Skip to content
Functional Safety Lifecycle Implementation

SIS Design and Engineering

We handle architecture, FMEDA, probability of failure calculation and cybersecurity to IEC 61511 clauses 11 and 12

Strategic context

What this element is and why it matters

Phase 4 takes the safety requirements specification and produces the as designed safety instrumented system. Our team handles architecture selection across one out of one, one out of two and two out of three voting, FMEDA grade component selection, probability of failure verification to IEC 61508 6, cybersecurity zone and conduit design to IEC 62443, and the full design documentation to IEC 61511 clauses 11 and 12.

SIS Design and Engineering

Individual significance for organisations

Design quality determines how the safety instrumented system behaves across its life, including its actual integrity, its spurious trip frequency, its proof test cost and its ageing pathway. Poor design choices cost your facility across the 20 to 25 year life of the asset, so we make sure those choices are sound.

Contribution to Functional Safety Lifecycle Implementation

Phase 4 produces the as designed safety instrumented system that Phase 5 commissions and Phase 6 operates. The safety manual it produces to clause 16 is the master document for the entire lifecycle of the system.

Key requirements

What compliant execution looks like

Architecture selection driven by the safety integrity level target and the mean time to fail spurious budget
FMEDA data to IEC 61508 sourced from TUV, exida or SIRA
Probability of failure verification to IEC 61508 6 Annex B
Cybersecurity zone and conduit design to IEC 62443
Architectural constraints handled through Route 1H using hardware fault tolerance and safe failure fraction, or Route 2H using reliability data
Systematic capability from level 1 to level 4 with a proven in use justification for each element
Implementation methodology

How we implement this element

A focused six step methodology calibrated to deliver sis design and engineering as a working capability rather than a documented compliance artefact.

Architecture Selection

We select the architecture across one out of one, one out of one with diagnostics, one out of two and two out of three based on the safety integrity level target, the mean time to fail spurious budget, common cause failure mitigation and any prior use evidence.

Component Selection by FMEDA

We choose sensors, logic solvers and final elements certified by TUV, exida or SIRA, and we verify the FMEDA data sheets covering the dangerous detected and dangerous undetected failure rates, the safe failure fraction and the diagnostic coverage.

Probability of Failure Verification

We calculate to IEC 61508 6 Annex B using fault tree or Markov methods, we include the beta factor common cause contribution to Annex D, and we verify that the safety integrity level target is met.

Architectural Constraint Check

To clause 11 we check Route 1H using hardware fault tolerance and safe failure fraction against Route 2H using reliability data, and we document compliance with the constraints.

Cybersecurity Design

We apply the IEC 62443 zone and conduit model, segregate the system from the basic process control system and the corporate network, set access control, and align with NIST SP 800 82.

Design Documentation and Safety Manual

We issue the design report, the hardware and software specifications, the cause and effect matrix and the safety manual to clause 16.

Implementation flow

Element implementation flow chart

A decision gated workflow that shows the actual sequence of activities from initiation through steady state operation, with key decision points highlighted.

Start
Safety requirements specification received from Phase 3
Architecture Trade Off
One out of one with diagnostics, one out of two or two out of three by SIL and mean time to fail spurious
FMEDA Component Selection
Certified by TUV or exida
Probability of Failure Calculation
To IEC 61508 6 Annex B
Decision
Target SIL Met?
Decision gate
Decision
Architectural Constraint Check
Route 1H using hardware fault tolerance and safe failure fraction, or Route 2H
Systematic Capability Verified
Systematic capability at or above the SIL with proven in use evidence
Cybersecurity Design
IEC 62443 zone and conduit
Safety Manual Compilation
To clause 16 covering operating, proof test and management of change
Design Hand Off to Phase 5
Installation, commissioning and validation
Deliverables

What we produce

  • A safety instrumented system design report with the architecture and the probability of failure calculation
  • An FMEDA graded component selection register
  • A safety manual to IEC 61511 clause 16
  • An architectural constraint compliance record covering Route 1H or 2H, hardware fault tolerance and safe failure fraction
  • A systematic capability and proven in use evidence file for each element
  • A cause and effect matrix and a zone and conduit security diagram
Common pitfalls

Where execution fails

  • A prior use claim made without statistical evidence
  • Beta factor scoring that is optimistic against your site context
  • Cybersecurity bolted on after the design is frozen
  • An average probability of failure that passes while the hardware fault tolerance and safe failure fraction constraints are not met
Standards & references

Codes this element is built on

IEC 61511 1 Cl.11 and Cl.12 (Design and Engineering)IEC 61508 6 Annex B and Annex D (probability of failure and beta factor)IEC 62443 (Operational Technology Cybersecurity)IEC 61508 2 and 61508 3 from 2010 (hardware and software systematic capability)ISA TR84.00.02 and TR84.00.03 (SIL verification and final element coverage)NIST SP 800 82 (Industrial Control System and Operational Technology Security Guidance)
Related elements

Explore related elements in this framework

Implement this element

Talk to us about implementing SIS Design and Engineering

We can scope this element implementation against your facility, regulatory context, and existing management system maturity, then integrate it with the other Functional Safety Lifecycle Implementation elements you already operate.