12.2 HAZOP Methodology
Key Takeaways
- HAZOP is a structured qualitative process hazard analysis that systematically searches for deviations from design intent
- The study divides the process into nodes; each node has a clear design intent (what the system is supposed to do)
- Guide words (No/None, More, Less, Reverse, As well as, Part of, Other than) combine with parameters to form deviations
- For each credible deviation, teams identify causes, consequences, safeguards, and recommendations
- HAZOP is not by itself a quantitative risk assessment or a substitute for detailed relief sizing calculations
Purpose of HAZOP
HAZOP (Hazard and Operability Study) is a structured, team-based, qualitative method to identify how a process can deviate from design intent, what hazards and operability problems that creates, and whether existing safeguards are adequate. It is widely used in oil & gas, petrochemicals, LNG-related facilities, and specialty chemicals—exactly the industrial context where Qatar-licensed chemical engineers work.
HAZOP answers questions such as:
- What if flow is less than design?
- What if temperature is higher than intended?
- What if the wrong material is present?
- What if a valve fails closed or open?
The method is systematic: it forces the team to consider deviations they might miss in an unstructured brainstorm. It is multidisciplinary: process, operations, instrumentation, mechanical, and safety perspectives reduce blind spots.
When HAZOP is applied
| Timing | Typical use |
|---|---|
| Design (FEED/detailed) | Identify hazards before construction; influence layout, SIS, relief, and procedures |
| Before major modifications | Support MOC with a fresh look at changed nodes |
| Periodic revalidation | Capture operational learning and updated process knowledge |
| After incidents | Focused re-HAZOP of affected systems |
HAZOP depends on adequate process knowledge: reasonably complete P&IDs, material balances, operating limits, and chemical properties. Performing HAZOP on drawings that do not match the field is worse than useless—it creates false confidence.
Operability as well as hazard
The “O” in HAZOP matters. Teams also capture operability issues: difficulty starting up, product quality upsets, fouling, sampling problems, and control difficulties that may not immediately kill people but can drive unsafe workarounds later.
Nodes and design intent
A node is a section of the process studied as a unit—often a line segment between equipment items, a vessel with its associated controls, a reactor system, or a transfer operation. Node selection balances granularity: too large and deviations become vague; too small and the study never finishes.
Design intent
For each node the scribe/facilitator records design intent: a clear statement of what that node is supposed to achieve under normal operation. Examples:
- “Transfer crude from storage T-101 to desalter at 50 m³/h and 40 °C.”
- “Cool reactor effluent from 180 °C to 60 °C in E-201 using cooling water.”
- “Maintain reflux drum level between 40% and 60% while supplying reflux and distillate.”
Design intent is the reference against which guide words create deviations. Without a clear intent statement, “More flow” is meaningless.
Parameters commonly paired with guide words
| Parameter | Typical meaning in process plants |
|---|---|
| Flow | Mass/volume flow rate in a line or to equipment |
| Pressure | Line or vessel pressure relative to design intent |
| Temperature | Stream or equipment temperature |
| Level | Liquid inventory in vessels/drums |
| Composition | Component fractions, impurities, phases |
| Reaction | Rate, conversion, side reactions (reactors) |
| Time / sequence | Batch timing, order of addition |
| Mixing / agitation | Homogeneity, dead zones |
Continuous plants emphasize flow/pressure/temperature/level/composition. Batch plants add sequence and charge deviations.
Team roles (awareness)
- Facilitator: keeps guide-word discipline, prevents endless storytelling without conclusions.
- Scribe: records causes, consequences, safeguards, actions.
- Process engineer: design intent, chemistry, balances.
- Operations: realistic causes and human factors.
- I&C / mechanical: control, SIS, equipment failure modes.
Exam stems may ask who must understand design intent—answer: the HAZOP team, with the process representation clear on drawings.
Guide words and deviations
A deviation is formed by combining a guide word with a parameter:
Deviation = Guide word + Parameter
Example: More + Temperature → higher temperature than design intent
Core guide words you should know
| Guide word | Meaning | Example deviation |
|---|---|---|
| No / None | Complete negation of intent | No flow in a feed line |
| More | Quantitative increase | More pressure in a vessel |
| Less | Quantitative decrease | Less cooling medium flow |
| As well as | Qualitative increase / additional activity | Additional component present (contamination) |
| Part of | Qualitative decrease / incomplete intent | Only partial composition of intended mixture |
| Reverse | Logical opposite of intent | Reverse flow in a pump discharge line |
| Other than / Instead | Complete substitution | Wrong material transferred |
| Early / Late / Before / After | Timing (often batch) | Reactant added before solvent |
Plants sometimes add Where else for misdirected flow. You do not need every local variant; you need the logic: guide words force structured imagination.
Credibility filter
Not every grammatical deviation is studied in depth. Teams discard non-credible combinations quickly (for example, “reverse temperature” without meaning) and spend time on deviations that can realistically occur given equipment and human error.
Mini examples for exam speed
- No flow to a furnace → possible tube overheating if fuel continues (consequence depends on interlocks).
- More level in a knockout drum → liquid carryover to compressor (damage, loss of containment risk).
- Less temperature in a reactor needing activation energy → incomplete reaction, accumulation of reactants, possible later runaway when heated.
- Reverse flow through a check-valve failure → contamination of upstream system or pump damage.
- Other than — truck unloads caustic into acid tank → violent reaction, toxic mist.
Each example shows why HAZOP is not a random safety chat: the guide word points to a specific physical wrongness.
Causes → consequences → safeguards → recommendations
For each credible deviation, the team walks a standard logic chain:
1) Causes
What could create the deviation? Typical cause categories:
- Equipment failure (pump trip, control valve fails open/closed, heat-exchanger leak)
- Utility failure (power, cooling water, instrument air, inert gas)
- Human error (wrong valve, wrong setpoint, skipped step)
- External events (blocked outlet, fire exposure)
- Upstream/downstream process upsets
List multiple independent causes when they matter; do not stop at the first idea.
2) Consequences
Assuming the deviation occurs and propagates, what happens to people, environment, assets, and production? Good consequence statements are specific: “overpressure of V-201 to rupture of weak joint leading to flammable release and possible jet fire,” not merely “bad” or “unsafe.”
Consider domino effects: release → fire → BLEVE of adjacent vessel; toxic release → impaired evacuation.
3) Safeguards (existing)
Safeguards are existing measures that prevent the cause, detect the deviation, or mitigate the consequence:
| Type | Examples |
|---|---|
| Inherent / passive | Lower inventory, dike, blast wall, elevation |
| Active engineered | PSV, SIS trip, emergency isolation valve, deluge |
| Basic process control | Level controller maintaining setpoint |
| Alarms + operator response | High-level alarm with defined response time |
| Procedural | Checklist, permit, two-person verification |
Critical exam point: BPCS (basic process control system) and operator response are real safeguards but are not fully independent of common human/control failures in the way a dedicated SIS or relief device may be. Later LOPA thinking makes independence explicit; HAZOP at least should not double-count the same fragile layer many times without thought.
4) Recommendations (actions)
If consequences are severe and safeguards weak or missing, the team writes recommendations: add independent high-level trip, resize relief, improve MOC, add check valve, revise procedure, improve detection. Actions need owners and tracking outside the meeting.
Recording quality
Weak HAZOP records say “operator care” as the only safeguard for a catastrophic scenario. Strong records identify engineered barriers and clear action items. For UPDA, prefer answers that recognize structured documentation of causes, consequences, safeguards, and recommendations.
What HAZOP is NOT
Misconceptions produce wrong MCQ choices:
| Claim | Reality |
|---|---|
| “HAZOP is a full quantitative risk assessment (QRA)” | False. HAZOP is primarily qualitative (sometimes semi-quantitative ranking). QRA uses frequencies and consequence modeling numerically. |
| “HAZOP replaces relief valve sizing” | False. HAZOP may identify overpressure scenarios that drive relief design; API/ISO engineering calculations still size devices. |
| “HAZOP guarantees no accidents” | False. It reduces unrecognized hazards; residual risk remains; implementation of actions is essential. |
| “HAZOP is only for new greenfield plants” | False. Used for modifications, revalidations, and brownfield units. |
| “One senior engineer alone is a HAZOP” | False. Method assumes team challenge of assumptions. |
| “HAZOP and LOPA are identical” | False. LOPA is a simplified risk-order method using independent protection layers after scenarios are defined; HAZOP is a broader deviation search. |
Relationship to other PHA methods
- What-If / checklist: less structured than HAZOP; faster for simple systems.
- FMEA: focuses on component failure modes.
- Fault tree / event tree: more logical/quantitative structures for selected scenarios.
- LOPA: often follows scenario identification (from HAZOP or other PHA) to test whether risk is tolerable with existing IPLs.
Common failure modes of the HAZOP process itself
- Studying nodes with outdated P&IDs
- Skipping “boring” utilities that actually cause major upsets
- Treating every alarm as an independent strong safeguard
- Closing actions without verification (paper HAZOP)
- Facilitator bias shutting down operations experience
Section takeaway
HAZOP systematically applies guide words to parameters on defined nodes with clear design intent, then documents causes, consequences, safeguards, and recommendations. It is a cornerstone qualitative PHA tool for chemical engineers—but it is not quantitative risk analysis alone, and it does not replace detailed safety-system engineering. Section 12.3 connects identified scenarios to LOPA, relief systems, and emergency response.
In HAZOP methodology, what is the primary purpose of defining design intent for each node?
Which option correctly pairs a HAZOP guide word with a meaningful process deviation?
Which statement correctly describes a limitation of HAZOP?