What Is an Automatic Overfill Prevention System (AOPS)

An Automatic Overfill Prevention System (AOPS) is a Safety Instrumented System (SIS) in a tank farm that is independent of the normal level control loop. It is used to automatically shut off inlet flow or trigger an alarm before the level reaches a dangerous high point. It directly relates to personnel safety, environmental compliance, and asset protection, and is an essential safety barrier for oil and chemical tank farms. The video demonstrates a typical automatic overfill interlock action sequence and can serve as a reference for understanding the solution.

Core Requirements of API 2350 and IEC 61511

API 2350: Methodology for Overfill Protection

API 2350 addresses overfill protection for atmospheric storage tanks and proposes a risk-based approach to determine protection layers and set points. It emphasizes the concept of Independent Protection Layers (IPL) and requires that the AOPS be as independent as possible from the Basic Process Control System (BPCS) in terms of sensors, logic, and final elements.

IEC 61511: Full Lifecycle of Safety Instrumented Systems

IEC 61511 specifies the complete process for an SIS from hazard analysis and SIL determination to design, verification, and operation and maintenance. As part of the SIS, the AOPS must meet the hardware redundancy and diagnostic coverage requirements of the target SIL and maintain traceable verification documentation.

System Architecture and Key Components

  • Level sensors: Preference should be given to continuous level transmitters or switches independent of the BPCS, such as radar, tuning fork, or float switches.
  • Logic controller: A safety PLC or certified safety relay to perform voting and interlock logic.
  • Final elements: Inlet shutoff valves and pump shutdown circuits, which must have a safe failure position.
  • Alarms and HMI: Independent high-high level alarms to avoid confusion with normal alarms.

Parameters and Selection Comparison

ItemNormal Level ControlAOPS Safety Interlock
Standard basisProcess control requirementsAPI 2350 / IEC 61511
Sensor independenceMay be shared with controlMust be independent
Target SILNot applicableSIL 1 to SIL 3
Testing requirementsPeriodic calibrationTest according to SIL verification cycle

Implementation Steps

  1. Conduct HAZOP and LOPA analyses to determine the SIL level and set points of the AOPS.
  2. Select sensors, logic controllers, and shutoff valves according to the principle of independence.
  3. Complete SIL verification calculations to confirm that PFDavg meets the target.
  4. Prepare testing and maintenance plans and incorporate them into management of change.
  5. Perform interlock function tests before commissioning and retain records.

Common Issues and Countermeasures

  • Shared sensors: This reduces independence; independent level switches should be added.
  • Set points too close: Sufficient response time should be left between high-high and high-high-high levels.
  • Insufficient testing: Failure to test according to the cycle will cause SIL failure, so strict execution is required.

Building an AOPS in accordance with API 2350 and IEC 61511 can significantly reduce overfill risk and meet compliance acceptance requirements. It is recommended to incorporate safety lifecycle management early in the project.