Professional Documents
Culture Documents
IICA FunctionalSafetyDeMystified 2017-07-19
IICA FunctionalSafetyDeMystified 2017-07-19
TOPICS
What is Functional Safety?
◦ SIS, SIF and SIL
Explains how to
comply with 4.5 day TÜV FSEng course in 45 minutes!
AS IEC 61511-2004 ◦ One day course also available
1
21/07/2017
IEC SIS
SIS SIS
61508 integrators &
device integrators & users
users
manufacturers SIL 1-3
SIL 4
IEC SIS
for process
61511 integrators & users
industries
SIL 1-3
Integrators & users in the process industries can use either IEC 61508 or
IEC 61511
IEC 61511 is generally simpler to apply
2
21/07/2017
Basic Terminology
Sensing subsystem Logic subsystem Final element subsystem
3
21/07/2017
5 Installation, commissioning
and validation
7 Modification
8 Decommissioning
4
21/07/2017
5
21/07/2017
5 Installation, commissioning
and validation
7 Modification
8 Decommissioning
A hazard
PSV-1
LIC
1
300t LPG
Product
Feed
P-1 P-2
6
21/07/2017
H LIC
1
300t LPG
Product
Feed
P-1 P-2
Risk
The product of severity and likelihood
Consequence
severity
Major
Medium
Minor Likelihood
LOW MEDIUM HIGH of occurrence
“The expected value of loss”
7
21/07/2017
Is risk acceptable ?
Hazard - 300t of LPG
LAH Alarm
Process out of control Level Increasing
Impact / Consequence
8
21/07/2017
5 Installation, commissioning
and validation
7 Modification
8 Decommissioning
9
21/07/2017
LAH Alarm
Process out of control Level Increasing
LZHH Trip
Hazardous situation High Pressure
PSV
Hazardous event Vessel fails
LZT
2
PSV-1
H
LIC
1
300t LPG
Product
Feed
P-1 P-2
10
21/07/2017
11
21/07/2017
5 Installation, commissioning
and validation
7 Modification
8 Decommissioning
12
21/07/2017
Cause-and-Effect Diagram
SIFs commonly documented by
Cause and Effect diagrams
Should include required SIL somewhere – examples:
OPENS VALVE UV-03C
Trip Point
Units
SIF
Tag# Description
BS-01 Burner Loss of Flame 12 ~ ~ X X X
PSL-01 Fuel Gas Pressure Low ~ 7 X X X
13
21/07/2017
5 Installation, commissioning
and validation
7 Modification
8 Decommissioning
Standards Compliance
14
21/07/2017
Types of failures
Random failures – components (“elements”) wear out
◦ use high reliability components
◦ use redundant components
◦ test frequently
◦ automated and/or manual
15
21/07/2017
16
21/07/2017
Appropriate to the
◦ potential consequence of the event
◦ SIL of the SIF
◦ novelty and complexity of the application and technology
SIL Verification
LZHH SIL 2
2
LZT
2
PSV-1
H
LIC
1
300t LPG
Product
Feed
P-1 P-2
17
21/07/2017
Standards Compliance
18
21/07/2017
SFF
Undetected
SAFE
Closes Detected
spontaneously by voltage control
due to loss
of energy
Detected
DANGEROUS by diagnostics
Stuck at Undetected
open
19
21/07/2017
LZT
2
PSV-1
H
LIC
1
300t LPG
Product
Feed
P-1 P-2
20
21/07/2017
Standards Compliance
21
21/07/2017
SIL Verification
LZHH SIL 2
2
LZT
2
PSV-1
H
LIC
1
300t LPG
Product
Feed
P-1 P-2
22
21/07/2017
Reliability data:
◦ Valve: λDU = 1/20y (= 0.05 y-1) LZHH
PFDavg = λDU x TI / 2
= 0.05 x 1 / 2 = 0.025 for valve
0.001 x 1 / 2 = 0.0005 for logic solver
0.01 x 1 / 2 = 0.005 for transmitter
Total PFDavg = 0.025 + 0.0005 + 0.005 = 0.0305
Calculated SIL = 1 (PFDavg range 0.01 – 0.1)
Required SIL = 2 Not OK!
How can this be fixed?
Reliability data:
◦ Valve: λDU = 1/20y (= 0.05 y-1) LZHH
PFDavg = λDU x TI / 2
= 0.05 / 12 / 2 = 0.002 for valve
0.001 / 12 / 2 = 0.00004 for logic solver
0.01 / 12 / 2 = 0.0004 for transmitter
Total PFDavg = 0.002 + 0.00004 + 0.0004 = 0.00244
Calculated SIL = 2 (PFDavg range 0.001 – 0.01)
Required SIL = 2 OK
BUT operations object to monthly testing !
23
21/07/2017
Standards Compliance
Target SIL must be specified for each SIF
based on hazard and risk analysis
Processes for SIS throughout lifecycle must comply
Each SIF must meet target SIL requirements for:
◦ Hardware Fault Tolerance (architectural constraints)
◦ random failure rate (PFDavg)
◦ Systematic Capability of each component.
24
21/07/2017
OR
meet requirements for Prior Use (or “proven in use”):
◦ sufficient experience gained in a comparable application
25
21/07/2017
Component Certification
An independent organisation certifies that the component meets the
requirements of IEC 61508 for a particular SIL
◦ not only “TÜV” !!!
The certificate also usually also includes failure data and whether the
component is “Type A” or “Type B”
◦ details are in a companion report
26
21/07/2017
27
21/07/2017
Standards Compliance
Target SIL must be specified for each SIF
based on hazard and risk analysis
Processes for SIS throughout lifecycle must comply
Each SIF must meet target SIL requirements for:
◦ Hardware Fault Tolerance (architectural constraints)
◦ random failure rate (PFDavg)
◦ Systematic Capability of each component
5 Installation, commissioning
and validation
7 Modification
8 Decommissioning
28
21/07/2017
Standards Compliance
Target SIL must be specified for each SIF
based on hazard and risk analysis
Processes for SIS throughout lifecycle must comply
Each SIF must meet target SIL requirements for:
◦ Hardware Fault Tolerance (architectural constraints)
◦ random failure rate (PFDavg)
◦ Systematic Capability of each component
29
21/07/2017
that, for specific inputs, the outputs meet in all respects the objectives
and requirements set for the specific phase” (IEC 61511 3.2.92)
30
21/07/2017
31
21/07/2017
5 Installation, commissioning
and validation
7 Modification
8 Decommissioning
32
21/07/2017
H
LIC
1
300t LPG
Product
Feed
P-1 P-2
5 Installation, commissioning
and validation
End User 6 Operation and maintenance
7 Modification
8 Decommissioning
21 July, 2017 IICA - FUNCTIONAL SAFETY DEMYSTIFIED 66
33
21/07/2017
Summary 2 – Requirements
Target SIL must be specified for each SIF
based on hazard and risk assessment
Processes for SIS throughout lifecycle must comply
Each SIF must meet target SIL requirements for:
◦ Hardware Fault Tolerance (architectural constraints)
◦ random failure rate (PFDavg)
◦ Systematic Capability of each component.
Need more?
IICA runs the following courses:
TÜV Rheinland Functional Safety Engineer course
◦ For those with 3+ years experience in functional safety
◦ Leads to Functional Safety Engineer (TÜV Rheinland) qualification
◦ Sydney 16-20 October 2017
◦ Melbourne June 2018 (exact date set Dec 2017)
34
21/07/2017
Questions?
35