The safe state is the condition the process is in once the hazard is gone, and reaching it is the whole job of a SIF: detect the problem, act, land the process there. For most process SIFs that means a closed valve, a stopped motor, or a de-energized circuit, but the safe state is a property of the process, not of the SIS. Getting it wrong is a design error that no amount of SIL math will fix.
Key Points
- A state that is safe for one SIF can raise the risk for another, so the safe states across a unit have to be checked against each other.
- Some safe states only hold while the process is actively controlled, and the process may pass through intermediate safe states on the way to the final one.
- IEC 61511 requires the SRS to define the safe state for every SIF as a stable condition where the hazardous event has been avoided or sufficiently mitigated, plus the response time to reach it (10.3.2).
Example
A fired heater SIF on high tube-skin temperature closes the fuel gas double block valves and opens the bleed. The safe state is fuel isolated and burners out. A cold heater is not a safe plant, though; the downstream unit that just lost its heat has SIFs of its own.
See Also: SRS, PST, final element
Cited Sources
- IEC 61511-1:2016, Clause 3.2.63
- IEC 61511-1:2016, Clause 10.3.2