When the Formosa Plastics plant in Illiopolis went up, the explanation that stuck was the easiest one on the shelf. An operator opened the wrong thing. Human error. A couple of the headlines said exactly that. It is the conclusion this whole newsletter exists to argue with, so let me show you what is sitting underneath it.

What Happened

On April 23, 2004, an operator at the Formosa Plastics PVC plant went to the wrong reactor and opened the bottom valve on a vessel that was under pressure and mid batch, making polyvinyl chloride. The valve had a pressure interlock that was supposed to stop exactly this. He got around it by disconnecting the actuator air and hooking up the emergency bypass hose, because he thought he was standing at the reactor he had just finished cleaning and figured the valve was stuck. Around 15,000 pounds of vinyl chloride dumped out, flashed from liquid into a flammable vapor cloud, rolled through the operating area, and found an ignition source. The plant exploded.

Five workers were killed and three more were seriously hurt. Around 150 residents were evacuated. The fire burned for two days and the plant never ran again.

So a person did make a mistake. I am not going to pretend otherwise. But if the investigation had stopped there, nobody would have learned the thing that actually keeps this from happening somewhere else.

The Easy Story

Human error is a satisfying place to stop because it closes the file. One person, one bad call, write up some retraining, move on. It feels like an explanation.

What it really is, is a description of what set the thing off. The CSB put it about as plainly as they ever do. One of their root causes is that the company did not adequately address the potential for human error. Another is that it relied on a written procedure to control a hazard with catastrophic consequences. Sit with that for a second. The problem was not that a human made a mistake. It was that the plant had been built and run as though one never would.

What Actually Set It Up

This is the part worth carrying back to your own site.

That reactor was full of vinyl chloride under pressure. Between a routine valve move and a catastrophic release there was exactly one real barrier, and it was a procedure. There was a pressure interlock, but getting around it took an emergency air hose and a supervisor saying yes out loud, and nothing physical stopped a man who skipped the asking. Nobody gave that permission the day it mattered. The last line of defense was somebody remembering to ask somebody else.

And it had nearly happened already. Twice. About a year before, at Formosa's Baton Rouge plant, an operator went to the wrong reactor, opened the bottom valve, and let around 8,000 pounds of vinyl chloride go. Baton Rouge responded by locking the drain valves so it could not happen again. Then, about sixty days before the explosion, it happened at Illiopolis itself. An operator there mistakenly drained an operating reactor to the wrong place. The investigation into that near miss recommended redesigning the system so it could not happen again, with a deadline of April 1, 2004. The redesign was never done. The reactor blew on April 23, three weeks past the date on their own corrective action.

So by the time the Illiopolis operator had his hand on that valve, a lot of other people had already made their decisions. Someone designed a reactor whose interlock came off with an air hose. Someone wrote a bypass that ran on a verbal okay. Someone read the Baton Rouge report and filed it as a Louisiana problem. Someone let their own April 1 redesign deadline slide past. The operator was the last name on a long list.

People always want to know what lit it. It does not really matter, and that is the point. The vapor found an ignition source somewhere between two and five minutes after the release started. Once you put a 15,000 pound flammable cloud into a running plant, something is going to find it, and the clock on that is measured in minutes. Chasing the spark is the wrong question. Not releasing the cloud is the only answer that was ever available.

How They Got Past Human Error

It is worth knowing how the CSB got from an operator opened the wrong valve to everything I just laid out, because the method is the whole difference between a real finding and a blame memo. And none of the tools they used are exotic. Every one of them is already sitting in your shop.

Start with who was asking. The CSB is an independent board. It cannot fine anyone and has no stake in who ends up paying for this. When the people running the investigation have no reason to stop at the operator, they keep going, and most of the job is just being willing to keep going.

First, they reconstructed the sequence from physical evidence. They read the as found state of both reactors. D306 open with the pressure washer still inside, clearly mid clean. D310 with its actuator air lines disconnected and the emergency bypass hose connected. That as found condition is what told them the operator went to the wrong reactor and forced the interlock by hand. No guessing, no leaning on one witness, just what the equipment was doing when it was over.

Then the one that actually cracked it, a human factors analysis. This was one of the four key issues the CSB built the report around, not a soft afterthought. The question was not did the operator err, it was why the plant made that exact error easy. Two near identical reactors side by side, controls that did not clearly tell them apart, and no indication on the lower level of whether the reactor in front of you was live. That is an error trap, and a human factors analysis is the tool that finds it. Skip it and you never get past the operator.

Next they went into the company's own process hazard analyses. Formosa had a 1992 PHA and a 1999 revalidation on the shelf, and here is the part that should bother you. The 1999 PHA had already identified severe consequences for opening the bottom valve on an operating reactor, and the team accepted the interlock plus a procedure as a good enough safeguard. The CSB did not have to discover the hazard. The company had written it down years earlier and signed off on a weak control for it.

Then they sized the safeguards against the hazard. Run it as a layers of protection analysis and the question is simple. How many independent protection layers actually stood between a routine valve move and a loss of containment. The answer was about one, a bypassable interlock gated by a verbal okay, standing in front of a consequence that could kill a crew. One bypassable administrative control is not a layer, it is a coin flip. One of the CSB's own contributing causes says it outright, the company had no written guidelines for matching safeguards with risk. That mismatch is exactly what a LOPA exists to surface before the event, not after.

Last, they treated the history as evidence. Baton Rouge and the February 2004 near miss were pulled into the file on purpose, and the failure to act on either was written up as a management of change and organizational learning failure, not bad luck. The same mistake landing at the same company over and over is the strongest proof you will ever get that the cause lives in the system and not in the man holding the valve.

So the toolkit is plain and it is all yours. Reconstruct the sequence from evidence instead of from the loudest theory. Run a real human factors lens over the task. Trust your PHA enough to act on what it already told you. Count your independent protection layers and check they match the size of the hazard. Treat every near miss, especially one from a sister plant, as a finding. That is the drill, whether the report comes out with a federal seal on the cover or you are running it yourself after something that never left the plant.

The Gap

Most plants have at least one spot where the only thing between a serious hazard and a bad day is a person doing the procedure right every single time. On paper it looks covered. In a real week, with real overtime and real production pressure, it is just a matter of when.

The honest question was never whether someone would eventually get it wrong. Someone will. The question is what your facility does when they do. If the answer is a release, a fire, or a funeral, then what you have is not a safety system. It is a good intention with a procedure stapled to it.

Monday Morning Checklist

  1. Take your three highest consequence scenarios and count the independent protection layers behind each. If a layer turns out to be one operator following one procedure, you do not have a safeguard, you have a single point of failure wearing a safeguard's name.

  2. List every interlock or trip that can be bypassed and look at how the bypass is authorized and tracked. If it runs on a verbal okay instead of a managed bypass under management of change, with a hard control at the point of risk, you have a LOPA gap and an MOC gap in the same spot.

  3. Pull your near misses, especially anything from a sister site or a sister unit, and check whether any got closed as not applicable here. A near identical event elsewhere in your company is the strongest leading indicator you will ever be handed, and acting on it is cheaper than every alternative.

You do not need a PVC reactor for this to land. You need one real hazard whose last layer of protection is a person being perfect.

Before Human Error is a teardown of industrial incidents for EHS and operations leaders. Every issue is built from public investigation findings. If this was useful, forward it to one person who would get something out of it.

Source: U.S. Chemical Safety and Hazard Investigation Board, Investigation Report 2004-10-I-IL, Vinyl Chloride Monomer Explosion, Formosa Plastics Corp., Illiopolis, Illinois, issued March 2007.