On many sites there is a gap between a SIL target that was determined and a safety instrumented function proven to meet it. A workshop set SIL 2 against a trip years ago, the paperwork exists, and everyone assumes the loop delivers it. Nobody has since calculated the probability of failure on demand for the sensor, logic solver and final element as installed, checked whether the proof test interval being worked to matches the one assumed in the calculation, or confirmed that the valve fitted at commissioning is the one the architecture was based on.
That gap only shows up when someone looks, usually during an audit, an insurance review or an incident investigation. We provide functional safety support across the whole lifecycle for process manufacturers in the UK, from determining what protection is needed through to verifying that the installed system delivers it and keeping that demonstrable for the rest of its life.
What the work involves
A Safety Integrity Level is a measure of the performance required from a safety instrumented function so that it reduces process risk to a tolerable level. Levels run from SIL 1 to SIL 4, each corresponding to a required risk reduction factor and probability of failure on demand. The work divides into three connected activities, all carried out in line with BS EN 61511.
SIL determination establishes the target. It usually follows a LOPA, where a scenario has been analysed for initiating event frequency, independent protection layers and consequence, and the residual risk shows an instrumented function is required. We facilitate the determination workshop, using LOPA or risk graph methods, and record the reasoning behind each target.
SIL verification proves the target is met. We analyse the proposed or installed loop end to end, taking in sensor, logic solver and final element, and calculate whether it achieves the required probability of failure on demand given its hardware reliability, redundancy, diagnostic coverage, architectural constraints and proof test interval. Where it falls short, we set out what would close the gap and what each option costs.
SIL design and lifecycle support turns the requirement into hardware and documentation: component selection, safety logic, cause and effect, wiring architecture, test procedures and the safety requirements specification. We also support testing and commissioning, write proof test procedures and maintenance strategies, and help maintain safety lifecycle documentation from concept through to decommissioning.
What you get
- Facilitated SIL determination workshops, with target and reasoning recorded for each function
- LOPA studies where scenarios need quantifying before targets can be set
- Verification calculations covering failure rates, architecture, diagnostics and proof test intervals
- A clear statement of where installed loops meet their targets and where they do not
- Safety requirements specifications, safety logic, cause and effect diagrams and design documentation
- Proof test procedures and maintenance strategies written for the people who use them
- Support through implementation, commissioning and proof testing
- Auditable lifecycle documentation for regulators, insurers and internal governance
When clients typically call us
- A HAZOP or LOPA has identified a scenario that needs an instrumented protective function
- A capital project needs SIL targets set and verified before the control and safety system is procured
- Existing SIL targets were determined years ago and have never been verified against the installed hardware
- Ageing plant is being revalidated or life-extended and the safety systems need reassessing
- An audit, insurer or corporate standard has raised the absence of functional safety documentation
- Obsolescence is forcing a change of sensor, valve or logic solver and the effect on SIL has to be assessed
Frequently asked questions
We have SIL targets already. Do we still need verification?
Determination tells you what performance is required. Verification tells you whether the equipment installed actually achieves it. They are separate exercises, and a target on its own is not evidence of protection.
Do we need a LOPA before SIL determination?
Not always, but it is the usual route and produces the most defensible targets. Where a LOPA has not been done, we can run one, or use a risk graph method against your tolerable risk criteria.
Will this mean replacing equipment?
Sometimes, but often not. Verification frequently shows the gap can be closed by shortening a proof test interval, improving diagnostics or correcting a test procedure. Right-sizing works both ways, and we will say when a system is over-engineered as readily as when it is short.
Can you help after the design is finished?
Yes. Functional safety is a lifecycle, not a project stage. We support commissioning, proof testing, management of change, periodic reassessment and the documentation that has to stay current through operation and into decommissioning.
Related: Part of our process safety services. See also LOPA and HAZOP facilitation.
If you want to know whether your safety instrumented functions genuinely deliver the protection they were credited with, we can determine, verify and document them. Talk to us about your site. Request a call
