BLOG

Date
07-09-2026

Functional Safety

Functional Safety Assessment: What Happens at Each of the Five Stages

A functional safety assessment is a structured examination of whether your safety instrumented system genuinely achieves the safety integrity you have claimed for it. Under IEC 61511 it happens at five defined points in the lifecycle rather than once at the end, and each stage examines different evidence. Organizations that treat it as a single end-of-project audit routinely fail, because by then the evidence from earlier stages either exists or it does not.

This guide sets out what each stage examines, who should conduct it, and what to have ready. If you need to establish which standard governs your assessment first, start with our guide to functional safety standards.

 

What an FSA Actually Examines

An FSA is not a repeat of your hazard study or your SIL calculations. It is an examination of whether the lifecycle was followed, whether the evidence supports the integrity claim, and whether the people who did the work were competent to do it. Assessors look for traceability above all: can a SIL 2 claim on a specific safety function be traced back through the SRS, the SIL determination, and the hazard scenario that generated it? Where that chain breaks, the claim fails regardless of how good the individual documents look.

 

The Five Assessment Stages

 

Stage

When It Occurs

What It Examines

FSA 1

After hazard and risk assessment and SIL allocation

Whether hazards were systematically identified and SIL targets are justified

FSA 2

After the safety requirements specification is complete

Whether the SRS fully and unambiguously defines each safety function

FSA 3

After design and engineering, before installation

Whether the design meets the SRS and the SIL calculations are sound

FSA 4

After installation and before startup

Whether the installed system was validated and is ready for service

FSA 5

Periodically during operation and after modification

Whether integrity has been maintained through proof testing and change

 

Stage 1 and 2: the foundation stages

These two determine whether everything downstream is defensible. Stage 1 examines whether the hazard study was systematic and whether SIL targets follow from documented scenarios rather than from convention or copied precedent. Stage 2 examines the SRS. Both depend on a current hazard study, which is why the HAZOP has to come first and why a study scoped only for regulatory compliance frequently lacks the detail LOPA and SIL determination need.

 

Stage 3 and 4: the engineering stages

Stage 3 examines the design against the SRS, including SIL verification calculations, architecture, device selection and the failure data behind it. Stage 4 examines validation: proof that the installed system performs each safety function as specified. Stage 4 is where projects most often stall, because validation evidence has to be produced during commissioning and cannot be reconstructed afterwards.

 

Stage 5: the operational stage

Stage 5 recurs. It examines whether proof testing has been performed at the required intervals, whether modifications went through management of change with impact assessment, and whether the integrity claim still holds. This is the stage most operators neglect, and it is where the majority of findings on established plants originate.

 

The finding auditors raise most often

Competence records. IEC 61511 requires that people performing lifecycle activities be competent for the work, and it requires that competence to be documented. Organizations routinely have capable engineers and no evidence of it. This is entirely avoidable, and it is one of the fastest findings to close.

 

Independence: Who Can Conduct an FSA

IEC 61511 sets independence requirements that increase with consequence and SIL. Lower-consequence functions can be assessed by someone independent of the specific design activity but within the same organization. Higher SIL and higher consequence applications call for independence from the project team, and in the highest cases from the organization itself.

The practical effect is that a design engineer cannot assess their own work at any meaningful SIL, and internal assessment becomes progressively harder to defend as consequence rises. Our guide to choosing a functional safety consultant covers how to evaluate independence and competence in an assessor.

 

What to Have Ready

  • Current hazard study with documented scenarios, causes and consequences
     
  • SIL determination records showing how targets were derived
     
  • Safety requirements specification for every safety instrumented function
     
  • SIL verification calculations with the failure data sources used
     
  • Validation records from commissioning
     
  • Proof test procedures, intervals and completed test records
     
  • Management of change records for every modification since the last assessment
     
  • Competence records for everyone who performed lifecycle activities

 

Why Choose Arista Cyber

Arista Cyber conducts independent functional safety assessments across all five stages, led by TUV Rheinland certified practitioners with the independence that higher SIL applications require.

Because we deliver the full lifecycle, we can also close what an assessment finds. Where a stage 1 assessment reveals that SIL targets are not traceable to hazard scenarios, we can run the HAZOP and SIL determination that fixes it. Where stage 4 reveals missing validation evidence, we can run the validation and verification work. That matters because a report listing findings you cannot close has limited value.

 

Next Steps

If you have an assessment scheduled or a finding to close, the first step is establishing which stage applies and what evidence exists. Explore our functional safety assessment services, read about closing assessment findings, or contact the Arista Cyber team.

 

Common Questions

Do we need all five assessment stages?

The stages apply to the lifecycle phases you undertake. A new installation passes through all five over time. An existing plant not undergoing modification is primarily concerned with stage 5, the periodic operational assessment. A modification project triggers assessment of the phases the change touches.
 

Can we conduct the FSA internally?

Sometimes, depending on SIL and consequence. IEC 61511 independence requirements scale with risk. Lower SIL functions can be assessed by someone independent of the specific design work. Higher SIL and higher consequence applications call for independence from the project team or the organization. In all cases the assessor must have documented competence.
 

How long does a functional safety assessment take?

A stage assessment on a single well-documented unit typically runs one to two weeks including reporting. Poor documentation is the main variable, since assessors cannot examine evidence that has to be assembled during the assessment. Multi-unit facilities and combined multi-stage assessments run longer.

 

Preparing for a functional safety assessment?

Arista Cyber conducts independent FSAs across all five stages, and can close what the assessment finds. TUV Rheinland certified practitioners.

Book a Free Consultation

BOOK YOUR CONSULTATION