HCBBS Forum (English)
Submit Chemical Projects / Find Solutions
Amplify Your Requirements on a Broader Chemical Platform *Engineering · Technology · Equipment · Solutions*
Submit Request

Step-by-step guide to performing SIL calculations

2022-05-06View Original

Thread Content

This post was last edited by biubiu0304 on 2022-5-6 at 11:10. Introduction: In previous articles published on the official account, we discussed that after conducting Hazard and Operability (HAZOP) analyses and Safety Integrity Level (SIL) assessments, if it is determined that a Safety Instrumented System (SIS) is needed to reduce risks, then it is necessary to perform SIL evaluations for the instrument safety functions (SIF). SIL assessment is carried out by calculating and analyzing the PFD/PFH of various components of the SIF, and by taking into account factors such as structural constraints and system capabilities in order to determine the SIL level of the SIF and confirm whether it meets the required target SIL level. This article will use Haopeng Technology’s PHACloud cloud platform to provide a detailed overview of the current SIL verification workflow, explore the challenges and key issues involved, and guide you step by step through the process of performing SIL verification. 1. During the preparation phase, the main documents required for SIL verification currently include: HAZOP analysis reports, SIL classification (LOPA) reports, SIS interlock logic design diagrams and SIL certification certificates, SRS safety requirement specifications, and SIS system configuration manuals. From the SIL classification report, we can determine which scenarios require the use of SIFs, what type of SIFs are needed (SIF description), and the corresponding SIL level (PFD or RRF). It should be noted in the SIL classification report that the SIF description must be consistent with the SIS interlock logic diagram and the actual installation on site, including the tag numbers of the instrumentation devices, the voting mechanism of sensors, and the actions to be carried out ; The PFD should not be too low (or the RRF should not be too high); the target PFD or RRF should be determined based on actual needs. As in the existing SIF1: The high-high interlock for the liquid level of the crude benzene storage tank V101 (LSHH101, 1oo1) shuts down the crude benzene feed isolation valve XV-101. The target safety integrity level for this SIF is SIL2, with a PFD of 4E-03 (RRF of 250). The SIL rating analysis worksheet and the SIS interlock logic diagram are shown in Figure 1 – Rating Worksheet and Interlock Logic Design. At present, most of the failure data required for SIL verification comes from the SIL certification certificate; therefore, it is necessary to ensure the authenticity and validity of this certification certificate. To determine whether an SIL certification is genuine and valid, it is mainly assessed from the following aspects: First, the existence of the certificate should be available for verification on the official website of the certification body ; Secondly, the products and certificates must match the manufacturer’s model ; Finally, the certificate should have a reasonable validity period. Of course, it is possible that the SIL certification certificate does not contain any data on failures or that the data available is incomplete; in such cases, it may be necessary to use FMEDA (Failure Mode, Effects, and Diagnostic Analysis) reports, or failure data from manuals such as the Reliability Data Manual, Safety Manual, and Functional Safety Manual, or even general failure data. The following are the SIL certification certificates and related manuals for SIF1, as shown in Figure 2 – Certificates and Manuals: Figure 2 – Certificates and Manuals. While collecting and verifying the above materials, it is also necessary to confirm the following aspects of each SIF with the enterprise: ① The configuration of input and output interfaces; for example, SIF1 has no input safety isolators but does have output safety relays ; ②The configuration of the logic operator modules, such as SIF1 involving AI and DO modules ; ③Verify the relevant assumed parameters, such as the design service life (LT) of SIF1: 15 years; inspection cycle (TI): 1 year; average time to recovery (MTTR): 24 hours; time to restart after shutdown (Tsd): 24 hours; functional test coverage (CTI): 90% for sensors and valves, 95% for logic operators; common cause failure rate (β): 3% for logic operators ; Operation mode: Low-demand operation mode. .2. Once the materials required for the verification calculation are ready, the actual verification calculation can proceed. PFD/PFH, structural constraints, and system capabilities together determine the SIL level that the SIF can ultimately achieve, among which the calculation of PFD/PFH is the most complex and difficult. In the field of reliability, Markov modeling is the preferred approach due to its flexibility and accuracy. We use PHACloud to calculate the PFDavg for SIF1, taking into account both structural constraints and system capabilities. The SIL verification for SIF1 is shown in Figure 3-SIF1 Verification. It should be noted that there are two different calculation paths for verifying the structural constraints of the hardware: Route1H and Route2H. The appropriate path should be selected based on the SIL certification requirements. 3. Result analysis and verification: After the calculations are completed, it is necessary to analyze the results. If aspects such as the SIL level and MTTFS (mean time to safety failure) meet the desired requirements, then the SIL verification process for that SIF is complete ; If the required objectives cannot be met, especially regarding the SIL level, further research and analysis of that SIF are necessary to identify the reasons and find solutions. The validation calculation results for SIF1 are shown in Figure 4 – Validation Results. Looking at these results, although PFDavg, structural constraints, and system capabilities all meet the SIL2 level, the specific value of PFDavg does not satisfy the required criteria. In other words, the risk reduction that SIF1 can achieve is 4.99E-3, which is greater than the target value of 4E-3. Since the difference between the two is not significant, we can conduct a sensitivity analysis on SIF1: First, we examine the contribution ratio of PFDavg to determine which component has the highest share; in this case, the execution element component accounts for 90.9% ; Secondly, seek reasonable solutions to reduce the PFDavg value of the final actuator components, such as using devices with a lower failure probability, increasing the coverage of functional testing, and shortening the testing cycle ; Finally, verification calculations were carried out again using the new scheme; for example, the test period for the final actuator part of SIF1 was reduced to 6 months, while all other assumption parameters related to the verification remained unchanged. The verification calculations showed that SIF1’s PFDavg dropped to 3.66E-3, which is lower than the target value of 4E-3. Thus, provided this scheme can be implemented, this SIF can meet the requirements for risk control. The changes and verification results related to the new scheme are shown in Figure 5 – New Scheme: Figure 5 – New Scheme Conclusion. The aforementioned SIL verification workflow represents only the author’s personal views; readers are welcome to discuss it together. This article is reprinted from the official account: Haopeng Technology
Reply #22022-05-07
What software is being used? Is it free?
Reply #32022-05-07
Haopeng Technology’s PHACloud is now available for free trial registration
Reply #42022-05-13
I believe that data missing from the certification report must be provided by the supplier for it to be valid; generic data obtained through investigations cannot be used for SIL calculations. These days, the market is full of mixed-quality products, and most certificates lack complete information
Reply #52022-05-17
Internationally recognized generic failure data can be used; such data is more conservative, making it harder to meet the verification requirements. Moreover, some electrical devices simply cannot undergo SIL certification.
Reply #62023-05-06
What if the structural constraint is SIL0? Does this meet the requirements?
Reply #72023-05-09
It is only possible when all of PFDavg, structural constraints, and system capabilities are met; if any one of these parameters has a SIL value of 0, it means that the corresponding SIF does not meet the requirements

Submit a Project

**Looking for Chemical Technology, Equipment & Solutions?** No Registration Required Broader Platform Exposure | Global Chemical Service Provider Connections

Submit Request — Free Consultation

Disclaimer

This is an automated machine translation of the original thread. Some technical terms may have inaccuracies; the original text shall prevail. Click "View Original" at the top right to access the source page, which supports IP-based automatic real-time language translation. Please watch out for contact details and sales inducements to prevent fraud. All content and translations are for reference only, representing solely the poster's personal views. For enquiries, email service@hcbbs.com.