Kenexis Functional Safety Podcast
Most engineers confuse assessment with verification, and auditing with checking calculations. Ed Marszal disentangles the four terms and explains why an FSA is fundamentally about whether the team did what it promised to do, not whether the work was technically right. The episode walks Clause 5.2.6.1.1 through 5.2.6.1.5: the procedure and team requirements, the planning considerations including scope and independence, the five lifecycle stages where FSAs occur, and the pre-hazard confirmations that must be completed before startup. Along the way, Ed draws on his own refinery experience with the Pennsylvania Board of Boiler Pressure Vessels, explains why 61511’s independence bar is lower than 61508’s, and argues that stage four belongs at the first turnaround. For anyone who has ever wondered why their “audit” found nothing wrong yet the plant still trips, this episode reframes what assessment should actually accomplish.
Many people misunderstand the fundamental concepts of assessment and auditing. It’s not about verifying whether the work was done correctly; it’s about ensuring that the work was carried out according to the plan or the way you said it would be done.
Please join Ed Marszal, President and CEO of Kenexis, for the latest episode of the inaugural season of our new Kenexis Functional Safety Podcast on Spotify and Apple Podcasts where he discusses the IEC 61511 standard. Clauses 5.2.6.1.1 to 5.2.6.1 are covered in this episode.
As a Principal Engineer (PE) himself with decades of experience in safety instrumented systems, Ed brings a unique perspective to this podcast, having actively contributed to the ISA 84 committee since 1994.
In this inaugural season, Ed will delve into the IEC 61511 standard, examining each word’s significance. He provides detailed insights into the standard’s interpretation and application, complemented by personal stories from his career and committee discussions.
Full Episode Transcript
KENEXIS FUNCTIONAL SAFETY PODCAST — S1E13 TRANSCRIPT (Markdown)
Cleaned & reflowed for web publication and AI crawlability.
The JSON-LD block below is schema.org structured data. If your CMS lets you
add raw HTML to a post, paste it into the page
body — crawlers read it either way). Fill in PLACEHOLDER_EPISODE_PAGE_URL
once the post exists. Everything from the "# Kenexis Functional Safety
Podcast…" heading down is the transcript body — paste it into your post.
–>
"`html
"`
# Kenexis Functional Safety Podcast — Season 1, Episode 13: IEC 61511, Clause 5.2.6.1 (Functional Safety Assessment)
—
## Introduction and Episode Overview
A lot of people get the basic concepts of assessment and auditing wrong. It's not a verification. You're not checking to make sure that the work that was performed was done right. You're actually checking to make sure that it was done the way that you said you were going to do it.
Welcome to the Kenexis Functional Safety Podcast. I'm your host, Ed Marszal, President and CEO of Kenexis. Kenexis is a technical safety consultancy that helps chemical process industry companies to analyze risk and design engineered safeguards like safety instrumented systems and fire and gas detection systems. Kenexis also provides the industry-leading suite of software tools, including our best-in-class Vertigo software for SIS safety lifecycle management.
In this first season of the podcast, we are going to focus on the IEC 61511 standard, doing a deep dive into the standard, including more depth of information on what the standard means and how to apply it, brought to life with personal war stories and behind-the-scenes discussions of the committee members as we develop the standard in ISA 84 and IEC SC 65.
Before we start, a little disclaimer. I will be providing my opinion on technical and engineering topics. This information is provided on a best-effort basis and is of a general nature. The information presented in this podcast might not be applicable to your specific application. It is the obligation of every engineer to thoroughly analyze any system that they are designing and not blindly rely on any general advice presented in this podcast.
## FSA Versus Verification, Validation, and Auditing
Starting off today in Clause 5.2.6, which is titled Assessment, Auditing, and Revisions. And it's a large section because it covers assessment, auditing, and revisions. The first topic of which is going to be the primary item that we're going to be discussing today, which is the FSA or the Functional Safety Assessment. So Clause 5.2.6.1 is titled Functional Safety Assessment. And it lists out all of the requirements for an FSA or for multiple FSAs that you need to do. And there are a lot of these requirements. So without further ado, let's dig in.
5.2.6.1.1 states, A procedure shall be defined and executed for a FSA in such a way that a judgment can be made as to the functional safety and safety integrity achieved by every SIF of the SIS. The procedure shall require that an FSA team be appointed, which includes the technical, application, and operations expertise needed for the particular application. All right. So this first clause basically is an extension of planning. You need to make a plan to do a functional safety assessment. So we're going to have a procedure by which we're going to do it.
And that procedure, once we execute the procedure, the outcome of that is that we're going to be able to make a judgment as to whether or not the functional safety has been achieved by every safety instrument and function in the SIS. Or technically, it would be all of the functions in the scope of a project.
So before we even dig even further than we have already, and we've already listed out one requirement, let me go into a little bit more detail on what a functional safety assessment is. Because there's a lot of conflicting terms. A lot of people do things different ways. And if you look at the standard as a whole, what's contained in the standard, it's really easy to confuse verification, validation, auditing, and functional safety assessment.
They're all different mechanisms by which you're going to look at the SIS or the activities surrounding the implementation of the SIS and make a judgment as to whether or not things were done right.
So with a functional safety assessment, I'm going to take assessment and auditing, which are the topics contained in 5.2.6, and separate them out from verification and validation.
So for verification and validation, what you're doing is you're checking work that was done to make sure that it was done correctly. Verification, which we're going to have a whole section on coming up in the not-too-distant future. Verification is kind of that step-by-step back check of the work products that were performed to make sure that they were done correctly. So this is kind of a step-by-step back check by an independent person, a separate person, of the quality of the paperwork that was generated. Whereas validation is more of that final physical test of the completed system.
So there, you're basically trying to judge the quality, the correctness of what was done.
Auditing and assessment are really different, and you don't want to confuse them and get a lot of overlap between them. Now, while doing a bit of assessment of the correctness of the work that was done is going to be part of functional safety assessment and auditing, that's not really the core or the primary purpose. The core and primary purpose is to make sure that your functional safety planning is being followed.
So in this assessment phase, in the auditing phase, you're checking to make sure that you have a program for what needs to be done, and that program for what needs to be done is being faithfully executed in the implementation of projects.
So it's not so much checking the quality of what was done, but realistically, it's more making sure that you're doing what you're supposed to do, that all the steps are being followed, all the steps are being followed in such a way that it matches up with your functional safety planning.
So again, one of the examples that I bring up time and time again is if your functional safety planning says that you're going to use a risk graph to pick a SIL target, subsequently, during your assessment and auditing phase, you determine that someone used layer of protection analysis instead of a risk graph. You might say to yourself, well, LOPA, layer of protection analysis, it's better, it's higher quality than a risk graph. Well, that doesn't really matter. You didn't do what you said you were going to do. You said you were going to use a risk graph.
So if you're not using a risk graph, that's a violation of your procedure. It's a violation of your planning. And that is the type of thing that we're trying to flesh out when we're in the assessment phase, when we're in the auditing phase.
Now, what is the difference between assessment and auditing? Well, let me dig into that a little bit. The functional safety assessment, basically, the best way to look at this is that the difference between assessment and auditing is really the scope of the activities that you're looking at. Because auditing is one of those things that's going to happen at a grand scale for the entire facility, all activities in the entire facility. And it really can't be separated from that full process safety management audit that you're going to be doing to look at all of your safety activities as a whole.
So the auditing of the safety instrumented system is going to be essentially just a part of that.
Whereas functional safety assessment is really something that occurs on a project-by-project basis. So I have a project for the implementation of SIS. I'm going to perform activities. And obviously, you're going to be doing verification step-by-step. But you're also going to have independent parties do a functional safety assessment, not to check the work products. That's the job of verification. But really to make sure that you're doing what you're supposed to be doing. That's what the audit does. That's what the assessment does.
## FSA as a Project-Scoped Audit
So kind of summing up, the best way to think of a functional safety assessment is that it is an audit that occurs on the scope of a project. Or it doesn't even have to be the entire project. It can be a certain subset of activities that happen on a project. So FSA, think project, whereas auditing, think the overall scope of the entire facility and all activities that are occurring in that facility. Okay.
So we just kind of covered 5.2.6.1.1 that says this functional safety assessment needs to happen in accordance with a procedure. And that procedure should probably also be giving you a checklist for what you're looking for when you're doing a functional safety assessment.
## Kenexis Open Audit Tool for FSA
So if you are interested, I highly recommend doing audits and functional safety assessments using the Kenexis Open Audit tool.
So Open Audit is a tool that kind of in look and feel looks similar to Open PHA, but it is specifically designed for performing functional safety assessments and audits where you list out what are the clauses or what are the requirements that you're trying to achieve during your audit process, some notes for the inspector for what they should be looking for, results, and then also tracking of what evidence that you have that those requirements were actually being implemented.
Furthermore, if you're using Kenexis Open Audit tool, there is an IEC 61511 functional safety assessment, functional safety audit tool that you can use. It's free download as part of the software. That'll give you kind of at least a starting point for a list of requirements that you're checking to make sure that have been implemented. And you're probably going to want to kind of focus those for the methods and tools that your specific organization uses. But that's a great methodology and tool for being able to perform these functional safety assessments.
It'll save you a lot of work. Okay, so that's a great way to look at planning, procedure development for FSA.
## FSA Team Composition and Independence Requirements
Second clause, 5.2.6.1.2 says, the membership of the FSA team shall include at least one senior competent person not involved in the project design for stages 1, 2, and 3, or not involved in the operation and maintenance of the SIS for stages 4 and 5.
So in this clause, we list out three stages in the design phase and two stages in the operation and maintenance phase at which you were going to want to consider doing a functional safety assessment. So there's going to be more discussion of the different stages a little bit later as we dig into more details of the FSA. But the bottom line of this clause is it's setting up a criteria for who is qualified to perform an FSA.
Now, it says that the FSA is going to be performed by a team. Okay, I mean, that should be pretty obvious. The membership of the FSA team implies there's a team. But then it goes on to say that it's going to include at least one person. So one person team, it's not out of the realm of possibility. A lot of FSAs are done by one senior competent person. So we have a team. We need to define who the team is. It needs to have at least one person that is senior.
So that means that, well, at a minimum, this is not going to be their first project. Now, there's no hard and fast criteria to determine what a senior person is versus a junior person. But at an absolute minimum, if they've never done an SIS project before, they're probably not going to be considered a senior person. So someone that has at least one SIS project under their belt is going to be an absolute bare minimum.
Your organization, when you're defining these things, you might put a years of experience in doing safety instrument and system design as one of those criterias that you're looking at when you're determining the seniority that's required.
And then competence. Competence, we already talked about. You need to define what competent means. The standard doesn't tell you what it means to be competent. It gives you some criteria to look at, but it doesn't give you training classes that need to be taken or an exam that needs to be taken. Now, you need to make those determinations in your functional safety planning, and that's something that we've already discussed. But senior person that is competent are the criteria for functional safety assessment.
The other key criteria is that they're not involved in the project. You want a cold eye review. You want someone who is not working on the project to check their own work. Now, it says that the senior competent person is not involved in the project or not involved in the operation and maintenance of the SIS.
It doesn't have the same rigor or detail of independence that you might see in, for instance, the IEC 61508 standard. So you're not seeing any requirements here that you need to go to an outside independent third party. It doesn't even say that you need to go to a different group in your organization. It just says that they need to not be involved in the project, which is a much lower bar than you would see in, for instance, the 61508 standard, which is a little bit stricter about those requirements. Okay. Okay.
## Planning the FSA: Clause 5.2.6.1.3 Requirements
Now, in terms of planning the FSA, we're going to go into clause 5.2.6.1.3, which states the following shall be considered when planning the FSA. And after that, you're going to get a bunch of bullet points for those items that the standard wants you to consider. So I'm going to go over the bullet points one at a time and give a little bit of a discussion with respect to each of those. All right.
So number one is the scope of the FSA. So when you're doing your planning, you need to think about which SIS lifecycle activities are you going to include and how are you going to group them together when you're doing your planning.
So for a small project, you might do the hazard and risk assessment, SIL verification, calculations, SRS development, detailed design. You might, like, lump all of that together before you go into the FSA process. Whereas for a big SIS project, you might want to do a functional safety assessment, for instance, right when you get done with your LOPA, which is kind of early in the game.
But if you make mistakes in a giant project and you don't know of those mistakes until you get really far along in the design process, it's going to be a whole lot harder to clean up the mess or resolve any of the discrepancies that you found.
So think about the scope of activities that you want to include into an FSA. Ultimately, the design lifecycle, you don't really need to, you're not forced to do an FSA until right before you start the plan up, right before you introduce the hazard. And that might be completely appropriate for a big plant, but for a small plant, you might want to break them, or for a small, for a small plant, small project. But for big projects, it makes more sense to break it into smaller pieces.
Okay, bullet item number two. Who is to participate in the functional safety assessment? So as we saw, all we really have to have is one senior competent person not involved. But you might want to have a team of people with specialists to focus on different areas. So a specialist in hazard and risk assessment, a specialist in safety requirement specifications, a specialist in detailed design of SIS. So who's going to participate?
The third bullet item, the skills, responsibilities, and authorities of the FSA team. So we're not only listing out who we need to participate, and you would generally do that more on a role basis as opposed to a named person basis. But you're also going to want to call out who has which skills to make sure that we have comprehensive coverage of everything that's going to be occurring in those lifecycle activities that are being assessed.
Four, the information that will be generated as a result of any FSA study. So you're going to do some planning on what you want your FSA to look like, what kind of report you're going to generate. So, yeah, using something like the open audit tool, which has a list of requirements that's the basis for the MSA, and generating reports out of that is an example of what you could do for that type of planning.
Item five, the identity of any other safety bodies involved in the FSA. So now you might — generally, FSAs are going to occur at the operating company level with operating company personnel. But in some cases, you might want to bring in an authority having jurisdiction who needs to approve your safety instrumented system devices before they actually go into service.
So as an example of this, at one point in time, I was doing — personally doing some work for an oil refiner, and we were preparing a safety instrumented system that was going to work in lieu of conventional relief. And we were doing this work in the state of Pennsylvania, which when you're going to replace a conventional relief with a safety instrumented system, you need to get specific approval of the Board of Boiler Pressure Vessels and Inspectors. So we had them along for these types of activities.
So any other safety bodies, whether it's OSHA or the Fire Marshal or the Board of Boiler Pressure Vessel Inspectors, if they need to be involved in the approval process, you're going to want to document that they need to be included in the FSA process. Okay.
Next item up is the resources required to complete the FSA activity. So what tools are you going to use? What measurement devices are you going to use? What forms, paperwork, requirements list? So how are you going to perform the activities and what are you going to use to execute the FSA?
The next bullet item states that you need to plan for the level of independence of the FSA team. So the standard says that you need to plan for what level of independence is required, but it does not set any requirements on what that degree of independence actually is. That is up to you.
The next bullet item says that you need to plan for the methods by which the FSA will be revalidated after modifications. So up to this stage in my career, I have yet to go through any kind of assessment or audit or validation or verification and not find anything. There are always findings. And when a finding occurs, you need to make sure that the content of the finding has been resolved before you move on to the next stage in safety lifecycle activities or definitely before you introduce hazards to the process under control.
So some sort of planning process for how you're going to approve, resolve, and verify the implementation of all of the requirements and recommendations that come out of the FSA. That needs to be part of the planning process.
Okay. So those are the bullet points that talk about the planning of an FSA. They all happen under 52613. And this clause also has a note. And that note says, When the FSA team is large, consideration can be given to having more than one senior competent individual on the team who is independent from the project team. Okay. So if the team is large, you might want to have more than one competent person. Okay. Okay. Seems like something that doesn't need to be said. I definitely can't argue with that. But there you go. Okay.
## FSA Scope, Ordering, and Incremental Review
Next clause up is going to be 5.2.6.1.4. And it states, Okay. FSA team shall review the work carried out on all phases of the safety life cycle prior to the stage covered by the assessment that have not already been covered by previous FSAs. Okay. That's the first sentence. There's going to be a couple more sentences to this requirement.
So basically what this is saying is when you're doing functional safety assessment, number one, it needs to be done in order. So you can't do a functional safety assessment of the SIL verification calculations if you haven't done a functional safety assessment of the hazard and risk analysis. Okay. Okay. Okay. Don't do things out of order.
And then it also kind of says, well, whatever stage you decide to do your functional safety assessment at, once you make that decision, once you start the FSA, you need to FSA or assess everything that has occurred from the last FSA to the point where you're at right now. And if you haven't done an FSA for the project, that means you need to assess everything that is done up to the current point or whatever the limit for the point is that you're going to extend your functional safety assessment activities out to.
So if you're in the SRS, you've completed an SRS, and you decide that now is the time to do a functional safety assessment, you're also going to make sure that the hazard and risk assessment has been assessed. So everything up through the SRS, all of those activities need to be part of the FSA.
Okay. Continuing on with the requirements in the clause. If previous FSAs have been carried out, then the FSA team shall consider the conclusions and recommendations of the previous assessments.
All right. So let's say I did a functional safety assessment through the hazard and risk assessment, and I, you know, came back and made recommendations because the hazard and risk assessment was not done correctly. When I do the next functional safety assessment, let's say that it occurred after SIL verification calculations and SRS were performed.
As part of that, you need to go back and look at that first assessment was done and make sure that any recommendations that were generated in the first FSA have been completed. So we're always trying to make sure through our assessment process that things are getting followed up on.
So those are the requirements.
But after the requirements, there are three notes, each of which has multiple bullet points. So we've got like another half page of text related to this clause, but it's all notes. Okay. Notes are important. So let's dig in to the notes.
Starting with note one. Additional FSA activities can be introduced as new hazards are identified after modification and at periodic intervals during operation.
So additional activities, what do they mean by additional FSA activities? When you perform a project, no matter how small the project, functional safety assessment is required. So anytime you perform a change order or a project as a result of a change order or a management of change item related to the facility, functional safety assessment activities need to be implemented. So if you are going to add a new safety instrumented function to an existing safety instrumented system, you're going to need to do FSA activities related to the project work that you do.
So no matter the size of the project, FSA is always going to be required. It's just a matter of what is the extent or the degree to which those functional safety activities need to occur.
## FSA Stages One Through Five
Note number two. Consideration can be given to carrying out FSA activities at the following stages.
Okay. That is the note, and the note has five bullet points. And each one of them is a stage. So let's list off the stages. Stage one is after the H&RA hazard and risk assessment has been carried out. The required protection layers have been identified and the SRS has been developed. Stage two is after the SIS has been designed. Stage three is after the installation, pre-commissioning, and final validation of the SIS has been completed and operation and maintenance procedures have been developed. Stage four, after gaining experience in operation and maintenance.
And stage five, after modification and prior to decommissioning of an SIS. So you'll note that we talked about these stages back in 52612 before we even defined what they were.
So when you look at this, you kind of think, okay, stage one is hazard and risk assessment. Stage two is design. Stage three is right before you, as we would say back in my UOP days, put oil in, before you introduce hazards into the process. A lot of times, functional safety assessments don't occur until after stage three for kind of small to medium to not huge projects. That's not very uncommon. Now, stage four and five are after you've introduced hazards to the plant. So the SIS is actually in operation.
Stage five, you know, yeah, we're going to need to do an FSA before we completely decommission an SIS.
But stage four is after we've gotten some experience in operating and maintaining the plant. Basically, that's something that I would recommend stage four at the first turnaround, the first time you do functional safety testing, periodic testing, after the plant has been put into service, just to make sure that the policies and procedures that you have for maintenance and testing are actually being implemented properly.
Stage four and stage five, specifically stage four, those are the ones that are going to be the easiest to confuse with the overall SIS auditing, which, again, I mentioned previously is kind of a different animal from this. Okay, so those are the stages.
Stage one, two, and three, often done together right before startup of the plant. Stage five, something you're going to want to hit that first turnaround, the first time you do periodic function testing after the plant's been put into operation. And stage five, before you decommission it.
Okay, we're not done with the notes. The notes continue. We're going to have a note three that has bullet points, and some of those bullet points have their own bullet points. So let's dig in.
## Note 3: Factors Affecting FSA Scope and Frequency
Note three states, the number, size, and scope of FSA activities can depend on the specific circumstances. The factors in the decision are likely to include, and then this is where we get our bullet point list.
So how many functional safety assessments you're going to do and when they get executed is going to depend on the plant, the specific circumstances. So what is the scope of the project? How big is the project? How big is the plant? So let's go over these.
First bullet point is the size of the project. Okay, that's pretty obvious. The bigger the project, the more you want to break it up into smaller steps. Two, the degree of complexity. Again, the more complex the project, kind of like the size, related to the size, the more complex, the more we're going to want to do functional safety assessments to make sure that we don't carry an error a long way into the design process and then kind of slow down the ability to implement things or fix things once problems are found.
The SIL. You may want to consider doing more functional safety assessments as you get higher SIL targets.
Item four, the duration of the project. So project planning is kind of part and parcel of functional safety assessment planning. There may be good break points due to the schedule of the project to schedule an FSA because one set of activities has been completed and you might want to assess it before you move on to the next set of activities.
The next item to consider is the consequence in event of a failure. So as the consequences of failure of the SIS get higher, you may want to go into more detail in your FSA activities.
The next bullet item says the degree of standardization of design features. So if you have a lot of the same thing in your SIS design, that can often streamline all of the activities in the design of the plant, including functional safety assessment.
Next bullet item for consideration is safety regulatory requirements. So obviously when you're doing your planning for functional safety assessment, you're going to want to think about what other regulations, what other authorities having jurisdiction are going to come into play into your SIS design and implement their requirements into your workflow.
The next bullet item is previous experience with a similar design. Again, the more experience you have, the more similarity you have, you're going to have a more streamlined workflow that's going to require less time and less resources.
The final bullet item, I'd like to call it the final bullet item, but it has three sub-bullet items. So the final bullet item is that in your planning, you need to give consideration to relevant factors such as A, time in operation, B, the number and scope of changes in operation, and C, proof test frequencies.
So that concludes all of the notes for clause 5.2.6.1.4. Which was all about kind of the scope and activities of the things that need to be carried out and when you need to do the activities, how many of these FSAs are you going to perform after which steps.
## Pre-Hazard FSA Confirmations: Clause 5.2.6.1.5
Okay, the next clause in the FSA section is 5.2.6.1.5. And it states, prior to the hazards being present, the FSA team shall undertake functional safety assessments and shall confirm.
Okay, so 5.2.6.1.5 actually gives you a list of bullet points, and there are quite a few of them, of the things that you need to confirm. So these are kind of like a to-do list of things that need to occur during the hazard and risk assessment.
So let me list off all these requirements, and I'm going to, you know, as I hit the bullet points, as usual, I'm going to kind of give some discussion of what those bullet points mean. So things you need to confirm.
First bullet point, you need to confirm that the hazard and risk assessment has been carried out, and then it refers to Clause 8.1, which is where the requirements for hazard and risk assessment are contained.
I would argue that it's much, much more than just making sure that the hazard and risk assessment has been carried out. You need to make sure that it has been carried out by the correct people at the right time, using the right procedures, using the right tools. So if you are required to use an approved third-party independent facilitator, using the three-dimensional hazard matrix tool, well, you need to make sure that all that is true.
So go back to your functional safety planning for hazard and risk assessment, and not only make sure the hazard and risk assessment was done, but it was done in accordance with the safety planning and all of the policies and procedures that you have developed for that phase.
Next bullet item, you need to confirm the recommendations arising from the hazard and risk assessment that apply to the SIS have been implemented or resolved. Wow. That's something that's super critical. But a lot of times just doesn't happen.
So when you're doing your SIL selection, you're in your LOPA study, you might have said, okay, well, I'm going to put in a SIL-1 safety function, but I'm going to make a recommendation to also put in a high-priority alarm so that I could take a operator intervention based on alarm credit. And implementation of that alarm might have been a recommendation in your hazard and risk assessment. Well, guess what? If that recommendation hasn't been implemented, you haven't achieved your tolerable risk.
So making sure that all of those recommendations, especially the ones that are going to impact your SIL targets and your ability to achieve tolerable risk with your safety instrumented system, you need to make sure that those recommendations have actually been implemented.
Okay, third bullet point. You need to confirm that project design change procedures are in place and have been properly implemented. So you need to make sure that you're following policies, following procedures for management of change, even during the project phase, to make sure that when design changes occur, that everything that gets executed in the SIS safety lifecycle is still going to be performed properly.
Bullet item four. You need to confirm that recommendations arising from any FSA have been resolved. So this goes back to what we talked about a few minutes ago, where if you did an FSA after hazard and risk assessment, and now you're doing another FSA after stage three, well, you need to make sure that all of the recommendations from all the previous FSAs have been followed up on.
Next bullet point. You need to confirm that the SIS is designed, constructed, and installed in accordance with the SRS, any differences having been identified and resolved. So, wow, you know what? That sounds kind of like commissioning. That sounds kind of like validation. Hmm. What's the difference here?
Well, basically, you're checking to make sure that your validation was done in accordance with your functional safety planning. You're checking to make sure that your FAT and your SAT were done, and they were done in accordance with your functional safety planning. So, you know, a lot of those activities, they're part of the safety planning, and during the FSA, you're making sure that those plans were executed, those plans were followed, and any recommendations were followed upon.
The next bullet point. You need to confirm that safety, operating, and maintenance, and emergency procedures pertaining to the SIS are in place. So, making sure that work gets done.
That bullet point is kind of a key for stage three, before you put the oil in, before you introduce the hazards into the process. You need to make sure that any procedures that you're going to need to use while you're operating the facility are there. They've been reviewed. They've been approved. People have been trained on them.
Next bullet item. You need to confirm the SIS validation planning is appropriate, and the validation activities have been completed.
So, make sure that you have a plan and procedure to execute that SAT site acceptance test, and you need to make sure that that validation, that SAT, as it's often called, has been done, and again, that's kind of a stage three activity, that you need to make sure all that occurs before you introduce hazards to your process plant.
Next bullet item. Confirm the employee training has been completed, and appropriate information about the SIS has been provided to the maintenance and operating personnel.
So, we already talked about the fact that the procedures needed to be created. This next bullet point, or actually, it's two away from there, this bullet point that we're currently talking about, makes sure that not only are the procedures there, but the people that are expected to implement the procedures have been trained on how to do so.
And finally, last bullet point, confirm that plans or strategies for implementing further FSAs are in place. So, that's an interesting bullet point. So, we need to check to make sure that we're going to check and make sure.
Think about this through the lens of stage three, where most functional safety activities are kind of focused. At stage three, you don't have any experience running the plant. You haven't done any testing of the SIS. You haven't followed up on testing of the SIS.
So, when you're doing that stage three assessment, you're going to want to make sure that planning is in place to make sure that after you do have experience operating that plant, after that first turnaround, when you've done your first batch of periodic functional testing of your SIS equipment, make sure that there is an FSA that's scheduled, that's in the planning process, that's going to make sure that all of that has been done correctly.
Okay, so those bullet items are 52615. And we've got more. There are at least five more bullet items related to functional safety assessment. But we're going to put a pin in that and come back to those requirements next time.
## Vertigo Software and SIS Lifecycle Management
Now that you've heard some insights on technical safety, functional safety, and the IEC 61511 standard, let me tell you a little bit more about how to easily and effectively implement the safety lifecycle using the Kenexis Integrated Safety Suite and our SIS safety lifecycle management tool,
Vertigo.
Vertigo is a comprehensive tool set for performing assessment calculations, documenting, and maintaining the design of safety instrumented systems. Analysis begins with importing or synchronizing a list of safety instrumented functions with their definitions and associated performance targets from our open PHA tool for HAZOP and LOPA documentation.
Each safety function can then be analyzed by performing a SIL verification calculation, complete with a collection of tools for optimizing designs and a database of thousands of potential instruments to define failure rates and diagnostic coverage capabilities.
After the SIL verification calculations are defined, you can build an SRS by automatically generating a cause and effect diagram from the SIF definitions and other defined instruments.
Each SIS instrument will include a customizable data sheet and general requirements that are applicable to the SIS as a whole and can be entered individually or even bulk imported from customizable libraries.
After the design phase, you can even use Vertigo to track and document testing throughout the entire life of the facility. Kenexis Vertigo is the most integrated, easy-to-use enterprise tool for allowing the development of SIS design basis information more efficiently and effectively than any other software application.
> *
*