Sabp Z 076
Sabp Z 076
Contents
1 Introduction............................................................................................... 2
2 Scope........................................................................................................ 3
3 Conflicts with Mandatory Standards.......................................................... 4
4 References................................................................................................ 4
5 Abbreviations............................................................................................ 5
6 Definitions................................................................................................. 6
7 Roles and Responsibilities........................................................................ 8
8 Preparation of Safety Requirements Specification (SRS)......................... 8
8.1 SRS Objective................................................................................. 8
8.2 SRS Template................................................................................. 9
8.3 SRS Development......................................................................... 21
1 Introduction
The SRS is a specification that contains all safety integrity requirements for each SIF
which must be achieved by the SIS in order to achieve the required functional safety as
determined during the SIL study. The SRS consists of general design requirements of the
SIS as well as specific integrity requirements for each individual SIF. Per SAES-B-058,
SAES-J-601 and SAEP-250 a single SRS is to be provided for each ESD system and the
SRS is required to identify each ESD function and its assigned SIL, even if the function is
assigned an integrity level of SIL 0.
The SIS requirements must be stated and structured in a clear, precise, verifiable,
maintainable and feasible manner. The SRS should be written to aid comprehension of
all individuals who will utilize the information at the various lifecycle phases.
This best practice has been developed to assure that quality SRS are developed in a
timely manner and used as the basis for SIS design, FAT, installation, commissioning,
validation, operation and maintenance as required by the applicable international
standards.
Page 2 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
2 Scope
This document provides guidance on SRS development to assure the content and style
of the SRS are consistent across all Saudi Aramco facilities.
This document provides an SRS template (Appendix A) to be used as a model for the
SRS development. Section 8 provided instruction for preparation of the SRS.
Page 3 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
The intent of the SRS template is to define a format that assures all process information,
SIS system requirements and SIF specific requirements are documented directly or by
reference in a single requirements document.
Define the roles and responsibilities of the various Saudi Aramco organizations in the
development, approval and implementation of the SRS.
This document is intended to comply with requirements for development of the SRS as
defined by ANSI / ISA-84.00.01-2004 (IEC61511-1 Mod), Functional Safety: Safety
Instrumented Systems for the Process Industry Sector - Part 1: Framework, Definitions,
System, Hardware and Software Requirements Clause 10, Saudi Aramco Engineering
Standard SAES-B-058, Saudi Aramco Engineering Standard SAES-J-601 and Saudi
Aramco Engineering Procedure SAEP-250.
Individual projects may add additional sections to the SRS to address vendor
requirements or specific project requirements. The SRS template should not be
modified in a manner that removes any requirements of ANSI/ISA-84.00.01-2004
(IEC61511-1 Mod).
The document does not define how the technical content for the SRS is developed.
In the event of a conflict between this Best Practice and Mandatory Saudi Aramco
Engineering Requirements (MSAERs), the Mandatory Saudi Aramco Engineering
Requirements shall govern.
4 References
Specific sections of the documents listed below are referenced within the body of this
standard. Where specific sections are not referenced the entire referenced document
shall apply.
Page 4 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
5 Abbreviations
BPCS Basic Process Control System
C&E Cause and Effect Diagram
CIL Commercial Integrity Level
DCS Distributed Control System
EIL Environmental Integrity Level
ESD Emergency Shutdown System
EUC Equipment under Control
E&PM Engineering and Project Management
FAT Factory Acceptance Test
HIPS High Integrity Protection System
IO Input/output
IL Integrity Level
IPL Independent Protection Layer
HAZOP Hazard and Operability Study
LOPA Layer of Protection Analysis
LPD Loss Prevention Department
MOC Management of Change
MSAER Mandatory Saudi Aramco Engineering Requirements
OO Operations Organization
P&CSD Process and Control System Department
PAN Process Automation Network
PAS Process Automation System
PCN Process Control Network
PCS Process Control System
PFDAvg Average Probability of Failure on Demand
PMT Project Management Team
P&ID Process and Instrumentation Diagram
RRF Risk Reduction Factor
Page 5 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
6 Definitions
Basic Process Control System (BPCS): System which responds to input signals from
the process, its associated equipment, other programmable systems and/or operator and
generates output signals causing the process and its associated equipment to operate in
the desired manner but which does not perform any safety instrumented functions with
a claimed SIL ≤ 1. [ANSI/ISA 84.00.01-2004 Part 1 (IEC61511-1 Mod) 3.2.3].
Commercial Integrity Level: Discrete level (one to four) for specifying the
commercial integrity requirements of an instrumented functions to be allocated to the
safety instrumented systems for the purpose of reducing commercial risk.
Common Cause Failure: Failure which is the result of one or more events, causing
failures of two or more separate channels in a multiple channel system, leading to
system failure. [ANSI/ISA 84.00.01-2004 Part 1 (IEC61511-1 Mod) 3.2.6.1].
Environmental Integrity Level: Discrete level (one to four) for specifying the
environmental integrity requirements of an instrumented functions to be allocated to the
safety instrumented systems for the purpose of reducing environmental risk.
Functional Safety: Part of the overall safety relating to the process and the BPCS
which depends on the correct functioning of the SIS and other protection layers.
[ANSI/ISA 84.00.01-2004 Part 1 (IEC61511-1 Mod) 3.2.25].
Page 6 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
Process Control System (PCS): The integrated system which is used to automate,
monitor and/or control an operating facility (e.g., plant process units). The PCS
consists of operating area Distributed Control Systems and their related auxiliary
systems which are connected together at the Process Control Network (PCN) and
Process Automation Network (PAN) level to form a single integrated system.
Safety Instrumented Function (SIF): Safety function with a specified safety integrity
level which is necessary to achieve functional safety and which can be either a safety
instrumented protection function or a safety instrumented control function.
[ANSI/ISA 84.00.01-2004 Part 1 (IEC61511-1 Mod) 3.3.71].
Safety Integrity Level (SIL): Discrete level (one to four) for specifying the safety
integrity requirements of the safety instrumented functions to be allocated to the safety
instrumented systems. Safety integrity level 4 has the highest level of safety integrity;
safety integrity level 1 has the lowest. [ANSI/ISA 84.00.01-2004 Part 1 (IEC61511-1
Mod) 3.2.74].
Page 7 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
Roles and responsibilities for development of the SRS are defined in Table 1.
TABLE 1
The objective of the SRS is to provide a single document which defines the
integrity requirements of the SIS and to communicate these requirements to the
individuals who will utilize the information throughout the SIS lifecycle.
These requirements should be sufficient to specify, design, test, install,
commission, validate, operate and maintain the SIS. The SRS should address
requirements of the logic solver, the individual SIFs, the process, plant operating
mode, plant maintenance activities, and any interfaces with the operator and
other systems.
The document should be concise, clear and easily understood by all users.
Depending on the process, there may be a single SRS for the entire SIS system
or there may be a separate SRS for each logic solver.
Page 8 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
The completed and approved SRS is the basis for design, test, installation,
commissioning, validation and maintenance of the SIS.
Page 9 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
SIL.
Section 4, the SIS Summary Table, provides a high level overview of the
functions implemented in the SIS associated with this particular SRS.
The summary table lists, for each function;
SIF Number – sequential number, e.g., SIF-001
SIF Name – name used in Cause and Effect Diagram (C&E) and on
P&ID, e.g., ZC-001
The target Integrity Level [i.e., SIL, Environmental Integrity Level
(EIL) and Commercial Integrity Level (CIL)]
Target RRF (list for each type IL)
Achieved SIL (List for each type IL)
Achieved RRF (List for each type IL)
Residual Risk (if any) (list for each type IL)
Identify systems/functions in other automation systems affected by
the SIS in this SRS, (such as SIS peer to peer communications or
initiation of SIFs located in other SIS.
Status of each SIF (active or decommissioned)
Note: The summary table should include all functions implemented in the
SIS even those with “no special IL requirements” functions, i.e., SIL 0.
The process description should state the planned turnaround for each unit
or train and identify any operational or licensor limits on the acceptable
Page 10 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
Identify and define requirements for any SIFs that must survive a major
incident, i.e., length of time an isolation valve needs to remain in
operation during a major fire.
Generally an SRS is prepared for each SIS (i.e., logic solver, relay panel,
etc.).
In some cases the plant may have multiple ESD’s. This section should
also provide a block diagram of the SISs for the entire facility and
highlight how the various ESD systems or logic solvers are grouped by
SRS.
Section 7.2 of the SRS should define the General SIS Design
Requirements. Table 3 lists the General SIS Design
Requirements which need to be defined in Section 7.2 of the
SRS.
Page 11 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
Selected technology e.g., TMR PES, DMR PES, Relay, Solid State
SIF Reset Method e.g., software, CR pushbutton, field
Unit Maintenance Turnaround Interval X years
Use of hardwired or software resets Hardwired/software
BPCS Hardware Product e.g., Honeywell C300
BPCS Software Revision e.g., R14x
SIS Hardware e.g., Honeywell Safety Manager
SIS Software Revision e.g., R15x
Asset Management Hardware Product name
Asset Management Software Revision Rxxx
Design MTTR (entire SIS) Hours
SIS Mission Life Years
Overall Availability Target %
UPS backup time Hrs
SIF Reset Philosophy Hardwired/software
Programming method State programming method to be utilized
Page 12 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
Page 13 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
Page 14 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
Page 15 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
Page 16 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
Page 17 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
Page 18 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
Item Description A B C
1 SIF Number/SIF Name -----Not Used-------
2 Facility/Plant/Unit
3 SIF Description
4 Hazard Description
Consequence Severity Rating
5
(SIL/EIL/CIL)
6 Process Safe State
7 Process Safety Time (minutes)
8 Safety Response Time (seconds)
9 Demand Rate (yr-1)/ Demand Mode -----Not Used-------
10 Demand Initiating Event Initiating Event Tag Description -----Not Used-------
-----Not Used-------
-----Not Used-------
11 Risk Targets SIL PFDavg RRF
12 Required (Target) SIL
13 Achieved SIL
14 Residual Risk EIL -----Not Used-------
Spurious Trip Rate
15
(acceptable/calculated) (yr-1) -----Not Used-------
16 SIF Architecture Description
SIF Inputs (including trips points and
17 Input Tag Trip Point Pre-Alarm
Pre-alarms)
Page 19 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
Item Description A B C
Page 20 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
Item Description A B C
Cause & Effect
Sequence Logic
Logic Narrative
Logic Printout
Operating Procedures
Maintenance Proof Test Procedures
IPL List
SIL Verification Report
DCS/ESD Communications Mapping
Instrument Specification Sheets (ISS)
Instrument Calculation Sheets
Instrument Piping Details
35 Notes:
The details of the SRS will be defined, developed and further refined over the
SIS lifecycle. The SRS should be developed immediately following the Risk
Allocation (SIL Assignment) effort. For this reason the major steps of SRS
development and validation should be included in the project schedule.
Revision Summary
21 February 2016 New Saudi Aramco Best Practice was created for the implementation of Virtual Servers
and Thin Clients for Process Automation Systems.
This best practice has been developed to assure that quality SRS are developed in a
timely manner and used as the basis for SIS design, FAT, installation, commissioning,
validation, operation and maintenance as required by Saudi Aramco and applicable
international standards.
Page 21 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
Page 22 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
This section is used to document sign-off of the final SRS and to track the revisions during
SRS development.
Approvals
PMT
Operations
Loss Prevention
P&CSD
Revision History
2. Executive Summary
This section contains the SRS Executive Summary, refer to requirements in SABP-XXX
Section 8.2.2
3. Acronyms
Page 23 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
This section is a summary of all SIF’s in the ESD system. The details should be per SABP-XXX Section 8.2.4.
Page 24 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
5. Process Overview
Block diagram showing the relationship between this ESD and other plant ESD systems,
see SABP-XXX Section 8.2.6.
This section documents the SIS general design requirements and design philosophies.
The details of this section are defined in SABP-XXX Section 8.
Page 25 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
Explanation of design philosophies which affect design of SIS. See SABP-XXX Section
8.2.2 Table 4 for topics to be addressed.
Explanation of IO functionality that affect SIS hardware design. See SABP-XXX Section
8.2.3 Table 5 for topics to be addressed.
Explanation of SIS communications requirements that will affect SIS hardware and
software design. See SABP-XXX Section 8.2.4 Table 6 for topics to be addressed.
Explanation of SIS faults which may affect the SIS hardware and software design.
See SABP-XXX Section 8.2.5 Table 7 for topics to be addressed.
Explanation of SIS device faults which may affect the SIS hardware and software design.
See SABP-XXX Section 8.2.6 Table 8 for topics to be addressed.
Explanation of Operator Interface requirements which may affect the SIS hardware and
software design. See SABP-XXX Section 8.2.7 Table 9 for topics to be addressed.
Page 26 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
8. SIF Details
Item Description A B C
1 SIF Number/SIF Name -----Not Used-------
2 Facility/Plant/Unit
3 SIF Description
4 Hazard Description
5 Consequence Severity Rating (SIL/EIL/CIL)
6 Process Safe State
7 Process Safety Time (minutes)
8 Safety Response Time (seconds)
9 Demand Rate (yr-1)/ Demand Mode -----Not Used-------
10 Demand Initiating Event Initiating Event Tag Description -----Not Used-------
-----Not Used-------
-----Not Used-------
11 Required (Target) SIL/PFDAvg/RRF
12 Achieved SIL/ PFDAvg /RRF
13 Residual Risk PFDAvg /RRF
14 Spurious Trip Rate (acceptable/calculated) (yr-1) -----Not Used-------
15 SIF Architecture Description
SIF Inputs (including trips points and
16 Input Tag Trip Point Pre-Alarm
Pre-alarms)
Page 27 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
Item Description A B C
Action on loss of power to equipment under
18
control (EUC)
Special Modes of Operation that SIF where is
19
required to function
20 Documentation References
HAZOP
LOPA
P&ID
Cause & Effect
Sequence Logic
Logic Narrative
Logic Printout
Operating Procedures
Maintenance/Proof Test Procedures
21 IPL List
22 SIL Verification Report
23 DCS/ESD Communications Mapping
24 Instrument Specification Sheet (ISS)
25 Notes:
End of SRS
Page 28 of 29
Document Responsibility: Process Control Standards Committee SABP-Z-076
Issue Date: 21 February 2016
Next Planned Update: TBD Guideline for Development of Safety Requirement Specification (SRS)
Page 29 of 29