Safety Considerations Guide, Tricon v9.0 - Tuv-fs.com

Safety Considerations Guide, Tricon v9.0 - Tuv-fs.com Safety Considerations Guide, Tricon v9.0 - Tuv-fs.com

13.07.2015 Views

12 Hazard and Risk Analysis▼PES Steps in a Safety Life Cycle:1 Develop a safety requirement specification.An SRS consists of safety functional requirements and safety integrityrequirements. An SRS can be a collection of documents or information.Safety functional requirements specify the logic and actions to be performed byan SIS and the process conditions under which actions are initiated. Theserequirements include such items as consideration for manual shutdown, loss ofenergy source, etc.Safety integrity requirements specify a SIL and the performance required forexecuting SIS functions. Safety integrity requirements include:• Required SIL for each safety function• Requirements for diagnostics• Requirements for maintenance and testing• Reliability requirements if the spurious trips are hazardous2 For conceptual design, an engineer should:• Define the SIS architecture to ensure the SIL is met; e.g. voting 1oo1,1oo2, 2oo2, 2oo3• Define the logic solver to meet the highest SIL if different SIL levels arerequired in a single logic solver• Select a functional test interval to achieve the SIL• Verify the conceptual design against the SRS3 Develop a detail design including:• General requirements• SIS logic solver• Field devices• Interfaces• Energy sources• System environment• Application logic requirements• Maintenance or testing requirementsTricon Safety Considerations Guide

Hazard and Risk Analysis 13Some key ANSI/ISA S84.01 requirements are:• The logic solver shall be separated from the basic process control system• Sensors for SIS shall be separated from the sensors for the BPCS• The logic system vendor shall provide:– MTTF data– Covert failure listing– Frequency of occurrence of identified covert failures• Each individual field device shall have its own dedicated wiring to thesystem I/O. Using a field bus is not allowed!• A control valve from the BPCS shall not be used as a single final elementfor SIL3• The operator interface may not be allowed to change the SIS applicationsoftware• Forcing shall not be used as a part of application software or operatingprocedures• When on-line testing is required, test facilities shall be an integral part ofthe SIS design4 Develop a pre-start-up acceptance test procedure that provides a fully functionaltest of the SIS to verify conformance with the SRS.5 Before startup, establish operational and maintenance procedures to ensure thatthe SIS functions comply with the SRS throughout the SIS operational life,including:• Training• Documentation• Operating procedures• Maintenance program• Testing and preventive maintenance• Functional testing• Documentation of functional testing6 Before start-up, complete a safety review.Chapter 1Safety Concepts

Hazard and Risk Analysis 13Some key ANSI/ISA S84.01 requirements are:• The logic solver shall be separated from the basic process control system• Sensors for SIS shall be separated from the sensors for the BPCS• The logic system vendor shall provide:– MTTF data– Covert failure listing– Frequency of occurrence of identified covert failures• Each individual field device shall have its own dedicated wiring to thesystem I/O. Using a field bus is not allowed!• A control valve from the BPCS shall not be used as a single final elementfor SIL3• The operator interface may not be allowed to change the SIS applicationsoftware• Forcing shall not be used as a part of application software or operatingprocedures• When on-line testing is required, test facilities shall be an integral part ofthe SIS design4 Develop a pre-start-up acceptance test procedure that provides a fully functionaltest of the SIS to verify conformance with the SRS.5 Before startup, establish operational and maintenance procedures to ensure thatthe SIS functions <strong>com</strong>ply with the SRS throughout the SIS operational life,including:• Training• Documentation• Operating procedures• Maintenance program• Testing and preventive maintenance• Functional testing• Documentation of functional testing6 Before start-up, <strong>com</strong>plete a safety review.Chapter 1<strong>Safety</strong> Concepts

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!