GeoBusinessIQGeoBusinessIQ

Safety instrumented systems: an independent protection layer, not another control loop

What this answers

What makes an instrumented protection layer genuinely independent, and what has to happen for it to stay trustworthy?

A control system keeps a process where you want it. A safety instrumented system exists for the moment control has already failed, and its entire value rests on being independent of whatever failed. That independence is what makes it different in equipment, in wiring, in testing and in who may change it. Specifying one starts from a hazard study of the specific process and is engineering work requiring an engineer qualified in process safety.

Written for: process safety engineers, instrumentation engineers, plant operations managers.

What separates protection from control

A protection layer has to act even when the control system is the cause of the problem. In practice that means its own sensors, its own logic solver and its own final elements, functionally separate from the basic process control system, driving the process to a defined safe state. Sharing a transmitter between control and protection reintroduces the common cause the design was meant to eliminate. Independence extends to people and procedures as well: one engineer changing both, with the same access and the same change process, weakens the separation the design assumed even where the hardware remains genuinely separate.

The specification comes from a hazard study, not a catalogue

Nothing about a protection layer can be selected before the hazard is understood. The sequence begins with a hazard and operability study identifying what can go wrong, followed by an assessment of how much risk reduction the instrumented layer must provide relative to other layers such as relief devices, mechanical protection and operator response. That assessment is specialist work, carried out for that process, by an engineer competent in it. Copying a design from a similar plant is the failure mode to avoid, because the surrounding layers and the consequences differ even where the equipment looks identical.

Proof testing is what keeps the claim true

A protection layer spends its life doing nothing, so failures inside it are dormant and invisible. Proof testing is how they are found, and the interval is derived during design rather than chosen for convenience, since the assumptions made about failure behaviour only hold if testing happens as assumed. Tests need to exercise the whole function from sensor through to final element, because testing the logic while leaving a seized valve untouched proves very little. Where full testing requires the process down, partial testing arrangements belong in the design record rather than in an informal maintenance habit.

Bypasses are the largest day-to-day exposure

Overrides exist because protection sometimes has to be inhibited for start-up or maintenance, and they are where most real harm originates. The exposure is not the bypass itself but the bypass that stays: applied on nights, undocumented, forgotten at handover, and rediscovered during an incident investigation. Control it as a formal permission with a named authoriser, a recorded reason, a stated duration, alternative protection described while it applies, and an indication operators cannot miss. Audit active bypasses on a routine, because a list nobody reviews rapidly becomes a list nobody bothers to maintain.

The lifecycle that follows handover

Design assumptions have to survive the plant's working life. Any modification to the process, the instrument, the valve, the logic or the operating procedure can invalidate them, so changes route through management of change with the safety engineer involved rather than through routine maintenance. Failure data should feed back, since a final element found stuck during a proof test is evidence that an assumed failure behaviour was optimistic. Competence matters too: technicians calibrating protection instruments need to know why that loop differs from the one beside it, and the difference is rarely visible on the equipment.

Frequently asked questions

Can the normal control system perform the safety function as well?
Doing both in one system defeats the purpose, because the layer meant to catch a control failure now shares its components, its software and its failure modes. Some processes do rely on the control system as a protective layer for lower-consequence hazards, but that is a deliberate decision recorded in the hazard assessment rather than a default. Where a genuinely independent layer is required it has separate sensing, separate logic, separate final elements and separate people authorised to change it.
Who is allowed to design a safety instrumented function?
Somebody competent in process safety engineering for that type of process, working from the site's own hazard study rather than another plant's drawings. Competence here is specific: understanding the chemistry or physics, the other protection layers, the failure behaviour of the chosen devices and the testing regime the design depends on. Equipment suppliers can advise on their own devices and cannot substitute for that assessment. Record who did the work and what they assumed, since those assumptions get revisited for the plant's life.
What if we cannot proof test without stopping production?
Say so during design instead of discovering it afterwards, because testability is a design requirement that shapes valve selection, bypass arrangements and instrument redundancy. Options include arrangements permitting partial testing of a final element while running, redundancy allowing one element to be tested at a time, and aligning intervals with planned shutdowns. What is not acceptable is quietly extending the interval, since the risk reduction claimed by the design rests on testing at the frequency the design assumed.

Data limitations

  • Plant, process, utility and equipment material is business intelligence, not engineering design. Layout, structural, electrical, mechanical, pressure, ventilation and fire-safety decisions require a qualified engineer working to the codes in force at the site.
  • Manufacturing figures are operator-supplied inputs, not market data. GeoBusinessIQ holds no factory costs, production volumes, yields, cycle times, tooling prices or capacity data and does not estimate them — every result reflects only the figures you enter.

Explore the graph

Sources

  • International Electrotechnical Commission IEC (accessed )
    Covers: International standards for electrical, electronic and related technologies, including industrial automation and machinery safety.
    Does not cover: Standard text, conformity decisions, or product approval.
    Why it matters: Cited for the origin of electrotechnical and automation standards referenced on automation and machinery pages.
    Review cadence: annual
  • Health and Safety Executive HSE (accessed )
    Covers: United Kingdom workplace health and safety regulation, including machinery, chemicals and process safety.
    Does not cover: Risk assessments for a specific workplace, or enforcement outcomes.
    Why it matters: The regulator that owns UK workplace safety duties; cited rather than a secondary summary.
    Review cadence: annual

Educational and operational information only — not legal, engineering, safety, customs, tax, or financial advice. Requirements vary by jurisdiction, product, process, and contract; confirm with the relevant authority or a qualified professional before acting.

Last updated: