A Preventable Catastrophe: What the CSB's Findings on the Longview Tank Failure Reveal About Asset Integrity Management

PAPER INDUSTRY NEWSMARKET ANALYSIS

Jino John

8/31/20265 min read

On May 26, 2026, a 1.2-million-gallon carbon steel storage tank at the Nippon Dynawave Packaging (NDP) pulp mill in Longview, Washington, catastrophically failed, releasing roughly 900,000 gallons of scalding, highly caustic white liquor. Eleven employees were killed and three more were seriously injured, including a member of the plant's own medical response team who waded into the pool of chemical believing it was water. Nearly three months later, the U.S. Chemical Safety and Hazard Investigation Board (CSB) has released an investigative update that transforms this event from an unexplained industrial accident into what appears, on the available facts, to be a foreseeable failure of asset integrity management.

The technical picture: a documented, quantified, and ignored defect

The most striking element of the CSB's update is not that the tank failed, but that its failure mode was known well in advance. In July 2025 — roughly ten months before the rupture — an inspection contractor performed ultrasonic thickness testing on the exterior shell of "G Tank" and found significant wall thinning in the lower shell courses, in places falling below the calculated minimum safe thickness required to hold the tank's contents safely. This is not an ambiguous or borderline finding. In tank integrity engineering (governed in U.S. practice largely by API 653, the standard for atmospheric storage tank inspection, repair, alteration, and reconstruction), a wall thickness reading below the calculated minimum required thickness (t-min) is a hard trigger: the vessel is, by definition, no longer capable of safely containing its design pressure and product at that location. The contractor's report reflected this unambiguously, characterizing the tank as unfit for continued service without repair and flagging a high likelihood and high consequence of failure — the kind of language that, on a standard risk matrix, sits in the "stop work" quadrant, not the "monitor and revisit" quadrant.

What happened next is the crux of the story. Rather than triggering an internal inspection, a shell repair, a derate of the tank's fill limit, or removal from service — the corrective actions the contractor explicitly recommended — NDP left the tank in unrestricted operation. Two subsequent external inspections, in October 2025 and February 2026, reconfirmed that large areas of the shell remained below minimum thickness. In other words, the company had three independent data points over roughly seven months, each reaffirming the same deficiency, and none of them altered the tank's operating status. That is not a single missed signal; it is a repeated, sustained decision — or failure to decide — to continue operating equipment that had been formally assessed as unfit.

The trigger event: an ordinary upset, an extraordinary consequence

The CSB's timeline of the morning of the failure is also instructive, because it shows how a routine, unremarkable operational event became the proximate trigger for catastrophe. Shortly before 2:00 a.m., a digester elsewhere in the mill was taken out of service for repairs — an entirely normal maintenance action. Because G Tank could no longer discharge white liquor into that digester, liquor continued flowing into the tank from upstream while outflow stopped. The tank approached full capacity by around 6:20 a.m. and failed roughly forty to fifty minutes later, just as the day shift was arriving.

This sequence matters because it illustrates a core principle of process safety: a degraded vessel does not need an extraordinary event to fail — it only needs the operating envelope to shift in a way that a healthy vessel would have absorbed without incident. A tank at or near its calculated minimum wall thickness has little to no margin left for the additional hydrostatic head of a near-full fill. In a sound vessel, routing liquor to a tank during a digester outage is unremarkable. In a vessel already known to be structurally compromised, it was the last variable needed to convert a known defect into a fatality event.

Why this looks like a management systems failure, not a knowledge failure

Root-cause investigations of major process safety incidents — from the 2005 Texas City refinery explosion to the 2013 West Fertilizer explosion — consistently show the same pattern: the hazard was technically knowable and often already known, but organizational systems failed to translate that knowledge into action. The Longview case fits this pattern closely. There is no indication in the CSB's update that NDP lacked the technical information needed to prevent this failure. The information existed, in writing, from a qualified contractor, on three separate occasions. What appears to have failed is the mechanical integrity program's authority to actually stop or restrict operation of equipment that inspection data says should be stopped or restricted — a gap between the inspection function and operational decision-making that CSB Chairperson Steve Owens pointed to directly, stating the agency was concerned that the tank had not been promptly removed from service or properly repaired following the inspection findings.

There is also a notable gap on the emergency response side. According to the CSB, when the mill's medical emergency response team was radioed for assistance, the call did not communicate that a caustic chemical release, rather than a water release, was underway. That gap in information likely contributed to a responder walking into the liquor pool and suffering serious chemical burns. Effective emergency response protocols for chemical releases depend on early and accurate hazard communication; a generic "medical emergency" call to a scene involving 60-plus°C caustic liquid materially changes the risk calculus for first responders.

The limits of the record so far

It is worth being precise about what the CSB has and has not established. The board has been explicit that its investigation is ongoing and that it has not yet determined the technical cause of the rupture itself — that is, the update establishes that the tank was known to be substandard and remained in service, but does not yet draw a direct causal line from the thinning to the specific failure mechanism (e.g., brittle fracture, ductile overload, weld failure, or another mode). Nippon Dynawave's president has publicly stated the company is disappointed with the update, characterizing it as omitting relevant context and timeline detail about actions the company took. The workers' union, AWPPW, while calling the findings deeply troubling, has similarly cautioned against drawing conclusions about causation or legal responsibility ahead of the final report. Readers should weigh the update accordingly: it establishes a damning integrity-management timeline, not yet a completed causal chain.

What should follow

Three things typically follow a finding of this kind in CSB investigations: a set of specific engineering and management-system recommendations in the final report (often addressed not just to the operating company but to industry bodies and sometimes regulators); parallel state-level enforcement, evidenced here by the Washington Department of Ecology's issuance of 35 environmental-violation notices to NDP; and, frequently, changes to how the broader pulp and paper sector treats "conditional" inspection findings — that is, findings that recommend action but do not, by themselves, force an automatic shutdown. The central lesson emerging from this update, even before the final report, is one the industry has learned before and will likely need to relearn here: an inspection report recommending removal from service is only as protective as the management system that acts on it.