Industrial Automation

SIL and IEC 61511 Explained for Automation Engineers

EDWartens Engineering Team
4 min read
SIL and IEC 61511 Explained for Automation Engineers

The short answer

A safety integrity level is a measure of how reliably a safety function performs when it is called upon, expressed as an average probability of failure on demand. SIL 1 means between 1 in 10 and 1 in 100 chance of failing on demand, SIL 2 is 1 in 100 to 1 in 1,000, SIL 3 is 1 in 1,000 to 1 in 10,000, and SIL 4 is 1 in 10,000 to 1 in 100,000. SIL is a property of a whole safety function, from sensor through logic solver to final element, not of a device you can buy.

The number, precisely

For low-demand mode, which covers most process safety functions:

SILAverage probability of failure on demandRisk reduction factor
110⁻² to 10⁻¹10 to 100
210⁻³ to 10⁻²100 to 1,000
310⁻⁴ to 10⁻³1,000 to 10,000
410⁻⁵ to 10⁻⁴10,000 to 100,000

SIL 4 is very rare in the process industries. If a study produces SIL 4, the usual and correct response is to change the design so that less risk reduction is needed from instrumentation.

What a SIS is, and what it is not

A safety instrumented system exists to take the process to a safe state when a hazardous condition occurs. It is separate from the basic process control system, and the separation is the point: if the control system's failure can cause the demand, the control system cannot also be what protects against it.

That separation is physical and organisational. Different logic solver, different I/O, usually different sensors and final elements, different change control, and a documented reason whenever anything is shared.

The three-part sum

A common misunderstanding is that buying a SIL 3 rated transmitter gives you a SIL 3 loop. It does not. The probability adds up across the whole function, and in most loops the largest contribution is the final element, usually a valve, because valves stick.

A typical split of the failure probability is roughly 15 per cent sensor, 15 per cent logic solver and 70 per cent final element. That is why proof testing concentrates on valves, and why partial stroke testing exists.

The lifecycle matters more than the number

IEC 61511 is a lifecycle standard, and the SIL number is one output of it. The parts that decide whether a plant is actually safe:

Hazard and risk assessment, usually a HAZOP, which identifies what can go wrong.

Allocation, typically a LOPA study, which decides how much risk reduction the instrumented layer must provide, and therefore the SIL.

Safety requirements specification, which states each function, its safe state, its trip points and its process safety time. This document is the one most often missing, and without it nobody can verify anything.

Design and verification, where the calculation proves the chosen equipment and test interval meet the target.

Operation, proof testing and change control. A SIL 2 loop with a five-year proof test interval that has not been tested in seven years is not a SIL 2 loop any more.

Where automation engineers fit

You will meet a SIS as the system you must not casually modify, and as the source of trips your process control has to handle gracefully. The practical skills are reading the safety requirements specification, understanding bypass and override management, knowing what a proof test involves, and never resolving a nuisance trip by defeating the function.

If you work on Siemens or Rockwell machinery safety rather than process safety, the neighbouring standards are ISO 13849 and IEC 62061 and the vocabulary is performance level rather than SIL. See machine safety risk assessment.

Courses: safety instrumented systems and SIL to IEC 61511, plus Siemens Safety Integrated and Allen-Bradley GuardLogix for the machinery side.

Frequently asked questions

Is IEC 61508 the same thing? IEC 61508 is the general standard that device manufacturers certify against. IEC 61511 is its application in the process industries, and it is the one a plant engineer works to.

Can a PLC be used as a safety logic solver? Only a safety-rated one, certified for the SIL you need, with the safety functions programmed to its safety manual. A standard PLC cannot, whatever it costs.

Who assigns the SIL? The risk assessment does, through a team including process, operations and safety. It is not an engineering preference and it is not a procurement decision.

Start Your Engineering Career at EDWartens

Join as a Junior Engineer at Wartens Automation Pvt Ltd. Get hands-on PLC SCADA training, industry certifications, and a 100% Job Guarantee backed by a 100% refund policy.