(01)EngineeringSafety Systems

Safety systems engineered from risk, not assumptions.

Safety design begins with hazard analysis and ends with verified risk reduction. Every safety instrumented function is traceable from the initiating hazard through SIL allocation, design, verification, testing, and long-term operation.

StandardsCSA B149.3 · IEC 61511 · ISA 84 · NFPA · IEC 61508
LifecycleHAZOP · LOPA · SRS · FAT · SAT
DeliverablesSRS · Cause & Effect Matrices · proof test procedures
(02)Risk Basis
LOPA / NODE-04 / OVERPRESSURE - V-101WORKSHEET 02INITIATING EVENTPCV-101 FAILf = 1.0 × 10⁻¹ /yrINDEPENDENT PROTECTION LAYERSIPL-1BPCS LOOPPFD 10⁻¹IPL-2OPERATOR ACTIONPFD 10⁻¹IPL-3RELIEF VALVEPFD 10⁻²IPL-4SIF (NEW)PFD 10⁻²TOLERABLE FREQUENCYF_t ≤ 1.0 × 10⁻⁶ /yrREQUIRED RRF10⁵CREDITED LAYERS10³SIF TARGETSIL 2SIL BAND REFERENCE - IEC 61511SIL 1RRF 10 - 100SIL 2RRF 100 - 1 000SIL 3RRF 1 000 - 10 000SIL 4RRF 10 000 - 100 000SHEET 02 OF 09 / FAC: V-101 / ENG: RVS / CHK: __ / APP: __
EXC.002LOPA / NODE-04 / V-101SIL 2

Risk-Based Safety Engineering

Safety systems should reflect actual process risk, not generic templates. Hazard studies, consequence analysis, and layer-of-protection evaluations establish the basis for every SIS decision.

  • Hazard AnalysisHAZOP facilitation and participation grounded in real operating conditions and process behaviour.
  • LOPA & SIL AllocationRisk reduction requirements established through defensible assumptions and documented methodology.
  • TraceabilityEvery hazard scenario linked directly to its corresponding safety instrumented function and lifecycle documentation.
Operating principle

Defensible risk reduction, verified safety performance, and documentation that survives the next twenty years of plant life.

(03)SIF Design
SIF-101 / 1oo2D · SIL 2 · DEMAND ≤ 1/yrFIG 04SENSORS · 1oo2PT-101APFD 5e-3PT-101BPFD 5e-31oo2VOTEDIAGLOGIC SOLVER · CERTIFIEDSIS-LS-01IEC 61508 SIL 3 CAPABLECAUSE → EFFECTPFD 1e-31oo2FINALELEMENTFINAL ELEMENTS · 1oo2XV-101AXV-101BPFD ALLOCATIONSENSORS1.0 × 10⁻³LOGIC SOLVER1.0 × 10⁻³FINAL ELEMENT5.0 × 10⁻³SIF TOTAL7.0 × 10⁻³SIL VERIFICATION: PFDavg 7.0e-3 → SIL 2 ACHIEVED · TARGET MET
FIG.004SIF-101 / 1oo2D / SIL 2VERIFIED

Verified Safety Instrumented Functions

Safety functions are engineered to achieve their required performance, not simply assembled from preferred hardware.

  • Safety Requirements SpecificationEach SIF defined with required action, response time, fail-state, testing method, and operating constraints.
  • Architecture SelectionVoting architecture, redundancy, diagnostics, and proof-test intervals selected to satisfy the required integrity target.
  • Cause & Effect DevelopmentProtection logic documented explicitly, eliminating undocumented interlocks, bypasses, and operator assumptions.
(04)Lifecycle
SAFETY LIFECYCLE - IEC 61511 / R2FIG 02PHASEANALYSISREALISATIONOPERATION/01HAZOP / LOPA/02SRS/03SIF DESIGN/04FAT/05SAT / COMMISSION/06OPERATION/07PROOF TEST/08MOC / DECOMVERIFICATION & ASSESSMENTindependent audit at every phase boundaryDELIVERABLESRISK REGISTER · LOPA WORKSHEETSSRS · CAUSE-AND-EFFECT · FAT PROTOCOLSPROOF TEST PLAN · MOC LOGREF: IEC 61511-1 §6 / RVSA SAFETY MANAGEMENT PLAN R2
FIG.002SAFETY LIFECYCLE / IEC 61511R2

Lifecycle & Compliance

Safety integrity is maintained, not granted at startup. Proof-test programs and management-of-change processes keep the SIS performing as intended throughout the life of the facility.

  • Proof-Test ProgramsOperations-ready procedures developed to maintain safety integrity throughout the life of the facility.
  • Management of ChangeSafety documentation structured to remain maintainable through audits, personnel turnover, and future modifications.
(05)Verification

Verified Performance

A SIL claim is only valid if it can be demonstrated. Verification work proves the installed system meets its required performance, with the math, the protocol, and the acceptance record on file.

  • SIL VerificationPerformance verified against certified failure data, actual architecture, and defined proof-test intervals.
  • Factory & Site Acceptance TestingProtection functions validated against the Safety Requirements Specification and Cause & Effect matrix.
(06)Engage

Bring us a hazard that needs a defensible answer.

Greenfield SIS, brownfield modifications, SIL verification, or proof-test program development - we'll work with your team to establish the risk basis before defining the path forward.