Thread Content
SH/T 3225-2024, \"Design Specifications for Safety Integrity Levels of Safety Instrumented Systems in the Petrochemical Industry,\" was issued on July 29, 2024, and came into effect on January 1, 2025. This standard is likely one of the highest-quality standards in China regarding the designation of SIL levels for safety instruments.
SH/T 3225-2024 requires that an LOPA analysis report be prepared in step 3 of the basic design phase, a SIL classification report in step 4, and SRS technical requirements in step 5. These reports are required for the design review of project safety facilities, trial production acceptance, verification for the issuance of safety licenses, and various safety inspections.
Both LOPA (Layer of Protection Analysis) and SIL (Safety Integrity Level) are risk analysis methods used in the field of process safety, but there are significant differences between them in terms of their core objectives, application scenarios, and analysis logic, as detailed below.
1. Definition and Core Purpose LOPA (Layer of Protection Analysis) is a semi-quantitative risk assessment method that identifies and evaluates the ability of existing protection measures (such as safety valves, alarm systems, operating procedures, etc.) to reduce risks in specific accident scenarios. It determines whether these existing protections are sufficient or whether additional protection measures (such as Safety Instrumented Systems SIS) are needed. Primary objective: Determine the initial risk in the accident scenario, assess the effectiveness of existing protective layers, and determine whether additional protective layers are needed to reduce the risk to an acceptable level.
SIL (Safety Integrity Level) is a metric used to assess a Safety Instrumented System’s ability to perform its safety functions within a specified time frame (it ranges from SIL1 to SIL4; the higher the level, the greater the requirement for risk reduction). SIL classification is determined by analyzing the level of risk reduction required for a specific Safety Instrumented Function (SIF) to establish its corresponding SIL level. Primary purpose: To provide clear performance requirements for the design, verification, and maintenance of Safety Instrumented Systems (SIS), ensuring that they can reduce specific risks to acceptable levels.
2. Application scenarios: LOPA is suitable for analyzing specific accident scenarios (such as material leaks, uncontrolled reactions, etc.) and assessing the overall risk control effectiveness of existing protection layers (including those that are not part of the SIS, such as the Basic Process Control System BPCS, safety valves, manual operations of emergency shutdown systems, etc.). It is commonly used to determine whether an SIS is necessary, as well as the risk reduction tasks that the SIS must undertake (providing input for SIL classification).
The SIL classification applies only to the safety instrument functions (SIF) within a safety instrumented system (SIS), such as emergency shutdown and interlock protection. Based on the results of LOPA or other risk analyses, the required level of risk reduction for the SIF is determined, which in turn defines its SIL level (for example, SIL2 requires a risk reduction of 10 to 100 times).
3. Analysis logic and output: The analysis logic of LOPA: 1. Identify the initial risks of specific accident scenarios (such as occurrence frequency and severity of consequences). 2. List the existing protection layers (such as engineering controls, management measures, SIS, etc.) and calculate the risk reduction factor (RRF) for each protection layer. 3. Calculate the residual risk after applying the protective measures, and compare it with the enterprise’s acceptable risk criteria: – If the residual risk is acceptable, no additional actions are required ; - If it is not acceptable, a new protective layer (such as SIS) must be added, and the amount of risk reduction that this protective layer needs to provide must be determined.
Analysis logic for SIL grading: 1. For the risk scenarios that require SIS control (usually identified by LOPA), define the specific tasks of the safety instrument functions (SIFs) (such as \"emergency shutdown of the process when the reaction temperature is too high\"). 2. Calculate the Risk Reduction Factor (RRF) required for that SIF, and use industry standards (such as IEC 61511) to determine the corresponding SIL level (for example, RRF=100 corresponds to SIL2). 3. Output the SIL level of the SIF, which serves as a basis for SIS design, selection, and verification.
Relationship: LOPA is an important input for SIL classification (providing the risk reduction requirements needed for SIF), while SIL classification represents the specific actions to be taken for the SIS as a result of the LOPA analysis.
LOPA is about \"determining whether an SIS is needed and how much risk reduction is required\", while SIL classification is about \"defining the specific performance level that the SIS must achieve\"; the two complement each other and work together to control process safety risks.