LOPA, Layer of Protection Analysis.
LOPA, Layer of Protection Analysis is the semi-quantitative process safety technique used to determine whether the existing layers of protection adequately reduce the risk of a hazardous scenario, and if not, what additional independent protection layer, typically a new safety instrumented function is required. LOPA takes a hazardous scenario identified by HAZOP as input, identifies the initiating event frequency and the existing layers of protection, each with a probability of failure on demand, and calculates the residual risk. The required risk reduction factor, RRF drives the target SIL of any new SIF.
What LOPA, Layer of Protection Analysis means.
LOPA emerged from CCPS, Center for Chemical Process Safety guidance in the early 2000s as a more rigorous alternative to qualitative risk-matrix scoring. The methodology is semi-quantitative. Initiating event frequencies, layer-of-protection failure probabilities, and consequence severity are estimated from generic data libraries rather than from full quantitative risk assessment, QRA. LOPA is the bridge between HAZOP, qualitative hazard identification and IEC 61511 SIL determination, quantitative SIL targeting. A LOPA study is typically conducted on the same nodes as the HAZOP, by a team that overlaps with the HAZOP team, after the HAZOP has identified the scenarios that warrant LOPA.
How does LOPA structure a scenario.
Each LOPA scenario starts with an initiating event, a deviation from HAZOP, such as 'control valve fails open' or 'operator opens manual valve in wrong sequence'. The initiating event has an estimated frequency, typically per year from generic data. Existing layers of protection sit between the initiating event and the consequence. Each layer has a probability of failure on demand, PFD. Layers of protection include the BPCS, basic process control system, PFD ~ 0.1, operator response to alarm, PFD ~ 0.1 with rich procedural support, higher otherwise, relief devices, PFD ~ 0.01 with regular proof testing, pre-existing SIS protection, PFD per the SIL of the existing SIF. The product of the initiating event frequency and the PFDs of all layers between the event and the consequence gives the residual frequency of the consequence.
How does LOPA produce the target SIL.
If the residual frequency of the consequence exceeds the tolerable risk target, set by the company's risk-matrix tolerable region, typically 10^-5 per year for severe consequences, the gap must be closed by adding a new independent protection layer. The required risk reduction factor, RRF is the ratio of the residual frequency to the tolerable target. The RRF translates to a target SIL. RRF 10-100 SIL 1, RRF 100-1000 SIL 2, RRF 1000-10000 SIL 3, RRF 10000-100000 SIL 4. The target SIL becomes the design constraint for the new SIF. SIL verification under IEC 61511 then confirms whether the as-designed architecture achieves the target.
What makes a layer of protection independent.
Independence is the central LOPA discipline. A layer of protection is independent if its failure does not share a common cause with the initiating event or with another layer being credited. The BPCS, the same system whose deviation initiated the scenario cannot be credited as an independent layer for the same scenario. A relief valve sized for the same overpressure case cannot be credited twice. Operator response to an alarm whose setpoint is set by the BPCS, whose failure initiated the scenario is not independent. Each credited layer must pass an independence test. Failed independence reduces the credited PFD product and increases the required RRF.
Common questions
What is the typical initiating event frequency data source.
What is the typical layer-of-protection PFD data source.
What is the tolerable risk target.
Can LOPA conclude that no SIF is required.
How often is LOPA repeated.
Run it on your drawings.
Upload a drawing set, get every document populated and classified, export to the format your team uses.