What is LOPA?
Layer of Protection Analysis (LOPA) studies a process accident scenario by estimating its frequency and the contribution of specific protective measures. It is typically used after hazard identification to further explore scenarios requiring risk reduction decisions.
Its scope is more specific than that of a general job evaluation. Each analysis requires a defined sequence, from an initiating event to a consequence. If incompatible causes and outcomes are grouped in the same row, the estimates become meaningless and may attribute protection to equipment that does not act against that scenario.
Define the scenario and the initiating event
The description identifies the operating conditions, the initial deviation, and the consequence to be avoided. The initiating event must have an estimable frequency with appropriate data and a clear time frame. Its selection can be based on a HAZOP study, incidents, or other documented studies.
It is important to distinguish between failure frequency, demand frequency, and probability. Data should not be added or multiplied without verifying that they represent the same thing. The source, its applicability to the installation, and any uncertainties must be recorded. A value from another industry may serve as an initial reference but may require further justification.
What is an independent protective layer?
An independent layer of protection can be a device, system, or action capable of preventing a scenario from reaching a defined outcome. To be considered a layer of protection, it must function independently of the initiator and other layers considered. Furthermore, it needs a clear function and a verifiable and supported performance.
Not all Bow-tie measures can be automatically counted as independent layers. General training, instructions, or alarms without a defined response do not receive numerical credit simply by being mentioned. The method requirements and specific conditions that allow for reliance on its performance must be reviewed.
Dependencies and double counting
Two protective devices can share a sensor, power supply, logic, final component, or the same person for intervention. In such cases, it’s necessary to investigate whether a common cause could compromise them. The appearance of redundancy does not demonstrate independence. A fault tree analysis can help examine relationships that cannot be resolved with a simple list.
Double counting can also occur if a measure is already included in the initiator’s frequency and is reapplied as an additional reduction. The review should reconstruct what each data point represents. Assumptions regarding availability, maintenance, and testing need to correspond to what is actually done at the facility.
Estimation and decision criteria
In a simplified scheme, the frequency of the scenario is combined with the failure probabilities of the accredited layers. The method may consider enabling conditions or modifiers when relevant and justified. Factors should not be added to achieve a favorable outcome, nor should relevant dependencies be omitted.
The result is compared against defined risk criteria for the decision. LOPA alone does not provide a universal threshold of acceptability nor does it replace legal obligations. If an additional reduction need is identified, the solution requires appropriate design and validation. Assigning requirements to instrumented systems necessitates corresponding technical development.
Practical example
As a purely educational exercise, assume an initiator with a frequency of 0.1 per year and two independent layers with a probability of failure on demand of 0.1 each. Under these simplified assumptions, the product is 0.001 per year. These numbers are invented to illustrate the operation and are not intended as design data.
If both layers depend on the same sensor, the previous calculation cannot be accepted as if they were independent. The model and the actual available protection must be reviewed. The example shows why the numerical result depends on the quality of the scenario, the data, and the relationships between its elements. If there are several triggers capable of producing a similar consequence, the analysis must retain their identification and apply consistent criteria to assess the whole. Reviewing a single sequence does not automatically represent the entire risk of the installation.
Maintain layer performance
Critical barriers require testing, maintenance, and response when they fail. An estimate based on periodic testing ceases to reflect reality if those tests are not performed or do not cover the full range of functions. Sufficient records must exist to demonstrate the assumed performance.
Change management must review equipment modifications, conditions, and procedures. Managing temporary overrides and unavailability is also important. A layer accredited in the study cannot be considered indefinitely available without verifying the conditions that allowed it to be granted that accreditation.
Documentation and limitations of the method
The report preserves the scenario, sources, data, assumptions, accredited layers, dependencies, criteria, and decisions. Relevant uncertainties must be clearly stated. Review by competent individuals helps to identify unjustified credits and omissions that a spreadsheet alone cannot resolve.
LOPA is a process safety tool, not an automatic demonstration of total safety. Its value lies in making the relationship between scenario and protection explicit, and in supporting the measures that the analysis deems necessary throughout the entire life of the process.
