FISEKON GmbH – Fischer Elektrokonstruktion

29 — Calculators

Calculate the PFH of a safety function

When a safety function is demanded more than once a year, or runs continuously, the probability on demand is no longer the useful measure. What counts then is how often the function fails dangerously per hour: the PFH. It too is the sum over sensor, logic solver and final element.

Input

Only affects multi-channel subsystems: it sets how long an undetected failure in the first channel goes unnoticed before the second one joins it.

Share of failures that hit all channels of a subsystem at once. Typically 1 % to 10 %. No effect on 1oo1 and 2oo2.

Transmitters, limit switches, pressure switches. The figure is in the device safety manual.

Safety controller or isolating amplifier. Usually the smallest of the three contributions.

Valve including solenoid, contactor, drive. In process industry almost always the largest contribution.

Result

PFH of the safety functionSum of sensor, logic solver and final element
1/h
SIL range reached
Sensor contribution
1/h
Logic solver contribution
1/h
Final element contribution
1/h
Largest contribution
Share of the largest contribution
%

A guide, not a design to standard. We give no warranty for the correctness of the results, the applicable standards and case-by-case verification govern.

Worked example

The default case the calculator starts with, worked through once. Change the values above and it recalculates immediately.

Inputs

Proof test interval T₁ in years
1
Common cause failures β
2 %
Sensor – architecture
1oo2 – two channels, one is enough
Sensor – failure rate λ_du
300 FIT
Logic solver – architecture
1oo2 – two channels, one is enough
Logic solver – failure rate λ_du
100 FIT
Final element – architecture
1oo1 – single channel
Final element – failure rate λ_du
800 FIT

Result

PFH of the safety function
8.09 · 10⁻⁷ 1/h
SIL range reached
SIL 2 (PFH from 10⁻⁷ to below 10⁻⁶ per hour), provided the architectural constraints are met.
Sensor contribution
6.76 · 10⁻⁹ 1/h
Logic solver contribution
2.08 · 10⁻⁹ 1/h
Final element contribution
8.00 · 10⁻⁷ 1/h
Largest contribution
The final element governs the result. That is the usual case — this is where the mechanics are, and where failure rates are highest.
Share of the largest contribution
98.9 %

Formula

  • PFH = PFH_sensor + PFH_logic + PFH_final element
  • per subsystem, 1oo1: PFH = λ_du
  • 2oo2: PFH = 2 · λ_du
  • 1oo2: PFH = 2 · ((1−β) · λ_du)² · t_CE + β · λ_du
  • 2oo3: PFH = 6 · ((1−β) · λ_du)² · t_CE + β · λ_du
  • t_CE = T₁ / 2 (without diagnostics)

Assumptions and standards

  • Simplified equations to IEC 61508-6 Annex B. Without diagnostics the mean time in the failed state t_CE equals half the proof test interval.
  • The 1oo3 architecture is deliberately absent: the simplified form has no equally established equation for it. A value that is only roughly right is of no help in a safety assessment.
  • Proof test interval and β apply to all three subsystems. In practice they can differ; a shared assumption is common for a first estimate, but not for a verification.
  • For 1oo1 and 2oo2 neither the proof test interval nor β has any effect — a single-channel subsystem fails at its rate, a 2oo2 subsystem at twice that.
  • THIS CALCULATOR DOES NOT DETERMINE A SIL. The achievable level also depends on the architectural constraints of IEC 61508-2 and on systematic capability.

Frequently asked

PFD or PFH — which applies to my plant?

It depends on the demand rate. If the safety function is demanded at most once a year and no more than half as often as it is proof tested, low demand mode applies and with it the PFD. Anything above that — and every function that runs continuously — is assessed by PFH. Process industry mostly works with PFD, machinery with PFH.

Why is looking at one subsystem not enough?

Because the safety function is a chain: it detects, decides and acts. If one link fails the function does not work. That is why the three values are added — and why in practice the weakest link almost always governs the result, usually the final element.

Why is PFH for 2oo2 twice that of 1oo1?

Because 2oo2 needs both channels for the safety function: if one fails, the function is gone. Two channels then mean twice as many opportunities for that. 2oo2 protects against spurious trips, not against failure — safety calls for 1oo2 or 2oo3.

Why does the proof test interval matter less here than for PFD?

Because for PFH it only affects the multi-channel part: it sets how long an undetected failure in the first channel sits there before the second one joins it. The common cause share does not depend on the interval at all and soon dominates multi-channel subsystems.

Does this replace a SIL verification?

No. The calculator works with simplified assumptions and no diagnostics. A verification treats each subsystem with its own boundary conditions, checks the architectural constraints of IEC 61508-2 and systematic capability, and is documented. That is work we support.

Calculating is the easy part.

A formula gives you a number. Designing a plant also demands installation method, grouping, discrimination, the standards in force and a look at the installed base. That is what we take on.

Discuss a project

Contact

Tell us what it is about.

A phone call or three lines is enough. From the very start you talk to the people who will later work on your project, not to a distribution list.

Direct

Locations

Registered office and postal addressStellmacherstr. 7
33428 Marienfeld (Harsewinkel)
Gütersloh officeWagenfeldstr. 2
33332 Gütersloh

Or write to us

We usually reply within one working day.

Write email

Opens your email program with the message already written. Read it, change whatever you like, and send it yourself — from your mailbox to ours.

Go to the contact form