AI Quick Summary

Build a safety-critical equipment register that links major-incident barriers to performance standards, inspection tasks, proof tests, and impairment controls.

Safety-Critical Equipment: How to Build and Maintain the Register

Two pumps stop during a maintenance backlog. One transfers wash water. The other supplies firewater to the tank farm. A maintenance priority code that treats both pumps alike hides the difference in consequence.
Safety-critical equipment (SCE) performs a function that prevents, detects, controls, or mitigates a major incident. A safety-critical equipment register tells the facility which items protect each major-incident scenario and what performance the items must deliver.

Download: MMRisk Safety-Critical Equipment Register Template (PDF) or use the print-friendly version.

Start with barriers, not equipment value

Cost, production importance, and repair time matter for maintenance planning. They do not define process-safety criticality.
Start from the hazard studies:

  • HAZOP and LOPA recommendations;
  • BowTie diagrams;
  • MHI risk assessment and QRA scenarios;
  • emergency response analysis;
  • incident and near-miss findings.
    For each scenario, list the barriers that must work. Then identify the equipment, software, utilities, structures, procedures, and human actions that deliver each barrier.
    Examples include:
  • tank overfill prevention and independent high-high trip;
  • pressure relief and safe disposal;
  • gas detection and automatic isolation;
  • safety instrumented functions;
  • firewater, foam, deluge, and passive fire protection;
  • bunding and contaminated drainage control;
  • emergency power, communications, and shutdown;
  • critical alarms with operator response;
  • corrosion monitoring and containment inspection.

Define the required safety function

"Gas detector" is an equipment description. A performance standard states what the barrier must achieve.
Record:

  • the hazard scenario and barrier;
  • required function;
  • demand or initiating condition;
  • response time;
  • capacity, accuracy, coverage, or set point;
  • availability or reliability requirement;
  • survivability during the event;
  • inspection, test, and maintenance method;
  • acceptance criteria;
  • responsible owner.
    For a remote isolation valve, the function may include closing within a defined time, achieving tight shutoff, remaining operable after loss of normal power, and being accessible from a safe location.

Use a clear criticality test

Ask four questions:

  1. Can failure of the item initiate a major incident?
  2. Can failure allow an initiating event to escalate?
  3. Does the item provide a credited preventive or mitigative barrier?
  4. Does the risk assessment assume that the item remains available or reliable?
    A "yes" answer should trigger SCE review. Document exclusions so future teams can understand the basis.

Connect the register to maintenance

Every SCE entry needs an executable assurance task. Examples include:

  • calibration and functional test;
  • proof test of an instrumented function;
  • stroke test of an emergency valve;
  • relief-device inspection and certification;
  • firewater flow or pump test;
  • gas-detector bump and coverage test;
  • inspection of passive fire protection;
  • thickness measurement or corrosion monitoring;
  • operator-response drill for a critical alarm.
    The maintenance system should flag SCE work, due dates, failures, deferrals, and repeated defects. A separate spreadsheet that does not drive work orders will fall out of date.
    Our asset integrity guide explains how to select inspection methods and act on degradation data.

Define acceptance criteria before the test

"Test passed" has little value without a standard.
Set measurable criteria:

  • valve closure time less than the scenario response limit;
  • detector alarm within the stated concentration tolerance;
  • pump flow and pressure above the firewater demand;
  • trip set point within the approved range;
  • relief device certification current and installation correct;
  • corrosion measurement above minimum allowable thickness;
  • alarm response completed within available process safety time.
    Record the actual result, not only a tick box.

Control impairments

Equipment can become unavailable through failure, testing, maintenance, bypass, override, isolation, or loss of a supporting utility.
An impairment process should state:

  • which barrier and scenarios are affected;
  • expected duration;
  • temporary controls and operating restrictions;
  • extra monitoring or staffing;
  • communication to operations and emergency teams;
  • approval authority;
  • restoration checks and closure.
    If a firewater pump is out of service, the decision may affect hot work, tank transfers, inventory, or the number of units allowed online. The control should match the scenario, not the repair department's convenience.
    Route long-term or design changes through Management of Change.

Include human and procedural barriers with care

Some scenarios rely on an operator responding to an alarm, a permit issuer checking an isolation, or an emergency team deploying equipment. Treat these as managed barriers, but do not make them look as reliable as automatic engineered protection without evidence.
Define:

  • cue or alarm;
  • required action;
  • available response time;
  • procedure and training;
  • staffing and access;
  • communication;
  • drills or assurance checks.
    Our human factors guide shows how to analyse the conditions around safety-critical tasks.

Review the register when the plant changes

Update the SCE register after:

  • HAZOP, LOPA, BowTie, or QRA changes;
  • an MOC or new project;
  • incident findings;
  • repeated test failures;
  • new degradation mechanisms;
  • changed operating limits or inventory;
  • revised emergency scenarios;
  • decommissioning or long-term bypass.
    Verify the register during Pre-Startup Safety Reviews and PHA revalidation.

Report barrier health to leaders

Useful metrics include:

  • overdue SCE tasks by barrier and scenario;
  • failed tests awaiting repair;
  • active impairments and duration;
  • repeated defects;
  • temporary controls past review date;
  • demand events where the barrier succeeded or failed;
  • register items without current performance standards.
    One green maintenance-compliance number can hide a red firewater or shutdown-system problem. Report the condition of the barriers that protect the site's highest-consequence scenarios.
    Recent process-safety discussions still show a practical gap between identifying SCEs and rationalising the register. The useful question is not "how many critical items do we have?" but "which items are genuinely credited for a major-incident barrier, and can we prove they meet the performance standard?"
    MMRisk helps facilities build BowTie models, identify safety-critical equipment, define assurance standards, and connect maintenance evidence to MHI risk assessments. Contact our process safety team to review your barrier register.

Related resources

Sources