Process Control and Automation Challenges in LNG Facilities
Process Control in LNG Facilities: Availability Is Not Control
Ask an LNG plant how its control system is performing and you will usually be told how available it is. Distributed control system (DCS) availability, programmable logic controller (PLC) uptime, loops in service, no outstanding faults.
None of that answers the question. A control system can be available 99.9% of the time and still not be controlling the plant. Availability measures whether the system is running. Control performance measures whether the process is being held where it was designed to sit—and those are different things, with a different set of numbers behind them.
That gap is where a great deal of LNG production quietly goes.
What the Availability Number Does Not Tell You
The measures that determine whether a plant is actually under control are rarely the ones on the monthly report: the share of loops sitting in manual and for how long, controller outputs saturated at a limit, oscillation and hunting between interacting loops, deviation from setpoint during transients rather than at steady state, the alarm rate an operator faces during an upset, and how many loops have never been retuned since commissioning.

Every one of those shows up in the same currency: variability. And variability is expensive in ways that rarely get attributed back to the control system. Pressure excursions push streams to relief, so product is burned rather than shipped—the argument we make at length in routine flaring as a symptom of control performance. Composition and temperature wander outside the window, producing off-spec and rework. Operators back away from limits they cannot hold steadily, which is how a plant ends up unable to reach capacity it has already paid for—the same mechanism at work in Joule-Thomson valves and expanders. And cycling wears valves, compressors, and refrigeration duty.
None of that appears on an availability report. All of it appears on the production report, usually attributed to something else.
The Alarm System Fails By Working
Alarm overload is the failure mode operators name first, and it is structurally different from every other system on the plant. Everything else fails by stopping. The alarm system fails by delivering exactly what it was configured to deliver, at the moment the operator has the least capacity to receive it.
The reference case is not from LNG, but it is the one the discipline was built on. In its case study of the explosion and fires at the Texaco Refinery, Milford Haven, on 24 July 1994, the UK Health and Safety Executive (HSE) records among the technical findings that an “excessive number of alarms in emergency situation reduced effectiveness of operator response”, alongside “a control valve being shut when the control system indicated it was open,” and control panel graphics that “did not provide necessary process overviews.” HSE’s own alarm management guidance puts the scale plainly: “the staff at Milford Haven Refinery were faced with a barrage of alarms for five hours preceding the incident.”

Two principles from that HSE guidance are worth applying line by line to any LNG alarm list. First: “Every alarm should be useful and relevant to the operator, and have a defined response.” Second: “Alarm levels should be set such that the operators have sufficient time to carry out their defined response before the plant condition escalates.”
Applied honestly, those are a hard test. Any alarm with no defined response fails the first. Any alarm arriving too late for the response to change the outcome fails the second. Both tests are cheap to run against a configured alarm list during design review, and effectively impossible to run for the first time during an upset.
Rationalisation, in other words, is not housekeeping. It is the difference between an alarm system that informs an operator and one that overwhelms them at the worst possible moment.
Where LNG Control Problems Are Actually Born
Three of them, all upstream of operations.
Vendor package control systems. An LNG plant is assembled from packages that each arrive with their own controller, its own alarm philosophy, its own HMI conventions, and its own idea of what constitutes a shutdown. Each is internally coherent. The integration between them is the owner’s problem, and it is usually specified thinly and tested late. Cooldown and startup—where the interactions are strongest and the sequencing is most demanding—are exactly where the seams show.
Incomplete cause-and-effect documentation. The cause-and-effect matrix is the document that says what trips what. If it is incomplete, inconsistent between packages, or never reconciled against the as-installed configuration, then nobody can state with confidence what the plant will do in an upset. That is not a documentation gap; it is an unknown in the safety case.
FAT and SAT with no owner in the room. Factory and site acceptance testing is the last practical opportunity to find the difference between what the vendor built and what the owner needs, while it is still the vendor’s cost to fix. An owner who does not send a qualified representative to witness FAT is, in practice, accepting the vendor’s configuration defaults as the plant’s control philosophy—and will meet them again at startup. That is the same handover logic set out in our post on FAT, SAT, and the commissioning handover, where commissioning-era settings become permanent by default.
The Regulatory Floor for U.S. LNG Plants
Federal rules do not specify control performance, but they do set requirements worth measuring a design against.
Under 49 CFR §193.2441, each LNG plant must have a control center that is “located apart or protected from other LNG facilities so that it is operational during a controllable emergency,” that can remotely actuate control and shutdown systems, and that has “personnel in continuous attendance while any of the components under its control are in operation.” Section §193.2507 requires monitoring capable of detecting “fire or any malfunction or flammable fluid that could cause a hazardous condition,” through attended control center alarms for gas, temperature, pressure, vacuum, and flow, or through scheduled inspections.
Maintenance is specified too. Under §193.2619, control systems must be “properly adjusted to operate within design limits”; a system out of service for 30 days or more must be inspected and tested before being returned to service; relief valves and shutdown devices that do not operate in normal service are tested at least annually, at intervals not exceeding 15 months; and fire protection systems are tested at intervals not exceeding six months. Personnel qualification under §193.2707 rests on training, relevant experience, and demonstrated proficiency.
Read together, these are a floor rather than a target—but a design or an operating practice that cannot meet them is not going to deliver control performance either.
What Owner-Side Review Changes
Independent oversight of a control system is a narrow, checkable set of activities:
- Reviewing the control philosophy as a document with a position in it, rather than a vendor template—including what runs in automatic, what the operator is expected to do, and where the design deliberately gives up control.
- Validating architecture against operating reality—segregation of control and safety, package integration, the behavior expected during startup, cooldown, turndown, and shutdown rather than at design rate only.
- Reconciling cause-and-effect across packages and against the as-installed configuration.
- Rationalising the alarm list against the two HSE tests before it is loaded, not after operators start suppressing alarms.
- Witnessing FAT and SAT with authority to reject, which is the only version of witnessing that changes anything.
- Establishing control performance baselines at startup, so degradation over the following years is visible rather than gradual and unattributed.
None of these are exotic. All of them are cheaper before startup than after, and all of them are things a vendor has no commercial reason to do on the owner’s behalf. That is the argument for owner-side process control and instrumentation engineering—independent of the party supplying the system.
Alaska LNG Services provides independent Owner’s Engineer and Owner’s Representative services across process plant and marine LNG facilities — LNG engineering consultants in Alaska with no control system to sell — including DCS and PLC design review, FAT and SAT participation, and commissioning support. Contact us to discuss your facility.
Frequently Asked Questions
Why is DCS availability a poor measure of control performance?
Availability tells you the system is running. It says nothing about whether the process is being held where it was designed to sit. The measures that matter are the share of loops in manual, controller outputs saturated at a limit, oscillation between interacting loops, deviation from setpoint during transients, alarm rate during upsets, and how many loops have never been retuned since commissioning. A plant can score perfectly on availability and still run with high variability.
What does poor control performance actually cost an LNG plant?
It is paid in variability: pressure excursions that push streams to relief and burn product rather than shipping it, composition and temperature excursions that produce off-spec, capacity that operators cannot reach because they will not sit near a limit they cannot hold steadily, and accelerated wear from cycling on valves, compressors, and refrigeration duty. These costs typically appear on the production report attributed to something other than the control system.
What is alarm rationalisation, and why is it a safety activity?
It is the review of every configured alarm against whether it should exist. HSE’s guidance states that “every alarm should be useful and relevant to the operator, and have a defined response,” and that “alarm levels should be set such that the operators have sufficient time to carry out their defined response before the plant condition escalates.” HSE cites the Texaco Milford Haven explosion of 24 July 1994, where staff “were faced with a barrage of alarms for five hours preceding the incident,” and where an excessive number of alarms in the emergency reduced the effectiveness of operator response.
Why does owner participation in FAT and SAT matter so much?
Factory and site acceptance testing is the last practical point at which the difference between what the vendor built and what the owner needs can be corrected at the vendor’s cost. An owner who does not witness FAT with the authority to reject is accepting the vendor’s configuration defaults as the plant’s control philosophy—and will encounter them again during startup, when changing them is expensive and slow.
You can learn more in our Alaska LNG engineering articles.
About the author: David Moras writes on LNG process control and automation for Alaska LNG Services LLC, an independent Owner’s Engineer and Owner’s Representative firm serving process plant and marine LNG projects.

