L. Safety Audits
SIS safety audits are requirements for validation of the design safety function.
IEC 61511, true to the criteria of a performance base standard, has no specific requirements regarding the frequency or the procedures. However, the safety audits must be independent and objective.
Process industry experience would indicate that:
- Audit frequency of 3 years is a starting point. Based on the number of negative findings, the frequency may be adjusted accordingly.
- Individuals conducting the audit should be independent of the plant personnel.
- Standards and/or Corporate documents against which the audit is to be conducted, should be agreed upon in anticipation.
- Procedures review should reveal if they are in place, understood and followed.
- Interviews should start with managers, followed by engineering and finally operation and maintenance personnel.
- All maintenance and testing records should be reviewed in detail.
- Especially critical is the review of management of change records.
- Visual inspection of field equipment condition and tagging is a key indicator of general health.
- Checking for unauthorized systems in bypass is critical.
- Records of the SIL for each SIF should be clearly documented.
- Records of the validation of the SIL and RRF for each SIF should be documented.
- Records of the number and cause of process demands should be clearly documented.
- Records of the number and cause of nuisance trips should be clearly documented.
- Records of the actual failure rates of the SIS devices, as they compare to the design assumptions, should be clearly documented.
- Documentation should reflect up to date installed hardware and software.
The safety audits are normally conducted by corporate personnel independent of the plant and/or by specialized consulting companies, such as Premier Consulting Services.
SCAMP® Safety Compliance Auditing and Maintenance Program is an excellent service for this phase of the safety lifecycle and compliance to IEC 61511 clause 16.1.1, which states: "To ensure that the required SIL of each safety instrumented function is maintained during operation and maintenance". "To operate and maintain the SIS so that the designed functional safety is maintained."