3.3 Safety-Critical Elements (SCEs) & Performance Standards

Key Takeaways

  • Safety-Critical Elements (SCEs) are structures, plant items, or software whose failure could cause or contribute to a Major Accident Hazard (MAH), or whose purpose is to prevent or mitigate MAHs.
  • Performance Standards define mandatory, quantifiable criteria for SCEs using the FARSI framework: Functionality, Availability, Reliability, Survivability, and Interdependency.
  • Survivability specifies that SCEs must remain operational under major accident conditions, such as surviving hydrocarbon jet fires (per ISO 22899) or blast overpressure waves.
  • Independent Verification Bodies (IVBs) conduct objective third-party audits and field examinations to verify compliance with Written Schemes of Verification (WSVs).
  • SCE impairments require formal deferral management protocols, immediate senior management notification, and the implementation of temporary compensatory risk controls.
Last updated: July 2026

3.3 Safety-Critical Elements (SCEs) & Performance Standards

Defining Safety-Critical Elements (SCEs)

In major hazard facilities—such as offshore oil platforms, refineries, chemical plants, and gas processing terminals—certain equipment items play a vital role in preventing catastrophic events. These components are designated as Safety-Critical Elements (SCEs).

Under regulations such as the UK Offshore Installations (Safety Case) Regulations and international process safety standards, an SCE is defined as:

Any part of an installation, structure, plant, or computer program (including safety software) whose failure could cause or substantially contribute to a Major Accident Hazard (MAH), or the purpose of which is to prevent, limit, or mitigate the effects of an MAH.

Major Accident Hazards (MAHs) vs. Operational Hazards

An MAH is an uncontained release of hazardous substances, major fire, explosion, or structural collapse that could result in multiple fatalities, severe environmental damage, or total asset loss.

SCEs are strictly differentiated from general operational equipment. For example, a utility cooling water pump whose breakdown merely stops production is an operational reliability item. Conversely, an Emergency Shutdown Valve (ESDV) that isolates a 50-tonne hydrocarbon inventory during a pipe rupture is an SCE.

                            MAJOR ACCIDENT HAZARDS (MAHs)
                                          │
                   ┌──────────────────────┴──────────────────────┐
                   ▼                                             ▼
       PREVENTIVE SCEs (Prevent Release)            MITIGATIVE SCEs (Limit Consequence)
       ├────────────────────────────────┤          ├──────────────────────────────────┤
       │ • Pressure Relief Valves (PRV) │          │ • Deluge & Firewater Systems     │
       │ • Emergency Shutdown (ESDV)    │          │ • Flammable & Toxic Gas Detectors│
       │ • High Integrity Protection    │          │ • Passive Fire Protection (PFP)  │
       │   Systems (HIPPS)              │          │ • Temporary Refuges & Blast Walls│
       └────────────────────────────────┘          └──────────────────────────────────┘

Core Categories of SCEs

  1. Primary Containment Barriers: Pressure vessels, reactors, storage tanks, and high-pressure process piping.
  2. Process Control & Protection Systems:
    • High Integrity Pressure Protection Systems (HIPPS).
    • Pressure Relief Valves (PRVs) and bursting discs.
    • Emergency Shutdown (ESD) logic solvers and isolation valves.
  3. Detection Systems: Flammable gas detectors (infrared/catalytic), toxic gas detectors ($H_2S$), optical flame detectors (UV/IR), and smoke detectors.
  4. Mitigation & Suppression Systems: Firewater pumps, deluge systems, foam monitors, passive fire protection (PFP coatings, fire blankets).
  5. Structural & Environmental Protection: Offshore jacket structures, blast walls, firewalls, bund walls, dynamic positioning systems.
  6. Life Safety & Evacuation Systems: Temporary Refuges (TR), HVAC positive-pressure dampers, emergency lighting, lifeboats (TEMPSC), escape routes.

The FARSI Criteria for Performance Standards

Identifying an SCE is only the first step. To ensure an SCE will perform reliably when called upon, engineers establish an explicit, quantifiable Performance Standard.

A Performance Standard defines the minimum standard of performance required of an SCE. To be complete and robust, every Performance Standard must be evaluated against the FARSI criteria:

 ┌───────────────────────────────────────────────────────────────────────────┐
 │                         FARSI PERFORMANCE CRITERIA                        │
 └─────────────────────────────────────┬─────────────────────────────────────┘
                                       │
        ┌──────────────┬───────────────┼───────────────┬──────────────┐
        ▼              ▼               ▼               ▼              ▼
  FUNCTIONALITY   AVAILABILITY    RELIABILITY    SURVIVABILITY INTERDEPENDENCE
  (What task?)   (Ready when?)   (How failure-   (Survive MAH    (What support
                                     free?)       environment?)    needed?)

1. Functionality (F)

Defines the precise physical action or duty the SCE must perform.

  • Example: An ESDV on a crude oil riser must achieve tight shut-off (ISO 5208 Rate A leakage limit) and close fully within 15 seconds of signal receipt against a differential pressure of 100 bar.

2. Availability (A)

Defines the percentage of time the SCE must be fully operational and ready to respond.

  • Example: The main firewater pumping system must maintain 99.5% operational availability, meaning scheduled maintenance downtime cannot exceed 44 hours per calendar year.

3. Reliability (R)

Defines the maximum allowable probability of failure on demand (PFD) or failure rate. Reliability is frequently defined via Safety Integrity Levels (SIL 1 to SIL 4 per IEC 61511).

  • Example: A High Integrity Pressure Protection System (HIPPS) protecting a low-pressure vessel must meet SIL 3 performance, corresponding to a $ ext{PFD} < 10^{-3}$ (less than 1 failure in 1,000 demands).

4. Survivability (S)

Defines the hostile conditions created by the Major Accident Hazard (heat flux, explosion overpressure, cryogenic spill, acid gas) that the SCE must withstand without losing its safety function.

  • Example: Emergency shutdown valve actuators and signal cables located within a hydrocarbon process module must feature Passive Fire Protection (PFP) certified to survive a $200 ext{ kW/m}^2$ jet fire for 60 minutes (per ISO 22899-1) and a 0.5 bar blast overpressure wave.

5. Interdependency (I)

Identifies all supporting utilities and secondary systems required for the primary SCE to function.

  • Example: An ESDV depends on:
    • Reliable instrument air supply (or hydraulic accumulator fluid).
    • 24V DC Uninterruptible Power Supply (UPS) battery back-up.
    • Inputs from the ESD Safety Logic Solver.
    • Fire-rated signal cabling.

Verification Schemes & Independent Verification Bodies (IVBs)

To provide independent assurance that SCEs conform to their Performance Standards, major hazard facilities implement a Written Scheme of Verification (WSV) enforced by an Independent Verification Body (IVB).

Role of the Independent Verification Body (IVB)

An IVB is a qualified, independent third-party organization (such as Lloyd's Register, DNV, or Bureau Veritas). The IVB operates independently of site operations, commercial pressures, and maintenance teams.

┌────────────────────────┐      Independent Audit &      ┌────────────────────────┐
│  OPERATING COMPANY     │ ────── Field Examination ───► │ INDEPENDENT VERIFIER   │
│  • Owns Site Safety    │                               │  (IVB: DNV/Lloyds)     │
│  • Manages SCEs        │ ◄───── Issues Statements ──── │  • Audits Maintenance  │
│  • Executes PMs        │        of Compliance          │  • Witnesses Proof Test│
└────────────────────────┘                               └────────────────────────┘

The Verification Workflow

  1. SCE Identification: The operating company compiles a comprehensive SCE Register derived from HAZOP, LOPA, and Safety Case analyses.
  2. Performance Standard Drafting: Explicit FARSI standards are established for every SCE group.
  3. Written Scheme of Verification (WSV): The IVB reviews and approves the WSV, which specifies:
    • Which SCE components must be inspected.
    • The examination methods (physical inspection, witnessing proof tests, record auditing).
    • The frequency of verification activities.
  4. Independent Examinations & Auditing: IVB surveyors visit the facility to:
    • Witness live proof testing of ESDVs, HIPPS, and deluge systems.
    • Audit maintenance records, calibration logs, and test certificates.
    • Conduct physical site walkdowns to inspect PFP coatings, structural integrity, and blast doors.
  5. Reporting & Non-Conformance Management: The IVB issues formal reports. If an SCE fails to meet its Performance Standard, a Non-Conformance Report (NCR) is raised, requiring urgent site remediation.

SCE Impairment and Deferral Management

When an SCE is damaged, degraded, taken offline for maintenance, or fails a proof test, it is classified as Impaired. Operating a major hazard facility with impaired SCEs significantly increases catastrophic risk.

Impairment Management Protocols

  1. Immediate Risk Assessment: When an SCE becomes impaired (e.g., a gas detector fails calibration or a firewater pump trips), operations personnel must immediately assess the impact on plant safety.
  2. Compensatory Control Implementation: Temporary risk mitigations must be applied immediately:
    • Impaired Firewater Pump: Connect temporary diesel driven trailer pumps to the ring main.
    • Impaired Gas Detector: Position portable gas detectors and post dedicated gas safety watches.
    • Impaired Deluge Valve: Place a dedicated operator at the manual bypass valve.
  3. Formal Deferral Authorization: If safety-critical maintenance cannot be completed within its scheduled window, a formal SCE Maintenance Deferral process must be invoked:
    • Requires formal Risk Assessment (e.g., Bow-Tie or Management of Change review).
    • Approval required from senior operational leaders (e.g., Site Operations Manager, Asset Integrity Manager).
    • Time-bound authorization with strict re-evaluation dates.
  4. Senior Management Notification: Accumulation of impaired SCEs must be displayed transparently on a central Safety-Critical Impairment Panel in the control room and reported to board-level safety committees.
Test Your Knowledge

What is the primary definition of a Safety-Critical Element (SCE)?

A
B
C
D
Test Your Knowledge

In the FARSI framework for SCE Performance Standards, what does the 'S' stand for?

A
B
C
D
Test Your Knowledge

What mandatory action must be taken immediately when a Safety-Critical Element becomes impaired?

A
B
C
D