In this episode of the Functional Safety Podcast:

The phrase “fail safe” sounds definitive, but as Ed Marszal explains, it obscures a far messier reality. This episode tackles Clause 11.2.11, where IEC 61511 confronts what happens when process safety demands the opposite of conventional wisdom: designing systems that do not go to a safe state when power or pressure disappears. Ed walks through energized-to-trip versus de-energized-to-trip architectures, the mechanical and electrical methods for detecting loss of utility and circuit integrity, and why the 2016 standard surprisingly relaxed a 2003 requirement for supplementary power supplies. A detailed hydrocracker depressuring example illustrates when spurious trip avoidance outweighs fail-safe convention. For engineers weighing the trade-offs between availability and safety integrity, this is the deep technical dive that connects standard text to field design decisions.

Energize to trip or de-energize to trip, that is the question… and the answer is… you can do whatever you want… Join Ed as he tackles this topic and discusses each option in more detail.

Tune in to the latest episode of the Kenexis Functional Safety Podcast, hosted by Ed Marszal, President and CEO of Kenexis. Now available on Spotify and Apple Podcasts, Ed offers his expert insights on the IEC 61511 standard.

With decades of experience in safety instrumented systems and as a Principal Engineer, Ed has a unique perspective to offer. He has been an active contributor to the ISA 84 committee since 1994, adding to his deep understanding of the field.

In this inaugural season, Ed delves into the IEC 61511 standard, unpacking the meaning behind each word and providing a thorough interpretation of its application. Through personal stories from his career and committee work, he offers valuable context and insights for professionals in the industry.

Full Episode Transcript

Episode Teaser and Introduction

Energize to trip or de-energize to trip? That is the question. And the answer is you can do whatever you want.

Welcome to the Kenexis Functional Safety Podcast. I’m your host, Ed Marszal, President and CEO of Kenexis. Kenexis is a technical safety consultancy that helps chemical process industry companies to analyze risk and design engineered safeguards like safety instrumented systems and fire and gas detection systems. Kenexis also provides the industry-leading suite of software tools, including our best-in-class Vertigo software for SIS Safety Lifecycle Management.

In this first season of the podcast, we are going to focus on the IEC 61511 standard, doing a deep dive into the standard, including more depth of information on what the standard means and how to apply it, brought to life with personal war stories and behind-the-scenes discussions of the committee members as we develop the standard in ISA 84 and IEC SC 65. Before we start a little disclaimer, I will be providing my opinion on technical and engineering topics. This information is provided on a best effort basis and is of a general nature.

The information presented in this podcast might not be applicable to your specific application. It is the obligation of every engineer to thoroughly analyze any system that they are designing and not blindly rely on any general advice presented in this podcast.

All right, so the topic for today, we’ve gotten ourselves all the way up to clause 11.2.11, which talks about the seemingly simple yet extraordinarily complex concept of energized to trip or de-energized to trip. And the infamous phrase fail safe, which sounds spectacular, but is not actually real. It’s more about what you do on loss of power as opposed to what happens when the system actually fails.

Clause 11.2.11 Overview and Fail Safe Concept

So let’s do a deep dive into this and get everything laid out on the table so that we can understand. So let’s start with the clause. Clause 11.2.11 is one sentence. It also has two notes. and it’s different than it was back in the 2003 version of the standard, the original version of the standard, and I will get into all the nitty-gritty and all these details. So let’s begin.

11.2.11 states, for any SIS device that on loss of utility. Okay, let’s pause right there. it doesn’t say anything about failure it says loss of utility and that’s what we’re really talking about the failure in fail safe is that we lost power or we lost utility and we’re going to get a parenthetical after for any sis device that on loss of utility with a bunch of examples of what do we mean by a utility? So, e.g., electrical power, air, hydraulics, or pneumatic supply. So, the International Electrotechnical Commission is kind of, shall we say, slightly going outside of their purview.

And they’re talking about instrument air, also known as pneumatics. and they’re also talking about hydraulics. So the pressure of air, the pressure of oil, the voltage in electricity is a driving force that is going to move things and make things happen. Those things are our utilities. So what we’re really saying is not that it’s going to fail safe, but if we lose our utility, If we lose our electrical supply, our hydraulics, oil, our instrument air, what is the device going to do?

So starting over, for any SIS device that on loss of utility does not fail to the safe state. So if you choose to design a system such that when the utility is removed, the process doesn’t go to a safe state, there’s going to be some additional requirements.

Now, the most common standard design, far and away the most common approach to designing safety instrumented systems today is to look at the system and design it so that when you lose power, you go to a safe state. But there are some situations where you’re not going to want to do that, specifically where the spurious trip is so undesirable, whether from a safety perspective or a mechanical perspective, that we can’t risk spurious trips.

And I’ll give you some examples of where that might come into play in a little bit. But so we’re talking about a system where we’re going to design it so that it doesn’t go to the safe state upon loss of supply.

Energize to Trip vs De-Energize to Trip

Why or what does that actually mean? Basically, it is energized to trip. So if a system does go to the safe state on loss of utility, that is called de-energized trip. And when we say de-energized trip, we mean that in the most broad sense. I’m removing my source of energy, my motive force. And again, that motive force, it could be electricity, it could be instrument air, pneumatics, it could be hydraulics. whatever that mode of force is, normally when that is removed, we’re going to use some sort of stored energy like a spring to move us to the safe state.

But we might choose instead to energize to trip, ETT.

So the common acronyms you’re going to see out in industry are DTT for de-energize to trip and ETT for energize to trip. Okay, so we’re talking now 11.211 about energized to trip systems where we are going to apply the power, apply the motive force to move the process to its normal state. And what that means is that if I don’t have the utility available, that’s a dangerous failure that is going to prevent me from being able to get to a safe state.

So now things got complicated on the calculation side of the fence because you need to include your utilities now as the part of the mechanism that I’m going to use to get to the safe state.

So failure of the utility, not having the utility means that the safety instrumented function is unavailable. unavailable. So that’s when we get to clause nine, and we will spend a long time on clause nine, because that’s the calculation clause. But it’s something that needs to be considered into the design. Okay, so I’m still, you know, working my way up to the first comma in the sentence.

And I’ve gotten that this clause has to do with energized to trip systems. So if I have an energize the trip system, meaning that my SIS upon loss of utility does not fail to the safe state, then two things are going to need to be true. What are those two things? Well, let’s read along.

Detecting and Alarming Loss of Utility

Loss of utility and SIS circuit integrity shall be detected and alarmed. So the two things I need or the two things. I need to be able to detect an alarm, detect an alarm if I lost my utility or if my circuit integrity is compromised. So loss of utility, let’s start by working that, working through that on the electrical side of fence. Normally, you’re going to send signals to your shutdown system using 24 volt DC. So if I’m using an energized to trip circuit on my input, so just imagine I have wiring from the power supply to the safety PLC to a switch, and then the return circuit.

So if I don’t have 24 volts DC to send, then I need to be able to detect that that’s the case and alarm that that’s the case.

So how would you normally do that? Well, it’s easy there because you’re just going to measure the voltage at the power supply. And if you lose your voltage, you’re going to set up an alarm. Maybe you’ll wire that to a pan alarm. Maybe you’ll wire it to your DCS. There aren’t really a whole lot of restrictions on how that alarm needs to be designed. Okay. So, which is fine. We’ll kind of, table that design process. We just need to know that we need to detect it and set an alarm.

So if you measure the voltage at the power supply and if the voltage drops below whatever set point you set drops below 20 volts, 18 volts, what have you, then you’re going to want to send up an alarm saying that you have no power.

And in this case, the system is unavailable because the power for your circuit is not available. You’re never going to be able to get that circuit to say that it’s in the dangerous state because you don’t have the power to make it happen. So that’s the first part of it. And we need to consider the unavailability. and also this is a dangerous detected failure. So when I get to Clause 11.3, 11.3 is not far away.

We’re on 11 to 11 and there’s 212, 213, 214. Then we’re going to get to Clause 11.3, which is how the system is required to behave upon detection of a dangerous failure or detection of a fault technically. And this is exactly what we’re talking about. this is detection of a dangerous failure. I need power for my safety instrumented function to work.

I don’t have power. So my safety instrumented function is now unavailable. I need compensating measures because I know it’s unavailable. And I am going to need to repair the safety instrumented system within my maximum permitted repair time, MPRT. So that’s the first part of it is loss of the utility itself. So, and I just talked about electrical. So temporarily, let’s talk about how do you determine if you have loss of utility for the other big two, which is going to be instrument air, pneumatics, or hydraulics, which is going to be pressured up oil.

Well, your motive force, your utility is pressure, pressure of a fluid. And well, not to make too long of a story out of it, but you simply measure the pressure. If the pressure drops, then I have lost my utility. If the pressure doesn’t drop, I haven’t lost my utility. So we’re basically going to put in a pressure transmitter, and we’re going to set an alarm if the pressure drops. Pretty simple.

Circuit Integrity Monitoring for ETT Systems

All right, so that’s how I detect and alarm my loss of utility. You also need to detect and alarm loss of circuit integrity, and that’s going to be a little bit trickier. Okay, so for circuit integrity. This is making sure that when I send a signal across the wire, it’s going to get across the wire. What is going to prevent the signal from getting all the way through the circuit? Well, if the circuit is open. Now, if you’re using a de-energized trip system, if you drop a wire somewhere, that becomes a spurious trip.

I lost my signal, which causes my devices to go to their fail-safe state, which is going to cause the plant to shut down. So there, dropped wires are still a real problem in any type of system, but for de-energized to trip, a dropped wire is going to result in your plant shutting down. If you have an energized to trip circuit, well, it’s not. There’s no way for your safety system to know.

If you go into the rack room, you go into the cabinet, you get your screwdrivers out and you unscrew a wire in a energized to trip circuit, if it doesn’t have circuit integrity monitoring, there’s no way for you to know that that wire is not connected until you try to send power out on that circuit and it doesn’t go anywhere. And then your plant shuts down.

I’m sorry, your plant doesn’t shut down. Your plant blows up. Or, you know, maybe you were doing this. You found this during a test. You detected this failure.

So circuit integrity is a very big deal in energized trip circuits because it is a dangerous failure. and we want to make sure that it’s a dangerous detected failure instead of a dangerous undetected failure. And we’re going to do that through a process called circuit integrity monitoring.

Now, in this case, I’m going to do pneumatics and hydraulics first. Because with pneumatics and hydraulics, if you don’t have circuit integrity, you’re going to lose your stuff at the end of the day. So you’ve got a circuit that’s full of instrument air. You’ve got a circuit that’s full of pneumatic oil. And if that tubing fails, you’re going to get a leak and that’s going to dump all your hydraulic oil out on the ground.

It’s going to blow down the pressure on your instrument air header. And that’s pretty detectable because once again, pressure went down. So pressure alarm is going to tell me that I lost circuit integrity. Now, you have to be very careful in your design to maximize the portion of the loop that is pressurized so that you can detect that it fails. But there is a very good chance that there is going to be a portion of the loop that is not protected. Now, can we protect it? Possibly.

It’s very, very hard to do. basically what you would need to do is put a small amount of pressure on the unpressurized circuit. That’s right. I said pressure up the unpressurized circuit. So you put enough pressure on the unpressured portion of the circuit to know that there’s no leak, but not enough pressure to make the final element move. So that’s the general concept of circuit integrity, is you need to actually be applying power, whatever that motive force is. And if it goes away, then you’re going to know that you lost your circuit integrity.

Electrical Circuit Integrity and Trickle Current

All right, so on electrical power, the good news is that 95% of the time, if you’re using a good SIL 3, maybe even SIL 2, definitely SIL 3 rated safety PLC, your equipment vendor has your back on this. They’re going to take care of it. And they’ve built all this into your system where simply when you’re doing the initial configuration of your safety PLC in the design process, there will be a checkbox that says, do you want to do circuit integrity monitoring, especially if you’ve configured it to be energized to trip, and it will do all the work for you. Well, what does the work look like?

Well, basically, you’re going to be putting a small voltage. It’s often, the most common name is going to be a trickle current, which is correct. There is a trickle current, but you’re technically measuring the voltage, but I digress. So how do we put a current through the loop without actually activating the final element. Well, I just told you how you did it. You need to basically apply a small enough voltage so that it doesn’t trigger your final element. It doesn’t, you know, and that’s on the output circuit.

On the input circuit side, you’d be trickling enough current to where the A to D converter in your safety PLC doesn’t think that the channel is energized and say that we have a positive. So usually, and now I’m going to be talking about maybes and usuallys, broad numbers, because every equipment vendor is different. So this is going to require a lot of on-site engineering, trial and error.

Back in the day, we at UOP, when we were specking this stuff out, we would say field to set because until you have everything installed in the field and start playing around with it, you’re not sure what the numbers are going to be. But it goes like this.

And let’s just talk about an input circuit real quick. So for an input circuit, there’s a voltage, there’s a wire that’s going out to the field. And then there’s a circuit, of course, there’s a circuit, there’s going to be a switch. And that switch in an energized to trip plant is going to be open. So that usually is going to prevent the curtain from flowing. So what we’re going to need to do is we’re going to need to apply a series of resistors.

So there’s one resistor that’s going to limit the total amount of power that can go out to the field to kind of minimize, even when the switch is closed, how much current is going to flow through that circuit. There’s going to be another resistor that goes across the switch. So we are purposely creating the opportunity for a short circuit. So it is a short circuit, but it’s a short circuit that you’re creating with a resistor that is going to give you a fairly high resistance.

Because even though we’re applying 24 volts to the circuit, we’re going to want the current to be very small, and we’re going to want the voltage that we measure to be very small.

Now, the voltage that we’re going to measure is the current flowing through the loop.

So in order to determine whether or not there’s current, the best way to do this is to put in a resistor and measure the voltage across the resistor because that’s going to be a proxy for what the current in the loop is.

so uh there’s that final resistor kind of at the end of line we’re measuring the voltage across that final resistor and we’re looking for something small like one and a half one one and a half two three volts which is enough to know I got current flowing I got a circuit but it’s not enough to cause whatever the action is to take place, whether that’s an A to D conversion in an input card or a solenoid activating to move a valve to its safe state.

So, all right, so that’s circuit integrity monitoring as presented to you by a chemical engineer who knows enough about 24 volts DC to be dangerous. So I would also recommend to you anytime you’re doing this type of circuit integrity monitoring, if you need something homegrown, hand rolled, bolted on, not provided by the equipment vendor, get yourself a really good, really quiet electrical or electronics engineer to look over your circuit and make sure you haven’t done something incredibly dumb.

Clause Summary and Reference to Clause 11.3

Okay, so that’s circuit integrity monitoring. So with these circuit integrity monitors, which are either going to be a pressure, low pressure alarm, or a low voltage alarm at the end of the day, that’s your means of detection, and then you also need to generate that alarm, and that alarm is an indication that you have a dangerous undetected failure in your safety instrumented system that you need to resolve. Okay. Pretty straightforward. Pretty simple. Pretty easy. Well, no, it’s not easy. So, all right.

So, that kind of gets me to almost the end of the clause, which says, loss of utility and SIS circuit integrity shall be detected and alarmed. Now, there’s another parenthetical right there with some examples. For example, end of line monitoring, supply pressure measurement, hydraulic or pneumatic pressure monitoring. Huh, how do you like that? That’s basically everything that I just described in significantly less detail than I just described it to you.

And that end of line monitoring, that basically it’s talking about that resistor at the end of the line. and measuring the voltage across it to make sure that you have that trickle current going through your circuit. All right, now, are we done yet? No, no, no, no, because it says loss of utility and SIS circuit integrity shall be detected and alarmed and action taken according to 11.3. I’ve already done a little bit of foreshadowing here with clause 11.3, and clause 11.3 is what are the Requirements for system behavior on detection of a fault.

And we are going to spend an entire webcast, podcast session talking about just this clause because it is weird, complicated.

You need to do strange things. But ultimately, you can shut down. So if you detect that you’re in an unsafe condition, you can always shut your plant down. Now, we’re talking about de-energize the trip. So can you shut down? Hmm. If my motive force to move my final elements to a safe state is no longer there, maybe I can’t shut down because I don’t have the power to shut down.

I just detected that I can’t shut down. so oh that that could get tricky now if it’s on the input side maybe you can and it all depends you need to look at every situation specifically in terms of how you’re doing your design but uh i’ll just throw throw it out there that this is going to be a tougher one to be able to achieve in terms of trying to just shut down the plant.

Whoa, dropped my pen there. Okay, next. All right, so the other thing that you can do in terms of Clause 11.3.1 is you can continue to operate the plant in the presence of that failure. But if you have a known, diagnosed, dangerous failure of an SIS component, you are required to put in place compensating measures. So what are compensating measures?

Compensating measures are the actions that you’re taking, whether it’s through humans, through additional equipment, what have you, to basically replace the safety instrumented function with something else for the duration of time that it takes to repair that failed safety instrumented function or failed SIS component and get it back to its normal operating state. So as I mentioned, we’re going to be talking more about that in a couple weeks. But the key thing to remember here is that it’s not enough to just have an alarm. You’re going to need to do something about it.

And that’s kind of the end there. So if I can start at the beginning and take all the parentheticals out, 11 to 11, for any SIS device that on loss of utility does not fail to the safe state, loss of utility and SIS circuit integrity shall be detected and alarmed and action taken according to 11.3.

Standard Notes and 2016 vs 2003 Changes

Okay, you would think that after talking about this for almost a half hour, we would be done. You would be wrong. We still have two notes that we haven’t discussed. All right, so next items. Note one, utility integrity can be improved through using a supplementary supply. And we have a parenthetical with that note. For example, battery backup, uninterruptible power supplies, air reservoirs, hydraulic accumulators, second gas supplies.

So in that note, or in the examples that they gave to that note, they gave a pretty good, pretty comprehensive full range of things that you can use for backup. up. Now, let me tell you, I find this very interesting because as you know, I have a very long history of looking at the standards, being involved in the standards committees and how they evolve and change over time. What you should note is that unlike every other standard known to man in the history of humankind, the IEC 61511 standard in the 2016 version actually got easier to comply with instead of more difficult.

And this is one example of that. If you look at the 2003 version of the standard, instead of two requirements, there were three.

So what are those two requirements again in 11 to 11? I need to be able to detect an alarm, loss of utility, number one, and number two, detect an alarm, loss of circuit integrity. There was a third one back in 2003, and that third one used to be that you were required to have a backup power supply for your safety instrument and function. And starting in 2016, when this version, the newer version of the standard came out, that was pulled because, well, the standards committee knuckled under to, the crowd said they didn’t want it.

And, you know, sometimes the standards committee has to give the people what they want. So that is a change to the clause that made things easier to accomplish, one could argue, a little less safe.

Now, myself and the people over at Kenexis are always going to recommend that you put in a supplementary power supply whenever possible.

Supplementary Power Supply Design and Options

but sometimes it’s not possible. So let’s do a little bit of a deeper dive into this and explain how we’re going to do supplementary power supplies. So let’s start with the easiest aspect of engineering a supplementary power supply and that would be for your signals. So for your signals, and in some cases the driving force of your safety instrumented functions, is going to be applied most of the time with a nice low DC voltage of 24 volts. And there’s going to be a power supply that supplies that 24 volts out to the field.

So we know that power supplies can fail, so what do we do? Well, we put in another power supply and then you’re going to put in a Wheatstone bridge to make sure that you don’t backflow from here to there, yada, yada, yada. Kind of your electrical check valve system, if you will. Spoken like a true chemical engineer, no? So that’s easy to do, but how far back do we go?

do I need those power supplies to be coming from different AC circuits from my power distribution? It’s not a bad idea. I would recommend that. That’s not unrealistic. You’ve got, I mean, you’re in the marshalling room. You’ve got all kinds of power coming in. But, well, maybe I want my power coming from multiple different locations. So maybe I have a power plant on site. Maybe I have multiple utility companies that are giving me different feeds. So I want power company A to supply one part of my plant and power company B to supply another area.

And then there’s also your good old uninterruptible power supplies where you’re storing a lot of power in a battery system that is going to allow you to run that safety instrumented system for long periods of time. 24 hours is not an uncommon design target. Eight hours is another not uncommon design target where if you lose your primary source of power, you’re going to get backup for some period of time. So a lot of considerations there. And again, we’re talking about relatively low currents of relatively low voltages, not that big of a deal. But when does this become a big deal?

Well, let’s say that I need to open a valve using a motor operator. So a motor operated valve, and it’s a big valve, maybe 72 inches. So I need 240 volts three phase, or maybe I need 600 volts three phase to actually make that valve move as fast as I need it to. So whereas pulling 24 volts DC off of a UPS when I don’t have my normal power ain’t no big thing, running two different sets of three-phase power out to the field for a motor-operated valve. Well, guess what? That kind of is a big thing.

So that’s probably one of the biggest examples of, hey, you know, if I can just alarm and know that I lost my utility, I can put in compensating measures, get myself to a safe state, I am not going to run spare power. And hey, you know what? At the end of the day, that’s not completely unreasonable. Okay, so that’s electricity on the circuit side and on the final element side. Most of the power that actually moves final elements is not going to be electrical in the process industries.

It is going to be pneumatic or hydraulic, and honestly, most of it is going to be pneumatic because pneumatic is a lot cheaper, a lot cleaner, a lot easier to maintain, yada, yada, yada, yada. So how do we provide backup instrument air? Are we going to have multiple instrument air compressors? Well, of course you’re going to have multiple instrument air compressors. There’s nothing more important in your plant than your instrument air compressor. I know that sounds weird to say, something that is given so little attention.

But when you lose it, if you lose instrument air, you know in a hurry, and it is a big problem for a lot of people. So redundancy in your instrument air is great. Do I want to have a whole bunch of redundant instrument air circuits running around my plant to where I can switch from system A to system B? No, that’s not a common design. It’s not unheard of, not uncommon design. So basically, we’re going to have redundancy on our instrument air compression or in our hydraulic oil compression, but we’re generally going to have one set of instrument air piping to carry it wherever it’s going to go.

Now, if we lose our instrument air supply, other than the redundancy on the air compressors, there’s additional redundancy that you can take at the actual final element. And this is going to be something that you’re going to think about for critical final elements. And that would be an accumulator system. So accumulator systems are going to work for pneumatic systems. They’re going to work for hydraulic systems.

And the way that they operate is you’re going to have a volume bottle, which is basically a piston with a spring on it and you fill, you can’t see me doing the air quotes, but I’m doing air quotes. You’re going to fill your volume bottle by applying the instrument air or the hydraulic oil. It’s going to push against the piston and compress the spring. So now you’re going to have a bottle full of air with the spring.

And if for some reason you lost your instrument air supply, you’d be able to use the spring to maintain the high pressure in that volume bottle to push it into the actuator and make the actuator move when you need it to. Now, a couple things about the instrument air or the hydraulics oil accumulator is that number one, you’re going to want to make sure to have a good check valve system that you maintain and test that once the air comes from the supply into the volume bottle, then when we lose the instrument air or hydraulic supply, it doesn’t just reverse flow right back into our dead system.

That’s not going to be very helpful. So upstream of the volume bottle, you’re going to have a check valve system that is necessarily relatively high integrity. You’re going to want to put that on the PM program, make sure it’s tested. You might want to double up on your check valves there. Okay. The other thing that you’re going to want to do is put that alarm, the pressure gauge, pressure transmitter, pressure alarm on this volume bottle.

So gauge, so people doing operator rounds can look and make sure that you have pressure and then the transmitter that’s going to send an alarm to the control room indicating that I lost my critical pressure. So that is your secondary power supply for your fluid-based power systems, specifically hydraulics and pneumatics.

Hydrocracker ETT Example and Spurious Trip Risk

So let me give you an example of an energized to trip system that is commonly run into in the oil refining business. By this point in time, you know that I grew up in the oil patch working for UOP. So I know all my oil refining processes inside out and upside down. And one of the ones that kind of throughout my career has driven the highest need for high powered thinking related to SIS is the hydrocracker.

So in that hydrocracker, we have a reactor where we’re basically removing everything other than carbon and hydrogen and sticking hydrogen on it so that we can kind of flush that garbage away.

We don’t want that in our fuel pool. And then we’re also taking those long change hydrocarbons and cracking them into smaller ones. So something that is basically the consistency of a Vaseline, a vacuum gas oil, we’re going to crack it and make a diesel fuel. So a very valuable unit, but that reaction that I just explained is highly, highly exothermic. And as a result, you can get a runaway reaction where the temperature goes up, the reaction goes faster, which makes the temperature go up higher, reaction go even faster.

You get a vicious cycle until you melt the outlet piping, because the outlet piping is going to be your weak point. It’s not going to be your reactor body. And you’re going to get like a 100 meter long, 75 meter wide gigantic jet fire. This has happened several times in industry. If you’re really interested, California EPA has a really good report on one of these incidents that happened in Martinez, California. So look at, search the internet for a hydrocracker incident, Martinez, California, EPA report.

And you’ll get a good description of that along with some really good pictures of how that outlet elbow melts.

Okay, so this is what we want to prevent. And prior to that incident, we generally relied on a human operator to be our protection against this scenario happening. But after that event, we’ve got safety instrumented functions dealing with this. Now, in order to reduce this runaway reaction, you’re thinking, I don’t know, do we get a bunch of hoses and cool down the outside of the reactor, dump a bunch of ice inside, flood it with water? How do we cool this thing down?

Well, turns out we don’t cool it down. What we’re going to want to do is we’re going to want to depressure the reactor. Now, going into chemical engineering, the reaction rate is going to be a function of the concentration of the components. And one of the reactants is hydrogen, and its concentration by proxy is its partial pressure. And partial pressure is a function of the total pressure. So in order to decrease the reaction rate, we’re going to decrease the hydrogen concentration by dumping all the hydrogen out of the reactor.

And this reactor, depending on what type of hydrocracker you have, could be up to like close to 3000 PSI for severe cracking of really heavy oils. If you’re doing mild hydrocracking of lighter oils, you might be in the 800 PSI range, but either way, the pressure is generally pretty high. So my safety function says if the temperature is high, I’m going to want to open the depressuring valve. For those of you that are in the know, you probably know that it’s kind of sitting in the outlet line of the separator.

So the deck where the outlet separator is going to be, it’s probably going to be on the vapor line coming out of the separator is where we’re going to do our depressuring.

Now, hydrogen is a nasty chemical. It can cause hydrogen embrittlement. And there’s this weird phenomenon where high pressure hydrogen kind of buries its way into metal. and when you decrease the pressure, all the hydrogen that’s migrated in the metal wants to work its way back out in a hurry. Okay, so how could we possibly make this worse? Well, the reaction that’s going on in this hydrocracker is nasty and it will destroy most normal metal. So we’re going to want some kind of really exotic metal.

And I don’t know what the metal is, so don’t quote me on this, but it’s going to be something like a Hastelloy C or an Inconel, something very expensive. So buying an entire thick vessel able to withstand 3,000 PSI out of this exotic metal, that’s not realistic. We’re not going to do that. So we’re going to do something called cladding where we have a thin coat of the metal on the inside of the vessel which is going to protect the carbon steel which is giving us our structural integrity and our thickness and making our price for the completed piece of equipment a little bit more realistic.

Now back to that hydrogen migration thing. Well the problem is the hydrogen is going want to migrate through that exotic metal and then it’s going to want to continue to penetrate into the carbon steel. Now, if you do this rapid depressuring, the hydrogen that’s in the carbon steel wants to get back into the reactor in a hurry and that can cause something we refer to as delamination. So activating your safety function can actually peel the exotic metal layer off of the carbon steel. Now, it’s probably not going to do that. It’s probably not going to do that the first time.

But if you’re depressuring and repressuring this thing a lot and really fast, it’s going to happen eventually. So spurious trips that accidentally throw this valve open are a big freaking deal. Big freaking deal. We don’t want them to happen. So even though the safe state is an open valve, I did the air quotes again. Sorry about that. When I said safe state, is an open valve. We don’t want a fail open valve here. We want an air to open fail closed valve here because we don’t want this thing to just go open.

And if we can detect that we don’t have the instrument air to make it go open, we can slowly ramp down our hydrocracker. instead of risking a spurious trip.

Hydrocracker ETT Design with Volume Bottle

So what the typical design is, is that we’re still going to go de-energize the trip out to the solenoid valve. We might sometimes put a 2 out of 2 or a 2 out of 2D solenoid package in to limit the PFD because this is generally going to be in the SIL 2 range, maybe even in the high 2 SIL range for most processed plants. So we’re going to want to go energize the trip out to the solenoids.

But for the solenoids, instead of them dumping the air off the actuator, we want to configure the solenoid so that when they’re de-energized, they’re going to allow the air to go to the actuator to cause the valves to go to the open state. So the portion of the loop from the solenoid through to the valve is energized trip. But again, SIL2 is super, super critical. So this is where we’re going to want to apply that volume bottle. So we’re going to bring our instrument air in. We’re going to go through our highly maintained double check valve system and it’s going to go to the volume bottle.

That volume bottle, we’re going to size that volume bottle so it’s got enough air volume and enough air pressure to be able to stroke that valve three times, not once, not twice, but thrice. That’s going to be our sizing criteria for that volume bottle. And then we are going to put a pressure transmitter maybe on the volume bottle, probably on the tubing really close to the bottle. And so there, we’re going to have a pressure gauge, which is generally going to be supplied by the vendor of the bottle and we’re going to have a pressure transmitter that we’re going to wire to the

SIS, to the DCS. Again, the standard doesn’t tell you which way to go. I don’t mind wiring that to the safety instrumented system and then communicating it to the SIS for enunciation. And that’s basically what I would expect for that system. And that’s probably, you know, one of those safety functions that it is more common to have energized to trip than de-energized to trip. And it’s a pretty good overall example of what we’re trying to achieve here.

Episode Summary and Next Week Preview

All right. So with that, I have talked clause 11 to 11 almost completely to death. So one sentence in two notes that are each one sentence, three sentences total, required almost an hour of discussion because, you know, that’s how much stuff is packed into this standard. It’s tight. It’s concise. But man, are there a lot of use cases, a lot of options, a lot of considerations to think about as you’re going through your design processes. So that’s all I’ve got for this week. Next week, We’re going to finish up Clause 12 talking about security. We’re going to talk about the safety manual.

Safety manual, also known as where the equipment vendor buries the bodies that they don’t want you to know about. And then we’ll close out Clause 11 with 11214, which talks about communications.

We kind of just talked a lot about communications today. hey, it seems like maybe they should have put these two things together. But I digress. That’s all I got for you today. We will talk to you next week.

Kenexis Vertigo Software Overview

Now that you’ve heard some insights on technical safety, functional safety, and the IEC 61511 standard, let me tell you a little bit more about how to easily and effectively implement the safety lifecycle using the Kenexis Integrated Safety Suite and our SIS Safety Lifecycle Management tool, Vertigo. Vertigo is a comprehensive tool set for performing assessment calculations, documenting, and maintaining the design of safety instrumented systems.

Analysis begins with importing or synchronizing a list of safety instrumented functions with their definitions and associated performance targets from our open PHA tool for HAZOP and LOPA documentation.

Each safety function can then be analyzed by performing a SIL verification calculation, complete with a collection of tools for optimizing designs and a database of thousands of potential instruments to define failure rates and diagnostic coverage capabilities.

After the SIL verification calculations are defined, you can build an SRS by automatically generating a cause-and-effect diagram from the SIF definitions and other defined instruments. Each SIS instrument will include a customizable data sheet and general requirements that are applicable to the SIS as a whole and can be entered individually or even bulk imported from customizable libraries.

After the design phase, you can even use Vertigo to track and document testing throughout the entire life of the facility. Kenexis Vertigo is the most integrated, easy-to-use enterprise tool for allowing the development of SIS design basis information more efficiently and effectively than any other software application. Thank you.