SIL Assessment and Determination: A Practical Guide for North American Operators
SIL assessment is one of those functional safety activities that sounds more settled than it is. Ask three engineers how a given safety function arrived at its Safety Integrity Level and you can get three different explanations, some of them wrong. Getting SIL assessment right matters, because the number you land on drives how much you spend on protection and how much risk you actually carry.
This guide explains SIL assessment and determination in practical terms for operators in Canada and the United States. It covers what a Safety Integrity Level is, the difference between assessment, determination, and verification, the two main methods used to set a SIL, the mistakes that most often go wrong, and what a proper engagement delivers.
A Safety Integrity Level is a measure of how much risk reduction a safety function must provide. IEC 61511 defines four levels, SIL 1 through SIL 4, each representing an order-of-magnitude greater reliability. A higher SIL means a more reliable, and usually more expensive, safety function.
What Safety Integrity Level Means
A Safety Integrity Level expresses the reliability required of a safety instrumented function. The concept exists because not every hazard warrants the same level of protection. A function guarding against a minor, easily recovered upset does not need the same reliability as one standing between normal operation and a catastrophic release. SIL is how functional safety puts a defensible number on that difference.
The four levels each represent a band of probability that the function will fail to perform when demanded. Moving up a level means roughly a tenfold improvement in reliability. That improvement is not free, which is why determining the correct SIL, rather than defaulting high to be safe, is an economic decision as much as a safety one.
SIL Assessment vs Determination vs Verification
These three terms are used loosely, often interchangeably, and that confusion causes real problems. They are distinct activities.
SIL determination
SIL determination is the process of deciding what SIL each safety function requires. It works forward from the hazard: given the consequence and likelihood of a hazardous event, how much risk reduction must this function deliver? This is where LOPA and risk graphs come in.
SIL verification
SIL verification works in the opposite direction. Given a safety function as designed, with its specific sensors, logic solver, and final elements, does it actually achieve the SIL that was required? Verification is a calculation against the hardware, covering failure rates, redundancy, and proof test intervals.
SIL assessment
SIL assessment is often used as an umbrella term covering both, and sometimes to mean an independent review of the whole functional safety picture. When you commission a SIL assessment, it is worth confirming exactly which activities are in scope, because the word means different things to different providers.
|
Activity |
Question It Answers |
|
SIL determination |
How much risk reduction does this safety function need to provide? |
|
SIL verification |
Does the function as designed actually achieve the required SIL? |
|
SIL assessment |
Umbrella term; confirm whether it covers determination, verification, or both. |
How SIL Is Determined: Risk Graph and LOPA
Two methods dominate SIL determination in North American practice. Both are recognized under IEC 61511, and each suits different situations.
Risk graph
A risk graph is a qualitative method. It routes each hazard through a series of parameters, consequence severity, frequency of exposure, possibility of avoidance, and demand rate, to arrive at a required SIL. It is quicker and works well for screening a large number of functions, but its qualitative nature means it depends heavily on consistent, well-calibrated judgment from the team applying it.
Layer of Protection Analysis (LOPA)
LOPA is semi-quantitative and more rigorous. It starts from an initiating event frequency, then credits each independent protection layer that reduces the risk, and calculates the remaining gap the safety instrumented function must close. LOPA is more defensible in front of an auditor because the reasoning is explicit and numerical, though it takes more time and data to perform.
In practice, many operators use a risk graph to screen functions quickly, then apply LOPA to the higher-consequence functions where a defensible, numerical justification is worth the extra effort. Using the right method for each function is itself a mark of a capable SIL assessment.
IEC 61511 and ANSI/ISA 84 Requirements
SIL assessment across North America rests on IEC 61511, the international standard for functional safety in the process sector. In the United States, that standard is adopted nationally as ANSI/ISA 84, which is the reference most US process safety engineers cite. The technical content is aligned, so a SIL assessment performed to IEC 61511 satisfies ANSI/ISA 84 expectations.
In Canada, IEC 61511 applies directly, with oversight distributed across provincial regulators. Wherever you operate, the standard expects SIL determination to be systematic, documented, and traceable, and it expects the people performing it to be competent. That competence expectation is why a certified functional safety expert is often involved in or reviewing the work.
Common SIL Assessment Mistakes
The same errors recur across facilities. Knowing them in advance is the cheapest way to avoid them.
-
Defaulting high to be safe. Assigning SIL 3 to functions that genuinely need SIL 1 wastes money on hardware, testing, and maintenance for no safety benefit. Over-specification is a real and common failure.
-
Claiming protection layers that are not independent. LOPA only credits layers that are genuinely independent of the initiating event and of each other. Crediting a layer that shares a common failure mode inflates the risk reduction on paper while leaving the real exposure unchanged.
-
Inconsistent risk graph calibration. When different teams apply the risk graph with different unstated assumptions, the results are not comparable and the whole exercise loses credibility.
-
Skipping verification after determination. Determining the required SIL is only half the job. If nobody verifies that the installed function achieves it, you have a target with no confirmation you met it.
-
Treating SIL as a one-time exercise. Process changes, modifications, and new hazards can change the required SIL. A SIL assessment that is never revisited slowly drifts out of date.
What a SIL Assessment Engagement Delivers
A properly scoped SIL assessment leaves you with more than a number per function. It produces a documented, traceable record: the hazards considered, the method applied, the assumptions made, the protection layers credited, and the resulting SIL for each safety instrumented function. That documentation is what makes the result defensible when a regulator or auditor asks how you arrived at it.
The strongest engagements also leave your team able to maintain the result. When a process change occurs, you should be able to see which functions it affects and reassess them, rather than commissioning the entire study again from scratch. This is where a mature functional safety program pays back, by making reassessment routine rather than a fresh project each time.
Frequently Asked Questions
What is a SIL assessment?
A SIL assessment establishes the Safety Integrity Level required for each safety instrumented function, and often verifies that the function as designed achieves it. It is a core functional safety activity under IEC 61511, and in the US under ANSI/ISA 84, that determines how much risk reduction each protective function must provide.
What is the difference between SIL determination and SIL verification?
SIL determination decides how much risk reduction a safety function needs, working forward from the hazard using methods like LOPA or a risk graph. SIL verification checks whether the function as designed actually achieves that required SIL, working from the hardware and its failure rates. Both are needed for a complete result.
What methods are used for SIL determination?
The two main methods are the risk graph, a quicker qualitative approach, and Layer of Protection Analysis (LOPA), a more rigorous semi-quantitative method. Many operators screen with a risk graph and apply LOPA to higher-consequence functions where a defensible numerical justification is worth the effort.
Does SIL assessment differ between the US and Canada?
The engineering is the same because both rest on IEC 61511, adopted in the US as ANSI/ISA 84 and applied directly in Canada under provincial regulators. A SIL assessment performed to IEC 61511 meets the technical expectations in both countries; the difference is in the surrounding regulatory framing.
Talk to a Functional Safety Expert
If you are scoping a SIL assessment, or you are not sure whether your existing SIL determinations would hold up to an audit, a short conversation will clarify where you stand. Book a free 30-minute consultation with one of our senior functional safety engineers, available to operators across Canada and the US.
[ Primary CTA: Book Your Free Consultation ]
[ Secondary CTA: Talk to a Functional Safety Expert ]