Thread Content
The seven stages of chemical engineering technology from concept to industrialization (Issue 52/100) —— Technology finalization: SIL classification. Dear friends: Hello everyone! In the previous issue, we discussed the application of HAZOP analysis during the process package stage, identifying hazardous scenarios that require safety instrumented interlock protection. In this issue, we will build on the outcomes of HAZOP to discuss SIL classification – how to transition from qualitative hazard identification to quantitative safety requirements. The SIL classification serves as a bridge between HAZOP and SIS design. HAZOP states that \"an interlock is needed here for protection,\" but it does not specify how reliable this interlock should be. The SIL classification answers this question: What level of reliability is required? Is SIL1 sufficient, or is SIL2 required? I. What is SIL? SIL stands for Safety Integrity Level, which refers to the level of safety integrity. It is an indicator for measuring the reliability of a safety instrument function; the higher the level, the stricter the requirements. Four levels: SIL1 to SIL4. In chemical plants, SIL1 and SIL2 are common, while SIL3 is less common; SIL4 is almost non-existent—because reaching the SIL4 level indicates that the inherent safety level of the existing process is too low. In such cases, it is usually necessary to change the process layout or design approach to address the issue, rather than trying to compensate by adding more monitoring instruments and shut-off valves. The SIL level essentially corresponds to the factor by which the risk is reduced. SIL1 requires a risk reduction of at least 10 times, SIL2 requires at least 100 times, SIL3 requires at least 1000 times, and SIL4 requires at least 10,000 times. This multiplier is not determined arbitrarily; it is calculated quantitatively through LOPA analysis. The results of the SIL classification directly determine the hardware configuration and operation and maintenance requirements for the SIS circuit. SIL1 can accept a single-channel configuration — one sensor, one logic controller, and one actuator. SIL2 typically requires a redundant configuration – either one-out-of-two or two-out-of-two for sensors, and the actuators may need a partial stroke testing function to verify their availability. SIL3 requires higher redundancy and fault tolerance – sensors may need a two-out-of-three configuration, logic controllers and power supplies must be redundant, and actuator elements must be capable of online testing. II. LOPA: The bridge from qualitative to quantitative analysis. LOPA stands for Layer of Protection Analysis, which is an analysis of protection layers. It is the core method that connects HAZOP qualitative analysis with SIL quantitative classification. The basic logic of LOPA is not complex. Starting from the high-risk scenarios identified through HAZOP, follow a causal chain: what is the initial event of this scenario, and how often does it occur? – this is the frequency of the initial event. What independent protective layers are available to prevent this scenario from turning into an accident—and these are the failure probabilities of those protective layers. After the reduction of these protective layers, what is the frequency of accidents left – this is the accident frequency after the reduction. Whether this frequency is below the acceptable standard is the basis for determining the SIL level. An example will make it more intuitive. Overheating of the reactor can lead to an explosion, which is a scenario with serious consequences. The initial event is a disruption in the cooling water supply—assuming such a disruption occurs once a year. The first protection layer is the DCS temperature alarm coupled with operator intervention – the operator manually starts the backup cooling pump upon receiving the alarm; the failure probability of this protection layer is typically set at 0.1. The second protective layer is the existing safety valve, which activates when overpressure occurs; its failure probability is typically set at 0.01. With these two layers of protection, the accident frequency is equal to the initial event frequency of 0.1 multiplied by 0.01, which is one in a thousand per year. If the acceptable accident frequency is one in 10,000 per year, that means the risk needs to be reduced by at least another factor of 10 – an additional SIL1 interlock circuit is required. If it needs to be reduced by another 100 times, it becomes SIL2. The key to LOPA analysis lies in the values of the parameters. How should the initial event frequency be determined? There are industry databases available for reference regarding the failure rates of general equipment – there is failure data available for pumps, valves, transmitters, and controllers. There are also standards for the failure probability of protective layers – 0.01 is typically used for safety valves, 0.1 for DCS alarms combined with operator intervention, and values ranging from 0.1 to 0.01 for fire and explosion prevention facilities. These data are not chosen arbitrarily; they must be supported by authoritative sources, such as the standards of the International Automation Federation or the data manuals from the Center for Chemical Process Safety. Here, a common misconception should be specifically pointed out: do not consider operator intervention to be a universal safeguard. The operator may not be on site, may be dealing with other alarms, may make mistakes due to stress, or may not react in time. The failure probability of operator intervention is usually not lower than 0.1; in scenarios with particularly severe consequences—where the risk of casualties is extremely high and environmental damage is irreversible—operator intervention alone is insufficient, and a more reliable automatic protection layer is necessary. III. How to determine acceptable risk criteria: There is an issue that cannot be ignored in LOPA analysis – what is the acceptable frequency standard for accidents? This standard is not a technical issue, but a decision related to risk management. Different types of consequences have different acceptable standards. The risk of casualties is typically estimated to be between one in a million and one in a hundred thousand per year, which is a commonly accepted standard internationally. The environmental impact risk depends on the amount of leakage and the degree of impact on surrounding sensitive targets. The risk of asset loss is typically determined by a company based on its own risk tolerance, and can be quantified as a threshold for acceptable economic losses. During the process package phase, there may be no established internal company standards to rely on for acceptable risk criteria. At this time, industry standards are usually referred to, or the owner’s experience with similar projects is taken into account. It is important that, regardless of the criteria used, they be clearly stated in the SIL classification report along with the rationale. During future reviews, if the standards become biased, all SIL levels will need to be re-evaluated. IV. How are the results of the SIL classification reflected in the process package? Once the SIL classification is completed, the results cannot remain solely in the LOPA report. It needs to be reflected in the design documents of the process package. First, the SIL level of each interlock circuit must be indicated on the interlock logic diagram. It’s not enough to simply write “SIL2”; rather, the design requirements corresponding to SIL2 must be reflected—such as whether the sensors are configured in a redundant manner, whether there are requirements for online testing of the actuator elements, and what the testing interval is. Secondly, the instrument data sheet should indicate the SIL suitability of each SIS instrument. The sensors, logic controllers, and actuators of SIS must all have certifications corresponding to the appropriate SIL level. Not any transmitter can be used in a SIL2 circuit – it must be SIL-certified. Furthermore, the distinction between SIS and DCS on the PID must be clear. With the SIL classification results, it becomes clear which instruments on the PID belong to the SIS and which belong to the DCS. For the same controlled variable that requires both DCS control and SIS interlock, separate sensors must be used, and this must be clearly indicated in the PID settings. Finally, the SIL classification report itself, as a technical attachment to the process package, together with the HAZOP report and the interlock logic diagrams, constitutes a complete set of documents for process safety design. The detailed SIS design and SIL verification in the subsequent basic design and detailed design phases are both based on the SIL classification report from the process package phase. V. Common issues in SIL classification There are several points worth noting regarding the SIL classification process. One is that the SIL level is set too high. Some projects, in order to achieve \"greater safety,\" set many circuits at SIL2 or even SIL3. However, a higher SIL level implies more complex hardware configurations, stricter maintenance testing requirements, and a greater risk of unintended stops. Accidental stops can result in significant losses for continuous production systems. Safety isn’t about the higher level being better; it’s about achieving the right balance – reducing risks to an acceptable level. Another is ignoring the impact of test intervals on the SIL level. The reliability of SIL certification is maintained through regular testing. If a SIL2 circuit requires functional testing every six months, and the equipment’s major maintenance cycle is one year, then it is not possible to conduct offline testing for that circuit during the six-month period between maintenance sessions. In such cases, an online testing scheme needs to be designed, or actuator elements that allow for online partial stroke testing should be used. If the issue of testing intervals is not considered during the process package phase, a dilemma may arise during operation: either refuse to start up the system in violation of safety requirements, or continue operating despite the inability to meet the testing requirements. Another one is common cause failure analysis. This is a question raised by a reader in the previous issue’s comments; it’s very pertinent. For circuits of SIL2 and higher levels, if the two redundant sensors are installed in the same fitting, a leak in the weld of that fitting can cause both sensors to lose pressure simultaneously – resulting in redundancy failure. If redundant cables are laid in the same layer of the same tray, a fire or mechanical damage could simultaneously interrupt both signal paths. Therefore, when determining the SIL level, it is necessary to conduct a common-cause failure analysis of the redundancy configuration to ensure that the redundant channels are truly independent from one another in terms of physical location. VI. In-depth Understanding of SIL Classification at the Process Package Stage Finally, let’s discuss to what extent the SIL classification should be carried out during the process package stage, as well as its connection with subsequent stages. The SIL classification during the process package phase involves determining the SIL level for each interlock circuit, as well as specifying the corresponding configuration requirements – whether it is SIL1 or SIL2, whether redundant sensors are needed, and whether the actuating elements require an online testing function. At this stage, there is no need to perform SIL verification calculations; that is done during the detailed design phase – when accurate reliability calculations are carried out based on the actual failure data of the specific equipment models selected, to verify whether the requirements of the SIL level can be met. But if the classification is not determined during the process package stage, it will cause problems at the basic design stage. Those in the instrumentation field don’t know how to configure SIS circuits – whether to use single or dual sensors, and whether the actuating elements should have an online testing function. The safety team is unsure whether the protective layer is sufficient, so an LOPA analysis needs to be conducted. Everything is pushed downstream, resulting in high costs for rework and delays in progress. For projects whose SIL classification is completed at the process package stage, the basis for SIS design becomes clear. The SIL verification in the subsequent detailed design phase is merely based on the data from the actual selection to check whether the requirement can be met; it does not overturn the configuration scheme already determined during the process package phase. Preview for the next issue: Issue 53 – Calculation of safety valve discharge rates: Fire, refrigerant supply interruption, power outages, and full opening of control valves. The SIL classification has been completed, and the safety levels for all interlock circuits are now established. But there is another important safety device that needs to be designed—the safety valve. How is the discharge volume of a safety valve calculated? How should the heat transfer rate under fire conditions be determined? How to estimate the leakage rate when the refrigerant is interrupted? What should be done in the case of a power outage and when all control valves are fully open? To be continued in the next issue.
The original poster’s series of posts is truly excellent; each one is packed with useful information! The experiences shared by the previous colleagues regarding risk matrices and instrument failure data are very useful; a semi-quantitative approach combined with internal scoring reference tables can indeed help reduce discrepancies, and that’s exactly what we do as well. Regarding SIL classification, I would like to add something that is often overlooked: after the SIL classification is determined, SIL verification (calculating PFDavg) is usually required, and this step particularly often encounters difficulties in identifying the failure modes of the safety functions. For example, when the same instrument is used in multiple SIF circuits, the risk of common cause failure must be assessed separately; otherwise, the verification results may be overly optimistic. It is recommended to leave a 20% margin when conducting verification, or simply follow the simplified formula in IEC 61511, to avoid discovering that the requirements are not met during later debugging. Furthermore, during the \"technology finalization\" stage mentioned by the original poster, the SIL classification should be closely linked to the results of the HAZOP analysis; if the HAZOP nodes are divided too broadly or too finely, it will affect the accuracy of the classification. If possible, align the scope boundaries with the process and equipment teams before grading, which can save a lot of rework.