Every offshore installation and major hazard facility has safety critical elements — the physical barriers and systems that stand between a hazardous event and a major accident. Knowing what yours are is the starting point. Being able to demonstrate that they are performing to their required standard is what the regulator actually asks for.
For many operators, there is a significant gap between those two positions. The SCE register exists. The performance standards are written. But the ability to show, at any given moment, that every SCE on the asset is performing as required — and to evidence what has been done when it is not — is where the system breaks down.
What a safety critical element is
A safety critical element is any part of an installation whose failure could cause or contribute to a major accident, or whose purpose is to prevent or limit the effect of a major accident. The term is defined in the Offshore Installations (Safety Case) Regulations 2015, but the concept applies equally to onshore major hazard sites under the Control of Major Accident Hazards Regulations 2015.
In practice, SCEs include fire and gas detection systems, emergency shutdown systems, pressure relief devices, blowdown systems, passive fire protection, escape and evacuation systems, and structural elements whose failure could result in loss of containment or collapse. The specific SCE inventory for any installation is defined in the safety case, derived from the major accident hazard identification process.
What matters is not the label but the logic: these are the things that, if they fail at the wrong moment, remove a barrier between normal operations and a catastrophic outcome.
What performance standards require
Each SCE must have a defined performance standard — a statement of what the element must do, under what conditions, to what level of reliability, and how that performance is to be verified. Performance standards are not optional. They are a core requirement of the safety case, and their existence — and the evidence that they are being met — is what a regulator or major hazard inspector will look for.
A performance standard for a fire and gas detection system, for example, will define the detection coverage required, the response time, the availability target, and the testing frequency needed to demonstrate that availability. A performance standard for a pressure relief valve will define the set pressure, the required flow capacity, the inspection interval, and the acceptance criteria for a function test.
The performance standard is only meaningful if it is being actively monitored. A relief valve that was last tested three years ago against a standard that requires annual testing is not performing to its performance standard — regardless of what the register says.
Where SCE management fails in practice
The failure modes for SCE management are consistent across facilities and sectors. They are worth naming precisely because they are so common:
Performance standards exist but are not connected to the maintenance and inspection programme. The required testing frequency is documented, but the work order system does not reference it. Overdue tests are not visible as SCE performance failures — they appear as maintenance backlog.
SCE status is a periodic snapshot rather than a live picture. The SCE register is updated quarterly, or following an audit, rather than reflecting the current state of every element in real time. Between updates, no one has a reliable view of how many SCEs are currently performing below their required standard.
Temporary impairments are not tracked against SCE status. When an SCE is taken out of service for maintenance — a fire detector inhibited, an ESD valve bypassed — the impact on the overall barrier is not assessed or recorded against the SCE record. The safety case assumption of availability is being violated in practice, without anyone having a consolidated view of it.
Findings from verification are not tracked to closure. An independent verification body identifies a gap between actual performance and the performance standard. The finding is recorded. Whether it is closed, and when, is not systematically tracked in a way that gives operations leadership confidence.
Each of these failure modes is individually manageable. In combination, they mean an operator cannot demonstrate — to themselves or to a regulator — that their safety barriers are performing as the safety case assumes.
What good SCE management looks like
Effective SCE management is not more paperwork. It is a live connection between four things that are often managed separately: the SCE register, the performance standards, the maintenance and inspection programme, and the impairment and deviation record.
When those four are connected, an operations manager can see — at any point — which SCEs are currently performing to standard, which have active impairments, which have overdue verification activities, and which have open findings from the last inspection cycle. That picture does not require a manual assembly of information from four different systems. It is visible in one place.
The practical self-assessment for SCE management follows the same logic as the performance standard itself:
- Can you produce a current list of all SCEs on the asset and their performance status within five minutes?
- Are overdue SCE verification activities visible as SCE performance issues, or only as maintenance backlog?
- When an SCE is inhibited or bypassed, is the impact on barrier performance assessed and recorded automatically?
- Do you have a live view of all active SCE impairments, including who authorised them and when they are due for review?
- Can you demonstrate, from your records, that every finding raised against an SCE in the last twelve months has been tracked to formal closure?
If any of those questions require significant effort to answer, the SCE management system is not providing the assurance that the safety case assumes it is.
The regulatory expectation
The Health and Safety Executive's inspection programme for major hazard facilities consistently focuses on SCE management as a leading indicator of overall safety performance. An operator who can demonstrate a live, evidenced view of SCE performance — with impairments controlled, verification activities current, and findings tracked to closure — is demonstrating that the safety case is a living document, not a filing exercise.
An operator who cannot answer basic questions about current SCE status without significant preparation is demonstrating the opposite. That gap is where enforcement attention goes.
How Elisian supports SCE management
Elisian's process safety module connects SCE registers directly to the operational management system — linking performance standards to the inspection and maintenance programme, tracking impairments and deviations against individual SCE records, and providing operations leadership with a live view of barrier performance across the asset.
When an SCE is taken out of service, the impairment is recorded against the element's performance standard. When a verification activity is completed, the result is captured against the SCE record. When a finding is raised, it is tracked in the same system until formal closure is confirmed.
The result is an SCE management system that provides the assurance the safety case requires — not as a periodic snapshot, but continuously. If you want to see how that works in practice for your asset, get in touch with the Elisian team.