Eight Investigation Principles for Ex Lifecycle Failures
An Ex investigation that stops at the ignition source produces an equipment failure report rather than an understanding of what happened. Drawing on Oakley's accident investigation methods, this article applies eight principles to explosion protection: work backwards through the lifecycle, reconstruct the sequence, treat change analysis as management of change, map barrier analysis onto engineered and administrative Ex barriers, preserve the compliance state alongside the damaged hardware, resist operator error as a root cause, treat loss of Ex integrity as an event even without ignition, and build corrective actions across equipment, system and management levels.

I do CSI. There are always few cases I am heavily involved in. For the same reason I used to read books. Right now one is Oakley’s Accident Investigation Techniques. Good book, I can only recommend it. Even for Head of Operations.
Its strongest contribution is a structured way to answer the question that matters after an explosion, ignition, Ex near miss, or loss of Ex integrity:
“How did the installation move from a demonstrated Ex-safe condition to a condition in which ignition became possible?”
The core model is investigation → analysis → corrective action. It stresses that all three phases are necessary: collect facts and evidence, reconstruct what happened and identify causal factors, then develop actions that prevent recurrence.
Ex evidence → Ex event sequence → failed/degraded barriers → systemic causes → restoration and prevention.
1. Do not investigate only the ignition
Accidents rarely have one cause; investigators should look from equipment/worker level through supervision and management systems.
So an Ex investigation should continue backwards:
Release → explosive atmosphere → hazardous area → ignition-capable condition → Ex protection failure/degradation → inspection/maintenance/MoC/documentation/competence failure → management-system conditions.
For example:
Solvent release → Zone 1 atmosphere → motor present → motor Ex integrity compromised → incorrect replacement cable gland → modification not technically assessed → inspection failed to detect it → asset history incomplete → contractor competence/authorization inadequate.
2. Sequence-of-events analysis is particularly powerful for Ex
The investigation should reconstruct the chronology and distinguish facts, conditions, assumptions and causal factors.
This fits Ex compliance Ex.tremely well because many serious Ex failures are actually missing lifecycle actions:
HAC → equipment selection → installation → initial inspection → commissioning → operation → periodic inspection → maintenance → modification → repair → return to service.
An Ex investigation therefore needs to identify where that chain moved away from the intended lifecycle.
3. Change Analysis = Ex Management of Change
Some form of change is a major factor in most accidents, and describes Change Analysis as both reactive and proactive. It compares the accident situation with an accident-free, procedural, or ideal situation.
Ask: What was different?
Product? Temperature? Pressure? Ventilation? throughput? Dust properties? Solvent concentration? Equipment? Gland? Seal? Motor? VSD? Enclosure? Battery? Cleaning method? Inspection interval? Contractor? Repair method? Temporary installation? Operating procedure?
Then compare: Before change → after change → Ex consequence.
This is valuable when the equipment is technically certified but the conditions of use have changed around it.
4. Barrier Analysis maps almost perfectly onto explosion protection
Hazard → Barrier → Target and asks whether barriers failed, were not used, or did not exist. It also separates engineered (“hard”) barriers from administrative (“soft”) barriers.
Explosive atmosphere + potential ignition source → Ex barriers → people / plant / environment
Typical engineered barriers are ventilation, containment, inerting, bonding/earthing, temperature limitation, Ex protection concepts, IP integrity, flamepaths, intrinsic-safety energy limitation, gas detection/interlocks and explosion isolation/venting.
Administrative barriers include HAC, EPD/Explosion Protection Document, equipment selection records, Verification Dossier, inspection programme, PTW, MoC, competence control, maintenance instructions, repair controls, special conditions of use and defect management.
The important question becomes: “Which Ex barrier failed, which existed but was not used, and which should have existed but did not?”
5. Evidence preservation is critical in Ex investigations
Preserving evidence before it is altered, collecting physical, documentary, photographic and witness evidence, and not confusing documentation with investigation.
This is especially important after an explosion because well-intentioned recovery activities can destroy the evidence needed to identify the ignition source.
For an Ex investigation, preserve not only damaged hardware but also the compliance state immediately before the event:
Ex marking and nameplate; certificate and schedule; “X” special conditions; drawings; HAC; EPD; equipment register; initial/periodic inspection records; defect history; maintenance history; repair records; modifications; work orders; PTWs; contractor competence; manufacturer instructions; process data; alarms; gas detection records; ventilation status; PLC/DCS histories; photographs; and actual field configuration.
A certificate itself proves very little about the condition of the installation at the time of the event.
6. Root cause should not become “operator error”.
An investigation should not solely assign blame. Its purpose is to understand the sequence and causal factors.
That matters enormously for Ex. If someone opened an Ex enclosure incorrectly, ask:
Why was it opened? → Were they authorized? → Were instructions available? → Was competence verified? → Was isolation/PTW adequate? → Was the enclosure correctly identified? → Was supervision adequate? → Was the subsequent inspection adequate?
Likewise, “maintenance error” is rarely a satisfactory root cause.
The better question is: “What management system allowed the Ex protection concept to be compromised and the equipment subsequently returned to service?”
7. Near misses should be treated as Ex events
The difference between an accident and near miss may simply be chance, and near misses should therefore be investigated.
For Ex operations this is extremely important.
A missing bolt on an Ex d enclosure, damaged IS segregation, uncertified replacement component, disconnected bonding conductor, overdue detailed inspection, incorrect gland, excessive surface temperature, or operation outside an “X” condition may produce no explosion at all.
That may mean: explosive atmosphere + effective ignition source simply did not coincide.
Therefore, loss of demonstrated Ex integrity itself should trigger investigation, even where there was no ignition.
8. Corrective actions must address several layers
There is an argue against superficial “quick fixes” and stresses linking causal factors to corrective actions.
In Ex terms, replacing the damaged gland is only the equipment-level correction.
A proper corrective-action package might include:
Immediate: isolate/STOP, restore protection integrity, inspect similar equipment.
Technical: correct equipment, installation, ventilation, bonding, IS segregation, etc.
System: update HAC/EPD/VD/register/procedures.
Competence: retrain or re-authorize relevant personnel.
Lifecycle: modify inspection/maintenance/repair controls.
Management: improve MoC, contractor control, escalation and accountability.
Organizational learning: determine whether the same weakness exists elsewhere.
Process of investigation:
EVENT / NEAR MISS
↓
Preserve the Ex condition and evidence
↓
Reconstruct the event sequence
↓
Release / explosive atmosphere / ignition-source analysis
↓
HAC validity check
↓
Ex equipment suitability & certificate conditions
↓
Installation integrity
↓
Inspection / maintenance / repair history
↓
Identify changes (MoC analysis)
↓
Analyse preventive & mitigating barriers
↓
Competence / PTW / contractor / supervision analysis
↓
Documentation & Verification Dossier analysis
↓
Management-system causal factors
↓
Corrective actions at equipment + system + management levels
↓
Check similar assets/sites
↓
Update EPD/HAC/VD/Ex Register/MoC/inspection strategy
↓
Verify effectiveness and close
The biggest Ex takeaway:
An Ex incident investigation should not ask only “What was the ignition source?” It should ask “What sequence of technical, operational and management-system failures allowed an effective ignition source and an explosive atmosphere to coexist despite the Ex barriers that were supposed to prevent it?”
That changes the investigation from an equipment failure report into an Ex lifecycle compliance investigation.
And it aligns particularly well with the Operational Ex principle: the accident often begins long before the ignition - at the point where the plant starts operating outside its demonstrated Ex-safe condition.
Note!!!
From the human point of view point 6 is an important topic, makes sense to pay attention.