Layers of Protection in Process Plant: NAZIR @2010
Layers of Protection in Process Plant: NAZIR @2010
Process Plant
NAZIR @2010
Layers of Protection for High Reliability
Strength in Reserve
EMERGENCY RESPONSE
• BPCS - Basic process
A control
CONTAINMENT
U • Alarms - draw attention
RELIEF T • SIS - Safety interlock
O system to stop/start
SIS M equipment
ALARMS
A • Relief - Prevent excessive
T pressure
BPCS I • Containment - Prevent
O materials from reaching,
N workers, community or
environment
• Emergency Response -
evacuation, fire fighting,
health care, etc.
2
Key Concept in process Safety: REDUNDANCY
PROCESS
3
Objectives of Process Control
1. Safety We are emphasizing
2. Environmental Protection these topics
3. Equipment Protection
4. Smooth Operation &
Production Rate
5. Product Quality
6. Profit
7. Monitoring & Diagnosis
4
Basic Process Control System (BPCS)
• First line of defense
• Process control maintains variables at set points, which are
fixed at some desired values
• Technology - Multiple PIDs, cascade, feedforward, etc.
• Guidelines
• Always control unstable variables (Examples in flash?)
• Always control “quick” safety related variables
Stable variables that tend to change quickly (Examples?)
• Monitor variables that change very slowly
Corrosion, erosion, build up of materials
• Provide safe response to critical instrumentation failures
- But, we use instrumentation in the BPCS?
5
Where could we use BPCS in the flash process?
F1
6
The pressure will
change quickly and
affect safety; it must
be controlled.
The level is
unstable; it must
be controlled.
F1
7
2. Alarm System
• Alarm has an anunciator and visual indication
- No action is automated!
- require analysis by a person - A plant operator
must decide.
• Digital computer stores a record of recent alarms
• Alarms should catch sensor failures
- But, sensors are used to measure variables for
alarm checking?
8
2. Alarm System
• Common error is to design too many alarms
- Easy to include; simple (perhaps, incorrect) fix to prevent
repeat of safety incident
- One plant had 17 alarms/h - operator acted on only 8%
• Establish and observe clear priority ranking
- HIGH = Hazard to people or equip., action required
- MEDIUM = Loss of RM, close monitoring required
- LOW = investigate when time available
9
Where could we use alarm in the Flash Process ?
F1
10
The pressure affects
PAH
safety, add a high
alarm
F1
LAH
LAL
11
3. Safety Interlock System
• Automatic action usually stops part of plant
operation to achieve safe conditions
- Can divert flow to containment or disposal
- Can stop potentially hazardous process, e.g.,
combustion
• Capacity of the alternative process must be for
“worst case”
• SIS prevents “unusual” situations
- We must be able to start up and shut down
- Very fast “blips” might not be significant
12
3. Safety Interlock System
• Also called emergency shutdown system (ESS)
• SIS should respond properly to instrumentation
failures
- But, instrumentation is required for SIS?
• Extreme corrective action is required and
automated
- More aggressive than process control (BPCS)
• Alarm to operator when an SIS takes action
13
3. Safety Interlock System
• The automation strategy is usually simple, for example,
How do we
steam automate this SIS
PC when PC is adjusting
the valve?
LC
water
fuel
14
If L123 < L123min; then, reduce fuel to zero
steam 15 psig
PC
LC LS s s
water
fuel
fc fc
L123
T105 SIS s
….. 100
16
3. Safety Interlock System
• The SIS saves us from hazards, but can shutdown the plant
for false reasons, e.g., instrument failure.
False Failure on
shutdown demand
T100 1 out of 1
s
must indicate
failure
Better 5 x 10-3 5 x 10-3
performance,
more expensive
T100 2 out of 3
s
T101 must indicate
T102 failure 2.5 x 10-6 2.5 x 10-6
Same variable,
multiple sensors!
17
3. Safety Interlock System
• We desire independent protection layers, without common-
cause failures - Separate systems
sensors sensors
18
KEY CONCEPT IN PROCESS SAFETY -
REDUNDANCY!
What do we do if a major incident occurs that causes
• loss of power or communication
• a computer failure (hardware or software)
SAFETY INTERLOCK
Stop the operation of part of process These layers require
SYSTEM electrical power, computing,
Bring unusual situation to attention communication, etc.
ALARM SYSTEM of a person in the plant
PROCESS
19
4. Safety Relief System
• Entirely self-contained, no external power required
• The action is automatic - does not require a person
• Usually, goal is to achieve reasonable pressure
- Prevent high (over-) pressure
- Prevent low (under-) pressure
• The capacity should be for the “worst case”
scenario
20
RELIEF SYSTEMS IN PROCESS PLANTS
21
Location of Relief System
Identify potential for damage due to high (or low) pressure
(HAZOP Study)
- may have exit path that should not be closed but could be
- hand valve, control valve (even fail open), blockage of line
22
Standard Relief Method: Valves
BASIC PRINCIPLE: No external power required -
self actuating - pressure of process provides needed force!
Pressure of protected
system can exceed
the set pressure.
23
Standard Relief Method: Rupture Disk
24
Relief Valves
Two types of designs determine influence of pressure immediately
after the valve
- Conventional Valve -pressure after the valve affects the valve lift
and opening
- Balanced Valve - pressure after the valve does not affect the valve
lift and opening
Conventional Balanced
25
Some Information about Relief Valves
ADVANTAGES
DISADVANTAGES
DISADVANTAGES
- must shutdown the process to replace
- greater loss of material through relief
- poorer accuracy of relief pressure the
valve
27
Symbols used in P&I D
To effluent handling
Process
• Rupture disc
28
Add Relief to the Following System
F1
29
Add Relief to the Following System
The drum can be isolated
with the control valves;
pressure relief is required.
We would like to recover
without shutdown; we
select a relief valve.
F1
30
Add Relief to the Following System
Positive
displacement
pump
31
Add Relief to the Following System
32
Add Relief to the Following System
33
Add Relief to the Following System
34
In some cases, relief and diaphragm are used in series –
WHY?
• What is the advantage
of two in series?
• Why not have two relief
valves (diaphragms) in
series?
35
In some cases, relief and diaphragm are used
in series – WHY?
Why is the pressure
indicator provided?
If the pressure increases,
the disk has a leak and
should be replaced.
Is it local or remotely
displayed? Why?
The display is local to
reduce cost, because we
do not have to respond
• What is the advantage immediately to a failed
of two in series? disk - the situation is not
hazardous.
The disc protects the
valve from corrosive or
sticky material. The
valve closes when the
pressure returns below
the set value.
36
Vents required to control or direct
vapour/dust explosion effect
Structure
explosion
37
Materials from relief must be process or dispose safely
From
relief
BPCS