Operating Plant Safeguarding Design Basis Verification
Your facility has changed. Does the safety basis it was built on still reflect what you operate today?
A structured multi-disciplinary assessment of the alignment between the safety design basis established during design and the safeguards as modified, integrated and reconfigured today.
Context
“Changes accumulate. The design basis does not always follow.”
Projects develop. Construction introduces practical decisions, and commissioning leaves accepted deviations behind. In operation, safeguarding systems keep changing through modifications, replacements, debottlenecking and integration with new systems. The concern is not the change itself. The concern is change that can no longer be traced back to the safety basis, or a safety basis that has not been updated to reflect the facility now in service.
This study is focused on that concern and nothing wider. Its scope is agreed with the asset owner before work starts, and it checks one thing: Whether the changes made to the plant have been carried into the safeguard configuration documents, and into the predecessor documents those configurations rest on. The answer also addresses a question organizations rarely ask directly:
Has the MoC system been run well from a safety perspective?
Within that focus, the assessment finds gaps and inconsistencies, anticipates the hazards they can open and sets out the actions to close them. It is meant to reduce uncertainty, not to create a parallel crisis.
Design basis
The connected body of hazardous scenarios, assumptions, requirements, multi-disciplinary predecessor documents, physical configuration documents, performance standards and verification evidence.
- Hazardous scenarios
- Assumptions
- Requirements
- Multi-disciplinary predecessor documents
- Physical configuration documents
- Performance standards
- Verification evidence
How the plant design basis evolves
- Temporary turned permanentBypassed, out-of-service or on-hold safeguards, shelved alarms and interim administrative controls that stay in place after their authorization has run out.
- Control and alarm evolutionSetpoints, trip logic, alarm priorities and operator actions adjusted in the control system over the years.
- Changed process basisFeed, capacity or operating envelope moved away from the cases the safeguards were designed for.
- Replacement and obsolescenceReplacements that are not truly equivalent: Different response time, failure mode, rating or certification.
- Layout and occupancy changeNew buildings and new equipment that shift congestion, access, exposure, evacuation and emergency-response conditions.
- Brownfield integrationNew units and tie-ins sharing relief, flare, fire water, fire and gas detection or emergency shutdown with the existing plant.
- Fragmented projectsModifications by different contractors, third-party consultants’ recommendations and revalidated HAZOP actions, each closed on its own terms and not always consolidated into the basis.
- Ageing recordsSuperseded or unauthorized revisions, missing calculations, and design rationale that may have left with the people who knew it.
Scope of Work
A controlled scope, set on the safeguards that carry the safety argument.
The comparison is confined to the safeguarding systems in the focus areas and to the documents that define them: Their configuration documents and the predecessor documents behind them. Holding the boundary there keeps the evidence chain traceable, ties each gap to a specific hazard and safeguard, and brings results to the owner while decisions on audits, turnarounds and modifications are still open. The boundary is agreed with the asset owner before work starts and is held through to close-out.
- Coverage
- All safety measures, or only the systems critical to major accident hazards (MAH). The owner decides.
- Depth
- Comparison and reconciliation. Each safeguard in scope is traced from its current configuration back to its authorized basis. Each difference is either reconciled against documented evidence, such as an approved MoC, or registered as a gap. Depending on the engagement model, the work can evolve into an extended reconciliation or a reconstitution of the safety basis.
What is included in the study, what is not
- Confirmation that each safeguard is fit for purpose against its governing philosophy
- Reconciliation of the applicable safety design basis with the decisions taken on it
- Comparison of the safeguards as operated against the safeguards as designed
- Mapping of design rationale, configuration documents, MoC records and the operating configuration against one another
- Identification of gaps against the as-operated configuration and against DSIB’s Technical Integrity Verification Scheme, built on recognised good practice
- Assessment of how well MoC has handled safety-critical changes so far
- Challenge of cross-disciplinary assumptions and of the decisions taken on deviations
- Investigation of missing evidence
- Verification of the multi-disciplinary predecessors behind the safeguard configuration documentsExample: An ESD valve closure time is taken as justified by a proper surge study. The surge study itself is not re-checked.
- Assurance that configuration documents match the physical as-built plant
- SAT, functional or integrity testing, and measurement against performance criteria
- Re-engineering studies or checking of calculations
- Review of day-to-day integrity management methods and their results
- Formal attestation of plant-wide safety
- Corrections to drawings, cause and effect charts, calculations or philosophies
Focus areas
A change in any of the areas below can open a discrepancy between what the basis assumes and what the plant now has. The criteria listed are examples. The comparison takes into account every element that alters the functional or integrity performance of a safeguard, or its configuration.
Design limits, hazardous inventory, segregation, materials selection, escalation prevention and the assumptions used to avoid or reduce hazard at source.
Independence from the initiating cause, credited risk reduction, setpoint, logic, fail-state and any operator dependency embedded in the function.
Relevance to the scenario, time available for operator response, independence, credited risk reduction, setpoint, process limits and the validity of human-response assumptions.
SIF definition, functional and integrity requirements, setpoint, response time, independence, bypass arrangements, proof-test assumptions and many other issues exposed by an issued SRS.
Scenario coverage, relief capacity, backpressure, blowdown time, thermal response and the destination or disposal route.
Coverage, detection target, voting, detector type and location, cause-and-effect response, availability and impairment assumptions.
Containment capacity, segregation, drainage path, isolation, contaminated-water handling and firewater management.
Fireproofing envelope, the list of equipment and structures to be fireproofed, fire rating, duration and relevance to supplementary protection such as cooling and modifications to the active firefighting system; escalation potential and the effect on the modified environment.
Design philosophy, hydraulic capacity, coverage, activation philosophy, simultaneous demand, availability and access for response, and the demand on back-up water and foam.
List and location of release sources, classification assumptions and extents with the resulting equipment category, chemical changes that shift gas group and temperature class, ignition source control and ventilation assumptions.
Siting scenarios, spacing, congestion, occupancy, blast and fire exposure, egress scenarios that drive pressurization design, lifting or vehicle interaction and emergency-response access.
A reminder. The study proceeds on the assumption that the basis is correct and the studies behind it were properly done. At some points that assumption may not hold. Where it does not, DSIB records the red flag and the hazard it bears on in the register, using its established gap taxonomy. Typical cases: A missing predecessor, an unauthorized predecessor, or a safeguard defined in design that does not appear on the operating list.
Approach
A structured investigation from hazard intent to the safety measures relied upon today.
The study compares two reference points. The first is the safety design basis as established and authorized. The second is the set of safeguards the plant relies on today, with every change it has absorbed. The study does not assume that every hazard in the plant was correctly identified, or that the safeguarding configuration holds the plant at an acceptable level of risk. It establishes the difference between the two reference points and traces each difference to where it came from.
A plant with well-designed safeguards that work as intended and are kept up to date has a defensible safety story. The study tests whether yours still holds, and where it does not.
How the comparison is built
Design basis
Multi-disciplinary design predecessors and safety design documents
Configuration documents of the safeguarding systems in each focus area
For example, a gas dispersion study in the engineering base, and the gas detector layout drawing that fixes where each detector is installed in the configuration base.
Change
Why the plant has to change
What changes, with the control documents raised on the way
Revised predecessors and safety design documents
For example, a capacity increase carried through an MoC package.
Operating system
The predecessor pool as revised by change
The physical configuration relied upon today
The study compares reference point 1 with reference point 2, and traces each change through the route between them.
Gap taxonomy
Every gap identified is filed under one of six classes. The class shows where the gap lies and the kind of remedy it is likely to need. A finding may carry a second class where two gap types overlap.
BASISSafety Design Basis Gap
The basis itself may not support the comparison. A governing document may be missing, unauthorized, superseded with no successor or inconsistent with another; the scenario or assumption behind a safeguard may not be traceable; or the design case may no longer be the governing case.
- Typical findings
- Missing predecessor. Predecessor never authorized. Assumption with no recorded source. Open registers. Missing performance criteria or verification evidence.
- Usual route
- Evidence recovery, revalidation or reconstitution
ASSETAsset Alignment Gap
The safeguard in service may no longer match what its basis requires. It exists, but its type, rating, setting, location or response differs from the configuration the basis supports, or it may be missing altogether.
- Typical findings
- Replacement valve with a slower closure time. Gas detector moved outside its mapped coverage. Safeguard defined in design that does not appear on the operating list.
- Usual route
- Reconciliation or re-engineering, with a shutdown need assessed where exposure is high
CHANGEChange and Configuration Gap
A change reached the plant without the full record behind it. What may be missing is a complete assumption set, an impact assessment, an approval path, an assurance record, or the corresponding update to predecessor and safeguarding configuration documents.
- Typical findings
- Trip setpoint changed in the control system without MoC. MoC closed without a cause and effect update. Debottlenecking with no relief re-check.
- Usual route
- Retrospective MoC and reconciliation
INTERFACEInterface Gap
Each discipline, package or project may be consistent within itself while the interaction between them is not. The gap typically sits where systems are shared, where scope is split between packages, vendors and licensors, or where roles are split between contractors, consultants and the owner.
- Typical findings
- New unit tied into an existing flare header without a combined relief case. Fire and gas executive action missing from the shutdown cause and effect. Third-party recommendation never assigned an owner.
- Usual route
- Cross-disciplinary revalidation
HUMANHuman Dependency Gap
A task, operator action, procedure, staffing arrangement, alarm response or organisational capability credited as risk reduction in the basis is no longer available, practicable or supported within the required time and conditions.
- Typical findings
- Manual isolation credited in the basis, with the valve now outside safe reach after a layout change. Field action credited on a staffing level that has since been reduced. Credited procedure withdrawn or superseded without a review of the scenario it supported.
- Usual route
- Revalidation of the credit, procedural or organisational changes, or re-engineering where the credit cannot be supported
LIFECYCLELifecycle Integrity Needs Gap
The basis does not provide a defensible foundation for readiness, performance standards, inspection, proof testing, maintenance, impairment control, SCE verification or ongoing safety review; the plant therefore relies on local assumptions or temporary workarounds.
- Typical findings
- Proof-test procedures written without the SRS test coverage and interval assumptions behind the PFD figures. SIF bypass practice with no compensating measures or maximum duration defined in the basis. SCE performance standards not derived from the scenarios the safeguards are credited for.
- Usual route
- Definition of lifecycle requirements in the basis, such as an SRS update or performance standards, followed by alignment of the integrity programme
Before the roadmap is drawn up, every registered gap is rated on a criticality matrix that weighs the hazard it bears on against the confidence left in the safeguard. The matrix and its criteria are agreed with the owner, so the order of the roadmap rests on terms both sides accepted in advance.
Outputs
Six deliverables. Each can be read on its own; together they form one traceable record from the design basis to the plant in service.
Current Safety Basis Dossier and Confidence Register
The agreed assessment baseline. The governing sources (predecessors, configuration documents and others) are listed with their latest authorized issues, before and after owner acceptance, each with a stated level of confidence. The assumptions and limitations the assessment worked under are recorded with them.
Reconciliation Map
The comparison rationale from design freeze through owner acceptance to operation, showing the link between predecessors, configuration documents, deviations, MoC evidence and current reliance. Where relevant, it includes a design-focused partial SCE/TIV traceability plan.
Integrated Gap and Decision Register
Every gap under its taxonomy class, with evidence notes, relevance to the hazard, potential consequences, safeguarding group and tags. Field evidence raised through feedback is logged alongside. Each entry ends with the decision needed and the recommendation.
Unit/Plant-Wide Alignment and Exposure Profile
A consolidated view of major deficiencies by unit, safeguarding area and equipment group.
Risk-Informed Remediation Roadmap
Short-, mid- and long-term actions, sorted by route: Evidence recovery, revalidation, reconciliation, reconstitution, re-engineering, and shutdown needs where they arise. Each action is marked for its CAPEX or OPEX relevance, for planning.
Management Decision Brief
The alarming points and highlights. The residual uncertainty. The decisions and assumptions that rest with the owner. Remediations with operating and capital cost relevance. A retrospective on how reliable the plant’s overall safety philosophies have proven to be.
Turn the page from its corner, or choose an output from the list.
When This Support Is Most Valuable
Before uncertainty becomes a project constraint—or an incident question.
The work is most useful when the owner needs a defensible view of the existing safeguarding basis before committing to audit, shutdown, modification or major investment.
-
Before an external review
Doubts have surfaced ahead of a third-party safety review or an international functional safety assessment. You need to know whether the changes call for a shutdown and correction before the turnaround, or whether they can wait. The study narrows that uncertainty before the review begins.
-
After a near miss
A near-miss or minor-incident investigation has exposed missing pieces. Before something larger happens, you want to review the documentation alignment that investigators, authorities and insurers are likely to look at first.
-
Before an operating change outside the usual
A capacity increase, a new feed or a change in inlet and outlet conditions can take the plant beyond the cases its safeguards were built for. The study builds confidence in those safeguards before you rely on them.
-
Before a costly integration project
Project executors, contractors and licensors need a reliable starting point. Clearing the uncertainty first keeps the new installation from bringing rework later or carrying hidden risk into the plant.
-
Before a computerized integrity management system
Put the safety-critical documentation in order before it is loaded, so the new system does not inherit the gaps.
-
Before a major configuration change
Ahead of a significant configuration or parametric change in the process or the control system, the study confirms the basis the change will be managed against.
In Short
Investigating Safeguarding Design Basis
This is a well-defined, owner-constrained assessment intended to reduce uncertainty without creating a parallel crisis. It is normally completed alongside routine operations and gives an initial, evidence-based view of whether a concern can be managed through planned work, needs interim controls, belongs in a turnaround, or requires further escalation—including specialist review of a possible unit or plant shutdown need.
The practical endpoint is clear:The organisation knows what it can rely on today, where confidence is limited, and how to close the difference without losing control of the work.
“Documented compliance does not always prove effective design.”
An alarm system may fully match its approved documents and still prove problematic over years of operation. The assessment then returns to the design basis: The hazard and human-response assumptions, the performance targets, the prioritization logic and the evidence collected in operation. From there it identifies whether the right route is rationalization, revalidation, redesign, reconstitution, operational changes or a combination of these.