Professional Documents
Culture Documents
SIL - Safety Integrity Level: WIKA - Part of Your Business
SIL - Safety Integrity Level: WIKA - Part of Your Business
SIL - Safety Integrity Level: WIKA - Part of Your Business
There are several methods used to assign a SIL. These are normally used in
combination, and may include:
Risk Matrices
Risk Graphs
Layers Of Protection Analysis (LOPA)
The assignment may be tested using both pragmatic and controllability approaches,
applying guidance on SIL assignment published by the UK HSE.[1] SIL assignment
processes that use the HSE guidance to ratify assignments developed from Risk
Matrices have been certified to meet IEC EN 61508
Source: Wikipedia
Current situation:
More complex control systems in combination with critical, not safe process
fear for danger events – particular situations could not be controlled anymore.
Before applying SIL, you have to make a risk analysis of your plant acc. to
IEC 61508
General valid (not only for WIKA); only HART®-Transmitters are classified acc. to SIL
For devices used in functional safety applications (devices with SIL) is valid: WIKA have to
create a calculation called probability of failures. This covers also a FMEDA (Failure Mode
Effect and Diagnostic Analysis).
The calculated values are always valid with connected sensors only.
The WIKA Quality system have to fulfill IEC 61508 aspects,
the documentation is to use acc. to IEC 61508
For new developments with resulting in a SIL Transmitter the following is valid:
The Development process has to be done acc. to IEC 61508.
(Full assessment per IEC 61508)
This is the case for T32.1S / T32.3S
λSD
λ SD + λ SU + λ DD λSU
SFF =
λ SD + λ SU + λ DD + λ DU
λ DU
SFF = 1 −
λ λDD
RTD, 4 -wire
Cable Break (Pt100 or wire to Pt100) – Dangerous Detected 1400 FIT
Thermocouple TC
Cable Break (TC or wire) – Dangerous Detected 4740 FIT
Wire Short (TC or wire) – Dangerous Undetected 50 FIT
Drift of the TC – Dangerous Undetected 200 FIT
Resistance-Change wires or contacts – Safe Detected 10 FIT
(clamps)
=> SFF = 94,97 %
Original values from the safety manual T32.xS and from EXIDA, Low Stress environment
T1
λ DU T32.1S with 4-wire RTD = (20 + 14) * 10 -9 [h]
PFD = λDU ⋅ T1 ⋅ 0,5 = λDU ⋅
Calibration Intervals: 1 Year = 8760 h 2
PFD = 34 * 10 -9 [h] * 8760 [h] * 0,5 => PFD = 1,482 *10 -4 [h] -> is suitable for SIL4
The device-specific hints and the intended safety-related use has to be considered e.g.:
Some sensor connections are not usable for SIL-Applications (e.g. Potentiometer-
connection) some are usable for SIL1 only, some for SIL2
The limitations of the operation methods are to be considered
The hints for the Inadmissible safety-related use and the Commissioning
and periodic tests have to be considered
If the figures required for the SIL level are not reached, the designer must either implement
additional constructional measures, design his systems redundantly or take other
measures that further reduce his plant risk
T32.xS.xxx – S – xxx.xxx
If the write protection is not activated, the SIL T32.xS Transmitter will remain in the error
signalization fail low (Downscale < 3.5 mA)
Measure for the safety relevant performance of an electrical or electronical control system
A control normally system consists of three components: Sensor, Actuator, PLC
Weighting of the functional safety: For the SIL calculation, a weighting is usually used:
35% for sensor/transmitter, 15% for the logic unit and 50% for the actuator
=> Our SFF values have a weight in the calculation of max. 35%
PFDAV SIL
≥ 10-2 ... < 10-1 SIL 1
≥ 10-3 ... < 10-2 SIL 2
≥ 10-4 ... < 10-3 SIL 3
≥ 10-6 ... < 10-4 SIL 4
PFDAV SIL
≥ 10-2 ... < 10-1 SIL 1
≥ 10-3 ... < 10-2 SIL 2
≥ 10-4 ... < 10-3 SIL 3
≥ 10-6 ... < 10-4 SIL 4
Despite the fact, that several customers ask for a SIL-certificate for sensors only
(RTD/TC), there is no chance to provide these because:
The sensor without Transmitter cannot supervise itself
The sensor without Transmitter content no further electronic components
But WIKA declares the possible usage of the sensors in combination with a suitable
Temperature Transmitters
With common used values (Literature)
With own values, from own experiences
8 FMEDA
Doppelsensor Pt100 Sicherheitsfunktion für „4…20 mA Ausgang“
λDU 57 FIT
λDD 4017 FIT
λSU + λSD 119 FIT
SFF – Safe Failure Fraction 98,8 %
MTTR 8h
PFD für Tproof 1 Jahr 2,495 * 10-4
DC manual
9 FMEDA
Doppelsensor TC mit interner Sicherheitsfunktion für „4…20 mA Ausgang“
Vergleichsstelle
λDU 516 FIT
λDD 9557 FIT
λSU + λSD 117 FIT
SFF – Safe Failure Fraction 95,3 %
MTTR 8h
PFD für Tproof 1 Jahr 2,262 * 10-3
DC manual
3 FMEDA
Pt100 3-Leiter Sicherheitsfunktion für „4…20 mA Ausgang“
λDU 30 FIT
λDD 2037 FIT
λSU + λSD 118 FIT
SFF – Safe Failure Fraction 98,6 %
MTTR 8h
PFD für Tproof 1 Jahr 1,316 * 10-4
DC manual
4 FMEDA
Pt100 4-Leiter Sicherheitsfunktion für „4…20 mA Ausgang“
λDU 34 FIT
λDD 2037 FIT
λSU + λSD 119 FIT
SFF – Safe Failure Fraction 98,6 %
MTTR 8h
PFD für Tproof 1 Jahr 1,482 * 10-4
DC manual
5 FMEDA
Pt100 2-Leiter Sicherheitsfunktion für „4…20 mA Ausgang“
λDU 414 FIT
λDD 1657 FIT
λSU + λSD 118 FIT
SFF – Safe Failure Fraction 81,2 %
MTTR 8h
PFD für Tproof 1 Jahr 1,815 * 10-3
DC manual
26 SIL – Safety Integrity Level / Claus Nielsen
Which values are available for the T32?
(Thermocouple)
6 FMEDA
TC mit interner Vergleichsstelle Sicherheitsfunktion für „4…20 mA Ausgang“
λDU 265 FIT
λDD 4807 FIT
λSU + λSD 116 FIT
SFF – Safe Failure Fraction 94,9 %
MTTR 8h
PFD für Tproof 1 Jahr 1,162 * 10-3
DC manual
7 FMEDA
TC mit externer Vergleichsstelle Sicherheitsfunktion für „4…20 mA Ausgang“
λDU 664 FIT
λDD 6407 FIT
λSU + λSD 118 FIT
SFF – Safe Failure Fraction 90,7 %
MTTR 8h
PFD für Tproof 1 Jahr 2,91 * 10-3
DC manual