Safety Leadership

How Longford Turned a Process Upset Into a Leadership Test

The Esso Longford gas-plant disaster began with a process upset and a catastrophic low-temperature failure, but the Royal Commission identified a wider leadership problem. This case study shows how hazard identification, engineering presence, alarm management, training, and management of change must work together before a high-consequence event.

By 5 min read
leadership scene showing how longford turned a process upset into a leadership test — How Longford Turned a Process Upset Int

Key takeaways

  1. 01The Longford event began with a process upset, but the serious exposure came from a chain of technical and management conditions.
  2. 02A hazard that is absent from the operating team's mental model is not controlled merely because equipment and procedures exist.
  3. 03Management of change must examine loss of engineering presence and competence, not only physical modifications to equipment.
  4. 04Alarm quantity does not equal warning quality when operators cannot distinguish the signal that requires immediate action.
  5. 05Leaders should test whether process-safety decisions remain visible when production is disrupted and the normal support structure is distant.

A process upset does not need to become a disaster. It becomes one when the organization has no reliable way to recognize the hazard, recover the process, escalate uncertainty, and isolate the energy before the situation outruns the response.

The Esso Longford gas-plant accident in Victoria, Australia, is a useful case because the visible event looked technical while the investigation exposed a leadership system that had lost important connections between engineering, operations, training, alarms, and organizational change. On September 25, 1998, the event killed two employees and injured eight, according to the Institution of Chemical Engineers incident summary.

Case anchor. The factual account is based on the Longford Royal Commission report published in June 1999 and the Institution of Chemical Engineers incident summary. The applications below translate that case into leadership checks for other high-hazard operations.

The initial scenario was a process upset that changed the equipment state

The plant was taken offline after a major upset. During the following restart, the rich-oil deethaniser reboiler became intensely cold, and warm lean oil was later reintroduced. The resulting thermal condition contributed to a catastrophic failure of the reboiler channel end.

The Institution of Chemical Engineers summary records that more than 10 tonnes of hydrocarbon vapour were released, the vapour cloud travelled approximately 170 metres to fired heaters, and the resulting fire continued for more than two days. Those figures matter because they show how quickly a local process condition can become a site-wide emergency when isolation and recovery barriers are weak.

The technical failure exposed a missing hazard in the operating model

The low-temperature hazard was not adequately identified before the event. That gap matters more than the final fracture because a risk assessment can only control hazards that the organization has recognized and represented accurately.

James Reason's work on latent failures helps explain the leadership implication. The operator may be acting inside a system whose procedures, training, alarms, and engineering support have already narrowed the available safe choices. A review that stops at the final action misses the conditions that made the action appear reasonable.

Hazard identification failed before the procedure failed

When a hazard is absent from the operating team's mental model, a procedure can be technically complete and still provide little protection. The Longford analysis identified incomplete operating procedures because the relevant abnormal condition had not been adequately recognized.

Leaders should therefore ask a harder question than whether procedures are current. They should ask which process states have been tested, which low-probability conditions could produce high consequences, and whether operators have practiced the recovery decisions that follow from those conditions.

Management of change included people, not only equipment

The incident analysis identified the relocation of senior engineering staff to Melbourne as an organizational change that did not receive an adequate management-of-change review. No pipe had to move for the safety system to change. The expertise available during an upset, the speed of technical escalation, and the quality of local supervision had already been altered.

This is a common blind spot. Many management-of-change processes focus on modifications, chemicals, software, or production rates while treating staffing and decision access as administrative matters. A safety leader should review changes in competence, authority, contractor reliance, and engineering presence with the same seriousness applied to physical changes.

Alarm volume did not create alarm quality

The Longford incident analysis identified inadequate alarm management, including too many alarms and poor prioritisation. An alarm system can therefore be active while the operator is functionally unsupported, because the signal that matters is buried in a stream that does not distinguish urgency.

The leadership test is practical. During an abnormal-condition exercise, can the operator identify the first alarm that changes the decision? Can the supervisor explain which alarm requires shutdown, isolation, evacuation, or technical escalation? If the answer depends on personal memory rather than a tested design, the alarm system is not carrying the control burden assigned to it.

Training could not replace missing abnormal-operation competence

The incident summary identified inadequate training for abnormal operations and upsets. That finding does not mean more classroom hours would have solved the case. Training is effective only when it gives people the knowledge, practice, authority, and equipment needed to perform the required recovery action.

A useful training review follows the event backward. What condition should the operator have recognized? What response was possible? What information was available? Who could authorize a stop? Which physical barrier could have limited the release? The answers reveal whether the gap belongs to competence, design, staffing, or leadership governance.

The measured result was a new expectation for major-hazard governance

The Longford Royal Commission created a public record that connected the fire to more than equipment. The incident contributed to stronger major-hazard regulation in Victoria, including the Occupational Health and Safety Major Hazard Facilities Regulations 2000 and a safety-case expectation for covered facilities, as summarized by the Institution of Chemical Engineers.

The useful before-and-after comparison is not the number of recommendations issued. It is whether the organization changed how it recognizes major hazards, manages competence, controls abnormal conditions, prioritizes alarms, and verifies that safeguards remain available.

Before the leadership testAfter the leadership test
Process upset is treated as a local operating problemUpset recovery has explicit escalation and isolation thresholds
Management of change focuses on physical modificationsStaffing, competence, authority, and engineering access are reviewed too
Alarm quantity is used as evidence of protectionAlarm priority is tested against the decision the operator must make
Training completion closes the competence discussionAbnormal-operation performance is observed and verified in the field

What plant leaders should apply before the next upset

Choose one process upset that could change temperature, pressure, flow, inventory, or isolation status faster than the normal operating routine can respond. Map the first ten minutes of the expected recovery. Identify the critical hazard, the first decision, the person who owns it, the signal that should trigger it, and the barrier that limits the consequence.

Then remove one assumed support. Make the engineering contact unavailable, introduce an unfamiliar alarm sequence, or delay a handover. The goal is not theatrical stress. It is to discover whether the safe response depends on a person, a document, or a communication path that the organization has never tested under degraded conditions.

What supervisors should verify at the point of work

Supervisors can turn the Longford case into a short field conversation. Ask what has changed since the last stable run, which abnormal condition would make the current procedure invalid, and who can authorize isolation when the evidence is incomplete.

When workers raise an unusual temperature, sound, alarm pattern, or process response, the supervisor should record the decision and escalate according to a known threshold. A concern that disappears into a log has been documented, not controlled.

Andreza Araujo's safety-leadership perspective places this gap between declared commitment and operating evidence at the center of transformation work. Leaders build credibility when they protect the time, competence, and authority required to act on weak signals before the process becomes unrecoverable.

Conclusion: treat organizational distance as a process hazard

Longford remains relevant because the event did not depend on one dramatic act of disregard. It emerged from a process condition that the operating system did not recognize well enough, supported by gaps in procedures, abnormal-operation training, alarm prioritisation, engineering presence, management of change, and process-safety governance.

That pattern gives safety leaders a concrete test. When the process leaves its normal state, can the people closest to it identify the hazard, reach competent support, make the stop decision, and isolate the energy before the consequence expands? If not, the leadership system is already part of the exposure.

Headline Podcast examines the decisions behind safer work. Explore Headline Podcast for more practical analysis of safety leadership and incident investigation.

Topics safety-leadership process-safety management-of-change hazard-identification incident-investigation

Frequently asked questions

What happened at the Longford gas plant?
On September 25, 1998, an upset at the Esso gas-processing plant in Longford, Victoria, was followed by a catastrophic failure of a deethaniser reboiler. The resulting hydrocarbon release ignited, killing two employees and injuring eight, according to the Institution of Chemical Engineers incident summary.
What did the Longford investigation identify beyond the equipment failure?
The incident analysis identified inadequate hazard identification, incomplete operating procedures, insufficient training for abnormal conditions, poorly prioritised alarms, a missing management-of-change review, and an incompletely implemented safety-management system.
Why is Longford relevant to safety leadership?
The case shows that leaders shape process safety through engineering support, staffing, review thresholds, training, alarm priorities, and resource decisions. These conditions determine whether a local upset remains manageable or becomes a major release.
What does management of change have to do with the incident?
The incident summary identifies the relocation of senior engineering staff to Melbourne as an organisational change that did not receive an adequate management-of-change review. The lesson is that changes in competence and decision access can alter risk even when equipment remains untouched.
How can a plant apply the Longford lesson?
A plant can select one high-hazard process upset, identify the assumptions required for safe recovery, and verify who owns the engineering decision, which alarm matters, what training is current, and when work must stop. The exercise should produce field evidence, not only a revised document.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI