HCBBS Forum (English)
Submit Chemical Projects / Find Solutions
Amplify Your Requirements on a Broader Chemical Platform *Engineering · Technology · Equipment · Solutions*
Submit Request

How do instrument technicians perform SIL verification for SIS systems

2019-12-22View Original

Thread Content

SIL calculation is a process of quantitatively evaluating the overall safety capability of the completed SIF circuit to verify whether it meets the required standards; in this article, CHANGHUI Instruments shares the methods used by instrument technicians for SIL calculation. SIL verification: yunrun.com.cn/product/2846.html. With the issuance of Document No. An Jian Zong Guan San 116 by the Third Department under the General Administration for Work Safety, starting in 2016, Safety Instrumented Systems (SIS) became a standard requirement for operational installations and new projects that fall under the category of “two key areas and one major hazard”. The policy change has given rise to an overwhelming amount of information regarding HAZOP/SIL and SIS systems. The plethora of vague and confusing terms makes it difficult for people to know what to do. The purpose of this article is to provide, in the simplest possible terms and without any beating around the bush, a straightforward explanation for instrumentation engineers who are not familiar with SIL, SIS, and SIF but have at least heard of them—namely, what SIL verification actually entails. In short, SIL assessment is a process of quantitatively evaluating the overall safety capability of a completed Safety Instrumented Function (SIF) circuit to verify whether it meets the required capabilities. In HAZOP analysis, process engineers play a more important role than instrument engineers; they are the driving force behind brainstorming, responsible for identifying various potential risks and proposing solutions. However, once the analysis is complete and the SIL classification is finalized, entering the SIL verification phase, the SIF circuits are essentially in place at this point, and it is then the instrument engineers who take charge. The SIF loop is also composed of a “sensing section – control section – actuation section”, as shown in the following image: http://yunrun.com.cn/upload/201912/21/201912210123149990.png The difference is that the system has switched from a DCS in the control loop to a safety instrumented system SIS with SIL certification. Instrument engineers familiar with control loops will quickly realize the similarities between SIF loops and control loops. No one is more familiar than you with the components within each unit of an SIF loop; thus, you are best suited to determine the SIL capability of those components. When your cooperation is needed to carry out SIL verification work, as an instrumentation engineer, what preparations do you need to make? Whether you plan to carry out the verification calculations yourself or delegate them to a third party, some of the basic procedures shown in the figure below are unavoidable. Step 1: Read the sizing report. Question 1: First, what exactly is SIL verification? The purpose of verification is to calculate the SIL level for each loop and to determine whether the required average failure probability (PFD) meets the specified requirements. If it does not meet these requirements, the selection and design of the safety instrument system need to be redone (you can search for articles on “Steps for selecting a SIS system (safety control system)” on Baidu); if it does meet the requirements, then the verification is considered successful. Therefore, the results for each loop in the verification report must be compared with those used for the classification of each loop. The average failure probability (PFD) has its own definition in the standards; simply put, it represents the likelihood of failure for the corresponding instrument/circuit. Of course, the lower the probability, the less likely something will go wrong, and thus the higher the SIL level. Undoubtedly, SIL2 represents a higher level of safety than SIL1, with a correspondingly lower average probability of failure on demand (PFD). Keeping this in mind will be very helpful when reviewing SIL verification reports later on. A good start is half the battle; a perfect SIL classification report is undoubtedly the first step toward success. Question 2: What does “perfect” mean in a perfect SIL classification report? The SIL classification report shall include the following: a complete description of the SIF circuit and its structure ; SIL rating and average failure probability (PFDavg) for each SIF circuit. As a perfect example, \"For the three temperatures TAHH2102A/B/C (2oo3) in the washing section of the SIF16 desulfurization tower, stop the combustion-supporting fan K132 or close MOV0203 (1oo2).\"” ; The signal identifiers are clear, the relationship between different signals is defined (2oo3); the actions to be performed are clear, their identifiers are also clear, and the relationship between these actions is as well defined (1oo2) ; The PFD value and SIL level are also clear. http://yunrun.com.cn/upload/201912/21/201912210135090380.png But not all SIF circuit descriptions can be as explicit as the above. Let’s take a less perfect example: “Low low level interlock of acetic acid storage tank T43201A closes valve XV-43202A”. Why is the level signal tag number missing? This situation usually occurs because, during the rating phase, the P&ID has not been finalized, or it is a signal that is planned to be added and whose tag number was not known at that time. At this point, it is only possible to rely on instrumentation engineers to identify the corresponding tag numbers in order to complete the circuit. Imperfect descriptions are a challenge that instrument engineers often face, and the biggest test comes from discovering that the SIF descriptions in the SIL classification report do not match those in the interlock circuit diagrams at hand. At this point, as an instrumentation engineer, would one not immediately feel panicked and anxious? The first thing to do is to determine whether the classification report available determines that the interlock design was completed prior to any subsequent changes; if such changes have led to alterations in the interlock circuits, then it is the most sensible approach to request an updated SIL classification report. As mentioned earlier, SIL verification relies entirely on the SIF circuits and SIL classification specified in the SIL classification report, which are used as a basis for evaluating the calculation results. If the classification report does not correspond to the actual situation, then SIL verification becomes meaningless ; If the classification report is already the latest version, it is necessary to clarify one concept here: a SIF circuit is not equivalent to an interlock circuit. While there are similarities between them, a SIF circuit focuses solely on the actions related to safety protection. Those actions that do not involve safety protection but are still necessary to carry out for operational reasons are not included in the SIF circuit; they may instead be part of the interlock circuit. See the comparison in the figure below – do you suddenly understand? http://yunrun.com.cn/upload/201912/21/201912210146548908.png Whether the report is perfect or not, understanding the classification report and assessing its reliability and usability are tasks that field instrument engineers must carry out. By comparing the classification report and specifying the model of each component in the SIF circuit, instrument engineers take the first step in providing support for SIL verification. Step 2: Collect information. Collecting information seems simple in theory but is difficult in practice. With the complex information contained in instrument records, manufacturer’s data packs, process flow diagrams, and various specification sheets, it’s hard to determine which information is essential and which can be omitted In fact, there’s no need to worry about this; if third parties are entrusted to carry out the verification calculations, they will specify exactly what information is required, and one simply needs to collect that information as instructed. Generally speaking, the model specifications provided by instrument manufacturers are basic requirements; the inspection cycle and service life, as well as the average time required for repairs in case of failures, also need to be specified. These are all parameters that are necessary for verification calculations. A Safety Integrity System (SIS) is not a system that can be set up and then left alone – its reliability must be ensured through periodic maintenance and testing, and it is essential to take into account the capabilities for maintenance when conducting such assessments. If the field maintenance instrument engineers can pay special attention to things such as the failure interval times and repair times of the instruments in their daily work, and compile this information for the manufacturers, then decades later it will constitute valuable data proving their performance in actual use. As for the instrument engineer who intends to carry out verification calculations on their own, you are already at a fighter-level proficiency, so you naturally know what you need. Step 3: Organize the certificates. The certificates in question are, of course, SIL certificates. The main purpose of organizing these certificates is to provide invalidation data to the third-party verification team. This raises a question: since the verification software already has its own database, why is it still necessary to collect invalidation data? This question will be explained in detail during the calculation phase. 1. The first piece of advice is to find the SIL certificate for the corresponding instrument. The SIL certificate contains a lot of information, such as the SIL level, possible hardware requirements (HFT), type (A/B), failure data (Lambda λ), and so on. The certificate serves as proof of the safety performance of this instrument. At present, SIL certificates from various sources are abundant; amid the genuine and fake ones, the credibility of the data poses a significant problem (it is recommended to search on Baidu for the article “Changhui Instruments: Exclusive insights into how to determine the authenticity of instrument SIL certificates”). But that’s another matter. But with a SIL certificate, it’s like having the necessary ingredients for the calculations. When checking SIL certificates, it is essential to verify whether there is a second page or if expired data is included. Inexperienced instrument engineers often fall into the following trap: they are told that the instruments they’re using come with certificates; however, those certificates actually apply to different models. Stay vigilant! ; It’s a shortweight trap: the certificate is indeed the corresponding certificate, but it’s completely useless for verification purposes, as only the first page of the certificate is provided. Although it does contain information regarding the SIL level, no corresponding failure data is given. At this point, the instrumentation engineer needs to be thorough and persistent, asking the manufacturer for the failure data – it may be on the second page of the certificate, or in the report accompanying it (for manufacturers who claim no such report, congratulations, you’ve most likely encountered a fake certification body), or it might be included in the safety manual. 2. Second point of experience: What to do if the required certificate is not provided? The desired failure efficiency may appear in the following documents. ◆Safety manuals ◆ Certificates of conformity. These two types of documents are generally information provided by the manufacturers themselves. 3. Thirdly, in cases where none of the above experiences apply, relying on general data is an option; this decision should be left to professional analysts who can assess the situation based on the software and databases available. However, the importance of field instrument engineers becomes evident at this point – it is only by relying on the types and specifications of instruments provided by these engineers that third-party analysts can choose the appropriate data. http://yunrun.com.cn/upload/201912/21/201912210150544114.png e*da certificate. In the image above, the items indicated by the red box include the following information: Model: 8314 series solenoid valve ; Manufacturer: ASCO ; Type: Class A ; SIL level: SIL2 in the case of no redundancy, SIL3 with redundancy at level 1, Path 2H ; Invalid data: Have you found λSD/SU/DD/DU all of them? After completing the filling in of the above SIF loop data and the organization of certificates, we can finally proceed to the calculation phase. During this phase, if a third party is commissioned to carry out the calculations, the instrumentation engineer can relax and wait with confidence. While waiting, let’s take a look at the software used for calculations. So far, the two software platforms that Changhui Instruments has come into contact with are exSILentia and RiskCloud. Most engineers* are accustomed to using Excel to handle complex calculations that require logical reasoning, but having to establish those logical relationships each time is a very troublesome task. The verification of SIF circuits is complicated and varies greatly; each circuit may have a different structure, use different instruments, and each project has its own specific requirements. Although the calculation formulas provided by standards remain consistent, how can one create a flexible structure that can be adjusted as needed while still allowing the use of standard formulas for each calculation? In such cases, Excel turns out to be somewhat cumbersome and not efficient enough. Developed by E*da, exSILentia leverages E*da’s extensive database of instrument certifications and decades of development experience. In accordance with IEC-61508/61511 standards, it incorporates failure data and maintenance capability assessments, offering a user-friendly platform that allows engineers to freely construct SIF circuits as needed. In verification calculations, exSILentia holds an irreplaceable position. However, for domestic users, although foreign products may be capable of performing the required functions, they often encounter various issues in practical use. For local petrochemical companies that make extensive use of domestically produced instruments and equipment, exSILentia lacks support for these domestic brands. exSILentia comes with its own database that contains the safety instrument certificates issued by them. If instrument equipment certified under e*da is used, it is very convenient to enter the expiration dates into the calculations by simply selecting the manufacturer and model in the database. SIL certificates that are not certified by E*da can still be used in exSILentia; however, the user must utilize the user-created function to manually enter the relevant certificate data. Such use is limited to the current calculation only. If certificates that are not in its database are to be used in a subsequent project, they need to be entered manually again, **which reduces the convenience provided by database support. On top of that, the unreasonably high price makes one sigh at the poor value for money. In contrast, the up-and-coming RiskCloud (GeLue Software) has promptly addressed these shortcomings. It offers online computing capabilities; users can log in to perform calculations once they have an account. It features a rich database of indicators and certificates, provides timely after-sales service with easy access to technical support at any time. As for the price, it naturally boasts the best cost-performance ratio among domestic software options. Additionally, it offers flexible payment methods, including short-term accounts that allow users to pay only for the period they need them. RiskCloud (GeLue Software) also uses E*da’s database, but it is more inclusive compared to E*da’s database; non-E*da certificates entered are retained, and users are encouraged to contribute their own certificates to the database. The more users there are and the more projects that are used, the more SIL certificate information is accumulated, which makes it more user-friendly for those who use domestic instruments. Both software applications use the Markov model algorithm. Relatively speaking, exSILentia takes into account more parameters; however, with RiskCloud (Gelue Software) undergoing rapid version updates over the past six months, its parameters have become quite similar to those of exSILentia, and the calculation results are also similar under the same conditions. Both software options allow for the export of calculation results and report tables, with little difference between them. ◆The exported tables and charts from GeLue Software: http://yunrun.com.cn/upload/201912/21/201912210155477340.png ◆ Exported table of calculation results: http://yunrun.com.cn/upload/201912/21/201912210159053909.png ◆ SIF loop structure diagram and pie chart showing the trend analysis of calculated PFD values: http://yunrun.com.cn/upload/201912/21/201912210208183582.png After comparing various software options, the SIL verification report should now be ready. At this moment, how should instrumentation engineers review the report to determine whether it is a qualified one? Do you still remember the SIL classification reports you have seen and the SIF circuit data sheets you have filled out? At this point, you need to retrieve them and open each one, then compare them with the detailed calculation sheets in the verification report to check whether all the information related to the SIF circuits has been entered correctly. Both exSlentia and RiskCloud are capable of generating detailed verification calculation sheets that list all the parameters used in the calculations as well as the details of the choices made. In addition to checking whether the SIF circuit meets the classification requirements based on the conclusions, many details can be found in the calculation report: 1. Which applicable standards have been chosen? 2. Has the SIF circuit structure been entered correctly? 3. Have the correct instrument models with e*da certificates been selected? 4. Have the invalid data for non-e*da certificates been entered correctly? 5. For uncertified instruments, has the appropriately specified generic data been used? 6. Does it correspond to the actual testing interval? 7. What is the average failure probability PFD for each unit of the calculated SIF circuit and for the entire circuit? ......Wait. One of the advantages of RiskCloud at this point is that the calculation documents are in Chinese, so there’s no need to worry about dealing with overly complex exSILentia reports that aren’t available in Chinese and are filled with English, which can become a barrier. You can read reports, gather information, and organize certificates. Congratulations, you’ve advanced to the first level of SIL verification.
Reply #22019-12-23
As an instrumentation professional, I’ve learned more about SIL here!
Reply #32019-12-23
Very good article, useful! !
Reply #42019-12-23
Thanks for sharing; it’s very useful! ! !
Reply #52019-12-23
Valuable content, verification completed: victory:

Submit a Project

**Looking for Chemical Technology, Equipment & Solutions?** No Registration Required Broader Platform Exposure | Global Chemical Service Provider Connections

Submit Request — Free Consultation

Disclaimer

This is an automated machine translation of the original thread. Some technical terms may have inaccuracies; the original text shall prevail. Click "View Original" at the top right to access the source page, which supports IP-based automatic real-time language translation. Please watch out for contact details and sales inducements to prevent fraud. All content and translations are for reference only, representing solely the poster's personal views. For enquiries, email service@hcbbs.com.