Alarm Rationalization Worksheet
A worksheet for teams doing alarm rationalization: deciding, alarm by alarm, what deserves to interrupt an operator and why. It is built on the alarm-management lifecycle concepts behind ISA-18.2, described here at a high level in our own words - the standard itself, available from ISA, is the authoritative reference.
The core test: an alarm exists to tell an operator that an abnormal condition requires their action. If there is no operator action, it is a status indication or an event log entry - not an alarm. Most alarm floods are built one “might as well alarm it” decision at a time, and rationalization is how you unbuild them.
Where Rationalization Fits: the Lifecycle
ISA-18.2 describes alarm management as a lifecycle rather than a one-time project. Paraphrased at a high level, the activities are:
- Philosophy - the site-wide document that defines what alarms are for, the priority scheme, and the rules everything else follows. Write this first; the worksheet below assumes it exists.
- Identification - collecting candidate alarms from process hazard analyses, P&IDs, incident reviews, and operations input.
- Rationalization - the systematic review of each candidate against the philosophy: does it merit being an alarm, what is its priority, what is its setpoint. This worksheet supports this stage.
- Detailed design - configuring the rationalized alarms: setpoints, deadbands, delays, messages, and any advanced handling.
- Implementation - putting alarms into service, including testing and operator training.
- Operation and maintenance - the day-to-day life of the alarm system, including shelving practices and keeping instruments healthy.
- Monitoring and assessment - measuring alarm system performance (rates, floods, chattering alarms, standing alarms) against the philosophy’s targets.
- Management of change and audit - controlling changes to alarm configuration and periodically checking that practice still matches the philosophy.
Industry guidance documents publish target alarm rates and priority distributions. We deliberately do not reproduce those numbers here - take them from your alarm philosophy, which should cite its own sources.
The Worksheet Fields
One row per alarm. The fields below are the working core of a rationalization record; many sites add columns for classification, testing requirements, and references.
| Field | What to record |
|---|---|
| Tag / alarm ID | The instrument tag and alarm identifier, e.g. LT-1201 LAH. |
| Alarm description | Plain-language statement of the abnormal condition being annunciated. |
| Purpose | Why this alarm exists: the specific abnormal condition it detects and why the operator must know. |
| Probable causes | The realistic causes an operator should consider when it activates. |
| Consequence of inaction | What happens if nobody acts - to safety, environment, equipment, and production. Be concrete. |
| Operator action | The specific corrective action expected. If the team cannot name one, the candidate fails the core test. |
| Time available to respond | How long the operator has before the consequence occurs. Site-specific: it depends on vessel sizes, flow rates, and process dynamics. |
| Priority and basis | The assigned priority and the reasoning, derived from consequence severity and time to respond per your alarm philosophy - never from gut feel in the meeting. |
| Setpoint and basis | The alarm limit and why: enough margin below any trip to allow response, far enough from normal operation to avoid nuisance activations. |
| Advanced handling flags | Candidate for state-based suppression, flood suppression grouping, on/off delay, deadband tuning, or shelving rules. |
Worked Example
A generic three-phase separator high level alarm, filled in the way a rationalization team might record it. Values marked site-specific must come from your process, not from this page.
| Field | Example entry |
|---|---|
| Tag / alarm ID | LT-1201 LAH (separator liquid level high) |
| Alarm description | Separator liquid level above the high operating limit |
| Purpose | Warn of rising liquid level early enough to prevent liquid carryover into the gas outlet and to avoid the high-high shutdown trip |
| Probable causes | Dump valve failed closed or plugged, downstream blockage, inflow slugging, level controller failure |
| Consequence of inaction | Level continues to LSHH: unit shutdown and deferred production; possible liquid carryover damaging downstream compression |
| Operator action | Verify dump valve operation and dump line flow; operate the manual bypass if safe; dispatch a technician if the valve has failed |
| Time available to respond | Site-specific - calculated from vessel holdup between LAH and LSHH at maximum expected inflow |
| Priority and basis | Assigned from the philosophy’s severity-versus-response-time matrix; the equipment-damage consequence typically places it above a purely economic alarm |
| Setpoint and basis | Above the normal operating band and wave action, below LSHH by enough margin for the response above; site-specific |
| Advanced handling flags | State-based suppression when the well or inlet is shut in; deadband tuned to prevent chattering from surface movement |
Blank Template
Copy this table into a spreadsheet and add one row per alarm. Rationalization is a team exercise - at minimum operations, process engineering, and controls should be in the room.
| Tag / ID | Description | Purpose | Causes | Consequence of inaction | Operator action | Time to respond | Priority + basis | Setpoint + basis | Advanced handling |
|---|---|---|---|---|---|---|---|---|---|
Practical Rules That Keep Sessions Honest
- If nobody can state the operator action, do not configure it as an alarm. Log it as an event instead.
- Priority comes from the philosophy’s matrix, not from whoever argues loudest. Record the basis so the decision survives staff turnover.
- Duplicate annunciations of one abnormal condition (the transmitter alarm, the derived-calculation alarm, and the trip pre-alarm) should be rationalized as a set.
- Rationalization is not a one-time project: route every new alarm request through the same worksheet, or the flood rebuilds itself.
Sources & Standards
Primary references for alarm management - this page paraphrases concepts and does not reproduce the text of any standard:
- ISA-18 committee (ISA-18.2, Management of Alarm Systems for the Process Industries) - the authoritative standard behind the lifecycle concepts summarized here, available for purchase from ISA.
- International Electrotechnical Commission (IEC) - publisher of IEC 62682, the international standard on management of alarm systems for the process industries.
- EEMUA - publisher of EEMUA 191, the widely used guide to alarm system design, management, and procurement.
After the Worksheet
The worksheet works with any control system. When the rationalized alarm list is ready, Merobix can be the place where those priorities, setpoints, and notifications actually live.