The Investigation That Paid for Itself Twice — A Design BRF Success Story

Most discussion of incident investigation focuses, understandably, on what goes wrong when a finding doesn’t reach far enough. It’s worth looking at the opposite case too — an investigation whose finding was deliberately used beyond the single incident it was written about, and what that decision was worth two years later.

A Near-Miss That Stayed a Near-Miss

At a petrochemical facility in Malaysia, a near-miss occurred on a transfer line — the same failure mode, in a smaller form, as a more serious incident that had happened on a different unit two years earlier. That earlier investigation had gone past the operator on shift and identified a Design BRF: a valve arrangement that made it possible to set up a wrong-line transfer without anyone intending to, simply because the arrangement didn’t physically prevent the error.

After that first investigation, the facility didn’t limit its response to retraining the operators on the one unit involved. It used the finding to audit every other unit on site with the same valve arrangement and redesigned the ones that matched the pattern. When the near-miss occurred two years later — on one of the units that hadn’t been flagged in the original audit, because the arrangement there was similar but not identical — the redesign already completed on every other matching line meant the event stayed a near-miss instead of repeating the original, more serious incident.

What a Design BRF Describes

Within Tripod Beta’s Basic Risk Factor framework, Design refers to a systemic gap in how equipment or a system was engineered — not a maintenance lapse or a procedural gap, but a configuration that makes a specific error easy to make regardless of operator skill or attentiveness. A valve arrangement that allows a wrong-line transfer to be physically set up is a design-level gap: no amount of training changes what the equipment’s configuration permits a person to do.

The Return That Never Gets Written Into a Report

Nobody wrote a report crediting the first investigation for the incident that didn’t happen two years later. That absence is the part of this story that’s easy to overlook: the actual return on a properly scoped investigation shows up as the shutdown that didn’t occur, the incident report that never had to be written, and the operator who wasn’t hurt on a line nobody had thought to check yet at the time of the original finding. None of that appears anywhere in a facility’s investigation metrics, because those metrics typically count incidents and findings, not incidents prevented by findings from years earlier.

Why the Audit-and-Redesign Step Mattered

The decision that made the difference in this case wasn’t the quality of the original investigation’s technical finding — it was the decision to treat that finding as applicable beyond the single asset it was written about. Auditing every other unit with a matching valve arrangement, and committing to redesign the ones that matched, is an additional step beyond what most investigation processes require. It is also the step that converted a correct diagnosis into an operation-wide prevention outcome.

The Difference Between Closing a File and Getting Better

An investigation done to close a file, and an investigation done to make the operation better at not failing the same way twice, can produce an identical technical finding and still diverge completely in what happens next. The difference isn’t visible in the investigation report itself — it’s visible in whether anyone went back, months or years later, and checked whether the same configuration existed anywhere else in the operation.

What This Means for How Investigations Get Scoped

Building this habit into a facility’s standard investigation process means adding one explicit step after any Design, Hardware, or Maintenance Management BRF finding: check whether the same configuration, specification, or arrangement exists elsewhere in the operation, and treat the finding as incomplete until that check has been done. This is not a large addition to an investigation’s scope. It is, based on this case, the specific step responsible for the incident that didn’t happen.

The Question Worth Asking

For a past investigation finding in your own organisation, it’s worth asking directly: did anything change beyond the single incident it was written about? If the answer is no, the finding may still be sitting in a filed report, waiting for the same configuration to fail again somewhere else in the operation.

Why This Is Worth Budgeting For, Not Just Praising

The audit-and-redesign step in this case had a real cost — engineering time to review every matching unit, and capital or maintenance budget to redesign the ones that matched. That cost was incurred once, upfront, against a finding from a single incident. The alternative — waiting for each unit to fail on its own before addressing it individually — would have meant paying a similar or larger cost repeatedly, spread across multiple incidents, each with its own investigation, its own downtime, and its own chance of escalating beyond a near-miss. Framed as a one-time investment against a known, identified gap, the audit-and-redesign step is a more defensible budget line than most facilities treat it as when the decision is being made in the weeks after an investigation closes.

Learn to scope investigations that prevent repeat failures across the whole operation, not just the one incident. Cikgu Barrier’s Tripod Beta Incident Investigation program teaches Malaysian HSE teams to identify Design, Hardware, and Maintenance Management BRFs and build the audit-and-act habit that turns a single finding into an operation-wide prevention outcome. Register your interest in upcoming public and in-house dates — no cost, no commitment.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top