Allocation of Safety Functions to Protection Layers
We allocate the required risk reduction across the basic process control system, alarms, the safety instrumented system and the non instrumented layers to IEC 61511 clause 9
What this element is and why it matters
Phase 2 allocates the required risk reduction from Phase 1 across the various protection layers, namely the basic process control system, alarms, operator response, mechanical relief, the safety instrumented system and plant emergency response. Layer of protection analysis is the dominant method our team uses, with independent protection layer credit governed by the CCPS LOPA guidelines.

Individual significance for organisations
Allocation discipline prevents the capital expense pattern of putting safety integrity level 3 everywhere. A well allocated layered protection scheme uses cheaper and more reliable independent layers before it reaches for SIL rated safety instrumented functions, and that is the balance we help your facility strike.
Contribution to Functional Safety Lifecycle Implementation
The outputs of Phase 2 feed Phase 3 with the safety integrity level target for each safety instrumented function and they inform the architecture requirements in Phase 4 design. The work also touches process knowledge management for the independent protection layer inventory.
What compliant execution looks like
How we implement this element
A focused six step methodology calibrated to deliver allocation of safety functions to protection layers as a working capability rather than a documented compliance artefact.
We set up the layer of protection analysis for each scenario from Phase 1 and identify the initiating event frequency and the target tolerable frequency.
We catalogue the protection layers across the basic process control system, alarms, operator response, mechanical relief, the safety instrumented system and emergency response, and we assess each one for independent protection layer eligibility.
We apply the CCPS four part test of independence, dependability, auditability and validation and document the evidence for each independent protection layer.
We calculate the risk reduction factor from the initiating frequency down to the tolerable frequency, deduct the existing protection layer credits and determine the residual gap.
We allocate the safety integrity level to IEC 61511 clause 9 Table 4, where SIL 1 covers a risk reduction factor of 10 to 100, SIL 2 covers 100 to 1000 and SIL 3 covers 1000 to 10000.
We issue the safety instrumented function register with the SIL band, the risk reduction factor, the protection layer credits and the assumption log, and we hand it to Phase 3 for the safety requirements specification.
Element implementation flow chart
A decision gated workflow that shows the actual sequence of activities from initiation through steady state operation, with key decision points highlighted.
What we produce
- Layer of protection analysis worksheets for each scenario
- An independent protection layer eligibility assessment register
- A safety instrumented function allocation register with the SIL targets
- A risk reduction factor calculation sheet per scenario running from the initiating frequency to tolerable
- A demand mode classification record for each function
- An allocation assumption log for traceability into the safety requirements specification
Where execution fails
- Non independent protection layers that get double counted
- Conservative defaults that quietly inflate the safety integrity level
- The basic process control system treated as a protection layer without proper independence verification
- The same control system logic solver credited as both the initiating cause and a protection layer
Codes this element is built on
Explore related elements in this framework
Functional Safety Lifecycle Implementation full element index
Talk to us about implementing Allocation of Safety Functions to Protection Layers
We can scope this element implementation against your facility, regulatory context, and existing management system maturity, then integrate it with the other Functional Safety Lifecycle Implementation elements you already operate.