Service Center Repairs We Buy Used Equipment: Instra
Service Center Repairs We Buy Used Equipment: Instra
Service Center Repairs We Buy Used Equipment: Instra
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
© 2016 Bently Nevada, Inc.
All rights reserved.
* Denotes a trademark of Bently Nevada, Inc., a wholly owned subsidiary of General Electric
Company.
Contact Information
The following contact information is provided for those times when you cannot contact your
local representative:
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
Additional Information
NOTE
This manual does not contain all the information required to operate and maintain the product. Refer to the
following manuals for other required information.
3500 Monitoring System Installation and Maintenance Manual (part number 129766-01)
3500 Monitoring System Rack Configuration and Utilities Guide (part number 129777-01)
3500 Monitoring System Computer Hardware and Software Manual (part number 128158-01)
3500/32 and 3500/32M 4-Channel Relay Module Manual (part number 129771-01)
3500/32 and 3500/32M 4-Channel Relay Module Data Sheet (part number 141533-01)
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
Contents
1. Purpose 1
1.1 Abbreviations 1
1.2 IEC 61508-2 Annex D Requirements References 3
1.3 References 4
2. Hardware 5
2.1 Rack Interface Monitor 6
2.2 System Power Supplies 6
2.3 Monitors 6
2.4 Relay Modules 7
2.4.1 3500/32M_SIL 4-Channel Relay Module 7
2.4.2 3500/33_SIL 16-Channel Relay Module 9
3. Constraints and SIL Requirements 12
3.1 Skills Required to Commission and Maintain SIL Monitors 12
3.2 SIL 1 Requirements 12
3.2.1 Ordering requirements: 12
3.2.2 Hardware Requirements: 12
3.2.3 Software Requirements: 13
3.3 Recommendations 14
4. Functional Specifications 15
4.1 Systematic Capability 15
4.2 Architectural/Random Constraints, Overview 15
4.2.1 Architectural/ Random Constraints, 1oo1 Configuration 15
4.2.2 Architectural/ Random Constraints, 1oo2 Configuration with Redundant Relay
Paths 17
4.2.3 Architectural/Random Constraints, 1oo2 Configuration with Redundant Controller
and Relay Paths 20
5. Failure Modes 23
5.1 Failure modes of the 3500/32M_SIL and 3500/33_SIL Modules 23
5.2 Failure modes that are not detected by internal diagnostics 23
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
1. Purpose
The purpose of this safety manual is to document all the information specifically related to the
functional safety aspects of the 3500/32M_SIL and 3500/33_SIL Relay Modules. These modules
are certified for use as a component in a functional safety system. This safety manual is required
in order to enable the integration of the 3500/32M_SIL and 3500/33_SIL into a safety related
system and to be in compliance with the requirement of IEC 61508-2 Annex D. This manual is
focused on those details which specifically apply to the functional safety use case, and must be
used in conjunction with the standard product documentation for these products.
1.1 Abbreviations
l ANSI/ISA – American National Standard Institute / International Society of Automation
l API - American Petroleum Institute
l ARM – armature
l β – common cause failure factor for undetectable dangerous faults
l βD – common cause failure factor for detectable dangerous faults
l CE – Conformité Européenne (European Conformity)
l DC - diagnostic coverage
l FIT - failures in time
l FMEA - failure mode effect and analysis
l FS – functional safety
l HFT - hardware fault tolerance
l IEC – International Electro-technical Commission
l MRT - mean repair time
l MTBF - mean time between failure
l MTTF - mean time to failure
l MTTR - mean time to restoration
l NC - normally closed
l NDE - normally de-energized
l NE - normally energized
l NO - normally open
l PTC - proof test coverage
l PFD - probability of failure on demand
l SC - systematic coverage
l SFF - safe failure fraction
l SIF – safety instrumented function
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
l SIL – Safety Integrity Level
l TUV – Technischer Überwachungsverein (Technical Inspection)
l λs = safe failure rate
l λsd = safe detected failure rate
l λsu = safe undetected failure rate.
l λd = dangerous failure rate.
l λdd = dangerous detected failure rate.
l λdu = The dangerous undetected failure rate.
l λ- Common = common failures across all channels
l λ- Redundant = channel specific failures, which would take into account β’s when used in
redundant a 1oo2 configuration
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
1.2 IEC 61508-2 Annex D Requirements References
The table below provides a reference to which section of this document fulfills the 61508-2
Standard.
D2.1 a) a functional specification of the functions capable of being Section 2.4.1 for 3500/32M_SIL
performed Section 2.4.2 for 3500/33_SIL
D2.1 b) identification of the hardware and/or software configuration of Section 2.4.1 for 3500/32M_SIL
the compliant item Section 2.4.2 for 3500/33_SIL
D2.2 b) for every failure mode in a), an estimated failure rate Section 4
D2.2 c) the failure modes of the compliant item due to random hardware
failures, that result in a failure of the function and that are detected by Section 5.3
diagnostics internal to the compliant item
D2.2 g) for every failure mode in c) the outputs of the compliant item
Section 5.3
initiated by the internal diagnostics
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
1.3 References
IEC 61508, Parts 1 - 7:2010: Functional safety of electrical/electronic/programmable electronic
safety-related systems
API Standard 670, 4th edition, Dec. 2000 Machinery Protection Systems
Schematic diagram 3500/33 & /32M Relay Control Module, Dwg. No: 149987
Copy of ISO 9001 certificate, issued by Det Norske Veritas, 11 Oct. 2001
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
2. Hardware
The 3500 system is a rack based machinery protection and condition monitoring system that
provides information to protect and assess the mechanical condition of rotating and
reciprocating machinery. The 3500 system continuously measures and monitors various
protection and supervisory parameters and provides important information for early
identification of machinery problems such as imbalance, misalignment, shaft crack, and bearing
failures. The 3500 system is composed of monitors which accept inputs from transducers,
condition the signals to provide various measurements, and compares the conditioned signals
with user-programmable alarms. These alarm statuses are generated and broadcast onto the
system alarming networks. Also in this system are relay modules that observe the alarming
networks, and drive relays based on user programmable relay logic.
In SIL Certified systems, the safety function is supported by one or more SIL certified monitors
which supply alarm and status information to one or more relay modules that consume the
information to resolve machine trip logic and drive their relay output(s). These relay outputs are
the monitoring system’s safety output function. The relay outputs, are intended to be used in the
greater Safety Instrumented Function (SIF) to bring the process to a safe state.
A basic 3500 system consists of a rack chassis, a backplane circuit board, redundant power
supplies and a system interface module. This basic system supports a number of
monitor/module slots where a variety of system monitors and modules can be installed in order
to perform the machinery protection function required by the application.
A SIL certified 3500 system will be made up of one or more certified monitors interacting with one
or more certified relay modules. Both the monitors and relay modules are designed specifically to
function within the 3500 architecture and communicate with each other, and cannot be directly
interfaced to external devices except as described above. The monitors and relay modules are
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
each certified independently to facilitate the flexibility of the system to be applied to a wide range
of safety instrumented function applications.
2.3 Monitors
The 3500 system monitors accept inputs from transducers in the field and condition the signal
into measurements useful for machinery protection. The monitor constantly compares the
measurements against configured alarm setpoints to generate alarm and channel OK statuses
that are broadcast onto system alarming networks. The monitors are installed in any of the
monitoring slots available in the system. Numerous SIL Certified monitors are available with the
3500 system, each providing different machinery protection capabilities. The different certified
monitors can be combined and/or duplicated to achieve the required safety instrumented
functionality.
A 3500 monitor is composed of a main card and an I/O module. The I/O module interfaces with
the transducers producing the machinery-related signals, and condition the signals for the
monitor main card. The main card is responsible for generating measurements from transducer
information and generating the alarm and status messages.
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
2.4 Relay Modules
The 3500 system relay modules consume the alarm and status information broadcast onto the
system alarming networks and constantly compares these messages against the configured
relay drive logic, to provide machinery protection trip output capability.
A 3500 relay module is a multi-channel module composed of a main card known as the relay
controller and a relay output module. The relay controller interfaces with the 3500 system
alarming network to process its configured relay drive logic and generate relay channel drive
signals. The relay I/O module accepts the relay drive signals from the controller and contains the
relay devices which provide the machinery trip contacts.
Each channel provides independent “Alarm Drive Logic” functionality which allows the user to
develop complex logic strings using Boolean (AND and OR) logic elements. The logic acts on the
alarm states (alert, danger) and validity states (Not OK) generated by monitors in the system
which are available from the system alarming networks. Each channel’s logic string drives its own
relay output which is intended to be used as a machinery trip output.
The module’s fundamental safety function is the relay output contact state change.
The module is configured using the 3500 Rack Configuration Software. All software configuration
options and logic parameters available, are valid for use supporting the safety function without
restriction. These parameters can be selected and arranged to suit the specific application
requirements.
The Relay I/O contains three output contacts: Armature (ARM), Normally Open (NO), and Normally
Closed (NC), which refer to the state of the contacts when the relay coils are de-energized. Also,
each channel is independently configurable for Normally Energized (NE) or Normally De-
energized (NDE) by means of DIP switches located on the back of the I/O module. The NE/NDE
state refers to the state of the relay drive coil under normal (non-emergency) conditions.
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
Refer to the 3500/32 and 3500/32M Operation and Maintenance Manual (Part Number 129771-01)
configuration section on how to properly configure the module using the 3500 Rack
Configuration Software. For proper field wiring installation diagrams refer to the appropriate
module section in of the 3500 System Field Wiring diagram package (Part Number 130432-01) for
further information.
1. Relay module
2. I/O module
3. Status LEDs
4. Relay channel LEDs
5. Relay Contacts
6. Relay mode selection switch
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
Table 2 - 1: SIL Certified 3500/32M_SIL Relay Modules
00 - None
3500/32M_SIL1 –A01 –BXX 01 - 4-Channel Relay
01 - CSA/NRTL/C (Class 1, Div 2)
3500/32M_SIL2 –A01 –BXX Output Module
02 - ATEX.CSA (Class 1, Zone 2)
Refer to the 3500/33 Operation and Maintenance Manual (Part Number 162291-01) configuration
section on how to properly configure the module using the 3500 Rack Configuration Software.
For proper field wiring installation diagrams refer to the appropriate module section in the 3500
System Field Wiring diagram package (Part Number 130432-01).
The 3500/33_SIL relay module provides two options for the Relay I/O. It can be paired with either
the standard I/O (3500/33-A01-BXX) or the “failsafe” I/O (3500/33-A02-BXX). The failsafe Relay I/O
Module provides fail-safe behavior under a number of relay module fault conditions as described
below:
l Removal of the main relay controller module from the front of the 3500 rack will cause all
relays on its associated failsafe relay I/O module to go to the in alarm state.
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
l When used with a failsafe Relay I/O module the microprocessor on the main relay
controller module will drive the relays to the in-alarm state in the event that it detects a fatal
error during its diagnostic checks or if a microprocessor execution exception occurs.
1. Relay module
2. I/O module
3. Status LEDs
4. Relay channel LEDs
5. Relay Contacts
6. Relay mode selection switch
00 - None
01 - 16-Channel Relay Output Module 01 - CSA/NRTL/C (Class 1, Div
3500/33_SIL1 –AXX –BXX
02 - 16-Channel Failsafe Relay Output 2)
3500/33_SIL2 –AXX –BXX
Module 02 - ATEX/CSA (Class 1, Zone
2)
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
Hardware Firmware
Spare part number Description
Revision Revision
3500/33_SIL1-A01-
3500/33 SIL1 16-Channel I/O Module M N/A
BXX
3500/33_SIL2-A01-
3500/33 SIL1 16-Channel I/O Module M N/A
BXX
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
3500/40M_SIL or 3500/42M_SIL.
l The 3500 System that contains the 3500/32M_SIL or 3500/33_SIL modules must be
supported by redundant 3500/15 Power Supplies.
l The system program keyswitch on the 3500/22M TDI must be set to the "RUN" position after
the 3500/32M_SIL or 3500/33_SIL Relay Modules are configured, and the system
commissioned.
l Removal of any component of the 3500 system that is part of the critical safety path will
require a full proof test of the SIL system.
l The output relays must be configured for normally energized at the non-alarm condition
(de-energize to trip).
l The wiring of the relay contacts must be such that the output circuit has continuity under
non-alarm conditions, with the loss of circuit continuity indicating the unsafe state (the
external circuit is de-energize to trip). Note that this is distinct and different from the relay
drive coil normally energize/normally de-energized configuration.
l The system OK relay on the 3500/22M TDI must continuously monitored by an automated
system to provide detection of system faults.
l The 3500/32M_SIL has a maximum contact rating of 2A and 30V.
l The 3500/33_SIL has a maximum contact rating of 5A and 30V.
l The 3500/32M_SIL and 3500/33_SIL are considered to be a system operating in low
demand mode.
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
3.3 Recommendations
Bently Nevada, Inc. recommends having GE Bently Nevada Services inspect the components and
system during validation/commissioning for proper installation, configuration and usage.
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
4. Functional Specifications
Each channel provides independent “Alarm Drive Logic” functionality which allows the user to
develop complex logic strings using Boolean (AND and OR) logic elements. The logic acts on the
alarm states (alert, danger) and validity states (Not OK) generated by monitors in the system
which are available from the system alarming networks. Each channel’s logic string drives its own
relay output intended to be used as a machinery trip output.
Associated safety related elements such as Proximitors* and other 3500 Monitors (e.g. 3500/7X),
have been independently assessed by the test institute and the results are documented under
their individual test reports.
The component level FMEDA was carried out by TÜV Rheinland under consideration to the
requirements of IEC 61508, parts 1-7:2010. Component failure rates were based on SN 29500, with
a maximum ambient temperature of 65°C.
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
l The relay channel must be configured for de-energize to trip.
l The safety-related circuit must be set up such that the opening of the relay contacts
activates the safety function (de-energize circuit to trip) as shown in figure 4-1.
l Average probability of a dangerous failure on demand (PFD) < 10 E-1.
l The 3500/32M_SIL and 3500/33_SIL modules are considered to be a system operating in a
low demand mode.
l The 3500/32M_SIL and 3500/33_SIL modules have a hardware safety integrity route of 1H.
l The 3500/32M_SIL and 3500/33_SIL modules have a systematic safety Integrity route of 1S.
l The rated life time of the 3500/32M_SIL and 3500/33_SIL modules is 10 years.
l The 3500/32M_SIL and 3500/32_SIL Relay Controller Module are Type B safety related
elements with a Safe Failure Fraction (SFF) of 60% to <90%.
l The 3500/32M_SIL and 3500/32_SIL Relay Output Modules are Type A safety related
elements with a Safe Failure Fraction (SFF) of <60%.
l The 3500/32M_SIL and 3500/33_SIL modules have a Hardware Fault Tolerance (HFT) of 0
when used in a 1oo1 configuration.
l The MTTR and MRT for the 3500/32M_SIL and 3500/33_SIL modules is 168 hours or 1
week**.
**MTTR and MRT were assigned as 168 hours for the purposes of generating the PFDAVE
calculation. This figure may be adjusted to suit application specific considerations as long as the
specific value is also used to adjust the PFDAVE calculation specific to the safety-related
installation.
As shown in the safety block diagram, Figure 4-2, the 3500/32M and 3500/33 Relay Controller
Modules are classified as Type B devices, and the 3500/32 and 3500/33 Relay Output Modules are
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
Type A. The failure rates when used in the 1oo1 configuration are shown in Table 4-1. These
failure rates are based on the 1oo1 safety block diagram in Figure 4-2.
The following values were calculated by TÜV Rheinland of North America for the 3500/32M and
3500/33.
The review of the SFF (safe failure fraction) requirements in reference to IEC 61508, parts 1-7:2010
has shown that the Relay Controller Module achieves 60% to <90% and the Relay I/O Module
when used in the 1oo1 configuration shown in Figure 4-2 is <60%.
The component level FMEDA was carried out by TÜV Rheinland under consideration to the
requirements of IEC 61508, parts 1-7:2010. Component failure rates were based from SN 29500,
with a maximum temperature of 65°C.
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
l The relay channel must be configured for de-energize to trip.
l The safety-related circuit must be set up such that the opening of the relay contacts
activates the safety function (de-energize circuit to trip) as shown in figure 4-3.
l Average Probability of a dangerous failure on demand (PFD) < 10 E-2.
l The 3500/32M_SIL and 3500/33_SIL modules are considered to be a system operating in a
low demand mode.
l The 3500/32M_SIL and 3500/33_SIL modules have a hardware safety integrity route of 1H.
l The 3500/32M_SIL and 3500/33_SIL modules have a systematic safety Integrity route of 1S.
l The rated life time of the 3500/32M_SIL and 3500/33_SIL modules is 10 years.
l The 3500/32M_SIL and 3500/33_SIL Relay Controller Modules, and a Relay Output Modules
are Type B safety related elements with a Safe Failure Fraction (SFF) of >90%, with a
Hardware Fault Tolerance (HFT) of 0.
l The 3500/32M_SIL and 3500/33_SIL Relay Output Modules are Type A safety related
elements with a Safe Failure Fraction (SFF) of <60%, with a Hardware Fault Tolerance (HFT)
of 1 when used in a 1oo2 configuration. The signal path of an individual relay channel
contained on the Relay Output Module is a Type A safety related element with a βD =5%,
and β =10%
l The MTTR and MRT for the 3500/32M_SIL and 3500/33_SIL modules is 168 hours or 1
week**.
**MTTR and MRT were assigned as 168 hours for the purposes of generating the PFDAVE
calculation. This figure may be adjusted to suit application specific considerations as long as the
specific value is also used to adjust the PFDAVE calculation specific to the safety-related
installation.
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
As shown in the 1oo2 safety block diagram, Figure 4-4, the 3500/32M and 3500/33 Relay
Controller Modules are classified as Type B devices, and the 3500/32 and 3500/33 Relay Output
Modules are Type A. The failure rates when used in the 1oo2 configuration are shown in Table 4-
2. These failure rates are based on the 1oo2 safety block diagram in Figure 4-4.
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
Table 4 - 2: 1oo2 Configuration Failure Rates
/32M and /33 Internal 1oo2 Relay Failure Modes Controller Module Relay Module
The following values were calculated by TÜV Rheinland of North America for the 3500/32M and
3500/33.
The component level FMEDA was carried out by TÜV Rheinland under consideration to the
requirements of IEC 61508, parts 1-7:2010. Component failure rates were based from SN 29500,
with a maximum temperature of 65°C.
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
l The 3500/32M_SIL and 3500/33_SIL modules have a hardware safety integrity route of 1H.
l The 3500/32M_SIL and 3500/33_SIL modules have a systematic safety Integrity route of 1S.
l The rated life time of the 3500/32M_SIL and 3500/33_SIL modules is 10 years.
l The 3500/32M_SIL and 3500/33_SIL Relay Controller Modules are Type B safety related
elements with a Safe Failure Fraction (SFF) of 60% to <90%. The Relay Controller Module has
a βD =5%, and β =10%.
l The 3500/32M_SIL and 3500/33_SIL Relay Output Modules are Type A safety related
elements with a Safe Failure Fraction (SFF) of <60%. The Relay Output Module has a βD =5%,
and β =10%.
l The 3500/32M_SIL and 3500/33_SIL modules have a Hardware Fault Tolerance (HFT) of 1
when used in a 1oo2 configuration.
l The MTTR and MRT for the 3500/32M_SIL and 3500/33_SIL modules is 168 hours or 1
week**.
**MTTR and MRT were assigned as 168 hours for the purposes of generating the PFDAVE
calculation. This figure may be adjusted to suit application specific considerations as long as the
specific value is also used to adjust the PFDAVE calculation specific to the safety-related
installation.
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
As shown in the 1oo2 safety block diagram, Figure 4-6, the 3500/32M and 3500/33 Relay
Controller Modules are classified as Type B devices, and the 3500/32 and 3500/33 Relay Output
Modules are Type A. The failure rates when used in the 1oo2 configuration are shown in Table 4-
3. These failure rates are based on the 1oo2 safety block diagram in Figure 4-6.
/32M and /33 Internal 1oo2 Relay Failure Modes Controller Module Relay Module
The following values were calculated by TÜV Rheinland of North America for the 3500/32M and
3500/33.
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
5. Failure Modes
This section covers the failure modes of the 3500/32M_SIL and 3500/33_SIL relay modules and
their internal diagnostics system. The estimated failure rate for each of these failure modes are
given after each subsection of the corresponding failure mode.
l Failure rates are based on Siemens standard SN 29500 and the outlined maximum
temperature limits shown under the user manual of the relevant component.
l The failure rate is constant over time.
l The listed failure rates are in Failure in Time (FIT) = fit = [10-9 1/h].
When faults are detected by the module, the 3500/22M TDI records the failures in the 3500 System
Event List. Refer to the "System Event List Messages" sections in the 3500/32M operation manual
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
(Part number 129771-01) or the 3500/33 operation manual (part number 162291-01) for a full list of
failure codes that are detected by the internal diagnostic system.
The 3500 system supporting the SIL certified monitor must have a 3500/22M TDI module installed.
The Rack interface monitor performs diagnostics on all the monitors and I/O's installed in the
Rack which are separate from the individual monitor internal diagnostics. When the Rack
Interface Monitor senses a failure mode of one of the installed monitors, it changes the Rack OK
relay to the Not OK state. Refer to the FMEDA report, which is available from GE Bently Nevada
under the SIL Report, for all failure modes that drive the Rack OK Relay.
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
3500/32M_SIL and /33_SIL Relay Modules
When performed properly, you may install the 3500/32M or 3500/33 controller module into or
remove the module from the rack while power is applied to the rack, except when the rack is in a
hazardous area. A hazardous area is defined by document BS EN 60079-0:2012 as an area in
which an explosive atmosphere is present, or may be expected to be present, in quantities such
as to require special precautions for the construction, installation and use of electrical apparatus.
Refer to the Rack Installation and Maintenance Manual (part number 129766-01) for the proper
procedure.
GE Bently Nevada Recommends a periodic proof test interval of 1 year but by using the PFDAVE
equation from 61508-6 that is appropriate for the specific safety-related system, the effect on the
PFDAVE value can be determined for longer or shorter periodic proof test intervals.
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com
Artisan Technology Group is your source for quality
new and certified-used/pre-owned equipment
• FAST SHIPPING AND SERVICE CENTER REPAIRS WE BUY USED EQUIPMENT
DELIVERY Experienced engineers and technicians on staff Sell your excess, underutilized, and idle used equipment
• TENS OF THOUSANDS OF at our full-service, in-house repair center We also offer credit for buy-backs and trade-ins
IN-STOCK ITEMS www.artisantg.com/WeBuyEquipment
• EQUIPMENT DEMOS
• HUNDREDS OF InstraView REMOTE INSPECTION
SM
LOOKING FOR MORE INFORMATION?
MANUFACTURERS Remotely inspect equipment before purchasing with Visit us on the web at www.artisantg.com for more
SUPPORTED our interactive website at www.instraview.com information on price quotations, drivers, technical
• LEASING/MONTHLY specifications, manuals, and documentation
RENTALS
• ITAR CERTIFIED
SECURE ASSET SOLUTIONS
Contact us: (888) 88-SOURCE | [email protected] | www.artisantg.com