ISO/FDIS 5133
(Main)Oil and gas industries including lower carbon energy — Protective system requirements for fired equipment
General Information
- Abstract
- Status
- Not Published
- Technical Committee
- ISO/TC 67/SC 6 - Processing equipment and systems
- Drafting Committee
- ISO/TC 67/SC 6/WG 8 - Process heat transfer equipment
- Current Stage
- 5020 - FDIS ballot initiated: 2 months. Proof sent to secretariat
- Start Date
- 02-Oct-2026
- Completion Date
- 02-Oct-2026
Buy Documents
ISO/FDIS 5133 - Oil and gas industries including lower carbon energy — Protective system requirements for fired equipment
REDLINE ISO/FDIS 5133 - Oil and gas industries including lower carbon energy — Protective system requirements for fired equipment
Overview
ISO/FDIS 5133:2026 – Oil and gas industries including lower carbon energy - Protective system requirements for fired equipment is an international standard developed by the International Organization for Standardization (ISO). It provides a structured, risk-based framework to determine protective system requirements for fired equipment used in the petroleum, petrochemical, and natural gas industries, including applications adopting lower carbon energy processes. This standard applies to both new and existing fired equipment, addressing the identification of hazards, implementing measures to reduce risks, and requirements for ongoing inspection, testing, and maintenance.
ISO/FDIS 5133 is vital in supporting safer operations, improving risk management, and facilitating compliance with modern safety requirements for process equipment.
Key Topics
The standard outlines key concepts and practical requirements critical for operators, engineers, and safety professionals:
- Risk-Based Protective System Design: Establishes a systematic process to identify hazards, assess risks, and define suitable protection systems for fired equipment.
- Hazard Identification: Details systematic methods for recognizing hazards, including flammable mixtures, equipment malfunctions, and process failures.
- Hierarchy of Risk Controls: Explains forms of risk reduction, ranging from engineering and administrative controls to safeguards and independent protection layers.
- Hazard Scenario Analysis: Introduces progression diagrams and methodologies to trace hazard development from initiating events, through safeguards, to potential loss events.
- ALARP Principle: Provides guidance on achieving risks that are as low as reasonably practicable, using both quantitative and qualitative approaches.
- Team-Based Hazard Analysis: Specifies requirements for multi-disciplinary hazard analysis teams with competence in fired equipment.
- Inspection, Testing, and Maintenance: Mandates ongoing programs for proactive discovery and management of equipment failures.
- Training and Documentation: Requires structured training programs, retention of records, and robust documentation for operational and maintenance personnel.
Applications
ISO/FDIS 5133 is applicable across a broad spectrum of operations within the oil and gas sector, as well as in transitioning energy facilities utilizing fired equipment. Typical scenarios include:
- Design and Commissioning of Fired Equipment: Ensures protective systems are embedded at the design and development stage.
- Modification of Existing Installations: Applies the risk-based assessment process to altered or upgraded fired equipment.
- Operational Risk Management: Serves as a guideline during regular operation, facilitating ongoing hazard identification and mitigation measures.
- Training and Competence: Assists in shaping workforce competence, operational discipline, and maintenance protocols.
- Supporting Regulatory Compliance: Provides a framework to satisfy regulatory requirements and align with global best practices for process safety.
The standard is not intended for commercial fired equipment employed in non-process applications (e.g., food preparation or small space heating).
Related Standards
Organizations implementing ISO/FDIS 5133 may find value in referencing additional standards and recommended practices to establish a comprehensive safety management framework:
- ISO 45001: Occupational health and safety management systems – Requirements with guidance for use.
- IEC 61511: Functional safety – Safety instrumented systems for the process industry sector.
- API RP 556: Instrumentation and control systems for fired heaters and steam generators.
- CCPS Guidelines: Center for Chemical Process Safety publications on process safety and risk analysis.
- ISO/IEC Guide 51: Safety aspects – Guidelines for risk reduction.
- Other ISO 516xx Series: Related standards covering general fired equipment requirements and safety principles.
By integrating ISO/FDIS 5133 with these related documents, organizations can enhance their fired equipment safety, achieve regulatory compliance, and promote a culture of continuous improvement in process safety management.
Keywords: ISO/FDIS 5133, fired equipment, risk-based protection, oil and gas safety standard, hazard identification, ALARP, process safety, lower carbon energy, inspection and maintenance, ISO standards for fired heaters.
Buy Documents
ISO/FDIS 5133 - Oil and gas industries including lower carbon energy — Protective system requirements for fired equipment
REDLINE ISO/FDIS 5133 - Oil and gas industries including lower carbon energy — Protective system requirements for fired equipment
Get Certified
Connect with accredited certification bodies for this standard

Element Materials Technology
Materials testing and product certification.
ABS Group Brazil
ABS Group certification services in Brazil.

ABS Quality Evaluations Inc.
American Bureau of Shipping quality certification.
Sponsored listings
Frequently Asked Questions
ISO/FDIS 5133 is a draft published by the International Organization for Standardization (ISO). Its full title is "Oil and gas industries including lower carbon energy — Protective system requirements for fired equipment". This standard covers: Oil and gas industries including lower carbon energy — Protective system requirements for fired equipment
Oil and gas industries including lower carbon energy — Protective system requirements for fired equipment
ISO/FDIS 5133 is classified under the following ICS (International Classification for Standards) categories: 75.200 - Petroleum products and natural gas handling equipment. The ICS classification helps identify the subject area and facilitates finding related standards.
ISO/FDIS 5133 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
FINAL DRAFT
International
Standard
ISO/TC 67/SC 6
Oil and gas industries including
Secretariat: AFNOR
lower carbon energy — Protective
Voting begins on:
system requirements for fired
2026-10-02
equipment
Voting terminates on:
2026-11-27
Industries du pétrole et du gaz, y compris les énergies à
faible teneur en carbone — Exigences relatives au système de
protection des équipements à combustion
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
Reference number
FINAL DRAFT
International
Standard
ISO/TC 67/SC 6
Oil and gas industries including
Secretariat: AFNOR
lower carbon energy — Protective
Voting begins on:
system requirements for fired
equipment
Voting terminates on:
Industries du pétrole et du gaz, y compris les énergies à
faible teneur en carbone — Exigences relatives au système de
protection des équipements à combustion
RECIPIENTS OF THIS DRAFT ARE INVITED TO SUBMIT,
WITH THEIR COMMENTS, NOTIFICATION OF ANY
RELEVANT PATENT RIGHTS OF WHICH THEY ARE AWARE
AND TO PROVIDE SUPPOR TING DOCUMENTATION.
© ISO 2026
IN ADDITION TO THEIR EVALUATION AS
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
BEING ACCEPTABLE FOR INDUSTRIAL, TECHNO
LOGICAL, COMMERCIAL AND USER PURPOSES, DRAFT
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
INTERNATIONAL STANDARDS MAY ON OCCASION HAVE
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
TO BE CONSIDERED IN THE LIGHT OF THEIR POTENTIAL
or ISO’s member body in the country of the requester.
TO BECOME STAN DARDS TO WHICH REFERENCE MAY BE
MADE IN NATIONAL REGULATIONS.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland Reference number
ii
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 2
3 Terms and definitions . 2
4 Normative requirements . 5
4.1 General .5
4.2 Inputs .6
4.2.1 Good practice .6
4.2.2 Documents .7
4.3 Hazard analysis team .7
4.4 Hazard identification .7
4.4.1 Primary loss events .7
4.4.2 Hazards leading to primary loss events .8
4.4.3 Escalation hazards following primary loss events .8
4.5 Hazard scenario progression diagram .8
4.5.1 Form and format .8
4.5.2 Hazard scenario identification .10
4.6 Severity of harm and tolerability criteria .10
4.6.1 Severity of harm .10
4.6.2 Risk criteria thresholds . .10
4.7 Establishing predicted event frequency, tolerability and ALARP .11
4.7.1 Initiating event frequency.11
4.7.2 Safeguards .11
4.7.3 Probability modifiers .11
4.7.4 Predicted event frequency .11
4.7.5 Predicted event frequency categorization . 12
4.7.6 Completion of risk reduction assessment procedure . 12
4.8 Ongoing Testing, Inspection and Maintenance . . 12
4.8.1 Inspection . 12
4.8.2 Testing . 12
4.8.3 Maintenance . 12
4.9 Training materials, schedules and record retention . 13
Annex A (informative) Quantitative ALARP subroutine . 14
Annex B (informative) Qualitative ALARP subroutine . 19
Annex C (normative) Safeguards and Independent Protection Layers .22
Annex D (informative) Feasibility of Detonation in Fired Heaters in Upset Conditions .24
Annex E (informative) Fired Equipment Deflagration Probability Modifier .32
Annex F (informative) Flammable Mixture and Flooded Firebox Hazard Scenario Progression
diagrams .34
Annex G (informative) Typical Hazard Scenario Progression Diagram Examples .36
Bibliography . 76
iii
Foreword
ISO (the International Organization for Standardization) is a worldwide federation of national standards
bodies (ISO member bodies). The work of preparing International Standards is normally carried out through
ISO technical committees. Each member body interested in a subject for which a technical committee
has been established has the right to be represented on that committee. International organizations,
governmental and non-governmental, in liaison with ISO, also take part in the work. ISO collaborates closely
with the International Electrotechnical Commission (IEC) on all matters of electrotechnical standardization.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of ISO document should be noted. This document was drafted in accordance with the editorial rules of the
ISO/IEC Directives, Part 2 (see www.iso.org/directives).
ISO draws attention to the possibility that the implementation of this document may involve the use of (a)
patent(s). ISO takes no position concerning the evidence, validity or applicability of any claimed patent
rights in respect thereof. As of the date of publication of this document, ISO had not received notice of (a)
patent(s) which may be required to implement this document. However, implementers are cautioned that
this may not represent the latest information, which may be obtained from the patent database available at
www.iso.org/patents. ISO shall not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT), see www.iso.org/iso/foreword.html.
This document was prepared by Technical Committee ISO/TC 67, Oil and gas industries including lower carbon
energy, Subcommittee SC 6, Process equipment, piping, systems, and related safety.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html.
iv
Introduction
The purpose of this document is to provide a basic framework for hazard identification, risk assessment,
and risk reduction including the “as low as reasonably practicable” (ALARP) methodology as it applies
specifically to fired equipment.
This document defines hazards associated with fired equipment that have potential to cause harm. This
document explains how these hazards develop into scenarios, starting with initiating events, in the presence
of probability modifiers that allow the fired equipment to progress through intermediate process states and
if unimpeded can lead to an irreversible loss event, potentially leading to harm.
This document gives guidance to the reader as to what initiating events, probability modifiers and safeguards
can be applied to fired equipment.
This document gives guidance to the reader as to how initiating event frequencies, probability modifiers and
safeguards can be applied to fired equipment to determine a loss event frequency. To reduce the loss event
frequency, improvements can be applied as reductions in the initiating event frequency or in the form of
safeguards. Regardless of how improvements are classified, they are only counted once per hazard scenario.
The user of this document is informed that further or differing requirements can be needed for individual
applications. This document is not intended to inhibit a vendor from offering, or the purchaser accepting,
alternative equipment or engineering solutions for the individual application. This can be particularly
applicable where there is innovative or developing technology. Where an alternative is offered, the vendor
needs to detail any variations from this document.
v
FINAL DRAFT International Standard ISO/FDIS 5133:2026(en)
Oil and gas industries including lower carbon energy —
Protective system requirements for fired equipment
1 Scope
This document defines a risk-based program for determining protective system requirements for petroleum,
petrochemical and natural gas industry fired equipment including lower carbon energy. The process applies
to new or existing fired equipment.
For modifications to existing fired equipment that has been designed in accordance with this document, the
scope can be limited to changes.
This document applies to:
— hazards that have potential to produce harm;
— engineered and administrative forms of risk reduction.
NOTE 1 See Figure 1 for a graphical representation of the hierarchy of risk reduction.
Figure 1 — Hierarchy of risk reduction and scope
NOTE 2 For guidance on elimination and substitution of hazards, see ISO 45001:2018, 8.1.2.
NOTE 3 An example of hierarchy of risk reduction related to a natural draft gas-fired process fired heater is as
follows:
— Elimination - eliminate the gas-fired process heater combustion risk by replacing with electric heating;
— Substitution - refinery fuel gas replaced with constant calorific value natural gas, for example, from a utility
pipeline;
— Engineering function - install mass flow meter that compensates for composition change in refinery fuel gas;
— Administrative function – maintain low occupancy around natural draft gas fired process fired heater.
The scope of this document excludes:
— assessment of environmental impact, business impact or loss of reputation;
— risk reductions in the forms of elimination, substitution, and personal protective equipment;
— commercial fired equipment used for food preparation, space heating, small potable water heaters, and
other non-process applications such as small heaters used in maintenance applications.
2 Normative references
There are no normative references in this document.
3 Terms and definitions
For the purposes of this document, the following terms and definitions apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
3.1
basic process control system
BPCS
combination of associated equipment, and either programmable systems or operators, or both that generate
output signals causing the process and its associated equipment to operate in the desired manner, but which
does not perform any safety instrumented function
3.2
competent person
competent personnel
person who has acquired through training, qualifications or experience, or a combination of these, the
knowledge and skills enabling that person to perform a specified task
3.3
control loop failure
failure of components or aspects of a control loop
Note 1 to entry: Examples of control loop failure include but are not limited to: sensor, controller, final element,
inadvertent set-point, loss of communication, loss of utility
3.4
facility operator
person, company, or organization that is responsible for the operations of a facility or worksite, or who has
the responsibility for a hazardous material or hazardous energy in a facility
3.5
fired equipment
device to convert fuel into heat by means of combustion, including the fuel gas train downstream of the
fuel supply manual shut-off valve, heat transfer sections, associated combustion air and flue gas handling
systems, instrumentation, controls and protection layers
3.6
flooded firebox hazard
presence of unburned fuel in firebox in the presence of an ignition source (flame), with sufficient calorific
value that when air is added, or fuel is quickly reduced an explosion may occur
3.7
flammable mixture hazard
presence of unburned fuel in the firebox in the presence of air, with sufficient calorific value that when an
ignition source is added an explosion can occur
3.8
flooding
continuing accumulation of unburned fuel in fired equipment where the injection of fuel is increased by the
feedback control of the primary process variable
EXAMPLE Coil outlet temperature for a heater.
3.9
good practice
recognized minimum methods and measures addressing an aspect of the fired equipment that existed at the
time the fired equipment project’s final investment decision was approved
Note 1 to entry: Aspects can include but are not limited to procedures writing, mechanical design, instrumentation
specification and installation, logic solver specification and installation, controls design and installation, protection
layer design installation.
3.10
harm
injury or damage to the health of people, or damage to property or the environment
Note 1 to entry: For the purposes of this document, the definition of harm is further reduced to death, or irreversible
physical injury to individual.
[SOURCE: ISO/IEC Guide 51:2014, 3.1, modified — Note 1 to entry added.]
3.11
hazard
potential source of harm
[SOURCE: ISO/IEC Guide 51:2014, 3.2]
3.12
hazard scenario
sequence of events starting with an initiating event, potentially causing harm
3.13
independent protection layer
IPL
device, system, or action capable of preventing a scenario from proceeding to the undesired consequence
regardless of the initiating event or the action of any other protection layer associated with the scenario
[13]
[SOURCE: CCPS ]
3.14
initiating event
IE
failure or error necessary to start the propagation of a hazard scenario
Note 1 to entry: Failure of an independent protection layer is not an initiating event.
3.15
loss event
LE
point in time in a hazard scenario when an irreversible physical event occurs that has the potential to cause
harm
Note 1 to entry: A primary loss event is sometimes the initiating event for one or more secondary loss events.
Note 2 to entry: Loss event is generally synonymous with hazardous event.
3.16
mode of operation
definable operating condition of process equipment as it progresses from shutdown to running and back to
shut down, where each mode of operation represents a unique operating regime that supports the process
equipment’s objectives of processing an input into a desired output
Note 1 to entry: Examples of modes of operation include but are not limited to: pre-firing, ignition, pilots only, normal
running, post-firing.
Note 2 to entry: Modes of operation can contain sub-modes, for example, purge is a sub-mode of pre-firing.
3.17
operational discipline
performance of all tasks correctly every time
[1]
[SOURCE: CCPS ]
3.18
probability modifier
PM
dimensionless value that provides a numerical adjustment to the sequence, likelihood, consequence, and
severity associated with the hazard scenario
EXAMPLE Probability of a hazardous atmosphere, probability of ignition, probability of explosion, probability of
personnel presence, probability of injury or fatality, probability of equipment damage, probability of increasing air
flow after combustibles are present in the firebox and time at risk.
Note 1 to entry: Enabling conditions and conditional modifiers are probability modifiers.
3.19
process control narrative
design document describing how the basic process control system is configured and programmed, and how
the operator interacts with the system, to cause the process and its associated equipment to function in a
desired manner within its operating envelope
3.20
process state
PS
initial or intermediate operating condition of fired equipment in a hazard scenario
Note 1 to entry: Examples of process states are default, fuel accumulation and flammable mixture hazard.
3.21
protection layer
any independent mechanism that reduces risk by control, prevention or mitigation
[SOURCE: IEC 61511-1:2016+AMD1: 2017, 3.2.57]
3.22
risk
combination of the probability of occurrence of harm and the severity of that harm
Note 1 to entry: The probability of occurrence includes the exposure to a hazard scenario, the occurrence of a
hazardous event and the possibility to avoid or limit the harm.
[SOURCE: ISO/IEC Guide 51:2014, 3.9]
3.23
residual risk
risk remaining after protection layers have been implemented
[SOURCE: ISO/IEC Guide 51:2014, 3.8]
3.24
safe
safety
freedom from risk which is not tolerable
[SOURCE: ISO/IEC Guide 51:2014, 3.14]
3.25
safeguard
any device, system, or action that either interrupts the chain of events following an initiating event or that
mitigates the consequences
Note 1 to entry: Not all safeguards will meet the requirements of an IPL.
[13]
[SOURCE: CCPS ]
3.26
safety instrumented function
SIF
safety function to be implemented by a safety instrumented system
[SOURCE: IEC 61511-1:2016+AMD1: 2017 3.2.67]
3.27
safety instrumented system
SIS
instrumented system used to implement one or more safety instrumented functions
[SOURCE: IEC 61511-1:2016+AMD1: 2017 3.2.67]
3.28
tolerable risk
level of risk which is accepted in a given context based on the current values of society
Note 1 to entry: The terms “acceptable risk” and “tolerable risk” are considered to be synonymous.
[SOURCE: ISO/IEC Guide 51:2014, 3.15]
4 Normative requirements
4.1 General
These clauses and subclauses define the normative requirements for a risk-based program for determining
protective system requirements for fired equipment in the petroleum, petrochemical and natural gas
industry including lower carbon energy.
NOTE See Figure 2 for an informative flowchart representation of the risk-based program.
Figure 2 — Risk-based program for determining protective system requirements
4.2 Inputs
4.2.1 Good practice
The fired equipment shall be designed, operated, inspected, tested, and maintained in accordance with good
practice addressing the following aspects of the equipment:
— fired equipment design;
— instrumentation design;
— controls design;
— protection layer design;
— logic solver design;
— ongoing inspection, testing and maintenance;
— operational discipline.
4.2.2 Documents
The following documents shall be provided as inputs to the risk-based process:
— general arrangement drawings;
— specifications;
— Piping and Instrument Diagram (PID);
— process control narrative;
— procedures.
4.3 Hazard analysis team
The hazard analysis team shall include representatives from process safety, instrumentation, operations
and fired equipment engineering.
The hazard analysis team shall include representatives of other technical disciplines as determined
necessary by the facility operator, for example:
— controls design;
— protection layer design;
— maintenance;
— process engineering.
A minimum of three hazard analysis team members shall be familiar with fired equipment.
One competent person may fill multiple roles.
A hazard analysis team coordinator shall be appointed.
The team coordinator may also be one of the discipline representatives.
The team should be a collaboration between all companies that are involved with design, manufacture,
ownership, operation and maintenance of the fired equipment.
4.4 Hazard identification
4.4.1 Primary loss events
The primary loss events shall be identified.
NOTE 1 Examples of primary loss events include:
— deflagration of accumulated gaseous fuel and air flammable mixture;
— deflagration of accumulated volatilized components of liquid fuels and air flammable mixture;
— pool fire of accumulated liquid fuel;
— process tube loss of containment;
— release of unburned toxic fuel;
— large mass of water at boiling point and high pressure.
NOTE 2 For discussion of deflagrations, see informative Annex D.
4.4.2 Hazards leading to primary loss events
Hazards that can lead to each primary loss event shall be identified.
NOTE Examples of hazards include:
a) flammable mixture hazard (fuel and air in absence of source of ignition), including flame out, fuel left in firebox
after trip, leaking tube during pre-firing mode of operation;
b) flooded firebox hazard (fuel and source of ignition in absence of air), including severely substoichiometric
operation, process tube failure, toxic fuel gas release;
c) process hazards at the outlet of the fired equipment, including high process fluid temperature, high process fluid
pressure.
4.4.3 Escalation hazards following primary loss events
The hazard analysis team shall determine if shutting down the fired equipment has the potential to create
another hazard within the fired equipment or elsewhere in the facility.
NOTE For example, shutting down the heater cools the process unit quickly which can lead to a flange fire
elsewhere in the unit.
4.5 Hazard scenario progression diagram
4.5.1 Form and format
Hazard scenarios follow the general form shown in Figure 3, starting with an initiating event (IE) occurring
when the fired equipment is in the default process state PS and in a particular mode of operation,
potentially in the presence of probability modifiers PM and safeguards SG , that causes the fired
1(x) 1(x)
equipment to progress to a new intermediate process state PS . The sequence then continues through a
further intermediate process states PS via probability modifiers and safeguards before the loss event (LE)
is reached. Final probability modifiers PM and mitigative safeguards SG can then be applied prior to
4(x) 4(x)
the harm event (HE) occurring.
NOTE For a detailed explanation of example hazard scenario progression diagrams related to typical initiating
events, see informative Annex G.
Key
PM probability modifier
x(a)
PS process state
x(a)
IE initiating event
LE loss event
HE harm event
SG safeguard
x(a)
A fuel accumulation
B second constituent leading to creation of flammable mixture hazard
C deflagration
D harm
NOTE Where the facility operator applies a risk assessment methodology which involves multiple IE Figure 3 can
be modified accordingly.
Figure 3 — Example flammable mixture hazard scenario progression diagram with safeguards
4.5.2 Hazard scenario identification
4.5.2.1 General
For hazards identified in 4.4.2, the team shall identify hazard scenarios based on unique IEs addressing the
following clauses.
4.5.2.2 Modes of operation
Hazard scenarios shall be identified for all modes of operation.
Hazard scenarios shall be identified when the fired equipment is transitioning between modes of operation.
Hazard scenarios shall be identified where transient conditions occur within modes of operation.
NOTE Examples of transient conditions are fuel composition change, process feed composition change, unit
charge rate change.
4.5.2.3 Initiating events
Hazard scenario IEs shall be identified in the following categories:
a) internal to the fired equipment;
b) external to the fired equipment;
c) equipment failure;
d) Process control failure;
e) human failure.
NOTE 1 An example of internal IE is fuel gas basic process control system (BPCS) loop failure.
NOTE 2 Examples of external initiating events include 3rd party intervention, external gas cloud, lightning strike,
liquid or solids in fuel, or general utility failure.
NOTE 3 Examples of an equipment failure initiating events include a piping leak.
NOTE 4 Examples of process control failures include BPCS loop failure.
NOTE 5 Examples of human failures include closing one or more burner air registers while burners are in service,
or operator setpoint entry error.
4.6 Severity of harm and tolerability criteria
4.6.1 Severity of harm
The severity of harm associated with each hazard scenario shall be identified and quantified based on the
number of people subject to harm.
NOTE 1 The proximity of the fired equipment relative to occupied buildings and to the public can have a large
impact on the severity of harm.
NOTE 2 For guidance regarding deflagrations when quantifying the severity of harm, see Annex D.
4.6.2 Risk criteria thresholds
The following threshold frequencies shall be provided based on severity of harm (4.5.1). These thresholds
may be the same:
— threshold between unacceptable and tolerable risk;
— threshold between tolerable and broadly acceptable risk.
NOTE 1 Tolerable risk criteria can be determined in partnership with regulating bodies in certain jurisdictions.
[23,24]
NOTE 2 Tolerable risk criteria can be extrapolated from risk contours published in public documents .
4.7 Establishing predicted event frequency, tolerability and ALARP
4.7.1 Initiating event frequency
The IE frequency shall be determined for each hazard scenario based on facility operator data.
NOTE 1 Facility operator data can be derived from internal and external sources including industry reliability
[13]
databases and CCPS reference
NOTE 2 Initiating event frequency is typically 0,1/year or greater, unless analysis justifies a value less than 0,1/
year.
NOTE 3 Analysis methods for equipment failure IE frequencies include Failure Mode and Effect Analysis (FMEA).
NOTE 4 Analysis methods for human error IE frequency include Human Error Assessment and Reduction Technique
(HEART), Empirical Technique to Estimate Operator Errors (TESEO).
4.7.2 Safeguards
Safeguards shall be identified for each hazard scenario, as per normative Annex C.
The average probability of failure on demand (PFD ) of the safeguard(s) shall be determined.
AVG
NOTE If there are no safeguards the PFD of the safeguard is 1.
4.7.3 Probability modifiers
Probability modifiers shall be determined for each hazard scenario.
When applicable, probability modifiers shown as PM , PM , PM and PM on Figure 3 shall be determined.
1 2 3 4
Limiting exposure of personnel to hazards may be a PM probability modifier or an SG administrative
4 4
protection layer, but it shall not be used as both in the same hazard scenario.
The product of all applicable probability modifiers, PM , PM , PM and PM , shall be determined.
1 2 3 4
NOTE 1 PM , PM and PM probability modifiers are typically 0,1 or greater, unless analysis justifies a value less
1 2 4
than 0,1.
NOTE 2 PM probability modifiers are typically 0,1 or greater, except for fired equipment that runs for a significant
amount of time above the auto-ignition temperature for fuels, where a value of less than 0,1 can be appropriate. See
informative Annex E for details.
NOTE 3 PM is the location in the hazard scenario progression diagram where the 2nd constituent in the creation
of the flammable mixture hazard is introduced. See informative Annex F for details on how this probability modifier is
used.
NOTE 4 For guidance on probability modifiers see Reference [14]
NOTE 5 The product of probability modifiers is typically 0,01 or greater, unless analysis capable of withstanding
scrutiny justifies a value less than 0,01.
4.7.4 Predicted event frequency
For each hazard scenario, the predicted event frequency, shall be determined as the product of the IE
frequency or frequencies (4.7.1) and the product of the PFD of the safeguard(s) (4.7.2) and the product of
AVG
all applicable probability modifiers, PM , PM , PM and PM (4.7.3).
1 2 3 4
4.7.5 Predicted event frequency categorization
For each hazard scenario, the predicted event frequency determined in 4.7.4 shall be categorized as
unacceptable, tolerable, or broadly acceptable (see 4.6.2).
If the predicted event frequency determined is broadly acceptable, further risk reductions are not necessary,
and further assessment shall not be required.
If the predicted event frequency determined is unacceptable, an additional SG shall be implemented, and the
PFD provided by the SG shall be determined, and the user shall proceed to subclause 4.7.3.
If the predicted event frequency determined is tolerable but not broadly acceptable, a quantitative or
qualitative ALARP assessment shall be performed to determine if additional risk reductions are justified.
NOTE See Annex A for guidance on quantitative ALARP and Annex B for guidance on qualitative ALARP.
4.7.6 Completion of risk reduction assessment procedure
If the predicted event frequency remaining after application of risk reductions justified by the ALARP
assessment is broadly acceptable or ALARP, further risk reductions are not necessary, and further
assessment shall not be required.
4.8 Ongoing Testing, Inspection and Maintenance
4.8.1 Inspection
The facility operator shall prepare procedures, schedules, and record retention policies for ongoing
inspection of fired equipment components.
NOTE 1 The purpose of the ongoing inspection program is to reveal developing component failures prior to a full
failure. Ongoing inspection procedures and schedules are based on applicable manufacturer’s recommendations,
industry standards, and prior operating experience.
NOTE 2 Application of a facility operator’s internal standard overlay to IEC 61511-1 meets the intent of this
requirement for instrumented protection layers.
NOTE 3 Application of a facility operator’s internal standard overlay to API RP 556 meets the intent of this
requirement.
4.8.2 Testing
The facility operator shall prepare procedures, schedules, and record retention policies for ongoing testing
of fired equipment components.
NOTE 1 The purpose of the ongoing testing program is to reveal dangerous undetected failures of fired equipment
components that will cause the safeguard (SG) to fail to function upon demand. Ongoing testing procedures and
schedules are based on applicable manufacturer’s recommendations, industry standards, and prior operating
experience.
NOTE 2 Application of a facility operator’s internal standard overlay to IEC 61511-1 meets the intent of this
requirement for instrumented protection layers.
4.8.3 Maintenance
The facility operator shall prepare procedures, schedules, and record retention policies for ongoing
maintenance of fired equipment components.
NOTE 1 Ongoing maintenance procedures and schedules are based on applicable manufacturer’s recommendations,
industry standards, and prior operating experience.
NOTE 2 Application of a facility operator’s internal standard overlay to IEC 61511-1 meets the intent of this
requirement for instrumented protection layers.
4.9 Training materials, schedules and record retention
The facility operator shall prepare training material, re-training schedules, and training record retention
policies for personnel involved in operation, ongoing inspection, testing, and maintenance of fired equipment.
NOTE 1 This training covers operational discipline, identification of process and fired equipment hazards, how to
identify and correct unsafe situations, procedures used as part of human independent protection layers (IPLs), as well
as procedures directing job tasks.
NOTE 2 For qualification of operators used in human IPLs see Reference [13] 5.2.2.5 and table 5.4
Annex A
(informative)
Quantitative ALARP subroutine
A.1 General
This annex presents informative guidance for an iterative quantitative “as low as reasonably practicable”
ALARP assessment.
NOTE See Figure A.1 for a flowchart representation of the iterative quantitative ALARP assessment.
Figure A.1 — Quantitative ALARP Assessment Flowchart
A.2 Input variables
The value of preventing harm (VopH) is provided.
The discount factor for investment calculations (r) is provided.
The expected equipment lifespan used in investment calculations (t) is provided.
NOTE 1 This is a financial representation of the potential consequences of the harm event (HE).
NOTE 2 See Reference [21] for an example calculation of the value of harm.
A.3 Value of additional safeguards
A reusable function is created to determine the value of potential additional safeguards to further reduce
the risk.
NOTE The quantitative “as low as reasonably practicable” (ALARP) subroutine is written with the following
example formula:
VopHxPEF
J
PV �� 1 (A.1)
J
t
r
1r
Where
PV is the present value (PV) following application of safeguard J, in monetary units which
J
represents the money available to implement the next risk reducing option
VopH is the value of preventing harm, in monetary units which is a financial representation of the
potential consequences of the HE
PEF is the predicted event frequency following application of safeguard J per annum
J
r is the discount factor, in percentage
t is the term of investment, in years
J is a series from 1 to N
A.4 Predicted event frequency after risk reductions
The predicted event frequency after application of good practice and extra risk reductions (4.7.5) is
determined as PEF .
A.5 Safeguard zero
Safeguard is defined as the combination of good practice and extra risk reductions (4.7.5).
A.6 Present value after safeguard zero
The PV following application of safeguard SG is calculated as PV .
0 0
A.7 Evaluation List of potential safeguards
The user creates an evaluation list of potential additional SGs to further reduce the risk and designates it
SG .
1→N
If there are no potential additional SGs (i.e., N=0), the predicted event frequency determined in 4.7.4 is
considered to be already ALARP and the user proceeds to subclause 4.7.6.
A.8 Estimate PFD and cost per safeguard
For each potential additional SG , the probability of failure on demand (PFD ) and present value cost of
J J
implementation (PV ) is estimated.
J
A.9 Ranking of safeguards
The potential additional safeguard list SG is ranked from 1 to N in the following order:
1→N
a) engineering functions from greatest to least risk reduction;
b) administrative functions from greatest to least risk reduction.
A.10 Predicted event frequency after safeguard J
Predicted event frequency following application of additional SG (PEF ) is determined as the product of the
J J
predicted event frequency following application of additional SG (PEF ) and the PFD of additional SG
J-1 J-1 J
(PFD ).
J
PEFP��EF �PFD (A.2)
JJ1 J
Where:
PEF is the predicted event frequency following application of safeguard J per annum
j
PFD is the probability of demand J per annum
j
A.11 Present value after safeguard J
The PV following application of additional SG (PV ) is calculated using Formula A.1.
J J
A.12 Benefit of safeguard J
The benefit of additional SG (BoS ) is calculated as the PV following application of additional SG (PV )
J J J-1 J-1
minus the PV following application of additional SG (PV ).
J J
BoSPVPV (A.3)
JJ1 J
Where:
BoS is the benefit of the additional safeguard J
J
PV is the present value (PV) following application of safeguard J, in monetary units which
J
represents the money available to implement the next risk reducing option
A.13 Net present value of safeguard J
The net present value (NPV ) of additional safeguard J is calculated as the benefit of the additional SG (BoS )
J J J
minus the cost of additional safeguard J (PV ).
J
NPVBoS �PV (A.4)
JJ J
Where:
NPV is the net present value of additional safeguard J
J
BoS is the benefit of the additional safeguard J
J
PV is the present value (PV) following application of safeguard J, in monetary units which
J
represents the money available to implement the next risk reducing option
A.14 Practicability of safeguard J
If NPV < 0 then additional SG is unjustified and is removed from the evaluation list, and the user sets value
J J
of PEF = PEF .
J J-1
If NPV ≥ 0 then additional SG is reasonably practicable.
J J
A.15 Categorization of predicted event frequency
Predicted event frequency is categorized as tolerable, or broadly acceptable.
A.16 Predicted event frequency is broadly acceptable
If predicted event frequency (PEF ) is broadly acceptable, further assessment is not required and the user
J
proceeds to 4.7.6.
A.17 Additional safeguards remaining
If predicted event frequency (PEF ) is tolerable and there are additional SGs to be evaluated (i.e., J < N), the
J
user sets J = J + 1 and proceeds to A.10.
A.18 No additional safe
...
ISO/TC 67/SC 6/WG 8
Secretariat: AFNOR
Date: 2026-03-09-17
Oil and gas industries including lower carbon energy – — Protective
system requirements for fired equipment
Industries du pétrole et du gaz, y compris les énergies à faible teneur en carbone — Exigences relatives au
système de protection des équipements à combustion
FDIS stage
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication
may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying,
or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO
at the address below or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: + 41 22 749 01 11
EmailE-mail: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii
Contents
Foreword . iv
Introduction . v
1 Scope . 1
2 Normative references . 2
3 Terms and definitions . 2
4 Normative requirements . 6
4.1 General. 6
4.2 Inputs . 7
4.3 Hazard analysis team . 7
4.4 Hazard identification . 8
4.5 Hazard scenario progression diagram . 8
4.6 Severity of harm and tolerability criteria . 11
4.7 Establishing predicted event frequency, tolerability and ALARP . 11
4.8 Ongoing Testing, Inspection and Maintenance . 12
4.9 Training materials, schedules and record retention . 13
Annex A (informative) Quantitative ALARP subroutine . 14
Annex B (informative) Qualitative ALARP subroutine . 19
Annex C (normative) Safeguards and Independent Protection Layers . 22
Annex D (informative) Feasibility of Detonation in Fired Heaters in Upset Conditions . 24
Annex E (informative) Fired Equipment Deflagration Probability Modifier . 32
Annex F (informative) Flammable Mixture and Flooded Firebox Hazard Scenario Progression
diagrams. 34
Annex G (informative) Typical Hazard Scenario Progression Diagram Examples . 36
Bibliography . 80
iii
Foreword
ISO (the International Organization for Standardization) is a worldwide federation of national standards
bodies (ISO member bodies). The work of preparing International Standards is normally carried out through
ISO technical committees. Each member body interested in a subject for which a technical committee has been
established has the right to be represented on that committee. International organizations, governmental and
non-governmental, in liaison with ISO, also take part in the work. ISO collaborates closely with the
International Electrotechnical Commission (IEC) on all matters of electrotechnical standardization.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types of
ISO document should be noted. This document was drafted in accordance with the editorial rules of the
ISO/IEC Directives, Part 2 (see www.iso.org/directives).
ISO draws attention to the possibility that the implementation of this document may involve the use of (a)
patent(s). ISO takes no position concerning the evidence, validity or applicability of any claimed patent rights
in respect thereof. As of the date of publication of this document, ISO had not received notice of (a) patent(s)
which may be required to implement this document. However, implementers are cautioned that this may not
represent the latest information, which may be obtained from the patent database available at
www.iso.org/patents. ISO shall not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT), see www.iso.org/iso/foreword.html.
This document was prepared by Technical Committee ISO/TC 67, Oil and gas industries including lower carbon
energy, Subcommittee SC 6, Process equipment, piping, systems, and related safety.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html.
iv
Introduction
The purpose of this document is to provide a basic framework for hazard identification, risk assessment, and
risk reduction including the “as low as reasonably practicable” (ALARP) methodology as it applies specifically
to fired equipment.
This document defines hazards associated with fired equipment that have potential to cause harm. The
standardThis document explains how these hazards develop into scenarios, starting with initiating events, in
the presence of probability modifiers that allow the fired equipment to progress through intermediate process
states and if unimpeded can lead to an irreversible loss event, potentially leading to harm.
This document gives guidance to the reader as to what initiating events, probability modifiers and safeguards
can be applied to fired equipment.
This document gives guidance to the reader as to how initiating event frequencies, probability modifiers and
safeguards can be applied to fired equipment to determine a loss event frequency. To reduce the loss event
frequency, improvements can be applied as reductions in the initiating event frequency or in the form of
safeguards. Regardless of how improvements are classified, they are only counted once per hazard scenario.
The user of this document is informed that further or differing requirements can be needed for individual
applications. This document is not intended to inhibit a vendor from offering, or the purchaser accepting,
alternative equipment or engineering solutions for the individual application. This can be particularly
applicable where there is innovative or developing technology. Where an alternative is offered, the vendor
needs to detail any variations from this document.
v
Oil and gas industries including lower carbon energy – — Protective
system requirements for fired equipment
1 Scope
This document defines a risk-based program for determining protective system requirements for petroleum,
petrochemical and natural gas industry fired equipment including lower carbon energy. The process applies
to new or existing fired equipment.
For modifications to existing fired equipment that has been designed in accordance with this document, the
scope can be limited to changes.
This document applies to:
— — hazards that have potential to produce harm;
— — engineered and administrative forms of risk reduction.
NOTE 1 See Figure 1Figure 1 for a graphical representation of the hierarchy of risk reduction.
Figure 1 — Hierarchy of risk reduction and scope
NOTE 2 For guidance on elimination and substitution of hazards, see ISO 45001:2018, 8.1.2.
Figure 1 — Hierarchy of risk reduction and scope
NOTE 3 An example of hierarchy of risk reduction related to a natural draft gas-fired process fired heater is as follows:
— — Elimination - eliminate the gas-fired process heater combustion risk by replacing with electric heating;
— — Substitution - refinery fuel gas replaced with constant calorific value natural gas, for example, from a utility
pipeline;
— — Engineering function - install mass flow meter that compensates for composition change in refinery fuel gas;
— — Administrative function – maintain low occupancy around natural draft gas fired process fired heater.
The scope of this document excludes:
— — assessment of environmental impact, business impact or loss of reputation;
— — risk reductions in the forms of elimination, substitution, and personal protective equipment;
— — commercial fired equipment used for food preparation, space heating, small potable water heaters,
and other non-process applications such as small heaters used in maintenance applications.
2 Normative references
There are no normative references in this document.
3 Terms and definitions
For the purposes of this document, the following terms and definitions apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— — ISO Online browsing platform: available at https://www.iso.org/obp
— — IEC Electropedia: available at https://www.electropedia.org/
3.1 3.1
basic process control system
BPCS
combination of associated equipment, and either programmable systems or operators, or both that generate
output signals causing the process and its associated equipment to operate in the desired manner, but which
does not perform any safety instrumented function
3.2 3.2
competent person
competent personnel
person who has acquired through training, qualifications or experience, or a combination of these, the
knowledge and skills enabling that person to perform a specified task
3.3 3.3
control loop failure
failure of components or aspects of a control loop
Note 1 to entry: Examples of control loop failure include but are not limited to: sensor, controller, final element,
inadvertent set-point, loss of communication, loss of utility
3.4 3.4
facility operator
person, company, or organization that is responsible for the operations of a facility or worksite, or who has
the responsibility for a hazardous material or hazardous energy in a facility
3.5 3.5
fired equipment
device to convert fuel into heat by means of combustion, including the fuel gas train downstream of the fuel
supply manual shut-off valve, heat transfer sections, associated combustion air and flue gas handling systems,
instrumentation, controls and protection layers
3.6 3.6
flooded firebox hazard
presence of unburned fuel in firebox in the presence of an ignition source (flame), with sufficient calorific
value that when air is added, or fuel is quickly reduced an explosion may occur
3.7 3.7
flammable mixture hazard
presence of unburned fuel in the firebox in the presence of air, with sufficient calorific value that when an
ignition source is added an explosion can occur
3.8 3.8
flooding
continuing accumulation of unburned fuel in fired equipment where the injection of fuel is increased by the
feedback control of the primary process variable
EXAMPLE Coil outlet temperature for a heater.
Coil outlet temperature for a heater.
3.9 3.9
good practice
recognized minimum methods and measures addressing an aspect of the fired equipment that existed at the
time the fired equipment project’s final investment decision was approved
Note 1 to entry: Aspects can include but are not limited to procedures writing, mechanical design, instrumentation
specification and installation, logic solver specification and installation, controls design and installation, protection layer
design installation.
3.10 3.10
harm
injury or damage to the health of people, or damage to property or the environment
Note 1 to entry: For the purposes of this document, the definition of harm is further reduced to death, or irreversible
physical injury to individual.
[SOURCE: ISO/IEC Guide 51:2014, 3.1, modified — Note 1 to entry added.]
3.11 3.11
hazard
potential source of harm
[SOURCE: ISO/IEC Guide 51:2014, 3.2]
3.12 3.12
hazard scenario
sequence of events starting with an initiating event, potentially causing harm
3.13 3.13
independent protection layer
IPL
device, system, or action capable of preventing a scenario from proceeding to the undesired consequence
regardless of the initiating event or the action of any other protection layer associated with the scenario
[13][13]
]]
[SOURCE: CCPS
3.14 3.14
initiating event
IE
failure or error necessary to start the propagation of a hazard scenario
Note 1 to entry: Failure of an independent protection layer is not an initiating event.
3.15 3.15
loss event
LE
point in time in a hazard scenario when an irreversible physical event occurs that has the potential to cause
harm
Note 1 to entry: A primary loss event is sometimes the initiating event for one or more secondary loss events.
Note 2 to entry: Loss event is generally synonymous with hazardous event.
3.16 3.16
mode of operation
definable operating condition of process equipment as it progresses from shutdown to running and back to
shut down, where each mode of operation represents a unique operating regime that supports the process
equipment’s objectives of processing an input into a desired output
Note 1 to entry: Examples of modes of operation include but are not limited to: pre-firing, ignition, pilots only, normal
running, post-firing.
Note 2 to entry: Modes of operation can contain sub-modes, for example, purge is a sub-mode of pre-firing.
3.17 3.17
operational discipline
performance of all tasks correctly every time
[1][1]
[SOURCE: CCPS ]]
3.18 3.18
probability modifier
PM
dimensionless value that provides a numerical adjustment to the sequence, likelihood, consequence, and
severity associated with the hazard scenario
EXAMPLE Probability of a hazardous atmosphere, probability of ignition, probability of explosion, probability of
personnel presence, probability of injury or fatality, probability of equipment damage, probability of increasing air flow
after combustibles are present in the firebox and time at risk.
Note 1 to entry: Enabling conditions and conditional modifiers are probability modifiers.
3.19 3.19
process control narrative
design document describing how the basic process control system is configured and programmed, and how
the operator interacts with the system, to cause the process and its associated equipment to function in a
desired manner within its operating envelope
3.20 3.20
process state
PS
initial or intermediate operating condition of fired equipment in a hazard scenario
Note 1 to entry: Examples of process states are default, fuel accumulation and flammable mixture hazard.
3.21 3.21
protection layer
any independent mechanism that reduces risk by control, prevention or mitigation
[SOURCE: IEC 61511-1:2016+AMD1:2017, 3.2.57]
3.22 3.22
risk
combination of the probability of occurrence of harm and the severity of that harm
Note 1 to entry: The probability of occurrence includes the exposure to a hazard scenario, the occurrence of a hazardous
event and the possibility to avoid or limit the harm.
[SOURCE: ISO/IEC Guide 51:2014, 3.9]
3.23 3.23
residual risk
risk remaining after protection layers have been implemented
[SOURCE: ISO/IEC Guide 51:2014, 3.8]
3.24 3.24
safe
safety
freedom from risk which is not tolerable
[SOURCE: ISO/IEC Guide 51:2014, 3.14]
3.25 3.25
safeguard
any device, system, or action that either interrupts the chain of events following an initiating event or that
mitigates the consequences
Note 1 to entry: Not all safeguards will meet the requirements of an IPL.
[13][13]
[SOURCE: CCPS ]]
3.26 3.26
safety instrumented function
SIF
safety function to be implemented by a safety instrumented system
[SOURCE: IEC 61511-1:2016+AMD1:2017 3.2.67]
3.27 3.27
safety instrumented system
SIS
instrumented system used to implement one or more safety instrumented functions
[SOURCE: IEC 61511-1:2016+AMD1:2017 3.2.67]
3.28 3.27
tolerable risk
level of risk which is accepted in a given context based on the current values of society
Note 1 to entry: The terms “acceptable risk” and “tolerable risk” are considered to be synonymous.
[SOURCE: ISO/IEC Guide 51:2014, 3.15]
4 Normative requirements
4.1 General
These clauses and subclauses define the normative requirements for a risk-based program for determining
protective system requirements for fired equipment in the petroleum, petrochemical and natural gas industry
including lower carbon energy.
NOTE See Figure 2figure 2 for an informative flowchart representation of the risk-based program.
Figure 2 — Informative Flowchart of Risk-based program for determining protective system
requirements
4.2 Inputs
4.2.1 Good practice
The fired equipment shall be designed, operated, inspected, tested, and maintained in accordance with good
practice addressing the following aspects of the equipment:
— — fired equipment design;
— — instrumentation design;
— — controls design;
— — protection layer design;
— — logic solver design;
— — ongoing inspection, testing and maintenance;
— — operational discipline.
4.2.2 Documents
The following documents shall be provided as inputs to the risk-based process:
— — general arrangement drawings;
— — specifications;
— — Piping and Instrument Diagram (PID);
— — process control narrative;
— — procedures.
4.3 Hazard analysis team
The hazard analysis team shall include representatives from process safety, instrumentation, operations and
fired equipment engineering.
The hazard analysis team shall include representatives of other technical disciplines as determined necessary
by the facility operator, for example:
— — controls design;
— — protection layer design;
— — maintenance;
— — process engineering.
A minimum of three hazard analysis team members shall be familiar with fired equipment.
One competent person may fill multiple roles.
A hazard analysis team coordinator shall be appointed.
The team coordinator may also be one of the discipline representatives.
The team should be a collaboration between all companies that are involved with design, manufacture,
ownership, operation and maintenance of the fired equipment.
4.4 Hazard identification
4.4.1 Primary loss events
The primary loss events shall be identified.
NOTE 1 Examples of primary loss events include:
— — deflagration of accumulated gaseous fuel and air flammable mixture;
— — deflagration of accumulated volatilized components of liquid fuels and air flammable mixture;
— — pool fire of accumulated liquid fuel;
— — process tube loss of containment;
— — release of unburned toxic fuel;
— — large mass of water at boiling point and high pressure.
NOTE 2 For discussion of deflagrations, see informative Annex DAnnex D.
4.4.2 Hazards leading to primary loss events
Hazards that can lead to each primary loss event shall be identified.
NOTE 1 Examples of hazards include:
a) flammable mixture hazard (fuel and air in absence of source of ignition), including flame out, fuel left in firebox after
trip, leaking tube during pre-firing mode of operation.;
b) flooded firebox hazard (fuel and source of ignition in absence of air), including severely substoichiometric operation,
process tube failure, toxic fuel gas release.;
c) process hazards at the outlet of the fired equipment, including high process fluid temperature, high process fluid
pressure.
4.4.3 Escalation hazards following primary loss events
The hazard analysis team shall determine if shutting down the fired equipment has the potential to create
another hazard within the fired equipment or elsewhere in the facility.
NOTE For example, shutting down the heater cools the process unit quickly which can lead to a flange fire elsewhere
in the unit.
4.5 Hazard scenario progression diagram
4.5.1 Form and format
Hazard scenarios follow the general form shown in Figure 3Figure 3,, starting with an initiating event (IE)
occurring when the fired equipment is in the default process state PS and in a particular mode of operation,
potentially in the presence of probability modifiers PM and safeguards SG , that causes the fired
1(x) 1(x)
equipment to progress to a new intermediate process state PS . The sequence then continues through a further
intermediate process states PS via probability modifiers and safeguards before the loss event (LE) is reached.
Final probability modifiers PM and mitigative safeguards SG can then be applied prior to the harm event
4(x) 4(x)
(HE) occurring.
NOTE For a detailed explanation of example hazard scenario progression diagrams related to typical initiating
events, see informative Annex GAnnex G.
Key
PMx(a) probability modifier
PSx(a) process state
IE initiating event
LE loss event
HE harm event
SGx(a) safeguard
A fuel accumulation
B second constituent leading to creation of flammable mixture hazard
C deflagration
D harm
NOTE Where the facility operator applies a risk assessment methodology which involves multiple IE Figure 3 can
be modified accordingly.
Figure 3 — Example flammable mixture hazard scenario progression diagram with safeguards
Key
NOTE Where the facility operator applies a risk assessment methodology which involves multiple IE Figure 3 can be
modified accordingly.
4.5.2 Hazard scenario identification
4.5.2.1 General
For hazards identified in 4.4.24.4.2, the team shall identify hazard scenarios based on unique IEs addressing
the following clauses.
4.5.2.2 Modes of operation
Hazard scenarios shall be identified for all modes of operation.
Hazard scenarios shall be identified when the fired equipment is transitioning between modes of operation.
Hazard scenarios shall be identified where transient conditions occur within modes of operation.
NOTE Examples of transient conditions are fuel composition change, process feed composition change, unit charge
rate change.
4.5.2.3 Initiating events
Hazard scenario IEs shall be identified in the following categories:
a) internal to the fired equipment;
b) external to the fired equipment;
c) equipment failure;
d) Process control failure;
e) human failure.
NOTE 1 An example of internal IE is fuel gas basic process control system (BPCS) loop failure.
NOTE 2 Examples of external initiating events include 3rd party intervention, external gas cloud, lightning strike,
liquid or solids in fuel, or general utility failure.
NOTE 3 Examples of an equipment failure initiating events include a piping leak.
NOTE 4 Examples of process control failures include BPCS loop failure.
NOTE 5 Examples of human failures include closing one or more burner air registers while burners are in service, or
operator setpoint entry error.
4.6 Severity of harm and tolerability criteria
4.6.1 Severity of harm
The severity of harm associated with each hazard scenario shall be identified and quantified based on the
number of people subject to harm.
NOTE 1 The proximity of the fired [ equipment relative to occupied buildings and to the public can have a large impact
on the severity of harm.
NOTE 2 For guidance regarding deflagrations when quantifying the severity of harm, see Annex DAnnex D.
4.6.2 Risk criteria thresholds
The following threshold frequencies shall be provided based on severity of harm (4.5.1(4.5.1). ). These
thresholds may be the same:
— — threshold between unacceptable and tolerable risk,;
— — threshold between tolerable and broadly acceptable risk.
NOTE 1 Tolerable risk criteria can be determined in partnership with regulating bodies in certain jurisdictions.
[23], [24][23, 24]
NOTE 2 Tolerable risk criteria can be extrapolated from risk contours published in public documents .
4.7 Establishing predicted event frequency, tolerability and ALARP
4.7.1 Initiating event frequency
The IE frequency shall be determined for each hazard scenario based on facility operator data.
NOTE 1 Facility operator data can be derived from internal and external sources including industry reliability
[13][13
databases and CCPS reference
NOTE 2 Initiating event frequency is typically 0,1/year or greater, unless analysis justifies a value less than 0,1/year.
NOTE 3 Analysis methods for equipment failure IE frequencies include Failure Mode and Effect Analysis (FMEA).
NOTE 4 Analysis methods for human error IE frequency include Human Error Assessment and Reduction Technique
(HEART), Empirical Technique to Estimate Operator Errors (TESEO).
4.7.2 Safeguards
Safeguards shall be identified for each hazard scenario, as per normative Annex CAnnex C.
The average probability of failure on demand (PFD ) of the safeguard(s) shall be determined.
AVG
NOTE If there are no safeguards the PFD of the safeguard is 1.
4.7.3 Probability modifiers
Probability modifiers shall be determined for each hazard scenario.
When applicable, probability modifiers shown as PM , PM , PM and PM on Figure 3Figure 3 shall be
1 2 3 4
determined.
Limiting exposure of personnel to hazards may be a PM probability modifier or an SG administrative
4 4
protection layer, but it shall not be used as both in the same hazard scenario.
The product of all applicable probability modifiers, PM , PM , PM and PM , shall be determined.
1 2 3 4
NOTE 1 PM1, PM2 and PM4 probability modifiers are typically 0,1 or greater, unless analysis justifies a value less than
0,1.
NOTE 2 PM probability modifiers are typically 0,1 or greater, except for fired equipment that runs for a significant
amount of time above the auto-ignition temperature for fuels, where a value of less than 0,1 can be appropriate. See
informative Annex EAnnex E for details.
NOTE 3 PM is the location in the hazard scenario progression diagram where the 2nd constituent in the creation of
the flammable mixture hazard is introduced. See informative Annex FAnnex F for details on how this probability modifier
is used.
[14] [14]
NOTE 4 For guidance on probability modifiers see Reference
NOTE 5 The product of probability modifiers is typically 0,01 or greater, unless analysis capable of withstanding
scrutiny justifies a value less than 0,01.
4.7.4 Predicted event frequency
For each hazard scenario, the predicted event frequency, shall be determined as the product of the IE
frequency or frequencies (4.7.1(clause 4.7.1)) and the product of the PFD of the safeguard(s)
AVG
(4.7.2(clause 4.7.2)) and the product of all applicable probability modifiers, PM , PM , PM and PM
1 2 3 4
(4.7.3(clause 4.7.3).).
4.7.5 Predicted event frequency categorization
For each hazard scenario, the predicted event frequency determined in 4.7.4clause 4.7.4 shall be categorized
as unacceptable, tolerable, or broadly acceptable (see 4.6.2refer clause 4.6.2).).
If the predicted event frequency determined is broadly acceptable, further risk reductions are not necessary,
and further assessment shall not be required.
If the predicted event frequency determined is unacceptable, an additional SG shall be implemented, and the
PFD provided by the SG shall be determined, and the user shall proceed to subclause 4.7.3subclause 4.7.3.
If the predicted event frequency determined is tolerable but not broadly acceptable, a quantitative or
qualitative ALARP assessment shall be performed to determine if additional risk reductions are justified.
NOTE See Annex AAnnex A for guidance on quantitative ALARP and Annex BAnnex B for guidance on qualitative
ALARP.
4.7.6 Completion of risk reduction assessment procedure
If the predicted event frequency remaining after application of risk reductions justified by the ALARP
assessment is broadly acceptable or ALARP, further risk reductions are not necessary, and further assessment
shall not be required.
4.8 Ongoing Testing, Inspection and Maintenance
4.8.1 Inspection
The facility operator shall prepare procedures, schedules, and record retention policies for ongoing inspection
of fired equipment components.
NOTE 1 The purpose of the ongoing inspection program is to reveal developing component failures prior to a full
failure. Ongoing inspection procedures and schedules are based on applicable manufacturer’s recommendations,
industry standards, and prior operating experience.
NOTE 2 Application of a facility operator’s internal standard overlay to IEC 61511-1 meets the intent of this
requirement for instrumented protection layers.
NOTE 3 Application of a facility operator’s internal standard overlay to American Petroleum Institute (API)API RP 556
meets the intent of this requirement.
4.8.2 Testing
The facility operator shall prepare procedures, schedules, and record retention policies for ongoing testing of
fired equipment components.
NOTE 1 The purpose of the ongoing testing program is to reveal dangerous undetected failures of fired equipment
components that will cause the safeguard (SG) to fail to function upon demand. Ongoing testing procedures and schedules
are based on applicable manufacturer’s recommendations, industry standards, and prior operating experience.
NOTE 2 Application of a facility operator’s internal standard overlay to IEC 61511-1 meets the intent of this
requirement for instrumented protection layers.
4.8.3 Maintenance
The facility operator shall prepare procedures, schedules, and record retention policies for ongoing
maintenance of fired equipment components.
NOTE 1 Ongoing maintenance procedures and schedules are based on applicable manufacturer’s recommendations,
industry standards, and prior operating experience.
NOTE 2 Application of a facility operator’s internal standard overlay to IEC 61511-1 meets the intent of this
requirement for instrumented protection layers.
4.9 Training materials, schedules and record retention
The facility operator shall prepare training material, re-training schedules, and training record retention
policies for personnel involved in operation, ongoing inspection, testing, and maintenance of fired equipment.
NOTE 1 This training covers operational discipline, identification of process and fired equipment hazards, how to
identify and correct unsafe situations, procedures used as part of human independent protection layers (IPLs), as well as
procedures directing job tasks.
[13] [13]
NOTE 2 For qualification of operators used in human IPLs see Reference 5.2.2.5 and table 5.4
Annex A
(informative)
Quantitative ALARP subroutine
A.1 General
This annex presents informative guidance for an iterative quantitative “as low as reasonably practicable”
ALARP assessment.
NOTE See Figure A.1figure A.1 for a flowchart representation of the iterative quantitative ALARP assessment.
Figure A.1 — Quantitative ALARP Assessment Flowchart
A.2 Input variables
The value of preventing harm (VopH) is provided.
The discount factor for investment calculations (r) is provided.
The expected equipment lifespan used in investment calculations (t) is provided.
NOTE 1 This is a financial representation of the potential consequences of the harm event (HE).
[21]
NOTE 2 See Reference [21] for an example calculation of the value of harm.
A.3 Value of additional safeguards
A reusable function is created to determine the value of potential additional safeguards to further reduce the
risk.
NOTE The quantitative “as low as reasonably practicable” (ALARP) subroutine is written with the following example
formula:
𝑉𝑉𝑉𝑉𝑉𝑉𝑉𝑉𝑉𝑉𝑉𝑉𝑉𝑉𝐹𝐹 1
𝐽𝐽
𝑃𝑃𝑉𝑉 = ( ) (1− ( )) (A.1)
𝐽𝐽
𝑡𝑡
𝑟𝑟 (1+𝑟𝑟)
Where
PV is the present value (PV) following application of safeguard J, in monetary units which represents the money
J
available to implement the next risk reducing option
VopH is the value of preventing harm, in monetary units which is a financial representation of the potential consequences
of the HE
PEF is the predicted event frequency following application of safeguard J per annum
J
r is the discount factor, in percentage
t is the term of investment, in years
J is a series from 1 to N
A.4 Predicted event frequency after risk reductions
The predicted event frequency after application of good practice and extra risk reductions (4.7.5(clause 4.7.5))
is determined as PEF .
A.5 Safeguard zero
Safeguard is defined as the combination of good practice and extra risk reductions (4.7.5(clause 4.7.5).).
A.6 Present value after safeguard zero
The PV following application of safeguard SG is calculated as PV .
0 0
A.7 Evaluation List of potential safeguards
The user creates an evaluation list of potential additional SGs to further reduce the risk and designates it
SG .
1→→N
If there are no potential additional SGs (i.e., N=0), the predicted event frequency determined in
4.7.4clause 4.7.4 is considered to be already ALARP and the user proceeds to subclause 4.7.6subclause 4.7.6.
A.8 Estimate PFD and cost per safeguard
For each potential additional SG, the probability of failure on demand (PFD) and present value cost of
J J
implementation (PV ) is estimated.
J
A.9 Ranking of safeguards
The potential additional safeguard list SG is ranked from 1 to N in the following order:
1→→N
a) engineering functions from greatest to least risk reduction;
b) administrative functions from greatest to least risk reduction.
A.10 Predicted event frequency after safeguard J
Predicted event frequency following application of additional SG (PEF ) is determined as the product of the
J J
predicted event frequency following application of additional SG (PEF ) and the PFD of additional SG
J-1 J-1 J
(PFD ).
J
𝑃𝑃𝑃𝑃𝐹𝐹 = 𝑃𝑃𝑃𝑃𝐹𝐹 × 𝑃𝑃𝐹𝐹𝐷𝐷 (A.2)
𝐽𝐽 𝐽𝐽−1 𝐽𝐽
Where:
PEFj is the predicted event frequency following application of safeguard J per annum
PFDj is the probability of demand J per annum
A.11 Present value after safeguard J
The PV following application of additional SG (PV ) is calculated using Formula (A.1)A1.
J J
A.12 Benefit of safeguard J
The benefit of additional SG (BoS ) is calculated as the PV following application of additional SG (PV ) minus
J J J-1 J-1
the PV following application of additional SG (PV ).
J J
𝐵𝐵𝐵𝐵𝑆𝑆 =𝑃𝑃𝑉𝑉 −𝑃𝑃𝑉𝑉 (A.3)
𝐽𝐽 𝐽𝐽−1 𝐽𝐽
Where:
BoS is the benefit of the additional safeguard J
J
PV is the present value (PV) following application of safeguard J, in monetary units which represents the money
J
available to implement the next risk reducing option
A.13 Net present value of safeguard J
The net present value (NPV ) of additional safeguard J is calculated as the benefit of the additional SG (BoS )
J J J
minus the cost of additional safeguard J (PV ).
J
𝑁𝑁𝑃𝑃𝑉𝑉 =𝐵𝐵𝐵𝐵𝑆𝑆 − 𝑃𝑃𝑉𝑉
𝐽𝐽 𝐽𝐽 𝐽𝐽
(A.4)
Where:
NPV is the net present value of additional safeguard J
J
BoS is the benefit of the additional safeguard J
J
PV is the present value (PV) following application of safeguard J, in monetary units which represents the money
J
available to implement the next risk reducing option
A.14 Practicability of safeguard J
If NPV < 0 then additional SG is unjustified and is removed from the evaluation list, and the user sets value of
J J
PEF = PEF .
J J-1
If NPV ≥ 0 then additional SG is reasonably practicable.
J J
A.15 Categorization of predicted event frequency
Predicted event frequency is categorized as tolerable, or broadly acceptable.
A.16 Predicted event frequency is broadly acceptable
If predicted event frequency (PEF ) is broadly acceptable, further assessment is not required and the user
J
proceeds to 4.7.6subclause 4.7.6.
A.17 Additional safeguards remaining
If predicted event frequency (PEF ) is tolerable and there are additional SGs to be evaluated (i.e., J < N), the
J
user sets J = J + 1 and proceeds to A.10subclause A.10.
A.18 No additional safeguards remaining
If there are no additional SGs to be evaluated (i.e., J = N), predicted event frequency (PEF ) is ALARP, and the
J
user proceeds to 4.7.6subclause 4.7.6.
Annex B
(informative)
Qualitative ALARP subroutine
B.1 General
This annex presents informative guidance for an iterative qualitative “as low as reasonably practicable”
ALARP assessment. The ALARP process can be summarized by the following question: “can we do a little more
to make things a lot better?”
NOTE See Figure B.1figure B.1 for a flowchart representation of the iterative qualitative ALARP assessment.
Figure B.1 — Qualitative ALARP Assessment Flowchart
B.2 List of additional risk reduction options
The hazard analysis team identifies a list of additional risk reduction options (RR ).
1→→N
NOTE Source of additional risk reduction options can be those implemented in comparable fired equipment in
similar circumstances and locations.
B.3 No additional risk reduction options
If no additional risk reduction options can be identified (i.e., N = 0), predicted event frequency (PEF ) is ALARP,
J
and the user proceeds to 4.7.6subclause 4.7.6.
B.4 Risk reduction option ranking
The additional risk reduction options identified in B.2clause B.2 are designated RR to RR and ranked in order
1 N
from highest to lowest magnitude of risk reduction.
B.5 Reasonably practicable determination
For the additional risk reduction option with the highest magnitude of risk reduction, the hazard analysis team
determines if the option is reasonably practicable.
B.5.1 Reasonably practicable determination
The additional risk reduction option is deemed to be practicable if the technology is available to be
implemented and in the opinion of the team, the approximate cost is not grossly disproportionate to the
perceived risk reduction benefit.
NOTE Among other factors, the degree of gross disproportionality applied depends on the residual risk prior to
application of the proposed additional risk reduction option. Referring to region 2 of Figure B.2Figure B.2,, if the residual
risk is close to the threshold between unacceptable and tolerable risk, the justified cost (time, money, effort) of the
proposed additional risk reduction option can be significantly more than if the residual risk is close to the threshold
between tolerable and broadly acceptable.
Figure B.2 — Risk categorization visualization
B.5.2 Risk reduction reasonably practicable
When the further risk reduction option (RR ) is deemed to be practicable and reasonable it is reasonably
J
practicable and is implemented.
B.5.3 Risk reduction not reasonably practicable
If the additional risk reduction option (RR ) is not reasonably practicable, the risk reduction option may not
J
be implemented and RR is removed from the list of options identified in B.2clause B.2.
J
B.5.4 Predicted event frequency reassessed
If the additional risk reduction option (RR ) is reasonably practicable the predicted event frequency (PEF ) is
J J
reassessed including the new risk reduction option.
B.5.5 Predicted event frequency categorized
The predicted event frequency (PEF ) is categorized as tolerable or broadly acceptable.
J
B.6 Determine completion
B.6.1 General
Determine whether the qualitative ALARP sub-routine is complete or go back into the qualitative ALARP sub-
routine.
B.6.2 Complete - predicted event frequency is broadly acceptable
If the predicted event frequency (PEF) is categorized as broadly acceptable, then the user proceeds to
J
subclause 4.7.6subclause 4.7.6.
B.6.3 Incomplete - option not reasonably practicable and other options exist
If the additional risk reduction option (RR ) is not reasonably practicable and there are still unassessed risk
J
reductions options on the list (i.e.,. J < N), the user sets J = J + 1 and proceeds to B.5.1B.5.1 to assess the next
highest ranked unassessed option.
B.6.4 Complete - no options remaining
If no additional risk reduction options are determined to be reasonably practicable, the predicted event
frequency (PEF ) is ALARP, and the user proceeds to subclause 4.7.6subclause 4.7.6.
J
Annex C
(normative)
Safeguards and Independent Protection Layers
C.1 General
As per the
...







