Академический Документы
Профессиональный Документы
Культура Документы
com
excellence in dependable automation
On-line Lesson
1
Introduction to Safety
Instrumented Systems
Topics:
• SIS Definitions
• SIS Purpose
• Safety Instrumented Function
• Laws/Regulations/Standards
• Risk Reduction
• Failure Modes
• SIS Equipment
2
Safety Instrumented System Definition
REACTOR
PT
1
TT
2
PT
2
TT
3
TT
1
3
IEC 61508 Definition
Power Output Input PT
CPU 3
Supply Module Module
REACTOR
PT
1
TT
IEC 61508 does not use the
term Safety Instrumented
2
PT
2
TT
IEC 61508 does not use the term Safety Instrumented System (SIS).
Instead it uses the term Safety Related System (SRS) to mean the same
thing. Many expect the 61508 standard to be updated to the newer term -
SIS.
4
Safety Instrumented System
Functional Definition
Power Output Input PT
CPU 3
Supply Module Module
REACTOR
PT
1
TT
2
PT
2
TT
3
TT
1
SIS
Power CPU Output Input
Supply Module Module
BPCS
e ida.com Copyright exida.com 2002
excellence in dependable automation
A SIS is much like a basic process control system (BPCS) in that both have
sensors, logic solvers and final elements. But a SIS operates in a
completely different mode and unique design and maintenance, or
mechanical integrity requirements are needed.
5
Layers of Protection - Controller
High level
Normal behavior
process value
Low level
Time
6
Layers of Protection - Alarms
High level
Normal behavior
process value
Low level
Time
7
Layers of Protection – Safety Instrumented
System
High level
Normal behavior
8
Incident If that does not work, there may
be an incident...
High level
Normal behavior
process value
Low level
Time
e ida.com Copyright exida.com 2002
excellence in dependable automation
9
Permissive function of SIS
Reset master
fuel trip relay(s)
10
Integrated Control System
High Performance
Control
Ultra High Low Cost Control
Availability
Safety System
11
Safety Instrumented System
Loop 1
1 Sensors
Loop 2 Final elements
2
6
3
Logic
Loop 3 4 Solver Loop 4
5 7
Loop 5
8
e ida.com Copyright exida.com 2002
excellence in dependable automation
12
Safety Instrumented Function (SIF)
Loop 1
1
Logic
Solver 6
Sensors
Final elements
13
Safety Instrumented Function Examples
14
SIF Sensors
15
Sensors
SIF Logic Solver
A SIS has a logic solver. This is typically a special purpose PLC but can
also be a relay system or solid state logic. The controller reads signals from
the sensors, executes pre-programmed functions designed to prevent or
mitigate a potentially dangerous process hazard and takes action by
sending signals to final elements.
16
SIF Final Elements
Final
Elements
17
Safety Instrumented Function (SIF)
Implementation
Sensing Signal
Element Conditioning Logic Solver Signal Final Control
Conditioning Element
Sensing Signal
Element Conditioning
Circuit Utilities Final Control
i.e. Electrical Power, Element
Sensing
Instrument Air etc.
Element
Interconnections
18
Safety Instrumented System vs.
Basic Process Control System
Safety Instrumented Basic Process Control
System (SIS) System (BPCS)
Inputs Outputs Inputs Outputs
PT PT
1A 1B
I/P
FT
A SIS appears in many ways like a control system and many of the
technical skills needed for good control system design are needed for
SIS design.
A SIS appears in many ways like a control system and many of the
technical skills needed for good control system design are needed for SIS
design. There are important differences however.
19
Safety Instrumented System Design
SIS
However, unlike control system design, there are special considerations and
additional requirements because of the critical nature of the application. SIS
design is also the subject of national regulations and international standards.
e ida.com Copyright exida.com 2002
excellence in dependable automation
20
Laws and Regulations
In many countries of the world legislation, national laws and acts, is passed
to protect people and the environment. Many examples from Europe and
the United States come to mind. Regulations are often issued by various
governmental bodies in support of legislation. In the United States for
example, the Clean Air Act resulted in the Environmental Protection Agency
issuing various regulations.
21
“Listed” Standards
¾ European Standard referencing an EU Directive
22
Standards
¾ Other national documents/standards
VDI/VDE 2180, NE 31
NFPA 8502, FM7605
State of the Art
Standards that are not referenced by legislation or regulation do not have the
force of law. However, it is generally recognized that these standards show
consensus regarding best technical practices and many companies choose
to follow them (or parts of them).
23
Most Influential Documents
24
9
ISA84.01 Safety Life Cycle
Not Covered
by S84.01
Define Target SIS Installation,
Commissioning Covered by
Start SIL
and Pre-startup S84.01
Acceptance Test
All the standards propose the use of a "safety life cycle." Safety lifecycle
analysis is a methodology used to insure that risks have been properly
managed, that they have been identified, that the necessary steps have
been taken to mitigate those risks. The safety lifecycle can be viewed simply
as a logical process for SIS design and operation.
25
Inherent Risk
The objective is the safety lifecycle process is reduce risk. Inherent Risk is
defined the amount of risk in a completed process design resulting from a
given quantities of materials and given process parameters.
26
Risk Reduction
Risk of the
Process
L Increasing Risk
i
k
e
l
i
h
o Unacceptable
Risk Region
o
d Tolerable Risk
ALARP
Risk Region
Region
Consequence
e ida.com Copyright exida.com 2002
excellence in dependable automation
27
Non-SIS Risk Reduction
Consequence
e ida.com Copyright exida.com 2002
excellence in dependable automation
28
SIS Risk Reduction
Consequence
e ida.com Copyright exida.com 2002
excellence in dependable automation
If this reduction in the likelihood still leaves the estimated process risk too
high, safety instrumented functions are often designed to reduce risk further.
29
Safety Integrity Levels
SIL 4 >=10
- 5to <10
- 4 100000 to 10000
SIL 3 >=10
- 4to <10
- 3 10000 to 1000
SIL 2 >=10
- 3to <10
- 2 1000 to 100
SIL 1 >=10
- 2to <10
- 1 100 to 10
The needed risk reduction is expressed in order of magnitude targets called safety
integrity levels. The IEC61508 standard shows four levels with the highest risk
reduction called SIL4, the lowest risk reduction called SIL1. Risk reduction levels
are shown in the right column of the SIL chart.
Risk reduction in a particular set of equipment chosen for a safety system is
measured by the probability that it will fail when needed. This is called “failure on
demand.” This is a measure used to determine if the design meets need. It is
shown in the middle column of the SIL chart.
30
The equipment used in control and
Safety Instrumented Systems has
more than failure mode.
One key difference between control system design and SIS design is the
realization that the way in which a piece of equipment fails is very important.
The failure modes of equipment used to implement a control system or a SIS
can be classified in two important failure categories - safe and dangerous.
31
35
Multiple Failure Modes
If the switch fails such that it does not conduct electricity no matter which
position it is in, that failure is called “open circuit.” In a normally energized
safety system, that de-energizes an output and is considered fail-safe.
If a switch fails such that it always conducts electricity no matter what the
switch position, that failure is called “short circuit.” It is potentially dangerous
in a normally energized SIS.
32
Boiler Example
PRESSURE
SWITCH
STEAM
SAFETY
PLC
FUEL VALVE
NATURAL GAS
33
Successful Operation
For normal + + For normal
operation, Normally Energized Systems operation,
switch is output switch
closed. is energized.
Pressure
For abnormal Sense Solid State For abnormal
operation,
switch opens.
Switch
Discrete Input PLC Output Switch operation,
output switch
de-energizes.
LOAD
The safety instrumented system consists of the switch, a PLC and the valve.
As long as the SIS is operating successfully, it will respond to high pressure
process demand. When operating successfully, the switch reads the
pressure, the PLC does timing and opens or closes its output switch. The
valve stays open when pressure is normal and closes when pressure goes
too high. The steam boiler is kept safe and operating as long as the safety
instrumented system is operating successfully.
34
36
Fail - Safe
System
+ + causes
Normally Energized Systems false trip!
Pressure
Sense Solid State
Switch
Discrete Input PLC Output Switch
LOAD
Input Circuit fails
such that the Logic Solver fails to -
PLC thinks the read logic 1 inputs,
sense switch is fails to solve logic, Output Circuit
open even when or fails to generate fails open
it is closed. logic 1 output. circuit.
If the SIS fails safely, it causes a false trip, it shuts the boiler down when it
should not have. This can certainly be caused by an open circuit failure of
the output device, It can also be caused by many types of failures of
components all through the system.
Input switch,
Input Circuits fail.
PLC fails,
Output Circuits,
Valve fails.
35
37
Fail - Danger
If Pressure
+ + goes high -
Normally Energized Systems system
cannot
Pressure respond.
Sense Solid State
Switch
Discrete Input PLC Output Switch
LOAD
Input Circuit fails
such that the Logic Solver fails to -
PLC thinks the read logic 0 inputs
sense switch is that indicate danger, Output Circuit
closed even fails to solve logic, fails short
when it is open. or fails to generate circuit.
logic 0 output.
e ida.com Copyright exida.com 2002
excellence in dependable automation
This is bad but it can especially be bad because these failures are likely to be
undetected in normal operation. The output is supposed to be energized. If
it fails energized, operators and maintenance personnel do not notice a
difference.
36
38
PFS
RELIABILITY
Nuisance Trip
AVAILABILITY
PFD
The area of this box represents successful or failed operation of the system.
The white area is successful operation. This is normally measured by a
parameter called availability or reliability. While reliability or availability are
important for an SIS, the other important metrics are called PFS, probability
of failing safety,
PFD, probability of failing dangerously and
RRF, risk reduction factor, the inverse of PFD.
37
Higher Availability
RELIABILITY
PFS
Lower Failure
AVAILABILITY
Rate
PFD
38
Higher Safety
SIS SAFETY
RELIABILITY
PFS
AVAILABILITY
39
Special Purpose SIS Equipment
• Many instrumentation
CCM
CCM
I/O
I/O
I/O
I/O
I/O
I/O
I/O
I/O
I/O
I/O
I/O
I/O
I/O
I/O
I/O
I/O
I/O
I/O
manufacturers build special
products for SIS
applications. This
equipment performs control
ODM
and logic functions like
normal controllers. This
equipment also meets
special requirements for
high availability and fail-
safe operation.
e ida.com Copyright exida.com 2002
excellence in dependable automation
40
The Functional Safety Certification Program
• Independent, internationally
recognized testing-agency
• A certification program for
equipment used in critical
installations
• Benefits vendor by improving
product and minimizing the
need to supply evaluation
systems
• Benefits user by supplying
impartial evaluation of system
41
Introduction to Safety
Instrumented Systems
Topics:
• SIS Definitions
• SIS Purpose
• Safety Instrumented Function
• Laws/Regulations/Standards
• Risk Reduction
• Failure Modes
• SIS Equipment
This lesson has covered the basics of SIS. Safety instrumented functions
were defined and described. Standards compliance, risk reduction and SIS
failure modes were also presented. Functional safety equipment certification
was reviewed. The participant should have an understanding of the
differences between basic process control systems and safety instrumented
systems. Please take the lesson quiz to verify correct understanding and
review the lesson if necessary.
42
More Information
We hope you have found this lesson useful. If have any questions, they may
sent via email to info@exida.com. Please refer to this particular lesson -
Introduction to Safety Instrumented Systems.
Additional resources are available from the exida website including a series
of free articles that may be downloaded. Books, reports and engineering
tools are available at exida on-line store.
Exida.com is a knowledge focused on system reliability and safety. We
provide training, tools, coaching, and consulting. For general information
about exida, please view our detail website - www.exida.com.
Thank you for your interest. Consider other lessons in the on-line training
series from exida.com.
43