Requirement 10: Application of the concept of defence in depth

empty

The design of a research reactor shall apply the concept of defence in depth. The levels of defence in depth shall be independent as far as is practicable.

6.13.

The defence in depth concept (see paras 2.10–2.14) shall be applied to provide several levels of defence that are aimed at preventing consequences of accidents that could lead to harmful effects on people and the environment, and at ensuring that appropriate measures are taken for the protection of people and the environment and for the mitigation of consequences in the event that prevention fails.

empty

6.14.

The design:

  1. Shall provide for successive verifiable physical barriers to the release of radioactive material from the reactor;

  2. Shall use conservative margins, and the manufacturing and construction shall be of high quality so as to provide assurance that failures and deviations from normal operation are minimized and that accidents are prevented as far as is practicable;

  3. Shall provide for the control of reactor behaviour by means of inherent and engineered features, such that failures and deviations from normal operation requiring actuation of safety systems are minimized or excluded to the extent possible;

  4. Shall provide for automatic actuation of safety systems, such that failures and deviations from normal operation that exceed the capability of control systems can be controlled with a high level of confidence, and the need for operator actions in the early phase of such failures or deviations from normal operation is minimized;

  5. Shall provide for structures, systems and components and procedures to control the course of and, as far as practicable, to limit the consequences of failures and deviations from normal operation that exceed the capability of safety systems;

  6. Shall provide effective means for ensuring that each of the main safety functions is performed, thereby ensuring the effectiveness of the barriers and mitigating the consequences of any failure or deviation from normal operation.

empty

6.15.

To ensure that the concept of defence in depth is maintained, the design shall prevent, as far as is practicable:

  1. Challenges to the integrity of physical barriers;

  2. The failure of one or more barriers;

  3. The failure of a barrier as a consequence of the failure of another barrier;

  4. The possibility of harmful consequences of errors in operation and maintenance.

empty

6.16.

The design shall ensure, as far as is practicable, that the first, or at most the second, level of defence in depth is capable of preventing an escalation to accident conditions for all failures or deviations from normal operation that are likely to occur over the operating lifetime of the research reactor.

empty

6.17.

The levels of defence in depth shall be independent as far as practicable to avoid a failure of one level reducing the effectiveness of other levels. In particular, safety features for design extension conditions (especially features for mitigating the consequences of accidents involving the melting of fuel) shall as far as is practicable be independent of safety systems.

empty