Pages

July 27, 2026

ARE YOU PREPARED FOR AN OFF SITE EMERGENCY?

A power failure occurred in a refinery, as a result of the failure of the main power line during maintenance. This led to an emergency shut down of the whole plant. The automatically operated safety systems started working : large quantities of products were dumped in the flare and were burnt off. Safety valves opened and released gasses to the atmosphere. Personnel and people working at the refinery were evacuated and only emergency staff remained at the plant.

Information at the central operating desk about what was going on in all the components of the plant was sparse. In the first hour after the incident it was not known which safety valves were opened and which products were vented. That information became available bit by bit.

One of the safety valves that opened released an amount of 70 kg H2S into the atmosphere. The release point is situated at about 40 m above ground level.

After 5 min, the cloud of H2S formed reaches a downwind distance of about 3 km with a concentration valued at nearly 10 ppm 3 m above ground level.

Driven by a wind from the south-south-west at 45 km/hr, the cloud proceeds over the western part of the province of Brabant and after about 70 min has reached the city of Dordrecht, 50 km from the refinery. Concentrations of H2S in the cloud are about 0.06 ppm, still well above the smell detection level .

No warning of the H2S spill was issued, partly due to a lack of information at the plant, partly due to a lack of communication between Belgium emergency services and the Dutch authorities.

A population of about 100.000 people was in the path of the cloud and potentially affected by it. An estimated several hundred people were affected by the H2S and experienced nauseous ness, and respiratory problems. 57 people needed medical care.

However the Dutch emergency services were not prepared to deal with the situation, due to lack of information about the event and its possible consequences. This in turn led to insecurity and a loss of confidence in the capacity of the government to deal with incidents like these.

Source:Aria database

July 22, 2026

DO YOU CONSIDER ACCIDENTAL REVERSAL OF PNEUMATIC HOSE CONNECTIONS TO CONTROL SYSTEMS DURING HAZOP?

 A reactor exploded in a fine chemicals plant during the chlorination of an alcohol by thionyl chloride (SOCl2 ). The relatively non-exothermic reaction took place in a solvent medium (1,2 dichloroethane or DCE), under a slightly lower pressure and a temperature of 70°C maintained by means of steam injection. The reactor initially contained the SOCl2 in solution in the DCE, with the alcohol being added under close monitoring for 30 hours. 

At the time of the accident, the reactor was being fed for three hours by successive 200- litre loads of alcohol, with the first injection still incomplete. Monitoring performed by two technicians, one of whom was a trainee, included an hourly reading of both the temperature and pressure drop; no anomaly had been observed until that point. Upon hearing a noise accompanied by a break to the protective disc on the glass column connected to the reactor and noticing smoke around the disc joints, the technician turned the feeder control box selector switch to the “off” position. As he closed the alcohol feed valve and was making his way to the valve used to shut down steam injection, he spotted that leaking on the column was becoming more persistent. He immediately left the unit, requesting that a co-worker follow him out — at which point the explosion happened. A rupture disc calibrated at 0.3 bar and the glass fixtures on top of the device burst. The explosion or toxic gases emitted once the equipment had broken killed the trainee technician, who did not exit the premises quickly enough. 

The feeder was equipped with two valves. The upper one (loading side) was found in the closed position while the lower valve (reactor side) was open with a reversal of the pneumatic control hoses. These recordings supported the hypothesis of an accidental addition of water into the reaction medium via the feeder. The laboratory simulation of such an addition found that the SOCl2 hydrolysis with the formation of SO2 and HCl led to a sudden pressure rise. 

Source:Aria database

ARE YOU MONITORING SUPPORTS FOR THEIR INTEGRITY? ARE YOU PROPERLY CONGURING ALARMS?

In a refinery, an alarm in the control room informed the operators of a fire in the distilling unit. The unit’s emergency shutdown procedure was initiated from the control room. The internal fire-fighting resources were initiated at to extinguish the fire and cool down certain installations in addition to the fixed installations at the site. No injuries were reported on or off the site. The distillation unit was partially destroyed over an area measuring 50 m x 50 m, and flaring episodes were required.

A petrol leak was discovered on a 3” diameter pressure testing pipe of a flowmeter on a hollow tubular support. The operator had visually noted corrosion on the support already 3 years earlier. Replacement of the support was planned to take place during the regulatory shut-down period but was not performed. The ignition source was not precisely identified. Before the fire started, an alarm corresponding to the 20% lower explosive limit had been triggered 6 times, without the operators noticing. As some of the units had still been shut down, the alarms dedicated to the unit in operation were filtered. This filtering arrangement masked the display of the fire and gas alarms and only displayed those pertaining to the unit’s processes that had been restarted. The flashing light visible in the control room was considered a “process” alarm, knowing that such signals are not explicitly dedicated to fire and gas alarms.

Source: Aria database

July 18, 2026

SMALL CHANGES BRING MAJOR HEADACHES

At a plant producing intermediate organic synthesis compounds, a runaway reaction coupled with an explosion (approx. 1 kg of TNT equivalent) took place in the 3.5-m high glass column overlooking a 3,000- litre reactor. The explosion triggered a fire outbreak inside the unit. A 110-kg cloud of hydrochloric acid (HCl) hovered over the site before dispersing after a few minutes due to a favourable wind. The noise alerted the technical staff, who promptly placed the installation in safe operating mode and launched the internal emergency plan. The staff began to fight the fire using the resources at hand, and were then joined by fire-fighters who brought the blaze under control within twenty minutes. One employee sustained loss of hearing due to the explosion and property damage amounted to €700,000. 

On the day of the accident, a batch production had been underway involving the addition of 1,000 kg of a cold liquid ethylene compound along with 750 kg of a highly flammable and volatile silyl (hydrosilane). The homogeneous mix was then supposed to be poured into a 2nd reactor at 100°C in the presence of a catalyst to form the final product. The hydrosilylation reaction was maintained under control by gradually introducing the mix. However, in this incident, a sudden rise in mix temperature caused a pressure surge and a pneumatic burst of the column. The hydrosilane was hydrolyzed into HCl upon coming into contact with humid air and then decomposed into the hydrogen that triggered this fire. 

The investigation revealed that in order to compensate for the loss of catalyst activity (this was the seventh consecutive batch), which would have necessitated an extended batch time, a technician took the initiative to insert around 10g of new catalyst into the reactor at the same time as the raw materials. Data studies and laboratory tests actually indicated that the reaction could not have started in the low temperature reactor (5-20°C), since deviation from the temperature required for synthesis (at 90°C) appears to safeguard the reaction safety of this modification, i.e. now deemed to be minor. Nonetheless, the tests conducted by the operator following the accident revealed that at these temperatures, an exothermic hydrosilylation reaction could arise following an induction period lasting several hours in the presence of trace alcohol amounts. Since the catalyst had been placed in solution with a ketone, an infinitesimal quantity of ketone (in the order of 0.01%) was found in the mix inside the reactor and subsequently reduced to alcohol by the hydrosilane. Despite an extensive process of analysing reaction risks plus the synthesis of 36 batches without an accident in six years, the accident occurred on the only batch for which the process had been slightly modified. 

The operator reminded plant technicians that: 1. this modification should have been rated as significant and undergone an in-depth, collective analysis prior to implementation; and 2. any modification to a process must be justified and accompanied by compensatory safety measures.

Source:Aria database

July 13, 2026

DO YOU HAVE BACK UP POWER TO SAFETY CRITICAL EQUIPMENT?

A transformer caught on fire at 7:45 pm on a production building’s basement floor at a pharmaceutical plant. The building’s electrical power was cut, causing shutdown of the reactors’ stirring and cooling mechanisms. An exothermic reaction that was taking place at the time became uncontrollable. The reactor’s rupture disc, calibrated at 4 bar, broke, and the explosion vent opened to protect the structural integrity of the reactor. A quantity of the reaction mix at 70°C, composed of several hazardous products, projected onto one employee and six fire-fighters in the vicinity and formed a 60-m² puddle on the floor. 

The plant operator activated the internal emergency plan and the facility was evacuated. The safety report conducted on-site had not identified any comparable scenario. No backup source had been allocated to ensure the continued operations of critical equipment. Activities assigned to the damaged building and associated solvent storage zone were suspended until the safety systems (fire detection control, both post and automatic extinction) were once again operational. A diagnostic assessment of all site electrical installations was performed, along with a study, on the backup power supply for critical equipment, dedicated to exothermic reactions, i.e.: cooling, stirring, temperature and pressure probes.

Source:Aria database

July 8, 2026

LIGHTNING STRIKE DAMAGES CARD

A thunderstorm struck in the vicinity of a flammable liquid storage facility protected by an early streamer emission lightning rod. The indirect effects of the lightning damaged one of the 4 computer interface cards. This particular card had interfaced with the bus network responsible for relaying high-level safety alarms from the storage tanks. The facility operator detected the malfunction via the depot supervisor, who had indicated the communication breakdown. The operator did not possess a backup card and was unable to perform a quick replacement. He decided to inform the entire operating staff and requested extra vigilance when monitoring the performance sheets. Operations continued in this manner for 5 days before the interface card could actually be replaced. The damaged card had not been protected against indirect lightning effects. Following this accident, the operator kept on hand an additional card as a backup and implemented the recommendations issued in the study on indirect lightning effects conducted in April 2006. These recommendations focused on the protection, mainly by lightning rod, of the supervisor’s computer, alarm relay units, sensors, utility rooms, fire pumps serving 3 depots, and the electric generating sets for 2 sites.

 Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

July 3, 2026

AMMONIA RELEASE DUE TO LACK OF DIAGNOSING THE PROBLEM

 On a tubular exchanger, a disc broke over ¼ of its cross-section at 4:50 am during a pressure surge in the liquid ammonia (NH3 ) circuit connecting NH3 storage cells to a urea workshop operating under stable conditions. NH3 was partially led to a 100-m high degassing stack. Given stable weather conditions, a foul-smelling cloud drifted towards the city. The release occurred unbeknownst to control room operators, who had incorrectly interpreted several alarms that had tripped. Once the diagnosis rendered, the device was isolated at 6:25 am. The plant operator only became aware of the severity of the event at 8 am; two and a half hours were then needed to fully determine the origin and likely causes. The 10 tonnes of NH3 release was due to a succession of physical, organisational and human malfunctions: - Lack of anomaly detection and automatic safety systems: information made available to control room operators was inadequate; - Poor diagnosis / decision-making process lacking adequate verifications despite several precursors; - Incomplete safety recommendations, insufficient monitoring procedures and inspection plans. This poor diagnosis would explain the delay required to isolate the deficient circuit and the potential impact of this release. Long periods elapsed between the onset of the accident, the alarm and activation of the internal emergency plan, source identification, causes and circumstances of the discharge, and then a definitive quantification.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

June 27, 2026

DOMINO EFFECTS DUE TO POWER NON AVAILABILITY NOT CONSIDERED DURING DESIGN

 In a Seveso chemical plant, a fire broke out at 12:59 pm in a substation supplying a hydrazine hydrate unit. An electrical fault on a cooling water pump caused a generalised short circuit on an electrical tower. The fire alarm was triggered at 1.00 pm. The fire spread to the other towers of the panel through the subfloor. The 400 V circuit breaker located upstream was blocked and did not function. The fault current passed through the 13,000 / 400 V transformer, there was overpressure and an oil leak followed by a primary side homopolar fault causing the 13 kV circuit breaker to trip. The absence of voltage caused the diesel generator set to stop but the switchover to the emergency system failed as the automatism was damaged by the fire. The smoke spread to the UPS room whose door remained opened. The UPS stopped when a high temperature (> 40 °C) was reached causing the loss of control and command on the process. The component switched over to safety mode. Due to the lack of power supply, the cooling system, agitation and the internal and external emergency plan siren were no longer functional. Since the ongoing reaction was exothermic, the reactor temperature and pressure increased. Several measures are taken such as designing an emergency cooling circuit, improving circuit breaker maintenance, sectoring UPS system, electric boards, generator sets, etc.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

June 22, 2026

BYPASSING A SAFETY SYSTEM CAUSES A DETONATION

 A leak of over-pressurised and overheated glycol water occurred at a chemical plant after the rupture of a pipe joint. At 2 am, a control room operator recorded a drop in coolant temperature (150°C), preventing vacuum drying operations from continuing. On-call staff diagnosed a loss of communication link between the plant’s utilities automated system and the plant’s process automated system. A specialist in such systems confirmed the defect of a card on the utilities automated system, whose replacement had been postponed until the next morning. Once the specialist left the premises and confident of his diagnosis, the on-call maintenance operator decided to restart the unit. He short-circuited all of the safety mechanisms for hot fluid monitored by the process system, and replicated the corresponding settings in manual mode. Called by another workshop an hour later, the operator abandoned the post for 30 min. Upon his return, the hot fluid had exceeded 180°C, and a noise resembling a detonation shook the plant. After joint rupture, the glycol water vaporised on the premises, which were closed immediately thereafter.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

June 17, 2026

INADEQUATE DESIGN PHILOSOPHY CAUSES AN INCIDENT

 At a facility producing carbonate and sodium bicarbonate, fire broke out at 7 am in an electrical cabinet containing transmission cables for the liquid part of the process. The blaze caused a complete loss of control for 2 hours and a shutdown of the process responsible for releasing 2 to 8 kg of gaseous ammonia (NH3) into the atmosphere, subsequent to the sudden stoppage of the gas scrubber. In addition, ammonium hydroxide was released into the plant’s accidental pollution retention basin following discharge of a brine tank; this water made its way into the nearby river given that retention basin controls and monitoring installations had become unresponsive. This discharge wound up causing the death of some 400_kg of fish. According to the facility operator, the heating of electrical cables, traced to worn insulation, had triggered the incident. The control system, composed of control stations, a connecting bus and an automated system programmed to monitor the process, had been designed with a critical point in the form of a «node» at the time of creating the site’s 1st control system (26 years prior), through which all automated system cables were routed. Whereas all electrical component supply lines had been backed up, the automated system cables ran through a single cable tray in the electrical cabinet.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

June 13, 2026

A process control system can in no way be equated with a safety system

 Inside a chemical plant, a sulphur dichloride (SCl2) leak on a pipeline supplying the boiler tube of a distillation column hydrolysed, thereby generating a strong emission of hydrogen chloride (HCl). 50 ppm of HCl were recorded inside the building. Operating losses were valued at Euros 270,000 (the downstream unit stayed idle for 18 days). A pressure sensor was undergoing maintenance; it had been diagnosed as defective after indicating a reading of 108 mbar of pressure at the boiler tube output, thus triggering closure of the valves controlling SCl2 supply and regulating the vapour heating the boiler tube. Since the sensor was not «fail safe», its electrical disconnection caused the vapour regulation valve to open, thus heating the boiler tube, whose temperature rose from 24° to 120°C in 30 min, and causing the emission of SCl2. Several measures were adopted as part of the feedback provided: monitoring and intervention procedures in a degraded operating mode, modification of the sectional valve / pressure sensor assembly, introduction of a positive safety loop independent of the regulation, thereby prohibiting any automatic restart once the high pressure threshold had been reached. This accident demonstrates that a process control system can in no way be equated with a safety system. More specifically, industrial automation satisfy a rationale and criteria that are not all known by response teams and that do not necessarily incorporate degraded modes and lockouts situations.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

June 8, 2026

INCORRECT DESIGN OF SAFETY SYSTEM CAUSES AN INCIDENT

 Dimethyl sulphate (DMS) began leaking around 11 am at a chemical plant as the product was being loaded. The connection between the DMS container and the loading station consisted of disassembling the solid flanges, replacing the joint by a new part and reconnecting the container flanges to the unit’s pipe flanges. After initiating DMS loading in the control room, the field operator climbed down to inspect the container and, at that point, identified a leak on the flange connecting the container to the loading pipeline. He sounded the siren and the emergency light before pressing the emergency stop button. The next day, the plant operator concluded that the leak had been caused by poor clamping of the loading flange while the container was connected to the loading station. Moreover, the safety automated system was not activated because the pushbutton had not been held down long enough for its cycle length (1/10th of a second). All emergency stop pushbuttons were replaced by locking buttons throughout the site.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

June 4, 2026

USING BOTH COMPRESSORS DURING SHIP UNLOADING CAUSES AN INCIDENT

At 6:55 am, a propane ship unloaded its cargo into 2 mounded spherical storage tanks at a Seveso plant. At 8:50 that evening, the liquid phase had been completely unloaded and the vessel’s pumps were turned off. Unloading of the gaseous phase via the ship’s compressors began a few minutes later. At 9:35 pm, the 2 relief valves on one of the tanks opened at their calibration level (10.9 bar) for 30 seconds. The on-duty pump operator stopped the transfer and connected the 2 spheres in order to lower the pressure, steadying it at 9.8 bar. The plant manager and ship captain jointly decided to halt the unloading operation and monitor pressure of both tanks every 30 minutes. According to the site operator, the sphere’s pressure rise from 9.2 to 10.9 bar in 35 min was due to the simultaneous use of both propane ship compressors to accelerate unloading. The installation inspection revealed that pressure alarm thresholds on the sphere had been set at a higher value than the valve calibration pressure. Subsequent to the incident, the pre-alarm levels (visual and sound) and sphere alarm were calibrated at 10.4 and 10.7 bar, respectively, i.e. below the valve tripping values. The effective closure of the sphere filling valve and opening of the spraying valve were both prominently displayed on the control room displays

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

May 31, 2026

LOOK ALIKES IN CONTROL ROOM CAUSES AN INCIDENT

Inside a petrochemical unit, a steam supply problem encountered at the site’s steam production plant caused activation of the cracked gas compressor. The steam cracker was immediately shut down and the gases routed to the flare, resulting in the flaring of 800 tonnes of a hydrocarbon mix between Saturday evening and Sunday end of the afternoon. The unit’s supply was being provided by 2 boilers, one serving as a backup to the other. During the incident, one of the boilers was taken off-line for maintenance, leaving just a single boiler running. The idle boiler had undergone numerous safety tests, one of which called for closing the intake valve. The test operator mistakenly closed the fuel intake valve on the operating boiler from the control panel, causing a significant and sudden drop in steam supply to the units. With the steam cracker shutting down immediately, the installations were degassed and the flare network used as a backup for hydrocarbon ignition. To mitigate this type of error, the site operator improved boiler differentiation appearing on the control room’s graphic interfaces.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

May 26, 2026

FAULTY LEVEL INDICATIONS CAUSES FIRE

 A fire broke out on the vacuum distillation unit in a refinery during its shutdown. The unit had been restarted the day before following the acceptance of the work, while other job sites were still underway at the site. The reheating operation had begun during the night, and the unit was still in the power build-up phase. At around 9.15 am, thick black smoke was observed coming from the stack (fire in the furnace), with flames shooting from the open explosion vents. This situation was preceded by hammering in the pipes and rising pressure in the tower increase and the opening of valves: hydrocarbons began spilling outside. Following the inquiry, it appears that erroneous level indicators caused the tower to be overfilled then the backflow of liquid into the furnace via the vacuum system (backflow of incondensable materials). A brief summary of the findings: the local levels were not visible, the chain associated with the control levels in the bottom of the tower had not been completely checked (card), and the configuration of the system and notably the extraction levels were not correct.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

May 22, 2026

TRIP BYPASS WITHOUT APPROVAL CAUSES INCIDENT

 Subsequent to a tube break inside a refinery, fire ignited on a furnace. The emergency shutoff system was tripped and the unit became depressurised via the tube that broke inside the furnace. During this incident, the unit was on a return path to its nominal flow rate. Roughly 24 hours prior to the break, following another incident, the reforming unit was operating at an extremely low flow rate over a 3-hour period. The low flow rate safety system had been bypassed without implementing any compensatory measures. The next day, this information was not even relayed to the daytime shift, with the abnormal situation leading to the quick coking of the tubes and accelerating their creep. The fire had originated from overheated tubes tied to an internal coking operation, caused by operating at an insufficient flow rate (in a breach of safety rules). In underestimating the incident occurring the previous day, the subsequent shift had not been properly informed. The environmental agency requested strengthening the refinery’s safety management rules and verifying their strict implementation, in addition to installing an alarm management system. The agency also requested: formalising both the resources to be notified in the event of a process-related incident outside of plant operating hours and the rules for overseeing unplanned shutdowns and corresponding start-ups; revising the periodic safety test acceptance protocol; and expanding training and recycling programmes thanks to the Company’s new tools, in emphasising furnaces and incident management.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

May 18, 2026

HUMAN ERROR IN ENTERING DCS INPUT CAUSES AN INCIDENT

 At 9:03 pm, the control room operator responsible for the catalyst section of a refinery’s fluid catalytic cracking (FCC) unit entered an erroneous opening value for the atmospheric relief valve at the discharge of a compressor blowing the air needed to suspend a catalyst inside the regenerator. This valve deviated some air flow to the compressor discharge in order to protect the compressor from pumping phenomena. The operator on duty had input, then validated, an erroneous valve opening control value (less than 10%), when he actually wanted to lower the value from 20% to 19.5%. This instruction wound up increasing air flow to the regenerator and subsequently tripping the safety mechanism for the compressor and then for the entire unit. The 15-minute unit decompression caused flare emissions, followed by a gradual shutdown. The facility management brought the unit back online incrementally between 11 pm and 5 am, resulting in new flare emissions. The updated guideline requested the panel operator to no longer enter a value, but instead solely use the «up» or «down» arrow commands to increment the initial value by 0.5% or max 1%.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

May 13, 2026

RUNAWAY REACTION DUE TO LOSS OF UTILITIES

 At 10:46 pm during a thunderstorm, an electrical outage interrupted polystyrene (PS) production at a Seveso-classified site. A safety disc broke and styrene was released. To minimise the effects of micro-outages (due to thunderstorms) on PS output quality, the site operator typically switched shop power supply onto the 4 electric generating sets of the facility’s Peak Day Withdrawal (PDW) unit. This manoeuvre was performed at 10:20 pm, with 3 sets still available. At 10:43, the thunderstorm knocked out the 1st set. Since the 2 remaining sets were no longer sufficient, the unit entered into safety mode at 10:46, closing all utilities. An employee tried to restart the PDW unit; the on-call electrical maintenance operator was called at 10:53 pm. By 11:05 pm, pressure on the 1st synthesis reactor had begun to rise. As per emergency procedures, gyro monitors started up at 11:15 to remove eventual vapours at the reactor line vent. The site was connected to the grid at 11:18 but the units were only allowed to resume operations a short time later. At 11:20, the disc on the 1st reactor burst at 5.8 bar, spraying a liquid mix containing 10 tonnes of PS and 3 tonnes of styrene.The runaway reactor was caused by the loss of utility service. The control room operator opened the vent too late, given all the actions required to put the 3 polystyrene lines into safe mode, in accordance with procedures.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

May 8, 2026

AUTOMATION INCIDENTS IN PROCESS SAFETY

 "The factory of the future will have only two employees, a man and a dog. The man will be there to feed the dog. The dog will be there to keep the man from touching the equipment.» Warren G. Bennis, North American consultant,1996"

HCL LEAKS FROM FURNACE FOR 10 MINUTES In a chemical plant, 0.6 tons of hydrogen chloride (HCl) escaped during a 10-minute period from all furnaces and vents within the potassium sulphate workshop while cleaning the HCl circuits. An employee living adjacent to the site notified the guard house of the presence of a cloud originating from the plant. The emergency sprinkling system connected to the washer was turned on to stop these emissions. Poor calibration of one of the two devices used to measure gas pressure at the furnace outlet (not directly related to the ongoing works), causing the control valve on the gas evacuation circuit to close, was responsible for this incident: since gases were no longer being drawn, they escaped from the furnaces. The lack of an alarm on this control parameter slowed personnel response, and the absence of any means for comparing the 2 pressure measurements prevented the detection of sensor drift. To reduce the probability of repeat occurrence, an alarm was installed to detect deviations between the 2 pressure readings; also, a procedure laying out the most sensitive steps, in particular those requiring a supervisor's presence, was issued.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION