Safety Considerations Guide, Tricon v9.0 - Tuv-fs.com
Safety Considerations Guide, Tricon v9.0 - Tuv-fs.com Safety Considerations Guide, Tricon v9.0 - Tuv-fs.com
20 TÜV Rheinland CertificationTÜV Rheinland CertificationWhen used as a PES in an SIS, the Tricon controller and its companionprogramming workstation, the TriStation 1131 Developer’s Workbench, havebeen certified by TÜV Rheinland/Berlin-Brandenburg to meet the requirements ofDIN 19250 AK5-AK6 and IEC 61508 SIL3. If these standards apply to yourapplication, compliance with the guidelines described in this chapter is highlyrecommended.General GuidelinesAll Safety SystemsThis section describes standard industry guidelines that apply to:• All safety systems• Emergency shutdown (ESD) systems• Fire and gas systems• Burner management systemsThe following general guidelines apply to all user-written safety applicationprograms and procedures:• Functional testing is recommended to verify the correct design andoperation.• After a safety system is commissioned, no changes to the system software(operating system, I/O drivers, diagnostics, etc.) are allowed without typeapproval and re-commissioning. Any changes to the application or thecontrol program should be made under strict change-control procedures. Formore information on change-control procedures, see section “ProjectChange and Control” on page 30. All changes should be thoroughlyreviewed, audited, and approved by a safety change control committee orgroup. After an approved change is made, it should be archived.• In addition to printed documentation of the application program, two copiesof the program should be archived on an electronic medium which is writeprotectedto avoid accidental changes.Tricon Safety Considerations Guide
General Guidelines 21• Under certain conditions, a PES may be run in a mode which allows anexternal computer or operator station to write to system attributes. This isnormally done by means of a communication link. The following guidelinesapply to writes of this type:– Serial communication should use Modbus or another approved protocolwith CRC checks.– Serial communication should not be allowed to write directly to outputpoints.– For information about writes to safety-related variables that result indisabling safety action, see section “Module Diagnostics” on page 43.• PID and other control algorithms should not be used for safety-relatedfunctions. Each control function should be checked to verify that it does notprovide a safety-related function.• An SIS PES should be wired and grounded according to the proceduresdefined by the manufacturer.Emergency Shutdown SystemsThe safe state of the plant should be a de-energized or low (0) state.For ESD functions, it is recommended that the hardware devices connected to PESoutputs should be made of fail-safe components or should have two separate,independent shutdown paths which are periodically inspected.Burner Management SystemsThe safe state of the plant should be a de-energized or low (0) state.When a safety system is required to conform with the DIN 0116 standard forelectrical equipment in furnaces, PES throughput time should ensure that a safeshutdown can be performed within one second after a problem in the process isdetected.Chapter 2Application Guidelines
- Page 1 and 2: TriconVersion 9Safety Consideration
- Page 3: AcknowledgementTriconex acknowledge
- Page 6 and 7: viRelated DocumentsRelated Document
- Page 8 and 9: viiiHow to Contact TriconexHow to C
- Page 10: xTrainingFor Turbomachinery Systems
- Page 13 and 14: xiCONTENTSAbout This Guide ........
- Page 15 and 16: xiiiAnalog Input Module Alarms ....
- Page 17 and 18: CHAPTER 1Safety ConceptsThis chapte
- Page 19 and 20: Safety Overview 3Protection LayersT
- Page 21 and 22: Hazard and Risk Analysis 5Hazard an
- Page 23 and 24: Hazard and Risk Analysis 7Completio
- Page 25 and 26: Hazard and Risk Analysis 9Equation
- Page 27 and 28: Hazard and Risk Analysis 11Flowchar
- Page 29 and 30: Hazard and Risk Analysis 13Some key
- Page 31 and 32: Safety Standards 15Safety Standards
- Page 33 and 34: Safety Standards 17Application-Spec
- Page 35: CHAPTER 2Application GuidelinesThis
- Page 39 and 40: Guidelines for Tricon Controllers 2
- Page 41 and 42: Guidelines for Tricon Controllers 2
- Page 43 and 44: Guidelines for Tricon Controllers 2
- Page 45 and 46: Guidelines for Tricon Controllers 2
- Page 47 and 48: Guidelines for Tricon Controllers 3
- Page 49 and 50: Guidelines for Tricon Controllers 3
- Page 51 and 52: Guidelines for Tricon Controllers 3
- Page 53 and 54: CHAPTER 3Fault ManagementThis chapt
- Page 55 and 56: System Diagnostics 39System Diagnos
- Page 57 and 58: Operating Modes 41Operating ModesEa
- Page 59 and 60: Module Diagnostics 43Module Diagnos
- Page 61 and 62: Module Diagnostics 45Relay Output M
- Page 63 and 64: Module Diagnostics 47System Attribu
- Page 65 and 66: CHAPTER 4Application DevelopmentThi
- Page 67 and 68: Important TriStation Commands 51Imp
- Page 69 and 70: Setting Scan Time 53Setting Scan Ti
- Page 71 and 72: Sample Safety-Shutdown Programs 55S
- Page 73 and 74: Sample Safety-Shutdown Programs 57I
- Page 75 and 76: Sample Safety-Shutdown Programs 59A
- Page 77 and 78: Sample Safety-Shutdown Programs 61P
- Page 79 and 80: Sample Safety-Shutdown Programs 63O
- Page 81 and 82: Sample Safety-Shutdown Programs 65D
- Page 83 and 84: Sample Safety-Shutdown Programs 67P
- Page 85 and 86: APPENDIX APeer-to-Peer Communicatio
General <strong>Guide</strong>lines 21• Under certain conditions, a PES may be run in a mode which allows anexternal <strong>com</strong>puter or operator station to write to system attributes. This isnormally done by means of a <strong>com</strong>munication link. The following guidelinesapply to writes of this type:– Serial <strong>com</strong>munication should use Modbus or another approved protocolwith CRC checks.– Serial <strong>com</strong>munication should not be allowed to write directly to outputpoints.– For information about writes to safety-related variables that result indisabling safety action, see section “Module Diagnostics” on page 43.• PID and other control algorithms should not be used for safety-relatedfunctions. Each control function should be checked to verify that it does notprovide a safety-related function.• An SIS PES should be wired and grounded according to the proceduresdefined by the manufacturer.Emergency Shutdown SystemsThe safe state of the plant should be a de-energized or low (0) state.For ESD functions, it is re<strong>com</strong>mended that the hardware devices connected to PESoutputs should be made of fail-safe <strong>com</strong>ponents or should have two separate,independent shutdown paths which are periodically inspected.Burner Management SystemsThe safe state of the plant should be a de-energized or low (0) state.When a safety system is required to conform with the DIN 0116 standard forelectrical equipment in furnaces, PES throughput time should ensure that a safeshutdown can be performed within one second after a problem in the process isdetected.Chapter 2Application <strong>Guide</strong>lines