Sil Verification
Sil Verification
Sil Verification
Amiya Ray
Sandeep Sidhu
RISK & IDENTIFICATION TECHNIQUE
PROTECTION LAYERS
FTA ANALYSIS
SIL VERIFICATION
2
In safety standards such as IEC 61511, what's at risk is identified as
personnel and the environment. However, most companies use an
expanded list of risk categories that can also include:
3
“What’s the likelihood a harmful
event will happen, and what are the
consequences if it does?”
4
• Preliminary Hazard Analysis
5
Sample likelihood risk assessment model
Adapted from IEC 61511-3, Table C.1 - Frequency of hazardous event likelihood
6
ASSESSING RISK .1
Sample consequence risk assessment model
Adapted from IEC 61511-3, Table C.2 - Criteria for rating the severity of impact of hazardous events . 7
The purpose of a plant safety program –
including safety instrumented systems – is to
ensure this exposure is tolerable at all times.
8
If inherent risk is greater than tolerable risk, the first choice should be to eliminate
the risk. If it can't be eliminated, it must be minimized or mitigated — by active
means such as relief valves or safety systems, or by passive means such as
containment dikes or bunds.
That's why it's important to identify how much the risks need to be reduced, and
then design a solution that delivers the appropriate level of protection.
9
How much do we need to reduce the risk? There are two ways of finding an answer:
quantitative and qualitative.
Quantitative
Risk a + Risk b + Risk c + Risk d……………………. Risk z = RRF x (Risk Tolerable )
For example, we may want to reduce the frequency of a fatality from once
every 10 years to once every 10,000 years. In other words, we want to reduce
risk by a factor of 1000 — which our Risk Reduction Factor or RRF.
10
Qualitative
The second way of assessing the required risk reduction is to use qualitative
rankings like those in the example consequence and likelihood models introduced
11
So how do we achieve the necessary level of risk reduction?
By adding protection layers.
12
The safety instrumented system (SIS) provides an independent protection layer
that is designed to bring the process to a safe state when a hazardous condition
occurs.
13
DEFINITIONS OF
TERMINOLOGY
MTTR < T / 2
PFD avg. =λdd(MTTR)+λdu(T/2 )
Probably MTTR is shorter
than 100 x T.
Accordingly, it is required
minimizing T for shortening Failure detected Failure detected
PFD. by self- diagnosis only by proof test
Safe Failure
Dangerous
Failure Undetected Dangerous Failure
FAILURE DETECTION MECHANISM IN SAFETY
SYSTEMS
Replace with
diagnostic
sensor
CALCULATION SHEET
FAULT TREE ANALYSIS