Functional Safety Assessment across the safety lifecycle
An evidence-based investigation and judgement of the functional safety achieved by one or more safety instrumented systems and/or other protection layers.
Functional safety must be assessed by competent personnel with the required independence before hazards are introduced to the process—and IEC 61511 carries the obligation into operation and relevant modification.
Contents Jump to a section
An FSA Tests Whether Lifecycle Evidence Supports The Functional Safety Claimed.
IEC 61511-1:2016 defines Functional Safety Assessment as an evidence-based investigation and judgement of the functional safety achieved by one or more SIS and/or other protection layers. Clauses 5.2.6.1.1–5.2.6.1.10 directly govern the assessment procedure, team, planning, information, independence, findings and lifecycle timing.
The FSA reviews the work completed up to the selected stage, including earlier conclusions and actions. Verification, validation, audit, testing, interviews and inspection may all provide evidence; none alone replaces the assessment judgement.
Confirmation that the outputs of a lifecycle phase satisfy its stated inputs, requirements and engineering performance criteria, using reports, checklists, reviews, analysis or recorded tests.
Confirmation that the installed and commissioned SIFs and SIS meet the Safety Requirements Specification in all respects.
A systematic and independent examination of whether functional-safety procedures comply with planned arrangements and are implemented effectively.
An evidence-based investigation that judges whether functional safety and safety integrity have been achieved for the agreed SIS/SIF scope.
A design can be correct and still receive an FSA finding because the record of how it was developed is incomplete, inconsistent between disciplines, or held in documents without a controlled number, revision or date. IEC 61511 requires one or more FSAs before hazards are introduced, periodic assessment during operation and maintenance, and assessment of relevant modifications before work begins. Stage 3 is the mandatory pre-hazard assessment; when it is the only pre-startup FSA, its scope must also address the Stage 1 and Stage 2 work already completed, making the assessment broader and typically longer.
Gate-Pass?
Why Assess Early?
Potential Outcomes And Final Report Coverage
Each assessor applies a defined procedure, stage-specific checklist and reporting method. Terminology varies; a practical reporting structure may distinguish the following requirement-level outcomes.
Positive / Pass
The requirement is satisfied directly or through an accepted, justified alternative.
Partial Compliance
The basis is substantially present, but completion, clarification or improvement is recommended.
Action Required
A material gap or negative finding requires documented resolution at the defined lifecycle stage.
Not Applicable
The requirement does not apply to the agreed project, lifecycle stage or assessment boundary.
Final report coverage. Purpose, assessment stage and boundary; team competence and independence; applicable requirements and evidence reviewed; compliance arguments and finding status; recommendations, action ownership and timing; overall conclusion, limitations, closeout evidence and the strategy for further assessments.
Collect Evidence Through 5 Lifecycle Stages
IEC 61511 identifies five useful stages for FSA activity from hazard analysis through design, pre-startup readiness, operation and change. Select a stage to see its timing and purpose; open the supporting rows for evidence, interactions, typical challenges and DSIB involvement.
Confirm that the project has a robust technical and management foundation before detailed SIS design proceeds.
Stage 1 examines whether hazards, required risk reduction, allocated protection layers and SIF requirements form a complete and traceable design basis. The Process SRS is the principal transfer point from analysis into design.
Evidence for FSA
Functional Safety Management Plan and lifecycle plan; competence, verification and audit arrangements; HAZOP/H&RA and LOPA or SIL target-selection study; recommendation closeout; SIF register and conceptual configuration; Process SRS; interdisciplinary work split; project quality, change, configuration and document-control procedures.
Interactions
The HAZOP/LOPA team defines the hazardous event, initiating causes, risk reduction and protection-layer assumptions. Process engineering converts these into safe state, trip points, response time, output action and operating-mode requirements. I&C challenges implementability and prepares the route into detailed design. The owner supplies risk criteria, proof-test, repair, bypass, operating and maintenance decisions. The FSM lead reconciles the interfaces and prevents unresolved assumptions from being passed downstream as design facts.
Typical Challenges
- The SIF need, boundary or successful action is unclear, or HAZOP/LOPA actions remain open.
- Schedule pressure advances detailed design while SIF definitions, process safety time, demand assumptions or response to detected faults are unresolved.
- Owner SIL-selection criteria and the project target-selection study point to different outcomes after design has progressed.
- H&RA, allocation records, P&IDs and Process SRS do not carry one consistent SIF definition.
- Without an active Functional Safety Management Plan and FSM leadership, systematic errors and avoidable findings accumulate across disciplines.
How DSIB Involves
DSIB can strengthen the lifecycle basis or assess it independently. The two scopes are contracted separately and the required assessor independence is maintained.
Confirm traceability from the SRS into hardware, application program, SIL verification and planned testing.
Stage 2 reviews detailed SIS design and engineering, including systematic capability, random hardware integrity and application-program development. Published FSA2 guidance treats project evidence through FAT as part of this stage; the assessment plan states the actual design and test evidence available at the selected timing.
Evidence for FSA
Controlled Process SRS issued for review and Design SRS at final issue; P&IDs and cause-and-effect; SIF architecture and conceptual configurations; configuration and SIF-element change log; application-program requirements and logic; SIL verification; device identification, datasheets, certificates, safety manuals, reliability data and prior-use justification; loop, wiring and interface drawings; design-verification records; FAT plan, procedures, results and punch closeout; SAT and validation plans.
Interactions
Process engineering protects the functional intent. I&C and the SIS integrator implement voting, diagnostics, bypasses, alarms, resets, logic and interfaces. Mechanical, piping and electrical teams confirm final-element and ancillary-device arrangements. Procurement and vendors provide equipment-specific failure data, certificates, safety manuals and package boundaries. The owner confirms proof-test intervals, repair time, bypass arrangements, testing infrastructure, construction constraints and spurious-trip targets. Document control keeps the combined design basis reviewable.
Typical Challenges
- Changes to a SIF element do not propagate through the SRS, parametric SIL verification, configuration records, drawings and vendor constraints.
- Late owner preferences on proof testing, bypasses, repair time, testing infrastructure, construction or spurious-trip targets alter an advanced design.
- SIS-specific verification is treated as another discipline’s task; conceptual configurations then conflict with loop, wiring or cause-and-effect documents.
- Amplifiers, barriers, MCC contactors, relays and package PLCs disappear from the SIF boundary, or different logic-solver failure-data boundaries are used.
- Revamp projects retain uncertain existing final elements or panels, including equipment without suitable certification, safety manuals or reliability evidence.
- Vendor packages and interfaces arrive with incomplete reliability diagrams or unrecorded SIF transfers caused by communication limitations.
- Late package procurement delays SIL verification, Design SRS finalisation and FAT-ready evidence.
How DSIB Involves
DSIB can prepare the design evidence for review or perform the independent Stage 2 judgement.
Confirm that the installed SIS meets the SRS and that operations and maintenance can accept the system.
Stage 3 follows installation, pre-commissioning and final validation, after the necessary operating and maintenance procedures have been developed. IEC 61511 requires the relevant assessment before hazards are present.
Evidence for FSA
Updated SRS and as-built design; installation, inspection and pre-commissioning records; FAT punch-list closeout; SAT/SIT and validation plans and results; calibration and functional-test records; approved configuration; proof-test, operating, maintenance, bypass and emergency procedures; training and handover dossier; safety-critical equipment records; status of prior FSA actions and relevant PSSR checklist outputs.
Interactions
Construction and commissioning teams establish what was installed and tested. The SIS integrator and package vendors supply configuration, interface and test evidence. Process, I&C, mechanical and electrical disciplines resolve deviations. Owner operations, maintenance and safety teams confirm procedures, staffing, competence, spares, testability and handover readiness. Stage 3 should be coordinated with the PSSR; PSSR outputs and checklist closure can provide supporting evidence without replacing the FSA.
Typical Challenges
- Pre-commissioning or commissioning records are treated as validation without demonstrating every applicable SRS requirement.
- FAT changes, site modifications, temporary configurations and punch items are not traced into the as-built basis.
- Package-vendor and site tests do not demonstrate integrated SIF action across every interface.
- Proof-test and bypass procedures do not reflect the installed arrangement or safety-manual limits.
- Operations and maintenance training, asset records, performance-data collection and action closeout are incomplete at handover.
How DSIB Involves
The focus shifts from design intent to installed evidence and operating readiness.
Confirm that operating evidence still supports the design assumptions and required safety integrity.
Stage 4 uses installed performance and the owner’s automation asset integrity arrangements to judge whether functional safety is being maintained in operation.
Evidence for FSA
Demand, trip, failure and repair records; proof-test schedules, methods, coverage and as-found/as-left results; calibration, inspection and work orders; bypass and deferral logs; alarm, incident and performance analysis; operating-limit and KPI reports; configuration, competence and safety-critical equipment records; audits, H&RA reviews and management-of-change records.
Interactions
Operations records demands, bypasses and operating context. Maintenance records testing, failures, repair and restoration. Automation and reliability teams analyse repeated failures, overdue work, test effectiveness and useful life. Process safety compares actual demand and performance with the original risk model. Management of change protects the approved configuration, procedures and SIL-verification assumptions.
Typical Challenges
- Proof tests record completion but not the as-found condition, achieved coverage or detected dangerous failures.
- Demand rate, repair time, bypass duration and spurious trips are not compared with SIL-verification assumptions.
- Repeated failures, operating-limit excursions and overdue tasks are managed as work orders rather than functional-safety performance signals.
- Equipment revisions, useful-life limits, temporary changes and configuration updates are not linked back to the SIF record.
- Performance data exists in separate systems but is not translated into periodic review, trends, corrective action and retained evidence.
How DSIB Involves
DSIB connects operational data, procedures and lifecycle assumptions.
Confirm that change has been analysed, authorised, implemented, verified and revalidated.
Stage 5 revisits the affected parts of Stages 1, 2 and 3. For larger changes, assessment activities can be staged before site work, during design and after revalidation.
Evidence for FSA
Approved change request and impact analysis; updated H&RA, allocation and SRS; revised hardware and application-program design; SIL verification; test, installation and validation records; configuration and authorisation records; updated procedures and training; decommissioning plan and retained-protection arrangements.
Interactions
The owner’s MOC authority defines and authorises the change. Process safety identifies affected hazards and protection layers. Engineering and the SIS integrator revise the design and software. Operations and maintenance control temporary states, testability and procedures. Decommissioning teams preserve any function still required while equipment is removed.
Typical Challenges
- The impact analysis treats the changed tag but not the full SIF, shared equipment or other protection layers.
- Temporary bypasses and transition hazards during site work are not included in the change plan.
- Application-program revisions are tested without updating the SRS, SIL verification or proof-test procedure.
- Safety-critical equipment records, operating limits, maintenance tasks and training are not updated before handover.
- Revalidation is narrowed without a documented risk basis or retained evidence.
How DSIB Involves
DSIB scales the work to the size and risk of the modification.
Seamless Lifecycle Data, Integrated Engineering And Traceable Project Controls.
DSIB does not mandate use of a specific tool either in engineering design, QA/QC or engineering management processes. An integrated lifecycle platform or a controlled set of equivalent tools can be used, provided that inputs, changes, checks and outputs remain traceable.
exSILentia® Or An Equivalent Environment
An integrated platform supports the controlled flow of information and engineering outputs from hazard-analysis inputs and SIL target selection through the Process SRS, SIL verification and Design SRS, reducing independent re-entry between lifecycle activities. Its equipment-reliability handbook provides a broad dataset covering sensors, logic solvers, interfaces and final elements. Values assigned to individual SIF elements remain traceable, can be compared with purchased vendor packages and allow the SIL-calculation basis to be supplied promptly as assessment evidence.
Registers, Matrices And Controlled Documents
Project-control arrangements vary between engineering organisations. Some requirements may be covered through general engineering practice or Safety-Critical Element Integrity Verification procedures. Within an FSM programme, dedicated documentation can include a SIF register, conceptual-configuration sheets, SRS responsibility matrix, IEC 61508 compliance register, certificate and safety-manual index, interface and RFI register, change logs, document/evidence index and action tracker. These records make design status, cross-discipline communication and assessment readiness visible between formal deliverables.
Readiness And Independent Assessment Serve Different Purposes.
Readiness Consultancy builds the controlled lifecycle evidence and engineering process before assessment. Independent FSA reviews that evidence and issues the judgement. DSIB does not combine the two roles within the same scope where independence would be compromised.
Readiness Consultancy
DSIB works with the project or operating organisation before the formal assessment. The scope can be a focused evidence review or an extended FSM and lifecycle-integration assignment.
See The Whole Scope
- Functional Safety Management Plan preparation and day-to-day FSM leadership
- Stage-specific readiness plan, evidence index and internal pre-assessment
- Engineering verification steps, procedures and discipline checklists
- Interdisciplinary SRS work split, design interfaces and consistency checks
- Collection and review of compliance, certification and reliability data
- Validation strategy, procedures, checklists and SRS-to-test traceability
- Review of RFIs, action registers, configuration changes and MOC logs
- Training, assessor package, technical responses and closeout coordination
Independent Functional Safety Assessment
DSIB appoints a competent assessment team with the independence required by IEC 61511 and issues the documented judgement for the agreed stage and boundary.
See The Whole Scope
- Assessment plan, checklist, scope, participants and information request
- Evidence review, interviews and technical clarification
- Requirement-by-requirement compliance arguments
- Finding classification, recommendations and action ownership
- Overall conclusion and strategy for further FSAs
- Closeout review against submitted resolution evidence
Preparing An EPC Engineering Team For An Independent FSA On A Major Refinery Revamp.
DSIB principals served within the functional-safety management structure of a Türkiye-based engineering contractor on a long-duration EPC project, taking responsibility for readiness through the external FSA1–2. The assessment itself was performed by EXIDA. The project, owner, EPC parties, site and technical identifiers remain anonymous.
Engineering processes were aligned to the IEC 61511 lifecycle and to the evidence needed to demonstrate compliance. Process, risk, I&C and design teams were trained in the selected tools and in the expected detail of their outputs.
In parallel, the project Functional Safety Management Plan, internal procedures and engineering work splits were established and led through the FSM role.
Project planning, procedures, work splits, competence and internal pre-assessments.
HAZOP/LOPA feedback, Process SRS, Design SRS, SIL verification and design checks.
Owner inputs, vendor evidence, existing systems, package boundaries and RFIs.
Readiness package, clarification, revision control, response and final-report support.
The five items were resolvable through evidence and controlled engineering updates. They did not create a material cost item, major rework or project delay. More importantly, the organisation retained a sustainable and robust functional safety management practice rather than a one-time assessment file.