Functional Safety Lifecycle Implementation

Decommissioning

Safe removal from service with hazard mitigation per IEC 61511 Cl.18

Strategic context

What this element is — and why it matters

Phase 8 closes the SIS lifecycle — safe removal from service, hazard mitigation during transition, and documentation retention. Per Cl.18, decommissioning must be planned to maintain protection of personnel and environment throughout the transition, with PHA-driven hazard analysis where the unit continues to operate without the SIS.

Decommissioning

Individual significance for organisations

Decommissioning is the often-overlooked phase where partial protection during transition creates the highest residual risk. Sites that plan Phase 8 properly maintain personnel safety during plant retirement or major restructuring.

Contribution to Functional Safety Lifecycle Implementation

Phase 8 closes the audit trail for the SIS lifecycle. Documentation produced (final FSA, decommissioning record) supports any post-event investigation or liability defence for legacy operations.

Key requirements

What compliant execution looks like

Decommissioning plan per Cl.18.2 with hazard analysis
Phased shutdown maintaining personnel and environmental protection
Documentation retention per OSHA PSM record-keeping requirements
Final FSA covering full lifecycle
Implementation methodology

How we implement this element

A focused 6-step methodology calibrated to deliver decommissioning as a working capability — not a documented compliance artefact.

Decommissioning Scope

Catalogue affected SIFs, units, dependencies; identify duration and phasing requirements.

Hazard Analysis

Per Cl.18.2 — assess hazards during shutdown transition; identify any operation without SIS; specify compensating controls.

Phased Plan Development

Build sequenced shutdown; specify temporary protections; align with utility isolation, process inerting, residual fluid removal.

Execution & Monitoring

Execute per plan; monitor against hazard analysis predictions; trigger MOC if deviation required.

Removal & Disposition

Physical removal or isolation; cybersecurity de-commissioning; documentation of final configuration.

Final FSA & Record Retention

Final functional safety assessment; retain documentation per OSHA PSM (m)(6) and corporate requirements.

Implementation flow

Element-implementation flow chart

Decision-gated workflow showing the actual sequence of activities — from initiation through steady-state operation — with key decision points highlighted.

Start
Decommissioning decision made
Affected SIFs Catalogued
Including dependencies
Hazard Analysis per Cl.18.2
Including transition hazards
Decision
Compensating Controls Needed?
Decision gate
Phased Plan Approved
Sequenced shutdown + temp protection
Execution + Monitoring
Per plan; MOC if deviation
Physical Removal/Isolation
Cybersecurity de-commissioning
Final FSA + Records Retained
Per OSHA PSM + corporate
Deliverables

What we produce

  • Decommissioning plan with hazard analysis
  • Phased shutdown record
  • Final FSA report + retained documentation pack
Common pitfalls

Where execution fails

  • Transition operation without compensating controls
  • Cybersecurity de-commissioning skipped (legacy attack surface)
  • Documentation retention shorter than statutory requirement
Related elements

Explore related elements in this framework

All elements in this framework

Functional Safety Lifecycle Implementation — full element index

Implement this element

Talk to us about implementing Decommissioning

We can scope this element implementation against your facility, regulatory context, and existing management-system maturity — and integrate it with the other Functional Safety Lifecycle Implementation elements you already operate.