A combustible dust hazard analysis is one of the few engineering documents routinely read backwards. It is written to prevent an incident, and then, if an incident happens anyway, it is read by people looking for what it failed to say. That reversal is worth designing for from the outset.

What the standard actually requires

NFPA 652 establishes the duty to determine whether the materials a facility handles are combustible or explosible, and to assess the resulting hazard. The obligation is not discharged by a general acknowledgement that dust is present. It requires identifying where combustible dust accumulates, in what quantity, and under what conditions it could be suspended and ignited.

Two failures recur. The first is scope: an analysis covering process equipment but not the building surfaces where fugitive dust settles. The second is currency: an analysis performed once and never revisited after a process change, a new raw material, or a modified dust collection arrangement. Both are visible on the face of the document, which is why they are usually the first things examined.

Primary and secondary events

In most destructive dust incidents the initiating event is comparatively small — a deflagration inside a collector, a dryer, a mill, or a length of ductwork. The damage comes from what follows. The pressure wave from the primary event lifts dust accumulated on beams, ledges, cable trays and rafters, creating a suspended cloud far larger than anything the process itself contained. That cloud then finds the flame front.

This is why housekeeping records carry disproportionate evidentiary weight. The severity of a secondary event is largely a function of how much dust had been allowed to accumulate on surfaces that no process drawing shows. A facility can have well-engineered protection on every vessel and still be destroyed by what was sitting on the structural steel above them.

The parameters that matter

Dust explosibility is not a single property. A defensible analysis rests on measured values rather than assumed ones: minimum explosible concentration, minimum ignition energy, minimum autoignition temperature, layer ignition temperature, and the deflagration index Kst, which governs venting and suppression design under NFPA 68 and NFPA 69.

Particle size distribution and moisture content shift all of these, sometimes substantially. A material that is marginally explosible as delivered may be aggressively so after milling or drying on site. This is why testing the dust as actually handled — sampled from the process, not from a supplier's reference lot — matters more than it first appears. Where an analysis relies on literature values for a material that has been ground, dried or blended in-house, that assumption is usually the first thing an opposing expert examines.

Ignition sources are rarely exotic

Contested cases sometimes devote enormous effort to identifying an unusual ignition source when the ordinary ones were never eliminated. Mechanical sparks from tramp metal, friction and bearing overheating, electrostatic discharge from ungrounded equipment, smouldering nests in collectors, and hot work all recur. The analytical question is usually less which source ignited the cloud than whether the facility had a credible basis for excluding each of them.

Ignition source control is also where documentation and practice most often diverge. A hot work permit system that exists on paper and is inconsistently applied produces a worse evidentiary position than none at all, because it establishes that the hazard was recognised.

What this means after an incident

Post-incident, the hazard analysis becomes evidence of what the operator knew and when. An assessment that identified an accumulation hazard and recommended controls never implemented is more damaging than no assessment at all — it establishes notice. Conversely, an assessment reasonable in scope, current with the process, and demonstrably acted upon is among the strongest defences available.

Preservation matters immediately and is frequently mishandled. Residual dust layers, the internal condition of collectors, the state of deflagration vent panels and isolation devices, and the deformation pattern of surrounding structure all carry information about sequence and direction. Cleaning a site before it is documented destroys the record of the very accumulation that determined the outcome, and it is often done with entirely good intentions during the rush to restore operations.

Where disputes usually land

Contested dust cases tend to turn on a small number of questions. Was the material's explosibility properly characterised for the form in which it was handled? Did the hazard analysis extend beyond process equipment to accumulation on building surfaces? Was protection designed to a measured Kst or an assumed one? Was the housekeeping programme executed at the frequency the analysis assumed? And was the analysis revisited after the last process change?

None of those are answerable from documents alone. Each requires examination of the site, the equipment and the material itself, which is why the sequence of preservation, sampling, testing and analysis usually determines what can ultimately be established — and why decisions made in the first days after an incident tend to constrain everything that follows.

Interconnection changes the analysis

Facilities are rarely a set of independent vessels. Collectors tie to ducting, ducting ties to mills and dryers, and pneumatic conveying links areas that are operationally separate. A deflagration initiating in one item of equipment can propagate along those connections into equipment that was never assessed as being at risk from it.

Hazard analyses that proceed equipment by equipment frequently miss this. Each vessel is assessed, protected and documented on its own terms, and the ducting between them is treated as a utility rather than as a propagation path. Where an incident has spread in a way the design did not anticipate, the systems-level gap in the original assessment is usually more significant than any single equipment deficiency, and it is visible in the analysis document itself.

This article is general technical orientation, not a failure analysis, an engineering opinion, or advice on any specific matter. Determining the cause of a particular incident requires hands-on examination by a credentialed expert.