Operator Training: When 'Safe' Is a Judgment Call
Safety is our top priority. We have all heard or seen that, perhaps in the basic safety video from the plant manager or on a poster somewhere in the plant. Companies spend enormous amounts of money on safety analyses and hardware: safety instrumented systems, hazard and operability studies, layers of protection analyses and alarm management. And yet, on May 26, 11 people died at a paper mill in Longview, Washington, following the rupture of a tank.
According to the U.S. Chemical Safety Board, the tank contained hot, highly caustic white liquor. Three inspections, beginning more than 10 months before the incident, indicated that the tank wall thickness had fallen below the minimum safe thickness. The tank remained in service until a minor plant upset increased the liquid level and, consequently, the pressure, resulting in the tank failure. Why the tank remained in service is still under investigation.
When we think of human error, we usually think of things like failing to respond to an alarm or adjusting the wrong control. We are less likely to consider human error in managerial decision-making. Yet interpreting the current situation is fundamental to decisions in both the control room and the boardroom, particularly when "safety" is involved.
What does it mean to be "safe"? To be safe is to be free from risk, and risk is the probability of encountering a hazard. At its heart, then, safety is a game of probability. Some risks are easy to evaluate, such as the toss of a coin. Others are far more complex, such as the likelihood and consequences of a catastrophic event. For complex situations, reasonable people can interpret the risk differently.
I have encountered several disagreements about what it means to be safe, and at various times I have found myself on different sides of the debate. While I was developing an emergency response plan for a chlorine manufacturer, the two operations representatives scoffed at the notion that a major release could occur. They thought the probability too low to warrant consideration. Years later, those same two were in one of their garages, constructing a fix for a major leak that had forced an areawide evacuation.
In helping a refinery set safe operating limits, I found myself in a kerfuffle about whether exceeding a heat exchanger's maximum allowable working pressure and exceeding its maximum allowable working temperature were equally unsafe. One group considered them equally unsafe regardless of the probability of failure. The group I was part of did not, because the likely consequences and nature of failure were different.
The industry needs a way to help resolve such differences in the interpretation of risk. My first job out of college was for a nuclear utility, evaluating control room changes from a human factors perspective. One change involved a new set of valves intended to prevent a recurrence of a valve misalignment caused by operator error. The proposed solution was essentially to prevent the error by making the task more complex. I thought the new design would increase the probability of error, but I was in the minority. I thought it was unsafe, but what could I do? My only apparent recourse was to contact the Nuclear Regulatory Commission. While I was struggling with that decision, the project team changed the design. The result wasn't perfect, but I considered it acceptable. The NRC provided a potential independent check on management's assessment of the risk. I didn't have to use it, but it was reassuring to have the option.
The problem isn't simply that someone made a bad decision. Organizations need a way to challenge safety decisions when the people closest to the hazard believe the organization's interpretation of the risk is wrong.
The process industries do not need another government regulatory agency. What is needed is an ombudsman function, an independent third party to the discussion that can be invoked anonymously. Some companies, such as Koch Industries, have such a function. Not all companies can or do create an ombudsman within their organizations. However, the industry could create such a function within one of its many industry groups, such as the American Petroleum Institute, the American Institute of Chemical Engineers, the Center for Chemical Process Safety or American Fuel & Petrochemical Manufacturers. The purpose would not be to transfer accountability from management to the ombudsman, but to make the decision and its rationale more transparent and harder to ignore.
With all our focus on safety and safety systems, how could 11 people die from a known hazard? The answer is that bad decision-making is not limited to the control room or front-line personnel.
How can we do better? In part, an industry ombudsman could give people with legitimate safety concerns a neutral third party to challenge decisions and help determine whether the risks are adequately understood and managed — and, ultimately, whether the situation is safe.
About the Author
David Strobhar David Strobhar
David Strobhar founded Beville Operator Performance Specialists in 1984. The company conducts human factors engineering analyses of plant modernization, operator workload, and alarm/display systems for BP, Phillips, Chevron, Shell and others. Strobhar was one of the founders of the Center for Operator Performance, a collaboration of operating companies, DCS suppliers and academia that researches human factors issues in process control. He is the author of "Human Factors in Process Plant Operations" (Momentum Press) and was the rationalization clause co-editor for ISA SP18.2, "Alarm Management for the Process Industries." Strobhar has a degree in human factors engineering, is a registered professional engineer in the state of Ohio and a fellow in the International Society of Automation.
