95WKS 4 Major Hazard Facilities Safety Assessment
95WKS 4 Major Hazard Facilities Safety Assessment
SA
F E T Y AT
W GOOD PRACTICE
GUIDELINES
O
H
R
LT
K
• HEA
AC T
HSWA
ACKNOWLEDGEMENTS
In recognition of the valuable contribution made towards the development of this guideline, WorkSafe
New Zealand (WorkSafe) would like to thank the members of the guidance group and those who provided
input and feedback during reviews and consultation.
WorkSafe would also like to acknowledge the following organisations for providing information used
to develop this guideline:
>> Health and Safety Executive (UK)
>> National Offshore Petroleum Safety and Environmental Management Authority (Australia)
>> Safe Work Australia
>> WorkSafe Victoria (Australia).
SAFETY ASSESSMENT
KEY POINTS:
01 INTRODUCTION 4
1.1 Purpose and scope of this guideline 5
1.2 What is a safety assessment? 5
1.3 How you can use this guideline 6
1.4 How this guideline fits into the suite of guidelines 6
1.5 Worker engagement, participation and representation practices 8
04 SAFETY ASSESSMENT 25
06 APPENDICES 45
TABLES
FIGURES
01/
INTRODUCTION
IN THIS SECTION:
1.1 Purpose and scope of
this guideline
1.2 What is a safety assessment?
1.3 How you can use this guideline
1.4 How this guideline fits into
the suite of guidelines
1.5 Worker engagement,
participation and
representation practices
4
SECTION 1.0 // INTRODUCTION
Table 1 presents an overview of the different types of facility and the corresponding obligations
imposed by the MHF Regulations. The focus of this guideline is on the safety assessment.
Notification
Emergency plan
Safety assessment
Safety case
A safety assessment generally follows the hazard identification process although some
duplication between the two processes may be necessary. Hazard identification determines
the hazards and causes of major incidents and starts to identify the range of controls that
provide protection against a major incident occurring. Knowledge of hazards and their
5
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
Coloured boxes summarise sections of the Regulation 39 requires the SMS to manage
MHF Regulations or the Health and Safety all aspects of risk control in relation to major
at Work Act 2015 (HSWA). incidents at the facility.
6
SECTION 1.0 // INTRODUCTION
Notification and
design notice
Designation
Prepare and
MHF: Safety Cases
submit safety
(Guideline)
cases
KEY
Operator
WorkSafe
LTMHF Lower tier major hazard facility
UTMHF Upper tier major hazard facility
7
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
8
SECTION 1.0 // INTRODUCTION
Provide reasonable
Engage with workers
opportunities for workers
+
on health and safety
to participate effectively in
matters that will – or
improving health and safety
are likely to – affect them.
on an ongoing basis
Ask questions
Share Information
WORKER
ENGAGEMENT,
PARTICIPATION AND
PCBU WORKERS
REPRESENTATION
Identify risks
Suggest Ideas
…effective worker participation is vital to managing health and safety issues successfully
in the workplace1.
The best results are achieved when a PCBU and its workers work together to manage risk,
improve health and safety at work, and find solutions.
1
The Report of the Independent Taskforce on Workplace Health & Safety: He Korowai Whakaruruhau (2013)
http://hstaskforce.govt.nz
9
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
02/
SAFETY
ASSESSMENT
OVERVIEW
IN THIS SECTION:
2.1 Expected outcomes
2.2 The safety assessment process
2.3 Engagement and consultation
2.4 Review of safety assessment
10
SECTION 2.0 // SAFETY ASSESSMENT OVERVIEW
>> routine or abnormal operations >> the critical operating parameters identified
for the selected controls
>> any off-site hazard that could reasonably
impact on the site, leading to a major >> the reasons for deciding which controls to
incident. implement with a documented justification
of any potential control considered not be
reasonably practicable
2.1 EXPECTED OUTCOMES
>> a description of how the identified controls
The safety assessment should demonstrate
prevent or minimise the major incidents
you are reducing risks of major incidents
and major incident hazards
so far as is reasonably practicable and there
>> demonstration of the adequacy of controls
is ongoing review.
for each major incident, so far as is
The outcomes of a robust safety assessment reasonably practicable
process should be:
>> an implementation plan for controls not
>> a list of all identified major incidents/ yet in place
scenarios
>> a description of how you will review and
>> the criteria and methods used to continually update the safety assessment
identify the major incident hazards
>> the path by which the major incident
and major incidents
hazards could lead or have led to a
>> an assessment of the cumulative major incident.
effects of the major incidents:
Use safety assessment tools and techniques
–– incidents that could reasonably
appropriate to your facility. Make sure you
lead to initiating further incidents
can explain and justify your choice.
–– multiple incidents from one
common hazard 2.2THE SAFETY ASSESSMENT
–– the exposure of one person or group PROCESS
of people to several hazards.
Table 2 summarises the steps to take when
>> identification of consequences for each
conducting one type of safety assessment
major incident without controls
and describes some matters to consider when
>> analysis of risk (likelihood and consequence) undertaking each step. Note that this list is an
for each major incident (with current example of an approach. It is not exhaustive,
controls and then with planned controls) and there may be other matters to consider
>> identification of the local community at each step.
potentially affected by the consequences
of any major incident
11
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
STEP CONSIDER
Prepare facility >> Establish scope: whole or part of facility, include routine and non-routine
description to activities, on and off-site hazards.
establish context >> Linkages between the facility description and hazard identification.
Establish required >> Composition of the hazard identification team, worker engagement
hazard identification and participation.
team and >> Competence and expertise of the hazard identification team.
competency >> Competency and independence of the facilitator.
Track remedial >> Method for tracking and closure of remedial actions and committed
actions further actions.
Monitor and review >> Revise safety assessment as necessary, for example, if there are changes
to the facility, process or new controls identified.
12
SECTION 2.0 // SAFETY ASSESSMENT OVERVIEW
Hazard identification
Evaluate risk
NO
Is implementing
YES Plan
additional controls
reasonably implementation
practicable?
> Specific
> Measurable
NO > Appropriate
> Realistic
> Timely
Is risk
Stop reduced so far as
NO YES Develop performance
process is reasonably practicable standards for controls and
or activity and does risk meet
safety-critical elements
until further any internal risk
controls criteria?
can be
identified
Integrate performance
standards into SMS
13
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
a team approach, accountability and roles an ongoing basis. Whether this review is
assigned, and a clear plan established regarding continuous or periodic depends on your SMS.
who does what. An elected and trained health Continually review residual risks and determine
and safety representative (HSR) could be if the risk should be re-evaluated.
assigned to the project.
Review and, as necessary, revise the safety
The assessment process will benefit if a assessment when:
cross-section of workers attends workshops, >> ongoing review indicates a change or
with sufficient resources allocated to them. proposed change to the MHF could:
Consider using workers who have insight
–– create a major incident hazard that
into the risks, and could directly influence
had not been previously identified
and advise on controls. You may choose to
use workers to lead hazard identification –– increase the likelihood of a major
You must consult with the Police, Ambulance, associated with that hazard, is identified
and New Zealand Fire Service emergency >> the results of engagement with workers
services and WorkSafe. Use the information indicate that a review is necessary
and recommendations they provide to inform >> a HSR requests a review because the
the safety assessment process. HSR reasonably believes that grounds for
For more information on consulting with the review exist (which may affect the health
emergency services see WorkSafe’s GPG and safety of workers) and you have not
14
SECTION 2.0 // SAFETY ASSESSMENT OVERVIEW
15
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
03/
MAJOR INCIDENT
AND MAJOR
INCIDENT
HAZARD
IDENTIFICATION
IN THIS SECTION:
3.1 Select the right technique
3.2 Major incident identification
3.3 Identify the major incident
and major incident pathways
3.4 Identify all specified
hazardous substances
3.5 Understand the hazardous
substances properties and
how they could cause harm
3.6 Identify major incident hazards
over the facility life cycle
16
SECTION 3.0 // MAJOR INCIDENT AND MAJOR INCIDENT HAZARD IDENTIFICATION
3.1 SELECT THE RIGHT multiple methods – but only use those most
TECHNIQUE relevant and best suited to the MHF:
Apply hazard identification and safety >> Audit findings and pending issues
assessment methodology suited to your >> Bow ties
operation and the major incident hazards >> Chemical reactivity hazard matrix
considered. For a UTMHF, justify your
>> Concept hazard analysis
reasons for technique selection in the
>> Event tree analysis (ETA)
safety case as well.
>> Failure modes and effects analysis (FMEA)
Hazards vary depending on the industry
>> Failure modes, effects and criticality
and operation. Hazards in complex chemical
analysis (FMECA)
operations will be different from those
for storage operations. Various hazard >> Fault tree analysis (FTA)
identification and assessment techniques >> Fire and explosion study
exist that can be used successfully. Multiple >> Hazard and operability study (HAZOP)
techniques are usually required to adequately
>> Hazard Identification (HAZID)
identify and assess all the major incident
>> Historic records of incidents both at the
scenarios. Make sure techniques:
facility and within industry, including near
>> are fit for the complexity and scale
misses
of the MHF
>> Human reliability analysis (HRA)
>> are chosen with meaningful engagement
>> Job safety analysis (JSA)
and participation by appropriately
skilled and knowledgeable workers >> Layers of protection analysis (LOPA)
17
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
18
SECTION 3.0 // MAJOR INCIDENT AND MAJOR INCIDENT HAZARD IDENTIFICATION
Major incident is defined in Regulation 9, The definition of major incident is not limited to
and has the following qualities: uncontrolled events which only cause or have
the potential to cause multiple fatalities. This is
>> they result from an uncontrolled event
because the MHF Regulations cover substances
(ie unplanned or involving the failure
with a variety of hazardous properties, some
of one or more controls)
of which cannot cause fatalities.
>> they involve or potentially involve specified
hazardous substances. This includes events There are incidents that do not involve or
initiated by other circumstances that may potentially involve specified hazardous
knock-on to specified hazardous substance substances, but that do potentially expose
storage or handling facilities multiple people to a serious risk to their health
or safety. These incidents do not have to be
>> they expose multiple people to a serious
included in the safety assessment and safety
risk to health and safety (at least two, and
case as they do not meet the definition of a
often more than two people, including
major incident. However, you still have the
those in the area surrounding the facility)
primary duty of care to make sure workers
>> the risk emanates from an immediate or
and others are not at risk from work carried
imminent exposure (which excludes long-
out at the facility. Adequately manage these
term cumulative impacts such as some
risks via the SMS and emergency plans
types of cancer) to:
prepared for the facility.
–– one or more of those substances as a
Major incident hazards are defined as those
result of the event
hazards that could cause or contribute to
–– the direct or indirect effects of the event.
causing a major incident or uncontrolled event.
Occurrences that may be classified as a major The intent is for the facility to fully understand
incident include: and control the chain of events (major incident
>> escape, spillage or leakage of a substance pathways) that may lead to a major incident.
(eg damage, overfill, decay) Identifying the potential major incidents
>> implosion (eg vacuum from steam requires some creativity, technical expertise,
condensation) and familiarity with the plant and equipment.
>> explosion (eg boiling liquid expanding Major incident hazard identification should be
vapour explosion (BLEVE), vapour performed in teams. It is important teams:
cloud explosion) >> understand what constitutes
>> fire (eg loss of containment which a major incident
could lead to fire, pool fire, jet fire, >> are composed of an appropriate variety
flash fires, fireball). of people
The uncontrolled event which may lead to >> are aware of the properties of the specified
a major incident has a spectrum of possible hazardous substances
consequences. If any of the possible >> are aware of how the hazardous substances
consequences of the event may lead to are used
serious risk to health and safety of multiple >> are familiar with the activities that occur
people, then the event leading to the serious within the processes, operation and
risk must be classed as a major incident. maintenance of the facility
Serious risk includes risk leading to death.
>> are aware of plant and industry incident
history
19
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
20
SECTION 3.0 // MAJOR INCIDENT AND MAJOR INCIDENT HAZARD IDENTIFICATION
>> The hazard of incompatible materials >> Stress corrosion cracking prevention
mixing in a storage warehouse was may require maintenance of water
rejected because procedures state they concentration within a certain range.
must not be stored together. Procedural
controls do not remove the potential Example 8: Understanding how the
major incident. equipment is designed to fail
These potential major incidents have been Engineers may design equipment with the
inappropriately rejected based on the intent that it shall ‘leak before break’, giving
selected controls. These major incidents the operators time to either isolate or remove
can still occur. the items before there is sufficient quantity to
cause a major incident. The incident pathway
Regulation 38 requires the safety is not eliminated, but the probability of major
assessment identify hazards and conditions incident is reduced. Examples include:
that could lead to a major incident. >> LPG hoses are designed to leak before
breaking. The hose can be safely taken
VALIDATE THE MAJOR INCIDENT PATHWAYS out of service without a major incident
even if it does leak.
The objective is to gain a detailed
understanding of what can go wrong. >> LPG hoses tend to creep as they
This helps you assess which controls are deteriorate. Spraying the hose connection
necessary, and what performance indicators with paint allows detection of this creep
and standards are required. Use work done and removal before any leak takes place.
at this stage later in the likelihood analysis
and consequence estimation. It is reasonable 3.4 IDENTIFY ALL SPECIFIED
to focus effort in understanding the major
HAZARDOUS SUBSTANCES
incidents of highest concern.
Consider all specified hazardous substances
Example 7: Understanding corrosion in the safety assessment, including:
as an initiator >> products
A HAZOP team identified the potential for >> by-products
corrosion to cause a loss of containment.
>> intermediates
It is necessary to further understand this
hazard as there are various approaches >> raw materials
>> Regular pre-emptive maintenance It does not matter whether they are held
to prevent corrosion. in storage, in process, or being transferred
>> Corrosion from erosion may be or otherwise handled.
controlled by velocity. This includes small isolated quantities that
>> Internal corrosion from acid attack may may be excluded from the notification
be controlled by regulation of pH and requirement. For more information, see
monitoring of coupons. WorkSafe’s GPG Major Hazard Facilities:
>> External ‘under insulation’ corrosion Notifications and Designation.
occurs more often in dead legs
and cannot occur above certain
temperatures.
21
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
>> chemical reactivity and interactions >> Ammonia is a toxic material and also
soluble in water to form an alkaline
>> incompatibilities
solution. At high pressures and
>> physical state
temperatures ammonia is capable of
>> concentrations forming an explosive mixture with air.
>> solubility >> If chlorpyrifos is heated above 90°C
>> properties at temperatures and pressures it decomposes. Above 130°C there
that may occur at the facility. is an exothermic decomposition
(runaway reaction).
The properties need to be understood at the
conditions encountered in the facility during
both normal and abnormal operations. These
properties will have a significant impact on
what, if and how a major incident will occur.
22
SECTION 3.0 // MAJOR INCIDENT AND MAJOR INCIDENT HAZARD IDENTIFICATION
23
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
>> Choice of >> Start-up >> Chemical >> Physical hazards >> Draining and
process procedures hazards (eg (eg dropped emptying of
technology >> Plant change flammable, objects, vehicle dangerous goods
>> Choice of process poisonous, collisions) >> Hazardous waste
equipment >> Loss of corrosive) >> Chemical disposal
>> Quality of containment >> Process hazards (eg >> Disassembling
materials issues (because hazards (eg welding, acid of equipment
>> Infrastructure of pumping, temperature, cleaning) >> Transportation
considerations equipment pressure and >> Site security and disposal etc
(eg transport, testing and flow changes) >> Electrical (eg >> Loss of expertise
communications, other process >> Fire and equipment, and plant
occupied start-up explosion (eg rating, static knowledge if in
buildings) activities) heat radiation, electricity, receivership etc
>> Construction >> Emergency overpressures, grounding, >> Shut-down
standards preparedness thermal flux) surges) requirements
>> Compliance with >> Initial fill prior to >> Procedures >> Permit-to-work >> Hauling and
legislation start-up related (eg system (eg for demobilisation
>> Checking fail normal high pressure
>> Process hazards >> Lock off of facilities
safes and operations, lines, mechanical
(eg temperature,
monitoring operating and electrical
pressure and
outside design systems)
flow changes) >> Hauling,
envelopes >> Coordination/
>> Electrical (eg mobilization &
positioning of >> Plant and notification with
equipment,
equipment and process operations re
rating, static
facilities changes maintenance
electricity,
grounding, >> Pressure >> Human factors activities
surges) testing and >> Required >> Depressurising
>> Firefighting maintenance controls and and cooling
equipment coordination their critical of hydraulics,
>> Simultaneous operating pneumatics,
>> Certifications
operations parameters and thermal
>> Factor of safety
involved in pre- equipment
used in the
commissioning before repair
design
Table 3: Some considerations for identifying major incident hazards during the facility life cycle
Note: Some stages may overlap, with considerations starting in one and continuing into another,
or being relevant through multiple stages.
24
04/
SAFETY
ASSESSMENT
IN THIS SECTION:
4.1 Likelihood analysis
4.2 Consequence estimation
4.3 Risk assessment
4.4 Risk evaluation
25
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
Likelihood analysis and consequence estimations are generally considered at the same time as
the hazard identification for developing controls against the hazard leading to a major incident.
After finding out likelihood and consequence, risk can be assessed.
Table 4 lists typical data sources and matters to consider while carrying out likelihood analysis.
Historic incidents, incidents, near misses >> Reliability and relevance of data
>> References for the data
>> Statistical significance based on population sample size
Fault tree, event tree, cause consequence >> Estimation of failure frequencies
diagrams
26
SECTION 4.0 // SAFETY ASSESSMENT
Standard databases and literature >> Suitability of data for the given conditions
>> Referencing the source of data (eg generally used
sources for obtaining information on standard failure
frequency rates, Health and Safety Executive (HSE),
DNV GL, OREDA, Chlorine Institute literature)
>> Statistical relevance of the data source in the literature
Safety alerts/bulletins >> Alerts from WorkSafe and various regulatory agencies
and institutes (eg HSE, Chemical Safety Board, Chlorine
Institute, American Petroleum Institute, Centre for
Chemical Process Safety)
Experiences and other sources >> Based on the experience and expertise of the workers
involved in the likelihood analysis process
>> Failure frequency database or incident database
maintained by the industry
Standard tools and techniques for the analysis include fault trees, event trees, LOPA and bow-tie
analysis. These have all been used successfully. Common mistakes are to:
>> claim benefit from controls that are not truly independent
>> misapply the techniques
>> fail to:
–– involve workers to gain realistic views/assumptions of the situation
–– validate analysis with audit findings, previous incidents, repair history, modifications
and worker changes
–– define likelihood criteria clearly
–– consider performance under all operating conditions
–– validate the current performance of existing controls.
It is also important to consider the influence of human factors on likelihood and include them
in the safety assessment. This may be achieved by identifying the possible human factors at
play and managing those factors within the SMS. Quantitative human factor assessment tools
are available, for example human error assessment and reduction technique (HEART), and can
be incorporated into the analysis of identified incident scenarios if appropriate or required.
They also examined the workload during critical periods and introduced:
>> additional resources for planned start-ups and shutdowns
>> an alarm reduction system focused on removing alarm flooding.
27
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
Any major incident has a range of potential consequences. You must identify the worst credible
consequence of a major incident where no controls are in place. The basis of this calculation
(inventory, external conditions, etc) should be clearly documented and discussed.
The intent is to understand and be prepared for the worst major incident. Premature focus on the
associated risk misses the opportunity to decide the consequence is not to be tolerated (as has
been decided by many oil companies about locating temporary maintenance building near vents
after the Texas City incident).
28
SECTION 4.0 // SAFETY ASSESSMENT
They concluded nearby neighbours (up to >> if the fire is caught early enough
500 m) could be affected. The number of (small fires are easily extinguished).
people affected would depend on the time
The nature of the (toxic) smoke plume
of day. The nearest sensitive receptor was
depends on:
a residence 1 km away and unlikely to be
>> wind speed and direction
affected by any event at the warehouse.
A nearby office building, however, had >> fire temperature (there are different
significant amounts of glass facing the stages of a fire, with different
facility that could be particularly vulnerable temperature profiles)
to heat. The facility chose to commission >> the nature of the burning chemicals.
modelling to establish the potential and
The operator realised that weather
recommend options to minimise potential
conditions and inventory had the greatest
impact in the event of a fire.
impact on the consequence zone. The time
of day also significantly influenced how
SENSITIVITY ANALYSIS many people were likely to be affected.
The actual consequence of an event will As the operator cannot control the weather,
be the result of a number of factors and is it was decided to focus on preventing the
unlikely to be the worst case. It is important incident, and ensuring fast communications
to understand which factors are important and response if an incident did occur.
and how the consequence severity varies
with variation in those factors (a sensitivity CONSEQUENCE MODELLING
analysis). This allows you to understand the WITH CONTROLS
performance requirements when planning for
Assessing consequences with controls
an emergency, and identifies additional risk
represents the most likely consequence.
minimisation methods.
All facilities benefit from being aware of
For more information on emergency planning, the most likely consequence when deciding
see WorkSafe’s GPG Major Hazard Facilities: priorities. You should control the most likely
Emergency Planning. events and the worst events. They can be
different major incidents.
Example 15: Warehouse fires
ABC Warehousing understood the ferocity USING THE CONSEQUENCE
of the fire depends upon: MODELLING
>> the nature of the stored chemicals
A common mistake is to commission
(eg flammable liquids ignite easily)
consequence and risk modelling from a
>> how the chemicals are stored consultant, fail to validate the results and fail
(combustible materials add to fire load, to use the information in emergency planning,
high racking may inhibit sprinkler systems, in both locating equipment and offices and
and packages of flammable liquids may in identifying potential knock-on events.
burst with heat, ignite and spread fire When commissioning modelling, consider if it
throughout the bund compound) would be worthwhile to complement fatality
>> how long it takes to detect the fire calculations with distances to injury or even
(automatic versus manual detection) distances to irritation/nuisance to understand
fully the potential consequences. This may
29
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
Make sure you have addressed any potential Types of risk assessments include:
credible events that may act as a knock-on >> quantitative risk assessments – all risks
event. Assessing effect ranges allows you to are quantified by using recognised data
find out if it is reasonably foreseeable for one and are numerically expressed
major incident to escalate and cause another.
>> semi-quantitative risk assessments –
Major incidents may also be triggered by
risks associated with a major incident
significant process safety events associated
are generally quantified by using industry
with non-specified hazardous substances
specific or site data
that knock-on or affect systems storing or
handling specified hazardous substances. >> qualitative risk assessments – assessment
of risk from subjective, considered opinion
Example 16: Knock-on events based on operating experience.
>> A small fire in a drum decanting operation There is no specified quantitative risk level
could spread to an adjacent large drum that is acceptable, so do not interpret ranking
store by a common drain system. as a requirement to conduct a quantitative
>> A boiler ruptures when the drum level risk assessment. Also, meeting any of the
reduces below the fire line. Projectiles quantitative risk criteria does not necessarily
damage the adjacent control room, prove that you have reduced risk so far as is
leading to a loss of control of a reasonably practicable.
production unit processing specified
Risk matrices can be useful tools, but need
hazardous substances.
to be simple, relevant, and used by skilled
>> A rupture of a large nitrogen storage assessors. They should not be the only risk
vessel causes local evacuation and analysis technique employed. The best results
prevents operators from responding are when a risk matrix is used where controls
to a dangerous process excursion. are in place, to test whether the remaining risk
is acceptable. Appendix A: Risk criteria offers
further detail on risk matrices.
30
SECTION 4.0 // SAFETY ASSESSMENT
ABC Company used these results to satisfy land use planning requirements and internal
risk tolerability targets. It does not, of itself, establish the risk has been reduced so far as is
reasonably practicable.
CONSEQUENCE
1 2 3 4 5
Possibility of
5 repeated events
(1 x 10-1 per year)
Possibility of
4 isolated incidents
(1 x 10-2 per year)
Possibility
of occurring
3
sometimes
(1 x 10-3 per year)
Rare occurrence
1
(1 x 10-5 per year)
KEY
Low risk Moderate risk Significant risk High risk
The company used the relative placement on the matrix to prioritise risk reduction projects.
Potential major incidents in the significant or high-risk category had to be documented and
their management explained to senior officers of the company.
31
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
The risk to individuals and workgroups >> Consider risk in concert: the evaluation
from both individual and collective events of the consequences of major incidents
(total risk) needs to be considered for all occurring in quick succession
populations exposed to or affected by those (eg an earthquake followed by tsunami).
events (near and far field). >> Consider risk by location: It may be useful
You can use risk matrix to represent the to consider whether the major incident
relative consequence and likelihood of an risk is concentrated in specific locations
incident. Determine the level of risk acceptable or roles. In these cases, additional controls
to the organisation collaboratively, engaging may be prudent to reduce the likelihood
with workers and consulting other key or consequence, and reduce risk.
stakeholders. Where the determination of cumulative
risk from multiple scenario is necessary,
Regulation 38 requires the safety
a quantitative risk assessment tool (eg
assessment be conducted using assessment
Quantitative Risk Assessment) other than, or
methods (including quantitative or
as well as a risk matrix, may be appropriate.
qualitative, or both) that are suitable for
The risk matrix method may underestimate
the hazards and major incidents being
the likelihood of an event by taking credit
considered.
of a barrier that could be a causal factor
for a failure event in another scenario.
RISK RANKING
32
SECTION 4.0 // SAFETY ASSESSMENT
The safety assessment determined that each hazard individually was in the significant risk
zone on a risk matrix. However, the one operator responsible for this area is exposed to the risk
presented by all of them since he spends the shift close to the reactor. Therefore, cumulatively,
the likelihood of the operator being exposed to a major incident is sufficient to increase the risk
faced by that operator into the high-risk zone.
CONSEQUENCE
Individual risks
KEY
Moderate risk Significant risk High risk
After reviewing this situation, the company decided to relocate the operator’s control console
to a central control room.
You will need to complete risk evaluation several times during the safety assessment process:
>> Before the controls are considered to determine the level of risk of the major incident hazard
without controls in place.
>> After the existing controls are considered to determine the current level of risk of the major
incident hazard and whether the risk is acceptable and has been reduced so far as is practicable.
>> After additional controls are identified to determine whether the additional controls reduce
the risk so far as is practicable.
It is very unusual for an operator to complete a safety assessment without a risk reduction plan
or list of items that are “on watch”. These could undergo changes in technology or other means
that may move risk reduction from impractical to reasonably practical.
33
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
34
05/
CONTROLS
IN THIS SECTION:
5.1 Identify controls
5.2 Demonstration of adequacy
5.3 What is reasonably
practicable?
5.4 Safety-critical elements
5.5 Develop performance
standards for controls
5.6 Critical operating parameters
35
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
36
SECTION 5.0 // CONTROLS
To identify controls, you need to understand >> Critical operating parameters have been
what needs to happen for the control to identified for safety-critical elements,
be effective, and manage that control in its compliance with which is necessary to
entirety. For example, an alarm without an avoid a major incident.
operator to notice its activation and respond, >> Existing performance standards for
has no safety benefit. A procedure only has a adopted controls have been considered (or
safety benefit if it is technically adequate and devised if absent).
workers are competent in its use. Engineering
>> You can show the adopted controls are
standards are only of benefit if they deal with
capable of maintaining operation within the
the issue at hand and are applied.
identified safe operating window.
>> Record identified controls rejected during
5.2DEMONSTRATION OF
the safety assessment, and the reason why
ADEQUACY
they were rejected (ie the justification of
The MHF Regulations are an example of a why they are not reasonably practicable).
proactive, performance-based regime, where
The safety assessment will have identified
a general expectation for performance is set in
what could and should be done to minimise
HSWA but you select the best way to achieve it.
and control risks. The onus is now to adopt
HSWA requires a performance standard and implement those controls. The means of
of ‘so far as is reasonably practicable’. implementing and maintaining the effectiveness
You must demonstrate the identified controls of the adopted controls is via the SMS.
eliminate or, if it is not reasonably practicable
to eliminate, minimise risks so far as is An assessment of whether doing something
reasonably practicable. is reasonably practicable must be carried
out in accordance with Section 22 of HSWA.
Consider the following factors: Regulation 30 requires the controls in the
>> The assessment includes both controls event of a major incident occurring, minimise
that eliminate and minimise risks. the magnitude and severity of its health and
>> The full range of operating and start-up/ safety consequences to people on-site and
shut-down conditions. off-site, so far as is reasonably practicable.
37
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
>> the degree of harm that might result from The massive explosion that occurred at
the hazard or risk (eg fatality, multiple the Buncefield Fuels Terminal in the UK in
injuries, medical or first aid treatment, 2005 significantly changed what that sector
long-or short-term health effects) ‘knows, or ought reasonably to know’ about
>> what the person concerned knows, the hazards or risks at this type of facility.
or ought reasonably to know, about: As a result, it is now reasonable to expect
that controls to prevent similar tank overflows
–– the hazard or risk
would be more robust than before.
–– ways of eliminating or minimising
the risk The final consideration is to weigh up the
cost of additional controls against the
>> the availability and suitability of ways
extent of risk reduction that could actually
to eliminate or minimise the risk
be obtained. This is similar to the process
>> the cost associated with available ways
many operators go through each year when
of eliminating or minimising the risk.
deciding which improvement projects to
This includes whether the cost is grossly
add to next year’s investment plan and
disproportionate to the risk. In other words,
which to defer. For many possible projects/
controls should be implemented unless the
improvements, qualitative comparisons are
risk is insignificant compared with the cost
sufficient. However, more detailed quantitative
of implementing the controls.
comparisons are often undertaken for more
important or high-cost projects.
Example 22: Identifying what is reasonably
practicable and recording this information Although the cost of eliminating or
Using an ammonia plant (UTMHF) as an minimising risk is relevant in determining
example, the identification and assessment what is reasonably practicable, there is a clear
steps may have identified the area with the presumption in favour of safety ahead of
highest likelihood of a loss of containment cost. Only consider cost after identifying the
is the tanker loading area. It is reasonable extent of the risk and the available ways of
to expect the operator has thought about eliminating or minimising the risk.
the controls needed for this area. The safety The costs of implementing a particular control
case should be able to explain this. may include costs of purchase, installation,
The operator and MHF designers may maintenance, and operation of the control
also have concluded the worst case and any impact on productivity as a result
scenario (ie major incident with the highest of the introduction of the control.
consequence) is catastrophic failure of the A calculation of the costs of implementing
large ammonia storage tank. Therefore it is a control should consider any savings
reasonable to expect that more effort is put from fewer incidents, injuries and illnesses,
into the design and controls for this part of potentially improved productivity and
the MHF because of the high-consequence reduced staff turnover.
should this failure occur. The information in
the safety case should demonstrate that this
worst case scenario has been addressed.
38
SECTION 5.0 // CONTROLS
Where the cost of implementing controls is Table 6 is a mock-up derived from Figure 5
grossly disproportionate to the risk, it may that shows specific controls listed for specific
be that implementing them is not reasonably hazards. However, tables showing a list of
practicable and therefore not required. This hazards in one column and a list of controls
does not excuse you from doing anything in another column (such as the mock-up in
to minimise the risk so far as is reasonably Table 7) do not help demonstrate that controls
practicable. Instead use a less expensive way reduce the risk of all identified hazards. They
of minimising the likelihood or consequence. do not clearly show which controls act for
which hazards and whether all hazards have
Safety cases submitted by UTMHFs may
an identified control.
contain examples where you’ve made similar
comparisons of alternative controls before The second aspect is the level of risk that
deciding which to adopt for specific risk remains after you have decided it is not
scenarios. reasonably practicable to do any more.
One means of gauging the validity of these
The safety assessment should provide
decisions is by comparing the final risk with
the information needed to make these
a suitable published benchmark.
judgements. Therefore much of the reasoning
behind your selection of controls may already Numerical evaluation of risk is only as good
be presented in the safety case (ie in the as the data you use in the evaluation of
summary of the safety assessment). The extra likelihood and consequences, both of which
information required to make a convincing are subject to much uncertainty.
demonstration will depend on the amount of
Appendix A: Risk criteria provides examples
detail included in the summary.
of criteria that can be used in relation to major
For more information on safety cases, incidents. These are not exhaustive and you
including the safety assessment summary, may choose to use criteria different from these
see WorkSafe’s GPG Major Hazard Facilities: examples. Whatever criteria are used, you
Safety Cases. will have to justify the criteria as suitable
and appropriate to the specific facility.
DO CONTROLS MINIMISE RISK SO FAR AS IS
REASONABLY PRACTICABLE?
39
40
0612 0610 0605
NDT Equipment Natural
Equipment Inspection specification ventilation of
corrosion programme and design storage area
to ABC
CRITICAL standards 0613
Maintenance Unignited Gas detection
error (eg ammonia in storage
0600 Inhalation
fitting too release – area
Trade of ammonia
hard, wrong inhalation
qualified fumes
component of ammonia 0632
workers PPE available
– not fit for fumes
service
0631
0610
Medical
Equipment
Leak from assistance
specification 0610
flange/ Component available
and design Valve and
seal gasket failure onsite
to ABC flange fitting
failure standards 0620
Emergency
CRITICAL plan 0632
PPE available
CRITICAL Ammonia
0617 Ammonia mixing with
0631 Generation
Onsite Storage area release at 0622 nearby
0618 Medical of chlorine
vehicle is protected storage Emergency store of
Speed limits assistance
collides with (chained isolation valve hypochlorite
on site available
storage tank off/vehicle
onsite
barriers) 0604
Gas detection
0629
0616 Relocate 0621
Dropped
Lifting gear equipment Ignition control
object Storage tank
inspection, requiring
(lifting over punctured
maintenance fitting 0624
storage tank)
and testing 0635 Ammonia Foam
CRITICAL Escalation to
Hot work Hot work release and generation
other vessels
permit ignition capabilities
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
0606 0619
Pressure 0625
Overfilling of ABC operating 0636 Separation
valve relief Overpressure
storage tank procedures for Furnace Separation distance
filling tank CRITICAL distance
0630
Tank
External heat designed KEY
source for 50°C
(eg sun) service (as Hazard Hazard pathway Major incident Outcome
per design
standards)
Figure 5: Example bow-tie showing an ammonia release at storage (control colour as per the hierarchy of controls)
SECTION 5.0 // CONTROLS
Equipment corrosion >> Non-Destructive Testing (NDT) inspection program >> High
>> Equipment specification and design to ABC standards >> Medium
Leak from flange/seal – >> Equipment specification and design to ABC standards >> Medium
gasket failure >> Valve and flange fitting training >> Medium
On-site vehicle collides >> Storage area is protected (chained off/vehicle barriers) >> High
with storage tank – restricted access
>> Speed limits on-site >> Low
Dropped object (lifting >> Lifting gear inspection, maintenance and testing >> Medium
over storage tank) >> Relocate equipment requiring lifting >> High
HAZARD CONTROLS
>> Dropped object (lifting over storage tank) >> ABC operating procedures for filling tank
>> Equipment corrosion >> Equipment specification and design to ABC
>> External heat source (eg sun) standards
>> Leak from flange/seal – gasket failure >> Lifting gear inspection, maintenance and testing
>> Maintenance error (eg fitting tightened too far, >> NDT inspection program
>> wrong component – not fit for service) >> Pressure relief valves
>> On-site vehicle collides with storage tank >> Relocate equipment requiring lifting
>> Overfilling of storage tank >> Speed limits on-site
>> Storage area is protected (chained off/vehicle
barriers) – restricted access
>> Tank designed for 50°C service (as per design
specification)
>> Trade qualified workers
>> Valve and flange fitting training
41
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
2
See Layers of Protection Analysis, Simplified Process Risk Assessment, Center for Chemical Process Safety, American
Institute of Chemical Engineers, 2001.
42
SECTION 5.0 // CONTROLS
Information on safety-critical elements can also be found in the GPG Major Hazard Facilities:
Safety Cases.
The performance standards are the parameters against which controls are assessed to make sure
they reduce risk so far as is reasonably practicable.
In developing these standards you should consider what level of performance is reasonable
to achieve from each control. It is important the parameters set in the performance standard
are specific (well defined and not open to wide interpretation), measurable, appropriate, realistic
and timely (SMART).
Performance standards are required for each control to make sure the effectiveness of that
control is tested and that a control failure is detected and remedied. The overall effectiveness
of the control can be judged by measuring its performance against the standard.
For more information on performance monitoring of controls and SMS elements see WorkSafe’s
GPG Major Hazard Facilities: Major Accident Prevention Policy and Safety Management Systems.
For the pressure safety valve in the table above, the corrective action in the event of failure
(ie not relieving at the set pressure) may be:
>> replacement
>> recalibration
>> reset.
This depends on the valve and service. The root cause of a trend of failures should also be
investigated. The second effectiveness measure may be reported to management, while the
first is used primarily as a guide for maintenance workers to determine what action to take in
response to failure.
43
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
parameter occurs. Define COPs for those >> maximum reactant addition rate for
parameters where there is a high reliance on a reactor
a worker to respond to a process or manage >> minimum cooling water flow rate for
an activity appropriately. Make sure that COP a reactor
documentation is continuously available to
>> maximum rpm of a high-speed turbine
workers and that it provides clear guidance as
to how people should respond if a deviation >> maximum number of pallets to be stored
investigation, including risk assessment, should >> maximum height or number of vertically
be conducted and outcome documented. stacked pallets in a storage area.
Known unsafe or
uncertain zone
COP never
Buffer zone exceed limit
operating window
Known safe
COP range
Troubleshooting
zone
Normal Maximum
operating zone normal
operating limit
44
06/
APPENDICES
IN THIS SECTION:
6.1 Appendix A: Risk criteria
6.2 Appendix B: More information
6.3 Appendix C: Glossary
45
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
6.1 APPENDIX A: RISK CRITERIA >> an upper region where ALARP has not been
demonstrated and risk is unacceptable
Comparison of estimated risk levels against set
>> a middle region where risk is tolerable
criteria may be useful as part of demonstrating
if ALARP is demonstrated through
the overall adequacy of controls, although it is
arguments based on relevant good
unlikely that adequacy can be demonstrated
practice, additional risk reduction methods
solely by this means. This appendix provides
and grossly disproportionate costs for
a brief discussion of the types of risk criteria
further risk reduction
that have been adopted internationally. These
>> a lower region where risk is broadly
approaches may be useful for applying to
acceptable and does not need further
individual MHFs, to specific aspects of major
reduction because relevant good practice
incident risk at MHFs (eg the off-site risk),
is applied.
or to particular sections of individual MHFs
(eg if a purely qualitative approach proves Although the broad risk ranges appear
insufficient in particular areas). compatible with HSWA’s performance
standard of ‘so far as is reasonably
GENERAL BASIS practicable’, the interpretation does not
incorporate the continuous improvement
Risk criteria can provide a basis for judging
aspects contained within the MHF Regulations.
the tolerability of risks that have been
This means that at the lowest risk band, some
assessed, and for deciding the urgency or
risks may remain not reduced, even where
priority with which any identified hazard
it may be reasonably practicable to further
or risk should be addressed.
reduce the risk.
However, all risk assessment is subject to
An interpretation of the broad risk ranges,
uncertainty, and hence use of rigid risk
which manages or reduces all risks and
criteria may be inappropriate. A possible
includes consideration of continual
alternate approach is provided by the UK HSE
improvement, is shown in Table 9 and
framework for the tolerability of risk and it’s
described in more detail below.
‘as low as reasonably practicable’ (ALARP)
concept. This is based on broad ranges of The overall demonstrations you make need
risk, rather than on specific criteria. The HSE’s to consider hazards and risks in all regions,
policy document Reducing Risks, Protecting and may need to specifically show that:
People – HSE’s decision-making process >> there are no hazards or risks currently in
(2001) presents the risk tolerability framework. the upper region, and any hazards or risks
This represents risk on an inverted triangle as that may arise in the upper region in the
increasing from a broadly acceptable region, future will be immediately and effectively
through a tolerable region, to an unacceptable dealt with
region (see Figure 7). This broad framework >> all hazards and risks in the middle and
is used in HSE’s permissioning guidance, lower regions have had all reasonably
Guidance on ‘as low as reasonably practicable’ practicable risk reduction measures applied
(ALARP) decisions in control of major accident
>> there are suitable and reliable processes
hazards (COMAH) and provides for the
for continuing to manage hazards and
following broad risk ranges:
risks at all levels and for achieving
continual improvement.
46
SECTION 6.0 // APPENDICES
Upper region Unacceptable risk Take prompt action to reduce risk regardless of cost, unless
extraordinary circumstances apply.
Middle region Tolerable risk Implement controls so far as is reasonably practicable, considering
the available measures, relevant good practice, cost etc.
Lower region Broadly Manage risks at this level so far as is reasonably practicable and
acceptable risk continuously try and reduce risk further.
RISK MATRICES
A risk matrix categorises the risk of individual major incidents, based upon the judgement of
an assessment team about the order of magnitude of the likelihood and consequence of the
incident occurring. Typical risk matrices for hazardous industrial facilities range in size from 3 x 3
to 5 x 5. Typically, this has likelihood on the Y axis and consequence on the X axis of the matrix.
The frequency or likelihood scale should be one order of magnitude per row or column.
Risk increases diagonally across the matrix and bands of broad risk levels can be established
on the matrix, perpendicular to the direction of risk increase. These bands broadly relate to the
risk bands in Figure 7, and can be used to show areas where risk is intolerable/unacceptable and
where risk is tolerable, subject to all practicable measures being taken and subject to continuous
improvement. The broad risk bands can also be related to the urgency of action required.
In general, preventative controls (left hand side of a bow-tie diagram) lead to a decrease in
the likelihood of an incident occurring, which usually means a decrease in the Y coordinate on
the matrix. Mitigative controls (right hand side of a bow-tie diagram) lead to a decrease in the
consequence of an incident if it occurs, which usually means a decrease in the X coordinate on
the matrix.
47
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
However, note the risk matrix approach—while >> Individual risk is the frequency at which
it may be useful in ranking risks and to support an individual may be expected to sustain a
a demonstration of adequacy—is unlikely to given level of harm from the realisation of
be sufficient on its own for many facilities. For specified hazards. The purpose of criteria
example, separate and additional analysis of based on this risk measure is to ensure that
the effects of alternate controls is likely to be no single person is overexposed to risk.
needed, as a risk matrix is often too coarse Risk assessment results using this measure
a tool to distinguish between options. It may are often based on risk ‘contour’ plots.
also be difficult to fully address cumulative >> Societal risk is the relationship between
risk using matrices alone. the frequency of occurrence of major
If using risk matrices, give clear definitions for incidents and the number of people
the matrix and any categorisation used within suffering from a specified level of harm in
it, and show what action or significance is a given population from those incidents.
attributed to each position on the matrix, and The purpose of criteria based on this risk
whether the matrix is applicable to an incident, measure is to control risk to society as a
or to an individual scenario which leads to the whole. Risk assessment results using this
incident. You should check the risk matrices, measure are often based on frequency-
and any risk criteria implied through their use, consequence graphs.
are consistent with commonly adopted risk These criteria may in principle be applied to
criteria, such as any quantitative risk criteria. any exposed population, on-site or off-site,
although for a variety of reasons the actual
QUANTITATIVE RISK ASSESSMENT AND
levels of risk tolerability may vary between
QUANTITATIVE CRITERIA
the different exposed groups. Risk tolerability
Quantitative approaches to risk assessment values for individuals exposed to major
have different strengths and weaknesses. They incident hazards should relate in a sensible
allow a more precise and consistent approach manner to levels of risk from other industrial
to defining the likelihood, consequence and and non-industrial activities.
severity of a major incident but the results can
In the case of off-site risk to the general
vary significantly depending on assumptions
population, a set of ‘interim’ criteria have
made for the calculations. They can also be
been used in a number of cases in Victoria,
resource-intensive, may lack transparency, may
for example, in relation to land use planning
be difficult for a non-specialist to understand
(Interim Victorian Risk Criteria – Risk
and may give a misleading sense of accuracy
Assessment Guidelines, prepared for the
of risk estimates.
Altona Chemical Complex and the Victorian
If you choose to conduct a Quantitative Risk Government, by DNV Technical, October
Assessment (QRA), then the results may be 1988). The criteria do not have legal status
used by comparison with predetermined but can provide guidance on values.
criteria or for comparing different options
Comparison with a benchmark such as the
as part of the overall demonstration of
Victorian risk criteria are a straightforward
adequacy. There are two main types of
exercise if you use QRA in the formal safety
quantitative risk measure that may be
assessment. QRA is not mandatory and you
used to define risk criteria:
can use alternative qualitative assessment
48
SECTION 6.0 // APPENDICES
techniques such as risk matrices. Since most >> Most established criteria relate specifically
matrices show a consequence band of one to fatality rates but the MHF Regulations
fatality on one axis, and some form of numerical do not require any specific form of criteria.
frequency (or likelihood) estimate on the other It may be appropriate to consider measures
axis, it is usually possible to determine what of risk related to lower levels of harm, for
sort of fatality rate you consider to be ‘High’, example, serious injury.
‘Medium’ or ‘Low’ on-site risk.
OTHER ISSUES
49
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
INTERNATIONAL
EUROPEAN COMMISSION (EUROPE)
For information and guidance about the European Seveso-Directives industrial accident policy
visit the commission’s website www.ec.europa.eu/environment/seveso/
FURTHER READING
For information and guidance about health and safety or to contact the High Hazard Unit visit
WorkSafe’s website www.worksafe.govt.nz or call 0800 030 040.
50
SECTION 6.0 // APPENDICES
Guidelines for Integrated Risk Assessment and Management in Large Industrial Areas
International Atomic Energy Agency www.iaea.org/index.html
Guide for Major Hazard Facilities – Safety Case: Demonstrating the Adequacy of Safety
Management and Control Measures
Safe Work Australia www.safeworkaustralia.gov.au
Hazardous Industry Planning Advisory Paper No.4 – Risk Criteria for Land Use Safety Planning
(HIPAP 4)
Former NSW Department of Planning www.planning.nsw.gov.au
How to Determine What is Reasonably Practicable to Meet a Health and Safety Duty
Safe Work Australia www.safeworkaustralia.gov.au
Hutchison R.B., Perera J., Witt H.H. (1996) Preliminary Environmental Risk Ranking ANSTO Safety
and Reliability. Risk Engineering Seminar Munro Centre for Civil and Environmental Engineering,
University of NSW.
Suarez, A. & Kirchsteiger, C. A. (1998) Qualitative Model to Evaluate the Risk Potential of Major
Hazardous Industrial Plants. EUR 18128 EN
51
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
Accepted safety case A safety case which WorkSafe has accepted under Regulation 48.
Amended safety case If WorkSafe has initially rejected a safety case or revised safety case under
Regulation 48, an operator may amend the safety case and resubmit it for
acceptance. This is an amended safety case.
Change or proposed Defined in the MHF Regulations. It means a change or proposed change of any
change at a MHF kind, including:
>> a change to any plant, structure, process, hazardous substance or other
substance used in a process, (including the introduction of new plant, new
structure, new process or new hazardous substance)
>> a change to the quantity of specified hazardous substances that are present
or likely to be present at the facility
>> a change to the operation, or the nature of the operation, of the facility
>> a change to the facility’s SMS
>> an organisational change at the facility (including a change in its senior
management).
Critical operating The upper or lower performance limits of any equipment, process or procedure,
parameters compliance with which is necessary to avoid a major incident.
Designation A formal decision made by WorkSafe that a facility is or will be either an LTMHF
or an UTMHF for the purposes of the MHF Regulations.
Facility Defined in the MHF Regulations, means the whole area under the control of the
same person where specified hazardous substances are present in 1 or more
places. Two or more areas under the control of the same person and separated
only by a road, railway, inland waterway, pipeline, or other structure are treated
as 1 whole area for the purposes of this definition.
Facility emergency An area where designated personnel co-ordinate information, develop strategies
control centre (FECC) for addressing the media and government agencies, handle logistical support for
the response team, and perform management functions. A centralised support
facility allows emergency managers and staff to contend with incident issues
more effectively.
Facility emergency The person in charge of managing an emergency for the facility and has overall
controller (FEC) responsibility for all functions performed by facility personnel during an emergency.
52
SECTION 6.0 // APPENDICES
Greenfield An area of land, or some other undeveloped site earmarked for commercial
development.
Hazard A situation or thing that could harm someone, and includes a person’s behaviour.
For example, an unguarded machine, hazardous substances etc.
Isolated quantity Defined in the MHF Regulations, means a quantity of a hazardous substance
where its location at the facility is such that it cannot on its own initiate a major
incident elsewhere at the facility.
Knock-on effects Secondary events (such as toxic releases) triggered by a primary event (such
as an explosion), resulting in an increase in consequences or in the area of an
impact zone over the initial event.
Local authority A territorial authority within the meaning of section 5(1) of the Local
Government Act 2002.
The words ‘at a minimum’ mean the 1 km radius does not mark the extent of
the definition. Paragraph (b) may extend the scope of the definition well beyond
1 km in some circumstances.
Lower threshold Defined in the MHF Regulations, the quantity specified in column 4 of table 1 or
quantity column 3 of table 2 of Schedule 2, and calculated in accordance with Part 3 of
the MHF Regulations.
Lower tier major Defined in the MHF Regulations, a facility that WorkSafe has designated as
hazard facility an LTMHF.
(LTMHF)
Major hazard facility Defined in the MHF Regulations, a facility that WorkSafe has designated as
(MHF) an LTMHF or a UTMHF.
Major incident Defined in the MHF Regulations as an uncontrolled event at a MHF that involves,
or potentially involves, specified hazardous substances, and exposes multiple
persons to a serious risk to their health and safety (including a risk of death)
arising from an immediate or imminent exposure to:
>> 1 or more of those substances as a result of the event
>> the direct or indirect effects of the event.
Major incident hazard Defined in the MHF Regulations, a hazard that has the potential to cause
a major incident.
Major incident The process or sequence by which the major incident hazard develops into a
pathway major incident. Depending on the incident process model adopted, this includes
how the initiators, contributing factors, enabling conditions, system failures and
mechanisms come together into the incident.
53
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
Near miss A situation where a worker or any other person is exposed to a serious risk to
their health and safety, even if no harm was incurred.
Notifiable incident Defined in HSWA, generally an incident that exposes workers or other people to
a serious risk to health or safety. It must be reported to WorkSafe, or the relevant
designated agency.
Notification The notification to WorkSafe required by MHF Regulations 12, 13, and 17.
Notification is required if specified hazardous substances are present or likely
to be present at a facility in a quantity equal to or exceeding the lower threshold
quantity or if there is a proposed new operator.
Off site Defined in the MHF Regulations, this means not on site.
Operator Defined in the MHF Regulations, the PCBU who manages or controls a facility or
a proposed facility, and has the power to direct the whole facility be shut down.
Person conducting Defined in HSWA, generally any legal person running a business or undertaking.
a business or For example, includes a limited liability company, partnership, trust, incorporated
undertaking (PCBU) society, etc.
Proposed facility Defined in the MHF Regulations. It is an existing workplace that is to become
a facility or a facility that is to be built in the future.
Qualitative risk A relative measure of risk based on ranking or separation into descriptive
assessment categories such as low, medium, high.
Quantitative risk The use of data to determine risk. Requires calculations of two components of
assessment risk; the consequence of the hazard, and the likelihood that the hazard will occur.
Risk assessment This involves considering what could happen if someone is exposed to a hazard
and the likelihood of it happening.
Safety assessment Defined in the MHF Regulations, the general process by which the operator of
a MHF systematically and comprehensively investigates and analyses all aspects
of risks (including decisions around which controls to implement) to health and
safety associated with all major incidents that could occur in the course of the
operation of the MHF.
Safety case Defined in the MHF Regulations, generally a written presentation of the
technical, management and operational information covering the hazards and
risks that may lead to a major incident at a UTMHF, and their control. It provides
justification for the measures taken to ensure the safe operation of the facility.
54
SECTION 6.0 // APPENDICES
Safety management Defined in the MHF Regulations, generally a comprehensive integrated system
system (SMS) for managing all aspects of risk control at a MHF and used by the operator as the
primary means of ensuring safe operation of the MHF.
Safety-critical Defined in the MHF Regulations, means any part of a facility or its plant (including
element a computer program):
>> that has the purpose of preventing, or limiting the effect of, a major incident; and
>> the failure of which could cause or contribute substantially to a major incident.
Specified hazardous Defined in the MHF Regulations, these are table 1 or 2 hazardous substances.
substances
Structure Defined in HSWA, means anything that is constructed, whether fixed, moveable,
temporary, or permanent; including:
>> buildings, masts, towers, frameworks, pipelines, quarries, bridges, and
underground works (including shafts or tunnels)
>> any component of a structure
>> part of a structure.
Table 2 The table of named hazardous substances in Schedule 2 of the MHF Regulations.
Threshold quantity Defined in the MHF Regulations, means the lower threshold quantity or the
upper threshold quantity.
Upper threshold Defined in the MHF Regulations, means the quantity specified in column 5 of
quantity table 1 or column 4 of table 2 of Schedule 2, and calculated in accordance with
Part 3 of the MHF Regulations.
Upper tier major Defined in the MHF Regulations, means a facility that WorkSafe has designated
hazard facility as a UTMHF.
(UTMHF)
Worker Defined in HSWA, generally a person who carries out work in any capacity
for a PCBU. It covers almost all working relationships, including employees,
contractors, sub-contractors, and volunteer workers.
55
GOOD PRACTICE GUIDELINES // MAJOR HAZARD FACILITIES: SAFETY ASSESSMENT
Workers can ask a worker representative to raise health and safety issues with
a PCBU on their behalf.
Workplace Defined in HSWA, generally a place where work is carried out for a PCBU,
including any place where a worker goes, or is likely to be, while at work.
56
DISCLAIMER
WorkSafe New Zealand has made every effort to ensure the information contained in this publication
is reliable, but makes no guarantee of its completeness. WorkSafe may change the contents of this
guideline at any time without notice.
This document is a guideline only. It should not be used as a substitute for legislation or legal advice.
WorkSafe is not responsible for the results of any action taken on the basis of information in this
document, or for any errors or omissions.
www.worksafe.govt.nz
Except for the logos of WorkSafe, this copyright work is licensed under a Creative Commons
Attribution-Non-commercial 3.0 NZ licence.
In essence, you are free to copy, communicate and adapt the work for non-commercial purposes,
as long as you attribute the work to WorkSafe and abide by the other licence terms.
WSNZ_2253_July 2016
WorkSafe New Zealand
Level 6
86 Customhouse Quay
PO Box 165
Wellington 6140