by Russel Treat, CEO and Founder of EnerSys Corporation
Process Safety Management (PSM) focuses on designing a facility in such a way that any type of abnormal operation presenting a safety risk is contained. Said another way, PSM focuses on guaranteed safe shutdown upon process upset.
Russel Treat.
Comparatively, Alarm Management focuses on operating the facility in such a way that you never reach the abnormal operating condition. Again, said another way, Alarm Management focuses on designing a facility to be operated so the pipeline operator can see the process moving to abnormal and take appropriate corrective action to avoid a shutdown.
Alarm Management serves as a safeguard while PSM serves as a failsafe. The challenge for operators is this distinction can be quite subtle. Both PSM and Alarm Management require a thorough and thoughtful understanding of operations and as a result, many of the questions asked to build context are the same, yet the conclusions are quite different.
Because both PSM and Alarm Management use the same understanding of operations context and because of the resulting similarity in questions that need to be asked, operators should be performing Alarm Management analysis upfront with PSM. Why? PSM is trying to ensure you do not have a bad outcome, while Alarm Management attempts to give the operator the ability to continue operating without ever getting to the abnormal condition.
Without combining the efforts, PSM often drives the design to an ‘operate to shutdown then restart’ model, while Alarm Management generally drives the operating model to ‘operate without shutdown’. Those different operating models are aligned from the point of view of the context building, but very different in terms of the analysis and in the final decisions you make for implementation.
For example, PSM ensures that if the operation reaches a specified limit, the system automatically shuts down and goes safe. An Alarm Management system, though, is set up to prevent the system from ever needing to shut down and this often requires a different approach in both physical design and automation.
Operators still need to ask the same upfront questions, analyse the cause and effects, and perform similar “what happens if” analysis and scenario tests. However, after performing the same upfront analysis to understand the process and then reaching the end of the analysis, you are asking different end-of-the-line questions that lead to different conclusions:
PSM: How do I make sure the system goes safe?
Alarm Management: How do I make sure I can operate and never hit the safety limits?
Because of the opportunity to perform the same upfront analysis before arriving at different conclusions, it is important to incorporate Alarm Management analysis into your PSM planning.
The Importance of PSM and Alarm Management nuance
While PSM and Alarm Management are very similar in the upfront questions being asked, there are important nuances that dictate the need to draw different conclusions. One important nuance is being able to make a clear distinction between Alarm Management and PSM.
Alarm Management is designed to ensure that alarms are received at the pipeline operator’s console in the appropriate time frame and with the appropriate information to equip the pipeline operator to act before an upset or unplanned shutdown occurs.
PSM addresses what occurs when the pipeline operator’s alarm response fails to avoid the upset and ensures the facility will safely mitigate the upset. Another way of looking at this nuance – and how to answer this question – is separating Alarm Management as a process to assure effective human intervention.
An alarm comes into the system, a pipeline operator performs activity to address the alarm, mobilizes other personnel and prevents an upset from occurring. If human intervention through alarm response cannot properly address the alarm, then PSM ensures mechanical devices will kick in to protect the system and potentially perform a shutdown.
In PSM analysis, the criteria in the system must not rely on human control to operate safely, therefore PSM requires more reliable, stringent and mechanical-oriented safeguards. This leads to different conclusions about the automation and how to set up the system to take appropriate action to ensure safe operation.
Another important nuance is defining an effective alarm. The goal of Alarm Management is to never trip process safety shutdowns. Rather, Alarm Management analysis looks at how to equip the pipeline operator with notifications, graphics and action plans to see and understand the abnormal operating condition and equip them to take action to avoid tripping safety shutdowns.
Alarm Management works to define effective alarms providing adequate time and tools to recognise, analyse and respond such that the pipeline operator can continue to operate safely without shutdown. Alarm Management designs the automation and the supervisory control and data acquisition (SCADA) systems so that pipeline operators can quickly gain complete clarity about what they are seeing on their HMI displays and can quickly achieve situation awareness.
It is all about operating philosophy. In the ‘operate to shutdown then restart’ model, the alarm response focus is to verify the shutdown and mobilise the restart. In the ‘operate without shutdown’ model, the focus is on recognising abnormal operation and taking action to return to normal operation without shutdown.
‘Operate to shutdown then restart’ is a facilities engineering process, while ‘operate without shutdown’ is an operations engineering process. In both cases, it is about identification and understanding according to the Plan-Do-Check-Act model outlined in Pipeline SMS (Pipeline Safety Management Systems).
What is required for an effective alarm management process
The ‘operate without shutdown’ philosophy requires critical understanding of putting in place an effective Alarm Management program. Effective Alarm Management starts with rationalisation, or defining for each alarm its severity, the time available to respond, possible root causes, methods of diagnostic and recommended action. The rationalisation process requires an understanding of operating philosophy. For existing systems, it is common to find that most alarms are not designed to achieve the operating goal.
The most difficult constraint is often the limited time available for human response. When the alarm setpoint is at or near the process safety trip, there is no time available to the operator to respond and avoid shutdown. Providing adequate time to respond often requires a redesign of the facility, the automation and/or the process.
Ultimately, the design must support providing pipeline operators and support personnel ample time to identify and respond to each alarm. This requires a highly effective and regular alarm analysis process that identifies bad actors and prevents alarm floods that inhibit the pipeline operator’s ability to process the alarms they are seeing.
If your operating goal is to operate without shutdown, then the Alarm Management program must attempt to provide ample time for pipeline operators to complete the ‘plan-do-check-act’ cycle – both as they operate the system and as they perform analysis of the program’s effectiveness.
The importance of culture to support Alarm Management
If the operating philosophy is to operate without shutdown, then each alarm must be meaningful. If not, there is a risk the pipeline operator will begin to ignore alarms.
Over time, a pipeline operator may become conditioned to mentally separate or filter certain alarms in their mind. They might think “I’ve seen this alarm 100 times, and it’s never linked to an abnormal operating condition”.
What about that one time where there actually is an abnormal condition and the adverse impact needs to be contained?
This introduces the importance of control room culture reinforcing to pipeline operators to treat each alarm as it’s displayed on the HMI. It’s not up to the pipeline operator to predetermine or prefilter whether an alarm is actually critical or not. It is effective alarm management vigilance that works to identify this type of bad actor and make appropriate modifications to improve the alarm system configuration.
One way to set the right culture is taking the time to rationalise and re-rationalise the alarms, optimise the Alarm Management program, communicate updates and continue to provide training. This will give pipeline operators confidence in the quality of the alarms and confidence in the reality of what they’re seeing on the HMIs.
Putting it all together for PSM and Alarm Management
For operators that are looking at cost efficiencies, pipeline safety improvements and alarming optimisation, there is a significant opportunity to approach PSM and Alarm Management as an integrated process.
Remember, though, that while the upfront questions, analysis and conversations are similar, the outcomes and conclusions you are working toward are different. Recognise that PSM is about trying to make the system mechanically safe, while Alarm Management is trying to operate without hitting the process safety shutdowns.
Keep in mind the importance of the operating philosophy dictating how alarms are handled in the system. Then, think about the business challenges associated with implementing and cultivating the right control room culture to support human intervention and response to alarms.
Start by integrating the PSM and Alarm Management planning functions. This will help operators achieve their goals for pipeline safety and operational integrity in an efficient and cost-effective manner.
This article was featured in the July 2020 edition of Pipelines International. To view the magazine on your PC, Mac, tablet or mobile device, click here.
If you have news you would like featured in Pipelines International contact Journalist Sophie Venz at svenz@gs-press.com.au