Archive

DOE-STD-1189-2008, Integration of Safety Into the Design Process

Functional areas: Safety, Integrated Project Team, Project Execution Plan, Tailoring Strategy, Risk Management, Documented Safety Analysis

The Standard is written primarily for the use of the contractor(s) responsible for the design of a new facility. The processes described in the Standard, in addition to facilitating the integration of safety into design by the contractor, result in the development of several documents for input to the federal project team, the Federal Project Director and his Integrated Project Team (IPT). Superseded by DOE-STD-1189-2016.
doe-std-1189-2008.pdf977.87KB
Version history and related documents

Superseded by

A newer version replaces this document.

View full version history

Document text

Text extracted from the attached file. Refer to the original document for the authoritative version.

Section 1

NOT MEASUREMENT SENSITIVE DOE-STD-1189-2008 March 2008 DOE STANDARD INTEGRATION OF SAFETY INTO THE DESIGN PROCESS U.S. Department of Energy AREA SAFT Washington, DC 20585 DISTRIBUTION STATEMENT A. Approved for public release; distribution is unlimited. DOE-STD-1189-2008 Page ii This document is available on the Department of Energy Technical Standards Program Web Page at http://www.hss.energy.gov/nuclearsafety/techstds/ DOE-STD-1189-2008 Page iii PREFACE The U.S. Department of Energy (DOE) has approved this Standard for use by DOE and its contractors. In a memorandum to DOE elements, dated December 5, 2005, on integration of Safety-in- Design, the Deputy Secretary of Energy stated, “I expect safety to be fully integrated into design early in the project. Specifically, by the start of the preliminary design, I expect a hazard analysis of alternatives to be complete and the safety requirements for the design to be established. I expect both the project management and safety directives to lead projects on the right path so that safety issues are identified and addressed adequately early in the project design.” DOE Standard 1189 has been developed to show how project management, engineering design, and safety analyses can interact to successfully implement the Deputy Secretary’s expectations. These interactions are a fundamental element necessary in the integration of safety throughout the DOE Acquisition Management System. They are key to the timely identification, evaluation, and adjudication of Safety-in-Design issues early in project life. This Standard provides the Department’s expectations for incorporating safety into the design process for new or major modifications to DOE Hazard Category 1, 2, and 3 nuclear facilities, the intended purpose of which involves the handling of hazardous materials, both radiological and chemical, in a way that provides adequate protection for the public, workers, and the environment. The Standard describes the Safety-in-Design philosophies to be used with the project management requirements of DOE Order (O) 413.3A, Change (Chg) 1, Program and Project Management for the Acquisition of Capital Assets, and incorporates the facility safety criteria in DOE O 420.1B, Facility Safety, as a key foundation for Safety-in-Design determinations. The requirements provided in the above DOE Orders and the expectations in this Standard provide for identification of hazards early in the project and the use of an integrated team approach to design safety into the facility. The basic Safety-in-Design precepts are as follows: • appropriate and reasonably conservative safety structures, systems, and components are selected early in project designs; • project cost estimates include these structures, systems, and components; and • project risks associated with safety structures, systems, and components selections are specified for informed risk decision-making by the Project Approval Authorities. The provisions of this Standard, when implemented in conjunction with DOE O 413.3A, Chg 1, and its guidance documents, are consistent with the core functions and guiding principles of Integrated Safety Management (ISM), as described in DOE P 450.4, Integrated Safety Management Policy. The Standard provides guidance on a process of integration of Safety-in-Design intended to implement the applicable ISM core functions—define the work, analyze the hazards, establish the controls—necessary to provide protection of the public, workers, and the environment from

Section 2

DOE-STD-1189-2008 Page iv harmful effects of radiation and other such toxic and hazardous aspects attendant to the work. Important ISM guiding principles involved in this process and addressed in this Standard are identification of safety standards and requirements and development of hazard controls tailored to the work to be performed. The process includes documentation and timely review of safety design evolution to ensure feedback and improvement, leading to design and construction that can lead to operations authorization. The Standard does not instruct designers how to design nor instruct safety personnel how to perform safety analyses. Rather, the Standard provides guidance on how these two disciplines and project management can interface and work together to incorporate safety into design. A project is expected to evolve over time, and the project safety design basis is also expected to evolve. The expectation is that within this evolution process, unanticipated issues will be minimized. Some of the key concepts that are included in the Standard are the following. 1. The importance of the Integrated Project Teams (IPT), federal and contractor, including a contractor Safety Design Integration Team (SDIT), and effective coordination among these teams. The SDIT comprises both safety and design subject matter experts and is the heart of the safety and design integration effort. 2. The development of a Safety Design Strategy (SDS) that provides a roadmap for strategizing how important safety issues will be addressed in the design and in the tailoring in the development of key safety documentation. The SDS should be initiated based on a statement of DOE expectations for Safety-in-Design developed during the pre- conceptual stage and should be submitted during the conceptual design stage and updated and refined through the design process. 3. The development, in the conceptual design stage, of facility-level design basis accidents (DBA) that provide the necessary input to the identification and classification of important safety functions. These classifications (i.e., safety class, safety significant, seismic design basis) provide design expectations for safety structures, systems, and components (SSC). 4. The development of objective radiological criteria for safety and design classification of SSCs. These criteria relate to public and collocated worker-safety design considerations. 5. The identification and application of nuclear safety design criteria as provided by DOE O 420.1B and its associated guides. 6. The development of guidance for the preparation of a Conceptual Safety Design Report (CSDR), a Preliminary Safety Design Report (PSDR), and the Preliminary Documented Safety Analysis (PDSA). These reports are required by DOE O 413.3A, Chg 1, for Hazard Category 1, 2, and 3 nuclear facilities, and they must be approved by DOE as part of the project approvals to proceed to the next design or construction phase. The intent of these reports and their approval is to ensure that the directions and decisions made regarding project safety are explicitly identified and dealt with in early stages of design. The objective is to reduce the likelihood of costly late reversals of design decisions involving safety. DOE-STD-1189-2008 Page v

Section 3

7. The definition, as needed, of a Risk and Opportunities Assessment that recognizes the risks of proceeding at early stages of design (especially conceptual design) on the basis of incomplete knowledge or assumptions regarding safety issues and the opportunities that may arise during preliminary and final design to reduce costs through alternative or refined design concepts or better knowledge regarding the uncertainties. This assessment is intended to be input to the Risk Management Plan assessments for a project. These key elements of the Standard have several intersections and possible overlaps with the guides for the implementation of DOE O 413.3A, Chg 1. These guides should also be consulted for more complete information on the associated activities and documents. In addition, several directives and standards deal with some aspects of Safety-in-Design that are also addressed in this Standard, such as safety system classification and seismic design bases. For new facility design, these directives and standards are supplemented by this Standard. The directives and standards in this category are as follows: • DOE G 420.1-1, Nonreactor Nuclear Safety Design Criteria and Explosive Safety Guide for use with DOE O 420.1 Facility Safety; • DOE G 420.1-2, Guide for the Mitigation of Natural Phenomena Hazards for DOE Nuclear Facilities and Nonnuclear Facilities; • DOE G 421-1-2, Implementation Guide for Use in Developing Documented Safety Analyses to Meet Subpart B of 10 CFR 830; • DOE-STD-1020-2002, Natural Phenomena Hazards Design and Evaluation Criteria for Department of Energy Facilities; • DOE-STD-1021-93, Natural Phenomena Hazards Performance Categorization Guidelines for Structures, Systems, and Components; and • DOE-STD-3009-94, Change Notice (CN) 3, Preparation Guide for U.S. Department of Energy Nonreactor Nuclear Facility Safety Analysis. Nuclear safety design basis documents required by DOE O 413.3A, Chg 1 and by Title 10, Code of Federal Regulations (CFR) Part 830, Nuclear Safety Management, Subpart B, Safety Basis Requirements, for new projects and major modifications must be developed consistent with the expectations and guidance in this Standard. There are a number of DOE Directives and Technical Standards specifically referenced in this Standard. Unless specifically prohibited or limited, successor documents may be used in place of the referenced directive or standard. Successor documents are subsequent revisions to the specified directives and standards issued through the DOE Directives System or DOE Technical Standards Program, as applicable, (for example, DOE O 420.1B would be a successor document to DOE O 420.1A) or the documents that replace them as defined within those programs (for example, a DOE directive may cancel all or part of a directive and replace those provisions with new provisions in a new directive). However, documents issued outside the Directives System and the Technical Standards Program are not considered to be successor documents to these directives and standards. Contracts and regulations may require that specific revisions be applied, particularly for individual projects (for example, 10 CFR Part 830 requires that hazard categorization be performed consistent with DOE-STD-1027-92, Change Notice 1, September DOE-STD-1189-2008 Page vi 1997). The provisions of 10 CFR Part 830, Appendix A to Subpart B, Table 2, (known as the “safe harbor methodologies” for 10 CFR Part 830) specifically permit use of successor documents for the listed directives and standards.

Section 4

DOE-STD-1189-2008 Page vii SAFETY DESIGN GUIDING PRINCIPLES 1. DOE Order 420.1B, Facility Safety, is utilized and addressed in design activities, as applicable. Design teams should be able to clearly articulate strategies in the design that address DOE O 420.1B expectations and include them in the design/safety basis information. 2. Control selection strategy to address hazardous material release events is based on the following order of preference at all stages of design development. • Minimization of hazardous materials is the first priority. • Safety structures, systems, and components (SSCs) are preferred over Administrative Controls. • Passive SSCs are preferred over active SSCs. • Preventative controls are preferred over mitigative controls. • Facility safety SSCs are preferred over personal protective equipment. • Controls closest to the hazard may provide protection to the largest population of potential receptors, including workers and the public. • Controls that are effective for multiple hazards can be resource-effective. 3. Design codes and standards incorporated into the DOE O 420.1B guides are to be followed, unless specific exceptions are taken to those listed and approved by DOE. 4. The risk and opportunity assessment includes consideration of the Safety-in-Design approaches selected to address project cost contingencies and appropriate mitigation strategies for the risks/opportunities identified for the strategies selected. 5. Early project decisions on a technical approach are conservative in order to establish appropriate cost and schedule baselines for the project. 6. The Critical Decision (CD) packages portray safety-item selections, bases, and risks and opportunities, with proposed mitigation strategies and cost and contingencies, to enable informed risk decision-making by the project approval authorities regarding the project technical basis and cost. 7. The project team includes appropriate expertise and is established early in the project cycle. 8. Safety personnel are used from the onset of project planning to help ensure that appropriate hazards and techniques for hazard management are considered (e.g., material-at-risk [MAR] limitation, prevention techniques, and operationally effective design solutions). 9. Important safety functions, such as facility building confinement, confinement ventilation approach and systems, fire protection strategies and systems, security requirements, life- safety considerations, emergency power systems, and associated seismic design bases are addressed during conceptual design. 10. The safety design team ensures sufficient process definition is available, particularly at the conceptual and preliminary design stages, to enable major safety cost drivers to be included DOE-STD-1189-2008 Page viii in the design documentation, along with their associated safety functions and design criteria. The team also identifies the risks and opportunities associated with the selections identified and develops mitigation strategies that are included in the cost-estimate contingencies. Details may not be available in early project stages to identify all hazards and needed hazard controls. 11. All stakeholders are important to the process. Stakeholder issues are identified early and addressed. 12. To ensure that the project/facility configuration can be managed appropriately, the basis for decisions related to safety is clearly documented. DOE-STD-1189-2008 Page ix

Section 5

TABLE OF CONTENTS PREFACE....................................................................................................................... iii SAFETY DESIGN GUIDING PRINCIPLES.................................................................... vii ABBREVIATIONS AND ACRONYMS........................................................................... xiv 1.0 INTRODUCTION...................................................................................................1 1.1 Background ................................................................................................1 1.2 Roadmap to the Standard for Categories of Users.....................................2 1.3 Applicability ................................................................................................3 1.4 Must and Should ........................................................................................4 1.5 Supplementary Guidance Documents ........................................................4 2.0 PROJECT INTEGRATION AND PLANNING ........................................................6 2.1 Contractor Integrated Project Team ...........................................................6 2.2 Safety Design Integration Team .................................................................7 2.3 Safety Design Strategy...............................................................................8 2.4 Safety Interface with Project Management ...............................................11 2.4.1 Relationship to Project Management........................................... 11 2.4.2 General Expectations .................................................................. 15 2.4.3 Planning ...................................................................................... 15 2.4.4 Tailoring of Requirements............................................................ 16 2.4.5 Safety Interface Requirements .................................................... 16 3.0 SAFETY CONSIDERATIONS FOR THE DESIGN PROCESS ...........................18 3.1. Pre-Conceptual Phase .............................................................................19 3.2 Conceptual Design Phase ........................................................................22 3.3 Preliminary Design Phase ........................................................................27 3.4 Final Design Phase ..................................................................................30 3.5 Construction, Transition, and Closeout.....................................................33 3.5.1 Introduction .................................................................................. 33 3.5.2 Construction................................................................................. 33 3.5.3 Development of Safety Basis ....................................................... 33 3.5.4 Checkout/Acceptance, Testing and Commissioning .................... 35 3.5.5 Readiness Reviews ..................................................................... 35 3.5.6 Project Closeout........................................................................... 35 DOE-STD-1189-2008 Page x 4.0 HAZARD AND ACCIDENT ANALYSES..............................................................37 4.1 Pre-conceptual Planning Phase ...............................................................37 4.2 Conceptual Design Phase ........................................................................37

Section 6

4.3 Preliminary Design Phase ........................................................................42 4.4 Final Design ............................................................................................44 5.0 NUCLEAR SAFETY DESIGN CRITERIA............................................................46 6.0 SAFETY REPORTS............................................................................................48 6.1 Safety Input to the Conceptual Design Report .........................................48 6.2 Conceptual Safety Design Report ............................................................49 6.3 Preliminary Safety Design Report (and PDSA) ........................................49 6.4 Change Control for Safety Reports as Affected by Safety-in-Design Activities ...................................................................................................50 7.0 SAFETY PROGRAM AND OTHER IMPORTANT PROJECT INTERFACES .....52 7.1 Quality Assurance ....................................................................................52 7.2 10 CFR 851 Worker Safety and Health Program .....................................54 7.3 Fire Protection ..........................................................................................55 7.4 Infrastructure ............................................................................................56 7.5 Nuclear Criticality Safety ..........................................................................57 7.6 Radiological Protection.............................................................................58 7.7 Human Factors.........................................................................................58 7.8 Security ....................................................................................................59 7.9 Environmental Protection ...........................................................................60 7.10 Hazardous Material ..................................................................................61 7.11 Radiological and Hazardous Waste Management....................................61 7.12 Emergency Preparedness ........................................................................62 7.13 External Reviews.....................................................................................62 7.14 System Engineer Program .......................................................................63 7.15 Procedures, Training and Qualification.....................................................64 8.0 ADDITIONAL SAFETY INTEGRATION CONSIDERATIONS FOR PROJECTS.71 8.1 Integration of Safety into Facility Modifications.........................................71 8.1.1 Review of Existing Hazard Analysis............................................. 74 8.1.2 Major Modifications ...................................................................... 75 DOE-STD-1189-2008 Page xi 8.1.3 Determining a Major Modification................................................. 75 8.2 Construction Projects within Operating Facilities......................................79 8.3 Government Furnished Equipment...........................................................79 8.3.1 GFE-Provider Responsibilities ..................................................... 80 8.3.2 GFE End User Responsibilities.................................................... 82 APPENDIX A SAFETY SYSTEM DESIGN CRITERIA ................................................ A-1

Section 7

A.1 Seismic Design Basis ............................................................................. A-1 A.2 Safety Classification of SSCs ................................................................. A-5 A.3 Existing Facilities and Major Modifications of Existing Facilities............. A-6 APPENDIX B CHEMICAL HAZARD EVALUATION..................................................... B-1 B.1 Screening of Hazardous Chemical Materials.......................................... B-1 B.2 Public and Collocated Worker Protection Criteria................................... B-2 B.3 Estimating Exposures to Collocated Workers and the Public ................. B-2 B.4 Chemical Mixtures .................................................................................. B-4 APPENDIX C FACILITY WORKER HAZARD EVALUATION ......................................C-1 APPENDIX D ADDITIONAL FUNCTIONAL CLASSIFICATION CONSIDERATIONS .D-1 D.1 Selection and Classification of a Complete Control Set..........................D-1 D.2 Criteria for Selecting SS Major Contributors to Defense-in- Depth.........D-1 APPENDIX E SAFETY DESIGN STRATEGY.............................................................. E-1 E.1 Introduction............................................................................................. E-1 E.2 SDS Format and Content ....................................................................... E-1 APPENDIX F SAFETY-IN-DESIGN RELATIONSHIP WITH THE RISK MANAGEMENT PLAN................................................................................................................. F-1 APPENDIX G HAZARDS ANALYSIS TABLE DEVELOPMENT ..................................G-1 DOE-STD-1189-2008 Page xii G.1 Scenario Description ..............................................................................G-1 G.2 Initiating Event Frequency ......................................................................G-2 G.3 Unmitigated Consequence Evaluation....................................................G-2 G.4 Safety Functions.....................................................................................G-2 G.5 Preventive Features (Design and Administrative) ..................................G-3 G.6 Method of Detection ...............................................................................G-4 G.7 Mitigative Features (Design and Administrative) ....................................G-4 G.8 SSC Safety Control Suite and Safety Functions.....................................G-5 G.9 Mitigated Consequences ........................................................................G-5 G.10 Planned Analyses, Assumptions and Risk/Opportunity Identification.....G-5 G.11 Hazards Analysis Table..........................................................................G-6 APPENDIX H CONCEPTUAL SAFETY DESIGN REPORT ........................................H-1 H.1 Introduction.............................................................................................H-1 H.2 CSDR FORMAT AND CONTENT GUIDE ..............................................H-2 APPENDIX I PRELIMINARY AND FINAL DESIGN STAGE SAFETY DOCUMENTATION ........................................................................................... I-1 I.1 Introduction.............................................................................................. I-1 I.1.1 Preliminary Safety Design Report ................................................. I-1

Section 8

I.1.2 Preliminary Documented Safety Analysis ..................................... I-3 I.2 PSDR/PDSA FORMAT AND CONTENT GUIDE..................................... I-4 APPENDIX J MAJOR MODIFICATION DETERMINATION EXAMPLES......................J-1 Example 1 ..........................................................................................................J-1 Example 2 ..........................................................................................................J-3 Example 3 ..........................................................................................................J-5 Example 4 ..........................................................................................................J-6 CONCLUDING MATERIAL................................................................. Concluding Page 1 DOE-STD-1189-2008 Page xiii LIST OF FIGURES AND TABLES  Table 2‐1. Roles and Responsibilities ____________________________________________ 12 Figure 3‐1.  Pre‐Conceptual Phase_______________________________________________ 21 Figure 3‐2.  Conceptual Design Phase ____________________________________________ 23 Figure 3‐3.  Preliminary Design Phase____________________________________________ 28 Figure 3‐4.  Final Design Phase _________________________________________________ 32 Table 7‐1.  Typical Actions Associated with Project Life‐Cycle Stages ___________________ 65 Table 7‐2.  Example Nuclear Criticality Safety Design Criteria_________________________ 70 Figure 8‐1.  Facility Modification Process _________________________________________ 73 Table 8‐1.  Major Modification Evaluation Criteria _________________________________ 77 Table A‐1.  Guidance for SDC Based on Unmitigated Consequences of SSC Failures in a Seismic  Event ______________________________________________________________________A‐3 Table F‐1.  Safety‐in‐Design Considerations for Risk and Opportunity Analysis ___________ F‐3 Table I‐1. Sample SMP Roadmap_______________________________________________ I‐39 DOE-STD-1189-2008 Page xiv ABBREVIATIONS AND ACRONYMS AEGL Acute Exposure Guideline Level AHJ Authority Having Jurisdiction ALARA As Low as Reasonably Achievable ANS American Nuclear Society ANSI American National Standards Institute ARF Airborne Release Fraction ARR Airborne Release Rate ASME American Society of Mechanical Engineers BOD Basis of Design BPV Boiler and Pressure Vessel Code CD Critical Decision CDR Conceptual Design Report CFR Code of Federal Regulation CHG Change CIPT Contractor Integrated Project Team CN Change Notice COA Condition of Approval CSDR Conceptual Safety Design Report CSE Criticality Safety Evaluation CSP Criticality Safety Program CX Categorical Exclusion D&D Decontamination and Decommissioning DBA Design Basis Accident DBT Design Basis Threat DCF Dose Conversion Factor DID Defense-in-Depth DNFSB Defense Nuclear Facilities Safety Board DOE U.S. Department of Energy DR Damage Ratio DSA Documented Safety Analysis EEGL Emergency Exposure Guidance Level DOE-STD-1189-2008 Page xv EMP Emergency Management Program EPA U.S. Environmental Protection Agency EPHA Emergency Planning Hazard Assessment ERPG Emergency Response Planning Guideline FONSI Finding of No Significant Impact FHA Fire Hazard Analysis FMEA Failure Modes and Effects Analysis FW Facility Worker GFE Government Furnished Equipment HA Hazards Analysis HASP Health and Safety Plan HAZOP Hazard and Operability Analysis HCN Health Code Number HEPA High Efficiency Particulate Air HPR Highly Protected Risk

Section 9

IPT Integrated Project Team ISM Integrated Safety Management ITS Important To Safety MAR Material-at-Risk MC&A Material Control and Accountability N/A Not Applicable NCS Nuclear Criticality Safety NEPA National Environmental Policy Act NFPA National Fire Protection Association NPH Natural Phenomena Hazard O Order OECM Office of Engineering and Construction Management OMB Office of Management and Budget ORR Operational Readiness Review OSHA Occupational Safety and Health Administration DOE-STD-1189-2008 Page xvi P&ID Piping and Instrumentation Diagram PC Performance Category PDSA Preliminary Documented Safety Analysis PEP Project Execution Plan PFD Process Flow Diagram PHA Preliminary Hazards Analysis PSDR Preliminary Safety Design Report QA Quality Assurance RF Respirable Fraction ROD Record of Decision RMP Risk Management Plan SAC Specific Administrative Control SC Safety Class SCAPA Subcommittee on Consequence Assessment and Protective Actions SDIT Safety Design Integration Team SDC Seismic Design Criteria SDS Safety Design Strategy SE System Engineer SER Safety Evaluation Report SME Subject Matter Expert SMP Safety Management Program SNM Special Nuclear Material SPEGL Short-Term Public Emergency Guidance Level SRI Safeguards Requirements Identification SRID Standards and Requirements Identification Document SS Safety Significant SSC Structure, System, and Component STD Standard TEC Total Estimated Cost TEDE Total Effective Dose Equivalent TEEL Temporary Emergency Exposure Limit TPQ Threshold Planning Quantity TSR Technical Safety Requirements DOE-STD-1189-2008 Page xvii USQ Unreviewed Safety Question DOE-STD-1189-2008 Page xviii DEFINITIONS Conceptual Safety Design Report (CSDR) – A Conceptual Safety Design Report is developed to: a. document and establish a preliminary inventory of hazardous materials, including radioactive materials and chemicals; b. document and establish the preliminary hazard categorization of the facility; c. identify and analyze primary facility hazards and facility Design Basis Accidents; d. provide an initial determination, based on preliminary hazard analysis, of Safety Class and safety significant structures, systems, and components (SSC); e. include a preliminary assessment of the appropriate Seismic Design Category for the facility itself, as well as the safety significant structures, systems, and components; f. evaluate the security hazards that can impact the facility safety basis (if applicable); and g. include a commitment to the nuclear safety design criteria of DOE O 420.1 (or proposed alternative criteria). Conceptual Safety Validation Report (CSVR) – The report prepared by DOE that documents the DOE review of the Conceptual Safety Design Report. Documented Safety Analysis (DSA) – A documented analysis of the extent to which a nuclear facility can be operated safely with respect to workers, the public, and the environment, including a description of the conditions, safe boundaries, and hazard controls that provide the basis for ensuring safety. Fire Hazards Analysis (FHA) – A comprehensive assessment of the potential for a fire at any location to ensure that the possibility of injury to people or damage to buildings, equipment, or the environment is within acceptable limits (NFPA 801). Hazards Analysis (HA) – This analysis supports PDSA development during Preliminary and Final Design and identifies the types and magnitudes of hazards that are anticipated in the facility. This level of hazard analysis expands the PHA to include evaluation of the process hazards.

Section 10

Integrated Project Team (IPT) – An Integrated Project Team is a cross-functional group of individuals organized for the specific purpose of delivering a project to an external or internal customer. For the purposes of this Standard, this team may be composed of both Federal and contractor (or subcontractor) personnel, and it will support and report to the Federal Project Director. For complex or hazardous projects, a subordinate contractor IPT (CIPT) may be formed to support the Federal IPT and Project Director. Major Modification – Modification to a DOE nuclear facility that is completed on or after April 9, 2001, that substantially changes the existing safety basis for the facility. Preliminary Documented Safety Analysis Report (PDSA) – Documentation prepared in connection with the design and construction of a new DOE nuclear facility or a major modification to a DOE nuclear facility that provides a reasonable basis for the preliminary DOE-STD-1189-2008 Page xix conclusion that the nuclear facility can be operated safely through the consideration of factors such as: (1) the nuclear safety design criteria to be satisfied; (2) a safety analysis that derives aspects of design that are necessary to satisfy the nuclear safety design criteria; and (3) an initial listing of the safety management programs that must be developed to address operational safety considerations. Preliminary Hazards Analysis (PHA) – This document provides a broad hazard-screening tool that includes a review of the types of operations that will be performed in the proposed facility and identifies the hazards associated with these types of operations and facilities. The results of the PHA are used to determine the need for additional, more detailed analysis; serve as a precursor where further analysis is deemed necessary; and serve as a baseline hazard analysis when further analysis is not indicated. The PHA is most applicable in the conceptual design stage, but it is also useful for existing facilities and equipment that have not had an adequate baseline hazard analysis. Preliminary Safety Design Report (PSDR) – The report developed during Preliminary Design that updates and provides additional site and design details to those provided in the CSDR. The PSDR follows the format and content of the PDSA produced during final design. Preliminary Safety Validation Report (PSVR) – The report prepared by DOE that documents the DOE review of the Preliminary Safety Design Report. Safety Design Strategy (SDS) – The SDS, as part of the Project Execution Plan, provides a strategy for the early safety design basis development starting in the pre-conceptual design phase. The SDS documents all applicable Safety-in-Design expectations for the early project phases. Safety-in-Design – The process of identifying and incorporating appropriate structures, systems, and components (SSCs) and their associated safety functions and design criteria into the project design to provide adequate protection for workers and the public. Safety Design Integration Team (SDIT) – This contractor team, when established, supports the Federal or the Contractor Integrated Project Team (IPT) to ensure the integration of safety into the design process. The composition of the team is adjusted as necessary to ensure the proper technical representation commensurate with the analyzed hazards and the specific project phase. The SDIT ultimately supports decisions to be made by the Federal Project Director.

Section 11

Safety Evaluation Report (SER) – The report prepared by DOE to document (1) the sufficiency of the documented safety analysis for a Hazard Category 1, 2, or 3 DOE nuclear facility; (2) the extent to which a contractor has satisfied the requirements of Subpart B of this part; and (3) the basis for approval by DOE of the safety basis for the facility, including any conditions for approval. DOE-STD-1189-2008 Page xx Safety Limits – The limits on process variables associated with those safety-class physical barriers, generally passive, that are necessary for the intended facility function and that are required to guard against the uncontrolled release of radioactive materials. DOE-STD-1189-2008 Page 1 1.0 INTRODUCTION 1.1 Background Federal Project Directors are accountable for the planning, programming, budgeting, and acquisition of capital assets. The principal goal of the Department of Energy (DOE) Acquisition Management System is to deliver capital assets on schedule, within budget, and fully capable of meeting mission performance and environment, safety, and health standards. DOE Federal Project Directors are responsible for managing capital asset projects with integrity and in compliance with applicable laws and contractual provisions. Major DOE objectives include obtaining quality products, ensuring timeliness of performance, controlling cost, and preventing or mitigating adverse events. To achieve these goals, Federal Project Directors assemble an integrated team that includes members from other DOE functional areas, such as budget, financial, legal, safety, and contracting, to assist them with the planning, programming, budgeting, and acquisition of capital assets. DOE O 413.3A, Chg 1,, Program and Project Management for the Acquisition of Capital Assets, was developed to implement the DOE acquisition policy and Office of Management and Budget (OMB) Circulars1 regarding planning, budgeting, and acquisition of capital assets; management accountability and control; financial management; and management of Federal information resources. The process, described in the Order and associated DOE directives and guidance2 and implemented by DOE organizational elements, is referred to as the DOE Acquisition Management System. A fundamental element that is necessary to achieve the DOE goal for capital asset acquisition is the integration of safety throughout the DOE Acquisition Management System. This Standard supports the DOE objective by providing guidance on those actions and processes important for integrating safety into the acquisition process for DOE Hazard Category 1, 2, and 3 nuclear facilities. Integrating safety into design is more than just developing safety documents that are accepted by the design function and organization: it requires that safety be understood by, and integrated into, all functions and processes of the project. Therefore, this Standard identifies interfaces, methodologies, and documentation strategies that might support proper integration. In addition, the Standard provides format and content guidance for the development of safety documentation required by DOE O 413.3A, Chg 1,3 and 10 CFR 830, Nuclear Safety Management. These required documents include the Conceptual Safety Design Report (CSDR), the Preliminary Safety Design Report (PSDR), and the Preliminary Documented Safety Analysis (PDSA). The Standard provides information and the methodology for identifying and analyzing hazards, selecting and

Section 12

1 OMB Circulars A-11 (Part 7), A-123, A-127, and A-130. 2 The DOE Office of Engineering and Construction Management (OECM) also publishes Project Management Practices that are available on the OECM web page: oecm.energy.gov. 3 The application and use of any revision to DOE O 413.3A,Chg 1, will be determined by DOE for any ongoing project. DOE-STD-1189-2008 Page 2 classifying appropriate safety structures, systems, and components (SSC), and integrating safety personnel at pertinent phases of project initiation, definition, and execution. 1.2 Roadmap to the Standard for Categories of Users The Standard is written primarily for the use of the contractor(s) responsible for the design of a new facility. The processes described in the Standard, in addition to facilitating the integration of safety into design by the contractor, result in the development of several documents for input to the federal project team, the Federal Project Director and his Integrated Project Team (IPT). These documents include: • the Safety Design Strategy (SDS), which supports the development of a Tailoring Strategy and the Project Execution Plan (PEP) required by DOE O 413.3A, Chg 1; • a Risk and Opportunities Assessment, which supports the Risk Management Plan required by Order 413.3A, Chg 1; and • three safety reports required by Order 413.3A, Chg 1, (Conceptual Safety Design Report, Preliminary Safety Design Report, and the Preliminary Documented Safety Analysis). Chapter 2 of this Standard discusses the preparation, reviews, and approvals of these safety documents. There are several categories of target audiences/users of the Standard. The parts of the Standard particularly relevant to all audiences are the Preface, including the key concepts and guiding principles upon which the Standard was developed, this Introduction (Chapter 1), Chapter 2, Project Integration and Planning, and Chapter 3, Safety Considerations for the Design Process, which provides an overall perspective of the Safety-in-Design process of this Standard. Project management, both federal and contractor, will also find Chapter 7, Safety Program and Other Important Project Interfaces, Appendix E, Safety Design Strategy, and Appendix F, Safety-in-Design Relationship with the Risk Management Plan informative and useful to their responsibilities and functions. Project safety personnel and DOE safety reviewers will find that Chapter 4, Hazard and Accident Analyses; Chapter 5, Nuclear Safety Design Criteria; Chapter 6, Safety Reports; Appendices A through D, which deal with safety SSC and seismic classifications; and Appendix G, Hazards Analysis Table Development are directed toward their functions and responsibilities. Appendix F, Safety-in Design Relationship with the Risk Management Plan is also important to safety personnel because they are the source of initial input to the Risk and Opportunities Assessment related to safety assumptions and uncertainties that can affect the project’s cost and schedule. DOE-STD-1189-2008 Page 3 Project design personnel should be familiar with Chapter 5, Nuclear Safety Design Criteria, Chapter 7, Safety Program and Other Important Project Interfaces, and Appendices A through D, which address safety design classifications for safety SSCs. Appendices H and I, which are format and content guidance for the preparation of the CSDR, PSDR, and PDSA, are important to the project team members charged with the preparation of these documents and to the DOE reviewers of them.

Section 13

For projects that are potential major modifications of existing facilities, Chapter 8, Additional Safety Integration Considerations for Projects, and Appendix J, Major Modification Determination Examples are especially relevant. 1.3 Applicability This Standard applies to the design and construction of the following: • new DOE Hazard Category 1, 2, and 3 nuclear facilities; • major modifications to DOE Hazard Category 1, 2, and 3 nuclear facilities (as defined by 10 CFR 830); and • other modifications to DOE Hazard Category 1, 2, and 3 nuclear facilities managed under the requirements of DOE O 413.3A, Chg 1. The activities and processes in this Standard may be applied to new facilities and to modifications to those facilities not listed above. DOE O 413.3A fundamentally establishes the roles, responsibilities, and requirements for the Department in the DOE Acquisition Management System. The Contractor Requirements Document (CRD) attached to that Order delineates requirements for contractors in the Project Management System. The tasks, deliverables, and suggested tools in this Standard are generally intended to be provisions primarily for DOE contractors, unless they are specifically identified as DOE actions. DOE responsibilities for review and approval of contractor submittals identified in this Standard are discussed in Chapter 2. DOE-STD-1104-2008, Review and Approval of Nuclear Facility Safety Basis and Safety Design Basis Documents, provides guidance for the review of safety design basis documents. For DOE projects subject to regulation by the Nuclear Regulatory Commission (NRC), where requirements in this standard overlap or duplicate applicable NRC requirements for nuclear safety (including quality assurance), the NRC requirements apply to the design, construction, operation, and decommissioning of DOE facilities and will be used to satisfy redundant or duplicative requirements from this standard. This exclusion does not apply to requirements for which NRC defers to DOE or does not exercise regulatory authority. DOE-STD-1189-2008 Page 4 1.4 Must and Should The verbs “must” and “should” are used throughout this Standard. If this Standard is listed as a contract requirement, or otherwise directed by DOE for a facility or project, the DOE contractor or other organization required to meet this Standard must comply with all of the applicable provisions that include the word “must”. Provisions that use the word “should” are not required, but they are recommended in order that the expectations of this Standard can be implemented, particularly for complex or hazardous activities. The majority of “must” statements in this Standard are derived from DOE directives, primarily DOE O 413.3A, Chg 1, DOE O 420.1B, and 10 CFR 830. That is, they reflect required actions necessary to comply with one or more of these directives. Where an activity is required by a DOE directive but is not directly involved with the integration of safety with design, it is assumed to be carried out by the project and may be indicated by “is” or “are” rather than a “must”. In addition, this Standard includes “must” statements associated with the Key Concepts and Guiding Principles that work together in enabling effective Safety-in- Design. Their application is necessary for the effective integration of safety into a project or facility design. The Guiding Principles of the Standard are derived from O 420.1B and O 413.3A, Chg 1. The Key Concepts include features introduced in this Standard and are consistent with effective implementation of O 420.1B and O 413.3A, Chg 1, regarding integration of Safety-in-Design. Failure to apply one or more of these principles or concepts to a new project or major modification design results in an effort that cannot claim to have fully implemented this Standard.

Section 14

Requirements specific to this Standard are defined only for objectively measurable parameters or conditions. Requirements are not defined when objective evidence of compliance is not achievable. Requirements unique to this Standard include the establishment of a Safety Design Strategy (SDS), which is in support of the tailoring strategy and Project Execution Plan (PEP) required by DOE O 413.3A, Chg 1; the Risk and Opportunities Assessment, which is in support of the Risk Management Plan required by DOE O 413.3A, Chg 1; and Appendix A, which specifies new safety design classification criteria. The remaining unique “must” statements are judged to be necessary to comply with the Safety-in-Design processes described in this Standard. Specific elements of this Standard may appropriately be tailored to fit a specific project and the SDS should establish the tailoring strategy. However, the Key Concepts and Guiding Principles represent high-level expectations for Safety-in- Design and are therefore applicable independent of tailoring. 1.5 Supplementary Guidance Documents DOE M 413.3-1, Project Management for the Acquisition of Capital Assets, and any guides developed in support of DOE O 413.3A, Chg 1, should be referred to and used DOE-STD-1189-2008 Page 5 in conjunction with this Standard to enhance safety integration into project management processes and decisions. DOE-STD-1189-2008 Page 6 2.0 PROJECT INTEGRATION AND PLANNING DOE O 413.3A , Chg 1, requires the formation of an Integrated Project Team (IPT), to be led by a Federal Project Director. Subgroups to the IPT may be chartered during the project, including a Contractor Integrated Project Team (CIPT) led by the Project Manager, as well as subgroups to the IPTs for specific tasks or deliverables. Further information on the roles, responsibilities, and functions of the IPT are provided in the Office of Engineering and Construction Management (OECM) Project Management Practices, Integrated Project Teams (see footnote 2). The Federal Integrated Project Team (IPT) will comprise both DOE Federal staff and contractors, and the contractor Project Manager will be a key member of the Federal IPT. If a Contractor IPT is formed for certain complex or hazardous projects, interfaces between the two IPTs must be established to ensure synchronization of information and reviews for all disciplines and functions essential to the project. The interfaces and interactions necessary for effectively integrating safety into project design are addressed in this Standard. Contractor IPT activities and deliverables support the Federal IPT and project decisions that are made by DOE. Similar to the roles and functions of the Federal IPT, Safety-in-Design roles and functions for each project should be specifically tailored for that project. The contractor should establish a Safety Design Integration Team (SDIT), especially for complex or hazardous projects. The SDIT would be the Safety-in-Design team support for the CIPT, if a CIPT is established, and would also be the key Safety-in-Design interface with the Federal IPT. For small or less- complex projects with a straightforward safety strategy, an SDIT may not be required, and any contractor Safety-in-Design input would go directly to the CIPT or Federal IPT through appropriate subject matter experts (SME). If an SDIT is formed, it should implement the Safety Design Strategy (SDS). The SDS and SDIT are discussed in sections 2.2 and 2.3.

Section 15

DOE O 413.3A , Chg 1, requires the appointment of a Federal Project Director and formation of an Integrated Project Team (IPT) during the conceptual design phase. Based on the documentation required at CD-1, such as an acquisition strategy, Project Execution Plan (PEP), a design review, and preparation of a Conceptual Safety Design Report (CSDR), appointing a Federal Project Director and forming an IPT and the contractor SDIT should be among the first orders of business as soon as mission need is approved (CD-0), if not before. 2.1 Contractor Integrated Project Team A CIPT may be formally established for complex or hazardous projects, with the Contractor Project Manager serving as the team leader.4 If established, the CIPT 4 It is recommended that a CIPT be considered for all Hazard Category 1 and 2 nuclear projects. If a Federal IPT is collocated with the contractor project team and has an active direct and dedicated management role for the project, a CIPT may not be warranted. The intent is to form a dedicated IPT, ultimately reporting to and supporting the Federal Project Director that will have active day-to-day roles and responsibilities on complex nuclear projects. DOE-STD-1189-2008 Page 7 provides the overarching contractor focal point specifically charged with executing a project through interactions with and support to the IPT and Federal Project Director. As the team members are representative of all competencies that influence or affect the execution of the project, the CIPT provides an important forum where project issues can be openly discussed and resolved. As a project progresses from initiation to transition/closeout completion, the CIPT membership may change to incorporate the necessary skills and expertise. Although a core team is expected to provide direct support to the project, team membership may be either full-time or part-time, depending on the scope and complexity of the project. The contractor safety lead should be a member of the CIPT and should be responsible for representing all safety issues before the team and for ensuring that project issues are appropriately shared with the SDIT. 2.2 Safety Design Integration Team If established, the SDIT should include the key members of the contractor project team who implement Safety-in-Design for the project. The SDIT is expected to be a dynamic organization that will be made up of a limited core team comprising safety, design, and operations personnel, as well as SMEs, who will come together for short or extended periods of time to accomplish a task. Often these task-specific teams may consist of the same people each time, but they will have a targeted responsibility that requires their time and attention away from their normal activities. For example, the SDIT will be quite active, and the membership will increase, while performing a hazard analysis. As noted previously, the CIPT may fulfill the role of the core SDIT for small projects or projects with a simple, straightforward safety strategy. Team composition is critical for the SDIT to be successful. A multi-disciplinary team is needed to identify and analyze the hazards in the facility and to ensure that the designed controls: • are adequate to perform the safety function; • do not create an undue burden on operations; • can be designed to fulfill the safety function; and • fit within the project cost and schedule.

Section 16

The SDIT (or the project safety lead if there is no SDIT) is responsible for drafting a SDS and also for preparing a Risk and Opportunity Assessment. The Risk and Opportunity Assessment is input to the project’s Risk Management Plan and is summarized in that document. Although the appropriate team composition will depend on the process or unit operation being developed, it should always include the core team and appropriate supporting specialists. The core SDIT should consist of safety personnel (CIPT safety lead), engineering and design personnel responsible for the process or facility, operations personnel, and the line management of the design organization. In DOE-STD-1189-2008 Page 8 addition to the core team, supporting specialists may be included as appropriate from the following areas: • security (depending on the project, security may need to be a core team member); • design, including appropriate disciplines (Civil, Structural, Electrical, Instrumentation, etc.); • geotechnical/seismic; • health physics and radiological protection (shielding, uptakes, or exposure to hazardous materials, etc.); • safety, accident, or risk analysts with expertise needed by the team; • criticality safety; • research and development (process, equipment development specialists); • process chemistry; • industrial safety (Occupational Safety and Health Administration [OSHA] issues); • fire protection; • emergency preparedness; • environmental protection and waste management; • human factors; and • interfacing system representatives. The presence of specialists will vary according to the process or unit operation that will be designed or analyzed and with the phase of the project. Communication within the CIPT and the SDIT is paramount to understanding the major issues and ensuring that the solutions put forward as design or planned operations are appropriate and fully meet the needs of design, construction, project constraints, facility operations, and safety. Timely and effective interactions between the CIPT and the Federal IPT are crucial for mission success. 2.3 Safety Design Strategy A Safety Design Strategy (SDS) must be developed for all projects subject to this Standard. DOE expectations for execution of safety activities during design should be identified and documented to support the development of the statement of mission need. The documentation of the DOE expectations for execution of safety during design is developed by the DOE safety lead and should define high-level DOE expectations. The SDS should then be based on those DOE expectations and should be developed as early in the Conceptual Design Phase as practicable. These DOE DOE-STD-1189-2008 Page 9 expectations are used during the development of the project SDS in the conceptual design stage. The SDS is updated throughout the design process. As the initial project safety management integration tool, the SDS provides the preliminary information to gauge the scope of significant hazards and the general strategy for addressing those hazards. The SDS is a tool to guide design, document the safety analysis approach, support the safety design basis documents to be developed during each project phase, and establish concurrence on major safety decisions related to project cost and schedule. It provides a single source for project safety policies, philosophies, major safety requirements, and safety goals to maintain alignment of safety with the design basis during project evolution.

Section 17

The SDS should contain enough detail to guide design on overarching design criteria, establish major safety SSCs, and identify significant project risks associated with the proposed facility relative to safety. Specifically, the SDS should address the following four main attributes of safety integration as the project progresses through project planning and execution: • The guiding philosophies or assumptions to be used to develop the design, • The Safety-in-Design and safety goal considerations for the project, • The approach to developing the overall safety design basis for the project, and • Significant discipline interfaces impacting safety. For projects that may not follow the traditional project cycle, the SDS provides a vehicle to describe how requirements for safety documentation will be tailored to that particular project approach while satisfying DOE O 413.3A, Chg 1. For certain projects, safety assumptions and criteria may be known when DOE approves the mission need at CD-0 (e.g., the facility will be a Hazard Category 2 nuclear facility). These assumptions and criteria should be in the SDS and should be used for developing the conceptual design and CSDR. The SDS is not intended to supplant or duplicate the required safety deliverables to or include information that should be contained in other project documentation (e.g., schedules, resource requirements). The SDS, at the conceptual design phase, is prepared by the SDIT (or the contractor safety lead in the absence of an SDIT) as an evolution of the DOE expectation for the execution of safety activities during design. It is approved by DOE Safety Basis Approval Authority and the Federal Project Director, with the advice of the Chief of Nuclear Safety (CNS) or the Chief of Defense Nuclear Safety (CDNS), as appropriate. Updates to the SDS should focus on those major safety decisions that influence project cost (e.g., seismic design criteria, confinement ventilation, safety functional classification, and strategy). Interim SDS updates can provide a means by which all DOE-STD-1189-2008 Page 10 parties are kept informed of important changes due to safety in design evolution between Critical Decision points. This Standard anticipates that the eventual safety basis for the facility being constructed or modified will be based on the format and content of DOE-STD-3009- 94, CN 3. If a different methodology is applicable to the project or modification (e.g. legacy facilities or departmental decontamination and decommissioning activities), the SDS should establish that expectation, and the format of the PSDR/PDSA as provided in this Standard should be modified as appropriate. However, the expectations for integration of safety into the design process and application of nuclear safety design criteria apply to all projects and modifications within the scope of this Standard. The safety documentation for a major modification project must include an SDS and a PDSA. Modification projects that require a new or revised hazards/accident analysis or require new hazard controls must be evaluated using the Major Modification Evaluation Criteria to determine if the modification constitutes a “major modification” and requires a PDSA (see Table 8.1). This evaluation must be documented in the PEP, the SDS itself, or in another appropriate project authorization document.

Section 18

Modification projects that do not involve a “substantial change to the safety basis” to an existing nuclear facility as defined in 10 CFR 830 are not considered “major modifications” and do not require a CSDR, PSDR or a PDSA. For modifications subject to DOE O 413.3A, Chg 1, the SDS should document the type and scope of the hazard/accident analysis, describe the supporting safety documentation and DSA amendment or revision to be prepared, and should explain the process to develop and review and approve these documents (see Section 2.4.4, “Tailoring of Requirements”). These modifications may represent a capital asset project other than a major modification that is subject to the acquisition processes in DOE O 413.3A, Chg 1. This Standard and the included Safety-in-Design approaches may be tailored for these modifications. As previously mentioned, in such cases the basis for determining that the modification is not a major modification must be documented. Guidance for determining whether a facility modification involves a “substantial change to the facility safety basis” and is considered to be a “major modification” under the requirements of 10 CFR 830, is provided in detail in Section 8.1. Modifications not requiring a new or revised hazard analysis/accident analysis and not requiring new hazard controls are considered simple modifications. These modifications need not be subject to the safety integration provisions of this Standard. The SDS is discussed in detail in Appendix E and the SDS role in each project phase is discussed in Chapter 3 of this Standard, along with the Safety-in-Design activities for that phase. Section 6.4 addresses the change control process that is applicable to safety documentation. DOE-STD-1189-2008 Page 11 2.4 Safety Interface with Project Management 2.4.1 Relationship to Project Management DOE O 413.3A, Chg 1, governs the execution of most DOE capital asset acquisition projects. The integration of the safety design development and approval processes into the execution cycle for DOE Hazard Category 1, 2, and 3 nuclear facilities is the focus of this Standard. This section defines how the project management requirements in DOE O 413.3A, Chg 1, relate to this Standard. Many projects are executed as “design-bid-build” projects with defined conceptual, preliminary, and final design phases. This is the underlying acquisition model presumed in this Standard. However, many projects are executed using different acquisition models and strategies. Accordingly, it is incumbent upon the Federal Project Director and the IPT to examine the provisions in this Standard and apply its processes and guidance appropriately to the project. This appropriate application of the processes, guidance, and methodologies in this Standard to the relevant phases of a project is known as “tailoring”. However, the project management requirements of DOE O 413.3A, Chg 1, will govern the timing and substance of critical DOE project decisions. In accordance with DOE O 413.3A, Chg 1, contractors responsible for the design of DOE Hazard Category 1, 2, and 3 nuclear facilities must implement this Standard, including the safety criteria of Appendix A, and submit the following safety basis documents for DOE approval (unless otherwise agreed to). • Conceptual Design Stage: Safety Design Strategy • Conceptual Design Stage: Conceptual Safety Design Report (CSDR) • Preliminary Design Stage: Preliminary Safety Design Report (PSDR)

Section 19

• Final Design Stage: Preliminary Documented Safety Analysis (PDSA) • Prior to Operations: Documented Safety Analysis and Technical Safety Requirements The Federal Project Director is responsible for ensuring the implementation of the requirements of DOE O 413.3A, Chg 1, and does this through contract requirements and through support of DOE entities. As such, the Federal Project Director approves or concurs on the approval of all safety submittals of the project. The DOE Safety Basis Approval Authority approves of the CSDR, PDSR, and PDSA based on a review by a Safety Basis Review Team. Table 2-1 shows the entities responsible for preparation, review, and approval of these safety documents. DOE-STD-1189-2008 Page 12 Table 2-1. Roles and Responsibilities Responsibility Product/ Document Prepare Review Approve Interface with Other Documents/Products Safety Design Strategy (SDS) Contractor SDIT or, in the absence of an SDIT, the contractor safety lead is responsible for the preparation of the SDS as early in the Conceptual Design phase as practicable. The SDS is updated, as necessary, throughout the design stages. DOE Safety Basis Review Team and the Integrated Project Team Federal Project Director and the Safety Basis Approval Authority. Pre-conceptual planning activities will provide the starting point. The SDS is part of or can be referenced from the tailoring strategy part of Project Execution Plan. Risk & Opportunity Assessment Contractor SDIT or, in the absence of an SDIT, the contractor safety lead prepares the Risk and Opportunity Assessment. It is updated, as appropriate, throughout the design stages. Federal Integrated Project Team and the DOE Safety Basis Review Team Federal Project Director The Risk and Opportunities Assessment is input to the Risk Management Plan. It is summarized in the Risk Management Plan. Conceptual Safety Design Report (CSDR) Contractor SDIT or, in the absence of an SDIT, the contractor safety lead is responsible for the preparation of the CSDR. DOE Safety Basis Review Team and the Integrated Project Team Approval is via approval of the CSVR. The CSDR needs to be consistent with the Conceptual Design Report (CDR). Conceptual Safety Validation Report (CSVR) DOE Safety Basis Review Team. DOE-STD-1104 provides guidance for review of the CSDR and preparation of the CSVR. Federal Integrated Project Team Safety Basis Approval Authority approves with concurrence by the Federal Project Director The CSVR results from the DOE review of the CSDR. It documents the findings of that review and is a prerequisite to Critical Decision-1 (CD-1). DOE-STD-1189-2008 Page 13 Responsibility Product/ Document Prepare Review Approve Interface with Other Documents/Products Preliminary Safety Design Report (PSDR) Contractor SDIT or, in the absence of an SDIT, the contractor safety lead is responsible for the preparation of the PSDR DOE Safety Basis Review Team and the Integrated Project Team Approval is via approval of the PSVR. The PSDR needs to be consistent with the Preliminary Design, as documented for the Preliminary Design Review. Preliminary Safety Validation Report (PSVR) DOE Safety Basis Review Team. DOE-STD-1104 provides guidance for review of the PSDR and preparation of the PSVR. Federal Integrated Project Team Safety Basis Approval Authority approves with concurrence by the Federal Project Director The PSVR results from the DOE review of the PSDR. It documents the findings of that review and is a prerequisite to Critical Decision-2 (CD-2).

Section 20

Preliminary Documented Safety Analysis (PDSA) Contractor SDIT or, in the absence of an SDIT, the contractor safety lead is responsible for the preparation of the PDSA. DOE Safety Basis Review Team and the Integrated Project Team Approval is via approval of the SER The PDSA needs to be consistent with the Final Design that is presented as part of the Critical Decision-3 (CD-3). Safety Evaluation Report (SER) DOE Safety Basis Review Team. DOE-STD-1104 provides guidance for review of the PDSA and preparation of the SER. Federal Integrated Project Team Safety Basis Approval Authority approves with concurrence by the Federal Project Director The SER results from the DOE review of the PDSA. It documents the findings of that review and is a prerequisite to Critical Decision-3 (CD-3). Documented Safety Analysis (DSA) and Technical Safety Requirements (TSR) Contractor SDIT or, in the absence of an SDIT, the contractor safety lead, augmented by an operations team are responsible for the preparation of the operational DSA and TSR. DOE Safety Basis Review Team and the Integrated Project Team Approval is via approval of the SER The DSA is an evolution of the PDSA. Any changes need to be identified and justified. The TSR is developed, based on the DSA. DOE-STD-1189-2008 Page 14 Responsibility Product/ Document Prepare Review Approve Interface with Other Documents/Products Safety Evaluation Report DOE Safety Basis Review Team. DOE-STD-1104 provides guidance for review of the DSA and TSR and preparation of the SER. Safety Basis Approval Authority The SER results from the DOE review of the operational DSA and TSR. It documents the findings of that review and is a prerequisite to Critical Decision-4 (CD-4). DOE-STD-1189-2008 Page 15 2.4.2 General Expectations This Standard focuses on establishing the safety design for a nuclear facility in an incrementally progressive way to provide some assurance that the safety design basis will be demonstrated to be acceptable when the design is completed. Accordingly, early project decisions on the technical approach should be reasonably conservative in establishing appropriate cost and schedule baselines for the project. The project is expected to evolve over time; the project design and safety design basis are also expected to evolve. The expectation is that within this evolution process, unanticipated issues will be minimized. To ensure that the project/facility configuration can be managed appropriately, the basis for decisions related to safety must be clearly documented. This includes, for example, controls selection, material-at-risk (MAR), process options, inputs, and assumptions. This documentation allows later decisions to modify the design or safety design basis based on knowledge of the original decision and not just on the current understanding of the issue. The overarching philosophy and logic in this Standard is that a heightened degree of conservatism is demanded in the earlier phases of a project when the design details are not available. In this vein, a broader or more conservative set of SSCs that would be designated as safety systems might be provisionally selected for conceptual design than might actually be required when the design is completed. The degree of conservatism can be relaxed, and, accordingly, the provisional set of SSCs may be refined when justified by evolving information as design progresses. This strategy should minimize the need for significant safety and major cost revisions to the project in later design cycles.

Section 21

2.4.3 Planning The project management practices required by DOE O 413.3A, Chg 1, emphasize appropriate planning for the execution of projects. The development and approval of the safety design is an essential element of the project execution cycle and warrants appropriate planning. The overall planning for project execution, of which safety is an integral part, is documented and approved in the PEP. To the extent desired by the IPT, and as specified in the project’s tailoring documentation, the SDS and other safety planning documentation may be included within the PEP, or be included in other required project management or safety documentation as described is subsection 2.4.4 below. DOE-STD-1189-2008 Page 16 2.4.4 Tailoring of Requirements DOE O 413.3A, Chg 1, allows tailoring of the CD process for projects based on “risk, size, and complexity.” The tailoring approach for the CD process is typically described in a “tailoring strategy” or as part of the PEP. Tailoring of the safety design basis development steps and documents for a project is also permitted based on the level of risk posed by the facility chemical and radiological hazards, the complexity of the processing operations, and the scope of the hazards analysis required for the project. Tailoring of the safety design basis steps and documents is described in Section 2.3. The tailoring approach for safety design basis documents must be: • described in the SDS; and • summarized in the PEP. DOE O 413.3A, Chg 1, specifies what safety documentation is required as prerequisites to obtaining specified CDs. This Standard provides guidance on the format and content of the safety documentation. As established in the tailoring strategy for the project, the information and approvals for documentation, as required by this Standard, can be sequenced, organized, and bundled as the project team desires to meet the safety performance measures in this Standard. For example, this option allows the project team to satisfy requirements often associated with separate documents or documents that are produced sequentially to be delivered in a manner that is effective and efficient for project team decisions. This Standard does not specify how a project would be phased or how the project supports its CDs. Instead, it specifies the safety expectations for a project during the project’s execution cycle. The mapping of when CDs are sought, what information requirements pertain to the CDs, and how the project will be executed will be specified in the tailoring strategy or, if desired, in the PEP. Should a significant change in the safety strategy occur, such changes may be documented by a revision to the SDS. Neither the PEP nor the applicable approved safety document (e.g., CSDR) need be revised to address the change. The safety documentation can be updated at the next CD safety document submittal (e.g., PSDR for the CSDR example above). 2.4.5 Safety Interface Requirements The following are the requirements for the safety interface. • In the process of selecting early, design-phase safety SSCs using reasonably conservative principles, it is recognized that project and design progression might cause the SSC designation to evolve. Significant impacts on the cost and schedule for potential changes in SSC designation are captured in the evolving cost and schedule baseline projections for the project, either explicitly (as part of projections for the evolving baseline design) or as an explicit

Section 22

DOE-STD-1189-2008 Page 17 contingency on those projections, if they are not included in the baseline design. • The methods and criteria by which SSCs are designated (either safety class, safety significant, or defense-in-depth) during project phases must be justified and documented. • The IPT must include applicable expertise to advise the Federal Project Director on matters relating to nuclear safety. DOE O 413.3A, Chg 1, requires the Chief, Defense Nuclear Safety (CDNS) and the Chief of Nuclear Safety (CNS) to validate that Federal personnel assigned to the Integrated Project Team as nuclear safety experts are appropriately qualified. DOE-STD-1189-2008 Page 18 3.0 SAFETY CONSIDERATIONS FOR THE DESIGN PROCESS This chapter discusses general concepts for fostering integration of safety considerations into design activities (Safety-in-Design) during the pre-conceptual, conceptual, preliminary, and final design stages. As a project design progresses, the design organization determines the appropriate safety features to be incorporated into a project, and obtains concurrence by the Integrated Project Team (IPT). The design organization and IPT should identify and reach agreement on these features as early in the process as it is possible and practical to do so. The goal is to make decisions at as early a point as possible, recognizing that as design progresses, these decisions may need to be revisited. In particular, it is important that the design decisions be transparent and visible to all stakeholders and that any related issues regarding them are recognized and included in the Risk Management Plan (RMP), as discussed in Appendix F. The design process for a complex facility is highly interactive and iterative. Therefore, coordination and communication among the activities and the individuals performing them is vital to the overall success of these activities. Because the design is evolving as the hazards and safety analyses are performed, it is essential that the IPT and Safety Design Integration Team (SDIT) are aware of the current state of the design at all times and that design staff are current on the status of the hazards/safety analyses work. Mechanisms must be established to ensure these communications. Failure to incorporate safety considerations early in the design process can result in prohibitively expensive changes later in the design process if they are recognized only at the Preliminary Documented Safety Analysis (PDSA) development stage (i.e., during final design). To document safety design features early in the design process, DOE O 413.3A, Chg 1, prescribes reports at both the conceptual design phase (Conceptual Safety Design Report or CSDR), and the preliminary design phase (Preliminary Safety Design Report or PSDR), in addition to the required PDSA before the start of construction. The content and detail of these reports should be tailored to the safety information and maturity of the design as appropriate for the specific project. This chapter discusses the Safety-in-Design considerations and activities to be performed during the initiation (pre-conceptual planning), conceptual design, preliminary design, and final design phases. The chapter also depicts the typical flow and interrelationships among project management, design development, and safety design basis development activities for these four phases. The design process for a specific project may vary considerably, commensurate with the tailoring of a project. The tailored design process is identified in the Project Execution Plan (PEP), which also evolves with the project activities. The Safety Design Strategy (see Section 2.3 and Appendix E) is developed consistent with, and works in conjunction with, the PEP and guides project design and safety documentation development.

Section 23

The four figures in this Chapter graphically portray the processes supporting each of the primary design phases of a typical project. These processes are associated with one or more of the marked divisions that represent Program and Project Management, Project Engineering, or Safety Design Basis activities. Within each marked division, activities may be shown as grouped together within a dashed box. These activities are so closely associated DOE-STD-1189-2008 Page 19 that they are elements of a larger effort. In turn, these boxes may be shown joined with double-headed arrows, representing the integration needed to support the individual efforts and the fact that these activities may iterate. In reality, there is no two-dimensional depiction of these processes that is complete and yet effective in illustrating all of the relationships involved. 3.1. Pre-Conceptual Phase During the pre-conceptual phase, the program identifies any gap between its current and required capabilities and compares the gap to the strategic plan. This gap analysis is translated into a Mission Needs Statement, which serves as the vehicle for formally establishing a project to close the identified performance gap. Safety-in-Design efforts must begin during the pre-conceptual phase of a potential design and construction project when initial planning activities occur. The project team must consider the Safety Design Guiding Principles and key concepts of this Standard in the development of the project requirements to support the Mission Needs package. To ensure these principles are incorporated at this phase, a safety lead should be designated as early as practical as a key member to be assigned to the IPT when it is formed. The safety lead will be responsible for providing safety input to guide early project planning consistent with the Guiding Principles and key concepts. DOE expectations for execution of safety activities during design should be clearly communicated commensurate with the hazard and control selection information available at this early stage in the potential project. Safety-in-Design goals should be identified; expectations for adherence to the design requirements of DOE O 420.1B, and any special safety requirements or expectations (e.g., active confinement) for the project should be included. These DOE Expectations for Safety-in-Design efforts should be formally documented. An initial alternative analysis is performed during the pre-conceptual planning phase to determine if a new facility or a modification to an existing facility would best satisfy the mission need. The analyst needs to have some understanding of the process technology that could be used for the facility to perform this analysis. In some cases, separate alternative analyses may be required to select the best process technology to achieve the facility mission. The material inputs and outputs, together with the process technology options, must be identified to provide the minimum amount of information needed for an initial assessment of the hazards posed by each proposed process. Detailed alternatives analyses will be completed later during the conceptual design phase. Upper-level facility functions and performance requirements may also be developed in this phase. The physical form and quantities of the nuclear materials to be generated and received, and the waste materials to be produced, should be identified. This is important to ensure that the initial material release analyses can provide meaningful information. Generally, a simple process model that shows the material inputs and outputs will satisfy this purpose.

Section 24

DOE-STD-1189-2008 Page 20 The hazard analysis at the pre-conceptual phase involves a qualitative high-level consideration of the facility/process risks performed in conjunction with the facility and initial technology selection alternative reviews. See Section 4.1 for guidance on hazard analysis for this phase of the project. Figure 3-1 illustrates the interactions of project management and safety design basis development activities during the pre-conceptual design phase. DOE-STD-1189-2008 Page 21 Figure 3-1. Pre-Conceptual Phase P ro je ct E ng in ee rin g P ro gr am a nd P ro je ct M an ag em en t S af et y D es ig n B as is DOE-STD-1189-2008 Page 22 3.2 Conceptual Design Phase The overall goal for Safety-in-Design at the conceptual design phase is to evaluate alternative design concepts, to prepare a Safety Design Strategy (SDS), and to provide a conservative safety design basis for a preferred concept to proceed into preliminary design. The intent is to perform sufficient analyses to make sound safety decisions during conceptual design and to document any risks and opportunities associated with selections and the associated project cost range and schedule impacts. A Quality Assurance Program (QAP), compliant with 10 CFR 830, Subpart A, and DOE O 414.1C is established early in the project. The QAP describes the planned quality-related activities, surveillances, and assessments and is developed in the project conceptual phase and updated as the project matures. Section 8.9 of this Standard addresses the QAP in more detail. The conceptual design phase presents a key opportunity for the safety analysis to influence the design. Figure 3-2 illustrates the interactions of project management, design development, and safety design basis development activities during the conceptual design phase. As can be seen in the figure, there are many activities that rely upon each other and that, in some cases, are iterative. DOE-STD-1189-2008 Page 23 Figure 3-2. Conceptual Design Phase DOE-STD-1189-2008 Page 24 The earlier in the project life cycle that requirements are identified and defined, the more effectively and efficiently the project will progress through the various phases and will meet project baselines, agreements, and commitments. As a project progresses from identification of the mission need through concept exploration, development, and design, the process of identifying, analyzing, and refining requirements is continual and is always ultimately traceable to specifications and designs. Once approved, the requirements document becomes part of the baseline requirements and is to be controlled through the change control process described in the PEP. When design requirements are established, alternatives are evaluated to establish a process approach, and facility and equipment arrangements are determined. The configuration alternatives are evaluated against technical, safety, cost, and schedule criteria. As design requirements are established for each alternative, engineering and safety personnel will begin to identify alternative facility layout and processing configurations. The DOE Expectations for Safety-in-Design and the Safety Design Guiding Principles and key concepts (see the Preface of this Standard) must be applied to these efforts to ensure that the design requirements and the selection of the preferred processing and facility arrangement alternatives are performed in a way that will result in a safe design. To ensure optimum Safety-in-Design considerations, a safety analyst must be involved as part of the evaluation of the processes for each of the various alternatives.

Section 25

The SDS, at the conceptual design phase, is prepared by the SDIT (or the project safety lead in the absence of an SDIT) based on the DOE Expectations for Safety-in- Design. It is approved by DOE Safety Basis Approval Authority and the Federal Project Director, with the advice of the Chief of Nuclear Safety (CNS) or the Chief of Defense Nuclear Safety (CDNS), as appropriate. As the processing approach and facility arrangements are being developed, alternatives are evaluated to select the design architecture; that is, the structures, systems and components (SSC). During the alternative analysis process, the IPT and SDIT ensure that the relative hazards, as well as the costs and uncertainties associated with the hazard controls that may be required to address these hazards, are considered for each alternative. The IPT and SDIT should also consider alternative facility locations that minimize the exposure of the public and collocated workers to facility releases or that minimize the threat of external events associated with nearby facilities. Due to the need to develop an integrated process which assures that both the security and safety requirements are met, it is important to specify physical security needs early in the conceptual design process. This allows security and safety professionals to identify and resolve any potential conflicts and/or identify risks that will be incorporated into the risk and opportunities assessment. Recommendations from the initial security Vulnerability Assessment should be identified, including the need for new technologies, or incorporation of new technologies, and factored into the DOE-STD-1189-2008 Page 25 preliminary hazards analysis. To aid in this integration, the strategy for security design should be documented and incorporated, as appropriate, into the SDS. Once the alternatives have been evaluated and a selected alternative designated, the design and safety work to identify and describe the SSCs to satisfy the facility performance requirements and to perform the facility processing operations is initiated. Safety design requirements and considerations in DOE O 420.1B, must be addressed in the developing design. To the extent that the design maturity will support in this conceptual phase, the Conceptual Safety Design Report (CSDR) includes a listing of applicable 420.1B design criteria and a brief summary of the implementation approach proposed for each applicable criterion. See Chapter 5 of this standard for further guidance on nuclear design criteria and Appendix H for documentation in the CSDR. The SDIT should formally recognize this point in the conceptual design phase as a point where refocusing of efforts from alternatives comparisons and selection to the goal of producing a conceptual design that integrates safety into the design is needed. The focus of safety work at this point in conceptual design is to (1) document and establish a preliminary inventory of hazardous materials; (2) document and establish the preliminary hazard categorization of the facility; (3) identify and analyze primary facility hazards and facility-level design basis accidents; and (4) provide an initial determination, based on the PHA, of safety class and safety significant SSCs. See Section 4.2 of this standard for guidance on hazard analysis for this project phase.

Section 26

As a result of the requirements analysis and the alternatives analyses, a general process block-flow diagram or description of the process operations based on the selected technology and a general description of the more significant hazard controls should be developed for the project. A Safety-in-Design Risk and Opportunity Assessment for the conceptual design is used to evaluate the overall safety design basis risks and opportunities associated with the project. The risks include the uncertainties related to the possibility that there may be additional costs and schedule impacts that are not yet identified because the design is still immature or there are uncertainties associated with the viability of the design and programmatic strategies selected. Opportunities refer to the potential opportunities to reduce the costs or improve the schedules as the design matures and to select proposed hazard controls or other cost and schedule drivers that are identified as not being necessary after all. The Risks and Opportunities Assessment associated with the safety strategies that are selected is essential to a robust assessment for the project. Appendix F provides information to ensure a complete Risk and Opportunities Assessment is performed for the project. In the conceptual design phase, the studies that still need to be completed to verify key safety strategy assumptions, make technology selections, or better understand the process operations or safety implications must be identified and should be documented in the SDS, CSDR, and CDR. Corresponding risks associated with DOE-STD-1189-2008 Page 26 possible outcomes of the studies identified should be included in the Safety-in-Design Risk and Opportunity Assessment. The following major safety activities take place during the conceptual design phase. • The requirements analysis from the pre-conceptual phase is further developed to include safety functions and SSC requirements and is documented in the project technical requirements documents and in the CDR. • Alternative design concepts are analyzed and a preferred alternative is selected. • An SDS is developed to guide design including description of strategies to address major hazards, commitment to appropriate safety design criteria and security issues as applicable. • A Preliminary Hazards Analysis (PHA) is performed to provide the basis for facility preliminary hazard categorization. (Appendix G provides guidance on the information requirements for the PHA.) • A preliminary Fire Hazards Analysis is performed that identifies and assesses fire risk and defines levels of Safety-in-Design that do not necessarily come from the PHA. • A preliminary security Vulnerability Assessment is completed and factored into the PHA. • A facility-level DBA Analysis is performed to identify the major facility safety functions needed. • SSCs and their safety classifications are proposed for the major safety functions. (Appendices A, B, C, and D provide guidance on safety classifications.) • The initial Safety-in-Design Risk and Opportunities Assessment is developed based on assumptions that may have been necessary and on uncertainties in safety and design considerations. (This assessment is input to the project Risk Management Plan and assessment.) • The CDR is developed to document the final conceptual design architecture. • The CSDR is developed to document the bases for the safety design aspects of the facility. (Appendix H provides guidance on the development and format and content of a CSDR.)

Section 27

• Required technical studies necessary to resolve risks and opportunities are identified. • The initial baseline range estimates are identified. • DOE reviews the CSDR and prepares a Conceptual Safety Validation Report (CSVR). DOE-STD-1189-2008 Page 27 3.3 Preliminary Design Phase Safety-in-design efforts during the preliminary design phase are intended to be incremental rather than a complete reevaluation of the conceptual design. The hazard analysis (HA) will evolve from a facility-level analysis to a system level hazard analysis as design detail becomes available. As the HA is refined, the selection of controls, safety functions, and classifications developed during the conceptual design phase must be revisited to ensure they are still appropriate. Decisions made during the preliminary design phase provide the basis for the approach to detailed design and construction. Decisions that are reversed after this phase, for whatever reason, can have significant impacts on overall project cost and schedule. It is essential that contractor and DOE safety personnel are totally engaged and fully participate in design reviews during this phase, so their views and advice can be considered in the evolving design in a timely fashion. Figure 3-3 depicts the workflow for the preliminary design phase. DOE-STD-1189-2008 Page 28 Figure 3-3. Preliminary Design Phase DOE-STD-1189-2008 Page 29 The project technical design requirements for the preliminary design phase include initial technical requirements for the project and embody many of the deliverables indicated in DOE O 413.3A, Chg 1, for the preliminary design phase, including the design requirements document(s) containing the information available at this phase These technical requirements include those derived from the safety analysis. Because the design is still evolving at this point in the process, adequate Safety-in- Design for the preliminary design phase is based primarily on identifying viable engineering resolutions to nuclear safety design requirements and specifying an adequate set of more detailed safety design requirements that are based on safety analyses. During this phase a more complete assessment of hazard controls, based on hazards analyses at the process level, is developed, including those intended for in- facility worker protection. Section 4.3 of this Standard provides an expanded discussion of hazards analysis, hazard control selection, and safety classification of these controls. The security Vulnerability Assessment should be updated based upon the developing design of the facility proposed security features. During this phase, security strategies may be refined, security system performance requirements are defined, and other infrastructure requirements are identified. Physical, information, personnel, and cyber security are all considered in the analysis. The approach for demonstrating how the preliminary design will satisfy the nuclear safety design criteria of DOE O 420.1B or proposed alternative criteria must be developed during this phase if it was not done earlier. Because the design is still evolving at this point in the process, adequate Safety-in-Design for the preliminary design phase is based primarily on identifying viable engineering resolutions to nuclear safety design requirements and specifying an adequate set of more detailed safety design requirements that are based on safety analyses. Chapter 5 of this Standard provides guidance on the nuclear safety design criteria of DOE O 420.1B and Appendix I for documentation in the PSDR.

Section 28

The Safety-in-Design Risk and Opportunity Assessment developed in the conceptual design phase must be updated during the preliminary design phase to reflect the results of any technical studies, design modifications, or other developmental work that impact the risk assessment. The results must be documented in the Risk Management Plan to provide information for the development of the project baseline cost, as described in DOE O 413.3A and its guidance. Additional information regarding the aspects to be considered in the Safety-in-Design Risk and Opportunity Assessment is provided in Appendix F, “Safety-in-Design Relationship with the Risk Management Plan”. Any remaining studies that need to be performed to address specific details in the facility final design must be delineated in the preliminary design phase. These studies may include assumption validation studies, any remaining equipment selection studies (e.g., trade studies), and design optimization studies. Studies that could affect the safety design basis developed for the preliminary design should be highlighted in the safety strategy section of the PDR and in the PSDR. Corresponding risks associated DOE-STD-1189-2008 Page 30 with possible outcomes of the studies identified are included in the updated Risk and Opportunity Assessment. Safety-in-Design documentation also evolves during the preliminary design phase as follows: • PHA is revised and updated to an HA (see Chapter 4 and Appendix G); • FHA is updated; • The security Vulnerability Assessment is updated; • PDSR is developed, building on the information in the CSDR (see Chapter 6); • SDS is updated to reflect the evolution in the design and safety design bases (see Chapter 2 and Appendix E; • Safety-in-design Risk and Opportunity Assessment is updated and should reflect changes that were made to take advantage of opportunities or address identified risks (see Appendix F); and • By the end of design, the final National Environmental Policy Act (NEPA) documentation is completed to support the selected site. 3.4 Final Design Phase During this phase, details for procurement in support of construction activities are developed. Typically, about 30 to 40 percent of the design activity is completed during the preliminary design phase, and the remainder of the design is completed during the final design phase. By the final design phase, both the preliminary design and the PSDR will have been reviewed and approved. These reviews may prompt changes to the conclusions and approaches taken for safety and design in the preliminary phase. Similarly, evolution of the design from preliminary to final may prompt the design approaches and commitments captured in the PSDR to be revised based on improved knowledge and process optimization. The security Vulnerability Assessment should be updated based upon the final design of the facility proposed security features. During this phase, security strategies, security system performance requirements, and other infrastructure requirements are finalized. During this phase a final set of hazard controls is developed, based on hazards and accident analysis of the final design. The safety analyses in the final design phase, including mitigated analyses, must encompass the scope of the design and demonstrate that the designated safety SSCs are adequately designed to reliably perform their intended safety functions. Appendix G provides guidance on documenting the hazard analysis results.

Section 29

The design adequacy of safety SSCs must be demonstrated. This is fundamental to the integration of Safety-in-Design activities. The burden of proof is on the design DOE-STD-1189-2008 Page 31 organization to demonstrate that the design and functional requirements derived from the safety analysis process are satisfied. The designed SSC should be evaluated to validate they can provide the desired safety function from the safety analysis, that they can be implemented, and are cost effective. Section 4.4 of this Standard provides an expanded discussion of hazards analysis, hazard control selection, and safety classification of these controls. The PDSA addresses the broad range of issues necessary to demonstrate compliance with DOE O 420.1B and its guides; specifically, DOE G 420.1-1, -2, and -3, where applicable. Many of the design criteria are qualitative in nature and require an analysis to show how they are applied to a particular SSC. System and component design must satisfy national codes and standards (code[s] of record where applicable) identified in DOE G 420.1-1. Compliance with the requirements of these standards will be reviewed during acceptance of the safety documentation and during readiness activities in support of the CD-4 milestone. Appendix I discusses how the PDSA evolves from the PSDR. Both documents have the same format to simplify the evolution process. The Safety-in-Design Risk and Opportunity Assessment from the preliminary design phase must be updated to reflect the results of any technical studies, design modifications, or other developmental work that affects the risk assessment. The Risk Management Plan is updated as necessary. Design reviews at the final design phase should ensure that the safety analysis is current with respect to the design. The configuration management process at the final design stage should be well defined and able to track changes to the design and initiate conforming changes to analyses and documentation as changes are made. Section 6.4 of this Standard discusses expectations with respect to configuration management. In addition, Section 3.9 of DOE-STD-1073, Configuration Management, provides guidance on turnover of configuration management from design to construction. As stated, these efforts should be begun well before turnover to ensure a smooth transition. The following safety activities are typically performed during the final design phase: • update SDS as necessary; • update hazard and accident analysis; • update the security Vulnerability Assessment • update the design requirements document(s) • update Safety-in-Design Risk and Opportunity Assessment; and • prepare a PDSA. Figure 3-4 depicts the workflow for the Final Design Phase. DOE-STD-1189-2008 Page 32 Figure 3-4. Final Design Phase Pre- CD-3, Final Design CD-2 Approval Initiate Final Design Update Security Vulnerability Analysis Update Risk Management Plan Baseline Management CD-3 Final Design Package Validate Design vs. Desired Control Functions & Criteria 3.4 Develop Design Output Documents Design Reviews (Fed and/or Contractor, as appropriate) Update Hazards Analysis 4.4 Mitigated Accident Analysis 4.4 Update Safety SSC Functions and Classification 4.4 PDSA 4.4 Safety Evaluation Report DOE Authorizes Procurement, Construction, & Final Implementation Update Safety in Design Risk & Opportunities Assessment 3.4 Execution Readiness Independent Review Updated SDS, as needed

Section 30

2.3 Update Project Risk Considerations CD-3 Approval Construction, Transition, & Closeout 7.0 DOE-STD-1189-2008 Page 33 3.5 Construction, Transition, and Closeout 3.5.1 Introduction This section describes those safety-basis-related activities that are accomplished after the final design and Preliminary Documented Safety Analysis (PDSA) are approved and before approval to operate is granted. The primary project activities that can occur in this project interval include construction and transition to operations. The primary safety basis activities include preparing the Documented Safety Analysis (DSA) and Technical Safety Requirements (TSR), review and approval of these by DOE, implementation of the commitments in the DSA and TSR, and verification that those requirements are met before normal operations begin. If not previously approved, a facility Unreviewed Safety Question (USQ) procedure is also prepared and submitted for DOE approval. 3.5.2 Construction Construction of the project design requires close coordination and integration of the various physical, contractual, technical, financial, and organizational interfaces. Numerous changes to the “final” design can occur during construction, some of which may affect the assumptions, commitments, or results of the safety analysis. Therefore, rigorous configuration management of the design and the safety analysis documentation is important to understand whether a design change can affect the approval basis for the PDSA, and to maintain consistency between the as-built facility and the safety basis documentation (DSA and TSR). Section 6.4 provides guidance on managing changes that affect the PDSA. In some cases, pre-existing SSCs or “government furnished equipment” (GFE) are provided to the project for use in the facility, creating the potential for additional challenges. Section 8.3 contains guidance and recommendations on the use of GFE. 3.5.3 Development of Safety Basis Development of the DSA and the TSR (or revisions as appropriate for a major modification) begins in this phase. The DSA evolves from the PDSA with the addition of the final analysis of operational hazards and any upset conditions that were not considered previously. Safety Management Programs (SMPs) are detailed in this document, and elements of those programs that are needed in hazards analyses and other upset events are defined in the appropriate hazards analyses. Guidance for development of an operational TSR is contained in DOE G 423.1-1. DOE-STD-1189-2008 Page 34 The DSA for a new facility documents a design, and its associated safety design basis, that has been approved by DOE as part of the Conceptual Safety Design Report (CSDR), Preliminary Safety Design Report (PSDR), and PDSA approval process. The DSA also documents any changes that were necessary during the construction phase for future operational reference and review and for approval of annual updates. Additional analysis tasks that may be needed to prepare the DSA include evaluation of equipment that was not part of the preliminary and final design, such as government furnished equipment (GFE) or specialty equipment designs that were performed in separate design activities not fully addressed in the PDSA, and detailed operational analysis for those activities that did not need to be considered for development of the design. In addition, hazards analyses that were completed as part of the PDSA must be reviewed to ensure that they remain accurate and that changes are made as necessary. Note that, ideally, GFE should be included in the early hazard and accident analysis activities and should be treated in the hazard and accident analysis as though it were part of the design. Otherwise, the design interfaces (and potentially acceptability of the GFE) may not be found in a timely fashion. This additional task would be a final check on interfacing facilities or systems that are not under the direct control of the project.

Section 31

To complete the operational hazards analyses and analyze other upset conditions that were not developed in the PDSA, the hazards analysis process should engage the operations staff. Detailed operational concepts should be developed by the operations staff in conjunction with the safety analysis efforts and should include GFE that may be used in these operations. The DSA cannot be completed until there is a high degree of certainty that facility configuration matches the design documentation, safety design basis documentation, and the operating procedures for that configuration. Final verification that the DSA information is consistent with the as-built configuration is necessary before sending the DSA and TSR to DOE for approval. A rigorous configuration management program (including change control) will help in this regard. The final development of the DSA and TSR should provide for implementation planning. The initial planning for these activities should be included in the Transition Plan, which should be baselined during final design. The Transition Plan provides the concepts that support when and how many operations staff are brought into the project to support transition and defines (to the extent known at the time) the activities that need to be performed, including those needed to implement the commitments expected to be in the DSA and TSR. Many of the details of activities needed to implement the DSA and TSR are based on limited information available in the preliminary design. Consequently, the detailed strategy and activities needed to implement the DSA and TSR need to be addressed and compared to the baseline in the Transition Plan such that appropriate adjustments can be made. DOE-STD-1189-2008 Page 35 Additional adjustments may be required based on the DOE Safety Evaluation Report (SER) for the facility operational safety basis and other transition activities. 3.5.4 Checkout/Acceptance, Testing and Commissioning The final stages of the project process involve acceptance and turnover of the SSCs from the construction effort to the operating organization. Acceptance is generally predicated on appropriate checkout/acceptance, testing, and commissioning. Planning for these activities should occur at early stages of the project and be coordinated with the operating organization to facilitate an efficient, timely turnover to ensure functionality of the safety SSCs. Testing serves to verify that the components, systems, and facilities meet or exceed design requirements and performance parameters and helps to train operating personnel in the operation of the equipment, systems, and other components of the completed project. Key activities include the preparation and approval of test procedures, and the organization of test teams. Procedures are prepared by personnel who are or will be part of the test teams. Staff from the operator organization is also part of the test teams. The project organization works closely with the user in developing and presenting specific process and facility related training, and continues to provide support to the operations and maintenance staff throughout transition and turnover. Early turnover and transition activities include facility walkdowns to identify and correct physical, process, safety, quality, or environmental deficiencies; and planning, preparation, performance, and documentation of equipment and systems testing and operation. Checkout and test planning and preparation typically begin at the equipment (item) level, progress to the system level, and culminate at the facility level. Test planning begins during design to ensure that the physical features needed to support testing are provided.

Section 32

3.5.5 Readiness Reviews Readiness reviews are performed to ensure that contractor programs, equipment, and personnel are ready to safely start up and operate the facility. DOE Order 425.1C, Startup and Restart of DOE Nuclear Facilities, defines the requirements for conducting either an Operational Readiness Review (ORR) or a Readiness Assessment (RA) for nuclear facilities. Readiness reviews may also be performed for non-nuclear facilities at the discretion of DOE. 3.5.6 Project Closeout When construction, testing, and turnover are complete and the operational capability has been attained, the project is ready for Critical Decision-4, DOE-STD-1189-2008 Page 36 Approve Start of Operations or Project Closeout. A key part of obtaining Critical Decision-4 is the delivery of appropriate project related documentation to support the initiation of operations. The key discriminator in the turnover is the operational organization’s readiness for assuming operational responsibility and the government acceptance of the asset. DOE-STD-1189-2008 Page 37 4.0 HAZARD AND ACCIDENT ANALYSES This chapter provides guidance on hazards and accident analyses as the design process progresses from scoping analyses in pre-conceptual design to the PHA and DBAs in conceptual design, system and process-level hazards analyses in preliminary and final design and the related identification of needed safety functions, and the selection and classification of safety structures, systems, and components (SSC). 4.1 Pre-conceptual Planning Phase A scoping analysis of potential hazards should be performed during the pre- conceptual planning phase to plan for the conceptual design phase. The scoping analysis is important for the development of DOE expectations for Safety-in-Design. There may be a wide range of maturity with respect to the definition of potential projects. In some cases, information available or developed may have target cost ranges identified and scope defined. In other cases, only rudimentary information on project plans and mission may be available. Knowledge of hazards will be dependent on maturity of the potential project. Scoping hazard analysis during pre-conceptual planning involves a qualitative assessment of the facility/process risks in conjunction with any facility and initial technology selection alternative reviews performed. During and after the facility and technology selection process, project technical staff, in conjunction with nuclear safety project personnel, should evaluate the need for safety functions and associated hazard controls that may be required given the nature of the hazards. The initial determination of hazard controls that may be required is based on the qualitative assessment of the facility hazards and a preliminary determination of the approach to be taken to satisfy the defense-in-depth requirements of DOE O 420.1B. At this phase, only the major hazard controls that will have a significant influence on the facility design and cost need to be identified. The results of the initial hazards assessment, including a discussion of the overall major Safety-in-Design strategies and DOE safety expectations, are documented in support of the Mission Need Statement, commensurate with the level of detail available during pre-conceptual planning.

Section 33

4.2 Conceptual Design Phase A formal, disciplined evaluation of the potential facility hazards must be performed during the conceptual design phase. The design information available at this phase will be limited and may involve several design alternatives, but this effort is needed to perform a preliminary identification of the required safety functions, as well as to identify a preliminary set of Safety SSCs. The hazards analyses performed in this DOE-STD-1189-2008 Page 38 phase include a PHA and identification of events warranting designation as design basis accident analyses (DBA). Early identification of safety SSCs (particularly those that could have high cost or schedule impacts) is a major contributor to developing an accurate estimate of facility and project costs. The hazards analyses establish the foundation for identifying the safety SSCs. At the conceptual design stage, this is achieved through hazards identification, hazards evaluation, and identification of major safety functions necessary to provide adequate protection, primarily for accident conditions. Safety SSCs are then chosen that will satisfy those safety functions for the preferred alternative. Identifying and classifying the safety SSCs (safety class and safety significant SSCs) is a fundamental part of the Safety-in-Design process. Safety-in-design considerations for safety SSCs and defense-in-depth or important to safety SSCs (SSCs that perform a safety function but are not classified as Safety Class or Safety Significant, see DOE G 421.1-2 section 5.3., Hierarchy and Selection of Control Items) should be communicated to the design staff in a timely fashion. Similarly, the Integrated Project Team (IPT) and Safety Design Integration Team (SDIT) need to be cognizant of the design concept as it evolves to ensure that safety considerations are factored into each design decision. Control strategies for DBAs must also be clearly identified in the hazards analysis, including the following: • required safety functions and classifications; • SSCs required to perform these functions; and • natural phenomena hazard (NPH) performance categories (non seismic NPH) and seismic design bases for major SSCs. Because preliminary cost and schedule baseline ranges being developed are strongly influenced by the selection of the hazard controls (and by NPH design requirements), the hazards analysis process used to arrive at these controls needs to be thorough and based on sound safety principles. To ensure that the baseline range estimates are conservative, the hazards analysis process and the criteria for selection of safety SSCs must also be conservative. After the preliminary process flow diagrams are prepared, the facility design should further evolve before the formal hazards analysis documentation in the PHA is completed. Ideally, the project decisions and design documentation that should be drafted during the conceptual design phase and that are necessary for the formal hazards analyses during the conceptual design phase are as follows: • facility site/location selection; • general arrangement drawings; • MAR estimates or assumptions and material flow balances; • sizing of major process system containers, tanks, piping, and similar items; DOE-STD-1189-2008 Page 39 • process block flow diagrams or equivalent documentation of the required major process flow steps and their sequence;

Section 34

• preliminary one-line diagrams for ventilation, electrical power and distribution, special mechanical handling, and instrumentation and control system architecture; • summary process design description and sequence of major operation; and • confinement strategy. Making the decision on the facility location will simplify the analysis process; however, the hazards analysis might also be a factor in site selection. If the site has not been selected around the time of inception of conceptual design, the analyst should either use bounding conditions or worst-case assumptions or perform a parametric comparison of the hazards involved at each potential facility site location. Such analyses increase the uncertainties in the Risk and Opportunities Assessment. The hazardous material release events must be evaluated more formally in a PHA and facility-level DBAs for the selected alternative design. Development of the PHA during the conceptual design phase is an iterative process, and the PHA should evolve to include consideration of more refined design details as they become available. A strong PHA developed during this phase is the foundation for an effective Safety-in- Design approach for the project. The PHA must be based on the following: • project decisions and documentation described in this section; • material-at-risk (MAR) quantities; and • key project assumptions and strategies identified in the project SDS. During the conceptual design phase, an objective of hazards analyses is to identify high-cost safety functions and design requirements (including those for NPH protection) for the SSCs that will be included in the project. Examples include the following: • building structure; • building and process confinement; • power systems, including those associated with single failure criteria for safety class SSCs; • fire protection provisions; and • special mechanical equipment (e.g., gloveboxes). The PHA must establish a suite of facility DBAs to define f functional and performance requirements for the facility design. This is facilitated by grouping the hazardous release events according to the nature of the postulated initiating events. One such grouping is shown below. DOE-STD-1189-2008 Page 40 • Internally Initiated Events - Fire – Consequences are typically due to inhalation or ingestion of released hazardous material. - Explosion – Consequences are typically due to inhalation or ingestion of released hazardous material. - Loss of Containment/Confinement – Consequences are typically due to inhalation or ingestion of released hazardous material. - Process Upsets – Consequences are typically due to inhalation or ingestion of released hazardous material. - Inadvertent Nuclear Criticality – Consequences are typically due to direct external exposure from the event with potential for additional direct exposure from, or inhalation of, fission products. • Externally Initiated Events – Consequences are typically due to inhalation or ingestion of released hazardous material. Depending on the specific event, direct exposure may also be applicable. • Natural Phenomena Hazards Initiated Events – Consequences are typically due to inhalation or ingestion of released hazardous material. Depending on the specific event, direct exposure may also be applicable.

Section 35

The categories of hazardous release events identified in these groupings essentially form the foundation for the facility level DBAs. The DBAs considered in the hazard analysis represent the range of potential accidents for the facility processes, and the results of that analysis must be used to identify the controls needed to protect against these accidents, considering both the public and collocated workers. All accident conditions (energy sources, intermediate process hazards, and similar conditions) must be considered. The DBA analysis must ultimately address applicable accident environmental conditions for which the safety SSCs need to be designed to withstand and perform their safety function. These design basis conditions, together with the bounding consequences of an unmitigated release, provide the basis for selecting safety class and safety significant SSCs and their functional and performance requirements. (See Appendix A, “Safety System Design Criteria,” and Appendix B, “Chemical Hazard Evaluation.”) Once the safety SSC functions are identified in the PHA (including the set of DBAs), the design team translates them into conceptual designs (e.g., drawings and initial system design descriptions). These conceptual designs are then the basis for cost estimates for the project. In the conceptual design phase, the hazardous release event evaluations are based on facility-level events and are not a complete listing of all events possible in the facility. At the conceptual design stage, facility-level DBA are characterized by locations and quantities of MAR and gross descriptions of events that could result in a release of MAR (fires, explosions, spills, NPH events). The purpose of these facility-level DOE-STD-1189-2008 Page 41 DBA, at this stage is primarily to classify safety functions, Performance Categories, and Seismic Design Categories for safety features that could provide those functions. The events evaluated should be chosen by the SDIT to ensure that the hazards considered and the safety features selected provide a reasonably conservative perspective of the high-risk/high-cost design requirements for the project. It is critical that the full SDIT be involved in the development of the PHA to ensure complete consideration of accidents and events, as well as design features to prevent or mitigate releases, to the degree practicable at this phase. (See Chapter 2, “Project Integration and Planning,” for additional details on team involvement expectations.) Due to the critical nature of the PHA process in defining the MAR release events and associated safety systems, it is important that certain key information is developed and described for each event postulated for use by the project team. Appendix G, “Hazard Analysis Table Development,” provides detailed guidance on what should be discussed for each MAR release event postulated by the IPT. Although many process details will not be available to perform a PHA during the conceptual design phase high-level events, such as fires, explosions, deflagrations, and NPH events, should be evaluated commensurate with the available process definition of MAR locations. From these evaluations, reasonably conservative prevention and mitigation strategies, along with the appropriate functional classifications and safety functional requirements, should be developed.

Section 36

For those events with consequences that do not lead to selection of safety class or safety significant controls, the analysis should also identify the controls that are appropriate for collocated worker and public defense-in-depth protection. Hazard controls other than safety class or safety significant are identified in the conceptual design phase to the extent necessary to identify cost-dominant SSCs. These controls may be included to meet requirements defined by safety management programs and other administrative programs. Appendix A of this Standard provides criteria for classification of SSCs for radiological hazards. Additionally, prevention/mitigation strategies must be identified for chemical hazards. Guidance for chemical hazards is provided in Appendix B of this Standard. Information from the PHA, as well as any uncertainties related to necessary hazard controls, is considered in the Risk and Opportunity Assessment so that appropriate cost contingencies and mitigation strategies for the items can be presented in the final Conceptual Design Report (CDR) and in the Conceptual Safety Design Report (CSDR). A project design review occurs during the conceptual design phase. The results of the PHA are included in the conceptual design and must be included in this review. For example, before selecting alternatives, the PHA should identify top-level safety requirements, provide a basis for the classification (unmitigated consequence analysis to help define whether safety class SSCs are needed), and identify uncertainties such as those associated with multiple sites. DOE-STD-1189-2008 Page 42 The events postulated and the safety strategies selected in the PHA provide the foundation for the development of the CSDR. The PHA also provides the foundation for performing the HA for future design phases of the project. 4.3 Preliminary Design Phase Hazard analysis effort during the preliminary design phase includes the following: • updating the facility hazard categorization (if needed); • updating the analysis of the DBAs analyzed in conceptual design to confirm the selection of facility-level hazard controls and their functional classifications; • developing a system-level HA and selecting and classifying hazard controls for the in-facility worker; and • considering beyond-DBA events. The objective for hazard analyses during the preliminary design phase is to confirm and add detail to the conceptual design stage analyses, including developing functional requirements and performance criteria for safety SSCs for in-facility worker hazards and identifying Specific Administrative Controls (SAC) (See DOE- STD-1186-2004). SACs should only be selected if engineered controls cannot be identified or are not practical. The hazard analysis performed during the preliminary design phase is the system-level HA. Prerequisites for the HA include developing or updating the information from the PHA during conceptual design, including the following: • facility general layout drawings; • Process and Instrumentation Diagrams (P&IDs); • updated process flow sheets; • electrical one-line diagrams; and • updated listing and locations of material at risk. The HA must: • address the spectrum of accidents that may impact design and which may be initiated by facility operations, natural phenomena, and external man-induced events; • evaluate potential accident consequences to the public and workers; and

Section 37

• identify and assess associated preventive and mitigative features, including classification (i.e., safety class, safety significant, and SACs based on the significance of possible consequences). DOE-STD-1189-2008 Page 43 The results of the HA provide an appropriate comprehensive evaluation of the complete facility hazardous event scenarios and accident spectra necessary to define the design. Guidelines for Hazard Evaluation Procedures, Second Edition with Worked Examples provides examples of some of the techniques that can be used to produce a well-reasoned and clear assessment of facility hazards and their associated controls. The HA considers the complete accident spectrum. However, at this design stage the HA only provides a preliminary definition of accident sequences and assumptions. The results of the HA are documented using the format and content guidance in Appendix G “Hazards Analysis Table Development”. A graded approach should be used for the HA based on the magnitude and complexity of the hazards of the facility. The graded approach should also be used to select techniques for hazard analysis. The technique selected will be sufficiently sophisticated or detailed to provide an appropriately comprehensive examination of the hazards associated with the facility given the complexity of the operation and degree of design maturity. Guidelines for Hazard Evaluation Procedures, Second Edition with Worked Examples contains guidance on some of the techniques that may be appropriate for HAs specific to the application and process. On the basis of the HA and the updated DBA analyses, a suite of SSCs must be selected and classified as safety class, safety significant, defense in depth or important to safety SSCs for the protection of in-facility workers, collocated workers, and the public. The DBA analysis also provides accident environmental conditions that safety SSCs need to be designed to withstand and continue to perform their safety function. Accident analyses are inherently graded in terms of the degree of physical modeling and engineering analysis needed to quantify accident consequences. The analysis to determine accident environmental conditions is generally included as part of the design process and may be documented as calculations separate from the safety documentation. Design details for safety SSCs must be developed that incorporate design requirements derived from the HA, the updated DBA analysis, and DOE O 420.1B. The hazard analysis must also indicate whether a facility contains significant chemical hazard(s) that necessitate DBA analysis for consideration of SSCs for safety significant classification (see Appendix B). The safety basis provisions of 10 CFR 830 require considering the need for analysis of accidents that may be beyond the design basis of the facility to provide a perspective of the residual risk associated with the operation of the facility. It is prudent to examine beyond DBAs at the preliminary design phase to provide insight into the possibility of additional facility features that could prevent or reduce severe beyond DBA consequences. They also serve as the bases for cost-benefit considerations for additional safety design provisions related to these postulated accidents. No lower limit of frequency for examination is provided for beyond DBAs. However, as frequencies become very low, little or no meaningful insight is attained. Beyond DBAs are not expected to be analyzed to the same level of detail as DBAs, and are not evaluated for man-made external events.

Section 38

DOE-STD-1189-2008 Page 44 4.4 Final Design During this phase, the DBAs are revised to reflect any changes that are design dependent (such as a change in the planned location of a structure resulting in different potential impacts from collocated facilities). In addition, during this phase analyses that support final classification of safety significant SSCs and demonstrate the adequacy of the control suite (engineered features with necessary SACs) are finalized. The major new safety analysis activity in this phase is completion of the safety analysis. The completed safety analysis demonstrates the adequacy of the design from the safety prospective. As with the design, it is not necessary to show the progression of the design that led to the final choices, only the final choices, and the justification for their adequacy. The Preliminary Documented Safety Analysis (PDSA) guidance in Appendix I discusses how this information is applied to support the completion and documentation of the safety analysis. At the final design phase, the safety analyses must encompass the scope of the design and demonstrate that the designated safety SSCs are adequately designed to reliably perform their intended safety functions. For system and component design, adherence to national codes and standards, in accordance with DOE G 420.1-1, -2, and -3 must be used to demonstrate that the design criteria have been met. Many of the design criteria are qualitative in nature and require an analysis to show how they are applied to a particular SSC. Demonstrating compliance with the requirements of these standards will be an important review consideration during acceptance of the safety documentation and during readiness activities in support of the CD-4 milestone. If the requirements of applicable standards were tailored, a justification that demonstrates the adequacy of the final design with the tailored requirements must be documented. A System Design Description may be used to capture and maintain such information.5 As the design progresses, design reviews should be used to validate the selection of criteria, application of codes and standards, deviations, and design output. To provide a baseline understanding of the adequacy of controls, the accident analysis in the PDSA must describe how the selected controls adequately prevent and mitigate the accidents, including how the controls provide defense-in-depth. The discussion puts the effectiveness of hazard controls into accident context and provides the baseline safety analysis for the evaluation of changes, for example, under the Unreviewed Safety Question (USQ) process, for the operational period. The development of safety design analysis information is important to the design progression. In many instances, the results will define design requirements for the procurement of safety materials or components. These design requirements represent 5 See DOE STD 3024-98, Content of System Design Descriptions. DOE-STD-1189-2008 Page 45 important quality assurance attributes that must be objectively demonstrated and should be tied to the procurement specifications. For example, a process control system may be selected as a safety system during the safety-design evolution. Once selected, the control system must be demonstrated to be capable of performing its safety function under all postulated process upsets or accidents as credited in the accident analysis.

Section 39

Example A process control system may be selected as a safety system during the safety-design evolution. Once selected, the control system must be demonstrated to be capable of performing its safety function under all postulated process upsets or accidents as credited in the accident analysis. Specifically, the design of a control system based on pressure instrumentation for some specified system transient must factor instrument uncertainty into the system response. If the system must operate following a postulated pipe break in its physical area, the instrumentation must be shown to be able to withstand the pipe break consequences, typically by qualification testing. Calculations are required to define the conditions for such testing. If the control system is deemed safety class and required to satisfy single failure criteria, Failure Modes and Effects Analyses (FMEA) or fault trees may be needed to ensure active single failures do not affect system function under postulated system faults. If the control system is required to function during and/or following a seismic event, not only must the system and its active components be demonstrated capable of withstanding the acceleration forces, but any SSCs not part of the system must be evaluated to ensure their failure cannot endanger the control system (target-source interaction analysis). In this case, instrument uncertainty, environmental qualification parameters, single failure, and seismic target-source interaction, must be considered in the selection of the actual components for installation, and these requirements must be translated to the procurement specifications. Typically, the final design concepts necessary to develop the PDSA are completed before the final design phase, but changes may arise during final design that result in the need to revise the PDSA. It should be recognized that the commitments and descriptions in the PDSA may change and adequate change controls will need to be established to accommodate this possibility. Not all design issues related to safety may be resolved by the final design phase. Consequently, it may be necessary to identify where these issues remain open and describe the safety implications associated with them. This is particularly applicable for equipment, such as government furnished equipment (GFE) that will be procured by others in a later phase of the project. This ultimately translates to a project risk issue as well as a safety issue. These risks must be documented in the Risk and Opportunity Assessment. DOE-STD-1189-2008 Page 46 5.0 NUCLEAR SAFETY DESIGN CRITERIA As discussed in Chapter 4, the results of the Preliminary Hazard Assessment (PHA), the Design Basis Accident (DBA) Analysis and the identification of Safety structures, systems, and components (SSC) must be considered in the design process. After the appropriate facility location and processing alternatives have been selected, other safety design requirements and considerations must be specifically addressed during design development. These requirements and considerations are in DOE O 4201.1B in the following chapters: • Nuclear and Explosives Safety Design Criteria (Chapter 1); • Fire Protection (Chapter 2); • Nuclear Criticality Safety (Chapter 3); and • Natural Phenomena Hazards Mitigation (Chapter 4) In addition, specific criteria or guidance for implementing these requirements are contained in the following:

Section 40

• DOE G 420.1-1, Nonreactor Nuclear Safety Design Criteria and Explosive Safety Criteria Guide for use with DOE O 420.1 Facility Safety; • DOE G 420.1-3, Fire Protection and Emergency Services Program; • DOE-STD-3007-2007, Guidelines for Preparing Criticality Safety Evaluations at Department of Energy Nonreactor Nuclear Facilities; and • DOE G 420.1-2, Guide for the Mitigation of Natural Phenomena Hazards for DOE Nuclear Facilities and Nonnuclear Facilities. Alternative safety design criteria may be proposed by the design contractor, as described in 10 CFR 830.206, but the alternative criteria must be approved by DOE. The SDIT (or its functional equivalent) should review DOE O 420.1B, as well as its implementation guides and their referenced Standards, and should compile a listing of the applicable safety design requirements and associated guidance relative to each of the safety topics addressed in the above-listed chapters of the Order. These safety design requirements and criteria must be placed under design control with an expectation to demonstrate implementation at project end. As the design evolves, requirements will become more specific. The intent of engineering design control is to ensure safety design requirements and criteria are controlled throughout the design process and changed only with appropriate review, approval, and flow down of the change into the design and documentation. Control of safety requirements is a fundamental responsibility of the SDIT. Where no SDIT is formed, control of these requirements is the responsibility of the project safety lead. The project change control process must provide for concurrence by the Federal Project Director for changes to criteria invoked in the SDS. Derived requirements which implement these criteria are controlled wholly within the design control process. The Conceptual Safety Design Report (CSDR), the Preliminary Safety Design Report (PSDR), the Preliminary Documented Safety Analysis (PDSA), and the Documented Safety DOE-STD-1189-2008 Page 47 Analysis (DSA) must address, to the appropriate degree of design maturity, each of the safety design requirements and considerations in DOE O 420.1B (unless an alternate set of requirements has been approved by DOE) and identify the extent to which the design incorporates them. Where the design does not fully satisfy one of these requirements, the rationale must be provided. Specific SSCs will have been identified in the conceptual design phase along with applicable DOE O 420.1B criteria. As design evolves, specific design codes and standards to be used for the design of the safety SSCs will typically be identified during Preliminary Design. Guidance for mapping between the safety functions and the selected safety SSCs and applicable design codes and standards is provided in the guidance documents listed above for DOE O 420.1B. The linkage between safety requirements and the design codes and standards should be provided at a high level in the safety documentation (see H.2 6. and I.2 Appendix B). If the codes and standards chosen for the safety functions and safety SSCs differ from those identified in the DOE requirements cited in this section, the rationale for the selection of alternate codes and standards must be provided. The PSDR is generally the first place where a linkage to the specifics of the alternative selection and rationale in a document such as the Design Criteria Document is provided. The PSDR should summarize and reference the document that contains this information.

Section 41

Demonstrating compliance with the requirements in DOE O 420.1B generally involves a design analysis or series of analyses. For example, some safety SSCs are required to be designed to withstand common cause effects and adverse interactions from natural phenomena hazard (NPH) events. The design analyses must demonstrate that those safety SSCs that are required to function before, during, or after the NPH event will continue to do so. This may entail evaluation of a number of nearby or overhead SSCs that perform no direct safety function. Design documentation to demonstrate this requirement for “source SSCs” may involve design criteria for the facility or system and calculations demonstrating acceptable seismic design. Each applicable analysis for a project should be considered as important technical basis information that is to be maintained in support of the safety basis for the life of the facility. During design, material in Type B containers with current certificates of compliance may be excluded from the inventory for final hazard categorization, when safety analyses demonstrate that containers can withstand all accident conditions. DOE-STD-1189-2008 Page 48 6.0 SAFETY REPORTS 6.1 Safety Input to the Conceptual Design Report DOE O 413.3A, Chg 1, requires developing a Conceptual Design Report (CDR) during the conceptual design phase. The CDR is intended to provide the Approval Authority with integrated information sufficient to understand the overall project scope and cost, the risk and opportunities, and the cost range for the selected conceptual design. The CDR for the selected conceptual design must incorporate an effective Safety-in-Design approach to address potential material-at-risk (MAR) release events. DOE O 413.3A, Chg 1, and its guidance establish the minimum content for the CDR, which summarizes the project requirements and the proposed design solution. The CDR is a necessary element in decision-making because it documents the following: • project design requirements; • alternatives evaluated and selected for facility and the process configurations; • design architecture (major structures, systems and components [SSCs]) selected to satisfy the design requirements, consistent with the selected alternatives; and • safety design basis for the proposed facility. Both the CDR and the Conceptual Safety Design Report (CSDR) provide the following: • risk-informed decision making information for the DOE approval authorities; and • equipment safety classifications and design requirements, as well as a corresponding cost range that reflects the Safety-in-Design decisions made during the conceptual design phase. The CDR provides an integrated discussion of the key results of the hazards analysis including the following: • facility hazard category determination; • selected safety functions and controls; • SSC functional classifications, performance categories, and seismic design criteria for natural phenomena hazard (NPH) protection; • design criteria for the safety SSCs; and • approach to be taken to further develop and document the safety basis through the remaining project phases. DOE-STD-1189-2008 Page 49 In addition, the SDS must also describe any uncertainties with respect to the safety design basis assumptions and selected hazard controls, and explain how the risks associated with these uncertainties will be managed. 6.2 Conceptual Safety Design Report

Section 42

DOE O 413.3A, Chg 1, requires a CSDR as a part of the approval package for CD-1. The purpose of the CSDR is to summarize the hazards analysis efforts and Safety-in- Design decisions incorporated into the conceptual design along with any identified project risks associated with the selected strategies. Appendix H provides specific guidance for preparing the CSDR. DOE must review the CSDR and document the review in a Safety Validation Report to confirm that the preliminary safety positions adopted during conceptual design constitute an appropriately conservative basis to proceed to preliminary design. These positions include the following: • selection of the preliminary hazard categorization (HC-1, 2, or 3) of the facility; • preliminary identification of facility Design Basis Accidents (DBA); • assessment (based on the analyses of DBAs) of the need for safety class and safety significant facility-level hazards controls; • preliminary assessment of the appropriate seismic design criteria for the facility; and • position(s) taken with respect to compliance with the safety design criteria of DOE O 420.1B or any alternate criteria proposed. 6.3 Preliminary Safety Design Report (and PDSA) The key Safety-in-Design documents developed during the preliminary design phase are the Hazards Analysis (HA) and the Preliminary Safety Design Report (PSDR). The format and content of the PSDR are designed to be built upon to produce the Preliminary Documented Safety Analysis (PDSA) during the final design phase. The format and content guidance for the PDSR are provided in Appendix I of this Standard. The PSDR addresses the following Safety-in-Design aspects for the Preliminary Design Phase: • site information of the type that can affect Safety-in-Design (e.g., location of nearby facilities and external hazards, meteorological information for dispersion analyses, seismic and other natural phenomena information); • facility and process descriptions, including facility structure types and layout, process description and flow sheet, and summary system descriptions for safety SSCs, consistent with the level of design; DOE-STD-1189-2008 Page 50 • summary of the HA, including process hazards evaluation, selected DBAs; FHA, selected safety SSCs and their safety function; functional classification; and required seismic and other natural phenomena design criteria, including their bases; • for safety class and safety significant SSCs and Specific Administrative Controls (SAC), the functional requirements and performance criteria (including applicable design requirements from DOE G 420.1-1 and DOE G 420.1-2); • information regarding aspects of the preliminary design that are required to support the prevention of inadvertent criticality; • roadmap of project documentation addressing design aspects related to the effective implementation of safety management programs; and • documentation of how the safety design criteria of DOE O 420.1B are met, including any exceptions or alternate approaches, which may include analyses performed to meet the safety analysis expectations. Based on the design maturity in preliminary design, the PSDR will demonstrate the adequacy of the hazards analyses and the selection and classification of the hazard controls, including consideration of the application of the principles associated with the hierarchy of controls. If the commitments made in the PSDR and design documents are met, the result should be a final design and a constructed facility that could be approved for operation without major modifications. The PDSA at the final design stage is an evolution of the PSDR.

Section 43

6.4 Change Control for Safety Reports as Affected by Safety-in- Design Activities A clearly defined project configuration should be established at the conclusion of each phase of the design. DOE-STD-1073-2003, Configuration Management, states: “The objective of change control is to maintain consistency among design requirements, the physical configuration, and the related facility documentation, even as changes are made.” At the conceptual design stage, change control should be implemented within the design organization to maintain consistency among the various concepts and their supporting documentation. The CSDR issued at the completion of the conceptual design must reflect the project configuration as described in the conceptual design. Critical relationships between safety and the concept that progresses to the final design are established in the CSDR. As the conceptual design evolves to the preliminary design, it is documented in a PSDR. The PSDR must specifically identify any changes to Safety-in-Design decisions and commitments that were described in the CSDR and must provide explanations for the changes. Similar identification of changes and explanations must be provided between the PSDR and the PDSA. DOE-STD-1189-2008 Page 51 As the preliminary design progresses to the final design, the PSDR evolves into the PDSA with its attendant supporting safety analyses, which have been formalized relative to earlier evaluations. The approved PDSA constitutes the basis upon which DOE agrees that procurement and construction may begin. PDSA configuration baseline documents should be identified within the project baseline. The PDSA configuration baseline is the basis for determining if PDSA revision is needed, and formally establishing and maintaining the PDSA configuration baseline provides the means to ensure that the Department can continue to rely on the information in the PDSA. Not every change in the PDSA configuration baseline will necessitate a PDSA revision. The following criteria are suggested to determine whether a PDSA revision is needed because of post-PDSA approval design changes. • The change alters a safety function for a safety SSC identified in the current PDSA. • The change results in a change in the functional classification, reliability, or rigor of the design standard for an SSC previously specified in the PDSA configuration baseline. • The change requires implementation of new or changed safety SSC or proposed Technical Safety Requirement (TSR) controls. • The change significantly alters the process design or its bases, such as increased material at risk, changes to seismic spectra, major changes to process control software logic, new tanks, new piping, new pumps, or different process chemistry. DOE-STD-1189-2008 Page 52 7.0 SAFETY PROGRAM AND OTHER IMPORTANT PROJECT INTERFACES There are multiple interfaces with required programs and project evolution steps that link with the Safety-in-Design process. The intent of this chapter is to highlight the links where these areas, particularly Safety Management Programs (SMP), which are required to be addressed in sections 6 through 17 of the Documented Safety Analysis (DSA), directly interface with the design process; specifically, where they link to the development of safety design bases. This chapter is not intended to provide comprehensive explanations because the subject matter is addressed in detail in other DOE documentation. Table 7-1 shows the typical activities associated with these SMPs for each project phase.

Section 44

For new facilities that will be built at existing DOE sites where SMPs have been established, much of the interface with the DSA will be similar to that for existing facilities. Exceptions may occur where new classes of hazards are introduced. For new sites, the development of SMPs should be a focus of management attention early in the project life cycle, and these programs should mature as the facility heads toward operational capability. Most of the sections in this chapter involve aspects important to design, and consideration of them should be integrated into the design effort as early as it is practical to do so. Among these are emergency preparedness, radiological protection, nuclear criticality safety, fire protection, human factors, and security. Further discussion on this integration is provided in the following sections, and Table 8-1 shows actions relating to them as a function of design stage. 7.1 Quality Assurance The quality assurance (QA) requirements of 10 CFR 830 and DOE O 414.1C apply to DOE nuclear facilities and activities. The scope of the QA rule is defined in 10 CFR 830.120 as follows: This subpart [Subpart A of 10 CFR 830] establishes quality assurance requirements for contractors conducting activities, including providing items or services, that affect, or may affect, nuclear safety of DOE nuclear facilities. This wording was specifically chosen to include activities in the design and construction phases before completion of the facility and introduction of nuclear material. That is because the quality of the design and construction is integral to the safe operation of the facility. Furthermore the inclusion of a robust QA program in the design and construction phases can greatly strengthen the ability to achieve the goals of Safety-in-Design, namely to identify and correct problems early in the design and construction phases when it is more cost-effective to make corrections. With respect to the activities defined in this Standard, QA should be viewed as an important tool. The successful completion of many nuclear facilities has occurred simply because of the quick DOE-STD-1189-2008 Page 53 response to QA findings during design and construction. In particular, the following QA activities can help keep the design process on track. • Establishing and using formal work processes such as design reviews, document control, verification processes, and configuration management. • Training of design and review staff on applicable standards, requirements, and work processes. • Performing periodic assessments of the documentation, including drawing reviews, to ensure that the drawings, design calculations, and other documents are in agreement. Key design and construction personnel should be involved in these reviews. • Performing independent design verifications, validations, assessments and design outputs by qualified persons to keep design and analysis errors to a minimum. • Identifying problems that occur in the design process, determining the root cause and taking timely corrective actions, both immediate and long term. • Developing and using approved vendor lists to ensure quality products. • Periodically evaluating the approved vendors to ensure their quality has not degraded; and, if it has, examining the products already supplied to ensure they are adequate. • Controlling documents and drawings, as well as changes to them, to approved processes. • Ensuring the quality of safety software used for design activities.

Section 45

• Identifying and controlling design interfaces. • Periodically meeting with vendors to ensure safety components can in fact be constructed and function consistent with design specifications without unconsidered exceptions. Ultimately, the safety documentation must be validated against approved design outputs. The iterative nature of the safety and design processes demands a more flexible change control process at this stage, but ultimately design outputs must be controlled under the applicable configuration management plan. DOE-STD-1073- 2003, Configuration Management, Section 3.9, discusses activities that should be initiated during design to ensure a smooth turnover from design to construction. DOE O 413.3A, Chg 1, requires that quality assurance begins at project inception and continues throughout the project’s life cycle. Consistent with that requirement, DOE O 413.3A, Chg 1, also requires that a quality assurance program (QAP) (compliant with 10 CFR 830, Subpart A, and DOE O 414.1C) is approved in CD-1 and updated and continuously applied throughout the project’s life cycle. The QAP describes the planned quality related activities, surveillances, and assessments and should be developed in the project conceptual phase and updated as the project matures. DOE-STD-1189-2008 Page 54 DOE and commercial nuclear industry QA experience highlight the need to specifically consider: • tracking and verification of assumptions from the safety analysis or design to operational acceptance; • appropriate translation of inspection and test requirements for installation verification or safety SSCs; • use of subcontractors with recent experience with nuclear QA; and • documentation of safety SSC inspections and tests. The project Quality Assurance Program (QAP), established at the project’s inception, will guide QA activities for the project. Appropriate assessments of the safety analysis and design process are planned and completed consistent with the project QAP. DOE G 414.1-4, Safety Software Guide for use with 10 CFR 830, Subpart A, and DOE O 414.1C are of special relevance with regard to design activities. 7.2 10 CFR 851 Worker Safety and Health Program The focus of the Worker Safety and Health Program Rule (i.e., 10 CFR 851) is as follows: • provide a place of employment that is free from recognized hazards that are causing or have the potential to cause death or serious physical harm to workers; and • ensure that work is performed in accordance with (i) all applicable requirements of this rule; and (ii) with the worker safety and health program for that workplace. This commitment to providing a workplace that is free of recognized hazards adds a layer of attention to the hazard analysis and facility controls that goes beyond that required for the Preliminary Documented Safety Analysis (PDSA). The 10 CFR 851 rule requires establishing a worker safety and health program that is approved by the Department. Two required areas of this rule that are of particular relevance to Safety-in-Design are fire protection and pressure safety. The rule invokes National Fire Protection Association (NFPA) requirements for fire protection and American Society of Mechanical Engineers (ASME) Boiler and Pressure Vessel code (BPV). These consensus standards are also typically invoked by DOE G 420.1- 1 for safety-significant and safety-class systems and components, as well as DOE G 420.1-3 for all fire protection systems, regardless of safety designation. These standards represent design input into any new construction and potentially to major modifications.

Section 46

Applicability of worker safety-related national consensus codes and standards should be recognized at the earliest stages of conceptual design and captured in appropriate DOE-STD-1189-2008 Page 55 requirements documents. As the design evolves into preliminary and detailed design, these codes and standards will drive certain areas of design. The worker safety and health program should ultimately be reflected in the SMP chapters of the DSA. Worker safety programs specifically described in the DSA are Hazardous Materials Program, Occupational Safety (which includes fire protection), Emergency Preparedness, Management, Organization, and Industrial Safety Provisions. These areas are discussed in more detail below. 7.3 Fire Protection A key interface during the early design phases is identifying the potential fire hazards and scenarios that can drive safety functional classification of fire protection SSCs (e.g., detection and suppression). Fire protection design includes the following elements: reliable water supply, noncombustible construction, fire-related barriers, detection systems, building contents, ventilation control, and automatic suppression systems. Design is developed through a competent and thorough FHA and interactions between the design team and fire protection SMEs. Design guidance for fire protection can be found in DOE G 420.1-3 and in DOE-STD-1066-99. Safety fire protection SSCs can represent a significant cost to the overall project and present special interface challenges between fire protection SMEs and safety analysis disciplines. A full understanding of the implications of fire protection selection is necessary to effectively implement such a strategy during detailed design. For example, selecting a confinement ventilation system that uses HEPA filtration necessitates considering potential particulate loading of the filters due to fire scenarios. An FHA is required for all nuclear facilities or facilities that present unique or significant fire risks. An FHA requires a comprehensive evaluation of fire hazards, including postulation of fire accident scenarios and estimates of potential consequences (i.e., maximum credible fire loss). DOE O 420.1B requires the conclusions of the FHA to be integrated into the DSA. DOE G-420.1-1 encourages the initiation of the FHA early in the design process and suggests that this effort be closely coordinated with the safety analysis effort. The preliminary FHA and its conclusions should be addressed in the facility CSDR and PSDR in a manner that reflects all relevant fire safety objectives that could affect the facility safety basis. The FHA is typically coordinated and integrated through teaming of fire safety personnel with hazard/accident analysts, and any conflicts related to the FHA and DSA should be resolved as early in the design process as practicable. DOE-HDBK- 1163-2003, Integration of Multiple Hazard Analysis Requirements and Activities, provides additional guidance. The FHA provides fire protection strategy and protection schemes necessary to control or mitigate fire hazards to workers and the general public. Each stage of the project life cycle as indicated in Table 8-1 demonstrates how the FHA supports the DOE-STD-1189-2008 Page 56

Section 47

design process. In the conceptual design, a preliminary FHA provides fire protection strategy alternatives for control or mitigation of accident consequences. Fire protection strategies will dictate design requirements. These design requirements will be evaluated as part of preliminary design. System-level hazard controls and classification are also developed and further refined. This includes other protection requirements, such as property protection and building code requirements. Another important facet of fire protection is the code-based requirement for an Authority Having Jurisdiction (AHJ). For designs that do not comply with appropriate NFPA Standards, AHJ review and acceptance of design outputs relevant to fire protection and life safety are required. Appropriate interfaces with the AHJ should be anticipated and planned. 7.4 Infrastructure Infrastructure considerations are critical to a project. It is important to identify infrastructure needs and existing capabilities or constraints as early as practicable in the design process. In this discussion, infrastructure includes all existing facilities and utilities that will interface or that may coexist with the new facility or modification to an existing facility. The infrastructure considerations include, but are not limited to the following: • supporting utilities (e.g., water, steam, power, industrial gases); • surrounding or collocated facilities; • supporting organizations and SMPs; and • interfacing facility (modifications). Of particular interest is the identification of any constraints that may hinder project planning and execution. Equipment compatibility (e.g., electrical) constraints can arise when interfaces with an aged infrastructure are possible. Gas systems should be investigated to fully understand interconnections with surrounding facilities and for features relevant to the hazard analysis. Utility interfaces should be identified in both pre-conceptual and conceptual design. An important consideration is the ability of the utilities to support SC and SS systems such as fire sprinkler systems. In preliminary design, specific needs should be reconciled with the existing systems capabilities and capacities to support baseline cost estimation. Surrounding or collocated facilities need to be considered in the early stages of the hazard analysis for conceptual design. Nearby facilities may present hazards (e.g., toxic or explosive gases) that must be considered in the hazard analysis as an external hazard. Provisions may be required within the planned facility to mitigate the effect of such events on personnel within the new facility. An analysis of the effects of nearby facilities should be completed in support of the Preliminary Safety Design Report (PSDR). DOE-STD-1189-2008 Page 57 7.5 Nuclear Criticality Safety Nuclear criticality safety (NCS) represents a specialized safety discipline. Given the significance of an inadvertent nuclear criticality, the presence of quantities of fissionable materials sufficient to sustain a critical reaction can determine the facility hazard categorization. Where there is sufficient fissionable material present, NCS controls can also result in safety significant functional classification of SSCs and, potentially, TSR controls. As a result, the NCS function must be represented on the project team and closely linked to the safety analysis effort from the earliest stages of project development. Criticality safety evaluations (CSE) must be integrated with the traditional safety analysis techniques to provide a comprehensive safety analysis. DOE has promulgated guidance for performing and documenting criticality safety evaluations in DOE-STD-3007-2007.

Section 48

To support design development, it is important to develop fundamental design criteria to address typical criticality safety concerns (e.g., safe geometry) and to incorporate these criteria early in the design process. The purpose of these criteria is to avoid the use of cumbersome and inherently less reliable administrative controls. An example set of design criteria is provided in Table 7-2. One of the most important criticality safety design features is to prevent, by design, natural phenomena initiators for criticality accidents (e.g. seismic and wind). In addition, the fire protection program at design will also drive criticality safety design requirements. The building code, Life Safety Code, national fire codes, and DOE directives almost always require automatic sprinkler protection and firefighting hose capability as well as suitable drainage for nuclear facilities. Unless exemptions and variances have been approved for automatic and manual fire suppression, the criticality calculations must take this moderator into account. For example, in a facility where sprinklers are planned, the criticality safety evaluations must consider the effects of introduction of water due to sprinkler activation. The presence of sprinklers will also tend to drive engineered controls for criticality safety to prevent water ingress to fissionable material containers, both in process containers and in storage. Criticality concerns could also result in a change from water-based sprinklers to an alternative gaseous suppression system, which could affect cost estimates. Therefore, there is a need for close cooperation between fire protection/fire hazards analysis and criticality safety early in design. Criticality safety includes human interaction with the potential criticality hazard. Addressing human interaction issues typically results in administrative controls. Minimizing use of administrative controls in lieu of more reliable engineered controls should be a focal point for design. This also points to the need to identify criticality safety issues early in the design process and design the facility in such a way as to preclude criticality problems (e.g., provide storage appropriate for the types of materials, design systems that can be used by the operator in a way that ensures criticality safety, consider criticality potential when designing sprinkler systems and other fire protection). One specific aspect of NCS operations requiring early project definition is emergency response to criticality accidents. Designs should strive to make a criticality accident a beyond extremely unlikely DOE-STD-1189-2008 Page 58 event. If that is not practical, the Double Contingency Principle requires control of two independent parameters (see DOE-STD-3007-2007). Deviations from the Double Contingency Principle must be specifically approved by DOE and typically results in layers of administrative controls. A singular focus of criticality Safety-in- Design should be to avoid the need for single parameter control in all processes where a criticality accident is credible. 7.6 Radiological Protection Radiological controls to achieve As Low as Reasonably Achievable (ALARA) represent a fundamental design philosophy that is used at the earliest stages of design and which is a requirement of 10 CFR 835. Subpart K of 10 CFR 835 “Design and Control and Facility Design and Modifications,” provides key inputs into the design process. DOE G 441.1-1B, Radiation Protection Programs Guide, provides additional guidance for design, in Section 7.4 of that guide.

Section 49

Radiological hazards will generally be considered as candidates for confinement or shielding strategies to minimize worker exposure. These strategies will evolve to design requirements through the project life cycle. In addition, detection or monitoring equipment is generally required to protect workers, the public, and the environment. 7.7 Human Factors In the context of safety bases development, DOE-STD-3009-94, CN 3, defines human factors to consist of the following: • human factors engineering that focuses on designing facilities, systems, equipment, and tools so they are sensitive to the capabilities, limitations, and needs of humans; and • human reliability analysis that quantifies the contribution of human error to the facility risk. These two factors apply to the design in (1) the layout and design of SSCs for operation, construction, maintenance, and testing or surveillance; and (2) in the evaluation of failure probability of human relied upon actions. In some instances, these factors overlap (e.g., control room operator action). The connection to the safety analysis is, in many cases, indirect in that, by including this philosophy, inadvertent human errors can be minimized. This is specifically important to ensure that administrative controls can be implemented within the facility. Within the project life cycle, the human potential for error is effectively addressed through the hazards analysis process and industrial or programmatic safety programs that identify other opportunities to avoid error potential. This is a normal part of design evolution and should be factored into the design process as those human DOE-STD-1189-2008 Page 59 factors reviews occur over the life cycle (particularly through preliminary and detailed design stages). Human factors for design should be established as a design philosophy early in the conceptual design phase. This philosophy should evolve to consider standard human interface issues. Many codes and standards reflect this approach, and it is inherent in the standards. It is also important to include operator input and reviews by maintenance and test personnel to ensure access for maintainability and testability. 7.8 Security Some measure of security is required to be addressed for most DOE facilities. However, for a limited number of facilities, security drivers for the design and operations are a key consideration for the project. In these limited cases, security requirements can represent a significant cost driver. Security protection schemes may involve one or more of the following: designed structural protection for key resources or materials; adversary deterrence and delay; intrusion detection systems; and protective force resources. Aspects of the security scheme must be coordinated with the design as it relates to safety in a two key areas: (1) structural design and (2) inadvertent or accidental discharge of weapons or weapon systems. The interaction between the project team and security personnel is needed to develop an integrated implementation involving both safety basis and security allowing achievement of the Design Basis Threat (DBT) objectives while ensuring safety is appropriately considered. Where significant structural protective measures are warranted (e.g., special nuclear material storage or processing), Natural Phenomena Hazards (NPH) design and security measures may be used in a complementary manner; that is, major structural components may be designed to serve both functions and result in efficient use of resources. The key factor is obtaining the security requirements early in the project to coordinate with the NPH design.

Section 50

Accidental discharges of security systems could initiate accidents such as hazardous material releases, fires, nuclear criticality, or damage to safety SSCs or process systems. As an initiator for an event, accidental or unintended discharge of weapons or deterrent systems could present a hazard to workers and the public, and must be addressed in the hazard analysis. These events could be caused by human error, faulty security system design, or internal or external hazards. There is also the potential for common cause effects on security systems that must be considered in the safety analysis. Some accident initiators that could actuate the security system and exacerbate accident consequences include facility events, such as fires, and seismic and other NPH events. Given the rapid evolution of security requirements, security modifications in existing facilities could be candidates for consideration as a major modification. In that case, preparation of a PDSA and application of the nuclear safety design criteria of DOE O 420.1B will be required. DOE-STD-1189-2008 Page 60 As safeguards and security has an independent set of directives that are implemented and the safety and security disciplines often use similar terms, it is important to clearly define the areas for which these two do not interface, as well as areas where interaction is needed. From the Safety-in-Design perspective, it is critical to address the interfaces and to clearly define when the protective measures implemented by the security system to meet the applicable requirements must be addressed by appropriate safety measures to ensure the safety and health of workers, public, and the environment. Interfaces with Safeguards and Security that are important to safety basis development include the development of Safeguards Requirements Identification (SRI), a Vulnerability Assessment (VA), and participation in the hazard analysis efforts. There are no requirements to document security strategies within the DSA. However, security plans and vulnerability assessments are required in the security domain and these documents may be influenced by safety-driven interaction through the process. 7.9 Environmental Protection The DOE National Environmental Policy Act (NEPA) process is a Federal process conducted in accordance with 10 CFR 1021, for identifying environmental impacts to support decision-making about a proposed action. The Integrated Project Team (IPT) needs to support this process. DOE O 451.1B, Chg 1, National Environmental Policy Act Compliance Program, establishes DOE internal requirements and responsibilities for implementing the National Environmental Policy Act (NEPA) of 1969, the Council of Environmental Quality Regulations implementing the Procedures Provisions of NEPA (40 CFR 1500-1508) and the DOE implementing procedures of 10 CFR 1021. The project should coordinate with the DOE Site and Operations Office NEPA compliance officers during the project initiation phase to ensure that the NEPA process is fully executed. NEPA documentation, consistent with design, should be developed as early as possible in the project acquisition process. In accordance with O 413.3A, Chg 1, the NEPA strategy and analysis are prepared during conceptual design. Final NEPA documents, including public involvement (if necessary) and resulting Record of Decision (ROD) or Finding of No Significant Impact (FONSI), must be issued prior start of final design.

Section 51

The Project Team needs to identify all applicable environmental regulatory requirements. These include regulations issued by the Environmental Protection Agency and by delegated states pursuant to statutes such as the Clean Air Act, the Clean Water Act, and the Resource Conservation and Recovery Act (RCRA). Other requirements (relating, for example, to protection of endangered species, protection of historic and cultural resources, and others) may also be applicable. Permits may be required under some of these regulations, and planning for these permits needs to be incorporated in the project schedule. Most permits are applicable to facility operation, but some may be required prior to start of construction. DOE O 450.1, Administrative Chg 1, Environmental Protection Program, and DOE-STD-1189-2008 Page 61 associated guides provide further information relative to environmental protection practices by which the DOE implements sound stewardship that is protective of the air, water, land, and other cultural resources impacted by DOE operations and by which DOE cost-effectively meets or exceeds compliance with applicable environmental, public health, and resource protection laws. DOE sites are required to implement environmental management systems, as part of their integrated safety management systems. The environmental aspects of the project should be reflected in the site’s environmental management system prior to operation. 7.10 Hazardous Material Similar to radiological hazards, DOE requirements invoke an ALARA concept for the protection of workers from hazardous materials. Design should support the primary objective of reducing the frequency, severity, and cost of incidents involving hazardous material, as well as the cost of hazardous operations. Prevention practices, such as substitution of less hazardous materials in a project or design of a process to reduce generation of hazardous waste, should be examined prior to consideration of protection strategies. Protection strategies will generally involve confinement strategies, such as gloveboxes, piped systems, and tanks, as well as administrative controls. The approach will typically be driven by the magnitude of the hazard and inventory. Major hazardous materials, typically associated with process requirements, should be identified and considered within the safety strategy. The process design will identify and refine inventory or maximum anticipated quantities to support structure, system, and component (SSC) functional classification. Codes and standards to be applied should be specified for application in detailed design. Provisions for facility monitoring and protection instrumentation for worker protection need to be considered. Further guidance is available in the DOE-HDBK-1139/2-2006, Chemical Management (Volume 2 of 3), “Chemical Safety and Lifecycle Management.” DSA Chapter 8, “Hazardous Material Protection,” must incorporate the ALARA approach, the elements to provide hazardous material exposure control, and facility protection instrumentation. 7.11 Radiological and Hazardous Waste Management Most processing facilities will generate waste. DOE-O-420.1B requires that facility process systems be designed to minimize waste production and mixing of radioactive and nonradioactive waste. Hazardous waste streams, including types, sources, and quantities should be identified early in the design and prevention practices, such as substitution of less hazardous materials in a project or design of a process to reduce generation of hazardous waste, should be examined to reduce management costs of these waste streams. Management strategies for these waste streams including

Section 52

DOE-STD-1189-2008 Page 62 storage and treatment and disposal systems must be described in the DSA. Any potential for accidental releases from waste handling and treatment systems should be addressed during the hazard analysis process in the preliminary and detailed design processes. 7.12 Emergency Preparedness DOE O 151.1C and its accompanying guidance set, the DOE G 151.1-series, establish specific requirements and methods for the Emergency Management Program (EMP). Early integration of EMP considerations into the safety design process can provide opportunities to minimize the hazardous nature of operations and to improve the ability to respond if an emergency occurs. There is much that can be gained in project integration between the EMP and the hazard analyses conducted for the safety analysis. At the early stages in the project, only major hazards are likely to be known. EMP SMEs, designers, and safety analysts can work together to identify options that may be less hazardous. Incorporating instrumentation, hardware, and related requirements into the design can improve the ability to detect emergency situations during operations. Early recognition of an event is essential to enable potentially affected workers and the public to take actions to prevent or limit their exposure to hazardous materials. Provisions in the design may be appropriate to support recovery and re- entry. The Emergency Planning Hazards Assessment (EPHA) for the EMP starts from the hazards analyses that support the safety design basis. The EPHA must include accident sequences where safety controls fail, as well as accidents that are beyond the design basis for a facility. DOE-HDBK-1163-2003 provides guidance for features of the EPHA that go beyond the scope of the hazards analyses that support design. EMP SMEs and project safety analysts should work together to define and analyze these scenarios. 7.13 External Reviews The safety documentation development effort should anticipate and prepare for external interfaces and reviews. Periodic reviews are required by DOE project oversight. In addition, external reviews are conducted by DOE pursuant to nuclear safety rules (i.e., 10 CFR 830, 835). The principal DOE external safety design basis reviews and approvals will be of the Conceptual Safety Design Report (CSDR), Preliminary Safety Design Report (PSDR), and PDSA, and, of course, review and approval of the operational DSA and Technical Safety Requirements (TSR). Periodic formal project reviews, particularly those at the major project approval stages, are required by DOE O 413.3A, Chg 1. The safety documentation development team should anticipate supporting these reviews. The team should DOE-STD-1189-2008 Page 63 expect focused reviews on safety functional classification determinations in relation to potential cost drivers for the project. The Defense Nuclear Facility Safety Board (DNFSB) is an independent oversight agency with purview of nuclear safety at DOE defense nuclear facilities. The DNFSB evaluates the effectiveness of DOE regulatory oversight activities and the safety of defense nuclear facility design, construction, operations, and decommissioning. Various DOE defense nuclear sites have resident DNFSB staff located with the DOE Site Operations Offices. The resident staff can, and typically will, participate in reviews of the project at any stage. Additionally the DNFSB conducts their own review of the proposed facility design, including the safety design basis development and construction, when determining the adequacy of project nuclear safety and the effectiveness of DOE oversight.

Section 53

Other external regulatory reviews performed for the purpose of permitting activities are conducted by independent agencies (local, state, and Federal) pursuant to environmental regulations such as the Resource Conservation and Recovery Act, Clean Air Act, and Clean Water Act. Typically, these permits or site permit modifications are approved before formally declaring facility readiness. In certain situations, the state may establish limiting criteria on design (e.g., zero release criteria) that may be more limiting on the design and operation than the requirements derived from safety design basis development. The project manager should anticipate and identify all stakeholders that could affect the development of the safety design case. Once identified, regular interaction with these key oversight groups should be planned to minimize unanticipated issues at critical review steps. 7.14 System Engineer Program DOE O 420.1B requires application of a System Engineer (SE) program to “active safety class and safety significant SSCs as defined in the facility’s DOE-approved safety basis, as well as to other active systems that perform important defense-in- depth functions, as designated by facility line management.” An objective of the program is to ensure operational readiness of systems within scope. This objective translates into ensuring proper configuration management of the systems and associated documentation and requirements. SE program requirements are also aimed at supporting operations and maintenance. In preparation for the operational phase, it will be important to identify SEs and involve them in the design and hazard analysis process. Ideally, this should begin in the final design phase so that they may become familiarized with the design in preparation for more direct involvement in the construction phase. SEs should be involved in the planning for and conduct of system testing to allow detailed operational understanding. The SEs should also have a fundamental understanding of the safety function and performance requirements for their assigned system, as well as for the associated design and safety documentation. Proper SE preparation will help facilitate a smooth transition to routine operation and maintenance following DOE-STD-1189-2008 Page 64 approval for operations. 7.15 Procedures, Training and Qualification A systematic approach to operations involves the development of operating procedures based on the design and identified hazard controls to operate SSCs within their design and DOE authorized limits through the TSRs. In turn, operators are trained on applicable process and hazard fundamentals, SSC operations and functions, and specific operating procedures. Operators are expected to understand important safety system features and any specific administrative controls, as well as the operator’s role in the safety of the facility. In order to satisfy expectations, the results of the safety and design process must be incorporated into the procedures and training programs. This includes nuclear criticality safety-derived requirements as well. System operating and test procedure development should begin in the detailed design phase. System description documents should be used as a tool to capture both operating intent and safety design information for use by the safety analysts and procedure writers. Draft qualification requirements should begin in parallel with detailed design and should be completed early in the construction phase. Training will ensue in the construction phase.

Section 54

DOE-STD-1189-2008 Page 65 Table 7-1. Typical Actions Associated with Project Life-Cycle Stages Actions Authorized by Critical Decision Approval Phase Interface Mission Need Conceptual Design Preliminary Design Detailed Design Construction Resource Requirements and Guidance QA • QA strategy • Update QA Plan • Conduct assessments • Assessments • Assessments • Input to DSA Ch. 14 • 10 CFR 830 • DOE-O-414.1C Fire Protection • Identify major fire scenarios and special fire considerations for input to likely safety SSC designation • Develop Preliminary FHA • Separation of SSCs • Life Safety – Egress considerations (approach) • Identify Fire Areas • Preliminary Functional classification • Define design codes and standards • FHA update • Design Basis Fire defined • Fire barrier design and fire areas finalized • AHJ review of building layout • FHA update • Support PDSA development • Final FHA • Prepare DSA Ch. 11 • DOE-O-420.1B • DOE-O-440.1 • DOE-STD-1066 • 10 CFR 851 • DOE G 420.1-3 DOE-STD-1189-2008 Page 66 Actions Authorized by Critical Decision Approval Phase Interface Mission Need Conceptual Design Preliminary Design Detailed Design Construction Resource Requirements and Guidance Criticality Safety • Determine criticality potential • Input to Hazard Categorization • Criticality Control Philosophy • Criticality guidance for Design • Preliminary CSEs • Updated criticality safety design requirements • Updated preliminary CSEs • Re-assess criticality limits and controls based on design and operating the process/facility • CSE input to PDSA (Hazard Analysis and TSR derivation) • Update and issue CSEs • TSRs and operating procedures will incorporate criticality controls, as developed under the guidance of DOE-STD-3007 and DOE G 423.1- 1. • Validate NCS controls in field\ • Prepare DSA Ch. 6 • DOE-O-420.1B • DOE-STD-3007- 2007 • DOE-G-421.1-1 • Radiological Protection • ALARA strategy • ALARA Review • Preliminary Shielding Analysis (Facility Layout and Material Location and Quantity) • ALARA Considerations in Design • Contamination Control • Zoning • Final Shielding Analysis • ALARA review • Monitoring (area and personnel) • Input to DSA Ch. 7 • 10 CFR 835 • DOE G 441.1-1B DOE-STD-1189-2008 Page 67 Actions Authorized by Critical Decision Approval Phase Interface Mission Need Conceptual Design Preliminary Design Detailed Design Construction Resource Requirements and Guidance Human Factors • Define HF strategy and goals • HF Engineering Plan HF Preliminary Review • HF Review • Prepare DSA Ch. 13 • DOE-HDBK- 1140-2001 Security • Draft Safeguards Requirements Identification (SRI) • SRI • Design reviews • Design Review • Security Plans • DOE-O-470.3 • DOE-O-470.4 Environmental Protection • EPA • State Environmental Agency • NEPA Strategy and Analysis • EPA • State Environmental Agency • Draft NEPA Documents • Final NEPA Documents • 10 CFR 1021 • DOE O 451.1B • DOE O 450 Hazardous Materials ALARA strategy • Toxicological Material Hazards Analysis • Contamination Control • Refine inventories • Codes and Standards defined • Zoning • ALARA review • ALARA reviews • Codes and Standards Implementation • Monitoring (area and personnel) requirements • Prepare DSA Ch. 8 • DOE-O-440.1A DOE-STD-1189-2008 Page 68 Actions Authorized by Critical Decision Approval Phase Interface Mission Need Conceptual Design Preliminary Design Detailed Design Construction

Section 55

Resource Requirements and Guidance Radiological and Hazardous Waste Management • Identify major waste streams • Fundamental approach defined • Develop waste handling designs • Prepare DSA Section 9 • 10 CFR 830 • DOE-O-420.1B • 10 CFR 850 • DOE O 435.1 Emergency Preparedness • Emergency Preparedness Hazard Survey and Screen • Update Emergency Preparedness Hazard Survey and Screen • Coordinate hazard evaluations • Preliminary EPHA • Update EPHA • EPHA updated and finalized • ERP updated and finalized • Prepare DSA Ch. 15 • 29 CFR 1910.119 • 40 CFR 68 • DOE-O-151.1C External Reviews • DNSFB • Project Review • SDS review • DNFSB • CSDR Review • Project Review • DNFSB • PSDR Review • Project Review • DNFSB • PDSA Review • Project Review • DNFSB • DSA/TSR Review • ORR/RA (as applicable) • DOE-O-226.1 System Engineer Program • Define systems requiring SE • Identify SEs • SEs participate in Final Design • SEs support testing • DOE-O-420.1B DOE-STD-1189-2008 Page 69 Actions Authorized by Critical Decision Approval Phase Interface Mission Need Conceptual Design Preliminary Design Detailed Design Construction Resource Requirements and Guidance Procedures, Training and Qualification • Identify training and qualification needs • Develop draft operating and maintenance procedures • Define operator qualification requirements • Complete procedures • Develop and conduct training • Input to DSA Ch. 12 • DOE O 5480.20A DOE-STD-1189-2008 Page 70 Table 7-2. Example Nuclear Criticality Safety Design Criteria Attribute Criteria Geometrically safe designs 1. Storage tanks, process piping, containers, etc. shall be designed for conservative enrichment or optimal concentration and reflection for all anticipated nuclides. 2. Designs shall be based on worst-case fire suppression actuation or local pipe breaks. 3. Leaks from solution areas should be anticipated and flooring designed to be compatible with solutions and provide collection capability (prevent long-term migration of fissionable material into sub-flooring materials). 4. Fissionable containing piping shall be spaced to preclude neutron interaction. Layout processes to support material flow 1. Fissionable solution piping shall be arranged to minimize or eliminate manual transfers. 2. Transfers from safe to non-geometrically safe geometry shall be provided with engineered controls. 3. Avoid any favorable to unfavorable geometry solution transfers. If such need to be made, active design features should be installed to mitigate the potential for a criticality accident due to transfer of fissionable solution to an unfavorable geometry vessel. System design for holdup minimization 1. Employ vertical tanks to facilitate particulate collection and monitoring. 2. Provide methods to facilitate holdup verification/assay. 3. Locate filtration on exhaust systems as close to main processing loop as possible. Maximize use of passive design features 1. Utilize positive isolation techniques to prevent unmonitored backflow potential (e.g., air breaks). 2. Avoid common ties between fissionable and non- fissionable systems. 3. Designs must eliminate potential for water ingress into fissionable material processes and containers in the event of fire. Standardize Equipment 1. Storage racks shall be modular and prevent relocation of fissionable material up to the seismic DBA. 2. Gloveboxes shall be designed to address concerns associated with spills or in-leakage of moderators. 3. All process equipment must withstand the facility seismic DBA. DOE-STD-1189-2008

Something wrong with this record? Tell us