For energy producers, redundancy is often treated as a cornerstone of process safety. Add a second transmitter, provide a backup signal, install another relay or send the measurement to a safety PLC, and the system should theoretically be better protected.
But redundancy alone does not necessarily provide independence.
If two protective devices depend on the same logic solver, power source, sensing technology, wiring path or other common infrastructure, a single problem can potentially affect both. This is the concern behind common-cause, common-mode and dependent failures—and it is why functional safety design increasingly looks beyond simply duplicating instrumentation.
For oil and gas facilities operating compressors, pumps, separators, pressure vessels, fired equipment and other critical assets, the more useful question is not simply, “Do we have a backup?”
It is:
“If the primary system fails, is the protection we are relying on actually capable of acting independently?”
Functional Safety Is About the Entire Loop
IEC 61511 provides the framework for safety instrumented systems (SIS) in the process industries, covering their specification, design, installation, operation and maintenance. A Safety Instrumented Function (SIF) encompasses the devices required to perform the safety function—from the sensor through the logic and ultimately to the final element that places or maintains the process in a safe state.
That distinction matters.
Installing a SIL 2-certified transmitter does not, by itself, make a safety function SIL 2.
The complete SIF has to be evaluated. Factors such as architecture, probability of failure on demand (PFD), proof-test interval and effectiveness, diagnostics, repair time, common-cause factors and the reliability of the final element all contribute to the achieved safety integrity of the function.
United Electric Controls makes this point directly in the safety documentation for its ONE Series Safety Transmitter: the achieved SIL of the complete SIF must be verified by the system designer, considering the architecture and reliability of all components involved.
That is an important principle for any energy facility reviewing a shutdown system during a new project, expansion or turnaround:
Functional safety is an engineered system, not a certification printed on one instrument.

Redundancy, Diversity and Independence Are Different Things
These terms are sometimes used interchangeably, but they address different risks.
Redundancy provides another means of performing the same function. Two pressure transmitters instead of one, for example, can improve tolerance to an individual device failure.
Diversity reduces the likelihood that identical technologies or designs will fail in the same way. Different sensing, processing or switching methods can help address common-mode failures that simple duplication may not.
Independence means that the protective function is sufficiently separated from the initiating event and other protection layers so that failure of one does not compromise the other.
Diagnostics address another problem entirely: hidden or latent failures. A device that continually checks its own health can identify certain failures before the instrument is actually called upon to perform its safety function.
Good safety architecture considers all four.
For example, two identical transmitters connected to the same PLC may provide redundancy against some random hardware failures, but they can still share a dependency on the PLC, its power, software, I/O or communications infrastructure.
Depending on the risk identified by the facility’s hazard analysis, greater separation may be appropriate.
Taking Some of the Safety Decision Closer to the Process
One approach is to give the field instrument the ability to initiate a protective action without requiring the central PLC or DCS to make the trip decision.
United Electric Controls’ ONE Series Safety Transmitter is an example of this architecture.
The device combines pressure, differential pressure or temperature measurement with a 4–20 mA analog output, onboard logic, diagnostics and a programmable Safety Relay Output. The analog signal can continue back to the PLC or DCS for process monitoring, while the safety relay can be configured to act directly on a final element or shutdown circuit when a defined trip condition is reached.
Consider a high-pressure application on rotating equipment.
The control system may continuously monitor discharge pressure through the transmitter’s analog output. Under normal conditions, the PLC or VFD uses that information for operation and control.
At a predetermined high-pressure threshold, however, the transmitter’s onboard safety relay can provide a separate trip path rather than depending entirely on the PLC to receive the analog measurement, interpret it correctly, execute the logic and initiate the shutdown.
That does not make a PLC or safety PLC unnecessary. Far from it. There are many applications where a dedicated safety PLC and conventional transmitter architecture is exactly the right solution.
What the field-based approach provides is another architecture for engineers to consider when greater separation, simpler shutdown logic or reduced system complexity is beneficial.
A Practical Energy Application: Pump Protection
A UE application involving progressive cavity pump protection provides a useful example.
In the original installation, a 4–20 mA transmitter provided a signal to the variable frequency drive controlling the pump. The operator also required a redundant overpressure shutdown in case the VFD failed to react to the condition.
That secondary protection required an external power supply, relay and enclosure in addition to the transmitter.
The ONE Series Safety Transmitter allowed the analog signal to continue to the VFD while its integrated safety relay provided the separate shutdown action. This eliminated the external relay and power-supply arrangement and reduced the number of components required to perform the protective function.
The broader lesson is not that fewer components are always better.
It is that every additional component creates another potential failure point, maintenance requirement, wiring connection and item that must be considered during testing and troubleshooting.
For remote wellsites, compressor stations and other energy installations where space, infrastructure and field maintenance can be challenging, simplifying the architecture without compromising the required risk reduction can be valuable.
Diagnostics Matter Because Dangerous Failures Are Not Always Visible
A protective device may spend years monitoring a process without ever being required to initiate an emergency shutdown.
That creates an obvious problem: how do you know it will work when it is finally needed?
Automatic diagnostics can help identify certain internal failures between scheduled proof tests.
The ONE Series Safety Transmitter uses redundant and diverse internal processing and performs automatic fault diagnostics. UE’s current product information specifies a Safe Failure Fraction (SFF) of up to 98.8%, while its exida FMEDA identifies a worst-case internal fault detection time of six seconds.
For an energy operator, the more important takeaway is not simply the percentage.
Rapid fault detection can reduce the amount of time a protective function remains unknowingly impaired.
Diagnostics can also provide information locally and remotely, allowing operations or maintenance personnel to identify an instrument problem rather than discovering it during a demand or scheduled test.
However, automatic diagnostics should not be confused with eliminating proof testing. Proof-test requirements, intervals and procedures remain part of the overall functional safety lifecycle and should be determined from the SIF design, safety requirements and applicable equipment safety manuals.
Be Careful When Calling Something an “Independent Protection Layer”
There is another important distinction when considering this type of architecture.
Sending an analog signal to a PLC while also using a transmitter’s onboard relay gives the designer different signal and shutdown paths. That can reduce dependence on the central control system.
It does not automatically mean that two independent protection layers can be credited in a Layer of Protection Analysis (LOPA).
The Center for Chemical Process Safety defines an Independent Protection Layer (IPL) as a device, system or action capable of preventing a scenario from reaching its undesired consequence independently of the initiating event and other protection layers. Independence is only one of several requirements; functionality, integrity, reliability, validation, maintenance, auditability, access security and management of change also have to be considered.
That means the architecture must be examined as a system.
Shared process connections, utilities, final elements, maintenance practices or other common dependencies can affect whether protection layers are sufficiently independent to receive separate risk-reduction credit.
This is why the HAZOP, LOPA and SIF design process remain essential regardless of how capable an individual instrument may be.
Questions Worth Asking at Your Next Shutdown or Turnaround
When reviewing critical pressure and temperature trips, energy producers may want to ask:
- Where are our common dependencies? Look beyond the transmitter to power, process connections, I/O, logic solvers, wiring, communications and final elements.
- Are redundant devices truly diverse? Two identical devices can protect against some individual failures while remaining susceptible to the same systematic or environmental problem.
- What happens if the PLC, DCS or VFD becomes unavailable? Determine whether the required protective action can still occur.
- How quickly are instrument faults detected and communicated? A failure that remains hidden for weeks or months represents a different risk than one detected automatically.
- What is our proof-test strategy? Confirm intervals, test coverage, bypass procedures and documentation rather than relying solely on self-diagnostics.
- Have we verified the complete SIF? SIL certification of an individual component does not establish the SIL of the complete safety function.
- Can the architecture be simplified? Fewer relays, power supplies, enclosures, wiring connections and interfaces may reduce maintenance requirements and potential failure points—but only when the resulting system still satisfies the required safety function.
- Are the proposed protection layers genuinely independent? Any IPL credit should be supported by the facility’s risk analysis rather than assumed from the number of devices or outputs installed.
Designing for Both Safety and Availability
Energy producers face a continual balancing act. Shutdown systems must act reliably when dangerous conditions develop, but nuisance trips and unnecessary complexity can also have significant operational and financial consequences.
The objective should not be to add instrumentation simply for the sake of redundancy.
It should be to understand the failure modes that matter, determine the risk reduction required, and select an architecture that provides the appropriate combination of reliability, diversity, independence, diagnostics and maintainability.
For some applications, that will continue to mean a conventional transmitter and dedicated safety PLC. For others—particularly pressure or temperature shutdown applications where direct field-level action is desirable—a safety transmitter with integrated logic and relay capability may provide an effective alternative.
United Electric Controls’ ONE Series Safety Transmitter gives engineers another option when evaluating these architectures, with SIL 2 certification, SIL 3 capability, onboard diagnostics, analog process measurement and a direct safety relay function within a single field device.
The most important question, however, remains bigger than the instrument:
If the process reaches a dangerous condition, have we designed the complete protection system so that it will respond as intended—even when something else has already failed?
Westech Industrial works with Canadian energy producers on pressure and temperature instrumentation, alarm and shutdown applications and functional safety solutions. For more information on the United Electric Controls ONE Series Safety Transmitter or to discuss an application, contact the Westech Industrial team at [email protected], visit our website at https://westech-ind.com or call us today at 1-800-912-9262.
Share This:





CDN NEWS |
US NEWS


























DIGGING DEEPER: Why Canadian Activists View LNG Development as Their Next Major Target