Safety / Tips and Tricks / Explosive Atmosphere
Activity 08 · Explosive Atmosphere
Emergency Isolation and Shutdown Systems
An emergency shutdown system spends essentially all of its life doing nothing, and that is precisely the problem — a safety function that is never exercised can degrade silently for years and only reveal its failure at the single moment it was installed to handle.
What emergency isolation is for
Emergency isolation systems stop the flow of flammable material into an area and remove energy sources, limiting the size of a release and removing what feeds a developing incident. The distinction from process control is important: a control system optimizes normal operation, while a safety instrumented system exists solely to bring the process to a safe state when defined limits are exceeded, and combining both functions in shared equipment means a fault in the control system can disable the protective function simultaneously.
Independence from the control system
Safety instrumented functions are generally designed to be independent of the basic process control system, so that a failure in the control layer — a failed sensor, a controller fault, a software issue — does not simultaneously remove the protective layer that exists to handle exactly that kind of failure. Where a shared sensor or shared final element is used for both purposes, the independence that protection depends on is compromised in a way that is not visible during normal operation.

Reliability of the safety function itself
The reliability required of a safety function depends on how much risk reduction it is being relied upon to provide, and the design principles for safety-related control systems set out in ISO 13849 address how that required performance is specified and achieved. A safety function assumed in a risk assessment to provide substantial risk reduction, but implemented with components and architecture that cannot actually deliver that reliability, leaves a gap between the assessed risk and the real one.
Proof testing
Because emergency systems are dormant, faults accumulate undetected between demands, and periodic proof testing — deliberately exercising the full function from sensor through logic to final element — is what reveals these dormant faults. Testing only part of the chain, such as confirming a button operates without verifying the valve actually closes, leaves the untested portion’s dormant faults exactly as hidden as before the test.
Accessibility and defeat
Emergency controls need to be reachable from where an operator would actually be during a developing incident, along a route that stays usable as the situation deteriorates, and controls positioned so they require approaching the hazard to activate provide much less than their design intent. Bypasses and overrides fitted for maintenance need documented control and removal, since a bypass left in place after maintenance disables the protective function while every indication suggests it remains available.
For the equipment this protection interfaces with, see selecting ATEX-rated electrical equipment.
Related standards
The standards below set the test methods and performance levels behind the equipment referenced in this note.
Common errors
1Sharing sensors or final elements between the control system and the safety function, compromising independence.
2Assuming a safety function delivers the risk reduction credited to it without verifying its architecture can achieve that reliability.
3Proof testing only part of the chain rather than the full function from sensor to final element.
4Leaving maintenance bypasses in place without documented control and removal.
Frequently asked questions
How does a safety instrumented system differ from process control?
Process control optimizes normal operation, while a safety instrumented system exists solely to bring the process to a safe state when defined limits are exceeded.
Why must safety functions be independent of the control system?
So a failure in the control layer does not simultaneously remove the protective layer that exists specifically to handle that kind of failure.
What does ISO 13849 contribute to emergency shutdown design?
It sets out design principles for safety-related control systems, addressing how the required reliability of a safety function is specified and achieved.
Why is proof testing necessary for emergency systems?
Because dormant systems accumulate undetected faults between demands, and deliberately exercising the full function is what reveals faults that would otherwise appear only when the system is needed.
What is wrong with testing only part of a safety function?
Confirming a button operates without verifying the valve actually closes leaves dormant faults in the untested portion exactly as hidden as before the test.
Need this as a document you can issue? The template library gives you the risk assessments, permits and inspection logs in editable form — and employer plans cover a whole team with completion records.
