🎓 Lesson 2 D2

PHA Types: HAZOP, What-If, FMEA — When to Use Which

PHA types are structured ways to spot potential hazards in mining and blasting operations before they cause harm — like using different checklists for different kinds of risks.

🎯 Learning Objectives

  • Explain the structural differences among HAZOP, What-If, and FMEA in terms of team composition, documentation format, and analytical depth
  • Analyze a blasting design workflow to select the most appropriate PHA method based on stage (e.g., conceptual design vs. operational review) and risk profile
  • Apply decision criteria (e.g., system complexity, data availability, regulatory requirement) to justify PHA method selection in a written engineering rationale
  • Compare and contrast the output deliverables (e.g., risk ranking, action items, SIL recommendations) of each PHA type for a given surface mine blast initiation system

📖 Why This Matters

In mining, a single undetected hazard — like misaligned detonator timing or inadequate stemming — can trigger flyrock, premature detonation, or environmental release. Choosing the wrong PHA method wastes time, misses critical risks, or generates overwhelming false positives. Knowing *when* to use HAZOP (deep, parameter-driven scrutiny), What-If (rapid, experience-based screening), or FMEA (component-specific reliability focus) ensures your safety analysis is fit-for-purpose — not just compliant.

📘 Core Principles

All PHAs share the goal of proactive hazard identification, but diverge in philosophy and execution. HAZOP is *systematic and prescriptive*: it applies guide words (e.g., NO, MORE, LESS, AS WELL AS) to every process node (e.g., 'initiation circuit', 'timing module') to uncover deviations from design intent. What-If is *heuristic and agile*: it poses open-ended questions ('What if the delay timer fails open-circuit?') — ideal for early-stage reviews or informal workshops. FMEA is *quantitative and hierarchical*: it catalogs failure modes per component (e.g., 'blaster’s handset battery depletion'), assigns severity, occurrence, and detection scores (S/O/D), then computes Risk Priority Number (RPN = S × O × D). The choice hinges on three dimensions: (1) maturity of the system (FMEA excels post-design, pre-commissioning), (2) regulatory context (OSHA 1910.119 mandates HAZOP for covered processes), and (3) available data (FMEA requires failure rate databases; What-If needs seasoned field experts).

📐 Risk Priority Number (RPN) Calculation

FMEA quantifies risk using the RPN — a simple multiplicative index that prioritizes failure modes for mitigation. While not predictive of absolute probability, RPN enables relative ranking when quantitative reliability data is limited — common in blasting hardware where field failure statistics are sparse.

Risk Priority Number (RPN)

RPN = S × O × D

A semi-quantitative risk scoring method used in FMEA to rank failure modes by relative risk magnitude.

Variables:
SymbolNameUnitDescription
S Severity dimensionless (1–10 scale) Likely severity of harm (e.g., 1 = nuisance, 10 = multiple fatalities)
O Occurrence dimensionless (1–10 scale) Estimated frequency of failure mode (e.g., 1 = extremely unlikely, 10 = inevitable)
D Detection dimensionless (1–10 scale) Likelihood of detecting failure before hazardous event (e.g., 1 = certain detection, 10 = no detection possible)
Typical Ranges:
Mining blasting hardware FMEA: 12 – 450
High-consequence failure modes (e.g., misfire leading to secondary blast): 200 – 450

💡 Worked Example

Problem: A surface mine’s electronic blasting system includes a wireless initiator. During FMEA, the team assesses the failure mode 'loss of RF signal during arming'. They assign Severity = 8 (potential fatality), Occurrence = 3 (rare, due to redundant comms), Detection = 4 (moderate — visual status lights but no real-time signal strength telemetry). Calculate RPN and interpret.
1. Step 1: Identify S = 8, O = 3, D = 4 (all on 1–10 scale per AIHA RP-2 and IEC 60812)
2. Step 2: Compute RPN = 8 × 3 × 4 = 96
3. Step 3: Compare to typical RPN thresholds: <50 = low priority; 51–100 = medium (review controls); >100 = high (immediate action). RPN = 96 triggers medium-priority action — e.g., adding signal-strength logging.
Answer: The result is 96, which falls within the medium-priority range of 51–100. Recommended action: enhance detection capability (e.g., integrate RSSI telemetry) to reduce D score.

🏗️ Real-World Application

At Newmont’s Boddington Mine (Western Australia), a HAZOP was conducted on the new automated bulk explosive delivery and initiation system prior to commissioning. Guide words were applied to nodes like 'slurry pump flow rate' (deviation: NO FLOW → causes incomplete charging → misfire risk) and 'timing sync signal' (deviation: LATE → causes out-of-sequence firing → ground vibration exceedance). In contrast, during routine quarterly reviews of portable detonator testers, the site used a What-If PHA: 'What if calibration sticker is expired?' led to immediate procedural update. For the legacy wired initiation network upgrade, an FMEA was performed on each cable splice joint, revealing high RPN for 'moisture ingress' — prompting replacement with IP68-rated connectors.

📋 Case Connection

📋 Grain Elevator Dust Explosion Mitigation Using ASTM E1226-Based Risk Model

Historic dust explosions (3 incidents since 1995); inadequate housekeeping and venting

📚 References