Safety Manual
Safety Manual
Safety Manual
1 Introduction 4
3 Operation 14
4 Service 24
5 Notes 26
INFORMATION!
The data in this supplement provides additional information for using the device in safety
applications.
The technical data in the handbook (document [1], [2] shall be valid, provided that it is not
rendered invalid or replaced by this supplement. If necessary, parts of document [1] are
referenced herein.
INFORMATION!
Installation, commissioning and maintenance may only be carried out by properly trained and
authorised personnel.
The device can be used in safety applications measuring mass flow rate, volume flow or density
of liquids using the safe current output at terminal C. The safe current output is available as
intrinsically safe and non-intrinsically safe variant according to IEC 60079-11.
1.4 Declaration
General
Device designation and OPTIMASS with flow sensors and electronics MFC 400 (according to following
permissible types section)
Safety-related output signal 4 to 20 mA (terminal C)
Safety function Put out a correct mass flow or volume flow or density measurement on safe current
output (4 to 20 mA) with a safety tolerance of ±2% within the process response time
of the device.
Device type acc. to IEC 61508-2 Type A Type B
Evaluation through – report no. TUEV Rheinland Industrie Service GmbH – Certificate No. 968/FSP 1048.06/21
Test documents Development documents, test reports, data sheets
Table 1-2: Safety-related characteristics - General
SIL - Integrity
Systematic safety integrity SIL 2 capable SIL 3 capable
Hardware safety integrity Single channel use (HFT = 0) SIL 2 capable SIL 3 capable
FMEDA 1
SD 0.1 FIT
SU 800.9 FIT
DD 1750.2 FIT
DU 89.9 FIT
SFF 96.59 %
PFDavg(TProof= 1 year) 3.9E-04
PFDavg(TProof= 3 years) 1.2E-03
PFDavg(TProof= 5 years) 2.0E-03
PFH 8.99E-08 1/h
PTC Up to 97 %
MTBF (safety function) 43.2 years
Diagnostic Test Interval 2 1 min.
Fault Reaction Time 1s
Table 1-4: Safety-related characteristics - FMEDA
1 Based on failure types specified in Siemens SN29500. Soft errors are taken into account.
The values are valid for an averaged ambient temperature up to 40°C / 104°F
2 All diagnostic functions are carried out at least once during this time.
The useful lifetime can only be extended under responsibility of the plant operator regarding
special operation conditions and the employment of suitable intervals for testing and
maintenance.
The following table shows the permitted signal converter variants for functional safety:
Refer to the next table to find which positions in the V-type code are related to functional safety.
The positions are marked by the letter "x".
Code VE ab c d e fg h j k l m n p q r s t u v w
The next table shows all codes of the permitted flow sensor variants which have constraints
Code Description Valid flow sensor codes for SIL device variant
ab Flow sensor type and size 71, 72, 73, 74, 75, 76, 77, 78 or 79
j Design 0, K
q Process requirements 0, 1
r Extended options 0
s Customer specific 0
t Signal converter type 6, 7
Table 1-7: Permitted flow sensor variants for functional safety
Term Description
Firmware Software embedded in the device
FIT Failure In Time (1x10-9 failures per hour)
FMEDA Failure Modes, Effects and Diagnostics Analysis
FRT Fault Response Time (diagnostic test interval + Fault Reaction Time).
This is the maximum time that is necessary for the current output to change to a
safe value when the safety function has an error condition.
HFT Hardware Fault Tolerance
High demand or Where the frequency of demands for operation made on a safety-related system is
continuous mode greater than one time per year.
I/O Input / output
DD Rate for dangerous detected failure
DU Rate for dangerous undetected failure
SD Rate for safe detected failure
SU Rate for safe undetected failure
Low demand mode Where the frequency of demands for operation made on a safety-related system is
not greater than one time per year.
MTBF Mean Time Between Failures
PFDAVG Average Probability of Failure on Demand
PFH Probability of a dangerous Failure per Hour
PLC Programmable logic controller
PTC Proof Test Coverage
Process safety Time starting when something fails and ending when the "undesired event" can no
time longer be prevented.
SAC Safety Application Condition. Conditions that must be adhered to when you use a
safety-related system or a safety-related sub-system.
SFF Safe Failure Fraction
SIL Safety Integrity Level
SIS Safety Instrumented Systems
Systematic Measure (given as a scale of SC 1 to SC 3) of the confidence that the systematic
Capability safety integrity of an element complies to the conditions of the specified SIL (related
to the safety function of an element), when the element is applied in accordance
with the instructions.
Type A system "Non-complex" system (all failure modes are well defined). For more data, refer to
subsection 7.4.3.1.2 of IEC 61508-2.
Type B system "Complex" system (not all failure modes are well defined). For more data, refer to
subsection 7.4.3.1.2 of IEC 61508-2.
TProof Proof Test Interval
Table 1-9: Terms and definitions
The safety tolerance is the tolerable error before setting the safe state of the device.
A random fault can cause an error of up to 2% of the present measurement value or output current before it
is signalled.
WARNING!
The safety application conditions and instructions must be followed if the device is used in a
safety related system.
2.2.1 General
• The operator must carefully select the correct tube diameter with respect to the expected flow rates.
• If the device is used in high demand mode of operation, the process safety time must be more than the
fault response time.
This minimum time agrees with International Standard IEC 61508 Part 2 ( [3], section 7.4.4.1.4).
2.2.2 Installation
• In case of a remote device variant, the serial number of the signal converter and flow sensor
must match.
• The current output at terminal C is the safety relevant output for safe operation.
• The operator must ensure that the wetted material is compatible with process product.
• Correctly sized cables for the cable glands must be used and the cable glands and the lid
must be tightened sufficiently. Furthermore, the device (lid, cable glands) must not be
opened during safe operation.
• If the safe current output is used in passive configuration an overvoltage at the terminal can
lead to loss of the safety function of the device. It is recommended to use a power supply with
voltage limitation or voltage monitoring.
• The device must not be operated above 2000 m / 6561 ft above sea level.
2.2.3 Operation
• The device must not be exposed to strong magnetic fields during operation.
• The device must not be exposed to excessive vibration during operation.
• The sensor tube must be filled completely by the process liquid.
• Ensure that entrained gas, cavitation, or two-phase flows do not occur in the flowmeter.
• The ambient temperature must not exceed the device limits.
• Corrosive products must be excluded according to [4].
• Erosive products must be excluded.
• Coating inside the sensor tube must be avoided.
• The process temperature must not exceed the limits of the flow sensor variant.
• In order to execute the safety function the device must be switched to safe operation
(for further information refer to Switch to safe operation on page 15).
• The device must be operated in the mass flow range 5...130% of nominal flow range.
INFORMATION!
HART®communication:
The measuring device can also communicate via HART® in safe operation state.
INFORMATION!
Bluetooth®communication:
The measuring device can also communicate via the wireless Bluetooth® interface in safe
operation state.
Security mechanisms have been implemented to avoid any impact on the safe operation via the
wireless interface.
Write access to safety-related parameters is blocked via the Bluetooth® interface, even though
the Bluetooth® access level is set to "Read + Write". Additionally, the configuration of the device
for usage in safety applications is not supported via the Bluetooth® interface.
INFORMATION!
Only properly trained and authorised personnel shall change device settings. Keep a report of
changes to the device settings. These reports must include the date, the menu item, the old
setting and the new setting.
The configuration is protected by a password. For more data on password protection and device
configuration refer to Switch to non-SIL operation on page 15.
In order to switch the device from non-SIL operation to safe operation several steps have to be
performed.
• Switch the device to safe configuration state by setting safety mode to "SIL Mode" (for further
information refer to Safe parameter verification on page 17).
• Configure the device for safe operation (for further information refer to Safe configuration on
page 16).
• Perform safe parameter verification (for further information refer to Safe parameter
verification on page 17).
• Perform confirmation (for further information refer to Confirmation on page 18).
INFORMATION!
Change your unlock password (menu C7.5) before switching the device to safe operation to avoid
unauthorised access.
• Unlock the device (menu C7.4) by entering the configurable unlock password (menu C7.5).
Default unlock password: 9999
• Change of safety mode to "Non-SIL Mode" (for further information refer to Safe parameter
verification on page 17).
• Perform confirmation (for further information refer to Confirmation on page 18).
1 Can only be configured for I/O variant (5) with code 4 (for details refer to Signal converter on page 8)
2 Not safety relevant if the measurement Density is selected
The safe configuration must be verified either via local display or via HART® interface in order to
enter the safe operation state:
During preparation of the safe parameter verification the following messages could be
displayed:
Message Description
Checking Parameters… Configuration is checked for plausibility.
Not allowed Device in safe operation or non-SIL operation. Therefore safe parameter
verification is not allowed.
Config. invalid Implausible configuration.
Press Return to Start Configuration checked successfully and verification can start.
Remove Jumper A lock jumper is set. Please remove it!
Table 3-4: Messages during safe parameter verification
This process can only be started if the configuration is plausible. During verification of the safe
configuration all safety relevant parameters must be reviewed guided by a wizard.
In the verification wizard all safety relevant parameters are displayed in the following format:
The parameter ID is used for identification of the parameter as described in the chapter "Safe
configuration" on page 16.
WARNING!
Check that all parameters listed in the table for the respective safe measurement are shown in
the verification process.
If the verification process is performed via HART® make sure that the correct device is
addressed by checking the device tag. Please make sure that the device tag is unique.
3.2.6 Confirmation
During the last step of switching to safe operation or non-SIL operation the user must confirm
the action by entering a confirmation key. The device generates a random 3-digit confirmation
key which is displayed as depicted below.
When the safe configuration is confirmed, all safety relevant parameters are write-locked and
the device switches to safe operation state.
Table 3-6: Dialogue containing the confirmation key for safe operation
Message Description
Timeout occured The safe parameter verification must be completed within 1 hour. Please restart
safe parameter verification.
Wrong Key The entered confirmation key was incorrect. Please restart safe parameter
verification.
Successful Device is in safe operation or non-SIL operation.
Table 3-7: Description of messages
INFORMATION!
All safety relevant parameters are locked during safe operation. If not safety relevant
parameters shall be locked please set the operator password [2].
WARNING!
We recommend not to use 3.8 mA or 20.5 mA as a limit for monitoring.
If the device is used in a safety loop both the high and low failure current must be monitored.
CAUTION!
Although the device can be set to send a high failure current signal ( 21 mA), some hardware
failures will always cause the device to send a low failure current signal ( 3.6 mA).
INFORMATION!
If 2 phase flow detection is configured according to the handbook [2], it can be either used to
• set the safe state at the safe current output by setting "Proc: 2 Phase Flow" (C7.1.11) to
"Failure" or
• signal it via any not safety relevant I/O by setting "Proc: 2 Phase Flow" (C7.1.11) to "Out of
Specification"
For more data about error conditions, refer to the following table:
The safety function data from each device are sent to one or more logic solvers. The logic solver
compares the data from the two devices to select a device status for each device.
If the difference between the data from each device exceeds the limit for the safety application,
then the logic solver uses the safety function to change the safety loop's status to "safe".
The installation method, maintenance strategy, and how you use the device will have an effect on
how you calculate the estimate.
4.1 Maintenance
Obey the maintenance instructions given in the handbook (document [1] [2]).
INFORMATION!
For more precise information, please contact our local sales office.
CAUTION!
• Proof tests done by the customer must cover at least the tests given in this section.
• Keep a report of each proof test. These reports must include the date, the tests results (performance of
the safety function or faults found), a list of approved personnel who did the test and the report revision
number. These reports must be put into storage and made easily available.
Required equipment
• A current meter with uncertainty below the required uncertainty of current loop
• Calibration rig
Test procedure
The following tables show all possible proof test steps resulting in a test coverage.
For test step 2 the device must be unlocked and set to non-SIL operation.
4.5 Troubleshooting
INFORMATION!
• The user must not make modifications to devices that operate in SIL mode.
• Only approved personnel from the manufacturer are permitted to repair the device.
If the device has a critical failure that is related to functional safety, send a report to the
technical support department of the manufacturer. If you find a problem, please inform your
local representative. If you must return the device to the manufacturer, refer to "Returning the
device to the manufacturer" in [1] [2].