Description
Woodward 5437-076
Technical Specifications
- Product Type: Safety Protection / Voting Logic Module.
- System: ProTech GII Redundant Safety System.
- SIL Rating: SIL 3 capable (Safety Integrity Level).
- Voting Logic: Configurable for 1oo2, 2oo3, or TMR architectures.
Functional Features
- Redundant Safety: Provides multiple layers of protection against single-point failures.
- Voting Logic: Automatically isolates a faulty sensor channel and continues to provide safe protection.
- Self-Diagnostics: Continuously monitors its own health and the health of connected sensors.
- Trip Output: Drives redundant trip solenoids to shut down the turbine in an emergency.
Application Scenarios
Mandatory for high-value, high-speed rotating equipment where an uncontrolled overspeed event would be catastrophic, such as in utility-scale steam turbines and gas compressors.
Performance Parameters
- Response Time: Extremely fast trip response (<20ms typically).
- Spurious Trip Rate: Very low probability of false trips due to advanced voting logic.
- Dangerous Failure Rate: Ultra-low, meeting SIL 3 requirements.
Material Composition
Built with high-reliability, safety-rated electronic components. Redundant power supplies and communication paths are integrated into the module design.
Structural Characteristics
Standard ProTech GII module size, plugging into a redundant backplane. Features clear LED indicators for channel status, voting status, and trip conditions.
Working Principle
Receives inputs from three independent speed sensors. The internal voting logic compares the three signals. If two or more sensors indicate an overspeed condition, the module energizes the trip output, regardless of the third sensor’s reading. It also continuously checks for sensor failures and module faults.
Installation Requirements
Must be installed in a ProTech GII chassis with redundant power supplies. Sensor wiring must be run in separate, shielded conduits to prevent common-mode failures.
Usage Precautions
- Never perform maintenance on a live safety system without following strict lockout/tagout procedures.
- All configuration changes must be documented and authorized.
- Regular proof testing is required to maintain SIL certification.




