Valid

GB/T 47696-2026Proof testing of safety instrumented systems for the process industry sector (English PDF)

过程工业安全仪表系统检验测试

Open the GB/T 47696-2026 preview as PDF

Preview — first pages of GB/T 47696-2026 (full document: 64 pages)

This is a limited preview

Buy now to download the full PDF (64 pages)

Issued by

SAMR; SAC

Level / Type

National · Recommended

Issue date

May 25, 2026

Implementation date

December 1, 2026

Scope

GB/T 47696-2026 is the English-translated version of 过程工业安全仪表系统检验测试.

GB/T 47696-2026 is the Chinese national standard covering the proof test of a safety instrumented system - the periodic test that finds the dangerous undetected failures a SIS accumulates while it sits waiting, and without which its claimed safety integrity level is a calculation and nothing more. It fixes the planning, the coverage the test must achieve, the procedures for sensors, logic solvers and final elements, the intervals and the records. At 21,500 words, first edition, in force from 1 December 2026. It was issued on 25 May 2026 and takes effect on 1 December 2026, as a first edition. The document is under the responsibility of the China Machinery Industry Federation. This page is published from the official record of the 2026 edition; the clause text of a standard this recent is not yet in circulation, and the figures, limits and tables it contains are those of the document itself, delivered in full with the English translation.

Document preview — GB/T 47696-2026

National Standard of the People's Republic of China

ICS
25.040
Classification
N 10

Issued by: State Administration for Market Regulation; Standardization Administration of the PRC

Contents

  • 5 General Requirements
  • 5.2 Management Requirements
  • 5.3 Inspection and testing content and methods
  • 5.3.1 Inspection and Testing Content
  • 5.3.2 Inspection and Testing Methods
  • 6 Inspection and Testing Plan
  • 6.1 General Provisions
  • 6.2 Planning Content
  • 7 Implementation of Inspection and Testing
  • 7.1 General Requirements
  • 7.2 Test Preparation
  • 7.3 Test Execution
  • 7.3.1 Offline verification test
  • 7.3.2 Online Inspection and Testing
  • 7.3.3 Recovery of Inspection and Testing
  • 8 Inspection and Testing Analysis
  • 8.1 Test Coverage Analysis
  • 8.2 Quantitative Analysis of Failure Probability Based on Inspection and Testing
  • 8.2.2 Based on the testing coverage determined in
  • 8.3 Operational Status Analysis Based on Failure Data
  • 9 Inspection and testing report
  • 10 Inspection and Testing Rectification
  • 10.1 General Requirements
  • 10.2 Offline Inspection and Testing Rectification Requirements
  • 10.3 Rectification Requirements for Online Inspection and Testing

5 General Requirements

5.1 Purpose Inspection and testing are part of the operation and maintenance activities of SIS, and their purpose is to ensure that SIS continues to be in "like new" condition or as good as possible during its use. Approaching "new" condition. The main objectives to be achieved through SIS testing include.

a) Ensure the SIS meets the expected security integrity level by uncovering potential faults;

b) The expected SIL and its security-related parameters (e.g., PFDavg/PFH) of each SIF in the SIS are continuously met throughout the security lifecycle. Requirements of SIS security requirements specifications;

c) Evaluate the operational status of the SIS through inspection and testing, effectively collect field failure data, and provide data for the continuous and stable operation of the SIS. Support and suggestions.

5.2 Management Requirements

5.2.1 Testing and inspection consist of numerous activities involving multiple departments and roles, which should be planned and coordinated throughout the SIS lifecycle. The investigation should establish written procedures to regulate the organization, teams, personnel, procedures, and technical requirements involved in the testing and inspection.

5.2.2 A dedicated inspection and testing team should be established to clearly define the responsibilities for the planning, implementation, recovery, and rectification of inspection and testing.

5.2.3 Personnel performing inspection and testing shall receive relevant training, the training content of which shall cover basic knowledge of functional safety and inspection and testing methods. And the use of on-site instruments/equipment, etc.

5.2.4 Management procedures should be used to review and approve delays in inspection and testing to prevent significant delays.

5.2.5 When changes occur that affect the SIF, the testing requirements should be redefined, including determining the testing intervals and testing plan. Requirements for inspection and testing implementation, etc.

5.2.6 Newly installed SIF equipment should be "new" or as close to "new" as possible; equipment that has been unused for a certain period of time should... Installation and use can only proceed after inspection, testing, and confirmation that the requirements are met.

Note. "A certain time" may vary for different equipment. For example, for measuring instruments, it may be the calibration cycle, while for other equipment, it may be the time specified by the manufacturer.

5.3.1 Inspection and Testing Content

5.3.1.1 The inspection and testing shall comply with the relevant provisions of GB/T 20438 (all parts) and GB/T 21109 (all parts).

5.3.1.2 Inspection and testing shall comply with the overall SRS, as well as the requirements of the SIS equipment safety manual, user manual, and relevant manufacturer information.

5.3.1.3 The entire SIS should be inspected and tested, including sensors, logic solvers, and final components, and the SIF loop should be inspected. Testing includes verification tests of the signal path from the SIF sensor to the logic solver, and from the logic solver to the final component.

5.3.1.4 The content of the inspection and testing should be based on the relevant documents provided by the manufacturer, such as the overall SRS, system design documents, and safety manuals. Regulation.

5.3.1.5 The inspection and testing shall include at least the following.

a) Testing the effectiveness of the performed safety functions, such as determining whether any undetected dangerous failures have occurred. (lambdaDU);

b) Testing the safety-related performance of the performed safety functions, such as safety response time, safety measurement accuracy, fault degradation mechanisms, and Safety-oriented capabilities, fault-tolerant capabilities, etc.;

c) Testing the effectiveness of diagnostic functions.

5.3.2 Inspection and Testing Methods

5.3.2.1 SIS testing can be conducted in an end-to-end, segmented, or single-device manner.

5.3.2.2 Before a new or modified SIF is put into use, a full-function verification test should be performed using end-to-end testing to validate the SIF. It meets the requirements. Afterwards, end-to-end inspection and testing, segmented inspection and testing, or individual equipment inspection and testing can be selected as needed.

5.3.2.3 During planned shutdowns for maintenance, enterprises should employ end-to-end or segmented inspection and testing. During non-planned shutdowns for maintenance, [further procedures may be implemented]. Individual equipment inspection and testing, end-to-end inspection and testing, and segmented inspection and testing are adopted.

5.3.2.4 Defects discovered during inspection and testing should be repaired in a safe and timely manner. After repair, another inspection should be conducted. Test.

5.3.2.5 Inspection and testing should minimize the physical modifications required for inspection and testing (e.g., jumpers).

5.3.2.6 Inspection and testing should meet functional safety requirements, and the impact of inspection and testing on on-site production operations should also be considered. Specific inspection and testing... The trial plan or process should be coordinated with the on-site production operation.

Note. Effective safety testing varies depending on the specific application. Hazards, resources, and site conditions can differ significantly. Regardless of the method used... All tests and inspections used to ensure the security and integrity of SIFs need to consider practical operability, and maintenance activities should be integrated with security considerations. And minimize operating costs.

5.4 Inspection and Testing Procedure The inspection and testing should be carried out according to the process shown in Figure 1.

6.1 General Provisions

6.1.1 Conduct testing and inspection planning before implementing the testing and inspection.

6.1.2 The input information for verifying the test plan should include at least the following.

b) Safety manuals and user manuals for all devices in the SIS;

c) Information on the relevant installation, layout, environmental conditions, and operation and maintenance procedures of the SIS application site.

6.1.3 The personnel involved in the development of the testing and inspection plan shall include at least the following.

a) On-site operation and maintenance personnel for SIS applications;

b) Manufacturers of critical and complex equipment in SIS;

c) Necessary safety supervisors.

6.2 Planning Content

6.2.1 Plan the overall inspection and testing strategy, including the specific testing methods, testing time, and personnel requirements, at least considering... Considering the following.

a) Inspection and testing methods, including end-to-end inspection and testing, segmented inspection and testing, and individual equipment inspection and testing; Example. This includes all components required for the entire loop operation, such as thermocouple sheaths, thermocouples, transmitters, inputs, logic operations, outputs, and final components. test.

b) Determine whether the safety instrumented function test needs to be conducted as a single, centralized test, or whether it can be performed at different times as needed. Each component of the safety instrumented function is tested separately to achieve the corresponding safety integrity level;

c) Confirm the feasibility and necessity of online testing, and the allocation ratio between online and offline testing;

d) The competence, division of labor, responsibilities, and safeguards of the personnel performing the inspection and testing.

6.2.2 Specific testing and inspection content and implementation processes should be planned, taking into account at least the following.

a) Inspection and testing procedures for each SIF and SIS device;

b) Approvals and notifications required to perform the test, such as notifications to operators;

c) Scope of work, such as the items to be checked, like flow rate and valve closure status;

d) Compensation measures to ensure operational safety during the testing process;

e) Clear and coordinated inter-departmental cooperation is required for the implementation of testing and inspection;

f) Preparation of testing tools/equipment;

g) Evaluation criteria for planning, testing, and inspection;

h) The required testing and inspection plan that needs to be implemented to achieve the required testing and inspection coverage;

7.1 General Requirements

7.1.1 Inspection and testing shall be carried out in accordance with the inspection and testing plan.

7.1.2 During the inspection and testing process, attention should be paid to potential negative impacts on on-site network security, electrical safety, or explosion protection, and appropriate measures should be taken. Take sufficient measures to reduce the risks posed by this impact to a tolerable level.

7.2 Test Preparation

7.2.1 A testing team should be established to conduct verification tests.

7.2.2 Record templates or forms should be developed for the testing process to achieve standardized and regulated test records. Dedicated testing tools should preferably be used. It enables automated recording. See Appendix A for an example of inspection and test records.

7.2.3 Select appropriate testing tools to assist in the execution of verification tests. The tools shall meet the following requirements.

a) Tools used for testing and verification, if related to calibration, should be properly calibrated to ensure measurement accuracy and traceability. (As per national law) Mandatory verification should be carried out where regulations or standards require it.

b) The software component of the testing tool shall meet the requirements for T2 type offline support tools specified in GB/T 20438.3.

Note. Depending on the impact of the tool on safety functions, some tools may need to meet T3 or other safety-related requirements. Please refer to GB/T 20438 (all parts) for details. (the regulations regarding points).

c) All inspection and testing tools used should be properly maintained, meet integrity requirements, and ensure that they are in good working order.

d) The testing team should have access to the relevant manuals for the tools and ensure that they use the tools in accordance with the recommendations and methods of the tool manufacturer.

e) Before performing inspection and testing, the functionality and integrity of the inspection and testing tools should be checked.

f) For testing tools intended for use in production environments, their compliance with on-site application requirements should be reviewed, including electrical... Compliance with gas safety requirements, explosion-proof requirements, electromagnetic interference requirements, etc.

7.2.4 A specific analysis should be conducted based on the established test plan to identify potential errors or disruptions during the execution of verification tests. For examples of adverse effects on the process and possible errors during inspection and testing, please refer to Appendix B.

7.2.5 Before performing the inspection and testing, key data such as the controller configuration information and equipment configuration information should be backed up.

7.3.1 Offline verification test

7.3.1.1 The most common inspection and testing method for SIF is offline manual inspection and testing, which can employ end-to-end inspection and testing, segmented inspection and testing, and unit-based testing. Preparations are underway for inspection and testing.

7.3.1.2 The advantages and disadvantages of end-to-end inspection and testing, segmented inspection and testing, and individual equipment inspection and testing should be analyzed, and where feasible, [further action should be taken]. Perform end-to-end verification tests to confirm that the entire SIF can perform security functions as expected.

7.3.1.3 When end-to-end testing is not feasible, or in order to find specific fault points, segmented inspection testing or individual equipment inspection testing may be used.

7.3.1.4 End-to-end verification testing is the verification testing of the entire SIF signal path, including the signal path from the SIF sensor to the logic solver. The testing of the signal path from the computer to the final component should include at least end-to-end functional testing, end-to-end response time testing, and... Safety guidance capability test under fault conditions. Note

1.End-to-end verification tests have the ability to directly verify that SIF is executed correctly. Note

2.The basic method of full-loop verification testing is. to generate or simulate an abnormal measurement value, so that the input variable first reaches the alarm state, and then... Then, the interlock value is used to observe whether the response of the rest of the system is as expected. Note

3.Complete end-to-end testing includes testing the entire SIF signal path, as well as testing the individual devices that make up the SIF. Before the original or modified SIF is put into use, a complete end-to-end verification test is required.

7.3.1.5 Segmented inspection testing refers to the inspection testing of individual equipment sections within the SIF loop. When using segmented inspection testing, there should be Overlapping should be ensured to guarantee that the test content covers all safety loop devices and interfaces. Example. Testing covers sensors, input wiring, input modules, communication, the arithmetic section of logic solvers, output modules, and relays (especially for meters). The output of the relay, the output wiring, and the final components are used to verify the operation of the entire test circuit. Figure 2 shows a circuit divided into three overlapping sections for testing. The SIF of the test. Figure

2.Example of SIF segmented test.

7.3.1.6 When necessary, specialized individual device testing should be conducted on the SIS equipment. Typical examples include.

a) Parts not covered by end-to-end testing due to objective reasons;

Note. For example, simulating a pressure signal can confirm whether the pressure interlock circuit is executing correctly, but this test may not include the pressure transmitter's tap. Specialized testing is required on the pressure tapping section.

b) Complex electronic or programmable electronic devices with sophisticated redundancy degradation or high coverage diagnostic capabilities;

c) Components with special weak points or poor reliability.

7.3.2 Online Inspection and Testing

7.3.2.1 Before conducting online testing, ensure that the process has stable operating conditions, including no significant rate changes or emergencies. Conditions, process failures, etc.

7.3.2.2 When using online inspection and testing, safety compensation measures should be implemented to compensate for risks arising from the shutdown of SIF or SIS equipment. Reduce the reduction in capabilities and ensure that overall safety meets acceptable risk standards.

7.3.2.3 Online testing should have time limits, and the timeframes to be considered include.

a) The test period allowed by the process based on safety planning (this period may be obtained through proactive adjustments to the process);

b) Within the permitted test period, the actual permitted test implementation time (during which SIF may be bypassed or in operation). abnormal);

c) The maximum time allotted for each test item planned within the allowed test implementation time.

7.3.2.4 When using online testing, parameters such as the test interval and possible downtime during the test should be incorporated into the assessment of random failures. Effectiveness estimation (PFDavg or PFH).

Note. Standards such as GB/T 20438.6 and GB/T 21109.2 do not provide reference calculation methods for estimating random failures under online inspection and testing conditions. In practical applications, this method can be mathematically derived based on parameters such as online inspection test interval and test coverage.

7.3.2.5 For subsystems with a hardware fault margin of 0, when online verification testing needs to be bypassed, the allowable test execution time is not... It should exceed the time specified in 7.3.2.3.

7.3.2.6 Online testing should be conducted under strict control and monitoring conditions, using procedures that have undergone technical review and have been previously executed offline.

7.3.2.7 It should be ensured that online testing can be completed step-by-step without unexpected interruptions. During the testing process, if bypass input or output is encountered... In case of any issues, dedicated personnel should be assigned to conduct continuous monitoring in order to prevent the need for downtime.

7.3.2.8 If on-site inspection and testing requires opening or performing certain on-site equipment operations, this must be done by a dedicated on-site operator. Personnel execution.

7.3.2.9 During online testing, the operator should be able to directly trigger the SIF via the manual stop switch when necessary, directly guiding the process to safety. state.

7.3.2.10 All personnel involved in the online inspection and testing of SIS equipment should understand the procedures to be followed when process requirements arise during the inspection and testing process. The program.

7.3.3 Recovery of Inspection and Testing

7.3.3.1 After the inspection and testing are completed, the following should be checked before the SIF circuit is put back into operation.

a) All bypasses and forced jumpers have been removed;

b) All bypass functions (including forced and disabled alarms) have been restored to their normal positions;

c) All process isolation valves are configured according to process startup requirements and procedures;

d) All test materials (e.g., liquids) have been removed;

e) The configuration or operating mode of the equipment or system has been restored to normal operation;

f) Other hardware or software changes that occurred during testing have been reversed.

7.3.3.2 Before resuming operation, appropriate safety verification activities should be performed to ensure that the process and system meet the requirements for resuming operation.

7.3.3.3 The recovery of in-situ tests should be the focus of inspection.

7.3.3.4 Restoration procedures involving disassembly and reassembly should be given special attention.

8.1 Test Coverage Analysis

8.1.1 The coverage of the two types of inspection and testing should be analyzed based on the specific inspection and testing methods implemented, including PTC1.for undiagnosable hazardous failures. Test coverage, PTC

2.Test coverage for diagnostic effectiveness of diagnostic functions.

8.1.2 For PTC1, calculate according to formula (1).

8.1.3 For PTC2, calculate according to formula (2).

8.2 Quantitative Analysis of Failure Probability Based on Inspection and Testing

8.2.1 Failures should be classified in conjunction with the results of inspection and testing. An example of failure classification based on inspection and testing is shown in Appendix D.

8.2.2 Based on the testing coverage determined in

8.1 and the current interval for performing testing, PFDavg/PFH testing should be conducted. calculate.

8.3 Operational Status Analysis Based on Failure Data

8.3.1 During the inspection and testing process, failure data for SIS components should be collected based on the inspection and testing results.

Note. Failure data collection references standards such as IEC 60300-3-2.

8.3.2 During the analysis, all anomalies or interlocking events that occurred in the SIS during the previous testing interval should be comprehensively considered. Furthermore, to determine whether the current operational status of the SIS complies with the SIS security requirements specification or all assumptions made during the PFDavg/PFH calculation process. Let there be constraints or conditions; possible scenarios include.

a) The failure rate of a single component does not meet the assumption of constant failure;

b) The demand rate is too high relative to the projections in the safety requirements specifications, failing to meet the proportional limits for diagnostic test intervals;

c) Systemic failure rate is too high.

8.3.3 If partial travel testing is used, an evaluation should be conducted on the test content and the test results that can be achieved to ensure that the requirements are met. The document outlines the objectives.

8.3.4 If, based on the above analysis, it is found that the SIS's operating status cannot meet the current safety operation requirements, corresponding corrective measures should be taken.

9 Inspection and testing report

9.1 The safety instrumented system inspection and test report shall include at least the following.

a) The testing and inspection commissioning unit;

b) Testing and inspection unit;

c) Basic information about the safety instrumented system, including name, tag number, serial number, design and operating parameters, etc.

d) The basis for testing and inspection, including relevant information such as the laws, regulations, technical specifications and standards, and names of basic technical documents on which the testing and inspection were conducted;

e) Project background, including the origin of the task, project overview, and project summary;

f) Verify the purpose of the test;

g) Scope of inspection and testing;

h) The content and methods of inspection and testing;

i) Testing and inspection tools, including hardware and software;

j) Inspect and test the process;

k) Verification and analysis of test data;

l) Checklist for test coverage;

m) Test results;

10.1 General Requirements

10.1.1 Any defects discovered during inspection and testing should be repaired in a safe and timely manner. After repair, another inspection should be conducted. Secondary inspection test.

10.1.2 Faults detected or occurring during the inspection and testing process should be recorded in relevant documents.

10.1.3 Rectification should be based on the data or results obtained from testing. The goal of rectification is to ensure that every SIF in the SIS continues to meet functional requirements. Safety requirements.

10.2 Offline Inspection and Testing Rectification Requirements

10.2.1 Faults detected or discovered during inspection and testing shall be repaired in accordance with the requirements of the procedures.

10.2.2 When a non-equivalent replacement occurs during the repair process, a change procedure should be executed and SIL verification should be performed. After the repair is completed, another procedure should be performed. A single inspection test.

10.2.3 When an equivalent replacement occurs during the repair process, an inspection test should be performed again after the repair is completed.

10.3 Rectification Requirements for Online Inspection and Testing

10.3.1 When a fault is detected or discovered through diagnostics, testing, or any other means, in a subsystem with a fault margin of 1, In the event of a dangerous malfunction, specific actions should be taken to bring the controlled process object to or maintain a safe state, or to carry out maintenance on the malfunctioning component. Even during this period, safe and continuous operation can still be maintained.

10.3.2 The repair time for faulty components should be determined in conjunction with the MTTR (Mean Time To Repair) limit (see 7.3.2.3), where MTTR is... The time set in the SIF PFDavg confirmation calculation. If the maintenance time exceeds the calculated set value, it means an increase in potential risk. At this point, it is necessary to take specific actions, such as ceasing continuous operation or shutting down the process.

10.3.3 When a hazard is detected or discovered in a non-redundant subsystem through diagnostics, testing, or any other means In the event of a malfunction, where the safety instrumented functions are entirely dependent on this subsystem and are operating in a demand mode, specific actions should be taken to ensure the controlled system... The workpiece must reach or remain in a safe condition; or the faulty component must be repaired within the specified MTTR (Mean Time To Repair). During maintenance, this should be done in accordance with the attached... Add remedial measures or constraints to ensure that the process object continues to operate safely. These supplementary measures...

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 64 pages — is available in the English PDF.

How to Buy GB/T 47696-2026

  1. 1Add to cart. Click the "Buy GB/T 47696-2026" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
64 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

GB/T 47696-2026

$635.00

$540.00for partners