API RP 14C / NORSOK S-001 tiered ESD architecture for safe rapid isolation and depressurisation
Emergency Shutdown System design — particularly on offshore platforms, LNG facilities, and refining complex units — implements tiered logic that progressively isolates, depressurises, and inerts process inventories as the severity of the credible accident scenario grows. The dominant frameworks are API RP 14C (offshore SAFE chart-based ESD), NORSOK S-001 (Norwegian Continental Shelf safety system) which has become the de-facto international standard for FPSOs and complex topsides, and IEC 61511 for onshore process industries. Tier definitions typically run ESD-0 (Abandon Platform / Total Site Shutdown), ESD-1 (Process Shutdown — all hydrocarbon-handling), ESD-2 (Unit Shutdown — partial), ESD-3 (Equipment Shutdown — local SIF), with cause-and-effect logic linking initiator (F&G, manual pushbutton, process SIF) to action (block valve closure, depressurisation, pump trip, fire-pump start, deluge activation). Modern design now also integrates blowdown-line sizing per API RP 521 (flare-system simultaneity), high-integrity-pressure-protection systems (HIPPS) per API 17O as ESD alternatives for subsea, and cybersecurity overlay per IEC 62443.

Define ESD scope from PHA/LOPA output — ESD-0 (total), ESD-1 (process), ESD-2 (unit), ESD-3 (sub-unit); allocate SIL per SIF following IEC 61511 PHA workflow; verify scope against API RP 14C minimum SAFE chart requirements for offshore.
Specify ESD logic solver platform (Triconex, HIMA, AB GuardLogix); design voting architecture (1oo1D, 1oo2, 2oo3) matched to SIL target and spurious-trip tolerance; segregate ESD from BPCS per IEC 61511 independence requirement.
Author ESD cause-and-effect matrix linking initiator → ESD level → executive actions (valve closure, motor trip, equipment isolation); review for completeness against PHA scenarios; specify reset and override logic per IEC 61511 manual-operation requirements.
Specify ESD valves (ball / gate / butterfly) with fire-safe rating per API 607/6FA, partial-stroke-test capability for SIL ≥2; specify sensors (pressure, temperature, level, gas) with FMEDA data; verify SFF/HFT vs SIL target per IEC 61508.
Develop ESD FAT procedure exercising full cause-and-effect; SAT with end-to-end loop testing; specify proof-test frequency from PFD/PFH calculation; design partial-stroke-test schedule for SIL ≥2 SDV/BDV; specify bypass and override management.
Compile ESD Safety Manual per IEC 61511 Cl.16; implement IEC 62443 zone-and-conduit cybersecurity with SIS isolation from corporate network; specify access control, audit log, and MOC procedure for ESD modifications.

Complete Emergency Shutdown System Design (ESD) scope — every calculation, drawing, specification, and construction support activity.
Speak with our team to scope an engagement tailored to your facility, regulatory context, and lifecycle stage.