Valid

NB/Z 20598-2021Guide for the nuclear power plant control room human factors engineering integrated system validation (English PDF)

核电厂控制室人因工程集成系统确认指南

Open the NB/Z 20598-2021 preview as PDF

Preview — first pages of NB/Z 20598-2021 (full document: 26 pages)

This is a limited preview

Buy now to download the full PDF (26 pages)

Issued by

NEA

Level / Type

Industry · Recommended

Issue date

January 7, 2021

Implementation date

July 1, 2021

Scope

NB/Z 20598-2021 is the English-translated version of 核电厂控制室人因工程集成系统确认指南.

NB/Z 20598-2021 is the Chinese guiding technical document for integrated system validation of human factors engineering in a nuclear power plant control room. It exists because verification and validation answer two different questions, and only one of them can be answered by inspection. Verification checks each element of the control room against its criteria - is this display legible, is that control reachable, does the alarm meet the guideline - and a well built control room can pass every one of those checks and still fail the operator. Validation is the step that puts the whole thing together: real licensed operators, the real procedures and the complete human-system interface, working a demanding scenario in real time on a full-scope simulator, to see whether the crew actually keeps the plant safe. That distinction is the lesson the industry took from accidents where the equipment behaved as designed and the control room still did not tell the crew what was happening. This document sets out how that test is run: how the validation team is put together and why it has to stay independent of the designers, how faithful the simulator has to be in physical form, function, data content and dynamic response, who may sit in the operator seats - licensed operators of that plant, not hand picked high performers and not anyone who worked on the design or on an earlier assessment - which plant conditions have to be sampled, from normal start-up and refuelling through faults and design basis accidents to design extension conditions such as station blackout, and how the resulting data is turned into a defensible conclusion. Being an NB/Z document it guides rather than obliges, but it is the text a Chinese reviewer works from when assessing the human factors engineering file for a control room. It was issued on 7 January 2021 by the National Energy Administration and took effect on 1 July 2021.

Document preview — NB/Z 20598-2021

National Standard of the People's Republic of China

ICS
27.120.20
Classification
F 65

Issued by: National Energy Administration of the PRC

Contents

  • Foreword3
  • 1 Scope1
  • 2 Normative references1
  • 3 Terms, definitions and abbreviations1
  • 4 General principles1
  • 5 Integrated system validation2
  • Annex A (Informative) Methodology study12

Foreword

This document was issued on 7 January 2021 by the National Energy Administration of the PRC and takes effect on 1 July 2021.

It is a NB/Z guiding technical document: it does not oblige, it guides.

It is classified under ICS 27.120.20, Chinese classification F 65.

This document was drafted in accordance with the rules given in GB/T 1.1-2020 Directives for standardization - Part 1: Rules for the structure and drafting of standardizing documents.

This document was proposed by the Nuclear Power Standardization Technical Committee of the Energy Industry.

This document is under the administration of the Nuclear Industry Standardization Research Institute.

Drafting organizations of this document: China Nuclear Power Engineering Co., Ltd.; Hualong International Nuclear Power Technology Co., Ltd.; Shanghai Nuclear Engineering Research and Design Institute Co., Ltd.; CGN Engineering Co., Ltd.

Main drafters of this document: Deng Shiguang, Yu Guangwei, Wang Yanjun, Duan Pengfei, Xu Yunlong, Hou Changzhi, Jiang Xingwei, Tian Hui, Wang Qiuyu, Jia Ming, Yu Zhoujun.

1 Scope

NB/Z 20598-2021 is the Chinese guiding technical document for integrated system validation of human factors engineering in a nuclear power plant control room. It exists because verification and validation answer two different questions, and only one of them can be answered by inspection. Verification checks each element of the control room against its criteria - is this display legible, is that control reachable, does the alarm meet the guideline - and a well built control room can pass every one of those checks and still fail the operator. Validation is the step that puts the whole thing together: real licensed operators, the real procedures and the complete human-system interface, working a demanding scenario in real time on a full-scope simulator, to see whether the crew actually keeps the plant safe. That distinction is the lesson the industry took from accidents where the equipment behaved as designed and the control room still did not tell the crew what was happening. This document sets out how that test is run: how the validation team is put together and why it has to stay independent of the designers, how faithful the simulator has to be in physical form, function, data content and dynamic response, who may sit in the operator seats - licensed operators of that plant, not hand picked high performers and not anyone who worked on the design or on an earlier assessment - which plant conditions have to be sampled, from normal start-up and refuelling through faults and design basis accidents to design extension conditions such as station blackout, and how the resulting data is turned into a defensible conclusion. Being an NB/Z document it guides rather than obliges, but it is the text a Chinese reviewer works from when assessing the human factors engineering file for a control room. It was issued on 7 January 2021 by the National Energy Administration and took effect on 1 July 2021.

This document specifies the requirements for every aspect of carrying out integrated system validation of human factors engineering for nuclear power plant control rooms, including the composition of the validation team, the test objective requirements, the test platform requirements, the requirements on the test participants, the selection of operating conditions, performance measurement, test design and personnel training, data analysis, and the validation conclusion.

This document applies to the guidance of integrated system validation activities for human factors engineering of nuclear power plant control rooms.

2 Normative references

The following document contains provisions which, through normative reference in this text, constitute indispensable provisions of this document. For dated references, only the edition corresponding to that date applies to this document. For undated references, the latest edition (including all amendments) applies to this document.

GB/T 13630-2015 Design of nuclear power plant control rooms

3 Terms, definitions and abbreviations

3.1 Terms and definitions

The following terms and definitions apply to this document.

3.1.1 human factors verification

The process of determining whether each component satisfies the specified requirements, that is, a series of analytical examinations of the human-machine interfaces - measuring instruments, controllers, displays and other equipment - carried out against the specified technical specifications, the human factors engineering criteria, and the operating and functional objectives.

3.1.2 human factors validation

The tests carried out to ensure that the integrated whole formed by the personnel, the procedures and the human-system interfaces within the control room system is able to guarantee the safe and reliable operation of the plant.

3.1.3 simulator

A physical human-system interface facility that represents the configuration of the actual nuclear power plant control room and is able to reproduce dynamically the operating characteristics and the real-time response of the plant.

3.2 Abbreviations

The following abbreviations apply to this document.

HSI: Human System Interface

PSA: Probabilistic Safety Assessment

SPDS: Safety Parameter Display System

4 General principles

Clause 8.3.1 of GB/T 13630-2015 states that the control room system as an integrated whole shall be validated in order to demonstrate that it can achieve the intended performance, and that particular attention shall be paid to the time-dependent dynamic characteristics of the integrated control room system.

Integrated system validation of human factors engineering in a nuclear power plant is an essential part of human factors verification and validation. It examines the human factors engineering design of the control room system as a whole and supports an effective assessment of the HSI design, of training and of procedure development, so that the nuclear power plant can be operated safely and effectively.

Integrated system validation activities shall be organised and planned in advance, the test activities shall be carried out in accordance with the established test procedure, and the validation conclusion shall finally be reached through analysis of the test data. The following principles shall be given full consideration in the course of the activity:

a) the validation team shall be made up of personnel from several disciplines and/or specialities, and shall remain independent of the design personnel concerned;

b) the test platform shall be highly consistent with the real unit;

c) the test participants shall be licensed operators of the plant concerned; the staffing of the test participants shall be consistent with the actual staffing of the unit control room; and the sample of participants shall be large enough to represent the overall level of the plant;

d) the operating conditions selected shall be representative;

e) a detailed test procedure shall be prepared, and both the test participants and the test execution personnel shall receive the corresponding training;

f) in order to ensure the quality of the test, a pre-test shall be carried out before the formal test activity;

g) all problems found during the whole activity shall be recorded, tracked and resolved;

h) the analysis of the validation test data shall combine qualitative and quantitative methods; the relationship between the observed performance data and the existing performance criteria shall be clear and shall be supported by the results of the data analysis;

i) the validation conclusion shall rest on a clear basis of data and logic.

5 Integrated system validation

5.1 Team composition

The validation team shall be made up of personnel from several disciplines (specialities), assembled according to the professional characteristics of the validation work, and the qualification requirements for the personnel shall be clearly stated. Personnel from the relevant specialities shall jointly take part in the test design, the development of the test procedure, the performance measurement and the data analysis.

The members of the validation team shall maintain a degree of independence from the design personnel concerned, so as to guarantee the objectivity and impartiality of the assessment. Independence also helps to prevent expectation bias on the part of the test personnel, a bias that would affect the validity of the test. Before conducting the system test, the independent validation team shall understand the assumptions and constraints of the design stage, and shall avoid problems arising during the test from exceeding those assumptions and constraints.

The validation team shall be able to consult all documents relating to human factors engineering and to have access to all members of the human factors engineering team.

The post responsibilities within the team and the corresponding disciplines (specialities) are given in Table 1.

Table 1 - Post responsibilities and corresponding specialities

Test design personnel, human factors engineering: responsible for the test design of the integrated system validation activity and for preparing the related documents.

Test design personnel, personnel training: take part in the pre-test of the integrated system validation activity and in scenario management and coordination during the test activity.

Test design personnel, plant operation: take part in the scenario design of the integrated system validation activity.

Test design personnel, instrumentation and control: provide technical support on the I&C system and on the HSI design during the integrated system validation activity.

Test execution personnel, human factors engineering: responsible for the conduct of the integrated system validation activity, for the analysis and for the writing of the report.

Test execution personnel, personnel training: take part in scenario management and coordination during the integrated system validation test activity.

Test execution personnel, instrumentation and control: provide technical support on the I&C system and on the HSI design during the integrated system validation activity.

Test participants, licensed operators: complete the test in accordance with the test design requirements.

Simulator personnel, simulator operation and maintenance: set up and operate the simulator in accordance with the test design requirements.

5.2 Test objectives

The overall objective of the test is to demonstrate that the integrated system can adequately support the safe and effective operation of the plant. To achieve this objective, the validation test shall cover the whole test scope bearing on that objective. The specific test objectives shall be determined by a systematic method that takes account of the actual situation and of the performance measurement criteria.

The following factors shall be considered during the validation process:

a) confirm the job responsibilities of the plant personnel taking part in the test;

b) confirm the staffing of the operating shift, the allocation of tasks among personnel and the effectiveness of coordination between personnel, both within the control room and between the control room, the local control stations and the support centre. The scope of validation shall include the staffing of the unit operating shift, the minimum operating shift staffing, and the staffing at shift handover;

c) confirm that, under normal operating conditions, anticipated operational occurrences, design basis accidents and the important human action events of design extension conditions, the personnel tasks can be carried out successfully and the HSI provides adequate alarms, information, control and feedback;

d) confirm that the unit personnel are able to complete their work tasks within the time and performance criteria while maintaining a high level of situation awareness and a reasonable workload; and confirm that the HSI design is able to reduce the probability of human error, or is capable of quickly detecting an error after it occurs and restoring the unit to a normal state;

e) confirm that the characteristics of the HSI meet the functional requirements, including the large screen, the alarm system, the safety parameter display system (SPDS), the computerised information monitoring and control facilities, the mimic panel monitoring facilities, the procedures and the communication system;

f) confirm that the unit personnel can switch effectively between different HSIs while performing tasks, and that the tasks related to HSI management, such as display configuration and navigation, do not significantly increase the operator's burden or distract the operator's attention;

g) confirm that the integrated system can operate effectively when the HSI failures considered in the design basis occur;

h) identify the factors that have a negative effect on the performance of the integrated system, including staffing, communication and training.

On the basis of the overall objectives above, the detailed objectives of each test shall be determined according to the design characteristics.

5.3 Test platform

5.3.1 Main control room

The main control room test platform, that is the simulator, shall satisfy the following requirements:

a) HSI completeness: the HSI on the test platform shall include all the HSI of the main control room; HSI not used in the test scenarios shall also be included in the test platform;

b) HSI physical fidelity: the physical form of the HSI on the test platform shall be highly consistent with that of the actual unit, including alarms, display interfaces, controls, auxiliary support functions, procedures, communication, interface management tools, layout and spatial relationships;

c) HSI functional fidelity: the functions of the HSI on the test platform shall be highly consistent with those of the actual unit, and all functions of the HSI shall be available. HSI functional fidelity includes the operation of HSI components, changes in the operating mode of components (for example, the operating mode of a component may change on the basis of the operator's selection and/or of a change in plant conditions), the type of feedback provided and the dynamic response characteristics, such as the time needed for data processing when refreshing a display or updating a parameter value;

d) fidelity of data completeness: the HSI on the test platform shall be able to present in full the information and data monitored in the main control room of the actual unit;

e) fidelity of data content: the data content of the test platform shall be highly consistent with that of the actual unit. The information and control data in the HSI of the test platform shall be based on an underlying model that accurately reflects the actual unit, and the input that this model provides to the HSI of the test platform shall be the same as the information in the actual main control room;

f) fidelity of data dynamics: the dynamic characteristics of the data on the test platform shall be highly consistent with those of the actual unit. The process model provides the input to the HSI of the test platform, and that input shall ensure that the information flow and the control response are accurate and consistent with the response time in the actual control room. In general, the HSI of the test platform shall have the same response time as the actual main control room; for example, the information delay experienced by the operator on the test platform HSI shall be consistent with that of the actual plant;

g) fidelity of the main control room environment: the main control room environment of the test platform shall be highly consistent with that of the actual unit. The lighting and noise characteristics of the main control room of the test platform should be the same as those of the actual main control room.

5.3.2 Monitoring and control facilities outside the main control room

For important activities outside the main control room that rely on a complex HSI and require timely and accurate human action, the use of a simulation or of a physical mock-up should be considered in order to validate human performance. For secondary actions, or where the HSI is not complex, human performance may be assessed by analysis.

When a simulation or a physical mock-up is used, the important characteristics of the task-related HSI and of the task environment, such as lighting, noise, heating, ventilation and air conditioning, and protective clothing and equipment, shall be taken into account.

5.3.3 Test platform verification

Before the validation test activity is performed, the conformity of the test platform with the characteristics described in 5.3.1 may be verified during the pre-test.

5.4 Test participants

The test participants who carry out the validation test shall be licensed operators of the plant concerned.

Given the variability of personnel, a sampling method shall be used to determine the test participants, and the sample shall reflect the characteristics of the population to which they belong. The characteristics that influence variation in system performance shall be identified in advance and enveloped in the sampling process. The sampling process shall take account of the following factors: licence and related qualifications, work experience, age and general demographic characteristics.

When determining the staffing of the test participants, it shall be consistent with the staffing of the unit control room, for example shift supervisor, senior operator, reactor operator and safety engineer.

To avoid sample bias, the following personnel shall not perform the test:

a) personnel who have taken part in the design;

b) personnel who have taken part in a previous assessment;

c) personnel who have been deliberately selected, such as those who are particularly outstanding or highly experienced.

5.5 Operating conditions

5.5.1 Sampling of operating conditions

5.5.1.1 Selection principles

Integrated system validation requires a dynamic assessment of the typical operating conditions of the plant. An operating condition is a combination of the plant state, the configuration, the events that cause the plant state to change, and the contextual influencing factors. Further refinement of an operating condition produces the test scenario used in the integrated system assessment activity. The selection of operating conditions is an important part of carrying out an integrated system assessment: it shall reflect the characteristics of the sampled population and must take account of both realism and representativeness. Realism means consistency with the actual operation of the plant. As regards representativeness, it is necessary to consider those characteristics that may reasonably cause the performance of the integrated system to vary, to cover typical representatives of the events that may be encountered during plant operation, and to focus on the typical events related to plant safety.

The selection of operating conditions shall be broad. The operating conditions that should not be selected are mainly:

a) scenarios expected to contain only positive outcomes;

b) scenarios that are relatively easy to implement on the simulator, that is, a scenario shall not be avoided merely because it is difficult to implement on the simulator;

c) familiar and carefully organised scenarios, for example dealing with familiar systems and failure modes such as a textbook design basis accident.

5.5.1.2 Plant conditions

The typical plant conditions that shall be selected for integrated system validation of the control room include:

a) normal operation, including plant start-up, shutdown or refuelling, and changes of operating power;

b) faults; when selecting faults, the role of the equipment in achieving the plant safety functions and the relationships between different systems shall be considered, and the propagation of the fault between systems shall be identified. Such faults include: 1) process equipment faults; 2) instrumentation and control faults; 3) HSI failure or degradation;

c) transients and accidents, such as: 1) design operating transients, for example load rejection; 2) design basis accidents, for example loss of primary coolant in a pressurised water reactor or rupture of a steam generator heat transfer tube; 3) shutdown and cooling of the reactor by means of the remote shutdown system;

d) design extension conditions determined by probabilistic safety analysis (PSA) to be reasonable and to contain risk-important tasks, such as station blackout.

5.5.1.3 Personnel tasks

The selection of scenarios shall reflect the human-machine interaction, and shall include:

a) important human actions, systems and accident sequences: the sampling shall include all the important human actions identified by probabilistic and deterministic methods. Other factors identified in the PSA as making a large contribution to risk shall also be considered, namely 1) dominant accident sequences and 2) dominant systems, determined by PSA importance analysis;

b) manual initiation of protective actions: the sampling shall include the manual system-level initiation of key safety functions;

c) monitoring of automatic systems: the sampling shall include scenarios in which personnel must monitor automatic systems that carry significant risk;

d) tasks identified for improvement by operating experience review (OER): the sampling shall include all the personnel tasks identified for improvement in the OER;

e) procedure-guided tasks. Not all categories of procedure need to be given equal weight; some categories, such as administrative management procedures and maintenance procedures, may be assessed as ancillary items of other tests. The validation activity shall include the important actions in the following procedures: 1) administrative procedures; 2) general operating procedures; 3) start-up, operating and shutdown procedures for safety-related systems; 4) abnormal and alarm procedures; 5) procedures for responding to emergencies and other major events; 6) radioactivity control procedures; 7) procedures for the control of measurement and test equipment, and supervision procedures such as testing and calibration; 8) maintenance procedures, which are not normally included in the integrated system assessment - when control room operators are required to control, or to follow up and confirm, plant maintenance activities, integrated system validation of the specific HSI required by the procedure may be carried out; 9) chemical and radiochemical control procedures;

f) knowledge-based tasks: the sampling shall include tasks that are not specified in detail by the procedures. If the rules provided by the procedure cannot completely solve the problem, or if it is not clear how to select the appropriate rule, some scenarios may require a knowledge-based decision process;

g) the range of personnel cognitive activities: the scenarios selected shall reflect the sequence of actions performed by personnel, including 1) monitoring and detection, for example when a critical safety function is threatened; 2) situation assessment, for example the understanding of alarms and displayed information for fault diagnosis of the plant process, the automatic control and the safety systems; 3) response planning, for example assessing options for repairing a plant fault; 4) response execution, for example using manual control in place of the automatic control system, or performing complex control actions; 5) status feedback, for example feedback that an action has been executed successfully;

h) all types of HSI shall be used in the validation scenarios selected, including 1) the alarm system and 2) the display system, such as digital indicators, process displays and the large screen.

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 26 pages — is available in the English PDF.

Referenced standards

Normative references

GB/T 13630-2015 Design of nuclear power plant control rooms

Similar standards

GB/T 13630-2015

How to Buy NB/Z 20598-2021

  1. 1Add to cart. Click the "Buy NB/Z 20598-2021" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
26 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

NB/Z 20598-2021

$470.00

$400.00for partners