Showing posts with label psm. Show all posts
Showing posts with label psm. Show all posts

Plant Engineering

Plant engineering is that branch of engineering which embraces the installation, operation, maintenance, modification, modernization, and protection of physical facilities and equipment used to produce a product or provide a service. It is easier to describe plant engineering than to define it. Yet, the descriptions will vary from facility to facility and over time. Every successful plant is continuously changing, improving, expanding, and evolving. And the activities of the plant engineer must reflect this environment. Each plant engineer is likely to have his own, unique job description, and that description is likely to be different from the one he had five years earlier. 

By definition, the plant engineering function is multidisciplinary. It routinely incorporates the disciplines of mechanical engineering, electrical engineering, and civil engineering. Other disciplines, such as chemical engineering for example, may also be needed, depending on the type of industry or service involved. In addition, skills in business/financial management, personnel supervision, project management, contracting, and training are necessary to the successful fulfillment of plant engineering responsibilities. The function is fundamentally a technical one, requiring a thorough technical/engineering background through education and/or experience. But beyond it’s most basic level, a broad range of skills is needed. If the plant engineer is a specialist in anything, it is in his/her own plant or facility. 

Plant engineers must learn to know their own plants thoroughly, from the geology underlying its foundations and the topology of the rainwater runoff to the distribution of its electricity and the eccentricities of its production machinery. They must ensure the quality of the environment both inside and outside the facility as well as the safety and health of the employees and the reliability of its systems and equipment. And they are expected to do all of this in a cost-effective manner. A few phrases from a 1999 classified ad for a plant engineer provide some real-world insight on the scope of responsibilities: 

  • Support ongoing operations, troubleshoot, resolve emergencies, implement shutdowns
  • Organize and maintain information on plant systems/equipment and improvement programs
  • Implement plant projects and maintain proper documentation 
  • Deal effectively with multiple activities, requests, and emergencies
  • Manage scope, design, specification, procurement, installation, startup, debugging, validation, training, and maintenance. 

To this list, most plant engineers would quickly add compliance with all applicable laws and regulations as well as accepted industry standards and practices. 

The primary mission of the plant engineer is to provide optimum plant and equipment facilities to meet the established objective of the business. This can be broken down into these four fundamental activities: 

(1) ensure the reliability of plant and equipment operation; 

(2) optimize maintenance and operating costs; 

(3) satisfy all safety, environmental, and other regulations; and 

(4) provide a strong element of both short term and long-range facilities and equipment planning.’ 

The description still rings true today

HAZOP

HAZOP stands for “hazard and operability studies.” This is a set of formal hazard identification and elimination procedures designed to identify hazards to people, process plants, and the environment. The techniques aim to stimulate in a systematic way the imagination of designers and people who operate plants or equipment so they can identify potential hazards. In effect, HAZOP studies make the assumption that a hazard or operating problem can arise when there is a deviation from the design or operating intention. Corrective actions can then be made before a real accident occurs.

Some studies have shown that a HAZOP study will result in recommendations that are 40 percent safety-related and 60 percent operability-related. HAZOP is far more than a safety tool; a good HAZOP study also results in improved operability of the process or plant, which can mean greater profitability.

The primary goal in performing a HAZOP study is to identify, not analyze or quantify, the hazards in a process. The end product of a study is a list of concerns and recommendations for prevention of the problem, not an analysis of the occurrence, frequency, overall effects, and the definite solution. If HAZOP is started too late in a project, it can lose effectiveness because:

1.               There may be a tendency not to challenge an already existing design.

2.               Changes may come too late, possibly requiring redesign of the process.

3.               There may be loss of operability and design decision data used to generate the design.

HAZOP is a formal procedure that offers a great potential to improve the safety, reliability, and operability of process plants by recognizing and eliminating potential problems at the design stage. It is not limited to the design stage, however. It can be applied anywhere that a design intention (how the part or process is expected to operate) can be defined, such as:

•            Continuous or batch processes being designed or operated

•            Operating procedures

•            Maintenance procedures

•            Mechanical equipment design

•            Critical instrument systems

•            Development of process control computer codeThese studies make use of the combined experience and training of a group of knowledgeable people in a structured setting. Some key concepts are:

•            Intention—defines how the part or process is expected to operate.

•            Guide words—simple words used to qualify the intention in order to guide and stimulate creative thinking and so discover deviations. Table 26-2 describes commonly used guide words.

Deviations—departures from the intention discovered by 

•            Causes—reasons that deviations might occur.

•            Consequences—results of deviations if they occur.

•            Actions—prevention, mitigation, and control —Prevent causes.

—Mitigate the consequence.

—Control actions, e.g., provide alarms to indicate things getting out of control; define control actions to get back into control.

The HAZOP study is not complete until response to actions has been documented. Initial HAZOP planning should establish the management follow-up procedure that will be used.

The guide words can be used on broadly based intentions (see Table 26-2), but when intentions are expressed in fine detail, some restrictions or modifications are necessary for chemical processes, such as:

No flow

Reverse flow

Less flow

More temperature

Less temperature

Composition change

Sampling

Corrosion/erosion

This gives a process plant a specific HAZOP guide-word list with a process variable, plant condition, or an issue.

HAZOP studies may be made on batch as well as continuous processes. For a continuous process, the working document is usually a set of flow sheets or piping and instrument diagrams (P&IDs). Batch processes have another dimension: time. Time is usually not significant with a continuous process that is operating smoothly except during start-up and shutdown, when time will be important and it will resemble a batch process. For batch processes, the working documents consist not only of the flow sheets or P&IDs but also the operating procedures. One method to incorporate this fourth dimension is to use guide words associated with time, such as those described in Table 26-3.

HAZOP studies involve a team, at least some of whom have had experience in the plant design to be studied. These team members apply their expertise to achieve the aims of HAZOP. There are four overall aims to which any HAZOP study should be addressed:

1.               Identify as many deviations as possible from the way the design is expected to work, their causes, and problems associated with these deviations.

2.               Decide whether action is required, and identify ways the problem can be solved.

3.               Identify cases in which a decision cannot be made immediately and decide what information or action is required.

4.               Ensure that required actions are followed through.

The team leader is a key to the success of a HAZOP study and should have adequate training for the job. Proper planning is important to success. The leader is actually a facilitator (a discussion leader and one who keeps the meetings on track) whose facilitating skills are just as important as technical knowledge. The leader outlines the boundaries of the study and ensures that the design intention is clearly understood. The leader applies guide words and encourages the team to discuss causes, consequences, and possible remedial actions for each deviation. Prolonged discussions of how a problem may be solved should be avoided.

Facilities Reviews

 There are many kinds of facilities reviews that are useful in detecting and preventing process safety problems. They include 

  1. pre-start-up reviews (before the plant operates),
  2. new plant reviews (the plant has started, but is still new), 
  3. reviews of existing plants (safety, technology, and operations audits and reviews), 
  4. management reviews, 
  5. critical instrument reviews, and 
  6. hazardous materials transportation reviews.

Knowledge Organization

 INSTITUTIONAL MEMORY

Most accidents do not occur because we do not know how to prevent them but because we do not use the information that is available. The recommendations made after an accident are forgotten when the people involved have left the plant; the procedures they introduced are allowed to lapse, the equipment they installed is no longer used, and the accident happens again. The following actions can prevent or reduce this loss of information.

•             Include a note on “the reason why” in every instruction, code, and standard, and accounts of accidents which would not have occurred if the instruction, code, or standard had been followed.

•             Describe old accidents, as well as recent ones, in safety bulletins and newsletters and discuss them at safety meetings.

•             Follow up at regular intervals (for example, during audits) to see that the recommendations made after accidents are being followed, in design as well as operations.

•             Make sure that recommendations for changes in design are acceptable to the design organization. On each unit keep a memory book, a folder of reports on past accidents, which is compulsory reading for new recruits and which 

•             others dip into from time to time. It should include relevant reports from other companies but should not include cuts and bruises.

•             Never remove equipment before you know why it was installed. Never abandon a procedure before you know why it was adopted.

•             Devise better information retrieval systems so that details of past accidents, in our own and other companies, and the recommendations made afterward are more easily accessible than at present.

•             Include important accidents of the past in the training of young graduates and company employees. 


INCIDENT INVESTIGATION AND HUMAN ERROR

Although most companies investigate accidents (and many investigate dangerous incidents in which no one was injured), these investigations are often superficial, and we fail to learn all the lessons for which we have paid the high price of an accident. The facts are usually recorded correctly, but often only superficial conclusions are drawn from them. Identifying the causes of an accident is like peeling an onion. The outer layers deal with the immediate technical causes and triggering events while the inner layers deal with ways of avoiding the hazard and with the underlying weaknesses in the management system (Kletz, Learning from Accidents, 2d ed., Butterworth-Heinemann, 1994).

Dealing with the immediate technical causes of a leak, for example, will prevent another leak for the same reason. If so little of the hazardous material can be used that leaks do not matter or a safer material can be used instead, as previously discussed, all significant leaks of this hazardous material can be prevented. If the management system can be improved, we may be able to prevent many more accidents of other sorts.

Other points to watch when drawing conclusions from the facts are:

1. Avoid the temptation to list causes we can do little or nothing about. For example, a source of ignition should not be listed as the primary cause of a fire or explosion, as leaks of flammable gases are liable to ignite even though we remove known sources of ignition. The cause is whatever led to the formation of a flammable mixture of gas or vapor and air. (Removal of known sources of ignition should, however, be included in the recommendations.) Similarly, human error should not be listed as a cause. 

2. Do not produce a long list of recommendations without any indication of the relative contributions they will make to the reduction of risk or without any comparison of costs and benefits. Resources are not unlimited and the more we spend on reducing one hazard, the less there is left to spend on reducing others.

3. Avoid the temptation to overreact after an accident and install an excessive amount of protective equipment or complex procedures which are unlikely to be followed after a few years have elapsed. Sometimes an accident occurs because the protective equipment available was not used; nevertheless, the report recommends installation of more protective equipment; or an accident occurs because complex procedures were not followed and the report recommends extra procedures. It would be better to find out why the original equipment was not used or the original procedures were not followed. 

4. Remember that few, if any, accidents have simple causes.

5. When reading an accident report, look for the things that are not said. For example, a gland leak on a liquefied flammable gas pump caught fire and caused considerable damage. The report drew attention to the congested layout, the amount of redundant equipment in the area, the fact that a gearbox casing had been made of aluminum, which melted, and several other unsatisfactory features. It did not stress that there had been a number of gland leaks on this pump over the years, that reliable glands are available for liquefied gases at ambient temperatures, and, therefore, there was no need to have tolerated a leaky pump on this duty.

As another example, a fire was said to have been caused by lightning. The report admitted that the grounding was faulty but did not say when it was last checked, if it was scheduled for regular inspection, if there was a specification for the resistance to earth (ground), if employees understood the need for good grounding, and so on.

6. At one time most accidents were said to be due to human error, and in a sense they all are. If someone—designer, manager, operator, or maintenance worker—had done something differently, the accident would not have occurred. However, to see how managers and supervisors can prevent them, we have to look more closely at what is meant by human error:

a.           Some errors are due to poor training or instructions: someone did not know what to do. It is a management responsibility to provide good training and instructions and avoid instructions that are designed to protect the writer rather than help the reader. However many instructions are written, problems will arise that are not covered, so people—particularly operators—should be trained in flexibility—that is, the ability to diagnose and handle unforeseen situations. If the instructions are hard to follow, can the job be simplified?

b.           Some accidents occur because someone knows what to do but makes a deliberate decision not to do it. If possible the job should be simplified (if the correct method is difficult, an incorrect method will be used); the reasons for the instructions should be explained; checks should be carried out from time to time to see that instructions are being followed; and if they are not, this fact should not be ignored.

c.            Some accidents occur because the job is beyond the physical or mental ability of the person asked to do it—sometimes it is beyond anyone’s ability. The plant design or the method of working should be improved.

d.           The fourth category is the commonest: a momentary slip or lapse of attention. They happen to everyone from time to time and cannot be prevented by telling people to be more careful or telling them to keep their minds on the job. All that can be done is to change the plant design or method of working to remove opportunities for error (or minimize the consequences or provide opportunities for recovery). Whenever possible, user-friendly plants (see above) should be designed which can withstand errors (and equipment failures) without serious effects on safety (and output and efficiency).


Plant Design for Safety—A User-Friendly Approach,

Intensification This involves using so little hazardous material that it does not matter if it all leaks out. For example, at Bhopal, methyl isocyanate (MIC), the material that leaked and killed over 2000 people, was an intermediate for which it was convenient but not essential to store. Within a few years many companies had reduced their stocks of MIC and other hazardous intermediates.

As another example, at one time nitroglycerin (NG) was manufactured in batch reactors containing about a ton of raw materials and product. If the reactor got too hot, there was a devastating explosion. In modern plants, NG is made in a small continuous reactor containing about a kilogram. The severity of an explosion has been reduced a thousandfold, not by adding on protective devices, which might fail or be neglected, but by redesigning the process. The key change was better mixing, achieved not by a better stirrer, which might fail, but by passing one reactant (acid) through a device like a laboratory water pump so that it sucks in the other reactant (glycerin) through a sidearm. If the acid flow stops, the glycerin flow also stops, not through the intervention of a flow controller, which might fail, but as an inevitable result of the laws of physics (Bell, Loss Prevention in the Process Industries, Institution of Chemical Engineers Symposium Series No. 34, 1971, p. 50).

Intensification is the preferred route to inherently safer design, as the plants, being smaller, are also cheaper.

Substitution If intensification is not possible, then an alternative is to consider using a safer material in place of a hazardous one. Thus it may be possible to replace flammable solvents, refrigerants, and heat-transfer media by nonflammable or less flammable (highboiling) ones, hazardous products by safer ones, and processes which use hazardous raw materials or intermediates by processes which do not. As an example of the latter, the product manufactured at Bhopal (carbaryl) was made from three raw materials. Methyl isocyanate is formed as an intermediate. It is possible to react the same raw materials in a different order so that a different and less hazardous intermediate is formed.

Attenuation Another alternative to intensification is attenuation, using a hazardous material under the least hazardous conditions. Thus large quantities of liquefied chlorine, ammonia, and petroleum gas can be stored as refrigerated liquids at atmospheric pressure instead of storing them under pressure at ambient temperature. (Leaks from the refrigeration equipment should also be considered, so there is probably no net gain in refrigerating quantities less than a few hundred tons.) Dyestuffs which form explosive dusts can be handled as slurries.

Process Safety Awareness

  1.  Increase of concern due to numbers of accidents involve 
    • Gas releases
    • Major explosions
    • Environmental incidents
  2. Hazard of the chemical plant
    • Damage & loss of life
    • Vapor cloud explosions
    • Sudden pressure release
    • Static electricity as hidden cause
    • Reactive nature of chemical
    • Loss of containment due to mechanical failure or miss operation
  3. Process Safety Analysis
    1. Hazard analysis
    2. Risk analysis
    3. Guidelines for estimating damage
    4. Project review and procedures
  4. Safety Devices
    1. Pressure relief devices
    2. Flame arresters
    3. Effluent handling
    4. Highly toxic & hazardous chemical handling & storage
  5. Hazardous Materials and Conditions
    1. Reactive
    2. Combustion and flammability hazards
    3. Gas explosions
    4. Unconfined vapor explosions (UVCEs) and Boiling Liquid Evaporating Vapor Explosions (BLEVEs)
    5. Dust explosions
    6. Static electricity
    7. Hazards of vacuum
    8. Hazard of Inert Gases
    9. Gas Dispersion
    10. Discharge rates from punctures lines and vessels

The Start of Process Safety Management: The Flixborough Disaster – June 1, 1974 by Inspector Frank blog

 


Reference

https://inspectioneering.com/blog/2022-02-24/10030/lets-be-frank-the-start-of-process-safety-management-the-flixborough-disaster

It was a failure of the cyclohexane plant that led to the explosion that occurred at 1653 hours on Saturday, June 1st, 1974.

A major leak of liquid from the reactor circuit led to the rapid formation of a large cloud of flammable hydrocarbon. When this met an ignition source (probably a furnace at a nearby hydrogen reformer), there was a massive fuel-air explosion. The plant control room collapsed, killing all 18 occupants. Nine other site workers were killed, and a delivery driver died of a heart attack in his cab. 28 were killed onsite, and 36 more were injured. Offsite, 53 additional people were injured. Fires started on-site which were still burning ten days later. Around 1,000 buildings within a mile radius of the site were damaged, as were nearly 800 in Scunthorpe (three miles away); the blast was heard over thirty-five miles away.

I have started using the Flixborough disaster as a safety talk topic, even though the disaster happened almost 48 years ago. Why? Because people forget, and it is still a good set of lessons to learn. This incident has long been held as one of the big events that drove the concept of process safety management (PSM) forward. First in Europe, and then around the rest of the world. I have been finding Flixborough useful to get people engaged in discussing PSM, and in getting junior inspectors interested in learning why the systems they are using and taking part in even exist.

Plus: being humans, we always turn our heads to look at the car crash, especially if we aren’t involved…

The Flixborough facility was a chemical works owned by Nypro UK, which was a joint venture between Dutch State Mines (DSM) and the British National Coal Board. It had originally been set up to produce fertilizer from by-products of coke ovens in a nearby steelworks. In 1967 it had been reconfigured to produce caprolactam, a chemical used in the manufacture of nylon. On the initial changeover, caprolactam was produced by hydrogenation of phenol. In 1972 there was a push from DSM to use one of their processes in which the caprolactam was produced from cyclohexane. This process was proprietary to DSM.

The process consisted of heating cyclohexane to around 311 degrees Fahrenheit before passing it through a series of six reactors. The reaction itself was the oxidation of cyclohexane with air going over a catalyst, to a mixture of cyclohexanone and cyclohexanol that is usually known as a KA (ketone/alcohol) mixture. The reaction took place in six vessels, each holding about 20 tonnes of material. On leaving the last reactor, the reaction products were removed and the unreacted cyclohexane was then reheated and rerun through again.

Two months prior to the explosion, the No. 5 reactor was discovered to be leaking. When insulation was stripped from it, a crack extending about 6 feet was visible in the mild steel shell of the reactor. Subsequent examination of the crack by DSM determined the cause of the failure to be nitrate stress corrosion cracking of the mild steel cladding. This nitrate stress corrosion cracking was believed to have been due to the practice of spraying nitrate-treated cooling water as a means for diluting and dispersing small leaks.

To maintain production, it was decided to bypass the No. 5 reactor while repairs were being done. A temporary bypass pipe was installed between the No. 4 reactor and the No. 6 reactor. Because the reactors were mounted on a sort of staircase, this pipe was not straight but contained two bends. The pipe was 20 inches in diameter, although the short pipes that were normally used to join the reactors together were 28 inches in diameter. Bellows, also 28 inches in diameter, were installed between each reactor, and these were left at each end of the temporary pipe. This temporary bypass pipe performed satisfactorily for two months after the plant was restarted on April 1.

However, the plant had been shut down for other leaks and during the start-up procedures the process pressure rose slightly, from 125 psi to 129 psi. The bending moment, caused by the action of this slight rise in pressure, was strong enough to tear the bellows. The temporary pipe twisted with this change in the flow, and the bellows were ruptured by shear stress. As a result of the rupture of the bellows, a great amount of cyclohexane escaped from the holes in the bellows and formed a cloud of cyclohexane vapor, which subsequently caused the explosion.

At least that’s the current thought process of what happened, and it took a while to get there. The investigative findings have been debated over the years and most experts now agree that the original government inquiry had some fundamental flaws.

Here are some interesting points to consider in all of this:

  • The workers who designed the temporary pipe were not professional engineers. The only calculations made were for the capacity of the assembly needed to carry the required flow. No calculations were done to ascertain whether the bellows or pipe would withstand the forces that would be exerted.
  • No reference was made to the relevant British Standard or any other accepted standard. No reference was made to the designer's guide issued by the manufacturers of the bellows. No drawing of the pipe was made, other than in chalk on the workshop floor.
  • The support of the temporary pipe was a scaffolding structure upon which the pipe rested, without being fastened down. Therefore, the support structure could not provide enough strength to withstand against bending stresses.
  • No process analysis or management of change type function was performed when it was decided to change process conditions (while PSM did not exist at this time, the idea of performing “what-if” scenario analyses was somewhat common in some petrochemical companies).
  • The source of ignition was probably a natural gas reforming furnace some distance away. It was estimated that 30-50 tonnes of cyclohexane escaped in the 50 seconds that elapsed before ignition occurred.

The original board of inquiry used the above to state the main reason was “human error.” There was some controversy over the exact cause of the failure and whether or not there may have been an external explosion that actually caused the bypass line to fail.

One of the reasons they had such a hard time piecing things together was that all relevant operations staff was killed in the explosion, and all relevant records and instrument history were also destroyed in the explosion.

This was the official board of inquiries summary conclusion statement:

“We believe, however, that if the steps we recommend are carried out, the risk of any similar disaster, already remote, will be lessened. We use the phrase "already remote" advisedly for we wish to make it plain that we found nothing to suggest that the plant as originally designed and constructed created any unacceptable risk. The disaster was caused wholly by the coincidence of a number of unlikely errors in the design and installation of a modification. Such a combination of errors is very unlikely ever to be repeated. Our recommendations should ensure that no similar combination occurs again and that even if it should do so, the errors would be detected before any serious consequences ensued.”

The people of the United Kingdom were basically told the accident was a one-off and should never happen again. However, process safety practitioners around the world felt that the explosion was not the result of basic engineering design errors, but was rather the result of multiple instances of one underlying cause. That cause being a complete failure of plant safety procedures, including the procedural shortcoming of not getting SMEs and/or experienced personnel involved in managing a change.

I still see this as a concern in many facilities I have worked at, which means the lessons that can be learned from Flixborough are still relevant and in need of being remembered.

“Progress, far from consisting in change, depends on retentiveness. When change is absolute there remains no being to improve and no direction is set for possible improvement: and when experience is not retained, as among savages, infancy is perpetual. Those who cannot remember the past are condemned to repeat it.”

– George Santayana (philosopher, poet, novelist)

AI : Barrier in communication at workplace

A *barrier in communication* at the workplace refers to any obstacle that hinders the effective exchange of information between individuals ...