Why do I need dual channel safety? Pete Archer - Product Specialist June 2018

Similar documents
The Best Use of Lockout/Tagout and Control Reliable Circuits

Implementing Emergency Stop Systems - Safety Considerations & Regulations A PRACTICAL GUIDE V1.0.0

PL estimation acc. to EN ISO

Managing for Liability Avoidance. (c) Lewis Bass

The following gives a brief overview of the characteristics of the most commonly used devices.

New Thinking in Control Reliability

Safety in pneumatic automation

Valve Communication Solutions. Safety instrumented systems

By Paul Malburg Facility Engineer / Controls Manager Madico, Inc.

What safety level can be reached when combining a contactor with a circuitbreaker for fail-safe switching?

Safely on the way in the automotive and Tier 1 supplier industry

Functional safety. Functional safety of Programmable systems, devices & components: Requirements from global & national standards

GAS FUEL VALVE FORM AGV5 OM 8-03

Safe hydraulics for hydroforming presses. more finished product to be created from less raw material.

Application Note. Safety Sub-function PUS Category 1, up to PL c. Application Note PUS, Category 1, up to PL c M20 S22 R20 M1 Q20

Safety Beyond the Electrics

Integrating Safety and Automation

Tullis Russell Machinery Safety Conference. David Robinson - Process Control Manager

MANUAL DIRECT PURGE OPTION. UNION Instruments GmbH CWD2005 PLUS. General information, safety standards and regulations for direct purge option

A4s Operation Manual

Session: 14 SIL or PL? What is the difference?

DETERMINATION OF SAFETY REQUIREMENTS FOR SAFETY- RELATED PROTECTION AND CONTROL SYSTEMS - IEC 61508

Sharing practice: OEM prescribed maintenance. Peter Kohler / Andy Webb

A4 Operation Manual. Fig.1-1 Controller Socket Diagram

E28/Q28 Safety Exhaust Valve Externally Monitored

Safety Manual VEGAVIB series 60

Safety Manual OPTISWITCH series relay (DPDT)

CT433 - Machine Safety

Ultima. X Series Gas Monitor

CITY AND COUNTY OF DENVER CR&CF RISK UNIT Job Hazard Analysis

P33 Safety Exhaust Valve Externally Monitored. Bulletin 0700-B14 ENGINEERING YOUR SUCCESS.

FLUID POWER FLUID POWER EQUIPMENT TUTORIAL ACCUMULATORS. This work covers part of outcome 2 of the Edexcel standard module:

Application Note. Safety Sub-functions SSC Category 1, up to PL c PUS Category 1, up to PL c. Application Note SSC, PUS, Category 1, up to PL c STOP

EMERGENCY SHUT-DOWN RELIABILITY ADVANTAGE

FP15 Interface Valve. SIL Safety Manual. SIL SM.018 Rev 1. Compiled By : G. Elliott, Date: 30/10/2017. Innovative and Reliable Valve & Pump Solutions

Operating instructions Safety Rope Emergency Stop Switches ZB0052 / ZB0053 ZB0072 / ZB0073

Advanced Pump Control for Irrigation Applications

Section 1: Multiple Choice

IST-203 Online DCS Migration Tool. Product presentation

PROCESS AUTOMATION SIL. Manual Safety Integrity Level. Edition 2005 IEC 61508/61511

ACV-10 Automatic Control Valve

Workshop Information IAEA Workshop

Application of EN ISO in electro-pneumatic control systems

Section 1: Multiple Choice Explained EXAMPLE

Understanding safety life cycles

*ACTUATOR CIRCUIT TEST DIAGNOSTICS (DUAL-ZONE)

AE R1 February 2015

EL-O-Matic E and P Series Pneumatic Actuator SIL Safety Manual

CLARKES ERO FEEDER MANUAL

Lockout. HealthandSafetyOntario.ca. What is Lockout? How is a Lockout Done? Why is a Lockout Necessary?

The Criticality of Cooling

Partial Stroke Testing. A.F.M. Prins

model for functional safety of

R E D I C O N T R O L S

Elements of a Lockout/Tagout Program OSHA

Copeland Discus with CoreSense Diagnostics January 2011

PLEASE READ CAREFULLY BEFORE INSTALLING OR USING MEGA POOL SAVER MPS 1100

200 A, 15 and 25 kv class loadbreak bushing insert installation instructions

SIL Safety Manual. ULTRAMAT 6 Gas Analyzer for the Determination of IR-Absorbing Gases. Supplement to instruction manual ULTRAMAT 6 and OXYMAT 6

Master Control Systems, Inc. Variable Speed Fire Pump Controllers

Impact on People. A minor injury with no permanent health damage

DATA ITEM DESCRIPTION Title: Failure Modes, Effects, and Criticality Analysis Report

OPERATIONS MANUAL RIGHT ANGLE CAPSTAN

Hydraulic (Subsea) Shuttle Valves

Victoreen B. Operators Manual. Image Intensifier Ion Chamber

Master Control Systems, Inc. Variable Speed Fire Pump Controllers

BUBBLER CONTROL SYSTEM

Safety Manual. Process pressure transmitter IPT-1* 4 20 ma/hart. Process pressure transmitter IPT-1*

LENNOX SLP98UHV DIAGNOSTIC CODES

MTS SafeGuard Technology. Solutions to protect test operators, equipment and specimen. be certain.

Unit 24: Applications of Pneumatics and Hydraulics

IBU3 Manual Addendum 1

COOPER POWER SERIES. 600 A, 15, 25, and 35 kv Class Cleer Grounding Elbow Installation Instructions. Loadbreak Apparatus Connectors MN650056EN

COOPER POWER SERIES. 200 A 15, 25, and 35 kv class portable feedthru installation instructions. Loadbreak Apparatus Connectors MN650037EN

Commissioning and safety manual

COOPER POWER SERIES. VariSTAR Storm Trapper high energy MOV arrester installation instructions. Surge Arresters MN235017EN

Safety Manual VEGAVIB series 60

Preview to the 2018 NFPA 70E, the Standard for Electrical Safety in the Workplace

OPERATION MANUAL. For the PARU01. Underwater Plasma Cutting. Supervisors Remote Panel

User Manual 1 P a g e Rev. V1.6-EN 11/08/2014

TEST REPORT Safety Laboratory-MD Team Report No.: RA/2013/90003

This manual provides necessary requirements for meeting the IEC or IEC functional safety standards.

Fail Operational Controls for an Independent Metering Valve

There is one Fact Sheet for each module presented in the course. They are easily printed either singly or collectively.

Safety Circuit Design. Heinz Knackstedt Safety Engineer C&E sales, inc.

Available online at ScienceDirect. Jiří Zahálka*, Jiří Tůma, František Bradáč

OC Panel High Limit Aquastat Kit, Manual Reset p/n

Time-Delay Electropneumatic Applications

Functional Safety SIL Safety Instrumented Systems in the Process Industry

TECHNICAL DATA. System water supply pressure enters the priming chamber of the deluge valve (A.1) through the 1/4 (8 mm) priming line, which

Mini Pod Press. #78H-M2 Mini Pod Press Manual-R1

Application of CHE100 in Frequency Conversion Alteration of Air Compressor System

(C) Anton Setzer 2003 (except for pictures) A2. Hazard Analysis

LOCK-OUT/TAG-OUT (LO/TO) SAFETY PROGRAM

Exercise 3-2. Two-Wire and Three-Wire Controls EXERCISE OBJECTIVE DISCUSSION OUTLINE DISCUSSION. Two-wire control

Control of Hazardous Energy Lockout / Tagout Program

H250 M9 Supplementary instructions

Roller AC Servo System

HAZARD RECOGNITION EVALUATION and CONTROL

Model PSI Compressor with 3-Gallon Air Tank 12VDC

Transcription:

Why do I need dual channel safety? Pete Archer - Product Specialist June 2018 To answer this, we need some basic background information. First why is safety needed? Here are 4 good reasons. 1. To Protect Employees 2. To Reduce insurance costs 3. To Satisfy government regulations 4. To Minimize liability and claims exposure Second is the concept of Control Reliability. From ANSI B11.20-1991Paragraph 6.13, The control system shall be designed, constructed, and installed such that a single component failure within the system does not prevent stopping action from taking place - but will prevent successive system cycles until the failure has been corrected. Any single fault shall be detected and shall not lead to a loss of the safety system. (Multiple faults can result in a loss of the safety system). Successive machine cycles shall be prevented until the fault is corrected. This strongly implies: o Redundancy o Cross Monitoring o Fault Detection Redundancy leads to dual channel safety. The duplication of control circuits and/or components such that if one component or circuit fails, the other (redundant) unit will still be able to assure machine shut-down Risk Assessment For those who do not want to go deep into Risk Assessments (will go a little deeper at the end of this discussion) If an injury will heal to its original state then the risk is probably Safety Category 1 If an injury results in permanent damage then the risk is probably Safety Category 3 **** Please note: The above 2 bullet points are not a substitute for a formal risk assessment. **** For Safety Category 3 and above, you will need Control Reliability Redundancy Dual Channel

For those wanting to keep reading. A little deeper discussion on Risk Assessments Now that you have completed your formal risk assessment, this table should look familiar to you. S: Severity of potential injury S1: slight injury (bruise) S2: severe injury (amputation or death) F: Frequency of exposure F1: infrequent F2: frequent to continuous P: Possibility of avoiding the hazard P1: Probable P2: Unlikely

Category 1 All conditions of category B apply, but the safety related system must use well-tried principles and components: o Avoid certain faults o Reduce probability of faults o Detect faults early o Assure the mode of a fault o Limit the consequences of a fault Category 2 o All conditions of Category B apply. In addition, the machine shall be prevented from starting if a fault is detected upon application of machine power. o Single channel monitoring is permitted provided input devices are periodically checked. This check may be manual. Category 3 o All conditions of Category B apply. In addition, the safety control system must be designed such that a single fault will not lead to the loss of the safety function, and, where practical, the single fault will be detected. An accumulation of undetected faults may lead to a loss of the safety function. In addition, successive machine cycles shall be prevented until the fault is corrected. o This requires redundancy and self-checking in the interface relay and dual channel monitoring of the input devices. Category 4 o All conditions of category B apply. In addition, every single fault must be detected at or before the next demand on the safety system. If this is not possible, then the accumulation of undetected faults must not lead to the loss of the safety function. o The number of allowable multiple faults will be determined by the application, technology, and system structure.

A bit on Safety Circuits: A simple safety circuit: Safety Category B if components selected properly Possible failure modes: Switch contact weld Contact spring failure Short in wiring Break in wiring Actuator failure/key break Switch manipulation Motor contactor/control relay weld Improved Safety control system: Safety Category 1 Improve reliability by adding another positive break contact to the switches-----redundancy Lacks fault detection Still not control reliable

Control Reliable Fault recognition Cross monitoring Self-Checking Black Box (Safety Controllers really should be discussed in a separate discussion) Safety system fault detection and control modules which detect (and locate) open machine guards and safety system component faults. Typically feature redundant, self- checking circuit design and positive-guided control relays. **Drawings and Diagrams are complimentary of Schmersal Safety Solutions http://www.schmersal.com/en/home/