IEC 61508 and IEC 61511, UK wide
Functional Safety and SIL Assessment
A trip that closes a valve on high pressure is a claim about reliability and somebody has to be able to prove the number behind it. AL23 Safety scopes and manages functional safety work to BS EN 61511 and BS EN 61508, from SIL determination through verification to proof test planning, for process operators UK wide.
What is a SIL assessment?
Risk reduction you can put a number on
Functional safety is the part of your protection that depends on something working when it is asked to work. A safety instrumented system is the sensor, the logic solver and the final element that together take the plant to a safe state. Each of those loops delivers a safety instrumented function and each function carries a target safety integrity level.
SIL is a property of the function, not of the device. A transmitter or a valve carries reliability data and a systematic capability rating. The SIL belongs to the loop as installed, tested and maintained. Buying a component described as SIL 2 does not give you a SIL 2 function.
A SIL assessment has two halves that are often confused. Determination asks how much risk reduction the function must deliver. Verification asks whether the design as built delivers it.
The four levels and the risk reduction behind them
Those figures apply to low demand mode, where the function is called on no more than once a year. In high demand or continuous mode the measure changes to average frequency of dangerous failure per hour and the bands shift accordingly.
Be careful with SIL 4. BS EN 61511 is written for the process sector and is aimed at SIL 1 to SIL 3. If a determination lands on SIL 4 the honest answer is almost never to build the loop. It is to change the process, reduce the inventory or add protection that does not depend on instrumentation.
SIL 1
Average probability of failure on demand between 0.1 and 0.01. A risk reduction factor of 10 to 100.
SIL 2
Average probability of failure on demand between 0.01 and 0.001. A risk reduction factor of 100 to 1,000.
SIL 3
Average probability of failure on demand between 0.001 and 0.0001. A risk reduction factor of 1,000 to 10,000.
SIL 4
Average probability of failure on demand between 0.0001 and 0.00001. A risk reduction factor of 10,000 to 100,000.
Who needs one
Anyone relying on instrumentation to prevent a major loss
- COMAH establishments where instrumented protective systems are claimed in the safety report as a technical measure
- Chemical, petrochemical, refining, oil and gas, LNG and LPG operations with pressure, temperature or level trips
- Anaerobic digestion, biogas and energy from waste plant with gas detection and shutdown functions
- Ammonia refrigeration in food and drink manufacturing
- Water treatment sites with chlorine or other gas dosing and their associated shutdown systems
- Pharmaceutical manufacturing with reaction runaway protection or solvent handling trips
- Any site where an overpressure protection claim rests on a high integrity pressure protection system rather than a relief device
- Any operator whose existing SIL study is old, undocumented or inherited with the asset
The regulations that apply
Your legal framework, in plain terms
No UK regulation names IEC 61508 or IEC 61511. HSE describes BS EN 61508 as the general benchmark of good practice for electrical, electronic and programmable electronic safety related systems. It describes BS EN 61511 edition 2 as the benchmark standard for the management of functional safety in the process industries. Neither standard is law. Both are relevant good practice against which inspectors judge whether general duties have been met, which in practice makes them very hard to argue against.
Health and Safety at Work etc. Act 1974, sections 2 and 3
The duty to protect employees and others so far as is reasonably practicable. Where a recognised standard exists, meeting it is the usual way of showing you have.
Management of Health and Safety at Work Regulations 1999, regulation 3
A suitable and sufficient risk assessment. A quantified integrity target is how that becomes specific for an instrumented protection layer.
Control of Major Accident Hazards Regulations 2015, regulation 5
All measures necessary to prevent major accidents and limit their consequences. The regulation 8 safety report must demonstrate this and the Competent Authority assesses control and instrumentation as a technical measure.
Dangerous Substances and Explosive Atmospheres Regulations 2002, regulation 6
Control and mitigation measures for explosive atmospheres, which frequently include instrumented gas detection and shutdown. The wider duty is covered on our DSEAR risk assessment page.
Provision and Use of Work Equipment Regulations 1998, regulations 18 and 22
Control systems must be safe and must fail to a safe condition. Maintenance must be possible without exposing people to risk.
Pressure Systems Safety Regulations 2000, SI 2000/128
Protective devices and the written scheme of examination, which is where an instrumented overpressure claim has to be reconciled with the relief case.
What the service covers
Determination and verification across the safety lifecycle
- SIL determination workshops using layer of protection analysis, taking cause and consequence pairs from your existing hazard study
- Calibration of the risk matrix and the tolerable risk criteria before any determination begins so the answers are yours rather than borrowed
- Independent protection layer challenge, testing each claimed layer for independence, specificity, dependability and auditability
- Review of conditional modifiers such as ignition probability and occupancy, where your method permits them, with the basis recorded
- Safety requirements specification for each safety instrumented function, covering the safe state, the process safety time and the trip settings
- SIL verification by calculation, covering average probability of failure on demand, average frequency of dangerous failure per hour and the effect of the proof test interval
- Architectural constraint checks, covering hardware fault tolerance and safe failure fraction, using route 1H or route 2H as appropriate
- Proof test procedure writing, with an honest statement of proof test coverage where a full test is not possible
- Functional safety assessment at the lifecycle stages and validation that the installed system meets the specification rather than the drawing
- Management of functional safety, covering competence, management of change and the operating and maintenance interfaces
- Gap analysis of an inherited or legacy SIS, including bypass and override management and demand rate recording
Our process
Score the risk, then prove the loop
- 01
Scope and criteria
We agree the boundary, confirm which hazard study feeds the work and calibrate the risk criteria with you before any scenario is scored.
- 02
Determination
We run the LOPA sessions with your process, operations and maintenance people in the room. The initiating event frequency and every layer credit is recorded with its justification.
- 03
Specification
We write the safety requirements specification for each function so the integrity target is tied to a defined safe state and a defined response time.
- 04
Verification
We model the loop against the target, test the architectural constraints and identify where the design falls short, where redundancy is needed and where the proof test interval is doing the work.
- 05
Lifecycle handover
We turn the findings into a proof test schedule, a competence requirement and a management of change trigger, then agree the review point.
What you get
Every number recorded with its justification
- A LOPA record for every scenario assessed, showing the initiating event, the layers credited, the modifiers applied and the resulting risk reduction requirement
- A SIL determination register listing each safety instrumented function with its target integrity level
- A safety requirements specification for each function, written to BS EN 61511 clause structure
- A SIL verification report with the calculation basis, the reliability data source and the assumed proof test interval stated openly
- Proof test procedures with the coverage claimed for each and a plain statement of what the test does not reveal
- A prioritised action plan separating design change, procedural change and evidence gaps, with owners and target dates
What we need from you
The hazard study, the drawings and the device data
- The existing hazard study, normally the HAZOP, with its cause and consequence records
- Piping and instrumentation diagrams, cause and effect matrices and trip schedules
- Your corporate risk matrix or tolerable risk criteria, if one exists
- Device data, including manufacturer failure rate data and any existing certificates
- Maintenance and proof test history, plus demand records and bypass logs where these are kept
Why AL23 Safety
We do not tune inputs to reach comfort
Accountable
If a claimed protection layer does not survive the independence test, we remove the credit and show you what that does to the number. We do not tune the inputs to reach a comfortable answer.
Specialist work, resourced honestly
Functional safety is a narrow discipline and we treat it as one. We scope the work, appoint the right specialist, interpret the results and turn them into an action plan you can actually deliver. The scope, the interpretation and the accountability stay with us.
Joined to the rest of your process safety case
The determination is only as good as the hazard study behind it, which is why we tie this work to your hazard analysis and, where relevant, to your COMAH demonstration.
UK wide
We support functional safety work for operators across the UK from our Manchester base, on single units and on whole sites.
Talk to us about functional safety
A straight answer on whether your SIL work would stand up
If you have inherited a SIL study you cannot defend or an inspector has asked how the proof test interval was chosen, describe the situation on a call. We will tell you what we would expect to find. No obligation and no pressure.
Common questions
Answers, up front
Cannot see your question? Get in touch and we will answer it directly.
Contact usCost follows the number of safety instrumented functions, the quality of the hazard study feeding the work and whether verification calculations are needed as well as determination. A workshop on twelve functions with a clean HAZOP behind it is a very different job from rebuilding a study on a site with no records. Tell us the function count and what documentation exists and we will scope it properly rather than quote blind.
Determination is usually a short series of workshops followed by a reporting period. Verification takes longer because it depends on reliability data and on confirming the as installed architecture, which often exposes drawings that no longer match the plant. We agree the programme before we start.
There is no statutory proof test interval in UK law and no fixed interval in the standard. The interval is whatever the average probability of failure on demand calculation assumed. Changing it invalidates the number. In practice full proof tests are often aligned to turnaround cycles, which is a convention rather than a rule. Where a full test is not possible, the proof test coverage must be reduced in the calculation. A partial test does not buy a full interval.
Almost never in the process sector. BS EN 61511 is written for SIL 1 to SIL 3. A result of SIL 4 is normally a signal that the underlying risk is too high to be managed by instrumentation. The correct response is to redesign, reduce inventory or add protection that does not depend on a loop working.
We keep the two services separate on purpose. HAZOP, HAZID and SWIFT are covered on our hazard analysis services page. A LOPA takes its cause and consequence pairs from that study. If you do not have one, that is the first job rather than this one.
BS EN 61508 parts 1 to 7 in the 2010 edition and BS EN 61511 in the edition 2 form adopted in the UK as BS EN 61511-1:2017. A third edition of IEC 61508 is in development and drafts are in circulation. No publication date is confirmed. We do not work to it and we would treat any supplier claiming compliance with a published edition 3 with caution.
Related services
