HCBBS Forum (English)
Submit Chemical Projects / Find Solutions
Amplify Your Requirements on a Broader Chemical Platform *Engineering · Technology · Equipment · Solutions*
Submit Request

Does a regular instrument using a three-out-of-two logic function equate to an SIL2 instrument?

2023-09-22View Original

Thread Content

I saw a project in which thermal resistors and pressure transmitters without an SIL rating were used to implement a three-way voting logic, and then those devices were integrated into the SIS system. Is this approach in compliance with the regulations?
Reply #22023-09-22
This post was last edited by sun_fm on 2023-9-22 at 10:50. Three cobblers equal Zhuge Liang? Or do you think three U.S. divisions can be exchanged for one Qian Lao?
Reply #32023-09-22
A look at the definitions of SIS, SIF, and SIL in GBT50770 will help clarify this. In other words, we need to be certified and competent, rather than just pretending to be qualified. Without authentication, it’s not possible to take 1 from 100000000000
Reply #42023-09-22
For further insight, one can also refer to the explanation in AQ3054 regarding the rule that DCS levels should not exceed two; in principle, the protection level of DCS should not be more than 2 layers, which is equivalent to not exceeding SIL1. The concept of “not exceeding two” means that, within the same scenario and for the same IE’s IPL, the risk reduction factors for all DCS systems together must not exceed 10^-2 (in other words, their combined effect must not reach SIL1). For example, if the liquid level is initially high, there can be ① a high liquid level alarm + response from qualified personnel ; ②LT+LV ; ③LT+XV ; ④WT+XV, etc. – these are from DCS, and only 2 of them can be used. The above content is subject to regulatory standards; reference can be made to Section 7.2 and Appendix D of AQT 3054-2015 Guidelines for the Application of the Protective Layer Analysis (LOPA) Method.
Reply #52023-09-22
This issue relates to the design of Industrial Safety Instrumented Systems (SIS) and the application of Safety Integrity Levels (SIL). Firstly, the \"two-out-of-three\" or \"one-out-of-three\" logic is a common redundancy design approach that enhances the reliability and fault tolerance of a system through voting by multiple devices. However, this does not mean that the system can be directly equated with a system having a specific SIL level. The SIL level is based on a risk assessment method used to determine the degree of hazard that a system is capable of preventing or reducing. When determining the SIL level, factors such as the system’s reliability, availability, diagnostic coverage, and hardware fault tolerance are taken into consideration. Therefore, merely by implementing a \"two-out-of-three\" or \"one-out-of-three\" logic, it is not possible to ensure that the system achieves the SIL2 safety level. Regarding the project you mentioned, whether the use of thermal resistors and pressure transmitters without SIL ratings in a SIS system complies with the specifications depends on the specific application environment and operating conditions. If the SIS system requires a specific SIL level, then all components, including thermoresistors and pressure transmitters, must meet the requirements of that corresponding SIL level. It should also be noted that even if all devices have the corresponding SIL rating, the SIL rating of the entire system still needs to be determined through a system-level assessment. This is because the safety integrity of a system depends not only on the performance of individual devices, but also on the interactions between those devices and the design of the entire system. In general, to determine whether an SIS system meets the specifications, it is necessary to consider not only the performance of the equipment itself and its SIL level, but also to conduct system-level risk assessment and verification. If you have any other questions on this topic, feel free to ask. .
Reply #62023-09-22
If you want to understand this in more depth, I’ll ask a few more questions; once you understand them, such issues won’t arise. 1. Can the sampling points for measurement elements in DCS and SIS be shared? 2. Can components be reused between BPCS and SIS? 3. How should safety interlocks and non-safety interlocks be understood? 4. Should interlocks use positive logic or negative logic? 5. Must redundant sensors in safety instruments be products based on different technologies? How should MOS and OOS be set up, and what are the differences in reset mechanisms between DCS and SIS? ... Finally: One question – can it be assumed that multiple SIL1 systems can meet the requirements of SIL2? A: If the measurement elements/final actuation elements of SIL1 are used in a SIL2 system and pass the relevant verification for SIL2, then it can be said that multiple SIL1 systems can fulfill the requirements of SIL2. From a results-oriented perspective, this is possible; however, in principle, such a situation should not occur, nor should it be done. Let’s first take a look at the components of SIF: there are measuring elements, logic controllers, and final actuating elements. Let’s take another look at the SIL verification; in the previous checks, it was determined that the circuit belongs to a certain SIL level, and by selecting components with a corresponding SIL level, the verification requirements are met (the structure was not considered previously). The current approach is to consider these three aspects as a whole (structural constraints), and verification can then be carried out. Based on the current practices, if the measuring elements for SIL1 are designed as 2oo50 and then pass the SIL verification, can these measuring elements be used for SIL2? No, for the following reason: According to 6.1.7 of GBT50770, the performance and settings of measuring instruments must meet the requirements of the safety integrity level. 7.1.3 The settings of the final components shall meet the safety integrity level requirements. According to 11.2.2 of GBT21109.1, when a SIS is required to perform both instrument safety functions and non-safety functions, all hardware and software that may have a negative impact on any SIF under normal and fault conditions shall be considered part of the SIS and must meet the requirements of the highest SIL level. SC capability (system capability stated in the SIL certificate per the manufacturer)

Submit a Project

**Looking for Chemical Technology, Equipment & Solutions?** No Registration Required Broader Platform Exposure | Global Chemical Service Provider Connections

Submit Request — Free Consultation

Disclaimer

This is an automated machine translation of the original thread. Some technical terms may have inaccuracies; the original text shall prevail. Click "View Original" at the top right to access the source page, which supports IP-based automatic real-time language translation. Please watch out for contact details and sales inducements to prevent fraud. All content and translations are for reference only, representing solely the poster's personal views. For enquiries, email service@hcbbs.com.