DOE-HDBK-1224-2018, Hazard and Accident Analysis Handbook
The principal purpose of this Handbook is to guide development of the DSA safety analysis for nuclear facilities in order to satisfy the requirements of a safe harbor method set out in 10 CFR Part 830, Subpart B.
Related To:
Version history and related documents
Superseded by
A newer version replaces this document.
- DOE-HDBK-1224-2024Hazard and Accident Analysis Handbook (Feb 28, 2024)
Related documents
- DOE-STD-5506-2021Preparation of Safety Basis Documents for Transuranic (TRU) Waste Facilities
- DOE-HDBK-1163-2020Integration of Hazard Analyses
- DOE-STD-1228-2019Preparation of Documented Safety Analysis for Hazard Category 3 DOE Nuclear Facilities
- DOE-HDBK-1163-2020Integration of Hazard Analyses
- DOE-STD-1228-2019Preparation of Documented Safety Analysis for Hazard Category 3 DOE Nuclear Facilities
- DOE-STD-5506-2021Preparation of Safety Basis Documents for Transuranic (TRU) Waste Facilities
Document text
Text extracted from the attached file. Refer to the original document for the authoritative version.
Section 1
DOE-HDBK-1224-2018
August 2018
DOE HANDBOOK
HAZARD AND ACCIDENT ANALYSIS HANDBOOK
Interim Use
U.S. Department of Energy
Washington, D.C. 20585
DOE-HDBK-1224-2018
ii
FOREWORD
This U.S. Department of Energy (DOE) Handbook is approved for use by all DOE elements and their
contractors. It may be applied to upgrading existing Documented Safety Analyses (DSAs) to the
requirements of DOE-STD-3009-2014, Preparation of Nonreactor Nuclear Facility Documented Safety
Analysis, or to revising DSAs for existing facilities based on their current safe harbor methodology. The
Handbook may also be used to prepare and document hazard and accident analyses during facility design.
This Handbook is intended to assist DOE and its contractors in preparing and reviewing DSAs that are
cost-effective and consistent in quality and content. To this end, the Handbook provides information on
applicable scientific theories, analysis techniques, practical examples, and lessons learned from DOE
applications and experience.
The Handbook addresses these subjects:
• Process for preparing a safety analysis, specifically the Chapter 3 portion of the DSA,
• Major accident types, such as fires, explosions, loss of confinement, chemical reactions, and
natural phenomena events,
• Criticality accident analysis,
• Source term analysis,
• Radiological dispersion and consequence analysis, and
• Chemical dispersion and consequence analysis.
DOE Order 252.1A, Admin. Chg. 1, Technical Standards Program, states that DOE handbooks provide
“a compilation of good practices, lessons-learned, or reference information that serve as resources on
specific topics.” The guidance provided in this Handbook is not mandatory and may be used at the
discretion of DOE contractors and field offices.
This Handbook is being issued for “Interim Use” because it is the first publication of a very large and
technically complex document. While great efforts have been made to achieve completeness and
accuracy, comments and feedback are welcome from users during the initial two-year period of
availability. Beneficial comments (recommendations, additions, and deletions), as well as any pertinent
data that may be of use in improving this document, should be emailed to nuclearsafety@hq.doe.gov or
addressed to:
Office of Nuclear Safety (AU-30)
Office of Environment, Health, Safety and Security
U.S. Department of Energy
19901 Germantown Road
Germantown, MD 20874
mailto:NuclearSafety@hq.doe.gov
DOE-HDBK-1224-2018
iii
ACKNOWLEDGMENTS
This technical handbook represents a multidisciplinary product of multiple authors and contributors who
have worked in some capacity in the DOE nuclear weapons complex. In the table below, DOE
acknowledges the contributions of the many professionals who authored or reviewed various sections of
this document.
Section 2
Contributor DOE or Contractor Affiliation DOE Nuclear Sites
Sam Rosenbloom DOE AU-30 Office of Nuclear Safety DOE AU-31 Program Manager
Ron Beaulieu National Security Technologies Nevada National Security Site
Sandra Brereton Lawrence Livermore National Laboratory Lawrence Livermore
R.T. Brock DOE Amarillo Area Office Pantex
Kevin Carroll Lawrence Livermore National Laboratory Lawrence Livermore
Roger Casteel DOE Office of Science Oak Ridge
Chris Chaves DOE AU-30 Office of Nuclear Safety DOE HQ
Doug Clark Consolidated Nuclear Security Y-12
Allan Coutts AECOM Savannah River
Doug Craig Advanced Technologies & Laboratories Savannah River
Dick Englehart DOE AU-30 Office of Nuclear Safety/PEC DOE HQ
Brad Evans Pacific Northwest National Laboratory Hanford
Terry Foppe Link Technologies/Foppe & Associates Rocky Flats, multiple DOE sites
Caroline Garzon DOE EM Chief of Nuclear Safety staff DOE HQ
Chuck Grigsby Los Alamos National Laboratory Los Alamos
Brent Gutierrez DOE Savannah River Site Savannah River
Mukesh Gupta AECOM Savannah River, other DOE sites
David Hesse Battelle Columbus Laboratories Multiple DOE sites
Jerry Hicks DOE Criticality Safety Support Group NNSA Albuquerque Service Center
Quazi Hossain Lawrence Livermore National Laboratory Lawrence Livermore
Roy Hunt Consolidated Nuclear Security Y-12
Lee Hyder Savannah River Nuclear Solutions Savannah River
Kamiar Jamali DOE AU-30 Office of Nuclear Safety DOE HQ
Sharon Jasim-Hanif DOE AU-30 Office of Nuclear Safety DOE HQ
Adam Jivelekas Washington River Protection Solutions Hanford
Hans Jordan Innovative Technology Solutions Rocky Flats
Kevin Kimball Consolidated Nuclear Security Y-12 and Pantex
Craig Kullberg NNSA Los Alamos Site Office Los Alamos
Roger Lanning Bechtel National Hanford
Bob Marusich Fluor Daniel Hanford
Carl Mazzola Project Enhancement Corporation Multiple DOE sites
John McAllister AECOM Hanford and Savannah River
Patrick McClure Los Alamos National Laboratory Los Alamos
DOE-HDBK-1224-2018
iv
Contributor DOE or Contractor Affiliation DOE Nuclear Sites
Steven McDuffie DOE EM Chief of Nuclear Safety staff DOE HQ
Tom McLaughlin DOE Criticality Safety Support Group Supporting NNSA HQ
Jofu Mishima SAIC Multiple DOE sites
Rich Miller Sonalysts Los Alamos and other DOE sites
Jim Morman DOE Criticality Safety Support Group Argonne National Laboratory
James O’Brien DOE DOE HQ
Kevin O’Kula AECOM Savannah River
Shirley Olinger DOE Rocky Flats Project Office Rocky Flats
Ingle Paik Westinghouse Safety Management Solutions Savannah River
Jane Peel Westinghouse Safety Management Solutions Savannah River
Vern Peterson Link Technologies/AB Consulting Rocky Flats, other DOE sites
David Pinkston Lawrence Livermore National Laboratory Lawrence Livermore
Marty Plys Fauske & Associates Oak Ridge and other DOE sites
Louis Restrepo Project Enhancement Corporation Multiple DOE sites
Rama Sastry DOE AU-30 Office of Nuclear Safety DOE HQ
Daniel Schmitt Hukari Technical Services Los Alamos
Jim Schornhorst Westinghouse Safety Management Solutions Savannah River
Garrett Smith DOE AU-30 Office of Nuclear Safety Director DOE HQ
Chris Steele DOE Los Alamos Site Office Los Alamos
Don Swanson Triad Safety Engineering Rocky Flats
Dave Thoman AECOM/Westinghouse Safety Management Sols. Savannah River
Ivan Trujillo NNSA Albuquerque Service Center NNSA HQ
Joe Vera Bechtel National Hanford
Doug Wenzel Lockheed Martin Idaho Technologies Idaho National Laboratory
Bob Wilson DOE Environmental Management DOE HQ
Jeff Woody Link Technologies Oak Ridge, other DOE sites
Al Wooten AECOM Savannah River
Ray Yeung AECOM Savannah River
Bruce Zimmerman Washington River Protection Solutions Hanford
Section 3
DOE-HDBK-1224-2018
v
CONTENTS
ACRONYMS ............................................................................................................................................................ XII
1 INTRODUCTION ......................................................................................................................................... 1
1.1 PURPOSE ....................................................................................................................................................... 1
1.2 OUTLINE ....................................................................................................................................................... 1
2 HAZARD ANALYSIS .................................................................................................................................. 3
2.1 ELEMENTS OF HAZARD ANALYSIS ................................................................................................................ 3
2.2 HAZARD IDENTIFICATION AND CHARACTERIZATION .................................................................................... 3
2.2.1 Hazard Data Gathering ............................................................................................................................. 4
2.2.2 Hazard Data Recording ............................................................................................................................. 4
2.2.3 Hazard Summary Development ................................................................................................................. 9
2.2.4 Exclusion of Standard Industrial Hazards and Other Hazardous Materials ........................................... 11
2.3 INITIAL HAZARD EVALUATION DEVELOPMENT .......................................................................................... 14
2.3.1 Overview .................................................................................................................................................. 14
2.3.2 Nuclear Criticality Hazard Evaluation .................................................................................................... 16
2.3.3 Chemical Hazard Evaluation ................................................................................................................... 16
2.4 HAZARD EVALUATION METHODS ................................................................................................................ 17
2.4.1 Commercial Industry Methods and DSA Hazard Evaluations ................................................................. 17
2.4.2 Method #1: What-If? ................................................................................................................................ 17
2.4.3 Method #2: Hazard and Operational Analysis ....................................................................................... 19
2.4.4 Method #3: Failure Modes and Effects Analysis .................................................................................... 23
2.4.5 Method #4: Event Trees and Fault Trees ................................................................................................ 24
2.5 INITIAL DEVELOPMENT OF A DSA HAZARD EVALUATION TABLE .............................................................. 25
2.6 LIKELIHOOD, CONSEQUENCE, AND RISK METHODS .................................................................................... 26
Section 4
2.6.1 Qualitative Consequences ........................................................................................................................ 26
2.6.1.1 Receptor Consequence Levels............................................................................................................................. 26
2.6.1.2 Facility Worker Consequences ............................................................................................................................ 28
2.6.1.3 Standard Industrial Hazard Consequences to Facility Worker ............................................................................. 32
2.6.2 Qualitative Likelihood ............................................................................................................................. 33
2.6.3 Qualitative Risk ........................................................................................................................................ 35
2.7 UNMITIGATED AND MITIGATED HAZARD EVALUATIONS ............................................................................ 35
2.8 HAZARD EVALUATION PRESENTATION IN DSA .......................................................................................... 36
3 ACCIDENT ANALYSIS ............................................................................................................................ 39
3.1 ACCIDENT TYPE SELECTION ....................................................................................................................... 39
3.2 ACCIDENT ANALYSIS PROCESS ................................................................................................................... 40
3.3 ANALYSIS INPUTS AND ASSUMPTIONS ........................................................................................................ 41
3.4 BEYOND DESIGN/EVALUATION BASIS ACCIDENTS ..................................................................................... 43
3.5 SOFTWARE QUALITY ASSURANCE .............................................................................................................. 46
4 EVALUATION OF EFFECTS OF MAJOR ACCIDENT TYPES ........................................................ 49
4.1 INTRODUCTION ........................................................................................................................................... 49
4.1.1 Information from Accident Analysis to Include in the DSA ..................................................................... 50
4.2 FIRE SCENARIO ANALYSIS .......................................................................................................................... 50
4.2.2 Fire Analysis ............................................................................................................................................ 52
4.2.2.1 Example Analytical Methods .............................................................................................................................. 54
4.2.2.1.1 Heat Release Rate ........................................................................................................................................ 54
4.2.2.1.2 Pool Fire Heat Release Rate ........................................................................................................................ 54
4.2.2.1.4 Flame Height ............................................................................................................................................... 56
4.2.2.1.5 Enclosure Fire Dynamics ............................................................................................................................. 57
Section 5
4.2.2.1.5.1 Pre-flashover ........................................................................................................................................ 57
4.2.2.1.5.2 Flashover.............................................................................................................................................. 58
4.2.2.1.6 Solid Fuel Ignition and Radiant Heating ...................................................................................................... 59
4.2.3 Source Term Calculation for Fire Scenarios ........................................................................................... 62
DOE-HDBK-1224-2018
vi
4.2.3.1 Effect on Hazardous Material.............................................................................................................................. 62
4.2.3.1.1 Determining MAR for the FIRE Event ........................................................................................................ 62
4.2.3.1.2 Determining DR and ARF/RF for the Fire Event ........................................................................................ 63
4.2.3.2 Thermal Effects ................................................................................................................................................... 64
4.2.3.3 Smoke Damage ................................................................................................................................................... 65
4.3 EXPLOSION SCENARIO ANALYSIS ............................................................................................................... 66
4.3.1 Explosion Event Types and Scenarios ...................................................................................................... 66
4.3.2 Explosions Analysis ................................................................................................................................. 71
4.3.2.1 Pressure Vessel Burst .......................................................................................................................................... 71
4.3.2.1.1 Blast Effect from Pressure Vessel Burst ...................................................................................................... 72
4.3.2.1.2 Fragmentation from Pressure Vessel Burst .................................................................................................. 80
4.3.2.1.3 Thermal Effects from Pressure Vessel Burst ............................................................................................... 87
4.3.2.2 BLEVE ............................................................................................................................................................... 87
4.3.2.2.1 Blast Effect from BLEVE ........................................................................................................................ 88
4.3.2.2.2 Fragmentation from BLEVE .................................................................................................................... 88
4.3.2.2.3 Thermal Effects from BLEVE ................................................................................................................. 88
Section 6
4.3.2.3 Vapor Cloud Explosion ..................................................................................................................................... 89
4.3.2.3.1 Vapor Cloud Deflagration ........................................................................................................................... 90
4.3.2.3.2 Vapor Cloud Detonation .............................................................................................................................. 90
4.3.2.3.3 VAPOR CLOUD Deflagration AND Detonation PRACTICAL DIFFERENCES ..................................... 90
4.3.2.3.4 Blast Effect from Vapor Cloud Explosion ................................................................................................... 91
4.3.2.3.5 Fragmentation from Vapor Cloud Explosion ............................................................................................... 99
4.3.2.3.6 Thermal Effect from Vapor Cloud Explosion .............................................................................................. 99
4.3.2.4 Flash Fire .......................................................................................................................................................... 99
4.3.3 Consequences of Explosions BEYOND RELEASES OF HAZARDOUS MATERIALS ............................ 99
4.3.3.1 Damage Caused by Overpressure (Detonations and Deflagrations) .................................................................... 99
4.3.3.2 Damage Caused by Fragmentation .................................................................................................................... 101
4.3.3.3 Damage Caused by Thermal Effects to Facility workers ................................................................................... 101
4.3.3.4 Damage Caused by Thermal Effects to SSCs .................................................................................................... 104
4.3.4 Source Term Calculation for Explosion Scenarios ................................................................................ 105
4.3.4.1 Explosion MAR ................................................................................................................................................ 105
4.3.4.2 Explosion Damage Ratio (DR).......................................................................................................................... 105
4.3.4.3 Explosion ARF/RF ............................................................................................................................................ 106
4.3.4.4 Explosion Release Duration .............................................................................................................................. 106
4.3.5 Case: Source Term Calculation for Hydrogen Explosion ..................................................................... 107
4.3.5.1 GAS Explosion source term (ST) .................................................................................................................... 109
4.3.5.2 Gas deflagration Source Term (ST) ................................................................................................................ 110
4.4 SPILLS ....................................................................................................................................................... 112
4.4.1 Types of Loss of Confinement/Spills and Scenarios ............................................................................... 112
4.4.2 Analysis of Spills .................................................................................................................................... 113
Section 7
4.4.2.1 Glovebox Spills ............................................................................................................................................... 114
4.4.2.2 Material Handling and Waste Container Accidents ........................................................................................ 114
4.4.2.3 Over-pressurizations ....................................................................................................................................... 115
4.4.2.3.1 Pressurized Powder Releases ..................................................................................................................... 115
4.4.2.3.2 Pressurized Liquid Releases ...................................................................................................................... 115
4.4.2.4 Aerodynamic Entrainment .............................................................................................................................. 115
4.5 ANALYSIS OF CHEMICAL REACTIONS ....................................................................................................... 116
4.5.1 Organic-based Ion Exchange Resin Reaction ........................................................................................ 116
4.5.1.1 Reactions of Nitric Acid with Organic Materials ............................................................................................ 117
4.5.1.2 Composition and Reactions of Ion Exchange Resins ...................................................................................... 118
4.5.1.3 Chemical Degradation of Ion Exchange Resins .............................................................................................. 118
4.5.1.4 Radiation Effects on Ion Exchange Resins ...................................................................................................... 119
4.5.1.5 Incidents Involving Chemical Reactions of Resins ......................................................................................... 119
4.5.1.6 Discussion of Accident Conditions .................................................................................................................. 120
4.5.2 “Red Oil” Reaction................................................................................................................................ 120
4.5.2.1 Background and Prior Red Oil Incidents ......................................................................................................... 120
4.5.2.2 Discussion of Red Oil Accident Conditions .................................................................................................... 123
4.5.2.3 Approach to Preventing Red Oil Accidents ..................................................................................................... 124
4.5.2.4 Preventive Controls ......................................................................................................................................... 125
4.5.3 Organic Reaction Event ......................................................................................................................... 125
4.5.3.1 Background and Discussion ............................................................................................................................ 125
DOE-HDBK-1224-2018
vii
Section 8
4.5.3.2 Analytical and Test Methods ........................................................................................................................... 127
4.5.3.3 Prevention and Mitigation ............................................................................................................................... 127
4.5.4 Hydroxylamine Nitrate Reaction............................................................................................................ 127
4.5.4.1 Prevention and Mitigation ............................................................................................................................... 128
4.5.5 Chemical Reactions Accident Analysis .................................................................................................. 128
4.6 NATURAL PHENOMENA HAZARD EVENTS................................................................................................. 129
4.6.1 NPH Event Types ................................................................................................................................... 129
4.6.2 NPH Event Analysis Overview ............................................................................................................... 129
4.6.2.1 Accident Analysis for A New Nuclear Facility or Major Modification of an existing nuclear facility............. 129
4.6.2.2 Accident Analysis for Existing Nuclear Facility DSA ...................................................................................... 130
4.6.2.3 General Methodology ........................................................................................................................................ 132
4.6.3 Seismic Events ........................................................................................................................................ 133
4.6.4 Extreme Wind Events ............................................................................................................................. 134
4.6.5 Flood and Precipitation Events ............................................................................................................. 134
4.6.6 Lightning Events .................................................................................................................................... 135
4.6.7 Volcanic Eruption and Ashfall Events ................................................................................................... 138
4.6.8 Wildland Fires ....................................................................................................................................... 139
4.6.8.1 Wildland Fire Event Description and Analysis ................................................................................................. 140
4.6.8.2 Example: Wildland Fire Facility/Structure Hazard ASSESSMENT ................................................................. 142
4.7 MAN-MADE EXTERNAL EVENTS .............................................................................................................. 147
4.7.1 Aircraft Crashes ..................................................................................................................................... 148
4.7.1.1 Screening Analysis ............................................................................................................................................ 148
4.7.1.2 Aircraft Crash Damage Assessment ................................................................................................................ 151
Section 9
4.7.2 Vehicle Crashes ..................................................................................................................................... 151
4.7.2.1 Vehicle Crash into Facility ............................................................................................................................... 151
4.7.2.2 Onsite Transportation Accident ........................................................................................................................ 151
4.7.3 Loss of Power to Safety-related SSCs .................................................................................................... 153
5 SOURCE TERM ANALYSIS .................................................................................................................. 154
5.1 INTRODUCTION ......................................................................................................................................... 154
5.2 RADIOLOGICAL SOURCE TERM COMPONENTS .......................................................................................... 154
5.2.1 Material at Risk ..................................................................................................................................... 157
5.2.1.1 Overview of Requirements, Guidance, and Practices for .................................................................................. 157
Identifying MAR ............................................................................................................................................................ 157
5.2.1.2 Examples for Identifying MAR ......................................................................................................................... 158
5.2.2 Determining the Damage Ratio (DR) .................................................................................................... 162
5.2.2.1 Overview of Requirements, Guidance, and Practices........................................................................................ 162
5.2.2.2 Examples .......................................................................................................................................................... 163
5.2.3 Airborne Release Fraction and Respirable Fraction ............................................................................. 168
5.2.3.1 Overview of Requirements, Guidance, and Practices for Determining ARF/RF ............................................... 168
5.2.3.2 Examples for Determining ARF/RF .................................................................................................................. 181
5.2.4 Airborne Release Rate ........................................................................................................................... 183
5.2.5 Leakpath Factor ..................................................................................................................................... 184
5.2.5.1 Filtration LPF .................................................................................................................................................... 185
5.2.5.2 LPF Modeling ................................................................................................................................................... 186
5.3 CHEMICAL RELEASE SOURCE TERMS........................................................................................................ 187
5.4 APPROPRIATENESS OF SOURCE TERMS ..................................................................................................... 190
Section 10
5.4.1 Adequate Technical Basis to Depart from Default or Bounding Values ................................................ 190
6 ATMOSPHERIC DISPERSION ............................................................................................................. 193
6.1 INTRODUCTION ......................................................................................................................................... 193
6.2 KEY RECEPTORS ....................................................................................................................................... 194
6.3 METEOROLOGICAL PARAMETERS AFFECTING DISPERSION ....................................................................... 195
6.3.1 Wind Speed, Wind Direction, and Wind Direction Standard Deviations ............................................... 196
6.3.1.1 Wind Speed ....................................................................................................................................................... 196
6.3.1.2 Wind Direction .................................................................................................................................................. 197
6.3.1.3 Wind Direction Standard Deviations................................................................................................................. 197
6.3.2 Wind Speed Profile with Height ............................................................................................................. 197
DOE-HDBK-1224-2018
viii
6.3.3 Mixing Layer Height .............................................................................................................................. 198
6.3.4 Vertical Temperature Profiles ............................................................................................................... 199
6.3.5 Precipitation .......................................................................................................................................... 200
6.3.6 Temperature and Relative Humidity ...................................................................................................... 200
6.4 GAUSSIAN PLUME MODEL FOR NEUTRALLY BUOYANT PLUMES .............................................................. 200
6.4.1 Basic Gaussian Equations ..................................................................................................................... 200
6.4.2 Gaussian Plume Widths and Depths ...................................................................................................... 203
6.4.2.1 Atmospheric Stability Classes ........................................................................................................................... 204
6.4.2.2 Methods of Calculating Stability Classes .......................................................................................................... 205
6.4.2.3 Additional Stability Classification Techniques ................................................................................................ 208
6.4.2.4 Methods of Calculating Plume Width and Plume Thickness ............................................................................ 210
Section 11
6.5 CHARACTERIZATION OF METEOROLOGICAL AND SITE DATA ................................................................... 216
6.5.1 Persistence ............................................................................................................................................. 218
6.5.2 Joint Frequency Distribution (JFD) ...................................................................................................... 218
6.5.3 Full Data Set Sampling .......................................................................................................................... 219
6.5.4 Treatment of Calm and Variable Winds ................................................................................................. 219
6.6 METEOROLOGICAL DATA ADEQUACY FOR SAFETY ANALYSIS ................................................................. 221
6.7 TYPICAL AND UNFAVORABLE DISPERSION CONDITIONS .......................................................................... 222
6.8 SPECIAL GAUSSIAN MODELING CONSIDERATIONS ................................................................................... 224
6.8.1 Averaging-Time and Large Eddy Plume Meander ................................................................................ 224
6.8.2 Mechanical Turbulence Due to Surface Roughness............................................................................... 226
6.8.3 Aerodynamic Effects of Buildings .......................................................................................................... 229
6.8.4 Plume Modifications Through Decay, Daughter In-Growth, and Deposition Processes ...................... 232
6.8.5 Principles Governing Plume Rise and Downwash ................................................................................ 236
6.8.5.1 Momentum Plume Rise ..................................................................................................................................... 237
6.8.5.2 Buoyancy Plume Rise ....................................................................................................................................... 238
6.8.6 PLUME IMPACTION ............................................................................................................................ 239
6.9 DOE CENTRAL REGISTRY OF RADIOLOGICAL DISPERSION AND CONSEQUENCE ANALYSIS CODES.......... 240
6.9.1 MACCS2 ................................................................................................................................................ 248
6.9.2 GENII ..................................................................................................................................................... 249
6.9.3 HOTSPOT .............................................................................................................................................. 250
6.10 ATMOSPHERIC DISPERSION OPTIONS IN DOE-STD-3009-2014 ............................................................... 250
6.11 ATMOSPHERIC DISPERSION MODELING PROTOCOL ............................................................................. 251
6.12 NON-GAUSSIAN DISPERSION MODELING .................................................................................................. 258
6.12.1 Dispersion under Extreme Wind or Tornado Event ............................................................................... 258
6.12.2 Finite Plume External Dose Modeling ................................................................................................... 260
6.12.3 Plumes from Energetic Events ............................................................................................................... 260
Section 12
6.13 CO-LOCATED WORKER DISPERSION FACTOR ............................................................................................ 263
6.13.1 Technical Report for CW χ/Q value ....................................................................................................... 263
6.13.2 Alternate χ/Q Value Justification ........................................................................................................... 263
6.13.2.1 Hand Calculations for a χ/Q Value Where the Default Value is Not Appropriate ........................................... 264
6.13.2.2 Computer Code Modeling for a χ/Q Value Where the Default Value is Not Appropriate ............................... 265
7 AQUATIC DISPERSION AND GROUNDWATER TRANSPORT .................................................... 267
7.1 OVERVIEW ................................................................................................................................................ 267
7.2 NRC REGULATORY GUIDANCE ON AQUATIC DISPERSION AND DOSE CALCULATION ...... 268
7.3 DOCUMENTED SAFETY ANALYSIS APPROACH .......................................................................................... 268
7.4 LIQUID EFFLUENT RELEASE KEY RECEPTORS .......................................................................................... 269
7.5 LIQUID EFFLUENT RELEASE REDISTRIBUTION MECHANISMS AND UPTAKE .............................................. 269
7.5.1 Initial Mixing ......................................................................................................................................... 269
7.5.2 Far-Field Mixing ................................................................................................................................... 269
7.5.3 Deposition And Resuspension In Sediments........................................................................................... 270
7.5.4 Uptake Mechanisms ............................................................................................................................... 271
7.6 AQUATIC DISPERSION MODELS AND COMPARISONS ................................................................................. 271
7.6.1 Classes of Aquatic Dispersion Models ................................................................................................... 271
7.6.2 Aquatic Dispersion Model Attributes and Characteristics .................................................................... 272
7.6.3 Comparison of Aquatic Dispersion Models ........................................................................................... 273
DOE-HDBK-1224-2018
ix
7.6.3.1 LADTAP2 ......................................................................................................................................................... 273
7.6.3.2 STREAM2 ....................................................................................................................................................... 274
7.6.3.3 GENII 2.10.1 .................................................................................................................................................... 274
7.6.3.4 RIVER-RAD .................................................................................................................................................... 274
7.6.3.5 DISPERS.......................................................................................................................................................... 274
Section 13
7.7 GROUNDWATER TRANSPORT .................................................................................................................... 275
7.7.1 Overview ................................................................................................................................................ 275
7.7.2 Groundwater Flow and Contaminant Transport ................................................................................... 275
7.7.3 Tritium in Sediments .............................................................................................................................. 276
7.7.4 Groundwater Transport Model Considerations ..................................................................................... 276
8 RADIOLOGICAL CONSEQUENCE ASSESSMENT .......................................................................... 278
8.1 FUNDAMENTALS ....................................................................................................................................... 278
8.1.1 Types of Radiation ................................................................................................................................. 279
8.1.2 Nuclear Fission ...................................................................................................................................... 280
8.1.3 Radioactivity .......................................................................................................................................... 281
8.2 EFFECTS OF RADIATION ON THE BODY ..................................................................................................... 282
8.2.1 Dose Evaluations ................................................................................................................................... 282
8.2.2 Inhalation (Plume) Dose ........................................................................................................................ 285
8.2.3 Cloudshine Dose .................................................................................................................................... 288
8.2.4 Groundshine Dose ................................................................................................................................. 288
8.2.5 Prompt (Direct) Dose ............................................................................................................................ 289
8.2.6 Plutonium Equivalent Curies ................................................................................................................. 290
8.3 HEALTH RISKS .......................................................................................................................................... 290
8.3.1 High-LET Radiation............................................................................................................................... 291
8.3.2 Low-LET Radiation ................................................................................................................................ 291
8.3.3 Acute Health Risks ................................................................................................................................. 292
Section 14
9 CHEMICAL DISPERSION AND CONSEQUENCE ANALYSIS ....................................................... 293
9.1 INTRODUCTION ......................................................................................................................................... 293
9.2 CHEMICAL CONSEQUENCE ASSESSMENT FUNDAMENTALS ....................................................................... 294
9.3 CHEMICAL SCREENING CRITERIA ............................................................................................................. 295
9.4 CHEMICAL HEALTH EFFECTS ON THE HUMAN BODY ................................................................................ 297
9.4.1 Chemical Concentrations and Exposure Time ....................................................................................... 297
9.4.1.1 Chemical Exposure Time .................................................................................................................................. 297
9.4.1.2 Protective Action Criteria for Releases of a Single Chemical ........................................................................... 299
9.4.1.3 Protective Action Criteria for Releases of Multiple Chemicals ........................................................................ 300
9.4.2 Modes of Exposure and Routes of Entry of Toxic Chemicals that Result in Health Effects ................... 300
9.4.3 Toxic Chemical Acute Exposure Limits ................................................................................................. 301
9.4.3.1 EPA Acute Exposure Guideline Levels ............................................................................................................ 301
9.4.3.2 AIHA Emergency Response Planning Guidelines ............................................................................................ 302
9.4.3.3 DOE PAC/TEELs ............................................................................................................................................. 302
9.4.4 Chemical Mixture Methodology ............................................................................................................. 306
9.4.5 Chronic Health Effects of Toxic Chemicals on the Human Body: Carcinogenicity, Mutagenicity, and
Teratogenicity ................................................................................................................................................... 307
9.5 TOXIC CHEMICAL RELEASE PHENOMENOLOGY AND SUBSEQUENT ATMOSPHERIC TRANSPORT AND
DIFFUSION ............................................................................................................................................................. 308
9.5.1 Pressurized Liquids: Two-Phase Flow Toxic Chemical Release .......................................................... 308
9.5.1.1 FLASHING FRACTION AND AEROSOL FORMATION ............................................................................. 309
9.5.1.2 TWO-PHASE RELEASE OF CHLORINE FROM A PIPE ............................................................................. 312
9.5.2 Pressurized Gases: Choked Flow Toxic Chemical Release ................................................................... 314
9.5.2.2 VAPOR OUTFLOW FROM BREACH OF A PIPELINE................................................................................ 317
9.5.2.3 OUTFLOW FROM A CYLINDRICAL TANK ............................................................................................... 318
9.5.2.4 OUTFLOW FROM A SPHERICAL TANK ..................................................................................................... 320
9.5.2.5 OUTFLOW FROM PROCESS VESSELS OF OTHER VARIOUS SHAPES ................................................. 321
Section 15
9.5.3 Dense Gas Toxic Chemical Release And Dispersion ............................................................................. 321
9.5.4 Non-Pressurized Liquid Release ............................................................................................................ 323
9.5.4.1 Convective Boiling............................................................................................................................................ 324
DOE-HDBK-1224-2018
x
9.5.4.2 Conductive Boiling ........................................................................................................................................... 325
9.5.4.3 Nitric Acid and Carbon Tetrachloride Pool Evaporation Rates ......................................................................... 325
9.5.4.3.2 Carbon Tetrachloride Pool Evaporation..................................................................................................... 329
9.5.5 Energetic Events: Fires, Deflagrations, Detonations, Delayed Ignition Explosions, and Bleves ......... 334
9.6 METEOROLOGICAL PARAMETERS AFFECTING TOXIC CHEMICAL CONSEQUENCE ANALYSIS .................... 335
9.6.1 Temperature Effects ............................................................................................................................... 336
9.6.2 Relative Humidity Effects ....................................................................................................................... 336
9.7 TOXIC CHEMICAL ATMOSPHERIC TRANSPORT AND DIFFUSION MODELS .................................................. 336
9.7.1 Neutrally-Buoyant Gaussian Models ..................................................................................................... 337
9.7.1.1 ALOHA............................................................................................................................................................. 337
9.7.1.2 EPIcode ............................................................................................................................................................. 339
9.7.1.3 Chemical Dispersion Analysis with ALOHA and EPIcode .............................................................................. 340
9.7.2 Dense Gas Dispersion Models ............................................................................................................... 342
9.7.2.1 ALOHA............................................................................................................................................................. 343
9.7.2.2 DEGADIS ......................................................................................................................................................... 343
9.7.2.3 HGSYSTEM .................................................................................................................................................... 344
9.7.2.4 SLAB ................................................................................................................................................................ 344
9.7.3 Variable Trajectory Dispersion Models ................................................................................................. 345
9.7.4 Research-Grade Dispersion Models ...................................................................................................... 345
Section 16
9.8 TOXIC CHEMICAL CONSEQUENCE SCOPING METHODOLOGY TO EXCEED PAC/TEEL VALUES ................ 345
9.8.1 Gas, Powder, and Solid Release Model ................................................................................................. 346
9.8.2 Liquid Evaporation Scoping Calculation Model ................................................................................... 347
9.8.3 Screening Method for Maximally-Exposed Offsite Individual (MOI) High Consequence ..................... 349
9.9 EXAMPLE TOXIC CHEMICAL CALCULATIONS ............................................................................................ 350
9.9.1 Example 1: Calculate Ammonia Gas Quantity that Exceeds PAC/TEEL-3 at the CW ......................... 351
9.9.2 Example 2: Calculate Aluminum Oxide Powder Quantity that Exceeds PAC/TEEL-3 at the CW........ 351
9.9.3 Example 3: Calculate Liquid 70% Nitric Acid Quantity that Exceeds PAC/TEEL Values at 1 Km Site
Boundary .......................................................................................................................................................... 351
9.9.4 Example 4: Calculate Liquid 55% Hydrofluoric Acid Quantity that Exceeds PAC/TEEL Values at 1 Km
Site Boundary.................................................................................................................................................... 353
10 HAZARD CONTROL SELECTION AND CLASSIFICATION ......................................................... 354
10.1 HAZARD CONTROL SELECTION ................................................................................................................. 355
10.1.1 Hazard Control Selection Process ......................................................................................................... 355
10.1.1.1 Hazard and Accident Analysis Input to Control Selection .............................................................................. 355
10.1.1.2 Hazard Control Types ..................................................................................................................................... 357
10.1.1.3 Use of Risk Matrices for Control Selection ..................................................................................................... 359
10.1.2 Hazard Control Selection Considerations ............................................................................................. 361
10.2 SAFETY CLASSIFICATIONS OF CONTROLS ................................................................................................. 362
10.2.1 Safety Class Designation ....................................................................................................................... 362
10.2.2 Safety Significant Designation ............................................................................................................... 362
10.2.3 Classification of Other Hazard Controls ............................................................................................... 362
10.3 EVALUATION OF EXISTING FACILITIES WITH MITIGATED OFFSITE CONSEQUENCE ESTIMATES OVER THE
EVALUATION GUIDELINE ....................................................................................................................................... 363
Section 17
APPENDIX A: HAZARD ANALYSIS TABLE DEVELOPMENT .................................................................... 18
A.1 SCENARIO DESCRIPTION ............................................................................................................................. 18
A.2 INITIATING EVENT FREQUENCY .................................................................................................................. 18
A.3 UNMITIGATED CONSEQUENCE EVALUATION .............................................................................................. 19
A.4 SAFETY FUNCTIONS .................................................................................................................................... 19
A.5 PREVENTIVE FEATURES (DESIGN AND ADMINISTRATIVE) .......................................................................... 20
A.6 METHOD OF DETECTION ............................................................................................................................. 20
A.7 MITIGATIVE FEATURES (DESIGN AND ADMINISTRATIVE) ........................................................................... 20
A.8 SSC SAFETY CONTROL SUITE AND SAFETY FUNCTIONS ............................................................................. 21
A.9 MITIGATED CONSEQUENCES ....................................................................................................................... 21
A.10 PLANNED ANALYSES, ASSUMPTIONS AND RISK/OPPORTUNITY IDENTIFICATION ....................................... 21
A.11 HAZARDS EVALUATION TABLE .................................................................................................................. 22
DOE-HDBK-1224-2018
xi
APPENDIX B: CRITICALITY ACCIDENTS ........................................................................................................ 2
B.1 INTRODUCTION ............................................................................................................................................. 2
B.2 REGULATORY REQUIREMENTS, RECOMMENDATIONS AND GUIDANCE ......................................................... 3
B.2.1 Unmitigated Analysis ................................................................................................................................. 3
B.3 ACCIDENT FISSION YIELDS ........................................................................................................................... 4
B.3.1 Fission Yields of Solution and Solution-Like Systems ................................................................................ 4
B.3.2 Fission Yields of Non-Solution-Like Systems ............................................................................................. 7
B.3.2.1 Metals/Solids – One or a Few Large Pieces ......................................................................................................... 7
B.3.2.2 Dry, unmoderated Solids – Numerous Small Pieces, and Large Arrays .............................................................. 8
B.3.3 Fission Yields of Autocatalytic Accidents .................................................................................................. 8
B.4 EVALUATION OF DIRECT RADIATION DOSES ................................................................................................ 8
B.5 CRITICALITY ACCIDENT SOURCE TERMS ...................................................................................................... 8
Section 18
B.5.1 Fission Product Inventories ....................................................................................................................... 8
B.5.2 Particulate Release and Health Related Parameters ................................................................................. 9
B.6 CRITICALITY ACCIDENT EXAMPLE ............................................................................................................. 10
DOE-HDBK-1224-2018
xii
ACRONYMS
AC Administrative Control or Alternating Current
ACGIH American Conference of Government Industrial Hygienists
AED Aerodynamic Equivalent Diameter
AEGL Acute Exposure Guideline Level
AICC Adiabatic, Constant-Volume Combustion
AIHA American Industrial Hygienist Association
AMAD Activity Median Aerodynamic Diameter
ANS American Nuclear Society
ANSI American National Standards Institute
APAC Accident Phenomenology and Consequence
ARF Airborne Release Fraction
ASCE American Society of Civil Engineers
ASME American Society of Mechanical Engineers
ASTM American Society for Testing and Materials
BC Building Construction
BDBA Beyond Design Basis Accident
BEBA Beyond Evaluation Basis Accident
BEU Beyond Extremely Unlikely
BLEVE Boiling Liquid Expanding Vapor Explosion
BNL Brookhaven National Laboratory
BR Breathing Rate
BST Building Source Term
CCPS Center for Chemical Process Safety
CDC Centers for Disease Control
CFAST Consolidated Model of Fire and Smoke Transport
CFD Computational Fluid Dynamics
CFR Code of Federal Regulations
CMM Chemical Mixture Methodology
CR Central Registry
CSE Criticality Safety Evaluation
CTH Cloud Top Height
CW Co-located Worker
DBA Design Basis Accident
DCF Dose Conversion Factor
DDT Deflagration to Detonation Transition
DF Decontamination Factor
DG Dense Gas
DNFSB Defense Nuclear Facilities Safety Board
DOE Department of Energy
DOS Disk Operating System
DOT Department of Transportation
DR Damage Ratio
DSA Documented Safety Analysis
DTA Differential Thermal Analysis
DOE-HDBK-1224-2018
xiii
EBA Evaluation Basis Accident
EDE Effective Dose Equivalent
EEGL Emergency Exposure Guidance Level
EFCOG Energy Facility Contractor Group
EG Evaluation Guideline
EPA Environmental Protection Agency
ERPG Emergency Response Planning Guideline
EU Extremely Unlikely
FDC Flood Design Category
FDT Fire Dynamics Tool
FGR Federal Guidance Report
FHA Fire Hazards Analysis
FMEA Failure Modes and Effects Analysis
FTF Filter Test Facility
FW Facility Worker
GEP Good Engineering Practice
GNB Gaussian Neutrally Buoyant
GRF German Research Foundation
HA Hazard Analysis
HAZOP Hazard and Operational Analysis
HC Hazard Category
HCN Health Code Number
HDBK Handbook
HE High Explosive
HEPA High Efficiency Particulate Air
HPR Highly Protected Risk
HRR Heat Release Rate
HSDB Hazardous Substances Data Bank
IACR International Association of Cancer Registries
ICRP International Council on Radiation Protection
IDLH Immediately Dangerous to Life and Health
IEEE Institute of Electrical and Electronics Engineers
ILA Immediate Landscaped Area
INL Idaho National Laboratory
IST Initial Source Term
JFD Joint Frequency Distribution
LANL Los Alamos National Laboratory
LCF Latent Cancer Fatality
LEL Lower Explosive Limit
LET Linear Energy Transfer
LFL Lower Flammability Limit
LOC Level of Concern
LPF Leak Path Factor
LPG Liquified Petroleum Gas
DOE-HDBK-1224-2018
xiv
MAR Material at Risk
MAK-Wert Maximale Arbeitsplatz-Konzentration
MOI Maximally Exposed Offsite Individual
MW Molecular Weight
Section 19
NAC/AEGL National Advisory Committee for Acute Exposure Guideline Levels
NARAC National Atmospheric Release Advisory Center
NASA National Aeronautics and Space Administration
NCRP National Council on Radiation Protection
NDC Natural Phenomena Hazard Design Category
NEPA National Environmental Policy Act
NFDRS National Fire Rating Danger System
NIOSH National Institute for Occupational Safety and Health
NIST National Institute of Standards and Technology
NNSA National Nuclear Security Administration
NNSS Nevada Nuclear Security Site
NOAA National Oceanic and Atmospheric Administration
NPH Natural Phenomena Hazard
NQA Nuclear Quality Assurance
NRC Nuclear Regulatory Commission
NTSB National Transportation Safety Board
OSHA Occupational Safety and Health Administration
PAC Protective Action Criteria
PBL Planetary Boundary Layer
PC Performance Category
PDC Precipitation Design Category
PEL Permissible Exposure Level
PHA Preliminary Hazard Assessment
PISA Potential Inadequacy of the Safety Analysis
PNNL Pacific Northwest National Laboratory
PRA Probabilistic Risk Assessment
PrHA Process Hazard Analysis
PSO Program Secretarial Office
PUREX Plutonium Uranium Redox Extraction
PWHA Probabilistic Wind Hazard Assessment
RCRA Resource Conservation and Recovery Act
REL Recommended Exposure Level
RF Respirable Fraction
RG Regulatory Guide
RTECS Registry of Toxic Effects of Chemical Substances
SAC Specific Administrative Control
SAWG Safety Analysis Working Group
SBAA Safety Basis Approval Authority
SC Safety Class
SCAPA Subcommittee for Consequence Assessment and Protective Actions
SDC Seismic Design Category
DOE-HDBK-1224-2018
xv
SDS Safety Data Sheet
SFPE Society of Fire Protection Engineers
SIH Standard Industrial Hazard
SIZ Structure Ignition Zone
SME Subject Matter Expert
SMP Safety Management Program
SNL Sandia National Laboratories
SNM Special Nuclear Material
SQA Software Quality Assurance
SRDT Solar Radiation Delta Temperature
SRNL Savannah River National Laboratory
SRS Savannah River Site
SS Safety Significant
SSC Structures, Systems, and Components
ST Source Term
STD Standard
STEL Short-Term Exposure Level
STP Standard Temperature and Pressure
TBP Tri-Butyl Phosphate
TED Total Effective Dose
TEDE Total Effective Dose Equivalent
TEEL Temporary Emergency Exposure Limit
TF Topographical Feature
TLV Threshold Limit Value
TNO The Netherlands Organization
TNT Trinitrotoluene
TRU Transuranic
TSL Technical Support Level
TSR Technical Safety Requirement
TWA Time-Weighted Average
UEL Upper Explosive Limit
UFL Upper Flammability Limit
UL Underwriters Laboratories
USQ Unreviewed Safety Question
V & V Verification & Validation
VDC Volcanic Design Category
VP Vapor Pressure
WDC Wind Design Category
WEEL Workplace Environmental Exposure Limit
WIPP Waste Isolation Pilot Plant
Note: Definitions related to the DOE hazard and accident analysis process can be found in 10 CFR
§830.3, DOE-STD-3009-2014 (or other Part 830 safe harbor), or DOE-HDBK-3010-94, Airborne Release
Fractions/Rates and Respirable Fractions for Nonreactor Nuclear Facilities. Other definitions related to
accident phenomenology for evaluation of potential consequences, such as physical and chemical effects,
are provided in references cited in the text.
DOE-HDBK-1224-2018
1
1 INTRODUCTION
Section 20
This Handbook contains methodology, data sources, and subject matter references for performing and
reviewing hazard and accident analysis for Department of Energy (DOE) nonreactor nuclear facilities.
The guidance offered supports development of a Documented Safety Analysis (DSA) required by 10
CFR1 Part 830, Nuclear Safety Management, Subpart B, “Safety Basis Requirements.”
The Handbook uses as a starting point drafts of a report prepared by the Safety Analysis Working Group
of the Energy Facility Contractors Group. This early effort was sponsored by DOE’s Office of Defense
Programs (predecessor of NNSA) in the early 2000s. Although that report was not completed, some of its
technical content has been incorporated into this Handbook.
The Handbook describes best practices gleaned from development of DSAs throughout the DOE complex
and from insights acquired in the development of DOE-STD-3009-2014, Preparation of Nonreactor
Nuclear Facility Documented Safety Analysis. The Handbook provides many application examples that
will be helpful to the analyst.
1.1 PURPOSE
The principal purpose of this Handbook is to guide development of the DSA safety analysis for nuclear
facilities in order to satisfy the requirements of a safe harbor method set out in 10 CFR Part 830, Subpart
B. The safety analysis process consists of three main steps:
• Hazard analysis (including hazard identification and evaluation);
• Accident analysis (including accident scenario definition and consequence analysis); and
• Preventive and mitigative control selection.
DOE-STD-3009-2014 provides criteria and guidance organized in the above manner. Further, it includes
lessons learned from use of DOE-STD-3009-94, Change Notice 3 (CN3), Preparation Guide for U.S.
Department of Energy Nonreactor Nuclear Facility Documented Safety Analysis, and other safe harbor
methods. Therefore, this Handbook uses excerpts from DOE-STD-3009-20142 as the starting point for
the amplifying guidance and good practices, but the scope of the Handbook is not limited to that standard.
The information in this Handbook is also relevant to other safe harbor methods for developing a safety
basis document, such as DOE-STD-3011-2016, Preparation of Documented Safety Analysis for Interim
Operations at DOE Nuclear Facilities, and DOE-STD-1120-2016, Preparation of Documented Safety
Analysis for Decommissioning and Environmental Restoration Activities. The Handbook may also be use
for upgrading existing DSAs to the new requirements of DOE-STD-3009-2014, or for updating DSAs for
existing facilities based on their current safe harbor methodology.
1.2 OUTLINE
This Handbook is organized as follows:
• Chapter 2, Hazard Analysis, addresses hazard identification and evaluation, including hazard
evaluation methods and safety control identification.
1 Code of Federal Regulations.
2 When used without a 2-digit or 4-digit year number after “DOE-STD-3009,” the term refers to both the 1994 and
2014 versions. If a specific version is meant to the exclusion of the other, the year will be stated.
DOE-HDBK-1224-2018
2
• Chapter 3, Accident Analysis, provides a high level overview of the events that were identified in
the hazard evaluation table to be evaluated for further accident analysis, provides an overview of
the accident analysis process, and discusses two key topics: (1) assumptions and initial
conditions; and (2) conservatism in analysis.
Section 21
• Chapter 4, Evaluation of Effects of Major Accident Types, addresses the analysis of accident
scenarios. The various topics covered provide information for evaluating the magnitude of the
accidents and the resulting accident environments, so that the amount of radioactive or other
hazardous material affected is defined. Toxic chemicals are a subset of hazardous materials that
require additional dispersion and consequence assessment. In addition to evaluation of potential
consequences to facility workers, this information is necessary to determine the source term
available for release from the facility, and to evaluate the capability of safety structures, systems,
and components (SSCs) to survive the accident environments and provide required safety
functions when called upon.
• Chapter 5, Source Term Analysis, addresses development of the amount of radioactive material or
toxic chemical released from a given confinement volume under the stress posed by insults from
a hypothetical accident. Source term estimations include quantifying radioactive or toxic
chemical material at risk, damage ratio, airborne release fractions or release rates, respirable
fractions (for radioactive materials only), and leakpath factor.
• Chapter 6, Atmospheric Dispersion, addresses atmospheric transport and diffusion,
meteorological data, and the models available for consequence assessment of radioactive releases
to the atmosphere.
• Chapter 7, Aquatic Dispersion and Groundwater Transport, addresses surface water and ground
water pathways, and the models available for consequence assessment of radioactive releases to
aquatic water bodies and ground water.
• Chapter 8, Radiological Consequence Assessment, addresses the different types of radiation and
the health effects they can have on the human body, its organs, and its tissues, and how
radiological doses to receptors of interest may be estimated.
• Chapter 9, Chemical Dispersion and Consequence Analysis, addresses toxic chemical releases,
their potential health effects and methods for estimating concentration at various distances.
• Chapter 10, Hazard Control Selection and Classification, addresses selection of safety significant
and safety class controls that are credited in the hazard evaluation or accident analysis.
• Chapter 11 provides a complete list of references cited in the text.
• Appendix A, Hazard Analysis Table Development, provides guidance on constructing this table
which is discussed in Chapter 2.
• Appendix B, Criticality Accidents, addresses this type of accident in greater detail.
DOE-HDBK-1224-2018
3
2 HAZARD ANALYSIS
This chapter addresses hazard analysis (HA) techniques for the identification and evaluation of hazards,
and the identification of controls to prevent or mitigate accidents. Hazard control selection is addressed
in Chapter 10.
2.1 ELEMENTS OF HAZARD ANALYSIS
DOE-STD-30093 states that an HA consists of (a) hazard identification, (b) hazard categorization,4 and
(c) hazard evaluation. Hazard evaluation includes identification and safety classification of controls to
prevent or mitigate potential hazard or accident scenarios.5
2.2 HAZARD IDENTIFICATION AND CHARACTERIZATION
Section 22
The objective of hazard identification and characterization is to systematically and comprehensively
identify radioactive and other hazardous materials within the facility, as well as natural phenomena
hazards (NPHs) and external man-made events that may impact the facility and result in the release of
these materials within the facility and to the environment. The hazard identification process includes
characterizing hazardous materials (radiological and non-radiological) and energy sources, in terms of
quantity, form and location. Examples of energy sources are falling objects, NPH-driven missiles, and
other kinetic energy sources. Nuclear Criticality Hazard Evaluations are addressed in Section 2.3.2.
For DSAs prepared in accordance with 10 CFR Part 830, Subpart B, the key to successful hazard
identification is ensuring comprehensive identification of the hazards associated with the full scope of
facility processes, associated operations such as handling of fissionable materials, radioactive or
hazardous wastes, and work activities covered by the DSA. Hazard identification does not yield specific
hazard scenarios to analyze. Rather, it yields initial data from which hazard scenarios are subsequently
developed. The overall quality of hazard scenario definition will be in direct proportion to the accuracy
and completeness of the initial hazard information gathered.
The hazard identification process involves:
• Hazard data gathering;
• Summarizing hazard data in tables or data sheets; and
• Identifying standard industrial hazards (SIHs) needing further evaluation.6
3 As discussed in Section 1.1, when used without a 2-digit or 4-digit year number after “DOE-STD-3009,” it refers
to both the 1994 CN3 and 2014 versions of the DOE Standard. Otherwise, specific versions of DOE-STD-3009 are
referenced throughout this Handbook.
4 This Handbook does not address hazard categorization. Requirements and guidance for performing hazard
categorization are provided in DOE-STD-1027-92, CN1.
5 DOE-STD-3009-2014 defines a “hazard scenario” as “An event or sequence of events associated with a specific
hazard, having the potential to result in undesired consequences identified in the hazard evaluation” and defines an
“accident” as “A specific event or progression of a sequence of events resulting from an initiating event that is
followed by any number of subsequent events that may lead to a release of radioactive or other hazardous material
and/or exposure to a predefined receptor.” The term “hazardous condition” has often been used in previous safety
basis hazard evaluations instead of “hazard scenario.” For the purposes of this Handbook, both terms are used
interchangeably in Chapters 2, 3, 4, and 10 and in Appendix A when referring to the hazard evaluation.
6 Such hazards might include electrical faults that could lead to a fire, or explosions harmful to nearby workers.
DOE-HDBK-1224-2018
4
Comprehensive identification of hazards is best accomplished by a team comprised of safety analysts,
system/process engineers, operational and support staff, industrial hygienists, and various subject matter
experts (SMEs), as needed.
2.2.1 HAZARD DATA GATHERING
Gathering of hazard data commences with review of existing documentation, which includes the
following:
Section 23
• Facility and process descriptions (including available drawings and flow sheets);
• Historical radioactive and hazardous material inventory records;
• Existing safety documentation;7
• Operating and support procedures;
• Previous occurrence reports for the facility and relevant reports from general industry; and
• Facility design reports setting out the scope of new operations.
Once documented sources of hazards have been reviewed, a physical walkdown of the facility is
undertaken to verify them and their locations. Such walkdowns are conducted with a floor plan noting the
most significant details. Useful details may include information such as gloveboxes or containers,
inventories and energy sources, system interconnections, and piping routes. Other details can be recorded
during the walkdown in checklists and notebooks for completeness. If the facility is being designed, the
floor plan can still be conceptually walked down using process and instrumentation drawings and process
engineering drawings at whatever stage of development they are available. Hazard analysis is performed
early in the project justification phase and during development of the Safety Design Strategy, continues
during development of safety design basis documents as the design progresses, and is updated during
development of the final DSA to authorize operations. If process and instrumentation drawings are based
on evolving design of a new facility, the hazard identification will need to be reverified against the final
design and as-built construction to support authorizing operations. The overall hazard identification and
analysis is an iterative process during the design and construction phase of the project.
2.2.2 HAZARD DATA RECORDING
Checklists are used to ensure the hazard identification process is comprehensive and thorough. Checklists
provide a generic list of hazards to look for in terms of radioactive and hazardous material types, energy
sources, moving components, and the potential for falling objects. Hazard identification preparers use
such checklists to systematically identify the presence or absence of hazards for a given area, from
individual components/operations (e.g., gloveboxes) to entire rooms.
The raw data of a hazard identification can be recorded in a variety of ways. The critical information to
be specifically noted in any recording mechanism is the hazard itself, its type, its magnitude and location,
and sufficient descriptive notes to allow the HA team to place individual hazards in an appropriate
context.
Materials of concern for release (or potential hazards in direct contact with materials of concern) are
identified separately. Bounding inventory values of radioactive or hazardous materials are needed for the
development of scenario-specific material at risk (MAR) for the hazard evaluation and accident analysis,
consistent with the maximum quantities of material that are stored and used in facility processes.
7 Safety data sheets (SDSs); waste data sheets; health and safety plans; procurement and inventory records; and
annual reports, such as the Emergency Planning and Community Right-to-Know Act, Tier II Chemical, and EPA
Toxic Release Inventory.
DOE-HDBK-1224-2018
5
Inventory data may be obtained from flowsheets, vessel sizes, contamination analyses, maximum
historical inventories, and similar sources.
Section 24
An example of a checklist for a DOE nuclear facility is shown in Table 2-1. The “Disposition” column is
optional and is discussed in Sections 2.2.3 and 2.2.4. Other types of checklists that have been developed
in the DOE Complex, and which may reflect site-specific and facility-specific hazards. These can be used
to identify hazards and energy sources. Commercial industry practices for hazard identification, such as
those described in the Center for Chemical Process Safety’s Guidelines for Hazard Evaluation
Procedures (CCPS, 2008), provide guidance for the development of a comprehensive identification of
hazards.
Table 2-1. Hazard Identification Checklist Example.
(Identify facility, location, or process)
No. Item
Hazard
present
(Y/N)
Description
(quantity, form, location)
Disposition
(SIH, accident
initiator/contributor)
1.0 Electrical
1.1 Battery banks
1.2 Cable runs
1.3 Diesel generators
1.4 Electrical equipment
1.5 Heaters
1.6 High voltage (> 600V)
1.7 Locomotive, electrical
1.8 Motors
1.9 Power tools
1.10 Pumps
1.11 Service outlets, fittings
1.12 Switchgear
1.13 Transformers
1.14 Transmission lines
1.15 Wiring/underground wiring
1.16 Other
2.0 Thermal
2.1 Boilers
2.2 Bunsen burners/hot plates
2.3 Electrical equipment
2.4 Electrical wiring
2.5 Engine exhaust
2.6 Furnaces
2.7 Heaters
2.8 Lasers
2.9 Steam lines
2.10 Welding surfaces
2.11 Welding torches
2.12 Other
3.0 Pyrophoric Material
3.1 Pu and U metal
3.2 Other (e.g., Zr)
4.0 Spontaneous Combustion
4.1 Cleaning/decontamination solvents
4.2 Fuels (gasoline, diesel)
DOE-HDBK-1224-2018
6
No. Item
Hazard
present
(Y/N)
Description
(quantity, form, location)
Disposition
(SIH, accident
initiator/contributor)
4.3 Grease
4.4 Nitric acid and organics
4.5 Paint solvents
4.6 Other
5.0 Open Flame
5.1 Bunsen burners
5.2 Welding/cutting torches
5.3 Other
6.0 Flammables
6.1 Cleaning/decontamination solvents
6.2 Flammable gases
6.3 Flammable liquids
6.4 Gasoline
6.5 Natural gas
6.6 Paint/paint solvent
6.7 Propane
6.8 Spray paint
6.9 Other
7.0 Combustibles
7.1 Paper/wood products
7.2 Petroleum-based products
7.3 Plastics
7.4 Other
8.0 Chemical Reactions
8.1 Concentration
8.2 Disassociation
8.3 Exothermic
8.4 Incompatible chemical mixing
8.5 Uncontrolled chemical reactions
8.6 Other
9.0 Explosive Material
9.1 Caps
9.2 Dusts
9.3 Dynamite
9.4 Electric squibs
9.5 Explosive chemicals
9.6 Explosive gases
9.7 Hydrogen
9.8 Hydrogen (batteries)
9.9 Nitrates
9.10 Peroxides
9.11 Primer cord
9.12 Propane
9.13 Other (e.g., NiCd batteries)
10.0 Kinetic (Linear and Rotational)
10.1 Acceleration/deceleration
10.2 Bearings
10.3 Belts
10.4 Carts/dollies
10.5 Centrifuges
10.6 Crane loads (in motion)
DOE-HDBK-1224-2018
7
No. Item
Hazard
present
(Y/N)
Description
(quantity, form, location)
Disposition
(SIH, accident
initiator/contributor)
10.7 Drills
10.8 Fans
10.9 Firearm discharge
10.10 Fork lifts
10.11 Gears
10.12 Grinders
10.13 Motors
10.14 Power tools
10.15 Presses/shears
10.16 Rail cars
10.17 Saws
10.18 Vehicles
10.19 Vibration
10.20 Other
11.0 Potential (Pressure)
11.1 Autoclaves
11.2 Boilers
11.3 Coiled springs
11.4 Furnaces
11.5 Gas bottles
11.6 Gas receivers
11.7 Pressure vessels
11.8 Pressurized system (e.g., air)
11.9 Steam headers and lines
11.10 Stressed members
11.11 Other
12.0 Potential (Height/Mass)
12.1 Cranes/hoists
12.2 Elevated doors
12.3 Elevated work surfaces
12.4 Elevators
12.5 Lifts
12.6 Loading docks
12.7 Mezzanines
12.8 Floor pits
12.9 Scaffolds and ladders
12.10 Stacked material
12.11 Stairs
12.12 Other
13.0 Internal Flooding Sources
13.1 Domestic water piping
13.2 Fire suppression piping
13.3 Process water piping
13.4 Other
14.0 Physical
14.1 Sharp edges or points
14.2 Pinch points
14.3 Confined spaces
14.4 Tripping
14.5 Other
15.0 Radioactive Material
Section 25
DOE-HDBK-1224-2018
8
No. Item
Hazard
present
(Y/N)
Description
(quantity, form, location)
Disposition
(SIH, accident
initiator/contributor)
15.1 Radioactive material
16.0 Hazardous Material
(Toxicological, Chemical,
Biological)
16.1 Asphyxiants
16.2 Bacteria/viruses
16.3 Beryllium and compounds
16.4 Biologicals/Biotoxins
16.5 Carcinogens
16.6 Chlorine and compounds
16.7 Corrosives
16.8 Decontamination solutions
16.9 Dusts and particles
16.10 Fluorides
16.11 Hydrides
16.12 Lead
16.13 Oxidizers
16.14 Poisons (herbicides, insecticides,
fungicides)
16.15 Other
17.0 Direct Radiation Exposures
17.1 Contamination
17.2 Electron beams
17.3 Radioactive material
17.4 Radioactive sources
17.5 Radiography equipment
17.6 X-ray machines
17.7 Other
18.0 Non-ionizing Radiation
18.1 Lasers
18.2 Other
19.0 Criticality
19.1 Fissile material
20.0 External Man-made Events
20.1 Aircraft crash
20.2 Explosion
20.3 Fire
20.4 Power outage
20.5 Transportation accident
20.6 Other
21.0 Vehicles in Motion
21.1 Airplane
21.2 Crane/hoist
21.3 Forklifts
21.4 Heavy construction equipment
21.5 Helicopter
21.6 Train
21.7 Truck/car
21.8 Waterborne Vehicle
21.9 Other
22.0 Natural Phenomena
DOE-HDBK-1224-2018
9
No. Item
Hazard
present
(Y/N)
Description
(quantity, form, location)
Disposition
(SIH, accident
initiator/contributor)
22.1 Earthquake
22.2 Flood
22.3 Lightning
22.4 Rain/hail
22.5 Snow/freezing weather
22.6 Extreme straight-line wind
22.7 Tornado
22.8 Tsunami, seiche
22.9 Volcanic ashfall
22.10 Other
An HA team safety analyst should work one-on-one with an individual SME and operations
representatives to fill out those parts related to the SME’s area of expertise and portions of the facility that
have been segmented into process or area nodes for analysis as discussed later in this chapter. The
multiple checklists from all the process or area nodes can be integrated into a complete draft of a hazard
identification table and presented to the HA team for review, or the checklist for each node can be
presented separately. Past experience has shown that this is a much more efficient way to complete the
exercise than to have the entire HA team meet to discuss every item for every process or area node.
2.2.3 HAZARD SUMMARY DEVELOPMENT
DOE-STD-3009-2014, Section 4.0, DSA Section [3.3.2.1], states that the hazard identification data sheets
(checklists) may be included in the DSA, or referenced as needed, and that a summary table that identifies
hazards by form, type, location, and total quantity be presented, as well as a summary of major accidents
or hazardous situations (e.g., fires, explosions, loss of confinement) that have occurred in the facility’s
operating history. The integrated checklist for the facility can be included in the DSA hazard
identification results section. The process or area node checklists can also be used to develop a summary
table to be included in the DSA. The range of information captured in the DSA hazard identification
table is designed to ensure that the minimum hazard identification results are established, appropriate
screening of hazards is performed, and information needed to perform an effective and efficient hazards
evaluation is established. Table 2-2 is an example Hazard Summary Table form for a facility.
DOE-HDBK-1224-2018
10
Table 2-2. Building XXX Hazard Identification Summary Table.
Hazard Type Location Form Quantity Remarks / Screening References
Radioactive
materials
Direct radiation
exposure
Section 26
Criticality
accidents
Hazardous
chemicals
(corrosives,
toxics, reactions)
Flammable/
combustible
materials
Explosive
materials
Electrical energy
Kinetic and
potential energy
Pressure-volume
Thermal energy
NPHs
Other
DOE-HDBK-1224-2018
11
These compilations of information reviews and facility walkdowns constitute initial information.
Iterations between the hazard identification and hazard evaluation phases are likely necessary in order to
ensure completeness.
2.2.4 EXCLUSION OF STANDARD INDUSTRIAL HAZARDS AND OTHER HAZARDOUS
MATERIALS
The comprehensive hazard identification process in Sections 2.2.1 through 2.2.3 addresses all radiological
and non-radiological hazards and energy sources. However, SIHs are not normally analyzed in a DSA
hazard evaluation, unless chemical and industrial hazards result in a release of nuclear material, or an
operator is incapacitated or prevented from taking credited action to prevent or mitigate a hazard scenario.
DOE-STD-3009-2014, Section 3.1.1 states:
Although the hazard identification process is comprehensive of all radiological and non-
radiological hazards, DSAs are not intended to analyze and provide controls for standard industrial
hazards such as burns from hot surfaces, electrocution, and falling objects. These hazards are
adequately analyzed and controlled in accordance with 10 C.F.R. Part 851, Worker Safety and
Health Program, and are analyzed in a DSA only if they can be an accident initiator, a contributor
to a significant uncontrolled release of radioactive or other hazardous material (for example, 115-
volt wiring as initiator of a fire), or considered a unique worker hazard such as explosive
energy. The basis for any identified hazards excluded from further evaluation shall be
provided. See Appendix A, Section A.1 of this Standard for further discussion on screening of
standard industrial hazards and Section A.2 for a discussion on screening out certain chemicals
based on low quantities or low hazard.
DOE-STD-3009-2014, Section A.1, provides the following SIH guidance:
The Department of Energy (DOE) recognizes, via Title 10 of the Code of Federal Regulations (CFR)
Part 830, the importance of including worker safety in safety analyses by specifically noting the
worker as a population of concern. Developing a conceptual basis for the methodology used in this
Standard requires answering the fundamental question of how worker safety is most appropriately
addressed in the DSA. DSAs include hazard analyses and hazard controls for worker safety, unless
the hazards and their potential consequences are due to standard industrial hazards.
Standard industrial hazards are hazards that are routinely encountered in general industry and
construction. These workplace hazards are addressed by provisions of 10 CFR Part 851, Worker
Safety and Health Program, which requires identification and assessment of worker hazards and
compliance with safety and health standards that provide specific safe practices and controls. Based
on these provisions, evaluation of standard industrial hazards within DSAs is needed to the extent that
these hazards act as initiators or contributors to accidents, or result from chemical or radiological
hazards (for example, when an explosion is caused by radiolysis inside a tank). When standard
industrial hazards are excluded from further evaluation, Section 3.1.1 of this Standard requires such
conclusions to be included in the hazard identification, along with the basis used for exclusion.
Section 27
Standard industrial hazards that may be considered for exclusion from the DSA hazard evaluation
include those in which a national consensus code and/or standard … defines and regulates appropriate
worker safety practices. Specifically, the codes and standards required by 10 CFR 851.23, Safety and
Health Standards, may be considered. Examples of hazards addressed by these requirements include
confined spaces, electrocution, falling objects, non-ionizing radiation, hot work, and lasers. Toxicity
of hazardous chemicals is addressed in Section A.2 rather than this subsection.
[Unique hazards …]
DOE-HDBK-1224-2018
12
Standard industrial hazards that have the potential to be an accident initiator involving chemical or
radioactive material releases are retained as part of the DSA hazard evaluation. For example, the
existence of 440-volt alternating current cabling in a glovebox could be identified as a potential
accident initiator of a fire involving radioactive or other hazardous materials.
The evaluation of hazards associated with “other hazardous materials,” and especially a subset involving
hazardous chemicals, warrants further discussion regarding which hazards can be screened out or
screened in. Some of these non-radiological hazards may be determined to be SIHs, while others may
require further evaluation in the DSA per 10 CFR § 830.204(b)(3) “that might contribute to the generation
or uncontrolled release of radioactive and other hazardous material.” One aspect of the “generation or
uncontrolled release of … other hazardous material” consideration is recognized in DOE-STD-3009-
2014, Section A.1, which states: “Toxicity of hazardous chemicals is addressed in Section A.2 rather than
this subsection” and is therefore not treated as a SIH. In addition to toxicity, other chemical hazards may
require further evaluation.
The introduction of DOE-STD-3009-2014, Section A.2 clarifies that not all chemical hazards (even those
that can cause serious injury or death) need to be evaluated in the DSA hazard evaluation:
The DSA is not intended to deal extensively with chemicals that can be safely handled by
implementation of a hazardous material protection program. Therefore, a screening process is
established to select for DSA evaluation only those chemicals of concern (i.e., type and quantity that
have the potential for significant health effect on the facility worker, co-located worker, or public) that
are present in the facility or activity and present hazard potentials outside the routine scope of the
hazardous material protection program.
The DSA hazard evaluation scope covers analysis of (a) hazardous chemicals affecting nuclear safety and
(b) in some cases, chemical hazards that are outside the scope of the facility’s hazardous material
protection program. The intent of DOE-STD-3009-2014 is to cover:
• radiation-related hazardous chemical events (examples: chemicals comingled with radiological
waste, chemicals generated through radiological processes, and chemicals generated or released
through processing of radioactive materials);
• nuclear safety-related hazardous chemical events (examples: events that affect a worker relied
upon for a credited action, events that affect safety-related SSCs through corrosion, fire, or
explosion); or
• unique hazardous chemical events, not addressed by 10 CFR Part 851, that could cause harm to
workers, the public or the environment.
Section 28
As an example of an excluded chemical hazard, consider a chemical supply tank in a nuclear facility that
has no interaction with radioactive material until the chemical is discharged into the nuclear process. The
chemical hazards presented by this tank, if they are routine and common in industry, should be screened
out of the DSA hazard evaluation as an SIH because 10 CFR Part 851 requirements will apply.
However, when a chemical is used in or generated by a nuclear process (i.e., interacting with nuclear
material), then such physical consequences from process accidents (e.g., over-pressurization) should be
evaluated in the DSA hazard evaluation. DOE-STD-3009-2014, Section 3.1.3.1 states:
Facility worker consequences, due solely to a standard industrial hazard, do not need to be categorized
in the hazard evaluation if screened out per Section 3.1.1. However, the evaluation of radiological or
chemical hazards that result in a prompt death or serious injury should be assigned a high consequence
DOE-HDBK-1224-2018
13
per Table 1. Examples of such hazards might include the generation of flammable/explosive hydrogen
gas by electrolysis of uranium in water or a spill of sodium hydroxide used in radioactive waste
processing.
Another chemical hazard not screened out is described in the DOE-STD-3009-2014, Section A.1 that
states: “Significant quantities of cryogenic material or compressed gases/liquids may also warrant
consideration because of asphyxiation hazards that might affect the ability of facility operators to safely
manage the facility. Such unique hazards are not treated as SIHs and are evaluated in the DSA.” Note
that the consideration is related to impacts on safely managing the facility. This situation would include
incapacitation of operators required to perform specific administrative controls affecting critical safety
functions.
In general, a chemical hazard should not be screened out if it affects a facility worker expected to perform
safety-related actions. Control room workers are in this category, as are operators expected to carry out
credited actions for a specific administrative control. DOE-STD-3009-2014, Section A.2 includes the
following example: “chemicals that may be excluded from the DSA’s hazard evaluation include …
chemical is not listed in OSHA or EPA toxic chemical regulations or is not assigned a PAC 2 or 3
value.”8 Regarding toxicity, impact on a facility worker is defined as being exposed to a chemical
concentration reaching Protective Action Criteria (PAC)-2 or PAC/TEEL-3 levels based on a qualitative
evaluation. Typically, PAC concentrations are evaluated over a 15-minute period. However for a
screening evaluation, a shorter time may be warranted if the worker becomes incapacitated due to the
chemical exposure in a shorter than 15-minute time frame.
Section A.1 of DOE-STD-3009-2014 describes situations that should not be screened out when
considering other unique hazards:
Unique hazards may be present in facilities that are not specifically addressed by the above exclusion
criteria, either because of quantities larger than typically used in general industry or because of unique
DOE applications or operations. Such hazards may represent a potential hazard to an entire work area
affecting multiple workers.
The intended distinction is to ensure analysis of “other hazardous materials” outside the scope of 10 CFR
Part 851 that could affect nuclear safety. If these unique hazards could impair or disable control room
operators or make uninhabitable entire rooms where nuclear operations are conducted, such hazards
should be evaluated in the DSA.
Section 29
DOE-STD-3009-2014 requires that “the basis for any identified hazards excluded from further evaluation
shall be provided.” Excluding a specific hazard or class of hazards should be accompanied by recording
the applicable code or standard and the relevant site safety management program for implementing the
code or standard. This basis may be included on the hazard identification table (see the “References”
column in Table 2-2), or for more complicated justifications, in the DSA hazard identification results
section. Either approach is suitable, as long as there is clear documentation of hazards screened out from
the hazard evaluation.9
8 See Section 9.3 for additional discussion of screening chemicals.
9 Many SIHs are evaluated in the hazard evaluation as an initiator or contributor to a radioactive or other hazardous
material release, which should be acknowledged somewhere in the hazard identification results section.
DOE-HDBK-1224-2018
14
2.3 INITIAL HAZARD EVALUATION DEVELOPMENT
2.3.1 OVERVIEW
Hazard evaluation is the starting point for control set selection to prevent or mitigate potential hazardous
conditions (or hazard scenarios as defined in DOE-STD-3009-2014) that could result in undesirable
consequences, and for the subsequent quantitative accident analysis. The definitions section of DOE-
STD-3009 states that the hazard evaluation portion of a hazard analysis includes an examination of “the
complete spectrum of potential accidents that could expose members of the public, onsite workers, facility
workers, and the environment to” radioactive and other hazardous materials. The DSA hazard evaluation
provides: (a) an assessment of the facility hazards associated with the full scope of planned operations
covered by the DSA, and (b) the identification of engineered and administrative controls that can prevent
or mitigate these hazards or hazardous conditions. It analyzes normal operations (startup, facility
activities, shutdown, and testing and maintenance configurations) as well as abnormal and accident
conditions. In addition to the process-related hazards identified during the hazard identification process,
the hazard evaluation also addresses NPHs and man-made external events that can affect the integrity of
an SSC. DOE-STD-3009-2014, Section 3.1.3 provides requirements and guidance on how hazard
evaluations are to be performed for DOE nuclear facilities.
The initial hazard evaluation is accomplished by the following steps:
1. Define the scope of the HA. This scope can vary from a single process in a single room to an
entire facility with multiple processes. Evaluation of the entire facility may be more efficiently
performed by dividing it into smaller process or area nodes. The scope of activities to be
evaluated by the analysis includes any activities that can occur when significant quantities of
hazardous materials are present. These activities include (a) DSA-authorized processes and
experiments in the facility, (b) off-shift activities, and (c) any hazard associated with maintenance
and support activities that can occur when significant quantities of hazardous materials are
present. (Quantities are significant if they can cause injury, for example, as related to
asphyxiation in DOE-STD-3009-2014.) Physical boundaries, process/support system interfaces,
and interfaces with other facilities need to be defined.
2. From the hazard identification results, evaluate hazards associated with authorized activities,
man-made external events, or NPHs. Develop a comprehensive list of postulated hazard
scenarios.
Section 30
3. From the hazard identification results, evaluate radioactive and other hazardous materials and
energy sources to determine possible interactions that could lead to accident conditions.
4. Evaluate circumstances such as equipment failures, process material hazards and failure of
barriers, and mission activities that could affect the initiation and progression of the accident
conditions.
5. Review applicable safety documentation, process history, occurrence reports, and other
information sources to identify postulated or historical hazardous conditions and accidents
associated with the facility.
DOE-HDBK-1224-2018
15
All activities within the facility boundaries are considered in the analysis. The HA team defines where
these boundaries, or process or area nodes, start and stop. Considerations include:
• Do activities start at the door of the facility, at the loading dock, or at an outside staging or
storage area?
• If two facilities share common space, at what point does one facility analysis start and the other
stop?
• Do immediately adjacent facilities pose hazards such as toxic materials?
• Are any hazards associated with the process or area nodes or facility boundaries that may warrant
consideration of controls?
Following this initial evaluation, the process continues with the documentation of hazardous conditions
and selection of unmitigated hazard scenarios based on potential interactions between hazardous materials
and energy sources.
Typical hazards commonly associated with DOE nonreactor nuclear facilities are identified in Table 2-3.
The table provides a suggested causal correlation between hazardous energy and material sources and
potential accident types or categories.10 Hazards identified in Table 2-3 do not always result in an
accidental release of radioactive or other hazardous material required to be evaluated by DOE-STD-3009.
Table 2 3. Correlation of Hazardous Energy and Material Sources to Accident Types/Categories.
Accident Category* Hazard Energy and Material Source Groups
FR-1: Fire Electrical Open Flame
Thermal Flammables
Friction Combustibles
Pyrophoric Material Chemical Reaction
Spontaneous Combustion
EX-2: Explosion Potential (Pressure)
Explosive Materials
Chemical Reactions
LC-3: Loss of Confinement/Spills Radioactive Material Toxic Chemical
Other Hazardous Material Chemical Reaction
DE-4: Direct Radiological
Exposure
Ionizing Radiation Sources
CR-5: Nuclear Criticality Fissile Materials
EE-6: Man-made External Events Non-Facility Events (e.g., aircraft crashes)
Vehicles in Motion
Cranes
NPH-7: Natural Phenomena Hazards NPH Events - Seismic, Extreme Wind, Flood, Lightning, Extreme
Precipitation, Volcanic Ashfall
*The number assigned to the accident categories is for ease of data management, and any numbering scheme
could be used if deemed necessary.
10 A similar correlation is provided in DOE-STD-5506-2007, Preparation of Safety Basis Documents for
Transuranic (TRU) Waste Facilities, Table 3.2-1, Hazard Sources and Potential Events.
DOE-HDBK-1224-2018
16
A graded approach as defined in 10 CFR §830.3 and DOE-STD-3009 should be applied to the selection
of hazard evaluation techniques and developing the hazard evaluations. The selection of techniques is
based on several factors, including the complexity and size of the operation being analyzed, the type of
operation, and the inherent nature of hazards being evaluated. A discussion of hazard evaluation
techniques and recommendations can be found in Part I of CCPS, 2008, especially Chapters 4 and 5.
Section 31
2.3.2 NUCLEAR CRITICALITY HAZARD EVALUATION
A criticality accident represents a special case for hazard evaluation. The criticality safety program
requirements11 are derived from the HA process established in the American National Standards
Institute/American Nuclear Society (ANSI/ANS)-8 series of national standards (e.g., ANSI/ANS-8.1,
Nuclear Criticality Safety in Operations with Fissionable Material Outside Reactors). These standards
require a documented nuclear criticality safety evaluation demonstrating that operations with fissionable
material remain subcritical under both normal and credible abnormal conditions. Criticality safety
evaluations provide the technical basis for controls to prevent or mitigate criticality accidents. The
ANSI/ANS-8 series requirements do not apply to critical assemblies or similar operations.
Section 3.1.3.2 of DOE-STD-3009-2014 provides requirements on what to include in the DSA hazard
evaluation of criticality accidents, while Section 3.3.4 provides requirements on safety classification of
criticality safety controls. Experience shows that only a few evaluations of criticality accident scenarios
for a facility may need to be included in the qualitative hazard evaluation. Appendix B provides guidance
on the magnitude and consequence analysis of criticality accidents and the estimation of fission product
yield and particulate source terms.
2.3.3 CHEMICAL HAZARD EVALUATION
As discussed in Section 2.2.4, chemical hazards are screened to determine the need for further hazard
evaluation. However, per DOE-STD-3009-2014, Section A.2, chemicals “that could otherwise be
screened out, but have the potential to be an accident initiator involving radioactive or hazardous material
releases, or could compromise the ability of the facility operators to safely manage the facility, are
retained as part of the DSA hazard evaluation.” Chemical properties such as reactivity, toxicity, and
incompatibility with other chemicals are thus included in the hazard evaluation.
Qualitative evaluation of toxic chemical consequences using any of the hazard evaluation techniques
discussed later in this chapter is generally sufficient to provide a basis for comparison to consequence
thresholds of interest for the selection of safety significant (SS) controls (i.e., serious injuries, fatalities, or
significant chemical exposure).
However, for some situations, further quantitative analysis of consequences is necessary for control
selection. 12 Later chapters of this Handbook will provide guidance on quantifying chemical source
terms (Sections 5.3 and 9.5) and dispersion analyses to estimate concentrations to receptors (Chapters 6, 7
11 Criticality safety program requirements are established in DOE O 420.1C. This Order states that DOE-STD-
3007-2007, Guidelines for Preparing Criticality Safety Evaluations at Department of Energy Nonreactor Nuclear
Facilities, is the required method for performing criticality safety evaluations, unless DOE approves an alternate
method. An update to that Standard has been issued in DOE-STD-3007-2017, Preparing Criticality Safety
Evaluations at Department of Energy Nonreactor Nuclear Facilities, which will be invoked in a revision to DOE O
420.1C.
12 For example, see DOE-STD-3009-2014, Section 3.2.3.3 and Section A.2 for further information for evaluation of
the toxicity hazard and determination of concentrations for the co-located worker (CW) at 100 m and maximally-
exposed offsite individual (MOI).
Section 32
DOE-HDBK-1224-2018
17
and 9). However, selection and application of appropriate source term and dispersion methods for
evaluation of chemical hazards will need to consider special situations such as chemical reactions,
chemical transformations in the plume, or heavier-than-air plume modeling.
2.4 HAZARD EVALUATION METHODS
2.4.1 COMMERCIAL INDUSTRY METHODS AND DSA HAZARD EVALUATIONS
Chapter 4 of CCPS, 2008 describes twelve methods that can be used in a hazard evaluation. The
discussion is oriented toward the chemical industry, but the basic strengths and weaknesses of each
method are generally applicable for the DSA hazard evaluation. The following sections discuss four of
these methods as applied to several facilities described in DOE-HDBK-3010-94, Airborne Release
Fractions/Rates and Respirable Fractions for Nonreactor Nuclear Facilities, Appendix B.
None of these industry hazard evaluation methods were designed to generate a DSA hazard evaluation
and do not yield hazard scenarios, nor were they designed to identify SS and safety class (SC) SSCs or
specific administrative controls (SACs). Those results are uniquely defined for DOE usage to develop a
DSA. Thus, one does not normally see the raw information generated from the industry hazard evaluation
in a DSA; however, it is a necessary step to developing hazard scenarios. The hazard evaluation is
performed to understand facility vulnerabilities and potential hazard scenarios. Those insights are then
distilled into a DSA hazard evaluation table and are used for safety classification of controls and
derivation of TSRs.
The common methods utilized vary in both complexity and focus. Each method has strengths and
weaknesses, and depending on the scope of the HA, multiple HA methods may be used. For example, the
Hazard and Operational Analysis (HAZOP) methodology is effective for analyzing a chemical process
within a facility, but the “What-If” methodology is better suited for evaluating NPH and man-made
external events with the potential to affect the entire facility.
2.4.2 METHOD #1: WHAT-IF?
The “What-If” method is a loosely-structured, brainstorming technique commonly used in the DOE
complex by itself or in combination with other hazard analysis techniques such as Process Hazard
Analysis (PrHA). As with any other hazard analysis method, the analysis typically is organized by
facility operations, process, or activity location (e.g., a production support laboratory). Analysts utilizing
this method formulate a series of questions, each beginning with the phrase “What if…?” for each process
or activity. An example might be “What if the liquid tank in the support laboratory overflows?”
The hazard evaluation would discuss ways in which the tank might overflow (e.g., initiators and overall
event progression sequences), the potential consequences of overflow, what preventive and mitigative
control responses are available, and what additional measures may be recommended for consideration.
The extent of the discussion is based on increasing potential consequences. If the liquid in question is
simply water with trace contamination or less harmful chemicals, the discussion will reach resolution
much more rapidly than if the liquid is radioactive or a highly volatile, toxic substance.
Section 33
To provide proper structure for comprehensive results, the examination progresses in an organized
manner, from the beginning of the activity/operation to the end. Well-designed checklists can provide
additional structure that limits the potential for important events to be missed. This approach combines
the “What-If” method with the simplest method for hazard evaluation that is a checklist that identifies
already-known or understood hazards such as fires and explosions and can be augmented with specific
design information. Furthermore, while a variety of potential outcomes can be identified, it is important
DOE-HDBK-1224-2018
18
to identify the ultimate consequence that is physically plausible. Analysts should not stop with the
assumption that a given control will function. To do so can result in failure to identify vulnerabilities, and
is also inconsistent with DOE’s stated intent for unmitigated analyses.
The strengths of the “What-If” method include broad applicability, ease of use, and its adherence to
natural thought processes. Weaknesses include a greater potential for neglecting interaction issues and
for missing some events altogether. Another weakness of the What-If analysis is that many scenarios
identified may result in no or insignificant consequences; thus, creating a large number of scenarios of no
interest to the DSA process. A modified What-If analysis has also been used to identify scenarios with
significant consequence potential for further analysis. Further analysis may include the DSA-required
evaluation of the frequency, consequence, and risk for such scenarios of interest, or combining the results
of the What-If analysis with other hazard analysis techniques, such as Process Hazard Analysis (PrHA).
The quality of “What-If” results can vary significantly based on the experience of the individual leading
the team effort. Generally, “What-If” analysis is most suited to simple operations and activities where the
potential end states of each step are discrete and easy to identify. Manual operations/activities are often
ideal for “What-If” analysis.
The H-21 TRU Waste Facility and the H-7 Production Support Lab discussed in DOE-HDBK-3010-94,
Appendix B illustrate examples of facilities amenable to a “What-If” analysis. The common feature of
these facilities is that they do not have complex processes. They consist of discrete, manual operations
with well-defined interaction boundaries.
Consider the liquid sampling glovebox in the Production Support Lab. It is a non-complex operation
where a laboratory operator analyzes 20 ml sample vials. A simple walkdown of the process generates
obvious “What-If” questions as shown on Table 2-4.
Table 2-4. “What-If” Hazard Analysis Example H-7 Production Support Lab.
“What if…?” Possible Consequences
1. …a collection of vials is dropped while being
entered into the glovebox?
1. Broken vials, small Pu airborne release, minor
worker exposure.
2. …the sample recycle bottle is dropped while
coming out of the glovebox?
2. Spill, small Pu airborne release, minor worker
exposure.
3. …liquid is spilled within the glovebox? 3. See #1 and #2 above, without direct worker
exposure potential.
4. …the sample recycle bottle is overfilled (i.e., double
batch of high concentration of fissile solution)?
4.a. Criticality Safety Evaluation shows large margin
= no issue
or
4.b. Criticality Safety Evaluation shows limited
margin = potential criticality event
Section 34
5. …the glovebox inventory of hexone solvent ignites? 5.a. Potential glovebox confinement breach
and/or
5.b. airborne Pu release (larger release potential than
spill)
6. …more samples are brought into the glovebox than
its allowable storage spaces?
6. No specific consequence (potential deviation in
operational practice that should be evaluated).
7. …planchettes are dropped outside of glovebox 7. No significant consequence (quantities of material
are too small)
DOE-HDBK-1224-2018
19
The above list is not exhaustive, but demonstrates the basic concept. This questioning process would be
repeated for each of the specific operations and general activities authorized in the facility. The resulting
complete set of questions and answers would then be combined and amplified as necessary to generate
specific hazard scenarios in the DSA hazard evaluation table. For example, if the potential exposure
consequences are sufficiently limited, all liquid spills might be combined into one representative hazard
scenario. Or, if only one or two of the liquid spill scenarios could pose significant exposure potential,
those would be documented as individual events.
Care should be exercised when combining scenarios. There should be no attempt to combine scenarios
until potential controls are identified. The considerations to determine if scenarios should be combined
include identifying that proposed controls are either bounded or are the same for all bundled scenarios. In
the hypothetical case presented in the previous paragraph, suppose one distinct spill with significant
consequences is combined with all other spills. The hazard evaluation would then identify any credited
controls for one scenario as applying to all glovebox liquid handling operations.
Dissimilar scenarios cannot be combined. For example, fires and spills should not be artificially
combined into one event because they have differing consequences, separate initiators, and unlike
controls. The required clarity of the analysis of the most important preventive and mitigative controls
will be lost if these dissimilar scenarios are combined. Bounding scenarios is primarily a function of their
controls. The example above only illustrates the identification of “what if” questions (which may help
define initiating events or scenarios) for a single operation, and the associated possible consequences. It
may not define a complete set of initiated events or define completely an accident scenario, nor include
the controls to prevent or mitigate such scenarios.
2.4.3 METHOD #2: HAZARD AND OPERATIONAL ANALYSIS
This method, abbreviated “HAZOP,” is designed to investigate chemical process and complex system
performance requiring a more methodical approach to ensure completeness, which cannot be effectively
accomplished with the “What-If” technique. It requires a significantly greater investment of time and
resources than a “What-If?” analysis because team members are required to identify and assess the
significance of system malfunctions or improper operations at each step of a process using a highly
formal, systematic approach.
The HAZOP method first divides a process or system into discrete sections (defined as process or system
nodes), with the intent or function of each section being well-defined. Figure 2-1 illustrates the complete
HAZOP method, after defining the process or system nodes.
Figure 2-1. HAZOP Method Overview
DOE-HDBK-1224-2018
20
Section 35
The method then examines deviations in hardware and those caused by human interactions (such as those
that occur during maintenance and operations) from design conditions by systematically combining each
parameter of interest for the process or system with guide words. Examples of parameters include flow,
pressure, temperature, composition, and even more conceptual items such as containment. Examples of
guide words include “no, more, less, high, low, as well as, partial, reverse, wrong type, sooner than, later
than, breach.” A HAZOP deviation matrix can be built to describe the evaluation criteria corresponding
to a guide word for a given process or system parameter as illustrated in Figure 2-2.
Figure 2-2. HAZOP Deviation Matrix
For example, the HAZOP team might start examining a process or system section by first identifying a
parameter such as flow and the guide word “None”, and postulating a deviation of “no flow.” They
would then identify the causes of no flow, qualitatively define the consequences of no flow, and what
safeguards or controls are available or may be recommended for consideration, or other action items that
may require further investigation. When significant consequence potential is identified, it is important to
trace causality back to previous sections examined if the deviation of interest originates there. For
additional perspective, consequence, likelihood, and risk rankings may be assigned to each of these
significant deviations/cause conditions, or that may be accomplished in a subsequent DSA hazard
evaluation. The team subsequently proceeds to other guide words for the selected parameter, such as
“low flow,” followed by “high flow” and so on. This procedure yields an understanding of the integrated
process or system behavior, as opposed to simply focusing on the discrete behavior of isolated
components.
The HAZOP method brings to bear considerable structural rigor. It breaks down the entire process or
system into a large number of discrete sections (pipe runs from Point A to Point B and individual vessels)
and goes through a repetitive exercise to examine deviations in significant detail. Most deviations will
not, in fact, involve any significant vulnerabilities, one reason that HAZOPs for large processes or
systems are conducted over multiple days. The exercise simply takes time. Attempting to move swiftly
through it tends to create an overload effect that defeats the purpose of this method.
The strengths of the HAZOP method are thoroughness enforced by structural rigor, focus on small details,
adaptability to almost any process or activity, and generation of an organized evaluation record as an
intrinsic part of the method. HAZOP also forces participants to properly define the process or activity at
a detail level prior to beginning. Weaknesses include the fact that HAZOP is much more time and
resource intensive than other methods. It is also vulnerable to poor initial organization. HAZOPs
generally represent overkill for simple processes and predominantly manual activities, but are ideal for
more complex processes, where the sheer magnitude of the potential deviations can overwhelm a “What-
If” examination. Another weakness of the HAZOP method is that since it is focused on processes or
DOE-HDBK-1224-2018
21
systems, and their deviations, it often can miss more generic hazard scenarios such as external and natural
phenomena events, or those not associated with process or facility systems.
Section 36
Table 2-5 presents a HAZOP example for the Metal Dissolution Process described in DOE-HDBK-3010-
94, Appendix B for the Plutonium Recovery Facility. This portion of the HAZOP evaluates a node
defined by piping from the heat exchanger to the spray chamber as shown in Figure B.8 of DOE-HDBK-
3010-94. The parameter examined is “Flow.” Compared to the previous “What-If” examples, the
rigorous and repetitive nature of the method is clear. “What-If” relies on the ability and experience of the
analysts to ensure completeness; HAZOP relies more on the method’s formal structure.
DOE-HDBK-1224-2018
22
Table 2-5. HAZOP Example.
Note: Piping from Heat Exchanger to Spray Chamber (as shown in DOE-HDBK-3010-94, Figure B.6).
Parameter Deviation
(guide
word)
Cause Consequence Safeguards or Controls Likelihood Consequence Risk Comments/Actions
Flow No 1. Pump not working
2. Heat exchanger
outlet valve
incorrectly positioned
3. In-line filter
clogged
Operational Return line flow meter,
Temperature sensors
Safe Condition:
Dissolution reaction
ceases without fresh acid
flow
Unsafe Condition:
Potential to pressurize
heat exchanger
Flow No 1. Piping rupture Plutonium
solution spill
Glovebox, Glovebox
ventilation, Critically safe
drainage basin, Room air
monitor, Room ventilation
Flow Low 1. Piping leak Plutonium
solution spill
Glovebox, Glovebox
ventilation, Critically safe
drainage basin, Room air
monitor, Room ventilation
Flow High 1. Pump output
excessive
2. Heat exchanger
outlet valve
incorrectly positioned
Temperature
transient (more
flow is heated
less)
Temperature sensor on slab
tank, Steam inlet control,
Return line flow meter,
Hydrogen detector, Shutdown
interlocks, Air sparge
Unsafe Condition: More
flow maximizes reaction.
Unsafe Condition: Low
acid temperature can
yield undesired hydride
sludge.
Flow Wrong 1. Steam inlet off
with heat exchanger
leak
Plutonium
solution enters
heat exchanger
condensate
Condensate collected in
Raschig ring tank, Condensate
samples
Action: Verify sampling
frequency
DOE-HDBK-1224-2018
23
As noted previously, the traditional HAZOP table is not an example of the hazard evaluation table
expected in an actual DSA, but with modifications as suggested in Table 2-5, it may be suitable. The
HAZOP identifies process vulnerabilities and interactions from which a set of hazard scenarios are
usually derived for the DSA hazard evaluation table. For example, a runaway exothermic reaction
generating hydrogen is an event that would be expected in the DSA hazard evaluation table.
Depending on the HAZOP results, there could be multiple entries for the same event to identify different
progression paths, some of which would be of concern, while others may not. Alternatively, one entry
could cover all potential progression paths; however, all paths should still be assessed to determine which,
if any, warrant specific control. Example outcomes include:
1. The hydrogen detector and shutdown interlock is adequate to credit for all scenarios; or,
2. An individual control in a specific progression path may require crediting as well, either due to
the high likelihood of that progression path or its ability to minimize the effect of the hydrogen
detector and associated interlocks.
These methods were not developed to credit SSCs. They are intended to address problems that may arise
when deviations from design conditions occur. The method (or any HA method) may uncover safety
issues to be further evaluated.
Section 37
2.4.4 METHOD #3: FAILURE MODES AND EFFECTS ANALYSIS
The failure modes and effects analysis (FMEA) is a flexible tool for examining equipment, a process, or
system failures (in this section, “system” also includes equipment or a process). It is particularly suitable
for characterizing the performance spectrum associated with individual component failures within the
system. Thus, it is ideal for identifying all potential failure modes for systems of interest typically of
moderate complexity. In some cases, the impact may not just be the failure of the system to perform its
intended function, but could result in an accident condition of interest, such as an explosion in a process
line.
The analysis proceeds as follows:
• Identify the major components (example: detectors);
• Identify the systems using these components (example: ventilation);
• Identify all failure modes for each component (high, low, loss of signal);
• Identify the effects of component failures on the systems.
Finally, for system consequences of interest, such as failure of the system to perform its function or an
accident of concern, the controls or safeguards to prevent such failures are identified.
FMEA equipment failures. As indicated, FMEAs are ideal for evaluating system failure modes, but are
not well-suited to supporting the identification of process hazard scenarios. FMEAs also lack the structure
to examine process upsets (e.g., reverse flow, process chemistry deviations) as initiators. Inexperience
with using the method can also lead to an excessively narrow focus on individual failures as opposed to
integrated process behavior. Therefore, because the FMEA is narrowly focused, it is usually applied in
combination with other techniques such as fault tree analysis to provide a more detailed understanding on
how a system could fail.
Table 2-6 shows an application of the FMEA method to the Metal Dissolution Process evaluated in Table
2-5 for flow from the heat exchanger to the spray chamber through a pipe. The component and the failure
modes of interest within this process is those associated with the hydrogen detector.
DOE-HDBK-1224-2018
24
Table 2-6. FMEA Example.
Process: Metal Dissolution Line Component: Hydrogen Detector
Failure
Mode Effect Safeguards Comments/Actions
Fails
high
Generates premature
process shutdown for low
H2 concentration. Fails
safe
Indication on operational
console, Shutdown
interlock.
Fail safe: None
Fails low Failure to generate process
shutdown, when required,
leading to unsafe
conditions (e.g., a
potential for exothermic
reaction and hydrogen
explosion)
Indication on operational
console, Spray chamber
temperature sensor (also
feeds shutdown
interlock), Temperature
indications on
operational console
Potential accident of concern
Increased hydrogen concentrations are
generally accompanied by higher
temperatures. A runaway exothermic
reaction would still yield a shutdown.
However, conditions short of that could
yield H2 concentrations in excess of the
shutdown limit.
Fail as is Failure to generate process
shutdown when required
See “Low Failure Mode”
See “Low Failure Mode” Potential accident of concern
See “Low Failure Mode”
comments/actions
Loss of
Power
Triggers shutdown
interlock
Indication on operational
console, Shutdown
interlock.
Fail safe: None
Signal to
Interlock,
Mode A
Triggers shutdown
interlock
Indication on operational
console, Shutdown
interlock.
Fail safe: None
Signal to
interlock,
Mode B
Section 38
Failure to generate process
shutdown when required
See “Low Failure Mode”
Effects
See “Low Failure Mode”
safeguards
Potential accident of concern
See “Low Failure Mode”
comments/actions
2.4.5 METHOD #4: EVENT TREES AND FAULT TREES
Event trees and fault trees are formal logic constructs designed to document progression paths for an
event. Event trees utilize inductive reasoning while fault trees utilize deductive reasoning. These two
tools can be combined in a formal quantitative or probabilistic risk assessment, but such an assessment for
an entire facility or process is not typical when evaluating DOE nonreactor nuclear facilities. Event trees
and fault trees are normally used in DSAs as support tools to illuminate a specific issue of interest.
Inductive reasoning is often characterized as a “bottom-up” analysis since it starts with a specific premise
and moves toward a general conclusion. An event tree correspondingly starts with a specific initiating
event and moves toward a broad collection of potential outcomes. Regarding DSA hazard analysis, this
approach results in event sequences with varying consequences in terms of radiological release potentials,
based on the success and failure of any preventive controls that may terminate the event or mitigative
controls that may reduce the consequences. A simple example of an initiating event might be “loss of
cooling water to a furnace.” Every action that can result from that event then forms a decision point from
which multiple possible outcomes branch. For example, suppose Alarm A is supposed to sound to
generate an operator response if cooling flow is lost. The first decision point is therefore “Alarm A
functions.” Two branches stem from that point: (a) if alarm A functions, the progression moves to a
decision point labeled “Operator responds;” (b) if Alarm A does not function, operator response is
initially bypassed and the resulting branch moves to a different decision point. The end result is a
DOE-HDBK-1224-2018
25
complete spectrum of outcomes, from successful to unsuccessful to catastrophic, which are characterized
in terms of actions and controls associated with their progression. Each individual path through this event
tree represents a separate event sequence. Thus, the minimum cut sets that yield failure of the system or
its safety function can be defined. Event trees graphically depict the relationship between an initiating
event and controls; thus, defining ranges of potential scenarios, their frequencies, and potential
consequences based on the response of credited controls. Event trees, as well as fault trees, are typically
used to support accident analyses and are not necessarily elevated to the DSA.
Deductive reasoning is often characterized as a “top-down” analysis since it uses general premises to
arrive at a specific conclusion. A fault tree thus begins with the undesired end state as the top event such
as a specified consequence of a potential accident and analyzes equipment failures and human errors that
cause the top event. Such end states have often been identified by application of other hazard evaluation
methods. For demonstration purposes, a simple example of an undesired end state is “the car does not
start.” The next step down in the fault tree lists the immediate causes such as starter motor failure, spark
plug failure, and lack of gas in the cylinder. The next step down lists all the potential causes for each
immediate cause: no gas in supply tank, failure of the fuel pump, fuel line leak. These potential failure
mechanisms are joined by “AND” or “OR” gates depending on whether multiple mechanisms (A “AND”
B) are needed to cause the failure above or if a single mechanism (A “OR” B) suffices. This process ends
either in basic occurrences that cannot be subdivided further or at a predetermined evaluation boundary.
Again, the minimum cut sets that yield failure of the system or its safety function can be defined.
Section 39
The strengths of this approach includes logical rigor, recording of results in a branch structure as the
evaluation occurs, and direct support of numerical estimation of likelihood of the postulated significant
consequences. Weaknesses include a tendency toward tunnel vision if the failure mode or safety function
of interest is not precisely defined, as well as a significant resource and time investment to generate
integrated results.
2.5 INITIAL DEVELOPMENT OF A DSA HAZARD EVALUATION TABLE
The commercial industry hazard evaluation methods previously discussed evaluated process upsets,
equipment failures, human errors, and potential safety features. Table 2-7 shows how similar hazard
studies can be used to start development of a hazard evaluation table for the DSA, based on an example of
a vehicle collision plus fire involving TRU waste containers which has often been evaluated using the
“What-If” method.
DOE-HDBK-1224-2018
26
Table 2-7. Initial Development of Hazard Evaluation Table.
Event
No. Event Description Initiators Preventive Features Mitigative Features
FR-1 Fuel powered vehicle suffers a
fuel leak due to an impact with
TRU waste drums in the
Shipping/Receiving Area and is
ignited. A forklift carrying a
single pallet with four drums
impacts a stack (two high) of
palletized drums with moderate
to severe stress causing breach
with material spill of 12 drums
and ensuing pool fire that
involves 88 additional drums in
the Shipping/ Receiving Area.
MAR: xx alpha curies in 100
drums
(DOE-STD-5506-2007 statistical
MAR distribution for Waste
Isolation Pilot Plant complaint
containers applied, see Table
yy)
INITIAL CONDITIONS:
Staging area inventory limit;
TRU waste in metal containers;
Metal pallets.
• Operator error
• Equipment
malfunction
• Vehicle impact
with fuel spill
• Ignition of
combustible
and/or flammable
materials
• Lightning
• Wildland fire
SSCs:
Concrete vehicle barriers.
Waste staging building
foundation.
ADMINISTRATIVE:
Procedures and Training
Program (Forklift
Operator training);
Vehicle maintenance
program;
Fire Protection Program:
• Combustible controls
Waste handling
operations curtailed
outdoors during
inclement weather;
Movement of waste is to
be accomplished using
electric or manual
powered equipment;
Fuel exclusion zone in
the Shipping/Receiving
Area.
SSCs:
None
ADMINISTRATIVE
Procedures and
Training Program
(workers trained to
evacuate);
Emergency
Preparedness
Program
(emergency
response
activities).
Control identification occurs as part of the initial hazard evaluation development and is recorded in the
hazard evaluation table as shown in Table 2-7. At this stage of developing the hazard evaluation table, all
preventive and mitigative controls are listed that are available, or can be readily implemented, to
demonstrate defense in depth as described in DOE-STD-3009.
2.6 LIKELIHOOD, CONSEQUENCE, AND RISK METHODS
The next step of the DSA hazard evaluation is to perform a qualitative estimate of the unmitigated
consequences, likelihood, and optionally, risk ranking of the hazard scenarios. The following subsections
present methods for these evaluations.
2.6.1 QUALITATIVE CONSEQUENCES
2.6.1.1 RECEPTOR CONSEQUENCE LEVELS
Table 2-8, reproduced from DOE-STD-3009-2014, Table 1, provides three qualitative consequence
thresholds (bins) to estimate potential effects on facility workers, CWs, and the public (i.e., MOI).13
High, moderate, and low consequence levels are quantitatively defined for the offsite public and CWs.
High consequence levels are qualitatively established for facility workers consistent with DOE-STD-3009
Section 40
13 These bins are similar to consequence level thresholds defined in DOE-STD-3009-94, CN3.
DOE-HDBK-1224-2018
27
guidelines for a significant worker consequence. Moderate and low consequence levels are not defined
for facility workers, because qualitative analysis would not yield results that provide a meaningful
comparison to a distinguishable threshold.14
Table 2-8. Consequence Thresholds.
Consequence Level Public1,4 Co-located Worker2,4 Facility Worker3
High
≥25 rem TED5
or
≥PAC6-2
≥100 rem TED
or
≥PAC/TEEL-3
Prompt death, serious
injury, or significant
radiological and chemical
exposure.
Moderate
≥5 rem TED
or
≥PAC/TEEL-1
≥25 rem TED
or
≥PAC/TEEL-2
No distinguishable
threshold
Low
<5 rem TED
or
<PAC/TEEL-1
<25 rem TED
or
<PAC/TEEL-2
No distinguishable
threshold
1 MOI - A hypothetical individual defined to allow dose or dosage comparison with numerical criteria for the public. This
individual is located at the point of maximum exposure on the DOE site boundary nearest to the facility in question (ground
level release), or may be located at some farther distance where an elevated or buoyant radioactive plume is expected to cause
the highest exposure (airborne release).
2 A CW at a distance of 100 m from a facility (building perimeter) or estimated release point.
3 A worker within the facility boundary and located less than 100 m from the release point.
4 Although quantitative thresholds are provided for the MOI and CW consequences, the consequences may be estimated using
qualitative and/or semi-quantitative techniques.
5 Total Effective Dose (TED), 50-yr commitment.
6 DOE’s PAC - see Chapter 9.
High consequence thresholds identified in Table 2-7 do not represent acceptable exposure levels to the
public or workers; they are merely criteria used to identify safety class and safety significant controls.
Qualitative judgment is inevitable in hazard evaluation. It is routinely utilized in industries outside DOE.
Guidelines for Hazard Evaluation Procedures (CCPS, 2008, Pg. 22), notes the following:
The subjective nature of these deliberations may trouble some people who use the results of these
studies because this subjectivity creates a lack of confidence in the results. Some people incorrectly
believe that if the analyst uses quantitative methods to express the significance of a problem, then the
limitation of subjectivity will simply fade away. However, this is not the case. The apparent
numerical precision of a QRA [“quantitative risk analysis” or “quantitative risk assessment”] can mask
(1) a great deal of the judgment that influenced the selection of accident models and (2) large
uncertainties associated with the data used to estimate risk.
Estimating consequences qualitatively requires consistent assignments of the high, moderate, and low
consequence levels for similar scenarios. This may require “normalizing” hazard scenarios by comparing
against one another for consistent assignment of a severity level and to verify no outliers exist absent a
sound explanation. In addition, for those hazard scenarios that were selected as representative or unique
design basis accidents/evaluation basis accidents (DBA/EBAs) for further quantitative accident analysis,
insights from that quantitative analysis should be used to verify the qualitative consequence assignments
for the hazard evaluation (i.e., an iterative process between the hazard evaluation and the accident
Section 41
14 Mitigated analysis that credits controls to reduce unmitigated high consequences to the facility worker generally
show mitigated low consequences on the DSA hazard evaluation table.
DOE-HDBK-1224-2018
28
analysis).
Assigning qualitative consequence levels may be informed by use of quantitative scoping estimates of
effects on facility workers, CWs, and the MOI. Consequence estimation is performed differently for
facility workers that may be near the source of the event or other areas within the facility where exposure
may occur, as opposed to CWs or the public located at a distance from the facility. The latter often has a
simplified quantitative basis. That is, it is a straightforward exercise to identify radioactive materials of
greatest concern downwind using specific activity and dose equivalents that also incorporate the
dispersion analysis. Likewise, chemicals that combine significant volatility and toxicity are easily
identified. The safety analyst therefore starts with a short list of materials and release scenarios that are
bounding. Bounding is intended to refer to the accident with the highest consequences among a group of
similar accidents.
It is a simple matter to calculate “unit release” consequences at any distance of concern (within the
capabilities of atmospheric dispersion tools being used) to yield “rules of thumb” for screening
calculations such as rem/Curie released or concentration/mass released. These in turn are used to
qualitatively scale given events into qualitative consequence bins or levels of severity (high, moderate,
low) for the CW and MOI.
The CW scoping calculations may also provide the technical basis to meet the following requirement
from DOE-STD-3009-2014, Section 3.1.3.1:
Consequence determinations used for co-located workers in the hazard evaluation shall be supported
by an adequate technical basis such as scoping calculations consistent with Section 3.2.4. Alternately,
the quantitative evaluation of co-located worker consequences used to compare to Table 1 thresholds
may be performed in the accident analysis and reported in the DSA Section [3.4].
2.6.1.2 FACILITY WORKER CONSEQUENCES
Given the qualitative nature of the consequence thresholds for facility workers in Table 2-8; the
designation of facility worker consequences is based on first understanding how these type of
consequence thresholds can be triggered by common hazards found in the DOE complex, or what these
consequence thresholds mean in relation to radiological or hazardous chemical worker exposures. That
is, facility worker consequences in many cases are based on accepted past-experience or consensus
judgments from previous hazard evaluations throughout the DOE Complex, and not on quantitative
calculations with their associated hard-to-defend assumptions and uncertainties. Thus, the following are
recommendations and best practices to determine facility worker consequences.
Past experience and consensus judgments indicate that prompt death can only occur by a limited set of
hazards and scenarios such as:
• nuclear criticalities,
• exposures at levels over 400 rads to penetrating radiation such as gamma or X-rays, and
• energetic releases of extremely hazardous chemicals.
Exposure to airborne (non-penetrating) radioactive material such as plutonium and uranium due to a wide
range of accident scenarios such as fires or spills are unlikely to result in prompt death. However, these
could result in significant radiological exposures depending on several factors associated with the hazard
(e.g., inventory, form of material) and the scenario themselves; as discussed in more detail below.
Section 42
DOE-HDBK-1224-2018
29
DOE has no simple numerical consequence metric to assess threshold consequences for facility workers.
Because of the location of the postulated facility workers inside a facility or very near the source of a
release, downwind considerations such as Χ/Q are not applicable. Therefore, the determination of facility
worker consequences is usually based on judgment, and not quantitative calculations.
In order to use a quantitative metric, one would have to equate a “serious injury or significant exposure”
to a mutually-accepted quantitative exposure level (either radiation dose or toxic concentration) to define
a threshold numerical value that is equivalent to a high consequence as defined on Table 2-8. This has
been accomplished in DOE-STD-3009-2014 for the co-located worker and public, but not for the facility
worker. Some previous DSAs have been based on a metric that radiation exposures due to accident
conditions that could lead to exceeding emergency planning threshold or process safety management
levels may be considered significant, since the selected level implies the onset for potential long-term
health effects. Nevertheless, if a quantitative approach is desired, agreement on what constitutes a
significant exposure should be reached with the DOE Approval Authority before any quantification is
performed in support of determining the facility worker consequences.
A quantitative analysis may not be necessary where insights from past industrial accidents are available,
as may be the case for large-scale releases of toxic substances such as hydrogen fluoride. Local facility
worker consequences should be evaluated with some sense of perspective and historical experience, as it
is possible to conceive extreme events immune to any possible set of controls.
The analyst should focus on the work areas in which accidents may result in a release of radioactive or
hazardous material. If quantitative analyses are to be performed to support facility worker consequences,
the associated concentrations of such releases are typically evaluated without reliance on specific
assumptions about worker placement and hypothetical work area volumes for mixing of the release.
However, a conservative but reasonable period of exposure could be assumed. Further guidance on these
issues is provided later in this section.
DOE-HDBK-1224-2018
30
The unmitigated consequence potential should not be underestimated, nor should unmitigated
consequences be exaggerated (relative to historical experience) to a point where every exposure to the
local facility worker is a high consequence event. DOE-STD-3009-2014 states:
To ensure an informed and defensible qualitative evaluation, the determination of facility worker
consequences should be based on a combination of the following:
• Magnitude, type, and form of radioactive and hazardous materials involved in a hazard scenario;
• Type and magnitude of energy sources involved in a hazard scenario;
• Characteristics of the hazard scenario such as duration and the location where it may occur (e.g.,
in unmanned areas such as tank vaults); and
• Potential for a hazard to impact workers’ mobility or ability to react to hazardous conditions.
Section 43
Some additional discussion of the fourth bullet is warranted. DOE-STD-3009-2014, Section 3.1.3.1
states that “the facility worker’s mobility or ability to react to hazardous conditions should not be used as
the sole or primary basis for determining facility worker impacts.” This means that all four of the factors
listed above ought to be considered collectively, not individually. A “see and flee” approach that results
in unmitigated low consequences should not be used without due consideration of the accident
characteristics. The last bullet, therefore, injects some realism into the event scenario for a “reasonable”
unmitigated estimate of potential consequences to the facility worker. As an example, an assumption that
a worker within a building is unaffected by a release from a building fire (based on hazard recognition
and timely evacuation) would have to be justified by considering the location and characteristics of the
fire relative to radioactive or hazardous material.
Although unmitigated analysis may not take credit for administrative controls or active engineered
features, it is reasonable to assume that facility workers have some knowledge of the facility hazards and
adequate training to react to hazardous situations. This assumption, however, is valid only when the
accident is not disabling, provides obvious warning signs, and is slow-developing. However, care should
be taken not to rely excessively on crediting this type of condition as defaults for unmitigated analysis.
Any credit of this nature needs to be justified in the evaluation of the unmitigated consequences for
facility workers, based on the contributing elements discussed in this section.
In evaluating the unmitigated consequences associated with a postulated hazard scenario, the following
considerations may be important in assigning facility worker consequences:
1. Timing of radiological release: Hazard scenarios involving fires can develop quickly, but not so
rapidly as to preclude evacuation in a reasonable period of time. Other scenarios, like criticality
accident, explosion, and instantaneous release from confinement enclosures or containers can
entail significantly more rapid radiological exposure. Another example is a long duration release
such as during a spill of a radioactive or hazardous chemical liquid where a worker in the vicinity
of the spill would not be expected to stand in the spilled liquid for an extended period of time.
Therefore, though some exposure might occur, a conservative but reasonable time of exposure
should be assumed.
2. Hazard warning: The availability of an obvious hazard warning and its timing relative to
significant radiological or toxic chemical exposure may impact facility worker consequences.
Warning may be provided by the event itself, as in smoke from a fire. However, engineered
detection and notification systems such as air monitors are not credited for the unmitigated
analysis. It is not reasonable to assume that a worker would remain in a room subject to flashover
or toxic concentrations from a major fire in order to receive a significant radiological or toxic
DOE-HDBK-1224-2018
31
chemical exposure. A conservative but reasonable period of exposure should be assumed,
including whether the workers may choose to respond to the event.15
These points should also be considered:
Section 44
• If the facility worker would reasonably be aware of the event’s occurrence, and could
take self-protective actions after the event occurs to protect themselves from a fatality or
serious injuries from the non-radiological or non-hazardous material consequences,
assume that the facility worker will be exposed for a conservative, but reasonable period
of time even when warning is provided by the event itself.
• In cases where the facility worker would not be reasonably aware of the event’s
occurrence (e.g., characteristics of the release such as no odors, no visibility of plumes or
smoke, occurrence in areas that could mask the release), there is no specified period of
exposure, such as two hours. Consider reasonable lengths of time the facility worker
would normally be present based on the nature of planned activities.
3. Scenario effect on protective action capability: Hazard scenarios involving explosions and NPH-
initiated failure of buildings or equipment can cause damage to structures or injury to personnel
impeding egress, thus increasing potential radiological or toxic chemical consequences. The
potential for human errors or equipment malfunctions, in response to mitigating or evacuation
actions following the accident, should be considered. Such an error might be putting the
ventilation system in an operational mode that will worsen the consequences due to smoke
generation. Also of importance is the impact of a toxic chemical release on potential worker
ability to take protective actions.
4. Potential exposure magnitude: Severity of radiological uptakes or chemical exposures is a
function of the magnitude of the energy associated with the accident scenario, the quantity and
specific activity or toxicity of the material estimated to be released, and the pathways for
transport to and absorption by workers. Inhalation is most often the dominant exposure pathway
for airborne radioactive material releases, though skin exposures to small quantities of some
chemicals such as aqueous hydrofluoric acid can be fatal.
5. Location: The impact to facility workers could be affected by the location of the worker with
respect to the location of the postulated scenario; or whether the accident being evaluated occurs
inside or outside of structures. For releases outside of structures, consider the qualitative impacts
on dose of the plume moving past the facility worker. For releases inside a nuclear facility,
consider whether the release is being mixed within a relatively small work area volume, such as
with glovebox operations or into a large open area such as waste container staging buildings.
Also, for releases within the facility, consider facility layout and unique non-ideal conditions such
as mining operations or areas of limited visibility that can make evacuation difficult to achieve
quickly.
As a general rule-of-thumb application of the above considerations, examples of high unmitigated
radiological or toxic chemical consequences to the facility worker are: (1) explosions, pressurized
powders or high-concentration liquid sprays, and other energetic events that impact large quantities of
radioactive material are considered to cause significant radiological exposure to the facility worker due to
the rapid nature of the event, the resulting source term, and the inability of the worker to take protective
action prior to receiving a substantial dose16; and (2) the prompt dose received from a criticality accident.
Other types of events such as fires, spills, or dropping of a container require more careful evaluation of
Section 45
15 Workers may respond to incipient stage fires only with portable fire extinguishers, if they have been trained to use
the extinguishers and feel safe in doing so.
16 This also apples to the consequences of exposure to hazardous chemicals.
DOE-HDBK-1224-2018
32
the characteristics of the actual accident event (e.g., time to develop) before credit can be given for the
elements identified in this section. Any credit taken in the potential unmitigated consequences for facility
workers needs to be justified.
2.6.1.3 STANDARD INDUSTRIAL HAZARD CONSEQUENCES TO FACILITY WORKER
Consequences to facility workers due to SIHs are included in the DSA when radiological or hazardous
materials are involved and the SIHs are not screened out. These consequences are addressed in DOE-
STD-3009-2014, Section 3.1.3.1 as follows:
Facility worker consequences, due solely to a standard industrial hazard, do not need to be categorized
in the hazard evaluation if screened out per Section 3.1.1. However, the evaluation of radiological or
chemical hazards that result in a prompt death or serious injury should be assigned a high consequence
per Table 1. Examples of such hazards might include the generation of flammable/explosive hydrogen
gas by electrolysis of uranium in water or a spill of sodium hydroxide used in radioactive waste
processing.17
For potentially serious injuries or fatalities, the event is assessed to determine whether the physical hazard
associated with initiating or worsening a radiological or other hazardous material accident is a SIH or if it
should be assigned a high consequence level. The primary consideration in determining whether the
physical hazard is a SIH is if the regulated material (i.e., radioactive or other hazardous material) is not a
primary cause or major contributor to the hazardous event, and that it is adequately addressed by 10 CFR
Part 851 (and its adoption of OSHA and industry standards), 10 CFR Part 835, Occupational Radiation
Protection, and Integrated Safety Management System HA requirements. These regulations and safety
management programs are committed to in the DSA/TSRs. Examples of SIH accident initiators of a
radioactive or other hazardous material release that may also cause physical injuries/fatalities are
provided below to clarify that the unmitigated consequences do not include those SIH physical
considerations. They illustrate that the unmitigated consequences do not include those SIH physical
considerations, unless these could potentially affect their ability to safely manage the facility or respond
to an accident condition. In that situation, the SIH should be considered for further analysis:
• Thermal hazards to the worker are due to welding equipment and combustible or flammable
material fires ignited by typical ignition sources (e.g., electrical or thermal). The welding torch is
a common SIH throughout various industries. The fires with typical ignition sources are also
SIHs because the hazard and potential physical consequences are due to common types of
equipment found throughout various industries. Both of these events are adequately regulated by
10 CFR Part 851, OSHA, NFPA, and national consensus standards.
• Explosions may involve ignition of flammable gases used with welding equipment; battery and
fuel vapors; or offgasing from waste containers. The welding and equipment explosion and
potential physical consequences are considered a SIH because these events commonly occur in
general industry and are adequately regulated by 10 CFR Part 851, OSHA, and national
consensus standards.
Section 46
• Missiles are caused by an equipment explosion, failure of pressurized or mechanical system (e.g.,
air compressor or gas bottle), compressed gas cylinder failures, over-pressurization or
deflagration of a hazardous (i.e., non-TRU) waste container, or from extreme straight-line winds,
hurricanes and tornadoes. Missiles are considered an SIH because these events commonly occur
in general industry and are adequately regulated by 10 CFR Part 851, OSHA, and national
17 The above reference to Section 3.1.1 of DOE-STD-3009-2014 is located in Section 2.2.4 of this Handbook. Table
1 of the Standard is reproduced as Table 2-8 in this Handbook.
DOE-HDBK-1224-2018
33
consensus standards, or by the DOE NPH directives. However, if the missile physical
consequence to the worker is due to the primary hazard being the regulated material, then those
physical hazards are considered along with the radiological or other hazardous material
consequences in assigning unmitigated consequences.
• Equipment-related events including vehicle/equipment load drops are SIHs because the hazards
are presented by the equipment used in the work process, and the events are not caused by the
regulated material. These events are adequately regulated by 10 CFR Part 851, OSHA, and
national consensus standards.
• Material and equipment movement is a hazard presented by moving, lifting, dropping, vehicle-
impact-induced movement, collapse due to corrosion/degradation, or movement due to a seismic
event. The hazard is due to the size and mass of the object being moved and is not a hazard
presented by the regulated material. The same hazard exists in various industries, such as
construction. These events are adequately regulated by 10 CFR Part 851, OSHA, and national
consensus standards.
• Asphyxiant hazards are presented by the use of small quantities of nitrogen and P-10 gas
associated with loading or unloading shipping casks; acetylene or other compressed gases for
maintenance activities and liquid nitrogen dewers for assaying waste containers; and exhaust
buildup from material handling vehicles inside a facility. These hazards are common in various
industries, and are adequately regulated by 10 CFR Part 851, OSHA, and national consensus
standards. Smaller amounts of gases (i.e., nitrogen or argon) present for equipment calibration
are in quantities that do not present an asphyxiation hazard. However, a large, rapid release of a
nitrogen or argon from glovebox inerting systems for a nuclear process into a small confined
occupied area that has an asphyxiation potential should be considered in assigning unmitigated
consequences if the system has unique hazards requiring special design and controls that are not
addressed by industry codes and standards.
• Other impacts encompass collisions from vehicles such as trucks traveling on the site, vehicles
external to the site, and potential site aircraft crashes. These hazards exist in everyday life and
are accepted by the public. Although no specific controls may be identified for these SIHs, the
safety management programs, as committed to by the DSA/TSRs, which govern the conduct of
activities involving various industrial hazards, will provide protection to the worker for these
occupational hazards.
Section 47
The qualitative evaluation for the facility worker may be supported by conservative quantitative scoping
calculations, engineering judgment, and acquired knowledge. This qualitative approach is used because
quantitative estimates are sensitive to a variety of possible assumptions such as facility worker position,
circumstance, and close proximity to the point of release. Consequence estimates can rely on historical
accident data or can be determined from: (1) simple bounding source term calculations, (2) existing safety
documentation, and/or (3) qualitative assessment supported by calculations.
2.6.2 QUALITATIVE LIKELIHOOD
Likelihood of a hazard or accident scenario is assigned to qualitative bins defined by guidelines, which
offer numerical ranges of two orders of magnitude or more. Table 2-9, reproduced from DOE-STD-
3009-2014, Table 2, defines the qualitative likelihood bins.
DOE-HDBK-1224-2018
34
Table 2-9. Qualitative Likelihood Classification.
Description Likelihood Range (/year) Definition
Anticipated Likelihood >10-2
Events that may occur several times during the
lifetime of the facility (incidents that
commonly occur).
Unlikely 10-2>likelihood >10-4
Events that are not anticipated to occur during
the lifetime of the facility. Natural phenomena
of this likelihood class include: International
Building Code-level earthquake, 100-year
flood, maximum wind gust.
Extremely Unlikely 10-4>likelihood >10-6 Events that will probably not occur during the
lifetime of the facility.
Beyond Extremely Unlikely Likelihood <10-6 All other accidents.
Although the exercise of determining accident likelihood is qualitative, safety analysts often develop a
numerical basis for judgments to provide consistency. An example is provided in DOE-STD-3009 that a
simple methodology for unmitigated likelihood assignment could be to assign a probability of “1” to non-
independent events, “0.1” to human errors, and “0.01” to genuinely independent SSC failures that would
be used to establish the initiating event likelihood8 as described on Table 2-9. For the unmitigated
analysis, these human errors and equipment failures cannot represent the failure probability of a
preventive control that would otherwise provide a SC or SS safety function. To determine the likelihood
of an accident scenario, only initiating events are expressed as rate of occurrence with the units of inverse
time (i.e., per year), and other enabling events are expressed in terms of dimensionless failure
probabilities.
Another methodology for unmitigated initiating event likelihood classification would be to use a
summary of historical data. Historical accident data may be used as long as this data represents the
frequency of initiating events for such type of scenarios, and not the frequency of the entire scenario.
Thus, caution is necessary in using historical data to support unmitigated frequency estimates for hazard
scenarios, since it may not result in conservative frequency estimates for such scenarios.
Section 48
Conservative values are chosen to accommodate uncertainties in frequency levels used in Table 2-9. A
conservative choice is particularly important when an event frequency is at the borderline, just below the
next highest frequency level. For example, 9.7E-3/year is at the upper limit of the unlikely frequency
level. Thus, considering the sources, methods, and uncertainty associated with this value, this event may
be better assigned to a frequency level of anticipated. For initiating events at the borderline of frequency
ranges, for the general rule is to assign to the next bin unless it can be justified based on the conservatism
of the analysis. For example, an event just below a frequency of 10-2/year may be conservatively
considered assigned to the anticipated frequency level. The same applies for scenarios with frequencies
slightly less than 10-4/yr and 10-6/year, i.e., may be assigned to the next higher frequency level of Unlikely
and Extremely Unlikely, respectively. The exception for this is for Beyond Extremely Unlikely scenarios
for external events only, which by default have always being defined as scenarios with a likelihood below
10-6/yr.
The mitigated frequency of occurrence when crediting preventive controls could also apply simple
numerical estimates to assign a lower frequency bin. For example, a 0.01 failure probability could be
assigned to a preventive engineered control or a SAC based on the technical justification in DSA Chapter
4.
DOE-HDBK-1224-2018
35
Estimating likelihoods qualitatively requires consistent assignments of the likelihood bins for similar
scenarios. To achieve consistency, hazard scenarios should be “normalized” by comparison to one
another.
2.6.3 QUALITATIVE RISK
The primary purpose of risk ranking is to support the selection of bounding DBA/EBAs for further
quantitative accident analysis and determination of SC controls that are based on consequences, not risk
rankings. However, risk rankings may also be used to support the hazard evaluation and SS control
selection. Combining a likelihood and a consequence level leads to defining a qualitative risk level,
sometimes called Risk Category or Risk Class. Table 2-10, reproduced from DOE-STD-3009-2014 Table
A-1, provides an example of a risk ranking table that combines likelihood and consequence, which is
based on using the consequence and likelihood thresholds in Table 2-8 and Table 2-9, respectively.
Table 2-10. Qualitative Risk Ranking Bins.
Consequence Level
Beyond18 Extremely
Unlikely
Below 10-6/yr
Extremely Unlikely
10-4 to 10-6/yr
Unlikely
10-2 to 10-4/yr
Anticipated
Above 10-2/yr
High Consequence III II I I
Moderate Consequence IV III II II
Low Consequence IV IV III III
Risk Category I = Combination of conclusions from risk analysis that identify situations of major concern
Risk Category II = Combination of conclusions from risk analysis that identify situations of concern
Risk Category III = Combination of conclusions from risk analysis that identify situations of minor concern
Risk Category IV = Combination of conclusions from risk analysis that identify situations of minimal concern
Beyond the qualitative application of consequences and likelihoods (or supplemented with quantitative
perspectives) for the hazard evaluation, risk ranking serves the broader purpose of confirming for the
DOE approval authority that the overall mitigated risk of facility operation is low. Risk ranking can also
highlight a given scenario whose mitigated risk remains significant. Additional guidance on use of
unmitigated risk estimates for control selection is provided in Chapter 10.
Section 49
2.7 UNMITIGATED AND MITIGATED HAZARD EVALUATIONS
The DSA hazard evaluation is based on unmitigated and mitigated analyses that derive the selection of
hazard controls. The guidance from Section 2.6 is applied to assign qualitative estimates of the
unmitigated and mitigated consequences, likelihood, and optionally, risk rankings of the hazard scenarios.
An unmitigated hazard scenario is evaluated for each initiating event by assuming the absence of
preventive and mitigative controls. Unmitigated likelihood and consequence estimates assume that active
engineered and administrative controls are not available to reduce either the consequence or likelihood of
the hazard scenario. However, the unmitigated analysis does assume that passive design features exist
and provide their safety function if these features are not affected by the accident scenario, or these
features are affected by the accident scenario and a separate assessment determines that they will survive
accident conditions.
18 For external events, likelihood below 10-6/yr conservatively calculated is “beyond extremely unlikely.”
DOE-HDBK-1224-2018
36
Passive features assumed to perform their safety functions are evaluated per DOE-STD-3009 for potential
designation as SC or SS SSCs and protection as TSR Design Features. In addition, the unmitigated
analysis considers facility geometry and physical plausibility, and evaluates the unmitigated likelihood
and consequence accordingly. For example, in an explosion scenario, the unmitigated likelihood would
not be reduced by an engineered control, such as a vessel purge. However, the unmitigated likelihood of
the explosion could be reduced based on physical realities of the facility, activity, or operation that will
cause the explosion-initiating condition to occur (accumulation of minimum explosive concentration); no
credit is allowed in the reduction of the likelihood for subsequent enabling conditions that will result in
the explosion itself (e.g., presence of an ignition and/or oxygen). Thus, the likelihood of the scenarios
should be based only the likelihood of the conditions leading to a physically meaningful initiating event,
and not on the subsequence engineering or administrative controls that maybe available to prevent the
explosion. Additional requirements and guidance on unmitigated analysis are provided in DOE-STD-
3009-2014, Section 3.2.2.
Initial conditions may be necessary to define the unmitigated evaluation and are identified as shown on
Table 2-7 and another example is provided later in Table 2-11. Credit for the initial condition is factored
into the unmitigated likelihood or consequence assignments, and that initial condition is evaluated per
DOE-STD-3009 for potential designation as a TSR control (e.g., MAR inventory-specific administrative
control). Additional guidance is provided in DOE-STD-3009-2014, Section A.3, and is further discussed
in Section 3.3 of this Handbook.
A mitigated analysis is performed to determine the effectiveness of SS and SC controls to protect CWs
and the public. This analysis should be the same as the unmitigated analysis except that event likelihood
is estimated with preventive controls available, and consequences are estimated with mitigative controls
available. The selection of preventive and mitigative controls is a judgment-based iterative process to
credit sufficient controls that provide confidence that the accident or release is prevented, or if not
prevented, the consequences will be reduced to below thresholds of concern. Additional requirements
and guidance on mitigated analysis are provided in DOE-STD-3009-2014, Section 3.2.3. The selection
and classification of the hazard controls for the mitigated analysis are discussed in Chapter 10 of this
Handbook.
Section 50
2.8 HAZARD EVALUATION PRESENTATION IN DSA
Results for the unmitigated and mitigated hazard analyses are presented in the DSA hazard evaluation
section as discussed in a DSA Section [3.3.2.3], Hazard Evaluation Results (see DOE-STD-3009-2014,
Section 4.0). The DSA hazard evaluation table, or alternate hazard evaluation data sheet as described in
DOE-STD-3009-2014, has certain essential characteristics:
• If multiple types of operations are being analyzed, the table is broken into separate sections where
each section presents results for one specific type of operation.
• Specific hazard scenarios are described in terms of well-defined events. For example, a HAZOP
may have dozens of entries for parameter-guide word combinations. These need to be turned into
discrete events. A HAZOP may note that low flow caused by incorrect positioning of valves
upstream has no major effect on a process other than operational disruption, while low flow due
to a large leak represents a significant operator hazard. Those are two entirely different events.
• Initial conditions and assumptions are identified.
• Potential preventive or mitigative controls are identified.
• Unmitigated and mitigated consequences and likelihoods, and optionally, risk estimates, are
identified to support control selection and classification. Source term parameters such as MAR,
DOE-HDBK-1224-2018
37
Damage Ratio (DR), Airborne Release Fraction (ARF), and Respirable Fraction (RF) may
optionally be listed.
Table 2-11 presents an example hazard evaluation table for presentation in the DSA, which builds upon
the example provided in Table 2-7. This table includes both the unmitigated and mitigated analysis.
There are many different formats that can be used to present this data, bearing in mind that the purpose is
to achieve a comprehensive hazard evaluation and an unmitigated analysis of hazard scenarios in terms of
potential consequences, their likelihoods, and identification of preventive and mitigative controls. The
hazard evaluation table, in whatever format is chosen, should also present the mitigated analysis that
credits safety controls, or this could be described in the DSA hazard evaluation results section. The
mitigated hazard evaluation can be included as additional columns as shown on Table 2-11, or another
convention is to use separate rows for the unmitigated and mitigated evaluations.
Appendix A provides another example of a hazard evaluation table for safety design basis documents, as
part of the process to perform a Preliminary Hazard Analysis required by DOE-STD-1189-2016,
Integration of Safety into the Design Process. Some additional data are included such as methods of
detection and more emphasis on further planned improvements and investigations as the design matures.
DOE-HDBK-1224-2018
38
Table 2-11. DSA Hazard Evaluation Table Example.
Unmitigated Analysis Mitigated Analysis
E
ve
nt
Event Description Event Causes
Fr
eq
.
L
ev
el
Consequence Level R
is
k
C
at
eg
or
y
Preventive Features Mitigative
Features Fr
eq
.
L
ev
el
Consequence
Level R
is
k
C
at
eg
or
y
x Fuel-powered vehicle suffers a
fuel leak due to an impact with
TRU waste drums in the
Shipping/Receiving Area and is
ignited. A forklift carrying a
single pallet with four drums
impacts a stack (two high) of
palletized drums with moderate to
severe stress causing breach with
material spill of 12 drums and
ensuing pool fire that involves 88
additional drums in the Shipping/
Receiving Area.
Section 51
MAR: xx alpha curies in 100
drums
(DOE-STD-5506-2007 statistical
MAR distribution for Waste
Isolation Pilot Plant compliant
containers applied, see Table yy)
INITIAL CONDITIONS:
Staging area inventory limit;
TRU waste in metal containers;
Metal pallets.
• Operator
error
• Equipmen
t
malfuncti
on
• Vehicle
impact
with fuel
spill
• Ignition of
combustib
le and/or
flammable
materials
• Lightning
• Wildland
fire
U Radiological
FW – High
CW – Moderate
MOI – Low
Hazardous Chemical
FW – Low
CW – Low
MOI – Low
RELEASE MECHANISM:
Impact + fire – 12 drums, 10% DR, 1E-
3/0.1 spill ARF/RF plus unconfined
burning 1E-2 ARF/RF and 90%
confined burning 5E-4 ARF/RF.
Pool fire – Conservatively modeled in a
single layer of drums with no stacking.
Unconfined burning 1E-2/0.1 ARF/RF
of 25% of drums that experience lid loss
(22 drums) that eject 33% contents and
have confined burning 5E-4 ARF/RF of
remaining contents in those drums, plus
confined burning of 66 drums that
experience seal failures (0.5 DR).
I
II
III
III
III
III
SSCs:
Concrete vehicle barriers.
Waste staging building
foundation.
ADMINISTRATIVE:
Procedures and Training
Program (Forklift
Operator training);
Vehicle maintenance
program;
Fire Protection Program:
• Combustible controls
Waste handling operations
curtailed outdoors during
inclement weather;
Movement of waste is to be
accomplished using
electric or manual
powered equipment
(SAC);
Fuel exclusion zone in the
Shipping/Receiving Area
(SAC).
SSCs:
None
ADMINISTR
ATIVE:
Procedures
and
Training
Program
(workers
trained to
evacuate);
Emergency
Preparedne
ss Program
(emergency
response
activities).
BE
U
Radiological
FW – High
CW – Moderate
MOI – Low
Chemical
FW – Low
CW – Low
MOI – Low
III
IV
IV
IV
IV
IV
Notes:
1. Likelihood: A = Anticipated U = Unlikely EU = Extremely Unlikely BEU = Beyond Extremely Unlikely
2. Consequences: H = High M = Moderate L = Low
3. FW = Facility Worker CW= Co-located Worker at 100 m MOI = Maximally-exposed Offsite Individual at 2.9 km
4. Risk Classes: I = Combination of conclusions from risk analysis that identify situations of major concern
II = Combination of conclusions from risk analysis that identify situations of concern
III = Combination of conclusions from risk analysis that identify situations of minor concern
IV = Combination of conclusions from risk analysis that identify situations of minimal concern
Bold/Underlined controls are credited in the mitigated analysis to reduce frequency, consequences, and Risk Class, or as Initial Condition
DOE-HDBK-1224-2018
39
3 ACCIDENT ANALYSIS
This chapter provides an introduction to the accident analysis process. The starting point is a review of
the hazard scenarios that were identified in the hazard evaluation table as discussed in Chapter 2 of this
Handbook. Specific events are selected for further quantitative accident analysis. This particular chapter
also addresses assumption and initial conditions, beyond DBAs/EBAs, and software quality assurance
(SQA).
In general, formal accident analysis is performed for HC-2 facilities, and may or may not be necessary for
HC-3 facilities. Accident analysis is the formal quantification of a subset of accidents, termed DBAs or
EBAs by DOE-STD-3009. These accidents represent a complete set of bounding conditions. The basic
components of accident analysis are accident type selection, accident scenario development, source term
analysis, consequence analysis and control selection. This process is highly iterative to ensure accident
scenarios are adequately developed, source term and consequence analysis is bounding, the suite of
controls are comprehensive and tailored to reflect accident conditions, and all identified facility hazards
are understood and properly controlled.
Section 52
3.1 ACCIDENT TYPE SELECTION
It is expected that only a subsect of the total hazard scenarios identified in the hazard analysis will be
evaluated as potential DBAs or EBAs in the accident analysis. The predominant purpose of accident
analysis is to evaluate the need for SC controls to protect the public from radiological accidents.
However, it may also be used to evaluate the need for defense in depth SS controls for protection of the
public from radiological or toxic chemical accidents, or for protection of the CWs. The facility worker is
not included in the scope of the DSA accident analysis and instead is addressed by the qualitative hazard
evaluation discussed in Chapter 2 of this Handbook.
DBAs are accidents to be analyzed in a DSA for the design of a new nuclear facility and major
modifications to an existing facility. The DSA will also include accident scenarios established during the
design of an existing facility. DOE-STD-1189-2008 provides guidance for selecting and analyzing
facility-level radiological and/or toxic chemical release events in the DBAs.
EBAs are postulated for existing facilities where DBAs were not identified as part of the design. The
term EBA recognizes that an existing facility was not designed to DBAs to prevent or mitigate the
accident, but rather is evaluated to ensure that it could do so with existing systems or added
systems/controls. When an adequate set of DBAs does not exist, EBAs are selected from the following
types of events:
• Operational accidents — process deviations (such as high temperatures and high pressures) and
initiating events internal to the facility (such as fires, explosions, and loss of power resulting in
release of radioactive or hazardous materials);
• NPH events such as earthquakes, floods, tornadoes, and wildland fires; and,
• Man-made external events such as an aircraft crash, external vehicular accident, or gas pipeline
break.
Two types of EBAs, representative and unique, are defined in DOE-STD-3009-2014 for further
quantitative accident analysis.
DBAs/EBAs are derived from the spectrum of hazard evaluation scenarios. Three screening steps convert
the spectrum of hazard evaluation scenarios into the selected DBAs/EBAs:
DOE-HDBK-1224-2018
40
• The first screening identifies potential consequences by population in relative bins of increasing
severity. This step will discard scenarios whose higher consequence potential relates only to in-
facility workers, because accident analysis focuses on consequences at a distance from the
facility.
• The second screening looks at accident types. It is necessary for DSA documentation purposes to
include at least one hazard and its consequence of each major accident type (e.g., fire, explosion,
spill, NPH), unless the scoping calculations for the hazard evaluation demonstrate low
consequences that do not have the potential to challenge the offsite Evaluation Guideline (EG)
(DOE-STD-3009). These are called representative scenarios with similar preventive and
mitigative control sets that bound the collective scenarios for that type.
• The final screening consists of looking at the remaining scenarios within a selected accident type
to see if any would warrant safety SSC designation to protect the public (and CW if included in
the DSA accident analysis, as mentioned above), but involve a different control set than the
representative accident already chosen for that type. These are called unique accidents.
Section 53
As an aid in screening the many hazard scenarios identified in the hazard evaluation, representative or
unique EBAs may be selected based on organization by accident category (operational, NPH, man-made
external event), accident type, and magnitude. Other means of grouping accidents may also be used,
especially for complex facilities that may require a broad suite of hazard controls. The selected
representative and unique scenarios are designed to bound all other postulated hazard scenarios, including
high risk scenarios that still may challenge the EG (as determined during the hazard analysis process
using the qualitative risk matrix in Section 2.6.3), or that may have high risk to the co-located worker if
that is being evaluated in the accident analysis.
An example of an aid to screen hazard scenarios is provided in DOE-STD-5506-2007, Table 3.3-1,
Minimum TRU Waste Activity/Hazard Evaluation Event Matrix. This table correlates 25 hazard
scenarios or accidents by TRU waste processing activities for use in the hazard evaluation, or as EBAs.
The minimum set of events addresses those with the potential for consequences that could be significant
enough to warrant crediting preventive or mitigative controls, safety classifications of those controls, and
explicit TSRs. Another example aid in screening hazard scenarios for EBA selection is NUREG/CR-
6410, Nuclear Fuel Cycle Facility Accident Analysis Handbook, Table 2-2, Methods of Release of
Radioactive Materials Anticipated for Nuclear Process Facilities.
3.2 ACCIDENT ANALYSIS PROCESS
The accident analysis process consists of the following sequence of steps intended to document numerical
estimates of radiological and toxic chemical consequences to the public (or CW as needed for the DSA
hazard evaluation):
1. Define the postulated accident scenario that releases radioactive material or toxic chemicals from
the facility.
2. Estimate the damage to the facility to the extent it affects the potential MAR and source term
released from the facility, e.g., loss of confinement areas.
3. Identify types and quantities of material involved in the accident MAR.
4. Determine the accident source term.
5. Conduct a dispersion analysis to determine the potential radiological dose or toxic chemical
consequences.
DOE-HDBK-1224-2018
41
Chapter 4 addresses steps 1-3 for potential accidents at DOE nuclear facilities. Chapter 5 addresses step
4. Chapters 6, 7, and 8 address step 5 for radiological releases, while Chapter 9 addresses step 5 for toxic
chemical releases.
The potential controls identified in the hazard evaluation are further evaluated in the mitigated accident
analysis, using the control selection and classification process described in Chapter 10.
3.3 ANALYSIS INPUTS AND ASSUMPTIONS
For most DOE accident analyses, the phenomena being examined have aleatory and systemic
uncertainties. Most often it is not possible to derive precise and absolute conclusions from first
engineering principles. Therefore, it is important to document the inputs, frame of reference, initial
conditions, and assumptions of the accident analysis to ensure that these are not only defensible but
conservative. This applies to all elements of the accident analysis process from accident selection, to
frequency estimates, and source term and consequence analyses. The focus in this section is on the
analysis of inputs and assumptions related to defining scenarios and their frequencies. Section 5.4.1
addresses the use of technically justified input and assumptions related to source term and consequence
calculations.
Section 54
Both hazard and accident analyses make use of initial conditions (ICs) to define hazard or accident
scenarios to be evaluated. Initial conditions are specific assumptions regarding a facility and its
operations that are used to define these scenarios. When not referring to physical facility features, these
are sometimes called “initial assumptions,” which creates confusion regarding the need for TSR controls
to protect these assumptions. The use of “IC” in this Handbook refers to initial conditions.
As discussed in DOE-STD-3009-2014, Sections 3.2.2 and 3.2.3, facilities are analyzed as they exist, or
are designed, when quantifying meaningful release mechanisms. For design of new facilities, the
unmitigated analysis may need to assume failure of the SSC to determine the potential consequences for
safety classifications of SSCs and their appropriate design requirements, for example, design criteria for
the selected NPH Design Category.
Accident scenario description includes, as appropriate, the operating mode of the system, all pertinent
aspects of the physical configuration of the system and its environment, and relevant operating
parameters, such as temperature, pressure, material inventories, and confinement, at the time the accident
is postulated to begin. Not all of these assumptions are ICs. Where a range of possible ICs, physical
properties, or environmental conditions exists, the range is specified, and the most conservative physically
credible combination of normal operating conditions is chosen, and an explanation of why the choices are
considered conservative should be provided.
As stated in Chapter 2, significant assumptions in hazard scenarios should be identified and justified, and
this also applies to the accident analysis. Specific examples of ICs include:
• A vault or building can withstand NPH events according to its NPH Design Category.
• Facility geometry or layout limits accident progression or release with respect to in-facility
transport.
• Solid TRU waste is contained in a certified Department of Transportation (DOT) Type-A drum
(i.e., an additional barrier).
• A certain material is present only within a certified DOT Type B shipping container.
• Facility and process inventories are limited to those identified.
• A passive engineered SSC prevents significant consequences.
DOE-HDBK-1224-2018
42
ICs should not include administrative controls, except those necessary to limit the inventory of
radioactive or toxic chemical materials, or as specified by the analyst and/or regulator. Controls should
be selected to protect assumptions such as MAR critical to the consequence analysis. ICs, and in some
cases the associated administrative control associated with the ICs, should warrant some level of Safety
SSC designation or SAC to ensure that the assumptions remain valid throughout the operating life of the
facility. Defining and documenting ICs and associated administrative controls ensures that they are
appropriately controlled, classified as SC or SS, and preserved via TSR operating limits, design features,
or SACs.
Section 55
Initial conditions that clearly prevent an accident and are part of the facility design basis (e.g., the
structure is designed to withstand vehicle impact) are encouraged. Other safety controls are discouraged
from being used since they may skew the unmitigated risk levels and result in unanalyzed or inadequately
controlled hazards. For example, a fire door may be improperly credited as an IC for preventing fire
propagation. This control may fail (blocked open door) so it does not completely prevent the event, but
only reduces the likelihood. If the likelihood reduction “moves” the event risk to a level that does not
require further analysis, then the adequacy of the control is not evaluated and the safety functions of the
door may not be properly determined. Additionally, this may lead to a larger control set since controls
identified for other fire events (e.g., combustible loading limits) may be adequate to protect against this
event.
Spreadsheet calculation and computer modeling of accident sequences can provide valuable insights on
the sensitivity of parameters, as well as indicating what reasonably lower and upper limits of response
might be expected so that an overall conservative consequence is estimated (see Section 5.4,
Appropriateness of Source Terms). The foundation of any accident analysis can be reduced to a set of
inputs and assumptions. An input can be defined as a value feeding into the analyses that can be
measured confidently and is readily obtainable. It could, for instance, be the internal freeboard volume of
a tank, the specific gravity of a solution, or the metal skin thickness of a 55-gallon drum. An input value
would not be expected to change as more information relative to it is obtained. An assumption, on the
other hand, is a value feeding into the analyses that is not known with reliability and accuracy.
Significant judgment therefore enters into the process of selecting the value or parameter of interest.
To address the uncertainty associated with the impact of assumptions and input variables, the default
values in DOE-STD-3009 and DOE-HDBK-3010 are to be used to ensure an overall conservative
analysis, and an analysis that is conservative to the extent envisioned when the Evaluation Guideline was
established. Section 5.4.1 provides additional guidance on the use of non-default values or values that
depart from the default values in the above-mentioned standard or handbook.
Examples of assumptions would be the rate of in-facility dispersion of a flammable gas leaked into a
ventilated volume, the degree to which two spilled chemicals that react together might intermingle
(synergism), or the nature of the physical interactions occurring in a structural collapse. The flammable
gas leak example can be calculated, but the means of calculation itself introduces an implicit set of
theoretical assumptions and uncertainties. The other two examples intrinsically involve making
judgments about what is likely to occur. Analysts should strive to use as few assumptions in the accident
analysis as possible, but their presence to some degree is inevitable. This point is specifically emphasized
in Guidelines for Hazard Evaluation Procedures (CCPS, 2008):
Because many of the events considered by the team may never have happened before, the team
must use their creativity and judgment to decide whether the potential causes and effects of the
accident pose a significant risk. The subjective nature of these deliberations may trouble some
people who use the results of these studies because this subjectivity creates a lack of confidence
Section 56
DOE-HDBK-1224-2018
43
in the results. Some people incorrectly believe that if an analyst uses quantitative measures to
express the significance of a problem, then the limitation of subjectivity will simply fade away.
However, this is not the case.
Another consideration is that there may be a difference between the level of conservatism of methods
used to derive input parameters used for unmitigated dose consequence calculations and input parameters
used to show that the design withstands physical stresses from the accident scenario. For example, dose
consequence calculations may use an extremely conservative value or method to calculate aerosol
generation for the purpose of determining the source terms and ultimately supporting classifying controls.
However, these conservative values or methods may not be appropriate for design basis calculations.
3.4 BEYOND DESIGN/EVALUATION BASIS ACCIDENTS
The DSA [Section 3.4] Accident Analysis (see DOE-STD-3009-2014, Section 4.0) evaluates
DBAs/EBAs for control selection and classification purposes. Section 3.5 of DOE-STD-3009-2014
provides guidance on the consideration of the need for analysis of accidents, which may be beyond the
design basis of the facility. This section addresses accident analysis of these extreme events.
The purpose of an analysis of accidents beyond the design or evaluation basis of the facility is to provide
(1) a perspective of the residual risk associated with the operation of the facility, and (2) additional
perspectives for accident mitigation. That standard describes that Beyond Design Basis
Accidents/Beyond Evaluation Basis Accidents (BDBAs/BEBAs) need not be analyzed to the same degree
of detail as DBAs/EBAs. The analysis is intended to provide insight into the magnitude of consequences
of such events and to identify potential facility vulnerabilities. The analysis has the potential, therefore,
for identifying additional facility features that could prevent or reduce severe accident consequences.
Unlike the unmitigated conservative analysis for DBAs/EBAs, a realistic analysis of potential
BDBA/BEBA consequences may be performed to determine whether accidents have a much larger
consequence (a “cliff edge effect”) than the largest DBA/EBA.
After the March 11, 2011 Fukushima Dai-Ichi nuclear plant accident in Japan, DOE embarked upon
several initiatives to investigate the safety posture of its nuclear facilities relative to Beyond Design Basis
Events (BDBEs). These initiatives included issuing Health, Safety and Security (HSS) Safety Bulletin
2011-01, “Events Beyond Design Safety Basis Analysis,” conducting pilot evaluations to refine possible
process improvements, and conducting two DOE nuclear safety workshops. DOE issued two reports
documenting the results of these initiatives: Review of Requirements and Capabilities for Analyzing and
Responding to BDBEs (DOE, 2011); and A Report to the Secretary of Energy: Beyond Design Basis
Event Pilot Evaluations, Results and Recommendations for Improvements to Enhance Nuclear Safety at
DOE Nuclear Facilities (DOE, 2013). A summary description of the pilot evaluation process and results
is provided in the HSS Operating Experience Level 1 notice (DOE HSS OE-1, 2013), “Improving
Department of Energy Capabilities for Mitigating Beyond Design Basis Events.” Additional details of
the pilot acti