Safety Manual VEGASWING 61, 63. Relay (DPDT) With SIL qualification. Document ID: 52082

Similar documents
Vibrating Switches SITRANS LVL 200S, LVL 200E. Relay (DPDT) With SIL qualification. Safety Manual. Siemens Parts

OPTISWITCH 5300C. Safety Manual. Vibrating Level Switch. Relay (2 x SPDT) With SIL qualification

Safety Manual. VEGABAR series ma/hart - two-wire and slave sensors With SIL qualification. Document ID: 48369

Safety Manual. PROTRAC series ma/hart - four-wire With SIL qualification. Document ID: 49354

Safety Manual. Vibration Control Type 663. Standard Zone-1-21 Zone Edition: English

Type Switching repeater. Safety manual

MANUAL Functional Safety

Type 9160 / Transmitter supply unit / Isolating repeater. Safety manual

Functional safety manual RB223

SAFETY MANUAL SIL Switch Amplifier

MANUAL Functional Safety

MANUAL Functional Safety

Failure Modes, Effects and Diagnostic Analysis

Soliphant M with electronic insert FEM54

Failure Modes, Effects and Diagnostic Analysis. PR electronics A/S

MANUAL Functional Safety

Proline Prowirl 72, 73

Failure Modes, Effects and Diagnostic Analysis

FMEDA Report Failure Modes, Effects and Diagnostic Analysis and Proven-in-use -assessment KF**-CRG2-**1.D. Transmitter supply isolator

FUNCTIONAL SAFETY CERTIFICATE

Failure Modes, Effects and Diagnostic Analysis

Mobrey Hydratect 2462

Failure Modes, Effects and Diagnostic Analysis

Special Documentation Liquicap M FMI51, FMI52

Safety instructions VEGATOR 121, 122

Soliphant M with electronic insert FEM57 + Nivotester FTL325P

Low voltage switchgear and controlgear functional safety aspects

HART Temperature Transmitter for up to SIL 2 applications

Failure Modes, Effects and Diagnostic Analysis

ACT20X-(2)HTI-(2)SAO Temperature/mA converter. Safety Manual

HART Temperature Transmitter for up to SIL 2 applications

FUNCTIONAL SAFETY CERTIFICATE

The ApplicATion of SIL. Position Paper of

Special Documentation Soliphant M with electronic insert FEM57 + Nivotester FTL325P

Failure Modes, Effects and Diagnostic Analysis

Failure Modes, Effects and Diagnostic Analysis

Rosemount Functional Safety Manual. Manual Supplement , Rev AG March 2015

DK32 - DK34 - DK37 Supplementary instructions

Safety manual. This safety manual is valid for the following product versions: Version No. V1R0

Functional safety manual Liquiphant M/S with FEL58 and Nivotester FTL325N

Service & Support. Functional Safety One Position switch. Safe Machine Concepts without Detours. benefit from the Safety Evaluation Tool.

Failure Modes, Effects and Diagnostic Analysis. Rosemount Inc. Chanhassen, MN USA

Commissioning and safety manual SIL2

New developments about PL and SIL. Present harmonised versions, background and changes.

Failure Modes, Effects and Diagnostic Analysis

Safety modules. 8/4 inputs PROFIsafe S20-PSDI8/4

Hardware Safety Integrity. Hardware Safety Design Life-Cycle

MACX MCR-SL-(2)I-2)I-ILP(-SP)

Products Solutions Services. Functional Safety. How to determine a Safety integrity Level (SIL 1,2 or 3)

Functional Safety Manual Cerabar S PMC71, PMP71, PMP75

FMEDA and Proven-in-use Assessment. Pepperl+Fuchs GmbH Mannheim Germany

Failure Modes, Effects and Diagnostic Analysis

Point Level Transmitters. Pointek CLS200 (Standard) Functional Safety Manual 02/2015. Milltronics

Hardware safety integrity (HSI) in IEC 61508/ IEC 61511

ProductDiscontinued. Rosemount TankRadar Rex. Safety Manual For Use In Safety Instrumented Systems. Safety Manual EN, Edition 1 June 2007

Intelligent Valve Controller NDX. Safety Manual

SIL-Safety Instructions SM/261/SIL-EN Rev. 05. Models 261GS/GC/GG/GJ/GM/GN/GR Models 261AS/AC/AG/AJ/AM/AN/AR Pressure Transmitter

Your Global Automation Partner. Magnetic Field Safety Sensors. Safety Manual

Failure Modes, Effects and Diagnostic Analysis

FMEDA and Prior-use Assessment. Pepperl+Fuchs GmbH Mannheim Germany

Your Global Automation Partner. Capacitive Safety Sensors. Safety Manual

Additional Operating Instructions SITRANS F. Vortex flowmeters. Functional Safety for SITRANS FX330.

What functional safety module designers need from IC developers

Table of Content: 1 Objective of assessment Abbreviations and glossary System Overview... 6

Operating Instruction

FMEDA and Proven-in-use Assessment. G.M. International s.r.l Villasanta Italy

Options for ABB drives. User s manual Emergency stop, stop category 0 (option +Q951) for ACS880-07/17/37 drives

Original operating instructions Safety relay with relay outputs with and without delay G1502S / / 2016

IQ Pro SIL option TÜV Certified for use in SIL 2 & 3 applications

FUNCTIONAL SAFETY CHARACTERISTICS

PSR-PC50. SIL 3 coupling relay for safety-related switch on. Data sheet. 1 Description

Failure Modes, Effects and Diagnostic Analysis

MACX MCR-EX-SL-2NAM-T(-SP)

Sense it! Connect it! Bus it! Solve it! SAFETY MANUAL SWITCHING AMPLIFIERS

Micropilot S FMR530/532/533, FMR540

Micropilot M FMR230/231/232/233/240/244/245

Original operating instructions Safety relay with relay outputs G1501S / / 2016

MACX MCR-EX-SL-RPSS-2I-2I

D5090S INSTRUCTION MANUAL. D A SIL 3 Relay Output Module for NE Load. DIN-Rail and Termination Board, Model D5090S

Safety instructions Overvoltage protection B81-35

SIRIUS Safety Integrated. Modular safety system 3RK3

Operating Instructions. VEGA DataViewer. Software for archive, administration and display of DTM data. Document ID: 51547

Safety instructions. IECEx TUN Ex ia IIC T6 Gb

BT50(T) Safety relay / Expansion relay

ELR H3-IES-PT- 24DC/500AC-...

INSTALLATION MANUAL PowerBot

FACTORY AUTOMATION. MANUAL VAA-2E-G4-SE Original Instructions Version 1.1

MACX MCR-EX-SL-RPSSI-I(-SP)

Original operating instructions Fail-safe inductive sensor GF711S / / 2013

Functional Safety and Safety Standards: Challenges and Comparison of Solutions AA309

Application Note. AC500-S Usage of AC500 Digital Standard I/Os in Functional Safety Applications up to PL c (ISO )

PSR-PS21. SIL coupling relay. Data sheet. 1 Description

Controller CMXH. Description STO. Safe Torque Off (STO) [ ]

Options for ABB drives. User s manual Prevention of unexpected start-up (option +Q957) for ACS880-07/17/37 drives

MSI-RM2 Safety Relays

Polymer Electric. Operating Instructions. Control Unit SG-EFS 1X4 ZK2/1 8k2. Version 3

English. Operating manual. Limit switch GS125. Keep for future reference. Ventures / brands of GHM

Micropilot FMR50/51/52/53/54/56/57

Safety manual for Fisher FIELDVUE DVC6200 SIS Digital Valve Controller, Position Monitor, and LCP200 Local Control Panel

Safety-related controls SIRIUS Safety Integrated

Transcription:

Safety Manual VEGASWING 61, 63 Relay (DPDT) With SIL qualification Document ID: 52082

Contents Contents 1 Document language 2 Scope 2.1 Instrument version... 4 2.2 Area of application... 4 2.3 SIL conformity... 4 3 Planning 3.1 Safety function... 5 3.2 Safe state... 5 3.3 Prerequisites for operation... 5 4 Safety-related characteristics 4.1 Key figures acc. to IEC 61508... 6 4.2 Figures according to ISO 13849-1... 6 4.3 Supplementary information... 7 5 Setup 5.1 General information... 8 5.2 Adjustment instructions... 8 6 Diagnostics and servicing 6.1 Behaviour in case of failure... 9 6.2 Repair... 9 7 Proof test 7.1 General information... 10 7.2 Test 1 - without filling/emptying or dismounting the sensor... 10 7.3 Test 2 - with filling/emptying or dismounting the sensor... 10 8 Appendix A - Test report 9 Appendix B - Term definitions 10 Supplement C - SIL conformity 2 Editing status: 2016-04-15

1 Document language 1 Document language DE EN FR RU Das vorliegende Safety Manual für Funktionale Sicherheit ist verfügbar in den Sprachen Deutsch, Englisch, Französisch und Russisch. The current Safety Manual for Functional Safety is available in German, English, French and Russian language. Le présent Safety Manual de sécurité fonctionnelle est disponible dans les langues suivantes: allemand, anglais, français et russe. Данное руководство по функциональной безопасности Safety Manual имеется на немецком, английском, французском и русском языках. 3

2 Scope 2 Scope 2.1 Instrument version This safety manual applies to point level sensors VEGASWING 61 with SIL qualification VEGASWING 63 with SIL qualification Electronics module: Relay (DPDT) 2.2 Area of application The instrument can be used for level detection of liquids in a safetyrelated system according to IEC 61508 in the modes low demand mode or high demand mode: Up to SIL2 in single-channel architecture Up to SIL3 in a multiple-channel architecture (systematic suitability SC3) The following interface can be used to output the measured value: Relay (DPDT) The NO contact must be used! 1) 2.3 SIL conformity The SIL conformity was independently judged by exida Certification S.A. according to IEC 61508. 2) 4 1) NO = Normal Open 2) Verification documents see appendix.

3 Planning 3 Planning Safety function Safe state 3.1 Safety function To monitor a limit level, the sensor detects via the conditions "Vibrating element uncovered" or "Vibrating element covered" a limiting value defined by the mounting location. The detected status is signalled on the output with "Relay contact open" or "Relay contact closed". 3.2 Safe state The safe state of the output signal is independent of the mode adjusted on the sensor. For the safety function, only the NO contact may be used (idle current principle)! Mode Overflow protection Mode max. Dry run protection Mode min. Vibrating element covered uncovered Relay NO contact open NO contact open (currentless) (currentless) Fault signals in case of malfunction Instructions and restrictions Relay outputs: NO contacts open 3.3 Prerequisites for operation The measuring system should be used appropriately taking pressure, temperature, density and chemical properties of the medium into account. The application-specific limits must be observed. The specifications according to the operating instructions manual, particularly the current load on the output circuits, must be kept within the specified limits To avoid a fusing of the relay contacts, these must be protected by an external fuse that triggers at 60 % of the max. contact current load. When used as dry run protection, buildup on the vibrating system should be avoided (probably shorter proof test intervals will be necessary) The instructions in chapter "Safety-related characteristics", paragraph "Supplementary information" must be noted All parts of the measuring chain must correspond to the planned "Safety Integrity Level (SIL)" 5

4 Safety-related characteristics 4 Safety-related characteristics 4.1 Key figures acc. to IEC 61508 Parameter Value Safety Integrity Level SIL2 in single-channel architecture SIL3 in multiple channel architecture 3) Hardware error tolerance HFT = 0 Instrument type Type A Mode Low demand mode, High demand mode SFF > 60 % MTBF = MTTF + MTTR 4) 3.36 x 10 6 h (383 years) Fault reaction time 5) < 1.5 s Failure rates λ S λ DD λ DU λ H λ L λ AD λ AU 166 FIT 0 FIT 32 FIT 0 FIT 0 FIT 0 FIT 2 FIT PFD AVG 0.027 x 10-2 (T1 = 1 year) PFD AVG 0.077 x 10-2 (T1 = 5 years) PFD AVG 0.140 x 10-2 (T1 = 10 years) PFH 0.032 x 10-6 1/h Proof Test Coverag (PTC) Test type 6) Remaining failure rate of dangerous undetected failures PTC Test 1 18 FIT 42 % Test 2 2 FIT 94 % 4.2 Figures according to ISO 13849-1 Derived from the safety-related characteristics, the following figures result according to ISO 13849-1 (machine safety): 7) Parameter MTTFd Value DC 0 % Performance Level 3567 years 3.20 x 10-8 1/h (corresponds to "e") 6 3) Homogeneous redundancy possible. 4) Including errors outside the safety function. 5) Time between the occurrence of the event and the output of a fault signal. 6) See section "Proof test". 7) ISO 13849-1 was not part of the certification of the instrument.

4 Safety-related characteristics Determination of the failure rates Assumptions of the FMEDA Calculation of PFD AVG Configuration of the processing unit 4.3 Supplementary information The failure rates of the instruments were determined by an FMEDA according to IEC 61508. The calculations are based on failure rates of the components according to SN 29500: All figures refer to an average ambient temperature of 40 C (104 F) during the operating time. For higher temperatures, the values should be corrected: Continuous application temperature > 50 C (122 F) by factor 1.3 Continuous application temperature > 60 C (140 F) by factor 2.5 Similar factors apply if frequent temperature fluctations are expected. The failure rates are constant. Take note of the useful service life of the components according to IEC 61508-2. Multiple failures are not taken into account Wear on mechanical parts is not taken into account Failure rates of external power supplies are not taken into account The environmental conditions correspond to an average industrial environment To avoid a fusing of the relay contacts, these must be protected by an external fuse The values for PFD AVG specified above were calculated as follows for a 1oo1 architecture: PTC λdu T1 PFDAVG = + λdd x MTTR + 2 Parameters used: PTC = 90 % LT = 10 years MTTR = 24 h T1 = Proof Test Interval (1 PTC) λdu LT A connected control and processing unit must have the following properties: The failure signals of the measuring system are judged according to the idle current principle "fail low" and "fail high" signals are interpreted as a failure, whereupon the safe state must be taken on If this is not the case, the respective percentages of the failure rates must be assigned to the dangerous failures and the values stated in chapter Safety-related characteristics redetermined! 2 Multiple channel architecture Due to the systematic suitability SC3, this instrument can also be used in multiple channel systems up to SIL3, also with a homogeneously redundant configuration. The safety-related characteristics must be calculated especially for the selected structure of the measuring chain using the stated failure rates. In doing this, a suitable Common Cause Factor (CCF) must be considered (see IEC 61508-6, appendix D). 7

5 Setup 5 Setup Mounting and installation Adjustment elements Please note! 5.1 General information Take note of the mounting and installation instructions in the operating instructions manual. Setup must be carried out under process conditions. 5.2 Adjustment instructions The adjustment elements must be set according to the specified safety function: Slide switch for changeover of the mode (min./max.) Slide switch for changeover of the sensitivity The function of the adjustment elements is described in the operating instructions manual. During adjustment process, the safety function must be considered as unreliable! If necessary, you must take other measures to maintain the safety function. With regard to the switch on/swich off delay it must be ensured that the sum of all switching delays from the transducer to the actuator is adapted to the process safety time! The instrument must be protected against inadvertent or unauthorized adjustment! 8

6 Diagnostics and servicing 6 Diagnostics and servicing Internal diagnosis Electronics exchange 6.1 Behaviour in case of failure The instrument is permanently monitored by an internal diagnostic system. If a malfunction is detected, the respective output signals change to the safe status (see section "Safe status"). The fault reaction time is specified in chapter "Safety-relevant characteristics". If failures are detected, the entire measuring system must be shut down and the process held in a safe state by other measures. The manufacturer must be informed of the occurrence of a dangerous undetected failure (incl. fault description). 6.2 Repair The procedure is described in the operating instructions manual. Note the instructions for setup. 9

7 Proof test 7 Proof test Objective Preparation Unsafe device status Conditions Procedure Expected result Proof Test Coverage Conditions 10 7.1 General information To identify possible dangerous, undetected failures, the safety function must be checked by a proof test at adequate intervals. It is the user's responsibility to choose the type of testing. The time intervals are determined by the selected PFD AVG (see chapter "Safety-related characteristics"). For documentation of these tests, the test protocol in the appendix can be used. If one of the tests proves negative, the entire measuring system must be switched out of service and the process held in a safe state by means of other measures. In a multiple channel architecture this applies separately to each channel. Determine safety function (mode, switching points) If necessary, remove the instruments from the safety chain and maintain the safety function by other means Warning: During the function test, the safety function must be treated as unreliable. Take into account that the function test influences downstream connected devices. If necessary, you must take other measures to maintain the safety function. After the function test, the status specified for the safety function must be restored. 7.2 Test 1 - without filling/emptying or dismounting the sensor Instrument can remain in installed condition Output signal corresponds to the level (covered or uncovered vibrating element) 1. Carry out a restart (switch the instrument off and then on again) 2. Push the min./max. switch on the sensor to 1: Output signal corresponds to the level to 2: Output signal changes status See Safety-related characteristics 7.3 Test 2 - with filling/emptying or dismounting the sensor Alternative 1: the instrument remains mounted; the condition "Vibrating element uncovered"/"vibrating element covered" can be changed by filling or emptying to the switching point.

7 Proof test Alternative 2: the instrument is dismounted; the condition "Vibrating element uncovered"/"vibrating element covered" can be changed by dipping the instrument into the original medium Output signal corresponds to the level (covered or uncovered vibrating element) Procedure Expected result Proof Test Coverage Filling or emptying up to the switching point or immersion into the original medium and assessing the corresponding switching status Output signal corresponds to the modified level See Safety-related characteristics 11

8 Appendix A - Test report 8 Appendix A - Test report Identification Company/Tester Plant/Instrument TAG Meas. loop TAG Instrument type/order code Instrument serial number Date, setup Date, last function test Test reason ( ) Setup ( ) Proof test Mode ( ) Overflow protection ( ) Dry run protection Test scope ( ) without filling or dismounting the sensor ( ) with filling or dismounting the sensor Sensitivity ( ) 0.7 g/cm³ (0.025 lbs/in³) ( ) 0.5 g/cm³ (0.018 lbs/in³) Test result Test step Level Expected measured value Real value Test result Confirmation Date: Signature: 12

9 Appendix B - Term definitions Abbreviations 9 Appendix B - Term definitions SIL Safety Integrity Level (SIL1, SIL2, SIL3, SIL4) SC Systematic Capability (SC1, SC2, SC3, SC4) HFT Hardware Fault Tolerance SFF Safe Failure Fraction PFD AVG PFH FMEDA Average Probability of dangerous Failure on Demand Average frequency of a dangerous failure per hour (Ed.2) Failure Mode, Effects and Diagnostics Analysis FIT Failure In Time (1 FIT = 1 failure/10 9 h) λ SD λ SU Rate for safe detected failure Rate for safe undetected failure λ S λ DD λ DU λ H λ L λ AD λ AU DC PTC T1 LT MTBF MTTF MTTR MRT λ S = λ SD + λ SU Rate for dangerous detected failure Rate for dangerous undetected failure Rate for failure, who causes a high output current (> 21 ma) Rate for failure, who causes a low output current ( 3.6 ma) Rate for diagnostic failure (detected) Rate for diagnostic failure (undetected) Diagnostic Coverage Proof Test Coverage Proof Test Interval Useful Life Time Mean Time Between Failure Mean Time To Failure Mean Time To Restoration (Ed.2) Mean Repair Time MTTF d Mean Time To dangerous Failure (ISO 13849-1) PL Performance Level (ISO 13849-1) 13

10 Supplement C - SIL conformity 10 Supplement C - SIL conformity 14

10 Supplement C - SIL conformity 15

10 Supplement C - SIL conformity 16

10 Supplement C - SIL conformity 17

10 Supplement C - SIL conformity 18

10 Supplement C - SIL conformity 19

10 Supplement C - SIL conformity 20

10 Supplement C - SIL conformity 21

10 Supplement C - SIL conformity 22

Notes 23

Printing date: All statements concerning scope of delivery, application, practical use and operating conditions of the sensors and processing systems correspond to the information available at the time of printing. Subject to change without prior notice VEGA Grieshaber KG, Schiltach/Germany 2016 VEGA Grieshaber KG Am Hohenstein 113 77761 Schiltach Germany Phone +49 7836 50-0 Fax +49 7836 50-201 E-mail: info.de@vega.com www.vega.com