Emergency Shutdown System, ESD.
An emergency shutdown, ESD system is the hardwired layer of safety that drives a process to a defined safe state on demand. It is a particular form of safety instrumented system, dedicated to high-consequence shutdown actions like blocking inlet flow, depressurizing a unit, or isolating a section of a pipeline. On offshore and oil & gas facilities the term ESD is preferred over SIS, although the IEC 61511 framework that governs design and proof testing is the same.
Three drawings included on a new account.
What Emergency Shutdown System, ESD means.
An emergency shutdown system is the safety instrumented system in its most decisive form. A function whose action is not to trim or alarm but to stop. On oil and gas production, LNG, and offshore facilities the ESD term is preferred over SIS, but the governing framework is identical, IEC 61511 for the lifecycle and the SIL allocation that sizes the redundancy. What distinguishes an ESD on the drawing and in the document set is its tiered structure. Most operators partition shutdown into levels, where a high-tier demand executes a platform-wide or unit-wide stop and an inventory blowdown, and a low-tier demand isolates a single compartment or item of equipment. The cause-and-effect matrix is the master record of which initiating event drives which level, and the ESDV and SDV valves that execute those levels carry a heavier line weight and an explicit fail-safe direction on the P&ID. Because an ESD action is broad and expensive when it fires without cause, the voting on its initiators is chosen to balance the loss of a spurious shutdown against the consequence of a missed real demand. The ESD valve list, with each valve's trip class, fail direction, and stroke-time requirement, is the part of the structured tag set that the safety integrator and the proof-test team work from, kept separate from the regulatory control scope for the same independence reason as the rest of the SIS.
ESD levels and partitioning
Most operators run a tiered ESD architecture, sometimes called ESD-1, ESD-2, ESD-3 or shutdown levels. Higher levels initiate broader actions. Total platform shutdown, manned-spaces evacuation, blowdown of inventory. Lower levels isolate a single piece of equipment or a compartment. The drawing-side representation uses ESDV-prefixed valves and SDV-prefixed sub-system valves, with cause-and-effect matrices documenting which initiating events trigger which level.
What ESD looks like on a drawing
ESD valves carry a heavier line weight than process valves on most drawing standards, frequently with an ESD designation in the tag prefix and the trip class, 1oo2, 2oo3 annotated nearby. Fail-safe direction, FC for fail-close, FO for fail-open is always called out. Blowdown valves often share the ESD prefix family because they execute as part of the same shutdown sequence.
Shutdown hierarchy levels, as they are commonly partitioned
The number of levels, their names and whether the numbering ascends or descends with severity are set by the project's own shutdown hierarchy document. The pattern below is the common one on oil and gas facilities; always read the project's cause and effect and safety requirements specification for the actual definitions.
| Level | Common name | Typical initiator | Typical action | Scope affected |
|---|---|---|---|---|
| APS | Abandon platform shutdown | Confirmed escalation of a fire or gas event, or a manual abandon pushbutton | Everything in the level below, plus shutdown of emergency power and non-essential life support systems | The whole installation |
| ESD 1 | Total facility or emergency shutdown | Confirmed gas release, confirmed fire, or a manual ESD pushbutton | Close the boundary shutdown valves, trip all process, and start blowdown where it is fitted | The whole facility |
| ESD 2 | Process shutdown, PSD | A process excursion beyond a trip setpoint | Trip the process equipment and close the sectionalising valves; no blowdown | One process train |
| ESD 3 | Unit shutdown, USD | A trip within one unit | Stop the unit and isolate it from the common headers | One unit, for example a compression train |
| ESD 4 | Equipment shutdown | A single machine protection trip | Stop that machine and close its own isolation | One item of equipment |
The valves an ESD acts on, and what each one is for
An ESD is recognised on a drawing by its final elements as much as by its logic. Each of these carries its own tag, its own fail position and its own test regime.
| Element | What it does on a demand | Usual fail position | How it is normally tested |
|---|---|---|---|
| Boundary or riser ESD valve, ESDV | Isolates the facility from an incoming or outgoing pipeline | Fail closed | Full stroke during a shutdown, partial stroke online where fitted |
| Sectionalising shutdown valve, SDV | Splits the process into isolatable inventories | Fail closed | Full stroke during a shutdown, partial stroke online where fitted |
| Blowdown valve, BDV | Routes an isolated inventory to flare or vent | Fail open | Full stroke during a shutdown |
| Depressurisation restriction orifice | Sets the rate at which an inventory is relieved | Fixed, no moving part | Inspection rather than stroking |
| Motor trip contact | Removes the drive from a pump, compressor or fan | De-energise to trip | Loop check and a functional test against the motor starter |
| Solenoid valve on an actuator | Vents the actuator so the valve goes to its fail position | De-energise to vent | Functional test with the valve, and partial stroke where it is fitted |
Common questions
Is an ESD the same thing as an SIS.
How does the ESD relate to the cause-and-effect matrix.
Who tests an ESD system and how often.
Get the cause and effect matrix as a workbook.
Every initiator against every final element, as a grid you can sort and hand to the logic solver.