The context — when the instrumented barrier does not act

On 23 March 2005, the BP Texas City refinery exploded. During the startup of the isomerization unit, a separation tower was filled far above its normal level. The level instrumentation gave a false reading, a high-level alarm failed, and no automatic protection stopped the filling. Liquid overflowed into a blowdown drum with an open vent, a flammable vapour cloud formed and ignited. Fifteen dead, nearly one hundred and eighty injured.

The investigation pointed to a chain of failures: unreliable instruments, alarms out of service, bypassed procedures, and the absence of a safety function able to stop the overfill. That is exactly the domain of IEC 61511: guaranteeing that the instrumented functions protecting a process exist, achieve the required risk reduction, and keep it throughout the life of the installation.

IEC 61511 vs IEC 61508: the process standard, from the operator’s side

IEC 61508 is the generic parent standard. We detailed it in the article Functional safety and IEC 61508. IEC 61511 is its application to the process industries: chemicals, petrochemicals, refining, pharma, gas.

The shift in viewpoint is essential. IEC 61508 mainly addresses the manufacturers of components (sensors, safety controllers, valves) who certify their products. IEC 61511 addresses the operators and integrators who design, install and operate a safety system from those components. In plain terms: you certify a transmitter to 61508; you design the safety loop that uses it to 61511.

It has three parts: Part 1 sets the requirements, Part 2 gives application guidance, Part 3 guides SIL determination. First edition in 2003, second edition in 2016.

SIS, SIF, SIL: the basic vocabulary

A safety instrumented system (SIS) is the hardware and software that performs one or more safety functions. A safety instrumented function (SIF) is a specific protection: “if the level exceeds the high-high threshold, close the feed valve.” Each SIF is assigned a safety integrity level (SIL, 1 to 4) expressing the expected risk reduction, measured by the average probability of failure on demand (average PFD) in low-demand mode.

To convert a risk reduction into a SIL, the PFD to SIL and risk reduction factor to SIL calculators give the result directly.

The golden rule: separate control from safety

This is the most structuring principle of IEC 61511, and the one Texas City illustrates by its absence. The system that runs the process — the BPCS, Basic Process Control System — must not be the one that protects it. The safety function must be independent from the control system: dedicated sensors, separate logic, its own actuators.

Why? Because a failure of the control system is often the very cause of the hazard. If the protection shares the failed sensor or controller, it falls at the same time as the cause. Independence guarantees the barrier stays up when the process runs away. IEC 61511 strictly governs any equipment sharing between BPCS and SIS.

Determining the SIL: risk graph and LOPA

Before designing, you must decide which SIL for which function. IEC 61511 does not impose it: it offers methods, starting from the risk analysis (typically a HAZOP).

Two approaches dominate. The risk graph is qualitative: you combine severity, frequency of exposure, possibility of avoiding the hazard and probability of occurrence to read a SIL from a decision tree. Fast, but sensitive to team judgement.

LOPA — Layers of Protection Analysis — is semi-quantitative and more rigorous. You start from the initiating-event frequency, multiply by the failure probability of each independent protection layer (IPL) already in place — alarm with operator action, relief valve, bund — and look at the gap to the tolerable risk. That gap sets the risk reduction the SIF must provide, hence its SIL. A layer only counts as an IPL if it is independent, effective and auditable.

The safety lifecycle, process edition

Like IEC 61508, IEC 61511 organises everything around a safety lifecycle. It starts from hazard and risk analysis, leads to the safety requirements specification (the SRS: each SIF, its SIL, its response time, its safe state), then to SIS design, installation, commissioning, operation and maintenance, change management, and decommissioning.

Two requirements specific to the 61511 spirit attach to it. Management of functional safety: defined roles, demonstrated competence, planning. And the functional safety assessment (FSA): independent audit milestones throughout the lifecycle, including at least one before the hazards are present — that is, before startup. The FSA is the safeguard that checks the whole chain holds before it is relied upon.

Prior use: the pragmatic route for components

IEC 61508 demands a heavy hardware assessment of components. IEC 61511 opens a more realistic route for the operator: prior use, or documented operating experience. If a pressure transmitter has been used for years in comparable conditions, with a tracked reliability history, its use in a SIF can be justified without starting from a full certification.

It is powerful but demanding: prior use is only valid if the operating conditions are genuinely comparable and the failure data is real, not optimistic. Poorly substantiated prior use is a false guarantee.

Proof testing: where the PFD is won or lost

A SIF in low-demand mode spends most of its life dormant. A dangerous undetected failure stays invisible there until the proof test. It is the test that reveals hidden faults and “resets” the probability of failure.

Hence a simple rule: for a channel without redundancy, the average PFD is roughly half the product of the dangerous undetected failure rate and the test interval. Testing twice as often halves that term. But test coverage matters as much as frequency: a partial test that does not stroke the valve through its full travel gives misleading confidence. The failure rate to mean time between failures calculator helps handle these orders of magnitude.

The stakes

The first stake is the major accident: fire, explosion, toxic release. Affected sites fall under the Seveso directive in Europe; demonstrating the integrity of your SIFs is not optional.

The second is availability: an over-sensitive SIF causes spurious trips that are costly and push — dangerously — towards bypassing. The right SIL is a balance, not a maximum.

The third is cyber. Modern SIS are connected. The Triton attack, in 2017, targeted precisely the safety instrumented system of a petrochemical site to disable its protections. Functional safety and cybersecurity can no longer be handled separately — see IEC 62443 and the article Exchanging data between two OT controllers.

The mistakes not to make

MistakeWhy people make itWhy it is dangerous
Protecting the process with the system that runs itSaving sensors and a controllerA BPCS failure is often the cause of the hazard; the barrier falls with it (cf. Texas City)
“The sensor is SIL 2, so my SIF is SIL 2”Confusing component and loopThe SIF depends on the whole loop, its architecture and its test interval
Prior use claimed without real dataSaving time on qualificationAssumed reliability ≠ proven reliability; the actual SIL collapses
Partial proof test judged sufficientThe valve “moved”An incomplete stroke hides sticking; the real PFD drifts
Bypassing a SIF to keep producing, “we’ll restore it later”Production pressureA classic accident scenario: the barrier exists but no longer acts

Good practice

Start from a solid HAZOP, then determine the SIL by LOPA where the stakes justify it, by risk graph for simple cases.

Write a clear, testable safety requirements specification, function by function, with SIL, response time and safe state.

Guarantee BPCS/SIS independence, and document any residual equipment sharing.

Choose components by 61508 certification or documented prior use — never by optimism.

Define a proof-test plan with realistic coverage, consistent with the targeted availability.

Manage bypasses: every override logged, time-bounded, signalled, cleared by procedure.

Put a functional safety management in place and have the assessments (FSA) carried out by people independent of the designers, including one before startup.

Review checklist

  • HAZOP documented and up to date
  • SIL determined by a justified method (LOPA or risk graph), per SIF
  • Safety requirements specification testable, per function
  • BPCS / SIS independence established and residual sharing justified
  • Components qualified (61508 certification or substantiated prior use)
  • PFD verified for each SIF (architecture, failure rate, test interval)
  • Proof-test plan with defined coverage
  • Bypass management logged and time-bounded
  • Functional safety management in place
  • FSAs carried out, including one before hazards are introduced
  • Change management applied to every modification

Going further

One last thing. Texas City did not lack procedures; it lacked an independent, reliable, tested barrier able to act when control had failed. That is the whole point of IEC 61511: not “do you have a safety system?”, but “is it independent from the process, sized to the right SIL, and can you prove it will act on the day it must?”.