HCBBS Forum (English)
Submit Chemical Projects / Find Solutions
Amplify Your Requirements on a Broader Chemical Platform *Engineering · Technology · Equipment · Solutions*
Submit Request

Design principles for SIS safety instrumented systems (**under the guidance of Document No. 116 issued by the State Administration of Work Safety)

2015-12-14View Original

Thread Content

To the Work Safety Supervision Bureaus of various provinces, autonomous regions, municipalities directly under the Central Government, and the Xinjiang Production and Construction Corps, as well as relevant central state-owned enterprises: In order to strengthen the management of safety instrumented systems in the chemical industry and prevent and reduce accidents involving chemicals, the following guidance is provided: I. Fully recognize the importance of strengthening the management of safety instrumented systems in the chemical industry. (1) Safety instrumented systems (SIS) include safety interlock systems, emergency shutdown systems, and detection and protection systems for toxic and harmful substances, flammable gases, and fires. The safety instrumented system is independent of the process control systems (such as distributed control systems, etc.). It remains in a dormant or inactive state during normal production, but can act instantly and accurately once a situation that could lead to a safety accident occurs in the production facility, thereby stopping the production process safely or bringing it into a predetermined safe state. It must have high reliability (i.e., functional safety) as well as proper maintenance and management. If the safety instrumented system fails, it can often result in serious safety accidents; most of the major chemical industry accidents that have occurred in developed countries in recent years have been related to failures in the safety instruments or improper installation of these systems. Based on the consequences and risks resulting from the failure of safety instrument functions, these functions are classified into different safety integrity levels (SIL1-4, with level 4 being the highest). Safety instrumented systems of different levels have varying technical requirements in terms of design, manufacturing, installation and commissioning, as well as operation and maintenance. At present, in China’s safety instrumented systems and related safety protection measures, throughout all stages of their life cycle – including design, installation, operation, and maintenance – there are issues such as insufficient hazard and risk analysis, inappropriate design choices, unreasonable redundant fault-tolerance structures, a lack of defined inspection and testing schedules, and preventive maintenance strategies that are not effective enough. It is therefore urgent to strengthen the regulation of safety instrumented system management. As China’s chemical plants and **chemical storage facilities become larger in scale and the level of automation in production processes continues to increase, it is extremely urgent and necessary to strengthen and standardize the management of safety instrumented systems. II. Strengthening the foundational work for the management of chemical process safety instrumented systems (II): Accelerating the training of technical and managerial personnel skilled in functional safety related to safety instrumented systems. Chemical engineering design and construction firms, as well as **chemical production and storage units, must organize specialized training on safety instruments for relevant personnel, as well as engineering and technical staff involved in processes and instrumentation. This training aims to spread knowledge related to functional safety and to familiarize them with relevant standards and regulations. Targeted training should be provided to designers, installation and commissioning personnel, as well as operation and maintenance staff at various stages of the safety instrument system’s life cycle, so that they can master relevant professional skills in safety instrument systems, risk analysis and control, risk mitigation, etc. Each chemical engineering design firm should take about a year to build a team of technical experts capable of handling the functional safety design of safety instrumented systems. Chemical enterprises and **chemical storage facilities** that operate production units involving \"two key areas and one major concern\" (namely, **chemicals under strict supervision, hazardous chemical processes under strict supervision, and major hazard sources of **chemicals) need to accelerate the training of personnel. It is necessary to cultivate a group of engineering and technical professionals with specialized skills and knowledge of relevant standards and regulations, in order to meet the requirements for implementing and strengthening the functional safety management of chemical safety instrumented systems. (III) Further improve the technical standards and certification system for chemical process safety instrument systems. Accelerate the formulation and revision of the technical standard system for chemical process safety instrumented systems. To organize research and develop a technical standard system for functional safety in China’s chemical industry, relevant departments and organizations need to formulate work plans and work on establishing functional safety-related technical standards and application guidelines that are suited to the current safety development situation of enterprises in this industry. Promote the establishment and improvement of a functional safety certification system and mechanism suited to China’s national conditions. In accordance with “Functional Safety of Electrical/Electronic/Programmable Electronic Safety-Related Systems” (GB/T 20438) and “Functional Safety of Safety Instrumented Systems in the Process Industry” (GB/T 21109), a functional safety certification service system for relevant personnel, products, and organizations shall be gradually established. III. Further strengthen the management of the whole life cycle of safety instrumented systems (IV) Before designing a safety instrumented system, it is necessary to clarify its process safety requirements, design intent, and underlying principles. Through process hazard analysis, it is necessary to fully identify hazards and hazardous events, scientifically determine the required safety instrument functions, and assess safety risks in accordance with **laws, regulations, and standards to establish the necessary risk reduction requirements. Prepare the technical document for the safety requirements of the safety instrumented system in accordance with the functional and integrity requirements of all safety instrument functions. (5) Standardize the design of chemical safety instrument systems. The safety instrument functions are designed and implemented in strict accordance with the technical documents specifying the safety requirements for safety instrument systems. The design of safety instrument functions is optimized through means such as the rational selection of instrumentation, structural constraints (redundancy and fault tolerance), inspection and testing cycles, and diagnostic techniques, to ensure that the requirements for risk reduction are met. To determine appropriately the inspection and testing cycle for safety instrument functions (or subsystems), online testing is required, and it is necessary to design corresponding online testing methods and measures. During the detailed design phase, requirements such as the inspection and testing cycle and testing methods for each safety instrumented function (or subsystem) must be defined. (6) Strictly regulate the installation, commissioning, and joint verification of safety instrumented systems. A comprehensive installation, commissioning, and joint verification plan should be developed and ensured to be implemented effectively; the processes and results of commissioning (individual instrument commissioning and circuit commissioning) should be recorded in detail, and management files should be established. After the construction unit has completed the installation and commissioning in accordance with the design documents, the enterprise shall, prior to putting the system into operation, organize a review and joint verification of the safety instrument system in line with **laws and regulations, standards and specifications, industry and enterprise safety management requirements, as well as technical documents related to safety requirements. This is done to ensure that the safety instrument system possesses the intended functions and meets the integrity requirements, thereby being ready for safe operation. (7) Strengthen the operation and maintenance management of safety instrumented systems in chemical enterprises. Chemical enterprises must develop operation and maintenance plans and procedures for safety instrumented systems to ensure that these systems can reliably perform all their safety-related functions, thereby achieving functional safety. The safety instrument functions shall be subject to regular and comprehensive inspection and testing in accordance with inspection and testing cycles that meet the requirements for safety integrity, with the testing process and results recorded in detail. It is necessary to strengthen the management, analysis, and handling of faults related to safety instrumented systems (including equipment failure, interlock actions, malfunctions, etc.), and gradually establish a database for such equipment failures. It is necessary to standardize the selection of equipment related to safety instrumented systems, establish systems for the approval and evaluation of such safety instrumented equipment as well as procedures for approving changes, and continuously revise and improve these systems based on the actual usage in enterprises and equipment failures. (8) Gradually improve the management systems and internal regulations for safety instrumented systems. Enterprises should formulate and improve management regulations or internal technical standards related to safety instrumented systems, integrate functional safety management into their overall safety management systems, and continuously enhance the level of process safety management. IV. Attach great importance to the management of protection measures for other related instruments (9) Strengthen process alarm management by formulating an enterprise alarm management system and enforcing it strictly. Alarms related to the functional safety integrity requirements of safety instrumented functions can be managed and tested in reference to those safety instrumented functions. (10) Strengthen the management of basic process control systems. Control loops related to safety integrity requirements shall be managed, inspected, and tested in accordance with safety instrumented functions, and the availability rate of automatic control loops must be ensured. (11) Design and implement toxic, hazardous, and flammable gas detection and protection systems in strict accordance with relevant standards; to ensure their reliable operation, such systems should be independent of the basic process control system. V. Accelerate the standardization of the management of safety instrument systems in newly constructed projects from the source (XII) Starting from January 1, 2016, large-scale chemical enterprises as well as those owned or jointly operated by foreign investors that meet the relevant criteria, and that construct new chemical plants involving \"two key areas and one major aspect\" or chemical storage facilities, must design safety instrument systems that comply with relevant standards, in accordance with the requirements of these guiding principles. (13) Starting from January 1, 2018, all newly constructed chemical plants and **chemical storage facilities that involve the ‘two key areas and one major concern’ must be designed with safety instrument systems that meet the required standards. For other newly built chemical processing units and **chemical storage facilities, safety instrument systems must, starting from January 1, 2020, comply with the requirements of functional safety standards, and such safety instrument systems shall be designed in accordance with those requirements. VI. Actively promote the evaluation of existing safety instrumented systems (14) Chemical enterprises and **chemical storage facilities that operate production units or facilities classified as “two key areas and one major hazard” should, on the basis of conducting comprehensive process hazard analyses (such as Hazard and Operability Studies), determine the functions of safety instruments and the requirements for risk reduction through risk analysis, and promptly assess whether the existing safety instrument functions meet these risk reduction requirements. (15) Enterprises shall, on the basis of assessment, formulate management plans for safety instrumented systems and regular inspection and testing plans. For safety instrument functions that do not meet the requirements, relevant maintenance plans and corrective action plans must be developed, with the assessment and improvement of the safety instrument system to be completed by the end of 2019. Other chemical processing units and **chemical storage facilities shall be implemented in accordance with the requirements set forth in these guidelines. VII. Work Requirements (16) Relevant enterprises and organizations shall, in accordance with relevant laws, regulations, standards, norms, and the requirements of these guiding principles, improve their management systems and frameworks for safety instrumented systems; they should also increase financial investment to ensure that the safety instrumented systems of newly constructed facilities meet the requirements of functional safety standards. For safety instrumented systems in operational equipment that do not meet functional safety requirements, they must be included in a rectification plan to be fixed within a specified time frame, in order to eliminate potential accident hazards, reduce the risk of accidents, prevent their occurrence, and effectively improve the inherent safety level of the enterprise. (17) Safety supervision departments at all local levels should conduct investigations and research as soon as possible, set work objectives, identify pilot units, define timeline requirements, and guide and urge enterprises to strengthen the management of chemical process safety instrumented systems and related safety protection measures. It is necessary to include aspects such as the functional safety assessment of Safety Instrumented Systems, the implementation of management systems for Safety Instrumented Systems, and personnel training in the scope of safety supervision and inspections. Provincial safety supervision bureaus are required to compile summaries of relevant inspection results each year, and submit them to the Third Department of the **General Administration of Safety Supervision by the end of February each year. Please ask the provincial safety supervision bureaus to promptly convey the spirit of these guiding principles to the safety supervision agencies at all levels within their respective jurisdictions, as well as to the relevant enterprises and design firms. **General Administration of Work Safety – Design Principles for SIS Safety Instrumented Systems. The primary function of a SIS safety instrumented system (ESD emergency shutdown system) is to automatically or manually bring the process back to a pre-determined safe state in the event of dangerous failures during production, thereby ensuring the safety of the manufacturing process and preventing serious injuries to personnel as well as significant damage to equipment. In the design of safety instrumented systems, IEC 61508 and IEC 61511 provide excellent internationally recognized technical specifications and references. When designing the circuits of such systems, it is generally necessary to follow the following principles. 1. Reliability principles (safety principles) for the design of SIS safety instrument systems (ESD emergency shutdown systems): To ensure the safe operation of process units, safety instrument systems must possess a reliability level corresponding to the Safety Integrity Level required for that process. To this end, IEC 61508 provides detailed technical specifications. For Safety Instrumented Systems, reliability has two meanings: one is the operational reliability of the Safety Instrumented System itself ; Another aspect is the reliability of the safety instrumented system in terms of its understanding of the process and its ability to provide interlock protection; there should also be high reliability in the measurement, assessment, and execution of interlocks related to the process. The main parameter for evaluating the Safety Integrity Level SIL is PFDavg (probability of failure on demand, i.e., the average rate of dangerous failures), and it is classified into levels 1 to 4 from highest to lowest. In the petrochemical industry, only SIL levels 1, 2, and 3 are typically involved; SIL4 requires substantial investment and involves a complex system, so it is generally used only in the nuclear power industry. 2. Availability principles for the design of SIS safety instrument systems (ESD emergency shutdown systems): To improve the availability of the system, SIS safety instrument systems (ESD emergency shutdown systems) should possess hardware and software self-diagnosis and testing functions. The Safety Instrumented System shall be equipped with maintenance bypass switches for each input process interlock signal, facilitating online testing and maintenance while minimizing downtime caused by maintenance of the Safety Instrumented System. It should be noted that the redundant detection elements used in the two-out-of-three voting scheme do not require bypassing, nor does the manual stop input require bypassing. At the same time, it is strictly prohibited to install bypass switches for the output signals of the safety instrumented system, in order to prevent accidents caused by improper operations. If the SIL calculation indicates that the test cycle is shorter than the process shutdown cycle, and it is not possible to ensure that performing online tests on actuators will not affect the process and thereby cause unintended shutdowns, then the design of the Safety Instrumented System must be modified as necessary. This can be achieved by increasing redundancy to prolong the test cycle, employing partial-stroke testing methods, adding manual bypass valves for valves that close during fault conditions, and adding manual shut-off valves for valves that open under such conditions, thereby enabling online testing of the valves in the Safety Instrumented System. These methods are very helpful in ensuring the availability of safety instrument systems. 3. Principle of independence in the design of SIS safety instrumented systems (ESD emergency shutdown systems): SIS safety instrumented systems (ESD emergency shutdown systems) should be independent of the basic process control systems (BPCS, such as DCS, FCS, CCS, PLCs, etc.), and carry out safety protection functions independently. The detection elements, control units, and actuators of the safety instrumented system shall be separately installed. If the process requirements call for both interlocking and control to be carried out simultaneously, the Safety Instrumented System and the BPCS should each have independent sensing elements and signal acquisition points (with some special exceptions, such as the use of a two-out-of-three sensing arrangement: three signals are fed to the DCS for decision-making, while three signals are fed to the Safety Instrumented System; in such cases, the sensing elements are shared through a signal distributor). If necessary, the SIS safety instrumented system (ESD emergency shutdown system) shall be able to communicate with the DCS in read-only mode via a data communication link, but the DCS is prohibited from writing information to the safety instrumented system through this communication link. The safety instrumented system should be equipped with an independent communication network, including separate network switches, servers, engineer stations, etc. The SIS safety instrumented system (ESD emergency shutdown system) shall utilize redundant power supplies, powered by independent dual-circuit distribution networks. It should be avoided that the signal wiring of the safety instrumented system and the BPCS share the same junction box, as well as being located within intermediate junction cabinets and control cabinets. 4. Standard certification principles for the design of SIS safety instrument systems (ESD emergency shutdown systems): With the introduction of safety standards and an increasing emphasis on safety systems, the certification of such systems has become increasingly important. The design concepts and system architectures must comply strictly with relevant international standards and obtain certification from authoritative bodies. Safety instrumented systems must be certified to IEC 61508 SIL and/or the corresponding SIL rating from TUV AK (Germany). The hardware, software, and instruments used in the SIS Safety Instrumented System (ESD Emergency Shutdown System) must be of an official version and commercially available. Additionally, they must have obtained **all mandatory certifications related to explosion protection, metrology, pressure vessels, etc.** The use of any test products is strictly prohibited. 5. Fail-safe principle: When components, equipment, elements, or energy sources within the SIS (Safety Instrumented System/ESD – Emergency Shutdown System) malfunction or fail, the design of the SIS must ensure that the process can proceed towards a safe operation or reach a safe state. This is the fail-safe principle of system design. Whether \"fail-safe\" can be achieved depends on the process and the design of the safety instrument system. The entire SIS safety instrumented system (ESD emergency shutdown system), including the field instruments and actuators, shall be designed in the following form of absolute safety: 1) The field contacts shall give an alarm when open, and be closed under normal operating conditions ; 2) The field actuator is unpowered during interlock, and powered under normal operating conditions.
Reply #22015-12-14
This was compiled by us ourselves~ Where did you see it? ?
Reply #32015-12-14
There are plenty of them online; how did it become something that you guys organized yourselves? It’s better to be sincere when doing things~
Reply #42015-12-14
Well, at least Hai Chuan didn’t see the same post. Anything that appears here is meant to be shared so that everyone can learn from it, right? I posted it in the resource sharing section; I just wanted everyone to be able to learn from it. Thank you!
Reply #52015-12-15
:victory::victory::victory::victory::victory::victory:
Reply #62015-12-15
:):):handshake
Reply #72015-12-15
:victory::victory::victory:
Reply #82015-12-15
Feel free to communicate more! Learn together*, make progress! :)

Submit a Project

**Looking for Chemical Technology, Equipment & Solutions?** No Registration Required Broader Platform Exposure | Global Chemical Service Provider Connections

Submit Request — Free Consultation

Disclaimer

This is an automated machine translation of the original thread. Some technical terms may have inaccuracies; the original text shall prevail. Click "View Original" at the top right to access the source page, which supports IP-based automatic real-time language translation. Please watch out for contact details and sales inducements to prevent fraud. All content and translations are for reference only, representing solely the poster's personal views. For enquiries, email service@hcbbs.com.