Description
Triconex 3625 32-Channel 24VDC Supervised Digital Output TMR Module for Tricon SIS
Product Description
The Triconex 3625 is a high-density triple modular redundant digital output module built for the Tricon Safety Instrumented System. It converts voted safety logic commands from the Tricon main processor triplet into 24VDC field drive signals for solenoid valves, ESD actuators, interlock relays and fire/gas alarm loads. This module supports two configurable operation modes: supervised mode and non-supervised mode. In supervised mode, the module provides continuous field-loop diagnostics to detect open load, short circuit, missing load and loss of field power, greatly improving diagnostic coverage for SIL safety loops. It adopts 2oo3 TMR voting architecture with quadruplicated output voter circuitry; single leg hardware faults are isolated and will not trigger undesired actuator action. Hot-swap replacement is available within a healthy Tricon rack, allowing maintenance without safety system shutdown. It requires matched Tricon field terminal assemblies for field wiring termination.

TRICONEX 3625
Technical Specifications
- Brand: Triconex (Schneider Electric / Invensys Legacy)
- Model: 3625
- Module Type: Digital Output (DO) Module
- Architecture: TMR Triple Modular Redundancy, 2oo3 voting
- Channel Count: 32 commoned-return output channels
- Nominal Field Output: 24 VDC
- Operating Voltage Range: 16–32 VDC, max transient 36 VDC
- Channel Rating: 1.7 A continuous per channel; 7 A surge for 10 ms
- Minimum Load Requirement: 10 mA (required for supervised diagnostics)
- Max Load Leakage: 4 mA
- Isolation: 1500 VDC optical isolation per point
- Diagnostic Modes: Supervised / Non-supervised configurable; open load, short circuit, field power loss, module self-test, leg fault detection
- Status Indicators: Per-channel ON/OFF LED; module PASS, FAULT, LOAD, ACTIVE LEDs
- Backplane Interface: Tricon dedicated I/O bus
- Hot Swap: Supported when Tricon rack and processor triplet are in PASS state
- Operating Temperature: 0 °C to +60 °C
- Storage Temperature: -40 °C to +85 °C
- Relative Humidity: 5%–95%, non-condensing
- Safety Certification: SIL 3 capable per IEC 61508, ATEX Zone 2, UL, CE
- Compatibility: Tricon 7-slot / 15-slot main and expansion chassis
- Power Source: Powered via Tricon chassis backplane
Application Scenarios
- Petrochemical and refinery ESD emergency shutdown solenoid valve control
- Onshore and offshore oil & gas fire and gas safety actuator tripping
- Power plant boiler protection, turbine trip and burner management safety relays
- LNG terminal and cryogenic plant SIL 3 safety shutdown output control
- Unmanned pipeline safety cabinet solenoid and alarm output driving
- Chemical process plant cascaded safety interlock and trip relay control
- Hazardous Class I Div 2 / Zone 2 SIS control panels
- Spare replacement and maintenance of existing Tricon SIS installations
8 Related Triconex Model Recommendations
- 3624 – 16-Channel 24VDC Supervised Digital Output Module
- 3623 – 16-Channel 120VDC Supervised Digital Output Module
- 3503E – 32-Channel 24VDC Digital Input Module
- 3805E – Tricon Main Processor Module
- 3703E – 8-Channel Analog Input Module
- 3704E – 8-Channel Analog Output Module
- 4351B – Tricon Communication Module TCM
- 8311 – 24VDC Input Tricon Power Supply
Compatibility & Installation Pitfalls
Compatibility
- Designed exclusively for Tricon TMR chassis; not compatible with Trident racks or Bently Nevada 3500 racks.
- Requires Tricon 3805E processor triplet and matching chassis firmware revision.
- Commoned-return output design; cannot be substituted for isolated-output DO modules.
- Supervised diagnostics demand a minimum 10 mA field load; low-current loads may disable loop supervision.
- Application logic and I/O configuration reside in the Tricon main processor, not locally on the 3625.
- Must pair with the correct Tricon terminal assembly; mismatched termination units cause diagnostic failures.
Installation Pitfalls
- Hot-swap is permitted only with all three Tricon processors online and in PASS status. Never perform hot-swap during active safety trips or processor faults.
- Supervised mode requires minimum load current; solenoids with extremely low coil resistance or tiny pilot valves may fail load detection.
- Field 24VDC output wiring must be segregated from high-power VFD and AC cables to avoid EMI-induced false energization.
- The module diagnostics detect field circuit faults, but they cannot verify mechanical actuator valve integrity; periodic proof-test of solenoids and valves remains mandatory.
- Do not exceed the 1.7 A continuous per-channel rating; overcurrent will trigger load faults and may damage output circuits.
- Mechanical keying prevents insertion into processor, power or communication slots; never force the module into non-I/O slots.
- Reverse field power polarity at terminals will impair supervised loop diagnostics and may damage channel circuitry.
- Firmware mismatch between the 3625 and processor triplet can disable load supervision and TMR voting functions.

TRICONEX 3625
Standard Operating Procedure (SOP)
SOP for 3625 Digital Output Module Inspection, Installation and Functional Test
- Pre-Installation Inspection Inspect the module for physical damage, bent connectors or contamination. Confirm the part number 3625 and verify compatibility with the selected terminal assembly and Tricon firmware. Review actuator load data and confirm each load meets the 10 mA minimum requirement if supervised mode is enabled. Apply lockout-tagout to associated output solenoid circuits if the module controls critical ESD functions.
- Rack Installation Power down the chassis if replacing the only active module for a critical safety loop. Insert the 3625 into the designated I/O slot and secure module fasteners. Connect the ribbon cable between the module and field terminal assembly. Terminate 24VDC solenoid and relay wiring at terminals. Separate discrete output wiring from high-energy power cables and implement shielding per approved SIS documentation.
- Software Configuration Open TriStation and connect to the Tricon rack. Add and map the 3625 within the system I/O configuration. Select supervised or non-supervised mode per SIL requirement specification. Configure fault alarm handling for load detection faults. Download the validated safety application to the 3805E processor triplet and resolve firmware or configuration mismatch alarms. Archive the I/O configuration for IEC 61508 audit traceability.
- Channel and Diagnostic Test Force each output channel ON and OFF from TriStation and confirm corresponding actuator or relay state changes. Simulate open load and short-circuit field conditions to validate supervised load fault alarms. Confirm TMR voting suppresses single leg faults and prevents unintended energization. Record channel response and diagnostic performance in the SIS maintenance log.
- System-Wide Interlock Verification Trigger safety input trip conditions and confirm the Tricon drives the 3625 outputs to the required de-energized safe state. Confirm single module or leg faults only raise maintenance alarms and do not cause undesired actuator operation. Verify trip status propagates correctly to HMI and peer systems.
- Return to Service Clear temporary fault latches and alarm acknowledgements. Remove lockout-tagout as applicable. Monitor channel health and load fault status through the required observation period. Notify operations that the Tricon digital output module is in service.
- Periodic Maintenance and Replacement During planned outages, inspect terminal torque, cable insulation and solenoid coil condition. Perform full channel proof-test and supervised load fault testing per site SIS schedule. If the 3625 reports persistent non-resettable leg faults, confirm the Tricon processor triplet is fully healthy before hot-swap. After replacement, recheck all channels and load diagnostics before releasing the module to safety duty.


