© Design Safety Intelligence Bureau. All rights reserved. Printing or copying of this page is not permitted.
SOLUTION SERIES.DSIB

Functional Safety Assessment across the safety lifecycle

An evidence-based investigation and judgement of the functional safety achieved by one or more safety instrumented systems and/or other protection layers.

Non-Negotiable

Functional safety must be assessed by competent personnel with the required independence before hazards are introduced to the process—and IEC 61511 carries the obligation into operation and relevant modification.

Contents Jump to a section
Definition

An FSA Tests Whether Lifecycle Evidence Supports The Functional Safety Claimed.

IEC 61511-1:2016 defines Functional Safety Assessment as an evidence-based investigation and judgement of the functional safety achieved by one or more SIS and/or other protection layers. Clauses 5.2.6.1.1–5.2.6.1.10 directly govern the assessment procedure, team, planning, information, independence, findings and lifecycle timing.

The FSA reviews the work completed up to the selected stage, including earlier conclusions and actions. Verification, validation, audit, testing, interviews and inspection may all provide evidence; none alone replaces the assessment judgement.

Verification

Confirmation that the outputs of a lifecycle phase satisfy its stated inputs, requirements and engineering performance criteria, using reports, checklists, reviews, analysis or recorded tests.

Confirming through the SIL verification report that the integrity and functional requirements stated in the Process SRS are achieved, and checking that the target design has been transferred into the Design SRS.
Validation

Confirmation that the installed and commissioned SIFs and SIS meet the Safety Requirements Specification in all respects.

Executing traceable tests for trips, timing, modes, resets, bypasses, diagnostics and final actions.
Functional Safety Audit

A systematic and independent examination of whether functional-safety procedures comply with planned arrangements and are implemented effectively.

Sampling whether competence, document control, verification and change procedures are being followed.
Functional Safety Assessment

An evidence-based investigation that judges whether functional safety and safety integrity have been achieved for the agreed SIS/SIF scope.

A competent independent team reviews evidence, interviews disciplines and issues findings and an overall conclusion.
Assessment Basis

A design can be correct and still receive an FSA finding because the record of how it was developed is incomplete, inconsistent between disciplines, or held in documents without a controlled number, revision or date. IEC 61511 requires one or more FSAs before hazards are introduced, periodic assessment during operation and maintenance, and assessment of relevant modifications before work begins. Stage 3 is the mandatory pre-hazard assessment; when it is the only pre-startup FSA, its scope must also address the Stage 1 and Stage 2 work already completed, making the assessment broader and typically longer.

Gate-Pass?
IEC 61511 does not define FSA as a generic pass/fail gate. An owner, contract or project governance system may use its conclusion as an input to authorisation.
Why Assess Early?
Contractual assurance, independent challenge, engineering quality management and early correction can justify FSA1 or FSA2 before the final pre-startup judgement.

Potential Outcomes And Final Report Coverage

Each assessor applies a defined procedure, stage-specific checklist and reporting method. Terminology varies; a practical reporting structure may distinguish the following requirement-level outcomes.

Positive / Pass

The requirement is satisfied directly or through an accepted, justified alternative.

Partial Compliance

The basis is substantially present, but completion, clarification or improvement is recommended.

Action Required

A material gap or negative finding requires documented resolution at the defined lifecycle stage.

Not Applicable

The requirement does not apply to the agreed project, lifecycle stage or assessment boundary.

Final report coverage. Purpose, assessment stage and boundary; team competence and independence; applicable requirements and evidence reviewed; compliance arguments and finding status; recommendations, action ownership and timing; overall conclusion, limitations, closeout evidence and the strategy for further assessments.

Lifecycle

Collect Evidence Through 5 Lifecycle Stages

IEC 61511 identifies five useful stages for FSA activity from hazard analysis through design, pre-startup readiness, operation and change. Select a stage to see its timing and purpose; open the supporting rows for evidence, interactions, typical challenges and DSIB involvement.

FSA 01
After H&RA, protection-layer allocation and SRS development

Confirm that the project has a robust technical and management foundation before detailed SIS design proceeds.

Stage 1 examines whether hazards, required risk reduction, allocated protection layers and SIF requirements form a complete and traceable design basis. The Process SRS is the principal transfer point from analysis into design.

Evidence for FSA

Functional Safety Management Plan and lifecycle plan; competence, verification and audit arrangements; HAZOP/H&RA and LOPA or SIL target-selection study; recommendation closeout; SIF register and conceptual configuration; Process SRS; interdisciplinary work split; project quality, change, configuration and document-control procedures.

Interactions

The HAZOP/LOPA team defines the hazardous event, initiating causes, risk reduction and protection-layer assumptions. Process engineering converts these into safe state, trip points, response time, output action and operating-mode requirements. I&C challenges implementability and prepares the route into detailed design. The owner supplies risk criteria, proof-test, repair, bypass, operating and maintenance decisions. The FSM lead reconciles the interfaces and prevents unresolved assumptions from being passed downstream as design facts.

Typical Challenges
  • The SIF need, boundary or successful action is unclear, or HAZOP/LOPA actions remain open.
  • Schedule pressure advances detailed design while SIF definitions, process safety time, demand assumptions or response to detected faults are unresolved.
  • Owner SIL-selection criteria and the project target-selection study point to different outcomes after design has progressed.
  • H&RA, allocation records, P&IDs and Process SRS do not carry one consistent SIF definition.
  • Without an active Functional Safety Management Plan and FSM leadership, systematic errors and avoidable findings accumulate across disciplines.
How DSIB Involves

DSIB can strengthen the lifecycle basis or assess it independently. The two scopes are contracted separately and the required assessor independence is maintained.

Readiness ConsultancyFunctional Safety Management Plan preparation and leadership, clause-based H&RA/SRS review, SRS work split, verification procedures and checklists, competence development, recommendation closeout and resolution of missing SIF requirements.
Independent AssessmentStage 1 plan, evidence review, discipline interviews, compliance judgement, recommendations and documented action register.
Tools

Seamless Lifecycle Data, Integrated Engineering And Traceable Project Controls.

DSIB does not mandate use of a specific tool either in engineering design, QA/QC or engineering management processes. An integrated lifecycle platform or a controlled set of equivalent tools can be used, provided that inputs, changes, checks and outputs remain traceable.

Integrated Lifecycle Platform

exSILentia® Or An Equivalent Environment

An integrated platform supports the controlled flow of information and engineering outputs from hazard-analysis inputs and SIL target selection through the Process SRS, SIL verification and Design SRS, reducing independent re-entry between lifecycle activities. Its equipment-reliability handbook provides a broad dataset covering sensors, logic solvers, interfaces and final elements. Values assigned to individual SIF elements remain traceable, can be compared with purchased vendor packages and allow the SIL-calculation basis to be supplied promptly as assessment evidence.

Project Controls

Registers, Matrices And Controlled Documents

Project-control arrangements vary between engineering organisations. Some requirements may be covered through general engineering practice or Safety-Critical Element Integrity Verification procedures. Within an FSM programme, dedicated documentation can include a SIF register, conceptual-configuration sheets, SRS responsibility matrix, IEC 61508 compliance register, certificate and safety-manual index, interface and RFI register, change logs, document/evidence index and action tracker. These records make design status, cross-discipline communication and assessment readiness visible between formal deliverables.

DSIB Solution Model

Readiness And Independent Assessment Serve Different Purposes.

Readiness Consultancy builds the controlled lifecycle evidence and engineering process before assessment. Independent FSA reviews that evidence and issues the judgement. DSIB does not combine the two roles within the same scope where independence would be compromised.

Solution 01

Readiness Consultancy

DSIB works with the project or operating organisation before the formal assessment. The scope can be a focused evidence review or an extended FSM and lifecycle-integration assignment.

See The Whole Scope
  • Functional Safety Management Plan preparation and day-to-day FSM leadership
  • Stage-specific readiness plan, evidence index and internal pre-assessment
  • Engineering verification steps, procedures and discipline checklists
  • Interdisciplinary SRS work split, design interfaces and consistency checks
  • Collection and review of compliance, certification and reliability data
  • Validation strategy, procedures, checklists and SRS-to-test traceability
  • Review of RFIs, action registers, configuration changes and MOC logs
  • Training, assessor package, technical responses and closeout coordination
Solution 02

Independent Functional Safety Assessment

DSIB appoints a competent assessment team with the independence required by IEC 61511 and issues the documented judgement for the agreed stage and boundary.

See The Whole Scope
  • Assessment plan, checklist, scope, participants and information request
  • Evidence review, interviews and technical clarification
  • Requirement-by-requirement compliance arguments
  • Finding classification, recommendations and action ownership
  • Overall conclusion and strategy for further FSAs
  • Closeout review against submitted resolution evidence
For an Independent FSA, DSIB issues the assessment plan and information request in advance. Transparency of scope and evidence requirements does not alter the independence of the judgement.
CASE / FSA1+2
Case Study

Preparing An EPC Engineering Team For An Independent FSA On A Major Refinery Revamp.

Process facility at night
Representative, non-identifying image · Supplied for unrestricted use

DSIB principals served within the functional-safety management structure of a Türkiye-based engineering contractor on a long-duration EPC project, taking responsibility for readiness through the external FSA1–2. The assessment itself was performed by EXIDA. The project, owner, EPC parties, site and technical identifiers remain anonymous.

Engineering processes were aligned to the IEC 61511 lifecycle and to the evidence needed to demonstrate compliance. Process, risk, I&C and design teams were trained in the selected tools and in the expected detail of their outputs.

In parallel, the project Functional Safety Management Plan, internal procedures and engineering work splits were established and led through the FSM role.

Scope Of Involvement
01Lifecycle Alignment

Project planning, procedures, work splits, competence and internal pre-assessments.

02Engineering Integration

HAZOP/LOPA feedback, Process SRS, Design SRS, SIL verification and design checks.

03External Interfaces

Owner inputs, vendor evidence, existing systems, package boundaries and RFIs.

04Assessment Coordination

Readiness package, clarification, revision control, response and final-report support.

Result5Minor Action Items After A Broad FSA1–2 Review
1Supporting evidence for generic data used at one step in the logic-solver calculations.
1Site-application evidence for one SIF.
2Parametric revisions to SIL verification for two SIFs.
1Completion of missing wiring diagrams.

The five items were resolvable through evidence and controlled engineering updates. They did not create a material cost item, major rework or project delay. More importantly, the organisation retained a sustainable and robust functional safety management practice rather than a one-time assessment file.

Why it succeededEarly lifecycle involvement, visible FSM ownership, trained discipline leads, seamless SIF information flow, transparent owner/vendor interfaces and internal pre-assessments before the external review.
What it demonstratesAssessment readiness is an engineering-management outcome. When started before FAT, most corrections remain design decisions and desktop reworks rather than construction changes.
ConfidentialityThis case is silent on all project, client, contractor, site, document, tag, design-value and correspondence identifiers. The description is limited to the verified scope, working methods and anonymised outcome categories.