Skip to main content
Zemerc
PSMProtect · Safety, Risk & Assurance

Process Safety Management System

Manage barriers and process-safety risk without unsupported composite scores.

Process safety treated as an engineering discipline: process hazard analysis and facilitated studies; barrier management and safety-critical elements; safety instrumented functions and requirements; operating envelopes; management of change and simultaneous operations; proof testing; and the process safety event and loss-of-containment records these controls are intended to prevent.

PSM dashboard showing Tier 1 and Tier 2 events, barrier impairments, open recommendations, methodology status, and recorded positions across safety-critical elements, operating envelopes, critical alarms, performance standards, loss of containment and management of change.
0Functional pillars
0Controlled documents
0Business areas
0Roles
The barrier model

Everything in process safety is a barrier or a consequence.

Causes are held back by preventive barriers. When they are not, recovery barriers decide how far it goes. PSM is arranged around that model, which is why barrier impairment is a first-class state rather than a note on an action.

Corrosion
Overpressure
External impact
Human error
Fire or explosion
Environmental release
Injury
Production loss
SCE
SIF
Envelope
MoC
Detection
ESD
Response
Loss of containment
What it will not compute

No certified method, no number.

Where no approved methodology or certified engineering method exists for a process-safety index, PSM states that limitation and does not generate the number. The underlying component measures remain available individually so the recorded position can still be reviewed.

An index needs a method

A health or assurance index requires defined component measures, formulae, scales, normalisation rules and thresholds. Where the organisation has not approved that methodology, combining the components into a single score would not constitute an authorised engineering result.

Components are reported individually

Instead of an unsupported aggregate, the application reports the recorded position by area, including safety-critical elements, operating envelopes, critical alarms, performance standards, loss of containment and management of change, with each position linked to its governing register.

The route to a real figure exists

An index becomes valid only when its method is owner-approved, version-controlled and executed through a governed deterministic calculation path that can reproduce the result. Until that method exists, the application reports that no valid index is available.

The functional safety lifecycle

Analyse, define requirements, design safeguards, operate, verify and feed learning back into the analysis.

The lifecycle is a cycle, which is why an event feeds hazard analysis rather than closing a file. Rest on the ring to hold a stage.

Hazard analysis
Requirement
Design
Operate
Prove
Learn
Lifecycle
1 of 6
Stage 1 · Hazard analysis

Hazard and operability, hazard identification and what-if studies run as workshops, with every recommendation becoming a tracked item rather than a line in a report.

In the application: Process Hazard Analysis

Controlled documents

Fourteen documents issued from the authoritative registers.

Executive and management, hazard analysis and workshops, risk, functional safety, barriers and safety-critical elements, operational process safety, management of change, events and learning, assurance and audit, engineering calculations, and governance and regulatory; each marked with its state and classification and recorded every time it is issued.

PSM reports generated from authoritative process-safety registers, including hazard studies, recommendations, barrier and safety-critical-element status, functional safety, operational controls, events, assurance and regulatory records, with each report retaining its state and classification.

A report states the period and facility it covers and is issued from the registers, not assembled alongside them.

  • Issued, not exported
    Issuing a controlled document is a recorded act with a state and a classification, distinct from taking an extract.
  • Register extracts stay separate
    Spreadsheet and data extracts come through data management, so a working file is never mistaken for a controlled document.
  • Eleven methodologies
    A study report can be produced for any of the methodologies the organisation actually runs.
Capability architecture

Understand, protect, assure, operate; and engineer beneath all of it.

The application's own navigation, arranged as the discipline works rather than as a feature list. Every chip is a page.

  • Understand

    Process hazard analysis across HAZOP, HAZID, environmental identification, what-if and structured what-if studies, with workshop recommendations converted into governed actions.

    • Process Hazard Analysis
    • Workshops
    • Engineering Intent
    • Knowledge Library
  • Protect

    Manage barriers and safety-critical elements, safety instrumented functions, safety requirements and alarm management as defined layers of protection against escalation.

    • Barriers
    • Safety-critical elements
    • SIF register
    • Safety requirements
    • Alarm management
  • Assure

    Govern process safety audits, proof testing, functional safety lifecycle activities and assurance evidence through to the executive assurance position.

    • Audits
    • Proof tests
    • Lifecycle
    • Assurance programme
    • Executive assurance
  • Operate

    Control operating envelopes and critical parameters, recorded deviations, management of change, temporary instructions, simultaneous operations, shift handover, operational readiness, start-up and shutdown.

    • Operating envelopes
    • Critical parameters
    • Deviations
    • Management of Change
    • Temporary instructions
    • SIMOPS
    • Shift handover
    • Startup & Shutdown
  • Engineer

    Govern engineering calculations, approved methods, method definitions, recorded executions and traceable results.

    • Engineering Calculations
    • Calculation Governance
    • Engineering Methods
    • Method Executions
  • Events and governance

    Maintain process safety event and loss-of-containment records together with regulatory frameworks, engineering decisions, assumptions, competency records and recommendation tracking.

    • Process Safety Events
    • Loss of Containment
    • Regulatory Frameworks
    • Engineering Decisions
    • Engineering Assumptions
    • Competency
    • Recommendations
Design and operation

TSM defines the barrier. PSM keeps it credible.

Technical safety in design owns the definitions; barriers, safety-critical elements, safety instrumented functions and their performance standards; and publishes them. PSM is the system of record once the plant is running: management of change, simultaneous operations, operating envelopes, proof-test execution, barrier health, events and loss of containment.

  • Design definitions published into operation rather than re-entered
  • Proof-test execution and operational barrier health held in PSM
  • Regulatory frameworks recorded against the facility they apply to
Governed configuration

Setup completeness is derived from your records, not declared.

How much of the organisation is actually configured is computed from what has been recorded. Roles come from an engineering role library with what each one permits; canonical engineering concepts are mapped to the organisation's own terminology; recurrence and revalidation intervals are configuration rather than convention.

  • Engineering role library with explicit permissions
  • Facility structure reconciled against references already in use
  • Immutable audit trail behind every change
  • A refusal is the application working

    Where no certified engineering method and no approved methodology exist, the application states that rather than producing an index. There is no dashboard arithmetic standing in for engineering.

  • Classified by a person

    Event tiers are classifications a person made against a governed scheme, not a severity the system inferred from a description.

  • Segregation on identity

    Separation of duties is enforced against identity, so the engineer who performed the work is not the one who verifies it; and the system refuses to close work that is not evidenced.

  • Your terminology, mapped

    The canonical engineering concepts the application reads are mapped to the organisation’s own terminology, so nobody has to rename their plant to fit a vendor’s vocabulary.

Also in PSM

More of what the application covers.

  • Workshops with recorded participants and recommendations
  • Impairment of a barrier held with its compensating measures
  • Temporary instructions with an expiry that is enforced
  • Simultaneous operations assessed before the work runs
  • Shift handover as a governed record
  • Operations readiness before start-up
  • Recurrence and revalidation intervals as configuration
  • Immutable audit trail of who changed what and when
PSM

See PSM with one of your hazard studies.

Bring one hazard study and its recommendations. We will show the barriers and safety-critical elements they produce, the proof tests that keep them credible, and what the application refuses to compute for you.