2
018-
03
14
Functional Safety KFD2-VR4-Ex1.26
Operation
5
Operation
Operating the device
1. Observe the safety instructions in the instruction manual.
2. Observe the information in the manual.
3. Use the device only with devices that are suitable for this safety application.
4. Correct any occurring safe failures within 8 hours. Take measures to maintain the safety
function while the device is being repaired.
5.1
Proof Test
According to IEC/EN 61508-2 a recurring proof test shall be undertaken to reveal potential
dangerous failures that are not detected otherwise.
Check the function of the subsystem at periodic intervals depending on the applied
PFD
avg
in accordance with the characteristic safety values. See chapter 3.4.
It is possible that the device is used under other circumstances than specified within
the assumptions for the FMEDA assessment. The calculations for the safety loop can also
reveal that the device can claim a different amount of the PFD value (standard is 15 %).
Both effects can have an influence on the proof test interval.
The proof test detects dangerous undetected failures that can affect the safety function
of the plant.
It is under the responsibility of the plant operator to define the type of proof test and the proof
test interval. Do not exceed the proof test interval of a maximum of 3 years.
The following sections describe the steps of the proof test. The proof test reveals almost
all possible dangerous faults (diagnostic coverage > 90 %).
The ancillary equipment required:
•
Digital multimeter with an accuracy better than 0.1 %
For the proof test of the intrinsic safety side of the devices, a special digital multimeter
for intrinsically safe circuits must be used.
Intrinsically safe circuits that were operated with non-intrinsically safe circuits may not
be used as intrinsically safe circuits afterwards.
•
Power supply set at nominal voltage of 24 V DC.
•
Apparatus suitable for generating the signals for test B.
•
Load of 2.1 k
and 1.8 k
for the input, 10 k
for the output.
Danger!
Danger to life from missing safety function
If the safety loop is put out of service, the safety function is no longer guaranteed.
•
Do not deactivate the device.
•
Do not bypass the safety function.
•
Do not repair, modify, or manipulate the device.