Y4.06.1Safety integrity level determinationdesign

A safety integrity level sets how far a function's failure probability must drop, based on consequence

Aliases: safety integrity level determination · functional safety

What it is

A safety integrity level (SIL) is a discrete target, under IEC 61508/61511, for how much risk a safety function must reduce. It constrains a specific safety instrumented function's dangerous failure probability (probability of failure on demand, PFD) or failure rate (PFH), not a generic reliability score for a whole device. The required level comes out of a risk assessment — a risk graph or LOPA layer-of-protection analysis — that weighs consequence, exposure, likelihood, and other protection together; consequence severity is never translated directly into a SIL number by itself.

Why it happens

SIL is a probability-times-severity judgment rather than a bare failure-rate threshold because the goal is to push risk — defined as failure probability multiplied by consequence severity — down to an acceptable level. The same failure rate can sit comfortably inside acceptable risk when the consequence is a shutdown, and jump several orders of magnitude in risk when the consequence is a fatality; only more independent protection layers, higher diagnostic coverage, and shorter proof-test intervals bring the probability back down enough to compensate. That is why the level has to come from a risk-assessment process instead of a direct mapping from severity. Low-demand functions, such as a relief valve that trips far less often than it is tested, are measured in PFD; continuous or high-demand functions use PFH — mixing the two measures misjudges the risk reduction actually achieved.

Where it stops holding

SIL is a target for one specified safety function under stated test intervals and operating conditions, not a fixed score stamped on a device, and not proof of zero risk — a function meeting SIL3 still fails within that probability band. The numeric bands differ by standard edition and sector: process industries follow IEC 61511, while machinery uses a parallel performance level (PL) scheme under ISO 13849, and neither can be applied from memory across the other without checking the applicable text.

Applying it

Identify hazard scenario, demand mode, and required risk reduction separately for each safety instrumented function, and keep the risk-graph parameters or LOPA layer list that justify the number rather than jumping straight to assigning a level. Operator displays should show current protection state and required action, not the SIL number itself used as a prompt. Verification should be able to produce the PFD/PFH calculation for each function so reviewers can re-check whether the original assumptions still hold.

Related

  • Same group: Y4.06.2 Architecture and independence at higher SIL · Y4.06.3 Proof testing of safety functions · Y4.06.4 Safety integrity versus general reliability
  • Nearby: Y3.10 Parameter limits and safety interlocks · Y4.02 Redundancy and voting
  • Search terms: safety integrity level · probability of failure on demand · IEC 61508 · functional safety

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/Y4.06.1