ESD — emergency shutdown system
≈ 21 min read · 4,214 words
ESD (Emergency Shutdown) is a high-reliability control system that automatically brings the plant to a safe state in an emergency.
It consists of field-mounted instruments (sensors, valves, trip relays), system logic that processes the incoming signals, and alarms, and it commands the equipment in accordance with the Cause & Effect chart defined for the installation. It is an independent layer of protection: it comes into action when the process moves outside its control range. Designing it is not enough: it must also be operated and checked, with a trip test, a register of the bypasses and a regular ESD audit.
Figure 1 — the ESD signal chain: the logic unit processes the signal of the sensors in accordance with the Cause & Effect chart, and through the final elements brings the system to a safe state.
Who is this for?
Section titled “Who is this for?”This article is for everyone who is responsible for the safe shutdown of a process plant or creates the conditions for it: shift and plant manager · operator · process engineer · control and instrumentation technician and maintenance staff · process safety (PSM) specialist · reliability engineer · asset team leader. Performing the trip test, recording the bypasses and handing them over shift by shift is in the hands of the people working on shift; the test cycle, the Cause & Effect logic and the ESD audit are the responsibility of the specialists and the management.
Learning objectives
Section titled “Learning objectives”After reading this article you will be able to:
- state what the ESD is, and list its main elements (sensor, logic, final element)
- place the ESD within the layers of protection, between process control, the alarm and the safety valve
- list the lifecycle phases of the ESD, and say which phase is the operator’s task
- explain what the trip test, the bypass (MOS/POS) register and the ESD audit are for
- recognize why an unrecorded or long-standing bypass is risky, and what to do about it
What is the ESD, what does it consist of, and how must it be operated?
Section titled “What is the ESD, what does it consist of, and how must it be operated?”A gas boiler shuts off the gas if the flame goes out; a kettle switches off if it boils dry. These everyday emergency shutdowns work exactly like the industrial ESD: they do not warn, they act by themselves, because there is no time to wait for someone to react.
The ESD (Emergency Shutdown) is the large-scale, high-reliability version of this principle: a system made up of field instruments, system logic and alarms, which, when the process runs away, commands the equipment into a safe state in accordance with the Cause & Effect chart. And operating it means three things: testing it regularly (trip test), recording every bypass, and auditing whether this practice is really alive.
In brief
Section titled “In brief”- What the ESD is: a high-reliability control system that brings the plant to a safe state in an emergency (shutdown, blow down, isolation).
- What it consists of: field sensors, valves, trip relays, system logic and alarms; it works in accordance with the Cause & Effect chart.
- A layer of protection: the ESD is one of the key elements of the layers of protection, the “safety layer”.
- Lifecycle: risk assessment → allocation of the functions into the layers → safety requirement → design and implementation → installation and put in operation → validation → operation and maintenance → MOC → disposal.
- Operation = checking: the reliability of the protection must be maintained by trip testing and maintenance, and every bypass must be entered into a register.
- Bypass register: who bypassed what, why and until when; when the status changes a notification goes out, and the goal is to reduce the bypasses and make them visible.
- ESD audit: it checks all ESD practices, acts as a reminder of the responsibilities, and gives management feedback for correction.
Why it matters (the stakes)
Section titled “Why it matters (the stakes)”What is at stake with the ESD depends on which step it occupies among the layers of protection, and how many steps are left below it. Normal process control keeps the parameter within the band; if it runs out, the alarm comes and the operator intervenes; the pre-trip alarm exists precisely so that the operator can take corrective action before the safety instrumented system would trip. If even that is not enough, the ESD trip brings the plant to a safe state, and only after that comes the mechanical last-resort protection, the blow down of the safety valve (PSV).
Figure 2 — the layers of protection: normal process control, alarm and pre-trip alarm, ESD trip, and finally the safety valve. The alarm set point lies below the upper trip limit, above the lower one, and below the pressure setting of the valve.
This order is not accidental but a design rule: the alarm set point should be lower than the upper trip limit of the safety function and higher than the lower limit, and also lower than the maximum pressure setting of the safety valve. If the ESD is bypassed or has not been tested for years, then one step drops out of the ladder: what would have stopped automatically until now is caught only by the operator’s attention or by the mechanical blow down.
An alarm and the operator intervention belonging to it cannot be assumed to give a risk reduction greater than a factor of ten, not even if the alarm system is rationalized and given special treatment. If the scenario calls for a greater reduction, a safety instrumented function is needed, designed in accordance with EN 61508 / 61511.
What does it consist of and how does it work?
Section titled “What does it consist of and how does it work?”The ESD basically consists of field-mounted instruments (sensors, valves and trip relays), system logic for processing the incoming signals, and alarms. The system processes the input signals and activates the outputs in accordance with the Cause & Effect chart defined for the installation. Electrical, electronic and programmable electronic systems are responsible for ensuring that machines and plants run safely and, in an emergency, shut down the facilities to a safe state. The initiating signals are both audible and visible.
The typical ESD actions (bottom of Figure 1): shutdown of part systems and equipment; isolate hydrocarbon inventories; isolate electrical equipment; prevent escalation of events; depressurize / blow down; emergency ventilation control; close watertight and fire doors.
SIS, SIF, C&E: what means what?
Section titled “SIS, SIF, C&E: what means what?”The acronyms surrounding the ESD cover three different levels. The SIS (Safety Instrumented System) is the safety instrumented system itself, the hardware and the software together. The SIF (Safety Instrumented Function) is one single, concrete safety function within it, for example “if the level indication is too high, close the feed”. And the Cause & Effect chart is the logic: which cause triggers which effect.
The operator does not see this system directly, but through the alarms. The interface between the system and the operator must be described in full, including the pre-trip alarms, the interlock alarms (the input of the function, “first fault” alarm), the shutdown alarms (the output of the function), the alarm of the override switches, the discrepancy alarm of the voting unit, and the diagnostic alarms (for example signal fault, faulty measurement). Special attention is due to the alarm that indicates that the final element did not carry out the command: the valve received the instruction, but did not close. This is one of the most important check points, because in such a case the trip has happened logically, but not physically.
The lifecycle of the ESD
Section titled “The lifecycle of the ESD”The ESD is a lifecycle process, whose phases are: risk assessment; allocation of the safety functions into the layers of protection; specification of the safety request; proposal and implementation; installation and put in operation; validation; operation and maintenance; modification through change management (MOC); and finally disposal. This is the operational mirror of the safety lifecycle: the design is the world of LOPA/SIL, while the operation and checking is the subject of this article.
Figure 3 — the nine lifecycle phases of the ESD. The dark boxes (operation and maintenance, modification) are the daily responsibility of the operating organization.
How can the reliability of the protection be maintained?
Section titled “How can the reliability of the protection be maintained?”The reliability of the protective systems and equipment (critical alarm, emergency response, etc.) must be maintained through appropriate testing and maintenance programs, including the handling of temporary disarming, overriding, bypassing or deactivation. This rests on three pillars.
Figure 4 — the operational discipline of the ESD: trip test, bypass register and ESD audit.
- Trip test — the periodic proof of the actual operation of the protective function, from the sensor through the logic to the final element (the whole loop). A local procedure must be worked out for it; electronic recording is allowed. The test is complete only if the confirmation of the execution has also happened: not only the logic released, but the final element really moved.
- Bypass (MOS/POS) register — every bypass must be recorded, and a local procedure is written for this too. The practical minimum of a usable register is four pieces of data: who bypassed what, why and until when. When the interlock status changes, a notification must be generated to those concerned. Where the status gets into the electronic log automatically from the process information system, the number of the disabled interlocks has measurably decreased.
- ESD audit — an essential part of a good ESD program: it checks all ESD practices, serves as a constant reminder of the responsibilities at every level, and gives the management the feedback needed for corrective action. In some places a separate ESD team reviews the open bypasses on a daily basis.
MOS or POS: two kinds of bypass
Section titled “MOS or POS: two kinds of bypass”There are two established kinds of bypass, and the difference is not a formality. The MOS (Maintenance Override Switch) releases the interlock for a maintenance purpose, for example while the instrument is being repaired or tested. The POS (Process Override Switch) does the same for a process reason, typically during start-up or during a defined operating state. The alarm of both switches is a safety-critical alarm with special treatment, so a stricter documentation, training, testing and auditing requirement applies to it.
The most important, easily teachable rule concerns the visibility of the bypass: if there is an activated MOS/POS switch in a group, the group must generate an alarm at least once per shift. In other words, an open bypass cannot be quietly left behind: every shift is confronted with it. Its counterpart belongs here too: the signalling alarm of the bypassed interlock must be suppressed, and a message generated only into the alarm history log, otherwise the bypass itself becomes a source of noise.
Process industry and safety context
Section titled “Process industry and safety context”The ESD is the hardest core of process safety: when every other control (normal process control, the alarm and the operator reaction) is insufficient, the ESD is the last automatic line of defence before the disaster. In the layers-of-protection model (see LOPA/SIL) the ESD is the safety layer; its reliability (its PFD) must be demonstrated in accordance with IEC 61508 / 61511, and the trip test checks exactly this assumed reliability in reality. The greatest hidden risk is the bypassed protection: a bypassed trip is an “invisibly” missing layer, which is why the bypasses must be entered into a register, reduced in number and their status made continuously visible. Together with alarm management, the ESD forms the active, instrumented part of the layers of protection.
The condition of an independent layer of protection is engineering independence. A sensor used for the alarm system must not also be used as part of the safety system (and vice versa), and safety-critical alarms with special treatment need an independent operator interface. If the same sensor gives both the alarm and the trip, then a single instrument fault takes out two “layers” at once.
The ESD as process-safety-critical equipment
Section titled “The ESD as process-safety-critical equipment”The ESD is not an operational convenience function but equipment critical from the viewpoint of process safety: the list of PS-critical assets names the instrumented safety systems (emergency shutdown, interlocks, sensors, PLC), as well as the emergency shutdown and isolation systems and the remotely operated shut-off valves. Two practical consequences follow from this. First, the PS-critical assets must be listed, the list kept up to date, and marked on the P&ID. Second, the temporary disabling of an interlock counts as a change: a record must be kept of the temporary states, their risks assessed regularly, and, depending on the level of the risk, handled in a controlled change management procedure (MOC). A bypass is therefore not a plant trifle but a state subject to recording and risk assessment.
Putting it into practice
Section titled “Putting it into practice”Introducing ESD discipline is not an IT project but the creation of a few procedures and one routine:
- Take stock of what you have. Draw up an up-to-date list of the PS-critical instrumented protections, and mark them on the P&ID.
- Write the two local procedures. One for performing the trip test, one for the register of the bypasses. Electronic recording is allowed, and is usually better as well.
- Make the status visible. A change of the interlock status should trigger an automatic notification, and an open bypass should report in at least once per shift.
- Tie it to the shift handover. Handing over and acknowledging the open bypasses should be a fixed element of the shift handover.
- Audit regularly. The ESD audit checks the practice and gives the management feedback for correction.
- Measure the trend. The number and the age of the open bypasses is the simplest, yet most telling indicator.
The shift leader takes over the shift, and on the open-bypass list of the log one item has been standing for three weeks: the interlock of a level switch was released by the instrument technician for a maintenance purpose (MOS), the repair has been done since, but nobody has put the switch back. Since the system reports the open bypass back once per shift, the item has not disappeared, only everyone has “got used to it” so far. The shift leader puts the job on the daily list, after the reset they prove the operation of the function with a trip test (including the movement of the final valve), and close the item in the register. A protective layer that had been missing for three weeks is back, in ten minutes, without any new investment.
Common mistakes
Section titled “Common mistakes”- “We design it, then we don’t test it” — without a trip test we do not know whether the protection actually works.
- Unrecorded bypass — a bypassed trip without a register entry and a notification = a hidden, missing layer.
- A long-standing bypass under the heading “temporary” — the bypass is forgotten, and the protection is missing for months.
- An ESD treated as an alarm, or the other way round — the roles of the two differ; the ESD is an automatic bringing to a safe state, not a warning.
- We test the logic, not the execution — if the valve does not move on command, the trip has happened only on paper.
- ESD modification without MOC — changing the Cause & Effect logic without controlled change management is dangerous.
- A shared sensor for the alarm and the trip — a single instrument fault takes out two layers of protection at once.
- The absence of an audit — without an ESD audit the practice slowly drifts away from the rule.
When NOT to use it? (the limits of the method)
Section titled “When NOT to use it? (the limits of the method)”The ESD is indispensable, but not every instrumented protection is an ESD, and it is not the answer to every problem:
- It is not an alarm substitute. If the right answer is an operator intervention carried out in time, then an alarm and rationalized alarm management are needed, not one more trip. Unnecessary trips cause production loss and start-up risk.
- It is not a process controller. Keeping the parameter within the band is the job of the basic process control system (BPCS); the ESD must not be used to compensate for a shortcoming of the control.
- It is not a machine protection, not a fire and gas (F&GS) and not a burner management (BMS) system. These are separate instrumented systems, with their own logic and their own requirements; the ESD does not absorb them.
- It does not solve a design fault. If the equipment regularly runs close to its limits, the answer is putting the technology or the operating limits (IOW) in order, not more frequent interlocking.
- It does not replace mechanical protection. The safety valve and the blow down are at the top of the ladder precisely because they do not depend on the electronics; the presence of the ESD is no reason to relax their sizing.
Take it home (keys)
Section titled “Take it home (keys)”- The ESD is one step on the ladder: process control, alarm and pre-trip, ESD trip, safety valve. If one step drops out, the next one carries the load.
- Designing is not enough: the reliability of the protection is kept alive by the trip test and by maintenance, not by the documentation.
- Test the execution too: without confirming that the final element carried out the command, the test is one-sided.
- Every bypass is recorded and visible: who, what, why, until when; a notification on a status change, and at least one report-back per shift.
- A bypass is a change: a temporary state, with a record and a risk assessment, and with an MOC where needed.
- Independence is not optional: a separate sensor, separate logic, a separate operator interface, otherwise there is no real layer.
- The audit closes the loop: without it the practice quietly drifts away from the rule.
Self-test
Section titled “Self-test”- Where does the ESD trip sit among the layers of protection, and where must the alarm set point fall relative to the trip limit and to the pressure setting of the safety valve?
- What is the difference between a MOS and a POS bypass, and what rule makes sure that an active bypass is not forgotten?
- Why is it not enough during the trip test to check only the release of the logic?
Answer key: 1) The ESD trip is above normal process control and above the alarm and the pre-trip alarm, and below the mechanical safety valve (PSV); the alarm set point should be below the upper trip limit, above the lower one, and below the maximum pressure setting of the valve. · 2) The MOS (Maintenance Override Switch) is an interlock release for a maintenance purpose, the POS (Process Override Switch) for a process purpose; if there is an activated MOS/POS switch in a group, the group must generate an alarm at least once per shift, so every shift is confronted with the open bypass. · 3) Because the final element can fail: it may receive the command without carrying it out. Without a test of the whole loop (sensor, logic, final element) and the confirmation of the execution, the protection works only on paper.
How does this show up in digital practice?
Section titled “How does this show up in digital practice?”The principle of ESD discipline does not stop at the interlock cabinet: the same logic is recorded automatically and becomes trackable in a digital operation. The mechanism differs, the principle is the same.
| Element | Digital implementation | Value |
|---|---|---|
| Performing the trip test | Scheduled test task with a reminder, completion proof and measurement result | The test cycle does not slip, and can be proven afterwards |
| Bypass (MOS/POS) | Interlock and override log with time stamp, owner, reason and expiry time | There is no “anonymous” bypass; the expiry forces the closure |
| Change of the interlock status | Automatic status notification to those concerned, with a log entry | A change of state of the protection does not go unnoticed |
| List of the open bypasses | A list appearing every shift, to be acknowledged at the handover | Items open for a long time stand out from the row |
| ESD modification | Change management (MOC) workflow with built-in risk assessment | The Cause & Effect logic does not change without an assessment |
| ESD audit | Searchable audit trail, corrective actions tracked as tasks | The audit finding is not lost in the minutes |
Modern digital operating systems realize the same principles as the paper interlock list and the bypass notebook: the recording of the state of the protection, the proof of the tests and the controlled tracking of the changes, only faster, retrievably and with an audit trail.
Connection to OPEREX (shift log)
Section titled “Connection to OPEREX (shift log)”The operating discipline of the ESD naturally lives in the shift log. The register of the bypasses, the changes of the interlock status and the completion of the trip tests can be recorded item by item, with a time stamp and an owner. The OPEREX shift log thus makes it visible and auditable which protective function is bypassed right now, by whom and until when, and at the shift change the outgoing shift hands over and the incoming shift acknowledges the open bypasses. This transparency directly reduces the risk of the bypassed (invisibly missing) protection, and it is the same mechanism by which the number of disabled interlocks can be reduced in plant practice.
Terminology (HU / EN)
Section titled “Terminology (HU / EN)”| Hungarian | English (canonical) | Note |
|---|---|---|
| vészleállító rendszer | Emergency Shutdown (ESD) | the layer of protection |
| biztonsági műszerezésű rendszer | Safety Instrumented System (SIS) | the wider frame of the ESD: the whole system |
| biztonsági műszerezésű funkció | Safety Instrumented Function (SIF) | one single, concrete protective function within the system |
| ok–okozat mátrix | Cause & Effect chart | the definition of the logic |
| trip-teszt | trip test / proof test | the proof of the operation |
| retesz előtti riasztás | pre-trip alarm | the operator can still intervene before the interlock |
| karbantartási reteszfeloldó kapcsoló | Maintenance Override Switch (MOS) | bypass for a maintenance purpose |
| technológiai reteszfeloldó kapcsoló | Process Override Switch (POS) | bypass for a process purpose |
| kiszakaszolás | bypass / override | the temporary disabling of the protection |
| trip relé | trip relay | the releasing element |
| alap folyamatirányító rendszer | Basic Process Control System (BPCS) | the layer of normal process control |
| biztonságos állapot | safe state | the target state of the shutdown |
What is the ESD, and what is it for?
The ESD (Emergency Shutdown) is a high-reliability control system that, in an emergency (when the process moves outside the control range), automatically brings the plant to a safe state: shutdown, blow down, isolation. Its purpose is to protect the personnel, the environment and the assets.
What is the Cause & Effect chart?
The logic definition that says which input signal (cause, e.g. high pressure) triggers which output (effect, e.g. closing a valve, shutting down a part system). The logic unit of the ESD processes the signals in accordance with this chart.
What is the difference between the SIS and the SIF?
The SIS (Safety Instrumented System) is the safety instrumented system itself: the sensors, the logic unit and the final elements together. The SIF (Safety Instrumented Function) is one single, concrete safety function within it, for example closing a given feed at high level. One system realizes several functions, and the reliability (SIL) requirement always belongs to a function.
What is the difference between a MOS and a POS bypass?
The MOS (Maintenance Override Switch) releases the interlock for a maintenance purpose, for example while the instrument is being repaired or tested; the POS (Process Override Switch) does so for a process reason, typically during start-up or during a given operating state. Both come with a safety-critical alarm with special treatment, and while active must report in again at least once per shift.
Why are a trip test and a bypass register needed?
Because the protection is worth something only if it really works when it must. The trip test proves the operation for the whole loop, including the movement of the final element; and the register makes visible which protection is bypassed right now, by whom and until when. Bypassed, unrecorded protection is the greatest hidden risk.
How does the ESD relate to LOPA/SIL?
The ESD is one active, instrumented layer of the layers of protection (LOPA); its reliability requirement (SIL/PFD) is determined in accordance with IEC 61508/61511. LOPA/SIL is the design side, “operate it and check it” is the operating side, and the trip test links the two.
Related concepts
Section titled “Related concepts”production reliability program · LOPA/SIL layers of protection · alarm management · HAZOP · management of change · operational risk assessment · integrity operating windows · shift handover
Next step
Section titled “Next step”- Size the layer: LOPA/SIL — how a protection need becomes a certified, quantified reliability requirement, and where the boundary of the safety function lies.
- Handle the change: management of change — why the temporary disabling of an interlock counts as a change, and what has to be documented for it.
- Tie it to the daily routine: shift handover and alarm management — how the open bypass and the critical alarm become a fixed agenda item of the shift.
References
Section titled “References”- IEC 61508 — Functional safety of electrical/electronic/programmable electronic safety-related systems. The general, industry-independent base standard of functional safety (the source of the safety lifecycle and of the concept of SIL).
- IEC 61511 — Functional safety: Safety instrumented systems for the process industry sector. The standard for the design, operation and periodic proof testing of safety instrumented systems in the process industry.
- IEC 62682 / ISA-18.2 — Management of Alarm Systems for the Process Industries. The standard frame for the interface between the alarm system and the safety system, and for handling the pre-trip alarm.
In practice
The register of the bypasses (MOS/POS), the changes of the interlock status and the completion of the trip tests can be recorded item by item in the shift log, with a time stamp and an owner. The OPEREX shift log thus makes it visible and auditable which protective function is bypassed right now, by whom and until when; this transparency directly reduces the risk of the bypassed (and so invisibly missing) protection.
Learn more: Shift log →