Im01e21a21 02en
Im01e21a21 02en
IM 01E21A21-02EN
IM 01E21A21-02EN
1st Edition
ADMAG TI Series
AXG/AXW Magnetic Flowmeter
Safety Manual
IM 01E21A21-02EN 1st Edition
Contents
1. Introduction....................................................................................................1
2. Safety Instrumented Systems Installation.................................................4
2.1 Scope and Purpose.............................................................................................. 4
2.2 Using this instrument for an SIS Application.................................................... 4
2.2.1 Safety Function...................................................................................... 4
2.2.2 Safety Accuracy..................................................................................... 4
2.2.3 Diagnostic Response Time.................................................................... 4
2.2.4 Setup...................................................................................................... 5
2.2.5 Required Parameter Setting.................................................................. 5
2.2.6 Proof Test............................................................................................... 5
2.2.7 Repair and Replacement....................................................................... 7
2.2.8 Startup Time........................................................................................... 7
2.2.9 Firmware Update................................................................................... 7
2.2.10 Reliability Data....................................................................................... 7
2.2.11 Lifetime Limits........................................................................................ 8
2.2.12 Environmental Limits............................................................................. 8
2.2.13 Application Limits................................................................................... 8
2.3 Definitions and Abbreviations............................................................................. 8
2.3.1 Definitions.............................................................................................. 8
2.3.2 Abbreviations......................................................................................... 8
SIL Declaration of Conformity
Failure Mode, Effects and Diagnostic Analysis
Revision Information
1. Introduction
This manual provides the basic guidelines for Safety Model Document Title Document No.
Instrumented Systems Installation of ADMAG TI ADMAG TI Series
AXW Magnetic Flowmeter
(Total Insight) Series AXG and AXW magnetic IM 01E24A01-01EN
[Size: 25 to 400 mm (1 to 16 in.)]
flowmeters. Installation Manual
For the items which are not covered in this ADMAG TI Series
manual, read the applicable user’s manuals and AXW Magnetic Flowmeter
[Size: 500 to 1800 mm IM 01E25A01-01EN
general specifications as listed in Table 1.1. These (20 to 72 in.)]
documents can be downloaded from the website of Installation Manual
YOKOGAWA. To ensure correct use of the ADMAG TI Series
AXW Magnetic Flowmeter
instrument, read these manuals thoroughly and fully IM 01E24A01-02EN
[Size: 25 to 1800 mm (1 to 72 in.)]
understand how to operate the instrument before AXW
Maintenance Manual
AXWG
maintaining it. For method of checking the model ADMAG TI Series
AXWW
and specifications, read the applicable general AXW4A
AXW Magnetic Flowmeter IM 01E24A02-01EN
BRAIN Communication Type
specifications in Table 1.1. AX01C
ADMAG TI Series
Website address: http://www.yokogawa.com/fld/doc/ AXW Magnetic Flowmeter IM 01E24A02-02EN
These manuals can be downloaded from the HART Communication Type
website of YOKOGAWA or purchased from the ADMAG TI Series
AXW Magnetic Flowmeter
YOKOGAWA representatives. [Size: 25 to 400 mm (1 to 16 in.)]
GS 01E24A01-01EN
General Specifications
Table 1.1 Manual and General Specifications List ADMAG TI Series
Model Document Title Document No. AXW Magnetic Flowmeter
[Size: 500 to 1800 mm GS 01E25D11-01EN
ADMAG TI Series
AXG AXG/AXW Magnetic Flowmeter IM 01E21A21-01Z1 (20 to 72 in.)]
AXW Read Me First General Specifications
AXG4A
ADMAG TI Series
AXW4A IM 01E21A21-02EN
AXG/AXW Magnetic Flowmeter
AX01C (this manual)
Safely Manual
ADMAG TI Series
NOTE
AXG Magnetic Flowmeter IM 01E22A01-01EN
Installation Manual When describing the model name like AXG
ADMAG TI Series in this manual, “”means any of the
AXG Magnetic Flowmeter IM 01E22A01-02EN
Maintenance Manual
following.
AXG ADMAG TI Series For AXG:
AXG4A AXG Magnetic Flowmeter IM 01E22A02-01EN 002, 005, 010, 015, 025, 032, 040, 050, 065,
AX01C BRAIN Communication Type
ADMAG TI Series
080, 100, 125, 150, 200, 250, 300, 350, 400
AXG Magnetic Flowmeter IM 01E22A02-02EN For AXW:
HART Communication Type
025, 032, 040, 050, 065, 080, 100, 125, 150,
ADMAG TI Series
AXG Magnetic Flowmeter GS 01E22A01-01EN 200, 250, 300, 350, 400
General Specifications For AXWG or AXWW:
500, 600, 700, 800, 900, 10L
IMPORTANT
The applicable scope of SIL 1 is as follows.
• AXG Integral Type
• Combination of AXG Remote Sensor and
AXG4A Remote Transmitter
• AXW Integral Type
• Combination of AXW Remote Sensor and
AXW4A Remote Transmitter
In case of combination of Remote Sensor and
AXFA11G Remote Transmitter, the combination
is outside the scope of SIL 1.
IM 01E21A21-02EN
<1. INTRODUCTION> 2
Precautions Related to the Protection, • For the protection and safe use of the
Safety, and Alteration of the Instrument instrument and the system in which this
The following safety symbol marks are used in this instrument is incorporated, be sure to follow
manual and instrument. the instructions and precautions on safety that
is stated in user's manual as listed in Table 1.1
whenever you handle the instrument. Take
WARNING special note that if you handle the instrument
in a manner that violated these instructions,
A WARNING sign denotes a hazard. It calls the protection functionality of the instrument
attention to procedure, practice, condition or the may be damaged or impaired. In such cases,
like, which, if not correctly performed or adhered YOKOGAWA does not guarantee the quality,
to, could result in injury or death of personnel. performance, function, and safety of instrument.
• Do not modify this instrument.
• The instrument should be disposed of in
accordance with local and national legislation/
CAUTION regulations.
A CAUTION sign denotes a hazard. It calls Regarding This User’s Manual
attention to procedure, practice, condition or the
• This manual should be provided to the end
like, which, if not correctly performed or adhered
user.
to, could result in damage to or destruction of
• The contents of this manual are subject to
part or the entire instrument.
change without prior notice.
• All rights reserved. No part of this manual
may be reproduced in any form without
IMPORTANT YOKOGAWA’s written permission.
• YOKOGAWA makes no warranty of any kind
An IMPORTANT sign denotes that attention is
with regard to this manual, including, but not
required to avoid damage to the instrument or
limited to, implied warranty of merchantability
system failure.
and fitness for a particular purpose.
• If any question arises or errors are found, or if
any information is missing from this manual,
NOTE inform the nearest YOKOGAWA sales office.
A NOTE sign denotes information necessary • The specifications covered by this manual are
for essential understanding of operation and limited to those for the standard type under the
features. specified model number break-down and do not
cover custom-made instruments.
• Note that changes in the specifications,
The following symbols are used in the Instrument
construction, or component parts of the
and the manual to indicate the accompanying
instrument may not immediately be reflected
safety precautions:
in this manual at the time of change, provided
Protective grounding terminal that postponement of revisions will not cause
difficulty to the user from a functional or
Functional grounding terminal (This terminal should
not be used as a protective grounding terminal.)
performance standpoint.
• To ensure correct use, read this manual and the
Alternating current
applicable user’s manuals as listed in Table 1.1
Direct current
thoroughly before starting operation. Read the
Caution
This symbol indicates that the operator must refer to general specifications as listed in Table 1.1 for
an explanation in the user’s manual in order to avoid its specification.
the risk of injury or death of personnel or damage to
the instrument.
IM 01E21A21-02EN
<1. INTRODUCTION> 3
Trademark
• All the brands or names of Yokogawa
Electric’s products used in this manual are
either trademarks or registered trademarks of
Yokogawa Electric Corporation.
• All other company and product names
mentioned in this manual are trade names,
trademarks or registered trademarks of their
respective companies.
• In this manual, trademarks or registered
trademarks are not marked with ™ or ®.
For Safe Use of Product
For the protection and safe use of the instrument
and the system in which this instrument is
incorporated, be sure to follow the instructions
and precautions on safety that is stated in user's
manual as listed in Table 1.1 whenever you handle
the instrument. Take special note that if you handle
the instrument in a manner that violated these
instructions, the protection functionality of the
instrument may be damaged or impaired. In such
cases, YOKOGAWA shall not be liable for any
indirect or consequential loss incurred by either
using or not being able to use the Instrument.
IM 01E21A21-02EN
<2. Safety Instrumented Systems Installation> 4
Measuring Actuator
Device
F0201.ai
This instrument converts Flow velocity, Volume flow, Mass flow, and Flow noise (for AXG only) to current. And
it outputs “Analog Output 1” at “I/O 1” terminal as its safety functions. Other functions (display, etc…) are out of
its scope. Use this “Analog Output 1” to connect the safety PLC when this instrument is used as a SIS.
It is necessary to set adequate parameters before starting to use this instrument as a SIS. Refer to Subsection
2..2.4 and Subsection 2.2.5 for details.
IM 01E21A21-02EN
<2. Safety Instrumented Systems Installation> 5
2.2.4 Setup
Set the ranges and units via the BRAIN or HART configuration tool. After configuration, make sure that
they are set correctly. The calibration of this instrument must be carried out after parameters are set. For its
parameter settings, read Chapter 4 and Chapter 5 in the user’s manual of applicable communication type as
listed in Table 1.1.
IM 01E21A21-02EN
<2. Safety Instrumented Systems Installation> 6
Table 2.2.3 Proof Test
Testing method Tool required Expected outcome Remarks
Loop test for “Analog output” For BRAIN: Proof Test Coverage; The output
1. Bypass the safety PLC or take other appropriate BRAIN Without Intrinsic safety needs to be
action to avoid a false trip. configuration tool circuitry = 94% monitored to
2. Verify the analog output whether it reaches With Intrinsic safety circuitry assure that
the expected level by making a condition of For HART: = 93% this instrument
an alarm as “> 21.6 mA” at “Analog Output HART communicates
1” through BRAIN or HART communication configuration tool Proof Test Coverage; the correct signal
protocol. (with a combination
3. Verify the analog output whether it reaches use between diagnostic
the expected level by making a condition of function)
an alarm as “< 2.4 mA” at “Analog Output Without Intrinsic safety
1” through BRAIN or HART communication circuitry = 99%
protocol. With Intrinsic safety circuitry
4. Confirm the condition neither error nor warning. = 99%
5. Verify their reasonability check of the analog
output through both its maximum flow range and
its minimum flow range.
6. Verify their reasonability check of the analog
output through its flow zero.
7. Verify their reasonability check of the analog
output through its typical flow rate.
8. Return the loop to the full operation.
9. Return to the normal operation from a condition
of bypass or prevention of malfunction to the
safety PLC.
IM 01E21A21-02EN
<2. Safety Instrumented Systems Installation> 7
(2) Set parameters through BRAIN or HART communication protocol in order to generate an alarm at “Analog
Output 1” by making a condition of scale out at its low limit side of current value.
BRAIN: G04: AO1 ALM OUT
HART Menu Path:
Device root menu▶Detailed setup▶Analog output/input▶Analog output 1▶AO1 alarm out
Select “< 2.4 mA” when generating an alarm for its low limit side.
IM 01E21A21-02EN
<2. Safety Instrumented Systems Installation> 8
2.2.11 Lifetime Limits
The expected lifetime of this instrument is 10 years. The reliability data listed the FMEDA report is only valid for
this period. The failure rates of this instrument may increase sometime after this period. Reliability calculations
based on the data listed in the FMEDA report for its lifetimes beyond 10 years may yield results that are too
optimistic, i.e. the calculated SIL will not be achieved.
● Verification
Definition Contents
Verification The demonstration for each phase of the life-cycle that the (output) deliverables of the
phase meet the objectives and requirements specified by the inputs to the phase. The
verification is usually executed by analysis and/or testing.
Validation The demonstration that the safety-related system(s) or the combination of safety-
related system(s) and external risk reduction facilities meet, in all respects, the Safety
Requirements Specification. The validation is usually executed by testing.
Safety Assessment The investigation to arrive at a judgment based on evidence of the safety achieved by
safety-related systems.
Further definitions of terms used for safety techniques and measures and the description of safety-related
systems are given in IEC 61508-4.
2.3.2 Abbreviations
Definition Contents
FMEDA Failure Mode, Effects and Diagnostic Analysis
SIF Safety Instrumented Function
SIL Safety Integrity Level
SIS Safety Instrumented System
SLC Safety Lifecycle
IM 01E21A21-02EN
Failure Modes, Effects and Diagnostic Analysis
Project:
AXG/W Magnetic Flowmeter
Company:
Yokogawa Electric Corporation
Musashino, Tokyo
Japan
The document was prepared using best effort. The authors make no warranty of any kind and shall not be liable in any
event for incidental or consequential damages in connection with the application of the document.
© All rights reserved.
Management Summary
This report summarizes the results of the hardware assessment in the form of a Failure Modes,
Effects, and Diagnostic Analysis (FMEDA) of the AXG/W Magnetic Flowmeter, hardware software
revision per Section 2.5.1. A Failure Modes, Effects, and Diagnostic Analysis is one of the steps to
be taken to achieve functional safety certification per IEC 61508 of a device. From the FMEDA,
failure rates are determined. The FMEDA that is described in this report concerns only the hardware
of the AXG/W Magnetic Flowmeter. For full functional safety certification purposes all requirements
of IEC 61508 must be considered.
The AXG/W Magnetic Flowmeter uses excitation coils and electrodes to measure fluid flow. HART
or BRAIN communication signal are superimposed on 4-20 mA signal. Besides the analog 4-20mA
current output is a Pulse Output signal. Diagnostics include monitoring electrodes for the adherence
of insulating material that would affect the flow measurement and a reverse calculation of the process
variables.
The AXG/W Magnetic Flowmeter is classified as a Type B1 element according to IEC 61508, having
a hardware fault tolerance of 0.
Based on the assumptions listed in 4.3, the failure rates for the AXG/W Magnetic Flowmeter are
listed in section 4.4.
These failure rates are valid for the useful lifetime of the product, see Appendix A.
Failure rates listed in this report do not include failures due to wear-out of any components. They
reflect random failures and include failures due to external events, such as unexpected use, see
section 4.2.
A user of the AXG/W Magnetic Flowmeter can utilize these failure rates in a probabilistic model of a
safety instrumented function (SIF) to determine suitability in part for safety instrumented system (SIS)
usage in a particular safety integrity level (SIL).
1Type B element: “Complex” element (using micro controllers or programmable logic); for details see 7.4.4.1.3
of IEC 61508-2, ed2, 2010.
© exida YEC 16-03-009 R001 V1R5 FMEDA AXG_W.docx
T-001 V10,R2 exida 64 N. Main St, Sellersville, PA 18960 Page 2 of 24
Table of Contents
2.1 exida ...................................................................................................................................... 5
2.2 Roles of the parties involved ................................................................................................. 5
2.3 Standards and literature used ............................................................................................... 5
2.4 exida tools used .................................................................................................................... 6
2.5 Reference documents ............................................................................................................ 6
2.5.1 Documentation provided by Yokogawa Electric Corporation ....................................... 6
2.5.2 Documentation generated by exida.............................................................................. 7
4.1 Failure categories description ................................................................................................ 9
4.2 Methodology – FMEDA, failure rates .................................................................................. 10
4.2.1 FMEDA ........................................................................................................................ 10
4.2.2 Failure rates ................................................................................................................. 10
4.3 Assumptions......................................................................................................................... 11
4.4 Results ................................................................................................................................. 12
5.1 PFDavg calculation AXW/G Magnetic Flowmeter ................................................................. 14
7.1 Liability ................................................................................................................................. 16
7.2 Releases .............................................................................................................................. 16
7.3 Future Enhancements ......................................................................................................... 16
7.4 Release signatures .............................................................................................................. 17
Appendix A Lifetime of Critical Components ................................................................... 18
Appendix B Proof Tests to Reveal Dangerous Undetected Faults .................................. 19
B.1 Suggested Proof Test .......................................................................................................... 19
Appendix C exida Environmental Profiles ................................................................... 20
Appendix D Determining Safety Integrity Level ............................................................ 21
The FMEDA includes the coils, electrodes and the four wire powered electronics. See diagram below.
The AXG/W Magnetic Flowmeter is classified as a Type B2 element according to IEC 61508, having
a hardware fault tolerance of 0.
2Type B element: “Complex” element (using micro controllers or programmable logic); for details see 7.4.4.1.3
of IEC 61508-2, ed2, 2010.
© exida YEC 16-03-009 R001 V1R5 FMEDA AXG_W.docx
T-001 V10,R2 exida 64 N. Main St, Sellersville, PA 18960 Page 8 of 24
4 Failure Modes, Effects, and Diagnostic Analysis
The Failure Modes, Effects, and Diagnostic Analysis was performed based on the documentation in
section 2.5.1 and is documented in [R1] , [R2], [R3], [R4]and [R3].
4.2.1 FMEDA
A Failure Modes and Effects Analysis (FMEA) is a systematic way to identify and evaluate the effects
of different component failure modes, to determine what could eliminate or reduce the chance of
failure, and to document the system in consideration.
A FMEDA (Failure Mode Effect and Diagnostic Analysis) is an FMEA extension. It combines standard
FMEA techniques with the extension to identify automatic diagnostic techniques and the failure
modes relevant to safety instrumented system design. It is a technique recommended to generate
failure rates for each important category (safe detected, safe undetected, dangerous detected,
dangerous undetected, fail high, fail low, etc.) in the safety models. The format for the FMEDA is an
extension of the standard FMEA format from MIL STD 1629A, Failure Modes and Effects Analysis.
These failure rates are valid for the useful lifetime of the product, see Appendix A.
According to IEC 61508 the architectural constraints of an element must be determined. This can be
done by following the 1H approach according to 7.4.4.2 of IEC 61508 or the 2H approach according
to 7.4.4.3 of IEC 61508.
The 1H approach involves calculating the Safe Failure Fraction for the entire element.
The 2H approach involves assessment of the reliability data for the entire element according to
7.4.4.3.3 of IEC 61508.
According to 3.6.15 of IEC 61508-4, the Safe Failure Fraction is the property of a safety related
element that is defined by the ratio of the average failure rates of safe plus dangerous detected
failures and safe plus dangerous failures. This ratio is represented by the following equation:
SFF = (ΣλS avg + ΣλDD avg)/(ΣλS avg + ΣλDD avg+ ΣλDU avg )
When the failure rates are based on constant failure rates, as in this analysis, the equation can be
simplified to:
SFF = (ΣλS + ΣλDD)/(ΣλS + ΣλDD + ΣλDU )
Where:
λS = Fail Safe
λDD = Fail Dangerous Detected
λDU= Fail Dangerous Undetected
3 It is important to realize that the No Effect failures are no longer included in the Safe Undetected failure
category according to IEC 61508, ed2, 2010.
4 Safe Failure Fraction if needed, is to be calculated on an element level
7.2 Releases
Version History: V1, R5: Update after FIT, November 7, 2016
V1, R4: First Release, August 3, 2016
V1, R3: Update after customer review, August 2, 2016
V1, R2: Second Draft for Customer Review, August 2, 2016
V1, R1: Draft for Customer Review, July 31, 2016
V0, R1: Draft for Internal Review, 25 July, 2016
Author(s): Kiyoshi Takai
Review: V0, R1: Rudolf Chalupa (exida), July 26, 2016
V1, R2: Kaoru Sonoda, August 2, 2016
V1, R3: Kaoru Sonoda, August 2, 2016
Release Status: Second Draft for Customer Review
It is the responsibility of the end user to maintain and operate the AXG/W Magnetic Flowmeter per
manufacturer’s instructions. Furthermore regular inspection should show that all components are
clean and free from damage.
When plant experience indicates a shorter useful lifetime than indicated in this appendix, the number
based on plant experience should be used.
5 Useful lifetime is a reliability engineering term that describes the operational time interval where the failure
rate of a device is relatively constant. It is not a term which covers product obsolescence, warranty, or other
commercial issues.
© exida YEC 16-03-009 R001 V1R5 FMEDA AXG_W.docx
T-001 V10,R2 exida 64 N. Main St, Sellersville, PA 18960 Page 18 of 24
Appendix B Proof Tests to Reveal Dangerous Undetected Faults
According to section 7.4.5.2 f) of IEC 61508-2 proof tests shall be undertaken to reveal dangerous
faults which are undetected by automatic diagnostic tests. This means that it is necessary to specify
how dangerous undetected faults which have been noted during the Failure Modes, Effects, and
Diagnostic Analysis can be detected during proof testing.
Step Action
1. Bypass the safety function and take appropriate action to avoid a false trip
2. Use HART communications to retrieve any diagnostics and take appropriate action.
3. Send a HART or BRAIN command to the transmitter to go to the high alarm current
output and verify that the analog current reaches that value6.
4. Send a HART or BRAIN command to the transmitter to go to the low alarm current output
and verify that the analog current reaches that value7.
5. Perform a two-point calibration8 of the transmitter over the full working range.
6. Check current output when there is no flow in the meter9.
7. Check current output when there is a typical flow in the meter.
8. Remove the bypass and otherwise restore normal operation
6 This tests for compliance voltage problems such as a low loop power supply voltage or increased wiring
resistance. This also tests for other possible failures.
7 This tests for possible quiescent current related failures.
8 If the two-point calibration is performed with electrical instrumentation, this step of the proof test will not detect
with all other variables remaining the same, the PFDavg for the SIF equals 5.76E-02 which barely
meets SIL 1 with a risk reduction factor 17. The subsystem PFDavg contributions are Sensor PFDavg
= 2.77E-03, Logic Solver PFDavg = 1.14E-05, and Final Element PFDavg = 5.49E-02 (Figure 4).
IM 01E21A21-02EN