You have a distillation column where the HIPPS trip point and the PSV set pressure are the same number. Push the column into a high-pressure excursion and both layers act together: the logic solver drops the source and the relief valve lifts on the same ramp. Two other columns in the same plant have the HIPPS set below the PSV, which is what you expected to see everywhere. So one of three things is true — the first column has a documented reason, the first column has a spec error, or the other two are the outliers. Do not guess which.
Start Here: The Fixes That Waste Your Time
Every one of these gets tried before anyone opens the design file. None of them is the fault.
- Lowering the HIPPS trip point in the logic solver. Fastest change to make, worst change to make undocumented. The HIPPS trip point is a Safety Requirements Specification value derived from the overpressure scenario analysis and the SIL assessment. Change it and you have changed the demand rate on the SIF, the process safety time margin, and possibly the spurious trip rate — none of which you recalculated. Without an MoC and a HAZOP revalidation on the item, you have made a paper problem into a safety problem.
- Raising the PSV set pressure to open a gap. The PSV set pressure is pinned to the vessel design pressure and the relief system design basis, not to whatever gives the HIPPS clean separation. Raise it and you eat into accumulation margin, invalidate the relief load calculation and the inlet/outlet pressure drop check, and put the nameplate out of step with the code stamp. This is the change that looks harmless and is not.
- Adding trip delay or a deadband in the logic solver. Delay does not create separation, it consumes process safety time. The pressure keeps ramping while you hold the trip off, so the PSV lifts anyway — just later, with less margin to the vessel.
- Re-ranging or recalibrating the HIPPS transmitters. Worth doing if drift is real, but drift is not why the numbers on the two data sheets match. A calibration is a maintenance action; a matched set point is a design record.
- Assuming the PSV is the problem because it lifted. The PSV lifting on a genuine excursion is the PSV working. It costs you paperwork, a reseat check, and possibly a lost batch — that is an operability cost, not evidence of a set point fault.
What Each Layer Is Actually For
HIPPS and a PSV are not two versions of the same protection. They occupy different rows on the layer-of-protection stack and fail in different ways.
HIPPS is a prevention layer. It is a SIF: sensors, logic solver, final elements, with a SIL target, a proof test interval and a defined response time. It removes the overpressure by shutting the source — the feed valve, the reboiler heat input, the pump, the upstream line. Its trip point is repeatable to roughly 1–2%, because that repeatability is what the SIL calculation and the set point stack-up assume.
The PSV is a mitigation layer. It does not remove the cause; it dumps the excess. Its set pressure carries a negative tolerance from the certified pop test, not a control-grade tolerance, and it responds to any pressure at its inlet regardless of the source.
The design intent in almost every plant is sequential: alarm, then HIPPS, then PSV, then vessel MAWP with accumulation. You want the HIPPS to do its job so the PSV never opens, because a PSV lift is release to flare or atmosphere, a reseat verification, and a documented event. In the classic HIPPS application the PSV is not there at all — HIPPS gets installed precisely because the relief load cannot be handled safely, or the location has no flare system. Two full layers set at the same pressure is the configuration that needs justification, not the staggered one.
Symptoms vs Causes
| What you see | Most likely cause | First check |
|---|---|---|
| HIPPS trips and PSV lifts on the same excursion, every time | Identical set points with no separation for trip repeatability or response time | Compare HIPPS trip point and PSV set pressure on the SRS and the relief data sheet, not on the DCS faceplate |
| PSV lifts before the HIPPS final element is fully closed | Response-time overshoot: detect + logic + valve stroke exceeds the available margin at the actual ramp rate | Measure SIF response time end to end; get the process ramp rate from a trend of the real event |
| HIPPS trips, source is isolated, pressure still climbs | An overpressure source the HIPPS does not cover — trapped inventory, reboiler heat, exothermic reaction, fire case, blocked outlet downstream of the isolation point | Walk the overpressure scenario list against the HIPPS isolation boundary on the P&ID |
| Two columns staggered, one column identical | Either a scenario-driven design decision on that column or a transcription error in the set point specification | Pull the SIL assessment and relief design basis for the odd column and compare it with the other two |
| PSV simmers or chatters near normal operating pressure | Operating margin below set pressure too small; unrelated to the HIPPS trip point | Trend normal operating pressure against PSV set pressure and inlet line pressure drop |
The Two Explanations That Survive Scrutiny
One: the HIPPS does not cover every overpressure source. This is the explanation that makes identical set points defensible. If the column has an overpressure scenario the HIPPS cannot terminate — heat still in the reboiler after the feed trips, an exothermic path, a fire case, a source that enters downstream of the HIPPS final elements — then the PSV is not a redundant backup. It is the only protection for that scenario, and it is sized and set for it independently. In that arrangement the PSV set pressure comes from the relief design and the HIPPS trip point comes from the scenarios it does cover, and the two landing on the same number is a coincidence of the design constraints rather than a mistake. Ask the question directly: if the HIPPS acts and every final element closes, does the pressure stop rising? On a straight pressure break — a pipeline or well shut in — the answer is yes and there is no reason for coincident set points. On a column with heat input and inventory, the answer is often no.
Two: someone entered the same number twice. Set point specifications get copied between documents. A relief valve set pressure gets propagated into the SIF data sheet, or the design pressure gets used for both. The staggered arrangement on the other two columns is a strong tell: same plant, same design office, same practice — one column out of step is more consistent with a transcription error than a deliberate deviation. It is also possible both layers were installed to make the risk-reduction arithmetic close, so the LOPA had enough independent protection layers to land the scenario in the acceptable band, and nobody revisited the set point stack after the layer count was satisfied.
Pull the Design Basis Before You Touch Anything
- Get the HAZOP or PHA report for that column and find the overpressure nodes. Note every deviation that lands on high pressure and what was credited against it.
- Get the LOPA worksheet. Confirm whether the HIPPS and the PSV were credited as independent protection layers against the same scenario or against different scenarios. Different scenarios is the answer that justifies identical set points.
- Get the SIL assessment and the SRS for the HIPPS. The trip point, the SIF response time, the proof test interval and the trip repeatability are specified there. The SRS trip point is the authoritative number, not the value currently in the logic solver — verify they match.
- Get the relief system design basis: the governing relief case, the relief load, the set pressure, accumulation, and the vessel MAWP. Confirm the PSV set pressure on the data sheet matches the valve nameplate and the last certified pop test.
- Mark the HIPPS isolation boundary on the P&ID. For each overpressure scenario from step 1, decide whether closing that boundary terminates the pressure rise. List the ones it does not.
- If step 5 produces an uncovered scenario, the identical set points are explained and documented — write that finding into the file so the next engineer does not repeat this exercise. If step 5 produces nothing, you have a set point error and the correction goes through MoC.
- Compare the three columns side by side. If the other two have the same scenario structure and staggered set points, that comparison is your strongest argument in the MoC.
Lay Out the Set Point Stack
Build the stack from the top down, from the vessel limit toward the operating pressure. Every step below has to be a real number from a document, not an assumption:
- Vessel MAWP / design pressure and the permitted accumulation for the governing relief case (from the relief design basis and the applicable pressure vessel and relief sizing standards — verify against the actual code of construction for the vessel, do not assume a percentage).
- PSV set pressure, minus the negative set tolerance from the valve certificate.
- HIPPS trip point, plus its trip repeatability (specified around 1–2% for a HIPPS-class SIF, but use the figure in your SRS), plus the transmitter accuracy and drift allowance between proof tests.
- Overshoot after the trip:
ΔP_overshoot = (dP/dt) × (t_detect + t_logic + t_stroke), wheredP/dtis the worst-case ramp rate for the covered scenario and the time terms come from the measured SIF response time. - High alarm, with enough separation for the operator to act.
- Normal operating pressure and its control band.
The separation criterion is straightforward: HIPPS trip + trip error + ΔP_overshoot < PSV set − PSV negative tolerance. If that inequality fails, the PSV will lift on a HIPPS demand, which is exactly what you are seeing. If the inequality cannot be satisfied — because the PSV set pressure is fixed at the design pressure and the HIPPS trip point cannot go lower without spurious trips at normal operating swings — then the column is telling you the operating window is too narrow, and that is a process design conversation, not a set point tweak.
Verify the Separation After the Change
- Run a full proof test of the SIF and record the measured trip point at each transmitter, not just pass/fail. Confirm it sits within the SRS repeatability band around the new value.
- Time the SIF end to end: pressure crossing the trip point to final element fully closed. Compare it against the response time assumed in the stack-up. If it is longer, the overshoot term grows and your margin shrinks.
- Bench-test or verify the PSV pop pressure and reseat against the certificate. A valve that pops low has silently eaten your separation margin.
- Trend the next real high-pressure excursion. The pass criterion is simple: HIPPS trips, PSV stays seated, pressure peaks below PSV set pressure. Capture the ramp rate from that trend and feed it back into the overshoot calculation.
- Confirm the high alarm still gives the operator usable time ahead of the trip after any trip point move.
- Update the SRS, the cause-and-effect chart, the loop folder and the relief data sheet together. A set point that lives in only one of those documents will drift back.
When Identical Set Points Stay
If the scenario mapping shows the PSV is the sole protection for a source the HIPPS cannot isolate, leave both set points where they are and close the finding with the justification written down. In that case the two devices are not competing — they are answering different demands that happen to share a pressure limit, and the PSV lifting on a HIPPS demand is an accepted operational consequence rather than a design defect. What you should not accept is the current state: identical set points with no traceable reason, on one column out of three, with nothing in the file explaining the deviation. That is the condition that gets a valve set point changed by the wrong person on a night shift.
Escalate when the design basis is missing or contradicts the installation. If the SIL assessment, LOPA or relief calculation cannot be located, or the relief load for an uncovered scenario has never been calculated, bring in the licensor or the original relief system design authority — reconstructing a relief case from field data is not a maintenance task. Take PSV set pressure, tolerance and reseat questions to the valve manufacturer's technical support with the serial number and certificate, and take SIF response time, proof test coverage and logic solver behaviour to the HIPPS system vendor's functional safety support. Any change to either set point goes through MoC with HAZOP revalidation before it reaches the field.
FAQ
How do I decide whether a HIPPS trip point should be below the PSV set pressure?
Default to below, with the gap sized by HIPPS trip repeatability (typically 1–2%), transmitter accuracy, and the overshoot (dP/dt) × SIF response time. Equal set points are only defensible when the PSV protects an overpressure scenario the HIPPS cannot terminate.
How do I find out why two protection layers were given the same set point?
Pull the HAZOP/PHA, the LOPA worksheet, the SIL assessment and the Safety Requirements Specification for that column, plus the relief system design basis. The LOPA tells you whether both layers were credited against the same scenario or different ones — that single fact usually settles it.
How do I change a HIPPS trip point safely?
Through MoC with HAZOP revalidation and an update to the SRS, SIL calculation, cause-and-effect chart and loop documentation. Then prove it with a full proof test that records the measured trip point and the end-to-end SIF response time, not just a pass result.
How do I know if my HIPPS covers all overpressure scenarios on a distillation column?
Mark the HIPPS final element boundary on the P&ID and test each HAZOP overpressure deviation against it: with every final element closed, does pressure stop rising? Reboiler heat still in the system, trapped inventory, fire case and any source entering downstream of the isolation point are the usual gaps.
How do I stop a PSV lifting every time the HIPPS trips?
Increase separation at the HIPPS end, never by raising the PSV set pressure — that is fixed by the vessel design pressure and the certified relief calculation. If the trip point cannot go lower without spurious trips, the operating window is too narrow and the issue is process design, not instrumentation.