Technical data referring to the fail safe unit, the actuator and actuator controls. Declaration of incorporation and EU declaration of conformity for the fail safe unit. SIL Declaration of Conformity on functional safety (order related) Reference documents are available on the Internet at: http:\\www.auma.com. Table of contents Page Terminology..........................
Page 3
with non safety-related actuators Table of contents 5.3. Operation 5.4. Lifetime 5.5. Decommissioning 5.6. Disposal and recycling Indications..........................Signals............................. 7.1. Signals via FS module 7.2. Status signals via output contacts (digital outputs) of actuator controls 7.3. Signals via fieldbus of actuator controls Tests and maintenance......................
Terminology with non safety-related actuators Terminology IEC 61508-4, Functional safety of electrical/electronic/programmable electronic Information sources safety-related systems Part 4: Definitions and abbreviations IEC 61511-1, Functional safety - Safety instrumented systems for the process industry sector Part 1: Framework, definitions, system, hardware and software requirements 1.1.
Page 5
with non safety-related actuators Terminology Periodic test performed to detect dangerous hidden failures in a safety-related system Proof test so that, if necessary, a repair can restore the system to an "as new" condition or as close as practical to this condition. Mean time to restoration once a failure has occurred.
2.1. Range of application AUMA actuators and actuator controls with the safety functions mentioned in this manual are intended for operation of industrial valves and are suitable for use in safety instrumented systems in accordance with IEC 61508 or IEC 61511.
Page 7
In applications with requirements on functional safety, only AUMA fail safe units in Information SIL version may be used. AUMA fail safe units in SIL version can, among others, be identified by the characters “SIL-V1.y.xx” following the ESD designation: ... on the name plate.
Architecture, configuration and applications with non safety-related actuators Architecture, configuration and applications 3.1. Architecture (actuator sizing) For actuator architecture (actuator sizing) including a fail safe unit, the maximum torques, run torques and operating times are major factors be taken into consideration. Incorrect actuator architecture can lead to device damage within the safety- related system! Possible consequences are for example: Valve damage, motor overheating, contactor...
Page 9
Typical fail safe operating times under standard conditions (in seconds) Configuration: Configuration: switch 30 %/max. Fail-Safe operating time 10 %/min. Fail-Safe operating time Bridge between None None XF … and XF … 31-32 31-33 31-34 31-32 31-33 31-34 FQM 05.1 FQM 07.1 FQM 10.1 FQM 12.1...
Architecture, configuration and applications with non safety-related actuators Configuration options for safety function Table 4: Configuration options for safety function Configuration Short description Initiated by SIL function Safe ESD CLOSE Safe CLOSING ESD or mains failure Safe ESD OPEN Safe OPENING ESD or mains failure Safe end position Signal is issued whether one of both...
with non safety-related actuators Safety instrumented system and safety functions Safety instrumented system and safety functions 4.1. Safety instrumented system including an actuator Typically, a safety instrumented system including an actuator is composed of the components as shown in the figure. Figure 2: Typical safety instrumented system Sensor Controls (standard and safety PLC)
Safety instrumented system and safety functions with non safety-related actuators Safe ESD OPEN/CLOSE: safe OPENING/CLOSING) Fail safe position: Fail safe unit operates in the defined operating time into the configured fail safe position (OPEN/CLOSED). Safe state is reached if the FQM has operated the mounted valve into the defined safety end position (OPEN/CLOSED) or the safe state is main- tained by the FQM.
with non safety-related actuators Safety instrumented system and safety functions ➭ page 16, Installation 4.4. Redundant system architecture Besides the already described typical safety instrumented system including an actuator, safety can be increased by implementing a second, redundant actuator with fail safe unit into the safety instrumented system. The decision on the appropriate version depends on the entire system.
Safety instrumented system and safety functions with non safety-related actuators 4.5. Application example Safe CLOSING of a tank farm using the Safe ESD function Standard PLC controls the overall system for filling the tank. A system fault occurs if the filling level or the tank pressure exceed the permissible specified level. In this case, the safety PLC immediately closes the valve for tank filling.
with non safety-related actuators Safety instrumented system and safety functions The following items are indications for potential FQM faults and must be continuously monitored by the safety PLC: If based on the standard operational status of the fail safe unit (“FS ready” signal and ESD high level input), the FS ready NO FS failure NC...
Installation, commissioning and operation with non safety-related actuators Installation, commissioning and operation Installation and commissioning have to be documented by means of an assembly Information report and an inspection certificate. Installation and commissioning must be carried out exclusively by suitably qualified personnel. Opening covers or unfastening screws is only permitted if the pertaining description is available in this manual or in the operation instructions.
Page 17
100 mA For the safe signals ( outputs as well as FS Ready FS Failure AUMA recommends the exclusive use of nominal 24 V DC signal voltages. Table 5: Example (refer to wiring diagram pertaining to order) Designation Signal Customer connections...
3 of the German version of IEC 61508-2:2010 7.4.9.5 b). This is the responsibility of the operator who will have to take appropriate and suitable measures. These measures must at least include a service by AUMA Riester GmbH & Co. KG. The above mentioned 500 fail safe cycles must not be exceeded.
with non safety-related actuators Installation, commissioning and operation 5.5. Decommissioning When decommissioning an actuator with safety functions, the following must be observed: Impact of decommissioning on relevant devices, equipment or other work must be evaluated. Safety and warning instructions contained in the actuator operation instructions must be met.
Indications with non safety-related actuators Indications Indications at actuator controls which are only available in combination with fail safe units, are described in the FQM operation instructions. General indications as well as settings and operation are described in the operation instructions pertaining to the actuator as well as in the Manual (Operation and setting) AC 01.2/ACExC 01.1 actuator controls.
with non safety-related actuators Signals Signals 7.1. Signals via FS module The integral FS module signals a fail safe fault via the fault relay ( FS ready NO outputs). Only these signals may be used in a safety-related FS failure NC system.
Tests and maintenance with non safety-related actuators Tests and maintenance Test and maintenance tasks may only be performed by authorised personnel who have been trained on functional safety. Test and maintenance equipment has to be calibrated. Within the lifetime of 10 years or the maximum number of cycles or modulating steps indicated in the <Lifetime>...
with non safety-related actuators Tests and maintenance A suitable FVST (Full Valve Stroke Test) or a suitable standard operation can replace the PVST provided that the operation is signalled to a safety PLC and the safety PLC is programmed as to control the following test sequence. If safe end position feedback is required for both end positions, and if the diagnostic coverage is to be used for the PVST, the PVST must be started from both end positions.
If a fault occurs during proof test, safe function has to be ensured introducing alternative actions. Please contact AUMA Riester GmbH & Co. KG. The type of proof test to be performed depends on version and configuration of the product.
with non safety-related actuators Tests and maintenance Operate actuator into end position OPEN (Safe ESD in direction CLOSE), or Test sequence into end position CLOSED (Safe ESD in direction OPEN). Information: For the test, operation commands (in directions OPEN or CLOSE) can be executed both from Remote (via DCS) and from Local at the controls (via the push buttons of the local controls).
Tests and maintenance with non safety-related actuators Initiate safety operation: Interrupt the FQM power supply. Information: Reaction time upon interruption is up to 10 seconds. When leaving the end position, start the operating time measurement. The FQM end position switch indicates the unseating from end position by signal change.
<Safety equipment: check> and <Proof test (verification of safe actuator function)> chapters. In case a fault is detected during maintenance, this must be reported to AUMA Riester GmbH & Co. KG.
Page 28
Tests and maintenance with non safety-related actuators AUMA actuators prioritise motor operation to manual operation. This means that the Information actuator automatically switches to motor operation if requested. However, we recom- mend activating motor operation after any maintenance and service interventions.
with non safety-related actuators Safety-related figures Safety-related figures 9.1. Determination of the figures The calculation of the safety-related parameters is based on the indicated safety functions. Hardware assessments are based on Failure Modes, Effects and Diagnostic Analysis (FMEDA). FMEDA is a step to assess functional device safety in compliance with IEC 61508.
Page 30
Safety-related figures with non safety-related actuators Furthermore, the following assumptions were made: The failure rates for the “Safe end position feedback” safety function always refer to an end position feedback signal (i.e. either to “OPEN” or “CLOSED”). If both end positions are used within the safety function, the indicated parameters must be accounted once for end position OPEN and once for end position CLOSED.
Page 31
with non safety-related actuators Safety-related figures ESD safety function with PVST Table 6: Safety instrumented figures and failure rates according to IEC 61508-2: 2010 Fault category Key performance indicators λ λ 273 FIT λ 784 FIT λ 513 FIT 67 % 60 % 95 % SIL AC...
Page 32
Safety-related figures with non safety-related actuators Table 8: Safety figures and failure rates according to ISO 13849-1 for feedback of one end position (OPEN or CLOSED) with PVST Fault category Failure rates MTTF (years) 787 (high) 71 % (low) Category (CAT) CAT 1 or CAT 2 Performance Level (calculated) 4.2E-08 1/h...
Checklists with non safety-related actuators Configuration ✎ Configuration ✎ Safe CLOSING Safe OPENING (ESD in direction fail safe position CLOSED) (ESD in direction fail safe position OPEN) FQM starts automatic initialisation (spring is wound) ⎕ ✓ FQM starts automatic initialisation (spring is wound) ⎕...
Page 35
with non safety-related actuators Checklists “Safe end position feedback” safety function Applies also for combination with of Safe ESD in direction OPEN/CLOSE. Only the actually used (assigned) contacts must be checked. In particular for variant 1 (➭ page 6, Valid device types), use of the NC contacts is not permit- ted;...
Checklists with non safety-related actuators Configuration ✎ Fail safe position OPEN and CLOSED (safety position OPEN and CLOSED) ➥ check FQM end position switch: ⎕ Yes ⎕ No End position OPEN not reached signal (output signal inactive), i.e.: LSO 38-20=NC output (NC contact) = closed LSO 19-21=NO (NO contact) output = open...
with non safety-related actuators Index Index Partial Valve Stroke Test (PVST) Actuator definition PFD for actuator Actuator monitoring internal Probability of failure Ambient conditions Proof test 5, 24, 24 Architecture Proof test checklists Certificate Range of application Checklists 33, 33 Recycling Commissioning Commissioning checklist...
Page 44
AUMA Riester GmbH & Co. KG P.O. Box 1362 DE 79373 Muellheim Tel +49 7631 809 - 0 Fax +49 7631 809 - 1250 info@auma.com www.auma.com Y008.255/003/en/1.21.V01 For detailed information on AUMA products, refer to the Internet: www.auma.com...
Need help?
Do you have a question about the FQM 05.1 and is the answer not in the manual?
Questions and answers