{"operation":"document","citation":"CPF 32024027NOA","title":"NORTHERN NATURAL GAS CO — Notice of Amendment","source_type":"enforcement","agency":"Pipeline and Hazardous Materials Safety Administration","status":"historical","official":true,"published_on":"2024-07-12","effective_on":null,"summary":"CLOSED notice of amendment citing 192.631(a)(1), 192.631(a)(2), 192.631(b)(4), 192.631(c)(1), 192.631(c)(2), 192.631(e)(1), 192.631(e)(2), 192.631(e)(3), 192.631(e)(5), 192.631(f), 192.631(g)(1), 192.631(h), 192.631(h)(5), 192.631(j)(2).","machine_formats":{"json":"https://regulus.evalyn.ai/document/phmsa-enforcement-32024027noa.json","markdown":"https://regulus.evalyn.ai/document/phmsa-enforcement-32024027noa.md"},"app_url":"https://regulus.evalyn.ai/document/phmsa-enforcement-32024027noa","source_url":"https://primis.phmsa.dot.gov/enforcement-data/case/32024027NOA","body":"Notice of Amendment involving NORTHERN NATURAL GAS CO. PHMSA's enforcement data identifies the cited regulations as 192.631(a)(1),  192.631(a)(2),  192.631(b)(4),  192.631(c)(1),  192.631(c)(2),  192.631(e)(1),  192.631(e)(2),  192.631(e)(3),  192.631(e)(5),  192.631(f),  192.631(g)(1),  192.631(h),  192.631(h)(5),  192.631(j)(2). The case was opened on 2024-07-12 and is reported as closed as of 2025-11-10. Open the official case record for notices, responses, orders, and the latest status.\n\nOfficial case documents:\n\n32024027NOA_Closure Letter_11102025_(20-188476).pdf: https://primis.phmsa.dot.gov/enforcement-documents/32024027NOA/32024027NOA_Closure%20Letter_11102025_(20-188476).pdf\n\n32024027NOA_Closure Letter_11102025_(20-188476)_text.pdf: https://primis.phmsa.dot.gov/enforcement-documents/32024027NOA/32024027NOA_Closure%20Letter_11102025_(20-188476)_text.pdf\n\n32024027NOA_Notice of Amendment_07122024_(20-188476).pdf: https://primis.phmsa.dot.gov/enforcement-documents/32024027NOA/32024027NOA_Notice%20of%20Amendment_07122024_(20-188476).pdf\n\n32024027NOA_Notice of Amendment_07122024_(20-188476)_text.pdf: https://primis.phmsa.dot.gov/enforcement-documents/32024027NOA/32024027NOA_Notice%20of%20Amendment_07122024_(20-188476)_text.pdf\n\n32024027NOA_Operator Response to Notice_09092024_(20-188476).pdf: https://primis.phmsa.dot.gov/enforcement-documents/32024027NOA/32024027NOA_Operator%20Response%20to%20Notice_09092024_(20-188476).pdf\n\n32024027NOA_Closure Letter_11102025_(20-188476)_text.pdf\n\nU.S. Department\nof Transportation\nPipeline and Hazardous\nMaterials Safety\n901 Locust Street, Suite 480\nKansas City, MO 64106\nVIA ELECTRONIC MAIL TO: laura.demman@nngco.com, thomas.correll@nngco.com;\nNovember 10, 2025\nMs. Laura Demman\nPresident & CEO\nNorthern Natural Gas Company\n1111 South 103rd Street\nOmaha, NE 68124\nRE: CPF 3-2024-027-NOA\nDear Ms. Demman:\nFrom September 8 through September 11, and September 23 through September 25, 2020, a\nrepresentative from the Pipeline and Hazardous Materials Safety Administration (PHMSA),\npursuant to chapter 601 of 49 United States Code, conducted an inspection of the procedures for\nthe Northern Natural Gas Company (NNG) Control Room located in Omaha, Nebraska. On July\n12, 2024, pursuant to 49 CFR § 190.206, PHMSA issued a Notice of Amendment which proposed\namendment of NNG’s procedures.\nNNG submitted its amended procedures, with the final submission occurring on November 10,\n2025. PHMSA has reviewed the amended procedures, and it appears that the inadequacies\noutlined in the Notice of Amendment have been corrected.\nThis letter is to inform you that no further action is necessary, and this case is now closed. Thank\nyou for your cooperation.\nSincerely,\nDavid Barrett\nActing Director, Central Region, Office of Pipeline Safety\nPipeline and Hazardous Materials Safety Administration\ncc: Thomas Correll, VP, Pipeline Safety and Risk, NNG, thomas.correll@nngco.com\n\n32024027NOA_Notice of Amendment_07122024_(20-188476)_text.pdf\n\nNOTICE OF AMENDMENT\nVIA ELECTRONIC MAIL TO: mark.hewett@nngco.com, thomas.correll@nngco.com;\njohn.gormley@nngco.com\nJuly 12, 2024\nMr. Mark Hewett\nPresident and CEO\nNorthern Natural Gas Company\n1111 S. 103rd Street\nOmaha, NE 68124\nCPF 3-2024-027-NOA\nDear Mr. Hewett:\nFrom September 8 through September 11, and September 23 through September 25, 2020, a\nrepresentative of the Pipeline and Hazardous Materials Safety Administration (PHMSA),\npursuant to Chapter 601 of 49 United States Code (U.S.C.), inspected procedures for the\nNorthern Natural Gas Company (NNG) Control Room located in Omaha, Nebraska. NNG\nupdated its Control Room Management procedures initially as a result of this inspection in 2020\nand continued to work on procedure amendments with PHMSA during meetings held at various\ntimes including those occurring in September 2022 and August 2023.\nAs a result of the inspection and NNG’s continued work on procedure amendments, PHMSA has\nidentified apparent inadequacy found within NNG’s plans or procedures. The items inspected\nand the inadequacies identified are described below:\n1. § 192.631 Control room management.\n(a) General.\n(1) This section applies to each operator of a pipeline facility with a controller\nworking in a control room who monitors and controls all or part of a pipeline\nfacility through a SCADA system. Each operator must have and follow written\ncontrol room management procedures that implement the requirements of this\nsection. . . .\n(b) Roles and responsibilities. Each operator must define the roles and\nresponsibilities of a controller during normal, abnormal, and emergency operating\n\n\n\nconditions. To provide for a controller's prompt and appropriate response to\noperating conditions, an operator must define each of the following:\n(1) . . . .\n(4) A method of recording controller shift-changes and any hand-over of\nresponsibility between controllers;\nNNG’s procedures 50.200, entitled “Controller Roles and Responsibilities” (Procedure 50.200),\nand 50.201, entitled “Providing Adequate Information – Shift Exchange” (Procedure 50.201),\nwere not adequate to address any hand-over responsibility between controllers as required by §\n192.631(b)(4). Specifically, while the procedures did require that a controller log-on to the\nconsole when handing over responsibility to another controller, nothing required that the\ncontroller leaving the console would log-off, or clarified that the SCADA system would\nautomatically log-off the outgoing controller after a period of time, leaving the prior controller’s\narea of responsibility active.\nThe control room has multiple consoles (North Horsepower, North Town Border Station (TBS),\nand South/Central), all three of which can monitor and control any other console’s information.\nThe control room procedures and SCADA system allow multiple controllers to be logged onto\nthe SCADA system at any given time. Some individuals that are not qualified controllers also\nhave access to the control room, such as the control room Director. Additionally, during certain\ntimes, controllers have completed training on only one or more consoles but have not completed\ntraining relevant to all of the specific consoles with the assigned area of responsibility. Procedure\n50.100, entitled “Control Room Management,” required a controller to be qualified, and\nProcedure 50.200 required a log-on, but nothing required a controller to perform a log-off\nfunction. Since multiple controllers can be logged-on at the same time, and this log-on feature\nsets their area of responsibility based on qualifications and supervisor’s assignment for the\nspecific day or night, nothing would prevent unqualified individuals from operating a console,\nunless a log-off function is required.\nNNG’s Procedure 50.200 in section 3.2.2 stated “[a] monthly audit will be completed to verify a\ncontroller did not operate on a console they were not qualified for. Document any violations in a\ndeviation report.” However, if controllers that are qualified can stay logged on indefinitely, then\nanyone in the control room (qualified or not) could access the console and execute commands or\nacknowledge alarms without this being detected or discovered in the monthly audit function.\nAdditionally, if controllers are not required to log-out/log-off or if the SCADA system does not\nautomatically log-out/log-off qualified individuals within a certain time frame, individuals that\nhad not completed cross-training on all consoles would also be able to execute commands and\nrespond to information for systems they were not qualified for. By not requiring a log-off\nfunction, the monthly audit would not be able to determine if a console had a person operating it\nthat was not qualified for that area of responsibility.\nNNG’s procedures 50.200 and 50.201 require amendment to adequately address the hand-over\nresponsibility between controllers and to adequately establish and implement the monthly review\nprocess regarding qualified controllers as described in Procedure 50.201, section 3.2.2.\n\n\n\n2. § 192.631 Control room management.\n(a) General.\n(1) This section applies to each operator of a pipeline facility with a controller\nworking in a control room who monitors and controls all or part of a pipeline\nfacility through a SCADA system. Each operator must have and follow written\ncontrol room management procedures that implement the requirements of this\nsection . . . .\n(b) . . . .\n(c) Provide adequate information. Each operator must provide its controllers with\nthe information, tools, processes and procedures necessary for the controllers to\ncarry out the roles and responsibilities the operator has defined by performing each\nof the following:\n(1) Implement sections 1, 4, 8, 9, 11.1, and 11.3 of API RP 1165 (incorporated by\nreference, see §192.7) whenever a SCADA system is added, expanded or replaced,\nunless the operator demonstrates that certain provisions of sections 1, 4, 8, 9, 11.1,\nand 11.3 of API RP 1165 are not practical for the SCADA system used;\nNNG’s procedure 50.202, entitled “Providing Adequate Information-SCADA Upgrade”\n(Procedure 50.202), was not adequate for defining adding, expanding or replacing a SCADA\nsystem as required by § 192.631(c)(1). Specifically, API RP 1165, section 3 Definitions, at 3.25\nstates that a SCADA system is, “[a] system which is a combination of computer hardware and\nsoftware used to send commands and acquire data for the purpose of monitoring and\ncontrolling.is comprised of hardware and software.” As a result, hardware individually, software\nindividually, or both hardware and software can be changed in an addition, expansion, or\nreplacement of the SCADA system. The entire SCADA system is not required to be changed for\na SCADA system expansion or addition, or replacement to occur. Procedure 50.202 did not\nclearly identify the types of hardware that when added, expanded or replaced (such as servers,\ncommunications components, or consoles) will result in API RP 1165 implementation.\nAdditionally, the requirements of API RP 1165 are not just applicable to a SCADA system that\nis upgraded. Other statements within NNG’s procedure were not clear regarding meaning as\nwell, such as the following:\n3.6 Northern considers an expansion of the SCADA system as the addition of a\nreal-time/historical environment integrated into the current SCADA systems.\nCurrent SCADA systems include the primary, backup and model office/test\nsystems.\nThis statement should be clarified as to whether or not it means a software or a hardware change\nas well. Further, neither the procedure nor the engineering standard for the HMI referenced in the\nprocedure (NNG’s procedure, entitled “ES 5675 General Specifications for HMI”) provided\nclarity on what record would be used to demonstrate compliance with the implementation of API\nRP 1165 sections 1, 4, 8, 9, 11.1, and 11.3, per § 192.631(j)(1).\nProcedure 50.202 requires amendment to adequately address the types of individual hardware or\nindividual software changes that will result in implementation of the appropriate sections of API\n\n\n\nRP 1165. Additionally, the record that will be used to demonstrate API RP 1165 has been\nimplemented needs to be added to the procedures.\n3. § 192.631 Control room management.\n(a) General.\n(1) This section applies to each operator of a pipeline facility with a controller\nworking in a control room who monitors and controls all or part of a pipeline\nfacility through a SCADA system. Each operator must have and follow written\ncontrol room management procedures that implement the requirements of this\nsection . . . .\n(b) . . . .\n(c) Provide adequate information. Each operator must provide its controllers with\nthe information, tools, processes and procedures necessary for the controllers to\ncarry out the roles and responsibilities the operator has defined by performing each\nof the following:\n(1) . . . .\n(2) Conduct point-to-point verification between SCADA displays and related field\nequipment when field equipment is added or moved and when other changes that\naffect pipeline safety are made to field equipment or SCADA displays;\nNNG’s procedure 50.203, entitled “Providing Adequate Information – SCADA Point to Point\nVerification” (Procedure 50.203), and ES-0165 entitled “Turnover/Start-Up Procedure for New\nConstruction ” (ES-0165), along with various engineering commissioning checklists, were not\nadequate to define point-to-point verifications between SCADA displays and related field\nequipment when field equipment is added or removed and when other changes that affect\npipeline safety are made to field equipment or SCADA displays as required by § 192.631(c)(2).\nSpecifically, Procedure 50.203 stated in section 3.1:\nFor the purposes of this procedure, Northern considers adding or moving field\nequipment (including but not limited to compression station equipment, meters,\ntransmitters and valves) to be defined as a change that affects the data\ncommunication to the SCADA system from monitoring devices such as a remote\nterminal unit (RTU) or programmable logic controller (PLC). This is further\ndefined as a field equipment change that results in an addition or change in RTU\nor PLC address for a safety related alarm point. This type of change would require\nthe SCADA support team and field representative to perform a point-to-point\nverification between the SCADA system and the field end device in order to\nensure gas controllers are viewing correct data.\nNNG’s Procedure 50.203 was not clear that either a change in data communication to SCADA,\nor, separately, a change or addition to an address would result in a point to point being\nconducted. This requires amendment because while a change in a transmitter range could result\nin a loss of communication during the replacement depending on how this was performed in the\nfield, the addressing may remain the same, but the range of the device would change, and it is\nnot clear if data communication such as loss of communication is considered. Data\n\n\n\ncommunication may only mean a change in address or method of communication, and this would\nnot adequately ensure gas controllers are viewing correct data. Clarification to procedures should\ninclude requiring flow computer changes to result in point-to-point verifications as well.\nFurther, NGG’s inadequate point-to-point verification procedures impacted alarm management\nprocedures, required under § 192.631(e)(1). Procedure 50.203, section 5.1.2, stated, “[c]alculated\npoints set up for processing alarms will be validated when points are added or deleted.\nCommunication from the new point will be cycled from on to off and verify the loss of\ncommunication changes the calculated points color.” However, it would be possible for a point\ninvolved in a calculation to have the same point with the same address used but the range\nchanged, and that range change could impact the calculation. This would only work correctly if\nthe calculated point did not have any separate alarm setpoints. For example, this would not be\naccurate for a calculated point such as that for a pack alarm as defined in the Alarm Management\nplan referenced as 50-400.\nAdditionally, Procedure 50.203 section 5.1.15 stated:\nFor project related SCADA display changes, a field technician or engineering\nrepresentative will submit a SCADA screen change EATS ticket and installation\nreport documenting SCADA point requirements for the screen prior to the work\nbeing performed. The EATS ticket will be approved by a designated\nrepresentative from gas control. For non-project related SCADA display changes,\na designated representative from gas control will submit a SCADA screen change\nEATS ticket to the SCADA support team. The display and point-to-point\nvalidation will be conducted per 5.1.14.\nHowever, nothing required that these changes be made before the project related assets are\npushed to the controllers or become operational and this would clearly be required for the\ncontrollers to have the necessary information and tools to complete their roles and\nresponsibilities.\nAlso, it was not clear how other aspects of point-to-point will be conducted and when. From\nProcedure 50.203, nothing was specially described regarding logic testing. Logic testing would\nbe required for ESD applications, or elements such as valve status alarming on emergency\nvalves. An alarm condition would be detected and alarmed on when the valve did not complete\nthe command sequence within a certain amount of time. While Procedure 50.203 did reference\nthe following ES 0165 procedures and the associated commissioning checklists,\nES 0165 - Turnover/Start-Up Procedure for New Construction;\nES 0165e - Appendix E: Fire and Gas System Commissioning Checklist;\nES 0165k - Appendix K: SCADA Commissioning Checklist; and\nES 0165v - Appendix V: ESD Commissioning Checklist;\nit was not clear whether this is only achieved by testing with air. Air testing would not be\nsufficient in some cases to confirm adequate information is available for controllers, as timing\nand operation can be impacted when the commodity is added to the pipe, thus impacting the\n\n\n\ntiming of adequate alarming. It was also not clear from procedures how the deficiencies\nidentified during the commissioning (known as COMM list) are addressed before the controller\nis required to operate the system. This is noted as in ES 0165k, as it stated in the Instructions\nsection, “[i]f a station was partially validated, provide a list of points that were left in the\n“COMM” group to DL-Gas Control.” The COMM list or group should not have any elements\nthat could impact safety implemented for the controller before completely tested and this is not\nclear in procedures.\nSection 192.631(e)(1) requires accurate alarms and is not time dependent so this would apply\nany time commodity is in the pipeline (regardless of flowing or not) and would impact point-to-\npoint activities.\nFinally, neither Procedure 50.203 nor the procedures referenced in ES-0165 defined how loss of\ncommunication is checked on point types beyond that of Calculated Points. Loss of\ncommunication is an alarm that must be checked to operate correctly through a point-to-point\nprior to operation. The procedures did not define how valve status alarms, various aspects of\npower including UPS systems, or man down alarms would receive a point-to-point as required.\nProcedures were not clear on how simulation would be noted in the point-to-point documentation\nand that the location of the simulation would be identified, as this can impact whether or not the\ncontroller has sufficient information to complete their roles and responsibilities upon point-to-\npoint completion.\nProcedures 50.203 and ES-0165 with associated commissioning checklists require amendment to\nsufficiently clarify these elements identified and to sufficiently address the requirements of\n§ 192.631(c)(2) and § 192.631(e)(1). Further these procedures need to clarify points that can\nimpact safety as required by § 192.631(c)(2).\n4. § 192.631 Control room management.\n(a) General.\n(1) This section applies to each operator of a pipeline facility with a controller\nworking in a control room who monitors and controls all or part of a pipeline\nfacility through a SCADA system. Each operator must have and follow written\ncontrol room management procedures that implement the requirements of this\nsection. . . .\n(b) . . . .\n(e) Alarm management. Each operator using a SCADA system must have a written\nalarm management plan to provide for effective controller response to alarms. An\noperator’s plan must include provisions to:\n(1) Review SCADA safety-related alarm operations using a process that ensures\nalarms are accurate and support safe pipeline operations;\nNNG’s Procedure 50.400, entitled “Alarm Management,” was not adequate as it did not clearly\ndefine how a review is conducted on alarms to ensure accuracy and the support of safe pipeline\noperations as required by §§ 192.631(e) and 192.631(e)(1). Specially, Section 192.631(e)\nrequires the Alarm Management plan to provide for effective controller response to alarms, and\n\n\n\nmust include provisions to review SCADA safety-related alarm operations using a process that\nensures alarms are accurate and support safe pipeline operations. Yet the Procedure 50.400 was\nnot clear as to which points will be reviewed to ensure accuracy and that the alarms are set to\nsupport safe pipeline operations.\nLoLo pressure alarms were identified as a Critical Alarm A priority 2 in Appendix A and not as a\nSafety Related Alarm Priority 1. It was not clear in procedures if this priority of alarm would be\nreviewed to ensure accuracy and the support of safe pipeline operations.\nSimilarly, Appendix A identified an alarm priority called Safety-Related Priority 1. However,\nnot all alarms that support safe-pipeline operations were found in this priority. For example,\nPriority 8 was communication failure. Communication failure is an alarm state that is necessary\nto support safe operations. Additionally, valve alarms associated with incorrect commanded\nstatus or a valve that has not achieved a commanded state within a certain amount of time were\nnot identified in Appendix A. Only ESD valves are identified as Safety-Related Priority 1. The\npriority and alarm function associated with other valves was unknown. Yet valves were defined\nas a point that is Safety-Related in section 3.1.8 of Procedure 50.400. The procedure needs to\nclarify if all points that are safety related, regardless of Alarm Priority, will be reviewed to\nensure the setpoints or values are accurate and support safe operation.\nAlso, Appendix A indicated H2S Delivery pressure would have a priority of 1 called Safety-\nRelated Alarm, but other information indicated that H2S high limit in composition would be a\nSafety Related Alarm Priority 1 with delivery pressure treated difference as a Critical Alarm A\nPriority 2. Because the Safety-Related alarm priority was not the only priority group that must be\naccurate and established to support safe operations, it was not clear from Procedure 50.400 how\nthese types of alarms in Priority 2 would be reviewed.\nThe operator identified verbally during the inspection and confirmed this information during\nfollow-up meetings as late as August 2023 that rate-of-change (ROC) alarms exist on certain\npoints. However, ROC alarms were not described in the Procedure 50.400 nor listed on the\nAppendix A: Alarm and Alert priorities table. As a result, it was not clear if these alarms would\nbe reviewed to support safe pipeline operations or what priority would be relevant.\nFinally, Procedure 50.400 defined “Safety-Related Point” in section 3.1.8 as an “input or output\npoint on the system that when it exceeds allowable levels results in a safety-related alarm or has\nthe potential to develop into abnormal operations or a safety-related condition. Input points\ninclude pipeline and station inlet and outlet pressures, pressure regulating inlet and outlet\npressures, delivery pressures, calculated line pack values, flow rates, valve operation, fire\ndetection, gas detection, H2S detection, smoke detection, temperatures associated with the gas\ncooling and high filter separator levels. Output points include set points for pressure and turbine\nspeed control, command for valve control, station isolation and unit shutdowns.” However, not\nall of these types of points were clarified as having a priority on Appendix A, such as flow rate\nor pack. If this is because alarms are not set on these two types of inputs or as an output, this\nshould be clarified in the Alarm Management procedure 50.400 as it was not clear why these\nwere not listed in Appendix A.\n\n\n\nProcedure 50.400 and Appendix A require amendment to clearly define how and on what\nspecific points (including the various priorities) a review is conducted on alarms to ensure\naccuracy and the support of safe pipeline operations as required by §§ 192.631(e) and\n192.631(e)(1).\n5. § 192.631 Control room management.\n(a) General.\n(1) This section applies to each operator of a pipeline facility with a controller\nworking in a control room who monitors and controls all or part of a pipeline\nfacility through a SCADA system. Each operator must have and follow written\ncontrol room management procedures that implement the requirements of this\nsection. . . .\n(b) . . . .\n(e) Alarm management. Each operator using a SCADA system must have a written\nalarm management plan to provide for effective controller response to alarms. An\noperator’s plan must include provisions to:\n(1) . . . .\n(2) Identify at least once each calendar month points affecting safety that have been\ntaken off scan in the SCADA host, have had alarms inhibited, generated false\nalarms, or that have had forced or manual values for periods of time exceeding that\nrequired for associated maintenance or operating activities;\nNNG’s Procedure 50.400 entitled “Alarm Management,” was not adequate as it did not clearly\ndescribe how the identification at least once each calendar month will be accomplished for points\nthat affect safety that have been taken off scan in the SCADA host, had alarms inhibited,\ngenerated false alarms or that have forced or manual values for period of time exceeding that\nrequired for associated maintenance or operator activities as required by §§ 192.631(e) and\n192.631(e)(2). Specifically, section 5.4 of Procedure 50.400 stated:\n5.4 Reports and analysis will be conducted on a monthly or annual basis as defined below to\ndemonstrate compliance and measure effectiveness.\n• 5.4.1 An alarm/alert review process will be completed at least once each calendar month.\nThis review will consist of the following:\no 5.4.1.1 Review the number of Safety-Related Alarms that have occurred, been\nsuppressed, manually overridden, points taken off-scan, shown to be false or had\nalarm limits changed and include in the monthly report.\no 5.4.1.1.1 Gas controllers shall include actions taken on all Safety-Related\nalarms received in the daily log.\no 5.4.1.1.2 Sequential alarms received during the day due to maintenance\nactivities can be consolidated in one daily log entry.\no 5.4.1.2 Review the number of Alarms/Alerts that have occurred, been suppressed,\nmanually overridden, points taken and off-scan to identify excessive\nreoccurrences and include in the monthly report.\no 5.4.1.2.1 The top 10 alarms and alerts from each console will be reviewed\nmonthly to determine the source of the alarm and if limits require\n\n\n\nadjustment.\no 5.4.1.3 Review points with frozen data from RTUs, PLCs or SCADA that are not\ncaused by loss of communications.\no 5.4.1.4 Review RTU communication outages and document the duration and\nactions to resolve the outage.\no 5.4.1.5 Parked alarms and alerts will be reviewed on a continuous basis and\naddressed as appropriate.\no 5.4.1.6 The manager of gas control or designee shall document and track\ndeficiencies in EATS and follow up with proper departments to ensure excessive,\nnuisance, false, parked, suppressed and manually overridden indications are\naddressed in a prompt manner.\nSection 195.446(e) requires the operator to have an alarm management plan that will provide for\neffective controller response to alarms. As such, controllers are only a part of the Alarm\nManagement process that will identify what must be reviewed for points that can impact safety\neach month as required by 195.446(e)(2) and have deficiencies addressed as required by\n195.446(e)(6). The following is not clear from procedures:\n1. 2. 3. 4. 5. 6. How the review of calculated points and associated alarming if the point can impact\nsafety will be included on a monthly basis (such as total flow through a station).\nHow frozen data (or forced data) at the Remote Terminal Unit (RTU), Programmable\nLogic Controller (PLC) or in SCADA will be detected and reported on is not clear.\nControllers are not the only individuals that this could be reported by. For example,\nfield technicians or SCADA personnel could identify forced data on points that can\nimpact safety, or automatic programming can identify this information, but it is not\nclear in procedures what is being done.\nHow standing alarms and alerts will be reported on and identified each month when\nassociated with points that can impact safety was not clear in procedures. While this\nis described as a continuous review process, if it is associated with a point that can\nimpact safety, it would be a point when in alarm is required to be part of the monthly\nreview and would require addressing.\nHow points taken off-scan will be identified or reported on. Again, this should not fall\nonly to the controllers to identify, as SCADA personnel can impact this change and\nthis may not be evident to the controller.\nHow the alarm inhibit function will be detected and reported on each month. While\ncontrollers can report on certain aspects of this function, others may also perform this\ntask, such as SCADA, and this must be identified as well. Suppression may be in\nplace at the time of the monthly report, and this would not be clearly identified\nwithout a reporting function being established.\nHow false alarms will be determined was not clear in procedures. While false alarms\nmay include chattering or nuisance alarms as described in Procedure 50.500, section\n5.4.1.2, it is not the only potential source for false alarms. Section 3.1.5 defined a\nfalse alarm. However, it was not clear if controllers receive an alarm from the field\ndue to maintenance activities, but they were not notified in advance of this activity, if\n\n\n\n7. 8. 9. this would result in a false alarm and if so, how this would be included in the monthly\nreview and addressed as required by section 5.4.1.6.\nThe process as described in Procedure 50.400 did not include points that can impact\nsafety that have been in manual for periods of time exceeding that required for\nassociated maintenance or operating activities. This would include if remote/manual,\nhand/off/auto, or remote/local switching can occur in the field on a valve or\ncompressor such that, if the remote function is removed from the controller (placed in\nmanual, local, hand, etc.) for periods exceeding associated maintenance or operating\nactivity requirements as part of the monthly report, and address the identified\ndeficiencies.\nHow loss of communication will be determined and reported on.\nThe process as described in Procedure 50.400 and did not include what specific\nreports or data sources will be reviewed as part of the monthly review process, such\nas emails being provided when alarm setpoints or limits are moved, alarm/event logs,\nRTU communication reports, or daily logs. It also did not clarify what information\nwill be used as the record to demonstrate this has been sufficiently accomplished each\nmonth.\nProcedure 50.400 requires amendments to clarify how the reviews identified in 5.4.1 will be\naccomplished, what data sources will be used as inputs for the monthly review process (emails,\nspecific reports, controller shift logs, alarm/events logs, etc.), and how the output will be\nrecorded (EATS and Summary files, etc.) to complete the monthly review required by §\n192.631(e)(2). Additionally, the amendments need to address how aspects of points taken off-\nscan, forced data, alarms inhibited, false alarms, and manual conditions on points affecting safety\nwill be identified monthly.\n6. § 192.631 Control room management.\n(a) General.\n(1) This section applies to each operator of a pipeline facility with a controller\nworking in a control room who monitors and controls all or part of a pipeline\nfacility through a SCADA system. Each operator must have and follow written\ncontrol room management procedures that implement the requirements of this\nsection. . . .\n(b) . . . .\n(e) Alarm management. Each operator using a SCADA system must have a written\nalarm management plan to provide for effective controller response to alarms. An\noperator's plan must include provisions to:\n(1) . . . .\n(3) Verify the correct safety-related alarm set-point values and alarm descriptions at\nleast once each calendar year, but at intervals not to exceed 15 months;\nNNG’s Procedure 50.400 did not adequately define the process used to verify the correct safety-\nrelated alarm set-point values and alarm descriptors at least once each calendar year, but at\nintervals not to exceed 15 months as required by § 192.631(e)(3).\n\n\n\nSpecifically, Procedure 50.400 section 5.4.2 stated:\n• 5.4.2 An alarm/alert review process will be completed annually, but at intervals\nnot to exceed 15 months.\no 5.4.2.1 The review process will consist of verifying the correct Safety-Related Alarm\nset point values and descriptions. Additionally, the alarm management procedure will\nbe reviewed as part of this process to determine effectiveness.\no 5.4.2.2 The annual review process will include an analysis of safety-related points to\nensure continued applicability.\no 5.4.2.3 The annual review process will utilize the Annual Safety-Related Alarm\nreport and Annual Alarm Management Plan Review Report.\no 5.4.2.4 Remedies to improve alarm or alerts include:\no Optimizing set points\no Addressing chattering or flooding alarm/alerts\no Evaluating priority levels for alarms/alerts\no Determining if an alert should be moved to an alarm\no Determining if an alarm should be moved to an alert\no 5.4.2.5 The manager of gas control or designee shall follow up with proper\ndepartments to ensure deficiencies are addressed in a prompt manner.\nDuring the inspection, NNG verbally explained that the process involved creating a list of the\nalarm setpoint values and alarm descriptors per location by the control room with SCADA\nassistance. This information was then sent to the various field locations for field personnel to\nsign off on the correct alarm setpoint values per point and the alarm descriptors. However, none\nof this was described as part of the process in Procedure 50.400, nor were the reports noted in\nsection 5.4.2.3 included as part of NNG’s Alarm Management procedure. It was not clear that\neither one or both reports identified in section 5.4.2.3 were developed using the existing SCADA\nsystem data or a Master Alarm Database separate from the SCADA system. It was also not clear\nhow changes that have been processed through EATS or as part of other MOC processes would\nbe confirmed to still be in place for relevant temporary or permanent changes. How verification\nof alarm setpoint values and alarm descriptors is performed was not adequately defined in\nProcedure 50.400.\nProcedure 50.400 requires amendment to describe how the requirements of § 192.631(e)(3) will\nbe implemented.\n7. § 192.631 Control room management.\n(a) General.\n(1) This section applies to each operator of a pipeline facility with a controller\nworking in a control room who monitors and controls all or part of a pipeline\nfacility through a SCADA system. Each operator must have and follow written\ncontrol room management procedures that implement the requirements of this\nsection. . . .\n(b) . . . .\n\n\n\n(e) Alarm management. Each operator using a SCADA system must have a written\nalarm management plan to provide for effective controller response to alarms. An\noperator's plan must include provisions to:\n(1) . . . .\n(5) Monitor the content and volume of general activity being directed to and\nrequired of each controller at least once each calendar year, but at intervals not to\nexceed 15 months that will assure controllers have sufficient time to analyze and\nreact to incoming alarms;\nNNG’s Procedure 50.400 was not adequate to assure that controllers have sufficient time to\nanalyze and react to incoming alarms as required by § 192.631(e)(5). Specifically, Procedure\n50.400 section 5.5.2 stated that during the review process the data collected will be analyzed to\ndetermine if the volume of activity processed by the gas controller is at a level that does not\njeopardize the safe operation of NNG facilities. Section 5.5.2.2 stated that NNG will measure the\ncontroller's workload against internally defined Key Performance Indicators (KPIs) to ensure the\ncontroller performance is adequate. However, which specific KPIs will be used has not been\ndefined. KPIs need to be defined before the analysis is able to be completed and documented.\nThis is significant to Procedure 50.400 being developed correctly as designed and then\nimplemented. Also, Procedure 50.400 did not clearly state where KPIs would be recorded and\nhow these selected KPIs would be used to determine the volume of activity was at a level not to\njeopardize the safe operation of NNG facilities.\nAdditionally, review of controller workload is required to determine that the controller has\nsufficient time to analyze and react to incoming alarms. While KPIs are certainly part of that\nanswer when selected correctly, without reviewing the time required for controllers to\nacknowledge alarms and respond based on priority, the process to confirm controllers have\nsufficient time to analyze and react to incoming alarms is incomplete. NNG’s alarm\nrationalization process may need to be adjusted and redone if the designed and expected time of\nresponse by priority cannot be achieved by controllers. Adjusting and redoing the alarm\nrationalization process was not clearly required in NNG’s procedures.\nFinally, how deficiencies associated with this workload analysis will be addressed and recorded\nis not adequate as defined in Procedure 50.400 section 5.5.2.1. Section 5.5.2.1 explained:\nIf the analysis reveals deficiencies, the gas control manager will take steps\nnecessary to ensure safe operation of facilities by:\n• Reducing the volume of phone calls\n• Reviewing changes that have been made to the overall operations\n• Exploring and implementing automated recordkeeping processes\n• Reviewing the need and applicability of alerts\n• Requesting staffing additions\n• Requesting controller input\n• Other actions as identified.\nHowever, it is not clear that “other actions as identified” would include actions such as console\nadditions, console asset reassignment, or a change to the alarm rationalization process. These\n\n\n\nthree actions are also types of changes that impact the time for controllers to respond to alarms.\nNNG’s procedures need amendment to clarify that these three actions are also possible outcomes\nof a workload study.\nProcedure 50.400 requires amendment to clarify how NNG will determine that that the volume\nof alarms does not jeopardize the safe operation of NNG facilities, to identify the specific KPIs\nthat will be used, and to clarify that other actions as identified would include at least console\nadditions, console asset reassignment, and changes to the alarm rationalization process.\n8. § 192.631 Control room management.\n(a) General.\n(1) This section applies to each operator of a pipeline facility with a controller\nworking in a control room who monitors and controls all or part of a pipeline\nfacility through a SCADA system. Each operator must have and follow written\ncontrol room management procedures that implement the requirements of this\nsection….\n(2) The procedures required by this section must be integrated, as appropriate,\nwith operating and emergency procedures required by §§192.605 and 192.615. An\noperator must develop the procedures no later than August 1, 2011, and must\nimplement the procedures according to the following schedule. The procedures\nrequired by paragraphs (b), (c)(5), (d)(2) and (d)(3), (f) and (g) of this section must\nbe implemented no later than October 1, 2011. The procedures required by\nparagraphs (c)(1) through (4), (d)(1), (d)(4), and (e) must be implemented no later\nthan August 1, 2012. The training procedures required by paragraph (h) must be\nimplemented no later than August 1, 2012, except that any training required by\nanother paragraph of this section must be implemented no later than the deadline\nfor that paragraph.\n(b) . . . .\n(f) Change management. Each operator must assure that changes that could affect\ncontrol room operations are coord","truncated":true,"body_characters":67069}