The independent high-level switch
20 Tank 912 was fitted with a new independent high-level switch on 1 July 2004.
This had been designed, manufactured and supplied by TAV Engineering Ltd. TAV
had designed the switch so that some of its functionality could be routinely tested.
Unfortunately, the way the switch was designed, installed and maintained gave a
false sense of security. Because those who installed and operated the switch did not
fully understand the way it worked, or the crucial role played by a padlock, the switch
was left effectively inoperable after the test. (A fuller description is in Appendix 1.)
The design fault could have been eradicated at an early stage if the design
changes had been subjected to a rigorous review process. In any event, clear
guidance, including instructions about the safety criticality of the padlock, should
have been passed on to installers and users.
TAV was aware that its switches were used in high-hazard installations and
therefore were likely to be safety critical.