View Categories

Tier 3 Metrics

Tier 3 metrics provide insight into challenges to safety systems before those challenges develop into higher-consequence process safety events. Within Safety Lifecycle Manager (SLM), Tier 3 metrics use operational event data to help users understand the performance of independent protection layers across a facility.

SLM can compare actual operating performance against defined design criteria for measures such as demand rate, failed-to-operate rate, failed-on-test rate, spurious trip rate and availability. The resulting information can then be viewed through scorecards, summaries and bad-actor dashboards.

This guide explains what Tier 3 indicators represent, how SLM calculates and displays them, what information is required before the dashboards can populate, and how operational performance can be connected back to PHA and LOPA risk information.

What Are Tier 3 Metrics?

Tier 3 metrics are process safety performance indicators focused on challenges to safety systems. They can provide earlier visibility of weaknesses or adverse performance that may warrant investigation before a more significant process safety event occurs.

Examples relevant to the SLM workflow include demands on safety functions, bypasses, failed tests, failures to operate and spurious trips. These events provide evidence about how protection layers are performing when challenged or tested.

The American Petroleum Institute describes Tier 3 indicators within API Recommended Practice 754 as challenges to safety systems and notes that these indicators provide an opportunity to identify and correct weaknesses within the safety system. API identifies Tier 3 and Tier 4 indicators as being intended primarily for internal company use. The API RP 754 information page provides authoritative background on this process safety performance-indicator framework.

Within SLM, the concept is applied to operational information associated with independent protection layers such as safety instrumented functions, HIPS, alarms, BPCS functions, fire and gas functions and interlocks.

Tier 3 Metrics Available in SLM

SLM tracks several measures that allow actual IPL performance to be compared with the applicable design criteria.

  • Demand rate
  • Failed-to-operate rate
  • Failed-on-test rate
  • Spurious trip rate
  • Availability percentage

These measures can be displayed through the Tier 3 Scorecard at site, unit and function levels. At the broader levels, users can compare multiple IPL types and identify functions whose actual performance is approaching or exceeding the established criteria.

The scorecard uses visual status indicators to distinguish performance relative to those thresholds. Users can also review supporting information such as the designated demand rate, number of process demands and accumulated time in service to understand the basis of an actual in-service demand rate.

This provides a connection between the high-level performance indicator and the operating information used to calculate it.

Tier 3 Scorecards, Summaries and Bad Actors

SLM provides several views of Tier 3 information rather than relying on a single dashboard.

The Tier 3 Scorecard organizes performance across different IPL types and displays the applicable measures for individual functions. This enables users to compare performance across safety instrumented functions, alarms, HIPS, BPCS functions, fire and gas functions and interlocks where applicable.

The Bad Actors view takes a more targeted approach by identifying functions that are failing to meet the relevant performance criteria. Users can investigate measures such as demand rate, availability, bypass information and failed tests to identify functions requiring further attention.

Tier 3 Data provides another scorecard-style view organized around the metrics themselves, while the Tier 3 Summary gives a higher-level picture of performance across the facility.

At an individual function level, users can also review Tier 3 information specifically for that function. This allows teams to move from a facility-wide indication of performance down to the particular protection layer that produced the result.

What Is Required to Calculate Tier 3 Metrics?

Tier 3 metrics do not begin populating simply because a safety function exists in SLM. Several pieces of lifecycle information must first be established so that operational performance has an appropriate design basis and time reference.

The first requirement is the applicable design threshold. For safety instrumented functions, the demonstrated workflow maintains values within the Safety Requirements Specification for measures such as design demand rate, maximum failed-on-test rate, maximum failed-to-operate rate and maximum spurious trip rate.

These values provide the criteria against which actual operational performance can subsequently be compared.

The second requirement is commissioning. Functions and devices need an appropriate commissioned service status so that SLM has a defined starting point for their time in service.

The third requirement is operational event information. Demands, bypasses, failed tests and other applicable events provide the operating evidence used by the calculations. Applicable events must also complete the configured finalization or approval process before they affect the scorecards.

Together, these elements establish the basic chain: design criteria define expected performance, commissioning starts the operating clock, and approved events provide the actual performance information.

Setting Design Thresholds for Performance Monitoring

Design thresholds provide the reference against which operating results are evaluated. Without an established expectation, an observed demand or failure rate has limited context.

Within the SLM workflow demonstrated in the training, the relevant criteria for a SIF are maintained as part of its Safety Requirements Specification information. These include design demand rate and maximum rates for failed tests, failures to operate and spurious trips.

SLM can then use these values as thresholds when evaluating operational information in the Operate & Maintain module.

The source of a design criterion may also be connected with earlier lifecycle studies. For example, where the SLM LOPA module is being used, an expected demand rate may originate from information associated with a barrier in the LOPA analysis.

This creates an important lifecycle connection: the performance expected during design can later be compared with the experience observed after the protection layer enters service.

Commissioning and Starting the Time-in-Service Clock

Time in service is fundamental to several performance calculations. SLM therefore needs to know when the function or device actually entered operation rather than simply when its record was created.

Commissioning establishes this starting point. Within the Operate & Maintain workflow, a Service Status Change Event can be created for a function and its associated instruments, recording the commissioned status and effective date.

That date starts the time-in-service clock used when operational events are compared with the applicable SRS criteria.

The Service Status Change Event guide explains how commissioning and other lifecycle status changes are recorded for functions and devices.

Accurate commissioning information is therefore an essential prerequisite for meaningful rate-based performance monitoring. A count of events without a reliable operating-time basis does not provide the same insight as a rate calculated over a known period of service.

How Operational Events Populate Tier 3 Metrics

Once design thresholds have been established and the applicable functions and devices are commissioned, operational events provide the next part of the calculation.

Events such as demands, bypasses and failed tests are captured through the Operate & Maintain workflow. However, creating an event does not necessarily cause the dashboard to update immediately.

The event must first complete the finalization or approval process configured for the applicable site or unit. Where an approval workflow is required, a user with the appropriate authority reviews and approves the event.

Until that process is complete, the event does not affect the applicable Tier 3 calculations. Once finalized or approved, SLM automatically takes the event into consideration when updating the relevant scorecards.

The Logging Events guide covers the related workflows for recording demands, tests, bypasses, faults and other operational events as well as the approval process that allows applicable information to contribute to dashboards and reports.

Connecting Operational Performance to LOPA and PHA Risk

One of the broader uses of this operational information is connecting actual protection-layer performance with the hazardous scenarios for which those protection layers were credited.

During LOPA, independent protection layers can be applied to scenarios to reduce the estimated risk. Once those protection layers are operating in the facility, their actual performance provides another perspective on the assumptions made during the risk assessment.

In the SLM workflow demonstrated in the training, LOPA scenarios can be displayed on a dynamic risk matrix together with the barriers associated with each scenario. Where those barriers are connected to applicable SIF or IPL objects, their operational status can also be represented.

For example, the demonstrated view can highlight a function when it is in bypass or when it is failing an applicable performance measure such as availability, demand rate, failed-on-test rate, failed-to-operate rate or spurious trip rate.

This allows users to consider a protection layer’s current operating performance in the context of the hazardous scenario against which it was credited. It does not replace the underlying PHA or LOPA, but it can provide additional operational visibility into the performance of the safeguards represented in those studies.

Using Tier 3 Metrics for Ongoing Performance Review

Tier 3 metrics are most valuable when they are used to investigate performance rather than viewed only as dashboard indicators.

A facility-level summary can identify where performance is outside the expected criteria. Bad-actor views can narrow that information to particular functions, while function-level information and underlying event records can help users investigate what contributed to the result.

This creates a path from a high-level indicator back to the operational evidence. A demand-rate warning, for example, can be considered alongside the number of actual demands and the function’s accumulated time in service rather than being interpreted without context.

Similarly, failed-test or failed-to-operate information can direct attention toward functions whose observed performance warrants engineering review.

Other operational information can complement this analysis. The Failure Rate Library provides a separate view of equipment reliability and prior-use information accumulated from devices operating in service.

Managing Tier 3 Metrics with Safety Lifecycle Manager

Tier 3 metrics in SLM connect information generated at different stages of the safety lifecycle. Design criteria establish expected performance, commissioning establishes when operation begins, and approved operational events provide evidence of actual performance.

SLM then uses this information to populate scorecards and dashboards at function, unit and site levels. Users can review individual IPL performance, identify bad actors and examine overall facility performance against established criteria.

The MSS Safety Systems solution supports the broader management of this safety-system lifecycle information. Within the Operate & Maintain workflow covered here, Tier 3 monitoring provides a way to connect design expectations with operating experience.

By maintaining the link between requirements, service status, operational events and performance indicators, teams can investigate where actual protection-layer performance differs from its expected design basis and use that information to support ongoing lifecycle review.

Please complete the form below

Please complete the form below.

You will automatically be forwarded to a demonstration video