Conformance statement
IEC 61511 and ISA-84
Scope
IEC 61511 (ANSI/ISA-84.00.01) covers the functional safety of safety instrumented systems for the process industry: the safety lifecycle, the safety requirements specification, the design and validation of safety instrumented functions, and their operation, maintenance and modification. A safety instrumented system (SIS) consists of sensors, a logic solver and final elements, and its safety integrity level is a property of that loop.
No component is part of a safety instrumented function. A web browser is not a safety-rated platform, and nothing in this library performs a protective action, computes a trip, applies a bypass or resets a trip. The components display the state of a safety system as the logic solver reports it, and they raise request events for the operator's actions. The safety function is implemented, and remains, in the SIS.
What is provided
- The cause and effect chart, live. smart-cause-effect-matrix displays the cause and effect matrix that the safety requirements specification defines: causes as rows, effects as columns, and marks (X trip, T timed trip, P permissive, A alarm only, or the plant's own marks) with delays and notes. The active causes, the tripped effects and the bypassed causes are shown as the SIS reports them.
- A discrepancy check for the display. From the active, unbypassed causes and the marks, the component computes which effects the chart expects to be tripped, compares this with the reported state, and marks an effect that is expected but not tripped, or tripped without an active cause. This is a display-side consistency check that supports the operator's diagnosis; it is not a safety function and does not replace the proof test or the SIS diagnostics.
- Bypasses as requests. No component applies a bypass. The cause and effect matrix shows a cause as bypassed when the SIS reports it and offers no bypass control of its own; smart-permissive, with allowBypass, offers a bypass control on each required condition that raises the bypassRequest event and changes nothing. The safety screen shows the expected procedure: a bypass is asked for with an electronic signature, recorded in the audit trail with the user and the reason, and shown in the matrix once the logic solver (simulated on the screen) has applied it.
- Final elements as device faceplates. smart-device-control shows the valves and motors the SIS acts on, with the interlock, its reason and the permissives, and refuses a start request while an interlock is active.
- Permissives and first-out. smart-permissive lists the conditions a start needs and, in interlock mode, marks the condition that tripped first from the timestamps the SIS supplies.
- Records. Trips, bypasses and resets shown on the screen can be written to the hash-chained audit trail with their timestamps, which supports the operation and maintenance records the lifecycle requires.
Known limitations
- No safety integrity level. The components have no SIL rating and cannot be used as part of a safety instrumented function, an interlock or a protective layer. The browser, the operating system and the network are outside the SIS.
- No logic. The trip logic, the voting, the timers and the bypass management are in the logic solver. The discrepancy check compares the chart with the reported state for display only.
- No bypass management. Authorization, time limits and the alarm on an active bypass are functions of the SIS and the bypass procedure. The components show a bypass and raise a request.
- No proof test or diagnostics. The proof test intervals, the diagnostic coverage and the failure records of the SIS are outside the scope of a display.
- Operator interface guidance. IEC 61511 requires that the operator interface does not compromise the SIS and that its information is clear. The components display the state as reported and never write to the SIS; the design of the screen, its access control and its data path are the responsibility of the system integrator.
Related: ISA-18.2 for the alarms an SIS raises, 21 CFR Part 11 and GAMP 5 for the signature and the record, and the security statement.