HCBBS Forum (English)
Submit Chemical Projects / Find Solutions
Amplify Your Requirements on a Broader Chemical Platform *Engineering · Technology · Equipment · Solutions*
Submit Request

SIS system valve acceptance

2018-01-10View Original

Thread Content

What qualification certificates and valve-related documents does the valve manufacturer need to provide for acceptance?
Reply #22018-01-10
To inspect valves, relevant testing and inspection methods should be used, right? If it is merely for information purposes, please provide the pressure test reports, safety grade certifications for the valves and accessories, as well as the factory inspection certificates.
Reply #32018-01-10
The most fundamental aspect of the Special Equipment Manufacturing License TS
Reply #42018-01-11
{Repost} Testing the Safety Integrity Level of the Safety Instrumented System for Certain Processes
1. Instrumented Safety Systems
The Safety Instrumented System (SIS) is a crucial component of the Safety and Automation System (SAS). The term “Safety Instrumented System” originates from the definition of safety system control systems provided by the International Society of Automation (ISA). It is also referred to as an Emergency Shutdown System (ESD), Safety Interlock System (SIS), or Instrument Protection System (IPS). A Safety Instrumented System is a system capable of performing one or more safety functions. It monitors the operation of a production facility or standalone unit, and in the event that the production process deviates from safe operating limits, it can bring the system to a safe state, thereby ensuring a certain level of safety for the facility or unit. Unlike batch control, sequence control, and process control interlocks, safety systems take action automatically (and manually if necessary) when process variables (temperature, pressure, flow rate, level, etc.) exceed specified limits, mechanical equipment fails, the system itself malfunctions, or there is a power outage. This ensures that operators and process equipment remain in a safe state. SIS can consist of any combination of sensor logic solvers and final actuators. SIS includes instrument safety control functions, it may also include instrument safety protection functions, or it may have both. SIS may include or exclude software, and human actions can also be part of SIS. The SIS system requires high reliability, which can be confirmed through testing.   2. Partial circuit testing The IEC61511 standard requires regular inspection and testing of the entire SIS system, which includes the final actuating elements such as ESD valves, in order to detect any undetected faults that could prevent the SIS from operating in accordance with safety requirements. ESD valves may experience a failure to operate when safety protection actions need to be carried out. When this occurs, it will lead to the failure of the SIS system, posing a threat to safe production, with consequences that could even be catastrophic. Analyses show that valve failures can account for over 50% of the total failures in SIS systems. The importance of valve testing is self-evident.   Partial Stroke Testing (PST) is increasingly becoming a topic of discussion, as it allows valves to be tested without shutting down production, compared to full stroke testing. This reduces the amount of hardware redundancy required for high Safety Integrity Levels (SIL), greatly extends the intervals between manual tests, and thus results in significant cost savings.   Through Partial Stroke Testing (PST), users can test the valve by determining the percentage of closure required in fault modes (when complete shutdown is needed), without having to physically close the valve completely. Partial Stroke Test (PST) is primarily used to prevent the safe closing function of safety shut-off valves from being impaired by solid deposits or corrosion, which could otherwise cause the valves to fail to operate properly and lead to accidents. In addition, the successful execution of partial journey tests can also be used to confirm or detect some yet undiscovered faults, such as whether the return spring is broken, etc.   Additionally, detecting the valve position can also determine whether the valve leaves its end point within the specified time. If it does not leave within that time, the test should be immediately terminated and an alarm should be issued. This is because at this point, the valve may suddenly pop out from its end position, resulting in serious consequences such as unstable or interrupted production. Today, PST is a technology that has been widely accepted by the oil industry, as well as recognized and approved by the IEC (International Electrotechnical Commission) and ISA (Instrumentation Society of America). The relevant standards include:
PTS-related standards:
IEC61508 – Functional safety of electrical/electronic/programmable electronic safety-related systems
IEC61511 – Functional safety – Safety instrumented systems for the process industry sector
ANSI/ISA-84.00.01 – Functional Safety: Safety instrumented systems for the process industry sector

In accordance with the requirements of IEC61511-16.3 Proof testing and inspection:
① Periodic verification tests should be carried out regularly in accordance with specified procedures, in order to detect any undetected faults and prevent the SIS system from not operating as required by the safety specifications.   ②The entire SIS system, including its logical components as well as the final components such as emergency shut-off valves (ESDV) and motors, must be tested.   ③The interval between verification tests shall be determined by calculating the average hazardous failure rate from the PFDavg (average Probability of Failure on Demand).   ④.⑤.⑥. Omitted.   It can be seen that PST is a mandatory requirement set by IEC for SIS systems.   Calculation of the 3-phase performance test (PST): The time interval for conducting PST tests on valves included in the SIS system, as well as the scope of diagnosis, depend primarily on the SIL level required for the valve and the corresponding PFDavg value. In IEC 61508, the safety lifecycle approach is adopted to evaluate the basis. During the design phase of this life safety cycle system, analysis methods such as Markov analysis, FMEA – Failure Mode and Effects Analysis, Fault tree analysis, and Hazop – Hazard and Operability Study are employed to determine the required level of safety performance. Through these methods, the frequency and consequences of risky behaviors can be determined, and the risk level can be quantified. A more general approach is to quantify it as SIL (Safety Integrity Level). The SIL levels are divided into 4 grades, with grade 4 representing the highest level of hazard requirement. Once the SIL level is determined, the average failure rate of the valve can be obtained based on the relationship between the SIL level and PFDavg; this allows for the calculation of the cycle time required for PST as well as the requirements regarding diagnostic coverage.   The relationship between SIL and PFDavg is shown in Table 1. One method for calculating PFDavg without taking redundancy into account is to use the following formula: Where: = diagnostic coverage (i.e., the efficiency of the testing); = probability of catastrophic failure; = time interval between full shutdown tests; = time interval between partial stroke tests.   As can be seen from the above equation: provided that the Safety Integrity Level remains unchanged, if the time interval between PST tests is shortened, the time interval between FST tests can be extended (thereby reducing the number of downtime inspections). This has saved costs to a great extent. Therefore, at this time, it is very important to maintain the SIL level of the ESD valve at its original level by increasing the testing frequency of PST and reducing the testing interval.   Solutions for the 4-stage Process Stress Test (PST) During normal operation of the production facility, ESD valves are usually kept in the fully open position. During PST tests, if these valves lack effective limit protection measures, their rapid response can cause them to exceed their operational limits, leading to instability in the production process. In severe cases, this can result in the valves shutting down unexpectedly, causing the production facility to stop operating and leading to accidents. Therefore, there must be a limit on the opening degree of the ESD valve to prevent it from closing accidentally. Under normal circumstances, during PST testing, the opening degree of the ESD valve is set between 10% and 30% of its full stroke. This can be achieved through various approaches: 4.1 Mechanical limit-based solution. In the case of partial-stroke testing using mechanical limits, a mechanical device is inserted between the valve and its actuator to physically prevent the valve’s position from exceeding the set point during testing, thereby avoiding plant shutdowns and system instability. Its characteristics are: (1) the safety circuit does not function during certain sections of the testing process ;   (2) Testing must be performed manually, resulting in higher testing costs ;   (3) Cannot be operated remotely or automatically ;   (4) It has a simpler structure compared to electronic systems, and does not require complex training by specialized personnel.   4.2 Dashboard-based solution
The dashboard-based partial-stroke testing involves installing a dashboard for partial-stroke testing near the valve. Using the switches and valves attached to the dashboard, the control loop associated with the emergency shut-off valve is controlled, thereby limiting the valve’s opening degree and allowing for testing of the valve. Its characteristics are: (1) The complex system and numerous components increase the likelihood of potential failures ;   (2) The safety circuit is generally unavailable during partial travel testing ;   (3) True data cannot be obtained from partial test runs ;   (4) The testing needs to be performed manually, and the cost is relatively high.   4.3 Solution Based on Valve Position Feedback Partial stroke testing based on valve position feedback involves using the valve position feedback mechanism of the control valve in emergency shut-off valves; the partial stroke test is initiated manually, and after a preset time the test signal is interrupted, causing the valve to return to its original position. The extent of the valve’s movement can be determined through the valve position feedback. Its characteristics are: (1) a relatively high failure rate ;   (2) The operation cannot be performed automatically ;   (3) Test results need to be manually recorded and explained.   4.4 Solutions based on automated control systems
The partial-stroke testing based on automated control systems is an online automatic testing system that can be operated manually or automatically. The valve control and feedback are integrated into the existing automatic control system.   (1) Use an automated control system to initiate and monitor certain stroke tests ;   (2) Use a configuration of solenoid valves and limit switches ;   (3) No additional components are required for the valve; the original solenoid valve and limit switch can be used to control the test.   4.5 Partial stroke testing via a safety valve controller Its features are: (1) The valve is equipped with a dedicated intelligent valve controller for performing partial stroke testing ;   (2) Use a configuration of solenoid valves and limit switches ;   (3) Use an automated control system to initiate and monitor certain stroke tests.   5 Conclusion Any of the systems mentioned above can meet the requirements for some type of performance testing. When making a choice, it is necessary to take into account the process requirements, the scale of the system, and the number of valves that need to be tested. If the process is simple, the system scale is small, and few valves need to be tested, the first few offline mechanical testing methods can be chosen. Conversely, the latter two intelligent online testing methods should be chosen.   Taking both performance and cost into account, the partial-stroke solution based on an automated system is a good choice. It enables valve testing without requiring any additional hardware for the valve itself, and has been widely used in many offshore engineering projects. It should be noted, however, that although the testing functions are integrated into the automatic control system, the functions of PST/SIS remain relatively independent within SAS. The so-called integration simply means that the PST/SIS system can send the final test results to SAS operators after testing is completed, or issue alerts to SAS operators in case of any faults. The SIS system should not share the PLC CPU and IO modules with other systems; furthermore, in accordance with the SIL level requirements of the circuit, the (PLC) CPU and IO modules used for processing PST/SIS must also possess the corresponding SIL processing capability. Since PST requires a high response speed, the program load of the control system as well as the input and output times must be strictly controlled. As the automation level of offshore engineering vessels increases, this approach will undoubtedly see wider application.   References: M.A.Lundteigen & M.Rausand, The effect of partial stroke testing on the reliability of safety valves. Houston Section Website: SIL & Partial Stroke Testing Solutions. IEC 61508 – Functional safety of electrical, electronic, and programmable electronic safety-related systems. IEC 61511 – Functional safety: Safety instrumented systems for the process industry sector. Please indicate the source when reproducing this content. Original address: http://www.xzbu.com/8/view-4720975.htm
Reply #52018-01-11
【Repost】SIS Safety Instrumented System Standards: SIS Classification, Verification, and Validation. How to achieve SIS safety instrumented system classification, verification, and validation? The safety verification of SIS safety instrumented systems (ESD emergency shutdown systems) is a term from the IEC61511 standard; in ANSI/ISA-84.01-1996, this concept is referred to as pre-commissioning acceptance testing. The interlock test prior to feeding is part of the SIS safety verification. The purpose of safety verification is to, through inspection and testing, prove that the installed and commissioned SIS along with its safety instrument functions meet the requirements specified in the safety requirement specification. The standard stipulates that the PSAT shall be completed before the occurrence of any hazards that the SIS instrumented safety system is designed to prevent or mitigate.   IEC61511 also states that the safety verification of SIS is sometimes referred to as field acceptance testing. For the STA of the entire SIS instrument control system (including all related devices such as sensors, logic controllers, and field final actuators), it refers to the verification test (commissioning trial run) carried out after installation and debugging, prior to the start of production; its purpose is to demonstrate that the SIS system (ESD emergency shutdown system) is ready and meets the conditions for operation in the field. It can be seen that it is an engineering node defined from a technical perspective. SIS – Safety Instrumented System. The test records and reports related to the SIS safety instrumented system (ESD emergency shutdown system), such as records of circuit tests and calibrations of sensors regarding their range and accuracy, can be used as a basis for safety verification.   Before verifying the SIS safety instrumented system (ESD emergency shutdown system), a detailed verification plan should be developed. The verification plan should define all activities required at the security verification nodes, including: verification of compliance with the security requirements specification ; Functional requirements under all process operation modes ; Reasonably predicted abnormal states and their responses ‘Steps, measures, and techniques employed for verification ; Schedule ; Requirements for the independence of personnel, departments, and organizations involved in verification work ; Technical documents serving as the basis for verification (such as functional logic diagrams, cause-and-effect diagrams, and other logical descriptions). Verification of the SIS safety instrumented system (ESD emergency shutdown system) includes the following aspects: 1) Whether all the functions implemented by the SIS safety instrumented system (ESD emergency shutdown system) meet the requirements specified in the safety requirements document.   2) It is confirmed that abnormal operations of the DCS or other third-party systems that communicate with the safety logic controller will not affect the proper functioning of the SIS safety instrumented system (ESD emergency shutdown system) logic controller.   3) Test the communication functionality of the logic controller of the SIS safety instrumented system (ESD emergency shutdown system) with the DCS or any other third-party system or network.   4) For the logic controllers of SIS safety instrumented systems (ESD emergency shutdown systems) with redundant configurations, examine their redundancy performance and characteristics of degraded operation modes.   5) Verify that all technical documents of the SIS safety instrument system are consistent with the installed system.   6) Review SIF’s signal processing for situations such as measurement values exceeding the range.   7) Check the alarm display and operation screen.   8) Test the calculation function in the logic.   9) The reset function in the verification logic.   10) Test the functions of the maintenance bypass and operation bypass.   11) The time intervals for inspection, testing, and verification are clearly specified in the maintenance procedures.   12) Review or test the required diagnostic alarm functions.   13) The desired SIS system state when support systems such as power and gas supplies fail, as well as after they are restored.   14) Verify that the SIS Safety Instrumented System (ESD Emergency Shutdown System) meets the requirements for EMC immunity.   15) Conduct a visual inspection of the installation status, including whether the nameplates, tag numbers, and markings are correct and whether there are any missing items ; Whether the exhaust port of the solenoid valve is blocked, etc.

Submit a Project

**Looking for Chemical Technology, Equipment & Solutions?** No Registration Required Broader Platform Exposure | Global Chemical Service Provider Connections

Submit Request — Free Consultation

Disclaimer

This is an automated machine translation of the original thread. Some technical terms may have inaccuracies; the original text shall prevail. Click "View Original" at the top right to access the source page, which supports IP-based automatic real-time language translation. Please watch out for contact details and sales inducements to prevent fraud. All content and translations are for reference only, representing solely the poster's personal views. For enquiries, email service@hcbbs.com.