NPSAG RAPPORT

Size: px
Start display at page:

Download "NPSAG RAPPORT"

Transcription

1 NPSAG RAPPORT Evaluation of Existing Applications and Guidance on Methods for HRA EXAM-HRA HRA Application guide NPSAG Report Gunnar Johanson, Sandra Jonsson 1 Kent Bladh, Tobias Iseland and Karl-Henrik Karlsson, 2 Anders Karlsson, Julia Ljungbjörk 3 Günter Becker 4 Lasse Tunturivuori 5 Markus Porthin 6 Anders Olsson 7 Jörg Böhm 8 1 ÅF Industry 2 Vattenfall 3 Forsmark NPP (FKA) 4 RISA 5 Olkiluoto NPP (TVO) 6 VTT 7 Lloyd's Register Consulting 8 Mühleberg NPP (KKM) Nordiska PSA Gruppen (NPSAG) är samarbete för forskning och utveckling inom PSA-relaterade frågor vid de nordiska kärnkraftverken

2

3

4 Issued by Sandra Jonsson Reviewed by Anna Georgiadis Approved by Gunnar Johansson Distribution Sign Sign Sign REPORT Document-ID Project number Client RAB, FKA, SSM HRA APPLICATION GUIDE Summary: This report is intended to provide guidance of the scope of HFEs (human failure event) to include in the HRA (human reliability analysis) applications in a plant specific PSA level 1 or 2 in order to improve the consistency of in-depth HRA and HEP (human error probability) assessment. Accordingly, this report is the result of performed survey and case studies in the EXAM-HRA project and presents an overview of operator actions represented by HFEs which are recommended to be covered in an HRA. The HRA application evaluation includes the following tasks: - By using the results from the survey of existing applications, an HRA application framework can be presented where for each HFE a context description can be formulated. This to provide a framework for screening and identification of candidate HFEs, including examples from the survey. Here a categorisation of the actions must be performed the in order to identify groups of operator action to compare. The initial grouping is based on action type, i.e. pre initiator (type A), initiator (type B) or post initiator (type C). - By using the check list developed in the project to assess the rationale for inclusion or exclusion of actions in the PSA model in question. The check list can be used initially as a part of the PSA model development or at a later stage as a part of a PSA model review. The application guide can be used as a tool for identification. By following the guide means are provided to get an understanding of how the HFE scope has been defined and how analysed operator actions have been chosen This document or any part of it may not be copied without permission of client or ÅF 1 (43)

5 R E V I S I O N S Ver. Cause / Reviewed pages Issued by Reviewed/Reg.no. Approved 1.0 New report SJ AG/ GJ New report/tables without numbers SJ AG/ GJ 2 (43)

6 LIST OF CONTENT LIST OF CONTENT... 3 REFERENCES BACKGROUND INTRODUCTION HFE CONTEXT DESCRIPTIONS CHECK LIST FOR REASONING FOR INCLUSION OR EXCLUSION OF ACTIONS HFE CONTEXT DESCRIPTION ACTION TYPE A PRE INITIATOR ACTION TYPE B INITIATOR ACTION TYPE C POST INITIATOR Connection to safety function Operating mode Level 1 and level 2 PSA HRA APPLICATION FRAMEWORK FOR PRE-INITIATORS LATENT ERRORS DEPENDENCIES HRA APPLICATION FRAMEWORK FOR INITIATORS LOCA/LEAKS Faulty opening of valve During work Valve opens due to misstake during test LOCAs due to Faulty maintenance Faulty handling of sealing PLugs/bottles/flanges Leakage through heat exchanger Faulty inspection PRESSURE EVENTS Pressure relief system Cold pressurization Faulty Alignment of systems/high temperature Faulty maintenance leading to pressure event or leak HEAVY LOAD DROP LOSS OF SYSTEM FUNCTION (43)

7 5.4.1 Loss of systems FAULTY LOADING OF FUEL HRA APPLICATION FRAMEWORK FOR POST-INITIATORS REACTIVITY CONTROL Manual actions regarding reactivity Boration after recriticality Manual Scram Failure to activate boron injection INTEGRITY OF RCPB Stop main feed water Isolation of main steam Isolation of Steam lines to ECCS/AFW EMERGENCY CORE COOLING Closing of containment air lock Flushing of strainers Manual activation of external water supply Manual activation of external water supply Feeding via pump seal/ rod lubrication Manual depressurization of RPV Manual actuation ECCS/AFW Regulate water level in RPV, power operation Regulate water level in RPV, shutdown Manual activation of dilution feed functions Manual restart of main feed water/auxiliary feed water Filling reactor pool with external water Core reflood RESIDUAL HEAT REMOVAL Manual restoration of residual heat removal Manual restoration of residual heat removal Flooding of containment with external water source Forced cooling with reactor water cleanup system manual activation of residual heat removal system at high pressure Manual activation of spray system Manual opening of containment pressure relief valve Closing of safety and pressure relief valves (43)

8 6.4.9 Manual connection of residual heat removal heat exchanger Residual heat removal using fuel pool cooling and cleanup system Feeding fuel storage pool using RHR system Feeding fuel storage pool using external water supply CONTAINMENT INTEGRITY Containment venting PSA level Containment venting, PSA level Containment isolation, PSA level Containment isolation, PSA level Containment water filling PSA level Containment water filling PSA level Containment spray Lower drywell flooding Stop of containment water filling Manual action after external pipe rupture (several systems) OTHER Failed activation of standby service/secondary water pump Failed restart of shutdown cooling water system /secondary water pump Failed local start of standby service/secondary water pump Failed manual actions regarding sea/river water inlet to ensure service cooling water Switch from diesel grid to external network Diesel activation from main control room Diesel activation from local control room Diesel activation from the diesel room fails Manual activation of gas turbines Connection of mobile generator Manual start of compressors in nitrogen system Manual connection of pressurized air network Failed manual isolation of leak CONCLUSIONS (43)

9 REFERENCES [1] SSM FS 2008:17 The Swedish Nuclear Power Inspectorate s Regulations concerning the Design and Construction of Nuclear Power Reactors [2] IAEA Safety standards series Safety of Nuclear Power Plants: Design Requirements No. NS-R-1 [3] ES-konsult report Survey regarding operator actions across six plant specific PSAs from Germany, Sweden and Finland [4] Draft EXAM HRA Case study C.13 Loca during shutdown [5] EXAM-HRA Case study C.0 - Closing of containment AirlockVTT-R , 2011 [6] EXAM HRA Case study C.2 External water supply, Scandpower Report R-003, version U1 [7] EXAM HRA Case study C.1p Manual Restoration of Residual Heat Removal System during full power operation, Scandpower Report R-001, version U2 [8] EXAM HRA Case study C.1s Manual Restoration of Residual Heat Removal System during shutdown conditions, Scandpower Report R-002, version U1 [9] EXAM HRA Case study C.7/C.13 - Containment water filling, C.7 - PSA level 1 / C.13 - PSA level 2. VTT-R [10] EXAM HRA Case study C.10 - Assessment of manual depressurization of the containment (venting). RISA Report nr Berlin (43)

10 1 BACKGROUND This report is part of the reporting of the EXAM-HRA project. In the project human reliability analysis (HRA) applications in existing probabilistic safety assessment (PSA) studies are assessed. The overall project objective is both to provide guidance for a state of the art HRA for purposes of PSA, to ensure that plant specific properties are properly taken into consideration in the analysis, and to give insights for potential plant improvements. This report is intended to provide guidance of the scope of humna failure events to include in the HRA applications in a plant specific PSA level 1 or 2 in order to improve the consistency of in-depth HRA and HEP assessment. HFE stands for human failure event and in the context of PSA it can be represented by a basic event, which stands for the failure of a task, which will lead to one of, or even both, of the following consequences: Degradation (latent failures) or unavailability of a system/function required for mitigation An initiating event Sometimes, a task is split into more than one basic event (diagnosis / decision making and implementation). The table of candidate HFEs presented in the survey report [3] has been used to develop this guidance document on HRA application scope. Accordingly, this report is the result of performed survey and case studies in the EXAM-HRA project and presents an overview of operator actions represented by HFEs which are recommended to be covered in an HRA. 7 (43)

11 2 INTRODUCTION This report should be considered as a guidance document of the evaluation process when selecting HFEs to be included in the scope of HRA applications. In this section an introduction to the evaluation process is presented and in the subsequent sections each task within the process is described in detail as well as results of the tasks. The HRA application evaluation includes the following tasks: - By using the results from the survey of existing applications, an HRA application framework can be presented where for each HFE a context description can be formulated. This to provide a framework for screening and identification of candidate HFEs, including examples from the survey. - By using the check list to assess the rationale for inclusion or exclusion of actions in the PSA model in question The application guide can be used as a tool for identification. By following the guide means are provided to get an understanding of how the HFE scope has been defined and how analysed operator actions have been chosen. 2.1 HFE CONTEXT DESCRIPTIONS The aim of the HFE context description is to give an understanding of the plant model and the preconditions for a specific operator action and aims at reaching an understanding of when and why the manual action is required. In sections 4-6 the HRA application framework from the different plants have been compiled into an overall scope, i.e. list of HFEs, with a HFE context description of how other plants have done it: - What is the operating mode? - After which initiating event is the action considered? - What is the overall task to be performed? - In what scenario context does the action appear, i.e. when is the action relevant? - HRA/HFE, definition of operator action 2.2 CHECK LIST FOR REASONING FOR INCLUSION OR EXCLUSION OF ACTIONS A practical tool in form of a checklist has been developed in the project, see Table 1. This check list shall be used for checking the rationale for inclusion or exclusion of actions in the PSA models. The idea here is that an evaluation of the scope of HRA application is performed based on the check list and applied on each operator action identified in the project survey. The check list can be used initially as a part of the PSA model development or at a later stage as a part of a PSA model review. In section 4-6 the outcome of the survey and case studies performed in the project is presented which consists of lists of HFEs. These lists can be seen 8 (43)

12 as recommendations of HFEs that should be covered in an HRA in order to reflect the plant features as good as possible. Why excluded? Reasons relating to plant design. Action not possible in specific plant design. Action is possible, but time is too short. Action is possible, but it is too complex to benefit from. Reasons relating to PSA concept. Action is not credited, because it is a backup to an automatic activation. Action is not credited, because it goes into an "and-gate" with some other event with low probability. Action is neglected, because it goes into an "or-gate" with some other event with large probability. Action is not credited, because it is known not to contribute to PSA results. Action is not included into the model to keep PSA logic simple. Action is beyond scope of PSA. Reasons relating to methodological constraints. Action is not credited due to lack of written procedures. Action is not credited, because the method used is not applicable (e.g. too many skill based or knowledge based aspects). Action is not credited, because too little is known about the context, or the context is too variable to obtain a probability value. Action is not credited, because it would yield too small total HRA contribution to a SINGLE minimal cut set. Administrative reasons. Action could have been credited, but there was lack of time. Action could have been credited, but there was lack of other resources. None of the above; please specify. Table 1. Check list for reasoning. 9 (43)

13 3 HFE CONTEXT DESCRIPTION In order to identify groups of operator action to compare, some kind of categorisation must be performed. In the case studies, all participating plants have submitted information regarding operator actions which is used for grouping and selection of actions for further evaluation. The completed survey has been reviewed during work group meetings, giving all participants the opportunity to give some explanation and input regarding the different operator actions. The survey contains information about unit, basic event ID and basic event description for all operator actions and for each action the following information (if applicable) is submitted: - Action type, i.e. pre initiator (type A), initiator (type B) or post initiator (type C) action - Operating mode - PSA level 1 or level 2 - Connection to initiating event (only initiators) - Connection to safety function (only post initiators) - HEP - Importance measure In this report limited information about the operator actions is presented and complete information can be found in the survey report [3]. 3.1 ACTION TYPE A PRE INITIATOR Pre initiator actions are such actions where equipment availability is degraded during for example testing and maintenance. The error is not immediately exposed but leads to affected function of the system whenever it is needed. Hence, the error can be latent for long time without notice. A framework regarding selecting pre initiators is presented in section ACTION TYPE B INITIATOR Initiator actions are directly causing or contributing to an initiating event. Initiator actions are therefore grouped based on what type of initiating event they contribute to, instead of categorising according to safety functions. A framework regarding selecting initiators is presented in section ACTION TYPE C POST INITIATOR Post initiator actions are such actions that occur after the initiating event. The actions can both aggravate and improve the situation. 10 (43)

14 The categorisation for post initiator actions is based on safety functions, as for the pre initiator actions. However, for post initiator actions additional sub categorisation is performed when applicable according to the IAEA safety function as described in section Table 2. A framework regarding selecting post initiators is presented in section CONNECTION TO SAFETY FUNCTION In order to categorise post initiator operator actions to specific safety functions it is essential to define the safety functions. The safety function categorisation is performed based on five main categories [1]: 1) Reactivity control 2) Integrity of reactor coolant pressure boundary 3) Emergency core cooling 4) Residual heat removal 5) Containment function 1 An additional main category named 6) Other, including safety functions such as pneumatic and electrical power supply, is added. These six categories have been further specified with the help of IAEAs list of safety functions [2], see Table 2. 1 REACTIVITY CONTROL 11 to prevent of unacceptable reactivity transients 12 to maintain the reactor in a safe shut down condition after all shutdown actions 13 to shut down the reactor as necessary to prevent anticipated operational occurrences from leading to design basis accident and to shut down the reactor to mitigate the consequence of design basis accidents 14 to maintain sufficient subcriticality of fuel stored outside the reactor coolant system but within the site 2 INTEGRITY OF REACTOR COOLANT PRESSURE BOUNDARY 21 to maintain the integrity of the reactor coolant pressure boundary 3 EMERGENCY CORE COOLING 31 to maintain sufficient reactor coolant inventory for core cooling in and after accident conditions not involving the failure of the reactor coolant pressure boundary 32 to maintain sufficient reactor coolant inventory for core cooling in and after all PIE considered in the design basis 1 For BWR the containment function refers to containment leaktightness function and pressure suppression function. For PWR the containment function refers to leaktightness function only. 11 (43)

15 33 to maintain acceptable integrity of the cladding of the fuel in the reactor core 4 RESIDUAL HEAT REMOVAL 41 to remove heat from the core 2 after a failure of the reactor coolant pressure boundary in order to limit fuel damage 42 to remove residual heat (see footnote 2) in appropriate operational states and accident conditions with the reactor coolant pressure boundary intact 43 to remove decay heat from irradiated fuel stored outside the reactor coolant system but within the site 5 CONTAINMENT FUNCTION 51 to limit the release of radioactive material from the reactor containment in accident conditions following an accident 52 to limit the radiation exposure of the public and site personnel in and following design basis accidents and selected severe accidents that release radioactive materials from sources outside the reactor containment 53 to limit the discharge or release of radioactive waste and airborne radioactive materials to below prescribed limits in all operational states 6 OTHER 61 to transfer heat from other safety systems to ultimate heat sink 3 62 to ensure necessary services (such as electrical, pneumatic, hydraulic power supplies, lubrication) as a support function for safety system 63 to prevent the failure or limit the consequences of failure of a structure, system or component whose failure would cause impairment of a safety function 64 to maintain control of environmental conditions within the plant for the operation of safety systems and for habitability for personnel necessary to allow performance of operations important to safety 65 to maintain control of radioactive releases from irradiated fuel transported or stored outside the reactor coolant system, but within the site, in all operational states Table 2. Definition of safety functions according to SSM and IAEA. 2 This safety function applies to the first step of the heat removal system(s). The remaining step(s) are encompassed in safety function (61). 3 This is a support function for other safety systems when they must perform their safety functions. 12 (43)

16 3.3.2 OPERATING MODE The following operating modes are used for categorisation of the initiators post initiators: - Power operation - Startup - Transition to shut down (shutting down?) - Shut down (cold shut down?) - Refuelling LEVEL 1 AND LEVEL 2 PSA The post initiators are categorised to PSA level 1 or level 2. The level 1 PSA is the part of the PSA which aims at quantifying the core damage frequency (CDF). The level 2 PSA is the part of the PSA which aims at quantifying the frequency of radioactive release. Level 1 PSA is used as input to level 2 PSA. 13 (43)

17 4 HRA APPLICATION FRAMEWORK FOR PRE- INITIATORS The pre initiators are often very common in the PSAs, representing several hundred basic events. Therefore, a more general case study of pre initiators has been performed where a group of pre initiators has been looked into regarding how they have been selected and treated. The following groups of pre initiators were included in the study: Latent errors Dependencies 4.1 LATENT ERRORS Pre initiators are latent errors and many of them originate from human errors during maintenance work. Maintenance personnel, site technicians and/or contractors as well as control room staff are involved in the events that may cause pre initiators. The latent errors can be divided into different categories such as: misalignments, faulty calibration and reparation. The selection process starts by identifying critical objects, e.g. in an FMEA. From these lists objects that are relevant for an error, e. g. misalignments, are collected. Then the barriers from making this error latent are identified. The barriers can be broken down as follows: 1. The alignment itself, normally including a number of (local) independent checks. 2. Signals, alarms or other forms of information in the control room that can reveal the error. 3. Function testing: operability verification, integral testing, tech spec testing. 4. Function testing during operation The barriers are considered to be independent.e.g. a latent misalignment error is thus considered possible if the alignment fails and the subsequent checks fail and information is missed or not present in the control room and function testing is missed or not present. Some plants consider pre initiators relatively thoroughly, while others have no explicit analysis of pre initiators. The reason behind this difference is different assumptions regarding testing before start-up, where testing is either seen to prevent pre initiators from happening at all, or is only seen as a kind of barrier in the models as described above. In the first case the risk introduced by pre initiators could implicitly be seen as part of basic event frequencies. 14 (43)

18 4.2 DEPENDENCIES Dependencies between actions are considered in different ways.dependency between human errors in maintenance actions can mean two things: 1. Human error probability can decrease after a person who has committed a human error notices it, and alters his way of working 2. Human error probability can increase after a person learns the wrong way of performing the action and continues to make errors. Actions which have immediate feedback, like leaving a valve which has a main control room indicator in the wrong position after maintenance, are of type 1, above. Cases where there is no immediate feedback are of type 2. Analysis of human common cause failures consists of two stages; qualitative analysis and quantitative analysis. The first stage in the qualitative analysis is the identification of possible dependencies in human actions, and the second stage is the identification of possibilities to notice the dependencies. A simplified method for systematic misalignment can be used. Dependency is for instance considered for the same object in different subdivisions. Location (same room?), person of shift (same person/shift?) and the use of checklists are also considered. Identified dependencies are modelled in fault trees. This might be conservative, since these dependencies in some sense are considered in the CCF contributions. On the contrary it may be non-conservative if there are several sequential basic events representing human actions appearing as independent barriers in a sequence of events, a so called cut set. In order to evaluate if there are several basic events representing human actions related to one scenario, the cut set list can be used as a tool to identify possible candidates for dependency analysis with respect to HRA. 15 (43)

19 5 HRA APPLICATION FRAMEWORK FOR INITIATORS Initiator actions have been subject for in-depth assessment within EXAM HRA phase initiator actions have been collected in the survey and the five case studies presented within EXAM HRA covers approximately 26 of these. The following initiating event groups are to be discussed: LOCA/leaks Pressure events Heavy load drop 5.1 LOCA/LEAKS Loss of system function Faulty loading of fuel FAULTY OPENING OF VALVE DURING WORK Plants consider faulty opening of valve during work on other systems causing leakage from reactor vessel as initiator and it is considered during cold shutdown. Systems where this failure mode is applied are main feedwater, auxiliary feedwater system, boron injection system or standby liquid control system, shutdown cooling system and low pressure coolant injection system. The expected frequency for failed action is in the observed applications between 2,0E-03 and 8,0E-04 per year, see the table below. Unit Basic event ID Operator action/ Basic event modeled Expected value Faulty opening of valve Leakage from reactor vessel due to faulty opening of valve during work on system 327 (auxiliary feedwater system) Leakage from reactor vessel due to faulty opening of valve during work on system 351 (boron injection system or standby liquid control system) Leakage from reactor vessel due to faulty opening of valve during work on feedwater Leakage from reactor vessel (outside the containment) due to faulty opening of valve during work on system 321 (shutdown cooling system) Leakage from reactor vessel due to faulty opening of valve during work on feedwater Leakage from reactor vessel due to faulty opening of valve during work on system 321 (shutdown cooling system) Leakage from reactor vessel due to faulty opening of valve during work on system 323 (low pressure coolant injection system) Leakage from reactor vessel due to faulty opening of valve during work on system 327 (auxiliary feedwater system) 16 (43)

20 Leakage from reactor vessel due to faulty opening of valve during work on system 351 (boron injection system or standby liquid control system) Leakage from reactor vessel (outside the containment) due to faulty opening of valve during work on system 321 (shutdown cooling system) VALVE OPENS DUE TO MISSTAKE DURING TEST Plants consider that the inner steam isolation valve opens due to mistake during hermetic testing when outer isolation valve is in an unwarranted open state. The expected frequency for failed action is in the observed applications between 1,0E-05 and 1,0E-06 per year, see the table below. Unit Basic event ID Operator action/ Basic event modeled Expected value Inner steam isolation valve opens due to misstake during hermetic testing when outer isolation valve is in an unwarrented open state LOCAS DUE TO FAULTY MAINTENANCE Plants consider small and large, top and bottom LOCAs due to human errors when performing maintenance on different systems, for example maintenance on RC pump, control rod drive and valves in shutdown cooling system. The expected frequency for failed action is in the observed applications between 3,0E-04 and 1,0E-07 per year, see the table below. Unit Basic event ID Operator action/ Basic event modelled Expected value Initiating event small bottom LOCA due to human errors when performing maintenace Initiating event large top LOCA due to human error when performing maintenance Initiating event medium top LOCA due to human error when performing maintenance Initiating event small top LOCA due to human error when performing maintenance Initiating event Large Bottom LOCA due to human errors when performing RC pump maintenance Initiating event Large Bottom LOCA due to human errors when performing maintenance on valve 321V1 (RHR) Initiating event medium size bottom LOCA due to human errors when performing control rod drive maintenance FAULTY HANDLING OF SEALING PLUGS/BOTTLES/FLANGES Plants consider faulty installation of sealing bottles for the probe of the core instrumentation. Due to faulty installation of sealing bottles plants also consider the possibility that the bottles will fall or are destroyed by objects on the turn disc of the control rod drive changing machine. Plants also consider faulty installation of sealing plugs when performing maintenance on RC pump. The expected frequency for failed action is in the observed applications between 1,0E-03 and 1,0E-07 per year, see the table below. 17 (43)

21 Unit Basic event ID Operator action/ Basic event modelled Expected value Faulty installation of "sealing bottles" (Swedish: tätflaskor) for the probe of the core instrumentation Faulty installation of "sealing bottles" (Swedish: tätflaskor) for the probe of the core instrumentation "Sealing bottles" (Swedish: tätflaskor) for probes (n units) fall or are destroyed by objects on the "turn disc" (Swedish: vridskiva) of the control rod drive changing machine Faulty installation of "sealing bottles" (Swedish: tätflaskor) for the probes of the core instrumenation Faulty installation of "sealing bottles" (Swedish: tätflaskor) for the probes of the core instrumenation "Sealing bottles" (Swedish: tätflaskor) for probes (n units) fall or are destroyed by objects on the "turn disc" (Swedish: vridskiva) of the control rod drive changing machine Control rod drive disassembled with the control rod drive housing not sealed with control rod or plug Control rod drive disassembled with the control rod drive housing not sealed with control rod or plug Faulty handling of sealing plug or unwarrented opening of sealing flang for recirculation pump Faulty handling of sealing plug or unwarrented opening of sealing flang for recirculation pump LEAKAGE THROUGH HEAT EXCHANGER Plants consider human errors leading to leakage through heat exchanger (recirculation pump) with plug and shaft disassembled. The expected frequency for failed action is in the observed applications between 1,0E-05 and 1,0E-06 per year. Unit Basic event Id Operator action/basic event modelled Expected value Leakage through heat exchanger (recirculation pump) with plug and shaft disassembled FAULTY INSPECTION One plant considers the initiating event of a large bottom LOCA due to human errors while performing inspection on 313 nozzles. The expected frequency for failed action is in the observed applications between 1,0E-05 and 1,0E-06 per year, see the table below. Unit Basic event ID Operator action/ Basic event modelled Expected value 5.2 PRESSURE EVENTS Initiating event Large Bottom LOCA due to human errors performing inspection on 313 nozzle PRESSURE RELIEF SYSTEM Plants consider maintenance on the pressure relief system without the sealing plug installed. The expected frequency for failed action is in the 18 (43)

22 observed applications between 2,0E-05 and 4,0E-06 per year, see the table below. Unit Basic event ID Operator action/ Basic event modelled Expected value Maintenance work on system 314 (pressure relief system) starts before the sealing plug is installed Maintenance work on system 314 (pressure relief system) starts before the sealing plug is installed Maintenance work on steam isolation valve starts before the sealing plug is installed Faulty loading of fuel assembly in supercell where the control rod is in an out position COLD PRESSURIZATION Plants consider human errors leading to cold pressurization of RPV when filling with water prior to lift of RPV lid. The expected frequency for failed action is in the observed applications between 1,0E-06 and 1,0E-08 per year, see the table below. Unit Basic event ID Operator action/ Basic event modelled Expected value Cold pressurization of RPV when filling with water prior to lift of RPV lid. Unwarrented start of feedwater causing top filling and cold pressure build-up of RCPB FAULTY ALIGNMENT OF SYSTEMS/HIGH TEMPERATURE Plants consider human alignment errors leading high temperature in cooling water circuits caused by recirculation. The expected frequency for failed action is in the observed applications between 1,0E-01 and 1,0E-03 per year, see the table below. Unit Basic event ID Operator action/ Basic event modelled Expected value High temperature in cooling water circuits caused by recirculation FAULTY MAINTENANCE LEADING TO PRESSURE EVENT OR LEAK Plants consider maintenance on the pressure relief system and/or on steam isolation valve before the sealing plug is installed. The expected frequency for failed action is in the observed applications between 5,0E-03 and 2,0E- 05 per year, see the table below. Unit Basic event ID Operator action/ Basic event modelled Expected value Faulty handling of maintenance work on steam isolation valve Faulty handling of maintenance work on steam isolation valve Maintenance work on system 314 (pressure relief system) starts before the sealing plug is installed Maintenance work on system 314 (pressure relief system) starts before the sealing plug is installed Maintenance work on steam isolation valve starts before the sealing plug is installed 19 (43)

23 5.3 HEAVY LOAD DROP Plants consider several initiating events related to heavy load drop. For example upper head, containment dome, steam separator, moisture separator, core shroud head or pool barriers. Due to faulty installation of sealing bottles plants also consider the possibility that the bottles will fall or are destroyed by objects on the turn disc of the control rod drive changing machine. The expected frequency for failed action is in the observed applications between 1,0E-06 and 1,0E-08 per year, see the table below. Unit Basic event ID Operator action/ Basic event modelled Expected value Falling steam separator, moisture separator or core shroud head Falling of two types of removable pool barriers (Swedish: sättlucka and skivport) in the reactor service room Falling upper head Lift of sealing plug with faulty shear bolt Initiating event heavy load drop Falling steam separator, moisture separator or core shroud head Falling of two types of removable pool barriers (Swedish: sättar and skivportar) in the reactor service room Falling upper head or containment dome 5.4 LOSS OF SYSTEM FUNCTION LOSS OF SYSTEMS Plants consider loss of systems due to erroneous disconnection or failure to start and connect systems. Systems where this failure mode is applied are main feedwater, auxiliary feedwater system, shutdown cooling system and fuel pool cooling and cleanup system. The expected frequency for failed action is in the observed applications between 3,0E-02 and 1,0E-06 per year, see the table below. Unit Basic event ID Operator action/ Basic event modelled Expected value Failing of system 321 (shutdown cooling system) (phase 1 and 6) Failing of system 321 (shutdown cooling system) (phase 2) Failing of system 321 (shutdown cooling system) (phase 3 and 5) Failing of systems 321/324 (shutdown cooling system/fuel pool cooling and cleanup system) (phase 4.2) Failing of systems 321/324 (shutdown cooling system/fuel pool cooling and cleanup system) (phase 4.2) Failing of system 324 (fuel pool cooling and 20 (43)

24 cleanup system) (pool cooling) Failing of system 321 (shutdown cooling system) Failing of system 321 (shutdown cooling system) (phase 2 and 6) Failing of system 321 (shutdown cooling system) (phase 3 and 5) Failing of systems 321/324 (shutdown cooling system/fuel pool cooling and cleanup system) (phase 4.2) Failing of systems 321/324 (shutdown cooling system/fuel pool cooling and cleanup system) (phase 4.2) Failing of system 324 (fuel pool cooling and cleanup system) (pool cooling) Failure to start and connect RHR (321) for cooling. Erroneous disconnection of MFW (415) without having connected AFW (329) No manual start and connection of RHR (321) in combination with to early disconnection of condenser 5.5 FAULTY LOADING OF FUEL Plants consider faulty loading of fuel assembly. The expected frequency for failed action is in the observed applications between 1,0E-05 and 1,0E-06 per year, see the table below. Unit Basic event ID Operator action/ Basic event modelled Expected value Faulty loading of fuel assembly in supercell where the control rod is in an out position. Faulty loading of fuel assembly in supercell where the control rod is in an out position. 21 (43)

25 6 HRA APPLICATION FRAMEWORK FOR POST- INITIATORS Post initiator actions have been subject for in-depth assessment within EXAM HRA phase 1 and post initiator actions have been collected in the survey and the six case studies presented within EXAM HRA covers approximately 280 of these in more detail. The following safety functions are to be discussed: Reactivity control Integrity of RCPB Emergency core cooling Residual heat removal Containment integrity Other 6.1 REACTIVITY CONTROL MANUAL ACTIONS REGARDING REACTIVITY To avoid recriticality a certain reactivity margin has to be ensured after the Xenon poisoning of the core has depleted. Manual actions regarding reactivity is credited during cold shut down and are related to PSA level 1. Plants consider failed actions regarding reactivity after the initiating event. The expected probability for failed action is in the observed applications high, between 1,0E-00 and 1,0E-01, see the table below. Failed actions regarding reactivity Failed actions regarding reactivity BORATION AFTER RECRITICALITY Boration after recriticality is credited during power operation and is related to PSA level 2. The expected probability for failed action is in the observed applications high although it is dependent of the time. Boration after recriticality Time window dependent (function p(t), t is a continuous variable) MANUAL SCRAM Manual scram is credited during power operation and is related to PSA level 1. The manual scram is credited as backup in various cases where the automatic signals have failed. The expected probability for failed action is in the observed applications high, between 1,0E-00 and 1,0E-01, see the table below. 22 (43)

26 Failed manual scram at emergency tripping of the turbine Manual scram activation within 2 minutes FAILURE TO ACTIVATE BORON INJECTION Failure to activate boron injection is credited during power operation and is related to PSA level 1. Plants consider failure to manually initiate boron injection, for example in case of incomplete reactor shutdown. The expected probability for failed action is in the observed applications high, between 1,0E-00 and 1,0E-02, see the table below. No manual start of boron injection. No manual initiation of boron injection in case of incompletet reactor shutdown (ATWS) Failure to activate boron system within 2 minutes 6.2 INTEGRITY OF RCPB STOP MAIN FEED WATER Manual stop of main feed water is credited during power operation and is related to PSA level 1. Plants consider failure to manually stop feed water system in case of uncontrolled feedwater injection. The expected probability for failed action is in the observed applications high, between 1,0E-00 and 1,0E-02, see the table below. Failure to manually stop feed water system at initiating event TZ (uncontrolled feedwater injection) ISOLATION OF MAIN STEAM Manual isolation of main steam lines is credited during power operation and is related to PSA level 2. Plants consider failed manual isolation of main steam line isolation valves in situations in case of external leaks. The expected probability for failed action is in the observed applications high, between 1,0E-00 and 1,0E-02, see the table below. No manual isolation of main steam line isolation valves (MSIV) ISOLATION OF STEAM LINES TO ECCS/AFW Manual isolation of steam lines to ECCS/AFW turbine driven pumps is credited during power operation and is related to PSA level 2. Plants with steam driven pumps consider failed manual activation of isolation chain in order to isolate steam lines to ECCS and AFW in case a steam line break in the auxiliary building. The expected probability for failed action is in the observed applications high, between 1,0E-00 and 1,0E-02, see the table below. 23 (43)

27 No manual activation of isolation chain in order to isolate steam lines for ECCS and AFW (turbine driven) 6.3 EMERGENCY CORE COOLING CLOSING OF CONTAINMENT AIR LOCK Closing of containment air lock is credited during cold shut down and refueling and is related to PSA level 1. The lower air lock is normally open during overhaul shutdown. In case of leak occurs inside containment below the reactor core, closing the lower airlock in a timely fashion is an important action. During critical outage work the airlock is monitored by a person trained to close the airlock, or the airlock is closed. After a not isolated leakage beneath core level, closing of the lower containment air lock is required to stabilize the situation. Closing of the lower containment air lock is also a relevant measure for leakages above core level, if the leakage point is within the containment. The measure stops the flow from the containment and helps to secure the water balance in the condensation pool. Depending on the initiating event the human action of closing the airlock has different success criteria. A larger leak will require the door to be closed within a shorter time window. The time windows considered for success range from 1 minute to 14 hours. Very large bottom leak has a time window of 1 minute, after which closing the airlock will likely be unsuccessful due to the water flow keeping the door open. The expected probability for failed action in the observed applications varies a lot dependent on case and the available time, between 1,0E-00 and 1,0E-04, see the table below. See EXAM HRA case study [5] for further details. closing containment airlock Failed closing of lower containment air lock door during large water flow Failed closing of lower containment air lock door during small water flow Failed water filling of the containment or closing of the upper containment air lock door at high break flow Failed water filling of the containment or closing of the upper containment air lock door at medium break flow Failed action regarding system 328 (condensation (suppression) pool) hatches, large bottom LOCA Failed action regarding system 328 (condensation (suppression) pool) hatches, medium bottom LOCA Failed action regarding system 328 (condensation (suppression) pool) hatches, small bottom LOCA Failed closing of lower containment air lock 24 (43)

28 door during large water flow Failed closing of lower containment air lock door during small water flow Failed water filling of the containment or closing of the upper containment air lock door during large water flow Failed water filling of the containment or closing of the upper containment air lock door during small water flow Failure to close wetwell doors Failure to close wetwell doors Containment lower airlock closure fails Containment lower airlock closure fails Containment lower airlock closure fails Containment lower airlock closure fails Containment lower airlock closure fails Containment lower airlock closure fails Containment lower airlock closure fails Containment upper airlock closure fails Containment upper airlock closure fails Failure to open gate Failure to close fuel storage pool gate Failure to close fuel storage pool gate Failure to close fuel storage pool gate Failure to close fuel storage pool gate FLUSHING OF STRAINERS Flushing of strainers is credited during power operation and is related to PSA level 1. Flushing of strainers is credited in the event of an internal pipe break and to prevent clogging of strainers in the condensation pool. Plants consider failed reverse flow flushing within 20 hours after the initiating event or failure to manually connect external water source to ECCS to back flush. The expected probability for failed action is between 3E-04 and 8E- 03, see the table below. Failed reverse flushing within 20 hours after initiating event Failed reverse flushing of pump suction strainer in system 323 (low pressure coolant injection system). DI For internal pipe break, loss of manual activation of back flushing of strainers in ECCS and containment spray system (CS). Failure to manually connect external water source to ECCS (backflushing) MANUAL ACTIVATION OF EXTERNAL WATER SUPPLY Manual activation of external water supply is credited during power operation and is related to PSA level 1. The type of scenarios that are evaluated here are related to PSA Level 1 but are still somewhat of SAMG (Severe Accident Management) in their nature. The SAMG nature is in the sense that the operator will try their last option to prevent a core damage to occur by using "un-clean water" (fire water, sea water, river water) and feed it into the RPV/primary system or the condensation pool (and from there it might be transferred to the RPV/primary system) in a feed and bleed sequence. The expected 25 (43)

29 probability for failed action in the observed applications varies a lot dependent on case and the available time, between 1,0E-00 and 1,0E-04, see the table below. See EXAM HRA case study [6] for further details. feeding with mobile pump from the elbe river into the reactor vessel using TH pipes (low pressure system) feeding with a mobile pump from the deionate container into the reactor vessel using TH pipes (low pressure system) feeding with a mobile pump from the deionate container into the reactor vessel using TF pipes (low pressure system) feeding with mobile pump from the deionate container into the reactor vessel using feed water pipes Failed manual start of extra circuit in system 732 (demineralization plant) Failed manual switch of buffer tank TD802 or 803. DI 'Auxiliary water into condensate system fails within 15 minutes 'Auxiliary water into condensate system fails within 20 minutes 'Auxiliary water into condensate system fails within 2 hours Activation of pump 733P2 manually fails 'Feeding of additional water from the demineralization plant fails within 2,5 horus 'Initiation of filling demineralized water tanks firefighting water is not initiated within 16 hours 'Initiation of filling demineralized water tanks firefighting water is not initiated within 4 hours MANUAL ACTIVATION OF EXTERNAL WATER SUPPLY Manual activation of external water supply is credited during shut down and is related to PSA level 1. Plants consider feeding the reactor vessel from the water grid or from the sea or river with a mobile pump. The expected probability for failed action is in the observed applications high, between 1,0E-00 and 1,0E-02, see the table below. feeding the reactor vessel from the water grid or from the elbe river with a mobile pump FEEDING VIA PUMP SEAL/ ROD LUBRICATION Feeding via pump seal/rod lubrication is credited during power operation or shut down and is related to PSA level 1. Plants consider feeding the reactor vessel with recirculation pump seal water and control rod drive lubrication water when other ways to feed the primary circuit are lost. The expected probability for failed action is in the observed applications between 1,0E-01 and 1,0E-03, see the table below. feeding the reactor vessel with recirculation pump seal water and control rod drive lubrification water feeding into the reaction vessel with RS control 26 (43)

30 rod drive lubrification water system feeding into the reactor vessel with TE system 7,90E MANUAL DEPRESSURIZATION OF RPV Manual depressurization of RPV is credited during power operation or shut down and is related to PSA level 1. Plants consider failure to manually depressurize RPV with different time windows between 5 minutes to 16 hours. It is also possible to manual open valves to regulate the water level in the reactor tank or manually unburden water with blowdown system. The expected probability for failed action in the observed applications varies depending on case and the available time, between 1,0E-01 and 1,0E-04, see the table below. Failed manual switch TB2 (manual forced blowing) Failed TB3-TB4 switch. ASI DI-3037 part 2.3, mainitaining level; within 5 minutes. Failed TB3-TB4 switch. ASI DI-3037 part 2.3, maintaining level; within 90 minutes Manually open valves to regulate water level in reactor tank and manually unburden water with blowdown system (314) Depressurization of the primary circuit Manual depressurization fails, 15 min Manual depressurization fails, 16 h Manual depressurization fails, 2 h Manual depressurization fails, 30 min Manual depressurization fails, 7 h in IRT-1A MANUAL ACTUATION ECCS/AFW Manual actuation of ECCS/AFW is credited during power operation, refuelling and shut down and is related to PSA level 1. When the automatic signal is missing it is possible to start (locally and manually) auxiliary feed water. It is also possible to manual start AFW from the control room when automatic start signal is missing. Plants also consider failure to activate ECCS/AFW manually under different time windows between 15 minutes to 2 hours. The expected probability for failed action in the observed applications varies depending on case and the available time, between 1,0E- 01 and 1,0E-03, see the table below. start up of a TH train (low pressure system) in the function core flooding switch TH trains to "soll kernfluten" (small leak in the wetwell) Local and manual start of auxiliry feed water, when automatical signal is missing. Manual start of AFW system from the control room, when there is no automatic start signal. Manual activation (327/323) fails within 2 hours Manual activation (327/323) fails within 30 minutes Manual activation (327/323) fails within 60 minutes Manual activation (327/323) fails, over 2 27 (43)

The Nitrogen Threat. The simple answer to a serious problem. 1. Why nitrogen is a risky threat to our reactors? 2. Current strategies to deal with it.

The Nitrogen Threat. The simple answer to a serious problem. 1. Why nitrogen is a risky threat to our reactors? 2. Current strategies to deal with it. International Conference on Topical Issues in Nuclear Installation Safety: Safety Demonstration of Advanced Water Cooled Nuclear Power Plants. The simple answer to a serious problem Vienna. 6 9 June 2017

More information

FUNDAMENTAL SAFETY OVERVIEW VOLUME 2: DESIGN AND SAFETY CHAPTER P: REFERENCE OPERATING CONDITION STUDIES (PCC)

FUNDAMENTAL SAFETY OVERVIEW VOLUME 2: DESIGN AND SAFETY CHAPTER P: REFERENCE OPERATING CONDITION STUDIES (PCC) PAGE : 1 / 11 1. PASSIVE SINGLE FAILURE ANALYSIS The aim of the accident analysis in Chapter P is to demonstrate that the safety objectives have been fully achieved, despite the most adverse single failure.

More information

Verification and validation of computer codes Exercise

Verification and validation of computer codes Exercise IAEA Safety Assessment Education and Training (SAET) Programme Joint ICTP- IAEA Essential Knowledge Workshop on Deterministic Safety Assessment and Engineering Aspects Important to Safety Verification

More information

ASVAD THE SIMPLE ANSWER TO A SERIOUS PROBLEM. Automatic Safety Valve for Accumulator Depressurization. (p.p.)

ASVAD THE SIMPLE ANSWER TO A SERIOUS PROBLEM. Automatic Safety Valve for Accumulator Depressurization. (p.p.) ASVAD Automatic Safety Valve for Accumulator Depressurization (p.p.) THE SIMPLE ANSWER TO A SERIOUS PROBLEM International Experts Meeting on Strengthening Research and Development Effectiveness in the

More information

An Improved Modeling Method for ISLOCA for RI-ISI and Other Risk Informed Applications

An Improved Modeling Method for ISLOCA for RI-ISI and Other Risk Informed Applications An Improved odeling ethod for ISLOCA for RI-ISI and Other Risk Informed Applications Young G. Jo 1) 1) Southern Nuclear Operating Company, Birmingham, AL, USA ABSTRACT In this study, an improved modeling

More information

CONTENTS OF THE PCSR CHAPTER 1 - INTRODUCTION AND GENERAL DESCRIPTION

CONTENTS OF THE PCSR CHAPTER 1 - INTRODUCTION AND GENERAL DESCRIPTION PAGE : 1 / 8 CONTENTS OF THE PCSR CHAPTER 1 - INTRODUCTION AND GENERAL DESCRIPTION SUB-CHAPTER 1.1 INTRODUCTION SUB-CHAPTER 1.2 GENERAL DESCRIPTION OF THE UNIT SUB-CHAPTER 1.3 COMPARISON WITH REACTORS

More information

Safety Analysis: Event Classification

Safety Analysis: Event Classification IAEA Training Course on Safety Assessment of NPPs to Assist Decision Making Safety Analysis: Event Classification Lecturer Lesson IV 1_2 Workshop Information IAEA Workshop City, Country XX - XX Month,

More information

Extensive Damage Mitigation Guidelines (EDMG)

Extensive Damage Mitigation Guidelines (EDMG) Extensive Damage Mitigation Guidelines (EDMG) Roy Harter RLH Global Services Regional Workshop on Sharing Best Practices in Development and Implementation of Severe Accident Management Guidelines October

More information

Workshop Information IAEA Workshop

Workshop Information IAEA Workshop IAEA Training Course on Safety Assessment of NPPs to Assist Decision Making Safety Assessment of General Design Aspects of NPPs (Part 2) Lecturer Lesson Lesson III III 1_2 1_2 Workshop Information IAEA

More information

NUBIKI Nuclear Safety Research Institute, Budapest, Hungary

NUBIKI Nuclear Safety Research Institute, Budapest, Hungary System Reliability Analysis and Probabilistic Safety Assessment to Support the Design of a New Containment Cooling System for Severe Accident Management at NPP Paks Tamas Siklossy* a, Attila Bareith a,

More information

FUNDAMENTAL SAFETY OVERVIEW VOLUME 2: DESIGN AND SAFETY CHAPTER I: AUXILIARY SYSTEMS 2. VOLUME AND CHEMICAL CONTROL (RCV [CVCS])

FUNDAMENTAL SAFETY OVERVIEW VOLUME 2: DESIGN AND SAFETY CHAPTER I: AUXILIARY SYSTEMS 2. VOLUME AND CHEMICAL CONTROL (RCV [CVCS]) PAGE : 1 / 16 2. VOLUME AND CHEMICAL CONTROL (RCV [CVCS]) 2.0. SAFETY REQUIREMENTS 2.0.1. Safety functions 2.0.1.1. Control of reactivity In normal operation, the RCV [CVCS] regulates and adjusts (jointly

More information

Engineering & Projects Organization

Engineering & Projects Organization Engineering & Projects Organization Note from : Date: 11/09/2012 To : Copy : N : PEPR-F.10.1665 Rev. 3 Subject: EPR UK - GDA GDA issue FS04 Single Tube Steam Generator Tube Rupture Analysis for the UK

More information

Custom-Engineered Solutions for the Nuclear Power Industry from SOR

Custom-Engineered Solutions for the Nuclear Power Industry from SOR Custom-Engineered Solutions for the Nuclear Power Industry from SOR As the world s aging nuclear power plants continue to be challenged with maintenance and Instrumentation Solutions for the Nuclear Power

More information

Nuclear safety Lecture 4. The accident of the TMI-2 (1979)

Nuclear safety Lecture 4. The accident of the TMI-2 (1979) Nuclear safety Lecture 4. The accident of the TMI-2 (1979) Ildikó Boros BME NTI 27 February 2017 The China Syndrome Opening: 16 March 1979 Story: the operator of the Ventana NPP tries to hide the safety

More information

FUNDAMENTAL SAFETY OVERVIEW VOLUME 2: DESIGN AND SAFETY CHAPTER F: CONTAINMENT AND SAFEGUARD SYSTEMS 7. CONTAINMENT HEAT REMOVAL SYSTEM (EVU [CHRS])

FUNDAMENTAL SAFETY OVERVIEW VOLUME 2: DESIGN AND SAFETY CHAPTER F: CONTAINMENT AND SAFEGUARD SYSTEMS 7. CONTAINMENT HEAT REMOVAL SYSTEM (EVU [CHRS]) PAGE : 1 / 16 7. CONTAINMENT HEAT REMOVAL SYSTEM (EVU [CHRS]) 7.0. SAFETY REQUIREMENTS 7.0.1. Safety functions The main functions of the EVU system [CHRS] are to limit the pressure inside the containment

More information

Loss of Normal Feedwater Analysis by RELAP5/MOD3.3 in Support to Human Reliability Analysis

Loss of Normal Feedwater Analysis by RELAP5/MOD3.3 in Support to Human Reliability Analysis Loss of Normal Feedwater Analysis by RELAP5/MOD3.3 in Support to Human Reliability Analysis ABSTRACT Andrej Prošek, Borut Mavko Jožef Stefan Institute Jamova cesta 39, SI-1 Ljubljana, Slovenia Andrej.Prosek@ijs.si,

More information

Considerations for the Practical Application of the Safety Requirements for Nuclear Power Plant Design

Considerations for the Practical Application of the Safety Requirements for Nuclear Power Plant Design Considerations for the Practical Application of the Safety Requirements for Nuclear Power Plant Design Joint ICTP-IAEA Essential Knowledge Workshop on Deterministic Safety Analysis and Engineering Aspects

More information

TEPCO s Safety Assurance Philosophy on Nuclear Power Generation Plants

TEPCO s Safety Assurance Philosophy on Nuclear Power Generation Plants TEPCO s Safety Assurance Philosophy on Nuclear Power Generation Plants January 25, 2013 Tokyo Electric Power Company, Inc. This English translation has been prepared with the intention of creating an accurate

More information

FUNDAMENTAL SAFETY OVERVIEW VOLUME 2: DESIGN AND SAFETY CHAPTER I: AUXILIARY SYSTEMS. A high-capacity EBA system [CSVS] [main purge]

FUNDAMENTAL SAFETY OVERVIEW VOLUME 2: DESIGN AND SAFETY CHAPTER I: AUXILIARY SYSTEMS. A high-capacity EBA system [CSVS] [main purge] PAGE : 1 / 9 5. CONTAINMENT PURGE (EBA [CSVS]) The Reactor Building purge system comprises the following: A high-capacity EBA system [CSVS] [main purge] A low-capacity EBA system [CSVS] [mini-purge] 5.1.

More information

-. 30ýv. Entergy ARKANSAS NUCLEAR ONE - UNIT I IMPROVED TECHNICAL SPECIFICATIONS SUBMITTAL. 05/01101 Supplement Volume 2 of 2. (Sections 3.7 and 3.

-. 30ýv. Entergy ARKANSAS NUCLEAR ONE - UNIT I IMPROVED TECHNICAL SPECIFICATIONS SUBMITTAL. 05/01101 Supplement Volume 2 of 2. (Sections 3.7 and 3. ARKANSAS NUCLEAR ONE - UNIT I IMPROVED TECHNICAL SPECIFICATIONS SUBMITTAL -. 30ýv May 1, 2001 05/01101 Supplement Volume 2 of 2 (Sections 3.7 and 3.8) Entergy MSSVs 3.7.1 3.7 PLANT SYSTEMS 3.7.1 Main Steam

More information

AP1000 European 19. Probabilistic Risk Assessment Design Control Document

AP1000 European 19. Probabilistic Risk Assessment Design Control Document APPENDIX 19E SHUTDOWN EVALUATION 19E.1 Introduction Westinghouse has considered shutdown operations in the design of the A1000 nuclear power plant. The AP1000 defense-in-depth design philosophy to provide

More information

Containment Isolation system analysis and its contribution to level 2 PSA results in Doel 3 unit

Containment Isolation system analysis and its contribution to level 2 PSA results in Doel 3 unit Containment Isolation system analysis and its contribution to level 2 PSA results in Doel 3 unit Marius LONTOS a*, Stanislas MITAILLÉ a, and Shizhen YU a, Jérémy BULLE a TRACTEBEL ENGIE, Brussels, Belgium

More information

Workshop Information IAEA Workshop

Workshop Information IAEA Workshop IAEA Training Course on Safety Assessment of NPPs to Assist Decision Making Risk Monitoring tools: Requirements of Risk Monitors, relation with the Living PSA, applications of Risk Monitors Lecturer Lesson

More information

Preliminary Failure Mode and Effect Analysis for CH HCSB TBM

Preliminary Failure Mode and Effect Analysis for CH HCSB TBM Preliminary Failure Mode and Effect Analysis for CH HCSB TBM Presented by: Chen Zhi Contributors by HCSB TBM Safety Group, in China June 21, 2007 E-mail: chenz@swip.ac.cn Outline Introduction FMEA Main

More information

Module No. # 01 Lecture No. # 6.2 HAZOP (continued)

Module No. # 01 Lecture No. # 6.2 HAZOP (continued) Health, Safety and Environmental Management in Petroleum and Offshore Engineering Prof. Srinivasan Chandrasekaran Department of Ocean Engineering Indian Institute Of Technology, Madras Module No. # 01

More information

Regulatory requirements with respect to Spent Fuel Pool Cooling

Regulatory requirements with respect to Spent Fuel Pool Cooling Regulatory requirements with respect to Spent Fuel Pool Cooling Dr. Christoph Pistner Annual Meeting on Nuclear Technology Hamburg, 12.05.2016 Important Documents Safety Requirements for Nuclear Power

More information

Review and Assessment of Engineering Factors

Review and Assessment of Engineering Factors Review and Assessment of Engineering Factors 2013 Learning Objectives After going through this presentation the participants are expected to be familiar with: Engineering factors as follows; Defense in

More information

IAEA SAFETY STANDARDS for protecting people and the environment

IAEA SAFETY STANDARDS for protecting people and the environment IAEA SAFETY STANDARDS for protecting people and the environment DESIGN OF REACTOR CONTAINMENT STRUCTURE AND SYSTEMS FOR NUCLEAR POWER PLANTS DRAFT SAFETY GUIDE DS 482 STATUS: STEP 11 Submission to Review

More information

Event tree analysis. Prof. Enrico Zio. Politecnico di Milano Dipartimento di Energia. Prof. Enrico Zio

Event tree analysis. Prof. Enrico Zio. Politecnico di Milano Dipartimento di Energia. Prof. Enrico Zio Event tree analysis Politecnico di Milano Dipartimento di Energia Techniques for Risk Analysis Hazard identification: FMEA (Failure Modes and Effects Analysis) & HAZOP (HAZard and OPerability study) Accident

More information

HEALTH AND SAFETY EXECUTIVE HM NUCLEAR INSTALLATIONS INSPECTORATE

HEALTH AND SAFETY EXECUTIVE HM NUCLEAR INSTALLATIONS INSPECTORATE HEALTH AND SAFETY EXECUTIVE HM NUCLEAR INSTALLATIONS INSPECTORATE New Reactor Generic Design Assessment (GDA) - Step 2 Preliminary Review Assessment of: Structural Integrity Aspects of AREVA/EdF EPR HM

More information

SENSITIVITY ANALYSIS OF THE FIRST CIRCUIT OF COLD CHANNEL PIPELINE RUPTURE SIZE FOR WWER 440/270 REACTOR

SENSITIVITY ANALYSIS OF THE FIRST CIRCUIT OF COLD CHANNEL PIPELINE RUPTURE SIZE FOR WWER 440/270 REACTOR PROCEEDINGS OF THE YEREVAN STATE UNIVERSITY Physical and Mathematical Sciences 216, 2, p. 57 62 P h y s i c s SENSITIVITY ANALYSIS OF THE FIRST CIRCUIT OF COLD CHANNEL PIPELINE RUPTURE SIZE FOR WWER 44/27

More information

Safety Engineering - Hazard Identification Techniques - M. Jahoda

Safety Engineering - Hazard Identification Techniques - M. Jahoda Safety Engineering - Hazard Identification Techniques - M. Jahoda Hazard identification The risk management of a plant 2 Identification of the hazards involved in the operation of the plant, due to the

More information

PI MODERN RELIABILITY TECHNIQUES OBJECTIVES. 5.1 Describe each of the following reliability assessment techniques by:

PI MODERN RELIABILITY TECHNIQUES OBJECTIVES. 5.1 Describe each of the following reliability assessment techniques by: PI 21. 05 PI 21. 05 MODERN RELIABILITY TECHNIQUES OBJECTIVES 5.1 Describe each of the following reliability assessment techniques by: ~) Stating its purpose. i1) Giving an e ample of where it is used.

More information

Periodical surveys of cargo installations on ships carrying liquefied gases in bulk

Periodical surveys of cargo installations on ships carrying liquefied gases in bulk (June 1999) (Rev.1 Mar 2006) (Rev.2 May 2007) (Rev.3 Mar 2010) (Corr.1 Feb 2011) (Rev.4 Oct 2013) Periodical surveys of cargo installations on ships carrying liquefied gases in bulk 1 General 1.1 Scope

More information

Lockout/Tagout Training Overview. Safety Fest 2013

Lockout/Tagout Training Overview. Safety Fest 2013 Lockout/Tagout Training Overview Safety Fest 2013 Purpose of Lockout/Tagout The standard covers the servicing and maintenance of machine and equipment in which the unexpected energization or start up of

More information

Understanding safety life cycles

Understanding safety life cycles Understanding safety life cycles IEC/EN 61508 is the basis for the specification, design, and operation of safety instrumented systems (SIS) Fast Forward: IEC/EN 61508 standards need to be implemented

More information

Inerting System Design for Medium Speed Vertical Spindle Coal Pulverizers TABLE OF CONTENTS

Inerting System Design for Medium Speed Vertical Spindle Coal Pulverizers TABLE OF CONTENTS Inerting System Design for Medium Speed Vertical Spindle Coal Pulverizers The PRB Coal Users Group plans to develop a Design Guide for Mill Inerting as an aid to users when designing a mill inerting system.

More information

Hazard Identification

Hazard Identification Hazard Identification Most important stage of Risk Assessment Process 35+ Techniques Quantitative / Qualitative Failure Modes and Effects Analysis FMEA Energy Analysis Hazard and Operability Studies HAZOP

More information

IAEA SAFETY STANDARDS for protecting people and the environment

IAEA SAFETY STANDARDS for protecting people and the environment Date: 2016-08-31 IAEA SAFETY STANDARDS for protecting people and the environment STATUS: STEP 8a For Submission to Member States DESIGN OF REACTOR CONTAINMENT STRUCTURE AND SYSTEMS FOR NUCLEAR POWER PLANTS

More information

EMERGENCY CORE COOLING SYSTEM SIMPLIFICATION

EMERGENCY CORE COOLING SYSTEM SIMPLIFICATION EMERGENCY CORE COOLING SYSTEM SIMPLIFICATION XA9846601 R.S. HART Sheridan Park Research Community, Atomic Energy of Canada Ltd, Mississauga, Ontario D.B. RHODES Chalk River Laboratories, Atomic Energy

More information

Enhancing NPP Safety through an Effective Dependability Management

Enhancing NPP Safety through an Effective Dependability Management Prepared and presented by Gheorghe VIERU, PhD Senior Scientific Nuclear Security Research Worker AREN/c.o. Institute for Nuclear Research Pitesti, ROMANIA Safety: Defence in Depth, October 2013 1 OUTLINES

More information

Lockout / Tag out Program

Lockout / Tag out Program Lockout / Tag out Program Presented by DOSHTI www.doshti.com You will learn Purpose of Lockout- Tag out Requirements for LOTO Types of Hazardous Energy Procedures for LOTO The OSHA Standard for the Control

More information

Safety and efficiency go hand in hand at MVM Paks NPP

Safety and efficiency go hand in hand at MVM Paks NPP International Forum Atomexpo 2018 Safety and efficiency go hand in hand at MVM Paks NPP József Elter MVM Paks Nuclear Power Plant Ltd. Hungary Start up Four of the VVER-440/V213 unit Power units up-rate

More information

Assessing Combinations of Hazards in a Probabilistic Safety Analysis

Assessing Combinations of Hazards in a Probabilistic Safety Analysis Assessing Combinations of Hazards in a Probabilistic Safety Analysis Halbert Taekema a, and Hans Brinkman a a NRG, Arnhem, The Netherlands Abstract: Guidance on how to systematically address combination

More information

Severe Accident Management Programmes for Nuclear Power Plants

Severe Accident Management Programmes for Nuclear Power Plants DS 483: Mode 2 27 March 2017 IAEA SAFETY STANDARDS for protecting people and the environment STEP 11: Approval by the relevant review Committees Reviewed in NSOC (Asfaw) Severe Accident Management Programmes

More information

SAFETY APPROACHES. The practical elimination approach of accident situations for water-cooled nuclear power reactors

SAFETY APPROACHES. The practical elimination approach of accident situations for water-cooled nuclear power reactors SAFETY APPROACHES The practical elimination approach of accident situations for water-cooled nuclear power reactors 2017 SUMMARY The implementation of the defence in depth principle and current regulations

More information

ANNEX AMENDMENTS TO THE INTERNATIONAL CODE FOR FIRE SAFETY SYSTEMS (FSS CODE) CHAPTER 15 INERT GAS SYSTEMS

ANNEX AMENDMENTS TO THE INTERNATIONAL CODE FOR FIRE SAFETY SYSTEMS (FSS CODE) CHAPTER 15 INERT GAS SYSTEMS Annex 3, page 2 ANNEX AMENDMENTS TO THE INTERNATIONAL CODE FOR FIRE SAFETY SYSTEMS (FSS CODE) CHAPTER 15 INERT GAS SYSTEMS The text of existing chapter 15 is replaced by the following: "1 Application This

More information

Identification and Screening of Scenarios for LOPA. Ken First Dow Chemical Company Midland, MI

Identification and Screening of Scenarios for LOPA. Ken First Dow Chemical Company Midland, MI Identification and Screening of Scenarios for LOPA Ken First Dow Chemical Company Midland, MI 1 Layers of Protection Analysis (LOPA) LOPA is a semi-quantitative tool for analyzing and assessing risk. The

More information

REGULATORY OBSERVATION

REGULATORY OBSERVATION RO unique no.: REGULATORY OBSERVATION REGULATOR TO COMPLETE RO-ABWR-0046 Date sent: 20 th April 2015 Acknowledgement required by: 08 th May 2015 Agreement of Resolution Plan required by: 14 th May 2015

More information

Assessment of Internal Hazards

Assessment of Internal Hazards Joint ICTP- Essential Knowledge Workshop on Deterministic Safety Analysis and Engineering Aspects Important to Safety Trieste, 12-23 October 2015 Assessment of Internal Hazards Javier Yllera Department

More information

A comparative study of FLEX strategies to cope with Extended Station Blackout (SBO)

A comparative study of FLEX strategies to cope with Extended Station Blackout (SBO) A comparative study of FLEX strategies to cope with Extended Station Blackout (SBO) Presented by M. G Shahinoor Islam Master s Student of KINGS October 26 th 2017 KNS Meeting FLEX Objectives 2 page of

More information

Lockout Tagout Policy

Lockout Tagout Policy Office of Environmental Health & Safety www.moreheadstate.edu/ehs 606-783-2584 Lockout Tagout Policy PURPOSE To establish procedures for the de-energization and isolation of energy sources or the lockout

More information

DESIGN OF REACTOR CONTAINMENT STRUCTURE AND SYSTEMS FOR NUCLEAR POWER PLANTS

DESIGN OF REACTOR CONTAINMENT STRUCTURE AND SYSTEMS FOR NUCLEAR POWER PLANTS SAFETY STANDARDS SERIES No. NS-G-1.10 DESIGN OF REACTOR CONTAINMENT STRUCTURE AND SYSTEMS FOR NUCLEAR POWER PLANTS SAFETY GUIDE DS 482 2016-04-20 INTERNATIONAL ATOMIC ENERGY AGENCY VIENNA, C-41 (May 13)

More information

DESIGN OF REACTOR CONTAINMENT STRUCTURE AND SYSTEMS FOR NUCLEAR POWER PLANTS

DESIGN OF REACTOR CONTAINMENT STRUCTURE AND SYSTEMS FOR NUCLEAR POWER PLANTS SAFETY STANDARDS SERIES No. NS-G-1.10 DESIGN OF REACTOR CONTAINMENT STRUCTURE AND SYSTEMS FOR NUCLEAR POWER PLANTS SAFETY GUIDE DS 482 2016-04-20 INTERNATIONAL ATOMIC ENERGY AGENCY VIENNA, C-41 (May 13)

More information

UKEPR Issue 04

UKEPR Issue 04 Title: PCSR Sub-chapter 6.8 Main steam relief train system - VDA [MSRT] Total number of pages: 16 Page No.: I / III Chapter Pilot: M. LACHAISE Name/Initials Date 25-06-2012 Approved for EDF by: A. PETIT

More information

DISTRIBUTION LIST. Preliminary Safety Report Chapter 19 Internal Hazards UK HPR1000 GDA. GNS Executive. GNS all staff. GNS and BRB all staff CGN EDF

DISTRIBUTION LIST. Preliminary Safety Report Chapter 19 Internal Hazards UK HPR1000 GDA. GNS Executive. GNS all staff. GNS and BRB all staff CGN EDF Rev: 000 Page: 2 / 20 DISTRIBUTION LIST Recipients GNS Executive GNS all staff Cross Box GNS and BRB all staff CGN EDF Regulators Public Rev: 000 Page: 3 / 20 SENSITIVE INFORMATION RECORD Section Number

More information

Recent Research on Hazards PSA

Recent Research on Hazards PSA Recent Research on Hazards PSA Marina Röwekamp, Hartmut Holtschmidt, Michael Türschmann Gesellschaft für Anlagen- und Reaktorsicherheit (GRS) ggmbh IEM8 - International Experts Meeting on Strengthening

More information

(C) Anton Setzer 2003 (except for pictures) A2. Hazard Analysis

(C) Anton Setzer 2003 (except for pictures) A2. Hazard Analysis A2. Hazard Analysis In the following: Presentation of analytical techniques for identifyin hazards. Non-formal, but systematic methods. Tool support for all those techniques exist. Techniques developed

More information

Hazard Operability Analysis

Hazard Operability Analysis Hazard Operability Analysis Politecnico di Milano Dipartimento di Energia HAZOP Qualitative Deductive (search for causes) Inductive (consequence analysis) AIM: Identification of possible process anomalies

More information

N2 Blanketing Valve DST100 / DST200 TYPE INSTRUCTION MANUAL CONTENTS K.S.P.C. General Description Operation. Installation Maintenance

N2 Blanketing Valve DST100 / DST200 TYPE INSTRUCTION MANUAL CONTENTS K.S.P.C. General Description Operation. Installation Maintenance DST100 / DST200 TYPE N2 Blanketing Valve INSTRUCTION MANUAL CONTENTS General Description Operation Installation Maintenance K.S.P.C 488-1 Wolha-ro, Tongjin-eup, Gimpo-si, Gyeonggi-Do, Korea Tel : +82-31-998-3825~7

More information

ACCIDENT MANAGEMENT AND EPR AT DUKOVANY NPP

ACCIDENT MANAGEMENT AND EPR AT DUKOVANY NPP ACCIDENT MANAGEMENT AND EPR AT DUKOVANY NPP 27-29 September 2017 Vienna IAEA Miroslav Trnka OVERVIEW General EOPs and SAMGs (changes) DAM (FLEX) EDMG Equipment (new + ongoing projects) Staff (drills and

More information

CLARKES ERO FEEDER MANUAL

CLARKES ERO FEEDER MANUAL CLARKES ERO FEEDER MANUAL It is the sole responsibility of the Owner and/or the Responsible Supervising Operators of this equipment to properly instruct their employees, either direct or contact, in the

More information

DISTRIBUTION LIST. Preliminary Safety Report Chapter 7 Safety Systems UK HPR1000 GDA. GNS Executive. GNS all staff. GNS and BRB all staff CGN EDF

DISTRIBUTION LIST. Preliminary Safety Report Chapter 7 Safety Systems UK HPR1000 GDA. GNS Executive. GNS all staff. GNS and BRB all staff CGN EDF Rev: 000 Page: 2 / 82 DISTRIBUTION LIST Recipients GNS Executive GNS all staff Cross Box GNS and BRB all staff CGN EDF Regulators Public Rev: 000 Page: 3 / 82 SENSITIVE INFORMATION RECORD Section Number

More information

Inspection Credit for PWSCC Mitigation via Peening Surface Stress Improvement

Inspection Credit for PWSCC Mitigation via Peening Surface Stress Improvement Inspection Credit for PWSCC Mitigation via Peening Surface Stress Improvement Glenn A. White, Kyle P. Schmitt, Kevin J. Fuhr, Markus Burkardt, and Jeffrey A. Gorman Dominion Engineering, Inc. Paul Crooker

More information

Manual Actuated Boiler Blowdown Valves

Manual Actuated Boiler Blowdown Valves Manual Actuated Boiler Blowdown Valves Installation and Maintenance Instructions 1. Safety information 2. General product information 3. Installation 4. Operation 5. Maintenance 6. Spare parts p.1 1. Safety

More information

HTR Systems and Components

HTR Systems and Components IAEA Course on HTR Technology Beijing, 22-26.October 2012 HTR Systems and Components Dr. Gerd Brinkmann Dieter Vanvor AREVA NP GMBH Henry-Dunant-Strasse 50 91058 Erlangen phone +49 9131 900 96840/95821

More information

Every things under control High-Integrity Pressure Protection System (HIPPS)

Every things under control High-Integrity Pressure Protection System (HIPPS) Every things under control www.adico.co info@adico.co Table Of Contents 1. Introduction... 2 2. Standards... 3 3. HIPPS vs Emergency Shut Down... 4 4. Safety Requirement Specification... 4 5. Device Integrity

More information

LOCK-OUT/TAG-OUT (LO/TO) SAFETY PROGRAM

LOCK-OUT/TAG-OUT (LO/TO) SAFETY PROGRAM LOCK-OUT/TAG-OUT (LO/TO) SAFETY PROGRAM REGULATORY STANDARD: OSHA - 29 CFR 1910.147 BASIS: Approximately three million workers in the United States face risks from uncontrolled energy when servicing machinery

More information

SAFETY DIRECTIVE 2.0 DEPARTMENTS AFFECTED. This Administrative Directive shall apply to all Town of Marana departments and employees.

SAFETY DIRECTIVE 2.0 DEPARTMENTS AFFECTED. This Administrative Directive shall apply to all Town of Marana departments and employees. SAFETY DIRECTIVE Title: Control of Hazardous Energy Lock-out/Tag-out/Try-out Issuing Department: Town Manager s Safety Office Effective Date: July 1, 2014 Approved: Gilbert Davidson, Town Manager Type

More information

Purpose. Scope. Process flow OPERATING PROCEDURE 07: HAZARD LOG MANAGEMENT

Purpose. Scope. Process flow OPERATING PROCEDURE 07: HAZARD LOG MANAGEMENT SYDNEY TRAINS SAFETY MANAGEMENT SYSTEM OPERATING PROCEDURE 07: HAZARD LOG MANAGEMENT Purpose Scope Process flow This operating procedure supports SMS-07-SP-3067 Manage Safety Change and establishes the

More information

Evaluation and Demonstration of Safety of Decommissioning of

Evaluation and Demonstration of Safety of Decommissioning of Evaluation and Demonstration of Safety of Decommissioning of Research Reactors Borislava Batandjieva, IAEA Research Reactor Decommissioning Demonstration Project (R2D2P) 26-30 June 2006, Manila, Philippines

More information

M-06 Nitrogen Generator (Nitrogen Making Machine)

M-06 Nitrogen Generator (Nitrogen Making Machine) Guideline No.M-06 (201510) M-06 Nitrogen Generator (Nitrogen Making Machine) Issued date: 20 th October, 2015 China Classification Society Foreword This Guideline is a part of CCS Rules, which contains

More information

BUTTERFLY VALVES Series 800

BUTTERFLY VALVES Series 800 BUTTERFLY VALVES Series 800 WARNING Before proceeding read ALL instructions and become familiar with the equipment and associated drawings. Follow ALL applicable safety regulations and codes for pressurized

More information

Training Fees 4,000 US$ per participant for Public Training includes Materials/Handouts, tea/coffee breaks, refreshments & Buffet Lunch.

Training Fees 4,000 US$ per participant for Public Training includes Materials/Handouts, tea/coffee breaks, refreshments & Buffet Lunch. Training Title CONTROL & SAFETY RELIEF VALVES Training Duration 5 days Training Venue and Dates Control & Safety Relief Valves 5 06-10 May, 2018 $4,000 Dubai, UAE Trainings will be conducted in any of

More information

Safety Classification of Structures, Systems and Components in Nuclear Power Plants

Safety Classification of Structures, Systems and Components in Nuclear Power Plants DS367 Draft 5.1 IAEA SAFETY STANDARDS for protecting people and the environment Date: 04/11/2008 Status: for Member States comments Reviewed in NS-SSCS Please submit your comments by 20 March 2009 Safety

More information

Water Mist Systems Inspection, Testing, and Maintenance of Water Mist Systems

Water Mist Systems Inspection, Testing, and Maintenance of Water Mist Systems Water Mist Systems Inspection, Testing, and Maintenance of Water Mist Systems Name of Property: Address: Phone Number: Inspector: Contract No.: Date: This Report Covers: Monthly Quarterly Annual Other

More information

MDEP Common Position No AP

MDEP Common Position No AP MDEP Validity: until net update or archiving MDEP Common Position No AP1000-01 Related to : AP1000 Working Group activities THE DESIGN AND USE OF EXPLOSIVE - ACTUATED (SQUIB) VALVES IN NUCLEAR POWER PLANTS

More information

Energy Control. Suite 2A, 55 Frid Street Hamilton, ON L8P 4M3 office: cell:

Energy Control. Suite 2A, 55 Frid Street Hamilton, ON L8P 4M3 office: cell: Energy Control Suite 2A, 55 Frid Street Hamilton, ON L8P 4M3 office: 905.577.0303 cell: 905.977.0210 consultant@staffaid.ca www.staffaid.com Safety, Energy Control, Power Lockout & Function Test Procedures

More information

SHUTDOWN SYSTEMS: SDS1 AND SDS2

SHUTDOWN SYSTEMS: SDS1 AND SDS2 Chapter 12 SHUTDOWN SYSTEMS: SDS1 AND SDS2 12.1 INTRODUCTION Up to this point we have looked with great details at the reactor regulating system. In order to better understand the overall design of a CANDU

More information

IEM on Severe Accident Management in the light of the accident at the Fukushima Daïchi NPP

IEM on Severe Accident Management in the light of the accident at the Fukushima Daïchi NPP IEM on Severe Accident Management in the light of the accident at the Fukushima Daïchi NPP Progress, challenges and perspectives in the field of design features, as regards SAMG IAEA, March 2014 Introduction

More information

LOCKOUT/TAGOUT PROGRAM

LOCKOUT/TAGOUT PROGRAM Santa Clarita Community College District LOCKOUT/TAGOUT PROGRAM Revised March 2018 TABLE OF CONTENTS PURPOSE... 3 COMPLIANCE...4 DEFINITIONS...5 SECTION I - ENERGY CONTROL PROCEDURES... 7 SECTION II -

More information

10. SYSTEM ANALYSIS. The assessment consist of two elements: Safety Analysis Report and an independent Review of Safety Report.

10. SYSTEM ANALYSIS. The assessment consist of two elements: Safety Analysis Report and an independent Review of Safety Report. 10. SYSTEM ANALYSIS Several projects related to the safety analysis of the Ignalina NPP or its safety systems have been performed. The joint Lithuanian - Sweden Barselina project - the first probabilistic

More information

THE NITROGEN INJECTION THREAT IN PWR REACTORS

THE NITROGEN INJECTION THREAT IN PWR REACTORS THE NITROGEN INJECTION THREAT IN PWR REACTORS Weakness of current strategies & ASVAD, the new passive solution. Arnaldo Laborda Rami ASVAD INTL. SL (SPAIN) Tarragona (SPAIN) Email: alaborda@asvad-nuclear.com

More information

Level 2 PSA for the VVER 440/213 Dukovany Nuclear Power Plant

Level 2 PSA for the VVER 440/213 Dukovany Nuclear Power Plant Nuclear Nuclear Research Research Institute Řež plc Institute Řež plc Level 2 PSA for the VVER 440/213 Dukovany Nuclear Power Plant Jiří Dienstbier, Stanislav Husťák OECD International Workshop on Level-2

More information

NOT PROTECTIVELY MARKED. REDACTED PUBLIC VERSION HPC PCSR3 Sub-chapter 16.2 PSA Results and Discussion NNB GENERATION COMPANY (HPC) LTD

NOT PROTECTIVELY MARKED. REDACTED PUBLIC VERSION HPC PCSR3 Sub-chapter 16.2 PSA Results and Discussion NNB GENERATION COMPANY (HPC) LTD HPC PCSR3 Sub-chapter 16.2 PSA Results and Discussion Page No.: i / iii NNB GENERATION COMPANY (HPC) LTD HPC PCSR3: CHAPTER 16 PROBABILISTIC SAFETY ASSESSMENT SUB-CHAPTER 16.2 PSA RESULTS AND DISCUSSION

More information

SAFETY DEMONSTRATION TESTS ON HTR-10

SAFETY DEMONSTRATION TESTS ON HTR-10 2nd International Topical Meeting on HIGH TEMPERATURE REACTOR TECHNOLOGY Beijing, CHINA,, September 22-24, 24 #Paper H6 SAFETY DEMONSTRATION TESTS ON HTR-1 Shouyin HU, Ruipian WANG, Zuying GAO Institute

More information

Transient Analyses In Relief Systems

Transient Analyses In Relief Systems Transient Analyses In Relief Systems Dirk Deboer, Brady Haneman and Quoc-Khanh Tran Kaiser Engineers Pty Ltd ABSTRACT Analyses of pressure relief systems are concerned with transient process disturbances

More information

DUQUESNE UNIVERSITY LOCKOUT/TAGOUT PROGRAM

DUQUESNE UNIVERSITY LOCKOUT/TAGOUT PROGRAM DUQUESNE UNIVERSITY LOCKOUT/TAGOUT PROGRAM Prepared by: Environmental Health and Safety Department TABLE OF CONTENTS Page Purpose 1 Scope 1 Introduction 2 Regulatory Requirements 2 Protective Materials

More information

DETAILS OF THE ACCIDENT PROGRESSION IN 1F1

DETAILS OF THE ACCIDENT PROGRESSION IN 1F1 DETAILS OF THE ACCIDENT PROGRESSION IN 1F1 EMUG 2019 BRAUN, Matthias Switzerland, 3 rd -5 th April 2019 Not part of the BSAF OECD Benchmark Project Relying exclusively on publically available input data

More information

Pressure Relief Device Investigation Testing Lessons Learned

Pressure Relief Device Investigation Testing Lessons Learned Pressure Relief Device Investigation Testing Lessons Learned 2018 General Meeting Presentation Prepared by: Joseph F. Ball, P.E. Overview National Board Investigation Testing Process Summary of Results

More information

PROBABILISTIC SAFETY ANALYSIS OF THE GREEK RESEARCH REACTOR

PROBABILISTIC SAFETY ANALYSIS OF THE GREEK RESEARCH REACTOR DEMO 2001/ 2 PROBABILISTIC SAFETY ANALYSIS OF THE GREEK RESEARCH REACTOR O.N. Aneziris C. Housiadas I.A. Papazoglou M. Stakakis National Centre for Scientific Research Demokritos Institute of Nuclear Technology

More information

EXPERIMENTAL SUPPORT OF THE BLEED AND FEED ACCIDENT MANAGEMENT MEASURES FOR VVER-440/213 TYPE REACTORS

EXPERIMENTAL SUPPORT OF THE BLEED AND FEED ACCIDENT MANAGEMENT MEASURES FOR VVER-440/213 TYPE REACTORS International Conference Nuclear Energy for New Europe 22 Kranjska Gora, Slovenia, September 9-12, 22 www.drustvo-js.si/gora22 EXPERIMENTAL SUPPORT OF THE BLEED AND FEED ACCIDENT MANAGEMENT MEASURES FOR

More information

PRA Methodology Overview

PRA Methodology Overview PRA Methodology Overview 22.39 Elements of Reactor Design, Operations, and Safety Lecture 9 Fall 2006 George E. Apostolakis Massachusetts Institute of Technology Department of Nuclear Science and Engineering

More information

Delayed Coker Automation & Interlocks

Delayed Coker Automation & Interlocks Delayed Coker Automation & Interlocks a Presented by Mitch Moloney of ExxonMobil @ coking.com April-2005 MJ Moloney - ExxonMobil April-2005 coking.com 0 Automation & Interlocks @ ExxonMobil - Background

More information

LOCKOUT/TAGOUT PLAN August 2015

LOCKOUT/TAGOUT PLAN August 2015 LOCKOUT/TAGOUT PLAN August 2015 Office of Environmental Health and Safety 423-354-5224 TABLE OF CONTENTS Purpose and Intended Use... 2 A. Types of Energy Sources... 2 B. Activities Requiring Lockout/Tagout

More information

Maintenance and Troubleshooting of Pneumatic Conveying Systems for Sand in a Foundry

Maintenance and Troubleshooting of Pneumatic Conveying Systems for Sand in a Foundry Maintenance and Troubleshooting of Pneumatic Conveying Systems for Sand in a Foundry Article Takeaways: Chris Doerschlag President ALB Klein Technology Group www.albkleinco.com 1. Troubleshooting Guide

More information

OPERATING PROCEDURES

OPERATING PROCEDURES OPERATING PROCEDURES 1.0 Purpose This element identifies Petsec s Operating Procedures for its Safety and Environmental Management System (SEMS) Program; it applies to all Petsec operations. Petsec is

More information

Ranking of safety issues for

Ranking of safety issues for IAEA-TECDOC-640 Ranking of safety issues for WWER-440 model RANKING OF SAFETY ISSUES FOR WWER-440 MODEL PLEASE BE AWARE THAT ALL OF THE MISSING PAGES IN THIS DOCUMENT WERE ORIGINALLY BLANK RANKING OF SAFETY

More information

LO/TO LOCKOUT/TAGOUT PROGRAM

LO/TO LOCKOUT/TAGOUT PROGRAM LO/TO LOCKOUT/TAGOUT PROGRAM April 2017 CONTENTS Section 1: Introduction...1 Section 2: Purpose... 1 Section 3: Application... 1 Section 4: Definitions... 2 Section 5: Roles and Responsibilities... 4 Section

More information

Leaks from Unit-3 PCV and steam release in a large amount

Leaks from Unit-3 PCV and steam release in a large amount Attachment 3-8 Leaks from Unit-3 PCV and steam release in a large amount 1. Background At Unit-3 the suppression chamber (S/C) vent line configuration was completed at 08:41 on March 13 th and the dry

More information