Skip to content

HAZOP Joint-Deviation Review

Review — instantiates Conjunctive Path Assurance

Walks a multidisciplinary panel through guide-word deviations taken in combination, surfacing the joint deviations a single-parameter review would miss and owning the residual-risk call.

Every other mechanism here computes or tests; HAZOP Joint-Deviation Review is the one where human judgement does the work. A deliberately diverse panel walks a design node by node, applying guide words — NO, MORE, LESS, AS WELL AS, REVERSE, and the rest — to each parameter, and, in the joint-deviation variant, to combinations of deviations. Its defining move is the room: the value comes from the range of expertise present, catching the plausible, messy conjunction that no formula was told to look for, and — just as important — from the panel owning the judgement of whether the residual risk is tolerable. Where the solvers and tests answer "is this combination possible," HAZOP answers "which combinations are worth worrying about, what do we do about them, and who says so."

Example

A pharmaceutical batch process reaches the node "sterilisation hold." The panel — process engineer, operator, automation lead, QA — applies guide words jointly rather than one at a time: MORE temperature AS WELL AS LESS hold-time. Singly, each is caught by an alarm. Together, the operator points out, a particular recipe edit lets a brief high-temperature excursion coincide with a shortened hold in a way that slips past both single-parameter alarms yet under-sterilises the batch. The panel records the joint deviation, judges the residual risk after existing safeguards, recommends an interlock plus a recipe-change control — and marks the node for re-review if the recipe or the equipment changes. The output is a documented deviation, an owned residual-risk decision, and a re-analysis trigger, not a number.

How it works

Assemble a panel chosen for genuine breadth of expertise; divide the system into nodes; for each node, apply the guide words to parameters and, in this variant, to pairs and combinations of deviations; for every credible deviation trace its causes and consequences, list the existing safeguards, judge whether the residual risk is tolerable, and assign follow-up actions — logging each with its rationale. What distinguishes it is that the mechanism is a facilitated human process: its yield depends on who is in the room and on the discipline of the guide-word sweep, not on an algorithm, which is why it catches the hazard a model was never instructed to consider.

Tuning parameters

  • Panel composition — the range of expertise around the table. Broader catches more cross-domain joint deviations but costs coordination and calendar time.
  • Guide-word set and pairing depth — which guide words are used, and whether they are applied singly or in combination. Combinations catch conjunctive hazards but lengthen the review quickly.
  • Node granularity — how finely the system is divided. Fine nodes are thorough but slow; coarse nodes move fast but blur the interactions that cross node boundaries.
  • Residual-risk threshold — how tolerable "tolerable" is. A strict threshold generates more actions and exceptions; a loose one closes items faster but accepts more.

When it helps, and when it misleads

Its strength is that human judgement catches the plausible, cross-disciplinary joint deviation a model would never be told to consider, and it produces an owned residual-risk decision with an audit trail — something no solver delivers. Its failure mode is that it is only as good as the panel and the facilitation: fatigue, groupthink, a missing discipline, or one dominating voice all leave gaps, it is slow, and its completeness can never be proven. The classic misuse is running it as a rubber stamp to close a gate, or narrowing the scope to finish on schedule. The discipline is to staff the panel for real diversity, timebox nodes to fight fatigue, and pair the qualitative review with a computational method so human and machine cover each other's blind spots.[1]

How it implements the components

  • operator_and_domain_review_panel — the mechanism is the multidisciplinary panel and its facilitated guide-word sweep.
  • residual_risk_and_exception_decision — the panel judges and records whether the residual risk is tolerable and what exceptions or actions apply.
  • change_trigger_and_reanalysis_rule — it marks nodes for re-review when the design, recipe, or equipment changes.

It judges rather than computes or tests: the minimal_activating_conjunction_set is Fault Tree with AND-Gate Logic's and Boolean SAT or SMT Path Search's, and the empirical end_to_end_activation_oracle is Full-Factorial Joint-State Test's; it decides on and documents the residual risk rather than designing the guard.

Notes

HAZOP is often the front-line qualitative sweep that decides which quantitative analyses are worth the effort — pointing at the fault trees to build and the combinations to test — while also owning the residual-risk call. Treat it as the router and risk-owner, not the calculator; its verdicts are strongest when a computational method checks the conjunctions it flags.

References

[1] HAZOP's guide words (NO, MORE, LESS, AS WELL AS, PART OF, REVERSE, OTHER THAN) are a fixed prompt set applied to each parameter to force systematic consideration of deviations; the standard method is described in IEC 61882. Applying them to combinations of parameters is what extends the classic single-deviation sweep to conjunctive hazards.