You are on page 1of 32

Functional safety

handbook

ABB Value Paper Series


ABB Value Paper Series

Contents

1.0 Introduction Page 1

2.0 Background Page 2-3

3.0 Putting the basics in place Page 3-5

4.0 Dening the boundaries Page 6-8

5.0 Specifying competency requirements Page 8-9

6.0 Benchmarking current practice Page 10-11

7.0 Selecting the certication body Page 11

8.0 Developing the safety lifecycle model and functional safety management system Page 12-21

9.0 Executing the certication process Page 22-23

10.0 Training courses Page 23-24

11.0 Establishing supporting activities Page 24

12.0 Managing channel partners and third-party integrators Page 24

13.0 Final comments and conclusions Page 24

Appendices Page 25-27

References Page 28

About the author Page 29

For more information, contact Stuart Nunns, UK Safety Lead Competency Centre at stuart.nunns@gb.abb.com

2
ABB Value Paper Series

A methodology for achieving Functional Safety


certication to IEC61508

1.0 Introduction
The demands of the safety critical systems market are based on the safety performance of their operation. In
becoming ever more exacting, with international standards order to compete or even survive, industry continually
being increasingly used to demonstrate compliance with strives to improve performance and protability while
legal requirements and the increasing need to justify that maintaining and improving safety. In todays world there
the required functional safety has been achieved. This is are signicant costs on an organization if they are not
not surprising given the increasing dependence on such acting in a socially responsible manner. Such costs include
systems to achieve the specied tolerable risk targets. direct nancial costs arising from the incident itself, from
With increasing contractual rigour and the potential for legal costs and nes in the event of being found guilty of
litigation should something go wrong, organizations need breaking the law, damages paid to injured parties caused
to demonstrate that their functional safety capability is by negligence and reputation damage which can have far
seen as best in class. reaching implications on the business. The result is that
safety and protability are inextricably linked.
Of particular importance in this context is the effectiveness
of the competence management arrangements to ensure In summary, there are strong regulatory and social demands
that those within the organization having responsibility for for businesses to demonstrate they have exercised their
functional safety are competent to undertake those duties. duty of care by providing a safe, reliable operation with full
In order to meet these increasing demands, safety suppliers documentation and decision traceability.
and integrators are increasingly embarking on more
formalized regimes, including certication programmes, 2.1 Safety technologies are changing rapidly
to ensure their safety applications are implemented in In line with all control system technologies, safety systems
accordance with IEC61508 [1] and IEC61511 [2]. are undergoing a revolution. Increasing reliance for
process protection is being placed on networked smart
The author has worked with a number of organizations equipment, integrated control and safety solutions,
seeking certication. This Functional Safety Handbook reusable safety components and subsystems with
provides a case study illustrating how a major automation automated conguration tools. The application of such
system supplier (the organization), with world wide systems technology has, potentially, signicant economic and
integration businesses (the integrators) undertook the safety benets, but to release its potential, it is vital that
challenge to achieve third-party accredited certication for such technology is applied by the adoption of current
its functional safety management system (FSMS) against good practice and this means the adoption of relevant
the requirements of IEC 61508 and IEC 61511. standards such as IEC 61508 and IEC 61511. These
standards represent current good practice and demand
The generic methodology described and comprising the that attention be paid to all safety lifecycle activities within
procedures and processes to achieve certication have an effective functional safety management system.
been developed by ABB Ltd.
2.2 Safety standards are also changing
2.0 Background The publication of the international safety standards IEC
Statistics relating to the performance of large organizations 61508 and IEC 61511 for the process sector are setting
are published internationally and incidents, especially those global benchmarks as good practices in functional
causing injury or death, make headline news. Recent safety. Safety Regulators and the legal professions world
inquiries into major incidents provide further support of wide are embracing these standards and using them to
the increasing importance of international standards (IEC make judgements as to whether accepted good practice
61508 and IEC 61511) where such standards have been has been applied if negligence is suspected. Ignore them
used as a benchmark of what constitutes acceptable at your peril!
good practice [3] [4]. Many management incentives are

3
ABB Value Paper Series

2.3 Globalization
The safety-related market is truly global and increasingly Striving to achieve recognition for organizational and
based on international standards. Although companies individual functional safety capabilities had to be seen as
throughout the supply chain are establishing the capability both a positive and essential requirement for the business
to ensure compliance with the relevant international as a whole. Also, in the light of many inaccurate and
standards there are currently differences in the way IEC disputed claims (so-called claims to fame) relating to
61508 and IEC 61511 are being implemented. These compliance of safety-related products in the marketplace
differences lead to a lack of cohesion in the supply chain it was necessary for the organization to establish an
and increase the likelihood of contractual and project objective and irrefutable means of demonstrating
disruption. The interface between the supply chain and compliance and competence. The organization could
the end user organization can sometimes be less than not afford to ignore the requirements IEC 61508 and
ideal as end user organizations have been subjected to IEC 61511 standards and those of its customers who
right-sizing, downsizing, restructuring and changes of increasingly specify them as a functional safety benchmark
ownership which makes it a challenge for them to retain and a contractual requirement.
core competencies in an environment of rapid change.
The additional benets to the business of achieving
2.4 Organizational and certication included:
personal competence Limiting the companys exposure to potential liabilities
Proven competence at a company, department and Demonstrating due diligence
individual level is increasingly seen as necessary to meet Implementing repeatable and cost effective safety
contractual and regulatory requirements. But which management systems (procedures, techniques,
competency scheme is most appropriate and who should tools etc)
it apply to? Reducing unnecessary and costly pre-contract
discussions and evidence gathering (which actually
2.5 What do the standards say about benets both the organization and its clients)
competency and functional safety? Winning work cost effectively
The following clauses relate to IEC 61508 Limiting effort (and cost) in developing so-called
and IEC 61511 in respect of the Management of functional bespoke project safety procedures
safety. In the case study, the organization had to develop Gaining a competitive advantage and as a result
a functional safety management system (FSMS), centrally, securing more business
in compliance with these clauses as an essential pre-
requisite to achieving accredited certication. 3.0 Putting the basics in place
In the case study, the senior management of the
The relevant clauses in these standards are: organization responded to the strategic objectives by
1. IEC 61508 Part 1 clause 6.2.1 states Those establishing an internal Company Safety Authority (CSA).
organizations or individuals that have overall The CSA was charged with the responsibility of ensuring
responsibility for one or more phases of the that safety applications were implemented in accordance
overall E/E/PES or software safety lifecycle shall, in with IEC61508 and IEC61511.
respect of those phases for which they have overall
responsibility, specify all management and technical The CSA was tasked with developing a set of core principles
activities that are necessary to ensure that the for functional safety and a program of work to achieve
E/E/PES safety-related systems achieve and maintain accredited certication for the organization as a whole.
the required functional safety. These core principles endorsed by senior management
are collectively referred to as Strategic Competency
2. IEC 61511 Part 1 clause 5.2.2.2 states Persons, Principles. They dene minimum requirements designed
departments or organizations involved in safety life- to reect a common purpose, shared beliefs and values
cycle activities shall be competent to carry out the and a commitment to (functional) safety within all the
activities for which they are accountable relevant businesses.

4
ABB Value Paper Series

The Strategic Competency Principles are based on a management system against IEC 61508 and IEC61511 to
multi-tiered approach to demonstrating functional safety establish the scope of the task. (See section 6)
capability, see Figure 1 below. At the highest level the
organization had to demonstrate compliance to good b) Implement safety standards
practice by the adoption of international standards IEC Following the gap assessment, specify and implement
61508 and IEC 61511. A key part of this demonstration a program of work to achieve accredited certication for
was the strategic aim of achieving third party accredited each of the organizations integrator companies functional
certication. An essential element of this was the safety management systems.
organizations competence framework.
Whilst the organizations integrator companies are seeking
The second level relates to individual competence and accredited certication, they shall produce safety plans
the requirement to achieve external recognition of an covering all their related safety activities.
individuals functional safety capability. This recognition
complements the organizations competence framework. c) Establish individual Competency
At the lowest level is the specic requirement to be The organizations Safety Engineers shall progress to
competent to implement and deliver a specic safety certied functional safety engineer status through the TUV
product, package or service. Rheinland Functional Safety Program.

There are four strategic competency principles: The organizations Lead Engineers and nominated Safety
a) Benchmark current practice Engineers working on a safety project shall have attended
Undertake and document a gap assessment of each of all the relevant safety system training courses prior to
the organizations integrator companies functional safety working on a safety project

d) Manage Third Party Integrators


and Channel Partners
All Third Party companies invited to carry
out safety-related activities on behalf
of the organizations integrator companies
shall be assessed and approved by
the CSA.

This assessment and approval shall be


achieved through a gap assessment,
project functional safety assessments
undertaken by the CSA and project audits
undertaken by the integrator. All Third Party
Integrators shall have in place a functional
safety management system compliant
with IEC 61508 and IEC 61511.

The key tenets of these Strategic


Competency Principles are:
To use Certied Products
To employ Competent
(Certied) persons
To implement safety systems
through the certied organization

5
ABB Value Paper Series

4.0 Dening the boundaries


In the case study, prior to the gap assessment a core Safety integrity data for the logic solver is clearly
set of prerequisites had to be agreed for the organization. dened in the Safety Manual provided by the supplier
These not only provided a clear understanding of the of the logic solver
organizations safety-related systems supply chain Reliability data necessary for the integrator to perform
responsibilities but also mapped the organizations their task is provided by supply chain manufacturers to
generic functional safety management system against the integrator and is readily available
IEC 61508 Part 1 clause 6 and IEC 61511 Part 1 clause 5 Hardware element design (e.g. Analog Input
(Management of Functional Safety). module, Analog Output module) is not undertaken
but hardware is congured into overall hardware
This core set of prerequisites are dened below: architecture by development of subsystems
The subsystem used for systems implementation Software is Limited Variability Language (LVL). This
(logic solver and associated I/O modules) is is dened in IEC61131-3 [5] and includes ladder
third-party certied in accordance with the diagram, functional block diagrams, sequential
requirements of IEC61508 function chart and structured text
Safety integrity data (PFD, systematic capability and Libraries are available with certied or approved
hardware fault tolerance) exists for all devices function blocks

Table 1 Requirements to be addressed


A description of all the safety instrumented functions necessary to achieve the required functional safety
Identication of requirements of common cause failures
Denition of the safe state of the process for each identied safety instrumented function
Denition of any individually occurring safe process states which, when occurring concurrently, create a separate
hazard (for example, overload of emergency storage, multiple relief to are system)
Assumed sources of demand and demand rate on the safety instrumented function
Requirement for proof-test intervals
Response time requirements for the SIS to bring the process to a safe state
Safety integrity level and mode of operation (demand/continuous) for each safety instrumented function
Description of SIS process measurements and their trip points
Description of SIS process output actions and the criteria for successful operation, for example, requirements
for tight shut-off valves
Functional relationship between process inputs and outputs, including logic, mathematical functions and
any required permissives
Requirements for manual shutdown
Requirements relating to energize or de-energize to trip
Requirements for resetting the SIS after a shutdown
Maximum allowable spurious trip rate
Failure modes and desired response of the SIS (for example, alarms, automatic shutdown)
Any specic requirements related to the procedures for starting up and restarting the SIS
All interfaces between the SIS and any other system (including the BPCS and operators)

6
ABB Value Paper Series

Special (approved) conguration tools are available as established a set of processes to facilitate a dialog with
part of the logic solver environment the client in order to complete, for the bid and proposal
Development tool support conrms that the phase purposes, the checklist in Table 1. However, this
downloaded run-time application software is identical was not a substitute for the delivery of an adequate SRS
to the source application software by the client which would be necessarysubsequent to the
Application software development is facilitated by the bid and proposal phase.
use of existing function blocks
Integration involves the downloading and compilation There are signicant benets to the parties involved
of the conguration data and application software on in needing the SRS (the party having responsibility for
the target platform developing the SRS and the party requiring the SRS in
Approved libraries and function blocks are protected order to undertake the integration process) engaging
from unauthorized modication in a dialog at an early stage. Early dialog facilitates the
Hardware consists of SIS logic solver, cabinets with concept of partnership working and can be of advantage
appropriate termination panels for connecting the to both parties.
process signal to the logic solver I/O modules. Power
supplies and power distribution for the logic solver and This core set of pre-requisites was also a requirement
eld devices are also normally included for dening the certication scope and applied area
A certied application development package is of each integrators certication. The certication
used to congure the SIS logic solver, I/O and scope covered:
communication hardware IEC 61508 E/E/PE safety related System Integration
Coding standards are available for each 61131-3 and IEC 61511 SIS Integration
language used, including any specic limitations Applicable phases IEC 61508 Phase 9
or restrictions & IEC 61511 Phase 4
The development environment provides version and Specically:
conguration management facilities Management of Functional Safety
Process Hazard and Risk Assessment has been Documentation
performed to ensure systematic development of a Safety Functional Safety Assessments
Requirements Specication and this has been provided
as a key deliverable from the End User/Engineering At the outset of the certication program it was necessary
Procurement and Construction (EPC) organization to analyze the two relevant standards (IEC 61508 and
IEC 61511) to identify differences in interpretation and
With respect to the last bullet point, there are signicant terminology for those clauses affecting the scope of
variations in the quality and contents of the Safety supply; such as levels of independence for Functional
Requirements Specication (SRS) within the industry. The Safety Assessments, Techniques and Measures, Site
fundamental requirements are for a clear specication of Acceptance Test (SAT), Verication and Validation.
the safety functions and target safety integrity for each
safety function. This information is critical to the integrator, In addition, this analysis was required as the organization
as it enables the integrator to not only provide a detailed only provides logic solver subsystems and IEC 61511
and constructive proposal to any bid document, but also, tends to focus on the complete SIS. As the organization
if successful, to engineer a solution which meets the had a requirement for its certication scope to include both
safety functions and target safety integrity required. IEC 61508 and IEC 61511 it had to reach an agreement
with its certication body on interpretation of the standards
Guidance is provided in IEC 61508 Part 2 clause 7.2.3 in specic areas. This resulted in a memorandum of
regarding the content of the Safety Requirements understanding providing interpretation and clarication.
Specication. This is strengthened, for the process
industry, in IEC 61511 part 1 clause 10.3.1. In the absence
of an SRS at the bid and proposal phase, the integrator

7
ABB Value Paper Series

For example: codes of accepted good practice which affect their work,
IEC 61511, Part 1, clause 15.1.1 states that SIS together with knowledge of working practices in similar
Validation is also referred to as Site Acceptance Test establishments and awareness of current developments
(SAT) which is undertaken on the complete SIS. However in their eld.
in the context of the integrator, Site Acceptance Test
(SAT) is an activity performed by the integrator on the Against this background the case study company
customers site, following Factory Acceptance Test established processes for both organizational and
(FAT) on the logic solver (and not the complete SIS) and individual competence. The ability to demonstrate that the
after delivery of the logic solver to site organization had competent functional safety staff called
for the establishment of a functional safety competence
IEC 61511, Part 1, 15.2.2, software validation can be scheme. This competence scheme was based on four
interpreted as applying to the SIS. In the context of the attributes:
integrator software validation is included in the Factory
Acceptance Test (FAT) on the logic solver itself, and not 1. Knowledge
the complete SIS which is out of the scope of supply 2. Experience
3. Training
IEC 61511, Part 1, Clause 13.1 refers to Factory 4. Qualications
Acceptance Test (FAT) and states that Factory
Acceptance Test (FAT) is sometimes referred to as One of the objectives of the CSA was set to establish
integration test and part of validation. In the context of a group of functional safety practitioners within the
the integrators Factory Acceptance Test (FAT) this is a organization.
separate activity from integration test and is undertaken
on the logic solver itself Strategic Competency Principle (c) (see section 3)
addresses training (attribute 3) in functional safety and
specic safety platforms. The CSA chose a respected
5.0 Specifying competency requirements third party specialist as the provider of training leading to
There is an increasing trend in the marketplace for TUV certied functional safety engineer status.
client organizations to demand formal evidence of the
competency of those providers of safety-related products The other three attributes above on which the competence
and services. Many of these requirements are colloquially of persons was based, namely knowledge, experience and
referred to as one liners (for example must have qualications, were addressed through the development
competent people or must have certied engineers), and introduction of a Competence Management System
and it is clear in many cases that the originators of such (CMS).
statements do not fully understand the requirement or
how to respond to questions relating to what is exactly The CMS introduced a further level of competence specic
meant by such statements. to functional safety, over and above that required by the
companys ISO 9001 QMS. The CMS was based on the
In any well-run organization, staff are required to be UK IEE/BCS Competency Criteria for Safety-related
competent to perform the tasks assigned to them. System Practitioners [6].
Organizations dealing with safety-related systems
increasingly nd that their customers need assurance The key requirement was for all personnel having
that the organizations personnel can be shown to meet responsibilities for specied tasks on a safety-related
the necessary standards of competency. This includes project to have their training, knowledge, experience and
the designers and implementers of such systems. qualications assessed in relation to the particular tasks
Professionals, with responsibility for design and/or for which they were responsible.
supervision, will also, for example, be expected to have a
detailed working knowledge of all relevant legislation,

8
ABB Value Paper Series

Although IEC61508 does not make a direct correlation Level 2:


with the required level of rigour and competence, the Has experience and training to the level of specifying/
following factors were taken into consideration: designing solutions for the systems platform. This is the
The consequences in the event of failure of the minimum level required for the relevant activities of the
Electrical/Electronic/Programmable Electronic (E/E/PE) designers of the system.
safety related system; the greater the consequence,
the more rigorous the specication and assessment of Level 3:
competence. A recognised expert in his/her application of the systems
platform, demonstrated through appropriate combination
The safety integrity levels of the Electrical/Electronic/ of experience, application and training. This is the minimum
Programmable Electronic (E/E/PE) safety related level required for the relevant activities of the reviewers of
system; the higher the safety integrity levels, the more the system.
rigorous the specication assessment of competence.
A set of supplementary guidelines assists those
The novelty of design procedures or application; the undertaking the assessment of an individual in order to
newer or more untried the designs, design procedures produce an assessment prole and the level of competence
or application, the more rigorous the specication and achieved. This information was subsequently recorded in
assessment of competence should be. the competence database.

Previous experience and its relevance to the specic The supplementary guidelines cover such areas as:
duties to be performed and the technology being Engineering knowledge appropriate to the
employed. The greater the required competence levels, industry domain
the closer the t should be between competencies Safety system knowledge applicable to the
developed from previous experience and those required application and technology
for the specic duties to be undertaken. Principles of Functional Safety Assurance
Specifying, witnessing & performing tests
A competence database, in existence at the organization, Transposing safety requirements to design
and used to record the technical capabilities of personnel Analysing design and code (in terms of software and
was used as the basis for personnel selection. That is, hardware architecture and including various forms of
the responsible Project Manager consults the database denition notation)
when assigning resources to a safety-related project, to
ensure that candidates have the necessary experience Completion of the assessment of competence not only
and qualications appropriate to the application area facilitates the mapping of the individuals competence
and technology, as well as knowledge of the legal and to the specic project tasks and activities they are
safety regulatory framework. The classication of the required to perform but also identies those areas where
level of competence achieved, with respect to specic mentoring and supervision is required and any additional
competence, is as follows: training necessary.

Level 1:
Has experience of the system safety platform in
an implementation capacity and / or has attended
appropriate training courses. This is the minimum level
required for the relevant activities of the implementers and
testers of the system.

9
ABB Value Paper Series

6.0 Benchmarking current practice


Strategic Competency Principle a) (see Section 3) called IEC 61511 rather than IEC 61508 was used to develop the
for a gap assessment to be performed of the functional detailed gap assessment methodology, simply because its
safety management system against the requirements of terminology was more readily understood and relevant to
IEC 61508 and IEC 61511 for each of the organizations the case study organization that operates predominantly
integrators involved in functional safety activities. In order in the process sector. The gap assessment methodology
to undertake this task, a gap assessment methodology, was aligned to those phases of IEC 61511 and mapped
based on the CASS (Conformity Assessment of Safety across to the core set of pre-requisites of the organization
Systems) [7] scheme was used. The CASS assessment (see Section 3. 2 Dening the boundaries), namely:
templates were developed to align with clause 6 of IEC
61508 Part 1 and clause 5 of IEC 61511 Part 1.

Table 2 Example Gap Assessment Target of Evaluation


Target of Purpose of TOE IEC 61508 Assessment IEC 61511 Clauses/purpose
Evaluation Clauses/tables prompt list

Competence To dene procedures 1/6.2.1 h) There is evidence 5.2.2.2


assessment for ensuring that that the functional Persons, departments or
process applicable parties Figs 2,3,4 and safety tasks to organisations involved in
involved in any of 1/Table 1 as be done have safety lifecycle activities shall
the overall, E/E/PES framework. been assigned be competent to carry out the
or software safety the competency activities for which they are
lifecycle activities are required for the task accountable.
competent to carry and a gap analysis What evidence is available
out the activities between the demonstrating this
for which they competencies of the Does it take into account,
are accountable; individual allocated specic technology, safety
in particular, the to the task have engineering, regulations,
following should be been undertaken. management and leadership
specied: There is evidence skills, consequences, SIL,
the training of staff of a logical process complexity, novelty
in diagnosing and that documents Knowledge how do you
repairing faults and in who is responsible show this
system testing, for deciding why an Training generally records in
the training of individual has been place (part of ISO9001)
operations staff, the allocated to the Experience traditionally
retraining of staff at task. poorly recorded
periodic intervals; This element will be How are these assessed /
explored in greater recorded / updated
detail within the How are the competency
overall competency needs identied
assessment TOES How is the gap between
(Annexe C) needs and skills assessed /
bridged

10
ABB Value Paper Series

Phase 4 SIS Design & Engineering Pedigree, including a description of the experience,
Phase 9 Verication capability and competence of the certication body
Phase 10 Management of functional safety and its auditors to perform these specic third-party
and functional safety assessment assessments (functional safety management as
and auditing opposed to product assessment)
Phase 11 Safety life-cycle structure and planning
Global presence of the certication body including
A gap assessment module was developed specically for countries in which they operate
each of the above phases.
Whether dependent on agencies in specic countries
For each gap assessment module, and for completeness, and if so their details
all relevant clauses of both standards were reviewed and
a series of gap assessment tables developed to include: Reciprocal arrangements including:
- Memoranda of Understanding (MOR)
Targets of Evaluation (TOE) i.e.) evidence expected - Mutual Recognition Arrangements (MRA)
Summary of the clause
Sub clause reference identier CVs of assessors
Supplementary assessor guidance (Assessor
prompt list) List of organizations including those that have been
Assessor ndings assessed, their scope of assessment and contact
details within the organization
An example is provided in table 2 on the previous page.
Description of:
As a result of performing the gap assessment common - the assessment methodology
areas for improvement were identied, which in turn - the assessment process
helped to prioritize the later development of the functional - guidance notes for the assessed organization
safety management system.
Typical work program (including labor costs) for a
7.0 Selecting the certication body third party functional safety assessment, including
The organization chose to achieve accredited third-party man-days effort
certication as its ultimate goal. Accredited certication
provides transparency, credibility, international recognition, Any current limitations envisaged in undertaking the
objectivity and independent scrutiny. third party assessment program

A short list of accredited certication bodies was Company accounts for the last accounting period
drawn up by the Company Safety Authority (CSA)
and invited to participate in a pre-qualication exercise Organizational structure
to provide information to demonstrate their capability
and competency. It was then necessary to establish an impartial and
independent panel representing the organization to review
The information requested included: the responses resulting in the selection of a global third-
Appropriate evidence of operation as an accredited party accredited certication organization. In the case
certication body including study this was the Company Safety Authority (CSA).
- national accreditation bodies to which accredited
- scope and date of accreditation
- details of applicable standards and certicates
relevant to the accreditation

11
ABB Value Paper Series

8.0 Developing the safety lifecycle model and


functional safety management system
This was the most signicant activity undertaken. It The development of this safety lifecycle model had
followed the gap assessment and entailed dening a in addition to make full use of the existing quality
comprehensive safety lifecycle model mapping the relevant management processes and procedures. Figure 2 below
phases of IEC 61508 [1] and IEC 61511 [2] in respect details the model.
of the core set of pre-requisites described in section 4
Dening the boundaries. This safety lifecycle model was An explanation of the deliverables specied in the model
supported by procedures, framework documents (basic is provided below in sections 8.1 to 8.5.
default information for a safety project to be customized
to meet any specic project variations) and skeletons
(a template consisting of all necessary headers to
be completed).

Figure 2: The Safety Lifecycle Model (see Appendix, page 26 for full version)

12
ABB Value Paper Series

8.1 Design Documentation Firewater pump logic


Evacuation criteria
8.1.1 Functional Design Specication
The Functional Design Specication (FDS) is the key 8.1.3 Boundary Diagram
design document produced by the integrator. It is also The purpose of the Boundary Diagram is to graphically
the key, controlling document for the system design identify which components form part of the Sensor, Logic
and contains all the rationale as to why the design has Solver and Final Element, and is of use as a reference
taken the specied approach. It takes the clients Safety point for the SIL verication report.
Requirement Specication (SRS) as input data, and
develops them through the FDS, detailing the platform Boundary Diagrams are an optional requirement and only
to be used, system layout (often in the form of a system need be produced if they are a requirement / necessity of
block diagram), interfaces, and functional and operational the project.
design considerations. The FDS, once approved, conrms
the basis of design and traceability of the ensuing design 8.2 Verication documentation
to the clients requirements. It also sets up the rollout of
the Hardware Design and Software Design Specications. 8.2.1 Test Plan
The FDS provides the key acceptance criteria for the The Test Plan denes the verication process for the
system Factory Acceptance Testing (FAT), and is used by System. This includes an outline of the tests and test
the integrator to measure the success of the project from criteria, test environment and test phase prerequisites
the results of FAT. necessary to verify and validate the system against the
appropriate reference documents and standards.
8.1.2 Module Design Specication
This is the lowest level of detailed design document Refer to the Review and Conguration Management
produced on the project. The primary function of the Procedure in respect of the verication activities which
Module Design Specication is to show clear design encompass documentation and code reviews.
intent, to communicate that design in a clear fashion,
and to allow for approval before its implementation. The 8.2.2 Module Test Specication
Module Design Specication denes in detail the inputs, Once a software module has been coded, and reviewed,
outputs and functionality for the operation of a particular it is subjected to formal testing dened by the Module Test
software module in pseudo code or structured English. Specication. As many module test specications can be
It will also dene all variables used (global or local), other produced as necessary.
modules called, the result and error conditions, parameters
passed and interfaces/relationships with other modules The functionality of each module will be veried by the
or systems. use of this document and the approved Module Design
Specication specic to the module under test.
The second function of the document is to enable any
trained programmer to code to the programming language 8.2.3 Integrated Test Specication
and standards dened in the document and in accordance The Integrated Test Specication is used to demonstrate
with the relevant project programming standards. The that each application software module produced
approach to the Module Design Specication is of integrates correctly with other software modules and
particular importance where there is more than one interfaces correctly with the system target hardware
programmer on the project team producing modules that and system rmware, all being an integral part of the
affect the overall functionality of the system. deliverable system. Testing will include both functional
safety and non-safety aspects of the system to verify that
Examples of modules are as follows: the system performs its intended functions and does not
Generic analog input module perform unintended functions.
Generic digital output module
Cause and effect mimic

13
ABB Value Paper Series

8.2.4 Factory Acceptance Test Specication


The Factory Acceptance Test Specication is used to Note that the Failure Modes Analysis is an optional
demonstrate to the client that each application software requirement and should only be produced if they are a
module produced integrates correctly with other software requirement/necessity of the project.
modules, and interfaces correctly with the system target
hardware and system rmware, all being an integral part of 8.3 Safety Lifecycle Structure and Planning
the deliverable system. Testing will include both functional Documentation
safety and non-safety aspects of the system, to verify that
the system performs its intended functions and does not 8.3.1 Safety Lifecycle Management Plan
perform unintended functions. The purpose of this document is to demonstrate how the
integrator intends to manage the realization sections of
8.2.5 Site Acceptance Test Specication the safety lifecycle of the project and denes how the user
The Site Acceptance Test Specication is used to manages the subsequent operational and maintenance
demonstrate to the client that the entire system, including parts. This is in order to show its alignment with the
all networks, function correctly after re-assembly and recommendations laid out in IEC 61508 and IEC 61511.
installation on site. In addition the SAT veries that the
software loaded is that which was demonstrated at Compliance with this safety lifecycle management plan,
the FAT stage, this is achieved by functionally testing and thus conformance with the recommendations
specic elements of the control system, previously veried of IEC61508 and IEC61511, is demonstrated by
at the FAT. means of assessment (Functional Safety Audits) and
verication (Module, Integrated and Factory Acceptance
8.2.6 SIL Achievement Report Testing) of the outputs from each phase of the safety
The purpose of the SIL Achievement Report is to lifecycle model.
demonstrate that the system meets the systematic and
hardware fault tolerances required by the SIL specied 8.3.2 Software Conguration
by the Safety Requirements Specication. The SIL Production Log
Achievement Report provides the quantitative evidence The purpose of the software conguration production log
in the form of PFD and architectural constraints (a is to modularize and categorize the software elements,
combination of Hardware Fault Tolerance (HFT) and Safe for example, generic loop types, graphics, and logic. The
Failure Fraction (SFF)). production log is then used to track the progress of each
module as it goes through design, build and stage stages,
8.2.7 Module Failure Modes Analysis according to the safety lifecycle model.
The purpose of the Module Failure Modes Analysis is to
provide a report of the hardware failure modes performed
on the System. 8.3.3 Techniques and Measures
Specication
This analysis attempts to discover and analyze all potential The purpose of this document is to dene the techniques
failure modes of the hardware sub-system, the effects and measures, and where applicable supporting tools,
these failures have on the system, and what measures necessary to align with the requirements of IEC61508,
have been engineered to correct and or mitigate the Part 2 (Annexes A and B) and Part 3 (Annexes A and B) for
failures or effects on the system. each phase of the E/E/PE and Software Safety Lifecycles.
In order to demonstrate compliance to the requirements
The analysis supports the Reliability and Availability of IEC 61508 it was necessary for the organization to
calculations in the SIL Verication Report, in providing specify those techniques and measures used in order to
evidence that the ESD system conforms to the availability avoid and control systematic faults, see IEC 61508 Part
requirement of the SIL, as identied in the Safety 2, clause 7.4.2.2.
Requirement Specication.

14
ABB Value Paper Series

In the case study, this was an extensive exercise. The safety capability of SIL 3. In respect to the techniques and
tables of Techniques and Measures within IEC 61508 measures used, the Highly Recommended HR option
cover the complete E/E/PES and Software Safety was selected and then tables populated with:
Lifecycles. The rst step was to identify only those tables cross references to organization procedures
associated with the integrators core set of pre-requisites certicates of compliance
(see section 3.2 above) related to IEC 61508 Phase 9 and use of certied logic solvers
IEC 61511 Phase 4. Having identied the sub-set of tables
the decision was made to benchmark the assessment of Examples are shown in Tables 3 and 4 below
the organization against the requirements for SIL 3. The
aim of the certication would be to provide the third party A Y in the SIS column within the table against a specic
evidence that the integrator had demonstrated, for the logic technique identies the technique as being selected for
solvers within the scope of the certication, a functional the project.

Table 3 - Recommendations to avoid faults and failures during E/E/PES integration


Technique/measure See IEC SIL1 SIL2 SIL3 SIL4 SILS Techniques and Methods
61508-7
Functional testing B.5.1 HR HR HR HR Y In-house Process Navigator
mandatory mandatory mandatory mandatory
Safety Lifecycle Management Plan

Test Plan

Module Test Specication

Integrated Test Specication

Factory Acceptance Test


Specication
Project Management B.1.1 HR HR HR HR Y ISO9001
Low Low Medium High
Process Navigator

Safety Lifecycle Management Plan


Documentation B.1.2 HR HR HR HR Y Process Navigator
Low Low Medium High
Safety Lifecycle Management Plan
Black box testing B.5.2 R R R R Y Validation and Test Plan
Low Low Medium High
Field experience B.5.4 R R R R N
Low Low Medium High
Statistical testing B.5.3 - - R R N
Low Low Medium High

All techniques marked R in the grey shaded group are replaceable, but at least one of these is required.
For the verication of this sa
NOTE 1 For the meaning of the entries under each safety integrity level, see the text preceding this table.
NOTE 2 The measures in this table can be used to varying effectiveness according to table B.6, which gives examples for low and high effectiveness.
The effort required for medium effectiveness lies somewhere between that specied for low and for high effectiveness.
NOTE 3 The overview of techniques and measures associated with this table is in annex B of IEC 61508-7.
Relevant sub-clauses are referenced in the second column.

15
ABB Value Paper Series

Table 4 Software design and development: support tools and programming language
Technique/measure See IEC SIL1 SIL2 SIL3 SIL4 SILS Techniques and Methods
61508-7
1. Suitable C.4.6 HR HR HR HR Y Certied Control Language, with
programming a subset of function blocks is
language certied for use, constrained by
certied logic solver

Certied Control Language


2. Strongly typed C.4.1 HR HR HR HR Y Certied function blocks are
programming utilized, constrained by certied
language logic solver

Certied Control Language


3. Language subset C.4.2 - - HR HR Y Certied Control Language is a
component of certied logic solver.
Safe subset dictated by the safety
manual and certied logic solver
4a. Certied tools C.4.3 R HR HR HR N Certied Control Language, with
a subset of function blocks is
certied for use. Safe subset
dictated by the safety manual and
certied logic solver

Certied Control Language

4b. Tools: increased C.4.4 HR HR HR HR Y


condence
from use
5a. Certied translator C.4.3 R HR HR HR Y Not used for LVL
5b. Translator: C.4.4 HR HR HR HR Y Certied Control Language has
increased >5 years proven in use
condence
from use
6. Library of trusted/ C.4.5 R HR HR HR Y Only certied function blocks,
veried software or modules constructed from
modules and these blocks, are utilized in this
components application. Refer to the Safety
Manual

* Appropriate techniques/measures s
following the number. Only one of the alternate or equivalent techniques/measures has to be satised.

8.3.4 Operator Manual plant personnel are provided with all relevant information
The Operator Manual is developed from the FDS and the on the maintenance of the System.
Module Design Specications and is written to ensure that
plant personnel are provided with all relevant information The Maintenance Manual makes reference to, and use of,
on the operation of the System. the standard integrator Document Reference Set. This is
a collated set of individual, standard instruction booklets
8.3.5 Maintenance Manual (IBs) for the companys generic Safety system (in the case
The Maintenance Manual is developed from the FDS and of the case study 800xA HI) (which includes the safety
the Module Test Specication and is written to ensure that manual), covering both hardware and software.

16
ABB Value Paper Series

The Maintenance Manual indicates, where applicable, the 8.4.5 Functional Safety Assessment (FSA)
verication tests that the user must undertake to proof Functional Safety Assessments are undertaken in
test the Logic Solver. This includes, but is not limited accordance with the requirements of IEC 61508 Part 1
to, the action to be taken when abnormal conditions are Clause 8.
indicated by the system (either via LED on the module, or
software diagnostic). In the case study, the CSA acted as the Independent
Department in performing functional safety assessments
The Maintenance Manual provides information to the of the integrators safety-related projects in accordance
end user to enable them to ensure functional safety with the requirements of IEC 61508 Part 1, Table 5 for
performance is maintained. Safety Integrity Level (SIL) 3. An assessor drawn from
the CSA plans, schedules and executes these functional
8.4 Management of Functional Safety safety assessments in accordance with a CSA procedure
Documentation (Functional Safety Assessment Process).

8.4.1 Query/Change Procedure Acting as an Independent Department for undertaking


The Query/Change Procedure provides guidance in the FSAs enables the CSA to perform a similar role for other
use of project queries, and denes the impact assessment business units within the organization planning for future
form to be used to assess each change or variation to the accredited certication.
Safety Instrumented System.
The FSA should provide, amongst other things,
8.4.2 Review and Conguration condence that the following have been achieved:
Management Procedure The safety instrumented system logic solver is
The Review and Conguration Management Procedure designed, constructed, veried and tested in
ensures that, through review and assessment, application accordance with the safety functional design
software code and supporting documentation is produced specication; any differences have been identied
to be consistent, maintainable, of acceptable quality, and resolved
satisfying user requirements, and is safe. The safety instrumented system logic solver validation
planning is appropriate and the validation activities
8.4.3 Project Competency have been completed
Assessment Procedure Project design change procedures are in place and
The purpose of the Project Competency Assessment have been properly applied
Procedure is to provide a formal means of assessing SIL capability achieves the SIL target requirements
personnel involved in any Safety Lifecycle Electric Regulations, mandatory standards and any stated
/ Electronic / Programmable Electronic Systems codes of practice have been met
(E/E/PES) and software activities, to ensure that they Where development and production tools are used
possess the necessary experience, knowledge, training they shall be included in the FSA
and qualications to carry out the activities for which they Adequate and complete documentation is provided
are accountable and, where necessary, to identify any
additional training requirements. At least one Functional Safety Assessment (FSA) is
performed during the projects safety lifecycle. The FSA is
8.4.4 Functional Safety Audit Procedure split into three phases:
The purpose of the Functional Safety Audit Procedure is Preliminary FSA trigger point completion of Safety
to provide additional guidance to the project auditors in Lifecycle Management Plan
order to verify correct implementation. Design FSA trigger point completion of Functional
Design Specication
Final FSA trigger point completion of Factory
Acceptance Test

17
ABB Value Paper Series

Additional FSAs may be required depending on criteria Safety regulatory requirements


such as: Degree of complexity
Duration of project
Number of safety systems implemented within the Each phase of the FSA is supported by checklists drawn
project directly from IEC 61508 and designed to assist the
assessment team in ensuring that the FSA is conducted
in accordance with the requirements of the standard.
Table 5 Example of a Final FSA checklist
Item Clause Objectives & Requirements Recommendation
Accept (A); Reject (R);
Qualied Acceptance (QA);
Not Applicable (NA)
1 IEC 61508-1 5.1 Objectives
Clause 5 5.1.1 The rst objective of the requirements of this clause is to specify the
Documentation necessary information to be documented in order that all phases of the
overall, E/E/PES and software safety lifecycles can be effectively performed.
5.1.2 The second objective of the requirements of this clause is to specify the
necessary information to be documented in order that the management
of functional safety (see clause 6), verication (see 7.18) and the functional
safety assessment (see clause 8) activities can be effectively performed.

Assessor Note: In respect of the Preliminary FSA this will seek evidence that the
key deliverables are identied within the SLMP and the SLMP has itself undergone
formal review and approval. During the Design and Final FSA the results of the
functional safety audits will be reviewed.

1.1 IEC 61508-1 5.2.1 The documentation shall contain sufcient information, for each phase of
Clause 5.2 the overall, E/E/PES and software safety lifecycles completed, necessary for
Requirements effective performance of subsequent phases and verication activities.
5.2.2 The documentation shall contain sufcient information required for the
management of functional safety (clause 6).
5.2.3 The documentation shall contain sufcient information required for the
implementation of a functional safety assessment, together with the
information and results derived from any functional safety assessment.
5.2.4 Unless justied in the functional safety planning or specied in the application
sector standard, the information to be documented shall be as stated in the
various clauses of this standard.
5.2.5 The availability of documentation shall be sufcient for the duties to be
performed in respect of the clauses of this standard.
5.2.6 The documentation shall be
accurate and concise;
be easy to understand by those persons having to make use of it;
suit the purpose for which it is intended;
be accessible and maintainable.
5.2.7 The documentation or set of information shall have titles or names indicating
the scope of the contents, and some form of index arrangement so as to
allow ready access to the information required in this standard.
5.2.8 The documentation structure may take account of company procedures and
the working practices of specic application sectors.
5.2.9 The documents or set of information shall have a revision index (version
numbers) to make it possible to identify different versions of the document.
5.2.10 The documents or set of information shall be so structured as to make it
possible to search for relevant information. It shall be possible to identify the
latest revision (version) of a document or set of information.
5.2.11 All relevant documents shall be revised, amended, reviewed, approved and
be under the control of an appropriate document control scheme.

18
ABB Value Paper Series

Table 5 (see page 18) provides an example of a checklist species for each stage of the project, its inputs, outputs
to be used during the nal FSA. The white cells are the and review responsibilities. The intention is that each
clauses from the standard setting out the objectives to integrator will populate the business process model
be achieved whereby compliance will be measured reference and activity references with local procedures. An
and ndings recorded. The blue cells are the clauses extract of the Activity Plan is provided in Table 6 below.
from the standard setting out the requirements to meet
the objectives. Although Activity Plan activities are in their respective
logic sequence, this does not constitute the actual order
8.5 Safety Project Activity Plans in which activities may be completed. Therefore reference
The project safety lifecycle model, as dened above, should be made to each specic safety project schedule.
is further supported by a detailed Activity Plan, which

Table 6 Safety Project Activity Plan


Activity Business Activity Activity Acceptance Prime Activity Inspection schedule
Number Process related criteria responsibility deliverable
Model procedure or for activity
reference document ABB Client VB

1.12 Preparation, Safety Conformity to SIS Lead Client H A R


Submission, Lifecycle ABB quality Engineer Approved
Review and Management system Project Project
up-date of Plan requirements Manager Competency
Competency Independent Assessment
Assessment Review and Verication Procedure
Procedure Conguration Body
Management
Procedure

1.13 Assessment of Project Conformity Project Completed H R R


Safety Team Competency to Safety Manager Safety Team
Members Assessment Lifecycle Independent Member
Procedure Management Verication Assessment
Plan Body Forms
1.14 Preparation, Safety Conformity to SIS Lead Client A A R
Submission, Lifecycle ABB quality Engineer Approved
Review and Management system Project Query/Change
up-date of Plan requirements Manager Procedure
Query/Change
Procedure Review and Independent
Conguration Verication
Management Body
Procedure

1.15 Preparation, Safety Conformity to SIS Lead Client A A R


Submission, Lifecycle ABB quality Engineer Approved
Review and Management system Project Review and
up-date of Plan requirements Manager Conguration
Review and Management
Conguration Review and Independent Procedure
Management Conguration Verication
Procedure Management Body
Procedure

Further clarication of some of the cells is provided on the following page

19
ABB Value Paper Series

Verication Body (VB) W: Witness Point


Verication is only applicable to those activities within This is an inspection or test that may be as important
the Quality Plan that relate to the design, hardware build, as a hold point (and must be notied to the client), but
software conguration, functional test and validation of which can be responsibly carried out after the point has
safety-related systems, that is Phase 9, Realization, of been passed.
the Safety Lifecycle recommended by IEC61508 and
IEC61511, and Phase 4, SIS design and engineering Witness points may be attended by the client, but
within IEC61511. authorization from the client is not required to allow work
to proceed beyond that point (following expiry of the
The eld marked VB is used to indicate (and demonstrate seven days notice).
to the client or Verication Body (VB)) that each applicable
activity has been formally assessed and veried in terms M: Monitor Point
of meeting the required Safety Integrity Level (SIL), for the This is a point in the programme of work where a check
particular item of safety-related equipment, to which the may be made to verify that a specied action has taken
activity relates. place, and that the correct documentation records exist.
Such checks can be retrospectively made.
The Verication Body will be a person that has the required
competency, skills and independence from the project to A: Approval Point
undertake the assessment of the particular activity. In line (documentation and/or records)
with the recommendations of IEC61511, Independence is Approval points are those which require documentation
dened as follows: and/or records to be reviewed and approved by the
integrator and the client, and beyond which work cannot
Independent Person a competent person who is proceed until the appropriate approval is given.
separate and distinct from the activities which take place
during the specic phase of the safety lifecycle and does R: Review Point
not have direct responsibility for those activities Review points are where design reviews and / or
walkthroughs are to be performed for the specied activity
Inspection Schedule Codes or activities that require verication.
The inspection / documentation schedule codes listed
in the Activity Plan are dened as follows: Review points may be attended by the client, but
authorization from the client is not required to allow work
H: Hold Point to proceed beyond that point (following expiry of the
This is an inspection or test that is considered vital to seven days notice).
the quality and integrity of the equipment and services
being supplied. Full adherence to the safety lifecycle model required the
development of a set of supporting procedures, framework
A hold point cannot be passed unless the specied documents and skeletons dened below. Tables 7, 8, 9
acceptance criteria have been met (unless a concession is and 10 provide titles for all of these additional documents
raised and approved). Where a hold point is also specied including those specic to the integrators QMS.
by the client, the point cannot be passed without written
authorization from the client.

20
ABB Value Paper Series

Table 7 QMS Document list Table 9 Supplementary FSMS specic


Skeletons Document list
New Supplier Assessment
Contract Review and Order Processing Functional Design Specication
Internal Kick-off Meeting Preparation Software Design Specication
Quality Plan/Safety Plan Module Test Specication
Query Management Process Integrated Test Specication
Conguration Management Factory Acceptance Test Specication
Competency and Training Work Practice Site Acceptance Test Specication
Complete Functional Description Operator Manual
Software Production Maintenance Manual
Complete Test Specication FMEA
Module Test Boundary Diagrams
Integrated Test
Factory Acceptance Test
Management System Audits
Bid and Proposal Guideline Table 10 FSMS Framework Documents
Safety Requirements Checklist
Product Alert Handling Safety Lifecycle Management Plan
Management System Review Software Production Log
Techniques and Tools
Verication and Test Plan
SIL Verication Report
Table 8 Supplementary FSMS Document list

Functional Safety Management System Overview


Functional Safety Policy (UK-SEC)
Project Competency Assessment
Project Competency Assessment Form
Review and Conguration Management
Document Review Form
Code Review Form
Project Query Handling Supplementary Instruction
& Guideline
Query Change Impact Analysis Form
Functional Safety Audit & Assessment Procedure
Safety Lifecycle Management Plan
Software Production Log
Techniques and Tools
Verication and Test Plan
SIL Verication Report

21
ABB Value Paper Series

9.0 Executing the certication process 9.1 Training in Functional Safety Management
A generic certication process model is necessary for and Recommended Lifecycle Procedures
the integrators to identify roles and responsibilities of all The purpose of this training module is to present the
parties. It is also used as the basis for the CSA Assessor recommended safety lifecycle model, FSMS procedures
to provide support and consultancy to each integrator in and specic examples to the integrator such that they
order to assist them to achieve certication. have a clear understanding of the intent and purpose of
the FSMS and its implementation within their organization.
The model shown below was used during the This allows the integrator to develop their local
case study. procedures based on a working model. It will also cover
the certication process and alignment to IEC 61508 and
IEC 61511. (See section 10 below for a description of the
training modules).
Complacency
Principle A
Strategic

Perform gap Gap Assessment


Assessment Report
At the conclusion of the training module, the integrator
is presented with a copy of the training material, the
Produce
recommended safety lifecycle model, and the suite of
Implementation
Program generic procedures. (See section 3.8).

Appoint Project
9.2 Advise on development / deviations for
CSA
Recommended
Manager
Champion integrators use of procedures
Lifecycle Model
REMOTE & SITE
Training in
Develop
REMOTE & SITE
Advise on Local Functional Safety
The CSA provides advice to the integrator on the
implementation of the FSMS, development of their own
Functional Safety
Standards Model Managment
Managment &
Template and Development & System
Recommended
Procedures Deviations
Lifecycle
CSA
Recommended
Proceduresdd1 2
FSMS procedures and answers technical queries on
Functional Safety
Procedures
REMOTE
XXXXX XXX
Certification Body
SITE
Certification Body procedures, templates and other documents.
Assessment &
Agree Program Awareness &
and Place Checklist
Contract 3 Completioneee4
Strategic Complacency Principle B

SITE REMOTE
The integrator then has the option of making alterations to
Training in SL
Achievement &
Issue Completed
Checklists to
Certification Body
Gap Assessment the generic suite of FSMS procedures to align with existing
Functional Safety Certification Body and Review
Assessment
5 6
at FSMS
requirements and local business systems. The CSA will
provide advice on the impact of these deviations on the
Certification Body
Identify Pilot
Project
Gap Assessment
and Review FSMS and the recommended certication process.
at FSMS

SITE
Perform
9.3 Liaison with the Certifying Authority
The CSA directly liaises with the certication body to
Functional Safety Pilot Project Certification Body
Assessment Implementation Pre-Audit

7
agree a formal program of work and place a contract on
SITE
Key
Pre-Certification
behalf of the organization for the agreed scope of work.
The scope and program is conrmed and agreed with the
Body Audit
CSA
Activity
8

Local Organisation
organization prior to order placement.
Activity
Certification Body Certification Body

9.4 Certication Body Assessment


Audit Audit Report
Certification Body
Activity

UK CSA Call off


Awareness and Checklist Completion
Activity Corrective Action
Program The purpose of this training module is to provide the
organization with an overview of the certication bodys
Certification own detailed certication process.

Figure 3: The Certication Process (see Appendix, page 25 for larger version) Following on from the training module, the CSA and the
integrator prepare the certication bodys compliance
checklists (including any deviations), which are required
as part of the certication process.

22
ABB Value Paper Series

Once completed, the CSA will issue the checklists to the In the case study, these technical training courses were
certication body Lead Assessor for review. At the same delivered to the organization with a period of six weeks
time, the organization will issue its FSMS procedures to separating them. The contents of these courses are set
the certication body. In parallel, the integrator identies out below:
a pilot project or projects to demonstrate that the
safety lifecycle and FSMS is being implemented in 10.1 Functional Safety Management &
its entirety. The pilot project(s) will be audited by the recommended lifecycle procedures
certication body. A two day course consisting of the following topics:
The certication process
9.5 Training in SIL Achievement and Overview of IEC 61508 and IEC 61511
Functional Safety Assessment Functional Safety Management and links to QMS
The purpose of this training module is to provide the Safety lifecycle planning and management the safety
integrator with a detailed understanding of the methodology lifecycle model, inputs, outputs, deliverables
adopted in order to prepare a SIL Achievement Report Requirements and design
for a safety project. This will include several worked Overview of SIL Achievement
examples, and prepare the safety engineers for the pilot Verication & Validation
project implementation. Functional safety audit and functional
safety assessment
The training module will also address the scope and Course exercises
purpose of Functional Safety Assessments and Audits,
and commence development of a plan of the assessment 10.2 SIL achievement & Functional
activity for the pilot project (see section 10, page 28). Safety Assessment
A 1.5 day course consisting of the following topics:
9.6 Perform Functional Safety Assessment Safety function and safety integrity requirements
As part of the CSAs responsibilities, a functional safety Design essentials of IEC 61508, hardware safety
assessment is performed on the pilot project. integrity and systematic safety integrity
SIL compliance to IEC 61508
9.7 Pre-Certication Body Audit SIL achievement procedure, worked example
In order to ensure the success of the certication site and exercise
audit, the CSA will perform a pre-audit to identify any Functional safety assessments in the context of
potential risks or omissions from the FSMS and/or the SIL achievement
pilot project. This gives the integrator the opportunity to
correct these deciencies before the ofcial certication 11.0 Establishing Supporting activities
audit, hence ensuring that the certication audit results in Prior to and during the case study, there was already
a successful outcome. in place a large internal company network of safety
practitioners with different safety objectives and operational
10.0 Training courses safety standards.
Technical training was an essential part of the
implementation program and the competency Other internal businesses had developed future plans
management system for the organization. Training is one for certication.
of the four attributes of competence (see Section 5). Two
technical training courses were developed by the CSA Consequently it was essential to establish, at an
suitable for delivery to business units working to the core early stage in the process, a common repository for
set of the pre-requisites earlier dened (see Section 4). information exchange.

23
ABB Value Paper Series

This was achieved in the form of a Safety Database The case study described above provides details relating
containing the following information: to implementation of an organizations generic processes,
Third-party certicates of safety products methodologies and procedures and then how these were
Lists of certied functional safety engineers and applied to a specic safety integration group within the
functional safety technology engineers organization. It outlines a step-wise approach covering:
Improvement themes Strategy
Technical papers and articles Benchmarking and gap assessment
Latest FSMS procedures Developing the functional safety management system
External functional safety standards Selecting the certication body
Sales and technical product material Implementing the functional safety
Case study progress and program updates management system
Rolling out the certication process
12.0 Managing channel partners and
third-party integrators Successful implementation of a certication program
The same rigorous approach to functional safety had to provided advantages to the organization, not least:
apply to any third-party integrators being used by any of Limiting the companys exposure to potential liabilities
the companys integrators. This ensured the safety and Demonstrating due diligence
quality of the third-party integrator. A program of work Implementing repeatable and cost effective
was required to perform a gap assessment on third- safety management systems (procedures,
party integrators and to subsequently work with them to techniques, tools etc)
ensure that they developed a compliant functional safety Reducing unnecessary and costly pre-contract
management system, preferably in line with that of the main discussions and evidence gathering actually
system vendor. This process has been seen to benet the beneting both the organization and its clients
third-parties in that they can also achieve certication and Winning work cost effectively
capitalize on the achievement in the safety market place. Limiting effort (and cost) in developing so-called
bespoke project safety procedures
13.0 Final Comments and Conclusions Gaining competitive advantage and as a result
The international safety market is undergoing many securing more business
changes driven by technology, standards, legislation and
incidents. Those organizations working in this demanding The author hopes that the information provided in this
and highly competitive arena seek to differentiate chapter will benet other organizations and individuals
themselves, secure market advantage and demonstrate with an interest in functional safety management
competence and due diligence. Many organizations see and certication.
accredited certication of the organization as a positive
step forward.

Accredited certication for an organization is a signicant


undertaking. It requires management commitment at
the highest level in addition to a comprehensive work
program involving not only that part of the organization
selected for certication, but other groups within the
organization itself.

24
ABB Value Paper Series

Appendices Complacency
Principle A
Strategic

Perform gap Gap Assessment


Assessment Report

Produce
Implementation
Program

Appoint Project
Manager
Champion
CSA
Recommended
Lifecycle Model
REMOTE & SITE
REMOTE & SITE
Training in
Develop Advise on Local Functional Safety
Functional Safety
Standards Model Managment
Managment &
Template and Development & System
Recommended
Procedures Deviations
Lifecycle
Proceduresdd1 2
CSA
Recommended
Functional Safety REMOTE SITE
Procedures XXXXX XXX Certification Body
Certification Body Assessment &
Agree Program Awareness &
and Place Checklist
Contract 3 Completioneee4
Strategic Complacency Principle B

SITE REMOTE
Training in SL Issue Completed Certification Body
Achievement & Checklists to Gap Assessment
Functional Safety Certification Body and Review
Assessment at FSMS
5 6

Certification Body
Identify Pilot Gap Assessment
Project and Review
at FSMS

SITE
Perform
Functional Safety Pilot Project Certification Body
Assessment Implementation Pre-Audit

SITE
Key
Pre-Certification
Body Audit
CSA
Activity
8

Local Organisation
Activity
Certification Body Certification Body
Audit Audit Report
Certification Body
Activity

UK CSA Call off


Activity Corrective Action
Program

Certification

Figure 3: The Certication Process (referred from page 22)

25
ABB Value Paper Series

Figure 2: The Safety Lifecycle Model (referred from page 12)

26
ABB Value Paper Series

27
ABB Value Paper Series

References

[1] IEC 61508 Functional safety of electronic/electrical/programmable electronic safety-related systems

[2] IEC 61511 Functional safety Safety instrumented systems for the process sector

[3] Recommendations on the design and operation of fuel storage sites; Bunceeld Major Incident Investigation Board:
http://www.bunceeldinvestigation.gov.uk/reports/recommendations.pdf

[4] The Report Of The BP U.S. Reneries Independent Safety Review Panel (concerning the Texas City incident).
http://www.csb.gov/completed_investigations/docs/Baker_panel_report.pdf

[5] IEC 61131 Programmable Controllers

[6] Safety, Competency & Commitment - Competency Guidelines for Safety-Related System Practitioners 1999
(ISBN 0 85296 787 X)

[7] CASS Conformity Assessment of Safety-related Systems certication scheme - Functional Safety Capability
Assessment (FSCA)

28
ABB Value Paper Series

About the author


Stuart R Nunns CEng, BSc, Nunns is a TUV Functional Safety Expert and member of
FIET, FInstMC - Principal the IET Functional Safety Professional Network Executive
Safety Consultant ABB Ltd Group and the InstMCs Safety Panel. He has written and
presented papers and led international safety-related
Stuart Nunns has thirty-six systems workshops. He was project manager of both the
years experience in automation CUIG (Framework IV) European safety group and the F/W
and safety within the oil & gas, V SIPI61508 EC Framework V project developing guiding
chemical, steel and electricity principals for the implementation of IEC 61508.
generation sectors and is a
Principal Consultant within the Within the UK he was the instigator and project manager
Safety Lead Competency Centre of ABBs Process of the CASS (conformity assessment of safety systems
Automation Division. Nunns is a member of ABBs Safety to IEC 61508) scheme and served as a Director of
Steering Team, responsible for identifying and managing CASS Ltd.
the development of functional safety products and
services, mapping the total safety lifecycle. He is currently
leading a global work program within ABB to establish
TUV certied Safety Execution Centres.

29
ABB Value Paper Series

Notes

30
ABB Value Paper Series

Notes

31
3BUS094519
www.abb.us 2008 ABB Inc.
US Creative Services 1260

You might also like