top of page

Search this site

171 results found with an empty search

  • What Are Tomorrow's Leaders Learning From Us Today? A Lesson in Ethical Leadership

    September 2026 - Ken O'Malley - I recently completed a couple of ethics training courses to renew my Professional Engineering license, and they got me thinking about ethics and leadership—not just in engineering decision-making, but in everyday leadership situations. That thinking led me back to a paper written by my former colleague Chris Powell, PE, CFSE, The Courage to Intervene: Developing Ethical Leadership in the Next Generation of Process Safety Professionals, prepared for the 2026 AIChE Global Congress on Process Safety. Chris opens with a story that has stuck with me. A safety-critical system had been commissioned and, from a procedural standpoint, the project was ready to move into startup. But a senior safety leader concluded that some of the work, performed under significant schedule pressure, had not been completed with the rigor it deserved. There was no regulatory violation, and there was no clear technical failure. The leader simply wasn't comfortable that the work met the standard of his organization. So, he required the most critical portions of the commissioning to be performed again under more controlled and thoughtful conditions. That decision delayed startup; it cost real money. And the decision had to be justified to his leadership team without a clear and compelling safety case that made the choice obvious. There is an important lesson in that story that extends well beyond process safety. Our values are most tested when honoring them costs us something. Today's leaders operate under tremendous pressure to perform. Grow revenue. Protect margins. Move fast to win market from competitors. Hit quarterly goals. Do more with less. These are all legitimate responsibilities of leadership. When Small Compromises Start to Look Reasonable Problems creep in, though, when small compromises begin to look reasonable in service of those goals. "We're technically compliant." "It's good enough." "We'll address it later." "It's only this once." Chris describes how individually defensible decisions like these can begin to normalize deviation. The extraordinary becomes acceptable, and eventually, it becomes normal. There is another dimension that I think is easy to overlook: When a leader faces a difficult decision, there can be real value in letting the team see some of the forces at work behind the scenes. Help them understand and appreciate the financial and schedule pressure, the reasons why the easier choice might have been attractive and technically defensible, and then why the harder path was chosen anyway. This visibility is important. If the team only sees the outcomes and consequences of a difficult decision, they miss an important part of learning what it means to be a leader. They need to see experienced leaders wrestle with competing responsibilities and ultimately decide where the line is. Certainly, not every leadership discussion can be shared broadly. But some difficult decisions can become great teachable moments, and those opportunities should not be wasted. The Takeaway Chris closes his paper with an idea I think is worth reflecting on: the most enduring legacy of experienced leaders may not be their technical or commercial knowledge, or even their ability for strategic thinking, but rather the examples they set for others to follow. I agree. Someday, the people being developed today will face their own versions of these decisions—when doing what's right has a real and immediate cost and the justification is opaque. What are tomorrow’s leaders learning from watching us today? Credit: Chris Powell, PE, CFSE, The Courage to Intervene: Developing Ethical Leadership in the Next Generation of Process Safety Professionals, prepared for the 2026 AIChE Spring Meeting and 22nd Global Congress on Process Safety.

  • How to Prevent the Five Most Common Industrial Alarm Management Issues

    Updated August 2026 — During my 24+ years in alarm management, I have collaborated with various companies on their distributed control systems (DCS) across the United States and throughout 20 other countries. Although every system is different, there are more commonalities than you might imagine. I am consistently asked what my favorite and least favorite control systems are to work on. My answer is always the same, “my favorite system is the one I just finished for obvious reasons, and my least favorite is the one I’m working on right now.” This is because all alarm management systems have issues, but naturally, these issues are different from system to system. That is why I felt it was important to discuss how to prevent the five most common industrial alarm management issues. Avoiding Unnecessary and Misused Alarms for Effective Industrial Alarm System Management One tenet of alarm management is that alarms will only be used for abnormal situations. I cannot tell you the number of times that I have found alarms configured on systems for things that should never have an alarm. Some of these were obviously designed for convenience. A typical example of a convenience alarm is a low-temperature alarm on an ambient sensor located just outside the control room door. Although there are a few circumstances when this could be necessary (e.g., an extremely low ambient temperature could adversely affect the viscosity of a process fluid), most of the times that I have encountered this type of convenience alarm, it is simply to let the operator know if it is cold outside. Once, a senior operator in upstate New York actually told me that without the alarm, he wouldn’t know if he should put on a coat or not. The alarm was removed. Another relatively common misuse of industrial alarm systems occurs when a system timer alarm set up thirty (30) to sixty (60) minutes before the end of the shift in order to remind personnel to fill out shift changeover paperwork before going home. In situations where I have found these, the alarms have descriptions like “Time for Turnover Paperwork” or “Call-in Reading to Foreman.” In one of these cases, the description was “Wake Up and Pack Up to Go Home.” In this case, not only was the alarm removed from the system, but the tag was removed as well, and the person this applied to was told to buy an alarm clock. Ultimately, avoiding unnecessary or misused alarms will improve your industrial alarm system’s effectiveness. Ensuring Operator Action — Proper Alarm Criteria and the Use of Alert Systems Another principle of alarm management is that every alarm requires an operator action. When designing an alarm philosophy, one of the steps is to determine the time to respond (how much time is available to take action to avoid the consequences) vs. the severity of consequences matrix, as shown in Table 1 below. Table 1 - Alarm Priority Determination - aeSolutions As you can see in the table above, if there are no consequences or the time available is more than thirty (30) minutes, the parameter does not qualify to be an alarm. Although the operator may need to know that an instrument has reached a certain point, that does not mean that it should necessarily be an alarm. This condition can cause concern when these points support operations and do not meet the necessary qualifications of an alarm but still need to be viewed or accessed as part of operational efficiency. For those items that do not qualify as an alarm, there should be a separate mechanism to inform the operator (e.g., an alert system). I have encountered many types of alert systems, and there are numerous ways to implement them. One of the most common is to set up an alert as a separate “priority” on the DCS that has no visual or audible actions tied to it. This will result in the alerts going to a separate screen designated just for them. The operators will have to become accustomed to checking the screen multiple times during a shift, however these alerts should not be short-time critical (e.g., <1 hour or the potential to be a HIGH priority). If the alarm has the potential to be a HIGH priority, then it should be re-engineered to the point that the time available is 30 minutes or less. Implementing Effective Single Alarms for Each Cause or Action | Industrial Alarm Management Creating a single alarm for each cause or corrective action is another doctrine of effective industrial alarm management. In other words, you should not have to be told more than once to do something. This issue most often occurs with multiple levels of alarming (e.g., High (H) & High-High (HH) or Low (L) & Low-Low (LL)). Below is an example of multiple level alarming being used correctly and incorrectly. Correct use of multiple levels of alarming example: A tank is ten feet in height and will overflow at that ten-foot level. There is a high-level alarm (H) set at nine feet with a HIGH priority to notify the operator to take action, stopping the level rise. There is a high-high level alarm (HH) at the do not exceed height of 9.5 feet, with a LOW priority and a corresponding automated action that stops filling the tank. The alarm located at nine feet notifies the operator that action is needed. The alarm at 9.5 feet notifies the operator that the action taken was not effective and the DCS — or in some cases — the safety instrumented system (SIS), has shut the process down to avoid over-filling the tank. Incorrect use of multiple levels of alarming example: A client had a 40-foot naphtha tank with a high-high alarm set at 39 feet, designated with emergency priority, and a high alarm set at 38 feet, designated with high priority. There were no automated shutdown systems on this tank, and during operations, they overfilled the tank and had a loss of containment (LOC) incident. In an attempt to remedy this issue, the client contacted the DCS vendor and had a custom code written to add a high-high-high (HHH) alarm at 39 feet with an emergency priority, a high-high alarm at 38 feet with an emergency priority, and a high alarm at 37 feet with a high priority. Much to the chagrin of the client, this attempted resolution left their problem unresolved, and once again, they overfilled the tank and had a subsequent loss of containment (LOC) incident. This cycle repeated several times until they performed an alarm rationalization project. At the beginning of this project, the client’s setup was: High-High-High-High-High (HHHHH) Alarm at 39 ft with an EMERGENCY priority High-High-High-High (HHHH) Alarm at 38 ft with an EMERGENCY priority High-High-High (HHH) Alarm at 37 ft with an EMERGENCY priority High-High (HH) Alarm at 36 ft with an EMERGENCY priority High (H) Alarm at 35 ft with a HIGH priority Not only was this bad practice for industrial alarm system management, but the operators became so numb to the alarms that they were ignoring them and setting themselves up to run the tank over again. The results of their alarm rationalization study findings suggested reverting back to the original two (2) alarms and adding an automated shutdown at 39.5 feet with a LOW priority to notify the operator that control has been taken away from the operator and that an automated shutdown has occurred. Preventing DCS Alarm Floods with Advanced Suppression Techniques Another common issue in industrial alarm system management is the prevention of DCS alarm floods (e.g., having more than ten alarms in ten minutes). A leading cause of alarm floods is the absence of the configuration of advanced alarming techniques such as suppression. Many of the newer DCS systems now have some form of suppression built into them; however, this feature is often underutilized. Automated suppression is when the DCS automatically disables (suppresses) an alarm’s audible and visual indicators and sends the alarm to an event log or journal instead. Suppression can be used to support alarm flooding in multiple ways; one way is that it allows a single indication of an issue to be alarmed while hiding all the similar alarms the issue causes. An example of this would be a compressor trip. When the compressor is running, it has numerous alarms configured and enabled, such as the run status, high & low suction pressure, high & low discharge pressure, bearing temperatures, and vibrations — just to name a few. If the discharge pressure goes high while the compressor is running, it can be a big issue. You may have a plug downstream or someone may have accidentally closed a wrong valve. These things need to be taken care of quickly. However, if the compressor shuts down without suppression configured, the result each time will be a run status alarm along with alarms for the high suction pressure, low discharge pressure, all the bearing vibrations as it spools down, and potentially many other alarms. Typically, the only alarm needed is the run status alarm because if the compressor shuts down, a good operator knows that all of these secondary issues are due to the shutdown. If they are allowed to alarm, they become a distraction and hindrance to the mitigation of the issue. Enhancing DCS Security — The Importance of Firewalls and Controlled Internet Access Lastly, the largest issue in industrial alarm system management — which thankfully is seen less and less these days — is the lack of firewalls between the DCS and the outside world. Ideally, a control system would be “air-gapped” in order to minimize the possibility of introducing intrusions or viruses. However, this is not always possible. Typically, the DCS will be protected by firewalls, and often, those firewalls will be in their own layer between the control system and the rest of the company assets. The firewalls will only have a minimum number of obscure ports opened, and those ports will only allow one-way (outbound) traffic. This helps to minimize potential hijacking and infections. The most egregious example of not having firewalls that I have encountered was a few years ago on a project outside the US. One of the client’s complaints was how slow their DCS was running, and they were asking for suggestions on how to improve it. Upon entering the control room, my colleague and I were greeted by what is inarguably the nicest control room I’ve ever seen. The room was brightly lit and immaculately clean. The two (2) main operator stations were laid out in a huge arch in the middle of the room with sixteen (16) monitors each. Sitting perpendicular on the right end was the foreman’s station with four (4) monitors. In the back left corner was the utilities operator station with another twelve (12) monitors, and dead center of the front wall were eight (8) 55” monitors that networked together to make two (2) giant screens that were each two screens high by two screens wide. It was impressive, to say the least — until I realized that the giant screen on the right had more flashing red alarms than I have fingers to count. No one was paying attention to them because the operator on the left was using his giant screen to play an online video game. That’s right, the DCS had a direct connection to the internet. My first suggestion was to disable the internet connection and establish firewalls and the second was to delete all non-business required software from the system. Amazingly, within a week of implementing the suggestions, the system speed had more than doubled. While there are many more issues that could be discussed, these are the five most common issues that stand out in my career. Does your plant suffer from any of these issues or others not mentioned here? The Takeaway | Common Industrial Alarm Management Issues Addressing the most common industrial alarm management issues is crucial for ensuring operational efficiency, safety, and system reliability. By avoiding unnecessary and misused alarms, setting proper alarm criteria, implementing single alarms for each cause or corrective action, preventing alarm floods through advanced suppression techniques, and securing the DCS with firewalls and controlled internet access, companies can significantly enhance their alarm management systems. These ISA-approved best practices not only streamline operations but also empower operators to respond effectively to true emergencies, thereby minimizing risks and maintaining optimal system performance. Implementing these strategies will lead to a more robust and responsive alarm management framework, ultimately contributing to the overall success and safety of industrial operations. If your alarm system issues have you scratching your head, the experts at aeSolutions are always available to help identify and mitigate your industrial alarm system problems.

  • PHA Revalidations | Beyond Checking Boxes

    Introduction | Process Hazard Analysis Revalidation Carolyn Bott, Process Safety Group Manager — In the world of industrial operations, hazards are a given — but unmanaged hazards are a risk no facility can afford. A well-executed Process Hazard Analysis (PHA) is a vital safeguard, helping teams identify potential risks and define the controls needed to mitigate them. But a PHA isn’t a one-time event. As facilities and operations evolve, so must the analysis. That’s where a PHA Revalidation comes in. What is a PHA Revalidation? A PHA revalidation is a systematic update of an existing PHA study to ensure that it accurately reflects current operations, risks, and safeguards. Mandated under OSHA’s Process Safety Management (PSM) standard (29 CFR 1910.119), PHA revalidations are required at least once every five years. This ensures that facilities consistently assess whether existing safeguards and Independent Protection Layers (IPLs) are still appropriate and effective. Unlike a first-time PHA, a revalidation starts with reviewing the previous study. The team evaluates modifications — be it process design, control systems, staffing, procedures, or incident history — and determines whether those changes introduce new risks or warrant updates to the previous Process Hazard Analysis study. It should be noted that in some cases, a facility may determine that the existing PHA is no longer a reliable baseline — perhaps because of major modifications, process redesign, or poor quality in the original study. In these situations, a full PHA redo may be the better option. Methodologies Commonly Used in PHA Revalidations Several risk assessment methodologies are used during PHA revalidations, depending on process complexity and organizational preference. These include: HAZOP (Hazard and Operability Study): A systematic, guideword-based approach for continuous and batch processes LOPA (Layers of Protection Analysis): A method for evaluating the effectiveness of protection layers in reducing the frequency or consequence severity of hazardous events What-If and Checklist Analyses: Useful for simpler systems or as supplementary tools HAZID (Hazard Identification Study): Often applied in the early design phase or as a high-level review FMEA (Failure Modes and Effects Analysis): Focuses on component-level failure scenarios Bowtie Analysis: Visual mapping of causal pathways and safeguards for major hazards These methodologies are not mutually exclusive — they are often used in combination. The chosen methodology(s) should match the process and risk profile. Regulatory Requirements and OSHA Expectations for PHA Revalidations According to OSHA, a PHA must be revalidated at least every five years to ensure it remains consistent with the current process. The revalidation must be conducted by a team with expertise in engineering, operations, and hazard analysis methodology. The team should evaluate changes in equipment, procedures, and materials; verify that recommendations from previous PHAs have been resolved; and confirm that documentation and drawings (such as P&IDs) are current. OSHA further clarifies that a PHA revalidation doesn’t need to start from scratch. It can build upon the previous PHA, provided the review is thorough and documented. Failing to properly revalidate — whether by missing the five-year deadline or conducting an insufficient review — can lead to citations and increased risk exposure. Should I Revalidate Sooner Than Five Years? While the five-year cycle is the regulatory minimum, some facilities choose or need to revalidate more frequently. Situations that may warrant earlier review include: - Significant process changes such as new equipment, revised control strategies, or major throughput adjustments - Facility expansions or new unit operations - Introduction of new chemicals or process conditions - Recurring incidents or near misses suggesting underlying hazards were missed - Internal audits that identify PHA gaps or non-compliance - Evolving industry standards or new safety guidance that impact existing risk assessments In such cases, updating the PHA before the five-year mark can strengthen safety performance and demonstrate due diligence to regulators and insurers. Five Common Challenges in PHA Revalidations Executing a quality PHA revalidation takes planning, expertise, and cross-functional engagement. Below, we describe five common challenges that facilities face when conducting a Process Hazard Analysis Revalidation. 1. Inadequate Documentation and Information Management A revalidation is only as good as the information available. If the previous PHA scenarios were poorly documented or if process safety information (P&IDs, chemistries, etc.) hasn’t been kept current, the team will struggle. Without complete, up-to-date data on what has changed since the last PHA, important scenarios might be overlooked, or the team may waste time reconfirming basic facts. 2. Loss of Key Knowledge and Stakeholder Engagement It isn’t uncommon to find that the team who performed the initial PHA has transferred, retired, or simply moved into new roles by the time of revalidation. If a PHA Reval is not documented effectively, nor involves the appropriate process experts, understanding of the process risks can be lost. This type of insufficient stakeholder engagement can result in missing insights into how the process truly operates or deviates. Every PHA relies on the collective knowledge of its team and if that’s weakened, the revalidation may miss hazards or misunderstand the adequacy of IPLs. 3. Poor or Inconsistent Methodology Application If your PHA revalidation isn’t executed with consistent and up-to-date methods, gaps can occur. In some cases, the prior PHA might have used a different method or risk criteria than what the company uses now, causing confusion. For example, if the initial PHA methodology was misapplied or too simplistic for the process, it can result in the need for substantial correction down the road. Ensuring a comprehensive and systematic approach is applied during revalidation is vital to avoid leaving gaps. 4. Underestimating Time and Resources Required PHA revalidations can be resource intensive. A common mistake is assuming a revalidation will be quick since “we’ve done this before”, and then not allocating enough time or personnel knowledgeable in the process. The result can be rushed sessions, incomplete reviews, or missing documentation. If an organization doesn’t budget adequate time (including for pre-work and team meetings), the five-year deadline can sneak up. 5. Failure to Close Gaps from Previous PHA Recommendations A situation that many face during a PHA revalidation is discovering that some recommendations or gaps from the last PHA were never implemented or fully resolved. Not only does this pose an ongoing risk, but it also complicates the analysis — the team might find themselves re-discussing hazards that should have been mitigated. OSHA expects that existing PHA recommendations are tracked and completed before revalidation​. If that hasn’t happened, your facility faces both compliance issues and potentially repetitive findings. This issue often stems from lack of a robust management system for PHA action items. Anticipating and addressing these challenges early can significantly improve the quality of your PHA revalidation process. Best Practices for an Effective PHA Revalidation To mitigate the challenges described above, facilities should adopt several best practices for PHA revalidations: Prepare thoroughly: Update your process safety information, drawings, procedures, and incident history before the first team meeting. Performing this type of “mini audit” of changes and process safety performance since the last PHA will help drive the revalidation scope. Engage experienced facilitators: Facilitators with expertise in the methodology selected for the reval can guide the process and ensure consistency across nodes and scenarios. Ultimately, your PHA Reval team should consist of experienced operations personnel, engineers familiar with the process, and a competent facilitator. Additionally, involving members from the original PHA team and/or certified PHA leaders can benefit the effort. Involve stakeholders: Cross-functional support from those in operations, engineering, maintenance, and even management stakeholders who understand the process will increase your ability to maintain consistency and accuracy throughout the revalidation process. Verify implementation of past recommendations: A revalidation is an opportunity to check the status of all previously identified hazards. Best practice is to explicitly review how each risk scenario identified last time has been addressed. The team should verify that no known hazard has been forgotten. If some recommendations were deferred or not resolved, this is the time to reassess those risks and decide on an action. Additionally, incorporate any relevant incident learnings (from your site or industry) to enhance the prior analysis​. By looping back on past findings and new learnings, the revalidation closes gaps and solidifies your facility’s risk baseline. Document and track everything: Just as you review old recommendations, establish a strong process for following through on new PHA recommendations coming out of the revalidation. This includes clearly prioritizing them (e.g. using a risk matrix or LOPA results to rank urgency), assigning responsibility, and setting deadlines. Remember, OSHA requires documented resolution of PHA recommendations​ — having a tracking system not only aids safety but keeps your facility compliant. Consider partnering with a qualified PHA facilitator: One of the best investments for a successful PHA revalidation can be partnering with a skilled facilitator. An experienced, third-party PHA facilitator can provide a litany of benefits — including chemical and process knowledge across industries. Beyond providing expert guidance, facilitators can also serve as an objective, unbiased perspective. When considering an external PHA facilitator, look for a provider who goes beyond “checking the boxes.” Facilitators should also offer effective prioritization of risks and recommendations. Additionally, a facilitator should be able to present an actionable gap closure game plan that includes recommendations for trusted engineering solutions providers who can support resolving identified issues. You’ve Completed Your PHA Reval — What Next? A successful PHA revalidation doesn’t end when the last worksheet is signed. The real value comes from implementing recommendations and closing identified gaps. At this stage, facilities should: - Prioritize recommendations using risk matrices or LOPA to focus efforts on high-consequence scenarios - Develop actionable plans for implementation, assigning ownership, and tracking progress - Work with a facilitator or engineering partner who can help close common recommendations such as SIS upgrades, BPCS changes, Alarm Management improvements, BMS modifications, Facility Siting enhancements, and Fire & Gas system updates. - Document closure, including verification of effectiveness and updates to procedures or training as needed Without follow-through, a PHA revalidation becomes a compliance checkbox rather than a meaningful tool for reducing risk. The Takeaway | Turn Your PHA Reval Findings into Forward Motion Process safety isn’t static — and your PHA shouldn’t be either. Regular, well-executed PHA revalidations are essential to staying compliant with OSHA, maintaining operational continuity, and safeguarding personnel and assets. For facilities navigating complex changes, aging infrastructure, or resource constraints, engaging with experienced PHA facilitators can bring structure, insight, and measurable outcomes to the revalidation process. When done right, PHA revalidations don’t just ensure compliance — they create a roadmap for safer, smarter operations.

  • Protecting Personnel and Plant with Facility Siting

    The Value of Facility Siting Studies Process industry history is sprinkled with catastrophic incidents that acted as drivers of regulatory change, such as the 1974 Flixborough explosion, the 1984 Bhopal toxic release disaster, and the 2005 Texas City Refinery flammable material release and explosion. Lack of process safety management, damage, and deaths were the commonalities among these incidents. The OSHA Process Safety Management (PSM) Standard and EPA Risk Management Plan (RMP) regulations were promulgated in response to these types of devastating accidents. These regulations were supplemented in the US by industry standards such as the American Petroleum Institute (API) Recommended Practices 752, 753, and 756, and with guidance developed by the Center for Chemical Process Safety (CCPS). These standards and guidance documents became the consensus industry practices for performing facility siting (FS) studies. Facility siting studies analyze potential toxic, fire, and explosion hazards to personnel from releases of hazardous chemicals. From a regulatory perspective, facility siting is required in the US by OSHA PSM and EPA RMP for facilities that meet the qualifying definition. A checklist is often utilized during Process Hazard Analyses (PHAs) to meet the regulatory requirements for facility siting; however, a facility siting study provides a more detailed analysis of specific facility siting concerns and should be referenced during PHA scenario development. Facility Siting | A Commitment to Your Team & Your Community Irrespective of regulation, it is best practice to conduct a facility siting study to understand the implications of a release of hazardous materials at your facility. While PHAs develop hazard scenarios that could potentially result in loss of containment, a FS study assumes a release has occurred and evaluates the outcomes accordingly. aeSolutions utilizes the following general approach to performing a facility siting study: Identify chemicals of concern Collect information on site-specific conditions (e.g., equipment and process data, building construction and occupancy data, equipment and building locations on the facility) Identify potential hazard event scenarios from a review of PHAs, incident investigation reports, discussions with experienced personnel, and other pertinent sources of information Identify and classify occupied buildings Perform the hazardous material release consequence analysis Perform the risk analysis if a risk-based approach is used Package the results in a way that the results can be understood and review the results with the client Discuss with the client options to reduce risk For the consequence analysis, software can be used to model the discharge, dispersion, and impacts of an accidental release of flammable or toxic material. Limiting the analysis to the consequence analysis, the facility siting study results are consequence-based, which provides a measure of the severity of the hazard. Taking the assessment, a further step, a Quantitative Risk Assessment (QRA) can apply release event frequencies and appropriate probabilities, such as probability of ignition and vulnerability of people to the various effects, to quantify the risk associated with a release scenario. A consequence-based facility siting study is simpler and requires less resources to perform, but the results of a consequence-based FS study may set a higher bar to address and necessitate additional action or protection at a facility. A risk-based QRA requires more expertise and resources to perform the study, but the benefit gained is that the study often finds that the event likelihood of many scenarios is so low that the hazard meets the company risk criteria and additional means of protection that a consequence-based study concludes is needed are not required after all (i.e., less resources spent on addressing facility siting study results). The Takeaway | Facility Siting Studies Conducting a facility siting with a practical approach to study methodology and risk mitigation can balance the cost and course of action to protect personnel and facility assets. This enables company leaders to better make reasonable decisions on how to protect their employees. For instance, relocating all personnel to blast resistant modules can become expensive and may not be necessary in all cases; an alternative combination of innovative solutions may accomplish the risk reduction. Protection can come in different forms, such as increasing airflow through a building for preventing flammable vapor or gas accumulation or utilizing shelter-in-place for toxic concerns. Facility siting requires a pragmatic evaluation of the nature and level of hazard and what would be best for personnel and the plant. Facility siting regulations and standards have improved significantly since the Flixborough, Bhopal, and Texas City Refinery catastrophic incidents and continue to evolve to ensure toxic, fire, and explosion hazards are appropriately mitigated in the future. Ultimately, a detailed facility siting study can help you understand the hazards of potential releases, how those hazards can impact occupied buildings, and most importantly, determine effective solutions to protect your valued workforce.

  • Can Stage 3 FSA Confirm Your Safety Instrumented System Is Ready for Operational Use?

    The primary goal of an FSA Stage 3 is to verify that the installed safety instrumented system (SIS) matches the design package and is prepared for operational use. FSA Stage 3 takes place once installation, commissioning, and validation activities are finalized, often as part of the Pre-Startup Safety Review. This stage entails a comprehensive assessment of the installation and pre-commissioning efforts to confirm that the SIS are properly implemented and prepared for safe operational use. This assessment is the final FSA prior to startup. Subsequent stages are done after gaining experience in operations and maintenance (Stage 4) and, after modifications and prior to decommissioning of a SIS (Stage 5). The deliverable for a Stage 3 FSA includes a comprehensive report with a Stage 3 FSA checklist derived from a site visit and independent assessment. This report will present findings, including serious deficiencies, recommendations, and general observations. The following recommendations will ensure a cost-effective, efficient, and expedient Stage 3 FSA. What Is the FSA Stage 3 Process? A Functional Safety Assessment (FSA), defined by IEC 61511, is an evidence-based investigation into the functional safety achieved by one or more safety instrumented systems (SIS) and/or other protection layers. Stages 1 through 3 of an FSA cover the Safety Instrumented System (SIS) from its inception through design, construction, and commissioning. These stages are essential for the implementation of a new or modified safety system. Stage 3, which occurs after the installation, pre-commissioning, and final validation of the SIS, ensures that the system is ready for operation and can effectively mitigate risks as intended. The FSA Stage 3 process typically consists of the following steps: installation validation, operational readiness, maintenance preparedness, and system validation. The objectives for each of these processes are listed below in the table below. Process Step Objectives Installation Validation ● Physical Validation: Ensure that hardware, such as transmitters and valves, is correctly installed and wired according to design specifications. ● Wiring and Connections: Check that all wiring and connections comply with design documentation, including correct labeling, termination, and routing. Operational Readiness ● Operator Training: Confirm that operators are trained to use the new system and understand its impact on process control. ● Procedure Verification: Ensure that operating procedures align with SIS functionality, including emergency shutdown procedures, alarm handling, and routine maintenance tasks. Maintenance Preparedness ● Maintenance Training: Train maintenance personnel on SIS maintenance requirements, including routine checks, troubleshooting, and repair procedures. ● Spare Parts Inventory: Verify that an adequate inventory of spare parts is available to address potential failures, ensuring minimal downtime. Validation of System Functionality ● Component Testing: Each component undergoes testing to ensure correct functionality. For instance, sensors must accurately detect process parameters, and actuators and final control elements must respond as expected. ● Integrated Systems Testing: Conduct integrated testing to ensure that the entire SIS works as a cohesive unit, as envisioned. This involves simulating process conditions and verifying the system's appropriate response to hazardous situations. Table: Process Steps for FSA Stage 3 Team Engagement and Stage 3 FSAs Successful Stage 3 FSAs benefit from active team engagement. Teams should allocate sufficient time for interviews and training sessions, allowing assessors to gather comprehensive information. This level of commitment, although challenging due to operational demands, significantly enhances the assessment's effectiveness and the overall safety of the SIS. During Stage 3 FSAs, typical issues include discovering that safety instrumented functions do not perform as expected during testing, often stemming from incorrect design assumptions. To mitigate such issues, it is essential to involve key personnel such as operations supervisors and maintenance technicians in the assessment process. This personnel inclusion ensures a comprehensive understanding of the system's functionality and readiness. Conclusion By ensuring that the installation, operational readiness, and maintenance preparedness are thoroughly verified, Stage 3 FSAs help prevent hazardous events and protect both personnel and assets. Engaging the team actively and addressing potential issues proactively can significantly enhance the effectiveness of Stage 3 FSAs, ensuring the safety and reliability of industrial operations.

  • How to keep the alarm management lifecycle evergreen

    Updated April 2026 - It is commonly touted that once a plant rationalizes their alarms, they have completed the alarm management lifecycle. Nothing could be further from the truth. So what can an organization do to keep the alarm lifecycle alive and evergreen? Alarm management is the collection of processes and practices for determining, documenting, designing, operating, monitoring, and maintaining alarm systems. It is characterized by design principles including hardware and software design, good engineering practices, and human factors. Tying the alarm management lifecycle into process safety management and other work processes that already exist will help ensure it remains evergreen and delivers the intended benefits. While the integration of these activities will look different for each company, time has shown that success comes most easily when the management of change process, testing and training activities have been integrated into what is already being accomplished. The alarm management lifecycle is essentially a circle; there is no beginning or ending. There are different places an organization may choose to enter it, but the overall lifecycle process never really ends. An organization may have developed a philosophy, rationalized alarms, and implemented them, but that does not mean they have ‘completed’ alarm management. As processes and equipment evolve and change (e.g., removing or introducing equipment, changing flow rates, changing chemicals, etc.), different steps of the lifecycle come back into importance. The goal of alarm management should be to keep the lifecycle updated and evergreen. Integrating the alarm management, functional safety, and cybersecurity lifecycles is a key to success and will help avoid costly rework. There are similarities in all three lifecycles (e.g., asses, implement, operate & maintain phases, management of change, testing and training requirements, etc.). The process hazards analysis (PHA) feeds the other lifecycles. When assessing items in cybersecurity, one is considering scenarios first identified in PHAs. The same is true in alarm management when an alarm is used as a protection layer. A change in one lifecycle may, and most likely will, impact all three lifecycles. Something as minor as altering a chattering alarm (e.g., because its setpoint was too close to a shutdown value) will impact the alarm, the master alarm database, the other lifecycles, and many different process safety information documents. If normalization of deviation is allowed (i.e., not tracking and reviewing the impact of what are believed to be minor changes), alarms will eventually become unrationalized, and things will revert back to their original, un-managed state. To learn more about the ISA 18.2 standard and how to keep the alarm management lifecycle evergreen, read the full paper “Breathing life into the alarm management lifecycle” .

  • aeSolutions Opens New Houston Office in Energy Corridor

    Houston, TX - February 20, 2024 - aeSolutions, a leading consulting, engineering, and systems integration company specializing in industrial process safety and automation products and services, announces the opening of its newest office located in Houston’s Energy Corridor. The relocation is part of the company’s aggressive strategic growth plans and will serve as a hub for its operations in the Gulf Coast region. The new office will allow aeSolutions to enhance its service offerings in the energy sector, providing localized client support and strengthening relationships with key industry partners. The Houston Energy Corridor, renowned as a global energy hub, offers an ideal location for aeSolutions to engage with a wide range of markets, including traditional and alternative energy sectors, agribusiness, metals, chemicals, and petrochemicals. aeSolutions, explained, "Houston continues to be a crucial market for aeSolutions because of its concentration of client operations and its significance in the energy sector as well as many other growing market sectors. We believe growing a regional presence from Houston will allow us to serve our clients better." The Houston office will provide a variety of expertise and services tailored to support aeSolutions' clients in the region. These services include project development and execution, focusing on fired equipment, alarm management, process safety management, and safety instrumented systems. "We aim to offer project solutions to our clients in Houston and the broader Gulf Coast area, helping them navigate complex safety issues and enhance their operations to drive client success," aeSolutions added. As part of its outreach, aeSolutions invites interested parties to schedule introductory meetings to learn more about its services and explore potential job opportunities in the Houston area and nearby Gulf Coast regions. For job inquiries, please email resumes@aesolutions.com. About aeSolutions In business since 1998, aeSolutions is a consulting, engineering, and systems integration company that provides industrial process safety and automation products and services. They specialize in helping industrial clients achieve their risk management and operational excellence goals through expertise in process safety, combustion control and safeguarding, safety instrumented systems, fire and gas, control system design and integration, alarm management, and related operations and integrity management systems. For more information, click here.

  • aeSolutions Announces Key Leadership Promotions to Support Continued Client Success

    Greenville, SC – April 2025 – aeSolutions, a provider of integrated, end-to-end critical system solutions that empower resilient operations and safer communities, is proud to announce three strategic internal promotions, reflecting the company’s continued commitment to realizing employee potential through the achievement of client success. Roland Stock, PMP, a current member of our Senior Leadership Team, has been named Vice President of Projects, where he will lead our Project Management Office and cross-functional project teams in the development and execution of projects to achieve our clients’ goals. Roland brings deep experience in project leadership and a strong track record of delivering complex solutions across industries. “These promotions reflect the depth and breadth of talent and the strategic importance of developing our leaders’ potential,” said aeSolutions. “Roland has demonstrated dedication to our clients’ success through exceptional leadership, technical acumen, and progressive experience. We are thrilled to him step into this new role.” Visit aeSolutions for more information.

  • Whitepaper: The Courage to Intervene | Developing Ethical Leadership in the Next Generation of Process Safety Professionals

    May 2026 — by aeSolutions Technical Team — As the process industries experience the “great shift change,” developing the next generation of leaders requires more than technical competence. It demands ethical courage and the ability to influence others to uphold process safety under pressure. This paper explores how ethical decision-making and leadership behaviors can be intentionally developed through structured case-based learning derived from real engineering failures. Drawing on historical and modern examples such as the Flint Water crisis, the Volkswagen emissions scandal, and the Challenger disaster, the presentation examines the ethical breakdowns that preceded technical failures and identifies leadership behaviors that could have altered outcomes. Each case is used to highlight the moral obligations of engineers to “hold paramount the safety, health, and welfare of the public,” and to show how ethical reflection builds the foundation for process safety leadership. Although the work does not present traditional process safety KPIs, it proposes leading qualitative indicators of ethical maturity, such as escalation behaviors, adherence to safety values under duress, and psychological safety for dissent, as precursors to measurable safety performance. The paper outlines a practical framework for integrating ethics-based reflection into leadership development programs, helping organizations sustain process safety excellence even as experienced leaders retire. Introduction Several years ago, during final commissioning activities on a newly installed Burner Management System (BMS), a corporate safety leader made a decision that delayed startup and imposed significant additional cost. The original validation and commissioning activities had been completed, and from a strictly procedural standpoint, the project could have moved forward. However, upon internal review, it became clear that portions of the work had been executed under schedule pressure and did not reflect the level of rigor the organization expected of itself. No regulation required the activities to be repeated. There was no formal non-compliance. Yet the corporate safety leader required that key validation steps be re-executed in full before the equipment was placed into service. The decision was met with understandable resistance. Project timelines were affected, operational plans were disrupted, and the financial impacts were real. What distinguished the moment was not merely the decision itself, but how it was communicated. The leader explained publicly that safety-critical work should never be rushed, “pencil-whipped,” or accepted at a standard below what the organization would defend in hindsight. If the work was not done correctly the first time, it would be done correctly before proceeding. The message was clear. Safety was not a box to be checked, but a value to be upheld even when operational pressures pushed in the opposite direction. For many younger engineers and professionals observing the situation, the lesson extended well beyond the technical. They witnessed a senior leader absorb cost and friction in order to align actions with the company’s principles. They saw that organizational values were not conditional on schedule convenience. Moments like this illustrate an important aspect of ethical leadership in process safety. Ethical leadership is often demonstrated not when a decision is obviously unsafe, but when a leader recognizes and interrupts the early stages of normalization of deviation before reduced rigor becomes accepted practice. As experienced leaders across the process industries approach retirement, moments like this raise an important question. What exactly are we at risk of losing? While much attention has been given to the transfer of technical knowledge and institutional memory, less attention has been paid to the transmission of ethical leadership. It is this visible modeling of values-aligned decision-making under pressure that this paper explores. This paper argues that as experienced process safety leaders retire, the deliberate development of ethical leadership capability becomes increasingly critical. Organizations can strengthen process safety performance not only by preserving technical expertise, but by training, equipping, and empowering leaders to make and model decisions that protect life and the environment even when those decisions carry personal, organizational, or commercial cost. Structural Transitions in the Process Industries The decision described in the introduction illustrates how organizational values are ultimately expressed through leadership behavior. Moments where safety-aligned decisions carry visible cost help shape how engineers and operators understand what their organization truly prioritizes. However, the context in which these leadership behaviors are transmitted is changing. Across the process industries, organizations are experiencing what is often described as the “great shift change,” as a large cohort of experienced engineers and operational leaders approach retirement. Much of the discussion surrounding this transition has focused on the transfer of technical knowledge. An equally important question concerns the transmission of leadership behaviors that shape process safety decision-making. Experienced leaders often carry not only deep technical expertise, but also practical judgment developed through years of navigating operational pressure and technical uncertainty. As these leaders leave the workforce, organizations face the challenge of ensuring that both technical competence and leadership norms are sustained in the next generation. Industrial operations inevitably function within environments where production targets, project schedules, and capital constraints compete with safety priorities. Major incident investigations repeatedly show that these pressures influence decision-making environments, particularly when technical uncertainty is present (Hopkins, 2012). At the same time, organizational structures have evolved. Many companies operate across geographically distributed assets, rely more heavily on contractors and specialized expertise, and maintain leaner staffing models. These changes can improve efficiency, but they may also reduce opportunities for informal apprenticeship through which personnel historically learned how experienced leaders approached difficult safety decisions. Taken together, these structural transitions do not imply that organizations today are less committed to safety. They simply highlight the importance of deliberately reinforcing the leadership behaviors that support sound safety decisions as experienced leaders retire and organizational complexity increases. What Ethical Leadership Means in a Process Safety Context Discussions of ethics in engineering are often framed in terms of professional codes and individual integrity. These principles are foundational, and most engineers readily agree that protecting the safety, health, and welfare of the public should guide their work. In practice, however, the ethical dimensions of process safety leadership rarely present themselves as clear distinctions between right and wrong. Instead, they typically emerge through routine operational decisions made under conditions of uncertainty, competing priorities, and incomplete information. In many situations, the safest course of action is not immediately obvious. Engineering analyses may indicate that equipment can continue operating within acceptable limits. Procedures may technically have been followed. Operational momentum may favor continuing planned activities rather than revisiting earlier work. Under these conditions, individuals may not recognize that safety margins are gradually eroding, or they may feel uncertain about their authority to challenge decisions that appear already accepted. The result is that well-intentioned professionals sometimes make expedient decisions that appear reasonable in the moment, even if those decisions incrementally reduce the rigor applied to safety-critical work. Over time, incremental compromises can reshape what an organization considers normal. Conditions that were once viewed as deviations may gradually become accepted practice, a phenomenon commonly described as normalization of deviation (Vaughan, 1996). As this occurs, safety margins may gradually erode without any deliberate decision to lower standards. Instead, the organization adapts to small departures from expected rigor until those departures are no longer perceived as unusual. Within this environment, ethical leadership plays a critical role. Ethical leadership in process safety involves recognizing and interrupting the early stages of normalization of deviation even when doing so requires slowing work, questioning accepted assumptions, or absorbing operational cost. The commissioning example described earlier illustrates this dynamic. The decision to repeat commissioning activities was not driven by regulatory non-compliance or a clear technical failure. Rather, it reflected recognition that the work had not been performed with the rigor expected for a safety-critical system. Understanding ethical leadership in these operational terms helps explain why leadership behavior plays such an important role in sustaining process safety performance. The challenge facing many organizations is therefore not simply to employ individuals with strong personal values, but to ensure that leadership behaviors that reinforce those values are consistently demonstrated and supported throughout the organization. How Ethical Erosion Occurs Major industrial accidents rarely begin with deliberate misconduct or reckless disregard for safety. Instead, investigations consistently show that incidents emerge through a sequence of decisions that appear reasonable within the context in which they are made. One mechanism through which this occurs is the gradual normalization of deviation. When small departures from expected standards do not immediately produce negative consequences, they can become incorporated into routine operations. As these departures accumulate, the boundary between acceptable practice and deviation becomes increasingly difficult to distinguish. The resulting decisions may continue to appear technically defensible, even as safety margins erode. Operational momentum often accelerates this process. In complex industrial environments, work frequently proceeds under schedule commitments, production targets, and project milestones that encourage forward progress. Within such contexts, the most expedient decision may be the one that allows operations to continue without interruption. While these pressures are not inherently incompatible with strong safety performance, they can create conditions in which revisiting earlier assumptions or pausing work for additional verification becomes increasingly difficult. Investigations into major incidents across the process industries reveal similar patterns. Events such as the Deepwater Horizon disaster in the Gulf of Mexico, the 2018 explosion at the Husky Energy refinery in Superior, Wisconsin, and the 2019 fire at the Intercontinental Terminals Company facility in Deer Park, Texas demonstrate how technically defensible decisions made within routine operational contexts can gradually reshape assumptions about acceptable risk (Hopkins, 2012; CSB, 2018; CSB, 2019). These examples illustrate a common theme: ethical erosion rarely occurs through a single dramatic decision. Instead, it develops through a sequence of technically defensible choices made within complex organizational environments. When operational momentum, incomplete information, and shifting expectations combine, the gradual normalization of deviation can make it difficult for individuals to recognize when safety margins are being compromised. Under such conditions, ethical leadership becomes particularly important. Leaders who pause work to request additional verification, challenge accepted assumptions, or escalate concerns play a critical role in interrupting these dynamics. Organizational Reinforcement of Ethical Leadership Preventing ethical erosion requires more than relying on the judgment of individual leaders. Organizational systems and leadership signals strongly influence whether safety-aligned decisions are recognized, supported, or discouraged. While personal integrity remains essential, the environment in which leaders operate plays a significant role in shaping how safety priorities are interpreted during routine operational decisions. Research on process safety leadership emphasizes that visible reinforcement from leaders is a critical factor in sustaining strong safety culture (CCPS, 2015). Employees continuously observe how leaders respond when safety concerns are raised, work is slowed, or additional verification is requested. These responses communicate powerful signals about what the organization truly values, particularly when safety decisions carry operational or financial consequences. One important signal concerns how organizations respond when operational momentum is interrupted in the interest of safety. In environments where schedule performance and production targets dominate performance discussions, individuals may hesitate to question assumptions or request additional scrutiny. Conversely, when leaders demonstrate that raising concerns or pausing work will be supported rather than criticized, employees are more likely to intervene when safety margins appear uncertain. Clear escalation pathways also influence whether potential deviations receive appropriate attention. When escalation processes are unclear or perceived as ineffective, individuals may conclude that raising concerns will have little practical impact. Organizations that provide clear channels for escalation and respond constructively to concerns help ensure that potential deviations are addressed before they become normalized. The example described in the introduction illustrates how these reinforcing signals operate in practice. By requiring the BMS commissioning activities to be repeated and explaining the reasoning behind that decision, the corporate safety leader not only addressed a specific concern but also reinforced a broader organizational expectation. Safety-critical work must be performed with the level of rigor that the organization is prepared to defend in hindsight. Organizations ultimately receive the safety culture they reinforce. When leaders visibly support individuals who pause work, escalate concerns, or request additional verification, they strengthen norms that help protect safety margins. The Mentorship Gap Historically, many leadership behaviors that support strong process safety performance were transmitted informally through observation and experience. Engineers and operators learned not only technical practices, but also how experienced leaders interpreted uncertainty, responded to operational pressure, and decided when additional rigor was necessary. These lessons were rarely taught explicitly. Instead, they were absorbed through repeated exposure to how respected leaders approached difficult operational decisions. In this informal apprenticeship model, early-career professionals often observed moments when experienced leaders paused work, challenged assumptions, or escalated concerns despite operational inconvenience. These decisions served as powerful signals about how the organization expected safety margins to be protected. Over time, such observations helped individuals develop judgment regarding when a situation required additional scrutiny or intervention. As the process industries undergo generational leadership transition, this mechanism of leadership transmission may become less reliable. The retirement of experienced leaders reduces opportunities for younger engineers to observe how complex safety-related decisions are handled in practice. At the same time, organizational structures that rely on distributed teams, lean staffing models, and increased contractor participation can limit the frequency of direct interaction between early-career professionals and senior leaders. Organizational researchers have described how complex systems can gradually “drift into failure” when deviations accumulate without visible intervention from experienced leaders (Dekker, 2011). When opportunities to observe those interventions decrease, individuals may rely more heavily on procedural compliance rather than judgment developed through experience. As experienced leaders retire, organizations may therefore need to take a more deliberate approach to ensuring that ethical leadership behaviors remain visible. Highlighting and discussing leadership decisions that demonstrate how safety commitments are applied under operational pressure can help the next generation of engineers understand how safety expectations should guide operational judgment. Developing the Next Generation of Ethical Leaders If organizations can no longer rely solely on informal mentorship to transmit leadership behaviors, they must become more deliberate in how ethical leadership is developed and reinforced. While formal training and management systems play an important role, many of the most influential lessons about safety leadership still come from observing how leaders make decisions in practice. For this reason, the everyday actions of leaders can significantly influence how safety expectations are interpreted across an organization. Several leadership behaviors can help reinforce ethical decision-making in practice. Three are particularly important. Explain safety decisions openly When leaders make safety-aligned decisions, such as repeating incomplete work, pausing operations for additional verification, or escalating a concern, explaining the reasoning behind those decisions helps others understand how safety margins are evaluated. Without this transparency, employees may see only the operational consequences of the decision rather than the safety considerations that motivated it. Over time, openly discussing these decisions helps establish shared expectations about the level of rigor required for safety-critical work. Encourage questioning and verification Many safety-critical decisions involve interpreting incomplete or uncertain information. In these situations, individuals may hesitate to raise questions if doing so could disrupt operations or challenge established plans. Leaders who consistently invite questions, request independent verification, or revisit underlying assumptions signal that scrutiny is expected rather than discouraged. This behavior helps create an environment in which potential deviations are more likely to be identified before they become normalized. Support those who intervene for safety When employees observe that raising safety concerns results in constructive engagement rather than criticism or frustration, they are more likely to act when conditions appear uncertain. Conversely, when individuals experience negative reactions after slowing work or escalating a concern, they may become reluctant to intervene in the future. Leaders who visibly support individuals who pause work to address uncertainty reinforce the expectation that protecting safety margins is consistent with organizational priorities. Together, these behaviors help ensure that safety expectations remain visible to the next generation of engineers and operators. While technical procedures define required safeguards, leadership behaviors shape how those safeguards are interpreted when operational pressures are present. Making ethical leadership visible in everyday decisions therefore plays a critical role in sustaining strong process safety performance. Conclusion The decision described in the introduction delayed startup and imposed real operational cost. From a procedural standpoint, the commissioning work had already been completed, and operations could have moved forward. Yet the corporate safety leader chose to repeat the validation activities to ensure that the work reflected the level of rigor expected for a safety-critical system. Moments like this shape how safety leadership is understood within organizations. Engineers and operators learn not only from procedures and training, but also from observing how leaders respond when operational pressure challenges safety expectations. These visible decisions communicate how organizational values should guide judgment when competing priorities are present. As the process industries experience generational leadership transition, the visibility of these examples may become less consistent. While technical knowledge can be documented and transferred through procedures and training programs, the leadership behaviors that demonstrate how safety commitments are applied in practice are more difficult to capture in written guidance. Ultimately, the most enduring legacy of experienced process safety leaders may not be the knowledge they pass on, but the example they set. By openly explaining and supporting safety-aligned decisions, particularly when those decisions carry operational consequences, leaders help ensure that the next generation of engineers understands how safety values should guide decision-making under pressure. References Hopkins, A. (2012). Disastrous Decisions: The Human and Organisational Causes of the Gulf of Mexico Blowout. CCH Australia. Vaughan, D. (1996). The Challenger Launch Decision: Risky Technology, Culture, and Deviance at NASA. University of Chicago Press. U.S. Chemical Safety and Hazard Investigation Board (CSB). (2018). Husky Energy Refinery Explosion and Fire Investigation Report. U.S. Chemical Safety and Hazard Investigation Board (CSB). (2019). Intercontinental Terminals Company (ITC) Deer Park Terminal Fire Investigation Report. Center for Chemical Process Safety (CCPS). (2015). Process Safety Leadership from the Boardroom to the Frontline. AIChE. Dekker, S. (2011). Drift Into Failure: From Hunting Broken Components to Understanding Complex Systems. Ashgate Publishing.

  • aeSolutions Recognized with 2026 CSIA Social Responsibility Award

    May 2026 - aeSolutions is proud to share that we were recognized with the 2026 Social Responsibility Award at the 2026 CSIA Awards, held during the Control System Integrators Association Conference in Baltimore, Maryland. Presented to an Integrator or Partner Member that has achieved outstanding results through corporate social responsibility and sustainability initiatives, the award recognizes the impact of aeSolutions’ evolving approach to charitable giving and community support. The award was accepted by Chery O’Malley, SPHR, and Ken O’Malley, PE (SC), CFSE, CEO. The 2026 CSIA Social Responsibility Award was accepted by Chery O’Malley, SPHR, and Ken O’Malley, PE (SC), CFSE, CEO. Expanding the Meaning of Community Since aeSolutions was founded in Greenville, South Carolina in 1998, supporting the communities where we live and work has been part of our culture. For many years, those efforts were closely connected to our office locations in Greenville, Houston, and Anchorage, where employees came together around local volunteer efforts, fundraisers, and charitable initiatives. As our workforce shifted to a more remote and hybrid structure, our approach needed to evolve. With employees now working from home offices across a wider geographic footprint, aeSolutions reconsidered what “community” means for a distributed team and how the company could continue supporting causes that matter to employees, clients, and families across the country. A Charitable Giving Program Led by Employees In 2024, aeSolutions relaunched its charitable giving program with a renewed focus on employee input. Rather than limiting support to organizations near our office locations, the program invites employees to recommend causes that are meaningful in their own communities. To ensure that each contribution is aligned with aeSolutions’ corporate responsibility goals, selected organizations must be highly rated and connected to one of four key pillars of support: Hunger Relief, Health and Human Services, Education, and Military/Veteran Support. This structure helps aeSolutions direct charitable support toward organizations that are both meaningful to employees and positioned to make a measurable impact. The program has continued to grow each year. In its first year, aeSolutions supported ten employee-recommended organizations, including local Red Cross chapters, meals programs, and health-related organizations. In year two, the company expanded the program to include matching campaigns, helping increase the impact of employee donations to selected organizations, including food banks during a period of increased need. Now in its third year, the program has continued to build momentum, including a recent education-focused initiative that provided a 3x match for employee donations through Donors Choose. This effort helped support STEM programming and classroom materials for under-funded schools across several communities. Continuing the Work This recognition from CSIA is an honor, but more importantly, it reflects the care and commitment of aeSolutions employees. Their recommendations, participation, and generosity have helped shape a charitable giving program that reaches beyond office walls and responds to real needs in communities across the country. As aeSolutions continues to grow, we remain committed to supporting the people and communities connected to our team, our clients, and our work. Learn more about aeSolutions’ Corporate Responsibility.

  • Control System Migrations | Part 7 | Best Practices for Installation, Testing, & Commissioning

    Introduction | Control System Migrations | Part 7 | Cutover, Commissioning, and the Final Push Updated May 2026 — by Tom McGreevy, PE, PMP, CFSE — Welcome to part 7 of our Control Systems Migration blog series. In this installment, we’ll be covering the cutover phase, which is where it all comes together. This is the point where months or even years of preparation culminate in the actual replacement of the old control system with the new. It’s a high-stakes, high-pressure moment, and one where success is determined by how well you’ve planned, documented, and executed. The term “cutover” covers everything from physical equipment replacement to software commissioning and testing. It’s not just about wiring panels; it’s about making sure every step, from demo drawings to site acceptance testing, is aligned and accounted for. Do I Need to Begin with a Full System Backup? The short answer: Absolutely. Before any equipment is touched, every element of the current system must be backed up. That includes program logic, Human Machine Interface (HMI) configurations, and current “as-found” drawings. Photos of panel internals and field installations can also be valuable, not just as references in case you need to troubleshoot, but as a last-resort rollback option if something unexpected forces you to pause or reset the transition. In a rip-and-replace scenario, rolling back may not be feasible, but having a complete picture of the system you’re decommissioning can still help solve problems when they arise during construction or testing. What Should I Include in a Cutover Execution Plan? Your cutover execution plan should be specific and clearly documented. It must describe step by step how the cutover will proceed and clarify who’s responsible for each task. It should also detail what tools, drawings, resources, and timing are required for each stage. This plan should leave no room for ambiguity. What’s happening to each wire? Which devices stay, which go? Are there mystery components, the purpose and disposition of which is not 100% understood? Those need to be resolved before the first wire is lifted, or if not, at least addressed as part of your early cutover activities. Most importantly, there is significant value in making sure this plan is in the hands of the right people. Having a perfectly crafted set of work packages and drawings means nothing if the team in the field doesn’t have them. This kind of breakdown in communication is surprisingly common, but fortunately, it is also completely avoidable. What Pre-Shutdown Work Should Be Done Before a Control System Migration? Any construction or staging work that can be done before the shutdown should already be complete. This includes routing and tagging cables, installing panels where possible, staging materials, and setting up temporary facilities like backup power in accordance with OSHA safety guidelines. If it can be done early, do it early. This will reduce the pressure during actual outage windows and create space to address the unexpected. The Details Matter — Down to the Wire One of the most critical aspects of a successful cutover is understanding where every single wire goes and what it does. If wires aren’t clearly labeled, properly documented, or tied to an understood function, you risk losing control over the tactical situation very quickly. Similarly, you must know the purpose and disposition of every field device. Is it being reused, replaced, or removed? Has it been tagged and labeled correctly? These details feed directly into the accuracy of your demo drawings and revised documentation, which in turn drives construction confidence and efficiency. Even the basics, like wire sizes, must be documented. Tasks like these may seem like a small detail, but mismatched or unlabeled wire sizes can lead to serious setbacks during installation. Construction Documents vs. Loop Sheets It’s also worth noting that loop sheets, while useful for function testing and configuration, are not construction documents. Teams need full demo drawings, updated termination diagrams, and accurate cable schedules to perform field work efficiently. Relying on loop sheets for installation will almost certainly slow the progress and may invite error and confusion. Mechanical Completion: Knowing When You’re Ready Before applying power to the new system, everyone involved must agree on what defines mechanical completion. At this point, all installation work should be finished, verified, and supported by construction assurance documentation. It’s a formal milestone that marks the transition from building the system to bringing it to life. Assurance activities in support of demonstration of Mechanical Completion include visual inspections, comparison to approved drawings, wiring continuity checks, and proper ground measurements (of both safety and signal ground). Site Acceptance Testing, Commissioning, and Function Checks Once mechanically complete, the system undergoes site acceptance testing (SAT) the first time it’s powered on in its new environment. This phase confirms that nothing was damaged during shipping or installation, and that devices are behaving as expected at a basic level. From there, teams move into loop checks, verifying that inputs and outputs are correctly wired and responsive. These checks ensure that transmitters, control valves, and I/O points communicate properly with the system and that grounding is correct. This may also include bumping of motors for those motors controlled by the system, and verification of good communications to any and all third-party devices. It is critical that EVERY I/O device that had its wiring touched during the cutover be checked, to give high confidence in wiring integrity and to enable efficient functional testing. Finally, functional testing begins. Depending on the system, this could include “water runs,” simulation of Safety Instrumented Functions (SIFs), and validation of interlocks. Every step should follow a documented test plan, not just for consistency, but to ensure accountability and traceability. The temptation to rush through these tests can be strong, especially during time-constrained shutdowns. But skipping steps here can have serious consequences, ranging from costly mistakes to safety hazards and legal liabilities. The Takeaway The cutover process is considered the most visible and intense phase of a control system migration. It’s where all the planning, documentation, and collaboration either pay off or fall short. When executed well, the cutover is a moment of accomplishment, the grand finale of your migration efforts. But without discipline, rigor, and proper preparation, it can quickly become chaotic, stressful, and, worst of all, dangerous to equipment and people This phase rewards diligence, not improvisation. Success lies in backing up thoroughly, planning clearly, assessing and addressing risk, labeling accurately, executing deliberately, and testing without compromise. If all of that is in place, your team can move forward with confidence, and your process can start up on a solid, resilient foundation.

  • Whitepaper: Six Feet Under | How to Dig Yourself Out of a Recommendations Graveyard

    Abstract Updated April 2026 — by aeSolutions Technical Team — Have you felt buried under six feet of safety study recommendations that must be closed? Does it feel impossible to follow Recognized and Generally Accepted Good Engineering Practices (RAGAGEPs) to convert recommendations into engineered design reality? You are not alone. To improve Process Safety, Capital Project and Operating teams must move recommendations from the hazard analysis stage through to a capital funding request, detailed design, construction execution, commissioning, startup, and operation. These steps are all part of the familiar Capital Projects process, but for Process Safety recommendations, they are also part of the Safety Life Cycle (SLC) journey based in ISA standards. Having an internal resource or external partner who is versed in both the Capital Projects process and the SLC process can alleviate recommendation closure challenges. This whitepaper discusses key lessons learned across multiple projects between an end-user and an SLC partner to ensure recommendations move to closure based on the intent of the risk assessment. It will also demonstrate how to go from being an owner-operator in a graveyard full of recommendations to living the high-life of PSM, Capital Projects, and SLC by identifying risk gaps and closing them in a timely, cost-effective, and safety-conscious framework. Read the complete whitepaper here

bottom of page