HAZOP and other qualitative and quantitative risk assessment methodologies are regulary applied to chemical and other high hazard processes.

Such process are being increasingly governed by software systems. These include, but are not confined to, emergency shutdown systems. How do we assess the reliability of the software system and determine if its actions can create a safety issue.  Assignment of  Safety Integrity Levels indicates what level of reliability is required. In principle, instrumentation is purchased, installed and tested accordingly. A complex system would normally be accompanied by logic diagrams, typically bespoke to the client process. Checking this logic is not always part of the HAZOP, using the same principle as a process HAZOP ( e.g. loss of voltage, missing connection…). But if it is checked, how do we ensure that the software is installed in accordance with the logic diagrams.   Interlock tests are carried out both before commissioning and periodically thereafter. However software systems are more complex in their objectives that simply interlocks.

There are excellent examples of software failure in the aviation industry where software to control the aeroplane in certain situations did not behave as intended, with disastrous consequences.

At least in a chemical plant or other physical process, and engineer can go out and visually check the pipelines and presence of the instruments in accordance with the Piping and Instrumentation Diagram. Should we not have a similar process for software?

User Comments ( 1 )

  • Trevor Hughes

    Comment from John

Give a Reply