What Is a Safety Integrity Level (SIL)? How to Calculate and Apply It

Chapters

Chapter 11: What Is a Safety Integrity Level (SIL)? How to Calculate and Apply It

Chapters

What Is a Safety Integrity Level (SIL)? How to Calculate and Apply It

A Hazard and Operability Study (HAZOP) identifies an overpressure scenario on a reactor vessel, and the team assigns a Safety Instrumented Function (SIF) to handle it. Six months later, during a Functional Safety Assessment (FSA), the assessor asks for the traceable chain from that hazard through the Safety Integrity Level (SIL) target, the Safety Requirements Specification (SRS), the SIL verification calculation, and the proof test procedure validating the assumptions. If any link is missing, the compliance case unravels.

For systems engineers, quality leads, and compliance officers under IEC 61508 or its derivatives, SIL is the metric that assessors most often challenge. This guide covers what SIL means, how to calculate and allocate it, how to apply it throughout the lifecycle, and where compliance most often breaks down.

What Is a Safety Integrity Level (SIL)?

A Safety Integrity Level(SIL) is one of four discrete levels that specify the safety integrity requirements of safety functions allocated to electrical, electronic, and programmable electronic (E/E/PE) safety-related systems. Each level corresponds to an order-of-magnitude band of risk reduction that the safety function must achieve.

SIL Applies to Safety Functions, Not Individual Components

IEC 61508 assigns SIL to a safety function, not to a sensor, logic solver, or valve. A SIF is the specific functionality identified through hazard analysis to prevent or mitigate a hazardous event. That function is implemented by a Safety Instrumented System (SIS) comprising sensors, logic solvers, and final elements that work together.

Installing SIL-certified components doesn’t make a SIL-rated loop. The SIF’s SIL depends on the aggregate failure probability across subsystems, the voting architecture, the proof test interval, and the design-process capability. Component-level certificates are inputs to that calculation, not substitutes for it.

The Four SIL Levels and Their Risk Reduction Factors

In low-demand mode, where the safety function is demanded less than once per year, SIL targets are expressed as Average Probability of Failure on Demand (PFDavg), with the Risk Reduction Factor (RRF) as its inverse. 

Safety Integrity Level PFDavg Range Risk Reduction Factor
SIL 1 ≥ 10⁻² to < 10⁻¹ > 10 to ≤ 100
SIL 2 ≥ 10⁻³ to < 10⁻² > 100 to ≤ 1,000
SIL 3 ≥ 10⁻⁴ to < 10⁻³ > 1,000 to ≤ 10,000
SIL 4 ≥ 10⁻⁵ to < 10⁻⁴ > 10,000 to ≤ 100,000

In high-demand or continuous mode, performance targets are expressed as Probability of Dangerous Failure per Hour (PFH). Each SIL band spans one order of magnitude from SIL 1 down to SIL 4.

How SIL Fits Within the Functional Safety Framework

IEC 61508 is the parent standard for functional safety of E/E/PE safety-related systems. Its framework rests on a safety lifecycle that reduces design-process errors through structured engineering, paired with probabilistic failure performance quantified through SIL. Industry-specific standards, derived from IEC 61508, address sector-specific conditions.

IEC 61508 and Its Industry-Specific Derivatives (IEC 61511, ISO 26262, IEC 62061)

The most industry-specific standard takes precedence. IEC 61508 applies directly where no sector standard exists, with three derivatives covering the most common engineering domains:

  • IEC 61511 (process industries): Governs SIS design, installation, operation, and maintenance in oil, gas, chemical, and pharmaceutical sectors. Component certification remains governed by IEC 61508, and SIL 4 applications must refer to it.
  • ISO 26262 (automotive): Uses Automotive Safety Integrity Levels (ASIL A through D) determined qualitatively through Severity, Exposure, and Controllability parameters. No normative mapping exists between SIL and ASIL.
  • IEC 62061 (machinery): Covers safety-related control systems for machinery, limited to SIL 1 through 3. Uses PFH as the governing metric because machinery operates in high-demand or continuous mode.

The application’s demand mode and consequence severity determine which derivative applies and which metrics govern verification.

Safety Instrumented Functions (SIFs) and Safety Instrumented Systems (SISs)

A single SIS may contain multiple SIFs, each with its own SIL target. The SIS is the physical system. The SIF is the individual safety loop within it, and the SIL is the performance requirement assigned to that loop. SIL compliance is verified at the SIF level, not at the SIS or component level.

How to Calculate Safety Integrity Level

SIL verification requires passing three independent barriers simultaneously, and the achieved SIL equals the lowest of the three evaluations.

Probability of Failure on Demand (PFD) and Risk Reduction Factor (RRF)

PFDavg is the primary quantitative metric for low-demand SIFs, representing the average failure-on-demand probability across all subsystems in the loop. IEC 61508 maps SIL bands in low-demand mode directly to PFDavg ranges, rather than explicitly defining RRF as 1/PFDavg.

In a worked example, a sensor subsystem at 1.3 × 10⁻², a logic subsystem at 1.5 × 10⁻⁴, and a final element at 1.1 × 10⁻² produce a system PFDavg of 2.415 × 10⁻². That yields an RRF of approximately 41, which falls within the SIL 1 band.

Low, High, and Continuous Demand Modes

The demand mode determines which probabilistic metric applies to the SIF. Low-demand mode, with a demand interval greater than twice the proof test interval, uses PFDavg. High-demand mode, in which the safety function is demanded more than once per year, and continuous mode both use PFH. Misclassifying the demand mode assigns the wrong metric to the SIF, which invalidates the entire verification.

Hardware Versus Systematic Safety Integrity

The second barrier addresses architectural constraints through Safe Failure Fraction (SFF) and Hardware Fault Tolerance (HFT). Type A components (with well-defined failure modes) and Type B components (with more complex behavior) are subject to different hardware architectural constraints under IEC 61508.

The third barrier addresses design errors, software bugs, and specification faults that can’t be characterized by failure rates and remain invisible to PFDavg calculations. Two independent paths can establish that a component meets the systematic capability requirement:

  • IEC 61508 certification: Assessment by an accredited body confirms the component meets the standard’s requirements for use at a stated level.
  • Prior-use justification: Documented operational history shows the component has performed reliably in a comparable application and environment.

A technically accurate PFDavg alone doesn’t constitute a complete demonstration of compliance.

How to Allocate SIL Requirements Through Risk Assessment

SIL allocation follows a logical sequence in which the team identifies the process risk, establishes tolerable risk, calculates the gap, credits other independent protection layers, and determines the remaining risk reduction the SIF must provide.

Hazard Analysis Methods: HAZOP, LOPA, and Risk Graph

HAZOP identifies hazards but does not assign a SIL target on its own. Layer of Protection Analysis (LOPA) is a semi-quantitative method that uses numerical initiating-event frequencies and protection-layer PFD values. The Risk Graph method, IEC 61508 Part 5 Annex D, is qualitative, combining consequence severity, exposure frequency, avoidance probability, and demand rate into a SIL recommendation.

In LOPA, each Independent Protection Layer (IPL) must be specific to the hazard, independent of the initiating event and other IPLs, and capable of at least one order of magnitude of risk reduction. The mitigated event frequency is compared against the tolerable risk target, and the remaining gap defines the required SIL.

Setting Tolerable Risk and Choosing the Right SIL Target

Tolerable risk is typically expressed as a target event frequency, with severe-consequence events targeting frequencies several orders of magnitude lower than the default threshold. For Risk Graph methods, category boundaries must be calibrated and agreed upon at the senior team level before use.

SIL Application Across the Safety Lifecycle

IEC 61508 structures functional safety across the full lifecycle, with SIL obligations appearing at every phase and not only during initial design.

SIL in Design, Specification, and Verification

The SRS must link each SIF’s functional and integrity requirements to the hazard analysis. Verification activities include Factory Acceptance Tests against the SRS and Site Acceptance Tests using the proof test procedures planned for operation.

SIL Through Operation, Proof Testing, and Maintenance

Periodic proof testing detects dangerous hidden failures that escape online diagnostics. The proof test interval directly determines PFDavg, so doubling the interval can push a SIF below its target SIL. Results must feed back into reliability calculations. If observed failure rates differ from those assumed in verification, the original data and device selection require reappraisal.

Modification of a SIF requires returning to an appropriate earlier phase of the safety lifecycle based on impact analysis, including reassessment of SIL requirements and re-verification as needed.

Common Mistakes That Undermine Safety Integrity Level Compliance

Three patterns account for most documented gaps in SIL compliance in functional safety assessments across industries.

Treating SIL as a Component Property

A team specifies a “SIL 2 transmitter,” a “SIL 2 logic solver,” and a “SIL 2 valve,” then treats the assembly as a SIL 2 SIF. What components actually receive through assessment is a SIL Capability rating, not a SIL rating. The full loop-level PFDavg calculation, architectural constraint verification, and capability assessment must still be completed before a SIF can claim any SIL.

Over-Specifying SIL Instead of Eliminating the Hazard at the Source

In one documented case, a Hazard Identification (HAZID) study identified overheating scenarios that required SIL-rated protection for a reactor vessel. Subsequent analysis showed heating was unnecessary for the product, eliminating the initiating events. Inherently safer design principles (eliminate, substitute, moderate, simplify) should be applied and documented before LOPA or SIL assignment.

Losing Traceability Between Hazards, Requirements, and Verification Evidence

The normative traceability chain runs from the identified hazard through the safety requirement through the safety function, through the safety-related system. Breaks in that chain, such as a SIL target assigned but SRS not updated, or proof test procedures that don’t match SIL verification assumptions, disconnect the compliance evidence. Under IEC 61511-2, the availability of sufficient current evidence is an assessment criterion in its own right.

How Jama Connect® Supports Safety Integrity Level Workflows

Maintaining the evidence chain across hazards, requirements, verification, and proof testing can break down when teams manage those artifacts in separate tools. Jama Connect® keeps safety requirements, hardware artifacts, software items, and verification evidence connected through Live Traceability™. When a safety requirement changes, downstream items are automatically flagged as suspect, prompting owners to assess, update, or clear the flag before gaps reach the assessment stage. The same mechanism reveals how modifications affect linked work through change propagation.

Jama Connect maintains connections from hazard analysis through SRS, SIL verification reports, validation records, and proof test procedures, giving teams managing SIFs across multiple lifecycle phases a current, auditable record instead of a last-minute reconstruction before assessment.

Keep SIL Evidence Aligned Over Time

SIL compliance hinges on preserving the evidence chain as assumptions, tests, and operating conditions change well beyond the initial calculation. Teams that keep hazard analysis, safety requirements, verification results, and operational proof aligned are better positioned to defend the safety case during assessment.

If you’re working to keep that chain current across hazards, requirements, verification, and proof testing, you can start a 30-day free trial of Jama Connect to see how it holds the safety case together over time.

Frequently Asked Questions About Safety Integrity Level

What is the difference between SIL and ASIL?

SIL levels 1 through 4 are defined by IEC 61508 and determined by quantitative risk targets, such as PFDavg or PFH. ASIL levels A through D, plus Quality Management (QM), are defined in ISO 26262 for automotive applications and are determined qualitatively using Severity, Exposure, and Controllability parameters. No normative mapping or conversion table exists between the two systems.

How do you calculate the SIL of a safety instrumented function?

The first step is determining the demand mode, which selects the metric: low demand uses PFDavg, while high or continuous demand uses PFH. The next step sums the dangerous failure rate contributions from each subsystem (sensor, logic solver, and final element) and maps the result to the SIL band tables. That calculation addresses only one of three required barriers. The architectural constraint barrier (SFF and HFT) and the capability barrier must also be satisfied independently, and the achieved SIL equals the lowest of all three.

Can an individual product have a SIL rating?

No, individual components cannot carry a SIL rating directly, but they may undergo a functional safety assessment under IEC 61508. That assessment confirms that their design and design process meet the requirements of IEC 61508 for use at a stated level. The end user must still verify that the complete SIF achieves the required SIL through full loop-level calculation and architectural verification.

How often should SIL verification be reviewed during operation?

IEC 61511 Edition 2 requires periodic functional safety assessment during operation, but does not prescribe a fixed numerical interval. The owner/operator determines the period based on SIF risk level, operating experience, and process changes. Beyond periodic review, specific triggers require immediate reassessment. These include any modification to a SIF element, changes in process conditions that alter demand rates or consequence severity, and proof test results revealing failure rates different from those assumed in the SIL verification.

This article was authored by Mario Maldari and published August 10, 2026.

Book a Demo

See Jama Connect in Action!

Our Jama Connect experts are ready to guide you through a personalized demo, answer your questions, and show you how Jama Connect can help you identify risks, improve cross-team collaboration, and drive faster time to market.