Occasionally, safety functions rely on components which are shared with a Basic Process Control System (BPCS) and operate outside of a demand from the SIF. Items such as power supplies, contactors, actuators, gearboxes and cabling may lie outside the formal Safety Instrumented Function (SIF) boundary but may still determine whether the safety function can deliver its action on demand. More often than not, these devices are not formally certified for use in a SIL-rated Safety Instrumented System (SIS).
This whitepaper describes a project delivered by Method Functional Safety to calculate the average Probability of Failure on Demand (PFDavg) for the sensor and logic solver aspects of a SIL-rated SIF, which depended on the availability of non-SIL-rated devices shared with the Basic Process Control System (BPCS) for delivery of the actuation subsystem.
The approach uses Fault Tree Analysis (FTA) modelling to determine PFDavg and considers deliberate normal equipment operation of shared devices as a partial proof test for critical hardware.
Fault Tree Analysis as the Core Technique
The assessment uses FTA, as specified in IEC 61025:2006, to model the SIF's failure mechanisms. The top event is defined as “SIF fails on demand”, capturing any failure of the safety function to respond when required.
The fault tree decomposes the top event into basic events representing individual component or subsystem failures. The following logic gates are used to model how combinations of failures lead to overall SIF failure:
- AND gates, where all failures must coincide
- OR gates, where any one failure is sufficient, and
- MooN (M‑out‑of‑N) gates, reflecting architectures like 1oo2 sensor voting
Each basic event is characterised by parameters such as the dangerous undetected failure rate, proof test interval, and mean time to repair, enabling the model to calculate system unavailability and PFDavg for the safety function.
Modelling Common Cause Failure
Redundant architectures were treated carefully to avoid overestimating the benefit of voting arrangements. Common-cause failures in parallel channels—such as redundant sensors or relays—were modelled using the beta‑factor method described in IEC 61508‑6:2010.
In practice, this means a proportion of each channel’s dangerous failures is allocated to a shared “common cause” event, with β values up to 10% used for sensors and actuators in line with the guidance. These dedicated CCF events are then included in the fault tree, ensuring that the PFDavg value calculated for the SIF reflects both independent and simultaneous failures.
PFDavg Calculation for the SIF devices
The devices selected for the SIS design were certified to IEC 61508. Dangerous undetected failure rates are provided for these devices within manufacturer safety manuals and SIL declarations.
With the FTA populated for the SIF devices, the modelling calculates the PFDavg for the SIF over the specified proof-test interval. This yields a quantitative risk reduction factor (RRF) that can be directly compared with the target from higher‑level risk assessments, such as LOPA.
The gap between the PFDavg for the sensor and logic subsystems of the SIF and the (LOPA) target provides the “risk budget” available for the shared, non-SIF devices required to actuate the SIF.
Shared Hardware and Partial Proof Testing
Where the modelling deviates from traditional PFDavg calculations is the treatment of hardware shared between the SIF and the BPCS.
Where specific failure‑rate data is limited, the assessment used operational history to estimate dangerous failure rates for these shared elements, often using conservative statistical methods based on observed failures (or lack of failures) over years of service. Simple annual proof tests of this hardware can lead to relatively high PFD values that may consume much of the remaining “risk budget” after the SIF devices themselves are modelled.
To address this, the technique treats routine or scheduled operation of the final element (for example, moving a valve under normal process control) as a partial proof test, as each successful movement confirms the availability of the actuation path and its associated components.
By incorporating a more frequent “operational test” interval into the FTA for shared devices, the model can determine the maximum allowable time between movements that still satisfies the overall risk-reduction requirement. This led to defining a limit on the interval between tests to exercise the final element and maintain the required PFDavg.
Sensitivity Analysis
By varying the proof-test interval for the SIF devices (for example, 3, 6, or 12 months) and architectural options (for example, changing a 2oo2 sensor design to 1oo1), this supported assessment of how design choices and maintenance strategies influence the PFDavg. This enables optimisation of the safety function while retaining sufficient margin to meet the risk reduction target.
From Analysis to Operational Requirements
The outcome of this analysis was the PFDavg for the SIF and a set of recommendations for the SIF's design and operation. These include:
- Maximum tolerable intervals between actuations of the final element to ensure shared hardware remains within its reliability budget.
- Suggestions for more detailed reliability studies (such as FMEA) where estimates of device failure rate are particularly conservative or data‑poor.
- Recommendations to develop or strengthen prior‑use justifications, or to consider SIL‑certified alternatives, for devices without formal functional safety certification.
By explicitly linking actuation frequency, device data and modelled PFDavg, the approach turns everyday operating practice into a quantifiable lever for meeting functional safety targets. It demonstrates how rigorous FTA, careful data handling and deliberate use of partial proof testing can be combined into a coherent strategy for designing, verifying and operating high‑integrity safety functions in any process or industrial context.
Talk to Jeni about Consultancy
Contact hereAbout the Author Jeni Lewthwaite

Jeni is a Chartered Engineer (MIET) and Certified Functional Safety Professional (TUV Sud) with over 14 years' experience of improving asset availability through the application of System Safety and Reliability Engineering.
Other articles by Jeni Lewthwaite
- qua. Ut enim ad minim veniam
- quis nostrud exercitation ullamco
- aliquip ex ea commodo consequ
