Field Pocket Guide

Hazardous area, IS barriers and safety loops

Two different problems share a panel in a classified area, and they get confused with each other. One is keeping ignition energy out of the field. The other is keeping a trip function working for the day it is asked. Barrier grounding, conduit seals, area classification and SIL verification land on the same drawing, and usually on the same technician.

One idea runs under all of it. A nameplate marking is permission for a specific installation under specific conditions. It is not a property the device carries into your loop. Intrinsic safety is assessed as a system, not as a device in isolation. SIL belongs to the loop, not to the boxes in it. Get the installed condition right and the marking is true. Get it wrong and the certificate is paper in a file.

Do intrinsic safety barriers need their own dedicated IS ground, and what resistance does it have to be?

Zener barriers need a dedicated IS ground of less than 1.0 Ω back to the grounding electrode system; galvanic isolators do not.

A zener barrier does three things at once. Zener diodes clamp voltage to ground, a series resistor limits current, and a fuse protects the diodes from the clamped current. All three lean on a low-impedance path to earth. Let that path open or go high and the clamp has nowhere to put fault current; the barrier's entity parameters stop describing the circuit from that moment on. The working number is less than 1.0 Ω from the barrier ground bus to the grounding electrode system.

That number is not NEC text, and it is worth knowing where it does come from. NEC 504.50 requires associated apparatus to be grounded and 504.60 covers bonding. Neither one sets a resistance limit. The 1 Ω figure and a 12 AWG (3.3 mm²) minimum grounding conductor come from ANSI/ISA-RP12.06.01 and from the barrier manufacturer's control drawing. The control drawing is what the installation gets judged against. IEC 60079-14 sets a minimum cross-section of 4 mm² for an intrinsically safe earth conductor, which is not the same requirement: 12 AWG is 3.31 mm², so a job worked to IEC needs the larger conductor. Two conductors in parallel are common, so that pulling one does not open the path.

Measure it with a 4-wire low-resistance ohmmeter. A handheld DMM will not do. Lead and probe contact resistance on its own is commonly 0.1 Ω to 0.5 Ω, a large fraction of the budget spent before you reach the bus. And do not assume the DIN rail carries the IS ground. That is true only where the control drawing says the rail assembly is listed for that duty.

Galvanic isolators work differently. Transformer or optical isolation limits the energy instead of a shunt to ground, so there is no dedicated IS ground to install. That is most of why isolators have displaced zener barriers on new work. Some isolating modules still ask for an earth connection on their control drawing, usually a screen or functional-earth terminal. Read the drawing before deciding that terminal is decorative. Two other Article 504 items get missed on the same panel:

  • 504.30 separation — IS and non-IS conductors kept at least 50 mm (2 in.) apart, or separated by a grounded metal partition or an approved insulating partition. The 2 in. is one permitted method, not the only one.
  • 504.80 identification — labels on the raceways, cable trays and boxes are what the code requires. Light blue is permitted as a color code for IS conductors where no other conductors in the installation are light blue. It is not required, and light blue wire with no labels does not satisfy 504.80.

Why does my SIL verification come out as SIL 2 when every device in the loop is SIL 3 certified?

SIL belongs to the loop, and PFDavg adds across every element in it. The largest single contributor sets the result. That is almost always the final element.

In low demand mode the bands are SIL 1: PFDavg 10-2 to 10-1 (risk reduction factor 10 to 100), SIL 2: 10-3 to 10-2 (100 to 1,000), and SIL 3: 10-4 to 10-3 (1,000 to 10,000). "Certified to SIL 3" means the device can be used in a SIL 3 function under the conditions in its safety manual. It does not mean it delivers a SIL 3 PFD in your configuration. Here is the arithmetic on a typical 1oo1 loop proof tested once a year. The failure rates below are generic illustrative values. Replace every one of them with the numbers from your own devices' safety manuals before you quote a result:

  • Transmitter, λDU = 1 × 10-7/h (100 FIT): 1E-07 × 8,760 / 2 = 4.4 × 10-4
  • Certified logic solver: 1 × 10-5
  • Valve, actuator and solenoid, λDU = 5 × 10-7/h, 90% proof test coverage, 10-year mission: (0.9 × 5E-07 × 8,760 / 2) + (0.1 × 5E-07 × 87,600 / 2) = 2.0E-03 + 2.2E-03 = 4.2 × 10-3

Loop total 4.6 × 10-3, RRF 217. That is SIL 2, and the final element is 90% of it. Nothing was wrong with the transmitter.

Three separate barriers have to clear, and the lowest one wins. The first is the PFDavg band, which is the arithmetic above. The second is architectural. IEC 61511-1 Table 6 requires a minimum hardware fault tolerance of 1 at SIL 3, so a 1oo1 architecture cannot claim SIL 3 unless the HFT reduction allowance in clause 11.4 is justified, and that allowance carries conditions of its own: selection based on prior use, and adjustment limited to protected process-related parameters. The third is systematic capability, and it is a hard weakest-link cap. One element at SC 2 holds the whole function at SIL 2 however good the PFD arithmetic looks.

Before blaming the software, check the inputs. Proof test coverage entered as 100% when the procedure never strokes the valve to its seat. MTTR entered as 8 hours when the site's real repair time is 72. The solenoid, interposing relay, instrument air supply or trip amplifier left out of the model entirely. Generic failure data standing in for the numbers in the device's own safety manual.

Does using a SIL 3 certified logic solver mean my whole safety loop is SIL 3?

No. The logic solver is typically 10% to 15% of the loop's PFD budget. It cannot cause a shortfall that lives in the sensor or the final element, and it cannot fix one either.

A safety instrumented function is a series arrangement, and the PFDs add. A certified logic solver usually contributes 1 × 10-5 to 1 × 10-4. That is one to two orders of magnitude below the SIL 3 ceiling of 1 × 10-3. The usual budget split is sensor about 35%, logic solver 10% to 15%, final element about 50% — a rule of thumb, not a requirement in either standard. Say the valve subsystem is sitting at 4 × 10-3. Trading a SIL 2 logic solver for a SIL 3 logic solver moves the loop total by less than 1 × 10-4, about two percent. The shortfall does not live there.

The certificate is conditional, and the conditions live in the safety manual rather than on the certificate. A stated proof test interval and a specific proof test procedure. A maximum MTTR. An ambient temperature limit. Which I/O modules are covered, whether outputs are de-energize-to-trip, whether output line monitoring is enabled. Break one of those and the certified failure rates no longer describe your installation. Systematic capability caps the function separately: every element has to sit at or above the target, so an SC 2 sensor with an SC 3 logic solver gives an SC 2 function.

The application program is yours, not the vendor's. IEC 61511-1 clause 12 covers how it gets developed. A certified logic solver running unverified logic is not a certified safety function. Cause-and-effect verification, bypass management and testing after change are part of the claim.

What happens to my SIL rating if I extend the proof test interval from 1 year to 3 years?

The periodically tested part of the undetected dangerous contribution triples. That typically halves the risk reduction factor, and it can cost you the SIL band.

For a 1oo1 element with perfect testing, PFDavg ≈ λDU × TI / 2. Going from 8,760 h to 26,280 h multiplies that term by three. Take the loop above. At one year it totaled 4.6 × 10-3, RRF 217. At three years the transmitter goes to 1.3 × 10-3, the valve subsystem to 8.1 × 10-3, and the loop totals 9.4 × 10-3 at RRF 106. Still inside SIL 2. But the SIL 2 limit is 1 × 10-2, which leaves the function 6% from being a SIL 1 loop with a SIL 2 label on the drawing.

Imperfect proof testing changes the shape of that. With coverage below 100% the model is PFDavg ≈ PTC × λDU × TI/2 + (1 − PTC) × λDU × LT/2, where LT is mission time. Only the first term triples. The second is set by mission time and does not move with your interval at all. Once it dominates, stretching the interval adds risk and buys little, and shortening it helps about as little. The answer there is overhaul or replacement, not more testing.

Two credits get taken that should not be. A partial stroke test is not a proof test. Typical PST coverage is 60% to 70% of a valve's dangerous undetected failures; a full stroke to seat with a leakage check is more like 90% or better. The other is transmitter self-diagnostics, which do not test the impulse line, the manifold, or the tap. A plugged tap is a dangerous undetected failure, and only an applied-pressure proof test finds it.

Changing the interval is not a maintenance decision. It changes the safety requirements specification, it requires the SIL verification to be re-run, and under OSHA PSM it is a management of change item under 29 CFR 1910.119(l). Editing the frequency field in the CMMS accomplishes none of that.

What is the difference between intrinsically safe and explosion proof?

Intrinsic safety prevents ignition by limiting the energy in the field circuit; explosion proof accepts that ignition may occur inside the enclosure and contains it.

Intrinsic safety caps voltage, current and stored energy so the worst-case spark or surface temperature cannot ignite the gas group, in normal operation and under specified faults. Ex ia is safe with two countable faults and is accepted in Zone 0. Ex ib tolerates one fault and is Zone 1. Ex ic is Zone 2 with no fault applied. That ia/ib/ic split is Zone marking. Under the Division system the governing text is NEC Article 504 and the apparatus is listed for Class I Division 1 or Division 2. Explosion proof, called flameproof (Ex d) outside North America, is a heavy enclosure with machined flame paths that cool escaping combustion products below the ignition temperature of the surrounding atmosphere.

At the panel, the maintenance difference is the one that matters. An IS loop can be worked live in the classified area — landing a lead, connecting a communicator — because the method itself does not require a hot work permit. Two conditions come with that. The test instrument has to be certified for the area or covered by the control drawing; an ordinary DMM or communicator is not IS apparatus, and connecting one defeats the certification for as long as it hangs on the loop. Site procedure can also require a permit no matter what the method allows. An Ex d enclosure is safe closed and correctly assembled, and only then. Opening it live needs a gas test and a permit. The flame path is defeated by a missing bolt, a painted or corroded mating surface, or fewer than five threads fully engaged at a conduit entry (NEC 500.8(E)); factory-threaded NPT entries are permitted at 4-1/2 threads.

IS costs you power. A common 28 V, 300 Ω zener barrier has entity parameters around Uo 28 V, Io 93 mA, Po 0.65 W. Those are worst-case maximums, not simultaneous output: Po = Uo × Io / 4. Day to day, the number that bites is the series resistance. 300 Ω at 22 mA is 6.6 V gone before the transmitter sees anything, on top of the drop across a 250 Ω sense resistor. That budget runs a 4-20 mA transmitter. It will not run a heater, a motor, or most solenoids, which is why sensors are usually IS and final elements are usually Ex d on the same skid.

Intrinsic safety is assessed as a system, so both ends and the cable have to be checked against the control drawing:

  • Voc (Uo) ≤ Vmax (Ui)
  • Isc (Io) ≤ Imax (Ii)
  • Po ≤ Pi
  • Ca (Co) ≥ Ci + Ccable
  • La (Lo) ≥ Li + Lcable

Where cable data is unknown, IEC 60079-14 permits 200 pF/m and 1 µH/m as defaults. On a 300 m run that is 60 nF — enough to exceed Ca on some barriers with no device connected at all. Neither method is safer than the other. They fail in different ways, and that is what should drive the choice.

Do I still need a conduit seal within 18 inches of an explosion proof enclosure?

Yes, in Class I Division 1, unless the enclosure is marked to say a seal is not required. NEC 501.15(A)(1) requires the seal within 450 mm (18 in.) of each entry into an explosionproof enclosure containing arcing or high-temperature parts.

What is inside is the trigger: switches, circuit breakers, fuses, relays, resistors, anything that can produce arcs, sparks or high temperatures. Between the seal and the enclosure you are allowed explosionproof unions, couplings, reducers, elbows and capped elbows no larger than the trade size of the conduit, and nothing else. A second trigger has nothing to do with arcing. 501.15(A)(2) requires a seal within 450 mm (18 in.) at every entry of trade size 2 or larger into an enclosure housing terminals, splices or taps.

The exception people miss is printed on the nameplate. Many field instruments are marked "factory sealed," "seal not required," or equivalent, and where the enclosure carries that marking no additional seal is needed at that entry. Two limits on it. A factory seal does not satisfy a boundary seal, so if that entry is also where the run leaves the classified location, the boundary seal is still owed. And the marking exception carries a trade size limit in the code text — read the section instead of assuming it covers every entry on the device. Division 2 is narrower. 501.15(B)(1) requires a seal only where conduit enters an enclosure that is required to be explosionproof, same 18 in. limit. Where the enclosure is not required to be explosionproof, no seal is required at it.

Boundary seals are a separate requirement, and they get confused with the 18 in. rule constantly. A seal is required where a conduit run leaves a Division 1 location, and where a run passes from a Division 2 location into an unclassified location. Either may sit on either side of the boundary within 3.05 m (10 ft), with no coupling, box or fitting other than a listed reducer between the seal and the boundary. The Division 2 boundary seal has a real exception. Unbroken metal conduit that passes completely through the Division 2 location, with no fittings within 300 mm (12 in.) of each boundary and both terminations in unclassified locations, does not have to be sealed.

Numbers for the pour itself. Compound thickness at least the trade size of the fitting, never less than 16 mm (5/8 in.). Conductor fill no more than 25% of the cross-sectional area of rigid metal conduit of the same trade size, unless the fitting is approved for more. No splices or taps inside a sealing fitting. Pack the fiber dam first. A seal poured without a dam runs down the conduit and cures into a plug that looks finished and seals nothing. Intrinsically safe circuits fall under NEC 504.70: seals where the location requires them, but an IS seal does not have to be explosionproof.

What is the difference between Class I Division 2 and Zone 2?

The two describe nearly the same exposure. Division 2 is the lower half of a two-level scheme; Zone 2 is the bottom of a three-level one. The gas groups, markings and permitted protection methods do not interchange.

The Division scheme (NEC Articles 500-504) has two levels. Division 1 is where the atmosphere is present under normal operation. Division 2 is where it shows up only under abnormal conditions. The Zone scheme (NEC Article 505 for gas, IEC 60079-10-1) has three: Zone 0 (continuous or long periods), Zone 1 (likely in normal operation), and Zone 2 (not likely, and short-lived if it happens). The hour bands people attach to those — more than 1,000 h/yr, 10 to 1,000 h/yr, and under 10 h/yr — are common practice guidance, not NEC or IEC text. Do not quote them to an AHJ as code. Class I Division 1 ≈ Zone 0 plus Zone 1. Class I Division 2 ≈ Zone 2, and that pair is the closest thing to a one-to-one match the two systems have.

Gas groups do not map by letter. This is where the wrong device gets ordered. Division Group A (acetylene) and Group B (hydrogen) both map to Zone Group IIC, though hydrogen service is sometimes covered by an IIB+H₂ marking, which is hydrogen without acetylene. Group C (ethylene) maps to IIB. Group D (propane, and most general hydrocarbon service) maps to IIA. IIC is the most severe group. That runs backwards from what people expect, A being first in the alphabet.

Temperature classes share endpoints without being identical. Both systems run T1 450 °C down to T6 85 °C. The Division system carries subdivisions the Zone system does not have: T2A 280 °C, T2B 260 °C, T2C 230 °C, T2D 215 °C, T3A 180 °C, T3B 165 °C, T3C 160 °C, T4A 120 °C. A Division nameplate marked T3B has no Zone equivalent finer than T3.

NEC 505.9(C) permits equipment listed for Class I Division 1 in Zone 1 or Zone 2, and equipment listed for Class I Division 2 in Zone 2, provided gas group and temperature class match. The reverse is not a blanket permission. Zone-marked equipment going into a Division-classified area needs AHJ acceptance. The practical reason to use Zone at all: increased safety (Ex e) and non-sparking (Ex ec / Ex nA) have no Division equivalent, so a Zone 1 area can take an Ex e terminal box where a Division 1 area would need Ex d. An area is classified under one scheme or the other, never both. Whichever it is, the classification has to be documented and in the hands of the people who design, install and maintain the equipment.

What is the difference between IEC 61508 and IEC 61511?

IEC 61508 is the standard a device manufacturer certifies against; IEC 61511 is the standard an owner, engineering firm and maintenance organization work to when applying those devices in a process plant.

IEC 61508 is the generic functional safety standard for electrical, electronic and programmable electronic safety-related systems, any industry, 7 parts. It governs device design: failure rate analysis, safe failure fraction, diagnostic coverage, systematic capability, software development rigor. A "SIL 3 certified transmitter" is certified against IEC 61508-2 for its hardware and IEC 61508-3 for its embedded software. IEC 61511 is the process sector application standard, 3 parts, second edition 2016. It covers the plant safety lifecycle end to end: hazard and risk assessment, SIL allocation, the safety requirements specification, design and engineering, installation and commissioning, validation, operation, proof testing, management of change, and decommissioning.

In the United States, ANSI/ISA 61511-1-2018 adopts IEC 61511-1:2016. The older ANSI/ISA-84.00.01-2004 mirrored the first edition and carried a grandfather clause for existing installations. OSHA has treated ISA 84 as a recognized and generally accepted good engineering practice under the PSM standard's process safety information clause, 29 CFR 1910.119(d)(3)(ii). The rule text does not name the standard. The RAGAGEP obligation does the work.

Device selection is where the two meet. IEC 61511-1 clause 11.5 gives two routes: a device certified to IEC 61508, or a device justified by prior use with documented operating experience in comparable service. Prior use is legitimate. It is not a shortcut — it requires records of hours in service, failure history, and the same operating environment. Write the trip logic yourself and you are in IEC 61511-1 clause 12 (application program), not IEC 61508-3. Limited variability and full variability languages carry different requirements there.

What this means at the panel: nothing you buy makes you compliant. Compliance with 61511 is documents, competency records, proof test records and change control. A certificate on the transmitter is one line in that file.

When this page runs out

This page stops where field work stops. Area classification drawings do not get written at a panel. Creating or revising one is a process safety engineer working from API RP 500 or API RP 505 with the AHJ. A SIL target comes out of a LOPA with operations and process engineering in the room, and no arithmetic on this page substitutes for that determination. A device certificate, a certificate review or a signed functional safety assessment comes from a certification body such as TÜV or exida. Whether an existing installation complies with the code as installed is the AHJ's call, not a consultant's. Bridges Industrial will say so when the answer is someone else.

Reference material, not a site-specific engineering recommendation. Verify against your own procedures, permits, and the manual for the device in hand.