Activity
Mon
Wed
Fri
Sun
Oct
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
What is this?
Less
More
Functional Safety Play Book

285 members • Free

22 contributions to Functional Safety Play Book
SIL Calculation
Good day everyone, I have few questions on SIL Calculation. I have a PILZ controller in SIF and try to make some calculation by hand. Controller has DI and DO with CPU. 1. If I would like to calculate PFDavg for Controller then I should combine DI, DO and CPU PFD avarage, correct? (No redundancy at DIs and DOs) For ex, PFD input, single + PFD output, single+ PFD CPU = 2,20 x 10^-4 + 1,30 x 10^-5 + 6,20 x 10^-5 (See please certificate) 2. As you see the certificate shows only PFD but not λ DU. Can I calculate my λDU from PFD as referencing the formula below? PFDavg = (λDU * T)/2 . Actually, the certificate does not say what T has been taken into account on PFD calculation as well, but I am going to take it as 1 year. 3. CPU Part: 773103 ( PNOZ m1p ETH) ; Certificate Link: https://www.pilz.com/download/open/PNOZmulti_TUEV-Sued_BM_M6A-020132-0284-R01_R4_4_valid_2030-Jun-24_1002803-BM-34.pdf Thank you!
0 likes • 14d
@Khalid Kalbiyev The certificate indicates that the reliability assessment for this PLC was made on the machinery FS standard. So you hardly find PFDavg values there. So you have to find other solution for this issue. So, instead you have some PFH numbers which you can treat as λ and use them in your own calculations of PFDavg. Just take number of DIs and DOs that are needed to manage all input and output signals. Then add CPU. And also don't forget about other components which are part of the safety PLC (like power supply, communication modules, etc.). They are components in series in a reliability block diagram - just add them and calculate final probability of failure within your mission time with some assumed proof test interval and proof test coverage (may be a generic data from safety logic controller).
The Playbook's been quiet — here's what's changing
I'll hold my hands up: I've been quiet in here for longer than I would have liked. Project work took over, and the community hasn't had the attention it deserves. That's changing from this week. Here's what's coming: - Decision Review Live is back — Friday 17th July, 6pm. Bring a real grey-area decision from a live project and we'll work through it together. - A new cohort of the nuclear programme opens in September — more on that shortly. - Q&A is coming back, running bi-weekly. - New SILVerify features are in development and will be live soon. - More case studies and guides on the way. Got a question sitting in your drafts? Post it, and let the community do its thing.
0 likes • Jul 7
I appreciate your work maintaining this forum. I have many ideas for topics, but not enough time to ask them before my vacation :)
Electrical final elements
Can anyone share their experience? Very practical two questions related to an issue which exists in many PFDavg calculations. What's your approach to a safety loop that includes typical electrical final elements, e.g. contactors? Although the IEC61508 and IEC61511 standards apply to electrical devices, many such solutions widely used in industry lack certification and reliability data. And if the data is available, it's usually related to PFH and is based on B10d - not well suitable for demand mode of operation calculations. Second one: how do you confirm their systematic capability?
0 likes • Jun 16
Hello everyone. Quite long time without answer so maybe I can trigger this topic once again. I really wonder your opinion about above high demand statement for the SIFs with breakers as final element. I have many doubts about this approach in the context of real possible demand for SIFs which protect rotating machines in process industry. My experience says that these critical ones usually work for long time without any stoppage, so should be treated as low demand. And one more: good quality breakers have a high operational reliability but usually don't have IEC61508 compliance documentation.
0 likes • Jun 26
@Harvey Dearden Same approach in my many projects. It's difficult to find a more common sense solution today. Confirming product quality based on the manufacturer's quality system and a declaration of compliance with IEC electrotechnical standards relevant to the implementation. However I look forward others point of view, it's always inspiring to find some new ideas.
Case Study 001 – Legacy SIS Assessment
A new case study has been added to the classroom. Scenario: A 1998 installed SIS with unknown diagnostic coverage is still in service. The asset owner believes it achieves SIL2 based on vendor documentation. Your task: Determine whether the claim is credible. Full case study here: [link] Questions: • What is the first thing you would check? • How would you deal with missing failure rate data? • Would you accept prior-use evidence?
1 like • May 20
I want to return to the topic of legacy systems, because I've just read your additional article on LI about this topic :) We're talking about systems that typically have dozens or even hundreds of SIF functions and even more devices. The problem certainly arises when we look at the devices installed before IEC61511. Let's assume they've all been operating for decades without any problems but for some reasons we want to do sth with their compliance. Doing assessment and relying 100% on generic reliability data can be a trap. Let's look at current equipment reliability data declared by manufacturers. Their expected lifetimes show that devices in legacy systems have typically exceeded these values ​​long time ago. Without evidence of testing, servicing, and refreshes, there's no way to formally confirm that these systems have the reliability we're aiming for. I think the approach you're presenting is based on common sense. There's probably no better method than successive analysis of individual system components and categorizing their importance based on risk assessment. And, whenever possible, upgrade to newer solutions based on real needs with cost-effective way.
0 likes • Jun 18
Mr Bachir, I don't know French but I tried to translate it. You are right about the need for a structured and well-defined way of collecting data. But what is your proven method for verifying that the devices to which you assign 'prior-use' data are not actually at the end of their useful lifetime, and that they won’t cause an increased probability of a major failure tomorrow?
IPL Management
Hi All, Just read an interesting article on the recent introduction of an ISA standard which provides guidance on the management of Independent Protection Layers - Low Integrity Protection Layers: ANSI/ISA-84.91.03-2025 Explained. This is an interesting subject as IPL's are an essential aspect when working out the target RRF of a SIF, however they are often forgotten about once the plant goes back into operation. Some sites do manage the maintenance of IPL's differently to non-safety loops, via a maintained IPL register, IPL validation and more stringent testing routines. However this is not always the case and a lot of the time IPL's just fall into the normal maintenance system as this article suggests. Would be interesting to hear from the group your thoughts on this subject .....
1 like • Jun 2
I agree with Anth. A banefit of your proposal is very minimal. Look at the failure rate of safety PLC in comparison to other elements - it's a very small part of overall system PFDavg. So you should aim at improving other parts rather the best one.
1-10 of 22
Tomasz Barnert
3
34 points to level up
@tomasz-barnert-4011
Head of process & functional safety department, CFSE, PhD

Online now
Joined Mar 11, 2026
Gdańsk