Archive

DOE-HDBK-1224-2018, Hazard and Accident Analysis Handbook

The principal purpose of this Handbook is to guide development of the DSA safety analysis for nuclear facilities in order to satisfy the requirements of a safe harbor method set out in 10 CFR Part 830, Subpart B.
DOE-HDBK-1224-2018.pdf5.98MB
Version history and related documents
Document text

Text extracted from the attached file. Refer to the original document for the authoritative version.

Section 1

DOE-HDBK-1224-2018 August 2018 DOE HANDBOOK HAZARD AND ACCIDENT ANALYSIS HANDBOOK Interim Use U.S. Department of Energy Washington, D.C. 20585 DOE-HDBK-1224-2018 ii FOREWORD This U.S. Department of Energy (DOE) Handbook is approved for use by all DOE elements and their contractors. It may be applied to upgrading existing Documented Safety Analyses (DSAs) to the requirements of DOE-STD-3009-2014, Preparation of Nonreactor Nuclear Facility Documented Safety Analysis, or to revising DSAs for existing facilities based on their current safe harbor methodology. The Handbook may also be used to prepare and document hazard and accident analyses during facility design. This Handbook is intended to assist DOE and its contractors in preparing and reviewing DSAs that are cost-effective and consistent in quality and content. To this end, the Handbook provides information on applicable scientific theories, analysis techniques, practical examples, and lessons learned from DOE applications and experience. The Handbook addresses these subjects: • Process for preparing a safety analysis, specifically the Chapter 3 portion of the DSA, • Major accident types, such as fires, explosions, loss of confinement, chemical reactions, and natural phenomena events, • Criticality accident analysis, • Source term analysis, • Radiological dispersion and consequence analysis, and • Chemical dispersion and consequence analysis. DOE Order 252.1A, Admin. Chg. 1, Technical Standards Program, states that DOE handbooks provide “a compilation of good practices, lessons-learned, or reference information that serve as resources on specific topics.” The guidance provided in this Handbook is not mandatory and may be used at the discretion of DOE contractors and field offices. This Handbook is being issued for “Interim Use” because it is the first publication of a very large and technically complex document. While great efforts have been made to achieve completeness and accuracy, comments and feedback are welcome from users during the initial two-year period of availability. Beneficial comments (recommendations, additions, and deletions), as well as any pertinent data that may be of use in improving this document, should be emailed to nuclearsafety@hq.doe.gov or addressed to: Office of Nuclear Safety (AU-30) Office of Environment, Health, Safety and Security U.S. Department of Energy 19901 Germantown Road Germantown, MD 20874 mailto:NuclearSafety@hq.doe.gov DOE-HDBK-1224-2018 iii ACKNOWLEDGMENTS This technical handbook represents a multidisciplinary product of multiple authors and contributors who have worked in some capacity in the DOE nuclear weapons complex. In the table below, DOE acknowledges the contributions of the many professionals who authored or reviewed various sections of this document.

Section 2

Contributor DOE or Contractor Affiliation DOE Nuclear Sites Sam Rosenbloom DOE AU-30 Office of Nuclear Safety DOE AU-31 Program Manager Ron Beaulieu National Security Technologies Nevada National Security Site Sandra Brereton Lawrence Livermore National Laboratory Lawrence Livermore R.T. Brock DOE Amarillo Area Office Pantex Kevin Carroll Lawrence Livermore National Laboratory Lawrence Livermore Roger Casteel DOE Office of Science Oak Ridge Chris Chaves DOE AU-30 Office of Nuclear Safety DOE HQ Doug Clark Consolidated Nuclear Security Y-12 Allan Coutts AECOM Savannah River Doug Craig Advanced Technologies & Laboratories Savannah River Dick Englehart DOE AU-30 Office of Nuclear Safety/PEC DOE HQ Brad Evans Pacific Northwest National Laboratory Hanford Terry Foppe Link Technologies/Foppe & Associates Rocky Flats, multiple DOE sites Caroline Garzon DOE EM Chief of Nuclear Safety staff DOE HQ Chuck Grigsby Los Alamos National Laboratory Los Alamos Brent Gutierrez DOE Savannah River Site Savannah River Mukesh Gupta AECOM Savannah River, other DOE sites David Hesse Battelle Columbus Laboratories Multiple DOE sites Jerry Hicks DOE Criticality Safety Support Group NNSA Albuquerque Service Center Quazi Hossain Lawrence Livermore National Laboratory Lawrence Livermore Roy Hunt Consolidated Nuclear Security Y-12 Lee Hyder Savannah River Nuclear Solutions Savannah River Kamiar Jamali DOE AU-30 Office of Nuclear Safety DOE HQ Sharon Jasim-Hanif DOE AU-30 Office of Nuclear Safety DOE HQ Adam Jivelekas Washington River Protection Solutions Hanford Hans Jordan Innovative Technology Solutions Rocky Flats Kevin Kimball Consolidated Nuclear Security Y-12 and Pantex Craig Kullberg NNSA Los Alamos Site Office Los Alamos Roger Lanning Bechtel National Hanford Bob Marusich Fluor Daniel Hanford Carl Mazzola Project Enhancement Corporation Multiple DOE sites John McAllister AECOM Hanford and Savannah River Patrick McClure Los Alamos National Laboratory Los Alamos DOE-HDBK-1224-2018 iv Contributor DOE or Contractor Affiliation DOE Nuclear Sites Steven McDuffie DOE EM Chief of Nuclear Safety staff DOE HQ Tom McLaughlin DOE Criticality Safety Support Group Supporting NNSA HQ Jofu Mishima SAIC Multiple DOE sites Rich Miller Sonalysts Los Alamos and other DOE sites Jim Morman DOE Criticality Safety Support Group Argonne National Laboratory James O’Brien DOE DOE HQ Kevin O’Kula AECOM Savannah River Shirley Olinger DOE Rocky Flats Project Office Rocky Flats Ingle Paik Westinghouse Safety Management Solutions Savannah River Jane Peel Westinghouse Safety Management Solutions Savannah River Vern Peterson Link Technologies/AB Consulting Rocky Flats, other DOE sites David Pinkston Lawrence Livermore National Laboratory Lawrence Livermore Marty Plys Fauske & Associates Oak Ridge and other DOE sites Louis Restrepo Project Enhancement Corporation Multiple DOE sites Rama Sastry DOE AU-30 Office of Nuclear Safety DOE HQ Daniel Schmitt Hukari Technical Services Los Alamos Jim Schornhorst Westinghouse Safety Management Solutions Savannah River Garrett Smith DOE AU-30 Office of Nuclear Safety Director DOE HQ Chris Steele DOE Los Alamos Site Office Los Alamos Don Swanson Triad Safety Engineering Rocky Flats Dave Thoman AECOM/Westinghouse Safety Management Sols. Savannah River Ivan Trujillo NNSA Albuquerque Service Center NNSA HQ Joe Vera Bechtel National Hanford Doug Wenzel Lockheed Martin Idaho Technologies Idaho National Laboratory Bob Wilson DOE Environmental Management DOE HQ Jeff Woody Link Technologies Oak Ridge, other DOE sites Al Wooten AECOM Savannah River Ray Yeung AECOM Savannah River Bruce Zimmerman Washington River Protection Solutions Hanford

Section 3

DOE-HDBK-1224-2018 v CONTENTS ACRONYMS ............................................................................................................................................................ XII 1 INTRODUCTION ......................................................................................................................................... 1 1.1 PURPOSE ....................................................................................................................................................... 1 1.2 OUTLINE ....................................................................................................................................................... 1 2 HAZARD ANALYSIS .................................................................................................................................. 3 2.1 ELEMENTS OF HAZARD ANALYSIS ................................................................................................................ 3 2.2 HAZARD IDENTIFICATION AND CHARACTERIZATION .................................................................................... 3 2.2.1 Hazard Data Gathering ............................................................................................................................. 4 2.2.2 Hazard Data Recording ............................................................................................................................. 4 2.2.3 Hazard Summary Development ................................................................................................................. 9 2.2.4 Exclusion of Standard Industrial Hazards and Other Hazardous Materials ........................................... 11 2.3 INITIAL HAZARD EVALUATION DEVELOPMENT .......................................................................................... 14 2.3.1 Overview .................................................................................................................................................. 14 2.3.2 Nuclear Criticality Hazard Evaluation .................................................................................................... 16 2.3.3 Chemical Hazard Evaluation ................................................................................................................... 16 2.4 HAZARD EVALUATION METHODS ................................................................................................................ 17 2.4.1 Commercial Industry Methods and DSA Hazard Evaluations ................................................................. 17 2.4.2 Method #1: What-If? ................................................................................................................................ 17 2.4.3 Method #2: Hazard and Operational Analysis ....................................................................................... 19 2.4.4 Method #3: Failure Modes and Effects Analysis .................................................................................... 23 2.4.5 Method #4: Event Trees and Fault Trees ................................................................................................ 24 2.5 INITIAL DEVELOPMENT OF A DSA HAZARD EVALUATION TABLE .............................................................. 25 2.6 LIKELIHOOD, CONSEQUENCE, AND RISK METHODS .................................................................................... 26

Section 4

2.6.1 Qualitative Consequences ........................................................................................................................ 26 2.6.1.1 Receptor Consequence Levels............................................................................................................................. 26 2.6.1.2 Facility Worker Consequences ............................................................................................................................ 28 2.6.1.3 Standard Industrial Hazard Consequences to Facility Worker ............................................................................. 32 2.6.2 Qualitative Likelihood ............................................................................................................................. 33 2.6.3 Qualitative Risk ........................................................................................................................................ 35 2.7 UNMITIGATED AND MITIGATED HAZARD EVALUATIONS ............................................................................ 35 2.8 HAZARD EVALUATION PRESENTATION IN DSA .......................................................................................... 36 3 ACCIDENT ANALYSIS ............................................................................................................................ 39 3.1 ACCIDENT TYPE SELECTION ....................................................................................................................... 39 3.2 ACCIDENT ANALYSIS PROCESS ................................................................................................................... 40 3.3 ANALYSIS INPUTS AND ASSUMPTIONS ........................................................................................................ 41 3.4 BEYOND DESIGN/EVALUATION BASIS ACCIDENTS ..................................................................................... 43 3.5 SOFTWARE QUALITY ASSURANCE .............................................................................................................. 46 4 EVALUATION OF EFFECTS OF MAJOR ACCIDENT TYPES ........................................................ 49 4.1 INTRODUCTION ........................................................................................................................................... 49 4.1.1 Information from Accident Analysis to Include in the DSA ..................................................................... 50 4.2 FIRE SCENARIO ANALYSIS .......................................................................................................................... 50 4.2.2 Fire Analysis ............................................................................................................................................ 52 4.2.2.1 Example Analytical Methods .............................................................................................................................. 54 4.2.2.1.1 Heat Release Rate ........................................................................................................................................ 54 4.2.2.1.2 Pool Fire Heat Release Rate ........................................................................................................................ 54 4.2.2.1.4 Flame Height ............................................................................................................................................... 56 4.2.2.1.5 Enclosure Fire Dynamics ............................................................................................................................. 57

Section 5

4.2.2.1.5.1 Pre-flashover ........................................................................................................................................ 57 4.2.2.1.5.2 Flashover.............................................................................................................................................. 58 4.2.2.1.6 Solid Fuel Ignition and Radiant Heating ...................................................................................................... 59 4.2.3 Source Term Calculation for Fire Scenarios ........................................................................................... 62 DOE-HDBK-1224-2018 vi 4.2.3.1 Effect on Hazardous Material.............................................................................................................................. 62 4.2.3.1.1 Determining MAR for the FIRE Event ........................................................................................................ 62 4.2.3.1.2 Determining DR and ARF/RF for the Fire Event ........................................................................................ 63 4.2.3.2 Thermal Effects ................................................................................................................................................... 64 4.2.3.3 Smoke Damage ................................................................................................................................................... 65 4.3 EXPLOSION SCENARIO ANALYSIS ............................................................................................................... 66 4.3.1 Explosion Event Types and Scenarios ...................................................................................................... 66 4.3.2 Explosions Analysis ................................................................................................................................. 71 4.3.2.1 Pressure Vessel Burst .......................................................................................................................................... 71 4.3.2.1.1 Blast Effect from Pressure Vessel Burst ...................................................................................................... 72 4.3.2.1.2 Fragmentation from Pressure Vessel Burst .................................................................................................. 80 4.3.2.1.3 Thermal Effects from Pressure Vessel Burst ............................................................................................... 87 4.3.2.2 BLEVE ............................................................................................................................................................... 87 4.3.2.2.1 Blast Effect from BLEVE ........................................................................................................................ 88 4.3.2.2.2 Fragmentation from BLEVE .................................................................................................................... 88 4.3.2.2.3 Thermal Effects from BLEVE ................................................................................................................. 88

Section 6

4.3.2.3 Vapor Cloud Explosion ..................................................................................................................................... 89 4.3.2.3.1 Vapor Cloud Deflagration ........................................................................................................................... 90 4.3.2.3.2 Vapor Cloud Detonation .............................................................................................................................. 90 4.3.2.3.3 VAPOR CLOUD Deflagration AND Detonation PRACTICAL DIFFERENCES ..................................... 90 4.3.2.3.4 Blast Effect from Vapor Cloud Explosion ................................................................................................... 91 4.3.2.3.5 Fragmentation from Vapor Cloud Explosion ............................................................................................... 99 4.3.2.3.6 Thermal Effect from Vapor Cloud Explosion .............................................................................................. 99 4.3.2.4 Flash Fire .......................................................................................................................................................... 99 4.3.3 Consequences of Explosions BEYOND RELEASES OF HAZARDOUS MATERIALS ............................ 99 4.3.3.1 Damage Caused by Overpressure (Detonations and Deflagrations) .................................................................... 99 4.3.3.2 Damage Caused by Fragmentation .................................................................................................................... 101 4.3.3.3 Damage Caused by Thermal Effects to Facility workers ................................................................................... 101 4.3.3.4 Damage Caused by Thermal Effects to SSCs .................................................................................................... 104 4.3.4 Source Term Calculation for Explosion Scenarios ................................................................................ 105 4.3.4.1 Explosion MAR ................................................................................................................................................ 105 4.3.4.2 Explosion Damage Ratio (DR).......................................................................................................................... 105 4.3.4.3 Explosion ARF/RF ............................................................................................................................................ 106 4.3.4.4 Explosion Release Duration .............................................................................................................................. 106 4.3.5 Case: Source Term Calculation for Hydrogen Explosion ..................................................................... 107 4.3.5.1 GAS Explosion source term (ST) .................................................................................................................... 109 4.3.5.2 Gas deflagration Source Term (ST) ................................................................................................................ 110 4.4 SPILLS ....................................................................................................................................................... 112 4.4.1 Types of Loss of Confinement/Spills and Scenarios ............................................................................... 112 4.4.2 Analysis of Spills .................................................................................................................................... 113

Section 7

4.4.2.1 Glovebox Spills ............................................................................................................................................... 114 4.4.2.2 Material Handling and Waste Container Accidents ........................................................................................ 114 4.4.2.3 Over-pressurizations ....................................................................................................................................... 115 4.4.2.3.1 Pressurized Powder Releases ..................................................................................................................... 115 4.4.2.3.2 Pressurized Liquid Releases ...................................................................................................................... 115 4.4.2.4 Aerodynamic Entrainment .............................................................................................................................. 115 4.5 ANALYSIS OF CHEMICAL REACTIONS ....................................................................................................... 116 4.5.1 Organic-based Ion Exchange Resin Reaction ........................................................................................ 116 4.5.1.1 Reactions of Nitric Acid with Organic Materials ............................................................................................ 117 4.5.1.2 Composition and Reactions of Ion Exchange Resins ...................................................................................... 118 4.5.1.3 Chemical Degradation of Ion Exchange Resins .............................................................................................. 118 4.5.1.4 Radiation Effects on Ion Exchange Resins ...................................................................................................... 119 4.5.1.5 Incidents Involving Chemical Reactions of Resins ......................................................................................... 119 4.5.1.6 Discussion of Accident Conditions .................................................................................................................. 120 4.5.2 “Red Oil” Reaction................................................................................................................................ 120 4.5.2.1 Background and Prior Red Oil Incidents ......................................................................................................... 120 4.5.2.2 Discussion of Red Oil Accident Conditions .................................................................................................... 123 4.5.2.3 Approach to Preventing Red Oil Accidents ..................................................................................................... 124 4.5.2.4 Preventive Controls ......................................................................................................................................... 125 4.5.3 Organic Reaction Event ......................................................................................................................... 125 4.5.3.1 Background and Discussion ............................................................................................................................ 125 DOE-HDBK-1224-2018 vii

Section 8

4.5.3.2 Analytical and Test Methods ........................................................................................................................... 127 4.5.3.3 Prevention and Mitigation ............................................................................................................................... 127 4.5.4 Hydroxylamine Nitrate Reaction............................................................................................................ 127 4.5.4.1 Prevention and Mitigation ............................................................................................................................... 128 4.5.5 Chemical Reactions Accident Analysis .................................................................................................. 128 4.6 NATURAL PHENOMENA HAZARD EVENTS................................................................................................. 129 4.6.1 NPH Event Types ................................................................................................................................... 129 4.6.2 NPH Event Analysis Overview ............................................................................................................... 129 4.6.2.1 Accident Analysis for A New Nuclear Facility or Major Modification of an existing nuclear facility............. 129 4.6.2.2 Accident Analysis for Existing Nuclear Facility DSA ...................................................................................... 130 4.6.2.3 General Methodology ........................................................................................................................................ 132 4.6.3 Seismic Events ........................................................................................................................................ 133 4.6.4 Extreme Wind Events ............................................................................................................................. 134 4.6.5 Flood and Precipitation Events ............................................................................................................. 134 4.6.6 Lightning Events .................................................................................................................................... 135 4.6.7 Volcanic Eruption and Ashfall Events ................................................................................................... 138 4.6.8 Wildland Fires ....................................................................................................................................... 139 4.6.8.1 Wildland Fire Event Description and Analysis ................................................................................................. 140 4.6.8.2 Example: Wildland Fire Facility/Structure Hazard ASSESSMENT ................................................................. 142 4.7 MAN-MADE EXTERNAL EVENTS .............................................................................................................. 147 4.7.1 Aircraft Crashes ..................................................................................................................................... 148 4.7.1.1 Screening Analysis ............................................................................................................................................ 148 4.7.1.2 Aircraft Crash Damage Assessment ................................................................................................................ 151

Section 9

4.7.2 Vehicle Crashes ..................................................................................................................................... 151 4.7.2.1 Vehicle Crash into Facility ............................................................................................................................... 151 4.7.2.2 Onsite Transportation Accident ........................................................................................................................ 151 4.7.3 Loss of Power to Safety-related SSCs .................................................................................................... 153 5 SOURCE TERM ANALYSIS .................................................................................................................. 154 5.1 INTRODUCTION ......................................................................................................................................... 154 5.2 RADIOLOGICAL SOURCE TERM COMPONENTS .......................................................................................... 154 5.2.1 Material at Risk ..................................................................................................................................... 157 5.2.1.1 Overview of Requirements, Guidance, and Practices for .................................................................................. 157 Identifying MAR ............................................................................................................................................................ 157 5.2.1.2 Examples for Identifying MAR ......................................................................................................................... 158 5.2.2 Determining the Damage Ratio (DR) .................................................................................................... 162 5.2.2.1 Overview of Requirements, Guidance, and Practices........................................................................................ 162 5.2.2.2 Examples .......................................................................................................................................................... 163 5.2.3 Airborne Release Fraction and Respirable Fraction ............................................................................. 168 5.2.3.1 Overview of Requirements, Guidance, and Practices for Determining ARF/RF ............................................... 168 5.2.3.2 Examples for Determining ARF/RF .................................................................................................................. 181 5.2.4 Airborne Release Rate ........................................................................................................................... 183 5.2.5 Leakpath Factor ..................................................................................................................................... 184 5.2.5.1 Filtration LPF .................................................................................................................................................... 185 5.2.5.2 LPF Modeling ................................................................................................................................................... 186 5.3 CHEMICAL RELEASE SOURCE TERMS........................................................................................................ 187 5.4 APPROPRIATENESS OF SOURCE TERMS ..................................................................................................... 190

Section 10

5.4.1 Adequate Technical Basis to Depart from Default or Bounding Values ................................................ 190 6 ATMOSPHERIC DISPERSION ............................................................................................................. 193 6.1 INTRODUCTION ......................................................................................................................................... 193 6.2 KEY RECEPTORS ....................................................................................................................................... 194 6.3 METEOROLOGICAL PARAMETERS AFFECTING DISPERSION ....................................................................... 195 6.3.1 Wind Speed, Wind Direction, and Wind Direction Standard Deviations ............................................... 196 6.3.1.1 Wind Speed ....................................................................................................................................................... 196 6.3.1.2 Wind Direction .................................................................................................................................................. 197 6.3.1.3 Wind Direction Standard Deviations................................................................................................................. 197 6.3.2 Wind Speed Profile with Height ............................................................................................................. 197 DOE-HDBK-1224-2018 viii 6.3.3 Mixing Layer Height .............................................................................................................................. 198 6.3.4 Vertical Temperature Profiles ............................................................................................................... 199 6.3.5 Precipitation .......................................................................................................................................... 200 6.3.6 Temperature and Relative Humidity ...................................................................................................... 200 6.4 GAUSSIAN PLUME MODEL FOR NEUTRALLY BUOYANT PLUMES .............................................................. 200 6.4.1 Basic Gaussian Equations ..................................................................................................................... 200 6.4.2 Gaussian Plume Widths and Depths ...................................................................................................... 203 6.4.2.1 Atmospheric Stability Classes ........................................................................................................................... 204 6.4.2.2 Methods of Calculating Stability Classes .......................................................................................................... 205 6.4.2.3 Additional Stability Classification Techniques ................................................................................................ 208 6.4.2.4 Methods of Calculating Plume Width and Plume Thickness ............................................................................ 210

Section 11

6.5 CHARACTERIZATION OF METEOROLOGICAL AND SITE DATA ................................................................... 216 6.5.1 Persistence ............................................................................................................................................. 218 6.5.2 Joint Frequency Distribution (JFD) ...................................................................................................... 218 6.5.3 Full Data Set Sampling .......................................................................................................................... 219 6.5.4 Treatment of Calm and Variable Winds ................................................................................................. 219 6.6 METEOROLOGICAL DATA ADEQUACY FOR SAFETY ANALYSIS ................................................................. 221 6.7 TYPICAL AND UNFAVORABLE DISPERSION CONDITIONS .......................................................................... 222 6.8 SPECIAL GAUSSIAN MODELING CONSIDERATIONS ................................................................................... 224 6.8.1 Averaging-Time and Large Eddy Plume Meander ................................................................................ 224 6.8.2 Mechanical Turbulence Due to Surface Roughness............................................................................... 226 6.8.3 Aerodynamic Effects of Buildings .......................................................................................................... 229 6.8.4 Plume Modifications Through Decay, Daughter In-Growth, and Deposition Processes ...................... 232 6.8.5 Principles Governing Plume Rise and Downwash ................................................................................ 236 6.8.5.1 Momentum Plume Rise ..................................................................................................................................... 237 6.8.5.2 Buoyancy Plume Rise ....................................................................................................................................... 238 6.8.6 PLUME IMPACTION ............................................................................................................................ 239 6.9 DOE CENTRAL REGISTRY OF RADIOLOGICAL DISPERSION AND CONSEQUENCE ANALYSIS CODES.......... 240 6.9.1 MACCS2 ................................................................................................................................................ 248 6.9.2 GENII ..................................................................................................................................................... 249 6.9.3 HOTSPOT .............................................................................................................................................. 250 6.10 ATMOSPHERIC DISPERSION OPTIONS IN DOE-STD-3009-2014 ............................................................... 250 6.11 ATMOSPHERIC DISPERSION MODELING PROTOCOL ............................................................................. 251 6.12 NON-GAUSSIAN DISPERSION MODELING .................................................................................................. 258 6.12.1 Dispersion under Extreme Wind or Tornado Event ............................................................................... 258 6.12.2 Finite Plume External Dose Modeling ................................................................................................... 260 6.12.3 Plumes from Energetic Events ............................................................................................................... 260

Section 12

6.13 CO-LOCATED WORKER DISPERSION FACTOR ............................................................................................ 263 6.13.1 Technical Report for CW χ/Q value ....................................................................................................... 263 6.13.2 Alternate χ/Q Value Justification ........................................................................................................... 263 6.13.2.1 Hand Calculations for a χ/Q Value Where the Default Value is Not Appropriate ........................................... 264 6.13.2.2 Computer Code Modeling for a χ/Q Value Where the Default Value is Not Appropriate ............................... 265 7 AQUATIC DISPERSION AND GROUNDWATER TRANSPORT .................................................... 267 7.1 OVERVIEW ................................................................................................................................................ 267 7.2 NRC REGULATORY GUIDANCE ON AQUATIC DISPERSION AND DOSE CALCULATION ...... 268 7.3 DOCUMENTED SAFETY ANALYSIS APPROACH .......................................................................................... 268 7.4 LIQUID EFFLUENT RELEASE KEY RECEPTORS .......................................................................................... 269 7.5 LIQUID EFFLUENT RELEASE REDISTRIBUTION MECHANISMS AND UPTAKE .............................................. 269 7.5.1 Initial Mixing ......................................................................................................................................... 269 7.5.2 Far-Field Mixing ................................................................................................................................... 269 7.5.3 Deposition And Resuspension In Sediments........................................................................................... 270 7.5.4 Uptake Mechanisms ............................................................................................................................... 271 7.6 AQUATIC DISPERSION MODELS AND COMPARISONS ................................................................................. 271 7.6.1 Classes of Aquatic Dispersion Models ................................................................................................... 271 7.6.2 Aquatic Dispersion Model Attributes and Characteristics .................................................................... 272 7.6.3 Comparison of Aquatic Dispersion Models ........................................................................................... 273 DOE-HDBK-1224-2018 ix 7.6.3.1 LADTAP2 ......................................................................................................................................................... 273 7.6.3.2 STREAM2 ....................................................................................................................................................... 274 7.6.3.3 GENII 2.10.1 .................................................................................................................................................... 274 7.6.3.4 RIVER-RAD .................................................................................................................................................... 274 7.6.3.5 DISPERS.......................................................................................................................................................... 274

Section 13

7.7 GROUNDWATER TRANSPORT .................................................................................................................... 275 7.7.1 Overview ................................................................................................................................................ 275 7.7.2 Groundwater Flow and Contaminant Transport ................................................................................... 275 7.7.3 Tritium in Sediments .............................................................................................................................. 276 7.7.4 Groundwater Transport Model Considerations ..................................................................................... 276 8 RADIOLOGICAL CONSEQUENCE ASSESSMENT .......................................................................... 278 8.1 FUNDAMENTALS ....................................................................................................................................... 278 8.1.1 Types of Radiation ................................................................................................................................. 279 8.1.2 Nuclear Fission ...................................................................................................................................... 280 8.1.3 Radioactivity .......................................................................................................................................... 281 8.2 EFFECTS OF RADIATION ON THE BODY ..................................................................................................... 282 8.2.1 Dose Evaluations ................................................................................................................................... 282 8.2.2 Inhalation (Plume) Dose ........................................................................................................................ 285 8.2.3 Cloudshine Dose .................................................................................................................................... 288 8.2.4 Groundshine Dose ................................................................................................................................. 288 8.2.5 Prompt (Direct) Dose ............................................................................................................................ 289 8.2.6 Plutonium Equivalent Curies ................................................................................................................. 290 8.3 HEALTH RISKS .......................................................................................................................................... 290 8.3.1 High-LET Radiation............................................................................................................................... 291 8.3.2 Low-LET Radiation ................................................................................................................................ 291 8.3.3 Acute Health Risks ................................................................................................................................. 292

Section 14

9 CHEMICAL DISPERSION AND CONSEQUENCE ANALYSIS ....................................................... 293 9.1 INTRODUCTION ......................................................................................................................................... 293 9.2 CHEMICAL CONSEQUENCE ASSESSMENT FUNDAMENTALS ....................................................................... 294 9.3 CHEMICAL SCREENING CRITERIA ............................................................................................................. 295 9.4 CHEMICAL HEALTH EFFECTS ON THE HUMAN BODY ................................................................................ 297 9.4.1 Chemical Concentrations and Exposure Time ....................................................................................... 297 9.4.1.1 Chemical Exposure Time .................................................................................................................................. 297 9.4.1.2 Protective Action Criteria for Releases of a Single Chemical ........................................................................... 299 9.4.1.3 Protective Action Criteria for Releases of Multiple Chemicals ........................................................................ 300 9.4.2 Modes of Exposure and Routes of Entry of Toxic Chemicals that Result in Health Effects ................... 300 9.4.3 Toxic Chemical Acute Exposure Limits ................................................................................................. 301 9.4.3.1 EPA Acute Exposure Guideline Levels ............................................................................................................ 301 9.4.3.2 AIHA Emergency Response Planning Guidelines ............................................................................................ 302 9.4.3.3 DOE PAC/TEELs ............................................................................................................................................. 302 9.4.4 Chemical Mixture Methodology ............................................................................................................. 306 9.4.5 Chronic Health Effects of Toxic Chemicals on the Human Body: Carcinogenicity, Mutagenicity, and Teratogenicity ................................................................................................................................................... 307 9.5 TOXIC CHEMICAL RELEASE PHENOMENOLOGY AND SUBSEQUENT ATMOSPHERIC TRANSPORT AND DIFFUSION ............................................................................................................................................................. 308 9.5.1 Pressurized Liquids: Two-Phase Flow Toxic Chemical Release .......................................................... 308 9.5.1.1 FLASHING FRACTION AND AEROSOL FORMATION ............................................................................. 309 9.5.1.2 TWO-PHASE RELEASE OF CHLORINE FROM A PIPE ............................................................................. 312 9.5.2 Pressurized Gases: Choked Flow Toxic Chemical Release ................................................................... 314 9.5.2.2 VAPOR OUTFLOW FROM BREACH OF A PIPELINE................................................................................ 317 9.5.2.3 OUTFLOW FROM A CYLINDRICAL TANK ............................................................................................... 318 9.5.2.4 OUTFLOW FROM A SPHERICAL TANK ..................................................................................................... 320 9.5.2.5 OUTFLOW FROM PROCESS VESSELS OF OTHER VARIOUS SHAPES ................................................. 321

Section 15

9.5.3 Dense Gas Toxic Chemical Release And Dispersion ............................................................................. 321 9.5.4 Non-Pressurized Liquid Release ............................................................................................................ 323 9.5.4.1 Convective Boiling............................................................................................................................................ 324 DOE-HDBK-1224-2018 x 9.5.4.2 Conductive Boiling ........................................................................................................................................... 325 9.5.4.3 Nitric Acid and Carbon Tetrachloride Pool Evaporation Rates ......................................................................... 325 9.5.4.3.2 Carbon Tetrachloride Pool Evaporation..................................................................................................... 329 9.5.5 Energetic Events: Fires, Deflagrations, Detonations, Delayed Ignition Explosions, and Bleves ......... 334 9.6 METEOROLOGICAL PARAMETERS AFFECTING TOXIC CHEMICAL CONSEQUENCE ANALYSIS .................... 335 9.6.1 Temperature Effects ............................................................................................................................... 336 9.6.2 Relative Humidity Effects ....................................................................................................................... 336 9.7 TOXIC CHEMICAL ATMOSPHERIC TRANSPORT AND DIFFUSION MODELS .................................................. 336 9.7.1 Neutrally-Buoyant Gaussian Models ..................................................................................................... 337 9.7.1.1 ALOHA............................................................................................................................................................. 337 9.7.1.2 EPIcode ............................................................................................................................................................. 339 9.7.1.3 Chemical Dispersion Analysis with ALOHA and EPIcode .............................................................................. 340 9.7.2 Dense Gas Dispersion Models ............................................................................................................... 342 9.7.2.1 ALOHA............................................................................................................................................................. 343 9.7.2.2 DEGADIS ......................................................................................................................................................... 343 9.7.2.3 HGSYSTEM .................................................................................................................................................... 344 9.7.2.4 SLAB ................................................................................................................................................................ 344 9.7.3 Variable Trajectory Dispersion Models ................................................................................................. 345 9.7.4 Research-Grade Dispersion Models ...................................................................................................... 345

Section 16

9.8 TOXIC CHEMICAL CONSEQUENCE SCOPING METHODOLOGY TO EXCEED PAC/TEEL VALUES ................ 345 9.8.1 Gas, Powder, and Solid Release Model ................................................................................................. 346 9.8.2 Liquid Evaporation Scoping Calculation Model ................................................................................... 347 9.8.3 Screening Method for Maximally-Exposed Offsite Individual (MOI) High Consequence ..................... 349 9.9 EXAMPLE TOXIC CHEMICAL CALCULATIONS ............................................................................................ 350 9.9.1 Example 1: Calculate Ammonia Gas Quantity that Exceeds PAC/TEEL-3 at the CW ......................... 351 9.9.2 Example 2: Calculate Aluminum Oxide Powder Quantity that Exceeds PAC/TEEL-3 at the CW........ 351 9.9.3 Example 3: Calculate Liquid 70% Nitric Acid Quantity that Exceeds PAC/TEEL Values at 1 Km Site Boundary .......................................................................................................................................................... 351 9.9.4 Example 4: Calculate Liquid 55% Hydrofluoric Acid Quantity that Exceeds PAC/TEEL Values at 1 Km Site Boundary.................................................................................................................................................... 353 10 HAZARD CONTROL SELECTION AND CLASSIFICATION ......................................................... 354 10.1 HAZARD CONTROL SELECTION ................................................................................................................. 355 10.1.1 Hazard Control Selection Process ......................................................................................................... 355 10.1.1.1 Hazard and Accident Analysis Input to Control Selection .............................................................................. 355 10.1.1.2 Hazard Control Types ..................................................................................................................................... 357 10.1.1.3 Use of Risk Matrices for Control Selection ..................................................................................................... 359 10.1.2 Hazard Control Selection Considerations ............................................................................................. 361 10.2 SAFETY CLASSIFICATIONS OF CONTROLS ................................................................................................. 362 10.2.1 Safety Class Designation ....................................................................................................................... 362 10.2.2 Safety Significant Designation ............................................................................................................... 362 10.2.3 Classification of Other Hazard Controls ............................................................................................... 362 10.3 EVALUATION OF EXISTING FACILITIES WITH MITIGATED OFFSITE CONSEQUENCE ESTIMATES OVER THE EVALUATION GUIDELINE ....................................................................................................................................... 363

Section 17

APPENDIX A: HAZARD ANALYSIS TABLE DEVELOPMENT .................................................................... 18 A.1 SCENARIO DESCRIPTION ............................................................................................................................. 18 A.2 INITIATING EVENT FREQUENCY .................................................................................................................. 18 A.3 UNMITIGATED CONSEQUENCE EVALUATION .............................................................................................. 19 A.4 SAFETY FUNCTIONS .................................................................................................................................... 19 A.5 PREVENTIVE FEATURES (DESIGN AND ADMINISTRATIVE) .......................................................................... 20 A.6 METHOD OF DETECTION ............................................................................................................................. 20 A.7 MITIGATIVE FEATURES (DESIGN AND ADMINISTRATIVE) ........................................................................... 20 A.8 SSC SAFETY CONTROL SUITE AND SAFETY FUNCTIONS ............................................................................. 21 A.9 MITIGATED CONSEQUENCES ....................................................................................................................... 21 A.10 PLANNED ANALYSES, ASSUMPTIONS AND RISK/OPPORTUNITY IDENTIFICATION ....................................... 21 A.11 HAZARDS EVALUATION TABLE .................................................................................................................. 22 DOE-HDBK-1224-2018 xi APPENDIX B: CRITICALITY ACCIDENTS ........................................................................................................ 2 B.1 INTRODUCTION ............................................................................................................................................. 2 B.2 REGULATORY REQUIREMENTS, RECOMMENDATIONS AND GUIDANCE ......................................................... 3 B.2.1 Unmitigated Analysis ................................................................................................................................. 3 B.3 ACCIDENT FISSION YIELDS ........................................................................................................................... 4 B.3.1 Fission Yields of Solution and Solution-Like Systems ................................................................................ 4 B.3.2 Fission Yields of Non-Solution-Like Systems ............................................................................................. 7 B.3.2.1 Metals/Solids – One or a Few Large Pieces ......................................................................................................... 7 B.3.2.2 Dry, unmoderated Solids – Numerous Small Pieces, and Large Arrays .............................................................. 8 B.3.3 Fission Yields of Autocatalytic Accidents .................................................................................................. 8 B.4 EVALUATION OF DIRECT RADIATION DOSES ................................................................................................ 8 B.5 CRITICALITY ACCIDENT SOURCE TERMS ...................................................................................................... 8

Section 18

B.5.1 Fission Product Inventories ....................................................................................................................... 8 B.5.2 Particulate Release and Health Related Parameters ................................................................................. 9 B.6 CRITICALITY ACCIDENT EXAMPLE ............................................................................................................. 10 DOE-HDBK-1224-2018 xii ACRONYMS AC Administrative Control or Alternating Current ACGIH American Conference of Government Industrial Hygienists AED Aerodynamic Equivalent Diameter AEGL Acute Exposure Guideline Level AICC Adiabatic, Constant-Volume Combustion AIHA American Industrial Hygienist Association AMAD Activity Median Aerodynamic Diameter ANS American Nuclear Society ANSI American National Standards Institute APAC Accident Phenomenology and Consequence ARF Airborne Release Fraction ASCE American Society of Civil Engineers ASME American Society of Mechanical Engineers ASTM American Society for Testing and Materials BC Building Construction BDBA Beyond Design Basis Accident BEBA Beyond Evaluation Basis Accident BEU Beyond Extremely Unlikely BLEVE Boiling Liquid Expanding Vapor Explosion BNL Brookhaven National Laboratory BR Breathing Rate BST Building Source Term CCPS Center for Chemical Process Safety CDC Centers for Disease Control CFAST Consolidated Model of Fire and Smoke Transport CFD Computational Fluid Dynamics CFR Code of Federal Regulations CMM Chemical Mixture Methodology CR Central Registry CSE Criticality Safety Evaluation CTH Cloud Top Height CW Co-located Worker DBA Design Basis Accident DCF Dose Conversion Factor DDT Deflagration to Detonation Transition DF Decontamination Factor DG Dense Gas DNFSB Defense Nuclear Facilities Safety Board DOE Department of Energy DOS Disk Operating System DOT Department of Transportation DR Damage Ratio DSA Documented Safety Analysis DTA Differential Thermal Analysis DOE-HDBK-1224-2018 xiii EBA Evaluation Basis Accident EDE Effective Dose Equivalent EEGL Emergency Exposure Guidance Level EFCOG Energy Facility Contractor Group EG Evaluation Guideline EPA Environmental Protection Agency ERPG Emergency Response Planning Guideline EU Extremely Unlikely FDC Flood Design Category FDT Fire Dynamics Tool FGR Federal Guidance Report FHA Fire Hazards Analysis FMEA Failure Modes and Effects Analysis FTF Filter Test Facility FW Facility Worker GEP Good Engineering Practice GNB Gaussian Neutrally Buoyant GRF German Research Foundation HA Hazard Analysis HAZOP Hazard and Operational Analysis HC Hazard Category HCN Health Code Number HDBK Handbook HE High Explosive HEPA High Efficiency Particulate Air HPR Highly Protected Risk HRR Heat Release Rate HSDB Hazardous Substances Data Bank IACR International Association of Cancer Registries ICRP International Council on Radiation Protection IDLH Immediately Dangerous to Life and Health IEEE Institute of Electrical and Electronics Engineers ILA Immediate Landscaped Area INL Idaho National Laboratory IST Initial Source Term JFD Joint Frequency Distribution LANL Los Alamos National Laboratory LCF Latent Cancer Fatality LEL Lower Explosive Limit LET Linear Energy Transfer LFL Lower Flammability Limit LOC Level of Concern LPF Leak Path Factor LPG Liquified Petroleum Gas DOE-HDBK-1224-2018 xiv MAR Material at Risk MAK-Wert Maximale Arbeitsplatz-Konzentration MOI Maximally Exposed Offsite Individual MW Molecular Weight

Section 19

NAC/AEGL National Advisory Committee for Acute Exposure Guideline Levels NARAC National Atmospheric Release Advisory Center NASA National Aeronautics and Space Administration NCRP National Council on Radiation Protection NDC Natural Phenomena Hazard Design Category NEPA National Environmental Policy Act NFDRS National Fire Rating Danger System NIOSH National Institute for Occupational Safety and Health NIST National Institute of Standards and Technology NNSA National Nuclear Security Administration NNSS Nevada Nuclear Security Site NOAA National Oceanic and Atmospheric Administration NPH Natural Phenomena Hazard NQA Nuclear Quality Assurance NRC Nuclear Regulatory Commission NTSB National Transportation Safety Board OSHA Occupational Safety and Health Administration PAC Protective Action Criteria PBL Planetary Boundary Layer PC Performance Category PDC Precipitation Design Category PEL Permissible Exposure Level PHA Preliminary Hazard Assessment PISA Potential Inadequacy of the Safety Analysis PNNL Pacific Northwest National Laboratory PRA Probabilistic Risk Assessment PrHA Process Hazard Analysis PSO Program Secretarial Office PUREX Plutonium Uranium Redox Extraction PWHA Probabilistic Wind Hazard Assessment RCRA Resource Conservation and Recovery Act REL Recommended Exposure Level RF Respirable Fraction RG Regulatory Guide RTECS Registry of Toxic Effects of Chemical Substances SAC Specific Administrative Control SAWG Safety Analysis Working Group SBAA Safety Basis Approval Authority SC Safety Class SCAPA Subcommittee for Consequence Assessment and Protective Actions SDC Seismic Design Category DOE-HDBK-1224-2018 xv SDS Safety Data Sheet SFPE Society of Fire Protection Engineers SIH Standard Industrial Hazard SIZ Structure Ignition Zone SME Subject Matter Expert SMP Safety Management Program SNL Sandia National Laboratories SNM Special Nuclear Material SQA Software Quality Assurance SRDT Solar Radiation Delta Temperature SRNL Savannah River National Laboratory SRS Savannah River Site SS Safety Significant SSC Structures, Systems, and Components ST Source Term STD Standard STEL Short-Term Exposure Level STP Standard Temperature and Pressure TBP Tri-Butyl Phosphate TED Total Effective Dose TEDE Total Effective Dose Equivalent TEEL Temporary Emergency Exposure Limit TF Topographical Feature TLV Threshold Limit Value TNO The Netherlands Organization TNT Trinitrotoluene TRU Transuranic TSL Technical Support Level TSR Technical Safety Requirement TWA Time-Weighted Average UEL Upper Explosive Limit UFL Upper Flammability Limit UL Underwriters Laboratories USQ Unreviewed Safety Question V & V Verification & Validation VDC Volcanic Design Category VP Vapor Pressure WDC Wind Design Category WEEL Workplace Environmental Exposure Limit WIPP Waste Isolation Pilot Plant Note: Definitions related to the DOE hazard and accident analysis process can be found in 10 CFR §830.3, DOE-STD-3009-2014 (or other Part 830 safe harbor), or DOE-HDBK-3010-94, Airborne Release Fractions/Rates and Respirable Fractions for Nonreactor Nuclear Facilities. Other definitions related to accident phenomenology for evaluation of potential consequences, such as physical and chemical effects, are provided in references cited in the text. DOE-HDBK-1224-2018 1 1 INTRODUCTION

Section 20

This Handbook contains methodology, data sources, and subject matter references for performing and reviewing hazard and accident analysis for Department of Energy (DOE) nonreactor nuclear facilities. The guidance offered supports development of a Documented Safety Analysis (DSA) required by 10 CFR1 Part 830, Nuclear Safety Management, Subpart B, “Safety Basis Requirements.” The Handbook uses as a starting point drafts of a report prepared by the Safety Analysis Working Group of the Energy Facility Contractors Group. This early effort was sponsored by DOE’s Office of Defense Programs (predecessor of NNSA) in the early 2000s. Although that report was not completed, some of its technical content has been incorporated into this Handbook. The Handbook describes best practices gleaned from development of DSAs throughout the DOE complex and from insights acquired in the development of DOE-STD-3009-2014, Preparation of Nonreactor Nuclear Facility Documented Safety Analysis. The Handbook provides many application examples that will be helpful to the analyst. 1.1 PURPOSE The principal purpose of this Handbook is to guide development of the DSA safety analysis for nuclear facilities in order to satisfy the requirements of a safe harbor method set out in 10 CFR Part 830, Subpart B. The safety analysis process consists of three main steps: • Hazard analysis (including hazard identification and evaluation); • Accident analysis (including accident scenario definition and consequence analysis); and • Preventive and mitigative control selection. DOE-STD-3009-2014 provides criteria and guidance organized in the above manner. Further, it includes lessons learned from use of DOE-STD-3009-94, Change Notice 3 (CN3), Preparation Guide for U.S. Department of Energy Nonreactor Nuclear Facility Documented Safety Analysis, and other safe harbor methods. Therefore, this Handbook uses excerpts from DOE-STD-3009-20142 as the starting point for the amplifying guidance and good practices, but the scope of the Handbook is not limited to that standard. The information in this Handbook is also relevant to other safe harbor methods for developing a safety basis document, such as DOE-STD-3011-2016, Preparation of Documented Safety Analysis for Interim Operations at DOE Nuclear Facilities, and DOE-STD-1120-2016, Preparation of Documented Safety Analysis for Decommissioning and Environmental Restoration Activities. The Handbook may also be use for upgrading existing DSAs to the new requirements of DOE-STD-3009-2014, or for updating DSAs for existing facilities based on their current safe harbor methodology. 1.2 OUTLINE This Handbook is organized as follows: • Chapter 2, Hazard Analysis, addresses hazard identification and evaluation, including hazard evaluation methods and safety control identification. 1 Code of Federal Regulations. 2 When used without a 2-digit or 4-digit year number after “DOE-STD-3009,” the term refers to both the 1994 and 2014 versions. If a specific version is meant to the exclusion of the other, the year will be stated. DOE-HDBK-1224-2018 2 • Chapter 3, Accident Analysis, provides a high level overview of the events that were identified in the hazard evaluation table to be evaluated for further accident analysis, provides an overview of the accident analysis process, and discusses two key topics: (1) assumptions and initial conditions; and (2) conservatism in analysis.

Section 21

• Chapter 4, Evaluation of Effects of Major Accident Types, addresses the analysis of accident scenarios. The various topics covered provide information for evaluating the magnitude of the accidents and the resulting accident environments, so that the amount of radioactive or other hazardous material affected is defined. Toxic chemicals are a subset of hazardous materials that require additional dispersion and consequence assessment. In addition to evaluation of potential consequences to facility workers, this information is necessary to determine the source term available for release from the facility, and to evaluate the capability of safety structures, systems, and components (SSCs) to survive the accident environments and provide required safety functions when called upon. • Chapter 5, Source Term Analysis, addresses development of the amount of radioactive material or toxic chemical released from a given confinement volume under the stress posed by insults from a hypothetical accident. Source term estimations include quantifying radioactive or toxic chemical material at risk, damage ratio, airborne release fractions or release rates, respirable fractions (for radioactive materials only), and leakpath factor. • Chapter 6, Atmospheric Dispersion, addresses atmospheric transport and diffusion, meteorological data, and the models available for consequence assessment of radioactive releases to the atmosphere. • Chapter 7, Aquatic Dispersion and Groundwater Transport, addresses surface water and ground water pathways, and the models available for consequence assessment of radioactive releases to aquatic water bodies and ground water. • Chapter 8, Radiological Consequence Assessment, addresses the different types of radiation and the health effects they can have on the human body, its organs, and its tissues, and how radiological doses to receptors of interest may be estimated. • Chapter 9, Chemical Dispersion and Consequence Analysis, addresses toxic chemical releases, their potential health effects and methods for estimating concentration at various distances. • Chapter 10, Hazard Control Selection and Classification, addresses selection of safety significant and safety class controls that are credited in the hazard evaluation or accident analysis. • Chapter 11 provides a complete list of references cited in the text. • Appendix A, Hazard Analysis Table Development, provides guidance on constructing this table which is discussed in Chapter 2. • Appendix B, Criticality Accidents, addresses this type of accident in greater detail. DOE-HDBK-1224-2018 3 2 HAZARD ANALYSIS This chapter addresses hazard analysis (HA) techniques for the identification and evaluation of hazards, and the identification of controls to prevent or mitigate accidents. Hazard control selection is addressed in Chapter 10. 2.1 ELEMENTS OF HAZARD ANALYSIS DOE-STD-30093 states that an HA consists of (a) hazard identification, (b) hazard categorization,4 and (c) hazard evaluation. Hazard evaluation includes identification and safety classification of controls to prevent or mitigate potential hazard or accident scenarios.5 2.2 HAZARD IDENTIFICATION AND CHARACTERIZATION

Section 22

The objective of hazard identification and characterization is to systematically and comprehensively identify radioactive and other hazardous materials within the facility, as well as natural phenomena hazards (NPHs) and external man-made events that may impact the facility and result in the release of these materials within the facility and to the environment. The hazard identification process includes characterizing hazardous materials (radiological and non-radiological) and energy sources, in terms of quantity, form and location. Examples of energy sources are falling objects, NPH-driven missiles, and other kinetic energy sources. Nuclear Criticality Hazard Evaluations are addressed in Section 2.3.2. For DSAs prepared in accordance with 10 CFR Part 830, Subpart B, the key to successful hazard identification is ensuring comprehensive identification of the hazards associated with the full scope of facility processes, associated operations such as handling of fissionable materials, radioactive or hazardous wastes, and work activities covered by the DSA. Hazard identification does not yield specific hazard scenarios to analyze. Rather, it yields initial data from which hazard scenarios are subsequently developed. The overall quality of hazard scenario definition will be in direct proportion to the accuracy and completeness of the initial hazard information gathered. The hazard identification process involves: • Hazard data gathering; • Summarizing hazard data in tables or data sheets; and • Identifying standard industrial hazards (SIHs) needing further evaluation.6 3 As discussed in Section 1.1, when used without a 2-digit or 4-digit year number after “DOE-STD-3009,” it refers to both the 1994 CN3 and 2014 versions of the DOE Standard. Otherwise, specific versions of DOE-STD-3009 are referenced throughout this Handbook. 4 This Handbook does not address hazard categorization. Requirements and guidance for performing hazard categorization are provided in DOE-STD-1027-92, CN1. 5 DOE-STD-3009-2014 defines a “hazard scenario” as “An event or sequence of events associated with a specific hazard, having the potential to result in undesired consequences identified in the hazard evaluation” and defines an “accident” as “A specific event or progression of a sequence of events resulting from an initiating event that is followed by any number of subsequent events that may lead to a release of radioactive or other hazardous material and/or exposure to a predefined receptor.” The term “hazardous condition” has often been used in previous safety basis hazard evaluations instead of “hazard scenario.” For the purposes of this Handbook, both terms are used interchangeably in Chapters 2, 3, 4, and 10 and in Appendix A when referring to the hazard evaluation. 6 Such hazards might include electrical faults that could lead to a fire, or explosions harmful to nearby workers. DOE-HDBK-1224-2018 4 Comprehensive identification of hazards is best accomplished by a team comprised of safety analysts, system/process engineers, operational and support staff, industrial hygienists, and various subject matter experts (SMEs), as needed. 2.2.1 HAZARD DATA GATHERING Gathering of hazard data commences with review of existing documentation, which includes the following:

Section 23

• Facility and process descriptions (including available drawings and flow sheets); • Historical radioactive and hazardous material inventory records; • Existing safety documentation;7 • Operating and support procedures; • Previous occurrence reports for the facility and relevant reports from general industry; and • Facility design reports setting out the scope of new operations. Once documented sources of hazards have been reviewed, a physical walkdown of the facility is undertaken to verify them and their locations. Such walkdowns are conducted with a floor plan noting the most significant details. Useful details may include information such as gloveboxes or containers, inventories and energy sources, system interconnections, and piping routes. Other details can be recorded during the walkdown in checklists and notebooks for completeness. If the facility is being designed, the floor plan can still be conceptually walked down using process and instrumentation drawings and process engineering drawings at whatever stage of development they are available. Hazard analysis is performed early in the project justification phase and during development of the Safety Design Strategy, continues during development of safety design basis documents as the design progresses, and is updated during development of the final DSA to authorize operations. If process and instrumentation drawings are based on evolving design of a new facility, the hazard identification will need to be reverified against the final design and as-built construction to support authorizing operations. The overall hazard identification and analysis is an iterative process during the design and construction phase of the project. 2.2.2 HAZARD DATA RECORDING Checklists are used to ensure the hazard identification process is comprehensive and thorough. Checklists provide a generic list of hazards to look for in terms of radioactive and hazardous material types, energy sources, moving components, and the potential for falling objects. Hazard identification preparers use such checklists to systematically identify the presence or absence of hazards for a given area, from individual components/operations (e.g., gloveboxes) to entire rooms. The raw data of a hazard identification can be recorded in a variety of ways. The critical information to be specifically noted in any recording mechanism is the hazard itself, its type, its magnitude and location, and sufficient descriptive notes to allow the HA team to place individual hazards in an appropriate context. Materials of concern for release (or potential hazards in direct contact with materials of concern) are identified separately. Bounding inventory values of radioactive or hazardous materials are needed for the development of scenario-specific material at risk (MAR) for the hazard evaluation and accident analysis, consistent with the maximum quantities of material that are stored and used in facility processes. 7 Safety data sheets (SDSs); waste data sheets; health and safety plans; procurement and inventory records; and annual reports, such as the Emergency Planning and Community Right-to-Know Act, Tier II Chemical, and EPA Toxic Release Inventory. DOE-HDBK-1224-2018 5 Inventory data may be obtained from flowsheets, vessel sizes, contamination analyses, maximum historical inventories, and similar sources.

Section 24

An example of a checklist for a DOE nuclear facility is shown in Table 2-1. The “Disposition” column is optional and is discussed in Sections 2.2.3 and 2.2.4. Other types of checklists that have been developed in the DOE Complex, and which may reflect site-specific and facility-specific hazards. These can be used to identify hazards and energy sources. Commercial industry practices for hazard identification, such as those described in the Center for Chemical Process Safety’s Guidelines for Hazard Evaluation Procedures (CCPS, 2008), provide guidance for the development of a comprehensive identification of hazards. Table 2-1. Hazard Identification Checklist Example. (Identify facility, location, or process) No. Item Hazard present (Y/N) Description (quantity, form, location) Disposition (SIH, accident initiator/contributor) 1.0 Electrical 1.1 Battery banks 1.2 Cable runs 1.3 Diesel generators 1.4 Electrical equipment 1.5 Heaters 1.6 High voltage (> 600V) 1.7 Locomotive, electrical 1.8 Motors 1.9 Power tools 1.10 Pumps 1.11 Service outlets, fittings 1.12 Switchgear 1.13 Transformers 1.14 Transmission lines 1.15 Wiring/underground wiring 1.16 Other 2.0 Thermal 2.1 Boilers 2.2 Bunsen burners/hot plates 2.3 Electrical equipment 2.4 Electrical wiring 2.5 Engine exhaust 2.6 Furnaces 2.7 Heaters 2.8 Lasers 2.9 Steam lines 2.10 Welding surfaces 2.11 Welding torches 2.12 Other 3.0 Pyrophoric Material 3.1 Pu and U metal 3.2 Other (e.g., Zr) 4.0 Spontaneous Combustion 4.1 Cleaning/decontamination solvents 4.2 Fuels (gasoline, diesel) DOE-HDBK-1224-2018 6 No. Item Hazard present (Y/N) Description (quantity, form, location) Disposition (SIH, accident initiator/contributor) 4.3 Grease 4.4 Nitric acid and organics 4.5 Paint solvents 4.6 Other 5.0 Open Flame 5.1 Bunsen burners 5.2 Welding/cutting torches 5.3 Other 6.0 Flammables 6.1 Cleaning/decontamination solvents 6.2 Flammable gases 6.3 Flammable liquids 6.4 Gasoline 6.5 Natural gas 6.6 Paint/paint solvent 6.7 Propane 6.8 Spray paint 6.9 Other 7.0 Combustibles 7.1 Paper/wood products 7.2 Petroleum-based products 7.3 Plastics 7.4 Other 8.0 Chemical Reactions 8.1 Concentration 8.2 Disassociation 8.3 Exothermic 8.4 Incompatible chemical mixing 8.5 Uncontrolled chemical reactions 8.6 Other 9.0 Explosive Material 9.1 Caps 9.2 Dusts 9.3 Dynamite 9.4 Electric squibs 9.5 Explosive chemicals 9.6 Explosive gases 9.7 Hydrogen 9.8 Hydrogen (batteries) 9.9 Nitrates 9.10 Peroxides 9.11 Primer cord 9.12 Propane 9.13 Other (e.g., NiCd batteries) 10.0 Kinetic (Linear and Rotational) 10.1 Acceleration/deceleration 10.2 Bearings 10.3 Belts 10.4 Carts/dollies 10.5 Centrifuges 10.6 Crane loads (in motion) DOE-HDBK-1224-2018 7 No. Item Hazard present (Y/N) Description (quantity, form, location) Disposition (SIH, accident initiator/contributor) 10.7 Drills 10.8 Fans 10.9 Firearm discharge 10.10 Fork lifts 10.11 Gears 10.12 Grinders 10.13 Motors 10.14 Power tools 10.15 Presses/shears 10.16 Rail cars 10.17 Saws 10.18 Vehicles 10.19 Vibration 10.20 Other 11.0 Potential (Pressure) 11.1 Autoclaves 11.2 Boilers 11.3 Coiled springs 11.4 Furnaces 11.5 Gas bottles 11.6 Gas receivers 11.7 Pressure vessels 11.8 Pressurized system (e.g., air) 11.9 Steam headers and lines 11.10 Stressed members 11.11 Other 12.0 Potential (Height/Mass) 12.1 Cranes/hoists 12.2 Elevated doors 12.3 Elevated work surfaces 12.4 Elevators 12.5 Lifts 12.6 Loading docks 12.7 Mezzanines 12.8 Floor pits 12.9 Scaffolds and ladders 12.10 Stacked material 12.11 Stairs 12.12 Other 13.0 Internal Flooding Sources 13.1 Domestic water piping 13.2 Fire suppression piping 13.3 Process water piping 13.4 Other 14.0 Physical 14.1 Sharp edges or points 14.2 Pinch points 14.3 Confined spaces 14.4 Tripping 14.5 Other 15.0 Radioactive Material

Section 25

DOE-HDBK-1224-2018 8 No. Item Hazard present (Y/N) Description (quantity, form, location) Disposition (SIH, accident initiator/contributor) 15.1 Radioactive material 16.0 Hazardous Material (Toxicological, Chemical, Biological) 16.1 Asphyxiants 16.2 Bacteria/viruses 16.3 Beryllium and compounds 16.4 Biologicals/Biotoxins 16.5 Carcinogens 16.6 Chlorine and compounds 16.7 Corrosives 16.8 Decontamination solutions 16.9 Dusts and particles 16.10 Fluorides 16.11 Hydrides 16.12 Lead 16.13 Oxidizers 16.14 Poisons (herbicides, insecticides, fungicides) 16.15 Other 17.0 Direct Radiation Exposures 17.1 Contamination 17.2 Electron beams 17.3 Radioactive material 17.4 Radioactive sources 17.5 Radiography equipment 17.6 X-ray machines 17.7 Other 18.0 Non-ionizing Radiation 18.1 Lasers 18.2 Other 19.0 Criticality 19.1 Fissile material 20.0 External Man-made Events 20.1 Aircraft crash 20.2 Explosion 20.3 Fire 20.4 Power outage 20.5 Transportation accident 20.6 Other 21.0 Vehicles in Motion 21.1 Airplane 21.2 Crane/hoist 21.3 Forklifts 21.4 Heavy construction equipment 21.5 Helicopter 21.6 Train 21.7 Truck/car 21.8 Waterborne Vehicle 21.9 Other 22.0 Natural Phenomena DOE-HDBK-1224-2018 9 No. Item Hazard present (Y/N) Description (quantity, form, location) Disposition (SIH, accident initiator/contributor) 22.1 Earthquake 22.2 Flood 22.3 Lightning 22.4 Rain/hail 22.5 Snow/freezing weather 22.6 Extreme straight-line wind 22.7 Tornado 22.8 Tsunami, seiche 22.9 Volcanic ashfall 22.10 Other An HA team safety analyst should work one-on-one with an individual SME and operations representatives to fill out those parts related to the SME’s area of expertise and portions of the facility that have been segmented into process or area nodes for analysis as discussed later in this chapter. The multiple checklists from all the process or area nodes can be integrated into a complete draft of a hazard identification table and presented to the HA team for review, or the checklist for each node can be presented separately. Past experience has shown that this is a much more efficient way to complete the exercise than to have the entire HA team meet to discuss every item for every process or area node. 2.2.3 HAZARD SUMMARY DEVELOPMENT DOE-STD-3009-2014, Section 4.0, DSA Section [3.3.2.1], states that the hazard identification data sheets (checklists) may be included in the DSA, or referenced as needed, and that a summary table that identifies hazards by form, type, location, and total quantity be presented, as well as a summary of major accidents or hazardous situations (e.g., fires, explosions, loss of confinement) that have occurred in the facility’s operating history. The integrated checklist for the facility can be included in the DSA hazard identification results section. The process or area node checklists can also be used to develop a summary table to be included in the DSA. The range of information captured in the DSA hazard identification table is designed to ensure that the minimum hazard identification results are established, appropriate screening of hazards is performed, and information needed to perform an effective and efficient hazards evaluation is established. Table 2-2 is an example Hazard Summary Table form for a facility. DOE-HDBK-1224-2018 10 Table 2-2. Building XXX Hazard Identification Summary Table. Hazard Type Location Form Quantity Remarks / Screening References Radioactive materials Direct radiation exposure

Section 26

Criticality accidents Hazardous chemicals (corrosives, toxics, reactions) Flammable/ combustible materials Explosive materials Electrical energy Kinetic and potential energy Pressure-volume Thermal energy NPHs Other DOE-HDBK-1224-2018 11 These compilations of information reviews and facility walkdowns constitute initial information. Iterations between the hazard identification and hazard evaluation phases are likely necessary in order to ensure completeness. 2.2.4 EXCLUSION OF STANDARD INDUSTRIAL HAZARDS AND OTHER HAZARDOUS MATERIALS The comprehensive hazard identification process in Sections 2.2.1 through 2.2.3 addresses all radiological and non-radiological hazards and energy sources. However, SIHs are not normally analyzed in a DSA hazard evaluation, unless chemical and industrial hazards result in a release of nuclear material, or an operator is incapacitated or prevented from taking credited action to prevent or mitigate a hazard scenario. DOE-STD-3009-2014, Section 3.1.1 states: Although the hazard identification process is comprehensive of all radiological and non- radiological hazards, DSAs are not intended to analyze and provide controls for standard industrial hazards such as burns from hot surfaces, electrocution, and falling objects. These hazards are adequately analyzed and controlled in accordance with 10 C.F.R. Part 851, Worker Safety and Health Program, and are analyzed in a DSA only if they can be an accident initiator, a contributor to a significant uncontrolled release of radioactive or other hazardous material (for example, 115- volt wiring as initiator of a fire), or considered a unique worker hazard such as explosive energy. The basis for any identified hazards excluded from further evaluation shall be provided. See Appendix A, Section A.1 of this Standard for further discussion on screening of standard industrial hazards and Section A.2 for a discussion on screening out certain chemicals based on low quantities or low hazard. DOE-STD-3009-2014, Section A.1, provides the following SIH guidance: The Department of Energy (DOE) recognizes, via Title 10 of the Code of Federal Regulations (CFR) Part 830, the importance of including worker safety in safety analyses by specifically noting the worker as a population of concern. Developing a conceptual basis for the methodology used in this Standard requires answering the fundamental question of how worker safety is most appropriately addressed in the DSA. DSAs include hazard analyses and hazard controls for worker safety, unless the hazards and their potential consequences are due to standard industrial hazards. Standard industrial hazards are hazards that are routinely encountered in general industry and construction. These workplace hazards are addressed by provisions of 10 CFR Part 851, Worker Safety and Health Program, which requires identification and assessment of worker hazards and compliance with safety and health standards that provide specific safe practices and controls. Based on these provisions, evaluation of standard industrial hazards within DSAs is needed to the extent that these hazards act as initiators or contributors to accidents, or result from chemical or radiological hazards (for example, when an explosion is caused by radiolysis inside a tank). When standard industrial hazards are excluded from further evaluation, Section 3.1.1 of this Standard requires such conclusions to be included in the hazard identification, along with the basis used for exclusion.

Section 27

Standard industrial hazards that may be considered for exclusion from the DSA hazard evaluation include those in which a national consensus code and/or standard … defines and regulates appropriate worker safety practices. Specifically, the codes and standards required by 10 CFR 851.23, Safety and Health Standards, may be considered. Examples of hazards addressed by these requirements include confined spaces, electrocution, falling objects, non-ionizing radiation, hot work, and lasers. Toxicity of hazardous chemicals is addressed in Section A.2 rather than this subsection. [Unique hazards …] DOE-HDBK-1224-2018 12 Standard industrial hazards that have the potential to be an accident initiator involving chemical or radioactive material releases are retained as part of the DSA hazard evaluation. For example, the existence of 440-volt alternating current cabling in a glovebox could be identified as a potential accident initiator of a fire involving radioactive or other hazardous materials. The evaluation of hazards associated with “other hazardous materials,” and especially a subset involving hazardous chemicals, warrants further discussion regarding which hazards can be screened out or screened in. Some of these non-radiological hazards may be determined to be SIHs, while others may require further evaluation in the DSA per 10 CFR § 830.204(b)(3) “that might contribute to the generation or uncontrolled release of radioactive and other hazardous material.” One aspect of the “generation or uncontrolled release of … other hazardous material” consideration is recognized in DOE-STD-3009- 2014, Section A.1, which states: “Toxicity of hazardous chemicals is addressed in Section A.2 rather than this subsection” and is therefore not treated as a SIH. In addition to toxicity, other chemical hazards may require further evaluation. The introduction of DOE-STD-3009-2014, Section A.2 clarifies that not all chemical hazards (even those that can cause serious injury or death) need to be evaluated in the DSA hazard evaluation: The DSA is not intended to deal extensively with chemicals that can be safely handled by implementation of a hazardous material protection program. Therefore, a screening process is established to select for DSA evaluation only those chemicals of concern (i.e., type and quantity that have the potential for significant health effect on the facility worker, co-located worker, or public) that are present in the facility or activity and present hazard potentials outside the routine scope of the hazardous material protection program. The DSA hazard evaluation scope covers analysis of (a) hazardous chemicals affecting nuclear safety and (b) in some cases, chemical hazards that are outside the scope of the facility’s hazardous material protection program. The intent of DOE-STD-3009-2014 is to cover: • radiation-related hazardous chemical events (examples: chemicals comingled with radiological waste, chemicals generated through radiological processes, and chemicals generated or released through processing of radioactive materials); • nuclear safety-related hazardous chemical events (examples: events that affect a worker relied upon for a credited action, events that affect safety-related SSCs through corrosion, fire, or explosion); or • unique hazardous chemical events, not addressed by 10 CFR Part 851, that could cause harm to workers, the public or the environment.

Section 28

As an example of an excluded chemical hazard, consider a chemical supply tank in a nuclear facility that has no interaction with radioactive material until the chemical is discharged into the nuclear process. The chemical hazards presented by this tank, if they are routine and common in industry, should be screened out of the DSA hazard evaluation as an SIH because 10 CFR Part 851 requirements will apply. However, when a chemical is used in or generated by a nuclear process (i.e., interacting with nuclear material), then such physical consequences from process accidents (e.g., over-pressurization) should be evaluated in the DSA hazard evaluation. DOE-STD-3009-2014, Section 3.1.3.1 states: Facility worker consequences, due solely to a standard industrial hazard, do not need to be categorized in the hazard evaluation if screened out per Section 3.1.1. However, the evaluation of radiological or chemical hazards that result in a prompt death or serious injury should be assigned a high consequence DOE-HDBK-1224-2018 13 per Table 1. Examples of such hazards might include the generation of flammable/explosive hydrogen gas by electrolysis of uranium in water or a spill of sodium hydroxide used in radioactive waste processing. Another chemical hazard not screened out is described in the DOE-STD-3009-2014, Section A.1 that states: “Significant quantities of cryogenic material or compressed gases/liquids may also warrant consideration because of asphyxiation hazards that might affect the ability of facility operators to safely manage the facility. Such unique hazards are not treated as SIHs and are evaluated in the DSA.” Note that the consideration is related to impacts on safely managing the facility. This situation would include incapacitation of operators required to perform specific administrative controls affecting critical safety functions. In general, a chemical hazard should not be screened out if it affects a facility worker expected to perform safety-related actions. Control room workers are in this category, as are operators expected to carry out credited actions for a specific administrative control. DOE-STD-3009-2014, Section A.2 includes the following example: “chemicals that may be excluded from the DSA’s hazard evaluation include … chemical is not listed in OSHA or EPA toxic chemical regulations or is not assigned a PAC 2 or 3 value.”8 Regarding toxicity, impact on a facility worker is defined as being exposed to a chemical concentration reaching Protective Action Criteria (PAC)-2 or PAC/TEEL-3 levels based on a qualitative evaluation. Typically, PAC concentrations are evaluated over a 15-minute period. However for a screening evaluation, a shorter time may be warranted if the worker becomes incapacitated due to the chemical exposure in a shorter than 15-minute time frame. Section A.1 of DOE-STD-3009-2014 describes situations that should not be screened out when considering other unique hazards: Unique hazards may be present in facilities that are not specifically addressed by the above exclusion criteria, either because of quantities larger than typically used in general industry or because of unique DOE applications or operations. Such hazards may represent a potential hazard to an entire work area affecting multiple workers. The intended distinction is to ensure analysis of “other hazardous materials” outside the scope of 10 CFR Part 851 that could affect nuclear safety. If these unique hazards could impair or disable control room operators or make uninhabitable entire rooms where nuclear operations are conducted, such hazards should be evaluated in the DSA.

Section 29

DOE-STD-3009-2014 requires that “the basis for any identified hazards excluded from further evaluation shall be provided.” Excluding a specific hazard or class of hazards should be accompanied by recording the applicable code or standard and the relevant site safety management program for implementing the code or standard. This basis may be included on the hazard identification table (see the “References” column in Table 2-2), or for more complicated justifications, in the DSA hazard identification results section. Either approach is suitable, as long as there is clear documentation of hazards screened out from the hazard evaluation.9 8 See Section 9.3 for additional discussion of screening chemicals. 9 Many SIHs are evaluated in the hazard evaluation as an initiator or contributor to a radioactive or other hazardous material release, which should be acknowledged somewhere in the hazard identification results section. DOE-HDBK-1224-2018 14 2.3 INITIAL HAZARD EVALUATION DEVELOPMENT 2.3.1 OVERVIEW Hazard evaluation is the starting point for control set selection to prevent or mitigate potential hazardous conditions (or hazard scenarios as defined in DOE-STD-3009-2014) that could result in undesirable consequences, and for the subsequent quantitative accident analysis. The definitions section of DOE- STD-3009 states that the hazard evaluation portion of a hazard analysis includes an examination of “the complete spectrum of potential accidents that could expose members of the public, onsite workers, facility workers, and the environment to” radioactive and other hazardous materials. The DSA hazard evaluation provides: (a) an assessment of the facility hazards associated with the full scope of planned operations covered by the DSA, and (b) the identification of engineered and administrative controls that can prevent or mitigate these hazards or hazardous conditions. It analyzes normal operations (startup, facility activities, shutdown, and testing and maintenance configurations) as well as abnormal and accident conditions. In addition to the process-related hazards identified during the hazard identification process, the hazard evaluation also addresses NPHs and man-made external events that can affect the integrity of an SSC. DOE-STD-3009-2014, Section 3.1.3 provides requirements and guidance on how hazard evaluations are to be performed for DOE nuclear facilities. The initial hazard evaluation is accomplished by the following steps: 1. Define the scope of the HA. This scope can vary from a single process in a single room to an entire facility with multiple processes. Evaluation of the entire facility may be more efficiently performed by dividing it into smaller process or area nodes. The scope of activities to be evaluated by the analysis includes any activities that can occur when significant quantities of hazardous materials are present. These activities include (a) DSA-authorized processes and experiments in the facility, (b) off-shift activities, and (c) any hazard associated with maintenance and support activities that can occur when significant quantities of hazardous materials are present. (Quantities are significant if they can cause injury, for example, as related to asphyxiation in DOE-STD-3009-2014.) Physical boundaries, process/support system interfaces, and interfaces with other facilities need to be defined. 2. From the hazard identification results, evaluate hazards associated with authorized activities, man-made external events, or NPHs. Develop a comprehensive list of postulated hazard scenarios.

Section 30

3. From the hazard identification results, evaluate radioactive and other hazardous materials and energy sources to determine possible interactions that could lead to accident conditions. 4. Evaluate circumstances such as equipment failures, process material hazards and failure of barriers, and mission activities that could affect the initiation and progression of the accident conditions. 5. Review applicable safety documentation, process history, occurrence reports, and other information sources to identify postulated or historical hazardous conditions and accidents associated with the facility. DOE-HDBK-1224-2018 15 All activities within the facility boundaries are considered in the analysis. The HA team defines where these boundaries, or process or area nodes, start and stop. Considerations include: • Do activities start at the door of the facility, at the loading dock, or at an outside staging or storage area? • If two facilities share common space, at what point does one facility analysis start and the other stop? • Do immediately adjacent facilities pose hazards such as toxic materials? • Are any hazards associated with the process or area nodes or facility boundaries that may warrant consideration of controls? Following this initial evaluation, the process continues with the documentation of hazardous conditions and selection of unmitigated hazard scenarios based on potential interactions between hazardous materials and energy sources. Typical hazards commonly associated with DOE nonreactor nuclear facilities are identified in Table 2-3. The table provides a suggested causal correlation between hazardous energy and material sources and potential accident types or categories.10 Hazards identified in Table 2-3 do not always result in an accidental release of radioactive or other hazardous material required to be evaluated by DOE-STD-3009. Table 2 3. Correlation of Hazardous Energy and Material Sources to Accident Types/Categories. Accident Category* Hazard Energy and Material Source Groups FR-1: Fire Electrical Open Flame Thermal Flammables Friction Combustibles Pyrophoric Material Chemical Reaction Spontaneous Combustion EX-2: Explosion Potential (Pressure) Explosive Materials Chemical Reactions LC-3: Loss of Confinement/Spills Radioactive Material Toxic Chemical Other Hazardous Material Chemical Reaction DE-4: Direct Radiological Exposure Ionizing Radiation Sources CR-5: Nuclear Criticality Fissile Materials EE-6: Man-made External Events Non-Facility Events (e.g., aircraft crashes) Vehicles in Motion Cranes NPH-7: Natural Phenomena Hazards NPH Events - Seismic, Extreme Wind, Flood, Lightning, Extreme Precipitation, Volcanic Ashfall *The number assigned to the accident categories is for ease of data management, and any numbering scheme could be used if deemed necessary. 10 A similar correlation is provided in DOE-STD-5506-2007, Preparation of Safety Basis Documents for Transuranic (TRU) Waste Facilities, Table 3.2-1, Hazard Sources and Potential Events. DOE-HDBK-1224-2018 16 A graded approach as defined in 10 CFR §830.3 and DOE-STD-3009 should be applied to the selection of hazard evaluation techniques and developing the hazard evaluations. The selection of techniques is based on several factors, including the complexity and size of the operation being analyzed, the type of operation, and the inherent nature of hazards being evaluated. A discussion of hazard evaluation techniques and recommendations can be found in Part I of CCPS, 2008, especially Chapters 4 and 5.

Section 31

2.3.2 NUCLEAR CRITICALITY HAZARD EVALUATION A criticality accident represents a special case for hazard evaluation. The criticality safety program requirements11 are derived from the HA process established in the American National Standards Institute/American Nuclear Society (ANSI/ANS)-8 series of national standards (e.g., ANSI/ANS-8.1, Nuclear Criticality Safety in Operations with Fissionable Material Outside Reactors). These standards require a documented nuclear criticality safety evaluation demonstrating that operations with fissionable material remain subcritical under both normal and credible abnormal conditions. Criticality safety evaluations provide the technical basis for controls to prevent or mitigate criticality accidents. The ANSI/ANS-8 series requirements do not apply to critical assemblies or similar operations. Section 3.1.3.2 of DOE-STD-3009-2014 provides requirements on what to include in the DSA hazard evaluation of criticality accidents, while Section 3.3.4 provides requirements on safety classification of criticality safety controls. Experience shows that only a few evaluations of criticality accident scenarios for a facility may need to be included in the qualitative hazard evaluation. Appendix B provides guidance on the magnitude and consequence analysis of criticality accidents and the estimation of fission product yield and particulate source terms. 2.3.3 CHEMICAL HAZARD EVALUATION As discussed in Section 2.2.4, chemical hazards are screened to determine the need for further hazard evaluation. However, per DOE-STD-3009-2014, Section A.2, chemicals “that could otherwise be screened out, but have the potential to be an accident initiator involving radioactive or hazardous material releases, or could compromise the ability of the facility operators to safely manage the facility, are retained as part of the DSA hazard evaluation.” Chemical properties such as reactivity, toxicity, and incompatibility with other chemicals are thus included in the hazard evaluation. Qualitative evaluation of toxic chemical consequences using any of the hazard evaluation techniques discussed later in this chapter is generally sufficient to provide a basis for comparison to consequence thresholds of interest for the selection of safety significant (SS) controls (i.e., serious injuries, fatalities, or significant chemical exposure). However, for some situations, further quantitative analysis of consequences is necessary for control selection. 12 Later chapters of this Handbook will provide guidance on quantifying chemical source terms (Sections 5.3 and 9.5) and dispersion analyses to estimate concentrations to receptors (Chapters 6, 7 11 Criticality safety program requirements are established in DOE O 420.1C. This Order states that DOE-STD- 3007-2007, Guidelines for Preparing Criticality Safety Evaluations at Department of Energy Nonreactor Nuclear Facilities, is the required method for performing criticality safety evaluations, unless DOE approves an alternate method. An update to that Standard has been issued in DOE-STD-3007-2017, Preparing Criticality Safety Evaluations at Department of Energy Nonreactor Nuclear Facilities, which will be invoked in a revision to DOE O 420.1C. 12 For example, see DOE-STD-3009-2014, Section 3.2.3.3 and Section A.2 for further information for evaluation of the toxicity hazard and determination of concentrations for the co-located worker (CW) at 100 m and maximally- exposed offsite individual (MOI).

Section 32

DOE-HDBK-1224-2018 17 and 9). However, selection and application of appropriate source term and dispersion methods for evaluation of chemical hazards will need to consider special situations such as chemical reactions, chemical transformations in the plume, or heavier-than-air plume modeling. 2.4 HAZARD EVALUATION METHODS 2.4.1 COMMERCIAL INDUSTRY METHODS AND DSA HAZARD EVALUATIONS Chapter 4 of CCPS, 2008 describes twelve methods that can be used in a hazard evaluation. The discussion is oriented toward the chemical industry, but the basic strengths and weaknesses of each method are generally applicable for the DSA hazard evaluation. The following sections discuss four of these methods as applied to several facilities described in DOE-HDBK-3010-94, Airborne Release Fractions/Rates and Respirable Fractions for Nonreactor Nuclear Facilities, Appendix B. None of these industry hazard evaluation methods were designed to generate a DSA hazard evaluation and do not yield hazard scenarios, nor were they designed to identify SS and safety class (SC) SSCs or specific administrative controls (SACs). Those results are uniquely defined for DOE usage to develop a DSA. Thus, one does not normally see the raw information generated from the industry hazard evaluation in a DSA; however, it is a necessary step to developing hazard scenarios. The hazard evaluation is performed to understand facility vulnerabilities and potential hazard scenarios. Those insights are then distilled into a DSA hazard evaluation table and are used for safety classification of controls and derivation of TSRs. The common methods utilized vary in both complexity and focus. Each method has strengths and weaknesses, and depending on the scope of the HA, multiple HA methods may be used. For example, the Hazard and Operational Analysis (HAZOP) methodology is effective for analyzing a chemical process within a facility, but the “What-If” methodology is better suited for evaluating NPH and man-made external events with the potential to affect the entire facility. 2.4.2 METHOD #1: WHAT-IF? The “What-If” method is a loosely-structured, brainstorming technique commonly used in the DOE complex by itself or in combination with other hazard analysis techniques such as Process Hazard Analysis (PrHA). As with any other hazard analysis method, the analysis typically is organized by facility operations, process, or activity location (e.g., a production support laboratory). Analysts utilizing this method formulate a series of questions, each beginning with the phrase “What if…?” for each process or activity. An example might be “What if the liquid tank in the support laboratory overflows?” The hazard evaluation would discuss ways in which the tank might overflow (e.g., initiators and overall event progression sequences), the potential consequences of overflow, what preventive and mitigative control responses are available, and what additional measures may be recommended for consideration. The extent of the discussion is based on increasing potential consequences. If the liquid in question is simply water with trace contamination or less harmful chemicals, the discussion will reach resolution much more rapidly than if the liquid is radioactive or a highly volatile, toxic substance.

Section 33

To provide proper structure for comprehensive results, the examination progresses in an organized manner, from the beginning of the activity/operation to the end. Well-designed checklists can provide additional structure that limits the potential for important events to be missed. This approach combines the “What-If” method with the simplest method for hazard evaluation that is a checklist that identifies already-known or understood hazards such as fires and explosions and can be augmented with specific design information. Furthermore, while a variety of potential outcomes can be identified, it is important DOE-HDBK-1224-2018 18 to identify the ultimate consequence that is physically plausible. Analysts should not stop with the assumption that a given control will function. To do so can result in failure to identify vulnerabilities, and is also inconsistent with DOE’s stated intent for unmitigated analyses. The strengths of the “What-If” method include broad applicability, ease of use, and its adherence to natural thought processes. Weaknesses include a greater potential for neglecting interaction issues and for missing some events altogether. Another weakness of the What-If analysis is that many scenarios identified may result in no or insignificant consequences; thus, creating a large number of scenarios of no interest to the DSA process. A modified What-If analysis has also been used to identify scenarios with significant consequence potential for further analysis. Further analysis may include the DSA-required evaluation of the frequency, consequence, and risk for such scenarios of interest, or combining the results of the What-If analysis with other hazard analysis techniques, such as Process Hazard Analysis (PrHA). The quality of “What-If” results can vary significantly based on the experience of the individual leading the team effort. Generally, “What-If” analysis is most suited to simple operations and activities where the potential end states of each step are discrete and easy to identify. Manual operations/activities are often ideal for “What-If” analysis. The H-21 TRU Waste Facility and the H-7 Production Support Lab discussed in DOE-HDBK-3010-94, Appendix B illustrate examples of facilities amenable to a “What-If” analysis. The common feature of these facilities is that they do not have complex processes. They consist of discrete, manual operations with well-defined interaction boundaries. Consider the liquid sampling glovebox in the Production Support Lab. It is a non-complex operation where a laboratory operator analyzes 20 ml sample vials. A simple walkdown of the process generates obvious “What-If” questions as shown on Table 2-4. Table 2-4. “What-If” Hazard Analysis Example H-7 Production Support Lab. “What if…?” Possible Consequences 1. …a collection of vials is dropped while being entered into the glovebox? 1. Broken vials, small Pu airborne release, minor worker exposure. 2. …the sample recycle bottle is dropped while coming out of the glovebox? 2. Spill, small Pu airborne release, minor worker exposure. 3. …liquid is spilled within the glovebox? 3. See #1 and #2 above, without direct worker exposure potential. 4. …the sample recycle bottle is overfilled (i.e., double batch of high concentration of fissile solution)? 4.a. Criticality Safety Evaluation shows large margin = no issue or 4.b. Criticality Safety Evaluation shows limited margin = potential criticality event

Section 34

5. …the glovebox inventory of hexone solvent ignites? 5.a. Potential glovebox confinement breach and/or 5.b. airborne Pu release (larger release potential than spill) 6. …more samples are brought into the glovebox than its allowable storage spaces? 6. No specific consequence (potential deviation in operational practice that should be evaluated). 7. …planchettes are dropped outside of glovebox 7. No significant consequence (quantities of material are too small) DOE-HDBK-1224-2018 19 The above list is not exhaustive, but demonstrates the basic concept. This questioning process would be repeated for each of the specific operations and general activities authorized in the facility. The resulting complete set of questions and answers would then be combined and amplified as necessary to generate specific hazard scenarios in the DSA hazard evaluation table. For example, if the potential exposure consequences are sufficiently limited, all liquid spills might be combined into one representative hazard scenario. Or, if only one or two of the liquid spill scenarios could pose significant exposure potential, those would be documented as individual events. Care should be exercised when combining scenarios. There should be no attempt to combine scenarios until potential controls are identified. The considerations to determine if scenarios should be combined include identifying that proposed controls are either bounded or are the same for all bundled scenarios. In the hypothetical case presented in the previous paragraph, suppose one distinct spill with significant consequences is combined with all other spills. The hazard evaluation would then identify any credited controls for one scenario as applying to all glovebox liquid handling operations. Dissimilar scenarios cannot be combined. For example, fires and spills should not be artificially combined into one event because they have differing consequences, separate initiators, and unlike controls. The required clarity of the analysis of the most important preventive and mitigative controls will be lost if these dissimilar scenarios are combined. Bounding scenarios is primarily a function of their controls. The example above only illustrates the identification of “what if” questions (which may help define initiating events or scenarios) for a single operation, and the associated possible consequences. It may not define a complete set of initiated events or define completely an accident scenario, nor include the controls to prevent or mitigate such scenarios. 2.4.3 METHOD #2: HAZARD AND OPERATIONAL ANALYSIS This method, abbreviated “HAZOP,” is designed to investigate chemical process and complex system performance requiring a more methodical approach to ensure completeness, which cannot be effectively accomplished with the “What-If” technique. It requires a significantly greater investment of time and resources than a “What-If?” analysis because team members are required to identify and assess the significance of system malfunctions or improper operations at each step of a process using a highly formal, systematic approach. The HAZOP method first divides a process or system into discrete sections (defined as process or system nodes), with the intent or function of each section being well-defined. Figure 2-1 illustrates the complete HAZOP method, after defining the process or system nodes. Figure 2-1. HAZOP Method Overview DOE-HDBK-1224-2018 20

Section 35

The method then examines deviations in hardware and those caused by human interactions (such as those that occur during maintenance and operations) from design conditions by systematically combining each parameter of interest for the process or system with guide words. Examples of parameters include flow, pressure, temperature, composition, and even more conceptual items such as containment. Examples of guide words include “no, more, less, high, low, as well as, partial, reverse, wrong type, sooner than, later than, breach.” A HAZOP deviation matrix can be built to describe the evaluation criteria corresponding to a guide word for a given process or system parameter as illustrated in Figure 2-2. Figure 2-2. HAZOP Deviation Matrix For example, the HAZOP team might start examining a process or system section by first identifying a parameter such as flow and the guide word “None”, and postulating a deviation of “no flow.” They would then identify the causes of no flow, qualitatively define the consequences of no flow, and what safeguards or controls are available or may be recommended for consideration, or other action items that may require further investigation. When significant consequence potential is identified, it is important to trace causality back to previous sections examined if the deviation of interest originates there. For additional perspective, consequence, likelihood, and risk rankings may be assigned to each of these significant deviations/cause conditions, or that may be accomplished in a subsequent DSA hazard evaluation. The team subsequently proceeds to other guide words for the selected parameter, such as “low flow,” followed by “high flow” and so on. This procedure yields an understanding of the integrated process or system behavior, as opposed to simply focusing on the discrete behavior of isolated components. The HAZOP method brings to bear considerable structural rigor. It breaks down the entire process or system into a large number of discrete sections (pipe runs from Point A to Point B and individual vessels) and goes through a repetitive exercise to examine deviations in significant detail. Most deviations will not, in fact, involve any significant vulnerabilities, one reason that HAZOPs for large processes or systems are conducted over multiple days. The exercise simply takes time. Attempting to move swiftly through it tends to create an overload effect that defeats the purpose of this method. The strengths of the HAZOP method are thoroughness enforced by structural rigor, focus on small details, adaptability to almost any process or activity, and generation of an organized evaluation record as an intrinsic part of the method. HAZOP also forces participants to properly define the process or activity at a detail level prior to beginning. Weaknesses include the fact that HAZOP is much more time and resource intensive than other methods. It is also vulnerable to poor initial organization. HAZOPs generally represent overkill for simple processes and predominantly manual activities, but are ideal for more complex processes, where the sheer magnitude of the potential deviations can overwhelm a “What- If” examination. Another weakness of the HAZOP method is that since it is focused on processes or DOE-HDBK-1224-2018 21 systems, and their deviations, it often can miss more generic hazard scenarios such as external and natural phenomena events, or those not associated with process or facility systems.

Section 36

Table 2-5 presents a HAZOP example for the Metal Dissolution Process described in DOE-HDBK-3010- 94, Appendix B for the Plutonium Recovery Facility. This portion of the HAZOP evaluates a node defined by piping from the heat exchanger to the spray chamber as shown in Figure B.8 of DOE-HDBK- 3010-94. The parameter examined is “Flow.” Compared to the previous “What-If” examples, the rigorous and repetitive nature of the method is clear. “What-If” relies on the ability and experience of the analysts to ensure completeness; HAZOP relies more on the method’s formal structure. DOE-HDBK-1224-2018 22 Table 2-5. HAZOP Example. Note: Piping from Heat Exchanger to Spray Chamber (as shown in DOE-HDBK-3010-94, Figure B.6). Parameter Deviation (guide word) Cause Consequence Safeguards or Controls Likelihood Consequence Risk Comments/Actions Flow No 1. Pump not working 2. Heat exchanger outlet valve incorrectly positioned 3. In-line filter clogged Operational Return line flow meter, Temperature sensors Safe Condition: Dissolution reaction ceases without fresh acid flow Unsafe Condition: Potential to pressurize heat exchanger Flow No 1. Piping rupture Plutonium solution spill Glovebox, Glovebox ventilation, Critically safe drainage basin, Room air monitor, Room ventilation Flow Low 1. Piping leak Plutonium solution spill Glovebox, Glovebox ventilation, Critically safe drainage basin, Room air monitor, Room ventilation Flow High 1. Pump output excessive 2. Heat exchanger outlet valve incorrectly positioned Temperature transient (more flow is heated less) Temperature sensor on slab tank, Steam inlet control, Return line flow meter, Hydrogen detector, Shutdown interlocks, Air sparge Unsafe Condition: More flow maximizes reaction. Unsafe Condition: Low acid temperature can yield undesired hydride sludge. Flow Wrong 1. Steam inlet off with heat exchanger leak Plutonium solution enters heat exchanger condensate Condensate collected in Raschig ring tank, Condensate samples Action: Verify sampling frequency DOE-HDBK-1224-2018 23 As noted previously, the traditional HAZOP table is not an example of the hazard evaluation table expected in an actual DSA, but with modifications as suggested in Table 2-5, it may be suitable. The HAZOP identifies process vulnerabilities and interactions from which a set of hazard scenarios are usually derived for the DSA hazard evaluation table. For example, a runaway exothermic reaction generating hydrogen is an event that would be expected in the DSA hazard evaluation table. Depending on the HAZOP results, there could be multiple entries for the same event to identify different progression paths, some of which would be of concern, while others may not. Alternatively, one entry could cover all potential progression paths; however, all paths should still be assessed to determine which, if any, warrant specific control. Example outcomes include: 1. The hydrogen detector and shutdown interlock is adequate to credit for all scenarios; or, 2. An individual control in a specific progression path may require crediting as well, either due to the high likelihood of that progression path or its ability to minimize the effect of the hydrogen detector and associated interlocks. These methods were not developed to credit SSCs. They are intended to address problems that may arise when deviations from design conditions occur. The method (or any HA method) may uncover safety issues to be further evaluated.

Section 37

2.4.4 METHOD #3: FAILURE MODES AND EFFECTS ANALYSIS The failure modes and effects analysis (FMEA) is a flexible tool for examining equipment, a process, or system failures (in this section, “system” also includes equipment or a process). It is particularly suitable for characterizing the performance spectrum associated with individual component failures within the system. Thus, it is ideal for identifying all potential failure modes for systems of interest typically of moderate complexity. In some cases, the impact may not just be the failure of the system to perform its intended function, but could result in an accident condition of interest, such as an explosion in a process line. The analysis proceeds as follows: • Identify the major components (example: detectors); • Identify the systems using these components (example: ventilation); • Identify all failure modes for each component (high, low, loss of signal); • Identify the effects of component failures on the systems. Finally, for system consequences of interest, such as failure of the system to perform its function or an accident of concern, the controls or safeguards to prevent such failures are identified. FMEA equipment failures. As indicated, FMEAs are ideal for evaluating system failure modes, but are not well-suited to supporting the identification of process hazard scenarios. FMEAs also lack the structure to examine process upsets (e.g., reverse flow, process chemistry deviations) as initiators. Inexperience with using the method can also lead to an excessively narrow focus on individual failures as opposed to integrated process behavior. Therefore, because the FMEA is narrowly focused, it is usually applied in combination with other techniques such as fault tree analysis to provide a more detailed understanding on how a system could fail. Table 2-6 shows an application of the FMEA method to the Metal Dissolution Process evaluated in Table 2-5 for flow from the heat exchanger to the spray chamber through a pipe. The component and the failure modes of interest within this process is those associated with the hydrogen detector. DOE-HDBK-1224-2018 24 Table 2-6. FMEA Example. Process: Metal Dissolution Line Component: Hydrogen Detector Failure Mode Effect Safeguards Comments/Actions Fails high Generates premature process shutdown for low H2 concentration. Fails safe Indication on operational console, Shutdown interlock. Fail safe: None Fails low Failure to generate process shutdown, when required, leading to unsafe conditions (e.g., a potential for exothermic reaction and hydrogen explosion) Indication on operational console, Spray chamber temperature sensor (also feeds shutdown interlock), Temperature indications on operational console Potential accident of concern Increased hydrogen concentrations are generally accompanied by higher temperatures. A runaway exothermic reaction would still yield a shutdown. However, conditions short of that could yield H2 concentrations in excess of the shutdown limit. Fail as is Failure to generate process shutdown when required See “Low Failure Mode” See “Low Failure Mode” Potential accident of concern See “Low Failure Mode” comments/actions Loss of Power Triggers shutdown interlock Indication on operational console, Shutdown interlock. Fail safe: None Signal to Interlock, Mode A Triggers shutdown interlock Indication on operational console, Shutdown interlock. Fail safe: None Signal to interlock, Mode B

Section 38

Failure to generate process shutdown when required See “Low Failure Mode” Effects See “Low Failure Mode” safeguards Potential accident of concern See “Low Failure Mode” comments/actions 2.4.5 METHOD #4: EVENT TREES AND FAULT TREES Event trees and fault trees are formal logic constructs designed to document progression paths for an event. Event trees utilize inductive reasoning while fault trees utilize deductive reasoning. These two tools can be combined in a formal quantitative or probabilistic risk assessment, but such an assessment for an entire facility or process is not typical when evaluating DOE nonreactor nuclear facilities. Event trees and fault trees are normally used in DSAs as support tools to illuminate a specific issue of interest. Inductive reasoning is often characterized as a “bottom-up” analysis since it starts with a specific premise and moves toward a general conclusion. An event tree correspondingly starts with a specific initiating event and moves toward a broad collection of potential outcomes. Regarding DSA hazard analysis, this approach results in event sequences with varying consequences in terms of radiological release potentials, based on the success and failure of any preventive controls that may terminate the event or mitigative controls that may reduce the consequences. A simple example of an initiating event might be “loss of cooling water to a furnace.” Every action that can result from that event then forms a decision point from which multiple possible outcomes branch. For example, suppose Alarm A is supposed to sound to generate an operator response if cooling flow is lost. The first decision point is therefore “Alarm A functions.” Two branches stem from that point: (a) if alarm A functions, the progression moves to a decision point labeled “Operator responds;” (b) if Alarm A does not function, operator response is initially bypassed and the resulting branch moves to a different decision point. The end result is a DOE-HDBK-1224-2018 25 complete spectrum of outcomes, from successful to unsuccessful to catastrophic, which are characterized in terms of actions and controls associated with their progression. Each individual path through this event tree represents a separate event sequence. Thus, the minimum cut sets that yield failure of the system or its safety function can be defined. Event trees graphically depict the relationship between an initiating event and controls; thus, defining ranges of potential scenarios, their frequencies, and potential consequences based on the response of credited controls. Event trees, as well as fault trees, are typically used to support accident analyses and are not necessarily elevated to the DSA. Deductive reasoning is often characterized as a “top-down” analysis since it uses general premises to arrive at a specific conclusion. A fault tree thus begins with the undesired end state as the top event such as a specified consequence of a potential accident and analyzes equipment failures and human errors that cause the top event. Such end states have often been identified by application of other hazard evaluation methods. For demonstration purposes, a simple example of an undesired end state is “the car does not start.” The next step down in the fault tree lists the immediate causes such as starter motor failure, spark plug failure, and lack of gas in the cylinder. The next step down lists all the potential causes for each immediate cause: no gas in supply tank, failure of the fuel pump, fuel line leak. These potential failure mechanisms are joined by “AND” or “OR” gates depending on whether multiple mechanisms (A “AND” B) are needed to cause the failure above or if a single mechanism (A “OR” B) suffices. This process ends either in basic occurrences that cannot be subdivided further or at a predetermined evaluation boundary. Again, the minimum cut sets that yield failure of the system or its safety function can be defined.

Section 39

The strengths of this approach includes logical rigor, recording of results in a branch structure as the evaluation occurs, and direct support of numerical estimation of likelihood of the postulated significant consequences. Weaknesses include a tendency toward tunnel vision if the failure mode or safety function of interest is not precisely defined, as well as a significant resource and time investment to generate integrated results. 2.5 INITIAL DEVELOPMENT OF A DSA HAZARD EVALUATION TABLE The commercial industry hazard evaluation methods previously discussed evaluated process upsets, equipment failures, human errors, and potential safety features. Table 2-7 shows how similar hazard studies can be used to start development of a hazard evaluation table for the DSA, based on an example of a vehicle collision plus fire involving TRU waste containers which has often been evaluated using the “What-If” method. DOE-HDBK-1224-2018 26 Table 2-7. Initial Development of Hazard Evaluation Table. Event No. Event Description Initiators Preventive Features Mitigative Features FR-1 Fuel powered vehicle suffers a fuel leak due to an impact with TRU waste drums in the Shipping/Receiving Area and is ignited. A forklift carrying a single pallet with four drums impacts a stack (two high) of palletized drums with moderate to severe stress causing breach with material spill of 12 drums and ensuing pool fire that involves 88 additional drums in the Shipping/ Receiving Area. MAR: xx alpha curies in 100 drums (DOE-STD-5506-2007 statistical MAR distribution for Waste Isolation Pilot Plant complaint containers applied, see Table yy) INITIAL CONDITIONS: Staging area inventory limit; TRU waste in metal containers; Metal pallets. • Operator error • Equipment malfunction • Vehicle impact with fuel spill • Ignition of combustible and/or flammable materials • Lightning • Wildland fire SSCs: Concrete vehicle barriers. Waste staging building foundation. ADMINISTRATIVE: Procedures and Training Program (Forklift Operator training); Vehicle maintenance program; Fire Protection Program: • Combustible controls Waste handling operations curtailed outdoors during inclement weather; Movement of waste is to be accomplished using electric or manual powered equipment; Fuel exclusion zone in the Shipping/Receiving Area. SSCs: None ADMINISTRATIVE Procedures and Training Program (workers trained to evacuate); Emergency Preparedness Program (emergency response activities). Control identification occurs as part of the initial hazard evaluation development and is recorded in the hazard evaluation table as shown in Table 2-7. At this stage of developing the hazard evaluation table, all preventive and mitigative controls are listed that are available, or can be readily implemented, to demonstrate defense in depth as described in DOE-STD-3009. 2.6 LIKELIHOOD, CONSEQUENCE, AND RISK METHODS The next step of the DSA hazard evaluation is to perform a qualitative estimate of the unmitigated consequences, likelihood, and optionally, risk ranking of the hazard scenarios. The following subsections present methods for these evaluations. 2.6.1 QUALITATIVE CONSEQUENCES 2.6.1.1 RECEPTOR CONSEQUENCE LEVELS Table 2-8, reproduced from DOE-STD-3009-2014, Table 1, provides three qualitative consequence thresholds (bins) to estimate potential effects on facility workers, CWs, and the public (i.e., MOI).13 High, moderate, and low consequence levels are quantitatively defined for the offsite public and CWs. High consequence levels are qualitatively established for facility workers consistent with DOE-STD-3009

Section 40

13 These bins are similar to consequence level thresholds defined in DOE-STD-3009-94, CN3. DOE-HDBK-1224-2018 27 guidelines for a significant worker consequence. Moderate and low consequence levels are not defined for facility workers, because qualitative analysis would not yield results that provide a meaningful comparison to a distinguishable threshold.14 Table 2-8. Consequence Thresholds. Consequence Level Public1,4 Co-located Worker2,4 Facility Worker3 High ≥25 rem TED5 or ≥PAC6-2 ≥100 rem TED or ≥PAC/TEEL-3 Prompt death, serious injury, or significant radiological and chemical exposure. Moderate ≥5 rem TED or ≥PAC/TEEL-1 ≥25 rem TED or ≥PAC/TEEL-2 No distinguishable threshold Low <5 rem TED or <PAC/TEEL-1 <25 rem TED or <PAC/TEEL-2 No distinguishable threshold 1 MOI - A hypothetical individual defined to allow dose or dosage comparison with numerical criteria for the public. This individual is located at the point of maximum exposure on the DOE site boundary nearest to the facility in question (ground level release), or may be located at some farther distance where an elevated or buoyant radioactive plume is expected to cause the highest exposure (airborne release). 2 A CW at a distance of 100 m from a facility (building perimeter) or estimated release point. 3 A worker within the facility boundary and located less than 100 m from the release point. 4 Although quantitative thresholds are provided for the MOI and CW consequences, the consequences may be estimated using qualitative and/or semi-quantitative techniques. 5 Total Effective Dose (TED), 50-yr commitment. 6 DOE’s PAC - see Chapter 9. High consequence thresholds identified in Table 2-7 do not represent acceptable exposure levels to the public or workers; they are merely criteria used to identify safety class and safety significant controls. Qualitative judgment is inevitable in hazard evaluation. It is routinely utilized in industries outside DOE. Guidelines for Hazard Evaluation Procedures (CCPS, 2008, Pg. 22), notes the following: The subjective nature of these deliberations may trouble some people who use the results of these studies because this subjectivity creates a lack of confidence in the results. Some people incorrectly believe that if the analyst uses quantitative methods to express the significance of a problem, then the limitation of subjectivity will simply fade away. However, this is not the case. The apparent numerical precision of a QRA [“quantitative risk analysis” or “quantitative risk assessment”] can mask (1) a great deal of the judgment that influenced the selection of accident models and (2) large uncertainties associated with the data used to estimate risk. Estimating consequences qualitatively requires consistent assignments of the high, moderate, and low consequence levels for similar scenarios. This may require “normalizing” hazard scenarios by comparing against one another for consistent assignment of a severity level and to verify no outliers exist absent a sound explanation. In addition, for those hazard scenarios that were selected as representative or unique design basis accidents/evaluation basis accidents (DBA/EBAs) for further quantitative accident analysis, insights from that quantitative analysis should be used to verify the qualitative consequence assignments for the hazard evaluation (i.e., an iterative process between the hazard evaluation and the accident

Section 41

14 Mitigated analysis that credits controls to reduce unmitigated high consequences to the facility worker generally show mitigated low consequences on the DSA hazard evaluation table. DOE-HDBK-1224-2018 28 analysis). Assigning qualitative consequence levels may be informed by use of quantitative scoping estimates of effects on facility workers, CWs, and the MOI. Consequence estimation is performed differently for facility workers that may be near the source of the event or other areas within the facility where exposure may occur, as opposed to CWs or the public located at a distance from the facility. The latter often has a simplified quantitative basis. That is, it is a straightforward exercise to identify radioactive materials of greatest concern downwind using specific activity and dose equivalents that also incorporate the dispersion analysis. Likewise, chemicals that combine significant volatility and toxicity are easily identified. The safety analyst therefore starts with a short list of materials and release scenarios that are bounding. Bounding is intended to refer to the accident with the highest consequences among a group of similar accidents. It is a simple matter to calculate “unit release” consequences at any distance of concern (within the capabilities of atmospheric dispersion tools being used) to yield “rules of thumb” for screening calculations such as rem/Curie released or concentration/mass released. These in turn are used to qualitatively scale given events into qualitative consequence bins or levels of severity (high, moderate, low) for the CW and MOI. The CW scoping calculations may also provide the technical basis to meet the following requirement from DOE-STD-3009-2014, Section 3.1.3.1: Consequence determinations used for co-located workers in the hazard evaluation shall be supported by an adequate technical basis such as scoping calculations consistent with Section 3.2.4. Alternately, the quantitative evaluation of co-located worker consequences used to compare to Table 1 thresholds may be performed in the accident analysis and reported in the DSA Section [3.4]. 2.6.1.2 FACILITY WORKER CONSEQUENCES Given the qualitative nature of the consequence thresholds for facility workers in Table 2-8; the designation of facility worker consequences is based on first understanding how these type of consequence thresholds can be triggered by common hazards found in the DOE complex, or what these consequence thresholds mean in relation to radiological or hazardous chemical worker exposures. That is, facility worker consequences in many cases are based on accepted past-experience or consensus judgments from previous hazard evaluations throughout the DOE Complex, and not on quantitative calculations with their associated hard-to-defend assumptions and uncertainties. Thus, the following are recommendations and best practices to determine facility worker consequences. Past experience and consensus judgments indicate that prompt death can only occur by a limited set of hazards and scenarios such as: • nuclear criticalities, • exposures at levels over 400 rads to penetrating radiation such as gamma or X-rays, and • energetic releases of extremely hazardous chemicals. Exposure to airborne (non-penetrating) radioactive material such as plutonium and uranium due to a wide range of accident scenarios such as fires or spills are unlikely to result in prompt death. However, these could result in significant radiological exposures depending on several factors associated with the hazard (e.g., inventory, form of material) and the scenario themselves; as discussed in more detail below.

Section 42

DOE-HDBK-1224-2018 29 DOE has no simple numerical consequence metric to assess threshold consequences for facility workers. Because of the location of the postulated facility workers inside a facility or very near the source of a release, downwind considerations such as Χ/Q are not applicable. Therefore, the determination of facility worker consequences is usually based on judgment, and not quantitative calculations. In order to use a quantitative metric, one would have to equate a “serious injury or significant exposure” to a mutually-accepted quantitative exposure level (either radiation dose or toxic concentration) to define a threshold numerical value that is equivalent to a high consequence as defined on Table 2-8. This has been accomplished in DOE-STD-3009-2014 for the co-located worker and public, but not for the facility worker. Some previous DSAs have been based on a metric that radiation exposures due to accident conditions that could lead to exceeding emergency planning threshold or process safety management levels may be considered significant, since the selected level implies the onset for potential long-term health effects. Nevertheless, if a quantitative approach is desired, agreement on what constitutes a significant exposure should be reached with the DOE Approval Authority before any quantification is performed in support of determining the facility worker consequences. A quantitative analysis may not be necessary where insights from past industrial accidents are available, as may be the case for large-scale releases of toxic substances such as hydrogen fluoride. Local facility worker consequences should be evaluated with some sense of perspective and historical experience, as it is possible to conceive extreme events immune to any possible set of controls. The analyst should focus on the work areas in which accidents may result in a release of radioactive or hazardous material. If quantitative analyses are to be performed to support facility worker consequences, the associated concentrations of such releases are typically evaluated without reliance on specific assumptions about worker placement and hypothetical work area volumes for mixing of the release. However, a conservative but reasonable period of exposure could be assumed. Further guidance on these issues is provided later in this section. DOE-HDBK-1224-2018 30 The unmitigated consequence potential should not be underestimated, nor should unmitigated consequences be exaggerated (relative to historical experience) to a point where every exposure to the local facility worker is a high consequence event. DOE-STD-3009-2014 states: To ensure an informed and defensible qualitative evaluation, the determination of facility worker consequences should be based on a combination of the following: • Magnitude, type, and form of radioactive and hazardous materials involved in a hazard scenario; • Type and magnitude of energy sources involved in a hazard scenario; • Characteristics of the hazard scenario such as duration and the location where it may occur (e.g., in unmanned areas such as tank vaults); and • Potential for a hazard to impact workers’ mobility or ability to react to hazardous conditions.

Section 43

Some additional discussion of the fourth bullet is warranted. DOE-STD-3009-2014, Section 3.1.3.1 states that “the facility worker’s mobility or ability to react to hazardous conditions should not be used as the sole or primary basis for determining facility worker impacts.” This means that all four of the factors listed above ought to be considered collectively, not individually. A “see and flee” approach that results in unmitigated low consequences should not be used without due consideration of the accident characteristics. The last bullet, therefore, injects some realism into the event scenario for a “reasonable” unmitigated estimate of potential consequences to the facility worker. As an example, an assumption that a worker within a building is unaffected by a release from a building fire (based on hazard recognition and timely evacuation) would have to be justified by considering the location and characteristics of the fire relative to radioactive or hazardous material. Although unmitigated analysis may not take credit for administrative controls or active engineered features, it is reasonable to assume that facility workers have some knowledge of the facility hazards and adequate training to react to hazardous situations. This assumption, however, is valid only when the accident is not disabling, provides obvious warning signs, and is slow-developing. However, care should be taken not to rely excessively on crediting this type of condition as defaults for unmitigated analysis. Any credit of this nature needs to be justified in the evaluation of the unmitigated consequences for facility workers, based on the contributing elements discussed in this section. In evaluating the unmitigated consequences associated with a postulated hazard scenario, the following considerations may be important in assigning facility worker consequences: 1. Timing of radiological release: Hazard scenarios involving fires can develop quickly, but not so rapidly as to preclude evacuation in a reasonable period of time. Other scenarios, like criticality accident, explosion, and instantaneous release from confinement enclosures or containers can entail significantly more rapid radiological exposure. Another example is a long duration release such as during a spill of a radioactive or hazardous chemical liquid where a worker in the vicinity of the spill would not be expected to stand in the spilled liquid for an extended period of time. Therefore, though some exposure might occur, a conservative but reasonable time of exposure should be assumed. 2. Hazard warning: The availability of an obvious hazard warning and its timing relative to significant radiological or toxic chemical exposure may impact facility worker consequences. Warning may be provided by the event itself, as in smoke from a fire. However, engineered detection and notification systems such as air monitors are not credited for the unmitigated analysis. It is not reasonable to assume that a worker would remain in a room subject to flashover or toxic concentrations from a major fire in order to receive a significant radiological or toxic DOE-HDBK-1224-2018 31 chemical exposure. A conservative but reasonable period of exposure should be assumed, including whether the workers may choose to respond to the event.15 These points should also be considered:

Section 44

• If the facility worker would reasonably be aware of the event’s occurrence, and could take self-protective actions after the event occurs to protect themselves from a fatality or serious injuries from the non-radiological or non-hazardous material consequences, assume that the facility worker will be exposed for a conservative, but reasonable period of time even when warning is provided by the event itself. • In cases where the facility worker would not be reasonably aware of the event’s occurrence (e.g., characteristics of the release such as no odors, no visibility of plumes or smoke, occurrence in areas that could mask the release), there is no specified period of exposure, such as two hours. Consider reasonable lengths of time the facility worker would normally be present based on the nature of planned activities. 3. Scenario effect on protective action capability: Hazard scenarios involving explosions and NPH- initiated failure of buildings or equipment can cause damage to structures or injury to personnel impeding egress, thus increasing potential radiological or toxic chemical consequences. The potential for human errors or equipment malfunctions, in response to mitigating or evacuation actions following the accident, should be considered. Such an error might be putting the ventilation system in an operational mode that will worsen the consequences due to smoke generation. Also of importance is the impact of a toxic chemical release on potential worker ability to take protective actions. 4. Potential exposure magnitude: Severity of radiological uptakes or chemical exposures is a function of the magnitude of the energy associated with the accident scenario, the quantity and specific activity or toxicity of the material estimated to be released, and the pathways for transport to and absorption by workers. Inhalation is most often the dominant exposure pathway for airborne radioactive material releases, though skin exposures to small quantities of some chemicals such as aqueous hydrofluoric acid can be fatal. 5. Location: The impact to facility workers could be affected by the location of the worker with respect to the location of the postulated scenario; or whether the accident being evaluated occurs inside or outside of structures. For releases outside of structures, consider the qualitative impacts on dose of the plume moving past the facility worker. For releases inside a nuclear facility, consider whether the release is being mixed within a relatively small work area volume, such as with glovebox operations or into a large open area such as waste container staging buildings. Also, for releases within the facility, consider facility layout and unique non-ideal conditions such as mining operations or areas of limited visibility that can make evacuation difficult to achieve quickly. As a general rule-of-thumb application of the above considerations, examples of high unmitigated radiological or toxic chemical consequences to the facility worker are: (1) explosions, pressurized powders or high-concentration liquid sprays, and other energetic events that impact large quantities of radioactive material are considered to cause significant radiological exposure to the facility worker due to the rapid nature of the event, the resulting source term, and the inability of the worker to take protective action prior to receiving a substantial dose16; and (2) the prompt dose received from a criticality accident. Other types of events such as fires, spills, or dropping of a container require more careful evaluation of

Section 45

15 Workers may respond to incipient stage fires only with portable fire extinguishers, if they have been trained to use the extinguishers and feel safe in doing so. 16 This also apples to the consequences of exposure to hazardous chemicals. DOE-HDBK-1224-2018 32 the characteristics of the actual accident event (e.g., time to develop) before credit can be given for the elements identified in this section. Any credit taken in the potential unmitigated consequences for facility workers needs to be justified. 2.6.1.3 STANDARD INDUSTRIAL HAZARD CONSEQUENCES TO FACILITY WORKER Consequences to facility workers due to SIHs are included in the DSA when radiological or hazardous materials are involved and the SIHs are not screened out. These consequences are addressed in DOE- STD-3009-2014, Section 3.1.3.1 as follows: Facility worker consequences, due solely to a standard industrial hazard, do not need to be categorized in the hazard evaluation if screened out per Section 3.1.1. However, the evaluation of radiological or chemical hazards that result in a prompt death or serious injury should be assigned a high consequence per Table 1. Examples of such hazards might include the generation of flammable/explosive hydrogen gas by electrolysis of uranium in water or a spill of sodium hydroxide used in radioactive waste processing.17 For potentially serious injuries or fatalities, the event is assessed to determine whether the physical hazard associated with initiating or worsening a radiological or other hazardous material accident is a SIH or if it should be assigned a high consequence level. The primary consideration in determining whether the physical hazard is a SIH is if the regulated material (i.e., radioactive or other hazardous material) is not a primary cause or major contributor to the hazardous event, and that it is adequately addressed by 10 CFR Part 851 (and its adoption of OSHA and industry standards), 10 CFR Part 835, Occupational Radiation Protection, and Integrated Safety Management System HA requirements. These regulations and safety management programs are committed to in the DSA/TSRs. Examples of SIH accident initiators of a radioactive or other hazardous material release that may also cause physical injuries/fatalities are provided below to clarify that the unmitigated consequences do not include those SIH physical considerations. They illustrate that the unmitigated consequences do not include those SIH physical considerations, unless these could potentially affect their ability to safely manage the facility or respond to an accident condition. In that situation, the SIH should be considered for further analysis: • Thermal hazards to the worker are due to welding equipment and combustible or flammable material fires ignited by typical ignition sources (e.g., electrical or thermal). The welding torch is a common SIH throughout various industries. The fires with typical ignition sources are also SIHs because the hazard and potential physical consequences are due to common types of equipment found throughout various industries. Both of these events are adequately regulated by 10 CFR Part 851, OSHA, NFPA, and national consensus standards. • Explosions may involve ignition of flammable gases used with welding equipment; battery and fuel vapors; or offgasing from waste containers. The welding and equipment explosion and potential physical consequences are considered a SIH because these events commonly occur in general industry and are adequately regulated by 10 CFR Part 851, OSHA, and national consensus standards.

Section 46

• Missiles are caused by an equipment explosion, failure of pressurized or mechanical system (e.g., air compressor or gas bottle), compressed gas cylinder failures, over-pressurization or deflagration of a hazardous (i.e., non-TRU) waste container, or from extreme straight-line winds, hurricanes and tornadoes. Missiles are considered an SIH because these events commonly occur in general industry and are adequately regulated by 10 CFR Part 851, OSHA, and national 17 The above reference to Section 3.1.1 of DOE-STD-3009-2014 is located in Section 2.2.4 of this Handbook. Table 1 of the Standard is reproduced as Table 2-8 in this Handbook. DOE-HDBK-1224-2018 33 consensus standards, or by the DOE NPH directives. However, if the missile physical consequence to the worker is due to the primary hazard being the regulated material, then those physical hazards are considered along with the radiological or other hazardous material consequences in assigning unmitigated consequences. • Equipment-related events including vehicle/equipment load drops are SIHs because the hazards are presented by the equipment used in the work process, and the events are not caused by the regulated material. These events are adequately regulated by 10 CFR Part 851, OSHA, and national consensus standards. • Material and equipment movement is a hazard presented by moving, lifting, dropping, vehicle- impact-induced movement, collapse due to corrosion/degradation, or movement due to a seismic event. The hazard is due to the size and mass of the object being moved and is not a hazard presented by the regulated material. The same hazard exists in various industries, such as construction. These events are adequately regulated by 10 CFR Part 851, OSHA, and national consensus standards. • Asphyxiant hazards are presented by the use of small quantities of nitrogen and P-10 gas associated with loading or unloading shipping casks; acetylene or other compressed gases for maintenance activities and liquid nitrogen dewers for assaying waste containers; and exhaust buildup from material handling vehicles inside a facility. These hazards are common in various industries, and are adequately regulated by 10 CFR Part 851, OSHA, and national consensus standards. Smaller amounts of gases (i.e., nitrogen or argon) present for equipment calibration are in quantities that do not present an asphyxiation hazard. However, a large, rapid release of a nitrogen or argon from glovebox inerting systems for a nuclear process into a small confined occupied area that has an asphyxiation potential should be considered in assigning unmitigated consequences if the system has unique hazards requiring special design and controls that are not addressed by industry codes and standards. • Other impacts encompass collisions from vehicles such as trucks traveling on the site, vehicles external to the site, and potential site aircraft crashes. These hazards exist in everyday life and are accepted by the public. Although no specific controls may be identified for these SIHs, the safety management programs, as committed to by the DSA/TSRs, which govern the conduct of activities involving various industrial hazards, will provide protection to the worker for these occupational hazards.

Section 47

The qualitative evaluation for the facility worker may be supported by conservative quantitative scoping calculations, engineering judgment, and acquired knowledge. This qualitative approach is used because quantitative estimates are sensitive to a variety of possible assumptions such as facility worker position, circumstance, and close proximity to the point of release. Consequence estimates can rely on historical accident data or can be determined from: (1) simple bounding source term calculations, (2) existing safety documentation, and/or (3) qualitative assessment supported by calculations. 2.6.2 QUALITATIVE LIKELIHOOD Likelihood of a hazard or accident scenario is assigned to qualitative bins defined by guidelines, which offer numerical ranges of two orders of magnitude or more. Table 2-9, reproduced from DOE-STD- 3009-2014, Table 2, defines the qualitative likelihood bins. DOE-HDBK-1224-2018 34 Table 2-9. Qualitative Likelihood Classification. Description Likelihood Range (/year) Definition Anticipated Likelihood >10-2 Events that may occur several times during the lifetime of the facility (incidents that commonly occur). Unlikely 10-2>likelihood >10-4 Events that are not anticipated to occur during the lifetime of the facility. Natural phenomena of this likelihood class include: International Building Code-level earthquake, 100-year flood, maximum wind gust. Extremely Unlikely 10-4>likelihood >10-6 Events that will probably not occur during the lifetime of the facility. Beyond Extremely Unlikely Likelihood <10-6 All other accidents. Although the exercise of determining accident likelihood is qualitative, safety analysts often develop a numerical basis for judgments to provide consistency. An example is provided in DOE-STD-3009 that a simple methodology for unmitigated likelihood assignment could be to assign a probability of “1” to non- independent events, “0.1” to human errors, and “0.01” to genuinely independent SSC failures that would be used to establish the initiating event likelihood8 as described on Table 2-9. For the unmitigated analysis, these human errors and equipment failures cannot represent the failure probability of a preventive control that would otherwise provide a SC or SS safety function. To determine the likelihood of an accident scenario, only initiating events are expressed as rate of occurrence with the units of inverse time (i.e., per year), and other enabling events are expressed in terms of dimensionless failure probabilities. Another methodology for unmitigated initiating event likelihood classification would be to use a summary of historical data. Historical accident data may be used as long as this data represents the frequency of initiating events for such type of scenarios, and not the frequency of the entire scenario. Thus, caution is necessary in using historical data to support unmitigated frequency estimates for hazard scenarios, since it may not result in conservative frequency estimates for such scenarios.

Section 48

Conservative values are chosen to accommodate uncertainties in frequency levels used in Table 2-9. A conservative choice is particularly important when an event frequency is at the borderline, just below the next highest frequency level. For example, 9.7E-3/year is at the upper limit of the unlikely frequency level. Thus, considering the sources, methods, and uncertainty associated with this value, this event may be better assigned to a frequency level of anticipated. For initiating events at the borderline of frequency ranges, for the general rule is to assign to the next bin unless it can be justified based on the conservatism of the analysis. For example, an event just below a frequency of 10-2/year may be conservatively considered assigned to the anticipated frequency level. The same applies for scenarios with frequencies slightly less than 10-4/yr and 10-6/year, i.e., may be assigned to the next higher frequency level of Unlikely and Extremely Unlikely, respectively. The exception for this is for Beyond Extremely Unlikely scenarios for external events only, which by default have always being defined as scenarios with a likelihood below 10-6/yr. The mitigated frequency of occurrence when crediting preventive controls could also apply simple numerical estimates to assign a lower frequency bin. For example, a 0.01 failure probability could be assigned to a preventive engineered control or a SAC based on the technical justification in DSA Chapter 4. DOE-HDBK-1224-2018 35 Estimating likelihoods qualitatively requires consistent assignments of the likelihood bins for similar scenarios. To achieve consistency, hazard scenarios should be “normalized” by comparison to one another. 2.6.3 QUALITATIVE RISK The primary purpose of risk ranking is to support the selection of bounding DBA/EBAs for further quantitative accident analysis and determination of SC controls that are based on consequences, not risk rankings. However, risk rankings may also be used to support the hazard evaluation and SS control selection. Combining a likelihood and a consequence level leads to defining a qualitative risk level, sometimes called Risk Category or Risk Class. Table 2-10, reproduced from DOE-STD-3009-2014 Table A-1, provides an example of a risk ranking table that combines likelihood and consequence, which is based on using the consequence and likelihood thresholds in Table 2-8 and Table 2-9, respectively. Table 2-10. Qualitative Risk Ranking Bins. Consequence Level Beyond18 Extremely Unlikely Below 10-6/yr Extremely Unlikely 10-4 to 10-6/yr Unlikely 10-2 to 10-4/yr Anticipated Above 10-2/yr High Consequence III II I I Moderate Consequence IV III II II Low Consequence IV IV III III Risk Category I = Combination of conclusions from risk analysis that identify situations of major concern Risk Category II = Combination of conclusions from risk analysis that identify situations of concern Risk Category III = Combination of conclusions from risk analysis that identify situations of minor concern Risk Category IV = Combination of conclusions from risk analysis that identify situations of minimal concern Beyond the qualitative application of consequences and likelihoods (or supplemented with quantitative perspectives) for the hazard evaluation, risk ranking serves the broader purpose of confirming for the DOE approval authority that the overall mitigated risk of facility operation is low. Risk ranking can also highlight a given scenario whose mitigated risk remains significant. Additional guidance on use of unmitigated risk estimates for control selection is provided in Chapter 10.

Section 49

2.7 UNMITIGATED AND MITIGATED HAZARD EVALUATIONS The DSA hazard evaluation is based on unmitigated and mitigated analyses that derive the selection of hazard controls. The guidance from Section 2.6 is applied to assign qualitative estimates of the unmitigated and mitigated consequences, likelihood, and optionally, risk rankings of the hazard scenarios. An unmitigated hazard scenario is evaluated for each initiating event by assuming the absence of preventive and mitigative controls. Unmitigated likelihood and consequence estimates assume that active engineered and administrative controls are not available to reduce either the consequence or likelihood of the hazard scenario. However, the unmitigated analysis does assume that passive design features exist and provide their safety function if these features are not affected by the accident scenario, or these features are affected by the accident scenario and a separate assessment determines that they will survive accident conditions. 18 For external events, likelihood below 10-6/yr conservatively calculated is “beyond extremely unlikely.” DOE-HDBK-1224-2018 36 Passive features assumed to perform their safety functions are evaluated per DOE-STD-3009 for potential designation as SC or SS SSCs and protection as TSR Design Features. In addition, the unmitigated analysis considers facility geometry and physical plausibility, and evaluates the unmitigated likelihood and consequence accordingly. For example, in an explosion scenario, the unmitigated likelihood would not be reduced by an engineered control, such as a vessel purge. However, the unmitigated likelihood of the explosion could be reduced based on physical realities of the facility, activity, or operation that will cause the explosion-initiating condition to occur (accumulation of minimum explosive concentration); no credit is allowed in the reduction of the likelihood for subsequent enabling conditions that will result in the explosion itself (e.g., presence of an ignition and/or oxygen). Thus, the likelihood of the scenarios should be based only the likelihood of the conditions leading to a physically meaningful initiating event, and not on the subsequence engineering or administrative controls that maybe available to prevent the explosion. Additional requirements and guidance on unmitigated analysis are provided in DOE-STD- 3009-2014, Section 3.2.2. Initial conditions may be necessary to define the unmitigated evaluation and are identified as shown on Table 2-7 and another example is provided later in Table 2-11. Credit for the initial condition is factored into the unmitigated likelihood or consequence assignments, and that initial condition is evaluated per DOE-STD-3009 for potential designation as a TSR control (e.g., MAR inventory-specific administrative control). Additional guidance is provided in DOE-STD-3009-2014, Section A.3, and is further discussed in Section 3.3 of this Handbook. A mitigated analysis is performed to determine the effectiveness of SS and SC controls to protect CWs and the public. This analysis should be the same as the unmitigated analysis except that event likelihood is estimated with preventive controls available, and consequences are estimated with mitigative controls available. The selection of preventive and mitigative controls is a judgment-based iterative process to credit sufficient controls that provide confidence that the accident or release is prevented, or if not prevented, the consequences will be reduced to below thresholds of concern. Additional requirements and guidance on mitigated analysis are provided in DOE-STD-3009-2014, Section 3.2.3. The selection and classification of the hazard controls for the mitigated analysis are discussed in Chapter 10 of this Handbook.

Section 50

2.8 HAZARD EVALUATION PRESENTATION IN DSA Results for the unmitigated and mitigated hazard analyses are presented in the DSA hazard evaluation section as discussed in a DSA Section [3.3.2.3], Hazard Evaluation Results (see DOE-STD-3009-2014, Section 4.0). The DSA hazard evaluation table, or alternate hazard evaluation data sheet as described in DOE-STD-3009-2014, has certain essential characteristics: • If multiple types of operations are being analyzed, the table is broken into separate sections where each section presents results for one specific type of operation. • Specific hazard scenarios are described in terms of well-defined events. For example, a HAZOP may have dozens of entries for parameter-guide word combinations. These need to be turned into discrete events. A HAZOP may note that low flow caused by incorrect positioning of valves upstream has no major effect on a process other than operational disruption, while low flow due to a large leak represents a significant operator hazard. Those are two entirely different events. • Initial conditions and assumptions are identified. • Potential preventive or mitigative controls are identified. • Unmitigated and mitigated consequences and likelihoods, and optionally, risk estimates, are identified to support control selection and classification. Source term parameters such as MAR, DOE-HDBK-1224-2018 37 Damage Ratio (DR), Airborne Release Fraction (ARF), and Respirable Fraction (RF) may optionally be listed. Table 2-11 presents an example hazard evaluation table for presentation in the DSA, which builds upon the example provided in Table 2-7. This table includes both the unmitigated and mitigated analysis. There are many different formats that can be used to present this data, bearing in mind that the purpose is to achieve a comprehensive hazard evaluation and an unmitigated analysis of hazard scenarios in terms of potential consequences, their likelihoods, and identification of preventive and mitigative controls. The hazard evaluation table, in whatever format is chosen, should also present the mitigated analysis that credits safety controls, or this could be described in the DSA hazard evaluation results section. The mitigated hazard evaluation can be included as additional columns as shown on Table 2-11, or another convention is to use separate rows for the unmitigated and mitigated evaluations. Appendix A provides another example of a hazard evaluation table for safety design basis documents, as part of the process to perform a Preliminary Hazard Analysis required by DOE-STD-1189-2016, Integration of Safety into the Design Process. Some additional data are included such as methods of detection and more emphasis on further planned improvements and investigations as the design matures. DOE-HDBK-1224-2018 38 Table 2-11. DSA Hazard Evaluation Table Example. Unmitigated Analysis Mitigated Analysis E ve nt Event Description Event Causes Fr eq . L ev el Consequence Level R is k C at eg or y Preventive Features Mitigative Features Fr eq . L ev el Consequence Level R is k C at eg or y x Fuel-powered vehicle suffers a fuel leak due to an impact with TRU waste drums in the Shipping/Receiving Area and is ignited. A forklift carrying a single pallet with four drums impacts a stack (two high) of palletized drums with moderate to severe stress causing breach with material spill of 12 drums and ensuing pool fire that involves 88 additional drums in the Shipping/ Receiving Area.

Section 51

MAR: xx alpha curies in 100 drums (DOE-STD-5506-2007 statistical MAR distribution for Waste Isolation Pilot Plant compliant containers applied, see Table yy) INITIAL CONDITIONS: Staging area inventory limit; TRU waste in metal containers; Metal pallets. • Operator error • Equipmen t malfuncti on • Vehicle impact with fuel spill • Ignition of combustib le and/or flammable materials • Lightning • Wildland fire U Radiological FW – High CW – Moderate MOI – Low Hazardous Chemical FW – Low CW – Low MOI – Low RELEASE MECHANISM: Impact + fire – 12 drums, 10% DR, 1E- 3/0.1 spill ARF/RF plus unconfined burning 1E-2 ARF/RF and 90% confined burning 5E-4 ARF/RF. Pool fire – Conservatively modeled in a single layer of drums with no stacking. Unconfined burning 1E-2/0.1 ARF/RF of 25% of drums that experience lid loss (22 drums) that eject 33% contents and have confined burning 5E-4 ARF/RF of remaining contents in those drums, plus confined burning of 66 drums that experience seal failures (0.5 DR). I II III III III III SSCs: Concrete vehicle barriers. Waste staging building foundation. ADMINISTRATIVE: Procedures and Training Program (Forklift Operator training); Vehicle maintenance program; Fire Protection Program: • Combustible controls Waste handling operations curtailed outdoors during inclement weather; Movement of waste is to be accomplished using electric or manual powered equipment (SAC); Fuel exclusion zone in the Shipping/Receiving Area (SAC). SSCs: None ADMINISTR ATIVE: Procedures and Training Program (workers trained to evacuate); Emergency Preparedne ss Program (emergency response activities). BE U Radiological FW – High CW – Moderate MOI – Low Chemical FW – Low CW – Low MOI – Low III IV IV IV IV IV Notes: 1. Likelihood: A = Anticipated U = Unlikely EU = Extremely Unlikely BEU = Beyond Extremely Unlikely 2. Consequences: H = High M = Moderate L = Low 3. FW = Facility Worker CW= Co-located Worker at 100 m MOI = Maximally-exposed Offsite Individual at 2.9 km 4. Risk Classes: I = Combination of conclusions from risk analysis that identify situations of major concern II = Combination of conclusions from risk analysis that identify situations of concern III = Combination of conclusions from risk analysis that identify situations of minor concern IV = Combination of conclusions from risk analysis that identify situations of minimal concern Bold/Underlined controls are credited in the mitigated analysis to reduce frequency, consequences, and Risk Class, or as Initial Condition DOE-HDBK-1224-2018 39 3 ACCIDENT ANALYSIS This chapter provides an introduction to the accident analysis process. The starting point is a review of the hazard scenarios that were identified in the hazard evaluation table as discussed in Chapter 2 of this Handbook. Specific events are selected for further quantitative accident analysis. This particular chapter also addresses assumption and initial conditions, beyond DBAs/EBAs, and software quality assurance (SQA). In general, formal accident analysis is performed for HC-2 facilities, and may or may not be necessary for HC-3 facilities. Accident analysis is the formal quantification of a subset of accidents, termed DBAs or EBAs by DOE-STD-3009. These accidents represent a complete set of bounding conditions. The basic components of accident analysis are accident type selection, accident scenario development, source term analysis, consequence analysis and control selection. This process is highly iterative to ensure accident scenarios are adequately developed, source term and consequence analysis is bounding, the suite of controls are comprehensive and tailored to reflect accident conditions, and all identified facility hazards are understood and properly controlled.

Section 52

3.1 ACCIDENT TYPE SELECTION It is expected that only a subsect of the total hazard scenarios identified in the hazard analysis will be evaluated as potential DBAs or EBAs in the accident analysis. The predominant purpose of accident analysis is to evaluate the need for SC controls to protect the public from radiological accidents. However, it may also be used to evaluate the need for defense in depth SS controls for protection of the public from radiological or toxic chemical accidents, or for protection of the CWs. The facility worker is not included in the scope of the DSA accident analysis and instead is addressed by the qualitative hazard evaluation discussed in Chapter 2 of this Handbook. DBAs are accidents to be analyzed in a DSA for the design of a new nuclear facility and major modifications to an existing facility. The DSA will also include accident scenarios established during the design of an existing facility. DOE-STD-1189-2008 provides guidance for selecting and analyzing facility-level radiological and/or toxic chemical release events in the DBAs. EBAs are postulated for existing facilities where DBAs were not identified as part of the design. The term EBA recognizes that an existing facility was not designed to DBAs to prevent or mitigate the accident, but rather is evaluated to ensure that it could do so with existing systems or added systems/controls. When an adequate set of DBAs does not exist, EBAs are selected from the following types of events: • Operational accidents — process deviations (such as high temperatures and high pressures) and initiating events internal to the facility (such as fires, explosions, and loss of power resulting in release of radioactive or hazardous materials); • NPH events such as earthquakes, floods, tornadoes, and wildland fires; and, • Man-made external events such as an aircraft crash, external vehicular accident, or gas pipeline break. Two types of EBAs, representative and unique, are defined in DOE-STD-3009-2014 for further quantitative accident analysis. DBAs/EBAs are derived from the spectrum of hazard evaluation scenarios. Three screening steps convert the spectrum of hazard evaluation scenarios into the selected DBAs/EBAs: DOE-HDBK-1224-2018 40 • The first screening identifies potential consequences by population in relative bins of increasing severity. This step will discard scenarios whose higher consequence potential relates only to in- facility workers, because accident analysis focuses on consequences at a distance from the facility. • The second screening looks at accident types. It is necessary for DSA documentation purposes to include at least one hazard and its consequence of each major accident type (e.g., fire, explosion, spill, NPH), unless the scoping calculations for the hazard evaluation demonstrate low consequences that do not have the potential to challenge the offsite Evaluation Guideline (EG) (DOE-STD-3009). These are called representative scenarios with similar preventive and mitigative control sets that bound the collective scenarios for that type. • The final screening consists of looking at the remaining scenarios within a selected accident type to see if any would warrant safety SSC designation to protect the public (and CW if included in the DSA accident analysis, as mentioned above), but involve a different control set than the representative accident already chosen for that type. These are called unique accidents.

Section 53

As an aid in screening the many hazard scenarios identified in the hazard evaluation, representative or unique EBAs may be selected based on organization by accident category (operational, NPH, man-made external event), accident type, and magnitude. Other means of grouping accidents may also be used, especially for complex facilities that may require a broad suite of hazard controls. The selected representative and unique scenarios are designed to bound all other postulated hazard scenarios, including high risk scenarios that still may challenge the EG (as determined during the hazard analysis process using the qualitative risk matrix in Section 2.6.3), or that may have high risk to the co-located worker if that is being evaluated in the accident analysis. An example of an aid to screen hazard scenarios is provided in DOE-STD-5506-2007, Table 3.3-1, Minimum TRU Waste Activity/Hazard Evaluation Event Matrix. This table correlates 25 hazard scenarios or accidents by TRU waste processing activities for use in the hazard evaluation, or as EBAs. The minimum set of events addresses those with the potential for consequences that could be significant enough to warrant crediting preventive or mitigative controls, safety classifications of those controls, and explicit TSRs. Another example aid in screening hazard scenarios for EBA selection is NUREG/CR- 6410, Nuclear Fuel Cycle Facility Accident Analysis Handbook, Table 2-2, Methods of Release of Radioactive Materials Anticipated for Nuclear Process Facilities. 3.2 ACCIDENT ANALYSIS PROCESS The accident analysis process consists of the following sequence of steps intended to document numerical estimates of radiological and toxic chemical consequences to the public (or CW as needed for the DSA hazard evaluation): 1. Define the postulated accident scenario that releases radioactive material or toxic chemicals from the facility. 2. Estimate the damage to the facility to the extent it affects the potential MAR and source term released from the facility, e.g., loss of confinement areas. 3. Identify types and quantities of material involved in the accident MAR. 4. Determine the accident source term. 5. Conduct a dispersion analysis to determine the potential radiological dose or toxic chemical consequences. DOE-HDBK-1224-2018 41 Chapter 4 addresses steps 1-3 for potential accidents at DOE nuclear facilities. Chapter 5 addresses step 4. Chapters 6, 7, and 8 address step 5 for radiological releases, while Chapter 9 addresses step 5 for toxic chemical releases. The potential controls identified in the hazard evaluation are further evaluated in the mitigated accident analysis, using the control selection and classification process described in Chapter 10. 3.3 ANALYSIS INPUTS AND ASSUMPTIONS For most DOE accident analyses, the phenomena being examined have aleatory and systemic uncertainties. Most often it is not possible to derive precise and absolute conclusions from first engineering principles. Therefore, it is important to document the inputs, frame of reference, initial conditions, and assumptions of the accident analysis to ensure that these are not only defensible but conservative. This applies to all elements of the accident analysis process from accident selection, to frequency estimates, and source term and consequence analyses. The focus in this section is on the analysis of inputs and assumptions related to defining scenarios and their frequencies. Section 5.4.1 addresses the use of technically justified input and assumptions related to source term and consequence calculations.

Section 54

Both hazard and accident analyses make use of initial conditions (ICs) to define hazard or accident scenarios to be evaluated. Initial conditions are specific assumptions regarding a facility and its operations that are used to define these scenarios. When not referring to physical facility features, these are sometimes called “initial assumptions,” which creates confusion regarding the need for TSR controls to protect these assumptions. The use of “IC” in this Handbook refers to initial conditions. As discussed in DOE-STD-3009-2014, Sections 3.2.2 and 3.2.3, facilities are analyzed as they exist, or are designed, when quantifying meaningful release mechanisms. For design of new facilities, the unmitigated analysis may need to assume failure of the SSC to determine the potential consequences for safety classifications of SSCs and their appropriate design requirements, for example, design criteria for the selected NPH Design Category. Accident scenario description includes, as appropriate, the operating mode of the system, all pertinent aspects of the physical configuration of the system and its environment, and relevant operating parameters, such as temperature, pressure, material inventories, and confinement, at the time the accident is postulated to begin. Not all of these assumptions are ICs. Where a range of possible ICs, physical properties, or environmental conditions exists, the range is specified, and the most conservative physically credible combination of normal operating conditions is chosen, and an explanation of why the choices are considered conservative should be provided. As stated in Chapter 2, significant assumptions in hazard scenarios should be identified and justified, and this also applies to the accident analysis. Specific examples of ICs include: • A vault or building can withstand NPH events according to its NPH Design Category. • Facility geometry or layout limits accident progression or release with respect to in-facility transport. • Solid TRU waste is contained in a certified Department of Transportation (DOT) Type-A drum (i.e., an additional barrier). • A certain material is present only within a certified DOT Type B shipping container. • Facility and process inventories are limited to those identified. • A passive engineered SSC prevents significant consequences. DOE-HDBK-1224-2018 42 ICs should not include administrative controls, except those necessary to limit the inventory of radioactive or toxic chemical materials, or as specified by the analyst and/or regulator. Controls should be selected to protect assumptions such as MAR critical to the consequence analysis. ICs, and in some cases the associated administrative control associated with the ICs, should warrant some level of Safety SSC designation or SAC to ensure that the assumptions remain valid throughout the operating life of the facility. Defining and documenting ICs and associated administrative controls ensures that they are appropriately controlled, classified as SC or SS, and preserved via TSR operating limits, design features, or SACs.

Section 55

Initial conditions that clearly prevent an accident and are part of the facility design basis (e.g., the structure is designed to withstand vehicle impact) are encouraged. Other safety controls are discouraged from being used since they may skew the unmitigated risk levels and result in unanalyzed or inadequately controlled hazards. For example, a fire door may be improperly credited as an IC for preventing fire propagation. This control may fail (blocked open door) so it does not completely prevent the event, but only reduces the likelihood. If the likelihood reduction “moves” the event risk to a level that does not require further analysis, then the adequacy of the control is not evaluated and the safety functions of the door may not be properly determined. Additionally, this may lead to a larger control set since controls identified for other fire events (e.g., combustible loading limits) may be adequate to protect against this event. Spreadsheet calculation and computer modeling of accident sequences can provide valuable insights on the sensitivity of parameters, as well as indicating what reasonably lower and upper limits of response might be expected so that an overall conservative consequence is estimated (see Section 5.4, Appropriateness of Source Terms). The foundation of any accident analysis can be reduced to a set of inputs and assumptions. An input can be defined as a value feeding into the analyses that can be measured confidently and is readily obtainable. It could, for instance, be the internal freeboard volume of a tank, the specific gravity of a solution, or the metal skin thickness of a 55-gallon drum. An input value would not be expected to change as more information relative to it is obtained. An assumption, on the other hand, is a value feeding into the analyses that is not known with reliability and accuracy. Significant judgment therefore enters into the process of selecting the value or parameter of interest. To address the uncertainty associated with the impact of assumptions and input variables, the default values in DOE-STD-3009 and DOE-HDBK-3010 are to be used to ensure an overall conservative analysis, and an analysis that is conservative to the extent envisioned when the Evaluation Guideline was established. Section 5.4.1 provides additional guidance on the use of non-default values or values that depart from the default values in the above-mentioned standard or handbook. Examples of assumptions would be the rate of in-facility dispersion of a flammable gas leaked into a ventilated volume, the degree to which two spilled chemicals that react together might intermingle (synergism), or the nature of the physical interactions occurring in a structural collapse. The flammable gas leak example can be calculated, but the means of calculation itself introduces an implicit set of theoretical assumptions and uncertainties. The other two examples intrinsically involve making judgments about what is likely to occur. Analysts should strive to use as few assumptions in the accident analysis as possible, but their presence to some degree is inevitable. This point is specifically emphasized in Guidelines for Hazard Evaluation Procedures (CCPS, 2008): Because many of the events considered by the team may never have happened before, the team must use their creativity and judgment to decide whether the potential causes and effects of the accident pose a significant risk. The subjective nature of these deliberations may trouble some people who use the results of these studies because this subjectivity creates a lack of confidence

Section 56

DOE-HDBK-1224-2018 43 in the results. Some people incorrectly believe that if an analyst uses quantitative measures to express the significance of a problem, then the limitation of subjectivity will simply fade away. However, this is not the case. Another consideration is that there may be a difference between the level of conservatism of methods used to derive input parameters used for unmitigated dose consequence calculations and input parameters used to show that the design withstands physical stresses from the accident scenario. For example, dose consequence calculations may use an extremely conservative value or method to calculate aerosol generation for the purpose of determining the source terms and ultimately supporting classifying controls. However, these conservative values or methods may not be appropriate for design basis calculations. 3.4 BEYOND DESIGN/EVALUATION BASIS ACCIDENTS The DSA [Section 3.4] Accident Analysis (see DOE-STD-3009-2014, Section 4.0) evaluates DBAs/EBAs for control selection and classification purposes. Section 3.5 of DOE-STD-3009-2014 provides guidance on the consideration of the need for analysis of accidents, which may be beyond the design basis of the facility. This section addresses accident analysis of these extreme events. The purpose of an analysis of accidents beyond the design or evaluation basis of the facility is to provide (1) a perspective of the residual risk associated with the operation of the facility, and (2) additional perspectives for accident mitigation. That standard describes that Beyond Design Basis Accidents/Beyond Evaluation Basis Accidents (BDBAs/BEBAs) need not be analyzed to the same degree of detail as DBAs/EBAs. The analysis is intended to provide insight into the magnitude of consequences of such events and to identify potential facility vulnerabilities. The analysis has the potential, therefore, for identifying additional facility features that could prevent or reduce severe accident consequences. Unlike the unmitigated conservative analysis for DBAs/EBAs, a realistic analysis of potential BDBA/BEBA consequences may be performed to determine whether accidents have a much larger consequence (a “cliff edge effect”) than the largest DBA/EBA. After the March 11, 2011 Fukushima Dai-Ichi nuclear plant accident in Japan, DOE embarked upon several initiatives to investigate the safety posture of its nuclear facilities relative to Beyond Design Basis Events (BDBEs). These initiatives included issuing Health, Safety and Security (HSS) Safety Bulletin 2011-01, “Events Beyond Design Safety Basis Analysis,” conducting pilot evaluations to refine possible process improvements, and conducting two DOE nuclear safety workshops. DOE issued two reports documenting the results of these initiatives: Review of Requirements and Capabilities for Analyzing and Responding to BDBEs (DOE, 2011); and A Report to the Secretary of Energy: Beyond Design Basis Event Pilot Evaluations, Results and Recommendations for Improvements to Enhance Nuclear Safety at DOE Nuclear Facilities (DOE, 2013). A summary description of the pilot evaluation process and results is provided in the HSS Operating Experience Level 1 notice (DOE HSS OE-1, 2013), “Improving Department of Energy Capabilities for Mitigating Beyond Design Basis Events.” Additional details of the pilot acti

Something wrong with this record? Tell us