A field engineer's critique of "SIL is Necessary for Process Safety, But it is Not Sufficient!" from instrumentationtools.com
SIL Is One Layer, Not the Whole Cake
The original article makes a point that every SIS engineer should tape to their monitor. A Safety Instrumented System is just one protection layer among many. IEC 61511, LOPA, and the bowtie model all show the same truth. First, basic process control keeps the plant stable. Second, alarms give operators a chance to intervene. Then, and only then, does the SIS trip the plant. Relief valves, dikes, and fire and gas systems follow. Therefore, a SIL 3 certificate on your logic solver says nothing about the stuck relief valve downstream. I once audited a compressor train with a perfectly verified SIL 3 loop. However, its fire and gas detectors had never been function tested. The risk gap sat outside the SIS, invisible to the SIL calculation.
Moreover, the article rightly warns against expecting miracles from SIL math. PFDavg is a statistical average, not a guarantee. It assumes proof tests happen on schedule and repair times match the site data. In real plants, both assumptions break often.
Verifying PFDavg on a Triconex Trident: The Steps That Matter
Take a typical high-high pressure trip on a separator. The loop uses a Triconex Trident, a 2oo3 voted pressure transmitter pair, and a de-energize-to-trip solenoid. Here is how I run the verification in practice.
- Step 1: Pull the failure rate data from the SIL 2 safety manual of each device. Check the dangerous undetected (DU) failure rates, not just the certificate.
- Step 2: Set the proof test interval honestly. A 12-month test on paper often becomes 18 months in the field. Therefore, run the calculation at the worst case, not the plan.
- Step 3: Confirm the Trident voting and diagnostic coverage in TriStation 1131. Enable extensive diagnostics on each I/O card. Record the achieved diagnostic coverage in your safety requirement specification.
- Step 4: Check de-energize-to-trip wiring end to end. Verify that each output channel opens the solenoid with a single channel failure. Never trust the schematic alone. Pull the fuse and watch the valve move.
- Step 5: Document the mean time to repair. If your site holds no spares, your restoration time kills your PFDavg faster than any transmitter failure rate.
Second, pay attention to common cause failures. The Trident's TMR architecture tolerates random hardware faults well. However, shared power supplies and shared impulse lines can defeat all three processors at once. Beta-factor analysis is not optional paperwork.
HIMA HIMax Practice Points
I apply the same discipline on HIMA HIMax projects. The HIMax X-CPU 01 controller supports SIL 3 applications with a clear safety manual. Moreover, its online modification capability lets you download changes without a full shutdown. That feature tempts plants into sloppy management of change. Therefore, I require a frozen application version and a signature sheet before any online download. In addition, set the SILbert-based parameter set for each I/O group. Mixing SIL 2 and SIL 3 channels on one card without justification is an audit finding waiting to happen. Finally, use the HIMA diagnostics in SILworX to trend fault messages. A rising count of module disturbances often predicts hardware drift months before a hard failure.
Field Failures That SIL Math Misses
The article hints at these, so let me name them bluntly. Impulse line plugging creates silent transmitter failure on dirty services. Solenoid valves seize after years without cycling. Bypass switches stay in service long after the work order closed. Moreover, partial stroke testing helps valves, but only if the test actually moves the element. I have seen partial stroke setups that stroked the positioner feedback, not the plug. Therefore, walk down every bypass and force log quarterly. Compare the force list against active work orders. A bypass without an owner is an unmanaged risk, no matter what your SIL certificate says.
Conclusion & Action Advice
SIL ratings are necessary, yet never sufficient. They quantify one layer of a larger defense system. First, verify your PFDavg with honest test intervals and repair times. Second, treat common cause failures and bypasses as live risks, not footnotes. Moreover, audit the layers around the SIS with the same rigor as the SIS itself. Therefore, schedule a protection layer review this quarter. Finally, remember that real safety lives in disciplined field execution, not in certificate folders.