Knowledge / Risk and reliability
HAZOP node boundaries: keeping design intent and interfaces visible
Select HAZOP nodes around coherent design intent, track connections across boundaries and test whether a downstream inventory consequence remains visible.
On this page
A node is an analytical boundary used to focus a HAZOP discussion. It is not a physical barrier and does not stop a deviation from propagating. Choosing nodes well means making local design intent clear while preserving the connections through which material, energy, information and human actions affect other parts of the system. A neat marked-up drawing can still contain a serious interface gap.
Write a design-intent sentence that can be challenged
For an invented transfer line, a useful statement is: move the specified liquid from source tank S to receiving tank R at the intended flow range, within the defined pressure and temperature envelope, in the selected operating mode. Add composition, direction and required isolation or containment functions where relevant. “Transfer system operates normally” is too vague to generate meaningful deviations.
The IEC 61882 public catalogue identifies HAZOP as a guide-word study of systems, with preparation, examination, documentation and follow-up. Only that public description is relied on here; no access to the paid standard's full text is claimed. The node map below is an original teaching example, not a prescribed partition.
Partition where the intended function changes
One workable map has four nodes: source inventory and suction; pump and immediate discharge; distribution manifold and selected branch; receiving inventory and venting. The first concerns available liquid and suction conditions, the second energy addition, the third routing and isolation, and the fourth accumulation and displaced gas. These differences provide a reason for the boundaries.
A page break on a drawing or a supplier package boundary is not by itself an engineering reason to end a node. Conversely, putting the entire transfer system into one node can blur pressure regions, reverse-flow paths and operating intentions. The useful scale is the one at which deviations and their causes can be discussed precisely without losing their downstream effects.
Assign every connection to an interface record
At each node boundary record the connecting line or signal, normal direction, possible reverse direction, operating range, isolation state and relevant receiving condition. For the manifold-to-tank interface, the upstream team needs to know whether the tank can accept flow and the downstream team needs to know what pressure and rate the source can deliver.
A check valve drawn at the boundary is a device with a failure mode, not a reason to exclude reverse flow. A closed valve during one mode may be open during another. Vent lines, drains, overflow paths and temporary hoses can connect nodes that appear separate on the main process diagram. Interfaces require examination even when the neighboring node has its own worksheet.
Use an inventory balance to test consequence propagation
Suppose the pump delivers 12 m³/h into R while the intended outlet removes 8 m³/h. Net accumulation is 4 m³/h. If only 6 m³ of usable volume remains before the defined overflow endpoint, the constant-rate time is 6/4=1.5 h. Each figure is invented and the balance assumes constant density, no other flows and a correctly defined usable margin.
If the pump node records only successful delivery and the tank node assumes its inflow is automatically matched to outflow, neither worksheet captures the accumulation. The interface reconciles those assumptions. At 16 m³/h inflow with the same 8 m³/h outlet, time falls to 0.75 h. The sensitivity makes a downstream consequence visible without claiming a full dynamic tank model.
Distinguish operating intent from equipment design limits
A desired flow of 12 m³/h is an operating target, not necessarily the maximum flow the pump can produce. A tank's nominal capacity is not automatically the allowable filling limit. A pipe pressure rating is not the alarm setpoint or normal pressure. Mixing these values can make a deviation disappear because the wrong reference has been selected.
Keep normal range, credible maximum source capability, protective setpoint and equipment limit in separate fields with units and basis. The study can then ask whether a deviation breaches function, containment or another criterion, and which evidence is missing. A normal operating value should never silently stand in for the limiting physical case.
Examine the node in each meaningful operating mode
Startup, normal transfer, shutdown and maintenance can change valve lineups, direction, available protection and human actions. Four nodes across four modes produce sixteen coverage cells, but filling sixteen boxes does not prove completeness. Some cells need several distinct scenarios, and a transition between modes can create a condition absent from either steady state.
For example, an isolated liquid segment during maintenance may be exposed to heat, although no flow is intended. A line drained for work may admit gas and later affect pump suction. State explicitly which modes were examined and why others are outside scope; preserve a route for reviewing them rather than assuming “normal operation” covers every condition.
Keep signal and utility boundaries beside fluid boundaries
A receiving-tank level signal may stop an upstream pump through a network and a control cabinet outside either physical node. If those connections are omitted, the study can credit a stop function without examining its dependencies. Record where information originates, where decisions occur and which final element changes the process.
The same applies to common power, air or cooling. A supplier may describe a package as complete while expecting external utilities and valid commands. The shipyard may describe those utilities as available while excluding package response. The interface record should make both assumptions visible and assign a traceable action when they cannot be reconciled.
Test the partition with a boundary-crossing scenario
Ask the team to follow one deviation from its initiating cause to its final consequence across all relevant nodes. A wrong manifold lineup may send flow into a tank assumed isolated, produce accumulation, challenge venting and expose a downstream space. Each handoff should preserve the same rate, pressure, substance and operating state unless an explicit mechanism changes them.
If the discussion repeatedly jumps between distant nodes, the partition may need adjustment or a dedicated interface review. If every node uses “see other node” without one complete causal record, responsibility has been displaced rather than resolved. Cross-references should point to a specific scenario and its closure evidence.
Reconcile quantities that cross a node boundary
Material is conserved as mass, while volume can change with temperature, pressure or composition. The simple tank example assumes compatible constant-density volume flows. If the source and receiver report volumetric flow at different reference conditions, copying the same number across the boundary can create an apparent inventory error or hide a real one. Record the reference state and use a mass balance where necessary.
Likewise, a pressure measured at the pump is not automatically the pressure at an elevated manifold, and a commanded valve position is not a measured delivery rate. Interface records should identify the quantity, unit, location, reference and time basis. Agreement of numbers without agreement of these meanings is weak evidence. The boundary review is a useful place to catch such mismatches before they become contradictory HAZOP assumptions.
Assign closure evidence across organizational boundaries
An interface action often requires evidence from more than one party. A pump supplier may establish a performance curve, a yard may establish installed resistance and a vessel team may establish the operating lineup. None alone necessarily demonstrates the complete delivery function. The action should name the required combined result and the information each part contributes.
Keep responsibility for assembling that result explicit while avoiding fragmented closure. Three separate statements that each local item is acceptable do not prove the connected system satisfies the intended function. Conversely, do not reopen every completed local study when only one interface assumption changes. Trace the affected quantities and scenarios, identify the evidence that remains valid and review the actual dependency. This makes the node structure useful throughout design development and operation.
Preserve node meaning when the design changes
An added cross-connection, changed pump, altered tank duty or new automatic stop can change both the local intent and the interfaces. HSE change-procedure guidance relates the level of hazard review to the nature and extent of a modification. Reusing old node numbers is acceptable only if their definitions are checked against the new configuration.
A useful final node record contains drawings and revision, boundary points, design intent, operating modes, inputs and outputs, connected safeguards, interface scenarios and open evidence gaps. This is a framework for a reviewable study, not a completed HAZOP or a vessel modification instruction. Its quality is shown by the causal paths it preserves, not the number of nodes it creates.
Sources
- IEC 61882:2016 public catalogue summary · International Electrotechnical Commission · Source check date: 2026-10-06
- Plant modification / Change procedures · UK Health and Safety Executive · Source check date: 2026-10-06