Workshop Functional Safety

Similar documents
VDMA-Einheitsblatt February 2013 VDMA

Combined Cycle Power Plants. Combined Cycle Power Plant Overview (Single- and Multi-Shaft) Training Module. ALSTOM (Switzerland) Ltd )*+,

Full electrical LNG-plant: Highest availability and energy efficiency trough overall system design

HW-1: Due Tuesday 13 Jun 2017 by 2:00:00 pm EDT to Your Division s GradeScope Site

Dye Penetrant Inspection Technique of Turbine Rotating Component

A RATIONAL APPROACH TO EVALUATE A STEAM TURBINE ROTOR GRABBING AND LOCKING EVENT

HTC steam turbine front radial bearing high temperature issue

OSHA 1994 AND FMA Chapter 4 (cont.)

OSHA Occupational Safety and Health Authority

Operation and Maintenance Energy Technology

Park Lawn Preschool Inc. Park Lawn Preschool * Humber Bay Child Care Centre * PLP Early Learning Centre at St. Mark

A Short Guide to. The Safety, Health and Welfare at Work Act, 2005

SAFETY INTEGRITY LEVELS CONSIDERATIONS FOR NEW AND EXISTING ASSESSMENTS

DEVELOPMENT OF THE PLATFORM FOR CONDITION BASED MAINTENANCE. Dr. Vladimir Navrotsky Per Johansson Bengt Svensson. Siemens Industrial Turbomachinery AB

CPS Creative Power Solutions

CENTRIFUGAL COMPRESSORS MAINTENANCE & FAILURE ANALYSIS

National Health and Safety Function, Workplace Health and Wellbeing Unit, National HR Division. Guideline Document

Main Steam & T/G Systems, Safety

CONDITION BASED MAINTENANCE

NSF LARGE FACILITY WORKSHOP

Specialist Study on Noise APPENDIX 4 : EXAMPLES OF GOOD OPERATING PRACTICES IN ORDER TO REDUCE NOISE EMISSIONS

Appendix B. Glossary of Steam Turbine Terms

1. The Energy Content of Fuels

DESIGN AND CONSTRUCTION OF HEAVY INDUSTRIAL ANCHORAGE FOR POWER-PLANTS

STEAM TURBINE-GENERATOR & AUXILLIARY SYSTEMS Presentation by: RANA NASIR ALI General Manager, Power Plants Projects, at PITCO November 02, 2017

"CAUGHT-IN/BETWEEN HAZARDS IN CONSTRUCTION ENVIRONMENTS"

Company s Name: GHI Warehouse Date of Risk Assessment:

Applied Thermodynamics - II

Prepared in association with. Assessing the benefits of an Online Vibration monitoring system?

SUMMES1 (SQA Unit Code - F9H3 04) Apply health & safety legislation and working practices

Steam Power Station (Thermal Station)

Hazard Recognition and Assessment

Energy Management in Plastics Processing

Hazard Recognition and Assessment

Design Features of Combined Cycle Systems

Hazard Recognition and Assessment

Exergy in Processes. Flows and Destruction of Exergy

RECENT REVIEW ON STANDARDS RELATED TO RISK ASSESSMENT FOR CONFINED SPACES

NATIONAL COMPETENCY STANDARD

Hazard & Risk Assessment Manual Hazard Assessment & Job Safety Analysis

MEC-MOS-E-2004 Assistant Commissioning Manager / Assistant Operation Lead

2. TECHNICAL DESCRIPTION OF THE PROJECT

JOB SAFETY ANALYSIS (JSA) FOR. <Insert Organization Name> Adopted <Insert Date Policy Is Adopted> LC-442 Rev. 3/11

Whitepaper. Five steps to safer machines. A primer on safety technology in standard automation. usa.siemens.com/motioncontrol

High Bridge Combined Cycle Plant

WHMIS. Canada Wide Standard that focuses on hazardous materials and their:

SUPERVISORY SYSTEM FOR THE TURBINE GENERATOR SET OF ANGRA 1 NPP

Unit No.4-1 Higashi Niigata Thermal Power Station Operating Status O C Class Gas Turbine Operation -

Class VIII CBSE Chemistry Study Notes for Combustion and Flame

Engineering Thermodynamics

Prohibition of Boiler Feed Water Pump Failure in Power Plant

THE USE OF ROTOR DIAGNOSIS FOR THE ANALYSIS OF HIGH VIBRATION EXPERIENCE AT TURBINE-GENERATOR SYSTEM IN NUCLEAR POWER PLANTS

Fire Precautions and Fire Fighting

Vocabulary. Heat production and transfer

Trial Operation Results of Steam Cooled M501H Type Gas Turbine

NATIONAL COMPETENCY STANDARD

Contents. Part I Design: Theory and Practice 1

Define Ventilation. Ventilation - The process of removing smoke, heat and toxic gases from a building and replacing them with air

Course 0101 Combined Cycle Power Plant Fundamentals

Vibration Diagnostics

Ultrasonic Monitoring of a Fiber Reinforced Plastic Steel Composite Beam During Fatigue

Risk Control at United Fire Group

MEC-MOS-E-2004 Gas Turbine Maintenance Engineer PERSONAL DATA EDUCATION LANGUAGES COMPUTER SKILLS TRAINING COURSES AND CERTIFICATIONS

ROTATING AND TURBOMACHINERY SERVICES C TEC

1. vapours or gases subject to pressures greater than 0.5 bar, 2. vapours at such temperatures that their vapour pressure is greater than 0.5 bar.

Development of 700 C Class Steam Turbine Technology

COMBUSTION TURBINE PRINCIPLES

Supercritical CO2 Brayton Cycles and Their Application as a Bottoming Cycle. Grant Kimzey UTSR Intern Project Summary Webcast September 7, 2012

Dismantling of a Heat Exchanger

Cook Nuclear Plant Unit 1 - Event and Recovery

Nuclear I&C Systems Basics. The role of Instrumentation and Control Systems in Nuclear Power Plants, and their Characteristics

Carrington Power Station

Safety and Health Plan (PSS)

Sections of the Health Safety and Welfare at Work Act 2005 directly affecting maintenance management.

NUCLEAR TRAINING CENTRE COURSE 134 FOR ONTARIO HYDRO USE ONLY

Gas turbines have been used for electricity generation. Gas turbines are ideal for this application as they can be started and stopped quickly.

MANAGER'S TOOLKIT. Behavior-Based Safety

Thermography-Excellent tool for Condition Monitoring in Industries

Flexible Operation. Integrating thermal power with Renewable Energy & Challenges. Y M Babu Technical Services, Noida

COMPRESSOR DESIGN, OPERATION & MAINTENANCE Hosted by Technology Support Limited Presented by Carmagen Engineering, Inc.

MATERIAL SAFETY DATA SHEET. Polypropylene

Energy and the Environment

Maintenance Optimization: A Critical Aspect of the Equipment Reliability Program

COLLECTION AND INCINERATION OF HIGH VOLUME-LOW CONCENTRATION PULP MILL NONCONDENSIBLE GASES

GAS-FIRED COMBINED-CYCLE POWER PLANTS HOW DO THEY WORK? A company of

Industrial Hygiene. Introduction to Industrial Hygiene ENVIRONMENTAL SCIENCE

Allianz Global Corporate & Specialty. Safety. Wind turbines. Cause investigation and consulting services. Allianz Center for Technology

Atoms for the Future 2013 Loss of Off Site Power: An Operator s Perspective

Item 36 has not been slated for public release in 2011.

❸ MAKING THE JOB SAFER

Acceptance Criteria in DBA

Marshall Municipal Utilities EXCAVATIONS AND TRENCHING Effective August 1, 2011 Revised August 17, 2017

Safe remaining lifetime assessment of power plant steam boilers

Performance Assessment and Benchmarking in Application: Turbine Control System

Material Safety Data Sheet

ES Fluid & Thermal Systems Page 1 of 6 STEAM TURBINE LABORATORY

Fuji Electric s Medium-capacity Steam Turbines FET Series

KAROLINA KOWAL. Warsaw University of Technology Student. Warsaw University of Technology Student

Legal Summary SHE-037 Handbook of Business Operation in Thailand s Industrial Estate Version 2

Transcription:

Workshop Functional Safety Workshop Functional Safety Nieuwegein 12 March 2014 VDMA 4315 Part 6 Page 1

Three com petitors peacefultogether? Why? What? Outcome! Page 2

Why? Functional safety was relative new stuff application power industry 2005 2010 different interpretations in turbine industry manufacturer, customers, authorities What? Process group analyses details of standard requirements prepares common "VDMA Turbine" risk graph Turbine groups judge their product applying common Risk graph Outcome! Common interpretation of standard application Recommendations for main Safety Instrumented Systems VDMA specification 4315 with parts 1; 5; 7; 8 Page 3

Process Team Steam turbine Team Compressor Team Gas Turbine Team Generator Team Members Alstom Atlas Copco Alstom Alstom MAN Turbo MAN Turbo MAN Turbo Siemens Siemens Siemens Siemens Page 4

Gas Turbine Part 6 Required boundaries Common Risk graph Manpower plan (who is how often at GT) Main list of protections (SIS-safety instrumented systems) Experienced team Valid for installation of the machinery in a normal industrial environment (mechanical drives) or in a large power plant environment (generator sets) e.g. means not in the mid of a soccer station or near to very poisoning chemicals in tanks etc. risks due to consequential damage on a neighboring plant that is not to be evaluated are not considered Page 5

VDMA Risk Graph Probability of occupancy F probability of not avoiding the hazardous event AV Rate of occurrence of the hazardous event W Severity of the harm S Page 6

Manpower plan for determ ining the probability of occupancy F Page 7

Manpower plan for determ ining the probability of occupancy F Occupancy near to machine or inside enclosure (if present) is very very rare only 1-2 persons some percentage of time Occupancy inside machine building is rare, some persons 10 to 30% of time Large number of persons in machine building or at site is seldom Page 8

Analyzed SIS, i.e. protection functions 30 protection functions have been analyzed this covers most of the gas turbine designs special functions which may be applied only to certain designs are not covered Applied method VDMA Risk graph Standard sheet to analyze all SIS systematically Hazard description, hazardous zone Risk estimation Explanation of risk estimation Detailed example for risk analysis over speed Page 9

6.1 Over speed protection Page 10

Title Hazard description (reference situation) Hazard: Egress of parts of the machine as a consequence of over speed Causes: 1. Load shedding and failure of control circuit 2. Running up with control circuit malfunction 3. Isolated operation or no-load and simultaneous failure of the speed control circuit (mechanical, electronic, hydraulic) 4. Failure of generator excitation current 5. Coupling fracture Consequences: Destruction of the turbine due to the rotor or coupling rupture. Egress of broken pieces of blade or broken pieces of the discs Fire as secondary damage, Escape of hot gas, Escape of fuel Serious harm or damage, fire Page 11

Risk estimation Gas turbines for generator drive, for single and multiple shaft gas turbines Explanation of risk estimation without protective measure: S: The egress of rotor parts is considered, as this hazard requires the highest SIL. Page 12

Risk estimation Gas turbines for generator drive, for single and multiple shaft gas turbines Explanation of risk estimation without protective measure: F: Starting: Starting from the control room. F1 In normal operation: Directly at machine: In case of pure hazard for inspectors F1 but: In the indirect hazard zone (outside machine building) a maximum of 10 staff can be affected at the same time. Assumption: Continuous operation, then hazard greater than 10% of the daily working time. Continuous F= F2 Page 13

Risk estimation Gas turbines for generator drive, for single and multiple shaft gas turbines Explanation of risk estimation without protective measure: A V : Sudden occurrence of harm (less than 10s). Not possible to avert hazard, vulnerability low, large zone potentially covered, however probability of being hit is low, therefore PV 1. Page 14

Risk estimation Gas turbines for generator drive, for single and multiple shaft gas turbines Explanation of risk estimation without protective measure: W: For 1) load shedding typically once per year, simultaneous failure of all limiting measures in the process regulation in 10% of all cases. As such an allocation to W1 would be justified, W2 has been selected to have additional room for additional uncertainties. For 2 to 4) is covered by 1) For 5) no specific increase in the severity of the requirement compared to 1), as probability a factor of 100 to 1000 lower. Page 15

Risk estimation Gas turbines for generator drive, for single and multiple shaft gas turbines Page 16

Over speed protection generator drive / compressor drive Risk: Egress of rotor parts Parameter Risk Estimation Explanation S Severity 3 F Occupancy 2 Egress of rotor parts, possible fatality of 1 to 10 persons Rotor parts can be ejected far away, probable that persons are in area of risk AV Not avoiding 1 Sudden Occurrence, no defend against danger, but probability to be hit at a certain place small W Occurrence 2 / 1 SIL Safety Integrity Level 2 / 1 Generator drive: 1/year, e.g. load rejection and z. B. LAW and failure of control Compressor drive: rigidly connected machine, load cannot be rejected, 1/10 year SIL requirement different for generator drive and compressor drive Page 17

Flame supervision with and without downstream steam generator Risk: deflagrations/explosions of unburnt fuel gas in downstream systems Parameter Risk Estimation Explanation S Severity 3 / 2 F Occupancy 2 / 1 Falling boiler or structure parts, escape of hot steam, several persons may be exposed, severity up to fatalities. If only open stack, effects of explosions are smaller Around steam generator presence of persons probable, if only stack, hazard area is supposed to be smaller AV Not avoiding 2 / 1 W Occurrence 1 / 1 Harm occurs suddenly, avoidance not possible. Damage of large steam generator implies high vulnerability, If only stack, damages smaller and vulnerability is lower Occurrence seldom, as ignition sequence high excess of air, Spontaneous extinguishing of flame is infrequently SIL Safety Integrity Level 2 / --- Protection requirement SIL 2 with steam generator, if only stack no special protection requirement Page 18

Vibration Monitoring Risk: Imbalance on rotating parts Parameter S Severity F Occupancy AV Not avoiding W Occurrence SIL Safety Integrity Level Risk Estimation n.a. Explanation Vibration monitoring is applied for condition monitoring of the machine indication of required balancing Vibration monitoring can not o prevent rapidly occurring damage events, as they can result from material defects or material degradation, (before trip is activated damage has already happened) Vibrations increase slowly and therefore operation stuff has sufficient time to react. Fast increasing damage mechanism have to be covered by appropriate design measures (material selection, test examinations, design calculations). Page 19

Coupling monitoring, e.g. by vibration monitoring Risk: Ejection of parts Parameter Risk Estimation Explanation S Severity 3 F Occupancy 2 Mechanical damage possible, ejection of larger parts may happen, more than one person at risk Occupied zone is not limited, Occupancy of persons probable AV Not avoiding 1 Parts are some kind of ballistic risk, probability to be hit small W Occurrence 0 Accident database shows, that occurrence is very seldom, assumptions 1 time in 100 year SIL Safety Integrity Level a SIL a means a protection function is required without special safety requirements, this can be a vibration monitoring Page 20

Monitoring of exhaust gas temperature Risk: Damage of parts, may be ejection of parts Parameter Risk Estimation Explanation S Severity 3 F Occupancy 1 Only in exceptional cases high severity, as a general rule casing protects hazards to outside, pessimistic Damage is limited to the immediate surrounding AV Not avoiding 2 Development of a damage can not be recognized from outside of the turbine / enclosure W Occurrence 0 For parameter S high severity was judged, these are very seldom, assumption: 1 time a year SIL Safety Integrity Level a SIL a means a protection function is required without special safety requirements, this can be a protection against high exhaust gas temperatures. Page 21

Emergency stop Risk: nonspecific Parameter S Severity F Occupancy AV Not avoiding W Occurrence SIL Safety Integrity Level Risk Estimation 2 Explanation Emergency stop serves as manual action to avoid resp. limit unforeseeable events / hazards. Safety judgments are by reason of nonspecific nature for an emergency stop not possible. For the SIL classification the risk potential of a gas turbine should be considered. Therefore a classification of SIL 2 is appropriate and simple to realize, as the trip function components are available. Page 22

Fire at gas turbine or inside enclosure Risk: Impact of heat of fire and smoke poisoning Parameter Risk Estimation Explanation S Severity 3 F Occupancy 1 In a pessimistic way a large fire with severe effect and severity is assumed At endangered area directly at the gas turbine rarely personal is present AV Not avoiding 1 As a rule fire can be recognized and allows with this to escape from affected areas W Occurrence 0 The pessimistic event of a large fire is very seldom, 1 time in 100 years SIL Safety Integrity Level --- No protection required, normally protection is available to limit property damage Page 23

Asphyxiation through release of CO 2 fire extinguishing system Risk: Asphyxiation and poisoning Parameter Risk Estimation Explanation S Severity 3 CO2 as breathing poison leads in less than 1 minute to unconsciousness and without rescue to death F Occupancy AV Not avoiding n.a. 1 Area inside noise enclosure not allowed to access at operation, administrative measures Optical and acoustic warning 30 sec before CO2 extinguishing starts W Occurrence 2 1 per year false release, release not based on method of functional safety, expected value lower SIL Safety Integrity Level a Protection: administrative measures, access to enclosure limited, if CO2 release to be blocked, warning 30 sec before release of CO2 Page 24

Operation at very low temperatures Risk: Brittleness of material, Rotor failure due to fracture Parameter Risk Estimation Explanation S Severity 3 F Occupancy 2 Comparable with rotor failure at over speed Can be subject to the whole facility site, occupancy rate high AV Not avoiding 2 Damage occurs suddenly, No risk prevention possible W Occurrence -1 Occurrence rate small, slow cooling down, administrative measures concerning heater, failure end of life (number of starts), combination of unfavorable conditions SIL Safety Integrity Level a Protection may be required, e.g. temperature measurement Page 25

Risk Analysis gas turbine protection 30 protection functions have been analyzed 9 risk assessments have been presented Result is: SIL 2: 3 SIS (over speed generator drive, flame monitoring, emergency button) SIL 1: 2 SIS (electrical gas heaters, over speed mechanical drive) SIL a: 7 SIS ("a" means design according proven technology) n. a. : 13 SIS (without special requirements on safety integrity) --- : 5 process risks without protection requirement Page 26

Conclusion: VDMA-Specification part 6 Risk assessment gas turbines Supports judgment of risks of gas turbine operation Differentiates risks in SIL levels /requirements leads to a standardization of the application of functional safety Are gas turbines now safer??? No, they are as safe as before!!! But functional safety application has lead to a review of protection functions and ensure a proper documentation of risk assessments. Page 27

Let me end with 2 illustrations Risk is nothing showing that: new Risk is relative Thank you for your attention Page 28

Title. Page 29