What SIL Level Do You Need? How Safety Integrity Level Targets Are Actually Set
A Safety Integrity Level describes how reliably a safety function has to work. SIL 1 is the lowest and SIL 4 the highest, and each step represents an order of magnitude more risk reduction than the one below it.
The more useful question is not what SIL means but which one your function needs, and the answer to that is derived rather than chosen. SIL targets come out of an assessment of the hazard, its consequence and the protection already present. A number selected because a similar plant used it, or because a vendor suggested it, will not survive scrutiny at assessment.
What Each Level Means
|
SIL |
Risk Reduction Factor |
Interpreted As |
|
SIL 1 |
10 to 100 |
The function fails on demand less than once in ten attempts |
|
SIL 2 |
100 to 1,000 |
Typical target for most process industry safety functions |
|
SIL 3 |
1,000 to 10,000 |
High consequence hazards; significant architecture and cost implications |
|
SIL 4 |
10,000 to 100,000 |
Rare in process industry; IEC 61511 encourages alternative risk reduction instead |
Two things are worth noticing. Each level is ten times more demanding than the one below, so the difference between SIL 2 and SIL 3 is not incremental. And SIL 4 is deliberately discouraged in process applications, because a function requiring that much reliability usually indicates the hazard should be reduced by other means.
How a Target Is Derived
The sequence is fixed, and skipping steps is what produces indefensible targets.
- Identify the hazard. A HAZOP or equivalent hazard study produces the scenario: cause, deviation, consequence.
- Establish the consequence. What happens if the function fails when required. Safety, environmental and financial consequences are usually assessed separately.
- Count existing protection. Layers already present reduce the risk before the safety instrumented function is considered.
- Calculate the gap. The difference between the residual risk and the tolerable risk criteria is the required risk reduction, and that maps directly to a SIL. LOPA is the most widely used method for this step.
- Record the basis. The target has to trace back to the scenario. A number without that chain fails at assessment.
|
Why higher is not safer Specifying SIL 3 when the risk assessment supports SIL 2 is not a conservative choice. Higher levels demand redundant architecture, more frequent proof testing and certified devices throughout, which raises capital cost, maintenance burden and spurious trip rate. Spurious trips carry their own risk, since an unplanned shutdown is itself a process upset. Over-specification is a real failure mode, not a safe default. |
What Determines Where a Function Lands
- Consequence severity. The dominant factor. Potential for multiple fatalities or a major release pushes targets upward quickly.
- Demand rate. How often the function is expected to be called on. It also determines whether low demand or high demand mode applies, which changes the metric entirely.
- Existing independent protection layers. Relief devices, alarms with operator response, and mechanical protection all reduce what the instrumented function has to deliver.
- Tolerable risk criteria. Your own documented risk tolerance sets the threshold. Without approved criteria, no target is defensible.
Having a Target Is Not the Same as Meeting It
A determination study produces the target. It says nothing about whether the system you built achieves it. That requires SIL verification: calculating the actual probability of failure on demand for the installed loop and confirming it falls within the band.
This distinction catches people out regularly. Operators hold a determination report, assume they are compliant, and discover at functional safety assessment that no verification calculation exists. Our guide to determination, verification and validation explains where each one sits.
Why Choose Arista Cyber
Arista Cyber runs SIL assessment and determination as part of the full lifecycle, from hazard study through verification, with TUV Rheinland certified practitioners.
That matters because determination quality depends on the hazard study feeding it. A HAZOP scoped only for regulatory compliance frequently records consequences too coarsely to support LOPA, which means revisiting it and paying twice. We scope the hazard study knowing SIL work will follow, so scenarios carry the detail the determination needs first time.
Next Steps
If you have been handed a SIL requirement in a specification and are not sure where it came from, that is worth establishing before design proceeds. Explore our functional safety services, read our guide to functional safety standards, or contact the Arista Cyber team.
Common Questions
What is SIL in simple terms?
Safety Integrity Level is a measure of how reliably a safety function performs when called upon. SIL 1 through SIL 4 each represent an order of magnitude of risk reduction, with SIL 1 the lowest and SIL 4 the highest. A SIL 2 function, for example, must reduce risk by a factor between 100 and 1,000.
Can we just specify SIL 3 to be safe?
It is not a safe default. Higher SIL requires redundant architecture, certified components and more frequent proof testing, which increases cost, maintenance load and the rate of spurious trips. An unplanned shutdown is itself a process upset carrying risk. The defensible target is the one the risk assessment supports, neither higher nor lower.
Does every safety function need a SIL?
No. A SIL applies to safety instrumented functions, meaning instrumented protection implemented through sensors, a logic solver and final elements. Mechanical protection such as relief valves, and procedural or alarm-based protection, are layers of protection but are not assigned a SIL. Our guide to SIF, SIS and BPCS covers what qualifies as which.
|
Not sure where your SIL target came from? Arista Cyber derives SIL targets that trace back to documented hazard scenarios, so they hold up at assessment. |