Skip to content
Process Safety Engineering

Emergency Shutdown System Design (ESD)

API RP 14C and NORSOK S 001 tiered ESD architecture for safe rapid isolation and depressurisation

Technical overview

Emergency Shutdown System
Design (ESD)

Emergency Shutdown System design, particularly on offshore platforms, LNG facilities, and refining complex units, implements tiered logic that progressively isolates, depressurises, and inerts process inventories as the severity of the credible accident scenario grows. The dominant frameworks are API RP 14C, which uses the offshore SAFE chart based ESD, NORSOK S 001, the Norwegian Continental Shelf safety system that has become the de facto international standard for FPSOs and complex topsides, and IEC 61511 for onshore process industries. Tier definitions typically run from ESD 0 for Abandon Platform or Total Site Shutdown, to ESD 1 for Process Shutdown of all hydrocarbon handling, to ESD 2 for a partial Unit Shutdown, to ESD 3 for Equipment Shutdown at the local SIF, with cause and effect logic that links each initiator such as fire and gas, a manual pushbutton, or a process SIF to an action such as block valve closure, depressurisation, pump trip, fire pump start, or deluge activation. Modern design also integrates blowdown line sizing per API RP 521 with flare system simultaneity, high integrity pressure protection systems per API 17O as ESD alternatives for subsea, and a cybersecurity overlay per IEC 62443. Our team builds the architecture so that it isolates fast and stays maintainable.

Emergency Shutdown System Design (ESD) Overview
Engineering process

Emergency Shutdown System Design (ESD) workflow

ESD Scope & SIL Allocation Review

Define ESD scope from PHA/LOPA output, ESD 0 (total), ESD 1 (process), ESD 2 (unit), ESD 3 (sub unit), allocate SIL per SIF following IEC 61511 PHA workflow, verify scope against API RP 14C minimum SAFE chart requirements for offshore.

ESD Architecture & Voting Logic

Specify ESD logic solver platform (Triconex, HIMA, AB GuardLogix), design voting architecture (1oo1D, 1oo2, 2oo3) matched to SIL target and spurious trip tolerance, segregate ESD from BPCS per IEC 61511 independence requirement.

Cause & Effect Matrix Development

Author ESD cause and effect matrix linking initiator → ESD level → executive actions (valve closure, motor trip, equipment isolation), review for completeness against PHA scenarios, specify reset and override logic per IEC 61511 manual operation requirements.

Final Element & Sensor Specification

Specify ESD valves (ball / gate / butterfly) with fire safe rating per API 607/6FA, partial stroke test capability for SIL ≥2, specify sensors (pressure, temperature, level, gas) with FMEDA data, verify SFF/HFT vs SIL target per IEC 61508.

FAT / SAT & Proof Test Programme

Develop ESD FAT procedure exercising full cause and effect, SAT with end to end loop testing, specify proof test frequency from PFD/PFH calculation, design partial stroke test schedule for SIL ≥2 SDV/BDV, specify bypass and override management.

Safety Manual & Cybersecurity Hardening

Compile ESD Safety Manual per IEC 61511 Cl.16, implement IEC 62443 zone and conduit cybersecurity with SIS isolation from corporate network, specify access control, audit log, and MOC procedure for ESD modifications.

Emergency Shutdown System Design (ESD) Scope
Scope of work

Every deliverable from basis to handover

Complete Emergency Shutdown System Design (ESD) scope covering every calculation, drawing, specification, and construction support activity.

ESD tier structure design across ESD 0, 1, 2, and 3 with progressive scope and operator action expectation
Cause and effect matrix linking fire and gas, manual ESD, and process SIFs to isolation, depressurisation, and utility actions
Final element selection covering the Emergency Shutdown Valve, the Blowdown Valve, and the Shutdown Valve
Valve specification that is SIL rated, fail safe in direction, and tight to fugitive emissions per ISO 15848
Partial stroke testing capability on critical block valves for online diagnostic coverage
Blowdown line and flare system simultaneity per API RP 521
High Integrity Pressure Protection System design per API 17O for subsea and high pressure service
Manual ESD pushbutton placement per NORSOK S 001 with a human factors and siting study
Bypass and inhibit management with time limit governance and compensating measure logic
Cybersecurity zone and conduit design per IEC 62443 with secure remote access
Engineering outcomes

Outcomes of Emergency Shutdown System Design (ESD)

ESD Functional Integrity Assurance
  • We achieve fast and deterministic isolation across the credible major accident scenarios
  • We drive blowdown design that prevents BLEVE and vessel rupture cascades
  • We close the silent partial stroke test gap on critical block valves
  • We anchor the emergency shutdown discipline learned from Macondo and Deepwater Horizon
IEC 61511 API 14C ESD Defence
  • We deliver design that holds up to audit under API RP 14C and NORSOK S 001
  • We meet IEC 61511 Ed.2 lifecycle compliance
  • We withstand BSEE, HSE, PSA Norway, and DGH offshore regulator examination
  • We align with IEC 62443 cybersecurity requirements
Nuisance Trip and Availability Optimisation
  • We reduce your spurious trip frequency through an MTTFS aware architecture
  • We enable online partial stroke testing on your critical ESDVs
  • We sharpen your bypass governance and prevent the creeping impairment pattern
  • We improve your post trip restart efficiency with documented restart logic
SIL Allocation and Trip Rate Efficiency
  • We right size the SIL claim and valve specification
  • We cut spurious trip business interruption cost, typically a 50 to 80 percent reduction
  • We reduce capex through partial stroke test credit that eliminates offline test scope
  • We trim underwriter loadings on high hazard ESD dependent assets
Standards & references

Codes & standards we work to

API RP 14C (offshore)API RP 17O (HIPPS)API RP 553 and 554 (valves and control)NORSOK S 001 (NCS)ISO 10418 (offshore)IEC 61511 Ed.2ISA TR84.00.04NFPA 59A (LNG)ISO 15848 (valve emissions)OISD STD 106, 116, and 118 (Petroleum)PESO certification (India)CEA Regulations 2010 (India Electrical Safety)Indian Petroleum Rules 2002ANSI ISA 84.91.01 2020 (Process Safety Critical Instrumentation)
When to engage

Triggers that signal the need

New offshore platform, FPSO, or LNG ESD designBrownfield ESD rewrite following plant modificationSIL claim revalidationPost incident ESD reviewCause and effect matrix rewriteCybersecurity driven ESD upgradeHIPPS deployment as an ESD alternative
Industries served

Where Emergency Shutdown System Design (ESD) applies

Oil & Gas, Upstream

Wellheads, separators, gas compression, FPSO topsides, produced water systems.

UpstreamOffshoreFPSO
Refineries & Petrochemicals

Distillation columns, reactors, heat exchangers, storage spheres, LPG handling.

RefiningPetrochemical
LNG & Gas Processing

Cryogenic exchangers, liquefaction trains, BOG compressors, storage and sendout.

LNGCryogenic
Specialty Chemicals

Reactive systems, batch reactors, solvent handling, runaway reaction scenarios.

ReactiveBatch
Power Generation

Boilers, HRSGs, steam headers, hydrogen systems, ammonia SCR units.

PowerHydrogen
Pharma & Food

Sterile vessels, CIP/SIP, pressure fermenters, solvent recovery, spray dryers.

PharmaFood & Bev
What we deliver

Tangible deliverables

  • ESD philosophy document with tier definitions
  • Cause and effect matrix for each scenario and unit
  • ESDV, BDV, and SDV specifications with FMEDA reliability data
  • Blowdown line sizing and flare network simultaneity analysis
  • HIPPS design where applicable per API 17O
  • Manual ESD pushbutton layout and human factors assessment
  • Bypass and inhibit procedure with time limit governance
  • SIL verification calculations for each SIF
  • FAT and SAT test specifications
  • Cybersecurity zone and conduit drawings
Get Started

Ready to start your project?

Speak with our team to scope an engagement tailored to your facility, regulatory context, and lifecycle stage.