Thread Content
I’ve seen quite a few discussions about SIS. I once read this article, so I’m reposting it for reference only: ==========================================================-----Source: Control Engineering (China) To improve the performance of safety systems and ensure they operate as required, it is necessary to have improved diagnostic capabilities, as well as mechanisms for maintenance and regular testing. In process plants, the Layers of Protection (LOP) include safety valves, explosion-proof membranes, protective barriers, and Safety Instrumented Systems (SIS). SIS is a specialized engineering solution that remains operational 24/7; whenever any unsafe process event is detected, it can take immediate action to minimize potential losses. But during the weeks, months, or even years that pass between two security incidents, how can the Probability of Failure on Demand (PFD) of certain parts of the SIS be minimized? The answer is: select appropriate devices for safe applications, use good engineering practice to design and install these devices, employ reliable maintenance procedures, and test, test, and retest. Improved security standards Security standards were once established to meet the specific requirements of certain applications, industries, and/or **. For example, the ANSI P-1.1-1969 standard sets safety requirements for pulp, paper, and cardboard manufacturers in the United States. Usually, such standards are established at the time of release as design specifications based on available technologies. Such a standard assumption that the system lifecycle is properly carried out, including installation, testing, and maintenance, has repeatedly proven to be a wrong assumption. More recently issued safety standards, such as those developed by the International Electrotechnical Commission (IEC) and the Instrumentation and Control Systems Association (ISA), are \"performance-based\" standards that are based on identifying and quantifying risks, eliminating those risks where possible, and using LOP when risks cannot be completely eliminated. The instrumentation system (S84-2004) complies with IEC 61511, with one exception. “Included in S84-2004 is a grandfather clause that requires equipment owners/operators to examine and document their SIS design, operation, and maintenance practices. If it is confirmed that the currently installed SIS can ensure safe operation, no modification to the system is required. However, if inspections show that the SIS does not provide adequate protection, it must be brought up to standard using the latest good engineering practices,” said Summers. The goal of IEC 61511 and S84-2004 is not so much to specify what technologies or levels of redundancy must be used, but rather the intention of these safety standards is to ensure that the higher the process risk, the greater the robustness of the installed SIS. Although compliance with IEC 61511 and S84-2004 remains voluntary, the following increase in numbers demonstrates that it is becoming the international safety system standard chosen by the process industry: ◆Papers submitted by end-users at seminars ; ◆ References on process control system suppliers’ websites ; ◆Reference materials developed by **organizations from China, India, Ireland, Italy, Norway, the United Kingdom, and the United States. An example of **recognizing the importance of S84 can be seen in the $361,500 fine imposed by the Occupational Safety and Health Administration (OSHA) of the U.S. Department of Labor on the Formosa Plastic factory**. Among the 45 serious violations cited by OSHA, some mentioned that the Formosa Plastic Plant \"failed to comply with recognized good engineering practices, such as ANSI/ISA S84.\" What to focus on: When engineers and technicians start learning about *SIS, they often jump to the conclusion that logic controllers require three or four times the level of redundancy. However, when examining the data, such as OREDA (Offshore Reliability Data), they found that final control element failures accounted for 50% of the cases, sensor failures accounted for 42%, while logic controller failures accounted for only 8%. These factors do not reduce the importance of either of the responsibilities involved in selecting and installing a suitable logic controller, but they do help to emphasize the need to consider all factors that affect the performance of the SIS. These factors include: ◆ Component inefficiency and failure modes ◆ Installed instruments ◆ Redundancy ◆ Voting mechanisms ◆ Diagnostic coverage ◆ Testing frequency. The only way to ensure that these factors are adequately considered while avoiding overly complex solutions is to establish high standards for design. This begins with risk management analysis and the determination of the required overall safety level (SIL), as defined in IEC standards. (See the table above) The likelihood of equipment failure increases over time. Increasing the frequency of proof testing can reduce PFDAVG, and two options are available: 1. Use the same equipment to meet a higher safety level (SIL) ; 2. Use cheaper equipment to achieve the same SIL. Regular use of manual or automatic local stroke valves for testing can extend the time between adequate tests while maintaining the required PFDAVG. Once the required SIL is determined, this standard provides the target Risk Reduction Factor (RRF) and the target average PFD, thereby quantifying the design criteria for the SIS. Of course, it is not sufficient to simply design and install an SIS to meet the defined overall safety level; the SIS must also be maintained so that its performance does not decline over time. Reduce PFD There are three fundamental ways to reduce the likelihood of SIS failures: ◆ Install twice, three times, or four times as many devices ; ◆Expand the scope of equipment diagnosis ; ◆Increase the frequency at which the equipment is tested. Today, expanding the scope of diagnostics is relatively easy and cost-effective, as a large number of devices offer built-in diagnostic functions that are integrated with asset management software. However, special caution is required when introducing such solutions as part of the SIS. For example, the security system experts at E*da.com examined the use of multiplexers that employ the HART communication protocol, such as those from P+F, which work in conjunction with Emerson Process Management’s Asset Management Solution (AMS) software to enhance the scope of diagnosis available for SIS devices. EXida reports that the tested design scheme can be effective in expanding the scope of device diagnosis and meet many of the requirements of IEC 61511, provided that: ◆The AMS software provides appropriate security measures for passwords and permissions ; ◆Identify and document the procedures to ensure the proper use of the HART handheld communicator ; ◆The failure rate of the multiplexer is explained in the SIS design scheme. Figure 1 illustrates how full-proof testing at higher frequencies reduces PFDAVG. However, readers should note that tests usually require shutting down the process or installing a bypass route to be properly verified. The longer process equipment operates between scheduled shutdowns, the fewer opportunities there are to conduct adequate proof testing. Another alternative for conducting adequate proof testing is a local travel safety valve – not sufficient to interrupt the process, but enough to test the required movement of the valve. Figure 2 illustrates how local stroke valve testing can extend the interval between fully validated tests, while maintaining the required PFDAVG. Local stroke valve testing The three basic methods for local stroke valve testing are: mechanical limitation ; Pulse solenoid valve ; Position control. Mechanical restriction is an inexpensive solution that involves installing a set of mechanical components, such as collars and valve sleeves, to limit the travel of the valve. When these devices are in use, the safety valve is unavailable. It is the program that ensures the valve has returned to normal operating condition. Sending pulse signals to the solenoid valve of the safety valve is a simple and effective method for opening/closing the safety shut-off valve. It requires a limit switch (or position transmitter), an adjustable, timed pulse output provided by the logic controller, and logic that forces the solenoid valve to return to a safe position, in order to prevent false process stops. Position control is the most effective when control valves and microcontroller-based intelligent positioners (controllers) are used as part of an SIS solution. In addition to being able to move the valve to a predetermined position, the intelligent positioner also provides a wide range of diagnostic capabilities, such as valve stroke and actuator separation force. Since safety valves usually do not have positioners installed, critics of this method point to the need for additional hardware and related installation costs as its main drawback. However, BP, a giant in the refining industry, reported that after installing the Neles VG800 valve controller and ValvGuard testing and monitoring software from Metso Automation, the safety of its plants improved significantly, and operating costs were reduced. BP also reported that there would be a very short payback period. A less publicized benefit of expanding the diagnostic scope of safety valves and/or increasing their testing frequency is the potential to reduce the amount of safety valves needed. In some high-risk applications, it is a common practice to install two safety valves in sequence for long-term use. The reason is that it is impossible for both valves to fail at the same time when they are required to be closed. However, by using redundant equipment cautiously, expanding the scope of diagnostics, and increasing the frequency of testing, some companies have removed one of the two safety valves without, reportedly, compromising the safety margin.