Safety Evaluation of Reactor Plants (PWR, BWR) Masayuki Nakatsuji Engineering & Safety Group Plant Management Department The Japan Atomic Power Company August 26th, 2015

Contents 1. Overview of Nuclear Power Safety Regulation 2. Concept of Safety Evaluation during Safety Reviews 3. Evaluation of Exposure Dose Equivalents during Normal Operation 4. Safety Design Evaluation

1. Overview of Nuclear Power Safety Regulations 1 (1) Unification of the Administration Related to Nuclear Safety Regulatory Affairs Divorcing Nuclear Regulation from Nuclear Promotion In the old organizational structure, the Nuclear and Industrial Safety Agency, an organization in charge of nuclear safety regulation, was placed under the Ministry of Economy, Trade and Industry, which was supposed to promote nuclear energy use. In order to settle the problem where nuclear regulation affairs and nuclear promotional affairs were under the administration of the same organization, the nuclear safety regulation section was separated from the Ministry of Economy, Trade and Industry, and the Nuclear Regulation Authority was newly established as an external Bureau of the Ministry of the Environment. Nuclear Regulation Authority Chairman and four commissioners (appointed with the approval of the Diet)

Nuclear Regulation Agency (secretariat)

*Transferred on April 1, 2013

Double checking to enhance regulations

Electric utilities, etc.

Regulation

Research institutes, universities, etc.

Source: NRA brochure

1. Overview of Nuclear Power Safety Regulations 2 (2) Nuclear Power Safety Regulation Flow The Japan Atomic Power Company Decommissioning Periodic inspection Examination on physical protection of nuclear material Inspection on safety management Source: Convention on Nuclear Safety National Report for the Sixth Review Meeting Operation Phase Certificate issuance Completion of construction Inspection before commercial operation Approval of compliance with regulations on physical protection of nuclear material Approval of compliance with safety regulations Permission of reactor installation Design Phase Power Reactor Licensee Nuclear Regulation Authority Construction Phase Approval of the construction plan According to the Nuclear Regulation Law, permission from the Nuclear Regulation Authority is necessary for the installation of a nuclear reactor. The nuclear power reactor licensee is required to get reactor installation approval, approval of the reactor construction plan, and inspection of the nuclear fuel assemblies at the design and construction stages. At the operation stage, the nuclear power reactor licensee is required to conduct periodic inspections and get examinations for compliance with the regulations on physical protection of nuclear material. Examinations for compliance with safety regulations are conducted by Inspectors for the Safety Management of Nuclear Installations. The nuclear power reactor licensee is required to evaluate safety management activities for the reactor facilities and to verify that new findings are incorporated into the safety management activities. In order to extend the period of operation, the results of the component deterioration evaluation and the maintenance management policy must be approved by the Nuclear Regulation Authority every ten years. Detailed design Basic design Periodic evaluation Evaluation of aging degradation management technology

1. Overview of Nuclear Power Safety Regulations 3 (3) Overall Image of Safety Reviews To keep adequate distance between a given reactor and the public. To reduce radioactive releases into the environment during normal operation. Measures to prevent the occurrence of abnormal events. Safety Security measures To confine radioactive materials based on defense-indepth concept Measures to mitigate the development of abnormal events into the accidents. To confirm suitability of measures. (safety assessment) Measures to prevent abnormal release of radioactive materials to the environment. Measures to prevent Severe Accidents The Japan Atomic Power Company Handle with care; restricted to authorized persons; use outside of the purposes of use, duplication, and disclosure are prohibited 1. 原子力安全規制の概要 3 (3) 安全審査の全体像 原子炉と公衆との適切な距離の 確保 通常運転時における公衆の被ば く低減対策 異常事象の発生を未 然に防止するための 対策 安全確保 対 策 多重防護の考え方による放射性 物質の閉じ込め 異常事象の拡大防止 および事故への発展 を防止するための対 策 対策の適正 の確認 (安全評価) 外部への放射性物質 の異常な放出を防止 するための対策 重大事故等を防止す るための対策 The Japan Atomic Power Company Handle with care; restricted to authorized persons; use outside of the purposes of use, duplication, and disclosure are prohibited 2. Concept of Safety Evaluation during Safety Reviews 4 (1) Concept of Safety Evaluation during Safety Reviews Evaluation Category Safety Design Evaluation Evaluation of dose equivalents during normal operation Unexpecte d transients during operation Accidents Purpose of Evaluation Confirmation that the radiation dose to which the local populace is exposed during normal operation is maintained at a sufficiently low level Confirmation the functions required to assure safety are realized by elements such as the structures and devices in nuclear power plants not only during normal operation, but also in abnormal statuses Phenomena to be evaluated Judgment Criteria Amount of radioactive substances released into the environment from exhaust stacks and waste water ports Confirmation that the dose equivalent to which the local populace in the vicinity of the power plant is exposed in below the target value (referred to as dose target value, indicating an annual effective dose equivalent of 0.05 mSv) Equipment failures and malfunctions or operational errors by operators and phenomena that may lead to an abnormal status caused by disturbances of external origin foreseen as occurring at a similar frequency during the life of the nuclear power plant. Confirmation that there is no damage to the reactor core and that normal operation can be restored once the phenomena have been eliminated Phenomena that lead to an abnormal status beyond unexpected transient changes occurring during operation and that, although rare, present the risk of release of radioactive substances from the nuclear power plant and that need to be assumed from the standpoint of the safety of the nuclear power plant Confirmation that there is no possibility of a reactor core meltdown or other serious damage, that there is no secondary damage that may cause other abnormal statuses during the process of the phenomena and, additionally, that the design of barriers against the diffusion of radioactive substances is valid Source: Safety Evaluation from the Safety Review Perspective, “Unfailing safety” through “appropriate review” (Agency of Natural Resources and Energy, Ministry of International Trade and Industry) The Japan Atomic Power Company Handle with care; restricted to authorized persons; use outside of the purposes of use, duplication, and disclosure are prohibited 2. 安全審査における安全評価の考え方 4 (1) 安全審査における安全評価の考え方 評価の分類 評価の目的 通常運転時の線 量当量評価 通常運転時における周辺公 衆の放射線被ばくが十分低く 保たれることを確認する 運転時の異 常な過渡変 化 安 全 設 計 評 価 原子力発電所の構築物や機 器は通常運転時のみならず, 異常状態においても安全確 保の観点から所定の機能を 果たすことを確認する 事故 評価すべき事象 判断基準 排気筒及び放水口から環境に放出 される放射性物質の量 発電所周辺における公衆の受ける線 量当量が目標値(線量目標値といい, 実効線量当量で年間0.05ミリシーベ ルト)以下であることを確認する 原子炉の運転中において,原子力 発電所の寿命期間中に予想される 機器の故障・誤動作又は運転員の 誤操作,及びこれらと類似の頻度で 発生すると予想される外乱によって 生ずる異常な状態に至る事象 炉心の損傷はなく,かつ,通常運転 に復帰することができる状態で事象 が収束されることを確認する 運転時の異常な過渡変化を超える 異常な状態であって,発生する頻 度はまれであるが,発生した場合 は原子力発電所からの放射性物質 の放出の可能性があり,原子力発 電所の安全性を評価する観点から 想定する必要のある事象 炉心の溶融あるいは著しい損傷のお それがなく,かつ,事象の過程におい て他の異常状態の原因となるような2 次的損傷が生じなく,さらに放射性物 質の放散に対する障壁の設計が妥 当であることを確認する 出典;安全審査から見た安全評価 「適切な審査」で「確かな安全」を(通商産業省資源エネルギー庁) The Japan Atomic Power Company Handle with care; restricted to authorized persons; use outside of the purposes of use, duplication, and disclosure are prohibited 2. Concept of Safety Evaluation during Safety Reviews 5 (1) Concept of Safety Evaluation during Safety Reviews Evaluation Category Site Evaluation Serious accidents Hypothetical accidents Purpose of Evaluation Confirmation that reactor core site conditions are appropriate Phenomena to be evaluated Judgment Criteria Confirmation that setting in a nonpopulated area is appropriate Serious accidents foreseeable in worst-case scenarios as seen from the technical perspective taking into account elements such as phenomena in the vicinity of the site, reactor characteristics and safety and protective facilities Confirmation that the local populace will not be exposed to damage caused by radiation Confirmation that areas with small populace can be ensured and that the power plant is appropriately isolated from areas where the population is concentrated Hypothetical phenomena that go beyond serious accidents the occurrence of which is inconceivable from the technical standpoint (1) Confirmation that the local populace will not be exposed to marked damage caused by radiation (2) Confirmation that the calculated total-body dose value low enough to be acceptable from the collective dose perspective Source: Safety Evaluation from the Safety Review Perspective, “Unfailing safety” through “appropriate review” (Agency of Natural Resources and Energy, Ministry of International Trade and Industry) New Regulatory Standards Evaluation Category Countermeasures against severe accidents Purpose of evaluation Phenomena to be evaluated 【Enforced or newly determined】 Before designing a nuclear reactor, external phenomena, which may possibly occur on site, must be fully examined, and their effect on the reactor must be adequately considered. - It must be verified that the effect of radiation on the populace and environment will be permissibly low if a severe accident occurs and a substantial amount of radioactive substances are released. Events of core damage, containment vessel damage, or the like, which are postulated to occur in case of a severe accident Seismic Events Tsunami Postulated Natural Phenomena Accidental human errors postulated in monitoring areas The Japan Atomic Power Company Judgment Criteria - The reactor must be installed on a foundation which can adequately support it when struck by an earthquake. - The safety functions must not be seriously damaged by a tsunami. - The safety functions must not be damaged by natural phenomena or human errors. - The reactor core must not be seriously damaged, and sufficient core cooling capability must be maintained. - The containment vessel must not be seriously damaged, and an abnormally large amount of radioactive substances must not be released from the site. 2. Evaluation of Exposure Dose Equivalents during Normal Operation 7 In the reactor facilities, it is crucial to try to keep radiation exposure dose in surrounding public and nuclear plant workers as low as reasonably achievable. This way of thinking is called ALARA, from the first letter of each word. To this end, Nuclear Safety Commission of Japan prescribed “Regulatory Guide for the Annual Dose Target for the Public in Vicinity of Light Water Nuclear Power Reactor Facilities” to manage radioactive material generated by nuclear reactor operation strictly and keep release into surrounding environment as low as reasonably achievable. 3. Evaluation of Exposure Dose Equivalents during Normal Operation 7 In the reactor facilities, it is crucial to try to keep radiation exposure dose in surrounding public and nuclear plant workers as low as reasonably achievable. This way of thinking is called ALARA, from the first letter of each word. To this end, Nuclear Safety Commission of Japan prescribed "Regulatory Guide for the Annual Dose Target for the Public in Vicinity of Light Water Nuclear Power Reactor Facilities" to manage radioactive material generated by nuclear reactor operation strictly and keep release into surrounding environment as low as reasonably achievable.

3. Evaluation of Exposure Dose Equivalents during Normal Operation 8 (1) Methods of Radioactive Waste Treatment and Routes of Impact on the Local Populace Gaseous waste [Irradiated undiluted gases (e.g. 16N, 19O, 3H)] Attenuation using filters and hold-up devices, for example, and release from exhaust stacks while monitoring radiation levels (Cause of external and internal exposure to radiation) Liquid waste [Irradiated rust, etc., incorporating water (e.g. 60Co, 58Co, 54Mn)] Attenuation processing using filters, for example, and release into the sea after confirmation that radioactive concentration is equivalent to or less than standard values (Cause of external and internal exposure to radiation) Solid waste [e.g. Contaminated cloths, filter sludge)] Attenuation and volume reduction using incinerators and attenuation tanks, for example, and storage in silos (Cause of external exposure to radiation) Source: Safety Evaluation from the Perspective of Safety Reviews, “Unfailing safety” through “appropriate review” (Agency of Natural Resources and Energy, Ministry of International Trade and Industry) The Japan Atomic Power Company Handle with care; restricted to authorized persons; use outside of the purposes of use, duplication, and disclosure are prohibited 3. 通常運転時の被ばく線量当量の評価 8 (1) 放射性廃棄物の処理方法と周辺公衆への影響経路 気体廃棄物[放射化した非凝縮性ガス(16N,19O,3H 等)] フィルタ,ホールドアップ装置等により減衰処理し,放射線レベルを監視しながら,排気筒より放出 (外部・内部被ばく要因) 液体廃棄物[放射化した錆等を含む水(60Co,58Co,54Mn 等)] フィルタ等により減衰処理し,放射能濃度が基準値以下であることを確認後,海洋放出(外部・内部被ばく要因) 固体廃棄物[汚染したウェス,フィルタスラッジ等] 焼却炉・減衰タンク等により減衰・減容処理し,貯蔵庫に保管(外部被ばく要因) 出典;安全審査から見た安全評価 「適切な審査」で「確かな安全」を(通商産業省資源エネルギー庁) The Japan Atomic Power Company Handle with care; restricted to authorized persons; use outside of the purposes of use, duplication, and disclosure are prohibited 3. 3. Safety Design Evaluation 10 (1) Definition of safety evaluation It is the action to evaluate an adequacy of the safety design quantitatively in the process for securing of reactor safety, which comes in pairs of safety design. After that, the process for securing of safety regarding construction and operation follows. Radiation disaster prevention for surrounding public and nuclear plant workers Approval procedures corresponding to them Safety Design Safety Assessment Construction Management of Reactor Facilities Operation Management of Reactor Facilities

Installment License (Safety Review) Construction plan approval, preoperation inspection, welding inspection, fuel assembly inspection Approval of operational safety program, regular inspection, safety inspection

4. Safety Design Evaluation 11 INSAG-3 In the deterministic method, design base events (DBE) are chosen to encompass a range of related possible initiating events which could challenge the safety of the plant. Analysis is used to show that the response of the plant and its safety systems to design basis events satisfies predetermined specifications both for the performance of the plant itself and for meeting safety targets. 4. Safety Design Evaluation a. 12 Safety design evaluation/effectiveness evaluation Scope of evaluation Abnormal transients during operation Abnormal statuses caused by a singular failure or malfunction of component or singular erroneous operation by an operator that could take place during normal operation, or disturbances of external origin foreseen to occur at a frequency similar to those accidents, which shall be postulated in the safety design process as phenomena that could lead to severe damages to the core or the pressure boundary of reactor coolant if left to continue. Design base accidents Abnormal statuses of a frequency lower than abnormal transients during normal operation, which shall be postulated in the safety design process as phenomena that could lead to release of large amounts of radioactive substances from nuclear power generation facilities if arising. 4. Safety Design Evaluation 13 b. 4. Safety Design Evaluation 14 b. Design base events Events to be evaluated Abnormal transients during operation Representative events shall be selected for assessment from among the events, which may potentially lead to excessive damage to the core or the reactor coolant pressure boundary if the nuclear reactor facility is left uncontrolled, from the viewpoint of confirming the adequacy of the designed functions of structures, systems and components belonging in general to abnormality mitigation systems, or simply referred to as mitigation systems (MSs), such as the safety protection system and the reactor shutdown system.. 4. Safety Design Evaluation 15 b. Design base events Events to be evaluated Design base accidents Representative events shall be selected for assessment from among the events, which may potentially lead to undue exposure of the off-site public by the radioactive materials released from the nuclear reactor facility, from the viewpoint of confirming the adequacy of the designed functions of structures, systems and components belonging in general to MSs such as the engineered safety features. Categories of events Loss of reactor coolant or considerable change in core cooling Abnormal insertion of reactivity or rapid changes in reactor power Abnormal release of radioactive materials to the environment Abnormal changes in reactor containment vessel pressure, atmosphere, etc. Other events recognized as necessary based on the design of nuclear reactor facilities If similar events exist, the most severe event with regard to the judgment criteria shall represent others. Source: Safety Evaluation Affirmed by Safety Examinations, "Adequate Examinations" Ensure "Solid Safety," Agency of Natural Resources and Energy Ministry of International Trade and Industry JAPAN

4. restricted to authorized persons; 取扱注意 関係者限り 目的外使用・複製・開示等禁止 use outside of the purposes of use, duplication, and disclosure are prohibited The specific events to be evaluated(PWR) Abnormal operational transients a) Abnormal changes in the reactivity or the output distribution in the core Accidents a) Loss of reactor coolant or significant change in core cooling condition ① Abnormal control rod withdrawal in the start up time of the reactor 1 Loss of reactor coolant ② Abnormal control rod withdrawal during operation 2 Loss of reactor coolant flow ③Control rod fall and imbalance of output 3 Shaft sticking for reactor coolant pump ④ Abnormal dilution of boron in reactor coolant 4 Breakage of main feed water pipe 5 Breakage of main steam pipe b) Abnormal changes in calorification and heat removal in the core ⑤ Partial loss of reactor coolant ⑥ Incorrect operation of stop loop of reactor coolant system ⑦ Loss of external power supply b) Abnormal increase of reactivity or rapid change in reactor output 6 Control rod ejection c) Abnormal release of radioactive material into environment ⑧ Loss of main feed water 7 Damage of radioactive gas waste disposal site ⑨ Abnormal increase of steam load 8 Breakage of steam generator tube ⑩ Abnormal pressure decrease of secondary cooling system 9 Fuel assembly fall ⑪ Excessive feed water to steam generator 1 Loss of reactor coolant 6 Control rod ejection c) Abnormal changes in reactor coolant pressure or reactor coolant holdings 17 d) Abnormal changes in reactor containment vessel and atmosphere, etc. ⑫ Loss of load ⑬ Abnormal pressure decrease of reactor cooling system ⑭ Incorrect operation of ECCS during operation The Japan Atomic Power Company 1 Loss of reactor coolant 10 Combustible gas generation Handle with care; restricted to authorized persons; 取扱注意 関係者限り 目的外使用・複製・開示等禁止 use outside of the purposes of use, duplication, and disclosure are prohibited 評価すべき具体的な事象(PWR) 運転時の異常な過渡変化(PWR:14) a) 炉心内の反応度又は出力分布の異常な変化 事故(PWR:13) a) 原子炉冷却材の喪失又は炉心冷却状態の著しい変化 ① 原子炉起動時における制御棒の異常な引き抜き 1 原子炉冷却材喪失 ② 出力運転中の制御棒の異常な引き抜き 2 原子炉冷却材流量の喪失 ③ 制御棒の落下及び不整合 3 原子炉冷却材ポンプの軸固着 ④ 原子炉冷却材中のほう素の異常な希釈 4 主給水管破断 b) 炉心内の熱発生又は熱除去の異常な変化 5 主蒸気管破断 ⑤ 原子炉冷却材流量の部分喪失 ⑥ 原子炉冷却材系の停止ループの誤起動 ⑦ 外部電源喪失 b) 反応度の異常な投入又は原子炉出力の急激な変化 6 制御棒飛び出し c) 環境への放射性物質の異常な放出 ⑧ 主給水流量喪失 7 放射性気体廃棄物処理施設の破損 ⑨ 蒸気負荷の異常な増加 8 蒸気発生器伝熱管破損 ⑩ 2次冷却系の異常な減圧 9 燃料集合体の落下 ⑪ 蒸気発生器への過剰給水 1 原子炉冷却材喪失 6 制御棒飛び出し c) 原子炉冷却材圧力又は原子炉冷却材保有量の異常な変化 ⑫ 負荷の喪失 d) 原子炉格納容器内圧力、雰囲気等の異常な変化 ⑬ 原子炉冷却材系の異常な減圧 1 原子炉冷却材喪失 ⑭ 出力運転中の非常用炉心冷却系の誤起動 10 可燃性ガスの発生 The Japan Atomic Power Company 17 Handle with care; restricted to authorized persons; 取扱注意 関係者限り 目的外使用・複製・開示等禁止 use outside of the purposes of use, duplication, and disclosure are prohibited The specific events to be evaluated(BWR) 18 Source: Safety Evaluation Affirmed by Safety Examinations, “Adequate Examinations” Ensure “Solid Safety,” Agency of Natural Resources and Energy Ministry of International Trade and Industry JAPAN The Japan Atomic Power Company Handle with care; restricted to authorized persons; 取扱注意 関係者限り 目的外使用・複製・開示等禁止 use outside of the purposes of use, duplication, and disclosure are prohibited 評価すべき具体的な事象(BWR) 18 Source: Safety Evaluation Affirmed by Safety Examinations, “Adequate Examinations” Ensure “Solid Safety”, Agency of Natural Resources and Energy Ministry of International Trade and Industry JAPAN The Japan Atomic Power Company Handle with care; restricted to authorized persons; 取扱注意 関係者限り 目的外使用・複製・開示等禁止 use outside of the purposes of use, duplication, and disclosure are prohibited The specific events to be evaluated(BWR) Abnormal operational transients a) Abnormal changes in the reactivity or the output distribution in the core Accidents a) Loss of reactor coolant or significant change in core cooling condition ① Abnormal control rod withdrawal in the start up time of the reactor 1 Loss of reactor coolant ② Abnormal control rod withdrawal during operation 2 Loss of reactor coolant flow b) Abnormal changes in calorification and heat removal in the core 3 Shaft sticking for reactor coolant pump ③ Partial loss of reactor coolant ④ Incorrect operation of stop loop of reactor coolant system ⑤ Loss of external power supply b) Abnormal increase of reactivity or rapid change in reactor output 4 Control rod fall c) Abnormal release of radioactive material into environment ⑥ Loss of feed water heater 5 Damage of radioactive gas waste disposal site ⑦ Incorrect operation of reactor coolant flow control system 6 Breakage of main steam pipe 7 Fuel assembly fall ⑧ Loss of load 1 Loss of reactor coolant ⑨ Incorrect close of main steam isolation valve 4 Control rod fall c) Abnormal changes in reactor coolant pressure or reactor coolant holding ⑩ Failure of feed water control system d) Abnormal changes in reactor containment vessel and atmosphere, etc. ⑪ Failure of reactor pressure control system 1 Loss of reactor coolant ⑫ Overall loss of feed water flow 8 Combustible gas generation 9 Dynamic load generation The Japan Atomic Power Company 19 Handle with care; 4. Safety Design Evaluation 20 b. Design base events Judgment criteria Abnormal transients during operation The design shall allow restoration of the nuclear reactor facilities to normal operation, without damaging the core. The minimum critical heat flux ratio or the minimum critical power ratio shall be larger than the acceptable limit. Fuel cladding shall not be mechanically damaged. Fuel enthalpy shall not exceed the acceptable limit. (The standard for preventing high-temperature rupture, melting, and embrittlement of cladding tubes) Pressure on the reactor coolant pressure boundary shall not exceed 110% of the maximum allowable working pressure. 4. Safety Design Evaluation b. 21 Design base events Judgment criteria Design base accidents It shall be verified that the nuclear reactor facility is designed such that a postulated event does not lead to melting or considerable damage of the core, that the event does not cause, in its process, a secondary damage which would lead to another abnormal condition, and that the function of the barriers against the release of radioactive materials in the event is adequate. The core shall not be damaged considerably, and adequate coolable state of the core shall be. (The standard related to embrittlement accompanying metal-water reaction (oxidization) of cladding tubes) The maximum temperature of fuel cladding: 1,200ºC or less The amount of oxidization of a fuel cladding tube: 15% of the cladding tube thickness or less The fuel enthalpy shall not exceed the limit values for maintaining integrity of the nuclear core or the pressure boundary of reactor coolant. (The standard for preventing generation of pressure wave due to melting and evaporating of pellets) The pressure exerted on the pressure boundary of reactor coolant shall be 1.2 times the maximum working pressure or less. The pressure on the reactor containment boundary and the temperature at the boundary of the reactor containment shall not exceed the maximum allowable working pressure and temperature, respectively. The facilities subject to the design standard shall not cause radiation damages to the public in factories and other facilities in the vicinity. 4. Safety Design Evaluation b. 22 Design base events Matters to be considered in analyses Scope of consideration The conditions before occurrence of abnormal status constitute the most severe initial conditions with regard to the judgment criteria, taking into consideration the entire scope of normal operation and operation period, changes in core burn-up during the cycle period, and variations due to fuel replacement, etc. All abnormal events that could arise during all the phases of normal operation (startup, shutdown, output operations, hot standby, fuel replacement, and other operational processes of nuclear reactor facilities) are covered. Up to the point where it is reasonable to assume that the situation would resume to a normal state and reach a cold shutdown without difficulty Assumptions regarding safety functions Reliable safety functions Among the safety functions for dealing with events, the functions that may be considered in the analyses are those belonging to MS-1 and 2, as a principle. 4. Safety Design Evaluation b. 23 Design base events Matters to be considered in analyses Assumptions regarding safety functions Assumption of singular failure Concerning structures, systems, and equipment for dealing with accidents, a singular equipment failure that brings about the most severe analysis result is assumed for each of the basic safety functions; namely, nuclear reactor shutdown, core cooling, and radioactivity containment. Applicable to active equipment for a short period following the occurrence of an event, and to active or passive equipment over a long period Passive equipment is exempted if removal or restoration is possible within a time period that would not affect safety, or if the probability of occurrence is sufficiently low. Equipment that starts operating before the occurrence of an event and continues operating after the occurrence is exempted. 4. Safety Design Evaluation b. 24 Design base events Matters to be considered in analyses Assumptions regarding safety functions Assumption of loss of external power source If operation of engineered safety features is to be relied on, cases in which an external power source is unavailable shall also be considered when analyzing accidents. However, cases in which external power source remains sound also need to be considered, because effects of availability of external power sources differ by events. Effects of reactor scram Appropriate scram delay time shall be considered. Aside from a singular failure of the nuclear reactor shutdown function, the shutdown effects shall be considered while assuming that a control rod of the maximum reactivity worth is held at fully withdrawn position. 4. Design Base Accident) 25 Examples of Safety Evaluation of Accident Phenomena (PWR) 1) Loss of Nuclear Reactor Coolant [Overview of Phenomenon] This is an assumed phenomenon for confirmation that the design properly ensures coolant for the reactor core in cases where there is a reactor core coolant outflow due to, for example, damage to the piping in the container connected to the nuclear reactor. It is assumed that damage to the piping, for example, that configures the nuclear reactor coolant pressure boundary during reactor drive operation causes an outflow of reactor coolant and a consequent drop in the reactor core cooling capacity. A pipe from the outlet of the primary coolant pump to the nozzle at the inlet of the reactor vessel ruptures at its double end. ( Loss of off-site power is also assumed.) Water level in the reactor falls. Reactor pressure sets to drop. Temperature of the fuel cladding tubes goes up. Bubble grows in the core. Water is automatically injected by the accumulator system, the highpressure injection system, and the low-pressure injection system of the emergency core cooling system (ECCS). Reactor self-control effect (Void effect) makes the reactor power decreases. Temperature of the fuel cladding tubes goes down. Water level in the reactor goes up. Reactor pressure sets to drop. ⇒Given a shutdown signal, all control rods are automatically inserted into the core. Source: Safety Evaluation Affirmed by Safety Examinations, "Adequate Examinations" Ensure "Solid Safety", Agency of Natural Resources and Energy Ministry of International Trade and Industry JAPAN

4. Safety Design Evaluation 26 It is assumed the pipe from the outlet of the primary coolant pump to the nozzle at the inlet of the reactor vessel ruptures at its double end. Source: Safety Evaluation Affirmed by Safety Examinations, "Adequate Examinations" Ensure "Solid Safety", Agency of Natural Resources and Energy Ministry of International Trade and Industry JAPAN

4. Safety Design Evaluation 27 Examples of Safety Evaluation of Accident Phenomena (BWR) 1) Loss of Reactor Coolant [Overview of Phenomenon] This is an assumed phenomenon for confirmation that the design properly ensures coolant for the reactor core in cases where there is a reactor core coolant outflow due, for example, to damage to the piping in the container connected to the nuclear reactor. Fuel rods Reactor water level(m) With water around the fuel rods evaporating due to the still high hiea valve,cooling temporarily runs short Core starts exposed due to the lowering water level Submerged again due to ECCS Cooling by steam is operation taking place Water level is restored by the temporarily growing core flow Automatic insertion of control rods Rupture occurs ECCS works Fuel cladding tubes temperature (℃) It is assumed that damage to the piping, for example, that configures the nuclear reactor coolant pressure boundary during reactor power operation causes an outflow of coolant and a consequent drop in the reactor core cooling capacity. Source: Safety Evaluation Affirmed by Safety Examinations, "Adequate Examinations" Ensure "Solid Safety," Agency of Natural Resources and Energy Ministry of International Trade and Industry JAPAN

4. Safety Design Evaluation c. 28 Site evaluation (reference) Events to be evaluated Conceptual accidents that are not likely to take place are considered, for confirming isolation from the public. 4. Safety Design Evaluation d. 29 Severe accidents and others Events to be evaluated Prevention of substantial core damage Evaluation is conducted pursuant to Examination Guidelines for Effectiveness Evaluation of Countermeasures to Prevent Damages to Reactor Cores and Reactor Containment Vessels of Commercial Nuclear Power Reactors. Prevention of damages to reactor containment vessels Evaluation is conducted pursuant to Examination Guidelines for Effectiveness Evaluation of Countermeasures to Prevent Damages to Reactor Cores and Reactor Containment Vessels of Commercial Nuclear Power Reactors. Prevention of damages to fuel assemblies in spent fuel storage pools Evaluation is conducted pursuant to Examination Guidelines for Effectiveness Evaluation of Countermeasures to Prevent Damages to Fuel Assemblies in Spent Fuel Storage Pools of Commercial Nuclear Power Reactors. 4. Safety Design Evaluation d. 30 Severe accidents and others Events to be evaluated Prevention of substantial core damage Accident sequences to be evaluated are those assuming the possibility of severe reactor core damages when the safety functions have been lost with structures, systems, and equipment that are required to be designed not to allow impairment of the reactor safety in cases of abnormal transients during operation and design base accidents. Accident sequence group to be assumed in all cases (see the table below) Accident sequence group extracted by individual plant evaluations (probabilistic risk assessment; PRA) BWR PWR Loss of high-pressure and low-pressure water injection functions Loss of function to remove heat from the secondary system Loss of high-pressure water injection and depressurization functions Loss of all AC power sources (with or without seal LOCA) Loss of all AC power sources Loss of component cooling water system Loss of decay heat removal function (loss of water intake function, defect in RHR) Loss of heat removal function of nuclear reactor containment vessel Loss of nuclear reactor shutdown function Loss of nuclear reactor shutdown function Loss of water injection function at times of LOCA (large-scale rupture, small- and medium-scale rupture) Loss of water injection function of ECCS (LOCA with large-scale rupture or small-, medium-scale rupture) Containment vessel bypass (IS-LOCA) Loss of recirculation function of ECCS (LOCA with large-scale or small-, medium-scale rupture) Containment vessel bypass (IS-LOCA, SGTR) The Japan Atomic Power Company Handle with care; restricted to authorized persons; use outside of the purposes of use, duplication, and disclosure are prohibited 4. 安全設計評価 30 d. 重大事故等 評価すべき事象 炉心の著しい損傷の防止 運転時の異常な過渡変化及び設計基準事故に対して原子炉の安全性を損な うことがないよう設計することを求められている構築物、系統及び機器が その安全機能を喪失した場合であって、炉心の著しい損傷に至る可能性が あると想定する事故シーケンスが対象 必ず想定する事故シーケンスグループ(下表) 個別プラント評価(確率論的リスク評価、PRA)により抽出した事故シーケンス グループ BWR PWR 高圧・低圧注水機能喪失 2次系からの除熱機能喪失 高圧注水・減圧機能喪失 全交流動力電源喪失(シールLOCAあり、無し) 全交流動力電源喪失 原子炉補機冷却機能喪失 崩壊熱除去機能喪失(取水機能喪失、RHR故障) 原子炉格納容器の除熱機能喪失 原子炉停止機能喪失 原子炉停止機能喪失 LOCA時注水機能喪失(大破断、中小破断) ECCS注水機能喪失(大破断LOCA、中小破断LOCA) 格納容器バイパス(IS-LOCA) ECCS再循環機能喪失(大破断LOCA、中小破断LOCA) 格納容器バイパス(IS-LOCA、SGTR) The Japan Atomic Power Company Handle with care; restricted to authorized persons; use outside of the purposes of use, duplication, and disclosure are prohibited 4. 4. 4. 4. Safety Design Evaluation d. 34 Severe accidents and others Judgment criteria Prevention of substantial core damage Concerning cases among the accident sequence group assumed in which the nuclear reactor containment vessel is expected to continue functioning after suffering severe damages to the core, sufficient countermeasures for preventing severe damages to the core shall have been planned and furthermore the countermeasures shall prove effective within the assumed scope. Concerning cases among the accident sequence group assumed in which it is difficult to expect the nuclear reactor containment vessel to continue functioning after suffering severe damages to the core, the countermeasures for preventing severe damages to cores shall be effective. The core shall be free of possibilities of serious damage, and furthermore sufficient cooling of the core shall be possible. (The standard related to embrittlement accompanying metal-water reaction (oxidization) of cladding tubes) Maximum temperature of the fuel cladding: 1,200ºC or less Amount of oxidization of a fuel cladding tube: 15% of the cladding tube thickness before severe oxidization or less The pressure exerted on the pressure boundary of reactor coolant shall be less than 1.2 times the maximum working pressure or the critical pressure. The pressure exerted on the boundary of nuclear reactor containment vessel shall be less than the maximum working pressure or the critical pressure. The temperature at the boundary of nuclear reactor containment vessel shall be less than the maximum working temperature or the critical temperature. In an effective evaluation of accident sequence groups using pressure release apparatus in the containment vessel, no serious risk of radiation exposure shall be posed to the public in the vicinity. 4. Safety Design Evaluation d. 35 Severe accidents and others Judgment criteria Prevention of damages to nuclear reactor containment vessels Concerning the containment vessel damage modes assumed, measures to prevent damages to nuclear reactor containment vessels and furthermore measures to prevent release of radioactive substances outside of the site at an abnormal level shall be effective. The pressure exerted on the boundary of nuclear reactor containment vessel shall be less than the maximum working pressure or the critical pressure. The temperature at the boundary of nuclear reactor containment vessel shall be less than the maximum working temperature or the critical temperature. The total amount of radioactive substances released shall pose as small an impact on the environment as possible, also taking into account the viewpoints on environmental pollution by radioactive substances. (The amount of Cs-137 released shall be no more than 100TBq) The pressure of nuclear reactor coolant shall have been lowered to 2.0MPa or less, by the time the nuclear reactor pressure vessel suffers damage. The functions of the boundary of nuclear reactor containment vessel shall not be lost due to the thermal and mechanical loads caused by rapid interactions between the molten fuel and coolant outside of the nuclear reactor pressure vessel. Hydrogen detonation that could damage the nuclear reactor containment vessel shall be prevented. The hydrogen concentration shall be 13 vol% or less when converted to dry conditions, or the oxygen concentration shall be 5 vol% or less. The standards for pressure exerted on the boundary of nuclear reactor containment vessel shall be met even when a flammable gas has accumulated or undergone combustion. In case the molten core that falls on the floor of nuclear reactor containment vessel spreads, it shall not come into contact with the boundary of the nuclear reactor containment vessel, and the molten core shall be cooled appropriately. The supporting function of structural members of the nuclear reactor containment vessel shall not be lost due to corrosion by the molten core, and the molten core shall be cooled appropriately. 4. Safety Design Evaluation d. 36 Severe accidents and others Judgment criteria Prevention of damages to fuel assemblies in spent fuel storage pools The following evaluation items shall be satisfied with regard to the assumed accidents 1 and 2. The top of the effective length of the fuels shall be underwater. A water level that maintains the radiation shielding properties shall be secured. The subcritical state shall be maintained. Prevention of damages to fuel assemblies in nuclear reactors that have been shut down The following evaluation items shall be satisfied with regard to the assumed accident sequence group during shutdown. The top of the effective length of the fuels shall be underwater. A water level that maintains the radiation shielding properties shall be secured. The subcritical state shall be maintained. 4. (Application of conservative assumptions and conditions is not denied) Models that have been verified through experiments and others and are with an appropriate scope of application shall be used. When a model with high uncertainty is used or if the scope of application of a verified model is exceeded, its impacts shall be taken into consideration appropriately based on the results of sensitivity analysis, etc. As a principle, the analysis shall cover up to the time point when the accident has been cleared and the nuclear reactor has reached a stable shutdown (hightemperature or low-temperature shutdown). (At least seven days, assuming that no outside support is available. If the stable condition was reached in a period less than seven days, it must be demonstrated that the stable conditions may be maintained.) If there are several countermeasures, basically the effectiveness of each shall be evaluated. 4. Safety Design Evaluation d. 38 Severe accidents and others Matters to be considered in analyses (Prevention of substantial core damage) Common conditions for effectiveness evaluation The nuclear reactor is operated at the rated thermal output. The output distribution at the core, core flow rate, decay heat, and other parameters shall be of realistic values supported by design values, etc. Conditions applicable to facilities for dealing with design base accidents The design values are used for the capacity of facilities. (If values other than the design values are used, the grounds and appropriateness for using the value must be demonstrated.) Instrumental errors are not taken into consideration for operation set points and other parameters. Except for facilities assumed to fail, facilities may be expected to function if appropriateness of the expectation has been demonstrated. (The pressure, temperature, water level, etc. of the nuclear reactor) Facilities assumed to fail are not expected to recover. Effects of availability of external power sources shall be taken into consideration. Operating conditions of facilities for dealing with severe accidents and others The time to implement the countermeasures is set in consideration of the training records, etc. The operating conditions, capacity, and delay time are set based on the design specifications. If there is uncertainty about the operating environment, its effects shall be considered. Singular failures are not assumed. The appropriateness of operating procedures related to the countermeasures shall be demonstrated. 4. (Application of conservative assumptions and conditions is not denied) Codes that have been verified through experiments and others and are with the appropriate scope of application shall be used. When a model with high uncertainty is used or if the scope of application of a verified model is exceeded, its impacts shall be taken into consideration appropriately based on the results of sensitivity analysis, etc. As a principle, the analysis shall cover up to the time point when the accident has been cleared and the nuclear reactor and the nuclear reactor containment vessel have reached a stable condition. (At least seven days, assuming that no outside support is available. If the stable condition is reached in a period less than seven days, it must be demonstrated that the stable condition may be maintained.) If there are several countermeasures being implemented, the effectiveness of each shall be evaluated. 4. The output distribution at the core, core flow rate, decay heat, and other parameters shall be of realistic values supported by design values, etc. Conditions applicable to facilities for dealing with design base accidents The design values are used for the capacity of facilities. (If values other than the design values are used, the grounds and appropriateness for using the value must be demonstrated.) Instrumental errors are not taken into consideration for operation set points and other parameters. Except for facilities assumed to fail, facilities may be expected to function if appropriateness of the expectation has been demonstrated. (The pressure, temperature, water level, etc. of the nuclear reactor containment vessel) Facilities assumed to fail are not expected to recover. Effects of availability of external power sources shall be taken into consideration. Operating conditions of facilities for dealing with severe accidents and others The time to implement the countermeasures is set in consideration of the training records, etc. The operating conditions, capacity, and delay time are set based on the design specifications. If there is uncertainty about the operating environment, its effects shall be considered. Singular failures are not assumed. The appropriateness of operating procedures related to countermeasures shall be demonstrated. 4. (Application of conservative assumptions and conditions is not denied) As a principle, the analysis shall cover up to the time point when the water level of spent fuel storage pool has resumed to the original level and the water level and temperature have reached a stable condition. (At least seven days, assuming that no outside support is available. If the stable condition is reached in a period less than seven days, it must be demonstrated that the stable condition may be maintained.) Common conditions for effectiveness evaluation Conditions inside of the spent fuel storage pool It is assumed that fuels for the entire core that have been taken out in the shortest period possible after the nuclear reactor shutdown are being temporarily stored, separately from stored fuels. Decay heat shall be evaluated appropriately taking into consideration the fuel composition, burn-up, etc. and based on the design. 4. (If values other than the design values are used, the grounds and appropriateness for using the value must be demonstrated.) Instrumental errors are not taken into consideration for operation set points and others. Except for facilities assumed to fail, facilities may be expected to function if appropriateness of the expectation has been demonstrated. (The stand-by conditions of facilities and effects of changes of temperature, water level, etc. of the spent fuel storage pool) Facilities assumed to fail are not expected to recover. Effects of availability of external power sources shall be taken into consideration. Operating conditions of facilities for dealing with severe accidents and others The time to implement the countermeasures is set in consideration of the training records, etc. The operating conditions, capacity, and delay time are set based on the design specifications. If there is uncertainty about the operating environment, its effects shall be considered. 4. Safety Design Evaluation d. 43 Severe accidents and others Matters to be considered in analyses (Prevention of damages to fuel assemblies in nuclear reactors that have been shut down) Method and scope of effectiveness evaluation Best estimate method is applied. (Application assumptions and conditions is not denied) of conservative As a principle, the analysis shall cover up to the time point when the accident has been cleared and the nuclear reactor has reached a stable condition. 4. Safety Design Evaluation d. 44 Severe accidents and others Matters to be considered in analyses (Prevention of damages to fuel assemblies in nuclear reactors that have been shut down) Common conditions for effectiveness evaluation (cont’d.) The flow rate at the nuclear reactor core, decay heat, and other parameters shall be of realistic values supported by design values, etc. Conditions applicable to safety facilities The design values are used for the capacity of facilities. (If values other than the design values are used, the grounds and appropriateness for using the value must be demonstrated.) Instrumental errors are not taken into consideration for operation set points and others. Except for facilities assumed to fail or that are exempted from stand-by, facilities may be expected to function if appropriateness of the expectation has been demonstrated. (The pressure, temperature, water level, etc. of the nuclear reactor) Facilities assumed to fail or that are exempted from stand-by are not expected to recover. Effects of availability of external power sources shall be taken into consideration. Operating conditions of facilities for dealing with severe accidents and others The time to implement the countermeasures is set in consideration of the training records, etc. The operating conditions, capacity, and delay time are set based on the design specifications. If there is uncertainty about the operating environment, its effects shall be considered. Singular failures are not assumed. The appropriateness of operating procedures related to the countermeasures shall be demonstrated. 4. Safety Design Evaluation d. 45 Severe accidents and others Probabilistic risk assessment (PRA) Used for extracting accident sequence groups of individual plants For nuclear power stations and other large-scale, complicated systems, the system safety (or risks) may be evaluated comprehensively and quantitatively with regard to all possible accidents that could occur, by estimating and assessing the probability of occurrence of the accidents and their impacts. 4. Safety Design Evaluation 46 d. Severe accidents and others PRA Item Deterministic safety assessment Probabilistic safety assessment (1) Object of evaluation The most severe process is evaluated among diverse event processes that may be anticipated, by gathering events into a relatively small number of typical events and assigning conservative conditions. Events that are not conceivable in terms of technical viewpoints are excluded, but the grounds of exclusion are not clear. As a principle, all the initiating events are evaluated; in reality, however, a small number of groups of typical initiating events are evaluated. The entire spectra of event processes (all the conceivable processes) that follow the occurrence of initiating events are evaluated. (2) Handling of failures Handled pursuant to the singular failure standards. Dependent failures that arise as a result of singular failure are considered, but failures of common causes are excluded from evaluation, in view of independence of design. Multiple failure is considered, as are failures of common causes. (3) Analysis conditions Conservative conditions that bring about more severe results Nominal (realistic) conditions, as a principle Conservative conditions may be set when uncertainty is significant. (4) Analysis results Analysis values derive from representative physical quantities (parameters) for judging appropriateness of safety design, etc. Various analysis values related to risks are obtained, such as risks to the reliability of systems and equipment and the level of contribution to the risks, in addition to the risk values for evaluating comprehensive safety. The risk values, reliability, and other results are indicated by the most probable values and their uncertainty levels. 4. Severe accidents and others PRA Item Deterministic safety assessment Probabilistic safety assessment (5) Judgment on results The appropriateness of safety design and other aspects are judged based on whether the analysis values of representative physical quantities (parameters) satisfy the prescribed criteria. Judgment is made based on whether the analysis values satisfy the judgment criteria prescribed for various uses. (6) Uses/ utilization The suitability of site conditions and appropriateness of safety design are confirmed in the basic design phase. Utilized for decision-making not only in the basic design phase, but also for detailed design, operation management, maintenance, and management in the construction and operation phases. (7) Others Unable to respond with regard to hypothetical appropriateness of analyses, such as elimination of multiple failures. Difficult to reach agreement on the sufficiency of conservativeness of evaluation. 4. Source: ATOMICA, an atomic energy encyclopedia on the Internet

4. Safety Design Evaluation 49 d. Source: Shunsuke Kondo, Nuclear Power Safety, Dobunshoin, 1990, P. 196

Source: Shunsuke Kondo, Nuclear Power Safety, Dobunshoin, 1990, P. 199

4. 4. Failed Failed No core damage (d) No core damage (d) (a) Failed (b) Failed (e) The Japan Atomic Power Company Accident sequence groups (a) Loss of high-pressure and low-pressure water injection function (b) Loss of high-pressure water injection and depressurization functions (c) Loss of all AC power sources (d) Loss of decay heat removal function (e) Loss of nuclear reactor shutdown function (f) Loss of water injection function at times of LOCA (g) Containment vessel bypassing (LOCA at interface system) Handle with care; restricted to authorized persons; use outside of the purposes of use, duplication, and disclosure are prohibited 4. 安全設計評価 50 d. 重大事故等 PRA 個別プラントのPRAにより抽出すべき事故シーケンスグループの有無の 確認例 圧力 過渡事象 原子炉停止 バウンダリ 健全性 高圧炉心 低圧炉心 事故シーケンス 原子炉減圧 崩壊熱除去 冷却 冷却 グループ 成功 成功 失敗 成功 成功 成功 成功 失敗 成功 失敗 失敗 (d) 炉心損傷なし (d) (a) 失敗 (b) 成功 成功 失敗 失敗 成功 成功 成功 失敗 炉心損傷なし 失敗 失敗 失敗 失敗 The Japan Atomic Power Company 炉心損傷なし (d) 炉心損傷なし (d) (a) (b) (e) 必ず想定する事故シーケン スグループのみであること を確認(想定される起因事 象すべてでPRAを実施し、 必ず想定する事故シーケン スグループ以外の事故 シーケンスグループが抽出 された場合には、想定する 事故シーケンスグループに 追加) 事故シーケンスグループ (a)高圧・低圧注水機能喪失 (b)高圧注水・減圧機能喪失 (c)全交流動力電源喪失 (d)崩壊熱除去機能喪失 (e)原子炉停止機能喪失 (f)LOCA時注水機能喪失 (g)格納容器バイパス(インターフェイスシステムLOCA) Handle with care; restricted to authorized persons; use outside of the purposes of use, duplication, and disclosure are prohibited
