![Allen-Bradley AADvance T9110 Safety Manual Download Page 112](http://html1.mh-extra.com/html/allen-bradley/aadvance-t9110/aadvance-t9110_safety-manual_2900165112.webp)
112
Rockwell Automation Publication ICSTT-RM446N-EN-P - April 2018
Chapter 5
Checklists
Functional Requirements Checklist
Safety Requirements Checklist
Description
Yes/No
Is the definition of each of the required functions complete?
Are the interfaces, signals, and data associated with each function clearly identified?
Where a 'tag referencing' scheme is used for these signals, has a summary description of the naming
convention been provided to facilitate an understanding of the role of the signal?
Have the performance requirements for each function, or collective functions, been defined?
Have the operating modes of the EUC, process or plant been clearly defined?
Have the functions required to operate in each plant operating-mode been identified?
Have the transitions between each plant operating-mode been defined? Have the functions
necessary to affect these transitions been established?
Description
Yes/No
Have all of the functional requirements been allocated a required safety requirements class?
Has the safety-related timing for each safety-related function, including process safety time (PST)
and fault tolerance period, been established?
Have the safety requirements been approved?
Are there clear definitions of the external interfaces involved in each of the safety-related functions?
(These may already be defined in the functional requirements).
Is there now sufficient information to understand how the plant should be controlled safely in each
of its intended operating modes?
Are the AADvance System Build Manual installation instructions available for installing and
commissioning the system?
Does the application program shut down the SIL 3 safety instrumented functions if a faulty module
has not been replaced within the MTTR assumed for the system in the PFD calculations?
Have the application programs been set up to monitor the "discrepancy alarms" and alert the
operators when a discrepancy alarm occurs?
Do the energize to action configurations conform to the restrictions (defined in this safety manual)
that should be applied when using these configurations?
Have the Controller System Security Measures been set up and observed?
Have the Communication Port security measures been set up and observed?