Skip to content
Functional Safety Lifecycle Implementation

Operation and Maintenance

We manage proof testing, repair, demand response and bypass control to IEC 61511 clause 16

Strategic context

What this element is and why it matters

Phase 6 covers the operational life of the safety instrumented system through proof testing that verifies continued integrity of each function, repair when failures are detected, response to actual demand events and disciplined control of bypasses and overrides. Clause 16 also asks for a documented safety manual that your operating teams reference every day.

Operation and Maintenance

Individual significance for organisations

Phase 6 is where the safety instrumented system either earns or loses the integrity it claims. Facilities with disciplined proof testing hold their safety integrity level claims across a 20 year life, while sites without it accumulate undetected failures that only surface during a real demand, and we keep your facility firmly in the first group.

Contribution to Functional Safety Lifecycle Implementation

Phase 6 generates the operational reliability data that feeds back into Phase 4 for re verification when components change and informs the modification triggers of Phase 7. It also produces the Stage 4 functional safety assessment evidence that proves your safety integrity level claims remain valid.

Key requirements

What compliant execution looks like

A proof test programme to clause 16.3 with documented proof test coverage
A repair procedure to clause 16.4 with mean time to repair tracking
Demand response analysis to clause 16.5
Bypass and override management to clause 16.2
Partial stroke testing of final elements between the full proof tests
As found failure data reconciled against the assumed dangerous undetected failure rate and spurious trip rate
Implementation methodology

How we implement this element

A focused six step methodology calibrated to deliver operation and maintenance as a working capability rather than a documented compliance artefact.

Proof Test Procedure Development

We author a procedure for each function covering the sensor stimulus, the logic verification and the final element actuation, and we specify the proof test coverage from the coverage analysis.

Proof Test Execution

We execute at the calculated interval derived from the probability of failure on demand, document the as found and as left condition, and trigger repair if any failure is found.

Repair and Failure Reporting

To clause 16.4 we track mean time to repair, establish the root cause for revealed failures and notify the functional safety engineer of any systematic pattern.

Demand Response Analysis

To clause 16.5 we analyse each demand response, verify that the function acted successfully and identify any systematic issue.

Bypass and Override Management

To clause 16.2 we set the authorisation hierarchy, the time limits, the compensating measures and the audit log, and we align with management of change for any extended bypass.

Stage 4 Operational Assessment

Every three to five years to paragraph o of OSHA PSM and IEC 61511 we review the proof test records, the demand responses and the modifications.

Implementation flow

Element implementation flow chart

A decision gated workflow that shows the actual sequence of activities from initiation through steady state operation, with key decision points highlighted.

Start
The system in operation after Phase 5 validation
Decision
Proof Test Due?
Decision gate against the proof test interval schedule
Proof Test Execution
From the sensor through the logic to final element actuation
Decision
Failure Detected?
Decision gate
Repair to Cl.16.4
Track mean time to repair and the root cause
Demand Event Response
Analyse to clause 16.5
Decision
Bypass Required?
Authorisation and time limit to clause 16.2
As Found Data Logged
Reconcile against the assumed failure rate and average probability of failure on demand
Decision
Average Probability of Failure Still Met?
Decision gate to re verify or shorten the proof test interval
Stage 4 Assessment Cycle
Every three to five years to paragraph o of OSHA PSM
Deliverables

What we produce

  • A proof test programme for each function
  • A repair and failure tracking database
  • A Stage 4 operational assessment pack
  • As found and as left proof test records with the coverage basis
  • A bypass and override log with compensating measures and time limits
  • A reliability data reconciliation comparing the field failure rate against the assumed average probability of failure
Common pitfalls

Where execution fails

  • Proof test coverage claimed higher than what is actually achievable
  • Bypasses authorised by operators without any compensating measures
  • Demand responses that are never formally analysed
  • A proof test interval that is never shortened even when as found failures exceed the assumptions
Standards & references

Codes this element is built on

IEC 61511 1 Cl.16 (Operation and Maintenance)OSHA 29 CFR 1910.119(j) (Mechanical Integrity)exida CFSE Body of Knowledge (Proof Testing)ISA TR84.00.03 (proof test coverage and partial stroke testing)ISA TR84.00.04 (as found failure data and average probability of failure reconciliation)CCPS Guidelines for Safe and Reliable Instrumented Protective Systems
Implement this element

Talk to us about implementing Operation and Maintenance

We can scope this element implementation against your facility, regulatory context, and existing management system maturity, then integrate it with the other Functional Safety Lifecycle Implementation elements you already operate.