13.9.1 Essential safety functions shall be designed
such that risks of harm to personnel or damage to the installation
or the environment are reduced to a level acceptable to the Administration,
both in normal operation and under fault conditions. Functions shall
be designed to fail-safe. Roles and responsibilities for integration
of systems shall be clearly defined and agreed by relevant parties.
13.9.2 Functional requirements of each component
subsystem shall be clearly defined to ensure that the integrated system
meets the functional and specified safety requirements and takes account
of any limitations of the equipment under control.
13.9.3 Key hazards of the integrated system shall
be identified using appropriate risk-based techniques.
13.9.4 The integrated system shall have a suitable
means of reversionary control.
13.9.5 Failure of one part of the integrated system
shall not affect the functionality of other parts, except for those
functions directly dependent on the defective part.
13.9.6 Operation with an integrated system shall
be at least as effective as it would be with individual stand-alone
equipment or systems.
13.9.7 The integrity of essential machinery or
systems, during normal operation and fault conditions, shall be demonstrated.