HAZOP — Deviations From Design Intent
The one idea
HAZOP doesn’t start from a list of known failure modes the way FMEA does — it starts from the process’s own design intent and systematically asks what happens if reality deviates from it, one guide word at a time, parameter by parameter.
Mechanics
For each parameter at each step of a process (flow rate, temperature, pressure, pH, concentration, time), a HAZOP team applies a fixed set of guide words and asks what a deviation of that kind would actually cause:
| Guide word | Meaning | Generic example |
|---|---|---|
| NO | The parameter is completely absent | No flow — pump failure |
| MORE | The parameter is higher than intended | More pressure than the system is rated for |
| LESS | The parameter is lower than intended | Less temperature than the reaction requires |
| AS WELL AS | Something additional is present | An unexpected contaminant enters with the intended feed |
| REVERSE | The parameter or flow runs backward | Reverse flow through a check valve that has failed |
| OTHER THAN | Something completely different happens instead | A different reagent is charged than intended |
Unlike FMEA, HAZOP doesn’t score every deviation on Severity/Occurrence/Detection — the output is a qualitative list of credible deviations, their causes, consequences, and existing safeguards, with follow-up actions where the safeguards look thin.
Worked example — HPLC flow rate and a bioreactor’s temperature
| Guide word | Parameter | Deviation | Consequence | Safeguard |
|---|---|---|---|---|
| MORE | HPLC flow rate | Pump set point drifts high | Column overpressure, potential seal failure, resolution loss | System pressure alarm, method-defined pressure limit |
| LESS | HPLC flow rate | Partial pump blockage | Retention times shift, poor resolution between API and impurity | System suitability retention-time check |
| NO | HPLC flow rate | Pump stalls | No separation occurs at all; run aborts | Run-sequence software flags a failed injection |
| MORE | Bioreactor temperature | Heating control fails open | Reduced cell viability, altered glycosylation profile (a CQA hit) | Independent high-temperature interlock, separate from the control loop |
| LESS | Bioreactor temperature | Cooling jacket over-corrects | Reduced growth rate, extended run time | Continuous temperature logging with trend alarms |
Notice the bioreactor row: a MORE temperature deviation doesn’t just risk an obvious failure (dead cells) — it can silently shift a critical quality attribute (glycosylation) while the culture still looks healthy, which is exactly the kind of consequence a guide-word walk-through is designed to surface deliberately, rather than relying on someone to have already thought of it.
When to reach for it vs. FMEA
HAZOP and FMEA overlap heavily in outcome — both end up identifying deviations and their consequences — but HAZOP is organized around the process’s design intent, parameter by parameter, which makes it a natural fit for engineering and process-design teams examining a new unit operation (a reactor, a filtration skid, a chromatography skid) before it’s ever run. Most QC labs default to FMEA for method risk because the “steps” of a method are already well defined; HAZOP earns its keep more in process/engineering contexts where the parameters, not discrete process steps, are the natural unit of analysis.
Known weaknesses
- Applying every guide word to every parameter at every step can be slow and exhaustive for a complex process — teams often scope it to the parameters most likely to matter, which reintroduces some of the same judgment calls HAZOP is meant to avoid.
- Without a scoring step, prioritizing which deviations to act on first is a separate, later exercise — HAZOP tells you what could deviate, not which deviation matters most.
- The overlap with FMEA means running both on the same process is often redundant; most sites pick one as the primary tool for a given risk type (HAZOP for process design, FMEA for methods) rather than running both routinely.