View Categories

Instrumented Systems – SIL Calculations

SIL calculations are a critical part of designing, validating, and maintaining Safety Instrumented Functions (SIFs) and High Integrity Pressure Protection Systems (HIPS). Within Safety Lifecycle Manager (SLM), users can perform SIL calculations using the native SIL Calc engine and compare results against target safety requirements and operational performance data.

By combining function architecture, failure rate sources, proof testing information, and demand mode selections, SLM enables organisations to evaluate whether their safety functions achieve the required level of risk reduction. The results can then be compared directly against target SIL requirements and observed operational performance.

This guide explains how SIL calculations work in SLM, the key parameters that influence results, how different failure rate sources are used, and how calculated results are compared against target requirements.

What Are SIL Calculations?

SIL calculations are mathematical evaluations used to determine whether a Safety Instrumented Function can achieve its required Safety Integrity Level (SIL). These calculations typically evaluate the probability of failure on demand (PFD), risk reduction factor (RRF), probability of failure per hour (PFH), and related reliability metrics.

Within SLM, SIL calculations can be executed for both SIF and HIPS functions using the built-in SIL Calc engine.

The calculation process uses:

  • Function architecture and voting arrangements
  • Failure rate sources
  • Proof testing information
  • Diagnostic coverage assumptions
  • Mission time parameters
  • Demand mode selections

The resulting calculations help determine whether the function is capable of achieving the required risk reduction specified during the safety lifecycle.

If you’re new to functional safety terminology, our Safety Integrity Levels (SIL) Explained guide provides an overview of how SIL ratings are determined and applied throughout the safety lifecycle.

How to Calculate SIL Using Function Architecture

One of the most important factors affecting SIL calculations is the architecture of the safety function itself.

Within SLM, users define the sensors, logic solvers, and final elements that make up the function. Voting arrangements determine how many elements must successfully operate for the function to respond to a demand.

SLM uses fault-tree style Boolean algebra calculations to evaluate these configurations.

Voting is expressed as M out of N:

  • M = Number of successful elements required
  • N = Total available elements

Examples include:

  • 1oo1 (1 out of 1)
  • 1oo2 (1 out of 2)
  • 2oo3 (2 out of 3)

Correct architecture and voting configuration are essential because even small changes can significantly affect the resulting PFD and RRF values.

SIL Calculation Parameters That Affect Results

Accurate SIL calculations depend on the quality and completeness of the input parameters supplied to the calculation engine.

Several fields directly influence calculation outcomes, including:

  • Mission Time
  • Beta Factor
  • Dangerous Failure Percentage
  • Proof Test Interval (PTI)
  • Proof Test Coverage (PTC)
  • Diagnostic Coverage (DC)
  • Mean Time To Repair (MTTR)
  • Partial Stroke Test Interval (PSTI)
  • Partial Stroke Test Coverage (PSTC)

Blank numerical fields are treated as zero values by the SIL Calc engine. As a result, incomplete data can significantly influence calculated results.

SLM also supports automatic unit conversions, allowing users to enter values using different units of measure while maintaining consistent calculations internally.

Probability of Failure on Demand (PFD) Explained

Probability of Failure on Demand (PFD) is one of the most widely used outputs generated by SIL calculations.

PFD represents the likelihood that a safety function will fail to perform when a demand occurs.

Several factors influence PFD values:

  • Failure rates
  • Proof testing frequency
  • Diagnostic coverage
  • Mission time
  • Voting architecture
  • Repair intervals

Generally:

  • More frequent proof testing lowers PFD.
  • Higher diagnostic coverage lowers PFD.
  • Improved architecture lowers PFD.
  • Longer proof test intervals increase PFD.

SLM automatically calculates and displays PFD values based on the selected demand mode and failure rate source.

PFD values play a major role in determining whether a function can achieve its required Safety Integrity Level. Learn more in our SIL 2 Explained and SIL 3 Explained guides.

Risk Reduction Factor (RRF) and SIL Calculations

Risk Reduction Factor (RRF) is closely related to PFD and forms an important part of many SIL calculations.

RRF represents the amount of risk reduction provided by a safety function.

As PFD decreases, RRF increases.

This means that a lower probability of failure results in a greater reduction in risk.

SLM automatically calculates RRF alongside PFD and displays both values within the SIL calculation results.

These values can then be compared directly against target SIL requirements established during design.

Understanding Delete vs Delete and Cascade

SLM provides two distinct deletion options that serve different purposes.

OptionPurpose
DeleteRemoves a single eligible object that has no blocking child relationships.
Delete and CascadeRemoves an object and all associated descendants within the hierarchy.

Selecting the correct option helps prevent accidental data loss while ensuring hierarchy structures remain valid.

Users should always review the objects affected before confirming any deletion activity.

Failure Rate Sources Used in SIL Calculations

SLM provides four different failure rate sources for use within SIL calculations.

These sources allow organisations to evaluate results using different assumptions and levels of operational experience.

The available sources are:

  • Prior Use Failure Rate – Based on event data captured through Prior Use Certificates.
  • Custom Failure Rate – User-entered failure rate values.
  • Design Basis Failure Rate – Static values stored within Prior Use Certificates.
  • External Results – Results entered from external SIL calculation tools.

Each source may produce different results, and organisations must select which source will govern performance comparisons and reporting.

For organisations managing operational performance data, prior use certificates can provide increasingly accurate results as more event information is collected.

Choosing Between Low Demand and Continuous Demand Modes

The demand mode selected for a function has a significant impact on SIL calculations.

SLM supports both Low Demand Mode and Continuous Demand Mode as defined within IEC 61511.

Low Demand Mode

  • Most commonly used mode.
  • Results displayed as PFD and RRF.
  • MTTFS displayed in years.

Continuous Demand Mode

  • Used when demands occur more than once per year.
  • Results displayed as PFH.
  • SIL levels displayed directly.
  • MTTFS displayed in hours.

Changing demand modes does not require users to manually update component parameters because SLM automatically handles unit conversions during recalculation.

Comparing SIL Calculation Results to Requirements

Once SIL calculations have been executed, SLM automatically compares the results against target requirements.

Results are displayed using visual indicators that quickly show compliance status.

  • Green indicates the target requirement has been met or exceeded.
  • Red indicates the target requirement has not been achieved.

Users must then select a governing result source that determines which calculation result is used for reporting and performance comparisons.

The selected governing source is displayed throughout the function performance views and higher-level reporting structures.

This allows organisations to consistently evaluate safety performance using their chosen calculation methodology.

When reviewing calculation results, it is important to understand the reliability requirements associated with each SIL target. Our guides covering SIL 1, SIL 2, SIL 3, and SIL 4 explain the requirements and risk reduction expectations for each level.

Best Practices for SIL Calculations

Producing reliable SIL calculation results requires more than simply entering data into the system.

Recommended best practices include:

  • Verify voting architecture before calculations.
  • Ensure proof test intervals are realistic.
  • Use accurate diagnostic coverage assumptions.
  • Maintain high-quality prior use certificate data.
  • Select the correct demand mode.
  • Review governing result source selections carefully.
  • Validate calculation inputs regularly.

Following these practices helps ensure calculated results accurately reflect real-world safety performance.

For organisations implementing broader functional safety programmes, see our Functional Safety Management Software resources.

Learn More About SIL Calculations and Functional Safety

Understanding SIL calculations is essential for designing, validating, and maintaining effective Safety Instrumented Functions. By combining architecture modelling, failure rate management, proof testing assumptions, and operational performance data, SLM provides a powerful platform for evaluating safety function performance.

You may also find these resources useful:

For additional information on SIL determination and safety lifecycle requirements, visit the International Electrotechnical Commission (IEC).

Please complete the form below

Please complete the form below.

You will automatically be forwarded to a demonstration video