SACA Safety Systems and Functional Safety 2 — Questions and Answers
Question 1: In safety system voting logic, what does a '1oo2' (one-out-of-two) architecture mean?
- One sensor is active while the second serves only as a backup
- Either one of two sensors detecting the hazard is sufficient to initiate a safety action (Correct answer)
- Both sensors must agree before a safety action is taken
- One sensor votes while the second is placed in standby mode
Correct answer: Either one of two sensors detecting the hazard is sufficient to initiate a safety action
A 1oo2 architecture initiates the safety function if either one of two sensors detects an abnormal condition, improving availability at the cost of potentially more spurious trips.
Question 2: Which IEC standard specifically addresses Safety Instrumented Systems (SIS) for the process industry sector?
- IEC 61508
- IEC 61511 (Correct answer)
- ISO 13849
- IEC 62061
Correct answer: IEC 61511
IEC 61511 is the process-industry sector application of IEC 61508, covering engineering and operation of SIS in oil, gas, and chemical plants.
Question 3: Probability of Failure on Demand (PFD) is used to measure:
- The likelihood a safety system fails to act when a safety demand occurs (Correct answer)
- The frequency of spurious trips per year in normal operation
- The probability that normal production will be interrupted by a control fault
- The chance that a sensor reading will drift during steady-state operation
Correct answer: The likelihood a safety system fails to act when a safety demand occurs
PFD quantifies the probability that a safety function will fail to perform its intended action when a demand occurs, and is used to verify that the required SIL target is met.
Question 4: The safety lifecycle concept in IEC 61508 requires that safety activities be performed:
- Only during initial design and commissioning
- Throughout all phases from concept through decommissioning (Correct answer)
- Only when the system undergoes a major modification
- During production operation and scheduled maintenance only
Correct answer: Throughout all phases from concept through decommissioning
The IEC 61508 safety lifecycle is a cradle-to-grave approach encompassing concept, design, implementation, operation, maintenance, and decommissioning to ensure functional safety is maintained throughout.
Question 5: Per IEC 60204-1, Stop Category 0 on a machine is defined as:
- A controlled deceleration to stop before removing power
- An immediate removal of power to the machine actuators (Correct answer)
- A stop triggered only by a safety PLC command
- A stop that requires manual reset before restarting
Correct answer: An immediate removal of power to the machine actuators
Stop Category 0 is an uncontrolled stop achieved by immediately removing power (or interrupting energy) to the machine actuators, which is the default safe state for E-stop functions.
Question 6: What is a 'safe state' in the context of a Safety Instrumented Function (SIF)?
- A state where production throughput is maximized
- A predefined condition where risk to personnel and equipment is reduced to an acceptable level (Correct answer)
- A state where all process alarms have been cleared
- A state where the control system has been switched to manual mode
Correct answer: A predefined condition where risk to personnel and equipment is reduced to an acceptable level
The safe state is the predefined, stable condition to which a process or machine is brought when the SIF is activated, minimizing risk to personnel, equipment, and the environment.
Question 7: What is the key difference between a Safety Instrumented System (SIS) and a Basic Process Control System (BPCS)?
- A SIS controls the process continuously while a BPCS activates only on safety alarms
- A SIS is an independent protection layer that acts when the BPCS cannot keep the process safe (Correct answer)
- A BPCS must meet higher SIL requirements than the SIS it supports
- There is no functional difference; they serve the same control purpose
Correct answer: A SIS is an independent protection layer that acts when the BPCS cannot keep the process safe
The SIS is separate and independent from the BPCS; while the BPCS handles normal process control, the SIS acts as an independent safety layer that activates when the BPCS fails to prevent a hazardous condition.
In safety system voting logic, what does a '1oo2' (one-out-of-two) architecture mean?