This is a subject and problem that often comes up when discussing SIS and especially with legacy systems. Given today’s modern instrumentation and the improvements in reliability, some people argue that there’s no need to replace the equipment until it fails. This certainly could be said for Basic Process Control Systems (BPCS) since the instrumentation and final elements are being continuously exercised. However, when it comes to SIS, this is not necessarily the case.
For SIS, one of the fundamental principles is that its reliability is based upon probabilistic analysis. SIS are primarily for monitoring and protection, although they could be used for control, which means they are mostly static systems not dynamic; sitting monitoring with their final elements not moving. This poses a number of potential problems for mechanical devices such as valves, solenoids, and actuators if they are static for 100 hours or more; namely stiction, cold-welding and corrosion. These dangerous conditions could prevent the SIS (and its Safety Instrumented Functions (SIFs)) being able to perform its protection function.
For this reason, we need to know what the Probability of Failure on Demand (PFDavg) is for the SIF, which is why we perform calculations in SIL verification analysis. To perform these calculations, we need to know the failure rates of each piece of equipment in the SIF. This is where the concept of a constant failure-rate during useful life of the equipment is utilized. Probabilistic calculations assume that the failure rate of the devices used in a SIF remain constant during the “flat” portion of the “bathtub” curve, shown below.

Bathtub Curve
Reliability engineers understand that the portion before the “flat” part of the “Bathtub” is where a high number of premature failures can occur commonly referred to as “premature failure”. Most manufacturers will perform stringent testing to weed-out, weaker units that could fail prematurely, leading to unwanted warranty claims. This usually involves testing, where the units are temperature cycled and/or subjected to shock/vibration testing.
Similarly, once the equipment reaches the end of the “flat” portion of the “Bathtub” then the failures start to rise dramatically. This part of the “Bathtub” is referred to as the “wear-out” phase. During this portion the concept of a constant failure rate no longer applies since the failures are unpredictable. Therefore, the probabilistic calculation of PFDavg can no longer be applied.
The Manufacturer will provide the useful life of its equipment in its Safety Manual, which will enable end users to be able to plan maintenance for changing out equipment that has reached the end of its useful life, assuming no failures up to this point. During the SIL verification of the SIFs in the SIS, the PFDavg is calculated for any Low Demand SIFs, predicated on the concept of constant failure rate during useful life. Once the useful life is exceeded, however, then the PFDavg is not applicable and hence the SIL of the SIF is now compromised and is no longer valid.
Oftentimes when I teach our FSE100 Course, I ask my students whether they have a run-to-fail policy and I’m surprised by how many times I hear the word “yes” in answer.
Therefore, if you follow a run-to-fail strategy for your SIS and its SIFs, you may want to think again because your system may not be as reliable as you think!
If this blog has stimulated your interest, then be sure to register for our upcoming webinar on this topic.
Tagged as: sis sil verification calculations reliability engineering