Thread Content
Dear experts, the SIS system is required to be designed as fail-safe, but since no such requirement exists for the DCS system, does it still need to be designed as fail-safe?
Normal instrument actuators should all be chosen to be fail-safe; otherwise, what is the purpose of specifying FC/FO/FL?
DCS doesn’t insist. Truncation is done based on actual requirements, but in general, a fail-safe approach is adopted.
This post was last edited by feng*aosa on 2019-6-12 at 17:20. The full name of fail-safe is the fail-safe principle. All control devices must comply with this principle. It refers to the design principle that enables a device or system to prevent catastrophic consequences in the event of a security failure, and to automatically direct the device to a safe location. Ensuring the safety and availability of control devices are two contradictory aspects. DCS and SIS differ in their focus on safety: SIS emphasizes the safety of the entire installation as well as the production system; in other words, errors are not allowed to occur ; DCS emphasizes availability; in simple terms, any error (loss of functionality) must not affect the operation of other functions.
I agree with what you said. Our design institute now requires that DCS systems also have a fail-safe design. Do we have any regulatory requirements in this regard?
GBT 20438 \"Functional Safety for Electrical and Electronic Programmable Electronic Safety-Related Systems\" GBT 21109 (IEC61511.1) \"Functional Safety for Safety Instrumented Systems in the Process Industry\"