B - Certification Report Sample
B - Certification Report Sample
Risknowlogy GmbH
Industriestrasse 47
6300 Zug
Switzerland
www.risknowlogy.com
RISKNOWLOGY
Certification Report: 176.101.2-0
Safety Related Level Sensor
[COMPANY], City, Country
LIMITATION OF LIABILITY - This report was prepared using best efforts. Risknowlogy does not accept any responsibility for omissions or inaccuracies in
this report caused by the fact that certain information or documentation was not made available to us. Any liability in relation to this report is limited to the
indemnity as outlined in our Terms and Conditions. A copy is available at all times upon request.
Printed in Switzerland
This document is the property of, and is proprietary to Risknowlogy®. It is not to be disclosed in whole or in part and no portion of this document shall be
duplicated in any manner for any purpose without Risknowlogy’s expressed written authorization.
Risknowlogy®, the Risknowlogy logo®, and Functional Safety Data Sheet®, and Spurious Trip Level™ are registered service marks.
RISKNOWLOGY Page 2
Certification Report: 176.101.2-0
Safety Related Level Sensor
[COMPANY], City, Country
Revisions
RISKNOWLOGY Page 3
Certification Report: 176.101.2-0
Safety Related Level Sensor
[COMPANY], City, Country
Table of Contents
Revisions ....................................................................................................................3
Table of Contents .......................................................................................................4
List of Tables ..............................................................................................................5
List of Figures .............................................................................................................5
Terms and Definitions.................................................................................................6
1 Introduction ...........................................................................................................7
1.1 Objective ............................................................................................................7
1.2 About CLIENT ....................................................................................................7
1.3 About Risknowlogy.............................................................................................7
2 [PRODUCT] Description........................................................................................8
2.1 Introduction ........................................................................................................8
3 Verification procedure and results.......................................................................10
3.1 History of the [PRODUCT] ...............................................................................10
3.2 Verification procedure ......................................................................................10
3.3 Management of Functional Safety....................................................................10
3.4 Hardware requirements....................................................................................11
3.5 Measures to control failures .............................................................................11
3.6 Reliability analysis............................................................................................12
3.7 Fault injection ...................................................................................................13
3.8 Software requirements .....................................................................................13
3.9 Software testing................................................................................................13
3.10 User documentation.........................................................................................14
3.11 Basic safety, environmental safety and EMC/EMI safety.................................14
3.12 Application specific requirements ....................................................................14
3.13 Conclusions .....................................................................................................15
References ...............................................................................................................16
RISKNOWLOGY Page 4
Certification Report: 176.101.2-0
Safety Related Level Sensor
[COMPANY], City, Country
List of Tables
List of Figures
RISKNOWLOGY Page 5
Certification Report: 176.101.2-0
Safety Related Level Sensor
[COMPANY], City, Country
Term Definition
Dangerous failure An internal failure that prevents the [PRODUCT] from carrying out
its safety function upon demand. See also safe failure.
Safe failure An internal failure where a [PRODUCT] carries out its safety
function without a demand from the process. This failure can lead to
a spurious trip. See also dangerous failure.
Detected failure An internal failure that is detected by built-in diagnostics. Because
of the diagnostics the [PRODUCT] can act upon the failure. See
also undetected failure.
Undetected failure An internal failure that is not detected by built-in diagnostics. See
also detected failure.
Diagnostic test A built-in test, frequently and automatically carried out, to determine
whether the [PRODUCT] could carry out its (safety) function without
problems.
FMEA Failure mode and effects analysis.
Functional safety A [PRODUCT] is functionally safe if random, systematic and
common cause failures do not lead to malfunctioning of the system
and do not result in injury or death of humans, spills to the
environment, or loss of equipment or [PRODUCT]ion
Hardware fault tolerance Hardware fault tolerance indicates the number of failures the
[PRODUCT] or subsystem can withstand without losing the safety
function.
HFT See hardware fault tolerance.
Periodic test A test that is initiated by hand on a periodic basis, e.g., once per
year, to determine whether the [PRODUCT] can carry out its
(safety) function without problems. See also diagnostic test.
PFDavg The average probability that the safety function has failed upon
demand.
PFSavg The average probability that the safety function causes a spurious
trip of the process.
Proof test See periodic test.
Safety function Function implemented in the [PRODUCT] required to achieve a
safe state of the process.
SIL Safety Integrity Level
Safety support function Function implemented in the [PRODUCT] which is not required to
achieve a safe state of the process but which enhances the
functionality of the [PRODUCT].
STL Spurious Trip Level™
SFF See safe failure fraction.
Type The complexity of a [PRODUCT] is designated by Type A or Type
B. See IEC 61508, part 2, clause 7.4.3.1.2 and 7.4.3.1.3.
RISKNOWLOGY Page 6
Certification Report: 176.101.2-0
Safety Related Level Sensor
[COMPANY], City, Country
1 Introduction
1.1 Objective
The objective of this report is to describe the verification and assessment activities of the certification
carried out by Risknowlogy on [COMPANY]’s [PRODUCT] level sensor system. The purpose of the
verification and assessment is to demonstrate that the level sensor system meets the requirements
up to safety integrity level 3 according to the IEC 61508 [1] standard including the requirements, as
far as applicable, of the standards listed in [1].
This report represents a full certification, addressing all requirements of IEC 61508, and is
not limited to a hardware FMEDA.
RISKNOWLOGY Page 7
Certification Report: 176.101.2-0
Safety Related Level Sensor
[COMPANY], City, Country
2 [PRODUCT] Description
2.1 Introduction
The [PRODUCT] device is a sensor used for level measurements in storage tanks situated in tank
farms for cryogenic storage of liquefied gases such as natural liquefied gas and petroleum liquefied
gas. The level sensor continuously follows the surface of the liquid and continuously transmits its
position to the safety system (and control system if desired). A typical application using 2oo3 level
sensors is shown in Figure 1.
A single [PRODUCT] sensor consists of mechanical hardware, electronic hardware, and embedded
and application specific software. A single sensor transmits two signals to the safety system. One is
the actual level of the liquid and the second is a diagnostic signal indicating the health status of the
sensor. The application (software) of the safety system uses the transmitted signals of the sensor to
determine the appropriate reaction depending on the level of the liquid and the internal status of the
sensor.
RISKNOWLOGY Page 8
Certification Report: 176.101.2-0
Safety Related Level Sensor
[COMPANY], City, Country
1oo1 1 x [PRODUCT] 2
1oo2 2 x [PRODUCT] 3
RISKNOWLOGY Page 9
Certification Report: 176.101.2-0
Safety Related Level Sensor
[COMPANY], City, Country
The safety plan describes the managerial and technical activities for the project. The verification
and validation plan describes when and who will carry out which verification activities.
Risknowlogy reviewed the two documents for completeness and correctness. The two documents
represent all the requirements of management of functional safety. The review of the documentation
did not lead to any objections.
3.3.1 Lifecycle
The lifecycle used for this project is described in the safety plan [7]. The lifecycle differs from the
hardware and software lifecycle as defined in IEC 61508.
RISKNOWLOGY Page 10
Certification Report: 176.101.2-0
Safety Related Level Sensor
[COMPANY], City, Country
Risknowlogy reviewed the lifecycle to assure that it meets the objectives of the hardware and
software lifecycle defined in IEC 61508 [1]. The review of the lifecycle did not lead to any objections.
Sub system
level sensor
1143-2
RISKNOWLOGY Page 11
Certification Report: 176.101.2-0
Safety Related Level Sensor
[COMPANY], City, Country
Subsystem
Type A A B
Software
SIL 3
A single [PRODUCT] is fit for use in a SIL 2. Because the software is developed according to the
requirements of SIL 3 it is possible to use redundant devices up to SIL 3. An overview of the possible
architectures and configurations is given in Table 3. Risknowlogy has carried out PFDavg and
PFSavg calculations for the low demand sub systems for all three architectures. The calculations are
based on Markov models and the reliability data of Table 2.
RISKNOWLOGY Page 12
Certification Report: 176.101.2-0
Safety Related Level Sensor
[COMPANY], City, Country
Architecture
Configuration 1x 2x 3 x [PRODUCT]
[PRODUCT] [PRODUCT]
The reliability analysis show that architectural constraints and the PFD values are met for each
specified architectures with its applicable SIL level. The analysis did not lead to any objections.
Risknowlogy reviewed the fault injections test results. This did not lead to any objections.
RISKNOWLOGY Page 13
Certification Report: 176.101.2-0
Safety Related Level Sensor
[COMPANY], City, Country
use. This is described in [10]. The new code needed to be developed according to the SIL 3
requirements of IEC 61508. The requirements are described in [10] and the verification and validation
plan included the appropriate measures to avoid and control failures [8]. The testing was carried out
by [COMPANY] and verified by Risknowlogy [30,31,32].
Risknowlogy has verified the software tests. This did not lead to any objections.
RISKNOWLOGY Page 14
Certification Report: 176.101.2-0
Safety Related Level Sensor
[COMPANY], City, Country
3.13 Conclusions
The full Risknowlogy certification of the [PRODUCT] level sensor demonstrates that the sensor is
suitable for safety related loops up to SIL 3 according to IEC 61508 and IEC 61511. The instructions
of the safety manual need to be considered for proper use of the [PRODUCT] and are an integral part
of this certification report.
RISKNOWLOGY Page 15
Certification Report: 176.101.2-0
Safety Related Level Sensor
[COMPANY], City, Country
References
The following references have been used during this certification project.
1 IEC 61508:2000, parts 1 – 7
Functional safety of electrical/electronic/programmable electronic safety related systems
2 IEC 61010-1:2001
Safety requirements for electrical equipment for measurement, control, and laboratory use
- Part 1: General requirements
3 EN 61326-1:1997 and annex A1:1998, A2:2001, and A3:2003
Electrical equipment for measurement, control and laboratory use - EMC requirements
4 IEC 61511, Parts 1-3: 2004
Functional safety
Safety instrumented systems for the process industry sector
5 NFPA 59:2004
Utility LP-Gas Plant Code
6 NFPA 59A:2001
Standard for the [PRODUCT]ion, Storage, and Handling of Liquefied Natural Gas (LNG)
7 [COMPANY], Safety Plan System 1143MK2, ID 1143 MKII /SAFETY PLAN, Version 2,
2005-09-01
8 [COMPANY], Verification And Validation Plan, ID 1143MKII/V&V, Version 0, 2005-09-1
9 [COMPANY], Safety requirements specification System 1143MK2, ID 1143 MKII /SRS,
Version 4, 2005-09-01
10 [COMPANY], Software Requirement Specification And High Level Software Architecture
Description. 1143mk2, ID 1143 MKII /software requirement specification, Version 1, 2005-
10-26
11 [COMPANY], FMEA, excel spreadsheet, version E, 2005-9-11
12 [COMPANY], Hardware Fault Injection Report, Version 0, 2005-10-28
13 BVQI, NF EN ISO 9001:2000 certificate, number 175608, 2005-08-25
14 INERIS, ATEX certificate, Notification Number INERIS 03ATEXQ409, 2003-08-01
15 Bureau Veritas, Certificate of Conformity to the Directive 89/336/EEC dealing with
electromagnetic compatibility, 2005-10-27
16 Cofrac, NF EN ISO/CEI 17025, 2002-11-01
17 [COMPANY], Sub-assy inspection, specification and report, 225-02990-112-TES-2,
version 2, 2003-11-17
18 [COMPANY], Mechanic Inward Receipt specification and report, 862-22008-990-TME-1,
Revision 1, 2004-01-08
19 [COMPANY], Final Inspection specification and report, 01143-TEP-6, Revision 6, 2004-
03-18
20 TUV, Certificate 968/EZ 165.00/04, HIMA H4135: Safety Relay, 2004-04-14
21 HIMA, Data Sheet H 4135 (0435)
22 [COMPANY], Assembly drawing Jaguer Asservi 01143 MKII Coupes sur compartiments
produit et adf, reperage, version 2005-07-28
23 [COMPANY], Assembly drawing Jaguer Asservi 01143 MKII Vues sur compartiments
produit et adf, reperage, version 2005-02-19
RISKNOWLOGY Page 16
Certification Report: 176.101.2-0
Safety Related Level Sensor
[COMPANY], City, Country
RISKNOWLOGY Page 17