Voting Logic.
Voting logic is the algorithm a safety instrumented function uses to decide whether a trip condition has actually occurred based on multiple redundant sensor inputs. Common voting schemes are 1oo1, single sensor, 1oo2, either of two, 2oo2, both of two, 2oo3, any two of three, and degraded modes like 1oo2D that re-architect on diagnostic failure. The choice trades fault tolerance against spurious-trip rate.
Three drawings included on a new account.
What Voting Logic means.
Voting logic is the rule a safety function applies to its redundant sensors before it acts. With two or three transmitters watching the same condition, how many must agree that the limit has been crossed before the function trips. It is the single most consequential architectural decision in a safety instrumented function because it sets both failure modes at once. A 1oo2 arrangement trips if either sensor calls the condition, which almost never misses a real demand but trips spuriously when one sensor fails high. A 2oo2 arrangement trips only when both agree, which almost never trips spuriously but is exposed if one sensor fails low. A 2oo3 arrangement, any two of three, improves both numbers at the same time, which is why it dominates SIL 2 and SIL 3 service. The voting is implemented in the certified logic solver, not in custom control code, so that the arrangement is provably deterministic and carries its certification into the SIL verification calculation, where the voting topology, the per-component failure rates, the diagnostic coverage, and the proof-test interval together produce the probability of failure on demand. Degraded-mode voting such as 1oo2D re-architects on a detected sensor fault to keep the safety function available while a failed transmitter is repaired. On the drawing and in the cause-and-effect matrix the voting is named alongside the instruments it governs, and it has to match the safety requirement specification exactly.
Why voting matters for the plant
A spurious trip is expensive. Lost production, possible damage to equipment from rapid shutdown, restart cost. A missed real trip is potentially catastrophic. Voting logic is the engineering knob that balances those failure modes. 1oo2 minimizes missed-trip probability but maximizes spurious trips. 2oo2 minimizes spurious trips but doubles the missed-trip exposure. 2oo3 is the compromise that gets the most SIS deployment in process industries because it improves both metrics simultaneously.
Voting in the logic solver
The certified-safe logic solver, Triconex Tricon, HIMA HIQuad, HIMax, ABB AC800M HI, Siemens S7-400 F-Systems, Honeywell SM, Emerson DeltaV SIS provides voting blocks pre-certified for the relevant SIL. The integrator wires the redundant sensor inputs into the voting block and configures the algorithm. The certified logic guarantees the voting is implemented correctly and deterministically. Custom-coded voting in non-certified ladder is not appropriate for SIS use.
Where voting is applied in a protective function
Voting is not one decision. It is applied separately at each subsystem, and the arrangement chosen at one does not have to match the others.
| Voting point | What is voted | Typical arrangement | What it guards against | What it costs |
|---|---|---|---|---|
| Sensor subsystem | Several transmitters or switches on the same process variable | 1oo2 or 2oo3 | A single transmitter failing undetected, or drifting out of calibration | Extra process connections, calibration and proof testing |
| Logic solver, internal | Redundant processors and I/O inside the safety controller | Vendor defined, commonly 1oo2D or 2oo3 | Processor, memory and internal bus failures | Carried inside the platform certification |
| Final element subsystem | Several valves, in series or in parallel | Series for a fail closed duty, parallel for a fail open duty | A single valve failing to move on demand | Extra valves, and an arrangement to test them online |
| Output driver | Redundant solenoids or trip amplifiers | Series for de-energise to trip | An output failing to de-energise | Wiring, cabinet space and more to proof test |
| Across subsystems | The rule applied when one channel is out of service | A written degradation rule with a time limit | An undeclared reduction in protection during maintenance | An operating rule, an alarm and a bypass record |
What each arrangement trades away
Every voting choice moves both failure modes at once, in opposite directions for 1oo2 and 2oo2. The right answer depends on what a false trip costs on that unit.
| Arrangement | Chance of failing to act on a real demand | Chance of acting when there is no demand | Tolerates a channel out of service |
|---|---|---|---|
| 1oo1 | Baseline | Baseline | No |
| 1oo2 | Much lower than 1oo1 | Roughly doubled | Yes, degrading to 1oo1 |
| 2oo2 | Roughly doubled | Much lower than 1oo1 | No |
| 2oo3 | Much lower than 1oo1 | Much lower than 1oo2 | Yes, degrading to 1oo2 or 2oo2 |
| 1oo3 | Lowest of these | Highest of these | Yes, degrading to 1oo2 |
| 2oo4 | Much lower than 1oo1 | Much lower than 1oo2 | Yes, degrading to 2oo3 |
Common questions
How does voting interact with SIL calculation.
Can voting be done in software in the BPCS rather than the SIS.
What does a spurious trip cost in practice.
Get the SIL verification workbook.
PFDavg by voting arrangement, with proof-test interval and the architectural constraint on the same sheet. Plain .xlsx.