B

The following table shows common requirements. The differences between solution A and B are shown by typeface italic.

Requirements for maintenance override handling

Responsibility

Already during the software configuration of the PLC system it is determined in a table or in the application program, whether the signal is allowed to be overridden.

The configuration may also specify by a table, whether simultaneousoverriding in independent parts of the ap- plicationisacceptable.

Maintenanceoverrides are enabled for the whole PLC or a subsystem (process unit) by the DCS or a hard-wired switch (e.g. key switch).

A.The override is activated via DCS.

B.The maintenance engineer activates the override via the programmingenvironment.

As an organizational measure, the operator should con- firm the overridecondition.

Project engineer and commissioner responsible for correctconfiguration.

A.Project engineer

B.Projectengineer, Typeapproval

A.OperatororMaintenanceengineer.

B.Typeapproval

A.Operator,Maintenanceengineer

B.Typeapproval,Maintenance engineer

Directoverrides on inputs and outputs are not allowed. Overrides have to be checked and to be implemented in relation to the application. Multiple overrides in a PLC are allowed as long as only one override is used in a given safety related group. The alarm shall not be overridden.

A.Project engineer

B.Projectengineer, Typeapproval

The PLC alerts the operator, e.g. via the DCS,indicating the override condition. The operator will be warned until the override is removed.

A.The override is removed via DCS.

B.The maintenanceengineer removes the override via the programmingenvironment.

A.There should be a second way to removethemaintenance overrodecondition.

B.If urgent, the maintenance engineer can remove the override by the hard-wiredswitch.

During the time of overrideproperoperationalmeasures have to be implemented. The time span for overriding shall be limited to one shift (typically not longer than 8 hours), or hard-wired common maintenance override switch (MOS) lamps shall be provided on the operator console (one per PLC or per process unit).

Project engineer,Commissioner

A.Operator,Maintenanceengineer

B.Maintenanceengineer

A.Project engineer

B.Maintenanceengineer, Type approval

Project engineer,Commissioner, DCS program,PLCprogram

B-2

GeniustModular Redundancy Flexible Triple Modular Redundant (TMR) System

GFK-0787B

 

User's Manual ± March 1995

 

Page 204
Image 204
GE GFK-0787B user manual Project engineer Projectengineer, Typeapproval