Pages

Showing posts with label Managing change. Show all posts
Showing posts with label Managing change. Show all posts

July 18, 2026

SMALL CHANGES BRING MAJOR HEADACHES

At a plant producing intermediate organic synthesis compounds, a runaway reaction coupled with an explosion (approx. 1 kg of TNT equivalent) took place in the 3.5-m high glass column overlooking a 3,000- litre reactor. The explosion triggered a fire outbreak inside the unit. A 110-kg cloud of hydrochloric acid (HCl) hovered over the site before dispersing after a few minutes due to a favourable wind. The noise alerted the technical staff, who promptly placed the installation in safe operating mode and launched the internal emergency plan. The staff began to fight the fire using the resources at hand, and were then joined by fire-fighters who brought the blaze under control within twenty minutes. One employee sustained loss of hearing due to the explosion and property damage amounted to €700,000. 

On the day of the accident, a batch production had been underway involving the addition of 1,000 kg of a cold liquid ethylene compound along with 750 kg of a highly flammable and volatile silyl (hydrosilane). The homogeneous mix was then supposed to be poured into a 2nd reactor at 100°C in the presence of a catalyst to form the final product. The hydrosilylation reaction was maintained under control by gradually introducing the mix. However, in this incident, a sudden rise in mix temperature caused a pressure surge and a pneumatic burst of the column. The hydrosilane was hydrolyzed into HCl upon coming into contact with humid air and then decomposed into the hydrogen that triggered this fire. 

The investigation revealed that in order to compensate for the loss of catalyst activity (this was the seventh consecutive batch), which would have necessitated an extended batch time, a technician took the initiative to insert around 10g of new catalyst into the reactor at the same time as the raw materials. Data studies and laboratory tests actually indicated that the reaction could not have started in the low temperature reactor (5-20°C), since deviation from the temperature required for synthesis (at 90°C) appears to safeguard the reaction safety of this modification, i.e. now deemed to be minor. Nonetheless, the tests conducted by the operator following the accident revealed that at these temperatures, an exothermic hydrosilylation reaction could arise following an induction period lasting several hours in the presence of trace alcohol amounts. Since the catalyst had been placed in solution with a ketone, an infinitesimal quantity of ketone (in the order of 0.01%) was found in the mix inside the reactor and subsequently reduced to alcohol by the hydrosilane. Despite an extensive process of analysing reaction risks plus the synthesis of 36 batches without an accident in six years, the accident occurred on the only batch for which the process had been slightly modified. 

The operator reminded plant technicians that: 1. this modification should have been rated as significant and undergone an in-depth, collective analysis prior to implementation; and 2. any modification to a process must be justified and accompanied by compensatory safety measures.

Source:Aria database

June 22, 2026

BYPASSING A SAFETY SYSTEM CAUSES A DETONATION

 A leak of over-pressurised and overheated glycol water occurred at a chemical plant after the rupture of a pipe joint. At 2 am, a control room operator recorded a drop in coolant temperature (150°C), preventing vacuum drying operations from continuing. On-call staff diagnosed a loss of communication link between the plant’s utilities automated system and the plant’s process automated system. A specialist in such systems confirmed the defect of a card on the utilities automated system, whose replacement had been postponed until the next morning. Once the specialist left the premises and confident of his diagnosis, the on-call maintenance operator decided to restart the unit. He short-circuited all of the safety mechanisms for hot fluid monitored by the process system, and replicated the corresponding settings in manual mode. Called by another workshop an hour later, the operator abandoned the post for 30 min. Upon his return, the hot fluid had exceeded 180°C, and a noise resembling a detonation shook the plant. After joint rupture, the glycol water vaporised on the premises, which were closed immediately thereafter.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

June 4, 2026

USING BOTH COMPRESSORS DURING SHIP UNLOADING CAUSES AN INCIDENT

At 6:55 am, a propane ship unloaded its cargo into 2 mounded spherical storage tanks at a Seveso plant. At 8:50 that evening, the liquid phase had been completely unloaded and the vessel’s pumps were turned off. Unloading of the gaseous phase via the ship’s compressors began a few minutes later. At 9:35 pm, the 2 relief valves on one of the tanks opened at their calibration level (10.9 bar) for 30 seconds. The on-duty pump operator stopped the transfer and connected the 2 spheres in order to lower the pressure, steadying it at 9.8 bar. The plant manager and ship captain jointly decided to halt the unloading operation and monitor pressure of both tanks every 30 minutes. According to the site operator, the sphere’s pressure rise from 9.2 to 10.9 bar in 35 min was due to the simultaneous use of both propane ship compressors to accelerate unloading. The installation inspection revealed that pressure alarm thresholds on the sphere had been set at a higher value than the valve calibration pressure. Subsequent to the incident, the pre-alarm levels (visual and sound) and sphere alarm were calibrated at 10.4 and 10.7 bar, respectively, i.e. below the valve tripping values. The effective closure of the sphere filling valve and opening of the spraying valve were both prominently displayed on the control room displays

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

May 22, 2026

TRIP BYPASS WITHOUT APPROVAL CAUSES INCIDENT

 Subsequent to a tube break inside a refinery, fire ignited on a furnace. The emergency shutoff system was tripped and the unit became depressurised via the tube that broke inside the furnace. During this incident, the unit was on a return path to its nominal flow rate. Roughly 24 hours prior to the break, following another incident, the reforming unit was operating at an extremely low flow rate over a 3-hour period. The low flow rate safety system had been bypassed without implementing any compensatory measures. The next day, this information was not even relayed to the daytime shift, with the abnormal situation leading to the quick coking of the tubes and accelerating their creep. The fire had originated from overheated tubes tied to an internal coking operation, caused by operating at an insufficient flow rate (in a breach of safety rules). In underestimating the incident occurring the previous day, the subsequent shift had not been properly informed. The environmental agency requested strengthening the refinery’s safety management rules and verifying their strict implementation, in addition to installing an alarm management system. The agency also requested: formalising both the resources to be notified in the event of a process-related incident outside of plant operating hours and the rules for overseeing unplanned shutdowns and corresponding start-ups; revising the periodic safety test acceptance protocol; and expanding training and recycling programmes thanks to the Company’s new tools, in emphasising furnaces and incident management.

Source: Aria ACCIDENT ANALYSIS OF INDUSTRIAL AUTOMATION

April 9, 2026

A CHANGE IN LEAK TESTING PROCEDURE CAUSES AN EXPLOSION

On December 10, 2023, at 3:38 p.m., two explosions and a fire occurred in a polymer reactor at a facility in Mt. Vernon, Indiana. Property damage was estimated at $3.5 million.
Three months prior to the incident, on September 18, the company had shut down its polybutylene terephthalate resin unit for scheduled maintenance. On the day of the incident, the maintenance work was nearing completion, and operators were preparing the unit’s reactor system for startup. At 3:38 p.m., a heat exchanger exploded, ejecting several equipment fragments, including one that landed approximately 505 feet away near the facility’s boundary along the Ohio River. A second explosion and flash fire soon followed, rupturing a reactor.
The company's investigation concluded that the initial explosion in the heat exchanger was caused by the rapid, energetic decomposition of unstable organic peroxide that had formed and accumulated inside the equipment. The second explosion and flash fire, which destroyed the reactor, was caused by heat from the first explosion igniting flammable tetrahydrofuran vapor inside the reactor.
The exchanger and reactor were interconnected, with no isolation between the two pressure vessels. The design of the reactor’s outlet piping retained liquid in the piping. Because the piping could not fully drain, it contained polybutylene terephthalate polymer, butanediol, and tetrahydrofuran when the unit was shut down on September 18, 2023.
On December 10, operators began pre-startup activities. At 3:16 a.m., hot oil was sent through the tracing used to heat the reactor’s outlet piping. As the piping heated, the residual hydrocarbon material also heated, evolving tetrahydrofuran vapor that flowed into the reactor and the heat exchanger. A 3-inch nozzle on the heat exchanger remained open to ambient air, allowing oxygen into the reactor system. The tetrahydrofuran vapor reacted with available oxygen to form an organic peroxide compound. The organic peroxide continued to form for another 12 hours, until it exploded in a rapid decomposition reaction at 3:38 p.m. The heat from the explosion ignited additional flammable tetrahydrofuran inside the reactor, triggering the second explosion and a flash fire.
The company's investigation found that the company’s historical practice of leaving residual hydrocarbon material in the reactor’s outlet piping during shutdown created hazards that were neither recognized nor controlled. The reaction of tetrahydrofuran with oxygen produced the explosive organic peroxide. Before the incident, personnel had assumed that the cooled, solidified material could remain in the reactor’s outlet piping because it was not hazardous, creating a false sense of safety.
The investigation also found that a change to the reactor’s leak-testing procedure contributed to the incident. Previously, the reactor was leak-tested online under vacuum. The company switched to using pressurized nitrogen and moved the test into the maintenance outage. A management of change review had been approved to allow a leak test of the reactor during pre-startup activities. However, the review did not assess how the leak test might adversely affect those activities.
When the hot oil heated the reactor’s outlet piping, the procedure required adding nitrogen to the reactor system. However, the nitrogen flow was omitted due to the modified leak test. The company’s investigation concluded that the risk of performing simultaneous tasks during startup had not been evaluated.
Probable Cause
Based on the company's investigation, the CSB determined that the probable cause of the incident was heating the reactor’s outlet piping containing solidified polybutylene terephthalate polymer, butanediol, and tetrahydrofuran while a nozzle on an interconnected heat exchanger was open, allowing oxygen (air) to enter the equipment. These conditions generated tetrahydrofuran vapor, which reacted with oxygen to form an explosive organic peroxide, and also created a flammable atmosphere in the equipment, which then ignited and exploded after the organic peroxide energetically decomposed. The management of change review conducted for the reactor’s leak testing did not assess how the leak testing might affect the simultaneous pre-startup tasks, contributing to the incident. As a result, there was no nitrogen flow through the reactor system, allowing unstable peroxide to form and developing flammable conditions within the equipment.

Source: CSB.gov 

February 25, 2026

CREEPING CHANGES CAUSES AN INCIDENT

The Fluidised Catalytic Cracker Unit (FCCU) was shut down on the 29 th May 2000 following the power distribution failure and was being restarted after an 11-day shutdown. On 10 th June 2000 during start-up a significant leak of hydrocarbons was discovered, creating a vapour cloud which ignited resulting in a serious fire. Workers escaped before the blast, nobody got injured in the incident.
Key learning points
The leak was as a result of failure of a tee-piece connection at the base of the debutaniser column which found a source of ignition nearby. The tee-piece connection which had originally been installed in the 1950’s was correctly specified but incorrectly fitted, and then hidden by lagging. There was no subsequent amendment to the plant layout drawings to identify that change.
Since the 1950’s, sections of the FCCU had been significantly modified. Prior to the modifications in 1986, changes had been made to the pipework at the base of the column and a valve had been removed. This resulted in there being inadequate support for the remaining pipework and the tee-piece connection. Between 1996 and 1998 the FCCU had been experiencing considerable difficulties and did not operate consistently. This resulted in an increase in the number of start-up/shutdown cycles for the plant and pipework. 

An incident occurred in 1999 during a prolonged start-up on the FCCU. It resulted in an ignition
of a torch oil vapour cloud. Contrary to plant operating instructions in the master operating manual, the torch oil had been admitted to the regenerator when the unit was at too low a temperature. As a result, ignition of the torch oil did not occur in the regenerator. Although ignition had not been verified, a considerable further quantity of torch oil was injected, and it is believed that hot spots in the slumped catalyst bed vapourised the torch oil. The provision of a temperature interlock had previously been considered and discounted, as it was decided that operating procedures alone provided enough control.
In the 11 weeks preceding the incident in 2000, 19 start-up attempts had been made and only 7 were
successful. Failure of the tee-piece connection pipework was probably caused by a combination of the incorrectly fitted tee-piece connection, the inadequately supported pipework and the cyclic
stresses/vibration caused by the increased number of start-up/shutdown activities on the plant. Eventually these led to fatigue failure of the pipework in the vicinity of the welded connection. The company reviewed the FCCU to find out why it did not operate properly but the findings were never implemented or communicated properly. The safety report failed to reflect the reality of the condition of the FCCU. The 1997/98 revision concluded that “hardware and software controls in place on the FCCU are adequate to prevent the occurrence of a major accident”. 

Incidents with vibration of the transfer line had occurred over the two years prior to the
explosion. These events were not reported or investigated. There were two incidents preceded the blast on 10 th June, a power distribution failure on 29th May 2000 and the medium pressure steam main rupture on 7th June 2000. Construction of a new facility had started in early 2000. The company hired a sub-contractor for the underground works and the sub-contractor sub-contracted the actual excavation work to an excavation contractor. The company also engaged a main electrical sub-contractor for the electrical and instrumentation work to be carried out. The electrical subcontractor further contracted the laying of the cable in the excavated trench to a cable-laying contractor. The schedule for the excavation and cable laying was very complicated and supervision of the excavation work was limited. On the 25th May a cable-laying operative from the cable-laying contractor observed a damaged tile and cable in preparation for laying a cable but he did not report the damaged cable in the belief that it was dead and it had already been reported. Before that, on 20th April an excavation contractor had been found using a clayspade to the trench at a depth greater than the instructions from the toolbox talks. The earth fault was caused by physical damage to the cable from a clayspade. This case is not a standalone event related to creeping changes. For example, the 2006 Royal Air Force Nimrod crash, Texas City refinery explosion, Buncefield, Shell Moerdijk, the Columbia space shuttle disaster, Bhopal or the Herald of Free Enterprise are cases similar in nature.

Source:IChemE 

 


June 18, 2025

TEMPORARY CHANGES MAY LOOK SIMPLE BUT ARE DANGEROUS!

 On April 11, 2020, at 11:25 p.m., a spent caustic release occurred at a facility in Louisiana. One operator was seriously injured by skin exposure to the corrosive liquid.

At the time of the incident, the operator was implementing a temporary procedure to remove liquid from a chemical hose connected to fill a portable storage tank (“frac tank”) that the company was using to store spent caustic. Once the frac tank was full, air was used to clear the chemical hose before moving the hose to an empty frac tank.
When the operator opened the valve at the frac tank, pressurized fluid in the chemical hose flowed into the tank, erupting spent caustic from the unsecured top hatch (manway) and splashing the corrosive liquid onto the operator. The operator's personal protective equipment (PPE) did not protect from caustic liquid exposure. It took the operator about two minutes to reach the closest plant safety shower to rinse off the corrosive liquid because there was no safety shower near the frac tank, despite the site requirement for a safety shower within 25 feet of the tank. The operator then went to the control room and reported the incident. Emergency responders transported the operator to a hospital, where she was admitted for treatment of chemical burns.

It was  estimated that approximately 20 gallons of spent caustic were released. The spent caustic was comprised of water, sodium hydroxide, sodium sulfide, sodium carbonate, and pyrolysis gasoline.

Source:CSB.gov

July 3, 2024

A change in receiving storage tanks kills one

A road tanker loaded with ammonia hydroxide was being unloaded into a polyethylene storage tank at the site of a chemical distributor.  This change was not taken through a MOC. The unloading was being accomplished by filling the vacant space above the liquid inside the tanker with compressed air, a standard method of unloading such tankers. When the tanker was emptied, the compressed air surged into the polyethylene storage tank, which was not designed to withstand that kind of pressure. The polyethylene tank ruptured, releasing a substantial volume of ammonia into the air. An employee, who was close to the drain valve on the tanker, inhaled a substantial volume of ammonia, He suffered serious chemical burns to his lungs, resulting in his death. 

Source:osha.gov 

May 13, 2021

Accident due to a change implemented during an emergency

Reactor #1, part of the ABS polymerization process began to overheat as the viscosity increased and threatened to stop agitation. This would cause a runaway reaction and ultimately result in an explosion. A small leak had developed in the lower bushing of the agitator and the employer instructed an employee to tighten it with a wrench. The employer replaced the normal feed (a mixture of styrene monomer, ground rubber, and acrylonitrile) with pure styrene monomer, which has a much lower viscosity, to "flush" the process in the hope that this would stop the leak. The mixture began to spill through the lower agitator packing and at approximately 2:30 p.m., there occurred a major spill of styrene monomer (flammable) and acrylonitrile (flammable and carcinogenic). They evacuated the plant and called for outside assistance to stop the spill and initiate clean-up. 

Source: OSHA.gov

January 9, 2021

MY ARTICLE IN CEP ISSUE JANUARY 2021

My fourth article "Understand Process Hazards to Safely manage Change" has been published in the January 2021 issue of the CEP magazine of the American Institute of Chemical Engineers. Read it after logging in in this link https://www.aiche.org/publications/cep

You have to be a member of AIChE to read it.

November 27, 2020

Accident due to a temporary connection

The alkylation unit was going into shut down. Two contractors were fixing a copper tube to a T-piece of a drain. During the work they turned the T-piece over 90°. Due to this fact a valve on the T-piece was accidentally opened and an amount of hydrogen fluoride (HF) was released. One of the contractors was very seri-ously injured. His eyes, nose and mouth were burned and he inhaled HF fumes, which caused internal injuries to them. The second person only had small injuries around his mouth.CausesBecause the alkylation unit was shut down, the biggest equip-ment was already emptied and the installation was cleaned with nitrogen. Then it was decided to drain the unit to remove all flu-ids left. The drain consisted of two valves and a blind flange. The blind flange was removed and replaced by a T-piece consisting of a manometer and a small valve. The T-piece was mounted in a horizontal way. A permit was written for two contractors to add a copper tube to the small valve on the T-piece. Because it was not easy to work with the T-piece mounted horizontally they decided to rotate the T-piece. While rotating the piece, the handle of the small valve touched a pipeline which opened the valve and 360ml HF was released. 

Important findings

The T-piece on the drain was a temporary piece only installed for the shutdown. There was no standard in the company to which temporary pieces had to comply. The T-piece used screw thread which made it possible to turn the T-piece. The accident showed that a standard for temporary pieces must be drawn up.In the company it was seen as normal that the manual valves in the line on which the T-piece was fitted had a small internal leak. So in the work permit protective clothing should have been specified for working on this line since they should have antici-pated that HF would build up between the fixed (leaking) valves and the quarter turn valve on the temporary T-piece. A quarter turn valve is easily manipulated accidentally, certainly while doing mechanical work in the immediate vicinity.

Source: European commission


June 17, 2020

Low temperature failure incident

Three nozzles on top of a reactor suffered cracks in the welds during decommissioning of a high-pressure lube oil hydrogenation unit when it inadvertently discharged liquid nitrogen into three reactors. Excessive shrinking occurred, caused by thermal shock.
Damage that occurred to equipment is estimated to be approximately US$55,000 (1999).
Source:IChemE

September 7, 2016

Accident in Sewage Treatment plant


Employee #1, the lead operator of a sewage treatment plant, noticed that the residual levels had dropped in the tanks, and he decided to add more ammonium hydroxide to increase the residual levels. Employee #1 removed the camlock fitting and line from an empty 335 gallon tote and installed it to a full 335 gallon tote containing ammonium hydroxide solution. While installing the camlock fitting and line onto the full tote, he failed to secure the camlock fitting latches into the valve coupling grooves.

As Employee #1 turned the valve to the open position, the camlock fitting and line sprung off the coupling and sprayed ammonium hydroxide onto his upper legs and groin area. Employee #1 immediately turned off the valve and secured the camlock fitting latches into the coupling grooves. He then went to the emergency eyewash/shower, approximately 120 feet away, to rinse off the ammonium hydroxide. Employee #1 rinsed for approximately 15 minutes, but did not take off his clothing.

He then drove a golf cart to the administrative building, to notify management of the accident. Management summoned emergency medical services at approximately 9:45 a.m. and rinsed Employee #1 with an emergency eyewash/shower, located in the administrative building, until the ambulance arrived. Employee #1 was transferred to the hospital via ambulance at approximately 10:00 a.m. He was hospitalized for two days for treatment of chemical burns to his upper legs and groin areas.
The use of ammonium hydroxide to control residual levels in tanks was a new process at the facility. No written procedures or hazard assessments were completed for the assigned task. Employee #1 was wearing safety glasses but no other form of PPE during the accident. Employee #1 said he was in a hurry and normally would have worn rubber gloves and a respirator while transferring the camlock and line from one tote to another.

 Source: Fire Analysis and Research Division,National Fire Protection Association

Contribute to the surviving victims of Bhopal by buying my book "Practical Process Safety Management"

Contribute to the surviving victims of Bhopal by buying my book "Practical Process Safety Management"

October 10, 2015

A temporary change causes a fatality

Temporary changes are dangerous if not managed properly. Read about an incident involving a temporary change that causes a fatality. This incident highlights what Dr trevor Kletz used to say "We do not know what we do not know"
Read the incident in this link.

Contribute to the surviving victims of Bhopal by buying my book "Practical Process Safety Management"

September 27, 2015

Hydrogen explosion incident due to a change

A company, which produces metal catalysts had made a modification to one of its reactors.
An explosion occurred on the first day of production following the modification and blew the lid through the roof of the factory.


Read about the incident in this link


Contribute to the surviving victims of Bhopal by buying my book "Practical Process Safety Management"

September 2, 2015

MOVING PROCESS SAFETY INTO THE BOARD ROOM - ARTICLE IN CHEMICAL ENGINEERING PROGRESS

To all my readers,
My article "Moving process safety into the board room" has been published in the September 2015 issue of Chemical Engineering Progress of American Institute of Chemical Engineers.

Contribute to the surviving victims of Bhopal by buying my book "Practical Process Safety Management"