Professional Documents
Culture Documents
SUG Presentation IEC SIL Jan 2007
SUG Presentation IEC SIL Jan 2007
Introduction
Concepts for defining Safety Integrity Level (SIL) and
choosing equipment
Sponsored by
1
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
Introduction
Concepts for defining Safety Integrity Level (SIL) &
choosing equipment
Program
2
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
Information resources
www.iec.ch
www.iec.ch/zone/fsafety
www.iec.ch/zone/fsafety/questions.htm
www.safetyusersgroup.com
3
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
IEC 61508
Functional safety of
Electrical/Electronic/Programmable Electronic (E/E/PE)
safety-related systems
▼Manufacturer
► Safety Equipment
Electrical equipment
Electronic equipment
Programmable electronic equipment
4
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
5
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
PROCESS PROCESS
SECTOR SECTOR
HARDWARE SOFTWARE
DEVELOPING
DEVELOPING USING USING DEVELOPING DEVELOPING APPLICATION
NEW PROVEN-IN- HARDWARE EMBEDDED APPLICATION SOFTWARE
HARDWARE USE DEVELOPED (SYSTEM) SOFTWARE USING
DEVICES HARDWARE AND SOFTWARE USING FULL LIMITED
ACCESSED VARIABILITY VARIABILITY
DEVICES
ACCORDING LANGUAGES LANGUAGES
TO IEC 61508
OR FIXED
PROGRAMS
FOLLOW FOLLOW FOLLOW FOLLOW FOLLOW FOLLOW
IEC 61508 IEC 61511 IEC 61511 IEC 61508-3 IEC 61508-3 IEC 61511
6
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
7
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
8
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
9
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
Technical Support
requirements parts
PART 1 References
Clause 2
Development of the overall safety
requirements (concept, scope definition, PART 1
hazard and risk assessment)
Definitions and
Clause 8 abbreviations
Clause 3
PART 1
PART 1
Danger / Hazard
Risk
Tolerable risk
Safety
Risk reduction
12
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
13
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
14
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
Protective measures
15
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
Risk protection
EMERGENCY MEANS
PROTECTION
PHYSISCAL SAFETY
PREVENTION
INSTRUMENTED SAFETY
PROCESS CONTROL
PROCESS
Example
Residual risk ≠ 0
17
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
Functional Safety
• Part of the overall safety relating to the EUC and the EUC control
system which depends on the correct functioning of the E/E/PE
safety-related systems, other technology safety-related systems
and external risk reduction facilities
18
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
19
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
21
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
22
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
EUC risk
• Risk arising from the EUC or its interaction with the EUC control
system
NOTE 1 – The risk in this context is that associated with the specific hazardous event in which
E/E/PE safety-related systems, other technology safety-related systems and external risk reduction
facilities are to be used to provide the necessary risk reduction, (i.e. the risk associated with
functional safety).
NOTE 2 – The EUC risk is indicated in figure A.1 of IEC 61508-5. The main purpose of determining
the EUC risk is to establish a reference point for the risk without taking into account E/E/PE safety-
related systems, other technology safety-related systems and external risk reduction facilities.
NOTE 3 – Assessment of this risk will include associated human factor issues.
23
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
► Actual risk
► Risk is a measure of the probability and consequence of the
occurrence of a specified hazardous event
► EUC risk
Risk arising from the EUC or its interaction with the EUC control
system
► Tolerable risk is determined on a societal basis and involves
consideration of societal and political factors.
Once the tolerable risk has been set, and the necessary risk
reduction estimated, the safety integrity requirements for the SIS can
be allocated. 24
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
25
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
27
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
28
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
29
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
30
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
31
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
2. Key concepts
2. Key concepts
33
16 De-commisioning or disposal
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
2. Key concepts
01 Concept
34
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
2. Key concepts
Overall Planning
35
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
2. Key concepts
Realization Realization
09 Safety
SafetyRelated
Related Systems 10 Safety Related 11 External Risk
Systems
E/E/PES Systems Reduction
Facilities
Other Other
Technology Technology
36
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
2. Key concepts
Back to appropriate
13 Overall Safety Validation overall safety life cycle
phase
16 De-commisioning or disposal
37
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
2. Key concepts
► Systematic failures
- Failure related in a deterministic way to a cause
- Relate to design & manufacturing process, operational procedure…
- Found only if specific test can find it!
- Standard does not consider them for failure analysis
38
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
2. Key concepts
39
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
2. Key concepts
► SRS
- Results from Hazard and Risk analysis >> SRS of each SF need to
protect the process
- As a minimum the SRS defines 5 elements for each safety function
40
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
2. Key concepts
• Suppliers
Proof the classification of their products.
• Plant builders/Engineering
Obligation to design and engineer the plant appropriately.
• End Users/Operators
Request compliant safety instrumented devices.
They must proof the remaining risk/tolerable risk.
• Insurance companies, government departments
Request proof of sufficient risk reduction and what risk limit is
achieved.
42
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
43
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
44
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
4 ≥10-5 to <10-4
3 ≥10-4 to <10-3
2 ≥10-3 to <10-2
1 ≥10-2 to <10-1
45
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
4 ≥10-9 to <10-8
3 ≥10-8 to <10-7
2 ≥10-7 to <10-6
1 ≥10-6 to <10-5
46
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
1 a -
Ga
Cb Fa Gb
Fb 2 1 a
Ga
Cc Fa Gb
3 2 1
Fb Ga
Cd Gb
Fa 4 3 2
Fb Ga
Gb
a - no special safety requirements b 4 3
b – a single SIS is insufficient
47
1,2,3,4 - SIL
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
Duration of stay of a person in the dangerous area or frequency & exposure time
Fa Seldom to frequent
Fb Frequent to permanent
48
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
1 a -
Ga
Cb Fa Gb
Fb 2 1 a
Ga
Cc Fa Gb
3 2 1
Fb Ga
Cd Gb
Fa 4 3 2
Fb Ga
Gb
b 4 3
Cb Severe injury or death of a person
Fa Seldom to frequent 49
Gb Hardly possible
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
50
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
PFD Probability of Failure on Demand - Mean failure probability of function for the demand
PFDsys Failure probability of complete measuring system
PFDs Failure probability of sensor
PFDL Failure probability of logic solver
PFDA Failure probability of actuator
51
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
52
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
4 ≥10-5 to <10-4
3 ≥10-4 to <10-3
2 ≥10-3 to <10-2
1 ≥10-2 to <10-1
53
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
54
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
4 ≥10-5 to <10-4
3 ≥10-4 to <10-3
2 ≥10-3 to <10-2
1 ≥10-2 to <10-1
55
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
4. Choosing equipment
o
I u
n t
CPU
p p
u u
t t
4. Choosing equipment
4. Choosing equipment
Architecture
Redundancy HFT
Voting
1oo1 no redundancy 0
1oo2 Dual 1
2oo2 no redundancy 0
1oo3 Triple 2
2oo3 Triple 1
58
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
4. Choosing equipment
λ +λ +λ
SFF =
SD SU DD
λ +λ +λ +λ
SD SU DD DU
4. Choosing equipment
4. Choosing equipment
61
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
4. Choosing equipment
4. Choosing equipment
The principal are identical between IEC 61508 and IEC 61511,
BUT simpler with IEC 61511.
63
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
4. Choosing equipment
4. Choosing equipment
proven-in-use
when a documented assessment has shown that there is appropriate
evidence, based on the previous use of the component, that the
component is suitable for use in a safety instrumented system (see
“prior use” in 11.5)
65
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
4. Choosing equipment
66
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
4. Choosing equipment
PROCESS PROCESS
SECTOR SECTOR
HARDWARE SOFTWARE
DEVELOPING
DEVELOPING USING USING DEVELOPING DEVELOPING APPLICATION
NEW PROVEN-IN- HARDWARE EMBEDDED APPLICATION SOFTWARE
HARDWARE USE DEVELOPED (SYSTEM) SOFTWARE USING
DEVICES HARDWARE AND SOFTWARE USING FULL LIMITED
ACCESSED VARIABILITY VARIABILITY
DEVICES
ACCORDING LANGUAGES LANGUAGES
TO IEC 61508
OR FIXED
PROGRAMS
FOLLOW FOLLOW FOLLOW FOLLOW FOLLOW FOLLOW
IEC 61508 IEC 61511 IEC 61511 IEC 61508-3 IEC 61508-3 IEC 61511
67
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
4. Choosing equipment
4. Choosing equipment
• Applicable standard
• Type
• Hardware fault tolerance
• Safe failure fraction
• Safe undetected failure rate
• Dangerous detected failure rate
• Dangerous undetected failure rate
• SIL of the product
• Recommended periodic proof test interval!
4. Choosing equipment
70
An independent professional Community with a unique focus: SAFETY INSTRUMENTATION
4. Choosing equipment
4.3 FAQ
71