How Reliable is Reliable Enough? LOPA will help!

LOPA is the industry recognised method for determining reliability requirements for safety trips. OTECSA can help demystify this.

How Reliable is Reliable Enough? Since the Buncefield disaster in 2005, the Health and Safety Executive has put an increasing focus on the quality and rigour shown in SIL determination studies, which are used to ensure critical trip systems are reliable enough to protect against high severity events.

We are often asked to assess or specify safety trips as part of risk assessments or through the design processes we deliver for clients. Often there is an assumption that a safety trip will need to be “independent” of the normal control system but with no appreciation of how reliable they actually need to be.

The reliability of safety trips needs to be established as part of the design process and the best practice method defined by the HSE in the UK for this is with Layers of Protection Analysis (LOPA).

Reliability and LOPA

LOPA studies follow on from a Hazard and Operability Study, which will have defined the consequences and severity of an event, as well as all the safeguards protecting against the event. The LOPA is then used for “SIL determination” to understand the reliability requirements of the safety trip.

We recommend taking any scenarios to LOPA if they result in a potential fatality event, with an instrumented system protecting against the event escalation. LOPA then takes those events and focusses on the independence of each “layer” to determine how far from a “Broadly Acceptable” risk the design currently is. This includes consideration of many factors, including operator responses, control system alarms and trips, mechanical design safeguards (e.g. relief valves or bursting discs in the case of over-pressure events) and other conditions such as occupancy factors and likelihood of ignition (in the case of fire or explosion events).

There is a common misconception that if an instrument or device is stated as being “SIL rated” that the requirements stop there. However it is the whole control loop including sensing element, logic solver and final element that needs to be considered and shown to be reliable enough to meet the SIL rating and probability of failure on demand identified in LOPA.

Assistance with SIL Determination

We recognise that that SIL determination can be daunting for clients. It requires specialised methods and expert practitioners not often held within engineering teams.

That’s why we help our clients understand and comply with the HSE demands for functional safety compliance, including IEC 61511 and IEC 61508, depending on your needs:

  • Plan your process safety management procedures and processes, to ensure you are clear on the route to compliance and ongoing management
  • Help define hazardous scenarios and quantify the severity of events e.g through Hazard Studies
  • Determine the reliability requirements of your critical trip systems using risk graphs or LOPA (layers of protection analysis)
  • Follow through with assistance in carrying out any Functional Safety design requirements, through our network of contacts in industry

We are trained in the main SIL determination methods such as risk graphs, LOPA and fault tree analysis and have carried out multiple broad ranging SIL studies for clients, often following on naturally from facilitating hazard studies (HAZOP).

Our links to qualified and experienced functional safety engineers and design organisations means you could be on the journey to functional safety compliance in a few easy steps.