Fired Equipment & BMS Upgrade Program

Do you know your fired equipment risk — across every site, right now?

Most multi-site operators can’t answer that with confidence. aeShield brings real-time, enterprise-wide risk management to every Burner Management System you own — so gaps don’t stay hidden until an incident finds them.

Talk to our team → See how the program works ↓
Ask yourself
?Do you have a lot of fired devices across your corporation?
?Is your risk analysis actually solid?
?Are you sure you don’t have risk gaps?

If you hesitated on any of those, you’re not alone. Fired equipment risk is typically assessed fired device by fired device, then filed away until the next PHA cycle — a snapshot that’s already stale the moment it’s signed off. What you need is real-time, enterprise-wide risk management for every Burner Management System you own, not a periodic study.

A “risk gap” usually isn’t one dramatic failure. It looks like this:

Late or missed proof tests
Excessive bypassing
Excessive demand rates
Excessive BMS field device failures

Each of those, on its own, can look like a little bit of drift — not enough to trip an alarm by itself. Aggregated at each fired device and across your enterprise, though, they add up to a portfolio that no longer meets your own corporate risk criteria. Most companies only find that out during an incident investigation.

What if this were live, in real time, on an enterprise-wide dashboard instead?
“Every site can show you a study. Almost none can show you the whole fleet.” — Recurring finding across corporate Process Safety Study reviews
Root cause

Three gaps behind every inconsistent ranking

1

Different facilitators, different assumptions

Occupancy counts, frequency data, and judgment calls vary study to study, with no shared reference.

2

No standard consequence model

In practice, almost no one runs actual blast modeling. Consequence selection comes down to the loudest voice in the room — so identical unit operations end up with wildly different rankings.

3

No enterprise equipment inventory

Risk analysis runs fired device by fired device, site by site, with no company-wide list to compare against.

The result: funding paralysis. When Boiler #1 comes back “fine” and Boiler #7 — the same unit operation — comes back with a huge risk gap, management has no consistent basis to act on. Even when the gap at Boiler #7 is real, it’s hard to justify spending real money there while an identical unit down the road needs nothing. Without a shared, defensible consequence basis, that inconsistency itself becomes the reason funding is delayed and risk gaps are carried in the portfolio longer than necessary.

Work smarter, not harder

A five-step corporate program — same rigor, lower cost, every site.

1

Survey the fleet

One inventory of every fired device, every site.

2

Corporate standard

One risk analysis method, applied consistently.

3

Standardized ranking

Blast-modeling-based consequence selection.

4

Templatized design

One design per risk tier, reused fleet-wide.

5

Performance monitoring

Ongoing KPIs to flag bad actors early.

Try the Blast Radius Calculator

Standardized ranking

Combustion chamber volume, fuel, frequency, occupancy

Enter chamber volume and loss-of-flame scenario, and see the fatality radius, collapse radius, and resulting BMS SIL targets update live — the same four-input consequence basis every facilitator, every site, can apply consistently.

Consequence selection driven by engineering rigor, not the loudest voice in the room — so the same risk gets the same rank, whoever's facilitating and wherever the unit sits.

Launch calculator →
64 ft
Fatality radius
36 ft
Collapse radius
SIF-001SIL 2
SIF-003SIL 2
SIF-005SIL 1

One expert system. Every BMS template, built once.

Expert system approach

Design once. Apply to every similar fired device.

aeShield’s expert system codifies your corporate standard into a reusable, digitally enabled BMS design template for each unit operation — so every similar fired device, at every site, gets the same defensible design instead of starting from a blank page. Fewer engineering hours per site, faster execution, and one consistent basis instead of one bespoke design per fired device.

Bulk-load your instrumentation data, press the button, and in minutes every deliverable is finished — consistent, high quality, and digital from the start. It’s the transition from dumb, static BMS designs to data-driven solutions: ready to be connected via API to the real world, monitoring assumed BMS performance against actual field data and flagging real risk gaps as they emerge, instead of gathering dust until the next audit.

Talk to our team →
Generated automatically, per risk tier
SIF list✓ Included
SRS (Safety Requirements Specification)✓ Included
C&Es (Cause & Effects)✓ Included
SIL verification calculations✓ Included
Proof test plans✓ Included
The business case

How do we get this funded?

A site rarely funds an enterprise risk program on its own budget line. What gets funded is a hard, defensible ROI case built on test interval optimization — taken to your Digital Transformation team, not just the site. That's the case that pays for the whole program.

1

Collect

Keep testing on today's schedule — just capture demand rates, bypasses, device failures, and proof-test results as you go.

2

Analyze

aeShield's SIL engine turns that real history into statistical, prior-use evidence — not generic industry tables.

3

Extend

Qualifying instruments shift to longer proof-test intervals — fewer tests per year, full audit trail.

NFPA 85, 86 & 87 compliance: necessary, but not sufficient

All three codes set a genuine, prescriptive minimum — typically a SIL 2 logic solver and a fixed, calendar-based proof-test interval, regardless of your unit's actual occupancy, demand rate, or failure history. That schedule assumes a generic device population, not your equipment's real duty cycle.

What compliance guarantees
  • A recognized, consensus-based minimum design
  • Prescribed interlocks and purge sequences
  • A legally defensible baseline in most jurisdictions
What it doesn't guarantee
  • That risk is actually reduced to a tolerable, quantified level
  • That the achieved SIL matches what the scenario requires
  • That your corporate TMEL is actually being met
What actually justifies a longer proof-test interval isn’t the code — it’s your own field data, statistically showing the device outperforms the generic assumption behind that schedule. That’s exactly what Collect and Analyze, above, produce.
Prescriptive to data-driven testing

Optimize testing intervals — without adding new testing

This isn’t asking you to test more field devices. It’s about collecting and analyzing the data from the testing you’re already doing — and using it to move off prescriptive, calendar-based intervals onto a data-driven basis. That evidence is what lets you safely optimize test intervals (including extending them where the data supports it) while proving, with the data itself, that you’re still safe.

Build a 12-year NPV model bottom-up from your own crew, rates, and test intervals — and see exactly how the program pays for itself, with savings that compound every year the program runs.

Launch calculator →
$717K
Total savings, 12-yr NPV
44%
ROI (savings ÷ baseline spend)
Baseline 12-yr spend (NPV)$1.64M
Optimized 12-yr spend (NPV)$810K
PaybackYr 3
Default scenario: 100 BMS units, 15 instruments/BMS, extending 12→36 mo test interval. Your results depend on your own fleet size and inputs.
$

Save money

Hard, compounding savings from testing fewer instruments per year — not a soft, hand-wavy estimate.

Ensure compliance

Auditable, data-driven test intervals defensible against IEC 61511 and NFPA 85/86/87 — not generic industry tables.

Make it safer

Real-time enterprise risk visibility and live barrier health — the same data powering the savings case.

Compliance generates data Data drives savings Savings fund the safety program

FSE200: Introduction to Burner Management Systems

FSE200
2 days · 9:00am–5:00pm UTC-5
Delivered via Microsoft Teams
$1,600/student
Reserve your seat →

Applied training, taught by the standard’s co-author

A thorough overview of BMS unit operation and the process safety hazards behind it — built around a single-burner gas-fired steam boiler and its full operating cycle (pre-fire, purge, light-off, normal operation, post-purge).

BMS unit operationCodes & standardsIEC 61511 for BMS O&M requirementsCombustion hazardsLOPA group exercise SIL verification calcsSafety performance assessment
Instructor — Mike Scott, PE, CFSE · CEO of aeShield, 30+ years with fired equipment and safety instrumented systems · Co-Chairman, ISA S84 Working Group on Burner Management Systems · IEC 61511 committee member · 7 patents · ISA Fellow
“Extremely informative to those unfamiliar with fired system operation, especially in deciding and assessing safety functions allocated to the BMS.” — W.R. Grace
Go deeper

White papers & resources

Placeholder titles below — swap in your actual white paper files/titles before publishing.

White paper

Critical instrumentation testing series

Technical deep-dives for process safety and instrumentation engineers.

White paper

PHMSA-cited compliance basis

What recent PHMSA incident findings mean for your BMS testing basis.

Webinar

BMS NFPA 85/86/87 compliance

Recorded session on building the compliance case for digital BMS lifecycle management.

Bottom line: not more spend — smarter, consistent spend that lowers cost and closes risk gaps at the same time.

Ready to standardize your BMS program?

Talk to our process safety team, or try either calculator first — no pressure either way.

Talk to our team →