Categories: Business

HiltonC

Share
HSE engineer conducting fire risk assessment at a petrochemical refinery facility

Most industrial fire risk assessments fail long before a single hazard is identified. Not because the engineers lacked the tools — but because no one in a position of authority clearly defined what the assessment was supposed to deliver. HSE managers sit at the intersection of engineering output, regulatory obligation, and operational decision-making. If you don’t understand the methodology behind a fire risk assessment, you cannot evaluate whether what you’re receiving is rigorous or superficial.

This article lays out the core engineering framework for fire risk assessments in industrial facilities — what each phase should produce, where Saudi and international standards align, and where HSE managers should push back on incomplete work.

What a Fire Risk Assessment Actually Is

A fire risk assessment (FRA) is a structured, systematic process for identifying fire hazards, evaluating the likelihood and consequence of fire scenarios, and determining what controls are adequate to bring residual risk to an acceptable level. That last clause — “acceptable level” — is where most FRAs go wrong. Acceptable to whom? Acceptable by what criteria?

In the absence of a defined risk tolerance, assessments drift toward box-checking. Inspectors verify that extinguishers are mounted and exit signs are lit. Engineers note that sprinkler heads are in place. Nobody asks whether the facility’s actual fire scenarios have been inventoried, ranked, and addressed by controls sized to the risk.

A credible FRA answers four questions:

  1. What can burn, and where? — Fuel inventory, flash points, quantities, storage configuration.
  2. What ignition sources are present? — Hot work, electrical classification zones, friction, static, process upsets.
  3. What happens if ignition occurs? — Consequence modeling: flame spread, heat flux, smoke movement, structural exposure.
  4. Are existing controls adequate? — Detection, suppression, compartmentation, egress, emergency response — each evaluated against the scenarios identified in step three, not against a generic checklist.

The Methodology: Five Phases HSE Managers Should Recognize

Regardless of which standard framework is applied — whether NFPA’s fire protection engineering principles, the UK’s PAS 79 methodology, or Saudi Aramco’s internal HSE management system requirements — a technically sound FRA follows a recognizable structure.

Phase 1: Scope Definition. Before any site walk, the assessment scope must be documented: which buildings, processes, or systems are included; what occupancy types and hazard classifications apply; what regulatory standards govern (NFPA codes, Saudi Civil Defense requirements, applicable SAES standards); and what the risk tolerance baseline is. Scope creep — or scope gaps — are the most common source of assessments that look complete but aren’t.

Phase 2: Hazard Identification. This is the field-intensive phase. Engineers conduct systematic walkthroughs using structured hazard identification methods — checklists, process hazard analysis (PHA) prompts, or HAZID worksheets tailored to the facility type. For process facilities, this phase integrates with process safety data: P&IDs, material safety data sheets, process descriptions, and equipment specifications. A tank farm assessment that doesn’t reference SAES-D-001 bund design or NFPA 30 secondary containment requirements isn’t complete.

Phase 3: Risk Evaluation. Each identified hazard scenario is assigned a likelihood rating and a consequence severity rating. The combination produces a risk ranking — typically plotted on a risk matrix. This is where engineering judgment matters most. Likelihood ratings must be grounded in facility history, incident databases, and process reliability data — not guesswork. Consequence ratings for flammable-liquid fires should reference recognized heat flux damage thresholds and separation distance criteria, not generic descriptors like “moderate.”

Phase 4: Control Adequacy Review. Existing fire protection measures — detection systems, suppression systems, passive fire protection, compartmentation, emergency response procedures — are mapped against the risk scenarios. The question isn’t whether controls exist. It’s whether the installed controls are correctly specified, properly maintained, and adequate for the fire scenario they’re supposed to address. A foam-water deluge system protecting a diesel fuel tank is only adequate if the foam type, application rate, and coverage area are correctly engineered for that specific fuel and tank geometry.

Phase 5: Recommendations and Risk Register. Every identified gap generates a recommendation with a priority rating, responsible party, and target completion date. The output is a risk register — a living document, not a report that gets filed and forgotten. HSE managers should insist that recommendations be tracked to closure, and that the risk register be reviewed on a defined cycle or following any significant facility change.

Where NFPA and SAES Standards Intersect in the FRA Process

For facilities operating in Saudi Arabia, the FRA process must navigate two parallel frameworks. NFPA standards — particularly NFPA 1 (Fire Code), NFPA 30 (Flammable and Combustible Liquids Code), NFPA 72 (National Fire Alarm and Signaling Code), and NFPA 25 (Inspection, Testing, and Maintenance) — define many of the baseline technical requirements that engineers reference in the hazard identification and control adequacy phases.

Saudi Aramco Engineering Standards (SAES) layer additional requirements on top of those baselines for Aramco-affiliated facilities. Where an NFPA standard sets a minimum, a corresponding SAES standard may impose a more stringent requirement — tighter spacing, higher suppression application rates, additional passive fire protection, or more frequent inspection cycles. An FRA conducted for a Saudi Aramco facility that only references NFPA and ignores applicable SAES documents is not a complete assessment.

Saudi Civil Defense requirements add another layer — particularly around emergency response plan approval, means of egress, and fire detection system acceptance testing. HSE managers should verify that their assessment team understands all three layers and has documented how conflicts or overlaps between them have been resolved.

Common Failures HSE Managers Should Watch For

After reviewing FRAs across a range of industrial facilities, certain failure patterns repeat:

  • Generic checklists substituted for scenario-based analysis. A checklist confirms the presence of a sprinkler system. Scenario-based analysis confirms whether the sprinkler system is the right type, correctly designed for the hazard, and maintained to NFPA 25 frequency requirements.
  • Consequence modeling omitted or oversimplified. Heat flux calculations, flame spread modeling, and smoke movement analysis are frequently skipped in favor of qualitative descriptors. For high-consequence facilities, this is not defensible.
  • Risk matrix ratings not anchored to defined criteria. When “high likelihood” and “low likelihood” aren’t defined quantitatively, the risk matrix is subjective and non-comparable across assessors.
  • No closure tracking on prior recommendations. An FRA that doesn’t verify the status of previous assessment findings is starting with an incomplete picture of current risk.
  • Scope that excludes temporary facilities or contractor areas. Hot work in contractor laydown areas has been a contributing factor in multiple major industrial fire events. If it’s on the site, it belongs in the scope.

What Good Output Looks Like

A well-executed fire risk assessment produces a package of documents, not a single report. HSE managers should expect:

  • A documented scope statement and basis of assessment
  • A hazard identification log with source references
  • A completed risk matrix with defined likelihood and consequence criteria
  • A control adequacy table mapping each scenario to existing and recommended controls
  • A risk register with prioritized recommendations, responsible parties, and target dates
  • A summary executive report suitable for management review and regulatory submission

If what you receive is a narrative report with a few photographs and a generic recommendation list, ask for the underlying analysis. The report is a summary of the work, not the work itself.

The Bottom Line

Fire risk assessment is not a compliance exercise you commission and file. It is an engineering process that, done correctly, gives facility leadership a defensible, quantified understanding of fire risk and a traceable record of what controls are in place and why. For HSE managers overseeing industrial operations — especially in the Saudi market where NFPA, SAES, and Civil Defense requirements all apply simultaneously — the ability to evaluate the quality of an FRA is as important as commissioning one.

Demand scenario-based analysis. Demand defined risk criteria. Demand a risk register with closure tracking. If the assessment can’t survive those three questions, it isn’t protecting your facility — it’s protecting whoever wrote it.

Work With Ignis Sentinel Engineering

Need a fire risk assessment, a third-party plan review, or an NFPA/SAES
compliance check for your facility? Our engineers help Saudi and international
industrial operators design safer operations.

Book a consultation