GE IS2I5WEMAHIA+IS210BPPBHZCAA Mark VIe Safety Controller & I/O Module Set
The GE IS2I5WEMAHIA safety controller, combined with the IS210BPPBHZCAA I/O terminal board, constitutes a robust safety control solution within the Mark VIeS platform. Certified to IEC 61508 for functional safety, this set is engineered for safety-critical applications such as turbine overspeed protection, emergency shutdown systems (ESD), fire and gas detection, and burner management. With systematic capability up to SIL 3, it ensures the highest level of risk reduction for personnel and equipment.
Safety Controller Core Features
The IS2I5WEMAHIA controller is a dedicated safety logic solver that runs independent, certified safety application blocks. It features dual or triple modular redundancy (TMR) with 2-out-of-3 voting logic on critical inputs and outputs. The controller operates on a deterministic frame rate (10 to 320 ms) and includes dedicated safety communication protocols over the IONet. Its hardware is designed with diagnostic coverage exceeding 90%, including built-in self-tests (BIST) for memory, CPU, and communication interfaces.
Safety Integrity LevelSIL 3 (IEC 61508)
Systematic CapabilitySC 3
RedundancySimplex, Dual, Triple
Voting Logic2-out-of-3 (TMR)
IONet Ports3 x 100 Mbps (redundant)
Safety Response Time< 50 ms typical
IS210BPPBHZCAA Terminal Board for Safety I/O
The IS210BPPBHZCAA terminal board is configured for safety applications with T-type or S-type modules. It accommodates discrete input modules with sequence of events (SOE) capability, as well as analog input modules for critical process variables. The board supports barrier or box-type terminal blocks with 24-point density, and each point can accept 2 x 3.0 mm² wires. For safety-related outputs, the board provides relay modules with dry form C contacts, capable of voting (e.g., 2-out-of-3) to drive final actuators such as trip solenoids.
All I/O packs on the safety system are certified for use in safety functions and are physically separated from non-safety I/O to prevent common-cause failures. The terminal board includes built-in fusing and suppression options for solenoid interfaces, reducing the need for external components.
Online Repair and Diagnostics: The IS2I5WEMAHIA controller and I/O packs support hot-swap replacement without compromising safety integrity. Automatic reconfiguration and extensive diagnostics (including temperature, voltage, and communication health) ensure high availability while maintaining SIL compliance.
Safety Application Development
The ToolboxST software suite provides a dedicated safety configuration environment. Certified function blocks (e.g., emergency stop, over-speed trip, pressure relief) are available from the safety library. Sequential Function Charts (SFC) are used for complex shutdown sequences, while SAMA-type diagrams represent logic for clarity. The software includes a lock/unlock mechanism for the safety controller to prevent unauthorized changes – a critical feature for SIL compliance.
All safety-related parameters are stored in non-volatile memory, and the system performs cyclic redundancy checks (CRC) to detect data corruption. Changes are logged with time-stamps and user identification, supporting audit trails for regulatory compliance.
Integration with Plant Control
While the Mark VIeS operates as a stand-alone safety system, it shares the same IONet infrastructure as the standard Mark VIe controllers. This enables peer-to-peer data exchange between safety and non-safety controllers – for example, the safety controller can send a trip demand to the main turbine controller, or the main controller can provide pre-trip alarms to the safety system. However, output data from the safety controller is restricted to safety-dedicated I/O modules to maintain separation.
The system supports shared IONet configurations where sensor data from safety-rated I/O can be used by balance-of-plant controllers for monitoring, reducing instrumentation duplication.
Cybersecurity for Safety Systems
Given the critical nature of safety functions, cybersecurity is paramount. The IS2I5WEMAHIA includes Achilles Level 1 certification, with hardened operating system, whitelisting, and encrypted communication. Role-based access control ensures only authorized personnel can modify safety logic. Security Information and Event Management (SIEM) integration logs all access attempts and configuration changes for forensic analysis.
Environmental and Certification Compliance
The safety controller operates from -30°C to +65°C (standard) or 0°C to +65°C (high-speed version), with storage from -40°C to +85°C. It complies with IEC 61508:2010 Parts 1-7, EN 50402, and meets ATEX Class I, Division 2 hazardous location requirements. The terminal board is UL 61010-1 certified and follows ANSI IPC guidelines for PCB assemblies.
Applications
Turbine overspeed protection and emergency trip
Flame/fire detection and extinguishing systems
Pressure relief and high-temperature shutdown
Generator protection (loss of field, overcurrent)
Emergency shutdown of compressors and pumps
Burner management systems (BMS)
Conclusion
The GE IS2I5WEMAHIA + IS210BPPBHZCAA Mark VIeS safety set offers a proven, certified solution for high-integrity protection systems. With SIL 3 capability, redundant architecture, and seamless integration with the Mark VIe ecosystem, it provides plant operators with the confidence that their most critical processes are safeguarded against failures, while maintaining operational efficiency and regulatory compliance.