Stepin Engineering

Blog

How to Conduct a QRA Study: Step-by-Step Guide for Process Safety Engineers

August 19, 2026

Ask five process safety engineers how a QRA study is done, and you’ll hear five different starting points. One launches straight into fault trees. Another talks your ear off about PHAST and dispersion contours. Someone else insists nothing happens until the HAZOP is finished. None of them are wrong; they’re each describing one link in a longer chain. A QRA study isn’t a single calculation you run and export. It’s a sequence, and a weak link anywhere in that sequence makes everything built on top of it wobble.

This piece is for anyone trying to understand that full sequence, whether you’re new to process safety, prepping for interviews, or tired of definitions that never explain how the work actually gets done.

So What Actually Is a QRA Study?

Strip away the jargon, and a QRA study is an attempt to put numbers on danger. A regular HAZOP tells you a scenario is “high” or “medium” risk based on a matrix. A QRA study goes further asking how often something could happen and how bad it would be, then combining both into something measurable.

The end products are usually two families of numbers: Individual Risk – roughly, “what’s the chance this specific person here gets killed this year?” and Societal Risk, shown as an FN curve, which captures the chances of an incident hurting a group rather than one person.

Regulators favour these numbers because they’re comparable; you can put two design options side by side and argue which is safer, instead of just trading opinions.

9-step QRA study process from scope definition to hazard identification, frequency and consequence modelling, ALARP evaluation, and final reporting.

Step 1 – Define Scope & Objectives 

This sounds obvious, which is exactly why it gets rushed. Before anyone opens a modelling tool, the team needs to agree on what’s in scope, why the study is being commissioned (a land-use submission looks different from a management-of-change review), which risk metrics apply, and where the boundaries sit. Skip this, and you don’t just lose time later; you end up with a technically correct QRA study answering a question nobody asked.

Step 2 – Data Collection & Documentation Review  

This stage often eats more time than the actual math. You’ll need P&IDs, process design data (pressures, temperatures, inventories), plot plans, equipment specs, site weather data, and population or occupancy figures for anyone nearby.

Older facilities are the worst offenders. Drawings get revised on paper, changes happen in the field, and the “as-built” reality drifts from whatever’s in the document control system. Chasing down current, accurate data is unglamorous, but a QRA study built on outdated drawings is basically fiction with good formatting.

Step 3 – Hazard Identification 

Now hazard identification kicks in, usually pulled from an existing HAZID or HAZOP. Working through the P&IDs, the team notes down plausible ways containment could be lost: leaks, pipe ruptures, pressure build-up beyond design limits, and situations where trouble in one unit spreads to the equipment sitting next to it (what’s often called a domino effect). This step is deliberately over-inclusive; it is better to carry a negligible scenario than quietly drop one that matters.

Step 4 – Frequency Analysis 

This is frequency analysis, where historical failure data earns its keep. Engineers draw on databases like OREDA, IOGP, or HSE’s FRED, build fault trees for engineered systems, and use event trees to map how a release could branch depending on ignition, weather, or time of day.

A common technique is the “parts count” method, counting valves, flanges, and fittings in an isolated section, then applying published leak-frequency figures to estimate how often a release of a given size might occur. Tedious, but it works.

Step 5 – Consequence Modelling 

This is what most people picture when they hear “QRA” consequence modelling estimates the physical effects of a release, how far a toxic cloud travels before diluting to a safe concentration, how hot a jet fire burns at a given distance, and what overpressure an explosion generates.

Tools like PHAST and SAFETI do the heavy lifting, running dispersion, fire, and explosion calculations across different weather conditions and release sizes, producing hazard distances or effect zones for every scenario flagged in Step 3.

Step 6 – Risk Calculation (IRPA & Societal Risk) 

Now the two threads come together. Frequency numbers from Step 4 combine with consequence outputs from Step 5 to produce the headline results of any QRA study:

  • Individual Risk per Annum (IRPA) – usually shown as risk contours drawn around the facility, indicating fatality probability at each location
  • Societal Risk, presented as an FN curve – cumulative frequency plotted against number of potential fatalities, capturing risk to groups rather than a single point

These get calculated scenario by scenario and then rolled up, so the final picture reflects the combined effect of everything credible, not just whatever the worst single case happens to be.

Step 7 – ALARP Evaluation 

A risk number by itself doesn’t mean much until you compare it to a benchmark. That’s where ALARP – As Low As Reasonably Practicable – comes into play. Calculated risk gets plotted against regulatory or internal company criteria and lands in one of three zones: broadly acceptable, tolerable-if-ALARP, or intolerable. The UK Health and Safety Executive has a genuinely useful explainer on the ALARP principle that a lot of national frameworks borrow from.

One thing worth remembering: acceptance criteria aren’t universal. A QRA study built around UK thresholds can’t just be copy-pasted for a project in another country without checking what that regulator actually accepts.

Step 8 – Risk Reduction Measures 

Wherever results land in the ALARP or intolerable zone, the study proposes something concrete: better detection systems, revised equipment spacing, upgraded relief capacity, or moving an occupied building further away. Good practice weighs each option’s risk-reduction benefit against its cost.

Step 9 – Documentation & Reporting

The most neglected step: the report. A QRA study is only as useful as its ability to be checked, so assumptions, data sources, and methodology need documenting clearly enough that another engineer, years later, could retrace how you got from raw data to final contours, especially when the study feeds a regulatory safety case.

A Few Mistakes That Keep Showing Up

Across different industries and different teams, the same handful of errors tend to repeat:

  • Treating generic failure-rate data like it’s precise, when it often carries order-of-magnitude uncertainty
  • Forgetting domino effects between units that sit right next to each other
  • Running the analysis on one weather condition instead of the full weather matrix a regulator expects
  • Using population data that’s years out of date, especially near sites with new residential development nearby
  • Treating the whole exercise as a one-time deliverable instead of revisiting it after a major modification

Conclusion

A QRA study isn’t really about one clever piece of software or one impressive chart. It’s disciplined, sequential work scoping properly, gathering data nobody wants to chase, identifying hazards without cutting corners, running the numbers, and writing it up so someone else can trust it. Engineers who understand the whole chain, not just the modelling step, tend to produce studies that hold up when someone pushes back.

If you’d rather learn this by doing it than by reading about it, our Advanced QRA Masterclass with PHAST & Safeti at Stepin Engineering takes you through this exact workflow: hazard identification, frequency and consequence modelling, and risk calculation using the same industry-standard software referenced throughout this guide, applied to real scenarios rather than textbook ones.

Frequently Asked Questions

How long does a QRA study usually take to complete?

Depends on facility complexity and data quality. A tightly scoped single-unit study might wrap up in a few weeks; a full-facility QRA Feeding a safety case can stretch several months, especially if hazard identification starts from a blank page.

What software do engineers actually use for a QRA study?

PHAST and SAFETI are the most common names for consequence modelling, paired with risk-integration tools that combine those outputs with frequency data to generate individual and societal risk results. The exact toolset usually comes down to company standards and local regulatory expectations.

Isn’t a QRA study basically the same thing as a HAZOP?

Not quite. A HAZOP is qualitative; it flags what could go wrong in general terms. A QRA study builds on HAZOP or HAZID output but pushes into actual numbers: frequency, consequence, individual risk, FN curves. Think of HAZOP as the input and QRA as what you build from it.

Why does ALARP matter so much in a QRA study?

Because risk numbers alone don’t tell you whether to act. ALARP is the yardstick comparing calculated risk against broadly acceptable, tolerable, or intolerable thresholds and whether further risk reduction is justified given its cost.

Who actually needs a QRA study done?

Mostly facilities handling hazardous inventories, oil and gas installations, chemical plants, LNG terminals, and pipelines. It’s typically triggered by a safety case submission, land-use planning application, or facility siting review, particularly where frameworks like COMAH apply.

Can you do a QRA study without specialised software?

For a very small, simple scenario, technically yes, using spreadsheets and published failure data. Once you’re modelling dispersion, thermal radiation, or explosion overpressure across multiple scenarios and weather conditions, manual calculation stops being practical.