DOE O 422.1 Chg 2 (Admin Chg), Conduct of Operations
Functional areas: Administrative Change, Conduct of Operations, Safety, Security, Property Management
This Order defines the requirements for establishing and implementing Conduct of Operations Programs at Department of Energy (DOE), including National Nuclear Security Administration (NNSA), facilities and projects. Admin Chg 2, dated 12-3-14, supersedes Admin Chg 1. Superseded by DOE O 422.1 Chg3 (MinChg).
Supersedes:
DOE O 422.1 Chg 1 (AdminChg), Conduct of Operations on Dec 03, 2014
Superseded By:
DOE O 422.1 Chg 3 (MinChg), Conduct of Operations on Oct 04, 2019
Certified By:
Version history and related documents
Superseded by
A newer version replaces this document.
- DOE O 422.1 Chg 3 (MinChg)Conduct of Operations (Oct 04, 2019)
Supersedes
Earlier documents this one replaced.
- DOE O 422.1 Chg 1 (AdminChg)Conduct of Operations (Dec 03, 2014)
Document text
Text extracted from the attached file. Refer to the original document for the authoritative version.
Section 1
U.S. Department of Energy ADMIN CHANGE
Washington, D.C.
Chg 2: 12-3-2014
SUBJECT: ADMINISTRATIVE CHANGE TO DOE O 422.1, CONDUCT OF OPERATIONS
1. EXPLANATION OF CHANGES. To update for organization change from Office of
Health, Safety and Security to Office of Environment, Health, Safety and Security and to
update references for certification.
2. LOCATIONS OF CHANGES:
Page Paragraph Changed To
Title Office of Health, Safety and
Security
Office of Environment, Health, Safety
and Security
1 3.a.(1) … DOE Technical Standard
(DOE-STD) 1027, Hazard….
…DOE Technical Standard (DOE-
STD) 1027-92(CH-1), Hazard...
4 5.b Office of Health, Safety and
Security
Office of Environment, Health, Safety
and Security
4 5.c. New- inserted between former
5.b.(2) and 5.b.(3)
5.c. Office of Enterprise Assessments
4 5.c. (3) Plans and conducts
assessments to determine …
Plans and conducts assessments to
determine… (remove number)
5 6.c DOE O 205.1B, Department of
Energy Cyber Security Program,
dated 5-16-11.
DOE O 205.1B Chg 3, Department of
Energy Cyber Security Program,
dated 5-16-11
5 6.g DOE O 232.2, Occurrence
Reporting and Processing of
Operations Information, dated 8-
30-11.
DOE O 232.2 Admin Chg 1,
Occurrence Reporting and Processing
of Operations Information, dated 8-
30-11.
6 6.j DOE O 470.4B, Safeguards and
Security Program, Change 1,
dated 2-15-13.
DOE O 470.4B Admin Chg 1,
Safeguards and Security Program,
dated 7-21-11.
6 6.k DOE-STD-1027 (CH-1), Hazard
Categorization and Accident
Analysis Techniques for
Compliance with DOE Order
5480.23, Nuclear Safety Analysis
Reports.
DOE-STD-1027-92 (CH-1), Hazard
Categorization and Accident Analysis
Techniques for Compliance with DOE
Order 5480.23, Nuclear Safety
Analysis Reports.
DOE O 422.1 Chg 2
Attachment 2 to DOE Order 422.1
Page Paragraph Changed To
5 2.g Operators should integrate related
requirements found in DOE O
232.2, Occurrence Reporting and
Processing of Operations
Information, dated 8-30-11; DOE
O 151.1C, Comprehensive
Emergency Management System,
dated 11-2-05; and DOE O
205.1B, Department of Energy
Cyber Security Program,
dated 5-16-11, and applicable
regulatory notification
requirements.
Operators should integrate related
requirements found in DOE O 232.2
Admin Chg 1, Occurrence Reporting
and Processing of Operations
Information, dated 8-30-11; DOE O
151.1C, Comprehensive Emergency
Management System, dated 11-2-05;
DOE O 470.4B Admin Chg 1,
Safeguards and Security Program,
dated 7-21-11, and DOE O 205.1B
Chg 3, Department of Energy Cyber
Security Program, dated 5-16-11, and
applicable regulatory notification
requirements.
AVAILABLE ONLINE AT: INITIATED BY:
www.directives.doe.gov Office of Environment, Health, Safety and Security
U.S. Department of Energy ORDER
Washington, D.C.
Approved: 6-29-2010
Chg 1: 6-25-2013
Chg 2: 12-3-2014
Certified: 12-3-2014
SUBJECT: CONDUCT OF OPERATIONS
1. PURPOSE. The objective of this Order is to define the requirements for establishing and
implementing Conduct of Operations Programs at Department of Energy (DOE),
including National Nuclear Security Administration (NNSA), facilities and projects. A
Conduct of Operations Program consists of formal documentation, practices, and actions
implementing disciplined and structured operations that support mission success and
promote worker, public, and environmental protection. The goal is to minimize the
Section 2
likelihood and consequences of human fallibility or technical and organizational system
failures. Conduct of Operations is one of the safety management programs recognized in
the Nuclear Safety Rule [Title 10 Code of Federal Regulations (CFR) Part 830, Nuclear
Safety Management], but it also supports safety and mission success for a wide range of
hazardous, complex, or mission-critical operations, and some conduct of operations
attributes can enhance even routine operations. It supports the Integrated Safety
Management (ISM) System by providing concrete techniques and practices to
implement the ISM Core Functions of Develop and Implement Hazard Controls and
Perform Work Within Controls. It may be implemented through facility policies,
directives, plans, and safety management systems and need not be a stand-alone
program.
The term “operations” encompasses the work activities of any facility or organization,
from building infrastructure, to print shops and computer centers, to scientific research,
and to nuclear facilities. While many hazards can be dealt with through engineered
solutions, people still have to perform operations, and they can and do make mistakes.
The purpose of this Order is to ensure that management systems are designed to
anticipate and mitigate the consequences of human fallibility or potential latent
conditions and to provide a vital barrier to prevent injury, environmental insult or asset
damage, and to promote mission success.
2. CANCELLATION. DOE O 5480.19, Conduct of Operations Requirements for DOE
Facilities, dated 7-9-90.
Cancellation of a directive does not, by itself, modify or otherwise affect any contractual
or regulatory obligation to comply with the directive. Contractor Requirements
Documents (CRDs) that have been incorporated into a contract remain in effect
throughout the term of the contract unless and until the contract or regulatory
commitment is modified to either eliminate requirements that are no longer applicable
or substitute a new set of requirements.
DOE O 422.1
http://www.directives.doe.gov/
2 DOE O 422.1
6-29-2010
3. APPLICABILITY.
a. Departmental Applicability. This Order applies to all Departmental elements
involved in operation of
(1) DOE Hazard Category 1, 2, and 3 nuclear facilities per DOE
Technical Standard (DOE-STD) 1027-92 Change 1, Hazard
Categorization and Accident Analysis Techniques for Compliance
with DOE Order 5480.23, Nuclear Safety Analysis Reports.
(2) Accelerator, explosives, laser, nanotechnology, biohazard,
chemical, or other facilities only when designated by DOE Line
Management.
(3) The Administrator of the National Nuclear Security Administration
(NNSA) must assure that NNSA employees comply with their
responsibilities under this directive. Nothing in this directive will
be construed to interfere with the NNSA Administrator’s authority
under section 3212(d) of Public Law (P.L.) 106-65 to establish
Administration-specific policies, unless disapproved by the
Secretary.
b. DOE Contractors. Except for the equivalencies/exemptions in paragraph 3.c, the
Contractor Requirements Document (CRD), Attachment 1, sets forth
requirements of this Order that will apply to contracts that include the CRD.
(1) The CRD must be included in contracts that involve operation of
DOE Hazard Category 1, 2, or 3 nuclear facilities.
(2) The CRD must be included in other contracts that involve
operation of accelerator, explosives, laser, nanotechnology,
Section 3
biohazard, chemical, or other facilities only when designated by
DOE Line Management.
c. Equivalencies/Exemptions for DOE O 422.1. Equivalencies and exemptions to
this Order are processed in accordance with DOE O 251.1C, Departmental
Directives Program. Central Technical Authority (or designee) concurrence is
required for both exemptions and equivalencies to this Order for nuclear facilities.
(1) Equivalency. In accordance with the responsibilities and authorities
assigned by Executive Order 12344, codified at 50 USC sections 2406 and
2511 and to ensure consistency throughout the joint Navy/DOE Naval
Nuclear Propulsion Program, the Deputy Administrator for Naval
Reactors (Director) will implement and oversee requirements and
practices pertaining to this Directive for activities under the Director's
cognizance, as deemed appropriate.
DOE O 422.1 3
6-29-2010
(2) Exemption. In accordance with Section 302 of the Department of Energy
Organization Act (Public Law 95-91), the Secretary operates and
maintains the Power Marketing Administration (PMA) electric power
transmission systems by and through the PMA Administrators. The PMAs
have in place operations management programs which are geared to the
special needs of utility operations, are responsive to coordinated multi-
utility system requirements, and are in conformance with prudent utility
practice. In view of the unique nature of the Administrators' obligations to
meet their statutory and public utility responsibilities for the safety,
security, and reliability of electric power transmission and of their legal
and contractual obligation, the Administrators shall determine the
appropriate operations management program for their facilities, which will
include consideration of appropriate parts of the criteria set forth by this
Order.
(3) Exemption. This Order does not apply to facilities that are subject to
regulation by other Federal agencies such as the U.S. Nuclear Regulatory
Commission.
4. REQUIREMENTS. The general approach to implementing this Order is for contractors
(or DOE organizations in the case of Government owned-Government operated (GO/GO)
facilities) to develop, for DOE line management approval, documentation demonstrating
implementation of the requirements in the CRD (or Attachment 2 for GO/GOs). DOE
line management means the federal officials such as Secretarial Officers and Heads of
Field Elements responsible for DOE facilities and operations. It is not necessary to
develop new documents to demonstrate implementation, but at a minimum to provide a
Conduct of Operations Matrix, which is a list of CRD requirements, citing the specific
documentation (e.g., procedure, manual) that implements each item, or providing
justification for each item that is not implemented.
a. DOE line management must determine which facilities, other than Hazard
Category 1, 2, and 3 nuclear facilities, require implementation of this Order,
considering the hazards, consequences of operational mishaps, and impact of
disruptions to mission. Hazard Category 1, 2, and 3 nuclear facilities are subject
to this Order automatically.
b. DOE line management must provide appropriate oversight of conduct of
operations. Field organizations must assign DOE facility representatives to
oversee conduct of operations in accordance with DOE–STD-1063-2006, Facility
Representatives.
c. DOE line management must review and approve documentation prepared by the
Section 4
contractor demonstrating conformance to the requirements in the CRD.
d. When reviewing the documentation cited in paragraph 4.c. above, DOE line
management must refer to this Order and should be familiar with the cited DOE
Technical Standards that detail applicable good practices for each of the specific
requirements areas in the CRD.
4 DOE O 422.1
6-29-2010
e. DOE line management must review and approve the documentation cited in
paragraph 4.c. above at its inception, when changes in conditions require changes
in the documentation, and at least every three years or as directed by the field
element manager. It is not intended that minor administrative changes and
corrections or routine updates to cited documents would require new DOE
approval.
f. For activities and programs at GO/GO facilities, DOE line management must
perform the requirements in Attachment 2 and the review and approval per
paragraphs 4.c., d., and e. above. Review and approval must be performed by
officials in a management tier above the organization performing Attachment 2
items
g. Full implementation of the requirements in this Order must be accomplished
within one year of its issuance, unless a different implementation schedule is
approved by the Program Secretarial Officer with concurrence of the Central
Technical Authority per DOE O 410.1, Central Technical Authority
Responsibilities Regarding Nuclear Safety Requirements.
5. RESPONSIBILITIES.
a. Program Secretarial Offices (PSOs).
(1) Determine the applicability of this Order to those facilities under their
cognizance that are other than Hazard Category 1, 2, or 3 nuclear
facilities.
(2) For GO/GO activities under their cognizance, approve or designate the
approval authority for conduct of operations documentation prepared in
accordance with Attachment 2.
b. Office of Environment, Health Safety and Security.
(1) Develops formal interpretations of the requirements of this Order.
(2) Develops, promulgates, and maintains conduct of operations policy,
standards, and guidance materials, and conducts training, as necessary, for
implementing the requirements of this Order.
c. Office of Enterprise Assessments.
Plans and conducts assessments to determine compliance with the requirements of
this Order, in accordance with DOE O 227.1, Independent Oversight Program,
dated 8-30-11.
DOE O 422.1 5
6-29-2010
d. Heads of Field Elements.
1
(1) Notify contracting officers to incorporate the CRD into the affected
contracts (considering the hazards and mission impact of the operations)
via the Laws, regulations, and DOE directives clause (DEAR 970.5204-
2) for those contracts that contain this clause. For contracts that do not
contain DEAR 970.5204-2, request that the contracting officer attempt
to get the CRD incorporated into the contract via a contract
modification. Notify contracting officers in advance to include the
requirements of the CRD in the terms and conditions of any request for
proposals for any new contracts.
(2) Provide direction and oversight for the development and
implementation of conduct of operations applicability matrices,
manuals, plans, procedures, and programs consistent with the provisions
of this Order. Perform oversight of the contractor’s conduct of
operations performance.
(3) Review and approve the documentation prepared by the contractor
demonstrating conformance to the specific requirements stated in the
CRD.
Section 5
(4) Assign DOE facility representatives to oversee conduct of operations in
accordance with DOE-STD-1063-2006, Facility Representatives.
e. Contracting Officers.
Modify contracts to incorporate the Contractor Requirements Document.
6. REFERENCES.
a. Title XXXII of P.L. 106-65, National Nuclear Security Administration Act, as
amended, which established a separately organized agency within the Department
of Energy.
b. DOE O 151.1C Comprehensive Emergency Management System, dated 11-2-05.
c. DOE O 205.1B Chg 3, Department of Energy Cyber Security Program,
dated 5-16-11
d. DOE O 225.1B, Accident Investigations, dated 3-4-11
e. DOE O 226.1B, Implementation of Department of Energy Oversight Policy,
dated 4-25-11.
1
Operations offices, service centers, site offices, area offices, field offices, project management offices, and regional
offices of federally staffed laboratories.
6 DOE O 422.1
6-29-2010
f. DOE O 227.1, Independent Oversight Program, dated 8-30-11
g. DOE O 232.2 Admin Chg 1, Occurrence Reporting and Processing of Operations
Information, dated 8-30-11.
h. DOE O 251.1C, Departmental Directives System, dated 1-15-09
i. DOE O 410.1, Central Technical Authority Responsibilities Regarding Nuclear
Safety Requirements, dated 8-28-07.
j. DOE O 470.4B Admin Chg 1, Safeguards and Security Program, dated 7-21-11.
k. DOE-STD-1027-92 (CH-1), Hazard Categorization and Accident Analysis
Techniques for Compliance with DOE Order 5480.23, Nuclear Safety Analysis
Reports.
l. DOE-STD-1029-92 (CH-1), Writer’s Guide for Technical Procedures.
m. DOE-STD-1030-96, Guide to Good Practices for Lockouts and Tagouts.
n. DOE-STD-1031-92 (CH-1), Guide to Good Practices for Communications.
o. DOE-STD-1032-92 (CH-1), Guide to Good Practices for Operations
Organization and Administration.
p. DOE-STD-1033-92 (CH-1), Guide to Good Practices for Operations and
Administration Updates Through Required Reading.
q. DOE-STD-1034-93 (CH-1), Guide to Good Practices for Timely Orders to
Operators.
r. DOE-STD-1035-93 (CH-1), Guide to Good Practices for Logkeeping.
s. DOE-STD-1036-93 (CH-1), Guide to Good Practices for Independent
Verification.
t. DOE-STD-1037-93 (CH-1), Guide to Good Practices for Operations Aspects of
Unique Processes.
u. DOE-STD-1038-93 (CH-1), Guide to Good Practices for Operations Turnover.
v. DOE-STD-1039-93 (CH-1), Guide to Good Practices for Control of Equipment
and System Status.
w. DOE-STD-1040-93 (CH-1), Guide to Good Practices for Control of On-Shift
Training.
x. DOE-STD-1041-93 (CH-1), Guide to Good Practices for Shift Routines and
Operating Practices.
DOE O 422.1 7
6-29-2010
y. DOE-STD-1042-93 (CH-1), Guide to Good Practices for Control Area Activities.
z. DOE-STD-1043-93 (CH-1), Guide to Good Practices for Operator Aid Postings.
aa. DOE-STD-1044-93 (CH-1), Guide to Good Practices for Equipment and Piping
Labeling.
bb. DOE-STD-1045-93 (CH-1), Guide to Good Practices for Notifications and
Investigation of Abnormal Events.
cc. DOE-STD-1063-2006, Facility Representatives.
dd. National Fire Protection Association (NFPA) 70E: Standard for Electrical Safety
in the Workplace.
ee. Title 29, Code of Federal Regulations Part 1910, Occupational Safety and Health
Standards.
ff. Title 29, Code of Federal Regulations Part 1926, Safety and Health Regulations
for Construction.
7. DEFINITIONS.
a. At-the-Controls Area. A designated area where special access and controls are
Section 6
necessary. Examples are the space in front and to the immediate sides of a control
panel, control station, computer terminal, etc., or the area where facility, work
station, or experiment controls (e.g., switches, knobs, buttons) are located.
(DOE-STD-1042-93 (CH-1))
b. Certification. The process by which facility management provides written
endorsement of the satisfactory achievement of qualification of a person for a
position. (DOE O 426.2)
c. Concurrent Dual Verification. A method of checking an operation, an act of
positioning, or a calculation, in which the verifier independently observes and/or
confirms the operation or calculation. (DOE-STD-1036-93 (CH-1))
d. Conduct of Operations Program. The formal documentation, practices, and
actions implementing disciplined and structured operations that support mission
success and ensure worker, public, and environmental protection. The program
goal is to minimize the likelihood and consequences of human fallibility or
technical and organizational system failures.
e. Control Area. The physical area (e.g., room, booth, desk) where the facility or
portions of the facility operations are monitored and controlled. (DOE-STD-1042-
93 (CH-1))
f. Facility Representative. For each major facility or group of lesser facilities, an
individual assigned responsibility by the field element manager (or designee) for
8 DOE O 422.1
6-29-2010
monitoring the safety performance of the facility and its operations. This
individual is the primary point of contact with the contractor for operational and
safety oversight and is responsible to the facility’s DOE line manager.
(DOE-STD-1063-2006)
g. Independent Verification. The act of checking, by a separate qualified person, that
a given operation or component position conforms to established criteria.
(DOE-STD-1036-93 CH-1))
h. Interrelated Processes. Those processes or activities that can affect operations, but
are under the control of persons other than the affected operators, such as shared
support systems or special testing.
i. Operations. The general term to encompass the work activities accomplished by
the facility or project. Examples include, but are not limited to, operating science
and technology machines, operating equipment, construction, decontamination
and decommissioning, dismantlement, environmental characterization and
monitoring activities, waste handling, research and development, maintenance,
and laboratory analysis activities.
j. Operator Aids. Approved, posted information used to assist personnel in
performing a task. Examples are copies of procedures (portion or pages thereof),
system drawings, information tags, curves, graphs, or prints.
(DOE-STD-1043-93 (CH-1))
k. Qualification. Education, experience, training, examination, and any special
requirements necessary to perform assigned responsibilities for a given position.
(DOE O 426.2)
l. Shift. The normal period of work for an individual or group, e.g. 8:00am to 5:00
pm. (DOE STD 1041-93 (CH-1)
8. CONTACT. Questions concerning this Order should be addressed to the Office of
Nuclear Safety at 301-903-333.
BY ORDER OF THE SECRETARY OF ENERGY:
DANIEL B. PONEMAN
Deputy Secretary
DOE O 422.1 Attachment 1
6-29-2010 Page 1 (and 2)
Attachment 1
CONTRACTOR REQUIREMENTS DOCUMENT
DOE O 422.1, Conduct of Operations
Regardless of the performer of the work, the contractor is responsible for complying with the
Section 7
requirements of this CRD. The contractor is responsible for flowing down the requirements of
this CRD to subcontractors at any tier to the extent necessary to ensure the contractor’s
compliance with the requirements.
Contractors must implement the requirements set forth in Attachment 2, Conduct of Operations
Program Requirements, which provides program requirements applicable to contracts in which
this CRD is inserted.
DOE O 422.1 Attachment 2
6-29-2010 Page 1
Attachment 2
PROGRAM REQUIREMENTS
This Attachment provides Conduct of Operations program requirements applicable to contracts
in which the CRD (Attachment 1 to DOE O 422.1) is inserted. This Attachment also provides the
program requirements applicable to Government Owned-Government Operated (GO/GO)
facilities subject to DOE O 422.1 Paragraph 4, Requirements.
In Paragraph 2, Specific Requirements, of this Attachment, each topic references the related
DOE Technical Standard to provide further explanatory material and examples, but not
requirements. Each topical area of the specific requirements is expanded into detailed program
attributes in Appendix A, Detailed Conduct of Operations Matrix. Throughout this Attachment,
the term “operator” means the contractor or federal entity or organization responsible for
operation of a facility.
1. GENERAL REQUIREMENTS.
a. Conduct of Operations Program Development:
(1) For Hazard Category 1, 2, and 3 nuclear facilities, the operator must
develop and implement a conduct of operations program using the specific
requirements in paragraph 2 below and the attributes of the Detailed
Conduct of Operations Matrix in Appendix A, unless a different set of
detailed attributes is approved by the Program Secretarial Officer with
concurrence of the Central Technical Authority per DOE O 410.1, Central
Technical Authority Responsibilities Regarding Nuclear Safety
Requirements, dated 8-28-07.
(2) For other than Hazard Category 1, 2, and 3 nuclear facilities, DOE line
management may specifically direct development and implementation of a
conduct of operations program using the specific requirements in
paragraph 2 below, and, if further directed by DOE line management, the
detailed attributes of Appendix A.
(3) Implementation is demonstrated by providing, at a minimum, a Conduct of
Operations Matrix, consisting of entries for each specific requirement in
paragraph 2 [and, if required by 1.a.(1) or 1.a.(2) above, each detailed
attribute in Appendix A], with either a citation of the specific
documentation (e.g., procedure, manual) that implements the item, or a
justification for each item that is not implemented. This justification is not
considered an “exemption” under the DOE O 251.1C, Departmental
Directives Program and does not invoke that process. The Conduct of
Operations Matrix may be provided through direct use of Appendix A or
by use of equivalent documents or electronic systems.
Attachment 2 DOE O 422.1
Page 2 6-29-2010
b. The operator must obtain DOE line management approval of the Conduct of
Operations Matrix or other documentation demonstrating conformance with the
specific requirements.
c. An operator with an approved Conduct of Operations Matrix previously submitted
in accordance with DOE O 5480.19 must submit either an addendum or page
changes to the matrix to reflect the changes made as a result of the
implementation of this Attachment. If no changes are needed, a memorandum to
Section 8
that effect may be submitted as the addendum. Changes or requests for time
extensions must be submitted to DOE for approval within 90 days from the date
this Attachment becomes binding.
d. The operator must review, update, and obtain approval of documentation
demonstrating conformance at inception, when changes in conditions require
changes in the documentation, and at least every three years or as directed by
DOE. If after the review, no changes are required to the documentation
demonstrating conformance to the requirements, a memorandum to that effect
may be submitted. It is not intended that minor administrative changes and
corrections or routine updates to cited documents would require new DOE
approval.
2. SPECIFIC REQUIREMENTS.
a. Organization and Administration. (DOE-STD-1032-92 (CH-1), Guide to Good
Practices for Operations Organization and Administration
The operator must establish policies, programs, and procedures that define an
effective operations organization, including the following elements:
(1) organizational roles, responsibilities, authority, and accountability;
(2) adequate material and personnel resources to accomplish operations;
(3) monitoring and self-assessment of operations (See DOE O 226.1B,
Implementation of Department of Energy Oversight Policy, dated4-25-11);
(4) management and worker accountability for the safe performance of work;
(5) management training, qualification, succession, and, when appropriate,
certification;
(6) methods for the analysis of hazards and implementation of hazard controls
in the work planning and execution process; and
(7) methods for approving, posting, maintaining, and controlling access to
electronic operations documents (procedures, drawings, schedules,
maintenance actions, etc.) if electronic documents are used.
DOE O 422.1 Attachment 2
6-29-2010 Page 3
b. Shift Routines and Operating Practices. (DOE-STD-1041-93 (CH-1), Guide to
Good Practices for Shift Routines and Operating Practices)
The operator must establish and implement operations practices to ensure that
shift operators are alert, informed of conditions, and operate equipment properly,
addressing the following elements:
(1) prompt notification to operating personnel and supervisors of changes in
the facility status, abnormalities, or difficulties encountered in performing
assigned tasks;
(2) adherence by operating personnel and other workers to established safety
requirements;
(3) awareness by operating personnel of the status of equipment through
inspection, conducting checks, and tours of equipment and work areas;
(4) procedures for completing round sheets or inspection logs, responding to
abnormal conditions, and periodic supervisory reviews of round sheets or
inspection logs;
(5) procedures for protecting operators from personnel hazards, e.g. chemical,
radiological, laser, noise, electromagnetic, toxic, or nano-scale materials;
(6) prompt response to instrument indications, including the use of multiple
indications to obtain parameters;
(7) procedures for resetting protective devices;
(8) authorization to operate facility equipment;
(9) designating shift operating bases and providing equipment for them; and
(10) professional and disciplined operator performance of duties.
c. Control Area Activities. (DOE-STD-1042-93 (CH-1), Guide to Good Practices
for Control Area Activities)
The operator must establish and implement operations practices that promote
Section 9
orderly, business-like control area operations and address the following elements:
(1) control-area access;
(2) formality and discipline in the control and at-the-controls areas;
(3) surveillance of control panels and timely response to determine and
correct the cause of abnormalities/out-of-specification conditions;
Attachment 2 DOE O 422.1
Page 4 6-29-2010
(4) limitation of the number of concurrent evolutions and duties, and
(5) authorization to operate control area equipment.
d. Communications. (DOE-STD-1031-92 (CH-1), Guide to Good Practices for
Communications)
The operator must establish and implement operations practices that ensure
accurate, unambiguous communications among operations personnel and address
the following elements:
(1) provision of communications systems for emergency and normal
operations;
(2) administrative control of communications equipment, including
authorization to use the public address system and allowable locations and
purposes for radio use;
(3) methods for control areas to contact operators and supervisors;
(4) use of abbreviations and acronyms; and
(5) use of oral instructions and communications, including use of repeat-backs
and sender/receiver identifications.
e. On-shift Training. (DOE-STD-1040-93 (CH-1), Guide to Good Practices for
Control of On-Shift Training)
The operator must establish and implement operations practices that control on-
shift training of facility operators, prevent inadvertent or incorrect trainee
manipulation of equipment, and address the following elements:
(1) on-shift training program;
(2) authorization and documentation of training activities;
(3) supervision and control of personnel under instruction by qualified
personnel; and
(4) facility conditions and controls for conducting training during operational
activities, including suspension of training during unanticipated or
abnormal events.
f. Investigation of Abnormal Events, Conditions, and Trends. (DOE-STD-1045-93
(CH-1), Guide to Good Practices for Notifications and Investigation of Abnormal
Events)
DOE O 422.1 Attachment 2
6-29-2010 Page 5
The operator must establish and implement operations practices for investigating
events to determine their impact and prevent recurrence, addressing the following
elements:
(1) specific events requiring investigation, and criteria for identifying other
events or conditions to be investigated;
(2) designation of investigators and their training and qualification;
(3) investigation process and techniques;
(4) causal analysis and corrective action determination;
(5) event investigation reporting, training, and trending; and
(6) response to known or suspected sabotage.
Operators should integrate related requirements in DOE O 232.2, Occurrence
Reporting and Processing of Operations Information, dated 8-30-11, and
DOE O 225.1B, Accident Investigations, dated 3-4-11.
g. Notifications. (DOE-STD-1045-93 (CH-1), Guide to Good Practices for
Notifications and Investigation of Abnormal Events)
The operator must establish and implement operations practices to ensure
appropriate event notification for timely response, addressing the following
elements:
(1) procedures for internal, DOE, and external notifications, including events,
persons to be notified, persons responsible to make notifications, contact
information, and recordkeeping; and
(2) communications equipment for notifications.
Operators should integrate related requirements found in DOE O 232.2 Admin
Section 10
Change 1, Occurrence Reporting and Processing of Operations Information,
dated 8-30-11; DOE O 151.1C, Comprehensive Emergency Management System,
dated 11-2-05; DOE O 470.4B Admin change 1, Safeguards and Security
Program, dated 7-21-11; and DOE O 205.1B Change 3, Department of Energy
Cyber Security Program, dated 5-16-11, and applicable regulatory notification
requirements.
h. Control of Equipment and System Status. (DOE-STD-1039-93 (CH-1), Guide to
Good Practices for Control of Equipment and System Status)
The operator must establish and implement operations practices for initial
equipment lineups and subsequent changes to ensure facilities operate with
known, proper configuration as designed, addressing the following elements:
Attachment 2 DOE O 422.1
Page 6 6-29-2010
(1) authorization for, and awareness of, equipment and system status changes;
(2) initial system alignment, and maintaining control of equipment and system
status through startup, operation, and shutdown, and documentation of
status;
(3) use and approval of lockouts and tagouts for administrative control of
equipment status (see also paragraph 2.i);
(4) operational limits compliance and documentation;
(5) management of equipment deficiencies, maintenance activities, post-
maintenance testing, and return to service;
(6) awareness and documentation of control panel and local alarm issues;
(7) control of temporary equipment modifications and temporary systems; and
(8) configuration control and distribution of engineering documents.
i. Lockout and Tagouts. (DOE-STD-1030-96, Guide to Good Practices for Lockouts
and Tagouts)
(1) The operator must establish and implement operations practices that
address the following elements for the installation and removal of
lockout/tagouts for the protection of personnel:
(a) procedures, roles and responsibilities associated with the
development, documentation, review, installation, and removal of
a lockout/tagout;
(b) compliance with Occupational Safety and Health Administration
Rules, 29 CFR Part 1910 and/or 29 CFR Part 1926, requirements
for the protection of workers using Lockout/Tagout;
(c) compliance with National Fire Protection Association Standard
70E electrical safety requirements using lockout/tagout;
(d) description and control of the tags, locks, lockboxes, chains, and
other components utilized for the lockout/tagout program; and
(e) training and qualification in lockout/tagout and special
considerations for DOE facilities, e.g., operational limitations, or
seismic issues from the mass of locks or chains.
(2) The operator must establish and implement operations practices that
address the following elements for the installation and removal of caution
tags for equipment protection or operational control:
DOE O 422.1 Attachment 2
6-29-2010 Page 7
(a) roles and responsibilities associated with the development,
documentation, review, installation, and removal of caution tags to
convey operational information or equipment alignments for
protection of equipment;
(b) description and control of the tags; and
(c) measures to prevent relying on caution tags for personnel
protection.
j. Independent Verification. (DOE-STD-1036-93 (CH-1), Guide to Good Practices
for Independent Verification)
The operator must establish and implement operations practices to verify that
critical equipment configuration is in accordance with controlling documents,
addressing the following elements:
Section 11
(1) structures, systems, components, operations, and programs requiring
independent verification;
(2) situations requiring independent verification;
(3) methods for performing and documenting independent verification;
(4) situations, if any, allowing concurrent dual verification; and
(5) methods for performing concurrent dual verification, if used.
k. Logkeeping. (DOE-STD-1035-93 (CH-1), Guide to Good Practices for
Logkeeping)
The operator must establish and implement operations practices to ensure
thorough, accurate, and timely recording of equipment information for
performance analysis and trend detection, addressing the following elements:
(1) narrative logs at all key positions, as defined by management, for the
recording of pertinent information;
(2) prompt and accurate recording of information;
(3) type, scope, and format for log entries;
(4) method for recording late entries and correcting erroneous entries without
obscuring the original entry;
(5) periodic supervisory reviews for accuracy, adequacy, and trends; and
(6) document retention requirements.
Attachment 2 DOE O 422.1
Page 8 6-29-2010
l. Turnover and Assumption of Responsibilities. (DOE-STD-1038-93 (CH-1),
Guide to Good Practices for Operations Turnover)
The operator must establish and implement operations practices for thorough,
accurate transfer of information and responsibilities at shift or operator relief to
ensure continued safe operation, addressing the following elements:
(1) definitions for all key positions requiring a formal turnover process;
(2) turnover of equipment/facility status, duties, and responsibilities that
results in the safe and effective transfer of equipment status and
in-progress or planned activities from one shift or workgroup to the next;
and
(3) process for reliefs during a shift.
m. Control of Interrelated Processes. (DOE-STD-1037-93 (CH-1), Guide to Good
Practices for Operations Aspects of Unique Processes)
The operator must establish and implement operations practices to ensure that
interrelated processes do not adversely affect facility safety or operations,
addressing the following elements:
(1) defined responsibilities with respect to the control of interrelated processes
(processes or activities that can affect operations, but are under the control
of persons other than the affected operators, such as shared support
systems or special testing);
(2) operator training and qualification to understand interrelated processes, to
interpret instrument readings, and provide timely corrective action for
process-related problems; and
(3) establish lines of communication between operating personnel, process
support personnel, and other interrelated process operators for
coordination of activities.
n. Required Reading. (DOE-STD-1033-92 (CH-1), Guide to Good Practices for
Operations and Administration Updates Through Required Reading)
The operator must establish and implement operations practices for an effective
required reading program to keep operators updated on equipment or document
changes, lessons learned, or other important information, addressing the following
elements:
(1) identification of material to be distributed via required reading;
(2) identification of which personnel are required to read specific required
reading items; and
DOE O 422.1 Attachment 2
6-29-2010 Page 9
(3) distribution of required reading to appropriate personnel and
documentation of their timely completion.
Section 12
o. Timely Instructions/Orders. (DOE-STD-1034-93 (CH-1), Guide to Good
Practices for Timely Orders to Operators)
The operator must establish and implement operations practices for timely written
direction and guidance from management to operators, addressing the following
elements:
(1) appropriate circumstances for the use of timely instructions/orders;
(2) designated levels of review and approval prior to issuance;
(3) configuration control of timely instructions/orders; and
(4) distribution of timely instructions/orders to appropriate personnel and
documentation of their receipt and understanding.
p. Technical Procedures. (DOE-STD-1029-92 (CH-1), Writer’s Guide for Technical
Procedures)
The operator must establish and implement operations practices for developing
and maintaining accurate, understandable written technical procedures that ensure
safe and effective facility and equipment operation, addressing the following
elements:
(1) expectations for the use of procedures to perform operations;
(2) a process for procedure development;
(3) procedure content, including consistent format and use of terms (e.g.
prerequisites, warnings, cautions, notes, hold points, etc.), detail sufficient
for accomplishing the operation, technically accurate procedures capable
of performance as written, and procedure conformance with the facility
design and manufacturer documentation;
(4) a process for procedure changes (pen and ink or page changes) and
revisions (complete reissues);
(5) a process for training personnel on new, revised, or changed procedures;
(6) a process for approval of new, revised, or changed procedures;
(7) initial-issue and periodic review and testing of procedures;
(8) availability and use of the latest revisions of procedures; and
Attachment 2 DOE O 422.1
Page 10 6-29-2010
(9) specified and defined procedure use requirements, i.e., reader-worker
method, reference use only, use-each-time, and emergency response.
q. Operator Aids. (DOE-STD-1043-93 (CH-1), Guide to Good Practices for
Operator Aid Postings)
The operator must establish and implement operations practices to provide
accurate, current, and approved operator aids, addressing the following elements:
(1) technical evaluation and management approval of operator aids;
(2) operator aids serve as conveniences, not operational requirements;
(3) operator aids do not obscure equipment;
(4) administrative control of installed operational aids; and
(5) periodic review for adequacy and correctness.
r. Component Labeling. (DOE-STD-1044-93 (CH-1), Guide to Good Practices for
Equipment and Piping Labeling)
The operator must establish and implement operations practices for clear, accurate
equipment labeling, addressing the following elements:
(1) components that require a label;
(2) label information that uniquely identifies components and is consistent
with regulations, standards, and facility documents;
(3) durable and securely attached labels that do not interfere with controls or
equipment; and
(4) administrative control of labels, including a process for promptly
identifying and replacing lost or damaged labels, preventing unauthorized
or incorrect labels, and control of temporary labels.
3. DEFINITIONS.
a. At-the-Controls Area. A designated area where special access and controls are
necessary. Examples are the space in front and to the immediate sides of a control
panel, control station, computer terminal, etc.; or the area where facility, work
Section 13
station, or experiment controls (e.g., switches, knobs, buttons) are located. (DOE-
STD-1042-93 CH-1))
b. Certification. The process by which facility management provides written
endorsement of the satisfactory achievement of qualification of a person for a
position. (DOE O 426.2)
DOE O 422.1 Attachment 2
6-29-2010 Page 11 (and Page 12)
c. Concurrent Dual Verification. A method of checking an operation, an act of
positioning, or a calculation, in which the verifier independently observes and/or
confirms the operation or calculation. (DOE-STD-1036-93 (CH-1))
d. Conduct of Operations Program. The formal documentation, practices, and
actions implementing disciplined and structured operations that support mission
success and ensure worker, public, and environmental protection. The program
goal is to minimize the likelihood and consequences of human fallibility or
technical and organizational system failures.
e. Control Area. The physical area (e.g., room, booth, desk) where the facility or
portions of the facility operations are monitored and controlled. (DOE-STD-1042-
93 CH-1))
f. Independent Verification. The act of checking, by a separate qualified person, that
a given operation or component position conforms to established criteria.
(DOE-STD-1036-93 CH-1))
g. Interrelated Processes. Those processes or activities that can affect operations, but
are under the control of persons other than the affected operators, such as shared
support systems or special testing.
h. Operations. The general term to encompass the work activities accomplished by
the facility or project. Examples include, but are not limited to, operating science
and technology machines, operating equipment, construction, decontamination
and decommissioning, dismantlement, environmental characterization and
monitoring activities, waste handling, research and development, maintenance,
and laboratory analysis activities.
i. Operator Aids. Approved, posted information used to assist personnel in
performing a task. Examples are copies of procedures, (portion or pages thereof),
system drawings, information tags, curves, graphs, or prints. (DOE-STD-1043-93
(CH-1))
j. Qualification. Education, experience, training, examination, and any special
requirements necessary to perform assigned responsibilities for a given position.
(DOE O 426.2)
k. Shift. The normal period of work for an individual or group, e.g. 8:00am to 5:00
pm. (DOE STD 1041-93 (CH-1)
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-1 (and A-2)
APPENDIX A. CONDUCT OF OPERATIONS
DETAILED CONDUCT OF OPERATIONS MATRIX
This Appendix consists of a series of tables comprising a Conduct of Operations Matrix for
documenting implementation of conduct of operations requirements at Hazard Category 1, 2,
and 3 nuclear facilities, plus others as designated by DOE Line Management. Each of the topics
in the specific requirements in Attachment 2, Conduct of Operations Program Requirements, is
expanded to list program attributes that implement that Conduct of Operations Program topic.
The Paragraph 2 specific requirements are listed in Column 1, and detailed attributes of these
high-level requirements are listed in Column 2. Column 3 is for entering the document citation
where the item is implemented, or for entering the justification for its non applicability, or, if the
item is partially applicable, both a citation and a justification.
Instructions for filling out the Matrix:
Section 14
Use the boxes in Column 1 and on the right of Column 2 to indicate whether the item is
Applicable (A), Not Applicable (N) or Partially Applicable (P).
If an entire topic (top item of each topic’s Column 1) is deemed Not Applicable, mark it and
enter the justification only once. Otherwise leave the box blank and address the remaining items
in Column 1, since it is assumed they could have different citations in Column 3.
If an item is marked Applicable in Column 1, all items in Column 2 are to be implemented, and
the implementing document(s) are entered in Column 3. It is not necessary to repeatedly list the
same implementing document for the detailed attributes under a higher-level item.
For items marked Partially Applicable in Column 1, indicate in Column 2 whether each item is
Applicable, Not Applicable, or Partially Applicable in the same manner as for Column 1.
For items marked Applicable or Partially Applicable, enter the operator’s implementing
document citation in Column 3.
For items marked Partially Applicable or Not Applicable, enter the justification for this
determination in Column 3.
If an entire Column 1 item is marked Applicable, enter the document citation only once, unless
different attributes are in different documents.
If an entire Column 1 item is marked Not Applicable, enter the justification only once.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-3
Organization and Administration, Attachment 2 Paragraph 2.a
1 Requirements,
Attachment 2 ¶ 2.a
2 Detailed Attributes
3 Doc Citation
/Justification
2.a.
The operator must establish
policies, programs, and
procedures that define an
effective operations
organization, including the
following elements:
2.a.(1) Organizational roles,
responsibilities, authority, and
accountability
a. Written policies state goals for
operations, safety, and security, the
means to achieve them, and the
controls instituted for the Conduct of
Operations Program.
b. Policies and procedures implement
DOE requirements for operations.
c. Policies and procedures implement
DOE safety requirements.
d. Policies and procedures implement
DOE security requirements.
e. Personnel and organizations are
assigned responsibilities for
implementing policies.
f. Policies clearly define operations
personnel authority, accountability,
and relationships with other groups,
including Stop-Work authority.
2.a.(2) Adequate material and
personnel resources to
accomplish operations
a. Sufficient qualified operators are
available to complete assigned tasks
without excessive overtime.
b. Adequate technical personnel are
assigned to support operations.
c. Staff development, retention, and
succession are managed under a
long-range staffing plan.
d. Adequate material, tooling,
equipment, safety gear, and facilities
are available for safe operations.
Attachment 2, Appendix A DOE O 422.1
Page A-4 6-29-2010
Organization and Administration, Attachment 2 Paragraph 2.a
1 Requirements,
Attachment 2 ¶ 2.a
2 Detailed Attributes
3 Doc Citation
/Justification
2.a.(3) Monitoring and self-
assessment of operations
a. Operating problems are
documented and evaluated, and
corrective actions are taken.
b. Supervisors and managers directly
observe operations frequently and
provide feedback.
c. Appropriate outside organizations
such as Quality Assurance or other
oversight organizations observe
operations and provide feedback.
d. Assessment and observation issues
Section 15
are tracked and corrected.
e. Auditable, measurable, realistic,
and challenging safety,
environmental, and operations goals
are set. Examples are safety system
operability; radiological or other
exposure; facility operational
availability; unscheduled shutdowns;
overtime; staffing; qualification, and
training; waste production; and plant
instrumentation alarms and warnings.
f. Facilities develop an action plan to
achieve safety, environment, and
operations goals with input from
operations personnel, and review and
approval by management.
g. Facilities monitor and report to
line and DOE management their
progress on completing the action
plan and achieving goals. Goals and
plans are adjusted and modified as
needed.
2.a.(4) Management and
worker accountability for the
safe performance of work
a. Management systems are designed
to minimize the effects of human
performance failures.
b. Personnel involved in repeated or
willful violations of operating
practices are counseled, retrained, or
disciplined as appropriate.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-5
Organization and Administration, Attachment 2 Paragraph 2.a
1 Requirements,
Attachment 2 ¶ 2.a
2 Detailed Attributes
3 Doc Citation
/Justification
c. Personnel are recognized for
notable safety improvement actions
or ideas.
d. Supervisory performance
appraisals and promotions take
operational and safety performance
into consideration.
2.a.(5) Management training,
qualification, succession, and,
when appropriate,
certification
a. Formal supervisory and
management training is provided for
first-line and shift supervisors.
b. Development, qualification,
retention, and succession for
supervisors are managed under a
long-range staffing plan.
c. Supervisors achieve certification
when required for their duties.
2.a.(6) Methods for the
analysis of hazards and
implementation of hazard
controls in the work planning
and execution process
a. The DOE Integrated Safety
Management System is used to plan
work.
b. Operations personnel are trained
in, and understand, integrating safety
into work planning.
2.a.(7) Methods for
approving, posting,
maintaining, and controlling
access to electronic
operations documents
(procedures, drawings,
schedules, maintenance
actions, etc.) if electronic
documents are used.
a. Management approves electronic
document accessibility on both
internal and public computer
systems, considering security and
privacy concerns.
b. Procedures define the methods and
positions responsible for approving,
revising, and posting electronic
documents.
Attachment 2, Appendix A DOE O 422.1
Page A-6 6-29-2010
Shift Routines and Operating Practices, Attachment 2 Paragraph 2.b
1 Requirements,
Attachment 2 ¶ 2.b
2 Detailed Attributes
3 Doc Citation
/ Justification
2.b.
The operator must establish
and implement operations
practices to ensure shift
operators are alert, informed
of conditions, and properly
operate equipment,
addressing the following
elements:
2.b.(1) Prompt notification to
operating personnel and
supervisors of changes in the
facility status, abnormalities,
or difficulties encountered in
performing assigned tasks.
a. Supervisors and Operators keep
each other informed of facility status
changes, abnormalities, or
difficulties.
b. Operators keep Supervisors
informed of unexpected situations.
2.b.(2) Adherence by
operating personnel and other
workers to established safety
Section 16
requirements
a. Operators comply with safety
programs, e.g. industrial, chemical,
explosive, pressure, temperature,
confined space, or others applicable
to the facility.
b. Operators use proper personal
protective equipment (PPE).
c. Operators use ladders or other
approved means for overhead access
in the absence of permanent ladders
or catwalks.
d. Operators do not routinely climb
or walk on components.
e. Operators use appropriate
electrical safety procedures.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-7
Shift Routines and Operating Practices, Attachment 2 Paragraph 2.b
1 Requirements,
Attachment 2 ¶ 2.b
2 Detailed Attributes
3 Doc Citation
/ Justification
2.b.(3) Awareness by
operating personnel of the
status of equipment through
inspection, conducting
checks, and tours of
equipment and work areas
a. Operators regularly tour their
assigned areas on a frequency
determined by management,
normally early in each shift. Tours
are thorough enough to provide
detailed equipment status.
b. Routine security concerns do not
override tour responsibilities.
c. Operators inspect equipment status
and condition during tours for proper
operation, for operability of standby
equipment, and any work planned or
in progress.
d. Operators recognize, document,
and report abnormal conditions and
take action to correct the conditions.
Examples include leaks, fire or safety
hazards, clogged drains, cleanliness
issues, or building deficiencies.
e. Operators periodically check alarm
and annunciator functionality.
2.b.(4) Procedures for
completing round sheets or
inspection logs, responding to
abnormal conditions, and
periodic supervisory reviews
of round sheets or inspection
logs
a. Management approves round
sheets, including frequency and time
of instrument readings and allowable
delay (normally one hour or less).
b. Round sheets cover the operator’s
area and equipment parameters; data
entry blocks follow the tour route.
c. Round sheets provide normal and
max/min expected equipment
instrumentation readings where
appropriate.
d. Round sheets provide safety limits
where appropriate.
e. Data readings outside the normal
or max/min range are circled or
otherwise highlighted and reported to
the supervisor. Operators, and
supervisors when appropriate, take
corrective action to restore proper
functioning.
Attachment 2, Appendix A DOE O 422.1
Page A-8 6-29-2010
Shift Routines and Operating Practices, Attachment 2 Paragraph 2.b
1 Requirements,
Attachment 2 ¶ 2.b
2 Detailed Attributes
3 Doc Citation
/ Justification
f. Operators make narrative records
of important events, abnormal
conditions and corrective actions, on
round sheets or logbooks.
g. Data entries on round sheets are
made at the specified time. If
readings are delayed beyond the
allowable range, the actual time and
explanation for the delay are
recorded.
h. Supervisors review round sheets
for trends, abnormalities, and proper
data and narrative entries during each
shift.
i. Supervisors periodically monitor
operator rounds for proper execution
and for any changes needed for
changed facility conditions.
2.b.(5) Procedures for
protecting operators from
personnel hazards, e.g.
chemical, radiological, laser,
noise, electromagnetic, toxic
or nano-scale materials
a. Operators are appropriately
qualified for expected hazards and
know protection practices to maintain
personnel exposure as low as
Section 17
reasonably achievable and within
facility controls for radiation,
chemicals, electromagnetic fields,
toxic materials, and other personnel
hazards.
b. Operators comply with all posted
personnel protection requirements
and precautions.
c. Operators properly use appropriate
monitoring instruments when
required.
d. Operators remain aware of their
radiological, toxic, or other
exposures and take action to
minimize them.
e. Operators properly use appropriate
administrative controls such as work
permits, radiological work permits,
and confined space permits.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-9
Shift Routines and Operating Practices, Attachment 2 Paragraph 2.b
1 Requirements,
Attachment 2 ¶ 2.b
2 Detailed Attributes
3 Doc Citation
/ Justification
f. Operators promptly report and take
corrective action for radiological or
hazardous material protection
deficiencies.
g. Operators and Supervisors notify
protection personnel prior to
activities that affect the protection
status (Industrial Hygiene,
Radiological, etc.).
h. Supervisors periodically review
exposure trends of operators to detect
and correct adverse factors that
contribute to personnel exposures.
2.b.(6) Prompt response to
instrument indications,
including the use of multiple
indications to obtain
parameters
a. Operators believe their indications
unless proven otherwise.
b. Operators check other indicators
when possible to confirm unexpected
readings.
c. Operators take prompt action to
investigate and correct abnormal
conditions.
d. Operators identify inaccurate or
malfunctioning instruments and
inform appropriate supervisors and
repair organizations.
e. In case of doubtful readings,
operators place safety above
production.
2.b.(7) Procedures for
resetting protective devices
a. Operators attempt to determine the
cause of protective device trips
(Breakers, fuses, relief valves, safety
systems, etc.).
b. Supervisors and management
provide guidance on addressing
protective device trips; normally,
devices are reset only after assuring
that no abnormal condition exists that
would cause a trip.
Attachment 2, Appendix A DOE O 422.1
Page A-10 6-29-2010
Shift Routines and Operating Practices, Attachment 2 Paragraph 2.b
1 Requirements,
Attachment 2 ¶ 2.b
2 Detailed Attributes
3 Doc Citation
/ Justification
c. Management investigates
protective system trips and
unplanned shutdowns.
2.b.(8) Authorization to
operate facility equipment
a. Designated supervisors direct the
overall operation of the facility,
including load changes.
b. Personnel operating equipment
have appropriate qualification and
certification.
c. Operators and Supervisors are
aware of all activities affecting
equipment.
d. Management designates routine
operations that do not require
permission for performance.
e. Supervisors approve non-routine
operation of facility or process
controls.
f. During emergencies, Operators
may take immediate actions for
worker, public, and environmental
protection without permission, and
inform supervisors promptly.
g. Operators achieve plant safety
over production for normal,
emergency and abnormal operations.
2.b.(9) Designating shift
operating bases and providing
equipment for them
a. Shift operating bases, the normal
location for operator(s) when not
otherwise performing evolutions, are
established for all feasible shift
positions.
b. Shift operating bases are equipped
Section 18
with communications, references,
and office materials and equipment
needed for facility operations, and
are conveniently located within the
operating area.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-11
Shift Routines and Operating Practices, Attachment 2 Paragraph 2.b
1 Requirements,
Attachment 2 ¶ 2.b
2 Detailed Attributes
3 Doc Citation
/ Justification
c. Shift turnovers normally occur at
the operating base and operators
return there when not performing
operations at equipment locations or
touring.
2.b.(10) Professional and
disciplined operator
performance of duties
a. Potential distractions such as
electronic devices (radio, TV, music
players, games), personal telephone
calls, game playing, and horseplay
are prohibited.
b. Non-work-related written
materials are prohibited. Operators
may read training bulletins, technical
manuals, or operating experience
information or review other written,
audible, or visual materials that relate
to operator duties.
c. Supervisors ensure operators’
primary duties are not compromised
and provide guidance on potentially
distracting materials and devices.
Attachment 2, Appendix A DOE O 422.1
Page A-12 6-29-2010
Control Area Activities, Attachment 2 Paragraph 2.c.
1 Requirements,
Attachment 2 ¶ 2.c
2 Detailed Attributes
3 Doc Citation
/.Justification
2.c.
The operator must establish
and implement operations
practices that promote
orderly, business-like control
area operations and address
the following elements:
2.c.(1) Control-area access
a. Control Areas and at-the-controls
areas are clearly identified and
boundaries are understood
b. Control area access is limited to
persons on official business only.
Access to the at-the-controls area is
further limited to persons who need
to be in the area.
c. Entry to control and at-the-
controls areas is granted by
designated persons whose identity is
known to persons desiring entry.
2.c.(2) Formality and
discipline in the control and
at-the-controls area
a. All persons in the area display
professional and disciplined
behavior. Only activities essential to
operations and authorized by
management are permitted in the
area.
b. Potential distractions such as
electronic devices (radio, TV, music
players, games), personal telephone
calls, game playing, and horseplay
are prohibited.
c. Non-work-related discussions are
minimized.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-13
Control Area Activities, Attachment 2 Paragraph 2.c.
1 Requirements,
Attachment 2 ¶ 2.c
2 Detailed Attributes
3 Doc Citation
/.Justification
2.c.(3) Surveillance of control
panels and timely response to
determine and correct the
cause of abnormalities/out-of-
specification conditions
a. Operators are alert and attentive to
control panel indicators and alarms
and monitor panels frequently.
b. Operators closely monitor
indications and conditions and trend
them to detect problems early.
c. Operators take timely alarm
response actions to address and
correct alarming conditions.
d. Concurrent operations that affect
control panel indications are limited
so that operators’ ability to detect
and respond to abnormal conditions
is not compromised.
e. Operators are ready to take
backup control of automated or
computer systems.
2.c.(4) Limitation of the
number of concurrent
evolutions and duties
a. Operator ancillary duties are
limited to prevent interference with
monitoring control panel indicators
Section 19
and alarms.
b. Tasks such as tagouts, work
authorizations, procedure review,
maintenance, or required reading do
not constitute a major portion of
operators’ shift responsibilities.
c. Control panel operator
administrative workload is
minimized. Other operators continue
monitoring when one operator has
necessary administrative work.
2.c.(5) Authorization to
operate control area
equipment
a. Operation of control area
equipment is performed only by
persons specifically authorized in
writing.
b. Trainees operating control area
equipment do so only under the
direct supervision of the normally
assigned operator.
Attachment 2, Appendix A DOE O 422.1
Page A-14 6-29-2010
Communications, Attachment 2 Paragraph 2.d
1 Requirements,
Attachment 2 ¶ 2.d
2 Detailed Attributes
3 Doc Citation
/ Justification
2.d.
The operator must establish
and implement operations
practices that ensure accurate,
unambiguous
communications among
operations personnel and
address the following
elements:
2.d.(1) Provision of
communications systems for
emergency and normal
operations
a. All facility personnel are promptly
alerted to facility emergencies.
b. Communications systems are in
place to support normal operations.
c. Alternate methods are provided
for areas where public address or
emergency signals cannot be heard.
d. Communications systems are
periodically tested.
e. Control areas can override other
communications system users for
emergencies.
2.d.(2) Administrative control
of communications
equipment, including
authorization to use the public
address system and allowable
locations and purposes for
radio use
a. Public address system use is
controlled to maintain its
effectiveness and prevent it
becoming commonplace.
b. Point-to-point communications
are the preferred method wherever
practical.
c. Radio usage is controlled to
prevent electronic interference with
facility equipment. Radio-prohibited
areas are defined and marked.
d. Radio frequency or channel
assignments are controlled and
readily available to users.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-15
Communications, Attachment 2 Paragraph 2.d
1 Requirements,
Attachment 2 ¶ 2.d
2 Detailed Attributes
3 Doc Citation
/ Justification
e. Where appropriate, dedicated
radio or pager channels are assigned
to specific functions such as
emergency communications or
security.
2.d.(3) Methods for control
areas to contact operators and
supervisors
a. Policies define how to notify
operators or supervisors to contact
the control area.
b. Emergency and normal
notification methods are distinctive.
2.d.(4) Use of abbreviations
and acronyms
a. Acronyms and abbreviations are
developed and promulgated for oral
and written communications.
b. Only approved abbreviations and
acronyms are allowed to be used.
2.d.(5) Use of oral
instructions and
communications, including
use of repeat-backs and
sender/receiver identifications
a. Policies require clear and concise
oral communications.
b. Policies define when repeat-backs
are appropriate and how they are
implemented.
c. Policies define protocols for
transmitting information and
identifying senders and receivers.
Attachment 2, Appendix A DOE O 422.1
Page A-16 6-29-2010
On-shift Training, Attachment 2 Paragraph 2.e
1 Requirements,
Attachment 2 ¶ 2.e
2 Detailed Attributes
3 Doc Citation
/ Justification
2.e.
The operator must establish
and implement operations
Section 20
practices that control on-shift
training of facility operators,
prevent inadvertent or
incorrect trainee manipulation
of equipment, and address the
following elements:
2.e.(1) On-shift training
program
a. The Operations Manager approves
the operator qualification program
and coordinates changes with the
Training Department.
b. For positions requiring operator
certification, candidates receive one-
on-one instruction on station.
c. On-shift training is conducted by
persons both qualified to operate
equipment and authorized to train
others. Authorization to train others
may require special instructor
qualifications.
2.e.(2) Authorization and
documentation of training
activities
a. Training activities during
operations are specifically identified
in the training program, including
knowledge requirements and trainee
actions such as perform, simulate,
etc.
b. Qualification program completion
is formally documented; on-shift and
classroom training activities are
documented as they occur.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-17
On-shift Training, Attachment 2 Paragraph 2.e
1 Requirements,
Attachment 2 ¶ 2.e
2 Detailed Attributes
3 Doc Citation
/ Justification
2.e.(3) Supervision and
control of personnel under
instruction by qualified
personnel.
a. Qualified operator-instructors
supervise trainees to prevent
misoperation of equipment.
b. Early-stage trainees discuss
operations, procedures, and actions
before performing actual operations.
More proficient trainees point and
describe actions before taking them.
Operator-instructors always monitor
trainees and remain capable of
intervention.
c. Operator-instructors verify trainee
entries on official round sheets and
logs, and discuss any out of
specification readings or unfavorable
trends.
2.e.(4) Facility conditions and
controls for conducting
training during operational
activities, including
suspension of training during
unanticipated or abnormal
events.
a. Training activities are conducted
only when facility conditions permit,
and as authorized by facility
management.
b. Training activities and trainee
operation of equipment is suspended
immediately during emergency or
unanticipated abnormal conditions,
or when deemed appropriate for
safety or operational conditions.
c. Management establishes the
maximum number of trainees
allowed during operations and the
maximum number of trainees per
operator-instructor.
Attachment 2, Appendix A DOE O 422.1
Page A-18 6-29-2010
Investigation of Abnormal Events, Conditions, and Trends,
Attachment 2 Paragraph 2.f
1 Requirements,
Attachment 2 ¶ 2.f
2 Detailed Attributes
3 Doc Citation
/ Justification
2.f.
The operator must establish
and implement operations
practices for investigating
events to determine their
impact and prevent
recurrence, addressing the
following elements:
2.f.(1) Specific events
requiring investigation, and
criteria for identifying other
events or conditions to be
investigated
a. Violation of a safety
documentation design limit (e.g.,
design feature or safety limit).
b. Abnormal or unexpected system
performance that adversely affects
operations or safety (e.g. improper
instrument readings, automatic
control failure, chemical analysis,
etc.)
c. Abnormal or unexpected safety
conditions (e.g. stray voltage, safety
feature or interlock malfunction, etc.)
d. Discovery of mispositioned valves,
switches, or components.
Section 21
e. Events reportable to DOE or other
agencies (e.g. EPA, DOT, State
regulators, etc.)
f. Unplanned shutdown or significant
loss of operation
g. Procedural violation or personnel
error with actual or potential
personnel injury, facility damage, or
facility safety degradation
h. Equipment failure that could affect
safety or mission
i. Radiological or toxic material
release limits are exceeded or
material is lost
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-19
Investigation of Abnormal Events, Conditions, and Trends,
Attachment 2 Paragraph 2.f
1 Requirements,
Attachment 2 ¶ 2.f
2 Detailed Attributes
3 Doc Citation
/ Justification
j. Recorded data is out-of-
specification or shows unexpected
trends, with actual or potential
adverse impact on operations or
safety.
k. Actual or suspected sabotage.
l. Lost special nuclear material.
m. Repetitive problems.
n. Measuring and test equipment is
found to be out of calibration, with
actual or potential impact on
operations or safety.
o. As directed by appropriate
authority, particularly for near-miss
situations.
2.f.(2) Designation of
investigators and their
training and qualification
a. A senior manager is responsible
for investigations; they may delegate
investigations or portions of
investigations to others, but retain
overall responsibility for rigor and
consistency of investigations.
b. Investigators are experienced and
technically qualified.
c. Investigators have no bias or
vested interest in the results of the
investigation.
d. Investigators are trained in facility
systems, operations, and
investigation techniques.
2.f.(3) Investigation process
and techniques
a. Timely data collection by a
designated person: initial conditions,
operator statements, pertinent
computer/instrument printouts or
charts, pertinent documentation and
records, and other appropriate
information.
b. Records and data are annotated to
prevent misinterpretation.
Attachment 2, Appendix A DOE O 422.1
Page A-20 6-29-2010
Investigation of Abnormal Events, Conditions, and Trends,
Attachment 2 Paragraph 2.f
1 Requirements,
Attachment 2 ¶ 2.f
2 Detailed Attributes
3 Doc Citation
/ Justification
c. Investigation data is permanently
recorded for future reference.
d. Data collection does not interfere
with facility operation unless vital to
understanding the event.
e. The facts of the event are
reconstructed chronologically from
the data.
f. The event is analyzed to determine
equipment and personnel response,
procedure and equipment adequacy,
human performance factors, and
safety impact.
g. Management determines the
appropriate restart process (if
applicable).
2.f.(4) Causal analysis and
corrective action
determination
a. The causes are determined.
b. Appropriate corrective actions to
prevent recurrence of the event are
determined.
c. Corrective actions are approved by
the responsible manager and tracked
to completion.
2.f.(5) Event investigation
reporting, training, and
trending
a. Investigation reports are timely.
b. Investigation Reports contain a
description of the event, its impact,
root cause, lessons, and corrective
actions.
c. Investigation Reports note any
positive aspects of the event.
d. Investigation Reports are approved
by the responsible manager and
reviewed by appropriate managers
and safety personnel.
e. Investigation Report lessons are
shared with appropriate operators,
support staff, other facility
Section 22
organizations, and other facilities.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-21
Investigation of Abnormal Events, Conditions, and Trends,
Attachment 2 Paragraph 2.f
1 Requirements,
Attachment 2 ¶ 2.f
2 Detailed Attributes
3 Doc Citation
/ Justification
f. Events are evaluated for inclusion
in training programs.
g. Processes include a method to
train operators on serious events
upon their return to work.
h. Procedure problems, operator
errors, and other appropriate events
are part of the facility trend analysis
program. Periodic summaries of
event analysis and trends are
provided to managers. Training
programs include appropriate
material from event reports and trend
analysis.
2.f.(6) Response to known or
suspected sabotage
a. Actual or suspected sabotage is
immediately investigated.
b. The condition of potentially
affected systems is determined, and
safety system operability is
confirmed.
c. Management determines whether
continued operation is justified and if
safe shutdown is viable or advisable.
d. Management takes action to
minimize the impact of sabotage and
deter future acts.
Attachment 2, Appendix A DOE O 422.1
Page A-22 6-29-2010
Notifications, Attachment 2 Paragraph 2.g
1 Requirements,
Attachment 2 ¶ 2.g
2 Detailed Attributes
3 Doc Citation
/ Justification
2.g.
The operator must establish
and implement operations
practices to ensure
appropriate event notification
for timely response,
addressing the following
elements:
2.g.(1) Procedures for
internal, DOE, and external
notifications, including
events, persons to be notified,
persons responsible to make
notifications, contact
information, and
recordkeeping
a. Responsibilities for making
notifications are specifically assigned
to positions or persons.
b. Events requiring notification are
identified and documented.
c. Notification timeliness standards
are established.
d. Primary and alternate personnel to
be notified for each event are
identified and documented.
e. Contact information for the
personnel to be notified is kept
current and available to notifying
personnel.
f. All notifications are documented in
formal records that include date,
time, reason, person notified, and
person making notification.
2.g.(2) Communications
equipment for notification
a. Adequate equipment for making
notifications is available at the main
control area and/or other appropriate
location.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-23
Control of Equipment and System Status, Attachment 2 Paragraph 2.h
1 Requirements,
Attachment 2 ¶ 2.h
2 Detailed Attributes
3 Doc Citation
/ Justification
2.h.
The operator must establish
and implement operations
practices for initial equipment
lineups and subsequent
changes to ensure facilities
operate with known, proper
configuration as designed,
addressing the following
elements:
2.h.(1) Authorization for, and
awareness of, equipment and
system status changes
a. Operations supervisor is
responsible for maintaining proper
configuration and authorizing status
changes for major equipment.
b. Operations supervisor may
delegate status change authorizations
for support or less-important systems
and equipment.
c. Status changes are communicated
to affected operators and
organizations.
d. Status changes resulting from
operations or work are reported to
cognizant supervisors.
2.h.(2) Initial system
alignment, maintaining
control of equipment and
Section 23
system status through startup,
operation, and shutdown, and
documentation of status
a. Components and systems are
aligned prior to first operation.
b. Checklists are used to guide initial
alignments and rechecks, and include
equipment identification matching
installed labels, required component
position, data entry space for actual
position and any deviations, and
documentation of alignment or
recheck.
c. Supervisors review and approve
completed alignment checklists.
Attachment 2, Appendix A DOE O 422.1
Page A-24 6-29-2010
Control of Equipment and System Status, Attachment 2 Paragraph 2.h
1 Requirements,
Attachment 2 ¶ 2.h
2 Detailed Attributes
3 Doc Citation
/ Justification
d. Management determines the need
for alignments and rechecks.
Examples of situations that may need
alignments or rechecks are startup
from complete shutdown, outage
recovery, or mode changes.
e. Restoration of safety-related
systems following maintenance
includes functional testing of their
capability.
f. Records of equipment and system
alignments are retained for operators’
reference.
g. Deviations from the reference
alignment, including lockouts and
tagouts, are tracked and controlled by
a status board or other effective
system.
2.h.(3) Use and approval of
lockouts and tagouts for
administrative control of
equipment
a. Supervisors approve lockouts and
tagouts in their facility and remain
aware of status changes that result.
b. Personnel are trained in their
responsibilities concerning changing
system or equipment status and
operation of locked or tagged
components.
2.h.(4) Operational Limits
compliance and
documentation
a. Compliance with operational
limits, including safety basis
Limiting Conditions for Operations,
is established through administrative
controls. Compliance and actions
taken to restore operation within
limits are documented in facility
records.
b. Supervisors are aware of and
direct completion of actions to
comply with operational limits.
c. Operational limit entry conditions
and actions are documented in
appropriate operating records.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-25
Control of Equipment and System Status, Attachment 2 Paragraph 2.h
1 Requirements,
Attachment 2 ¶ 2.h
2 Detailed Attributes
3 Doc Citation
/ Justification
d. Operating personnel are kept
informed of any limiting conditions
and their required actions.
e. Operating personnel periodically
review Limiting Conditions for
Operation and Action Statements in
effect for proper implementation.
2.h.(5) Management of
equipment deficiencies,
maintenance activities, post-
maintenance testing, and
return to service
a. Operators note equipment
deficiencies, document them in work
control systems for correction, and
identify them to other operators by
tags, logs, status boards, or other
effective method.
b. Designated managers authorize in
writing the work control documents
for all activities, including
maintenance on equipment important
to safety, on equipment that affects
operations, or that changes control
indications or alarms.
c. The status of work in progress is
documented and available for review
by operators.
d. Work control documents specify
retest requirements to ensure, prior to
restoration to service, proper
functioning, effectiveness of the
maintenance, and that no new
problems were introduced.
e. Supervisors assure themselves of
proper equipment operation before
Section 24
authorizing its return to service after
maintenance, testing, or
emergency/abnormal event.
2.h.(6) Awareness and
documentation of control
panel and local alarm issues
a. Operators and supervisors are
aware of inoperable alarms, alarms
with temporary set points, multiple-
input alarms that do not provide
indication of a subsequent condition,
or other limitations.
Attachment 2, Appendix A DOE O 422.1
Page A-26 6-29-2010
Control of Equipment and System Status, Attachment 2 Paragraph 2.h
1 Requirements,
Attachment 2 ¶ 2.h
2 Detailed Attributes
3 Doc Citation
/ Justification
b. Deficient alarms are documented
for information to all affected
personnel and entered into work
control systems for correction.
c. Operators take appropriate actions
to monitor conditions when alarms
are unreliable.
d. Operators and supervisors are
aware of alarms expected during
normal operations.
2.h.(7) Control of temporary
equipment modifications and
temporary systems
a. Administrative systems control
temporary modifications; examples
include electrical jumpers or lifted
leads, pulled circuit cards, disabled
alarms, piping jumpers or blocks,
disabled relief valves, strainers or
filters temporarily installed or
removed, temporary shielding,
blocked drains, and others.
b. Administrative systems control
temporary systems.
c. Administrative controls include:
1. Appropriate engineering review
and approval of the design and
safety of the modification
before installation.
2. Written authorization for
installation.
3. Independent verification of
installation and removal.
4. Documentation of the
modifications.
5. Completion of any training,
procedure changes, or labeling
required.
6. Periodic audits of installed
temporary modifications.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-27
Control of Equipment and System Status, Attachment 2 Paragraph 2.h
1 Requirements,
Attachment 2 ¶ 2.h
2 Detailed Attributes
3 Doc Citation
/ Justification
2.h.(8) Configuration control
and distribution of
engineering documents
a. Administrative systems provide for
configuration control of engineering
documents per applicable DOE
directives.
b. Processes provide for designating
safety structures, systems, and
components and their quality
assurance requirements to support
system engineer and maintenance
needs.
c. Processes control safety software
per applicable DOE directives.
d. Operations personnel and all other
affected organizations have access to
current, approved engineering
documents.
Attachment 2, Appendix A DOE O 422.1
Page A-28 6-29-2010
Lockouts and Tagouts, Attachment 2 Paragraph 2.i
1 Requirements,
Attachment 2 ¶2.i
2 Detailed Attributes
3 Doc Citation
/ Justification
2.i.(1) The operator must
establish and implement
operations practices that
address the following
elements for the installation
and removal of
lockout/tagouts for the
protection of personnel:
2.i.(1)(a) Procedures, roles
and responsibilities associated
with the development,
documentation, review,
installation, and removal of a
lockout/tagout
1. Procedures and/or Lockout/Tagout
Program implements OSHA Rules
and is designed to control hazardous
energy and materials during
servicing, maintenance, or whenever
unexpected operation or energization
could cause injury.
2. Procedures include provisions that
only authorized, qualified personnel
perform lockout/tagouts.
3. Personnel are trained on their
Section 25
responsibilities regarding tags and
locks.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-29
Lockouts and Tagouts, Attachment 2 Paragraph 2.i
1 Requirements,
Attachment 2 ¶2.i
2 Detailed Attributes
3 Doc Citation
/ Justification
2.i.(1)(a) Procedures, roles
and responsibilities
(continued)
4. Procedures include provisions for
documenting lockout/tagouts,
including:
An indexing/numbering system
Identification of the reason for
the lockout/tagout
Applicable work packages or
other documents
Equipment covered
all components and their
position
Authorization for installing the
lockout/tagout
Placement and verification of
locks/tags
Authorization for removing the
entire lockout/tagout or
individual locks/tags
Documenting the removal of
locks/tags
Designating the component
position after clearing
locks/tags, and
Documenting the repositioning
of components after clearing
locks/tags.
5. Procedures designate the manager
responsible for lockout/tagout
records.
6. Procedures include provisions for
periodic management reviews of
lockout/tagout records.
7. Procedures include provisions for
checking component positions of
equipment outside the lockout/tagout
necessary to support restoring
locked/tagged equipment to service.
8. Procedures include periodic audits
of active lockout/tagouts to ensure
locks and tags are properly attached
and components are in the correct
position.
Attachment 2, Appendix A DOE O 422.1
Page A-30 6-29-2010
Lockouts and Tagouts, Attachment 2 Paragraph 2.i
1 Requirements,
Attachment 2 ¶2.i
2 Detailed Attributes
3 Doc Citation
/ Justification
9. Procedures include techniques for
verifying the position of locked
components, with preference for the
use of a hands-on check or position
indicator.
10. Procedures include provisions for
authorizing and documenting the
repositioning of locked components
for a lockout/tagout.
11. Procedures include provisions for
returning removed tags to the
authorizing manager and
documenting the manager’s final
check that all locks and tags are
removed.
12. Procedures include provisions
that permit, but discourage,
temporary clearance of locks/tags per
OSHA Rules.
2.i.(1)(b) Compliance with
Occupational Safety and
Health Administration Rules,
29 CFR Part 1910 and/or 29
CFR Part 1926, requirements
for the protection of workers
using lockout/tagout
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-31
Lockouts and Tagouts, Attachment 2 Paragraph 2.i
1 Requirements,
Attachment 2 ¶2.i
2 Detailed Attributes
3 Doc Citation
/ Justification
2.i.(1)(c) Compliance with
National Fire Protection
Association Standard 70E
electrical safety requirements
using lockout/tagout
2.i.(1)(d) Description and
control of the tags, locks,
lockboxes, chains, and other
components utilized for the
lockout/tagout program
1. Procedures contain provisions that
when key operated locks are used,
access to the keys is restricted to
authorized personnel.
2. Procedures contain provisions that
when key operated locks are used,
keys are readily available to
appropriate personnel.
2.i.(1)(e) Training and
qualification in lockout/tagout
and special considerations for
DOE facilities, e.g.
operational limitations, or
seismic issues from the mass
of locks or chains
1. Training programs comply with
applicable OSHA Rules and support
qualification of personnel to perform
lockout/tagouts.
Section 26
2. Training includes material on how
lockouts can hinder facility
operations, particularly when local
component operations are necessary
while remote controls are locked out.
3. Training includes material on how
the mass of locks or chains may
impair seismic design features of
components.
Attachment 2, Appendix A DOE O 422.1
Page A-32 6-29-2010
Lockouts and Tagouts, Attachment 2 Paragraph 2.i
1 Requirements,
Attachment 2 ¶2.i
2 Detailed Attributes
3 Doc Citation
/ Justification
2.i.(2) The operator must
establish and implement
operations practices that
address the following
elements for the installation
and removal of caution tags
for equipment protection or
operational control.
2.i.(2)(a) Roles and
responsibilities associated
with the development,
documentation, review,
installation, and removal of
caution tags to convey
operational information or
equipment alignments for
protection of equipment
1. Personnel are formally designated
to prepare, approve, and install tags.
2. Personnel are trained on their
responsibilities regarding tags.
3. Procedures include provisions for
documenting caution tags, including:
An indexing/numbering system
Effective date and time
The precaution or information
applicable to the situation or
equipment
Location of tags by component
name
Number or other identification
Authorization for installing the
tags
Documentation of placement
and verification of the tags
Authorization for removing tags
Documentation of removal
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-33
Lockouts and Tagouts, Attachment 2 Paragraph 2.i
1 Requirements,
Attachment 2 ¶2.i
2 Detailed Attributes
3 Doc Citation
/ Justification
4. Procedures designate the manager
responsible for caution tag approval
and location of records for review by
appropriate personnel.
5. Procedures contain provisions for
management determination that
instructions on caution tags comply
with facility procedures, technical
safety requirements, or other
specifications.
6. Situations requiring caution tags
are brought to the attention of
responsible managers, who approve
them if necessary.
7. Procedures contain provisions for
a documented periodic review of all
active caution tags to determine their
continued need, that the records are
correct, and that appropriate action is
taken to remedy conditions requiring
tags for long periods (over three
months).
2.i.(2)(b) Description and
control of the tags
1. Procedures contain provisions for
caution tags to be uniquely
identifiable and easily distinguished
from other tags.
2. Procedures contain provisions for
caution tag placement so as to not
obscure indications or controls, while
remaining readily apparent to
operators.
2.i.(2)(c) Measures to prevent
relying on caution tags for
personnel protection
1. Procedures contain provisions
restricting the use of caution tags to
situations where a component or
system is functional, but some
precaution or item(s) of information
is necessary prior to operation.
Attachment 2, Appendix A DOE O 422.1
Page A-34 6-29-2010
Lockouts and Tagouts, Attachment 2 Paragraph 2.i
1 Requirements,
Attachment 2 ¶2.i
2 Detailed Attributes
3 Doc Citation
/ Justification
2. Procedures contain provisions for
management determination that
caution tags are appropriate and that
they are not used instead of more
appropriate administrative controls or
a lockout/tagout.
Section 27
Independent Verification, Attachment 2 Paragraph 2.j
1 Requirements,
Attachment 2 ¶ 2.j
2 Detailed Attributes
3 Doc Citation
/ Justification
2.j.
The operator must establish
and implement operations
practices to verify that critical
equipment configuration is in
accordance with controlling
documents, addressing the
following elements:
2.j.(1) Structures, systems,
components, operations, and
programs requiring
independent verification
a. Procedures or other authoritative
documents explicitly identify
components whose positions must be
independently verified.
b. Management uses accepted safety
analysis methods (for example, fault
tree or probability risk analysis)
and/or expert opinion to develop the
list of equipment/components
requiring independent verification.
c. Facility management considers all
safety-related system components for
independent verification.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-35
Independent Verification, Attachment 2 Paragraph 2.j
1 Requirements,
Attachment 2 ¶ 2.j
2 Detailed Attributes
3 Doc Citation
/ Justification
d. Procedures allow exemption from
independent verification for
components whose mispositioning
does not affect system performance,
whose mispositioning is immediately
known to operators, or where
significant radiation exposure would
be required for verification. Alternate
means of determining position are
considered, and any such exemptions
are approved by senior operations
management.
e. Management considers
independent verification for
components whose mispositioning
could challenge safety-related
equipment, cause shutdowns or other
undesirable results, or lead to
unintended toxic or radioactive
material release.
f. Management specifies safety
management programs and other
functions such as training and
procedure development that will be
independently appraised to verify
their continued conformance with
regulations and directives.
2.j.(2) Situations requiring
independent verification
a. Procedures require independent
verification when equipment must be
available and it is reasonably
possible that components were
mispositioned.
b. Procedures require independent
verification of lineups to take
equipment out of service or return it
to service, e.g. isolation boundaries,
equipment under maintenance or
repair, instrumentation lineups for
testing and their restoration, work on
backup components and their
restoration, etc.
Attachment 2, Appendix A DOE O 422.1
Page A-36 6-29-2010
Independent Verification, Attachment 2 Paragraph 2.j
1 Requirements,
Attachment 2 ¶ 2.j
2 Detailed Attributes
3 Doc Citation
/ Justification
c. Procedures include appropriate
independent verification for system
lineups.
d. Procedures include appropriate
routine periodic verification of
critical components during operation,
which would not normally need a
second check.
e. Procedures include provisions for
dealing with mispositioned
components found during routine
periodic checks or lineups, including
appropriate management approval for
repositioning and subsequent
independent verification.
2.j.(3) Methods for
performing and documenting
independent verification
a. Management develops and
approves verification techniques
appropriate to facility-specific
equipment, using manufacturer’s
recommendations and expert
operators.
b. Operators are trained in techniques
appropriate to the facility’s
equipment.
Section 28
c. Procedures provide reference
documentation explaining how to
perform verification of the facility’s
components, e.g. manual, solenoid-,
motor- and air-operated valves,
circuit breakers, blank flanges,
removable links and fuses, control
power availability, and any other
specific component position or
condition required.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-37
Independent Verification, Attachment 2 Paragraph 2.j
1 Requirements,
Attachment 2 ¶ 2.j
2 Detailed Attributes
3 Doc Citation
/ Justification
2.j.(3) Independent
Verification Methods
(continued)
d. Procedures specify how to achieve
independence, including having each
check include identification of the
component and determining both its
required and actual position, and
minimizing interactions between
operators positioning components
and those verifying position, except
in special situations for throttled
valves or to reduce radiation or toxic
exposure (concurrent dual
verification).
e. Procedures favor direct local
position checks over remote
indications, absent exposure
considerations or other overriding
factors.
f. Procedures favor direct local
position checks over process
indications such as flow, pressure, or
voltage, absent exposure
considerations or other overriding
factors. Any such indirect methods
are specifically authorized in
procedures.
g. Procedures specify how to check
throttled valves. Local mechanical
position indicators, scribe marks, or
other authorized methods are
preferred over shutting and then
opening a prescribed number of
turns. If shutting/opening is
necessary, facility procedures
consider concurrent dual verification.
h. Procedures favor direct local
position checks over surveillance
testing to show component positions.
If surveillance tests are used, they
must conclusively prove component
position and must be specifically
approved by operations management.
Attachment 2, Appendix A DOE O 422.1
Page A-38 6-29-2010
Independent Verification, Attachment 2 Paragraph 2.j
1 Requirements,
Attachment 2 ¶ 2.j
2 Detailed Attributes
3 Doc Citation
/ Justification
i. Procedures specify that
components danger tagged per the
lockout/tagout program will not be
manipulated for independent
verification.
j. Procedures specify that verifiers do
not change component position or
status to correct an inconsistency.
k. Procedures specify how to
document independent verification,
including component identification;
normal or expected position, desired
position, final position, identification
and signature or initials of
positioners and verifiers for each
item, and supervisory review.
2.j.(4) Situations, if any,
allowing concurrent dual
verification
a. Procedures specify situations
where concurrent dual verification is
used. Examples are throttled valves
that must be repositioned to
determine position, or sequential
operations such as a bolt torquing
pattern.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-39
Independent Verification, Attachment 2 Paragraph 2.j
1 Requirements,
Attachment 2 ¶ 2.j
2 Detailed Attributes
3 Doc Citation
/ Justification
2.j.(5) Methods for
performing concurrent dual
verification, if used.
a. Procedures specify how concurrent
dual verification is done, if at all.
b. Procedures for concurrent dual
verification (if used) include
provisions for maintaining
independence to the maximum extent
possible, and facility policies include
Section 29
provisions preventing the use of
concurrent dual verification unless
specifically authorized.
[An example for a throttled valve: the
operator would shut the valve, the
verifier would verify the shut
position, then the operator would
open the valve the specified number
of turns while the observer observes
and counts turns silently, with both
not influencing the other, and both
record the position separately.]
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-41
Logkeeping, Attachment 2 Paragraph 2.k
1 Requirements,
Attachment 2 ¶ 2.k
2 Detailed Attributes
3 Doc Citation
/ Justification
2.k.
The operator must establish
and implement operations
practices to ensure thorough,
accurate, and timely
recording of equipment
information for performance
analysis and trend detection,
addressing the following
elements:
2.k.(1) Narrative logs at all
key positions, as defined by
management, for the
recording of pertinent
information
a. Procedures include provisions for
narrative logs maintained by the
operations supervisor or control area
operator (or equivalent) at a
minimum.
b. Procedures include provisions for
narrative logs at stations staffed part-
time to provide continuity and
information pass-down.
c. Procedures include provisions for
narrative sections on round sheets
when a separate narrative log is not
maintained.
2.k.(2) Prompt and accurate
recording of information
Attachment 2, Appendix A DOE O 422.1
Page A-42 6-29-2010
Logkeeping, Attachment 2 Paragraph 2.k
1 Requirements,
Attachment 2 ¶ 2.k
2 Detailed Attributes
3 Doc Citation
/ Justification
2.k.(3) Type, scope, and
format for log entries
a. Management provides written
direction on information to be
recorded in each log, including the
following elements to be recorded in
at least one log, but not necessarily
all in the same log:
1. Facility mode changes
2. Criticalities and criticality
information (for reactors or critical
experiments)
3. Abnormal facility
configurations
4. Status changes of safety-related
or other major equipment
5. Occurrence of reportable events
6. Starting and completing
surveillance tests
7. Entering and exiting Limiting
Conditions for Operations
8. Security incidents
9. Out-of-specification chemistry
or process analysis results or
measurements
10. Shift reliefs
11. Significant information
concerning emergencies,
abnormal, or unexpected events,
but not to interfere with taking
appropriate response actions.
b. Management provides written
direction on the format for log
entries, including legible, permanent,
smear-proof, entries capable of
machine copying.
c. Management provides written
direction on electronic log entries, if
used.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-43
Logkeeping, Attachment 2 Paragraph 2.k
1 Requirements,
Attachment 2 ¶ 2.k
2 Detailed Attributes
3 Doc Citation
/ Justification
2.k.(4) Method for recording
late entries and correcting
erroneous entries without
obscuring the original entry
a. Management provides written
direction on how to make late entries,
including noting the actual time late
entries are made and prohibiting
rewriting logs to make entries appear
timely.
b. Management provides written
direction on how to make log
corrections. A widely-accepted
industry standard is to make a single
lineout through the incorrect entry
without obscuring it and writing the
correct entry in a nearby space, with
Section 30
the date and initials of the person
making the correction.
2.k.(5) Periodic supervisory
reviews for accuracy,
adequacy, and trends
a. Management provides written
direction for periodic supervisory
review of logs for accuracy,
completeness, timeliness, trends, and
conformance with management
direction.
b. Log review practices include
periodic operations supervisor review
of control area logs, and periodic
review of operating station logs
outside the control area by the
control area supervisor or other
appropriate manager.
2.k.(6) Document retention
requirements
a. Management provides written
direction on keeping logs available
for operator review after return from
periods of absence.
b. Management provides written
direction on log storage and
preservation for the expected life of
the facility or as directed by DOE
and National Archives and Records
Administration regulation.
c. Management provides written
direction on how to retrieve stored
logs.
Attachment 2, Appendix A DOE O 422.1
Page A-44 6-29-2010
Turnover and Assumption of Responsibilities, Attachment 2 Paragraph 2.l
1 Requirements,
Attachment 2 ¶ 2.l
2 Detailed Attributes
3 Doc Citation
/ Justification
2.l.
The operator must establish
and implement operations
practices for thorough,
accurate transfer of
information and
responsibilities at shift or
operator relief to ensure
continued safe operation,
addressing the following
elements:
2.l.(1) Definitions for all key
positions requiring a formal
turnover process
a. Procedures contain provisions for
using a turnover process for at least
the supervisory positions.
b. Procedures contain provisions for
using a turnover process for key
positions, including appropriate
stations staffed part-time.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-45
Turnover and Assumption of Responsibilities, Attachment 2 Paragraph 2.l
1 Requirements,
Attachment 2 ¶ 2.l
2 Detailed Attributes
3 Doc Citation
/ Justification
2.l.(2) Turnover of
equipment/facility status,
duties, and responsibilities
that results in the safe and
effective transfer of
equipment status and in-
progress or planned activities
from one shift or workgroup
to the next
a. Turnover procedures contain
provisions for documenting a review
of checklists or other documents that
record key information appropriate
for the position, either operational or
supervisory, such as:
Facility operating mode and
status
Key process parameters
Key tank or vessel levels
Status of safety equipment
Operational limits in effect
Limiting Conditions for
Operations in effect, either
normal or abnormal
Any procedures, either standard
or temporary, in progress
Changes in radiological or
hazardous material conditions
Waste management status
Required samples or analyses
Upcoming or in-progress
maintenance, testing, or
evolutions
b. Turnover procedures contain
provisions for operators and
supervisors to complete document
reviews before assuming
responsibility for their position,
reviewing in enough detail to
understand status, important history,
and plans. Such reviews normally
extend back the shorter of 24 hours
or their last shift.
Attachment 2, Appendix A DOE O 422.1
Page A-46 6-29-2010
Turnover and Assumption of Responsibilities, Attachment 2 Paragraph 2.l
1 Requirements,
Attachment 2 ¶ 2.l
2 Detailed Attributes
3 Doc Citation
/ Justification
2.l.(2) Shift turnover
procedures (continued)
Section 31
c. Turnover procedures contain
provisions for operators and
supervisors to walk down appropriate
control panels and computer displays
to determine facility status, alarms,
lineups, and equipment
configuration. For control areas, the
oncoming and offgoing personnel
jointly walk down the control panels
and displays. Supervisors and
operators walk down panels early in
the shift and preferably before
turnover.
d. Turnover procedures contain
provisions for offgoing and
oncoming operators and supervisors
to discuss, during stable facility
conditions whenever possible,
turnover documentation and clarify
any questions.
e. Turnover procedures contain
provisions that when all turnover
items are complete and the oncoming
person understands the status, they
formally state that they assume
responsibility and make a narrative
log entry to that effect.
f. Turnover procedures contain
provisions for operations supervisors
to conduct briefings as needed for
their oncoming shift operators and
appropriate support personnel
(vendors, maintenance, crafts) to
review status, problems, upcoming
work, or other appropriate topics.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-47
Turnover and Assumption of Responsibilities, Attachment 2 Paragraph 2.l
1 Requirements,
Attachment 2 ¶ 2.l
2 Detailed Attributes
3 Doc Citation
/ Justification
2.l.(3) Process for reliefs
during a shift
a. Turnover procedures contain
provisions for conducting operator
and supervisor reliefs during shifts.
These turnovers may include a less
exhaustive process than the regular
shift change as long as the oncoming
person is at least as knowledgeable as
they would be from a regular
turnover.
Control of Interrelated Processes, Attachment 2 Paragraph 2.m
1 Requirements,
Attachment 2 ¶ 2.m
2 Detailed Attributes
3 Doc Citation
/ Justification
2.m.
The operator must establish
and implement operations
practices to ensure
interrelated processes do not
adversely affect facility safety
or operations, addressing the
following elements:
Attachment 2, Appendix A DOE O 422.1
Page A-48 6-29-2010
Control of Interrelated Processes, Attachment 2 Paragraph 2.m
1 Requirements,
Attachment 2 ¶ 2.m
2 Detailed Attributes
3 Doc Citation
/ Justification
2.m.(1) Defined
responsibilities with respect
to the control of interrelated
processes
(Processes or activities that
can affect operations, but are
under the control of persons
other than the affected
operators, such as shared
support systems or special
testing)
2.m.(2) Operator training and
qualification to understand
interrelated processes, to
interpret instrument readings,
and provide timely corrective
action for process-related
problems
2.m.(3) Establish lines of
communication between
operating personnel, process
support personnel, and other
interrelated process operators
for coordination of activities
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-49
Required Reading, Attachment 2 Paragraph 2.n
1 Requirements,
Attachment 2 ¶ 2.n
2 Detailed Attributes
3 Doc Citation
/ Justification
2.n.
The operator must establish
and implement operations
practices for an effective
required reading program to
keep operators updated on
equipment or document
changes, lessons learned, or
other important information,
addressing the following
elements:
2.n.(1) Identification of
material to be distributed via
required reading
a. Directives contain provisions for a
Section 32
required reading program, including,
as appropriate, procedure changes,
equipment design changes, operating
experience information, and other
facility-specific items.
b. Directives for the required reading
program include provisions for
listing designated items, screening
them for appropriate content, and
procuring copies of the documents.
2.n.(2) Identification of which
personnel are required to read
specific required reading
items
a. Directives for the required reading
program include provisions for
designating specific items for
specific operators or groups of
operators.
b. Directives for required reading
program include provisions for ready
access to required reading materials.
Attachment 2, Appendix A DOE O 422.1
Page A-50 6-29-2010
Required Reading, Attachment 2 Paragraph 2.n
1 Requirements,
Attachment 2 ¶ 2.n
2 Detailed Attributes
3 Doc Citation
/ Justification
2.n.(3) Distribution of
required reading to
appropriate personnel and
documentation of their timely
completion
a. Directives for the required reading
program include provisions for
assigning due dates for items,
including, where appropriate,
completion before operators go on
shift again.
b. Directives for the required reading
program include provisions for
documenting and tracking
completion of designated specific
items for specific operators or groups
of operators.
c. Directives for required reading
program include provisions for
retaining documentation of
completion and for periodic
management review for timely
assignment completion.
d. Directives for the required reading
program include provisions for
removing completed items from
distribution.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-51
Timely Instructions/Orders, Attachment 2 Paragraph 2.o
1 Requirements,
Attachment 2 ¶ 2.o
2 Detailed Attributes
3 Doc Citation
/ Justification
2.o.
The operator must establish
and implement operations
practices for timely written
direction and guidance from
management to operators,
addressing the following
elements:
2.o.(1) Appropriate
circumstances for the use of
timely instructions/orders
a. Directives for timely
instructions/orders specify
appropriate information items such as
special operations, administrative
directions, special data collection
campaigns, or notification of
expected visitors.
b. Directives for timely
instructions/orders specify
appropriate orders such as direction
to perform special evolutions or tests,
limitations on performing certain
operations, direction to perform
maintenance actions, or other
direction.
c. Directives for timely
instructions/orders include provisions
to prevent the use of timely
instructions/orders as a substitute for
administrative or operational
procedure revisions.
2.o.(2) Designated levels of
review and approval prior to
issuance
a. Directives for timely
instructions/orders include
designation of review and approval
authorities.
Attachment 2, Appendix A DOE O 422.1
Page A-52 6-29-2010
Timely Instructions/Orders, Attachment 2 Paragraph 2.o
1 Requirements,
Attachment 2 ¶ 2.o
2 Detailed Attributes
3 Doc Citation
/ Justification
2.o.(3) Configuration control
of timely instructions/orders
a. Directives for timely
instructions/orders include
segregation of timely
instructions/orders into daily and
long term categories.
b. Directives for timely
instructions/orders include provisions
for removing or canceling superseded
Section 33
or outdated items.
c. Directives for timely
instructions/orders include provisions
for periodic management reviews
that only appropriate and current
items are distributed, and that
appropriate personnel review them
within time limits.
2.o.(4) Distribution of timely
instructions/orders to
appropriate personnel and
documentation of their receipt
and understanding
a. Directives for timely
instructions/orders include provisions
for distribution of timely
instructions/orders to appropriate
operators.
b. Directives for timely
instructions/orders include provisions
for appropriate operators to review
items before or early in shift.
c. Directives for timely
instructions/orders include provisions
for documenting operator reviews
every shift for daily items, including
those that are delayed or remain in
force longer than a day, and periodic
and as-changed reviews of long term
items.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-53
Technical Procedures, Attachment 2 Paragraph 2.p
1 Requirements,
Attachment 2 ¶ 2.p
2 Detailed Attributes
3 Doc Citation
/ Justification
2.p.
The operator must establish
and implement operations
practices for developing and
maintaining accurate,
understandable written
technical procedures that
ensure safe and effective
facility and equipment
operation, addressing the
following elements:
2.p.(1) Expectations for the
use of procedures to perform
operations.
a. Management policies establish the
expectation that operators will use
written procedures for operations,
will perform them as written, and
will stop work and notify
management when procedures cannot
be executed as written.
Attachment 2, Appendix A DOE O 422.1
Page A-54 6-29-2010
Technical Procedures, Attachment 2 Paragraph 2.p
1 Requirements,
Attachment 2 ¶ 2.p
2 Detailed Attributes
3 Doc Citation
/ Justification
2.p.(2) A process for
procedure development
a. Directives include a written
process for procedure development,
including format, clear language
standards, and configuration control.
b. Management policies designate
procedures to be developed for all
anticipated operations, evolutions,
tests, and abnormal or emergency
situations.
c. Management policies direct
alarm/annunciator response
procedures to be developed for all
alarm panels.
d. Directives designate a senior
manager responsibility for procedure
development, and include provisions
for the capabilities and experience of
procedure writers.
e. Directives include a process for
completing and documenting
procedure review and approval of
both hard-copy and electronic
procedures.
f. Directives specify that procedures
will provide administrative and
technical direction to effectively
conduct the operation, using detail
appropriate to the complexity of the
task, the experience and training of
the operators, the frequency of
performance, and the significance of
the consequences of error.
g. Procedure preparation records
contain documentation of the reason
for key steps so they are not
inadvertently deleted or changed in
revisions and changes.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-55
Technical Procedures, Attachment 2 Paragraph 2.p
1 Requirements,
Attachment 2 ¶ 2.p
2 Detailed Attributes
3 Doc Citation
/ Justification
2.p.(3) Procedure content,
including consistent format
and use of terms (e.g.
prerequisites, warnings,
cautions, notes, hold points,
etc.), detail sufficient for
accomplishing the operation,
Section 34
technically accurate
procedures capable of
performance as written, and
procedure conformance with
the facility design and
manufacturer documentation
a. Procedure scope and applicability
are readily apparent.
b. Procedures for multiple equipment
trains are clearly distinguishable
from each other.
c. Emergency procedures are clearly
distinguishable from normal
operating procedures.
d. Procedures incorporate appropriate
information from applicable source
documents, including design, safety
basis, and vendor technical
documents.
e. Prerequisites and initial conditions
are clearly specified.
f. Tools, equipment, and materials
are specified and procedures provide
measures to document their
calibration or condition before use.
g. Hold points requiring independent
verification or approval are clearly
indicated.
h. Procedure language is clear,
definitions are explained, and detail
is appropriate for the operators’ skill,
experience, and training.
i. Procedure format standards: One
action per step; Warnings, Notes, and
Cautions are clear, do not contain
actions, and precede the applicable
step; Warnings, Notes, Cautions, and
headings appear on the same page as
the applicable step.
j. Procedures are technically and
administratively accurate:
instructions and information are
correct; referenced documents are
correctly identified; and instructions
for transferring between procedures
are clear.
Attachment 2, Appendix A DOE O 422.1
Page A-56 6-29-2010
Technical Procedures, Attachment 2 Paragraph 2.p
1 Requirements,
Attachment 2 ¶ 2.p
2 Detailed Attributes
3 Doc Citation
/ Justification
2.p.(3) Procedure content
(continued)
k. Critical steps include
signature/initial/checkoff blocks,
with only one action per block.
l. Instrument readings and tolerances
are specified and conform to
instrument scales or readability.
m. Procedures contain explicit
parameters and do not require mental
arithmetic to determine acceptability.
Any calculations are clearly
explained and procedures provide
space to record them.
n. Procedure step sequence conforms
to normal operational sequence.
o. Procedures reflect human factors
considerations such as procedure
callouts exactly matching equipment
labels, units in procedures match
instrument markings, charts and
graphs easily read, and important
steps or information highlighted.
p. Emergency procedures provide
guidance for both single and multiple
casualties.
q. When procedures use or refer to
other procedures or steps, they are
clearly identified with the exact
identification to prevent confusion in
transferring to or from them.
r. Procedures specify the restoration
or shutdown steps for equipment
following tests or other operations.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-57
Technical Procedures, Attachment 2 Paragraph 2.p
1 Requirements,
Attachment 2 ¶ 2.p
2 Detailed Attributes
3 Doc Citation
/ Justification
2.p.(4) A process for
procedure changes (pen and
ink or page changes) and
revisions (complete reissues)
a. Directives include a documented
process for review and approval of
revisions and changes. Directives
may also use only a revision process
or may use an electronic publishing
process. In all cases, configuration
control must be maintained.
b. Procedure changes intended for
more than one-time use are
documented in a location readily
available for operator reference and
noted in timely orders/instructions
Section 35
and/or turnover documents.
c. Directives contain provisions for
initiation of changes or revisions if
procedure problems are found,
including provisions for emergent
changes or revisions necessary to
proceed with operations when a
procedure is faulty.
d. Directives contain provisions for
initiating a procedure revision when
changes remain in effect for extended
periods (e.g. more than 6 months) or
when several changes have
accumulated (e.g. more than 5).
e. Directives contain provisions for
including all outstanding changes in
any procedure’s revision.
f. Directives include provisions for
implementing revisions for
permanent equipment modifications
or replacements, and implementing
changes for temporary equipment
modifications.
g. Directives include provisions to
review procedure development
records of the reason for key steps to
prevent inadvertent deletion or
change.
Attachment 2, Appendix A DOE O 422.1
Page A-58 6-29-2010
Technical Procedures, Attachment 2 Paragraph 2.p
1 Requirements,
Attachment 2 ¶ 2.p
2 Detailed Attributes
3 Doc Citation
/ Justification
h. Directives include provisions to
use walkthroughs (procedure
execution with actual or simulated
operation of components by subject
matter expert(s)) to validate
procedure changes and revisions.
2.p.(5) A process for training
personnel on new, revised, or
changed procedures
a. Directives include provisions for
communicating important procedure
changes and revisions to operating
personnel through required reading
or other appropriate method.
b. Directives include provisions for
communication of procedure changes
and revisions to the training
department to update training
courses.
c. Directives include provisions for
communication of procedure changes
and revisions to the organizations
responsible for personnel
qualification to update qualification
requirements.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-59
Technical Procedures, Attachment 2 Paragraph 2.p
1 Requirements,
Attachment 2 ¶ 2.p
2 Detailed Attributes
3 Doc Citation
/ Justification
2.p.(6) A process for approval
of new, revised, or changed
procedures
a. Directives include provisions for
operations supervisor or manager
approval of new or revised
procedures prior to use, with reviews
of revisions to at least the depth as
the initial version.
b. Directives include provisions for
safety committee or safety manager
or equivalent, and, if applicable,
emergency manager, review of
procedures that affect safety-related
equipment or emergency response.
c. Directives include provisions
defining appropriate circumstances
for expeditious approval of minor
procedure changes and the process,
with a minimum of at least one
designated senior qualified operator
and one senior operations manager
approval, followed up by standard
review and approval within a short
period, up to 2 weeks.
d. Directives include provisions for
using the standard review and
approval process for changes that do
not meet the facility’s criteria for
minor changes.
2.p.(7) Initial-issue and
periodic review and testing of
procedures
a. Directives include provisions for
review of new and revised
procedures prior to use and
periodically for technical accuracy
and human factors considerations.
b. Directives specify the frequency of
periodic procedure reviews,
considering the complexity of the
operation, maturity of operations, and
facility life cycle.
Section 36
c. Directives include provisions for
reviewing procedures after a
significant occurrence, either human
error or equipment upset.
Attachment 2, Appendix A DOE O 422.1
Page A-60 6-29-2010
Technical Procedures, Attachment 2 Paragraph 2.p
1 Requirements,
Attachment 2 ¶ 2.p
2 Detailed Attributes
3 Doc Citation
/ Justification
d. Procedure reviews include
comparison to source documents to
verify accuracy.
e. Procedure reviews include
validation walkthroughs.
2.p.(8) Availability and use of
the latest revisions of
procedures
a. Directives include provisions for
maintenance of a controlled copy of
all operating procedures at the
control area for operator reference,
and selected procedure controlled
copies at appropriate locations
outside the control area.
b. Directives include provisions for
verifying working copies of
procedures against controlled copies
for use during evolutions, and
controlling working copies to prevent
using outdated procedures.
c. Directives include provisions for
maintenance of controlled copies of
alarm and annunciator response
procedures readily accessible to
operators for alarm response.
d. Directives detail how operators
obtain current copies of electronic or
hard-copy procedures for performing
evolutions, and how to determine
procedure approval and revision
status.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-61
Technical Procedures, Attachment 2 Paragraph 2.p
1 Requirements,
Attachment 2 ¶ 2.p
2 Detailed Attributes
3 Doc Citation
/ Justification
2.p.(9) Specified and defined
procedure use requirements,
i.e. reader-worker method,
reference use only, use-each-
time, and emergency response
a. Operators are trained in procedure
use requirements and management
oversight reinforces the expectations.
b. Directives and management policy
contain provisions for operators to
report deficient procedures and
initiate changes or revisions to
correct them instead of continuing
on. During emergency conditions,
operators may take necessary action
to place the facility in a safe
condition, and to protect equipment,
personnel, and public safety without
first initiating a procedure change.
c. Directives define applicable
procedure use methods and specify
when to use them. Options include
reader-worker, reference, fill out
steps as a checklist, and others.
d. Directives include provisions for
use of procedures for emergency
response. Normally, immediate
actions are committed to memory
and may be executed without
reference to the procedure. When
conditions permit, operators use the
procedure to check completion of the
immediate actions and continue with
follow-up actions.
Attachment 2, Appendix A DOE O 422.1
Page A-62 6-29-2010
Operator Aids, Attachment 2 Paragraph 2.q
1 Requirements,
Attachment 2 ¶ 2.q
2 Detailed Attributes
3 Doc Citation
/ Justification
2.q.
The operator must establish
and implement operations
practices to provide accurate,
current, and approved
operator aids, addressing the
following elements:
2.q.(1) Technical evaluation
and management approval of
operator aids
a. Directives contain a process for
developing, approving, and
controlling operator aids.
b. Operators, maintenance staff, and
other facility staff are trained on the
operator aids process.
c. Operator aids are approved by
operations management prior to
posting. Approving authorities
determine the accuracy and necessity
of operator aids.
Section 37
d. Directives and management
practice do not allow operator aids to
alter procedures, but instead initiate
procedure revisions or changes if
necessary.
2.q.(2) Operator aids serve as
conveniences, not operational
requirements.
a. Directives and training provide
that operator aids serve as a
convenient reminder or quick
reference source for information, not
a substitute for procedures.
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-63
Operator Aids, Attachment 2 Paragraph 2.q
1 Requirements,
Attachment 2 ¶ 2.q
2 Detailed Attributes
3 Doc Citation
/ Justification
2.q.(3) Operator aids do not
obscure equipment,
a Directives call for posting operator
aids close to the point of use in a
manner that does not obscure
indications or controls.
b. Directives call for operator aids to
be sturdy, and securely mounted or
stowed, and waterproof where
necessary.
2.q.(4) Administrative control
of installed operator aids
a. Directives controlling operator
aids include provisions for
maintaining a master list and copy of
all approved operator aids in the
control area or other appropriate area.
The listing includes:
- Unique identification numbers for
each operator aid.
- Listing of source documents for
operator aid content, including
revision status or notation that there
are no source documents for the rare
aids that are not developed from
other sources.
- Date of approval, revision, and
posting location for operator aids
b. Directives controlling operator
aids include provisions to update
operator aids when their source
material is updated.
2.q.(5) Periodic review for
adequacy and correctness
a. Verify the accuracy, necessity, and
condition of posted operator aids.
b. Verify only approved operator aids
are posted.
c. Verify agreement between the
master list and actual postings;
remove or replace operator aids and
update the master list as needed.
d. Verify operator aids reflect the
latest revisions of source material.
Attachment 2, Appendix A DOE O 422.1
Page A-64 6-29-2010
Component Labeling, Attachment 2 Paragraph 2.r
1 Requirements,
Attachment 2 ¶ 2.r
2 Detailed Attributes
3 Doc Citation
/ Justification
2.r.
The operator must establish
and implement operations
practices for clear, accurate
equipment labeling,
addressing the following
elements:
2.r.(1) Components that
require a label
a. Directives contain provisions for
component labeling, including
identification of components and
standardized label format and colors.
Labeled components include:
1. Valves
2. Major equipment
3. Switches
4. Circuit breakers
5. Fuse panels or locations
6. Instruments and gauges
7. Busses and motor control centers
8. Cabinets, including, where
appropriate, listing major
components inside
9. Room doors
10. Emergency equipment
11. Fire protection systems
12. Piping
13.Any named SSC, item, or
operator control
DOE O 422.1 Attachment 2, Appendix A
6-29-2010 Page A-65
Component Labeling, Attachment 2 Paragraph 2.r
1 Requirements,
Attachment 2 ¶ 2.r
2 Detailed Attributes
3 Doc Citation
/ Justification
2.r.(2) Label information that
uniquely identifies
components and is consistent
with regulations, standards,
and facility documents
a. Directives for component labeling
contain provisions for label
information to match facility
documentation, including design and
safety basis documents, procedures,
lineup sheets, and other documents
that refer to components.
Section 38
b. Label nomenclature, abbreviations,
and identification codes are
standardized and included in operator
training.
c. Labeled components have unique
identification numbers.
d. Color codes are consistent and
unambiguous.
e. Piping labels indicate the fluid and
normal flow direction.
f. Piping is color coded per
OSHA/ANSI standards and piping
for hazardous and explosive
materials is uniquely identified.
2.r.(3) Durable and securely
attached labels that do not
interfere with controls or
equipment
a. Labels, adhesives, and fasteners
are made of durable materials
compatible with the material to
which they are attached.
b. Labels are securely attached.
c. Labels are oriented for easy
reading and located as close as
practical to the labeled item.
d. Labels do not interfere with
equipment operations or indicators.
Attachment 2, Appendix A DOE O 422.1
Page A-66 6-29-2010
Component Labeling, Attachment 2 Paragraph 2.r
1 Requirements,
Attachment 2 ¶ 2.r
2 Detailed Attributes
3 Doc Citation
/ Justification
2.r.(4) Administrative control
of labels, including a process
for promptly identifying and
replacing lost or damaged
labels, preventing
unauthorized or incorrect
labels, and control of
temporary labels
a. Directives prohibit informal labels
and provide a process for replacing
labels.
b. Directives provide for deliberate
inspections for missing or damaged
labels, such as post-maintenance
checks, operator tours, lineup sheets,
or other appropriate means.
c. Directives include a process to
document lost, damaged, or incorrect
labels and procure replacements.
d. Directives include provisions for
temporary replacement labels,
including: documentation of senior
operations supervisor approval,
verification of proper placement, and
documenting temporary labels in the
facility.
e. Temporary labels have the same
information content as permanent
labels.
ADMINISTRATIVE CHANGE TO DOE O 422.1, CONDUCT OF OPERATIONS
1. EXPLANATION OF CHANGES
2. LOCATIONS OF CHANGES
Section 39
CONDUCT OF OPERATIONS
1. PURPOSE. The objective of this Order is to define the requirements for establishing and implementing Conduct of Operations Programs at Department of Energy (DOE), including National Nuclear Security Administration (NNSA), facilities and projects. A Conduct of Operations Program consists of formal documentation, practices, and actions implementing disciplined and structured operations that support mission success and promote worker, public, and environmental protection. The goal is to minimize the likelih
2. CANCELLATION. DOE O 5480.19, Conduct of Operations Requirements for DOE Facilities, dated 7-9-90.
3. APPLICABILITY.
a. Departmental Applicability. This Order applies to all Departmental elements involved in operation of
(1) DOE Hazard Category 1, 2, and 3 nuclear facilities per DOE Technical Standard (DOE-STD) 1027-92 Change 1, Hazard Categorization and Accident Analysis Techniques for Compliance with DOE Order 5480.23, Nuclear Safety Analysis Reports.
(2) Accelerator, explosives, laser, nanotechnology, biohazard, chemical, or other facilities only when designated by DOE Line Management.
(3) The Administrator of the National Nuclear Security Administration (NNSA) must assure that NNSA employees comply with their responsibilities under this directive. Nothing in this directive will be construed to interfere with the NNSA Administrator’s authority under section 3212(d) of Public Law (P.L.) 106-65 to establish Administration-specific policies, unless disapproved by the Secretary.
b. DOE Contractors. Except for the equivalencies/exemptions in paragraph 3.c, the Contractor Requirements Document (CRD), Attachment 1, sets forth requirements of this Order that will apply to contracts that include the CRD.
(1) The CRD must be included in contracts that involve operation of DOE Hazard Category 1, 2, or 3 nuclear facilities.
(2) The CRD must be included in other contracts that involve operation of accelerator, explosives, laser, nanotechnology, biohazard, chemical, or other facilities only when designated by DOE Line Management.
c. Equivalencies/Exemptions for DOE O 422.1. Equivalencies and exemptions to this Order are processed in accordance with DOE O 251.1C, Departmental Directives Program. Central Technical Authority (or designee) concurrence is required for both exemptions and equivalencies to this Order for nuclear facilities.
4. REQUIREMENTS. The general approach to implementing this Order is for contractors (or DOE organizations in the case of Government owned-Government operated (GO/GO) facilities) to develop, for DOE line management approval, documentation demonstrating implementation of the requirements in the CRD (or Attachment 2 for GO/GOs). DOE line management means the federal officials such as Secretarial Officers and Heads of Field Elements responsible for DOE facilities and operations. It is not necessary to develop n
5. RESPONSIBILITIES.
6. REFERENCES.
7. DEFINITIONS.
8. CONTACT. Questions concerning this Order should be addressed to the Office of Nuclear Safety at 301-903-333.
1. GENERAL REQUIREMENTS.
2. SPECIFIC REQUIREMENTS.
a. Organization and Administration. (DOE-STD-1032-92 (CH-1), Guide to Good Practices for Operations Organization and Administration
b. Shift Routines and Operating Practices. (DOE-STD-1041-93 (CH-1), Guide to Good Practices for Shift Routines and Operating Practices)
Section 40
The operator must establish and implement operations practices to ensure that shift operators are alert, informed of conditions, and operate equipment properly, addressing the following elements:
c. Control Area Activities. (DOE-STD-1042-93 (CH-1), Guide to Good Practices for Control Area Activities)
d. Communications. (DOE-STD-1031-92 (CH-1), Guide to Good Practices for Communications)
e. On-shift Training. (DOE-STD-1040-93 (CH-1), Guide to Good Practices for Control of On-Shift Training)
f. Investigation of Abnormal Events, Conditions, and Trends. (DOE-STD-1045-93 (CH-1), Guide to Good Practices for Notifications and Investigation of Abnormal Events)
g. Notifications. (DOE-STD-1045-93 (CH-1), Guide to Good Practices for Notifications and Investigation of Abnormal Events)
h. Control of Equipment and System Status. (DOE-STD-1039-93 (CH-1), Guide to Good Practices for Control of Equipment and System Status)
i. Lockout and Tagouts. (DOE-STD-1030-96, Guide to Good Practices for Lockouts and Tagouts)
(a) procedures, roles and responsibilities associated with the development, documentation, review, installation, and removal of a lockout/tagout;
(b) compliance with Occupational Safety and Health Administration Rules, 29 CFR Part 1910 and/or 29 CFR Part 1926, requirements for the protection of workers using Lockout/Tagout;
(c) compliance with National Fire Protection Association Standard 70E electrical safety requirements using lockout/tagout;
(d) description and control of the tags, locks, lockboxes, chains, and other components utilized for the lockout/tagout program; and
(e) training and qualification in lockout/tagout and special considerations for DOE facilities, e.g., operational limitations, or seismic issues from the mass of locks or chains.
(a) roles and responsibilities associated with the development, documentation, review, installation, and removal of caution tags to convey operational information or equipment alignments for protection of equipment;
(b) description and control of the tags; and
(c) measures to prevent relying on caution tags for personnel protection.
j. Independent Verification. (DOE-STD-1036-93 (CH-1), Guide to Good Practices for Independent Verification)
k. Logkeeping. (DOE-STD-1035-93 (CH-1), Guide to Good Practices for Logkeeping)
l. Turnover and Assumption of Responsibilities. (DOE-STD-1038-93 (CH-1), Guide to Good Practices for Operations Turnover)
m. Control of Interrelated Processes. (DOE-STD-1037-93 (CH-1), Guide to Good Practices for Operations Aspects of Unique Processes)
n. Required Reading. (DOE-STD-1033-92 (CH-1), Guide to Good Practices for Operations and Administration Updates Through Required Reading)
o. Timely Instructions/Orders. (DOE-STD-1034-93 (CH-1), Guide to Good Practices for Timely Orders to Operators)
p. Technical Procedures. (DOE-STD-1029-92 (CH-1), Writer’s Guide for Technical Procedures)
q. Operator Aids. (DOE-STD-1043-93 (CH-1), Guide to Good Practices for Operator Aid Postings)
r. Component Labeling. (DOE-STD-1044-93 (CH-1), Guide to Good Practices for Equipment and Piping Labeling)
3. DEFINITIONS.