6) If the manufacturer’s safety analysis determines that hydrogen in air, hydrogen
in oxygen or oxygen in hydrogen combustible gas mixture hazards require and
emergency stop function, then the emergency stop shall be initated when the
maximum volume fraction of 1% hydrogen in air, 2% hydrogen in oxygen or
1.6% oxygen in hydrogen is exceeded. The response time and accuracy of the
instruments used for detection and actuation of a control shall be accounted
for in the safety analysis.
7) Safety components shall incorporate appropriate safety factors as prescribed
by the manufacturer’s safety analysis to ensure that the alarm threshold lies
outside the limits to be registered, taking into account, in particular, the
operating conditions of the installation and possible faults in the measuring
system. Safety components shall :
‐ be so designed and constructed as to be reliable and suitable for their
intended use.
‐ be independent to other functions, unless their safety functions cannot be
affected by such other functions
‐ comply with design principles in order to obtain suitable and reliable
protection. These principles include, in particular, fail‐safe modes,
redundancy, diversity and self‐diagnosis.