SACA Safety Systems and Functional Safety 5 — Questions and Answers
Question 1: What is a 'common cause failure' (CCF) in the context of redundant safety systems?
- A failure that occurs only in a single channel
- A single event that causes multiple redundant channels to fail simultaneously (Correct answer)
- A failure mode exclusive to software components
- A fault detected by the diagnostic self-test
Correct answer: A single event that causes multiple redundant channels to fail simultaneously
Common cause failure is a single root cause (e.g., a shared environment, design flaw, or maintenance error) that defeats multiple redundant channels at the same time.
Question 2: In the context of the Safety Lifecycle, what activity immediately follows the Hazard and Risk Assessment?
- Installation and commissioning of the SIS
- Definition of overall safety requirements (Correct answer)
- Selection of safety integrity level
- Design and engineering of the safety function
Correct answer: Definition of overall safety requirements
After identifying hazards and assessing risks, the next step in the IEC 61508/61511 safety lifecycle is to define the overall safety requirements that the system must meet.
Question 3: Which metric quantifies the average probability that a safety function will fail to respond when a demand occurs?
- SIL (Safety Integrity Level)
- PFD (Probability of Failure on Demand) (Correct answer)
- MTTFd (Mean Time to Dangerous Failure)
- DDC (Dangerous Detected Coverage)
Correct answer: PFD (Probability of Failure on Demand)
PFDavg (average Probability of Failure on Demand) is the key metric used to quantify SIS reliability for low-demand mode safety functions.
Question 4: Under IEC 62061, which term describes the portion of dangerous failures detected by the system's own diagnostics?
- Safe Failure Fraction (SFF)
- Diagnostic Coverage (DC) (Correct answer)
- Beta factor
- Hardware Fault Tolerance (HFT)
Correct answer: Diagnostic Coverage (DC)
Diagnostic Coverage (DC) is the fraction of dangerous failures that are detected by automatic diagnostic tests within the safety-related system.
Question 5: What is the role of a 'final element' in a Safety Instrumented Function?
- To measure the process variable and transmit it to the logic solver
- To perform the physical action that brings the process to a safe state (Correct answer)
- To execute the safety logic and make trip decisions
- To provide operator interface and alarm management
Correct answer: To perform the physical action that brings the process to a safe state
The final element (e.g., a shutdown valve or contactor) is the actuator component that physically implements the safety action commanded by the logic solver.
Question 6: What does 'Hardware Fault Tolerance' (HFT) of 1 mean for a safety subsystem?
- The subsystem can tolerate zero faults before losing the safety function
- The subsystem can still perform its safety function with one fault present (Correct answer)
- The subsystem requires one channel to be active at all times
- The subsystem has a 1% probability of hardware failure per year
Correct answer: The subsystem can still perform its safety function with one fault present
HFT of 1 means the subsystem can experience one hardware fault and still correctly perform its intended safety function, requiring at least two channels in a redundant configuration.
Question 7: In functional safety management, what is the primary purpose of a 'functional safety assessment' (FSA)?
- To calculate the SIL target for each safety function
- To provide an independent judgement that safety requirements have been correctly implemented (Correct answer)
- To update the process hazard analysis after a near-miss event
- To train operators on emergency shutdown procedures
Correct answer: To provide an independent judgement that safety requirements have been correctly implemented
A functional safety assessment is an independent, systematic review performed to verify that the safety lifecycle activities and their outputs satisfy the applicable functional safety requirements.
What is a 'common cause failure' (CCF) in the context of redundant safety systems?