Skip to content
Functional Safety Lifecycle Implementation

Allocation of Safety Functions to Protection Layers

We allocate the required risk reduction across the basic process control system, alarms, the safety instrumented system and the non instrumented layers to IEC 61511 clause 9

Strategic context

What this element is and why it matters

Phase 2 allocates the required risk reduction from Phase 1 across the various protection layers, namely the basic process control system, alarms, operator response, mechanical relief, the safety instrumented system and plant emergency response. Layer of protection analysis is the dominant method our team uses, with independent protection layer credit governed by the CCPS LOPA guidelines.

Allocation of Safety Functions to Protection Layers

Individual significance for organisations

Allocation discipline prevents the capital expense pattern of putting safety integrity level 3 everywhere. A well allocated layered protection scheme uses cheaper and more reliable independent layers before it reaches for SIL rated safety instrumented functions, and that is the balance we help your facility strike.

Contribution to Functional Safety Lifecycle Implementation

The outputs of Phase 2 feed Phase 3 with the safety integrity level target for each safety instrumented function and they inform the architecture requirements in Phase 4 design. The work also touches process knowledge management for the independent protection layer inventory.

Key requirements

What compliant execution looks like

Layer of protection analysis to the CCPS guidelines with independent protection layer eligibility tests
Risk graph and matrix methods to ISA TR84.00.04
Independence, dependability, audit and validation tests applied to every protection layer
Safety integrity level band allocation to IEC 61511 clause 9 Table 4
A risk reduction factor derived from the initiating frequency down to the tolerable target
Inherently safer and non instrumented alternatives reviewed before any allocation of safety integrity level 3 or higher
Implementation methodology

How we implement this element

A focused six step methodology calibrated to deliver allocation of safety functions to protection layers as a working capability rather than a documented compliance artefact.

LOPA Worksheet Build

We set up the layer of protection analysis for each scenario from Phase 1 and identify the initiating event frequency and the target tolerable frequency.

Protection Layer Inventory

We catalogue the protection layers across the basic process control system, alarms, operator response, mechanical relief, the safety instrumented system and emergency response, and we assess each one for independent protection layer eligibility.

Eligibility Test

We apply the CCPS four part test of independence, dependability, auditability and validation and document the evidence for each independent protection layer.

Required Risk Reduction Factor

We calculate the risk reduction factor from the initiating frequency down to the tolerable frequency, deduct the existing protection layer credits and determine the residual gap.

Safety Integrity Level Band Allocation

We allocate the safety integrity level to IEC 61511 clause 9 Table 4, where SIL 1 covers a risk reduction factor of 10 to 100, SIL 2 covers 100 to 1000 and SIL 3 covers 1000 to 10000.

Allocation Register

We issue the safety instrumented function register with the SIL band, the risk reduction factor, the protection layer credits and the assumption log, and we hand it to Phase 3 for the safety requirements specification.

Implementation flow

Element implementation flow chart

A decision gated workflow that shows the actual sequence of activities from initiation through steady state operation, with key decision points highlighted.

Start
Phase 1 hazardous events received
LOPA Worksheet Setup
Per scenario from the hazard and risk assessment register
Eligibility Test
Independence, dependability, audit and validation
Decision
Existing Layers Sufficient?
Decision gate
Safety Instrumented Function Required
Allocate the residual risk reduction to a new function
SIL Band Allocation
To IEC 61511 clause 9 Table 4
Decision
SIL of 3 or Less?
Decision gate where SIL 3 or higher triggers an inherent safety review
Demand Mode Confirmed
Low demand on average probability of failure on demand versus high or continuous on probability of failure per hour
Risk Reduction and SIL Reconciled
The allocated SIL band is consistent with the required risk reduction factor
Assumption Log Recorded
Protection layer credits and conditional modifiers documented
Allocation Register
Hand off to the Phase 3 safety requirements specification
Deliverables

What we produce

  • Layer of protection analysis worksheets for each scenario
  • An independent protection layer eligibility assessment register
  • A safety instrumented function allocation register with the SIL targets
  • A risk reduction factor calculation sheet per scenario running from the initiating frequency to tolerable
  • A demand mode classification record for each function
  • An allocation assumption log for traceability into the safety requirements specification
Common pitfalls

Where execution fails

  • Non independent protection layers that get double counted
  • Conservative defaults that quietly inflate the safety integrity level
  • The basic process control system treated as a protection layer without proper independence verification
  • The same control system logic solver credited as both the initiating cause and a protection layer
Standards & references

Codes this element is built on

IEC 61511 1 Cl.9 (Allocation of Safety Functions)CCPS LOPA Guidelines (3rd Edition, 2014)ISA TR84.00.04 (SIL Determination)CCPS Guidelines for Initiating Events and Independent Protection Layers in LOPAIEC 61511 3 from 2016 (guidance on SIL determination methods)ISA TR84.00.02 (SIF SIL verification, demand mode and average probability of failure on demand)
Implement this element

Talk to us about implementing Allocation of Safety Functions to Protection Layers

We can scope this element implementation against your facility, regulatory context, and existing management system maturity, then integrate it with the other Functional Safety Lifecycle Implementation elements you already operate.