Calculator D2

LOPA vs. HAZOP vs. QRA: When to Use Each Method

LOPA, HAZOP, and QRA are three different safety analysis tools: HAZOP finds possible hazards, LOPA checks if safety layers are strong enough, and QRA calculates how likely and severe accidents really are.

Industry Applications
Chemical processing, oil & gas refining, pharmaceutical manufacturing, LNG terminals
Key Standards
IEC 61511 (functional safety), CCPS Guidelines (Center for Chemical Process Safety), ISA 84.00.01
Typical Scale
Applied per scenario (not per unit); average 5–15 scenarios per process unit; 2–4 hours per scenario

⚠️ Why It Matters

1
Inadequate hazard identification
2
Missed credible ignition or escalation pathways
3
Underestimated frequency of high-consequence events
4
Insufficient IPL redundancy or reliability
5
Failure to meet corporate risk tolerance or regulatory ALARP requirements
6
Regulatory non-compliance leading to operational stoppage or enforcement action

📘 Definition

Layer of Protection Analysis (LOPA) is a semi-quantitative method used to evaluate the adequacy of independent protection layers (IPLs) against specific hazardous scenarios by estimating initiating event frequency and IPL failure probabilities. It bridges qualitative hazard identification (e.g., HAZOP) and fully quantitative risk assessment (QRA), assigning risk reduction factors (RRFs) to IPLs and verifying whether the residual risk meets tolerable risk criteria. LOPA is standardized in IEC 61511 and CCPS guidelines, requiring explicit definition of scenario causality, IPL independence, and verification of IPL effectiveness.

🎨 Concept Diagram

HAZOP → LOPA → QRA Workflow1HAZOP2LOPA3QRAQualitative hazard IDSemi-quant IPL validationFull frequency/consequence modeling

AI-generated illustration for visual understanding

💡 Engineering Insight

LOPA is not a substitute for engineering judgment — it is a consistency check. A 'passing' LOPA with SIL-2 SIS does not guarantee safety if the IPL’s response time exceeds process dynamics (e.g., runaway reaction time < 2 min), or if human IPLs rely on untrained personnel during night shift. Always validate IPL timing, diagnostics coverage, and human factors context — not just PFD numbers.

📖 Detailed Explanation

LOPA begins by isolating a single hazardous scenario — such as 'vessel overpressure due to cooling water failure' — derived from prior HAZOP studies. The analyst identifies one initiating event (e.g., 'control valve fails closed') and estimates its frequency using sources like OREDA, exida, or site-specific failure history. This establishes the 'unmitigated' risk baseline.

Next, each proposed IPL (e.g., pressure relief valve, high-pressure shutdown system, operator intervention) is rigorously assessed for independence: it must act without reliance on components or signals used by other IPLs, and its failure must not affect others. PFD is assigned using recognized reliability data, with conservative assumptions applied where uncertainty exists (e.g., using upper 90% confidence bound for PFD).

At advanced levels, LOPA integrates dynamic considerations: time-to-failure vs. time-to-intervention (TTI), common cause failures (CCF) via beta-factor or MGL models, and uncertainty propagation using Monte Carlo methods. Modern practice also links LOPA outcomes directly to SIS configuration (e.g., 1oo2 vs. 2oo3 architecture), proof test intervals, and diagnostic coverage requirements — making it a living input to functional safety lifecycle execution, not a static worksheet.

🔄 Engineering Workflow

Step 1
Step 1: Define scope and hazardous scenario (from HAZOP or incident history)
Step 2
Step 2: Identify credible initiating event(s) and estimate frequency using historical data or industry databases
Step 3
Step 3: Identify candidate Independent Protection Layers (IPLs) and verify independence, reliability, and auditability
Step 4
Step 4: Calculate PFD for each IPL and aggregate RRF; compute residual scenario frequency
Step 5
Step 5: Compare residual frequency against tolerable risk target — accept, reject, or recommend risk reduction
Step 6
Step 6: Document IPL verification evidence (e.g., SIL certification, maintenance logs, response time tests)
Step 7
Step 7: Integrate findings into Safety Requirements Specification (SRS) and management of change (MOC) process

📋 Decision Guide

Rock/Field Condition Recommended Design Action
Scenario with high consequence (e.g., toxic release >1 ton) but low initiating frequency (<1E−3/yr) and no existing IPLs Perform LOPA to quantify required RRF; assign SIL-2 SIS + procedural IPL (e.g., operator response <10 min) with documented independence and testing.
HAZOP identified multiple credible scenarios sharing one common IPL (e.g., shared DCS alarm system) Reject as invalid IPL; redesign to ensure true independence (e.g., separate hardwired SIS) or split scenarios and re-evaluate each separately.
PFD uncertainty exceeds ±1 order of magnitude (e.g., based on generic OREDA data without site-specific proof test records) Treat as 'LOPA not valid'; escalate to QRA or require empirical reliability data before proceeding.

📊 Key Properties & Parameters

Initiating Event Frequency (IEF)

1E−6 to 1E−1 /yr (e.g., 0.1/yr for common operator errors; 1E−6/yr for SIS hardware failures)

Estimated frequency per year at which a specific hazardous initiating event (e.g., valve failure, human error) occurs.

⚡ Engineering Impact:

Drives required Risk Reduction Factor (RRF) — lower IEF allows higher PFD for same target risk.

PFD (Probability of Failure on Demand)

1E−2 to 1E−4 (e.g., 0.01 for manual shutdown; 1E−4 for SIL-3 certified SIS)

The likelihood that an Independent Protection Layer (e.g., SIS, relief valve) will fail to perform its required safety function when demanded.

⚡ Engineering Impact:

Directly determines achievable RRF (RRF = 1/PFD); governs SIL assignment and verification testing intervals.

Risk Reduction Factor (RRF)

10 to 10,000 (corresponding to SIL 1–4 per IEC 61511)

The factor by which an IPL reduces the frequency of a hazardous scenario (RRF = 1 / PFD).

⚡ Engineering Impact:

Determines whether a proposed IPL satisfies the required risk reduction to achieve tolerable risk (e.g., RRF ≥ 100 needed if IEF = 0.1/yr and target = 1E−3/yr).

Tolerable Risk Target

1E−4 to 1E−6 fatalities/year (e.g., 1E−4/yr for site boundary offsite fatality per UK HSE guidelines)

The maximum acceptable frequency of a specific consequence (e.g., fatality, major release) defined by corporate policy or regulation.

⚡ Engineering Impact:

Sets the numerical threshold against which LOPA-calculated residual risk is compared — drives design decisions and IPL justification.

📐 Key Formulas

Residual Frequency

f_res = f_init × PFD₁ × PFD₂ × ... × PFDₙ

Calculates post-IPL frequency of a hazardous scenario

Variables:
Symbol Name Unit Description
f_res Residual Frequency 1/year Post-IPL frequency of a hazardous scenario
f_init Initial Frequency 1/year Frequency of hazardous scenario before IPLs
PFD₁ Probability of Failure on Demand for IPL 1 dimensionless Probability that the first independent protection layer fails when required
PFD₂ Probability of Failure on Demand for IPL 2 dimensionless Probability that the second independent protection layer fails when required
PFDₙ Probability of Failure on Demand for IPL n dimensionless Probability that the nth independent protection layer fails when required
Typical Ranges:
Refining unit overpressure
1E−6 to 1E−3 /yr
Pharma reactor runaway
1E−7 to 1E−4 /yr
⚠️ Must be ≤ tolerable risk target (e.g., ≤1E−4/yr)

Required Risk Reduction Factor (RRF_req)

RRF_req = f_init / f_target

Minimum RRF needed from IPLs to meet tolerable risk

Variables:
Symbol Name Unit Description
RRF_req Required Risk Reduction Factor Minimum RRF needed from IPLs to meet tolerable risk
f_init Initial Frequency of Hazardous Event per year Frequency of the hazardous event before implementation of IPLs
f_target Target Frequency of Hazardous Event per year Maximum tolerable frequency of the hazardous event after implementation of IPLs
Typical Ranges:
Low-frequency, high-consequence (e.g., BLEVE)
100 – 10,000
Moderate-consequence leak
10 – 100
⚠️ RRF_req must be achievable by verified IPLs; if not, add IPLs or reduce f_init (e.g., eliminate hazard)

🏭 Engineering Example

ExxonMobil Baton Rouge Refinery — Coker Fractionator Overpressure Scenario

N/A (process safety context)
PFD_PSV
5.0E−3 (mechanical relief valve, inspected annually per API RP 576)
PFD_SIS
1.8E−3 (SIL-2 certified DCS-based shutdown system, tested quarterly)
Tolerable Risk Target
1.0E−4 fatalities/year (corporate ALARP criterion for onsite fatality)
Initiating Event Frequency
3.2E−3 /yr (cooling water control valve failure, based on 12-year site log)

🏗️ Applications

  • SIL assignment for safety instrumented systems
  • Justification of mechanical IPLs (e.g., PSVs, dikes)
  • ALARP demonstration for regulatory submissions (e.g., COMAH, OSHA PSM)

📋 Real Project Case

Chemical Reactor Overpressure Mitigation at Midwest Petrochemical Plant

Retrofit of exothermic batch reactor system handling nitration chemistry

Challenge: Uncontrolled reaction runaway leading to overpressure exceeding MAWP; prior relief valve sizing base...
Chemical Reactor Overpressure MitigationMidwest Petrochemical Plant • LOPA-Validated IPL HierarchyIE0.5/yrHAZOP 'High Temp'DCS AlarmNon-SIS • Alert onlySISPFD = 0.012Dual PTs + SolenoidRVMechanicalMAWP ≥ PmaxOperator ResponseRRF = 15 • Procedure-basedInitiating EventNon-SIS IPLSIS IPLMechanical IPL
Read full case study →

🎨 Technical Diagrams

HAZOP: Qualitative Hazard IDLOPA: Semi-Quantitative IPL ValidationQRA: Fully Quantitative Risk Model
IEFPFDRRF✓/✗

📚 References