# NORTHERN NATURAL GAS CO — Notice of Amendment

- **operation:** document
- **citation:** CPF 32024027NOA
- **title:** NORTHERN NATURAL GAS CO — Notice of Amendment
- **source type:** enforcement
- **agency:** Pipeline and Hazardous Materials Safety Administration
- **status:** historical
- **official:** true
- **published on:** 2024-07-12
- **effective on:** Not available
- **summary:** CLOSED notice of amendment citing 192.631(a)(1), 192.631(a)(2), 192.631(b)(4), 192.631(c)(1), 192.631(c)(2), 192.631(e)(1), 192.631(e)(2), 192.631(e)(3), 192.631(e)(5), 192.631(f), 192.631(g)(1), 192.631(h), 192.631(h)(5), 192.631(j)(2).
- **machine formats:** - **json:** https://regulus.evalyn.ai/document/phmsa-enforcement-32024027noa.json
- **markdown:** https://regulus.evalyn.ai/document/phmsa-enforcement-32024027noa.md
- **app url:** https://regulus.evalyn.ai/document/phmsa-enforcement-32024027noa
- **source url:** https://primis.phmsa.dot.gov/enforcement-data/case/32024027NOA
**body:**

Notice of Amendment involving NORTHERN NATURAL GAS CO. PHMSA's enforcement data identifies the cited regulations as 192.631(a)(1),  192.631(a)(2),  192.631(b)(4),  192.631(c)(1),  192.631(c)(2),  192.631(e)(1),  192.631(e)(2),  192.631(e)(3),  192.631(e)(5),  192.631(f),  192.631(g)(1),  192.631(h),  192.631(h)(5),  192.631(j)(2). The case was opened on 2024-07-12 and is reported as closed as of 2025-11-10. Open the official case record for notices, responses, orders, and the latest status.

Official case documents:

32024027NOA_Closure Letter_11102025_(20-188476).pdf: https://primis.phmsa.dot.gov/enforcement-documents/32024027NOA/32024027NOA_Closure%20Letter_11102025_(20-188476).pdf

32024027NOA_Closure Letter_11102025_(20-188476)_text.pdf: https://primis.phmsa.dot.gov/enforcement-documents/32024027NOA/32024027NOA_Closure%20Letter_11102025_(20-188476)_text.pdf

32024027NOA_Notice of Amendment_07122024_(20-188476).pdf: https://primis.phmsa.dot.gov/enforcement-documents/32024027NOA/32024027NOA_Notice%20of%20Amendment_07122024_(20-188476).pdf

32024027NOA_Notice of Amendment_07122024_(20-188476)_text.pdf: https://primis.phmsa.dot.gov/enforcement-documents/32024027NOA/32024027NOA_Notice%20of%20Amendment_07122024_(20-188476)_text.pdf

32024027NOA_Operator Response to Notice_09092024_(20-188476).pdf: https://primis.phmsa.dot.gov/enforcement-documents/32024027NOA/32024027NOA_Operator%20Response%20to%20Notice_09092024_(20-188476).pdf

32024027NOA_Closure Letter_11102025_(20-188476)_text.pdf

U.S. Department
of Transportation
Pipeline and Hazardous
Materials Safety
901 Locust Street, Suite 480
Kansas City, MO 64106
VIA ELECTRONIC MAIL TO: laura.demman@nngco.com, thomas.correll@nngco.com;
November 10, 2025
Ms. Laura Demman
President & CEO
Northern Natural Gas Company
1111 South 103rd Street
Omaha, NE 68124
RE: CPF 3-2024-027-NOA
Dear Ms. Demman:
From September 8 through September 11, and September 23 through September 25, 2020, a
representative from the Pipeline and Hazardous Materials Safety Administration (PHMSA),
pursuant to chapter 601 of 49 United States Code, conducted an inspection of the procedures for
the Northern Natural Gas Company (NNG) Control Room located in Omaha, Nebraska. On July
12, 2024, pursuant to 49 CFR § 190.206, PHMSA issued a Notice of Amendment which proposed
amendment of NNG’s procedures.
NNG submitted its amended procedures, with the final submission occurring on November 10,
2025. PHMSA has reviewed the amended procedures, and it appears that the inadequacies
outlined in the Notice of Amendment have been corrected.
This letter is to inform you that no further action is necessary, and this case is now closed. Thank
you for your cooperation.
Sincerely,
David Barrett
Acting Director, Central Region, Office of Pipeline Safety
Pipeline and Hazardous Materials Safety Administration
cc: Thomas Correll, VP, Pipeline Safety and Risk, NNG, thomas.correll@nngco.com

32024027NOA_Notice of Amendment_07122024_(20-188476)_text.pdf

NOTICE OF AMENDMENT
VIA ELECTRONIC MAIL TO: mark.hewett@nngco.com, thomas.correll@nngco.com;
john.gormley@nngco.com
July 12, 2024
Mr. Mark Hewett
President and CEO
Northern Natural Gas Company
1111 S. 103rd Street
Omaha, NE 68124
CPF 3-2024-027-NOA
Dear Mr. Hewett:
From September 8 through September 11, and September 23 through September 25, 2020, a
representative of the Pipeline and Hazardous Materials Safety Administration (PHMSA),
pursuant to Chapter 601 of 49 United States Code (U.S.C.), inspected procedures for the
Northern Natural Gas Company (NNG) Control Room located in Omaha, Nebraska. NNG
updated its Control Room Management procedures initially as a result of this inspection in 2020
and continued to work on procedure amendments with PHMSA during meetings held at various
times including those occurring in September 2022 and August 2023.
As a result of the inspection and NNG’s continued work on procedure amendments, PHMSA has
identified apparent inadequacy found within NNG’s plans or procedures. The items inspected
and the inadequacies identified are described below:
1. § 192.631 Control room management.
(a) General.
(1) This section applies to each operator of a pipeline facility with a controller
working in a control room who monitors and controls all or part of a pipeline
facility through a SCADA system. Each operator must have and follow written
control room management procedures that implement the requirements of this
section. . . .
(b) Roles and responsibilities. Each operator must define the roles and
responsibilities of a controller during normal, abnormal, and emergency operating



conditions. To provide for a controller's prompt and appropriate response to
operating conditions, an operator must define each of the following:
(1) . . . .
(4) A method of recording controller shift-changes and any hand-over of
responsibility between controllers;
NNG’s procedures 50.200, entitled “Controller Roles and Responsibilities” (Procedure 50.200),
and 50.201, entitled “Providing Adequate Information – Shift Exchange” (Procedure 50.201),
were not adequate to address any hand-over responsibility between controllers as required by §
192.631(b)(4). Specifically, while the procedures did require that a controller log-on to the
console when handing over responsibility to another controller, nothing required that the
controller leaving the console would log-off, or clarified that the SCADA system would
automatically log-off the outgoing controller after a period of time, leaving the prior controller’s
area of responsibility active.
The control room has multiple consoles (North Horsepower, North Town Border Station (TBS),
and South/Central), all three of which can monitor and control any other console’s information.
The control room procedures and SCADA system allow multiple controllers to be logged onto
the SCADA system at any given time. Some individuals that are not qualified controllers also
have access to the control room, such as the control room Director. Additionally, during certain
times, controllers have completed training on only one or more consoles but have not completed
training relevant to all of the specific consoles with the assigned area of responsibility. Procedure
50.100, entitled “Control Room Management,” required a controller to be qualified, and
Procedure 50.200 required a log-on, but nothing required a controller to perform a log-off
function. Since multiple controllers can be logged-on at the same time, and this log-on feature
sets their area of responsibility based on qualifications and supervisor’s assignment for the
specific day or night, nothing would prevent unqualified individuals from operating a console,
unless a log-off function is required.
NNG’s Procedure 50.200 in section 3.2.2 stated “[a] monthly audit will be completed to verify a
controller did not operate on a console they were not qualified for. Document any violations in a
deviation report.” However, if controllers that are qualified can stay logged on indefinitely, then
anyone in the control room (qualified or not) could access the console and execute commands or
acknowledge alarms without this being detected or discovered in the monthly audit function.
Additionally, if controllers are not required to log-out/log-off or if the SCADA system does not
automatically log-out/log-off qualified individuals within a certain time frame, individuals that
had not completed cross-training on all consoles would also be able to execute commands and
respond to information for systems they were not qualified for. By not requiring a log-off
function, the monthly audit would not be able to determine if a console had a person operating it
that was not qualified for that area of responsibility.
NNG’s procedures 50.200 and 50.201 require amendment to adequately address the hand-over
responsibility between controllers and to adequately establish and implement the monthly review
process regarding qualified controllers as described in Procedure 50.201, section 3.2.2.



2. § 192.631 Control room management.
(a) General.
(1) This section applies to each operator of a pipeline facility with a controller
working in a control room who monitors and controls all or part of a pipeline
facility through a SCADA system. Each operator must have and follow written
control room management procedures that implement the requirements of this
section . . . .
(b) . . . .
(c) Provide adequate information. Each operator must provide its controllers with
the information, tools, processes and procedures necessary for the controllers to
carry out the roles and responsibilities the operator has defined by performing each
of the following:
(1) Implement sections 1, 4, 8, 9, 11.1, and 11.3 of API RP 1165 (incorporated by
reference, see §192.7) whenever a SCADA system is added, expanded or replaced,
unless the operator demonstrates that certain provisions of sections 1, 4, 8, 9, 11.1,
and 11.3 of API RP 1165 are not practical for the SCADA system used;
NNG’s procedure 50.202, entitled “Providing Adequate Information-SCADA Upgrade”
(Procedure 50.202), was not adequate for defining adding, expanding or replacing a SCADA
system as required by § 192.631(c)(1). Specifically, API RP 1165, section 3 Definitions, at 3.25
states that a SCADA system is, “[a] system which is a combination of computer hardware and
software used to send commands and acquire data for the purpose of monitoring and
controlling.is comprised of hardware and software.” As a result, hardware individually, software
individually, or both hardware and software can be changed in an addition, expansion, or
replacement of the SCADA system. The entire SCADA system is not required to be changed for
a SCADA system expansion or addition, or replacement to occur. Procedure 50.202 did not
clearly identify the types of hardware that when added, expanded or replaced (such as servers,
communications components, or consoles) will result in API RP 1165 implementation.
Additionally, the requirements of API RP 1165 are not just applicable to a SCADA system that
is upgraded. Other statements within NNG’s procedure were not clear regarding meaning as
well, such as the following:
3.6 Northern considers an expansion of the SCADA system as the addition of a
real-time/historical environment integrated into the current SCADA systems.
Current SCADA systems include the primary, backup and model office/test
systems.
This statement should be clarified as to whether or not it means a software or a hardware change
as well. Further, neither the procedure nor the engineering standard for the HMI referenced in the
procedure (NNG’s procedure, entitled “ES 5675 General Specifications for HMI”) provided
clarity on what record would be used to demonstrate compliance with the implementation of API
RP 1165 sections 1, 4, 8, 9, 11.1, and 11.3, per § 192.631(j)(1).
Procedure 50.202 requires amendment to adequately address the types of individual hardware or
individual software changes that will result in implementation of the appropriate sections of API



RP 1165. Additionally, the record that will be used to demonstrate API RP 1165 has been
implemented needs to be added to the procedures.
3. § 192.631 Control room management.
(a) General.
(1) This section applies to each operator of a pipeline facility with a controller
working in a control room who monitors and controls all or part of a pipeline
facility through a SCADA system. Each operator must have and follow written
control room management procedures that implement the requirements of this
section . . . .
(b) . . . .
(c) Provide adequate information. Each operator must provide its controllers with
the information, tools, processes and procedures necessary for the controllers to
carry out the roles and responsibilities the operator has defined by performing each
of the following:
(1) . . . .
(2) Conduct point-to-point verification between SCADA displays and related field
equipment when field equipment is added or moved and when other changes that
affect pipeline safety are made to field equipment or SCADA displays;
NNG’s procedure 50.203, entitled “Providing Adequate Information – SCADA Point to Point
Verification” (Procedure 50.203), and ES-0165 entitled “Turnover/Start-Up Procedure for New
Construction ” (ES-0165), along with various engineering commissioning checklists, were not
adequate to define point-to-point verifications between SCADA displays and related field
equipment when field equipment is added or removed and when other changes that affect
pipeline safety are made to field equipment or SCADA displays as required by § 192.631(c)(2).
Specifically, Procedure 50.203 stated in section 3.1:
For the purposes of this procedure, Northern considers adding or moving field
equipment (including but not limited to compression station equipment, meters,
transmitters and valves) to be defined as a change that affects the data
communication to the SCADA system from monitoring devices such as a remote
terminal unit (RTU) or programmable logic controller (PLC). This is further
defined as a field equipment change that results in an addition or change in RTU
or PLC address for a safety related alarm point. This type of change would require
the SCADA support team and field representative to perform a point-to-point
verification between the SCADA system and the field end device in order to
ensure gas controllers are viewing correct data.
NNG’s Procedure 50.203 was not clear that either a change in data communication to SCADA,
or, separately, a change or addition to an address would result in a point to point being
conducted. This requires amendment because while a change in a transmitter range could result
in a loss of communication during the replacement depending on how this was performed in the
field, the addressing may remain the same, but the range of the device would change, and it is
not clear if data communication such as loss of communication is considered. Data



communication may only mean a change in address or method of communication, and this would
not adequately ensure gas controllers are viewing correct data. Clarification to procedures should
include requiring flow computer changes to result in point-to-point verifications as well.
Further, NGG’s inadequate point-to-point verification procedures impacted alarm management
procedures, required under § 192.631(e)(1). Procedure 50.203, section 5.1.2, stated, “[c]alculated
points set up for processing alarms will be validated when points are added or deleted.
Communication from the new point will be cycled from on to off and verify the loss of
communication changes the calculated points color.” However, it would be possible for a point
involved in a calculation to have the same point with the same address used but the range
changed, and that range change could impact the calculation. This would only work correctly if
the calculated point did not have any separate alarm setpoints. For example, this would not be
accurate for a calculated point such as that for a pack alarm as defined in the Alarm Management
plan referenced as 50-400.
Additionally, Procedure 50.203 section 5.1.15 stated:
For project related SCADA display changes, a field technician or engineering
representative will submit a SCADA screen change EATS ticket and installation
report documenting SCADA point requirements for the screen prior to the work
being performed. The EATS ticket will be approved by a designated
representative from gas control. For non-project related SCADA display changes,
a designated representative from gas control will submit a SCADA screen change
EATS ticket to the SCADA support team. The display and point-to-point
validation will be conducted per 5.1.14.
However, nothing required that these changes be made before the project related assets are
pushed to the controllers or become operational and this would clearly be required for the
controllers to have the necessary information and tools to complete their roles and
responsibilities.
Also, it was not clear how other aspects of point-to-point will be conducted and when. From
Procedure 50.203, nothing was specially described regarding logic testing. Logic testing would
be required for ESD applications, or elements such as valve status alarming on emergency
valves. An alarm condition would be detected and alarmed on when the valve did not complete
the command sequence within a certain amount of time. While Procedure 50.203 did reference
the following ES 0165 procedures and the associated commissioning checklists,
ES 0165 - Turnover/Start-Up Procedure for New Construction;
ES 0165e - Appendix E: Fire and Gas System Commissioning Checklist;
ES 0165k - Appendix K: SCADA Commissioning Checklist; and
ES 0165v - Appendix V: ESD Commissioning Checklist;
it was not clear whether this is only achieved by testing with air. Air testing would not be
sufficient in some cases to confirm adequate information is available for controllers, as timing
and operation can be impacted when the commodity is added to the pipe, thus impacting the



timing of adequate alarming. It was also not clear from procedures how the deficiencies
identified during the commissioning (known as COMM list) are addressed before the controller
is required to operate the system. This is noted as in ES 0165k, as it stated in the Instructions
section, “[i]f a station was partially validated, provide a list of points that were left in the
“COMM” group to DL-Gas Control.” The COMM list or group should not have any elements
that could impact safety implemented for the controller before completely tested and this is not
clear in procedures.
Section 192.631(e)(1) requires accurate alarms and is not time dependent so this would apply
any time commodity is in the pipeline (regardless of flowing or not) and would impact point-to-
point activities.
Finally, neither Procedure 50.203 nor the procedures referenced in ES-0165 defined how loss of
communication is checked on point types beyond that of Calculated Points. Loss of
communication is an alarm that must be checked to operate correctly through a point-to-point
prior to operation. The procedures did not define how valve status alarms, various aspects of
power including UPS systems, or man down alarms would receive a point-to-point as required.
Procedures were not clear on how simulation would be noted in the point-to-point documentation
and that the location of the simulation would be identified, as this can impact whether or not the
controller has sufficient information to complete their roles and responsibilities upon point-to-
point completion.
Procedures 50.203 and ES-0165 with associated commissioning checklists require amendment to
sufficiently clarify these elements identified and to sufficiently address the requirements of
§ 192.631(c)(2) and § 192.631(e)(1). Further these procedures need to clarify points that can
impact safety as required by § 192.631(c)(2).
4. § 192.631 Control room management.
(a) General.
(1) This section applies to each operator of a pipeline facility with a controller
working in a control room who monitors and controls all or part of a pipeline
facility through a SCADA system. Each operator must have and follow written
control room management procedures that implement the requirements of this
section. . . .
(b) . . . .
(e) Alarm management. Each operator using a SCADA system must have a written
alarm management plan to provide for effective controller response to alarms. An
operator’s plan must include provisions to:
(1) Review SCADA safety-related alarm operations using a process that ensures
alarms are accurate and support safe pipeline operations;
NNG’s Procedure 50.400, entitled “Alarm Management,” was not adequate as it did not clearly
define how a review is conducted on alarms to ensure accuracy and the support of safe pipeline
operations as required by §§ 192.631(e) and 192.631(e)(1). Specially, Section 192.631(e)
requires the Alarm Management plan to provide for effective controller response to alarms, and



must include provisions to review SCADA safety-related alarm operations using a process that
ensures alarms are accurate and support safe pipeline operations. Yet the Procedure 50.400 was
not clear as to which points will be reviewed to ensure accuracy and that the alarms are set to
support safe pipeline operations.
LoLo pressure alarms were identified as a Critical Alarm A priority 2 in Appendix A and not as a
Safety Related Alarm Priority 1. It was not clear in procedures if this priority of alarm would be
reviewed to ensure accuracy and the support of safe pipeline operations.
Similarly, Appendix A identified an alarm priority called Safety-Related Priority 1. However,
not all alarms that support safe-pipeline operations were found in this priority. For example,
Priority 8 was communication failure. Communication failure is an alarm state that is necessary
to support safe operations. Additionally, valve alarms associated with incorrect commanded
status or a valve that has not achieved a commanded state within a certain amount of time were
not identified in Appendix A. Only ESD valves are identified as Safety-Related Priority 1. The
priority and alarm function associated with other valves was unknown. Yet valves were defined
as a point that is Safety-Related in section 3.1.8 of Procedure 50.400. The procedure needs to
clarify if all points that are safety related, regardless of Alarm Priority, will be reviewed to
ensure the setpoints or values are accurate and support safe operation.
Also, Appendix A indicated H2S Delivery pressure would have a priority of 1 called Safety-
Related Alarm, but other information indicated that H2S high limit in composition would be a
Safety Related Alarm Priority 1 with delivery pressure treated difference as a Critical Alarm A
Priority 2. Because the Safety-Related alarm priority was not the only priority group that must be
accurate and established to support safe operations, it was not clear from Procedure 50.400 how
these types of alarms in Priority 2 would be reviewed.
The operator identified verbally during the inspection and confirmed this information during
follow-up meetings as late as August 2023 that rate-of-change (ROC) alarms exist on certain
points. However, ROC alarms were not described in the Procedure 50.400 nor listed on the
Appendix A: Alarm and Alert priorities table. As a result, it was not clear if these alarms would
be reviewed to support safe pipeline operations or what priority would be relevant.
Finally, Procedure 50.400 defined “Safety-Related Point” in section 3.1.8 as an “input or output
point on the system that when it exceeds allowable levels results in a safety-related alarm or has
the potential to develop into abnormal operations or a safety-related condition. Input points
include pipeline and station inlet and outlet pressures, pressure regulating inlet and outlet
pressures, delivery pressures, calculated line pack values, flow rates, valve operation, fire
detection, gas detection, H2S detection, smoke detection, temperatures associated with the gas
cooling and high filter separator levels. Output points include set points for pressure and turbine
speed control, command for valve control, station isolation and unit shutdowns.” However, not
all of these types of points were clarified as having a priority on Appendix A, such as flow rate
or pack. If this is because alarms are not set on these two types of inputs or as an output, this
should be clarified in the Alarm Management procedure 50.400 as it was not clear why these
were not listed in Appendix A.



Procedure 50.400 and Appendix A require amendment to clearly define how and on what
specific points (including the various priorities) a review is conducted on alarms to ensure
accuracy and the support of safe pipeline operations as required by §§ 192.631(e) and
192.631(e)(1).
5. § 192.631 Control room management.
(a) General.
(1) This section applies to each operator of a pipeline facility with a controller
working in a control room who monitors and controls all or part of a pipeline
facility through a SCADA system. Each operator must have and follow written
control room management procedures that implement the requirements of this
section. . . .
(b) . . . .
(e) Alarm management. Each operator using a SCADA system must have a written
alarm management plan to provide for effective controller response to alarms. An
operator’s plan must include provisions to:
(1) . . . .
(2) Identify at least once each calendar month points affecting safety that have been
taken off scan in the SCADA host, have had alarms inhibited, generated false
alarms, or that have had forced or manual values for periods of time exceeding that
required for associated maintenance or operating activities;
NNG’s Procedure 50.400 entitled “Alarm Management,” was not adequate as it did not clearly
describe how the identification at least once each calendar month will be accomplished for points
that affect safety that have been taken off scan in the SCADA host, had alarms inhibited,
generated false alarms or that have forced or manual values for period of time exceeding that
required for associated maintenance or operator activities as required by §§ 192.631(e) and
192.631(e)(2). Specifically, section 5.4 of Procedure 50.400 stated:
5.4 Reports and analysis will be conducted on a monthly or annual basis as defined below to
demonstrate compliance and measure effectiveness.
• 5.4.1 An alarm/alert review process will be completed at least once each calendar month.
This review will consist of the following:
o 5.4.1.1 Review the number of Safety-Related Alarms that have occurred, been
suppressed, manually overridden, points taken off-scan, shown to be false or had
alarm limits changed and include in the monthly report.
o 5.4.1.1.1 Gas controllers shall include actions taken on all Safety-Related
alarms received in the daily log.
o 5.4.1.1.2 Sequential alarms received during the day due to maintenance
activities can be consolidated in one daily log entry.
o 5.4.1.2 Review the number of Alarms/Alerts that have occurred, been suppressed,
manually overridden, points taken and off-scan to identify excessive
reoccurrences and include in the monthly report.
o 5.4.1.2.1 The top 10 alarms and alerts from each console will be reviewed
monthly to determine the source of the alarm and if limits require



adjustment.
o 5.4.1.3 Review points with frozen data from RTUs, PLCs or SCADA that are not
caused by loss of communications.
o 5.4.1.4 Review RTU communication outages and document the duration and
actions to resolve the outage.
o 5.4.1.5 Parked alarms and alerts will be reviewed on a continuous basis and
addressed as appropriate.
o 5.4.1.6 The manager of gas control or designee shall document and track
deficiencies in EATS and follow up with proper departments to ensure excessive,
nuisance, false, parked, suppressed and manually overridden indications are
addressed in a prompt manner.
Section 195.446(e) requires the operator to have an alarm management plan that will provide for
effective controller response to alarms. As such, controllers are only a part of the Alarm
Management process that will identify what must be reviewed for points that can impact safety
each month as required by 195.446(e)(2) and have deficiencies addressed as required by
195.446(e)(6). The following is not clear from procedures:
1. 2. 3. 4. 5. 6. How the review of calculated points and associated alarming if the point can impact
safety will be included on a monthly basis (such as total flow through a station).
How frozen data (or forced data) at the Remote Terminal Unit (RTU), Programmable
Logic Controller (PLC) or in SCADA will be detected and reported on is not clear.
Controllers are not the only individuals that this could be reported by. For example,
field technicians or SCADA personnel could identify forced data on points that can
impact safety, or automatic programming can identify this information, but it is not
clear in procedures what is being done.
How standing alarms and alerts will be reported on and identified each month when
associated with points that can impact safety was not clear in procedures. While this
is described as a continuous review process, if it is associated with a point that can
impact safety, it would be a point when in alarm is required to be part of the monthly
review and would require addressing.
How points taken off-scan will be identified or reported on. Again, this should not fall
only to the controllers to identify, as SCADA personnel can impact this change and
this may not be evident to the controller.
How the alarm inhibit function will be detected and reported on each month. While
controllers can report on certain aspects of this function, others may also perform this
task, such as SCADA, and this must be identified as well. Suppression may be in
place at the time of the monthly report, and this would not be clearly identified
without a reporting function being established.
How false alarms will be determined was not clear in procedures. While false alarms
may include chattering or nuisance alarms as described in Procedure 50.500, section
5.4.1.2, it is not the only potential source for false alarms. Section 3.1.5 defined a
false alarm. However, it was not clear if controllers receive an alarm from the field
due to maintenance activities, but they were not notified in advance of this activity, if



7. 8. 9. this would result in a false alarm and if so, how this would be included in the monthly
review and addressed as required by section 5.4.1.6.
The process as described in Procedure 50.400 did not include points that can impact
safety that have been in manual for periods of time exceeding that required for
associated maintenance or operating activities. This would include if remote/manual,
hand/off/auto, or remote/local switching can occur in the field on a valve or
compressor such that, if the remote function is removed from the controller (placed in
manual, local, hand, etc.) for periods exceeding associated maintenance or operating
activity requirements as part of the monthly report, and address the identified
deficiencies.
How loss of communication will be determined and reported on.
The process as described in Procedure 50.400 and did not include what specific
reports or data sources will be reviewed as part of the monthly review process, such
as emails being provided when alarm setpoints or limits are moved, alarm/event logs,
RTU communication reports, or daily logs. It also did not clarify what information
will be used as the record to demonstrate this has been sufficiently accomplished each
month.
Procedure 50.400 requires amendments to clarify how the reviews identified in 5.4.1 will be
accomplished, what data sources will be used as inputs for the monthly review process (emails,
specific reports, controller shift logs, alarm/events logs, etc.), and how the output will be
recorded (EATS and Summary files, etc.) to complete the monthly review required by §
192.631(e)(2). Additionally, the amendments need to address how aspects of points taken off-
scan, forced data, alarms inhibited, false alarms, and manual conditions on points affecting safety
will be identified monthly.
6. § 192.631 Control room management.
(a) General.
(1) This section applies to each operator of a pipeline facility with a controller
working in a control room who monitors and controls all or part of a pipeline
facility through a SCADA system. Each operator must have and follow written
control room management procedures that implement the requirements of this
section. . . .
(b) . . . .
(e) Alarm management. Each operator using a SCADA system must have a written
alarm management plan to provide for effective controller response to alarms. An
operator's plan must include provisions to:
(1) . . . .
(3) Verify the correct safety-related alarm set-point values and alarm descriptions at
least once each calendar year, but at intervals not to exceed 15 months;
NNG’s Procedure 50.400 did not adequately define the process used to verify the correct safety-
related alarm set-point values and alarm descriptors at least once each calendar year, but at
intervals not to exceed 15 months as required by § 192.631(e)(3).



Specifically, Procedure 50.400 section 5.4.2 stated:
• 5.4.2 An alarm/alert review process will be completed annually, but at intervals
not to exceed 15 months.
o 5.4.2.1 The review process will consist of verifying the correct Safety-Related Alarm
set point values and descriptions. Additionally, the alarm management procedure will
be reviewed as part of this process to determine effectiveness.
o 5.4.2.2 The annual review process will include an analysis of safety-related points to
ensure continued applicability.
o 5.4.2.3 The annual review process will utilize the Annual Safety-Related Alarm
report and Annual Alarm Management Plan Review Report.
o 5.4.2.4 Remedies to improve alarm or alerts include:
o Optimizing set points
o Addressing chattering or flooding alarm/alerts
o Evaluating priority levels for alarms/alerts
o Determining if an alert should be moved to an alarm
o Determining if an alarm should be moved to an alert
o 5.4.2.5 The manager of gas control or designee shall follow up with proper
departments to ensure deficiencies are addressed in a prompt manner.
During the inspection, NNG verbally explained that the process involved creating a list of the
alarm setpoint values and alarm descriptors per location by the control room with SCADA
assistance. This information was then sent to the various field locations for field personnel to
sign off on the correct alarm setpoint values per point and the alarm descriptors. However, none
of this was described as part of the process in Procedure 50.400, nor were the reports noted in
section 5.4.2.3 included as part of NNG’s Alarm Management procedure. It was not clear that
either one or both reports identified in section 5.4.2.3 were developed using the existing SCADA
system data or a Master Alarm Database separate from the SCADA system. It was also not clear
how changes that have been processed through EATS or as part of other MOC processes would
be confirmed to still be in place for relevant temporary or permanent changes. How verification
of alarm setpoint values and alarm descriptors is performed was not adequately defined in
Procedure 50.400.
Procedure 50.400 requires amendment to describe how the requirements of § 192.631(e)(3) will
be implemented.
7. § 192.631 Control room management.
(a) General.
(1) This section applies to each operator of a pipeline facility with a controller
working in a control room who monitors and controls all or part of a pipeline
facility through a SCADA system. Each operator must have and follow written
control room management procedures that implement the requirements of this
section. . . .
(b) . . . .



(e) Alarm management. Each operator using a SCADA system must have a written
alarm management plan to provide for effective controller response to alarms. An
operator's plan must include provisions to:
(1) . . . .
(5) Monitor the content and volume of general activity being directed to and
required of each controller at least once each calendar year, but at intervals not to
exceed 15 months that will assure controllers have sufficient time to analyze and
react to incoming alarms;
NNG’s Procedure 50.400 was not adequate to assure that controllers have sufficient time to
analyze and react to incoming alarms as required by § 192.631(e)(5). Specifically, Procedure
50.400 section 5.5.2 stated that during the review process the data collected will be analyzed to
determine if the volume of activity processed by the gas controller is at a level that does not
jeopardize the safe operation of NNG facilities. Section 5.5.2.2 stated that NNG will measure the
controller's workload against internally defined Key Performance Indicators (KPIs) to ensure the
controller performance is adequate. However, which specific KPIs will be used has not been
defined. KPIs need to be defined before the analysis is able to be completed and documented.
This is significant to Procedure 50.400 being developed correctly as designed and then
implemented. Also, Procedure 50.400 did not clearly state where KPIs would be recorded and
how these selected KPIs would be used to determine the volume of activity was at a level not to
jeopardize the safe operation of NNG facilities.
Additionally, review of controller workload is required to determine that the controller has
sufficient time to analyze and react to incoming alarms. While KPIs are certainly part of that
answer when selected correctly, without reviewing the time required for controllers to
acknowledge alarms and respond based on priority, the process to confirm controllers have
sufficient time to analyze and react to incoming alarms is incomplete. NNG’s alarm
rationalization process may need to be adjusted and redone if the designed and expected time of
response by priority cannot be achieved by controllers. Adjusting and redoing the alarm
rationalization process was not clearly required in NNG’s procedures.
Finally, how deficiencies associated with this workload analysis will be addressed and recorded
is not adequate as defined in Procedure 50.400 section 5.5.2.1. Section 5.5.2.1 explained:
If the analysis reveals deficiencies, the gas control manager will take steps
necessary to ensure safe operation of facilities by:
• Reducing the volume of phone calls
• Reviewing changes that have been made to the overall operations
• Exploring and implementing automated recordkeeping processes
• Reviewing the need and applicability of alerts
• Requesting staffing additions
• Requesting controller input
• Other actions as identified.
However, it is not clear that “other actions as identified” would include actions such as console
additions, console asset reassignment, or a change to the alarm rationalization process. These



three actions are also types of changes that impact the time for controllers to respond to alarms.
NNG’s procedures need amendment to clarify that these three actions are also possible outcomes
of a workload study.
Procedure 50.400 requires amendment to clarify how NNG will determine that that the volume
of alarms does not jeopardize the safe operation of NNG facilities, to identify the specific KPIs
that will be used, and to clarify that other actions as identified would include at least console
additions, console asset reassignment, and changes to the alarm rationalization process.
8. § 192.631 Control room management.
(a) General.
(1) This section applies to each operator of a pipeline facility with a controller
working in a control room who monitors and controls all or part of a pipeline
facility through a SCADA system. Each operator must have and follow written
control room management procedures that implement the requirements of this
section….
(2) The procedures required by this section must be integrated, as appropriate,
with operating and emergency procedures required by §§192.605 and 192.615. An
operator must develop the procedures no later than August 1, 2011, and must
implement the procedures according to the following schedule. The procedures
required by paragraphs (b), (c)(5), (d)(2) and (d)(3), (f) and (g) of this section must
be implemented no later than October 1, 2011. The procedures required by
paragraphs (c)(1) through (4), (d)(1), (d)(4), and (e) must be implemented no later
than August 1, 2012. The training procedures required by paragraph (h) must be
implemented no later than August 1, 2012, except that any training required by
another paragraph of this section must be implemented no later than the deadline
for that paragraph.
(b) . . . .
(f) Change management. Each operator must assure that changes that could affect
control room operations are coord
- **truncated:** true
- **body characters:** 67069
