Safety Instrumented System, SIS.
A safety instrumented system is a separate control system whose only job is to take a process to a defined safe state when a measurement crosses a trip threshold. Designed and proof-tested per IEC 61511, ANSI-ISA 84, an SIS sits alongside the BPCS but is structurally independent so neither can mask a fault in the other.
Three drawings included on a new account.
What Safety Instrumented System, SIS means.
A safety instrumented system exists for one reason. To move the process to a safe state when the basic process control system, the operators, and the mechanical safeguards have not. IEC 61511, harmonized in North America as ANSI/ISA 84, governs it as a complete lifecycle rather than a piece of hardware, running from the hazard study that identifies which scenarios need an instrumented safeguard, through the safety requirement specification, to the proof-test schedule that runs for the life of the plant. The defining design rule is independence. Clause 9 of IEC 61511 requires that a fault in the BPCS cannot disable the SIS, which in practice forces separate logic solvers, separate I/O, and separate field cabling for the safety-classified loops. That independence is why the SIS is carried as its own scope on a project. When an I/O list is built from a P&ID set, the safety tags, PSHH, FSLL, ESDV, and the SIF-flagged final elements are separated into their own workbook so they get their own SIL allocation, their own cabinet, and their own proof-test cadence, and so the safety case can be audited without untangling it from the regulatory control scope. A tag that the drawing shows as safety-classified but that never reaches that separate register is exactly the gap a pre-startup safety review is designed to catch.
What an SIS actually does
An SIS continuously monitors process variables. When a value exceeds a configured trip point, high pressure, low flow, high temperature, the SIS executes a configured action. Shut a feed valve, open a vent, isolate a unit. The action must be deterministic, fast, and provably reliable to a Safety Integrity Level, SIL 1, 2, 3, or 4 appropriate for the hazard. Loop-by-loop proof testing verifies the SIS still works as designed. Falsifying or skipping a proof test is a regulatory failure.
How SIS instruments show up on a P&ID
Tag prefixes such as PSHH, PSLL, FSLL and TSHH are a common house convention for safety service, and they identify a candidate rather than a member. The drawing legend states the SIS classification scheme the project actually uses, and the safety requirements specification, the cause and effect matrix and the shutdown logic diagrams establish which functions are in the SIS and what SIL each carries. When extracting I/O lists from a P&ID set, teams split the confirmed SIS set into a separate workbook so it gets its own cabinet and cabling.
SIS against BPCS, the separation IEC 61511 asks for
The two systems answer different questions. IEC 61511 clause 9 sets the independence expectation between them.
| Attribute | Basic process control system (BPCS) | Safety instrumented system (SIS) |
|---|---|---|
| Purpose | Hold the process at setpoint and keep it running | Move the process to a defined safe state on demand |
| Mode of operation | Continuous; acting every scan | Dormant; acts only when a demand arrives |
| Governing standard | IEC 61131 for the platform, plus vendor practice | IEC 61511 for the process sector, IEC 61508 for the devices |
| Sensors and final elements | Shared freely across control strategies | Independent of the device that creates the demand; often fully dedicated |
| Performance measure | Loop stability, availability, control quality | PFDavg against a target SIL, and a spurious trip rate |
| Proof testing | Routine calibration on a maintenance schedule | A scheduled proof test at the interval the SIL verification assumed |
| Bypass | An operational act, logged | Controlled, time limited, alarmed, and recorded against an authorisation |
| Application program | Changed under normal engineering change control | Changed under the full safety lifecycle, with re-verification of the affected functions |
| Access to change | Engineering and, for tuning, the operator | Restricted, with a key switch or equivalent and an audit record |
| Failure on loss of power | Usually holds last state or a configured default | Usually de-energises to the safe state |
What an SIS is made of, from demand to safe state
Each subsystem is specified, verified and proof-tested separately, and each contributes to the function's PFDavg.
| Subsystem | What it contains | What the specification pins down |
|---|---|---|
| Sensor subsystem | Transmitters or switches on the process variable, with their process connections | Tag numbers, trip setpoint, voting, and the process connection arrangement |
| Logic solver | A safety rated controller, its I/O and its application program | Platform, SIL capability, fail-safe direction, and the program that implements each function |
| Final element subsystem | Valves, actuators, solenoids, trip amplifiers and motor trip circuits | Fail position, stroke time, and any partial stroke arrangement |
| Operator interface | Alarms, status, bypass control and reset | What the operator may see, bypass, and reset, and what is recorded |
| Supporting utilities | Instrument air, power, and the trip signal path | What must fail safe, and what must de-energise to trip |
Common questions
What does SIL mean.
Can BPCS and SIS share field instruments.
Who is responsible for specifying SIS instruments on a project.
Get the SIL verification workbook.
PFDavg by voting arrangement, with proof-test interval and the architectural constraint on the same sheet. Plain .xlsx.