āThere must be a defined operator response to correct the condition, and the action must be for the short term.ā ISA 18 Co-chair Nicholas Sands on the essential qualifications of a process alarm.
When process-manufacturing facilities started changing their control rooms from analog panels to modern DCS displays, plants justified the new control systems by reducing the number of operators by about 75%. āWe knew they added a lot of capability and flexibility,ā said Nicholas Sands, senior manufacturing technology fellow, global alarm management leader, and process control engineer, DuPont Safety and Construction. He is also co-chair of the ISA 18 standard committee and a 2019 inductee into the Control Process Automation Hall of Fame.
āWe threw together the new HMI [human-machine interface] to look like the old panel control rooms,ā Sands explained in a presentation at this weekās Honeywell Users Group Americas 2019 in Dallas. āBut we gave the operator more tags and data points and alarms. It used to be $5,000 to add an alarm on the panel board. Then, with the new system, they didnāt cost anything.ā
Managers, engineers and operators went alarm-crazy. āIf we werenāt using all the alarms, we werenāt getting our moneyās worth out of the DCS,ā Sands reminisced. And soon, HMIs became overrun with so many alarms that operators couldnāt even see the ones that required immediate corrective action. Eventually, a procedure and a lifecycle map were needed to streamline the alarms and develop a continuous-improvement process for review.
āThe reason for alarm management is to improve safety and business performance,ā explained Sands. āWhen I started with DuPont, weād have a high alarm and a low alarm when a pump turned on or off.ā The alarm would go on when the tank hit the high level, and another would activate when it hit the low level, which just added to the onslaught of unnecessary alarms. āGet rid of the alarms you donāt need, so you can see the ones you do,ā said Sands. This ultimately became part of the audit function, one of the 10 steps in the alarm-management lifecycle that is part of ISA 18.2.
Standard procedure
According to ISA 18.2, an alarm is āan audible and/or visible means of indicating to the operator an equipment malfunction, process deviation or abnormal condition requiring a timely response.ā
The alarm must indicate a problem, not a normal process condition, explained Sands. āThere must be a defined operator response to correct the condition, and the action must be for the short term,ā he said, āin minutes, not days.ā
As co-chair of the ISA 18 committee, Sands led the group that developed the alarm management lifecycle standard for new facilities and existing plants. It builds on the works of the Abnormal Situation Management Consortium and the Engineering Equipment and Materials Users Association. The alarm-management lifecycle is a continuous-improvement process, designed to be a best practice for control system maintenance.
It comprises 10 steps, three of which can be points of entry. The philosophy step is a good place to start for new facilities or systems. However, brownfield systems can begin with the monitoring-and-assessment step or the audit step.
-
Alarm-management philosophy is the guide for all alarm-management activities at a site. āA written philosophy is necessary to maintain an alarm system over time,ā explained Sands. āPhilosophy doesnāt have to be your first step, but itās usually a good place to start.ā Philosophy identifies what you want to achieve. It includes definitions, performance goals, roles, responsibilities and methods for rationalization activities. Sands recommended eight to 10 pages for the philosophy document.
-
Identification is the step where you insert your method for finding out if and where you want an alarm, determining whether itās a quality, safety, environmental or regulatory reason.
-
Rationalization is when you decide if it really is going to be an alarm. āIn our results, about 50% of the alarms went away,ā said Sands. āAnd 80% of our priorities changed.ā Rationalization includes classification, prioritization and documentation. Sandsā words of advice: Be careful not to jump ahead and do the detailed design during the rationalization.
-
Detailed design has three parts: basic alarm design, which includes alarm types, dead bands and delays; HMI design, which includes indications and summaries; and advanced alarm design, which includes designed suppression.
-
Implementation is the process of putting the alarm or alarm system into operation. āTraining and testing are key activities,ā said Sands. āSafety systems are mostly testing and some training. Alarm priorities are flippedāmostly training and some testing.ā
-
Operation is when the alarm is in service and performing its function. āShelving and removal from service are key processes to define for operations,ā explained Sands. āYou can use shelving to track out-of-service and in-service. Shelving is for the operator and by the operator.ā
-
Maintenance is when the alarm is out of service for repair, replacement or testing. āTesting and return to service are key activities in maintenance,ā he said. āYou can track how long it takes, and you can return it to service after the repair.ā
-
Monitoring and assessment are the tracking of the alarm system performance vs. objectives in the philosophy. āAn unmonitored alarm system is almost always broken,ā said Sands. āMonitoring is a key requirement of ISA 18.2. That requirement has changed what every control system supplier offers. The data tells you what needs to be fixed.ā
-
Management of change administers the authorization for modifications to the alarm system. āEach change is reviewed and approved prior to implementation. Changes should follow the steps of the lifecycle,ā he explained. āOnce weāve done steps 1-8, we donāt want to let that go uncontrolled. The data will drive that continuous-improvement loop.ā
-
Audit is the periodic check that the alarm system is meeting the objectives and procedures are followed. āAudit drives changes to the alarm philosophy,ā said Sands, bringing the lifecycle full circle. āCompare the performance metrics to the targets.ā
About the Author
Mike Bacidore
Mike Bacidore

Leaders relevant to this article:

