Thread Content
This post was last edited by The one on 2026-6-9 02:51. I. Relevant specifications and standards 1. Document No. 3116 issued by the General Administration of Work Safety: (XI) Design and implement toxic, hazardous, and flammable gas detection and protection systems in strict accordance with relevant standards; to ensure their reliable operation, such systems should be independent of the basic process control systems.
2. \"Code for Design of Detection and Alarm Systems for Flammable and Toxic Gases in Petrochemical Industries\" GB/T 50493-2019 [Article 3.0.8]: Detection and alarm systems for flammable and toxic gases shall be installed separately from other systems. 【Explanation of Clause 3.0.8】: Independent operation means that the detection and alarm-functioning of the combustible gas and toxic gas detection and alarm systems are not affected by failures in the control instrument systems of the corresponding production processes.
3. \"Technical Specifications for Safety Monitoring of Major Hazard Sources of Hazardous Chemicals\" GB17681-2024 [Article 6.4.3.7]: The GDS should be independent of the BPCS and SIS. When the interlock circuit for combustible gas and/or toxic gas detectors has SIL rating requirements, the detectors shall be installed independently of the GDS, and their output signals shall be sent to the SIS. The configuration of the gas detector interlock circuit shall comply with the relevant provisions of GB/T 50770. When gas detectors are not directly involved in BPCS interlocks, SIS interlocks, or fire protection interlocks, the gas detector interlocks should be set in the GDS.
4. \"Guidelines for the Safety Management of Chemical Process Operations\" AQ/T 3034-2022 [Article 4.7.2.7] The installation of gas detection and alarm systems shall meet the requirements of GB/T 50493; the setting of alarm values and alarm points shall be in line with the characteristics of the media that may leak. If the gas detection alarm signal is to be integrated into the Safety Instrumented System (SIS), it shall comply with the relevant requirements of GB/T21109 and GB/T50770.
5. \"Safety Management Specifications for Fine Chemical Enterprises\" AQ 3036-2025 [Article 7.4.1.1.b] The GDS should be installed separately from other systems.
6. \"Code for Design of Automatic Fire Alarm Systems\" GB50116-2013 [Article 8.1.2] The combustible gas detection and alarm system shall be formed independently; combustible gas detectors shall not be connected to the detector circuits of the fire alarm controller; When the alarm signal from a combustible gas needs to be connected to the automatic fire alarm system, it should be connected through the combustible gas alarm controller. 【Article 8.1.3】For combustible gas detectors used in process control within the petrochemical industry, they can be installed in accordance with the relevant provisions of the current standard **\"Design Code for Detection and Alarm of Combustible and Toxic Gases in Petrochemical Industries\" GB 50493; however, their alarm signals must be fed into the fire control room.
Based on the above specification requirements for the setup of a GDS, the GDS system should be independent of systems such as DCS, SIS, and automatic fire alarm systems.
II. Functions of the GDS system The GDS system is essentially a monitoring and early-warning system, and its main functions include monitoring, issuing alerts, as well as recording and analyzing alert data. When a dangerous gas leak is detected, it uses audio-visual alarms to alert people to evacuate and ventilate the area, but it does not directly control the production process; its primary function is to provide warnings and facilitate evacuation. Connecting combustible or toxic gas detectors that are part of process or safety interlocks to the GDS system is clearly inconsistent with the functions of the GDS system.
For example: Suppose a toxic gas detector that is part of the emergency stop interlock is also connected to the GDS system – what risks might arise? 1. If the GDS system shuts down or becomes ineffective due to software bugs, power failures, cabinet environment issues (such as excessive temperature), or human error (such as accidentally disabling alarms on the GDS screen), it may affect the interlock detectors connected to it, preventing them from triggering interlock actions in dangerous situations. A security barrier that should have been highly reliable became unreliable due to the integration of an insecure system. 2. Maintenance and testing may present difficulties. The devices in the SIS system require regular, rigorous safety integrity level (SIL) verification tests. If the detectors involved in interlocking are connected to the GDS system, testing, maintaining, or calibrating the detectors in the SIS may accidentally trigger alarms in the GDS, resulting in unnecessary panic and evacuations in the production area. Conversely, maintenance operations on the GDS may also inadvertently affect SIS functions. 3. There may be an unclear division of management responsibilities. The management departments or personnel responsible for GDS, DCS, and SIS systems may differ, and mixed integration can lead to blurred boundaries of responsibilities, making it difficult to determine accountability in case of problems and affecting the quality of system maintenance.
Example: In a warehouse storing toxic gases, a toxic gas detector is connected to an emergency fan via interlock; can such a detector be integrated into the GDS system? Firstly, this function does not belong to the process interlock system; it should either be connected to the GDS or to the SIS. Two scenarios can be considered: 1. In normal circumstances, this toxic gas detector is connected to the GDS system. Reason: The safety integrity level (SIL) requirement for activating this safety function of the emergency fan is usually not high (it may be assessed as requiring no SIL level or SIL0). The reliability of the GDS system itself is already sufficient to meet the requirements, eliminating the need for a more expensive and complex SIS system. 2. In special cases, this toxic gas detector is connected to the SIS system. Reason: Through safety assessments such as Layer of Protection Analysis (LOPA), it was concluded that this interlock function (gas leakage → activation of fans) is a critical layer of protection to prevent major safety accidents, and since it requires a certain level of safety integrity (SIL) – such as SIL1 or SIL2 – it must be implemented by a SIS.
Summary: 1. Combustible gas or toxic gas detectors involved in process interlocks cannot be connected to the GDS system. 2. Combustible gas or toxic gas detectors that are part of the safety interlock system cannot be connected to the GDS system when the interlock circuit has specific SIL rating requirements ; When no SIL rating requirement is specified, it can be connected to the GDS system.