© Design Safety Intelligence Bureau. This page is not available for printing. Please visit the DSIB website to view it.
Solutions Series · DSIB

Maintaining SIS Integrity from Owner Acceptance through Operation

For the owners and operators of the Safety Instrumented System (SIS).

A technically sound SIS can still become difficult to defend: Unreconciled field changes, thin test evidence, loosely controlled bypasses, modifications that reopen earlier assumptions. On this page you will find a confidence check for the SIS you take over, the support you can select in each lifecycle phase, and a needs list assembled automatically as a first draft of scope.

Confident in the SIS You Take Over?  Assess Your Lifecycle Needs

Three ways of engaging

DSIB Solution Models

See our engagement models for your functional safety management program in summary.

INTEGRATED SOLUTIONS

Frequently Asked

Q1Can audit work be combined with advisory or engineering support?

Yes. Functional safety audits can be delivered inside an advisory or engineering engagement — as recurring health checks, gate reviews or evidence audits — with scope, personnel and reporting lines agreed so the challenge stays real.

Q2Can DSIB issue the formal FSA on work it also implemented?

No. The standard requires the FSA to be independent of the work it assesses. So for any given scope, DSIB takes either the implementation side or the assessment side — not both.

Q3What can be done before a formal FSA?

FSA pre-checklist as readiness study: The evidence expectations mapped, gaps closed, actions from earlier stages verified — so the formal assessment, whoever performs it, arrives at a prepared organization. Readiness support is an Advisory activity and is always distinct from the formal assessment itself.

From owner acceptance to decommissioning

Lifecycle Integrity Management

The sections below follow the lifecycle phases of IEC 61511-1 Cl. 14–18, with owner acceptance as the transition that connects the project's basis to your operating control.

GET AN AUTOMATED NEEDS LIST

The lifecycle phases below set out the needs that arise in each phase and the solutions DSIB can offer against them. Start by measuring how confident you are, as the operating team, in the SIS you are taking over. Then, in each phase, review the solutions offered under the three DSIB models and leave the ones that interest you ticked. Your needs list is assembled automatically at the end of this section.

Start here — check your position

Owner Acceptance & Handover Control

Is the SIS you are about to accept the SIS that was specified, installed and validated?

How the design basis is created and assured is the subject of Management of SIS Lifecycle During Conceptual Design / FEED and Detailed Engineering. This page begins where the question changes: Did that basis reach the installed and validated SIS — and can the owner now take control of it? Handover is not documents delivered; owner acceptance is a matter of confidence in what was installed, validated and handed over. Complete documentation alone does not prove functional safety. Without controlled evidence, however, nothing can be demonstrated at all.

  1. DESIGN BASIS
  2. PROCURED / CONFIGURED SIS
  3. INSTALLED SIS
  4. COMMISSIONING EVIDENCE
  5. SAFETY VALIDATION
  6. OWNER ACCEPTANCE
  7. OPERATING LIFECYCLE CONTROL

PHASE 1 — IEC 61511-1 CL. 14–15

SIS Installation, Commissioning and Validation

How many punch items touching protection functions went forward — and with what documented risk decision?

PHASE 2 — IEC 61511-1 CL. 16

SIS Operation and Maintenance

Have actual demands ever been compared against the demand rate the design assumed?

When a proof test last failed, who interpreted what it meant for the function — and what changed?

PHASE 3 — IEC 61511-1 CL. 17

SIS Modification

Who checks whether a “small” change reaches the SRS, the response time or the proof-test basis?

PHASE 4 — IEC 61511-1 CL. 18

SIS Decommissioning

Before a safety function is removed, who confirms that the rest of the plant no longer depends on it?

The outcome of this assessment

Your SIS Integrity Scope Summary

The selections you leave ticked in the lifecycle phases above are collected here, ordered by phase and grouped by deliverable type. Nothing is stored or transmitted; the list reflects only the selections on this page.

From records to decisions

Operational Excellence in SIS Management

A successful FSM program should be heading somewhere specific: Fewer unknowns in the evidence, closure that is owned and on time, and resources allocated on trend rather than on the loudest recent event. In DSIB practice, this view matures into the Operational Excellence in Functional Safety due-diligence report.

Strategic Oversight

Completion shows that an activity was recorded. Management also needs the scope, the quality, the findings, the restoration status and the technical meaning of the evidence — including the short-, mid- and long-term expenditure the SIS position implies, from proof-test access improvements to obsolescence-driven replacement.

Organizational Development

Each degraded or bypassed function, finding, decision and action needs an accountable owner, an authority route and an evidence-based closure condition. Over time, responsibilities settle into the facility's other management systems, and the assigned people grow — design, operations and maintenance skills together, with the training and certification their roles require.

Learning from Experience

Demand, failure, trip and maintenance records become useful when consistently classified, reviewed and connected to corrective action. Recurring degradation, useful-life concerns, obsolescence and evidence quality inform maintenance strategy and investment priorities — and configuration, procedures, assumptions and actual work practice get controlled review as modifications and operating experience accumulate.

SIS Performance Monitoring

Operating management should hold one view of test status and quality — overdue, failed and incomplete tests, as-found trends, restoration — alongside degraded and bypassed functions with their deferrals and compensating measures, operating events such as demands, trips and recurring failures, and the lifecycle position: Open modifications, obsolescence exposure, spares, evidence confidence. No universal targets are implied; definition, owner, data source and management trigger are set per indicator.

Illustrative KPI dashboard

A — Enterprise / management risk
Open high-significance lifecycle findings3
Oldest open high-significance finding47 days
Evidence-recovery actions open5
B — Governance & assurance
FSA actions open / overdue7 / 0
MoC items affecting the SIS, open6
Assigned roles with current competence14 of 16
C — SIS integrity & performance
Overdue proof tests4 of 128
Failed or incomplete tests, 12 mo5
Active bypasses / oldest2 / 11 days
Approved test / repair deferrals3 / 1
Real demands / spurious trips, 12 mo1 / 3
Devices past vendor support9
D — Delivery & action closure
6-month plan items closed21 of 34
Validation anomalies open2
Average action close-out age28 days

For each indicator adopted, the engagement establishes definition, owner, scope, data source, review frequency, baseline, agreed target or tolerance, and the management action trigger.

SEE DETAILSOperational Excellence: The Design Safety Chapter

An Advisory & Consultancy offering

Functional Safety Management Program

DSIB assembles the Functional Safety Management Plan with you as a written, controlled document — scoped to your operating SIS, run by your people, and interfaced with the management systems you already operate: Your CMMS, your document control, your MoC among them. Turn the pages to see what the plan contains.

Functional Safety Management Plan
ASSEMBLED THROUGH THE ADVISORY & CONSULTANCY MODEL — DSIB
DESIGN SAFETY INTELLIGENCE BUREAU
Cover
A contained first step

Start with One SIS

An initial engagement can be limited to one SIS, one operating unit, one commissioning or validation scope, one operation-and-maintenance lifecycle review, one modification, one selected group of critical SIFs, or one specific evidence problem. That first scope determines the decision to be supported, the evidence available and its confidence, the material uncertainty, the immediate controls, the accountable owners, the deliverables required, the right DSIB solution model — and whether a broader program is justified at all.