HAZOP — Deviations From Design Intent

Hazard and Operability study asks, guided word by guided word, what happens if a process parameter is too much, too little, reversed, or accompanied by something unintended — a process/engineering tool applied here to a chromatography example.
A banner titled 'HAZOP — Deviations From Design Intent' with the tagline 'Ask "What if?" before it happens.' and the note that this is a structured, guide-word approach to identify how process parameters can deviate, what could happen, and how to keep the process safe, robust, and in control. Panels: (1) The One Idea — HAZOP doesn't start from a list of known failure modes, it starts from the process's own design intent and systematically asks what happens if reality deviates from it, one guide word at a time, parameter by parameter, captioned 'Use guide words to challenge assumptions, uncover what could go wrong, and strengthen the design before it happens.'; (2) How a HAZOP Works — a five-step chevron: define scope and team (process section, e.g. chromatography; multidisciplinary team — process, analytical, engineering, quality, EHS), list design intent (process steps, key parameters like flow/temperature/pressure/pH/time/concentration, normal operating ranges), apply guide words (ask what happens for each parameter using NO, MORE, LESS, AS WELL AS, REVERSE, OTHER THAN), identify causes and consequences (what could cause the deviation, what are the consequences for safety/quality/operability/regulatory), assess safeguards and actions (what safeguards already exist, are they sufficient, define actions for gaps) — captioned to document, track actions, and follow through to closure; (3) The HAZOP Guide Words — a table of six guide words with meaning and a generic example: NO (completely absent, no flow — pump failure), MORE (higher than intended, more pressure than the system is rated for), LESS (lower than intended, less temperature than required), AS WELL AS (something additional is present, an unexpected contaminant enters the intended feed), REVERSE (opposite direction, reverse flow through a failed check valve), OTHER THAN (completely different than intended, a different reagent is charged instead of the intended one); (4) Worked Examples — two side-by-side tables applying guide words: Example 1, HPLC Flow Rate (Analytical Process) — MORE (flow rate too high, pump set point drifts high, column overpressure/seal failure/resolution loss, system pressure alarm), LESS (flow rate too low, partial pump blockage, retention times shift/poor resolution, system suitability retention-time check), NO (no flow, pump stalls, no separation occurs/run aborts, run-sequence software flags failed injection), AS WELL AS (contaminant in mobile phase, impurity or wrong solvent present, interfering peaks/method failure, incoming solvent specification/UV scan), REVERSE (reverse flow, check valve failure, column damage/carryover, check valve and system pressure direction check), OTHER THAN (different solvent, wrong solvent selected, unexpected selectivity/no separation, barcode verification/method review); Example 2, Bioreactor Temperature (Manufacturing Process) — MORE (temperature too high, heating control fails open, reduced cell viability/altered glycosylation — a CQA hit, independent high-temperature interlock), LESS (temperature too low, cooling jacket over-corrects, reduced growth rate/extended run time, continuous temperature logging with trend alarms), NO (no temperature control, control system failure, loss of culture control/batch failure, alarm and automated shutdown), AS WELL AS (contaminant introduced, leaking line or open port, microbial contamination, closed system design/sterility assurance), REVERSE (reverse flow of coolant, valve mispositioned, overheating risk, valve position interlocks), OTHER THAN (wrong medium added, operator error, cell stress/off-spec product, barcode scanning/double-check procedure), with the note that a higher temperature may not cause an obvious failure but can silently change a critical quality attribute like glycosylation — exactly the kind of risk HAZOP is designed to uncover; (5) HAZOP vs. FMEA — Different Starting Points, Complementary Tools, a comparison table across direction (starts from design intent/deviations vs. starts from process steps/failure modes), key question (what happens if this parameter deviates vs. what could fail at each step), focus (process/engineering design and operability vs. analytical methods and detailed processes), output (list of credible deviations, causes, consequences, safeguards, actions vs. prioritized failure modes (RPN) and actions), best for (manufacturing and process design vs. QC methods and laboratory processes), captioned 'Use HAZOP for process and engineering risk. Use FMEA for analytical methods. They often inform each other.'; (6) Strengths and Limitations — strengths (structured/systematic way to challenge the design, uncovers non-obvious deviations using guide words, focuses on patient safety/product quality/operability, ideal for complex processes and new designs, multidisciplinary — brings different perspectives together) and limitations (can be time-consuming and exhaustive, requires good process understanding to identify true CCPs, no built-in scoring — prioritization is a separate step, can overlap with FMEA if both are used, less natural for analytical-method risk where FMEA is usually preferred); (7) Key Takeaways — HAZOP uses guide words to explore deviations from design intent; not every step is a CCP — only where the hazard cannot be caught downstream; focus on causes, consequences, and existing safeguards; works best for process and engineering risk (e.g., manufacturing); use HAZOP and FMEA together for a stronger, more complete risk program. Footer: 'People + Process + Risk-Based Thinking = Better Medicines for Patients,' Temple University branding, and the tagline 'Science Today. Healthier Tomorrows.'

The one idea

HAZOP doesn’t start from a list of known failure modes the way FMEA does — it starts from the process’s own design intent and systematically asks what happens if reality deviates from it, one guide word at a time, parameter by parameter.

Mechanics

For each parameter at each step of a process (flow rate, temperature, pressure, pH, concentration, time), a HAZOP team applies a fixed set of guide words and asks what a deviation of that kind would actually cause:

Guide wordMeaningGeneric example
NOThe parameter is completely absentNo flow — pump failure
MOREThe parameter is higher than intendedMore pressure than the system is rated for
LESSThe parameter is lower than intendedLess temperature than the reaction requires
AS WELL ASSomething additional is presentAn unexpected contaminant enters with the intended feed
REVERSEThe parameter or flow runs backwardReverse flow through a check valve that has failed
OTHER THANSomething completely different happens insteadA different reagent is charged than intended

Unlike FMEA, HAZOP doesn’t score every deviation on Severity/Occurrence/Detection — the output is a qualitative list of credible deviations, their causes, consequences, and existing safeguards, with follow-up actions where the safeguards look thin.

Worked example — HPLC flow rate and a bioreactor’s temperature

Guide wordParameterDeviationConsequenceSafeguard
MOREHPLC flow ratePump set point drifts highColumn overpressure, potential seal failure, resolution lossSystem pressure alarm, method-defined pressure limit
LESSHPLC flow ratePartial pump blockageRetention times shift, poor resolution between API and impuritySystem suitability retention-time check
NOHPLC flow ratePump stallsNo separation occurs at all; run abortsRun-sequence software flags a failed injection
MOREBioreactor temperatureHeating control fails openReduced cell viability, altered glycosylation profile (a CQA hit)Independent high-temperature interlock, separate from the control loop
LESSBioreactor temperatureCooling jacket over-correctsReduced growth rate, extended run timeContinuous temperature logging with trend alarms

Notice the bioreactor row: a MORE temperature deviation doesn’t just risk an obvious failure (dead cells) — it can silently shift a critical quality attribute (glycosylation) while the culture still looks healthy, which is exactly the kind of consequence a guide-word walk-through is designed to surface deliberately, rather than relying on someone to have already thought of it.

When to reach for it vs. FMEA

HAZOP and FMEA overlap heavily in outcome — both end up identifying deviations and their consequences — but HAZOP is organized around the process’s design intent, parameter by parameter, which makes it a natural fit for engineering and process-design teams examining a new unit operation (a reactor, a filtration skid, a chromatography skid) before it’s ever run. Most QC labs default to FMEA for method risk because the “steps” of a method are already well defined; HAZOP earns its keep more in process/engineering contexts where the parameters, not discrete process steps, are the natural unit of analysis.

Known weaknesses

  • Applying every guide word to every parameter at every step can be slow and exhaustive for a complex process — teams often scope it to the parameters most likely to matter, which reintroduces some of the same judgment calls HAZOP is meant to avoid.
  • Without a scoring step, prioritizing which deviations to act on first is a separate, later exercise — HAZOP tells you what could deviate, not which deviation matters most.
  • The overlap with FMEA means running both on the same process is often redundant; most sites pick one as the primary tool for a given risk type (HAZOP for process design, FMEA for methods) rather than running both routinely.