Technology and Consulting
February 27, 2024
12 minutes read
A safety instrumented system (SIS) is an independent set of sensors, logic solvers, and final elements that takes a process to a safe state when defined conditions are exceeded, separate from the SCADA and control systems that run the plant day to day. The separation is the point: the system that operates the process must not be the only thing protecting it.
This guide covers what an SIS is and how it differs from SCADA and basic process control, the standards that govern it, what safety integrity levels actually mean, how SIL targets are determined, the full safety lifecycle, and why buying SIL-rated components does not produce a SIL-rated system.
It is written for process safety engineers, I&C and controls engineers, and plant managers responsible for functional safety in oil and gas, petrochemical, chemical, and power facilities.
A safety instrumented system is composed of one or more safety instrumented functions (SIFs), each built from a sensor, a logic solver, and a final element, designed to detect a hazardous condition and drive the process to a safe state. It is also referred to as an emergency shutdown system, safety shutdown system, or safety interlock system.
Each SIF is a complete protective loop, not a component. A pressure transmitter detects an excursion, a safety logic solver evaluates it against a defined trip point, and a final element such as a shutdown valve acts. All three must function for the safety function to work, which is why SIS performance is always assessed loop by loop.
The distinction from SCADA and basic process control is fundamental. A basic process control system (BPCS) regulates the process during normal operation and provides the first layer of protection, while SCADA supervises, displays, and records.
That independence is what makes an SIS a credible protection layer. If the same system that controls a process is also the only thing protecting it, a single failure can cause the hazard and disable the protection simultaneously.
Functional safety for safety instrumented systems is governed by IEC 61511 in the process industries, derived from the broader IEC 61508 framework, with ANSI/ISA 84.00.01 as the United States adoption. These standards define requirements across the entire life of the system, not just its design.
The regulatory hook in the United States runs through process safety management. OSHA's PSM standard at 29 CFR 1910.119 requires that process equipment be designed and maintained in accordance with recognized and generally accepted good engineering practice, and ANSI/ISA 84.00.01 is the recognized practice for safety instrumented systems.
Compliance is therefore not optional in PSM-covered facilities. It is documented through hazard analysis, SIL determination, a safety requirements specification, verification calculations, and records of proof testing across the system's operating life.
A safety integrity level is a discrete band, SIL 1 through SIL 4, that quantifies the risk reduction a safety instrumented function must deliver. It is a performance requirement expressed as a probability, not a product feature or a quality rating.
Which measure applies depends on how often the function is demanded. Low demand mode means the safety function is called upon no more than once per year and is measured by average probability of dangerous failure on demand (PFDavg). High demand or continuous mode is measured as probability of dangerous failure per hour (PFH).
According to TÜV SÜD, the IEC 61508 classification is as follows:
Each level represents an order-of-magnitude improvement, corresponding to risk reduction factors of roughly 10 to 100 for SIL 1 and 1,000 to 10,000 for SIL 3. Architecture typically scales accordingly, with SIL 1 often achieved on a single channel and SIL 2 and SIL 3 requiring redundancy through the sensor, logic solver, and final element.
SIL 4 exists in the standards but is rarely applied in the process industries. It is difficult to design, difficult to maintain, and in practice most process facilities cap at SIL 3.
A SIL target is determined by risk analysis, not by preference or by copying a similar plant. The process establishes how much risk reduction a specific hazard requires, and only then specifies hardware capable of delivering it.
The sequence begins with a process hazard analysis, commonly a HAZOP, which identifies hazardous scenarios and their causes and consequences. Existing independent protection layers are then credited, including relief devices, the basic process control system, alarms with operator response, and physical containment.
The key question is whether the residual risk is tolerable once those layers are counted. If it is not, a safety instrumented function is required, and the gap between the residual and the tolerable frequency defines the required risk reduction, which maps to a SIL.
Three methods are recognized in IEC 61511-3 for making that determination:
Not every hazard needs an SIS. A properly conducted study frequently concludes that existing protection layers are sufficient, which prevents the expensive mistake of applying instrumented protection where a relief device already does the job.
IEC 61511 structures functional safety as a lifecycle running from hazard analysis to decommissioning, not as a design activity that ends at commissioning. The standard is explicit that safety integrity must be maintained in operation, not merely achieved on paper.
The lifecycle phases in sequence:
Verification is analytical, confirming by calculation that the design meets the target. Validation is physical, confirming that the installed system actually performs the safety function under real conditions.
The cyclic nature matters operationally. Any change to process design, operating conditions, or equipment requires returning to the relevant phase, which is why management of change is inseparable from functional safety.
Buying SIL-rated sensors, logic solvers, and valves does not produce a SIL-compliant safety function, and this is the most common and most consequential misunderstanding in functional safety. Safety integrity is a property of the complete loop, not of the parts inside it.
The Institution of Chemical Engineers states the problem directly. Operators complete a SIL assessment and install individual elements rated for the SIL, believing they now have a SIL-rated safety system, but SIL is a property of the whole loop, and installing individual SIL-rated elements does not necessarily result in a SIL-compliant loop.
The arithmetic explains why. The PFDavg of a safety instrumented function is the sum of contributions from the sensor subsystem, the logic solver, and the final element. Three individually SIL 2 capable components can combine into a loop whose calculated PFDavg falls short of SIL 2, particularly because final elements such as shutdown valves usually dominate the total.
Three constraints must be satisfied together, and the weakest one caps the achievable SIL. The loop must meet the target PFDavg by calculation, satisfy hardware fault tolerance and safe failure fraction requirements, and every component must have adequate systematic capability. A loop with SIL 3 calculated PFDavg but SIL 1 systematic capability is a SIL 1 function.
Proof test interval is part of the calculation, not a separate matter. The PFDavg of a single-channel element depends directly on its dangerous undetected failure rate multiplied by the proof test interval, which means a loop verified on a six-month test interval no longer achieves its SIL if testing slips to annual.
Proof testing is what keeps a safety instrumented function at its designed integrity, because it detects the dangerous undetected failures that diagnostics cannot see. A verified SIL is a claim about the future that only holds if the test regime assumed in the calculation is actually performed.
Dangerous undetected failures are the reason the discipline exists. Detected failures drive the system to a safe state and contribute little to PFDavg, while undetected failures sit silently until a demand arrives. Proof testing is the only mechanism that reveals them.
Test intervals are derived, not chosen. Because PFDavg scales with the interval, the frequency assumed during verification becomes a binding operational commitment. Intervals in the range of three to six months are common for functions where demand rates are higher. Holding that interval in practice is a maintenance planning commitment as much as an engineering one.
Two operational practices commonly erode integrity in service. Bypasses left in place beyond their authorized window remove the protection entirely, and deferred proof tests silently move the loop out of its verified SIL. Both should be tracked as functional safety events, not as routine maintenance backlog.
Prismecs supports safety instrumented systems through I&C engineering, control and safety system integration, and the operational maintenance that keeps a verified SIL intact in service. The focus is the implementation and operational phases of the safety lifecycle rather than independent certification.
The Prismecs capability set for SIS and control integration:
Prismecs is clear about the boundary. SIL determination studies, independent SIL verification calculations, and functional safety assessments are performed by certified functional safety practitioners and assessment bodies. Prismecs implements, integrates, and maintains the systems those studies specify, which is where most SIL degradation actually occurs.
A safety instrumented system (SIS) is an independent protection system composed of safety instrumented functions, each built from a sensor, a logic solver, and a final element. It detects a defined hazardous condition and drives the process to a safe state. It is also called an emergency shutdown system or safety interlock system, and it operates independently of the basic process control system.
A basic process control system (BPCS) regulates the process during normal operation and serves as the first layer of protection, while SCADA supervises and records. A safety instrumented system does neither; it remains idle until a defined hazardous condition occurs, then acts independently. That independence is essential, because a system that both controls and protects can fail in a way that causes the hazard and disables the protection.
Safety integrity levels quantify required risk reduction. In low demand mode, SIL 1 corresponds to an average probability of dangerous failure on demand of 10⁻² to 10⁻¹, SIL 2 to 10⁻³ to 10⁻², SIL 3 to 10⁻⁴ to 10⁻³, and SIL 4 to 10⁻⁵ to 10⁻⁴. Each level is an order-of-magnitude improvement. SIL 4 is rarely applied in process industries.
A SIL target comes from risk analysis, not preference. A process hazard analysis identifies hazardous scenarios, existing independent protection layers are credited, and if residual risk remains intolerable, the gap defines the required risk reduction. IEC 61511-3 recognizes three methods: Layers of Protection Analysis (LOPA), risk graphs, and fault tree analysis. Many hazards require no SIS once existing layers are credited.
No. Safety integrity is a property of the complete loop, and installing individually SIL-rated elements does not necessarily produce a SIL-compliant loop. The loop's PFDavg is the sum of sensor, logic solver, and final element contributions, and it must also satisfy hardware fault tolerance and systematic capability requirements. The weakest of those three constraints caps the achievable SIL.
Because the calculated PFDavg of a safety function depends directly on the proof test interval assumed during verification. Proof testing reveals dangerous undetected failures that diagnostics cannot detect and that otherwise remain hidden until a demand occurs. A loop verified on a six-month interval no longer achieves its verified SIL if testing slips, making the test regime a binding operational commitment.
Functional safety succeeds or fails in operation, not in design. The standards are established, the calculation methods are mature, and the studies are widely available, yet safety integrity degrades in service through deferred proof tests, extended bypasses, and field devices maintained as ordinary instruments rather than as safety-critical assets.
Operators maintaining safety instrumented systems need a partner who can integrate the control and safety layers, execute commissioning and loop checks, and maintain the field devices that determine whether a verified SIL survives contact with the plant. That is the Prismecs model: I&C engineering and O&M built around systems that must work when demanded.
To discuss control and safety system integration, commissioning, or SIS maintenance support, call +1 (888) 774-7632 or email sales@prismecs.com.
Tags: safety instrumented systems safety integrity level SIL IEC 61511 functional safety SIS proof testing BPCS vs SIS
O&M Services
40 minutes read
Rotating Equipment Maintenance: A Field Guide to Uptime for Pumps, Compressors, and Turbines
Get rotating equipment maintenance right: daily to annual PM checklist, cost benchmarks, and troubleshooting tables Built by O&M crews under contract...
EPCM Services
26 minutes read
EPC vs EPCM: Which Model Fits Your Project's Risk and Control Needs?
EPC transfers risk for a lump-sum premium; EPCM keeps you in control but on the hook. See the numbers, the failure modes, and score which model fits y...
O&M Services
16 minutes read
Predictive Maintenance for Power Assets: How It Works, Challenges, and Real Applications
Predictive maintenance cuts power plant downtime, but only inside the P-F window. See fault signatures, honest ROI math and false alarm traps. Read th...
Renewables
17 minutes read
Renewable Energy Integration: Challenges, Technologies, and How the Grid Adapts
Renewable energy integration breaks grids built for baseload. See how inertia loss, duck curves, and storage decide reliability, with field-proven fix...