DSIB — Audit Solutions
© Design Safety Intelligence Bureau. Printing of this page is not permitted.

Operating Plant
Safeguarding Design
Basis Verification

A structured multi-disciplinary assessment of the alignment between the safety design basis established during design and the safeguards as modified, integrated and reconfigured today. Six deliverables form one traceable record from the design basis to the plant in service:

  • Current Safety Basis Dossier and Confidence Register
  • Reconciliation Map
  • Integrated Gap and Decision Register
  • Unit/Plant-Wide Alignment and Exposure Profile
  • Risk-Informed Remediation Roadmap
  • Management Decision Brief

Focus areas of the comparison:

  • Inherent safety design characteristics
  • BPCS-based safety functions
  • Alarm system or BPCS-based alarms
  • Safety instrumented system (SIS)
  • Relief and depressurization system
  • Fire and gas system
  • Secondary containment and drainage
  • Passive fire protection design
  • Active firefighting system
  • Explosion protection and hazardous area compliance design
  • Layout safety

DSIB’s Solutions Series article “Operating Plant Safeguarding Design Basis Verification” develops the perspective further.

Third-Party
Safety Reviews

Safety reviews and assurance studies can be contracted on their own, independent of who performs the engineering. Depending on where the project is, typical scope might include:

  • Inherent Safety Review
  • Layout Safety Review and 3-D Model Safety Review
  • Early Phase PHAs
  • Design HAZOP
  • Alarm Rationalization
  • 3-Guide-Word Task Analysis for Preliminary Safety-Critical Procedures
  • ALARP Demonstration Study
  • Consolidation of Risk Registers
  • Pre-Start-Up Safety Review (PSSR)
  • Technical Integrity Verification (TIV) Report for SCE
  • HRA on Safety-Critical Tasks and Close-Out Report
  • Typical Safety Check-Point for DCNs

Each review states its Terms of Reference prior to the engagement.

Functional Safety
Assessment

Executed before the design proceeds further, to ensure the hazard analysis and the initial SRS are robust for each SIF. The assessment reads the evidence that carries the analysis into design:

  • Verified PHA outputs, the target SIL assignment and the close-out of recommendations
  • The Process SRS: SIF definition, target SIL, hazard description, demand mode, safe state and process safety time
  • The Functional Safety Management Plan, the interdisciplinary work split, and the competence and verification arrangements it sets out

Stage 1 is the first opportunity to stop weak requirements and identify incomplete or unresolved issues. DSIB executes FSA1 as an independent body, or prepares the project team and its evidence for it through a readiness study — never both on the same scope.

DSIB’s Solutions Series articles “Functional Safety Assessment Across the Safety Lifecycle” and “Management of SIS Lifecycle During Conceptual Design / FEED and Detailed Engineering” develop the perspective further.

Conducted following successful design and testing, before site installation. The assessment confirms traceability from the SRS into hardware, application program, SIL verification and planned testing:

  • The finalized detailed SRS, and the SIL verification report with the final architecture and technology choices
  • Application program documentation: Cause and effect matrices, diagnostic details, logic diagrams and logic narratives
  • Hardware documentation: Loop, wiring and termination diagrams, panel layouts, I/O list, bypass, reset and shutdown switches, and UPS distribution plans
  • Factory Acceptance Testing of hardware (HWFAT) and application programming (APFAT)

The assessment plan states the hardware, application-program and FAT boundary, and the conclusion does not imply review of evidence outside it. DSIB executes FSA2 as an independent body, or prepares the project team and its evidence for it through a readiness study — never both on the same scope.

DSIB’s Solutions Series articles “Functional Safety Assessment Across the Safety Lifecycle” and “Management of SIS Lifecycle During Conceptual Design / FEED and Detailed Engineering” develop the perspective further.

IEC 61511 positions Stage 3 after installation, pre-commissioning and final validation, with operation and maintenance procedures developed: An independent look at whether the installed, validated SIS and the organization around it are ready for hazardous material. The assessment tests that:

  • The installed configuration matches the approved basis, including every field change made along the way
  • Commissioning failures and exceptions have a defined disposition and closure evidence
  • Validation traces requirement by requirement to the SRS
  • The information owner acceptance depends on is complete, controlled and retrievable

Where Stage 3 is the only pre-start-up FSA, its scope also addresses the Stage 1 and Stage 2 work already completed. DSIB executes FSA3 as an independent body, or prepares the organization and its evidence for it through a readiness study — never both on the same scope.

DSIB’s Solutions Series articles “Functional Safety Assessment Across the Safety Lifecycle” and “Maintaining SIS Integrity from Owner Acceptance through Operation” develop the perspective further.

The periodic assessment asks whether operating evidence still supports the claims made at acceptance. No universal frequency is implied; the assessment cycle is planned within the owner’s management system. The assessment tests that:

  • Proof-test coverage matches the verification assumptions
  • The picture of degraded, bypassed and deferred functions is complete
  • Operating evidence (demands, failures, trips, as-found results) is analysed against the assumptions and leads to decisions when performance drifts
  • Procedures reflect the SRS, the installed arrangement and the way the work is actually done

DSIB executes FSA4 as an independent body, or prepares the organization and its evidence for it through a readiness study — never both on the same scope.

DSIB’s Solutions Series articles “Functional Safety Assessment Across the Safety Lifecycle” and “Maintaining SIS Integrity from Owner Acceptance through Operation” develop the perspective further.

After modification, Stage 5 is an independent look at whether the change was impact-assessed, implemented, verified and where required revalidated, and whether the records now describe the SIS that is actually running. The assessment tests that:

  • The configuration before the change is preserved, so a controlled baseline exists to compare against
  • All affected requirements, interfaces and assumptions have been reviewed, not only the changed item
  • Cumulative small changes have been examined together, and temporary changes actually ended

Before a SIS is decommissioned, Stage 5 independently examines whether the plan protects the transitional states, the adjacent systems and the record the remaining plant will rely on. DSIB executes FSA5 as an independent body, or prepares the organization and its evidence for it through a readiness study — never both on the same scope.

DSIB’s Solutions Series articles “Functional Safety Assessment Across the Safety Lifecycle” and “Maintaining SIS Integrity from Owner Acceptance through Operation” develop the perspective further.

Flexibility and Integration Changes in a Refinery

52-Day HAZOP

Reviewing Changes in the Interconnection of Units, Tank Farms and Jetties

Operating Plant Safeguarding Design Basis Verification

Your facility has changed. Does the safety design basis it was built on still reflect what you operate today?

Changes accumulate. Design assumptions do not always follow.

Functional Safety Assessment

A concise DSIB brief on the scope, challenges and engineering interfaces across five FSA stages.

-case study for a capital EPC project supplemented.

From Alarm Flood to Operator Focus

Control panel with buttons, switches, and screens, possibly in a transportation or industrial setting.

A refinery alarm rationalization project showing how we turned an unmanageable alarm load into a prioritized, actionable system aligned with ISA 18.2 and EEMUA 191.

The Independent Lens

In our audits, we trace findings back to the design decisions, interfaces and assumptions that created them. Reviewed at the right stage, these issues can often be resolved before technical questions lead to contractual disputes.