40
Rockwell Automation Publication 1715-RM001A-EN-P - June 2019
Chapter 4
Using 1715 Hardware in a ControlLogix SIL 2 System
Energize-to-Action
Energize-to-action configurations can be used only if the following apply:
• At least two independent power sources must be used for both the system
and field supplies. (four total) The system provides the power supply
monitoring, but this needs to be connected in the application. You must
write application code that monitors the diagnostics for the power
supplies. These power sources must provide emergency power for a safe
process shutdown or a time span that is required by the application.
• Each power source must feature power integrity monitoring with safety
critical input read-back into the system controller or implicit power
monitoring that is provided by the I/O modules. Any power failure must
trigger an alarm.
• Unless provided implicitly in the I/O modules, all safety-critical inputs
and outputs must be fitted with external line and load integrity
monitoring and safety-critical read-back of the line-status signals. Any line
or load failure must trigger an alarm.
– See
for more information on using external line devices,
aka End- Of-Line devices.
• The application program must be designed to shut down energize-to-
action SIL 2 safety instrumented functions if a faulty adapter or output
module has not been replaced within the mean time to restoration
(MTTR). That is, you cannot run on one adapter or output module for
longer than the MTTR.
• You as the customer decides on the value of MTTR. Two typical values are
8 hours or 10 hours but you must determine the proper value for your
application.
• For SIL 2 high demand, energize-to-action applications, you must use two
output modules.
In cases where one or more outputs is used in an energize-to-action
configuration, all specific requirements that are listed previously must be
implemented for all associated inputs.
The user manual also contains all probability of a dangerous failure on demand
(PFD) and probability of failure per hour (PFH) values for Energize-to-Action
configurations.