10.07.2015 Views

SAFETY P R A C TIC E S - gnssn - International Atomic Energy Agency

SAFETY P R A C TIC E S - gnssn - International Atomic Energy Agency

SAFETY P R A C TIC E S - gnssn - International Atomic Energy Agency

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

This publication is no longer validPlease see http://www-ns.iaea.org/standards/RedundancyThe design of the EPS must be adapted to the redundancy concept of the othersafety systems. This means in simple applications that the number of divisions in theEPS is the same as the number of divisions of safety systems it supplies. Examplesare:— 2 X 100% divisions of safety systems powered by 2 X 100% divisions of theEPS. This form of redundancy takes into account the single failure criterion.— 3 X 100% divisions of safety systems powered by 3 x 100% divisions of theEPS. This form of redundancy covers the combination of single failure, asabove, and simultaneous outage of one division — either in the EPS or thepowered safety systems — for maintenance.Another form of redundancy, which gives similar results to the example above,is a 4 X 50% division redundancy.Some components may not be connected to a single redundancy division. Suchcomponents, for example, are those which can be connected to either redundant division(e.g. spare converter). In other cases it is necessary to have redundant componentswithin one fluid system (e.g. redundant containment isolation valves) whichwould therefore have to be powered from different divisions of the EPS to meet thesingle failure criterion. In these cases the reviewer must verify that the redundantcomponents are physically separated by a sufficient distance and that appropriateisolation devices are incorporated.Basis for acceptanceCode, paras 329-336.Safety Guide 50-SG-D7, paras 307, 308, 401.Assessment questions(1) Is the redundancy such that for on-site power operation of the EPS, power canbe supplied to systems and components important to safety assuming unavailabilityof off-site power from the grid and a single failure within the EPS?(2) Is the number of divisions which are considered independent at least as largeas the largest number of functionally independent safety related system divisionswhich have to be supplied by the EPS?(3) What provisions are incorporated to permit the outage of one redundant divisionfor maintenance purposes without unacceptable increase of systemunavailability?(4) Has a quantitative outage time analysis identified the permissible outage periodfor one division?10

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!