Doc : Q066 Rev : 10
Issued : 01/11/13 Page : 24 of 25
18. Functional Safety Data
Parameter name Symbol Equation / source
PNL / HYL
Actuator
HY/DG
actuator
PN
actuator
Proof Test Interval T1
8760 8760 8760
Type A/B type A
type A type A type A
Total failures:
From FMEA
2.14E-06 1.30E-06 8.48E-07
Safe diagnosed failures:
SD
From FMEA
0.00E+00 0.00E+00 0.00E+00
Safe undiagnosed failures:
SU
From FMEA
1.65E-06 8.26E-07 5.37E-07
Dangerous diagnosed failures:
DD
From FMEA
0.00E+00 0.00E+00 0.00E+00
Dangerous undiagnosed
failures:
DU
or High demand mode, PFH per
(hour)
4.95E-07 4.75E-07 3.11E-07
Safe Failure Fraction: SFF
(
SD
+
SU
+
DD
) /
76.92% 63.48% 63.29%
PFD
AVG
(using 61508-6
equation) PFD
AVG
DU
+
DD
) t
CE
2.17E-03 2.09E-03 1.37E-03
SIL capability (High demand
mode)
SIL 2 SIL 2 SIL 2
Parameter name Symbol Equation / source
PNL / HYL
Actuator
HY/DG
actuator
PN
actuator
Proof Test Interval T1 Given, for this example
8760 8760 8760
Hardware Fault Tolerance HFT
1 1 1
Type A/B type A Given, for this example
type A type A type A
Total failures:
SD 1oo2
+
SU 1oo2
+
DD 1oo2 +
DU
1oo2
2.40E-07 1.38E-07 8.82E-08
Safe diagnosed failures:
SD 1oo2
2
SD
2
MTTR +
SD
0.00E+00 0.00E+00 0.00E+00
Safe undiagnosed failures:
SU 1oo2
SU
2
T + b
SU
1.89E-07 8.86E-08 5.62E-08
Dangerous diagnosed failures:
DD 1oo2
2
DD
2
MTTR +
DD
0.00E+00 0.00E+00 0.00E+00
Dangerous undiagnosed
failures:
DU 1oo2
DU
2
T + b
DU
5.16E-08 4.95E-08 3.20E-08
Safe Failure Fraction:
SFF
1oo2
(
SD 1oo2
+
SU 1oo2
+
DD 1oo2
) /
1oo2
79% 64% 64%
PFD
AVG
(using simplified
equation)
PFD
AVG
1oo2
DU 1oo2
(T / 2+MTTR) + (
DD 1oo2
*MTTR)
2.26E-04 2.17E-04 1.40E-04
SIL capability (1oo2)
SIL 3 SIL 3 SIL 3
18.1 Operating limits and Conditions
The actuators must be operated within the pressure and temperature limits shown in the
product test certificate and displayed on the actuator nameplate. DO NOT EXCEED THESE
LIMITS.
The hardware fault tolerance is shown in the above table – HFT=0 is SIL2 capable, HFT=1 is
SIL3 capable.
The Proof Test Interval is shown in the table above. Proof test can be carried out by full or
partial stroking of the actuator.