background image

13

Pressure Transmitter Series 2000T and 265Ax, 265Gx, 265Vx, 265Dx, 265Jx, 267Cx, 269Cx

SM 265/7/9 SIL-EN

Instructions for Functional Safety

©

exida.com

GmbH 

abb 03-09-13 r001 v1 r1.2, March 1, 2004 

Stephan Aschenbrenner 

Page 3 of 11 

For safety applications only the 4..20 mA output was considered. All other possible output 
variants or electronics are not covered by this report. The different devices can be equipped 
with or without display. 

The failure rates used in this analysis are the basic failure rates from the Siemens standard 
SN 29500. 

According to table 2 of IEC 61508-1 the average PFD for systems operating in low demand 
mode has to be 

t

10

-3

 to < 10

-2

 for SIL 2 safety functions. A generally accepted distribution of 

PFD

AVG

 values of a SIF over the sensor part, logic solver part, and final element part assumes 

that 35% of the total SIF PFD

AVG

 value is caused by the sensor part. For a SIL 2 application the 

total PFD

AVG

 value of the SIF should be smaller than 1,00E-02, hence the maximum allowable 

PFD

AVG

 value for the sensor part would then be 3,50E-03. 

The pressure transmitter 2600T / 2000T Series with 4..20 mA output is considered to be a Type 
B

1

 component with a hardware fault tolerance of 0. 

Type B components with a SFF of 60% to < 90% must have a hardware fault tolerance of 1 
according to table 3 of IEC 61508-2 for SIL 2 (sub-) systems. 

As the pressure transmitter 2600T / 2000T Series with 4..20 mA output is supposed to be a 
proven-in-use device, an assessment of the hardware with additional prior-use demonstration 
for the device and its software was carried out. The prior-use investigation was based on field 
return data collected and analyzed by ABB Automation Products GmbH. This data cannot cover 
the process connection. The prior-use justification for the process connection still needs to be 
done by the end-user. 

According to the requirements of IEC 61511-1 First Edition 2003-01 section 11.4.4 and the 
assessment described in section 5.1 the Type B pressure transmitter 2600T / 2000T Series with 
a hardware fault tolerance of 0 and a SFF of 60% to < 90% is considered to be suitable for use 
in SIL 2 safety functions The decision on the usage of prior-use devices, however, is always 
with the end-user. 

Failure rates that are assigned to the various failure modes of the sensor part of the pressure 
transmitter 2600T / 2000T Series were obtained from field failure data using only operational 
hours from the warranty period of operation. Confidence Interval calculations were done using a 
chi-square distribution and an upper limit failure rate based on a 70% confidence factor per 
IEC 61508. The failure rate results were compared with industry databases [N6] and found to be 
within a reasonable range considering the much higher amount of operational hours. 

Assuming that a connected logic solver can detect both over-range (fail high) and under-range 
(fail low), high and low failures can be classified as safe detected failures or dangerous detected 
failures depending on whether the pressure transmitter 2600T / 2000T Series with 4..20 mA 
output is used in an application for “low level monitoring”, “high level monitoring” or “range 
monitoring”. For these applications the following tables show how the above stated 
requirements are fulfilled. 

                                                

Type B component: 

“Complex” component (using micro controllers or programmable logic); for details 
see 7.4.3.1.3 of IEC 61508-2. 

Summary of Contents for 265Ax

Page 1: ...SIL Safety Instructions SM 265 7 9 SIL EN Rev 02 Pressure Transmitter Series 2000T and 265Ax 265Gx 265Vx 265Dx 265Jx 267Cx 269Cx Instructions for Functional Safety ...

Page 2: ...s 3 3 Acronyms and abbreviations 3 4 Relevant standards 4 5 Terms and definitions 4 6 Determination of the Safety Integrity Level SIL 4 7 Specifications for the safety function 6 8 Applicable device documentation 6 9 Behavior during operation and in case of malfunction 6 10 Periodic checks 6 11 Settings 7 12 Safety related characteristics 7 13 SIL conformity declaration 9 14 Management summary 11 ...

Page 3: ... function failures occurring on demand PFDav Average Probability of Failure on Demand This is the average likelihood of dangerous safety function failures occurring on demand SIL Safety Integrity Level Safety Integrity Level The international standard IEC 61508 specifies four discrete Safety Integrity Levels SIL 1 to SIL 4 Each level corresponds to a specific probability range regarding the failur...

Page 4: ...ment as seen in the illustration below Fig 6 1 Normal distribution of the average probability of failure on demand PFDav over the subsystems Standard Designation IEC 61508 Part 1 to 7 Functional safety of electrical electronic programmable electronic safety related systems Target group Manufacturers and Suppliers of Devices IEC 61511 Part 1 Functional safety Safety Instrumented Systems for the pro...

Page 5: ...ired Safety Integrity Level SIL less than 4 The transmitter meets all requirements Fig 6 2 Safety function e g for pressure limit monitoring with 265DS as a subsystem 1 265DS with local operation option and adjustable lower and upper range value and damping 2 Computer with user interface like SMART VISION for setting all parameters e g alarm behavior max alarm operating mode etc 3 Hand held termin...

Page 6: ...69C 2010TC 42 15 714 For explosion proof devices the respective EC type examination certificate must be available 9 Behavior during operation and in case of malfunction Note The behavior during operation and in case of malfunction is detailed in the operating instructions 10 Periodic checks The operativeness of the transmitter must be checked at appropriate intervals e g by controlling the calibra...

Page 7: ... transmitter control via the local keys after having entered all parameters and after having checked the safety function This is to protect your settings against unwanted or unauthorized modification A lock activated via the local keys can only be deactivated by using the keys again Fig 11 1 12 Safety related characteristics 12 1 Assumptions HART communication is only used for configuring adjustin...

Page 8: ...ngerous and of safe faults λdu Fault rate of undetected dangerous faults The characters in brackets indicate the catalog number for the measuring range Transmitter type Measuring range SFF PFDav λdd λs λdu 265Dx A 265Jx A 10 mbar 75 9 8 54 10 4 614 FIT 195 FIT 267Cx A 269Cx A 10 mbar 76 4 9 43 10 4 699 FIT 216 FIT 265Dx C F L N 265Jx C F L N 265Vx F L N 60 mbar to 20 bar 60 mbar to 20 bar 400 mbar...

Page 9: ...9 Pressure Transmitter Series 2000T and 265Ax 265Gx 265Vx 265Dx 265Jx 267Cx 269Cx SM 265 7 9 SIL EN Instructions for Functional Safety 13 SIL conformity declaration ...

Page 10: ...10 Pressure Transmitter Series 2000T and 265Ax 265Gx 265Vx 265Dx 265Jx 267Cx 269Cx SM 265 7 9 SIL EN Instructions for Functional Safety ...

Page 11: ...anty of any kind and shall not be liable in any event for incidental or consequential damages in connection with the application of the document All rights reserved FMEDA and Prior use Assessment Project Pressure Transmitter 2600T 2000T Series with 4 20 mA output Customer ABB Automation Products GmbH Minden Germany Contract No ABB 03 09 13 Report No ABB 03 09 13 R001 Version V1 Revision R1 2 March...

Page 12: ...dered Table 1 Version overview Type Application Sensor Electronics 265D A 2010TD Differential pressure 10mbar 2 6187 P1 3 2 6195 P1 2 764913_P1 V1 1 265J A Differential and absolute pressure 10mbar 2 6187 P1 3 2 6195 P1 2 764913_P1 V1 2 267C A 269C A 2010TC Mass flow Differential pressure 10mbar 2 6187 P1 3 2 6195 P1 2 764913_P1 9280 039 P1 3 265D C F L N 2010TD Differential pressure 60mbar to 20b...

Page 13: ...use investigation was based on field return data collected and analyzed by ABB Automation Products GmbH This data cannot cover the process connection The prior use justification for the process connection still needs to be done by the end user According to the requirements of IEC 61511 1 First Edition 2003 01 section 11 4 4 and the assessment described in section 5 1 the Type B pressure transmitte...

Page 14: ...er configured fail safe state fail high Failure rates according to IEC 61508 Failure Categories Osd Osu Odd Odu SFF DCS 2 DCD Olow OSd Ohigh Odd 15 FIT 138 FIT 462 FIT 195 FIT 75 10 70 Olow Odd Ohigh Osd 461 FIT 138 FIT 15 FIT 195 FIT 75 77 7 Olow Osd Ohigh Osd 476 FIT 138 FIT 0 FIT 195 FIT 75 78 0 Transmitter configured fail safe state fail low Failure rates according to IEC 61508 Failure Categor...

Page 15: ...Undetected 1 1 Not part 54 54 MTBF MTTF MTTR 118 years 118 years Transmitter configured fail safe state fail high Failure rates according to IEC 61508 Failure Categories Osd Osu Odd Odu SFF DCS DCD Olow Osd Ohigh Odd 16 FIT 167 FIT 516 FIT 216 FIT 76 9 70 Olow Odd Ohigh Osd 516 FIT 167 FIT 16 FIT 216 FIT 76 76 7 Olow Osd Ohigh Osd 532 FIT 167 FIT 0 FIT 216 FIT 76 76 0 Transmitter configured fail s...

Page 16: ...ndetected 1 1 Not part 54 54 MTBF MTTF MTTR 145 years 145 years Transmitter configured fail safe state fail high Failure rates according to IEC 61508 Failure Categories Osd Osu Odd Odu SFF DCS DCD Olow Osd Ohigh Odd 15 FIT 128 FIT 391 FIT 198 FIT 73 10 66 Olow Odd Ohigh Osd 391 FIT 128 FIT 15 FIT 198 FIT 73 75 7 Olow Osd Ohigh Osd 406 FIT 128 FIT 0 FIT 198 FIT 73 76 0 Transmitter configured fail s...

Page 17: ...Undetected 1 1 Not part 54 54 MTBF MTTF MTTR 128 years 128 years Transmitter configured fail safe state fail high Failure rates according to IEC 61508 Failure Categories Osd Osu Odd Odu SFF DCS DCD Olow Osd Ohigh Odd 16 FIT 157 FIT 446 FIT 218 FIT 73 9 67 Olow Odd Ohigh Osd 446 FIT 157 FIT 16 FIT 218 FIT 73 74 7 Olow Osd Ohigh Osd 462 FIT 157 FIT 0 FIT 218 FIT 73 75 0 Transmitter configured fail s...

Page 18: ...ndetected 1 1 Not part 54 54 MTBF MTTF MTTR 50 years 50 years Transmitter configured fail safe state fail high Failure rates according to IEC 61508 Failure Categories Osd Osu Odd Odu SFF DCS DCD Olow Osd Ohigh Odd 15 FIT 125 FIT 1510 FIT 558 FIT 74 11 73 Olow Odd Ohigh Osd 1510 FIT 125 FIT 15 FIT 558 FIT 74 92 3 Olow Osd Ohigh Osd 1525 FIT 125 FIT 0 FIT 558 FIT 74 92 0 Transmitter configured fail ...

Page 19: ...Undetected 1 1 Not part 56 56 MTBF MTTF MTTR 90 years 90 years Transmitter configured fail safe state fail high Failure rates according to IEC 61508 Failure Categories Osd Osu Odd Odu SFF DCS DCD Olow Osd Ohigh Odd 15 FIT 126 FIT 775 FIT 300 FIT 75 11 72 Olow Odd Ohigh Osd 775 FIT 126 FIT 15 FIT 300 FIT 75 86 5 Olow Osd Ohigh Osd 790 FIT 126 FIT 0 FIT 300 FIT 75 86 0 Transmitter configured fail sa...

Page 20: ...Undetected 1 1 Not part 53 53 MTBF MTTF MTTR 144 years 144 years Transmitter configured fail safe state fail high Failure rates according to IEC 61508 Failure Categories Osd Osu Odd Odu SFF DCS DCD Olow Osd Ohigh Odd 15 FIT 116 FIT 386 FIT 222 FIT 69 11 64 Olow Odd Ohigh Osd 386 FIT 116 FIT 15 FIT 222 FIT 69 77 6 Olow Osd Ohigh Osd 401 FIT 116 FIT 0 FIT 222 FIT 69 78 0 Transmitter configured fail ...

Page 21: ...tters of the pressure transmitter 2600T 2000T Series with 4 20 mA output have a PFDAVG within the allowed range for SIL 2 according to table 2 of IEC 61508 1 and table 3 1 of ANSI ISA 84 01 1996 and a Safe Failure Fraction SFF of more than 69 Based on the verification of prior use they can be used as a single device for SIL2 Safety Functions in terms of IEC 61511 1 First Edition 2003 01 A user of ...

Page 22: ...rmation contained herein without notice Printed in the Fed Rep of Germany 05 2007 ABB 2007 ABB Limited Howard Road St Neots Cambridgeshire PE19 8EU UK Tel 44 0 1480 475321 Fax 44 0 1480 217948 ABB Inc 125 E County Line Road Warminster PA 18974 USA Tel 1 215 674 6000 Fax 1 215 674 7183 ABB Automation Products GmbH Schillerstr 72 32425 Minden Germany Tel 49 551 905 534 Fax 49 551 905 555 CCC support...

Reviews: