Pressure Transmitter Series 2000T and 265Ax, 265Gx, 265Vx, 265Dx, 265Jx, 267Cx, 269Cx
Instructions for Functional Safety
4
Relevant standards
Standard
IEC 61508,
Part 1 to 7
IEC 61511,
Part 1
5
Terms and definitions
Terms
Dangerous failure
Safety-related system
Safety function
6
Determination of the Safety Integrity Level (SIL)
The reachable Safety Integrity Level depends on the following safety-related characteristics:
• Average probability of failure on demand (PFDav)
• Hardware fault tolerance (HFT)
• Safe failure fraction (SFF).
The specific safety-related characteristics for the transmitter as a part of the safety function are detailed in chapter
"Safety-related characteristics".
The following table shows the dependence of the Safety Integrity Level (SIL) on the average probability of failure on
demand (PFDav). The "Low demand mode" is considered, i.e. the maximum demand rate on the safety-related sys-
tem is once per year.
Safety Integrity Level (SIL)
The sensor, the logic unit and the final control element form together a safety-related system which carries out a
safety function. The average probability of failure on demand (PFDav) is usually distributed over the subsystems
(sensor, logic unit and final control element) as seen in the illustration below.
Fig. 6-1: Normal distribution of the average probability of failure on demand
(PFD
Designation
Functional safety of electrical/electronic/programmable electronic safety-related systems (Target group:
Manufacturers and Suppliers of Devices)
Functional safety – Safety Instrumented Systems for the process industry sector (Target group: Safety
Instrumented Systems Designers, Integrators and Users)
Definitions
Failure with the potential to set the safety-related system to a dangerous or inoperative state.
A safety-related system carries out the safety functions needed to establish or maintain a
safe state e.g. in a plant.
Example: A pressure gauge, a logic unit (e.g. limit signal transmitter) and a valve form a safe-
ty-related system.
A defined function carried out by a safety-related system in order to establish or maintain a
safe state of the plant under consideration of a specified dangerous incident.
Example: Pressure limit monitoring
4
PFD
av
3
2
1
Sensor
e.g. pressure
sensor
≤
35 %
) over the subsystems
av
(Low demand mode)
≥ 10
-5
-4
...< 10
≥ 10
-4
-3
...< 10
≥ 10
-3
-2
...< 10
≥ 10
-2
-1
...< 10
Logic unit
e.g. PLC
≤
15 %
SM 265/7/9 SIL-EN
Final control
element
e.g. valve
≤
50 %
4