Safety Instrumented Systems — SIS, ESD, BMS (IEC 61511 / IEC 61508)
A Safety Instrumented System (SIS) is an independent protection layer (IPL) designed to bring a process to a safe state when a dangerous condition is detected — operating independently from the basic process control system (BPCS/DCS). SIS comprises a sensor subsystem (initiating element), a logic solver (safety PLC or relay), and a final element (shutdown valve, interlock, or motor trip). Emergency Shutdown (ESD) systems protect personnel and equipment from process over-conditions. Burner Management Systems (BMS) control safe start-up, operation, and shutdown of fired equipment. All SIS are designed and certified to IEC 61511 (process industry) using the target Safety Integrity Level (SIL) determined by HAZOP/LOPA risk assessment.


The SIS is designed around a defined SIL target (SIL 1, 2, or 3) derived from risk assessment — SIL determines the required probability of failure on demand (PFD) per safety function: SIL 1: PFD 0.1–0.01; SIL 2: PFD 0.01–0.001; SIL 3: PFD 0.001–0.0001. For each Safety Instrumented Function (SIF), the SIL is achieved through the combination of sensor redundancy (1oo2, 2oo3 voting), logic solver reliability (SIL-certified safety PLC), final element reliability (SIL-rated shutdown valve with solenoid and partial stroke testing), proof test interval (annual or more frequent), and self-diagnostics. The SIS logic solver must be architecturally segregated from the BPCS — separate hardware, separate power supply, separate I/O network.
Challenges
SIS Bypass (Inhibit) Left Active After Maintenance — SIS Non-Functional
Maintenance bypass left on — SIS cannot initiate shutdown if demand arises; protection layer absent.
Proof Test Interval Longer Than Required by SIL Calculation
Proof test at 5-year interval when SIL 2 calculation requires annual test — PFD accumulates beyond SIL target.
Common Cause Failure: BPCS and SIS Share Power Supply or Network
Shared power supply failure simultaneously disables BPCS control and SIS protection — dual failure with no protection.
Final Element Failure to Close on Demand (Valve Stuck Open)
Shutdown valve corrodes in open position during long standby — partial stroke testing not done; fails to close on demand.
SIL Verification Not Updated After Process Modification (Management of Change)
Process modification changes hazard frequency — SIL requirement may have increased; original SIS is now under-specified.
Solutions
- Automatic Bypass Monitoring with Timed Alarm (Max 2-Hour Bypass Duration): PLC/SIS logs every bypass activation with timestamp; automatic alarm if bypass exceeds 2 hours — forces return or management approval.
- Proof Test Management System (Digital Work Order, As-Found/As-Left Recording): Digital work order system generates proof test procedures, records results, and alerts if overdue — traceability for audit.
- Physical Segregation: SIS on Separate UPS + Dedicated Power Distribution Board: SIS powered from separate UPS from BPCS — loss of BPCS power does not affect SIS; loss of SIS power goes to fail-safe (de-energise to trip).
- Partial Stroke Testing (PST) on All SIS Shutdown Valves (Quarterly): PST strokes the valve 10–20% to confirm it is not stuck — low-cost diagnostic; detects most stuck-valve failure modes between annual proof tests.
- Functional Safety Management Plan per IEC 61511 + MOC Procedure for SIL Re-Verification: All process modifications reviewed by SIS engineer for hazard impact — SIL re-verification if safety case changes.
Applications
- Oil & Gas: ESD on wellheads, separators, and compressors; gas detection and emergency shutdown — SIL 2/3.
- Chemical: Emergency relief initiation, reactor runaway prevention, overpressure shutdown — SIL 2 typical.
- Pharmaceutical: CIP/SIP temperature interlock, autoclave safety, bioreactor pressure safety — SIL 1/2; IEC 61511.
- Power Generation: Turbine overspeed trip, boiler drum high-level, furnace BMS — SIL 2/3; IEC 61511 + NFPA 85.
- Utilities / Infrastructure: High-pressure gas station ESD, chlorination system interlock, water treatment overfeed shutdown — SIL 1/2.
SIS / ESD / BMS System Reference
Safety Instrumented Systems — SIL Reference and System Configuration | ||||||||
System Type | SIL Level | PFD Target (per demand) | Logic Solver Architecture | Sensor Voting | Final Element Verification | Proof Test Interval | Key Standard | Industries |
SIL 1 Safety Function | SIL 1 | 0.1–0.01 | 1oo1 (safety PLC SIL 1 certified) | 1oo1 (single sensor) | Annual valve stroke test | 12 months | IEC 61511 / IEC 61508 | General chemical; utility; pharmaceutical; water |
SIL 2 Safety Function | SIL 2 | 0.01–0.001 | 1oo2D (dual logic solver with diagnostics) | 1oo2 or 2oo3 voting | PST quarterly + annual full stroke | 12 months | IEC 61511 / IEC 61508 | O&G, chemical, nuclear, pharma — standard for high-hazard process |
SIL 3 Safety Function | SIL 3 | 0.001–0.0001 | 2oo3 TMR (triple modular redundant) | 2oo3 voted sensors | Monthly PST + annual full proof test | 6 months (or less) | IEC 61511 SIL 3 / IEC 61508 | Nuclear; offshore; LNG; high-consequence hazardous chemical |
Emergency Shutdown (ESD) | SIL 1–3 | Application-specific | Safety PLC (1oo2 to 2oo3 per SIL) | Per SIF requirement | PST + full proof test | Per SIL-derived interval | API 14C (offshore); NFPA 72; IEC 61511 | O&G upstream/downstream; chemical; mining |
Burner Management (BMS) | SIL 2 (typical) | 0.01–0.001 | Certified BMS controller (1oo2D) | 1oo2 flame detection | Burner trip test per start | 6 months | NFPA 85 (boilers); IEC 61511; EN 50156 (industrial furnace) | Boilers; fired heaters; ovens; power generation |
Fire & Gas (F&G) | SIL 1–2 | Application-specific | F&G safety controller (1oo2D) | 1oo2 or 2oo3 detector voting | Quarterly gas/fire detector test | 6–12 months | IEC 61511; EN 54 (fire); ATEX | O&G; chemical; nuclear; data centres |
High Integrity Pressure Protection (HIPPS) | SIL 2–3 | 0.01–0.0001 | Safety PLC (2oo3 TMR for SIL 3) | 2oo3 pressure transmitters | PST monthly; annual full test | 3–6 months | IEC 61511; API 14C; ISO 10418 | O&G; chemical; high-pressure process — replaces physical PRV bank |