SnSD Consultants logo
SnSD Consultants • Process Safety Thought Leadership Series

When Everything Is Critical, Nothing Is.

Why Hardware Barrier Management Projects Fail — and the Evidence They Don’t Have To

Scroll to explore

Opening Insight

70k out of 110k items were labelled as Safety Critical Equipment.
“You cannot manage what you cannot see.”

The first step is not fixing barriers. It is knowing which ones truly matter.

Most of them not systematically verified. That was the starting point for one of our transformation programmes. The actual effectiveness of the equipment that – which must be labelled as safety critical — had never been baselined, validated or consistently monitored. In addition, there was a significant maintenance backlog where the risk was not clear as SCE were not identified. The barriers existed on paper. Whether they would perform when there is a demand was, at best, assumed.

This is the most common and the most dangerous gap in Hardware Barrier Management: the distance between what is documented and what is genuinely in control. Across the industry, many organisations have initiated Safety Critical Equipment (SCE) or Hardware Barrier Management programmes with good intentions. A significant proportion fail to deliver lasting results. The root causes are rarely technical. They are systemic.

The Universal Challenge: Paper Barriers vs. Real Barriers

Most of the Process Safety incidents occur not because there were missing barriers but the existing barriers were not health i.e. effective. They are ineffective because the barriers that were believed healthy were actually degraded or unverified. The Baker Panel report following the Texas City refinery disaster[1] and the Buncefield investigation[2] both point to the same structural failure: safety management systems that generated confidence in protection that did not, in practice, exist.

The UK HSE’s framework for Process Safety Leadership describes this as the gap between ‘the work as imagined’ and ‘the work as done.’[3] Hardware Barrier Management exists precisely to close that gap — to move from assumed control to demonstrable, sustained assurance. But only if the programme is implemented correctly.

Barrier Health as a Leading Indicator

Process Safety Overview KPI visual with Tier 1, Tier 2, Tier 3 and Tier 4 indicators
Figure 3. Process Safety KPIs (API RP 754 Standard) used to structure performance monitoring and risk discussions.

Industry guidance — including IOGP Report 456 on Process Safety KPIs [4] and API RP 754[5] — consistently identifies Safety Critical Equipment effectiveness as the clearest leading indicator of real risk control. Not incident counts, not audit scores. Barrier health.

Lagging indicators tell you what happened. Leading indicators give early warning. Barrier health indicators tell you whether your defences will hold — before you need them to.

Why Projects Fail: The 10 Most Common Pitfalls

Based on nearly two decades of Hardware Barrier Management delivery across multiple regions and asset types, the same issues repeatedly undermine implementation. These are not theoretical risks. They are observed patterns — and they are predictable, which means they are preventable.

The table below is designed as a practical diagnostic. Use it to assess your own programme before, during, or after implementation. The three categories — Foundation, Governance, Execution — reflect where in the delivery lifecycle each failure typically occurs.

1

Prerequisites not in place before project start

Asset register is incomplete or unvalidated; SCE scope cannot be agreed before work begins
2

Work process not clearly defined or documented

No SCE Identification & Management Manual; no deviation or deferral procedure exists
3

SCE boundary conditions and selection criteria unclear

Different disciplines apply different definitions; scope creep leads to everything being 'critical'
4

Learnings from similar projects not incorporated

Project plan mirrors previous failed attempts; known pitfalls are re-encountered rather than avoided
5

Project management disciplines not applied

No stage gates, KPIs or governance cadence; delivery milestones are informal and untracked
6

Change management not implemented

Stakeholders are informed rather than engaged; resistance surfaces late; impact assessments absent
7

Project team not onboarded; roles and responsibilities unclear

Accountability gaps between Reliability, Integrity, Maintenance and Operations and Process Safety are unresolved
8

Handshakes not completed; end-user acceptance not obtained

System is configured and 'handed over' but frontline teams do not own or trust the outputs
9

Maintenance execution not effective

PM and CM backlogs persist; inspection and testing timelines are not met; impairments accumulate silently
10

Training and coaching insufficient

Teams can operate the system mechanically but do not understand the risk logic behind it
Table 1: Hardware Barrier Management — Project Readiness Diagnostic
# Pitfall Warning Sign in Your Organisation
1Prerequisites not in place before project startAsset register is incomplete or unvalidated; SCE scope cannot be agreed before work begins
2Work process not clearly defined or documentedNo SCE Identification & Management Manual; no deviation or deferral procedure exists
3SCE boundary conditions and selection criteria unclearDifferent disciplines apply different definitions; scope creep leads to everything being 'critical'
4Learnings from similar projects not incorporatedProject plan mirrors previous failed attempts; known pitfalls are re-encountered rather than avoided
5Project management disciplines not appliedNo stage gates, KPIs or governance cadence; delivery milestones are informal and untracked
6Change management not implementedStakeholders are informed rather than engaged; resistance surfaces late; impact assessments absent
7Project team not onboarded; roles and responsibilities unclearAccountability gaps between Reliability, Integrity, Maintenance and Operations and Process Safety are unresolved
8Handshakes not completed; end-user acceptance not obtainedSystem is configured and 'handed over' but frontline teams do not own or trust the outputs
9Maintenance execution not effectivePM and CM backlogs persist; inspection and testing timelines are not met; impairments accumulate silently
10Training and coaching insufficientTeams can operate the system mechanically but do not understand the risk logic behind it

Table 1: Hardware Barrier Management — Project Readiness Diagnostic

The most consequential pitfalls are typically in the Foundation category. When prerequisites are absent and boundary conditions are unclear, every subsequent step builds on an unstable base. Governance and Execution failures are recoverable. Foundation failures almost always require a restart.

What Successful Programmes Do Differently

Successful Hardware Barrier Management programmes address these pitfalls upfront. They establish foundations before selecting tools, define governance before configuring systems, and build ownership before expecting operational accountability. The distinction is not philosophical — it is structural.

Foundations First

Verified asset register. Agreed SCE boundary conditions. Clear SCE Identification & Management Manual. Learnings from comparable projects formally incorporated before mobilisation.

Governance Before Configuration

Stage-gate delivery plan. Stakeholder engagement from day one. Defined roles across Reliability, Integrity, Maintenance and Operations. End-user acceptance built in, not bolted on.

Ownership Before Automation

Training and coaching at sufficient depth. Teams understand the risk logic, not just the system mechanics. Handshakes completed. Frontline ownership secured before go-live.

Figure 1: SnSD Hardware Barrier Management — Three Pillars of Successful Implementation

When these elements are treated as prerequisites rather than lessons learned after the fact, programmes deliver lasting value.

Our partners at SnSD has led Hardware Barrier Management projects for nearly two decades across multiple regions and asset types. By establishing strong foundations, applying structured delivery frameworks, onboarding and training teams, configuring maintenance systems correctly, and operationalizing processes in the field, sustainable results can be achieved.

In practice, this approach has enabled significant improvements in project delivery and the establishment of effective Hardware Barrier Management systems for multi-asset organisations in less than 18 months.

Global Experience

World map showing Canada, USA, Trinidad and Tobago, UK, Ireland, Norway, Netherlands, Turkey, Egypt, Nigeria, Cameroon, Gabon, Russia, Azerbaijan, Syria, Kazakhstan, Oman, China, Philippines, Malaysia, Brunei and New Zealand

Our Approach: Collaborative, Grounded in Operations

Process Safety
Reliability
Integrity
Maintenance

At SnSD, our approach to SCE identification and management is deliberately collaborative. We do not arrive with pre-defined lists or generic templates. We work side-by-side with Process Safety, Reliability, Integrity, and Maintenance teams to identify what truly prevents major accidents in your assets and operating context.

Together, we define the Safety Critical Equipment, clarify their performance standards, and test whether those standards are practical, measurable, and genuinely understood by those responsible for delivering them. This co-creation approach builds ownership, strengthens interfaces between functions, and ensures SCEs move beyond documentation into day-to-day decision-making and execution.

The Process Safety Triangle provides the governance framework that holds this together: not as an abstract model, but as a structured view of how major accident risk is actually managed — from outcomes, to barrier integrity, to the activities that sustain it.

Leadership discussions should not ask: ‘What happened?’ They should ask: ‘How strong are our barriers today?’ That shift requires a system that makes the answer visible.

Case Study 1 — From Assumed Control to Demonstrable Assurance

The Starting Point

Many items had already been labelled as Safety Critical Equipment; however, for a significant portion of them, their effectiveness had not been systematically verified or baselined. Hazard studies or baselines were missing for many of the already identified SCEs. Definitions were applied inconsistently across disciplines. There was no consolidated, validated SCE register, and no clear view of how many items were genuinely safety-critical. Decision-making relied on assumptions rather than structured assurance.

The Intervention

From Assumed Barriers to Verified Effectiveness

Rather than inheriting legacy lists or applying generic templates, the program began with a fundamental reset:

“Before managing Safety Critical Equipment, we must first agree on what is actually safety critical in this asset.”

1.
Identify SCE Performance Standards
2.
Align with Maintenance Strategies
3.
Execute performance assurance activities
4.
Manage deviations
5.
Analyze and Improve
Figure 4. Hardware Barrier or Safety Critical Equipment identification and management process

Using a structured 18-step Safety Critical Equipment identification and management process:

  • Identified SCE Performance Standards by defining major hazards, barriers, SCE groups, and performance requirements, then capturing the required SCE information in CMMS.
  • Aligned SCEs with Maintenance Strategies by linking each SCE to appropriate assurance tasks, maintenance strategies, and live barrier health monitoring requirements.
  • Executed Performance Assurance Activities by planning assurance work, recording results, analyzing findings, and identifying SCE assurance backlogs.
  • Managed Deviations by assessing risks, defining mitigating actions, executing those actions, and reviewing deviation approvals.
  • Analyzed and Improved SCE Performance by reporting SCE performance, reviewing SCE status, and driving continuous improvement of the verified SCE register.

This step alone created visibility where none previously existed.

At the point of first systematic identification, the true level of exposure became visible for the first time:

~0

Ineffective (A non-functional SCE device & it does not meet its performance standard) Safety Critical Equipment items identified at baseline

< 0

Months to establish full operational control

Figure 2: Baseline exposure at programme start — Refinery Case Study 1

The initial spike did not represent sudden loss of control. It represented the first time the organisation could see its true risk exposure. From this baseline, ineffective SCEs were reduced in a structured and prioritised manner. After 18 months, all the facilities reached ZERO ineffective barriers level, and that was sustained for the past 4 years.

Sustained at Zero — The Real Proof Point

Journey to Zero Ineffective Barrier chart
Figure 5. Journey to Zero Ineffective Barrier
Many organizations can drive numbers down temporarily. Far fewer can prevent them from rising again once attention shifts elsewhere. This Asset maintained zero ineffective Safety Critical Equipment for more than 4 years — under normal operating conditions, without extraordinary intervention.

The absence of rebound is the proof point. It confirms that SCE management moved beyond a project mindset and became part of how the facility operates day to day. This is the difference between improvement and assurance.

Case Study 2 — Refinery and Petrochemical Complex: From Unknown to Known

The Starting Point: When Everything Is Critical, Nothing Is

This asset had about 350,000 equipment items. SCE identification was not carried out yet, labelled or treated as safety critical. That meant no meaningful prioritisation of inspection or maintenance, persistent volumes of open SCE work orders, and no defined restoration expectation for impaired barriers. The organisation had coverage — but not control.

BEFORE

~0

Equipment

AFTER

~0

Of them were Safety Critical Equipment after structured identification

Figure 3: SCE scope reduction through structured boundary-condition identification — Refinery Case Study 2

Risk was not reduced by narrowing the scope; it was reduced by understanding which equipment truly matters and ensuring accountability. Through a structured, cross-functional identification process based on clear boundary conditions, the SCE population was refined from approximately 350,000 items to 47,000 true Safety Critical Equipment items.

The Intervention: Enforcing Restoration Discipline

With a clearly defined SCE population in place, the refinery introduced a 48-hour restoration rule. Any impaired SCE was expected to have its safety critical function restored within 48 hours. Where restoration was not feasible, a formal SCE Risk / Deferral Assessment was required — involving review of major accident scenarios, evaluation of remaining barriers, and definition of compensating measures. Deferral was not automatic. If risk could not be maintained within acceptable tolerance, postponement was not permitted.

To sustain this governance model, 32 Performance Standards were developed. Assurance tests were configured within GE API, SAP –GE API data flows were stabilised, and a Live Barrier Model was implemented to provide real-time visibility of barrier effectiveness, supported by integration with the Digital MOC system.

Results

SCE Open Work Orders chart showing Facility-1 and Facility-2 journeys to zero
Figure 1. Zero Impaired SCEs Journey
0

Impaired SCEs identified in initial diagnosis period

0

Impaired maintenance notifications (backlog item + new impaired items) closed within 4 months

0

Formal risk/deferral assessments governed

Zero

Impaired SCEs at 4-month mark — and sustained

Figure 2. Programme outcomes over 12 months — zero impaired SCEs achieved within 4 months and sustained thereafter

Over the 12-month programme, the organisation moved from operating in ‘unknown unknowns’ to governing risk within ‘known knowns’. Zero impaired SCEs were achieved within the first 4 months and sustained for the remainder of the programme.

The 48-hour restoration rule materially changed prioritisation dynamics. Barrier impairment became visible and time-bound, strengthening Operations –Maintenance alignment and giving leadership real-time transparency on risk exposure.

The next maturity milestone, targeted for 2027, is Zero Ineffective Barrier. An SCE is considered ineffective if impairment exceeds 48 hours without approved risk assessment, if assurance testing is overdue, or if temporary risk evaluations expire. The objective is clear: no barrier should exist whose effectiveness cannot be demonstrably verified when required.

This marks the shift from tracking maintenance activity to governing major accident risk.

That distinction matters more than any system configuration.

Risk Visibility

Known Knowns, Known Unknowns, Unknown Knowns and Unknown Unknowns risk visibility quadrant

From Paper to People — Where It Really Matters

Hardware Barrier Management is not a technology project or a data exercise. It is a risk governance commitment. When SCEs are clearly defined and embedded into routine work, they shift from compliance artefacts to operational risk controls. Major accident prevention is not won in policy documents — it is won in how barriers are owned, prioritised, and acted upon in daily operations.

The two case studies in this article share the same underlying logic: visibility precedes control, and control precedes assurance. Neither refinery achieved sustainable results by deploying better software or writing more detailed procedures. They achieved it by defining clearly what mattered, holding organisations accountable to it, and refusing to tolerate the ambiguity of assumed protection.

The 10 pitfalls described in this thought leadership series are not inevitable. They are predictable — and that means they can be designed out. Every item on that checklist represents a decision that can be made before the project begins rather than a lesson learned after it fails.

How many of your Safety Critical Equipment items can you verify as effective — right now? If that question cannot be answered with confidence, that is where the work begins.

References

References
  1. Baker Panel Report — The Report of the BP U.S. Refineries Independent Safety Review Panel (2007). Available at: csb.gov
  2. Buncefield Major Incident Investigation Board — Final Report (2008). Available at: buncefieldinvestigation.gov.uk
  3. UK Health and Safety Executive — Process Safety Leadership in the Major Hazards Industries (2016).
  4. IOGP Report 456 — Process Safety – Recommended Practice on Key Performance Indicators (2011, updated).
  5. American Petroleum Institute — API RP 754: Process Safety Performance Indicators for the Refining and Petrochemical Industries (2016).
  6. Energy Institute — Guidance on Meeting the Expectations of the Process Safety Management Framework (2020).