Procedural HAZOP: applying guide words to human tasks

Analyze task omissions, wrong objects, timing, information quality and workload without replacing a task-specific assessment with a generic human-error probability.

On this page

A procedural HAZOP examines how a task could depart from its intended purpose and what that departure could do to the system. The unit of analysis is more specific than a sentence saying that an operator may make an error. It includes the task, the object acted on, the information available, the required sequence and the evidence of completion. This makes it possible to distinguish a weak instruction from an unsuitable interface, an impossible workload or an unresolved technical prerequisite.

Define the task before applying guide words

The public description of IEC 61882:2016 includes procedural HAZOP within its application examples. The principle is to challenge a defined intent systematically. For a generic verification task, specify what condition is to be established, which equipment or location it concerns, who has the information and how a valid result is recognized. The examples here are analytical questions, not a shipboard operating procedure.

Compare “check the system” with “confirm that the identified service is available at the specified downstream measurement point before the transition is authorized.” The latter exposes an object, a location, a prerequisite and a decision. It can still be wrong or incomplete, but the study has something concrete to challenge. A broad instruction can hide several independent tasks and make an apparent single action impossible to assess.

Use task analysis to understand real work

HSE’s operating-procedure guidance recommends formal task analysis for important procedures and discusses the need to identify undocumented practices. A written sequence should therefore be compared with the actual task, including where information is obtained and which other activity competes for attention. A document review alone may miss a difficult-to-reach indicator, an ambiguous equipment label or a routine interruption.

Select detail according to consequence and decision difficulty. A critical identification or authorization step may need close examination, while listing every trivial movement can bury the significant questions. Include the people who perform and support the task so the study can distinguish the intended work from a convenient imagined version. Record assumptions about environment, staffing and equipment availability instead of treating them as invisible constants.

Challenge omission, substitution and wrong object separately

An omitted action leaves the expected state change or check absent. An action performed on the wrong object may create a different state elsewhere while the intended object remains unchanged. A substituted action can appear to satisfy the wording but fail to achieve its purpose. These deviations are not interchangeable and should not be compressed into one row labelled failure to follow procedure.

For example, acknowledging an alarm is different from establishing that its cause has been resolved. Reading an adjacent instrument is different from reading the identified instrument. Signing a completion field is different from obtaining the physical evidence that the field represents. Each scenario should retain its cause, consequence and relevant safeguard so that the proposed improvement addresses the actual mismatch.

Examine information and decision quality

HSE’s human-failure overview distinguishes unintended execution errors from mistaken decisions and discusses factors such as design, distraction, time pressure and workload. The useful question is why the available situation could produce the wrong action or conclusion. More training is not automatically the correct response to an interface that makes two equipment identities difficult to distinguish.

A decision can be logically correct for information that is stale, incomplete or from the wrong operating mode. Check units, timestamp, source and the meaning of normal or available indications. If a task requires combining several displays, identify whether the required values can be compared consistently. The person should not be assumed to infer an unshown process state accurately merely because the equipment is familiar.

Test whether the assigned work fits the available time

Suppose an invented response requires three strictly sequential tasks by one person: identify the affected function in 12 s, complete an authorized control action in 14 s and verify its result in 6 s. The assumed total is 32 s. If the process assessment supplies a 28 s completion window, the proposed sequence exceeds it by 4 s even before travel, communication or interruption is included.

This does not establish real human response times or a failure probability. The durations are hypothetical inputs exposing a consistency problem in the assumed task model. Adding another person does not automatically solve it: the tasks may depend on the same information or require sequential authorization. A defensible assessment needs task-specific evidence and the actual operational constraints, not a generic assertion that trained staff will act quickly.

Use time ranges without inventing a statistical confidence

For a second independent timing example, assume detection and interpretation take between 8 and 12 s, action takes between 5 and 9 s, and a necessary sequential confirmation takes 3 s. The bounded sum is 16–24 s. Against an assumed 22 s window, the upper-bound case is 2 s late. An average-looking total inside the window would not establish that all cases satisfy it.

These are simple bounds, not a probability distribution or a ninety-five-percent confidence interval. They assume all three stages occur in series and that the stated bounds apply in the same scenario. If one duration grows when another does, that dependency belongs in the assessment. If stages overlap, document the overlap rather than adding every nominal time or assuming parallel work without evidence.

Distinguish a second signature from an independent check

A second person can provide valuable verification, but independence depends on what is checked and how information is obtained. If both people copy the same incorrect label or read the same stale display, the additional signature may not challenge the original error. If the second person sees only a completed form, the check may establish document completeness rather than the physical state.

Specify the failure mechanism the check is intended to reveal. For a wrong-equipment scenario, the verification must address identity; for an omitted restoration step, it must address the resulting state. The scope should be practical in the actual working environment. Avoid assigning numerical error-reduction credit merely from the number of signatures or people listed in the procedure.

One stale display feeds two people who both read and sign. Their signatures merge into one result with a shared evidence dependency. The diagram asks a check to challenge the source, timestamp and physical state instead of assigning independence merely because two people sign.
Original evidence-lineage diagram for the article’s shared stale-display example. Arrows represent information dependence, not a prescribed task sequence. A second person may add value, but independence must address the failure mechanism being checked. The example does not claim that all double checks are ineffective, assign a human-error probability or specify a shipboard procedure. Evidence from the same mistaken source can preserve the same error through both signatures.

Design the procedure around its intended user

HSE’s procedure-design principles emphasize task analysis, user involvement and a format appropriate to the task and consequences. A long narrative, a short checklist and a diagnostic aid serve different purposes. The study should ask whether the selected format lets the user find the required decision, prerequisite and evidence at the moment they are needed.

A warning separated from the action it qualifies may be missed; an ambiguous unit can undermine a correct calculation; and a completion box covering several actions can conceal an omitted subtask. Improvements should be tested with representative users and the intended use conditions. Readability is valuable, but a well-formatted instruction cannot compensate for a physically unavailable indication or contradictory technical requirements.

Turn findings into testable changes

HSE’s procedure-usability inspection questions connect the need for procedures, human-error consideration, approval, accessibility and operator involvement. A useful procedural-HAZOP action similarly names the specific weakness and the evidence that the revision resolves it. For example, an identity-confusion issue needs evidence that the revised identification is unambiguous at the relevant location, not only a revised training slide.

Common mistakes are assigning a generic human-error probability, treating experience as immunity from slips, adding signatures without specifying their independence, and closing a finding when new text is issued but cannot be used in practice. The final record should preserve the task boundary, deviation, performance conditions and verification result. It should explain how the system supports successful work and how unresolved technical assumptions remain visible.

Sources