Alternative fuels are changing the safety landscape of shipping.

Ammonia, methanol, hydrogen and other emerging fuels introduce different combinations of toxicity, flammability, cryogenic conditions, pressure, chemical compatibility and operational complexity.

At the same time, technologies, regulatory provisions and operating experience are still developing. In this environment, structured risk assessment becomes an important part of how safety decisions are made. [1]

The challenge, however, is not simply to perform more safety studies.

A project may complete a sound HAZID, a detailed HAZOP, consequence analysis, QRA or other specialised assessment and still face a more difficult question later: does the basis of those safety decisions remain visible and valid as the design evolves and the vessel enters operation?

That question matters because risk assessment is valuable not only for the report it produces. Its real value lies in the reasoning behind the decisions: the hazardous scenarios considered, the assumptions made, the safeguards relied upon, the conditions under which the conclusions remain valid and the actions expected from people and organisations.

If those connections weaken, the study may remain technically correct while becoming progressively less representative of the system being operated.

Four-stage chain from the risk basis through safety requirements and design, operational control, and change and revalidation, with a feedback loop from change back into the risk basisThe value of a risk assessment depends on whether its basis remains connected to design, operation and changes that follow.Source: ICORA MED conceptual model, informed by the guidance and studies listed in the References.

The risk basis has to survive beyond the study

Risk assessment produces more than a risk ranking or an action list. For significant scenarios, it establishes a basis for decision-making. It explains what can go wrong, what controls are relied upon, what assumptions support the analysis and under what conditions the resulting conclusion is valid.

As a project develops, that information is progressively translated into engineering requirements, design features, control logic, operating limits, procedures, competence requirements and emergency arrangements. [2][3] This translation is necessary, but it is also where important information can become diluted.

A recommendation such as "provide additional gas detection" is useful at an early stage, but it is not yet a complete safety requirement. The important question is what safety function the detection system is expected to provide, under what conditions, what response is required and what other controls depend on it. [7]

The same applies to ventilation, containment, shutdown systems, segregation, access control and operational restrictions.

The objective is not to preserve every line of a workshop record. It is to preserve enough of the risk basis to understand why an important safety decision was made and to verify that the final implementation still satisfies that intent.

This distinction is fundamental. Closing an action confirms that something has been done. It does not, by itself, demonstrate that the intended risk-control function has been achieved.

From design intent to operational control

The next transition is equally important.

Some assumptions made during risk assessment eventually become part of the operating envelope of the vessel. They may relate to equipment availability, system configuration, bunkering conditions, occupancy, simultaneous operations, alarm response, maintenance states or circumstances requiring an activity to stop.

A technically sound assessment can therefore lose value if those assumptions remain in the design documentation but do not become effective operational controls.

This does not mean that operators should be expected to read risk-assessment reports or that procedures should reproduce engineering analysis. Procedures need to remain clear and usable. The broader safety-management and assurance system should preserve the basis of the requirement, while the operator receives the information needed to act correctly. The distinction can be expressed simply:

Traceability preserves the safety basis; operational controls translate the relevant part of that basis into practice.

This is particularly important where human or organisational action forms part of the risk-control strategy. A response written into a procedure should not automatically be credited as a reliable safeguard. If a person is expected to recognise an alarm, diagnose a situation, isolate equipment or initiate an emergency response, the conditions required for successful performance also matter. [4][6]

Time available, information presented to the operator, workload, accessibility, communications, protective equipment and competence can all influence whether the intended response is realistically achievable.

Engine control room of a cruise ship: an engineer at a console surrounded by monitoring screensEngine control room of the cruise ship Harmony of the Seas, 2026. The alarm settings, trips and operating limits decided during design end up here, in front of the watchkeeper.Source: Larry D. Moore, Wikimedia Commons, licence CC BY 4.0

The same principle applies across organisational interfaces. Alternative-fuel bunkering and other port operations may involve the vessel, bunker supplier, terminal, port organisation and emergency services. Each party may have adequate procedures, while weaknesses still exist in the interfaces between them. [5][11]

The hazard scenario does not stop where one organisation's responsibility ends. Safe operation therefore depends not only on the strength of individual procedures, but on whether authority, communications, limits, shutdown arrangements and emergency actions remain compatible across the whole operation.

Past gas and chemical tanker casualties offer a useful warning, even though they are not direct evidence about future alternative-fuel ships. On Ennerdale, a major LPG release occurred while an emergency shutdown valve was jammed open; the UK Marine Accident Investigation Branch (MAIB) also found gaps in sampling guidance and in requirements for testing ESD valves. [9] On Stolt Groenland, MAIB found that heat transfer from adjacent cargoes to the styrene cargo was not fully appreciated and that the cargo temperature was not monitored; it recommended making handling guidance consistent and achievable on board. [10] These accidents involved different substances and operations, so they should not be treated as equivalent to ammonia or methanol. The wider lesson still applies: having technical safety information somewhere in the system is not enough if it is not turned into workable controls, monitoring and operational practice.

Change is where the original risk basis is tested

No risk assessment remains valid independently of change.

Equipment is modified. Control logic evolves. Operating arrangements change. New bunkering locations are introduced. Maintenance experience reveals new dependencies. Procedures are revised, and operating experience provides information that may not have been available during design.

This does not mean that every change should trigger a complete new HAZID or HAZOP. [3] The more useful question is whether the change affects an assumption, hazardous scenario, credited control, interface or operating condition on which an existing risk conclusion depends.

If it does, the relevant part of the assessment should be reconsidered.

This is where risk assessment and management of change meet.

The relationship also works in the other direction. Alarms, failures, inspection findings, drills, near misses and abnormal events provide evidence about how controls perform in practice and whether earlier assumptions remain valid. Operating experience may confirm the original basis, or it may show that parts of it need to be revisited.

Risk information should therefore move in both directions: from assessment into design and operation, and from operation back into assessment when new evidence changes the basis on which earlier decisions were made.

The practical principle is traceability

The answer is not a larger HAZID report, and it is not another administrative register.

What matters is the ability to maintain the connection between the risk basis and the controls that continue to rely on it. At a high level, that connection can be expressed as:

Risk basis → safety requirements and design → operational control → change and revalidation

This is not a prescribed documentation structure. It is an assurance relationship.

The relevant information may sit across risk-assessment records, engineering requirements, design documentation, verification activities, the Safety Management System and management-of-change processes. That is acceptable, provided the relationship between them can still be understood.

For a significant scenario, the organisation should still be able to answer a few fundamental questions:

  • What is the hazard being controlled?
  • What assumptions underpin the conclusion?
  • What safety functions are relied upon?
  • How have they been implemented?
  • What operating conditions must remain true?
  • What change or evidence would require the conclusion to be reconsidered?

If those questions remain answerable, the essential risk information has largely survived the transition from study to operation.

If they do not, the risk assessment may still exist on file while part of its safety value has been lost.

From risk assessment to operational safety

HAZID, HAZOP, QRA and other safety studies remain important, but their value should not be judged only by the quality of the workshop, the sophistication of the analysis or the number of recommendations closed.

Their real value is realised later: when the safety intent behind the assessment remains visible in the design, when the intended risk-control functions can be verified, when operating conditions reflect the assumptions on which the analysis relied and when change prompts proportionate review of the affected risk basis.

For alternative-fuel projects, this continuity is particularly important because technology, regulation and operating experience are developing in parallel. The central principle is therefore simple:

A strong risk assessment is not only one that reaches a defensible conclusion. It is one whose basis remains connected to the controls that manage the risk throughout the life of the system.

That is where risk assessment becomes operational safety.

References

  1. International Maritime Organization. Alternative Fuel and Technology Safety Guidelines (Future Fuels and Technology hub linking the IGF Code and the interim safety guidelines for ammonia, hydrogen, LPG, methanol/ethanol and other technologies). futurefuels.imo.org/safety-guidelines
  2. Maritime Technologies Forum. Guidelines for Conducting Qualitative Risk Assessments for Alternative-Fuelled Ships: HAZID and HAZOP, October 2025. maritimetechnologiesforum.com
  3. Maritime Technologies Forum. Guidelines to Develop and Implement a Safety Management System for Ammonia-fuelled Ships, March 2025. maritimetechnologiesforum.com
  4. International Maritime Organization. Preparing Seafarers for the Energy Transition (STCW.7/Circ.25, generic interim guidelines, 2025; STCW.7/Circ.26 for methyl/ethyl alcohol and STCW.7/Circ.27 for ammonia, approved at MSC 111 and circulated in July 2026). imo.org
  5. European Maritime Safety Agency. New reports on the safety of ammonia and hydrogen as fuels in shipping, January 2026 (equipment and failure-mode analysis, HAZOP of a generic fuel-supply system, ship-level HAZIDs and risk analysis of simultaneous port operations). emsa.europa.eu
  6. European Maritime Safety Agency. TRAINALTER: Identification of specific competences for seafarers – alternative fuels and energy systems, 2024. emsa.europa.eu
  7. Lloyd's Register Maritime Decarbonisation Hub and Mærsk Mc-Kinney Møller Center for Zero Carbon Shipping. Recommendations for Design and Operation of Ammonia-Fuelled Vessels Based on Multi-disciplinary Risk Analysis, June 2023. lr.org
  8. Im, T.-K., Yeo, S., Chun, K.W. and Lee, W.-J. (2026). HAZID-based quantitative framework for design-stage risk evaluations of ship-to-ship ammonia bunkering. Proceedings of the Institution of Mechanical Engineers, Part M: Journal of Engineering for the Maritime Environment. doi.org/10.1177/14750902251414749
  9. UK Marine Accident Investigation Branch. Report 10/2007: Major leak of liquefied propane from liquid gas carrier Ennerdale at Fawley Marine Terminal, Southampton, 2007. gov.uk/maib-reports
  10. UK Marine Accident Investigation Branch. Report 9/2021: Cargo tank explosion and fire on chemical tanker Stolt Groenland, Ulsan, 2021. gov.uk/maib-reports
  11. DNV. Practical guide for approval of ammonia- or hydrogen-fuelled ships (Maritime Impact expert story). dnv.com