Vectus Ltd. 2008 Copyright Page 1 Safety Process in Vectus ’ PRT Project Inge Alme: Safety Manager Jörgen Gustafsson: CTO.

Slides:



Advertisements
Similar presentations
Ways to Improve the Hazard Management Process
Advertisements

Integra Consult A/S Safety Assessment. Integra Consult A/S SAFETY ASSESSMENT Objective Objective –Demonstrate that an acceptable level of safety will.
A Joint Code of Practice Objectives and Summary Presentation
1 Maintenance management. 2 Maintenance Management Loop.
Contractor Safety Management
Software Quality Assurance (SQA). Recap SQA goal, attributes and metrics SQA plan Formal Technical Review (FTR) Statistical SQA – Six Sigma – Identifying.
5 december 2011 Living Probabilistic Asset Management Dr.ir. J.A. van den Bogaard.
Vancouver, October 08th 2013 DB Systemtechnik GmbH Marc Geisler The challenge of transforming a rule-based system into a risk-based culture on an example.
SAE AS9100 Quality Systems - Aerospace Model for Quality Assurance
Scandpower AS P.O. Box 3, N-2027 Kjeller, Norway Risk management in the Scandinavian railway industry Karl Ove Ingebrigtsen Vice president Sweden Norway.
1 Certification Chapter 14, Storey. 2 Topics  What is certification?  Various forms of certification  The process of system certification (the planning.
Chapter 11: Testing The dynamic verification of the behavior of a program on a finite set of test cases, suitable selected from the usually infinite execution.
Quality Risk Management ICH Q9 Annex I: Methods & Tools
Seafood HACCP Alliance for Training and Education Chapter 10 Principle 6: Establish Verification Procedures.
Fundamentals of ISO.
Introduction to Software Quality Assurance (SQA)
© Palaniappan R Kannan PMP.,CFSE 1 IEC Standard – What is it? IEC is a Standard for the functional safety of Electric / Electronic / Programmable.
Basics of OHSAS Occupational Health & Safety Management System
ISO Tor Stålhane IDI / NTNU. What is ISO ISO 9001 was developed for the production industry but has a rather general structure ISO describes.
Commissioning of Fire Protection and Life Safety Systems Presented by: Charles Kilfoil Bechtel National Waste Treatment Plant Richland WA.
Software Engineering 2003 Jyrki Nummenmaa 1 REQUIREMENT SPECIFICATION Today: Requirements Specification Requirements tell us what the system should.
SE-02 SOFTWARE ENGINEERING LECTURE 3 Today: Requirements Analysis Requirements tell us what the system should do - not how it should do it. Requirements.
VTT-STUK assessment method for safety evaluation of safety-critical computer based systems - application in BE-SECBS project.
WHAT IS SYSTEM SAFETY? The field of safety analysis in which systems are evaluated using a number of different techniques to improve safety. There are.
Product Development Chapter 6. Definitions needed: Verification: The process of evaluating compliance to regulations, standards, or specifications.
Jörg R. Müller, Technical University of Braunschweig
Software Engineering – University of Tampere, CS DepartmentJyrki Nummenmaa REQUIREMENT SPECIFICATION Today: Requirements Specification.
Essentials of Machine Safety Standards in Perspective.
Are You Ready for an SIS? What to do before starting on your SIS…and after it’s installed March 24, 2009.
Safety-Critical Systems T Ilkka Herttua. Safety Context Diagram HUMANPROCESS SYSTEM - Hardware - Software - Operating Rules.
Main Requirements on Different Stages of the Licensing Process for New Nuclear Facilities Module 4.5/1 Design Geoff Vaughan University of Central Lancashire,
Safety-Critical Systems 7 Summary T V - Lifecycle model System Acceptance System Integration & Test Module Integration & Test Requirements Analysis.
1 ACSF Test Procedure Draft proposal – For discussion OICA and CLEPA proposal for the IG Group ACSF Tokyo, 2015, June Informal Document ACSF
Use of Fieldbus in safety related systems, an evaluation study of WorldFIP according to proven-in-use concept of IEC Jean Pierre Froidevaux WorldFIP.
Company for Urban Innovative Transport (CUIT) 19/12/2007 Request for proposal.
6 July 2000CSAM Team1 CERN Safety Alarm Monitoring Invitation to Tender Strategy CERN Safety Alarm System Supervisory Board 3st meeting CSAM project team.
Validation | Slide 1 of 27 August 2006 Validation Supplementary Training Modules on Good Manufacturing Practice WHO Technical Report Series, No. 937, 2006.
Over View of CENELC Standards for Signalling Applications
SAFETY MANAGEMENT SYSTEM IN TURKISH STATE RAILWAYS (TCDD)
RLV Reliability Analysis Guidelines Terry Hardy AST-300/Systems Engineering and Training Division October 26, 2004.
Risk and Safety in the Transport Sector (RISIT) - a research programme covering road-, sea-, air- and the railway sector Finn H. Amundsen, Head of programme.
Ensuring the Safety of Future Developments
Erman Taşkın. Information security aspects of business continuity management Objective: To counteract interruptions to business activities and to protect.
1 A Seminar On Pharmaceutical Outsourcing A Seminar On Pharmaceutical Outsourcing.
Monitoring, review and audit.
Swedish Risk Management System Internal management and control Aiming to Transport Administration with reasonable certainty to.
SwCDR (Peer) Review 1 UCB MAVEN Particles and Fields Flight Software Critical Design Review Peter R. Harvey.
© SBB I ETCS The Concept of the SWISS ETCS Safety Case The safety case as a basis for achieving the ETCS operating approval in Switzerland.
HIGH SPEED RAIL ASSESSMENT NORGE
About Us! Rob StockhamBA IEng MIEE General Manager Moore Industries-Europe, Inc MemberIEE Honorary Secretary ISA England Institute of Directors DirectorThe.
IEEE Required – End-of-life processing requirements For all end of life equipment collected by manufacturer under :  The manufacturer.
Software Testing. SE, Testing, Hans van Vliet, © Nasty question  Suppose you are being asked to lead the team to test the software that controls.
Process Safety Management Soft Skills Programme Nexus Alliance Ltd.
Use and Conduct of Safety Analysis IAEA Training Course on Safety Assessment of NPPs to Assist Decission Making Workshop Information IAEA Workshop Lecturer.
1 Address: UIC Safety Database (SDB) System and Results.
Introduction to Safety Engineering for Safety-Critical Systems Seo Ryong Koo Dept. of Nuclear and Quantum Engineering KAIST Lab. Seminar.
World Health Organization
OH&S Plant Obligations make
Regulation (EU) No 2015/1136 on CSM Design Targets (CSM-DT)
Session II: System authority for ERTMS 4RP Trackside approval
Software Requirements
Decree of the Ministry of Interior 3rd August 2015 The “so called” Italian Fire Prevention Code - IFC: S7 – Fire Detection and Alarm Systems Piergiacomo.
Air Carrier Continuing Analysis and Surveillance System (CASS)
Quality Management Systems – Requirements
BU IS GIG Chemical, Oil & Gas
Quantitative Risk Assessment
Submitted by the experts of OICA
New Assessment & Test Methods
PSS verification and validation
ESHAC #8 Safety Readiness Review Thomas Hansson, ESH
Presentation transcript:

Vectus Ltd Copyright Page 1 Safety Process in Vectus ’ PRT Project Inge Alme: Safety Manager Jörgen Gustafsson: CTO

Vectus Ltd Copyright Page 2 Overview of the process including Requirements Criteria Analyses Documentation

Vectus Ltd Copyright Page 3 Law: Rail vehicles, track and other systems have to be approved by the Rail Agency before putting into service. Regulation: A safety case for the system is required for an approval. The regulations are according to the process in the standard EN (Demonstration of Reliability, Availability Maintainability and Safety) Manufacturer or operator/owner shall apply for approval and provide all documents for the safety case. There has to be an operator also approved by the Rail Agency. An approved vehicle is allowed to be put into service by an operator with a safety certificate. (There also has to be an infrastructure owner) Laws and regulations in Sweden 3

Vectus Ltd Copyright Page 4 Approval requirements Safety process / safety case (described in more detail) Compliance with international standards agreed to be applicable for various aspects of the system, e.g. noise, EMC, electrical installations, doors. Fulfillment of certain agreed functionality if not suitably covered by any international standards. Various documentation, e.g. descriptions, validation plan, maintenance plan and manuals, operating procedures etc.

Vectus Ltd Copyright Page 5 Safety Acceptance Criteria For the generic PRT system: Maximum 0.3 fatalities per billion person kilometers for passengers in PRT system. A fatality risk of maximum 1 · per year for the most exposed third person For each subsystem: A single failure shall not lead to undesirable events, loss of lives or serious injuries. If such failures are identified, they must be controlled through either maintenance or operational actions For future changes in concept: Changes shall as a minimum not increase the risks in the system. If any increasing risk is identified, necessary mitigations should be implemented according to the ALARP-principle In railway, metro, trams etc. there are often specific requirements for individual parts of the complete system, usually derived over time based on historic performance. Distribution of levels for individual parts are not always optimized for best overall performance, and are sometimes based on certain operating conditions (e.g. certain size of a system, certain technical solution etc). We wanted to have criteria which are independent of system size and technical solutions, hence a new approach with a generic target has been set.

Vectus Ltd Copyright Page 6 Safety criteria, perspective Third person risk (our criterium: 1 · per year for the most exposed third person) The same as the average annual risk for a Swede to die in a railway level crossing accident About the same level as the average risk of dying struck by lightning A factor 40 less risk than the average risk of dying in a fire Many oil & gas installations use the criterium 1 · for the most exposed third person  The risk level for third person is very low compared to other “ involuntarily ” risks (note that our criterium is for the most exposed person compared to the average person in above examples) Passenger risk (our criterium: 0.3 fatalities per billion person kilometers) Swedish rail statistics fluctuate between 0.3 and 0.6 in the period from The average number for railway systems in EU countries + Switzerland and Norway was 0.58 (in 2000) The corresponding number for bus passengers in Norway was 0.65 ( ) The corresponding number for airplanes in Norway was 0.20 ( )

Vectus Ltd Copyright Page 7 Safety Acceptance Criteria Risk matrix for the test site

Vectus Ltd Copyright Page 8 Safety process, requirements 1.Concept with intended operation and preliminary safety targets 2.Specification with technical description, safety plan and safety requirements 3.Design with standards, risk analysis and safety measurements 4.Validation with test reports, manuals, main- tenance plans and future modification process 5.Safety case, independent assessors report and infrastructure manager track admittance 6.Approval for operation with conditions

Vectus Ltd Copyright Page 9 Basis for Safety Process EN / IEC (RAMS-standard) IEC for electronic safety systems (this standard is more generic than EN and EN that is used for traditional railway systems) The Swedish Railway Agency has required a third party assessment of the Safety Instrumented System (SIS) of the PRT system, i.e. a third party verification of the compliance with IEC 61508

Vectus Ltd Copyright Page 10 Safety Organization in the Project Vectus Swedish Rail Agency SD Station and Foundation SD = Safety Documentation SD CabinSD Track and ChassisSD Control System incl. SIS NoventusWGHTDISkanska Safety Management - Safety Plan - Safety requirements - Safety ReportCase - Hazard Log - Test Program - Manuals - Etc. Scandpower (Norway) 3rd party assessor for control system RequirementsProve fulfillment of requirements Application Contract Reporting 3rd party assessor for track Contract Reporting Jacobs Babtie (England)

Vectus Ltd Copyright Page 11 Safety Process in the Project Concept risk analysis Safety Plan Safety requirments Start up meeting 3rd Party Assessment 3rd Party Work Shops (5 in total) Presentation of 3rd Party Assessment Report to SRA Preliminary Hazard Assessment Site Risk Analysis Safety Analyses of subsystems (7 in total) Safety Analysis for Safety Instr. System QRA Safety Case Hazard Log Safety Audit

Vectus Ltd Copyright Page 12 Methods used in safety analyses FMECA = Failure Mode, Effects and Criticality Analysis (done for all parts of the safety instrumented system and control system) FTA = Fault Tree Analysis (done for all parts of the safety instrumented system and relevant parts of control system) ETA = Event Tree Analysis (done for all identified accident scenarios) Analysis of safety critical functions (done for all subsystems) The Risk Graph method (done to identify the right SIL-requirements)

Vectus Ltd Copyright Page 13 Main results of analyses The passenger risk is quantified to fatalities per billion person kilometres, which is well below the acceptance criterion of 0.3 fatalities per billion person kilometres The fatality frequency for the most exposed third person, i.e. a person who is not choosing to be exposed to the risk of the PRT system, is calculated to 1.9 · per year. This is also well below the acceptance criterion of maximum 1 · All subsystems are analysed with regard to the single failure principle and a number of safety critical maintenance activities are identified and implemented

Vectus Ltd Copyright Page 14 Safety case trivia More than 1200 pages in total. The hazard log contains over 200 items that are followed up with actions. The quantitative risk analysis includes 78 different sensitivity calculations to check out the criticality of different input factors. This is the first time a quantitative risk analysis is performed for a total railway system in Sweden.

Vectus Ltd Copyright Page 15 Requirements for Third Party Assessment of SIS Formal requirements: IEC 61508, Chapter 1 –Documentation –Management of Functional Safety –QA, incl. verification and validation activities Hardware requirements: IEC 61508, Chapter 2 –Hardware specification and development –Avoidance and control of systematic failures –Reliability of components (SIL): Probability of Failure on Demand (PFD) –Structure/topology of components (redundancy) –Avoidance and control of systematic failures –Diversity and independence –Testing Software requirements: IEC 61508, Chapter 3 –Software specification and development –Software implementation –Testing

Vectus Ltd Copyright Page 16 Focus of third party assessment FSA Part 1 FSA Part 2

Vectus Ltd Copyright Page 17 Results – Third Party Assessment The results from the Third Party Assessment are documented in two reports: Functional Safety Assessment (FSA) for the Control System of the PRT System Functional Safety Assessment (FSA) - On-site Observation for the PRT System

Vectus Ltd Copyright Page 18 Approval status VECTUS PRT safety case for the generic application, i.e. over and beyond what is requried for the test track as such, will be accepted with the completion of the ongoing testing activities.

Vectus Ltd Copyright Page