64
Rockwell Automation Publication ICSTT-RM446N-EN-P - April 2018
Chapter 4
AADvance Functional Safety System Implementation
presence of a fault during this period, the system will continue to be able to
respond when configured in a fault tolerant arrangement.
When a module is operating in a dual mode (or is degraded to a dual mode)
and a state or value discrepancy occurs, then if no module fault is detected, the
state or value reported to the application will always be the lower of the two
states or values for a digital and analogue input module configurations.
ATTENTION:
When a channel is not capable of reporting a value within the
safety accuracy specified for the module, 'safe' values are reported instead.
Thus, an I/O channel fault condition results in a fail-safe state.
ATTENTION:
The maximum duration for single-channel operation of I/O
modules depends on the specific process and must be specified individually
for each application:
•
Input modules can operate in a simplex arrangement without time limit
for SIL 3 and lower applications.
•
Faulty Output modules must be replaced within the MTTR used for PFD
calculations.
•
Faulty Processor modules must be replaced within the MTTR used for the
PFD calculations.
•
Unless compensating measures are defined in the Safety Requirements
Specification (SRS) and documented in operating procedures, the
application program must be designed to shut down safety
instrumented functions if a module failure due to a dangerous fault has
not been replaced within the MTTR.
ATTENTION:
In safety applications channel discrepancy alarms shall be
monitored by the application program and used to provide an alarm to plant
operations personnel.