systems engineering//hazard analysis//HAZOP
HAZOP, the hazard and operability study, is a structured team method of hazard analysis that walks through a process design section by section and applies a fixed set of guide words to each parameter to imagine every deviation from the design intent, and it is the standard hazard study of chemical plants, refineries, water treatment and pharmaceuticals, run on the piping and instrumentation diagrams before construction and again before every significant change. Its output is a list of deviations, their causes and consequences, the safeguards already in place and the actions still needed.
HAZOP, the hazard and operability study, is a structured team method of hazard analysis that walks through a process design section by section and applies a fixed set of guide words to each parameter to imagine every deviation from the design intent, and it is the standard hazard study of chemical plants, refineries, water treatment and pharmaceuticals, run on the piping and instrumentation diagrams before construction and again before every significant change. Its output is a list of deviations, their causes and consequences, the safeguards already in place and the actions still needed.
The mechanism is a grid. The diagram is cut into nodes (a line, a vessel, a heat exchanger); for each node, each parameter (flow, pressure, temperature, level, composition) is combined with each guide word: no, more, less, reverse, as well as, part of, other than. Take the deviation no flow in the feed line to a reactor: causes (pump trips, valve fails closed, blocked strainer), consequences (the reactor runs dry, the cooling jacket overheats), safeguards (low-flow alarm, interlock that stops the heater), action (add an independent flow switch to the trip). The words are crude on purpose: they force the team to consider deviations nobody would have thought of by staring at the drawing.
A HAZOP is as good as the people in the room.
It is run by an independent chair with process, operations, instrumentation and maintenance engineers, over days or weeks for a large unit; the method organizes their imagination, it does not replace it, and a study done by the designers alone checks the design against itself.
It is the process world's front end to functional safety. Deviations whose consequences are severe and whose existing safeguards are insufficient become safety functions with a required integrity level, assigned by a layer-of-protection analysis and implemented in the safety instrumented system under IEC 61508 (and its process version, IEC 61511).
It finds operability problems along with hazards: a line that cannot be drained for maintenance, a start-up sequence that needs an operator in two places at once. Many teams value it as much for those.
It works on flows and parameters, which suits continuous processes and suits a drone or a machine poorly; component-heavy systems are better served by an FMEA, combinations of failures by a fault tree analysis, and software and operator interaction by STPA.