Topic MYTH FUNCTIONAL SAFETY IMPLIES HAVING A SIL RATED COMPONENT. Presented by : Arunkumar A

Similar documents
PPA Michaël GROSSI - FSCE PR electronics

Changes in IEC Ed 2

New requirements for IEC best practice compliance

67 th Canadian Chemical Engineering Conference EDMONTON, AB OCTOBER 22-25, 2017

New Developments in the IEC61511 Edition 2

Technical Paper. Functional Safety Update IEC Edition 2 Standards Update

SIL Safety Guide Series MS Single-Acting Spring-Return Hydraulic Linear Actuators

Process Safety - Market Requirements. V.P.Raman Mott MacDonald Pvt. Ltd.

Assessment of the Safety Integrity of Electrical Protection Systems in the Petrochemical Industry

100 & 120 Series Pressure and Temperature Switches Safety Manual

Digital EPIC 2 Safety manual

ADIPEC 2013 Technical Conference Manuscript

IEC61511 Standard Overview

User s Manual. YTA110, YTA310, YTA320, and YTA710 Temperature Transmitters. Manual Change No

2015 Functional Safety Training & Workshops

Addressing Challenges in HIPPS Design and Implementation

United Electric Controls One Series Safety Transmitter Safety Manual

Is your current safety system compliant to today's safety standard?

INTERNATIONAL STANDARD

Implementing Safety Instrumented Burner Management Systems: Challenges and Opportunities

USER APPROVAL OF SAFETY INSTRUMENTED SYSTEM DEVICES

Safety Integrity Verification and Validation of a High Integrity Pressure Protection System to IEC 61511

Overfill Prevention Control Unit with Ground Verification & Vehicle Identification Options. TÜVRheinland

Battery Design Considerations

Safety Instrumented Systems The Smart Approach

Session Ten Achieving Compliance in Hardware Fault Tolerance

Functional Safety: the Next Edition of IEC 61511

AVOID CATASTROPHIC SITUATIONS: EXPERT FIRE AND GAS CONSULTANCY OPTIMIZES SAFETY

IEC Functional Safety Assessment

AVOID CATASTROPHIC SITUATIONS: EXPERT FIRE AND GAS CONSULTANCY OPTIMIZES SAFETY

Licensing of FPGA-based Safety Platform RadICS: Case Study

Safety Instrumented Systems

Certification Report of the ST3000 Pressure Transmitter


Measurement of Safety Integrity of E/E/PES according to IEC61508

Where Process Safety meets Machine Safety

Failure Modes, Effects and Diagnostic Analysis

Failure Modes, Effects and Diagnostic Analysis

Battery Design Considerations

Strathayr, Rhu-Na-Haven Road, Aboyne, AB34 5JB, Aberdeenshire, U.K. Tel: +44 (0)

Siemens Process Automation End-user Summit- 2011

PRIMATECH WHITE PAPER CHANGES IN THE SECOND EDITION OF IEC 61511: A PROCESS SAFETY PERSPECTIVE

InstrumentationTools.com

This document is a preview generated by EVS

Failure Modes, Effects and Diagnostic Analysis. PR electronics A/S Rønde Denmark

Process Safety Workshop. Avoiding Major Accident Hazards the Key to Profitable Operations

Certification Report of the ST 3000 Pressure Transmitter with HART 6

excellence in Dependable Automation

The agri-motive safety performance integrity level Or how do you call it?

Session Four Functional safety: the next edition of IEC Mirek Generowicz Engineering Manager, I&E Systems Pty Ltd

INTERNATIONAL STANDARD

FUNCTIONAL SAFETY IN FIRE PROTECTION SYSTEM E-BOOK

FUNCTIONAL SAFETY OF ELECTRICAL INSTALLATIONS IN INDUSTRIAL PLANTS BY OTTO WALCH

Proof Testing Level Instruments

Failure Modes, Effects and Diagnostic Analysis

Safety Instrumented Systems Overview and Awareness. Workbook and Study Guide

SAFETY MANUAL. Electrochemical Gas Detector GT3000 Series Includes Transmitter (GTX) with H 2 S or O 2 Sensor Module (GTS)

Management of installed safety instrumented systems (SIS)

DNVGL-CP-0407 Edition February 2016

Failure Modes, Effects and Diagnostic Analysis

Safe area; Zone 1 and Zone 2

The evolution of level switches and detectors

SAFETY MANUAL. Multispectrum IR Flame Detector X3301

Advanced Diagnostics for HART Protocol Rosemount 3051S Scalable Pressure, Flow, and Level Solutions

Australian Standard. Functional safety Safety instrumented systems for the process industry sector

INTERNATIONAL STANDARD

HIGH-VOLTAGE CABLE TESTING: TYPE TEST EXPERIENCES AND NEW INSIGHTS INTO PRE-QUALIFICATION

Safety in the process industry

This is a preview - click here to buy the full publication

Session Ten: The importance of a clear Safety Requirements Specification as part of the overall Safety Lifecycle

Reliability and Safety Assessment in Offshore and Process Industries

Options for Developing a Compliant PLC-based BMS

CO-ORDINATION OF NOTIFIED BODIES PPE Regulation 2016/425 RECOMMENDATION FOR USE

DNVGL-CP-0401 Edition February 2016

Practical Methods for Process Safety Management

IEC PRODUCT APPROVALS VEERING OFF COURSE

Safety and Security: Can they live together?

Integrated but separate

SAFETY MANUAL. X2200 UV, X9800 IR, X5200 UVIR SIL 2 Certified Flame Detectors

Terminal lugs for LV power cables with aluminum conductors

Fully configurable SIL2 addressable Fire & Gas Detection solutions

SAFETY MANUAL. PointWatch Eclipse Infrared Hydrocarbon Gas Detector Safety Certified Model PIRECL

Design & Use of Ground Based Pumps Guidance Document

430128A. B-Series Flow Meter SIL Safety Manual

Fire and Gas Detection and Mitigation Systems

Failure Modes, Effects and Diagnostic Analysis

Failure Modes, Effects and Diagnostic Analysis

NEW CENELEC STANDARDS & CSM-RA NEW CENELEC STANDARDS & CSM-RA 2017

Achieve Success with European Medical Device Commercialization. By Russ King

DeltaV SIS TM. for Process Safety Systems Smart Safety Loops. Reliable Process.

Functional safety according to IEC / IEC Important user information. Major changes in IEC nd Edition

Valve Manufacturers Association of America

2015 Honeywell Users Group Europe, Middle East and Africa

Value Paper Authors: Stuart Nunns CEng, BSc, FIET, FInstMC. Compliance to IEC means more than just Pfd!

SITRANS. Temperature transmitter Functional safety for SITRANS TW. Introduction. General safety instructions 2. Device-specific safety instructions

Applying Buncefield Recommendations and IEC61508 and IEC Standards to Fuel Storage Sites

DNVGL-CP-0398 Edition December 2015

Soliphant M with electronic insert FEM52

MARINE GYRO COMPASS STANDARD FOR CERTIFICATION. DET NORSKE VERITAS Veritasveien 1, N-1322 Høvik, Norway Tel.: Fax:

Low-voltage switchgear and controlgear - rated voltage does not exceed 1000V AC or 1500V DC

Transcription:

Topic MYTH FUNCTIONAL SAFETY IMPLIES HAVING A SIL RATED COMPONENT Presented by : Arunkumar A

DNV GL Who are we? Only by connecting the details can we impact the bigger picture We classify, certify, verify and test against regulatory requirements, rules, standards and recommended practices We develop new rules, standards and recommended practices We qualify new technologies and operational concepts We give expert advice

Functional Safety Introduction Family Tree IEC 61508 General Application IEC 61511 IEC 61513 IEC 62061 ISO 13849 Def Stan 00-56 EN 50126 50128 50129 ISO 26262 Process Nuclear Machinery Military Rail Automotive

Relationship between IEC 61511 and IEC 61508 PROCESS SECTOR SAFETY INSTRUMENTED SYSTEM STANDARD Manufacturers and Suppliers of Devices IEC 61508 Safety Instrumented System Designers, Integrators and Users IEC 61511

Functional Safety Lifecycle O & M O&M Installation Commissioning Validation System Design Software Development Testing SIL Verification Safety Requirements SIL Determination Hazard and Risk Assessment

Functional Safety Lifecycle O&M Installation Commissioning Validation SIL Verification Safety Requirements SIL Determination Hazard and Risk Assessment

Myth # 1: Using SIL Certified equipment/components ensures a safe system Assumption in certification inconsistent with operating profiles and physical Environment (Proven in use, failure mechanism, proof test interval etc.,) Deterioration in performance of SIFs through the life of the facility A device should not be user-approved until sufficient experience has been gained in a similar operating environment that you know how it works, how it fails, how frequently it fails, how to detect its failure, and how to correct the failure. The user of a product must feel confident that they understand the required frequency of inspection, maintenance, and proof testing to maintain its mechanical integrity in an as good as new condition.

Myth # 2: Failure Detection is more important than Failure Prevention Frequent interruption in process due to detection of failure. MTBF also need to be considered in development of the SRS.

Myth # 3: Proof Test suffices to ensure Mechanical Integrity Proof Test do not prevent the system from failure. Identifies failures but not the cause. Regular Inspection (Proactive/ Condition based Maintenance) to identify and correct incipient issues and degraded conditions. Preventive Maintenance to reduce failure rates. Root Cause Analysis- Detailed analysis of detection of failures to prevent future failures.

Myth # 4: Partial Testing is Good enough 100% of all dangerous failures are not detected. Tests only a portion of Dangerous Undetected failures.. Proactive/ Condition based Maintenance to identify and correct incipient issues and degraded conditions. Preventive Maintenance Functionality of SIS components other than valve is not checked. Proof Testing as per System design.

Myth # 5: A Vendor can determine whether a Safe System meets the IEC Requirements Many are not field proven and some are not demonstrating the robustness necessary to survive a process plant environment. Software lacks the necessary attention. A user approval process should be established to examine evidence of suitability of devices for the application and operating environment. Develop and implement a software lifecycle.

Myth # 6: Fail-Safe design of SIS is an Optimal design Fail-safe design implies poor reliability and adversely affects the availability of the plant. Reliability and availability aspects needs to be considered in developing the SRS.

How to avoid it Effective safety planning! In our experience corporate standards backed up a project specific overall Functional Safety Management Plan (FSMP) is the answer Is a Live document Describe techniques and measures FSMP Clearly define inputs and outputs from each phase. Assign responsibility

Safety Planning Functional Safety Management System Project Functional Safety Plan Competency Independent FSA-4 Verification & Approval Phase 6 Operate and Maintain the SIS Introduce the Hazards Independent FSA-3 Verification & Approval Phase 5 Install and Commission the SIS Independent FSA-2 Verification & Approval Phase 4 Design the SIS Independent FSA-1 Verification & Approval Phase 3 Specify the SIS Verification & Approval Phase 2 Allocate Safety Functions Verification & Approval Phase 1 Hazard & Risk Assessment Supplier Conformity Management Review

Stages of Typical Functional Safety Assessments Stage 1 Assessment: upto SRS development Stage 2 Assessment: SIS Design and Engineering Stage 3 Assessment: Installation Commissioning Verification Review of Hazard and risk assessment Review of SIL Allocation Review of Safety Requirements Specification Review of Hardware Architecture Review of Software Development Review of SIL Achievement Review of Test Results Review of installation Review of commissioning procedures Review of validation results Stage 4 Assessment: Operation and Maintenance Review of Operation and Maintenance after a period of operation Review of proof testing, fault and demand rate recording and system performance

Functional Safety Management The key to success Safety Planning Roles and Responsibilities Demonstration of Competency Verification

Thank you. Arunkumar Manager Safety & Risk arunkumar.arunachalam@dnvgl.com P Lakshmi Narayana Sr. Consultant Safety & Risk lakshmi-narayana.pitchandi@dnvgl.com www.dnvgl.com SAFER, SMARTER, GREENER