SOLUTIONS
Functional Safety
Reliable execution of safety functions to reduce risk. Origo Solutions designs, delivers and supports safety instrumented systems that keep people, assets and the environment protected throughout the lifecycle of your facility.
Navigating Functional Safety
Five key questions that define what functional safety means in practice, from concept to daily operation.
Functional safety ensures that safety-related systems respond reliably under defined conditions. In industries such as the process industries, energy sector and rail industry, functional safety supports safe operation, compliance with regulatory requirements and the long-term performance of industrial assets.
Safety-related systems continuously monitor relevant process conditions. When a critical situation is detected, predefined safety functions automatically initiate the required measures, ranging from alarms and emergency shutdowns to the isolation of plant sections. This helps bring the plant to a safe state or maintain it in a safe state.
As industrial plants and processes become increasingly complex, managing risk reliably becomes more important. Functional safety helps protect people, assets and the environment, supports compliance with regulatory requirements and contributes to avoiding unplanned downtime and its consequences.
Functional safety does not end with system design and implementation. It spans the entire safety lifecycle, from risk assessment and specification through validation and operation to maintenance, testing and modification. This helps ensure that safety functions continue to perform as intended throughout the lifecycle.
Functional safety depends on safety-related systems operating reliably and being protected against unauthorised access or manipulation. This is where OT security plays an important role, helping protect industrial control and automation systems against cyber threats and tampering. As industrial systems become increasingly connected, the relationship between functional safety and security continues to grow in importance.
The standards that govern functional safety
Functional safety is governed by international standards that define how risks are assessed, how safety functions are designed, and how systems are developed, validated, operated and maintained. Requirements vary by industry and application, and our engineers design and deliver systems in line with these standards throughout the project lifecycle.
01 IEC 61508 - Standard for Manufacturers
The international basic standard for the functional safety of safety-related electrical, electronic and programmable electronic (E/E/PE) systems. It defines the safety lifecycle and Safety Integrity Levels (SIL 1–4).
Target audience: Manufacturers and developers of safety-related hardware and software components, including sensors, logic systems, valves and actuators.
02 IEC 61511 - Standard for Operators
The international standard for the specification, design, implementation, operation and maintenance of Safety Instrumented Systems (SIS) in the process industries, including oil and gas, chemicals, pharmaceuticals and food processing.
Target audience: System integrators, engineering companies and operators in the process industries.
03 IEC 62443 - OT Security
An international series of standards addressing industrial cybersecurity and OT security. It provides a flexible framework for securing Industrial Automation and Control Systems (IACS) throughout their entire lifecycle.
04 EN 5012X - Railway Applications
A family of European CENELEC standards for railway applications focusing on functional safety, RAMS (Reliability, Availability, Maintainability, Safety) and system/software integrity, covering rail infrastructure and rolling stock.
05 EN ISO 13849-1 - Safety of Machinery
An internationally recognised standard specifying safety requirements and design principles for the safety-related parts of machinery control systems, using Performance Levels (PL a–e) to classify risk reduction.
Solutions
Safety systems and applications
We design, deliver and support safety instrumented systems in line with IEC 61508 and IEC 61511. Our scope ranges from core barriers such as emergency shutdown and fire and gas detection to specialized applications for pressure protection, fired equipment and turbomachinery. Each system is designed around the process, the risk assessment and the client’s requirements, with the architecture and technology selected to fit.
ESDEmergency Shutdown System
The barrier that brings the installation to a safe state when the process can no longer be controlled.
Key functions: Hierarchical shutdown levels, from total plant to local unit, executed through the cause and effect matrix: valve isolation, blowdown and depressurization, isolation of ignition sources and stop of rotating equipment, with proof testing and override handling.
Value: Brings the plant to a safe state in seconds without shutting down more than the event requires.
IEC 61508 / 61511 · ISO 13702 · NORSOK S-001
PSDProcess Shutdown System
A local safety function that handles process upsets in one part of the process while the rest of the facility keeps running.
Key functions: Detects hazardous process conditions and shuts down the affected process section, with defined interfaces to ESD, F&G, PCS/DCS and operator HMI.
Value: Contains upsets locally, protecting people and equipment while keeping production loss to a minimum.
IEC 61508 / 61511 · SIL 1-3
F&GFire and Gas Detection System
The detection and initiation layer for fire and explosion hazards.
Key functions: Monitors gas, flame, smoke and heat detectors and manual call points, with voting so a single faulty detector does not trip the plant. On confirmation it initiates alarms and beacons, ESD, HVAC damper closure, ignition source isolation and deluge, supported by a Critical Alarm/Action Panel (CAP) and HMI safety overview.
Value: Acts fast on a real release and stays quiet on a faulty detector, cutting spurious shutdowns.
IEC 61508 / 61511 · ISO 13702 · NORSOK S-001
HIPPSHigh Integrity Pressure Protection System
Fast-closing protection of downstream equipment against overpressure.
Key functions: Redundant pressure transmitters in voting configuration, a dedicated logic solver and fast-acting shutdown valves in series, with provisions for partial-stroke and proof testing.
Value: Allows downstream piping and equipment to be rated below full upstream pressure, saving CAPEX, weight and footprint and reducing relief and flare requirements.
IEC 61508 / 61511 · typically SIL 2-3
BMSBurner Management System
Safe start-up, operation and shutdown of burners in furnaces, boilers, heaters and flares.
Key functions: Enforces a permissive-based start-up sequence (purge, ignition, flame proving), monitors flame and safety conditions during operation, and shuts off fuel on flame failure, abnormal fuel pressure or loss of combustion air.
Value: Reduces the explosion risk in fired equipment, supports regulatory compliance and reduces nuisance trips.
IEC 61508 / 61511
TMCTurbomachinery Control
Operation, control, protection and condition monitoring of turbines and compressors in one system.
Key functions: Turbine and compressor control and protection, ESD and condition monitoring of vibration and axial displacement, configurable from fully integrated to fully segregated.
Value: One engineering, one commissioning and one maintenance interface, with optimized fuel consumption.
IEC 61508 / 61511
SafeCom®Safety-Related Communication
Safety-related transfer of signals over any distance and communication medium.
Key functions: Transfers safety signals over fiber, radio, satellite or network for applications up to SIL 3, with system design according to IEC 62443. Main applications are remote ESD and pipeline protection systems (PPS).
Value: Safe remote operation of critical infrastructure. In pipeline protection, a specification break reduces CAPEX and material use.
IEC 61508 / 61511 · IEC 62443
FMCFire Monitor Control
Reliable control of fire monitors from the control room, the field or a hardwired emergency panel.
Key functions: Operation via HMI, Ex-certified wireless remote control units and a SIL-capable hardwired emergency interface, with interlocking between operating positions and support for three-axis control and automated oscillation.
Value: Higher reliability for mitigating systems on an independent platform, with safety functions such as water release implemented where required.
IEC 61508 / 61511
Safety-related communication over any distance
One safety function, two locations
SafeCom® transfers safety signals and information between safety controllers at different locations, so a safety function can act across any distance.
- Up to SIL 3 according to IEC 61508 / 61511
- Any medium - fibre, radio, satellite or network
- Secure by design - system design according to IEC 62443
- Remote operation of safety-related tasks between any locations
IEC 61508 / 61511 · IEC 62443
Built for critical infrastructure
SafeCom® was developed for two main applications, and suits any application that requires safety-related transfer of signals.
- ESD - safety-related, also wireless, transfer of shutdown signals between installations and a control centre
- PPS - pipeline protection for long-distance pipelines, with a specification break
- Energy and grid - safety signals to offshore wind, substations and onshore terminals
Each location is kept within its own secure perimeter.
Pipeline Protection System
On long pipelines, SafeCom® carries the protection function from one end to the other. This allows a specification break, so the downstream section can be designed for a lower pressure than the upstream section.
- Safe operation of critical infrastructure such as gas pipelines
- Reduced CAPEX through the specification break
- Lower environmental footprint through reduced material use
Illustration is schematic and not to scale.
Initiator to final element
The ESD system isolates inventories, stops rotating equipment, depressurizes and removes ignition sources on demand from F&G, process safeguarding, manual pushbuttons or the fire and explosion strategy for the installation.
- Hierarchical shutdown levels executed through the cause and effect matrix
- Fail-safe valve isolation, blowdown and isolation of ignition sources
- Proof testing, partial-stroke testing and override handling with status to the operator
IEC 61508 / 61511 · ISO 13702 · NORSOK S-001
A global safety function
ESD handles emergencies that threaten large or entire parts of the facility. Confirmed fire or gas from F&G initiates ESD, and ESD in turn initiates PSD, so a higher shutdown level always includes the lower ones.
- Typical system interfaces - CAP, F&G, PCS/DCS, HMI and the electro control system
- Mechanical protection such as PSVs remains as the final barrier
- Typical field interfaces - digital and analog I/O
A local safety function
PSD detects hazardous process conditions and shuts down the affected process section, while the rest of the facility continues to operate. PSD is the lowest level in the shutdown hierarchy and is also initiated by every ESD level above it.
- Contains upsets locally instead of escalating to a wider shutdown
- Defined interfaces to ESD, F&G, PCS/DCS and operator HMI
- Protects people and equipment with minimal production loss
IEC 61508 / 61511 · SIL 1-3
Working with ESD and F&G
A pressure transmitter on the separator signals the PSD logic, which closes the inlet shutdown valve on a process upset. Gas detection is handled by F&G, which initiates ESD. ESD closes the same valve directly and also initiates PSD.
- Typical system interfaces - CAP, F&G, PCS/DCS and HMI
- Typical field interfaces - digital and analog I/O
The detection and initiation layer
F&G continuously monitors the installation for gas releases, flames, smoke and heat. On confirmed detection it initiates the mitigating actions defined in the cause and effect matrix.
- Critical Alarm/Action Panel (CAP) as part of the delivery
- HMI safety overview with auto-navigation on F&G alarm
- Detector fault and inhibit status to the operator
IEC 61508 / 61511 · ISO 13702 · NORSOK S-001
Fast on a real release, quiet on a faulty detector
Voting means a single faulty detector raises an alarm without shutting the plant down, while confirmed detection initiates protective actions.
- Fewer spurious trips and less lost production
- Complete, testable and traceable cause and effect logic from hazard to action
A barrier that replaces or supplements mechanical relief
HIPPS closes fast on high pressure to protect downstream piping and equipment, so they can be rated below full upstream pressure.
- Redundant pressure transmitters in voting configuration, typically 2oo3
- Dedicated logic solver and fast-acting shutdown valves in series
- Lower CAPEX, weight and footprint, and reduced relief and flare requirements
IEC 61508 / 61511 · typically SIL 2-3
Prevents unburned fuel from accumulating
The BMS closes the fuel supply through double block and bleed valves on flame failure, low or high fuel pressure, or loss of combustion air or draft.
- Continuous monitoring of flame and safety conditions
- Fail-safe shutdown of the fuel train
- Fewer nuisance trips while keeping fired equipment in production
IEC 61508 / 61511
Permissive-based start-up
The BMS enforces a safe start-up sequence and does not allow the next step until its conditions are met.
- Purge before ignition
- Flame proving before normal operation
- Safe shutdown whenever a safety condition is lost
Operation, control, protection and monitoring
All functions of a turbine and compressor train can be combined in one system, or kept segregated where the project requires it.
- One engineering, one commissioning and one maintenance interface
- Condition monitoring of vibration and axial displacement
- Optimized fuel consumption through integrated control
IEC 61508 / 61511
Protection and control of the whole train
Turbine and compressors are controlled and protected as one train, with process measurements, speed and anti-surge control, and condition monitoring.
- Turbine and compressor protection, including ESD
- Vibration and axial displacement monitoring
- Local operating station and connection to DCS/SCADA
Reliable operation of mitigating systems
Fire monitors can be operated from the control room, from the field or from a hardwired emergency interface, with interlocking so they are not operated from two positions at once.
- Three-axis control - horizontal, vertical and fog/jet
- Automated oscillation for monitors that support it
- Independent platform, with safety functions such as water release where required
IEC 61508 / 61511
Technology
HIMA Safety Platform
As a HIMA company, we have direct access to HIMA's safety platform, product expertise and lifecycle support. The platform brings safety control, engineering, communication and cybersecurity together, from compact SIL 3 systems to highly available, redundant architectures.
Talk to our functional safety specialists
Planning a new safety system, an upgrade or a modification? Our specialists are ready to discuss your project and help you find the right solution.