Académique Documents
Professionnel Documents
Culture Documents
Standards
Certification
Education & Training
Publishing
Conferences & Exhibits
Strategic Proof Testing
William Goble
Sellersville, PA., USA +1-215-453-1720
www.exida.com
2
IEC 61511 Safety Life Cycle
3
Risk Analysis and Protection Layer Design
Sub-clause 8
SIS Design
Allocation of Safety Functions to Safety Instrumented
Systems or Other Means of Risk Reduction
Sub-clause 9
Safety Requirements Specification -
Safety Requirements Specification
for the Safety Instrumented System ANALYSIS Functional Description of each Safety
Sub-clause 10
Instrumented Function, Target SIL,
Design and Development of Design and Development of
Safety Instrumented System Other Means of Risk Reduction Mitigated Hazards, Process parameters,
Sub-clause 11 Sub-clause 9
Logic, Bypass/Maintenance
Installation, Commissioning, and Validation
Sub-clause 14 REALIZATION requirements, Response time, etc
Operation and Maintenance
Sub-clause 15 OPERATION
Decommissioning
Modification
Sub-clause 15.4 Sub-clause 16 7a. Select Choose sensor, logic solver
Technology and final element technology
PERIODIC INSPECTION
Determine Test Time Interval: 5 Years, 1 Year, 6 Mos, 3 Mos.
Philosophy
Procedure: Shutdown Plant?
Reliability Bypass SIS?
Evaluation
Transmitter Testing?
Performance No Valve / Actuator Testing?
Target Met?
Yes, proceed
5
SIF Verification Task
Safety Requirements- Verificación de las FIS
Specification - Safety
Function Requirements
including target SIL
Manufacturer’s
Failure Data
7d. Reliability and
Failure Data Safety Evaluation
Database
PFDavg, RRF
MTTFS,
SIL achieved
6
Proof Test
8
Pressure Transmitters
Transmisores de Presión
– Failure Modes
– Output Saturated Hi
– Output Saturated Lo
S/D – Frozen Output
– Indication Error Hi
– Indication Error Lo
– Output cannot get to 100%
D – Output cannot get to 0%
– Internal automatic diagnostic circuit
failed
D – Temperature compensation circuit
failed
A
?
9
Actuator Failure Modes
Modos de Falla de un Actuador
– Failure Modes
– Severe leak/loss of air pressure
S – Clogged air inlet – trapped air
– Damaged/jammed spring – no
D return force
– Jammed shaft – no movement
D – Damaged shaft – no force / torque
– Automatic partial stroke box fails
D
A
10
Ball Valve Failure Modes
Modos de Falla de una Válvula de Bola
– Failure Modes
D • No movement /
excessive force-
torque required
D • Leaky seal – cannot
stop flow
– Application issues
• Environment
• Tight shut off
11
Proof Test
12
Safety Manual
Manual de Seguridad
• Products intended for SIF applications are supplied with a “Safety Manual.”
– The “safety manual” may be part of another document
• The Safety Manual contains important restrictions on how the product must be
used in order to maintain safety.
– Environmental restrictions
– Design restrictions
– Periodic Inspection / Test requirements
– Failure rate / failure mode data
13
Failure Modes, Effects and Diagnostic Analysis (FMEDA)
From ISA Book: Control Systems Safety Evaluation and Reliability, W.M. Goble, 1998 used with permission.
14
Failure Modes, Effects and Diagnostic Analysis (FMEDA)
PROVIDES:
• IEC 61508 Safe Failure Fraction
• Coverage Factors: CD, CS
• Failure Rates: λS, λD, λSD, λSU, λDD, λDU
Also can provide PROOF TEST
EFFECTIVENESS
15
Safety Manual
Test Content
From Rosemount
3051S, Safety:
Proof Test 1 –
65%
Proof Test 2 –
98%
Why bother with
proof test 1?
17
Strategic Proof Test
18
Questions?
19