Feyzin, 1966: When a Routine Drain Created a Major Hazard
On January 4, 1966, an attempt to drain water from a propane storage sphere at the Feyzin refinery became a major fire. The UK Health and Safety Executive's case study shows how a familiar task, an unexpected restriction, and a vulnerable storage arrangement combined before the release ignited. This F5 case study turns the event into a practical review of routine operations that carry major-hazard potential.

Key takeaways
- 01A routine task can carry major-hazard potential when the material, inventory, and failure consequence are severe.
- 02The Feyzin event developed through a sequence of small operating decisions, not one dramatic departure from the procedure.
- 03Drain and sampling tasks need explicit isolation, flow expectations, abnormal-condition limits, and stop criteria.
- 04Emergency readiness must be designed around escalation, equipment exposure, and the time available after a release.
- 05Leaders should inspect ordinary tasks that involve high-energy or flammable inventories because familiarity can hide consequence.
Routine work can be more dangerous than unusual work when familiarity hides the consequence of a wrong assumption. On January 4, 1966, an operation to drain an aqueous layer from a propane storage sphere at the Feyzin refinery became a major fire. The UK Health and Safety Executive records the event as a defining process-safety case.
The task did not begin as an obvious emergency. Operators opened two valves in series at the bottom of the sphere. When the operation was nearly complete, the upper valve was closed and then opened slightly again because no flow appeared. That small decision changed the condition of the task. A restriction had formed, the expected signal was absent, and the response was to open the valve further.
Feyzin's central lesson is that routine operations need explicit stop criteria when the inventory is hazardous, because an absent signal can indicate a developing restriction rather than permission to continue.
Why a familiar drain became a major-hazard task
Draining water from a storage vessel sounds simple when the liquid is treated as the only thing that matters. The vessel, however, contained propane under pressure. The operator was working at the interface between a small quantity of water and a large flammable inventory whose release could produce a vapor cloud, fire, and escalating equipment damage.
The task therefore needed to be designed around the whole system. What happens if the drain freezes, plugs, flashes, or stops flowing? What tells the operator that the line is clear? Which valve isolates the inventory? How quickly can the area be evacuated if propane escapes? A procedure that answers only the normal sequence leaves the abnormal sequence to improvisation.
That is the first leadership test. The effort required to write a procedure should reflect the consequence of failure, not the number of times the task has been performed without an incident.
How the missing flow changed the decision
The absence of flow was an important signal, although it was not given a safe meaning. When the upper valve was cracked open and no flow emerged, the operator opened it further. That response was understandable if the assumption was that the line simply needed more opening. It became dangerous if the restriction indicated a different condition in the drain path.
Operators need an explicit response for missing, delayed, or unexpected information. A valve that does not produce the expected flow should trigger a pause, communication, and verification before the opening is increased. The procedure must explain which observations require a stop, because people under pressure will otherwise interpret silence as a reason to continue.
James Reason's work on active and latent failures helps explain why the final valve movement is not a sufficient cause. The action occurred within a system of design choices, equipment arrangements, procedural assumptions, training, supervision, and emergency barriers. Removing the last action from that context removes the opportunity to repair the conditions that made it seem reasonable.
What leaders should verify in routine operating procedures
A strong procedure makes the hazardous state visible before the task begins. It identifies the material, pressure, temperature, isolation points, expected flow, protective equipment, communication route, and emergency boundary. It also gives the operator a clear rule for stopping when the field does not match the expected sequence.
Review the procedure at the point of work. Ask the person performing it to demonstrate where the isolation exists, what evidence confirms that the correct line is open, and what condition would require immediate evacuation. If the answer depends on a diagram in an office or on a person who is not present, the procedure is not field-ready.
Use the hierarchy of controls review to test whether the task relies too heavily on attention and response. The best design reduces the chance of release, limits the inventory that can escape, and makes the wrong path difficult to select.
Why emergency response cannot be an afterthought
Once a flammable release begins, the time available for correction can shrink rapidly. Emergency planning must therefore address the first indication, the first isolation action, the first communication, and the point at which people stop trying to control the task and move to a safe location.
The Feyzin case is useful because it connects the operating task to the surrounding equipment and response capability. A storage sphere is not an isolated object. A fire near one vessel can expose adjacent vessels, pipework, access routes, and people who are not involved in the original task.
Leaders should run a short field exercise around one drain or sampling operation. Start with the loss of expected flow, then test who calls the control room, who closes the isolation, who stops nearby work, who sounds the alarm, and who confirms that the area is clear. The purpose is not to stage a theatrical drill. It is to find the seconds in which responsibility is uncertain.
How familiarity creates blind spots
Frequent tasks can acquire informal shortcuts. The operator learns how far to open a valve, which sound means the line is clear, and how long to wait before trying again. Those habits may be useful knowledge, yet they can also bypass the written control and disappear when a new person takes the shift.
Andreza Araujo's The Illusion of Compliance offers a practical test for this problem. A process is not reliable because the form is complete. It is reliable when the control still works under pressure, uncertainty, turnover, and inconvenient evidence. A familiar task that depends on local memory is vulnerable even when its incident history looks clean.
Look for tasks that are described as simple, standard, or always done this way. Those phrases should prompt a consequence review rather than reassurance. Ask what would happen if the material were released, the isolation failed, the communication channel was unavailable, or the person with the most experience were not present.
What an incident investigator should reconstruct
An investigation should map the event as a sequence of decisions and changing conditions. Record the expected flow, the actual flow, the valve movements, the warnings, the communication, the equipment state, and the decisions made after each unexpected observation.
Then examine the design assumptions. Was the water drain treated as a low-risk task because the quantity of water was small? Was the propane inventory visible in the procedure? Did the isolation arrangement make the hazardous state clear? Were operators trained to stop when the expected signal was missing? Did emergency responders know the likely escalation path?
Compare the decision-ready evidence chain with the incident evidence-status guide. The goal is to separate observed facts from assumptions and to show where a warning became a decision, a delay, or an unowned question, especially when the original task looked ordinary enough to discourage escalation.
Recommendation: audit the ordinary tasks first
Start with routine drains, vents, samples, purges, and line breaks that involve hazardous inventories, then test whether the procedure makes abnormal conditions and stop criteria unmistakable.
Choose one task and observe it without announcing the answer in advance. Ask the operator what should happen, what would be abnormal, and who can stop the work. Inspect the isolation, the line identification, the communication, the emergency route, and the condition of the equipment. If any answer depends on a private habit, repair the system before the next shift.
Feyzin remains relevant because major incidents often begin inside work that feels ordinary. The leader's job is not to make every task dramatic. It is to make the consequence visible early enough that people can pause, verify, and choose a safer path before the inventory chooses for them.
For a broader control review, compare the safety governance model with this case. Both ask the same question, which is whether technical design, operating discipline, decision ownership, and emergency readiness remain connected when the work stops behaving normally.
Frequently asked questions
What happened at Feyzin in 1966?
Why is Feyzin important for safety leaders?
What should a drain operation procedure include?
How can leaders find similar risks?
What is the main lesson from the Feyzin case?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.