Safety Instrumented Systems (SIS) and SCADA: Functional Safety, SIL, and the IEC 61511 Lifecycle

Technology and Consulting

February 27, 2024

12 minutes read

SCADA and SIS Services

A safety instrumented system (SIS) is an independent set of sensors, logic solvers, and final elements that takes a process to a safe state when defined conditions are exceeded, separate from the SCADA and control systems that run the plant day to day. The separation is the point: the system that operates the process must not be the only thing protecting it.

This guide covers what an SIS is and how it differs from SCADA and basic process control, the standards that govern it, what safety integrity levels actually mean, how SIL targets are determined, the full safety lifecycle, and why buying SIL-rated components does not produce a SIL-rated system.

It is written for process safety engineers, I&C and controls engineers, and plant managers responsible for functional safety in oil and gas, petrochemical, chemical, and power facilities.

What a Safety Instrumented System Actually Is

A safety instrumented system is composed of one or more safety instrumented functions (SIFs), each built from a sensor, a logic solver, and a final element, designed to detect a hazardous condition and drive the process to a safe state. It is also referred to as an emergency shutdown system, safety shutdown system, or safety interlock system.

Each SIF is a complete protective loop, not a component. A pressure transmitter detects an excursion, a safety logic solver evaluates it against a defined trip point, and a final element such as a shutdown valve acts. All three must function for the safety function to work, which is why SIS performance is always assessed loop by loop.

The distinction from SCADA and basic process control is fundamental. A basic process control system (BPCS) regulates the process during normal operation and provides the first layer of protection, while SCADA supervises, displays, and records.

That independence is what makes an SIS a credible protection layer. If the same system that controls a process is also the only thing protecting it, a single failure can cause the hazard and disable the protection simultaneously.

The Standards Governing Functional Safety

Functional safety for safety instrumented systems is governed by IEC 61511 in the process industries, derived from the broader IEC 61508 framework, with ANSI/ISA 84.00.01 as the United States adoption. These standards define requirements across the entire life of the system, not just its design.

Standard

Scope

IEC 61508

Functional safety of electrical, electronic, and programmable electronic safety-related systems; the parent standard applicable across all industries

IEC 61511

Functional safety: safety instrumented systems for the process industry sector, derived from IEC 61508

IEC 61511-1

Requirements: defines SIS and SIF, SIL assignment, the safety requirements specification, and the lifecycle

IEC 61511-3

Guidance on determining required safety integrity levels, including LOPA, risk graphs, and fault tree analysis

ANSI/ISA 84.00.01

The United States adoption of IEC 61511, applying SIS to process industry hazards

The regulatory hook in the United States runs through process safety management. OSHA's PSM standard at 29 CFR 1910.119 requires that process equipment be designed and maintained in accordance with recognized and generally accepted good engineering practice, and ANSI/ISA 84.00.01 is the recognized practice for safety instrumented systems.

Compliance is therefore not optional in PSM-covered facilities. It is documented through hazard analysis, SIL determination, a safety requirements specification, verification calculations, and records of proof testing across the system's operating life.

Safety Integrity Levels: What SIL Actually Measures

A safety integrity level is a discrete band, SIL 1 through SIL 4, that quantifies the risk reduction a safety instrumented function must deliver. It is a performance requirement expressed as a probability, not a product feature or a quality rating.

Which measure applies depends on how often the function is demanded. Low demand mode means the safety function is called upon no more than once per year and is measured by average probability of dangerous failure on demand (PFDavg). High demand or continuous mode is measured as probability of dangerous failure per hour (PFH).

According to TÜV SÜD, the IEC 61508 classification is as follows:

SIL

Low demand mode (PFDavg)

High demand or continuous mode (per hour)

SIL 1

≥ 10⁻² to < 10⁻¹

≥ 10⁻⁶ to < 10⁻⁵

SIL 2

≥ 10⁻³ to < 10⁻²

≥ 10⁻⁷ to < 10⁻⁶

SIL 3

≥ 10⁻⁴ to < 10⁻³

≥ 10⁻⁸ to < 10⁻⁷

SIL 4

10⁻⁵ to < 10⁻⁴

≥ 10⁻⁹ to < 10⁻⁸

Each level represents an order-of-magnitude improvement, corresponding to risk reduction factors of roughly 10 to 100 for SIL 1 and 1,000 to 10,000 for SIL 3. Architecture typically scales accordingly, with SIL 1 often achieved on a single channel and SIL 2 and SIL 3 requiring redundancy through the sensor, logic solver, and final element.

SIL 4 exists in the standards but is rarely applied in the process industries. It is difficult to design, difficult to maintain, and in practice most process facilities cap at SIL 3.

How a SIL Target Is Determined

A SIL target is determined by risk analysis, not by preference or by copying a similar plant. The process establishes how much risk reduction a specific hazard requires, and only then specifies hardware capable of delivering it.

The sequence begins with a process hazard analysis, commonly a HAZOP, which identifies hazardous scenarios and their causes and consequences. Existing independent protection layers are then credited, including relief devices, the basic process control system, alarms with operator response, and physical containment.

The key question is whether the residual risk is tolerable once those layers are counted. If it is not, a safety instrumented function is required, and the gap between the residual and the tolerable frequency defines the required risk reduction, which maps to a SIL.

Three methods are recognized in IEC 61511-3 for making that determination:

  • Layers of Protection Analysis (LOPA): a semi-quantitative method crediting independent protection layers against an initiating event frequency.
  • Risk graph: a qualitative method using consequence, occupancy, avoidance, and demand-rate parameters.
  • Fault tree analysis: a fully quantitative method for complex scenarios.

Not every hazard needs an SIS. A properly conducted study frequently concludes that existing protection layers are sufficient, which prevents the expensive mistake of applying instrumented protection where a relief device already does the job.

The IEC 61511 Safety Lifecycle

IEC 61511 structures functional safety as a lifecycle running from hazard analysis to decommissioning, not as a design activity that ends at commissioning. The standard is explicit that safety integrity must be maintained in operation, not merely achieved on paper.

The lifecycle phases in sequence:

  • Hazard and risk assessment: identify hazardous scenarios and required risk reduction.
  • Allocation of safety functions: assign protection to layers and determine SIL targets.
  • Safety requirements specification (SRS): document exactly what each SIF must do, its trip points, response time, and safe state.
  • Design and engineering: select architecture, voting, and components capable of the target SIL.
  • Verification: calculate that the designed loop achieves the required PFDavg.
  • Installation, commissioning, and validation: confirm the installed system performs the specified function.
  • Operation and maintenance: proof testing, bypass management, and demand recording.
  • Modification and decommissioning: any change returns the process to the appropriate earlier phase.

Verification is analytical, confirming by calculation that the design meets the target. Validation is physical, confirming that the installed system actually performs the safety function under real conditions.

The cyclic nature matters operationally. Any change to process design, operating conditions, or equipment requires returning to the relevant phase, which is why management of change is inseparable from functional safety.

Why SIL-Rated Components Do Not Make a SIL-Rated System

Buying SIL-rated sensors, logic solvers, and valves does not produce a SIL-compliant safety function, and this is the most common and most consequential misunderstanding in functional safety. Safety integrity is a property of the complete loop, not of the parts inside it.

The Institution of Chemical Engineers states the problem directly. Operators complete a SIL assessment and install individual elements rated for the SIL, believing they now have a SIL-rated safety system, but SIL is a property of the whole loop, and installing individual SIL-rated elements does not necessarily result in a SIL-compliant loop.

The arithmetic explains why. The PFDavg of a safety instrumented function is the sum of contributions from the sensor subsystem, the logic solver, and the final element. Three individually SIL 2 capable components can combine into a loop whose calculated PFDavg falls short of SIL 2, particularly because final elements such as shutdown valves usually dominate the total.

Three constraints must be satisfied together, and the weakest one caps the achievable SIL. The loop must meet the target PFDavg by calculation, satisfy hardware fault tolerance and safe failure fraction requirements, and every component must have adequate systematic capability. A loop with SIL 3 calculated PFDavg but SIL 1 systematic capability is a SIL 1 function.

Proof test interval is part of the calculation, not a separate matter. The PFDavg of a single-channel element depends directly on its dangerous undetected failure rate multiplied by the proof test interval, which means a loop verified on a six-month test interval no longer achieves its SIL if testing slips to annual.

Proof Testing and the Operational Phase

Proof testing is what keeps a safety instrumented function at its designed integrity, because it detects the dangerous undetected failures that diagnostics cannot see. A verified SIL is a claim about the future that only holds if the test regime assumed in the calculation is actually performed.

Dangerous undetected failures are the reason the discipline exists. Detected failures drive the system to a safe state and contribute little to PFDavg, while undetected failures sit silently until a demand arrives. Proof testing is the only mechanism that reveals them.

Test intervals are derived, not chosen. Because PFDavg scales with the interval, the frequency assumed during verification becomes a binding operational commitment. Intervals in the range of three to six months are common for functions where demand rates are higher. Holding that interval in practice is a maintenance planning commitment as much as an engineering one.

Two operational practices commonly erode integrity in service. Bypasses left in place beyond their authorized window remove the protection entirely, and deferred proof tests silently move the loop out of its verified SIL. Both should be tracked as functional safety events, not as routine maintenance backlog.

How Prismecs Supports Safety Instrumented Systems

Prismecs supports safety instrumented systems through I&C engineering, control and safety system integration, and the operational maintenance that keeps a verified SIL intact in service. The focus is the implementation and operational phases of the safety lifecycle rather than independent certification.

The Prismecs capability set for SIS and control integration:

  • Integrated control and safety panels: the UMCP-100 universal master control panel, which incorporates SCADA, safety instrumented, and fire safety control in one engineered system with PLC programming to ISA and IEC standards.
  • I&C engineering and integration: instrumentation, logic solver integration, and interfacing between the basic process control system and the safety layer.
  • Installation and commissioning support: field execution, loop checking, and commissioning of control and safety systems.
  • Operational maintenance: proof testing support, instrument maintenance, and management of the field devices that determine loop integrity.
  • Equipment sourcing: OEM-agnostic supply of transmitters, logic solvers, valves, and actuators through eINDUSTRIFY.

Prismecs is clear about the boundary. SIL determination studies, independent SIL verification calculations, and functional safety assessments are performed by certified functional safety practitioners and assessment bodies. Prismecs implements, integrates, and maintains the systems those studies specify, which is where most SIL degradation actually occurs.

Frequently Asked Questions

What is a safety instrumented system?

A safety instrumented system (SIS) is an independent protection system composed of safety instrumented functions, each built from a sensor, a logic solver, and a final element. It detects a defined hazardous condition and drives the process to a safe state. It is also called an emergency shutdown system or safety interlock system, and it operates independently of the basic process control system.

What is the difference between BPCS and SIS?

A basic process control system (BPCS) regulates the process during normal operation and serves as the first layer of protection, while SCADA supervises and records. A safety instrumented system does neither; it remains idle until a defined hazardous condition occurs, then acts independently. That independence is essential, because a system that both controls and protects can fail in a way that causes the hazard and disables the protection.

What do SIL 1, 2, 3, and 4 mean?

Safety integrity levels quantify required risk reduction. In low demand mode, SIL 1 corresponds to an average probability of dangerous failure on demand of 10⁻² to 10⁻¹, SIL 2 to 10⁻³ to 10⁻², SIL 3 to 10⁻⁴ to 10⁻³, and SIL 4 to 10⁻⁵ to 10⁻⁴. Each level is an order-of-magnitude improvement. SIL 4 is rarely applied in process industries.

How is a SIL target determined?

A SIL target comes from risk analysis, not preference. A process hazard analysis identifies hazardous scenarios, existing independent protection layers are credited, and if residual risk remains intolerable, the gap defines the required risk reduction. IEC 61511-3 recognizes three methods: Layers of Protection Analysis (LOPA), risk graphs, and fault tree analysis. Many hazards require no SIS once existing layers are credited.

Does buying SIL-rated components give me a SIL-rated system?

No. Safety integrity is a property of the complete loop, and installing individually SIL-rated elements does not necessarily produce a SIL-compliant loop. The loop's PFDavg is the sum of sensor, logic solver, and final element contributions, and it must also satisfy hardware fault tolerance and systematic capability requirements. The weakest of those three constraints caps the achievable SIL.

Why does proof testing affect SIL compliance?

Because the calculated PFDavg of a safety function depends directly on the proof test interval assumed during verification. Proof testing reveals dangerous undetected failures that diagnostics cannot detect and that otherwise remain hidden until a demand occurs. A loop verified on a six-month interval no longer achieves its verified SIL if testing slips, making the test regime a binding operational commitment.

Why Functional Safety Is an Operational Discipline

Functional safety succeeds or fails in operation, not in design. The standards are established, the calculation methods are mature, and the studies are widely available, yet safety integrity degrades in service through deferred proof tests, extended bypasses, and field devices maintained as ordinary instruments rather than as safety-critical assets.

Operators maintaining safety instrumented systems need a partner who can integrate the control and safety layers, execute commissioning and loop checks, and maintain the field devices that determine whether a verified SIL survives contact with the plant. That is the Prismecs model: I&C engineering and O&M built around systems that must work when demanded.

To discuss control and safety system integration, commissioning, or SIS maintenance support, call +1 (888) 774-7632 or email sales@prismecs.com.

Tags: safety instrumented systems safety integrity level SIL IEC 61511 functional safety SIS proof testing BPCS vs SIS