IEC 61508 and IEC 61511 safety lifecycle · safety instrumented functions defined, verified and evidenced.
A safety integrity level is a claim about how reliably a protective function will act when demanded. We define the safety instrumented functions, calculate the probability of failure on demand from device data and architecture, and verify that the achieved integrity supports the level being claimed.
Usually not because the logic solver is inadequate. A safety instrumented function is a complete path · sensor, logic solver, final element · and the probability of failure on demand is dominated by whichever element is weakest. In practice that is almost always the final element. A certified SIL 3 logic solver in series with a single ordinary shutdown valve, on a proof test interval that has quietly slipped, does not deliver SIL 3, and the certificate on the logic solver says nothing about the loop.
The second cause is proof testing. PFD is a function of dangerous undetected failure rate and test interval, so an assumed one-year interval that is actually performed every three years multiplies the calculated figure. A test that exercises the logic but does not stroke the valve is not the test the calculation assumed. Integrity claimed at design and integrity achieved in operation diverge quietly, and the divergence is only visible if someone recalculates against what is actually being done.
The third is scope. IEC 61508 and IEC 61511 describe a lifecycle, not a calculation. Verification of a number satisfies one clause of it.
IEC 61508 and IEC 61511 safety lifecycle · SIF definition through verification and assessment · deliverables independently reviewed and signed by a Chartered Engineer. Routes to the Risk + Safety practice lead within 24 hours.
Each safety instrumented function defined in full · the hazardous event it protects against, the process trip point, the safe state, the demand mode, the required response time, and the target SIL carried through from LOPA or risk graph. A calculation performed without a written SRS is verifying an assumption rather than a requirement.
The complete sensor, logic solver and final element path documented per function, with voting architecture, redundancy, common cause factors and diagnostic coverage identified. Manufacturer safety manuals and certificates reviewed against how the device is actually applied, since a certificate is issued for a stated configuration and use outside it invalidates the data.
Probability of failure on demand computed per function from dangerous undetected failure rates, architecture, diagnostic coverage, proof test interval, proof test coverage and mission time. The result is checked against the SIL band, and architectural constraints on hardware fault tolerance are verified separately, since both must be satisfied.
Where a function does not achieve target, the governing contributor is identified and the options are set out with their effect quantified · shorter or more complete proof testing, redundancy at the weak element, partial stroke testing on the final element, higher diagnostic coverage, or a change of device. The point is to show which change buys the integrity, not to list all of them.
An assessment against the lifecycle phases in scope, covering the SRS, design, verification, and the operation and maintenance requirements that carry the claim forward · proof test procedures, intervals, competence, and management of change. The output states what is required in operation for the SIL claim to remain valid.
Assessments follow the functional safety standards for the process sector and the underlying generic standard. Every deliverable independently reviewed and signed by a Chartered Engineer (CEng MIE India).
Three landmark engagements from our verified roster · quantified outcomes, no client names disclosed without written permission.
Verification across a set of safety instrumented functions carried out of a LOPA study during an SIS upgrade. The functions that failed to achieve target were governed by final element performance and proof test interval rather than by logic solver capability, which redirected the upgrade scope.
Recalculation of PFD against proof test intervals as actually executed rather than as assumed at design. Several functions were shown to be operating outside the integrity claimed, and were restored by revising test scope and frequency rather than by hardware change.
Safety requirement specifications reconstructed for legacy functions that had never had one, establishing trip points, safe states and response times before any verification was attempted.
Tell us your plant, region, and scope · a named Chartered Engineer responds within 24 hours.