Kathmandu University
Chemical Process Safety
System Designs
Dr. Ziaul Haque Ansari
Department of
Chemical Science and Engineering
Table of Contents
Bottle of Isopropyl Ether
Nitrobenzene Sulfonic Acid Decomposition
Organic Oxidation
Lessons Learned
Introduction
When new plants are constructed or when modifications are
needed in existing plants, detailed process designs are required.
These designs must include special safety features to protect the
system and operating personnel.
The following case histories emphasize the importance of
these special safety design features.
Ethylene Oxide Explosion
A process storage tank contained 6500 gal of ethylene oxide.
It was accidentally contaminated with ammonia.
The tank ruptured and dispersed ethylene oxide into the air.
A vapor cloud was formed and almost immediately exploded.
It created an explosive force equivalent to 18 tons of TNT, as
evidenced by the damage.
The events happened so rapidly that personnel could not take
appropriate cover.
One person was killed and nine were injured; property losses
exceeded $16.5 million.
Ethylene Oxide Explosion
This accident was attributed to the lack of design protection to
prevent the backup of ammonia into this storage tank.
It also appears that mitigation techniques were not part of the
system (deluge systems, dikes, and the like).
Ethylene Explosion
Failure of a 3/8-in compression fitting on a 1000-2500-psi ethylene
line in a pipe trench resulted in a spill of 200-500 lb of ethylene.
A cloud was formed and ignited, giving an explosion equivalent to
0.12-0.30 ton of TNT.
This accident took place in a courtyard, giving a partially confined
vapor cloud explosion.
Two people were killed and 17 were injured; property loss was $6.5
million.
Ethylene Explosion
The probable causes of this accident include
1. use of nonwelded pipe,
2. installation of pipe in trenches, resulting in an accumulation of
flammable vapors, and
3. lack of automated vapor detection analyzers and alarms.
Butadiene Explosion
A valve on the bottom of a reactor accidentally opened because of
an air failure.
The spill generated a vapor cloud that was ignited 50 ft from the
source.
About 200 gal of butadiene spilled before ignition.
Overpressures of 0.5-1 psi were estimated.
Three people were killed and two were injured.
Butadiene Explosion
Probable causes of this accident include
1. installation of a fail-open valve instead of a fail-closed valve,
2. lack of vapor detectors,
3. lack of a block installed as a mitigating device, and
4. failure to eliminate ignition sources in this operating region.
Light Hydrocarbon Explosion
A pipe failed and resulted in a spill of 16,800 lb of light hydrocarbons.
A vapor cloud developed and ignited.
The explosion knocked out the deluge systems and electrical supplies
to the fire pumps.
Significant damage resulted from the subsequent fires.
The maximum overpressure was estimated from the damage to be 3.5
psi at 120 ft.
An equivalent of 1 ton of TNT was estimated, giving an explosion
yield of approximately 1% of the total energy source.
Light Hydrocarbon Explosion
This accident had two fatalities and nine injuries.
The total damage was estimated to be $15.6 million.
The magnitude of this accident could have been reduced with
(1) improved pipe design,
(2) improved deluge system design,
(3) backup or more secure electrical supply, and
(4) Installation of detection analyzers and block valves.
Pump Vibration
Vibration from a bad pump bearing caused a pump seal to fail in a
cumene section of a phenol acetone unit.
The released flammable liquids and vapors ignited.
An explosion ruptured other process pipes, adding fuel to the original
fire.
Damage to the plant exceeded $23 million.
This accident could have been prevented by a good inspection and
maintenance program.
Potential design improvements include vibration detectors, gas
analyzers, block valves, and deluge systems.
Pump Failure
A pump roller bearing failure in a crude oil refinery initiated the
fracture of the motor shaft and the pump bearing bracket.
The pump casing then broke, releasing hot oil, which autoignited.
Secondary pipe and flange failures contributed fuel to the fire.
Plant damage totaled over $15 million.
Because the pump was equipped only with manually operated suction-
side valves, the valves could not be reached during the fire.
Automated block valves would have minimized damage in this fire.
A good inspection and maintenance program would have prevented
the accident.
Ethylene Explosion
A drain fitting in a high-pressure (40 kpsi) compressor line broke,
allowing ethylene to escape.
The ethylene cloud drifted and entered the intake system of an engine
that was driving one of the compressors.
The ethylene detonated in the engine, and this explosion ignited the
rest of the vapors.
The explosions were felt 6 miles away.
Twelve buildings were destroyed, and fire and explosion damage
occurred throughout the polyethylene plant.
The damage was estimated at over $15 million.
Ethylene Explosion
Automatic equipment promptly detected the hazardous vapor and
operated the automatic high-density water-spray system, which was
designed to wash the ethylene from the atmosphere.
The leak was too large for the spray system to handle.
This accident could have been mitigated if the gas detection analyzers
alarmed at lower concentrations.
Also, in the layout design it should have been noticed that the
compressor needed special consideration to eliminate this ignition
source.
Ethylene Explosion
a
Ethylene Explosion
Example 13-3
Analyze the first ethylene explosion example (318-in fitting failure) to
determine the percentage of fuel that actually exploded compared to
the quantity of ethylene released in a vapor cloud.
Solution
The total energy contained in the vapor cloud is estimated by
assuming the heat of combustion (appendix B). The combustion
reaction is
Ethylene Explosion
Therefore the theoretical energy is
The tons of TNT based on this heat of combustion are calculated using Eq 6-24
Based on the accident investigation, the explosive energy was equivalent to
0.3 ton TNT. Therefore the fraction of energy manifested in the explosion is
0.312.69 = 11.2%. This 11.2% is considerably higher than the 2% normally
observed for unconfined vapor cloud explosions. The higher energy
conversion is a result of the explosion occurring in a partially confined area.
4 Procedures
An organization can develop a good safety program if it has personnel
who can identify and eliminate safety problems.
An even better safety program, however, is developed by
implementing management systems to prevent the existence of safety
problems in the first place.
The management systems commonly used in industry include safety
reviews, operating procedures, and maintenance procedures.
The causes of all accidents can ultimately be attributed to a lack of
management systems.
Case histories that especially demonstrate this problem.
4 Procedures
In the study of these case histories, one must recognize that the
existence of procedures is not enough.
There must also be a system of checks in place to ensure that the
procedures are actually used - and used effectively.
Leak Testing a Vessel
A 2-ft-diameter float was fabricated using stainless steel and welded
seam construction.
Pipefitters were given the job of checking the welds for leaks.
They were instructed to use 5 psi of air pressure and a soap solution to
identify the leaks.
They clamped a 100-psi air hose to a nipple on the tank.
A busy instrument worker gave them a gauge.
The gauge was incorrectly chosen for vacuum service and not pressure
because the vacuum identifier was small.
Leak Testing a Vessel
A short time later, as the fitters were carrying out the tests, the float
ruptured violently.
Fortunately, there was no fragmentation of the metal, and the two
fitters escaped injury.
The accident investigation found that the leak test should have been
conducted with a hydraulic procedure and not air and that the vessel
should have been protected with a relief device.
In addition, the fitters should have taken more time to check out the
gauge to ensure that it was correct for this application.
Man Working in Vessel
Two maintenance workers were replacing part of a ribbon in a large
ribbon mixer.
The main switch was left energized; the mixer was stopped with one
of three start-stop buttons.
As one mechanic was completing his work inside the mixer, another
operator on an adjoining floor pushed, by mistake, one of the other
start-stop buttons.
The mixer started, killing the mechanic between the ribbon flight and
the shell of the vessel.
Lock-tag-and-try procedures were developed to prevent accidents of
this kind.
Man Working in Vessel
A padlocked switch at the starter box disconnect, with the key in the
mechanics pocket, prevents this type of accident.
After the switch gear lockout, the mechanic should also verify the
dead circuit by testing the push-button at all switches; this is the "try"
part of the lock-tag-and-try procedure.
Vinyl Chloride Explosion
Two vinyl chloride polymerization reactors were being operated by the
same team of operators.
Reactor 3 was in the cool down and dump phase of the process, and
reactor 4 was nearly full of monomer and in the polymerization phase.
The foreman and three employees set to work to discharge the
contents of reactor 3, but in error they opened vessel 4 instead.
The gaseous vinyl chloride monomer just in the process of
polymerization burst out of the vessel, filled the room, and shortly
afterward exploded violently, presumably ignited by a spark from an
electric motor or by static electricity generated by the escaping gas.
Vinyl Chloride Explosion
This accident resulted in four fatalities and ten injuries in and around
the plant.
The accident could have been prevented with better operating
procedures and better training to make the operators appreciate the
consequences of mistakes.
Modern plants use interlocks or sequence controllers and other special
safeguards to prevent this type of error.
Dangerous Water Expansion
A hot oil distillation system was being prepared for operation.
The temperature was gradually raised to 500 °F.
A valve at the bottom of the tower was opened to initiate the transfer
of heavy hot oil to a process pump.
Before this particular start-up, a double block valve arrangement was
installed in the bottom discharge line.
It was not realized, however, that the second valve created a dead
space between the two block valves and that water was trapped
between them.
Dangerous Water Expansion
When the bottom valve was opened, the pocket of water came in
contact with the hot oil.
Flashing steam surged upward through the tower.
The steam created excessive pressures at the bottom of the tower, and
all the trays dropped within the tower.
In this case the pressure luckily did not exceed the vessel rupture
pressure.
Although no injuries were sustained, the tower was destroyed by this
accident.
Problems similar to this are usually identified in safety reviews.
Dangerous Water Expansion
This accident, for example, could have been prevented if the plant had
used a safety review procedure during the design phase of this plant
modification.
A bleed line and possibly a nitrogen blow-out line would have
prevented the accumulation of this water.
Consequences of contaminating hot and high boiling liquids with low
boilers can be estimated using thermodynamics.
If these scenarios are possible, relief valves should also be installed
to mitigate these events, or adequate safeguards should be added to the
system to prevent the specific hazard scenario.
Phenol-Formaldehyde Runaway Reaction
A plant had a runaway reaction with a phenol-formaldehyde
polymerization reaction.
The result was one fatality and seven injuries and environmental
damage.
The runaway reaction was triggered when, contrary to standard
operating procedures, all the raw materials and catalyst were charged
to the reactor at once, followed by the addition of heat.
The primary reason for this accident was the lack of administrative
controls to ensure that the standard operating procedures were used
appropriately and that the operators were trained.
Phenol-Formaldehyde Runaway Reaction
The other root causes were
(1) the poor understanding of the chemistry,
(2) an inadequate risk analysis, and
(3) no safeguard controls to prevent runaway reactions.
This EPA case history also summarized seven similar accidents with
phenol-formaldehyde reactions during a 10-year period (1988-1997).