Kenexis Functional Safety Podcast
What good is a safety instrumented system that cannot be tested without shutting down production for weeks? In this episode, Ed Marszal dismantles the fantasy that end-to-end testing is the only valid approach, walking through Clause 11.8.1’s permission to test in segments and the critical warning that online test facilities become mandatory when proof test intervals outrun turnaround schedules. He recounts a 2006 Southern U.S. oil refinery where a high-priced consultant’s elaborate partial-stroke testing scheme met an operations veto of “oh, hell no”—leaving the plant with no test plan, no bypasses, and quarterly sensor tests in a six-year turnaround cycle. The episode then presses into Clause 11.8.2’s requirement that test facilities be integral to the SIS design, not jury-rigged later, and Clause 11.8.3’s twin mandates that testing conform to the SRS and that operators be alerted to every bypass. For engineers wrestling with stretched turnarounds and the political economy of production versus proof testing, this is essential listening on designing for testability before the plant is built.
The design shall allow for testing of the SIS either end to end OR in segments meaning you could test one piece at a time, but when you do that, you must be very careful… Listen in as sections 11.8.1 to 11.8.3 are discussed in more detail.
Tune in to the latest episode of the Kenexis Functional Safety Podcast, hosted by Ed Marszal, President and CEO of Kenexis. Now available on Spotify and Apple Podcasts, Ed offers his expert insights on the IEC 61511 standard.
With decades of experience in safety instrumented systems and as a Principal Engineer, Ed has a unique perspective to offer. He has been an active contributor to the ISA 84 committee since 1994, adding to his deep understanding of the field.
In this inaugural season, Ed delves into the IEC 61511 standard, unpacking the meaning behind each word and providing a thorough interpretation of its application. Through personal stories from his career and committee work, he offers valuable context and insights for professionals in the industry.
Full Episode Transcript
KENEXIS FUNCTIONAL SAFETY PODCAST — S1E44 TRANSCRIPT (Markdown)
Cleaned & reflowed for web publication and AI crawlability.
The JSON-LD block below is schema.org structured data. If your CMS lets you
add raw HTML to a post, paste it into the page
body — crawlers read it either way). Fill in PLACEHOLDER_EPISODE_PAGE_URL
once the post exists. Everything from the "# Kenexis Functional Safety
Podcast…" heading down is the transcript body — paste it into your post.
–>
"`html
"`
# Kenexis Functional Safety Podcast — Season 1, Episode 44: IEC 61511, Clause 11.8.1 to 11.8.3 (Maintenance or Testing Design Requirements)
—
## Introduction and Clause 11.8 Overview
The design shall allow for testing of the SIS either end-to-end or in segments, meaning you can test one piece at a time. But when you do that, you have to be very careful.
Welcome to the Kenexis Functional Safety Podcast. I'm your host, Ed Marszal, President and CEO of Kenexis. Kenexis is a technical safety consultancy that helps chemical process industry companies to analyze risk and design engineered safeguards like safety instrumented systems and fire and gas detection systems. Kenexis also provides the industry-leading suite of software tools, including our best-in-class Vertigo software for SIS safety lifecycle management.
In this first season of the podcast, we are going to focus on the IEC 61511 standard, doing a deep dive into the standard, including more depth of information on what the standard means and how to apply it, brought to life with personal war stories and behind-the-scenes discussions of the committee members as we develop the standard in ISA 84 and IEC SC 65.
Before we start, a little disclaimer. I will be providing my opinion on technical and engineering topics. This information is provided on a best-effort basis and is of a general nature. The information presented in this podcast might not be applicable to your specific application. It is the obligation of every engineer to thoroughly analyze any system that they are designing and not blindly rely on any general advice presented in this podcast.
All right. In today's installment of the Functional Safety Podcast, we are going to be talking about maintenance or testing design requirements. We are looking at Clause 11.8. Clause 11.8 has six sub-clauses to it, and we should be able to get through all of them in one installment of the podcast. It is approximately a half to three-quarters of a page of text. So since we've got an hour, we might be able to get through the material, but then again, we might not.
There's a whole lot in these six sub-clauses that require some examples, require some additional discussion, require some additional considerations, because you might not have completely thought through everything that needs to be done, everything that needs to be considered.
So let's start off by explaining what this clause is and what it is not. So we are still in Clause 11. Clause 11 is related to detailed design of the SIS, and what we're going to see here, especially related to this clause, is that we're concerned about the detailed design of the entire plant with a focus on the safety instrumented systems. But even though we're really focused on the safety instrumented systems, we need to think about the rest of the plant, piping, insulation, paint.
There's a whole lot more to installing and operating a safety instrumented system than just the instruments themselves. And this is going to kind of require us to think about how we're going to perform the tests.
What needs to be done to simulate a process condition? How can we confirm that the actual final element actuation is happening in such a way that we're confident that it would have happened while the plant is online and in operation? And, well, this gets really complicated when the plant is online and in operation.
So how can we perform a test that is comprehensive, that gives us a proof test coverage, a manual proof test coverage approaching 100%, which is absolutely always going to be our target for the design of the safety instrumented systems, without interfering or interrupting production?
Well, usually that's going to happen by doing the test while the plant is offline for a turnaround and doing the test end-to-end. But in a lot of cases, we can't do the test end-to-end because of operational constraints. The plant never shuts down. I always like to say that for offshore oil and gas production, once they poke a hole in the ground and oil starts flowing out of it, they ain't shutting that plant down until all the oil's gone.
So there, there's a lot more planning to be able to do testing without taking the plant offline, or at least without taking the plant completely offline, maybe taking portions offline. So, all right, let's, let's get into it. And we're going to, again, clause 11 is about the design of the SIS and the design of the plant such that you will be able to test it.
This is completely different from an upcoming clause. And let me kind of scroll down here to that, which is going to be clause 16, I believe. Yes. So 15 is site acceptance testing or validation. Clause 16 is going to be SIS operation and maintenance. So clause 16 actually talks about doing the maintenance activities, doing the testing, operating the devices, using the procedures, and so on. That is different from clause 11, which is how do I design my plant so that I am capable of testing it?
I need to think about how I'm going to perform the tests while we're in the design phase, because, well, right when you need to test it is not a good time to find out that it's not possible to test it because you didn't design in the features, the equipment, the bypasses to allow that testing to occur. So 11.8 needs to occur during the design phase where we think about how we're going to test the devices.
Maybe we even write the test plans at that point in time and make sure that we're actually going to be able to perform the tests with the equipment that we have. And if we can't, then we need to put into the design the equipment that we need to be able to perform that testing. Okay, let's hit it.
## Clause 11.8.1: End-to-End Testing Requirements
11.8 maintenance or testing design requirements. And as I mentioned previously, there are six clauses. The first one is two whopping sentences with a note. So let's read. 11.8.1 states, the design shall allow for testing of the SIS either end-to-end or in segments. Now that first sentence, absolutely super critical. And I've been in arguments with people on the standards committees, whether it's 1511 or ISA 84, all the way back into the 90s, where there are people 100% completely adamant that the only possible conceivable way to test an SIS is to do an end-to-end test.
So here, I'm going to actually read the note first before I get to the second sentence of the clause because it talks about what end-to-end means. So the note for this clause is, the term end-to-end means from process fluid at the sensor end to the process fluid at the actuation end. So we're going to test everything, including the process fluids, to make sure that we can simulate a process condition with the process fluid and we can actuate against the process fluid.
Now, actuating against the process fluid is something that's almost never done in practice because it's so difficult to do and it might actually even be more dangerous than not testing at all. Trying to, you know, stop a hot, toxic, high-pressure fluid live. So most testing of the valves, and we'll talk about this a little bit later, probably a lot more when we get into clause 16, is that you're probably going to test that valve dry. You're going to test it when the process is not in service. But sometimes you do actually actuate the shut-off valves against the force of the motive fluid.
And I'll go back to the offshore oil and gas case. When you're closing your shut-off valves, whether it's the downhole valve, your master valve, your wing valve, you're generally going to shut it off against the process fluid because practicality. I mean, you can't do anything other than that. And you're definitely not going to take the valve out of service and bring it back to the shop. And if you did take it out of service and bring it back to the shop, you would have had to have shut it against the process fluid in the first place.
So that's kind of the end-to-end test is we're going to simulate a process condition with a process fluid. And we're going to see the final element activate. That is a great test.
That is a very comprehensive test. But in order to perform that kind of test, it is a massive operational issue. Especially considering that, you know, something like an offshore oil platform, if you close in the production separator, you're going to close in all of the wells that are coming into that production separator. So this could be a massive undertaking to shut everything down, which generally doesn't happen.
And, you know, and again, I'm kind of picking on offshore oil and gas because that's one of the industries where it's exceedingly rare to do an end-to-end test. Because when you do an end-to-end test, you're going to stop complete production of an entire field. Whereas you're generally going to want to do testing of one well at a time on the final element side. And then on the sensor side, you'll just, you know, test the sensor by itself in the bypassed state so that you don't activate any of the shutdowns or activate any of the valves to actually go into the closed position.
So end-to-end requires basically the entire facility, entire facility to be shut down for maintenance because it is such a thorough, comprehensive test.
Now, generally, this is the case. I mean, there are some situations where you could do a complete loop test, complete end-to-end test while a plant is online and running. If you have kind of some process redundancy where you're maybe stopping train A while train B is running or something to that effect. But again, end-to-end is generally a lot more difficult to accomplish. It requires a lot more setup. It generally requires the plant to be offline when you do this type of testing.
## Segmented Testing and Subsystem Test Intervals
So that is one of the allowed tests, but the standard also specifically right there in the first sentence says that you're allowed to test in segments. And what does that mean, test in segments? Well, that means I'm going to test each subsystem or even individual components at different times, at different intervals, for different reasons, using different procedures sometimes. So let me give you an example.
Now, I'm going to go back again. For offshore oil and gas production, you're going to have a test of shut-off valves that's going to happen at a regular basis. So these tests are all happening on a prescribed basis. They're being documented. But when you shut in a well, you're going to shut in one well at a time, and you're just going to activate the valves and make sure that the valves go to the closed position, make sure that they're completely closed, make sure that they close within the maximum equipment response time, maximum SIF response time.
We're generally going to break down, especially when we're doing our testing in segments, we definitely need to break down that SIF response time into individual subsystems and kind of give a budget for each of the subsystems to get to the safe state in an appropriate amount of time. Okay, so that's the test.
And all we tested there was the valves. Now, for the sensors, we're usually going to put a sensor into bypass. And then disconnect the sensor from the process, you know, pump it up with a hand pump and make sure that it's calibrated, that it functions properly, that it trips at the correct trip point, or at least that it indicates that it's going to correct at the trip point without actually activating the safety function. And that would be the test of the sensor.
Now, the test of the sensor and the test of the valve, they often happen at different time intervals. So you're going to test the valves or the sensors more often than the other. So they're not tested at the same time, and they're not even generally tested at the same intervals. Well, what about the logic solver? Well, the logic solver is going to be really, really difficult to test because the logic solver impacts all of the safety equipment on the platform. So that's going to be reserved to very infrequent testing.
And again, there's a lot of redundancy. There's a low probability of failure on demand on the logic solver system that allows you to test it a lot less frequently than the rest of the equipment, especially if you have a SIL 3 certified device. So we have the ability to do, you know, kind of testing at different time intervals, and it's okay to do that. So test the sensors at one point in time, test the valves at a different point in time, test the logic solver at a different point in time.
Well, let's continue on in what the standard says. The next sentence to Clause 11.8.1 is, where the interval between scheduled process downtime is greater than the proof test interval, then online test facilities are required. Okay, so first sentence, we're allowed to test end-to-end or in parts.
## Online Test Facilities Required for Live Plant Testing
The second sentence says, If you need to test more frequently than the plant is shut down for maintenance, so more frequently than the turnaround interval or the pit stop interval, whatever you want to call it, then you need to, the clause says, then online test facilities are required. What does that mean, actually?
Well, what this clause is really telling you is that if you need to perform a test while the plant is online and running, you need to think about how you're going to perform that test. So you're going to need to visualize the test. You're going to need to write a step-by-step detailed procedure for how you're going to perform that test. And while you're doing that, you need to be thinking each step, how is this step going to impact the plant that is still online and running? And how do I make sure that even though the plant is online and running, my test is not going to shut the plant down.
It's not going to cause a spurious trip. And also, how do I make sure that the plant is safe while I'm testing the system? Okay, and that's going to go back to clause 11.3, compensating measures again. We'll come back to that.
So, clause 11.8.1, first sentence says you can test end-to-end or in parts. And then the second sentence says, if you're going to need to test while the plant is online and running, you need to design in the test facilities, the equipment, to allow this test to be able to happen while you're online and running.
So, there's more coming up in 11.8.2 and 11.8.3 on what these additional, what the additional equipment is. What do we mean by these online test facilities?
## Overlap Requirements When Testing in Segments
So, now, before we leave clause 11.8.1, a little bit of stress needs to be placed on designing your tests if you're testing in segments, if you're doing a partial test. Now, this stress occurs in part two of the standard, which is the informative best practices, additional explanation, and so on. And it's not shown in clause 11.8.1. Maybe a note in clause 11.8.1 should be even in part one because when you're testing in parts, you're playing a little bit of a dangerous game. What do I mean by that?
Well, I know when I test my sensor that the sensor works. I know when I test my logic solver that the logic solver works. I know when I test my final element that my final element works. But how do I know that the signal is going to get from the process fluid, through the sensor, through the logic solver, through the final element to the process fluid, on the final element side. In order to do that, there needs to be some degree of overlapping in the testing.
So, let me give you a good example. When you're testing a pressure transmitter, your sensor, you're going to want to make sure that that signal gets into the logic solver. It gets through the logic solver. So, you're actually going to be testing some portion of the logic solver while you're testing the sensor. So, it's not enough just to pump up the transmitter to 50%, see that it's reading 12 milliamps, pump it up to 100%, make sure that it's reading 100 milliamps. Listen to me. 20 milliamps. Okay? All you're testing there is the electronics of the sensor.
You're not testing the signal wiring between the sensor and the logic solver.
You're not testing the logic solver's input card, the A to D conversion. You're not testing the logic on what is the set point that's in the logic solver consistent with what our expectations are, what the documentation is. Okay. So, we're going to want to shoot that signal into the logic solver and check the signal process aspects of the logic solver and probably even the activation of the shutdown signal, which, of course, you can trap with a bypass. That's part of those online test facilities that I was discussing.
And this kind of goes back to the discussion that we had in the last podcast about the maintenance and engineering interface, about how we should still be showing alarms indicating that we have tripped, even if we're in bypass. And the purpose of that is to confirm that the SIS is going to attempt to perform a shutdown. So, we're kind of testing that functionality of the logic solver when we're doing this. So, that's a good comprehensive test of the input. And, of course, you tested a portion of the logic solver.
Now, when I'm testing the logic solver, this is something where you're going to want to, if you can, you're going to want to manipulate input signals. You're going to want to test the program comprehensively. You're going to want to power up. You're going to want to power down. Make sure we go through our whole boot sequence. It's a pretty stressful thing.
A lot of people bring their equipment vendors in to help them with the logic solver tests and maybe even take that logic solver application program and put it into the test system to make sure that all of the logic is executing properly by simulating inputs and looking at the outputs. A lot of this can be done automatically with automatic test systems to make sure that that's occurring. And all of those types of activities, you're also going to want to do at the final element subsystem.
You're going to want to make sure that the logic solver triggers a shutdown command, but you can put the logic solver or the final element subsystem into a state where it won't respond to the demand of the safety instrumented system to prevent that production outage from occurring.
So a key to testing in parts is that you're really going to want to spend a lot of time. You're going to want to spend a lot of effort to make sure that when you do this test, that any dangerous failure in any portion, any subsystem of the SIS will be detected. Again, always thinking about what are the potential failure modes of all of our subsystems and making sure that our tests or our battery of tests, if we're going to test in parts, is going to allow for all of those dangerous failure modes to be detected.
So I can't stress enough how important it is when you're writing your test plans to have that list of the failure modes. What can go wrong in not just the instruments themselves, but the process connections, the interface devices, the wiring, the communication cards, the input cards, the output cards, the valve itself, the actuator, the solenoids, the positioners, every tiny subsystem you need to analyze thoroughly to identify what are all the failure modes and make sure that your test will identify those failure modes if they're present.
So a good degree of overlap between your subsystems is going to be absolutely essential when you're performing your tests to make sure that those tests are going to be done safely and that they're going to achieve that ultimate objective of 100% manual proof test coverage. Every failure mode that you can possibly envision, you're going to test to make sure that that failure mode is not present when you're doing your testing. Okay, so that's Clause 11.8.1.
## Clause 11.8.2: Test Facilities as Integral SIS Design
Now let's move on to Clause 11.8.2. So Clause 11.8.2 states, When online proof testing is required, test facilities shall be an integral part of the SIS design. Okay, this clause has a lot of weight to it. It requires a lot of you that you may not have thought about.
So let me give you some horror stories. I'm going to kind of, you know, expand this. And even right now, I'm looking at what's left in Clause 11.8. And I've already made the determination that I'm going to have to break this into two podcasts because there's just simply too much here to go through in one episode. So test facilities shall be an integral part of the SIS design. All right, putting this another way,
I want the ability to bypass my safety instrumented system to allow tests to occur to be an elegant built-in part of the safety instrumented system. Allowing for bypass of the safety instrumented system elegantly in an engineered process in a way that it is automatically tracked and those bypasses are then managed through a management of change system is absolutely essential.
If you don't design your safety instrumented system to be bypassed elegantly, does that mean people are just not going to bypass it? Don't kid yourself. Where there's a will, there's a way. If somebody's job is to get the safety instrumented system tested and the system has not been designed to allow it, they will figure out a way. And you know what? The way that they're going to figure out to perform these tests is something that you're probably not going to want.
So if you don't design in the mechanisms, either the test is not going to happen at the required test interval or you're going to use ad hoc bypassing methods that are easily forgotten and left in place. And you know, you're setting up the corporate philosophy. You are allowing everyone to use unofficial methods to put things into bypass, which is not something that you want to do in your plant.
Just from a design philosophy, a safety philosophy, you know, the safety philosophy of the organization should not be one where it's okay to jury rig bypasses to allow testing to occur. Okay. So let me go back and…
## Oil Refinery Horror Story: Ignored Test Requirements
Southern United States oil refinery. I am called in to do some consulting for this oil refinery because they paid a high-priced consultant to do a bunch of safety instrumented system design. And this high-priced consultant gave them a beautiful three-ring binder chock full of paper that the engineering team promptly proceeded to just throw up on the shelf and, you know, go about their business.
This consultancy also recommended some very expensive partial stroke testing devices be applied to all the shutoff valves on every safety instrumented function in this plant. Okay. I get called in because the new SIS engineers kind of going into a little panic. And they said, you know, can you come out here and talk to me and, you know, give a presentation to my maintenance technicians and the, you know, the rest of the instrumentation and control engineering group. And during this presentation, they busted out their design basis documents, this three-ring binder from the consultancy.
And I said, okay, so you installed this new safety instrumented system as designed here. And they said, well, no, no, no, no, we didn't. Because all of those two out of two, fancy two out of two D solenoid valve systems, we didn't install those. We just have regular one out of one three-way solenoid valves.
Because when we were in the process of installing the two out of two that included partial stroke testing, so two out of two SOVs with a fancy partial stroke testing mechanism, they explained to the operators how once a week, automatically the valve, the shutoff valve is going to partially go closed and then it's going to open itself back up. And the operators, the operators didn't say no. The operators said, oh, hell no. So there was an operations veto on the whole concept of partial stroke testing. And of course, you know, this was included in the SIL verification calculation.
So I'm like, okay, well, we're going to need to redo all your SIL calcs to reflect your actual as-designed plant. So you did everything else in the design other than the actual design of the plant, yes? Or the actual SOVs, yes? It matches. Sure. Yep. Absolutely. Okay. So have you written your test plans and in your maintenance management system, have you incorporated the test intervals that are required as per the calculations?
And everyone kind of looks at everyone else and they're like, well, we haven't written test procedures because the turnaround's not going to happen for another three years. What could possibly go wrong? So, you know, maybe six months out from when we're actually going to do the turnaround, we will write our test procedures. I'm like, okay. Pop open the calculation. The first safety instrument or function that I look at had quarterly tests of the sensors, tests of the final elements every six months, and tests of the logic solver once per year.
And I'm like, did you know that you're supposed to be testing your sensors according to this report every three months? And, you know, everyone's, you know, the person that contacted me that was most concerned about this just went white as a ghost. Completely pale. Kind of, you know, mentally in panic mode. Everyone else is just kind of looking around, confused, like, who made that decision? Who said that was okay? And they're like, well, we were only planning on testing once every turnaround.
And for this unit, the turnaround doesn't happen, but once every four or five, or they're trying to stretch it out to six years. Now, this was 2006, 2007 timeframe. So a long time ago. They've been stretching those test intervals more and more ever since. So everyone's kind of angry, confused, disinterested, panicked. You know, I got the full range of people in the room. You know, some people are like, what, this is, all of these fancy calculations are a bunch of bull crap anyway. I don't believe in them. We've been testing once a turnaround since the, since the 50s.
You know, there's some of that attitude and then there's, you know, other attitudes of, well, the calculations say this, so we have to do what the calculations say.
Ultimately, I was able to rerun the calculations at four years and all of the safety instrumented functions achieved their SIL targets. So most of these safety functions, as you would expect in an oil refinery, were SIL one, a handful of SIL twos, mostly SIL ones, fully capable of achieving their risk reduction factor of 10 at a test interval of four or five years, whatever, whatever the calculation showed. And the person that I was talking to kind of breathed the sigh of relief. And they're like, well, why did the consultant use these test intervals?
And why did they recommend all this partial stroke testing equipment? Well, I'm not going to get into why they recommended the partial stroke testing equipment. Let's just say maybe somebody had a conflict of interest. There was some financial rewards. I'll just leave it right there. But hey, I guess the other big lesson here is you people at the operating company, you know, caveat emptor, buyer beware, you're operating, you're maintaining your plant, you need to be involved in the design.
Now, sure, shame on the consultant for not getting your buy-in and explaining what the issues are related to test intervals. But it shouldn't have gotten this far. So, I guess in this case, they found out that they needed to test much more frequently than their turnaround and they didn't have the proof testing facilities. So, they didn't have the bypasses of the sensors. They didn't have the bypasses of the final elements. They didn't have the logic solvers.
## Implementing Sensor and Final Element Bypass Facilities
So, bypassing on the sensor side is usually fairly straightforward because it can be done by programming in a PLC. You know, the days of having a switch that basically shorts power around the field switch are gone. We're doing most of this stuff in the logic solver, which is a very good design for bypassing of sensors because if it happens in the logic solver, it's easy for us to send that information to the operator by way of alarm. It's easy for us to send that information into the historian.
It's easy for us to export data out of the historian into something like Power BI where I can keep track of who's putting stuff into bypass, how long is stuff in bypass, have the things that have gone into bypass been approved to be bypass by comparing that against our management of change system. So all of that is relatively straightforward.
Now, where we get into issues with test facilities is going to be if we need to do a full stroke test of a valve while the plant is online and running or if we need to be able to do a stopping a pump. So activation, de-energization of a motor starter. And between those two, that's like 99.99% of final elements in the process industry. So in those cases, we need to create test and bypass facilities that are going to require the involvement of other groups beyond the instrumentation and control group.
So that means we're going to need to involve people from piping, the pipe fitters, the boilermakers. We're going to need to involve maybe insulation, heat tracing, a lot of additional equipment, and then maybe we might need to also include information in the control system that allows you to keep track of these bypasses. So this additional test and bypass facility information is going to be discussed in clause 1183.
So
1182, when online proof testing is required, test facilities shall be integral part of the SIS design. So we need to think about it during the design process. We need to implement the equipment during the design of the plant. It's not okay to wait for the next turnaround because your calcs might have shown that you needed to test it two, three, four times in between turnarounds, depending on who did the calculation and what their design assumptions were.
Okay, so clause 1183 talks a little bit more about what those test and bypass facilities need to be, what you need to think about, what the different things that you may need to include in the process.
## Clause 11.8.3: Bypass Facility Conformance Requirements
So clause 1183 has one sentence and then two bullet points of one sentence each. So 1183 begins, when test or bypass facilities are included in the SIS, they shall conform with the following. Okay, so if I need online testing facilities, I need to install equipment to allow me to test the SIS, they need to conform with the following two bullet points.
Bullet point number one, the SIS shall be designed in accordance with the maintenance and testing requirements defined in the SRS. So, when I'm writing my test plans, I need to meet the requirements of the SRS. And the SRS is, again, it's the detailed design of the plant, so it's going to include what are all the test intervals, what are the common cause considerations, what is the process safety time, what is the response time of the SIF, and the way I've always done it, we're going
*[inaudible]*
know the response time of each SIF element as opposed to the SIF as a whole, making sure that the sum of all the elements is less than the maximum equipment response time in the next version of the standard or the process safety time in this version of the standard.
Okay, so think about, you need to think about what all that equipment is that needs to be included in the design to allow the testing to occur. And it's not just process equipment, but maybe you need to think about do I have calibration devices, do I have hand pumps, what other equipment is required to isolate my instrumentation from the process and simulate process conditions and verify that actions are happening.
So signal simulators, hand pumps, stopwatches, these are all things you need to consider in the design phase. Now, sometimes you might be able to make up for the fact that you didn't think about these things while you're doing, performing your test, run out to Walmart and get yourself a stopwatch, but sometimes it's too late. So please think about this during the design process. Okay, bullet one, the SIS shall be designed, oh, I just said this, the SIS shall be designed in accordance with all of what is in the SRS. The big proponent there, the big key number there is test interval.
## Operator Alerting and Full-Stroke Test Scenario
Bullet point number two, the operator shall be alerted to the bypass of any portion of the SIS via an alarm or operating procedure. That is big and that is key. So the operator needs to be alerted to the bypass of any portion of the SIS via an alarm or operating procedure.
Let's pull on this for just a second. So let's say I am doing an elaborate test where I need to do a full stroke test while the plant is online and running. why would I need to do a full stroke test while the plant is online and running? Well, guess what? This is happening more and more and more frequently. Operating plants do not want to shut down once every five. They're trying to stretch that major turnaround to six, seven, eight, nine, ten years of continuous operation without shutting down the plant.
valves have already been a weak point in this process because they are definitely valves. You know, if you've taken my EC50 training class or any training class I've ever given, I will always tell you that the final element subsystem is the most likely location to get a failure and as a result, it's the thing that you need to test the most in order to achieve higher sills or achieve longer proof test intervals. So if I want to go ten years between turnarounds, there's no way, no way you can do that without doing a full stroke test while the plant is online and running.
So this is happening more and more frequently and people are getting a little bit more cognizant about things like valves leaking. Now, there's a whole other discussion and please go to the Kenexis website and look for leak testing requirements for SIS. It's a one and a half hour webinar I gave simply on the topic of leak testing requirements for valves and a lot of people overblow the spec and say everything needs to be tight shut off but then they turn around and never test for it. So if your valve actually does need to be tight shut off, you need every time you
*[inaudible]*
test the valve confirm that a tight shut off has occurred and that is impossible while the plant is online and running unless you have elaborate test facilities.
So what do those test facilities look like? Those test facilities are going to include a full diameter bypass around your shut off valve. You're going to need isolation valves upstream and downstream of your shut off valve with a bleed valve that's capped. You're going to need a bypass valve, full port, full diameter bypass valve around your shut off valve with a gate valve upstream, a gate valve downstream, and a bleed mechanism to be able to bleed off pressure along with pressure gauges to make sure that you've bled off the pressure, therefore your bypass valve and your shut off valve.
So all that kit is going to be required.
But now all that kit is out in the field. So let's get back to the mechanism for testing this valve, a full stroke test. What do I need to do? I'm going to need to go out to the field. I'm going to need to open my block valves that have isolated my bypass valve. I am going
*[inaudible]*
open my bypass valve so I've got a full flow. Then I am going to need to slowly crank down, usually on the upstream valve, upstream of the shutoff valve. It's usually going to be a gate valve. Sometimes you use glow valves, there's a lot of different options. But you're going to want to close off that upstream valve. And then once it's closed off, now you've got your full flow going through that bypass valve and we are in a dangerous state.
So we're going to need to think about compensating measures because our final element is no longer working. So compensating measures all coming up in the next podcast. Now, so I isolate upstream, I isolate downstream, and then I'm going to bleed off the material in that valve. And if you need to test for tight shutoff, you're going to need to put in maybe an upstream and a downstream vent to allow you to pressure up the upstream side of your closed valve, look at the pressure gauge, make sure that it doesn't leak.
But at a minimum, you're going to need to stroke this valve and make sure that it strokes within the process safety time when you command it.
Okay, that's a lot of equipment. And all of what I just described happens out in the field.
## Bypass Management: Alarms, Permits, and Authorization
so clause 11.8.3, the second bullet, makes it clear that if you're bypassing any portion of the SIS, you need to let the operator know.
Now, most of the time when you're bypassing, you're going to bypass a sensor, and it's probably going to be the operator who activates the bypass in the first place. bypass. So when the operator is activating the bypass, obviously they know. Still, it's a good practice to have an enunciated alarm to confirm that you put the device into bypass, and then that alarm is going to get registered with the historian so you have a record of when the device was put into bypass, who put it into bypass, etc. Now, what if the operator doesn't physically activate the bypass?
Well, the operator still needs to know.
Now, the most low brow way of doing this is, okay, so that clause again says the operator shall be alerted to the bypass of any portion of the SIS via an alarm or procedure. So that's the second bullet until 11.8.3. So the operator needs to know about the bypass, and if you can trigger an alarm, that's a best practice. That's what I would like to see.
That's what I want you to do, because you're generating an alarm log, and you can compare that bypass alarm log against bypass authorizations to make sure that everything was done elegantly and that nobody is abusing bypasses by putting stuff in the bypass without going through the authorization process. Okay, so we've got those things that we can trigger automatically if you're in the DCS, but what if you're in the field?
Well, even if you're in the field, you can automatically generate alarms. So for a sensor, you might have a switch out in the field, and then you'll have a hand switch that's basically going to short power around that switch. Well, for
> *[inaudible, 0:52:49 – 0:52:56]*
you have out in the field, you can make it a throw, where one set of contacts activates other set of contacts simply brings a signal into the safety PLC saying that you've put that device in the bypass, and you can alarm against that.
Similarly, that full diameter bypass valve that's out in the field, you can do the same thing. you can put a limit switch on
*[inaudible]*
says, if my closed contact switches break, then set an alarm saying that my bypass valve is no longer closed, and that would generate an alarm. That's a possibility. Now, those bypasses, alarms, are not required because if you read the clause again, it says that the operator shall be alerted via an alarm or operating procedure. So, I would argue that the best practice is for that alarm to be there, but it doesn't actually have to be there.
You can replace that alarm with an operating procedure. Now, any well-run plant is going to follow a authorization to work system. So, work permits need to get generated for anything that happens out in the field. Any job is going to require a work permit, and that work permit is going to include a job safety assessment. It's going to include reviews. It's going to include discussions. It's going to include authorizations, and one of those authorizations is going to have to be the operator who is controlling that plant.
So, in your work authorization process, anytime you're performing a test, that discussion of what you're doing should reside in that work permit, and that work permit should be signed off by the operator. So, that's a fully allowable process.
So, if you're not going to put those limit switches on field-activated bypasses that are going to automatically generate an alarm, then you're going to want to make sure that your permit-to-work system is tight in that if any activity is going to put something into bypass, then that is automatically going to show up on a work permit system that the operator has to sign off on. And the other thing that you'd want to consider is if you have field-located bypass devices that do not trigger an alarm, you're going to want them car-sealed.
## Car-Sealing and Physical Bypass Controls
So, car-sealing is a whole topic in and of itself. Car-sealing basically is use of some sort of physical device and physical tagging system system that clearly indicates that there is a safety critical device that shouldn't be moved without proper controls.
So, what would you do, for instance, for a two-position switch out in the field that's going to jump power around the process switch? Well, you would probably want to have a cover over top of the switch with a locking mechanism. And maybe you might want to use a physical lock. Generally, that's considered a bit of overkill. Most of the time, you're just going to use a cable tie. So, you know, one of those zip cable ties to kind of cable tie it shut, which, of course, you know, if you have a pair of wire cutters, you can just put that cable tie and free it.
but you're going to want to zip tie the box shut and you're going
*[inaudible]*
attach a tag to it, indicating that this device is car sealed into the non-bypass position. And then that's going to indicate to anyone that, okay, if I'm going to put this into bypass, I need to follow a management of change procedure and I need to get authorization. Similarly, you can put a car seal of a similar quality on that manual valve that allows you to do the bypass.
So, best practice, wire everything through alarms that get enunciated. And even if
*[inaudible]*
that, you're still going to want a really good, tight management of change process and permit to work process.
But if you're not going to have those automatic alarms indicating that you put things into bypass, then permit to work is essential and you're going to want to supplement that permit to work system with a car seal system that's going to make it difficult at a minimum without tools to move one of those safety critical devices into the bypass position. And then also that car seal system, it's not enough just to seal it and tag it.
once a week, best practice, maybe once a shift, maybe once a month, you're going to want to go out to the field and have a list of everything that's supposed to be car sealed and make sure that it's in its proper position. All right, so with that, we've gone pretty much an hour at this point in time and I've only gotten through clause 11.3. So, I'm going to have to come back at you next week with clauses 1184 through 1186, rounding out and completing clause 11.8. Talk to you then.
## Vertigo Software for SIS Lifecycle Management
Now that you've heard some insights on technical safety, functional safety, and the IEC 61511 standard, let me tell you a little bit more about how to easily and effectively implement the safety lifecycle using the Kenexis Integrated Safety Suite and our SIS Safety Lifecycle Management Tool, Vertigo.
Vertigo is a comprehensive tool set for performing assessment calculations, documenting, and maintaining the design of safety instrumented systems. Analysis begins with importing or synchronizing a list of safety instrumented functions with their definitions and associated performance targets from our open PHA tool for HAZOP and LOPA documentation.
Each safety function can then be analyzed by performing a SIL verification calculation, complete with a collection of tools for optimizing designs and a database of thousands of potential instruments to define failure rates and diagnostic coverage capabilities.
After the SIL verification calculations are defined, you can build an SRS by automatically generating a cause and effect diagram from the SIF definitions and other defined instruments. Each SIS instrument will include a customizable data sheet and general requirements that are applicable to the SIS as a whole and can be entered individually or even bulk imported from customizable libraries.
After the design phase, you can even use Vertigo to track and document testing throughout the entire life of the facility. Kenexis Vertigo is the most integrated, easy-to-use enterprise tool for allowing the development of SIS design basis information more efficiently and effectively than any other software application. Thank you.