{"operation":"document","citation":"DCA05MP001","title":"Anhydrous Ammonia Pipeline Rupture","source_type":"incident","agency":"National Transportation Safety Board","status":"current","official":true,"published_on":"2026-01-30","effective_on":"2004-10-27","summary":"Accident. in Kingman, KS, USA. on 2004-10-27. Magellan Midstream Partners, L.P.. Rupture/release","machine_formats":{"json":"https://regulus.evalyn.ai/document/ntsb-case-dca05mp001.json","markdown":"https://regulus.evalyn.ai/document/ntsb-case-dca05mp001.md"},"app_url":"https://regulus.evalyn.ai/document/ntsb-case-dca05mp001","source_url":"https://www.ntsb.gov/investigations/Pages/DCA05MP001.aspx","body":"NTSB investigation DCA05MP001.\n\nEvent Type: Accident\n\nEvent Date: 2004-10-27\n\nEvent City: Kingman\n\nEvent State Or Region: KS\n\nEvent Country: USA\n\nPipeline Operator: Magellan Midstream Partners, L.P.\n\nPipeline Type: Hazardous Liquid - Regulated\n\nAccident Type: Rupture/release\n\nCompletion Status: Completed\n\nReport Number: PAB-07-02\n\nProbable cause: The National Transportation Safety Board determines that the probable cause of the pipeline rupture near Kingman, Kansas, on October 27, 2004, was a pipe gouge created by heavy equipment damage to the pipeline during construction in 1973 or subsequent excavation activity at an unknown time that initiated metal fatigue cracking and led to the eventual rupture of the pipeline. Contributing to the severity of the accident was the pipeline controller’s failure to accurately evaluate available operating data and initiate a timely shutdown of the pipeline.\n\nTier1Name: System operating\n\nTier2Name: Product leak/release\n\nTier1Name: System operating\n\nTier2Name: Pipe structural malfunction/failure\n\nFinding Tier1Name: Organizational\n\nFinding Tier2Name: Support/oversight/monitoring\n\nFinding Tier3Name: Oversight\n\nFinding Modifier Name: Federal agency\n\nFinding Report Text: Organizational - Support/oversight/monitoring - Oversight - Federal agency\n\nFinding Tier1Name: Organizational\n\nFinding Tier2Name: Management\n\nFinding Tier3Name: Policy/procedure\n\nFinding Modifier Name: Other institution/organization\n\nFinding Report Text: Organizational - Management - Policy/procedure - Other institution/organization\n\nFinding Tier1Name: Personnel\n\nFinding Tier2Name: Action/decision\n\nFinding Tier3Name: Information processing/decision making\n\nFinding Modifier Name: SCADA operations personnel\n\nFinding Report Text: Personnel - Action/decision - Information processing/decision making - SCADA operations personnel\n\nFinding Tier1Name: Pipeline\n\nFinding Tier2Name: Pipeline structure\n\nFinding Tier3Name: Pipe\n\nFinding Modifier Name: Damaged/degraded\n\nFinding Report Text: Pipeline - Pipeline structure - Pipe - Damaged/degraded\n\nOfficial NTSB investigation data. NTSB findings determine probable cause and make safety recommendations; they do not adjudicate civil liability or regulatory violations.\n\nWhat Happened\nAbout 11:15 a.m. on October 27, 2004, an 8-inch-diameter pipeline owned by Magellan Midstream Partners, L.P., (Magellan) and operated by Enterprise Products Operating L.P. (Enterprise) ruptured near Kingman, Kansas, and released approximately 4,858 barrels (204,000 gallons) of anhydrous ammonia.\n\nNobody was killed or injured due to the release. The anhydrous ammonia leaked into a creek and killed more than 25,000 fish including some from threatened species. The cost of the accident was $680,715, including $459,415 for environmental remediation.\n\nWhat We Found\nWe determined that the probable cause of the pipeline rupture near Kingman, Kansas, on October 27, 2004, was a pipe gouge created by heavy equipment damage to the pipeline during construction in 1973 or subsequent excavation activity at an unknown time that initiated metal fatigue cracking and led to the eventual rupture of the pipeline.\n\nContributing to the severity of the accident was the pipeline controller’s failure to accurately evaluate available operating data and initiate a timely shutdown of the pipeline.\n\nWhat We Recommended\nAs a result of this investigation, we made the following new safety recommendations.\n\nTo the Pipeline and Hazardous Materials Safety Administration:\n\nRequire in 49 Code of Federal Regulations 195.52 that a pipeline operator must have a procedure to calculate and provide a reasonable initial estimate of released product in the telephonic report to the National Response Center. (P-07-7)\nRequire in 49 Code of Federal Regulations 195.52 that a pipeline operator must provide an additional telephonic report to the National Response Center if significant new information becomes available during the emergency response. (P-07-8)\nRequire an operator to revise its pipeline risk assessment plan whenever it has failed to consider one or more risk factors that can affect pipeline integrity.(P-07-9)\nTo Enterprise Products Operating L.P.: Provide initial and recurrent training for all controllers that includes simulator or noncomputerized simulations of abnormal operating conditions that indicate pipeline leaks. (P-07-10)\n\nPAB-07-02\n<<<PAGE 1>>>\n\nL\nT\nR\nA\nN\nS\nP\nA\nO\nN\nR\nU\nR\nI\nB\nU\nS\nM\nT\nO\nI\nA\nT\nA\nU N U\nP\nL\nE\nT\nI\nO\nN\nN\nS\nA\nF\nE\nT\nY\nB\nD\nO\nA\nR\nNational Transportation Safety Board\nWashington, D.C. 20594\nPipeline Accident Brief\nAccident No.: DCA05-MP001\nType of System: Hazardous liquid\nAccident Type: Pipeline rupture and leak with vapor cloud\nLocation: 6 miles west of Kingman, Kansas\nDate: October 27, 2004\nTime: 11:15 a.m. central daylight time\nOwner: Magellan Midstream Partners, L.P.\nFacility: Magellan Ammonia Pipeline/Enid Lateral\nOperator: Enterprise Products Operating L.P.\nFatalities/Injuries: None\nDamage/Clean-up Cost: $680,715\nMaterial Released: Anhydrous ammonia\nQuantity Released: 4,858 barrels (204,000 gallons)\nPipeline Pressure: 981 psig\nComponent Affected: Pipe\nThe Accident\nAbout 11:15 a.m. central daylight time1 on October 27, 2004, an 8-inch-diameter pipeline\nowned by Magellan Midstream Partners, L.P., (Magellan) and operated by Enterprise Products\nOperating L.P. (Enterprise) ruptured near Kingman, Kansas, and released approximately 4,858\nbarrels (204,000 gallons) of anhydrous ammonia.2 Nobody was killed or injured due to the\nrelease. The anhydrous ammonia leaked into a creek and killed more than 25,000 fish including\nsome from threatened species. The cost of the accident was $680,715, including $459,415 for\nenvironmental remediation.\nAccident Narrative\nOn October 27, 2004, a pipeline controller in the Enterprise control center in Houston,\nTexas, was operating an 8-inch-diameter anhydrous ammonia pipeline owned by Magellan. The\n1 All times in this brief are central daylight time.\n2 Anhydrous ammonia is classified in 49 Code of Federal Regulations (CFR) Part 195 as a highly volatile\nliquid. Anhydrous ammonia is transported as a liquefied gas in a pipeline and, when released, will immediately\nreturn to a gaseous state and rapidly expand. It is a hazardous liquid that is highly corrosive and toxic, and its vapors\nalso are extremely irritating and corrosive. Anhydrous ammonia may be fatal if inhaled, ingested, or absorbed\nthrough the skin.\nNTSB/PAB-07/02\n\n<<<PAGE 2>>>\n\nammonia pipeline runs from Borger, Texas, to Mankato, Minnesota. The Enid Lateral segment of\nthe ammonia pipeline originates at the Koch Enid production facility in Enid, Oklahoma, runs\nthrough Harper Station (Kansas), and ties in to the mainline at Partridge Station. (See figure 1.)\nFigure 1. Map of Magellan ammonia pipeline showing rupture location on 8-inch Enid Lateral.\nWhen the pipeline controller returned to his console after getting his lunch, he noticed\ntwo rate-of-change alarms3 that had been displayed on the alarm screen for the ammonia pipeline\nless than a minute earlier. The supervisory control and data acquisition (SCADA) event log\nindicated negative rate-of-change alarms for suction pressure at both Harper Station (at\n11:15:43 a.m.) and Conway Station (at 11:16:27 a.m.).\nAbout 11:18 a.m., an off-duty volunteer firefighter traveling on Highway 54 called 911 to\nreport a huge vapor cloud on the north side of the highway that he believed was a pipeline\nrelease. (See figure 2.) The 911 center in Kingman County, Kansas, is in the county sheriff’s\noffice. The Kingman County Fire Department was dispatched to the rupture site about 11:20 a.m.\nBecause the rupture site was in an agricultural area that is home to several threatened and\nendangered species of fish and wildlife, it was designated by Enterprise as a high-consequence\narea.4 The vapor cloud moved northwest from the rupture and affected vegetation in an area\n3 A rate-of-change alarm is displayed when a change in pressure or flow exceeds an identified value.\n4 A high-consequence area is defined in the Federal pipeline safety regulations as a commercially navigable\nwaterway, high- or concentrated-population area, or unusually sensitive area that might be affected by an accident\n2\nNTSB/PAB-07/02\n\n<<<PAGE 3>>>\n\napproximately 1/2 mile wide and 1 1/2 miles long. The release entered an unnamed tributary\nstream that was approximately 36 feet from the pipeline failure. The tributary stream enters\nSmoots Creek approximately 1 1/2 miles downstream of the rupture.\nFigure 2. Ammonia vapor cloud moving northwest from pipeline rupture.\nBetween 11:19:34 a.m. and 11:19:55 a.m., four more alarms from Conway Station were\ndisplayed at the controller’s console, including low suction pressure,5 low-low suction pressure,6\nan uncommanded pump shutdown, and a rate-of-change alarm that was followed by a low\nsuction pressure alarm from Partridge Station. Then two additional rate-of-change alarms were\ndisplayed, at 11:20:31 a.m. from Conway and at 11:21:26 a.m. from Partridge. In the 13 seconds\nbetween 11:27:33 a.m. and 11:27:46 a.m., five additional alarms were displayed, including low\nflow and the uncommanded shutdown of Abilene Station. At 11:27:50 a.m., the controller\nincreased the flow rate set point on the flow control valve at Enid Station from approximately\n450 barrels per hour to 550 barrels per hour. At 11:27:51 a.m., a second low-low suction pressure\nalarm from Conway Station was displayed.\ninvolving the pipeline. Title 49 CFR 195.450 contains the criteria for designating an area a high-consequence area\nfor hazardous liquid pipelines.\n5 A low suction pressure alarm for a pump at a pump station along a pipeline can be set at a value selected by\nthe pipeline controller (higher than low-low) as a warning of an abnormal condition or a possible pipeline leak.\n6 A low-low suction pressure alarm is a high level (red) alarm in the SCADA system that is considered an\nimmediate response alarm.\n3\nNTSB/PAB-07/02\n\n<<<PAGE 4>>>\n\nThe controller knew that Enterprise maintenance personnel were working at Conway\nStation. In a telephone call to Conway Station at 11:28 a.m., he asked why the pump had shut\ndown. By 11:30 a.m., Conway Station personnel had told the controller that they had not caused\nthe pump to shut down. At 11:34:05 a.m., the SCADA system displayed a low suction pressure\nrate-of-change alarm downstream at Linn Station followed by a low-low suction pressure alarm\nat 11:34:30 a.m.\nOn the basis of the 911 call at 11:18 a.m., the Kingman County sheriff’s office had\nresponded to the site and started telephoning residents in 35 houses; four families were\nevacuated; no residents were home at 28 houses. By about 11:40 a.m., the sheriff’s office and the\nfire department had blocked roads that could be affected by the vapor cloud.\nAbout 11:48 a.m., the dispatcher called Enterprise’s control room to report the release\nthat had been reported to 911. Another controller, who was sitting at the console adjacent to the\nammonia pipeline controller’s console, answered the phone and handled the call. The ammonia\npipeline controller told investigators that when he heard the telephone ring he immediately\nrealized that there was a leak on the ammonia pipeline. He started to shut down the pipeline at\n11:48:20 a.m. by remotely stopping the pumps at Enid, Verdigris, Wellsford, and Borger\nStations,7 in that order. The last one, Borger, was shut down at 11:52:57 a.m. From his console,\nhe remotely closed the block valve at Harper Station, and at 11:54:24 a.m., he closed the block\nvalve at Partridge Station. These closures isolated a 50.85-mile-long segment of pipeline in\nwhich the rupture had occurred. At 12:08 p.m., he dispatched Enterprise personnel to close\nmanual block valves at milepost markers 21 and 32 to further isolate the leaking pipeline\nsegment. At 12:56 p.m. and 1:09 p.m., respectively, those valves were closed. These valve\nclosures reduced the isolated segment of pipeline in which the rupture had occurred to 11 miles.\nController’s Actions\nThe controller told investigators after the rupture that he had been viewing the tabular\nscreen and knew the alarms indicated a potential problem with the pipeline. To evaluate the\nalarms from the pipeline, he used the tabular data screen in the SCADA system. This screen\nlisted the pipeline facilities and displayed current data for the entire pipeline system, including\npump station suction and discharge pressures, pump status, tank levels, flow rates, valve status,\nand set points. Alarm information that was displayed on the alarm screen also flashed and\nchanged color on the tabular screen. The controller’s assessment was that he was delivering more\nammonia from the pipeline than was being added to the pipeline and that this condition had\ndecreased the pressure. This assessment led him to increase the flow rate at 11:27:50. He later\nsaid that he thought that within 10 or 15 minutes the pressure readings would increase.\nTherefore, he planned to wait for a few minutes, and, if the pressure readings for the pipeline did\nnot increase, he would reevaluate and delve deeper into the situation.\nThe SCADA system can display a trend screen that shows pressure and flow trend data\ngraphically, and the controller told investigators that looking at a trend screen would have been\nhelpful in the analytical stage. However, he did not use trend screens in evaluating the incoming\n7 The controller stopped pumps at these stations because at the time he did not know whether the leak was on\nthe mainline from Borger, on the Enid Lateral, or on the mainline downstream of Partridge Station.\n4\nNTSB/PAB-07/02\n\n<<<PAGE 5>>>\n\ndata. He said that his training did not specify which screens to use to analyze and evaluate the\nSCADA data. He stated that from 11:15 a.m. to 11:48 a.m. an unusually high number of alarms\nand status events were displayed for the pipeline.8 During this 33-minute period, the SCADA\nsystem displayed 119 alarms and status events. The controller said that he felt that he had full\nauthority to shut down the pipeline and that he did not believe there would be consequences from\nEnterprise if he shut down a pipeline and it was subsequently determined that there was no leak.\nThe operations control supervisor stated in an interview that he expects pipeline\ncontrollers to use the tabular screen as the main screen, or “front page.” He said that controllers\nare taught to access and display a trend screen, or “second page,” to further investigate an alarm\nand the condition that caused it. The supervisor said that pressure and flow changes are the\nprimary parameters used to detect leaks. He stated that at the time of the accident, rate-of-change\nalarms were displayed in blue and immediate response alarms were displayed in red. He\nindicated that he believes the controller had enough information between 11:20 a.m. and\n11:25 a.m. to lead him to shut down the ammonia pipeline.\nTelephonic Reporting of Release\nThe Federal pipeline safety regulation for telephonic reporting of hazardous liquid\npipeline accidents (49 CFR 195.52) requires telephonic notification to the National Response\nCenter when the pipeline accident has caused a death or injury requiring hospitalization; has\nresulted in either an unintentional fire or explosion; has caused estimated property damage\n(including cleanup and recovery costs and the value of the lost product) exceeding $50,000; has\nresulted in pollution of streams, rivers, reservoirs, or other similar bodies of water; or, in the\njudgment of the operator, is significant even though the accident does not meet the other\nspecified criteria. The regulation further requires an operator to include in the telephonic\nnotification not only the basic details, such as the identity of the operator, the location and time\nof the accident, and the number of fatalities and injuries, but also “all other significant facts\nknown by the operator that are relevant to the cause of the failure or extent of the damages.”\nOn August 30, 2002, the Pipeline and Hazardous Materials Safety Administration\n(PHMSA)9 published a Federal Register notice issuing a safety advisory bulletin10 to operators\nof gas and hazardous liquid pipelines and liquefied natural gas facilities about telephonic\nreporting. In the notice, PHMSA stated that it is critical for an operator to provide accurate\ninformation on the extent of the incident and that PHMSA expects an operator to provide\nsignificant updated information during the emergency response phase. The bulletin stated that if\n8 The pipeline systems that this controller operated experienced an increase from an average of 137 alarms in an\nhour to 286 alarms between 11:00 a.m. and noon.\n9 In a U.S. Department of Transportation reorganization, the Research and Special Programs Administration\n(RSPA) ceased operations on February 20, 2005. RSPA’s Office of Pipeline Safety programs moved to the new\nPipeline and Hazardous Materials Safety Administration. All references to predecessor agencies are designated as\nPHMSA in this report.\n10 The August 30, 2002, advisory bulletin was issued in response to the Safety Board’s Safety Recommendation\nP-02-02 (See Rupture of Piney Point Oil Pipeline and Release of Fuel Oil Near Chalk Point, Maryland, April 7,\n2000, Pipeline Accident Report, NTSB/PAR-02/01 [Washington, DC: NTSB, 2002.]). The Safety Board\nissued Safety Recommendation P-02-02 to PHMSA to require pipeline owners and operators to provide follow-up\ntelephone updates to the National Response Center when they discover that the information they initially reported\ncontains significant errors or when they identify significant new information directly related to the reporting criteria.\n5\nNTSB/PAB-07/02\n\n<<<PAGE 6>>>\n\nadditional information leads to a significant change in the estimated quantity of product released,\nthe estimated number of fatalities and injuries, the extent of environmental damage, or the extent\nof property damage, the operator should make an additional telephonic report to the National\nResponse Center. PHMSA considered “significant change” to include an increase or decrease of\npreviously reported fatalities or injuries and a revised estimate of product released or property\ndamage that is at least 10 times greater than the previous estimates. Regarding release estimates,\nthe bulletin also stated that if the operator does not provide an estimate, the National Response\nCenter will record a default estimate of 1,000 barrels (42,000 gallons). In February 2005,\nPHMSA informed the Safety Board that rather than the National Response Center entering the\n1,000-barrel default estimate, PHMSA will consider telephonic reports made without a spill\nestimate to have the same priority as reports with spill estimates of 1,000 barrels. The National\nResponse Center confirmed in March 2005 that it will not enter the 1,000-barrel default value if\nthe operator does not provide a spill estimate.\nThe U.S. Environmental Protection Agency (EPA) requires that an anhydrous ammonia\nrelease equal to or greater than 100 pounds of ammonia (equivalent to approximately 20 gallons)\nbe reported within 15 minutes of discovery.\nAbout 12:15 p.m. on October 27, the controller notified Enterprise’s central region\noperations manager of the release. Because field personnel were too busy to make the call, the\nmanager called the controller back to tell him to report the accident to Enterprise’s accident\nreporting contractor.11 In the controller’s phone conversation with the accident reporting\ncontractor at 12:23 p.m., the controller reported that a large quantity of anhydrous ammonia had\nbeen released and had formed an ammonia vapor cloud, but he stated that he did not know the\namount of anhydrous ammonia that had been released. When the contractor responded that\nwithout an estimate of a specific quantity the National Response Center would enter a 1,000-\nbarrel estimate in its incident report, the controller told the contractor that a 1,000-barrel estimate\nwould be fine. The contractor asked whether the amount released was at least 20 gallons.12 The\ncontroller confirmed that it was. Later, when the contractor asked for a damage estimate, the\ncontroller said that he had no idea. When the contractor asked him to choose one of several\nranges of dollar values from less than $5,000 to exceeding $50,000 as an estimate of the damage\ncaused by the release, the controller chose the less-than-$5,000 range.\nAt 1:08 p.m., Enterprise’s reporting contractor reported the release to the National\nResponse Center. The National Response Center report of the incident stated that the release was\na vapor cloud over the pipeline due to unknown causes. The contractor reported the estimated\nquantity of the release as 20 gallons and told the National Response Center that Enterprise would\ncalculate the amount released when it got a chance. An updated release amount was not reported\nto the National Response Center.\nA PHMSA inspector arrived on site at 7:00 a.m. the next morning, October 28. About\n8:00 a.m., the inspector learned from Enterprise operations employees that at that time, the\n11 3E Company was Enterprise’s accident reporting contractor.\n12 When reporting an anhydrous ammonia release of unknown volume, Enterprise reported small releases as at\nleast 20 gallons to indicate that a reportable quantity had been released.\n6\nNTSB/PAB-07/02\n\n<<<PAGE 7>>>\n\nestimated amount of anhydrous ammonia released was at least 3,000 barrels (126,000 gallons).13\nThis estimate of the release volume was based on an approximation of the amount of product\nnormally contained in the pipeline between the two valves that had been manually closed. The\nfinal estimate of the release volume was later calculated by Enterprise to be 4,858 barrels\n(204,000 gallons).\nThe EPA had received the initial report of a 20-gallon release from the National Response\nCenter on October 27 about 2:42 p.m. EPA representatives indicated that the EPA had not\nresponded to the accident site because the reported release volume was so small. The next\nmorning, during a review of the previous day’s National Response Center reports, the EPA duty\nofficer noticed that a vapor cloud had been reported, and he called Enterprise at 9:30 a.m. to ask\nwhy a vapor cloud was associated with a 20-gallon release. The Enterprise representative told the\nduty officer that the amount of ammonia released was much greater than the reported quantity,\nand he estimated the release to be at least 2,000 barrels (84,000 gallons). Following the phone\ncall, two EPA on-scene coordinators were dispatched to the site to investigate.\nThe EPA on-scene coordinators arrived at the site at 5:00 p.m. and discussed with Apex\nEnvironmental, Inc. (Apex), Magellan’s environmental contractor, the need for sparging14 at\nSmoots Creek to lower the pH levels in the creek. Apex began sparging about 9:00 p.m. Sparging\ncontinued for several weeks following the rupture. Later, the Kansas Department of Health and\nEnvironment authorized the spreading of 3,500 cubic yards of nitrogen-rich soil, which had been\nexcavated from the rupture location, over a cultivated area to fertilize the ground.\nPipe Specification and Operating Conditions\nThe 8.625-inch nominal outside diameter carbon steel pipe at the rupture location was\nspecified as American Petroleum Institute Specification 5LX, grade X46, 0.156-inch nominal\nwall thickness with an electric resistance welded seam. After Mid-America Pipeline Company\ncompleted construction, the pipeline segment at the rupture location was hydrotested to 1,580\npounds per square inch gauge (psig) on December 11, 1973. At the rupture location, the pipeline\nhad a maximum operating pressure of 1,198 psig. The calculated pipeline operating pressure at\nthe rupture site at the time of the release was 981 psig, and records of the operating conditions\nimmediately before the accident do not indicate that the maximum operating pressure had been\nexceeded. The exterior surface of the pipe was coated with tar tape primer and spirally wrapped\nwith a continuous overlap of tar tape. At the location of the rupture, the pipe was 4 feet 5 inches\nunderground and was cathodically protected to control external corrosion.\nMaterials Laboratory Examination and Tests\nThe pipe segment that ruptured was removed and sent to the Safety Board’s Materials\nLaboratory for examination and testing. The segment had four external gouges. The\n13 The 3,000-barrel estimate was a rough field estimate. With the postaccident implementation of new reporting\nprocedures, Enterprise would have been able to provide a more refined estimate of 3,600 barrels. See “Enterprise’s\nPostaccident Actions – Telephonic Report Procedure” in this report.\n14 Sparging is the process of injecting compressed air into a waterway causing volatile pollutants such as\nammonia to vaporize into the air.\n7\nNTSB/PAB-07/02\n\n<<<PAGE 8>>>\n\napproximately 11.7-inch-long rupture occurred at one of the gouges. (See figure 3.) Over most of\nthe rupture length, the gouge penetrated 0.019 inch (approximately 12.2 percent of the pipe wall\nthickness) into the pipe wall. Within the gouge, shear cracks penetrated the metal. From the base\nof the shear crack that led to the rupture, a fatigue crack propagated toward the interior of the\npipe. The fatigue crack extended approximately 0.080 inch below the shear crack with no\nexternal corrosion that resulted in a loss of material thickness. A detailed examination showed\nthat the fatigue region had five bands, each with a different shade of gray, consistent with crack\narrest marks. The area below the fatigue crack had a shear lip created during the sudden and final\nrupture of the pipe.\nFigure 3. Ruptured 8-inch Enid Lateral anhydrous ammonia pipeline showing four gouges\nand rupture.\nThe results of chemical analysis, dimensional measurements, and tensile strength testing\nwere in accordance with the American Petroleum Institute specification for 5LX-X46 pipe. An\nexamination of a cross section of the gouge at the fracture origin area showed that metal of a\ndifferent composition had transferred to the wall of the pipe. Elemental analysis of a metal tooth\nfrom the backhoe bucket owned by the property owner did not provide a unique signature when\ncompared to the transferred metal in the gouges. The examination of the cross section revealed\nno manufacturing defects (such as laminations, voids, or porosity) in the pipe material. The\nexamination of the inside surface of the pipe showed no corrosion degradation or additional\ncracking.\n8\nNTSB/PAB-07/02\n\n<<<PAGE 9>>>\n\nConstruction and Excavation Activity\nTo identify any construction and excavation activities in the area of the rupture,\ninvestigators examined all available maintenance records, aerial patrol records, and aerial\nphotographs that covered the period from construction of the pipeline in 1973 to the present, but\nidentified no excavation activities immediately over the rupture site. The 1973 construction\nspecifications for the pipeline required that any coating damage be repaired before backfilling\nthe pipeline. The trench for the pipeline was excavated with a trenching machine, and backfilling\nwas done with an auger-type backfill machine or a bulldozer. According to the construction\nspecifications, where these machines could not be used to backfill, the site inspector would\napprove the method of backfilling before it began. The pipeline tie-in inspector for the Enid\nLateral construction did not recall what occurred at the accident location, and no construction\ninspection records exist. He indicated that a backhoe was not likely to be used in the pipe rupture\narea during construction because the unnamed stream was not a major stream crossing that\nrequired the use of a backhoe.\nAccording to the current owner (since 1989), the area where the pipe ruptured had not\nbeen cultivated. Between 1990 and 1992, he had used his backhoe to grade the unnamed stream’s\nbanks to create a vehicle ramp that was approximately 100 feet north of the pipe rupture. He told\ninvestigators that no excavation had been performed at the location of the rupture.\nThe four gouges located longitudinally along the top half of the pipeline are consistent in\nshape and location with the type of mechanical damage caused by excavation equipment such as\na backhoe. Since a unique metallurgical signature was not found in the analysis of metal deposits\nwithin the gouges, the Safety Board could not determine whether the landowner’s backhoe\nbucket was the source of the deposits. The pipeline tie-in inspector stated that on this pipeline\nconstruction project a backhoe typically would not have been used for crossing a stream of this\nsize. However, the Safety Board could not rule out damage to the pipeline during construction.\nAvailable information and records covering the time from when the pipeline was constructed in\n1973 to the present did not indicate any excavation activity by the pipeline operator near the\nlocation of the rupture. However, the possibility of unknown excavation activities could not be\neliminated. The Safety Board concludes that heavy equipment damage to the pipeline during\nconstruction or subsequent excavation activity created a pipe gouge that initiated metal fatigue\ncracking and led to the eventual rupture of the pipeline.\nEnterprise’s Policies and Procedures\nProcedures for Abnormal Operating Conditions\nEnterprise’s procedure manual defined an abnormal operating condition as “any condition\nthat may cause, create, or contribute to a situation which exceeds the design or normal operating\nparameters of the pipeline.” The manual instructed controllers to treat an unexplained variation\nin pressure or flow as an abnormal operating condition. It also instructed controllers to continue\nto monitor pipeline operations and follow specific steps that include checking “with others\ninvolved with the operations to determine the cause of the variation” and to be “especially\nattentive for any sign that an emergency condition may follow.”\n9\nNTSB/PAB-07/02\n\n<<<PAGE 10>>>\n\nTo investigate a variation in pressure or flow, control room personnel were to notify on-\ncall field personnel or supervisors; review flow data; check instantaneous line balance by\ncomparing simultaneous meter readings at point of origin, destination, and intermediate\nlocations; and contact customers for possible explanation of the pressure or flow variation. If a\nlogical reason for a variation could not be determined, the control room operator was to shut\ndown the pipeline and monitor pressure.\nEnterprise’s draft Natural Gas Liquids Pipeline Control Operations and Maintenance\nTraining Manual15 also contained information regarding the monitoring and control of anhydrous\nammonia pipelines. The manual noted that rate-of-change alarms usually occur at the onset of an\nabnormal condition or a pipeline leak. Controllers were instructed to investigate all rate-of-\nchange and parameter alarms immediately, and they were advised that if an alarm resulted from a\nknown cause, the pipeline system in the area of the alarm would stabilize in a short period of\ntime. If the cause of a rate-of-change or parameter alarm was not readily apparent and the alarm\nwas accompanied by one or more indications of a product release, or the pressure or flow failed\nto stabilize, controllers were instructed to shut down and block in the line segment. If a sudden\nunexplained decrease in operating pressure without a corresponding increase in flow rate was\nobserved, the controller was instructed to shut down and block in the line segment for 30 minutes\nand then observe the line segment for any sign of a leak.\nControllers were instructed during training to use trend screens to monitor the pipeline\npressure and, if the pressure continued to fall or did not stabilize, to perform an emergency\nshutdown. This procedure was included in the training manual. The alarm response matrix in the\ntraining manual described the SCADA alarm color scheme and listed a rate-of-change alarm as a\nhigh-level alarm. The matrix also indicated that rate-of-change alarms for pressure and flow\n(high-level, immediate attention) were shown in red on the SCADA screen and that these alarms\nindicated a possible line break.\nEnterprise defined an emergency as a “significant change from steady state operating\nconditions” that could include an “accidental release of hazardous vapors or liquids from a\npipeline causing a hazardous situation.” When a controller determined that an emergency\nexisted, the manual required him to shut down pumps that feed the affected facility and close the\nnearest upstream remotely operated block valve. Pump stations downstream of the facility were\nto remain operating until they shut down on low flow, and then the nearest remotely operated\ndownstream block valve was to be closed. The controller also was to notify identified personnel\nwithin the company as well as customers and emergency response agencies.\nController’s SCADA Training and Qualification\nThe controller who operated the pipeline during the accident started at Enterprise as an\narea operator and was promoted to operations supervisor in the field in 1996. He took controller\ntraining, consisting of classroom study of company procedures and manuals, operations, SCADA\ninformation retrieval, and site-specific information. He functioned as a pipeline scheduler from\n1997 until 2003. In February 2003, he began on-the-job controller training. Enterprise assessed\nthe effectiveness of his training by testing his knowledge and observing his actions in operating\n15 Enterprise used the draft manual for training controllers.\n10\nNTSB/PAB-07/02\n\n<<<PAGE 11>>>\n\npipelines. He completed refresher training on May 21, 2003. His training included the study of\nprocedural and training manuals for the ammonia pipeline. The study material explained how to\nrespond to abnormal conditions and use trend screens with graphical displays. He successfully\ncompleted written examinations covering this material on September 13, 2003, and was qualified\nby Enterprise to operate the pipeline. Enterprise did not have a pipeline simulator for controller\ntraining but did use noncomputerized simulations in postaccident controller training sessions in\n2001. The review of noncomputerized simulations of accidents is not a requirement listed in\nEnterprise’s training program.\nTelephonic Report Policy\nEnterprise’s Procedural Manual for Operations, Maintenance, and Emergencies stated\nthat operations personnel are accountable for telephoning a report of an accident to the National\nResponse Center. The procedure repeats the requirements for telephonic reporting in\n49 CFR 195.52.\nEnterprise’s draft Natural Gas Liquids Pipeline Control Operations and Maintenance\nTraining Manual stated that its reporting contractor would do all reporting of releases and\naccidents to Federal, State, and local authorities for Magellan’s ammonia pipeline, and that the\nEnterprise field supervisor was responsible for reporting releases and accidents to the contractor.\nEnterprise did not have a policy about who was responsible for deciding whether to send an\nadditional report to the National Response Center in order to comply with the August 30, 2002,\nPHMSA advisory bulletin urging operators to update a telephonic report with significant new\ninformation, including a change in the estimate of the release volume.\nBefore the accident, Enterprise’s central region operations manager had supplemental\nreporting guidelines drafted for training field personnel. The operations manager’s objective was\nto improve timely reporting of accidents in his region using the reporting contractor. The\nguidelines identified reporting responsibilities and included a list of questions that the contractor\nwould ask. However, the guidelines did not address how to estimate the quantity of product\nreleased or how to make a dollar estimate of damages. The draft guidelines were used in a\ntraining session conducted during a quarterly safety meeting in the quarter ending\nMarch 31, 2003. The draft guidelines, Release Reporting Roles and Responsibilities, dated\nJune 3, 2003, was the last update of the draft.\nIntegrity Management Program for Ammonia Pipeline\nWilliams Companies, Inc. (Williams), the previous owner and operator of the pipeline,\nprepared the initial integrity management program for the ammonia pipeline. It used a relative\nrisk assessment model that considered the following factors: third-party damage, corrosion,\nincorrect operation, design, and leak impact. It ranked various pipeline segments according to\ntheir risk with respect to each other. Using this model, a lower score indicated higher risk, and a\nhigher score indicated lower risk. The risk scores were used with other input to prioritize\nscheduling of baseline assessments of pipeline segments. Pipe segments with risk scores of 0 to\n35, 36 to 66, and 67 and above were considered high, medium, and low risk, respectively. When\nthe baseline assessment plan was developed, the model assigned a risk score of 69 (low risk) to\n11\nNTSB/PAB-07/02\n\n<<<PAGE 12>>>\n\nthe segment on the Enid Lateral that ruptured in this accident. This Enid Lateral segment was\nscheduled for a baseline assessment in 2006.\nIn February 2003, Enterprise became the operator for the pipeline under contract to a\nsubsidiary of Williams. Enterprise has been responsible for the integrity management program\nfor the pipeline since that time. Williams subsequently sold the pipeline to Magellan, and\nEnterprise continued as the operator. The original integrity management program remained in\neffect until 2004 when Enterprise finished developing its own integrity management program,\nwhich was the program in effect at the time of the accident. The risk model in the Enterprise\nprogram was the same as the one used by Williams, and the risk score for the pipeline segment\nthat contained the rupture had not been revised.\nPHMSA’s integrity management regulations list risk factors that must be considered in\nprioritizing the scheduling of baseline assessments. A pipeline segment’s leak history is\nspecifically included in the list of risk factors. Although Enterprise had leak history data for the\naccident pipeline segment, Enterprise did not have complete instructions for calculating the leak\nhistory risk factor in its integrity management program. As a result, leak history was not used in\ncalculating the relative risk scores, nor was it otherwise considered to classify pipe segments as\nhigh, medium, or low risk for the baseline assessment before the Kingman accident.\nFederal Integrity Management Inspections\nIn September and October 2003, PHMSA inspected the Enterprise integrity management\nprogram for the anhydrous ammonia pipeline, including the Enid Lateral pipeline segment. The\ninspection revealed some deficiencies that were noted on PHMSA’s Integrity Management\nInspection Form and Inspection Summary Report. PHMSA identified several compliance issues\nand issued a Notice of Amendment to Enterprise on April 22, 2004, to correct deficiencies in its\nintegrity management program. One of the compliance issues pertained to risk factors used in\nprioritizing the baseline assessment schedule. PHMSA noted that the following risk factors\nrequired by regulation were not addressed by Enterprise: seam type, results of previous\nassessments, defect type and size that the assessment method can detect, and defect growth rate.\nPHMSA also asked that more detail be included in documentation describing how these risk\nfactors will be integrated into the decision-making process for prioritizing the baseline\nassessment schedule. However, PHMSA did not identify that pipeline leak history also was not\nused in Enterprise’s calculation of relative risk scores.\nIn letters dated May 21 and July 28, 2004, Enterprise responded to the PHMSA Notice of\nAmendment with revised procedures to integrate the risk factors that had been identified in the\nnotice as ","truncated":true,"body_characters":45832}