Engineering Design Verification Inspections
Engineering Design Verification Inspections
01.01 Verify that the design authority (e.g., the organizations contracted by an NRC
applicant to provide engineering, procurement, and construction support) has developed
processes that allow for the complete and accurate transfer of the high level design
information and performance requirements specified in the Final Safety Analysis Report
(FSAR) into detailed procedures, specifications, calculations, drawings, procurement,
and/or construction documents, in a manner consistent with the requirements of Appendix
B to 10 CFR Part 50.
01.02 Verify that the design authority has developed processes to ensure changes to the
design are adequately controlled.
01.03 Verify, through a detailed technical review of selected systems, that the design
authority’s implementation of its design and design control processes has produced
detailed procedures, specifications, calculations, drawings, procurement, and/or
construction documents that are consistent with NRC regulations, the FSAR, and the
NRC’s Safety Evaluation Report (if issued).
It is anticipated that one EDV (and related follow-up inspections) will be completed for each
certified design.
The EDV inspection should be performed when the detailed design is complete for
at least 70% of safety systems. Design complete in this context means that the
initial detailed design is complete for the system. Additional activities to validate
the detailed design to actual “as purchased” or “as installed” component level data
may remain since these activities may be incomplete at the time of the inspection.
An additional limited scope EDV may be performed at a later date if detailed design
work for a significant system was not complete at the time of the initial EDV (such
as would be the case if the I&C system design was incomplete) or if significant
design validation activities remain to be completed.
The team leader should acquire the following documents which will be provided to
the team to aid in the system sample selection process:
documents listing the scope and standards for engineering and design
work expected to be done in the field
b. System Selection. Prior to selecting its inspection sample, the team should meet
with NRO’s Division of Safety Systems and Risk Assessment (DSRA), Division of
Engineering (DE), Division of Construction Inspection Programs and Operational
Programs (DCIP), and Division of Site and Environmental Reviews (DSER) to
obtain information on the systems, design features, and components that are
important based upon their relative risk significance . The NRO technical divisions
should also be asked to provide insights on systems and design features that they
believe would be good candidates for review during the inspection. Considering the
insights obtained above, the information obtained during the team’s pre-inspection
visit, and the following considerations, two systems should be selected for review:
In general, the systems selected for review should be mechanical systems. The
Electrical and Instrumentation and Control (I&C) features of the design should be
reviewed as supporting to the selected mechanical systems. Note: It is possible
that at the time this inspection is performed the detailed design for the I&C system
may be incomplete. In such cases, a separate inspection of the I&C system may
be required. In addition, at least one civil structure associated with the selected
mechanical systems should be reviewed.
It is important to note that the EDV is an inspection activity that is meant to assess
the adequacy of the design authority’s processes for developing and controlling the
detailed design and is not meant to take the place of specific technical reviews
performed as part of the licensing process or as part of ITAAC verification
inspections. As such, the EDV may not be able to cover all the technical staff’s
suggested systems and design features. In certain instances, and in order to meet
the objectives of the inspection, some inspection may also be authorized by the
team leader beyond the boundaries of the sample systems.
c. Notification of Design Authority of Sample Selection. At least two weeks prior to the
component data
The following inspection requirements should be completed for work controlled by the
design authority. Parallel inspection activities may be necessary for design work being
completed by sub-vendors under control of the design authority.
a. Design Program Review. Review the design authority’s processes that govern the
transfer of the high level design information and performance requirements into
detailed procedures, specifications, calculations, drawings, procurement, and/or
construction documents. Verify the design authority’s processes meet the
requirements of Appendix B to 10 CFR Part 50 as well as the applicable
requirements contained in the FSAR. This inspection requirement should be
completed by a subset of the inspection team as directed by the inspection team
leader. Ensure that sufficient processes are in place to validate the detailed design
against “as procured” and “as installed” component level data.
b. Design Document Review. For the selected sample, confirm that the design
documents have been prepared in accordance with the applicable design
procedures, specifications and instructions. Specific design control attributes to be
checked include:
design verification
document control
c. Design Technical Review. Utilizing the guidance contained in Appendix A for each
design discipline, verify that the design authority’s implementation of its design and
design control processes has produced detailed procedures (including
maintenance, operating, and emergency operating procedures), specifications,
Verify that the design authority has identified and entered design issues in the applicable
corrective action programs. Verify the adequacy of a sample of corrective actions for the
system(s) selected for review.
Refer to the guidance in Appendix A for discipline-specific design review attributes. The
information in Appendix A is intended to provide a focus for each inspection team
member’s discipline-specific reviews. An inspection team member is not required to
address all of the inspection elements in Appendix A, or restrict the scope of the inspection
to the inspection elements listed in the appendix.
This inspection is estimated to require 1280 hours of preparation time, 1600 hours of direct
inspection, and 800 hours of documentation (assuming a ten person team). This does not
include time for any follow-up inspection activities, the extent of which will vary based upon
the results of the inspection. Appendix B provides additional discussion of the projected
level of effort, program scope and timetable, and the team composition expected to be
used in the conduct of an initial or follow-up EDV inspection.
37805-05 REFERENCES
Appendix B to 10 CFR 50, “Quality Assurance Criteria for Nuclear Power Plants and Fuel
Reprocessing Plants”
An EDV inspection is completed when the staff has performed an inspection that meets the
END
The information in this appendix is intended to provide a focus for each inspection team
member’s discipline-specific reviews. An inspection team member is not required to
address all of the inspection elements in this appendix, or restrict the scope of the
inspection to the inspection elements listed in the appendix. While this inspection is not
meant to verify ITAAC, inspectors should be familiar with the ITAAC level design
requirements that apply to the selected systems and consider such requirements when
constructing their individual inspection plans. Applicable sections of the NRC’s Standard
Review Plan and associated Regulatory Guides may be referred to for additional guidance.
a. The overall design basis of the mechanical fluid system should be known by the
inspection team. Particular attention should be given to the functional and
performance requirements imposed on the system for the purpose of assuring
reactor safety. To accomplish a review of the mechanical fluid system, the
inspection team should review the design requirements in the FSAR as well as the
system description for the selected fluid system.
e. Verify that the portions of the system penetrating the containment barrier are
designed with isolation features that are acceptable for maintaining containment
integrity for all operating and accident conditions. Check interfaces with the
instrumentation and control functional area relative to isolation valve actuation and
control.
f. Evaluate the classification of the structures related to the selected fluid system for
conformance to the requirements for safety-related systems. Evaluate the
spectrum of conditions that have been considered in the design of the structures.
Evaluate the loading conditions that arise from events such as pipe rupture, LOCA,
earthquakes, operational transients, reactor trip, loss of component cooling, etc.
g. Verify the compatibility of the materials and components of the selected fluid
system with the service conditions, including normal and accident conditions as well
as the design life. Ensure that the fluid system's components have proper safety
and code classifications.
b. Review all input information used in the piping analysis. This will require
coordination with other team members to determine that the correct design inputs
are used. Verify that the piping analysis will be updated to incorporate as-built
information, when that data becomes available.
c. Review the model used in the piping analysis. This includes review of the analyses
performed (thermal, deadweight, seismic, etc.), review of the computer programs
d. Review stress and support load summary sheets for correct load combinations as
specified in the FSAR. Also verify that these documents have been transmitted to
the appropriate group for support evaluations.
e. Review component design reports to verify that the basic premises are correct and
that data are in conformance with the design requirements of the FSAR. Review
test qualification documents, if applicable, including correctness of the test
parameters for conformance with the design requirements of the FSAR. This
review should verify that the loads from the piping analysis are included in the
component evaluation.
f. Review valve design reports for conformance with the design requirements of the
FSAR. Particular attention should be given to the operability evaluation for seismic
events. Also, valve actuator qualification documentation should be reviewed for
conformance with licensee commitments the design requirements of the FSAR.
g. Review the loads used in the evaluation of pipe supports and verify that these are
the correct loads from the piping analysis. Review the support analysis for
conformance with the design requirements in the FSAR and procedures. The load
combinations should be checked for the correct specification of primary and
secondary loadings. Verify that integral attachments have been evaluated for their
effects on the piping and that buckling of compression members has been
considered. For spring hangers and snubbers, verify that thermal movements were
considered. Review the attachments to the structure and verify that the loads have
been considered by the structural group.
a. Identify the location of the fluids system selected. Include associated equipment,
such as:
● power supplies
● control systems
● piping supports
b. Verify that structural safety categories are consistent and correct. Consider the
location and possible effect of non-safety-related items on the fluids system.
Review the safety categories defined in FSAR Section 3 and the classification of
structures. Compare the safety categories of the mechanical fluid system selected
against these criteria for compatibility.
c. Review the model and boundary conditions used in the structural analysis of the
design configuration utilizing the output and information from other functional areas
such as mechanical, electrical power, instrumentation and control, and systems
design to verify the correctness. Also review the output provided from the civil-
structural area to the other disciplines. Assess the safety impact of these reviews.
d. Verify that all pertinent loads and load combinations are considered in the analysis
of structural elements, in addition to the piping system. Ensure that appropriate
codes and standards are used in the design of structures. Examine the sensitivity
of the structural analysis and design to changes in piping system loads, supports,
and configurations as well as the influence on resulting structural deformations.
Emphasis should be placed on the identification of the discipline boundaries and
necessary interfaces in the design process. Determine that the correct loads and
load combinations have been used and that methods for combining loads or load
elements are correct.
e. Review samples of the design calculations based on the internal forces resulting
from the analyses. Determine that the design techniques committed to in the FSAR
have been or are being met. Also review specific areas of the design calculations.
g. Review examples where the basic design documents are used to produce product,
components, or elements that will be integrated into the final structure. This review
would include such items as fabrication and shop drawings, produced by a
subcontractor, or installation procedures, defined by a supplier.
h. Review and evaluate the process by which design documents are checked and
verified and the process by which the final documents are issued for use and
construction.
i. Review and evaluate several types of design changes, such as those initiated by:
field engineering
j. Review and evaluate the acceptance process used in the civil-structural area for
final acceptance of the structures or elements thereof, including the incorporation of
as-built information, when that information becomes available.
k. Review the seismic analysis of one seismic Category I structure that is associated
with the sample system being inspected.
Note: for passive plants the electrical review should focus on the Class 1E safety related
portions of the system (generally batteries and 120 VAC). Other non-safety portions of the
electrical system may be reviewed based upon their relative risk significance.
a. Identify all components of the mechanical fluid system selected that require electric
power to perform their safety function(s). Determine if the electric power system
supplying power to each of these components will be capable of providing the
required electric energy as needed by each component. Examine required voltage,
current, and frequency (maximums, minimums, and nominal including transient
values) and compare with power source voltage, current and frequency for several
sample sets of conditions representative of maximum and minimum loads and
expected perturbations on the power source. Determine if required power quality
can be provided for the needed time of interest. A review of diesel generator (or
other stand-by power source such as a gas turbine generator) load sequencing of
b. Identify all components of the mechanical fluid system that require disconnection
from their electric power source in order to perform their safety function. Review
the control circuit for at least two such components to determine if it meets its
design requirements. Focus on time allowed for disconnection from power source
in the electric power system design and the corresponding time assumed in safety
analysis.
c. Examine the control relaying for at least two components of the mechanical fluid
system that require power to perform their safety function and two components that
require power disconnection to perform their safety function. Evaluate the
documentation and actual installation of these circuits and assess the ability of the
circuits to perform as required.
d. For several samples of each kind of electric component (i.e., motors, valve
operators, relays, connections, cables), determine if the design meets acceptance
criteria for performing the required safety function in the presence of the most
severe environment specified in the component's design bases. Verify that
acceptance criteria are consistent with licensee commitments the design
requirements in the FSAR.
test results showed the equipment able to meet specified performance under
the design-basis conditions specified
h. Examine methods and procedures for providing electric power to operable electric
equipment when the normal offsite source and the normal onsite emergency source
are unavailable. Determine if these methods or procedures could compromise
redundant power source independence or prevent supply of electric power to one
Issue Date: 04/25/11 A-6 37805
or more redundant loads.
i. Confirm the power distribution system to safety-related electric loads has been
adequately designed with regard to breaker, motor starter, and cable sizing, as well
as breaker coordination. Review several sample calculations in this area.
j. For at least 2 electric loads, determine the basis for interruption of electric power in
the case of an electric power demand in excess of the normal rating for the loads.
Determine what basis was used to decide if the system was designed to ensure the
performance of the safety function or to protect the equipment in cases of
overloads. Review design of electric motor-operated valves provided with torque
switches used to cause motor shutdown when excess torque is detected.
Determine the validity of basis for torque switch settings. Review procedures for
testing such switches.
k. Examine specifications for several items of electric equipment and compare to the
expected environment in their designated location to determine if special
environmental controls should have been provided or if a different location should
have been selected.
l. Determine how the need for special environmental controls (e.g., battery room
ventilation) on electric equipment was determined. Review design documentation
(descriptions, drawings, etc.) to determine how the environment is to be maintained
and how operating personnel are made aware of the needs for these special
environmental controls.
Note: Depending on the timing of this inspection, significant portions of the Instrumentation
and Control System may be incomplete. In such cases, the team’s review should consist of
verifying the details of the design to the maximum extent practicable. As an option, an
additional limited scope inspection of the I&C system may be performed at a later date.
b. Review all input information used for the design. It will be necessary to Interface
with the electrical power system design and the mechanical system design. Verify
that the design input parameters meet the design requirements for the fluid system
design. This should include the ranges of system process parameters required for
normal and accident conditions.
g. Review the system description for any unusual operating requirements. Examples
of these requirements could be: special operation required of the systems during
and after an accident, capability of the systems to shut down the reactor from a
remote location, or any special automatic/manual control features.
h. Verify that the instrumentation and control system detects and maintains essential
parameters during all anticipated plant conditions. Check if the capability to provide
the required detection and control during loss of offsite power, or other anticipated
operational occurrences and accident conditions meets design requirements.
k. Review procedures and basis for developing set points. Verify setpoints for a
sample of instruments were properly established, including consideration of any
relevant as-built deviations from the original design.
l. Review sample I&C valve data sheets to make sure that appropriate process data,
setpoints, accuracy specifications, and other features have been correctly
considered.
m. Verify that all attributes of control system input and output points have been
appropriately implemented.
n. Review the detailed I&C architecture diagrams to assure that all applicable
o. Ensure that the control room design is consistent with the detailed I&C architecture
diagrams.
p. Review sample control room screen graphics to ensure that the control system
input and output points and their functions have been correctly specified.
q. Check the traceability for the implementation of sample I&C functions and
requirements.
END
b. Level of Effort. The NRC staff should perform the EDV inspection when the
detailed design is complete for at least 70% of the safety systems. Design
complete in this context means that the initial detailed design is complete for the
system. Additional activities to validate the detailed design to actual component
level data may remain, since final procurement activities may have yet to be
completed. An additional limited scope EDV may be performed if detailed design
work for a significant system was not complete at the time of the initial EDV (such
as would be the case if the I&C system design was incomplete). The NRC staff will
perform additional inspections to follow up on identified problems and to verify
corrective actions. The NRC staff will perform a sufficient number of follow-up
inspections after the initial EDV inspection has been performed for the defined
scope of review to confirm that the design authority has adequately closed any
inspection team’s initial findings.
Time
EDV Inspection Activity Allocation
(Weeks)
Team Preparation 2
- Team Indoctrination Meeting
- Review of Information Obtained from Pre-inspection visit
- Meetings with NRO technical divisons
- System Selection
- Preparation of Draft Inspection Plans
Specific inspection and experience needs for a particular team will depend on the
certified design, the system or systems selected in the sample, and the safety and
risk significance of specific disciplines such as digital instrumentation and controls
(I&C). Some inspections may require the use of contractor support to augment
available NRO and Regional staff.
At the conclusion the inspection, the inspection team should discuss their
preliminary findings with the design authority’s management at a scheduled exit
meeting. These exit meetings may be scheduled on the last day of planned
inspection activities or deferred until some later date after a team meeting / briefing
of NRC management personnel. The design authority should be briefed on
ongoing inspection results daily over the course of the inspection.
END









