HCBBS Forum (English)
Submit Chemical Projects / Find Solutions
Amplify Your Requirements on a Broader Chemical Platform *Engineering · Technology · Equipment · Solutions*
Submit Request

Introduction to Functional Safety of Safety Instrumented Systems (SIS)

2019-09-27View Original

Thread Content

This post was last edited by live859 on 2019-11-8 09:19. Introduction to the functional safety of safety instrumented systems – I. Introduction: The document \"An Jian Zong Guan San 116\" issued by the State Administration of Work Safety sets out specific requirements for the evaluation of safety instrumented systems (SIS). These requirements include further strengthening the management of safety instrumented systems throughout their entire lifecycle, accelerating the standardization of such systems in new projects from the outset, and actively promoting the evaluation of safety instrumented systems that are already in use. Additionally, the safety instrumented system assessments and improvements for existing installations must be completed by the end of 2019; new \"Safety Production Licenses\" will not be issued for old installations or new projects that do not have a safety instrumented system in place or that have not undergone SIL classification. In the future, there will be an increasing number of tasks related to safety instrumented systems, and these tasks will become increasingly important. Based on this, this article will introduce the knowledge regarding functional safety of safety instrumented systems. Standards such as IEC61508, IEC61511, and ISA84 provide detailed descriptions of the overall lifecycle of safety instrumented systems. It is a structured process, where the activities at various stages are not isolated from one another; rather, it constitutes a complete system with certain logical relationships and sequences among its components. The safety life cycle of the Safety Instrumented System SIS is divided into 3 phases: the analysis phase, the implementation phase, and the operation phase. Risk management is carried out during the analysis phase, with the main tasks being the analysis of hazards and risks, as well as the identification of measures to reduce those risks. During the implementation phase, it is necessary to consider the technologies, architecture, and testing intervals used in the SIS system, as well as to evaluate the system’s availability and security in order to meet its performance requirements. Finally, during the operation phase, safety monitoring prior to startup is necessary; engineers must verify whether the system meets all safety requirements and whether all SIF circuits satisfy the required SIL levels. Moreover, detailed documentation is required for every maintenance and modification of the system. During the life cycle of a safety instrumented system, hazard identification is carried out in the initial stage, usually using methods such as HAZOP analysis or WHAT-IF analysis, to identify hypothetical accident scenarios with high risks. Subsequently, a semi-quantitative analysis is conducted on these high-risk scenarios; here, the Layer of Protection Analysis (LOPA) method is generally employed to determine whether safety instrumented functions (SIFs) are necessary, while also specifying the SIL level requirements for the SIF circuits. Next, the technical requirements for the safety instrument functions SIF are specified in the Safety Requirements Specification (SRS), including the SIL level, testing intervals, reliability requirements, as well as input and output specifications. Once the SRS parameters are determined, the next step is to carry out SIL verification for the SIF circuit. In accordance with the requirements specified in the Safety Requirements Specification (SRS), failure data and architectural constraints related to the devices in the SIF circuit are collected, in order to determine the SIL level achieved by that circuit. Finally, there is the operation phase, which requires periodic maintenance, online testing, and offline inspections to ensure the system’s performance. II. Safety Instrumented System A Safety Instrumented System (SIS) is a system composed of sensors, logic operators, and final control elements, designed to bring the installation into a safe state when process conditions deviate from normal. The functions of the safety instrumented system include, 1, monitoring the status of the production process to determine whether any potential hazardous conditions exist during production. 2. When dangerous conditions arise, it automatically carries out its designated Safety Instrumented Functions (SIF) to prevent the occurrence of dangerous events. In other words, once the safety instrument system performs its normal safety functions, no hazardous events will occur. 3. Mitigate the impact of hazardous events, that is, reduce risks by minimizing losses or the consequences of those impacts. In some cases, the purpose of a safety instrument system in fulfilling its safety functions is to reduce risks, or in other words, to decrease the probability of potential hazards occurring. In other cases, the purpose of implementing safety instrument functions is to mitigate the consequences of hazardous events that have already occurred; in yet other cases, it is a combination of both approaches. SIF, or safety instrument function, reflects whether a safety instrument system is able to carry out its safety functions effectively, with each safety instrument function being designed to provide protection against specific risk scenarios. In safety instrumented functions, the key actions vary depending on the different hazardous accident scenarios being discussed. In practical systems, a thorough understanding of various aspects such as control, equipment, and process procedures is required to properly design safety instrumented functions SIF. The safety instrumented system SIS includes multiple safety instrument functions SIF. A sensor or an actuator may belong to multiple SIFs (Safety Instrumented Function loops); for example, if the parameter monitored by sensor S-1 exceeds the set value, it can trigger the operation of final actuator No. 6. At the same time, the S-2 sensor can also activate actuator No. 6. The SIL level corresponding to different SIFs can vary, as the risks associated with the hypothetical accident scenarios for each SIF circuit are not identical. Meanwhile, for the same SIF loop, the required SIL level may also differ in two different accident scenarios. It cannot be said that the entire SIS system is of SIL-1 level. The differences between safety instrumented systems (SIS) and basic process control systems (BPCS) confuse many beginners; since these two types of systems appear similar in terms of logical structure, why is it necessary to make a distinction between them? Now let’s talk about their differences. 1. The functions performed by the two are different; a basic process control system is a system used for controlling regular production processes. According to statistics, over 95% of control systems in industry are basic process control systems. It can be seen that BPCS performs basic production control functions to meet the requirements for the proper operation of the production process. SIS is used to monitor the status of the production process, identify hazardous conditions, and prevent accidents from occurring. 2. The two have different operating modes: SIS is passive and in a dormant state, while BPCS is active and dynamic; it is designed to meet production requirements, hence it needs to operate dynamically to ensure the continuous and stable progress of the production process. 3. Regarding failures, the two systems exhibit different manifestations. Most failures of BPCS are obvious; for example, during the production process, if a specific switching state is not achieved, it will inevitably affect normal production, and thus the fault will become apparent. Since the SIS system is in a dormant state most of the time, it is difficult to detect whether it has failed or has any hidden issues. Therefore, the SIS system requires a self-diagnosis testing system, as well as periodic offline and online tests. In IEC61508, SIL is defined as the probability that a safety-related system will perform its specified safety functions under certain conditions over a given period of time. The purpose of selecting a safety integrity level is to reduce risks to an acceptable level by lowering the probability of their occurrence. The SIL levels defined by the “high-demand operation mode” and “low-demand operation mode” in the IEC61508 standard differ from each other. The low-demand operation mode refers to a situation where the operational requirements for the safety instrumented system are no more than once per year, or no more than twice the frequency of functional tests. SIL stands for Safety Integrity Level; in simple terms, SIL is a measure of safety reliability. Each SIL level represents an order of magnitude of risk reduction; for example, a SIL-1 safety function reduces the frequency of accidents by one order of magnitude, while SIL-2 reduces the frequency of such incidents by two orders of magnitude. The UK Health and Safety Executive (HSE) investigated 34 accidents caused directly by failures in control systems and safety systems, and the results showed that 44% of these accidents were due to incorrect safety requirements. The second major cause of accidents is changes made after commissioning, accounting for 21%. Therefore, it is obvious how important it is to ensure that the safety requirements are specified correctly. In other words, a system may carry out the functions for which it was designed, but those functions may not be correct in themselves. Of the accidents caused directly by control system failures mentioned earlier, 44% were resulting from incorrect safety requirement specifications. So, how should SIF’s safety requirement specifications be formulated? Definition in the IEC61511 standard: A specification that encompasses all the requirements for Safety Instrumented Functions (SIF). Its goal is to specify the requirements needed in detailed process safety information. Before drafting the safety requirement specifications, we need to collect the following information: 1. Conceptual process safety design. 2. Hazard analysis and risk assessment, 3. Application of protective layers for non-safety instrumented systems. 4. Determine the safety integrity level for the essential safety instrument functions. These contents must be valid and complete. If these processes do not exist or are imperfect, no matter how much time is spent formulating system specifications, the resulting security requirements will be incorrect. When safety requirement specifications specify that an SIF loop should achieve a safety integrity level of SIL-2, how should we design the system architecture? If we use sensors, logic controllers, and final actuation elements of SIL-2 to form a 1oo1 configuration, can we achieve an SIL-2 rating for the SIF circuit? The answer is that it is not necessarily possible to achieve SIL-2. This is because the overall average hazardous failure probability PFD of a safety instrumented system is approximately equal to the sum of the average hazardous failure probabilities of each component, namely the sensor, the logic controller, and the final actuator. Then, it is possible to consider using SIL-3 equipment to implement SIL-2 SIF circuits, but the cost in such a case would likely be much higher. So we focus more on implementing redundant structures. Such as 1oo2, 2oo3, etc. Here, a redundant structure of 1oo2, 2oo2, and 2oo3 can be seen. In the first 1oo2 structure, as long as one of the devices is functioning properly, the system will not experience a catastrophic failure, which significantly reduces the probability of such failures. However, the probability of a safety failure increases, because as long as one device experiences a safety failure, it can cause the system to stop operating abnormally. If a 2oo2 redundant architecture is chosen, both devices must detect a deviation in the process parameters simultaneously before the safety instrumented function circuit will activate. This significantly reduces the probability of safety failures (i.e., availability issues), thereby minimizing the impact of unintended shutdowns. The redundant structure of 2oo2 significantly reduces the security of the system and increases the probability of hazardous failures. The 1oo2 and 2oo2 configurations either fail to meet safety requirements or reliability requirements; therefore, in many cases people opt for the 2oo3 redundant configuration, which takes into account both safety failures and hazardous failures, representing a relatively balanced approach to redundancy. For more details, please watch the video………… – Li Qiang, Product Manager at Hangzhou Haopeng Technology Co., Ltd
Reply #22019-09-27
Not bad! I’ve learned it.* It’s worth studying carefully!
Reply #32019-10-12
The attachment failed to be decompressed. Why do I keep encountering such problems? It’s wasting my money
Reply #42019-10-17
:) The osmanthus is fragrant – it’s a wonderful time!
Reply #52019-10-17
You need to download all four at once before you can unzip them. I’m sorry!

Submit a Project

**Looking for Chemical Technology, Equipment & Solutions?** No Registration Required Broader Platform Exposure | Global Chemical Service Provider Connections

Submit Request — Free Consultation

Disclaimer

This is an automated machine translation of the original thread. Some technical terms may have inaccuracies; the original text shall prevail. Click "View Original" at the top right to access the source page, which supports IP-based automatic real-time language translation. Please watch out for contact details and sales inducements to prevent fraud. All content and translations are for reference only, representing solely the poster's personal views. For enquiries, email service@hcbbs.com.