LOPA Explained: How Layer of Protection Analysis Bridges HAZOP and SIL
A HAZOP tells you what can go wrong. A SIL target tells you how reliable your protection has to be. Layer of Protection Analysis is the step in between, and it is where most of the actual decision-making about safety instrumented systems happens.
LOPA takes the scenarios a hazard study produced, counts the protection already in place, and calculates the gap between the risk you have and the risk you are willing to accept. That gap becomes the required risk reduction, and the required risk reduction becomes the SIL target for a safety instrumented function. Get LOPA wrong and every SIL claim downstream inherits the error. If you have not yet run the hazard study, start with our guide to when a HAZOP is required.
Where LOPA Sits
LOPA is semi-quantitative. It sits between a qualitative HAZOP, which identifies scenarios without assigning numbers, and a full quantitative risk assessment, which models consequences in detail and costs considerably more. For most process industry applications LOPA provides enough rigour to defend a SIL target without the expense of full QRA.
|
Step |
Method |
Output |
|
1. Identify scenarios |
HAZOP or HAZID |
Cause, deviation, consequence for each node |
|
2. Quantify risk gap |
LOPA |
Required risk reduction for each scenario |
|
3. Assign integrity target |
SIL determination |
SIL target for each safety instrumented function |
|
4. Specify the function |
Safety requirements specification |
What each SIF must do, and to what integrity |
IEC 61511 recognizes LOPA as an acceptable method for SIL determination, and it is by some distance the most widely used one in process industries.
How the Calculation Works
For each scenario, LOPA establishes an initiating event frequency, then applies a probability of failure on demand for each independent protection layer that stands between the initiating event and the consequence. Multiplying them gives a mitigated event frequency.
That mitigated frequency is compared against your tolerable risk criteria. Where the mitigated frequency is already below the tolerable threshold, no safety instrumented function is required. Where a gap remains, the size of that gap determines the SIL target. Our SIL assessment and determination guide covers how the target maps to a risk reduction factor.
The arithmetic is straightforward. The judgment sits entirely in two places: what initiating event frequency you assign, and what you are willing to count as a protection layer.
What Actually Qualifies as an Independent Protection Layer
This is where LOPA studies most often fail assessment. A protection layer can only be credited if it meets specific criteria, and the criteria are stricter than teams under schedule pressure tend to apply.
- Independent. It must be independent of the initiating cause and of every other layer being credited. A layer that shares a sensor, a logic solver or a final element with another credited layer is not independent.
- Effective. It must actually prevent the specific consequence in the specific scenario, not a similar one.
- Auditable. Its performance must be verifiable through testing and records. A layer whose integrity cannot be demonstrated cannot be credited.
- Of known integrity. There must be a defensible basis for the probability of failure on demand claimed, whether from vendor data, industry data or plant history.
|
The three credits that most often get removed at assessment First, claiming the basic process control system more than once. The BPCS is a single system, so crediting it as two separate layers in the same scenario is not independence. Second, claiming operator response without adequate detection, sufficient time to act, and a documented procedure the operator is trained on. Third, claiming a vendor package system as a protection layer without failure data or an integrity claim behind it, which is a particular problem with battery management systems on energy storage projects. |
Where LOPA Studies Go Wrong
- Optimistic initiating event frequencies. Selecting a favorable figure from a data source without documenting why it applies to your equipment and service.
- Layers credited that are not independent. The most common finding, and usually a shared element rather than a shared concept.
- Scenarios inherited from a HAZOP that lacks the detail. A hazard study scoped for regulatory compliance frequently records consequences too coarsely to support LOPA, which means revisiting it. This is why studies intended to feed SIL work should be scoped that way from the start, as our HAZOP cost guide explains.
- Tolerable risk criteria not formally set. LOPA cannot produce a defensible answer without documented and approved risk tolerance criteria. Establishing them mid-study invites the accusation that they were set to suit the result.
- No traceability back to the scenario. A SIL target that cannot be traced to the LOPA and back to the hazard scenario fails at functional safety assessment regardless of how sound the calculation was.
When LOPA Is Not the Right Tool
LOPA is well suited to scenarios with a single identifiable initiating event and a linear chain of protection. It handles most process industry cases well. It handles some cases poorly.
Scenarios with multiple simultaneous initiating events, complex interdependent protection, or consequences that depend heavily on dispersion and ignition modelling are better served by quantitative risk assessment. Emerging technologies are another case where care is needed: thermal runaway in battery storage and hydrogen release scenarios both behave in ways that generic process failure data does not describe well, which we cover in our guide to functional safety for battery storage and hydrogen.
Why Choose Arista Cyber
Arista Cyber runs LOPA as part of a connected lifecycle rather than as a standalone exercise, which matters because LOPA quality is determined largely by what comes before and after it.
We scope the HAZOP so that scenarios carry the cause and consequence detail LOPA needs, which avoids the common and expensive pattern of running the hazard study twice. We take LOPA through to SIL determination and into the safety requirements specification, so the traceability an assessor looks for exists from the outset. And because our practitioners are TUV Rheinland certified, the competence behind the protection layer judgments is documented, which is itself an assessment requirement.
Next Steps
If you have hazard scenarios and no defensible SIL basis, or a LOPA with credits you are not confident would survive review, that is worth addressing before the next assessment. Explore our functional safety services, read our guide to functional safety standards, or contact the Arista Cyber team.
Common Questions
What is the difference between HAZOP and LOPA?
HAZOP is qualitative and identifies what can go wrong, using guidewords to examine deviations from design intent across each node. LOPA is semi-quantitative and takes selected HAZOP scenarios, applies frequencies and failure probabilities, and calculates whether existing protection is sufficient. HAZOP finds the scenarios; LOPA decides which ones need a safety instrumented function and how reliable it must be.
Can the basic process control system be credited as a protection layer?
Typically once, and only where it is genuinely independent of the initiating cause. Crediting the BPCS twice in the same scenario is not independence, since it is a single system with shared elements. Where the initiating event is itself a BPCS failure, the BPCS cannot be credited as protection against it at all. This is one of the most frequently removed credits at assessment.
Do we need LOPA if our HAZOP already assigned SIL targets?
SIL targets assigned during a HAZOP without a documented determination method are difficult to defend. IEC 61511 requires the target to follow from an assessment of risk, and an assessor will ask how the number was reached. Where the answer is engineering judgment in the room, the claim usually fails. LOPA provides the documented basis. See our guide to the five functional safety assessment stages for what assessors examine.
|
Need a defensible SIL basis? Arista Cyber delivers HAZOP, LOPA and SIL determination as one connected engagement, so the traceability holds from scenario to safety function. |