Safety and environmental standards for fuel storage sites
Final report
22
MIIB Recommendation 1
The Competent Authority and operators of Buncefield-type sites should develop and agree a
common methodology to determine safety integrity level (SIL) requirements for overfill prevention
systems in line with the principles set out in Part 3 of BS EN 61511. This methodology should
take account of:
(a) the existence of nearby sensitive resources or populations;
(b) the nature and intensity of depot operations;
(c) realistic reliability expectations for tank gauging systems; and
(d) the extent/rigour of operator monitoring.
Application of the methodology should be clearly demonstrated in the COMAH safety report
submitted to the Competent Authority for each applicable site. Existing safety reports will need
to be reviewed to ensure this methodology is adopted.
29 The overall systems for tank filling control should be of high integrity, with sufficient
independence to ensure timely and safe shutdown to prevent tank overflow.
30 Dutyholders’ systems should meet the latest international standards, ie BS EN 61511:2004.
31 Before protective systems are installed there is a need to determine the appropriate level of
integrity that such systems are expected to achieve.
32 For each risk assessment/SIL determination study, dutyholders should be able to justify each
claim, and data used in the risk assessment, and ensure that appropriate management systems and
procedures are implemented to support those claims. For COMAH top-tier sites this will form part
of the demonstration required within the safety report. Of particular importance is the reliability and
diversity of the independent layers of protection. To avoid common mode failures extreme care should
be taken when claiming high reliability and diversity, particularly for multiple human interventions.
33 LOPA is one method and is a suitable methodology to determine SILs within the framework of
BS EN 61511-1. Note that other methods are available, and are described in BS EN 61511-1.
Overfill protection systems for storage tanks
34 Overfill protection systems, including instrumentation, devices, alarm annunciators, valves and
components comprising the shutdown system, should be assessed using BS EN 61511, which
sets a minimum performance for SILs. This includes the following considerations:
design, installation, operation, maintenance and testing of equipment;
■
■
management systems;
■
■
redundancy level, diversity, independence and separation;
■
■
fail safe, proof test coverage/frequency; and
■
■
consideration of common causes of failures.
■
■
Part 1 Systematic assessment of
safety integrity level requirements




