You are on page 1of 2

GULF FIRE GULF FIRE

Fire and gas safety systems  Designing and


implementing a fire and
gas detection system for

for oil and gas applications


hazardous applications,
such as offshore oil
platforms, requires a
custom solution tailored to
the site’s unique layout and
Process owners and fire protection professionals in the oil and gas industry know that certification needs.

functional safety system components such as flame and gas detectors need to be certified 1 Safety System Controller
2 Explosion-proof
for compliance with specific standards, including a facility’s target Safety Integrity Level (SIL). Smoke Detector
3 Extinguishing
What is not as well known is that the certifying bodies asked to determine SIL compliance Releasing Circuits
4 Line-of-Sight IR
may not be accredited to conduct every certification they undertake. Gas Detector
5 Multispectrum
he International Electrotechnical process must be set up so that one IR Flame Detector

7 Image courtesy of Det-Tronics Inc.


Commission (IEC) defines the can be reasonably confident the final 6 Addressable Smoke
requirements for ensuring system will attain the required SIL level. and Heat Module
systems are designed, implemented, Each component used in the functional 7 Point IR Gas Detector
operated and maintained to attain a target safety system must also be certified for
Safety Integrity Level (SIL). Defined as the compliance with the desired SIL level.
relative level of risk-reduction provided Although product certifying bodies can
by a safety function, the target SIL for an certify to any standard, they may not have SIL doesn’t stand still ■ Treatment of no-effect failures. The components and sub-assemblies meet
application or process is arrived at through accreditation for that standard, which As an international safety standards FMEDA calculations used now require required standards.
a risk assessment. This target SIL becomes means there is no third-party confirmation authority, IEC strives to anticipate safety the exclusion of non-safety, “no-effect It is not uncommon to see safety
a requirement for the final system, and of their competency. hazards and develop requirements, failures.” A no-effect failure is the failure components and sub-assemblies such
the specific safety integrity level (SIL 1, processes and procedures that anticipate of a component that is part of the as fire detectors referred to as being SIL
Jon D. Miller 2, 3 or 4) characterizes the development and mitigate them. As voids and weaknesses safety-related circuit, but which has no “certified.” Technically, this is incorrect. SIL
requirements that must be met in order to in the code are identified or new issues and effect on the functional/system level certification applies to functional safety
achieve the overall risk reduction target.  SIL certifications can be an important technologies emerge, requirements evolve when it fails. Under edition 2000, no- processes at the system level and not to
In effect, the SIL requirement factor in processors’ efforts to protect human to bridge the gaps, address the issues and effect failures were considered safe and components contained in that system.
determines how the development life, plant assets and business operations. improve the standard. From early editions could be tallied as such for purposes When a device manufacturer refers to
in 1998 and 2000 to its most current edition, of calculating the overall safety score. its product as certified under SIL, what
IEC 61508 Series (2010), major modifications Under edition 2010, no-effect failures they are really communicating is that
have been introduced within the standard. cannot be added to the safe side of the the product has been evaluated against
Specifically, IEC 61508 Series (2010) changed ledger for purposes of balancing out the appropriate set of requirements, has
or added several requirements, including: unsafe findings. passed them, and is therefore “compliant”
■ Electromagnetic compatibility (EMC) with IEC 61508. In effect, the product is
■ Traceability. Specification must now requirements. Electromagnetic “SIL capable,” helping to contribute to the
provide details of a component’s supply immunity is of critical importance SIL certification of the system in which the
Mark A. Gaalswyk chain and document how a component to functional safety, and is now product is used.
relates to other components in a sub- mandatory rather than optional.
assembly or integrated system. Not all product certifiers
Jon D. Miller has over 25 years’ experience in ■ Redundancy of SIL 2 products and Components need to be SIL-capable are equally qualified
functional safety and hazardous locations ,
focusing on fire and gas detection and systems services no longer achieves SIL 3. It is no Functional safety certification addresses The relevant accreditation standard for
with Det-Tronics since 1996. He is Chairman
for the U.S. and International Gas Detection longer the case that functional system how the entire fire and gas detection product certifying bodies is ISO/IEC 17065,
Standards Development Committees and is a
member of IEEE, ISA, UL, and IEC committees
level certification can be achieved system meets the requirements and IEC 61508:2010 should be explicitly
responsible for hazardous locations and by applying redundancy to SIL 2 and standards set by the regulatory mentioned in the scope of a certifying
functional safety electrical equipment.
Miller holds an MBA and bachelor’s degree in components and processes. The only agencies. This is a process that involves organization’s accreditation. Companies
Electrical Engineering.
way to achieve SIL 3 functional system conducting an initial safety assessment, offering to certify products are numerous
Mark A. Gaalswyk has held roles in
certification is by using SIL 3 compliant determining what actions need to be and include organizations such as exida,
7 Image courtesy of Det-Tronics Inc.

Engineering, Compliance and Product


Management at multiple UTC companies, components in conjunction with SIL 3 taken to enhance or upgrade the safety FM, SIRA, UL and TÜV Rheinland. They
most recently serving as Group Leader for
Det-Tronics system solutions development certified processes (with or without platform, and having the appropriate provide a variety of services when it
group. Gaalswyk’s compliance work focused on
Functional Safety and he is a certified FMEDA redundancy) or using redundant SIL 2 certifying companies and agencies comes to certification, and each is unique
assessor. He holds an MBA and a bachelor’s
degree in Physics. compliant components in conjunction evaluate the systems. The process also in its capabilities and accreditations.
with SIL 3 certified processes. requires determining whether system’s The accreditation bodies that evaluate

112 G U L F F I R E J A N U A R Y 2 017 www.gulffire.com Subscribe at www.gulffire.mdmpublishing.com/subscribe J A N U A R Y 2 017 G U L F F I R E 113


GULF FIRE

product certifiers look for conformance their scope of accreditation (item B above). in the newest version of IEC 61508.
with competency standards to ensure Such certifications will not include the The product manufacturer must
that products are evaluated and certified certification body logo on the certificate. first prove it has a SIL 3-compliant
by the product certifier to meet expected Without this crucial step there is no formal development process, because process
performance levels. evidence of competency, and safety may capability is fundamentally necessary
The accreditation body seeks to ensure be compromised. as a systematic measure in assuring
products are properly certified, which product design robustness.
generally means: Other Cautions about SIL Certifications ■ A certification of SIL compliance may
■ A SIL-capable certification does not not be to current standards. Each SIL
A The product is labeled with the mean that the product is performance certificate includes the standards met,
registered certification mark; approved. A SIL-capable product and particularly significant, the year of
B The product certifier issues certification certificate may list a variety of codes release of the standard used to issue
to a well-recognized test standard and standards. Such a list must not be the certification. Products evaluated
that is within the certifier’s scope of mistaken for compliance. It means only to an older standard may or may not
accreditation; and that during evaluation such codes and meet the current standard. For instance,
C The product certifier issues certification standards were considered. if a product has been evaluated to the
from one of its recognized facility ■ Redundancy cannot make a SIL 2 older IEC 61508:2000 (Edition 1) Series
locations. -compliant product SIL 3. Another released version, a potential buyer
misperception relating to SIL is that needs to be aware that this standard
Points A and C above are usually well the manufacturer of a SIL 2-capable version is less specific and therefore
understood and applied. However, not product can claim SIL 3 compliance allows for more optimistic Safe Failure
all product certifiers issue functional by simply requiring redundancy Fraction values (therefore less safe)
safety certifications per IEC 61508 within (HFT + 1). This is no longer acceptable than the most current 2010 (Edition 2)
released version.

In summary
Products designed to reduce risks in
hazardous oil and gas applications must
be certified to particular standards, and
those who offer product certification
are responsible for examining these
products to ensure that they meet
functional safety requirements. However,
not all product certifiers are in a position
to certify what a specific application
may require. Confirming that a product
certifier is accredited for the assessment of
conformity to IEC 61508 is a critical step in
ensuring the functional safety of fire and
gas systems.
 The matrix above shows that each product certifying  Both product and process SIL
organization is unique in its accredited ability to certify certifications are required for SIL system Authors’ disclaimer
products to different standards. As of December 2016, certification. As highlighted, a system The information above is provided for
no product certifier was accredited for all three IEC with SIL 2 products and SIL 2 process informational purposes only and is not
certifications: SIL, performance and hazardous locations. cannot attain SIL 3 certification. intended to provide professional services
or substitute for the review and advice, in
any given circumstances, of an appropriate
professional. Det-Tronics makes every
effort to provide timely and accurate
information but makes no claims, promises,
or warranty regarding the accuracy,
completeness, timeliness or adequacy of This article has been reproduced with kind permission of MDM Publishing Ltd. AR-1117 | January 2017
the information provided in this paper and
expressly disclaims any implied warranties
and any liability for use of this white paper
or reliance on views expressed in it. Corporate Office
6901 West 110th Street Phone: 952.946.6491
For more information, go to Minneapolis, MN 55438 USA Toll-free: 800.765.3473
 www.det-tronics.com www.det-tronics.com Fax: 952.829.8750
det-tronics@det-tronics.com

114 G U L F F I R E J A N U A R Y 2 017 www.gulffire.com © 2017 Detector Electronics Corporation. All rights reserved.

You might also like