A safety integrity level sets how far a function's failure probability must drop, based on consequence
Aliases: safety integrity level determination · functional safety
What it is
A safety integrity level (SIL) is a discrete target, under IEC 61508/61511, for how much risk a safety function must reduce. It constrains a specific safety instrumented function's dangerous failure probability (probability of failure on demand, PFD) or failure rate (PFH), not a generic reliability score for a whole device. The required level comes out of a risk assessment — a risk graph or LOPA layer-of-protection analysis — that weighs consequence, exposure, likelihood, and other protection together; consequence severity is never translated directly into a SIL number by itself.
Why it happens
SIL is a probability-times-severity judgment rather than a bare failure-rate threshold because the goal is to push risk — defined as failure probability multiplied by consequence severity — down to an acceptable level. The same failure rate can sit comfortably inside acceptable risk when the consequence is a shutdown, and jump several orders of magnitude in risk when the consequence is a fatality; only more independent protection layers, higher diagnostic coverage, and shorter proof-test intervals bring the probability back down enough to compensate. That is why the level has to come from a risk-assessment process instead of a direct mapping from severity. Low-demand functions, such as a relief valve that trips far less often than it is tested, are measured in PFD; continuous or high-demand functions use PFH — mixing the two measures misjudges the risk reduction actually achieved.
Where it stops holding
SIL is a target for one specified safety function under stated test intervals and operating conditions, not a fixed score stamped on a device, and not proof of zero risk — a function meeting SIL3 still fails within that probability band. The numeric bands differ by standard edition and sector: process industries follow IEC 61511, while machinery uses a parallel performance level (PL) scheme under ISO 13849, and neither can be applied from memory across the other without checking the applicable text.
Applying it
Identify hazard scenario, demand mode, and required risk reduction separately for each safety instrumented function, and keep the risk-graph parameters or LOPA layer list that justify the number rather than jumping straight to assigning a level. Operator displays should show current protection state and required action, not the SIL number itself used as a prompt. Verification should be able to produce the PFD/PFH calculation for each function so reviewers can re-check whether the original assumptions still hold.
Related
- Same group: Y4.06.2 Architecture and independence at higher SIL · Y4.06.3 Proof testing of safety functions · Y4.06.4 Safety integrity versus general reliability
- Nearby: Y3.10 Parameter limits and safety interlocks · Y4.02 Redundancy and voting
- Search terms:
safety integrity level·probability of failure on demand·IEC 61508·functional safety
Cards in the same group
- Y4.06.2A higher safety integrity level demands real independence between channels, not just one more sensor
- Y4.06.3A safety function's failure probability has to be reconfirmed by periodic testing, not assumed forever
- Y4.06.4Treating general reliability as if it were safety integrity leads to a function that's durable, not safe