Refinery Unit Trips: What Actually Happens?

Learn | Industrial Operations & Process Fundamentals

A refinery can be running normally one moment and suddenly become a completely different workplace seconds later.

Alarms begin sounding. Pumps stop. Control valves move. Furnaces lose firing. Compressors unload or shut down. Operators begin responding to rapidly changing pressures, temperatures, flows, and liquid levels. Relief or flare systems may become active. Maintenance crews may be told to stop work or clear an area.

Workers often describe the event simply:

“The unit tripped.”

But a refinery unit trip is not one single action. It is a coordinated response involving instrumentation, process controls, electrical systems, rotating equipment, valves, utilities, relief systems, and operators.

Understanding what happens during a trip helps craftspeople understand why equipment suddenly changes state, why operations may restrict access, and why restarting a refinery unit can take considerably longer than shutting one down.

What Is a Refinery Unit Trip?

A trip is an automatic or manually initiated protective action that moves equipment or a process toward a safer condition after a potentially dangerous or damaging condition is detected.

The important word is protective.

A trip does not necessarily mean equipment has already failed catastrophically. In many cases, the trip occurs specifically to prevent that from happening.

A refinery may have protection at several levels:

  • Individual equipment trips.
  • Burner or furnace trips.
  • Compressor shutdowns.
  • Process-unit shutdowns.
  • Emergency shutdown systems.
  • Electrical protective trips.
  • Plantwide responses to major utility failures.

One pump stopping is therefore very different from an entire process unit shutting down.

1. Something Changes First


A refinery trip begins with detection. An abnormal process condition—such as high pressure—is identified by field instrumentation, which sends the signal to the control system so operators and safety systems can respond.

Before the trip occurs, something normally crosses a predefined operating or protective limit.

Possible initiating conditions include:

  • Excessively high pressure.
  • Excessively low pressure.
  • High temperature.
  • Low flow.
  • High or low liquid level.
  • Excessive equipment vibration.
  • Loss of lubrication.
  • Loss of cooling.
  • Flame failure.
  • Motor electrical fault.
  • Compressor instability.
  • Loss of instrument air.
  • Loss of steam.
  • Loss of electrical power.
  • Detection of fire or combustible gas.
  • Manual emergency shutdown activation.

A transmitter, switch, relay, equipment protection system, burner management system, programmable safety system, or another protective device detects the condition.

From that point forward, events can happen extremely quickly.

2. The Control System Sees the Problem

Modern refineries use extensive instrumentation to continuously measure process conditions.

Common measurements include:

  • Pressure.
  • Temperature.
  • Flow.
  • Level.
  • Vibration.
  • Speed.
  • Gas concentration.
  • Valve position.
  • Motor condition.

Normal process control is commonly handled through a Distributed Control System, or DCS.

Independent protective functions may also be handled by a Safety Instrumented System, commonly called an SIS.

These systems serve related but different purposes.

The DCS generally helps operate and control the process.

The SIS is intended to perform specified safety functions when defined hazardous conditions occur.

A simple way to think about it is:

DCS: Keep the process operating correctly.

SIS: Move the process toward a safer state when certain dangerous conditions occur.

The actual architecture varies considerably from facility to facility.

3. An Alarm Is Not Necessarily a Trip


The control system takes action. Once a trip condition is confirmed, the DCS/SIS executes its programmed response—stopping equipment, closing isolation valves, activating alarms, and bringing the refinery unit toward a safe shutdown state.

This distinction is important.

An alarm tells an operator that something requires attention.

A trip causes an action.

For example, imagine process pressure begins increasing.

At one pressure, the operator may receive a high-pressure alarm.

If pressure continues increasing, another protective setpoint could initiate a shutdown action.

Conceptually:

Normal → Warning → Alarm → Protective Action

Not every process follows this exact sequence, and trip logic varies by facility and equipment.

The key lesson is that alarms and trips are not interchangeable.

4. The Shutdown Logic Executes

Once a valid trip condition is recognized, predetermined shutdown logic begins executing.

Depending on the process, the system may command equipment to:

  • Stop.
  • Start.
  • Close.
  • Open.
  • Isolate.
  • Depressurize.
  • Divert.
  • Unload.
  • Reduce firing.
  • Transfer material elsewhere.

These actions are designed around the hazards of that particular process.

For example, a shutdown might close feed entering a unit while maintaining another flow temporarily for equipment protection.

A compressor trip may close suction or discharge valves according to the engineered sequence while activating anti-surge protection.

A fired heater trip may immediately remove fuel from the burners.

The objective is not simply:

“Turn everything off.”

It is:

Move the process into its engineered safe shutdown condition.

5. Shutdown Valves Begin Moving


The unit reaches a safe state. Pumps stop, valves close, heaters shut down, and the process is isolated while pressure and temperature are brought under control. Operators then verify critical conditions, stabilize the unit, and keep it secured until the cause of the trip can be safely investigated.

Some of the most visible actions during a trip involve valves.

Emergency shutdown or isolation valves may automatically change position.

Depending on their purpose, a valve may be designed to fail:

  • Open.
  • Closed.
  • In place.

The required failure position depends on the process hazard.

For example, a fuel-gas isolation valve may be designed to close upon loss of its control energy because stopping fuel flow is generally the safer condition for that application.

Another valve may need to open during a failure to provide cooling, depressurization, or another protective function.

This is why workers should never assume that every valve closes during a trip.

Different valves have different safety functions.

6. Pumps Begin Tripping

Pumps are everywhere in refinery process units.

When a trip occurs, some pumps may stop automatically while others may remain running.

That can initially seem strange.

Why not stop everything?

Because certain pumps may still be needed to:

  • Maintain circulation.
  • Remove heat.
  • Transfer remaining inventory.
  • Provide lubrication.
  • Supply cooling water.
  • Maintain seal systems.
  • Prevent equipment damage.

Some systems also have standby pumps configured to automatically start if the operating pump fails.

This means a trip can involve both equipment stopping and equipment starting.

7. Compressors Can Become Critical Very Quickly


The trip is investigated before the refinery unit returns to service. Operators and maintenance review alarms, process trends, instrumentation, and equipment conditions to identify the cause. Any problems are repaired, safeguards and interlocks are tested, and the unit is only cleared for restart once safe operation has been verified.

Large process compressors require particularly careful protection.

Compressors may handle:

  • Hydrogen.
  • Natural gas.
  • Refinery fuel gas.
  • Process vapors.
  • Refrigerants.
  • Hydrocarbon gases.

A compressor trip may be initiated by conditions such as:

  • High vibration.
  • Low lubrication pressure.
  • High bearing temperature.
  • Overspeed.
  • Electrical faults.
  • Process instability.
  • Seal-system problems.

When a compressor trips, flow conditions can change almost instantly.

Pressure may rise upstream while pressure falls downstream.

That disturbance can propagate through connected equipment.

Compressor protection systems may therefore activate anti-surge controls, recycle valves, isolation valves, unloading systems, or other protective sequences.

One equipment trip can become a unit-wide process problem very quickly.

8. Fired Heaters Lose Their Fire

Fired heaters introduce fuel and combustion into the refinery process.

Because of that, burner protection is extremely important.

If the burner management system detects an unsafe condition, fuel supply may be isolated.

Potential initiating conditions can include:

  • Flame failure.
  • Low fuel pressure.
  • Combustion-air problems.
  • Unsafe furnace conditions.
  • Process-flow problems.
  • Emergency shutdown signals.

Fuel valves close and burners extinguish according to the engineered protection sequence.

But the process material inside the heater does not instantly become cold.

The refractory, tubes, metal, and surrounding structure retain substantial heat.

That stored thermal energy is one reason shutdown procedures must consider what happens after firing stops.

9. Pressure Does Not Simply Disappear


The unit returns to service under controlled conditions. Once repairs and safety checks are complete, equipment is restarted in the proper sequence while operators closely monitor critical process conditions. Understanding the difference between a process trip, planned shutdown, and emergency shutdown is essential—each protects the refinery in a different way.

Stopping equipment does not automatically remove process pressure.

The unit may still contain large inventories of:

  • Hydrocarbons.
  • Steam.
  • Hydrogen.
  • Process gases.
  • Hot liquids.
  • Pressurized vapor.

Some systems may remain isolated under pressure.

Others may be depressurized through engineered systems.

Pressure-relief devices remain available to protect equipment if pressure exceeds allowable limits.

Depending on the event and facility design, material may ultimately be routed toward the refinery flare system.

10. Why the Flare May Suddenly Become Large

One of the most visible signs of a refinery upset is increased flaring.

A flare is part of the facility’s pressure-relief and disposal system.

During certain shutdowns or process disturbances, hydrocarbon gases that cannot safely remain in equipment may be routed into the flare system.

A simplified path might look like:

Process Equipment → Relief/Depressurization System → Flare Header → Knockout Drum → Flare Stack

The knockout drum helps separate entrained liquids before gas continues toward the flare.

At the flare stack, combustible gases are burned under controlled conditions.

A suddenly larger flare therefore does not automatically mean the refinery itself is on fire.

It can indicate that the safety and relief systems are handling excess hydrocarbons during an upset.

11. Operators Immediately Start Diagnosing

Automation can execute protective actions rapidly.

Humans still have to determine what happened.

Control-room operators begin reviewing information such as:

  • Which alarm occurred first?
  • Which trip initiated first?
  • What equipment stopped?
  • Which valves changed position?
  • What pressures changed?
  • What temperatures changed?
  • What happened immediately beforehand?
  • Did electrical power disappear?
  • Was instrument air lost?
  • Did one equipment failure cascade into another?

The first-out indication can be extremely valuable.

A unit may generate dozens or hundreds of alarms after a trip.

Most may be consequences rather than causes.

The first meaningful abnormal condition can point investigators toward the initiating event.

12. Why Hundreds of Alarms Can Appear

Imagine a major feed pump suddenly trips.

Flow disappears.

Downstream pressure changes.

Temperatures begin changing.

Levels move.

Control valves respond.

Other equipment moves outside normal operating ranges.

Each condition may generate another alarm.

The control room can therefore experience what is sometimes called an alarm flood.

That creates a troubleshooting challenge.

The question is not:

“Which alarms are active?”

The better question is:

“What happened first?”

Sequence-of-events information and high-resolution event records can help reconstruct the incident.

13. Electrical Trips Can Cascade Across the Unit

Sometimes the initiating event is not a process problem.

It is electrical.

A fault may cause a breaker or protective relay to trip.

That can remove power from a motor.

If that motor drives a critical pump or compressor, the process immediately reacts.

Now process alarms begin appearing.

A worker looking only at the process might think:

“The pump caused the unit trip.”

But the real sequence could be:

Electrical Fault → Breaker Trip → Motor Stops → Pump Stops → Process Flow Disappears → Unit Trips

Understanding sequence matters.

The first visible symptom is not always the root cause.

14. Instrument Air Failure Can Affect Many Valves

Instrument air is another utility capable of creating widespread problems.

Many pneumatic control valves depend on compressed instrument air for actuation.

If instrument-air pressure drops significantly, affected valves move according to their designed failure behavior.

Some may fail closed.

Others may fail open.

Others may remain near their existing position depending on the actuator and control arrangement.

A major instrument-air problem can therefore affect numerous parts of a process simultaneously.

This is one reason refinery utilities are so important.

They may not produce the final product, but the process depends on them.

15. Steam Loss Can Also Create Problems

Refineries use steam for many purposes, including:

  • Heating.
  • Stripping.
  • Turbine drives.
  • Tracing.
  • Ejectors.
  • Process services.
  • Equipment cleaning.
  • Utility applications.

A significant steam disturbance can affect several systems at once.

The consequences depend heavily on the particular refinery and process unit.

This illustrates an important refinery principle:

Utility systems connect everything.

An event that begins outside the process unit can still shut the process unit down.

16. The Unit Is Now in a Different Condition

After the immediate trip sequence, the unit may no longer be operating—but it is not necessarily safe for maintenance access.

Equipment may still be:

  • Hot.
  • Pressurized.
  • Electrically energized.
  • Chemically hazardous.
  • Filled with hydrocarbons.
  • Under vacuum.
  • Containing trapped pressure.
  • Capable of releasing stored mechanical energy.

Operations must determine the actual condition of the equipment.

This is where isolation, depressurization, draining, purging, gas testing, electrical isolation, and lockout/tagout procedures become critical.

A stopped machine is not automatically an isolated machine.

A stopped process is not automatically a safe process.

17. Maintenance Crews Enter the Picture

Once operations identifies the suspected problem and equipment is properly prepared for maintenance, crafts may become involved.

Depending on the failure, that might include:

  • Pipefitters.
  • Welders.
  • Millwrights.
  • Electricians.
  • Instrument technicians.
  • Boilermakers.
  • Valve technicians.
  • Scaffold builders.
  • Insulators.
  • Nondestructive examination technicians.
  • Reliability personnel.

The repair itself may be relatively simple.

Finding the actual cause may not be.

Replacing a failed component without understanding why it failed can simply reset the clock until the next failure.

18. Why Restart Takes So Long

Workers sometimes see a repair completed and wonder:

“Why aren’t they starting the unit?”

Because repairing the failed component is only one part of recovery.

Before restart, the facility may need to verify:

  • Mechanical repairs.
  • Instrument functionality.
  • Valve positions.
  • Electrical systems.
  • Equipment rotation.
  • Lubrication systems.
  • Cooling systems.
  • Seal systems.
  • Utilities.
  • Isolation removal.
  • Process inventory.
  • Permissives and interlocks.
  • Safety systems.
  • Required inspections.
  • Startup readiness.

A refinery process cannot usually be restarted like a pickup truck.

The process must be rebuilt operationally in the correct sequence.

19. Permissives Prevent Equipment From Starting Too Early

Many industrial systems use permissives.

A permissive is a condition that must be satisfied before an action is allowed.

A large pump, for example, might require certain conditions before starting:

  • Correct valve alignment.
  • Adequate lubrication.
  • Acceptable process level.
  • Electrical availability.
  • No active trip condition.
  • Required auxiliary systems operating.

Only when the required conditions are satisfied does the system permit the start.

Permissives help prevent operators from starting equipment in an unsafe or damaging configuration.

20. Interlocks Coordinate Equipment

Interlocks create relationships between equipment or process conditions.

For example, one piece of equipment may not be allowed to operate unless another system is already running.

Or one condition may automatically cause another piece of equipment to stop.

The exact logic is plant-specific.

The important concept is:

Industrial equipment does not operate independently.

A refinery unit is a network.

Changing one part can affect many others.

A Simplified Trip Sequence

Consider a hypothetical process compressor experiencing excessive vibration.

The sequence could look something like this:

  1. Vibration increases.
  2. Instrument detects high vibration.
  3. Alarm activates.
  4. Vibration reaches protective trip setpoint.
  5. Compressor trip initiates.
  6. Driver is shut down.
  7. Protective valves reposition.
  8. Recycle/anti-surge system responds.
  9. Process pressures and flows change.
  10. Additional alarms occur.
  11. Connected equipment responds.
  12. Unit reaches its engineered shutdown condition.
  13. Operations investigates.
  14. Equipment is isolated.
  15. Maintenance inspects and repairs.
  16. Systems are tested.
  17. Startup sequence begins.

The real sequence could be much more complicated, but this demonstrates how one abnormal measurement can propagate through an entire process.

Common Misunderstandings About Refinery Trips

“Everything shuts off.”

Not necessarily. Some equipment may intentionally continue running, while standby or protective equipment may automatically start.

“If the flare gets big, the refinery is on fire.”

Not necessarily. Increased flaring can occur because relief or depressurization systems are routing combustible gases to the flare for controlled disposal.

“The equipment that stopped caused the trip.”

Not always. It may simply have been responding to another problem.

“Once the equipment stops, it is safe.”

No. Heat, pressure, electricity, chemicals, vacuum, gravity and stored mechanical energy may remain.

“Once maintenance finishes the repair, operations can immediately restart.”

Often not. Verification, testing, alignment, permissives, process preparation and controlled startup may still be required.

Troubleshooting: Cause vs. Consequence

One of the most useful lessons for any industrial worker is learning to separate cause from consequence.

Suppose you observe:

  • Pump stopped.
  • Low-flow alarm.
  • Low downstream pressure.
  • High vessel level.
  • Furnace trip.

Which one caused the event?

You cannot determine that from the list alone.

The sequence matters.

If the pump stopped first, the other conditions may have followed.

But perhaps low vessel level caused the pump to trip for protection.

Or an electrical failure stopped the pump.

Or an upstream valve closed first.

Good troubleshooting requires reconstructing events rather than simply identifying everything that went wrong.

Field Rule

The loudest alarm is not necessarily the first problem.

During major process disturbances, dozens of secondary symptoms can distract from the initiating event.

Sequence matters.

What Craftspeople Should Understand During a Trip

You do not need to be a process operator to understand the fundamentals.

When a unit trips:

  • Follow facility instructions immediately.
  • Do not assume equipment is de-energized because it stopped.
  • Do not reposition valves unless specifically authorized.
  • Treat process equipment as hazardous until properly isolated and released.
  • Be aware that automatic valves or equipment may change state.
  • Understand that conditions may continue changing after the initial trip.
  • Respect barricades, restricted areas, permits, gas testing, and lockout/tagout requirements.
  • Never assume that a previous equipment condition still exists after a process upset.

The unit you walked through 15 minutes earlier may now be operating under completely different conditions.

Why This Matters Beyond Operations

Understanding unit trips makes other industrial subjects easier to understand.

Once you understand the basic sequence, concepts such as control valves, instrument air, emergency shutdown systems, flare systems, compressor protection, electrical relays, permissives, interlocks, process alarms, and lockout/tagout begin fitting together.

Instead of seeing a refinery as thousands of unrelated pipes and pieces of equipment, you begin seeing it as one interconnected system.

That is a major step toward understanding how industrial plants actually operate.

Knowledge Check

1. What is the primary purpose of a trip?
To move equipment or a process toward a safer condition when specified abnormal conditions occur.

2. Is an alarm the same thing as a trip?
No. An alarm communicates an abnormal condition; a trip initiates protective action.

3. Why might some equipment continue operating after a unit trip?
Certain equipment may be required for cooling, circulation, lubrication, safe inventory handling, or other protective functions.

4. Why can the flare become larger during a unit upset?
Hydrocarbon gases may be routed through engineered relief or depressurization systems for controlled disposal.

5. Why is the first alarm important?
Later alarms may be consequences of the original failure. The first meaningful event can help identify the initiating cause.

6. Does stopped equipment mean isolated equipment?
No. Hazardous energy and process inventory may remain.

7. Why can’t a refinery unit always restart immediately after repairs?
Equipment, instrumentation, utilities, valves, safety systems, process conditions, permissives, and other requirements may need verification before controlled startup.

Practical Exercise

Imagine a refinery process unit experiences the following events:

  • Main process pump stops.
  • Flow immediately falls.
  • Furnace trips shortly afterward.
  • Vessel level begins increasing.
  • Several downstream pressure alarms activate.
  • Operators later discover that the pump motor breaker opened.

Build the sequence from initiating event to final consequences.

A likely investigation would begin with:

Electrical Event → Motor Loses Power → Pump Stops → Process Flow Falls → Process Conditions Change → Protective Systems Respond → Additional Equipment Trips → Secondary Alarms Appear

Now ask the most important troubleshooting question:

Why did the breaker open?

That is where the next investigation begins.

The Bottom Line

A refinery unit trip is not simply equipment turning off.

It is a carefully engineered chain of protective actions designed to control energy, isolate hazards, protect equipment, and move a complex process toward a safer condition.

Sensors detect.

Logic evaluates.

Valves move.

Equipment stops or starts.

Pressures change.

The flare may respond.

Operators diagnose.

Maintenance repairs.

Operations verifies.

Then—only when the system is ready—the process begins coming back online.

Understanding that sequence changes the way you see a refinery.

A unit is not a collection of individual machines. It is a connected system—and when one important part changes, the entire system can react.

Leave a Reply

Discover more from Næxon

Subscribe now to keep reading and get access to the full archive.

Continue reading