© SBM Offshore 2012. All rights reserved.
www.sbmoffshore.com21
v) Safety function will not work in a
specific error state
Fail-safe techniques not fully applied
•
Normally open field contacts used instead of normally closed.
•
Use of energise to trip circuits when fail-safe circuits are required.
•
Communications between controllers not set to fail-safe on loss of communications.
•
Wrong voting logic used, affecting the logic degrading on sensor failure.
•
Revealed sensor error not programmed as required to automatically generate a trip.
Counter-measures:
•
Awareness of logic solver team and verification measures
•
Awareness of commissioning teams
•
Test procedures - specific test for action on failure (e.g. test procedure
for specific requirements of the SRS)
Neil Wakeling, August 2014