Emergency Shutdown System Design (ESD)
API RP 14C and NORSOK S 001 tiered ESD architecture for safe rapid isolation and depressurisation
Emergency Shutdown System
Design (ESD)
Emergency Shutdown System design, particularly on offshore platforms, LNG facilities, and refining complex units, implements tiered logic that progressively isolates, depressurises, and inerts process inventories as the severity of the credible accident scenario grows. The dominant frameworks are API RP 14C, which uses the offshore SAFE chart based ESD, NORSOK S 001, the Norwegian Continental Shelf safety system that has become the de facto international standard for FPSOs and complex topsides, and IEC 61511 for onshore process industries. Tier definitions typically run from ESD 0 for Abandon Platform or Total Site Shutdown, to ESD 1 for Process Shutdown of all hydrocarbon handling, to ESD 2 for a partial Unit Shutdown, to ESD 3 for Equipment Shutdown at the local SIF, with cause and effect logic that links each initiator such as fire and gas, a manual pushbutton, or a process SIF to an action such as block valve closure, depressurisation, pump trip, fire pump start, or deluge activation. Modern design also integrates blowdown line sizing per API RP 521 with flare system simultaneity, high integrity pressure protection systems per API 17O as ESD alternatives for subsea, and a cybersecurity overlay per IEC 62443. Our team builds the architecture so that it isolates fast and stays maintainable.

Emergency Shutdown System Design (ESD) workflow
Define ESD scope from PHA/LOPA output, ESD 0 (total), ESD 1 (process), ESD 2 (unit), ESD 3 (sub unit), allocate SIL per SIF following IEC 61511 PHA workflow, verify scope against API RP 14C minimum SAFE chart requirements for offshore.
Specify ESD logic solver platform (Triconex, HIMA, AB GuardLogix), design voting architecture (1oo1D, 1oo2, 2oo3) matched to SIL target and spurious trip tolerance, segregate ESD from BPCS per IEC 61511 independence requirement.
Author ESD cause and effect matrix linking initiator → ESD level → executive actions (valve closure, motor trip, equipment isolation), review for completeness against PHA scenarios, specify reset and override logic per IEC 61511 manual operation requirements.
Specify ESD valves (ball / gate / butterfly) with fire safe rating per API 607/6FA, partial stroke test capability for SIL ≥2, specify sensors (pressure, temperature, level, gas) with FMEDA data, verify SFF/HFT vs SIL target per IEC 61508.
Develop ESD FAT procedure exercising full cause and effect, SAT with end to end loop testing, specify proof test frequency from PFD/PFH calculation, design partial stroke test schedule for SIL ≥2 SDV/BDV, specify bypass and override management.
Compile ESD Safety Manual per IEC 61511 Cl.16, implement IEC 62443 zone and conduit cybersecurity with SIS isolation from corporate network, specify access control, audit log, and MOC procedure for ESD modifications.

Every deliverable from basis to handover
Complete Emergency Shutdown System Design (ESD) scope covering every calculation, drawing, specification, and construction support activity.
Outcomes of Emergency Shutdown System Design (ESD)
- We achieve fast and deterministic isolation across the credible major accident scenarios
- We drive blowdown design that prevents BLEVE and vessel rupture cascades
- We close the silent partial stroke test gap on critical block valves
- We anchor the emergency shutdown discipline learned from Macondo and Deepwater Horizon
- We deliver design that holds up to audit under API RP 14C and NORSOK S 001
- We meet IEC 61511 Ed.2 lifecycle compliance
- We withstand BSEE, HSE, PSA Norway, and DGH offshore regulator examination
- We align with IEC 62443 cybersecurity requirements
- We reduce your spurious trip frequency through an MTTFS aware architecture
- We enable online partial stroke testing on your critical ESDVs
- We sharpen your bypass governance and prevent the creeping impairment pattern
- We improve your post trip restart efficiency with documented restart logic
- We right size the SIL claim and valve specification
- We cut spurious trip business interruption cost, typically a 50 to 80 percent reduction
- We reduce capex through partial stroke test credit that eliminates offline test scope
- We trim underwriter loadings on high hazard ESD dependent assets
Codes & standards we work to
Triggers that signal the need
Where Emergency Shutdown System Design (ESD) applies
Wellheads, separators, gas compression, FPSO topsides, produced water systems.
Distillation columns, reactors, heat exchangers, storage spheres, LPG handling.
Cryogenic exchangers, liquefaction trains, BOG compressors, storage and sendout.
Reactive systems, batch reactors, solvent handling, runaway reaction scenarios.
Boilers, HRSGs, steam headers, hydrogen systems, ammonia SCR units.
Sterile vessels, CIP/SIP, pressure fermenters, solvent recovery, spray dryers.
Tangible deliverables
- ESD philosophy document with tier definitions
- Cause and effect matrix for each scenario and unit
- ESDV, BDV, and SDV specifications with FMEDA reliability data
- Blowdown line sizing and flare network simultaneity analysis
- HIPPS design where applicable per API 17O
- Manual ESD pushbutton layout and human factors assessment
- Bypass and inhibit procedure with time limit governance
- SIL verification calculations for each SIF
- FAT and SAT test specifications
- Cybersecurity zone and conduit drawings
Ready to start your project?
Speak with our team to scope an engagement tailored to your facility, regulatory context, and lifecycle stage.