Ebook: Understanding the Shop Floor — now on Gumroad
Industrial technology, indexed.
Industrial automation · manufacturing · OT — updated 2026-09-23

Safety instrumented systems: the boundary between control and protection

Basic SIS and SIF concepts, independence, SIL targets, proof testing, bypasses, and the questions to answer before connecting safety to a control system.

A safety instrumented system (SIS) provides a defined protective action when a hazardous process reaches a dangerous condition. It is not simply a second PLC with a red label, and it is not a replacement for the basic process control system (BPCS). Its design begins with hazards, consequences, initiating events, and the risk reduction a safety instrumented function (SIF) must provide.

Define the function

A SIF has a sensor, logic solver, and final element that together detect a defined condition and move the process to a safe state. Examples may include high pressure trip, high temperature shutdown, or loss of flow protection. Write the process boundary, trip setpoint, response time, safe state, and reset policy in a way operators and maintenance can understand.

Use hazard analysis to determine whether a SIF is required and what target it has. Safety Integrity Level (SIL) is a reliability target for the function, not a marketing grade for one component. The complete loop, common causes, diagnostics, proof-test interval, and demand rate matter.

Keep independence intentional

Independence does not always mean separate buildings or vendors, but shared power, networks, cabinets, engineering tools, and maintenance errors can defeat a theoretical separation. Document which failures the SIS must survive, what it may share with the BPCS, and how a demand is recorded.

Bypasses and overrides need authorization, indication, compensating measures, and automatic expiry where possible. Proof testing must check the complete path, including the final element. A logic solver that passes a test while a stuck valve never moves is not a functioning safety loop.

IEC 61511 provides the process-sector lifecycle language; the functional safety glossary entry and OT zones guide add adjacent context. Keep cybersecurity in the safety case because unauthorized changes can alter the protective function, but do not treat a firewall as the only safety barrier.

For a concise map of control, safety, and plant data systems, read Understanding the Shop Floor, a practical companion ebook.

Cite this page: Safety instrumented systems: the boundary between control and protection, Shopfloor, 2026-09-23. https://shopfloor.space/articles/safety-instrumented-system-basics/

Related