FISEKON GmbH – Fischer Elektrokonstruktion

28 — Calculators

Calculate the PFD of a safety function

In low demand mode a safety function is measured by its average probability of a dangerous failure on demand, the PFD. It always consists of three links — sensor, logic solver, final element — and its PFD is the sum of the three. Look at only one of them and the answer comes out too favourable.

Input

How often the safety function is fully tested. It enters the result linearly and is often the most effective adjustment.

Share of failures that hit all channels of a subsystem at once. Typically 1 % to 10 %. No effect on 1oo1 and 2oo2.

Transmitters, limit switches, pressure switches. The figure is in the device safety manual.

Safety controller or isolating amplifier. Usually the smallest of the three contributions.

Valve including solenoid, contactor, drive. In process industry almost always the largest contribution.

Result

PFD of the safety functionSum of sensor, logic solver and final element
SIL range reached
Sensor contribution
Logic solver contribution
Final element contribution
Largest contribution
Share of the largest contribution
%

A guide, not a design to standard. We give no warranty for the correctness of the results, the applicable standards and case-by-case verification govern.

Worked example

The default case the calculator starts with, worked through once. Change the values above and it recalculates immediately.

Inputs

Proof test interval T₁ in years
1
Common cause failures β
2 %
Sensor – architecture
1oo2 – two channels, one is enough
Sensor – failure rate λ_du
300 FIT
Logic solver – architecture
1oo2 – two channels, one is enough
Logic solver – failure rate λ_du
100 FIT
Final element – architecture
1oo1 – single channel
Final element – failure rate λ_du
800 FIT

Result

PFD of the safety function
3.54 · 10⁻³
SIL range reached
SIL 2 (PFD from 10⁻³ to below 10⁻²), provided the architectural constraints are met.
Sensor contribution
2.85 · 10⁻⁵
Logic solver contribution
9.01 · 10⁻⁶
Final element contribution
3.50 · 10⁻³
Largest contribution
The final element governs the result. That is the usual case — this is where the mechanics are, and where failure rates are highest.
Share of the largest contribution
98.9 %

Formula

  • PFD = PFD_sensor + PFD_logic + PFD_final element
  • per subsystem, 1oo1: PFD = λ_du · T₁ / 2
  • 2oo2: PFD = λ_du · T₁
  • 1oo2: PFD = ((1−β) · λ_du · T₁)² / 3 + β · λ_du · T₁ / 2
  • 2oo3: PFD = ((1−β) · λ_du · T₁)² + β · λ_du · T₁ / 2
  • 1oo3: PFD = ((1−β) · λ_du · T₁)³ / 4 + β · λ_du · T₁ / 2

Assumptions and standards

  • Simplified equations to IEC 61508-6 Annex B, as also used by VDI/VDE 2180 Part 3. They hold for small values of λ_du · T₁ and become inaccurate as the product approaches 1.
  • Proof test interval and β apply to all three subsystems here. In practice they can differ — a valve is often tested differently from a transmitter. A shared assumption is common for a first estimate, but not for a verification.
  • The calculation assumes no diagnostics and no repair time: λ_du covers dangerous undetected failures only. The result is therefore on the safe side.
  • The common cause share behaves like a single-channel system and cannot be reduced by adding channels. Above a certain β it governs a subsystem on its own.
  • THIS CALCULATOR DOES NOT DETERMINE A SIL. The achievable level also depends on the architectural constraints of IEC 61508-2 – hardware fault tolerance (HFT) and safe failure fraction (SFF) – and on systematic capability. The PFD is a necessary, not a sufficient condition.

Frequently asked

Why is looking at the sensor not enough?

Because the safety function is a chain: it detects (sensor), decides (logic solver) and acts (final element). If one link fails the function does not work, however good the others are. That is why the three PFD values are added — and why in practice the weakest link almost always governs the result.

Why is the final element usually the largest contribution?

Because that is where the mechanics are. A safety valve with its solenoid has failure rates an order of magnitude above a transmitter or a safety controller, and it is rarely made redundant. A second sensor then improves nothing — the calculation shows this immediately in the contribution share.

What do 1oo1, 1oo2 and 2oo3 mean?

MooN means M out of N channels have to perform the safety function for it to act. 1oo2 has two channels and one is enough — that raises safety but also the number of spurious trips. 2oo2 requires both channels and doubles the probability of failure compared with 1oo1; it protects against spurious trips, not against failure. 2oo3 is the usual compromise.

Where do I get λ_du?

From the device safety manual, often as part of the SIL certificate. It usually gives a breakdown into λ_sd, λ_su, λ_dd and λ_du. Only λ_du counts here: the dangerous failures no diagnostic detects.

Does this replace a SIL verification?

No. The calculator works with simplified assumptions, one shared proof test interval and no diagnostics. A verification treats each subsystem with its own boundary conditions, checks the architectural constraints of IEC 61508-2 and systematic capability, and is documented. That is work we support.

Calculating is the easy part.

A formula gives you a number. Designing a plant also demands installation method, grouping, discrimination, the standards in force and a look at the installed base. That is what we take on.

Discuss a project

Contact

Tell us what it is about.

A phone call or three lines is enough. From the very start you talk to the people who will later work on your project, not to a distribution list.

Direct

Locations

Registered office and postal addressStellmacherstr. 7
33428 Marienfeld (Harsewinkel)
Gütersloh officeWagenfeldstr. 2
33332 Gütersloh

Or write to us

We usually reply within one working day.

Write email

Opens your email program with the message already written. Read it, change whatever you like, and send it yourself — from your mailbox to ours.

Go to the contact form