Member, National Safety Council

What is Safety Integrity Level (SIL)? SIL 1, 2 & 3 Explained

An open safety PLC cabinet featuring yellow safety-rated I/O modules, DIN rail terminal blocks, and organized cable ducting inside a process plant control room

Safety Integrity Level (SIL) is a key concept in functional safety used to specify the required level of risk reduction associated with a safety function. In process industries, SIL is closely associated with Safety Instrumented Functions (SIFs) implemented through Safety Instrumented Systems (SISs).

SIL is often misunderstood as a rating given to an individual instrument, PLC or shutdown system. In practice, the safety integrity requirement applies to the safety function as a whole. The required SIL is determined through hazard and risk assessment, while the implemented SIF must subsequently be designed, verified, validated, operated and maintained so that it can achieve the required level of safety integrity.

For process industries, IEC 61511 provides the principal functional safety framework for safety instrumented systems, while IEC 61508 provides the broader functional safety framework for electrical, electronic and programmable electronic safety related systems.

What is Safety Integrity Level?

A Safety Integrity Level (SIL) is a discrete level used to specify the safety integrity requirements of a safety function.

IEC 61508 defines four SIL levels:

SIL 1, SIL 2, SIL 3 and SIL 4.

The levels represent increasing requirements for risk reduction capability. IEC’s functional safety material associates SIL 1 through SIL 4 with progressively higher risk reduction factors.

For process industry SIS applications, SIL 1, SIL 2 and SIL 3 are the levels normally encountered. SIL 4 is defined within IEC 61508 but is not normally encountered for typical process industry SIS applications.

The important point is that SIL is not selected simply because a higher level provides more protection.

The required SIL should come from an appropriate hazard and risk assessment and the risk reduction that the safety function needs to provide.

SIL, SIF and SIS: What is the Difference?

Understanding the difference between SIL, SIF and SIS is essential before discussing SIL assessment.

What is a Safety Instrumented Function?

A Safety Instrumented Function (SIF) is a specific instrumented safety function intended to achieve or maintain a safe state when a defined hazardous condition occurs.

A typical SIF has three functional elements:

Sensor → Logic Solver → Final Element

For example, consider a high pressure scenario in a process vessel.

A pressure transmitter detects the hazardous condition.

The safety logic solver evaluates the signal.

A final element, such as a shutdown valve, takes the defined action to bring the process toward a safe state.

Those elements collectively perform the SIF.

The SIF is the function for which the required safety integrity is specified.

What is a Safety Instrumented System?

A Safety Instrumented System (SIS) is the system used to implement one or more Safety Instrumented Functions.

It can include sensors, logic solvers, final elements and the associated hardware, application software and supporting arrangements required for the safety functions.

IEC 61511 specifies requirements for the specification, design, installation, operation and maintenance of SIS so that they can be entrusted to achieve or maintain a safe state of the process.

What is the Difference Between SIL and SIF?

The simplest way to remember the distinction is:

SIF: the specific safety function

SIS: the system implementing one or more SIFs

SIL: the level of safety integrity specified for the safety function

This distinction is important because saying that an individual transmitter or PLC is “SIL 2” does not, by itself, establish that the complete SIF achieves SIL 2.

Why is SIL Important in Process Safety?

Process plants can involve hazardous chemicals, flammable materials, high pressures, high temperatures and reactions that can escalate rapidly following a process deviation.

Consider a reactor where temperature exceeds a defined safe limit.

Possible protection may include:

  1. Basic process control
  2. High temperature alarm
  3. Operator response
  4. Automatic shutdown
  5. Pressure relief
  6. Emergency response measures

These measures do not necessarily qualify as Independent Protection Layers, and they do not necessarily provide the same degree of risk reduction.

A structured risk assessment is therefore required to determine whether the existing safeguards are sufficient and whether an additional safety function is required.

Where an SIF is required, SIL provides a way of specifying the required safety integrity of that function.

How is SIL Determined?

SIL determination begins with the hazardous scenario, not with the instrument selection.

A typical process involves several stages.

1. Identify the Hazardous Scenario

The assessment first identifies a credible hazardous scenario.

Examples may include:

  1. High pressure
  2. High temperature
  3. High level
  4. Loss of cooling
  5. Loss of containment
  6. Excessive flow
  7. Loss of critical utility
  8. Dangerous chemical reaction

The scenario may have been identified through a HAZOP, PHA or another structured hazard identification process.

2. Identify the Initiating Event

The initiating event is the event or combination of failures and errors that starts the incident sequence.

Potential initiating events may include:

  1. Equipment failure
  2. Instrument failure
  3. Utility failure
  4. Control system failure
  5. Human error
  6. Incorrect operation
  7. Loss of cooling

The initiating event frequency must be established using the methodology and data appropriate to the assessment.

3. Determine the Consequence

The potential consequence is evaluated based on the scenario.

Depending on the process, consequences may include:

  1. Personnel injury or fatality
  2. Fire
  3. Explosion
  4. Toxic exposure
  5. Environmental release
  6. Equipment damage
  7. Production interruption

4. Identify Creditable Protection Layers

Existing safeguards are then reviewed to determine which can legitimately be credited for risk reduction.

This is where the concept of an Independent Protection Layer (IPL) becomes particularly important.

CCPS defines an IPL as a device, system or action capable of preventing a scenario from proceeding to its undesired consequence independently of the initiating event and other protection layers credited for that scenario. CCPS also identifies independence, functionality, integrity, reliability, auditability and other attributes that need to be considered.

Not every safeguard automatically qualifies as an IPL.

5. Determine the Additional Risk Reduction Required

The remaining risk is compared with the applicable risk acceptance criteria.

If existing protection does not reduce the scenario risk sufficiently, additional risk reduction may be required.

Where the additional protection is assigned to an SIF, the required safety integrity can then be determined.

How Does LOPA Support SIL Determination?

Layer of Protection Analysis (LOPA) is one of the commonly used approaches for evaluating process risk and determining whether additional protection is required.

CCPS describes LOPA as a semi quantitative methodology for analysing a single cause consequence scenario and evaluating initiating events, Independent Protection Layers and their associated failure probabilities.

The basic LOPA process includes:

  1. Identify the consequence.
  2. Define the accident scenario.
  3. Identify the initiating event and determine its frequency.
  4. Identify qualifying IPLs and estimate their probability of failure on demand.
  5. Determine the frequency of the mitigated consequence.
  6. Compare the resulting risk with the applicable risk criteria.
  7. Determine whether additional risk reduction is required.

If an additional SIF is required, the LOPA result can support determination of the required SIL.

CCPS specifically notes that LOPA has been used to determine the SIL necessary for an instrumented safety system.

An important distinction

LOPA is not simply a SIL calculator.

LOPA is a risk assessment methodology. The SIL requirement is derived from the risk reduction that the SIF needs to provide, using an appropriate methodology and risk criteria.

IEC 61511 Part 3 provides guidance on methods for determining required SILs.

SIL 1, SIL 2, SIL 3 and SIL 4

The SIL levels represent increasing levels of required safety integrity.

For low demand mode, the IEC framework uses PFDavg, or average probability of failure on demand, as one of the relevant safety integrity measures.

A simplified representation is:

SIL Low demand PFDavg Approximate Risk Reduction Factor
SIL 1 ≥ 10⁻² to < 10⁻¹ >10 to ≤100
SIL 2 ≥ 10⁻³ to < 10⁻² >100 to ≤1,000
SIL 3 ≥ 10⁻⁴ to < 10⁻³ >1,000 to ≤10,000
SIL 4 ≥ 10⁻⁵ to < 10⁻⁴ >10,000 to ≤100,000

These ranges should be understood specifically in the context of the applicable low demand safety integrity measure. IEC’s functional safety material presents the corresponding SIL risk reduction bands.

They should not be used as a shortcut for assigning SIL to a plant, instrument or SIF without performing the appropriate risk assessment.

Is SIL 3 Better Than SIL 2?

SIL 3 represents a higher safety integrity requirement than SIL 2.

However, that does not mean SIL 3 should automatically be selected whenever possible.

The appropriate SIL is determined by the required risk reduction.

Selecting a higher SIL than necessary can introduce additional design, verification, testing, maintenance and lifecycle requirements without being justified by the risk assessment.

The objective is therefore not to achieve the highest SIL.

The objective is to achieve the required risk reduction for the identified hazardous scenario.

What is SIL Determination?

SIL determination establishes the required safety integrity level for a SIF.

It answers the question:

How much risk reduction does this safety function need to provide?

The determination can use different hazard and risk assessment techniques depending on the application.

Common approaches include:

Layer of Protection Analysis

LOPA can provide a structured semi quantitative assessment of an individual cause consequence scenario and can support SIL determination.

Risk Graph

A risk graph approach uses defined risk parameters to determine an appropriate safety integrity requirement.

Quantitative Risk Assessment

Where greater numerical detail is required, a QRA may be used to quantify risk and support decisions regarding required risk reduction.

The selected method should be appropriate to the process, hazard, available data, risk criteria and applicable standards.

What is SIL Verification?

SIL determination and SIL verification are not the same activity.

SIL Determination

Determines the required SIL for the SIF.

SIL Verification

Checks whether the proposed SIF design can achieve the required SIL.

Verification can involve consideration of:

  1. Sensor subsystem
  2. Logic solver
  3. Final element subsystem
  4. Hardware architecture
  5. Diagnostic coverage
  6. Dangerous failure rates
  7. Proof test interval
  8. Proof test effectiveness
  9. Common cause considerations
  10. Other applicable hardware and systematic requirements

The actual verification method depends on the architecture, operating mode, applicable standard and available reliability information.

A manufacturer’s statement that a component is suitable for a particular SIL does not automatically establish the SIL capability of the complete SIF.

Why Proof Testing Matters for SIL

Safety instrumented functions can experience dangerous failures that are not immediately detected.

Proof testing is used to reveal dangerous failures that may otherwise remain undetected.

The effectiveness of the proof test and its interval can therefore influence the calculated safety integrity performance of the SIF.

This is one reason why SIL is not simply a design stage exercise.

The safety function has to be managed throughout its lifecycle.

IEC 61511 covers lifecycle activities associated with SIS, including specification, design, installation, operation and maintenance.

IEC 61508 and IEC 61511: What is the Difference?

IEC 61508

IEC 61508 is the broader functional safety standard for electrical, electronic and programmable electronic safety related systems.

It provides the underlying functional safety framework and principles for achieving the required safety integrity.

IEC 61511

IEC 61511 applies those functional safety principles specifically to Safety Instrumented Systems in the process industry sector.

IEC 61511 Part 1 covers requirements for the specification, design, installation, operation and maintenance of SIS. IEC identifies IEC 61511 as a process sector implementation of IEC 61508.

What about IEC 61511:2026?

This is important for a current 2026 article.

IEC currently lists the IEC 61511:2026 series, published on July 10, 2026. The series listing currently contains IEC 61511 Part 1:2016 with Amendment 1:2017, Part 2:2016, Part 3:2016 and the relevant technical reports.

Therefore, for a public article, I recommend not casually stating that “IEC 61511:2026 replaces IEC 61511:2016” unless the applicable project or standard documentation specifically establishes that.

A safer statement is:

IEC 61511 is the principal functional safety standard for safety instrumented systems in the process industry sector. The applicable edition, amendments and project requirements should be verified for each application.

That keeps the article technically responsible and avoids an outdated standards statement.

Common SIL Mistakes

Treating SIL as an Instrument Rating

A component may have functional safety capability or certification, but that does not by itself establish the SIL achieved by the complete SIF.

The SIF needs to be evaluated as a complete safety function.

Assuming Every Shutdown Function is SIL 3

Different SIFs can have different SIL requirements.

The required level depends on the risk associated with the particular hazardous scenario.

Taking Credit for Every Alarm or Safeguard

Not every alarm, operator action or protective measure automatically qualifies as an IPL.

LOPA requires defined criteria for crediting IPLs.

Using LOPA Without Clear Scenario Definition

CCPS states that LOPA is applied to a single cause consequence pair at a time.

A poorly defined scenario can therefore undermine the quality of the analysis.

Confusing SIL Determination with SIL Verification

Determining that an SIF requires SIL 2 does not prove that the proposed design achieves SIL 2.

The design needs to be verified against the applicable requirements.

Choosing a Higher SIL Without a Risk Basis

SIL should be based on the required risk reduction rather than simply selecting the highest available level.

When Should a SIL Assessment Be Performed?

SIL determination and related functional safety activities may be required during different stages of a facility’s lifecycle.

Examples include:

New Process or Plant Design

SIL requirements can be established before the SIS is fully designed.

HAZOP or PHA Follow Up

A hazard study may identify scenarios where additional instrumented protection is required.

Process Modification

Changes to process conditions, equipment, chemistry or operating philosophy can affect existing safety functions.

Management of Change

Changes that affect a SIF or its associated process risk should be evaluated through the applicable MOC and functional safety processes.

Existing Facility Review

Existing SIFs may require review where assumptions, operating conditions, documentation or protection requirements have changed.

Functional Safety Lifecycle Activities

SIL determination, specification, verification, validation, operation, maintenance and proof testing form part of the broader functional safety lifecycle.

What Information is Needed for SIL Assessment?

A meaningful SIL assessment requires an adequate understanding of the process and hazardous scenarios.

Depending on the project, relevant information may include:

  1. Process Flow Diagrams
  2. Piping and Instrumentation Diagrams
  3. Process descriptions
  4. HAZOP or PHA documentation
  5. Cause and Effect diagrams
  6. Process operating conditions
  7. Alarm philosophy
  8. Existing safeguards
  9. SIS documentation
  10. Instrumentation details
  11. Relief system information
  12. Control narratives
  13. Risk acceptance criteria
  14. Existing SIF information
  15. Applicable company standards
  16. Relevant reliability data

The exact information required depends on the assessment methodology and project scope.

SIL in the Functional Safety Lifecycle

SIL should not be treated as a one time calculation.

A typical functional safety lifecycle includes activities such as:

Hazard and Risk Assessment

SIL Determination

Safety Requirements Specification

SIF Design

SIL Verification

Installation and Commissioning

Validation

Operation and Maintenance

Proof Testing

Modification and Management of Change

Periodic Review

The actual lifecycle and responsibilities should be established in accordance with the applicable functional safety standard, safety planning and project requirements.

IEC 61511 provides lifecycle requirements for process industry SIS, while IEC 61508 provides the broader functional safety framework.

How INDSAFE Can Support SIL and Functional Safety

INDSAFE can support organizations with process safety and functional safety activities associated with risk identification, protection layer assessment and safety instrumented functions.

Depending on project requirements, services may include:

  1. HAZOP and Process Hazard Analysis
  2. Layer of Protection Analysis
  3. SIL Determination
  4. Safety Instrumented Function identification
  5. SIL Verification
  6. Functional Safety studies
  7. Safety Requirements Specification support
  8. Process Safety Management
  9. Quantitative Risk Assessment

The objective is to connect the identified process risk with appropriate protection requirements and support a structured functional safety lifecycle.

For new facilities, process modifications and existing plant reviews, SIL related activities should be performed using the applicable standards, project criteria and documented risk assessment methodology.

Frequently Asked Questions About Safety Integrity Level

What does SIL stand for?

SIL stands for Safety Integrity Level. It is a discrete level used to specify the safety integrity requirements associated with a safety function.

What are SIL 1, SIL 2 and SIL 3?

SIL 1, SIL 2 and SIL 3 represent progressively higher safety integrity requirements. The appropriate level depends on the risk reduction required for the particular safety function.

What is SIL 4?

SIL 4 is the highest SIL defined in IEC 61508. It represents a very high safety integrity requirement and is uncommon in typical process industry SIS applications. IEC 61508 defines four SIL levels according to the risk involved in the application.

Is SIL 2 safer than SIL 1?

SIL 2 represents a greater risk reduction capability than SIL 1. However, that does not mean every application should use SIL 2. The required SIL should be established from the risk assessment.

What is a SIF?

A Safety Instrumented Function is a specific instrumented safety function designed to achieve or maintain a safe state when a defined hazardous condition occurs.

What is an SIS?

A Safety Instrumented System is the system used to implement one or more Safety Instrumented Functions.

Can LOPA determine SIL?

LOPA can support determination of the required SIL by evaluating the risk associated with a defined scenario and determining whether additional risk reduction is required. CCPS specifically identifies LOPA as an approach that has been used for determining the SIL necessary for an instrumented safety system.

Is SIL determination the same as SIL verification?

No.

SIL determination establishes the required safety integrity.

SIL verification evaluates whether the proposed SIF design can achieve the required integrity.

Does every safety instrument need a SIL rating?

No.

SIL is associated with the safety integrity requirements of a safety function. A component’s functional safety capability or certification does not by itself establish the achieved SIL of the complete SIF.

Is HAZOP enough to determine SIL?

Not necessarily.

HAZOP is primarily a structured hazard identification and deviation analysis technique. Where an instrumented safety function requires a defined SIL, an appropriate SIL determination methodology is required.

Does a higher SIL always mean a better design?

No.

The objective is to provide the risk reduction required by the assessment. Selecting a higher SIL without a risk basis can add unnecessary complexity and lifecycle requirements.

Key Takeaway

Safety Integrity Level is fundamentally about risk reduction, not simply equipment classification.

A robust SIL assessment begins with a clearly defined hazardous scenario and considers the initiating event, consequence, existing safeguards and applicable risk criteria.

Where additional risk reduction is required, an appropriate Safety Instrumented Function can be identified and its required safety integrity determined.

The resulting SIF must then be properly specified, designed, verified, validated, operated, maintained and tested throughout its lifecycle.

For process industry applications, IEC 61511 provides the central functional safety framework for SIS, while IEC 61508 provides the broader functional safety framework. LOPA can provide a structured method for evaluating individual process risk scenarios and can support SIL determination where appropriate.

The objective is not simply to select the highest SIL.

The objective is to achieve the risk reduction required for the actual hazardous scenario through a properly engineered and managed safety function.

Technical References

International Electrotechnical Commission

IEC 61511: Functional safety, Safety instrumented systems for the process industry sector

International Electrotechnical Commission

IEC 61508: Functional safety of electrical/electronic/programmable electronic safety related systems

Center for Chemical Process Safety, AIChE

Layer of Protection Analysis: Simplified Process Risk Assessment

Center for Chemical Process Safety, AIChE

LOPA Data and Methodology

Center for Chemical Process Safety, AIChE

Guidelines for Initiating Events and Independent Protection Layers in Layer of Protection Analysis

Leave A Comment