Use of NUMARC/EPRI TR-102348, Guideline on Licensing Digital Upgrades, in Determining the Acceptability of Performing Analog-To-Digital Replacements Under 10 CFR 50.59 (Generic Letter 95-02)
April 26, 1995
|NRC GENERIC LETTER 95-02:||USE OF NUMARC/EPRI REPORT TR-102348, "GUIDELINE ON LICENSING DIGITAL UPGRADES," IN DETERMINING THE ACCEPTABILITY OF PERFORMING ANALOG-TO-DIGITAL REPLACEMENTS UNDER 10 CFR 50.59|
All holders of operating licenses or construction permits for nuclear power reactors.
The U.S. Nuclear Regulatory Commission (NRC) staff is issuing this generic letter to inform addressees of a new staff position on the use of Nuclear Management and Resources Council/Electrical Power Research Institute (NUMARC/EPRI) Report TR-102348, "Guideline on Licensing Digital Upgrades," dated December 1993, as acceptable guidance for determining when an analog-to- digital replacement can be performed without prior NRC staff approval under the requirements of Section 50.59 of Title 10 of the Code of Federal Regulations (10 CFR 50.59). The report applies to all digital equipment that uses software and, in particular, to microprocessor-based systems. The report, together with the clarifications discussed in this generic letter, represents a method acceptable to the staff for use in making a determination of whether or not an unreviewed safety question exists with respect to 10 CFR 50.59 requirements. It is expected that recipients will consider the information in this generic letter when performing analog-to-digital instrumentation and control systems replacements. However, suggestions contained in this generic letter are not NRC requirements; therefore, no specific action or written response is required.
Description of Circumstances
The age-related degradation of some earlier analog electronic systems and the difficulties in obtaining qualified replacement components for those systems, as well as a desire for enhanced features such as automatic self-test and diagnostics, greater flexibility, and increased data availability have prompted some operating reactor licensees to replace existing analog systems with digital systems. After reviewing a number of these digital system replacements and digital equipment failures in both nuclear and non-nuclear applications, the staff has identified potentially safety-significant concerns pertaining to digital systems in nuclear power plants. The concerns of the staff stem from the design characteristics specific to the new digital electronics that could result in failure modes and system malfunctions that either were not considered during the initial plant design or may not have been evaluated in sufficient detail in the safety analysis report. These concerns include potential common mode failures due to (1) the use of common software in redundant channels, (2) increased sensitivity to the effects of electromagnetic interference, (3) the improper use and control of equipment used to control and modify software and hardware configurations, (4) the effect that some digital designs have on diverse trip functions, (5) improper system integration, and (6) inappropriate commercial dedication of digital electronics.
As a result of the above concerns, the NRC staff issued a draft generic letter for public comment in the Federal Register (57FR36680) on August 14, 1992, wherein a position was established that essentially all safety-related digital replacements result in an unreviewed safety question because of the possibility of the creation of a different type of malfunction than those evaluated previously in the safety analysis report. The staff concluded, therefore, that prior approval by the NRC staff of all safety-related digital modifications was necessary. However, subsequent discussions and comments on the draft generic letter have resulted in the staff position as described in this letter.
To assist licensees in effectively implementing digital replacements by addressing the concerns indicated above and in determining which upgrades can be performed under 10 CFR 50.59 without prior NRC staff approval, Report TR- 102348 has been published. The NRC staff reviewed and provided comments on this report while it was in draft form, and the final report reflects a coordinated effort between industry and the NRC staff. The NRC staff believes that, when properly implemented, modern digital systems offer the potential for greater system reliability and enhanced features such as automatic self- test and diagnostics, as well as greater flexibility, increased data availability, and ease of modification.
Report TR-102348 contains guidance that will assist licensees in implementing and licensing digital upgrades in such a manner as to minimize the potential concerns indicated above. It describes actions to be taken in the design and implementation process to ensure that the digital upgrade licensing and safety issues are addressed, and ways to consider these issues when performing the 10 CFR 50.59 evaluation. It is not the intent of the report or of the NRC staff to predispose the outcome of the 10 CFR 50.59 process, but rather to provide a process that will assist licensees in reaching a proper conclusion regarding the existence of an unreviewed safety question when undertaking a digital system replacement. However, as shown in Example 5-6 of the report, when using this document as guidance for the analysis of modifications of some safety-significant systems such as the reactor protection system or an engineered safety feature system, it is likely these digital modifications will require staff review when 10 CFR 50.59 criteria are applied. Report TR- 102348 states in the introduction that the guidance is supplemental to and consistent with that provided in NSAC-125, "Guidelines for 10 CFR 50.59 Safety Evaluations." Licensees should bear in mind that NSAC-125 has not been endorsed by the NRC, and therefore any use of those guidelines is advisory only, and that nothing in NSAC-125 can be construed as a modification of 10 CFR 50.59. While the guidelines of NSAC-125 can be useful in the evaluation of systems, and are representative of logic used in making a 10 CFR 50.59 determination, the actual determination of whether or not an unreviewed safety question exists must be done in accordance with 10 CFR 50.59.
10 CFR 50.59(a)(2)(i) and (ii) states that a proposed change, test or experiment involves an unreviewed safety question if the probability or consequences of an accident or malfunction previously evaluated in the safety analysis report may increase, or if the possibility for an accident or malfunction of a different type than any previously evaluated in the safety analysis report may be created. If during the 10 CFR 50.59 determination there is uncertainty about whether the probability or consequences may increase, or whether the possibility of a different type of accident or malfunction may be created, the uncertainty should lead the licensee to conclude that the probability or consequences may increase or a new type of malfunction may be created. If the uncertainty is only on the degree of improvement the digital system will provide, the modification would not involve an unreviewed safety question. If, however, the uncertainty involves whether or not this modification is more or less safe than the previous analog system, or if no degree of safety has been determined, an unreviewed safety question is involved.
The staff believes that two clarifications to Report TR-102348 are appropriate as follows:
EPRI Report TR-102348, together with the clarifications discussed in this generic letter, can be used as guidance by licensees in both designing analog- to-digital replacements and, with respect to unreviewed safety question determinations, determining if an analog-to-digital replacement can be performed under 10 CFR 50.59 without prior staff approval.
This generic letter requires no specific action or written response. If you have any questions about this matter, please contact the technical contact listed below or the appropriate Office of Nuclear Reactor Regulation project manager.
original signed by S.A. Varga
Roy P. Zimmerman
|Technical contact:||Paul J. Loeser, NRR
|Lead project manager:||Robert M. Pulsifer, NRR