Operating instructions
Functional safety
8.1 General safety notes
SIPART PS2 with and without HART communications
106 Operating Instructions, A5E00074631-09
Functioning of the system as shown in the example
The transmitter generates a process-specific analog signal. The downstream control system
monitors this signal to ensure that it does not fall below or exceed a set limit value. In case of
a fault, the control system generates a failure signal of < 3.6 mA or > 22 mA for the
connected positioner, which switches the associated valve to the specified safety position.
See also
Certificates (http://www.siemens.com/processinstrumentation/certificates)
8.1.2 Safety Integrity Level (SIL)
The international standard IEC 61508 defines four discrete Safety Integrity Levels (SIL) from
SIL 1 to SIL 4. Each level corresponds to the probability range for the failure of a safety
function.
Description
The following table shows the dependency of the SIL on the "average probability of
dangerous failures of a safety function of the entire safety-instrumented system" (PFD
AVG
)
The table deals with "Low demand mode", i.e. the safety function is required a maximum of
once per year on average.
Table 8- 1 Safety Integrity Level
SIL Interval
4 10
-5
≤ PFD
AVG
< 10
-4
3 10
-4
≤ PFD
AVG
< 10
-3
2 10
-3
≤ PFD
AVG
< 10
-2
1 10
-2
≤ PFD
AVG
< 10
-1
The "average probability of dangerous failures of the entire safety-instrumented system"
(PFD
AVG
) is normally split between the three sub-systems in the following figure.
6HQVRU
HJ
3UHVVXUH
WHPSHUDWXUHHWF
&RQWUROV\VWHPRU
/RJLFXQLW
HJ
3/&
3)'$9*SHUFHQWDJH
)LQDOFRQWUROOLQJ
HOHPHQW
HJ
9DOYHZLWKDFWXDWRU
DQGSRVLWLRQHU
Figure 8-2 Example of PFD distribution
The following table shows the achievable Safety Integrity Level (SIL) for the entire safety-
instrumented system for type B subsystems depending on the safe failure fraction (SFF) and
the hardware fault tolerance (HFT). Type B subsystems include analog transmitters and
shut-off valves without complex components, e.g. microprocessors (also see IEC 61508,
Section 2).
Chapter 8 is invalid and is replaced by
Compact operating instructions
"Functional Safety SIPART PS2" A5E00442120-04










