M. Modifications / MOC
IEC 61511 requires that modifications to any safety instrumented system (SIS) are properly planned, reviewed and approved prior to making the change. Additionally, the required safety integrity of the SIS should be maintained despite any changes performed.
Management of Change (MOC) procedures should be in place and all requirements of the SRS should be assessed.
- Prior to making any modifications to the SIS, procedures for authorizing and controlling changes should be effective and understood.
- MOC authorizations should identify the hazards which may be affected.
- Modifications require a functional safety impact analysis prior to authorization.
- Any impact on safety requires returning to the first affected step in the safety lifecycle
- Modifications that imply a change of hardware or software calls for returning to the first affected step in the safety lifecycle (i.e. replacement in kind, proven-in-use, minimum hardware fault tolerance, maximum SIL claim limit, etc).
- Tests should verify that the changes were properly implemented.
- Tests should ensure that functional safety is not negatively affected.
- Modifications should be performed by qualified and competent personnel.
- All affected and appropriate personnel should be notified and trained regarding the change and its implications.
- Documentation should be updated to reflect the modifications, including the reason for the change, the hazards affected and the tests performed to verify that the safety integrity is maintained.
Modifications are normally performed by the user/operator and or a maintenance contractor, with supervision of competence engineering and safety personnel.