API Recommended Practice 14C is the industry standard for analyzing, designing, installing, and testing the surface safety systems that protect offshore production platforms. It provides a structured, process-component method for deciding which protective devices every vessel, pump, and flowline needs so that no single failure releases hydrocarbons uncontrolled. This guide explains how API 14C works and where it fits in oil and gas.
API 14C in one line: API 14C (formally API RP 14C) is a recommended practice that defines a systematic method for determining the surface safety devices required on offshore production platforms. It analyzes each process component for undesirable events, assigns primary and secondary protective functions, and documents the result on Safety Analysis Function Evaluation (SAFE) charts, all built around a two-barrier protection philosophy.
API Recommended Practice 14C, titled Analysis, Design, Installation, and Testing of Safety Systems for Offshore Production Facilities, is published by the American Petroleum Institute and is incorporated by reference into US federal regulations for the Outer Continental Shelf. On the US OCS, compliance with API 14C is effectively mandatory rather than merely advisory because BSEE regulations point to it directly.
The core idea is that a production platform is broken down into standard process components: flowlines, wellheads, headers, separators, gas boots, compressors, pumps, heat exchangers, pipeline pumps, vessels, fired components, and so on. For each component type, API 14C already knows the credible undesirable events (overpressure, underpressure, liquid overflow, gas blowby, leak, excess temperature) and the protective devices that guard against them.
The heart of API 14C is the two-barrier philosophy: every undesirable event must have both a primary protective device and an independent secondary device, so a single failure never leads to release. For example, a separator's high pressure is guarded primarily by a pressure sensor that shuts in the inflow, and secondarily by a relief valve that vents mechanically without needing power or logic.
Engineers document this on a Safety Analysis Function Evaluation (SAFE) chart, a matrix that lists each process component against each detectable condition and the device that responds to it. A companion Safety Analysis Table (SAT) and Safety Analysis Checklist (SAC) justify every device that is present and, importantly, every device that has been omitted. If a required device is absent, API 14C requires a documented, defensible reason rather than a silent gap.
API 14C governs the surface safety system, which sits above and around the process: emergency shutdown valves, wellhead surface safety valves, sensors, and relief devices that bring the platform to a safe state on demand. It is closely related to API RP 14E (piping design), 14F (electrical), and 14J (hazards analysis), and it complements, rather than replaces, a full hazards study.
Although API 14C is written for offshore, its device-per-component logic and SAFE chart documentation are widely borrowed by onshore facility designers who want a rigorous, auditable record of protective functions. The chart becomes the single reference that operators, inspectors, and control system integrators use to confirm that the platform's automated protections match the certified design.
Technically it is a recommended practice, but on the US Outer Continental Shelf it is incorporated by reference into BSEE regulations, which makes compliance effectively mandatory for offshore production facilities in US federal waters. Elsewhere and onshore it is often adopted voluntarily as best practice because its SAFE chart method is a well-proven, auditable way to justify a safety system.
API 14C is a prescriptive, component-based method that tells you the protective devices a standard process component needs, and it is efficient precisely because it reuses proven logic. A process hazards analysis such as HAZOP is a broader, scenario-driven study that can uncover risks outside the standard component set. Good practice uses both: API 14C for the systematic device coverage and a hazards analysis for the platform-specific scenarios.
The surface safety system defined by API 14C is the safety layer; a SCADA system sits alongside it to acquire, display, and record the process and device states. A cloud SCADA platform like Merobix reads the same sensors and shutdown status over standard protocols such as Modbus and DNP3 for visibility and alarming, but it does not replace the independent, hardwired protective functions that API 14C requires.
Primary references from the standards bodies and regulators that define this topic:
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.