semi合集-English.pdf - 第6822页
SEMI S2-0703a E © SEMI 1991, 2004 51 and other sources of design guidance for applicab ility to the design of the system. The supplier should estab lish EPS design criteri a derived from applicable data including the pre…

SEMI S2-0703a
E
© SEMI 1991, 2004 50
RELATED INFORMATION 1
EQUIPMENT/PRODUCT SAFETY PROGRAM
NOTICE: This related information is not an official part of SEMI S2 and was derived from practical application by
task force members. This related information was approved for publication by vote of the responsible committee on
October 21, 1999.
R1-1 Preface
R1-1.1 Compliance with design-based safety standards
does not necessarily ensure adequate safety in complex
or state-of-the-art systems. It is often necessary to
perform hazard analyses to identify hazards that are
specific to the system, and develop hazard control
measures that adequately control the associated risk
beyond those that are covered in existing design-based
standards. This document provides guidelines for
developing a deliberate, planned equipment/product
safety (EPS) program integrating the compliance
assessment activities with hazard analyses and other
activities needed to provide a safe system throughout
the life of equipment or products.
R1-1.2 An effective EPS program reduces the cost,
schedule slips, and liability associated with the late
identification and correction of hazards. To be most
effective, an EPS program should be begun by the
manufacturer early during the design phase. Starting
early allows safety to be designed into the system and
its subsystems, equipment, facilities, processes,
procedures, and their interfaces and operations. These
guidelines are designed to assist the manufacturer in
planning and implementation of an effective EPS
program.
R1-1.3 The lowest costs for implementing safety can
be achieved when hazards are identified and resolved
before hardware is built and firmware or software is
coded. This guide is intended to provide the basis for a
methodology for implementing a safety program for
early and continued hazard identification and the
elimination or reduction of associated risks.
R1-1.4 EPS program success depends directly upon
management emphasis and support applied during the
system design and development process and throughout
the life cycle of the product. This emphasis should
include the following management controls:
R1-1.4.1 Agreement from management that the EPS
program will be maintained and supported throughout
the product or facility life cycle;
R1-1.4.2 Clear and early statements of agreement with
EPS objectives and requirements;
R1-1.4.3 Understanding of, and participation in, the
risk acceptance process; and
R1-1.4.4 Continuing consideration of risk reduction
during the management review process.
R1-2 Purpose
R1-2.1 This guide describes an approach for
developing and implementing an EPS program of
sufficient comprehensiveness to identify the hazards of
a product and to develop design and administrative
controls to prevent incidents. The EPS program
addresses hazards from many sources to include system
design, hazardous materials, advancing technologies,
and new techniques. The goal is to eliminate hazards or
reduce the associated risk to an acceptable level.
R1-3 Scope
R1-3.1 This guide applies to every activity of the
product life cycle (e.g., research, technology
development, design, test and evaluation, production,
construction, checkout/calibration, operation,
maintenance and support, modification and disposal).
R1-4 General Guidelines
R1-4.1
EPS Program — The supplier should establish
and maintain an EPS program to support efficient and
effective achievement of overall EPS objectives.
Depending upon the needs of the company, the EPS
Program may be a company wide program covering all
projects, separate programs for each project, or some
combination of the two.
R1-4.1.1 Management System — The supplier should
establish an EPS management system to implement
provisions of this guide commensurate with the needs
of the program. The program manager should be
responsible for the establishment, control, incorpor-
ation, direction and implementation of the EPS program
policies and should assure that risk is identified and
eliminated or controlled. The supplier should establish
internal reporting systems and procedures for
investigation and disposition of product related
incidents and safety incidents, including potentially
hazardous conditions not yet involved in an incident.
R1-4.2 EPS Design Guidelines
R1-4.2.1 EPS design requirements should be specified
after review of pertinent standards, specifications,
regulations, design handbooks, safety design checklists,

SEMI S2-0703a
E
© SEMI 1991, 2004 51
and other sources of design guidance for applicability to
the design of the system. The supplier should establish
EPS design criteria derived from applicable data
including the preliminary hazard analyses. These
criteria should be the basis for developing system
specification EPS requirements. The supplier should
continue to expand the criteria and requirements for
inclusion in development specification during the
subsequent program phases.
R1-5 Detailed Guidelines
R1-5.1 The purpose of the EPS program is to ensure
that the equipment or product is designed and
documented in a manner that reduces the safety risk
associated with that equipment or product to a level that
is acceptable to the customer. This consideration
applies to all life cycle phases of the equipment or
product. The following sections include detailed
elements of a formal EPS program. Management should
select or tailor the elements appropriate to their needs.
R1-5.2 EPS Program Plan (EPSPP) — The purpose of
a EPS Program Plan (EPSPP) is to describe the tasks
and activities of EPS management and engineering
required to identify, evaluate, and eliminate/control
hazards, or reduce the associated risk to an acceptable
level throughout the system life cycle. The plan
provides a basis of understanding of how to organize
and execute an effective EPS program.
R1-5.2.1 EPS Program Scope and Objectives — Each
EPSPP should describe, as a minimum, the following
four elements of an effective EPS program:
a planned approach for task accomplishment,
qualified people to accomplish tasks,
authority to implement tasks through all levels of
management, and
appropriate commitment of resources (both staffing
and funding) to assure tasks are completed.
The scope and objectives should:
Describe the scope of the overall program and the
related EPS program.
Identify the tasks and activities of EPS
management and engineering functions. Describe
the interrelationships between EPS and other
functional elements of the program. Identify the
other program requirements and tasks applicable to
EPS.
Account for major required EPS tasks and
responsibilities.
R1-5.2.2 EPS Function — The EPSPP should
describe:
R1-5.2.2.1 The EPS function within the organization of
the total program, including organizational and
functional relationships, and lines of communication.
Other functional elements that are responsible for tasks
that impact the EPS program should be included. This
description should include the integration/management
of associate suppliers, subcontractors and engineering
firms. Review and approval authority of applicable
tasks by EPS should be described.
R1-5.2.2.2 The responsibility and authority of EPS
personnel, other supplier organizational elements
involved in the EPS effort, subcontractors, and EPS
groups. Identify the organizational unit responsible for
executing each task and the authority in regard to
resolution of identified hazards.
R1-5.2.2.2.1
One highly effective organizational
approach to hazard resolution authority is through the
use of a EPS Working Group (EPSWG). The activities
of the EPSWG could include:
Identifying safety deficiencies of the program and
providing recommendations for corrective actions
or prevention of reoccurrence.
Reviewing and evaluating the hazard analyses to
develop agreement that the hazards have been
properly identified and controlled.
Provide recommendations to the proper level of
management concerning the need for additional
hazard controls and the acceptability of residual
risks.
The staffing of the EPS function.
The procedures by which the supplier will integrate
and coordinate the EPS efforts.
The process through which supplier management
decisions will be made.
Details of how resolution and action relative to
EPS will be effected at the program management
level possessing resolution and acceptance
authority.
R1-5.2.3 EPS Program Milestones — The EPSPP
should include:
Identification of the major EPS program
milestones. These should be related to major
program milestones, program element
responsibility, and required inputs and outputs.
A program schedule of EPS tasks, including start
and completion dates, reports, and reviews.

SEMI S2-0703a
E
© SEMI 1991, 2004 52
Identification of subsystem, component, software
safety activities as well as integrated system level
activities (i.e., design analyses, tests, and
demonstrations) applicable to the EPS program but
specified in other engineering studies and
development efforts to preclude duplication.
R1-5.2.4 General EPS Guidelines and Criteria — The
EPSPP should:
Describe general engineering requirements and
design criteria for safety.
Describe the risk assessment procedures (see SEMI
S10). The hazard severity categories, hazard
likelihood categories, and the EPS precedence that
should be followed to satisfy the safety
requirements of the program.
Describe closed-loop procedures for taking action
to resolve identified unacceptable risks including
those involving non-developmental items.
R1-5.2.5 Hazard Analysis — The EPSPP should
describe:
The analysis techniques and formats to be used to
identify hazards, their causes and effects, hazard
elimination, or risk reduction requirements and
how those requirements are met.
Recommended techniques for identification of
hazards and hazard scenarios include Preliminary
Hazard Lists, Preliminary Hazard Analysis,
HAZOPs, FMEA, FTA, “what if?” and process
control analyses. Other types of hazard analysis
techniques are discussed in a variety of sources,
such as EN 1050, Annex B. No single method is
the best for all types of systems, subsystems,
subsystem interaction or facilities. A combination
of techniques may be most appropriate.
The integration of subcontractor or supplier hazard
analyses and safety data with overall system hazard
analyses.
Efforts to identify and control hazards associated
with materials used during the system’s life cycle.
R1-5.2.6 System Safety Data — The EPSPP should
describe the approach for collecting and processing
pertinent historical hazard, incident, and safety lessons
learned, data.
R1-5.2.7 Safety Verification — The EPSPP should
describe:
The verification (test, analysis, inspection, etc.)
methods to be used for making sure that safety is
adequately demonstrated. Identify any
requirements for safety certification, safety devices
or other special safety verification or
documentation requirements.
Procedures for transmitting safety-related
verification information to the customer or others
for review and analysis.
R1-5.2.8 Audit Program — The EPSPP should
describe the techniques and procedures to be employed
to make sure the objectives and requirements of the
EPS program are being accomplished.
R1-5.2.9 Incident Reporting — The supplier should
describe in the EPSPP the incident alerting/notification,
investigation and reporting process including
notification of the customer.
R1-5.2.10 EPS Interfaces — The EPSPP should
identify:
The interface between EPS and all other applicable
safety disciplines.
The interface between EPS, systems engineering,
and all other support disciplines such as:
maintainability, quality control, reliability,
software development, human factors engineering,
and others as appropriate.
The interface between EPS and product design,
integration and test disciplines.
R1-5.3 Hazard Analysis Documentation
The hazard analysis process is used to identify hazards
and their controls. This information should be
documented in a closed loop tracking system to track
the implementation of the controls and may also be
required for presentation to management, the customer
and others. The safety documentation could include a
system description, the identification of hazards and
their residual risks, as well as special procedures and
precautions necessary for safety.
The documentation should include the following:
R1-5.3.1 System Description — This should consist of
summary descriptions of the physical and functional
characteristics of the system and its components.
Reference to more detailed system and component
descriptions, including specifications and detailed
review documentation should be supplied when such
documentation is available. The capabilities, limitations
and interdependence of these components should be
expressed in terms relevant to safety. The system and
components should be addressed in relation to its
function and its operational environment. System block
diagrams or functional flow diagrams may be used to
clarify system descriptions. Software and its role(s)
should be included in this description.