Layers of Protection and Safety Functions

Where the SIS sits among the other defences.

13 min

Layers of protection

Process safety relies on independent layers, each capable of preventing or mitigating the hazard on its own. Working outward from normal operation:

  1. Process design — inherently safer design, where the hazard is removed or reduced rather than controlled.
  2. Basic process control system — normal regulatory control keeping the process in its envelope.
  3. Alarms and operator response — a human layer, credited only where the operator has clear indication, adequate time and a defined action.
  4. Safety instrumented system — automatic detection and action, independent of the control system.
  5. Mechanical protection — relief valves and rupture discs.
  6. Containment — bunds, dykes, drains.
  7. Mitigation — fire and gas detection, deluge, blowdown.
  8. Emergency response — plant and community response.

The essential requirement is independence. A layer that shares a sensor, a logic solver, a final element or a common cause with another layer cannot be credited twice. Using the control system's level transmitter for the high-level trip is the archetypal error: if it fails high, the control system fills the vessel and the trip is blind to it.

The safety instrumented function

A safety instrumented function (SIF) is a single, specific protective action: detect a defined abnormal condition and bring the process to a safe state. It has three parts:

  • Sensor — transmitters or switches detecting the condition.
  • Logic solver — a safety PLC or relay logic deciding when to act.
  • Final element — normally a shutdown valve with its solenoid and actuator, or a motor trip.

The safety instrumented system is the collection of all such functions. Each function is specified, assessed and tested individually, because each has its own hazard, its own required reliability and its own equipment.

Demand mode

  • Low demand — the function is called upon less than once a year. Nearly all process shutdown functions. The measure of performance is the probability of failure on demand: the chance that the function will not work when it is finally needed.
  • High demand or continuous — called upon frequently or continuously, measured by dangerous failure rate per hour. Machinery safety and some burner management functions.

The low demand case has an uncomfortable implication that drives the entire discipline: a safety function may sit untested and unused for years, accumulating undetected failures, and nobody will know until the day it is needed. Proof testing exists precisely to find those failures.

1 of 9

Checking your enrolment…