Servomex 2223A Functional Safety Manual Download Page 9

2223A Oxygen Transmitter Functional Safety Manual 

02223006A / Revision 0 

 

2.12  Safety integrity level (SIL) 

The international standard IEC 61508 defines four Safety Integrity Levels from SIL1 to 
SIL4. Each of these corresponds to a range of probabilities that the safety function will fail. 
The higher the SIL the greater the probability that the safety function will work when 
required to do so. 

The achievable SIL is determined by a number of factors that include the safety 
management procedures and lifecycle activities carried out during the development of a 
product or system. This manual only considers product hardware failures and so covers the 
following characteristics:- 

 

Product type (A or B) 

 

Hardware fault tolerance 

 

Safe failure fraction 

 

Average probability of a dangerous failure of the safety function on demand 
(PFD

AVG

) and associated proof test interval 

The following table shows the relationship between hardware fault tolerance and safe 
failure fraction for a Type B subsystem (see IEC 61508 Section 2). 

HFT 

SFF 

0 1 2 

<60% Not 

allowed  SIL1 

SIL2 

60 to 90% 

SIL1 

SIL2 

SIL3 

90 to 99% 

SIL2 

SIL3 SIL4 

>99% SIL3  SIL4  SIL4 

 

The following table shows the dependency of the SIL on the probability of failure on 
demand (PFD

AVG

) for low demand mode of operation. 

Safety Integrity 

Level 

Low Demand Mode of Operation 

Average Probability of Failure to Perform 

Safety Function on Demand 

 10

-5

 to 10

-4

 10

-4

 to 10

-3

 10

-3

 to 10

-2

 10

-2

 to 10

-1

 

Summary of Contents for 2223A

Page 1: ...Part Number 02223006A Revision 0 Language UK English Functional Safety Manual SERVOTOUGH OxyExact 2223A Transmitter PROCESS ANALYSERS...

Page 2: ...This page intentionally blank...

Page 3: ...B subsystems 3 2 7 Hardware fault tolerance HFT 4 2 8 Safe failure fraction SFF 4 2 9 PFDAVG 4 2 10 Mean time to repair MTTR 4 2 11 Proof test 4 2 12 Safety integrity level SIL 5 3 SAFETY INSTRUCTION...

Page 4: ...2223A Oxygen Transmitter Functional Safety Manual ii 02223006A Revision 0 This page intentionally blank...

Page 5: ...r as inputs from external measurements The measurement is provided as a mA output Fault indications are provided by a solid state relay output and by an out of range current from the mA output Additio...

Page 6: ...2223A Oxygen Transmitter Functional Safety Manual 2 02223006A Revision 0 This page intentionally blank...

Page 7: ...diagnostic tests proof tests operator intervention or through normal operation 2 6 Type A and type B subsystems This relates to the complexity of the subsystem and the degree to which it is understood...

Page 8: ...AVG The probability of a dangerous failure on demand This is intended to apply to systems operating in a low demand mode where the safety function is required on average a maximum of once per year A t...

Page 9: ...ardware failures and so covers the following characteristics Product type A or B Hardware fault tolerance Safe failure fraction Average probability of a dangerous failure of the safety function on dem...

Page 10: ...2223A Oxygen Transmitter Functional Safety Manual 6 02223006A Revision 0 This page intentionally blank...

Page 11: ...on The safety function of the 2223A Oxygen Transmitter is the measurement of oxygen concentration in a sample stream The dangerous failure is the failure to indicate this oxygen concentration to the p...

Page 12: ...elect Transmitter Peripherals Enter the appropriate forms and ensure that the necessary settings are made as described below Note that it may be necessary to scroll the forms displayed on the control...

Page 13: ...s should then be set as appropriate As an alternative to the internal flow sensor external devices may be used in conjunction with the external flow alarm inputs as described in the installation manua...

Page 14: ...application the design of the overall safety instrumented system and the target SIL The recommended proof test interval is a maximum of one year If there are any transmitter fault conditions present...

Page 15: ...layed is within an acceptable tolerance of the actual pressure 4 Calibrate the pressure sensor 5 Carry out a full low and high calibration of the oxygen measurement 6 Carry out pressure compensation c...

Page 16: ...2223A Oxygen Transmitter Functional Safety Manual 12 02223006A Revision 0 This page intentionally blank...

Page 17: ...2223A Oxygen Transmitter Functional Safety Manual A1 APPENDIX 02223006A Revision 0 13...

Reviews: