IEC 61508 — SIL, PFD and fault tree analysis
IEC 61508 is the parent standard for functional safety of electrical, electronic and programmable electronic systems, and the source of the Safety Integrity Level vocabulary that ISO 26262, EN 50126, IEC 61511 and IEC 62061 all descend from. It names fault tree analysis as a technique for quantifying whether a safety function meets its target. This page covers what the target actually is, why demand mode changes the arithmetic, and where the fault tree does and does not carry the argument.
What a SIL is, and what it is not
A Safety Integrity Level is a property of a safety function, not of a component, a product or a company. "SIL 2 transmitter" is shorthand at best: the device may be suitable for use in a SIL 2 function given a particular architecture, proof-test interval and demand rate. Change any of those and the claim changes with it.
The level is expressed as a probability target, and which target applies depends on how often the function is called upon:
| SIL | Low demand — PFDavg | High demand / continuous — PFH (per hour) |
|---|---|---|
| SIL 4 | ≥ 10⁻⁵ to < 10⁻⁴ | ≥ 10⁻⁹ to < 10⁻⁸ |
| SIL 3 | ≥ 10⁻⁴ to < 10⁻³ | ≥ 10⁻⁸ to < 10⁻⁷ |
| SIL 2 | ≥ 10⁻³ to < 10⁻² | ≥ 10⁻⁷ to < 10⁻⁶ |
| SIL 1 | ≥ 10⁻² to < 10⁻¹ | ≥ 10⁻⁶ to < 10⁻⁵ |
Low demand means the function is called on less than once a year — a shutdown system that sits dormant until something goes wrong. The quantity of interest is the probability it fails to act when asked, averaged over the proof-test interval, because between tests an undetected dangerous failure simply accumulates. High demand or continuous means the function is doing its job all the time, so the quantity is a dangerous failure rate per hour. Reporting a PFD against a PFH target, or the reverse, is not a rounding error — the two differ by orders of magnitude and by dimension.
Our λ to PFD calculator does this conversion for both modes and reads off the band, which is usually quicker than deriving it by hand for a first sanity check.
Where the fault tree fits
IEC 61508-6 offers several routes to a PFD figure: simplified equations, Markov models, reliability block diagrams and fault tree analysis. The fault tree earns its place when the architecture is not a clean series-parallel arrangement — when a diagnostic channel is shared, when one element appears in two paths, or when common-cause failures couple branches that the block diagram draws as independent.
The construction is bottom-up from the safety function's failure: the top event is "safety function fails to perform on demand", the intermediate gates are the sensor, logic-solver and final-element subsystems, and the basic events are dangerous undetected failures of each element over the proof-test interval. Minimal cut sets then tell you which single failures or pairs defeat the function — and a single-element cut set in a function claiming SIL 2 or above is usually an architecture problem, not a numbers problem.
The three things a fault tree does not settle
Quantification is one leg of a SIL claim. IEC 61508 imposes two others, and a tree that meets its target while ignoring them supports nothing.
Architectural constraints
Safe failure fraction and hardware fault tolerance impose a ceiling on the SIL that an architecture may claim, regardless of how good the computed PFD is. A 1oo1 arrangement with a low safe failure fraction cannot claim SIL 3 no matter what the arithmetic says. This is a deliberate hedge against over-confidence in failure-rate data, and it is checked separately from the probability calculation.
Systematic capability
The probability targets above address random hardware failures. Design faults, specification errors and software defects are not random and are not modelled by a failure rate. IEC 61508 handles them through lifecycle rigour — techniques, documentation and independence of assessment that ratchet up with the SIL. No fault tree addresses this leg at all.
Common cause
Redundancy is worth what its independence is worth. A 1oo2 arrangement of identical devices, in the same enclosure, on the same supply, calibrated by the same technician, is not two independent chances of success. IEC 61508-6 Annex D gives a scoring method for the beta factor; whatever value you land on, it belongs in the model. A tree with a redundant branch and no common-cause term will overstate the achieved SIL, often by more than the redundancy bought. The Beta-factor versus MGL guide covers when the simple model stops being adequate.
Proof testing, and why the average matters
For a low-demand function, PFDavg is an average over the proof-test interval, and for a simple element it is approximately λDU·τ/2 — half the interval, because on average a dangerous undetected failure has been present for half of it when the demand arrives. Two consequences follow, both of which show up in real projects.
First, the interval is a design parameter with the same weight as the hardware. Halving τ halves the PFD as surely as halving the failure rate does, and it is usually the cheaper lever. Second, the coverage of the proof test is part of the claim. A test that exercises the logic but never strokes the valve leaves a portion of the dangerous failures undetected no matter how often it runs, and that portion has to be modelled as a separate, un-tested contribution. An assumed-perfect proof test is one of the most common ways a SIL claim quietly fails.
How this relates to the domain standards
IEC 61508 is generic by design and expects sectors to specialise it. IEC 61511 does that for the process industries, adding LOPA to set the target and treating the end user as the integrator. ISO 26262 replaces SIL with ASIL, derived from severity, exposure and controllability rather than from a demand-rate calculation. EN 50126 and its companions do it for rail. IEC 62061 does it for machinery, alongside ISO 13849's Performance Levels.
Because the derivations differ, the levels are not interchangeable — see the ASIL ↔ DAL ↔ SIL crosswalk for where the correspondence holds and where treating it as a conversion goes wrong.
Doing this in FTA Studio
Set the project standard to IEC 61508 and the SIL verdict is computed against the bands above, in the demand mode you select. Basic events accept a dangerous undetected failure rate with a proof-test interval, so the λDU·τ/2 model is applied per element rather than assumed for the whole function. Common-cause groups carry a beta factor, importance measures rank which elements actually drive the result, and Monte Carlo propagates the uncertainty in the failure-rate data into a percentile band — which matters, because handbook λ values are estimates with error factors of three or more.