Operational Reactor Safety

22.091 /22.903

Professor Andrew C. Kadak Professor of the Practice

Probabilistic Safety Analysis Lecture 11

Topics to be Covered

Probabilistic Basics

Event Trees

Fault Trees



Safety Goals


Deterministic Safety Analysis

Probabilistic Safety Analysis

PWR Engineered Safety Systems

BWR Early Engineered Safety Systems

PSA Applications

The Pre-PRA Era (prior to 1975)

Management of (unquantified at the time) uncertainty was always a concern.

Defense-in-depth and safety margins became embedded in the regulations.

“Defense-in-Depth is an element of the NRC’s safety philosophy that employs successive compensatory measures to prevent accidents or mitigate damage if a malfunction, accident, or naturally caused event occurs at a nuclear facility.” [Commission’s White Paper, February, 1999]

Design Basis Accidents are postulated accidents that a nuclear facility must be designed and built to withstand without loss to the systems, structures, and components necessary to assure public health and safety.

Potential Offsite Doses

Farmer’s Paper (1967)

Iodine-131 is a major threat to health in a nuclear plant accident.

Attempting to differentiate between credible (DBAs) and incredible accidents (Class 9; multiple protective system failures) is not logical.

If one considers a fault, such as a loss-of-coolant accident (LOCA), one can determine various outcomes, from safe shutdown and cooldown, to consideration of delays and partial failures of shutdown or shutdown cooling with potential consequences of radioactivity release.

Historical Risk Studies

Technological Risk Assessment

Study the system as an integrated socio-technical system.

Probabilisti c Ris k Assessmen t (PRA ) support s Risk Managemen t b y answerin g th e questions:

What can go wrong? (accident sequences or scenarios)

How likely are these scenarios?

What are their consequences?

Reactor Safety Study (WASH-1400; 1975)

Prio r Beliefs:

1. Protect against large LOCA.

2. CDF is low (about once every 100 million years, 10 -8 per reactor year)

3. Consequences of accidents would be disastrous. Majo r Findings

1. Dominant contributors: Small LOCAs and Transients.

2. CDF higher than earlier believed (best estimate: 5x10 -5 , once every 20,000 years; upper bound: 3x10 -4 per reactor year, once every 3,333 years).

3. Consequences significantly smaller.

4. Support systems and operator actions very important.

Risk Curves

Frequency of Fata lities Due to Man-Caused Events (RSS)



Control Reactor Power Control reactivity additions Shutdown reliably

Cool the Reactor and Spent Fuel Maintain coolant inventory Maintain coolant flow Maintain coolant heat sinks


M aintain Containment Integrity Prevent over-pressurization Prevent over-heating Prevent containment bypass

Capture Material Within Contain ment Scrubbing

Deposition Chemical capture


The Single-Failure Criterion

“Fluid and electric systems are considered to be designed against an assumed single failure if neither (1) a single failure of any active component (assuming passive components function properly) nor (2) a single failure of a passive component (assuming active components function properly), results in a loss of the capability of the system to perform its safety functions.”

The intent is to achieve high reliability (probability of success) without quantifying it.

Looking for the worst possible single failure leads to better system understanding.

Defense in Depth

“Defense-in-Depth is an element of the Nuclear Regulatory Commission’s safety philosophy that employs successive compensatory measures to prevent accidents or mitigate damage if a malfunction, accident, or naturally caused even t occurs at a nuclear facility.”

[Commission’s W h ite Paper, USNRC, 1999]

PRA Model Overview

Leve l I Leve l II Leve l III




Public health effects


Containment failure/release sequences



Accident sequences leading to plant damage states


At-power Operation

Shutdown / Transition Evolutions


Internal Events External Events


Basic Elements of PSA

Transition of a Risk Assessment

Event and Fault Tree Structure

Loss-of-offsite-power event tree

LOOP Secondary Bleed Recirc. Core Heat Removal & Feed




CDF and LERF Definitions

Cor e damag e frequency is defined as the sum of the frequencies of those accidents that result in uncovery and heatup of the reactor core to the point at which prolonged oxidation and seve re fuel damage involving a large fraction of the core (i.e., sufficient, if released from containment, to have the potential for causing offsite health effects) is anticipated.

L arg e earl y releas e frequency is defined as the frequency of those accidents leading to significant, unmitigated rele ases from containment in a time frame prior to effective evacuation of the close-in population such that there is the potential for early health effects. Such accidents generally include unscrubbed releases associated with ear ly containment failure shortly after vessel breach, containment bypass events , and loss of containment isolation.

Draft Regulatory Guide 1.200 Rev. 1, “An Approach for Determining the Technical Adequacy of Probabilistic Risk Assessment Results for Risk-Informed Activities”

At Power Level I Results

CDF = 4.5x10 -5 / yr (Modes 1, 2, 3)

Initiator Contribution to CDF Total:

Internal Events… 56%

External Events 44%

Seismic Events






Level I Results

Functional Sequences

Contribution CDF

T ransients - Station Blackout/Seal LOCA 45%

T ransients - L oss of Support Systems/Seal LOCA 29%

T ransients - L oss of Feedwater/Feed & Bleed 12%

L OCA - Injection/Recirculation Failure 7%

A TWS - N o Long Term Reactivity Control 6%

A TWS - Reactor Vessel Overpressurization 2%

At Power Level II Results

Release Categories

Conditiona l Probability









Large-Early Release Freq (LERF) = 7x10 -8 / yr

Large-Early Failure Mode

Percen t Contribution

Containment Bypass


Containment Isolation Failure


Gross Containment Failure


Shutdown, Full Scope, Level 3 PSA (1988) Results: Mean CDF shutdow n ~ Mean CDF power

Dominant CD sequence:

Loss of RHR at reduced inventory .

Risk dominated by operator actions - c ausing and mitigating events.

Significant risk reductions with low-cost modifications and controls.

Midloop level monitor, alarm Procedures, training

Administrative controls on outage planning

Shutdown PRA Issues

R isk is dominated by operator actions - i mportance of HRA.

Generic studies give useful insights, but risk- controlling factors are plant-specific .

Shutdown risk is dynamic - a verage risk is generally low (relative to full power risk), but is subject to risk “spikes.”

S hutdown risk is more amenable to “management.” At-power risk is designed in.

Integrated Risk (All Modes) 2002 Update

Mode Description CDF Percen t o f Total

Mode 1

Full-power (>70% pwr)

4.28 E-5


Mode 2

Low-power (<70% pwr)

0.15 E-5


Mode 3

Hot Standby

0.08 E-5


Mode 4

Hot Shutdown

0.05 E-5


Mode 5

Cold Shutdown

0.91 E-5


Mode 6


1.38 E-5


Total Core Damage Frequency

6.86 E-5


Risk Assessment Review Group

“We a r e unable to define whether the overall probability o f a core melt gi ve n in WASH-1400 is high or low, bu t we ar e certain that the err or ban ds are u n d erstated.”

WASH-1400 i s "inscrutable."

"…the f a ul t -tree/event-tree method ology is sound, and b o th can and sh ould be more widely used b y NRC ."

"PS A me th od s sh ould b e us ed to de al wit h ge neric safe ty iss ues, to formulate new regulatory re quirements , to a ssess and revalid ate exis ting r e gul at or y requirements, and to e v alu ate new designs."

Commission Actions (Jan. 18, 1979)

“…the Commission has reexamined its views regarding the Study in light of the Review Group’s critique.”

“The Commission withdraws any explicit or implicit past endorsement of the Executive Summary.”

“…the Commission does not regard as reliable the Reactor Safety Study’s numerical estimate of the overall risk of reactor accidents.”

Zion and Indian Point PRAs (1981)

First PRAs sponsored by the industry.

Comprehensive analysis of uncertainties (Bayesian methods).

Detailed containment analysis (not all accidents lead to containment failure).

“External” events (earthquakes, fires) may be significant contributors to risk.

Seabrook PRA Results

NUREG-1150 and RSS CDF for Peach Botto m

Comparison of Iodine Releases (Peach Bottom)

Quantitative Safety Goals of the

US Nuclear Regulatory Commission (August, 1986)

E a r l y a nd l a t e nt c a nc e r m o r t a l i t y

r i s k s t o an i n d i v i d u al l i v i n g n e ar t h e

p l a n t s h o u l d n o t ex cee d 0 . 1 p ercen t o f t h e ba c k g r o u nd a c c i de nt o r c a nc e r

m o r t a l i t y r i s k , a p p r o x i m a t e l y

5 x 10 -7 / y ear f o r ea r l y d e a t h a n d

2 x 10 -6 / y ear f o r d e a t h f r o m ca n c e r .

The prompt fatality goal applies to an average individual living i n the region betw een the site boundary and 1 mile beyond this boundary.

The latent cancer fatality goal applies to an average i ndividual living in the region betw een the site boundary and 10 miles beyond this boundary.

Societal Risks

Annual Individual Occupational Risks

All industries 7x10 -5

Coal Mining: 24x10 -5

Fire Fighting: 40x10 -5

Police: 32x10 -5

US President 1,900x10 –5 (!)

Annual Public Risks

Total 870x10 -5

Heart Disease 271x10 -5

All cancers 200x10 -5

Motor vehicles: 15x10 -5

From: Wilson & Crouch, Risk/Benefit Analysis, Harvard University Press, 2001.

Subsidiary Goals

The average core damage frequency (CDF) should be less than 10 -4 /ry (once every 10,000 reactor years)

The large early release frequency (LERF) should be less than 10 -5 /ry (once every 100,000 reactor years)

Large Early Release Frequency

LERF is being used as a surrogate for the early fatality QHO.

It is defined as the frequency of those accidents leading to significant, unmitigated releases from containment in a time frame prior to effective evacuation of the close-in population such that there is a potential for early health effects.

Such accidents generally include unscrubbed releases associated with early containment failure at or shortly after ve ssel breach, containment bypass events, and loss of containment isolation.

PRA Model Overview and Subsidiary O bjective s




10 -4 /ry




10 -5 /ry

Leve l I Leve l II Leve l III


Public health effects


Accident sequences leading to plant damage states


Containment failure/release sequences


At-power Operation Shutdown / Transition


Internal Events External Events

Evolution s


“Acceptable” vs. “Tolerable” Risks (UKHSE)

Ris k ca nnot be jus tifie d sa v e in e x tra or dina ry ci r c u ms ta nc es

Contro l me as ur es mus t be i n t r od u ced f o r ri sk i n t h is r e gion to dr ive r e s i d u al r i sk tow a r ds the b r oa dly accept ab le reg ion

Le vel of r e s i d u a l r i sk re gar de d a s in si gnifi ca nt - - fur the r e ffor t to r e du ce r i s k not l i k e l y t o be r e qu ir e d

In creasin g individ ual risk s and so cietal concerns




PRA Policy Statement (1995)

The use of PRA should be increased to the extent supported by the state of the art and data and in a manner that complements the defense-in-depth philosophy.

PRA should be used to reduce unnecessary conservatisms associated with current regulatory requirements.

Risk Decrease, Neutral , or Small Increase

Monitor Performance

Integrated Decision Making

Risk-Informed Decision Making

Compl y wit h

Regulation s

Maintain Defense-in- Depth Philosophy

Maintain Safety Margins

for Licensin g Basi s Change s (R G 1.174 , 1998 )


Region I

Region I

- No changes

10 -5

Regio n I I

- S mall Changes

- T rack Cumulative Impacts Region III

- V ery Small Changes

10 -6

Region II

Region III

- More flexibility with respect to Baseline

- T rack Cumulative Impacts

10 -5

10 -4


Accep tanc e Guideline s fo r Cor e Damag e Frequenc y

R isk-Informe d Framewor k

Traditional “Deterministic” Approaches

Unquantified Probabilities

Design-B asis Accidents

Structuralist Defense in Depth

Risk- Informed Approach

Combination of traditional and


Risk-Based Approach

Quantified Probabilities

Scenario Based


Can impose heavy regulatory burden



Rationalist Defense in Depth


Quality is an issue



P roblems: 14.16, 19, 24, 28

