Safety Instrumented Systems — SIS, ESD, BMS (IEC 61511 / IEC 61508)

A Safety Instrumented System (SIS) is an independent protection layer (IPL) designed to bring a process to a safe state when a dangerous condition is detected — operating independently from the basic process control system (BPCS/DCS). SIS comprises a sensor subsystem (initiating element), a logic solver (safety PLC or relay), and a final element (shutdown valve, interlock, or motor trip). Emergency Shutdown (ESD) systems protect personnel and equipment from process over-conditions. Burner Management Systems (BMS) control safe start-up, operation, and shutdown of fired equipment. All SIS are designed and certified to IEC 61511 (process industry) using the target Safety Integrity Level (SIL) determined by HAZOP/LOPA risk assessment.

Challenges

SIS Bypass (Inhibit) Left Active After Maintenance — SIS Non-Functional

Maintenance bypass left on — SIS cannot initiate shutdown if demand arises; protection layer absent.

Proof Test Interval Longer Than Required by SIL Calculation

Proof test at 5-year interval when SIL 2 calculation requires annual test — PFD accumulates beyond SIL target.

Common Cause Failure: BPCS and SIS Share Power Supply or Network

Shared power supply failure simultaneously disables BPCS control and SIS protection — dual failure with no protection.

Final Element Failure to Close on Demand (Valve Stuck Open)

Shutdown valve corrodes in open position during long standby — partial stroke testing not done; fails to close on demand.

SIL Verification Not Updated After Process Modification (Management of Change)

Process modification changes hazard frequency — SIL requirement may have increased; original SIS is now under-specified.

Solutions

Applications

SIS / ESD / BMS System Reference

Safety Instrumented Systems — SIL Reference and System Configuration

System Type

SIL Level

PFD Target (per demand)

Logic Solver Architecture

Sensor Voting

Final Element Verification

Proof Test Interval

Key Standard

Industries

SIL 1 Safety Function

SIL 1

0.1–0.01

1oo1 (safety PLC SIL 1 certified)

1oo1 (single sensor)

Annual valve stroke test

12 months

IEC 61511 / IEC 61508

General chemical; utility; pharmaceutical; water

SIL 2 Safety Function

SIL 2

0.01–0.001

1oo2D (dual logic solver with diagnostics)

1oo2 or 2oo3 voting

PST quarterly + annual full stroke

12 months

IEC 61511 / IEC 61508

O&G, chemical, nuclear, pharma — standard for high-hazard process

SIL 3 Safety Function

SIL 3

0.001–0.0001

2oo3 TMR (triple modular redundant)

2oo3 voted sensors

Monthly PST + annual full proof test

6 months (or less)

IEC 61511 SIL 3 / IEC 61508

Nuclear; offshore; LNG; high-consequence hazardous chemical

Emergency Shutdown (ESD)

SIL 1–3

Application-specific

Safety PLC (1oo2 to 2oo3 per SIL)

Per SIF requirement

PST + full proof test

Per SIL-derived interval

API 14C (offshore); NFPA 72; IEC 61511

O&G upstream/downstream; chemical; mining

Burner Management (BMS)

SIL 2 (typical)

0.01–0.001

Certified BMS controller (1oo2D)

1oo2 flame detection

Burner trip test per start

6 months

NFPA 85 (boilers); IEC 61511; EN 50156 (industrial furnace)

Boilers; fired heaters; ovens; power generation

Fire & Gas (F&G)

SIL 1–2

Application-specific

F&G safety controller (1oo2D)

1oo2 or 2oo3 detector voting

Quarterly gas/fire detector test

6–12 months

IEC 61511; EN 54 (fire); ATEX

O&G; chemical; nuclear; data centres

High Integrity Pressure Protection (HIPPS)

SIL 2–3

0.01–0.0001

Safety PLC (2oo3 TMR for SIL 3)

2oo3 pressure transmitters

PST monthly; annual full test

3–6 months

IEC 61511; API 14C; ISO 10418

O&G; chemical; high-pressure process — replaces physical PRV bank

×

Search

Are you looking for a specific product or topic? Tyoe in the term here and quickly receive the answer to your search.

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors

Enquiry