Risk + Safety + AMC

Functional Safety Assessment

IEC 61508 and IEC 61511 safety lifecycle · safety instrumented functions defined, verified and evidenced.

A safety integrity level is a claim about how reliably a protective function will act when demanded. We define the safety instrumented functions, calculate the probability of failure on demand from device data and architecture, and verify that the achieved integrity supports the level being claimed.

25 marquee operators · 21 countries · verified roster
Bayer · Pfizer · TATA · Adani · JSW · ISRO · Siemens · Bosch · DuPont · Mahindra · Hindalco · and others
Bayer
Pfizer
TATA
Adani
JSW
Nestle
ISRO
Mahindra
Siemens
Bosch
DuPont
Aditya Birla
Hindalco
Amazon
Indian Oil
ITC
Asian Paints
Dr. Reddy
Kia
Bureau Veritas
Lloyd
Halliburton
Jindal Steel
AMNS
Rolls Royce
Bayer
Pfizer
TATA
Adani
JSW
Nestle
ISRO
Mahindra
Siemens
Bosch
DuPont
Aditya Birla
Hindalco
Amazon
Indian Oil
ITC
Asian Paints
Dr. Reddy
Kia
Bureau Veritas
Lloyd
Halliburton
Jindal Steel
AMNS
Rolls Royce
Why this matters

Why do safety instrumented functions fail to achieve their claimed SIL?

Usually not because the logic solver is inadequate. A safety instrumented function is a complete path · sensor, logic solver, final element · and the probability of failure on demand is dominated by whichever element is weakest. In practice that is almost always the final element. A certified SIL 3 logic solver in series with a single ordinary shutdown valve, on a proof test interval that has quietly slipped, does not deliver SIL 3, and the certificate on the logic solver says nothing about the loop.

The second cause is proof testing. PFD is a function of dangerous undetected failure rate and test interval, so an assumed one-year interval that is actually performed every three years multiplies the calculated figure. A test that exercises the logic but does not stroke the valve is not the test the calculation assumed. Integrity claimed at design and integrity achieved in operation diverge quietly, and the divergence is only visible if someone recalculates against what is actually being done.

The third is scope. IEC 61508 and IEC 61511 describe a lifecycle, not a calculation. Verification of a number satisfies one clause of it.

Method

How we deliver Functional Safety Assessment

IEC 61508 and IEC 61511 safety lifecycle · SIF definition through verification and assessment · deliverables independently reviewed and signed by a Chartered Engineer. Routes to the Risk + Safety practice lead within 24 hours.

01

Safety requirement specification

Each safety instrumented function defined in full · the hazardous event it protects against, the process trip point, the safe state, the demand mode, the required response time, and the target SIL carried through from LOPA or risk graph. A calculation performed without a written SRS is verifying an assumption rather than a requirement.

02

Loop architecture and device review

The complete sensor, logic solver and final element path documented per function, with voting architecture, redundancy, common cause factors and diagnostic coverage identified. Manufacturer safety manuals and certificates reviewed against how the device is actually applied, since a certificate is issued for a stated configuration and use outside it invalidates the data.

03

PFD calculation and SIL verification

Probability of failure on demand computed per function from dangerous undetected failure rates, architecture, diagnostic coverage, proof test interval, proof test coverage and mission time. The result is checked against the SIL band, and architectural constraints on hardware fault tolerance are verified separately, since both must be satisfied.

04

Gap identification and remediation options

Where a function does not achieve target, the governing contributor is identified and the options are set out with their effect quantified · shorter or more complete proof testing, redundancy at the weak element, partial stroke testing on the final element, higher diagnostic coverage, or a change of device. The point is to show which change buys the integrity, not to list all of them.

05

Functional safety assessment and lifecycle evidence

An assessment against the lifecycle phases in scope, covering the SRS, design, verification, and the operation and maintenance requirements that carry the claim forward · proof test procedures, intervals, competence, and management of change. The output states what is required in operation for the SIL claim to remain valid.

Standards + compliance

Built to the standards your auditors quote

Assessments follow the functional safety standards for the process sector and the underlying generic standard. Every deliverable independently reviewed and signed by a Chartered Engineer (CEng MIE India).

Anonymous case anchors

What this looks like in production

Three landmark engagements from our verified roster · quantified outcomes, no client names disclosed without written permission.

Refinery, western India · SIS upgrade verification

Verification across a set of safety instrumented functions carried out of a LOPA study during an SIS upgrade. The functions that failed to achieve target were governed by final element performance and proof test interval rather than by logic solver capability, which redirected the upgrade scope.

Gas processing facility, GCC · proof test interval review

Recalculation of PFD against proof test intervals as actually executed rather than as assumed at design. Several functions were shown to be operating outside the integrity claimed, and were restored by revising test scope and frequency rather than by hardware change.

Pharmaceutical utilities, South Asia · SRS reconstruction

Safety requirement specifications reconstructed for legacy functions that had never had one, establishing trip points, safe states and response times before any verification was attempted.

Frequently asked

Functional safety and SIL · the questions instrumentation leads ask

What is the difference between IEC 61508 and IEC 61511?
IEC 61508 is the generic functional safety standard and applies principally to those who design and manufacture safety-related devices and systems. IEC 61511 is its application to the process industry sector and is the standard an operating plant works to. In practice an end user follows IEC 61511 for the safety lifecycle of the installation, while device certification and hardware failure data trace back to IEC 61508. Where a device is applied outside its certified configuration, the end user carries the burden of justifying it.
How is probability of failure on demand calculated?
PFD average is derived from the dangerous undetected failure rate of each element, the loop architecture and voting arrangement, diagnostic coverage, the proof test interval, how completely the proof test exercises the element, and mission time. The elements are combined across the sensor, logic solver and final element to give the loop figure, which is then compared against the SIL bands. The parameters that most often move the result are proof test interval and proof test coverage, both of which are operational rather than design choices.
What SIL do we actually need?
SIL is not selected, it is determined by the risk gap. LOPA is the usual method · the unmitigated event frequency is compared against the tolerable frequency in your corporate risk criteria, credit is taken for each independent protection layer, and the residual gap is what the instrumented function must close. Risk graph is used as a faster screening approach. Specifying a SIL before determining it typically results in over-specified functions that are expensive to prove and to maintain.
Why does the final element usually govern the calculation?
Because a valve is a mechanical device in process service and it fails dangerously more often than the electronics do, while its failures are also less likely to be revealed by diagnostics. A logic solver reports its own faults continuously; a shutdown valve that has seized will not announce it until demanded or until it is stroked. This is why partial stroke testing is often the most effective single improvement available, and why a SIL claim resting on a certified logic solver alone does not survive verification.
Does a certified SIL 3 device give us a SIL 3 loop?
No. The certificate applies to the device in a stated configuration, and the safety integrity level applies to the whole safety instrumented function from sensor through logic solver to final element. The loop achieves whatever the combination of all three, its architecture, its diagnostics and its proof test regime supports. A SIL 3 certified component in a loop whose valve and test interval support SIL 1 gives a SIL 1 function.
What has to happen after the assessment for the SIL claim to stay valid?
The operational requirements the calculation assumed must actually be carried out · proof testing at the assumed interval and to the assumed coverage, with results recorded; bypasses and overrides controlled and time-limited; failures recorded so demand and failure rates can be reviewed against the assumptions; competence maintained for those operating and maintaining the system; and any change routed through management of change with the effect on the function assessed. A SIL verification is a statement about a system under stated conditions, and it lapses quietly when those conditions stop being met.

Scope your Functional Safety Assessment engagement.

Tell us your plant, region, and scope · a named Chartered Engineer responds within 24 hours.

  • 4 fields. No phone interview to start.
  • Per-discipline routing to the Risk + Safety + AMC practice lead.
  • Anonymous case anchors sent with first reply.
  • Same-day callback for deadline-driven enquiries.

Risk + Safety + AMC Scoping

HAZOP/LOPA/SIL/QRA · 5-year AMC retainer · Practice Lead Safety responds in 24 hr.