SIS Proof Testing: Bypass Management
How placing Safety Instrumented System (SIS) loops in bypass during online testing represents a massive hazard, and how to control it.
1. Introduction & Context
In the process industries, Safety Instrumented Systems (SISs) act as the silent protectors of the facility. Comprising sensors, logic solvers (Safety PLCs), and final control elements (like emergency shutdown valves), an SIS is designed to take the process to a safe state if normal control systems fail.
To ensure the SIS works when called upon, standard IEC 61511 mandates periodic “proof testing.” However, conducting these tests while the plant is online often requires technicians to temporarily place specific safety loops into a “bypass” state. During this bypass window, the safety net is gone, exposing the plant to catastrophic risk if an upset occurs.
2. The Core Issue
To test a safety transmitter or shutdown valve without shutting down the entire plant, technicians insert a bypass—either by forcing a software bit inside the Safety PLC or by placing a physical jumper wire or calibrator on the loop terminals. This allows them to simulate fault conditions (like high pressure or high level) to verify the logic solver and downstream components respond correctly.
The hazards during this proof testing window include:
- Zero Protection: While bypassed, that specific safety loop is completely blind. If the actual process variable reaches the danger threshold, the SIS will not trip.
- Human Factor Oversights: The most common failure mode in bypass management is the “forgotten bypass.” A technician gets distracted by a radio call, shifts change, or the test is aborted, and the safety loop is left in bypass. The plant runs for days or weeks with its emergency shutdown loop disabled.
- Improper Validation: Bypasses must be inserted at the correct point in the loop. If a bypass is placed at the logic solver output rather than the input sensor, the test may fail to verify the actual valve stroke, providing a false sense of security.
Without a robust, documented bypass management system, online proof testing can become the direct trigger for a catastrophic process event.
3. Actionable Takeaways
- Implement Automated Bypass Timers: Program safety logic solvers with automated bypass timeout alarms. If a bypass remains active for more than a pre-determined duration (e.g., 2 hours), trigger a high-priority alarm on the operator’s HMI.
- Require Visual HMI Indicators: Ensure that any active software bypass or force displays a permanent, flashing indicator on the main SCADA/HMI screens. Operators must have immediate, unambiguous visibility of what safety systems are currently defeated.
- Standardize on Physical “Bypass Keys”: For critical safety loops, transition from software forces to physical key-switches on the control panel. Technicians must physically turn a key to bypass the loop, and the key cannot be removed while the bypass is active, leaving a clear physical indicator.
- Strict Pre-Commissioning Verification: Implement a mandatory two-person sign-off protocol for any online test. The second qualified technician must verify that the bypass has been successfully removed and the safety loop is fully restored before signing off the work order.