A burner management system, or BMS, is the safety system that governs anything with a flame - a fired heater, a boiler, an incinerator, a flare pilot. Its purpose is narrow and vital: make sure fuel and ignition only ever come together safely, and cut the fuel instantly if they do not. It exists because the most dangerous moments for fired equipment are lighting it and losing the flame. This guide explains how a BMS works and where it fits in oil and gas.
Burner Management System (BMS) in one line: A burner management system (BMS), also called a flame safeguard system, is a safety system that manages the safe start-up, operation, and shutdown of fuel-fired equipment. It enforces a purge of the firebox before ignition, sequences a controlled light-off, continuously supervises the flame, and trips the fuel supply through safety shutoff valves if any unsafe condition occurs - no flame, low fuel pressure, or loss of combustion air. It is governed by standards such as NFPA 85 and NFPA 86 and is kept independent of combustion control.
The two most dangerous events for fired equipment are a furnace explosion at light-off (igniting fuel that has accumulated in the firebox) and a flame-out that keeps feeding fuel into a hot chamber. A BMS is engineered specifically to prevent both. Before any ignition, it forces a purge: combustion air is swept through the firebox for enough volume changes to clear out any accumulated fuel, and it will not permit light-off until that purge is proven complete.
Once purged, the BMS runs a strict light-off sequence - establish the pilot, prove its flame with a flame scanner, then admit main fuel and prove main flame - with permissives at every step. During normal firing it continuously supervises the flame with ultraviolet or infrared scanners. If it ever loses proof of flame, or sees low fuel pressure, high fuel pressure, or loss of combustion air, it executes a safety shutdown: the safety shutoff valves (double block and bleed on the fuel line) close and cut the fuel immediately.
Crucially, the BMS is kept independent of the combustion control system that modulates firing rate for temperature or steam demand. Combustion control optimizes the burn; the BMS only ensures it is safe. This separation mirrors the SIS-versus-BPCS principle, and BMS safety functions carry SIL requirements. The safety shutoff valves are fail-closed and proof-tested, because a valve that cannot close on demand defeats the entire system.
Fired equipment is everywhere in oil and gas, so BMS is too. Heater treaters and line heaters at well sites and tank batteries, glycol reboilers on dehydration units, process heaters and reboilers in gas plants and refineries, steam boilers, and thermal oxidizers and incinerators all need burner management. Even flare and vapor-recovery pilots rely on flame supervision to confirm the pilot is lit so that vented gas is actually being combusted.
The applicable standard depends on the equipment. NFPA 85 covers boilers and larger combustion systems; NFPA 86 covers ovens and furnaces; API and manufacturer standards apply to fired process heaters. Smaller field heaters may use a packaged flame-safeguard controller, while large plant heaters use a full safety PLC. In all cases the logic is the same: prove it is safe before you light it, watch the flame while it burns, and cut the fuel the instant it is not.
The BMS handles its trips locally and does not wait on a monitoring link. What SCADA adds is oversight of unattended and remote fired equipment: flame status, fuel pressures, trip alarms, and reason-for-trip. This matters at remote well sites where a heater-treater flame-out means a shutdown and possible freeze-up nobody is standing next to. A cloud SCADA such as Merobix reads that status over Modbus, DNP3, or OPC UA so operators are alerted and can dispatch a relight, while the burner-management safety logic remains fully independent.
Combustion control modulates the firing rate - adjusting fuel and air to hold a temperature or steam demand - and is a process-control function. The burner management system is a safety function: it enforces the purge and safe light-off, supervises the flame, and trips the fuel if anything unsafe occurs. The two are kept independent, so a fault in combustion control cannot disable the safety trips, mirroring the SIS-versus-control-system separation.
Because fuel can accumulate in the firebox - from a previous failed light-off or a leaking valve - and igniting that accumulated mixture causes a furnace explosion, one of the most destructive events in fired equipment. The purge sweeps combustion air through the firebox for a defined number of volume changes to clear any fuel before ignition is permitted. The BMS interlocks light-off so it cannot proceed until purge is proven complete.
It depends on the equipment. NFPA 85 covers boilers and larger combustion systems, NFPA 86 covers ovens and furnaces, and API and manufacturer standards apply to fired process heaters common in oil and gas. Across all of them the safety functions are designed to the functional-safety lifecycle with SIL targets, and the fuel safety shutoff valves are fail-closed and proof-tested on a schedule.
This page references the standards, specifications, and official documentation published by the organizations below. Editions, product capabilities, and documentation change over time - confirm current requirements and specifications directly with the source.
Last reviewed: July 27, 2026. Merobix is not affiliated with, endorsed by, or sponsored by these organizations; their names are used only to identify the standards and products discussed.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.