PFDavg calculation: result precision and data uncertainty
In SIL verification, reporting the result of a PFDavg calculation with several decimal places can create a false sense of accuracy. Numerical precision does not mean that the result accurately represents the actual behaviour of the SIF.
Numerically meeting the PFDavg target is not enough to accept the result without reviewing that uncertainty. We need justified data and a defensible margin relative to the requirement.
For a safety instrumented function (SIF) operating in low demand mode, PFDavg represents the average probability of dangerous failure on demand. SIL verification estimates this value using a model and input data. Confidence in the result depends on both reflecting the actual conditions of the installation.
Where does uncertainty in PFDavg calculations come from?
Failure rates need context
Failure rates usually come from an FMEDA, a safety manual or a reliability database. Their applicability depends on process conditions, the environment, maintenance and the device's useful life.
A manufacturer's failure rate is not a universal constant. We must check the associated assumptions and limitations, particularly when using generic data or equipment exposed to demanding conditions.
Failures classified as dangerous detected, λDD, also need review. Diagnostic credit is valid only if the assumed detection and response are effective in the installation. Otherwise, the affected failures may need to be treated as dangerous undetected, λDU.
Proof test coverage must reflect the actual procedure
Proof test coverage, Cpt or PTC, represents the fraction of hidden dangerous failures that the procedure can detect.
A manufacturer may specify high coverage for a particular test. The plant, however, may carry out a different or more limited test, or one constrained by production requirements.
For example, if a valve must provide tight shut-off, checking that it reaches the closed position does not demonstrate that it meets the leakage requirement. If the specified leak test is not performed, we cannot automatically assume the manufacturer's stated coverage.
Cpt must represent the tests actually performed, with a justification linked to the failure modes.
The beta factor: redundancy does not eliminate dependencies
In redundant architectures, common cause failures can make a significant contribution to PFDavg and may even dominate the result.
The beta factor must reflect the actual dependencies between channels: process connections, power supplies, utilities, environmental exposure, physical separation and maintenance practices.
Using a familiar value from a table does not demonstrate that it is suitable for our installation. Apparently robust redundancy may deliver much less benefit than expected if its channels share causes of failure.
Testing, repair and ageing
The calculation must use proof test intervals and repair times that the plant can achieve. If tests are delayed or repairs take longer than assumed, the result becomes less representative.
We must also review the validity of failure rates when equipment exceeds the assumed useful life. A good operating history provides evidence, but does not by itself demonstrate that the original assumptions remain valid indefinitely.
Result precision: how much does the difference between two values matter?
Consider 2.70 × 10⁻³ and 3.10 × 10⁻³. The relative difference is approximately 15%. These are different values, but if input uncertainty exceeds that difference, they may represent very similar performance for engineering decision-making.
We should therefore not infer a meaningful improvement simply because one result is slightly lower. We need to establish that the difference corresponds to a real and significant improvement relative to the uncertainty.
When one value meets the requirement and the other does not, proximity to the target calls for particularly careful review.
A PFDavg of 9.00 × 10⁻³: within SIL 2, but with little margin
In low demand mode, 9.00 × 10⁻³ falls within the SIL 2 quantitative band, whose upper limit is 1.00 × 10⁻², excluded. However, an increase of just over 11% in the calculated result would be enough to exceed that limit.
That percentage does not estimate the SIF's uncertainty; it shows how small the available margin is.
As an engineering judgement, I would normally not accept that result against a target of 1.00 × 10⁻² without particularly strong justification. It could be defensible if the data and assumptions are conservative and documented, and the uncertainty assessment supports compliance. In practice, that conservatism must be demonstrated.
We must also compare the result with the specific SIF requirement. If the risk assessment requires a maximum PFDavg of 5.00 × 10⁻³, a result of 9.00 × 10⁻³ fails to meet the requirement, even though it falls within the SIL 2 band.
How can we establish a defensible PFDavg margin?
ISA-TR84.00.02-2022 explicitly addresses uncertainty and describes strategies such as using a design target lower than the required target, or a conservative estimate supported by the confidence available in the data.
No single margin percentage is appropriate for every SIF. It must be justified according to data quality and result sensitivity. A margin also does not correct omitted components, incorrectly modelled architectures or assumptions known to be invalid.
A practical check is to vary the most influential parameters within technically justified ranges: increase λDU or beta, reduce Cpt, or consider foreseeable testing delays. This helps identify which assumptions determine acceptance and where better data are needed.
This sensitivity analysis helps assess the robustness of the result, although it does not by itself provide a statistical confidence interval.
SILcet Cloud includes the SIF Sensitivity function to support sensitivity analysis and the exploration of design alternatives. SILcet REVIEW allows users to review SIL verification data, assumptions and results, and identify potential errors or inconsistencies through configurable checks. It can import SILcet Cloud projects and convert detailed exSILentia reports. Both tools support engineering review; justifying the data and deciding whether to accept the result require technical judgement.
SIL verification must remain valid during plant operation
Confidence in PFDavg requires checking during operation that testing, maintenance and service conditions still match the report's assumptions. Failure, test and repair records help validate and improve those assumptions.
The quality of SIL verification depends on the data, the model and the engineering judgement applied. The result must be a defensible estimate, with sufficient margin relative to the requirement and clearly documented conditions for its validity.
Reference: ISA-TR84.00.02-2022, Safety Integrity Level (SIL) Verification of Safety Instrumented Functions, Sections 4, 10.5, 10.8.3 and 11.4. PFDavg is one part of SIL verification; applicable architectural and systematic integrity requirements must also be satisfied.
