Skip to content

HAZOP — Hazard and Operability Study

≈ 22 min read · 4,433 words

When the kitchen sink overflows, it is because something deviated from the intended operation: more water came in than went out. In a chemical plant the same logic applies, only the stakes are different: if more goes into a vessel than comes out, the result is not a puddle but overpressure. HAZOP asks this question in a disciplined way, for every pipe run and every parameter: what if there is more? less? the other way round?

HAZOP is a structured, team-based process safety study that works through every meaningful process deviation of a plant, node by node.

It breaks the plant into manageable sections (nodes), then forms the deviations as the product of standard guide words (no, less, more, reverse, other than) and process parameters (flow, pressure, temperature, level, composition, phase). For every deviation it works out the cause, the consequence and the existing layers of protection (safeguards). Where the residual risk is too high, it formulates a recommendation (or action) with an owner and a deadline.

hazop-folyamat-en.svg Figure 1 — the logical chain of HAZOP: node → parameter → guide word → deviation → cause → consequence → safeguard → recommendation.

This article is for those who meet hazard analysis in practice as well: plant manager · shift supervisor · process engineer · process safety engineer · HSE specialist · instrument and control technician · project engineer · reliability engineer.

After reading this article you will be able to:

  • break a P&ID down into nodes, and justify where you draw the boundaries;
  • form meaningful deviations from the parameter × guide word matrix;
  • distinguish a safeguard from an independent protection layer (IPL), and assign a typical order of magnitude of risk reduction to each;
  • say when a HAZOP is mandatory, and at what cadence it must be revalidated;
  • recognize what HAZOP does not examine, and which method to switch to in that case.
  • What: a structured, team-based risk analysis that examines every meaningful process deviation within a P&ID-based node, using guide word + parameter logic.
  • Origin: developed at the chemical company ICI around 1970; today one of the most widespread methods in the chemical and oil/gas industries.
  • Logic: node → parameter → guide word → deviation → cause → consequence → safeguard → recommendation. Filling in the whole matrix guarantees that not a single meaningful deviation is left out.
  • When: primarily in the basic design (basic / FEED) phase; in addition, at every significant modification (revamp, MOC), and recurrently, typically in a cycle of at most five years.
  • Who: a multidisciplinary team (process, operations, maintenance, instrumentation, project, safety), an independent chairman and a scribe.
  • Output: a worksheet per node + a tracked action list + input to the SIL analysis and to LOPA.
  • Limit: a qualitative method that may underestimate the risk, does not examine combinations of causes and does not prioritize; this is why we pair it with SIL/LOPA/FTA analysis.

An unexamined deviation does not stay a theoretical gap: a scenario left out of the design sooner or later shows up during operation, and by then without a layer of protection. The stake of HAZOP is that it breaks the chain while still on the drawing board, where writing in a check valve or an alarm is a few lines in the worksheet.

hazop-tet-lanc-en.svg Figure 2 — escalation of a deviation left out of the study. HAZOP is cheapest at the start of the chain, in the design phase.

The further the chain slides, the more expensive it is to bring back: in the design phase a recommendation is a drawing change, during operation it is already a modification, a shutdown and a permitting process.

What is HAZOP, and where does it come from?

Section titled “What is HAZOP, and where does it come from?”

HAZOP is short for “Hazard and Operability”. The technique was introduced by the engineers of the chemical company ICI around 1970, specifically to prevent process deviations. The framework works through how a process can deviate from the intended (design intent) operation, and what safety and operability consequences this can have.

HAZOP is a member of the Process Hazard Analysis (PHA) family of methods; related procedures are Preliminary Hazard Analysis, HAZID (Hazard Identification) and FMEA. Their logic is similar, the difference is in the focus: HAZOP combs through the P&ID by parameter deviation, so it concentrates on the process logic, while FMEA concentrates on specific equipment failures.

Two timing patterns come up again and again in project practice:

  • Pre-HAZOP: carried out early in the project, at the first drawing issue, so that the significant hazards and operability problems are caught early. In a typical pre-HAZOP only the new or modified parts of the revamp are examined, and the full HAZOP is deferred to the detailed design phase.
  • Basic HAZOP (revamp): its purpose is that the drawings and process specifications be detailed enough for an EPC contractor to give a fixed lump sum price; later, in the EPC phase, a detailed HAZOP follows on the final drawings.

How does HAZOP identify process safety risks?

Section titled “How does HAZOP identify process safety risks?”

HAZOP finds risk in that it does not expect completeness from brainstorming, but from filling in a matrix: it applies all the guide words to every parameter of every node, and whichever combination has a meaningful physical interpretation is taken through the cause–consequence–safeguard chain.

1. Breaking the system into nodes. First we define the system and the subsystems, then designate nodes (study nodes). A node is a manageable, well-delimited section of the P&ID: a set of equipment groups, valves, alarms and pipe runs. The nodes are marked in colour on the drawings, and this becomes the reference of the worksheet. In plant practice the granularity looks like this: one node may be the “feed and vaporizer”, within which the vaporizer is a sub-node; another may be the “air blower, flue gas fan, preheater and stack”.

2. Parameter + guide word → deviation. For every node we go through the process parameters, typically flow, pressure, temperature, level, composition, phase, and apply the standard guide words to each.

Guide word Meaning
None / No The given parameter is absent (e.g. no flow)
Less Quantitative decrease (low pressure/flow/level)
More Quantitative increase (high pressure/temperature)
Part of Qualitative decrease (missing component)
As well as Qualitative increase (extra phase, contamination, carry-over)
Reverse The opposite of the usual direction (backflow)
Other than Complete substitution (wrong material, misdirected flow)

hazop-matrix-en.svg Figure 3 — the parameter × guide word matrix. The product gives the deviations to be examined; the meaningless cells are closed off by the team with a justification.

3. Cause → consequence → safeguard → recommendation. For every meaningful deviation the team goes through the initiating cause (control valve failure, pump trip, operator error, spurious trip, plugged filter, heat exchanger leak), the consequence (overpressure, loss of containment, fire and explosion, catalyst damage, lost production), and then the existing protection.

A safeguard is a device working independently that takes the process to a safe state, or draws the operator’s attention to the unsafe state. Its types are summarized in Figure 4. If the residual risk is too high, or a protection is missing, a recommendation is raised: a new alarm, a second check valve, moving a switch into a SIF, a review of the material selection.

hazop-safeguard-en.svg Figure 4 — safeguard types by the nature of the action, with typical orders of magnitude of risk reduction.

4. Risk ranking (optional, with care). Some teams use a risk matrix for the estimation and the prioritization. This is not always effective, because thanks to the control system and the layers of protection a catastrophic scenario rarely surfaces in a HAZOP. In basic-level HAZOPs, therefore, the team often decides on the acceptability of the risk itself, and the matrix is brought out only in doubtful cases.

5. Documentation and follow-up. Every deviation goes into the node worksheet. The output is a recommendation tracking sheet, which, beyond the referenced safeguard identifier, carries the priority, the owner, the status, the degree of completion, the planned and actual dates, the way it was closed out, and the signature of the preparer, the checker and the approver. The skeleton of the report: summary, introduction, scope, team composition, plant and node description, conclusion, with process flow diagrams, node-marked drawings and worksheets as appendices.

HAZOP is one of the pillars of process safety in the process and chemical industries, because in these plants the typical consequences are loss of containment, fire, explosion, toxic release and environmental damage. The table below shows the anonymized skeleton of real worksheet rows, and at the same time teaches the shape of the worksheet:

Deviation Cause Consequence Safeguard
More + temperature (vaporizer drum) pressure controller sticks open overheating, pressure rise, drum rupture, fire and explosion high temperature alarm · PSV · at high pressure a SIF closes the shutdown valve
Reverse + flow feed stopped, downstream equipment under pressure backflow, mixing check valve on the feed line
As well as + composition (air ingress) compressor backpressure lets air into the hydrocarbon system explosive mixture above the auto-ignition temperature check valve at the tie-in point
Other than + flow (drain branch) the operator leaves the manual drain valve open hydrogen or C3/C4 gas gets into the oily-water system and from there into the open air: fire and explosion hazard duplicated manual isolation valve · gas detector (LEL 20%) · routing to flare · hydrogen is lighter than air, so it dilutes quickly
As well as + composition (hydrotreater train) ammonium salt deposition plugging, corrosion wash water injection · rapid depressurization at the hot bed of the reactor

HAZOP also fits into the legal and standards framework:

  • The Seveso III Directive (2012/18/EU) requires the systematic identification of hazards and the analysis of major accident scenarios; HAZOP is one of the recognized tools of the safety report.
  • Within the framework of IEC 61511 (functional safety tailored to the process industry) and IEC 61508, HAZOP is typically the process from which the necessary safety instrumented functions (SIF) and their SIL levels derive; the need for protection identified in the HAZOP is quantified by the follow-on SIL/LOPA analysis.
  • The ALARP (As Low As Reasonably Practicable) principle gives the decision philosophy: the risk must be reduced to the lowest reasonably practicable level.
  • ISO 45001 and process safety management (PSM) systems require systematic hazard identification and risk assessment, leaving the choice of method to the organization. For technological risks, process industry practice typically designates HAZOP, or HAZID, as the accepted method, and makes it a recurring element of management of change (MOC).

Introducing HAZOP at a plant or on a project can be carried through in seven steps. The order of the steps is fixed: without a scope there is nothing to examine, and without an up-to-date drawing it is not worth starting.

  1. Fix the scope and the objective. Write down what you are examining (the whole plant or only the modified parts), which hazards (flammability, explosivity, toxicity, release of high-energy fluid), which operating modes (start-up, normal operation, shutdown) and which external events (typically utility failure). Fix the consequence categories as well: safety and health, financial and operability, environment.
  2. Assemble the documentation. Up-to-date P&IDs (this is the main working tool), process flow diagrams, process description, equipment data, and where available, incident history. It is the HAZOP leader’s responsibility that the study does not start on an obsolete drawing. If a device is not yet on the drawing but the specialist confirms it for the next version, that must be recorded as a recommendation.
  3. Call the team together. Process, operations, maintenance, instrumentation, project, safety, and where relevant, the representative of the technology owner (licensor). Separate roles are the neutral chairman (who has no stake in the design) and the scribe.
  4. Break the drawing into nodes. Designate the manageable sections, and colour them in on the marked-up drawing.
  5. Run the workshop. Proceed node by node, in the parameter–guide word matrix. A HAZOP of a whole process typically takes a week or more. The leader’s greatest challenge is keeping the specialists engaged: if there is a substitution mid-way, the assumptions have to be explained to the new member all over again.
  6. Assign and close out the actions. Every recommendation has an owner, a deadline and a way of being closed, and after the HAZOP you must communicate the new process risk to those concerned in operations and maintenance.
  7. Carry it over into the related analyses. Hand the protection needs over to the SIL analysis and to LOPA; where a combined scenario or a probability is needed, an FTA must be carried out.

The quality and maturity of a HAZOP is tracked by a few practical indicators, and the rhythm of revalidation is fixed by a rule, not by feel.

  • Action close-out rate: closed actions / all HAZOP actions × 100%. Open actions are the carriers of the residual risk: a revamp project typically generates a few dozen actions, and every one of them has to be closed.
  • Coverage: every node × every parameter × every guide word examined. The entry “not relevant, no scenario” is also evidence of coverage.
  • Safeguard maturity: does every critical deviation have an independent layer of protection; how many “Proposed” safeguards stand next to the “Exists” ones.
  • Semi-quantitative risk ranking: RRF = 1 / PFD, where PFD is the probability of failure on demand of the layer of protection. Comparing the required and the achieved RRF shows whether a risk gap remains.
  • Revalidation cadence: process industry HSE standards typically prescribe a mandatory HAZID/HAZOP analysis for every operational factor in a cycle of at most five years, and in the case of a significant technological modification, before start-up. The analysis needs must be reviewed and ranked annually, and the approved actions go into the HSE action plan. Rule of thumb for choosing a method: HAZID for those factors that do not yet have a HAZOP, or if only a minor change has been made to the technological process.

Typical risk reduction factors. The orders of magnitude of a plant-specific IPL rule set look like this:

Layer of protection Typical RRF
Pressure relief valve or rupture disc 100
Dike, fireproof coating 100
SIF in an independent fail-safe PLC, 2-out-of-3 voting (SIL 2) 100
SIF in an independent fail-safe PLC, 1-out-of-1 (SIL 1) 10
Dual check valves of different operating principles 50
Independent instrument in the basic control system (BPCS/DCS) 5
Single check valve 5
Operator response to an independent alarm 10

The typical failures of a HAZOP stem not from the methodology but from a lack of discipline. Each of the six mistakes below traces back to one of the claims made earlier in this article.

  • Starting with an obsolete drawing. A HAZOP is only as good as the drawing it is based on: without an up-to-date P&ID the study gives a false sense of security. Instead: restore the documentation, then hold the workshop.
  • Underestimating the risk. HAZOP is qualitative, so a hazard can be undervalued and an important recommendation can be left out. Instead: take the critical deviations into LOPA/SIL.
  • Forcing the risk matrix on mechanically. Because of the existing control system most cases will come out “moderate”, so the matrix misleads and produces many unprioritized recommendations that are then dropped on cost grounds. Instead: let the catastrophic scenario be handled by PHA and consequence analysis, and the layers of protection by the SIL analysis.
  • Missing detail on equipment failures. HAZOP does not give a device-specific preventive action. Instead: FMEA or reliability analysis on the initiating cause (a recurring failure of a filter is not answered by the downstream control valve).
  • Ignoring the knock-on effect of the modification. In a revamp or MOC HAZOP the effects reaching across node boundaries must be asked about as a separate question: how does the change affect the other subsystems?
  • Poor logistics and team continuity. A change of members restarts the clarification of the assumptions. Instead: named participation for the whole workshop.

When NOT to use it (the limits of the method)

Section titled “When NOT to use it (the limits of the method)”

HAZOP is strong, but it is not a tool for everything. The most important limit is that it does not examine combinations of causes: the method assumes that a single cause triggers the deviation, so the probability of the deviation occurring cannot be learned from the HAZOP.

  • Need a combined scenario or a probability? Then FTA is the right tool: the HAZOP deviation becomes the top event, the safeguards proposed by the HAZOP can be fed back into the tree, and the probability can be recalculated.
  • Need a certified integrity level? HAZOP does not assign the SIL. It identifies the need for protection; the level is assigned by LOPA and SIL analysis.
  • Is the root cause of an equipment failure the question? FMEA and reliability analysis give the device-specific preventive action.

The scope of a HAZOP is deliberately narrowed. A typical study explicitly excludes the following, because they are demonstrated elsewhere:

  • specifications (taken as separately verified);
  • construction and mechanical integrity (a pipe rupture or a major equipment failure cannot be a scenario cause);
  • maintenance (poor maintenance cannot be a scenario cause);
  • heat exchanger tube rupture (excluded on the grounds of vibration-free design);
  • separate treatment of control valve bypasses (the Cv of the bypass is not greater than that of the control valve);
  • closed valves and figure-8 blinds (assumed in the position shown on the drawing);
  • standards and code review (not part of the study).

Two strengths of the method nevertheless make it a basic tool of the process industry: it is a well-defined tool that covers every process, system and subsystem of the P&ID, and it is suited to examining what effect a process deviation has on the other subsystems.

Which tool is strongest in which life-cycle phase?

Asset phase Recommended method
Conceptual design PHA
Design subsystem PHA, DFMEA
Basic project (basic / FEED) HAZOP, alongside FMEA/FMECA, LOPA, SIL, ETA
Operation PHA, workplace PHA, LOPA, SIL
Decommissioning PHA
  • Completeness comes from the matrix, not from brainstorming: if a parameter × guide word cell stays empty without a justification, risk may remain there.
  • The drawing is the basis of the method: a HAZOP done on an obsolete P&ID gives a false sense of security.
  • Not every safeguard is a layer of protection: an alarm depends on a human response, so it is the weakest element; the real risk reduction comes from the independent, self-acting layers.
  • A HAZOP is not a one-off event: at a significant modification it must be revalidated before start-up, otherwise typically at most every five years.
  • Know its limits: FTA for combinations of causes, LOPA/SIL for the integrity level, FMEA for equipment failures.
  • The action list is the real output: without an owner, a deadline and a way of closing out, a HAZOP is just a set of minutes.
  1. In one node the team wrote a single check valve as the safeguard for the “Reverse + flow” deviation. What order of magnitude of risk reduction does this mean, and how could it be strengthened?
  2. A plant had a HAZOP three years ago, and since then a significant technological modification has been made that has not yet been started up. When must the analysis be carried out, and why is it not enough to wait out the remaining two years?
  3. During an incident investigation it turns out that two simultaneous failures caused the release. Why did the HAZOP not find this, and with which method must it be continued?

How does this show up in digital practice?

Section titled “How does this show up in digital practice?”

In essence HAZOP is a structured register: a linked set of nodes, deviations, safeguards and actions. It works in a spreadsheet too, but in a digital system it becomes enforceable and auditable: the missing cell is visible, the expiring cycle raises a flag, and the bypassed protection is not forgotten.

HAZOP principle Digital implementation What it prevents / what it delivers
Node completeness a worksheet template that enforces every parameter × guide word cell or asks for a justification the deviation quietly skipped
Safeguard register every safeguard gets an identifier and lives linked to the referring deviations the protection that exists on paper but has been removed in reality
Action tracking the recommendation is a live item with owner, deadline, status and way of closing the recommendation forgotten without being closed
Interlock and alarm override an override log with an expiry time and an approval the safety function permanently bypassed
Revalidation cadence the register flags the expiring cycle and the re-analysis triggered by a change the hazard study going stale unnoticed
Drawing versioning the HAZOP is stored bound to a given revision of the P&ID the study carried out on an obsolete drawing

The result of a HAZOP is a living protection system: alarms, SIFs, PSVs, check valves, prescribed manual valve positions and open recommendations. These live in the shift: leaving a manual valve accidentally open or closed is a recurring initiating cause in HAZOP worksheets. The OPEREX shift log closes the loop in that:

  • the status of the safety-critical valve positions, bypasses and disabled protections defined in the HAZOP can be recorded and handed over at shift handover;
  • the override events of the HAZOP alarms and SIFs can be logged and tracked;
  • the open actions of the HAZOP and the temporary deviations become visible to the operating team, so the gap between the designed and the actually working layers of protection keeps narrowing.
Hungarian English Note
Veszély- és üzemeltethetőség-elemzés Hazard and Operability Study (HAZOP) The name of the method
Csomópont Node / study node A drawing section, the unit of the study
Vezérszó Guide word None/Less/More/Part of/As well as/Reverse/Other
Eltérés Deviation Parameter × guide word
Ok Cause The initiating event
Következmény Consequence The effect
Védelmi réteg / safeguard Safeguard Independent protection
Védelmi réteg (önálló) Layer of Protection (IPL) Acts without human intervention
Kockázatcsökkentési tényező Risk Reduction Factor (RRF) RRF = 1 / PFD
Biztonsági műszerezett funkció Safety Instrumented Function (SIF) Characterized by a SIL level
Nyomáshatároló szelep Pressure Safety Valve (PSV) / relief valve Mechanical protection
Visszacsapó szelep Check valve Against reverse flow
Ajánlás / akció Recommendation / Action The output of the HAZOP
Tervezett működés Design intent What the deviation is measured from
Kapcsolási rajz P&ID (Piping & Instrumentation Diagram) The main working tool
What is the difference between HAZOP and PHA / HAZID / FMEA?

They all belong to the PHA family of methods and follow a similar logic. HAZOP examines the P&ID by parameter deviation, focusing on the process logic. HAZID serves hazard identification where there is not yet a HAZOP, or where only a minor change has been made to the process, and it is typically carried out before the HAZOP. FMEA concentrates on specific equipment failures and their effects.

When must a HAZOP be carried out?

Primarily in the basic design (basic/FEED) phase, so that there is time to implement the recommendations. In addition, at every significant plant modification, before start-up, and recurrently, typically in a cycle of at most five years.

Who leads the HAZOP, and how long does it take?

A neutral HAZOP leader (chairman) leads it, a scribe keeps the record, and a multidisciplinary team carries out the study. A HAZOP of a whole plant typically takes a week or more.

What is the role of the guide word?

The guide words (None, Less, More, Part of, As well as, Reverse, Other) systematically “provoke” the deviations for a given parameter, so the team asks about every meaningful deviation, not only the obvious ones.

Does the HAZOP give the SIL level?

Not directly. The HAZOP identifies the need for protection and the necessary safety instrumented functions (SIF), but assigning the appropriate SIL level requires a separate SIL analysis or LOPA. The HAZOP is the input, the SIL analysis is the quantification.

Why is the HAZOP not enough to determine the probability?

Because the method does not examine combinations of causes: it treats every cause on its own, as the trigger of the deviation. If the joint probability of several simultaneous failures is needed, an FTA must be carried out, in which the HAZOP deviation becomes the top event.

LOPA · SIL · SIF · management of change · pre-startup safety review · HAZID · PHA · FMEA · FTA · Seveso · Bow-tie · ALARP · incident analysis

If you understand the logic of HAZOP, the process safety picture builds on in this order:

  1. LOPA and SIL — the quantification of the layers of protection and the assignment of the SIL; this is where the need for protection identified in the HAZOP gets its value.
  2. management of change — the change management that keeps the HAZOP alive: every significant modification brings the analysis back.
  3. FMEA — the equipment-level failure mode analysis, which continues where the scope of the HAZOP ends.
  • IEC 61882Hazard and operability studies (HAZOP studies) — Application guide: the international standard of the method.
  • IEC 61511 (functional safety for the process industry) and IEC 61508 — the framework of safety instrumented functions and the SIL life cycle.
  • Seveso III Directive: 2012/18/EU on the control of major-accident hazards involving dangerous substances.
  • ISO 45001:2018 — the hazard identification and risk assessment requirements of the occupational health and safety management system.
  • Eduardo Calixto: Gas and Oil Reliability Engineering: Modeling and Analysis. 2nd edition, Elsevier, 2016 — Chapter 6 (risk analysis methods, HAZOP and FTA).
  • CCPS (AIChE): Guidelines for Hazard Evaluation Procedures — the canonical collection of the PHA family of methods.