Kenexis Functional Safety Podcast

A certificate of conformity does not relieve anyone of thinking like an instrumentation engineer. In this episode, Ed Marszal takes the podcast out of the logic solver and into the field, where he argues prior-use judgment matters more than third-party seals. Clause 11.6.1 (11.6.1) demands devices be chosen for specific process conditions—corrosion, coking, freezing, condensation in dry legs—not generic vendor claims. Ed works through level measurement technologies from displacers to guided wave radar, illustrating how each fails differently in hostile service. The episode also revisits energized-to-trip circuit integrity (11.6.2) and traces the thirty-year evolution of smart sensor write protection from field dip switches to Azure-authenticated asset management systems (11.6.3). For engineers tired of outsourcing their judgment to certifying bodies, this is a refresher in first-principles field engineering.

Don’t let the instrument’s certificate distract you. Your role as an instrumentation and control engineer requires continued diligence. The work still needs to be done! Let’s dive into Section 11.6 for a detailed exploration and discussion of this topic!

Tune in to the latest episode of the Kenexis Functional Safety Podcast, hosted by Ed Marszal, President and CEO of Kenexis. Now available on Spotify and Apple Podcasts, Ed offers his expert insights on the IEC 61511 standard.

With decades of experience in safety instrumented systems and as a Principal Engineer, Ed has a unique perspective to offer. He has been an active contributor to the ISA 84 committee since 1994, adding to his deep understanding of the field.

In this inaugural season, Ed delves into the IEC 61511 standard, unpacking the meaning behind each word and providing a thorough interpretation of its application. Through personal stories from his career and committee work, he offers valuable context and insights for professionals in the industry.

Full Episode Transcript

KENEXIS FUNCTIONAL SAFETY PODCAST — S1E40 TRANSCRIPT (Markdown)
Cleaned & reflowed for web publication and AI crawlability.

The JSON-LD block below is schema.org structured data. If your CMS lets you
add raw HTML to a post, paste it into the page (or anywhere in the
body — crawlers read it either way). Fill in PLACEHOLDER_EPISODE_PAGE_URL
once the post exists. Everything from the "# Kenexis Functional Safety
Podcast…" heading down is the transcript body — paste it into your post.
–>

"`html

"`

# Kenexis Functional Safety Podcast — Season 1, Episode 40: IEC 61511, Clause 11.6 (Field Devices)

## Introduction and Course Overview

Just because the instruments that you bought have a fancy certificate with it does not mean you get to stop being an instrumentation and control engineer. Do the work.

Welcome to the Kenexis Functional Safety Podcast. I'm your host, Ed Marszal, President and CEO of Kenexis. Kenexis is a technical safety consultancy that helps chemical process industry companies to analyze risk and design engineered safeguards like safety instrumented systems and fire and gas detection systems. Kenexis also provides the industry-leading suite of software tools, including our best-in-class Vertigo software for SIS safety lifecycle management.

In this first season of the podcast, we are going to focus on the IEC 61511 standard, doing a deep dive into the standard, including more depth of information on what the standard means and how to apply it, brought to life with personal war stories and behind-the-scenes discussions of the committee members as we develop the standard in ISA 84 and IEC SC 65.

Before we start, a little disclaimer. I will be providing my opinion on technical and engineering topics. This information is provided on a best-effort basis and is of a general nature. The information presented in this podcast might not be applicable to your specific application. It is the obligation of every engineer to thoroughly analyze any system that they are designing and not blindly rely on any general advice presented in this podcast.

## Field Devices and Clause 11.6 Overview

All right, we are going to move along out to the field. We spent a lot of time in the past couple episodes talking about logic solvers, specifically how to justify the use of logic solvers in a safety instrumented system, with a focus on how to do it using safety configuration instead of buying a certified device.

Well, this week we're going out into the field. And out in the field is where I personally see a lot more value in prior use experience, in good, old-fashioned instrumentation and control engineering, as opposed to relying on some sort of trusted third party to tell you that something is good, because that trusted third party is really just wanting to put money in their own pocket. Please. So, what you need to do is when you're installing instrumentation and control equipment in the field, you need to be the engineer of record. You need to do the work. You need to do the thinking.

What device should I use? What technology should I use? How am I going to install it? All of that needs to be done by you.

And all of that, well, I don't want to say all of it is discussed, but as much as we need to know for the SIS standard, is contained in Clause 11.6. And 11.6 doesn't really contain that much information. It's going to be kind of a brief episode here. But the key message of Clause 11.6 is you're an instrumentation control engineer.

Think about what the service is, what the ambient environment is, and pick a device, a component that's going to be suitable for your specific process service, your specific application in terms of not just the vendor, but also the technology and the installation practices.

I mean, something as simple as, well, there's dust in the service. I probably want to mount the impulse line on the top of the pipe instead of the bottom of the pipe where all that dust can accumulate in my impulse piping and mess up my signal. Now, all of this is really not instrumentation control engineering, but it's not safety instrument. It's system engineering in so much as you need to think about this for every other instrument that's in the plant, whether it's safety related or not. So pick a device that is suitable for the application.

That is the summary of Clause 11.6. But let's go ahead and delve into the details, talk through a couple of special situations that you might want to think about that you might want to consider as you're doing this.

## Level Measurement Technologies and Selection

All right. So Clause 11.6 is field devices. Okay. Clause 11.6.1 is the first requirement. There are three clauses that contain requirements. 11.6.1 is the first one. And it says, you know, I'm going to read this through to you. There's only two sentences. I'll be able to get through the entire first sentence. The second sentence is going to require a bunch of stops. But for that first sentence, it says, field devices shall be selected and installed to minimize failures that could result in inaccurate information due to conditions arising from the operating equipment. Okay.

Conditions arising from the operating equipment. Back when I was at UOP, we called that the service description, the process service. What chemicals am I touching? What is the temperature? What is the pressure? What are the barriers between my instrument and the process fluid? All this stuff needs to be thought through. Because instruments that are good in one application might not be good in another application.

So, as we're going through this discussion, I think that the best measurement type to really think this through is level. I mean, there are a ton of ways to measure level continuously. There are even more ways to do point level measurements. So, for continuous level, you're going to start out with the most old school, which is going to be the displacer. You've got a float in a chamber. And depending on what the level is, the float is going to float a little bit more. When the float chamber is full, it's going to float a little bit less.

And you can kind of measure the torque, or you can measure the weight. There's a lot of different measurements that you can make. That's kind of one of the original methods.

Then we started messing around with radars. And lasers are kind of in the same vein, where you're going to shoot a signal at the surface, and then it's going to bounce back up. And you're going to measure time in flight, and that tells you what your level is kind of by the negative. The faster the signal gets back to you, the more full your vessel is. And so, in terms of the level measurements, especially the radar, we kind of learned that, well, you know, if you kind of shoot that radar into open space, you're going to get all kinds of bouncing and weird signals.

So, you do things like having stilling chambers that are going to give you kind of a cleaner path to shoot that signal down. And then someone said, you know what, why don't we just take that radar signal and shoot it through a piece of metal instead of shooting it through open air. So, there you have your guided wave radar where you're sending that signal. And the guided wave radar, very, very popular now.

But also, some of the other old school methods for measuring level would include differential pressure. You know, the pressure, the head pressure of the fluid. You can measure that and kind of translate that into what the height is. Also, if you want to go real, real old school, you can use the bubblador. That would be a little Spanish lingo for you there. The bubbler. So, you just kind of bubble some instrument air into the process and you can kind of measure the pressure. The more pressure you're facing when you're putting your bubbles into the system, the higher the level is.

So, those are some methods for continuous measurement. Oh, nuclear. Well, let's just shoot a bunch of radiation through the vessel. And depending on how much radiation we receive on the other side, that tells us what the level is. But you've also got switches like your tuning forks, your floats, all kinds of stuff.

## Field Device Failure Modes and Service Conditions

Now, all of these different mechanisms have different failure modes in different types of operations.

So, there are all kinds of things that can mess up your signal. Well, number one, if your processed fluid is super, super corrosive, then you probably don't want to stick a piece of metal in there because the metal is going to get corroded and that's going to screw up your signal. You might have a lot of foam. You might have, you might be boiling and then, you know, when you put cold water into the boiling water, everything kind of collapses even though you technically increased the amount of water in the vessel. It kind of looks like it dropped down because the boiling stopped for a second.

You know, anybody who's made pasta is familiar with that process. So, you need to think about all of the things that your measurement type is sensitive to that can cause errors.

So, the second sentence in Clause 11.6.1 starts to list out, well, what are all of the different things that you should think about? And it does not give you an exhaustive list. It just gives you a few some things to think about.

So, number one, corrosion. Corrosion on something like a float type level measurement can prevent it from moving along its pathway if it's on some sort of rod that's kind of guiding where the float goes. Corrosion on a sensor for a guided wave radar is going to dampen the signal at a minimum and just kind of prevent you from being able to get a feel for what's out there. You're basically putting a coat on that prevents the sensor from actually feeling, if you will, the actual process fluid. So, that is corrosion. Lots of negative impacts there.

Freezing of materials. So, this goes to not just your equipment selection, but also to your installation methods. And the appurtenances, you've got to love that word, appurtenances. I first started using that word while I was reading the boiler and pressure vessel code where they use it a lot. So, appurtenances is all the extra stuff, the extra kit that goes along. So, if you need to put an insulation bag and some insulation around your impulse piping to prevent it from freezing, you need to think about that. So, freezing of materials in the pipes or even in the impulse lines.

Next item of concern is going to be suspended solids. Now, suspended solids have a variety of problems associated with them. Number one, they can settle out into a low point. And if that low point is the impulse piping of your pressure measurement, that's a very bad thing. So, you're going to need to think about installing things like tap flushing apparatus. You might want to think about remote seals. Also, suspended solids in a high velocity liquid, you're basically sandblasting your equipment.

And, you know, maybe your pitot tube that you're using to measure a differential pressure. You start sandblasting that thing and it might actually break off. Or, if you're sandblasting an orifice for a differential pressure flow measurement, well, that's going to kind of screw up the signal also.

Next item on the list would be polymerization. Your old popcorn polymers are kind of the most infamous safety problem where you're basically creating plastic pellets and plugs inside your process, which can impact the ability for fluids to flow in and out of instruments to get to instruments and so on.

Coking! So, you know, cutting my teeth in the oil patch, getting my PhD in refining, if you will, from working at UOP for those years when I first started my career, I could tell you all about coking. Coking on purpose and coking by accident. Here we're talking, for the most part, about coking by accident. So, when you're heating up a lot of those hydrocarbons, sometimes you're going to, when you're in the cracking process, you're going to leave elemental carbon. It's going to build up and cake up.

And in an oil refinery, probably the number one cause of tap plugging is going to be coking in all of the fired equipment that you use. Now, we do have the coker unit where we make coke on purpose. We're trying to squeeze every last bit of hydrocarbon out by just basically cracking away the coke and leaving the coke by itself. So, in a coker unit, there is all kinds of issues related to coking that you'll need to deal with, not just for your instrument, not just for your SIS, but for all your instrumentation and all your equipment.

You know, plugging up of relief valves in coke drums is kind of, you know, that's another major design issue. A little bit away from what we're talking about here, but not that much.

## Temperature, Pressure, and Impulse Line Considerations

Temperature. Most of this fancy schmancy new instrumentation and control equipment has microprocessors that cannot handle the heat. So, if you need to measure something really, really hot, you're going to need to take care to get that process condition suitable for the way that you're measuring it. So, you know, things like on a valve, there's such a thing as an extension bonnet, which is going to keep the actuator a good safe distance away from the process fluid so that all of the mechanisms that are going to move the valve can cool down before they get into the actuator.

And, you know, there are other similar techniques that you can use if you're measuring high temperatures.

And then finally, high pressures are also difficult to do measurements in because you need to keep the process fluid in, yet you need to get the signal out. So there's going to be seals and interfaces that you need to think about while you're doing these types of things. Okay, there's more items.

Next item on the list is condensation in dry leg impulse lines. What? Okay.

So for those of you that are not in the new, impulse line is the connection between the process and your instrument. Okay. Sometimes your impulse lines are wet, wet leg. Sometimes they are dry, dry leg. So what a wet leg means. So let's say, let's give you the easiest thing to think about conceptually, which would be measuring steam. So if you're measuring steam, you know that when it cools down, you're going to get back to water.

And if your impulse piping is exposed to atmospheric temperatures, then the steam that is in the impulse line is going to cool down, and it's going to turn to water, and eventually it's going to fill up.

So when you're measuring that steam flow rate, generally you're going to have wet legs in that your steam is condensed out to water, and you need to think about that while you're doing your calibration, while you're doing your installation, while you're doing your testing. Because if you calibrate it dry and it gets wet, now your signal is way off. It's not a little off. It's way off.

Now, if I'm measuring a differential pressure to get a level signal, for instance, now the lower leg that's measuring the liquid is going to be a wet leg for sure. But your other leg that's up high that is in the vapor space, it's probably going to end up being a wet leg too. Because if you've got an interface between a vapor and a liquid, that means that the temperature differential, not really that, well, actually they're probably going to be at the same temperature. We've just got the latent heat of vaporization differentiating the vapor from the liquid.

So as soon as that saturated vapor gets into that impulse piping and cools down a lot, it's going to condense, and you're going to fill that dry leg, what you think is a dry leg, you're going to fill it up with liquid, and it will quickly become a wet leg. So think about that.

And for this particular warning, the biggest deal there is going to be on your differential pressure measurements, where you know what's in the liquid is going to be liquid, but you think what's going to be in the vapor is going to be vapor, but it's not. Most of the time, a lot of the time, I should be very careful with my superlatives, a lot of the time, you're going to condense your vapor into a liquid, and even the vapor side of your differential pressure, that impulse piping is going to be filled with liquid.

So you need to think about that while you're doing your calculations, while you're doing your design, while you're doing your maintenance, while you're doing your testing. Okay, that's all 11.6.1.

## Clause 11.6.2 Energized-to-Trip Circuit Integrity

Let's move on to the next item, which is 11.6.2. And that is, I will go ahead and read it out. We've got a clause, one sentence clause, and two informative notes. Let's read the clause. And as soon as you read this, you're going to get some deja vu.

All it says is, energized to trip circuits shall apply means to ensure circuit and power supply integrity. I'd swear we spent most of an episode already talking about this, didn't we? Didn't we? Didn't we? Yes, we did. But that's where we were in a clause where we were just saying that we prefer energized to trip, and if you're, or, we prefer de-energize to trip. And if you're going to do energized to trip, you should probably include some other design considerations.

And one of those other design considerations was circuit integrity monitoring, and the other design consideration is power supply integrity. So being able to ensure that your power supply is available, and if the power supply is not available, you're going to go ahead and set an alarm. The same way the circuit integrity is, if you drop a connection somewhere, you're going to get an alarm saying that, I don't have continuity in my circuit. So we've already spent a lot of time talking about that.

This is a little bit of a repeat. Why did we have to repeat this information? Not really sure. Is it a problem that we've repeated the information? Maybe. Maybe to some people. Not to me. I'm okay with it. Okay.

So, note one to this requirement states, an example of such means is end-of-line monitoring, where a pilot current is continuously monitored to detect circuit continuity, where the pilot current is not of sufficient magnitude to affect proper IO operations. So, I talked this requirement to death a few weeks ago when we were looking at clause 11.211. There are a lot of different ways to do end-of-line monitoring. And as a matter of fact, if you're really interested in this topic, I would highly encourage you to go to the Kenexis YouTube channel and look for one of the videos that I did.

I spent probably an hour to an hour and a half talking about energized to trip and de-energized to trip and the mechanics of how to do circuit integrity monitoring. So, that's out there.

It's on the YouTube channel. It's also, if you get into Kenexis Integrated Safety Suite in the learning management system, all of our webinars are also in there. And if you view one of our webinars, since we are getting close to the year, I know there are a lot of professional engineers out there that are in search of the professional development hours. If you view our webinars through our learning management system and contact me, there's really no cost to do it. It's free. You just need to have a KISS account. And if you don't have a KISS account, why not? Come on.

If you view the free webinar through the learning management system, you'll be able to print out a certificate that includes professional development hours. So, yeah, something to think about there. Very, very, very, very valuable. And, you know, free. Can't beat that price.

Okay, I'm getting off on a tangent. Note 2 says additional requirements for loss of power can be found in 11.2.11. Okay, so we have an entire webinar on it. There's also an entire podcast on that topic. If you don't remember it, if you skipped over it, definitely want to go backtrack and check that out.

## Clause 11.6.3 Smart Sensor Write Protection

All right, next item up is Clause 11.6.3. One sentence and one note. So let's go ahead and read that sentence. Smart sensors shall be write-protected to prevent inadvertent modification unless appropriate safety review, for example, hazard and risk analysis, allows the use of read-write. Okay, how old do you have to be for this? As old as me, I guess. Maybe you could be a little bit younger. Not a whole lot younger.

So before I get into the wild world and the history of right protection and what that means to an old timer versus what that means to a new person versus what that means about how you do it today, let me go ahead and hit the informative note.

The informative note simply says the review can take into account human factors such as failure to follow procedures. So while you're thinking about right protection.

Okay, so smart sensors are near and dear to my heart because they were brand new when I was brand new to industry. I remember the ISA show in 1993. I believe was in New Orleans. Spectacular show. And to this day, I would like to thank the fine folks over at Wonderwear for the show that they put on. My goodness, I still talk about it to this day. They rented out the Superdome and they had Dr. John and the Neville Brothers playing along with all the Cajun food you can eat and cocktails, shall we say. We're also on the unlimited side. Good time was to have it by all. But why do I bring this up?

Because it was at that show that there were a lot of introductions for this new thing called the Smart Transmitter. Whereas dumb transmitters, if you will, were devices that were still, you know, your resistors and transistors and, no, no. Yeah, maybe some transistors, some potentiometers and that kind of stuff. Your traditional electronics. But they were not microprocessor based. There were no programs running on them.

And the equipment vendors all decided, you know what, we could get a lot more functionality into our equipment and maybe even charge a higher price while reducing the price by putting some chips into these systems.

So for the first pass of these smart devices, which now your pressure measurement, your level measurement, what have you, is being performed by a program that's running on a chip inside the sensor. Now, most of you in the audience now probably professionally don't remember a time before smart devices. But back in the day, everyone was afraid because you could connect a HART communicator anywhere on the loop and talk to this device by basically doing kind of a frequency modulation, amplitude.

I don't even know exactly how it works, but on your 4 to 20 milliamp signal, there is a digital signal riding on it that you communicate with the device. And you can bring up all the parameters. You could change the parameters. And back in the day, that had to be done with a special HART communicator that had a couple alligator clips. You clip it into the circuit and you make changes.

So now everyone was afraid that, well, you know, what if I connected my communicator to the wrong wires? Maybe people from the wrong unit are connecting to the wrong wires. Maybe a rogue employee is connecting in the control room and they're manipulating stuff out in the field. How can we prevent this? Well, all the vendors said, you know what we should do? We should put in some right protection. So what that right protection looked like is you still kind of get to the electronics of the transmitter the same way.

You're going to kind of unscrew the cap and look inside and you're going to see the electronics, including the circuit board now. And over off to the side, there was a little set of dip switches. Dip switches. That's right. They're little tiny, tiny switches. You know, you use your little micro screwdriver to lift them up and lift them up and down. And one of those dip switches, when you put it into the disabled position, it would disable the heart communications from working. And then when you put it in the enabled position, it would allow the heart communications to work.

So if you went out and you're a technician, you go out to the field, you could flip the dip switch that would put the transmitter into write-protected mode. And now you're not allowed to either communicate with the device at all, or at least you're not allowed to write anything. You might be able to read the signals, but you're not allowed to write anything. All right.

Well, fast forward. Oh my God. Is it 30 years? More than 30 years. Nobody goes out to the field anymore. We have asset management systems. So somebody is sitting in a control room with all kinds of IT protections. So Azure Active Directory, single sign-on, multi-factor authentication to get into the computer alone, let alone the passwords on the asset management system. But that device is now going, that computer, that maintenance and engineering interface computer, which we're probably going to talk about two weeks from now, because next section is going to be interfaces.

But for right now, that maintenance and engineering interface, it is extremely secure. So at this point in time, it doesn't make a whole lot of sense to have the dip switches on the devices in the field anymore. So those things have kind of gone the way of the dinosaur.

So now what does right protection mean? Well, it means the authentication to be able to use the maintenance and engineering interface, which is your asset management system, which allows you to change parameters of equipment out in the field.

So the process for securing that maintenance and engineering interface is something that I am certain that you have worked through. But when we get to clause 11.7, where's my mouse here? 11.7.3, we're going to talk about it again. But we're not there. We're still in field devices. And as a matter of fact, we're kind of done with field devices.

## Episode Summary and Next Episode Preview

So that's all I've got for this week. We talked about clause 11.6, talked about those pesky field devices. Next week, when we get back to you, we're going to be talking about interfaces. We're probably going to spend three weeks talking about interfaces. Week number one is going to have to do with operator interface requirements. Then the week after that, we're going to spend the episode talking about maintenance and engineering interface requirements.

And then after that, you know, I might combine clause 11.7.4 with clause 11.7.1 and just talk about the general requirements of interfaces, which is going to be clause 11.7.4, which we'll get to that in a couple of weeks from now. But that's all I got for now. Thank you for your time. And I will talk to you next week.

## Vertigo Software Advertisement

Now that you've heard some insights on technical safety, functional safety, and the IEC 61511 standard, let me tell you a little bit more about how to easily and effectively implement the safety lifecycle using the Kenexis integrated safety suite and our SIS safety lifecycle management tool, Vertigo.

Vertigo is a comprehensive tool set for performing assessment calculations, documenting, and maintaining the design of safety instrumented systems.

Analysis begins with importing or synchronizing a list of safety instrumented functions with their definitions and associated performance targets from our open PHA tool for HAZOP and LOPA documentation.

Each safety function can then be analyzed by performing a SIL verification calculation, complete with a collection of tools for optimizing designs and a database of thousands of potential instruments to define failure rates and diagnostic coverage capabilities.

After the SIL verification calculations are defined, you can build an SRS by automatically generating a cause and effect diagram from the SIF definitions and other defined instruments.

Each SIS instrument will include a customizable data sheet and general requirements that are applicable to the SIS as a whole and can be entered individually or even bulk imported from customizable libraries.

After the design phase, you can even use Vertigo to track and document testing throughout the entire life of the facility.

Kenexis Vertigo is the most integrated, easy-to-use enterprise tool for allowing the development of SIS design basis information more efficiently and effectively than any other software application.

*[inaudible]*

Thank you.