Learn PLCs free
Programming Guides17 min read3,237 words

HAZOP Study Explained: Guide Words, Process, and a Worked Example

A HAZOP study explained — the node concept, the seven guide words, the workshop process and worksheet, and how a HAZOP action becomes a safety instrumented function.

PPI
PLC Programming IO Editorial Team
Sourced guidance with documented review and correction standards

A HAZOP study (Hazard and Operability Study) is a structured, team-based technique for identifying process hazards and operability problems by systematically applying a set of guide words to each defined section of a process. The result is a prioritised list of recommended actions — some of which directly become safety instrumented functions (SIFs) implemented on a safety PLC.

What Is a HAZOP Study?

HAZOP was developed by ICI in the UK during the 1960s and formalised in IEC 61882 (Hazard and Operability Studies — Application Guide). It has since become the dominant hazard identification method in the oil and gas, chemical, pharmaceutical, and power industries.

The technique works by taking a process design — typically represented on a P&ID — and asking a disciplined question for every section of that design: "What happens if this process parameter deviates from its intention?" The word "operability" in the name is deliberate. HAZOP captures problems that degrade production and quality, not just those that injure people.

When Is a HAZOP Required — and When Should You Use Something Else?

HAZOP sits alongside several other risk techniques. Understanding where it fits prevents over- or under-specification:

Technique Best suited for Typical output
HAZID Early design; facility-level hazard identification Hazard register, qualitative risk ranking
HAZOP Detailed design; node-by-node P&ID review Deviation table, action register
FMEA Equipment and component failure modes Failure mode register, maintenance priorities
LOPA Quantifying risk reduction needed after HAZOP SIL target for each SIF
QRA Major accident risk estimation Individual/societal risk contours

A HAZOP is typically conducted after the P&IDs reach Approved for Design (AFD) status — detailed enough to identify instruments, control valves, and interlocks, but before construction begins when changes are still economical. It is usually followed by a LOPA (Layer of Protection Analysis) for the scenarios that require a quantified risk-reduction target.

The Node Concept

The HAZOP team does not review an entire plant simultaneously. The P&ID is first divided into nodes — discrete sections of the process that have a clearly defined design intent (what the process is supposed to do there) and a defined set of process parameters (flow, temperature, pressure, level, composition, etc.).

A node might be:

  • A single pipeline segment between two vessels
  • A reactor feed section including the control valve, flow meter, and isolation valve
  • A storage tank and its associated level control loop

The node boundary is drawn to capture the cause–consequence relationship cleanly. If a pump and its downstream control valve share a cause–consequence link, they belong in the same node. If they are independent sections with their own intentions, they are separate nodes.

Selecting Process Parameters

For each node, the team identifies which process parameters are relevant. Common parameters include:

  • Flow — the most common parameter; applies to nearly every pipeline node
  • Temperature — critical for reaction nodes, heat exchangers, fired equipment
  • Pressure — relevant wherever pressure containment or protection is designed
  • Level — vessel and separator nodes
  • Composition / Concentration — reactor feeds, blending, chemical storage
  • Phase — where liquid/vapour separation matters
  • Reaction — for reactive systems (rate, selectivity, exotherm)
  • Time / Sequence — batch processes and start-up/shutdown procedures

The Seven HAZOP Guide Words

The power of HAZOP comes from its guide words — a fixed vocabulary that forces the team to consider the complete space of deviations from the design intention. IEC 61882 defines seven primary guide words:

Guide Word Meaning Example deviation
No / None Complete negation of the intention No flow in a feed line
More Quantitative increase above the intention High flow, high pressure, high temperature
Less Quantitative decrease below the intention Low flow, low pressure, low level
Reverse Logical opposite of the intention Reverse flow, reverse reaction
As Well As Qualitative increase — something extra Contamination, additional phase present
Part Of Qualitative decrease — something missing Partial composition, incomplete separation
Other Than Complete substitution — something else entirely Wrong material, maintenance mode active

These seven guide words are applied to each parameter at each node, generating a matrix of deviations. Not every combination is meaningful — "No temperature" rarely makes physical sense — but the discipline of checking each cell prevents the team from unconsciously skipping scenarios that feel unlikely.

HAZOP deviation matrix: guide words applied to process parameters to generate deviations Grid showing seven guide words (No, More, Less, Reverse, As Well As, Part Of, Other Than) as columns and four process parameters (Flow, Pressure, Temperature, Level) as rows. Cells show example deviations or N/A where not applicable. HAZOP Deviation Matrix — Guide Word × Parameter No / None More Less Reverse As Well As Part Of Other Than Flow No flow / blocked line High flow / cv failed open Low flow / cv failed closed Backflow / check vlv failure Two-phase / contamination Wrong composition Wrong fluid / maintenance iso Pressure Zero pressure / vacuum collapse Overpressure / PRV lift Low pressure / pump cavitation N/A Pressure + surge transient N/A External fire / source change Temp. N/A High temp / runaway risk Low temp / freezing / brittle N/A Heat + vibration combined effect N/A Wrong utility / cooling failure Level Empty vessel / pump deadhead High level / overflow Low level / loss of suction N/A Level + foam / interface layer N/A Wrong vessel / wrong product Each cell = one deviation to analyse; N/A cells are excluded by the team after checking — not assumed
Fig. 1 — HAZOP deviation matrix. The team applies each guide word to each parameter at the current node. Not every cell is physically credible; the team documents why N/A cells are excluded rather than silently skipping them.

Secondary Guide Words

IEC 61882 also lists secondary guide words that capture intent-level deviations not fully covered by the primary seven: Early, Late, Before, After (for sequence and timing in batch processes), and Where Else (for spatial deviations such as wrong destination). These become especially important during HAZOP of batch recipes and start-up procedures.

The Workshop Process and Team Roles

A HAZOP is a facilitated workshop, not a desk review. It requires a multi-disciplinary team in the same room — typically for two to four hours per node, over several days or weeks for a large plant. The discipline mix is essential because causes and consequences cross engineering boundaries.

Core Team Members

Role Responsibility
HAZOP Leader / Facilitator Controls the methodology; ensures every guide word is applied; prevents the team from jumping to solutions before recording the deviation fully
Process Engineer Explains the design intent; describes expected causes and consequences
Instrument / Control Engineer Describes existing interlocks, control loops, and alarms; identifies where a safety PLC function may be needed
Operations Representative Brings operational experience; identifies human factor causes and consequences
Mechanical / Piping Engineer Addresses equipment failure modes and layout issues
Safety Engineer Assesses consequence severity; links to the major hazard register
Scribe / Recorder Captures deviations, causes, consequences, safeguards, and actions in the HAZOP worksheet in real time

The team size is usually five to eight people. Fewer than five risks missing knowledge; more than eight makes facilitation difficult and the session slow.

HAZOP workshop process: five sequential phases from preparation through close-out Five horizontal steps connected by arrows: 1 Preparation (P&IDs, node list), 2 Deviation Generation (guide word × parameter), 3 Consequence Assessment (severity and likelihood), 4 Safeguard Review (existing layers), 5 Action Assignment (recommendation to responsible person with due date). A feedback arrow from Action Assignment back to Deviation Generation shows iterative review. 1. Prepare Finalise P&IDs Define nodes 2. Deviations Guide word × parameter matrix 3. Consequence Severity + likelihood without safeguards 4. Safeguards Existing layers of protection (IPLs) 5. Actions Recommendation + responsible / date Iterative: new node → repeat steps 2–5 Pre-meeting Workshop Workshop Workshop Workshop + follow-up Actions are tracked to close-out; those requiring SIL verification proceed to LOPA
Fig. 3 — HAZOP workshop process. Steps 2–5 are repeated for each node. Actions that identify a need for a new or upgraded safety function proceed to LOPA and SIL determination.

The Workshop Sequence

For each node, the facilitator works through the following sequence:

  1. State the design intent — the scribe records it verbatim at the top of the node sheet.
  2. Select parameter — start with the most critical parameter (usually flow for pipeline nodes).
  3. Apply guide word — generate the deviation (e.g., "More Flow").
  4. Identify credible causes — instrument failures, operator error, upstream upsets. Only credible causes for this process and design are recorded; exotic theoretical causes can be noted separately.
  5. Identify consequences — what happens if the deviation persists? Follow the chain until the top event (injury, release, equipment damage) is reached.
  6. Identify existing safeguards — alarms, interlocks, relief valves, procedures. These reduce risk but do not eliminate the deviation.
  7. Assess residual risk — does the combination of severity and likelihood, with existing safeguards credited, meet the company risk criteria?
  8. Raise actions — if the residual risk is unacceptable or uncertain, raise a formal action with a responsible person and target date.

The HAZOP Worksheet

The worksheet is the permanent record of the HAZOP. Each row represents one deviation at one node. Industry standard columns are:

Column What to record
Node Node identifier and a brief description of the design intent
Parameter The process parameter being examined
Guide Word The guide word applied
Deviation The guide word + parameter phrase (e.g., "High Flow")
Cause One or more credible initiating causes
Consequence The worst credible outcome without safeguards
Safeguards Existing independent protection layers (IPLs) that prevent or mitigate the consequence
Likelihood (S/L) Qualitative or semi-quantitative severity and likelihood rating
Action / Recommendation What needs to change (design, procedure, instrument, SIF)
Action Number Unique identifier for tracking
Responsible Who owns the action
Due Date / Status Target date and current close-out status
HAZOP worksheet flow: from deviation through cause, consequence, safeguard, to action Five connected boxes in a horizontal flow: Deviation feeds into Cause, which feeds into Consequence, which is partially blocked by Safeguards, which determines whether an Action is needed. A risk acceptance gate sits between safeguards and the action decision. Deviation Guide word + parameter Cause Credible initiating event / failure Consequence Worst credible outcome (no IPLs) Safeguards Existing IPLs alarm, relief, SIS Risk OK? Yes No action needed No Action Redesign / new SIF / alarm IPL = Independent Protection Layer; each IPL must be independent of the cause and of other IPLs
Fig. 2 — HAZOP worksheet logic flow. When existing safeguards do not reduce residual risk to the tolerable level, the team raises a formal action — which may require a new or upgraded safety instrumented function.

A Fully Worked Node Example

The following example applies HAZOP to a realistic node: the feed line to a continuous stirred-tank reactor (CSTR) carrying a flammable solvent-based feed stream. The design intent is: deliver feed at 5 m³/h, 3.5 barg, to the reactor inlet.

Node Definition

  • Node ID: N-04
  • Design intent: Deliver feed stream at 5 m³/h and 3.5 barg from the feed tank (T-101) to the reactor inlet (R-201) via feed pump P-101A/B and flow control valve FCV-104.
  • Parameters selected: Flow, Pressure, Temperature, Composition

Worked HAZOP Worksheet — Node N-04 (Selected Rows)

# Deviation Cause Consequence Safeguards Action
N04-01 No Flow (No + Flow) FCV-104 fails closed; FT-104 failure causing controller to close FCV; pump P-101A/B fails Reactor starved of feed; temperature excursion due to uncontrolled exotherm on residual reactants; potential runaway PAH-201 (high reactor pressure alarm); TAHH-201 (high-high temp shutdown); operator rounds HAZ-A01: Evaluate need for low-flow safety shutdown on FI-104; assess SIL requirement via LOPA
N04-02 More Flow (More + Flow) FCV-104 fails open; controller fault; bypass valve inadvertently opened Reactor over-feed; accumulation of reactants; exotherm and overpressure; PRV-201 lift FAHH-104 (high-high flow alarm); PRV-201; operator response HAZ-A02: Confirm FAHH-104 is independent of FCV-104 controller; verify PRV-201 relief capacity for this scenario
N04-03 Reverse Flow (Reverse + Flow) Loss of pump pressure; check valve CV-101 fails; reactor pressure higher than feed line pressure Reactor contents back-flow into feed tank T-101; potential contamination or reactive mixture in feed system Check valve CV-101 HAZ-A03: Upgrade CV-101 to safety-rated NRV with position confirmation; consider high-pressure interlock to isolate FCV-104
N04-04 More Temperature (More + Temperature) Ambient heat gain in summer; steam tracing fault; cross-contamination from hot utility Feed approaches boiling point; FCV-104 cavitation; partial vaporisation causing loss of flow control; two-phase flow TAH-104 (high temperature alarm) HAZ-A04: Assess whether TAHH-104 (high-high trip on feed temperature) is required; define safe operating limit
N04-05 As Well As (As Well As + Composition) Wrong feed drum connected; maintenance error; supplier error Incompatible chemistry enters reactor; uncontrolled reaction; potential explosion Receiving inspection; material identification labels HAZ-A05: Assess administrative control adequacy; consider inline analyser or connection key system; record in safety case

What the Worked Example Demonstrates

  • The same initiating cause (e.g., FCV-104 fails open) can appear under multiple deviations, since it may cause more flow and high pressure simultaneously. The team records each deviation separately.
  • Existing safeguards are credited — but only when they are genuinely independent of the cause. If FCV-104 fails because the controller fails, an alarm generated by the same controller is not independent and cannot be credited.
  • Actions N04-01 and N04-03 have been flagged for SIL assessment — they involve a potentially high-consequence scenario where existing safeguards may be insufficient.

From HAZOP Action to Safety Instrumented Function

This is the bridge that differentiates a process-safety-aware controls engineer from one who simply wires interlocks. A HAZOP action that reads "evaluate need for safety shutdown" does not automatically become a SIF — it triggers a Layer of Protection Analysis (LOPA) to determine whether a SIF is needed, and if so, at what SIL target.

The sequence from HAZOP action to commissioned safety PLC looks like this:

  1. HAZOP action raised — the team identifies that existing safeguards are insufficient for a credible high-severity scenario.
  2. LOPA conducted — the process safety engineer calculates the unmitigated event frequency and the tolerable frequency from the company risk matrix. The ratio determines the required risk reduction factor (RRF), which maps directly to a SIL target.
  3. SIF defined — a Safety Instrumented Function is specified: sensor(s), logic solver, final element(s), and the safety action (e.g., close FCV-104, initiate emergency shutdown).
  4. SIL verification — the SIF design is verified to meet the target SIL, accounting for PFD of each element, proof-test intervals, and architectural constraints (HFT, SFF per IEC 61508/61511).
  5. Safety PLC programmed — the SIF logic is implemented in the safety PLC using a certified logic solver, with the safety function segregated from the standard control logic and tested to the required proof-test procedure.
  6. Functional Safety Assessment (FSA) — an independent review confirms the SIF has been correctly specified, designed, and implemented before plant start-up.
Bridge from HAZOP action to safety instrumented function on a safety PLC Six sequential boxes connected by arrows: HAZOP Action leads to LOPA (SIL target), then to SIF Specification (sensor, logic, final element), then to Safety PLC programming, then to SIL Verification (PFD calculation), then to Functional Safety Assessment (FSA). A color gradient goes from amber at HAZOP through green at SIF Spec to blue at safety PLC to violet at FSA. HAZOP Action Residual risk unacceptable LOPA Calculate RRF Assign SIL target (SIL 1 / 2 / 3) SIF Spec. Sensor(s) + logic solver + final element defined Safety PLC SIF logic coded in certified logic solver SIL Verify PFD calculation Architecture check (HFT/SFF) FSA Independent review before start-up IEC 61511 (Process) / IEC 61508 IEC 61508 / TÜV-certified hardware Process safety Risk analysis Engineering Controls design Verification Assurance A single HAZOP action can trigger this entire lifecycle — the controls engineer owns the safety PLC step
Fig. 4 — From HAZOP action to commissioned safety instrumented function. The controls engineer is responsible for the Safety PLC step; the LOPA and FSA steps require a process safety engineer or competent authority.

What This Means for the Controls Engineer

When you receive a HAZOP action that says "consider high-level safety shutdown on V-201," you are looking at the start of a functional safety lifecycle. The action is not simply a request to add a high-level interlock to the standard PLC. It requires:

  • A SIL determination (via LOPA or risk graph) before the design begins
  • Selection of a certified logic solver (e.g., a TÜV-certified safety PLC) if SIL 1 or above is assigned
  • Segregation of the SIF logic from standard control logic
  • A documented proof-test procedure and a proof-test interval that achieves the target PFD
  • An entry in the Safety Requirements Specification (SRS), which becomes the governing document for design and testing

This is why the machine safety hub matters for controls engineers: process safety and machine safety share the same underlying standards framework, and a HAZOP-derived SIF follows the same IEC 61511 lifecycle whether the plant is a refinery or a pharmaceutical batch plant.

Common Mistakes in HAZOP Practice

Even experienced teams make these errors:

Crediting non-independent safeguards. If the cause is a controller failure, an alarm from the same controller is not an independent protection layer. The HAZOP team must challenge every credited safeguard for independence.

Skipping N/A cells without justification. Every cell in the guide-word × parameter matrix should be assessed and, if excluded, the reason documented. "Obviously not applicable" is not a sufficient record.

Conflating HAZOP with risk quantification. HAZOP identifies hazards and operability problems. It does not, by itself, determine SIL. That is the job of LOPA or another quantified risk technique.

Treating actions as optional. A HAZOP action is a formal engineering record. Closing an action with "discussed and no change required" without documented engineering justification exposes the company to liability and may not satisfy a regulatory audit.

Reviewing P&IDs that are not yet AFD. HAZOP conducted on preliminary P&IDs wastes time because nodes and instruments change. The P&ID must be stable before the HAZOP begins.

Frequently Asked Questions

What is a HAZOP study?

A HAZOP study (Hazard and Operability Study) is a structured team technique that identifies process hazards and operability problems by applying a set of guide words to each defined section (node) of a process, using the P&ID as the primary reference document. It is standardised in IEC 61882 and is the dominant hazard identification method in the process industries.

What are the seven HAZOP guide words?

The seven primary HAZOP guide words defined in IEC 61882 are: No/None (complete negation), More (quantitative increase), Less (quantitative decrease), Reverse (logical opposite), As Well As (qualitative addition), Part Of (qualitative reduction), and Other Than (complete substitution). Secondary guide words — Early, Late, Before, After, Where Else — are used for batch and sequential processes.

What is the difference between HAZOP and FMEA?

HAZOP analyses process deviations from the design intent at the system or node level, starting from the P&ID. It is best suited to continuous processes and piped systems. FMEA (Failure Mode and Effects Analysis) analyses component failure modes from the bottom up, starting from individual equipment items. HAZOP is stronger at capturing multi-cause, multi-consequence process scenarios; FMEA is stronger at identifying specific equipment reliability issues and prioritising maintenance. Many projects use both — HAZOP for the process P&ID review, FMEA for critical equipment.

Who is in a HAZOP team?

A standard HAZOP team includes a HAZOP leader/facilitator, a process engineer, an instrument and control engineer, an operations representative, a mechanical or piping engineer, a safety engineer, and a scribe. Typically five to eight people attend any single session. The multi-disciplinary mix is essential: a HAZOP conducted without an operations representative or a controls engineer will miss important causes and safeguards.


Related reading: Functional Safety BasicsWhat Is SIL?E-Stop and Safety Circuit DesignMachine Safety HubHow to Read a P&ID

See also: HAZOP glossary entry

#HAZOP#processsafety#guidewords#SIF#functionalsafety#riskassessment
Share this article:

Related Articles