Archives of Directives

Archive

DOE O 5480.22 Chg 1, Technical Safety Requirements

Functional areas: Environmental Quality & Impact

o548022c1.pdf767.65KB
Document text

Text extracted from the attached file. Refer to the original document for the authoritative version.

Section 1

Vertical line denotes change. DISTRIBUTION: INITIATED BY: All Departmental Elements Assistant Secretary for Nuclear Energy U.S. Department of Energy ORDER Washington, D.C. 2-25-92 Change 1: 9-15-92 Change 2: 1-23-96 SUBJECT: TECHNICAL SAFETY REQUIREMENTS 1. PURPOSE. To clearly state the requirements to have Technical Safety Requirements (TSR) prepared for Department of Energy (DOE) nuclear facilities and to delineate the criteria, content, scope, format, approval process, and reporting requirements of these documents and revisions thereof. 2. CANCELLATIONS. a. Paragraphs 5h, 7e(4), and 8d of DOE 5480.5, SAFETY OF NUCLEAR FACILITIES, as of 9-23-86. b. Paragraphs 5v, 7e(4), and 8d of DOE 5480.6, SAFETY OF DEPARTMENT OF ENERGY-OWNED NUCLEAR REACTORS, as of 9-23-86. 3. SCOPE. The provisions of this Order apply to all Departmental Elements and to covered contractors to the extent implemented under a contract or other agreement. A covered contractor is a seller of supplies or services, involving a DOE-owned or -leased nuclear facility, under a contract or subcontract containing one of four contract clauses as follows: (a) Safety and Health (Government-owned or -leased facility) [DEAR 970.5204-2], (b) Nuclear Facility Safety [DEAR 970.5204-26], (c) Radiation Protection and Nuclear Criticality [DEAR 952.223-72], or (d) another clause whereby DOE elects to require compliance with DOE nuclear safety requirements. The provisions of this Order will be applied to DOE-owned nuclear facilities and operations exempt from Nuclear Regulatory Commission (NRC) licensing, excluding those facilities and activities conducted under Executive Order 12344 and Public Law 98-525. 4. EXCLUSIONS. Director of the Naval Nuclear Propulsion Program: Executive Order 12344, statutorily prescribed by P.L. 98-525 (42 U.S.C. 7158, Note) establishes the responsibilities and authorities of the Director of the Naval Nuclear Propulsion Program (who is also the Deputy Assistant Secretary for Naval Reactors within the Department) for all facilities and activities that comprise the Program, a joint Navy-DOE organization. DOE 5480.22 http://www.explorer.doe.gov:1776/pdfs/archiveordtext/pagechanges/548022c1.pdf http://www.explorer.doe.gov:1776/pdfs/archiveordtext/pagechanges/548022c2.pdf Important If you want to see the changes only, simply click on the link provided. 2 DOE 5480.22 2-25-92 These executive and legislative actions establish that the Director is responsible for all matters pertaining to naval nuclear propulsion, including direction and oversight of environment, safety, and health matters for all program facilities and activities. Accordingly, the provisions of this order do not apply to the Naval Nuclear Propulsion Program. 5. REFERENCES. a. b. c. d. e. f. g. h. i. j. DOE 1324.2A, RECORDS DISPOSITION, of 9-13-88, which establishes the Departmental records disposition program. DOE 3790.1A, FEDERAL EMPLOYEE OCCUPATIONAL SAFETY AND HEALTH PROGRAM, of 10-22-84, which establishes the policy and requirements for the occupational safety and health program for Federal employees. DOE 5000.3A, OCCURRENCE REPORTING AND PROCESSING OF OPERATIONS INFORMATION, of 5-30-90, which establishes reporting of unusual occurrences with programmatic significance for DOE operations. DOE 5480.3, SAFETY REQUIREMENTS FOR THE PACKAGING AND TRANSPORTATION OF HAZARDOUS MATERIALS, HAZARDOUS SUBSTANCES, AND HAZARDOUS HASTES, of 7-9-85, which establishes the requirements for packaging and transportation of hazardous materials, hazardous substances, and hazardous wastes.

Section 2

DOE 5480.5, SAFETY OF NUCLEAR FACILITIES, of 9-23-86, which establishes DOE’s nonreactor nuclear facility safety program. DOE 5480.6, SAFETY OF DEPARTMENT OF ENERGY-OWNED NUCLEAR REACTORS, of 9-23-86, which establishes requirements for a WE reactor safety program. DOE 5480.20, PERSONNEL SELECTION, QUALIFICATION, TRAININ6, AND STAFFING REQUIREMENTS AT DOE REACTOR AND NONREACTOR NUCLEAR FACILITIES, of 2-20-91, which establishes the selection, qualifications, training, and staffing requirements for personnel at Department of Energy-owned nuclear facilities. DOE 5480.21, UNREVIEWED SAFETY QUESTIONS, of 12-24-91, which sets forth the definitions and basis for determining the existence of an Unreviewed Safety Question. DOE 5481.1B, SAFETY ANALYSIS AND REVIEW SYSTEM, of 9-23-86, which establishes uniform requirements for the preparation and review of safety analyses. Title 10, CFR 50.36, which establishes the Technical Specifications and requirements for commercial nuclear facilities. DOE 5480.22 2-25-92 3 k. NUREG-1431, STANDARD TECHNICAL SPECIFICATIONS FOR WESTINGHOUSE PLANTS, January 1991, which presents the standard Technical Specifications for Westinghouse nuclear reactors. l. ANS-15.1-1982;R90, DEVELOPMENT OF TECHNICAL SPECIFICATIONS FOR RESEARCH REACTORS, which is the national consensus standard for the Technical Specification requirements for research reactors. m. Executive Order 12344, which establishes the responsibilities of the Director as including the safety of reactors and associated naval nuclear propulsion plants, the control of radiation and radioactivity associated with naval nuclear propulsion plants, and the operating practices and procedures applicable to naval nuclear propulsion plants. 6. DEF INITIONS. a. b. c. d. e. f. g. Category A Reactor Facilities means those production, test, and research reactors designated by DOE based on power level (e.g., design thermal power rating of 20 megawatts steady state and higher), potential fission product inventory, and experimental capability. Category B Reactor Facilities means those test and research reactors designated by DOE based on power level (e.g., design thermal power rating of less than 20 megawatts steady state), potential fission product inventory, and experimental capability. Certification as stated in DOE 5480.20, chapter I, paragraph 6. Contractor means any person under contract with the Department of Energy with responsibility to perform activities in connection with a nuclear facility. Controlled Document is a document whose content is maintained uniform among the copies by an administrative control system. Hazardou s Materials are those materials that are toxic, explosive, flammable, corrosive, or otherwise physically or biologically health threatening. Nonreactor Nuclear Facility. Those activities or operations that involve radioactive and/or fissionable materials in such form and quantity that a nuclear hazard potentially exists to the employees or the general public. Included are acttvities or operations that: (1) Produce, process, or store radioactive liquid or solid waste, fissionable materials, or tritium; (2) Conduct separations operations; 4 h. i. j. k. 1. m. n. DOE 5480.22 2-25-92 (3) Conduct irradiated materials inspection, fuel fabrication, decontamination, or recovery operations; (4) Conduct fuel enrichment operations; or (5) Perform environmental remedi ati on or waste management activities involving radioactive materials.

Section 3

Incidental use and generating of radioactive materials in a facility operation (e.g., check and calibration sources, use of radioactive sources in research and experimental and analytical laboratory activities, electron microscopes, and X-ray machines) would not ordinarily require the facility to be included in this definition. Accelerators and reactors and their operations are not included. The application of any rule to a nonreactor nuclear facility shall be applied using a graded approach. Nuclear facility means reactor and nonreactor nuclear facilities. Program Manager means the Headquarters (HQ) individual, or his designee appointed by and under the direction of a Program Secretarial Officer, who is directly involved in the operation of a facility under his cognizance and who holds signature authority to provide technical direction through field offices to DOE contractors for these facilities. Program Secretarial Officer (PSO) means the heads of DOE offices with responsibility for specific facilities. These include the Assistant Secretaries for Conservation and Renewable Energy, Nuclear Energy, Defense Programs, Environmental Restoration and Waste Management and, Fossil Energy, and the Directors of Energy Research, Civilian Radioactive Waste Management, and New Production Reactors. Reactor Operator is as stated in DOE 5480.20, (page 5, paragraph 6.s). Risk is quantitative or qualitative expression of possible loss that considers both the probability that a hazard will cause harm and the consequences of that event. Safety Analvs is means documented processes: (1) to provide systematic identification of hazards within a given DOE operation, (2) to describe and analyze the adequacy of the measures taken to eliminate, control, or mitigate identified hazards; and (3) to analyze and evaluate potential accidents and their associated risks. Safety Analysis Repo tr (SAR) means that report which documents the adequacy of safety analysis for a nuclear facility to ensure that the facility can be constructed, operated, maintained, shut down, DOE 5480.22 2-25-92 5 and decommissioned safely and in compliance with applicable laws and regulations. o. Senior Reactor Operator is as stated in DOE 5480.20, (page 5, paragraph 6.i) p. Technical Safety Requ irements (TSRs) means those requirements that define the conditions, safe boundaries, and the management or administrative controls necessary to ensure the safe operation of a nuclear facility and to reduce the potential risk to the public and facility workers from uncontrolled releases of radioactive materials or from radiation exposures due to inadvertent criticality. A TSR consists of safety limits, operating limits, surveillance requirements, administrative controls, use and application instructions, and the basis thereof. TSRs were formerly known as Operational Safety Requirements for nonreactor nuclear facilities and Technical Specifications for reactor facilities. q. Unreviewed Safety Questions. A determination made by examining the following circumstances: (1) Temporary or permanent changes in the facility as described in existing safety analyses; (2) Temporary or permanent changes in the procedures as derived from existing safety analyses; and (3) Tests or experiments not described in existing safety analyses. On identification of any of the above circumstances, an Unreviewed Safety Question exists if one or more of the following conditions result:

Section 4

(1) The probability of occurrence or the consequences of an accident or malfunction of equipment Important to safety as previously evaluated in the facility safety analyses could be increased; (2) The possibility for an accident or malfunction of a different type than any evaluated previously in the facility safety analyses could be created; and (3) Any margin of safety as defined in the bases of the Technical Safety Requirements could be reduced. 7. Policy. It is the policy of the Department that nuclear facilities operate within PSO-approvee Technical Safety Requirements which prescribe the bounds for safe operation of these facilities in order to protect the health and safety of the public and reduce risk to workers., 6 8. DOE 5480.22 2-25-92 RESPONSIBI LITIES AND AUTHORITIES a. Program Secretarial Officers (PSOs) shall carry out responsibilities for facilities under their program jurisdiction that include, but are not limited to, the following: (1) Require preparation of Technical Safety Requirements for all nuclear facilities, unless for a particular facility, based upon safely analysis, the PSO determines that a TSR would not be appropriate for that particular facility. In the case of such a determination, the requirements of this Order do not apply. (2) (3) (4) (5) (6) (7) (8) (9) Grant temporary exemptions for up to one year from the provisions of this Order after notifying the Secretary. Request the Secretary grant permanent exemptions from this Order after concurrence from the Assistant Secretary for Nuclear Energy, Assistant Secretary for Environment, Safety and Health, and/or the Director, Office of Nuclear Safety, as appropriate. Issue a directive that shall delineate the flow of TSR or TSR change submittals from the contractor through the line and review, approval, and concurrence responsibilities. Review and approve schedules for preparing new Technical Safety Requirements in accordance with this Order. Review and approve new Technical Safety Requirements and revisions thereto for all nuclear facilitates. Provide guidance and assistance to field organizations in the performance of safety reviews, appraisals, and the preparation of Technical Safety Requirements. Conduct appraisals to assure compliance with this Order. Direct the line to transmit the results of the actions taken under subparagraphs (3), (4), (5), and (7) to the responsible program managers and field organizations with any necessary appropriate instruction as to subsequent action to be taken. Copies of these documents shall be forwarded to the Director, Office of Nuclear Safety and the Office of Environment, Safety and Health according to the respective issues (nuclear versus nonnuclear and occupational safety and health) being addressed. (10) Designate an individual (s) to be responsible for bringing to the attention of the contracting officer each procurement falling within the scope of this Order. Unless another DOE 5480.22 2-25-92 b. 7 individual is designated, the responsibility is that of the procurement request originator (the individual responsible for initiating a requirement on DOE F 4200.33). (a) (b) Procurement Request Originators (the individuals responsible for initiating a requirement on DOE F 4200.33) or such other individuals(s) as designated by the cognizant PSO shall bring to the attention of the cognizant contracting officer the following: (1) each procurement requiring the application of this Order, (2) requirements for flowdown of provisions of this Order to any subcontract or subaward, and (3) identification of the paragraphs or other portions of this Order with which the awardee, or if different, a subawardee, is to comply.

Section 5

Contracting Officers , based on advice received from the procurement request originator or other designated individual, shall apply applicable provisions of this Order to awards falling within its scope. For awards, other than management and operating contracts, this shall be by incorporation or reference using explicit language in a contractual action, usually bilateral. All paragraphs of this Order shall be applied to contractors excluding paragraph 7. Heads of Field Offices shall carry out responsibilities that include, but are not limited to, the following: (1) Review all new Technical Safety Requirements and revisions to Technical Safety Requirements submitted by contractors under their cognizance and take review responsibilities as directed by the cognizant PSO. (2) Take such action as may be appropriate, including curtailment and suspension of operations, when, in their opinion, such operations may result in an undue risk to health, safety, or the environment. (3) Provide the PSO (with a copy to NS-1 and EH-1) appropriate safety documentation (e.g, Implementation Schedules, Technical Safety Requirements, and Technical Safety Requirements Change Requests) to permit those organizations to meet responsibilities as outlined in this Order as directed by the PSO. (4) Assure that applicable DOE contractors implement the requirements of this Order and provide advisory services to DOE contractors on matters involving policies, standards, codes, guides, and procedures which relate to the requirements of this Order as directed by the PSO. DOE 5480.228 2-25-92 (5) Designate an individual(s) to be responsible for bringing to the attention of the contracting officer each procurement falling within the scope of this Order. Unless another individual is designated, the responsibility is that of the procurement request originator (the individual responsible for initiating a requirement on DOE F 4200.33). (a) Procurement request originators (the individuals responsible for initiating a requirement on DOE F 4200.33) or such other individuals(s) as designated by the cognizant heads of field organizations shall bring to the attention of the cognizant contracting officer the following: (1) each procurement requiring the application of this Order, (2) requirements for flowdown of provisions of this Order to any sub- contract or sub-award, and (3) identification of the paragraphs or other portions of this Order with which the awardee, or, if different, a sub-awardee, is to comply. (b) Contracting officers based on advice received from the procurement request originator or other designated individual, shall apply applicable provisions of this Order to awards falling within its scope. For awards, other than management and operating contracts, this shall be by incorporation or reference using explicit language in a contractual action, usually bilateral. All paragraphs of this Order shall be applied to contractors excluding paragraph 7. c. The Director, Office of Nuclear Safety (NS-1) acting as the independent element responsible for nuclear safety oversight of line management for the Department, shall: (1) (2) (3) (4) (5) Monitor and audit the implementation of all aspects of this Order related to nuclear safety, including field organization and contractor performance; Review documentation such as Technical Safety Appraisals, Safety Analysis Reports (SARs), implementation schedules, TSRs, program office and onsite reports, and observe on-site activities;

Section 6

Identify circumstances that are indicative of deteriorating or poor performance that may warrant further action;. Review and concur in the Department’s nuclear safety policy; and Concur with requests for permanent exemptions from the requirements of this Order. DOE 5480.22 2-25-92 d. 9 Assistant Secretary for Environment, Safety and Health (EH-1), acting as the independent element responsible for nonnuclear safety oversight of line management for the Department, which includes issues related to environment, radiation protection, industrial hygiene, uncontrolled releases of nonradioactive hazardous materials, occupational safety and health shall: (1) Monitor and audit all aspects of the implementation of this Order related to EH functional areas of responsibility including field organization and contractor performance; (2) Review documentation and observe on-site activities and identify circumstances indicative of poor performance that may warrant further action; and (3) Concur with requests for permanent exemptions from the requirements of this Order within their areas of responsibility. 9. TECHNICAL SAFETY REQUIREMENTS. a. A contractor responsible for the operation of a DOE nuclear facility shall: (1) prepare Technical Safety Requirements for the facility; (2) submit the Technical Safety Requirements to the PSO for approval; and (3) operate the facility in accordance with the Technical Safety Requirements as approved by the PSO including any modification by the PSO; b. Technical Safety Requirements shall define the operating limits and surveillance requirements, the basis thereof, safety boundaries, and management or administrative controls necessary to protect the health and safety of the public and to minimize the potential risk to workers from the uncontrolled release of radioactive or other hazardous materials and from radiation exposure due to inadvertent criticality. Technical Safety Requirements shall be based on the facility Safety Analysis Report and shall set forth specific limits and other requirements as specified in this Order and Attachment 1 to this Order, Guidelines for Technical Safety Requirements.n Attachment 1 presents an approach for the implementation and preparation of Technical Safety Requirements documents which is acceptable to DOE. Other approaches that are compatible with Attachment 1 may be utilized providing that they are justified and approved in writing by the PSO. 10 DOE 5480.22 c. d. e. 2-25-92 The TSR and its appendices constitute an agreement or contract between DOE and the facility operating management regarding the safe operation of the facility. As such, they cannot be changed without PSO approval. TSRs should be written in a clear and concise manner, in language that is directed at and clearly understandable by those in the facility operating organization. The TSR should not contain excessive details that are more appropriate to the Safety Analysis Report. Technical Safety Requirements shall consist of the following: (1) Use and Application. Definitions of terms, operating modes, frequency notations, and actins to be taken in th eevent of violation of Technical Safety Requirements operating limits or surveillance requirements are to be included in the Use and Application section. This section of the Technical Safety Requirements shall contain the basic instructions for using and applying the safety restriction contained in the Technical Safety Requirements.

Section 7

(2) Safety Limits (SL). Safety Limits are limits on process variables associated with those physical barriers, generally passive, that are necessary for the intended facility function and which are found to be required to guard against the uncontrolled release of radioactivity and other hazardous materials (this includes releases into the complex and/or the community). If any Safety Limit is exceeded at any reactor or nonreactor nuclear facility, action shall begin immediately to place the facility in the most stable, safe condition attainable including total shutdown of either reactor or nonreactor nuclear facilities. The appropriate time frame for the completion of the action for each nuclear facility has to be developed and justified by the contractor, as appropriate, in the TSR document which requires PSO approval. The Sls shall describe the action to be taken when an SL is exceeded. If a SL is exceeded, the contractor shall notify DOE in accordance with DOE 5000.3A, review the matter, and record the results of the review. The review shall include the cause of the condition and the basis for any corrective actions taken to preclude reoccurrence. The safe, stable condition entered as corrective action shall be maintained until the cognizant Program Manager authorizes further operations. (3) Operating Limits (a) Limiting Control Settings (LCS). Limiting Control Settings are settings on safety systems that control process variables to prevent exceeding Safety Limits. 11DOE 5480.22 2-25-92 (4) (b) This subsection of the Technical Safety Requirements shall contain the settings for automatic alarms and automatic or non-automatic initiation of protective actions related to those variables having significant safety functions. The specific settings shall be chosen such that if exceeded, sufficient time is available to automatically or manually correct the condition prior to exceeding Safety Limits. If the automatic alarms or protective devices do not function as required during applicable operating modes, the contractor shall take action as defined in the Limiting Control Setting to maintain the variables within the requirements and to promptly repair the automatic devices or the affected part of the process or, if required, the facility shall be placed in its most safe, stable condition. The LCS shall describe the action to be taken in case of exceedance of LCS. If an LCS is exceeded, the contractor shall notify DOE in accordance with DOE 5000.3A, review the matter, and record the results of the review including the cause of the condition and the basis for any corrective actions taken to preclude reoccurrence. Limiting Conditions for Operatlon l (LCO). Limiting Conditions for Operation are the lowest functional capability or performance level of safety-related structures, systems, component and their support systems required for normal safe operation of the facility. This subsection of the TSR shall contain the limits on functional capability or performance level. When a Limiting Condition for Operation is not met, the contractor shall take remedial actions defined by the Technical Safety Requirements until the condition can be met. The LCO shall describe the action to be taken in case of exceedance of the LCO. In cases of exceedance of an LCO, the contractor shall notify DOE in accordance with DOE 5000.3A, review the matter, and record the results of the review including the cause of the condition and the basis for any corrective actions taken to preclude reoccurrence.

Section 8

Surveillance Requirements. Surveillance Requirements are requirements relating to test, calibration, or inspection to ensure that the necessary operability and quality of safety- related structures, systems, components, and their support systems required for safe operation of the facility are maintained. This section of the Technical Safety Requirements shall contain the requirements necessary to maintain operation of the facility within the Safety Limits, Limiting Control Settings, and Limiting Conditions for Operations. In the event that Surveillance Requirements are 12 DOE 5480.22 2-25-92 (5) not successfully completed or accomplished within their required frequency, the systems or components involved shall be assumed to be inoperative and actions defined by the Limiting Condition for Operation or Limiting Control Setting shall be taken until the systems or components can be shown to be operable. Administrative Controls. Administrative Controls are the provisions relating to organization and management, procedures, recordkeeping, reviews, and audits necessary to ensure safe operation of the facility. This section of the Technical Safety Requirements shall contain the requirements associated with Administrative Controls including those for reporting deviations from Technical Safety Requirements (i. e., exceedances of LCO, LCS, or SR, or violation of TSR). Staffing requirements for facility position important to safe operation of the facility shall be provided in the Administrative Controls sections. Physical and administrative controls of the criticality safety program shall also be provided in the Administration Controls section. (6) Appendices. The following information shall be in the Appendices: (a) Basis. This Appendix shall provide summary statements of the reasons for the operating limits and associated surveillance requirements. The basis shall show how the numeric value, the condition, or the surveillance does fulfill the purpose derived from the safety documentation. The primary purpose for describing the basis for each requirement will not affect its original intent or purpose. (b) Design Features. This Appendix shall describe passive design features of the facility which, if altered or modified, would have a significant effect on safe operation. If Design Features are in a DOE-approved Safety Analysis Report, this Appendix is not required. f. The TSR shall be kept current at all times so that it reflects the facility as it exists and as it is analyzed in Safety Analysis Reports. Contractors shall determine whether revisions to the Technical Safety Requirements are required upon originating or proposing a revision to a Safety Analysis Report, and, if SO, shall prepare revisions and submit them with their basis for PSO approval concurrent with the revisions to the Safety Analysis Report. The TSR must be approved prior to facility or facility practice change. To assure that the TSR is current, it shall be reviewed at least annually along with the facility Safety Analysis Report. DOE 5480.22 Chg 2 13 1-23-96 g. All proposed revisions to Technical Safety Requirements or its Appendices shall be submitted for PSO approval. Such submittals shall include the basis for the proposed revision. Revision implementation shall occur only after PSO approval. h. Only the current PSO-approved Technical Safety Requirements shall be used for the operation of the facility. The current PSO- approved Technical Safety Requirements shall be a controlled document.

Section 9

i. A contractor may take emergency actions that depart from the approved Technical Safety Requirements when no actions consistent with the Technical Safety Requirements are immediately apparent, and when these actions are needed to protect the public health and safety. Such contractor actions shall be approved, as a minimum, by a certified operator or supervisor certified on that system through an accredited training program. If emergency actions are taken, verbal notifications shall be made to the Head of the Field Element within 2 hours and by written reports to the PSO within 24 hours. 10. IMPLEMENTATION. a. For new facilities, the contractor shall submit a draft Technical Safety Requirements document with its appendices to the PSO for approval. PSO approval of the Technical Safety Requirements document shall be obtained prior to operation. b. For existing facilities that do not have DOE approved Technical Specifications or Operational Safety Requirements, the contractor shall submit for approval a schedule for the development and delivery of a draft Technical Safety Requirements document and its appendices that satisfy the requirements of this Order. This schedule shall be submitted to the PSO for approval by August 25, 1992. This submittal shall include the basis for the content, schedule, and level of detail proposed, basis for interim operation or restrictions on interim operations, and administrative controls during the upgrade process. Once a submitted plan and schedule is approved by the PSO, the contractor shall comply with the plan and schedule including any modifications made by the PSO. Unless approved by the PSO earlier, the plan and schedule submitted by a contractor, as modified or directed to be modified by the PSO, shall be considered to be approved 180 days after submittal. Approved plans and schedules may be changed, but such changes must be approved in the same manner as initial plans and schedules. c. For existing facilities that have DOE-approved Technical Specifications or Operational Safety Requirements, a review shall be conducted by the contractor to compare these documents with the provisions of this Order and its related guidance, Attachment 1. Vertical line denotes change. 14 DOE 5480.22 Chg 2 1-23-96 (1) If the existing Technical Specifications or Operational Safety Requirements comply with the provisions of this Order and guidance, except for format, the contractor shall submit a statement to the PSO stipulating to that fact by August 25, 1992. A copy of the existing documents shall accompany the statement. The PSO shall review this statement for approval. A schedule shall be submitted to the PSO for the conversion of the existing Technical Specifications or Operational Safety Requirements to Technical Safety Requirements (i.e., reprinting, changing references in procedures, etc.). Unless approved by the PSO earlier, the statement and schedule submitted by the contractor, as modified or directed to be modified by the PSO, shall be considered to be approved 180 days after submittal. Approved statements and schedules may be changed but such changes must be approved in the same manner as initial statements and schedules. The existing Technical Specifications or Operational Safety Requirements shall be converted to Technical Safety Requirements (i.e., reprinting, changing references in procedures, etc.) when revisions are made to the documents.

Section 10

During the interim period until the revised Technical Safety Requirements are approved by the PSO, the existing Technical Specifications or Operational Safety Requirements or subset thereof shall be treated as DOE-approved Technical Safety Requirements for purposes of this Order. (2) If the existing Technical Specification or Operational Safety Requirements do not comply with the provisions of this Order and guidance (Attachment 1), the contractor shall provide a plan and schedule for making the revisions necessary to bring the document into compliance. The schedule shall be submitted to the PSO for approval by August 25, 1992. This submittal shall describe the need for upgrading the TS or OSR and shall include the basis for the content, schedule, and level of detail proposed, Vertical line denotes change. DOE 5480.22 Chg 2 15 (and 16) 1-23-96 basis for interim operation or restrictions on interim operations, and administrative controls during the upgrade process. Once a submitted plan and schedule is approved by the PSO, the contractor shall comply with the plan and schedule including any modifications by the PSO. Unless approved by the PSO earlier, the plan and schedule submitted by a contractor, as modified or directed to be modified by the PSO, shall be considered to be approved 180 days after submittal. Approved plans and schedules may be changed, but such changes must be approved in the same manner as the initial plans and schedules. JAMES D. WATKINS Admiral, U.S. Navy (Retired) Vertical line denotes change. DOE 5480.22 Page i (and ii) 2-25-92 Attachment 1 GUIDELINES FOR TECHNICAL SAFETY REQUIREMENTS DOE 5480.22 Attachment 1 Page iii2-25-92 TABLE OF CONTENTS Attachment 1 Page iv DOE 5480.22 2-25-92 DOE 5480.22 2-25-92 List of Figures Attachment 1 Page v Attachment 1 Page vi DOE 5480.22 2-25-92 List of Acronyms ANSI - American National Standards Institute ASME - American Society of Mechanical Engineers Limiting Conditions for Operation Limiting Control Setting Operating Limit Operational Safety Requirements Program Manager Personnel Protective Clothing and Equipment Program Secretarial Officer Safety Analysis Report Safety Limit Surveillance Requirements Technical Specifications Technical Safety Requirements CERCLA- Comprehensive Environmental Response, Compensation, and Liability Act LCO - LCS - OL - OSR - PM - PPE - PSO - SAR - SL - SR - TS - TSR - USNRC - United States Nuclear Regulatory Commission USQ - Unresolved Safety Question DOE 5480.22 Attachment 1 2-25-92 Page 1 BACKGROUND The following discussion addresses general topics associated with the development, use, and philosophy of Technical Safety Requirements (TSR). This information is supplied to provide the user of this Guide with background information to allow for better utilization of this Guide.

Section 11

1. Source Documents for the TSR. In the development of setpoints, limits, staffing requirements, and other parameters for input into the TSR, the site-specific Safety Analysis Report (SAR), and especially the safety analyses contained therein, is to serve as the source document. The requirements that are to be included in TSRs should be derived from these site-specific safety analyses, which consider all credible accidents (generally termed design basis accidents) including the most significant possible releases of radioactive and other hazardous materials, criticality scenarios, and the accidental releases expected during the lifetime of the facility. Careful and thorough examination of the accident analyses will yield values for defining the operational limits necessary to assure that facility operation does not occur outside the bounds assumed in the analyses. Such an examination will also identify parameters and operating conditions that should be limited in order to reduce, provide warning of, and mitigate the uncontrolled release of hazardous materials and to prevent inadvertent criticality. Examples of requirements expected to be developed include: operating limits for principal process parameters, technical and administrative conditions that must be met, availability of safety equipment and systems, and critical functions of instrumentation and controls. Operation within the bounds of the resulting requirements will provide reasonable assurance that the nuclear facility will not threaten the health and safety of the public or pose an undue risk to workers from uncontrolled releases of radioactive or other hazardous materials and inadvertent criticality. For facilities that do not have a Department of Energy (DOE)-approved SAR, the technical input into the TSR may be derived from existing documents/analyses that specifically demonstrate the limiting conditions that the facility is expected to experience during normal operation and upset conditions. In order to serve as the basis for the TSR, these documents/analyses must systematically evaluate: a) all potential off- normal conditions that are expected to occur during the life of the facility and (b) what could be considered design basis accidents. In areas that the SAR does not directly supply all of the input for the TSR, such as surveillance intervals and acceptance criteria, national and international codes, standards, and guides are to be used wherever possible. Use of a value less conservative than that expressed in applicable codes, standards, and guides should be justified in the SAR. Where codes, standards, and guides conflict, the selection of a particular code, standard, or guide to follow should be justified; normally the most conservative should be selected. Where no code, standard, or guide is applicable, other documents, such as risk assessments and manufacturer documentation, may serve as a basis; a Attachment 1 DOE 5480.22 Page 2 2-25-92 justification should be placed in the SAR. The sources of TSR information for the SAR are shown in Figure 1. 2. Violation of TSR. Violations of the TSR occur as the result of four circumstances: (a) Exceeding a Safety Limit (SL); (b) Failure to take the actions required within the required time limit following: (1) exceeding a Limiting Control Setting (LCS), (2) failure to meet Limiting Conditions for Operation (LCO), or (3) failure to successfully meet a Surveillance Requirement (SR);

Section 12

(c) Failure to perform a surveillance within the required time limit; and (d) Failure to comply with an Administrative Control requirement. For subparagraph (2b) above, it iS important to note that the violation relates to failure to comply with an Action Statement. The actions required to be taken when LCS are exceeded or when operations outside an LCO occur are intended to provide compensatory protection for the same safety concerns for which the limit was established. Thus, exceeding the limit, by itself, is not considered a violation but is a reportable event as an off-normal occurrence (DOE 5000.3A, Attachment 1, page 4, Group 1C). Reporting TSR violations to DOE must be done in accordance with DOE 5000.3A. other reporting requirements, such as entering an LCO Action Statement, must be listed and discussed in Section 5, “Administrative Controls.” 3. Conditions Outside TSR In an emergency, if a situation develops that is not addressed by the TSR, site personnel are expected to use their training and expertise to take actions to correct or mitigate the situation. Also, site personnel may take actions that depart from a requirement in the TSR provided that: (a) an emergency situation exists; (b) these actions are needed immediately to protect the public health and safety; and (c) no action consistent with the TSR can provide adequate or equivalent protection. Such action must be approved minimally by an operator or supervisor who is certified on the system or reactor through a DOE-accredited training program. If emergency action iS taken, both a verbal notification shall be made to the responsible Head of the Field Element and a written report made to the Program Secretarial Officer (PSO) within 24 hours. Attachment 1 DOE 5480.22 Page 4 2-25-92 4. Administrative Control of TSR. The facility must be operated in accordance with the provisions of a current DOE-approved TSR. In order to ensure this is the case, the TSR and its appendices must be an administratively controlled document so that only current copies of the DOE-approved TSR are used for operation of the facility. Making the TSR controlled involves establishing a list of the copies of the TSR that serve as “official” copies, then instituting a formal process of issuing and distributing the copies as well as installing DOE-approved changes in them. 5. Requirement to Update TSR. No changes may be made to the TSR until they have been approved by the PSO. The TSR is to be a living document, that is, it is to be updated prior to changes to the facility, the way the facility is operated, or the facility’s Safety Analyses. Operating with an outdated TSR is prohibited. Should a discrepancy between the facility and the TSR be discovered, it must be reported to DOE in accordance with DOE 5000.3A, an evaluation must be performed to determine if an Unreviewed Safety Question exists per DOE 5480.21, and the discrepancy must be resolved in an expeditious manner.

Section 13

6. Worker Safety. DOE’s first safety responsibility must be the protection of the public. Those who work at DOE facilities accept some risk of exposure to radioactive and other hazardous materials due to the nature of the materials with which the facilities operate. Nevertheless, it is incumbent upon DOE to assure that its facilities are operated in a manner that minimizes the risk to workers and limits exposures to hazardous materials to levels permitted by Federal or State regulations and relevant DOE Orders. The TSRs, by requiring the facilities to operate within predetermined safety limits, not only protect the public health and safety and that of nearby workers but also inherently reduce the risk to workers and facilities. The TSRs are not based upon maintaining worker exposures below some acceptable level following an uncontrolled release of hazardous material or inadvertent criticality; rather the risk to workers is reduced through the reduction of the likelihood and potential impact of such events. This is accomplished by the development of safety requirements in the TSR for those systems, components, and equipment that: (a) are barriers preventing the uncontrolled release of radioactive and other hazardous materials; (b) mitigate such releases; and (c) prevent inadvertent criticality. It should be noted that the impact from the release of hazardous materials is also reduced through industrial hygiene and radiation protection oversight (e.g., monitoring of worker exposures, use of personal protective clothing and equipment (PPE) and emergency evacuation planning), as well as the use of TSRs. Consistent with relevant DOE Orders, the control of the levels of hazardous materials to which workers may, at any time, be exposed is addressed in each facilities’ safety and health programs. These programs are required by reference in the Administrative Control Section of the TSR. Because of the necessary and inherent presence of hazardous and radioactive materials at DOE nuclear facilities and the workers’ DOE 5480 l 22 Attachment 1 2-25-92 Page 5 proximity to these materials, it is impractical to reduce worker risk to an insignificant level through selection of operating limits in TSRs. The protection of the health and safety of workers is assured by the combination of: (a) the development of TSRs for barriers to uncontrolled releases and for preventative and mitigative systems, components, and equipment; (b) use of PPE; (c) emergency protection programs; (d) worker education; and (e) drills. 7. Size and Complexity of TSR Category A reactors and highly hazardous nonreactor nuclear facilities are expected to have far more extensive TSRs than other facilities, even though the documents were developed with the same starting point criteria. This is because Category A reactors and highly hazardous nonreactor nuclear facilities usually require a greater number of limits on operation and a larger number of safety- related systems for which limits must be established. The number and complexity of the systems needed to maintain an acceptable level of risk will result in comparably complex TSRs. TSRs are developed primarily to detect indications of potential failure of engineered systems, to demonstrate operability of such systems, and to provide actions in the event that such systems become inoperable. Some DOE nonreactor nuclear operations have very limited or no engineered systems; safety control of these operations would be through worker protection programs and/or environmental protection programs rather than TSRs. An example of this kind of operation could be an environmental restoration project involving cleanup of radioactive contamination.

Section 14

The scope and content of TSRs have been limited to include only the most critical nuclear safety areas in order to make TSR documents more operationally useful for controlling facility safety. The TSR should be written in a clear, concise manner using language that iS directed at the facility-operating organization. 8. Regulatory Authority Note. Release of hazardous materials is regulated under the provisions of the Resource Conservation Recovery Act (RCRA) and the Comprehensive Environmental Response, Compensation, and Liability Act (CERCLA) as authorized by the Superfund Amendments and Reauthorization Act (SARA) . Worker exposure to hazardous materials and/or conditions is regulated under the provisions of the Occupational Safety and Health Act Administered by the occupational Safety and Health Administration (OSHA). Compliance with applicable Federal and State regulatory requirements is necessary in addition to compliance with TSR document limits. Attachment 1 Page 6 DOE 5480.22 2-25-92 I. INTRODUCTION This document iS intended to give guidance to DOE contractors on the preparation and implementation of TSRs for DOE reactor and nonreactor nuclear facilities, and to provide a basis upon which DOE can approve TSRs submitted by contractors. The contents of this document constitute an approach acceptable to DOE. Other approaches may be used, provided PSO approval is obtained, and the specific requirements of DOE 5480.22 are met. In the interest of uniformity, contractors are encouraged to follow the format presented in this document. Justification will be required before a TSR in a format different from that presented here is approved by DOE. Existing Technical Specifications/Operational Safety Requirements (TS/OSRs) must be revised to meet the content requirements in DOE 5480.22. The format of the TS/OSR is to be brought into conformance with the revised content and format presented in this document in accordance with the PSO's agreed upon schedule. Nonreactor nuclear facilities may develop a TSR document for an entire facility or the facility may be divided according to process, with a separate segment of the TSR generated for each process. In any case, every portion of the facility that contains radioactive or other hazardous material in sufficient quantities to adversely impact the health and safety of the public or pose a risk to workers must be covered by the TSR. Reactor facilities are expected to develop a single TSR document for the entire reactor facility. Every portion of the facility that contains radioactive or other hazardous material in sufficient quantities to adversely impact the health and safety of the public or pose a risk to workers must be covered by the TSR. DOE 5480.22 Attachment 1 2-25-92 Page 7 II. PREPARATION OF TECHNICAL SAFETY REQUIREMENTS This section presents material to assist in the preparation of TSR for DOE reactor and nonreactor nuclear facilities. It is divided into four parts: Organization, Content, Format, and Examples. The Organization part presents the basic organization required by this Order along with some details to assist in unifying the document. Content of the TSR is the second part, which discusses in detail what is expected to be in each of the sections of the TSR. The third part is a detailed presentation of TSR format from how to number pages to layout of the requirements themselves. Examples are embedded in the document to illustrate various parts of a TSR. 1. Organization

Section 15

1.1 Front Matter. Front matter should consist of at least the following items: a. b. c. d. e. Title page should include at least: name of the reactor or nonreactor nuclear facility, location, the words “Technical Safety Requirements,” and the contractor responsible. The Table of Contents should list every item in the volume (see Figure 2 for a reactor facility example and Figure for a nonreactor nuclear facility example). A List of Tables should be included (see Figure 4 for a reactor facility example and Figure 5 for a nonreactor nuclear facility example). A List of Figures should be included (see Figure 6 for a reactor facility example and Figure 7 for a nonreactor nuclear facility example). A List of Acronyms l, bbreviations, and Svmbols should be 3 compiled and included. 1.2 Arrangement of Sections. The arrangement of sections should be in accordance with the following: a. Section 1 - Use and Application b. Section 2 - Safety Limits c. Section 3/4 - Operational Limits and Surveillance Requirements Attachment 1 DOE 5480.22 Page 8 2-25-92 TABLE OF CONTENTS Paragraph Page Section 1 Use and Application 1.1 DEFINITIONS 1.2 OPERATIONAL MODES 1.3 FREQUENCY NOTATIONS 1.3.1 Frequency Codes 1.4 MODE APPLICAB1LITY SUMMARY 1.5 1.6 1.7 Section 2 2.1 2.2 2.3 Section 3/4 LIMITING CONDITIONS FOR OPERATIONS (LCO) ACTION REQUIREMENTS SURVEILLANCE REQUIREMENTS Safety Limits POWER LIMITS PRESSURE LIMITS TEMPERATURE LIMITS Operational Limits and Surveillance Requirements GENERAL APPLICATION REACTIVITY CONTROL SYSTEMS 3.0 3.1 3.1.1 Control Bank Insertion Limits 3.1.2 Core Reactivity 3.2 INSTRUMENTATION • Ž Figure 2 Example Table of Contents for a Nuclear Reactor Facility TSR DOE 5480.22 Attachment 1 2-25-92 Page 9 TABLE OF CONTENTS Paragraph Page Section 1 Use and Application 1.1 DEFINITIONS 1.2 OPERATIONAL MODES 1.3 FREQUENCY NOTATIONS 1.3.1 Frequency Codes 1.4 MODE APPLICABILITY SUMMARY 1.5 LIMITING CONDITIONS FOR OPERATIONS (LCO) 1.6 ACTION REQUIREMENTS 1.7 SURVEILLANCE REQUIREMENTS Section 2 Safety Limits 2.1 FISSILE MATERIAL Section 3/4 Operational Limits and Surveillance Requirements 3.0 GENERAL APPLICATION 3.1 CRITICALITY, RADIOACTIVITY, AND CHEMICAL ALARM SYSTEMS 3.1.1 Criticality Alarms 3.1.2 Area Monitors 3.1.3 Chemical Alarm Systems 3.2 VENTILATION SYSTEMS 3.2.1 HEPA Filters 3.2.2 Fire Screens • • • Figure 3 Example Table of Contents for a Nonreactor Nuclear Facility TSR Attachment 1 DOE 5480.22 Page 1O 2-25-92 LIST OF TABLES Table No. 2-1 2.2-1 Page 3.3-1 3.4-1 4.3-1 Title Reactor Core Safety Limits Decay Heat Removal Rate Versus Shutdown Time Control Rod Withdrawal Limits Versus Mode Maximum Power Level Versus Primary Pump Configuration Control Rod Surveillances Figure 4 Example List of Tables for a Nuclear Reactor Facility TSR Table No. 3-1 LIST OF TABLES Title Limiting Control Settings Page 3.3-1 Criticality, Radioactivity, and Chemical Alarm Sensors 3.4-1 4.3-1 Fire Detection Sensor Criticality Alarm Surveillances Figure 5 Example List of Tables for a Nonreactor Nuclear Facility TSR DOE 5480.22 Attachment 1 2-25-92 Page 11 Figure No. 3-1 3.3-1 3.4-1 LIST OF FIGURES Title Page Maximum Vessel Pressure Versus Metal Temperature Maximum Control Rod Withdrawal Versus Power Minimum Reactor Coolant Flow Versus Power Figure 6 Example List of Figures for a Nuclear Reactor Facility TSR Figure No. Page 3.371 3.4-1 LIST OF FIGURES Title

Section 16

Location of Criticality Alarm Sensors Location of Fire Detection Sensors Figure 7 Example List of Figures for a Nonreactor Nuclear Facility TSR Attachment 1 Page 12 DOE 5480.22 2-25-92 Note that Section 3 is Operational Limits, and Section 4 is Surveillance Requirements. Surveillance Requirements are established to demonstrate and assure that the Operational Limits are met. These two sections are thus intimately related. They are presented together in the text of the TSR document because of this relationship. Such presentation makes it easier to assure that Surveillance Requirements are appropriate for the related Operational Limits. d. Section 5 - Administrative Controls 1.3 Cover Page. Each section should have a cover page that has the section number and the title centered on the page. 1.4 Appendices. Appendices should be placed at the end of the document. They should be designated as Appendix A, Appendix B, etc., and should have a cover page with the letter designation and title. The appendix that contains the TSR bases should be Appendix A and the Design Features Appendix should be Appendix B. Other appendices should be designated alphabetically beginning with Appendix C. 2. Content. The content of each section of the TSR is described in the following paragraphs. 2.1 Section 1 - Use and Application This section should contain basic information and instructions for using and applying the TSR. The following elements should be addressed under separate headings in this section: a. Definition Provide a list of defined terms and corresponding definitions as used throughout the TSR. Arrange the defined terms in alphabetical order and in tabular form as shown in Figure 8. Include a note at the beginning of the list stating that defined terms appear in upper-case type throughout the TSR. b. Operational Modes (Reactors). In the interest of uniformity, the operational conditions or modes listed below are preferred and an attempt should be made to fit each reactor facility into this scheme. If, however, a reactor facility cannot be made to fit, modes may be defined as needed, provided the definition is clearly written with definite lines of demarcation between modes. The number of modes should be held to a minimum. The number of modes should be established based upon the DOE 5480.22 Attachment 1 2-25-92 Page 13 NOTE: Defined terms in this list-appear in upper-case type throughout these Technical Safety Requirements. Term Definition ACTION The steps listed in each requirement that are required to be performed when the specified LIMITING CONDITIONS FOR OPERATION are not met ACTUATION LOGIC TEST The application of various simulated input signal combinations in conjunction with each possible interlock logic state and verifying the required logic output. Shall include, as a minimum, a continuity check of output devices ANALOG CHANNEL Injection of a simulated signal OPERATIONAL TEST into... Figure 8 Example Listing of Definition Attachment 1 Page 14 DOE 5480.22 2-25-92 minimum number required to be able to distinguish between different facility conditions and to ensure the provision of an adequate level of safety while in each condition. (1) Define the Operational Modes as follows: (a) Operation Mode - To be in Operation Mode, the reactor shall be critical and may be at any power level up to and including maximum allowed power.

Section 17

(b) Standbv Mode - To be in Standby Mode, the reactor shall be subcritical but capable of operation without substantial administrative or mechanical actions. K effective limits or other limits needed to define the mode should be included. (c) Shutdown Mode - To be in Shutdown Mode, the reactor shall be significantly subcritical and capable of operation only after completing substantial administrative and/or mechanical actions. Normally, this would be a procedure or series of procedures (such as multiple system valve line-ups) that must be performed, but it could be mechanical or electrical repairs, calibration, or other activity. The K effective values should normally be included, unless they are of no use for a particular reactor, in which case conrol rod position(s) or other appropriate means should be defined for “significantly subcritical.” (d) Refueling Mode - To be in the Refueling mode, the reactor vessel integrity is breached (in all nonaccident conditions), or any core alterations including fuel rods, control rods, targets, or other vessel, internals are occurring or have occurred. Normally this mode requires major mechanical and associated administrative steps be completed before operation is possible. (e) Submodes may be created and defined as needed by reactor facilities. The definition should be clearly written with numerical or other definite demarcation between submodes. The number of submodes should be limited as much as possible to avoid complexity and potential confusion. (2) Normally the definition of the modes in a TSR document will be a summary of the definitions above Operational Modes (Nonreactor Nuclear Facilities). In DOE 5480.22 Attachment 1 2-25-92 Page 15 with whatever additional information is needed for a particular reactor, such as maximum allowed power, in the definition of Operation Mode. It should be noted that different mode definitions will be needed for facilities being decommissioned and while they are being dismantled. c. the interest of uniformity, the operational conditions and modes listed below are preferred and an attempt should be made to fit each nonreactor nuclear facility into this scheme. If, however, a nonreactor nuclear facility cannot be made to fit, modes may be defined as needed, provided they are clearly defined with definite lines of demarcation between modes (such as a numerical value of pressure, temperature, or flow). The number of modes should be held to a minimum because nonreactor nuclear facilities may encompass various operations that may be in differing modes rather than the whole facility being in a single mode. It should be noted that different mode definitions will be needed for facilities being decomissioned and while they are being dismantled. Define the Operational Modes as follows: (1) (2) (3) (4) (5) (6) Cold Standby - the facility is not operating with its Operation Mode - the mission of the facility or its current campaign is being performed. Shutdown Mode - the facility iS not performing its mission or its current campaign, and is incapable of doing so in its present condition. Warm Standby - the facility is not operating but still retains its inventory of hazardous material. hazardous material inventory removed. Repair Mode - the facility iS not able to perform its mission in its current condition.

Section 18

Submodes may be created and defined as needed by nonreactor nuclear facilities. The definition should be clearly written with numerical or other definite demarcation between submodes. The number of submodes should be limited as much as possible to avoid complexity and potential confusion. Attachment 1 Page 16 DOE 5480.22 2-25-92 d. Frequency Notation. The frequency notations, as used in the surveillances and elsewhere, should be defined as follows when included in the TSR: Notation S - Shiftly D - Daily W - Weekly M - Monthly Q - Quarterly A - Semi-annually C - Campaign R - Refueling S/U - Start-up N/A Minimum Frequency (Periodicity Notation) At least once per 12 hours. At least once per 24 hours. At least once per 7 days. At least once per 31 days. At least once per 92 days. At least once per 184 days. Prior to each campaign startup. Prior to entering Standby or Operation Modes after reactor refueling. Prior to each startup. Not applicable. e. Acronyms. Provide a list of the acronyms used in the TSR. f. Safety Limits. Describe here the purpose and scope of Safety Limits, i.e., process variable parameters indicative of barrier failure that could lead to uncontrolled release of radioactive materials. Application of Safety Limits should be described in terms of four basic rules: (1) Compliance with safety Limits is required in all modes. (2) Upon exceeding a Safety Limit, the following steps are to be taken: (a) The affected parameter must be immediately brought within the Safety Limit; (b) Reactors are required to be shutdown immediately. At nonreactor nuclear facilities, the TSR is to specify actions to be taken which must place the involved process in the most stable, safe condition attainable, including shutdown; and (c) All other ACTION requirements must be met. (3) A technical evaluation of the Safety Limit violation is required to determine if any damage may have DOE 5480.22 2-25-92 Attachment 1 Page 17 occurred and to evaluate the capacity of system(s)/component(s) to restart. (4) After violation of a Safety Limit, restart of the affected system(s)/component(s) is prohibited until approval from the cognizant Program Manager (PM) is received. Requirements (3) and (4) above may be included in Section 5 of the TSR “Administrative Controls,” provided reference to the requirement is in the appropriate Safety Limit. g. Limiting Control Setting. Describe here the purpose and function of Limiting Control Settings, i.e., process variable parameters for safety systems that function to prevent the exceedance of Safety Limits. Application of Limiting Control Settings should be described in terms of four basic rules: (1) Compliance with a Limiting Control Setting is required in the modes specified. (2) Upon discovery that the instrumentation or interlock setpoint is less conservative than the required Limiting Control Settings, the associated ACTION requirement must be met. (3) Failure to comply with the ACTION statement in the stated time interval is considered a TSR violation. (4) If an automatic safety system does not function as required, appropriate action should be taken to compensate. In the case of reactors, that action may take the form of reactor shutdown and/or engineered safeguards feature initiation or adjustment. In the case of nonreactor nuclear facilities, such action might be manual process shutdown or adjustment.

Section 19

h. Limiting Conditions for Operation Describe here the purpose and function of Limiting conditions for Operation, i.e., Limiting Conditions for Operation establish the lowest functional capability or performance levels-of equipment required for normal safe operation of the facility. Also, this part should contain the requirements for how Limiting Conditions for Operation should be applied. Application of Limiting Conditions for operation follows six basic rules: Attachment 1 Page 18 DOE 5480.22 2-25-92 (1) Compliance with a Limiting Condition for Operation is required in the modes specified. (2) Upon the failure to meet a Limiting Condition for Operation, the associated ACTION Requirement must be met. (3) Failure to meet the specified Limiting Condition for Operation and its ACTION Statements within the time interval is considered noncompliance with the requirement. Similarly, completing the ACTION Statement within the specified interval is considered noncompliance with the requirement. (4) Restoration of the Limiting Conditions for Operation prior to the expiration of the specified time interval(s) of the ACTION Statement removes the requirement to complete the ACTION Statement. (5) When a Limiting Condition for Operation is not met, unless provided for differently in the ACTION statement, within 1 hour action should be initiated to place the facility in a mode in which the requirement does not apply. (6) Entry into a different mode should not be made unless all of the Limiting Conditions for Operation are met for that mode, except for the passage through a mode as required to comply with ACTION Statements. For example, for reactors, criticality should not be achieved unless all Limiting Conditions for Operation are met for OPERATION Mode; however, passage through STANDBY Mode is allowed without all STANDBY Mode Limiting Conditions for Operation be met if going from OPERATION Mode to SHUTDOWN Mode under an ACTION Statement. The above rules should be discussed in detail, with specific examples if necessary, along with information that will help the user interpret and apply the requirements. i. Surveillance Requ irements. Describe the purpose of Surveillance Requirements, that is, Surveillance ¹It should be noted that at nonreactor nuclear facilities that contain an inventory of radioactive materials, the LCOs that are necessary to monitor for a breech of the barriers containing the material, are always applicable. The ACTION statement in this case should be rapid restoration of the capability, or compensatory measures. DOE 5480.22 Chg 1 9-15-92 Attachment 1 Page 19 Requirements are requirements relating to test, calibration, or inspection to assure that the necessary quality of systems and components is maintained, that facility operation will be within the Safety Limits, and that the Limiting Control Settings and the Limiting Conditions for Operation will be met. Application of surveillances follows four basic rules: (1) Surveillance Requirements must be met for all equipment/components/conditions to be considered operable. (2) (3) Each Surveillance Requirement shall be performed within the specified interval, with a maximum extension of 25 percent of the interval between any two consecutive surveillances. (This extension is intended to provide operational flexibility both for scheduling and for performing surveillances. It should not be relied upon as a routine extension of the specified interval).

Section 20

Failure to perform a surveillance within the required time interval or failure of a surveillance test shall result in the equipment/component/condition being declared inoperable and shall be considered a violation of the TSR and a failure to meet a Limiting Condition for Operation (LCO). When an equipment or a component fails the surveillance test, the action required by the TSR for failing to meet the LCO shall be taken. When a surveillance requirement is not performed within its required time frequency, in order to avoid subjecting the facility to unnecessary transients, e.g., scramming a reactor, additional time may be allowed to complete a surveillance before declaring a failed LCO and taking the required action. In this case, from the time of discovery, Up to 24 hours, or up to the time limit of the specified surveillance frequency, whichever is less, is allowed for performing a surveillance test. The need for this allowance and the time needed to perform the surveillance test shall be justified in the TSR Bases and be approved by the PSO. Vertical line denotes change. Attachment 1 Page 20 DOE 5480.22 2-25-92 (4) A different mode may not be entered unless all of the Surveillance Requirements for equipment/components/ conditions of that mode are current, except for the passage through an operational mode as required to comply with ACTION Statements. The above rules should be discussed as they apply to each facility, and examples should be given as needed to fully explain the surveillance system. 2.2 Section 2 - Safety Limits a. Safety Limits. Safety Limits should describe as precisely as possible the parameters being limited and state the limit in measurable units (pressure, temperature, flow, etc.). See Figure 9 for an example of a reactor Safety Limit. b. Applicabilitv. Each Safety Limit is to have a mode applicability statement. This statement shall consist of a simple list of modes or other conditions for which the Safety Limit is applicable. c. Actions. Action Statements are to completely describe the actions to be taken in the event that the Safety Limit is not met. These actions should first place the facility in a safe, stable condition or should verify that the facility already is safe and stable and will remain so. Secondly, the ACTION Statement should establish the steps and time limits to correct the out- of-specification condition. The actions should bring the affected parameter immediately within the Safety Limit and should effect a shutdown of the affected system(s) (or the reactor) within a justified facility-specific time frame, normally less than an hour. Other actions required after a Safety Limit violation, including reporting requirements and an evaluation of possible damage caused by the Safety Limit violation, may be included in the ACTION Statement or may be placed in Section 5, “Administrative Controls,” with proper reference to the Requirement. A statement prohibiting restart prior to PM approval of the system(s) shutdown following a Safety Limit violation must be included either in the ACTION Statement of each Safety Limit or in Section 5 of the TSR “Administrative Controls.” d. Selection of Safety Limits. Safety limits are those limits which, if exceeded, could directly cause the failure of one or more of the barriers that prevent the uncontrolled release of radioactive or other hazardous materials. Generally, containment/confinement should not DOE 5480.22 2-25-92 Attachment 1 Page 21

Section 21

be considered as barriers that require Safety Limits because they are mitigative in nature; however, these systems will be considered in the development of Limiting Conditions for Operation. For reactors, typically these 2.1 SAFETY LIMITS 2.1.1 REACTOR SL: The CORE SAFETY LIMIT reactor shall not be in OPERATION mode unless reactor coolant flow exceeds X gallons per minute APPLICABILITY: Operation Mode ACTIONS : 1. Go to SHUTDOWN mode immediately, 2. Notify the DOE EOC within one hour of reaching SHUTDOWN mode, and 3. Prohibit facility operation until authorized by DOE. Figure 9 Example of Safety Limit for a Nuclear Reactor Facility Attachment 1 Page 22 DOE 5480.22 2-25-92 barriers are considered to be the fuel cladding and primary coolant system, including piping and pressure vessels. Typical reactor limits of importance are primary coolant system pressure, primary coolant system temperature, and reactor power. For reactors without closed primary coolant systems (SUCh as pool-type reactors), or with primary coolant systems that operate at essentially atmospheric pressure, the only Safety Limits may be on maximum reactor power and water temperature. For nonreactor nuclear facilities, the barriers preventing the uncontrolled release of radioactive and other hazardous materials are considered to be the process material boundary (tank, pipe, glove box, etc.). Limits of importance for nonreactor nuclear facilities are facility specific, but often relate to pressure differential across barriers, combustible/flammable material limits, and process heat limits. A filter system that is the only barrier between a process and the environment may require a Safety Limit. The state of a system relative to being critical is often expressed in terms of the system’s neutron multiplication factor [Keff]. Other measures, such as fraction of a critical dimension or mass, can also be used at times. There are typically no methods available to provide continuous monitoring of the Keff of an operating system. Because the neutron multiplication factor cannot be measured directly, safety limits for nuclear criticality safety are not applicable. Rather than relying upon a numerical safety limit, the safety of an operation is assured through the application of the double contingency principle, which provides that no credible single failure can lead to a criticality accident. This methodology results in a wide variety of limits and controls such that the violation of any single limit or control would not result in a “point beyond which safety cannot be assured.” These limits or conditions are contained in Limiting Conditions for Operations or could be contained in the Nuclear Criticality Safety Program in the Administrative Control Section. Not all nuclear facilities will have Safety Limits; for example, Hazard Category 3 facilities may have no such limits. DOE 5480.22 2-25-92 Attachment 1 Page 23 2.3 Section 3/4 - Operational Limits and Surveillance Requirements³. This section should contain the Limiting Control Settings and the Limiting Conditions for Operations, as well as mode applicability information, Action Statements, and Surveillance Requirements, for each requirement.

Section 22

The initial conditions of the safety analyses upon which the authorization to operate is based are the least conservative limits of acceptable operation. These initial condition values must be adjusted for both instrument error and the expected instrument drift between surveillances, and an allowance should be made for calculational uncertainties prior to being used as limits in the TSR. The adjustment for instrument error accounts for the fact that the TSR limit is a measured value, while the SAR initial condition/assumption is an exact number. Instrumentation has inherent inaccuracy that must be accounted for. If an SAR initial condition is a maximum pressure of 100 psi, for example, this value must be adjusted to 97 psi for the maximum measured pressure if the instrumentation has an accuracy of ±3 percent. Likewise, adjustment must be made to the SAR initial condition or assumption value to account for any calculations/assumptions that may have been made in getting from the SAR initial condition/assumption to the measured parameter(s). For example, if the SAR assumes a certain flow of water through a reactor core, some adjustments or conservatism must be built into the measured coolant flow in circulation loops to account for the fact that not all of that flow may pass through the core. The most conservative value for each parameter contained in the safety analyses makes up the envelope within which the facility must operate in order to ensure that the SAR analyses bound safe operation. That is to say that, provided the facility is operated within these SAR initial condition limits (suitably adjusted for instrument error and uncertainties), the SAR results accurately demonstrate that the consequences of accidents/transients/ incidents are acceptable. a. Limiting Control Settings. LCSs should describe, as precisely as possible, the parameter being controlled and its limit, or the limiting setting of the device to control it. This information may be presented in tabular or graphic form, with whatever written information that is necessary placed in the body of the requirement. Figure 10 is an example of LCS. ³Section 3 delineates Operational Limits. Section 4 describes Surveillance Requirements. There is usually a one-to-one correlation between operational limits and the surveillances related to them. Each limit is typically presented at the same place as its related surveillance. For this reason, the combined TSR section is designated Section 3/4. Attachment 1 Page 24 DOE 5480.22 2-25-92 b. c. d. Limiting Conditions for Operation. The LCO statement should describe, as precisely as possible, the lowest functional capability or performance level of equipment required for continued safe operation of the facility. Each separate limiting condition should have an LCO with associated Mode Applicability, ACTION statement, and Surveillance Requirement. Applicabilitv. Mode Applicability Statements are to be included for each LCS and LCO. These shall consist of a simple listing of the modes or conditions for which the LCS or LCO is applicable. Actions. Action Statements are to completely describe the actions to be taken in the event that an LCS or LCO is not met.

Section 23

For LCS ACTION Statements, if the setting in question is less conservative than the required setpoint but still within the Allowable Value, no action is required, as the difference between the nominal setpoint and the Allowable Value of the setpoint is equal to the band allowed for calibration accuracy and instrument drift. If, however, the setting is nonconservative relative to the Allowable Value, the ACTION statement should require that the setpoint be adjusted to within limits in a set time or that the channel be declared inoperable. See Figure 10 for an example of an LCS. The Action Statement for LCOs should state the action required to address the condition not meeting the LCO. Normally this simply requires the adverse condition be corrected in a certain time frame and provides further action if this is impossible. For example, if an LCO requires two pumps to be operable at all times when in the OPERATION Mode, the Action Statement would likely state that if one pump is inoperable it must be made operable in X hours or the facility shall be placed in SHUTDOWN Mode within the following Y hours; if both pumps were inoperable, the Action Statement would likely require at lease one pump be operable in Z hours and the second pump operable in the following W hours or the facility shall be placed in SHUTDOWN Mode. Figure 11 is an example of an LCO Action Statement. DOE 5480.22 2-25-92 Attachment 1 Page 25 3.2 LIMITIN6 CONTROL SETTINGS 3.2.2 CALCINER BED FLUIDIZING AIR FLOW LCS : The Calciner Bed fluidizing air flow isolation trip setpoint shall be set to ˆ 125 scfm. APPLICABILITY: Operation Mode. ACTIONS: A. With an air flow setpoint less than 125 scfm but more than 117 scfm, adjust the setpoint to be ˆ 125 scfm within 8 hours or declare the channel inoperable. B. With an air flow setpoint \ 117 scfm, adjust the setpoint to be ˆ 125 scfm within one hour or declare the channel inoperable. C. With neither of the two Calciner Bed fluidizing air flow channels OPERABLE, return at least one channel to OPERABLE status within 8 hours or place the calcining operations in SHUTDOWN. Figure 10 Example of Limiting Control Settings Attachment 1 DOE 5480.22 Page 26 2-25-92 3/4.4 CONFINEMENT SYSTEMS 3.4.2 CONFINEMENT EXHAUST SYSTEMS LCO: A. Two CONFINEMENT EXHAUST SYSTEMS shall be OPERABLE with each system comprised of the following components: 1. 2. 3. B. One Applicability: ACTIONS: 1. One CONFINEMENT EXHAUST SYSTEM fan One in-line charcoal filter The following instrumentation: a. one confinement exhaust flow indicator, with alarm b. one beta-gamma radiation monitor, with alarm c. one gas temperature sensor down-stream of the filter CONFINEMENT EXHAUST SYSTEM shall be in operation. OPERATION MODE, and during FUEL MOVEMENT With one CONFINEMENT EXHAUST SYSTEM inoperable, restore the inoperable system to OPERABLE status within 72 hours OR be in STANDBY within the next 6 hours. (continued) Figure 11 Example of LCO Page 1 of 2 DOE 5480.22 2-25-92 Attachment 1 Page 27 3/4.4 CONFINEMENT SYSTEMS 3.4.2 CONFINEMENT EXHAUST SYSTEMS ACTIONS (continued) 2. With both CONFINEMENT EXHAUST SYSTEMS inoperable: a. Restore one of the systems to OPERABLE status within 1 hour OR be in at least STANDBY within the following 1 hour AND b. Restore the second system to OPERABLE status within 72 hours OR be in STANDBY in the following 6 hours c. Cease moving fuel until at least one system is OPERABLE SURVEILLANCE REQUIREMENTS

Section 24

4.4.2 Each CONFINEMENT EXHAUST SYSTEM shall be demonstrated OPERABLE a. at least shiftly: 1) the CONFINEMENT EXHAUST SYSTEM in OPERATION shall be verified to be taking a suction on the reactor building at a rate of 500 SCFM or more 2) the CONFINEMENT EXHAUST SYSTEM in STANDBY shall be verified to be aligned to take suction on the reactor building and with the fan control in “AUTO” position 3) all instrumentation required in LCO A.3. above is verified OPERABLE b. at least monthly each CONFINEMENT EXHAUST SYSTEM shall be operated for an hour or more with a flow of 500 SCFM or more c. at least annually the charcoal filter shall be tested to have an efficiency of at least 99% removal of methyl iodine. Figure 11 Example of LCO Page 2 of 2 The Action Statement for nuclear criticality safety LCO should normally be that the process or activities not in compliance with the LCO should be stopped immediately (if Attachment 1 Page 28 DOE 5480.22 2-25-92 this action would not result in a less stable condition) and the process, system, or area be restored to a safe condition in accordance with an approved recovery plan. Action Statements should be broken down whenever possible into separate statements describing a single deviated condition requiring operator action; this simplifies the explanation of the expected action and better ensures that it will be performed correctly. Completion times for each action should be stated in simple units of time. Use the term “inoperable” to describe the deviated condition to limit the length of the Action Statement. Use the term “OPERABLE” to describe the corrected condition or part of the system without deviation. While “inoperable” is presented in lower-case letters, “OPERABLE” is presented in upper-case letters. Keep wording in Action Statements as brief as possible. Be consistent in the use of verbs and tense. Use the same wording structure between requirements. Do not use articles unless necessary for clarity. When a mode change is required by an Action Statement, use the actual title of the modes (e.g., rather than numerical designation of modes) to prevent any possible misunderstanding or typographical error that could cause the operator to take inappropriate action. Action Statements should cover all possible combination of operable and inoperable components in the systems described. e. Surveillance Requirements. Surveillance Requirement statements consist of short descriptions of each requirement and its frequency of performance. A frequency of performance is mandatory. These statements should be as brief as possible but should identify those requirements needed to ensure compliance with the LCS or LCO. Begin each Surveillance. Requirement with a verb. Be consistent in use of terms and sentence structure between requirements. f. Selection of Limiting Control Settings (1) Limiting Control Settings (reactors) consist of the reactor trip system instrumentation setpoints. All reactor trip setpoints should be listed in this section, along with the “Allowable Value,” which is the limiting value of the LCS accounting for all instrumentation channel uncertainties. The Reactor Trip Setpoint limits specified here are the nominal values at which the reactor trips are set and shall be selected to provide sufficient allowances between the trip setpoint and the Safety Limit to ensure DOE 5480.22 2-25-92 Attachment 1 Page 29

Section 25

that the core and the reactor coolant system are prevented from exceeding their Safety Limits during normal operation and anticipated operational occurrences. (2) Limiting Control Settings of instruments that monitor process variables at nonreactor nuclear facilities are the settings that either initiate protective devices themselves or sound an alarm to alert facility personnel to take action in order to protect barriers that prevent the uncontrolled release of radioactive materials. Where a Limiting Control Setting is specified for a variable that is also subject to a Safety Limit, the setting shall be chosen so that protective action taken upon exceeding the setting, either automatic or manual, will correct the abnormal situation before a Safety Limit is exceeded. An example of a Limiting Control Setting might be the high differential pressure across a glove box. g. Selection of Limiting Conditions for Operation (for reactors). LCO should be written only for systems and equipment that meet one (or more) of the following descriptions: (1) Installed instrumentation that is used to detect and indicate in the control room or other control location an inadvertent criticality or a significant degradation of any of the physical barriers that prevent the uncontrolled release of radioactive or other hazardous materials that could threaten the health and safety of the public and pose a risk for workers. This section is intended to control those instruments installed to detect excessive reactor coolant system or other container leakage. Depending on design, this could, for example, include instrumentation to measure coolant systems pressure or level , make-up tank level, pool level, sump level, or even radiation level. Instrumentation used to detect degradation of or leakage from waste systems and storage tanks, such as pressure and level instrumentation and radiation or chemical monitors, should be included. (2) Structures, systems, and components that are relied upon in the Safety Analysis to function or actuate to mitigate accidents, or transients that either involve the assumed failure of, or present a challenge to, the integrity of a physical barrier that prevents the uncontrolled release of radioactive materials that could threaten the health and safety of the public and pose a risk for workers. This section is intended to include Attachment 1 Page 30 DOE 5480.22 2-25-92 only those structures, systems, and components that are part of the primary success path of a safety sequence analysis, and those support and actuation systems necessary for them to function successfully. The primary success path of a safety sequence analysis is the sequence of events assumed by the Safety Analyses which leads to the conclusion of a transient or accident with consequences that are acceptable. Hence, any structure, system, or component in that assumed sequence should be included in the LCOs. Each transient or accident analysis that challenges the integrity of a radioactive material barrier, or involves its assumed failure, should be studied to compile a list of involved components, systems, and structures. Radioactive material barriers are typically fuel cladding, the primary coolant system, the confinement or containment, tanks, piping, and ventilation systems.

Section 26

Included here should be the reactor trip systems, decay heat removal systems, ventilation systems, and containment or confinement systems, as well as emergency power sources. Other items that might be included, if they are assumed by the Safety Analyses to operate, are emergency diesel generators, poison injection systems, makeup systems, and radioactive waste systems. In all cases, support and actuation systems necessary for the above to function must be included, such as instrumentation and controls, power supplies (electric, compressed air), and cooling systems. The above are to serve only as examples; a list must be developed for each reactor facility. Care should be taken to include only structures, systems, and components that meet the qualifying definitions. Maintaining the LCOs at the minimum number necessary will emphasize the importance of the LCOs and better ensure the compliance with them. (3) Process variables that are initial conditions for those design basis accidents or transient analyses that involve the assumed failure of, or present a challenge to, the integrity of a radioactive material barrier. Identification of these variables should come from a search of each such transient and accident analysis. Every initial condition of a process variable mentioned in these analyses should be included in the TSRs. The LCO should be established at a level that will assure that the process variable is not less conservative during actual operation than was assumed in any of the safety analyses. DOE 5480.22 2-25-92 (4) (5) Attachment 1 Page 31 Included here, for example, would be reactor coolant flow, temperature, pressure, neutron flux, storage tank level, pressure, temperature, and content concentration. Experiments and experimental facilities that could provide a path for the uncontrolled release of radioactive materials, or that could affect criticality. This section is to include experimental facilities and experiments containing radioactive materials that could leak to threaten the public and workers. Likewise included here are the reactivity effects of experiments and experimental facilities. Any experiment or experimental facility that can adversely affect the critical state of the reactor by either adding reactivity or significantly altering distribution of power, should have an LCO stating the conditions and limits placed on the experiment or experimental facility and must be approved by DOE as a TSR revision before the experiment can be conducted. Systems and equipment that are used for handling fissile material outside of the reactor core. LCOs written to cover equipment that meets this description shall incorporate the double contingency principle. This principle requires that at least two unlikely, independent changes in process conditions would have to occur concurrently in order to make a criticality accident possible. Hence, inadvertent criticality protection shall be provided by either: (a) the control of two independent process parameters (the preferred approach, if practical); or (b) a system of multiple (at least two) controls on a single parameter. In all cases, no single failure shall result in the potential for a criticality accident. Mass/density limits, geometry spacing, the use of neutron poisons, measures necessary to prevent unplanned transport of materials to an unfavorable geometry, etc., are parameters/conditions that may be controlled to meet this requirement. The basis for selecting either approach shall be fully documented.

Section 27

h. Selection of Limiting Conditions for Operation (for nonreactor nuclear facilities) LCOs should be written only for systems and equipment which meet one (or more) of the following descriptions: (1) Installed instrumentation that is used to detect and indicate in the control room or other control location, an inadvertent criticality or a significant degradation of the physical barriers that prevent the uncontrolled release of radioactive materials. This is most Attachment 1 Page 32 (2) DOE 5480.22 2-25-92 applicable to the primary isolation barrier, which can be the process material boundary. The instrumentation indicated here would be that which is used to detect leakage from the tank, pipe, glove box, and so on that define the primary isolation. In addition to various types of radiation and chemical monitors, other instrumentation included here could be flow (gas or liquid), pressure, etc., depending on design. Structures, systems, and components that are relied upon in the Safety Analyses to function or actuate to prevent or mitigate accidents, or transients that either involve the assumed failure of, or present a challenge to, the integrity of a physical barrier that prevents the uncontrolled release of radioactive materials. This section is intended to include only those structures, systems, and components that are part of the primary success path of a safety sequence analysis and those support and actuation systems necessary for them to function successfully. The primary success path of a safety sequence analysis is the sequence of events assumed by the Safety Analyses, which leads to the conclusion of a transient or accident with consequences that are acceptable. Hence, any structure, system, or component in that assumed sequence should be included in the LCO. Each transient or accident analysis that challenges the integrity of a radioactive material barrier, or involves its assumed failure, should be studied to compile a list of involved components, systems, and structures. Radioactive material barriers are typically the process material barrier and the containment or confinement. Included here should be systems that automatically place the facility in a safe condition, such as instrumentation and controls that trip or S1OW processes and automatic isolation systems. Other items that might be included, if they are assumed by the Safety Analyses to operate, are emergency power sources (diesel generators, turbines, etc.), fire detection/suppression and possibly seismic detection instrumentation. Containment/confinement requirements would be in this section as LCOs. In all cases, support and actuation systems necessary for the above to function must be included, such as instrumentation and controls, power supplies (electric, compressed air), and cooling systems. The above are to serve only as examples; a list must be developed for each facility. DOE 5480.22 2-25-92 Attachment 1 Page 33 (3) Care should be taken to include only structures, systems, and components that meet the qualifying definitions. However, if operating experience or risk assessment indicates that additional structures, systems, or components should have LCOs, they may be included provided strong justification is documented. Maintaining the LCOs at the minimum number necessary will emphasize the importance of the LCOs and better ensure the compliance with them.

Section 28

Process variables that are initial conditions for those design basis accidents or transient analyses that involve the assumed failure of, or present a challenge to, the integrity of a radioactive material barrier. Identification of these variables should come from a search of each such transient and accident analysis. Every initial condition of a process variable mentioned in these analyses should be included in the TSRs. The LCO should be established at a level that will assure that the process variable is not less conservative during actual operation than was assumed in any of the safety analyses. (4) Experiments and experimental facilities that could provide a path for the uncontrolled release of radioactive or other hazardous materials or that could affect criticality. This section is to include experimental facilities and experiments containing radioactive materials that could leak to threaten the public and workers. (5) Systems and equipment that are used for handling fissile material. LCOs written to cover equipment that meets this description shall incorporate the double contingency principle. This principle requires that at least two unlikely, independent changes in process conditions would have to occur concurrently in order to make a criticality accident Hence, inadvertent criticality protectionpossible. . shall be provided by either: (a) the control of two independent process parameters (the preferred approach, if practical) or (b) a system of multiple (at least two) controls on a single parameter. In all cases, no single failure shall result in the potential for a criticality accident. Mass/density limits, geometry/spacing, the use of neutron poisons, measures necessary to prevent unplanned transport of materials to an unfavorable geometry, etc., are parameters/conditions that may be controlled to meet DOE 5480.22Attachment 1 Page 34 i. j. k. 2-25-92 this requirement. The basis for selecting either approach shall be fully documented. Application of LCO. General rules of application of LCOs, as discussed in section II.2.1.h, should be written as the first division of Section 3 (3.0.1, 3.0.2,...). An example of an application LCO is given in Figure 12 (nuclear reactors) and Figure 13 (nonreactor nuclear facilities). Application of Surveillance Requirements. General rules of application of Surveillance Requirements, as discussed in section II.2.1.i, should be written as the first division of Section 4 (4.0.1, 4.0.2, . ..). An example of such surveillance rules is given in Figure 14. Special Test Exceptions. Special test exceptions may be allowed under controlled conditions. These test exceptions should be placed in Section 3 (LCO). Any test exceptions should be clearly written to state which LCOs are being excepted, for how long, and under what conditions. 2.4 Section 5 - Administrative Controls. This section should impose administrative requirements necessary to control operation of the facility such that it meets the TSR. The sections that follow discuss some of the administrative controls that should be placed in this section. The list here DOE 5480.22 Attachment 1 2-25-92 Page 35 3/4 OPERATING LIMITS AND SURVEILLANCE REQUIREMENTS 3/4.0 GENERAL APPLICATION OPERATING LIMITS 3.0.1 LIMITING CONTROL SETTINGS 3.0.1.1 Compliance with the LIMITING CONTROL SETTINGS requirements is required during the OPERATIONAL MODES or other conditions specified therein.

Section 29

3.0.1.2 Noncompliance with a requirement (TSR violation) shall exist when the LIMITING CONTROL SETTING and associated ACTION statement are not met within the specified time interval. 3.0.2 LIMITING CONDITIONS FOR OPERATION 3.0.2.1 Compliance with the LIMITING CONDITIONS FOR OPERATION contained in the succeeding requirements are demanded during the OPERATIONAL MODES or other conditions specified therein; except that upon failure to meet the LIMITING CONDITIONS FOR OPERATION, the associated ACTION Statement shall be met. 3.0.2.2 Noncompliance with a requirement (TSR violation) shall exist when the demands of the LIMITING CONDITION FOR OPERATION and associated ACTION Statement are not met within the specified time intervals. If the LIMITING CONDITION FOR OPERATION is restored prior to expiration of the specified time intervals, completion of the ACTION Statement is not required. (continued) Figure 12 Example of General Application of Operating Limits for a Nuclear Reactor TSR Page 1 of 2 Attachment 1 Page 36 DOE 5480. 22 2-25-92 3/4 OPERATING LIMITS AND SURVEILLANCE REQUIREMENTS 3/4.0 GENERAL APPLICATION OPERATING LIMITS 3.0.2.3 When a LIMITING CONDITION FOR OPERATION is not met, except as provided in the associated ACTION Statement, within 1 hour action shall be initiated to place the unit in a MODE in which the requirement does not apply. Where corrective measures are completed that permit operation under the ACTION Statement, the action may be taken in accordance with the specified time limits as measured from the time of failure to meet the LIMITING CONDITION FOR OPERATION. Exceptions are stated in the individual requirements. This requirement is not applicable in SHUTDOWN or REFUELING MODES. 3.0.2.4 Entry into an OPERATIONAL MODE or other specified condition shall not be made unless the conditions for the LIMITING CONDITION FOR OPERATION are met without reliance on provisions contained in the ACTION Statement. This provision shall not prevent passage through or to OPERATIONAL MODES as required to comply with ACTION Statement. Exceptions are stated in the individual requirements. Figure 12 Example of 6eneral Application of Operating Limits for a Nuclear Reactor TSR Page 2 of 2 DOE 5480.22 Attachment 1 2-25-92 Page 37 3/4 OPERATING LIMITS AND SURVEILLANCE REQUIREMENTS 3/4.0 GENERAL APPLICATION OPERATING LIMITS 3.0.1 LIMITING CONTROL SETTINGS 3.0.1.1 Compliance with the LIMITING CONTROL SETTINGS requirements is required during the OPERATIONAL MODES or other conditions specified therein. 3.0.1.2 Noncompliance with the requirement (TSR violation) shall exist when the LIMITING CONTROL SETTINGS and associated ACTION Statement are not met within the specified time interval. 3.0.2 LIMITING CONDITIONS FOR OPERATION 3.0.2.1 Compliance with the LIMITING CONDITIONS FOR OPERATION contained in the succeeding requirements is demanded during the OPERATIONAL MODES or other conditions specified therein; except that upon failure to meet the LIMITING CONDITIONS FOR OPERATION, the associated ACTION Statement shall be met. 3.0.2.2 Noncompliance with a requirement (TSR violation) shall exist when the demands of the LIMITING CONDITION FOR OPERATION and associated ACTION Statements are not met within the specified time intervals. If the LIMITING CONDITION FOR OPERATION is restored prior to expiration of the specified time intervals, completion of the ACTION Statement is not required. (continued)

Section 30

Figure 13 Example of General Application of operating Limits for a Nonreactor Nuclear Facility TSR Page 1 of 2 Attachment 1 Page 38 DOE 5480.22 2-25-92 3/4 OPERATING LIMITS AND SURVEILIANCE REQUIREMENTS 3/4.0 GENERAL APPLICATION OPERATING LIMITS 3.0.2.3 When a except within LIMITING CONDITION FOR OPERATION is not met, as provided in the associated ACTION Statement, 1 hour action shall be initiated to place the unit in a MODE in which the requirement does not-apply by placing it in SHUTDOWN within the next 12 hours. Where corrective measures are completed that permit operation under the ACTION Statement, the action may be taken in accordance with the specified time limits as measured from the time of failure to meet the LIMITING CONDITION FOR OPERATION. Exceptions are stated in the individual requirements. This specification is not applicable in SHUTDOUN or REPAIR MODES. 3.0.2.4 Entry into an OPERATIONAL MODE or other specified condition shall not be made unless the conditions for the LIMITING CONDITION FOR OPERATION are met without reliance on provisions contained in the ACTION Statement. This provision shall not prevent passage through or to OPERATIONAL MODES as required to comply with ACTION Statement. Exceptions are stated in the individual requirements. Figure 13 Example of 6eneral Application of operating Limits for a Nonreactor Nuclear Facility TSR Page 2 of 2 DOE 5480.22 2-25-92 Attachment 1 Page 39 3/4 OPERATING LIMITS AND SURVEILLANCE REOUIREMENTS 3/4.0 GENERAL APPLICATION SURVEILLANCE REQUIREMENTS 4.0.1 4.0.2 4.0.3 4.0.4 SURVEILLANCE REQUIREMENTS shall be met during the Operational Modes or other conditions specified for individual LCS and LCOs unless otherwise stated in an individual SURVEILLANCE REQUIREMENT. Each SURVEILLANCE REQUIREMENT shall be performed within 1.25 of the specified time interval. Failure to perform a SURVEILLANCE REQUIREMENT within the specified time interval (TSR violation) shall constitute a failure to meet the OPERABILITY requirements for a LIMITING CONDITION FOR OPERATION. Exceptions are stated in the individual requirements. Surveillances do not have to be performed on inoperable equipment. Entry into an Operational Mode or other specified condition shall-not be made unless the SURVEILLANCE REQUIREMENT(S) associated with the LIMITING CONDITION FOR OPERATION has been performed within the stated surveillance interval or as other otherwise specified. Figure 14 Example of 6eneral Application for SURVEILLANCE REQUIREMENTS Attachment 1 Page 40 DOE 5480.22 2-25-92 is not complete; additions should be made by each facility. a. Contractor Resoonsibilitv (1) The Facility Supervisor shall be responsible for overall unit operation and shall delegate in writing the succession to this responsibility during his absence. (2) The Shift Foreman shall be responsible for the local command function. A management directive to this effect, signed by the [highest level of corporate management] shall be reissued to all station personnel on an annual basis. During any absence of the Shift Foreman from the area, a designated, qualified individual shall assume the command function.

Section 31

b. Contracto r Organizat ion. Onsite and offsite organizations shall be described for facility operation and contractor management. The onsite and offsite organizations shall be described in terms of the lines of authority, responsibility, and communication for the highest management levels through intermediate levels to and including all operating organization positions. The individuals who train the operating staff and those who carry out health physics and quality assurance functions may report to the appropriate onsite manager; however, they shall have sufficient organizational freedom to ensure their independence from operating pressures. c. Procedures. Procedures should be required to be established, implemented, and maintained for all activities in support of the TSR. This should include: emergency operating procedures; operating procedures for all phases of operation, procedures for all surveillances required by TSR; Security Plan implementation; Emergency Plan implementation; fire protection; procedures for all programs listed in paragraph d below; and procedures governing the administrative aspects of operation of the facility. A system should be developed to control all procedures used in support of the TSR. The system should include the mechanism of review, approval, revision, control, and temporary-changes. d. Programs. Programs developed to ensure the safe and healthful operation of the facility should be discussed here and thereby required by reference. These programs might include but not be limited to the following: in- service inspection of components, pumps, and valves as DOE 5480.22 2-25-92 Attachment 1 Page 41 per ASME Boiler and pressure Vessel Code Section XI; worker protection such as Radiation Protection Programs, Inplant Radiation, and Toxic Substance Monitoring; industrial hygiene and occupational safety; Process Control Programs; Ventilation Filter Testing Program; Explosive Gas and Storage Tank Radioactivity Monitoring Programs; radiological effluent control; environmental measurement and control programs; quality programs; configuration control programs; and document control. The individual program documents should be referenced or the basic elements of these programs should be described in this section but are to be separate controlled volumes not included in the TSR. The detailed Nuclear Criticality Safety Program may be presented in this subsection of the TSR. e. Minimum Operations Shift Complement should be as follows. This Section of the Administrative Controls should include the maximum working hours and maximum number of consecutive days on duty. (1) For Categorv A Reactors. (a) A certified reactor operator or senior reactor operator should be required to be at the controls in the control room at all times when the reactor is fueled, except if the reactor is shut down and secured with a physical constraint (a lock, for example) such that no reactivity changes are possible; (b) In addition, a certified senior reactor operator should be required to be in the control room at all times when the reactor is operating or in an operational mode other than shut down or refueling; (c) A certified senior reactor operator or senior reactor operator limited to fuel handling should be required to be present at the facility to directly supervise any alteration of the core including fuel loading or transfer. This person should be required to have no other concurrent duties; and

Section 32

(d) Required staffing of operating shifts should be specified on the basis of relevant safety analyses. This is to include health physics, fire protection, and other on-shift or on-demand support staff. Attachment 1 Page 42 DOE 5480.22 2-25-92 Note that for Category A reactors, USNRC Regulatory Guide 1-114, Rev. 2, “Guidance to the Operators at the Controls and Senior Operators in the Control Room of a Nuclear Power Unit” should be used to define acceptable control room boundaries for the senior reactor operator and reactor operator to be considered “in the control room” and “at the controls” respectively. (2) For Cateqorv B Reactors. (a) A certified reactor operator or senior reactor operator should be required to be at the controls at all times during the operation of the reactor. (b) A certified senior reactor operator should be required to be present at the reactor facility or readily available or on call at all times during operation and to be present in the control room during startup and approach to power, during recovery from an unplanned or unscheduled shutdown, or during significant reduction in power. A certified senior reactor operator should be required to be present in the facility during refueling; and (c) Required staffing of operating shifts should be specified on the basis of relevant safety analyses. This is to include health physics, fire protection, and other on-shift or on-demand support staff. (3) For Nonreactor Nuclear Facilities The required staffing of operating shifts for nonreactor nuclear facilities and the members of the shift staff required to be present in the control room or control area for different operating conditions should be specified on the basis of relevant safety analyses. f. Operating Support. Included should be the requirement to maintain a current list in the control room or other control location of facility support personnel by name, title, and work and home telephone number. The list should include management, radiation safety, and technical support personnel. This section of the Administrative Controls should delineate the shift staffing including operations and others as needed (health physics, fire protection, individuals monitoring industrial hygiene parameters, etc.). DOE 5480.22 2-25-92 Attachment 1 Page 43 g. Facilitv Staff Qualifications and Training. Minimum qualifications for members of the unit staff shall be specified by use of an overall qualification statement referencing an American National Standard Institute (ANSI) standard; alternately, by specifying individual position qualification. Generally, the first method is preferable; however, the second method is adaptable to those unit staffs requiring special qualification statements because of a unique organizational structure. A retraining and replacement training program for the unit staff shall be maintained under the direction of the [position title] and shall meet or exceed the requirements and recommendations of Section [ ] of [an ANSI standard], and, for appropriate designated positions, shall include familiarization with relevant industry operational experience. h. OPERABILITY Definition and Implementation Principles. The definition of OPERABLE-OPERABILITY is to be included in the TSR as follows:

Section 33

“A system, subsystem, train, component, or device shall be OPERABLE or have OPERABILITY when it is capable of performing its specified function, and when all necessary attendant instrumentation, controls, electrical power, cooling or seal water, lubrication, or other auxiliary equipment that are required for the system, subsystem, train, component, or device to perform its function(s) are also capable of performing their related support function(s).” General Principles of OPERABILITY are to be included as follows: GENERAL PRINCIPLE 1: A system is considered OPERABLE as long as there exists assurance that it is capable of performing its specified safety function(s). GENERAL PRINCIPLE 2: A system can perform its specified safety function(s) only when all of its necessary support systems are capable of performing their related support functions. GENERAL PRINCIPLE 3: Assuring the capability to perform a safety function is an ongoing and continuous process: GENERAL PRINCIPLE 4: When all systems designed to perform a certain safety function are not capable of performing that safety function, a loss of function Attachment 1 Page 44 DOE 5480.22 2-25-92 condition exists. Facility operation with such a condition may not continue. GENERAL PRINCIPLE 5: When a system is determined to be incapable of performing its intended safety function(s), the declaration of inoperability shall be immediate. GENERAL PRINCIPLE 6: Any exception to an immediate determination-of inoperability must be justified. i. Technical Safety Requ i rement Basis Control. Contractor may make changes to the TSR Bases without prior DOE approval provided the changes do not involve any of the following: (1) A change in the TSR; (2) A change to the SAR that involves an Unreviewed Safety Question as defined in DOE 5480-.21; (3) A change to the way that OPERABILITY or the TSR could be met, applied, or interpreted. Proposed changes that meet the criteria of (a), (b), or (c) above shall be reviewed and approved by the DOE prior to implementation. Changes to the Basis that may be implemented without prior DOE approval will be provided to the DOE at least annually. j. Reviews and Audits . Describe the method(s) established to conduct independent reviews and audits. The methods may take a range of forms acceptable to the DOE. These may include creating an organizational unit, a standing or ad hoc committee, or assigning individuals capable of conducting these reviews and audits. When an individual performs a review function, a cross-disciplinary review determination is necessary. If deemed necessary, such reviews shall be performed by the review personnel of the appropriate discipline. Individual reviewers shall not review their own work or work for which they have direct responsibility. Regardless of the method used, management shall specify the functions, organizational arrangement, responsibilities, appropriate ANSI/ANS 3.1- 1981 qualifications, and reporting requirements of each functional element or unit that contributes to these processes. Reviews and audits of activities affecting facility safety have two distinct elements. The first of these is the review performed by facility personnel to ensure that day-to-day activities are conducted in a safe manner. DOE 5480.22 Attachment 1 2-25-92 Page 45

Section 34

The second of these is the review and audit of facility activities and programs affecting nuclear safety that are performed independent of the facility staff. The independent review and audit should provide for the integration of the reviews and audits into a cohesive program to provide senior level facility management with an assessment of facility operation and recommend actions to improve nuclear safety and facility reliability. It should include an assessment of the effectiveness of reviews conducted by facility staff. Facility staff reviews should include: USQ determinations; proposed tests and experiments; procedures; programs; facility changes and modifications; TSR changes; facility operation, maintenance, and testing; DOE and industry issues of safety significance; and any other safety-related items. Reviews by the offsite safety organization should include: USQ determinations; proposed changes to the TSR; violations of codes, Orders, and procedures that have safety and health significance; Occurrence Reports; staff performance; unanticipated deficiencies of structures, systems, or components that could affect nuclear safety; significant, unplanned radiological or toxic material releases; and significant operating abnormalities. Audits by the offsite safety organization should include conformance with TSR; training and qualification of facility staff; program implementation; deficiency corrective actions; quality program adherence; and other activities of safety significance. k. Reporting Requirements. Reporting requirements are to be in accordance with DOE 5000.3A. 2.5 Bases Appendix. This Appendix shall provide brief summary statements of the reasons for the SLs, OLs, and associated Srs. The bases shall show how the numeric values, the conditions, the surveillances, and the Action Statements fulfill the purpose derived from the safety documentation. The primary purpose for describing the basis of each requirement is to ensure that any future changes to the requirement will not affect its original intent or purpose. The Bases Appendix shall reference the more specific detailed basis for the TSRs in the SAR. 2.6 Design Features Appendix. Until a facility has a DOE-approved SAR, a Design Features Appendix should be included with the TSR. After DOE approves a facility SAR, the Design Features Attachment 1 DOE 5480.22 Page 46 2-25-92 Appendix may be eliminated, provided that assurance is made that the provisions of the Design Features Appendix are present in the approved SAR or elsewhere in the TSR. The purpose of the Design Features Appendix is to describe in detail those features not covered elsewhere in the TSRs that, if altered or modified, would have a significant effect on safety. Three areas need to be addressed: vital passive components, configuration and physical arrangement, and materials. a. Vital passive components are essentially piping, vessels, supports, structures (such as confinement), and containers. This discussion should present a detailed description of each vital passive component, including functions, dimensions, design criteria, applicable codes and standards, materials used, in-service inspection required, manufacturer, and all details that must be considered prior to alteration, modification, or replacement.

Section 35

b. The Design Features Appendix should also address configuration and physical arrangement where it is a safety concern. Details should be given of the configuration or physical arrangement including dimensions, the parameter(s) being controlled, and the reasoning behind the design. Examples of such a situation would be where criticality avoidance is dependent on physical separation and where configuration is used to minimize radiation levels. c. If safe operation of the facility is dependent on any component being constructed of a particular material, that requirement should be discussed in the Design Features Appendix. The component and system should be identified as well as the special material involved, any in-service inspections required of the material or component, and any special operational considerations such as maximum/minimum temperature, pressure, flow, or chemical concentration. Material considerations may be a separate section of the Design Features Appendix or may be integrated into other portions of the Design Features Appendix. d. Site Characteristics such as the locations of public access roads, collocated facilities, facility area boundaries, site boundaries, nearest residence distances, etc., should be presented in this appendix. 3. Format DOE 5480.22 Attachment 1 2-25-92 Page 47 3.1 Numbering of Pages/Sections/Tables/Figures a. Page Numbering. All page numbers should be centered at the bottom of the page. The following paragraphs describe the numbering schemes for individual sections. (1) Front Matter Pages. Number the front matter pages with successive lower-case Roman numerals i, ii, iii, etc. (2) Section Page Numbering (Except Sections 2 and 3/4). All section page numbers, except for Sections 2 and 3/4, should have two parts: an Arabic section number followed by a dash, and an Arabic number designating the numerical page number within the section (see example below). Ex ample Page Numbering for Sections l and 5 1-1, 1-2, 1-3, . . . . 5-1, 5-2, 5-3, . . . . (3) Sections 2 and 3/4 Page Numbering. Sections 2 and 3/4 are subdivided into numerous subsections corresponding to the individual requirement numbers. The first part of each page number for Sections 2 or 3/4 should, therefore, correspond to the subsection number followed by a dash and an Arabic number designating the numerical page number within the subsection (see examples below). xample Page Numbering for Sect ions 2 and 3/4 2 l-l, 2 1-2, 2 1-3, . . . . 3/4 1-1, 3/4 1-2, 3/4 1-3, . . . . 3/4 2-1, 3/4 2-2, 3/4 2-3, . . . . (4) Numbering of Appendix Pages. Number all pages of appendices, except for the 8asis Appendix, with an alpha-numeric number separated by a dash. The first part should be a capital letter corresponding to the appendix letter (appendices are designated alphabetically). The second part should denote the numeric sequence of pages within the appendix (Examples: A-1, A-2, . . . . B-1, B-2 . ..).. (5) Basis Appendix Page Numbering. All page numbers for the Bases Appendix should begin with the word “Basesn followed by the subsection number that it supports (see examples below). Attachment 1 Page 48 DOE 5480.22 2-25-92 Bases 2 l-l, Bases 2 1-2, . . . . Bases 3/4 O-1, Bases 3/4 O-2 . . . . Bases 3/4 1-1, Bases 3/4 1-2 . . . . b. Paragraph Numbering for Sections 1 and 5. Paragraphs should be numbered with successive Arabic numbers - separated by decimal points. The following scheme should be used for subordination of paragraphs:

Section 36

Example Paragraph Numbering 1.1 (Major Paragraph) 1.1.1 (First Subordinate Paragraph) 1.1.1.1 (First Subdivision of First Subordinate Paragraph) 1.2 (Second Major Paragraph) c. Numbering of Safety Limits (Section 2), Limiting Control Settings, and Limiting Conditions for Operation (Section 3) (1) (2) (3) (4) (5) All SLs, LCSs, and LCOs should begin with 2. or 3., then the number associated with the group, which will be followed by the number of the requirement. Complex systems may require further subdivision. Example: 2.11 Reactor Coolant Circulation System 3.10.2.1 Diesel Generator Fuel Oil Tank Number Safety Limits beginning with 2.1 and continuing with 2.2, 2.3, . . . . Any subdivision of Safety Limits should be numbered with an additional number added to the number of the SL; for example, 2.1.1, 2.1.2, . . . . Number Operating Limits beginning with 3.1 and continuing with 3.2, 3.3, . . . . Any subdivisions of OLs should be numbered with an additional number added to the number of the LCS, for example, 3.2.2, 3.2.3, . . . . Operating Limits should be grouped by principal system or function and each OL within a group should be numbered sequentially. Limiting Control Settings are normally the first requirements within a group. For reactors, normally all OLs can be put into the following groups: DOE 5480.22 2-25-92 Attachment 1 Page 49 (6) 0. 1. 2. 3. 4. 5. 6. 7. 8. 9. Application Reactivity Control Core Power Distribution Instrumentation Coolant System Engineered Safety Systems Confinement/Containment Plant Systems” Electrical Systems Experiment Facilities 10. Radwaste Systems 11. Special Tests 12. Refueling Requirements 13. Spent Fuel Pool Requirements For less complex reactor facilities, omit groups above (except “O”) as appropriate and retain the same numbering scheme to indicate that a group was omitted. Add other groups as necessary. For nonreactor nuclear facilities, standardized grouping of requirements is more difficult because of the diversity of facilities, however, many facilities will have the following: 0. Applicability 1. Criticality, Radioactivity, and Hazardous Material Alarm Systems 2. Confinement/Ventilation 3. Fire Detection and Suppression 4. Emergency Power 5. Chemical Systems DOE 5480.22Attachment 1 Page 50 2-25-92 6. Instrumentation 7. Experimental Facilities (7) ACTION Statements should be lettered with upper case letters. Subdivisions of ACTION Statements should be numbered, 1., 2., . . . . (8) See Figure 11 for sample numbering of LCO and ACTION Statements. d. Numbering of Surveillance Requ irements (Section 4) (1) Surveillance Requirements should be designated with numbers beginning with 4. (2) The second number should correspond to the same grouping scheme utilized for the LCS or the LCO, and the third number in the sequence indicates the LCS or the LCO which this surveillance principally supports. Hence, the Surveillance Requirements will have numbers the same as the LCS or the LCO which they support except for the first number which will be a “4” instead of a “3.” (3) Subdivisions should be identified with a lowercase letter and indented; further subdivisions should be numbered with a number and “close parenthesis" (eg., 1), 2), . ..) and should be indented from the letter (see Figure 11 for an example). e. Numbering of Bases (Bases Appendix). Bases are numbered in accordance with the number of the SL, LCS, or LCO which they support.

Section 37

f. Table Numberi nq (1) Table numbers the number of followed by a numbers. See samples. in Sections 2 and 3/4 should begin with the specification to which they apply, dash, and then sequential Arabic the example below and Figure 15 for Example Table Numbers for Section 3/4 Table 3.3.l - 1. Title (Sheet 1 of 6) Table 4.2.5 - 1. Title (2) Numbers of tables in the Basis appendix should begin with the words “Bases Table” and the subsection DOE 5480.22 2-25-92 Attachment 1 Page 51 number that it supports, followed by a dash and then sequential Arabic numbers. Ex ample Table Numbers for Basis Appendix Bases Table 3/4.1-1 Bases Table 3/4.2-1 (3) Table numbers in all other sections should begin with the applicable section number followed by a dash and then sequential Arabic numbers. Example Table Numbers for Sections Other Than Bases and Sections and 3/4 Table 5-1. Table 5-2. Attachment 1 DOE 5480.22 Page 52 2-25-92 3/4.5 INSTRUMENTATION 3.5.1 REACTOR TRIP SYSTEM INSTRUMENTATION LCO: As a minimum, the Reactor Trip System Instrumentation channels of Table 3.5-1 shall be OPERABLE. APPLICABILITY: AS shown in Table 3.5-1. ACTIONS: As shown in Table 3.5-1. SURVEILLANCE REQUIREMENTS 4.5.1 Each Reactor Trip System instrumentation channel and automatic trip logic shall be demonstrated OPERABLE by the performance of the Reactor Trip System Instrumentation Surveillance Requirements specified in Table 4.5-1. (continued) Figure 15 Example of LCO Page 1 of 4 Attachment 1 Page 56 DOE 5480.22 2-25-92 (4) For multiple-page tables in all sections, use the phrase “(Sheet 1 of , Sheet 2 of etc.)” after the table title (see example for f (1) above). (5) All tables should be located as near as possible after the place where they are first referenced. Where tables and figures are both referenced in a specification, present the tables before the figures. g. Figure Numbering (1) Figure numbers in Sections 2 and 3/4 should begin with the number of the requirement to which they apply, followed by a dash, then sequential Arabic numbers. Example Figure Numbers for Section 3/4 Figure 2.1.1-1 Title Figure 3/4.2.1-1. Title (Sheet 1 of 6) Figure 3/4.2.5-1. Title (2) Figure numbers in the Basis appendix should begin with the words “Bases Figure” and the subsection number that it supports, followed by a dash and then sequential Arabic numbers. Example Figure Numbers for Bases Appendix Bases Figure 2.1-1 Bases Figure 3/4.2-1 (3) Figure numbers in. al 1 other sections should begin with the applicable section number followed by a dash and then sequential Arabic numbers. Example Figure Numbers for Sections Other Than Sections 2 and 3/4 and Appendix Figure 5-1. Figure 5-2. (4) For multiple-page figures in all sections, use the phrase “(Sheet 1 of , Sheet 2 of _, etc. )” after the figure title. DOE 5480.22 2-25-92 3.2 Attachment 1 Page 57 (5) All figures should be located as near as possible after the place where they are first referenced. Page Headings. Use upper case letters in the page headings for consistency and to set the heading apart from the body of the requirement. The heading information is provided as a convenience for the user in locating requirements and should not be emphasized by bold face type. Separate the heading information from the body of the requirement by a solid horizontal line across the entire page (see Figures 9 and 11).

Section 38

Continuation Between Pages. Use the word “continued” in parentheses and in lower case letters to denote continuation of a grouping of action statements, surveillances, or Basis to the next page (see Figure 11 and Example 3 below). Example Page Headings Example 1: 3/4.4 REACTOR COOLANT SYSTEM 3.4.2 PRESSURE PROTECTION SETPOINTS Example 2: 3/4.6 CONFINEMENT SYSTEMS 3.6.2 AIR CLEANING SYSTEM Example 3: 3/4.6 CON INEMENF T SYSTEMS 4.6.1 SURVEILLANCE REQUIREMENTS (continued) 3.3 Highlighting. Various forms of highlighting are used in the example shown in Figure 15 to improve visibility of the information presented. These include: a. Bolding. Bold type is used to highlight the major headings, table column headings, and to emphasize especially important information. Notes are also in bold type for added emphasis. Attachment 1 Page 58 DOE 5480.22 2-25-92 b. Spatial Dedication. The SL, LCS, and LCO are offset or indented so that this information stands out from the surrounding text. Recognition and separation of the SL, LCS, and LCO requirements allows this information to be more quickly and easily located and scanned without interference from the surrounding text. Also, the SL, LCS, and LCO mode applicability headings are separated by extra “white space,” allowing for quick recognition and scanning of specific information. c. Delimiters. Delimiters function as visual cues for the user, signaling the beginning and/or end of specific segments of information. Delimiters should take the form of two closely spaced horizontal lines. Separation of two independent requirements on the same page would call for the use of delimiters, for example. d. Underscoring. Underscoring is an effective way of adding emphasis to specific information when properly used. However, it tends to lose its effectiveness when used too much. For this reason, underscoring is used in the example only to add emphasis to logical connectors (AND, OR, BUT, etc.). 3.4 Use of Log ic Terms. Logic terms (AND, OR, IF, BUT, etc.) should be used as little as possible. In preparing TSR, try to avoid logic terms. When they must be used, the following guidelines apply: All logic terms should be underscored, in uppercase bold type, and flush left between the two (or more) sets of connected conditions, and: a. b. c. AND is used to connect two or more sets of criteria that must both (all) be satisfied for a given logical decision. If more than two sets of conditions are required, a list format is preferable. OR should be used to denote alternative combinations or conditions, meaning either one, or the other. Because it is easily misinterpreted, the use of OR should be avoided whenever possible. When action steps are continent upon certain conditions, terms such as IF, BUT, IF NOT, etc., may be used as appropriate, however, use of such terms should be kept to a minimum. Where possible, DOE 5480.22 2-25-92 3.5 3.6 3.7 3.8 Attachment 1 Page 59 rewrite the condition so the logic term is not needed. Notes and Cautions. Notes and Cautions should not normally occur within the context of the TSR. The TSR in itself is a compendium of potential cautions, and Notes often indicate that the basic explanation is inadequate. When Notes or Cautions are necessary, the following applies:

Section 39

a. Cautions shall be placed immediately before the information to which they refer. Notes may be placed before or after the text they amplify as is most appropriate. All notes and cautions should be preceded by the centered heading “NOTE” or "CAUTION" in uppercase bold type. Text in the note or caution statement should be bold type, indented from both sides of the page. Cautions should be delimited from standard text. b. Notes and Cautions pertaining to information inside the ACTIONS and SURVEILLANCE REQUIREMENTS statements should be placed immediately before the information to which they apply. Tables. When the volume of tabular information to be presented is small, consider integrating the information in text rather than using a separate table. When tables are necessary, they should be located as conveniently as possible for the user. They should have a formal title and number. Body Of Section 1 - Use and Application. This section is expected to be mostly text, so should take the form of paragraphs numbered in accordance with Section II.3.1.b. Other forms of input (tables, notes, etc.) should follow the guidance outlined in Section II.3.1. ody of Section 2 - Safety Limits. Safety Limits should be presented in the format shown in Figure 9. The page heading, as described in Section II.3.2, subparagraph 3.2, should be to the left margin of the page. Below the, heading, and indented, should be the letters “SL:” (in al 1 bold, upper case letters), followed on the same line by a colon and the requirement. If the requirement has subdivisions, they should also be indented. Attachment 1 DOE 5480.22 Page 60 2-25-92 Below the requirement, with sufficient space left above to make the requirement stand apart, the word “APPLICABILITY:” should appear at the left margin and in bold upper case letters. On the same line should be the applicability modes or other conditions. Below the Applicability statement with sufficient space so as to make it obviously separate, should appear the word “ACTIONS” in bold, upper case letters. Immediately below “ACTIONS” should be the ACTION Statements, which should be indented from the left margin and lettered with capital letters. Subdivisions of the ACTION Statements should be further indented and numbered. 3.9 Body of Section 3/4 - Operational Limits and Surveillance Requirements should be presented in the format shown in Figures 10 and 11. The page headings should be as described in Section 11.3.2, above and should be to the left hand margin of the page. Below the heading and indented should be the letters “LCS” or “LCO” in bold upper case letters. This should be followed on the same line by a colon and then the requirement. For simple requirements, only a sentence or two may suffice while for a complex requirement, subdivisions may be necessary. Use upper case letters for the main divisions and indented numbers as the first subcategory. Use indented lower case letters for the next division, if necessary. If further division appears to be necessary, consider making an entire new requirement within the main group. Below the requirement, with sufficient space left above to make a clear separation, the word “APPLICABILITY:” should appear at the left margin and in bold upper case letters. On the same line should be the applicability modes or other conditions.

Section 40

Below the APPLICABILITY statement, also with sufficient space left above to make a clear separation, should appear the word “ACTIONS:” in bold upper case letters. Immediately below “ACTIONS:” and indented should be the ACTION Statements, the main divisions of which should be numbered, and subdivisions should be lettered. Below the ACTION statements, with sufficient space left above to make a clear separation, should appear the words “SURVEILLANCE REQUIREMENTS:” in bold upper case letters at the left margin. Below “SURVEILLANCE REQUIREMENTS:”, and indented, should be the number of the surveillance, as defined in Section II.3.1. The statement of the DOE 5480.22 2-25-92 Attachment 1 Page 61 surveillance(s) should follow, with subdivisions indented. 3.10 Body of Section 5 - Administrative Controls. The body of this section is expected to be mostly text, possibly with tables, so it should take the form of paragraphs numbered in accordance with Section II.3.1.b, and as noted on Section II.3.1, for other types of input. 3.11 Bodv of Basis_ Appendix The body of the Bases appendix should be presented in the format shown in the example of Figure 16. The page heading should be that described in Section 11.3.2, with the number of the SL, LCS, or LCO and the same title used in that requirement. Below the requirement number and title (3.3 .2. BORON INJECTION SYSTEM in Figure 16, for example), the word BASIS in bold upper case letters should be at the left margin and underlined with a delimiter. Immediately below the delimiter are the Bases themselves. 3.12 Changes to the TSR. Changes to the TSR shall be designated in the following manner: (a) a list of pages in effect with page number and date, (b) a record of revision pages, (c) sidebar changes in the TSR text, and (d) each page should contain the page number, document number, and effective date. Attachment 1 Page 62 DOE 5480.22 2-25-92 3.3 REACTIVITY CONTROL 3.3.2 BORON INJECTION SYSTEM BASES Each section would normally be in paragraph form and should include the information required by Section 11.2.5. Figure 16 Example of Basis Appendix DOE 5480.22 2-25-92 Attachment 1 Page 63 III. WRITER’S GUIDE 1. Introduction. Style in writing is the cumulative effect of the writer’s choice of words and phrases, sentence structure, emphasis, and arrangement of material. In any technical writing, the style must not intrude on the communication of facts. Good technical writing style is not apparent until it falters. Inconsistent or inappropriate wording, sentence structure, or punctuation distracts the user and distorts meaning. This section contains style guidelines for writing Technical Safety Requirements. They apply to all sections of the requirements. Their consistent use will ensure that the information in Technical Safety Requirements is as clear, concise, and usable as possible. 2. Words and Phrases. 2.1 Use Familiar Words. Brief, clear writing increases reading speed and comprehension. To make writing readable and understandable, use familiar words. Such words tend to be short and used meaning gained Less familiar: approximately often in conversation. There is rarely any by using a longer, less familiar word. Familiar: about utilize, employ use accumulation buildup prior to before however but proceed go on, go facilitate help, ease additionally too, also 2.2 Use Words With Precise Meanings. Words and phrases such as the following do not have precise meaning for the user and should be avoided:

Section 41

immediately approximately as soon as possible initiate at once When a word or phrase is to be used as the basis for compliance requirement, be precise. Do not use words that cannot be precisely interpreted. 2.3 Verbs. Use the standards in the following paragraphs as guidelines for the correct use of verbs and verb forms. Attachment 1 Page 64 DOE 5480.22 2-25-92 Strong Versus Weak Verbs. DO not smother strong verbs by turning them into objects of weaker verbs. Smothered: Strong: make an inspection inspect perform a verification verify take the measurement measure Strong Versus Long Verbs. Use one-syllable verbs instead of two-syllable verbs. Use one- and two-syllable verbs instead of verbs with several syllables. Unless technical meaning demands the longer verb, there is no good reason to use it. Long: Short: function work accomplished done accumulate build up perform do, make, take, run prevent...from keep...from fabricated made 2.4 Articles. Articles are a, an, and the. Use articles in descriptive text only as needed for clarity and flow of thought. The following guidelines apply to use of articles. Do not use articles in: a. Titles of documents, chapters, sections, paragraphs, Figures, tables, appendices, or other document elements. b. Table column headings. c. Table entries and tabular instructions unless a passage cannot be clearly understood without articles. d. Procedural steps and instructions. Keep procedural information direct and concise by omitting articles, unless a them. 3. SENTENCE STRUCTURE 3.1 General Rules passage cannot be clearly understood without a. Arrange words in sentences and sentences in paragraphs so that the meaning is clear on first reading. b. Make sentences concise by omitting useless words. DOE 5480.22 2-25-92 c. d. e. Attachment 1 Page 65 Rewrite sentences that may be confusing, awkward, illogical, or obscure to the reader. Break up long, straggling, complex sentences into two or more short ones. Do not include words, phrases, or clauses that do not relate directly to the main thought of the sentence. 3.2 Sentence Length. Short sentences and clauses make writing more readable and understandable. Not all long sentences are hard to understand, but length and difficulty tend to be related. Sentence length can be varied to avoid monotony, however, examine long sentences to see if they can be shortened. Change long sentences to shorter ones. Change clauses to phrases, clauses or phrases to single adjectives or adverbs, and long phrases to shorter ones. For example: Long: Better: During the performance of an ANALOG CHANNEL OPERATIONAL TEST, it is necessary to check the entire instrumentation loop (excluding sensor) including the function of an annunciator light; however, during performance of a CHANNEL CALIBRATION, it is not necessary to ensure that all annunciators function properly. When performing an ANALOG CHANNEL OPERATIONAL TEST, the entire instrumentation loop (except sensor), including the annunciator light, must be checked. When performing a CHANNEL CALIBRATION, annunciators need not be checked. If, in the course of testing of valve stroke times, it is found that any valve exhibits a stroke time that is 25 percent greater than the stroke time measured during a previous test of the same valve, the test frequency of the valve shall be increased to once per month until corrective action is taken, at which time the original test frequency shall be resumed. Long:

Section 42

Better: When testing valve stroke times, if any valve is found to have a stroke time 25 percent greater than when previously tested, increase its test frequency to once per month. When corrective action is taken, resume the original test frequency. 3.3 Positive Versus Negative Sentences. Where possible, use positive sentences instead of negative sentences. Attachment 1 DOE 5480.22 Page 66 2-25-92 Negative: High steam pressure is not uncommon under such conditions. Positive: High steam pressure is common under such conditions. Negative: If at least one pump cannot be put back in service, . . . . Positive: If no pump can be put back in service, . . . . 3.4 Active Versus Passive Sentences. Where possible, use sentences with active instead of passive verbs. Passive: System pressure is relieved by PORVs when . . . . Active: PORVs relieve steam pressure when . . . . Passive: This limitation provides assurance that . . . . Active: This limitation ensures that . . . . 4. BREVITY IN WRITING 4.1 Unnecessary Words and Phrases. Economy in writing is reached by omitting needless words and phrases and by phrasing information succinctly. Below are examples of ways to simplify sentences and phrases. Wordy: Better: Wordy: Better: Fire Detectors that are used to actuate Fire Suppression Systems represent a more critically important component of the facility’s Fire Protection Program than detectors that are installed solely for early fire warning and notification. Fire Detectors that actuate Fire Suppression Systems are more important to the facility’s Fire Protection Program than detectors used solely for early fire warning. Inservice inspection of heat exchangers is essential in order to maintain surveillance of the conditions of the tubes in the event that there is evidence of mechanical damage or progressive degradation due to design, manufacturing errors, or inservice conditions that lead to corrosion. Inservice inspection of heat exchangers is required to ensure that there is no damage or progressive degradation of the tubes caused by design or manufacturing errors, or corrosion. DOE 5480.22 2-25-92 Attachment 1 Page 67 Wordy: Better: in the event that... if... in order to... to... for the purpose of... for, to... it is dependent upon... it depends on... Each of the curves shows... Each curve shows... give consideration to consider initiated immediately started at once more frequent intervals more frequently In the following examples, the underlined words can be left out of the sentences with no loss in meaning but with a gain in economy of expression. The underlined words add nothing to the sense of the sentences. The purpose of the drains is to remove water from the turbine. Two alarm signals serve to indicate that the pump is not working. The thermocouples are designed to sense metal temperature variations. The phrase relationship between the generator output and the applied load is very critical. A pressure switch located on the seal oil supply unit . . . . Do not remove any tools from the work area without proper authorization. 4.2 Abbreviations. Acronyms. and Symbols. Use only those abbreviations, acronyms, and symbols-that are clearly recognized by the user. Avoid abbreviations of words, phrases, or names, unless the system or component is frequently and commonly abbreviated. Following are common symbols that should be used in Technical Safety Requirements. =

Section 43

Except for °F and text. When space symbols should be Symbol % °F °C + < °C, symbols should be avoided in narrative is limited, such as in tables or figures, used for brevity and to save space. Meaning Equal to P e r c e n t Degrees Fahrenheit Degrees Celsius Plus Minus Less Than - Attachment 1 Page 68 DOE 5480.22 2-25-92 \ Less Than or Equal To ^ > Greater Than Greater Than or Equal To 4.3 Capitalization . In general, standard American English rules for capitalization should be used. The following specific guidelines apply to writing of Technical Safety Requirements: a. Use of Upper Case Letters. Write the following in upper case letters: (1) Defined terms (2) Requirement titles and systems when used as page or LCO headings (3) Acronyms (4) The word NOTE when used as a heading (5) Logic terms used as connectors, e.g., AND, OR, EITHER, etc. (6) Table column headings (7) Headings in the LCOs and Bases (Refer to the example in Figures 9 and 14 of Part II “Preparation”) b. Use of Initial Upper Case Letters (First Letter in Each Word). Initially capitalize the following: (1) Each word in system titles (2) First word in a phrase used in a list (3) Each word in component nomenclature (4) Each word in a system or component (5) Proper nouns (6) Each word in major system names (7) Figure and table titles reference 4.4 Punctuation . In general, use standard American English rules for punctuation. Refer to Figure 9 of Part II for an example of punctuation in Technical Safety Requirements. Do not use periods in the Action Statement tables. Use periods as DOE 5480.22 Attachment 1 2-25-92 Page 69 appropriate in the surveillance requirement tables. Do not use contractions of words. For example, use “cannot” rather than “can’t” or “is notn rather than “isn’t.” 4.5 Units of Measure. Follow the guidelines below when writing units of measurement: a. Use the same units of measurement that appear on instruments or gauges whenever possible. b. Use units of measure that are familiar to the operators. c. Use Arabic numerals unless specific equipment dictates otherwise. 4.6 Tolerances. Follow the guidelines below when writing tolerances: a. Whenever possible, always provide acceptable tolerances for given values. b. Give tolerances in immediately understood terms. DO not use the ± symbol to express tolerances. When possible, state the value as an acceptable range, i.e., ‘between xx and xx.” The ± symbol may be used as a heading where a list of values is to be entered, e.g.: Pressure (± l0% ) psid psid In this application, the ± symbol is used as an acceptable tolerance for calculating actual values, that should then be written as acceptable ranges in the table. 4.7 Formulas and Calculation s. Formulas and calculations should be avoided in Technical Safety Requirements when possible. Unless the formula or calculation is part of an instruction or procedure that must be performed by the user, formulas of calculations can usually be avoided. Attachment 1 DOE 5480.22 Page 70 2-25-92 IV. CONVERSION OF TS/OSR TO TSR Chapter II provides guidance on the preparation of TSR. This Chapter gives contractors guidance on conversion of existing TS and OSRs into TSRs.

Section 44

1. Conversion of Existing Technical Specifications. For reactor facilities with existing TS which are not formatted in accordance with this Order, the conversion can be assisted with the use of a screening form. This form would be essentially a checklist to be applied against each existing requirement. The form would pose five questions, one question for each of the five criterion of Section II.2.3.g. Any requirement which generates a positive response to any of the five questions must be included in the TSR. If a specification is to be transferred to the TSR, it can be categorized into Safety Limit, Limiting Control Setting, or Liimiting Condition for Operation according to the criteria in Section II.2.3.g. Figure 17 provides a sample screening form for Technical Specifications.. 2. Conversion of Existinq Operational Safetv Requ irements. For nuclear facilities with existing OSR which are not formatted in accordance with this order, the conversion can be assisted with the use of a screening form. This form would be essentially a checklist to be applied against each existing requirement. The form would pose five questions, one question for each of the five criterion of Section II.2.3.h, page 32, of this document. Any requirement which generates a positive response to any of the five questions must be included in the TSR. If a requirement is to be transferred to the TSR, it can be categorized into Safety Limit, Limiting Control Setting, or Limiting Condition of Operation according to the criteria in Section II.2.3.h. Figure 18 provides a sample screening form for Operational Safety Requirements. DOE 5480.22 Attachment 1 2-25-92 Page 71 TECHNICAL SPECIFICATION SCREENING FORM 1. TECHNICAL SPECIFICATION NUMBER: 2. EVALUATION: Is the technical specification applicable to: YES NO YES NO YES NO YES NO YES NO a. Installed instrumentation that is used to detect and indicate in the control room or other control location a significant degradation of the any of the physical barriers that prevent the uncontrolled release of radioactive or other hazardous materials, or; b. A structure, system, or component that is part of the primary success path and which functions or actuates to mitigate an accident or transient that either involves the assumed failure of, or presents a challenge to, the integrity of a radioactive or other hazardous material barrier, or; c. A process variable that is an initial condition to a design basis accident or transient that involves the assumed failure of, or presents a challenge to, the integrity of a radioactive or other hazardous material barrier, or; d. Experiments or experimental facilities that could provide a path for the uncontrolled release of radioactive or other hazardous material or that could affect criticality. e. Systems and equipment used to handle fissile material outside the reactor core. If the answer to any one of the above questions is “YES,” then the technical specification should be included in the Technical Safety Requirements, unless justified otherwise. Figure 17 Example Technical Specifications Screening Form Page 1 of 2 Attachment 1 Page 72 DOE 5480.22 2-25-92 3. DISCUSSION: Here explain why the specification does or does not meet the criteria and note any special considerations why a particular specification should or should not be included in the TSR. This part should also include the following specific information:

Section 45

a. If the specification is found to meet criteria “b” or “c,” provide examples of the accidents or transients for which the specification represents an initial condition or which it is assumed to mitigate. b. Where a component, structure, or system has more than one purpose or function that is addressed in other technical specifications, reference the other specification(s) for the other function(s). c. If the specification does not meet any of the criteria, a short description of the requirements should be provided. 4. CONCLUSION: This technical specification is included in the Technical Safety Requirements. This technical specification is not included in the Technical Safety Requirements. Figure 17 Example Technical Specifications Screening Form Page 2 of 2 DOE 5480.22 Attachment 1 2-25-92 Page 73 OPERATIONAL SAFETY REQUIREMENTS SCREENING FORM 1. OPERATIONAL SAFETY REQUIREMENTS NUMBER: 2. EVALUATION: Is the operational safety requirement applicable to: YES NO YES NO YES NO YES NO YES NO a. InstalLed instrumentation that is used to detect, and indicate in the control room or other control location, a significant degradation of the physical barriers which prevent the uncontrolled release of radioactive or other hazardous materials, or; b. A structure, system, or component which functions or actuates to mitigate an accident or transients that either involves the assumed failure of, or present a challenge to, the integrity of a physical barrier which prevents the uncontrolled release of radioactive or other hazardous materials, or; c. A process variable that is an initial condition for those design basis accidents or transient analyses that involves the assumed failure of, or presents a challenge to, the integrity of a radioactive or other hazardous material barrier, or; d. Experiments and experimental facilities that could provide a path for the uncontrolled release of radioactive or other hazardous materials, or that could affect critically, or; e. Systems and equipment used to handle fissile materials. If the answer to any one of the above questions is “YES," then the operational safety requirement should be included in the Technical Safety Requirements unless justified otherwise. Figure 18 Example Operational Safety Requirements Screening Form Page 1 of 2 Attachment 1 Page 74 DOE 5480.22 2-25-92 OPERATIONAL SAFETY REOUIRFMENTS SCREENING FORM (continued) 3. DISCUSSION: Explain why the requirement does or does not meet the criteria and note any special considerations why a particular requirement should or should not be included in the TSR. This part should also include the following specific information: a. If the requirement is found to meet criteria “b” or “c,” provide examples of the accidents or transients for which the requirement represents an initial condition or which it is assumed to mitigate. b. Where a component, structure, or system has more than one purpose or function that is addressed in other operational safety requirements, reference the other requirement(s) for the other function(s). c. If the requirement does not meet any of the criteria, a short description of the requirements should be provided. 4. CONCLUSION: This operational Technical Safety This operational Technical Safety safety requirement Requirements. safety requirement Requirements. is included in the is not included in the Figure 18 Example Operational Safety Requirements Screening Form Page 2 of 2

Something wrong with this record? Tell us