SIL Analysis
Summary
Designing Safety Instrumented System (SIS) complying with international standards on functional safety, IEC 61508/IEC 61511 has been widely adopted practice. Our support services for the Safety Integrity Level (SIL) analysis assign SIL required for SIS according to the magnitude of the process risk it needs to address, then determine the SIS configuration and frequency of functional tests necessary for maintaining the SIL throughout the lifecycle.
Features
- TOYO proposes a rational SIS design according to the process risks.
- TOYO assesses the process risks from the viewpoints of safety and the environment, and proposes the SIL that the SIS should achieve. (TOYO also conducts assessments from the viewpoint of asset risks, if requested by the client.)
- TOYO proposes the SIS configuration and frequency of functional tests necessary for maintaining the SIL throughout the lifecycle.
Services
1. Consultation for analysis
- TOYO offers consultation services concerning the methods and concept for designing SIS systematically and reasonably in compliance with IEC 61508/IEC61511.
2. Implementation of analysis
- TOYO dispatchs an analysis leader who has extensive experience in risk analysis to support the implementation of effective risk analysis (SIL determination).
- Process risk analysis (SIL determination) can be conducted by a team of experts from client (in the field of process, operation, control, safety, environment, etc.) and an analysis leader from TOYO.
- Through assessment of the process risks, the SIL required for each SIS is determined.
- TOYO’s experts perform quantitative reliability analysis and proposes the SIS configuration and the frequency of functional tests for achieving the SIL determined.
3. Compilation of analysis results
- TOYO prepares a report stipulating the criteria and methods used in process risk evaluation, the targeted SIL, and the verification results of SIL (SIS configuration and frequency of functional tests).
Examples of analysis
- TOYO has abundant experiences to conduct SIL analysis for oil refinery plants, petrochemical plants, fertilizer plants and energy-related plants.
Examples of analysis
Process Hazard Analysis
- Process hazard analysis such as HAZOP Study is conducted to identify the hazard scenario that forms the base of the process risk analysis.
Process risk analysis (SIL determination)
- With respect to the hazard scenarios identified by the process hazard analysis, risk assessment criteria that consider the hazard severity (C), frequency of hazard occurrence (W), possibility of avoiding the hazard (P) and other elements are applied to determine the SIL required for each SIS.
- SIL is defined as follows based on the Average Probability of Failure on Demand (PFDavg), which indicates the probability of a system failing to perform a specified function on demand.
Average Probability of Failure on Demand
| Safety Integrity Level (SIL) | Average Probability of Failure on Demand (PFDavg) |
|---|---|
| SIL 4 | 10-4 > PFDavg ≧10-5 |
| SIL 3 | 10-3 > PFDavg ≧10-4 |
| SIL 2 | 10-2 > PFDavg ≧10-3 |
| SIL 1 | 10-1 > PFDavg ≧10-2 |
![]() Example of risk assessment criteria: Risk Graph |
Verification on SIL
- Whether the SIS satisfies the requirements on system configuration and PFD specified in IEC 61508/IEC 61511 is verified.
PFDTotal = PFDsensor + PFDlogic + PFDfinal element - Through reliability analysis that uses fault tree or other methods, the SIS configuration and frequency of functional tests for the constituent elements necessary for achieving the SIL are determined.
- The failure rate data of the SIS constituent elements used for reliability analysis are obtained from the vendor or from publicly available data sources.
![]() Example of fault tree application |
![]() Example of typical system configuration by SIL |
Effects of implementation
Grading the importance of SIS (SIL determination) according to the potential risks provides the criteria for effectively allocating the facility and maintenance costs to where they are needed.
By periodically conducting functional tests based on the SIL analysis results, preventive maintenance can be provided in a planned manner.













