DOE-STD-1189-2008, Integration of Safety Into the Design Process
Functional areas: Safety, Integrated Project Team, Project Execution Plan, Tailoring Strategy, Risk Management, Documented Safety Analysis
The Standard is written primarily for the use of the contractor(s) responsible for the design of a new facility. The processes described in the Standard, in addition to facilitating the integration of safety into design by the contractor, result in the development of several documents for input to the federal project team, the Federal Project Director and his Integrated Project Team (IPT). Superseded by DOE-STD-1189-2016.
Superseded By:
Version history and related documents
Superseded by
A newer version replaces this document.
Document text
Text extracted from the attached file. Refer to the original document for the authoritative version.
Section 1
NOT MEASUREMENT
SENSITIVE
DOE-STD-1189-2008
March 2008
DOE STANDARD
INTEGRATION OF SAFETY INTO THE
DESIGN PROCESS
U.S. Department of Energy AREA SAFT
Washington, DC 20585
DISTRIBUTION STATEMENT A. Approved for public release; distribution is unlimited.
DOE-STD-1189-2008
Page ii
This document is available on the Department of Energy
Technical Standards Program Web Page at
http://www.hss.energy.gov/nuclearsafety/techstds/
DOE-STD-1189-2008
Page iii
PREFACE
The U.S. Department of Energy (DOE) has approved this Standard for use by DOE and its
contractors.
In a memorandum to DOE elements, dated December 5, 2005, on integration of Safety-in-
Design, the Deputy Secretary of Energy stated, “I expect safety to be fully integrated into design
early in the project. Specifically, by the start of the preliminary design, I expect a hazard
analysis of alternatives to be complete and the safety requirements for the design to be
established. I expect both the project management and safety directives to lead projects on the
right path so that safety issues are identified and addressed adequately early in the project
design.”
DOE Standard 1189 has been developed to show how project management, engineering design,
and safety analyses can interact to successfully implement the Deputy Secretary’s expectations.
These interactions are a fundamental element necessary in the integration of safety throughout
the DOE Acquisition Management System. They are key to the timely identification, evaluation,
and adjudication of Safety-in-Design issues early in project life.
This Standard provides the Department’s expectations for incorporating safety into the design
process for new or major modifications to DOE Hazard Category 1, 2, and 3 nuclear facilities,
the intended purpose of which involves the handling of hazardous materials, both radiological
and chemical, in a way that provides adequate protection for the public, workers, and the
environment. The Standard describes the Safety-in-Design philosophies to be used with the
project management requirements of DOE Order (O) 413.3A, Change (Chg) 1, Program and
Project Management for the Acquisition of Capital Assets, and incorporates the facility safety
criteria in DOE O 420.1B, Facility Safety, as a key foundation for Safety-in-Design
determinations.
The requirements provided in the above DOE Orders and the expectations in this Standard
provide for identification of hazards early in the project and the use of an integrated team
approach to design safety into the facility. The basic Safety-in-Design precepts are as follows:
• appropriate and reasonably conservative safety structures, systems, and components are
selected early in project designs;
• project cost estimates include these structures, systems, and components; and
• project risks associated with safety structures, systems, and components selections are
specified for informed risk decision-making by the Project Approval Authorities.
The provisions of this Standard, when implemented in conjunction with DOE O 413.3A, Chg 1,
and its guidance documents, are consistent with the core functions and guiding principles of
Integrated Safety Management (ISM), as described in DOE P 450.4, Integrated Safety
Management Policy.
The Standard provides guidance on a process of integration of Safety-in-Design intended to
implement the applicable ISM core functions—define the work, analyze the hazards, establish
the controls—necessary to provide protection of the public, workers, and the environment from
Section 2
DOE-STD-1189-2008
Page iv
harmful effects of radiation and other such toxic and hazardous aspects attendant to the work.
Important ISM guiding principles involved in this process and addressed in this Standard are
identification of safety standards and requirements and development of hazard controls tailored
to the work to be performed. The process includes documentation and timely review of safety
design evolution to ensure feedback and improvement, leading to design and construction that
can lead to operations authorization.
The Standard does not instruct designers how to design nor instruct safety personnel how to
perform safety analyses. Rather, the Standard provides guidance on how these two disciplines
and project management can interface and work together to incorporate safety into design.
A project is expected to evolve over time, and the project safety design basis is also expected to
evolve. The expectation is that within this evolution process, unanticipated issues will be
minimized.
Some of the key concepts that are included in the Standard are the following.
1. The importance of the Integrated Project Teams (IPT), federal and contractor, including a
contractor Safety Design Integration Team (SDIT), and effective coordination among
these teams. The SDIT comprises both safety and design subject matter experts and is
the heart of the safety and design integration effort.
2. The development of a Safety Design Strategy (SDS) that provides a roadmap for
strategizing how important safety issues will be addressed in the design and in the
tailoring in the development of key safety documentation. The SDS should be initiated
based on a statement of DOE expectations for Safety-in-Design developed during the pre-
conceptual stage and should be submitted during the conceptual design stage and updated
and refined through the design process.
3. The development, in the conceptual design stage, of facility-level design basis accidents
(DBA) that provide the necessary input to the identification and classification of
important safety functions. These classifications (i.e., safety class, safety significant,
seismic design basis) provide design expectations for safety structures, systems, and
components (SSC).
4. The development of objective radiological criteria for safety and design classification of
SSCs. These criteria relate to public and collocated worker-safety design considerations.
5. The identification and application of nuclear safety design criteria as provided by DOE O
420.1B and its associated guides.
6. The development of guidance for the preparation of a Conceptual Safety Design Report
(CSDR), a Preliminary Safety Design Report (PSDR), and the Preliminary Documented
Safety Analysis (PDSA). These reports are required by DOE O 413.3A, Chg 1, for
Hazard Category 1, 2, and 3 nuclear facilities, and they must be approved by DOE as part
of the project approvals to proceed to the next design or construction phase. The intent of
these reports and their approval is to ensure that the directions and decisions made
regarding project safety are explicitly identified and dealt with in early stages of design.
The objective is to reduce the likelihood of costly late reversals of design decisions
involving safety.
DOE-STD-1189-2008
Page v
Section 3
7. The definition, as needed, of a Risk and Opportunities Assessment that recognizes the
risks of proceeding at early stages of design (especially conceptual design) on the basis of
incomplete knowledge or assumptions regarding safety issues and the opportunities that
may arise during preliminary and final design to reduce costs through alternative or
refined design concepts or better knowledge regarding the uncertainties. This assessment
is intended to be input to the Risk Management Plan assessments for a project.
These key elements of the Standard have several intersections and possible overlaps with the
guides for the implementation of DOE O 413.3A, Chg 1. These guides should also be consulted
for more complete information on the associated activities and documents. In addition, several
directives and standards deal with some aspects of Safety-in-Design that are also addressed in
this Standard, such as safety system classification and seismic design bases. For new facility
design, these directives and standards are supplemented by this Standard. The directives and
standards in this category are as follows:
• DOE G 420.1-1, Nonreactor Nuclear Safety Design Criteria and Explosive Safety Guide
for use with DOE O 420.1 Facility Safety;
• DOE G 420.1-2, Guide for the Mitigation of Natural Phenomena Hazards for DOE
Nuclear Facilities and Nonnuclear Facilities;
• DOE G 421-1-2, Implementation Guide for Use in Developing Documented Safety
Analyses to Meet Subpart B of 10 CFR 830;
• DOE-STD-1020-2002, Natural Phenomena Hazards Design and Evaluation Criteria for
Department of Energy Facilities;
• DOE-STD-1021-93, Natural Phenomena Hazards Performance Categorization
Guidelines for Structures, Systems, and Components; and
• DOE-STD-3009-94, Change Notice (CN) 3, Preparation Guide for U.S. Department of
Energy Nonreactor Nuclear Facility Safety Analysis.
Nuclear safety design basis documents required by DOE O 413.3A, Chg 1 and by Title 10, Code
of Federal Regulations (CFR) Part 830, Nuclear Safety Management, Subpart B, Safety Basis
Requirements, for new projects and major modifications must be developed consistent with the
expectations and guidance in this Standard.
There are a number of DOE Directives and Technical Standards specifically referenced in this
Standard. Unless specifically prohibited or limited, successor documents may be used in place
of the referenced directive or standard. Successor documents are subsequent revisions to the
specified directives and standards issued through the DOE Directives System or DOE Technical
Standards Program, as applicable, (for example, DOE O 420.1B would be a successor document
to DOE O 420.1A) or the documents that replace them as defined within those programs (for
example, a DOE directive may cancel all or part of a directive and replace those provisions with
new provisions in a new directive). However, documents issued outside the Directives System
and the Technical Standards Program are not considered to be successor documents to these
directives and standards. Contracts and regulations may require that specific revisions be
applied, particularly for individual projects (for example, 10 CFR Part 830 requires that hazard
categorization be performed consistent with DOE-STD-1027-92, Change Notice 1, September
DOE-STD-1189-2008
Page vi
1997). The provisions of 10 CFR Part 830, Appendix A to Subpart B, Table 2, (known as the
“safe harbor methodologies” for 10 CFR Part 830) specifically permit use of successor
documents for the listed directives and standards.
Section 4
DOE-STD-1189-2008
Page vii
SAFETY DESIGN GUIDING PRINCIPLES
1. DOE Order 420.1B, Facility Safety, is utilized and addressed in design activities, as
applicable. Design teams should be able to clearly articulate strategies in the design that
address DOE O 420.1B expectations and include them in the design/safety basis information.
2. Control selection strategy to address hazardous material release events is based on the
following order of preference at all stages of design development.
• Minimization of hazardous materials is the first priority.
• Safety structures, systems, and components (SSCs) are preferred over Administrative
Controls.
• Passive SSCs are preferred over active SSCs.
• Preventative controls are preferred over mitigative controls.
• Facility safety SSCs are preferred over personal protective equipment.
• Controls closest to the hazard may provide protection to the largest population of
potential receptors, including workers and the public.
• Controls that are effective for multiple hazards can be resource-effective.
3. Design codes and standards incorporated into the DOE O 420.1B guides are to be followed,
unless specific exceptions are taken to those listed and approved by DOE.
4. The risk and opportunity assessment includes consideration of the Safety-in-Design
approaches selected to address project cost contingencies and appropriate mitigation
strategies for the risks/opportunities identified for the strategies selected.
5. Early project decisions on a technical approach are conservative in order to establish
appropriate cost and schedule baselines for the project.
6. The Critical Decision (CD) packages portray safety-item selections, bases, and risks and
opportunities, with proposed mitigation strategies and cost and contingencies, to enable
informed risk decision-making by the project approval authorities regarding the project
technical basis and cost.
7. The project team includes appropriate expertise and is established early in the project cycle.
8. Safety personnel are used from the onset of project planning to help ensure that appropriate
hazards and techniques for hazard management are considered (e.g., material-at-risk [MAR]
limitation, prevention techniques, and operationally effective design solutions).
9. Important safety functions, such as facility building confinement, confinement ventilation
approach and systems, fire protection strategies and systems, security requirements, life-
safety considerations, emergency power systems, and associated seismic design bases are
addressed during conceptual design.
10. The safety design team ensures sufficient process definition is available, particularly at the
conceptual and preliminary design stages, to enable major safety cost drivers to be included
DOE-STD-1189-2008
Page viii
in the design documentation, along with their associated safety functions and design criteria.
The team also identifies the risks and opportunities associated with the selections identified
and develops mitigation strategies that are included in the cost-estimate contingencies.
Details may not be available in early project stages to identify all hazards and needed hazard
controls.
11. All stakeholders are important to the process. Stakeholder issues are identified early and
addressed.
12. To ensure that the project/facility configuration can be managed appropriately, the basis for
decisions related to safety is clearly documented.
DOE-STD-1189-2008
Page ix
Section 5
TABLE OF CONTENTS
PREFACE....................................................................................................................... iii
SAFETY DESIGN GUIDING PRINCIPLES.................................................................... vii
ABBREVIATIONS AND ACRONYMS........................................................................... xiv
1.0 INTRODUCTION...................................................................................................1
1.1 Background ................................................................................................1
1.2 Roadmap to the Standard for Categories of Users.....................................2
1.3 Applicability ................................................................................................3
1.4 Must and Should ........................................................................................4
1.5 Supplementary Guidance Documents ........................................................4
2.0 PROJECT INTEGRATION AND PLANNING ........................................................6
2.1 Contractor Integrated Project Team ...........................................................6
2.2 Safety Design Integration Team .................................................................7
2.3 Safety Design Strategy...............................................................................8
2.4 Safety Interface with Project Management ...............................................11
2.4.1 Relationship to Project Management........................................... 11
2.4.2 General Expectations .................................................................. 15
2.4.3 Planning ...................................................................................... 15
2.4.4 Tailoring of Requirements............................................................ 16
2.4.5 Safety Interface Requirements .................................................... 16
3.0 SAFETY CONSIDERATIONS FOR THE DESIGN PROCESS ...........................18
3.1. Pre-Conceptual Phase .............................................................................19
3.2 Conceptual Design Phase ........................................................................22
3.3 Preliminary Design Phase ........................................................................27
3.4 Final Design Phase ..................................................................................30
3.5 Construction, Transition, and Closeout.....................................................33
3.5.1 Introduction .................................................................................. 33
3.5.2 Construction................................................................................. 33
3.5.3 Development of Safety Basis ....................................................... 33
3.5.4 Checkout/Acceptance, Testing and Commissioning .................... 35
3.5.5 Readiness Reviews ..................................................................... 35
3.5.6 Project Closeout........................................................................... 35
DOE-STD-1189-2008
Page x
4.0 HAZARD AND ACCIDENT ANALYSES..............................................................37
4.1 Pre-conceptual Planning Phase ...............................................................37
4.2 Conceptual Design Phase ........................................................................37
Section 6
4.3 Preliminary Design Phase ........................................................................42
4.4 Final Design ............................................................................................44
5.0 NUCLEAR SAFETY DESIGN CRITERIA............................................................46
6.0 SAFETY REPORTS............................................................................................48
6.1 Safety Input to the Conceptual Design Report .........................................48
6.2 Conceptual Safety Design Report ............................................................49
6.3 Preliminary Safety Design Report (and PDSA) ........................................49
6.4 Change Control for Safety Reports as Affected by Safety-in-Design
Activities ...................................................................................................50
7.0 SAFETY PROGRAM AND OTHER IMPORTANT PROJECT INTERFACES .....52
7.1 Quality Assurance ....................................................................................52
7.2 10 CFR 851 Worker Safety and Health Program .....................................54
7.3 Fire Protection ..........................................................................................55
7.4 Infrastructure ............................................................................................56
7.5 Nuclear Criticality Safety ..........................................................................57
7.6 Radiological Protection.............................................................................58
7.7 Human Factors.........................................................................................58
7.8 Security ....................................................................................................59
7.9 Environmental Protection ...........................................................................60
7.10 Hazardous Material ..................................................................................61
7.11 Radiological and Hazardous Waste Management....................................61
7.12 Emergency Preparedness ........................................................................62
7.13 External Reviews.....................................................................................62
7.14 System Engineer Program .......................................................................63
7.15 Procedures, Training and Qualification.....................................................64
8.0 ADDITIONAL SAFETY INTEGRATION CONSIDERATIONS FOR PROJECTS.71
8.1 Integration of Safety into Facility Modifications.........................................71
8.1.1 Review of Existing Hazard Analysis............................................. 74
8.1.2 Major Modifications ...................................................................... 75
DOE-STD-1189-2008
Page xi
8.1.3 Determining a Major Modification................................................. 75
8.2 Construction Projects within Operating Facilities......................................79
8.3 Government Furnished Equipment...........................................................79
8.3.1 GFE-Provider Responsibilities ..................................................... 80
8.3.2 GFE End User Responsibilities.................................................... 82
APPENDIX A SAFETY SYSTEM DESIGN CRITERIA ................................................ A-1
Section 7
A.1 Seismic Design Basis ............................................................................. A-1
A.2 Safety Classification of SSCs ................................................................. A-5
A.3 Existing Facilities and Major Modifications of Existing Facilities............. A-6
APPENDIX B CHEMICAL HAZARD EVALUATION..................................................... B-1
B.1 Screening of Hazardous Chemical Materials.......................................... B-1
B.2 Public and Collocated Worker Protection Criteria................................... B-2
B.3 Estimating Exposures to Collocated Workers and the Public ................. B-2
B.4 Chemical Mixtures .................................................................................. B-4
APPENDIX C FACILITY WORKER HAZARD EVALUATION ......................................C-1
APPENDIX D ADDITIONAL FUNCTIONAL CLASSIFICATION CONSIDERATIONS .D-1
D.1 Selection and Classification of a Complete Control Set..........................D-1
D.2 Criteria for Selecting SS Major Contributors to Defense-in- Depth.........D-1
APPENDIX E SAFETY DESIGN STRATEGY.............................................................. E-1
E.1 Introduction............................................................................................. E-1
E.2 SDS Format and Content ....................................................................... E-1
APPENDIX F SAFETY-IN-DESIGN RELATIONSHIP WITH THE RISK MANAGEMENT
PLAN................................................................................................................. F-1
APPENDIX G HAZARDS ANALYSIS TABLE DEVELOPMENT ..................................G-1
DOE-STD-1189-2008
Page xii
G.1 Scenario Description ..............................................................................G-1
G.2 Initiating Event Frequency ......................................................................G-2
G.3 Unmitigated Consequence Evaluation....................................................G-2
G.4 Safety Functions.....................................................................................G-2
G.5 Preventive Features (Design and Administrative) ..................................G-3
G.6 Method of Detection ...............................................................................G-4
G.7 Mitigative Features (Design and Administrative) ....................................G-4
G.8 SSC Safety Control Suite and Safety Functions.....................................G-5
G.9 Mitigated Consequences ........................................................................G-5
G.10 Planned Analyses, Assumptions and Risk/Opportunity Identification.....G-5
G.11 Hazards Analysis Table..........................................................................G-6
APPENDIX H CONCEPTUAL SAFETY DESIGN REPORT ........................................H-1
H.1 Introduction.............................................................................................H-1
H.2 CSDR FORMAT AND CONTENT GUIDE ..............................................H-2
APPENDIX I PRELIMINARY AND FINAL DESIGN STAGE SAFETY
DOCUMENTATION ........................................................................................... I-1
I.1 Introduction.............................................................................................. I-1
I.1.1 Preliminary Safety Design Report ................................................. I-1
Section 8
I.1.2 Preliminary Documented Safety Analysis ..................................... I-3
I.2 PSDR/PDSA FORMAT AND CONTENT GUIDE..................................... I-4
APPENDIX J MAJOR MODIFICATION DETERMINATION EXAMPLES......................J-1
Example 1 ..........................................................................................................J-1
Example 2 ..........................................................................................................J-3
Example 3 ..........................................................................................................J-5
Example 4 ..........................................................................................................J-6
CONCLUDING MATERIAL................................................................. Concluding Page 1
DOE-STD-1189-2008
Page xiii
LIST OF FIGURES AND TABLES
Table 2‐1. Roles and Responsibilities ____________________________________________ 12
Figure 3‐1. Pre‐Conceptual Phase_______________________________________________ 21
Figure 3‐2. Conceptual Design Phase ____________________________________________ 23
Figure 3‐3. Preliminary Design Phase____________________________________________ 28
Figure 3‐4. Final Design Phase _________________________________________________ 32
Table 7‐1. Typical Actions Associated with Project Life‐Cycle Stages ___________________ 65
Table 7‐2. Example Nuclear Criticality Safety Design Criteria_________________________ 70
Figure 8‐1. Facility Modification Process _________________________________________ 73
Table 8‐1. Major Modification Evaluation Criteria _________________________________ 77
Table A‐1. Guidance for SDC Based on Unmitigated Consequences of SSC Failures in a Seismic
Event ______________________________________________________________________A‐3
Table F‐1. Safety‐in‐Design Considerations for Risk and Opportunity Analysis ___________ F‐3
Table I‐1. Sample SMP Roadmap_______________________________________________ I‐39
DOE-STD-1189-2008
Page xiv
ABBREVIATIONS AND ACRONYMS
AEGL Acute Exposure Guideline Level
AHJ Authority Having Jurisdiction
ALARA As Low as Reasonably Achievable
ANS American Nuclear Society
ANSI American National Standards Institute
ARF Airborne Release Fraction
ARR Airborne Release Rate
ASME American Society of Mechanical Engineers
BOD Basis of Design
BPV Boiler and Pressure Vessel Code
CD Critical Decision
CDR Conceptual Design Report
CFR Code of Federal Regulation
CHG Change
CIPT Contractor Integrated Project Team
CN Change Notice
COA Condition of Approval
CSDR Conceptual Safety Design Report
CSE Criticality Safety Evaluation
CSP Criticality Safety Program
CX Categorical Exclusion
D&D Decontamination and Decommissioning
DBA Design Basis Accident
DBT Design Basis Threat
DCF Dose Conversion Factor
DID Defense-in-Depth
DNFSB Defense Nuclear Facilities Safety Board
DOE U.S. Department of Energy
DR Damage Ratio
DSA Documented Safety Analysis
EEGL Emergency Exposure Guidance Level
DOE-STD-1189-2008
Page xv
EMP Emergency Management Program
EPA U.S. Environmental Protection Agency
EPHA Emergency Planning Hazard Assessment
ERPG Emergency Response Planning Guideline
FONSI Finding of No Significant Impact
FHA Fire Hazard Analysis
FMEA Failure Modes and Effects Analysis
FW Facility Worker
GFE Government Furnished Equipment
HA Hazards Analysis
HASP Health and Safety Plan
HAZOP Hazard and Operability Analysis
HCN Health Code Number
HEPA High Efficiency Particulate Air
HPR Highly Protected Risk
Section 9
IPT Integrated Project Team
ISM Integrated Safety Management
ITS Important To Safety
MAR Material-at-Risk
MC&A Material Control and Accountability
N/A Not Applicable
NCS Nuclear Criticality Safety
NEPA National Environmental Policy Act
NFPA National Fire Protection Association
NPH Natural Phenomena Hazard
O Order
OECM Office of Engineering and Construction Management
OMB Office of Management and Budget
ORR Operational Readiness Review
OSHA Occupational Safety and Health Administration
DOE-STD-1189-2008
Page xvi
P&ID Piping and Instrumentation Diagram
PC Performance Category
PDSA Preliminary Documented Safety Analysis
PEP Project Execution Plan
PFD Process Flow Diagram
PHA Preliminary Hazards Analysis
PSDR Preliminary Safety Design Report
QA Quality Assurance
RF Respirable Fraction
ROD Record of Decision
RMP Risk Management Plan
SAC Specific Administrative Control
SC Safety Class
SCAPA Subcommittee on Consequence Assessment and Protective Actions
SDIT Safety Design Integration Team
SDC Seismic Design Criteria
SDS Safety Design Strategy
SE System Engineer
SER Safety Evaluation Report
SME Subject Matter Expert
SMP Safety Management Program
SNM Special Nuclear Material
SPEGL Short-Term Public Emergency Guidance Level
SRI Safeguards Requirements Identification
SRID Standards and Requirements Identification Document
SS Safety Significant
SSC Structure, System, and Component
STD Standard
TEC Total Estimated Cost
TEDE Total Effective Dose Equivalent
TEEL Temporary Emergency Exposure Limit
TPQ Threshold Planning Quantity
TSR Technical Safety Requirements
DOE-STD-1189-2008
Page xvii
USQ Unreviewed Safety Question
DOE-STD-1189-2008
Page xviii
DEFINITIONS
Conceptual Safety Design Report (CSDR) – A Conceptual Safety Design Report is developed
to:
a. document and establish a preliminary inventory of hazardous materials, including
radioactive materials and chemicals;
b. document and establish the preliminary hazard categorization of the facility;
c. identify and analyze primary facility hazards and facility Design Basis Accidents;
d. provide an initial determination, based on preliminary hazard analysis, of Safety Class
and safety significant structures, systems, and components (SSC);
e. include a preliminary assessment of the appropriate Seismic Design Category for the
facility itself, as well as the safety significant structures, systems, and components;
f. evaluate the security hazards that can impact the facility safety basis (if applicable); and
g. include a commitment to the nuclear safety design criteria of DOE O 420.1 (or proposed
alternative criteria).
Conceptual Safety Validation Report (CSVR) – The report prepared by DOE that documents
the DOE review of the Conceptual Safety Design Report.
Documented Safety Analysis (DSA) – A documented analysis of the extent to which a nuclear
facility can be operated safely with respect to workers, the public, and the environment,
including a description of the conditions, safe boundaries, and hazard controls that provide the
basis for ensuring safety.
Fire Hazards Analysis (FHA) – A comprehensive assessment of the potential for a fire at any
location to ensure that the possibility of injury to people or damage to buildings, equipment, or
the environment is within acceptable limits (NFPA 801).
Hazards Analysis (HA) – This analysis supports PDSA development during Preliminary and
Final Design and identifies the types and magnitudes of hazards that are anticipated in the
facility. This level of hazard analysis expands the PHA to include evaluation of the process
hazards.
Section 10
Integrated Project Team (IPT) – An Integrated Project Team is a cross-functional group of
individuals organized for the specific purpose of delivering a project to an external or internal
customer. For the purposes of this Standard, this team may be composed of both Federal and
contractor (or subcontractor) personnel, and it will support and report to the Federal Project
Director. For complex or hazardous projects, a subordinate contractor IPT (CIPT) may be
formed to support the Federal IPT and Project Director.
Major Modification – Modification to a DOE nuclear facility that is completed on or after April
9, 2001, that substantially changes the existing safety basis for the facility.
Preliminary Documented Safety Analysis Report (PDSA) – Documentation prepared in
connection with the design and construction of a new DOE nuclear facility or a major
modification to a DOE nuclear facility that provides a reasonable basis for the preliminary
DOE-STD-1189-2008
Page xix
conclusion that the nuclear facility can be operated safely through the consideration of factors
such as:
(1) the nuclear safety design criteria to be satisfied;
(2) a safety analysis that derives aspects of design that are necessary to satisfy the nuclear
safety design criteria; and
(3) an initial listing of the safety management programs that must be developed to address
operational safety considerations.
Preliminary Hazards Analysis (PHA) – This document provides a broad hazard-screening tool
that includes a review of the types of operations that will be performed in the proposed facility
and identifies the hazards associated with these types of operations and facilities. The results of
the PHA are used to determine the need for additional, more detailed analysis; serve as a
precursor where further analysis is deemed necessary; and serve as a baseline hazard analysis
when further analysis is not indicated. The PHA is most applicable in the conceptual design
stage, but it is also useful for existing facilities and equipment that have not had an adequate
baseline hazard analysis.
Preliminary Safety Design Report (PSDR) – The report developed during Preliminary Design
that updates and provides additional site and design details to those provided in the CSDR. The
PSDR follows the format and content of the PDSA produced during final design.
Preliminary Safety Validation Report (PSVR) – The report prepared by DOE that documents
the DOE review of the Preliminary Safety Design Report.
Safety Design Strategy (SDS) – The SDS, as part of the Project Execution Plan, provides a
strategy for the early safety design basis development starting in the pre-conceptual design
phase. The SDS documents all applicable Safety-in-Design expectations for the early project
phases.
Safety-in-Design – The process of identifying and incorporating appropriate structures, systems,
and components (SSCs) and their associated safety functions and design criteria into the project
design to provide adequate protection for workers and the public.
Safety Design Integration Team (SDIT) – This contractor team, when established, supports the
Federal or the Contractor Integrated Project Team (IPT) to ensure the integration of safety into
the design process. The composition of the team is adjusted as necessary to ensure the proper
technical representation commensurate with the analyzed hazards and the specific project phase.
The SDIT ultimately supports decisions to be made by the Federal Project Director.
Section 11
Safety Evaluation Report (SER) – The report prepared by DOE to document (1) the sufficiency
of the documented safety analysis for a Hazard Category 1, 2, or 3 DOE nuclear facility; (2) the
extent to which a contractor has satisfied the requirements of Subpart B of this part; and (3) the
basis for approval by DOE of the safety basis for the facility, including any conditions for
approval.
DOE-STD-1189-2008
Page xx
Safety Limits – The limits on process variables associated with those safety-class physical
barriers, generally passive, that are necessary for the intended facility function and that are
required to guard against the uncontrolled release of radioactive materials.
DOE-STD-1189-2008
Page 1
1.0 INTRODUCTION
1.1 Background
Federal Project Directors are accountable for the planning, programming, budgeting,
and acquisition of capital assets. The principal goal of the Department of Energy
(DOE) Acquisition Management System is to deliver capital assets on schedule,
within budget, and fully capable of meeting mission performance and environment,
safety, and health standards. DOE Federal Project Directors are responsible for
managing capital asset projects with integrity and in compliance with applicable laws
and contractual provisions. Major DOE objectives include obtaining quality
products, ensuring timeliness of performance, controlling cost, and preventing or
mitigating adverse events. To achieve these goals, Federal Project Directors
assemble an integrated team that includes members from other DOE functional areas,
such as budget, financial, legal, safety, and contracting, to assist them with the
planning, programming, budgeting, and acquisition of capital assets.
DOE O 413.3A, Chg 1,, Program and Project Management for the Acquisition of
Capital Assets, was developed to implement the DOE acquisition policy and Office of
Management and Budget (OMB) Circulars1 regarding planning, budgeting, and
acquisition of capital assets; management accountability and control; financial
management; and management of Federal information resources. The process,
described in the Order and associated DOE directives and guidance2 and implemented
by DOE organizational elements, is referred to as the DOE Acquisition Management
System.
A fundamental element that is necessary to achieve the DOE goal for capital asset
acquisition is the integration of safety throughout the DOE Acquisition Management
System. This Standard supports the DOE objective by providing guidance on those
actions and processes important for integrating safety into the acquisition process for
DOE Hazard Category 1, 2, and 3 nuclear facilities. Integrating safety into design is
more than just developing safety documents that are accepted by the design function
and organization: it requires that safety be understood by, and integrated into, all
functions and processes of the project. Therefore, this Standard identifies interfaces,
methodologies, and documentation strategies that might support proper integration.
In addition, the Standard provides format and content guidance for the development
of safety documentation required by DOE O 413.3A, Chg 1,3 and 10 CFR 830,
Nuclear Safety Management. These required documents include the Conceptual
Safety Design Report (CSDR), the Preliminary Safety Design Report (PSDR), and
the Preliminary Documented Safety Analysis (PDSA). The Standard provides
information and the methodology for identifying and analyzing hazards, selecting and
Section 12
1 OMB Circulars A-11 (Part 7), A-123, A-127, and A-130.
2 The DOE Office of Engineering and Construction Management (OECM) also publishes Project Management
Practices that are available on the OECM web page: oecm.energy.gov.
3 The application and use of any revision to DOE O 413.3A,Chg 1, will be determined by DOE for any ongoing
project.
DOE-STD-1189-2008
Page 2
classifying appropriate safety structures, systems, and components (SSC), and
integrating safety personnel at pertinent phases of project initiation, definition, and
execution.
1.2 Roadmap to the Standard for Categories of Users
The Standard is written primarily for the use of the contractor(s) responsible for the
design of a new facility. The processes described in the Standard, in addition to
facilitating the integration of safety into design by the contractor, result in the
development of several documents for input to the federal project team, the Federal
Project Director and his Integrated Project Team (IPT). These documents include:
• the Safety Design Strategy (SDS), which supports the development of a
Tailoring Strategy and the Project Execution Plan (PEP) required by DOE O
413.3A, Chg 1;
• a Risk and Opportunities Assessment, which supports the Risk Management
Plan required by Order 413.3A, Chg 1; and
• three safety reports required by Order 413.3A, Chg 1, (Conceptual Safety
Design Report, Preliminary Safety Design Report, and the Preliminary
Documented Safety Analysis).
Chapter 2 of this Standard discusses the preparation, reviews, and approvals of these
safety documents.
There are several categories of target audiences/users of the Standard. The parts of
the Standard particularly relevant to all audiences are the Preface, including the key
concepts and guiding principles upon which the Standard was developed, this
Introduction (Chapter 1), Chapter 2, Project Integration and Planning, and Chapter 3,
Safety Considerations for the Design Process, which provides an overall perspective
of the Safety-in-Design process of this Standard.
Project management, both federal and contractor, will also find Chapter 7, Safety
Program and Other Important Project Interfaces, Appendix E, Safety Design
Strategy, and Appendix F, Safety-in-Design Relationship with the Risk Management
Plan informative and useful to their responsibilities and functions.
Project safety personnel and DOE safety reviewers will find that Chapter 4, Hazard
and Accident Analyses; Chapter 5, Nuclear Safety Design Criteria; Chapter 6, Safety
Reports; Appendices A through D, which deal with safety SSC and seismic
classifications; and Appendix G, Hazards Analysis Table Development are directed
toward their functions and responsibilities. Appendix F, Safety-in Design
Relationship with the Risk Management Plan is also important to safety personnel
because they are the source of initial input to the Risk and Opportunities Assessment
related to safety assumptions and uncertainties that can affect the project’s cost and
schedule.
DOE-STD-1189-2008
Page 3
Project design personnel should be familiar with Chapter 5, Nuclear Safety Design
Criteria, Chapter 7, Safety Program and Other Important Project Interfaces, and
Appendices A through D, which address safety design classifications for safety SSCs.
Appendices H and I, which are format and content guidance for the preparation of the
CSDR, PSDR, and PDSA, are important to the project team members charged with
the preparation of these documents and to the DOE reviewers of them.
Section 13
For projects that are potential major modifications of existing facilities, Chapter 8,
Additional Safety Integration Considerations for Projects, and Appendix J, Major
Modification Determination Examples are especially relevant.
1.3 Applicability
This Standard applies to the design and construction of the following:
• new DOE Hazard Category 1, 2, and 3 nuclear facilities;
• major modifications to DOE Hazard Category 1, 2, and 3 nuclear facilities (as
defined by 10 CFR 830); and
• other modifications to DOE Hazard Category 1, 2, and 3 nuclear facilities
managed under the requirements of DOE O 413.3A, Chg 1.
The activities and processes in this Standard may be applied to new facilities and to
modifications to those facilities not listed above.
DOE O 413.3A fundamentally establishes the roles, responsibilities, and requirements
for the Department in the DOE Acquisition Management System. The Contractor
Requirements Document (CRD) attached to that Order delineates requirements for
contractors in the Project Management System. The tasks, deliverables, and
suggested tools in this Standard are generally intended to be provisions primarily for
DOE contractors, unless they are specifically identified as DOE actions. DOE
responsibilities for review and approval of contractor submittals identified in this
Standard are discussed in Chapter 2. DOE-STD-1104-2008, Review and Approval of
Nuclear Facility Safety Basis and Safety Design Basis Documents, provides guidance
for the review of safety design basis documents.
For DOE projects subject to regulation by the Nuclear Regulatory Commission
(NRC), where requirements in this standard overlap or duplicate applicable NRC
requirements for nuclear safety (including quality assurance), the NRC requirements
apply to the design, construction, operation, and decommissioning of DOE facilities
and will be used to satisfy redundant or duplicative requirements from this standard.
This exclusion does not apply to requirements for which NRC defers to DOE or does
not exercise regulatory authority.
DOE-STD-1189-2008
Page 4
1.4 Must and Should
The verbs “must” and “should” are used throughout this Standard. If this Standard is
listed as a contract requirement, or otherwise directed by DOE for a facility or
project, the DOE contractor or other organization required to meet this Standard must
comply with all of the applicable provisions that include the word “must”. Provisions
that use the word “should” are not required, but they are recommended in order that
the expectations of this Standard can be implemented, particularly for complex or
hazardous activities.
The majority of “must” statements in this Standard are derived from DOE directives,
primarily DOE O 413.3A, Chg 1, DOE O 420.1B, and 10 CFR 830. That is, they
reflect required actions necessary to comply with one or more of these directives.
Where an activity is required by a DOE directive but is not directly involved with the
integration of safety with design, it is assumed to be carried out by the project and
may be indicated by “is” or “are” rather than a “must”.
In addition, this Standard includes “must” statements associated with the Key
Concepts and Guiding Principles that work together in enabling effective Safety-in-
Design. Their application is necessary for the effective integration of safety into a
project or facility design. The Guiding Principles of the Standard are derived from O
420.1B and O 413.3A, Chg 1. The Key Concepts include features introduced in this
Standard and are consistent with effective implementation of O 420.1B and O
413.3A, Chg 1, regarding integration of Safety-in-Design. Failure to apply one or
more of these principles or concepts to a new project or major modification design
results in an effort that cannot claim to have fully implemented this Standard.
Section 14
Requirements specific to this Standard are defined only for objectively measurable
parameters or conditions. Requirements are not defined when objective evidence of
compliance is not achievable. Requirements unique to this Standard include the
establishment of a Safety Design Strategy (SDS), which is in support of the tailoring
strategy and Project Execution Plan (PEP) required by DOE O 413.3A, Chg 1; the
Risk and Opportunities Assessment, which is in support of the Risk Management
Plan required by DOE O 413.3A, Chg 1; and Appendix A, which specifies new safety
design classification criteria. The remaining unique “must” statements are judged to
be necessary to comply with the Safety-in-Design processes described in this
Standard.
Specific elements of this Standard may appropriately be tailored to fit a specific
project and the SDS should establish the tailoring strategy. However, the Key
Concepts and Guiding Principles represent high-level expectations for Safety-in-
Design and are therefore applicable independent of tailoring.
1.5 Supplementary Guidance Documents
DOE M 413.3-1, Project Management for the Acquisition of Capital Assets, and any
guides developed in support of DOE O 413.3A, Chg 1, should be referred to and used
DOE-STD-1189-2008
Page 5
in conjunction with this Standard to enhance safety integration into project
management processes and decisions.
DOE-STD-1189-2008
Page 6
2.0 PROJECT INTEGRATION AND PLANNING
DOE O 413.3A , Chg 1, requires the formation of an Integrated Project Team (IPT), to be led
by a Federal Project Director. Subgroups to the IPT may be chartered during the project,
including a Contractor Integrated Project Team (CIPT) led by the Project Manager, as well as
subgroups to the IPTs for specific tasks or deliverables. Further information on the roles,
responsibilities, and functions of the IPT are provided in the Office of Engineering and
Construction Management (OECM) Project Management Practices, Integrated Project
Teams (see footnote 2).
The Federal Integrated Project Team (IPT) will comprise both DOE Federal staff and
contractors, and the contractor Project Manager will be a key member of the Federal IPT. If
a Contractor IPT is formed for certain complex or hazardous projects, interfaces between the
two IPTs must be established to ensure synchronization of information and reviews for all
disciplines and functions essential to the project. The interfaces and interactions necessary
for effectively integrating safety into project design are addressed in this Standard.
Contractor IPT activities and deliverables support the Federal IPT and project decisions that
are made by DOE.
Similar to the roles and functions of the Federal IPT, Safety-in-Design roles and functions for
each project should be specifically tailored for that project. The contractor should establish a
Safety Design Integration Team (SDIT), especially for complex or hazardous projects. The
SDIT would be the Safety-in-Design team support for the CIPT, if a CIPT is established, and
would also be the key Safety-in-Design interface with the Federal IPT. For small or less-
complex projects with a straightforward safety strategy, an SDIT may not be required, and
any contractor Safety-in-Design input would go directly to the CIPT or Federal IPT through
appropriate subject matter experts (SME). If an SDIT is formed, it should implement the
Safety Design Strategy (SDS). The SDS and SDIT are discussed in sections 2.2 and 2.3.
Section 15
DOE O 413.3A , Chg 1, requires the appointment of a Federal Project Director and formation
of an Integrated Project Team (IPT) during the conceptual design phase. Based on the
documentation required at CD-1, such as an acquisition strategy, Project Execution Plan
(PEP), a design review, and preparation of a Conceptual Safety Design Report (CSDR),
appointing a Federal Project Director and forming an IPT and the contractor SDIT should be
among the first orders of business as soon as mission need is approved (CD-0), if not before.
2.1 Contractor Integrated Project Team
A CIPT may be formally established for complex or hazardous projects, with the
Contractor Project Manager serving as the team leader.4 If established, the CIPT
4 It is recommended that a CIPT be considered for all Hazard Category 1 and 2 nuclear projects. If a
Federal IPT is collocated with the contractor project team and has an active direct and dedicated
management role for the project, a CIPT may not be warranted. The intent is to form a dedicated IPT,
ultimately reporting to and supporting the Federal Project Director that will have active day-to-day
roles and responsibilities on complex nuclear projects.
DOE-STD-1189-2008
Page 7
provides the overarching contractor focal point specifically charged with executing a
project through interactions with and support to the IPT and Federal Project Director.
As the team members are representative of all competencies that influence or affect
the execution of the project, the CIPT provides an important forum where project
issues can be openly discussed and resolved. As a project progresses from initiation
to transition/closeout completion, the CIPT membership may change to incorporate
the necessary skills and expertise. Although a core team is expected to provide direct
support to the project, team membership may be either full-time or part-time,
depending on the scope and complexity of the project.
The contractor safety lead should be a member of the CIPT and should be responsible
for representing all safety issues before the team and for ensuring that project issues
are appropriately shared with the SDIT.
2.2 Safety Design Integration Team
If established, the SDIT should include the key members of the contractor project
team who implement Safety-in-Design for the project. The SDIT is expected to be a
dynamic organization that will be made up of a limited core team comprising safety,
design, and operations personnel, as well as SMEs, who will come together for short
or extended periods of time to accomplish a task. Often these task-specific teams
may consist of the same people each time, but they will have a targeted responsibility
that requires their time and attention away from their normal activities. For example,
the SDIT will be quite active, and the membership will increase, while performing a
hazard analysis. As noted previously, the CIPT may fulfill the role of the core SDIT
for small projects or projects with a simple, straightforward safety strategy. Team
composition is critical for the SDIT to be successful. A multi-disciplinary team is
needed to identify and analyze the hazards in the facility and to ensure that the
designed controls:
• are adequate to perform the safety function;
• do not create an undue burden on operations;
• can be designed to fulfill the safety function; and
• fit within the project cost and schedule.
Section 16
The SDIT (or the project safety lead if there is no SDIT) is responsible for drafting a
SDS and also for preparing a Risk and Opportunity Assessment. The Risk and
Opportunity Assessment is input to the project’s Risk Management Plan and is
summarized in that document.
Although the appropriate team composition will depend on the process or unit
operation being developed, it should always include the core team and appropriate
supporting specialists. The core SDIT should consist of safety personnel (CIPT
safety lead), engineering and design personnel responsible for the process or facility,
operations personnel, and the line management of the design organization. In
DOE-STD-1189-2008
Page 8
addition to the core team, supporting specialists may be included as appropriate from
the following areas:
• security (depending on the project, security may need to be a core team
member);
• design, including appropriate disciplines (Civil, Structural, Electrical,
Instrumentation, etc.);
• geotechnical/seismic;
• health physics and radiological protection (shielding, uptakes, or exposure to
hazardous materials, etc.);
• safety, accident, or risk analysts with expertise needed by the team;
• criticality safety;
• research and development (process, equipment development specialists);
• process chemistry;
• industrial safety (Occupational Safety and Health Administration [OSHA]
issues);
• fire protection;
• emergency preparedness;
• environmental protection and waste management;
• human factors; and
• interfacing system representatives.
The presence of specialists will vary according to the process or unit operation that
will be designed or analyzed and with the phase of the project.
Communication within the CIPT and the SDIT is paramount to understanding the
major issues and ensuring that the solutions put forward as design or planned
operations are appropriate and fully meet the needs of design, construction, project
constraints, facility operations, and safety. Timely and effective interactions between
the CIPT and the Federal IPT are crucial for mission success.
2.3 Safety Design Strategy
A Safety Design Strategy (SDS) must be developed for all projects subject to this
Standard. DOE expectations for execution of safety activities during design should
be identified and documented to support the development of the statement of mission
need. The documentation of the DOE expectations for execution of safety during
design is developed by the DOE safety lead and should define high-level DOE
expectations. The SDS should then be based on those DOE expectations and should
be developed as early in the Conceptual Design Phase as practicable. These DOE
DOE-STD-1189-2008
Page 9
expectations are used during the development of the project SDS in the conceptual
design stage. The SDS is updated throughout the design process.
As the initial project safety management integration tool, the SDS provides the
preliminary information to gauge the scope of significant hazards and the general
strategy for addressing those hazards. The SDS is a tool to guide design, document
the safety analysis approach, support the safety design basis documents to be
developed during each project phase, and establish concurrence on major safety
decisions related to project cost and schedule. It provides a single source for project
safety policies, philosophies, major safety requirements, and safety goals to maintain
alignment of safety with the design basis during project evolution.
Section 17
The SDS should contain enough detail to guide design on overarching design criteria,
establish major safety SSCs, and identify significant project risks associated with the
proposed facility relative to safety. Specifically, the SDS should address the
following four main attributes of safety integration as the project progresses through
project planning and execution:
• The guiding philosophies or assumptions to be used to develop the design,
• The Safety-in-Design and safety goal considerations for the project,
• The approach to developing the overall safety design basis for the project, and
• Significant discipline interfaces impacting safety.
For projects that may not follow the traditional project cycle, the SDS provides a
vehicle to describe how requirements for safety documentation will be tailored to that
particular project approach while satisfying DOE O 413.3A, Chg 1.
For certain projects, safety assumptions and criteria may be known when DOE
approves the mission need at CD-0 (e.g., the facility will be a Hazard Category 2
nuclear facility). These assumptions and criteria should be in the SDS and should be
used for developing the conceptual design and CSDR.
The SDS is not intended to supplant or duplicate the required safety deliverables to or
include information that should be contained in other project documentation (e.g.,
schedules, resource requirements).
The SDS, at the conceptual design phase, is prepared by the SDIT (or the contractor
safety lead in the absence of an SDIT) as an evolution of the DOE expectation for the
execution of safety activities during design. It is approved by DOE Safety Basis
Approval Authority and the Federal Project Director, with the advice of the Chief of
Nuclear Safety (CNS) or the Chief of Defense Nuclear Safety (CDNS), as
appropriate.
Updates to the SDS should focus on those major safety decisions that influence
project cost (e.g., seismic design criteria, confinement ventilation, safety functional
classification, and strategy). Interim SDS updates can provide a means by which all
DOE-STD-1189-2008
Page 10
parties are kept informed of important changes due to safety in design evolution
between Critical Decision points.
This Standard anticipates that the eventual safety basis for the facility being
constructed or modified will be based on the format and content of DOE-STD-3009-
94, CN 3. If a different methodology is applicable to the project or modification (e.g.
legacy facilities or departmental decontamination and decommissioning activities),
the SDS should establish that expectation, and the format of the PSDR/PDSA as
provided in this Standard should be modified as appropriate. However, the
expectations for integration of safety into the design process and application of
nuclear safety design criteria apply to all projects and modifications within the scope
of this Standard.
The safety documentation for a major modification project must include an SDS and
a PDSA. Modification projects that require a new or revised hazards/accident
analysis or require new hazard controls must be evaluated using the Major
Modification Evaluation Criteria to determine if the modification constitutes a “major
modification” and requires a PDSA (see Table 8.1). This evaluation must be
documented in the PEP, the SDS itself, or in another appropriate project authorization
document.
Section 18
Modification projects that do not involve a “substantial change to the safety basis” to
an existing nuclear facility as defined in 10 CFR 830 are not considered “major
modifications” and do not require a CSDR, PSDR or a PDSA. For modifications
subject to DOE O 413.3A, Chg 1, the SDS should document the type and scope of the
hazard/accident analysis, describe the supporting safety documentation and DSA
amendment or revision to be prepared, and should explain the process to develop and
review and approve these documents (see Section 2.4.4, “Tailoring of
Requirements”). These modifications may represent a capital asset project other than
a major modification that is subject to the acquisition processes in DOE O 413.3A,
Chg 1. This Standard and the included Safety-in-Design approaches may be tailored
for these modifications. As previously mentioned, in such cases the basis for
determining that the modification is not a major modification must be documented.
Guidance for determining whether a facility modification involves a “substantial
change to the facility safety basis” and is considered to be a “major modification”
under the requirements of 10 CFR 830, is provided in detail in Section 8.1.
Modifications not requiring a new or revised hazard analysis/accident analysis and
not requiring new hazard controls are considered simple modifications. These
modifications need not be subject to the safety integration provisions of this Standard.
The SDS is discussed in detail in Appendix E and the SDS role in each project phase
is discussed in Chapter 3 of this Standard, along with the Safety-in-Design activities
for that phase. Section 6.4 addresses the change control process that is applicable to
safety documentation.
DOE-STD-1189-2008
Page 11
2.4 Safety Interface with Project Management
2.4.1 Relationship to Project Management
DOE O 413.3A, Chg 1, governs the execution of most DOE capital asset
acquisition projects. The integration of the safety design development and
approval processes into the execution cycle for DOE Hazard Category 1, 2,
and 3 nuclear facilities is the focus of this Standard. This section defines how
the project management requirements in DOE O 413.3A, Chg 1, relate to this
Standard.
Many projects are executed as “design-bid-build” projects with defined
conceptual, preliminary, and final design phases. This is the underlying
acquisition model presumed in this Standard. However, many projects are
executed using different acquisition models and strategies. Accordingly, it is
incumbent upon the Federal Project Director and the IPT to examine the
provisions in this Standard and apply its processes and guidance appropriately
to the project. This appropriate application of the processes, guidance, and
methodologies in this Standard to the relevant phases of a project is known as
“tailoring”. However, the project management requirements of DOE O
413.3A, Chg 1, will govern the timing and substance of critical DOE project
decisions.
In accordance with DOE O 413.3A, Chg 1, contractors responsible for the
design of DOE Hazard Category 1, 2, and 3 nuclear facilities must implement
this Standard, including the safety criteria of Appendix A, and submit the
following safety basis documents for DOE approval (unless otherwise agreed
to).
• Conceptual Design Stage: Safety Design Strategy
• Conceptual Design Stage: Conceptual Safety Design Report (CSDR)
• Preliminary Design Stage: Preliminary Safety Design Report (PSDR)
Section 19
• Final Design Stage: Preliminary Documented Safety Analysis (PDSA)
• Prior to Operations: Documented Safety Analysis and Technical
Safety Requirements
The Federal Project Director is responsible for ensuring the implementation of
the requirements of DOE O 413.3A, Chg 1, and does this through contract
requirements and through support of DOE entities. As such, the Federal
Project Director approves or concurs on the approval of all safety submittals
of the project. The DOE Safety Basis Approval Authority approves of the
CSDR, PDSR, and PDSA based on a review by a Safety Basis Review Team.
Table 2-1 shows the entities responsible for preparation, review, and approval
of these safety documents.
DOE-STD-1189-2008
Page 12
Table 2-1. Roles and Responsibilities
Responsibility Product/
Document
Prepare Review Approve
Interface with Other
Documents/Products
Safety Design
Strategy (SDS)
Contractor SDIT or, in the absence of
an SDIT, the contractor safety lead is
responsible for the preparation of the
SDS as early in the Conceptual Design
phase as practicable. The SDS is
updated, as necessary, throughout the
design stages.
DOE Safety Basis Review
Team and the Integrated
Project Team
Federal Project Director and the
Safety Basis Approval
Authority.
Pre-conceptual planning
activities will provide the
starting point. The SDS is
part of or can be referenced
from the tailoring strategy
part of Project Execution
Plan.
Risk &
Opportunity
Assessment
Contractor SDIT or, in the absence of
an SDIT, the contractor safety lead
prepares the Risk and Opportunity
Assessment. It is updated, as
appropriate, throughout the design
stages.
Federal Integrated Project
Team and the DOE Safety
Basis Review Team
Federal Project Director The Risk and Opportunities
Assessment is input to the
Risk Management Plan. It
is summarized in the Risk
Management Plan.
Conceptual
Safety Design
Report (CSDR)
Contractor SDIT or, in the absence of
an SDIT, the contractor safety lead is
responsible for the preparation of the
CSDR.
DOE Safety Basis Review
Team and the Integrated
Project Team
Approval is via approval of the
CSVR.
The CSDR needs to be
consistent with the
Conceptual Design Report
(CDR).
Conceptual
Safety Validation
Report (CSVR)
DOE Safety Basis Review Team.
DOE-STD-1104 provides guidance for
review of the CSDR and preparation of
the CSVR.
Federal Integrated Project
Team
Safety Basis Approval Authority
approves with concurrence by
the Federal Project Director
The CSVR results from the
DOE review of the CSDR.
It documents the findings
of that review and is a
prerequisite to Critical
Decision-1 (CD-1).
DOE-STD-1189-2008
Page 13
Responsibility Product/
Document
Prepare Review Approve
Interface with Other
Documents/Products
Preliminary
Safety Design
Report (PSDR)
Contractor SDIT or, in the absence of
an SDIT, the contractor safety lead is
responsible for the preparation of the
PSDR
DOE Safety Basis Review
Team and the Integrated
Project Team
Approval is via approval of the
PSVR.
The PSDR needs to be
consistent with the
Preliminary Design, as
documented for the
Preliminary Design
Review.
Preliminary
Safety Validation
Report (PSVR)
DOE Safety Basis Review Team.
DOE-STD-1104 provides guidance for
review of the PSDR and preparation of
the PSVR.
Federal Integrated Project
Team
Safety Basis Approval Authority
approves with concurrence by
the Federal Project Director
The PSVR results from the
DOE review of the PSDR.
It documents the findings
of that review and is a
prerequisite to Critical
Decision-2 (CD-2).
Section 20
Preliminary
Documented
Safety Analysis
(PDSA)
Contractor SDIT or, in the absence of
an SDIT, the contractor safety lead is
responsible for the preparation of the
PDSA.
DOE Safety Basis Review
Team and the Integrated
Project Team
Approval is via approval of the
SER
The PDSA needs to be
consistent with the Final
Design that is presented as
part of the Critical
Decision-3 (CD-3).
Safety
Evaluation
Report (SER)
DOE Safety Basis Review Team.
DOE-STD-1104 provides guidance for
review of the PDSA and preparation of
the SER.
Federal Integrated Project
Team
Safety Basis Approval Authority
approves with concurrence by
the Federal Project Director
The SER results from the
DOE review of the PDSA.
It documents the findings
of that review and is a
prerequisite to Critical
Decision-3 (CD-3).
Documented
Safety Analysis
(DSA) and
Technical Safety
Requirements
(TSR)
Contractor SDIT or, in the absence of
an SDIT, the contractor safety lead,
augmented by an operations team are
responsible for the preparation of the
operational DSA and TSR.
DOE Safety Basis Review
Team and the Integrated
Project Team
Approval is via approval of the
SER
The DSA is an evolution of
the PDSA. Any changes
need to be identified and
justified. The TSR is
developed, based on the
DSA.
DOE-STD-1189-2008
Page 14
Responsibility Product/
Document
Prepare Review Approve
Interface with Other
Documents/Products
Safety
Evaluation
Report
DOE Safety Basis Review Team.
DOE-STD-1104 provides guidance for
review of the DSA and TSR and
preparation of the SER.
Safety Basis Approval Authority The SER results from the
DOE review of the
operational DSA and TSR.
It documents the findings
of that review and is a
prerequisite to Critical
Decision-4 (CD-4).
DOE-STD-1189-2008
Page 15
2.4.2 General Expectations
This Standard focuses on establishing the safety design for a nuclear facility in
an incrementally progressive way to provide some assurance that the safety
design basis will be demonstrated to be acceptable when the design is
completed. Accordingly, early project decisions on the technical approach
should be reasonably conservative in establishing appropriate cost and
schedule baselines for the project. The project is expected to evolve over
time; the project design and safety design basis are also expected to evolve.
The expectation is that within this evolution process, unanticipated issues will
be minimized.
To ensure that the project/facility configuration can be managed appropriately,
the basis for decisions related to safety must be clearly documented. This
includes, for example, controls selection, material-at-risk (MAR), process
options, inputs, and assumptions. This documentation allows later decisions
to modify the design or safety design basis based on knowledge of the original
decision and not just on the current understanding of the issue.
The overarching philosophy and logic in this Standard is that a heightened
degree of conservatism is demanded in the earlier phases of a project when the
design details are not available. In this vein, a broader or more conservative
set of SSCs that would be designated as safety systems might be provisionally
selected for conceptual design than might actually be required when the
design is completed. The degree of conservatism can be relaxed, and,
accordingly, the provisional set of SSCs may be refined when justified by
evolving information as design progresses. This strategy should minimize the
need for significant safety and major cost revisions to the project in later
design cycles.
Section 21
2.4.3 Planning
The project management practices required by DOE O 413.3A, Chg 1,
emphasize appropriate planning for the execution of projects. The
development and approval of the safety design is an essential element of the
project execution cycle and warrants appropriate planning. The overall
planning for project execution, of which safety is an integral part, is
documented and approved in the PEP. To the extent desired by the IPT, and
as specified in the project’s tailoring documentation, the SDS and other safety
planning documentation may be included within the PEP, or be included in
other required project management or safety documentation as described is
subsection 2.4.4 below.
DOE-STD-1189-2008
Page 16
2.4.4 Tailoring of Requirements
DOE O 413.3A, Chg 1, allows tailoring of the CD process for projects based
on “risk, size, and complexity.” The tailoring approach for the CD process is
typically described in a “tailoring strategy” or as part of the PEP. Tailoring of
the safety design basis development steps and documents for a project is also
permitted based on the level of risk posed by the facility chemical and
radiological hazards, the complexity of the processing operations, and the
scope of the hazards analysis required for the project. Tailoring of the safety
design basis steps and documents is described in Section 2.3. The tailoring
approach for safety design basis documents must be:
• described in the SDS; and
• summarized in the PEP.
DOE O 413.3A, Chg 1, specifies what safety documentation is required as
prerequisites to obtaining specified CDs. This Standard provides guidance on
the format and content of the safety documentation. As established in the
tailoring strategy for the project, the information and approvals for
documentation, as required by this Standard, can be sequenced, organized, and
bundled as the project team desires to meet the safety performance measures
in this Standard. For example, this option allows the project team to satisfy
requirements often associated with separate documents or documents that are
produced sequentially to be delivered in a manner that is effective and
efficient for project team decisions. This Standard does not specify how a
project would be phased or how the project supports its CDs. Instead, it
specifies the safety expectations for a project during the project’s execution
cycle. The mapping of when CDs are sought, what information requirements
pertain to the CDs, and how the project will be executed will be specified in
the tailoring strategy or, if desired, in the PEP. Should a significant change in
the safety strategy occur, such changes may be documented by a revision to
the SDS. Neither the PEP nor the applicable approved safety document (e.g.,
CSDR) need be revised to address the change. The safety documentation can
be updated at the next CD safety document submittal (e.g., PSDR for the
CSDR example above).
2.4.5 Safety Interface Requirements
The following are the requirements for the safety interface.
• In the process of selecting early, design-phase safety SSCs using
reasonably conservative principles, it is recognized that project and
design progression might cause the SSC designation to evolve.
Significant impacts on the cost and schedule for potential changes in
SSC designation are captured in the evolving cost and schedule
baseline projections for the project, either explicitly (as part of
projections for the evolving baseline design) or as an explicit
Section 22
DOE-STD-1189-2008
Page 17
contingency on those projections, if they are not included in the
baseline design.
• The methods and criteria by which SSCs are designated (either safety
class, safety significant, or defense-in-depth) during project phases
must be justified and documented.
• The IPT must include applicable expertise to advise the Federal
Project Director on matters relating to nuclear safety. DOE O 413.3A,
Chg 1, requires the Chief, Defense Nuclear Safety (CDNS) and the
Chief of Nuclear Safety (CNS) to validate that Federal personnel
assigned to the Integrated Project Team as nuclear safety experts are
appropriately qualified.
DOE-STD-1189-2008
Page 18
3.0 SAFETY CONSIDERATIONS FOR THE DESIGN PROCESS
This chapter discusses general concepts for fostering integration of safety considerations into
design activities (Safety-in-Design) during the pre-conceptual, conceptual, preliminary, and
final design stages.
As a project design progresses, the design organization determines the appropriate safety
features to be incorporated into a project, and obtains concurrence by the Integrated Project
Team (IPT). The design organization and IPT should identify and reach agreement on these
features as early in the process as it is possible and practical to do so. The goal is to make
decisions at as early a point as possible, recognizing that as design progresses, these
decisions may need to be revisited. In particular, it is important that the design decisions be
transparent and visible to all stakeholders and that any related issues regarding them are
recognized and included in the Risk Management Plan (RMP), as discussed in Appendix F.
The design process for a complex facility is highly interactive and iterative. Therefore,
coordination and communication among the activities and the individuals performing them is
vital to the overall success of these activities. Because the design is evolving as the hazards
and safety analyses are performed, it is essential that the IPT and Safety Design Integration
Team (SDIT) are aware of the current state of the design at all times and that design staff are
current on the status of the hazards/safety analyses work. Mechanisms must be established to
ensure these communications.
Failure to incorporate safety considerations early in the design process can result in
prohibitively expensive changes later in the design process if they are recognized only at the
Preliminary Documented Safety Analysis (PDSA) development stage (i.e., during final
design). To document safety design features early in the design process, DOE O 413.3A,
Chg 1, prescribes reports at both the conceptual design phase (Conceptual Safety Design
Report or CSDR), and the preliminary design phase (Preliminary Safety Design Report or
PSDR), in addition to the required PDSA before the start of construction. The content and
detail of these reports should be tailored to the safety information and maturity of the design
as appropriate for the specific project.
This chapter discusses the Safety-in-Design considerations and activities to be performed
during the initiation (pre-conceptual planning), conceptual design, preliminary design, and
final design phases. The chapter also depicts the typical flow and interrelationships among
project management, design development, and safety design basis development activities for
these four phases. The design process for a specific project may vary considerably,
commensurate with the tailoring of a project. The tailored design process is identified in the
Project Execution Plan (PEP), which also evolves with the project activities. The Safety
Design Strategy (see Section 2.3 and Appendix E) is developed consistent with, and works in
conjunction with, the PEP and guides project design and safety documentation development.
Section 23
The four figures in this Chapter graphically portray the processes supporting each of the
primary design phases of a typical project. These processes are associated with one or more
of the marked divisions that represent Program and Project Management, Project
Engineering, or Safety Design Basis activities. Within each marked division, activities may
be shown as grouped together within a dashed box. These activities are so closely associated
DOE-STD-1189-2008
Page 19
that they are elements of a larger effort. In turn, these boxes may be shown joined with
double-headed arrows, representing the integration needed to support the individual efforts
and the fact that these activities may iterate. In reality, there is no two-dimensional depiction
of these processes that is complete and yet effective in illustrating all of the relationships
involved.
3.1. Pre-Conceptual Phase
During the pre-conceptual phase, the program identifies any gap between its current
and required capabilities and compares the gap to the strategic plan. This gap
analysis is translated into a Mission Needs Statement, which serves as the vehicle for
formally establishing a project to close the identified performance gap.
Safety-in-Design efforts must begin during the pre-conceptual phase of a potential
design and construction project when initial planning activities occur. The project
team must consider the Safety Design Guiding Principles and key concepts of this
Standard in the development of the project requirements to support the Mission Needs
package. To ensure these principles are incorporated at this phase, a safety lead
should be designated as early as practical as a key member to be assigned to the IPT
when it is formed. The safety lead will be responsible for providing safety input to
guide early project planning consistent with the Guiding Principles and key concepts.
DOE expectations for execution of safety activities during design should be clearly
communicated commensurate with the hazard and control selection information
available at this early stage in the potential project. Safety-in-Design goals should be
identified; expectations for adherence to the design requirements of DOE O 420.1B,
and any special safety requirements or expectations (e.g., active confinement) for the
project should be included. These DOE Expectations for Safety-in-Design efforts
should be formally documented.
An initial alternative analysis is performed during the pre-conceptual planning phase
to determine if a new facility or a modification to an existing facility would best
satisfy the mission need. The analyst needs to have some understanding of the
process technology that could be used for the facility to perform this analysis. In
some cases, separate alternative analyses may be required to select the best process
technology to achieve the facility mission. The material inputs and outputs, together
with the process technology options, must be identified to provide the minimum
amount of information needed for an initial assessment of the hazards posed by each
proposed process. Detailed alternatives analyses will be completed later during the
conceptual design phase.
Upper-level facility functions and performance requirements may also be developed
in this phase. The physical form and quantities of the nuclear materials to be
generated and received, and the waste materials to be produced, should be identified.
This is important to ensure that the initial material release analyses can provide
meaningful information. Generally, a simple process model that shows the material
inputs and outputs will satisfy this purpose.
Section 24
DOE-STD-1189-2008
Page 20
The hazard analysis at the pre-conceptual phase involves a qualitative high-level
consideration of the facility/process risks performed in conjunction with the facility
and initial technology selection alternative reviews. See Section 4.1 for guidance on
hazard analysis for this phase of the project.
Figure 3-1 illustrates the interactions of project management and safety design basis
development activities during the pre-conceptual design phase.
DOE-STD-1189-2008
Page 21
Figure 3-1. Pre-Conceptual Phase
P
ro
je
ct
E
ng
in
ee
rin
g
P
ro
gr
am
a
nd
P
ro
je
ct
M
an
ag
em
en
t
S
af
et
y
D
es
ig
n
B
as
is
DOE-STD-1189-2008
Page 22
3.2 Conceptual Design Phase
The overall goal for Safety-in-Design at the conceptual design phase is to evaluate
alternative design concepts, to prepare a Safety Design Strategy (SDS), and to
provide a conservative safety design basis for a preferred concept to proceed into
preliminary design. The intent is to perform sufficient analyses to make sound safety
decisions during conceptual design and to document any risks and opportunities
associated with selections and the associated project cost range and schedule impacts.
A Quality Assurance Program (QAP), compliant with 10 CFR 830, Subpart A, and
DOE O 414.1C is established early in the project. The QAP describes the planned
quality-related activities, surveillances, and assessments and is developed in the
project conceptual phase and updated as the project matures. Section 8.9 of this
Standard addresses the QAP in more detail.
The conceptual design phase presents a key opportunity for the safety analysis to
influence the design. Figure 3-2 illustrates the interactions of project management,
design development, and safety design basis development activities during the
conceptual design phase. As can be seen in the figure, there are many activities that
rely upon each other and that, in some cases, are iterative.
DOE-STD-1189-2008
Page 23
Figure 3-2. Conceptual Design Phase
DOE-STD-1189-2008
Page 24
The earlier in the project life cycle that requirements are identified and defined, the
more effectively and efficiently the project will progress through the various phases
and will meet project baselines, agreements, and commitments. As a project
progresses from identification of the mission need through concept exploration,
development, and design, the process of identifying, analyzing, and refining
requirements is continual and is always ultimately traceable to specifications and
designs. Once approved, the requirements document becomes part of the baseline
requirements and is to be controlled through the change control process described in
the PEP.
When design requirements are established, alternatives are evaluated to establish a
process approach, and facility and equipment arrangements are determined. The
configuration alternatives are evaluated against technical, safety, cost, and schedule
criteria.
As design requirements are established for each alternative, engineering and safety
personnel will begin to identify alternative facility layout and processing
configurations. The DOE Expectations for Safety-in-Design and the Safety Design
Guiding Principles and key concepts (see the Preface of this Standard) must be
applied to these efforts to ensure that the design requirements and the selection of the
preferred processing and facility arrangement alternatives are performed in a way that
will result in a safe design. To ensure optimum Safety-in-Design considerations, a
safety analyst must be involved as part of the evaluation of the processes for each of
the various alternatives.
Section 25
The SDS, at the conceptual design phase, is prepared by the SDIT (or the project
safety lead in the absence of an SDIT) based on the DOE Expectations for Safety-in-
Design. It is approved by DOE Safety Basis Approval Authority and the Federal
Project Director, with the advice of the Chief of Nuclear Safety (CNS) or the Chief of
Defense Nuclear Safety (CDNS), as appropriate.
As the processing approach and facility arrangements are being developed,
alternatives are evaluated to select the design architecture; that is, the structures,
systems and components (SSC). During the alternative analysis process, the IPT and
SDIT ensure that the relative hazards, as well as the costs and uncertainties associated
with the hazard controls that may be required to address these hazards, are considered
for each alternative. The IPT and SDIT should also consider alternative facility
locations that minimize the exposure of the public and collocated workers to facility
releases or that minimize the threat of external events associated with nearby
facilities.
Due to the need to develop an integrated process which assures that both the security
and safety requirements are met, it is important to specify physical security needs
early in the conceptual design process. This allows security and safety professionals
to identify and resolve any potential conflicts and/or identify risks that will be
incorporated into the risk and opportunities assessment. Recommendations from the
initial security Vulnerability Assessment should be identified, including the need for
new technologies, or incorporation of new technologies, and factored into the
DOE-STD-1189-2008
Page 25
preliminary hazards analysis. To aid in this integration, the strategy for security
design should be documented and incorporated, as appropriate, into the SDS.
Once the alternatives have been evaluated and a selected alternative designated, the
design and safety work to identify and describe the SSCs to satisfy the facility
performance requirements and to perform the facility processing operations is
initiated. Safety design requirements and considerations in DOE O 420.1B, must be
addressed in the developing design. To the extent that the design maturity will
support in this conceptual phase, the Conceptual Safety Design Report (CSDR)
includes a listing of applicable 420.1B design criteria and a brief summary of the
implementation approach proposed for each applicable criterion. See Chapter 5 of
this standard for further guidance on nuclear design criteria and Appendix H for
documentation in the CSDR.
The SDIT should formally recognize this point in the conceptual design phase as a
point where refocusing of efforts from alternatives comparisons and selection to the
goal of producing a conceptual design that integrates safety into the design is needed.
The focus of safety work at this point in conceptual design is to (1) document and
establish a preliminary inventory of hazardous materials; (2) document and establish
the preliminary hazard categorization of the facility; (3) identify and analyze primary
facility hazards and facility-level design basis accidents; and (4) provide an initial
determination, based on the PHA, of safety class and safety significant SSCs. See
Section 4.2 of this standard for guidance on hazard analysis for this project phase.
Section 26
As a result of the requirements analysis and the alternatives analyses, a general
process block-flow diagram or description of the process operations based on the
selected technology and a general description of the more significant hazard controls
should be developed for the project.
A Safety-in-Design Risk and Opportunity Assessment for the conceptual design is
used to evaluate the overall safety design basis risks and opportunities associated with
the project. The risks include the uncertainties related to the possibility that there
may be additional costs and schedule impacts that are not yet identified because the
design is still immature or there are uncertainties associated with the viability of the
design and programmatic strategies selected. Opportunities refer to the potential
opportunities to reduce the costs or improve the schedules as the design matures and
to select proposed hazard controls or other cost and schedule drivers that are
identified as not being necessary after all.
The Risks and Opportunities Assessment associated with the safety strategies that are
selected is essential to a robust assessment for the project. Appendix F provides
information to ensure a complete Risk and Opportunities Assessment is performed for
the project.
In the conceptual design phase, the studies that still need to be completed to verify
key safety strategy assumptions, make technology selections, or better understand the
process operations or safety implications must be identified and should be
documented in the SDS, CSDR, and CDR. Corresponding risks associated with
DOE-STD-1189-2008
Page 26
possible outcomes of the studies identified should be included in the Safety-in-Design
Risk and Opportunity Assessment.
The following major safety activities take place during the conceptual design phase.
• The requirements analysis from the pre-conceptual phase is further developed
to include safety functions and SSC requirements and is documented in the
project technical requirements documents and in the CDR.
• Alternative design concepts are analyzed and a preferred alternative is
selected.
• An SDS is developed to guide design including description of strategies to
address major hazards, commitment to appropriate safety design criteria and
security issues as applicable.
• A Preliminary Hazards Analysis (PHA) is performed to provide the basis for
facility preliminary hazard categorization. (Appendix G provides guidance on
the information requirements for the PHA.)
• A preliminary Fire Hazards Analysis is performed that identifies and assesses
fire risk and defines levels of Safety-in-Design that do not necessarily come
from the PHA.
• A preliminary security Vulnerability Assessment is completed and factored
into the PHA.
• A facility-level DBA Analysis is performed to identify the major facility
safety functions needed.
• SSCs and their safety classifications are proposed for the major safety
functions. (Appendices A, B, C, and D provide guidance on safety
classifications.)
• The initial Safety-in-Design Risk and Opportunities Assessment is developed
based on assumptions that may have been necessary and on uncertainties in
safety and design considerations. (This assessment is input to the project Risk
Management Plan and assessment.)
• The CDR is developed to document the final conceptual design architecture.
• The CSDR is developed to document the bases for the safety design aspects of
the facility. (Appendix H provides guidance on the development and format
and content of a CSDR.)
Section 27
• Required technical studies necessary to resolve risks and opportunities are
identified.
• The initial baseline range estimates are identified.
• DOE reviews the CSDR and prepares a Conceptual Safety Validation Report
(CSVR).
DOE-STD-1189-2008
Page 27
3.3 Preliminary Design Phase
Safety-in-design efforts during the preliminary design phase are intended to be
incremental rather than a complete reevaluation of the conceptual design. The hazard
analysis (HA) will evolve from a facility-level analysis to a system level hazard
analysis as design detail becomes available. As the HA is refined, the selection of
controls, safety functions, and classifications developed during the conceptual design
phase must be revisited to ensure they are still appropriate.
Decisions made during the preliminary design phase provide the basis for the
approach to detailed design and construction. Decisions that are reversed after this
phase, for whatever reason, can have significant impacts on overall project cost and
schedule. It is essential that contractor and DOE safety personnel are totally engaged
and fully participate in design reviews during this phase, so their views and advice
can be considered in the evolving design in a timely fashion.
Figure 3-3 depicts the workflow for the preliminary design phase.
DOE-STD-1189-2008
Page 28
Figure 3-3. Preliminary Design Phase
DOE-STD-1189-2008
Page 29
The project technical design requirements for the preliminary design phase include
initial technical requirements for the project and embody many of the deliverables
indicated in DOE O 413.3A, Chg 1, for the preliminary design phase, including the
design requirements document(s) containing the information available at this phase
These technical requirements include those derived from the safety analysis.
Because the design is still evolving at this point in the process, adequate Safety-in-
Design for the preliminary design phase is based primarily on identifying viable
engineering resolutions to nuclear safety design requirements and specifying an
adequate set of more detailed safety design requirements that are based on safety
analyses. During this phase a more complete assessment of hazard controls, based on
hazards analyses at the process level, is developed, including those intended for in-
facility worker protection. Section 4.3 of this Standard provides an expanded
discussion of hazards analysis, hazard control selection, and safety classification of
these controls.
The security Vulnerability Assessment should be updated based upon the developing
design of the facility proposed security features. During this phase, security strategies
may be refined, security system performance requirements are defined, and other
infrastructure requirements are identified. Physical, information, personnel, and
cyber security are all considered in the analysis.
The approach for demonstrating how the preliminary design will satisfy the nuclear
safety design criteria of DOE O 420.1B or proposed alternative criteria must be
developed during this phase if it was not done earlier. Because the design is still
evolving at this point in the process, adequate Safety-in-Design for the preliminary
design phase is based primarily on identifying viable engineering resolutions to
nuclear safety design requirements and specifying an adequate set of more detailed
safety design requirements that are based on safety analyses. Chapter 5 of this
Standard provides guidance on the nuclear safety design criteria of DOE O 420.1B
and Appendix I for documentation in the PSDR.
Section 28
The Safety-in-Design Risk and Opportunity Assessment developed in the conceptual
design phase must be updated during the preliminary design phase to reflect the
results of any technical studies, design modifications, or other developmental work
that impact the risk assessment. The results must be documented in the Risk
Management Plan to provide information for the development of the project baseline
cost, as described in DOE O 413.3A and its guidance.
Additional information regarding the aspects to be considered in the Safety-in-Design
Risk and Opportunity Assessment is provided in Appendix F, “Safety-in-Design
Relationship with the Risk Management Plan”.
Any remaining studies that need to be performed to address specific details in the
facility final design must be delineated in the preliminary design phase. These studies
may include assumption validation studies, any remaining equipment selection studies
(e.g., trade studies), and design optimization studies. Studies that could affect the
safety design basis developed for the preliminary design should be highlighted in the
safety strategy section of the PDR and in the PSDR. Corresponding risks associated
DOE-STD-1189-2008
Page 30
with possible outcomes of the studies identified are included in the updated Risk and
Opportunity Assessment.
Safety-in-Design documentation also evolves during the preliminary design phase as
follows:
• PHA is revised and updated to an HA (see Chapter 4 and Appendix G);
• FHA is updated;
• The security Vulnerability Assessment is updated;
• PDSR is developed, building on the information in the CSDR (see Chapter 6);
• SDS is updated to reflect the evolution in the design and safety design bases
(see Chapter 2 and Appendix E;
• Safety-in-design Risk and Opportunity Assessment is updated and should
reflect changes that were made to take advantage of opportunities or address
identified risks (see Appendix F); and
• By the end of design, the final National Environmental Policy Act (NEPA)
documentation is completed to support the selected site.
3.4 Final Design Phase
During this phase, details for procurement in support of construction activities are
developed. Typically, about 30 to 40 percent of the design activity is completed
during the preliminary design phase, and the remainder of the design is completed
during the final design phase.
By the final design phase, both the preliminary design and the PSDR will have been
reviewed and approved. These reviews may prompt changes to the conclusions and
approaches taken for safety and design in the preliminary phase. Similarly, evolution
of the design from preliminary to final may prompt the design approaches and
commitments captured in the PSDR to be revised based on improved knowledge and
process optimization.
The security Vulnerability Assessment should be updated based upon the final design
of the facility proposed security features. During this phase, security strategies,
security system performance requirements, and other infrastructure requirements are
finalized.
During this phase a final set of hazard controls is developed, based on hazards and
accident analysis of the final design. The safety analyses in the final design phase,
including mitigated analyses, must encompass the scope of the design and
demonstrate that the designated safety SSCs are adequately designed to reliably
perform their intended safety functions. Appendix G provides guidance on
documenting the hazard analysis results.
Section 29
The design adequacy of safety SSCs must be demonstrated. This is fundamental to
the integration of Safety-in-Design activities. The burden of proof is on the design
DOE-STD-1189-2008
Page 31
organization to demonstrate that the design and functional requirements derived from
the safety analysis process are satisfied. The designed SSC should be evaluated to
validate they can provide the desired safety function from the safety analysis, that
they can be implemented, and are cost effective. Section 4.4 of this Standard
provides an expanded discussion of hazards analysis, hazard control selection, and
safety classification of these controls.
The PDSA addresses the broad range of issues necessary to demonstrate compliance
with DOE O 420.1B and its guides; specifically, DOE G 420.1-1, -2, and -3, where
applicable. Many of the design criteria are qualitative in nature and require an
analysis to show how they are applied to a particular SSC. System and component
design must satisfy national codes and standards (code[s] of record where applicable)
identified in DOE G 420.1-1. Compliance with the requirements of these standards
will be reviewed during acceptance of the safety documentation and during readiness
activities in support of the CD-4 milestone. Appendix I discusses how the PDSA
evolves from the PSDR. Both documents have the same format to simplify the
evolution process.
The Safety-in-Design Risk and Opportunity Assessment from the preliminary design
phase must be updated to reflect the results of any technical studies, design
modifications, or other developmental work that affects the risk assessment. The Risk
Management Plan is updated as necessary.
Design reviews at the final design phase should ensure that the safety analysis is
current with respect to the design. The configuration management process at the final
design stage should be well defined and able to track changes to the design and
initiate conforming changes to analyses and documentation as changes are made.
Section 6.4 of this Standard discusses expectations with respect to configuration
management.
In addition, Section 3.9 of DOE-STD-1073, Configuration Management, provides
guidance on turnover of configuration management from design to construction. As
stated, these efforts should be begun well before turnover to ensure a smooth
transition.
The following safety activities are typically performed during the final design phase:
• update SDS as necessary;
• update hazard and accident analysis;
• update the security Vulnerability Assessment
• update the design requirements document(s)
• update Safety-in-Design Risk and Opportunity Assessment; and
• prepare a PDSA.
Figure 3-4 depicts the workflow for the Final Design Phase.
DOE-STD-1189-2008
Page 32
Figure 3-4. Final Design Phase
Pre- CD-3, Final Design
CD-2 Approval
Initiate Final
Design
Update Security
Vulnerability
Analysis
Update Risk
Management Plan
Baseline
Management
CD-3 Final Design
Package
Validate Design
vs. Desired
Control Functions
& Criteria
3.4
Develop Design
Output Documents
Design Reviews
(Fed and/or
Contractor, as
appropriate)
Update Hazards
Analysis
4.4
Mitigated Accident
Analysis
4.4
Update Safety
SSC Functions
and Classification
4.4
PDSA
4.4
Safety Evaluation
Report
DOE Authorizes
Procurement,
Construction, &
Final
Implementation
Update Safety in
Design Risk &
Opportunities
Assessment
3.4
Execution
Readiness
Independent
Review
Updated SDS, as
needed
Section 30
2.3
Update Project
Risk
Considerations
CD-3 Approval
Construction,
Transition, &
Closeout
7.0
DOE-STD-1189-2008
Page 33
3.5 Construction, Transition, and Closeout
3.5.1 Introduction
This section describes those safety-basis-related activities that are
accomplished after the final design and Preliminary Documented Safety
Analysis (PDSA) are approved and before approval to operate is granted. The
primary project activities that can occur in this project interval include
construction and transition to operations. The primary safety basis activities
include preparing the Documented Safety Analysis (DSA) and Technical
Safety Requirements (TSR), review and approval of these by DOE,
implementation of the commitments in the DSA and TSR, and verification
that those requirements are met before normal operations begin. If not
previously approved, a facility Unreviewed Safety Question (USQ) procedure
is also prepared and submitted for DOE approval.
3.5.2 Construction
Construction of the project design requires close coordination and integration
of the various physical, contractual, technical, financial, and organizational
interfaces. Numerous changes to the “final” design can occur during
construction, some of which may affect the assumptions, commitments, or
results of the safety analysis. Therefore, rigorous configuration management
of the design and the safety analysis documentation is important to understand
whether a design change can affect the approval basis for the PDSA, and to
maintain consistency between the as-built facility and the safety basis
documentation (DSA and TSR). Section 6.4 provides guidance on managing
changes that affect the PDSA. In some cases, pre-existing SSCs or
“government furnished equipment” (GFE) are provided to the project for use
in the facility, creating the potential for additional challenges. Section 8.3
contains guidance and recommendations on the use of GFE.
3.5.3 Development of Safety Basis
Development of the DSA and the TSR (or revisions as appropriate for a major
modification) begins in this phase. The DSA evolves from the PDSA with the
addition of the final analysis of operational hazards and any upset conditions
that were not considered previously. Safety Management Programs (SMPs)
are detailed in this document, and elements of those programs that are needed
in hazards analyses and other upset events are defined in the appropriate
hazards analyses. Guidance for development of an operational TSR is
contained in DOE G 423.1-1.
DOE-STD-1189-2008
Page 34
The DSA for a new facility documents a design, and its associated safety
design basis, that has been approved by DOE as part of the Conceptual Safety
Design Report (CSDR), Preliminary Safety Design Report (PSDR), and
PDSA approval process. The DSA also documents any changes that were
necessary during the construction phase for future operational reference and
review and for approval of annual updates.
Additional analysis tasks that may be needed to prepare the DSA include
evaluation of equipment that was not part of the preliminary and final design,
such as government furnished equipment (GFE) or specialty equipment
designs that were performed in separate design activities not fully addressed
in the PDSA, and detailed operational analysis for those activities that did not
need to be considered for development of the design. In addition, hazards
analyses that were completed as part of the PDSA must be reviewed to ensure
that they remain accurate and that changes are made as necessary. Note that,
ideally, GFE should be included in the early hazard and accident analysis
activities and should be treated in the hazard and accident analysis as though it
were part of the design. Otherwise, the design interfaces (and potentially
acceptability of the GFE) may not be found in a timely fashion. This
additional task would be a final check on interfacing facilities or systems that
are not under the direct control of the project.
Section 31
To complete the operational hazards analyses and analyze other upset
conditions that were not developed in the PDSA, the hazards analysis process
should engage the operations staff. Detailed operational concepts should be
developed by the operations staff in conjunction with the safety analysis
efforts and should include GFE that may be used in these operations.
The DSA cannot be completed until there is a high degree of certainty that
facility configuration matches the design documentation, safety design basis
documentation, and the operating procedures for that configuration. Final
verification that the DSA information is consistent with the as-built
configuration is necessary before sending the DSA and TSR to DOE for
approval. A rigorous configuration management program (including change
control) will help in this regard.
The final development of the DSA and TSR should provide for
implementation planning. The initial planning for these activities should be
included in the Transition Plan, which should be baselined during final design.
The Transition Plan provides the concepts that support when and how many
operations staff are brought into the project to support transition and defines
(to the extent known at the time) the activities that need to be performed,
including those needed to implement the commitments expected to be in the
DSA and TSR. Many of the details of activities needed to implement the
DSA and TSR are based on limited information available in the preliminary
design. Consequently, the detailed strategy and activities needed to
implement the DSA and TSR need to be addressed and compared to the
baseline in the Transition Plan such that appropriate adjustments can be made.
DOE-STD-1189-2008
Page 35
Additional adjustments may be required based on the DOE Safety Evaluation
Report (SER) for the facility operational safety basis and other transition
activities.
3.5.4 Checkout/Acceptance, Testing and Commissioning
The final stages of the project process involve acceptance and turnover of the
SSCs from the construction effort to the operating organization. Acceptance
is generally predicated on appropriate checkout/acceptance, testing, and
commissioning. Planning for these activities should occur at early stages of
the project and be coordinated with the operating organization to facilitate an
efficient, timely turnover to ensure functionality of the safety SSCs.
Testing serves to verify that the components, systems, and facilities meet or
exceed design requirements and performance parameters and helps to train
operating personnel in the operation of the equipment, systems, and other
components of the completed project. Key activities include the preparation
and approval of test procedures, and the organization of test teams.
Procedures are prepared by personnel who are or will be part of the test teams.
Staff from the operator organization is also part of the test teams. The project
organization works closely with the user in developing and presenting specific
process and facility related training, and continues to provide support to the
operations and maintenance staff throughout transition and turnover.
Early turnover and transition activities include facility walkdowns to identify
and correct physical, process, safety, quality, or environmental deficiencies;
and planning, preparation, performance, and documentation of equipment and
systems testing and operation. Checkout and test planning and preparation
typically begin at the equipment (item) level, progress to the system level, and
culminate at the facility level. Test planning begins during design to ensure
that the physical features needed to support testing are provided.
Section 32
3.5.5 Readiness Reviews
Readiness reviews are performed to ensure that contractor programs,
equipment, and personnel are ready to safely start up and operate the facility.
DOE Order 425.1C, Startup and Restart of DOE Nuclear Facilities, defines
the requirements for conducting either an Operational Readiness Review
(ORR) or a Readiness Assessment (RA) for nuclear facilities. Readiness
reviews may also be performed for non-nuclear facilities at the discretion of
DOE.
3.5.6 Project Closeout
When construction, testing, and turnover are complete and the operational
capability has been attained, the project is ready for Critical Decision-4,
DOE-STD-1189-2008
Page 36
Approve Start of Operations or Project Closeout. A key part of obtaining
Critical Decision-4 is the delivery of appropriate project related
documentation to support the initiation of operations. The key discriminator
in the turnover is the operational organization’s readiness for assuming
operational responsibility and the government acceptance of the asset.
DOE-STD-1189-2008
Page 37
4.0 HAZARD AND ACCIDENT ANALYSES
This chapter provides guidance on hazards and accident analyses as the design process
progresses from scoping analyses in pre-conceptual design to the PHA and DBAs in
conceptual design, system and process-level hazards analyses in preliminary and final design
and the related identification of needed safety functions, and the selection and classification
of safety structures, systems, and components (SSC).
4.1 Pre-conceptual Planning Phase
A scoping analysis of potential hazards should be performed during the pre-
conceptual planning phase to plan for the conceptual design phase. The scoping
analysis is important for the development of DOE expectations for Safety-in-Design.
There may be a wide range of maturity with respect to the definition of potential
projects. In some cases, information available or developed may have target cost
ranges identified and scope defined. In other cases, only rudimentary information on
project plans and mission may be available. Knowledge of hazards will be dependent
on maturity of the potential project.
Scoping hazard analysis during pre-conceptual planning involves a qualitative
assessment of the facility/process risks in conjunction with any facility and initial
technology selection alternative reviews performed. During and after the facility and
technology selection process, project technical staff, in conjunction with nuclear
safety project personnel, should evaluate the need for safety functions and associated
hazard controls that may be required given the nature of the hazards. The initial
determination of hazard controls that may be required is based on the qualitative
assessment of the facility hazards and a preliminary determination of the approach to
be taken to satisfy the defense-in-depth requirements of DOE O 420.1B. At this
phase, only the major hazard controls that will have a significant influence on the
facility design and cost need to be identified. The results of the initial hazards
assessment, including a discussion of the overall major Safety-in-Design strategies
and DOE safety expectations, are documented in support of the Mission Need
Statement, commensurate with the level of detail available during pre-conceptual
planning.
Section 33
4.2 Conceptual Design Phase
A formal, disciplined evaluation of the potential facility hazards must be performed
during the conceptual design phase. The design information available at this phase
will be limited and may involve several design alternatives, but this effort is needed
to perform a preliminary identification of the required safety functions, as well as to
identify a preliminary set of Safety SSCs. The hazards analyses performed in this
DOE-STD-1189-2008
Page 38
phase include a PHA and identification of events warranting designation as design
basis accident analyses (DBA).
Early identification of safety SSCs (particularly those that could have high cost or
schedule impacts) is a major contributor to developing an accurate estimate of facility
and project costs. The hazards analyses establish the foundation for identifying the
safety SSCs. At the conceptual design stage, this is achieved through hazards
identification, hazards evaluation, and identification of major safety functions
necessary to provide adequate protection, primarily for accident conditions. Safety
SSCs are then chosen that will satisfy those safety functions for the preferred
alternative. Identifying and classifying the safety SSCs (safety class and safety
significant SSCs) is a fundamental part of the Safety-in-Design process.
Safety-in-design considerations for safety SSCs and defense-in-depth or important to
safety SSCs (SSCs that perform a safety function but are not classified as Safety
Class or Safety Significant, see DOE G 421.1-2 section 5.3., Hierarchy and Selection
of Control Items) should be communicated to the design staff in a timely fashion.
Similarly, the Integrated Project Team (IPT) and Safety Design Integration Team
(SDIT) need to be cognizant of the design concept as it evolves to ensure that safety
considerations are factored into each design decision.
Control strategies for DBAs must also be clearly identified in the hazards analysis,
including the following:
• required safety functions and classifications;
• SSCs required to perform these functions; and
• natural phenomena hazard (NPH) performance categories (non seismic NPH)
and seismic design bases for major SSCs.
Because preliminary cost and schedule baseline ranges being developed are strongly
influenced by the selection of the hazard controls (and by NPH design requirements),
the hazards analysis process used to arrive at these controls needs to be thorough and
based on sound safety principles. To ensure that the baseline range estimates are
conservative, the hazards analysis process and the criteria for selection of safety SSCs
must also be conservative.
After the preliminary process flow diagrams are prepared, the facility design should
further evolve before the formal hazards analysis documentation in the PHA is
completed. Ideally, the project decisions and design documentation that should be
drafted during the conceptual design phase and that are necessary for the formal
hazards analyses during the conceptual design phase are as follows:
• facility site/location selection;
• general arrangement drawings;
• MAR estimates or assumptions and material flow balances;
• sizing of major process system containers, tanks, piping, and similar items;
DOE-STD-1189-2008
Page 39
• process block flow diagrams or equivalent documentation of the required
major process flow steps and their sequence;
Section 34
• preliminary one-line diagrams for ventilation, electrical power and
distribution, special mechanical handling, and instrumentation and control
system architecture;
• summary process design description and sequence of major operation; and
• confinement strategy.
Making the decision on the facility location will simplify the analysis process;
however, the hazards analysis might also be a factor in site selection. If the site has
not been selected around the time of inception of conceptual design, the analyst
should either use bounding conditions or worst-case assumptions or perform a
parametric comparison of the hazards involved at each potential facility site location.
Such analyses increase the uncertainties in the Risk and Opportunities Assessment.
The hazardous material release events must be evaluated more formally in a PHA and
facility-level DBAs for the selected alternative design. Development of the PHA
during the conceptual design phase is an iterative process, and the PHA should evolve
to include consideration of more refined design details as they become available. A
strong PHA developed during this phase is the foundation for an effective Safety-in-
Design approach for the project.
The PHA must be based on the following:
• project decisions and documentation described in this section;
• material-at-risk (MAR) quantities; and
• key project assumptions and strategies identified in the project SDS.
During the conceptual design phase, an objective of hazards analyses is to identify
high-cost safety functions and design requirements (including those for NPH
protection) for the SSCs that will be included in the project. Examples include the
following:
• building structure;
• building and process confinement;
• power systems, including those associated with single failure criteria for
safety class SSCs;
• fire protection provisions; and
• special mechanical equipment (e.g., gloveboxes).
The PHA must establish a suite of facility DBAs to define f functional and
performance requirements for the facility design. This is facilitated by grouping the
hazardous release events according to the nature of the postulated initiating events.
One such grouping is shown below.
DOE-STD-1189-2008
Page 40
• Internally Initiated Events
- Fire – Consequences are typically due to inhalation or ingestion of
released hazardous material.
- Explosion – Consequences are typically due to inhalation or ingestion of
released hazardous material.
- Loss of Containment/Confinement – Consequences are typically due to
inhalation or ingestion of released hazardous material.
- Process Upsets – Consequences are typically due to inhalation or
ingestion of released hazardous material.
- Inadvertent Nuclear Criticality – Consequences are typically due to
direct external exposure from the event with potential for additional direct
exposure from, or inhalation of, fission products.
• Externally Initiated Events – Consequences are typically due to inhalation
or ingestion of released hazardous material. Depending on the specific event,
direct exposure may also be applicable.
• Natural Phenomena Hazards Initiated Events – Consequences are typically
due to inhalation or ingestion of released hazardous material. Depending on
the specific event, direct exposure may also be applicable.
Section 35
The categories of hazardous release events identified in these groupings essentially
form the foundation for the facility level DBAs. The DBAs considered in the hazard
analysis represent the range of potential accidents for the facility processes, and the
results of that analysis must be used to identify the controls needed to protect against
these accidents, considering both the public and collocated workers. All accident
conditions (energy sources, intermediate process hazards, and similar conditions)
must be considered.
The DBA analysis must ultimately address applicable accident environmental
conditions for which the safety SSCs need to be designed to withstand and perform
their safety function. These design basis conditions, together with the bounding
consequences of an unmitigated release, provide the basis for selecting safety class
and safety significant SSCs and their functional and performance requirements. (See
Appendix A, “Safety System Design Criteria,” and Appendix B, “Chemical Hazard
Evaluation.”)
Once the safety SSC functions are identified in the PHA (including the set of DBAs),
the design team translates them into conceptual designs (e.g., drawings and initial
system design descriptions). These conceptual designs are then the basis for cost
estimates for the project.
In the conceptual design phase, the hazardous release event evaluations are based on
facility-level events and are not a complete listing of all events possible in the facility.
At the conceptual design stage, facility-level DBA are characterized by locations and
quantities of MAR and gross descriptions of events that could result in a release of
MAR (fires, explosions, spills, NPH events). The purpose of these facility-level
DOE-STD-1189-2008
Page 41
DBA, at this stage is primarily to classify safety functions, Performance Categories,
and Seismic Design Categories for safety features that could provide those functions.
The events evaluated should be chosen by the SDIT to ensure that the hazards
considered and the safety features selected provide a reasonably conservative
perspective of the high-risk/high-cost design requirements for the project. It is
critical that the full SDIT be involved in the development of the PHA to ensure
complete consideration of accidents and events, as well as design features to prevent
or mitigate releases, to the degree practicable at this phase. (See Chapter 2, “Project
Integration and Planning,” for additional details on team involvement expectations.)
Due to the critical nature of the PHA process in defining the MAR release events and
associated safety systems, it is important that certain key information is developed
and described for each event postulated for use by the project team. Appendix G,
“Hazard Analysis Table Development,” provides detailed guidance on what should be
discussed for each MAR release event postulated by the IPT.
Although many process details will not be available to perform a PHA during the
conceptual design phase high-level events, such as fires, explosions, deflagrations,
and NPH events, should be evaluated commensurate with the available process
definition of MAR locations. From these evaluations, reasonably conservative
prevention and mitigation strategies, along with the appropriate functional
classifications and safety functional requirements, should be developed.
Section 36
For those events with consequences that do not lead to selection of safety class or
safety significant controls, the analysis should also identify the controls that are
appropriate for collocated worker and public defense-in-depth protection. Hazard
controls other than safety class or safety significant are identified in the conceptual
design phase to the extent necessary to identify cost-dominant SSCs. These controls
may be included to meet requirements defined by safety management programs and
other administrative programs. Appendix A of this Standard provides criteria for
classification of SSCs for radiological hazards. Additionally, prevention/mitigation
strategies must be identified for chemical hazards. Guidance for chemical hazards is
provided in Appendix B of this Standard.
Information from the PHA, as well as any uncertainties related to necessary hazard
controls, is considered in the Risk and Opportunity Assessment so that appropriate
cost contingencies and mitigation strategies for the items can be presented in the final
Conceptual Design Report (CDR) and in the Conceptual Safety Design Report
(CSDR).
A project design review occurs during the conceptual design phase. The results of the
PHA are included in the conceptual design and must be included in this review. For
example, before selecting alternatives, the PHA should identify top-level safety
requirements, provide a basis for the classification (unmitigated consequence analysis
to help define whether safety class SSCs are needed), and identify uncertainties such
as those associated with multiple sites.
DOE-STD-1189-2008
Page 42
The events postulated and the safety strategies selected in the PHA provide the
foundation for the development of the CSDR. The PHA also provides the foundation
for performing the HA for future design phases of the project.
4.3 Preliminary Design Phase
Hazard analysis effort during the preliminary design phase includes the following:
• updating the facility hazard categorization (if needed);
• updating the analysis of the DBAs analyzed in conceptual design to confirm
the selection of facility-level hazard controls and their functional
classifications;
• developing a system-level HA and selecting and classifying hazard controls
for the in-facility worker; and
• considering beyond-DBA events.
The objective for hazard analyses during the preliminary design phase is to confirm
and add detail to the conceptual design stage analyses, including developing
functional requirements and performance criteria for safety SSCs for in-facility
worker hazards and identifying Specific Administrative Controls (SAC) (See DOE-
STD-1186-2004). SACs should only be selected if engineered controls cannot be
identified or are not practical.
The hazard analysis performed during the preliminary design phase is the
system-level HA.
Prerequisites for the HA include developing or updating the information from the
PHA during conceptual design, including the following:
• facility general layout drawings;
• Process and Instrumentation Diagrams (P&IDs);
• updated process flow sheets;
• electrical one-line diagrams; and
• updated listing and locations of material at risk.
The HA must:
• address the spectrum of accidents that may impact design and which may be
initiated by facility operations, natural phenomena, and external man-induced
events;
• evaluate potential accident consequences to the public and workers; and
Section 37
• identify and assess associated preventive and mitigative features, including
classification (i.e., safety class, safety significant, and SACs based on the
significance of possible consequences).
DOE-STD-1189-2008
Page 43
The results of the HA provide an appropriate comprehensive evaluation of the
complete facility hazardous event scenarios and accident spectra necessary to define
the design. Guidelines for Hazard Evaluation Procedures, Second Edition with
Worked Examples provides examples of some of the techniques that can be used to
produce a well-reasoned and clear assessment of facility hazards and their associated
controls. The HA considers the complete accident spectrum. However, at this design
stage the HA only provides a preliminary definition of accident sequences and
assumptions. The results of the HA are documented using the format and content
guidance in Appendix G “Hazards Analysis Table Development”.
A graded approach should be used for the HA based on the magnitude and
complexity of the hazards of the facility. The graded approach should also be used to
select techniques for hazard analysis. The technique selected will be sufficiently
sophisticated or detailed to provide an appropriately comprehensive examination of
the hazards associated with the facility given the complexity of the operation and
degree of design maturity. Guidelines for Hazard Evaluation Procedures, Second
Edition with Worked Examples contains guidance on some of the techniques that may
be appropriate for HAs specific to the application and process.
On the basis of the HA and the updated DBA analyses, a suite of SSCs must be
selected and classified as safety class, safety significant, defense in depth or
important to safety SSCs for the protection of in-facility workers, collocated workers,
and the public. The DBA analysis also provides accident environmental conditions
that safety SSCs need to be designed to withstand and continue to perform their safety
function. Accident analyses are inherently graded in terms of the degree of physical
modeling and engineering analysis needed to quantify accident consequences. The
analysis to determine accident environmental conditions is generally included as part
of the design process and may be documented as calculations separate from the safety
documentation. Design details for safety SSCs must be developed that incorporate
design requirements derived from the HA, the updated DBA analysis, and
DOE O 420.1B.
The hazard analysis must also indicate whether a facility contains significant
chemical hazard(s) that necessitate DBA analysis for consideration of SSCs for safety
significant classification (see Appendix B).
The safety basis provisions of 10 CFR 830 require considering the need for analysis
of accidents that may be beyond the design basis of the facility to provide a
perspective of the residual risk associated with the operation of the facility. It is
prudent to examine beyond DBAs at the preliminary design phase to provide insight
into the possibility of additional facility features that could prevent or reduce severe
beyond DBA consequences. They also serve as the bases for cost-benefit
considerations for additional safety design provisions related to these postulated
accidents. No lower limit of frequency for examination is provided for beyond
DBAs. However, as frequencies become very low, little or no meaningful insight is
attained. Beyond DBAs are not expected to be analyzed to the same level of detail as
DBAs, and are not evaluated for man-made external events.
Section 38
DOE-STD-1189-2008
Page 44
4.4 Final Design
During this phase, the DBAs are revised to reflect any changes that are design
dependent (such as a change in the planned location of a structure resulting in
different potential impacts from collocated facilities). In addition, during this phase
analyses that support final classification of safety significant SSCs and demonstrate
the adequacy of the control suite (engineered features with necessary SACs) are
finalized.
The major new safety analysis activity in this phase is completion of the safety
analysis. The completed safety analysis demonstrates the adequacy of the design
from the safety prospective. As with the design, it is not necessary to show the
progression of the design that led to the final choices, only the final choices, and the
justification for their adequacy. The Preliminary Documented Safety Analysis
(PDSA) guidance in Appendix I discusses how this information is applied to support
the completion and documentation of the safety analysis.
At the final design phase, the safety analyses must encompass the scope of the design
and demonstrate that the designated safety SSCs are adequately designed to reliably
perform their intended safety functions. For system and component design,
adherence to national codes and standards, in accordance with DOE G 420.1-1, -2,
and -3 must be used to demonstrate that the design criteria have been met. Many of
the design criteria are qualitative in nature and require an analysis to show how they
are applied to a particular SSC. Demonstrating compliance with the requirements of
these standards will be an important review consideration during acceptance of the
safety documentation and during readiness activities in support of the CD-4
milestone.
If the requirements of applicable standards were tailored, a justification that
demonstrates the adequacy of the final design with the tailored requirements must be
documented. A System Design Description may be used to capture and maintain
such information.5 As the design progresses, design reviews should be used to
validate the selection of criteria, application of codes and standards, deviations, and
design output.
To provide a baseline understanding of the adequacy of controls, the accident analysis
in the PDSA must describe how the selected controls adequately prevent and mitigate
the accidents, including how the controls provide defense-in-depth. The discussion
puts the effectiveness of hazard controls into accident context and provides the
baseline safety analysis for the evaluation of changes, for example, under the
Unreviewed Safety Question (USQ) process, for the operational period.
The development of safety design analysis information is important to the design
progression. In many instances, the results will define design requirements for the
procurement of safety materials or components. These design requirements represent
5 See DOE STD 3024-98, Content of System Design Descriptions.
DOE-STD-1189-2008
Page 45
important quality assurance attributes that must be objectively demonstrated and
should be tied to the procurement specifications. For example, a process control
system may be selected as a safety system during the safety-design evolution. Once
selected, the control system must be demonstrated to be capable of performing its
safety function under all postulated process upsets or accidents as credited in the
accident analysis.
Section 39
Example
A process control system may be selected as a safety system during the safety-design
evolution. Once selected, the control system must be demonstrated to be capable of
performing its safety function under all postulated process upsets or accidents as
credited in the accident analysis.
Specifically, the design of a control system based on pressure instrumentation for
some specified system transient must factor instrument uncertainty into the system
response. If the system must operate following a postulated pipe break in its physical
area, the instrumentation must be shown to be able to withstand the pipe break
consequences, typically by qualification testing.
Calculations are required to define the conditions for such testing. If the control
system is deemed safety class and required to satisfy single failure criteria, Failure
Modes and Effects Analyses (FMEA) or fault trees may be needed to ensure active
single failures do not affect system function under postulated system faults. If the
control system is required to function during and/or following a seismic event, not
only must the system and its active components be demonstrated capable of
withstanding the acceleration forces, but any SSCs not part of the system must be
evaluated to ensure their failure cannot endanger the control system (target-source
interaction analysis).
In this case, instrument uncertainty, environmental qualification parameters, single
failure, and seismic target-source interaction, must be considered in the selection of
the actual components for installation, and these requirements must be translated to
the procurement specifications.
Typically, the final design concepts necessary to develop the PDSA are completed
before the final design phase, but changes may arise during final design that result in
the need to revise the PDSA. It should be recognized that the commitments and
descriptions in the PDSA may change and adequate change controls will need to be
established to accommodate this possibility.
Not all design issues related to safety may be resolved by the final design phase.
Consequently, it may be necessary to identify where these issues remain open and
describe the safety implications associated with them. This is particularly applicable
for equipment, such as government furnished equipment (GFE) that will be procured
by others in a later phase of the project. This ultimately translates to a project risk
issue as well as a safety issue. These risks must be documented in the Risk and
Opportunity Assessment.
DOE-STD-1189-2008
Page 46
5.0 NUCLEAR SAFETY DESIGN CRITERIA
As discussed in Chapter 4, the results of the Preliminary Hazard Assessment (PHA), the
Design Basis Accident (DBA) Analysis and the identification of Safety structures, systems,
and components (SSC) must be considered in the design process. After the appropriate
facility location and processing alternatives have been selected, other safety design
requirements and considerations must be specifically addressed during design development.
These requirements and considerations are in DOE O 4201.1B in the following chapters:
• Nuclear and Explosives Safety Design Criteria (Chapter 1);
• Fire Protection (Chapter 2);
• Nuclear Criticality Safety (Chapter 3); and
• Natural Phenomena Hazards Mitigation (Chapter 4)
In addition, specific criteria or guidance for implementing these requirements are contained
in the following:
Section 40
• DOE G 420.1-1, Nonreactor Nuclear Safety Design Criteria and Explosive Safety
Criteria Guide for use with DOE O 420.1 Facility Safety;
• DOE G 420.1-3, Fire Protection and Emergency Services Program;
• DOE-STD-3007-2007, Guidelines for Preparing Criticality Safety Evaluations at
Department of Energy Nonreactor Nuclear Facilities; and
• DOE G 420.1-2, Guide for the Mitigation of Natural Phenomena Hazards for DOE
Nuclear Facilities and Nonnuclear Facilities.
Alternative safety design criteria may be proposed by the design contractor, as described in
10 CFR 830.206, but the alternative criteria must be approved by DOE.
The SDIT (or its functional equivalent) should review DOE O 420.1B, as well as its
implementation guides and their referenced Standards, and should compile a listing of the
applicable safety design requirements and associated guidance relative to each of the safety
topics addressed in the above-listed chapters of the Order. These safety design requirements
and criteria must be placed under design control with an expectation to demonstrate
implementation at project end. As the design evolves, requirements will become more
specific. The intent of engineering design control is to ensure safety design requirements and
criteria are controlled throughout the design process and changed only with appropriate
review, approval, and flow down of the change into the design and documentation. Control
of safety requirements is a fundamental responsibility of the SDIT. Where no SDIT is
formed, control of these requirements is the responsibility of the project safety lead. The
project change control process must provide for concurrence by the Federal Project Director
for changes to criteria invoked in the SDS. Derived requirements which implement these
criteria are controlled wholly within the design control process.
The Conceptual Safety Design Report (CSDR), the Preliminary Safety Design Report
(PSDR), the Preliminary Documented Safety Analysis (PDSA), and the Documented Safety
DOE-STD-1189-2008
Page 47
Analysis (DSA) must address, to the appropriate degree of design maturity, each of the safety
design requirements and considerations in DOE O 420.1B (unless an alternate set of
requirements has been approved by DOE) and identify the extent to which the design
incorporates them. Where the design does not fully satisfy one of these requirements, the
rationale must be provided.
Specific SSCs will have been identified in the conceptual design phase along with applicable
DOE O 420.1B criteria. As design evolves, specific design codes and standards to be used
for the design of the safety SSCs will typically be identified during Preliminary Design.
Guidance for mapping between the safety functions and the selected safety SSCs and
applicable design codes and standards is provided in the guidance documents listed above for
DOE O 420.1B. The linkage between safety requirements and the design codes and
standards should be provided at a high level in the safety documentation (see H.2 6. and I.2
Appendix B).
If the codes and standards chosen for the safety functions and safety SSCs differ from those
identified in the DOE requirements cited in this section, the rationale for the selection of
alternate codes and standards must be provided. The PSDR is generally the first place where
a linkage to the specifics of the alternative selection and rationale in a document such as the
Design Criteria Document is provided. The PSDR should summarize and reference the
document that contains this information.
Section 41
Demonstrating compliance with the requirements in DOE O 420.1B generally involves a
design analysis or series of analyses. For example, some safety SSCs are required to be
designed to withstand common cause effects and adverse interactions from natural
phenomena hazard (NPH) events. The design analyses must demonstrate that those safety
SSCs that are required to function before, during, or after the NPH event will continue to do
so. This may entail evaluation of a number of nearby or overhead SSCs that perform no
direct safety function. Design documentation to demonstrate this requirement for “source
SSCs” may involve design criteria for the facility or system and calculations demonstrating
acceptable seismic design. Each applicable analysis for a project should be considered as
important technical basis information that is to be maintained in support of the safety basis
for the life of the facility.
During design, material in Type B containers with current certificates of compliance may be
excluded from the inventory for final hazard categorization, when safety analyses
demonstrate that containers can withstand all accident conditions.
DOE-STD-1189-2008
Page 48
6.0 SAFETY REPORTS
6.1 Safety Input to the Conceptual Design Report
DOE O 413.3A, Chg 1, requires developing a Conceptual Design Report (CDR)
during the conceptual design phase. The CDR is intended to provide the Approval
Authority with integrated information sufficient to understand the overall project
scope and cost, the risk and opportunities, and the cost range for the selected
conceptual design. The CDR for the selected conceptual design must incorporate an
effective Safety-in-Design approach to address potential material-at-risk (MAR)
release events. DOE O 413.3A, Chg 1, and its guidance establish the minimum
content for the CDR, which summarizes the project requirements and the proposed
design solution. The CDR is a necessary element in decision-making because it
documents the following:
• project design requirements;
• alternatives evaluated and selected for facility and the process configurations;
• design architecture (major structures, systems and components [SSCs])
selected to satisfy the design requirements, consistent with the selected
alternatives; and
• safety design basis for the proposed facility.
Both the CDR and the Conceptual Safety Design Report (CSDR) provide the
following:
• risk-informed decision making information for the DOE approval authorities;
and
• equipment safety classifications and design requirements, as well as a
corresponding cost range that reflects the Safety-in-Design decisions made
during the conceptual design phase.
The CDR provides an integrated discussion of the key results of the hazards analysis
including the following:
• facility hazard category determination;
• selected safety functions and controls;
• SSC functional classifications, performance categories, and seismic design
criteria for natural phenomena hazard (NPH) protection;
• design criteria for the safety SSCs; and
• approach to be taken to further develop and document the safety basis through
the remaining project phases.
DOE-STD-1189-2008
Page 49
In addition, the SDS must also describe any uncertainties with respect to the safety
design basis assumptions and selected hazard controls, and explain how the risks
associated with these uncertainties will be managed.
6.2 Conceptual Safety Design Report
Section 42
DOE O 413.3A, Chg 1, requires a CSDR as a part of the approval package for CD-1.
The purpose of the CSDR is to summarize the hazards analysis efforts and Safety-in-
Design decisions incorporated into the conceptual design along with any identified
project risks associated with the selected strategies. Appendix H provides specific
guidance for preparing the CSDR.
DOE must review the CSDR and document the review in a Safety Validation Report
to confirm that the preliminary safety positions adopted during conceptual design
constitute an appropriately conservative basis to proceed to preliminary design.
These positions include the following:
• selection of the preliminary hazard categorization (HC-1, 2, or 3) of the
facility;
• preliminary identification of facility Design Basis Accidents (DBA);
• assessment (based on the analyses of DBAs) of the need for safety class and
safety significant facility-level hazards controls;
• preliminary assessment of the appropriate seismic design criteria for the
facility; and
• position(s) taken with respect to compliance with the safety design criteria of
DOE O 420.1B or any alternate criteria proposed.
6.3 Preliminary Safety Design Report (and PDSA)
The key Safety-in-Design documents developed during the preliminary design phase
are the Hazards Analysis (HA) and the Preliminary Safety Design Report (PSDR).
The format and content of the PSDR are designed to be built upon to produce the
Preliminary Documented Safety Analysis (PDSA) during the final design phase. The
format and content guidance for the PDSR are provided in Appendix I of this
Standard. The PSDR addresses the following Safety-in-Design aspects for the
Preliminary Design Phase:
• site information of the type that can affect Safety-in-Design (e.g., location of
nearby facilities and external hazards, meteorological information for
dispersion analyses, seismic and other natural phenomena information);
• facility and process descriptions, including facility structure types and layout,
process description and flow sheet, and summary system descriptions for
safety SSCs, consistent with the level of design;
DOE-STD-1189-2008
Page 50
• summary of the HA, including process hazards evaluation, selected DBAs;
FHA, selected safety SSCs and their safety function; functional classification;
and required seismic and other natural phenomena design criteria, including
their bases;
• for safety class and safety significant SSCs and Specific Administrative
Controls (SAC), the functional requirements and performance criteria
(including applicable design requirements from DOE G 420.1-1 and DOE
G 420.1-2);
• information regarding aspects of the preliminary design that are required to
support the prevention of inadvertent criticality;
• roadmap of project documentation addressing design aspects related to the
effective implementation of safety management programs; and
• documentation of how the safety design criteria of DOE O 420.1B are met,
including any exceptions or alternate approaches, which may include analyses
performed to meet the safety analysis expectations.
Based on the design maturity in preliminary design, the PSDR will demonstrate the
adequacy of the hazards analyses and the selection and classification of the hazard
controls, including consideration of the application of the principles associated with
the hierarchy of controls. If the commitments made in the PSDR and design
documents are met, the result should be a final design and a constructed facility that
could be approved for operation without major modifications. The PDSA at the final
design stage is an evolution of the PSDR.
Section 43
6.4 Change Control for Safety Reports as Affected by Safety-in-
Design Activities
A clearly defined project configuration should be established at the conclusion of
each phase of the design. DOE-STD-1073-2003, Configuration Management, states:
“The objective of change control is to maintain consistency among design
requirements, the physical configuration, and the related facility documentation, even
as changes are made.” At the conceptual design stage, change control should be
implemented within the design organization to maintain consistency among the
various concepts and their supporting documentation. The CSDR issued at the
completion of the conceptual design must reflect the project configuration as
described in the conceptual design. Critical relationships between safety and the
concept that progresses to the final design are established in the CSDR.
As the conceptual design evolves to the preliminary design, it is documented in a
PSDR. The PSDR must specifically identify any changes to Safety-in-Design
decisions and commitments that were described in the CSDR and must provide
explanations for the changes. Similar identification of changes and explanations must
be provided between the PSDR and the PDSA.
DOE-STD-1189-2008
Page 51
As the preliminary design progresses to the final design, the PSDR evolves into the
PDSA with its attendant supporting safety analyses, which have been formalized
relative to earlier evaluations. The approved PDSA constitutes the basis upon which
DOE agrees that procurement and construction may begin.
PDSA configuration baseline documents should be identified within the project
baseline. The PDSA configuration baseline is the basis for determining if PDSA
revision is needed, and formally establishing and maintaining the PDSA
configuration baseline provides the means to ensure that the Department can continue
to rely on the information in the PDSA.
Not every change in the PDSA configuration baseline will necessitate a PDSA
revision. The following criteria are suggested to determine whether a PDSA revision
is needed because of post-PDSA approval design changes.
• The change alters a safety function for a safety SSC identified in the current
PDSA.
• The change results in a change in the functional classification, reliability, or
rigor of the design standard for an SSC previously specified in the PDSA
configuration baseline.
• The change requires implementation of new or changed safety SSC or
proposed Technical Safety Requirement (TSR) controls.
• The change significantly alters the process design or its bases, such as
increased material at risk, changes to seismic spectra, major changes to
process control software logic, new tanks, new piping, new pumps, or
different process chemistry.
DOE-STD-1189-2008
Page 52
7.0 SAFETY PROGRAM AND OTHER IMPORTANT PROJECT
INTERFACES
There are multiple interfaces with required programs and project evolution steps that link
with the Safety-in-Design process. The intent of this chapter is to highlight the links where
these areas, particularly Safety Management Programs (SMP), which are required to be
addressed in sections 6 through 17 of the Documented Safety Analysis (DSA), directly
interface with the design process; specifically, where they link to the development of safety
design bases. This chapter is not intended to provide comprehensive explanations because
the subject matter is addressed in detail in other DOE documentation. Table 7-1 shows the
typical activities associated with these SMPs for each project phase.
Section 44
For new facilities that will be built at existing DOE sites where SMPs have been established,
much of the interface with the DSA will be similar to that for existing facilities. Exceptions
may occur where new classes of hazards are introduced. For new sites, the development of
SMPs should be a focus of management attention early in the project life cycle, and these
programs should mature as the facility heads toward operational capability.
Most of the sections in this chapter involve aspects important to design, and consideration of
them should be integrated into the design effort as early as it is practical to do so. Among
these are emergency preparedness, radiological protection, nuclear criticality safety, fire
protection, human factors, and security. Further discussion on this integration is provided in
the following sections, and Table 8-1 shows actions relating to them as a function of design
stage.
7.1 Quality Assurance
The quality assurance (QA) requirements of 10 CFR 830 and DOE O 414.1C apply to
DOE nuclear facilities and activities. The scope of the QA rule is defined in 10 CFR
830.120 as follows:
This subpart [Subpart A of 10 CFR 830] establishes quality assurance
requirements for contractors conducting activities, including providing
items or services, that affect, or may affect, nuclear safety of DOE nuclear
facilities.
This wording was specifically chosen to include activities in the design and
construction phases before completion of the facility and introduction of nuclear
material. That is because the quality of the design and construction is integral to the
safe operation of the facility.
Furthermore the inclusion of a robust QA program in the design and construction
phases can greatly strengthen the ability to achieve the goals of Safety-in-Design,
namely to identify and correct problems early in the design and construction phases
when it is more cost-effective to make corrections. With respect to the activities
defined in this Standard, QA should be viewed as an important tool. The successful
completion of many nuclear facilities has occurred simply because of the quick
DOE-STD-1189-2008
Page 53
response to QA findings during design and construction.
In particular, the following QA activities can help keep the design process on track.
• Establishing and using formal work processes such as design reviews,
document control, verification processes, and configuration management.
• Training of design and review staff on applicable standards, requirements,
and work processes.
• Performing periodic assessments of the documentation, including drawing
reviews, to ensure that the drawings, design calculations, and other
documents are in agreement. Key design and construction personnel
should be involved in these reviews.
• Performing independent design verifications, validations, assessments and
design outputs by qualified persons to keep design and analysis errors to a
minimum.
• Identifying problems that occur in the design process, determining the root
cause and taking timely corrective actions, both immediate and long term.
• Developing and using approved vendor lists to ensure quality products.
• Periodically evaluating the approved vendors to ensure their quality has
not degraded; and, if it has, examining the products already supplied to
ensure they are adequate.
• Controlling documents and drawings, as well as changes to them, to
approved processes.
• Ensuring the quality of safety software used for design activities.
Section 45
• Identifying and controlling design interfaces.
• Periodically meeting with vendors to ensure safety components can in fact
be constructed and function consistent with design specifications without
unconsidered exceptions.
Ultimately, the safety documentation must be validated against approved design
outputs. The iterative nature of the safety and design processes demands a more
flexible change control process at this stage, but ultimately design outputs must be
controlled under the applicable configuration management plan. DOE-STD-1073-
2003, Configuration Management, Section 3.9, discusses activities that should be
initiated during design to ensure a smooth turnover from design to construction.
DOE O 413.3A, Chg 1, requires that quality assurance begins at project inception and
continues throughout the project’s life cycle. Consistent with that requirement, DOE
O 413.3A, Chg 1, also requires that a quality assurance program (QAP) (compliant
with 10 CFR 830, Subpart A, and DOE O 414.1C) is approved in CD-1 and updated
and continuously applied throughout the project’s life cycle. The QAP describes the
planned quality related activities, surveillances, and assessments and should be
developed in the project conceptual phase and updated as the project matures.
DOE-STD-1189-2008
Page 54
DOE and commercial nuclear industry QA experience highlight the need to
specifically consider:
• tracking and verification of assumptions from the safety analysis or design to
operational acceptance;
• appropriate translation of inspection and test requirements for installation
verification or safety SSCs;
• use of subcontractors with recent experience with nuclear QA; and
• documentation of safety SSC inspections and tests.
The project Quality Assurance Program (QAP), established at the project’s inception,
will guide QA activities for the project. Appropriate assessments of the safety
analysis and design process are planned and completed consistent with the project
QAP.
DOE G 414.1-4, Safety Software Guide for use with 10 CFR 830, Subpart A, and
DOE O 414.1C are of special relevance with regard to design activities.
7.2 10 CFR 851 Worker Safety and Health Program
The focus of the Worker Safety and Health Program Rule (i.e., 10 CFR 851) is as
follows:
• provide a place of employment that is free from recognized hazards that
are causing or have the potential to cause death or serious physical harm to
workers; and
• ensure that work is performed in accordance with (i) all applicable
requirements of this rule; and (ii) with the worker safety and health
program for that workplace.
This commitment to providing a workplace that is free of recognized hazards adds a
layer of attention to the hazard analysis and facility controls that goes beyond that
required for the Preliminary Documented Safety Analysis (PDSA).
The 10 CFR 851 rule requires establishing a worker safety and health program that is
approved by the Department. Two required areas of this rule that are of particular
relevance to Safety-in-Design are fire protection and pressure safety. The rule
invokes National Fire Protection Association (NFPA) requirements for fire protection
and American Society of Mechanical Engineers (ASME) Boiler and Pressure Vessel
code (BPV). These consensus standards are also typically invoked by DOE G 420.1-
1 for safety-significant and safety-class systems and components, as well as DOE G
420.1-3 for all fire protection systems, regardless of safety designation. These
standards represent design input into any new construction and potentially to major
modifications.
Section 46
Applicability of worker safety-related national consensus codes and standards should
be recognized at the earliest stages of conceptual design and captured in appropriate
DOE-STD-1189-2008
Page 55
requirements documents. As the design evolves into preliminary and detailed design,
these codes and standards will drive certain areas of design.
The worker safety and health program should ultimately be reflected in the SMP
chapters of the DSA. Worker safety programs specifically described in the DSA are
Hazardous Materials Program, Occupational Safety (which includes fire protection),
Emergency Preparedness, Management, Organization, and Industrial Safety
Provisions. These areas are discussed in more detail below.
7.3 Fire Protection
A key interface during the early design phases is identifying the potential fire hazards
and scenarios that can drive safety functional classification of fire protection SSCs
(e.g., detection and suppression). Fire protection design includes the following
elements: reliable water supply, noncombustible construction, fire-related barriers,
detection systems, building contents, ventilation control, and automatic suppression
systems. Design is developed through a competent and thorough FHA and
interactions between the design team and fire protection SMEs. Design guidance for
fire protection can be found in DOE G 420.1-3 and in DOE-STD-1066-99. Safety
fire protection SSCs can represent a significant cost to the overall project and present
special interface challenges between fire protection SMEs and safety analysis
disciplines. A full understanding of the implications of fire protection selection is
necessary to effectively implement such a strategy during detailed design. For
example, selecting a confinement ventilation system that uses HEPA filtration
necessitates considering potential particulate loading of the filters due to fire
scenarios.
An FHA is required for all nuclear facilities or facilities that present unique or
significant fire risks. An FHA requires a comprehensive evaluation of fire hazards,
including postulation of fire accident scenarios and estimates of potential
consequences (i.e., maximum credible fire loss). DOE O 420.1B requires the
conclusions of the FHA to be integrated into the DSA. DOE G-420.1-1 encourages
the initiation of the FHA early in the design process and suggests that this effort be
closely coordinated with the safety analysis effort. The preliminary FHA and its
conclusions should be addressed in the facility CSDR and PSDR in a manner that
reflects all relevant fire safety objectives that could affect the facility safety basis.
The FHA is typically coordinated and integrated through teaming of fire safety
personnel with hazard/accident analysts, and any conflicts related to the FHA and
DSA should be resolved as early in the design process as practicable. DOE-HDBK-
1163-2003, Integration of Multiple Hazard Analysis Requirements and Activities,
provides additional guidance.
The FHA provides fire protection strategy and protection schemes necessary to
control or mitigate fire hazards to workers and the general public. Each stage of the
project life cycle as indicated in Table 8-1 demonstrates how the FHA supports the
DOE-STD-1189-2008
Page 56
Section 47
design process. In the conceptual design, a preliminary FHA provides fire protection
strategy alternatives for control or mitigation of accident consequences. Fire
protection strategies will dictate design requirements. These design requirements will
be evaluated as part of preliminary design. System-level hazard controls and
classification are also developed and further refined. This includes other protection
requirements, such as property protection and building code requirements.
Another important facet of fire protection is the code-based requirement for an
Authority Having Jurisdiction (AHJ). For designs that do not comply with
appropriate NFPA Standards, AHJ review and acceptance of design outputs relevant
to fire protection and life safety are required. Appropriate interfaces with the AHJ
should be anticipated and planned.
7.4 Infrastructure
Infrastructure considerations are critical to a project. It is important to identify
infrastructure needs and existing capabilities or constraints as early as practicable in
the design process. In this discussion, infrastructure includes all existing facilities
and utilities that will interface or that may coexist with the new facility or
modification to an existing facility. The infrastructure considerations include, but are
not limited to the following:
• supporting utilities (e.g., water, steam, power, industrial gases);
• surrounding or collocated facilities;
• supporting organizations and SMPs; and
• interfacing facility (modifications).
Of particular interest is the identification of any constraints that may hinder project
planning and execution. Equipment compatibility (e.g., electrical) constraints can
arise when interfaces with an aged infrastructure are possible. Gas systems should be
investigated to fully understand interconnections with surrounding facilities and for
features relevant to the hazard analysis. Utility interfaces should be identified in both
pre-conceptual and conceptual design. An important consideration is the ability of
the utilities to support SC and SS systems such as fire sprinkler systems. In
preliminary design, specific needs should be reconciled with the existing systems
capabilities and capacities to support baseline cost estimation.
Surrounding or collocated facilities need to be considered in the early stages of the
hazard analysis for conceptual design. Nearby facilities may present hazards (e.g.,
toxic or explosive gases) that must be considered in the hazard analysis as an external
hazard. Provisions may be required within the planned facility to mitigate the effect
of such events on personnel within the new facility. An analysis of the effects of
nearby facilities should be completed in support of the Preliminary Safety Design
Report (PSDR).
DOE-STD-1189-2008
Page 57
7.5 Nuclear Criticality Safety
Nuclear criticality safety (NCS) represents a specialized safety discipline. Given the
significance of an inadvertent nuclear criticality, the presence of quantities of
fissionable materials sufficient to sustain a critical reaction can determine the facility
hazard categorization. Where there is sufficient fissionable material present, NCS
controls can also result in safety significant functional classification of SSCs and,
potentially, TSR controls. As a result, the NCS function must be represented on the
project team and closely linked to the safety analysis effort from the earliest stages of
project development. Criticality safety evaluations (CSE) must be integrated with the
traditional safety analysis techniques to provide a comprehensive safety analysis.
DOE has promulgated guidance for performing and documenting criticality safety
evaluations in DOE-STD-3007-2007.
Section 48
To support design development, it is important to develop fundamental design criteria
to address typical criticality safety concerns (e.g., safe geometry) and to incorporate
these criteria early in the design process. The purpose of these criteria is to avoid the
use of cumbersome and inherently less reliable administrative controls. An example
set of design criteria is provided in Table 7-2.
One of the most important criticality safety design features is to prevent, by design,
natural phenomena initiators for criticality accidents (e.g. seismic and wind). In
addition, the fire protection program at design will also drive criticality safety design
requirements. The building code, Life Safety Code, national fire codes, and DOE
directives almost always require automatic sprinkler protection and firefighting hose
capability as well as suitable drainage for nuclear facilities. Unless exemptions and
variances have been approved for automatic and manual fire suppression, the
criticality calculations must take this moderator into account. For example, in a
facility where sprinklers are planned, the criticality safety evaluations must consider
the effects of introduction of water due to sprinkler activation. The presence of
sprinklers will also tend to drive engineered controls for criticality safety to prevent
water ingress to fissionable material containers, both in process containers and in
storage. Criticality concerns could also result in a change from water-based
sprinklers to an alternative gaseous suppression system, which could affect cost
estimates. Therefore, there is a need for close cooperation between fire
protection/fire hazards analysis and criticality safety early in design.
Criticality safety includes human interaction with the potential criticality hazard.
Addressing human interaction issues typically results in administrative controls.
Minimizing use of administrative controls in lieu of more reliable engineered controls
should be a focal point for design. This also points to the need to identify criticality
safety issues early in the design process and design the facility in such a way as to
preclude criticality problems (e.g., provide storage appropriate for the types of
materials, design systems that can be used by the operator in a way that ensures
criticality safety, consider criticality potential when designing sprinkler systems and
other fire protection). One specific aspect of NCS operations requiring early project
definition is emergency response to criticality accidents.
Designs should strive to make a criticality accident a beyond extremely unlikely
DOE-STD-1189-2008
Page 58
event. If that is not practical, the Double Contingency Principle requires control of
two independent parameters (see DOE-STD-3007-2007). Deviations from the
Double Contingency Principle must be specifically approved by DOE and typically
results in layers of administrative controls. A singular focus of criticality Safety-in-
Design should be to avoid the need for single parameter control in all processes where
a criticality accident is credible.
7.6 Radiological Protection
Radiological controls to achieve As Low as Reasonably Achievable (ALARA)
represent a fundamental design philosophy that is used at the earliest stages of design
and which is a requirement of 10 CFR 835. Subpart K of 10 CFR 835 “Design and
Control and Facility Design and Modifications,” provides key inputs into the design
process. DOE G 441.1-1B, Radiation Protection Programs Guide, provides
additional guidance for design, in Section 7.4 of that guide.
Section 49
Radiological hazards will generally be considered as candidates for confinement or
shielding strategies to minimize worker exposure. These strategies will evolve to
design requirements through the project life cycle. In addition, detection or
monitoring equipment is generally required to protect workers, the public, and the
environment.
7.7 Human Factors
In the context of safety bases development, DOE-STD-3009-94, CN 3, defines human
factors to consist of the following:
• human factors engineering that focuses on designing facilities, systems,
equipment, and tools so they are sensitive to the capabilities, limitations, and
needs of humans; and
• human reliability analysis that quantifies the contribution of human error to
the facility risk.
These two factors apply to the design in (1) the layout and design of SSCs for
operation, construction, maintenance, and testing or surveillance; and (2) in the
evaluation of failure probability of human relied upon actions. In some instances,
these factors overlap (e.g., control room operator action).
The connection to the safety analysis is, in many cases, indirect in that, by including
this philosophy, inadvertent human errors can be minimized. This is specifically
important to ensure that administrative controls can be implemented within the
facility.
Within the project life cycle, the human potential for error is effectively addressed
through the hazards analysis process and industrial or programmatic safety programs
that identify other opportunities to avoid error potential. This is a normal part of
design evolution and should be factored into the design process as those human
DOE-STD-1189-2008
Page 59
factors reviews occur over the life cycle (particularly through preliminary and
detailed design stages).
Human factors for design should be established as a design philosophy early in the
conceptual design phase. This philosophy should evolve to consider standard human
interface issues. Many codes and standards reflect this approach, and it is inherent in
the standards. It is also important to include operator input and reviews by
maintenance and test personnel to ensure access for maintainability and testability.
7.8 Security
Some measure of security is required to be addressed for most DOE facilities.
However, for a limited number of facilities, security drivers for the design and
operations are a key consideration for the project. In these limited cases, security
requirements can represent a significant cost driver. Security protection schemes may
involve one or more of the following: designed structural protection for key resources
or materials; adversary deterrence and delay; intrusion detection systems; and
protective force resources. Aspects of the security scheme must be coordinated with
the design as it relates to safety in a two key areas: (1) structural design and (2)
inadvertent or accidental discharge of weapons or weapon systems.
The interaction between the project team and security personnel is needed to develop
an integrated implementation involving both safety basis and security allowing
achievement of the Design Basis Threat (DBT) objectives while ensuring safety is
appropriately considered.
Where significant structural protective measures are warranted (e.g., special nuclear
material storage or processing), Natural Phenomena Hazards (NPH) design and
security measures may be used in a complementary manner; that is, major structural
components may be designed to serve both functions and result in efficient use of
resources. The key factor is obtaining the security requirements early in the project to
coordinate with the NPH design.
Section 50
Accidental discharges of security systems could initiate accidents such as hazardous
material releases, fires, nuclear criticality, or damage to safety SSCs or process
systems. As an initiator for an event, accidental or unintended discharge of weapons
or deterrent systems could present a hazard to workers and the public, and must be
addressed in the hazard analysis. These events could be caused by human error,
faulty security system design, or internal or external hazards. There is also the
potential for common cause effects on security systems that must be considered in the
safety analysis. Some accident initiators that could actuate the security system and
exacerbate accident consequences include facility events, such as fires, and seismic
and other NPH events.
Given the rapid evolution of security requirements, security modifications in existing
facilities could be candidates for consideration as a major modification. In that case,
preparation of a PDSA and application of the nuclear safety design criteria of
DOE O 420.1B will be required.
DOE-STD-1189-2008
Page 60
As safeguards and security has an independent set of directives that are implemented
and the safety and security disciplines often use similar terms, it is important to
clearly define the areas for which these two do not interface, as well as areas where
interaction is needed. From the Safety-in-Design perspective, it is critical to address
the interfaces and to clearly define when the protective measures implemented by the
security system to meet the applicable requirements must be addressed by appropriate
safety measures to ensure the safety and health of workers, public, and the
environment. Interfaces with Safeguards and Security that are important to safety
basis development include the development of Safeguards Requirements
Identification (SRI), a Vulnerability Assessment (VA), and participation in the hazard
analysis efforts.
There are no requirements to document security strategies within the DSA. However,
security plans and vulnerability assessments are required in the security domain and
these documents may be influenced by safety-driven interaction through the process.
7.9 Environmental Protection
The DOE National Environmental Policy Act (NEPA) process is a Federal process
conducted in accordance with 10 CFR 1021, for identifying environmental impacts to
support decision-making about a proposed action. The Integrated Project Team (IPT)
needs to support this process. DOE O 451.1B, Chg 1, National Environmental Policy
Act Compliance Program, establishes DOE internal requirements and responsibilities
for implementing the National Environmental Policy Act (NEPA) of 1969, the
Council of Environmental Quality Regulations implementing the Procedures
Provisions of NEPA (40 CFR 1500-1508) and the DOE implementing procedures of
10 CFR 1021. The project should coordinate with the DOE Site and Operations
Office NEPA compliance officers during the project initiation phase to ensure that the
NEPA process is fully executed. NEPA documentation, consistent with design,
should be developed as early as possible in the project acquisition process. In
accordance with O 413.3A, Chg 1, the NEPA strategy and analysis are prepared
during conceptual design. Final NEPA documents, including public involvement (if
necessary) and resulting Record of Decision (ROD) or Finding of No Significant
Impact (FONSI), must be issued prior start of final design.
Section 51
The Project Team needs to identify all applicable environmental regulatory
requirements. These include regulations issued by the Environmental Protection
Agency and by delegated states pursuant to statutes such as the Clean Air Act, the
Clean Water Act, and the Resource Conservation and Recovery Act (RCRA). Other
requirements (relating, for example, to protection of endangered species, protection of
historic and cultural resources, and others) may also be applicable. Permits may be
required under some of these regulations, and planning for these permits needs to be
incorporated in the project schedule. Most permits are applicable to facility
operation, but some may be required prior to start of construction.
DOE O 450.1, Administrative Chg 1, Environmental Protection Program, and
DOE-STD-1189-2008
Page 61
associated guides provide further information relative to environmental protection
practices by which the DOE implements sound stewardship that is protective of the
air, water, land, and other cultural resources impacted by DOE operations and by
which DOE cost-effectively meets or exceeds compliance with applicable
environmental, public health, and resource protection laws. DOE sites are required to
implement environmental management systems, as part of their integrated safety
management systems. The environmental aspects of the project should be reflected in
the site’s environmental management system prior to operation.
7.10 Hazardous Material
Similar to radiological hazards, DOE requirements invoke an ALARA concept for the
protection of workers from hazardous materials. Design should support the primary
objective of reducing the frequency, severity, and cost of incidents involving
hazardous material, as well as the cost of hazardous operations. Prevention practices,
such as substitution of less hazardous materials in a project or design of a process to
reduce generation of hazardous waste, should be examined prior to consideration of
protection strategies. Protection strategies will generally involve confinement
strategies, such as gloveboxes, piped systems, and tanks, as well as administrative
controls. The approach will typically be driven by the magnitude of the hazard and
inventory.
Major hazardous materials, typically associated with process requirements, should be
identified and considered within the safety strategy. The process design will identify
and refine inventory or maximum anticipated quantities to support structure, system,
and component (SSC) functional classification. Codes and standards to be applied
should be specified for application in detailed design. Provisions for facility
monitoring and protection instrumentation for worker protection need to be
considered.
Further guidance is available in the DOE-HDBK-1139/2-2006, Chemical
Management (Volume 2 of 3), “Chemical Safety and Lifecycle Management.”
DSA Chapter 8, “Hazardous Material Protection,” must incorporate the ALARA
approach, the elements to provide hazardous material exposure control, and facility
protection instrumentation.
7.11 Radiological and Hazardous Waste Management
Most processing facilities will generate waste. DOE-O-420.1B requires that facility
process systems be designed to minimize waste production and mixing of radioactive
and nonradioactive waste. Hazardous waste streams, including types, sources, and
quantities should be identified early in the design and prevention practices, such as
substitution of less hazardous materials in a project or design of a process to reduce
generation of hazardous waste, should be examined to reduce management costs of
these waste streams. Management strategies for these waste streams including
Section 52
DOE-STD-1189-2008
Page 62
storage and treatment and disposal systems must be described in the DSA. Any
potential for accidental releases from waste handling and treatment systems should be
addressed during the hazard analysis process in the preliminary and detailed design
processes.
7.12 Emergency Preparedness
DOE O 151.1C and its accompanying guidance set, the DOE G 151.1-series,
establish specific requirements and methods for the Emergency Management
Program (EMP). Early integration of EMP considerations into the safety
design process can provide opportunities to minimize the hazardous nature of
operations and to improve the ability to respond if an emergency occurs.
There is much that can be gained in project integration between the EMP and the
hazard analyses conducted for the safety analysis.
At the early stages in the project, only major hazards are likely to be known. EMP
SMEs, designers, and safety analysts can work together to identify options that may
be less hazardous. Incorporating instrumentation, hardware, and related requirements
into the design can improve the ability to detect emergency situations during
operations. Early recognition of an event is essential to enable potentially affected
workers and the public to take actions to prevent or limit their exposure to hazardous
materials. Provisions in the design may be appropriate to support recovery and re-
entry.
The Emergency Planning Hazards Assessment (EPHA) for the EMP starts from the
hazards analyses that support the safety design basis. The EPHA must include
accident sequences where safety controls fail, as well as accidents that are beyond the
design basis for a facility. DOE-HDBK-1163-2003 provides guidance for features of
the EPHA that go beyond the scope of the hazards analyses that support design. EMP
SMEs and project safety analysts should work together to define and analyze these
scenarios.
7.13 External Reviews
The safety documentation development effort should anticipate and prepare for
external interfaces and reviews. Periodic reviews are required by DOE project
oversight. In addition, external reviews are conducted by DOE pursuant to nuclear
safety rules (i.e., 10 CFR 830, 835). The principal DOE external safety design basis
reviews and approvals will be of the Conceptual Safety Design Report (CSDR),
Preliminary Safety Design Report (PSDR), and PDSA, and, of course, review and
approval of the operational DSA and Technical Safety Requirements (TSR).
Periodic formal project reviews, particularly those at the major project approval
stages, are required by DOE O 413.3A, Chg 1. The safety documentation
development team should anticipate supporting these reviews. The team should
DOE-STD-1189-2008
Page 63
expect focused reviews on safety functional classification determinations in relation
to potential cost drivers for the project.
The Defense Nuclear Facility Safety Board (DNFSB) is an independent oversight
agency with purview of nuclear safety at DOE defense nuclear facilities. The
DNFSB evaluates the effectiveness of DOE regulatory oversight activities and the
safety of defense nuclear facility design, construction, operations, and
decommissioning. Various DOE defense nuclear sites have resident DNFSB staff
located with the DOE Site Operations Offices. The resident staff can, and typically
will, participate in reviews of the project at any stage. Additionally the DNFSB
conducts their own review of the proposed facility design, including the safety design
basis development and construction, when determining the adequacy of project
nuclear safety and the effectiveness of DOE oversight.
Section 53
Other external regulatory reviews performed for the purpose of permitting activities
are conducted by independent agencies (local, state, and Federal) pursuant to
environmental regulations such as the Resource Conservation and Recovery Act,
Clean Air Act, and Clean Water Act. Typically, these permits or site permit
modifications are approved before formally declaring facility readiness. In certain
situations, the state may establish limiting criteria on design (e.g., zero release
criteria) that may be more limiting on the design and operation than the requirements
derived from safety design basis development.
The project manager should anticipate and identify all stakeholders that could affect
the development of the safety design case. Once identified, regular interaction with
these key oversight groups should be planned to minimize unanticipated issues at
critical review steps.
7.14 System Engineer Program
DOE O 420.1B requires application of a System Engineer (SE) program to “active
safety class and safety significant SSCs as defined in the facility’s DOE-approved
safety basis, as well as to other active systems that perform important defense-in-
depth functions, as designated by facility line management.” An objective of the
program is to ensure operational readiness of systems within scope. This objective
translates into ensuring proper configuration management of the systems and
associated documentation and requirements. SE program requirements are also
aimed at supporting operations and maintenance.
In preparation for the operational phase, it will be important to identify SEs and
involve them in the design and hazard analysis process. Ideally, this should begin in
the final design phase so that they may become familiarized with the design in
preparation for more direct involvement in the construction phase. SEs should be
involved in the planning for and conduct of system testing to allow detailed
operational understanding. The SEs should also have a fundamental understanding of
the safety function and performance requirements for their assigned system, as well
as for the associated design and safety documentation. Proper SE preparation will
help facilitate a smooth transition to routine operation and maintenance following
DOE-STD-1189-2008
Page 64
approval for operations.
7.15 Procedures, Training and Qualification
A systematic approach to operations involves the development of operating
procedures based on the design and identified hazard controls to operate SSCs within
their design and DOE authorized limits through the TSRs. In turn, operators are
trained on applicable process and hazard fundamentals, SSC operations and functions,
and specific operating procedures. Operators are expected to understand important
safety system features and any specific administrative controls, as well as the
operator’s role in the safety of the facility.
In order to satisfy expectations, the results of the safety and design process must be
incorporated into the procedures and training programs. This includes nuclear
criticality safety-derived requirements as well. System operating and test procedure
development should begin in the detailed design phase. System description
documents should be used as a tool to capture both operating intent and safety design
information for use by the safety analysts and procedure writers. Draft qualification
requirements should begin in parallel with detailed design and should be completed
early in the construction phase. Training will ensue in the construction phase.
Section 54
DOE-STD-1189-2008
Page 65
Table 7-1. Typical Actions Associated with Project Life-Cycle Stages
Actions Authorized by Critical Decision Approval
Phase
Interface
Mission Need Conceptual
Design
Preliminary
Design Detailed Design Construction
Resource
Requirements
and Guidance
QA • QA strategy • Update QA Plan
• Conduct
assessments
• Assessments
• Assessments
• Input to DSA Ch.
14
• 10 CFR 830
• DOE-O-414.1C
Fire Protection • Identify major fire
scenarios and
special fire
considerations for
input to likely
safety SSC
designation
• Develop
Preliminary FHA
• Separation of SSCs
• Life Safety –
Egress
considerations
(approach)
• Identify Fire Areas
• Preliminary
Functional
classification
• Define design
codes and
standards
• FHA update
• Design Basis Fire
defined
• Fire barrier design
and fire areas
finalized
• AHJ review of
building layout
• FHA update
• Support PDSA
development
• Final FHA
• Prepare DSA Ch.
11
• DOE-O-420.1B
• DOE-O-440.1
• DOE-STD-1066
• 10 CFR 851
• DOE G 420.1-3
DOE-STD-1189-2008
Page 66
Actions Authorized by Critical Decision Approval
Phase
Interface
Mission Need Conceptual
Design
Preliminary
Design Detailed Design Construction
Resource
Requirements
and Guidance
Criticality Safety • Determine
criticality potential
• Input to Hazard
Categorization
• Criticality Control
Philosophy
• Criticality
guidance for
Design
• Preliminary CSEs
• Updated criticality
safety design
requirements
• Updated
preliminary CSEs
• Re-assess
criticality limits
and controls based
on design and
operating the
process/facility
• CSE input to
PDSA (Hazard
Analysis and TSR
derivation)
• Update and issue
CSEs
• TSRs and
operating
procedures will
incorporate
criticality controls,
as developed under
the guidance of
DOE-STD-3007
and DOE G 423.1-
1.
• Validate NCS
controls in field\
• Prepare DSA Ch. 6
• DOE-O-420.1B
• DOE-STD-3007-
2007
• DOE-G-421.1-1
• Radiological
Protection
• ALARA strategy
• ALARA Review
• Preliminary
Shielding Analysis
(Facility Layout
and Material
Location and
Quantity)
• ALARA
Considerations in
Design
• Contamination
Control
• Zoning
• Final Shielding
Analysis
• ALARA review
• Monitoring (area
and personnel)
• Input to DSA Ch. 7 • 10 CFR 835
• DOE G 441.1-1B
DOE-STD-1189-2008
Page 67
Actions Authorized by Critical Decision Approval
Phase
Interface
Mission Need Conceptual
Design
Preliminary
Design Detailed Design Construction
Resource
Requirements
and Guidance
Human Factors • Define HF strategy
and goals
• HF Engineering
Plan HF
Preliminary
Review
• HF Review • Prepare DSA Ch.
13
• DOE-HDBK-
1140-2001
Security • Draft Safeguards
Requirements
Identification
(SRI)
• SRI
• Design reviews • Design Review • Security Plans • DOE-O-470.3
• DOE-O-470.4
Environmental
Protection
• EPA
• State
Environmental
Agency
• NEPA Strategy
and Analysis
• EPA
• State
Environmental
Agency
• Draft NEPA
Documents
• Final NEPA
Documents
• 10 CFR 1021
• DOE O 451.1B
• DOE O 450
Hazardous
Materials
ALARA strategy • Toxicological
Material Hazards
Analysis
• Contamination
Control
• Refine inventories
• Codes and
Standards defined
• Zoning
• ALARA review
• ALARA reviews
• Codes and
Standards
Implementation
• Monitoring (area
and personnel)
requirements
• Prepare DSA Ch. 8 • DOE-O-440.1A
DOE-STD-1189-2008
Page 68
Actions Authorized by Critical Decision Approval
Phase
Interface
Mission Need Conceptual
Design
Preliminary
Design Detailed Design Construction
Section 55
Resource
Requirements
and Guidance
Radiological and
Hazardous Waste
Management
• Identify major
waste streams
• Fundamental
approach defined
• Develop waste
handling designs
• Prepare DSA
Section 9
• 10 CFR 830
• DOE-O-420.1B
• 10 CFR 850
• DOE O 435.1
Emergency
Preparedness
• Emergency
Preparedness
Hazard Survey and
Screen
• Update Emergency
Preparedness
Hazard Survey and
Screen
• Coordinate hazard
evaluations
• Preliminary EPHA
• Update EPHA • EPHA updated and
finalized
• ERP updated and
finalized
• Prepare DSA Ch.
15
• 29 CFR 1910.119
• 40 CFR 68
• DOE-O-151.1C
External Reviews
• DNSFB
• Project Review
• SDS review
• DNFSB
• CSDR Review
• Project Review
• DNFSB
• PSDR Review
• Project Review
• DNFSB
• PDSA Review
• Project Review
• DNFSB
• DSA/TSR Review
• ORR/RA (as
applicable)
• DOE-O-226.1
System Engineer
Program
• Define systems
requiring SE
• Identify SEs
• SEs participate in
Final Design
• SEs support testing
• DOE-O-420.1B
DOE-STD-1189-2008
Page 69
Actions Authorized by Critical Decision Approval
Phase
Interface
Mission Need Conceptual
Design
Preliminary
Design Detailed Design Construction
Resource
Requirements
and Guidance
Procedures,
Training and
Qualification
• Identify training
and qualification
needs
• Develop draft
operating and
maintenance
procedures
• Define operator
qualification
requirements
• Complete
procedures
• Develop and
conduct training
• Input to DSA Ch.
12
• DOE O 5480.20A
DOE-STD-1189-2008
Page 70
Table 7-2. Example Nuclear Criticality Safety Design Criteria
Attribute Criteria
Geometrically safe designs
1. Storage tanks, process piping, containers, etc. shall be
designed for conservative enrichment or optimal
concentration and reflection for all anticipated nuclides.
2. Designs shall be based on worst-case fire suppression
actuation or local pipe breaks.
3. Leaks from solution areas should be anticipated and
flooring designed to be compatible with solutions and
provide collection capability (prevent long-term
migration of fissionable material into sub-flooring
materials).
4. Fissionable containing piping shall be spaced to preclude
neutron interaction.
Layout processes to support
material flow
1. Fissionable solution piping shall be arranged to
minimize or eliminate manual transfers.
2. Transfers from safe to non-geometrically safe geometry
shall be provided with engineered controls.
3. Avoid any favorable to unfavorable geometry solution
transfers. If such need to be made, active design
features should be installed to mitigate the potential for a
criticality accident due to transfer of fissionable solution
to an unfavorable geometry vessel.
System design for holdup
minimization
1. Employ vertical tanks to facilitate particulate collection
and monitoring.
2. Provide methods to facilitate holdup verification/assay.
3. Locate filtration on exhaust systems as close to main
processing loop as possible.
Maximize use of passive
design features
1. Utilize positive isolation techniques to prevent
unmonitored backflow potential (e.g., air breaks).
2. Avoid common ties between fissionable and non-
fissionable systems.
3. Designs must eliminate potential for water ingress into
fissionable material processes and containers in the event
of fire.
Standardize Equipment
1. Storage racks shall be modular and prevent relocation of
fissionable material up to the seismic DBA.
2. Gloveboxes shall be designed to address concerns
associated with spills or in-leakage of moderators.
3. All process equipment must withstand the facility
seismic DBA.
DOE-STD-1189-2008