HCBBS Forum (English)
Submit Chemical Projects / Find Solutions
Amplify Your Requirements on a Broader Chemical Platform *Engineering · Technology · Equipment · Solutions*
Submit Request

Design principles for SIS safety instrumented systems (ESD emergency shutdown systems)

2024-04-22View Original

Thread Content

In the design of safety instrumented systems, IEC 61508 and IEC 61511 provide excellent internationally recognized technical specifications and references. When designing the circuits of such systems, it is necessary to adhere to the principles of reliability (safety), availability, independence, standard certification, and fail-safe operation. **Relevant documents from the State Administration of Work Safety regarding SIS safety instrumented systems. Work safety supervision and administration bureaus of all provinces, autonomous regions, municipalities directly under the Central Government, and the Xinjiang Production and Construction Corps; relevant central enterprises: To strengthen the management of safety instrumented systems in the chemical industry and to prevent and reduce accidents involving hazardous chemicals, the following guiding opinions are hereby put forward: 1. Fully recognize the importance of strengthening the management of safety instrumented systems in the chemical industry. Safety instrumented systems (SIS) in the chemical industry include safety interlock systems, emergency shutdown systems, as well as systems for detecting and protecting against toxic/harmful substances, flammable gases, and fires. The Safety Instrumented System operates independently of the process control system (such as a distributed control system). Under normal operating conditions, it remains dormant or inactive. However, in the event that any situation arises within the production equipment or facilities that could potentially lead to a safety incident, it can respond instantly and accurately, thereby bringing the production process to a safe halt or automatically transitioning it into a predetermined safe state. It must therefore possess a high level of reliability (i.e., functional safety) and be subject to proper maintenance and management. Should the Safety Instrumented System fail, it often results in serious safety accidents. In recent years, most major chemical (hazardous chemicals) accidents occurring in developed countries have been associated with malfunctions or improper configuration of such systems. Based on the consequences and risks arising from the failure of safety instrument functions, these functions are classified into different safety integrity levels (SIL1-4, with level 4 being the highest). Safety instrumented systems of different levels have varying technical requirements in terms of design, manufacturing, installation and commissioning, as well as operation and maintenance. At present, in China’s safety instrumented systems and related safety protection measures, various issues exist across all stages of their lifecycle – including design, installation, operation, and maintenance – such as insufficient hazard and risk analysis, inappropriate design choices, unreasonable redundant fault-tolerance structures, a lack of defined inspection and testing schedules, and preventive maintenance strategies that are not effective enough. It is therefore urgent to improve the standards for managing safety instrumented systems. As China’s chemical processing plants and hazardous chemical storage facilities become larger in scale and the level of automation in production processes continues to improve, it is extremely urgent and necessary to strengthen and standardize the management of safety instrumented systems. II. Strengthening the foundational work for the management of chemical process safety instrumented systems 1. Accelerate the training of technical and managerial personnel skilled in functional safety related to safety instrumented systems. Chemical engineering design and construction firms, as well as entities involved in the production and storage of hazardous chemicals, should organize specialized training on safety instruments for relevant personnel, as well as engineering and technical staff working on processes and instrumentation. This training should aim to spread knowledge related to functional safety and to familiarize them with relevant standards and regulations. Targeted training should be provided to design, installation and commissioning, as well as operation and maintenance personnel at various stages of the safety instrument system’s life cycle, so that they can master relevant professional skills such as safety instrument systems, risk analysis and control, and risk mitigation. Chemical engineering design units should spend about a year cultivating a core team of technical personnel capable of performing the functional safety design of safety instrumented systems. Chemical enterprises and hazardous chemicals storage facilities that deal with \"two key areas and one major concern\" (i.e., hazardous chemicals under strict supervision, hazardous chemical processes under strict supervision, and major hazard sources of hazardous chemicals) should accelerate the training of personnel, cultivating a group of engineering and technical experts with professional skills and knowledge of relevant standards and regulations, in order to meet the needs of implementing and strengthening the functional safety management of chemical process safety instrument systems. 2. Further improve the technical standards and certification system for chemical process safety instrument systems. Accelerate the formulation and revision of the technical standard system for chemical process safety instrumented systems. To organize research and develop a technical standard system for functional safety in China’s chemical industry, relevant departments and organizations need to formulate work plans to establish functional safety-related technical standards and application guidelines that are suited to the current safety development situation of enterprises in this industry. Promote the establishment and improvement of a functional safety certification system and mechanism suited to China’s national conditions. In accordance with \"Functional Safety of Electrical/Electronic/Programmable Electronic Safety-Related Systems\" (GB/T20438) and \"Functional Safety of Safety Instrumented Systems in the Process Industry\" (GB/T21109), a functional safety certification service system for relevant personnel, products, and organizations is being established step by step. III. Further strengthen the management of the entire life cycle of safety instrumented systems 1. Before designing a safety instrumented system, it is necessary to clarify its process safety requirements, design objectives, and underlying principles. Through process hazard analysis, it is necessary to fully identify hazards and hazardous events, scientifically determine the required safety instrumented functions, and evaluate safety risks in accordance with **laws, regulations, and standards, so as to define the necessary risk reduction requirements. Prepare the technical document on safety requirements for the safety instrumented system in accordance with the functional and integrity requirements of all safety instrument functions. 2. Standardize the design of chemical safety instrument systems. The safety instrument functions are designed and implemented in strict accordance with the technical documents specifying the safety requirements for safety instrument systems. The design of safety instrument functions is optimized through proper selection of instrumentation, structural constraints (redundancy and fault tolerance), inspection and testing schedules, as well as diagnostic techniques, to ensure that the requirements for risk reduction are met. To determine appropriately the inspection and testing cycle for safety instrument functions (or subsystems), online testing is required, and it is necessary to design methods and relevant measures for such testing. During the detailed design phase, requirements such as the inspection and testing cycle and testing methods for each safety instrumented function (or subsystem) must be defined. 3. Strict installation, commissioning, and joint verification of the safety instrumented system. A comprehensive installation, commissioning, and joint verification plan should be developed and ensured to be effectively implemented; the processes and results of commissioning (individual instrument commissioning and circuit commissioning) should be meticulously recorded, and management files should be established. After the construction contractor has completed the installation and commissioning in accordance with the design documents, the enterprise shall, prior to putting the system into operation, organize a review and joint verification of the safety instrument system in line with **laws and regulations, standards and specifications, industry and enterprise safety management requirements, as well as technical documents related to safety requirements. This is done to ensure that the safety instrument system possesses the intended functions and meets the integrity requirements, thereby being ready for safe operation. 4. Strengthen the operation and maintenance management of safety instrument systems in chemical enterprises. Chemical enterprises must develop operation and maintenance plans and procedures for safety instrumented systems to ensure that these systems can reliably perform all their safety-related functions, thereby achieving functional safety. The safety instrument functions shall be subject to regular and comprehensive inspection and testing in accordance with inspection and testing cycles that meet the requirements for safety integrity, with the testing process and results recorded in detail. It is necessary to strengthen the management of failures in equipment related to safety instrumented systems (including equipment failures, interlock actions, malfunctions, etc.) as well as their analysis and handling, and gradually establish a database for such equipment failures. It is necessary to standardize the selection of equipment related to safety instrumented systems, establish systems for the approval and evaluation of such safety instrumented equipment as well as procedures for approving changes, and continuously revise and improve these systems based on the actual usage in enterprises and equipment failures. 5. Gradually improve the management systems and internal regulations for safety instrumented systems. Enterprises should establish and improve management systems or internal technical specifications related to safety instrumented systems, integrate functional safety management into their overall safety management systems, and continuously enhance the level of process safety management. IV. Attach great importance to the management of protection measures for other related instruments. 1. Strengthen process alarm management by formulating an enterprise alarm management system and enforcing it strictly. Alarms related to the safety integrity requirements of safety instrumented functions can be managed and tested in accordance with the safety instrumented functions. 2. Strengthen the management of basic process control systems; control loops related to safety integrity requirements should be managed and tested following the safety instrumented functions, and the operational rate of automatic control loops must be ensured. 3. The detection and protection systems for toxic, harmful, and flammable gases shall be designed and implemented in strict accordance with relevant standards; to ensure their reliable operation, such systems should be independent of the basic process control system. V. Accelerate the standardization of the management of safety instrument systems in newly constructed projects from the source 1. Starting from January 1, 2016, large-scale chemical enterprises as well as those owned or jointly operated by foreign investors that meet the relevant criteria, and that construct new chemical processing units and hazardous chemical storage facilities that fall under the category of “two key areas and one major hazard,” must design safety instrument systems that comply with relevant standards, in accordance with the requirements of these guiding principles. 2. Starting from January 1, 2018, all newly constructed chemical processing units and hazardous chemical storage facilities related to the \"two key areas and one major issue\" must be designed with safety instrument systems that meet the required standards. For the safety instrument systems of other newly built chemical processing units and hazardous chemical storage facilities, starting from January 1, 2020, it is necessary to comply with the requirements of functional safety standards and design safety instrument systems that meet those requirements. VI. Actively promote the assessment of existing safety instrumented systems 1. Chemical enterprises and hazardous chemicals storage facilities that operate production units or facilities classified as “two key areas and one major hazard” should, on the basis of conducting comprehensive process hazard analyses (such as Hazard and Operability Studies), determine the functions of safety instruments and the requirements for risk reduction through risk analysis, and promptly assess whether the existing safety instrument functions meet these risk reduction requirements. 2. Enterprises should, based on the assessment, formulate a management plan for safety instrumented systems as well as a schedule for regular inspection and testing. For safety instrument functions that do not meet the requirements, relevant maintenance plans and remediation plans must be developed, with the assessment and improvement of the safety instrument system to be completed by the end of 2019. Other chemical processing units and hazardous chemical storage facilities shall be implemented in accordance with the requirements of these guidelines. VII. Work Requirements 1. Relevant enterprises and organizations shall, in accordance with relevant laws, regulations, standards, norms, and the requirements of these guiding principles, improve their management systems and frameworks for safety instrumented systems; they should also increase financial investment to ensure that the safety instrumented systems of newly built facilities meet the requirements of functional safety standards. For safety instrumented systems in operational equipment that do not meet functional safety requirements, they must be included in a remediation plan for timely correction, in order to eliminate potential accident hazards, reduce accident risks, prevent accidents from occurring, and effectively improve the inherent safety level of the enterprise. 2. Local safety supervision departments at all levels should promptly conduct investigations and research, set work objectives, identify pilot units, define progress requirements, and guide and urge enterprises to strengthen the management of safety instrumented systems in chemical processes as well as related safety protection measures. The functional safety assessment of safety instrumented systems, the implementation of management systems for such systems, and personnel training should all be included in the scope of safety inspections and audits. Provincial safety supervision bureaus are required to compile summaries of relevant inspection activities each year, and submit them to the Third Supervision Department of the **General Administration of Safety Supervision by the end of February each year. Please ask the provincial safety supervision bureaus to promptly convey the spirit of these guiding principles to the safety supervision agencies at all levels within their respective jurisdictions, as well as to the relevant enterprises and design firms. Design principles for SIS safety instrumented systems: The primary function of SIS safety instrumented systems (such as ESD emergency shutdown systems) is to automatically or manually return the process to a pre-defined safe state in the event of any hazardous failure during the production process. This ensures the safe operation of the processing equipment and prevents serious personal injuries and significant equipment damage. In the design of safety instrumented systems, IEC 61508 and IEC 61511 provide excellent internationally recognized technical specifications and references. When designing the circuits of safety instrumented systems, it is generally necessary to follow the following principles. 1. Reliability principles (safety principles) in the design of SIS – Safety Instrumented Systems (ESD – Emergency Shutdown Systems). To ensure the operational safety of process equipment, the Safety Instrumented System must possess a reliability level corresponding to the required Safety Integrity Level (SIL) for the particular process. To this end, IEC 61508 provides detailed technical specifications. For safety instrumented systems, reliability has two meanings: one is the operational reliability of the safety instrumented system itself ; Another aspect is the reliability of the safety instrumented system in terms of its understanding of the process and its ability to provide interlock protection; there should also be high reliability in the measurement, evaluation, and execution of interlocks related to the process. The main parameter for evaluating the Safety Integrity Level SIL is PFDavg (probability of failure on demand, i.e., the average rate of dangerous failures), and it is classified into levels 1 to 4 from highest to lowest. In the petrochemical industry, only SIL levels 1, 2, and 3 are generally used, as SIL level 4 requires large investments and complex systems, and is typically applied only in the nuclear power industry. 2. Availability principles for the design of SIS safety instrument systems (ESD emergency shutdown systems): To improve the availability of the system, SIS safety instrument systems (ESD emergency shutdown systems) should possess hardware and software self-diagnosis and testing functions. The safety instrumented system shall provide a maintenance bypass switch for each input process interlock signal, to facilitate online testing and maintenance while reducing shutdowns caused by maintenance of the safety instrumented system. It should be noted that the redundant detection elements used in the two-out-of-three voting scheme do not require bypassing, nor does the manual stop input require bypassing. At the same time, it is strictly prohibited to install bypass switches for the output signals of the safety instrumented system, in order to prevent accidents caused by accidental operations. If the SIL calculation shows that the testing period is shorter than the process shutdown time, and it is not possible to ensure that online testing of the actuators will not cause an unintended shutdown of the process, then the design of the safety instrumented system should be modified as necessary. This can be achieved by increasing redundancy to extend the testing period, or by using partial stroke testing methods. In addition, manual bypass valves should be added to valves that close in an emergency situation, and manual shut-off valves should be added to valves that open in such situations, so as to allow for the online testing of the safety instrumented system valves. These methods are very helpful in ensuring the availability of safety instrument systems. 3. Principle of independence in the design of SIS safety instrumented systems (ESD emergency shutdown systems): SIS safety instrumented systems (ESD emergency shutdown systems) should be independent of the basic process control systems (BPCS, such as DCS, FCS, CCS, PLCs, etc.), and carry out safety protection functions independently. The sensing elements, control units, and actuators of the safety instrumented system should be installed separately. If the process requirements call for both interlocking and control to be carried out simultaneously, the Safety Instrumented System and the BPCS should each have independent sensing elements and signal acquisition points (with some special exceptions, such as the use of a two-out-of-three sensing arrangement: three signals are fed to the DCS, while two signals are fed to the Safety Instrumented System, with the sensing elements shared through a signal distributor). If necessary, the SIS safety instrumented system (ESD emergency shutdown system) shall be able to communicate with the DCS in read-only mode via a data communication link, but the DCS is prohibited from writing information to the safety instrumented system through this communication link. The safety instrumented system should be equipped with an independent communication network, including separate network switches, servers, engineer stations, etc. The SIS safety instrument system (ESD emergency shutdown system) should utilize redundant power supplies, powered by independent dual-circuit distribution systems. It should be avoided to have the signal wiring of the safety instrumented system and the BPCS in the same junction box, as well as within intermediate junction cabinets and control cabinets. 4. Standard certification principles for the design of SIS safety instrument systems (ESD emergency shutdown systems): With the introduction of safety standards and an increasing emphasis on safety systems, the certification of such systems has become increasingly important. The design concepts and structural aspects of these systems must comply strictly with relevant international standards, and they must also receive certification from authoritative bodies. The Safety Instrumented System must be certified to the corresponding SIL level under IEC 61508 SIL and/or TUV AK (Germany). The hardware, software, and instruments used in the SIS safety instrument system (ESD emergency shutdown system) must adhere to official standards and be commercially available; furthermore, they must obtain mandatory certifications related to explosion protection, metrology, pressure vessels, etc. The use of any test products is strictly prohibited. 5. Fail-safe principle: When components, equipment, elements, or energy sources within the SIS (Safety Instrumented System/ESD – Emergency Shutdown System) malfunction or fail, the design of the SIS must ensure that the process can proceed towards a safe operation or reach a safe state. This is the fail-safe principle of system design. Whether “fail-safe” can be achieved depends on the process and the design of the safety instrumented system. The entire SIS safety instrumented system (ESD emergency shutdown system), including the field instruments and actuators, should be designed in such an absolutely safe manner that: ① the field contacts shall give an alarm when open, and remain closed under normal operating conditions ; ②The on-site actuator is de-energized during interlock, but energized under normal operating conditions.

Submit a Project

**Looking for Chemical Technology, Equipment & Solutions?** No Registration Required Broader Platform Exposure | Global Chemical Service Provider Connections

Submit Request — Free Consultation

Disclaimer

This is an automated machine translation of the original thread. Some technical terms may have inaccuracies; the original text shall prevail. Click "View Original" at the top right to access the source page, which supports IP-based automatic real-time language translation. Please watch out for contact details and sales inducements to prevent fraud. All content and translations are for reference only, representing solely the poster's personal views. For enquiries, email service@hcbbs.com.