Blog/Workplace Safety

Workplace Safety

When 11 controls fail: what the Shell Monaca explosion teaches about engineered safeguards and HMI

At Shell Monaca, 11 administrative controls did not prevent cracked gas from flowing back into a furnace with lit pilots. The CSB report shows why safeguard quality, HMI and operating modes must be treated as one system.

Technical analysis of the CSB final report on the Furnace 5 explosion at Shell Polymers Monaca, focusing on safeguard independence, administrative controls, HMI, human factors, PHA, SIS and operating modes.

In brief: eleven controls were not eleven independent safeguards

The June 4, 2025 explosion at Furnace 5 occurred after flammable cracked gas backflowed from downstream equipment into the firebox and met lit pilots. The U.S. Chemical Safety Board determined that the inadvertent simultaneous opening of two motor-operated isolation valves created that unintended path.

The final report catalogued 11 administrative controls intended to prevent or mitigate the scenario. In the conditions of the event, they failed, were unavailable, did not apply to the actual configuration or were not performed and interpreted as required.

A long control list is not proof of independence. Several measures relied on the same people recognising signals, understanding the operating mode, navigating similar displays and correcting the trajectory in time. Counting controls is easy; demonstrating independence and availability is engineering.

What happened at Monaca

The ethane cracking unit began operating in November 2022. During a 2025 outage, Shell decided to clean the coke traps of all seven furnaces for the first time. Furnace 5 was isolated from the downstream quench tower by closing two 36-inch MOVs in series.

While returning the furnace to service, a process, automation, control and optimisation engineer — PACO in the report — manipulated the valves remotely. The engineer had not performed that task before. Other furnaces were already producing cracked gas into the common downstream system.

The logic display showed three visually similar MOVs whose tags differed primarily in the final digit. The job aid placed steps out of operational sequence, and a mode change refreshed the display to a position that favoured selection of the wrong valve. Both isolation MOVs became open.

Pressure in the downstream system drove gas back toward the lower-pressure furnace. About six minutes after the inadvertent command, the CSB estimated that roughly 641 pounds of cracked gas had accumulated before ignition. The explosion ruptured a firebox wall and was followed by fire.

Shell petrochemical complex under construction in Beaver County beside the Ohio River in 2019
Context image from January 31, 2019, before the 2025 incident. Photo: Drums600/Wikimedia Commons, CC BY-SA 4.0. Resized and converted to WebP by Andrade Safe.

Serious consequences without reported injuries

Fifteen employees evacuated and no injuries were reported. A contractor was trapped in a nearby elevator and rescued. The absence of casualties does not make the mechanism minor: the facility's own hazard analysis had recognised a potentially fatal explosion scenario.

Shell estimated $95 million in property damage and about 5,100 pounds of ethylene and combustion products released. Furnace 5 returned to service on January 22, 2026 after reconstruction.

It was not simply a wrong click

The CSB identified the simultaneous opening of both isolation MOVs as the cause. Contributing factors included assigning a person with limited experience in the task and limited process knowledge, ineffective administrative controls, and deficiencies in the safety system HMI.

The command was the proximal action, not a complete explanation. A useful investigation asks why the selection was plausible, why the display increased ambiguity, why relevant alarms were suppressed, why the procedure did not match the configuration and why no automatic safeguard prevented both valves from remaining open.

Calling the event human error closes the inquiry where systems analysis should begin.

Conceptual diagram of backflow through two motor-operated valves into a furnace with lit pilots
Simplified Andrade Safe concept based on the CSB sequence. It distinguishes administrative guidance from an engineered block and does not replace a P&ID, control logic or site-specific analysis.

Eleven controls — how independent were they?

Policies, procedures, alarms, field execution, a job aid, bypass rules, emergency shutdown and exclusion controls can all be valuable. Their number alone says little about robustness.

A safeguard must perform a defined function in the scenario, remain available in the actual mode and avoid excessive common dependencies. Procedures, alarms and operator response may all fail together when they rely on the same person, display and assumption.

Editorial synthesis of the CSB report. No quantitative independence or reliability credit is assigned.
Control groupExpected roleSystem lesson
Policies and proceduresMaintain isolation and guide the transitionProtection exists only when instructions match the real task and mode
AlarmsReveal pressure, gas or unexpected valve stateRelevant alarms were suppressed or poorly differentiated
HMI and actionIdentify and operate the correct MOVSimilar tags and representation increased selection burden
Temporary operationRecognise abnormal configuration and add compensating measuresThe applicable requirement was not sufficiently known or understood
Emergency and exclusionLimit consequences and remove peopleThese depend on timely recognition after the hazardous path develops
EngineeringPhysically prevent backflowThe licensor's protection was not configured for double-isolation removal

Control is not synonymous with an independent protection layer

In risk analysis, a safeguard needs more than a name. Its initiating condition, action, response time, energy source, availability and failure modes must be defined.

Two instructions in one procedure are not automatically two barriers. Two alarms suppressed by the same mode share a dependency. Training and supervision can fail together when the task is misclassified.

This article therefore assigns no SIL or failure probability to the eleven measures. The supported conclusion is qualitative: the high-consequence scenario relied solely on administrative controls while the engineered protection was unavailable in that configuration.

HMI is not decoration

A human-machine interface is the collection of displays, symbols, tags, controls, alarms, trends and feedback through which a person understands and changes a process. In process safety it is part of the path between operational intent and physical movement.

The CSB found three almost identical MOVs on one logic screen, tags distinguished mainly by a final digit, navigation demands and insufficient confirmation safeguards for a critical command.

A high-performance interface supports the task through visual hierarchy, process context, functional distinction, clear state, consequence-appropriate confirmation and useful feedback. The CSB cited ISA-101; this article uses only public characterisation and does not reproduce proprietary standards.

Alarms must exist in the mode where the hazard exists

Pressure and gas-detection alarms that could have supplied information were suppressed in pilot-only mode. A critical unexpected-state alarm appeared, but its description was nearly identical to another valve's message and it was acknowledged without correcting the condition.

Alarm suppression can be legitimate when a signal has no meaning in a defined state. The risk arises when logic covers only nominal operation and leaves gaps during maintenance, isolation recovery or an unforeseen combination.

The design question is not whether every alarm should always be active. It is what information and independent protection remain available whenever the hazard can exist.

The operating-mode trap

An ethane furnace has more than on and off states. The report describes ethane cracking, decoking, hot steam standby, pilot-only, startup, shutdown and maintenance. Pressure, ignition sources, permissives and flow paths change between them.

A safeguard effective in normal operation may be inhibited or unavailable during transition. The licensor had provided local controls capable of preventing backflow, but Shell had not configured them for double-isolation removal.

Hazard reviews should therefore treat operating mode as a safety variable. Ask whether every credited function remains enabled during startup, shutdown, pilot-only, maintenance, bypass, recovery and emergency.

When the hazard analysis already knows the scenario

The 2023 process hazard analysis revalidation identified reverse or misdirected flow into an offline furnace as an explosion scenario with multiple-fatality potential. The hazard was not unimaginable.

Two administrative controls credited in the analysis were not active on the day. More broadly, the CSB concluded that the scenario relied on administrative measures instead of an engineered safeguard available during double isolation.

The first CSB recommendation asks Shell to review deviations addressed solely by administrative controls and implement inherently safer design or engineered controls for scenarios capable of fatality, serious injury or substantial property damage.

Engineering existed, but not for this configuration

The technology licensor had supplied local-panel controls capable of preventing backflow. They were not configured for use when removing double isolation, so the task migrated to remote manipulation through the deficient interface.

The second recommendation calls for an engineered control that prevents cracked-gas backflow during all furnace operating modes. It cites the IEC/ISA 61511 family as a functional-safety reference.

That does not prescribe one universal architecture or SIL. A site must define the safety function, validate it for relevant modes, manage bypasses and maintain evidence of availability.

What changed after the event

Shell modified local control so field operators could operate the furnace-side, decoking and tower-side MOVs without PACO manipulation for this task. It also implemented SIS logic that keeps the tower-side MOV closed if the furnace-side MOV is opened by mistake.

A new step-by-step operating procedure was issued and personnel were trained. The combination matters: engineering blocks process progression, while procedure and competence structure execution. Human performance should not be the sole defence against a catastrophic consequence.

US regulatory context

OSHA's Process Safety Management rule connects process safety information, PHA, operating procedures, training, mechanical integrity, management of change, pre-startup safety review and incident investigation.

The public record for inspection 1829624.015 shows closure on January 2, 2026, two serious violations and a current total penalty of $26,480. That record is presented as regulatory context, not as a broad legal judgment.

The institutional distinction also matters: OSHA enforces requirements and issues citations; the CSB is an independent, nonregulatory investigative agency that issues findings and recommendations, not fines.

What this means for Brazil

Brazilian NR-1 and NR-20 did not govern the Pennsylvania incident. At an equivalent Brazilian installation, after confirming scope, they provide useful questions about hierarchy, risk assessment, design, operating modes, changes and learning from events.

NR-1 prioritises avoiding hazards, collective protection and then administrative and individual measures. NR-20 links petrochemical design, interruption of leak-fire-explosion chains, documented risk analysis, modifications, maintenance and procedures for normal, temporary, emergency, shutdown and post-emergency operation.

Brazilian GRO/PGR is not legally equivalent to US PHA/PSM. ISA-101 and IEC 61511 are not automatically mandatory in Brazil; applicability depends on law, project basis, contract and site-specific risk decisions.

Questions to test safeguards before the next startup

Use these as review prompts, not as a substitute for site-specific PHA, design or validation.

  • What happens if the critical action is performed out of sequence?
  • What automatic or engineered safeguard blocks that hazardous path?
  • Is it available during startup, shutdown, maintenance, bypass and emergency?
  • Are important alarms suppressed in the task mode, and what compensation remains?
  • Do supposedly independent controls depend on the same person, display, procedure, signal or power source?
  • Does the HMI distinguish similar equipment by function, position and consequence?
  • Do hazardous commands provide confirmation, feedback and recovery?
  • Does task analysis cover non-routine maintenance and isolation recovery?
  • Does the procedure match the exact process configuration?
  • Does the PHA give excessive credit to training, alarms or procedures?
  • Are deferred engineering actions documented and periodically revisited?
  • Does the team know when to abort the transition and reach a safe state?

What the case does not prove

It does not prove that training is useless, procedures do not work or operators are a sufficient cause. Competence and procedures remain essential inside a system that makes dangerous actions less likely and limits their consequences.

It does not support generic claims about culture, intention or blame. Nor does citing ISA, IEC, CCPS, NIOSH or OSHA make those references automatically binding Brazilian law.

Conclusion

Monaca had policies, alarms, procedures, rules and trained people. The known scenario still crossed those layers because they shared human dependencies and the engineered protection was unavailable in the real task mode.

The transferable question is simple: if this action is performed incorrectly, what independent safeguard prevents escalation without requiring another person to notice and correct it in time? If the answer is only that the procedure says to do it correctly, the analysis is not finished.

Frequently asked questions

What caused the Shell Polymers Monaca explosion?

According to the CSB, both isolation MOVs opened inadvertently, allowing cracked gas to backflow into the firebox and ignite at lit pilots.

Why did the CSB highlight 11 administrative controls?

Eleven measures expected to prevent or mitigate the scenario did not stop it. They relied heavily on human awareness, interpretation and action.

Does having many barriers make a system safe?

Not necessarily. Independence, availability, common dependencies and validity in every operating mode must be demonstrated.

What is an engineered safeguard?

A process or equipment feature that blocks or reduces a hazard with less dependence on continuous human action.

What is HMI in process safety?

The interface that presents process states, alarms, commands and context. Its design influences identification, action and recovery.

Why do operating modes matter?

A safeguard active in normal operation may be inhibited or unavailable during startup, maintenance, pilot-only, shutdown or isolation recovery.

What changed after the incident?

Shell modified local MOV control, added SIS logic, issued a step-by-step procedure and trained personnel. Furnace 5 returned to service on January 22, 2026.

Are ISA-101 and IEC 61511 mandatory in Brazil?

Not automatically. Applicability depends on the legal and project basis, contracts and site-specific risk decisions.

Verified sources

References

  1. Furnace Explosion and Fire at Shell Polymers — Final Investigation ReportU.S. Chemical Safety and Hazard Investigation Board
  2. CSB releases final report on Shell Polymers MonacaCSB
  3. Inspection 1829624.015 — Shell Chemical Appalachia LLCOccupational Safety and Health Administration
  4. 29 CFR 1910.119 — Process Safety ManagementOSHA
  5. Hierarchy of ControlsNIOSH
  6. Human factors and ergonomicsHealth and Safety Executive
  7. ISA-101 Series of StandardsInternational Society of Automation
  8. NR-01 — Disposições Gerais e Gerenciamento de Riscos OcupacionaisMinistério do Trabalho e Emprego
  9. NR-20 — Segurança e Saúde no Trabalho com Inflamáveis e CombustíveisMinistério do Trabalho e Emprego
  10. Shell Cracker Plant.jpgWikimedia Commons