7.3
Lifetime of Critical Components
According to Section 7.4.9.5 of IEC 61508-2, a useful life-
time, based on experience, should be determined and used
to replace equipment before the end of useful life.
Although a constant failure rate is assumed by the exida
FMEDA prediction method, this only applies provided that
the useful lifetime* of components is not exceeded. Beyond
their useful lifetime, the result of the probabilistic calcula-
tion method is likely optimistic, as the probability of failure
significantly increases with time. The useful lifetime is
highly dependent on the subsystem itself and its operating
conditions.
Table 8 shows which components are contributing to the
dangerous undetected failure rate and, therefore, to the
PFDavg calculation and what their estimated useful
lifetime is.
It is the responsibility of the end user to maintain and oper-
ate the 961/962 per manufacturer’s instructions.
Furthermore, regular inspection should show that all com-
ponents are clean and free from damage.
The limiting factors with regard to the useful lifetime of the
system are the aluminum electrolytic capacitors. Therefore,
the useful is predicted to be 10 years.
For high demand mode applications, the useful lifetime of
the relays is limited by the number of cycles. The useful life-
time of the relay is > 100,000 full scale cycles or 8 to 10
years, whichever results in the shortest lifetime.
When plant/site experience indicates a shorter useful life-
time than indicated in this appendix, the number based on
plant/site experience should be used.
*
Useful lifetime is a reliability engineering term that describes
the operational time interval where the failure rate of a
device is relatively constant. It is not a term which covers
product obsolescence, warranty, or other commercial issues.
23
51-650 Model 961/962 Echotel SIL Safety Manual
Component
Useful Life
Capacitor (electrolytic) — Aluminum electrolytic, non-solid electrolyte
Approximately 90,000 hours
Table 8
Useful lifetime of components contributing to dangerous undetected failure rate