Critical Thinking·DSIB

Red Flags a Project Manager Should Recognise During or After HAZOP

A HAZOP can run to schedule, fill a report and close every action, and still leave the project carrying the risk it was convened to resolve. A project manager does not need to lead the deviation-by-deviation discussion to see it: what is said in the room, what is written in the register, and what happens to the design afterwards give the answer. The 18 red flags below are drawn from the field experience of DSIB principals, and each carries a question meant to be asked while the work is still running — at the end of a node, at the close of a session, before a report is signed.

Classification 01 · 4 signals

Design Maturity and Basis of Review

Whether an issued, internally consistent design exists for the review to test.

01

The team is reviewing a design that does not yet exist.

Discussions repeatedly rely on what will be added, revised or supplied later.

Ask

Are we assessing the issued design, or describing the design we hope to have?

02

The workshop is resolving fundamental design questions.

Operating philosophy, shutdown architecture, isolation boundaries or relief strategy are being invented during the review.

Ask

Is this a review of design intent, or a substitute for unfinished design development?

03

Predecessor documents exist but tell different stories.

P&IDs, control narratives, cause-and-effect logic, equipment data and vendor documents contain inconsistent assumptions.

Ask

Which document represents the design being authorised for the next stage?

04

Safeguards are credited without an adequate design basis.

Planned alarms, trips, procedures or vendor features are credited before they are incorporated into the design, while existing safeguards may be described without tags, functions, set points, voting logic, response times or performance requirements.

Ask

Where is this safeguard defined in the current design, and what evidence supports both its existence and its claimed performance?

Classification 02 · 3 signals

Scope Coverage and Interface Boundaries

Which operating states, interfaces and lines of enquiry the analysis actually reached.

05

Important operating modes are outside the discussion.

The review concentrates on normal operation while start-up, shutdown, bypass, maintenance, regeneration or utility failure remain poorly defined.

Ask

Which credible operating states have not yet been represented in the analysis?

06

Package or battery-limit boundaries end the conversation.

A consequence crosses an interface, but responsibility is deferred with “vendor scope,” “by others” or “outside battery limits.”

Ask

Who owns the complete scenario across the interface, and where will it be verified?

07

Node progress is unusually fast.

The team records deviations without testing design intent, causes, consequences or the conditions required for safeguards to work.

Ask

Are we achieving coverage, or merely completing the schedule?

Classification 03 · 5 signals

Risk Judgement and Evidential Basis

Where a technical basis gives way to a matrix score, an optimistic assumption, a name or a silence — and whether the assumptions the conclusions rest on are controlled.

08

Risk ranking closes the discussion.

A matrix score is accepted without challenging consequence assumptions, safeguard validity or uncertainty.

Ask

Would the judgement change if an assumed safeguard, occupancy condition or initiating cause were different?

09

Missing information is interpreted optimistically.

Where data are absent, the team defaults to favourable assumptions about inventories, occupancy, response times, failure behaviour or vendor performance.

Ask

How would the judgement change if the uncertainty were treated conservatively rather than optimistically?

10

Authority is being used as evidence.

Statements such as “the licensor requires it,” “the owner has accepted it” or “management has already decided” close the discussion without a traceable technical basis.

Ask

What evidence supports the claim, and who is accountable if the underlying assumption proves false?

11

The room agrees too easily.

Senior influence, schedule pressure, reluctance to reopen previous decisions or a tendency for disciplines to avoid challenging matters outside their formal scope suppress independent questioning, and silence is treated as multidisciplinary agreement.

Ask

Would each discipline reach the same conclusion if asked independently to state its concerns, uncertainties and challenges to decisions beyond its immediate scope?

12

Assumptions and the validity limits of the review are not controlled.

The analysis depends on temporary inventories, operating conditions, staffing, response times or vendor performance that are absent from the report, while no criteria define which subsequent design changes would invalidate the conclusions or require revalidation.

Ask

Who will verify each assumption, what conditions define the validity of the review, and what change will trigger revalidation?

Classification 04 · 6 signals

Recommendation Quality, Closure and Project Commitments

Whether recommendations resolve the decision, reach the design as evidence, and are settled while project commitments can still be changed.

13

“Confirm later” has become the dominant outcome.

Numerous actions request confirmation without defining the decision, requirement or consequence of an unfavourable answer.

Ask

If the confirmation fails, which scenarios, deliverables and commitments must be revisited?

14

The review creates activity without resolving material uncertainty.

The workshop produces numerous records, actions and apparent decisions, yet many remain low-impact, avoid major design choices, generate no material design recommendations and leave the principal uncertainties largely untouched.

Ask

Which major design decision is now better supported, and what significant uncertainty has actually been removed because this review was performed?

15

Many small actions are masking one strategic decision.

A cluster of minor recommendations appears to address individual symptoms while the underlying issue—such as shutdown philosophy, segregation, relief strategy, package responsibility or risk acceptance—remains undecided.

Ask

What single project decision would remove or fundamentally reshape this group of actions?

16

Operational and administrative controls are substituting for unresolved design protection.

Operator intervention, procedures, permits, inspection or supervision are repeatedly proposed to manage hazards arising from unresolved isolation, layout, control-system or equipment decisions, without demonstrating alarm quality, available response time, accessibility, workload, procedures or training.

Ask

Are these credible and engineered controls, or convenient substitutes for design protection that the project has not yet developed?

17

Actions lack design traceability and objective closure evidence.

Recommendations are assigned to individuals without identifying the affected P&ID, specification, logic diagram, package document or procedure (either explicitly or implicitly), and may later be closed through written explanations without revised documentation, technical approval or interface verification.

Ask

What objective evidence will demonstrate that the decision has entered the design and that the risk—not merely the action—has been resolved?

18

Open issues have no relationship to project commitments.

Safety actions remain open while procurement, layout freeze, package award or construction release proceed independently.

Ask

Which upcoming commitment — procurement, layout freeze, package award or construction release — will close the window for resolving this issue, and by what date must it therefore be closed?

Remember

Ask for the evidence, not the reassurance

None of these 18 signals needs a technical argument to raise. Each one is tested with a single question, and the answer is either a document, a tag number, an owner and a date — or it does not exist yet. That distinction is the whole of the judgement.

A review that cannot produce the evidence is not a failed review. It is an unfinished one, and the project still has time to say so.

Design Safety Intelligence Bureau
Critical Thinking Series
© Design Safety Intelligence Bureau. All rights reserved. This document and its contents may not be copied, reproduced, distributed, downloaded or printed, in whole or in part, without prior written permission.
© Design Safety Intelligence Bureau. This document may not be printed or reproduced without prior written permission.