dramatize their presentation of the information it may been proposed by International Oil Insurers. t3 The
become politically difficult to secure the acceptance of procedure is as follows :
risks at a level which represents a rational allocation of The procedure is based on a set of datum levels for a
resources in limiting the risks from one type of hazard chosen mass of flammable gas* and the observed
(e.g. nuclear power) and another (e.g. the use of coal to extent of damage within two circles of specified radii,
generate electricity) to achieve the same end. centred about the source position, which can be scaled
In common with some other workers in this field, the as required. In this context, flammable gas includes
flammable vapour and/or aerosol mist.
* See "Definitions", p. 175. The datum size of cloud is postulated as that arising
Risk assessment methods for vapour-cloud explosions 175
from 20 tons of flammable gas which is involved in the (2) less than 100 kg/min for pipework installed with
explosive process. fail-safe remotely operated valves. Where a plato has
The datum circles relating to the size of cloud multiple streams of similar operations, assessment
implied in the previous paragraph are assumed to be should be concentrated on the largest stream.
100 yards and 200 yards in radius respectively. It will be seen that this procedure is, in fact, a method
It is assumed there will be 80~o total loss within the for consequence assessment rather than risk assess-
inner circle and 40~o total loss within the outer ment, and does not extend to evaluation of the
annulus. Assuming that the distribution of building consequences outside the plant. Although it seems
and plant values is uniform across the total area the rather limited in relation to assessment of the sequen-
overall average loss within the 200 yard circle will then tial damage when checked against historical evidence,
be 50~o. Where there is a marked divergence from it is found to allow satisfactorily for fire and other
uniformity in value distribution, adjustments must be damage.
made for the location and content of areas of high and An alternative empirical approach has been de-
low value concentration. scribed by Davenport. 14
This procedure should be repeated using several This procedure, which has been used by Industrial
neighbouring positions for the site of the cloud to Risk Insurers of the United States for some years, is as
ensure that the maximum probable value has been follows :
evaluated. Only circle centres at drift distances up to
(1) The maximum release considered is equal to the
200 yards from the original position need be
contents of the largest process vessel, or train of
considered.
vessels not readily isolated. Storage vessels and
When the datum case quantity of 20 tons is not
pipelines are not considered.
appropriate adjustments to the circle radii are made in
(2) The amount of material vaporized from a hot
accordance with the correlation shown in Table 2.
flashing liquid is estimated on the basis that all the
For the purpose of scaling from the datum case it is
superheat is used to supply heat of vaporization.
assumed that 5~o of the total inventory in a single
However, if the boiling point is below 70°F, 100~o
discrete circuit (defined below) within the area would
vaporization is assumed.
be involved in the explosive process.
(3) It is assumed that 2~o of the theoretical chemical
energy in the cloud appears as explosive energy.
For comparative purposes, this is expressed in
TABLE 2
terms of an equivalent amount of TNT, but the
Weight of flammable Circle radii maximum over-pressure is assumed to be 5 psi and
in mixed cloud (yards) the amount of damage is estimated from the
(tons) Inner Outer information given in.well known sources such as
Brasie and Simpson.i 5
10 79 158
20 100 200 It will be seen, therefore, that there is a degree of
30 114 229 similarity between the two empirical procedures, but
40 126 252
50 135 271 the one proposed by International Oil Insurers is
60 144 288 easier to apply. A less empirical method for assessment
70 152 304 of losses, including those due to vapour-cloud explo-
80 158 317 sions which combines both probability and con-
90 165 330
100 171 342 sequence aspects, is being developed in the U.K. by the
Insurance Technical Bureau. 16 Although more com-
plicated than the methods described above, it should
Definitions: be much simpler, and much less costly, than assess-
Flammable gas. In addition to gases under pressure, ment based on the use of event trees and fault trees.
the term flammable gas is taken to include the vapour
arising from a flammable liquid at or above its
9.2. Assessment of Risks Outside the
atmospheric boiling point, whether or not this point
Parent Installation
lies above or below ambient temperature. The term
also includes the fine mist or aerosol which is produced If the parent installation covers a large area in which
when a liquid under pressure is ejected from its a lot of"active" plant is located, as in the case of Pernis
container at high velocity. and Flixborough, there is a good chance that a
For the simple case of vaporization of a hot liquid potentially explosive vapour-cloud will be ignited
escape, the liquid must be at least 10°C above its within the complex, so that the damage beyond the site
atmospheric boiling point. boundary is relatively small--e.g, at Flixborough,
Single discrete circuits. A single discrete circuit although houses were extensively damaged, there were
consists of the total network of process vessels and no fatal casualties outside the site boundary. However,
pipework defined by a boundary of specified limiting there are other types of installation, such as the storage
line-flow rates. These limiting flow rates are: (1) less area of a refinery (where there will be little "active"
than 10 kg/min of material for normal pipework, and plant), pipelines and other forms of transport which
176 L. CAVE