SIL Safety Instrumented Systems Design & Validation 2 — Questions and Answers
Question 1: What is the primary purpose of a Proof Test in an SIS?
- To verify that the SIS will perform its safety function on demand (Correct answer)
- To confirm the SIS has not triggered any spurious trips
- To validate that the PLC firmware is up to date
- To measure the process variable accuracy under normal conditions
Correct answer: To verify that the SIS will perform its safety function on demand
A proof test is a periodic test performed to reveal dangerous undetected failures, confirming the SIS can perform its intended safety function on demand.
Question 2: Which IEC 61511 clause governs the Management of Functional Safety for SIS?
- Clause 5 (Correct answer)
- Clause 8
- Clause 12
- Clause 16
Correct answer: Clause 5
IEC 61511 Clause 5 addresses the Management of Functional Safety, including the safety management system and competency requirements.
Question 3: During SIS design, what does 'architectural constraints' refer to in IEC 61511?
- Physical space limitations for mounting equipment
- Hardware fault tolerance requirements based on SIL and safe failure fraction (Correct answer)
- Network topology restrictions for field devices
- Environmental sealing requirements for enclosures
Correct answer: Hardware fault tolerance requirements based on SIL and safe failure fraction
Architectural constraints define the minimum hardware fault tolerance (HFT) required based on the target SIL and the safe failure fraction (SFF) of the subsystem.
Question 4: A 1oo2 voting architecture means the SIS initiates a safety action when:
- Both sensors detect a hazardous condition
- At least one of two sensors detects a hazardous condition (Correct answer)
- Neither sensor detects a hazardous condition
- A majority of sensors detect a hazardous condition
Correct answer: At least one of two sensors detects a hazardous condition
In a 1oo2 (1-out-of-2) architecture, a safety action is triggered when any one of the two sensors detects the hazardous condition, improving availability.
Question 5: What is 'Systematic Capability' (SC) in the context of SIS hardware?
- The device's rated SIL for random hardware failures only
- A measure of the device's ability to avoid systematic failures based on its development process (Correct answer)
- The proof test coverage percentage of the device
- The MTBF rating published by the manufacturer
Correct answer: A measure of the device's ability to avoid systematic failures based on its development process
Systematic Capability (SC) rates a device's resistance to systematic failures, reflecting how rigorously the device was designed and manufactured to IEC 61508.
Question 6: Which document formally records the results of an SIS validation and confirms it meets the SRS?
- Hazard and Operability Study (HAZOP) report
- Safety Requirements Specification (SRS)
- Validation Test Report (VTR) (Correct answer)
- Process Hazard Analysis (PHA) worksheet
Correct answer: Validation Test Report (VTR)
The Validation Test Report (VTR) documents the validation activities performed and confirms the SIS meets all requirements defined in the Safety Requirements Specification.
Question 7: In SIS design, what is the significance of the 'demand rate' on SIL selection?
- Higher demand rates require higher SIL to achieve the same risk reduction (Correct answer)
- Demand rate has no effect on SIL; only consequence severity matters
- Lower demand rates always require SIL 4
- Demand rate only affects the proof test interval, not the SIL
Correct answer: Higher demand rates require higher SIL to achieve the same risk reduction
A higher demand rate means the SIS is called upon more frequently, so a higher SIL may be needed to maintain the same acceptable residual risk level.
What is the primary purpose of a Proof Test in an SIS?