3500 - Proximitor and Seismic Monitor
3500 - Proximitor and Seismic Monitor
3500 - Proximitor and Seismic Monitor
Prox/Seismic Monitor
SIL2 Safety Manual
Bently Nevada* Asset Condition Monitoring
Document: 115M9608
Rev. A
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
Copyright 2016 - 2018 Baker Hughes, a GE company, LLC ("BHGE")
All rights reserved.
The information contained in this document is the property of BHGE and its affiliates; and is
subject to change without prior notice. It is being supplied as a service to our customers and
may not be altered or its content repackaged without the express written consent of BHGE.
* Denotes a trademark of Bently Nevada, LLC, a wholly owned subsidiary of Baker Hughes, a
GE company.
Bently Nevada, Proximitor, Velomitor
All product and company names are trademarks of their respective holders. Use of the
trademark does not imply any affiliation with or endorsement by the respective holders.
The information published in this document is offered to you by BHGE in consideration of its ongoing sales
and service relationship with your organization. However, since the operation of your plant involves many
factors not within our knowledge, and since operation of the plant is in your control, ultimate responsibility
for its continuing successful operation rests with you, BHGE specifically disclaims any responsibility for
liability based on claims for damage of any type, i.e., direct, consequential or special that may be alleged to
have been incurred as result of applying this information regardless of whether it is claimed that BHGE is
strictly liable, in breach of contract, in breach of warranty, negligent, or is in other respects responsible for
any alleged injury or damage sustained by your organization as a result of applying this information. This
document is furnished to customers solely to assist in the installation, testing, operation and/or
maintenance of the equipment described. BHGE retains all rights to any intellectual property that may be
contained in this document.
Contact Information
When you cannot reach your local representative, use the following contact information to
reach us:
115M9608 Rev. A ii
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
Additional Information
NOTE
This manual does not contain all the information required to operate and
maintain the product. Refer to the following manuals for other required
information.
Contents
1. General Safety 1
1.1 Product Disposal Statement 1
2. Purpose 2
2.1 Abbreviations 3
2.2 IEC 61508-2 Annex D Requirements References 5
2.3 References 7
3. Hardware 8
3.1 Rack Interface Module 9
3.2 System Power Supplies 9
3.3 Monitors 9
3.4 Relay Modules 10
3.5 3500/40_SIL Setup and Hardware 11
3.6 3500/42_SIL and Setup and Hardware 14
4. Constraints and SIL Requirements 18
4.1 Who Should Commission and Maintain SIL Monitors? 18
4.2 SIL Requirements 18
5. Functional Specifications 21
5.1 Systematic Capability 23
5.2 Architectural and Random Constraints 23
5.3 3500/40_SIL Architectural Constraints 24
5.4 3500/42_SIL Architectural Constraints 28
6. Failure Modes 33
6.1 Failure Modes of the Modules 33
6.2 Failure Modes Not Detected by Internal Diagnostics 33
6.3 Failure Modes Detected by Internal Diagnostics 35
6.4 Failure Modes of the Diagnostic System 35
6.5 External Diagnostics 36
7. Periodic Proof Test 37
7.1 How to Choose a Periodic Proof Test Interval 37
7.2 Periodic Proof Test Guide 37
115M9608 Rev. A iv
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
1. General Safety
115M9608 Rev. A 1
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
2. Purpose
This safety manual contains information about the 3500/40M Proximitor and 3500/42M
Prox/Seismic Monitor. These monitors are certified components that can be used in a
functional safety system.
This safety manual is required for the integration of the 3500/40_SIL and 3500/42_SIL into a
safety related system in compliance with IEC 61508-2 Annex D.
The manual focuses on the functional safety use case. It augments the datasheets and user
manuals of the 3500/40_SIL Proximitor Monitor and 3500/42_SIL Prox/Seismic Monitor.
115M9608 Rev. A 2
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
2.1 Abbreviations
Abbreviation Description
ARM Armature
DC Diagnostic coverage
FS Functional Safety
NC Normally Closed
NE Normally Energized
NO Normally Open
SC Systematic coverage
115M9608 Rev. A 3
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
Abbreviation Description
115M9608 Rev. A 4
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
D2.1 c)
Constraints on the use of the compliant item an
See "Constraints and SIL Requirements" on page 18.
assumptions on which analysis of the behavior or
failure rates of the item are based
D2.2 a)
The failure modes of the compliant item due to
See "Failure Modes Not Detected by Internal
random hardware failures that result in a failure of the
Diagnostics" on page 33.
function and are not detected by diagnostics internal
to the compliant item
D2.2 b)
See "Functional Specifications" on page 21.
For every failure mode in a), an estimated failure rate
D2.2 c)
The failure modes of the compliant item due to
See "Failure Modes Not Detected by Internal
random hardware failures, that result in a failure of
Diagnostics" on page 33.
the function and that are detected by
diagnostics internal to the compliant item
D2.2 d)
The failure modes of the diagnostics, internal to the
See "Failure Modes of the Diagnostic System" on page
compliant item due to random hardware failures, that
35.
result in a failure of the diagnostics
to detect failures of the function
D2.2 f)
For every failure mode in section c) detected by See "How to Choose a Periodic Proof Test Interval" on
diagnostics internal to the compliant item, the page 37.
diagnostic test interval
115M9608 Rev. A 5
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
IEC 61508 Requirements
Reference
(Part 2 Annex D)
D2.2 h)
See "Periodic Proof Test Guide" on page 37.
Any periodic proof test and maintenance requirements
D2.2 i)
For those failure modes, in respect of a specified
function, that are capable of being detected by
See "External Diagnostics" on page 36.
external diagnostics, sufficient information shall be
provided to facilitate the development of an external
diagnostics capability
D.2.3 a)
The systematic capability of the complaint item or that See "Systematic Capability" on page 23.
part of the element that provides the function
D.2.3 b)
Any instructions or constraints relating to the
application of the compliant item, relevant to the See "SIL Requirements" on page 18.
function, that should be observed in order to prevent
systematic failures of the compliant item
115M9608 Rev. A 6
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
2.3 References
IEC 61508, Parts 1 - 7:2010
Functional safety of electrical, electronic and programmable electronic safety-related systems
API Standard 670, 5th edition, November 2014, Machinery Protection Systems
TÜV Certificate and Report: 968/EZ 310.03/18
Schematic Diagram 3500/42M & 40 Board, Dwg. No: 184574
Schematic Diagram Consolidated I/O Dwg. No: 184140
Schematic Diagram I/O with internal Barrier, Dwg Number 184608
Statement of Compliance, BN26744C-18
115M9608 Rev. A 7
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
3. Hardware
The 3500 system is a rack based machinery protection and condition monitoring platform that
provides information to assess and protect the mechanical condition of rotating and
reciprocating machinery. The system continuously measures and monitors various protection
and supervisory parameters. It provides important information for early identification of
machinery problems such as imbalance, misalignment, shaft crack and bearing failures.
The 3500 system has different slots where a system monitor and various other modules can
be installed. The monitor modules accept inputs from transducers, condition the signals to
provide various measurements, and compare the conditioned signals with user-programmable
alarms. Alarm statuses are generated and broadcast onto the system alarming networks.
In SIL-certified systems, the safety function is supported by one or more SIL-certified monitors.
These monitors supply alarm and status information to one or more relay modules. The relay
modules consume the information to resolve machine trip logic and drive their relay outputs.
The 3500 system also has relay modules that observe the alarming networks and drive relays
based on user programmable relay logic. The relay outputs are the monitoring system’s safety
output function. The relay outputs are used in the greater Safety Instrumented Function (SIF)
to bring the process to a safe state.
The core 3500 system consists of the following components:
l A rack chassis
l A backplane circuit board
l Redundant power supplies
l A rack interface module
The balance of the rack is made up of a series of monitoring slots. The minimum rack includes
seven slots. The full-size rack has 14 slots. The system performs machinery monitoring
including SIL-certified functionality.
115M9608 Rev. A 8
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
architecture and communicate with each other. The monitors and relay modules cannot be
directly interfaced to external devices except as depicted in the 3500 safety element
architecture.
The monitors and relay modules are certified individually. They can be used for many safety
instrumented function applications.
3.3 Monitors
The 3500 monitors accept inputs from transducers in the field and condition signals into
measurements useful for machinery protection. The monitors constantly compare the
measurements against configured alarm setpoints to generate alarm and channel OK statuses.
These statuses are broadcast onto system alarming networks.
A monitor’s safety function is the broadcast alarm status and validity states on the alarming
network. All available software configuration options and logic parameters are valid for
supporting the safety function without restriction. These parameters can be selected and
arranged to suit application requirements.
The monitors are installed in any of the monitoring slots available in the system. Bently Nevada
offers numerous SIL-certified monitors for the 3500 system, each providing different
115M9608 Rev. A 9
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
machinery protection capabilities. Different certified monitors can be combined and
duplicated to achieve the required safety instrumented functionality.
A 3500 monitor is composed of a main card and an I/O module. The I/O module interfaces with
the transducers producing the machinery-related signals and conditions the signals for the
monitor main card. The main card generates measurements from transducer information as
well as alarm and status messages.
115M9608 Rev. A 10
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
115M9608 Rev. A 11
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
115M9608 Rev. A 12
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
SIL-Certified 3500/40_SIL I/O Modules
The following table lists SIL-certified 3500/40_SIL I/O modules:
The following table lists the spare parts for the 3500/40_SIL Proximitor Monitor:
3500/40_SIL 3500/40_SIL Proximitor
176449-01 SIL GA 5.2
Monitor
115M9608 Rev. A 13
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
115M9608 Rev. A 14
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
115M9608 Rev. A 15
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
SIL-Certified 3500/42_SIL I/O Modules
The following table lists SIL-certified 3500/42_SIL I/O modules:
05 - I/O Module
with internal barriers,
internal terminations,
2 x Prox/Accel and
2 x Velomitor
06 - I/O Module
with internal barriers,
internal terminations,
and 4 x Velomitor
The following table lists the spare parts for the 3500/42_SIL Prox/ Seismic Monitor:
Prox/Seismic I/O
128229-01 SIL Module with Internal H N/A
Terminations
Prox/Seismic I/O
128240-01 SIL Module with External G N/A
Terminations
115M9608 Rev. A 16
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
Orderable Spare Spare Part
Description Hardware Revision Firmware Revision
Part Number Number
Barriers,
Internal Terminations,
2 x Prox/Accel and
2 x Velomitor
Prox/Velomitor I/O
140471-01 SIL Module with Internal D N/A
Terminations
115M9608 Rev. A 17
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
115M9608 Rev. A 18
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
Hardware Requirements
n The 3500/40_SIL Proximitor Monitor or 3500/42_SIL Prox/Seismic Monitor must be
installed in a 3500 Rack with the following requirements:
l The rack must have a 3500/22M Transient Data Interface Module.
l The rack must contain at least one SIL-certified relay module.
n The 3500 System with the 3500/40_SIL Proximitor Monitor or 3500/42_SIL Prox/Seismic
Monitor must be supported by redundant 3500/15 power supplies.
n You must set the system program keyswitch on the 3500/22M TDI to RUN after
configuring the 3500/40_SIL Proximitor Monitor or 3500/42_SIL Prox/Seismic Monitor
and commissioning the system.
n After removing any components that are part of the critical safety path in the 3500
Monitoring System, you must perform a full-proof test of the SIL system.
n An automated system must continuously monitor the System OK relay on the 3500/22M
TDI to detect system faults.
n The 3500/40_SIL Proximitor Monitor or 3500/42_SIL Prox/Seismic Monitor operate in low
demand mode.
Software Requirements
n You must configure the relay card used with the 3500/40_SIL Proximitor Monitor or
3500/42_SIL Prox/Seismic Monitor per the applicable relay card SIL safety manual.
n You can configure the monitors using the available options and parameters. These values
are valid for the safety function without restriction.
n You must perform the validation tests outlined in the following manuals:
l The 3500/40M Monitor Manual (Document 143488).
115M9608 Rev. A 19
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
Recommendations
We recommend having Bently Nevada Services inspect your 3500 Monitoring System when
validating and commissioning the components to ensure proper installation, configuration and
usage.
115M9608 Rev. A 20
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
5. Functional Specifications
The 3500/40_SIL Proximitor Monitor and the 3500/42_SIL Prox/Seismic Monitor condition
transducer inputs to create a measured value and compare the measured value to the
configured alarm set points. As a result of this comparison, the monitors generate alarm
statuses and broadcast them onto the system alarming networks. The safety function is the
monitor's broadcasting of the alarm status and validity states on the alarming network.
The test institute has assessed the associated safety-related elements of Proximitors and
system relay modules such as 3500/32M_SIL and documented the results in test reports.
Due to the recent need for RoHS compliancy, the 3500 series of monitor modules and I/O
modules have undergone internal changes to the circuit boards. RoHS compliant boards are
BLUE and RoHS non-compliant boards are GREEN. There are also differences in how the
monitor modules and I/O modules are labeled. Both options are shown below, and are pictured
with the faceplate to the left.
115M9608 Rev. A 21
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
115M9608 Rev. A 22
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
n The 3500/40_SIL Proximitor Monitor and the 3500/42_SIL Prox/Seismic Monitor are
systems operating in a low demand mode.
n The 3500/40_SIL Proximitor Monitor and the 3500/42_SIL Prox/Seismic Monitor have a
hardware safety integrity route of 1H.
n The 3500/40_SIL Proximitor Monitor and the 3500/42_SIL Prox/Seismic Monitor have a
systematic safety Integrity route of 1S.
n The rated life time of the 3500/40_SIL Proximitor Monitor and the 3500/42_SIL
Prox/Seismic Monitor is 10 years.
115M9608 Rev. A 23
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
n The 3500/40_SIL Proximitor Monitor and the 3500/42_SIL Prox/Seismic Monitor are Type
B safety-related elements with a Safe Failure (SFF) of 60% to < 90%.
n The 3500/40_SIL Proximitor Monitor and the 3500/42_SIL Prox/Seismic Monitor
monitors have a Hardware Fault Tolerance (HFT) of zero when used in a one-out-of-one
(1oo1) configuration.
n For the 3500/40_SIL Proximitor Monitor and the 3500/42_SIL Prox/Seismic Monitor ,
MTTR and MRT are 168 hours or one week1.
1. MTTR and MRT were assigned as 168 hours for the purposes of generating the PFDavg
calculation. You may adjust this figure to suit your application's needs as long as the
same value is also used to adjust the PFDavg calculation specific to the safety-related
installation.
115M9608 Rev. A 24
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
3500/40_SIL-A01-BXX
The 3500/40_SIL-A01-BXX consists of the 3500/40_SIL main card and the Proximitor I/O
module with Internal Terminations. The BXX option represents the available approvals for the
3500/40_SIL. See " 3500/40_SIL Setup and Hardware" on page 11.
3500/40_SIL-A01-BXX RoHS
The following table lists the 3500/40_SIL-A01-BXX failure rates for Non-RoHS Compliant SIL-
rated modules:
115M9608 Rev. A 25
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
3500/40_SIL-A02-BXX
The 3500/40_SIL-A02-BXX consists of the 3500/40_SIL main card and the Proximitor I/O
module with External Terminations. The BXX option represents the available approvals for the
3500/40_SIL. See " 3500/40_SIL Setup and Hardware" on page 11.
The following table lists the 3500/40_SIL-A02-BXX Non-RoHS Compliant failure rates:
3500/40_SIL-A02-BB Non-RoHS
115M9608 Rev. A 26
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
3500/40_SIL-A03-BXX
The 3500/40_SIL-A03-BXX consists of the 3500/40_SIL main card and the Proximitor I/O
module with internal barriers. The BXX option represents the available approvals for the
3500/40_SIL. See " 3500/40_SIL Setup and Hardware" on page 11.
3500/40_SIL-A03-BXX RoHS
The following table lists the 3500/40_SIL-A03-BXX failure rates for Non-RoHS Compliant SIL-
rated modules:
3500/40_SIL-A03-BXX Non-RoHS
115M9608 Rev. A 27
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
l A04-BXX
l A05-BXX
l A06-BXX
See "3500/42_SIL with Internal Barrier I/O" on page 31.
115M9608 Rev. A 28
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
3500/42_SIL-A01-BXX
The 3500/42_SIL-A01-BXX consists of the 3500/42_SIL main card and the Proximitor I/O
module with Internal Terminations. The BXX option represents the available approvals for the
3500/42_SIL. See "3500/42_SIL and Setup and Hardware" on page 14.
3500/42_SIL-A01-BXX RoHS
The following table lists the 3500/42_SIL-A01-BXX failure rates for Non-RoHS Compliant SIL-
rated modules:
3500/42_SIL-A01-BXX Non-RoHS
115M9608 Rev. A 29
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
3500/42_SIL-A02-BXX
The 3500/42_SIL-A02-BXX consists of the 3500/42_SIL main card and the Proximitor I/O
module with External Terminations. The BXX option represents the available approvals for the
3500/42_SIL. See "3500/42_SIL and Setup and Hardware" on page 14.
3500/42_SIL-A02-BXX RoHS
The following table lists the 3500/42_SIL-A02-BXX failure rates for Non-RoHS Compliant SIL-
rated modules:
3500/42_SIL-A02-BXX Non-RoHS
115M9608 Rev. A 30
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
3500/42_SIL with Internal Barrier I/O
The 3500/42_SIL Prox/Seismic Monitor with Internal Barriers consists of the 3500/42_SIL main
card and one I/O module with internal Barriers. The following options are available:
n A04 provides 4 x Prox/Accel channels
n A05 provides 2 x Prox and 2 x Velomitor channels
n A06 provides 4 x Velomitor channels
The BXX option represents the available approvals for the 3500/42_SIL . See "3500/42_SIL and
Setup and Hardware" on page 14.
Figure 5 - 10: 3500/42_SIL Prox/Seismic Monitor with Internal Barrier I/O Safety Block
Diagram for Options A04, A05 and A06
The following tables list the 3500/42_SIL Prox/Seismic Monitor with Barrier I/O failure rates
(RoHS Compliant) for options A04, A05 and A06:
115M9608 Rev. A 31
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
3500/42_SIL - A06-BXX RoHS
The following tables list the 3500/42_SIL Prox/Seismic Monitor with Barrier I/O failure rates
(Non-RoHS Compliant) for options A04, A05 and A06:
115M9608 Rev. A 32
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
6. Failure Modes
NOTE
This chapter covers the failure modes of the 3500/40_SIL Proximitor Monitor and the
3500/42_SIL Prox/Seismic Monitor and their internal diagnostics system. Subsequent sections
list the estimated failure rate for each failure mode.
The failure rates are driven by the following assumptions:
n Failure rates are based on Siemens standard SN 29500 at the outlined maximum
temperature limits shown under the user manual of the relevant component.
n The failure rate is constant over time.
n The listed failure rates are in Failures in Time (FIT).
For the failure rates of the relay or a sensor, refer to their SIL manuals.
The 3500/40_SIL Proximitor and the 3500/42_SIL monitors are set up for a single monitor
channel in a 1oo1 configuration. This configuration provides a hardware fault tolerance of zero.
These monitors are Type B safety related elements or subsystems.
115M9608 Rev. A 33
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
n The Rack OK relay does not change state.
115M9608 Rev. A 34
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
When a fault prevents the monitor from generating alarming messages, the system relay
module detects the loss of alarming communication and responds by adjusting its alarm drive
logic per its application-specific configuration.
When the monitor or the system relay module detects a fault, the 3500/22M TDI records the
failure in the 3500 System Event List. For a list of failure codes detected by the internal
diagnostic system, refer to the following sources:
n The 3500/40M Operation and Maintenance Manual (Document 143488)
n The 3500/42M Operation and Maintenance Manual (Document 143489)
System Outputs
When the internal diagnostic system of the 3500/40_SIL Proximitor and 3500/42_SIL
Prox/Seismic detects a failure mode, the state of the Rack OK relay changes to NOT OK.
115M9608 Rev. A 35
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
SIL certification report, which includes the required information from the FMEDA.
115M9608 Rev. A 36
3500/40M Proximitor and 3500/42M Prox/Seismic Monitor
SIL2 Safety Manual
115M9608 Rev. A 37