Functional Safety Lifecycle Implementation

SIS Design and Engineering

Architecture, FMEDA, PFD/PFH calculation, cybersecurity per IEC 61511 Cl.11-12

Strategic context

What this element is — and why it matters

Phase 4 takes the SRS and produces the as-designed SIS — architecture selection (1oo1, 1oo2, 2oo3), FMEDA-grade component selection, PFD/PFH verification per IEC 61508-6, cybersecurity zone-and-conduit per IEC 62443, and full design documentation per IEC 61511 Cl.11-12.

SIS Design and Engineering

Individual significance for organisations

Design quality determines the SIS's lifecycle behaviour — its actual integrity, spurious-trip frequency, proof-test cost, and ageing pathway. Poor design choices cost the site for the 20-25 year lifecycle of the asset.

Contribution to Functional Safety Lifecycle Implementation

Phase 4 produces the as-designed SIS that Phase 5 commissions and Phase 6 operates. The Safety Manual it produces (per Cl.16) is the master document for the entire SIS lifecycle.

Key requirements

What compliant execution looks like

Architecture selection per SIL target and MTTFS budget
FMEDA data per IEC 61508 from TÜV / exida / SIRA
PFD / PFH verification per IEC 61508-6 Annex B
IEC 62443 cybersecurity zone-and-conduit design
Implementation methodology

How we implement this element

A focused 6-step methodology calibrated to deliver sis design and engineering as a working capability — not a documented compliance artefact.

Architecture Selection

Select architecture (1oo1 / 1oo1D / 1oo2 / 2oo3) per SIL target, MTTFS budget, CCF mitigation, and prior-use evidence.

Component Selection per FMEDA

Choose TÜV / exida / SIRA-certified sensors, logic solvers, final elements; verify FMEDA data sheets (λDD, λDU, SFF, DC).

PFD / PFH Verification

Calculate per IEC 61508-6 Annex B using fault tree or Markov; include β-factor common-cause per Annex D; verify SIL target met.

Architectural Constraint Check

Per Cl.11 — Route 1H (HFT + SFF) vs Route 2H (reliability data); document compliance with constraints.

Cybersecurity Design

IEC 62443 zone-and-conduit; segregation from BPCS / corporate; access control; align with NIST SP 800-82.

Design Documentation & Safety Manual

Issue design report, hardware specs, software specs, cause-and-effect, Safety Manual per Cl.16.

Implementation flow

Element-implementation flow chart

Decision-gated workflow showing the actual sequence of activities — from initiation through steady-state operation — with key decision points highlighted.

Start
SRS received from Phase 3
Architecture Trade-Off
1oo1D / 1oo2 / 2oo3 per SIL + MTTFS
FMEDA Component Selection
TÜV / exida certified
PFD / PFH Calculation
Per IEC 61508-6 Annex B
Decision
Target SIL Met?
Decision gate
Cybersecurity Design
IEC 62443 zone-and-conduit
Safety Manual Compilation
Per Cl.16 — operating + proof-test + MOC
Design Hand-Off to Phase 5
Installation, commissioning, validation
Deliverables

What we produce

  • SIS design report with architecture and PFD/PFH calculation
  • FMEDA-graded component selection register
  • Safety Manual per IEC 61511 Cl.16
Common pitfalls

Where execution fails

  • Prior-use claim without statistical evidence
  • β-factor scoring optimistic vs site context
  • Cybersecurity bolted on after design freeze
Related elements

Explore related elements in this framework

All elements in this framework

Functional Safety Lifecycle Implementation — full element index

Implement this element

Talk to us about implementing SIS Design and Engineering

We can scope this element implementation against your facility, regulatory context, and existing management-system maturity — and integrate it with the other Functional Safety Lifecycle Implementation elements you already operate.