Determining the appropriate Safety Integrity Level (SIL) is an important part of functional and process safety. A Safety Instrumented Function (SIF) should provide enough risk reduction to bring a hazardous scenario within the organization’s defined tolerable risk criteria—without assigning a higher SIL than the scenario requires.
Layer of Protection Analysis (LOPA) provides a structured, semi-quantitative method for making this determination. It evaluates an initiating event, the effectiveness of qualifying Independent Protection Layers (IPLs), and the resulting mitigated event frequency. If the existing protection layers do not reduce the risk sufficiently, the remaining risk reduction requirement can be allocated to a SIF and used to establish its target SIL.
For process facilities, LOPA therefore creates an important link between hazard studies such as HAZOP and the specification of Safety Instrumented Systems (SIS).
Aura Safety & Risk Consultants includes SIL and HAZOP study services within its process safety portfolio.
What Is LOPA?
Layer of Protection Analysis is a risk assessment technique used to examine specific hazardous scenarios individually.
Rather than treating every safeguard as equally reliable, LOPA evaluates whether a protection measure meets the criteria required to be credited as an independent protection layer. Each accepted IPL is assigned an appropriate Probability of Failure on Demand (PFD) or equivalent risk-reduction credit based on the methodology and supporting evidence being used.
A typical LOPA scenario considers the initiating event, potential consequence, enabling conditions or conditional modifiers where applicable, existing IPLs, and the organization’s tolerable event frequency.
The analysis answers a practical question:
After accounting for valid independent protection layers, is additional risk reduction required?
If the answer is yes and a SIF is selected to provide that reduction, the required Risk Reduction Factor (RRF) helps determine the target SIL.
Understanding the Relationship Between LOPA and SIL
LOPA and SIL determination are related, but they are not the same activity.
LOPA evaluates the hazardous scenario and calculates the additional risk reduction required. SIL determination translates the risk-reduction requirement allocated to a SIF into a target Safety Integrity Level.
This distinction matters because a SIL is assigned to a Safety Instrumented Function, not simply to a plant, process, instrument, or piece of equipment.
For example, a high-pressure scenario may already have sufficient independent protection layers to achieve the organization’s tolerable risk target. In that case, an additional SIF may not be required for that scenario. If a gap remains, LOPA quantifies the additional risk reduction needed.
Step-by-Step: How to Determine SIL Level Using LOPA
Step 1: Define the Hazardous Scenario
The first step is to clearly define the scenario being evaluated.
A scenario may originate from a HAZOP, HAZID, Process Hazard Analysis (PHA), risk assessment, or another hazard-identification activity. It should establish a clear cause-and-consequence relationship.
For example:
Loss of cooling → reactor temperature increases → pressure rises → potential loss of containment.
Each materially different initiating event or consequence pathway should be assessed appropriately rather than combining unrelated scenarios into a single calculation.
A well-defined scenario provides the foundation for credible LOPA results.
Step 2: Identify the Initiating Event
Next, identify the event that starts the hazardous sequence.
Examples can include equipment failure, control-system failure, loss of utilities, process deviation, or human error where appropriately modelled.
The initiating event is assigned an Initiating Event Frequency (IEF), normally expressed as occurrences per year.
For illustration only, assume:
Initiating Event Frequency = 0.1 per year
This means the initiating event is estimated to occur once every 10 years on average. This value should not be treated as a default; actual studies require justified, scenario-specific data.
Step 3: Identify Valid Independent Protection Layers
The team then identifies safeguards that can legitimately receive risk-reduction credit.
An Independent Protection Layer (IPL) is a safeguard capable of preventing or mitigating the consequence and sufficiently independent of the initiating event and other credited protection layers.
Depending on the scenario and methodology, potential IPLs may include appropriately designed process controls, alarms with operator response, mechanical protection systems, or other engineered safeguards.
However, simply listing a safeguard in a HAZOP does not automatically make it an IPL.
Its independence, functionality, reliability, auditability, and other applicable qualification criteria must be considered before risk-reduction credit is assigned.
This prevents the analysis from overstating the protection already available.
Step 4: Assign PFD Values to Credited IPLs
Each qualifying IPL is assigned a Probability of Failure on Demand (PFD).
PFD represents the probability that the protection layer will fail to perform its required function when demanded.
For a simplified example:
| Protection Layer | Illustrative PFD |
| IPL 1 | 0.1 |
| IPL 2 | 0.1 |
These numbers are examples for explaining the calculation only. PFD values in an actual LOPA should be supported by the organization’s methodology, design information, reliability data, applicable standards, or other justified sources.
Step 5: Calculate the Mitigated Event Frequency
The scenario frequency after credited IPLs can be estimated using:
Mitigated Event Frequency = Initiating Event Frequency × PFD of IPL 1 × PFD of IPL 2 × …
Using the illustrative values above:
0.1 × 0.1 × 0.1 = 0.001 per year
Therefore:
Mitigated Event Frequency = 1 × 10−3 per year
Where relevant, enabling conditions and conditional modifiers may also form part of the LOPA calculation according to the organization’s methodology. They should not be inserted or credited without technical justification.
Step 6: Compare the Result With the Tolerable Risk Target
The calculated event frequency is then compared with the organization’s defined tolerable event frequency for the consequence being evaluated.
Suppose, purely for illustration:
Calculated mitigated frequency = 1 × 10−3/year
and the defined target is:
Tolerable event frequency = 1 × 10−5/year
Existing IPLs are therefore insufficient to meet the assumed target.
Additional risk reduction is required.
Step 7: Calculate the Additional Risk Reduction Factor
The required additional Risk Reduction Factor can be expressed as:
Required RRF = Mitigated Event Frequency ÷ Tolerable Event Frequency
Using our example:
RRF = 10−3 ÷ 10−5 = 100
The additional safety function therefore needs to provide a risk reduction factor of at least 100, subject to the study assumptions and applicable SIL allocation methodology.
Because:
PFDavg ≈ 1/RRF
the corresponding maximum average probability of failure on demand would be approximately:
PFDavg = 1/100 = 0.01
This requirement can then be mapped to the relevant SIL band for a low-demand SIF.
Step 8: Translate the Required RRF Into a Target SIL
For low-demand mode safety functions, the commonly used IEC SIL ranges are:
| SIL | Average PFD Range | Approximate Risk Reduction Factor |
| SIL 1 | ≥10−2 to <10−1 | >10 to ≤100 |
| SIL 2 | ≥10−3 to <10−2 | >100 to ≤1,000 |
| SIL 3 | ≥10−4 to <10−3 | >1,000 to ≤10,000 |
| SIL 4 | ≥10−5 to <10−4 | >10,000 to ≤100,000 |
An important boundary issue appears in our example. An RRF requirement of exactly 100 corresponds to a PFDavg of 0.01 (10−2), which is at the SIL 1/SIL 2 boundary. Under the conventional low-demand ranges shown above, 10−2 falls within SIL 1. An RRF requirement greater than 100 moves into the SIL 2 range.
This is why SIL should be determined from the actual calculated requirement and the applicable standard—not by simply rounding a risk-reduction number upward or downward.
A Practical LOPA-to-SIL Example
Consider a process vessel where an initiating event could lead to excessive pressure and a hazardous release.
Assume the following illustrative inputs:
- Initiating event frequency: 1 × 10−1/year
- IPL 1 PFD: 1 × 10−1
- IPL 2 PFD: 1 × 10−1
- Tolerable event frequency: 1 × 10−5/year
After the existing IPLs:
10−1 × 10−1 × 10−1 = 10−3/year
The remaining required risk reduction is:
10−3 ÷ 10−5 = 100
Therefore, if this additional risk reduction is allocated to a SIF, the required RRF is 100, corresponding to a PFDavg requirement of 10−2 and, using the conventional low-demand ranges above, the upper boundary of SIL 1.
The key point is not the example SIL itself. The important principle is:
SIL is derived from the risk-reduction gap remaining after valid protection layers have been credited.
Common Mistakes When Using LOPA for SIL Determination
Several errors can produce an inappropriate SIL target or an unreliable risk assessment:
- Crediting safeguards that are not truly independent: Two safeguards dependent on the same sensor, logic, utility, or failure mechanism may not provide independent risk reduction.
- Double-counting protection layers: A safeguard already included in the initiating-event frequency or another credited IPL should not receive duplicate credit.
- Using generic PFD values without justification: Protection-layer performance should be supported by an appropriate technical basis.
- Starting with a preferred SIL: The target should result from the risk assessment rather than being selected first and justified afterward.
- Confusing SIL determination with SIL verification: LOPA can establish the required risk reduction and target SIL. A separate verification process determines whether the proposed SIF design can actually achieve the required integrity.
- Ignoring assumptions: Initiating frequencies, IPL credits, enabling conditions, and consequence assumptions should be documented so the analysis can be reviewed and maintained.
What Happens After the Target SIL Is Determined?
Determining a SIL target is not the end of the functional safety process.
Once the required SIL has been established, the SIF requirements need to be clearly specified. Engineering teams can then evaluate the sensor subsystem, logic solver, final elements, architecture, proof-test arrangements, failure data, and other design factors relevant to achieving the required integrity.
This is where SIL verification becomes important.
A useful distinction is:
SIL determination asks, “How much risk reduction do we need?”
SIL verification asks, “Can the proposed SIF design deliver that level of risk reduction?”
Validation later provides evidence that the implemented safety function meets its specified functional and integrity requirements in the installed application.
Why LOPA Is Valuable for Process Safety Decisions
LOPA provides a traceable framework for connecting hazardous scenarios with risk-reduction decisions.
For HSE managers, process engineers, and facility operators, this can help clarify which safeguards are being relied upon, identify gaps in existing protection, support proportionate SIF requirements, and document the reasoning behind SIL targets.
It also helps avoid two undesirable outcomes: under-specification, where insufficient risk reduction is provided, and unnecessary over-specification, which can add design complexity, testing requirements, and lifecycle costs without a corresponding risk-based need.
LOPA, HAZOP and SIL: How They Work Together
These activities serve different but connected purposes.
HAZOP systematically identifies process deviations, causes, consequences, and safeguards. LOPA can then examine selected scenarios in greater depth and quantify the effect of qualifying independent protection layers. SIL determination establishes the integrity requirement for a SIF where additional instrumented risk reduction is required.
Readers comparing related risk-study methods can also review how QRA, HAZOP, and SIL studies differ and connect.
Aura Safety & Risk Consultants lists HAZOP, SIL, QRA, HAZID, FERA, Bow-Tie Analysis, and other risk studies within its process safety portfolio.
How Aura Safety Supports SIL and Process Safety Studies
Aura Safety & Risk Consultants provides process safety services in India, including Safety Integrity Level and HAZOP studies.
For organizations evaluating hazardous scenarios, the objective should be a technically defensible risk assessment that clearly documents initiating events, credited safeguards, residual risk, and required risk reduction.
Need support with SIL assessment or process safety studies? Get a Quote from Aura Safety & Risk Consultants to discuss your project requirements.
Frequently Asked Questions
Can LOPA be used to determine SIL?
Yes. LOPA can be used to determine the additional risk reduction required for a hazardous scenario after qualifying independent protection layers have been considered. Where this risk reduction is allocated to a Safety Instrumented Function, the required RRF or PFDavg can be used to establish its target SIL.
What is the difference between LOPA and SIL?
LOPA is a risk assessment method. SIL is an integrity target assigned to a Safety Instrumented Function. LOPA can provide the quantitative basis for determining how much additional risk reduction a SIF needs to provide.
What is an IPL in LOPA?
An Independent Protection Layer is a safeguard that can prevent or mitigate a hazardous consequence and satisfies the applicable criteria for independence and effectiveness. A safeguard should not receive LOPA credit merely because it exists.
What is the relationship between RRF and PFD?
For low-demand functions, the approximate relationship is RRF = 1/PFDavg. For example, a PFDavg of 0.01 corresponds to an RRF of 100.
Does every HAZOP recommendation require LOPA?
No. LOPA is generally applied to scenarios that require additional risk evaluation under the organization’s risk-assessment procedure. Not every HAZOP finding automatically requires LOPA or a Safety Instrumented Function.
Is SIL 3 always safer than SIL 1?
SIL 3 represents a higher integrity and risk-reduction capability than SIL 1, but that does not mean every application should use SIL 3. The target should correspond to the risk reduction required for the specific SIF and hazardous scenario.
Is SIL determination the same as SIL verification?
No. SIL determination establishes the required SIL target. SIL verification assesses whether the proposed SIF design is capable of meeting that target.