Utility Process Safety System (UPSS) for SIL 2 Hazardous Process Protection
Designing and implementing an independent Safety Instrumented System to meet fire code compliance requirements and protect personnel from hazardous conditions across a biotechnology manufacturing campus


Independent Safety Layer
The completed system established functional independence between the safety layer and the building automation and fire alarm systems.
Campus Operating Footprint
The project scope covered seven system groups across chemical distribution and utility systems.
Lifecycle Documentation
The documentation package supports long-term maintainability of the safety functions and provides the audit trail required for ongoing regulatory compliance.
Executive Summary
A biotechnology manufacturing facility in Southern California required an independent Safety Instrumented System (SIS) following local fire department inspection findings. The facility handled hazardous materials, across chemical distribution and utility systems and lacked an independent protective layer capable of detecting abnormal conditions and executing deterministic shutdown actions separate from the building automation system.
The project scope covered seven system groups: the Clean Caustic System (CCS), CIPA Distribution (Acid) system, CIPB Distribution (Caustic) system, Fire Alarm System, Asphyxiant Gas Monitoring system, Tetramethylammonium chloride (TMAC) systems, and Freeze-thaw Skids. Mangan Biopharm designed, installed, commissioned, tested, and documented the Utility Process Safety System (UPSS), a Safety Integrity Level (SIL) 2-rated SIS implemented across seven control panels and multiple campus areas, in accordance with ANSI/ISA 84.01 and the IEC 61511-aligned safety lifecycle framework.
The completed system established functional independence between the safety layer and the building automation and fire alarm systems, extended SIL 2 protective logic across a broad campus operating footprint, and provided the lifecycle documentation required to support long-term maintainability of the safety functions.
System Description
The UPSS was a supervisory Safety Instrumented System designed to monitor, evaluate, and respond to hazardous conditions across seven chemical distribution and utility systems on the facility campus. Its primary function was to detect abnormal states and execute defined Safety Instrumented Functions (SIFs) that transitioned affected equipment to a verified safe state.
| System | Safety Scope |
|---|---|
| Clean Caustic System (CCS) | Caustic chemical handling; containment monitoring and automated shutdown on release or abnormal condition |
| CIPA Distribution (Acid) | Acid distribution system; spill detection, excess flow monitoring, and containment status |
| CIPB Distribution (Caustic) | Caustic distribution system; spill detection, excess flow monitoring, and containment status |
| Fire Alarm System | Integration with site fire alarm; coordinated response to fire events affecting covered utility systems |
| Asphyxiant Gas Monitoring | Detection of oxygen-deficient atmospheres in areas where asphyxiant gases are present |
| TMAC (Tetramethylammonium chloride) | Monitoring and shutdown for TMAC chemical handling systems; hazardous material release detection |
| Freeze Thaw Skids | Safe state management for freeze thaw operations under defined hazardous conditions |
All seven systems were covered under the UPSS through a distributed architecture of seven control panels serving different campus areas and process boundaries. Mangan’s execution scope covered the full safety lifecycle: engineering documentation, panel design and fabrication, application programming, installation, electrical wiring, I/O checkout, cause-and-effect verification, factory acceptance testing (FAT), site acceptance testing (SAT), commissioning, qualification, and startup.
Client Profile
A biotechnology manufacturing facility in Southern California developing advanced therapies across oncology, immunology, neuroscience, and ophthalmology. Site operations depend on tightly controlled chemical distribution and utility systems that handle hazardous materials and require high standards of safety, reliability, and regulatory compliance.
Mangan Biopharm was selected for this project based on its history designing and implementing Safety Instrumented Systems in Refineries & Pipelines, industries where SIL-rated safety architecture, fail-safe logic design, and full safety lifecycle execution are standard project requirements. Applying that discipline to a regulated biopharmaceutical environment, where the hazard profiles differ but the engineering rigor does not, was the basis for Mangan’s selection and the foundation of the technical approach used on this project.
The Challenge
The facility’s existing building automation system (BAS) and fire alarm system did not include a dedicated, independent safety layer capable of meeting the functional requirements of a Safety Instrumented System. A local fire department inspection finding identified the need for a compliant hazardous material monitoring and response system. The scope of covered hazards required detection and response capability across chemical release, combustible atmosphere, oxygen-deficient atmosphere, and abnormal transfer conditions, each requiring deterministic, fail-safe response independent of the building automation system.
Engineering Complexity: A Platform with Limited Field History
The SIL 2-rated Rockwell platform selected for the UPSS, including the safety-rated processor and associated I/O modules, had limited field deployment history at the time of project execution. This introduced engineering uncertainty that would not be present on a mature, widely deployed SIS platform. Logic development, communications architecture, and system integration required additional rigor at each interface boundary, particularly where the UPSS communicated with the BAS and fire alarm system.
Maintaining functional independence between the safety layer and the building automation environment, a core SIS design requirement under IEC 61511, required deliberate architectural decisions at each integration point to avoid common-cause vulnerabilities. The limited platform field history meant that some behaviors had to be identified and resolved through direct collaboration with Rockwell’s technical support organization during logic development and integration rather than through established precedent.
Scope Complexity: Multiple Systems, Multiple Boundaries
The project covered seven chemical distribution and utility systems across multiple campus areas and process boundaries. Each group presented distinct hazard profiles and monitoring requirements. The final architecture had to accommodate this variety within a single SIS framework while preserving deterministic response behavior and maintaining traceability from design intent through field validation for each covered system.
The Solution
Mangan designed and implemented the UPSS in accordance with ANSI/ISA 84.01 and the IEC 61511-aligned SIS lifecycle framework, covering safety lifecycle deliverables from functional specification through verification, startup, commissioning and qualification. The system was designed to address California Fire Code Section 5003 requirements for hazardous material monitoring, including leak detection and defined response to abnormal conditions across oxygen-deficient atmospheres, combustible gases and vapors, and hazardous material storage, transport, and delivery.
Safety System
The UPSS was implemented as an independent protective layer functionally and electrically separate from the BAS and fire alarm system with a SIL 2-rated logic solver evaluating defined input conditions and executing trip and permissive actions on confirmed demand. The permissive-based shutdown strategy required SIL-rated run permissive contacts for all VSDs and motor starters within the covered system groups. This contact had to be in a true state before the motor controller could energize the motor. Under a hazardous condition, the UPSS removed the permissive, preventing equipment energization regardless of the command state from the BAS. This architecture ensured that a single control system failure in the BAS or individual motor controller could not bypass the safety response.
Hazard Detection Coverage
As a supervisory safety platform, the UPSS performed hazard detection, alarm generation, permissive management, and automated trip execution across seven categories of initiating conditions. Inputs were configured on a de-energize-to-trip basis wherever applicable, so that loss of power, signal, or communication biased the system toward a safe condition rather than defeating the safety response.
| Input Type | Condition Monitored |
|---|---|
| Spill sensors | Surface-level chemical release detection |
| Secondary containment sensors | Wet/dry status of pipe secondary containment |
| Primary containment profiling | Pressure monitoring for primary containment integrity |
| Excess flow monitoring | Abnormal flow indicative of line breach or failure |
| Gas and vapor detection | Combustible gas and hazardous vapor presence |
| Oxygen deficiency monitoring | Atmospheric oxygen levels in potentially asphyxiant areas |
| Emergency stop stations | Local E-stops near susceptible equipment; global E-stops along primary egress routes |
California Fire Code Compliance
The system was designed to address hazardous material monitoring requirements under California Fire Code Section 5003, including leak detection and defined response to abnormal conditions in hazardous material systems. The design supported the detection, alarm, and automated response sequence required to demonstrate compliance with inspection findings and maintain ongoing code adherence.
Integration and Communication Design
Interface boundaries with the BAS and fire alarm system require careful design to preserve SIS independence while enabling coordinated response across systems. Communication paths were defined and verified to ensure that a failure or fault condition in the BAS or fire alarm network could not propagate into the UPSS in a way that compromised safety function availability or created a common-cause failure mode.
Lifecycle Execution
The full safety lifecycle was delivered as a single integrated scope, not separated between design and commissioning phases. This approach maintained traceability from initial functional specification through cause-and-effect verification, I/O checkout, FAT, SAT, commissioning, and qualification. The resulting documentation package supports long-term maintainability of the safety functions and provides the audit trail required for ongoing regulatory compliance.
Technical Highlights
| Capability | Implementation Detail |
|---|---|
| SIL 2 Rating | SIL 2-rated SIS designed to execute Safety Instrumented Functions independently of process control |
| Independent Protection Layer | Functional and electrical separation from BAS and fire alarm systems to eliminate common-cause exposure. IPL, a system that can prevent an event from progressing to the undesired consequence affected by the initiating event or action of any protection layer associated with the event |
| Hazard Detection Coverage | Seven input categories: spill, containment, pressure profiling, excess flow, gas/vapor, O2 deficiency, E-stop |
| De-energize-to-Trip | Fail-safe output philosophy: loss of power, signal, or communication biases toward safe state |
| Permissive Shutdown Logic | SIL-rated run permissives required for all VSDs and motor starters across all seven covered systems. Conditional algorithms used in SIL systems to prevent risky actions or start-ups until specific safe preconditions are met. |
| California Fire Code Section 5003 | Architecture designed to address Section 5003 hazardous material monitoring and response requirements. The general requirements for the storage, use, and handling of hazardous materials. |
| Full Scope | Engineering lifecycle documentation, panel design and fabrication, programming, panel installation, electrical wiring, FAT, SAT, I/O checkout, commissioning, qualification, startup |
| Campus Distribution | Seven control panels serving multiple areas and process boundaries across the facility campus |
The Results
The completed UPSS addressed local fire department inspection findings and established a qualified, independent safety layer across seven covered system groups and seven campus control panels. The following conditions were verified at project completion:
Fire code compliance achieved
The system addressed California Fire Code Section 5003 requirements for hazardous material monitoring and response, resolving the inspection findings that initiated the project.
Independent protection layer established
Functional and electrical separation between the UPSS and the BAS and fire alarm system was verified. A single failure in the building automation system cannot bypass the SIL 2 safety response.
Hazard detection coverage confirmed
Seven categories of hazardous conditions and protective inputs were integrated and verified through cause-and-effect testing and I/O checkout across all seven control panels.
Permissive architecture verified
SIL-rated run permissive contacts for all VSDs and motor starters within the seven covered system groups were tested and confirmed to function as designed, removing the ability to energize affected equipment in a confirmed hazardous condition.
Full lifecycle documentation delivered
Safety lifecycle documentation from functional specification through qualification was produced and approved, providing traceability from design intent to field-verified performance and supporting long-term maintainability of the safety functions.
Campus-wide deployment completed
The UPSS was commissioned across seven control panels spanning multiple campus areas and process boundaries, extending SIL 2 protective logic to the full scope of all seven covered systems.
Operational continuity maintained
The UPSS architecture was designed to provide safety coverage without requiring changes to normal operating procedures. Equipment control and sequencing continue to be managed by the BAS under normal conditions; the UPSS intervenes only when a defined hazardous condition is detected.
Key Takeaways
This project illustrates several considerations relevant to engineering teams, EHS managers, and facilities and operation managers implementing Safety Instrumented Systems in biopharmaceutical manufacturing environments particularly where the project scope involves chemical distribution and utility systems with integration to existing building automation and fire alarm infrastructure.
SIS independence is an architectural requirement, not a configuration setting
Functional and electrical separation between a Safety Instrumented System and the building automation environment must be established at the design level. It cannot be achieved through software configuration alone. Each interface boundary with the BAS, or fire alarm system requires deliberate analysis to ensure the safety function availability is not compromised by a failure in the connected system.
Platform maturity affects project execution risk
When a SIL-rated platform has limited field deployment history, logic development and integration require additional rigor. Behaviors that would be resolved by precedent on a mature platform must be identified and resolved through direct engagement with the manufacturer and methodical testing. This should be scoped as a project risk and resourced accordingly.
De-energize-to-trip is the correct default for hazardous environments
Configuring SIS outputs on a de-energize-to-trip basis means that loss of power, signal, or communication drives the system toward a safe state rather than allowing equipment to continue operating. This is the engineering default in high-hazard environments. Deviations from this approach require documented justification and should be minimized.
Permissive-based shutdown architecture extends safety coverage efficiently
Requiring SIL-rated run permissives for all VSDs and motor starters within covered systems provides safety coverage across the full operating footprint without requiring a dedicated safety output for every individual actuator. This approach scales effectively across multi-system, multi-boundary implementations.
Full lifecycle traceability is not optional in regulated environments
In a biopharmaceutical facility, the documentation package produced during SIS implementation is not only a delivery requirement, but also the audit trail that supports ongoing regulatory compliance, inspection readiness, and long-term maintainability. Treating safety lifecycle documentation as an integrated deliverable rather than a project close-out task maintains quality and traceability throughout execution.
This project demonstrates that rigorous Safety Instrumented System design and implementation, including functional independence, fail-safe behavior, cause-and-effect verification, and full lifecycle documentation, can be applied in biopharmaceutical manufacturing to the same standard expected in oil and gas and chemical processing. The engineering discipline required to deliver a qualified SIS in this environment is not materially different from that required in oil and gas or chemical processing; what changes is the regulatory context and the specific hazard profile being addressed.
For sterile manufacturing validation projects, see our sterile filling line validation case study.
Related Capabilities
Planning a safety or automation lifecycle project?
Talk with Mangan Biopharm about engineering, validation, compliance, and lifecycle documentation for regulated manufacturing environments.