SnSD Consultants
SnSD Consultants • Process Safety Thought Leadership Series

FROM VERIFIED TO LIVE

A Practical Model for Making Safety-Critical Barrier Health Visible and Actionable

How Barrier Thinking, Performance Standards, assurance data, work processes and role-based competence come together in a Live Barrier Model.

Scroll to explore
Podcast Version

FROM VERIFIED TO LIVE

Executive Summary

Periodic verification confirms that a safety-critical barrier met its requirements at a particular point in time. Live Barrier Management extends that assurance by bringing current maintenance, inspection, testing and deviation information into an operational view of barrier health. It helps the organisation understand not only what is safety critical, but whether the barrier function remains available and what response is required when its condition changes.

This paper sets out a practical model for implementing a Live Barrier Model (LBM) across complex operating assets. The model starts with Barrier Thinking and the major accident scenario, connects barriers to Safety Critical Equipment (SCE), defines measurable Performance Standards, captures current assurance evidence and translates changes in barrier condition into owned and time-bound operational decisions.

The principles are supported by evidence from a multi-asset implementation covering five operating assets. The experience included the review of 109,057 functional locations, the identification of 25,685 safety-critical items and the use of a common structure of 41 SCE groups and 41 Performance Standards per facility. The initial capability modules generated 924 recorded training attendances across Operations, Maintenance, Planning, Engineering and Process Safety roles.

5
operating assets
109,057
functional locations reviewed
25,685
items identified as safety critical
924
recorded attendances in initial modules

The figures demonstrate the scale at which the method has been applied. They should be read as evidence of implementation reach and design discipline, rather than as final claims of sustained operational performance.

1. The Assurance Gap

SCE registers answer an essential question: which equipment and activities are required to prevent or mitigate a major accident? Performance Standards define what those barriers must achieve, while maintenance and inspection systems record the work intended to preserve their function. None of these elements, considered separately, provides a complete view of current barrier health.

The gap appears between formal verification events. A functional test may have been completed successfully, but a later defect, override, temporary repair, overdue assurance activity or expired deviation can change the confidence that the barrier will perform on demand. Periodic verification remains necessary; the LBM adds the operational link required to keep that evidence current and usable.

Barrier-management guidance therefore places emphasis on knowing the status of barriers during operation, not only at the point of a scheduled test or review [2]. The practical challenge is to combine evidence from different systems without losing the relationship between the equipment condition and the risk-control function it supports.

2. Barrier Thinking: Starting with the Major Accident Scenario

Barrier Thinking starts with the unwanted event rather than the equipment list. It considers the threats that may lead to a major accident, the preventive and mitigative barriers intended to control it, and the Safety Critical Equipment and activities required for those barriers to perform. Common barrier definitions and bow-tie methods provide a consistent language for making those relationships explicit [3][4].

Figure 1. Relationship between a major accident scenario, its preventive and mitigative barriers, and the supporting hardware barrier categories.
Figure 1. Relationship between a major accident scenario, its preventive and mitigative barriers, and the supporting hardware barrier categories.

This approach changes how maintenance and inspection information is interpreted. A defect is not assessed solely by technical severity, work-order age or equipment class. It is considered in terms of the safety function affected, the condition of the remaining barriers and the resulting change in major accident exposure.

An overdue activity on a pressure relief valve, for example, is more than a scheduling issue. The relevant questions are whether the valve's required function can still be demonstrated, which overpressure scenario it protects against, what other barriers remain available and what action is needed while uncertainty persists.

In practical terms, an LBM operationalises Barrier Thinking by linking current equipment, work and assurance information back to the barrier and scenario it supports. This is what allows prioritisation to move beyond backlog age or equipment count alone.

3. What Makes a Barrier Model Live

An LBM combines information from the computerised maintenance management system, inspection or asset-performance systems, and deviation or Management of Change records. The model maps these signals to the relevant SCE, barrier group and major accident scenario, then applies agreed rules to produce a current barrier-health view.

Figure 2. Multiple source systems contribute to one current and traceable view of barrier health.
Figure 2. Multiple source systems contribute to one current and traceable view of barrier health.

The word "Live” does not necessarily mean that every source updates second by second. It means that the information is refreshed at a frequency appropriate to the decisions being made, and that changes in maintenance, inspection or deviation status pass through a controlled data and governance process. The status displayed should always be traceable to the underlying evidence.

From condition data to barrier status

The classification logic must be explicit. An effective barrier meets its Performance Standard and has current assurance evidence. A degraded barrier may retain some function (partially effective), but a known defect, overdue activity or temporary condition requires active management. A barrier is ineffective when the required safety function is unavailable (Impaired) or when restoration, assurance or temporary risk controls have exceeded agreed limits.

Figure 3. Illustrative status logic. Exact thresholds should be defined through Performance Standards, impairment criteria and deferral rules.
Figure 3. Illustrative status logic. Exact thresholds should be defined through Performance Standards, impairment criteria and deferral rules.

Impairment is a condition the operating model is designed to identify and control. Ineffectiveness reflects a more serious loss of assurance: either the safety function is not available or the organisation can no longer demonstrate that the exposure remains within its own risk-management rules.

4. Turning Performance Standards into Operational Evidence

Performance Standards define the functional, availability, reliability and survivability requirements that an SCE must meet. They also provide the acceptance criteria against which continued performance can be demonstrated. Guidance on SCE management treats these standards and their assurance arrangements as central to maintaining the integrity of major-accident barriers [5].

The assurance task translates the Performance Standard into routine work: a test, inspection or maintenance activity with a defined frequency, method and result-recording requirement. If the result falls outside the acceptance criteria, the work process should create the relevant notification, impairment classification and follow-on action.

Figure 4. An assurance task connects the Performance Standard to a test, acceptance criterion, recorded result and impairment decision.
Figure 4. An assurance task connects the Performance Standard to a test, acceptance criterion, recorded result and impairment decision.

Task completion alone is therefore not evidence that a barrier is effective. The result must be recorded against the correct equipment, assessed against the relevant criterion and reflected in the barrier-health logic. A closed work order with missing, ambiguous or untraceable evidence may still leave the organisation unable to demonstrate that the safety function is available.

5. From Visibility to Action

Visibility creates value only when it is linked to a defined response. The operating model should specify who owns a degraded barrier, how quickly the safety function is expected to be restored, when compensating measures are required and who has the authority to approve continued operation.

Where immediate restoration is not feasible, the decision should be governed through formal deferral management supported by a proper risk assessment. A sound assessment considers the affected major accident scenario, the condition of the remaining barriers, proposed compensating measures, the approval authority and the period for which the decision remains valid. The LBM should retain the deviation, its expiry and its current status so that temporary control does not become unmanaged exposure.

This approach also changes work prioritisation. An overdue test or open defect is no longer viewed only as an item in a maintenance backlog. Its effect on a major accident barrier becomes visible, allowing planning and leadership discussions to focus on risk significance and restoration requirements.

6. Addressing Pitfall No. 10

Our earlier Hardware Barrier Management thought leadership identified insufficient training and coaching as one of the ten most common causes of implementation failure. The warning sign was that teams could operate the system mechanically but did not understand the risk logic behind it [1].

This gap becomes more consequential in Live Barrier Management. Users are expected to interpret changing barrier conditions, distinguish between different levels of degradation and determine when restoration, escalation or formal risk assessment is required. A technically accurate status may still lead to an inappropriate response if the person reviewing it does not understand the safety function, the affected major accident scenario or the condition of the remaining barriers.

Figure 5. Excerpt from the earlier Hardware Barrier Management paper: Pitfall No. 10.
Figure 5. Excerpt from the earlier Hardware Barrier Management paper: Pitfall No. 10.

The response is therefore not a short software-onboarding exercise. Capability building must be designed around the operational decisions required to manage barrier health. The model provides visibility; organisational capability determines whether that visibility leads to the right decision.

A curriculum that follows the risk logic

The curriculum follows the sequence of decisions used to manage barrier health. It begins with Barrier Thinking and the relationship between major accident scenarios, barriers and SCEs; establishes the required performance and assurance evidence; and then develops the capability to interpret current status and govern deviations when immediate restoration is not possible.

ModuleWhat it builds
Live Barrier Management and SCE AwarenessBarrier Thinking, major accident scenarios, barrier types and the purpose of a current barrier-health view.
SCE Identification and Performance StandardsSCE boundary conditions, SCE assignment, Performance Standards, acceptance criteria and assurance requirements.
Assurance Task Management and Impairment AssessmentPreventive maintenance alignment, result recording, work requests, impairment criteria and work prioritisation.
LBM Tool and DashboardInterpretation of barrier health by asset, SCE group and scenario, including the action required from each role.
Deferral ManagementRisk assessment, approval levels, bypass and temporary MOC controls, monitoring, expiry and close-out.

The implementation evidence reviewed for this paper recorded 924 attendances across the initial three modules, covering LBM and SCE awareness, SCE identification and Performance Standards, and assurance-task management and impairment assessment. Participants came from Operations, Maintenance, Planning, Engineering and Process Safety. The significance lies not only in the volume of attendance, but in the breadth of the decision chain covered - from the people identifying equipment condition to those planning restoration work and assessing remaining risk.

Figure 6. Training should follow the barrier decision chain, from recognising a condition to closing the exposure.
Figure 6. Training should follow the barrier decision chain, from recognising a condition to closing the exposure.

What Training Changes

The intended outcome is not platform proficiency alone. Training should change how work is understood and prioritised. Operators need to recognise when equipment condition affects the required safety function. Maintenance and Integrity teams need to understand what an assurance task proves and how the result should be recorded. Planners need to distinguish routine backlog from work that affects a major accident barrier. Technical authorities need to evaluate remaining barriers and compensating measures before accepting a temporary deviation, while leaders need to recognise when an activity delay represents a change in current risk exposure.

When these capabilities are developed across functions, the same barrier condition is more likely to produce a consistent response: clearer ownership, risk-based work priority, timely restoration and controlled deferral. Early implementation experience indicated that this shared understanding helped bring previously under-recognised safety-critical issues, including pressure-relief equipment, into routine barrier-health discussions and work prioritisation.

This should not be interpreted as evidence that training alone produced the operational improvement. The effect came from the combination of clearer technical rules, improved data visibility, defined workflows and greater role competence. Training enabled people to use those elements as one connected risk-control system.

From Learning to Sustainable Ownership

Training delivery should be followed by coaching, application in normal work and assessment of implementation effectiveness. Course completion confirms participation; it does not demonstrate that the required judgement has become part of routine operations. Users should be able to apply the model to real conditions, explain the risk logic and complete the decision expected from their role.

The intended result is not long-term dependence on a central project team or a small group of specialists. It is an organisation in which barrier-health information is understood and acted upon by the functions that own the equipment, execute the work and manage the risk. Once this capability is established, the next challenge is to apply it consistently across assets with different equipment hierarchies, maintenance practices and data systems.

7. Scaling the Model Across Multiple Assets

Multi-asset implementation requires a deliberate balance between standardisation and local configuration. Barrier terminology, SCE taxonomy, Performance Standard structure, status rules and core governance should be consistent. Equipment hierarchies, maintenance workflows, system interfaces, approval routes and operating routines must reflect how each asset actually works.

Figure 7. Standardise the common risk logic; configure the workflows and data interfaces required by each asset.
Figure 7. Standardise the common risk logic; configure the workflows and data interfaces required by each asset.

The implementation experience underpinning this paper tested that balance across five operating assets. A common structure was applied to 109,057 reviewed functional locations and 25,685 identified SCE items, while differences in maintenance and inspection systems required asset-specific configuration. This is a normal feature of large-scale implementation, not an exception.

The traceability of the data objects is more important than the size of the dataset. The model should preserve the chain between functional location, SCE group, Performance Standard, assurance measure, maintenance plan, work order, recorded result and notification. A visually strong dashboard cannot compensate for incomplete hierarchies, inconsistent task descriptions, missing target values or unreliable status fields.

8. What Good Looks Like

A useful LBM should improve the organisation's ability to recognise degradation, prioritise restoration and govern temporary exposure. Its effectiveness cannot be demonstrated by a single dashboard metric. A balanced set of technical, operational and capability measures is required.

MeasureWhat good looks like
SCE and data coverageIdentified SCEs have complete master data, traceable source records and clear links to the relevant barrier and Performance Standard.
Assurance-task alignmentTasks, frequencies, acceptance criteria, target values and result-recording requirements are defined and consistently applied.
Restoration performanceImpaired barriers are visible by age and risk significance, with performance tracked against the agreed restoration expectation.
Deferral governanceOpen, overdue and expired deviations are controlled through adequate risk assessments, compensating measures and approval levels.
Role competencePeople can explain the risk logic, complete the required workflow and make the decision expected from their role.

Conclusion

A Live Barrier Model is not a substitute for sound Hardware Barrier Management. It depends on clearly identified SCEs, measurable Performance Standards, effective assurance tasks and disciplined deviation management. What it adds is the ability to connect current evidence to barrier function and make that information usable in daily operational decisions.

The implementation experience described in this paper shows that the model is most credible when four elements are designed together: technical rules, source data, work processes and organisational competence. Weakness in any one of them reduces confidence in the status being presented. When they are aligned, barrier-health information can become part of normal operating governance rather than a separate Process Safety report.

The practical test is whether a change in barrier condition leads to a timely, risk-informed and owned response. That is the point at which verification becomes live assurance.

Questions Leaders Should Be Able to Answer

1Can we identify which safety-critical barriers are currently degraded, which major accident scenarios they affect and how long the condition has remained open?
2When immediate restoration is not feasible, are the remaining barriers, compensating measures, approval authority and expiry date clearly governed?
3Do the people creating and reviewing the status understand the Performance Standard, impairment logic and decision required from their role?
4Can we demonstrate that the model is improving work prioritisation and restoration performance rather than simply creating another reporting layer?

References

1. SnSD Consultants. When Everything Is Critical, Nothing Is: Why Hardware Barrier Management Projects Fail - and the Evidence They Do Not Have To. Process Safety Thought Leadership Series, 2026.

2. Petroleum Safety Authority Norway (Havtil). Principles for Barrier Management in the Petroleum Industry, 2013; revised 2017.

3. International Association of Oil & Gas Producers (IOGP). Report 544: Standardization of Barrier Definitions.

4. Center for Chemical Process Safety and Energy Institute. Bow Ties in Risk Management: A Concept Book for Process Safety, 2018.

5. Energy Institute. Guidelines for the Management of Safety Critical Elements.