28 — Calculators
Calculate the PFD of a safety function
In low demand mode a safety function is measured by its average probability of a dangerous failure on demand, the PFD. It always consists of three links — sensor, logic solver, final element — and its PFD is the sum of the three. Look at only one of them and the answer comes out too favourable.
Result
- PFD of the safety functionSum of sensor, logic solver and final element
- —
- SIL range reached
- —
- Sensor contribution
- —
- Logic solver contribution
- —
- Final element contribution
- —
- Largest contribution
- —
- Share of the largest contribution
- —%
Please fill all fields with valid numbers.
- Opens the print dialog. Choose “Save as PDF” as the destination.
- Opens your email program with the values from this calculation. Nothing is sent to us until you send it yourself.
A guide, not a design to standard. We give no warranty for the correctness of the results, the applicable standards and case-by-case verification govern.
Worked example
The default case the calculator starts with, worked through once. Change the values above and it recalculates immediately.
Inputs
- Proof test interval T₁ in years
- 1
- Common cause failures β
- 2 %
- Sensor – architecture
- 1oo2 – two channels, one is enough
- Sensor – failure rate λ_du
- 300 FIT
- Logic solver – architecture
- 1oo2 – two channels, one is enough
- Logic solver – failure rate λ_du
- 100 FIT
- Final element – architecture
- 1oo1 – single channel
- Final element – failure rate λ_du
- 800 FIT
Result
- PFD of the safety function
- 3.54 · 10⁻³
- SIL range reached
- SIL 2 (PFD from 10⁻³ to below 10⁻²), provided the architectural constraints are met.
- Sensor contribution
- 2.85 · 10⁻⁵
- Logic solver contribution
- 9.01 · 10⁻⁶
- Final element contribution
- 3.50 · 10⁻³
- Largest contribution
- The final element governs the result. That is the usual case — this is where the mechanics are, and where failure rates are highest.
- Share of the largest contribution
- 98.9 %
Formula
- PFD = PFD_sensor + PFD_logic + PFD_final element
- per subsystem, 1oo1: PFD = λ_du · T₁ / 2
- 2oo2: PFD = λ_du · T₁
- 1oo2: PFD = ((1−β) · λ_du · T₁)² / 3 + β · λ_du · T₁ / 2
- 2oo3: PFD = ((1−β) · λ_du · T₁)² + β · λ_du · T₁ / 2
- 1oo3: PFD = ((1−β) · λ_du · T₁)³ / 4 + β · λ_du · T₁ / 2
Assumptions and standards
- Simplified equations to IEC 61508-6 Annex B, as also used by VDI/VDE 2180 Part 3. They hold for small values of λ_du · T₁ and become inaccurate as the product approaches 1.
- Proof test interval and β apply to all three subsystems here. In practice they can differ — a valve is often tested differently from a transmitter. A shared assumption is common for a first estimate, but not for a verification.
- The calculation assumes no diagnostics and no repair time: λ_du covers dangerous undetected failures only. The result is therefore on the safe side.
- The common cause share behaves like a single-channel system and cannot be reduced by adding channels. Above a certain β it governs a subsystem on its own.
- THIS CALCULATOR DOES NOT DETERMINE A SIL. The achievable level also depends on the architectural constraints of IEC 61508-2 – hardware fault tolerance (HFT) and safe failure fraction (SFF) – and on systematic capability. The PFD is a necessary, not a sufficient condition.
Frequently asked
Why is looking at the sensor not enough?
Because the safety function is a chain: it detects (sensor), decides (logic solver) and acts (final element). If one link fails the function does not work, however good the others are. That is why the three PFD values are added — and why in practice the weakest link almost always governs the result.
Why is the final element usually the largest contribution?
Because that is where the mechanics are. A safety valve with its solenoid has failure rates an order of magnitude above a transmitter or a safety controller, and it is rarely made redundant. A second sensor then improves nothing — the calculation shows this immediately in the contribution share.
What do 1oo1, 1oo2 and 2oo3 mean?
MooN means M out of N channels have to perform the safety function for it to act. 1oo2 has two channels and one is enough — that raises safety but also the number of spurious trips. 2oo2 requires both channels and doubles the probability of failure compared with 1oo1; it protects against spurious trips, not against failure. 2oo3 is the usual compromise.
Where do I get λ_du?
From the device safety manual, often as part of the SIL certificate. It usually gives a breakdown into λ_sd, λ_su, λ_dd and λ_du. Only λ_du counts here: the dangerous failures no diagnostic detects.
Does this replace a SIL verification?
No. The calculator works with simplified assumptions, one shared proof test interval and no diagnostics. A verification treats each subsystem with its own boundary conditions, checks the architectural constraints of IEC 61508-2 and systematic capability, and is documented. That is work we support.
Calculating is the easy part.
A formula gives you a number. Designing a plant also demands installation method, grouping, discrimination, the standards in force and a look at the installed base. That is what we take on.
More tools
- 01Cable cross-section
- 02Voltage drop
- 03Cable resistance
- 04Cable losses
- 05Maximum cable length
- 06Current-carrying capacity
- 07Parallel cables
- 08Conductor temperature
- 09Cable capacitance
- 10Short-circuit current
- 11Cable impedance
- 12Network impedance
- 13Short-circuit current at the far end
- 14Thermal short-circuit withstand
- 15Length and disconnection
- 16Motor current
- 17Torque
- 18Starting current
- 19Star-delta starting
- 20Soft starting
- 21Motor efficiency
- 22Speed control instead of throttling
- 23Speed and slip
- 24Setting the motor protection
- 25Single-phase motor
- 26Motor feeder
- 27Required motor rating
- 29PFH and SIL
- 30Protective conductor size
- 31Earth rod
- 32Touch voltage
- 33Residual current protection
- 34Check discrimination
- 35Connecting a surge arrester
- 36Enclosure cooling
- 37Reference designation
- 38Reactive power compensation
Contact
Tell us what it is about.
A phone call or three lines is enough. From the very start you talk to the people who will later work on your project, not to a distribution list.
Direct
- Phone+49 (0) 5247 4070-66
- Emailinfo@fisekon.com
- AvailabilityMon – Fri, 8:00 – 17:00 CET
Locations
33428 Marienfeld (Harsewinkel)Gütersloh officeWagenfeldstr. 2
33332 Gütersloh
Or write to us
We usually reply within one working day.
