Results of the IEC Functional Safety Assessment. ABB, Inc. Baton Rouge, LA USA

Size: px
Start display at page:

Download "Results of the IEC Functional Safety Assessment. ABB, Inc. Baton Rouge, LA USA"

Transcription

1 Results of the IEC Functional Safety Assessment Project: MT5000, MT5100 and MT5200 Level Transmitter Customer: ABB, Inc. Baton Rouge, LA USA Contract No.: Q Report No.: ABB R001 Version V3, Revision R1, November 1, 2016 Gregory Sauk - David Butler The document was prepared using best effort. The authors make no warranty of any kind and shall not be liable in any event for incidental or consequential damages in connection with the application of the document. All rights reserved.

2 Management Summary The Functional Safety Assessment of the ABB, Inc. MT5000, MT5100 and MT5200 Level Transmitter development project, performed by exida consisted of the following activities: - exida assessed the development process used by ABB, Inc. through an audit and review of a detailed safety case against the exida certification scheme which includes the relevant requirements of IEC The assessment was executed using subsets of the IEC requirements tailored to the work scope of the development team. - exida reviewed and assessed a detailed Failure Modes, Effects, and Diagnostic Analysis (FMEDA) of the devices to document the hardware architecture and failure behavior. - exida reviewed field failure data to verify the accuracy of the FMEDA analysis. The functional safety assessment was performed to the SIL 3 requirements of IEC 61508:2010. A full IEC Safety Case was created using the exida Safety Case tool, which also was used as the primary audit tool. Hardware and software process requirements and all associated documentation were reviewed. Environmental test reports were reviewed. The user documentation and safety manual also were reviewed. The results of the Functional Safety Assessment can be summarized by the following statements: The audited development process, as tailored and implemented by the ABB, Inc. MT5000, MT5100 and MT5200 Level Transmitter development project, comply with the relevant safety management requirements of IEC SIL 3. The assessment of the FMEDA, done to the requirements of IEC 61508, has shown that the MT5000, MT5100 and MT5200 Level Transmitter can be used in a low demand safety related system in a manner where the PFD AVG is within the allowed range for SIL 2 (HFT=0), according to table 2 of IEC The assessment of the FMEDA also shows that the MT5000, MT5100 and MT5200 Level Transmitter meets the requirements for architectural constraints of an element such that it can be used to implement a SIL 2 safety function (with HFT = 0) or a SIL 3 safety function (with HFT = 1). This means that the MT5000, MT5100 and MT5200 Level Transmitter is capable for use in SIL 3 applications in Low demand mode when properly designed into a Safety Instrumented Function per the requirements in the Safety Manual and when using the versions specified in section 3.1 of this document. T-034 V5R1 80 N. Main St, Sellersville, PA Page 2 of 21

3 The manufacturer will be entitled to use the Functional Safety Logos. Manufacturing Facilities are located in Prairieville, LA and Shanghai, China. T-034 V5R1 80 N. Main St, Sellersville, PA Page 3 of 21

4 Table of Contents Management Summary Purpose and Scope Tools and Methods used for the assessment Project Management exida Roles of the parties involved Standards / Literature used Reference documents Documentation provided by ABB, Inc Documentation generated by exida Assessment Approach Product Description Hardware and Software Version Numbers IEC Functional Safety Assessment Scheme Product Modifications Results of the IEC Functional Safety Assessment Lifecycle Activities and Fault Avoidance Measures Functional Safety Management Safety Requirement Specification Change and modification management Hardware Design and Verification Hardware Design Hardware Design / Probabilistic properties Software Design Verification Safety Validation Safety Manual IEC Functional Safety Surveillance Audit Roles of the parties involved Surveillance Methodology Documentation provided by ABB, Inc Surveillance Documentation generated by exida Surveillance Results Procedure Changes Engineering Changes Impact Analysis Field History T-034 V5R1 80 N. Main St, Sellersville, PA Page 4 of 21

5 6.3.5 Safety Manual FMEDA Update Previous Recommendations Terms and Definitions Status of the document Liability Version History Future Enhancements Release Signatures T-034 V5R1 80 N. Main St, Sellersville, PA Page 5 of 21

6 1 Purpose and Scope This document shall describe the results of the IEC functional safety assessment of the: Model Descriptions MT5000 Guided Wave Radar Level Transmitter MT5100 MT5200 Guided Wave Radar Level and Interface Transmitter Guided Wave Radar Bulk Solids Level Transmitter by exida according to the accredited exida certification scheme which includes the requirements of IEC 61508:2010. The purpose of the assessment was to evaluate the compliance of: - the MT5000, MT5100 and MT5200 Level Transmitter with the technical IEC and -3 requirements for SIL 3 and the derived product safety property requirements and - the MT5000, MT5100 and MT5200 Level Transmitter development processes, procedures and techniques as implemented for the safety-related deliveries with the managerial IEC , -2 and -3 requirements for SIL 3. and - the MT5000, MT5100 and MT5200 Level Transmitter hardware analysis represented by the Failure Mode, Effects and Diagnostic Analysis with the relevant requirements of IEC The assessment has been carried out based on the quality procedures and scope definitions of exida. The results of this assessment provide the safety instrumentation engineer with the required failure data per IEC / IEC and confidence that sufficient attention has been given to systematic failures during the development process of the device. 1.1 Tools and Methods used for the assessment This assessment was carried out using the exida Safety Case tool. The Safety Case tool contains the exida scheme which includes all the relevant requirements of IEC 61508:2010. For the fulfillment of the objectives, expectations are defined which builds the acceptance level for the assessment. The expectations are reviewed to verify that each single requirement is covered. Because of this methodology, comparable assessments in multiple projects with different assessors are achieved. The arguments for the positive judgment of the assessor are documented within this tool and summarized within this report. All assessment steps were continuously documented by exida (see [R3]) T-034 V5R1 80 N. Main St, Sellersville, PA Page 6 of 21

7 2 Project Management 2.1 exida exida is one of the world s leading accredited Certification Bodies and knowledge companies, specializing in automation system safety and availability with over 300 years of cumulative experience in functional safety. Founded by several of the world s top reliability and safety experts from assessment organizations and manufacturers, exida is a global company with offices around the world. exida offers training, coaching, project oriented system consulting services, safety lifecycle engineering tools, detailed product assurance, cyber-security and functional safety certification, and a collection of on-line safety and reliability resources. exida maintains a comprehensive failure rate and failure mode database on process equipment based on 100 billion hours of field failure data. 2.2 Roles of the parties involved ABB, Inc. Transmitters exida exida Manufacturer of the MT5000, 5100 and MT5200 Level Performed the hardware assessment [R3] Performed the Functional Safety Assessment [R1] per the accredited exida scheme. ABB, Inc. contracted exida with the IEC Functional Safety Assessment of the above mentioned devices. 2.3 Standards / Literature used The services delivered by exida were performed based on the following standards / literature. [N1] IEC (Parts 1-3): 2010 Functional Safety of Electrical/Electronic/Programmable Electronic Safety-Related Systems 2.4 Reference documents Documentation provided by ABB, Inc. [D1] QM-0001D, Rev D, 10/13/2011 [D2] QMP-0003K, Rev K, 8/19/2011 [D3] QMP-0008D, Rev D, 1/17/2012 [D4] QMP-0010D, Rev D, 9/13/2012 [D5] QMP-0018C, Rev C, 11/27/2012 [D6] QMP-0023G, Rev G, 9/13/2012 K-TEK Corporation Quality Manual Quality Management Plan Procedure, Control of Documents Quality Management Plan Procedure, Design & Development Quality Management Plan Procedure, Supplier Selection and Evaluation Quality Management Plan Procedure, Control and Monitoring of Measuring Devices Quality Management Plan Procedure, Control of Nonconforming Products T-034 V5R1 80 N. Main St, Sellersville, PA Page 7 of 21

8 [D7] QMP-0026, Rev A, 3/26/2007 [D8] PRC0077, Rev A, 4/3/2008 [D9] PRC0078, Rev A, 5/6/2008 [D10] PRC0079, Rev A, 4/29/2008 [D11] PRC0080, Rev A, 3/28/2008 [D12] PRC0081, Rev NC, 4/22/2008 [D13] PRC0082, Rev A, 4/7/2009 [D14] FRM-0708, Rev B, 5/2/2008 [D15] PNP , Rev NC, 4/15/2008 [D16] FRM-0008, Rev NA, 2/26/2008 [D17] PNP PL, Rev NC, 4/15/2008 [D18] PNP , Rev NC, 4/22/08 [D19] PNP , Rev NC, 4/24/2008 [D20] PNP , Rev NC, 4/24/08 [D21] PNP , Rev NC, 5/6/2008 [D22] PNP , Rev NC, 4/29/2008 [D23] PNP A, Rev A, 5/6/2008 [D24] PNP , Rev NC, 4/22/2008 [D25] PNP , Rev NC, 4/21/2008 [D26] PNP , Rev NC, 4/29/2008 [D27] PNP , Rev NC, 4/29/2008 [D28] PNP , Rev NC, 4/2/2008 [D29] PNP , Rev NC, 3/31/08 [D30] PNP , Rev NC, 4/2/2008 [D31] PNP , Rev NC, 4/24/2008 [D32] PNP , Rev NC, 4/22/2008 [D33] FRM-0708B , 8/6/2010 Quality Management Plan Procedure, Corrective and Preventive Action Quality Procedure, Software Coding & Style Guidelines Quality Procedure, Software Design & Development Procedure Quality Procedure, Functional Safety Management Plan Quality Procedure, Safety Requirements Review Checklist Quality Procedure, Safety Critical Tools Qualification Quality Procedure, R&D Group Qualification Record Design Project Records Template for General Arrangement Drawings New Product Release Checklist Top Level Parts List Construction Table Template Template for Safety Requirements Specifications Template for Integration & Validation Test Plan Template for Functional Safety Documentation Checklists Template for Impact Analysis Template for Modification & Change of Design Project Records Template for Architecture Design Overview High Level UML & Sub Assemblies Template for Hardware Design Template for Software Configuration Record Template for Software Design Review Template for Software & Critical Code Review Template for Architecture Design & SW HW Interface Review Template for Safety Requirements Review per PRC0080 Checklist Template for Safety Integration & Validation Test Plan Review Template for Safety Manual Review Template for Integration & Validation Testing MT5000 Design Project Records T-034 V5R1 80 N. Main St, Sellersville, PA Page 8 of 21

9 [D34] MT , Rev F, February 2009 [D35] MT , Rev F, February 2009 [D36] MT , Rev E, January 2008 [D37] MT , Rev A, April 2009 Data Sheet, MT5000 Data Sheet, MT5100 Data Sheet, MT5200 Installation and Operational Manual, MT5000 [D38] MT f, Rev E, 4/1/2010 MT5000 Series IOM/Safety Manual (Draft) [D39] MT , Rev NC, September 2005 [D40] MT , Rev A, March 2009 [D41] MT , Rev NC, 5/3/2010 [D42] MT , Rev A, 6/14/2010 [D43] MT , Rev NC, 5/25/2010 [D44] MT , Rev NC, 3/8/2010 [D45] MT , Rev NC, 6/10/2010 [D46] MT , Rev NC, 6/22/2010 [D47] MT , 8/11/2010 [D48] MT , Rev NC, 6/8/2010 [D49] MT , Rev NC, 5/20/2010 [D50] MT , Rev NC, 2/20/2010 [D51] MT , Rev NC, 6/20/2010 [D52] MT , Rev NC, 5/24/2010 [D53] MT , Rev NC, 5/5/2010 [D54] MT , Rev NC, 6/20/2010 Installation and Operational Manual, MT5100 Installation and Operational Manual, MT5200 MT5000 Series General Specifications Requirements MT5000 Series Safety Requirements Specification MT5000 Series Level Transmitters Integration and Validation Test Plan MT5000 Series SIL 2 Project Plan (Phase 1) MT5000 Series Modification Impact Analysis MT5000 Series Modification Impact Analysis - BBTC3 MT5000 Series Architecture UML Design Overview MT5000 Software Configuration Record MT5000 Software Design Review MT5000, MT5100,& MT5200 Series Software & Safety Critical Code Review MT5000, MT5100 & MT5200 Architecture Design & SW/HW Interface Review MT5000 Series Requirements Review per Checklist - Completed MT5000 Series SIL 2 Safety Integration and Validation Test Plan Review MT5000 Integration and Validation Testing Results T-034 V5R1 80 N. Main St, Sellersville, PA Page 9 of 21

10 [D55] MT A, Rev A, 6/22/2010 [D56] MT B, 6/24/2010 [D57] ELE1032, Rev B, November 7, 2005 [D58] MT , Rev B, 11/11/2005 [D59] Field_failure_analysis_KTEK_ABB_ MT_ _Update.xls, 8/19/2013 [D60] SPM efm, October 15, 2008 [D61] MT jcg after FI.efm, 9/1/09 [D62] MT jcg after FI with added diagnostics.efm, 8/5/10 [D63] SPM C.efm, October 15, 2008 [D64] SPM B.efm, October 15, 2008 [D65] Probe_Assembly FMEDA R3-gps, 9/3/09 [D66] TAB, 8/4/2010 [D67] PMU 10, Rev G, March 5, 2013 [D68] ITP , Rev 0 [D69] Production Doc Package, Rev01 [D70] Engineering Change Documentation MT5000 Integration and Validation Testing Results Addendum MT5000 BBTC3 RAM tests after code correction Block Diagram, MT5000, MT5100, MT5200, /M6 /M7 /M7A /M7B Intrinsically Safe Modules MT5000, MT5100, MT5200 Series General Assembly and Options Field Failure Analysis PIU spreadsheet Failure Modes, Effects, and Diagnostic Analysis MT5x00 Transmitter Series EPROM / Connector Board Failure Modes, Effects, and Diagnostic Analysis MT5x00 Transmitter Series Radar Transmit/Receive Module Failure Modes, Effects, and Diagnostic Analysis MT5x00 Transmitter Series uprocessor Board Failure Modes, Effects, and Diagnostic Analysis MT5x00 Transmitter Series HART Interface Board Failure Modes, Effects, and Diagnostic Analysis MT5x00 Transmitter Series SPM201 Electronics Failure Modes, Effects, and Diagnostic Analysis MT5x00 Transmitter Series Probe Assembly IEC Tables, document shows all tables from IEC Annex A and B from part 2 and part 3 along with a description as to how ABB, Inc. meets each of the requirements Supply Management Procedure Inspection Test Plan, Magnetic Level Gauge Production Document Package Form Engineering Changes, including impact analysis documentation Documentation generated by exida [R1] [R2] [R3] KTEK R001 V1 R3 FMEDA Report MT5x00.doc, 8/6/2010 MT5000_Fault_Injection_report_ xls, 6/17/10 K-TEK MT5x00 SafetyCase DB IEC61508 R2.esc, August 2010 FMEDA Report MT5000 Series Guided Wave Radar Level Transmitters Fault Injection Test report for MT5x00 Series IEC SafetyCaseDB for MT5000, 5100 and MT5200 Level Transmitters T-034 V5R1 80 N. Main St, Sellersville, PA Page 10 of 21

11 [R4] [R5] KTEK R001 V2R1 MT5x00 IEC Assessment.doc, 11/11/2013 Field_failure_analysis_KTEK_ABB_ MT_ _Update.xls IEC Functional Safety Assessment for MT5000, MT5100 and MT5200 Level Transmitter (This document) Field failure analysis. 2.5 Assessment Approach The certification audit was closely driven by requirements of the exida scheme which includes subsets filtered from IEC The assessment was planned by exida and agreed with ABB, Inc.. The following IEC objectives were subject to detailed auditing at ABB, Inc.: FSM planning, including o o o o o o Safety Life Cycle definition Scope of the FSM activities Documentation Activities and Responsibilities (Training and competence) Configuration management Tools and languages Safety Requirement Specification Change and modification management Software architecture design process, techniques and documentation Hardware architecture design - process, techniques and documentation Hardware design / probabilistic modeling Hardware and system related V&V activities including documentation, verification o Integration and fault insertion test strategy Software and system related V&V activities including documentation, verification System Validation including hardware and software validation Hardware-related operation, installation and maintenance requirements The project teams, not individuals were audited. T-034 V5R1 80 N. Main St, Sellersville, PA Page 11 of 21

12 3 Product Description The MT5000 Series Level Transmitters are a series of two-wire 4 20 ma smart devices. It contains self-diagnostics and is programmed to send its output to a specified failure state, either high or low, upon internal detection of a failure. For safety instrumented systems usage it is assumed that the 4 20 ma output is used as the primary safety variable. Figure 1 shows an overview of the main parts of the MT5000 Series Level Transmitters and the boundary for the Failure Modes, Effects, and Diagnostic Analysis. SIGNAL CONDITIONING PROCESSOR OUTPUT CURRENT GENERATION, POWER SUPPLY 4-20mA USER INTERFACE HART (optional) PROBE EXTENT OF FMEDA Figure 1 MT500, MT5100, and MT5200 SIS Assembly Table 1 gives an overview of the different versions that were considered in this assessment of the MT5000, MT5100 and MT5200 Level Transmitters. Table 1 Models Overview MT5000 MT5100 MT5200 Guided Wave Radar Level Transmitter Guided Wave Radar Level and Interface Transmitter Guided Wave Radar Bulk Solids Level Transmitter The MT5000 Series Level Transmitters are classified as a Type B device according to IEC 61508, having a hardware fault tolerance of Hardware and Software Version Numbers This assessment is applicable to the following hardware and software versions of MT5000, 5100 and MT5200 Level Transmitters: T-034 V5R1 80 N. Main St, Sellersville, PA Page 12 of 21

13 MT5000 Series Level Transmitters Options: 4-20mA output, single output Hardware Processor board #: MT Revision Level: G Signal conditioning board #: MT Display board #: MT Connector board #: SPM Hart Board #: SPM Software/Firmware Revision Level: E Revision Level: C Revision Level: E Revision Level: F 4 IEC Functional Safety Assessment Scheme exida assessed the development process used by ABB, Inc. for this development project against the objectives of the exida certification scheme. The results of the assessment are documented in [R3][R1]. All objectives have been successfully considered in the ABB, Inc. development processes for the development. exida assessed the set of documents against the functional safety management requirements of IEC 61508:2010. An evaluating assessor created a safety case, to argue that the relevant requirements of IEC to -3 have been met, based on documented the evidence provided. An independent certifying assessor then reviews the safety case to ensure coverage of the requirements and the validity of the arguments. Additionally, an audit is performed to witness development and manufacturing environments and techniques to ensure procedures are being followed and that certain testing is carried out successfully. The detailed assessment evaluated the compliance of the processes, procedures and techniques, as implemented for the ABB, Inc. MT5000, 5100 and MT5200 Level Transmitters, with IEC The assessment was executed using the exida certification scheme which includes subsets of the IEC requirements tailored to the work scope of the development team. The result of the assessment shows that the MT5000, 5100 and MT5200 Level Transmitters are capable for use in SIL 3 (Systematic Capability is SC3) applications, when properly designed into a Safety Instrumented Function per the requirements in the Safety Manual. 4.1 Product Modifications The modification process has not yet been assessed and audited, so modifications are not currently covered by this assessment. No modifications are permitted to the certified versions of the MT5000, 5100 and MT5200 Level Transmitters without reassessment. 5 Results of the IEC Functional Safety Assessment exida assessed the development process used by ABB, Inc. during the product development against the objectives of the exida certification scheme which includes IEC parts 1, 2, & 3 [N1]. The development of the MT5000, 5100 and MT5200 Level Transmitters was done per this IEC SIL 3 compliant development process. The Safety Case was updated with project specific design documents. T-034 V5R1 80 N. Main St, Sellersville, PA Page 13 of 21

14 5.1 Lifecycle Activities and Fault Avoidance Measures ABB, Inc. has an IEC compliant development process as assessed during the IEC certification. This compliant development process is documented in [D3]. This functional safety assessment evaluated the compliance with IEC of the processes, procedures and techniques as implemented for the product development. The assessment was executed using the exida certification scheme which includes subsets of IEC requirements tailored to the SIL 3 work scope of the development team. The result of the assessment can be summarized by the following observations: The audited development process complies with the relevant managerial requirements of IEC SIL Functional Safety Management FSM Planning The functional safety management of any ABB, Inc. Safety Instrumented Systems Product development is governed by QMP-0008B Quality Management Plan Procedure, Design & Development [D3]. ABB, Inc. has a Functional Safety Management Plan Quality Procedure, PRC0079A [D10] which is fixed but requires the creation of Design Project Records per FRM-0708 [D14] for each development which defines all of the tasks that must be done to ensure functional safety as well as the person(s) responsible for each task. These processes, and the procedures referenced herein, fulfill the requirements of IEC with respect to functional safety management. Version Control All documents are under version control as documented in [R3] and required by the Control of Documents Quality Management Plan Procedure [D2]. Design drawings and documents are also under version control, using a version control software application. Training, Competency recording Personnel training records are kept in accordance with IEC requirements as documented in [R3] and PRC0082 the R&D Group Qualification Record Quality Procedure [D13]. ABB, Inc. hired exida as an independent assessor, per IEC Safety Requirement Specification As defined in [D10] and [D14], a safety requirements specification (SRS) is created for all products that must meet IEC requirements. The requirements specification contains a scope and safety requirements section. For the MT5000, 5100 and MT5200 Level Transmitters, the SRS [D42] has been assessed. Safety requirements are tracked, throughout the development process, by the creation of derived requirements. Safety requirements are mapped to the design, and to the appropriate validation tests in the validation test plan [D53]. Requirements from IEC , Table B.1 that have been met by ABB, Inc. include project management, documentation, separation of safety requirements from non-safety requirements, structured specification, inspection of the specification, semi-formal methods and checklists. [D66] documents more details on how each of these requirements has been met. This meets the requirements of SIL 3. T-034 V5R1 80 N. Main St, Sellersville, PA Page 14 of 21

15 5.3 Change and modification management The modification process has been successfully assessed and audited for IEC 61508:2000, but has not yet been assessed for IEC 61508:2010 requirements. ABB, Inc. may not make modifications to this product until that assessment is successfully completed. 5.4 Hardware Design and Verification Objectives The main objectives of the related IEC requirements are to: - Create E/E/PE safety-related systems conforming to the specification for the E/E/PES safety requirements (comprising the specification for the E/E/PES safety functions requirements and the specification for the E/E/PES safety integrity requirements). - Ensure that the design and implementation of the E/E/PE safety-related systems meets the specified safety functions and safety integrity requirements. - Demonstrate, for each phase of the overall, E/E/PES and software safety lifecycles (by review, analysis and/or tests), that the outputs meet in all respects the objectives and requirements specified for the phase. - Test and evaluate the outputs of a given phase to ensure correctness and consistency with respect to the products and standards provided as input to that phase. - Integrate and test the E/E/PE safety-related systems Hardware Design As defined in [D10] and [D14], a safety requirements specification (SRS) is created for all products that must meet IEC requirements. The requirements specification contains a scope and safety requirements section. For the MT5000, 5100 and MT5200 Level Transmitters, the SRS [D42] has been assessed. Safety requirements are tracked, throughout the development process, by the creation of derived requirements. Safety requirements are mapped to the design, and to the appropriate validation tests in the validation test plan [D53]. Requirements from IEC , Table B.1 that have been met by ABB, Inc. include project management, documentation, separation of safety requirements from non-safety requirements, structured specification, inspection of the specification, semi-formal methods and checklists. [D66] documents more details on how each of these requirements has been met. This meets the requirements of SIL Hardware Design / Probabilistic properties To evaluate the hardware design of the MT5100 Series Level Transmitters, a Failure Modes, Effects, and Diagnostic Analysis was performed by exida for each component in the system. This is documented in [R1]. The FMEDA was verified using Fault Injection Testing as part of the development, see [R2], and as part of the IEC assessment. T-034 V5R1 80 N. Main St, Sellersville, PA Page 15 of 21

16 A Failure Modes and Effects Analysis (FMEA) is a systematic way to identify and evaluate the effects of different component failure modes, to determine what could eliminate or reduce the chance of failure, and to document the system in consideration. An FMEDA (Failure Mode Effect and Diagnostic Analysis) is an FMEA extension. It combines standard FMEA techniques with extension to identify online diagnostics techniques and the failure modes relevant to safety instrumented system design. From the FMEDA failure rates are derived for each important failure category. These results must be considered in combination with PFD AVG of other devices of a Safety Instrumented Function (SIF) in order to determine suitability for a specific Safety Integrity Level (SIL). The Safety Manual states that the application engineer should calculate the PFD AVG for each defined safety instrumented function (SIF) to verify the design of that SIF. The objectives of the standard are fulfilled by the ABB, Inc. functional safety management system, FMEDA quantitative analysis, and hardware development guidelines and practices. 5.5 Software Design Software design is done according to [D3], [D10], [D14], [D8], and [D9]. The software design process includes software interface specification and detailed module design [D47], specification of configuration records [D48], design and critical code reviews [D49] and [D50], and UML specifications [D47]. Requirements from IEC , Table A.1 through A.5 that have been met by ABB, Inc. include observance of guidelines and standards, project management, documentation, structured design, modularization, use of well-tried components, checklists, semi-formal methods, computer aided design tools, simulation, and inspection of the specification, selection of suitable programming language, use of a defined subset of the language, and others. This meets the requirements of SIL Verification The development and verification activities are defined in [D10] and [D14]. Verification activities include the following: Fault Injection Testing, Code Review [D50] per [D27], Checklists embedded in [D14], and FMEDA [R1]. Further verification activities are documented in [D10] and [D14] for new product development projects. 5.7 Safety Validation Validation Testing is done via a set of documented tests (see [D10] and [D14]). The validation tests are traceable to the Safety Requirements Specification [D42] in the validation test plan [D43]. In addition to standard Test Specification Documents, third party testing may be included as part of agency approvals. As the MT5100 Series Level Transmitters consists of simple electrical devices with a straightforward safety function, integration testing has been limited to verifying that all diagnostics take the appropriate action when they find a problem (See [D54] and [R2] for more details on this testing). Procedures are in place for corrective actions to be taken when tests fail as documented in [R3] and [D7]. T-034 V5R1 80 N. Main St, Sellersville, PA Page 16 of 21

17 Requirements from IEC , Table B.3 that have been met by ABB, Inc. include functional testing, project management, documentation, and black-box testing. Field experience and statistical testing via regression testing are not applicable. [D66] documents more details on how each of these requirements has been met. This meets the requirements of SIL 3. Requirements from IEC , Table B.5 that have been met by ABB, Inc. include functional testing and functional testing under environmental conditions, Interference surge immunity testing, fault insertion testing, project management, documentation, static analysis, dynamic analysis, and failure analysis, expanded functional testing and black-box testing. [D66] documents more details on how each of these requirements has been met. This meets SIL Safety Manual ABB, Inc. updated the user manual for the MT5100 Series Level Transmitters and incorporated the requirements for the Safety Manual, see [D37] and [D38]. This (safety) manual was assessed by exida. The final version is considered to be in compliance with the requirements of IEC The document includes all required reliability data and operations, maintenance, and proof test procedures. Requirements from IEC , Table B.4 that have been met by ABB, Inc. include operation and maintenance instructions, user friendliness, maintenance friendliness, project management, documentation, limited operation possibilities, protection against operator mistakes, and operation only by skilled operators. [D66] documents more details on how each of these requirements has been met. This meets the requirements for SIL 3. T-034 V5R1 80 N. Main St, Sellersville, PA Page 17 of 21

18 IEC Functional Safety Surveillance Audit 6.1 Roles of the parties involved ABB, Inc. exida exida Manufacturer of the MT5000, 5100 and MT5200 Level Transmitters Performed the hardware assessment review Performed the IEC Functional Safety Surveillance Audit per the accredited exida scheme. ABB, Inc. contracted exida in October 2016 to perform the surveillance audit for the above MT5000, 5100 and MT5200 Level Transmitters. The surveillance audit was conducted remotely in October Surveillance Methodology As part of the IEC functional safety surveillance audit, the following aspects have been reviewed: Procedure Changes Changes to relevant procedures since the last audit are reviewed to determine that the modified procedures meet the requirements of the exida certification scheme. Engineering Changes The engineering change list is reviewed to determine if an of the changes could affect the safety function of the MT5000, 5100 and MT5200 Level Transmitters. Impact Analysis If changes were made to the product design, the impact analysis associated with the change will be reviewed to see that the functional safety requirements for an impact analysis have been met. Field History Shipping and field returns during the certification period will be reviewed to determine if any systematic failures have occurred. If systematic failures have occurred during the certification period, the corrective action that was taken to eliminate the systematic failure(s) will be reviewed to determine that said action followed the approved processes and was effective. Safety Manual The latest version of the safety manual will be reviewed to determine that it meets the IEC requirements for a safety manual. FMEDA Update If required or requested the FMEDA will be updated. This is typically done if there are changes to the IEC standard and/or changes to the exida failure rate database. Recommendations from Previous Audits If there are recommendations from the previous audit, these are reviewed to see if the recommendations have been implemented properly. T-034 V5R1 80 N. Main St, Sellersville, PA Page 18 of 21

19 6.2.1 Documentation provided by ABB, Inc. [D71] MTs with M7A_2016 hours calculated [D72] OI_MT5000-EN_H. Failure return data and shipping records Safety Manual Surveillance Documentation generated by exida [R6] [R7] ABB R001 V1 R5 FMEDA Report MT5x00.doc, 10/27/2016 DRAFT - ABB R001 V3R Assessment Report - MT5x00.docx, 10/31/2016 [R8] ABB V1R Update Analysis MT 5x00.xlsx FMEDA Report MT5000 Series Guided Wave Radar Level Transmitters IEC Assessment Report (this file) Update from ed. 1 to ed. 2 Gap analysis. 6.3 Surveillance Results Procedure Changes There were no changes to the procedures during the previous certification period Engineering Changes There were no safety-related design changes during the previous certification period Impact Analysis There were no safety-related design changes during the previous certification period Field History The field history of the product has been analyzed and found to be consistent with the failure rates predicted by the FMEDA Safety Manual The safety manual was reviewed and found to be compliant with IEC 61508: FMEDA Update No FMEDA update was necessary as there were no safety-related design changes during the certification period. However, the FMEDA report was updated to reflect changes made in the 2010 version of the standard and to add Route 2 H Previous Recommendations There were no previous recommendations to be assessed at this audit. T-034 V5R1 80 N. Main St, Sellersville, PA Page 19 of 21

20 7 Terms and Definitions exida criteria A conservative approach to arriving at failure rates suitable for use in hardware evaluations utilizing the 2 H Route in IEC Fault tolerance FIT FMEDA HFT Low demand mode High demand mode PFD AVG PFH Random Capability SFF SIF SIL SIS Ability of a functional unit to continue to perform a required function in the presence of faults or errors (IEC , 3.6.3) Failure In Time (1x10-9 failures per hour) Failure Mode Effect and Diagnostic Analysis Hardware Fault Tolerance Mode where the demand interval for operation made on a safety-related system is greater than twice the proof test interval. Mode where the demand interval for operation made on a safety-related system is less than 100x the diagnostic detection/reaction interval, or where the safe state is part of normal operation. Average Probability of Failure on Demand Probability of dangerous Failure per Hour The SIL limit imposed by the Architectural Constraints for each element. Safe Failure Fraction - Summarizes the fraction of failures, which lead to a safe state and the fraction of failures which will be detected by diagnostic measures and lead to a defined safety action. Safety Instrumented Function Safety Integrity Level Safety Instrumented System Implementation of one or more Safety Instrumented Functions. A SIS is composed of any combination of sensor(s), logic solver(s), and final element(s). Systematic Capability Measure of the confidence that the systematic safety integrity of an element meets the requirements of the specified SIL. Type A element Non-Complex element (using discrete components); for details see of IEC Type B element Complex element (using complex components such as micro controllers or programmable logic); for details see of IEC T-034 V5R1 80 N. Main St, Sellersville, PA Page 20 of 21

21 8 Status of the document 8.1 Liability exida prepares reports based on methods advocated in International standards. Failure rates are obtained from a collection of industrial databases. exida accepts no liability whatsoever for the use of these numbers or for the correctness of the standards on which the general calculation methods are based. 8.2 Version History Contract Number Report Number, version Q16/ ABB R001 V3R1 Q16/ ABB R001 V3R0 Q13/ KTEK R001 V2R1 Q13/ KTEK R001 V2R0 Q13/ KTEK R001 V1R2 Q10/ KTEK R001 V1R1 Q10/ KTEK R001 V0R1 Revision Notes Changed city to Baton Rouge, DEB, 31-Oct-2016 Revised for surveillance assessment, D. Butler, 31-Oct Revised for (minor) ABB comments, D. Butler, 11-Nov Revised for surveillance assessment, D. Butler, 29-Oct Added manufacturing locations, S. Close, 11-Mar Released to ABB, Inc.; 27-Aug-2010 Internal Draft; 25-Aug-2010 Review: V2, R0: Gregory Sauk; October 30, 2013 V0, R1: Iwan van Beurden (exida); August 27, 2010 Status: Released, 10/31/ Future Enhancements At request of client. 8.4 Release Signatures David Butler, CFSE, Safety Engineer Gregory Sauk, CFSE Senior Safety Engineer William M. Goble, Principal Partner T-034 V5R1 80 N. Main St, Sellersville, PA Page 21 of 21

Results of the IEC Functional Safety Assessment

Results of the IEC Functional Safety Assessment Results of the IEC 61508 Functional Safety Assessment Project: 3051S Electronic Remote Sensors (ERS ) System Customer: Emerson Automation Solutions (Rosemount, Inc.) Shakopee, MN USA Contract No.: Q16/12-041

More information

IEC Functional Safety Assessment

IEC Functional Safety Assessment IEC 61508 Functional Safety Assessment Project: Rosemount 5300 Series 4-20mA HART Guided Wave Radar Level and Interface Transmitter Device Label SW 2.A1 2.J0 Customer: Rosemount Tank Radar (an Emerson

More information

IEC Functional Safety Assessment

IEC Functional Safety Assessment IEC 61508 Functional Safety Assessment Project: 3051S HART Advanced Diagnostics Pressure Transmitter, option code DA2 Customer: Rosemount Inc. (an Emerson Process Management company) Chanhassen, MN USA

More information

IEC Functional Safety Assessment

IEC Functional Safety Assessment IEC 61508 Functional Safety Assessment Project: Rosemount 2051 4-20mA Pressure Transmitter Device Label SW 1.0.0-1.4.x Company: Rosemount Inc. (an Emerson Process Management company) Chanhassen, MN USA

More information

IEC Functional Safety Assessment

IEC Functional Safety Assessment IEC 61508 Functional Safety Assessment Project: LESV - Flow Sensor Customer: Woodward Industrial Controls Fort Collins, CO USA Contract Number: Q13/04-021 Report No.: WOO Q13-04-021 R001 Version V0, Revision

More information

ida Certification Services IEC Functional Safety Assessment Project: Series 327 Solenoid Valves Customer: ASCO Numatics

ida Certification Services IEC Functional Safety Assessment Project: Series 327 Solenoid Valves Customer: ASCO Numatics e ida Certification Services IEC 61508 Functional Safety Assessment Project: Series 327 Solenoid Valves Customer: ASCO Numatics Scherpenzeel The Netherlands Contract Number: Q13/01-001 Report No.: ASC

More information

IEC Functional Safety Assessment

IEC Functional Safety Assessment IEC 61508 Functional Safety Assessment Project: Rosemount 3051 4-20mA HART Pressure Transmitter Device Label SW 1.0.0-1.4.x Company: Rosemount Inc. (an Emerson Process Management company) Chanhassen, MN

More information

ida Certification Services IEC Functional Safety Assessment Project: Series 8314, 8316, and Way/2 Position Solenoid Valves Customer:

ida Certification Services IEC Functional Safety Assessment Project: Series 8314, 8316, and Way/2 Position Solenoid Valves Customer: e ida Certification Services IEC 61508 Functional Safety Assessment Project: Series 8314, 8316, and 8320 3 Way/2 Position Solenoid Valves Customer: ASCO Florham Park, NJ USA Contract Number: Q13/01-001

More information

Results of the IEC Functional Safety Assessment. Rosemount Tank Radar Sweden

Results of the IEC Functional Safety Assessment. Rosemount Tank Radar Sweden Results of the IEC 61508 Functional Safety Project: Rosemount TM 5408 Level Transmitter Customer: Rosemount Tank Radar Sweden Contract No.: Q15/01-149 Report No.: ROS 15-01-149 Version V1, Revision R1,

More information

IEC Functional Safety Assessment. SPR Series Spool Valves. Bifold Fluidpower Ltd. Chadderton, Manchester United Kingdom

IEC Functional Safety Assessment. SPR Series Spool Valves. Bifold Fluidpower Ltd. Chadderton, Manchester United Kingdom IEC 61508 Functional Safety Assessment Project: SPR Series Spool Valves Customer: Bifold Fluidpower Ltd. Chadderton, Manchester United Kingdom Contract No.: Q17/05-127 Report No.: BIF 11/02-075 R002 Version

More information

IEC Functional Safety Assessment

IEC Functional Safety Assessment IEC 61508 Functional Safety Assessment Project: DeltaV SIS DeltaV SIS Relay Module, KJ2231X1- EA1 DeltaV SIS Voltage Monitor, KJ2231X1 EB1 Customer: Emerson Process Management Fisher Rosemount Systems

More information

Results of the IEC Functional Safety Assessment HART transparent repeater. PR electronics

Results of the IEC Functional Safety Assessment HART transparent repeater. PR electronics exida Certification S.A. 2 Ch. de Champ-Poury CH-1272 Genolier Switzerland Tel.: +41 22 364 14 34 email: info@exidacert.com Results of the IEC 61508 Functional Safety Assessment Project: 9106 HART transparent

More information

IEC Functional Safety Assessment. General Electric Salem, VA USA

IEC Functional Safety Assessment. General Electric Salem, VA USA IEC 61508 Functional Safety Assessment Project: Mark VIe PPRO Protection Module Customer: General Electric Salem, VA USA Contract No.: Q12/05-045r1 Report No.: GE 12-05-045 R001 Version V1, Revision R2,

More information

ida Certification Services IEC Functional Safety Assessment Project: Automax Pneumatic Rack & Pinion Actuators Customer: Flowserve Flow Control

ida Certification Services IEC Functional Safety Assessment Project: Automax Pneumatic Rack & Pinion Actuators Customer: Flowserve Flow Control e ida Certification Services IEC 61508 Functional Safety Assessment Project: Automax Pneumatic Rack & Pinion Actuators Customer: Flowserve Flow Control Haywards Heath West Sussex United Kingdom Contract

More information

Results of the IEC Functional Safety Assessment. Pressure, Temperature and Vacuum Switches. BETA B.V. Rijswijk The Netherlands

Results of the IEC Functional Safety Assessment. Pressure, Temperature and Vacuum Switches. BETA B.V. Rijswijk The Netherlands exida Certification S.A. 2 Ch. de Champ-Poury CH-1272 Genolier Switzerland Tel.: +41 22 364 14 34 email: info@exidacert.ch Results of the IEC 61508 Functional Safety Assessment Project: Pressure, Temperature

More information

IEC Functional Safety Assessment

IEC Functional Safety Assessment IEC 61508 Functional Safety Assessment Project: Micro Motion Series 1700/2700 Flowmeters with Standard or Enhanced Core Company: Micro Motion, Inc. Emerson Boulder, Colorado USA Contract No.: Q17/02-079

More information

Results of the IEC Functional Safety Assessment Universal Converter. PR electronics

Results of the IEC Functional Safety Assessment Universal Converter. PR electronics exida Certification S.A. 2 Ch. de Champ-Poury CH-1272 Genolier Switzerland Tel.: +41 22 364 14 34 email: info@exidacert.com Results of the IEC 61508 Functional Safety Assessment Project: 9116 Universal

More information

Comparing Certification under IEC st Edition and 2nd Edition

Comparing Certification under IEC st Edition and 2nd Edition White Paper Project: Comparing Certification under IEC 61508 1st Edition and 2nd Edition Version 1, Revision 5, November 15, 2016 Rudolf P. Chalupa The document was prepared using best effort. The authors

More information

FUNCTIONAL SAFETY ASSESSMENT REPORT FOR THE LIFECYCLE AND MANAGEMENT OF FUNCTIONAL SAFETY

FUNCTIONAL SAFETY ASSESSMENT REPORT FOR THE LIFECYCLE AND MANAGEMENT OF FUNCTIONAL SAFETY FUNCTIONAL SAFETY ASSESSMENT REPORT FOR THE LIFECYCLE AND MANAGEMENT OF FUNCTIONAL SAFETY Author:. Paul Reeve BEng CEng MIET MInstMC Functional Safety Consultant Sira Associate Report checked:. Hassan

More information

Safety Manual In Accordance with IEC 61508

Safety Manual In Accordance with IEC 61508 Direct Acting Pneumatic Trip with Partial Stroke Safety Manual In Accordance with IEC 61508 Elliott Company, 901 North Fourth Street, Jeannette, PA 15644 Document number 5046521 Rev No. Issued By Issued

More information

on behalf of TÜV INTERCERT GmbH Group of TÜV Saarland

on behalf of TÜV INTERCERT GmbH Group of TÜV Saarland on behalf of TÜV INTERCERT GmbH Group of TÜV Saarland SIL SUMMARY REPORT IEC 61508-1/7: 2010 Pneumatic / hydraulic compact scotch-yoke spring return actuators Series RC Rotork Sweden AB Kontrollvägen,

More information

SERIES 92/93 SAFETY MANUAL PNEUMATIC ACTUATOR. The High Performance Company

SERIES 92/93 SAFETY MANUAL PNEUMATIC ACTUATOR. The High Performance Company SERIES 92/93 PNEUMATIC ACTUATOR SAFETY MANUAL The High Performance Company Table of Contents 1.0 Introduction...1 1.1 Terms and Abbreviations... 1 1.2 Acronyms... 1 1.3 Product Support... 2 1.4 Related

More information

Spring return and double acting pneumatic rack and pinion actuator

Spring return and double acting pneumatic rack and pinion actuator Test Report No.: FS 28717071 Version-No.: 1 Date: 2017-08-03 Product: Model: Customer/Manufacturer: Spring return and double acting pneumatic rack and pinion actuator Series FieldQ Emerson Automation Solutions

More information

Failure Modes, Effects and Diagnostic Analysis

Failure Modes, Effects and Diagnostic Analysis Failure Modes, Effects and Diagnostic Analysis Project: Rosemount 8800D Vortex Flowmeter Company: Emerson Eden Prairie, MN USA Contract Number: Q16/12-042 Report No.: ROS 06/03-34 R001 Version V3, Revision

More information

ida Certification Services IEC Functional Safety Assessment Project: Worcester 51/52, 53/54 1 piece and 519/529 Series Ball Valves Customer:

ida Certification Services IEC Functional Safety Assessment Project: Worcester 51/52, 53/54 1 piece and 519/529 Series Ball Valves Customer: e ida Certification Services IEC 61508 Functional Safety Assessment Project: Worcester 51/52, 53/54 1 piece and 519/529 Series Ball Valves Customer: Flowserve Flow Control Haywards Heath West Sussex United

More information

FUNCTIONAL SAFETY CERTIFICATE. IQT3 Actuator manufactured by

FUNCTIONAL SAFETY CERTIFICATE. IQT3 Actuator manufactured by FUNCTIONAL SAFETY CERTIFICATE This is to certify that the IQT3 Actuator manufactured by Rotork Controls Ltd (A Division of Rotork PLC) Brassmill Lane Bath, BA1 3JQ UK have been assessed by with reference

More information

FUNCTIONAL SAFETY CERTIFICATE

FUNCTIONAL SAFETY CERTIFICATE FUNCTIONAL SAFETY CERTIFICATE This is to certify that the D-Series Switchbox Manufactured by Topworx 3300 Fern Valley Road Louisville Kentucky 40213 USA Has been assessed by with reference to the CASS

More information

FUNCTIONAL SAFETY CERTIFICATE. TVL/TVH/TVF Switchboxes

FUNCTIONAL SAFETY CERTIFICATE. TVL/TVH/TVF Switchboxes FUNCTIONAL SAFETY CERTIFICATE This is to certify that the TVL/TVH/TVF Switchboxes manufactured by TopWorx 3300 Fern Valley Road Louisville Kentucky 40213 USA have been assessed by with reference to the

More information

FUNCTIONAL SAFETY CERTIFICATE. Topworx, Inc 3300 Fern Valley Road, Louisville, Kentucky, 40213, USA

FUNCTIONAL SAFETY CERTIFICATE. Topworx, Inc 3300 Fern Valley Road, Louisville, Kentucky, 40213, USA FUNCTIONAL SAFETY CERTIFICATE This is to certify that the GO TM switch models: 73, 74, 75, 76, 77, 7G, 7H, 7I, 7J Manufactured by Topworx, Inc 3300 Fern Valley Road, Louisville, Kentucky, 40213, USA Have

More information

FUNCTIONAL SAFETY CERTIFICATE. IQ3 Valve Actuator manufactured by

FUNCTIONAL SAFETY CERTIFICATE. IQ3 Valve Actuator manufactured by FUNCTIONAL SAFETY CERTIFICATE This is to certify that the IQ3 Valve Actuator manufactured by Rotork Controls Ltd (A Division of Rotork PLC) Brassmill Lane Bath, BA1 3JQ UK have been assessed by with reference

More information

FUNCTIONAL SAFETY CERTIFICATE

FUNCTIONAL SAFETY CERTIFICATE FUNCTIONAL SAFETY CERTIFICATE This is to certify that the T-Series Switchbox Manufactured by Topworx 3300 Fern Valley Road Louisville Kentucky 40213 USA Has been assessed by with reference to the CASS

More information

SIL SAFETY MANUAL. Turnex Pneumatic Actuators. Experience In Motion. NAF Turnex Pneumatic Actuators NFENDS A4 02/15 FCD NFENDS A4 05/15

SIL SAFETY MANUAL. Turnex Pneumatic Actuators. Experience In Motion. NAF Turnex Pneumatic Actuators NFENDS A4 02/15 FCD NFENDS A4 05/15 SIL SAFETY MANUAL NAF Turnex Pneumatic Actuators NFENDS7459-00-A4 02/15 Turnex Pneumatic Actuators FCD NFENDS7459-00-A4 05/15 Experience In Motion 1 Contents 1 Introduction... 3 1.1 Scope and purpose of

More information

Results of the IEC Functional Safety Assessment

Results of the IEC Functional Safety Assessment Results of the IEC 61508 Functional Safety Assessment Project: SITRANS TH420/320; TR420/320 Customer: Siemens AG 76181 Karlsruhe, Germany Contract No.: Q16/09-078-C Report No.: Q1609-078-C R004 Version

More information

Session Nine: Functional Safety Gap Analysis and Filling the Gaps

Session Nine: Functional Safety Gap Analysis and Filling the Gaps Session Nine: Functional Safety Gap Analysis and Filling the Gaps Presenter Colin Easton ProSalus Limited Abstract Increasingly regulatory and competent authorities are looking to hazardous Installation

More information

FUNCTIONAL SAFETY CERTIFICATE

FUNCTIONAL SAFETY CERTIFICATE FUNCTIONAL SAFETY CERTIFICATE This is to certify that the T-Series Switchbox Manufactured by Topworx 3300 Fern Valley Road Louisville Kentucky 40213 USA Has been assessed by with reference to the CASS

More information

FUNCTIONAL SAFETY CERTIFICATE Series Poppet Valve

FUNCTIONAL SAFETY CERTIFICATE Series Poppet Valve FUNCTIONAL SAFETY CERTIFICATE This is to certify that the 1750 Series Poppet Valve manufactured by Rotork Midland Ltd Patrick Gregory Rd Wolverhampton West Midlands WV11 3DZ UK has been assessed by with

More information

Requirements Are Evolving In The Elevator Industry. November 28, 2012

Requirements Are Evolving In The Elevator Industry. November 28, 2012 How Safety And Safety Requirements Are Evolving In The Elevator Industry November 28, 2012 UL and the UL logo are trademarks of UL LLC 2012 DISCLAIMER/ TERMS OF USE: THE INFORMATION PROVIDED HEREIN IS

More information

FUNCTIONAL SAFETY CERTIFICATE

FUNCTIONAL SAFETY CERTIFICATE FUNCTIONAL SAFETY CERTIFICATE This is to certify that the 80 series proximity switch manufactured by Topworx, Inc. 3300 Fern Valley Road Louisville Kentucky 40213 USA has been assessed by with reference

More information

Safety cannot rely on testing

Safety cannot rely on testing Standards 1 Computer-based systems (generically referred to as programmable electronic systems) are being used in all application sectors to perform non-safety functions and, increasingly, to perform safety

More information

Introduction and Revision of IEC 61508

Introduction and Revision of IEC 61508 Introduction and Revision of IEC 61508 Ron Bell OBE, BSc, CEng FIET Engineering Safety Consultants Ltd Collingham House 10-12 Gladstone Road Wimbledon London, SW19 1QT UK Abstract Over the past twenty-five

More information

Development of Safety Related Systems

Development of Safety Related Systems July 2015 LatticeSemiconductor 7 th Floor,111SW5 th Avenue Portland,Oregon97204USA Telephone:(503)268I8000 www.latticesemi.com WP004 The increasing degree of automation brings a lot of comfort and flexibility

More information

Comparing Failure Rates for Safety Devices

Comparing Failure Rates for Safety Devices Comparing Failure Rates for Safety Devices FMEDA Prediction vs OREDA Estimation Standards Certification Education & Training Publishing Conferences & Exhibits Iwan van Beurden, exida Vice President Product

More information

ida Certification Services IEC Functional Safety Assessment Customer: Flowserve Flow Control Haywards Heath West Sussex United Kingdom

ida Certification Services IEC Functional Safety Assessment Customer: Flowserve Flow Control Haywards Heath West Sussex United Kingdom e ida Certification Services IEC 61508 Functional Safety Assessment Project: Worcester 44/59/459/599 Series Ball Valves Customer: Flowserve Flow Control Haywards Heath West Sussex United Kingdom Contract

More information

Report. Certificate Z F-CM AS-i Safety for SIMATIC ET 200SP

Report. Certificate Z F-CM AS-i Safety for SIMATIC ET 200SP Report to the Certificate Z10 16 07 38717 052 Safety Components F-CM AS-i Safety for SIMATIC ET 200SP Manufacturer: Siemens AG I IA CE Werner-von-Siemens-Straße 48 D-92220 Amberg Germany Revision 1.7 dated

More information

Functional Safety Machinery

Functional Safety Machinery Functional Safety Machinery One of the fundamental aspects of machinery safety is the reliability of safety-related command parts, namely the Functional Safety, defined as the portion of the overall safety

More information

Management of Functional Safety

Management of Functional Safety Training: Automotive ISO 26262 Road Vehicles Functional Safety Content: Section 1 (1 day): Overview over ISO 26262 Management of Functional Safety From Item definition to System design Section 2 (1.5 days):

More information

Reliability of Safety-Critical Systems Chapter 2. Concepts and requirements

Reliability of Safety-Critical Systems Chapter 2. Concepts and requirements Reliability of Safety-Critical Systems Chapter 2. Concepts and requirements Mary Ann Lundteigen and Marvin Rausand mary.a.lundteigen@ntnu.no & marvin.rausand@ntnu.no RAMS Group Department of Production

More information

CASS TOES FOR FUNCTIONAL SAFETY MANAGEMENT ASSESSMENT (IEC : 2010)

CASS TOES FOR FUNCTIONAL SAFETY MANAGEMENT ASSESSMENT (IEC : 2010) CASS S FOR FUNCTIONAL SAFETY MANAGEMENT ASSESSMENT (IEC 61508-1: 2010) For general guidance on using CASS conformity assessment documents, refer to: Guidance for assessors on using the CASS s available

More information

International Safety Standards Designing the Future

International Safety Standards Designing the Future International Safety Standards Designing the Future Wayne Pearse Safety Consultant FSExpert (TÜV Rheinland, Machinery) Rev 5058-CO900D Copyright 2013 Rockwell Automation, Inc. All Rights Reserved. Copyright

More information

Compliance driven Integrated circuit development based on ISO26262

Compliance driven Integrated circuit development based on ISO26262 Compliance driven Integrated circuit development based on ISO26262 Haridas Vilakathara Manikantan panchapakesan NXP Semiconductors, Bangalore Accellera Systems Initiative 1 Outline Functional safety basic

More information

IEC KHBO, Hobufonds SAFESYS ing. Alexander Dekeyser ing. Kurt Lintermans

IEC KHBO, Hobufonds SAFESYS ing. Alexander Dekeyser ing. Kurt Lintermans IEC 61508 KHBO, Hobufonds SAFESYS ing. Alexander Dekeyser ing. Kurt Lintermans page 2 PART 1 : GENERAL REQUIREMENTS 1 Scope The first objective of this standard is to facilitate the development of application

More information

A Survey on the Development and Design Strategies for Safety Related Systems according the Standard IEC/EN 61508

A Survey on the Development and Design Strategies for Safety Related Systems according the Standard IEC/EN 61508 Proceedings of the 6th WSEAS International Conference on Applied Computer Science, Tenerife, Canary Islands, Spain, December 16-18, 2006 97 A Survey on the Development and Design Strategies for Safety

More information

Functional safety Safety instrumented systems for the process industry sector

Functional safety Safety instrumented systems for the process industry sector BRITISH STANDARD BS IEC 61511-1:2003 Functional safety Safety instrumented systems for the process industry sector Part 1: Framework, definitions, system, hardware and software requirements ICS 25.040.01;

More information

Process Assessment Model SPICE for Mechanical Engineering - Proposal-

Process Assessment Model SPICE for Mechanical Engineering - Proposal- Process Assessment Model SPICE for Mechanical Engineering - Proposal- Version: 1.4 Release date: 06.07.2017 Distribution: Status: Public. For the worldwide SPICE community and any other interested parties.

More information

ISO INTERNATIONAL STANDARD

ISO INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO 25119-3 First edition 2010-06-01 Tractors and machinery for agriculture and forestry Safety-related parts of control systems Part 3: Series development, hardware and software

More information

Integrating Functional Safety with ARM. November, 2015 Lifeng Geng, Embedded Marketing Manager

Integrating Functional Safety with ARM. November, 2015 Lifeng Geng, Embedded Marketing Manager Integrating Functional Safety with ARM November, 2015 Lifeng Geng, Embedded Marketing Manager 1 ARM: The World s Most Scalable Architecture ARM ecosystem meets needs of vertical markets from sensors to

More information

TÜV SÜD BABT Production Quality Certification Scheme

TÜV SÜD BABT Production Quality Certification Scheme TÜV SÜD BABT Production Quality Certification Scheme The Production Quality Certification Scheme for Manufacturers A Certification Body of Copyright TÜV SÜD BABT 2014 Page 1 of 38 CONTENTS Page AMENDMENT

More information

REQUIREMENTS FOR SAFETY RELATED SOFTWARE IN DEFENCE EQUIPMENT PART 1: REQUIREMENTS

REQUIREMENTS FOR SAFETY RELATED SOFTWARE IN DEFENCE EQUIPMENT PART 1: REQUIREMENTS Ministry of Defence Defence Standard 00-55(PART 1)/Issue 2 1 August 1997 REQUIREMENTS FOR SAFETY RELATED SOFTWARE IN DEFENCE EQUIPMENT PART 1: REQUIREMENTS This Part 1 of Def Stan 00-55 supersedes INTERIM

More information

MIE TALK - January 2017

MIE TALK - January 2017 MIE TALK - January 2017 Functional Safety (SIL) basics for Process Control Compiled by: Gary Friend BSc PrEng, CEng MIET, Sales Director, Extech Safety Systems (MTL, Beka Associates, Extronics, AEGEx,

More information

Functional Safety: ISO26262

Functional Safety: ISO26262 Functional Safety: ISO26262 Seminar Paper Embedded systems group Aniket Kolhapurkar, University of Kaiserslautern, Germany kolhapur@rhrk.uni kl.de September 8, 2015 1 Abstract Functions in car, such as

More information

Session Seven Functional safety and ageing assets

Session Seven Functional safety and ageing assets Session Seven Functional safety and ageing assets Shane Higgins Principal Safety and Risk Engineer, HIMA Australia Lyn Fernie VP Global Consulting, HIMA Australia Abstract When designing a new facility,

More information

Research on software systems dependability at the OECD Halden Reactor Project

Research on software systems dependability at the OECD Halden Reactor Project Research on software systems dependability at the OECD Halden Reactor Project SIVERTSEN Terje 1, and ØWRE Fridtjov 2 1. Institute for Energy Technology, OECD Halden Reactor Project, Post Box 173, NO-1751

More information

Functional Safety Implications for Development Infrastructures

Functional Safety Implications for Development Infrastructures Functional Safety Implications for Development Infrastructures Dr. Erwin Petry KUGLER MAAG CIE GmbH Leibnizstraße 11 70806 Kornwestheim Germany Mobile: +49 173 67 87 337 Tel: +49 7154-1796-222 Fax: +49

More information

Software requirements for the control systems according to the level of functional safety

Software requirements for the control systems according to the level of functional safety JAMSI, 12 (2016), No. 1 25 Software requirements for the control systems according to the level of functional safety Abstract D. GABRIŠKA The article describes the main requirements of the software subsystems

More information

IEC and ISO A cross reference guide

IEC and ISO A cross reference guide and A cross reference guide This guide sets out to explain where the details for different safety lifecycle activities can be found in the standards for the Machinery Sector: and. 1 Concept 2 Overall scope

More information

Software Safety and Certification

Software Safety and Certification Software Safety and Certification presented to IEEE Spring Switchgear Committee Luncheon Seminar 4 May, 2004 by Howard Cox Laboratories 1 What we will cover... Functional Safety Concepts from IEC 61508

More information

SUPPLY AND INSTALLATION OF TURBINES AND GENERATORS CONTRACT SCHEDULE 8 QUALITY MANAGEMENT TABLE OF CONTENTS

SUPPLY AND INSTALLATION OF TURBINES AND GENERATORS CONTRACT SCHEDULE 8 QUALITY MANAGEMENT TABLE OF CONTENTS SUPPLY AND INSTALLATION OF TURBINES AND GENERATORS CONTRACT SCHEDULE 8 QUALITY MANAGEMENT TABLE OF CONTENTS 1 INTERPRETATION... 1 1.1 Definitions... 1 2 QUALITY MANAGEMENT SYSTEM... 2 2.1 Quality Management

More information

Supplier Quality System Survey

Supplier Quality System Survey Supplier Division Address Date: Quality Contact: Reports to: Title: Title: Phone Fax e-mail Plant size (ft 2 ): Union: Contract expires: Total Employment: Direct Labor: Shifts: QA employees: This report

More information

This document describes the overall software development process of microcontroller software during all phases of the Company Name product life cycle.

This document describes the overall software development process of microcontroller software during all phases of the Company Name product life cycle. Maturity Process Owner Check Release Description Valid Name / Department Name / Department Name / Department Detailed procedure for software development Title: Software Development Procedure Purpose: This

More information

On Board Use and Application of Computer based systems

On Board Use and Application of Computer based systems (Dec 2006 (Corr.1 Oct 2007) (Rev.1 Sept 2010) (Rev.2 June 2016 Complete Revision) On Board Use and Application of Computer based systems 1. Introduction 1.1 Scope These requirements apply to design, construction,

More information

AS9003A QUALITY MANUAL

AS9003A QUALITY MANUAL Your Logo AS9003A QUALITY MANUAL Origination Date: (month/year) Document Identifier: Date: Document Status: Document Link: AS9003A Quality Manual Latest Revision Date Draft, Redline, Released, Obsolete

More information

c) Have personnel been appointed to supervise the production operations across all shifts in order to ensure the product quality?

c) Have personnel been appointed to supervise the production operations across all shifts in order to ensure the product quality? Factory s Quality Assurance Ability 1 Responsibilities and Resources 1.1 Responsibilities a) Have the responsibilities and interrelation of various personnel involved in quality activities been defined?

More information

ISO : Rustam Rakhimov (DMS Lab)

ISO : Rustam Rakhimov (DMS Lab) ISO 26262 : 2011 Rustam Rakhimov (DMS Lab) Introduction Adaptation of IEC 61508 to road vehicles Influenced by ISO 16949 Quality Management System The first comprehensive standard that addresses safety

More information

Session Three Management of Functional Safety Gaps in the Operation Phase Andy Yam Functional Expert-Safety Systems, Yokogawa Australia Pty. Ltd.

Session Three Management of Functional Safety Gaps in the Operation Phase Andy Yam Functional Expert-Safety Systems, Yokogawa Australia Pty. Ltd. Session Three Management of Functional Safety Gaps in the Operation Phase Andy Yam Functional Expert-Safety Systems, Yokogawa Australia Pty. Ltd. 1 Abstract According to the IEC 61511 standard, the purpose

More information

FUNCTIONAL SAFETY EVALUATION of SIS and APPLICATIONS

FUNCTIONAL SAFETY EVALUATION of SIS and APPLICATIONS TÜV Rheinland International Symposium in China Functional Safety in Industrial Applications October 18 19, 2011 in Shanghai China FUNCTIONAL SAFETY EVALUATION of SIS and APPLICATIONS 1 FUNCTIONAL SAFETY

More information

11th International Workshop on the Application of FPGAs in Nuclear Power Plants

11th International Workshop on the Application of FPGAs in Nuclear Power Plants 11th International Workshop on the Application of FPGAs in Nuclear Power Plants Case Study for Tailoring and Adapting IEEE Std 1012 Software Verification and Validation Requirements for FPGA Technology

More information

Expected and Unintended Effects of Instrumented Safety Protections

Expected and Unintended Effects of Instrumented Safety Protections Expected and Unintended Effects of Instrumented Safety Protections Edgar Ramirez Safety Instrumented Systems Specialist, ABB Inc. John Walkington Safety Lead Competency Centre Manager, ABB Ltd. Abstract

More information

Mechanical Component Failure Rates - Static vs. Dynamic Operation. Web Seminar March 11, 2015 Loren L. Stewart exida Sellersville, PA USA

Mechanical Component Failure Rates - Static vs. Dynamic Operation. Web Seminar March 11, 2015 Loren L. Stewart exida Sellersville, PA USA Mechanical Component Failure Rates - Static vs. Dynamic Operation Web Seminar March 11, 2015 Loren L. Stewart exida Sellersville, PA USA Mechanical Component Failure Rates - Static vs. Dynamic Operation

More information

IECRE OPERATIONAL DOCUMENT

IECRE OPERATIONAL DOCUMENT IECRE OD-405-2 Edition 1.0 2016-09-26 IECRE OPERATIONAL DOCUMENT IEC System for Certification to Standards relating to Equipment for use in Renewable Energy applications (IECRE System) IECRE Quality System

More information

Supplier Quality Survey. 1. Type of Business: g) Commodities supplied? Supplier Changes/comments: 2. Headcount breakdown by group: Purchasing

Supplier Quality Survey. 1. Type of Business: g) Commodities supplied? Supplier Changes/comments: 2. Headcount breakdown by group: Purchasing Supplier: Phone: Prime Contact/Title: Sales Contact/Title: Address: Fax: e-mail address e-mail address Quality Contact/Title: e-mail address 1. Type of Business: a) Number of years in business? b) Company

More information

R214 SPECIFIC REQUIREMENTS: INFORMATION TECHNOLOGY TESTING LABORATORY ACCREDITATION PROGRAM

R214 SPECIFIC REQUIREMENTS: INFORMATION TECHNOLOGY TESTING LABORATORY ACCREDITATION PROGRAM A2LA R214 Specific Requirements: Information Technology Testing Laboratory Accreditation Document Revised: 3/5/18 Page 1 of 34 R214 SPECIFIC REQUIREMENTS: INFORMATION TECHNOLOGY TESTING LABORATORY ACCREDITATION

More information

RSC-G-009D-Annex1 (SP) Checklist for evaluation of a Project Safety Plan

RSC-G-009D-Annex1 (SP) Checklist for evaluation of a Project Safety Plan RSC-G-009D-Annex1 (SP) Checklist for evaluation of a Project Safety Plan Prepared by: Maik Wuttke 22.02.2012 Reviewed by: Mary Molloy 22.02.2012 1 Introduction This checklist will be employed by the RSC

More information

Medical Device Directive

Medical Device Directive Medical Device Directive WG9 - IEC/SC 62A ISO/TC 184/SC 2 Joint Working Group 9 Saeed Zahedi 4 th of July 2012 Blatchford Copyright 2012 Commercial in confidence Definition and Requirements MDD is law,

More information

Document Rev: 18 State: RELEASED see Smarteam for approval authorities TASK REQUIREMENTS. Supplier Quality Requirements

Document Rev: 18 State: RELEASED see Smarteam for approval authorities TASK REQUIREMENTS. Supplier Quality Requirements Document 0000000000000045 Rev: State: RELEASED see Smarteam for approval authorities This document is applicable only to suppliers of Production Items as defined below and their sub-tier suppliers. Non-

More information

Equipment In-house Calibration Requirements and use of Non-Accredited Calibration Service Providers

Equipment In-house Calibration Requirements and use of Non-Accredited Calibration Service Providers Issue 5.0: Provided additional clarification on record retention and non-conforming work with In- House calibration. Issue 6.0: Updated UL internal approvers only. No other changes. For Client Labs Purpose

More information

Form Instructions for Suppliers

Form Instructions for Suppliers SUPPLIER QUALITY SYSTEM REQUIREMENTS CAGE Code S3344 Reference LQA-002(E) Date 06.09.2010 Page 1 of 16 Form Instructions for Suppliers 1. Purpose This document describes the forms which RUAG suppliers

More information

SOFTWARE DEVELOPMENT STANDARD

SOFTWARE DEVELOPMENT STANDARD SFTWARE DEVELPMENT STANDARD Mar. 23, 2016 Japan Aerospace Exploration Agency The official version of this standard is written in Japanese. This English version is issued for convenience of English speakers.

More information

QUALITY MANUAL. Origination Date: XXXX. Latest Revision Date. Revision Orig

QUALITY MANUAL. Origination Date: XXXX. Latest Revision Date. Revision Orig QUALITY MANUAL Origination Date: XXXX Document Identifier: Date: Document Status: Latest Revision Date Revision Orig Abstract: This document describes the tailored quality management system for the build

More information

Certificating a safety related part of a control system

Certificating a safety related part of a control system Certificating a safety related part of a control system Marita Hietikko, Mika Riihimaa VTT Expert Services Ltd, P.O. Box 345, FI-33101 Tampere, Finland Tel: +358 20 722 111, E-mail: marita.hietikko@vtt.fi,

More information

Preliminary Investigation on Safety-related Standards

Preliminary Investigation on Safety-related Standards Preliminary Investigation on Safetyrelated s Christian Esposito and Domenico Cotroneo Consorzio Interuniversitario Nazionale per l Informatica (CINI), via Cinthia, Campus Monte S. Angelo, Napoli, Italy

More information

ACCREDITATION CRITERIA FOR FABRICATOR INSPECTION PROGRAMS FOR WOOD WALL PANELS AC196. April 2017 (Effective June 1, 2017) PREFACE

ACCREDITATION CRITERIA FOR FABRICATOR INSPECTION PROGRAMS FOR WOOD WALL PANELS AC196. April 2017 (Effective June 1, 2017) PREFACE ACCREDITATION CRITERIA FOR FABRICATOR INSPECTION PROGRAMS FOR WOOD WALL PANELS April 2017 (Effective June 1, 2017) PREFACE The attached accreditation criteria have been issued to provide all interested

More information

Project QMS and Quality by Design Activities

Project QMS and Quality by Design Activities QMS and Quality by Design Activities Main Topics of the Presentation Quality by Design Structure Critical Control Points in the Different Phases 1. Acquisition Phase 2. Design and Engineering Phase 3.

More information

Space product assurance

Space product assurance ECSS-Q-ST-10C Space product assurance Product assurance management ECSS Secretariat ESA-ESTEC Requirements & Standards Division Noordwijk, The Netherlands Foreword This Standard is one of the series of

More information

Desk Audit of. Based on Federal Transit Administration (FTA) Quality Assurance and Quality Control Guidelines FTA-IT

Desk Audit of. Based on Federal Transit Administration (FTA) Quality Assurance and Quality Control Guidelines FTA-IT Desk Audit of Based on Federal Transit Administration (FTA) Quality Assurance and Quality Control Guidelines FTA-IT-90-5001-02.1 Reviewed by: Element Requirements Applicable 1. Is a quality policy defined

More information

DO-178B 김영승 이선아

DO-178B 김영승 이선아 DO-178B 201372235 김영승 201372237 이선아 Introduction Standard Contents SECTION 1 INTRODUCTION SECTION 2 SYSTEM ASPECTS RELATING TO SOFTWARE DEVELOPMENT SECTION 3 SOFTWARE LIFE CYCLE SECTION 4 SOFTWARE PLANNING

More information

Document 2007 Rev 0 December 2005 Page 1 of 8

Document 2007 Rev 0 December 2005 Page 1 of 8 Document 2007 Rev 0 December 2005 Page 1 of 8 1. Scope... 2 2. Definitions... 2 a. LabTest...2 b. Factory Location/ Manufacturer's Premises...2 c. Manufacturer...2 d. Subcontractor...2 e. f. Out-Worker...2

More information

Summary of TL 9000 R4.0 Requirements Beyond ISO 9001:2000

Summary of TL 9000 R4.0 Requirements Beyond ISO 9001:2000 This summary identifies the additional TL 9000 Release 4.0 requirements beyond those stated in ISO 9001:2000. See the TL 9000 R4.0 Handbook for the actual TL 9000 R4.0 requirements. ISO 9001:2000 section

More information

Purchase Order Quality Clause SCC20 Revision E, Effective 1/20/2015

Purchase Order Quality Clause SCC20 Revision E, Effective 1/20/2015 Clause A - Quality System Requirements All references to the term Government in any of the documents referenced below shall be replaced with the term Curtiss-Wright and/or the Government. All references

More information

Field Failure Data the Good, the Bad and the Ugly

Field Failure Data the Good, the Bad and the Ugly Field Failure Data the Good, the Bad and the Ugly Dr. William M. Goble, CFSE Joseph F. Siebert, CFSE Exida Consulting Sellersville, PA 18960, USA wgoble@exida.com, jsiebert@exida.com Keywords: safety instrumented

More information

Proprietary Document Disclosure Restricted To Employees and Authorized Holders

Proprietary Document Disclosure Restricted To Employees and Authorized Holders Revision Level: A Page 1 o f 33 Revision Level: A Page 2 o f 33 (This page left blank intentionally.) Revision Level: A Page 3 o f 33 S i g n a t u r e P a g e Reviewed By Management Representative: 1

More information