SIL Functional Safety Principles & Standards 3 — Questions and Answers
Question 1: In IEC 61508, what does 'systematic safety integrity' refer to?
- The probability of random hardware failures per hour
- The freedom from systematic faults caused by design errors, specification faults, or human error (Correct answer)
- The redundancy level of the safety function architecture
- The diagnostic test interval of the SIS
Correct answer: The freedom from systematic faults caused by design errors, specification faults, or human error
Systematic safety integrity addresses freedom from faults caused by design, specification, or process errors as opposed to random hardware failures.
Question 2: According to IEC 61511, which party is primarily responsible for ensuring the SIL target is correctly allocated for each safety instrumented function?
- The SIS supplier
- The asset owner/operator (Correct answer)
- The certification body
- The process licensor
Correct answer: The asset owner/operator
IEC 61511 places responsibility on the asset owner/operator to define the hazards and determine SIL targets through risk assessment.
Question 3: What does the Common Cause Failure (CCF) beta factor represent in a redundant SIS architecture?
- The fraction of dangerous failures attributed to a single common cause affecting multiple channels simultaneously (Correct answer)
- The ratio of detected to undetected failures
- The probability of spurious trip per year
- The test coverage achieved by proof testing
Correct answer: The fraction of dangerous failures attributed to a single common cause affecting multiple channels simultaneously
The beta factor is the fraction of total random hardware failures assumed to be common cause failures that defeat redundancy simultaneously.
Question 4: Which of the following is an example of an independent protection layer (IPL) that would typically NOT be credited in a LOPA?
- A basic process control system (BPCS) action that also initiates the initiating cause (Correct answer)
- A relief valve sized and maintained per API standards
- A dike designed to contain a full inventory spill
- A deluge system activated on separate detection logic
Correct answer: A basic process control system (BPCS) action that also initiates the initiating cause
A BPCS action cannot be credited as an IPL if the BPCS failure is also the initiating cause, violating the independence requirement.
Question 5: In IEC 61508, the Safe Failure Fraction (SFF) is calculated as the ratio of:
- Safe failures plus dangerous detected failures to total failure rate (Correct answer)
- Dangerous failures to total failure rate
- Safe failures to dangerous failures
- Detected failures to undetected failures
Correct answer: Safe failures plus dangerous detected failures to total failure rate
SFF = (λS + λDD) / (λS + λD), representing the proportion of failures that are either safe or detected dangerous failures.
Question 6: What is the maximum SIL achievable by a single safety function implemented in a simplex (1oo1) architecture according to IEC 61508 Route 1H constraints?
- SIL 1
- SIL 2 (Correct answer)
- SIL 3
- SIL 4
Correct answer: SIL 2
Route 1H architectural constraints limit a Type B 1oo1 subsystem to SIL 2 maximum based on SFF thresholds.
Question 7: Which document in the IEC 61511 lifecycle formally captures the as-built configuration of the SIS and serves as the baseline for future modifications?
- Pre-startup safety review (PSSR)
- Safety requirements specification (SRS)
- As-built documentation / SIS mechanical completion record (Correct answer)
- Functional safety assessment report
Correct answer: As-built documentation / SIS mechanical completion record
As-built documentation captures the final installed configuration and serves as the baseline for managing future modifications under MOC procedures.
In IEC 61508, what does 'systematic safety integrity' refer to?