SIL Risk Assessment & Hazard Analysis 3 — Questions and Answers
Question 1: Which method is most appropriate for identifying common-cause failures in redundant safety systems?
- HAZOP study
- Failure Mode and Effects Analysis (FMEA)
- Beta-factor model analysis (Correct answer)
- Bow-tie analysis
Correct answer: Beta-factor model analysis
The beta-factor model quantifies common-cause failure probability in redundant architectures by estimating the fraction of failures that affect multiple channels simultaneously.
Question 2: When applying LOPA, the Initiating Event Likelihood (IEL) represents:
- The probability that an IPL fails on demand
- The frequency per year at which the initiating cause occurs without any protection (Correct answer)
- The combined risk reduction factor of all IPLs
- The consequence severity of the hazardous event
Correct answer: The frequency per year at which the initiating cause occurs without any protection
IEL is the unmitigated frequency of the initiating event per year, before credit is taken for any independent protection layers.
Question 3: A 'Tolerable Risk' criterion of 1×10⁻⁵ per year for a fatal event means:
- One fatality is expected every 10,000 years at the plant
- The probability of a specific individual being fatally harmed does not exceed one in 100,000 per year (Correct answer)
- Ten fatalities per year are tolerable
- The SIF must achieve SIL 1 as a minimum
Correct answer: The probability of a specific individual being fatally harmed does not exceed one in 100,000 per year
A tolerable individual risk of 1×10⁻⁵/yr means no more than a 1-in-100,000 annual probability of a fatal outcome for any specific exposed individual.
Question 4: In FMEA, 'criticality' combines which two factors?
- Detection rating and occurrence rating
- Severity of failure effect and probability of occurrence (Correct answer)
- Proof test interval and diagnostic coverage
- Hardware fault tolerance and safe failure fraction
Correct answer: Severity of failure effect and probability of occurrence
Criticality in FMEA is determined by the combination of the severity of the failure effect and the probability (rate) of the failure occurring.
Question 5: Which hazard analysis technique maps causes and consequences on either side of a central event using bow-tie diagrams?
- Event Tree Analysis (ETA)
- Fault Tree Analysis (FTA)
- Bow-tie analysis combining FTA and ETA (Correct answer)
- Checklist analysis
Correct answer: Bow-tie analysis combining FTA and ETA
Bow-tie analysis integrates FTA on the threat/cause side with ETA on the consequence side, centered on the top event, providing a complete risk picture.
Question 6: What is the significance of the 'Safe Failure Fraction (SFF)' in IEC 61508?
- It determines the maximum proof test interval
- It influences the hardware safety integrity level that can be claimed for a given architecture (Correct answer)
- It defines the maximum allowable PFD of the SIF
- It sets the beta factor for common-cause failures
Correct answer: It influences the hardware safety integrity level that can be claimed for a given architecture
SFF, combined with hardware fault tolerance, determines the maximum SIL that can be claimed for a subsystem according to IEC 61508 Route 1H architectural constraints.
Question 7: During a What-If analysis, the review team asks 'What if the cooling water supply fails?' This is an example of:
- A HAZOP deviation node
- A structured brainstorming question to identify hazard scenarios (Correct answer)
- An FTA top event definition
- An LOPA initiating event calculation
Correct answer: A structured brainstorming question to identify hazard scenarios
What-If analysis uses structured open-ended questions to systematically explore potential failure scenarios and their consequences.
Which method is most appropriate for identifying common-cause failures in redundant safety systems?