Process safety gaps can remain even when a review lists numerous controls. The critical question is whether those controls can prevent the event in the condition the plant is actually in.
On September 16, 2026, the U.S. Chemical Safety Board released its investigation into the June 4, 2025 explosion at Shell Polymers Monaca. The CSB reported that the unintended opening of two isolation valves allowed flammable gas to backflow into a furnace during its return to service. The agency identified reliance on administrative controls and deficiencies in the human-machine interface as primary safety issues. CSB investigation announcement
The CSB described 11 administrative controls that depended on people following procedures. Available engineered controls had not been configured to prevent this backflow during removal of double isolation. The report also describes similar valve symbols and identification tags on the control screen. These findings concern this specific incident; they deserve careful examination without reducing the event to an individual mistake. CSB final report

Finding process safety gaps between operating modes
My practical takeaway is to examine transitions explicitly. A plant can have a well-understood normal operating state and a well-understood maintenance state, while the movement between them receives less detailed scrutiny.
Take a system returning from maintenance. Its relationship with adjacent operating equipment may have changed. Responsibilities may move from a maintenance team to operations. A control function that was appropriate during the work may require a different configuration before the process can safely advance.
For each consequential transition, ask what hazardous flow path or condition could become possible, what prevents it, and how the team confirms that protection applies at that moment. Carry those questions through the plant’s hazard review, control design, and startup planning.
Count independent protection carefully
A permit, a checklist, a verbal instruction, and a second signoff can each be useful. If several depend on the same person correctly interpreting the same ambiguous information, however, their number does not establish independent protection.
I would want the review team to identify those dependencies. Which assumptions are shared? Could one misunderstanding defeat several measures? Where does the design itself prevent a hazardous action, and where does prevention depend on recognition and response?
That discussion requires operations and instrumentation expertise together. The appropriate safeguards must follow the scenario and the required risk reduction. Adding a control without examining its failure behavior, testing needs, and interaction with other systems can create another unresolved assumption.
Treat the control screen as an engineering interface
A control screen should help the user understand equipment identity, process context, and the effect of an action. That becomes especially important during infrequent tasks, when familiarity cannot be assumed.
During a structured design review, ask an appropriately qualified colleague to explain an infrequent task using an offline or otherwise approved representation of the interface. Listen for uncertainty about which equipment is selected, what state it is in, and what the command will change. Resolve that ambiguity through the formal engineering process.
For an upcoming turnaround, I would select one consequential return-to-service transition and review it with the people who will authorize and perform it. Their shared understanding should be supported by the control design and clear evidence of readiness. A completed work package alone cannot demonstrate that protection.
Preparing a shutdown or control-system change? Discuss the operating transitions and safeguards with TEC.

