4 ;
•• removal control potential ignition sources as fired unit, engines and non-essential electrical equipment;
• control subsurface safety valve(s);
• where appropriate, depressurize hydrocarbon inventory and vent it to safe location.
The design of the Emergency Shut-Down System shall take into account the needs resulting from normal operation and shall also fulfil the requirements that may arise during other possible (and likely to occur) abnormal or down-graded configurations.
The following issues shall be adequately addressed when relevant:
• all operating configurations, generated by the Emergency Shut-Down System, shall be safe, stable and reversible;
• the Emergency Shut-Down shall be compatible with the re-start philosophy;
• the Emergency Shut-Down, including sensors, actuators and associated connections and circuit, shall operate independently of other process and alarm systems;
• the Emergency Shut-Down System design shall consider interference from other electromagnetic sources and shall incorporate suitable protection too;
• care shall be taken in the design and structure of the Emergency Shut-Down System to eliminate common cause failures;
• the Emergency Shut-Down valves installed for the following purposes shall not auto-reset:
o to prevent gas blow-by from Separators;
o to isolate the Platform;
o to isolate Chemicals Skids;
o to isolate Fuel Gas System and Power Generation.
• Single manual and local reset shall be provided. Ensure that Shut-Down System reset will be only manually operated and allowed only after theof shut-down causes.