CASE
STUDY

Category: Oil & Gas

CLOSING THE SIL GAP:
BUILDING A COMPLIANT FUNCTIONAL SAFETY PROGRAM FOR A REFINERY OPERATOR

Summary

How a North American refinery operator moved from undocumented, unverified safety instrumented functions to a fully governed IEC 61511 functional safety lifecycle, with a complete SIL verification, a defensible safety case, and a functional safety management program that holds up to audit.

At a Glance
Challenge Solution Result
Safety instrumented functions in service with no verified SIL and no traceable safety requirements Full IEC 61511 safety lifecycle assessment, from hazard review through SIL verification Every SIF assigned a verified, documented SIL with a defensible engineering basis
No functional safety management system; safety activities managed informally and in silos A functional safety management program defining ownership, competence, and change control Auditable FSM program with clear accountability across the safety lifecycle
Unclear compliance position under IEC 61511 and OSHA PSM ahead of an audit Traceable safety case linking hazards to functions, SILs, and verification evidence Documented, audit-ready compliance posture and a prioritized remediation roadmap

Project Background

A North American refinery operator running multiple safety instrumented systems across its process units needed to establish a defensible functional safety position. Safety instrumented functions had been installed over many years, but their required Safety Integrity Levels had never been formally verified, and the safety requirements behind them were not traceable. With an OSHA Process Safety Management audit approaching and internal uncertainty about whether the installed protection layers actually met their targets, leadership had no consolidated view of functional safety risk. The operator engaged Arista Cyber to assess the full safety lifecycle against IEC 61511 and build a governed program the organization could stand behind.

Challenge

Unverified SILs, an Undocumented Safety Case, and No Functional Safety Governance

The operator's safety instrumented systems had grown organically. Safety instrumented functions were in service across several process units, but no one could demonstrate that each function actually achieved the Safety Integrity Level its risk reduction depended on. SIL targets had been assigned years earlier, in some cases without a documented determination, and no verification calculations existed to confirm that the installed sensors, logic solvers, and final elements met those targets in practice.

The safety requirements specification, the document that should link each identified hazard to the safety function addressing it and the SIL required, was incomplete or missing for several functions. Proof test intervals were inconsistent and not always tied to the assumptions behind the original SIL. Modifications had been made to the process over time without a structured assessment of their functional safety impact, meaning earlier determinations may have been silently invalidated.

Underlying all of this was the absence of a functional safety management system. Responsibility for safety lifecycle activities was diffuse, competence was assumed rather than assured, and there was no change-control discipline governing how modifications were assessed. With an OSHA PSM audit approaching, leadership could not produce a traceable safety case, and had no structured basis for prioritizing the gaps that mattered most.

Solution

A Full IEC 61511 Lifecycle Assessment and a Governed Functional Safety Program

Arista Cyber conducted a structured, engineering-led functional safety engagement, working directly with the operator's process safety, instrumentation, operations, and maintenance teams to assess the safety lifecycle as it actually operated, not as documentation assumed.

The engagement covered seven phases:

01

Hazard & Safety Function Review

Reviewed existing HAZOP and LOPA studies to validate each identified hazard, associated safety function, and expected risk reduction. This established the basis for all subsequent SIL targets.

02

Safety Requirements Specification

Developed or rebuilt a traceable safety requirements specification for every safety instrumented function, capturing hazards, required SIL, process safety time, and all functional and integrity requirements in a single auditable record.

03

SIL Verification

Completed verification calculations for each SIF loop—covering sensor, logic solver, and final element—to confirm installed architecture achieved its target SIL, factoring in device failure rates, proof test intervals, and common-cause risks.

04

Gap & Shortfall Analysis

Pinpointed functions failing to meet SIL targets or lacking adequate evidence, differentiating between true integrity shortfalls and those related to documentation or proof test discrepancies.

05

Functional Safety Management Design

Established a governed functional safety management program, assigning responsibility for lifecycle activities, defining competence standards, implementing proof test oversight, and setting up a robust management of change process to ensure ongoing validity.

06

Safety Case Consolidation

Consolidated hazards, safety functions, SIL assignments, verification findings, and proof test regimes into a single traceable safety case, providing a continuous chain of evidence for auditors and engineers.

07

Remediation Roadmap

Created a prioritized remediation roadmap, sequencing hardware upgrades, proof-test updates, and documentation improvements by assessed risk, enabling gap closure without interrupting production.

Result

Verified SILs, a Defensible Safety Case, and an Audit-Ready FSM Program

Arista Cyber delivered a complete functional safety assessment, a traceable safety case, and a functional safety management program that gave the operator its first consolidated, defensible view of functional safety risk across its process units.

Every safety instrumented function was assigned a verified Safety Integrity Level supported by documented calculations, replacing years of assumed compliance with demonstrable engineering evidence. The verification work identified specific functions where the installed architecture fell short of its target, exposure that had previously gone unacknowledged, and the gap analysis separated true integrity shortfalls from documentation issues so remediation effort went where risk actually was.

The functional safety management program resolved the governance vacuum, establishing clear ownership, competence assurance, and a management-of-change discipline so the safety case would remain valid as the process evolved rather than decaying after the engagement. The consolidated safety case gave the operator a traceable chain from every hazard to its safety function, SIL, and verification evidence, exactly the form of documentation an OSHA PSM and IEC 61511 audit examines.

The client entered its audit with a documented, defensible compliance posture, a prioritized roadmap for closing the remaining shortfalls, and a governance foundation capable of sustaining functional safety maturity over the long term, with the assurance that its protection layers genuinely deliver the risk reduction the plant depends on.

Who Should Engage Arista Cyber?

Process safety leaders, operations managers, and engineering teams in refining, petrochemical, chemical, and other process industries who need assurance that their safety instrumented systems genuinely meet their required integrity levels, and a governed functional safety program they can defend to auditors and regulators.

What's the Next Step?

  • Schedule a Functional Safety Lifecycle Assessment
  • Commission SIL Verification for your safety instrumented functions
  • Build or strengthen your Functional Safety Management program

Ready to establish a defensible functional safety position for your operation? Contact Arista Cyber to schedule a Functional Safety Assessment.

BOOK YOUR CONSULTATION