Safety Considerations Guide, Tricon v9.0 - Tuv-fs.com

Safety Considerations Guide, Tricon v9.0 - Tuv-fs.com Safety Considerations Guide, Tricon v9.0 - Tuv-fs.com

13.07.2015 Views

34 Guidelines for Tricon ControllersDesign RequirementsDuring an override, properoperating measures should beimplemented. The time span foroverriding should be limited to oneshift (typically no longer than 8hours). A maintenance overrideswitch (MOS) light on the operatorconsole should be provided (oneper a controller or process unit).DCSProject Engineer,Commissioner, DCS,TriStationResponsible PersonTriStationOperating RequirementsThe following table describes operating requirements for handling maintenanceoverrides when using serial communication.Operating RequirementsDCSResponsible PersonTriStationMaintenance overrides areenabled for an entire controller orfor a subsystem (process unit).Controller activates an override.The operator should confirm theoverride condition.Controller removes an override.Operator,Maintenance EngineerOperator,Maintenance EngineerOperator,Maintenance EngineerMaintenance Engineer,Type ApprovalMaintenance Engineer,Type ApprovalMaintenance EngineerTricon Safety Considerations Guide

Guidelines for Tricon Controllers 35Additional RecommendationsThe following procedures are recommended in addition to the recommendationsdescribed in the tables on page 33 and page 34:• A DCS program should regularly verify that no discrepancies exist betweenthe override command signals issued by a DCS and override-activatedsignals received by a DCS from a PES. The following diagram depicts thisprocedure:Safety-Instrumented SystemControllerSensorsSafeguardingApplicationProgramActuatorsPES Block DiagramHard-WiredSwitchMaintenanceOverride Handling(Application Program)OperatorWarningDistributedControl SystemInputsEngineeringWorkstation• Use of the maintenance override capability should be documented in a DCSor TriStation log. The documentation should include:– Begin- and end-time stamps of the maintenance override.– Identification of the maintenance engineer or operator who activates amaintenance override. If the information cannot be printed, it should beentered in a work-permit or maintenance log.– Tag Name of the signal being overridden.– Communication packages that are different from a type-approvedModbus should include CRC, address check, and check of thecommunication time frame.– Loss of communication should lead to a warning to the operator andmaintenance engineer. After loss of communication, a time-delayedremoval of the override should occur after a warning to the operator.Chapter 2Application Guidelines

<strong>Guide</strong>lines for <strong>Tricon</strong> Controllers 35Additional Re<strong>com</strong>mendationsThe following procedures are re<strong>com</strong>mended in addition to the re<strong>com</strong>mendationsdescribed in the tables on page 33 and page 34:• A DCS program should regularly verify that no discrepancies exist betweenthe override <strong>com</strong>mand signals issued by a DCS and override-activatedsignals received by a DCS from a PES. The following diagram depicts thisprocedure:<strong>Safety</strong>-Instrumented SystemControllerSensorsSafeguardingApplicationProgramActuatorsPES Block DiagramHard-WiredSwitchMaintenanceOverride Handling(Application Program)OperatorWarningDistributedControl SystemInputsEngineeringWorkstation• Use of the maintenance override capability should be documented in a DCSor TriStation log. The documentation should include:– Begin- and end-time stamps of the maintenance override.– Identification of the maintenance engineer or operator who activates amaintenance override. If the information cannot be printed, it should beentered in a work-permit or maintenance log.– Tag Name of the signal being overridden.– Communication packages that are different from a type-approvedModbus should include CRC, address check, and check of the<strong>com</strong>munication time frame.– Loss of <strong>com</strong>munication should lead to a warning to the operator andmaintenance engineer. After loss of <strong>com</strong>munication, a time-delayedremoval of the override should occur after a warning to the operator.Chapter 2Application <strong>Guide</strong>lines

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!