Archives of Directives

Current

DOE G 423.1-1B, Implementation Guide for Use in Developing Technical Safety Requirements

Functional areas: Defense Nuclear Facility Safety and Health Requirement, Safety

This Guide provides a complete description of what Technical Safety Requirements should contain and how they should be developed and maintained. This revision of the guide provides new guidance on Technical Safety Requirements for Specific Administrative Controls, incorporates and addresses lessons learned, and makes clarifications and organization changes to improve usability. Supersedes DOE G 423.1-1A.
g423.1-1b.pdf1005.63KB
Version history and related documents
Document text

Text extracted from the attached file. Refer to the original document for the authoritative version.

Section 1

AVAILABLE ONLINE AT: INITIATED BY: www.directives.doe.gov Office of Environment, Health, Safety and Security DOE G 423.1-1B 3-18-2015 IMPLEMENTATION GUIDE FOR USE IN DEVELOPING TECHNICAL SAFETY REQUIREMENTS [This Guide describes acceptable, non-mandatory means for meeting requirements. Guides are not requirements documents and are not to be construed as requirements in any audit or appraisal for compliance with associated rules or directives.] U.S. DEPARTMENT OF ENERGY Office of Environment, Health, Safety and Security NOT MEASUREMENT SENSITIVE http://www.directives.doe.gov/ DOE G 423.1-1B i (and ii) 3-18-2015 FOREWORD This Department of Energy (DOE) Implementation Guide is available for use by all DOE components and contractors. Beneficial comments (recommendations, additions, deletions, and any pertinent data) that may improve this document should be sent to— Mr. Garrett Smith AU-31/GTN U.S. Department of Energy Washington, D.C. 20585 Phone (301) 903-7440 Facsimile (301) 903-6172 DOE Guides are part of the DOE Directives System and are issued to provide guidance and supplemental information regarding the Department’s requirements as contained in rules, Orders, Notices, and regulatory standards. Guides also provide acceptable methods for implementing these requirements. This Guide may be used by all contractors for DOE Hazard Category 1, 2, or 3 nuclear facilities, including contractors for the National Nuclear Security Administration (NNSA). Throughout this document, references to a “contractor” or a “DOE contractor” apply to a contractor for NNSA as well. This Guide was developed in support of Title 10 Code of Federal Regulations (C.F.R.) Part 830, Nuclear Safety Management. This Guide provides a complete description of what Technical Safety Requirements should contain and how they should be developed and maintained. This revision of the guide provides new guidance on Technical Safety Requirements for Specific Administrative Controls, incorporates and addresses lessons learned, and makes clarifications and organization changes to improve usability. This Guide imposes no requirements. DOE G 423.1-1B iii (and iv) 3-18-2015 CONTENTS 1. INTRODUCTION....................................................................................................................1 1.1 Purpose ............................................................................................................................. 1 1.2 Terminology ..................................................................................................................... 1 1.3 Overview .......................................................................................................................... 1 2. APPLICATION........................................................................................................................2 3. BACKGROUND ......................................................................................................................3 4. DEVELOPMENT AND CONTENT OF TECHNICAL SAFETY REQUIREMENTS ...4 4.1 TSR Development - Inputs from the DSA ....................................................................... 4 4.2 Determining the Type of TSR .......................................................................................... 5 4.2.1 Safety Limits ..................................................................................................... 5

Section 2

4.2.2 Limiting Control Settings ................................................................................. 5 4.2.3 Limiting Conditions for Operation ................................................................... 5 4.2.4 Administrative Controls .................................................................................... 6 4.2.5 Design Features ................................................................................................. 6 4.3 TSR Document Organization and Development Guidance ............................................. 6 4.3.1 Front Matter ...................................................................................................... 7 4.3.2 Use and Application .......................................................................................... 7 4.3.3 Safety Limits ..................................................................................................... 9 4.3.4 Operating Limits & Surveillance Requirements ............................................. 10 4.3.5 Administrative Controls .................................................................................. 17 4.3.6 Design Features ............................................................................................... 19 4.3.7 Bases Appendix .............................................................................................. 20 Appendix A. Structure and Format of TSRs.............................................................................. 1 Appendix B. TSR Examples ......................................................................................................... 1 Appendix C. Implementation Verification Reviews (IVRs) ...................................................... 1 Appendix D. Conversion of Technical Specifications and Operational Safety Requirements to Technical Safety Requirements ............................................... 1 DOE G 423.1-1B 1 3-18-2015 1. INTRODUCTION 1.1 Purpose This Guide provides information to assist in the implementation of 10 Code of Federal Regulations (C.F.R.) §830.205, Technical Safety Requirements. More specifically, the Guide provides methods acceptable to the Department of Energy (DOE) for contractors to develop Technical Safety Requirements (TSRs) for Hazard Category 1, 2, and 3 nuclear facilities. The Guide imposes no requirements; however, a contractor following the analytical and drafting methods described below has assurance that compliance with 10 C.F.R. §830.205 is being achieved. The rule specifies in subpart B, App A, G.4, that “DOE Guide 423.X, Implementation Guide for Use in Developing Technical Safety Requirements (TSRs), provides a complete description of what Technical Safety Requirements should contain and how they should be developed and maintained.” Other methods may be used, provided the resulting TSRs meet the requirements of 10 C.F.R. §830.205 and perform their intended purpose of establishing the specific parameters and requisite actions for the safe operation of a nuclear facility. 1.2 Terminology Most terms used in this Guide are defined in 10 C.F.R. Part 830, Nuclear Safety Management, DOE-Standard (STD)-3009-2014, Preparation of Nonreactor Nuclear Facility Documented Safety Analysis, and DOE-STD-1189-2008, Integration of Safety into the Design Process. Terms not defined in these documents will be defined in the text. 1.3 Overview

Section 3

DOE’s approach to ensuring the health and safety of the public with respect to nuclear safety is found in the provisions and appendices of 10 C.F.R. Part 830. Many of the concepts found in this rule are based on regulatory approaches developed by the Atomic Energy Commission and later by the Nuclear Regulatory Commission (NRC). Those familiar with NRC’s safety regulations will note that DOE’s documented safety analysis (DSA) parallels NRC’s safety analysis report. Similarly, DOE’s TSRs parallel NRC’s technical specifications. Analyzing the safety features of an existing nuclear facility or a design for a new nuclear facility begins with development of the DSA. This process is guided by DOE-STD-3009 for DOE nonreactor nuclear facilities and supported by DOE-STD-1189 for new nuclear facilities or major modifications. The hazard and accident analysis guided by these standards identify safety controls/assumptions. The purpose of TSRs is to ensure important operating parameters are maintained within acceptable limits and that safety structures, systems, and components (SSCs) and Administrative Controls (ACs) are available and able to perform their intended safety functions under normal, abnormal, and accident conditions. The four appendices cover special topics. Appendix A provides an acceptable approach to the structure and format of TSRs. Appendix B provides examples of acceptable TSRs. Appendix C addresses the performance of independent Implementation Verification Reviews (IVRs) of safety 2 DOE G 423.1-1B 3-18-2015 basis controls, while Appendix D offers methods for converting older safety requirements, such as technical specifications and operational safety requirements, to TSRs. 2. APPLICATION The information contained in this Guide is intended for use by all Department elements, including the National Nuclear Security Administration (NNSA), and all contractors for DOE- owned or DOE-leased Hazard Category 1, 2, or 3 nuclear facilities or nuclear operations. This Guide provides a format that is effective in highlighting the important features of TSRs. An older format was described in the attachment to DOE 5480.22, Technical Safety Requirements, dated 2-25-92, which was superseded by 10 C.F.R. Part 830. If in place, the older format may be retained, but when the TSRs are significantly modified, the format in this Guide should be considered. This format is based on the NRC Technical Specification Improvement Program (TSIP), and is designed to aid the use of operations information by the operators. However, neither the older format nor the new TSIP format is required. Other guides and formats for the development of TSRs may be used to comply with the requirements of 10 C.F.R. Part 830 Subpart B. This Guide does not apply to:  activities regulated under a license issued by the NRC;  activities regulated by a State under an agreement with the NRC (including activities certified by the NRC under §1701 of the Atomic Energy Act of 1954, 42 USC §2297f);  activities conducted under the authority of the Director, Naval Nuclear Propulsion, pursuant to Executive Order 12344, codified at 50 U.S.C. §§2406, 2511;  transportation activities regulated by the Department of Transportation;  activities conducted under the Nuclear Waste Policy Act of 1982;  any facility identified in §202(5) of the Energy Reorganization Act of 1974 (42 USC §5842); and  activities related to the launch approval and actual launch of nuclear energy systems into

Section 4

space. A contractor for an environmental restoration activity may follow the method in DOE-STD- 1120-98 or successor document, and provisions of 29 C.F.R. §1910.120 or §1926.65 for construction activities (see 10 C.F.R. Part 830, Subpart B, Appendix A, Table 2) to develop specifications for hazard controls rather than TSRs. This option is available when the activity involves either (1) work not done within a permanent structure or (2) decommissioning of a facility with only low-level residual fixed radioactivity. The following documents provide additional information on the development of specifications for safety controls for onsite transportation activities:  DOE Order 460.1C, Packaging and Transportation Safety (2010);  DOE Guide 460.1-1, Implementation Guide for Use with DOE O 460.1A, Packaging and Transportation Safety (1997); and  DOE Order 461.2, Onsite Packaging and Transfer of Materials of National Security Interest (2010). DOE G 423.1-1B 3 3-18-2015 3. BACKGROUND DOE’s nuclear safety rule “requires the contractor responsible for a DOE nuclear facility to analyze the facility, the work to be performed, and the associated hazards and to identify the conditions, safe boundaries, and hazard controls necessary to protect workers, the public and the environment from adverse consequences. These analyses and hazard controls constitute the safety basis upon which the contractor and DOE rely to conclude that the facility can be operated safely” (10 C.F.R. Part 830, Appendix A, Section B). The first major step in establishing the safety basis of a nuclear facility is the drafting of a DSA. This document gathers together the information and analyses to be relied upon by DOE in authorizing the operation of any nuclear facility within the scope of the rule. DSAs (including Transportation Safety Documents) define the performance capabilities of SSCs, and personnel, and are aimed at confirming the ability of the SSCs, and personnel to perform their intended safety function under normal, abnormal, accident, and anticipated failure conditions. The approved DSA provides the analytical basis for developing and selecting limiting parameters to be set forth in TSRs, the subject of this Guide. TSRs can be viewed as a distillation of the DSA’s analytical results for the required performance of safety related SSCs and ACs. TSRs set forth the minimum acceptable limits for operations under normal and specified failure conditions and establish maintenance and surveillance requirements (SRs). In accordance with 10 C.F.R. Part 830, all TSRs written by operating contractors, and proposed changes thereto, must be reviewed and approved by DOE before nuclear operations can commence. Typically, Chapter 5 of a facility’s DSA identifies needed TSRs and their technical basis. Subsection 5.5, “TSR Derivation,” is intended to provide a link between the safety analysis and the list of variables, SSCs, and ACs that are necessary to ensure safety. In some cases, the DSA may not supply all of the technical details necessary for the development of a TSR. This situation may apply in areas such as maintenance and surveillance frequencies and compensatory measures for systems out of service. In such cases, national and international codes, standards, and guides should be used if available. Where no code, standard, or guide is applicable, other documents such as reliability analyses, instrumentation/equipment uncertainty

Section 5

analyses, failure modes and effects analyses, manufacturer documentation, and data based on operating history may be used, along with engineering judgment. The DSA, TSRs, facility-specific commitments, and the safety evaluation report (SER) constitute the nuclear safety basis and facility authorization from DOE for the contractor to operate Hazard Category 1, 2, and 3 nuclear facilities. Following approval of the DSA, TSR, and issuance of the SER, the nuclear safety basis must be fully and effectively implemented prior to the start of nuclear operations in accordance with 10 C.F.R. Part 830. An IVR should be conducted to assure the full and effective implementation. Appendix C is a recommended approach for the conduct of the IVR. 4 DOE G 423.1-1B 3-18-2015 4. DEVELOPMENT AND CONTENT OF TECHNICAL SAFETY REQUIREMENTS TSR development begins with the DSA, which identifies those parameters and SSCs that are to be controlled to ensure the safety requirements for the facility are met. An individual control may be governed by several different types of TSR, depending on the consequences associated with loss of the control. Low consequences may be dealt with by an AC, while high consequences may demand the use of an engineered control. The selection principles to be used are stated in Table 4 of Appendix A to 10 C.F.R. Part 830, Subpart B. The output of the TSR development process is a set of TSRs for significant controls relied upon in the DSA. As required by 10 C.F.R. §830.205(a)(2), this set of TSRs must be submitted by the contractor to DOE for review and approval prior to use. During operations, any violation of a TSR must be reported to DOE [10 C.F.R. §830.205(a)(3)]. 4.1 TSR Development - Inputs from the DSA TSR development begins with compiling a list of controls identified in a given DSA that require TSR coverage. For DSAs prepared in accordance with 10 C.F.R. §830.204 using an acceptable methodology such as DOE-STD-3009, the list of controls should include all DSA commitments to provide TSRs for ACs and safety-class and safety-significant SSCs. The following information from the DSA provides useful inputs in developing TSRs:  Specific safety functions called out (e.g., functional requirements and associated performance criteria);  Implicit analytical assumptions;  SSC interfaces and conditions that define operability;  Key physical parameters (e.g., temperature, pressure, or distance);  Assumptions or parameters that define inspection requirements;  Facility description, including process and activity descriptions (DSA Chapter 2);  Hazard analysis tables (DSA Chapter 3);  Hazard analysis discussion of events with significant potential for uncontrolled release of radioactive or other hazardous material or energy, and the controls available to prevent or mitigate such events (DSA Chapter 3);  Hazard analysis discussion of the events identified as presenting a significant hazard to workers and the controls available to prevent or mitigate such events (DSA Chapter 3);  Accident analysis of the events that challenge offsite evaluation guidelines, and the controls available to prevent or mitigate such events (DSA Chapter 3);  Safety SSC descriptions (DSA Chapter 4); and  TSR derivation description (DSA Chapter 5). 4.2 Determining the Type of TSR Once the items to be included in the TSRs are specified, it is necessary to determine the TSR type appropriate for each item.

Section 6

DOE G 423.1-1B 5 3-18-2015 The specified types of TSRs are:  Safety Limits  Operating limits, subdivided into o Limiting Control Settings o Limiting Conditions for Operation  Administrative Controls (including Programmatic and Specific Administrative Controls (SACs))  Design Features TSR preparers should select the TSR type most appropriate for the item under consideration using the subsequent guidance below. Once the TSR type for each relevant control is selected, TSRs should be written following the format offered in Appendix A of this Guide. 4.2.1 Safety Limits Safety limits are defined as follows in 10 C.F.R. §830.3: “Safety limits means the limits on process variables associated with those safety class physical barriers, generally passive, that are necessary for the intended facility function and that are required to guard against the uncontrolled release of radioactive materials.” 4.2.2 Limiting Control Settings Limiting control settings (LCSs) are the “settings on safety systems that control process variables to prevent exceeding a safety limit” (10 C.F.R. §830.3). LCSs of instruments that monitor process variables are the settings at which protective devices actuate or alarms sound to alert facility personnel. An LCS includes specification of actions required when the limiting setting is exceeded. Assignment of an LCS also requires defining associated SRs that ensure continuous functioning of SSCs measuring the limiting setting or carrying out associated actions. 4.2.3 Limiting Conditions for Operation Limiting Conditions for Operation (LCOs) are the limits “that represent the lowest functional capability or performance level of safety structures, systems, and components required for safe operations (10 C.F.R. §830.3).” They delineate the minimum conditions necessary to ensure that the initial conditions assumed in the analysis remain intact and operability of an SSC is verified or the conditions of a SAC are met. LCOs include specific actions to be taken if minimum conditions are not met and define associated SRs. LCOs are specifically intended to cover safety SSCs and SACs identified in the DSA. Such SSCs might include, for example, a ventilation system providing negative pressure, fire detection and suppression systems, and criticality alarm systems. Such systems prevent or mitigate hazards to the worker, the public and the environment. Significant passive SSCs, such as a rated, sealed fire wall, may be covered by LCOs if they are explicitly relied upon in the DSA to mitigate a design basis event. In other cases, passive SSCs may be controlled as TSR Design Features. 6 DOE G 423.1-1B 3-18-2015 4.2.4 Administrative Controls ACs are “provisions relating to organization and management, procedures, record-keeping, assessment, and reporting necessary to ensure safe operation of a facility” (10 C.F.R. §830.3). Two types of ACs are used in nuclear facilities. The first type, termed a SAC, covers a single item of sufficient importance to be called out individually. When the DSA states that a SAC is relied on for safety, it should be the subject of a TSR. Guidance on the development and use of SACs is provided in DOE-STD-1186-2004, Specific Administrative Controls. The second type of control, termed a programmatic administrative control, or AC, commits the facility operator to establish, maintain, and implement one or more elements of a safety

Section 7

management program (SMP). Programmatic ACs frequently apply to safety programs such as radiation protection, criticality safety, fire protection, emergency preparedness, hazardous material safety, quality assurance, maintenance, and inventory control. ACs supporting effective safety administration covers generic topics such as facility procedures, contractor organization and management, safety reviews and audits, record-keeping, operating support, minimum staffing, facility staff qualification and training, and TSR violations. In some situations, the DSA may identify a SAC to implement the function of what otherwise would be an active SSC. This approach can be taken when flexibility in implementation is desired or when the SSC naturally falls under an area of routine programmatic supervision. Using a SAC as an expedient alternative to an engineered control should, however, be avoided. SACs may be acceptable for ensuring safe operation in some cases, but they generally do not have the same level of reliability associated with an Engineered Control. 4.2.5 Design Features Design Features (DF) are “the design features of a nuclear facility specified in the Technical Safety Requirements, that, if altered or modified, would have a significant effect on safe operation (10 C.F.R. §830.3).” DFs are normally passive characteristics of the facility, not subject to significant alteration by operations personnel, which accomplish their function without a change of state. Examples include shielding, structural walls, relative locations of major components, installed poisons, and special material. 4.3 TSR Document Organization and Development Guidance A TSR document should have the following major sections:  Front Matter  Use and Application (Section 1)  Safety Limits (Section 2)  Operating Limits and Surveillance Requirements (Sections 3/4)  Administrative Controls (Section 5)  Design Features (Section 6)  Bases Appendix DOE G 423.1-1B 7 3-18-2015 The content and guidance for development of each of these major sections is discussed below. See Appendix A for structure and format details. 4.3.1 Front Matter The front matter section of a facility TSR should consist of the following parts: (1) Title page (with appropriate document classification) (2) List of affected pages (3) Table of contents (4) List of tables and figures (5) List of acronyms, abbreviations, and symbols (6) Record of changes The lists for tables, figures, and acronyms may not be required if none are contained in the body of the TSR document. The list of tables or figures is a simple three-column list with the first column being the unique figure or table number, the second column being the description or title, and the last column showing the page number where the item can be found. Changes to the TSRs may be indicated by:  a list of pages in effect with page number and date;  a record of revision pages;  sidebar changes in the TSR text; and  page number, document number, and the revision number. The acronym list should be as short as possible. An acronym should be used only where the term is repeated a number of times. Definitions of acronyms in the list should be verified to match the precise meaning of the terms as used in the TSR. 4.3.2 Use and Application The Use and Application Section provides: The basic instructions for applying the safety restrictions contained in a technical safety

Section 8

requirement. The use and application section includes definitions of terms, operating modes, logical connectors, completion times, and frequency notations. (Table 4, 10 C.F.R. Part 830, Subpart B, Appendix A) The Use and Application section is placed first to provide the ground rules for use of the TSR before presenting any requirements. This section will contain essential information for understanding the rest of the TSR. It should reference the DSA as necessary but should not be a tutorial on the entire facility. 8 DOE G 423.1-1B 3-18-2015 This section of the TSR will be subdivided into subsections based on the complexity and nature of the TSR document itself. This section should include the following subsections:  Definitions of Terms  Operating Modes  Logical Connectors  Completion Times  Frequency Notations Definition of Terms The list of definitions should be alphabetically arranged in tabular form. When used in the TSR document, these terms should appear in all uppercase when the precise definition provided in the definition section is intended. The list of definitions should contain the more frequently encountered definitions found in TSRs. TSRs should be carefully reviewed to ensure that terms are used in a manner consistent with the definitions list. Terms used in the TSR that are in common parlance should not be listed. Operating Modes Operating Modes in the DSA represent the facility SSC configurations that preserve safety in different phases, or modes, of facility operations. Mode distinctions are determined by differences in process parameters or needed safety controls and equipment for different operational states. Examples of mode definitions are found in Appendix A. The example modes show the operational distinctions that can be made. In the “safest mode,” certain TSR requirements may not apply. For example, a TSR may apply only when specific operations are under way, and thus does not apply when these operations are shut down. However, for some nuclear facilities it may not be possible to define a mode where TSRs do not apply, as the hazard is always present. In that case, the safest mode is that which minimizes risk. In general, requirements applicable in a given mode are required for all actions or conditions represented by this mode. The TSR writer should ensure that the mode requirements are in alignment with how the specific LCO control is credited in the DSA. For example, if a fire protection system is credited whenever material-at-risk (MAR) is within the nuclear facility, the LCO for the fire protection system should be applicable in all modes in which MAR is present. Logical Connectors Logical connectors are used in TSRs to discriminate between, and yet connect, conditions, required actions, completion times, surveillance, and frequency periods. Completion Times Completion Time is the amount of time allowed for completing a required action. It might be, for example, the time interval allowed for carrying out compensatory measures or restoration activities when an Action Statement has been entered. DOE G 423.1-1B 9 3-18-2015 Frequency Notation The “Specified Frequency” typically consists of (a) requirements of the frequency column of each surveillance requirement, and (b) any notes in the surveillance requirement column modifying performance requirements. Sometimes special situations dictate when the SRs are to

Section 9

be met, as when an event triggers the need for a surveillance action. These special situations should be stated in the TSR document. Examples of frequency notations are found in Appendix A. 4.3.3 Safety Limits Appendix A to Subpart B of 10 C.F.R. Part 830 describes DOE expectations for safety limits as follows: The limits on process variables associated with those safety class physical barriers, generally passive, that are necessary for the intended facility function and that are required to guard against the uncontrolled release of radioactive materials. The safety limit section describes, as precisely as possible, the parameters being limited, states the limit in measurable units (pressure, temperature, flow, etc.), and indicates the applicability of the limit. The safety limit section also describes the actions to be taken in the event that the safety limit is exceeded. These actions should first place the facility in the safest], [most] stable condition attainable, including total shutdown (except where such action might reduce the margin of safety) or should verify that the facility already is safe and stable and will remain so. The technical safety requirement should state that the contractor must obtain DOE authorization to restart the nuclear facility following a violation of a safety limit. The safety limit section also establishes the steps and time limits to correct the out-of-specification condition. Safety Limits control important process variables to prevent the uncontrolled release of radioactive materials. Reactor Facilities. Typical reactor limits of importance and possible candidates for SLs are those placed on primary coolant system pressure, primary coolant system temperature, and reactor power. For reactors without closed primary coolant systems (such as pool-type reactors), or with primary coolant systems that operate at essentially atmospheric pressure, the main candidates for SLs would be maximum reactor power and water temperatures. Generally, containment or/confinement systems should not be considered as barriers that require SLs because they are mitigative in nature. However, these systems should be considered in the development of LCOs because they typically provide important defense-in-depth or worker safety protective features. For reactors, typically these barriers are considered to be the fuel cladding and primary coolant system, including piping and pressure vessels. LCSs for reactors should include reactor trip system instrumentation set points. Reactor trip set-point limits should be selected to provide sufficient margin between the trip set point and the SL. This margin will ensure that the core and the reactor coolant system do not exceed SLs during normal operations and anticipated operational occurrences 10 DOE G 423.1-1B 3-18-2015 Nonreactor Nuclear Facilities. Possible candidates for safety limits are specific barriers, preventing the accident or accidents for which maintaining the integrity of the barrier is necessary to protect public health and safety. Limits of importance for nonreactor nuclear facilities tend to be facility-specific, though often may relate to physical variables such as pressure and temperature. LCSs define the settings on safety systems that will ensure process variables remain within applicable SLs. For all facilities, LCSs should be chosen so that there is adequate time after exceeding a normal setting to correct the abnormal situation, automatically or manually, before

Section 10

an SL is exceeded. When developing TSR limiting values or set points based on the DSA, the TSR developer should bear in mind that values in the DSA are generally the exact values at which something is assumed to happen. Because the values and set points in the TSR are measured and hence have some margin of error, TSR set points should be chosen on the conservative side of the DSA assumptions. The adjustments should account for calibration uncertainty, instrumentation uncertainty during operation and accident conditions, and instrument drift. The DSA and TSR developer, if not the same person, should work together to ensure that the DSA Hazard Analysis and Accident Analysis are preserved through compliance with the TSR. 4.3.4 Operating Limits & Surveillance Requirements When developing TSR limiting values or set points based on the DSA, the TSR developer should bear in mind that values in the DSA are generally the exact values at which something is assumed to happen. Because the values and set points in the TSR are measured and hence have some margin of error, TSR set points should be chosen on the conservative side of the DSA assumptions. The adjustments should account for calibration uncertainty, instrumentation uncertainty during operation and accident conditions, and instrument drift. The DSA and TSR developer, if not the same person, should work together to ensure that the DSA Hazard Analysis and Accident Analysis are preserved through compliance with the TSR. 4.3.4.1 Operating Limits Appendix A to Subpart B of 10 C.F.R. Part 830 describes DOE expectations for operating limits as follows: Those limits which are required to ensure the safe operation of a nuclear facility. The operating limits section may include subsections on limiting control settings and limiting conditions for operation. DOE’s TSRs might not contain a separate section titled “Operating Limits.” TSRs are typically written in a format that combines Operating Limits as LCS/LCOs in Section 3 with SRs in Section 4 in the facility’s TSR document followed by the number and name associated with the group that yields LCS/SR and LCO/SR in Sections 3/4.x. LCS/LCOs define the limits that represent the lowest functional capability or performance level of safety SSCs or SAC required to perform an activity safely. SRs verify whether or not the minimum operability requirements of LCS/LCO-required safety equipment or parameters are satisfied. DOE G 423.1-1B 11 3-18-2015 4.3.4.2 Limiting Control Settings Appendix A to Subpart B of 10 C.F.R. Part 830 describes DOE expectations for limiting control settings as follows: The settings on safety systems that control process variables to prevent exceeding a safety limit. The limited control settings section normally contains the settings for automatic alarms and for the automatic or nonautomatic initiation of protective actions related to those variables associated with the function of safety class structures, systems, or components if the safety analysis shows that they are relied upon to mitigate or prevent an accident. The limited control settings section also identifies the protective actions to be taken at the specific settings chosen in order to correct a situation automatically or manually such that the related safety limit is not exceeded. Protective actions may include maintaining the variables within the requirements and repairing the automatic device promptly or shutting

Section 11

down the affected part of the process and, if required, the entire facility. At a minimum, each individual LCS should contain a LCS statement, a mode applicability statement, action statements, and SRs. LCSs should be based on, and specified in terms of, these three rules: Rule 1: Compliance with an LCS is required in the modes specified. Rule 2: Upon discovery that the instrumentation or interlock set point is less conservative than the required LCSs, the associated action should require that it be restored or adjusted to meet the LCS. Other actions should be specified (e.g., the time allowed, out of service, for resetting, test, maintenance, repair, or calibration.) Rule 3: If an automatic safety system is not operable as specified, appropriate action should be described in the action statement to compensate. In the case of reactors, that action may take the form of a reactor shutdown and/or engineered safety feature initiation or adjustment. In the case on nonreactor nuclear facilities such action might be manual process shutdown or process adjustment. 4.3.4.3 Limiting Conditions for Operation Appendix A to Subpart B of 10 C.F.R. Part 830 describes DOE expectations for limiting conditions for operation as follows: The limits that represent the lowest functional capability or performance level of safety structures, systems, and components required to perform an activity safely. The limiting conditions for operation section describes, as precisely as possible, the lowest functional capability or performance level of equipment required for continued safe operation of the facility. The limiting conditions for operation section also state the action to be taken to address a condition not meeting the limiting conditions for operation section. Normally this simply provides for the 12 DOE G 423.1-1B 3-18-2015 adverse condition being corrected in a certain time frame and for further action if this is impossible. Any safety-class SSC providing a credited safety function in the DSA for an assumed accident or transient sequence should be included in the LCOs. Each LCO should be established at a level that will ensure the process variable is not less conservative during actual operation than was assumed in the safety analyses. LCOs should also cover SSCs that either provide support for or actuate a system credited in the DSA. SSCs that support the safety function of another SSC may be covered by separate LCOs if that approach simplifies implementation. A common example of separate coverage is an emergency diesel generator providing backup electrical power to a credited ventilation system. LCOs should be written in a user-friendly manner to assist an operator faced with adverse, stressful conditions. The LCO should communicate quickly and effectively the information needed by the operator to assess and properly respond to off-normal and accident conditions. The operator should be able to grasp quickly from looking at the LCO (a) what operating parameters/ conditions represent the lowest functional capability or performance for a specified required Limiting Condition, (b) how to measure or determine whether that parameter condition is met, and (c) what to do if a Limiting Condition is not met. The following are good practices in LCO development: (1) The TSR developer should consult with facility engineers and operating staff in the development of an LCO to ensure ease of implementation.

Section 12

(2) Area applicability should be defined so that the LCO is only required for the facility areas for which it is credited. The TSR developer should consider whether subdivision of an area might ease implementation. (3) The LCO should only be specified for limited processes if the accidents for which the control is credited applies only to certain processes. (4) If the LCO is mode-specific, the conditions that must be maintained in those modes should be specified. For conditions that vary by mode, a separate LCO should be written for each mode. Placing the facility in a mode where the LCO is not applicable is always an option to consider. Once action is taken to enter a mode where the LCO is not required, the facility has exited the LCO. (5) Multiple parameters grouped under one SR should be avoided, as it may be unclear which action to enter if the SR is not met. Parameters specified to be met must be measurable or readily determinable. Actions should be specified that are reasonable to perform within the required time specified. The TSR developer should also consider the conditions under which surveillances or actions need to be performed. Under normal conditions it might be reasonable to expect an operator to climb a ladder to shut a roof vent within 20 minutes. This action might be dangerous or impossible under actual fire conditions. DOE G 423.1-1B 13 3-18-2015 (6) One aid to LCO usability is to minimize the number of different conditions of operability. TSR developers sometimes minimize the total number of LCOs at the expense of individual LCO simplicity. One to three conditions are usually considered ideal for the user. When the number of conditions approaches or exceeds about six, the operator has difficulty grasping the entire LCO and it begins to become unwieldy. When the LCO becomes this complex, splitting it into two or more LCOs should be considered. Conditions could be split among systems/ subsystems, grouped by similar required actions or surveillances, or grouped by area. Conditions must always be grouped by mode such that all conditions apply to all modes specified in the applicability. If there are different requirements for different modes a separate LCO should be specified for each mode. (7) Another way to simplify conditions is consolidation. This technique may be useful when all the conditions are the same except for one parameter such as MAR limits. In this case, a single condition can be specified with reference to a “look-up” table. This table should be placed directly below the condition or within the body of the TSR itself. Placing this table in the bases should be avoided and it should never reference an external document. 4.3.4.4 LCS/LCO Statement LCS/LCO specification statements should be concise. The objective is to distill a clear, precise statement or specification of operability. Examples of such concise statements are as follows:  The criticality alarm system shall be OPERABLE with two detection channels and an alarm set point for each detector set at less than or equal to 100 mR/hr.  The exhaust ventilation system shall be OPERABLE with two exhaust fans maintaining flow greater than or equal to 2,500 cfm and two HEPA filter banks each with a removal efficiency greater than or equal to 99.9% for 0.3 micron particles or greater. The LCS/LCO specification statement typically focuses on the most important SSCs and

Section 13

parameters; therefore, it may not be necessary to list all subcomponents. The list provided in the SRs demonstrates compliance with the LCS/LCO statement, except where key support SSCs have been assigned their own individual LCS/LCO. In some cases, concise LCS/LCO specification statements may lead to multiple LCSs/LCOs for the same equipment and modes. This is an acceptable outcome. 4.3.4.5 Action Statements Action statements should describe the actions to be taken in the event that an LCO is not met. An action statement should establish the steps and agreed upon time limits to correct the condition or conditions that are beyond the TSR’s limits. Action statements fall into three general categories:  Restorative: The action statement might provide that a certain adverse condition must be corrected in a certain time frame and that further action must be taken if corrective action cannot be taken in a stated amount of time. For example, if an LCO requires two pumps 14 DOE G 423.1-1B 3-18-2015 to be operable at all times when in the “normal operations” mode, the action statement might require that if one pump is inoperable, it must be made operable in X hours or operations must cease within the following Y hours. If both pumps became inoperable, the action statement would likely require cessation of operations and restoration of at least one pump within Z hours and the second pump within W hours.  Eliminative: This type of action places the facility in a mode or condition in which the DSA credited safety function is no longer required. If such a mode or condition is not practical, the facility or operation may be placed in a condition that reduces the probability of occurrence of the accident for which the safety function is credited in the DSA, for a limited period of time.  Compensatory: This type of action replaces the lost safety function with another device or a manual action that substitutes for the unavailable safety function. [Note: An action statement to merely develop a plan for corrective action is typically not sufficient because resolution of the condition is not accomplished until plan completion. Typically, an action statement to develop a plan would either require regulatory approval or be preceded by an action to either change modes or transition to a safer condition.] An action statement should provide a clear, logical method to reach a safe and stable state. However, in complex facilities care must be taken to ensure that an action statement does not inadvertently decrease safety. Occasionally, it may be necessary for an action statement to specify transition through an operating mode even though required safety equipment would be inoperable for the transitional state. The general LCOs are used to provide additional actions when conditions or SRs are not met. 4.3.4.6 Operability Operability embodies the principle that an SSC can perform its credited safety function(s) as described in the DSA. This principle extends the requirements of an LCO for those SSCs that directly perform a specified safety function (supported systems) to those that perform a required support function (support systems). Operability applies only to SSCs. These general principles of operability should be followed in generating LCOs:  An SSC is considered operable as long as its associated SRs are completed satisfactorily within the specified timeframe.  An SSC can perform its specified safety function(s) only when all of its necessary

Section 14

support systems are capable of performing their related support functions.  When all SSCs designed to perform a certain safety function are not capable of performing that safety function, a loss of function condition exists. When an SSC is determined to be incapable of performing its intended safety function(s), the declaration of inoperability should be immediate. DOE G 423.1-1B 15 3-18-2015 4.3.4.7 Completion Times The format of an action statement consists of a condition statement, required actions, and completion times. Every required action in an operating limit (LCS/LCO) has a defined associated completion time. The completion time is the amount of time allowed for completing a required action. When developing TSRs, the safety importance of the lost safety function of the LCS/LCO and the risk of continued operations while the condition is not met (as described in the DSA) are important considerations in determining a proper completion time, with the most important required actions or highest operating risk conditions having the shorter completion times. The technical rationale for selecting a certain completion time should be provided in the bases. Completion times should be specified in a manner that is either predefined or easily understood; for example, use of “7 days” versus use of “1 week”. In establishing completion times in the TSR, caution should be exercised to prevent inadvertent continuous operation by alternating back and forth between conditions in an action statement without restoration of the system to meet the operating limit. Completion times begin at the time of declaration. When an LCO is intentionally entered for maintenance or surveillance, the completion time is sometimes referred to as the allowable outage time (AOT). Required actions and their associated completion times should be written to accommodate the maintenance or surveillances which are anticipated to compromise or degrade a systems capability to meet the conditions of the operating limit. The AOT of any support system should ensure the minimum functional operating requirements for the supported system and should not be longer than the allowable outage time of any of its supported systems. 4.3.4.8 Surveillance Requirements Appendix A to Subpart B of 10 C.F.R. Part 830 describes DOE expectations for SRs as follows: Requirements relating to test, calibration, or inspection to assure that the necessary operability and quality of safety structures, systems, and components is maintained; that facility operation is within safety limits; and that limiting control settings and limiting conditions for operation are met. If a required surveillance is not successfully completed, the contractor is expected to assume the systems or components involved are inoperable and take the actions defined by the technical safety requirement until the systems or components can be shown to be operable. If, however, a required surveillance is not performed within its required frequency, the contractor is allowed to perform the surveillance within 24 hours or the original frequency, whichever is smaller, and confirm operability. SRs are used to ensure operability or availability of the safety SSCs and SACs identified in the Operating Limits. SRs are most often used with LCS/LCOs to periodically validate the operability of SSCs that are subject to a limiting condition. SRs consist of short descriptions of the type of surveillance required and the required frequency

Section 15

of performance. These statements should identify those requirements needed to ensure 16 DOE G 423.1-1B 3-18-2015 compliance with the related OLs. Failure to perform a surveillance within the required time interval, or failure of the SSC to meet acceptance criteria during surveillance tests, require that the SSC be declared inoperable. The TSR writer should consider developing general SRs that corresponded to the general LCOs (see Appendix B, Figures 6a and 6b, for examples). Upon discovery of a missed surveillance test, a grace period such as 24 hours or the time limit of the specified surveillance frequency, whichever is less, may be allowed to complete the surveillance before taking the required action of the LCO. Such grace periods should be stated explicitly or may be stated generically in the Use and Applications section of the TSR document. There may be process systems for which it is not acceptable to apply the concept of a grace period because failing to perform the surveillance or maintenance places the system in a state requiring immediate corrective action. 4.3.4.9 Surveillance Requirement Statements SR statements consist of definitions of the type of surveillance required to verify operability of SSCs. Examples are as follows:  Verify that the pressure in Room 27A is a minimum of 0.05 inch WG lower than the outside atmospheric pressure.  Perform a channel functional test on each criticality alarm system detector using an external radiation source. The total collection of SR statements associated with a given LCS/LCO should (a) confirm operability of required SSCs, and (b) maintain facility operations within LCS/ LCOs operating parameters. 4.3.4.10 Surveillance Requirement Frequencies SR frequencies are direct statements of the time interval in which the surveillance must be performed. One-word statements such as weekly, monthly, quarterly, or annually, or specific time interval statements (12 hours, 24 hours, 7 days, 30 days, etc.) are preferred. The interval can be based on specific DSA assumptions, national and international codes, standards, and guides, reliability analyses, failure modes and effects analyses, instrumentation/equipment uncertainty analyses, manufacturer documentation, information from operating history, or engineering judgment. 4.3.5 Administrative Controls Appendix A to Subpart B of 10 C.F.R. Part 830 describes DOE expectations for ACs as follows: Organization and management, procedures, record-keeping, assessment, and reporting necessary to ensure safe operation of a facility consistent with the technical safety requirement. In general, the administrative controls section addresses (1) the requirements associated with administrative controls, (including those for reporting violations of the technical safety requirement); (2) the staffing requirements for facility positions important to safe conduct of the facility; and (3) the commitments to the safety management programs identified in the DOE G 423.1-1B 17 3-18-2015 documented safety analysis as necessary components of the safety basis for the facility. ACs can be “programmatic” or “specific.” Programmatic controls describe safety management programs that are assumed in the DSA to be functional and properly maintained. SACs, identify requirements explicitly credited in safety analysis. In general, the ACs should document all those administrative functions that are required to meet facility safety criteria as identified in the DSA,

Section 16

including commitments to safety management programs. ACs may include reporting deviations from TSRs, staffing requirements for facility positions important to safe operation of the facility, and commitments to safety management programs important to worker safety. Efforts should be made to use engineered SSCs whenever possible for controlling the likelihood and consequences of accidents. ACs should be considered as defense in depth measures rather than as primary or redundant controls. While ACs may be acceptable for ensuring some aspects of safe operation, their generally lower reliability, compared with engineered controls, should be weighed when choosing safety measures for long-term hazardous activities. Human actions, taken either in response to an event or taken proactively to establish desired conditions, are subject to errors of omission or commission. Sets of ACs are prone to common cause failure. The following attributes can increase human reliability:  use of reader/worker/checker systems;  independent verification;  positive feedback systems;  human factor analysis;  operator training and certification;  continuing training and requalification;  abnormal event response drills;  ergonomic considerations in procedures; and  conduct of operations. When invoking ACs for control of accident scenarios, the preceding attributes, appropriate to the consequences of the accidents they are intended to prevent, should be considered. 4.3.5.1 Programmatic Administrative Controls A programmatic AC represents commitments to establish, implement, and maintain a safety management program. Safety management programs that might be covered by an AC include quality assurance, procedures, maintenance, training, conduct of operations, emergency preparedness, fire protection, waste management, and radiological protection. ACs supporting effective safety administration cover generic topics such as facility procedures, contractor organization and management, safety reviews and audits, record-keeping, operating support, facility staff qualification and training, and TSR violations. The cumulative effect of these safety management programs is recognized as being important to overall facility safety. For each safety management program, the DSA may specify key elements that: (1) are specifically assumed to function for mitigated scenarios in the hazard evaluation, but not designated an SAC; or, (2) are 18 DOE G 423.1-1B 3-18-2015 not specifically assumed to function for mitigated scenarios, but are recognized by facility management as an important capability warranting special emphasis. A TSR violation may be declared when a safety management program fails to a degree that renders the DSA summary invalid. Where safety management programs or key elements are relied on to ensure a safety function required by the safety analysis, it is important to capture this information in the TSR document as appropriate. Programmatic ACs typically begin with the phrase, “A program shall be established, implemented, and maintained to ensure that…” For example: A radiation protection program shall be established, implemented, and maintained to ensure that radiation exposure to employees, subcontractors, visitors, and members of the general public is controlled in accordance with requirements of 10 C.F.R. Part 835. Specifying key elements does not automatically convert those elements to SACs. Note that active

Section 17

SSCs are sometimes assigned to ACs as well. This can be done for non safety-class or safety significant SSCs when flexibility in implementation is desired or when the SSC naturally falls under an area of routine programmatic supervision. 4.3.5.2 Specific Administrative Controls A SAC is identified in the DSA as an AC needed to prevent or mitigate an accident scenario. DOE-STD-1186 defines a SAC as an AC “that provides a specific preventive or mitigative function for accident scenarios identified in the DSA where the safety function has importance similar to, or the same as, the safety function of a safety SSC (e.g., discrete operator actions, combustible loading program limits, hazardous material limits protecting hazard analyses or facility categorization).” SACs can be presented in the TSRs in either of two formats: LCO/SR or Directive Action. LCO/SR format should be used when the SAC is well-defined, clear corrective actions are available, and supporting conditions can be easily verified. Guidance for an SSC-related LCO/SR provided in Section 4.3.4 is applicable to an SAC written in LCO/SR format. LCO/SR format may be more appropriate and preferred for a SAC if:  A clear distinction between when a SAC is met or not met.  Specific surveillances are required.  The actions to respond to an inoperable condition must be clearly spelled out.  What constitutes a TSR violation for an LCO is better defined than for an AC. Directive Action SAC format is used when it is essential that the SAC be performed when called upon every time and without delay. A violation of a Directive Action SAC is an immediate TSR violation. DOE-STD-1186-2004 provides additional guidance and expectations for SACs. [Note: For Hazard Category 3 facilities, TSRs may consist solely of an inventory limit to maintain the Hazard Category 3 classification and other ACs that provide appropriate commitments to safety programs.] DOE G 423.1-1B 19 3-18-2015 An example SAC: “TRU waste containers shall not be stacked more than two levels high, and the bottom of the second level shall be stored no more than 4 feet above ground.” 4.3.5.3 Violation of Technical Safety Requirements Appendix A to Subpart B of 10 C.F.R. Part 830 describes DOE expectations for the ACs section to address requirements for reporting violations of the TSRs.” Violations of a TSR occur as a result of the following four circumstances:  Exceeding an SL.  Failure to complete an action statement within the required time limit following exceeding an LCS or failure to comply with an LCO.  Failure to perform a surveillance within the required time limit.  Failure to comply with an AC statement. The following are two examples of “failure to comply with an LCO:” (1) an operation is performed that is prohibited by the mode the facility is in, and (2) a safety system is rendered incapable of performing its safety function (e.g., by maintenance) without entering the applicable LCO. There are two types of violations of “failure to comply with an AC statement:” (1) any single instance of a failure to comply with a requirement in a directive action SAC, and (2) a failure to meet the intent of a referenced safety management program that is significant enough to render the DSA summary invalid. 4.3.6 Design Features Appendix A to Subpart B of 10 C.F.R. Part 830 describes DOE expectations for Design Features as follows: Design features of the facility that, if altered or modified, would have a significant

Section 18

effect on safe operation. Design Features (DFs) specify the inherent characteristics or qualities of an object or component required to protect the validity of the DSA accident analysis. DFs may be intrinsic characteristics—such as enrichment, neutron absorption, fire rating, and load capacity—or physical characteristics such as siting, berms, and fueling locations. DFs are normally passive attributes of the facility not subject to significant alteration by operations personnel. Examples of passive attributes include shielding, structural walls, relative locations of major components, installed reactivity poisons, or special materials. The DF section captures those permanently built-in features critical to safety that do not require, or infrequently require, maintenance or surveillance. The attributes of the passive DFs that are important in the DSA should be described completely. Active safety features that are controlled by other types of TSRs should not be included in the DF section. 20 DOE G 423.1-1B 3-18-2015 Methods necessary to ensure DF are available as credited should be identified. Some DFs have the potential to be degraded by the effects of aging. Surveillance requirements for DFs are typically located in programs such as configuration management or in-service inspections (ISIs). It is appropriate to consider inclusion or reference to applicable ISIs for DFs in section 6 of the TSR. 4.3.7 Bases Appendix Appendix A to Subpart B of 10 C.F.R. Part 830 describes DOE expectations for the Bases Appendix as follows: The reasons for the safety limits, operating limits, and associated surveillance requirements in the technical safety requirements. The statements for each limit or requirement shows how the numeric value, the condition, or the surveillance fulfills the purpose derived from the safety documentation. The primary purpose for describing the basis of each limit or requirement is to ensure that any future changes to the limit or requirement is done with full knowledge of the original intent or purpose of the limit or requirement. Although Part 830 requires that a basis be provided only for “safety limits, operating limits, and associated surveillance requirements,” the technical basis for other aspects of TSRs such as Design Features and SACs may be provided when practical. The bases appendix provides summary statements of the reasons for the selection of each specific SL, OL, and SR. The bases appendix should summarize and reference any more specific analyses related to the TSRs and their derivation. The bases should (a) describe the credited safety functions in the DSA that each safety system or SAC provides, (b) identify what is included in each safety system or SAC, (c) identify all requirements relevant to the safety basis that has been selected, and (d) identify specific information from the DSA used in the derivation of individual TSRs. The level of detail in the descriptions should be sufficient for the operations staff to confirm that the system is operable or that a SAC is met. The bases appendix can conceptually be divided into seven areas: background, application to safety analysis, SLs and OLs, mode applicability, Action Statements, SRs, and references:  Background. Discuss in a general way the function of each system, component or SAC. Include relevant major components, schematics , operational aspects, unique features, and general design features. Limits protected by the requirement, and the consequences of

Section 19

exceeding the limits should be discussed. This section should also cross-reference related or similar requirements.  Application to Safety Analysis. Discuss the evaluations included in the safety analysis from which the requirement has been derived, including: o applicable accident or transient; o major input assumptions of the safety analysis; o relationship of this TSR to the accepted consequence of the analysis; and DOE G 423.1-1B 21 3-18-2015 o basis of each SL or OL, including any allowances or margins of safety specified in the DSA.  SL or OL. For SLs, identify in the DSA the specific barrier protected by the SL and the accident or accidents for which maintaining the integrity of the barrier is necessary to protect public health and safety. For LCSs or LCOs, explain why the requirement is suitable. Discuss how it was determined to be the minimum functional capability or performance level for that system or component to ensure safe operation of the facility. Discuss any other relevant facets of the LCS or LCO, such as conditions required, numbers of components required, parameter requirements, exceptions or notes, and implications of LCS or LCO violations.  Mode Applicability. Present information on expected and distinguishable operational conditions suitable to be considered in separate modes.  Action Statement. For each action statement: o Explain why the actions should be taken and why continued operation is acceptable if the LCS/LCO is not met; o Address the level of protection provided, the probability of an event occurring during the period covered, and how the required actions compensate for LCS/LCO deviations; o Explain the technical basis for completion times; o Describe why mode changes are required; o Discuss how all required actions for an LCS/LCO relate to each other; and o Explain the source of all numerical values such as completion times, parameter values, and component requirements.  Surveillance Requirement. For each SR: o Discuss how the surveillance demonstrates operability of the LCS/LCO requirements; o Discuss how the surveillance verifies the LCS/LCO requirements; this discussion should establish a one-to-one correspondence between each SR and LCS/LCO; o Explain why the SR is necessary at the frequency specified; and o Provide justification for surveillance test frequencies and parameter values, using engineering judgment, vendor information, or probabilistic risk assessment..  References. In all sections of the Bases, identify the applicable DSA section, applicable reports, and relevant codes and standards. It is good practice to provide a list of documents where more detailed information pertinent to the TSRs can be found. For any reference cites, consider providing the full title, date, and revision number. DOE G 423.1-1B Appendix A 3-18-2015 A-1 Appendix A. Structure and Format of TSRs This section provides guidance on the recommended structure and format of TSRs. Section 1 presents a suggested organization to meet the requirements of the TSR rule and provides details to assist in unifying the TSR document. Section 2 delineates the suggested content for each of the TSR sections. 1. Organization 1.1 Front Matter Front matter should consist of the following parts. Note: all figures referred to below are found in Appendix B.  Title page. The title page should include, at a minimum, the name of the facility, the

Section 20

facility location, the words “Technical Safety Requirements,” and the name of the responsible contractor.  Table of Contents. The table of contents should list every item in the volume.  Tables. A list of tables should be included.  Figures. A list of figures should be included.  Acronyms. A list of acronyms, abbreviations, and symbols should be compiled and included. An acronym, abbreviation or symbol should not be created for a name or term used only a few times in the document. When a short form reference is to be used, it should be defined on first use by means of parentheses. Thereafter, the short form of the name or term should be used. 1.2 Arrangement of Sections The main body should include the following sections in the order indicated.  Section 1—Use and Application  Section 2—Safety Limits  Section 3/4—Limiting Control Settings, Limiting Conditions for Operation, and Surveillance Requirements. Section 3 covers LCS and LCO operational limits, Section 4 covers surveillance requirements. These three TSR aspects are presented together to show the interconnections among them. The three-column format retains the same LCO and LCS number for related SRs  Section 5—Administrative Controls  Section 6—Design Features 1.3 Appendices Appendices appear last in the TSR document and are identified by letter. Appendix A contains the TSR bases. Appendix A DOE G 423.1-1B A-2 3-18-2015 2. Content The recommended content for each section of the TSR is described in the following paragraphs. 2.1 Section 1 - Use and Application This section should contain basic information and instructions for using and applying the TSR. The following elements should be addressed under separate headings. 1. Definitions. Provide an alphabetical list of terms used throughout the TSR and their corresponding definitions (see Figure 3). Include a note on the first page of the list stating that defined terms appear in uppercase type throughout the TSR. 2. Operational Modes (Reactors). In the interest of uniformity, the operational conditions or modes listed below are preferred and an attempt should be made to fit each reactor facility into this scheme. If, however, a reactor facility cannot be made to fit, modes may be defined as needed, provided the definition is clearly written with definite lines of demarcation between modes. The number of modes should be held to a minimum. The number of modes should be established based upon the minimum number required to be able to distinguish between different facility conditions and to ensure the provision of an adequate level of safety while in each condition. Define operational modes for reactor facilities, for example:  Operation Mode. To be in operation mode, the reactor is critical and may be at any power level up to and including maximum allowed power.  Start-up Mode. To be in start-up mode, the reactor will begin in a subcritical state and be intentionally made to increase reactivity in a controlled manner to achieve a critical condition and to increase flux in an exponential manner until a low power is reached. Specific low power values are usually associated with the onset of measurable heat.  Standby Mode. To be in standby mode, the reactor is subcritical, but capable of operation without substantial administrative or mechanical actions. Keff limits or other limits needed to define the mode should be included.  Shutdown Mode. To be in shutdown mode, the reactor is significantly subcritical and

Section 21

capable of operation only after completing substantial administrative and/or mechanical actions. Normally, this would be a procedure or series of procedures (such as multiple system valve lineups) that should be performed, but it could be mechanical or electrical repairs, calibration, or other activity. The Keff values should normally be included, unless they are of no use for a particular reactor, in which case control rod positions or other appropriate means should be defined for “significantly subcritical.” (This is to be understood to refer to reactor shutdown, not facility shutdown.) DOE G 423.1-1B Appendix A 3-18-2015 A-3  Refueling Mode. To be in the refueling mode, the reactor vessel integrity is breached (in all non-accident conditions), or any core alterations including fuel rods, control rods, targets, or other vessel internals are occurring or have occurred. Normally this mode requires major mechanical and associated administrative steps be completed before operation is possible. Submodes may be created and defined as needed by reactor facilities. The definitions should be clearly written with numerical or other definite demarcation between submodes. The number of submodes should be limited as much as possible to avoid complexity and potential confusion. Normally, the definition of the modes in a TSR document will be a summary of the definitions above with whatever additional information is needed for a particular reactor. 3. Operational Modes (Nonreactor Nuclear Facilities). Modes may be defined as needed, provided the definitions are clear and there are definite lines of demarcation between modes (such as a numerical value of pressure, temperature, or flow). The number of modes should be established based on the minimum number required to distinguish between different facility conditions as dictated by required equipment operability and needed parameter limits. If a mode is not used in the LCOs (except for the safest mode) or if it doesn’t have different equipment or parameter limits specified from other modes, then it shouldn’t be a mode. Define the operational modes for nonreactor nuclear facilities, for example:  Operation Mode. The mission of the facility or its current campaign being performed.  Start-up Mode. The facility is operating in a transient state from shutdown or near shutdown to reach conditions in which the mission or campaign is performed. This mode is only prescribed for facilities where the start-up procedures are complex and important to nuclear safety.  Shutdown Mode. The facility is not performing its mission or its current campaign, and is incapable of doing so in its present condition. (This is to be understood to refer to a process state and not a facility shutdown.)  Standby. The facility is not operating but retains its inventory of hazardous material.  Repair Mode. The facility is not able to perform its mission in its current condition. Submodes may be created and defined as needed for nonreactor nuclear facility TSRs. The definitions should be clearly written with numerical or other definite demarcation between submodes. The number of submodes should be limited as much as possible to avoid complexity and potential confusion. Appendix A DOE G 423.1-1B A-4 3-18-2015 5. Frequency Notation. The frequency notations, as used in the surveillances and elsewhere, should be defined as follows when included in the TSR, for example. Notation Minimum Frequency

Section 22

(periodicity notation) S Every shift At least once every 12 hours D W Daily Weekly At least once every 24 hours At least once every 7 days M Monthly At least once every 31 days Q Quarterly At least once every 92 days S/A Semiannually At least once every 184 days A Annually At least once every 365 days C Campaign Before start-up of each campaign R Refueling Before entering standby or operation modes after reactor refueling S/U Start-up Before each start-up N/A Not applicable Not applicable 2.2 Section 2 - Safety Limits SLs should describe as precisely as possible the process variables or the parameters being limited, and state the limit in measurable units such as degrees, gallons per minute, or psi. (See Figures 4a and 4b for examples of SLs.) In general, SLs should be monitored continuously. SLs should be based on and specified in terms of these three rules: Rule 1: Exceeding an SL is a TSR violation for each applicable mode. Upon exceeding an SL, the following steps should be taken: 1. The affected parameter should be immediately brought within the SL. 2. The facility should be placed in the most stable, safe condition attainable, including shutdown if appropriate. 3. Reactors should be shut down immediately - (e.g. scrammed). DOE G 423.1-1B Appendix A 3-18-2015 A-5 4. Nonreactor nuclear facilities should be placed in the most stable, safe condition attainable, including shutdown if appropriate. The TSR should specify actions to be taken. 5. All other action requirements should be met. Rule 2: Each SL should have a mode applicability statement. This statement identifies the modes or other conditions for which the SL is applicable. Rule 3: Action statements should describe the actions to be taken in the event that the SL is not met. In regard to Rule 3, specified actions should:  place the facility in a safe, stable condition and verify that this condition has been achieved;  establish the steps and time limits to correct the out-of-specification condition; and  bring the affected parameter immediately within the SL and should affect a shutdown of the facility, within a justified facility-specific time frame, normally less than an hour. Other actions required after exceeding an SL, including reporting the event and evaluating possible damage, may be included in the action statement or may be placed in Section 5, “Administrative Controls,” with a suitable cross-reference. A statement prohibiting restart of operations until DOE approval is received should be included in the action statement of each SL and in Section 5 of the TSR. 2.3 Sections 3/4 - Limiting Control Settings, Limiting Conditions for Operations, and Surveillance Requirements 1 This section contains LCSs, LCOs, and SRs. Mode and location applicability statements and action statements should also be included for each LCO or LCS, as appropriate. Limiting Control Settings. LCSs should describe, as precisely as possible (a) the parameter or process variable being controlled or equipment being actuated and (b) the limiting settings of control devices. This information may be presented in tabular or graphic form, with necessary written information placed in the body of the requirement. The LCS or an associated LCO should specify the allowed out-of-service time permitted when testing, resetting, repairing, or maintaining trip devices, and similarly specify the allowed outage time for associated equipment

Section 23

that must be removed from service for these activities. LCSs should be based on these three rules: Rule 1: Compliance with an LCS is required in the modes specified. 1 Section 3 delineates LCS and LCO operational limits. Section 4 describes SRs. There is usually a one-to-one correlation between LCS and LCO operational limits and the surveillances related to them. The combined TSR section is designated Section 3/4. Appendix A DOE G 423.1-1B A-6 3-18-2015 Rule 2: Upon discovery that the instrumentation or interlock set point is less conservative than the required LCSs, the associated action should require that it be reset. Other requirements such as allowable outage times should be specified. Rule 3: If an automatic safety system is not operable as specified, the action statement should describe the appropriate action to restore the affected system to an operable condition as well as compensatory measures while the automatic safety system is out of service. The LCS should specify the allowed out-of-service time permitted when testing, resetting, repairing, or maintaining trip devices and similarly the time permitted for associated equipment to be removed from service for these activities. Figure 5 provides an example of a LCS. Limiting Conditions for Operation. The LCO statement should describe, as precisely as possible, the lowest functional capability or performance level of equipment required for safe operation of the facility. Each separate limiting condition should have an LCO with associated mode applicability, action statements, and SRs. This part should contain the requirements for how LCOs should be applied. LCOs should be based on and specified according to three rules. Rule 1: Compliance with an LCO is required in the modes specified. Rule 2: The LCO should include an AOT to attempt restoration of operability. Rule 3: Upon failure to meet an LCO, the associated action requirement must be met. In addition to these rules, the following guidance should be considered. Applicability Statements. For each LCS and LCO, the applicability statement should list the modes or conditions for which the LCS or LCO is applicable. Action Statements. An action statement should describe the actions to be taken in the event that an LCS is exceeded or an LCO statement is not met. Action statements should include the AOT to attempt to restore operability. Whenever possible, action statements should be divided into separate sections, each describing a single deviated condition requiring operator action. This format simplifies the explanation of the expected action and better ensures that the action will be performed correctly. Completion times for each action should be stated in simple units of time such as minutes or hours. Use the term “OPERABLE” to describe the corrected condition or part of the system without deviation. (While “inoperable” is presented in lowercase letters, operable is presented in uppercase letters.) Keep wording in action statements as brief as possible. Be consistent in the use of verbs and tense. Use the same wording structure when specifying requirements. Do not use articles unless necessary for clarity. When a mode change is required by an action statement, it is preferable to use the actual title of the modes (i.e., rather than numerical designation of modes) to avoid a misunderstanding or a typographical error that could cause the operator to take

Section 24

inappropriate action. Action statements should cover all reasonably expected combinations of DOE G 423.1-1B Appendix A 3-18-2015 A-7 operable and inoperable components in the systems described. Generic LCOs can cover the conditions not called out in individual action statements. Surveillance Requirements. SR statements are descriptions of the type of surveillance required and its frequency of performance. These should identify those requirements needed to ensure compliance with the LCS or LCO. SRs are requirements relating to test, calibration, or inspection that ensure the necessary operability and availability of safety-related SSCs. Surveillance should be based on the following three rules: Rule 1: SRs must be met for all safety-related SSCs for the facility to be considered operable. Rule 2: Each SR should be performed at the specified frequency, with a maximum extension of 25 percent of the interval between any two consecutive surveillances. (This extension is intended to provide operational flexibility both for scheduling and for performing surveillances. It should not be relied upon as a routine extension of the specified interval.) Rule 3: Special test exceptions to TSRs may be allowed under controlled conditions. These test exceptions should be placed in Section 3 (LCO). Any test exception should explain which LCOs are affected, for how long, and what compensatory measures (such as enhanced supervision) will be taken. 2.3.1 Section 5 - Administrative Controls This section imposes administrative requirements necessary to ensure TSR compliance. The paragraphs that follow discuss some of the ACs that should be placed in this section. Contractor Responsibility. The facility or plant manager is responsible for overall operation of the nuclear facility and should delegate in writing the succession to this responsibility during his or her absence. The shift supervisor is responsible for the local command function. During any absence of the shift supervisor from the area, a designated, qualified individual should be assigned the command function. Contractor Organization. On-site and off-site organizations should be described for facility operation and contractor management. The on-site and off-site organizations should be described in terms of the lines of authority, responsibility, and communication for the highest management levels through intermediate levels to and including all operating organization positions. The individuals who train the operating staff and those who carry out health physics and quality assurance functions may report to the appropriate on-site manager; however, they should have sufficient organizational freedom to ensure their independence from operating pressures. Procedures. Operations procedures should provide sufficient direction to ensure that the facility is operated within its approved design basis. Topics that should be considered for coverage include:  Operating procedures for all modes of operations,  Emergency Operating Procedures,  Maintenance Requirements, Appendix A DOE G 423.1-1B A-8 3-18-2015  Required surveillances,  Emergency plans,  Fire protection,  Safety Management Program Implementation procedures; and  Administration. A system should be developed to control all procedures related to TSR compliance. The system should include mechanisms for review, approval, revision, control, and temporary changes to the procedures. The TSRs refer to the control system adopted.

Section 25

Programs. Programs developed to ensure the safe operation of the facility should be discussed and committed to by reference. Such programs should include (1) in-service inspection of components, pumps, and valves as per ASME Boiler and Pressure Vessel Code Section XI, (2) worker protection (such as radiation protection), (3) process control, (4) ventilation filter testing, (5) explosive gas and storage tank radioactivity monitoring, (6) radiological effluent control, (7) quality assurance, (8) criticality safety, (9) configuration control, and (10) document control. The basic elements of these programs should be described in this section, but the details and implementing processes for each program should be placed in separate controlled volumes and are not to be included in the TSR. Minimum Operations Shift Complement. This section of the ACs should state the maximum daily working hours and maximum number of consecutive days on duty. The required total staffing of operating shifts for nonreactor nuclear facilities, and the members of the shift staff required to be present in the control room or control area for different operating conditions, should be specified based on the safety analysis. Operating Support. A list of facility support personnel by name, title, and work and home telephone number must be kept up to date. The list should include management, radiation safety, and technical support personnel. The list should be referenced in the TSR and made readily accessible to operating personnel. Facility Staff Qualifications and Training. Minimum qualifications for members of the facility staff in positions affecting safety should conform to the requirements of DOE Order 426.2 or successor document. These requirements should be referenced in the AC section. Record-keeping. Records need to be kept of all information supporting the implementation of the TSR. To this end, a records retention program should be established that determines which records are to be kept, in what format, for how long, and under what storage requirements. Reviews and Audits. This section describes the methods used to conduct independent reviews and audits. Methods may include creating an organizational unit, a standing or ad hoc committee, or assigned individuals capable of conducting these reviews and audits. Individual reviewers should not review their own work or work for which they have direct responsibility. Regardless of the method used, management should specify the functions, organizational arrangement, responsibilities, appropriate qualifications, and reporting requirements of each functional element or unit that contributes to these processes. DOE G 423.1-1B Appendix A 3-18-2015 A-9 Reviews and audits of activities affecting facility safety have two distinct elements. The first of these is the review performed by facility personnel to ensure that day-to-day activities are conducted in a safe manner consistent with the TSRs. The second is the review and audit of activities and programs affecting nuclear safety performed independently of the facility staff. Facility staff reviews should include: TSR changes, USQ determinations, proposed tests and experiments, procedures, programs, facility changes and modifications, facility operation, maintenance, and testing; DOE and industry issues of safety significance; and any other safety- related items. Reviews by the independent safety organization should include these same items and in addition:

Section 26

conformance with TSRs, violations of codes, orders, and procedures that have safety and health significance, Occurrence Reports, staff training, qualifications and performance, quality assurance program adherence, unanticipated deficiencies of SSCs that could affect nuclear safety, significant, unplanned radiological or toxic material releases, and significant operating abnormalities. (For additional guidance on performing independent Implementation Verification Reviews of TSRs, see Appendix C.) TSR Violations. This section defines what constitutes a TSR violation and associated reporting requirements. See Figure 10 in Appendix B for an example. 2.3.2 Section 6—Design Features The purpose of a design features section is to describe in detail features not covered elsewhere in the TSRs that, if altered or degraded, would have a significant effect on safety. The following two areas should be addressed in this section: (1) Significant passive safety SSCs such as piping, vessels, supports, structures (such as confinement), and containers, and (2) configuration or physical arrangement of SSCs. For each design feature covered, the discussion should address the specific parameters being controlled and the technical basis for the importance of these parameters. One example might be the need to maintain the configuration and physical separation of stored materials to avert a criticality event. [Note: Surveillance requirements for DFs are typically located in programs such as configuration management or in-service inspections (ISIs). In many cases it is appropriate to include or reference ISIs for design features in section 6 of the TSR.] 2.3.3 Bases Appendix This appendix provides technical reasoning behind the SLs, LCSs, LCOs, and SRs. The bases show how the numeric values, conditions, surveillances, and action statements fulfill the purpose derived from the safety documentation. The primary purposes for describing the bases of each requirement are to (a) ensure that future changes to the requirement will not adversely affect its original intent or purpose, and (b) aid in understanding why the requirement exists. The bases appendix should reference relevant sections of the safety analyses. Appendix A DOE G 423.1-1B A-10 3-18-2015 2.4 Format The TSR document must be usable by the operations staff and at the same time understandable by DOE and contractor managers charged with review responsibilities. To meet both of these objectives, a suggested format is provided in the following sections. This standardized format should minimize the burden on oversight organizations and make any necessary training of operations staff easier. DOE recognizes, however, that wholesale changes in TSR documentation for the sake of consistency may be costly and produce no balancing safety benefit. Thus, DOE will approve TSRs in other formats if the contractor provides adequate justification and the requirements of 10 C.F.R. Part 830 are met. In particular, the three-column format provides an advantage in terms of clarity for the operator and is strongly suggested (but not required) for those facilities with complex operations and many safety or operational limits. 2.4.1 Numbering of Pages, Sections, Tables, and Figures Page Numbering. All page numbers should be centered at the bottom of the page. The following paragraphs describe the page numbering schemes for individual sections of the TSR.

Section 27

 Front Matter Pages. Number the front matter pages with successive lowercase Roman numerals (i, ii, iii, etc.).  Section Pages (except Sections 2 and 3/4). All section page numbers, except for Sections 2 and 3/4, should have two parts: an Arabic number for the section, followed by a dash, and an Arabic number designating the numerical page number within the section. For example, pages in Section 1 would be numbered 1-1, 1-2, 1-3, etc.; likewise, pages in Section 5 would be numbered 5-1, 5-2, 5-3, etc.  Sections 2 and 3/4 Pages. Sections 2 and 3/4 are subdivided into numerous subsections corresponding to the individual requirement numbers. The first part of each page number for Sections 2 or 3/4 should, therefore, correspond to the subsection number. This subsection number should be followed by a dash and an Arabic number designating the numerical page number within the subsection (e.g., 2.1.1-1, 3/4.1-1).  Appendix Pages. Number all pages of appendices, except for the bases appendix, with an alphanumeric number consisting of the appendix letter and the sequential page number separated by a dash.  Bases Appendix Pages. All page numbers for the bases appendix should begin with the word “Bases” followed by the section number for the particular section the basis supports (see examples below). o Bases 2.1-1, Bases 2.1-2, … o Bases 3/4.0-1, Bases 3/4.0-2, … o Bases 3/4.1-1, Bases 3/4.1-2, … Paragraph Numbering for Sections 1, 5, and 6. Paragraphs should be numbered hierarchically with successive Arabic numerals separated by decimal points. The following scheme should be used for subordination of paragraphs. DOE G 423.1-1B Appendix A 3-18-2015 A-11  1.1 Major Paragraph  1.1.1 First Subordinate Paragraph  1.1.1.1 First Subdivision of First Subordinate Paragraph  1.2 Second Major Paragraph Numbering for Sections 2 and 3 (Safety Limits, Limiting Control Settings, and Limiting Conditions for Operation). All SLs, LCSs, and LCOs should begin with either 2 or 3, then the number associated with the group, which will be followed by the number of the requirement, per the following examples. (Complex systems may require further subdivision.)  2.11 Reactor Coolant Circulation System  3.10.2.1 Diesel Generator Fuel Oil Tank o Number SLs beginning with 2.1 and continuing with 2.2, 2.3, etc. Any subdivision of SLs should be numbered with an additional number added to the number of the SL; for example, 2.1.1, 2.1.2, etc. o Number OLs beginning with 3.1 and continuing with 3.2, 3.3, etc. Any subdivisions of OLs should be numbered with an additional number added to the number of the LCS (e.g., 3.2.2, 3.2.3, 3.2.4). OLs should be grouped by principal system or function and each OL within a group should be numbered sequentially. LCSs are normally the first requirements within a group. For reactors, normally all OLs can be put into the following groups:  Reactivity Control  Core Power Distribution  Instrumentation  Coolant System  Safety Systems  Confinement/Containment  Plant Systems  Electrical Systems  Experiment Facilities  Rad Waste Systems  Special Tests  Refueling Requirements  Spent Fuel Pool Requirements For less complex reactor facilities, omit any inappropriate groups above, but retain the same numbering scheme to indicate that a group was omitted. Add other groups as necessary. For nonreactor nuclear facilities, standardized grouping of requirements is more difficult because

Section 28

of the diversity of facilities; however, many facilities will have the following.  Criticality, Radioactivity, and Hazardous Material Alarm Systems Appendix A DOE G 423.1-1B A-12 3-18-2015  Confinement/Ventilation  Fire Detection and Suppression  Emergency Power  Chemical Systems  Instrumentation  Experimental Facilities o For less complex nonreactor facilities, omit any inappropriate groups above, but retain the same numbering scheme to indicate that a group was omitted. Add other groups as necessary. o Action statements should be lettered with uppercase letters. Subdivisions of action statements should be numbered 1, 2, 3, etc. Numbering for Section 4 (Surveillance Requirements). SRs should be designated with numbers beginning with 4. The second number should correspond to the grouping scheme used for the LCS or the LCO, and the third number in the sequence indicates the LCS or the LCO that this surveillance principally supports. Hence, the SRs will have numbers the same as the LCS or the LCO that they support except for the first number, which will be a “4” instead of a “3.” Subdivisions should be identified with a lowercase letter and indented; further subdivisions should be labeled consecutively with a number enclosed in parentheses [e.g., (1), (2)] and should be indented from the letter. Numbering Bases (Bases Appendix). Bases are numbered in accordance with the number of the SL, LCS, or LCO that they support. Numbering Tables. All tables should be located as close as possible after the place where they are first referenced. Where tables and figures are both referenced in a specification, present the tables before the figures. Table numbers in Sections 2 and 3/4 should begin with the number of the specification to which they apply, followed by a dash, and then sequential Arabic numerals. Example Table Numbers for Section 3/4 Table 3.3.1-1. Title Table 4.2.5-1. Title Numbers of tables in the bases appendices should begin with the words “Bases Table” and the subsection number that they support, followed by a dash and then sequential Arabic numbers. Example Table Numbers for Bases Appendix Bases Table 3/4.1-1. Title Bases Table 3/4.2-1. Title Table numbers in all other sections should begin with the applicable section number followed by a dash and then sequential Arabic numbers. DOE G 423.1-1B Appendix A 3-18-2015 A-13 Example Table Numbers for Sections Other Than Bases and Sections 2 and 3/4 Table 5-1. Title, (Sheet 1 of 6) Table 5-2. Title For multiple-page tables in all sections, use the phrase (Sheet 1 of __, Sheet 2 of __, etc.) after the table title (see example above). Numbering Figures. All figures should be located as near as possible after the place where they are first referenced. Figure numbers in Sections 2 and 3/4 should begin with the number of the requirement to which they apply, followed by a dash, then sequential Arabic numbers. Example Figure Numbers for Section 3/4 Figure 2.1.1-1. Title Figure 3/4.2.1-1. Title Figure 3/4.2.5-1. Title Figure numbers in the bases appendixes should begin with the words “Bases Figure” and the subsection number that they support, followed by a dash and then sequential Arabic numbers. Example Figure Numbers for Bases Appendix Bases Figure 2.1-1. Title. Bases Figure 3/4.2-1. Title. Figure numbers in all other sections should begin with the applicable section number followed by a dash and then sequential Arabic numbers. For multiple-page figures in all sections, use the

Section 29

phrase (Sheet 1 of __, Sheet 2 of __, etc.) after the figure title. Example Figure Numbers for Sections Other Than Sections 2 and 3/4 and Appendix Figure 5-1. Title, (Sheet 1 of 6). Figure 5-2. Title. 2.4.2 Page Headings Use uppercase letters in the page headings for consistency and to set the headings apart from the body text. Separate the heading information from the body of the requirement by a solid horizontal line across the entire page. Appendix A DOE G 423.1-1B A-14 3-18-2015 Example 1. 3/4.4 REACTOR COOLANT SYSTEM 3.4.2 PRESSURE PROTECTION SET POINTS Example 2. 3/4.6 CONFINEMENT SYSTEMS 3.6.2 AIR CLEANING SYSTEM 2.4.3 Continuation Pages Use the word “continued” in parentheses and in lowercase letters to denote continuation of a grouping of action statements, surveillances, or bases to the next page. Example 3. 3/4.6 CONFINEMENT SYSTEMS 4.6.1 SURVEILLANCE REQUIREMENTS (continued) 2.4.4 Highlighting Various forms of highlighting may be used to improve visibility of the information presented. These include the following. Bolding. Bold type may be used to highlight the major headings, table column headings, and to emphasize especially important information. Notes can also be in bold type for added emphasis. Spatial Dedication. The SL, LCS, and LCO requirements may be offset or indented so that this information stands out from the surrounding text. Recognition and separation of the SL, LCS, and LCO requirements allows this information to be more quickly and easily located and scanned without interference from the surrounding text. Also, the SL, LCS, and LCO mode applicability headings may be separated by extra “white space” (blank lines), allowing for quick recognition and scanning of specific information. Delimiters. Delimiters function as visual cues for the user, signaling the beginning and/or end of specific segments of information (two independent requirements on the same page, for example). Delimiters may take the form of two closely spaced horizontal lines, one dark, heavy line, a series of dark dashes, or any similar prominent marking. Underscoring. Underscoring is an effective way of adding emphasis to specific information, when properly used; however, it tends to lose its effectiveness when used too much. For this reason, underscoring should be used only to add emphasis to logical connectors (AND, OR, etc.). DOE G 423.1-1B Appendix A 3-18-2015 A-15 2.4.5 Use of Logic Terms (AND, OR, IF, BUT, etc.) The following guidelines apply.  All logic terms should be underscored, in uppercase bold type, and flush left between the two (or more) sets of connected conditions to which they apply.  AND should be used to connect two or more sets of criteria that must both (all) be satisfied for a given logical decision. If more than two sets of conditions are required, a list format is preferable.  OR should be used to denote alternative combinations or conditions, meaning either one or the other. When action steps are contingent upon certain conditions, terms such as IF, BUT, IF NOT, may be used as appropriate. 2.4.6 Notes and Cautions Notes and cautions should not normally occur within the context of the TSR. The TSR in itself is a compendium of potential cautions, and notes often indicate that the basic explanation is inadequate. When notes or cautions are necessary, the following apply.  Cautions should precede the information to which they refer, with no other intervening

Section 30

information. Notes may be placed before or after the text they amplify, whichever is most appropriate. All notes and cautions should be preceded by the centered heading “NOTE” or “CAUTION” in uppercase, bold type. Text in the note or caution statement should be in bold type, indented from both sides of the page. Cautions should be delimited from standard text.  Notes and cautions pertaining to information inside the action and SR statements should be placed before the information to which they apply, with no other intervening information. 2.4.7 Tables When the volume of tabular information to be presented is small, consider integrating the information in text rather than using a separate table. When tables are necessary, they should be located as conveniently as possible for the user. They should have a formal title and number. 2.4.8 Body of Section 1—Use and Application This section is expected to be mostly text, so it should take the form of paragraphs numbered in accordance with Section 2.4.1. Other forms of input should follow the guidance outlined in Section 2.4. 2.4.9 Body of Section 2—Safety Limits SLs should be presented in a single-column or three-column format. Appendix A DOE G 423.1-1B A-16 3-18-2015 The page heading, as described in Section 2.4.2, should be to the left margin of the page. The SL, denoted by the acronym SL, should follow, separated by at least one blank line from other text. If the requirement has subdivisions, they should follow on separate lines and be indented. Below the requirement, with sufficient space left above to make the requirement stand apart, the word “APPLICABILITY” should appear at the left margin, in bold uppercase letters, followed by a colon (also bold). On the same line should be the applicability modes or other conditions. Below the applicability statement, separated by at least one blank line, the word “ACTIONS,” in bold, uppercase letters, followed by a bold colon, should appear. The action statements should follow indented from the left margin and labeled with capital letters. Subdivisions of the action statements should be further indented and numbered. 2.4.10 Body of Section 3/4 - Limiting Control Settings, Limiting Conditions for Operation, and Surveillance Requirements Figures 7 through 10 provide examples of the way information for Section 3/4 should be presented. The page headings should be as described in Section 2.4.2 and should be to the left- hand margin of the page. Below the heading and indented should be the letters “LCS” or “LCO” in bold uppercase letters. This should be followed on the same line by a colon and then the requirement. For simple requirements a sentence or two may suffice, while for a complex requirement subdivisions may be necessary. Use uppercase letters for the main divisions and indented numbers as the first subcategory. Use indented lowercase letters for the next division, if necessary. If further division appears to be necessary, consider making an entire new requirement within the main group. Below the requirement, separated by at least one blank line, the word “APPLICABILITY” should appear at the left margin, in bold, uppercase letters. On the same line should be the applicability modes or other conditions. Below the applicability statement, again, separated by at least one blank line, should appear the word “ACTIONS” in bold, uppercase letters. The action statements should follow. The main

Section 31

divisions and subdivisions of the action statements should be numbered/lettered according to conventional outlining practices or as described above for requirements. SRs should follow the action statements, separated by at least one blank line. They should be labeled by the title (SURVEILLANCE REQUIRMENTS) in bold, uppercase letters. The surveillance statement should include the surveillance number; a statement of the requirement (with indented subdivisions, if necessary); and an indication of the frequency. Examples of the suggested format for SRs are given in Appendix B. 2.4.11 Body of Sections 5 and 6 - Administrative Controls and Design Features These sections are expected to be mostly text, possibly with tables, so they should take the form of paragraphs numbered in accordance with Section 2.4.1 of this Guide. 2.4.12 Body of Bases Appendix DOE G 423.1-1B Appendix A 3-18-2015 A-17 (and A-18) The body of the bases appendix should be presented in the format shown in Figures 217b or 9b. The page heading should be that described in Section 2.4.2, with the number of the SL, LCS, or LCO and the same title used in that requirement. Below the requirement number and title, the word BASES in bold, uppercase letters should be at the left margin, followed by a delimiter and the bases themselves. 2.5 Changes to Technical Safety Requirements Changes to the TSR should be designated in the following manner:  a list of pages in effect with page number and date;  a record of revision pages;  sidebar changes in the TSR text; and,  for each altered page, the page number, document number, and revision number. DOE G 423.1-1B Appendix B 3-18-2015 B-1 Appendix B. TSR Examples Contents Introduction Figure 1: Example Table of Contents for a Nuclear Reactor Facility TSR Figure 2: Example Table of Contents for a Nonreactor Nuclear Facility TSR Figure 3: Example Definitions List Figure 4a: Example of Safety Limit for a Nuclear Reactor Facility Figure 4b: Example of Safety Limit for a Nuclear Reactor in Three-Column Format Figure 5: Example of Limiting Control Settings in Three-Column Format Figure 6a: Example of General Application LCOs Figure 6b: Example of General Application for Surveillance Figure 6c: Example of General Application LCO Bases Figure 7a: Example of SAC LCO Figure 7b: Example of SAC LCO Bases Figure 8: Example of Fire Suppression LCO Figure 9a: Example of Diesel Generator LCO Figure 9b: Example of Diesel Generator LCO Bases Figure 10: Example of Administrative Controls Figure 11: Example of Overpack Directive Action SAC Figure 12: Example of Type B Container DF Appendix B DOE G 423.1-1B B-2 3-18-2015 Introduction This appendix provides examples of TSR controls similar to those that might be found in a DOE nuclear facility. The appendix may be used as a reference, but does not contain requirements. The examples offered do not represent an existing DOE facility, although some may have been adapted from existing facilities. The appendix follows the order of a typical TSR, with the exception of the TSR Bases section. Thus the appendix begins with a Use and Application section and ends with a Design Features section. The technical bases for each example appear immediately following the TSR itself. Explanatory sections are provided to aid users in understanding each example. DOE G 423.1-1B Appendix B 3-18-2015 B-3 TABLE OF CONTENTS Section 1 Use and Application

Section 32

1.1 DEFINITIONS ...............................................................................................................1 1.2 OPERATIONAL MODES ............................................................................................1 1.3 FREQUENCY NOTATIONS ........................................................................................2 1.3.1 Frequency Codes ................................................................................................2 1.4 MODE APPLICABILITY SUMMARY .......................................................................4 Section 2 Safety Limits 2.1 POWER LIMITS ...........................................................................................................6 2.2 PRESSURE LIMITS .....................................................................................................7 2.3 TEMPERATURE LIMITS ............................................................................................7 Section 3/4 Operational Limits and Surveillance Requirements 3. GENERAL APPLICATION. .........................................................................................8 3.1 REACTIVITY CONTROL SYSTEMS ......................................................................10 3.1.1 Control Bank Insertion Limits ........................................................................12 3.1.2 Core Reactivity .................................................................................................5 3.2 INSTRUMENTATION ...............................................................................................24 Section 5 Administrative Controls Section 6 Design Features Appendix ATSR Bases ..................................................... ...................................................A-1 Figure 1. Example Table of Contents for a Nuclear Reactor Facility TSR. Appendix B DOE G 423.1-1B B-4 3-18-2015 TABLE OF CONTENTS Section 1 Use and Application 1.1 DEFINITIONS .....................................................................................................................1 1.2 OPERATIONAL MODES ..................................................................................................1 1.3 FREQUENCY NOTATIONS ..............................................................................................3 1.3.1 Frequency Codes ..................................................................................................................4 1.4 MODE APPLICABILITY SUMMARY .............................................................................5 Section 2 Safety Limits 2.1 NONE .................................................................................................................................7 Section 3/4 Operational Limits and Surveillance Requirements 3.0 GENERAL APPLICABILITY ...........................................................................................8 3.1 FACILITY MAR LIMITS ................................................................................................10 3.2 FIRE ALARM AND SUPPRESION SYSTEMS .............................................................11 3.1.1 Fire Suppression ....................................................................................................13 3.1.2 Fire Detection and Alarm ......................................................................................17

Section 33

3.3 VENTILATION SYSTEMS ..............................................................................................21 3.3.1 HEPA Filters ..........................................................................................................24 3.3.2 Building DP ...........................................................................................................27 Section 5 Administrative Controls Section 6 Design Features Appendix A. TSR Bases .......................................................................................................... A-1 Figure 2. Example Table of Contents for a Nonreactor Nuclear Facility TSR. DOE G 423.1-1B Appendix B 3-18-2015 B-5 Table of Contents Example Discussion The “Use and Application” section appears first in a TSR document because it contains the conventions to be used throughout the TSRs. “Use and Application” explains to the user how to interpret the array of information that follows and how to use that information correctly. Traditionally, the order of the sections in most TSR documents has followed the order originally established for reactors. In reactors, the sections are arranged in what was established as the order of importance for safe operations. The “Safety Limits” section follows right after the general “Use and Applicability” section because these limits are the absolute highest limits of operation for public safety and are established reactor design parameters that should never be approached. Following in the order of importance is the “Operating Limits and Surveillance Requirements” specifying the safe operating parameters for all the reactor SSCs. Finally, the “Administrative Control” section of a reactor is last because it contains the policies governing the human element conducting the operations in accordance with the requirements specified in the previous sections. For nonreactor facilities, position in the TSRs is not necessarily an indicator of the control’s importance to safety. For example, the first limiting condition of operation (LCO) in many TSRs is the facility material-at-risk (MAR) limit, which protects the source term as analyzed in the documented safety analysis (DSA). This LCO is a SAC and differs from the reactor LCO in that it is not an SSC operating limit. However, whether this SAC appears in the “Operating Limits and Surveillance Requirements” section or the “Administrative Control” section of a TSR does not affect the importance to safety of this particular limit. For reactors, the TSRs are typically developed prior to construction and therefore the ability to prioritize engineering controls and follow established operational priority. DOE non-nuclear facilities consist of a much broader range of operations and phases of life cycles, which could make the traditional operational priority of sections impractical. For example, new construction under a preliminary documented safety analysis (PDSA) may have more dependence on engineering controls whereas an environmental restoration site may be required to be completely dependent on administrative controls. However, the principle of operational priority still applies within sections or individual controls themselves. When it is established that a particular control or limit is more important than another, it should precede the other limits within the section or control. Appendix B DOE G 423.1-1B B-6 3-18-2015 DEFINITIONS

Section 34

ACTION - The part of the TSR that prescribes Required Actions to be taken under designated Condition within specified Completion Times. CALIBRATION - The adjustment (as necessary) of the output such that it meets established acceptance criteria (e.g., responds within the necessary range and accuracy to known values). The CALIBRATION SHALL encompass the sensor, alarm, and trip functions, and SHALL be checked by a FUNCTIONAL TEST. CHANNEL - The combination of sensor, line, amplifier, and output devices that are connected for the purpose of measuring the value of a parameter and providing a signal for actuation. COMPLETION TIME - The amount of time allowed for completing an ACTION. See Section 1.3. CONDITION - A discrete degradation of a system or component in which an ACTION is performed within a specified COMPLETION TIME. ENSURE - To confirm, substantiate, and assure that an activity or CONDITION has been implemented in conformance with the specified requirements. Allows for manipulation of equipment or instrumentation to conform with specified requirements. May be done by reliable methods other than direct observation. FUNCTIONAL TEST - Tests OPERABILITY, including required alarms, interlock(s), trip functions, and CHANNEL failure trips (e.g., the injection of a simulated or actual signal into the CHANNEL as close to the sensor as practical). In contrast to VERIFICATION, this FUNCTIONAL TEST is an active test of the system. IMMEDIATE/ IMMEDIATELY - Term used as a COMPLETION TIME for ACTION statements when a step is to be initiated as soon as possibly achievable without creating a less safe condition, and continuously and aggressively pursued until complete. SAFE CONFIGURATION - Condition resulting from the minimization of risk in on-going processes commensurate with the chemical and/or physical form of material and/or arrangement of material and/or equipment. SHALL - Denotes a mandatory requirement that must be complied with to maintain the requirements, assumptions, or conditions of the facility SAFETY BASIS. TERMINATE - Means to stop an operation or activity as quickly and safely as possible. TIME OF DECLARATION - The actual time when the Facility Operations Director or designee determines that a CONDITION exists that requires entry into the ACTION statement of an LCO. As soon as possible upon notification of a problem, the problem should be evaluated and the Facility Operations Director or designee should make this declaration if it is determined that an LCO is not met. Figure 3. Example Definitions List. DOE G 423.1-1B Appendix B 3-18-2015 B-7 Definitions Example Discussion Writers and reviewers of a TSR document must be aware of the potential for misinterpretation of a term and should carefully consider which terms used in the document should be defined. Convention dictates that all terms defined in the TSR document, are shown in upper-case letter when the technical meaning is intended their usage so dictates in the TSR. This use of upper-case letters indicates to the reader that these terms may have a specific meaning apart from general usage, and that the definition is available in the TSR itself. The table lists examples of terms which should be considered for inclusion in the Definition section of the TSR. Definitions should be tailored to the specific facility and controls as derived from the DSA. Appendix B DOE G 423.1-1B B-8 3-18-2015 2.1 SAFETY LIMITS

Section 35

2.1.1 REACTOR COOLANT SYSTEM (RCS) PRESSURE SAFETY LIMIT SL: The RCS shall be maintained < 1000 psia APPLICABILITY: Operation Mode ACTIONS: 1. Go to SHUTDOWN mode IMMEDIATELY, 2. Notify the DOE CSO within one hour of reaching SHUTDOWN mode, and 3. Prohibit facility operation until authorized by DOE. Figure 4a. Example of Safety Limit for a Nuclear Reactor Facility. 2.1 SAFETY LIMITS 2.1.1 REACTOR COOLANT SYSTEM (RCS) PRESSURE SAFETY LIMIT SL: The RCS shall be maintained < 1000 psia MODE APPLICABILITY: Operation Mode ACTIONS: CONDITIONS REQUIRED ACTION COMPLETION TIME A. The RCS exceeds the Safety Limit (1000 psia). A.1. Go to SHUTDOWN mode. AND A.2. Notify the DOE CSO. AND A.3. Prohibit facility operation. IMMEDIATELY Within one hour of reaching SHUTDOWN mode Until authorized by DOE Figure 4b. Example of Safety Limit for a Nuclear Reactor in Three-Column Format. DOE G 423.1-1B Appendix B 3-18-2015 B-9 TSR Safety Limits Example Discussion A safety limit (SL) controls a process variable that is directly measurable and continuously observable. In this example, the reactor coolant system (RCS) is a primary barrier to the release of radioactive material. The piping and welds of this system are designed and built to withstand pressures up to 1,000 psia. Exceeding this pressure could breach the RCS or weaken RCS piping to a degree that risks catastrophic failure. Exceeding this value is a TSR violation and requires taking these three steps: 1. Go to SHUTDOWN mode IMMEDIATELY; 2. Notify the DOE CSO within one hour of reaching SHUTDOWN mode; and, 3. Prohibit facility operation until authorized by DOE. A single column format usually suffices for a safety limit it is a single variable, the required actions are always the same, and it is important not to mislead the user into thinking that performance of the actions within the specified times would result in avoidance of a TSR violation. There are no surveillances for a safety limit because the variable being limited is continuously monitored and protected by a Limiting Control Setting (LCS). Appendix B DOE G 423.1-1B B-10 3-18-2015 3/4.4 LIMITING CONTROL SETTINGS 3.4.4.3 COOLANT PRESSURE LCS: Maintain Coolant system below 100 psia MODE APPLICABILITY: All Modes. ACTIONS: CONDITION REQUIRED ACTION COMPLETION TIME Pressure > 100 psia Reduce pressure to < 100 psia 15 minutes SURVEILLANCE REQUIREMENTS SURVEILLANCE REQUIREMENT FREQUENCY SR 34.4.3.1 Verify Pressure < 100 psia Each shift SR 4.4.3.2 CALIBRATE Pressure Relief Valve and verify Set Point = 95 +/- 4 psia Annually Figure 5. Example of Limiting Control Settings in Three-Column Format. DOE G 423.1-1B Appendix B 3-18-2015 B-11 Limiting Control Settings Example Discussion LCS control process variables in safety systems to prevent exceeding SLs. This example LCS is associated with the previous SL example and is a control on the same process variable, namely, system pressure. In this instance, the automatic pressure relief valve is set to open at 95 psia. This operating limit can be exceeded if the valve fails to operate as designed or the pressure transient is beyond the relief valve’s capability. A LCS needs to be chosen so that the required action (either automatic or manual) corrects the abnormal condition before its associated SL is exceeded. Providing at least one LCS for each SL ensures that an SL cannot be exceeded without first exceeding an LCS.

Section 36

LCSs always follow the general LCOs because the rules for applying LCOs apply also to LCSs. LCSs are placed before any LCOs as they protect the maximum operating range for the process variables they represent. Appendix B DOE G 423.1-1B B-12 3-18-2015 GENERAL LIMITING CONDITIONS FOR OPERATION (LCOS) 3.0 LCO 3.0.1 LCOs shall be met during the MODES or other specified conditions in the Applicability, except as provided in LCO 3.0.2. LCO 3.0.2 Upon discovery of a failure to meet an LCO, the associated ACTIONS shall be met, except as provided in LCO 3.0.5 and LCO 3.0.6. If the LCO is restored or is no longer applicable before the specified completion time(s) expires, completion of the ACTION is not required, unless otherwise stated. The Completion Time(s) for Required Action(s) are also applicable when a system or component is intentionally removed from service. Acceptable reasons for intentionally entering Required Action(s) for an LCO include, but are not limited to, performance of SRs, preventive maintenance, corrective maintenance, or investigation of operational problems. LCO 3.0.3 When an LCO statement is not met and the associated ACTIONS are not met, or when an associated ACTION is not provided, the facility shall be placed in a MODE or other specified condition in which the LCO is not applicable. If the LCO is applicable in all MODES, the facility shall be placed in the safest MODE. Activities shall be initiated to place the affected PROCESS AREA(S) or facility in STANDBY within 1 hour. The affected PROCESS AREA or facility shall be in STANDBY within 12 hours. Where corrective measures are completed that permit operation in accordance with the LCO or ACTIONS, completion of the ACTIONS required by LCO 3.0.3 are not required. LCO 3.0.3 is applicable in all MODES. Exceptions to LCO 3.0.3 may be stated in the individual LCOs. LCO 3.0.4 When an LCO is not met, a MODE or other specified condition in the Applicability shall not be entered, except when the associated ACTIONS to be entered permit continued operation in the MODE or other specified condition in the Applicability for an unlimited period of time. LCO 3.0.4 shall not prevent changes in MODES or other specified conditions in the Applicability that are required to comply with ACTIONS or that are part of a shutdown of the affected PROCESS AREA(S) or facility. Exceptions to LCO 3.0.4 are stated in the individual LCOs. When an individual LCO states that LCO 3.0.4 does not apply, it allows entry into MODES or other specified conditions in the Applicability when the associated ACTIONS to be entered permit operation in the MODE or other specified condition for only a limited time. (Note: Continued on Next Page) Figure 6a. Example of General Application LCOs (Page 1). DOE G 423.1-1B Appendix B 3-18-2015 B-13 GENERAL LIMITING CONDITIONS FOR OPERATION (LCOS) 3.0 LCO 3.0.5 Equipment removed from service or declared inoperable to comply with ACTIONS may be returned to service under administrative control solely to perform testing required to demonstrate its OPERABILITY or the OPERABILITY of other equipment. This is an exception to LCO 3.0.2 for the system returned to service under administrative control to perform the testing required to demonstrate OPERABILITY. LCO 3.0.6 When a support system is declared inoperable, the supported systems are also required to be declared inoperable. However, only the support system’s

Section 37

ACTIONS are required to be entered, provided they reflect the supported system’s degraded safety condition. This is an exception to LCO 3.0.2 for the supported system. Figure 6a. Example of General Application LCOs (Page 2). Appendix B DOE G 423.1-1B B-14 3-18-2015 4.0 GENERAL SURVEILLANCE SURVEILLANCE REQUIREMENTS SR 4.0.1 SURVEILLANCE REQUIREMENTS shall be met during the Operational Modes or other conditions specified for individual LCS and LCOs unless otherwise stated in an individual SURVEILLANCE REQUIREMENT. Failure to meet a Surveillance, whether such failure is experienced during the performance of the Surveillance or between performances of the Surveillance, shall be failure to meet the LCO, except as provided in SR 4.0.3. Surveillances do not have to be performed on inoperable equipment or variables outside specified limits. SR 4.0.2 Each SURVEILLANCE REQUIREMENT shall be performed within the specified frequency. The specified frequency for each SR is met if the Surveillance is performed within 1.25 times the interval specified in the frequency, as measured from the previous performance or as measured from the time a specified condition of the frequency is met. For frequencies specified as "once," the above interval extension does not apply. If a Completion Time requires periodic performance on a "once per . . ." basis, the above frequency extension applies to each performance after the initial performance. Exceptions to this Specification are stated in the individual Specifications. 4.0.3 Failure to perform a SURVEILLANCE REQUIREMENT within 1.25 times the specified time interval (TSR violation) shall constitute a failure to meet the OPERABILITY requirements for a LIMITING CONDITION FOR OPERATION. The LCO ACTIONS shall be entered at the time it is determined that the SR has not been performed or is not met, except as provided below. If it is discovered that a Surveillance was not performed within its specified Frequency, then compliance with the requirement to declare the LCO not met may be delayed, from the time of discovery, up to 24 hours or up to the limit of the specified Frequency, whichever is less. This delay period is permitted to allow performance of the Surveillance. If the Surveillance is not performed within the delay period, the LCO must immediately be declared not met, and the applicable Condition(s) must be entered. When the Surveillance is performed within the delay period and the Surveillance is not met, the LCO must immediately be declared not met, and the applicable Condition(s) must be entered. (Note: Continued on Next Page) Figure 6b. Example of General Application LCOs (Page 1). DOE G 423.1-1B Appendix B 3-18-2015 B-15 SR 4.0.4 Entry into an Operational Mode or other specified condition shall not be made unless the SURVEILLANCE REQUIREMENT(S) associated with the LIMITING CONDITION FOR OPERATION has been performed within the stated surveillance interval or as other otherwise specified. When an LCO is not met due to Surveillances not having been met, entry into a MODE or other specified condition in the Applicability shall only be made in accordance with LCO 3.0.4. Figure 6b. Example of General Application LCOs (Page 2). B 3/4.0 General Limiting Conditions for Operation and Surveillance Requirements Background LCOs 3.0.1 through 3.0.6 establish the general requirements applicable to Summary all LCOs and apply at all times, unless otherwise stated.

Section 38

LCO 3.0.1 LCO 3.0.1 establishes the APPLICABILITY statements within each LCO as the requirement for when to the LCO is required to be met (i.e., when the facility is in the MODES or other specified conditions of the Applicability statement of each LCO). LCO 3.0.2 LCO 3.0.2 establishes that, upon discovery of a failure to meet an LCO, the associated ACTIONS shall be met. The Completion Time of each Required Action for an ACTIONS Condition is applicable from the point in time that an ACTIONS Condition is entered. The Required Actions establish those remedial measures that must be taken within specified Completion Times when the requirements of an LCO are not met. This LCO establishes that: a. Completion of the Required Actions within the specified Completion Times constitutes compliance with an LCO, and b. Completion of the Required Actions is not required when an LCO is met within the specified Completion Time, unless otherwise specified. LCO 3.0.2 There are two basic types of ACTIONS. The first type of ACTION specifies a time limit in which the LCO SHALL be met or additional ACTION is needed. This time limit is the COMPLETION TIME to restore an INOPERABLE system or component to OPERABLE status or to restore variables to within specified limits. If this type of ACTION is not completed within the specified COMPLETION TIME, the facility may be required to be placed in an operating configuration in which the LCO is not applicable. Whether stated as an ACTION or not, restoration of INOPERABLE equipment or a CONDITION to within limits is an ACTION that may always be considered on entering LCO ACTIONS. (Note: Continued on Next Page) Figure 6c. Example of General Application LCOs (Page 1). Appendix B DOE G 423.1-1B B-16 3-18-2015 Some LCO ACTIONS specify a COMPLETION TIME to initiate ACTION to place the facility in a specified MODE or other safe condition. This wording allows building operations a reasonable amount of time to determine what actions are necessary, to determine the correct course of action to safely perform the necessary actions, and to perform any necessary administrative functions associated with the actions. When COMPLETION TIMES were not specified for completion of facility reconfiguration or MODE change to allow reasonable operational flexibility, the intent is not to delay placing the facility in a safe condition or MODE. Necessary actions should be completed in a minimum time frame and not extended for operational convenience. The second type of ACTION specifies remedial measures that permit continued operation of the facility without further restriction by the COMPLETION TIME of the ACTION. In this case, conformance to the ACTION provides an acceptable level of safety for continued operation. Completion of ACTIONS is not required when an LCO is met or is no longer applicable within the associated COMPLETION TIMES, unless otherwise stated in the individual LCO. The nature of some ACTIONS for some CONDITIONS necessitates that, once the CONDITION is entered, ACTIONS SHALL be completed even though the associated CONDITIONS are resolved. The ACTIONS of the individual LCOs specify where this is the case. The COMPLETION TIMES of the ACTIONS are also applicable when a system or component is intentionally taken OUT-OF-SERVICE. The reasons for intentionally relying on the ACTIONS include, but are not limited to, performance of SURVEILLANCES, preventative or corrective maintenance, or

Section 39

investigation of operational problems. ACTIONS for these reasons SHALL be performed in a manner that does not compromise safety. (Note: Continued on Next Page) Figure 6c. Example of General Application LCOs (Page 2). DOE G 423.1-1B Appendix B 3-18-2015 B-17 LCO 3.0.2 When a change in MODE or other specified condition is required to comply with Required Actions, the facility may enter a MODE or other specified condition in which a new LCO becomes applicable. In this case, the Completion Times of the associated Required Action would apply from the point in time that the new LCO becomes applicable, and any Condition(s) are entered. LCO 3.0.3 LCO 3.0.3 establishes the ACTIONS that SHALL be implemented when an LCO is not met.  Associated ACTIONS and COMPLETION TIMES are not met and no other CONDITION applies.  The CONDITION of the facility is not specifically addressed by the associated ACTIONS. This means that no combination of CONDITIONS stated in the ACTIONS corresponds exactly to the actual CONDITION of the facility. Sometimes possible combinations of CONDITIONS are such that entering LCO 3.0.3 is warranted; in such cases, the ACTIONS specifically state a CONDITION corresponding to such combinations and also that LCO 3.0.3 must be entered This LCO is intended to provide a “safe-harbor” provision when either the ACTION cannot be complied with, or the ACTION cannot be complied with within the specified COMPLETION TIME when an LCO is not met. It also provides a default ACTION when the facility is in a condition that is indeterminate, or is not readily categorized into the specified limits of an LCO. Entry into LCO 3.0.3 and completion of the associated ACTIONS within the required COMPLETION TIME does not in and of itself constitute a VIOLATION of a TSR. (Note: Continued on Next Page) Figure 6c. Example of General Application LCOs (Page 3). Appendix B DOE G 423.1-1B B-18 3-18-2015 LCO 3.0.3 This LCO delineates the time limit to initiate ACTION for placing the facility in a safe operating configuration when operation cannot be maintained within the limits for safe operation, as defined by the LCO and its ACTIONS. It is not an operational convenience that permits routine, voluntary removal of redundant or standby systems or components from service in lieu of other alternatives that would result in redundant or standby systems or components being OPERABLE. Upon entry into LCO 3.0.3, one hour is allowed to prepare for a change in facility operation. The time limit specified to initiate actions permits the change to proceed in a controlled and orderly manner that is well within the capabilities of the facility. This reduces the potential for a facility upset that could challenge safety systems under operating configurations to which this LCO applies. Change in facility operation required in accordance with LCO 3.0.3 may be orderly terminated and LCO 3.0.3 exited, if any of the following occurs:  The LCO is now met.  A CONDITION exists for which the ACTION has been performed.  ACTIONS exist that do not have expired COMPLETION TIMES. These COMPLETION TIMES are applicable from the point in time that the CONDITION was initially entered and not from the time LCO 3.0.3 is exited. The time limit of LCO 3.0.3 allows one hour to initiate action to place the facility in a safe operating configuration and 12 hours to complete the action. The exceptions to LCO 3.0.3 are provided in instances where requiring a facility

Section 40

change in accordance with LCO 3.0.3 would not provide appropriate remedial measures for the associated CONDITION of the facility. These exceptions are addressed in the individual LCOs. LCO 3.0.4 LCO 3.0.4 establishes limitations on changes in MODES or other specified conditions in the Applicability when an LCO is not met. It precludes placing the facility in a different MODE or other specified condition when the following exists: (Note: Continued on Next Page) Figure 6c. Example of General Application LCOs (Page 4). DOE G 423.1-1B Appendix B 3-18-2015 B-19  The requirements of an LCO in the MODE or other specified condition to be entered are not met.  Continued noncompliance with these requirements would result in requiring that the unit be placed in a MODE or other specified condition in which the LCO does not apply to comply with the ACTIONS. Compliance with ACTIONS that permit continued operation of the facility for an unlimited period of time in an applicable MODE or other specified condition provides an adequate level of safety for continued operation. This is without regard to the status of the facility before or after the MODE change. Therefore, in such cases, entry into a MODE or other condition the Applicability may be made in accordance with the provisions of the ACTIONS. The provisions of this LCO shall not be interpreted as endorsing the failure to exercise the good practice of restoring systems or components to OPERABLE status before facility startup. LCO 3.0.4 The provisions of LCO 3.0.4 shall not prevent changes in MODES or other specified conditions in the Applicability that are required to comply with ACTIONS. Exceptions to LCO 3.0.4 are stated in individual LCOs. Exceptions may apply to all the ACTIONS or to a specific ACTION of an LCO. When changing MODES or other specified conditions while in a condition (in compliance with LCO 3.0.4 or where an exception to LCO 3.0.4 is stated) the ACTIONS define the remedial measures that apply. SURVEILLANCES do not have to be performed on the associated INOPERABLE equipment (or on variables outside the specified limits), as permitted by SR 4.0.1. Therefore a change in MODE or other specified condition in this situation does not violate SR 4.0.1 or SR 4.0.4 for those SURVEILLANCES that do not have to be performed because of the associated INOPERABLE equipment. However, SRs SHALL be met to demonstrate OPERABILITY before declaring the associated equipment OPERABLE (or variable within limits) and restoring compliance to the affected LCO. LCO 3.0.5 LCO 3.0.5 establishes the allowance of restoring equipment to service under administrative/procedural controls when it has been removed from service or declared INOPERABLE to comply with ACTIONS. The sole purpose of this LCO is to provide an exception to LCO 3.0.2 to allow the performance of SURVEILLANCE REQUIREMENTS to DEMONSTRATE the following: (Note: Continued on Next Page) Figure 6c. Example of General Application LCOs (Page 5). Appendix B DOE G 423.1-1B B-20 3-18-2015  OPERABILITY of the equipment being returned to service; or  OPERABILITY of other associated equipment. An example of DEMONSTRATING the OPERABILITY of other equipment is taking an INOPERABLE channel or trip system out of the tripped condition to prevent the trip function from occurring during the performance of a SURVEILLANCE REQUIREMENT on another channel in the other trip system. ANOTHER similar example of DEMONSTRATING the OPERABILITY of

Section 41

other equipment is taking a channel out of the tripped condition to permit the logic to function and indicating the appropriate response during performance of a SURVEILLANCE REQUIREMENT on another channel in the same trip system. LCO 3.0.6 LCO 3.0.6 establishes an exception to LCO 3.0.2 for support systems that have an LCO or ACTION statement specified in the TSR. This exception is necessary because LCO 3.0.2 requires that the CONDITIONs and ACTIONs of the associated INOPERABLE supported system LCO be entered solely from the INOPERABILITY of the support system. This exception is justified because the ACTIONs that are required to ensure that the facility is maintained in a safe operating configuration are specified in the support system ACTIONS. These ACTIONS may include entering the supported system’s CONDITIONs and ACTIONs or may specify other ACTIONs. When a support system is INOPERABLE and there is no LCO or Action statement specified for it in the TSR, the effects on the supported system(s) operability is required to be evaluated and a formal declaration made. However, it is not necessary to enter into the supported system’s CONDITIONs and ACTIONs unless directed to do so by the support system’s ACTIONS. The confusion and inconsistency of interpretation of requirements related to the entry into multiple CONDITIONs and ACTIONs SHALL be eliminated by providing all actions that are necessary to be taken to ensure that the facility is maintained in a safe operating configuration in the support system’s ACTIONS. When a support system is INOPERABLE and there is no LCO specified for it, the impact of the degradation of the support system function on the supported systems’ OPERABILITY SHALL be evaluated. (Note: Continued on Next Page) Figure 6c. Example of General Application LCOs (Page 6). DOE G 423.1-1B Appendix B 3-18-2015 B-21 The degradation of the support system may or may not affect the OPERABILITY of the supported systems. OPERABILITY of the supported system SHALL depend on the intended function of the supported system and the level of support that the supported system provides. Unless otherwise justified (on determination that the supported system is INOPERABLE), the CONDITIONs and ACTIONs of the supported system’s LCO SHALL apply or other compensatory actions or requirements SHALL apply, as otherwise justified. Administrative/procedural controls are to ensure the time the equipment is returned to service in conflict with the requirements of the ACTIONS is limited to the time absolutely necessary to perform the allowed SURVEILLANCE REQUIREMENT. This LCO does not provide time to perform any other preventive or corrective maintenance. Background SRs 4.0.1 through 4.0.4 establish the general requirements applicable to all Summary SURVEILLANCE REQUIREMENTs and apply at all times, unless stated otherwise. The general requirements contained in LCOs 4.0.1–4.0.4 provide overall rules to guide the use and application of the specific requirements of the LCOs in Section 4.0 of the TSR. When exceptions to the general requirements contained in LCOs 4.0.1–4.0.4 are allowed, they are stated as notes in the individual LCO. SR 4.0.1 SR 4.0.1 establishes that SURVEILLANCE REQUIREMENTS must be met during the MODES or other specified operating conditions in the APPLICABILITY statements for individual LCOs, unless otherwise stated in the individual SURVEILLANCE REQUIREMENTS. This SR ensures that

Section 42

SURVEILLANCES are performed to VERIFY the OPERABILITY of systems and components, and that variables are within specified limits. Failure to meet a SURVEILLANCE REQUIREMENT within the specified FREQUENCY, in accordance with SR 4.0.2, constitutes a failure to meet an LCO. Systems and components are assumed to be OPERABLE when the associated SURVEILLANCE REQUIREMENTS have been met. Nothing in this SR, however, is to be construed as implying that systems or components are OPERABLE when:  The systems or components are known to INOPERABLE, although still meeting the SRs; or  The requirements of the SURVEILLANCE(s) are not met between required SURVEILLANCES performances. (Note: Continued on Next Page) Figure 6c. Example of General Application LCOs (Page 7). Appendix B DOE G 423.1-1B B-22 3-18-2015 SURVEILLANCES do not have to be performed when facility is in a MODE or other specified operating configuration for which the requirements of the associated LCO are not applicable, unless otherwise specified. SURVEILLANCES, including SURVEILLANCES invoked by ACTIONS, do not have to be performed on INOPERABLE equipment because the sole purpose of a SURVEILANCE is to determine OPERABILITY. If the equipment has been declared INOPERABLE and/or out-of-service, an OPERABILITY determination has already been made. ACTIONS because of the equipment INOPERABILITY define the remedial measures that apply. SURVEILLANCE REQUIREMENTs have to be met in accordance with SR 4.0.2 before returning equipment to OPERABLE status. Measurement devices used to DEMONSTRATE compliance with LCO SRs SHALL be calibrated to plant design, manufacturer’s specifications and/or industry standards as described in the Laboratory Calibration Program. SURVEILLANCE REQUIREMENT results SHALL be documented in an auditable and traceable manner. SR 4.0.1 Upon completion of maintenance, appropriate post-maintenance testing is required to declare equipment OPERABLE. This includes meeting applicable SURVEILLANCE REQUIREMENTS in accordance with SR 4.0.2. Post- maintenance testing may not be possible in the specified operating configuration in the APPLICABILITY because the necessary facility parameters were not established. In these situations, the equipment may be considered OPERABLE provided testing has been satisfactorily completed to the extent possible and that the equipment is not otherwise believed to be incapable of performing its function. This will allow operation to proceed to a specified operating configuration where other necessary post maintenance tests can be completed. A SURVEILLANCE REQUIREMENT that requires removal of equipment from service does not constitute failure to meet an LCO. Individual SURVEILLANCE procedures SHALL describe appropriate limitations beyond which an out-of- tolerance CONDITION would exist. SR 4.0.2 SR 4.0.2 establishes the requirements for meeting the specified FREQUENCY for SURVEILLANCES. Surveillance frequencies should be based on historical data, engineering or manufacturer’s information or safety analysis to allow the longest reasonable time period between SURVEILLANCEs to ensure OPERABILITY. Failure to perform the SURVEILLANCE REQUIREMENTS within the specified FREQUENCIES may allow operation beyond the assumptions specified in the DSA. (Note: Continued on Next Page) Figure 6c. Example of General Application LCOs (Page 8). DOE G 423.1-1B Appendix B 3-18-2015 B-23

Section 43

SR 4.0.3 SR 4.0.3 permits a 25% extension of the interval specified in the SURVEILLANCE REQUIREMENTS FREQUENCY. This SR is designed to facilitate SURVEILLANCE REQUIREMENT scheduling in conditions where performance would represent an operational hardship or cause an unsafe transient. It allows consideration of facility operating conditions that may not be suitable for conducting the SURVEILLANCE REQUIREMENT (e.g., transient states or other ongoing SURVEILLANCE REQUIREMENTS or maintenance activities). The 25% extension does not significantly degrade the reliability that results from performing the SURVEILLANCE REQUIREMENT at its specified FREQUENCY. This is based on the recognition that the most probable result of any particular SURVEILLANCE REQUIREMENT being performed is the VERIFICATION of conformance with the SURVEILLANCE REQUIREMENTS. The exceptions to SR 4.0.3 are those SURVEILLANCE REQUIREMENTS for which the 25% extension of the interval specified in the FREQUENCY does not apply. These exceptions are stated in the individual SURVEILLANCE REQUIREMENTS. An example of where SR 4.0.3 does not apply is a SURVEILLANCE REQUIREMENT with a FREQUENCY of "in accordance with another DOE regulation." The requirements of regulations take precedence over the TSR. The TSR cannot, in and of itself, extend a test interval specified in the regulations. Therefore, there would be a Note: in the FREQUENCY stating, "SR 4.0.3 is not applicable." SR 4.0.3 The provisions of SR 4.0.3 are not intended to be used repeatedly merely as an operational convenience to extend SURVEILLANCE REQUIREMENT intervals or periodic COMPLETION TIME intervals beyond those specified SR 4.0.3 establishes the flexibility to defer declaring AFFECTED equipment INOPERABLE or an affected variable outside the specified limits when SURVEILLANCE has not been completed within the specified FREQUENCY. A delay period of up to 24-hours applies from the time it is discovered that the SURVEILLANCE has not been performed, in accordance with SR 4.0.2, and not at the time the specified FREQUENCY was not met. To avoid subjecting the facility to unnecessary transients, upon discovery of a missed SURVEILLANCE, 24 hours or the time limit of the specified SURVEILLANCE FREQUENCY, whichever is less, is allowed to complete the SURVEILLANCE before taking the required ACTION of the LCO. This delay period provides an adequate time limit to complete missed SURVEILLANCES. (Note: Continued on Next Page) Figure 6c. Example of General Application LCOs (Page 9). Appendix B DOE G 423.1-1B B-24 3-18-2015 This delay period permits the completion of a SURVEILLANCE before compliance with ACTIONS or other remedial measures would be required that may preclude completion of the SURVEILLANCE. The basis for this delay period includes consideration of facility operating configuration, adequate planning, availability of personnel, the time required to perform the SURVEILLANCE, the safety significance of the delay in completing the required SURVEILLANCE, and the recognition that the most probable result of any particular SURVEILLANCE being performed is the VERIFICATION of conformance with the SURVEILLANCE REQUIREMENTS. When a SURVEILLANCE with a FREQUENCY, based not on time intervals but on specified facility CONDITIONS or operational situations, is discovered not to have been performed when specified, SR 4.0.3 allows the full 24-hour delay period in which to perform the SURVEILLANCE.

Section 44

The provisions of SR 4.0.3 also provide a time limit for completion of SURVEILLANCES that become applicable as a consequence of changes imposed by ACTIONS. Failure to comply with specified frequencies for SURVEILLANCE REQUIREMENTS is expected to be an infrequent occurrence. Use of the delay period established by SR 4.0.3 is a flexibility that is not intended to be used as an operational convenience to extend SURVEILLANCE intervals. This extension also does not preclude notification of a VIOLATION of SR 4.0.2. This allows performance of SURVEILLANCE REQUIREMENTS when the prerequisite CONDITIONS specified in a SURVEILLANCE REQUIREMENT procedure require entry into the MODE or other specified operating configuration in the APPLICABILITY Statements of the associated LCO prior to the performance or completion of a SURVEILLANCE REQUIREMENT. A SURVEILLANCE REQUIREMENT, which could not be performed until after entering the LCO APPLICABILITY statements, would have its FREQUENCY specified such that it is not "due" until the specific operating configuration needed is met. Alternately, the SURVEILLANCE REQUIREMENT may be stated in the form of a note as not required (to be met or performed) until a particular event, operating configuration, or time has been reached. (Note: Continued on Next Page) Figure 6c. Example of General Application LCOs (Page 10). DOE G 423.1-1B Appendix B 3-18-2015 B-25 SR 4.0.3 If a SURVEILLANCE REQUIREMENT is not completed within the allowed delay period, the equipment is considered not OPERABLE or the variable is considered outside the specified limits and the COMPLETION TIMES of the ACTIONS for the applicable LCO CONDITIONS begin IMMEDIATELY upon expiration of the delay period. If a SURVEILLANCE REQUIREMENT is failed within the delay period, then the equipment is INOPERABLE, or the variable is outside the specified limits and the COMPLETION TIMES of the ACTIONS for the applicable LCO CONDITIONS begin IMMEDIATELY upon the failure of the SURVEILLANCE REQUIREMENT. Completion of the SURVEILLANCE REQUIREMENT within the delay period allowed by this LCO, or within the COMPLETION TIMES of the ACTIONS, restores compliance with SR 4.0.1. SR 4.0.4 SR 4.0.4 establishes the requirement that all applicable SURVEILLANCE REQUIREMENTS must be met before entry into a MODE or other specified operating configuration in the APPLICABILITY Statements. This SURVEILLANCE REQUIREMENT ensures that system and component OPERABILITY requirements and variable limits are met before entry into a MODE or other specified operating configuration in the APPLICABILITY Statements for which these systems and components ensure safe operation of the facility. This SURVEILLANCE REQUIREMENT applies to changes in MODES or other specified operating configurations in the APPLICABILITY Statements associated with the facility. The provisions of SR 4.0.4 SHALL not prevent changes in MODES or other specified operating configurations in the APPLICABILITY Statements that are required to comply with the ACTIONS. The precise requirements for performance of SURVEILLANCE REQUIREMENTS are specified such that exceptions to SR 4.0.4 are not necessary. The specific time frames and CONDITIONS necessary for meeting the SURVEILLANCE REQUIREMENTS in accordance with the requirements of SR 4.0.4 are specified in the FREQUENCY, in the SURVEILLANCE REQUIREMENT, or both. Figure 6c. Example of General Application LCOs (Page 11).

Section 45

Appendix B DOE G 423.1-1B B-26 3-18-2015 General Limiting Conditions for Operation and Surveillance Requirements Example Discussion General LCOs (Sections 3.0.1 through 3.0.6 in the main text) and general SRs (Sections 4.0.1 through 4.0.4 in the main text) establish rules generally applicable to all LCOs and SRs. Because these rules provide a framework for applying the facility-specific LCOs and SRs, they should be considered when developing specific LCOs and SRs. They are placed at the front of Section 3/4 to indicate their applicability to later sections. These rules do not apply to other sections of the TSR unless specifically invoked by those sections. Example: “NOTE: SR 4.0.3 is applicable to the following ISIs.” The general rules cause the specific LCO requirements to be applied uniformly and to function effectively. These rules and their choice of specific words reflect long experience and hence should be used as presented unless specific circumstances dictate otherwise. The most common exception to this principle is the “safest mode” and required action times of LCO 3.0.3. These particular values should be tailored to the specific facility safety basis. More flexibility exists with respect to the general LCO bases, though changes should be deliberate and purposeful. They are presented here to assist the user in interpreting the general LCOs. DOE G 423.1-1B Appendix B 3-18-2015 B-27 3/4.1 MATERIAL AT RISK (MAR) Inventory Control 3.1.1 FACILITY MAR Limits LCO: MAR inventory SHALL meet the following limits:  Total FACILITY MAR ≤ 10,000 g 239PuE  YARD MAR ≤ 2,000 g 239PuE. NOTE MAR in TRANSFER within the FACILITY structure is counted upon reaching its final destination. MAR in TRANSFER in the YARD is counted against the applicable YARD limit while in TRANSFER. CONDITION ACTIONS COMPLETION TIME A. MAR inventory exceeded. A.1 VERIFY fire suppression system is OPERABLE in the affected area. 1 hour AND A.2 VERIFY combustible loading meets limits in the affected area. 1 hour AND A.3 Initiate a FIRE WATCH in the affected area. 4 hours AND A.4 Restore inventory to within limits. 72 hours (Note: Continued on Next Page) Figure 7a. Example of SAC LCO (Page 1). Appendix B DOE G 423.1-1B B-28 3-18-2015 CONDITION ACTIONS COMPLETION TIME B. ACTIONS and associated COMPLETION TIMES of CONDITION A not met B.1 Place the affected AREA in STANDBY. IMMEDIATELY AND B.2 Restore inventory to within limits. 7 days C. ACTIONS and associated COMPLETION TIMES of CONDITION B not met. C.1 Place the affected AREA in SHUTDOWN. 30 days 4.1 SURVEILLANCE REQUIREMENTS SR Surveillance FREQUENCY 4.1.1 VERIFY FACILITY MAR inventory ≤ 10,000 g 239 PuE. M 4.1.2 VERIFY YARD MAR inventory ≤ 2,000 g 239 PuE. M 4.1.3 Perform a physical reconciliation of MAR inventory A Figure 7a. Example of SAC LCO (Page 2). DOE G 423.1-1B Appendix B 3-18-2015 B-29 B3/4.1 MATERIAL-AT-RISK LIMIT BACKGROUND The MAR LCO establishes the maximum (or upper bound) SUMMARY quantity of materials at risk in terms of PuE on site at any one time and in any particular location at one time. These maximum quantities established the bases in all accident scenarios evaluated in Chapter 3 of the DSA. APPLICATION MAR limits are placed on the yard and the facility. The physical TO SAFETY form of the material is assumed to be metal. The goal is to ensure that the ANALYSIS MAR is maintained at or below an appropriate level to maintain the

Section 46

potential consequences to the maximum exposed offsite individual (MEOI) from postulated accidents to below those evaluated in the DSA. Accident scenarios (selected from the entire list of breaches, leaks, fires, deflagrations, explosions, natural phenomena, and external event accidents, which includes an aircraft crash, evaluated in the DSA) result in bounding releases involving the entire facility, or specific locations within the facility. LCO The MAR limits LCO places restrictions on the amount of MAR that may be present at various locations within the facility. This limit is imposed to limit potential offsite doses from postulated bounding accident scenarios. The safety analysis assumed that the MAR limit is in vault and the work area. APPLICABILITY The LCO is applicable at all times. CONDITION A, Condition A is entered when the amount of MAR resident within the ACTIONs and inventory is discovered to exceed the corresponding location limits COMPLETION specified in the LCO. Under this condition, ACTION A.1 through A.3 are TIMEs entered with the objective of ensuring that a fire does not occur while A.4 works on reducing the inventory to below MAR limits. Verifying the operability of the FSS and compliance with combustible limits and establishing a fire patrol all lessen the opportunity or reduce the ramification of a fire. The first two of the compensatory actions must be implemented within 1 hours of time of declaration. ACTION A.4 requires removing excess MAR inventory from the location within 72 hours given the compensatory actions to reduce the threat of fire. The required (Note: Continued on Next Page) Figure 7b. Example of SAC LCO Bases (Page 1). Appendix B DOE G 423.1-1B B-30 3-18-2015 B3/4.1 MATERIAL-AT-RISK LIMIT CONDITION A, ACTION will limit the potential consequence of accidental release of ACTIONs and these materials to that which exists when the noncompliance condition COMPLETION occurs. Removing the excess inventory lowers the inventory to below the TIMEs limit that would ensure the bounding of the analyses evaluated in the DSA. This ACTION ensures that the inventory is less than or equal to the limits specified in the LCO. Three days (72 hours) is a reasonable COMPLETION TIME considering the need to arrange for removing the MAR containers or excess MAR from the facility. It is an acceptable period of time relative to the estimated FREQUENCY of bounding accidents that could impact the total building inventory, such as natural phenomena accidents, large fires, and vehicle crashes. The required ACTIONS reduce the likelihood of accidents and the magnitude of potential MAR releases from the facility during accident conditions. Condition B is entered when the ACTION A.4 cannot be met within its COMPLETION TIME. Under this condition, ACTION B.1 is entered. ACTION B.1 requires that the facility be placed in STANDBY MODE IMMEDIATELY. All process operations are not allowed while the excess inventory is removed from the facility. The removal of the excess inventory must be completed within 7 days. The frequency of fire is 1.75E-3 per year. Based on this frequency, the approximate probability that an incipient fire will occur during the 7-day period is 3.4E-5, which represents a low risk and makes the COMPLETION TIME prudent. This compensatory ACTION reduces the likelihood of accidents and the magnitude of potential MAR releases from the facility during accident

Section 47

conditions. (Note: Continued on Next Page) Figure 7b. Example of SAC LCO Bases (Page 2). DOE G 423.1-1B Appendix B 3-18-2015 B-31 CONDITION C, ACTIONs and COMPLETION TIMEs SURVEILLANCE REQUIREMENTS SR 4.1.1 SR 4.1.2 S SR 4.1.3 REFERENCES B3/4.1 MATERIAL-AT-RISK LIMIT Condition C is entered when ACTION B.2 cannot be met within its COMPLETION TIME. ACTION C.1 directs the facility to enter SHUTDOWN within 30 days. This SURVEILLANCE REQUIREMENT requires verification that the facility inventory is not exceeded once a month. This SR is intended to prevent any MAR within facility from exceeding the facility limit. Verification once a month that MAR inventory is within limits is judged to be acceptable given the small turnover rate of MAR. This SURVEILLANCE REQUIREMENT requires verification that the yard inventory is not exceeded once a month. This SR is intended to prevent any MAR within the yard from exceeding the MAR limit. Verification once a month that MAR inventory is within limits is judged to be acceptable given the small turnover rate of MAR. This SURVEILLANCE REQUIREMENT requires an inventory check for all MAR within the facility once a year and verification against the electronic MAR inventory. This SR is intended to reduce likelihood of possible LCO VIOLATION by not knowing the MAR quantity on hand. This SR will reduce the likelihood of exceeding the LCO limit at a specified time. Figure 7b. Example of SAC LCO Bases (Page 3). Appendix B DOE G 423.1-1B B-32 3-18-2015 SAC LCO Example Discussion This LCO is an example of a SAC in an LCO format. It is one of the more common SACs and often appears as the first LCO following the general LCO section. This LCO typically protects an assumption in the accident analysis regarding the maximum quantity and form of MAR involved in bounding accidents. In this example, the primary accident of concern is a fire. The MAR limit in the yard is less than the MAR limit in the facility because less credit can be taken for structural mitigation in the yard. When the MAR limit is exceeded, the initial actions (A) are aimed at reducing the probability of a large fire during the short period (72 hrs) required to reduce the MAR below allowed limits. If this is not possible, the actions restrict the facility to modes in which the probability of an accident is reduced to a minimum. This example reveals the value of a well-drafted bases section to an operator in understanding the LCO itself. The operator may not have the DSA readily available, and in off-normal conditions may not have the time needed to research the technical basis for the control of concern. DOE G 423.1-1B Appendix B 3-18-2015 B-33 3/4.3 FIRE SUPPRESSION SYSTEM 3.3.1 Facility Fire Suppression System LCO: The Facility Fire Suppression System SHALL be OPERABLE as follows: 1. A static pressure > 100 psig at the base of risers. 2. An unobstructed flow path from the water supply to the sprinklers. 3. Sprinkler Heads OPERABLE NOTE A separate entry CONDITION is allowed for each AFFECTED AREA MODE APPLICABILITY: OPERATION and STANDBY MODES AREA APPLICABILITY: Inoperable SSC AFFECTED AREA Sprinkler System #1 North Wing (Sprinkler Coverage Zone 1 supplied by Riser #1) Sprinkler System #2 South Wing (Sprinkler Coverage Zone 2 supplied by Riser #2) PROCESS APPLICABILITY: N/A ACTIONS CONDITION ACTIONS COMPLETION TIME A. Static pressure less than 100 psig at the base of

Section 48

risers. A.1 Establish a FIRE WATCH in the affected AREA. 2 hours and every hour thereafter OR AND Loss of flow path from the water supply to the sprinklers A.2 Conduct a combustible loading inspection in the affected AREA. 24 hours (Note: Continued on Next Page) Figure 8. Example Fire Suppression LCO (Page 1). Appendix B DOE G 423.1-1B B-34 3-18-2015 ACTIONS CONDITION ACTIONS COMPLETION TIME OR AND Sprinkler Heads INOPERABLE A.3 Restore FSS to OPERABLE. 1 week B. ACTIONS and completion times of Condition A not met. B.1 Place the affected AREA in STANDBY MODE. IMMEDIATELY AND B.2 Restore FSS to OPERABLE. 7 days C. ACTIONS and completion times of Condition B not met. C.1 Place affected AREA in SHUTDOWN MODE. 30 days 4.3 SURVEILLANCE REQUIREMENTS: SR Surveillance FREQUENCY 4.3.1 VERIFY that the static gauge pressure is greater than 100 psig at the base of the riser. D 4.3.2 Perform a Fire Suppression System control valve inspection and alignment VERIFICATION M 4.3.3 Perform a main drain test A 4.3.4 Perform a visual inspection of sprinkler heads and adjacent ceiling tiles. A Figure 8. Example Fire Suppression LCO (Page 2). DOE G 423.1-1B Appendix B 3-18-2015 B-35 Facility Fire Suppression System LCO Example Discussion An automatic fire suppression system is often found in TSRs for DOE nuclear facilities. The primary accident of concern in this example is a large fire. The limiting conditions are: A. Minimum riser static pressure – This condition ensures that there is enough water available for the system to perform its safety function. In facilities with dedicated tanks, this limit is often a minimum tank level instead of water quantity. B. Unobstructed flowpath and operable sprinkler heads – This condition ensures that all sprinkler heads are supplied with water and in condition to operate. When these conditions are not met, establishing a fire watch creates a temporary substitute for the system’s safety function. Reducing combustibles further reduces the probability of a large fire. If the system cannot be restored, changing the operating mode may reduce the risk of a fire in the affected area. The surveillances verify that the limits are met. In this case, two surveillances are required for verifying an unobstructed flowpath. The valve line-up is an external surveillance to ensure that valve positions will permit flow. The main drain test is an indirect internal surveillance to ensure unobstructed flow in the piping itself. The Bases are not included in this example for the sake of brevity. Typically, a fire suppression LCO Bases will involve calculations of the maximum fire’s intensity and duration, required sprinkler flow and duration, and references to applicable fire protection standards. Appendix B DOE G 423.1-1B B-36 3-18-2015 3/4.4 EMERGENCY POWER 3.4.1 STANDBY POWER DIESEL GENERATOR LCO 3.4.1: The Standby Power Diesel Generator shall be OPERABLE. MODE APPLICABILITY: All MODES ACTIONS: CONDITION ACTIONS COMPLETION TIME A. The Standby Power Diesel Generator is inoperable. A.1 Restore the Standby Power Diesel Generator to OPERABLE status. 8 Hours SURVEILLANCE REQUIREMENTS: Surveillance FREQUENCY SR 4.4.1.1 Verify that the starting battery [parameters] for the Standby Power Diesel Generator are within [limits]. Monthly SR 4.4.1.2 Perform a start and load test on the Standby Power Diesel Generator. Monthly

Section 49

SR 4.4.1.3 Verify that Standby Power Diesel Generator fuel oil storage tank is filled to greater than or equal to [7] day supply of fuel Within 24 Hours after each diesel engine shutdown SR 4.4.1.4 Verify diesel fuel oil properties of new and stored fuel oil are tested in accordance with, and maintained within the limits of the Diesel Fuel Oil Testing Program. In accordance with the Diesel Fuel Oil Testing Program Figure 9a. Example of Diesel Generator LCO. DOE G 423.1-1B Appendix B 3-18-2015 B-37 B3/4.4 EMERGENCY POWER B3.4.1 STANDBY POWER DIESEL GENERATOR BASES BACKGROUND SUMMARY Backup power is automatically provided by a 300-kW diesel generator. Upon loss of normal power to either Motor Control Centers, MCC-A or MCC-B the transfer switch will automatically start the diesel generator and supply the ventilation exhaust fan. At a full-load fuel consumption the 550-gallon oil tank provides a service time of approximately 20 hours. APPLICATION TO SAFETY ANALYSIS This LCO is applied to ensure that backup power from the Standby Power Diesel Generator is available to support the operation of a ventilation exhaust fan following a loss of normal power. Operation of an exhaust fan is necessary to maintain the exhaust tunnel pressures required by LCO 3.3.1, which are required to protect the offsite public and to prevent and mitigate the consequences of an air reversal. LIMITING CONDITION FOR OPERATION The Standby Power Diesel Generator shall be OPERABLE to ensure that the ventilation exhaust system will be supplied with the necessary backup power during a loss of normal sources of electrical power. To be considered OPERABLE, the Standby Power Diesel Generator shall be supported by an OPERABLE starting battery (SR 4.4.1.1), an OPERABLE fuel supply (SRs 4.4.1.3 and 4.4.1.4), and have successfully undergone a periodic startup and load test (SR 4.4.1.2). MODE APPLICABILITY The Standby Power Diesel Generator is required to be OPERABLE during all MODES because radioactive materials are expected to be present within the Facility and the potential for a loss of normal power is credible. ACTION STATEMENTS A.1 If the Standby Power Diesel Generator is inoperable, Required Action A.1 requires the diesel generator to be restored to OPERABLE status within 8 Hours. The Completion Time of 8 Hours is based on the failure frequency of the loss of AC power to the Facility found in the DSA (Ref. 1). (Note: Continued on Next Page) Figure 9b. Example of Diesel Generator LCO Bases (Page 1). Appendix B DOE G 423.1-1B B-38 3-18-2015 SURVEILLANCE REQUIREMENTS SR 4.4.1.1 The starting batteries on the Standby Power Diesel Generator shall be checked at least Monthly to ensure that the batteries are charged and capable of starting the generator on demand. Inspections shall include verification of proper voltage, proper cell electrolyte level and specific gravity of all cells (Ref. 1). The surveillance frequency is based on the low consequences associated with a loss of power and upon established practices. SR 4.4.1.2 This SR demonstrates that the Standby Power Diesel Generator automatically starts from standby conditions and attains the required voltage and frequency within the specified time (15 seconds) in accordance with guidance provided in Reference 1. After achieving the required voltage and frequency, the diesel generator must supply at least 30% of the rated capacity for at least 30 minutes (Ref. 1). The surveillance

Section 50

frequency is based on the low consequences associated with a loss of power and upon established practices. SR 4.4.1.3 The fuel oil level for the Standby Power Diesel Generator shall be checked within 24 Hours after each diesel engine shutdown to ensure that the fuel tank inventory is available to support [7] days of full load operation. The fuel oil inventory equivalent to a [7] day supply is [400] gallons and is based on a diesel consumption rate for the run time. SR 4.4.1.4 The diesel fuel oil properties of new and stored fuel oil are tested in accordance with, and maintained within the limits of the Diesel Fuel Oil Testing Program. Testing shall include [specific gravity, appearance, particulates, etc. in accordance with national standards]. REFERENCES 1. Documented Safety Analysis – Facility. Figure 9b. Example of Diesel Generator LCO Bases (Page 2). DOE G 423.1-1B Appendix B 3-18-2015 B-39 Standby Power Diesel Generator Example Discussion A standby or emergency diesel generator is often included in the TSRs. This is so because such generators may be supplying emergency power in accident conditions. In such cases, the LCO is covering a support system. The credited safety system in this example is the ventilation system, to which the diesel provides the backup power upon loss of offsite power. The LCO itself is a simple “shall be operable” statement, coupled with a Bases statement containing the specifics of what “operable” means. The LCO describes the surveillances in a general way, with the details provided in the Bases. The concern with this particular type of organization is that the LCO is not stand alone, the bases must be referred to for a full understanding of the requirement, which may hinder response under accident conditions, and that it is essential that the Bases provide the required information to ensure the operator can execute the proper control. Because this is a support system only, many of issues listed above are not as important as they might be for a critical system. Due to this being a support system, the required action is also a simple return to service. While a return to service is an implied default action for any LCO, it is specified in this case to provide a proper time frame, based on the DSA analysis, for a return to service without invoking a TSR violation. Appendix B DOE G 423.1-1B B-40 3-18-2015 5.0 ADMINISTRATIVE CONTROLS 5.1 Responsibility 5.1.1 The Facility Manager shall be responsible for overall safe operation of the FACILITY and shall have control over those activities necessary for safe operation of the FACILITY. The Facility Manager shall delegate, in writing, the succession to this responsibility during any absences. 5.1.2 The Control Room Supervisor (CRS), or in their absence a designated, qualified individual, shall be responsible for the FACILITY command function. As part of this command function, the CRS shall ensure operation of the FACILITY is in accordance with approved TSRs. 5.2 Organization 5.2.1 Organization Lines of authority, responsibility, and communication shall be defined and established for the highest management levels, through intermediate levels, down to and including all operating organization positions. The individuals who train the operating staff, carry out radiological control, or perform Quality Assurance (QA) functions may report to the Facility Manager; however, they shall have sufficient organizational freedom to ensure their

Section 51

independence from operating pressures. 5.2.2 FACILITY Staff The FACILITY staff organization shall be as follows: A current list of FACILITY support personnel shall be maintained. This list should include management, radiation safety, and technical support personnel. The minimum FACILITY shift crew composition shall be as shown in Table 5.2.2-1. Administrative procedures shall be developed and implemented to limit the working hours of staff who perform safety-related functions (e.g., personnel required to meet the minimum shift crew composition). (Note: Continued on Next Page) Figure 10. Example of Administrative Controls (Page 1). DOE G 423.1-1B Appendix B 3-18-2015 B-41 5.2 Organization (continued) 5.2.2 FACILITY Staff (continued) Table 5.2.2-1 [FACILITY] Minimum Shift Crew Composition 1 MODE CRS CRO BOP RC OPERATION 1 3 3 1 STANDBY 1 2 3 1 MAINTENANCE 1 2 3 1 CRS Control Room Supervisor CRO Control Room Operator BOP Balance of Plant Operator/Supervisor RC Radiological Control 1 During a shift, to accommodate unexpected absences of on–duty shift crew members, the shift crew composition may be one less than the minimum requirements for not more than 2 Hours provided immediate action is taken to restore the shift crew composition to within the minimum requirements. This provision is not applicable at the time of shift turnover. 5.3 Staff Qualifications and Training 5.3.1 Qualification A program shall be established to ensure that FACILITY staff who perform safety- related functions meet established qualification requirements for their positions. This program shall adhere to qualification requirements established in accordance with applicable DOE regulations. (Note: Continued on Next Page) Figure 10. Example of Administrative Controls (Page 2). Appendix B DOE G 423.1-1B B-42 3-18-2015 5.3.2 Training An initial training and retraining program for the FACILITY staff shall be established and maintained. This program shall adhere to training requirements established in accordance with applicable DOE regulations. 5.3.3 Violation of the TSR occur as the result of the following: • Exceeding an SL. • Failure to complete an action statement within the required time limit following exceeding an LCS or failure to comply with an LCO. • Failure to perform a surveillance within the required time limit. • Failure to comply with an AC statement. The following are two examples of failure to comply with an LCO: (1) An operation is performed that is prohibited by the mode the facility is in, and (2) A safety system is rendered incapable of performing its safety function (e.g., by maintenance) without entering the applicable LCO. There are two different types of ADMINISTRATIVE CONTROL VIOLATIONS; (1) The first is the failure to comply with a SPECIFIC ADMINISTRATIVE CONTROL requirement in a directive action SAC. A single failure to comply constitutes a TSR VIOLATION. (2) The second type of AC VIOLATION is when the intent of a program included in the ADMINISTRATIVE CONTROLS is not fulfilled. The AC can be directly violated, for example, by not implementing the AC at all. A single non- compliance would not necessarily constitute a TSR VIOLATION. To qualify as a TSR VIOLATION, the failure to meet the intent of the referenced program would need to be significant enough to render the DSA summary invalid. (Note: Continued on Next Page) Figure 10. Example of Administrative Controls (Page 3).

Section 52

DOE G 423.1-1B Appendix B 3-18-2015 B-43 5.7 Procedures, Programs, and Manuals 5.7.2 Programs and Manuals The following programs shall be established, implemented, and maintained. 5.7.2.1 Radiation Protection Program The radiation protection program shall ensure that the radiation exposure of onsite and offsite individuals is maintained within applicable DOE limits and is As Low As Reasonably Achievable (ALARA). The program shall ensure that individual and collective radiation exposures are minimized. Procedures for personnel radiological protection shall be prepared consistent with DOE requirements and shall be approved, maintained, and adhered to for all operations involving personnel radiation exposure. 5.7.2.2 FACILITY Fire Protection Program A FACILITY fire protection program shall be established to minimize the following: • Threats to the public health or welfare resulting from a fire • Undue hazards to site personnel from a fire The fire protection program shall include the following key elements: Fire Prevention • Fire-resistive construction • Control of combustibles • Control of ignition sources • FACILITY inspections • Handling of combustible or flammable liquids and gases • Fire Protection impairment control and compensatory action process Fire Control • Automatic detection/suppression and alarm systems • Fire Watches/Patrols (as necessary) • Proper availability and maintenance of FACILITY firefighting equipment • Identification of firefighting personnel, responsibilities, and training • Fire barriers (as required by the DSA) • 24-hour firefighting coverage (Note: Continued on Next Page) Figure 10. Example of Administrative Controls (Page 4). Appendix B DOE G 423.1-1B B-44 3-18-2015 5.7.2.2 Configuration Management Program A Configuration Management Program shall be established, implemented, and maintained that: • Identifies and documents the technical baseline of Structures, Systems, Components and computer software; • Ensures that changes to the technical baseline are properly developed, assessed, approved, issued, and implemented; • Maintains a system for recording, controlling, and indicating the status of technical baseline documentation on a current basis; and • Controls the configuration of the SSCs specified in the Design Features section of this TSR. Figure 10. Example of Administrative Controls (Page 5). Administrative Controls Example Discussion Section 5.0 is typically the section reserved for administrative controls in the TSRs. This section contains various types of administrative contents which appear under major headings. These normally include purpose, organization & management, technical safety requirements, procedures, review & audit, and facility operating records. These sections generally contain high-level descriptions of the important aspect of these topics, as provided in the example of the organization and management section in this example. The definition of a TSR violation shown would normally appear under the TSR section and might also include subjects such as operations outside the TSR and the TSR review and approval process. The final two sections of the administrative control section would typically be the safety management program section and a specific administrative control section. The safety management program section contains short descriptions of assumed programs usually followed by a bulleted list of any specific elements of

Section 53

those programs that were identified in the DSA. The specific administrative control section would then identify any SACs that were specified in the DSA. It is strongly recommended that SACs be placed in a separate section to provide easier accessibility for operations staff. It is important to note that this section is intended to be a high-level description of the aspects of administrative controls necessary to ensure that the facility is operated within the safety basis, and not a comprehensive description of controls or programs that are implemented in this facility. This example was a short selection of typical content and not intended to indicate an entire administrative control section as that would normally run several pages long. Besides the organization and management section, other general examples were provided in no particular order to give some commonly found information that might appear in the administrative controls and to indicate the level of detail and form that might typically be encountered. DOE G 423.1-1B Appendix B 3-18-2015 B-45 SAC Example [NOTE: This is the directive action SAC that is mentioned in the previous Drum LCOs] 5.7.3 OVERPACKING TRU WASTE Drums with MAR > X00 PE-Ci located in RETRIEVAL AREAS Safety Function: The safety function is to reduce radiological consequences by limiting the amount of MAR affected by thermal or mechanical insults. Control Description: TRU WASTE Drums ≥ X00 PE-Ci retrieved from Trenches SHALL be OVERPACKED prior to retrieval of an additional TRU WASTE drum in the DEFINED AREA. Basis: Many drums that are currently stored in Trenches are known to contain greater than X00 PE-Ci. These drums are not currently OVERPACKED as required by LCO 3.1.7 for above- ground containers, and cannot be OVERPACKED until they have been removed from the trench. Upon removal from an uncovered culvert, any drum with ≥ X00 PE-Ci is OVERPACKED before another drum is retrieved. Depending on the integrity of a retrieved drum with ≥ X00 PE-Ci, OVERPACKING may require the retrieved drum to be OVERPACKED with a single TRU WASTE container (if the retrieved drum itself is of sound integrity) or with two TRU WASTE successive containers (if the retrieved drum is not of sound integrity) Metal TRU WASTE containers with higher PE-Ci values that are OVERPACKED provide a mitigative function by reducing the MAR involved in the event. This control addresses fire, deflagration, loss of confinement, external, and NPH events. Based upon the types of activities that may be conducted within an area (e.g., storage or processing) it was determined that limiting the quantity of radiological material that may be involved in any one process upset is an effective means for controlling the risk. With high MAR containers being OVERPACKED, the material available for release is limited and, therefore, reduces the consequences to the public, collocated workers, and facility workers. Figure 11. Example of Overpack Directive Action SAC. Appendix B DOE G 423.1-1B B-46 3-18-2015 Drum Overpack SAC Example Discussion This example SAC deals with retrieval of waste drums from a trench. The SAC protects DSA assumptions about the maximum MAR exposed to an accident condition. As stated in the text, this SAC is connected to an LCO for drum PE-Ci values and overpacking. This relationship demonstrates how the same SAC may be addressed in both directive action and LCO formats.

Section 54

The relevant LCO provides rules for overpacking and storing any single drum that exceeds ≥ X00 PE-Ci. The SAC requires that no additional drum be retrieved until the high-MAR drum is overpacked. The control is split into two different types of LCO because of the difference in importance to safety. One exposed drum does not create a condition outside the safety analysis. Because this situation is anticipated, it is appropriate to have an LCO that provides the proper required actions and times for responding to this condition. However, uncovering more than one drum violating the condition creates a situation outside the safety analysis. For this reason, the SAC is provided so that any further uncovering of drums before overpacking is a TSR violation. If this control were associated with the complimentary LCO, it would allow a condition where more drums could be uncovered before the drum of concern was overpacked. This is an important point for a TSR writer to consider. Any non-compliance with a directive action SAC is an instant TSR violation, so this type of SAC should be used only when its safety significance justifies a TSR violation. No specific format is required for a directive action SAC; the one provided here is for example purposes only. Providing information on the safety function of the control, while not required, can be very beneficial to the operator. Since directive action SACs do not contain required actions, this additional information can aid the operator in making the appropriate responses to a failure to meet a SAC statement. DOE G 423.1-1B Appendix B 3-18-2015 B-47 DF Example 6.1.3 Type B Containers Type B containers are robust, transportation containers designed to withstand accident conditions without releasing radioactive material. The containers’ specific performance criteria are documented in a Safety Analysis Report for Packaging. Applicability: Type B containers are required to meet their performance criteria when they are sealed, with radioactive waste inside. IN-SERVICE INSPECTIONS FREQUENCY VERIFY that Type B containers have a current inspection sticker or documentation of compliance provided by the manufacturer. Prior to the loading of MAR into a Type B container Basis: The accident analysis assumes a Radiological Inventory Control that specifies the radioactive waste material limits and administratively monitors the amount of radiological inventory within each area to ensure that its limit is not exceeded. This control is credited for fire, explosion, loss of confinement/containment, external, and NPH events. As allowed by DOE-STD-1027, radioactive waste in a sealed Type B container is not included in the radiological inventory. These containers, properly assembled, ensure that their contents are not MAR for postulated accidents. Because Type B containers are either government-supplied equipment (e.g., TRUPACT II or HalfPACT) or commercially supplied equipment (e.g., Model 10-160B), the verification of the performance criteria for these containers is the responsibility of another entity. Ensuring that the containers have a current inspection sticker (or comparable documentation) provides evidence that the containers meet the conditions of their current Certificate of Compliance and their Safety Analysis Report for Packaging, and will perform their safety function as intended. Figure 12. Example of Type B Container DF. Appendix B DOE G 423.1-1B B-48 3-18-2015

Section 55

Type B Container Design Feature Example Discussion This is an example of a design feature (DF) for a type B container used to exclude MAR from the analyzed accident. The DF protects the assumption that the type B containers used are qualified in accordance with the analysis. The format provided here is an example only, though the DF specification and associated ISI are typically specified. Since DFs do not contain required actions, additional information can aid the operator in making the appropriate responses to a failure to meet design specifications or failure to perform an ISI. DOE G 423.1-1B Appendix C 3-18-2015 C-1 Appendix C. Implementation Verification Reviews (IVRs) 1. PURPOSE This appendix describes suggested approaches for performing independent implementation verification reviews of all controls designed to implement the Safety Basis. Such controls include TSRs and their associated DSA assumptions and commitments. The purpose of an IVR is to independently confirm the proper implementation of new or revised safety basis controls. Independence of the review adds an additional layer of defense in depth and is a common practice standard in the commercial nuclear power industry. IVRs support meeting the 10 C.F.R. §830.201 requirement for operating contractors for Hazard Category 1, 2, or 3 nuclear facilities to “perform work in accordance with the facility safety basis” and quality assurance (QA) requirements found in 10 C.F.R. Part 830, Subpart A. Special emphasis is placed on 10 C.F.R. §830.122(j), Criterion 10, which mandates “independent assessments to measure item and service quality, to measure the adequacy of work performance, and to promote improvement.” 2. APPLICABILITY AND SCOPE OF APPENDIX This appendix is intended for use by DOE and DOE contractor organizations responsible for Hazard Category 1, 2 and 3 nuclear facilities. It applies to hazard controls identified in TSRs and their associated DSA assumptions and commitments. This appendix is focused on IVRs performed by operating contractors, but also provides guidance for DOE’s oversight of IVRs. The scope of this appendix includes initial verification of safety basis controls for new DSAs and DSA revisions (both major and minor) as well as periodic review of the continued effective implementation of safety basis controls. The appendix is limited to independent verification of the implementation of safety basis hazard controls. It does not address the review of the safety basis documentation itself. Guidance for review of such documentation can be found in DOE Guide 421.1-2, Implementation Guide for Use in Developing Documented Safety Analyses to Meet Subpart B of 10 C.F.R. 830. 3. WHEN TO CONDUCT AN IVR 3.1. Initial IVRs The initial contractor IVR should follow the initial implementation of the new safety basis. The IVR should be completed prior to the contractor declaring readiness to commence operation under the new controls. The IVR may be a prerequisite to a Readiness Review required in accordance with DOE Order 425.1D, Verification of Readiness to Startup or Restart Nuclear Facilities. The IVR should not be part of, or a substitute for any part of, a required Readiness Review. Prior to commencing the IVR, contractor line management should ensure that the safety basis has been fully implemented. This means that safety basis controls are implemented to the point Appendix C DOE G 423.1-1B C-2 3-18-2015

Section 56

that independent verification of their efficacy is practical. The following are attributes of a fully implemented safety basis:  All requirements, assumptions, and commitments in the TSRs and DSA have been identified and implementing controls have been developed.  Safety basis controls have been incorporated into implementing procedures and work control documents.  Implementing procedures are executable as written.  Document configuration control procedures are fully developed and implemented such that any changes to implementing procedures will receive an appropriate USQ review.  A DOE-approved USQ procedure has been implemented.  Operators and facility personnel are trained and knowledgeable on the new controls and their relationship to the safety basis.  Required surveillance activities and inspections are complete.  Surveillances correctly test or verify assumptions and requirements of the safety basis.  Physical changes associated with the safety basis change have been made and tested under a rigorous startup test process to verify operability in accordance with the design basis.  Configuration items have been updated to reflect safety basis changes, (e.g., drawings, design documents, software).  Labeling of components identified in updated safety systems has been completed.  Inventory control procedures have been evaluated for consistency with the new safety basis.  Process instruments, tools, and measuring and test equipment have been calibrated and tested. Contractors often create and utilize a flow-down matrix to support proper implementation of safety basis controls. An example of such a matrix appears below: TSR Requirement Implementing Procedure or Policy 5.7.1 Restricted Public Access to Transfer Route SAC: Public vehicular access to the transfer route SHALL be restricted. P&T-WI-003, Trip Commander Instructions 5.7.2 Combustible Material Limits SAC: The transfer vehicle cargo storage area SHALL be inspected and combustible materials that do not support normal ongoing transfer operations SHALL be removed prior to transfer. P&T-WI-002, Driver Instructions DOE G 423.1-1B Appendix C 3-18-2015 C-3 3.2 IVRs Following Safety Basis Changes Following a safety basis change, an IVR should be performed and any pre-implementation findings closed prior to commencing operation under the revised safety basis. The breadth of the IVR should encompass the entire safety basis change, which means that all safety basis controls that have been created or changed should be verified as fully implemented. However, the depth and level of detail and the degree of formality of the review can be graded as follows:  “Major” Changes – Multiple changes, physical alterations of credited components, or changes in methods used to demonstrate operability of TSR hazard controls. Major changes are those that could potentially affect the ability to comply with the safety basis.  “Moderate” Changes – Safety basis changes that may warrant review prior to use. Moderate changes are more complex than edito

Something wrong with this record? Tell us