Functional safety is the part of overall safety that depends on a system working correctly in response to a dangerous condition, so that it brings the process to a safe state when something goes wrong. In the process industry it usually refers to the safety instrumented systems that detect a hazardous deviation with a sensor, decide on an action in a logic solver and take that action through a final element such as a valve, all with a defined and verified reliability.
The idea is that a protective function is not simply present or absent but has a measurable reliability that must match the risk it guards against. Functional safety provides the framework for setting that reliability target, designing to meet it, and keeping it proven throughout the life of the plant.
The safety instrumented function
Before the terms make sense it helps to picture a single protective loop. A sensor detects a dangerous condition, a logic solver decides what to do, and a final element takes action to reach a safe state. That whole loop is a safety instrumented function, for example a high pressure that trips a feed valve closed. A collection of such functions implemented in a dedicated system forms a safety instrumented system, which sits apart from the basic process control that runs the plant day to day.
What a safety integrity level measures
A safety integrity level, or SIL, is a measure of how reliable a safety instrumented function needs to be. It is not a rating of how good a component is or how serious a hazard feels. For a function that acts only when a demand arrives, the SIL is expressed as the average probability of failure on demand, the chance the function fails to work when needed. The levels run from one to four, and each step is an order of magnitude more reliable than the one below.
- SIL 1 corresponds to a probability of failure on demand between one in ten and one in a hundred
- SIL 2 corresponds to between one in a hundred and one in a thousand
- SIL 3 corresponds to between one in a thousand and one in ten thousand
- SIL 4 is between one in ten thousand and one in a hundred thousand and is rare in the process industry
A higher SIL demands more, whether through better components, redundancy, more frequent testing or all three. Because cost rises steeply with each level, the target must be set correctly rather than inflated for comfort, which is why methods such as LOPA are used to derive it.
The safety lifecycle
Setting a SIL target is only the start. The functional safety standard frames the whole effort as a safety lifecycle that runs from hazard identification through allocation of safety functions, design, installation, validation, operation, proof testing and eventual decommissioning. A SIL 2 function that is never proof tested does not stay SIL 2, because the reliability calculation assumes a testing interval. The verification calculation, the proof test procedure and the record of every test are therefore part of keeping the function at the integrity it was designed for.
Which standards apply
The core standard for the process industry is IEC 61511, which sets out the safety lifecycle, the requirements for safety instrumented systems and the way integrity is specified and maintained. It sits under the broader IEC 61508, the generic functional safety standard for electrical, electronic and programmable systems from which device manufacturers derive their certifications. Together these define how a function is specified, how its reliability is calculated, and how hardware fault tolerance and systematic capability are demonstrated.
Common pitfalls
Functional safety fails quietly when the SIL target is assigned by feel rather than derived from a risk analysis, which leaves some functions over engineered and others genuinely short. Crediting a safety function that is not truly independent of the cause it protects against, skipping proof testing so the assumed reliability drifts, and treating a certificate on a device as proof of a whole loop are all frequent errors. The systematic side, meaning the quality of the specification and the software, is often neglected in favour of the easier hardware calculation.
Functional safety turns protection from a hopeful presence into a measured and maintained capability. If you want help setting SIL targets, verifying that your functions meet them or building the lifecycle records that keep them valid, a functional safety specialist can work through the system with your team.