ATEX Zone 2 intrinsically safe isolating barriers in a control cabinet

Burner Management Systems to IEC 61511

A burner management system (BMS) supervises the safe start-up, operation and shutdown of fired equipment. It enforces the sequence: purge the furnace in accordance with the applicable burner management requirements, establish ignition permissives, light off through the burner, prove flame, and on loss of flame or unsafe condition trip fuel and air in a defined order.

The BMS acts when permissives fail, when flame is not proved within the allowed time, or when a trip condition is reached — not as a continuous process controller. On a refinery CHP boiler we implemented automatic start-up from a hot state as a DCS sequence under HIMA HIQuad burner management: purge, light-off through the BMS, ramp to minimum stable load against drum thermal stress limits, and hand-over to load control, in accordance with SR EN 12952.

Safety instrumented systems

A safety instrumented system (SIS) takes the plant to a safe state when a hazardous condition is detected — overpressure, high level in a vessel that must not overflow, gas in a classified area, or a condition that requires an emergency shutdown. Safety instrumented functions are separate from the DCS: dedicated sensors, a logic solver rated for the required SIL, and final elements that fail to the safe position.

On a combined cycle power plant the safety instrumented system runs at SIL 3 on Foxboro Triconex and ABB AC800, with the SIL status integrated into the operator HMI rather than left on a separate panel.

Functional safety to IEC 61511

Safety instrumented functions are specified, implemented and verified under the functional safety lifecycle of IEC 61511, including factory and site acceptance testing as we describe under acceptance testing. ISYSTEMS AUTOMATION has contributed to the certification of SIL 2 and SIL 3 applications, covering:

  • Safety requirement specifications and cause-and-effect matrices
  • ESD and BMS conceptual architecture, including sensor, logic solver and final element subsystems
  • Test procedures, Factory Acceptance Tests and site loop testing against the safety requirement specification
  • Proof test intervals and documentation for the operating phase
  • Verification of I&C design documentation against local and international standards

Proof tests are scheduled at the interval the safety requirement specification demands — valve stroke tests, burner flame scanner checks, logic solver diagnostics — and recorded so the operating phase can show the safety function still meets its SIL claim.

Logic solvers

Safety logic solvers delivered on HIMA HIQuad, Foxboro Triconex and ABB AC800. Burner management on the refinery CHP plant runs on HIMA HIQuad; the combined cycle project used Triconex and AC800 at SIL 3.

Reference plant work

On a refinery CHP plant: automatic boiler start-up on boiler No. 3 — 100 kgf/cm² at 540 °C, nine burners, purge and light-off through the burner management system, ramp against drum thermal stress limits, hand-over to load control. Plant-wide protection logic across four turbines, four boilers and auxiliary equipment so a trip on one item takes the correct action on the rest.

Continuous maintenance since 2022 on the same plant's DCS, ESD, BMS and MES: Emerson Ovation, ABB Industrial IT 800xA, HIMA HIQuad and Honeywell PHD.