View Categories

Shell Monaca CSB report: step-by-step checklist to convert PHA administrative controls into engineered SIS protections

Shell Monaca CSB report is the focus of this technical briefing. The U.S. Chemical Safety Board released a final report on 16 September 2026 into the ethane cracking furnace explosion at Shell Polymers Monaca on 4 June 2025.

The CSB found that a process hazard analysis (PHA) had identified a cracked-gas backflow scenario but relied on administrative controls rather than the engineered protection available from the licensor, and it recommended re‑reviewing PHAs and implementing engineered protections where scenarios could cause fatality or major damage.

This article separates the verified findings from practical interpretation, explains why the issue matters across the asset lifecycle, and sets out a concise operational checklist and evidence workflow practitioners can use to convert administrative actions into safety instrumented system (SIS) protections.

Shell Monaca CSB report — latest evidence and technical context

The CSB final report was published on 16 September 2026 and records that the Shell Polymers Monaca site experienced a furnace explosion on 4 June 2025. A central finding is procedural: the PHA identified the hazardous scenario of cracked‑gas backflow but credited administrative controls instead of the engineered protection that was available from the process licensor.

The CSB recommended that operators review PHAs where deviations were addressed solely by administrative measures and implement engineered controls where potential scenarios could cause fatality or major damage.

That recommendation aligns with the functional‑safety framework now consolidated in the IEC 61511 series; the IEC 61511:2026 SER was published on 10 July 2026 as the standards pack title 'Functional safety – Safety instrumented systems for the process industry sector – ALL PARTS'.

Taken together, these documents provide the contemporaneous technical context for converting PHA conclusions into safety‑instrumented solutions and for revalidating existing IPL attributions where consequence magnitudes warrant an engineered barrier. The original evidence can be reviewed in U.S. Chemical Safety and Hazard Investigation Board (CSB) — Shell Polymers Furnace Explosion and Fire.

For related MSS guidance, see What Is IEC 61511?.

Shell Monaca CSB report: why this matters across the lifecycle

The CSB’s findings highlight recurring lifecycle weaknesses: PHAs that credit administrative barriers instead of independent protection layers, gaps in SIS boundaries, and poor management‑of‑change (MOC) traceability. These weaknesses are not merely paperwork issues; they affect how risk is reduced from design through operation and into modification and decommissioning.

From an operational perspective, a control credited in a PHA determines subsequent decisions—LOPA inputs, safety requirements specifications (SRS), proof‑test regimes and training. If an administrative control is misattributed as an IPL, the plant may lack an appropriately designed and maintained SIS, and regulators or insurers will question the technical basis for risk reduction.

To address this, teams should revalidate PHAs where consequences could be major or fatal, explicitly consider the licensor’s engineered options, and ensure every decision is recorded with its technical basis, owners and verification steps so that the decision survives design handover, MOC and audits. For related MSS guidance, see What Is a Safety Requirements Specification (SRS)?.

Operational checklist: converting PHA administrative controls into engineered protections

Practitioners need a pragmatic, auditable workflow to convert PHA action items into engineered IPLs or SIS protections. The following eight‑step checklist summarises the technical actions teams should take: 1) Locate PHA scenarios that currently rely on administrative controls and flag those with major or fatal consequence classifications.

2) Re‑run LOPA for each flagged scenario using conservative consequence and exposure assumptions to test whether the administrative barrier is sufficient. 3) Identify candidate engineered IPLs or SIS architectures (including vendor/licensor options) that demonstrably reduce risk to target tolerability.

4) Define the Safety Requirements Specification (SRS) for any SIS function and state proof‑test intervals and failure‑rate assumptions. 5) Update MOC records and PHA documentation to show the decision, the technical basis, named owners and due dates. 6) Schedule engineering verifications, functional safety assessments (FSA) and proof tests to confirm that the implemented IPL meets the SRS.

7) Update operating procedures, emergency response actions and training to reflect the new engineered protection and any residual administrative tasks. 8) Capture completion evidence—SRS, vendor data, test records and approvals—in the plant’s SLM/CMMS so the record is findable during audits.

At each step, document assumptions, involve the appropriate disciplines (process, instrumentation, safety, operations) and lock in explicit acceptance criteria for verification. For related MSS guidance, see What Is Management of Change (MOC)?.

How MSS supports controlled lifecycle information and traceable decisions

Controlling lifecycle information and maintaining traceable decisions are central to demonstrating that a PHA conversion to engineered protection was properly managed. MSS workflows are designed to connect source evidence—PHA outputs, LOPA worksheets, SRS documents and vendor data—with approvals, MOC entries and verification records in a single controlled environment.

That linkage preserves the technical basis, named responsibilities and completion evidence without replacing specialist engineering judgement: the SRS, proof‑test results and FSA outcomes remain technical artefacts authored by engineers, while the controlled workflow ensures they are discoverable and auditable.

For teams responding to the CSB recommendation, this means easier verification that a flagged PHA scenario was reassessed, that an engineered IPL was specified and tested against a stated SRS, and that any residual administrative measures are recorded with their limitations.

Maintaining this end‑to‑end traceability reduces the risk of decisions becoming dissociated from evidence as assets evolve through MOC, upgrades and operator turnover. For related MSS guidance, see IEC 61511 Compliance Explained.

Please complete the form below

Please complete the form below.

You will automatically be forwarded to a demonstration video