Management of SIS Lifecycle During Conceptual Design / FEED and Detailed Engineering
Analysis
Design & Implementation
→ Scope of this briefOperation & Maintenance
Introduction
In the process industry, the execution of functional safety engineering activities revolves strictly around the IEC 61511 standard. To maintain a healthy Safety Instrumented System (SIS) lifecycle—typically summarized as Analysis, Design & Implementation, and Operation & Maintenance—the roots stemmed to Conceptual and Detailed Design phases are fundamentally critical.
This brief outlines how to systematically address the necessary documentation, controls, and role assignments during the design phases to ensure the long-term integrity and reliability of a SIS.
The Bridge Between Analysis and Design: The SRS
The transition from the Analysis phase (incorporating Process Hazard Analysis and Layer of Protection Analysis - LOPA) into the Design phase is established through the Safety Requirements Specification (SRS).
The SRS is not a static file; it is a “living document” that evolves throughout the project and is continuously updated, even sometimes through Management of Change (MOC) protocols if necessary. Initially beginning as a “Process SRS,” it captures most importantly a clear definition of each SIF and associated target Safety Integrity Levels (SIL), hazard description, demand mode, safe state and process safety time. As the design matures, it transforms into a “Detailed SRS,” incorporating specific hardware, software, and testing requirements. Ideally, a detailed SRS guides the engineering team in developing detailed engineering deliverables; however, as noted above, it is a living document that requires iterative updates throughout the project.
Relevance to IEC 61511
Similar to the practice we apply at Design Safety Intelligence Bureau, each company should develop its own engineering progress checklists, a SRS preparation guideline and a project-specific Functional Safety Management Plan.
Design Phase: from verified analysis outputs to site installation
Two engineering phases and three assessment and test gates. Open a phase to read its key decisions, documentation and controls.
Conceptual Design & FEED
Conceptual design begins with the verified outputs of PHA and target SIL assignment. During this phase, basic entries to the SRS are translated into a tangible engineering strategy and engineers determine, with optimized cost, how the SIS will achieve the three critical criteria: Probability of Failure on Demand (PFD), architectural constraints and systematic capability.
At this stage, decisions are mostly given by operators, process designers, functional safety engineers and sometimes by consultation with vendors.
Key Decisions & Documentation
Key Controls
If the desired Risk Reduction Factor (RRF) or SIL is not met during calculations, the design must iteratively return to technology selection, revising architecture, adjusting proof test intervals, or enhancing test coverage assumptions as per Owner’s declaration. Before proceeding further, Functional Safety Assessment (FSA) Stage 1 should be executed to ensure the hazard analysis and initial SRS are robust for each SIF.
FSA Stage 1
Executed before proceeding further, to ensure the hazard analysis and initial SRS are robust for each SIF.
Detailed Design
Detailed design associates the SRS with engineering deliverables that can be checked, tested and handed over.
This phase starts after the procurement of devices and heavily involves collaboration with technology vendors to finalize both hardware and software (application programming) aspects of the SIS like rest philosophy, programming method, system interfaces, UPS backup time, actual response time, asset management system interfaces, auxiliaries, mission life and etc. The goal is to provide all necessary details for procurement, installation, and commissioning.
A SIF that is well described in the SRS but poorly reflected in Cause & Effect, logic, HMI, bypass handling, proof test procedure or validation plan is not yet lifecycle-ready.
Key Decisions & Documentation
Key Controls
The design must undergo software verification (using simulation tools) and rigorous Factory Acceptance Testing (FAT). The FAT verifies both hardware (HWFAT) and application programming (APFAT) in a controlled environment. Following successful design and testing, FSA Stage 2 is conducted before site installation.
FAT — HWFAT and APFAT
Hardware and application programming verified in a controlled environment. The SIS design phase ends with FAT.
FSA Stage 2
Conducted following successful design and testing.
Roles & Responsibilities in the Design Phases
Project Management Team (PMT) / Project Manager
Holds ultimate accountability (Accountable/Responsible) for the main engineering deliverables like PHA/LOPA report, SIF list, SRS and the full I&C, vendor and process documentation relevant to SIS. They must ensure that safety lifecycle activities are included in the project schedule addressed to relevant respondents. PMT is also responsible for closure of all actions from risk registers, technical inquiries, FSAs, HOLD issues, technical deviation lists and control checklists.
Engineering & Instrument (E&I) Team / SIS Designers
Responsible for the actual design and engineering of the SIS to meet the safety requirements, ensuring maintenance provisions (safe and cost-effective testing) are met.
Operating Organization (OO) / Owner
Must be Consulted during the design phase. They define expected plant maintenance (turnaround) intervals, acceptable spurious trip rates, and bypass strategies. They ultimately take over accountability during the Operation & Maintenance phase.
Technology Providers / Vendors
Responsible for providing certified safety manuals, device failure rates, and standard documentation (e.g., maintenance/troubleshooting manuals, TUV/EXIDA/ISA certificates).
Process Safety Manager / Independent Assessors
Besides mentoring and/or facilitating PHA/LOPA sessions, they take the responsibility of initiating, preparing or controlling SRS and SIL verification reports in accordance with the organizational work split in the company. They are also responsible for verifying that an effective MOC process is in place, relevant procedures are followed, SCE TIV reports (at least engineering control checklists) have been fulfilled, SIS relevant KPIs are reported and they organize the independent Functional Safety Assessments (FSAs).
Critical Recommendations for a Robust SIS Lifecycle
01 Report unresolved integrity issues early and transparently
Recommendations, deviations, overdue actions, SCE status, documentation gaps and governance issues should be visible before commissioning, not absorbed silently into operation. Stage 1 and 2 assessments are the opportunities to stop weak requirements and identify incomplete or unresolved issues.
02 Manage Common Cause Failures (CCF)
During detailed design, by using every flexibility you have, actively mitigate CCFs by employing physical separation, diverse technologies (e.g., different measurement principles for level transmitters), and independent taps for redundant sensors.
03 Design for Testability (AAI Integration)
Automation Asset Integrity (AAI) planning must begin in the design phase. Ensure that the architecture allows for safe, on-line proof testing without interrupting plant throughput. Include bypass logic and bypass annunciation explicitly in the application programming.
04 Maintain Personnel Competency
System integrity relies as much on human reliability as it does on hardware. Ensure that everyone involved—from the logic programmers to the operators performing the site acceptance test (SAT)—has documented, verified training and competency specific to IEC 61511 requirements. Additionally, make sure that all personnel clearly understand and accept their respective roles.
05 Focus on Documentation Handover
The transition from the project team to maintenance and operations is a vulnerable period. Ensure seamless transfer of the Detailed SRS, as-built loop drawings, and proof test procedures. Treat documentation as a long-term asset by maintaining SIF traceability and initiating the SRS once SIFs are identified. Either prepare a separate Application Program Software specification or integrate it into the detailed SRS.
06 Do Not Underestimate Software Use
Appropriate software is essential for managing SIF functional and integrity requirements. Beyond HAZOP and LOPA, it supports SIL verification through complex calculations and reliability databases, facilitates structured SRS development, and provides seamless integration, improved traceability, and minimized data loss across the SIS lifecycle.