SIL Functional Safety Principles & Standards 4 — Questions and Answers
Question 1: A SIS operates in low-demand mode with a proof test interval of 1 year. If one proof test reveals a failure that has been present since the last test, what does this indicate about the PFD calculation?
- The Mission Time must be reduced
- The average PFD (PFDavg) accounts for this by averaging the probability of being in a failed state over the full test interval (Correct answer)
- The SIL target must be increased by one level
- The diagnostic test interval must be shortened to match the proof test interval
Correct answer: The average PFD (PFDavg) accounts for this by averaging the probability of being in a failed state over the full test interval
PFDavg integrates the probability of an undetected dangerous failure existing over the entire proof test interval, accounting for failures that could persist until found by the periodic proof test.
Question 2: Under IEC 61511, when must a Management of Change (MOC) procedure be applied to a SIS?
- Only when the SIL rating of a function is changed
- Whenever any modification is made to the SIS hardware, software, or operating procedures (Correct answer)
- Only when physical hardware is replaced
- Only after the five-year periodic functional safety assessment
Correct answer: Whenever any modification is made to the SIS hardware, software, or operating procedures
MOC applies to any change—hardware, software, configuration, or procedures—that could affect the functional safety of the SIS.
Question 3: Which IEC 61508 software safety integrity level (SSIL) technique is categorized as 'Highly Recommended' for SSIL 3 and 4 to reduce systematic faults?
- Structured programming
- Dynamic analysis and testing
- Formal methods (Correct answer)
- Modular design
Correct answer: Formal methods
Formal methods (e.g., model checking, theorem proving) are Highly Recommended at SSIL 3/4 to rigorously prove the absence of systematic design errors.
Question 4: What is the meaning of 'demand mode of operation' in the context of a safety instrumented function?
- The SIS is continuously active and must prevent hazardous events at all times
- The SIS is normally passive and activates only when a demand (hazardous condition) is detected (Correct answer)
- The SIS operates on a scheduled basis independent of process conditions
- The SIS responds only to operator-initiated manual trips
Correct answer: The SIS is normally passive and activates only when a demand (hazardous condition) is detected
In demand mode the SIF remains dormant until a process demand occurs, at which point it must perform its safety function to prevent a hazardous event.
Question 5: Which concept in IEC 61508 addresses the ability of a system to avoid bringing itself or the process into a hazardous state due to component failures?
- Fail-safe design (Correct answer)
- Diagnostic self-test
- Proof test coverage
- Fault avoidance
Correct answer: Fail-safe design
Fail-safe design ensures that upon component failure the system moves to a pre-defined safe state rather than a hazardous one.
Question 6: In a layer of protection analysis (LOPA), what value is typically assigned as the initiating event frequency for a 'basic process control system (BPCS) failure causing high pressure'?
- 10⁻¹ per year
- 10⁻² per year (Correct answer)
- 10⁻⁴ per year
- 10⁻⁶ per year
Correct answer: 10⁻² per year
A generic BPCS control loop failure initiating event frequency is typically taken as 10⁻¹ per year, but specific failures like high-pressure initiating causes are often assigned 10⁻² per year per industry guidance.
Question 7: According to IEC 61511, which activity must be completed before the detailed SIS design phase begins?
- Proof test procedure development
- Completion of the Safety Requirements Specification (SRS) (Correct answer)
- Factory Acceptance Testing (FAT)
- Operational and maintenance training
Correct answer: Completion of the Safety Requirements Specification (SRS)
The SRS must be completed and approved before detailed SIS design, as it defines what the SIS must do and the integrity required.
A SIS operates in low-demand mode with a proof test interval of 1 year.
If one proof test reveals a failure that has been present since the last test, what does this indicate about the PFD calculation?