The context — the ATEX manual that mandates an instrumented measure

More and more ATEX equipment manuals (vacuum pumps, compressors, motors in a zone) mandate an instrumented protective measure. A typical, documented case: the manual requires temperature monitoring of the equipment body, tied to an interlock that stops the machine as soon as a limit is reached — for example a trip at 100 °C, a pre-trip at 90 °C, because beyond that the hot surface could become an ignition source.

At that exact moment, something shifts. As long as explosion protection is constructive (zoning, protection types Ex d/e/i…), it belongs to pure ATEX. But the moment an instrumented function — sensor → logic → actuator — becomes the barrier that prevents ignition, it enters the field of functional safety. And a safety function must be classified, sized and proven: it receives a SIL.

The principle: the instrumented protective measure (MSR-Schutzeinrichtung)

The German term is precise: MSR-Schutzeinrichtung — a measurement, control and regulation (Mess-, Steuer- und Regeltechnik) device used as a protective measure. When the ignition-source analysis (Zündquellenanalyse) concludes that an instrumented measure is necessary to reach safety — either by preventing the explosive atmosphere from forming, or by neutralising the ignition source — that measure is no longer a mere control interlock: it is a safety function in its own right.

The safety goal then typically reads: “prevent the formation of a dangerous explosive atmosphere and/or an ignition source becoming active.”

The two normative bridges: TRGS 725 and EN 50495

This is where regulation explicitly links the two worlds.

  • TRGS 725 (German technical rule) — “Dangerous explosive atmosphere — measurement, control and regulation devices within explosion-protection measures.” It describes how an MSR-Schutzeinrichtung is classified (by risk graph) and assigns it a SIL and a class. It is the reference text in the German-speaking world.
  • EN 50495“Safety devices required for the safe functioning of equipment with respect to explosion risks.” At European level, it links the required reliability of the safety device to the equipment’s protection level (EPL): a SIL-rated safety device can “raise” the EPL of equipment.

Upstream, the ignition-source analysis (IEC 60079-0 for the EPL, IEC 80079-36/-37 for non-electrical equipment) identifies whether an instrumented measure is needed. Downstream, the function is designed to IEC 61511 (process) or IEC 61508.

Classification: from risk graph to SIL

The determination is not chosen, it is computed. The TRGS 725 risk graph starts from initial values (severity S, frequency/probability W) and leads to a SIL (most often SIL 1 or 2 for this kind of measure) and a class of MSR-Schutzeinrichtung. In practice, an “over-temperature → stop” function of this type frequently comes out at SIL 1: the residual risk to cover is real but moderate, and a single instrumented function is enough to bring it to the tolerable level.

The typical function: over-temperature → Safe Torque Off

The most common concrete scheme illustrates the bridge perfectly. A temperature measurement exceeds its high-high limit; through the safety instrumented system (SIS), it commands the safe stop of the motor via the drive’s Safe Torque Off (STO) — torque is removed safely, the equipment can no longer heat up or become an ignition source.

Two structuring points, inherited directly from IEC 61511:

  • Control / safety separation. The BPCS (control system) may switch off the contactor and the run command — but that path is not SIL. The safety function acts independently through the drive STO via the safety logic solver. Control and safety do not share the barrier.
  • Lean, documented architecture. Sensor 1oo1, actuator 1oo1, common-cause factor accounted for, and a response time shorter than the process safety time — the actuator (the STO) is often its dominant contributor. Drives with a certified thermal-protection module and integrated STO cover this need.

The trap to avoid: Ex “i” is not a SIL

This is the classic confusion, and it holds here too. An Ex ia sensor guarantees it will not be an ignition source; a SIL guarantees the function achieves its risk reduction. Two orthogonal axes: you can — and often must — have an Ex ia transmitter inside a SIL 1 loop. Likewise, the EPL (Ga/Gb/Gc) measures the probability that the equipment becomes an ignition source, the SIL the probability of function failure: same fault-tolerance grammar, different events.

The lifecycle: classify, prove, test, trace

Treating an explosion-protection measure as a SIL means placing it in the full IEC 61511 lifecycle:

  1. Risk and ignition-source analysis (the “why”).
  2. Classification (risk graph → SIL + class).
  3. Safety requirements specification (SRS): limits, response time, safe state, architecture.
  4. SIL verification (PFD/PFH calculation): demonstrate the chain reaches the target SIL.
  5. Commissioning (sensor / actuator / loop test plans).
  6. Operation & maintenance: periodic proof tests documented over time — they maintain the PFD; without them, integrity erodes.
  7. Life record (SIF-Lebenslauf): traceability of the function over its whole life.

The mistakes not to make

MistakeWhy people make itWhy it is dangerous
Treating ATEX and functional safety in silosTwo teams, two standardsThe instrumented explosion-protection measure IS a SIF — it must be classified and proven
”It’s Ex ia, so it’s SIL”Confusing the two axesEx i ≠ SIL; you need both, they do not replace each other
Ignoring the manufacturer’s ATEX manual”We know our pumps”The manufacturer may mandate an MSR measure; omitting it voids conformity
Wiring the safety stop through the BPCSSaving a channelNo independence: control and safety fall together
Classify once, never test”It worked at commissioning”The PFD drifts; without realistic periodic testing, the barrier fades

Good practice

Read the manufacturer’s ATEX manual: if an MSR protective measure is mandated, it triggers the whole process.

Classify the measure by risk graph (TRGS 725) and design it to IEC 61511 / EN 50495.

Implement the safety stop independently of the BPCS — typically via the drive STO through the safety logic solver.

Verify the SIL by calculation (PFD/PFH), including architecture, β and test interval. The PFD to SIL and risk reduction to SIL calculators help you find your bearings.

Plan periodic proof tests and keep a life record of the function.

Going further

One last thing. Explosion protection is not only a matter of construction and zoning. The day a measurement-control-regulation measure becomes the barrier that prevents ignition, it changes worlds: it becomes a safety function, with its SIL, its proof calculation and its lifecycle. TRGS 725 and EN 50495 only name that bridge — you still have to cross it all the way.