Risk + Safety + AMC

SIL Determination + SIS Design

Safety Integrity Level allocation + Safety Instrumented System architecture.

What's the right SIL for the high-pressure trip on R-101? How many redundant sensors do you need to hit SIL 2? Will a 1oo2 architecture do, or do you need 2oo3? Determined by risk graph, LOPA, or fault tree · designed in compliance with IEC 61508 / 61511 · validated by PFD calculation. CEng MIE-signed.

25 marquee operators · 21 countries · verified roster
Bayer · Pfizer · TATA · Adani · JSW · ISRO · Siemens · Bosch · DuPont · Mahindra · Hindalco · and others
Bayer
Pfizer
TATA
Adani
JSW
Nestle
ISRO
Mahindra
Siemens
Bosch
DuPont
Aditya Birla
Hindalco
Amazon
Indian Oil
ITC
Asian Paints
Dr. Reddy
Kia
Bureau Veritas
Lloyd
Halliburton
Jindal Steel
AMNS
Rolls Royce
Bayer
Pfizer
TATA
Adani
JSW
Nestle
ISRO
Mahindra
Siemens
Bosch
DuPont
Aditya Birla
Hindalco
Amazon
Indian Oil
ITC
Asian Paints
Dr. Reddy
Kia
Bureau Veritas
Lloyd
Halliburton
Jindal Steel
AMNS
Rolls Royce
Why this matters

Why SIL determination + SIS design are usually badly separated · and why that costs

SIL determination (the what's required) and SIS design (the how to implement) are often done by different parties · the safety consultant determines SIL, the I&C contractor designs the SIS. Result: gaps. The SIL was determined assuming a 1oo1 architecture but the I&C contractor proposes 1oo2 (over-engineered). The SIS uses sensors with worse PFD than the SIL assumed (under-engineered). We do both in one engagement so the SIL assumption and the SIS architecture are consistent.

Method

How we deliver SIL Determination + SIS Design

CEng MIE India-signed deliverables · LiDAR-powered where applicable · digital twin handover ready · routes to the Risk + Safety + AMC practice lead within 24 hours.

01

SIL determination

Risk graph (qualitative · for low complexity), LOPA (semi-quantitative · most common), or fault tree (quantitative · for SIL 3+) per IEC 61511 Part 3.

02

SIS architecture design

Sensor (1oo1, 1oo2, 2oo3), logic solver (single, redundant, TÜV-certified), final element (1oo1, 1oo2) per SIL requirement. Voting logic + diagnostic coverage specified.

03

PFD calculation

Probability of Failure on Demand computed per IEC 61508 Part 6 formulas. Validated against target SIL band. Markov modelling for complex architectures.

04

Proof test interval + procedure

Proof test interval (1-5 years typical) selected. Detailed proof test procedure documented · including override management and bypass alarm rationalisation.

05

Sign-off + handover

CEng MIE-signed SIL determination + SIS architecture pack. Ready for I&C contractor procurement or in-house engineering.

Standards + compliance

Built to the standards your auditors quote

Reports reference the international and national standards your regulators, F500 audit teams, and corporate process safety leads cite. Every deliverable signed by a Chartered Engineer (CEng MIE India).

Anonymous case anchors

What this looks like in production

Three landmark engagements from our verified roster · quantified outcomes, no client names disclosed without written permission.

Refinery, India · hydrocracker SIS

14 safety functions · 11 SIL 2, 3 SIL 3. Architecture: SIL 2 = 1oo2 sensors, single TÜV-certified PLC, 1oo1 final. SIL 3 = 2oo3 sensors, redundant PLC, 1oo2 final. PFD validated.

Petrochem, KSA · ethylene cracker

SIS specification for 27 safety functions on new cracker. Aramco SAES-J-001 compliance. TÜV-certified PLC procurement specification.

LNG, Qatar · ESD-1/ESD-2 system

Emergency Shutdown Levels 1 + 2 designed to SIL 3. Proof test procedure + bypass alarm rationalisation delivered.

Frequently asked

SIL Determination + SIS Design · the practical questions

Do you do SIL + SIS, or only one of them?
Both. They're tightly coupled · doing them in one engagement avoids the consistency gap that shows up when they're done separately.
What's the link to LOPA?
LOPA is the most common SIL determination method (semi-quantitative). LOPA output (residual frequency gap) maps directly to SIL band. For very high complexity or SIL 3+, fault tree is the method · still informed by LOPA-style logic.
Can you specify the SIS hardware?
Yes · TÜV-certified PLC make/model shortlist (tier-1 SIS platforms RS, Siemens S7 F, tier-1 platform SafetyManager, ABB AC800M HI, Triconex). Sensor brands shortlisted per certification class. Final element selection by failure-rate match to PFD target.
How long is a typical SIL + SIS design engagement?
Small block (5-10 safety functions): 8-12 weeks. Full process unit (20-50 functions): 16-24 weeks. Time-driven by the SIL determination workshops + PFD calculation iterations.
Do you provide proof test procedures?
Yes · detailed proof test step-by-step procedure for each safety function, including override management, bypass alarm rationalisation, and post-test acceptance criteria. Critical for actually maintaining SIL after commissioning.

Scope your SIL Determination + SIS Design engagement.

Tell us your plant, region, and scope · a named Chartered Engineer responds within 24 hours.

  • 4 fields. No phone interview to start.
  • Per-discipline routing to the Risk + Safety + AMC practice lead.
  • Anonymous case anchors sent with first reply.
  • Same-day callback for deadline-driven enquiries.

Risk + Safety + AMC Scoping

HAZOP/LOPA/SIL/QRA · 5-year AMC retainer · Practice Lead Safety responds in 24 hr.