Description

Application Scenarios:
Picture a hydrocracker unit at a refinery whose emergency shutdown system was commissioned in the late 1990s on Honeywell FSC. The ESD logic, the furnace burner management interlocks and the compressor safeguarding trips all live in that one safety controller, and the plant’s SIS documentation — the SIL verification, the proof-test intervals, the cause-and-effect matrix — is all written against it. Then one morning a CPU card fails self-test: the watchdog de-energizes the safe outputs, the unit goes to its defined safe state, and production stops.
The immediate problem is not the logic — it is the spare. The plant’s original processor is the RAM/EPROM type, which means a replacement card arrives blank, needs the application EPROMs programmed and seated, and depends on the diagnostic and battery module to retain anything at all. Every hour of that exercise is an hour of lost throughput. This is exactly where 10012/1/2 earns its place on the shelf: it is the flash-memory CPU for the same FSC central part, populated and ready, so the recovery becomes a like-for-like card swap in the existing slot rather than an EPROM programming session.
The same story repeats across the FSC installed base — HIPPS skids on gas export lines where a spurious trip costs a day of deferred production, fire and gas systems on offshore platforms where a failed CPU means a manned facility on standby, and boiler management systems in captive power plants where the safety controller must survive a decade between turnarounds. In each case the pain point is identical: keeping a TÜV-certified SIL 3 safety system alive and auditable without rewriting the safety application or disturbing a single field wire.
Parameter:
| Parameter | Value / Description |
|---|---|
| Product Model | 10012/1/2 |
| Manufacturer | Honeywell |
| Product Category | Central processing unit (CPU) module for a safety instrumented system — flash-memory type |
| System Family | Honeywell Fail Safe Controller (FSC), central part rack |
| Safety Classification | AK1–AK6, reaching AK6 in redundant configuration — suitable for SIL 3 safety loops under IEC 61508 / EN 61511 |
| Memory Architecture | On-board non-volatile flash memory — application logic, system parameters and configuration survive complete power loss without battery backup; requires FSC system software version ≥ 500 |
| Power Requirements | 5 Vdc at 35 mA plus 24 Vdc at 35 mA from the FSC backplane — an unusually low draw, roughly 0.4 W, that keeps rack thermal load negligible |
| Analog Input Channels | 16 single-ended channels, 0 to 4.1 V input range, input resistance > 1 MΩ |
| A/D Conversion | 12-bit resolution, converter inaccuracy ±1 LSB; module inaccuracy better than 0.25% of full scale; inter-channel crosstalk > 60 dB — adequate for supervising process references directly on the CPU card |
| Input Protection | ±36 Vdc absolute maximum input tolerance with surge protection circuitry on the analog front end |
| External Voltage Readback | 0 to 4.1 V readback range, typically 1 MΩ input resistance — lets the module verify the signal it is actually receiving, a diagnostic the FSC platform uses for input-path checking |
| Physical & Environmental | 4 TE × 3 HE Eurocard (4 HP, 3U); approx. 20 × 128 × 160 mm, approx. 0.2 kg; IP20 for cabinet installation; operating 0 to +60 °C, storage –20 to +70 °C (–40 to +85 °C on some revisions) |
| Certifications | CE, TÜV certified to the FSC safety platform; UL listing pending/under review depending on revision |
Technical Principles and Innovative Values:
- Innovation Point 1: Non-volatile flash instead of battery-backed RAM. The earlier 10002/1/2 carried 128 Kbytes of system RAM and 128 Kbytes of application RAM held up by batteries on the diagnostic and battery module, with the system program on a separate EPROM daughter card (10002/A/1). 10012/1/2 replaces that stack with flash: the application and configuration stay resident through a total power loss, so a restart is a boot rather than a reload. That removes battery expiry as a failure mode and typically turns a multi-hour recovery into a card exchange.
- Innovation Point 2: Deterministic fail-safe execution with watchdog supervision. The CPU runs self-diagnostics on processor, memory and arithmetic logic in real time, and any detected discrepancy drives the system to a predefined safe state instead of an undefined one. Paired with the FSC watchdog module (10005/1/1), which uses two-out-of-three voting across three independent watchdog sections and can de-energize its output directly from an external ESD input, the safety path does not depend solely on the application program running correctly — the hardware can shut the plant down even if the processor cannot.
- Innovation Point 3: Processing and acquisition on one card. Sixteen 0–4.1 V analog inputs with a 12-bit converter and > 60 dB channel separation sit on the CPU itself. For designers that means critical reference signals can be read and cross-checked at the processor level, adding a layer of signal plausibility checking without consuming I/O card slots in the rack.
- Innovation Point 4: Redundancy that lifts the safety class. In redundant (dual central part) configuration the FSC platform reaches AK6, and 10012/1/2 supports hot-standby operation so that a primary processor fault hands control to the standby without a process bump. Availability goes up without any change to the safety application or to field wiring.
- Innovation Point 5: Lifecycle continuity for a discontinued platform. FSC is no longer sold, and Honeywell has been phasing out support for the coaxial-technology base. 10012/1/2 is the practical bridge: it keeps an installed SIL 3 system running and auditable while the plant plans its migration on its own schedule rather than on an outage schedule forced by missing spares.
Application Cases and Industry Value:
Case 1 — Refinery hydrocracker ESD recovery. A European refinery running FSC on a hydrocracker lost a CPU card during a winter startup. Because the installed processor was the RAM/EPROM type, the maintenance team’s planned recovery involved locating an EPROM programmer, re-seating the memory print and re-downloading the application — an estimated eight to ten hours of unit downtime. Substituting a pre-loaded 10012/1/2 from the critical spares store changed the sequence to a controlled rack power-down, card exchange in the 4 TE slot, power-up and watchdog verification. The unit was back in its safe state and ready to start in under ninety minutes. Beyond the avoided production loss, the measurable gain was in the safety audit trail: because 10012/1/2 holds the application in flash, there was no ambiguity about whether the running logic matched the validated version, which is precisely the question a functional safety assessor asks after any processor replacement.
Case 2 — LNG regasification terminal, phased safety system modernization. At a large LNG import terminal, the safety system on one train comprised fourteen FSC controllers across seven substations — one per substation for emergency shutdown, one for the depressurizing system — all originally commissioned in the early 2000s and integrated to the plant DCS over the Universal Control Network. Operators were carrying 10012/1/2 and companion FSC cards as critical spares purely to keep the installed system viable while the modernization project was scoped. That spares posture bought the time for a phased migration: application conversion done off-site, each substation converted one at a time during planned windows, FSC I/O and all field wiring retained. Plants taking this route report a 30% faster controller scan rate and roughly 50% fewer controller modules after migration — but none of that is achievable if the legacy CPU fails first. In both cases the industry value is the same: 10012/1/2 converts an unplanned safety system outage into a scheduled card swap, protecting production, protecting the validated safety application, and giving the plant control of its own migration timetable.






