Safety instrumented systems: the boundary between control and protection
Basic SIS and SIF concepts, independence, SIL targets, proof testing, bypasses, and the questions to answer before connecting safety to a control system.
A safety instrumented system (SIS) provides a defined protective action when a hazardous process reaches a dangerous condition. It is not simply a second PLC with a red label, and it is not a replacement for the basic process control system (BPCS). Its design begins with hazards, consequences, initiating events, and the risk reduction a safety instrumented function (SIF) must provide.
Define the function
A SIF has a sensor, logic solver, and final element that together detect a defined condition and move the process to a safe state. Examples may include high pressure trip, high temperature shutdown, or loss of flow protection. Write the process boundary, trip setpoint, response time, safe state, and reset policy in a way operators and maintenance can understand.
Use hazard analysis to determine whether a SIF is required and what target it has. Safety Integrity Level (SIL) is a reliability target for the function, not a marketing grade for one component. The complete loop, common causes, diagnostics, proof-test interval, and demand rate matter.
Keep independence intentional
Independence does not always mean separate buildings or vendors, but shared power, networks, cabinets, engineering tools, and maintenance errors can defeat a theoretical separation. Document which failures the SIS must survive, what it may share with the BPCS, and how a demand is recorded.
Bypasses and overrides need authorization, indication, compensating measures, and automatic expiry where possible. Proof testing must check the complete path, including the final element. A logic solver that passes a test while a stuck valve never moves is not a functioning safety loop.
IEC 61511 provides the process-sector lifecycle language; the functional safety glossary entry and OT zones guide add adjacent context. Keep cybersecurity in the safety case because unauthorized changes can alter the protective function, but do not treat a firewall as the only safety barrier.
For a concise map of control, safety, and plant data systems, read Understanding the Shop Floor, a practical companion ebook.
Cite this page: Safety instrumented systems: the boundary between control and protection
, Shopfloor, 2026-09-23. https://shopfloor.space/articles/safety-instrumented-system-basics/