Pages

Showing posts with label Incidents. Show all posts
Showing posts with label Incidents. Show all posts

August 13, 2026

ARE YOU INSPECTING ALL VULNERABLE COMPONENTS OF PIPING AS PER STANDARDS?

At 11:15 pm, high-pressure steam pipe elbow at 120 bar and 520°C connected to catalytic reforming equipment burst. The elbow and pipe , a 40-kg block of steel, was projected longitudinally. Inside the shop area, a walkway was ripped off its supports damaging an access ladder. It then flew over an ammonium nitrate conveyor belt only to land 230 m away in a parking zone for tanker cars full of ammonia awaiting shipment, which on that day happened to be empty. The steam tore apart the asbestos cement cladding on the wall located 20 m from the original rupture and escaped into the atmosphere with a load noise. 
















The two employees present in the unit at the time shut down production operations and cooled the steam reformer with nitrogen. 

A metallurgical assessment of the elbow indicated that slow creep had initiated on the outer skin, which combined with flow into the material layer was the cause of pipe rupture. This hypothesis relied on the detection of oxidised, yet non-deformed, pipe openings in the presence of intergranular microcracks on both the pipe and its elbow. The origin of this creep was explained by the metallurgical composition of the elbow, i.e. ordinary carbon steel containing no alloys and not adapted to temperatures above 425°C. The pipeline was made of a slightly-alloyed P22 type steel, which was more resistant to creep and compliant with the original specifications defined 32 years prior for both material elements. 

Inspections carried out at the time on the elbow did not detect any noncompliance of the steel, given that non-destructive technology had not yet come of age. This creep might have been accelerated as a result of heat treatment performed at 700°C during equipment installation, once the assembly had been welded. Periodic inspections dedicated to pressurised equipment on the damaged pipe were only recorded into the log 25 years after service start-up, at the time of applying for facility recertification. The initial recertification was rendered official without any underlying structural documentation (misplaced), and subsequent inspections never focused on the section of pipe that would burst.

Source: Aria database

August 8, 2026

CONFUSION DURING A MAJOR LOPC CAUSES WRONG ACTION TO BE TAKEN

In a petrochemical complex, an ethylene (a highly flammable gas) compressor was in stable operation when a sudden drop in pressure occurred at 5:33 p.m., accompanied by a loud noise. The gas detectors in the zone became saturated, and a 2nd level alarm was triggered in the unit’s control room, as well as in the control room controlling the nearby compressor and at the safety station. The compressor began to vibrate. Its motor stopped but not its ethylene supply.

Confusion over which compressor was leaking
Not knowing which compressor was causing the leak, the shift crew of compressor No. 1 contacted the crew in charge of compressor No. 2. The latter crew persuaded them it was compressor No. 2 that was to blame. Crew No. 1 left their control room to help them. The alarms and parameters indicating the malfunction of compressor No. 1 (pressure drop) were not taken into account since the control room had been deserted.

The two shift crews, joined by the internal fire brigades, approached the area of the accident but were unable to enter due to the deafening noise. They encountered a flammable cloud of ethylene measuring 4 m high x 100 m, with visible droplets. The firefighters protected the nearby units with water curtains. Around 5:45 p.m., the shift leader 1 consulted with the shift leader in charge of the neighbouring unit. A leak on the ethylene supply network was suspected. Two operators, equipped with hearing protection, moved through the cloud, protected by a water curtain, to reach the network’s manual shut-off valves. They were able to close the valves manually, ending the leak. The cloud rapidly dispersed. The operators returned to the control room and closed the local supply valve of compressor 1. 8 t of ethylene (354 kg of flammable mass) was released in 21 minutes.

ROOT CAUSE: Valve ejection due to incorrect tightening and a non-compliant seal
The hatch and the valve porthole of the second stage of compressor 1 were found 6 m away. One stud from the hatch was severed (sudden brittle-type rupture), while the other five studs remained in place, three of which were missing their nuts and exhibited torn threads. These studs are compliant but had never been replaced since the compressor was commissioned 16 years ago. An expert assessment showed that the valve’s copper seal was not annealed at the time of its installation, contrary to procedure and the other seals on the equipment. It was therefore not as flexible and less able to absorb stresses. This defect, combined with a bolt tightening error on the verge of plastic deformation, led to fluttering in the stack and its rupture.

If the emergency stop had been activated, the leak could have been stopped more quickly as it shuts down both the motor and the ethylene supply. The operators believed that the motor shut-down because of vibration was sufficient. After the accident, the compressor was equipped with an emergency stop triggered by gas detection. However, the manual emergency stop remains in operation should this detection system fail.

Source: Aria database

August 4, 2026

INADVERTENT CHEMICAL ADDITION DURING CLEANING CAUSES EXPLOSION

 An explosion and fire occurred at night in a workshop set up to synthesise toluene diamine (TDA), by means of hydrogenating dinitrotoluene (DNT) in the presence of Raney nickel, during a scheduled maintenance downtime. In-house fire-fighters brought the fire under control within 35 min; in the meantime, four employees required hospitalisation. One of them, who was handling the valves to wash the hydrogenation reactors with isopropanol, sustained burns over 40%-50% of his body and died 15 days later. The workshop was completely destroyed. The reactor burst; the bunker housing the workshop was deformed due to the combined action of the blast wave and sprayed fragments; the reinforced concrete wall was ripped open, with rebar twisted; and the control room was heavily damaged. Glass panes were broken over a 50- to 100-m radius, while the distillation unit juxtaposing the bunker was damaged and allowed isopropanol and TDA to escape, adding fuel to the fire. Buildings belonging to the neighbouring industrial facility located 150 m away suffered deformations to their lightweight structures. 

According to the investigation conducted, this explosion resulted from injecting pure DNT into one of the reactors washed by the circuit used at the time of production startup. Two valves connected in series equipping this DNT feed line were found partially opened (at 10°) after the accident, most likely allowing 500 to 700 kg/h of product to flow into the reactor. The heat release upon hydrogenation of a small quantity of DNT probably triggered the sudden decomposition of the remaining DNT, while abruptly reheating the reaction medium. Corrective measures were adopted to prevent routing pure dinitrotoluene into the reactor. These were elimination of the DNT intake line on the injection tank, addition of two automatic on-off valves on the mixing tank’s DNT feed line, closure of the link (by an automatic on-off valve) between the mixing tank and the injection tank during the reactor washing

July 27, 2026

ARE YOU PREPARED FOR AN OFF SITE EMERGENCY?

A power failure occurred in a refinery, as a result of the failure of the main power line during maintenance. This led to an emergency shut down of the whole plant. The automatically operated safety systems started working : large quantities of products were dumped in the flare and were burnt off. Safety valves opened and released gasses to the atmosphere. Personnel and people working at the refinery were evacuated and only emergency staff remained at the plant.

Information at the central operating desk about what was going on in all the components of the plant was sparse. In the first hour after the incident it was not known which safety valves were opened and which products were vented. That information became available bit by bit.

One of the safety valves that opened released an amount of 70 kg H2S into the atmosphere. The release point is situated at about 40 m above ground level.

After 5 min, the cloud of H2S formed reaches a downwind distance of about 3 km with a concentration valued at nearly 10 ppm 3 m above ground level.

Driven by a wind from the south-south-west at 45 km/hr, the cloud proceeds over the western part of the province of Brabant and after about 70 min has reached the city of Dordrecht, 50 km from the refinery. Concentrations of H2S in the cloud are about 0.06 ppm, still well above the smell detection level .

No warning of the H2S spill was issued, partly due to a lack of information at the plant, partly due to a lack of communication between Belgium emergency services and the Dutch authorities.

A population of about 100.000 people was in the path of the cloud and potentially affected by it. An estimated several hundred people were affected by the H2S and experienced nauseous ness, and respiratory problems. 57 people needed medical care.

However the Dutch emergency services were not prepared to deal with the situation, due to lack of information about the event and its possible consequences. This in turn led to insecurity and a loss of confidence in the capacity of the government to deal with incidents like these.

Source:Aria database

July 22, 2026

DO YOU CONSIDER ACCIDENTAL REVERSAL OF PNEUMATIC HOSE CONNECTIONS TO CONTROL SYSTEMS DURING HAZOP?

 A reactor exploded in a fine chemicals plant during the chlorination of an alcohol by thionyl chloride (SOCl2 ). The relatively non-exothermic reaction took place in a solvent medium (1,2 dichloroethane or DCE), under a slightly lower pressure and a temperature of 70°C maintained by means of steam injection. The reactor initially contained the SOCl2 in solution in the DCE, with the alcohol being added under close monitoring for 30 hours. 

At the time of the accident, the reactor was being fed for three hours by successive 200- litre loads of alcohol, with the first injection still incomplete. Monitoring performed by two technicians, one of whom was a trainee, included an hourly reading of both the temperature and pressure drop; no anomaly had been observed until that point. Upon hearing a noise accompanied by a break to the protective disc on the glass column connected to the reactor and noticing smoke around the disc joints, the technician turned the feeder control box selector switch to the “off” position. As he closed the alcohol feed valve and was making his way to the valve used to shut down steam injection, he spotted that leaking on the column was becoming more persistent. He immediately left the unit, requesting that a co-worker follow him out — at which point the explosion happened. A rupture disc calibrated at 0.3 bar and the glass fixtures on top of the device burst. The explosion or toxic gases emitted once the equipment had broken killed the trainee technician, who did not exit the premises quickly enough. 

The feeder was equipped with two valves. The upper one (loading side) was found in the closed position while the lower valve (reactor side) was open with a reversal of the pneumatic control hoses. These recordings supported the hypothesis of an accidental addition of water into the reaction medium via the feeder. The laboratory simulation of such an addition found that the SOCl2 hydrolysis with the formation of SO2 and HCl led to a sudden pressure rise. 

Source:Aria database

ARE YOU MONITORING SUPPORTS FOR THEIR INTEGRITY? ARE YOU PROPERLY CONGURING ALARMS?

In a refinery, an alarm in the control room informed the operators of a fire in the distilling unit. The unit’s emergency shutdown procedure was initiated from the control room. The internal fire-fighting resources were initiated at to extinguish the fire and cool down certain installations in addition to the fixed installations at the site. No injuries were reported on or off the site. The distillation unit was partially destroyed over an area measuring 50 m x 50 m, and flaring episodes were required.

A petrol leak was discovered on a 3” diameter pressure testing pipe of a flowmeter on a hollow tubular support. The operator had visually noted corrosion on the support already 3 years earlier. Replacement of the support was planned to take place during the regulatory shut-down period but was not performed. The ignition source was not precisely identified. Before the fire started, an alarm corresponding to the 20% lower explosive limit had been triggered 6 times, without the operators noticing. As some of the units had still been shut down, the alarms dedicated to the unit in operation were filtered. This filtering arrangement masked the display of the fire and gas alarms and only displayed those pertaining to the unit’s processes that had been restarted. The flashing light visible in the control room was considered a “process” alarm, knowing that such signals are not explicitly dedicated to fire and gas alarms.

Source: Aria database

July 18, 2026

SMALL CHANGES BRING MAJOR HEADACHES

At a plant producing intermediate organic synthesis compounds, a runaway reaction coupled with an explosion (approx. 1 kg of TNT equivalent) took place in the 3.5-m high glass column overlooking a 3,000- litre reactor. The explosion triggered a fire outbreak inside the unit. A 110-kg cloud of hydrochloric acid (HCl) hovered over the site before dispersing after a few minutes due to a favourable wind. The noise alerted the technical staff, who promptly placed the installation in safe operating mode and launched the internal emergency plan. The staff began to fight the fire using the resources at hand, and were then joined by fire-fighters who brought the blaze under control within twenty minutes. One employee sustained loss of hearing due to the explosion and property damage amounted to €700,000. 

On the day of the accident, a batch production had been underway involving the addition of 1,000 kg of a cold liquid ethylene compound along with 750 kg of a highly flammable and volatile silyl (hydrosilane). The homogeneous mix was then supposed to be poured into a 2nd reactor at 100°C in the presence of a catalyst to form the final product. The hydrosilylation reaction was maintained under control by gradually introducing the mix. However, in this incident, a sudden rise in mix temperature caused a pressure surge and a pneumatic burst of the column. The hydrosilane was hydrolyzed into HCl upon coming into contact with humid air and then decomposed into the hydrogen that triggered this fire. 

The investigation revealed that in order to compensate for the loss of catalyst activity (this was the seventh consecutive batch), which would have necessitated an extended batch time, a technician took the initiative to insert around 10g of new catalyst into the reactor at the same time as the raw materials. Data studies and laboratory tests actually indicated that the reaction could not have started in the low temperature reactor (5-20°C), since deviation from the temperature required for synthesis (at 90°C) appears to safeguard the reaction safety of this modification, i.e. now deemed to be minor. Nonetheless, the tests conducted by the operator following the accident revealed that at these temperatures, an exothermic hydrosilylation reaction could arise following an induction period lasting several hours in the presence of trace alcohol amounts. Since the catalyst had been placed in solution with a ketone, an infinitesimal quantity of ketone (in the order of 0.01%) was found in the mix inside the reactor and subsequently reduced to alcohol by the hydrosilane. Despite an extensive process of analysing reaction risks plus the synthesis of 36 batches without an accident in six years, the accident occurred on the only batch for which the process had been slightly modified. 

The operator reminded plant technicians that: 1. this modification should have been rated as significant and undergone an in-depth, collective analysis prior to implementation; and 2. any modification to a process must be justified and accompanied by compensatory safety measures.

Source:Aria database

July 13, 2026

DO YOU HAVE BACK UP POWER TO SAFETY CRITICAL EQUIPMENT?

A transformer caught on fire at 7:45 pm on a production building’s basement floor at a pharmaceutical plant. The building’s electrical power was cut, causing shutdown of the reactors’ stirring and cooling mechanisms. An exothermic reaction that was taking place at the time became uncontrollable. The reactor’s rupture disc, calibrated at 4 bar, broke, and the explosion vent opened to protect the structural integrity of the reactor. A quantity of the reaction mix at 70°C, composed of several hazardous products, projected onto one employee and six fire-fighters in the vicinity and formed a 60-m² puddle on the floor. 

The plant operator activated the internal emergency plan and the facility was evacuated. The safety report conducted on-site had not identified any comparable scenario. No backup source had been allocated to ensure the continued operations of critical equipment. Activities assigned to the damaged building and associated solvent storage zone were suspended until the safety systems (fire detection control, both post and automatic extinction) were once again operational. A diagnostic assessment of all site electrical installations was performed, along with a study, on the backup power supply for critical equipment, dedicated to exothermic reactions, i.e.: cooling, stirring, temperature and pressure probes.

Source:Aria database

July 8, 2026

LIGHTNING STRIKE DAMAGES CARD

A thunderstorm struck in the vicinity of a flammable liquid storage facility protected by an early streamer emission lightning rod. The indirect effects of the lightning damaged one of the 4 computer interface cards. This particular card had interfaced with the bus network responsible for relaying high-level safety alarms from the storage tanks. The facility operator detected the malfunction via the depot supervisor, who had indicated the communication breakdown. The operator did not possess a backup card and was unable to perform a quick replacement. He decided to inform the entire operating staff and requested extra vigilance when monitoring the performance sheets. Operations continued in this manner for 5 days before the interface card could actually be replaced. The damaged card had not been protected against indirect lightning effects. Following this accident, the operator kept on hand an additional card as a backup and implemented the recommendations issued in the study on indirect lightning effects conducted in April 2006. These recommendations focused on the protection, mainly by lightning rod, of the supervisor’s computer, alarm relay units, sensors, utility rooms, fire pumps serving 3 depots, and the electric generating sets for 2 sites.

 Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

July 3, 2026

AMMONIA RELEASE DUE TO LACK OF DIAGNOSING THE PROBLEM

 On a tubular exchanger, a disc broke over ¼ of its cross-section at 4:50 am during a pressure surge in the liquid ammonia (NH3 ) circuit connecting NH3 storage cells to a urea workshop operating under stable conditions. NH3 was partially led to a 100-m high degassing stack. Given stable weather conditions, a foul-smelling cloud drifted towards the city. The release occurred unbeknownst to control room operators, who had incorrectly interpreted several alarms that had tripped. Once the diagnosis rendered, the device was isolated at 6:25 am. The plant operator only became aware of the severity of the event at 8 am; two and a half hours were then needed to fully determine the origin and likely causes. The 10 tonnes of NH3 release was due to a succession of physical, organisational and human malfunctions: - Lack of anomaly detection and automatic safety systems: information made available to control room operators was inadequate; - Poor diagnosis / decision-making process lacking adequate verifications despite several precursors; - Incomplete safety recommendations, insufficient monitoring procedures and inspection plans. This poor diagnosis would explain the delay required to isolate the deficient circuit and the potential impact of this release. Long periods elapsed between the onset of the accident, the alarm and activation of the internal emergency plan, source identification, causes and circumstances of the discharge, and then a definitive quantification.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

June 27, 2026

DOMINO EFFECTS DUE TO POWER NON AVAILABILITY NOT CONSIDERED DURING DESIGN

 In a Seveso chemical plant, a fire broke out at 12:59 pm in a substation supplying a hydrazine hydrate unit. An electrical fault on a cooling water pump caused a generalised short circuit on an electrical tower. The fire alarm was triggered at 1.00 pm. The fire spread to the other towers of the panel through the subfloor. The 400 V circuit breaker located upstream was blocked and did not function. The fault current passed through the 13,000 / 400 V transformer, there was overpressure and an oil leak followed by a primary side homopolar fault causing the 13 kV circuit breaker to trip. The absence of voltage caused the diesel generator set to stop but the switchover to the emergency system failed as the automatism was damaged by the fire. The smoke spread to the UPS room whose door remained opened. The UPS stopped when a high temperature (> 40 °C) was reached causing the loss of control and command on the process. The component switched over to safety mode. Due to the lack of power supply, the cooling system, agitation and the internal and external emergency plan siren were no longer functional. Since the ongoing reaction was exothermic, the reactor temperature and pressure increased. Several measures are taken such as designing an emergency cooling circuit, improving circuit breaker maintenance, sectoring UPS system, electric boards, generator sets, etc.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

June 22, 2026

BYPASSING A SAFETY SYSTEM CAUSES A DETONATION

 A leak of over-pressurised and overheated glycol water occurred at a chemical plant after the rupture of a pipe joint. At 2 am, a control room operator recorded a drop in coolant temperature (150°C), preventing vacuum drying operations from continuing. On-call staff diagnosed a loss of communication link between the plant’s utilities automated system and the plant’s process automated system. A specialist in such systems confirmed the defect of a card on the utilities automated system, whose replacement had been postponed until the next morning. Once the specialist left the premises and confident of his diagnosis, the on-call maintenance operator decided to restart the unit. He short-circuited all of the safety mechanisms for hot fluid monitored by the process system, and replicated the corresponding settings in manual mode. Called by another workshop an hour later, the operator abandoned the post for 30 min. Upon his return, the hot fluid had exceeded 180°C, and a noise resembling a detonation shook the plant. After joint rupture, the glycol water vaporised on the premises, which were closed immediately thereafter.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

June 17, 2026

INADEQUATE DESIGN PHILOSOPHY CAUSES AN INCIDENT

 At a facility producing carbonate and sodium bicarbonate, fire broke out at 7 am in an electrical cabinet containing transmission cables for the liquid part of the process. The blaze caused a complete loss of control for 2 hours and a shutdown of the process responsible for releasing 2 to 8 kg of gaseous ammonia (NH3) into the atmosphere, subsequent to the sudden stoppage of the gas scrubber. In addition, ammonium hydroxide was released into the plant’s accidental pollution retention basin following discharge of a brine tank; this water made its way into the nearby river given that retention basin controls and monitoring installations had become unresponsive. This discharge wound up causing the death of some 400_kg of fish. According to the facility operator, the heating of electrical cables, traced to worn insulation, had triggered the incident. The control system, composed of control stations, a connecting bus and an automated system programmed to monitor the process, had been designed with a critical point in the form of a «node» at the time of creating the site’s 1st control system (26 years prior), through which all automated system cables were routed. Whereas all electrical component supply lines had been backed up, the automated system cables ran through a single cable tray in the electrical cabinet.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

June 13, 2026

A process control system can in no way be equated with a safety system

 Inside a chemical plant, a sulphur dichloride (SCl2) leak on a pipeline supplying the boiler tube of a distillation column hydrolysed, thereby generating a strong emission of hydrogen chloride (HCl). 50 ppm of HCl were recorded inside the building. Operating losses were valued at Euros 270,000 (the downstream unit stayed idle for 18 days). A pressure sensor was undergoing maintenance; it had been diagnosed as defective after indicating a reading of 108 mbar of pressure at the boiler tube output, thus triggering closure of the valves controlling SCl2 supply and regulating the vapour heating the boiler tube. Since the sensor was not «fail safe», its electrical disconnection caused the vapour regulation valve to open, thus heating the boiler tube, whose temperature rose from 24° to 120°C in 30 min, and causing the emission of SCl2. Several measures were adopted as part of the feedback provided: monitoring and intervention procedures in a degraded operating mode, modification of the sectional valve / pressure sensor assembly, introduction of a positive safety loop independent of the regulation, thereby prohibiting any automatic restart once the high pressure threshold had been reached. This accident demonstrates that a process control system can in no way be equated with a safety system. More specifically, industrial automation satisfy a rationale and criteria that are not all known by response teams and that do not necessarily incorporate degraded modes and lockouts situations.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

June 8, 2026

INCORRECT DESIGN OF SAFETY SYSTEM CAUSES AN INCIDENT

 Dimethyl sulphate (DMS) began leaking around 11 am at a chemical plant as the product was being loaded. The connection between the DMS container and the loading station consisted of disassembling the solid flanges, replacing the joint by a new part and reconnecting the container flanges to the unit’s pipe flanges. After initiating DMS loading in the control room, the field operator climbed down to inspect the container and, at that point, identified a leak on the flange connecting the container to the loading pipeline. He sounded the siren and the emergency light before pressing the emergency stop button. The next day, the plant operator concluded that the leak had been caused by poor clamping of the loading flange while the container was connected to the loading station. Moreover, the safety automated system was not activated because the pushbutton had not been held down long enough for its cycle length (1/10th of a second). All emergency stop pushbuttons were replaced by locking buttons throughout the site.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

June 4, 2026

USING BOTH COMPRESSORS DURING SHIP UNLOADING CAUSES AN INCIDENT

At 6:55 am, a propane ship unloaded its cargo into 2 mounded spherical storage tanks at a Seveso plant. At 8:50 that evening, the liquid phase had been completely unloaded and the vessel’s pumps were turned off. Unloading of the gaseous phase via the ship’s compressors began a few minutes later. At 9:35 pm, the 2 relief valves on one of the tanks opened at their calibration level (10.9 bar) for 30 seconds. The on-duty pump operator stopped the transfer and connected the 2 spheres in order to lower the pressure, steadying it at 9.8 bar. The plant manager and ship captain jointly decided to halt the unloading operation and monitor pressure of both tanks every 30 minutes. According to the site operator, the sphere’s pressure rise from 9.2 to 10.9 bar in 35 min was due to the simultaneous use of both propane ship compressors to accelerate unloading. The installation inspection revealed that pressure alarm thresholds on the sphere had been set at a higher value than the valve calibration pressure. Subsequent to the incident, the pre-alarm levels (visual and sound) and sphere alarm were calibrated at 10.4 and 10.7 bar, respectively, i.e. below the valve tripping values. The effective closure of the sphere filling valve and opening of the spraying valve were both prominently displayed on the control room displays

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

May 31, 2026

LOOK ALIKES IN CONTROL ROOM CAUSES AN INCIDENT

Inside a petrochemical unit, a steam supply problem encountered at the site’s steam production plant caused activation of the cracked gas compressor. The steam cracker was immediately shut down and the gases routed to the flare, resulting in the flaring of 800 tonnes of a hydrocarbon mix between Saturday evening and Sunday end of the afternoon. The unit’s supply was being provided by 2 boilers, one serving as a backup to the other. During the incident, one of the boilers was taken off-line for maintenance, leaving just a single boiler running. The idle boiler had undergone numerous safety tests, one of which called for closing the intake valve. The test operator mistakenly closed the fuel intake valve on the operating boiler from the control panel, causing a significant and sudden drop in steam supply to the units. With the steam cracker shutting down immediately, the installations were degassed and the flare network used as a backup for hydrocarbon ignition. To mitigate this type of error, the site operator improved boiler differentiation appearing on the control room’s graphic interfaces.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

May 26, 2026

FAULTY LEVEL INDICATIONS CAUSES FIRE

 A fire broke out on the vacuum distillation unit in a refinery during its shutdown. The unit had been restarted the day before following the acceptance of the work, while other job sites were still underway at the site. The reheating operation had begun during the night, and the unit was still in the power build-up phase. At around 9.15 am, thick black smoke was observed coming from the stack (fire in the furnace), with flames shooting from the open explosion vents. This situation was preceded by hammering in the pipes and rising pressure in the tower increase and the opening of valves: hydrocarbons began spilling outside. Following the inquiry, it appears that erroneous level indicators caused the tower to be overfilled then the backflow of liquid into the furnace via the vacuum system (backflow of incondensable materials). A brief summary of the findings: the local levels were not visible, the chain associated with the control levels in the bottom of the tower had not been completely checked (card), and the configuration of the system and notably the extraction levels were not correct.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

May 22, 2026

TRIP BYPASS WITHOUT APPROVAL CAUSES INCIDENT

 Subsequent to a tube break inside a refinery, fire ignited on a furnace. The emergency shutoff system was tripped and the unit became depressurised via the tube that broke inside the furnace. During this incident, the unit was on a return path to its nominal flow rate. Roughly 24 hours prior to the break, following another incident, the reforming unit was operating at an extremely low flow rate over a 3-hour period. The low flow rate safety system had been bypassed without implementing any compensatory measures. The next day, this information was not even relayed to the daytime shift, with the abnormal situation leading to the quick coking of the tubes and accelerating their creep. The fire had originated from overheated tubes tied to an internal coking operation, caused by operating at an insufficient flow rate (in a breach of safety rules). In underestimating the incident occurring the previous day, the subsequent shift had not been properly informed. The environmental agency requested strengthening the refinery’s safety management rules and verifying their strict implementation, in addition to installing an alarm management system. The agency also requested: formalising both the resources to be notified in the event of a process-related incident outside of plant operating hours and the rules for overseeing unplanned shutdowns and corresponding start-ups; revising the periodic safety test acceptance protocol; and expanding training and recycling programmes thanks to the Company’s new tools, in emphasising furnaces and incident management.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

May 18, 2026

HUMAN ERROR IN ENTERING DCS INPUT CAUSES AN INCIDENT

 At 9:03 pm, the control room operator responsible for the catalyst section of a refinery’s fluid catalytic cracking (FCC) unit entered an erroneous opening value for the atmospheric relief valve at the discharge of a compressor blowing the air needed to suspend a catalyst inside the regenerator. This valve deviated some air flow to the compressor discharge in order to protect the compressor from pumping phenomena. The operator on duty had input, then validated, an erroneous valve opening control value (less than 10%), when he actually wanted to lower the value from 20% to 19.5%. This instruction wound up increasing air flow to the regenerator and subsequently tripping the safety mechanism for the compressor and then for the entire unit. The 15-minute unit decompression caused flare emissions, followed by a gradual shutdown. The facility management brought the unit back online incrementally between 11 pm and 5 am, resulting in new flare emissions. The updated guideline requested the panel operator to no longer enter a value, but instead solely use the «up» or «down» arrow commands to increment the initial value by 0.5% or max 1%.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION