Thread Content
To strengthen the management of safety instrumented systems in the chemical industry and prevent and reduce accidents involving hazardous chemicals, in 2014, the former **State Administration of Work Safety issued the \"Guiding Opinions of the **State Administration of Work Safety on Strengthening the Management of Safety Instrumented Systems\" (An Jian Zong Guan San [2014] No. 116), which provided guidance on the management of such systems. The introduction of these guidelines has encouraged enterprises to strengthen the foundational work related to the management of safety instrumented systems, thereby effectively improving their inherent safety levels. However, the author has found that current enterprises still have the following shortcomings in the management of safety instrumented systems: 1. Insufficient understanding and awareness of safety instrumented systems. The management of safety instrumented systems in China started relatively late compared to other countries. Some enterprises and design units lack sufficient understanding and awareness of the concept of Safety Instrumented Systems. So what is a Safety Instrumented System (SIS)? As the name implies, it is an instrument system that performs one or more Safety Instrumented Functions (SIFs). It relies on the coordinated interaction of sensors (which detect and transmit changes in status parameters), logic controllers (which perform calculations and issue commands), and final elements (which carry out the final actions) to achieve specific functional safety objectives. It takes emergency measures against potential dangers to the installations or equipment, and responds promptly to situations that are worsening, bringing them into a predefined safe state thereby minimizing risks and losses and ensuring the safety of production equipment, the environment, and personnel. Which systems fall under the category of safety instrumented systems? The \"Guiding Opinions on Strengthening the Management of Safety Instrumented Systems in the Chemical Industry\" (An Jian Zong Guan San [2014] No. 116) specifies systems such as safety interlock systems, emergency shutdown systems, and detection and protection systems for toxic and harmful gases sowie flammable gases and fires. IEC61511 classifies SIS types into instrument protection systems, safety interlocks, safety-related systems, emergency shutdown systems, burner management systems, fire and gas systems, and high-integrity (pressure) protection systems, among others. Regardless of the classification, SISs carry out one or more safety instrument functions; for example, systems for detecting toxic and harmful gases as well as flammable gases and for fire protection can automatically trigger the activation of actuators by detecting and processing specific signals, thereby preventing accidents from occurring in the first place. Its safety life cycle includes process hazard analysis, SIF identification, SIL classification, preparation of safety requirement specifications, preliminary design of the SIS, life cycle cost analysis, verification calculations for SIL, detailed design of the SIS, installation and commissioning of the SIS, operation of the SIS, as well as its maintenance, modification, and decommissioning. The 02 interlock is kept in the disengaged state for a long time in order to reduce losses caused by unplanned shutdowns. The safety instrument system remains inactive for extended periods, relying entirely on the \"adaptability\" of personnel to carry out operational control; as a result, it becomes nothing more than a formality to meet various safety inspections ; The management capability of the safety instrumented system is insufficient, resulting in frequent malfunctions of the interlocks; instead of conducting in-depth analysis to address these issues, the company resorts to disabling the interlocks as a solution. 03 The safety instrumented system integrity levels of the chemical plants or storage facilities that were constructed in the early stages and are involved in operations related to \"two major, one high-risk\" processes do not meet the required standards. On one hand, these plants built in earlier times did not undergo process hazard analysis, nor were SIL ratings and verifications carried out, making it impossible to determine whether the current safety instrumented systems meet the requirements for risk reduction ; On the other hand, although process hazard analysis, SIL classification, and verification were generally carried out for the chemical plants built in the early stages, there are many issues with the quality of these analyses. 1) The analysts involved, especially those in production, operations, and maintenance, lack sufficient awareness of the relevant hazards. Out of concern that overly stringent analysis requirements might lead to increased design and management costs, there is a tendency to deliberately lower these requirements during the analysis process; the practice of conducting analyses merely for the sake of doing so is quite common on-site. 2). The capabilities of third-party consulting firms conducting HAZOP and SIL analyses vary widely. There is a lack of regulation and oversight in the industry regarding the qualifications and capabilities of third-party consulting firms. To a certain extent, in pursuit of efficiency, there are cases of falsifying certification results in order to meet the requirements of the client. 04 There is a relative shortage of skilled professionals in safety instrumentation with the necessary capabilities. The project involves a wide range of personnel across design, construction, commissioning, operation, maintenance, and management phases, and requires many specialized experts. In China, regulations and standards related to safety instrumentation were developed late; as a result, many individuals involved in SIS design, integration, installation, maintenance, repair, SIL analysis, and SIL verification do not have a sufficient understanding of these regulations and lack the appropriate professional skills, which directly affects the accuracy of the analysis results. 05 The data used for verification are not based on reality; according to IEC 61508, it is first recommended to use failure probabilities calculated by the enterprise itself, which reflect the actual conditions of that enterprise (that is, data derived from past usage experiences, as they offer the highest level of accuracy). Secondly, the failure probability provided in the SIL level certificate of that safety device/component can be used. If none of the above data are available, industry-recognized databases on the failure rates of safety instrumented systems (such as ORED, e*da, etc.) and data provided by the equipment suppliers themselves can be used. Safety Instrumented Systems are one of the important means of reducing the probability or likelihood of hazardous events occurring. Without accurate data to serve as a basis, any preliminary quantitative analysis becomes meaningless; it is also impossible to determine whether the frequency of hazardous events can be reduced to an acceptable level. However, there are very few accurate site-based data that can be summarized in China based on actual on-site usage experience. Undeniably, currently there is a wide variety of certification certificates issued by certification bodies in the market; it is difficult to verify the accuracy of the data, and their authority has **diminished. 06 Low level of operation and maintenance management: The operation and maintenance of safety instrumented systems require comprehensive user manuals, operation manuals, and maintenance manuals, thorough maintenance activities and schedules, as well as consistent records in accordance with established procedures. However, at present, instrument management in various companies is limited to repairs only when problems arise; routine inspections and maintenance are merely formalities. There is a lack of management related to regular testing, as well as procedures for making changes or shutting down equipment, let alone maintenance carried out in accordance with the requirements outlined in the manuals. In light of the above issues, what exactly should we do to maintain the safety instrumented system as an important barrier against accidents? In my opinion, efforts should be made in the following five areas: 1) Clearly understanding the concept of the independence of safety instrumented systems. This refers to the system’s independence in performing its safety instrumented functions; it does not mean that the system must be completely isolated from any external systems and have no interaction with them at all. Generally, it is necessary for the logic controller of an SIS system to be independent, while whether the measuring instruments and final actuating elements need to be independent depends on a comprehensive consideration of the SIL classification and verification results. The safety instrumented system can also exchange data with the basic process control system; for example, the basic process control system can retrieve signals from the SIS system in a read-only manner. 2) Organize the classification and verification of the Safety Integrity Level (SIL) in a scientific manner, based on risk matrices. Bring together professionals in areas such as processes, equipment, instrumentation, electrical systems, and safety, and use Hazard and Operability Analysis (HAZOP) and Layer of Protection Analysis (LOPA) to determine the SIL level of the safety instrumented system. Subsequently, enlist the help of third-party consulting firms to verify the SIL level of the currently operating safety instrumented system, determine whether it meets the requirements for that SIL level, and implement the necessary corrective actions. Supervise the relevant organizations or companies that carry out HAZOP analysis, SIL analysis, and verification tasks. By having regulatory authorities and industry associations work together to establish requirements for process control and quality control in the preparation of various assessment reports, it is possible to ensure that SIS meets the ultimate requirements. 3) Strengthen training to improve the capabilities of professionals: Relevant functional departments should provide guidance and support, and enhance the training for professionals in related fields so that they can understand and comply with relevant regulatory requirements. In particular, design organizations should strengthen their understanding and mastery of various standards, and actively promote the use of standards related to \"functional safety\", such as GB/T 20438/21109 (equivalent to IEC 61508/61511) \"Functional Safety for Electrical/Electronic/Programmable Electronic Safety-Related Systems\". 4) Establish a reliable and accurate database. During the production process, enterprises should pay attention to the collection and summarization of data related to safety instruments, in order to create a database suitable for their needs. Industry associations organize the collection, compilation, and analysis of data within the industry, in order to create reliable and accurate databases suitable for that industry. All types of safety instruments, whether domestic or imported, must be verified; their certificates and relevant data need to be checked. A unified channel or platform should be established for examining such compliant safety instruments, in order to prevent the use of any non-compliant ones and thus ensure the accuracy of the SIS. 5) Carry out routine maintenance and change management for the safety instrumented system. Regularly test the functions of these safety instruments, and keep detailed records of the testing process and results. Periodically review the failure data collected on-site, compare it with the data used in system design and safety performance analysis, determine appropriate measures, and gradually establish a database of failures related to these devices. Changes to the safety instrumented system include the adjustment of interlock values, the deactivation and activation of interlocks, modifications and improvements to interlock logic, replacement of spare parts with different types (including changing the manufacturer), as well as iterative upgrades to software systems. All of these are considered part of the change management process for safety instrumented systems, and companies must establish a comprehensive management framework to ensure thorough risk identification and effective safety measures. The safety instrumented system is an important independent protection layer for safe production; only by implementing proper lifecycle management can it truly play a role in preventing accidents.