Académique Documents
Professionnel Documents
Culture Documents
Ian Cameron
School of Engineering
The University of Queensland, Australia
PEOPLE PROCEDURES
Organizational Absence of engineers Focus on LTIs
PLANT PEOPLE PROCEDURES PROCEDURES
PEOPLE
Poor engineering Maintenance Poor Failure to Failure to identify
design backlog auditing HAZOP GP1 interconnection
PEOPLE hazards
Poor supervision PROCEDURES PEOPLE
Failure of incident
PROCEDURES PROCEDURES PROCEDURES reporting system PROCEDURES PEOPLE
Operating in Poor shift Poor maintenance
alarm mode handover priorities Inadequate procedures
& training
PROCEDURES PLANT
PEOPLE
PLANT PLANT Warm oil restart Plant interconnections
Incorrect
Condensate
operation of Warm oil pump trip PLANT
overflow Loss of
manual bypass PLANT 2 week site
valve
PROCEDURES Explosion closure supply
Cold metal embrittlement
© Ian T Cameron
PROCEDURES
PLANT PLANT
PEOPLE PEOPLE
Accident sequence
HAS Budapest 2007 © Ian T. Cameron
BP Texas City Refinery - 2005
Accident sequence
Components
Plant
People
Procedures
• Coupling
– Loose or tight (energy and control integration levels)
Raman & Cameron, 2005, Abnormal Situation Management – Is it in control?, WWCE 2005, IChemE, UK
Personnel
Production rates
Raw materials
u S y Product volumes
Profit
Environmental
Energy sources Performance
Finance Risk levels
…
x, p …
y = S[u,d]
HAS Budapest 2007 © Ian T. Cameron
A functional perspective of the system
d
S Components The intended effects Desired end
make up
Plant of the capabilities point
Capabilities x
Ci = {CiP, j : j = 1… m CSi ,k : k = 1… n}
Procedures
Bulk storage for holding Delivery system to transfer solvent Head tank to hold solvent for
solvent at a controlled rate the press
Input induced
Pressure More More ….. failure …..
pressure {<ambient><temperature><less>} ≡ {<disturb><state><s_condition>}
Disturbance
induced failure
{<valve><fails><open>} ≡ {<com><action><state>}
Provides the basis for Fault Tree
Underlying causes segments
of the failure mode
(Reason for incapability)
Automatic generation
System effects:
Impacts on wider functions
{<production><rate><less>} ≡ {<function><state><s_condition>}
{<production><quality><less>} ≡ {<function><state><s_condition>}
{<hydrocarbon><liquid><released>} ≡ {<com><state><condition>}
{<corrosion><rate><increase>} ≡ {<function><state><s_condition>}
achieves realizes
possess
Capabilities
Abilities of a component to affect
the states of the system
FM
fa
de
loc
ac
ef /sys
il
m
ur
te
fe te
al
t io
ca
po
cti
cts m
ns
us
ne
on
es
od
nt
s
es
Multiscale
τ-L-D
Scale-map
Diagnostic
Multiscale
τ-L-D
Scale-map
Diagnostic
Real-time Agents
based on R-T ontology
Real-time ACL messaging
Database Remote Agent
Directory
Monitoring Agent Management
Facilitator
GUI System
Completeness Co-ordinator
Parameter Estimator
Symptom Generator
Conflict Resolver
Loss Preventor
Conflict Resolver
Conflict Resolver
Conflict Resolver
Fault Detector
Fault Isolator
Information Decision
Acquisition Responses and
ofOperator
processing + making
information (goal driven) physical activity
(logic)
interface
y u
S
d disturbances
see Rasmussen, Vicente, Sanderson