Thread Content
This post was last edited by Senjougen Nadyo on 2020-1-15 08:48. When conducting LOPA analysis, BPCS is discussed as an independent protection layer; one view is that the control circuit of BPCS can have at most two options, provided that the sensors and final actuating elements are independent, which can reduce the risk by a factor of 100 at least, making it easy to achieve the risk control objectives. Another view is that BPCS, as an independent protection layer, can be used at most once; in other words, BPCS can reduce the risk factor by a maximum of 10 times, which limits the choices available for protection layers. With different choices, the conclusions of LOPA analysis can vary greatly; the latter analysis may require more SIF loops, while the former lacks support from regulations and standards. For instance, if an accident occurs due to the absence of an effective protective layer, it is difficult to argue against this, raising doubts about the validity of LOPA analysis. This paper mainly explores how much risk factors BPCS can reduce in an accident scenario, with the aim of providing a reference for engineers conducting LOPA analyses. BPCS (Basic Process Control System) is a control system that carries out routine normal production functions during the production process, such as PID control and integral control. Basic process control systems are in contrast to complex “advanced” process control systems such as those for process optimization. According to statistics, over 95% of control systems in industry are basic process control systems. It can be seen from this that the basic process control system performs basic production control functions to meet the requirements for the proper operation of the production process. Therefore, under certain conditions, the BPCS control loop can serve as a safety protection measure; CCPS CPQRA (2000a) considers LOPA analysis to be a simplified quantitative risk analysis method (semi-quantitative). This simplification includes assumptions regarding the numerical values of scenario elements (initial event frequency, triggering events (enabling factors), number of independent protection layers, and failure frequency values), as well as simplified calculation methods. However, these simplifications adopt a conservative approach (that is, the number of protection layers and the failure frequency of these layers are chosen conservatively); therefore, if quantitative risk analysis (event trees, fault trees) is used entirely, the risk analysis results for the accident scenarios will be lower than those obtained using LOPA. In the IEC61511 standard, \"Safety Instrumented Systems for Process Industries\" – Part 1 states that \"as a protective layer, the risk reduction factor [BPCS] should be less than 10.\" This means that the probability of failure for all of BPCS’s risk reduction functions should be greater than 1E-1. In other words, in the event of an accident, BPCS can function only as an independent protective layer to reduce risks. This article will discuss the matter from several perspectives, including standard specifications (IEC61511 for safety instrumented systems in process industries and LOPA guideline AQT3054-2015) as well as the possible PFDs (Probability of Failure on Demand) for various components in BPCS control loops. It is hoped that this approach will encourage reflection among readers, thereby preventing incorrect use of the LOPA analysis method or a lack of analytical basis that could lead to inaccurate results. When citing standard specifications, it is necessary to be clear about their prerequisites and not overestimate the effectiveness of the protective layer. I. IEC61511-1(2016) The following are the relevant provisions in IEC61511-1 2016 regarding the BPCS as a protection layer: 9.3.2 The risk reduction factor required for the BPCS protection layer shall be less than 10. (The BPCS protection layer can only reduce the risk by a factor of 10.) Note: Another scenario to consider is that the BPCS might also be needed to protect against initial event occurrences. (That is, a BPCS failure could lead to an accident scenario.) 9.3.3 If it is required that the risk reduction factor for the BPCS protection layer be greater than 10, then the design and management of the BPCS must comply with the requirements of the EC61511 series. If BPCS is not intended to comply with the IEC 61511 series. Then, when BPCS is the initial event required for the protection layer in an accident scenario, for the same event scenario that leads to a hazardous event, no more than one BPCS protection layer shall be required ; Or, when the BPCS is not the initial event required for the protection layer, for the same event scenario that leads to a hazardous event, more than two BPCS protection layers should not be required. (In accident scenarios that are not caused by a BPCS failure, two BPCS protection layers can be used.) (When 9.3.4 applies, each BPCS protection layer should be independent of the initial event and separated from one another; please refer to 9.3.5.) Note: The BPCS protection layers can consist of one BPCS serving as the initial event in an accident scenario (see 8.2.2) and a second separate BPCS protection layer (see 9.3.2 and 9.3.3), or, when the initial event is not related to a BPCS failure, they can consist of up to two separate BPCS protection layers. 8.2.2 The average hazardous failure frequency of the BPCS as an initial event shall not be less than 1E-5 (i.e., PFD > 1E-1). 9.3.5 When 9.3.4 applies, each BPCS protection layer shall be independent of the initial event and separated from one another to ensure that the risk reduction required for each BPCS protection layer is not compromised. Note 1: The assessment of separation and independence can take into account what is necessary to achieve risk reduction, such as central processing units (CPUs), input/output modules, relays, field devices, application programming, networks, program databases, engineering tools, human-machine interface bypass tools, and other devices. Note 2: A hot standby controller is not considered independent of the main controller, as it is subject to common failures; for example, a hot standby controller shares components with the main controller, such as backplanes, firmware, diagnostic programs, transmission mechanisms, and undetected critical faults. According to IEC61511, when a BPCS can function as two separate protection layers, each BPCS protection layer must be independent of the initial event and separated from the other to ensure that the risk reduction required by each layer is not compromised. That is, the components of the BPCS control loop such as the processor CPU, actuating elements, and sensors are all independent and separate, with no shared parts. II. Guidelines for LOPA Application (AQT3054-2015) – Guidelines for the Application of the Protective Layer Analysis (LOPA) Method (AQT3054-2015). The description regarding BPCS as an independent protective layer is as follows: Evaluation method for multiple functional loops within the same BPCS as IPLs. 1. In the same scenario, when a single BPCS has multiple functional loops, methods A or B can be used to evaluate its IPLs. 1.1 Method A assumes that if a single BPCS circuit fails, then all other BPCS circuits that share the same logic controller will also fail. For a single BPCS, only one IPL is allowed, and it should be independent of the IE (initial event) or any enabling event. 1.2 Method B assumes that a BPCS loop fails, most likely due to a failure in the sensor or the final control element, while the BPCS logic controller remains functional. The PFD of the BPCS logic controller is at least two orders of magnitude lower than that of other components in the BPCS circuit. Method B allows the same BPCS to have more than one IPL. As shown in the figure, the two BPCS circuits use the same logic controller. Assuming that these two circuits meet the other requirements for being IPLs in the same scenario, Method A allows only one of the circuits to serve as the IPL, while Method B permits both circuits to act as IPLs in the same scenario. In the same scenario, multiple functional loops of the same BPCS serve as the data for IPL simultaneously. The requirements regarding data and data analysis are as follows: 3.1 a) Method B assumes that the PFD of the BPCS logic controller is at least two orders of magnitude lower than that of other components in the BPCS loop; there should be data to support this assumption, and that data must be analyzed. These data include: 1) historical performance data such as BPCS logic controllers, input/output cards, sensors, final actuators, and human responses ; 2) Data provided by the system manufacturer ; 3) Inspection, maintenance, and functional testing data ; 4) Instrument diagrams, Piping and Instrumentation Diagrams (P&ID), circuit diagrams, standard specifications, and other related documents ; 5) Access the BPCS to make program changes, bypass alarms, and other operations that require secure access to the BPCS. b) The analysis of these data should include: 1) Calculating the effective failure rate of the circuit components in the equipment or BPCS system ; 2) Comparison of data from various components, particularly the BPCS logic controller PFD ; 3) Assessment of the independence of logic input/output cards and related circuits ; 4) Sufficiency assessment of secure access control ; 5) The suitability of using multiple BPCS loops as multiple IPLs in the same scenario. D.3.2 The requirements for analysts are as follows: a) Analysts should be able to: 1) determine whether there is sufficient and complete data, and whether such data can enable calculations with adequate precision ; 2) Understand the design of the instruments and whether the BPCS system meets the independence requirements ; 3) Understand the impact of the recommended IPL on the process or system. b) The analysis team or personnel should possess relevant professional expertise, such as: 1) independent third-party certification with a sufficiently low PFD for BPCS logic controllers ; 2) Analysis of historical performance data and maintenance records to establish design standards ensuring that multiple BPCS circuits meet the requirements of IPL ; 3) Design and implement multiple BPCS loop systems to meet requirements such as independence and reliability. c) If the analysis team or personnel do not meet the above requirements, then when determining whether a BPCS loop functions as an IPL, it is advisable to use Method A for analysis. III. Examples of PFD calculation for various BPCS components: According to the guidelines for applying LOPA, if the PFD of a logical operator is at least two orders of magnitude lower than that of other components in the BPCS circuit, then Method B can be used, allowing both circuits to be considered as IPLs within the same scenario. At the same time, analysts are required to possess relevant professional knowledge, such as SIL verification capabilities ; This paper will use the general data from the PDS manual to verify the PFD values of various components in the BPCS control loops, and analyze whether the PFD values of the logic operators and other components meet the requirements of the LOPA application guidelines The PDS manual (Safety Instrumented System Reliability Data) provides data consistent with the latest available data sources, as well as data for some new devices. It was carried out as part of the research project on “Safety Instrumented System Integrity Management”. Note: The PDS manual is a research project initiated by users, sponsored by the Norwegian Research Council and PDS Forum participants. The verification software utilized is the SIL verification software independently developed by Hangzhou Haopeng Technology. This software has been tested and shows complete consistency in its calculation results with those obtained from certificates issued by authoritative third-party certification bodies such as TUV, E*DA, BV, etc. It is one of the leading SIL verification software solutions in China, and it is also used as an example software in TUV Trenton’s training programs. Many third-party companies in China use this software to carry out SIL verification work. 1. General data from the PDS manual: The following data comes from the PDS manual; the first section contains sensor data, of which PDS considers 70% to be reliable. Components: λDU (average): 1; λDU (70%): reliable ratings. Pressure switches: 2000–4800; proximity switches: 3000–insufficient data available. Pressure transmitters: 300–500; level transmitters: 600–1200; temperature transmitters: 300–600. For logical operators in Part II, PDS considers 70% of the available data to be insufficient, and thus uses average values (with low reliability). Component Group Component λDU(Average) 1 λDU(70%) Confidence Value Industrial PLC System Analog Input (single) 700.00 Insufficient available data CPU(1oo1) 3500.00 Insufficient available data Digital Output (single) 700.00 Insufficient available data Programmable Safety System Analog Input (single) 160.00 Insufficient available data CPU(1oo1) 480.00 Insufficient available data Digital Output (single) 160.00 Insufficient available data Hardwired Safety System Trip Amplifier/Analog Input (single) 40.00 Insufficient available data Logic System (1oo1) 30.00 Insufficient available data Digital Output (single) 30.00 Insufficient available data The third section contains data on the final actuating elements, using 70% confident data. Component λDU (average): 1; λDU (70%): reliable. Pilot/valve: 800, 1100. Control valves (excluding pilot valves) (frequent operation): 2200, 3500. Control valves (excluding pilot valves) (only for shutdown operations): 3500, 5500. 2. Assuming other parameters of the control circuit remain unchanged, in the same scenario all valves are considered as part of the IPL calculation. Sensors, logic operators, and maximum operating mode: low-demand operating mode ; Operating time (Lt): 10 years ; System startup time (Tsd): 24 hours ; System recovery time (MTTR): 24 hours. Functional testing cycle (TI): 12 months. Functional testing coverage (CTI): 95%. System restart time: 24 hours. Since redundancy is rarely used in the BPCS control loops, a 1oo1 voting structure is adopted in this example; common cause failures are not considered for now. 3. Calculation of PFD values for sensors, logic operators, and final actuation elements. 3.1 For sensors, a \"level transmitter\" was selected; the 70% confidence value for du (dangerous condition undetectable) is 1200 fit, resulting in an average PFD value of 7.6E-3. The calculation results obtained using Haopeng Technology’s SIL verification software are shown in the figure below. Note: MTTFS represents the average false operation rate; since there is no data on safety failures (SU/SD) in this case, it is not possible to calculate corresponding values. SIL (structural constraint) cannot be calculated due to the lack of an SFF failure score. 3.2 The average PFD value for the logical operator in industrial PLC systems is 3.07E-2. Note: Since in this example the PFD is calculated simply using the dangerous failure rate (DU), the “simple mode” of the SIL verification software was used for the calculations. 3.2.1 The average PFD value for the programmable safety system using logical operators is 5.72E-3. 3.2.2 The PFD value for the hardwired safety system using logical operators is 6.38E-04. The graph above shows the PFD curve for the hardwired safety system; its PFD value meets the SIL3 standard, and therefore it can theoretically satisfy the requirements of the LOPA guidelines. 3.3 For the selection of the final actuator, \"control valve (excluding pilot valves) (for shutdown only)\\" is chosen; the 70% confidence value for du (hazard not detectable) is 5500 fit, resulting in an average PFD value of 3.42E-2 (SIL-1). 4. Statistical analysis of the verification results: 1. If an industrial PLC system is used in the control loop, it can be seen that the PFD value of such systems is quite high, and it is close to the PFD value of the final actuator. In this case, the requirement specified in the LOPA guidelines, namely that the PFD value of logic operators should be two orders of magnitude lower than that of other components, cannot be met. 2. The use of a programmable safety system: The PFD value of such a system is significantly lower than that of industrial PLC systems, but it still does not meet the requirement set by LOPA guidelines, which calls for a PFD value that is two orders of magnitude lower than that of other components. 3. Hardwired safety system: If a hardwired safety system is used, the PFD of the logic operator can be two orders of magnitude lower than that of other components. The first requirement of the LOPA application guidelines has been met; however, the guidelines also explain Method B, stating that once the value is below two orders of magnitude, there must be data to support this assumption, and that such data needs to be analyzed. Additionally, the logical operator requires certification from a third party. IV. Summary: BPCS uses two circuits in the same scenario to reduce risks; according to IEC61511, sensors, logic operators, and final actuators must be completely independent, and the initial event cannot be a failure in the BPCS control circuit. According to Method B of the LOPA application guidelines, the PFD (Average Hazard Failure Rate) for logical operators is two orders of magnitude lower than that of other components, and since the data is certified by a third party and the analysts possess the necessary expertise, this method can be used. This paper calculates the PFD values for various components of the BPCS using an example from the general failure database in the PDS manual. Analysis of the calculation results shows that the PFD (average value of dangerous failures) for logic operators is two orders of magnitude lower than that required for other components, making it difficult to meet this requirement. Therefore, the author suggests that in LOPA analysis, it is generally advisable to adopt a conservative approach by treating BPCS as an independent protection layer to reduce risks; if BPCS failure is considered the initial event, then BPCS can no longer be regarded as an independent protection layer. Additionally: when BPCS is required as two protection layers to reduce risks, it is recommended that the logic operators use devices with third-party certification (such as TUV, E*DA, BV, etc.). The PFDs must meet the SIL3 standard, and operational management of the SIS system must be implemented, in order to comply with the pre-requisites for Method B outlined in the LOPA application guidelines.