In my view your statement is due to misunderstanding of process design rules.
By definition the "Design" conditions shall cover all of the operating cases such as normal, start-up, shut down and upset conditions. Setting design conditions belong to "
Passive" protection concept while the instrumentation is "
Active" in nature. These two corrective actions belong to two
different layers of protection. So statements like what you said (simultaneous occurance of two unrelated causes (cooling failure and instrument malfunction) are wrong.
Let us raise a similar case study:
Consider two pressure vessels with different design pressure values which are connected together through liquid outlet line from the first vessel (a typical example can be gas sweetening plants and absorber tower and downstream flash separator)
In this case based on your justification we can rely on proper operation of instrumentation at the onset of very low liquid level for the absorber and ignore about level control valve failure for downstream flash gas separator BUT as you know we never ignore about this contigency. Do you confirm? (In this case process shutdown due to very low liquid level belongs to active protection philosophy while considering level control valve failure belongs to passive protection philosophy and can not be mixed up together)
Am I specific now?!

Be informed,the Integrated Plant Control System (IPCS) consists of
control systems and
safety systems.
In the case of any malfunction of the plant equipment the
safety systems will bring automatically the relevant units or part of the units to a safe condition.
The lowest level of protection (among
safety systems) generally acts as an additional loop that protects and/or trips equipment.
Contrary to your statement and as i mentioned earlier,relying on HH alarm by TI-4012 that closes a SDV is not relying on proper operation of instruments that are covered by
Control Systems.
TI-4012 and relevant SDV are instruments belong to
Safety Systems (not belong to
Control System, as you think) and depending on the condition should have proper SIL certification to cope with expected malfunctions.
Per above,LCV,you mentioned as an example,is among
Control System and doesn't relate to current discussion.