Maintaining SIS Integrity from Owner Acceptance through Operation
For the owners and operators of the Safety Instrumented System (SIS).
A technically sound SIS can still become difficult to defend: Unreconciled field changes, thin test evidence, loosely controlled bypasses, modifications that reopen earlier assumptions. On this page you will find a confidence check for the SIS you take over, the support you can select in each lifecycle phase, and a needs list assembled automatically as a first draft of scope.
Confident in the SIS You Take Over? Assess Your Lifecycle Needs
DSIB Solution Models
See our engagement models for your functional safety management program in summary.
DSIB determines the current position and develops the governance, responsibilities, management framework, priorities and improvement program for the operating SIS.
Typical outputs- Current-state assessment and evidence-confidence view
- Functional Safety Management Program policy decisions and written plan
- Management review framework
- Readiness for formal third-party functional safety assessments or audits
- Risk-ranked improvement roadmap and investment priorities
Not scoped for execution — scoped for the intelligence that excellence in SIS integrity requires.
DSIB challenges lifecycle evidence, implementation, readiness and installed arrangements against agreed criteria — and, where competence and independence requirements are satisfied, performs the formal Functional Safety Assessment (FSA).
Typical outputs- Execution of FSA Stages 1 to 5 as an independent body
- Functional safety audits to the agreed timeline
- Independent action close-out verification
Personnel who implement work do not formally assess that same work. For a formally issued FSA, DSIB therefore takes either the implementation side or the assessment side of a given scope — never both. Functional safety audits, by contrast, can be delivered within integrated solutions.
SEE DETAILSFunctional Safety Assessment across the safety lifecycle
DSIB converts requirements and findings into working procedures, registers, forms, evidence structures, technical analyses, tracking systems and close-out arrangements — owner-side, embedded with your teams.
Typical outputs & work- Lifecycle procedure development and revision
- SIS-related SCE register and evidence index development
- Proof-test, bypass and deferral procedures; validation evidence integration
- SIL verification and SRS revisions
- Failure and demand data analysis
- Installed-base and obsolescence review; MoC involvement; remediation tracking
- Preparation of registers, checklists and management reports
- Relevant workshops
Owner-side implementation support — not detailed SIS design, application programming or maintenance execution, and never independent assessment of its own work.
Frequently Asked
Q1Can audit work be combined with advisory or engineering support?
Yes. Functional safety audits can be delivered inside an advisory or engineering engagement — as recurring health checks, gate reviews or evidence audits — with scope, personnel and reporting lines agreed so the challenge stays real.
Q2Can DSIB issue the formal FSA on work it also implemented?
No. The standard requires the FSA to be independent of the work it assesses. So for any given scope, DSIB takes either the implementation side or the assessment side — not both.
Q3What can be done before a formal FSA?
FSA pre-checklist as readiness study: The evidence expectations mapped, gaps closed, actions from earlier stages verified — so the formal assessment, whoever performs it, arrives at a prepared organization. Readiness support is an Advisory activity and is always distinct from the formal assessment itself.
Lifecycle Integrity Management
The sections below follow the lifecycle phases of IEC 61511-1 Cl. 14–18, with owner acceptance as the transition that connects the project's basis to your operating control.
The lifecycle phases below set out the needs that arise in each phase and the solutions DSIB can offer against them. Start by measuring how confident you are, as the operating team, in the SIS you are taking over. Then, in each phase, review the solutions offered under the three DSIB models and leave the ones that interest you ticked. Your needs list is assembled automatically at the end of this section.
Owner Acceptance & Handover Control
Is the SIS you are about to accept the SIS that was specified, installed and validated?
How the design basis is created and assured is the subject of Management of SIS Lifecycle During Conceptual Design / FEED and Detailed Engineering. This page begins where the question changes: Did that basis reach the installed and validated SIS — and can the owner now take control of it? Handover is not documents delivered; owner acceptance is a matter of confidence in what was installed, validated and handed over. Complete documentation alone does not prove functional safety. Without controlled evidence, however, nothing can be demonstrated at all.
- DESIGN BASIS
- PROCURED / CONFIGURED SIS
- INSTALLED SIS
- COMMISSIONING EVIDENCE
- SAFETY VALIDATION
- OWNER ACCEPTANCE
- OPERATING LIFECYCLE CONTROL
Can the owner demonstrate the accepted SIS basis?
A representative evidence view — not a mandatory universal checklist, and deliberately not a score. Open each group and set the state of every item as you believe it stands today; nothing is stored or transmitted. Incomplete evidence does not prove physical failure. It reduces confidence, increases uncertainty, and may require evidence recovery before acceptance, start-up or assessment decisions can be defended.
SET THE STATE OF EACH ITEM
Can every installed SIF be traced, revision by revision, to the SRS and the verification basis it claims?
SET THE STATE OF EACH ITEM
Which FAT exceptions remain open, and what was the documented basis for accepting each one into commissioning?
SET THE STATE OF EACH ITEM
Do installation and loop records demonstrate conformity with the approved design — including every field change made along the way?
SET THE STATE OF EACH ITEM
Does the validation evidence demonstrate, requirement by requirement, that the installed SIS meets the SRS in all relevant operating modes?
SET THE STATE OF EACH ITEM
Are the operating, maintenance and proof-test arrangements in place and understood by trained people — before hazards are introduced?
SET THE STATE OF EACH ITEM
Are the management arrangements — competence, MoC, records — ready to carry the SIS through operation, and are prior assessment findings closed?
SIS Installation, Commissioning and Validation
How many punch items touching protection functions went forward — and with what documented risk decision?
The SIS is installed in accordance with the approved requirements, commissioned element by element, and then validated against one question: Does the installed SIS meet the SRS — in the relevant operating modes, at the set-points, within the response times, through to the final elements? Commissioning completion is not safety validation; the two produce different evidence for different claims, and owner acceptance will draw on both.
Some examples of how confidence might be lost
- Field changes made during installation may never find their way back into the configuration and design records.
- Under schedule pressure, validation can shrink into a repeat of FAT instead of a demonstration of the installed system.
- Punch items touching protection functions can be carried into start-up without a documented risk decision.
- Changes made during commissioning may not be fed back into the validated baseline, so the documented SIS and the operating SIS diverge on day one.
Evidence & assurance basis
Evidence typically available: Approved installation and commissioning plans; installation drawings, loop information and a controlled configuration baseline; receiving, storage, installation and inspection records; calibration, configuration and loop-commissioning records; FAT records, exception list and corrective-action status; commissioning procedures, results and anomaly records; field-change, deviation and punch-item registers; as-built documentation and handover index; validation plan, procedures, results and anomaly dispositions; equipment preservation and reinstatement (return-to-service) records.
What still needs to be demonstrated: The installed configuration matches the approved basis, including every field change made along the way; commissioning failures and exceptions have a defined disposition and closure evidence; validation traces requirement by requirement to the SRS; and the information owner acceptance depends on is complete, controlled and retrievable. Possessing a document does not, by itself, prove adequacy.
Tick one or more solution types below. Each ticked selection opens an outline of what that solution would cover in this phase — and everything you leave ticked is consolidated into your scope summary at the end of this section.
Owner acceptance readiness plan — acceptance criteria, evidence expectations and the decision route to start-up; commissioning-to-validation governance review with a prioritised open-item briefing.
Training & workshopsOwner-team working session on acceptance criteria and what the evidence must show.
Independent sampling of installed loops and records against the approved requirements; validation evidence audit against the SRS; FSA Stage 3 execution as an independent body, before hazards are introduced.
Reports & management outputsInstallation and validation conformity review with a risk-ranked finding register; pre-start-up gate conclusion.
As-built reconciliation against the SRS and configuration baseline; punch, exception and anomaly disposition records with closure evidence.
Procedures & plansValidation plan and procedures, traceable to SRS requirements; the SIF-by-SIF commissioning and validation evidence pack owner acceptance will rely on.
Tests, reviews & assessmentsReadiness preparation to FSA Stage 3.
FSA STAGE 3 — BEFORE HAZARDS ARE INTRODUCED
IEC 61511 positions Stage 3 after installation, pre-commissioning and final validation, with operation and maintenance procedures developed: An independent look at whether the installed, validated SIS and the organization around it are ready for hazardous material. It is distinct from commissioning, validation, verification and audit — and readiness support is distinct from the formal assessment itself.
SEE DETAILSFunctional Safety Assessment across the safety lifecycle
SIS Operation and Maintenance
Have actual demands ever been compared against the demand rate the design assumed?
When a proof test last failed, who interpreted what it meant for the function — and what changed?
The longest phase, and the one where drift is quietest. The operating regime — testing, inspection, calibration, controlled bypassing, repair and restoration, deferral decisions, response to diagnosed faults and degradation — either keeps the accepted basis supported by evidence, or lets it erode without an event to mark the moment. Changes in process demand can invalidate assumptions without any physical change at all.
Some examples of how confidence might be lost
- Proof tests may complete on schedule while their coverage of the failure modes that matter is never established.
- Bypasses and deferrals can accumulate until no one holds the full picture of degraded or bypassed functions in one view.
- Demand, failure and spurious-trip data may be recorded but never analysed at SIF level.
- Where ageing and vendor support are not watched, obsolescence arrives as a surprise capital demand.
Evidence & assurance basis
Evidence typically available: Operations and maintenance procedures; inspection items and forms; calibration records; preventive and predictive maintenance records; diagnostic and fault records; proof-test procedures, templates and results; as-found/as-left records; restoration records; demand logs; trip investigation and failure reports; bypass permits, assessments and logs; deferral approvals; competence records; performance and management-system metrics; audit records; action tracking.
What still needs to be demonstrated: Proof-test coverage matches the verification assumptions; the picture of degraded, bypassed and deferred functions is complete; operating evidence — demands, failures, trips, as-found results — is analysed against the assumptions and leads to decisions when performance drifts; and procedures reflect the SRS, the installed arrangement and the way the work is actually done.
Tick one or more solution types below. Each ticked selection opens an outline of what that solution would cover in this phase — and everything you leave ticked is consolidated into your scope summary at the end of this section.
Operating SIS integrity baseline review; functional-safety governance and management-review framework — indicators, owners, escalation routes.
Training & workshopsProof-test quality and operating-evidence interpretation sessions, including the interpretation methodology for demand, failure and recurring-event review.
Functional safety audit of the operating and maintenance arrangements, to the agreed timeline; proof-test, bypass and deferral evidence audit; FSA Stage 4 execution as an independent body.
Reports & management outputsEvidence sufficiency matrix; risk-ranked finding register; independent action close-out verification.
Proof-test, bypass, deferral and maintenance-strategy procedures, developed or revised.
Operational records, forms & registersDemand and failure record structures; register of degraded, bypassed and deferred functions; the SIS evidence and document index kept current — every record filed where the next reviewer can find it.
Reports & management outputsSIS performance and operating-experience executive report; technical remediation register.
Tests, reviews & assessmentsPlanned test results, failure, demand and spurious-trip analysis against the verification assumptions; readiness preparation to FSA Stage 4.
Proof Test: Completion Is Not Coverage
Management should be able to distinguish two different statements: “The proof-test task was completed” and “The test demonstrated the intended coverage.” The difference lives in scope and the failure modes addressed; whole-loop versus segmented testing; pass/fail criteria; preparation and test equipment; as-found and as-left condition; restoration and post-test confirmation; the relationship between diagnostics and proof testing; how incomplete or partial tests are treated; and how a failed test is interpreted and recorded. A signature at the bottom of a form answers the first statement only.
DSIB can provide: Proof-test procedure development or review; coverage review; test-evidence audit; failed-test interpretation; procedure revision; data-quality review; training; action tracking.
Bypasses & Deferrals
A bypass, a test deferral or a repair deferral can be a legitimate, controlled operating decision. What makes it legitimate is the control: A stated reason, technical review, authorisation at the right level, risk consideration with compensating measures, an expected duration, a responsible owner, visibility to operations, a defined return-to-service — and attention to repeated use and overdue status, because a bypass renewed monthly is a design decision being taken informally.
DSIB can develop or review: Bypass procedure, permit, assessment form and log; test deferral procedure and approval form; repair deferral procedure and form; review of degraded or bypassed functions; recurring-use analysis.
FSA STAGE 4 — AFTER OPERATING AND MAINTENANCE EXPERIENCE
The periodic assessment asks whether operating evidence still supports the claims made at acceptance. No universal frequency is implied; the assessment cycle is planned within your management system.
SEE DETAILSFunctional Safety Assessment across the safety lifecycle
SIS Modification
Who checks whether a “small” change reaches the SRS, the response time or the proof-test basis?
Modification is a lifecycle activity, not paperwork after a decision: Process changes, changed demand assumptions, set-point and logic changes, device substitution, temporary changes, ageing and replacement all reopen parts of the basis. A modification may require controlled re-entry into earlier lifecycle activities — which ones, and how far back, is exactly what the impact review decides. Not every modification repeats every activity.
Some examples of how confidence might be lost
- A device may be treated as replacement-in-kind even though its model, firmware, configuration, response or safety-manual constraints differ.
- A set-point, logic or maintenance-interval change can be approved without identifying all affected SIFs and protection-layer assumptions.
- Only the changed component may be tested, although interfaces or non-modified functions could be affected.
- Temporary changes can remain in service without an agreed expiry, an owner, or conversion back to the permanent basis.
Evidence & assurance basis
Evidence typically available: MoC records; impact assessments; revised SRS or verification records where affected; re-validation results; updated configuration and cause-and-effect records; close-out confirmations; FSA or routine audit records.
What still needs to be demonstrated: The configuration before the change is preserved, so a controlled baseline exists to compare against; all affected requirements, interfaces and assumptions have been reviewed — not only the changed item; cumulative small changes have been examined together; and temporary changes actually ended.
Tick one or more solution types below. Each ticked selection opens an outline of what that solution would cover in this phase — and everything you leave ticked is consolidated into your scope summary at the end of this section.
SIS change-control basis review — including demand-assumption and temporary-change triggers; replacement and upgrade roadmap.
Procedures & plansReview of the existing SIS MoC procedure.
Training & workshopsMoC screening and impact-analysis workshop; cross-discipline change-authority workshop.
Sampled-modification audit for complete impact analysis, re-verification and revalidation; reinstatement evidence review after turnaround; FSA Stage 5 execution as an independent body, after modification; independent close-out verification of modification actions.
Technical close-out report, including the modification verification and validation dossier.
Procedures & plansThe SIS-specific route implemented inside your existing MoC system; SRS revision support; SIL-verification revision support.
Operational records, forms & registersRevisions to the SIF register and the MoC log; impact-assessment templates.
Tests, reviews & assessmentsReadiness preparation to FSA Stage 5.
FSA STAGE 5 — AFTER MODIFICATION
Stage 5 follows modification: An independent look at whether the change was impact-assessed, implemented, verified and where required revalidated — and whether the records now describe the SIS that is actually running.
SEE DETAILSFunctional Safety Assessment across the safety lifecycle
SIS Decommissioning
Before a safety function is removed, who confirms that the rest of the plant no longer depends on it?
Decommissioning is a controlled lifecycle activity, not equipment removal. It is planned and authorised; residual hazards and adjacent systems are assessed; temporary safeguards are governed; the removal or disablement of safety functions — including partial-system decommissioning — is examined for what the surviving plant still relies on; and configuration, documentation and retained records are closed out, with responsibility after removal made explicit.
Some examples of how confidence might be lost
- Equipment removal can begin before the protection needed during the transitional plant states has been identified.
- Partial decommissioning may change shared utilities, communications or final elements that remain necessary elsewhere.
- Temporary safeguards and bypasses can be put in place without a controlled end condition or a reinstatement requirement.
- Configuration and document close-out can discard history that retained or adjacent systems still need.
Evidence & assurance basis
Evidence typically available: Decommissioning plan and authorisations; hazard and impact reviews for the work; isolation and reinstatement plans; MoC records for the removal; temporary safeguard and bypass records; configuration and document close-out records; retained-records index.
What still needs to be demonstrated: The protection needed during each decommissioning state has been identified; impacts on adjacent units, shared systems and facility services have been addressed; temporary safeguards, isolation and reinstatement are controlled and visible; and the retained information supports the remaining plant and the final close-out decision.
Tick one or more solution types below. Each ticked selection opens an outline of what that solution would cover in this phase — and everything you leave ticked is consolidated into your scope summary at the end of this section.
Decommissioning basis report — the approach, the residual hazards, and the decisions management must take; temporary safeguard, isolation and reinstatement strategy.
Training & workshopsDecommissioning risk-interface workshop; operations, projects and contractor responsibility session.
Impact-analysis and hazard-review challenge; review of required SIF availability during the work; adjacent-unit, service and temporary-safeguard review; authorisation, isolation, reinstatement and close-out evidence review; FSA Stage 5 execution as an independent body, prior to decommissioning.
SIS decommissioning procedure.
Operational records, forms & registersTemporary safeguard and bypass register; the retained-records set — what is kept, where it lives, and who answers for it; register updates for removed functions and residual hazards.
FSA STAGE 5 — PRIOR TO DECOMMISSIONING
Before a SIS is decommissioned, Stage 5 independently examines whether the plan protects the transitional states, the adjacent systems and the record the remaining plant will rely on.
SEE DETAILSFunctional Safety Assessment across the safety lifecycle
Your SIS Integrity Scope Summary
The selections you leave ticked in the lifecycle phases above are collected here, ordered by phase and grouped by deliverable type. Nothing is stored or transmitted; the list reflects only the selections on this page.
The items above are drawn from a service template and give a first, rough view of scope. For a proposal aligned to your facility, contact DSIB directly.
Operational Excellence in SIS Management
A successful FSM program should be heading somewhere specific: Fewer unknowns in the evidence, closure that is owned and on time, and resources allocated on trend rather than on the loudest recent event. In DSIB practice, this view matures into the Operational Excellence in Functional Safety due-diligence report.
Strategic Oversight
Completion shows that an activity was recorded. Management also needs the scope, the quality, the findings, the restoration status and the technical meaning of the evidence — including the short-, mid- and long-term expenditure the SIS position implies, from proof-test access improvements to obsolescence-driven replacement.
Organizational Development
Each degraded or bypassed function, finding, decision and action needs an accountable owner, an authority route and an evidence-based closure condition. Over time, responsibilities settle into the facility's other management systems, and the assigned people grow — design, operations and maintenance skills together, with the training and certification their roles require.
Learning from Experience
Demand, failure, trip and maintenance records become useful when consistently classified, reviewed and connected to corrective action. Recurring degradation, useful-life concerns, obsolescence and evidence quality inform maintenance strategy and investment priorities — and configuration, procedures, assumptions and actual work practice get controlled review as modifications and operating experience accumulate.
Operational Experience Back to the Technical Basis
Operating evidence does not automatically change the SRS or the SIL verification. It can show that assumptions should be reviewed. Any revision travels through the applicable lifecycle and MoC process: Controlled, verified, and where required revalidated.
What counts as operating evidence?
Actual demands; failures where classification is supportable; proof-test findings; as-found/as-left data; recurring failures; spurious trips; diagnostic faults; bypass exposure; restoration data; changed process conditions or operating envelope; response-time observations; environmental conditions; common-cause observations; device ageing; device suitability observations; vendor-support and obsolescence status; maintenance and spare strategy experience.
DSIB's role: Data analysis; assumption review; evidence-confidence assessment; technical-basis revision support; prioritisation; remediation planning.
SIS Performance Monitoring
Operating management should hold one view of test status and quality — overdue, failed and incomplete tests, as-found trends, restoration — alongside degraded and bypassed functions with their deferrals and compensating measures, operating events such as demands, trips and recurring failures, and the lifecycle position: Open modifications, obsolescence exposure, spares, evidence confidence. No universal targets are implied; definition, owner, data source and management trigger are set per indicator.
Illustrative KPI dashboard
A — Enterprise / management risk
B — Governance & assurance
C — SIS integrity & performance
D — Delivery & action closure
For each indicator adopted, the engagement establishes definition, owner, scope, data source, review frequency, baseline, agreed target or tolerance, and the management action trigger.
SEE DETAILSOperational Excellence: The Design Safety Chapter
Functional Safety Management Program
DSIB assembles the Functional Safety Management Plan with you as a written, controlled document — scoped to your operating SIS, run by your people, and interfaced with the management systems you already operate: Your CMMS, your document control, your MoC among them. Turn the pages to see what the plan contains.
1 — Define the operating SIS scope and current position
Which SIS and units are in scope, a detailed SIF register, what the evidence currently supports, and which decisions are pending. The plan starts from an honest baseline, with data confidence stated rather than assumed.
- Scope and boundary statement
- Current-state assessment
- Evidence and document index
- Initial gap and decision register
2 — Establish governance, responsibility and competence
Who owns each lifecycle activity, under a prepare–review–approve authorization scheme, and with what demonstrated competence — across operations, maintenance, engineering and management.
- Governance policy
- Lifecycle responsibility matrix
- Competence framework
- Document authorization scheme
3 — Connect lifecycle procedures and decision routes
Define how operation, proof testing, maintenance, bypasses, deferrals, faults, modifications and decommissioning procedures are initiated, reviewed, authorised, performed and closed.
- Lifecycle procedure set — or revision plan — and their interactions
- Decision and approval scheme
4 — Control evidence, records and configuration
Establish the controlled information needed to operate, maintain, test, assess and modify the SIS — including where each master copy lives, who is responsible for it, revision control, required data fields, and how long records are kept.
- Evidence and document index
- Configuration-control framework
5 — Integrate operations, maintenance, MoC and vendor interfaces
The plan plugs into what already exists — CMMS, document control, MoC, alarm management, shutdown and isolation procedures, vendor handover, turnaround planning — rather than competing with it.
- Identification and list of relevant procedures, registers, software and stakeholders interfacing FSM
- Identification of interfacing authorities for document, task and change approvals
6 — Establish performance monitoring and management review
Define indicators that show evidence quality, degraded or bypassed functions, test effectiveness, failures, demands, action closure and lifecycle drift — together with ownership and decision triggers.
- Indicator definitions
- Management-review framework
- Data-quality improvement plan
7 — Prioritise remediation and investment
Findings become a risk-ranked roadmap tied to decisions — what to fix, fund or review first, in a form the budget cycle can absorb.
- Improvement register and roadmap
- Capital and operating expenditure priorities
8 — Implement, sustain and develop the plan
Embed the agreed controls through working sessions, document implementation, pilot use, assurance checks, management review — and controlled updates that develop the plan as operating evidence accumulates.
- Implementation plan
- Role-based training
- Pilot and verification records
- A standing review-and-update cycle that keeps the plan current
Start with One SIS
An initial engagement can be limited to one SIS, one operating unit, one commissioning or validation scope, one operation-and-maintenance lifecycle review, one modification, one selected group of critical SIFs, or one specific evidence problem. That first scope determines the decision to be supported, the evidence available and its confidence, the material uncertainty, the immediate controls, the accountable owners, the deliverables required, the right DSIB solution model — and whether a broader program is justified at all.