SIL Safety Instrumented Systems Design & Validation 3 — Questions and Answers
Question 1: What is the purpose of a 'Safety Integrity Level Verification' calculation?
- To determine the required SIL from a risk graph
- To confirm that the designed SIS achieves the required PFDavg or PFH (Correct answer)
- To select the appropriate sensor technology for the process
- To schedule the next proof test date
Correct answer: To confirm that the designed SIS achieves the required PFDavg or PFH
SIL Verification calculations (using RBD, Markov, or simplified equations) confirm that the actual PFDavg (low demand) or PFH (high demand) of the as-designed SIS meets the SIL target.
Question 2: According to IEC 61511, who is responsible for ensuring that devices used in an SIS are suitable for the intended SIL?
- The device manufacturer exclusively
- The SIS end user or asset owner (Correct answer)
- The process licensor
- The insurance company auditor
Correct answer: The SIS end user or asset owner
IEC 61511 places responsibility on the end user (asset owner) to verify that devices are appropriate for the SIL, including reviewing manufacturer documentation and prior use justification.
Question 3: What distinguishes a 'High Demand' SIS from a 'Low Demand' SIS per IEC 61508?
- High demand mode has a demand rate greater than once per year or greater than twice the proof test frequency (Correct answer)
- High demand mode requires more than two redundant sensors
- High demand mode uses SIL 3 or SIL 4 only
- High demand mode SIS must use fail-safe logic solvers
Correct answer: High demand mode has a demand rate greater than once per year or greater than twice the proof test frequency
IEC 61508 defines high demand (or continuous) mode as a demand rate exceeding once per year or exceeding twice the proof test frequency; otherwise the system is low demand.
Question 4: In a Markov model used for SIL verification, what does the 'dangerous detected' (DD) state represent?
- A failure that causes a spurious trip and is detected by diagnostics
- A dangerous failure that is revealed by the automatic diagnostic function of the system (Correct answer)
- A failure that goes undetected until the proof test
- A failure with no safety consequence that has been identified
Correct answer: A dangerous failure that is revealed by the automatic diagnostic function of the system
The DD state in a Markov model represents dangerous failures that are automatically detected by built-in diagnostics, allowing the system to take a safe state or alert operators.
Question 5: What is the typical impact of increasing the proof test interval on PFDavg?
- PFDavg decreases because the system is tested less often, reducing wear
- PFDavg increases because dangerous undetected failures can accumulate longer (Correct answer)
- PFDavg remains unchanged as it depends only on hardware failure rates
- PFDavg decreases because the SIS spends less time in the test state
Correct answer: PFDavg increases because dangerous undetected failures can accumulate longer
Longer proof test intervals allow dangerous undetected failures to remain in the system for more time, which increases the average probability of failure on demand (PFDavg).
Question 6: Which type of failure is NOT typically revealed by automatic diagnostics in a SIS?
- Short circuits in wiring loops
- Dangerous undetected (DU) failures (Correct answer)
- Open circuit faults in 4-20mA loops
- Power supply voltage deviations
Correct answer: Dangerous undetected (DU) failures
Dangerous undetected (DU) failures are, by definition, those not revealed by automatic diagnostics and can only be found through periodic proof testing.
Question 7: In SIS validation, what is 'Factory Acceptance Testing' (FAT) primarily intended to confirm?
- That the SIS logic solver meets SIL requirements in the field environment
- That the assembled SIS system functions correctly per the SRS before shipment to site (Correct answer)
- That operator training has been completed satisfactorily
- That the proof test procedure has been reviewed by a competent person
Correct answer: That the assembled SIS system functions correctly per the SRS before shipment to site
FAT verifies that the assembled SIS hardware and software perform as specified in the SRS under controlled conditions at the manufacturer's or system integrator's facility before site delivery.
What is the purpose of a 'Safety Integrity Level Verification' calculation?