Buncefield and ITC Deer Park: What Two Tank Farm Disasters Taught the Industry About Leak Detection

Most maintenance and design guidance on leak and gas detection focuses on getting a single sensor right: the correct type, the right mounting height, a sensible test interval. Two of the largest tank farm disasters in recent history are a reminder that the bigger risk usually sits one level up, in whether detection and shutdown layers actually work together, and whether anyone can act on an alarm before the situation is unrecoverable.

Buncefield, UK — 2005

At the Hertfordshire Oil Storage Limited depot, unleaded petrol was being pumped into Tank 912 overnight. Two separate systems were meant to stop it overflowing.

  • The automatic tank gauge, which should have tracked the rising level and triggered alarms as it approached full, stuck at a fixed reading in the early hours of the morning and stopped registering the level at all.
  • The independent high-level switch, the last line of defence, also failed to trip. The official investigation found it had been left isolated, reportedly because a padlock meant to keep it in service was missing.

With both systems silent, the tank kept filling. By the time petrol began spilling from vents on the tank roof, well over 250,000 litres had already overflowed into the bund. The vapour cloud that formed found an ignition source and produced what investigators called one of the largest peacetime explosions in Europe. More than 40 people were injured; there were no fatalities. Five companies were later convicted and fined close to £10 million between them.

The investigation’s conclusion was not that a single sensor failed. It was that two independent layers of protection, the gauge and the high-level switch, had both been allowed to fail at the same time, without anyone realizing either one was out of service.

ITC Deer Park, Texas — 2019

At Intercontinental Terminals Company’s tank farm, a circulation pump on a tank holding a naphtha and butane blend failed. The flammable mixture escaped through the failed pump and pooled in the containment area.

The U.S. Chemical Safety Board’s investigation found a specific gap: there was no monitoring in place to alert operators that the pump itself had failed, and no automatic means of detecting the flammable vapour building up in the dike. The release went on for roughly half an hour before it found an ignition source. The resulting fire spread and ultimately destroyed 15 storage tanks.

CSB’s recommendations afterward covered several layers at once: pump mechanical integrity monitoring, flammable gas detection in containment areas, remotely operated emergency isolation valves so a leak can be shut off without someone approaching it, and closing regulatory gaps that had left this type of tank farm outside routine process safety oversight.

What Changed in Practice

Neither incident was resolved by adding one better sensor. The changes that followed focused on layers working together:

  • Independent protection layers that are actually independent. Buncefield’s high-level switch existed on paper but had been taken out of service. Since the incident, industry guidance has pushed harder on verifying that backup trips are genuinely live, not just installed, and on formal Layers of Protection Analysis (LOPA) for overfill scenarios.
  • Detection that covers the whole containment area, not just point locations. A single sensor only responds to gas that reaches it. Since these incidents, tank farms have leaned more on detection that covers an entire dike or perimeter: open-path infrared beams that watch a line across the containment area, and acoustic sensors that listen for the sound of a pressurized leak rather than waiting for gas to drift somewhere.
  • Remote, automatic isolation. CSB’s recommendation for remotely operated emergency isolation valves reflects a wider theme: once a leak the size of these two is underway, manual isolation is often too slow or too dangerous to reach.

For a facility or MEP engineer, the transferable lesson scales down well below tank-farm size. A generator room fuel line, a chiller plant oil sump, or a fuel day tank has the same structure: a primary control, a backup alarm, and a plan for what happens if both are ignored at once. Buncefield’s padlock and ITC’s missing pump monitor were both small, ordinary gaps. Neither would have looked urgent on a maintenance checklist the week before.

Related Reading

Sources: UK Health and Safety Executive, Buncefield; Buncefield Major Incident Investigation Board report; U.S. Chemical Safety Board, ITC Deer Park investigation.

Related Posts

Mohamed Suhail

Author

Leave a Reply

Your email address will not be published. Required fields are marked *


Engineering tools, HVAC guides, calculators, and practical MEP resources.

Email

info@buildmep.com

Newsletter

© 2026 BuildMEP. All rights reserved.