Login / Register ID | EN
This page has no official English version. It was translated automatically and may contain errors. Read the original in Indonesian →
Alarm, Interlock, dan Trip: Tiga Lapis Proteksi yang Sering Dikira Satu
Foto: Pixabay on Pexels
IT Industri

Alarm, Interlock, and Trip: Three Layers of Protection Often Mistaken for One

In the control room of a process plant, there is a conversation that almost always recurs every time a disturbance occurs. The operator says the alarm has gone off. The supervisor asks why the unit remains tripped. Then the instrumentation person who arrives later finds that these two issues actually do not originate from the same system.

This is not about negligence. It is about terminology that gradually merges in the minds of field personnel, even though by design it is intentionally separated. Alarms, interlocks, and trips stand on different layers, have different purposes, and lead to different consequences if one of them is ignored.

Three layers often mistaken for one

An alarm is the layer that requests human action. It notifies, but does nothing. An interlock is the logic that prevents an action from occurring when conditions are not safe, for example, a pump that will not start while the suction valve is still closed. Meanwhile, a trip or Emergency Shutdown is the layer that brings the process to a safe condition without waiting for anyone's approval.

The IEC 61511 standard, "Functional safety: Safety instrumented systems for the process industry sector," refers to that last layer as the Safety Instrumented System. It consists of a combination of sensors, logic solvers, and final elements designed separately and independently from the daily control system, and is given a performance target called Safety Integrity Level.

The key term is "separate and independent." If one transmitter is used to control the process as well as to trip the process, what is actually available is only one layer, not two. In a P&ID diagram, this becomes apparent quickly, as long as the person reading it is accustomed to tracing instrument tags to the final element, rather than stopping at the circular symbol.

Alarms that keep sounding eventually go unheard

The first layer is actually the most prone to failure, and it fails gradually. Before the DCS era, the number of alarms was physically limited by the size of the panel board. Now, adding one alarm is just a matter of software configuration, and no one holds anyone accountable until one day the operator faces a full screen.

EEMUA 191, an alarm guideline developed with input from the UK safety regulator and now in its fourth edition, sets a fairly strict benchmark from the start. Fewer than one alarm per ten minutes is considered very likely acceptable for operators. Meanwhile, fewer than ten alarms in ten minutes after an upset is still considered manageable but potentially difficult. ISA 18.2 and IEC 62682:2023 are aligned with the same guidelines.

That number often feels arbitrary for those who have never counted alarms in their own unit. Try counting. The results are usually surprising.

Protection has a lifespan, not a one-time installation

In Indonesia, this aspect of lifespan has already entered the realm of regulation. Minister of Energy and Mineral Resources Regulation Number 32 of 2021 concerning Technical Inspection and Safety Checks of Installations and Equipment in Oil and Gas Business Activities regulates design reviews, risk analysis, and assessments of the remaining service life of installations. This regulation combines Minister of Energy and Mineral Resources Regulation 18 of 2018 and Decree of the Minister of Mining and Energy 300 K/1997, placing the Chief Engineer as responsible for installation safety.

The context is also significant. The Ministry of Manpower, referring to data from BPJS Ketenagakerjaan, recorded 319,382 workplace accidents throughout 2025 across all sectors. While this number is not exclusive to the process industry, it is sufficient to explain why layers of protection are never considered merely administrative matters.

What is most often overlooked is not the design, but the maintenance. Interlocks that are bypassed during commissioning and forgotten to be restored. Protection transmitters that are not included in the calibration schedule because they are considered rarely used. New alarms added without removing any.

Instrumentation indeed works without being prompted, and that is precisely why humans must know exactly which layer is protecting what. Systems can take over in milliseconds, but the decision of whether that layer is still trustworthy or not remains with the person reading the P&ID.

Sources

  • International Electrotechnical Commission, IEC 61511: Functional safety, Safety instrumented systems for the process industry sector. en.wikipedia.org/wiki/IEC_61511
  • EEMUA, Publication 191: Alarm systems, a guide to design, management and procurement, Edition 4, 2024. eemua.org
  • Control Global, ASM Alarm Management Guidelines and ISA-18.2: How Do They Stack Up?. controlglobal.com
  • Ministry of Energy and Mineral Resources, Socialization of Minister of Energy and Mineral Resources Regulation 32 of 2021: Simplification of Technical Inspection and Safety Check Regulations for Oil and Gas Installations. esdm.go.id
  • Databoks Katadata, Distribution of Workplace Accident Cases in Indonesia 2025, East Java the Most. databoks.katadata.co.id