Functional Safety 2018
© Institute of Measurement and Control 2018
Third Layer of Protection: SIL 1
The SIL 1 rated system failed to operate due to:
1. A fundamental flaw in the specification and design
2. The design flaw was overlooked by an Independent Functional Safety
Assessment (FSA)
3. The flaw was not discovered due to inadequate “proof” testing during
system commissioning
Specification – Failure Example
SIS Specification and Design Functionality
SIS Specification and Design Integrity
SIS functionality was tested and was found to operate when the level of liquid in the vapour
knock-out pot reached 6 Litres or the pressure in the vapour line reached 46mbar.
After the incident the pot was drained and 5 Litres was found to be present hence not
enough liquid had entered the vapour system quickly enough to activate the SIS system
prior to the vehicle overtopping form the vehicles man-lid with relief valve.