12.07.2015 Views

AADvance Safety Manual - Tuv-fs.com

AADvance Safety Manual - Tuv-fs.com

AADvance Safety Manual - Tuv-fs.com

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 3 Functional <strong>Safety</strong> ManagementInput Module CalibrationPlanned MaintenanceField Device MaintenanceModule Fault HandlingThe Operation and Maintenance Plan shall include re<strong>com</strong>mendations to check thecalibration of controller input modules.The calibration of each analogue input module should be checked every two years; thecalibration of each digital input module should be checked every five years.In most system configurations there will be some elements that are not tested by thesystem's internal diagnostics — for example, the final passive elements in I/O modules,the sensors and actuators themselves, and the field wiring.A regime of planned maintenance testing shall be defined to ensure that any faults,which could ultimately lead to the system's inability to perform its safety functions, donot accumulate. The maximum interval between these tests shall be defined beforeinstallation. It is highly re<strong>com</strong>mended the test interval be less than 12 months.The Operation and Maintenance Plan shall include field maintenance activities, such asre-calibration, testing and replacement of devices, which were specified by the systemdesign requirements.In general, adequate provision for these measures will be defined by the client. As longas the necessary maintenance overrides and other facilities are implemented, nofurther safety requirements will be needed.It is highly re<strong>com</strong>mended the I/O forcing capability is NOT used to support field devicemaintenance. Should I/O forcing be used to support field device maintenance, therequirements defined for 'Input and Output Forcing' in this manual shall be applied.When the <strong>AADvance</strong> controller uses modules in a dual or triple redundantconfiguration, the controller can continue to operate if one of its modules shoulddevelop a fault. However, when a module does have a fault it should be replacedpromptly to ensure that faults do not accumulate and that multiple failure conditionsresult in a plant shutdown.All modules permit live removal and replacement within a fault-tolerant configuration(dual or triple redundant configurations only). On-site repair is not supported exceptfor the replacement of fuses within some termination assemblies. All failed modulesshould be returned for repair or fault diagnosis in accordance with the warranty andreturn policy documentation delivered with your system.Document number 553630 Issue 7: February 2010 3-7

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!