burners activated before rundown had been estab - lished; and a heat-up ramp rate applied at 50% above the value specified in the SOP. Post-incident analysis indicates that these depar - tures were not isolated events but were sympto - matic of a broader condition in which procedures had progressively lost reliability as guides to field practice. A subsequent review of the incident framed this dynamic
Work-as-prescribed How work is formally expected to be carried out according to documented rules, procedures, instructions and compliance requirements.
Actions taken under real-life conditions, including adjustments made for equipment limits or resource gaps Incomplete or evolving information Use of experience, judgement and coordination Informal workarounds Variability between sites, shifts or operating contexts Work-as-done
Work-as-imagined
Design Work & production planning Safety management, investigations & auditing
Figure 1 Work on the plant floor often differs from formal procedures when these contain incomplete or inaccurate information
maintained their own document versions; some documents circulating in the field had not been formally approved; pro - cedure content was frequently interspersed with unrelated vendor material; and field execution had no automated tracking capability. Engineers had no systematic means of verifying whether a procedure had been followed as docu - mented during a given job. Structural limitations of the document-based model The limitations of document-centric procedure manage - ment are structural in nature. Static documents do not allow for field data gathering. There is no mechanism to enforce step completion, detect deviations from the prescribed sequence, or generate an auditable record of execution. Version control depends on manual discipline, and multi - ple incompatible versions of critical procedures can coexist across teams, shifts, and plants without triggering auto - mated detection. Execution transparency, defined as the ability to verify, after the fact, whether a procedure was followed correctly, is absent from paper-based systems. Supervisors rely on ver - bal confirmation and handwritten logs. Audit trails, where they exist, consist of paper records that are labour-inten - sive to compile and impossible to analyse at scale. For process safety frameworks requiring documented evidence of procedural adherence, including API RP 754 (process safety performance indicators) and API 770 (reduction of human error in process operations), docu - ment-based systems provide limited evidentiary support. Procedure failure: Texas City refinery explosion (2005) The April 2005 explosion at BP’s Texas City Refinery, which resulted in 15 fatalities and 180 injuries, provides the most extensively documented case study of procedural failure in modern refinery history. The Mogford Report, commis- sioned by BP, identified the raffinate splitter start-up pro - cedure and the application of operational knowledge as one of four critical contributing factors. The immediate sequence of operational departures from documented procedure included: a faulty hard-wired alarm left unrepaired; a DCS high-level alarm acknowledged but not acted upon; a control valve operated in manual mode when the start-up SOP required 50% open in automatic;
in terms consistent with the human factors literature: “When procedures are not updated or do not reflect actual practice, operators and supervisors learn not to rely on procedures for accurate instructions. Other major acci - dent investigations reveal that workers frequently develop work practices to adjust to real conditions not addressed in the formal procedures. Human factors expert James Reason refers to these adjustments as ‘necessary violations,’ where departing from the procedures is necessary to get the job done. Management’s failure to regularly update the proce - dures and correct operational problems encouraged this practice: ‘If there have been so many process changes since the written procedures were last updated that they are no longer correct, workers will create their own unofficial pro - cedures that may not adequately address safety issues’ (API 770, 2001).”7 James Reason’s concept of ‘necessary violations’ provides a framework for interpreting the 29% of ASM Consortium failures attributed to procedures not being followed. In a significant proportion of such cases, non-adherence is likely to reflect operator-level adaptation to procedural content that had drifted from operational reality: a rational response to an unreliable document rather than a failure of individual compliance (see Figure 1 ). This pattern is consistent with HSG48, which highlights that operators will adapt or bypass procedures that are perceived as inaccurate, impractical, or misaligned with real operating conditions. In such cases, non-compliance is often a symptom of poor procedure design rather than individual failure. Procedure drift as an incremental process Procedure drift is the progressive divergence between writ - ten guidance and actual field practice. It develops through the accumulated effect of routine operational events rather than discrete failure. Process modifications occur; proce - dure updates are deferred. Equipment is replaced; start-up sequences change before documentation is revised. Experienced operators develop more effective methods for managing transitions; this knowledge is transmitted infor - mally rather than incorporated into formal documentation. The ASM Consortium data indicate that this process is operating at scale across the industry. The dominance of
90
PTQ Q3 2026
www.digitalrefining.com
Powered by FlippingBook