How BP Texas City Exposed the Cost of Measuring Safety by the Wrong Signals
The BP Texas City case shows why injury totals and completed programs can hide process-safety exposure when warning evidence never changes a decision.
Key takeaways
- 01Treat startup as a separate decision state because changing process conditions can defeat controls that appear adequate during steady operation.
- 02Separate personal-safety outcomes from process-safety exposure so low injury totals do not become false evidence that high-energy hazards are controlled.
- 03Route warning evidence to a named decision owner with a deadline, because awareness without authority does not change the physical risk.
- 04Investigate latent conditions, design choices, temporary arrangements, and management decisions instead of assigning the full explanation to the final operator action.
- 05Use Andreza Araujo safety leadership approach to connect high-consequence exposure with visible decisions, field verification, and accountable follow-up.
F5 case study for process-safety leaders, investigators, and plant executives
The BP Texas City disaster shows how a site can record safety activity while losing control of the decisions that matter most. On March 23, 2005, an explosion during the startup of an isomerization unit killed 15 people and injured 180, according to the U.S. Chemical Safety and Hazard Investigation Board. The decisive failure was not a missing slogan. It was a management system that allowed warning evidence, weak safeguards, and production pressure to remain disconnected.
The case still matters because many organizations have improved their dashboards without improving the decisions behind them. A plant can report training completion, inspection counts, and recordable injuries while a high-energy startup remains poorly controlled. That gap is where this case becomes useful for leaders who need to distinguish activity from protection.
Initial scenario: a routine startup carried abnormal exposure
The Texas City event occurred during the startup of an isomerization unit, a phase that required operators to manage changing process conditions while flammable hydrocarbons were present. The CSB final report describes a sequence in which the raffinate splitter tower was overfilled, pressure increased, and hydrocarbons were discharged from the blowdown stack. The resulting vapor cloud ignited near occupied trailers.
Startup was not a normal operating condition, even though the work had become familiar. That distinction is important. Familiar work often receives less challenge precisely because people have performed it many times, while the energy, temporary configuration, and interaction between safeguards may change from one startup to the next.
The investigation also found that the site had experienced previous process-safety incidents and warning signals. Those signals did not become a decision to redesign the startup boundary, remove occupied trailers from the hazard zone, or require stronger control of abnormal conditions. Information existed, but it did not travel to the authority that could change the exposure.
Decision: the wrong question stayed in charge
The central decision failure was not simply that an operator made a mistake. The deeper problem was that the organization treated process safety as a collection of programs rather than as a discipline for controlling high-consequence energy. The system asked whether procedures, training, and inspections existed, but it did not consistently ask whether the operating envelope remained safe during startup.
That distinction changes what leaders review. A low injury rate cannot demonstrate that a flare, relief system, isolation, alarm, or emergency shutdown will perform when demand arrives. The CSB concluded that organizational and safety deficiencies existed at multiple levels of BP, including weaknesses in process-safety leadership, safety culture, management of change, operating procedures, training, and mechanical integrity.
When leaders count activity instead of barrier performance, they create a false sense of control. The dashboard looks full, the meeting ends on time, and the unresolved exposure remains in the field. Andreza Araujo's Safety Culture: From Theory to Practice makes the same practical point from another direction. Culture is visible in the decisions leaders reinforce when operational pressure meets risk evidence.
Execution: how warning evidence became background noise
Several lessons from the case concern the execution layer. First, the physical layout placed occupied trailers close to a process area where a release could produce severe consequences. Second, the blowdown system allowed the discharge of flammable material to an open location. Third, the startup process depended on operators recognizing changing conditions while the system gave them weak protection when those conditions moved beyond expectation.
These conditions did not appear at the instant of ignition. They were built through design choices, operating assumptions, maintenance decisions, and management routines that made the exposure seem acceptable, even though each choice narrowed the margin available when startup conditions moved beyond the expected range. James Reason's work on organizational accidents is useful here because it separates active errors from latent conditions. The visible action happens at the front line, but the opportunity for harm is often created much earlier.
A serious investigation therefore has to ask where the organization allowed risk to accumulate. It should examine who approved the arrangement, which review challenged it, what evidence was available, how exceptions were tracked, and why earlier events failed to trigger a different decision. Without those questions, the investigation produces an individual explanation for an organizational exposure.
Measured result: the outcome was larger than the injury total
The immediate result was catastrophic. Fifteen people died, 180 were injured, the surrounding community was alarmed, and the CSB reported financial losses exceeding $1.5 billion. Those numbers describe consequence, but they do not fully describe the management failure.
| What the organization could count | What leaders needed to know | Why the difference matters |
|---|---|---|
| Training completion | Whether operators could recognize and control startup deviation | Attendance does not prove decision readiness under abnormal conditions |
| Inspection completion | Whether critical equipment and safeguards would perform on demand | A completed inspection can still miss degraded protection |
| Recordable injury rate | Whether high-energy process hazards were controlled | Personal injury data can remain low while catastrophic exposure grows |
| Open action closure | Whether the action changed the physical or decision environment | Closure is not the same as verified risk reduction |
The lesson is not that lagging indicators have no value. They help leaders see some outcomes. The problem appears when they are treated as evidence that the highest-consequence risks are under control. A serious-risk review must connect each critical exposure to a control, an owner, a verification method, and a decision boundary.
Generalizable lesson 1: separate personal safety from process safety
Personal-safety activity and process-safety protection overlap, but they are not interchangeable. A plant may improve hand safety, housekeeping, and training while leaving an overfill scenario, relief path, or occupied-building exposure unchanged.
Leaders should maintain two connected views. The first tracks injuries and everyday work conditions. The second tracks scenarios that could release enough energy to kill many people or disable a site. The second view needs engineering evidence, operating limits, safeguard status, and field verification, which ordinary injury dashboards cannot provide alone.
Generalizable lesson 2: treat startup as a decision state
Startup deserves its own control logic because equipment status, process conditions, staffing, alarms, and temporary arrangements may differ from steady-state operation. A startup authorization should identify the expected condition, the deviations that require a pause, the people who can stop the sequence, and the evidence required before proceeding.
The best test is practical. Ask a supervisor to explain what would make the team stop, which alarm or reading matters first, and who has authority to change the plan. If the answers depend on personal memory rather than a visible decision boundary, the startup is not ready for release.
Generalizable lesson 3: make warning evidence reach authority
Near misses, abnormal trends, repeated alarms, temporary repairs, and operator concerns only protect people when someone with authority can act on them. A warning log that ends in a local meeting is not an escalation system.
Each serious warning should therefore carry four pieces of information. The first identifies the exposure. The second states the evidence. The third names the decision owner. The fourth defines when the decision must be made. This structure prevents leaders from confusing awareness with control, which is a common failure in large operating systems.
Generalizable lesson 4: investigate the conditions that made failure possible
An investigation should reconstruct the operating picture before the event, not only the final sequence. Review staffing, workload, competence, equipment condition, temporary changes, maintenance history, supervision, contractor interfaces, and the signals that were available but not acted upon.
The Columbia Shuttle case and the Deepwater Horizon case show why warning evidence deserves its own reconstruction. In both cases, the question is not only what people knew. It is also how evidence was interpreted, which doubts were discounted, and which decisions allowed the work to continue.
What to apply in your operation
Plant leaders can translate the case into a 30-day review without copying the historical scenario. Start by selecting one high-consequence startup or abnormal operating condition. Map the credible release, identify the controls that must perform, and name the person who can stop the sequence.
During the second week, compare the approved safeguards with field conditions. Check the physical location of people, the status of alarms and shutdowns, the quality of procedures, and the evidence supervisors use before release. Record every mismatch as a decision problem rather than as a generic observation.
During the third week, review warnings from the previous twelve months. Look for repeated alarms, temporary repairs, late handoffs, production exceptions, and concerns that were closed without a physical change. Then ask the responsible executive which decision was made for each pattern and whether the evidence supports that decision.
During the final week, test the system with a short scenario exercise. Give supervisors a changing condition and ask what they would do, who they would contact, and what evidence would allow work to resume. The exercise is useful only when the answers lead to changes in design, staffing, procedures, authority, or verification.
Andreza Araujo's experience across more than 250 cultural transformation projects reinforces the value of this approach. Improvement becomes credible when the organization changes what leaders count as evidence, not merely when it adds another campaign or closes another action.
Conclusion: the metric must follow the consequence
The BP Texas City disaster remains a clear warning against measuring safety by the wrong signals. Injury totals, training records, and completed inspections can coexist with serious process exposure when leaders do not connect evidence to control performance and decision authority.
For senior leaders, the practical question is direct. Which high-consequence scenario could still defeat the current system, and what evidence would prove that the protection is working today? That question turns history into a management routine.
To deepen the work, read how more than 250 safety culture projects changed the definition of improvement and compare it with the division between board, executive, and field safety review. Andreza Araujo's Make The Difference: Be a Leader in Health & Safety offers a further guide for leaders who want daily decisions to reflect real exposure.
Frequently asked questions
What happened at the BP Texas City refinery?
Why did safety metrics fail to prevent the Texas City disaster?
How should a plant investigate warning signs before a serious incident?
What is the difference between personal safety and process safety?
How can leaders apply the BP Texas City lessons in 30 days?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.