18.1 Installation, Commissioning, Validation, and SAT
Key Takeaways
- ISA/IEC 61511-1:2018 Clause 15 validation shows the installed and commissioned SIF meets the SRS; Clause 14 commissioning only shows installed equipment is brought into service.
- NCEES PE Control Systems 2027 item 5.E tests installation, commissioning, validation procedures, and SAT; FAT itself is a Clause 13 design/engineering activity (item 5.D).
- SAT must time the as-installed sensor–logic–final-element path against the SRS response time and process safety time; simulated I/O at FAT does not prove field valve stroke.
- Leftover FAT punchlist items that depend on field devices, air supply, or process connections must be retested on the actual installed equipment before the SIF is claimed as a protection layer.
- As-built drawings document what was installed; discrepancies against the SRS are nonconformances that require correction or a formal SRS/SIL change, not silent redlines.
Why SAT is a PE Control Systems item
The April 2027 NCEES PE Control Systems exam tests installation, commissioning, and validation, including procedures and site acceptance testing (SAT) as Knowledge Area 5, item E. The design standard supplied in the session is ISA/IEC 61511-1:2018. That Part 1 text is the U.S. adoption of IEC 61511-1:2016. On the exam, a powered cabinet is not proof that a safety instrumented function (SIF) will take the process to the specified safe state inside process safety time.
ISA/IEC 61511-1:2018 splits the work. Clause 13 factory acceptance testing (FAT) belongs with design and engineering (NCEES 5.D). Clause 14 covers SIS installation and commissioning. Clause 15 is SIS safety validation: inspection and testing that the installed and commissioned safety instrumented system (SIS) and its SIFs meet the safety requirements specification (SRS). SAT is the usual site vehicle for that Clause 15 demonstration. Mixing those clauses is a frequent exam trap.
Commissioning is not validation
Commissioning asks whether installed equipment is energized, loop-checked, communicating, calibrated, and ready for intended service. Typical work includes P&ID walkdowns, point-to-point wiring, impulse-line integrity, instrument-air quality, UPS checks, loop simulation, and permitted stroking of final elements.
Validation asks whether this installed SIF meets the SRS. The SRS states the demand condition, trip setting, voting, safe state, reset philosophy, bypass and override constraints, diagnostics, SIF response time, and the SIL target. A SIF can have green loop folders and still fail validation: a shutdown valve that will not close in time, a shared impulse line that defeats independence used in SIL verification, or an HMI bypass that skips the authorized sequence.
Treat SAT as validation against SRS clauses, not against vendor catalog sheets. Commissioning data may be reused when the same test, same as-installed equipment, and same acceptance criterion already satisfy an SRS item. Reuse does not convert a loop check into a SIL claim.
FAT versus SAT leftover punchlist
FAT usually tests the logic solver, cabinets, application program, simulated I/O, communications, diagnostics, and HMI in a shop. A simulated digital output to a dummy load does not prove actuator air volume, packing friction, process-fluid forces, or actual stroke time. SAT tests the as-installed chain: process connection, sensor, wiring, logic solver, final element, and process action.
Open FAT punchlist items are not waived by shipment. Split them. Shop-closeable items include cabinet labeling and documentation typos that do not change SIF behavior. Items that must be retested on site are anything that depends on field devices, process connections, air or hydraulic supply, grounding, environmental installation, or timing through the actual final element. If FAT deferred “valve stroke to be confirmed at SAT,” SAT owns that test. A signed FAT does not close a deferred field demonstration.
As-built versus SRS
As-built drawings document what was installed. The SRS states what safety requires. Validation reconciles the two. If the field installed a 2oo3 transmitter set on a common process tap that the SRS and SIL verification treated as independent, the as-built is a nonconformance, not a paperwork update. Restore independence, or return to hazard analysis, SIL verification, and SRS revision under management of change. Do not rewrite the SRS after the fact to match a weaker installation.
End-to-end SAT is preferred: stimulate the process condition at the sensor, confirm the logic solver decides correctly, and time the final element to the safe state. When a live process cannot be driven to the trip point, segmented tests are allowed only if the segments overlap so no untested gap remains (sensor-to-logic, then logic-to-valve, with the same trip output and the same acceptance times). Simulation at the transmitter terminals is not a substitute for proving the process connection is open and the impulse line is not plugged, unless a documented overlapping test covers that failure mode.
Validation planning also has to show that bypass, override, manual shutdown, and reset behave as the SRS requires; that BPCS communications cannot defeat the SIF; that diagnostic alarms are visible and not silently shelved; and that the proof-test procedure written for operations is actually executable on the installed equipment. If the SAT team cannot isolate and test a final element the way the proof-test procedure assumes, that is a Clause 15 finding, not a later maintenance inconvenience.
Before hazardous chemicals or energy are introduced, a functional safety assessment (often Stage 3, frequently folded into the pre-startup safety review) checks that validation evidence is complete. The FSA does not replace SAT. It asks whether SAT and the leftover punchlist actually closed the SRS.
Activity versus the question it answers
| Activity | Question it answers | Typical evidence | Proves the SIF meets the SRS? |
|---|---|---|---|
| Mechanical completion / walkdown | Was it installed per drawings and manufacturer instructions? | Punchlist, redlines, tag and torque checks | No — installation quality only |
| Commissioning / loop check | Does each loop energize, communicate, and move? | Loop folders, calibration sheets | No — device function, not SRS compliance |
| FAT (Clause 13) | Does the assembled logic solver and application behave in the shop? | FAT procedure, simulated I/O traces | Partial — shop only; field timing unproven |
| SAT / validation (Clauses 14–15) | Does the installed SIF meet the SRS, including response time and safe state? | Timed end-to-end or overlapping segmented tests; bypass/reset checks; as-built versus SRS | Yes — this is the SRS demonstration |
| Pre-startup FSA / PSSR | Is lifecycle evidence complete enough to introduce the hazard? | FSA report, open-item closeout | Assessment of the demonstration, not a substitute |
Worked example: FAT pass, SAT fail on stroke time
SIF-201 is a high-pressure trip on separator V-201. The SRS requires a demand at 8.0 barg (80% of a 10 barg URV), safe state with feed ESD valve XV-201 closed, process safety time of 12 s, and a maximum SIF response time of 6 s (sensor, logic, solenoid, and valve) so that action finishes with margin inside process safety time. Architecture is 1oo2 pressure transmitters, de-energize-to-trip solenoid, spring-to-close valve.
FAT used the logic solver with simulated analog inputs and a dummy load on the trip output. Injecting the 8.0 barg equivalent dropped the trip output in 90 ms. FAT was signed with punch item “XV-201 stroke time to be confirmed at SAT.”
SAT used the actual transmitters on the vessel and the actual solenoid and valve. Measured lags: sensor and filtering to trip decision 0.7 s; logic solver output 0.1 s; solenoid drop-out, air exhaust, and full stroke to the closed limit switch 7.8 s. Total SIF response 8.6 s.
8.6 s exceeds the 6 s SRS limit. SAT fails. The logic solver does not need a new FAT unless the application program changes. The punchlist belongs to the final-element path: actuator sizing, instrument-air volume and restriction, quick-exhaust, packing, or a faster valve. Until a retest shows 6 s or less, SIF-201 is not validated and must not be claimed as the LOPA independent protection layer. The vendor datasheet stroke of 4 s is not a timed SAT of the installed air path.
Exam trap: treating FAT simulated I/O as equivalent to SAT because the tag list matches. Matching tags is necessary. Proving process safety time on the real valve is the SAT question.
Under ISA/IEC 61511-1:2018, what is the correct relationship between commissioning and SIS safety validation?
A logic solver passed FAT using simulated I/O. At SAT the installed ESD valve’s full-stroke time makes the SIF response exceed the SRS limit and process safety time. What is the correct SAT conclusion?
How should leftover FAT punchlist items and as-built documentation be treated before a SIF is claimed as a protection layer?