Skip to content
Functional Safety Lifecycle Implementation

Modification

We govern controlled change to the hardware, software and operating conditions of the safety instrumented system to IEC 61511 clause 17

Strategic context

What this element is and why it matters

Phase 7 governs every change to the safety instrumented system, whether that is a sensor replacement, a logic solver migration, a software update, a voting change, a setpoint adjustment or an operating mode change. To IEC 61511 clause 17 a modification must trigger a fresh hazard and risk assessment, a specification update, design verification and re validation as appropriate, and our team makes sure none of those steps are skipped.

Modification

Individual significance for organisations

Phase 7 prevents the silent degradation of safety integrity that drives most field failures of safety instrumented systems. Uncontrolled modifications collapse the safety integrity level claims and produce the familiar pattern of a system commissioned for SIL 2 that is actually operating at SIL 1.

Contribution to Functional Safety Lifecycle Implementation

Phase 7 re enters the earlier lifecycle phases according to the impact of the modification. It also integrates with your site management of change to paragraph l of OSHA PSM and with the pre startup safety review to paragraph i so that the modified system is re validated before it goes live.

Key requirements

What compliant execution looks like

A management of change procedure for modifications to clause 17
An impact assessment across the hazard and risk assessment, the specification, the design and validation
Re validation to clause 15 for any material change
A pre startup safety review to paragraph i of OSHA PSM before highly hazardous chemicals are reintroduced
A clear determination of replacement in kind versus modification before any work begins
Re verification of the probability of failure whenever the component or the voting architecture changes
Implementation methodology

How we implement this element

A focused six step methodology calibrated to deliver modification as a working capability rather than a documented compliance artefact.

Modification Scope Definition

We catalogue the change across component, logic, setpoint, voting and operating mode and align it with your site management of change procedure.

Impact Assessment

To clause 17.2 we assess the impact on the hazard and risk assessment, the specification, the design and validation and identify the lifecycle re entry point.

Lifecycle Re Entry

We re execute the affected phases, including revalidating the hazard and risk assessment if the hazard set changes, updating the specification, verifying the design and rerunning the factory and site acceptance tests and validation.

Cybersecurity Re Assessment

To IEC 62443 we verify that the modification introduces no new attack vectors and no zone violations.

Re Validation to Cl.15

We verify the function from end to end before live operation and document the evidence to clause 17.4.

Pre Startup Safety Review Closure

We run the pre startup safety review to paragraph i of OSHA PSM to confirm readiness and secure site leadership sign off before highly hazardous chemicals are reintroduced.

Implementation flow

Element implementation flow chart

A decision gated workflow that shows the actual sequence of activities from initiation through steady state operation, with key decision points highlighted.

Start
Modification proposed across hardware, software or setpoint
Management of Change Trigger
To the site procedure and IEC 61511 clause 17
Decision
Replacement in Kind?
Decision gate where a true replacement in kind exits to documentation
Impact Assessment
Which lifecycle phases are affected?
Decision
Hazard and Risk Revalidation Needed?
Decision gate
Specification Update
A refresh of the functional and integrity requirements
Design Re Verification
Probability of failure if there is a component change
Decision
Probability of Failure Re Verified?
Decision gate where the safety integrity level is still met after the change
Re Validation to Cl.15
End to end function verification
Pre Startup Safety Review and Live Operation
To paragraph i of OSHA PSM with leadership sign off
Deliverables

What we produce

  • A management of change pack with an impact assessment for each phase
  • Re validation evidence for each modified function
  • A pre startup safety review sign off record
  • A determination record of replacement in kind versus modification
  • An updated probability of failure calculation and a specification revision
  • A cybersecurity re assessment to IEC 62443
Common pitfalls

Where execution fails

  • A like for like change misclassified as a replacement in kind
  • Cybersecurity not re assessed for digital changes
  • A pre startup safety review closed before re validation is complete
  • FMEDA data of a substitute device that is not equivalent to the original, with drift in safe failure fraction and dangerous undetected failure rate
Standards & references

Codes this element is built on

IEC 61511 1 Cl.17 (Modification)OSHA 29 CFR 1910.119(l) (Management of Change)OSHA 29 CFR 1910.119(i) (Pre Startup Safety Review)IEC 61511 1 Cl.15 (re validation after modification)IEC 62443 (cybersecurity re assessment of changes)CCPS Guidelines for the Management of Change for Process Safety
Implement this element

Talk to us about implementing Modification

We can scope this element implementation against your facility, regulatory context, and existing management system maturity, then integrate it with the other Functional Safety Lifecycle Implementation elements you already operate.