Streamlining and prioritising alarms at a chemical processing plant

2024 / Functional safety and alarm management in the process industry / Industries

The purpose of an alarm system is to draw the operator’s attention to abnormal process conditions that require a prompt response: an alarm is an audible and visual signal triggered by a process measurement that exceeds a defined threshold towards an undesirable or hazardous value, and must always have an associated action. The relevant international standards — ISA-18.2, IEC 62682 and EEMUA Publication 191 — require that every alarm be justified, correctly prioritised and have a defined response: nuisance alarms, repeated alarms or alarms without an action overload the operator and erode confidence in the system. The correct configuration of the alarm system is also a prerequisite for LOPA (Layer of Protection Analysis, CCPS) studies: the operator’s response to the alarm is one of the creditable independent layers of protection (IPLs), and the associated risk reduction credit is only justifiable if the alarm is rationalised, with documented priorities, response times and corrective actions.

The study, developed by TECSA for a chemical processing plant subject to Legislative Decree 105/2015, focused on the rationalisation and prioritisation of alarms in the synthesis units, including the definition of the plant’s general alarm management specification. The methodological approach, carried out in accordance with ISA-18.2 and EEMUA 191 best practices, included defining the alarm philosophy (principles, priority levels, a severity matrix comprising three levels of severity and four consequence categories — people, environment, reputation, production/assets — and four response urgency classes, ranging from ‘urgent’ within 5 minutes to ‘non-urgent’ beyond 30 minutes), the pre-population of the alarm database using P&IDs, HAZOP reports, cause-and-effect tables and operating procedures, and rationalisation sessions with a multidisciplinary team (process, instrumentation, safety and operations) which assessed, for each alarm, the initiating cause, uniqueness, expected consequences, severity, available time and required operator response. The work was carried out using the exida exSILentia® software (SILalarm™ module), supplied to TECSA, which enabled the construction of the master alarm database and the automatic generation of Alarm Response Procedures.

The analysis examined 110 process tags for 273 rationalised alarms: 57 with High priority (20.9%), 28 Medium (10.3 per cent) and 39 Low (14.3 per cent), with 82 trip thresholds recorded and displayed separately, and 67 signals (24.5 per cent) downgraded to non-alarm status as they required no action from the operator — recorded as events but not announced, thereby reducing the cognitive load in the control room. For each confirmed alarm, the Alarm Response Procedures document causes, expected consequences, priority, setpoints and corrective actions. The specification also defines optimisation functions — grouping of alarms by piece of equipment and systematic masking across different operational states (equipment shut down, units stopped, start-up and shutdown) — and periodic operational reviews as part of continuous improvement, with a performance target of Level 4 ‘Robust’ according to EEMUA 191. The study has thus qualified the alarm system as a reliable tool for the operator and as a defensible layer of protection in LOPA studies, defining the technical and managerial framework for its long-term maintenance.