Module 12 – SIL Verification
Practice Exam
Table of Contents
Introduction
Multiple Choice Questions (MCQs)
Short Answer Questions
Case Study Questions
Introduction
Module 12 focuses on Safety Integrity Level (SIL) verification, which ensures that safety
instrumented functions (SIFs) meet their required risk reduction targets. This exam
covers key concepts, calculations, and best practices in SIL verification. It includes
multiple-choice questions (MCQs), short answer questions, and a case study. Each
question is followed by a detailed explanation to reinforce learning. Use this exam to test
your understanding of SIL verification principles, methodologies, and calculations.
Multiple Choice Questions (MCQs)
1. What is the primary purpose of SIL verification?
A. To determine the risk reduction provided by a SIF
B. To ensure the SIF meets its target probability of failure on demand (PFD)
C. To identify hazards and assess risk
D. To develop the safety requirements specification
Answer: B – The primary purpose of SIL verification is to ensure that a safety
instrumented function (SIF) meets its target SIL by confirming that its probability of
failure on demand (PFD) or probability of dangerous failure per hour (PFH) falls within the
required range for that SIL . This ensures the SIF achieves the necessary risk reduction to
meet the functional safety requirements.
Explanation: SIL verification is a quantitative assessment that checks if the safety
function’s failure rate performance meets the target. It does not determine risk (that’s
hazard analysis, A), nor is it used to develop requirements (that’s hazard analysis and
requirements specification, D). Identifying hazards is part of hazard and risk analysis,
not SIL verification . The goal is strictly to verify the SIF’s performance (PFD/PFH) against
the SIL target.
2. Which of the following best describes a proof test in SIL verification?
A. A test performed by the manufacturer to verify the product’s safety
B. A test of the safety system’s logic to ensure it responds correctly
C. A test that exercises the safety function and checks for failure
D. A test that checks for systematic errors in the system design
Answer: C – A proof test is a test that exercises the safety function and checks for
failure. It involves intentionally initiating the safety function or simulating a failure
condition to verify that the safety system responds as intended and that no dangerous
failure goes undetected . Proof tests are typically scheduled at regular intervals to
ensure the system remains reliable over time.
Explanation: A is incorrect because proof tests are usually performed by the end-user
or system integrator, not the manufacturer. B is incorrect because a logic test (like a
functional test) checks the logic, whereas a proof test is specifically about detecting
failures. D is incorrect because proof tests are primarily about random failures and
testing, not about identifying systematic errors in design (that would be part of design
verification or audits). Proof tests are quantitative tests that evaluate the system’s ability
to respond correctly under failure conditions.
3. Which method is typically used to perform SIL verification for a safety instrumented
system?
A. Fault Tree Analysis (FTA)
B. Layer of Protection Analysis (LOPA)
C. Hazard and Operability Study (HAZOP)
D. Failure Modes and Effects Analysis (FMEA)
Answer: A – Fault Tree Analysis (FTA) is typically used to perform SIL verification for a
safety instrumented system. FTA is a top-down logic diagram technique that models the
failure events leading to a dangerous failure of the SIF, allowing calculation of the
PFDavg . It is a powerful method to systematically evaluate the reliability of the SIF
architecture and component failures.
Explanation: B is incorrect because LOPA is a semi-quantitative risk assessment tool
used to determine the need for an SIF and its required SIL (not to verify the achieved
SIL). C is incorrect because HAZOP is a qualitative hazard analysis technique, not a
verification method. D is incorrect because FMEA (especially FMECA) can be used to
gather failure rate data, but FTA is the standard method for calculating PFD/PFH and
verifying the achieved SIL . SIL verification calculations are often done using FTA, RBD
(Reliability Block Diagram), or Markov models, with FTA being the most common for
complex systems .
4. In SIL verification, what does PFDavg represent?
A. The average Probability of Failure on Demand for a safety function
B. The average Probability of Dangerous Failure per Hour for a safety function
C. The average Safe Failure Fraction for a safety component
D. The average Probability of Safe Failure on Demand for a safety function
Answer: A – PFDavg stands for the average Probability of Failure on Demand for a
safety function. It is a key performance metric for low-demand safety instrumented
functions, representing the probability that the system will fail to perform its safety
function when demanded . PFDavg directly links to the SIL target and guides the
engineering design and validation process .
Explanation: B is incorrect because PFH (Probability of Dangerous Failure per Hour) is
a metric for high-demand or continuous mode SIFs. C is incorrect because SFF (Safe
Failure Fraction) is a different metric (the fraction of failures that are safe or detected) .
D is incorrect because there is no such term as “Probability of Safe Failure on Demand”
– the term is PFDavg for dangerous failures. PFDavg is a critical measure in SIL
verification to ensure the SIF’s performance meets the required SIL level .
5. Which of the following would not typically be part of a SIL verification study?
A. Proof test coverage analysis
B. Common cause failure analysis
C. Hazard and operability study (HAZOP)
D. Markov model analysis for repairable systems
Answer: C – A Hazard and Operability Study (HAZOP) would not typically be part of a
SIL verification study. HAZOP is a hazard analysis technique used to identify potential
hazards and risk, which is done before SIL verification. SIL verification is a quantitative
analysis to ensure the safety function meets its target, whereas HAZOP is qualitative risk
identification .
Explanation: A is incorrect because proof test coverage analysis is important in SIL
verification to determine how effectively periodic tests detect failures. B is incorrect
because common cause failure analysis is often included to account for shared causes of
failure that could affect multiple components in the SIF. D is incorrect because Markov
model analysis is a method used in SIL verification to model the reliability of repairable
safety systems, calculating PFD/PFH over time . These are all part of the SIL verification
process, whereas HAZOP is a separate step in the safety lifecycle.
6. When performing SIL verification for a high-demand safety function, which metric is
typically used?
A. PFDavg (Probability of Failure on Demand)
B. PFH (Probability of Dangerous Failure per Hour)
C. SFF (Safe Failure Fraction)
D. HFT (Hardware Fault Tolerance)
Answer: B – For a high-demand safety function, the metric typically used is PFH
(Probability of Dangerous Failure per Hour). High-demand SIFs are activated frequently
(continuous or near-continuous operation), so PFH (failures per hour) is the appropriate
measure of failure rate . Low-demand SIFs use PFDavg (failures per demand) .
Explanation: A is incorrect because PFDavg is used for low-demand mode. C is
incorrect because SFF is not a failure rate metric but a measure of how many failures are
detected. D is incorrect because HFT (Hardware Fault Tolerance) is a design parameter
(number of redundant channels) rather than a failure rate metric. High-demand SIFs
require PFH calculations to ensure they meet the target SIL for continuous operation .
7. What is the purpose of a Functional Safety Assessment (FSA) in the context of
SIL verification?
A. To assess the systematic capability of a safety system
B. To verify that the SIF meets its required PFD/PFH
C. To audit the safety lifecycle processes and ensure compliance
D. To evaluate the common cause failure factors in the SIF
Answer: C – The purpose of a Functional Safety Assessment (FSA) in the context of SIL
verification is to audit the safety lifecycle processes and ensure compliance. An
FSA is an independent review that checks if appropriate methods, techniques, and
processes were used to achieve functional safety, covering aspects like hazard analysis,
design, verification, and maintenance . It ensures that the system was developed and
maintained in accordance with the safety standards and best practices.
Explanation: A is incorrect because systematic capability is a measure of the
likelihood of systematic errors in a component, which is assessed during component
certification or in safety assessments, but FSA is broader. B is incorrect because
verifying the PFD/PFH is part of SIL verification calculations, not an FSA. D is incorrect
because common cause failure analysis is a specific part of reliability modeling, not the
overall FSA. An FSA reviews all aspects of safety management to ensure the system is
safe, not just one technical aspect like common cause failures .
8. In SIL verification, what does Hardware Fault Tolerance (HFT) represent?
A. The maximum number of dangerous failures a system can have and still meet its SIL
B. The number of redundant channels or units required to achieve a certain SIL
C. The fraction of failures that are detected by automatic diagnostics
D. The probability that a system will fail to perform its safety function on demand
Answer: B – Hardware Fault Tolerance (HFT) represents the number of redundant
channels or units required to achieve a certain SIL. It is a design parameter indicating
how many failures the system can tolerate while still meeting the safety requirements.
For example, an HFT of 1 means the system can have one failure and still function safely
(requiring at least 2 channels in 2oo2 voting), while an HFT of 2 means it can tolerate
two failures (e.g. 3 channels in 2oo3 voting) .
Explanation: A is incorrect because HFT is not about counting failures; it’s about
redundancy. C is incorrect because SFF (Safe Failure Fraction) is the fraction of failures
detected. D is incorrect because PFDavg is the probability of failure on demand. HFT is a
key concept in SIL verification, as per IEC 61508 and 61511, which provide tables linking
HFT and SFF to required SIL levels .
9. Which of the following is not a typical output of SIL verification?
A. A report showing PFDavg or PFH for each SIF
B. A recommendation to increase the SIL if the target is not met
C. A detailed design of the safety system
D. A confirmation that the SIF meets the required SIL
Answer: C – A detailed design of the safety system is not a typical output of SIL
verification. SIL verification is an assessment of the design’s performance (PFD/PFH) to
ensure it meets the SIL target. It produces reports, analyses, and conclusions (e.g.
whether the SIF meets the SIL or not), but it does not typically include the detailed
design documentation itself.
Explanation: A is incorrect because SIL verification typically results in a report that
includes the calculated PFDavg or PFH for each SIF, showing the achieved performance.
B is incorrect because if the target SIL is not met, one possible output is a
recommendation to increase the SIL or to modify the design to meet the target. D is
incorrect because a confirmation that the SIF meets the required SIL is a standard output
of SIL verification – if the PFD/PFH is within the required range for the target SIL, that’s
confirmed in the report. The detailed design of the safety system would have been done
earlier in the lifecycle (during design phase), not as an output of SIL verification.
10. When using a reliability block diagram (RBD) to calculate PFDavg, what is the
first step?
A. Identify all possible failure modes of each component
B. Define the system architecture and failure logic
C. Calculate the failure rates for each component
D. Assign a safety integrity level to the system
Answer: B – When using an RBD to calculate PFDavg, the first step is to define the
system architecture and failure logic. This involves modeling how the system’s
components are connected and how failures in those components lead to a dangerous
failure of the safety function. For example, you would draw the RBD showing sensors,
logic solver, final elements, and how they must fail to cause a hazard.
Explanation: A is incorrect because identifying failure modes is part of FMEDA or FTA
input; for an RBD approach, you typically use the given failure rates of components. C is
incorrect because failure rates are input data; you don’t calculate them first. D is
incorrect because SIL is assigned during hazard analysis, not in the RBD setup. The RBD
method is applied after the SIL is determined, to verify the achieved SIL . The first step in
an RBD-based SIL verification is to set up the diagram representing the safety function’s
architecture.
11. Which of the following is a qualitative method for SIL determination, not typically
used for SIL verification?
A. Layer of Protection Analysis (LOPA)
B. Fault Tree Analysis (FTA)
C. Failure Modes and Effects Analysis (FMEA)
D. Reliability Block Diagram (RBD)
Answer: A – Layer of Protection Analysis (LOPA) is a qualitative method for SIL
determination, not typically used for SIL verification. LOPA is a semi-quantitative risk
assessment that helps decide if a safety instrumented function is needed and what SIL it
should have, but it does not directly calculate the PFD/PFH to verify the achieved SIL . It
uses frequency estimates and protection layers to determine the required SIL, not a
detailed reliability analysis.
Explanation: B is incorrect because FTA is a quantitative method used for SIL
verification (calculating PFDavg). C is incorrect because FMEA (especially FMECA) can be
used to gather failure rate data and is part of SIL verification (it’s used to input data for
calculations). D is incorrect because RBD is a quantitative method used for SIL
verification (to calculate PFDavg). LOPA is a different technique used earlier in the
process to allocate SIL, not to verify it.
12. In SIL verification, what is the purpose of Common Cause Failure (CCF) analysis?
A. To ensure the system is designed with at least two independent channels
B. To account for failures that have a common cause and could affect multiple
components
C. To calculate the probability of failure on demand for the system
D. To verify that the system meets the required Hardware Fault Tolerance (HFT)
Answer: B – The purpose of Common Cause Failure (CCF) analysis in SIL verification is
to account for failures that have a common cause and could affect multiple
components. CCF analysis identifies shared factors (like power supply failures,
environmental factors) that could cause simultaneous failures in redundant components,
which would reduce the system’s reliability more than if failures were independent. By
including CCF factors, the verification calculations more accurately reflect the system’s
real-world reliability.
Explanation: A is incorrect because having two independent channels is a design
practice to mitigate CCF (not the purpose of CCF analysis). C is incorrect because
calculating PFDavg is done via reliability modeling; CCF analysis is an input to that
modeling. D is incorrect because HFT is about redundancy design, while CCF analysis is
about failure dependencies. The goal of CCF analysis is to quantify the impact of shared
failures so that the SIL verification results are conservative and realistic .
13. Which of the following would not be considered when calculating the probability
of failure on demand (PFDavg) for a safety function?
A. The failure rates of each component in the safety function
B. The architecture of the safety system (e.g. 1oo2, 2oo3)
C. The number of sensors and final elements
D. The maintenance schedule and diagnostic coverage
Answer: C – The number of sensors and final elements alone would not be
considered when calculating PFDavg. PFDavg depends on the failure rates of
components, their architecture (voting logic), and maintenance and diagnostic aspects.
The quantity of sensors or final elements doesn’t directly determine PFDavg – rather,
it’s their failure rates and how they are arranged. For example, two sensors in a 2oo2
architecture will have a certain PFD, whereas two sensors in a 1oo2 architecture would
have a different PFD, but the number of sensors isn’t the determining factor; it’s their
failure rates and redundancy.
Explanation: A is incorrect because failure rates of components are a critical input
(each component’s dangerous failure rate contributes to the overall PFD). B is incorrect
because the architecture (like 1oo2 or 2oo3) affects the PFD calculation (it determines
how failures lead to dangerous outcomes). D is incorrect because maintenance (proof
test interval, test coverage) and diagnostic coverage are factored into PFDavg
calculations (for example, if a component is tested periodically, that reduces the PFD).
The number of sensors or final elements is not a direct input to the PFDavg formula;
what matters is their individual failure rates and how they are configured.
14. What is the primary purpose of Failure Mode and Effects Analysis (FMEA) in
the context of SIL verification?
A. To identify potential hazards and their consequences
B. To determine the required Safety Integrity Level (SIL) for each SIF
C. To gather failure rate data for components in the safety system
D. To verify that the safety system meets its functional requirements
Answer: C – The primary purpose of FMEA in the context of SIL verification is to
gather failure rate data for components in the safety system. FMEDA (Failure
Modes, Effects, and Diagnostic Analysis) is a detailed FMEA focused on safety systems,
which provides failure rates for dangerous and safe failures of each component. These
failure rates are then used in reliability calculations (like PFDavg) during SIL verification .
Explanation: A is incorrect because hazard identification is done in hazard analysis
(e.g. HAZOP), not in FMEA for SIL verification. B is incorrect because SIL assignment is
done in hazard analysis (LOPA, etc.), not via FMEA. D is incorrect because verifying
functional requirements is part of testing and validation, not FMEA. FMEA (especially
FMEDA) provides the input data (failure rates, dangerous vs. safe failures) that are
needed for SIL verification calculations .
15. Which of the following is a semi-quantitative method for SIL determination, often
used in the process industry?
A. Fault Tree Analysis (FTA)
B. Layer of Protection Analysis (LOPA)
C. Reliability Block Diagram (RBD)
D. Markov Model
Answer: B – Layer of Protection Analysis (LOPA) is a semi-quantitative method for
SIL determination, often used in the process industry. LOPA uses frequency estimates
and the concept of protection layers to determine the required SIL for a safety function,
making it semi-quantitative (it doesn’t calculate exact PFDs but uses order-of-magnitude
estimates) .
Explanation: A is incorrect because FTA is a fully quantitative method (it can calculate
exact PFD values). C is incorrect because RBD is also a fully quantitative method for
reliability analysis. D is incorrect because Markov models are used for detailed
quantitative reliability calculations (they can model state transitions and calculate
PFD/PFH over time). LOPA is semi-quantitative and is commonly used in process safety to
allocate SIL .
16. In SIL verification, what does Proof Test Coverage (PTC) refer to?
A. The fraction of dangerous failures that are detected by automatic diagnostics
B. The fraction of dangerous failures that are detected by periodic proof tests
C. The probability that a system will fail to perform its safety function on demand
D. The fraction of the time the system is tested
Answer: B – Proof Test Coverage (PTC) refers to the fraction of dangerous failures
that are detected by periodic proof tests. It is a measure of how effective the
scheduled tests are in catching undetected dangerous failures. For example, if a proof
test has 70% coverage, it means 70% of dangerous failures will be caught during the
test, and 30% will remain undetected until the next test.
Explanation: A is incorrect because diagnostic coverage (DC) is the fraction of
dangerous failures detected by automatic diagnostics. C is incorrect because PFDavg is
the probability of failure on demand. D is incorrect because PTC is not about time; it’s
about coverage of failures. PTC is an important parameter in SIL verification calculations
to account for the effectiveness of proof testing .
17. Which of the following is not a common output of a SIL verification study?
A. A recommendation to modify the design if the target SIL is not met
B. A report documenting the achieved PFDavg or PFH for each SIF
C. A copy of the final safety requirements specification (SRS)
D. A confirmation that the safety function meets the required SIL
Answer: C – A copy of the final safety requirements specification (SRS) is not
a common output of a SIL verification study. SIL verification is an assessment of an
existing design to ensure it meets the SIL target; it doesn’t typically produce the SRS
document itself (that’s created earlier in the lifecycle). Instead, it produces a report that
includes findings, calculations, and conclusions regarding the SIL achievement.
Explanation: A is incorrect because if the target SIL is not met, a typical output is a
recommendation to change the design (e.g. add redundancy or better components) to
meet the target. B is incorrect because a report documenting the achieved PFDavg or
PFH for each SIF is a standard output of SIL verification – this shows the quantitative
results. D is incorrect because a confirmation that the safety function meets the
required SIL is an output; if the verification confirms the PFD/PFH is within the required
range for the target SIL, that’s stated in the report. The SRS is part of the design
documentation, not an output of the verification study.
18. What is the purpose of a Functional Safety Audit in the context of SIL
verification?
A. To verify that the safety function meets its required PFD/PFH
B. To ensure that the safety lifecycle processes are being followed correctly
C. To identify potential hazards and assess risk
D. To perform the actual SIL verification calculations
Answer: B – The purpose of a Functional Safety Audit in the context of SIL
verification is to ensure that the safety lifecycle processes are being followed
correctly. A functional safety audit is an independent review that checks compliance
with safety standards and good practices throughout the project. It examines
documentation, processes, and procedures to confirm that the safety function was
designed, implemented, and maintained in accordance with the functional safety
management system and relevant standards .
Explanation: A is incorrect because verifying the PFD/PFH is done in SIL verification
calculations, not by an audit. C is incorrect because hazard identification is done in
hazard analysis, not by an audit. D is incorrect because performing SIL verification
calculations is the work of the safety engineer, not an audit. The audit ensures that the
verification was done correctly and that all required processes were applied, rather than
performing the calculations themselves .
19. When using a Markov model for SIL verification, what does the model represent?
A. The sequence of events leading to a dangerous failure
B. The failure rates of each component in the safety system
C. The state transitions of the safety system over time
D. The probability of success of the safety function on demand
Answer: C – When using a Markov model for SIL verification, the model represents the
state transitions of the safety system over time. A Markov model is a
mathematical model that describes the system in various states (e.g. normal operation,
single-point failure, multiple-point failure, failed state) and how the system transitions
between these states. By solving the model, one can calculate metrics like PFD or PFH
over time, taking into account repairs and common cause failures .
Explanation: A is incorrect because the sequence of events leading to a dangerous
failure is modeled in a fault tree or event tree, not in a Markov model. B is incorrect
because failure rates are inputs to the Markov model; the model itself doesn’t
“represent” the failure rates. D is incorrect because the probability of success on
demand is the complement of PFD; a Markov model calculates PFD (failure probability)
and from that, success probability (1 – PFD). The model is about state transitions over
time, not directly about success probability.
20. Which of the following cannot be used as a metric for a high-demand safety
function?
A. PFDavg (Probability of Failure on Demand)
B. PFH (Probability of Dangerous Failure per Hour)
C. MTTF (Mean Time To Failure)
D. Both A and C
Answer: A – PFDavg cannot be used as a metric for a high-demand safety function.
PFDavg is specifically for low-demand mode SIFs (where the system is not frequently
called upon) . For high-demand SIFs (continuous or near-continuous operation), the
appropriate metric is PFH (failures per hour) . MTTF (Mean Time To Failure) is also
relevant for high-demand systems as it relates to failure rates over time. Thus, PFDavg is
not applicable for high-demand functions.
Explanation: B is incorrect because PFH is used for high-demand. C is incorrect
because MTTF is used in calculating failure rates (for example, PFH = 1 / MTTF for
continuous operation). D is incorrect because only PFDavg is not applicable for high-
demand, while PFH and MTTF are. PFDavg is designed for low-demand scenarios
(occasional demand), whereas PFH is designed for continuous operation .
21. In SIL verification, what is the role of diagnostic coverage (DC)?
A. To determine the number of redundant channels needed
B. To calculate the probability of failure on demand
C. To measure the fraction of dangerous failures detected by automatic diagnostics
D. To ensure the system meets the required Hardware Fault Tolerance
Answer: C – Diagnostic coverage (DC) in SIL verification measures the fraction of
dangerous failures detected by automatic diagnostics. It is an important
parameter that, when combined with failure rates and redundancy, affects the calculated
PFD/PFH. For example, if a component has 90% diagnostic coverage, 90% of its
dangerous failures will be caught by internal tests, and only 10% will remain undetected
until the next proof test.
Explanation: A is incorrect because hardware fault tolerance (HFT) determines the
number of redundant channels needed. B is incorrect because diagnostic coverage is
one input to calculating PFD/PFH, but it doesn’t directly calculate PFD. D is incorrect
because HFT ensures the system meets the required safety margin, whereas DC is about
diagnostics. Diagnostic coverage is a critical factor in SIL verification to account for
failures that are detected automatically (as opposed to those caught by periodic proof
tests) .
22. Which of the following is not a valid approach for SIL verification?
A. Using a commercially available SIL verification software tool
B. Manually calculating PFDavg using formulas from the standards
C. Performing a thorough review of the system’s design documentation
D. Using a failure modes and effects analysis (FMEA) to estimate failure rates
Answer: C – Performing a thorough review of the system’s design
documentation is not a valid approach for SIL verification. SIL verification is a
quantitative assessment that requires reliability calculations (PFD/PFH) or equivalent, not
just document review. A document review might catch design issues but does not
quantify the system’s performance.
Explanation: A is incorrect because using SIL verification software is a valid approach –
many tools exist to automate the calculations of PFD/PFH based on input data. B is
incorrect because manually calculating PFDavg using the formulas in IEC 61508/61511 is
a valid approach for small systems or to understand the method. D is incorrect because
using FMEA to gather failure rate data is a standard and valid step in SIL verification
(FMEDA provides input for calculations). A document review might be part of a safety
assessment or audit, but it is not an acceptable method for verifying that the SIF meets
its SIL target .
23. What is the relationship between SIL and PFDavg (Probability of Failure on
Demand)?
A. Higher SIL corresponds to lower PFDavg
B. Higher SIL corresponds to higher PFDavg
C. SIL is independent of PFDavg
D. PFDavg is the reciprocal of SIL
Answer: A – There is an inverse relationship: higher SIL corresponds to lower
PFDavg. A higher SIL (e.g. SIL 3 vs. SIL 1) requires a lower probability of failure on
demand to meet the safety integrity level. In other words, a SIL 3 system must have a
PFDavg in the 10⁻⁴ to 10⁻³ range, whereas a SIL 1 system can have a PFDavg up to 10⁻¹.
This relationship is defined by the IEC standards .
Explanation: B is incorrect because higher SIL means lower PFDavg (more reliable). C
is incorrect because SIL is directly determined by PFDavg; it’s a measure of risk
reduction, which is quantified by PFDavg. D is incorrect because PFDavg is not the
reciprocal of SIL; they are related by the required risk reduction factors, but not directly
reciprocal. The relationship is shown in the table below, which clearly links each SIL to a
range of PFDavg values. Data Source:
24. Which of the following is not typically included in a SIL verification report?
A. A summary of the SIL verification methodology used
B. The calculated PFDavg or PFH for each SIF
C. The list of hazard analysis results for the project
D. A comparison of the achieved performance against the target SIL
Answer: C – The list of hazard analysis results for the project is not typically
included in a SIL verification report. Hazard analysis results (like identified hazards and
their risk assessments) are part of the safety requirements specification or hazard
analysis documentation, not the SIL verification report. The SIL verification report
focuses on the quantitative verification of the SIF’s performance.
Explanation: A is incorrect because a summary of the methodology (FTA, RBD, etc.)
used is usually included in the report. B is incorrect because the calculated PFDavg or
PFH for each SIF is a key output. D is incorrect because comparing achieved
performance to the target SIL (e.g. “achieved PFDavg = 5×10⁻⁴, target SIL 3 (≤10⁻³) –
meets requirement”) is typically done. The SIL verification report’s purpose is to
document that the SIF meets the required SIL; it doesn’t repeat the hazard analysis
results that were done earlier.
25. What is the primary purpose of Functional Safety Management (FSM) in the
context of SIL verification?
A. To ensure that the safety function meets its required PFD/PFH
B. To manage the safety lifecycle processes and ensure compliance
C. To calculate the probability of failure on demand for the safety function
D. To identify potential hazards and assess risk
Answer: B – The primary purpose of Functional Safety Management (FSM) in the
context of SIL verification is to manage the safety lifecycle processes and ensure
compliance. FSM covers all aspects of safety planning, process, certification,
competency, and testing . It ensures that the team follows the correct procedures
(hazard analysis, design, verification, maintenance) and that the necessary
documentation and audits are performed to achieve functional safety. In the context of
SIL verification, FSM is about ensuring the verification process itself is conducted
properly and that all relevant processes (like hazard analysis, component selection, etc.)
were executed correctly.
Explanation: A is incorrect because ensuring the SIF meets its PFD/PFH is the goal of
SIL verification, not FSM. C is incorrect because calculating PFD/PFH is the task of the
safety engineer, not FSM. D is incorrect because hazard identification is done in hazard
analysis, not FSM. FSM is a higher-level management of safety activities – it includes
defining responsibilities, planning the safety work, providing training, performing audits,
etc., so that the verification and other safety tasks are done correctly .
26. Which of the following is a quantitative method for SIL determination?
A. Layer of Protection Analysis (LOPA)
B. Failure Modes and Effects Analysis (FMEA)
C. Risk Graph
D. Both A and C
Answer: B – Failure Modes and Effects Analysis (FMEA) is a quantitative method
for SIL determination (when used in FMEDA form). While basic FMEA is qualitative,
FMEDA (Failure Modes, Effects, and Diagnostic Analysis) involves assigning failure rates
to modes and can be used to calculate failure probabilities for a safety function, making
it quantitative. The other options are semi-quantitative or qualitative: A (LOPA) is semi-
quantitative, C (Risk Graph) is qualitative.
Explanation: A is incorrect because LOPA is semi-quantitative (uses frequency
estimates). B is correct because FMEDA can produce quantitative data (failure rates,
PFDs) for SIL verification. C is incorrect because a risk graph is qualitative (it’s a visual
representation of risk without exact probabilities). Thus, only FMEA (with FMEDA) is fully
quantitative among these methods for SIL determination.
27. What is the relationship between SIL and Hardware Fault Tolerance (HFT)?
A. Higher SIL requires higher HFT (more redundancy)
B. Higher SIL requires lower HFT (less redundancy)
C. HFT is independent of SIL
D. HFT is the reciprocal of SIL
Answer: A – There is a direct relationship: higher SIL requires higher HFT (more
redundancy). IEC 61508 and 61511 define that certain levels of redundancy are
required for each SIL. For example, in low-demand mode, SIL 1 and 2 can be achieved
with HFT = 0 (no redundancy) under certain conditions, but SIL 3 and 4 require HFT ≥ 1
(at least one level of redundancy) . Thus, to reach a higher SIL, the system must have
more redundancy (higher HFT).
Explanation: B is incorrect because higher SIL means more redundancy, not less. C is
incorrect because HFT is a design parameter that directly affects SIL (you can’t get SIL 3
without at least some redundancy). D is incorrect because HFT and SIL are not
reciprocals; they are related by the required safety margin. The table below from IEC
61511 clearly shows the required HFT for each SIL in low-demand mode. Data Source:
28. Which of the following is not a common step in the SIL verification process?
A. Defining the safety function and its requirements
B. Performing a hazard and operability study (HAZOP)
C. Calculating PFDavg or PFH for the safety function
D. Verifying that the calculated PFD/PFH meets the target SIL
Answer: B – Performing a hazard and operability study (HAZOP) is not a step
in the SIL verification process. HAZOP is a hazard analysis done before SIL verification to
identify hazards and allocate SIL to SIFs. SIL verification is the step after that, where you
quantitatively check if the SIF meets its SIL target.
Explanation: A is incorrect because defining the safety function and its requirements
is part of the design process and may be reviewed during verification. C is incorrect
because calculating PFDavg/PFH is a core step of SIL verification. D is incorrect because
verifying that the PFD/PFH meets the target is the ultimate goal of SIL verification.
HAZOP is a separate activity in the safety lifecycle, not part of verifying the achieved SIL.
29. What is the purpose of proof test interval in SIL verification?
A. To determine the frequency of proof tests needed to maintain the required SIL
B. To calculate the probability of failure on demand
C. To measure the fraction of dangerous failures detected by automatic diagnostics
D. To ensure the system meets the required Hardware Fault Tolerance
Answer: A – The purpose of the proof test interval in SIL verification is to
determine the frequency of proof tests needed to maintain the required SIL.
The proof test interval (e.g. once a year) is chosen such that the probability of an
undetected dangerous failure over the interval remains within the acceptable range for
the SIL. By setting a test interval, you ensure that periodic tests catch failures before
they accumulate to a level that would violate the SIL target.
Explanation: B is incorrect because the proof test interval is an input to calculating
PFDavg; it doesn’t calculate PFDavg itself. C is incorrect because diagnostic coverage is
about automatic diagnostics, not proof tests. D is incorrect because hardware fault
tolerance is about redundancy, not test interval. The proof test interval is critical in SIL
verification to balance the cost of testing against the risk of undetected failures.
30. Which of the following is not a component typically included in a safety
instrumented function (SIF)?
A. Logic solver
B. Final control element
C. Pressure sensor
D. Emergency stop button
Answer: D – An emergency stop button is not typically included in a safety
instrumented function (SIF). SIFs are electronic/PLC-based systems for automatic
shutdown. An emergency stop button is a manual safety device (mechanical) and not
part of an SIF. The components of an SIF include a logic solver (PLC or dedicated safety
controller), final control elements (valves, etc.), and sensors (transmitters, switches) .
Explanation: A is incorrect because a logic solver is a core component of an SIF. B is
incorrect because final control elements (valves, etc.) are part of the SIF. C is incorrect
because pressure sensors (transmitters) are part of the SIF (they are sensors that detect
the hazardous condition). Emergency stop buttons are separate safety devices and not
part of the automated SIF logic.
31. What is the role of Common Cause Failure (CCF) in SIL verification calculations?
A. It increases the calculated PFDavg, making the system more reliable
B. It decreases the calculated PFDavg, making the system less reliable
C. It increases the calculated PFDavg, making the system less reliable
D. It has no effect on the calculated PFDavg
Answer: C – Common Cause Failure (CCF) increases the calculated PFDavg, making
the system less reliable. CCF occurs when multiple components fail due to a single
common cause (e.g. a power supply failure). Without accounting for CCF, the reliability is
overestimated because the model assumes failures are independent. By including CCF,
the model calculates a higher probability of failure (higher PFDavg), reflecting the real-
world scenario where simultaneous failures are more likely. Thus, CCF analysis is
important to ensure the SIL verification results are conservative and that the system is
safe.
Explanation: A is incorrect because CCF makes the system less reliable (higher
PFDavg), not more. B is incorrect because CCF makes the system less reliable (higher
PFDavg), not more. D is incorrect because CCF does have an effect – it reduces
reliability. Including CCF factors in the calculations is standard practice to avoid
overestimating the system’s performance and to ensure the SIL target is not exceeded .
32. Which of the following is not a valid method for calculating PFDavg for a safety
function?
A. Using a simplified reliability block diagram (RBD) formula
B. Conducting a detailed fault tree analysis (FTA)
C. Using a Monte Carlo simulation
D. Performing a failure modes and effects analysis (FMEA)
Answer: D – Performing a failure modes and effects analysis (FMEA) is not a
valid method for calculating PFDavg. FMEA can provide failure rate data, but to calculate
PFDavg, you need to use reliability models (RBD, FTA, Markov, etc.) that combine these
failure rates with the system architecture and diagnostics. FMEA alone doesn’t directly
compute PFDavg; it’s a precursor to such calculations.
Explanation: A is incorrect because using simplified RBD formulas is a valid method to
approximate PFDavg. B is incorrect because conducting a detailed FTA is a valid method
to calculate PFDavg. C is incorrect because using Monte Carlo simulation to model the
system and calculate PFDavg is a valid approach (especially for complex systems). Thus,
only FMEA (without additional modeling) is not a method to calculate PFDavg.
33. What is the purpose of a Functional Safety Assessment (FSA) during the
operation phase of a safety system?
A. To verify that the system meets its required PFD/PFH
B. To ensure that the safety system is maintained correctly and its performance is
validated
C. To identify new hazards introduced by changes
D. To perform the initial hazard analysis for the system
Answer: B – The purpose of a Functional Safety Assessment (FSA) during the
operation phase is to ensure that the safety system is maintained correctly and
its performance is validated. An FSA in operation checks that maintenance
procedures are followed, that proof tests are conducted as scheduled, that any changes
are properly analyzed, and that the system’s performance (e.g. proof test results, failure
rates) is within the expected range. It also verifies that the safety integrity level is
maintained over time through proper maintenance.
Explanation: A is incorrect because verifying PFD/PFH is done during design
verification; during operation, the focus is on maintaining performance. C is incorrect
because identifying new hazards is part of hazard analysis during a management of
change (MOC) process, not an FSA. D is incorrect because initial hazard analysis is done
at the start, not during operation. The FSA in operation ensures that the system remains
safe in practice, addressing issues like maintenance, testing, and changes to maintain
the safety integrity.
34. Which of the following is not a typical input for SIL verification calculations?
A. Failure rates of components
B. The system’s architecture (voting logic)
C. Maintenance and diagnostic data
D. The list of hazards identified in the project
Answer: D – The list of hazards identified in the project is not a typical input for
SIL verification calculations. SIL verification is a quantitative assessment of a specific
safety function; it doesn’t need the full list of hazards. Instead, it needs the failure
rates of components, the architecture of the safety system, and
maintenance/diagnostic data to compute PFD/PFH. The hazards list would have been
used to assign the SIL target, but the verification calculations themselves use the
technical details of the system.
Explanation: A is incorrect because failure rates are a key input (each component’s
dangerous failure rate is needed). B is incorrect because the system architecture (1oo2,
2oo3, etc.) is an input to calculate how failures lead to dangerous outcomes. C is
incorrect because maintenance (proof test interval, test coverage) and diagnostic data
are inputs to account for how failures are detected. The hazards list is relevant earlier in
the process, but not for the actual verification calculations .
35. What is the role of Hardware Fault Tolerance (HFT) in the SIL verification
process?
A. It is used to determine the probability of failure on demand
B. It is used to calculate the safe failure fraction of a component
C. It ensures that the system can tolerate certain failures without violating the SIL
D. It is used to verify that the system meets the required diagnostic coverage
Answer: C – Hardware Fault Tolerance (HFT) ensures that the system can tolerate
certain failures without violating the SIL. HFT is a design parameter that defines the
number of failures the system can have and still meet the safety requirements. For
example, an HFT of 1 means the system can have one failure and still function safely
(requiring at least 2 channels in 2oo2 voting). By ensuring HFT meets the required level
for the SIL, we ensure that the system’s architecture provides the necessary safety
margin.
Explanation: A is incorrect because HFT is not directly used to calculate PFDavg; it’s
an input for determining the required PFD/PFH. B is incorrect because SFF (Safe Failure
Fraction) is used to calculate HFT, not vice versa. D is incorrect because diagnostic
coverage is about detecting failures, not HFT. HFT is part of the architecture and
redundancy design, ensuring the system can handle failures (like single-point failures)
without causing a dangerous failure of the safety function .
36. Which of the following is not a valid metric for a safety instrumented function
(SIF)?
A. PFDavg (Probability of Failure on Demand)
B. PFH (Probability of Dangerous Failure per Hour)
C. SFF (Safe Failure Fraction)
D. HFT (Hardware Fault Tolerance)
Answer: D – Hardware Fault Tolerance (HFT) is not a metric for an SIF; it is a
design parameter. HFT is the number of redundant channels needed to achieve a certain
SIL, not a performance metric of the SIF itself. The other options are all metrics: PFDavg
and PFH are failure probability metrics, and SFF is a measure of failure detection
capability.
Explanation: A is incorrect because PFDavg is a key metric for low-demand SIFs. B is
incorrect because PFH is a metric for high-demand SIFs. C is incorrect because SFF is a
metric (the fraction of failures detected) . HFT is a design requirement (e.g. “we need
HFT=1 for SIL 3”), not a performance metric of the SIF.
37. What is the purpose of Systematic Capability (SC) in the context of SIL
verification?
A. To ensure the system meets the required Hardware Fault Tolerance (HFT)
B. To measure the fraction of dangerous failures detected by automatic diagnostics
C. To verify that the system is free of systematic errors
D. To calculate the probability of failure on demand for the system
Answer: C – The purpose of Systematic Capability (SC) in SIL verification is to
verify that the system is free of systematic errors. Systematic Capability is a
measure of how confident we are that the system’s design, implementation, and
maintenance processes have been effective in preventing systematic failures (errors
caused by human factors, design mistakes, etc.). A higher SC means the system is more
robust against systematic faults.
Explanation: A is incorrect because HFT is about redundancy, not systematic
capability. B is incorrect because diagnostic coverage is about detecting failures, not
preventing systematic errors. D is incorrect because SC is not used to calculate
PFD/PFH; it’s an assessment of design quality. Systematic Capability is part of the overall
safety assessment (e.g. in IEC 61508 certification, SC is evaluated for components) to
ensure that systematic errors are minimized .
38. Which of the following is not a typical output of a Functional Safety
Assessment (FSA)?
A. A list of compliance findings and recommendations
B. A confirmation that the system meets the required SIL
C. A review of the safety lifecycle processes
D. An audit report with findings
Answer: B – A confirmation that the system meets the required SIL is not a
typical output of an FSA. An FSA is an audit or assessment of processes and
documentation; it does not typically calculate the SIL or provide a confirmation that the
SIF meets its target. It might recommend improvements or verify that processes were
followed, but it’s not an independent verification of the achieved SIL (that’s done in SIL
verification).
Explanation: A is incorrect because FSAs often produce a list of findings and
recommendations to address any compliance gaps. C is incorrect because reviewing
safety lifecycle processes is a primary output of an FSA. D is incorrect because an FSA
typically results in an audit report with findings. The FSA focuses on ensuring that the
safety function was developed and maintained in accordance with standards; it doesn’t
directly verify the achieved SIL performance.
39. What is the primary purpose of Layer of Protection Analysis (LOPA) in the
safety lifecycle?
A. To calculate the probability of failure on demand for a safety function
B. To determine the required Safety Integrity Level (SIL) for a safety function
C. To verify that the safety function meets its required SIL
D. To identify potential hazards and assess risk
Answer: B – The primary purpose of Layer of Protection Analysis (LOPA) in the
safety lifecycle is to determine the required Safety Integrity Level (SIL) for a
safety function. LOPA is a semi-quantitative risk assessment that uses frequency
estimates and protection layers to decide if a safety instrumented function is needed
and what SIL it should have . It helps allocate the SIL target based on risk assessment.
Explanation: A is incorrect because LOPA does not calculate PFDavg; it’s used to
assign the target SIL. C is incorrect because verifying the achieved SIL is done in SIL
verification, not LOPA. D is incorrect because hazard identification is done in hazard
analysis (like HAZOP); LOPA is done after hazards are identified to determine what
safeguards are needed. LOPA is a step in SIL allocation, not verification .
40. Which of the following is not a valid approach for Systematic Capability (SC)
assessment?
A. Reviewing the system’s design documentation for errors
B. Conducting a design review by an independent team
C. Using failure rate data from the manufacturer’s certificate
D. Performing a functional safety assessment (FSA) of the design
Answer: C – Using failure rate data from the manufacturer’s certificate is not
a valid approach for assessing Systematic Capability (SC). SC is about the quality of the
design and processes, not about the failure rates of components. Failure rate data (from
FMEDA or certificates) is used for reliability calculations, not for SC assessment.
Explanation: A is incorrect because reviewing design documentation for errors is a
way to assess SC (it checks for systematic errors in design). B is incorrect because an
independent design review can catch systematic issues (it’s a method to assess SC). D
is incorrect because a functional safety assessment (FSA) often includes an evaluation of
the systematic capability of the design (it checks if appropriate methods were used to
avoid systematic faults) . Thus, using component failure rate data is not a method for SC
assessment.
41. What is the relationship between SIL and Probability of Dangerous Failure per
Hour (PFH)?
A. Higher SIL corresponds to lower PFH
B. Higher SIL corresponds to higher PFH
C. SIL is independent of PFH
D. PFH is the reciprocal of SIL
Answer: A – Similar to PFDavg, there is an inverse relationship: higher SIL
corresponds to lower PFH. A higher SIL (e.g. SIL 3 vs. SIL 1) requires a lower PFH
(fewer dangerous failures per hour) to meet the safety integrity level. In continuous
operation, PFH values for SIL levels are defined in IEC 61508/61511, analogous to how
PFDavg is defined for low-demand.
Explanation: B is incorrect because higher SIL means lower PFH (more reliable). C is
incorrect because SIL is directly determined by PFH; it’s a measure of risk reduction,
which is quantified by PFH. D is incorrect because PFH is not the reciprocal of SIL; they
are related by the required risk reduction factors, but not directly reciprocal. The
relationship is defined by the IEC standards, linking each SIL to a range of PFH values.
42. Which of the following is not a common step in the SIL verification process for a
new safety system?
A. Designing the safety system
B. Performing a hazard and operability study (HAZOP)
C. Calculating PFDavg or PFH for each SIF
D. Verifying that the calculated PFD/PFH meets the target SIL
Answer: B – Performing a hazard and operability study (HAZOP) is not a step
in the SIL verification process for a new safety system. HAZOP is a hazard analysis done
before SIL verification to identify hazards and allocate SIL to SIFs. SIL verification is the
step after that, where you quantitatively check if the SIF meets its SIL target.
Explanation: A is incorrect because designing the safety system is part of the lifecycle
and is needed before verification. C is incorrect because calculating PFDavg/PFH is a
core step of SIL verification. D is incorrect because verifying that the PFD/PFH meets the
target is the ultimate goal of SIL verification. HAZOP is a separate activity in the safety
lifecycle, not part of verifying the achieved SIL.
43. What is the purpose of proof test coverage in SIL verification calculations?
A. To ensure the system meets the required Hardware Fault Tolerance (HFT)
B. To calculate the probability of failure on demand
C. To measure the fraction of dangerous failures detected by automatic diagnostics
D. To determine the frequency of proof tests needed to maintain the required SIL
Answer: D – The purpose of proof test coverage in SIL verification calculations is to
determine the frequency of proof tests needed to maintain the required SIL.
Proof test coverage (PTC) is the fraction of dangerous failures that a proof test can
detect. By setting the PTC and the SIL target, we can calculate the required proof test
interval to ensure that the probability of an undetected dangerous failure over the
interval is within the acceptable range for the SIL.
Explanation: A is incorrect because HFT is about redundancy, not proof test coverage.
B is incorrect because proof test coverage is an input to calculating PFDavg; it doesn’t
calculate PFDavg itself. C is incorrect because diagnostic coverage is about automatic
diagnostics, not proof tests. Proof test coverage is critical in SIL verification to balance
the cost of testing against the risk of undetected failures.
Short Answer Questions
1. Question: Explain the difference between SIL determination and SIL verification.
Answer: SIL determination is the process of assigning a target SIL to a safety function
based on a risk assessment of the hazards it protects against. Methods like LOPA or risk
graphs are used to determine the required level of risk reduction. SIL verification, on the
other hand, is the quantitative analysis performed after the safety system is designed to
confirm that the design meets the assigned SIL target. It involves calculating the PFDavg
or PFH of the SIF and comparing it to the required range for the target SIL .
2. Question: What are the three main requirements that a Safety Instrumented
Function (SIF) must meet to achieve its target SIL?
Answer: To achieve its target SIL, a SIF must meet three requirements:
1. Probability of Failure: The calculated PFDavg (for low-demand mode) or PFH (for
high/continuous demand mode) must be within the range specified for the target SIL.
2. Architectural Constraints: The system's architecture must meet the minimum
Hardware Fault Tolerance (HFT) requirements for the target SIL, as defined in standards
like IEC 61511.
3. Systematic Capability (SC): All components in the SIF must have a systematic
capability rating equal to or greater than the target SIL to ensure they are sufficiently
robust against systematic design and manufacturing faults .
3. Question: Describe the concept of Safe Failure Fraction (SFF) and its role in
determining architectural constraints.
Answer: Safe Failure Fraction (SFF) is the ratio of the rate of safe failures plus
dangerous detected failures to the total failure rate of a device. It measures how "safe" a
component's failure modes are, either by failing to a safe state or by being detected by
diagnostics. SFF is used in the "Route 1H" approach of IEC 61508 to determine the
required Hardware Fault Tolerance (HFT). Tables in the standard link SFF and HFT to the
maximum SIL that can be claimed for a subsystem. A higher SFF means a device is more
likely to fail safely, which may allow for a lower HFT (less redundancy) to achieve a given
SIL .
4. Question: Why is it important to consider common cause failures (CCF) in SIL
verification, especially for redundant systems?
Answer: Common cause failures are critical in SIL verification because they can defeat
the benefits of redundancy. Redundant systems are designed to tolerate random,
independent failures of individual components. However, a single external event (e.g.,
power surge, extreme temperature, maintenance error) could cause multiple redundant
components to fail simultaneously. If CCF is ignored, the calculated reliability (and
PFDavg) of the system will be overly optimistic. Including a beta-factor (β) in calculations
accounts for the probability of dependent failures, providing a more realistic and
conservative assessment of the SIF's performance .
5. Question: What is a Safety Requirements Specification (SRS), and what key
information does it provide for SIL verification?
Answer: A Safety Requirements Specification (SRS) is a document that details all the
requirements for a safety instrumented system. For SIL verification, the SRS provides
critical information, including: the functional description of each SIF, the target SIL for
each SIF, the required response time, operational modes, proof test intervals, and any
specific environmental or operational constraints. The SIL verification process uses this
information to confirm that the designed system meets all specified safety and
performance targets .
Case Study Questions
Case Study: A chemical reactor is protected by a SIL 2 Safety Instrumented Function
(SIF) designed to prevent over-pressurization. The SIF consists of a single pressure
transmitter (sensor), a safety PLC (logic solver), and a single solenoid valve/actuator
assembly (final element). The system operates in low-demand mode.
Data:
Pressure Transmitter (PT): Dangerous Undetected (DU) failure rate (λ_DU) = 150 FITs
Safety PLC (LS): λ_DU = 50 FITs
Solenoid Valve (FV): λ_DU = 400 FITs
Proof Test Interval (TI) = 1 year (8760 hours)
Assume 100% Proof Test Coverage (PTC) and no significant diagnostic coverage (DC).
Note: 1 FIT = 1 failure per 10⁹ hours.
1. Question: Calculate the total PFDavg for the entire SIF.
Answer:
First, calculate the PFDavg for each component using the simplified formula for a 1oo1
architecture: PFDavg ≈ (λ_DU * TI) / 2.
- Transmitter PFDavg: (150 * 10⁻⁹ failures/hr * 8760 hr) / 2 = 6.57 * 10⁻⁴
- PLC PFDavg: (50 * 10⁻⁹ failures/hr * 8760 hr) / 2 = 2.19 * 10⁻⁴
- Valve PFDavg: (400 * 10⁻⁹ failures/hr * 8760 hr) / 2 = 1.75 * 10⁻³
Next, sum the individual PFDavg values to get the total for the SIF:
Total PFDavg = PFDavg(PT) + PFDavg(LS) + PFDavg(FV)
Total PFDavg = (6.57 * 10⁻⁴) + (2.19 * 10⁻⁴) + (1.75 * 10⁻³) = 0.000657 + 0.000219 +
0.001752 = 2.628 * 10⁻³
2. Question: Does the calculated PFDavg meet the requirements for a SIL 2 system?
Explain your answer.
Answer: No, the calculated PFDavg does not meet the requirements for a SIL 2 system.
The SIL 2 range for PFDavg is ≥ 10⁻³ to < 10⁻². The calculated PFDavg of 2.628 * 10⁻³
falls within this range.
Explanation:
- SIL 1: ≥ 10⁻² to < 10⁻¹
- SIL 2: ≥ 10⁻³ to < 10⁻²
- SIL 3: ≥ 10⁻⁴ to < 10⁻³
Since 2.628 * 10⁻³ (or 0.002628) is greater than or equal to 10⁻³ (0.001) and less than
10⁻² (0.01), the SIF design meets the PFDavg requirement for SIL 2 .
3. Question: The final element (solenoid valve) has the highest PFDavg. Suggest two
ways to improve the SIF's overall PFDavg to potentially achieve a higher SIL.
Answer:
1. Add Redundancy: The most effective way to improve the PFDavg is to add
redundancy to the final element, which is the weakest link. For example, changing the
final element architecture from 1oo1 to 1oo2 (two valves in series) would significantly
reduce its PFDavg and, therefore, the total SIF PFDavg.
2. Reduce the Proof Test Interval: Shortening the proof test interval (e.g., from 1
year to 6 months) for the solenoid valve would reduce its PFDavg. Since PFDavg is
directly proportional to the test interval, halving the interval would roughly halve the
PFDavg for that component.
Section 2: Comprehensive Calculation
Examples and Detailed Walkthroughs
This section provides detailed, step-by-step examples of key calculations used in SIL
verification. These examples are designed to build on the concepts covered in the
practice exam and provide a practical understanding of how to apply formulas from
standards like IEC 61508.
Example 1: PFDavg Calculation for a 1oo1 Architecture
Scenario: A simple Safety Instrumented Function (SIF) consists of a single sensor, a
logic solver, and a final element (1-out-of-1 or 1oo1 architecture). We need to calculate
its total PFDavg and determine if it meets a SIL 1 target.
Given Data:
Sensor (λ_DU): 200 FITs (200 x 10⁻⁹ failures/hour)
Logic Solver (λ_DU): 100 FITs (100 x 10⁻⁹ failures/hour)
Final Element (λ_DU): 500 FITs (500 x 10⁻⁹ failures/hour)
Proof Test Interval (TI): 1 year (8760 hours)
Proof Test Coverage (PTC): Assumed to be 100% for simplicity.
Step 1: Understand the Formula
For a simple 1oo1 architecture with no diagnostics, the average Probability of Failure on
Demand (PFDavg) is calculated using the simplified formula from IEC 61508-6 :
PFDavg ≈ (λ_DU * TI) / 2
Step 2: Calculate PFDavg for Each Component
Sensor PFDavg: (200 x 10⁻⁹ failures/hr * 8760 hr) / 2 = 8.76 x 10⁻⁴
Logic Solver PFDavg: (100 x 10⁻⁹ failures/hr * 8760 hr) / 2 = 4.38 x 10⁻⁴
Final Element PFDavg: (500 x 10⁻⁹ failures/hr * 8760 hr) / 2 = 2.19 x 10⁻³
Step 3: Calculate Total SIF PFDavg
The total PFDavg for the SIF is the sum of the PFDavg of its components.
Total PFDavg = PFDavg_Sensor + PFDavg_LS + PFDavg_FE
Total PFDavg = (8.76 x 10⁻⁴) + (4.38 x 10⁻⁴) + (2.19 x 10⁻³) = 0.000876 + 0.000438 +
0.00219 = 3.504 x 10⁻³
Step 4: Verify Against SIL Target
The target is SIL 1. The PFDavg range for SIL 1 is ≥ 10⁻² to < 10⁻¹.
Our calculated PFDavg is 3.504 x 10⁻³, which is less than 10⁻² (0.01). In fact, it falls
within the SIL 2 range (≥ 10⁻³ to < 10⁻²).
Conclusion: The SIF meets and exceeds the SIL 1 requirement. It achieves SIL 2.
Example 2: PFDavg Calculation for a 1oo2 Architecture
Scenario: To improve reliability, the sensor subsystem from Example 1 is upgraded to a
1-out-of-2 (1oo2) architecture. Let's recalculate the PFDavg for this redundant sensor
subsystem.
Given Data:
Sensor (λ_DU): 200 FITs for each of the two sensors.
Proof Test Interval (TI): 1 year (8760 hours).
Common Cause Failure (β): 5% (a typical value for similar sensors). This means
5% of failures are assumed to be common cause.
Step 1: Understand the Formula
For a 1oo2 architecture, the PFDavg formula is more complex as it must account for both
independent and common cause failures :
PFDavg ≈ ( (1 - β)² * (λ_DU * TI)² ) / 3 + (β * λ_DU * TI) / 2
Step 2: Calculate PFDavg for the 1oo2 Sensor Subsystem
Independent Failure Term: ( (1 - 0.05)² * (200 x 10⁻⁹ * 8760)² ) / 3
= (0.95² * (1.752 x 10⁻³)² ) / 3
= (0.9025 * 3.069 x 10⁻⁶) / 3 = 9.23 x 10⁻⁷
Common Cause Failure Term: (0.05 * 200 x 10⁻⁹ * 8760) / 2
= (0.05 * 1.752 x 10⁻³) / 2 = 4.38 x 10⁻⁵
Total Sensor PFDavg: (9.23 x 10⁻⁷) + (4.38 x 10⁻⁵) = 4.47 x 10⁻⁵
Step 3: Compare with 1oo1 Result
The PFDavg of the 1oo1 sensor was 8.76 x 10⁻⁴. The new PFDavg for the 1oo2 sensor
subsystem is 4.47 x 10⁻⁵. This is a significant improvement in reliability (a reduction of
over 90%).
Example 3: PFDavg Calculation for a 2oo3 Architecture
Scenario: A high-integrity SIF requires a 2-out-of-3 (2oo3) voting architecture for its
sensors to provide both high safety and high availability.
Given Data:
Sensor (λ_DU): 200 FITs for each of the three sensors.
Proof Test Interval (TI): 1 year (8760 hours).
Common Cause Failure (β): 2% (lower due to diversity or separation).
Step 1: Understand the Formula
The simplified formula for a 2oo3 architecture is :
PFDavg ≈ ( (1 - β)² * (λ_DU * TI)² ) + (β * λ_DU * TI) / 2
Note: This is a simplified approximation. More precise formulas exist, but this illustrates
the concept. A more common simplified formula is: PFDavg ≈ 6 * ( (1-β) * λ_DU * T1/2 )²
+ β * λ_DU * T1/2
Step 2: Calculate PFDavg for the 2oo3 Sensor Subsystem
Using the more common simplified formula:
PFDavg ≈ ( (1 - β)² * (λ_DU * TI)² ) + (β * λ_DU * TI) / 2
Independent Failure Term: (1 - 0.02)² * (200 x 10⁻⁹ * 8760)²
= (0.98)² * (1.752 x 10⁻³)²
= 0.9604 * 3.069 x 10⁻⁶ = 2.95 x 10⁻⁶
Common Cause Failure Term: (0.02 * 200 x 10⁻⁹ * 8760) / 2
= (0.02 * 1.752 x 10⁻³) / 2 = 1.75 x 10⁻⁵
Total Sensor PFDavg: (2.95 x 10⁻⁶) + (1.75 x 10⁻⁵) = 2.045 x 10⁻⁵
Conclusion: The 2oo3 architecture provides a PFDavg of 2.045 x 10⁻⁵, which is well
within the SIL 3 range (≥ 10⁻⁴ to <; 10⁻³). This demonstrates how higher levels of
redundancy and fault tolerance can achieve very high safety integrity.
Example 4: Risk Reduction Factor (RRF) and SIL
Scenario: A hazard analysis (like LOPA) has determined that a risk gap exists, requiring
a risk reduction of 500.
Step 1: Understand RRF
The Risk Reduction Factor (RRF) is the inverse of the PFDavg. It represents how much
the SIF reduces the risk of a hazardous event.
RRF = 1 / PFDavg
Step 2: Determine the Required PFDavg and SIL
Required RRF: 500
Required PFDavg: 1 / 500 = 0.002 = 2.0 x 10⁻³
Step 3: Map to SIL Table
We compare the required PFDavg to the SIL table:
SIL 1: PFDavg ≥ 10⁻² (RRF 10 to 100)
SIL 2: PFDavg ≥ 10⁻³ (RRF 100 to 1,000)
SIL 3: PFDavg ≥ 10⁻⁴ (RRF 1,000 to 10,000)
Conclusion: A PFDavg of 2.0 x 10⁻³ falls into the SIL 2 range. Therefore, a SIF with a
target of SIL 2 is required to provide the necessary risk reduction of 500 .
Example 5: Impact of Proof Test Coverage (PTC)
Scenario: Let's revisit the final element from Example 1, but this time, the proof test is
imperfect.
Given Data:
Final Element (λ_DU): 500 FITs
Proof Test Interval (TI): 1 year (8760 hours)
Proof Test Coverage (PTC): 80% (0.8). This means the test only finds 80% of
dangerous undetected faults.
Step 1: Understand the Formula with PTC
When PTC is less than 100%, some dangerous failures are never detected by the proof
test. The formula for PFDavg must be adjusted to account for both detected and
undetected failures during the test.
PFDavg ≈ (1 - PTC) * λ_DU * TI + (PTC * λ_DU * TI) / 2
This formula separates the failures into two groups: those missed by the test (which
accumulate linearly over time) and those found by the test (which are averaged over the
interval).
Step 2: Calculate PFDavg with 80% PTC
Undetected Portion: (1 - 0.8) * (500 x 10⁻⁹ * 8760) = 0.2 * (4.38 x 10⁻³) = 8.76 x
10⁻⁴
Detected Portion: (0.8 * 500 x 10⁻⁹ * 8760) / 2 = (0.8 * 4.38 x 10⁻³) / 2 = 1.752 x
10⁻³
Total PFDavg: (8.76 x 10⁻⁴) + (1.752 x 10⁻³) = 2.628 x 10⁻³
Step 3: Compare with 100% PTC
In Example 1, with 100% PTC, the PFDavg for the final element was 2.19 x 10⁻³. With
80% PTC, the PFDavg has increased to 2.628 x 10⁻³.
Conclusion: Imperfect proof testing degrades the safety performance of the SIF. The
lower the PTC, the higher the PFDavg, because a fraction of dangerous faults remain
hidden in the system indefinitely. This highlights the importance of designing thorough
and effective proof test procedures .