Knowledge / Risk and reliability
Operator response in LOPA: detection, decision and available time
Evaluate a complete alarm-to-action chain, calculate available response time and distinguish demonstrated feasibility from an unsupported human-error probability.
On this page
An operator response can reduce a hazardous scenario only if the information arrives, the person understands it, the action is feasible and the process reaches a sufficiently safe condition before the deadline. An alarm symbol alone proves none of those steps. In LOPA, the question is whether a specific response can justify bounded credit for a specific initiating cause and consequence, under the actual workload and operating conditions.
Define success as a physical outcome
For an invented receiving tank, success means stopping incoming flow before the usable volume margin is exhausted. Acknowledging the alarm, calling another station or issuing a stop command is not the endpoint. The chain includes measurement, alarm generation, attention, interpretation, decision, execution and the final physical response. Each link can fail or take time.
HSE alarm-management guidance calls for a defined response and sufficient time for that response. It does not provide one universal operator failure probability. Translate the intended action into an observable completion criterion so that timing evidence refers to the actual protection function rather than a convenient intermediate signal.
Calculate the process deadline first
Assume the tank has 12 m³ of usable margin at the moment the hazardous condition becomes detectable. Inflow is a constant 90 m³/h and outflow is zero. Since 90/3,600=0.025 m³/s, the no-action time to exhaust the margin is 12/0.025=480 s, or eight minutes. This is a volume balance, not an alarm-setting recommendation.
The definition of usable margin matters. Tank geometry, measurement uncertainty, ship motion, unpumpable volume and the chosen consequence threshold can make nominal empty volume different from the margin available to this response. If the alarm triggers after the defined detectable point, the elapsed sensing or threshold delay belongs in the response budget rather than disappearing from it.
Build a response budget without hiding travel or actuation
Assign illustrative durations: sensing delay 15 s, annunciation 5 s, attention and recognition 40 s, interpretation and decision 90 s, travel 60 s, manual action 30 s, and final closure 45 s. Their sum is 285 s. Under the conservative assumption that full inflow continues until complete closure, the remaining time margin is 480−285=195 s.
The numbers are not measured performance and cannot support a numerical LOPA credit. They show how to expose missing time. If the action requires another person, a radio exchange or access through a restricted area, represent those tasks explicitly. Parallel actions should be combined according to their actual dependencies, not simply added or assumed simultaneous for convenience.
Test a faster transient before claiming a comfortable margin
At 150 m³/h, the same 12 m³ margin is exhausted in 288 s. The unchanged 285 s response leaves only 3 s in the full-flow-until-closure model. A small sensing delay, slower movement or higher actual inflow can reverse the result. A response that appears feasible at average transfer rate may therefore be unsuitable for the credible maximum scenario.
If the inflow declines linearly during the final 45 s, the accumulated volume at 90 m³/h is 0.025×(240+45/2)=6.5625 m³, rather than 7.125 m³ for constant flow throughout 285 s. That more favorable calculation requires evidence for the valve and hydraulic trajectory. A commanded linear travel does not establish linear flow decay.
Assess the actual human task
A named operator may be monitoring several systems, handling communications or responding to the same initiating disturbance elsewhere. The relevant task analysis asks what information is available, which alternatives must be distinguished and what action can realistically be completed. Familiar routine actions and diagnosis of an unfamiliar fault are not interchangeable demands on human performance.
HSE human-factors risk-assessment guidance emphasizes understanding safety-critical tasks and the conditions in which they occur. For a shipboard example, noise, movement, visibility, language, fatigue, accessibility and team coordination can affect the chain. These are scenario characteristics to examine, not reasons to assign a generic pessimistic or optimistic number.
Check independence at the alarm and the action
If the initiating fault is a level sensor stuck low, an alarm derived from that same sensor may never appear. A perfectly trained operator then has no modeled trigger. A second screen showing the same signal does not restore independence. Likewise, a manual stop that uses the same failed output path as an automatic stop may not provide an alternative physical action.
Two alarms to one operator are not automatically two independent protection layers. They may share the display, attention demand, diagnosis and final valve. A different alarm threshold can provide additional information while still belonging to one response chain. Credit should follow a supported function and dependency model, not the count of annunciators on the console.
Interpret drills as evidence with a population
A drill can reveal access problems, ambiguous instructions and actual elapsed times. Its relevance depends on whether the scenario, workload and starting awareness resemble the demand being assessed. A prepared crew waiting for a known alarm may demonstrate equipment operation while providing weak evidence about recognition during an unexpected event.
Zero observed failures in a small exercise set do not demonstrate zero failure probability. Even under ideal independent identical trials, zero failures in ten trials gives a one-sided 95% binomial upper bound of 1−0.05^(1/10)≈0.259. That mathematical illustration is not a recommended way to certify operator credit; it shows the limited information in a small perfect record.
Keep the credit conditional and reviewable
A response claim should identify the initiating causes it can address, the alarm path, responsible role, action, physical completion criterion, available time and evidence behind each timing assumption. Record conditions that invalidate the claim, such as unmanned periods, blocked access or loss of the communication link required to complete the action.
If credible response time exceeds the process deadline, assigning a smaller human-error probability cannot fix the physical incompatibility. The scenario requires a different justified protective arrangement or a changed operating envelope through the appropriate engineering process. A spreadsheet credit is the conclusion of that evidence chain, not a substitute for it.
Use distributions without adding incompatible percentiles
Response times vary between demands. A mean attention time plus a mean travel time describes neither a guaranteed completion time nor a particular upper percentile of the total. Even adding each task's upper percentile does not automatically give the same percentile for the full chain. The dependence between tasks and the event conditions must be considered.
A demanding disturbance may delay recognition and movement together; a well-understood alarm may shorten both. Preserve paired observations where possible, including the starting workload and alarm context. Compare the distribution of total physical completion time with the process deadline distribution, rather than compare two unrelated averages. For the worked tank, uncertainty in initial volume and inflow changes the deadline itself. A favorable response average can coexist with an important probability of exceeding that changing deadline.
Check wrong action as well as slow action
A task can finish quickly while affecting the wrong tank, valve or pump. Timing alone therefore cannot establish successful protection. The response definition should identify the correct equipment, intended direction of action and the feedback that confirms the physical result. Similar labels, ambiguous displays or a changed lineup can make rapid execution ineffective.
Verification also consumes time. If the operator must confirm that flow has actually stopped and take another action when it has not, the response chain includes that branch. A test that ends at the first button press misses it. Keep such branches visible in the task analysis and relate them to the available process time. The purpose is to examine whether the complete intended action is usable, not to rate a person's speed in isolation.
Preserve the distinction between feasibility and reliability
The worked volume balance establishes a conditional deadline, and the response budget illustrates a possible timing chain. Neither establishes how often the full chain succeeds. Reliability also depends on the detection path, human task, final element and dependencies under the initiating event. A positive time margin is necessary for this particular response, but it is not sufficient evidence for a probability claim.
This article supplies no alarm setpoint, emergency procedure or universal operator PFD. Its practical use is to make a proposed human protection claim testable: what must happen, how quickly, under which conditions, and what observation would show that the claim no longer holds.
Sources
- Alarm management · UK Health and Safety Executive · Source check date: 2026-10-06
- Human factors in risk assessment · UK Health and Safety Executive · Source check date: 2026-10-06
- Functional safety · UK Health and Safety Executive · Source check date: 2026-10-06