Proof Testing and Redundant Use in Safety Instrumented Systems
Industrial accidents are an inevitable phenomenon that must be prevented due to the losses they cause. In this context, the largest and most important part of the work undertaken falls under the heading of process safety.
At facilities, a risk assessment is first conducted to identify the potential risks inherent in the process. As a result of this work, it becomes clear how much risk reduction is needed to bring the facility to a safe level.
This difference—the required risk reduction—is expressed as Safety Integrity Level (SIL). SIL consists of 4 levels; for the process requiring the most risk reduction (the most hazardous process), the level is 4, while for the least hazardous, this level is 1.
For this reason, each control loop created must meet this required SIL level.
Although correct device selection is the first step in creating safe loops and processes, it is not sufficient on its own. Appropriate installation conditions, maintenance, testing, and training for the relevant personnel on the subject are also of great importance.
For a device that makes up a safety loop, device maintenance and proof testing are sometimes confused with each other. Devices have a SIL level from the moment they are put into use, but this level does not remain constant throughout their operation.
To ensure that the specified SIL level is met, proof testing must be performed on the relevant device at the intervals specified in its SIL certificate (Test interval, Ti).
The SIL value specified for a device is actually an average value that the device will have at the specified test intervals (PFDavg), and it loses validity if proof testing is not performed at the specified intervals. The reason for this is that the average probability of failure (PFD) used in determining the SIL value is a mathematical function that increases in direct proportion to time. As shown in the figure below, if proof testing is not performed, the PFDavg value increases over time, reaching lower SIL levels—that is, a less safe range. Through proof testing performed, it returns to the initial level or the nearest possible point.Because high-technology devices have low PFD values, the required proof testing interval also shows improvement proportionally.
For example, a flowmeter with an FIT (Failure in Time) value of 160, defined as the failure rate in a given time period, requires proof testing at least every 2 years, while a next-generation device with an FIT value of 73 has this interval reduced to 5 years. For this reason, the FIT value stands out as another important parameter alongside the device's current SIL value. The lower the FIT value a device has, the less frequently it will require proof testing to maintain its current SIL value. The figure below clearly shows the impact of this.Proof testing performed can be classified into two categories: wet or remote partial. Wet testing is performed directly on the process and provides a 100% return to the initial value. However, in some cases, wet testing may not be possible. With newly developed devices, remote partial proof testing is also an option. A device's ability to permit remote proof testing depends on its capability to test device functions both in software and hardware, and the scope of partial proof testing varies from device to device, determining the extent to which partial proof testing will reduce the average probability of failure.Since partial proof testing does not provide full restoration, although it may extend intervals, it does not completely eliminate the need for wet testing.
In some cases, a safety instrumented system (SIS) may not achieve the desired SIL level even if all components individually meet the desired SIL level. As shown in the example below, although all components individually provide SIL2 compliance, the safety loop they form remains at SIL1 level. To overcome this situation, redundancy is employed.A device that can provide a SIL level on its own can provide a higher SIL level when used redundantly.
Of course, this may not apply to every device. The SIL level provided through redundancy must also be specified in the SIL certificate or must be verifiable through necessary calculations. Redundancy can also be applied to reduce the likelihood of false alarms. In this way, unnecessary shutdowns can be prevented and facility availability can be improved. For redundancy, an expression in the form of MooN is used. In this expression, N represents the total number of devices used, while M represents the number of devices that must be in alarm position for an alarm to be triggered. Looking at it through an example; 1oo2 indicates that a total of two devices are used in the system and an alarm will be triggered when one of the two devices goes into alarm position. 2oo2, on the other hand, indicates a total of two devices are used, but both devices must go into alarm position for an alarm to be triggered. In the first case, an increase in safety level is provided, while in the second case, the safety level remains equivalent to using a single device, but the likelihood of false alarms is reduced and facility availability is increased. To achieve different SIL levels and increase availability, multi-channel redundant system designs can be configured in different ways according to requirements. Not every multi-channel system will take you to a better SIL level. For example, in homogeneous redundancy, using two identical devices that are SIL2 in both software and hardware together can still meet SIL2 level because common failure rates will be high. To make such a system SIL3, either the devices must be at least SIL3 on the software side, or different types (different principles) of devices must be used (heterogeneous redundancy). An example of heterogeneous redundancy would be one device performing measurement using the differential pressure principle and another operating on the radar principle at a point where level measurement is conducted. The most important thing to remember: Taking precautions will always be more economical than paying the price of an accident. Cem Özen Industry Manager Endress Hauser A.Ş.Advertisement
Ad Space728 × 90








