Functional Safety in Industrial Automation: What SIL Means, Why It Matters, and How Safety PLCs Work
When it comes to safety PLC automation, why Standard Automation Is Not Enough for Safety Functions
In a standard automation system, the PLC controls the process and also handles safety functions such as emergency shutdown (ESD) and safety interlocks. This approach has a fundamental vulnerability: if the PLC itself fails, due to a hardware fault, firmware error, or power supply anomaly, the safety function may also fail.
For processes where failure could result in injury, loss of life, environmental damage, or catastrophic equipment failure, this is not acceptable. Functional Safety engineering provides a framework for designing systems that maintain their safety function even in the presence of hardware and software failures.
The Standards Framework
Standard
Scope and Application
IEC 61508
Functional Safety of E/E/PE Systems, the foundational generic standard. Applies to all electrical, electronic, and programmable electronic systems used in safety functions.
IEC 61511
Functional Safety, Safety Instrumented Systems for the Process Industry (process plants, chemical, oil & gas). Derived from IEC 61508.
IEC 62061
Safety of Machinery, Functional safety of control systems. Applicable to machine builders and system integrators. Used for CNC, press, conveyor, and robot safety systems.
ISO 13849
Safety of Machinery, Safety related parts of control systems. Defines Performance Level (PL), a parallel framework to SIL used in machinery.
Safety Integrity Level (SIL): What It Actually Means
Safety Integrity Level (SIL) is a measure of the reliability of a safety function, specifically, the probability that the safety function will operate correctly on demand. For low demand safety functions, SIL bands are commonly expressed using average probability of failure on demand (PFDavg):
| SIL Level | PFD Range | Risk Reduction Factor |
|---|---|---|
| SIL 1 | ≥10⁻² to <10⁻¹ | >10 to 100 |
| SIL 2 | ≥10⁻³ to <10⁻² | >100 to 1,000 |
| SIL 3 | ≥10⁻⁴ to <10⁻³ | >1,000 to 10,000 |
| SIL 4 | ≥10⁻⁵ to <10⁻⁴ | >10,000 to 100,000 |
| The SIL requirement for a specific safety function is determined through a risk assessment process , typically HAZOP (Hazard and Operability Study) combined with LOPA (Layer of Protection Analysis). The required SIL is set based on the severity and likelihood of the hazard and the number of independent protection layers already in place. | The Safety Instrumented System (SIS): Architecture | A Safety Instrumented Function is commonly represented by three subsystems that must collectively achieve the required risk reduction: |
| Safety Sensor → Safety Logic Solver (Safety PLC) → Final Safety Element | The complete Safety Instrumented Function, sensor subsystem, logic solver, and final element subsystem, must achieve the required risk reduction. Component suitability, systematic capability, architecture, diagnostics, proof test interval, and failure data must be evaluated together. | • Safety sensors: suitably assessed transmitters and switches selected for the service. Voting architectures such as 1oo2 or 2oo3 may be used when justified by the hazard analysis, diagnostic coverage, spurious trip objectives, and proof test strategy |
- Safety logic solver: Siemens SIMATIC S71200F or S71500F controllers can execute failsafe logic in TIA Portal using STEP 7 Safety. The achievable integrity level depends on the complete certified system architecture and application design.
- Final safety elements: shutdown valves, solenoids, contactors, or other actuators selected and engineered for the required safe state. Final elements often dominate the probability of failure and therefore require careful diagnostics, proof testing, and maintenance.
Siemens SIMATIC Safety: How It Works in Practice
Fail-safe CPU (FCPU) Architecture
Siemens failsafe controllers use certified internal diagnostics, diverse safety mechanisms, and failsafe I/O monitoring to detect defined faults and transition the application to a safe state. Exact internal architecture varies by product family:
- Safety execution and diagnostics are designed to detect relevant internal faults within the certified product architecture
- Detected safety related faults cause the affected safety function or controller to transition to the configured safe response
- FI/O provides configurable channel diagnostics such as discrepancy, wire break, or short-circuit monitoring where supported by the selected module and wiring method
Safety Program Segregation
In TIA Portal, safety programs are physically and logically separated from standard automation programs. Safety Function Blocks (FFBs) have restricted data interfaces, safety data cannot be written by non-safety code. This architectural separation ensures that a bug in the standard control program cannot compromise the safety program.
Simple Safety Applications: SIRIUS Safety Relays
Not every safety function requires a Safety PLC. For simple machine safety applications, emergency stop buttons, light curtains, two hand control panels, and guard monitoring, Siemens SIRIUS 3SK safety relays provide a cost-effective, certified solution:
- SIRIUS 3SK safety relays: configurable solutions for emergency stop, guard monitoring, light curtains, and other defined machine safety functions
- Modular expansions: additional safe outputs and functions can be added where the selected 3SK architecture supports them
- Distributed safety options: selected Siemens safety products can integrate decentralized safety devices through supported safe communication architectures
Common Safety Functions in Indian Industrial Plants
Application
Typical SIL
Safety Function
Boiler Emergency Shutdown
SIL 2
Fuel valve closure on flame failure, high pressure, or low low water level
Chemical Reactor Runaway Protection
SIL 23
Cooling activation and feed valve closure on temperature excursion
Gas Leak Detection and ESD
SIL 2
Process shutdown on gas detector activation
Compressor High Vibration Trip
SIL 1
Compressor shutdown on excessive bearing vibration
Machine Guard Monitoring
PL d (SIL 2 equivalent)
Machinery stop on safety guard opening or Estop activation
Fire and Gas Suppression System
SIL 2
Automatic suppression activation on confirmed fire/gas alarm
Conclusion: Safety Is an Engineering Discipline, Not a Feature
Functional safety cannot be retrofitted by labelling a standard PLC as 'safety.' It requires certified hardware, certified software tools, structured risk assessment methodology, and engineers who understand both the process hazards and the safety standard requirements.
Formal functional safety practices are increasingly relevant across manufacturing and process industries. IEC 61511 is commonly applied to process sector safety instrumented systems, while IEC 62061 and ISO 13849 are widely used for machinery safety.
Suggested social hashtags: #FunctionalSafety #SIL #SafetyPLC #IEC61508 #IEC61511 #SiemensSafety #SIMATICF #SIRIUS #IndustrialSafety #ACSEngitech
About ACS Engitech Pvt. Ltd.
Since 2009, ACS Engitech has delivered automation solutions across manufacturing sectors. As a Siemens Channel Partner, we provide comprehensive automation systems including PLC panels, SCADA implementation, and remote monitoring solutions. Our 6000 sq. ft. manufacturing facility in Ahmedabad serves clients across India with ISO 9001-certified control panel solutions.
Take Action Today
Ready to optimize your facility? Connect with us to discuss how automation can improve your operations and address critical demands.
Connect With Us