Valid

NB/Z 20249-2013Guidance for use of probabilistic safety assessment for classification of functions for instrumentation and control system important to safety in nuclear power plants (English PDF)

概率安全评价在核电厂安全重要仪表和控制功能分类中的应用指南

Open the NB/Z 20249-2013 preview as PDF

Preview — first pages of NB/Z 20249-2013 (full document: 22 pages)

This is a limited preview

Buy now to download the full PDF (22 pages)

Issued by

NEA

Level / Type

Industry · Recommended

Issue date

June 8, 2013

Implementation date

October 1, 2013

Scope

NB/Z 20249-2013 is the English-translated version of 概率安全评价在核电厂安全重要仪表和控制功能分类中的应用指南.

NB/Z 20249-2013 is the Chinese guiding technical document for using probabilistic safety assessment to classify the instrumentation and control functions important to safety in a nuclear power plant. It exists because the classification decides the cost and the schedule of everything downstream, and the traditional way of making it is blunt. Every I and C function is placed in category A, B or C, and that letter determines the qualification the equipment must pass, the redundancy and separation it must have, the software development rigour it must follow and the testing it must undergo; a function classified one letter too high is paid for many times over, one classified too low is a gap in the defence. The deterministic method in GB/T 15474 assigns the letter from the role the function plays in the design basis events, which is sound but takes no account of how likely those events actually are or of how much a given function really contributes to risk. This document adds the probabilistic view as a supplement, not a replacement: it uses the accident sequences, the core damage frequency and the importance measures of a Level 1 PSA to test and refine the deterministic classification, so that effort is concentrated where risk actually is. It defines the twenty-two terms the method needs, from accident sequence and event tree through common cause failure, screening and uncertainty to controlled state and safe shutdown; it sets the general principles, including the requirement that the deterministic and the probabilistic design be iterated against each other rather than used in isolation; it defines the three function categories and their relation to the safety systems and safety-related systems of HAD 102/14; and it gives the application method and the implementation steps. Three informative annexes cover the limitations of using either method alone, the way PSA classification is applied in other countries, and the application methods and results of PSA. The document was prepared with reference to IEC/TR 61838:2009. It was issued on 8 June 2013 by the National Energy Administration and took effect on 1 October 2013.

Document preview — NB/Z 20249-2013

National Standard of the People's Republic of China

ICS
27.120.20
Classification
F 83

Issued by: National Energy Administration of the PRC

Contents

  • Foreword2
  • 1 Scope1
  • 2 Normative references1
  • 3 Terms and definitions1
  • 4 Abbreviations4
  • 5 General principles4
  • 6 Definition of the function categories4
  • 7 Application of PSA techniques to the classification of I and C functions in nuclear power plants5
  • Annex A (Informative) Limitations of using the deterministic method or the probabilistic method alone in the classification of I and C functions12
  • Annex B (Informative) Application of PSA classification techniques in some countries14
  • Annex C (Informative) Application methods and results of PSA17
  • Bibliography19

Foreword

This document was issued on 8 June 2013 by the National Energy Administration of the PRC and takes effect on 1 October 2013.

It is a NB/Z guiding technical document: it does not oblige, it guides.

It is classified under ICS 27.120.20, Chinese classification F 83.

This guiding technical document was drafted in accordance with the rules given in GB/T 1.1-2009.

This guiding technical document was prepared by the redrafting method with reference to IEC/TR 61838:2009 Nuclear power plants - Instrumentation and control systems important for safety - Use of probabilistic safety assessment for the classification of functions; the degree of correspondence with IEC/TR 61838:2009 is non-equivalent.

This guiding technical document was proposed by the Nuclear Power Standardization Technical Committee of the Energy Industry.

This guiding technical document is under the administration of the Nuclear Industry Standardization Research Institute.

Drafting organizations of this guiding technical document: CGN Engineering Co., Ltd.; Shenzhen CGN Engineering Design Co., Ltd.

Main drafters of this guiding technical document: Sun Wei, Zhang Huanxin, Sun Yongbin, Guo Zhiwu, Yang Jie, Li Youran, Gu Pengfei, Zhang Longqiang, Jiang Hui, Liu Aiguo, Yang Chunju.

1 Scope

NB/Z 20249-2013 is the Chinese guiding technical document for using probabilistic safety assessment to classify the instrumentation and control functions important to safety in a nuclear power plant. It exists because the classification decides the cost and the schedule of everything downstream, and the traditional way of making it is blunt. Every I and C function is placed in category A, B or C, and that letter determines the qualification the equipment must pass, the redundancy and separation it must have, the software development rigour it must follow and the testing it must undergo; a function classified one letter too high is paid for many times over, one classified too low is a gap in the defence. The deterministic method in GB/T 15474 assigns the letter from the role the function plays in the design basis events, which is sound but takes no account of how likely those events actually are or of how much a given function really contributes to risk. This document adds the probabilistic view as a supplement, not a replacement: it uses the accident sequences, the core damage frequency and the importance measures of a Level 1 PSA to test and refine the deterministic classification, so that effort is concentrated where risk actually is. It defines the twenty-two terms the method needs, from accident sequence and event tree through common cause failure, screening and uncertainty to controlled state and safe shutdown; it sets the general principles, including the requirement that the deterministic and the probabilistic design be iterated against each other rather than used in isolation; it defines the three function categories and their relation to the safety systems and safety-related systems of HAD 102/14; and it gives the application method and the implementation steps. Three informative annexes cover the limitations of using either method alone, the way PSA classification is applied in other countries, and the application methods and results of PSA. The document was prepared with reference to IEC/TR 61838:2009. It was issued on 8 June 2013 by the National Energy Administration and took effect on 1 October 2013.

This guiding technical document gives the method, the general principles and the implementation steps for the classification of instrumentation and control (I and C) functions on the basis of risk-informed probabilistic safety assessment (PSA) techniques.

The classification method given in this guiding technical document applies to the classification of the functions of I and C systems important to safety in pressurised water reactor nuclear power plants; nuclear power plants of other reactor types may apply it by reference, according to their actual technical characteristics. Depending on the purpose, the methods concerned may be used in the design, construction, operation and decommissioning phases of a nuclear power plant.

2 Normative references

The following documents are indispensable for the application of this document. For dated references, only the edition cited applies to this document. For undated references, the latest edition, including all amendments, applies to this document.

GB/T 12727 Quality qualification of electrical equipment of the safety system of nuclear power plants

GB/T 13630 Design of nuclear power plant control rooms

GB/T 15474-2010 Classification of instrumentation and control functions important to safety in nuclear power plants

GB/T 20438 Functional safety of electrical, electronic and programmable electronic safety-related systems

HAD 102/14 Instrumentation and control systems important to safety in nuclear power plants

IAEA NS-G-1.3:2002 Safety Guide: Instrumentation and control systems important to safety in nuclear power plants

3 Terms and definitions

The following terms and definitions apply to this document.

3.1 accident sequence

A sequence of events leading to an undesired consequential state.

3.2 accident sequence analysis

The process of determining the combinations of initiating events, safety functions and system failures and availabilities that may lead to core damage.

3.3 anticipated operational occurrences (AOO)

The various operating processes deviating from normal operation that are expected to occur at least once during the operating lifetime of a nuclear power plant. Because appropriate measures have been taken in the design, such events do not cause serious damage to items important to safety and do not lead to accident conditions.

3.4 basic event

In a fault tree model, an event that does not need to be developed further because a suitable level of resolution has already been reached.

3.5 beyond design basis accident (BDBA)

Accident conditions whose severity exceeds that of the design basis accidents.

3.6 common cause failure

In a multi-channel system or in multiple systems, a failure in which one or more events cause two or more separated channels to fail simultaneously, so leading to the failure of the whole system or of several systems. A failure in which a specific single event or cause leads to the failure of two or more structures, systems or components.

3.7 core damage frequency

The expected number of core damage events per unit time.

3.8 design basis accident (DBA)

Those accident conditions against which a nuclear power plant has taken specific measures in the design according to established design criteria, and in which the damage to the fuel and the release of radioactive material remain within the regulatory limits.

3.9 design basis event (DBE)

A hypothetical event applied in the design in order to establish the acceptable performance requirements for structures, systems and equipment.

3.10 event tree

A logic diagram that starts from an initiating event or state and describes the progression of the accident through a series of branches representing the success or failure of the expected system or operator actions, finally reaching an end state of success or failure.

3.11 functions, and the associated systems and equipment (FSE)

The set of associated systems and equipment that carry out a given purpose or objective.

3.12 I and C function

The control, operation and/or monitoring carried out on a defined process.

3.13 I and C systems important to safety

Those I and C systems whose system failure or spurious operation could cause site personnel or the public to receive excessive radiation exposure, together with those I and C systems that prevent anticipated operational occurrences from leading to unacceptable consequences; they include the safety systems and the safety-related I and C systems.

3.14 initiating event

Any internal or external event that disturbs the steady operating state of the nuclear power plant and thereby gives rise to an abnormal event such as a transient or a loss of coolant accident (LOCA). An initiating event requires a response from the mitigating systems of the plant and from the personnel; if that response fails, undesired consequences such as core damage may follow.

3.15 internal event

A class of initiating event originating within the nuclear power plant. When combined with failures of the safety systems and/or with operator errors it affects the operability of the plant systems and may lead to core damage. By convention, loss of off-site power is treated as an internal event, while internal flooding and internal fire are regarded as external events.

3.16 postulated initiating event (PIE)

An event identified during the design that may lead to anticipated operational occurrences or to accident conditions.

3.17 probabilistic safety assessment (analysis) (PSA)

A comprehensive and structured approach that identifies the background of nuclear power plant failures and produces a numerical estimate of the risk borne by the workers and by the public. PSA is normally divided into three levels, of which Level 1 PSA identifies the accident sequences that may cause core damage, estimates the core damage frequency, evaluates the safety and the reasonableness of the nuclear power plant, finds the weak links of the plant and proposes measures to reduce the core damage frequency.

3.18 screening

The process of not considering an event further on the basis that its probability, or its contribution to the consequences of an accident, is negligible.

3.19 severe accident

Accident conditions whose severity exceeds that of the design basis accidents and that cause significant degradation of the core.

3.20 uncertainty

An expression of the confidence in the level of knowledge of the parameter values and of the models used in constructing the PSA.

3.21 controlled state

The core is subcritical, the core power is removed by an open cooling train such as the steam generators and the auxiliary feedwater system, the core coolant inventory is kept stable, and the radioactivity is brought down within the acceptable range.

3.22 safe shutdown

The core is subcritical, the residual heat of the core can be removed continuously, for example by the residual heat removal system, and the radioactive release is within the limits corresponding to the design basis events.

4 Abbreviations

The following abbreviations apply to this document.

AOO: Anticipated Operational Occurrences

ATWS: Anticipated Transient without Scram

BDBA: Beyond Design Basis Accident

CCF: Common Cause Failure

CDF: Core Damage Frequency

DBA: Design Basis Accidents

DBE: Design Basis Events

FSE: Functions and the associated systems and equipment

HMI: Human Machine Interface

I and C: Instrumentation and Control

IAEA: International Atomic Energy Agency

LERF: Large Early Release Frequency

NO: Normal operation

PIE: Postulated Initiating Event

PSA: Probabilistic Safety Assessment

SFC: Single Failure Criterion

5 General principles

PSA techniques may be used to identify the potential risks of a nuclear power plant, to make decisions effectively and to concentrate resources.

PSA techniques may be used to improve the functions of the I and C systems of a nuclear power plant, and to provide support for the periodic safety review of an operating plant.

The deterministic classification method is given in Clause 4 of GB/T 15474-2010; the classification method based on PSA techniques may be used as a supplement to the deterministic classification method.

PSA techniques may be used during the design phase of the I and C systems of a nuclear power plant to supplement the classification of I and C functions made on a deterministic basis, and the relevant reliability data may be continuously improved in practical application.

The deterministic design and the PSA-based design of a nuclear power plant should be iterated repeatedly in order to arrive at a reasonably sound design solution, and the classification of the I and C functions is finally determined on the basis of the safety important functions of the plant that have been established.

6 Definition of the function categories

6.1.1 Safety Guide HAD 102/14 has already divided the I and C systems important to safety of a nuclear power plant into safety systems and safety-related systems according to the safety importance of the function. In accordance with the provisions of GB/T 15474, the I and C functions important to safety of a nuclear power plant are divided into three categories, category A, category B and category C. Compared with HAD 102/14, the functions falling within the scope of the safety systems belong to category A or category B, and the functions falling within the scope of the safety-related systems belong to category B or category C.

6.1.2 Category A functions are those that play the principal part in achieving or maintaining the safety of the nuclear power plant so as to prevent a design basis event from leading to unacceptable consequences. Where no other alternative action can be taken in the initial phase of a transient, that part is also indispensable even if the latent fault can be detected.

Remaining clauses in the full document

  • 7 Application of PSA techniques to the classification of I and C functions in nuclear power plants

......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 22 pages — is available in the English PDF.

Referenced standards

Normative references

GB/T 13630 Design of nuclear power plant control rooms · GB/T 15474-2010 Classification of instrumentation and control functions important to safety in nuclear power plants · GB/T 20438 Functional safety of electrical, electronic and programmable electronic safety-related systems

Similar standards

GB/T 12727|GB/T 13630|GB/T 15474-2010|GB/T 20438

How to Buy NB/Z 20249-2013

  1. 1Add to cart. Click the "Buy NB/Z 20249-2013" button on this page. You can add more standards before checkout.
  2. 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
  3. 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
  4. 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.

Related Standards

English PDF
22 pages
Instant delivery (0–9 sec)
Invoice included
View Cart

Secure payment via Stripe

Payments accepted

VisaMastercardAmerican ExpressApple PayGoogle PayStripe

NB/Z 20249-2013

$400.00

$340.00for partners