LOPA scenario aggregation: from one consequence frequency to a risk picture

Aggregate LOPA outcomes with a consistent incident definition, correct overlapping rows and preserve consequence severity instead of calling one frequency total risk.

On this page

A LOPA worksheet normally follows one initiating cause toward one consequence endpoint. A ship or terminal can have many such routes, and the same physical incident may appear in several rows. Aggregation is therefore an event-definition problem before it is a summation problem. The result must say what is counted, over which exposure, and whether it describes releases, fires, injuries or another explicitly defined outcome.

Choose one counting unit

Define the endpoint as a distinct loss-of-containment incident from one specified transfer system during one year of the stated operating profile. A single incident may have several failed protections, but it is counted once in the incident-frequency total. If the objective instead counts individual component failures, the counting rule changes and the totals cannot be compared directly.

IMO's public FSA explanation treats scenarios, likelihood and consequences as parts of a broader risk assessment. A LOPA aggregation can inform that picture, but an annual release count alone does not represent every consequence dimension. Keep the objective narrow enough that the summed quantity has a coherent interpretation.

Separate distinct initiators from duplicated descriptions

One row might describe overfill following a transfer-control fault and another overfill following a missed stop. If the same failed sensor causes the control fault and conceals the stop cue, the rows may describe the same incident population. Different wording is not evidence of disjoint scenarios. Review the causal histories and incident identifiers before adding the rows.

Alternatively, two distinct incidents can occur in the same year. Adding their expected counts is legitimate even when their annual occurrence indicators overlap. Do not subtract the product of annual probabilities from an expected incident count merely because both types could occur during the year. A union of incident descriptions and a union of yearly yes/no events are different objects.

Work an explicit overlap correction

Suppose row A covers incidents at 2×10⁻⁴/year and row B at 3×10⁻⁴/year. A reviewed event model identifies 8×10⁻⁵/year of the same physical incidents in both rows. Then the distinct-incident frequency is 0.0002+0.0003−0.00008=0.00042/year. The raw sum 0.0005/year double-counts the shared population.

An equivalent partition is A-only at 0.00012/year, B-only at 0.00022/year and both-label incidents at 0.00008/year. These nonoverlapping groups sum to 0.00042/year. The overlap value is stipulated for this teaching example; a real study needs evidence for the shared population rather than an arbitrary percentage deduction.

Use bounds if the overlap is unknown

For these two incident populations, the overlap rate cannot be negative or exceed the smaller row's rate. Without further information the union lies between max(fA,fB)=0.0003/year and fA+fB=0.0005/year. A bound is an honest interim result if the decision can be examined across that range.

Calling the upper bound conservative is limited to this duplication question. Missing initiators, understated layer failures or excluded operating modes could still make the real total higher. Likewise, the lower bound assumes maximum overlap and is not a best estimate. Record what evidence would narrow the interval and whether its width affects the proposed decision.

Do not sum nested consequence endpoints

Assume, separately, that 30% of the 0.00042/year releases progress to the defined fire endpoint. The fire frequency is 0.000126/year, and the release-without-fire frequency is 0.000294/year. Fire is a subset of release in this construction. Adding release frequency and fire frequency would count fire incidents twice.

A clear outcome partition lists non-fire release and fire, or lists all releases with fire reported as a conditional subset. If escalation can produce several distinct harms within one incident, retain that joint consequence structure. Environmental contamination and injury may coexist; their occurrence frequencies should not be summed into a generic accident count without a stated counting rule.

Preserve severity when forming an expected consequence

For another explicit partition of the same total, suppose 0.0004 incidents/year each release 2 m³ and 0.00002 incidents/year each release 50 m³. Expected annual released volume is 0.0004×2+0.00002×50=0.0018 m³/year. Frequency times volume per incident gives volume per year, so the dimensions are clear.

That mean does not mean a vessel releases 0.0018 m³ steadily every year. It combines rare discrete outcomes and can hide the larger spill's importance. It also says nothing by itself about toxicity, location, response, shoreline sensitivity or injuries. Expected quantity is one useful metric, not a universal measure of acceptable marine risk.

Keep operating and fleet denominators compatible

A per-transfer probability, a per-vessel-year frequency and a fleet-wide count cannot be added until their exposure bases are reconciled. Ten otherwise comparable vessels with the same 0.00042/year rate have an expected fleet count of 0.0042/year by linearity of expectation. Independence between vessels is not needed for that expected-count sum.

Independence does matter for some other outputs, such as the probability of at least one fleet event or multiple simultaneous losses. Shared weather, maintenance policy or design can couple vessels. A fleet expected count is therefore neither the risk to a particular crew member nor evidence that multi-vessel consequences have been represented.

Aggregate uncertainty without erasing common inputs

Several scenarios may use the same uncertain failure-rate estimate or the same protection-layer performance model. Sampling each occurrence of that input independently can create artificial cancellation and narrow the total uncertainty. Keep common parameters common when propagating uncertainty, while preserving genuine differences between operating states and equipment populations.

IMO's public FSA guidance summary stresses reporting data reliability, uncertainty and limitations. For aggregation, also report unquantified scenarios and the reason they are excluded from the total. A precise sum of selected rows can be a useful partial result, provided it is not presented as a complete inventory of hazards.

Keep an incident hierarchy instead of flattening every row

One physical episode can contain an initiating fault, a release, a fire and several injuries. A useful database gives the episode one parent identifier and links its causes, protective failures and outcomes beneath it. Aggregating parent incidents answers a different question from counting releases, affected people or failed barriers. The relationship should survive export into the analysis worksheet.

This also helps reconcile ship and terminal reports of the same transfer event. Two organizations can describe different observations without describing two accidents. Conversely, one report can summarize several separate releases. Review time, location, equipment and causal continuity before merging records. The purpose is to preserve the quantity required by the analysis, not to force every source into an arbitrary one-row-per-report rule.

Use an improvement consistently across the whole scenario set

A new barrier can reduce several initiating-to-consequence routes at once. Calculate the revised distinct-incident total using the revised overlap structure; do not simply add separate row benefits if the same incidents are prevented in more than one row. Some changes can also alter the distribution of consequence severity without changing the initial release count.

For example, faster isolation can shorten release duration while leaving the number of initial leaks unchanged. An incident-frequency-only dashboard would miss that benefit, whereas a volume or consequence model might capture it. Conversely, reducing frequent minor events can leave the rare severe endpoint unchanged. Present the baseline and changed result for each decision-relevant metric, with one consistent exposure profile, so that a favorable aggregate does not conceal the dimension that motivated the study.

Retain the observation window when comparing totals

A calendar-year total and a completed-voyage total can describe different exposure even when their numerical labels look similar. A partial year with more intensive transfer activity should not be compared directly with a quieter full year. Normalize by the relevant exposure for the comparison, then retain the actual annual count when annual consequence is the question. Changes in reporting completeness must also remain visible; a larger recorded total can reflect better detection rather than a demonstrated deterioration in physical performance. If event definition, scope or reporting method differs between periods, the whole difference cannot be interpreted as a change in safety.

Link the total to a defined decision criterion

A scenario-specific target and an aggregate target are not interchangeable. Ten scenarios each below a per-scenario threshold may together exceed an applicable group criterion; conversely, a group limit cannot be divided equally among rows without a reasoned allocation. The criterion's endpoint, population and exposure must match the calculated quantity.

A reviewable aggregation record includes row definitions, overlap treatment, mutually exclusive partitions, consequence categories, units, exposure and uncertainty. It should show how changes in one shared barrier affect all relevant scenarios. The educational example provides arithmetic and interpretation, not a tolerability criterion or an approval of ship operations.

Sources