Stepin Engineering

Blog

Consequence Modelling Explained: PHAST vs SAFETI for Process Safety Engineers 

June 26, 2026

Senior engineer correcting a common consequence modelling mistake with a junior engineer

Ask any process safety engineer how a QRA study actually starts, and most will tell you it begins long before risk numbers show up in a report. It begins with consequence modelling.

Consequence modelling is the engineering process of predicting what happens physically when a hazardous material escapes containment, before anyone calculates how likely that escape is. Toxic gas drifting downwind, a vapor cloud finding an ignition source, a tank fire radiating heat onto a neighboring vessel – all of it gets modelled mathematically first.

For engineers entering process safety, two software names come up constantly: Phast and Safeti. Both are built by DNV, both share the same modelling engine, and both get confused with each other more often than they should. Most training materials assume you already know the difference, which leaves a real gap for anyone starting out. This article breaks down what consequence modelling actually involves, how Phast and Safeti differ in practice, and where these skills fit into a process safety career.

What Is Consequence Modelling in Process Safety

Process safety engineer reviewing consequence modelling dispersion overlay near refinery LPG storage tanks

Consequence modelling answers one specific question: if this equipment fails right now, how far do the effects reach, and how severe are they? It does not ask how often failure happens. That part belongs to a different stage of the assessment.

In a refinery or chemical plant, a loss of containment scenario starts with a hole in a pipe, a flange leak, or a ruptured vessel. Consequence modelling takes that release and works through discharge rate, dispersion in the atmosphere, and then the physical effects: toxic exposure, thermal radiation from a fire, or overpressure from an explosion.

Picture an LPG storage leak at a refinery during a routine valve change. Before anyone discusses likelihood or risk ranking, the safety team needs to know how far the flammable vapor cloud could travel and what happens if it finds an ignition source near the control room.

This is exactly the gap consequence modelling fills. It gives facility designers, HSE teams, and regulators a physical basis for decisions on equipment spacing, blast wall height, and emergency response planning, often tied to compliance frameworks such as OSHA’s process safety management standard.

Releases are typically grouped as continuous or instantaneous. A continuous release, such as a small pinhole leak, keeps feeding material into the atmosphere over time. An instantaneous release, like a sudden vessel rupture, dumps the entire inventory almost immediately. Each type produces a different dispersion pattern, and getting this classification right early changes every downstream result.

Why Consequence Modelling Comes Before Risk Numbers

Many fresh graduates mix up consequence results and risk results the first time they sit through a QRA review. The distinction is simple once it clicks: consequence tells you how bad, frequency tells you how often, and risk multiplies the two together.

A consequence model on its own produces physical outcomes: a dispersion footprint, a thermal radiation contour, an explosion overpressure zone. None of these numbers say anything about probability. A facility could face a severe consequence and still carry low risk if the release frequency is genuinely rare.

This separation matters on real projects. Process design engineers often need consequence modelling results alone, for example to size a flare stack or define safe separation distances during facility layout. Risk engineers need those same outputs combined with frequency data before they can build an F-N curve or justify a risk reduction measure to plant management.

Engineers who jump straight to risk numbers without understanding the underlying modelling often struggle to defend their assumptions during a HAZOP or management of change review. Knowing where each figure comes from makes technical discussions far easier to handle.

Take an ammonia storage facility near a residential boundary. The consequence model alone might show a toxic plume reaching well past the fence line under worst-case weather. That number alone does not tell management whether to invest in additional safeguards. Only once frequency data is added does the risk picture become clear enough to justify, or rule out, further spending.

What Is Phast Software and What Does It Model

 Engineer running Phast consequence modelling software showing dispersion and explosion contour plots

Phast is DNV’s consequence analysis software, and it is usually the first tool engineers encounter in process safety training. It calculates what happens physically after a loss of containment, using empirical models and, for more complex geometries, computational fluid dynamics.

Process safety professionals have relied on Phast for decades across oil and gas, petrochemical, and LNG work, with growing use in hydrogen and ammonia projects too. It handles pool spreading, evaporation, dispersion, and the flammable or toxic effects tied to a release scenario.

What makes Phast practical on real projects is its scenario builder. Engineers define a release source, whether from a pressure vessel, pipeline, or storage tank, and the software works out discharge behaviour automatically. Add-on modules extend this further into multi-component mixtures and three-dimensional CFD modelling for congested plant layouts.

Discharge, Dispersion, Fire and Explosion Effects in Phast

A typical Phast study walks through three stages: discharge rate from the failure point, dispersion of the released material through the atmosphere, and then fire or explosion modelling depending on whether ignition occurs. Toxic releases skip straight to exposure calculations instead.

Output comes as contour plots overlaid on a site plan, showing how far a flammable cloud, toxic concentration, or thermal radiation zone extends. These visuals often get presented directly in a HAZOP, a facility siting study, or an emergency response plan.

For especially congested layouts, such as offshore platforms or densely packed process units, engineers sometimes pair Phast with DNV’s KFX or EXSIM software, both built specifically for advanced computational fluid dynamics modelling of fires and gas explosions in three-dimensional space.

What Is Safeti Software and How It Builds on Phast

Safeti is DNV’s quantitative risk analysis software, and it builds directly on top of Phast rather than replacing it. Safeti incorporates the same consequence engine, then layers on frequency data, ignition probability, weather statistics, and population information to calculate actual risk.

This is where confusion usually starts for new engineers. Phast tells you what could happen. Safeti tells you how likely it is to happen, and to whom. A QRA delivered to a client almost always comes from Safeti, since regulators and insurers want risk figures, not just consequence footprints.

Risk Outputs from Safeti: Individual Risk, Societal Risk, F-N Curves

Safeti produces risk metrics engineers see referenced constantly in safety reports: Location Specific Individual Risk (LSIR) contours, societal risk through F-N curves, and Potential Loss of Life (PLL) figures. These feed directly into cost-benefit analysis and ALARP demonstrations when a company has to justify whether a risk reduction measure is worth the investment.

Safeti also supports occupied building risk assessments and fire and explosion risk assessment studies, both common deliverables for offshore platforms and congested onshore facilities.

Weather data deserves particular attention here. Safeti runs calculations across multiple wind directions and atmospheric stability classes rather than a single worst-case condition, which is exactly why two facilities with seemingly similar layouts can show very different societal risk profiles.

PHAST vs SAFETI: Key Differences Engineers Should Know

 Side by side comparison of PHAST consequence modelling output and SAFETI risk contour output

Once the relationship is clear, the practical differences are easy to summarise. The table below covers what most engineers actually need to know before deciding which tool to learn first.

AspectPhastSafeti
Scope of analysisConsequence onlyConsequence plus risk
Typical outputDispersion, fire, and explosion contoursIndividual and societal risk, F-N curves
Primary use caseFacility siting, flare design, emergency planningFull QRA, cost-benefit analysis, regulatory submissions
Who uses itProcess design engineers, HSE analystsRisk engineers, safety consultants, regulators

Most engineers starting out learn Phast first, simply because it is the foundation. Safeti adds an entire layer of frequency and population data on top, and that layer needs its own set of assumptions: ignition probabilities, weather frequency distributions, and demographic data around the facility.

In practice, very few projects use Phast in isolation for long. Once a consequence model exists, the natural next question from management is almost always “so what is the actual risk to people,” and that question needs Safeti to answer properly.

From a learning standpoint, the jump from Phast to Safeti is less about new physics and more about new data management. Engineers already comfortable with Phast scenarios usually pick up Safeti’s risk module within a few weeks, provided they understand where frequency and population data actually come from.

How Consequence Modelling Fits Into a Typical QRA Workflow

 Engineers reviewing HAZOP scenarios feeding into a consequence modelling QRA workflow

A full QRA rarely starts with software at all. It starts with a hazard identification exercise, usually a HAZID or HAZOP, where the team lists realistic loss of containment scenarios for a facility, a process covered in depth in our Process & Technical Safety Study training. Only after that list exists does consequence modelling begin.

Each scenario from the hazard identification gets built into Phast or Safeti as a release case. Engineers define hole sizes, fluid properties, and operating conditions, then run the model to see dispersion distance, fire size, or explosion overpressure for that specific scenario.

From HAZID to Consequence Modelling to Risk Calculation

Once consequence results exist for every scenario, frequency data gets attached, usually drawn from historical failure rate databases or company-specific records. Safeti combines both data sets into individual and societal risk figures, which then get checked against company or regulatory risk criteria.

If a scenario exceeds acceptable risk, the project team revisits design options such as additional isolation valves, better detection systems, or increased separation distance, then reruns the model to confirm the change actually brings risk down to an acceptable level.

This loop between modelling and mitigation can run several times on a single project. A pipeline route, for instance, might need three or four iterations before the calculated individual risk along its length drops within the company’s acceptance criteria.

Common Mistakes Engineers Make With Consequence Modelling

Senior engineer correcting a common consequence modelling mistake with a junior engineer

New users tend to repeat the same handful of mistakes when they first start running consequence models, often without realizing it until a senior reviewer questions the output.

  • Using default weather data without checking if it matches the actual site location, which can significantly change dispersion distance
  • Ignoring release duration, treating every scenario as instantaneous when many leaks are actually time-varying
  • Skipping sensitivity checks, accepting the first model run instead of testing how results shift with different hole sizes or wind speeds
  • Confusing consequence severity with risk, assuming a large dispersion footprint automatically means high risk without checking frequency
  • Copying old scenario files from previous projects without updating fluid composition or operating pressure for the new facility
  • Overlooking population data accuracy, using outdated demographic figures around the facility instead of current site survey information

Most of these mistakes come from rushing the setup stage rather than any flaw in the software itself. Phast and Safeti are only as accurate as the input data engineers feed into them. A model built on assumed values instead of actual process conditions produces numbers that look precise but mean very little in a real audit, especially one referencing standards published by API.

Where Consequence Modelling Skills Take Your Career

Consequence modelling is not a niche skill confined to one industry. Anyone working in oil and gas, petrochemical, LNG, hydrogen, or ammonia handling eventually runs into a project that requires it, directly or while reviewing someone else’s report.

For engineers, this knowledge tends to open doors into specialist roles rather than general design positions. It also gives site engineers and process engineers a meaningful path into safety-focused careers without starting from zero. Engineers coming from an inspection or mechanical integrity background often find the transition smoother than expected, since they already understand failure modes and equipment limits before adding the modelling layer on top. Our Advanced QRA Masterclass with Phast & Safeti is built around exactly this transition, with hands-on scenario building from start to finish.

Roles That Use Phast and Safeti

  • Process safety engineer: runs consequence and risk studies as a core daily responsibility
  • HSE consultant: reviews QRA reports and advises clients on risk reduction measures
  • Facility siting specialist: uses consequence outputs to position equipment and buildings safely
  • Loss prevention engineer: applies consequence modelling to insurance and asset protection assessments
  • Regulatory and compliance engineer: interprets QRA results against safety case requirements

Conclusion

Consequence modelling is the starting point for almost every serious process safety decision, whether that decision involves flare sizing, building placement, or emergency response planning. Phast handles the consequence side on its own, while Safeti takes those same physical effects and turns them into the risk numbers that regulators, insurers, and management actually act on.

Neither tool is harder than the other to learn once the relationship between them is clear. The real skill lies in setting up scenarios correctly and reading what the output actually means for a specific facility. Even a basic working knowledge of how Phast and Safeti relate puts you ahead of most engineers who blur the line between consequence modelling and risk thinking.

For engineers building a career in process safety, understanding consequence modelling properly, before jumping into risk numbers, makes every later QRA discussion easier to follow and defend.

FAQs

What is consequence modelling in process safety?

Consequence modelling predicts the physical effects of a hazardous release, including dispersion distance, fire size, and explosion overpressure, without considering likelihood. It gives engineers a physical basis for facility siting, emergency planning, and risk assessment decisions.

What is the difference between Phast and Safeti?

PHAST models only the physical consequences of a release. Safeti uses the same consequence engine but adds frequency and population data to calculate actual risk figures like individual and societal risk.

Is Safeti the same as Phast?

No. Safeti incorporates Phast’s consequence engine internally, but adds risk calculation capability on top. Phast alone cannot produce risk figures; Safeti is needed whenever a project requires a full quantitative risk assessment.

Do engineers need to learn both Phast and Safeti?

Most process safety careers eventually require both. Phast is usually learned first since it covers consequence fundamentals, while Safeti becomes necessary once a role involves delivering full QRA reports to clients or regulators.

Which industries rely on consequence modelling software?

Oil and gas, petrochemical, LNG, hydrogen, ammonia, and chemical processing industries rely heavily on consequence modelling. Any facility handling flammable or toxic materials under pressure typically needs this analysis for safety compliance.

Can Phast be used on its own without Safeti?

Yes, Phast works independently for projects needing only consequence results, such as flare sizing, equipment spacing, or emergency response planning. Safeti becomes necessary only when frequency-based risk figures are specifically required.

What background do you need to start doing consequence modelling?

A process, chemical, or mechanical engineering background with basic fluid mechanics knowledge is enough to start. Most engineers build practical consequence modelling skills through dedicated QRA and process safety training programs.

How long does it take to learn Phast and Safeti?

Most engineers reach working competence in Phast within a few weeks of hands-on practice. Safeti’s risk calculations typically take a similar period to learn, especially through structured QRA training rather than self-study.

Are there alternatives to Phast and Safeti for consequence modelling?

Yes. ALOHA and EFFECTS are common alternatives, though Phast and Safeti remain the industry standard for oil, gas, and chemical QRA work because of their validated models and wide regulatory acceptance.