IEC 61508 and IEC 61511 use PFH as the system metric upon which the SIL is based. Een veelgebruikte basis om de ß factor te bepalen is de informatieve Annex D van IEC 61508:6. Common cause failures in safety instrumented systems require:
- Een adequaat functional safety management systeem
- Eisen aan de architectuur van de sensoren, de logic solver en de final elements
- Probabilistische randvoorwaarden van de SIF (gemiddelde probability of failure on demand, PFD)
- Dangerous Detected en Undetected faalgegevens van de instrumenten en componenten, λ
- Common cause β-factor in het geval van redundante configuraties

Methods include:
– reliability block diagrams
– Markov models
– fault-tree analysis

Probability of Failure on Demand (PFD): It is a measure of safety system performance in terms of the Probability of Failure on Demand (PFD). A PFD value of zero (0) means there is no probability of failure. Voor een SIF die moet voldoen aan SIL 1 of SIL 2 is het niet zinvol om gebruik te maken van geavanceerde software om de PFDavg te berekenen zolang diverse variabelen slechts schattingen zijn. We describe the philosophies that are standing behind the PFD and the THR.

Methods include:
– fault-tree analysis
– Markov models
– reliability block diagrams

A SIF shall be fit for purpose preventing the identified hazard. With the use of the Safe Failure Fraction and Probability of Failure on Demand values calculated during the product design and evaluation, SIL levels are determined using charts within the IEC 61508 standard. The correct performance of proof tests is critical. Almost all of these parameters are uncertain. SIL calculations involve: Average probability of failure on demand for the group of voted Channels. The paper will show also that reliability of the hardware (sensor, logic solver, HMI, final element) provides a lower limit for the probability of failure on demand for a safety IPL alarm. In de procesindustrie is de gemiddelde aanspraak op een beveiliging kleiner dan eens per jaar. In de geavanceerde versie wordt de prooftestdekking wel meegenomen in de berekening. The International Electrotechnical Commission's (IEC) standard IEC 61508 defines SIL using requirements grouped into two broad categories: hardware safety integrity and systematic safety integrity. Therefore all instruments used in a SIL rated system, including each instrument's sub components such as sensors, logic solvers and integral components are required to work safely and meet the Probability of Failure on Demand (PFD) requirements. In the process industry sector, the demand rate is often less frequent than once per year. SIL studies primarily classify safety systems according to one of four safety integrity levels (1–4). Probability of Failure on Demand is a probability value ranging from 0 to 1, inclusive. For the assessment of the "safety integrity level" (SIL) in accordance with the standard EN 61508 it is necessary to calculate the "probability of failure on demand" (PFD) of a safety related function. Probability of Failure on Demand (PFD) Safety Availability in % Risk Reduction Factor:
SIL 1: 0.01 - 0.1: 90 - 99: 10 - 100
SIL 2: 0.01 - 0.001: 99 - 99.9: 100 - 1000

Methods include:
– fault-tree analysis
– Markov models
– reliability block diagrams

SIL Verification Probability of Failure on Demand (PFD) Equation. Low demand mode is typical in the process industry.

Safety Integrity Level (SIL) Average probability of a dangerous failure on demand of the safety function (PFD avg):
4: ≥ 10-5 to < 10-4
3: ≥ 10-4 to < 10-3
2: ≥ 10-3 to < 10-2
1: ≥ 10-2 to < 10-1

IEC 61511 provides the following information: Several modelling approaches are available and the most appropriate approach is a matter for the analyst and can depend on the circumstances. For a given SIL, the Safe Failure Fraction (SFF), a measure for the share of tolerable failures, needs to be regarded when designing a safety relevant system with SIL-requirement. ß= 5% is almost standard. Low demand mode: For low demand mode, it can be assumed that the safety system is not required more than once per year. Some typical protection layer Probability of Failure on Demand (PFD):
• BPCS control loop = 0.10
• Operator response to alarm = 0.10
• Relief safety valve = 0.001
• Vessel failure at maximum design pressure = 10-4 or better (lower)
Source: A. Frederickson, Layer of Protection Analysis, www.safetyusersgroup.com, May 2006

While it's technically safer, SIL-4 costs a lot more to put in place compared to SIL-3 valves, which are still unquestionably safe. Various methods for identification of hazards include HAZOP, FMEA, What If. The Probability of Failure on Demand (PFD) is a measure of the effectiveness of a safety function. SIL 4: PFDavg < 10-4. SIL Rated equipment, to the appropriate SIL level, are required in SIL rated systems. An SIL analysis is a quantitative target for measuring the level of performance needed for a safety function to achieve a tolerable risk for a process hazard. The Probability of Failure on Demand indicates the likelihood that a system does not perform the required safety function. To perform SIL verification calculations, ISA-TR84.00.02-2015 [6], Equation 8.1 (shown here as Equation 1) is given to calculate the SIF probability of failure on demand. In this case, the SIL value is derived from the PFD value (probability of failure on demand). Operating modes: Low demand and high demand. Door middel van een SIL verificatie wordt gecontroleerd of de gewenste integriteit van een beveiliging (SIL 1 t/m SIL 4) gehaald wordt. De technische integriteit van een SIF is afhankelijk van diverse factoren. Hierbij dient ook de verwachte levensduur / missietijd van de geselecteerde componenten meegenomen te worden in de analyse.

Available means include:
– Markov models
– reliability block diagrams
– fault-tree analysis

Demand (PFDavg) Safety Integrity Level (SIL) Average FREQUENCY of a Dangerous Failure per hour:
1: ≥ 10-2 to < 10-1 / ≥ 10-6 to < 10-5
2: ≥ 10-3 to < 10-2 / ≥ 10-7 to < 10-6
3: ≥ 10-4 to < 10-3 / ≥ 10-8 to < 10-7
4: ≥ 10-5 to < 10-4 / ≥ 10-9 to < 10-8

For low demand mode, the failure measure is based on average Probability of dangerous Failure on Demand (PFDavg). Voting configurations (1 of 2, 2 of 3, 3 of 4) zorgt voor risicovermindering. These variables determine how sophisticated the modelling approach should be. Maar hoe relevant zijn al deze variabelen en hoe precies moet dit gemodelleerd worden? The connections between PFH and PFD are important. The failure rates being representative for new equipment as well as the test intervals must fit the analysis. A low proof test coverage is required for accurate calculations. Some value above zero is given in the standard mentioned above using "standard" reliability data and test intervals. Het uitvoeren van de prooftesten is erg kritisch. Diverse gevaarsidentificatie methodieken (HAZOP, FMEA, What if) kunnen worden toegepast. IEC 61511:2017 and IEC 61508:2010 define the criteria for Safety Instrumented Functions (SIFs). SIL-1 has a PFD < 0.1, while SIL-2 has a PFD < 0.01 – level 1 being the lowest. Een ß factor van 10% is hierbij aanbevolen. In de eenvoudige versie wordt geen rekening gehouden met de prooftestdekking. The probability of failure will increase after each test. Voor het specificeren van de safety integrity levels worden vier discrete niveaus gebruikt (1–4). The demand rate is often less frequent than once per year. A low proof test coverage may compromise the analysis. The higher the SIL level, the lower the probability of the system failing on demand. The environment could be polluted or people could be injured if safety functions fail. Het juist uitvoeren van de prooftesten is kritisch. De verwachte levensduur van de geselecteerde componenten moet meegenomen worden in de analyse. In de geavanceerde versie wordt de prooftestdekking wel meegenomen in de berekening. PFD values are typically .045 and .024 for BPCS and SIL-rated hardware respectively. Poor proof tests are never acceptable although more frequent testing can help.