BLOG

Date
22-09-2026

Functional Safety

SIL Assessment for Oil and Gas: What Upstream, Midstream and Downstream Operators Need

Oil and gas carries more safety instrumented functions per facility than almost any other sector, and the SIL requirements differ considerably depending on where in the value chain you sit. An upstream wellhead, a compressor station and a refinery hydrotreater present different hazards, different demand rates and different practical constraints on how protection can be implemented.

This guide covers what SIL assessment involves across each segment and what operators need in place. If you need the underlying framework first, start with our guide to how SIL targets are set.

 

Upstream: Wellheads, Separation and Remote Sites

Upstream safety functions typically protect against overpressure, loss of containment and well control events. Common instrumented functions include high pressure shutdown on separators and flowlines, emergency shutdown valves, and wellhead safety systems.

The distinctive constraint is remoteness. Sites are frequently unmanned, which removes operator response as a credited protection layer and pushes more of the risk reduction onto the instrumented function. That tends to raise SIL targets relative to a manned facility with the same hazard. Proof testing also becomes a logistics problem: a shorter interval improves the calculation but requires someone to travel to site, so the proof test regime has to be one the organization will actually sustain.

 

Midstream: Pipelines, Compression and Metering

Midstream functions protect against overpressure, rupture and unintended release across geographically distributed assets. Typical instrumented functions include pipeline overpressure protection, compressor station emergency shutdown, and station isolation on leak detection.

The characteristic challenge is that a single function may span considerable distance, with sensor, logic solver and final element separated by kilometers and connected by communications that are themselves a potential failure point. Verification has to account for the whole loop including that path. These are also the assets where cybersecurity and functional safety intersect most directly, because remote SCADA access reaches the same systems.

 

Downstream: Refining and Petrochemical

Downstream carries the highest density of safety instrumented functions. Fired heaters, distillation columns, hydrotreaters, reactors and storage all have instrumented protection, frequently many functions per unit.

Two things distinguish downstream SIL work. Continuous operation means proof testing and any remediation requiring a shutdown have to align to turnaround cycles that may run several years apart, so a verification shortfall discovered mid-cycle can sit unresolved for a long time. And the sheer number of functions makes traceability an administrative challenge in its own right: a refinery with several hundred safety instrumented functions needs each one traceable to a scenario, a target and a calculation.

 

Segment

Typical Safety Functions

Distinctive Constraint

Upstream

High pressure shutdown, ESD valves, wellhead safety systems

Unmanned sites remove operator response as a credited layer

Midstream

Pipeline overpressure protection, compressor ESD, station isolation

Loop components separated by distance; communications in the path

Downstream

Fired heater trips, column protection, reactor shutdown, tank overfill

Continuous operation; turnaround cycles govern remediation timing

LNG and terminals

Cryogenic protection, ESD, marine transfer isolation

Multi-framework regulatory overlay across a single facility

 

The constraint that shapes everything in oil and gas

When the next shutdown window is three years away, a verification shortfall is not a three-week fix. Operators who discover at assessment that a loop cannot reach its target face either an interim risk acceptance with compensating measures, or an unplanned outage. Running verification during design rather than after commissioning is what avoids that position entirely, and it costs a fraction as much.

 

What Oil and Gas Operators Should Have in Place

  • A current hazard study covering every unit, with scenarios detailed enough to support LOPA
  • SIL targets for every safety instrumented function, traceable back to a documented scenario
  • Verification calculations for each function, including the final element. See our guide to SIL verification
  • A safety requirements specification defining what each function does and to what integrity
  • Proof test procedures with intervals consistent with the verification calculation, and a maintenance schedule that matches
  • Validation records from commissioning, and functional safety assessment evidence at the relevant lifecycle stages

 

Why Choose Arista Cyber

Arista Cyber works extensively across oil and gas, with TUV Rheinland certified practitioners and direct experience of the operational constraints that shape functional safety in this sector.

We deliver across Houston and the Gulf Coast, Calgary and Edmonton, and internationally. That matters because the regulatory overlay differs by jurisdiction while the engineering does not, and a provider working in one market only tends to produce documentation that has to be reworked for the other. We also work across both functional safety and OT cybersecurity, which is increasingly relevant for remotely operated midstream assets.

 

Next Steps

If your safety instrumented functions have targets but the verification chain is incomplete, that is the gap worth closing before your next assessment. Explore our functional safety services, read about SIL determination, verification and validation, or contact the Arista Cyber team.

 

Common Questions

What SIL level do most oil and gas safety functions need?

SIL 2 is the most common target across the sector, with SIL 1 appearing for lower consequence functions and SIL 3 reserved for the highest consequence hazards. There is no standard answer, because the target is derived from the specific hazard, the consequence, and the protection already present. A facility quoting a blanket SIL for all functions has not done a determination.

Do unmanned sites need higher SIL targets?

Frequently yes, though not automatically. Operator response can be credited as a protection layer only where there is adequate detection, sufficient time to act, and a trained procedure. At an unmanned site that credit generally cannot be claimed, which leaves more risk reduction for the instrumented function to provide and can push the target up a level.

How do turnaround cycles affect SIL work?

Considerably. Proof testing, device replacement and any architecture change generally require a shutdown, so remediation timing is governed by the turnaround schedule rather than by the urgency of the finding. This is the main argument for running verification during design rather than discovering a shortfall after commissioning, when the next window may be years away.

 

Need SIL assessment for oil and gas operations?

Arista Cyber delivers the full functional safety lifecycle across upstream, midstream and downstream, in North America and internationally.

Book a Free Consultation

BOOK YOUR CONSULTATION