The electronic pdf versions of the documents found through http://www.dnv.com/ are the officially binding versions. Copyright Det Norske Veritas.

[Book] [Expand] [Collapse] [Search Forms] [Previous Section with Hits] [Next Section with Hits] [Clear Search] [Help]

Expand Search


Ch.2: Technical Provisions [Table of Contents]

DNV-OS-D202 Automation, Safety, and Telecommunication Systems

[-] Ch.3: Certification and Classification

CHAPTER 3

Certification and Classification

Ch.3

SECTION 1
Certification and Classification - Requirements

Ch.3 Sec.1
A. General

Ch.3 Sec.1
A 100   Introduction

Ch.3 Sec.1 A
101
   As well as representing DNV's interpretation of safe engineering practice for general use by the offshore industry, the offshore standards also provide the technical basis for DNV classification, certification and verification services.

Ch.3 Sec.1 A
102
   A complete description of principles, procedures, applicable class notations and technical basis for offshore classification is given by the offshore service specifications, see Table A1.

Ch.3 Sec.1 A
Table A1 Offshore Service Specifications 
No. Title  
DNV-OSS-101 Rules for Classification of Offshore Drilling and Support Units  
DNV-OSS-102 Rules for Classification of Floating Production, Storage and Loading Units 

Ch.3 Sec.1
A 200   Organisation of Ch.3

Ch.3 Sec.1 A
201
   Ch.3 identifies the specific documentation, certification and surveying requirements to be applied when using this standard for certification and classification purposes.

Ch.3 Sec.1
A 300   Classification principles

Ch.3 Sec.1 A
301
   Classification of automation, safety, and telecommunication systems shall generally be according to the principles of:
document evaluation (see B)
certification requirements (see C)
on-board inspection (visual inspection and functional testing).

Ch.3 Sec.1
B. Documentation

Ch.3 Sec.1
B 100   General

Ch.3 Sec.1 B
101
   Overview documentation as listed in Table B1 is requested submitted early in the approval work, applicable for vessel/units with automation and safety systems installed.

Ch.3 Sec.1 B
102
   Documentation listed in Table B2 is required submitted in order to adequately describe the automation and safety system.

Ch.3 Sec.1 B
103
   The documentation shall be limited to describe and explain the relevant aspects governed by the standard requirements.

Ch.3 Sec.1 B
104
   Symbols used shall be explained, or reference to a standard code given.

Ch.3 Sec.1 B
105
   The documentation type number together with identification of the automation and safety system can be used as a unique identifier for the document. The 'T' indicates that the documentation type is required also for automation and safety systems where type approved components or software modules are used.

Ch.3 Sec.1 B
106
   For a system subject to certification, documentation listed in Table B3 shall be available for the surveyor at testing at the manufacturer.

Ch.3 Sec.1 B
107
   For on-board inspection, documentation listed in Table B4 is required submitted to survey station.

Ch.3 Sec.1 B
108
   The documentation shall be limited to describe and explain the relevant aspects governed by the rule requirements.

Ch.3 Sec.1 B
Table B1 Documentation requested submitted at an early stage in the approval work (typically submitted by yard and/or designer and/or manufacturer based upon their detailed specification, applicable for vessels/units with the automation and safety system installed) 
Documentation type Information element Purpose 
System philosophy (1010) (T) 
the tasks allocated to each sub-system, divided between system tasks and manual tasks, including emergency recovery tasks
principles that will be used in the technical implementation of each system.
 
Approval 
General arrangement for the vessel/unit General vessel/unit information. Information 
General arrangement for the main control stations  Main equipment layout, including main engine room, local equipment or instrument room, central equipment room and main control stations.  Information  
Project specification /design basis for automation and safety related systems.  Automation and safety aspects of the following:
Propulsion and steering
Production and/or drilling plant
Turret and swivel
Position keeping
Marine systems
Cargo and offloading systems
Power production
Fire & gas detection system(s)
ESD system
Utility systems.
 
Information 

Ch.3 Sec.1 B
Table B2 Documentation required to describe the automation and safety system(typically submitted by manufacturers based upon their project specific specification) 
Documentation type Information element Purpose 
Functional description (system requirement specification) (1020) (T) 
clear text description of the system configuration
clear text description of scope of supply and what is controlled and monitored as well as how
clear text description of safe state(s) for each function implemented
clear text description of switching mechanisms for systems designed with redundancy R0
P&I/hydraulic/pneumatic diagrams if relevant.
 
Information 
System block diagrams (1030) (T)  
a diagram showing connections between all main components (units, modules) of the system and interfaces with other systems. With details showing segregation between F&G, ESD, PSD and PCS systems as well as other systems where relevant.
 
Approval 
User interface
documentation (1040) 
a description of the functions allocated to each work and operator station
a description of transfer of responsibility between work and operator stations.
 
Information 
Power supply arrangement (1050) (T) 
electrical supply: diagram showing connection to distribution board(s), batteries, converters or UPS. Including information regarding Ex/Non Ex as applicable.
 
Approval 
Functional failure analysis, for essential
systems and important closed loop system (Z070) (T) 
The purpose is to ensure that for single failures, essential systems will fail to safety and that systems in operation will not be lost or degraded beyond acceptable performance criteria when specified by the offshore standard.
The following aspects shall be covered:
a description of the boundaries of the system including power supply preferably by a block diagram
a list of items which are subject to assessment with a specification of probable failure modes for each item, with references to the system documentation
a description of the system response to each of the above failure modes identified
a comment to the consequence of each of these failures.
 
Information 
Failure mode and effect analysis (FMEA) (Z071) (T)(Only when requested) A failure modes and effect analysis (FMEA) is to be carried out for the entire system. The FMEA is to be sufficiently detailed to cover all the systems' major components and is to include but not be limited to the following information:
a description of all the systems' major components and a functional block diagram showing their interaction with each other
all significant failure modes
the most predictable cause associated with each failure mode
the transient effect of each failure on the vessel/unit's position
the method of detecting that the failure has occurred
the effect of the failure upon the rest of the system's ability to maintain station
an analysis of possible common failure mode.
Where parts of the system are identified as non-redundant and where redundancy is not possible, these parts shall be further studied with consideration given to their reliability and mechanical protection. The results of this further study shall be submitted for review.

    Guidance note:
    A project specific FMEA would normally only be expected when using new, unproven, technology or to resolve any doubt as to the reliability of the chosen system topology.

    ---e-n-d---o-f---G-u-i-d-a-n-c-e---n-o-t-e---

 
Information 
List of control &
monitored points (I110) (T) 
A list and or index identifying all input and output signals to the system as required in the offshore standard, containing at least the following information:
service description
instrument tag-number
system (control, safety, alarm, indication)
type of signal (digital / analogue input / output).
 
Approval 
Circuit diagrams (I150) 
for essential hardwired circuits (for emergency stop, shutdown, interlocking, etc.) details of input and output devices and power source for each circuit.
 
Approval 
Test program for testing at the manufacturer (Z120) (T)  Description of test configuration and test simulation methods.Based upon the functional description, each test shall be described specifying:
initial condition
how to perform the test
what to observe during the test and acceptance criteria for each test.
The tests shall cover all normal modes as well as failure modes identified in the functional failure analysis, including power and communication failures. 
Examination 
Software quality plan, based upon life cycle activities (I140) (T)(Shall be available during certification) The software life cycle activities shall minimum contain procedures for:
software requirements specification
parameters data requirements
software function test:
parameter data test
validation testing
system project files stored at the manufacturer
software change handling and revision control.
 
Information 
Data sheets with
environmental
specifications (I080) 
environmental conditions stipulated in Sec.4 for temperature, vibration, humidity, enclosure and EMC.
 
Information 
Cause and effect diagrams 
Cause and effect matrix/chart for PSD, ESD and F&G, showing the various inputs and corresponding actions to be taken by the logic, where relevant.
 
Approval 
Operation manual (Z160) (Available during
certification and to be kept on board) 
A document intended for regular use on board, providing information as applicable about:
operational mode for normal system performance, related to normal and abnormal performance of the EUC
operating instructions for normal and degraded operating modes
details of the user interface
transfer of control
redundancy
test facilities
failure detection and identification facilities (automatic and manual)
data security
access restrictions
special areas requiring user attention
procedures for start-up
procedures for restoration of functions
procedures for data back-up
procedures for software re-load and system regeneration.
 
Information 
Installation manual. (Z170)(Available during
certification) 
A document providing information about the installation procedures. Information 
Maintenance manual(Z180)(Available during
certification and to be kept on board) 
A document intended for regular use on board providing information about:
maintenance and periodical testing
acceptance criteria
fault identification and repair
list of the suppliers' service net
vessel/unit's systems' software - maintenance log.
 
Information 
Test program for dock and sea trials (Z140) (Available during
certification and to be kept on board) 
initial condition
what to test
how to perform the test
acceptance criteria for the test.
 
Examination 
ESD and F&G overview mimics A document showing the main ESD and F&G overview mimics. Information 
CAAP Panel Layout A drawing showing layout of the CAAP panel with information showing all functions, feedbacks and alarms.  Approval 
Network documentation requirements The following information related to the network properties shall be included in the documentation submitted for approval:
Topology and network details including power supply arrangement
Functional description, with special focus on interfaces
Identification of critical network components
Qualitative reliability analysis (e.g. FMEA) Failure response test program.
 
Approval 
Documentation of wireless communication The following information related to the wireless communication shall be included in the documentation submitted for approval:
Functional Description
ISM certificate(IEEE802) from a licence authority (typical flag state) or alternatively applicable test reports
Single line drawings of the WLAN topology with power arrangements
Specification of frequency band(s), power output and power management
Specification of modulation type and data protocol
Description of integrity and authenticity measures.
 
Approval 

Ch.3 Sec.1 B
Table B3 Documentation required available for the testing at the manufacturer 
Documentation type Information element Purpose 
Software quality plan,based upon life cycle activities(Available for information at testing at the manufacturer) The software life cycle activities shall minimum contain procedures for:
software requirements specification
parameters data requirements
software function test:
parameter data test
validation testing
system project files stored at the manufacturer
software change handling and revision control.
 
Information 
Operation manual(Available for information at testing at the manufacturer) A document intended for regular use on board, providing information as applicableabout:
operational mode for normal system performance, related to normal and abnormal performance of the EUC
operating instructions for normal and degraded operating modes
details of the user interface
transfer of control
redundancy
test facilities
failure detection and identification facilities (automatic and manual)
data security
access restrictions
special areas requiring user attention
procedures for start-up
procedures for restoration of functions
procedures for data back-up
procedures for software re-load and system regeneration.
 
Information 
Installation manual(Available for information at testing at the manufacturer). A document providing information about the installation procedures. Information 
Maintenance manual(Available for information at testing at the manufacturer) A document intended for regular use on board providing information about:
maintenance and periodical testing
acceptance criteria
fault identification and repair
list of the suppliers' service net
ship's systems' software - maintenance log.
 
Information 
Test program for dockand sea trials 
initial condition
what to test
how to perform the test
acceptance criteria for the test.
 
Examination 

Ch.3 Sec.1 B
Table B4 Documentation required for on-board inspection 
Documentation type  Information element Purpose 
Test program for dockand sea trials 
initial condition
what to test
how to perform the test
acceptance criteria for the test
 
Examination 

Ch.3 Sec.1
C. Certification

Ch.3 Sec.1
C 100   General

Ch.3 Sec.1 C
101
   Essential and important computer based systems shall be provided with a DNV product certificate. For DNV type approved systems, additional testing is only required for the application software programming and function, unless further testing is required in the type approval certificates. The certification procedure normally consists of:

Document evaluation
review of documentation listed in Sec.1 B for the appropriate system.

Manufacturing survey (MS)
survey of hardware and software
test of project specific application software
issue of a DNV product certificate.

    Guidance note:
    Type approval of systems includes hardware, operating system software, standard software modules and standard function blocks. If new software modules or function blocks are made, testing will be required. Application software is project specific and shall be tested before the certificate can be issued.

    ---e-n-d---o-f---G-u-i-d-a-n-c-e---n-o-t-e---



Ch.3 Sec.1 C
102
   The certification requirement of the various instrumented systems shall follow the same certification requirement as the system they control. Reference is made to Ch.1 Sec.1 B200 for the list of relevant Offshore Standards.

Ch.3 Sec.1 C
103
   Integrated control and safety system shall always be certified.

Ch.3 Sec.1
D. Inspection and Testing

Ch.3 Sec.1
D 100   Manufacturing survey

Ch.3 Sec.1 D
101
   All test programs shall be approved by DNV.

Ch.3 Sec.1 D
102
   Approval testing according to C100 and Ch.2 Sec.1 F100 shall be performed at the manufacturer's works.

Ch.3 Sec.1
D 200   On board testing

Ch.3 Sec.1 D
201
   Approval testing shall be carried out as necessary to demonstrate that the overall requirements of testing described in Ch.2 Sec.1 F100 to F500 have been fulfilled.

Ch.3 Sec.1 D
202
   A copy of the approved test programme and test record shall be kept on board, and shall be completed with final set points and endorsed by the inspecting party.

Ch.3 Sec.1
D 300   Renewal survey

Ch.3 Sec.1 D
301
   Correct functioning of the following systems shall be verified, as far as applicable:
each automation and safety system
fire & gas system
ESD / PSD system
manual control of machinery
remote control of propulsion machinery.

In connection with the latter point, the following manoeuvres are normally required to be effected:
from stop to ahead
from ahead to astern
stop
from stop to astern
stop by operating the emergency device.


Ch.3 Sec.1 D
302
   It shall be verified that the remote control can be transferred to standby manual control in the engine control room in case of power supply failure to the remote control system.



Ch.3 Sec.1 D
303
   When cancelling of automatic load reduction and/or automatic stop of engine are provided, these functions are to be demonstrated to the satisfaction of the surveyor.

Ch.3 Sec.1
E. Alterations and Additions

Ch.3 Sec.1
E 100   General

Ch.3 Sec.1 E
101
   When an alteration or addition to an approved system is proposed, documentation of the alteration or addition shall be submitted for approval. A survey covering testing and installation of the alteration or addition shall be performed.
Sec.7: Supplementary Requirements for Production and Storage Units [Table of Contents]