HAZOP Study Explained: Guide Words, Process, and a Worked Example
A HAZOP study explained — the node concept, the seven guide words, the workshop process and worksheet, and how a HAZOP action becomes a safety instrumented function.
A HAZOP study (Hazard and Operability Study) is a structured, team-based technique for identifying process hazards and operability problems by systematically applying a set of guide words to each defined section of a process. The result is a prioritised list of recommended actions — some of which directly become safety instrumented functions (SIFs) implemented on a safety PLC.
What Is a HAZOP Study?
HAZOP was developed by ICI in the UK during the 1960s and formalised in IEC 61882 (Hazard and Operability Studies — Application Guide). It has since become the dominant hazard identification method in the oil and gas, chemical, pharmaceutical, and power industries.
The technique works by taking a process design — typically represented on a P&ID — and asking a disciplined question for every section of that design: "What happens if this process parameter deviates from its intention?" The word "operability" in the name is deliberate. HAZOP captures problems that degrade production and quality, not just those that injure people.
When Is a HAZOP Required — and When Should You Use Something Else?
HAZOP sits alongside several other risk techniques. Understanding where it fits prevents over- or under-specification:
| Technique | Best suited for | Typical output |
|---|---|---|
| HAZID | Early design; facility-level hazard identification | Hazard register, qualitative risk ranking |
| HAZOP | Detailed design; node-by-node P&ID review | Deviation table, action register |
| FMEA | Equipment and component failure modes | Failure mode register, maintenance priorities |
| LOPA | Quantifying risk reduction needed after HAZOP | SIL target for each SIF |
| QRA | Major accident risk estimation | Individual/societal risk contours |
A HAZOP is typically conducted after the P&IDs reach Approved for Design (AFD) status — detailed enough to identify instruments, control valves, and interlocks, but before construction begins when changes are still economical. It is usually followed by a LOPA (Layer of Protection Analysis) for the scenarios that require a quantified risk-reduction target.
The Node Concept
The HAZOP team does not review an entire plant simultaneously. The P&ID is first divided into nodes — discrete sections of the process that have a clearly defined design intent (what the process is supposed to do there) and a defined set of process parameters (flow, temperature, pressure, level, composition, etc.).
A node might be:
- A single pipeline segment between two vessels
- A reactor feed section including the control valve, flow meter, and isolation valve
- A storage tank and its associated level control loop
The node boundary is drawn to capture the cause–consequence relationship cleanly. If a pump and its downstream control valve share a cause–consequence link, they belong in the same node. If they are independent sections with their own intentions, they are separate nodes.
Selecting Process Parameters
For each node, the team identifies which process parameters are relevant. Common parameters include:
- Flow — the most common parameter; applies to nearly every pipeline node
- Temperature — critical for reaction nodes, heat exchangers, fired equipment
- Pressure — relevant wherever pressure containment or protection is designed
- Level — vessel and separator nodes
- Composition / Concentration — reactor feeds, blending, chemical storage
- Phase — where liquid/vapour separation matters
- Reaction — for reactive systems (rate, selectivity, exotherm)
- Time / Sequence — batch processes and start-up/shutdown procedures
The Seven HAZOP Guide Words
The power of HAZOP comes from its guide words — a fixed vocabulary that forces the team to consider the complete space of deviations from the design intention. IEC 61882 defines seven primary guide words:
| Guide Word | Meaning | Example deviation |
|---|---|---|
| No / None | Complete negation of the intention | No flow in a feed line |
| More | Quantitative increase above the intention | High flow, high pressure, high temperature |
| Less | Quantitative decrease below the intention | Low flow, low pressure, low level |
| Reverse | Logical opposite of the intention | Reverse flow, reverse reaction |
| As Well As | Qualitative increase — something extra | Contamination, additional phase present |
| Part Of | Qualitative decrease — something missing | Partial composition, incomplete separation |
| Other Than | Complete substitution — something else entirely | Wrong material, maintenance mode active |
These seven guide words are applied to each parameter at each node, generating a matrix of deviations. Not every combination is meaningful — "No temperature" rarely makes physical sense — but the discipline of checking each cell prevents the team from unconsciously skipping scenarios that feel unlikely.
Secondary Guide Words
IEC 61882 also lists secondary guide words that capture intent-level deviations not fully covered by the primary seven: Early, Late, Before, After (for sequence and timing in batch processes), and Where Else (for spatial deviations such as wrong destination). These become especially important during HAZOP of batch recipes and start-up procedures.
The Workshop Process and Team Roles
A HAZOP is a facilitated workshop, not a desk review. It requires a multi-disciplinary team in the same room — typically for two to four hours per node, over several days or weeks for a large plant. The discipline mix is essential because causes and consequences cross engineering boundaries.
Core Team Members
| Role | Responsibility |
|---|---|
| HAZOP Leader / Facilitator | Controls the methodology; ensures every guide word is applied; prevents the team from jumping to solutions before recording the deviation fully |
| Process Engineer | Explains the design intent; describes expected causes and consequences |
| Instrument / Control Engineer | Describes existing interlocks, control loops, and alarms; identifies where a safety PLC function may be needed |
| Operations Representative | Brings operational experience; identifies human factor causes and consequences |
| Mechanical / Piping Engineer | Addresses equipment failure modes and layout issues |
| Safety Engineer | Assesses consequence severity; links to the major hazard register |
| Scribe / Recorder | Captures deviations, causes, consequences, safeguards, and actions in the HAZOP worksheet in real time |
The team size is usually five to eight people. Fewer than five risks missing knowledge; more than eight makes facilitation difficult and the session slow.
The Workshop Sequence
For each node, the facilitator works through the following sequence:
- State the design intent — the scribe records it verbatim at the top of the node sheet.
- Select parameter — start with the most critical parameter (usually flow for pipeline nodes).
- Apply guide word — generate the deviation (e.g., "More Flow").
- Identify credible causes — instrument failures, operator error, upstream upsets. Only credible causes for this process and design are recorded; exotic theoretical causes can be noted separately.
- Identify consequences — what happens if the deviation persists? Follow the chain until the top event (injury, release, equipment damage) is reached.
- Identify existing safeguards — alarms, interlocks, relief valves, procedures. These reduce risk but do not eliminate the deviation.
- Assess residual risk — does the combination of severity and likelihood, with existing safeguards credited, meet the company risk criteria?
- Raise actions — if the residual risk is unacceptable or uncertain, raise a formal action with a responsible person and target date.
The HAZOP Worksheet
The worksheet is the permanent record of the HAZOP. Each row represents one deviation at one node. Industry standard columns are:
| Column | What to record |
|---|---|
| Node | Node identifier and a brief description of the design intent |
| Parameter | The process parameter being examined |
| Guide Word | The guide word applied |
| Deviation | The guide word + parameter phrase (e.g., "High Flow") |
| Cause | One or more credible initiating causes |
| Consequence | The worst credible outcome without safeguards |
| Safeguards | Existing independent protection layers (IPLs) that prevent or mitigate the consequence |
| Likelihood (S/L) | Qualitative or semi-quantitative severity and likelihood rating |
| Action / Recommendation | What needs to change (design, procedure, instrument, SIF) |
| Action Number | Unique identifier for tracking |
| Responsible | Who owns the action |
| Due Date / Status | Target date and current close-out status |
A Fully Worked Node Example
The following example applies HAZOP to a realistic node: the feed line to a continuous stirred-tank reactor (CSTR) carrying a flammable solvent-based feed stream. The design intent is: deliver feed at 5 m³/h, 3.5 barg, to the reactor inlet.
Node Definition
- Node ID: N-04
- Design intent: Deliver feed stream at 5 m³/h and 3.5 barg from the feed tank (T-101) to the reactor inlet (R-201) via feed pump P-101A/B and flow control valve FCV-104.
- Parameters selected: Flow, Pressure, Temperature, Composition
Worked HAZOP Worksheet — Node N-04 (Selected Rows)
| # | Deviation | Cause | Consequence | Safeguards | Action |
|---|---|---|---|---|---|
| N04-01 | No Flow (No + Flow) | FCV-104 fails closed; FT-104 failure causing controller to close FCV; pump P-101A/B fails | Reactor starved of feed; temperature excursion due to uncontrolled exotherm on residual reactants; potential runaway | PAH-201 (high reactor pressure alarm); TAHH-201 (high-high temp shutdown); operator rounds | HAZ-A01: Evaluate need for low-flow safety shutdown on FI-104; assess SIL requirement via LOPA |
| N04-02 | More Flow (More + Flow) | FCV-104 fails open; controller fault; bypass valve inadvertently opened | Reactor over-feed; accumulation of reactants; exotherm and overpressure; PRV-201 lift | FAHH-104 (high-high flow alarm); PRV-201; operator response | HAZ-A02: Confirm FAHH-104 is independent of FCV-104 controller; verify PRV-201 relief capacity for this scenario |
| N04-03 | Reverse Flow (Reverse + Flow) | Loss of pump pressure; check valve CV-101 fails; reactor pressure higher than feed line pressure | Reactor contents back-flow into feed tank T-101; potential contamination or reactive mixture in feed system | Check valve CV-101 | HAZ-A03: Upgrade CV-101 to safety-rated NRV with position confirmation; consider high-pressure interlock to isolate FCV-104 |
| N04-04 | More Temperature (More + Temperature) | Ambient heat gain in summer; steam tracing fault; cross-contamination from hot utility | Feed approaches boiling point; FCV-104 cavitation; partial vaporisation causing loss of flow control; two-phase flow | TAH-104 (high temperature alarm) | HAZ-A04: Assess whether TAHH-104 (high-high trip on feed temperature) is required; define safe operating limit |
| N04-05 | As Well As (As Well As + Composition) | Wrong feed drum connected; maintenance error; supplier error | Incompatible chemistry enters reactor; uncontrolled reaction; potential explosion | Receiving inspection; material identification labels | HAZ-A05: Assess administrative control adequacy; consider inline analyser or connection key system; record in safety case |
What the Worked Example Demonstrates
- The same initiating cause (e.g., FCV-104 fails open) can appear under multiple deviations, since it may cause more flow and high pressure simultaneously. The team records each deviation separately.
- Existing safeguards are credited — but only when they are genuinely independent of the cause. If FCV-104 fails because the controller fails, an alarm generated by the same controller is not independent and cannot be credited.
- Actions N04-01 and N04-03 have been flagged for SIL assessment — they involve a potentially high-consequence scenario where existing safeguards may be insufficient.
From HAZOP Action to Safety Instrumented Function
This is the bridge that differentiates a process-safety-aware controls engineer from one who simply wires interlocks. A HAZOP action that reads "evaluate need for safety shutdown" does not automatically become a SIF — it triggers a Layer of Protection Analysis (LOPA) to determine whether a SIF is needed, and if so, at what SIL target.
The sequence from HAZOP action to commissioned safety PLC looks like this:
- HAZOP action raised — the team identifies that existing safeguards are insufficient for a credible high-severity scenario.
- LOPA conducted — the process safety engineer calculates the unmitigated event frequency and the tolerable frequency from the company risk matrix. The ratio determines the required risk reduction factor (RRF), which maps directly to a SIL target.
- SIF defined — a Safety Instrumented Function is specified: sensor(s), logic solver, final element(s), and the safety action (e.g., close FCV-104, initiate emergency shutdown).
- SIL verification — the SIF design is verified to meet the target SIL, accounting for PFD of each element, proof-test intervals, and architectural constraints (HFT, SFF per IEC 61508/61511).
- Safety PLC programmed — the SIF logic is implemented in the safety PLC using a certified logic solver, with the safety function segregated from the standard control logic and tested to the required proof-test procedure.
- Functional Safety Assessment (FSA) — an independent review confirms the SIF has been correctly specified, designed, and implemented before plant start-up.
What This Means for the Controls Engineer
When you receive a HAZOP action that says "consider high-level safety shutdown on V-201," you are looking at the start of a functional safety lifecycle. The action is not simply a request to add a high-level interlock to the standard PLC. It requires:
- A SIL determination (via LOPA or risk graph) before the design begins
- Selection of a certified logic solver (e.g., a TÜV-certified safety PLC) if SIL 1 or above is assigned
- Segregation of the SIF logic from standard control logic
- A documented proof-test procedure and a proof-test interval that achieves the target PFD
- An entry in the Safety Requirements Specification (SRS), which becomes the governing document for design and testing
This is why the machine safety hub matters for controls engineers: process safety and machine safety share the same underlying standards framework, and a HAZOP-derived SIF follows the same IEC 61511 lifecycle whether the plant is a refinery or a pharmaceutical batch plant.
Common Mistakes in HAZOP Practice
Even experienced teams make these errors:
Crediting non-independent safeguards. If the cause is a controller failure, an alarm from the same controller is not an independent protection layer. The HAZOP team must challenge every credited safeguard for independence.
Skipping N/A cells without justification. Every cell in the guide-word × parameter matrix should be assessed and, if excluded, the reason documented. "Obviously not applicable" is not a sufficient record.
Conflating HAZOP with risk quantification. HAZOP identifies hazards and operability problems. It does not, by itself, determine SIL. That is the job of LOPA or another quantified risk technique.
Treating actions as optional. A HAZOP action is a formal engineering record. Closing an action with "discussed and no change required" without documented engineering justification exposes the company to liability and may not satisfy a regulatory audit.
Reviewing P&IDs that are not yet AFD. HAZOP conducted on preliminary P&IDs wastes time because nodes and instruments change. The P&ID must be stable before the HAZOP begins.
Frequently Asked Questions
What is a HAZOP study?
A HAZOP study (Hazard and Operability Study) is a structured team technique that identifies process hazards and operability problems by applying a set of guide words to each defined section (node) of a process, using the P&ID as the primary reference document. It is standardised in IEC 61882 and is the dominant hazard identification method in the process industries.
What are the seven HAZOP guide words?
The seven primary HAZOP guide words defined in IEC 61882 are: No/None (complete negation), More (quantitative increase), Less (quantitative decrease), Reverse (logical opposite), As Well As (qualitative addition), Part Of (qualitative reduction), and Other Than (complete substitution). Secondary guide words — Early, Late, Before, After, Where Else — are used for batch and sequential processes.
What is the difference between HAZOP and FMEA?
HAZOP analyses process deviations from the design intent at the system or node level, starting from the P&ID. It is best suited to continuous processes and piped systems. FMEA (Failure Mode and Effects Analysis) analyses component failure modes from the bottom up, starting from individual equipment items. HAZOP is stronger at capturing multi-cause, multi-consequence process scenarios; FMEA is stronger at identifying specific equipment reliability issues and prioritising maintenance. Many projects use both — HAZOP for the process P&ID review, FMEA for critical equipment.
Who is in a HAZOP team?
A standard HAZOP team includes a HAZOP leader/facilitator, a process engineer, an instrument and control engineer, an operations representative, a mechanical or piping engineer, a safety engineer, and a scribe. Typically five to eight people attend any single session. The multi-disciplinary mix is essential: a HAZOP conducted without an operations representative or a controls engineer will miss important causes and safeguards.
Related reading: Functional Safety Basics — What Is SIL? — E-Stop and Safety Circuit Design — Machine Safety Hub — How to Read a P&ID
See also: HAZOP glossary entry


