Operator facing a wall of annunciators with most alarms suppressed
Knowledge base
Operations 7 minUpdated 2026-08-19

Alarm rationalisation playbook

Reducing nuisance alarms using EEMUA 191 principles, with a worked example from a recent project.

In short
  • An alarm requires an operator response. If there is no response, it is not an alarm.
  • EEMUA 191 puts the long-term average at roughly one alarm per operator per ten minutes.
  • Rationalisation is a documented decision per alarm, captured in a master alarm database.

Alarm floods are not an operator problem. They are a design debt that comes due at the worst possible moment. The Texaco Milford Haven explosion in 1994 is the canonical case: in the last eleven minutes before the blast, two operators had to act on 275 alarms, the overwhelming majority of which were not relevant to the developing upset.[1]

The definition does the work

ANSI/ISA-18.2, adopted internationally as IEC 62682, defines an alarm as an audible or visible means of indicating an equipment malfunction, process deviation or abnormal condition requiring a timely response.[2][3] Every word is load-bearing. If there is no defined operator response, and no time in which the response would help, the item is information — and belongs on a display, not in the alarm list.

Configured alarms at start100%
Everything the vendor shipped enabled
Survive the response test46%
A named operator action exists
Survive consequence review33%
Consequence and time-to-respond documented
Prioritised and set31%
Priority from consequence severity × urgency
Typical rationalisation outcome on a brownfield DCS migration

Performance targets you can measure against

MetricGuidelineMeaning
Average alarm rate~6 per hour (1 per 10 min)Manageable long-term load[4]
Peak burst≤10 in any 10-minute windowAbove this, response quality degrades[4]
Standing alarmsUnder ~10 at any timeChronic standing alarms train operators to ignore the list[2]
Priority distribution≈80% low, 15% medium, 5% highPriority only means something if it is scarce[4]
Stale alarmsNone older than 24 hA stale alarm is an unclosed decision[2]
EEMUA 191 / ISA-18.2 guidance for a steady-state operator console

The rationalisation session

Interactive · walkthrough

Per alarm, in a room with an operator present

1 / 5
State the cause

What physical condition produces this alarm? If the answer is 'a threshold', keep digging.

Deal with the bad actors first

In most plants a handful of tags produce the majority of activations. Chattering and fleeting alarms are typically fixed with deadband, on-delay or a repair — not with a priority change. ASM Consortium practice puts bad-actor resolution ahead of full rationalisation because it buys the operator immediate relief.[5]

Suppression is legitimate when it is designed: state-based suppression, shelving with an automatic un-shelve, and mode-dependent alarms are all sanctioned by ISA-18.2 provided each is documented and auditable.[2] Suppression that happens because someone silenced an annunciator is not. Presentation matters too — colour, layout and consistency are governed by ISA-101, and an alarm that cannot be distinguished from decoration on the HMI has already failed.[6]

Control room with a small number of active alarms among quiet displays
The goal is not fewer lights. It is that every light that remains has a name, an action and a deadline.
Interactive · checklist

Rationalisation readiness

0%

Common questions

What qualifies as an alarm?

An alarm requires an operator response. If there is no response the operator can take, it is information or a log entry — annunciating it as an alarm only spends the operator's attention on something they cannot act on.

What is an acceptable alarm rate?

EEMUA 191 puts the long-term average at roughly one alarm per operator per ten minutes, with flood conditions handled separately. Rates well above that are a design finding, not an operations one.

What is a master alarm database?

The record of the documented decision behind each retained alarm: its cause, the consequence of inaction, the operator response, the time available to respond, and the setpoint that follows from those.

How do you start reducing nuisance alarms?

Measure first — rate, top contributors, chattering and stale alarms — then rationalise the worst offenders against the response test. Suppression applied before measurement hides the evidence you need.

References

Sources for every claim above

Each footnote in the article links here. Standards are cited by designation so you can verify the current edition with the issuing body.

  1. [1]
    The explosion and fires at the Texaco Refinery, Milford Haven, 24 July 1994 — investigation report
    Health and Safety Executive · HSE Books, United Kingdom · 1997
    View source
  2. [2]
    ANSI/ISA-18.2-2016 — Management of Alarm Systems for the Process Industries
    ISA · International Society of Automation · 2016
    View source
  3. [3]
    IEC 62682:2022 — Management of alarm systems for the process industries
    IEC · International Electrotechnical Commission · 2022
    View source
  4. [4]
    EEMUA Publication 191 — Alarm systems: a guide to design, management and procurement
    EEMUA · Engineering Equipment and Materials Users' Association · 3rd edition, 2013
    View source
  5. [5]
    Effective Alarm Management Practices — ASM Consortium Guidelines
    ASM Consortium · Abnormal Situation Management Consortium · 2009
    View source
  6. [6]
    ANSI/ISA-101.01-2015 — Human Machine Interfaces for Process Automation Systems
    ISA · International Society of Automation · 2015
    View source
Let's build

Have a project in mind? Let's scope it together.

Tell us about your site, your constraints and your timeline. We'll respond with a practical engineering perspective — not a sales pitch.

View projects