Every process plant has safety systems that are supposed to act when something goes wrong - a high-pressure trip, an emergency shutdown, an interlock. A SIL study asks a harder question than "does it exist?". It asks how reliable does it need to be, and is it actually that reliable?
What SIL means
SIL stands for Safety Integrity Level. It is a measure of how dependable a safety function must be, expressed on a scale from SIL 1 to SIL 4. A higher SIL means a lower tolerable probability that the function fails when called upon.
The framework comes from IEC 61508, the general functional safety standard, and IEC 61511, its application to the process industry sector.
The key idea: SIL is not a rating of a device. It is a requirement placed on a function - a complete loop from sensor through logic solver to final element. A certified valve does not make a SIL 2 loop. The whole loop, including how it is tested and maintained, is what determines achieved integrity.
Safety Instrumented Functions
A Safety Instrumented Function (SIF) is one specific protective loop. For example: a pressure transmitter detects high pressure, a logic solver processes the signal, and a shutdown valve closes. Sensor, logic and final element together form the SIF, and all three contribute to whether the target SIL is met.
A collection of SIFs makes up the Safety Instrumented System (SIS).
The two studies people confuse
| SIL Determination | SIL Verification | |
|---|---|---|
| Question answered | What SIL does this function need? | Does the proposed design achieve it? |
| Based on | Risk - consequence and likelihood | Reliability data for the actual equipment |
| Typical method | LOPA, risk graph or risk matrix | PFD calculation across the full loop |
| When | After HAZOP, during design | After determination, before commissioning |
| Output | Target SIL per function | Achieved SIL, plus test interval and architecture requirements |
Determination without verification is the more dangerous gap. It leaves a plant with documented targets and no evidence that anything meets them.
How SIL determination works in practice
LOPA - Layer of Protection Analysis is the most widely used method. It starts from a hazard scenario, usually one identified during HAZOP, and works through it systematically:
- Identify the initiating event and how often it is expected to occur
- Identify the consequence if nothing intervenes
- Credit each independent protection layer already present - basic process control, alarms with operator response, relief devices, physical containment
- Compare the residual risk against the tolerable risk criteria
- The gap, if any, becomes the integrity requirement on the safety instrumented function
The discipline of LOPA lies in what may be counted. A protection layer must be genuinely independent of the initiating event and of other layers. Counting a layer twice, or crediting one that shares a failure mode with the initiator, produces an answer that is comfortable and wrong.
What verification calculates
Verification computes the Probability of Failure on Demand (PFD) for the whole loop, using failure rate data for each element. Several factors drive the result:
- Architecture - redundancy such as 1oo2 or 2oo3 voting
- Proof test interval - how often the function is fully tested. This has a direct and often decisive effect
- Diagnostic coverage - what proportion of failures the system detects itself
- Common cause failure - the possibility that redundant elements fail together for the same reason
A frequent and expensive discovery at this stage is that the target is achievable with existing hardware, but only if proof testing happens far more often than the site currently plans. Verification output is therefore not just a number - it is a maintenance commitment.
Where SIL fits with everything else
HAZOP identifies the scenarios. LOPA determines how much protection each one needs. Verification confirms the design delivers it. Proof testing sustains it over the plant's life. And where quantified risk to people or neighbours is in question, QRA answers that separately.
Alongside SIL, FMEA, RAM and RCM studies address failure modes, availability and maintenance strategy - related disciplines that share much of the same reliability data.
Frequently Asked Questions
What does SIL stand for?
Safety Integrity Level. It expresses how reliable a safety instrumented function must be, on a scale from SIL 1 to SIL 4, where a higher level corresponds to a lower tolerable probability of failure on demand.
Is SIL a rating of equipment or of a function?
Of a function. A complete loop - sensor, logic solver and final element - achieves a SIL, together with its proof test interval and architecture. Individual devices may be certified as suitable for use in a given SIL loop, but a certified device does not by itself make the loop compliant.
What is the difference between SIL determination and SIL verification?
Determination establishes what integrity level each safety function requires, based on risk, and typically uses LOPA. Verification calculates whether the proposed design actually achieves that level, using reliability data and probability of failure on demand calculations. Both are needed.
Which standards govern SIL studies?
IEC 61508 is the general functional safety standard covering electrical, electronic and programmable electronic safety-related systems. IEC 61511 applies those principles specifically to the process industry sector and is the standard most commonly referenced for process plants.
How often should proof testing be carried out?
The interval is an output of the verification calculation rather than a fixed rule - it is one of the variables used to achieve the target integrity level. This is why verification results should be treated as a maintenance commitment: if the assumed test interval is not honoured in practice, the achieved integrity is lower than documented.
Need expert help with this?
We carry out SIL determination and verification studies, LOPA, FMEA, RAM and RCM assessments for process industries.
Talk to a Functional Safety Consultant