Professional Documents
Culture Documents
Value at Risk Perspective On LOPA (2007)
Value at Risk Perspective On LOPA (2007)
Value at Risk Perspective On LOPA (2007)
PROTECTION ANALYSIS
Abstract: Layers of protection analysis (LOPA) is an established tool for designing, character-
izing, and evaluating risk in the chemical process industry. Value at risk (VaR) is a method first
introduced in the financial sector for modeling potential loss in a complex venture. In this paper
we demonstrate the application of VaR principles to the LOPA of an ethylene refrigeration com-
pressor. We calculate the changes in risk profile (probability versus loss) associated with adding
or removing different safety interlocks around the compressor. The VaR analysis shows that the
benefits of a given layer of protection are not necessarily captured by a single average number,
since the entire probability –value curve is affected. This type of analysis will aid in the allocation
of limited resources to process risk interventions.
Keywords: chemical process safety; value at risk; quantitative risk assessment; layers of protec-
tion analysis.
Present Work the generic event tree structure. The top event (failure)
occurs with an estimated frequency. Each of the safety
In this paper we describe the integration of QRA with VaR.
interlocks provides a success/failure node; there is a certain
Specifically we analyse the VaR loss probability distribution
probability (x) that the interlock will successfully trip the
functions associated with different configurations of protec-
compressor and a complementary probability (1 2 x) that it
tion layers around an ethylene refrigeration compressor.
will not trip. The upward branch represents a successful
The frequency and cost data are real-world estimates for
trip and ends with a shutdown; the downward branch rep-
this type of equipment. The paper is organized as follows.
resents a failure to trip and leads to either a subsequent
The next section defines the process, potential hazards,
interlock or ultimate compressor failure (if it is the last
and available layers of protection. The third section describes
layer). The appropriate branch probabilities are multiplied
the VaR theory as applied to this problem. The results and
by the top event frequency to yield the frequencies of a
conclusions are presented in the two final sections,
given sub-event (a successful shutdown or an ultimate
respectively.
compressor failure).
While we consider six types of failure events, there are
PROBLEM DEFINITION multiple surge controllers, so there are actually eight distinct
top events: (1) 1st SG surge control failure, (2) 2nd/3rd SG
Process Description and Potential Failures surge control failure, (3) 4th/5th SG surge control failure,
The main focus of our analysis is an individual ethylene gas (4) high suction drum level process demand failure, (5) lube
refrigeration compressor with a capacity of processing oil control system failure, (6) LC01 seal oil control failure,
millions of pounds of material per day. Such a device would (7) speed suction control failure, and (8) vibration process
be found in a liquefied natural gas processing complex, con- demand failure. Each of the eight top events was given a fre-
densing light hydrocarbons for storage and transportation. quency determined from historical data.
The compressor, like any piece of equipment, is subject to fail- Table 1 provides a summary of the eight top events and
ures of varying type and severity. We will consider six different their sub-events, corresponding to the response of the
types of failure, namely failures associated with surge control, safety devices in the different layers of protection. The
high suction drum level process demand, lube oil control, seal first column of Table 1 lists the events and sub-events.
oil control, speed suction control and vibration process The second column provides the cost associated with
demand. Most of these failure types, if unchecked, would each individual sub-event outcome. The third column
result in approximately one million dollars of equipment provides the frequency associated with each top and
damage plus the loss of production from being shut down sub-event, for the base case of full layers of protection (all
for about 7 days. The exception is a seal oil control failure, devices in place). Subsequent columns represent the
which would incur a 30-day loss of production. To prevent same information, but for perturbations of the base case
these high levels of damage, one may install safety interlocks (called ‘scenarios’) where one layer of protection has been
that shut down, or ‘trip’, the compressor in response to an removed. The cost data for each sub-event is not
undesirable event. These shutdowns typically cause the com- scenario-dependent, so it appears in only one column.
pressor to be down for one business day, significantly limiting The frequencies and costs for a top event and its sub-
the loss. However, one drawback of the interlocks is that they events can be mapped directly onto an event tree like that
occasionally have spurious trips that shut down the compres- shown in Figure 1.
sor when there is no true process fault; this causes unnecess- Spurious trips of these safety devices are summarized at
ary loss in production. Details of the interlock implementation the bottom of Table 1, with the considered possible trips
are described in the next section. being (1) Overspeed 1, (2) Overspeed 2, (3) Vibration, (4)
KO drum level 1–5, (5) lube oil pressure, and (6) SO level.
Each of these spurious trips may be considered as an inde-
Layers of Protection pendent, individual sub-event for the purposes of the follow-
SIS-Tech has performed a QRA on a set of safety inter- ing discussion.
locks for the ethylene refrigeration compressor as described
above. The interlocks are layered in series so that if the
THEORY AND METHODS
first interlock does not successfully shut down the system,
the second can shut it down, and so on. The QRA is rep- Calculations of Frequencies and Cost Values
resented as a set of event trees, each modeling the response
As mentioned previously, the sub-event frequencies in
of the safety system to one of the failure events described in
Table 1 were obtained from an event tree like that shown in
the previous section. Each interlock and event tree is con- Figure 1. The frequency of sub-event i is given by
sidered to be independent of the others. Figure 1 shows
Y
i
fi ¼ Ftop pj (1)
j¼1
Trans IChemE, Part B, Process Safety and Environmental Protection, 2007, 85(B1): 81–87
VALUE AT RISK PERSPECTIVE ON LAYERS OF PROTECTION ANALYSIS 83
Table 1. Frequencies and cost data for all the events and cases.
(6) LCO1 Seal Oil Control Fails 9.80E–02 9.80E– 02 9.80E–02 9.80E– 02
SO level interlock success $266, 667 9.58E–02 9.58E– 02 9.58E–02 9.58E– 02
SO level interlock failure $7, 066, 667 2.26E–03 2.26E– 03 2.26E–03 2.26E– 03
Spurious Events
Overspeed interlock 1 spurious $266, 667 4.08E–02 0.00E þ 00 4.08E–02 4.08E– 02
Overspeed interlock 2 spurious $266, 667 4.88E–02 4.88E– 02 0.00E þ 00 4.88E– 02
Vibration interlock spurious $266, 667 7.31E–02 7.31E– 02 7.31E–02 0.00E þ 00
KO DRUM LVL 1 –5 spurious $266, 667 1.20E–02 1.20E– 02 1.20E–02 1.20E– 02
Lube Oil press spurious $266, 667 1.20E–02 1.20E– 02 1.20E–02 1.20E– 02
SO level spurious $266, 667 1.20E–02 1.20E– 02 1.20E–02 1.20E– 02
(fourth column in Table 1). The top event frequency was (1–0.9760) ¼ 0.0000896 y21. These calculations produce
assigned a value of 0.16 y21 based on historical data. Since the numerical values found in Table 1. We note that the top
Overspeed interlock 1 is absent in this scenario, the probability event frequency Ftop and the probability of success on
of its success is 0 and therefore the frequency of its success is demand for a given interlock type is held fixed across the differ-
(0.16 y21) (0.0) ¼ 0.0 y21. Overspeed interlock 2 is present in ent scenarios; it is the presence or absence of a given layer of
this scenario and we assign the probability of its successful protection that causes the differences in frequencies observed
response on demand as 0.9769 based on historical data. in Table 1.
The frequency for Overspeed interlock 2 success is the pro- Each of the sub-event outcomes has an associated cost.
duct of this probability and the demand frequency under this We assume that the cost may comprise both asset damage
scenario, i.e., (0.16 y21) (1.0–0.0) (0.9769) ¼ 0.0156 y21. and business interruption. Business interruption may include
The final layer of protection is the vibration interlock, to both lost (flared) feed and product that was not made.
which we assign a success probability of 0.9760 on demand. We assume that two hours of feed flaring occurs at every
The frequency for successful vibration interlock intervention shutdown and that the feed costs $0.20/pound. We also
is therefore (0.16 y21) (1.0–0.0) (1–0.9769) (0.9760) ¼ assume that the earnings before interest, taxes, deprecia-
0.00364 y21, and the frequency of failed vibration tion, and amortization (EBITDA) is $0.05/pound of product.
interlock intervention is (0.16 y21) (1.0–0.0) (1–0.9769) A one-day shutdown from any safety interlock trip will
Trans IChemE, Part B, Process Safety and Environmental Protection, 2007, 85(B1): 81– 87
84 FANG et al.
then cost roughly off the abscissa value v corresponding to the ordinate at
the chosen confidence level pv. In the present case we
2 4 MM lb $0:20 have only three discrete cost values, so it is more convenient
ctrip ¼ day
24 day lb to choose the median cost value and report the correspond-
ing confidence level.
4 MM lb $0:05
þ 1 day ¼ $266 667 (2) As a first step in calculating VaR, we must convert our
day lb
event frequencies Fc to normalized probabilities over a
For most events in which all interlocks fail, there will be chosen time horizon. Perhaps the simplest approach is to
approximately $1 MM in damage to the compressor plus a assume that failure events are uncorrelated in time over a
seven day shutdown of the process. The cost will be given horizon. This assumption is likely to be accurate in
our case, because the overarching QRA analysis assumes
2 4 MM lb $0:20 that failures arise from a variety of independent event types
cfail ¼ day and sub-types (as shown in Table 1). So we employ a Pois-
24 day lb
son distribution of events with a 1-year time horizon
4 MM lb $0:05
þ 7 days þ $1 000 000
day lb ln l
pðn;lÞ ¼ e , n ¼ 0, 1, 2, 3, . . . (6)
¼ $2 466 667 (3) n!
Generation of Frequency-Cost Graphs and VaR These probabilities can be used to construct probability mass
Statistics functions (pmf) and cumulative mass functions (cmf) and
subsequently calculate VaR values, as described above.
For a given scenario, the total Frequency Fc at a given cost
outcome c was obtained by summing up all of the frequen-
cies as Total Expected Cost Value
X
Fc ¼ fi (5) A total expected cost value for each scenario was calcu-
fsub-eventsi gc lated as
X
where the sum includes only those sub-events that have the kEl ¼ c Fc (9)
c
particular cost outcome c (spurious trips included). This was
done for each different scenario shown in Table 1 and the
where the sum runs over all possible cost outcomes c (in our
results are presented as bar graphs in the next section.
example, there are three outcomes).
These graphs are similar to probability mass function (pmf)
graphs in statistics, except that we are plotting frequency
(in y21) instead of normalized probability. RESULTS
In financial applications, the actual ‘value at risk’ is defined
Overview
as the value that sets some lower confidence limit on the nor-
malized probability-value function. For example, say that the Results for the four scenarios shown in Table 1 are pre-
value v represents a lower limit (typically negative, indicating sented and discussed in this section. The scenarios are the
a loss) where pv of the probability lies above it. Then we can base case (full layers of protection), overspeed interlock 1
state that we are (pv 100)% certain that we will lose no removed, overspeed interlock 2 removed, and the vibrational
more than v over the time horizon used to construct the prob- interlock removed. The different scenarios are presented
ability curve, or equivalently, with (pv 100)% certainty over side-by-side in the figures for convenient comparison. The
the next time period t, the VaR is v (Fang et al., 2004). A frequency versus cost graphs are shown in Figure 2, the
cumulative representation of the probability curve is particu- cumulative mass function (cmf) graphs (as calculated via
larly useful in determining VaR, since one may simply read the procedure described previously) are shown in Figure 3,
Trans IChemE, Part B, Process Safety and Environmental Protection, 2007, 85(B1): 81–87
VALUE AT RISK PERSPECTIVE ON LAYERS OF PROTECTION ANALYSIS 85
and the total expected values are shown in Figure 4. The In this case, we examine the impact of removing over-
(a,b) figures associated with Figures 2 and 3 are magnifi- speed interlock 1 layer of protection. As shown in Table 1,
cations of the low-frequency, high-cost events, which can we removed the benefits of overspeed interlock 1 from all
be difficult to see. The results of all the cmf and pmf studies top events and removed the possibility of spurious trips of
are summarized in Table 2. that device. Removal of this layer of protection affected five
of the eight top events.
Figure 2 shows that removing overspeed interlock 1
Base Case involves a tradeoff between risk at different cost levels.
Removing this interlock reduces the frequency of $266 667
The base case represents full layers or protection, mean- cost events to 1.022 y21, as compared to 1.066 y21 in the
ing the compressor is equipped with Overspeed interlock 1,
Overspeed interlock 2, and Vibrational interlock. The base
case data in Figure 2 may be used to make several state-
ments. For example, a catastrophic event costing the com-
pany $7 066 667 will happen with a frequency of 0.002259
per year (which equates to 440 years per loss of this mag-
nitude), and a shutdown at the least costly level of $266 667
will happen with a frequency of 1.066 per year. Value-at-risk
Trans IChemE, Part B, Process Safety and Environmental Protection, 2007, 85(B1): 81– 87
86 FANG et al.
Figure 3a. Close-up view of the cumulative mass probability functions Figure 4. Total expected cost values for the four scenarios.
at the $2 466 667 cost level.
Var
confidence
table
$0 34.28 36.07 36.28 36.84
$266 667 99.71 99.51 99.51 93.35
$2 466 667 99.86 99.86 99.86 99.86
Figure 3b. Close-up view of the cumulative mass probability functions $7 066 667 100.00 100.00 100.00 100.00
at the $7 066 667 cost level.
Trans IChemE, Part B, Process Safety and Environmental Protection, 2007, 85(B1): 81–87
VALUE AT RISK PERSPECTIVE ON LAYERS OF PROTECTION ANALYSIS 87
Total Expected Value for Damage Cost protection scheme is to shift the probability between different
cost levels.
The total expected loss value for each scenario is shown in
Figure 4; this is a simplified approach where the low prob-
ability/high cost –high probability/low cost tradeoffs are not CONCLUDING REMARKS
thoroughly examined, but rather all costs are integrated to
We applied a VaR analysis to the LOPA of an ethylene
produce a single expectation value for each scenario. In
refrigeration compressor system. We analysed the data
order of increasing expected cost, the scenario without Over-
with all layers of protection included and also in three different
speed interlock 2 is the least costly followed by overspeed
scenarios in which one type of interlock was removed. We
interlock 1, the base case, and then the very costly vibration
found that the full layers of protection scheme was conserva-
interlock scenario. As ranked solely by this criterion, the
tive, having the lowest frequencies of occurrence for the most
scenario without vibration interlock is the least desirable by
costly events but relatively frequent low-cost incidents (spur-
far. The scenario without Overspeed interlock 2 is the most
ious trips). Removing Overspeed interlock 1 and Overspeed
desirable, slightly beating the base case of full layers of pro-
interlock 2 lowered the frequency of minor spurious shut-
tection. There is an interesting contrast between this ranking
downs but raised the chances of a more severe event.
and one based on the VaR criterion, which would show that
Removing the Vibrational interlock, however, was much
the base case is the most desirable. This is discussed
more detrimental at the higher cost levels. A simple expec-
more fully in the next subsection.
tation value calculation indicated that the scenario without
Overspeed interlock 2 would be the least costly on average.
However, a VaR analysis of frequencies and probabilities at
Best Choice Among the Four Scenarios? different cost levels can provide more insight than simple
averages when deciding on the allocation of safety
The numerical results of the analysis are summarized in
resources.
Table 2. The total expected cost analysis and the VaR analy-
sis both send one consistent message: the first three scen-
arios (base, without Overspeed 1, without Overspeed 2) are REFERENCES
similar and much superior to the scenario without the
Pasman, J., 2000, Risk informed resource allocation policy:
vibrational interlock. However, the two analyses diverge safety can save costs, Journal of Hazardous Materials, 71(1–3):
slightly when considering which of the first three scenarios 375– 394.
is best. The total expected cost analysis indicates that the Center for Chemical Process Safety of the American Institute of
scenario without Overspeed 2 is the best (least costly). The Chemical Engineers, 1989, Guidelines for Chemical Process
Quantitative Risk Analysis (American Institute of Chemical Engin-
VaR analysis provides a different viewpoint. In the ‘base’ eers, New York, USA).
scenario, we have a 99.71% confidence that there will be Summers, A.E., 2003, Introduction to layers of protection analysis,
no losses worse than $266 667 during the next year. In the Journal of Hazardous Materials, 104(1– 3): 163 –168.
‘without Overspeed 2’ scenario, we have only a 99.51% con- Jorion, P., 2000, Value at Risk: The New Benchmark for Managing
Financial Risk, 2nd edition (McGraw-Hill, New York, USA).
fidence of no losses worse than $266 667. The base scenario
Fang, J., Ford, D. and Mannan, S.M., 2004, Making the business
might then be preferred because of this increase in confi- case for process safety using value-at-risk concepts, Journal of
dence level; although the magnitude of the increase is Hazardous Materials, 115(1–3): 17– 26.
small (0.2%), the next level of cost ($2 466 667) is an order Barbaro, A.F. and Bagajewicz, M., 2004, Managing financial risk in
of magnitude higher. planning under uncertainty, AIChE J, 50(5): 963– 989.
Hahn, G.J. and Shapiro, S.S., 1967, Statistical Models in Engineering
The difference in conclusions occurs because the VaR (John Wiley & Sons, Inc., New York, USA).
confidence criterion places more weight on the higher cost
levels, while the expected value criterion is based on a The manuscript was received 23 August 2005 and accepted for
straight average. Clearly, one effect of altering the layers of publication after revision 16 May 2006.
Trans IChemE, Part B, Process Safety and Environmental Protection, 2007, 85(B1): 81– 87