Safety instrumented systems and SIL
Safety instrumented systems, layers of protection, SIL bands, LOPA-based SIL targets and PFDavg verification for 1oo1, 1oo2 and 2oo3 designs.
Drafted with Aria, reviewed by the AiCanCode.org team. Spotted an error? Use Give Feedback at the bottom of the page.
Why it matters
When control fails and a reactor overheats or a vessel over-pressures, the last automatic line of defence is the safety instrumented system (SIS). Accidents such as Bhopal, Texas City and Buncefield showed the cost of weak protective layers. Indian refineries, petrochemical and fertiliser plants design SIS to IEC 61511, and engineers who can calculate a SIL target and verify a design are in demand.
Key ideas
What an SIS is. An independent system of sensors, a logic solver and final elements (valves, motor trips) that takes the process to a safe state when a dangerous condition is detected. Each protective action is a safety instrumented function (SIF) — for example "close the feed valve and open the vent if reactor pressure exceeds 18 bar". The SIS is separate from the basic process control system (BPCS) so that a single fault cannot both cause the upset and disable the protection.
Layers of protection. Process design, BPCS control, alarms with operator response, the SIS, mechanical relief (relief valves, rupture discs), physical containment (dikes), and emergency response. Each independent protection layer (IPL) reduces the frequency of the hazardous outcome by its probability of failure on demand (PFD).
Standards. IEC 61508 is the generic functional-safety standard (and covers product certification); IEC 61511 is its process-industry application. Both use a safety lifecycle: hazard and risk analysis (HAZOP), allocation of safety functions to layers, a safety requirements specification (SRS), design, installation, validation, operation with proof testing, and management of change.
Safety integrity level (SIL). For a SIF in low-demand mode (demanded less than once a year — most process trips) the SIL is set by the average PFD:
- SIL 1: PFDavg 10⁻² to 10⁻¹ (risk reduction factor RRF 10 to 100)
- SIL 2: 10⁻³ to 10⁻² (RRF 100 to 1000)
- SIL 3: 10⁻⁴ to 10⁻³ (RRF 1000 to 10 000)
- SIL 4: 10⁻⁵ to 10⁻⁴ (RRF 10 000 to 100 000) — rarely used in process plants. High-demand or continuous-mode functions use the probability of dangerous failure per hour (PFH) instead. A SIL applies to a whole SIF, not to a single instrument.
Determining the SIL. Layer of protection analysis (LOPA) compares the mitigated event frequency with the tolerable frequency set by company risk criteria. The SIF must supply the remaining risk reduction. Risk graphs and risk matrices are simpler qualitative alternatives.
Verifying the design. PFDavg is calculated from the dangerous undetected failure rate λ_DU of each element, the proof-test interval T_I and the architecture (voting):
- 1oo1 — one device; any dangerous failure defeats it.
- 1oo2 — either of two devices can trip; safer, but more spurious trips.
- 2oo2 — both must agree; fewer spurious trips, less safe than 1oo1.
- 2oo3 — two of three; a good balance of safety and availability. Common-cause failures (same design, same process connection, same maintenance error) are represented by a β-factor and often dominate redundant designs. The design must also meet hardware fault tolerance (architectural) constraints and systematic-capability requirements.
Design practices. De-energise to trip (loss of power or signal gives the safe state); separate sensors and valves from the BPCS; diagnostics to convert undetected failures into detected ones; partial-stroke testing of valves; regular proof testing; strict bypass management.
Formulas
RRF = 1 / PFDavg
- RRF: risk reduction factor (dimensionless); PFDavg: average probability of failure on demand (dimensionless).
f_mitigated = f_initiating × PFD₁ × PFD₂ × …
- f: event frequencies (per year); PFDᵢ: PFDs of the independent protection layers other than the SIF.
PFD_SIF,required = f_tolerable / f_mitigated
PFDavg(1oo1) ≈ λ_DU·T_I / 2
PFDavg(1oo2) ≈ (λ_DU·T_I)² / 3 + β·λ_DU·T_I / 2
PFDavg(2oo3) ≈ (λ_DU·T_I)² + β·λ_DU·T_I / 2
PFDavg(2oo2) ≈ λ_DU·T_I
- λ_DU: dangerous undetected failure rate (per hour); T_I: proof-test interval (h); β: common-cause fraction. Valid when λ_DU·T_I ≪ 1; repair time neglected.
PFDavg,SIF = PFD_sensors + PFD_logic + PFD_final elements
Worked examples
Example 1 (standard) — SIL target by LOPA. A cooling-water failure (initiating frequency 0.2 per year) can cause a reactor runaway. Existing IPLs: a high-temperature alarm with operator response (PFD 0.1) and a relief valve (PFD 0.01). The tolerable frequency is 10⁻⁶ per year. Find the required SIL.
- f_mitigated = 0.2 × 0.1 × 0.01 = 2 × 10⁻⁴ per year.
- PFD_required = 10⁻⁶/(2 × 10⁻⁴) = 5 × 10⁻³.
- RRF = 1/(5 × 10⁻³) = 200.
- 5 × 10⁻³ lies between 10⁻³ and 10⁻², so the SIF must be SIL 2 (RRF ≥ 200).
Example 2 (GATE level) — verifying PFDavg. The SIF uses pressure transmitters (λ_DU = 1 × 10⁻⁶ per h), a certified logic solver (PFD = 1 × 10⁻⁴) and shut-off valves (λ_DU = 4 × 10⁻⁶ per h). Proof test interval T_I = 1 year = 8760 h. Find PFDavg and the achieved SIL for (a) 1oo1 sensor and 1oo1 valve; (b) 1oo2 sensors and 1oo2 valves with no common cause; (c) case (b) with β = 10 %.
- λT: sensor 1 × 10⁻⁶ × 8760 = 8.76 × 10⁻³; valve 4 × 10⁻⁶ × 8760 = 3.504 × 10⁻².
- (a) Sensor 8.76 × 10⁻³/2 = 4.38 × 10⁻³; valve 3.504 × 10⁻²/2 = 1.752 × 10⁻². Total = 4.38 × 10⁻³ + 1 × 10⁻⁴ + 1.752 × 10⁻² = 2.20 × 10⁻² → SIL 1 (fails SIL 2).
- (b) Sensors (8.76 × 10⁻³)²/3 = 2.56 × 10⁻⁵; valves (3.504 × 10⁻²)²/3 = 4.09 × 10⁻⁴. Total = 2.56 × 10⁻⁵ + 1 × 10⁻⁴ + 4.09 × 10⁻⁴ = 5.35 × 10⁻⁴ → SIL 3 range.
- (c) Add common cause: sensors 0.1 × 4.38 × 10⁻³ = 4.38 × 10⁻⁴ → 4.64 × 10⁻⁴; valves 0.1 × 1.752 × 10⁻² = 1.752 × 10⁻³ → 2.16 × 10⁻³. Total = 4.64 × 10⁻⁴ + 1 × 10⁻⁴ + 2.16 × 10⁻³ = 2.72 × 10⁻³ → SIL 2. Common cause, not the independent failures, now dominates; it meets the SIL 2 target of Example 1 (PFD ≤ 5 × 10⁻³).
Common mistakes
- Writing PFD = 1 − RRF. The correct relation is RRF = 1/PFD.
- Using λ·T instead of λ·T/2 for the average PFD of a 1oo1 element.
- Ignoring common-cause failure and claiming a SIL that the redundant design does not reach.
- Assigning a SIL to an individual transmitter rather than to the complete function.
- Using a BPCS transmitter or valve as part of the SIF without proving independence.
- Forgetting that a longer proof-test interval directly increases PFDavg.
For GATE IN
GATE treats this area through reliability: probability of failure for series and parallel (redundant) systems, availability, MTBF and failure rates, and simple voting logic such as 1oo2 and 2oo3. Practise computing system reliability from component reliabilities, PFD from failure rate and test interval, and converting PFD to RRF and SIL bands.
Quick check
- A SIF has PFDavg = 2 × 10⁻³. What are its RRF and SIL?
- A 1oo1 valve has λ_DU = 2 × 10⁻⁶ per h and is proof-tested yearly. What is its PFDavg?
- Which voting arrangement gives fewer spurious trips than 1oo2 while remaining tolerant of one dangerous failure?
- Why are SIS outputs usually de-energise-to-trip?
Answers: 1. RRF = 500, SIL 2. 2. About 8.76 × 10⁻³. 3. 2oo3. 4. So that loss of power, signal or a broken wire drives the process to the safe state.
Interview questions
All Process Control and Automation interview questionsTry answering each one aloud before you open it.
1.What is a Safety Instrumented System (SIS)?Concept
A Safety Instrumented System (SIS) is a system composed of sensors, logic solvers, and actuators designed to take the process to a safe state when predetermined conditions are violated. It is used to prevent hazardous events or to mitigate their consequences, ensuring the safety of personnel, equipment, and the environment.
2.Explain the concept of Safety Integrity Level (SIL).Concept
Safety Integrity Level (SIL) is a measure of safety system performance, in terms of probability of failure on demand (PFD). It is a discrete level (1 to 4) that corresponds to a range of PFD values, with SIL 4 being the most reliable and SIL 1 being the least. SIL is used to specify the safety performance requirements for SIS.
3.How is SIL determined for a Safety Instrumented Function (SIF)?Concept
SIL is determined through a risk assessment process that evaluates the potential hazards and the required risk reduction. The process involves identifying the hazards, assessing the risk, and determining the necessary risk reduction to achieve an acceptable level of safety. The SIL level is then assigned based on the required risk reduction.
4.Why is redundancy used in Safety Instrumented Systems?Application
Redundancy is used in Safety Instrumented Systems to increase reliability and reduce the probability of failure. By having multiple components performing the same function, the system can continue to operate safely even if one component fails. This is crucial for maintaining safety in critical processes.
5.What happens if a Safety Instrumented System fails during operation?Application
If a Safety Instrumented System fails during operation, it may not be able to perform its intended safety function, potentially leading to hazardous situations. To mitigate this risk, SIS are designed with redundancy and regular testing to ensure they are operational when needed. In case of failure, the system should ideally fail-safe, meaning it defaults to a safe state.
6.Explain the difference between a Basic Process Control System (BPCS) and a Safety Instrumented System (SIS).Concept
A Basic Process Control System (BPCS) is designed to control the normal operation of a process, ensuring efficiency and productivity. In contrast, a Safety Instrumented System (SIS) is specifically designed to take the process to a safe state in case of abnormal conditions. While BPCS focuses on process control, SIS focuses on safety and risk reduction.
7.Why is it important to regularly test Safety Instrumented Systems?Application
Regular testing of Safety Instrumented Systems is important to ensure they are functioning correctly and can perform their safety functions when required. Testing helps identify any faults or failures in the system components, allowing for timely maintenance and repairs to maintain the system's reliability and safety integrity.
8.Calculate the average probability of failure on demand (PFDavg) for a single (1oo1) safety device with a dangerous undetected failure rate of 0.01 per year and a proof-test interval of 1 year.Numerical
For a 1oo1 element the probability of being failed rises roughly linearly from zero after each proof test to λ_DU·T at the end of the interval, so its average is PFDavg ≈ λ_DU·T_I/2. Here PFDavg = 0.01 × 1/2 = 0.005, which corresponds to a risk reduction factor of 200 (SIL 2 range). Quoting λ·T = 0.01 gives the worst-case value just before the test, not the average used for SIL verification.
9.What is the role of a logic solver in a Safety Instrumented System?Concept
The logic solver in a Safety Instrumented System is responsible for processing input signals from sensors and making decisions based on predefined logic to activate actuators. It acts as the brain of the SIS, ensuring that the system responds appropriately to potential hazards by executing the necessary safety functions.
10.If a Safety Instrumented Function (SIF) has a required SIL 2, what is the range of its probability of failure on demand (PFD)?Numerical
For a Safety Instrumented Function (SIF) with a required SIL 2, the probability of failure on demand (PFD) should be in the range of 0.001 to 0.01. This range ensures that the SIF meets the reliability and safety performance required for SIL 2.
Finished this topic? Mark it so your progress, study plan and readiness keep up.
Stuck on something here?