Process Safety · 9 min read
Eleven Procedures, No Engineered Barrier: Lessons From the Monaca Furnace Explosion

The CSB’s final report shows why numerous administrative controls cannot replace an engineered safeguard when one valve-selection error can create a catastrophic flow path.
What the CSB established
On 4 June 2025, Furnace 5 at a petrochemical facility in Monaca, Pennsylvania, was being returned to service after its coke trap had been cleaned. The US Chemical Safety Board determined that two motor-operated isolation valves were inadvertently opened at the same time. That combination created an unintended route for flammable cracked gas to flow backward from the quench tower into the furnace firebox, where lit pilots provided an ignition source.
The gas ignited about six minutes later, causing an explosion that ruptured the firebox wall and led to a fire. Fifteen employees evacuated. The CSB reported no serious injuries, an estimated 5,100 pounds of ethylene and combustion products released, and approximately $95 million in property damage. These are findings from the agency’s final report, not preliminary allegations.
Eleven controls can still represent one weak barrier
The hazard analysis had identified cracked-gas backflow as potentially fatal. Yet the CSB found that the operator relied on 11 administrative controls, all dependent on workers and managers taking the correct actions. Counting controls can therefore create false confidence: if every item relies on the same human decision, the system may have many tasks but only one vulnerable barrier type.
Procedures, checking and competence are essential. The lesson is that they should not be the sole defence against a catastrophic state when an inherently safer design or engineered safeguard is reasonably available. The technology licensor had supplied engineered functionality capable of preventing backflow, but it had not been configured to protect the furnace while double isolation was being removed.
Safeguards must work in every operating mode
A protection layer may perform well in steady production and disappear during shutdown, maintenance, testing or recommissioning. Those transitions are not side activities; they are operating modes with their own configurations, hazards and demands. A process hazard analysis should explicitly test whether the required interlocks and permissives remain available in each mode.
Teams should map the combinations of individually legitimate actions that can create an unsafe route. If opening either valve is acceptable in one context but opening both is catastrophic, the control system should prevent, constrain or clearly challenge that combination. Restoration plans should specify the required plant state, the order of change and the evidence needed before moving to the next step.
Human-machine interface design is a barrier decision
The CSB found that one logic screen displayed three nearly identical valves whose tags differed mainly by their final digit. That design increased the opportunity to select the wrong device. A technically accurate display can still be operationally weak if it makes consequence-critical equipment difficult to distinguish under time pressure.
High-hazard commands deserve visual separation, meaningful service descriptions and confirmation based on consequence—not merely a repeated tag number. Where a single selection could create a catastrophic flow path, consider inhibitions, state-based permissives or an independent verification step. Alarm and event displays should also make the resulting plant state understandable before the operator commits the next action.
Competence must match the critical task
The process-control engineer performing the task had not carried it out before and had limited process knowledge. Training records alone do not establish readiness for an unfamiliar, consequence-critical activity. Competence assurance should test whether the person understands the process hazard, the required state, credible error paths and the conditions that demand a pause or escalation.
For first-time or infrequent critical tasks, use deliberate preparation: competent supervision, a field or simulator walk-through, clear roles, independent checking and authority to stop. Procedures should explain why the sequence matters, not simply list clicks. Understanding the hazard gives people a chance to recognise when the plant response does not match the intended operation.
A practical leadership review
Select one catastrophic scenario in your facility and identify the strongest barrier that physically prevents the hazardous state. Then repeat the review for startup, shutdown, maintenance, testing and reinstatement. If the answer becomes a list of instructions and careful actions, the scenario deserves engineering attention.
Ask which simultaneous valve movements or control commands can form an unintended route; whether the HMI makes similar equipment unmistakable; whether an unfamiliar person could be assigned the task; and whether the safeguard remains active when normal isolation is removed. Track engineered improvements to completion rather than allowing temporary administrative measures to become permanent by familiarity.
Sources
- US Chemical Safety Board — Investigation reportsPublished Accessed 17 September 2026
Daily HSSE updates
Subscribe for practical HSSE updates.
Subscribe for the daily message, selected HSSE news and occasional new-resource alerts from Worksite Safety Hub.