ISA CAP Risk Management & Mitigation 3 — Questions and Answers
Question 1: In fault tree analysis (FTA), what does an AND gate signify?
- The top event occurs if any one input event occurs
- The top event occurs only when all input events occur simultaneously (Correct answer)
- The event is a basic failure with no further decomposition
- The event is conditional on an external trigger
Correct answer: The top event occurs only when all input events occur simultaneously
An AND gate in a fault tree means all input events must occur simultaneously for the output (top) event to occur.
Question 2: What is the key distinction between a 'hazard' and a 'risk' in process safety terminology?
- Hazard is quantitative; risk is qualitative
- Hazard is the potential source of harm; risk combines likelihood and consequence (Correct answer)
- Hazard requires a SIL rating; risk does not
- There is no meaningful distinction in ISA standards
Correct answer: Hazard is the potential source of harm; risk combines likelihood and consequence
A hazard is an inherent property that can cause harm, while risk is defined as the combination of the probability of harm and the severity of that harm.
Question 3: Which layer of protection in a LOPA analysis is NOT typically credited as an Independent Protection Layer (IPL)?
- Basic Process Control System (BPCS) control loop (Correct answer)
- Pressure Relief Valve (PRV) sized and maintained per code
- Operator response to a dedicated alarm with adequate response time
- Dike or bund designed to contain a full liquid release
Correct answer: Basic Process Control System (BPCS) control loop
The BPCS initiating cause cannot simultaneously serve as an IPL because it shares common hardware and software with the initiating event, violating the independence requirement.
Question 4: What is 'common cause failure' (CCF) and why is it important in redundant safety systems?
- A single failure that defeats multiple independent channels simultaneously, undermining redundancy (Correct answer)
- A failure that occurs in the common utilities feeding the process
- A systematic failure caused by incorrect process design
- A failure mode that is detected during routine proof testing
Correct answer: A single failure that defeats multiple independent channels simultaneously, undermining redundancy
Common cause failure is a single event or root cause that causes multiple redundant components to fail simultaneously, potentially defeating the benefit of redundancy.
Question 5: In LOPA, what is the typical PFD credit assigned to a well-designed and maintained passive dike/bund as an IPL?
- 0.1
- 0.01 (Correct answer)
- 0.001
- 0.0001
Correct answer: 0.01
A properly designed and maintained dike or bund is typically assigned a PFD of 0.01 (1 in 100 chance of failure) in LOPA.
Question 6: What does the term 'safety lifecycle' in IEC 61511 encompass?
- Only the design and installation phases of a SIS
- All phases from hazard analysis through decommissioning of the safety system (Correct answer)
- The operational lifespan before a mandatory SIS replacement
- The certification interval for SIL verification
Correct answer: All phases from hazard analysis through decommissioning of the safety system
The safety lifecycle in IEC 61511 covers all phases including hazard analysis, design, installation, commissioning, operation, maintenance, modification, and decommissioning.
Question 7: What type of redundancy architecture is described as '2oo3' (two-out-of-three) voting?
- All three channels must fail for a safety action to occur
- At least two of three channels must agree on a demand for the safety action to occur (Correct answer)
- Two channels operate and the third is a cold standby
- Any single channel can independently initiate the safety action
Correct answer: At least two of three channels must agree on a demand for the safety action to occur
2oo3 voting requires at least two of three independent channels to detect the demand condition before the safety function is actuated.
In fault tree analysis (FTA), what does an AND gate signify?