Free NEBOSH PSM Exam Flashcards

Memorize 50 essential terms and definitions for the NEBOSH HSE Certificate in Process Safety Management. See the term, recall the definition, then flip to check yourself.

50 Flashcards
14 Topics
100% Free
TermClick to flip

What is process safety, and how does it differ from personal (occupational) safety?

Tap to reveal definition
Card 1 of 50Process Safety Leadership

Filter by Topic

Jump to Card

About These NEBOSH PSM Flashcards

These 50 flashcards are designed to help you memorize key terms and definitions for the NEBOSH HSE Certificate in Process Safety Management. Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.

Topics Covered

Process Safety Leadership7 cards
Process Safety Management Systems2 cards
Risk Assessment Techniques6 cards
Asset Integrity3 cards
Permit-to-Work3 cards
Shift Handover and Contractors2 cards
Operating Procedures and Safe Limits4 cards
Safety-Critical Elements3 cards
Utilities and Static Electricity4 cards
Dangerous Substances and Reactions5 cards
Bulk Storage2 cards
Fire and Explosion Hazards3 cards
Explosion Prevention and Protection4 cards
Emergency Planning2 cards

Complete Flashcard Reference

Review every term in this set. Open any term to reveal its definition.

What is process safety, and how does it differ from personal (occupational) safety?

Process safety is the blend of engineering and management skills aimed at preventing catastrophic loss of containment of energy or dangerous substances - fires, explosions, structural collapse and toxic releases. Personal safety deals with high-frequency, low-severity harm such as slips, trips and manual handling. Process safety deals with low-frequency, high-severity events, so a site can post an excellent injury rate while its major accident risk is out of control.

Why did the 2005 BP Texas City explosion happen on a site with a low personal-injury rate?

During start-up of the ISOM unit the raffinate splitter tower was overfilled and hot liquid discharged through the relief system into an obsolete atmospheric blowdown stack, releasing a flammable cloud that ignited and killed 15 people working in trailers sited too close to the unit. Investigators found the company was tracking personal-injury statistics as its measure of safety while process safety warning signs went unmanaged. Lesson: injury rates say nothing about major accident risk.

What is the role of senior leadership and the board in process safety management?

Directors decide the priorities, resources and culture that determine whether barriers are actually maintained. Effective leaders visibly own major accident risk, review process safety indicators at board level rather than only injury figures, fund asset integrity instead of deferring it under production pressure, and make it safe to report bad news. In Great Britain the Process Safety Leadership Group, formed by industry, unions and regulators after Buncefield, put these expectations into published standards for fuel storage sites.

What does 'dual assurance' mean when setting process safety performance indicators?

HSE guidance HSG254 asks you to pair indicators for each critical risk control system: a lagging indicator showing the control has already failed (a loss of containment, a relief valve that failed its test), and a leading indicator showing whether it is working as intended now (safety-critical inspections completed on time, overdue actions, alarm rationalisation status). Lagging data alone means you only learn about a barrier after it has failed.

Which failure caused the 1974 Flixborough explosion, and what does it teach about change?

Reactor 5 was removed for repair and replaced by a temporary 20-inch dogleg bypass pipe resting on scaffolding. It was not designed to any recognised standard, not checked by a qualified engineer and not pressure tested. It failed, releasing tens of tonnes of hot cyclohexane that formed a vapour cloud explosion killing 28 people. Lesson: a temporary modification needs the same formal management of change scrutiny as a permanent one.

What must a management of change (MOC) procedure cover before a change is approved?

What is changing (plant, process, chemicals, procedures, software or organisation), a hazard review proportionate to the risk, sign-off by a competent technical authority, updates to P&IDs, procedures, alarm settings and training, and for temporary changes a defined expiry date and removal plan. Like-for-like replacement is normally exempt, but 'similar' is not 'same': a different material, rating or supplier is a change. Organisational change - cutting an operator post or a maintenance team - is a change too.

How is competence defined in process safety, and what does a competence management system do?

Competence is the combination of knowledge, skill and experience, plus the willingness and reliability to work to agreed standards, needed to prevent major accidents. A competence management system identifies the safety-critical roles, defines the standard for each, assesses individuals against it, refreshes training, and re-assesses after changes, incidents or long absence. Holding a qualification is not competence: it must be demonstrated in the actual role and maintained.

What is a process safety management system for, and how is the CCPS framework structured?

A PSM system turns process safety from individual expertise into a managed, auditable business system spanning the whole plant life cycle - who is accountable, which standards apply, how performance is measured and how findings are closed out. The CCPS Risk Based Process Safety framework groups its twenty elements under four pillars: commit to process safety, understand hazards and risk, manage risk, and learn from experience. The weakest link is usually the last one: open actions from HAZOPs and investigations.

Under the COMAH Regulations 2015, what does a lower-tier site have to do that an upper-tier site must exceed?

Every COMAH establishment must notify the Competent Authority (HSE working jointly with the environment agency) and prepare a Major Accident Prevention Policy backed by a safety management system. Upper-tier establishments must additionally submit a safety report demonstrating that all necessary measures have been taken, prepare an on-site emergency plan, supply information for the local authority's off-site plan, and provide information to the public. Tier is determined by the quantities of dangerous substances present.

What is a HAZOP study, and how are guide words used?

A HAZOP is a structured, multidisciplinary examination of a design, chaired by an independent leader and worked node by node through P&IDs. The team applies guide words - no/none, more, less, as well as, part of, reverse, other than - to parameters such as flow, pressure, temperature, level and composition to generate credible deviations ('more pressure', 'reverse flow'), then records causes, consequences, existing safeguards and actions. The technique was developed by ICI in the 1960s.

When would you use a HAZID rather than a HAZOP?

HAZID is a broad, team-based hazard identification used early - at concept or front-end design, or before modifying existing plant - and it covers non-process hazards such as transport, occupational and environmental issues alongside process hazards. HAZOP is far more detailed and needs a firm design: completed P&IDs and defined operating conditions. Running a HAZOP too early wastes the effort because the design will still move; skipping HAZID means whole hazard categories are never considered.

In a LOPA, what qualifies as an independent protection layer, and in what order are layers preferred?

LOPA starts from an initiating cause and its frequency, then credits each protection layer with an order-of-magnitude probability of failure on demand to test whether residual risk meets the target. An independent protection layer must be effective against that specific consequence, independent of the initiating cause and of every other credited layer, and auditable. The preferred order is inherently safer design, basic process control, alarms with operator action, safety instrumented systems, relief devices, containment such as bunds, then site and community emergency response. A control-system loop can normally be credited only once, and an alarm generated by that same control system is not independent of it.

What do the left and right sides of a bow-tie diagram represent?

The knot is the top event - loss of control, typically loss of containment. The left side lists the threats that could cause it and the preventive barriers stopping each threat reaching the top event. The right side lists the consequences and the mitigative or recovery barriers that limit them once the top event has happened. Escalation factors hang beneath barriers to show what could defeat them, each with its own control. Its value is that every barrier can be named, owned, resourced and monitored.

What are the inherent safety principles, and how do they apply to Bhopal?

Intensification (hold less hazardous material), substitution (use a less hazardous material or route), attenuation (use it under less hazardous conditions - lower pressure, lower temperature, diluted), and simplification (design out complexity and the errors it invites). At Bhopal in 1984 water entering a bulk storage tank triggered a runaway reaction releasing around 40 tonnes of methyl isocyanate, with the refrigeration, scrubber and flare defences unavailable. Storing far less MIC would have limited the release whichever control failed: what you do not have cannot leak.

What does ALARP require beyond simply having controls in place?

ALARP means the risk has been driven down to the lowest level reasonably practicable: a further measure must be implemented unless its cost in money, time and trouble would be grossly disproportionate to the risk reduction it buys. The higher the risk, the greater the disproportion needed to justify inaction, and the burden of showing that sits with the duty holder. Sitting in the tolerable region with no further action and no argument recorded is not ALARP.

What does 'asset integrity' mean, and what are its three strands across the life cycle?

Asset integrity is the ability of equipment to perform as intended, effectively and efficiently, throughout its whole life while protecting people and the environment. Design integrity means it was specified and built right for the duty; technical integrity means inspection, testing and maintenance keep it fit for service; operating integrity means it is run inside its design envelope by competent people. Integrity is usually lost quietly - deferred inspections, temporary repairs, creeping change - long before anything leaks.

Compare breakdown, planned preventive and condition-based maintenance for process plant.

Breakdown (run-to-failure) maintenance is only defensible where failure has no safety, environmental or production consequence. Planned preventive maintenance services or replaces items on a fixed time or usage interval regardless of condition: simple, but it can act too late or discard useful life. Condition-based or predictive maintenance uses vibration analysis, thermography, oil analysis and thickness monitoring to intervene before failure. Safety-critical equipment must never sit on a run-to-failure regime.

What is risk-based inspection, and why is corrosion under insulation so dangerous?

Risk-based inspection ranks equipment by likelihood and consequence of failure so inspection effort and intervals target what matters instead of treating every vessel alike. Corrosion under insulation is a classic RBI target because it is hidden - water penetrates the cladding and attacks the wall out of sight, so it is only found by stripping insulation or using specialist techniques. Ultrasonics measure wall loss, radiography finds weld defects, dye penetrant reveals surface-breaking cracks, and magnetic particle inspection finds surface and near-surface flaws in ferrous steel.

What is a permit-to-work system for, and what are its four operating stages?

A permit to work is a formal, documented control for high-risk non-routine work and the communication link between plant management, supervisors and the people doing the job. The stages are issue (the authorised person defines the work, hazards, precautions and isolations), receipt (the performing party accepts and confirms understanding), clearance or hand-back (work stopped or finished, people and tools withdrawn, plant left in a defined state), and cancellation (the issuer accepts hand-back and returns the plant to operations). The permit records that precautions were checked - it does not make the work safe by itself.

Which permit-to-work and handover failures caused the Piper Alpha disaster in 1988?

A pressure safety valve had been removed from condensate pump A for recertification and the open line temporarily blanked, under a permit that was suspended and never communicated at shift handover. When pump B tripped, the night crew restarted pump A; condensate escaped from the blank and ignited. 167 people died. The Cullen Inquiry into the disaster led to the offshore safety case regime, and it remains the standard case study for permit cross-referencing, isolation control and handover of incomplete work.

What isolation standards are used to make process plant safe for maintenance?

Isolation must be graded to the risk: a single valve locked and tagged for low-hazard, short-duration work; double block and bleed where leakage past one valve would be serious; and positive isolation by spade, blind, spectacle plate or physical disconnection for vessel entry, hot work or long jobs. The isolation must be proved at the point of work - drained, depressurised, vented, purged and tested - not assumed from a valve position or a control-room indication. HSE guidance HSG253 sets out this graded approach.

What makes a shift handover safe rather than a formality?

Handover works when it is a two-way, face-to-face conversation with time formally allowed for it, supported by a written log so the same information exists in both spoken and recorded form. Both parties carry responsibility: the incoming operator must question, repeat back and confirm understanding rather than just sign the book. The highest-risk handovers are those covering non-routine or incomplete work - suspended permits, overrides and bypasses in place, plant out of service and abnormal conditions.

What must an operator do to manage contractors on a major hazard site?

Select on competence and process safety record rather than lowest price, define the scope and the hazards in writing, verify that individuals are trained and competent, brief them on site rules, the permit system and emergency arrangements before work starts, supervise and monitor the work in progress, and review performance afterwards. The client cannot contract out its duties. Multi-employer sites fail when nobody owns the interface between contractor activity and live plant.

What is a safe operating envelope, and what should happen as the plant approaches its limits?

The safe operating envelope is the set of upper and lower limits - pressure, temperature, flow, level, composition - within which the process is known to be safe. Procedures should state the normal range, the alarm point that warns the operator, the required action, and the trip point at which automatic protection acts. Operating outside the envelope, even briefly, is an excursion that should be reported and investigated: a rising excursion count is a leading indicator that a major accident is being approached.

What makes a standard operating procedure effective for process safety?

It sets out step by step how to run a specific part of the process so the safe operating envelope is maintained. It should be written with the operators who use it, validated against the plant as built, cover normal, abnormal, start-up, shutdown and emergency conditions, state the limits and the consequences of exceeding them, be a controlled document with a review date, and be revised through management of change whenever plant or process changes. A procedure that no longer matches the plant trains people to ignore procedures.

Why are start-up and shutdown the highest-risk phases of process operation?

In transient operation the plant passes through conditions it never sees in steady state: vessels are filled and emptied, flammable material can meet air, temperatures and levels swing, protective systems may be bypassed or on manual, and operators intervene manually far more often. Controls include written start-up and shutdown procedures with checklists, a pre-start-up safety review confirming the plant is complete and isolations removed, formal authorisation and tracking of every override, and experienced supervision on shift.

What is the difference between a planned shutdown, an emergency shutdown and a total shutdown?

A planned shutdown follows a written sequence to bring plant down in a controlled order for maintenance or turnaround, with time for depressurisation, draining and purging. An emergency shutdown is triggered automatically by the ESD system or manually to isolate feed, remove ignition sources, depressurise and route inventory to flare or a safe location. A total shutdown extends this to utilities and services. The residual hazard is what is left behind - trapped inventory, hot surfaces, stored energy - which must be proved safe before anyone breaks containment.

What is a safety-critical element, and why does each one need a written performance standard?

A safety-critical element is any system, equipment or structure whose failure would cause or substantially contribute to a major accident, or whose purpose is to prevent or limit one - emergency shutdown valves, gas and fire detection, relief systems, firewater, blast and fire walls. A performance standard states exactly what the element must achieve and how that is verified, so inspection, testing and maintenance can be audited against a defined claim rather than a general intention, and so nobody quietly downgrades it.

What does the acronym FARSI stand for in a performance standard?

Functionality - what the element must actually do, stated measurably. Availability - the proportion of time it must be able to do it. Reliability - the probability it will work on demand. Survivability - its ability to keep working in the very conditions it exists to control, such as fire, blast or flooding. Interdependency - what else it relies on, such as power, instrument air or another system. Survivability is the one most often forgotten: a detector or cable that fails in the fire it was fitted for is not a barrier.

What is a safety instrumented function, and what does its SIL express?

A safety instrumented function is an independent sensor - logic solver - final element loop that takes the process to a safe state when a defined limit is reached, for example a high-high level closing the feed valve. Its safety integrity level expresses the risk reduction required, defined by average probability of failure on demand in low-demand mode: SIL 1 gives 10 to 100 times reduction, SIL 2 100 to 1,000, SIL 3 1,000 to 10,000. Higher SILs demand redundancy, proof testing at defined intervals and strict control of overrides and bypasses.

What hazards arise from steam and water in the process industries?

Steam causes severe scalds and is often invisible at the leak point; losing steam can also stop critical heating or stripping. Water hammer from condensate slugs in a steam line can fracture pipework and break supports. Water trapped in hot oil flashes violently to vapour with a huge volume increase, which is what drives boil-over in a burning storage tank. Loss of cooling water removes the heat sink from an exothermic reactor, and water reaching a water-reactive chemical can itself start a runaway.

Why must the failure position of every control valve be defined for loss of instrument air?

Utilities - instrument air, electrical power, cooling water, nitrogen, steam - are common-cause failures that can remove several barriers at once. On loss of air each valve moves to its spring position, so the design must decide whether fail-closed, fail-open or fail-in-place leaves the process safe: a feed valve that fails open on a reactor could be catastrophic while a cooling valve failing open is protective. Utility failure should be an explicit HAZOP deviation and an alarmed condition, not an assumption.

How does static electricity ignite flammable atmospheres, and how is it controlled?

Charge separates whenever materials move apart - liquid flowing through pipework, splash filling a tank, powder discharging into a vessel, steam or dust jetting. If the charge cannot flow to earth it accumulates until it discharges as a spark carrying enough energy to ignite a flammable vapour or dust cloud. Controls: bond conductive parts together and earth them, fill from the bottom or through a dip pipe rather than splash filling, keep the initial fill velocity low until the inlet is submerged, use conductive or antistatic equipment and clothing, allow relaxation time before dipping or sampling, and inert where practicable.

Which electrical ignition sources must be controlled on a process plant, and how?

Switching sparks, arcing from damaged cables or loose terminals, hot surfaces on motors and lighting, and stray currents from cathodic protection or welding returns can all ignite a flammable atmosphere. Controls are equipment protected to a standard appropriate for the hazardous zone (flameproof, increased safety or intrinsically safe), earthing and bonding, inspection and maintenance to the hazardous-area standard rather than the general electrical standard, control of portable equipment through the permit system, and hot work permits with gas testing before and during the job.

What does hazardous area classification under DSEAR require?

Places where an explosive atmosphere may occur are classified into zones by how likely and how long the atmosphere is present. For gases, vapours and mists: Zone 0 is present continuously, for long periods or frequently; Zone 1 is likely to occur occasionally in normal operation; Zone 2 is not likely in normal operation and short-lived if it does. Dusts use Zones 20, 21 and 22 on the same logic. Equipment must be selected to a category suitable for its zone, and the classification drives ignition control, permits and the DSEAR risk assessment.

How does the physical form of a dangerous substance change the risk it presents?

Gas disperses and travels: a dense gas or vapour such as LPG or petrol vapour slumps and collects in pits, trenches and drains, while lighter-than-air gases such as methane and hydrogen rise and disperse. A liquefied gas held under pressure flashes to a very large vapour volume on release. A flammable liquid released as a fine mist or spray can ignite well below its flashpoint, because droplet size rather than bulk temperature controls ignition. A combustible solid is inert as a lump but explosive as an airborne dust.

Define flashpoint, LEL and UEL - and explain why a mixture above the UEL is still dangerous.

Flashpoint is the lowest temperature at which a liquid gives off enough vapour to ignite momentarily when an ignition source is applied under specified test conditions. The lower explosive limit is the minimum vapour concentration in air that will propagate flame; the upper explosive limit is the maximum. Between them the mixture is flammable. Above the UEL it is too rich to burn where it stands, but any dilution with air - opening a tank, ventilating a space, a breeze - carries it back down through the flammable range, which is why tank vapour spaces and confined spaces are so hazardous.

What causes a thermal runaway reaction?

A runaway occurs when the rate of heat generated by an exothermic reaction exceeds the rate at which heat can be removed. Reaction rate climbs roughly exponentially with temperature while cooling capacity rises only in proportion to the temperature difference, so a small excess accelerates until the batch boils, decomposes or over-pressurises. Typical triggers: loss of cooling, agitator failure allowing unreacted material to accumulate then mix suddenly, charging too much or too fast, wrong order of addition, contamination, and starting too hot.

What measures mitigate the consequences of a thermal runaway?

Prevention comes first: reaction hazard testing before scale-up, defined safe charge quantities and addition rates, reliable cooling with a backup, agitation interlocks and feed trips. Mitigation includes an emergency relief system routed to a catch pot or scrubber rather than the atmosphere, a dump or quench system draining the batch into cooled diluent, inhibitor or shortstop injection, and emergency cooling. Relief sizing for a runaway must assume two-phase flow - vapour and liquid leaving together - or the vent will be far too small.

What are the main hazards of bulk atmospheric storage of flammable liquids?

Overfilling, which puts a large volume at ground level and generates a spreading vapour cloud; rim seal and roof fires on floating roof tanks; overpressure or vacuum collapse when vents and breather valves are blocked or filling and emptying rates are wrong; shell and floor corrosion causing slow undetected leaks; and loss of secondary containment. Bunds must retain the largest tank plus an allowance, be impermeable and be closed off, otherwise the release passes to drains, groundwater and watercourses as it did at Buncefield.

Why did tank 912 overfill at Buncefield in 2005, and which protection layer failed?

The automatic tank gauge used for routine level control had stuck and had not been repaired, so the control room never saw the rising level. The independent high-level switch that should have shut the filling line as a separate protection layer could not operate, because its test lever needed a padlock fitted to hold it in the working position and that had not been done. Around 300 tonnes of petrol overflowed. The lesson: a high-level trip is a safety-critical element needing its own performance standard, proof testing and maintenance - not a spare level gauge.

Distinguish a pool fire, a jet fire, a flash fire and a fireball.

A pool fire burns above a spreading liquid pool and threatens surrounding plant through radiant heat over a wide area. A jet fire is a pressurised release burning as a flame jet: far more intense and erosive, and where it impinges on a vessel, pipe or structural support it can cut through steel and cause escalation within minutes. A flash fire is a vapour cloud igniting and burning back through itself with little overpressure, killing by direct flame contact. A fireball is the brief, intense burning cloud from sudden release of a pressurised liquefied gas.

What is a BLEVE, and how is it prevented?

A boiling liquid expanding vapour explosion happens when a vessel holding liquid above its atmospheric boiling point is heated - typically by flame impingement on the vapour space, where no liquid carries the heat away - until the weakened shell tears open. The contents flash instantly, producing a blast wave, missiles and, for a flammable liquid, a fireball. Prevention: water deluge and cooling directed at the vapour space, passive fire protection or mounding, emergency depressurisation to flare, sloped bases and drainage so pools cannot sit beneath vessels, and separation distances.

Why do some vapour cloud releases explode while others only flash fire?

An unconfined flammable cloud usually burns as a flash fire because the flame front stays slow. It becomes a damaging explosion when the flame accelerates, and acceleration comes from congestion and confinement - pipe racks, dense structures, vegetation, parked vehicles - which generate turbulence ahead of the flame front. At Buncefield in 2005 the cloud produced overpressures far higher than open-air models predicted, and the dense trees along the site boundary were identified as a major contributor to that flame acceleration.

What five conditions must coincide for a dust explosion?

Combustible dust, oxygen, an ignition source, dispersion of the dust as a cloud within its explosible concentration range, and confinement in an enclosure, duct or building so that pressure can build. The first three are the fire triangle; dispersion and confinement are what turn a dust fire into a dust explosion. Particle size is decisive - the finer the dust, the greater the surface area exposed and the more violent the event.

Why is the secondary dust explosion usually the one that destroys the building?

A relatively small primary explosion inside a vessel or duct shakes the structure and lifts dust that has been allowed to settle on beams, ledges, floors and ductwork. That far larger dispersed cloud then ignites, so the damage scales with the housekeeping failure rather than the original event. Explosion violence is measured by the Kst value from a standard test, which sorts dusts into St 1, St 2 and St 3 classes of increasing severity and is used to size explosion relief. The primary control is simply preventing dust accumulation.

Name the main explosion protection measures used when prevention alone cannot be relied on.

Containment - design the vessel to withstand the maximum explosion pressure. Explosion relief venting - deliberate weak panels or bursting discs, correctly sized and discharging to a safe place, so pressure escapes instead of bursting the plant. Suppression - detectors sense the pressure rise within milliseconds and inject a suppressant to quench the flame. Isolation - fast-acting valves, rotary valves or material chokes that stop flame and pressure propagating along ducts into other equipment. Prevention itself means inerting to hold oxygen below the limiting concentration and rigorous ignition-source control.

What is the difference between active and passive fire protection, and why is detection critical?

Passive protection needs no action and no power: fire and blast walls, intumescent or cementitious coatings on structural steel and vessel supports, separation distances, and drainage that carries a spill away from equipment. Active protection must operate on demand: deluge, sprinkler and water spray systems, foam pourers on tanks, firewater pumps and ring mains. Fixed gas and flame detection linked to emergency shutdown matters most because it buys the time to isolate and depressurise before ignition - something passive protection can never do.

What must a major accident emergency plan contain, and how often is it tested?

Named roles and a clear person in command, alarm and communication arrangements, muster points, escape routes and a method of accounting for everyone on site, actions to contain and control the incident, arrangements with the emergency services, provision for informing the public and the authorities, and plans for restoration and clean-up afterwards. Under the COMAH Regulations upper-tier operators prepare the on-site plan while the local authority prepares the off-site plan; both must be reviewed and tested at intervals not exceeding three years.

What is the priority of on-site emergency response once a process fire has started?

Stopping escalation, because escalation is what turns one leak into a disaster: radiant heat and flame impingement weaken adjacent vessels and pipework until they fail and add their own inventory. So the response sequence is detect, raise the alarm and muster, shut down and isolate to break the plant into small inventories, depressurise to flare, then cool exposed plant with water while fighting the fire. Piper Alpha escalated beyond control largely because connected platforms kept feeding hydrocarbon to the fire after it started.

Frequently Asked Questions

How is the NEBOSH HSE Certificate in Process Safety Management assessed?

The qualification has one unit, PSM1, assessed by a single 90-minute online multiple-choice examination. The paper has 40 questions, 10 of which are extended scenario questions distributed through the paper. Each question carries one mark and offers one correct and three incorrect responses. It is closed book, all questions are compulsory, and the paper covers the whole syllabus with at least one question per element. Assessments run monthly and are available for a 24-hour window; you can start at any point in that window but then have 90 minutes to finish.

What is the NEBOSH PSM pass mark, and is there a Merit or Distinction grade?

You need 60% or higher, which is 24 of the 40 marks. NEBOSH grades Unit PSM1 as Pass (60% or higher) or Refer (59% or lower) - there is no Credit, Merit or Distinction grade for this qualification, and the qualification grade comes solely from PSM1. Results are issued within 15 working days of the assessment, and the qualification parchment is normally issued within 20 working days of a confirmed pass.

What is the NEBOSH PSM pass rate?

NEBOSH does not publish a pass rate for the HSE Certificate in Process Safety Management, so any percentage you see quoted by a training provider is that provider's own cohort figure rather than an official statistic. Treat provider pass-rate marketing with caution and judge your readiness against the syllabus instead: the 40-question paper samples all four elements, so weak coverage of any element is what usually causes a referral.

Can I self-study for the NEBOSH PSM certificate?

No. NEBOSH qualifications cannot be self-studied or self-registered. You must enrol with a NEBOSH-accredited Learning Partner, who delivers the course and registers you for the PSM1 assessment. Registration can be made any time before the course and up to 10 working days before the assessment date. Free resources like these flashcards are revision support alongside an accredited course, not a substitute for it.

What happens if I am referred (fail) in Unit PSM1?

A result of 59% or lower is a 'Refer'. You may re-sit the unit, and NEBOSH sets no limit on the number of re-sits and publishes no mandatory waiting period between attempts. In practice the constraint is the assessment calendar: sittings are monthly and your Learning Partner must register you at least 10 working days before the date you want. Your Learning Partner will support you after a referral and book the next available sitting.

What does the PSM1 syllabus cover, and how is it weighted?

Unit PSM1 has four elements. NEBOSH sets minimum tuition hours rather than percentage weights: Element 1 Process safety leadership (4 hours), Element 2 Management of process risk (9 hours), Element 3 Process safety hazard control (10 hours), Element 4 Fire and explosion protection (5 hours) - 28 taught hours in total. Elements 2 and 3 together account for roughly two-thirds of the taught time, so risk management techniques, asset integrity, permit-to-work, operating limits, dangerous substances and reactions deserve the bulk of your revision.

How long does the NEBOSH PSM qualification take to study?

NEBOSH sets 49.5 notional learning hours: a minimum of 28 taught hours, approximately 20 hours of private study, and 1.5 hours for the assessment. Classroom and virtual courses typically run over four days with the exam shortly afterwards; eLearning routes spread the same content over weeks or months. The qualification is credit rated by Qualifications Scotland at SCQF Level 7 with 5 credits, comparable to RQF Level 4.

Does the NEBOSH PSM certificate expire?

The NEBOSH learner syllabus guide sets out no expiry date and no renewal or re-certification requirement for this qualification: once you pass PSM1 a parchment is issued and the qualification stands. That is not the same as staying current - process safety guidance, standards and your own plant change, so employers on major hazard sites normally expect ongoing refresher training and evidence of maintained competence regardless of when you passed.

Same family resources

Explore More NEBOSH Health and Safety Qualifications

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.

More From This Family

Videos and articles for deeper review.