12.07.2015 Views

AADvance Safety Manual - Tuv-fs.com

AADvance Safety Manual - Tuv-fs.com

AADvance Safety Manual - Tuv-fs.com

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>AADvance</strong> <strong>Safety</strong> <strong>Manual</strong>Both input and output modules undergo regular diagnostics testing during operationthat is managed by the processor modules. The self-tests are coordinated betweenmodules that are configured in a fault tolerant arrangement, to ensure that the systemremains on-line even in the case of a demand during the execution of the tests. I/Ochannel discrepancy and deviation monitoring further enhances the verification andfault detection of module or field failures.The processor reports any detected I/O fault to the Workbench application andprovides an alarm signal for a central alarm indicator. A front panel LED indications onthe faulty module will indicate a module or field fault. In all cases, even in the presenceof a fault during this period, the system will continue to be able to respond whenconfigured in a fault tolerant arrangement.When a channel is not capable of reporting a value within a safety accuracyspecification of 1% of the full scale measurement 'safe' values are reported by thevariables. Thus, an I/O point fault condition results in a fail-safe state.The maximum duration for single-channel operation of I/O modules dependson the specific process and must be specified individually for each application: Input modules can operate in a simplex arrangement without time limit for SIL3and lower applications. Output modules can operate in a simplex arrangement without time limit for SIL3de-energize to action applications. Output modules can operate in a simplex arrangement without time limit for SIL2energize to action applications or for up to the MTTR when used in SIL3 energizeto action applications. Processor modules can operate in a simplex arrangement without time limit forSIL2 applications or for up to the MTTR when used in SIL3 applications.The application program must be designed to shut down a SIL3 equipment if afaulty module has not been replaced within the MTTR to meet the appropriaterestrictions stated above.When a module is operating in a dual mode (or is degraded to a dual mode) and a statediscrepancy occurs, then if no module fault is detected, the state reported to theapplication will always be the lower of the two states for a digital and analogue moduleconfigurations.In safety critical applications, the channel discrepancy alarms shall be monitoredby the application program and used to provide an alarm to the plant operationspersonnel.5-2 Document number 553630 Issue 7: February 2010

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!