- SIL assessment determines the required Safety Integrity Level for each safety instrumented function, while SIL verification confirms the design can actually achieve that target two distinct but interdependent steps in the IEC 61511 functional safety lifecycle.
- Misunderstanding the difference between SIL assessment and SIL verification is one of the most common compliance gaps in Malaysian process facilities, often leading to under-designed or over-engineered safety systems.
- Many plant operators treat SIL as a one-time exercise or confuse assessment with verification, resulting in safety instrumented systems that look compliant on paper but fail to deliver the required risk reduction in practice.
- A structured approach that separates SIL assessment (what level do we need?) from SIL verification (can the design deliver it?) ensures both regulatory compliance and genuine safety performance.
- Engage a TÜV-certified functional safety consultancy to review your facility’s SIL assessment and verification records against IEC 61511 requirements.
What is SIL Assessment?
SIL assessment also referred to as SIL determination or SIL classification is the process of establishing the required Safety Integrity Level for each Safety Instrumented Function (SIF) at your facility. It answers the question: how reliable must this safety function be to reduce the process risk to an acceptable level?
The assessment is conducted during the hazard and risk analysis phase of the functional safety lifecycle, typically after a HAZOP or process hazard analysis has identified scenarios where a Safety Instrumented System (SIS) is required as a layer of protection.
Several methods can be used for SIL assessment, with the most common being Layer of Protection Analysis (LOPA), risk graph, risk matrix, and calibrated risk graph. In the Malaysian process industry, LOPA is the most widely adopted method because it provides a semi-quantitative, auditable, and transparent approach to SIL determination.
The output of a SIL assessment is a target SIL level (SIL 1, SIL 2, SIL 3, or in rare cases SIL 4) assigned to each SIF. This target defines the minimum performance the safety function must achieve, measured primarily through the Probability of Failure on Demand (PFDavg) for low-demand mode applications.
| SIL Level | PFDavg Range | Risk Reduction Factor (RRF) |
|---|---|---|
| SIL 1 | 0.01 to 0.1 | 10 to 100 |
| SIL 2 | 0.001 to 0.01 | 100 to 1,000 |
| SIL 3 | 0.0001 to 0.001 | 1,000 to 10,000 |
| SIL 4 | 0.00001 to 0.0001 | 10,000 to 100,000 |
IEC 61511 suggests that SIL determination should not be based on vendor recommendations, historical precedent, or industry convention alone it must be grounded in a rigorous hazard analysis specific to each facility’s operating context.
What is SIL Verification?

SIL verification is the engineering activity that confirms whether the proposed or installed Safety Instrumented Function can actually achieve the target SIL level determined during the SIL assessment. While SIL assessment asks “what do we need?”, SIL verification asks “can the design deliver it?”
SIL verification is a quantitative, calculation-based process that evaluates the complete SIF loop from sensor through logic solver to final element, against the target PFDavg. The verification takes into account certified failure rate data for each device, system architecture (single, dual, or triple redundancy configurations such as 1oo1, 1oo2, 2oo3), diagnostic coverage factors, common cause failure factors (beta factors), proof test intervals, and mean time to repair (MTTR).
IEC 61511 requires SIL verification be conducted during the design phase, before the Safety Instrumented System is installed and commissioned. The verification must demonstrate that the combined PFDavg of the entire SIF loop meets or exceeds the target SIL.
This is a critical distinction that experts suggest that should be emphasised: a SIL 2 rated transmitter connected to a SIL 2 rated logic solver and a SIL 2 rated valve does not automatically result in a SIL 2 capable loop. The actual PFDavg depends on the specific failure rates, architecture, proof test intervals, and diagnostic coverage of each component in combination.
Malaysian Data & Regulatory Context
In Malaysia, functional safety requirements for the process industry are primarily driven by PETRONAS Technical Standards (PTS), which mandate compliance with IEC 61511 for Safety Instrumented Systems in oil and gas facilities. DOSH’s regulatory framework under the Occupational Safety and Health Act 1994 further reinforces the obligation to implement adequate safety measures.
The SSI Regulations 2025, launched jointly by PETRONAS and DOSH, have added further impetus to proper SIL assessment and verification practices. By embedding risk-based approaches into the regulatory framework, these regulations demand that plant operators can demonstrate, with documented evidence, that their safety systems deliver the required risk reduction.
Research documented in the Journal of Engineering Research and Reports (2021) confirmed that process safety management in Malaysia is strongly influenced by PETRONAS’ Mandatory Control Framework, which includes explicit requirements for SIL studies as part of the hazard and risk assessment process.
Pure Integrity’s project experience reflects this reality. Our team has conducted SIL assessment and verification studies for offshore platforms in Sabah and Sarawak waters, FPSO facilities, GTL plants, and major onshore process facilities across Peninsular Malaysia. In every engagement, the gap between SIL assessment and SIL verification is where the most critical compliance issues arise.
How SIL Assessment and SIL Verification Work Together
Understanding the relationship between SIL assessment and SIL verification is essential. They are not alternatives, they are sequential steps in the same lifecycle.

Step 1: Hazard Identification (HAZOP/HAZID) The process begins with a structured hazard analysis, typically a HAZOP study, that identifies process deviations, potential consequences, and existing safeguards. The HAZOP team identifies scenarios where a Safety Instrumented Function may be required.
Step 2: SIL Assessment (Determination) For each identified SIF, a SIL assessment study is conducted to determine the required SIL level. Using LOPA, the assessment team evaluates the unmitigated risk, credits existing independent protection layers (IPLs), and calculates the residual risk gap the SIF must close.
Step 3: Safety Requirement Specification (SRS) The SIL target, along with process conditions, response time requirements, and failure mode specifications, is documented in a Safety Requirement Specification.
Step 4: SIL Verification During detailed engineering design, the proposed SIF architecture is verified against the SIL target using quantitative reliability calculations. If the calculated PFDavg exceeds the allowable range, the design must be modified.
Step 5: Validation & Commissioning After installation, the SIF undergoes validation, functional testing to confirm it operates correctly under actual plant conditions.
Risk Factors
Outdated Hazard Studies: SIL assessments conducted during original plant design may no longer reflect current operating conditions. Process modifications, feedstock changes, and de-bottlenecking can invalidate previous SIL determinations.
Incomplete LOPA Studies: A common weakness is LOPA studies that credit protection layers without verifying their independence, reliability, or audit trail.
Using Generic Failure Data: SIL verification calculations are only as reliable as the failure rate data used. Using generic database values without considering Malaysia’s tropical climate can produce misleading results.
Ignoring Common Cause Failures: When redundant architectures are used, common cause failures can eliminate the reliability benefit of redundancy. Beta factors must be properly estimated.
Proof Test Effectiveness: If actual proof testing in the field does not achieve the assumed coverage, the real-world SIL capability will be lower than calculated.
Industry Myths vs. Reality
| Myth | Reality |
|---|---|
| “SIL assessment and SIL verification are the same thing.” | SIL assessment determines what SIL level is needed. SIL verification confirms the design can achieve it. They serve different purposes at different lifecycle stages. |
| “If every device in the loop is SIL 2 certified, the loop is SIL 2.” | Device-level SIL certification is necessary but not sufficient. The loop PFDavg depends on architecture, proof test intervals, diagnostic coverage, and common cause factors. |
| “We only need to do SIL studies for new plants.” | IEC 61511 requires periodic reassessment. Existing plants must verify SIL assignments remain valid, especially after process modifications. |
| “SIL 3 is always better than SIL 2.” | Over-specifying SIL levels wastes capital, increases complexity, and can create additional failure modes. The correct SIL matches actual risk. |
| “Only instrument engineers need to understand SIL.” | SIL assessment requires input from process, operations, maintenance, and safety disciplines. It is a multidisciplinary exercise. |
Our Experience at Pure Integrity
Facing Industry Challenges
In our years of conducting functional safety studies across Malaysian facilities, we have consistently observed plants that invest in SIL assessment during initial design but neglect SIL verification, or vice versa. This creates a dangerous gap where safety systems appear compliant but may not deliver required risk reduction.
We have worked with offshore operators who discovered during revalidation that their SIL verification calculations were based on outdated failure rate data. We have supported GTL plants where LOPA studies credited protection layers that had since been removed. And we have encountered facilities where SIL 2 targets were assigned to functions that only required SIL 1, leading to unnecessary cost.
Solving SIL Assessment & Verification Challenges
At Pure Integrity, we approach SIL assessment and verification as inseparable components of a single functional safety programme. Our team includes TÜV-certified Functional Safety Engineers who conduct both activities using methods aligned with IEC 61511.
Our functional safety consultancy covers the full lifecycle, from initial SIL determination using LOPA, through SRS development, SIL verification calculations, to FSA Stage 2 assessments during operations.
Real Solutions from Our Services
SIL Assessment (LOPA): We facilitate structured LOPA workshops with multidisciplinary plant teams, producing auditable SIL determinations.
SIL Verification: Our engineers perform quantitative SIL verification calculations using certified failure rate data.
Safety Requirement Specification (SRS): We develop detailed SRS documents bridging SIL assessment outcomes and detailed engineering design.
Functional Safety Assessment (FSA): We conduct independent FSA at all lifecycle stages, including Stage 2 assessments.
Our Procedure for SIL Studies
Step 1: HAZOP/PHA Review. We review hazard study outputs to identify all scenarios requiring SIF protection. Where studies are outdated, we recommend HAZOP revalidation.
Step 2: SIL Determination Workshop. We facilitate a structured LOPA workshop with process, operations, maintenance, and safety personnel.
Step 3: SRS Development. We document the SIL target, safe state, process conditions, and response time in a formal SRS.
Step 4: SIL Verification Calculations. Using certified failure rate data and proposed SIF architecture, we calculate PFDavg for each SIF loop.
Step 5: Gap Analysis & Recommendations. Where verification reveals gaps, we provide specific engineering recommendations.
Step 6: Ongoing FSA Support. We support clients through Functional Safety Assessments at key lifecycle stages including operations and decommissioning.
Expert Commentary
From a functional safety perspective, the distinction between SIL assessment and SIL verification is the difference between knowing what risk reduction you need and proving your system can deliver it. Both are mandatory under IEC 61511 and require distinct competencies.
Experts suggest that that Malaysian plant operators pay particular attention to LOPA quality. A poorly conducted LOPA that over-credits protection layers will result in under-specified SIL targets meaning the SIS may not provide adequate risk reduction. Conversely, an overly conservative LOPA leads to over-specified SIL targets, driving unnecessary capital expenditure.
The integration of SIL studies with broader process safety management frameworks is equally important. Panduan PETRONAS suggested that SIL assessment findings feed directly into the facility’s major hazard register.
For facilities operating in Malaysia’s oil and gas sector, engaging a qualified functional safety consultancy with TÜV-certified engineers is an investment in the reliability of your most critical safety barriers.
When Should You Seek Professional Consultancy?
New Facility Design: SIL assessment and verification should be integrated from the earliest design stages.
HAZOP Revalidation: When HAZOP studies are updated, SIL assignments must be reviewed.
Plant Modifications (MOC): Any change to process conditions, SIS hardware, or operating procedures should trigger SIL reassessment.
Regulatory Audit Preparation: Having up-to-date SIL records is essential for DOSH or PETRONAS reviews.
Ageing SIS Equipment: When SIS approaches end-of-life, SIL verification must be repeated with current failure rate data.
Competency Gaps: If your facility lacks TÜV-certified functional safety engineers, external support ensures studies meet IEC 61511 rigour.
What is the main difference between SIL assessment and SIL verification?
SIL assessment determines the required Safety Integrity Level based on hazard and risk analysis. SIL verification confirms the proposed design can achieve that required SIL through quantitative reliability calculations. Assessment answers “what do we need?” while verification answers “can the design deliver it?”
Is SIL assessment mandatory for all Malaysian process plants?
For facilities governed by PETRONAS Technical Standards, SIL assessment is mandatory for any process with Safety Instrumented Functions. Under DOSH regulations, any facility operating safety-critical systems is expected to demonstrate adequate risk reduction which in practice requires formal SIL determination.
How often should SIL studies be revalidated?
IEC 61511 requires periodic reassessment, particularly when process changes occur or SIS hardware is modified. Best practice is to revalidate SIL studies alongside HAZOP revalidation cycles typically every 5 years or whenever a significant MOC is triggered.
Can SIL assessment be done without a LOPA study?
Yes alternative methods such as risk graph or risk matrix can be used. However, LOPA is most widely accepted in Malaysian process industry because it provides semi-quantitative, transparent, and auditable SIL assignment.
What happens if SIL verification shows the design cannot meet the target SIL?
The design must be modified. Options include adding redundancy, selecting devices with lower failure rates, reducing proof test intervals, or revisiting the SIL assessment to confirm the target is correctly specified.
Conclusion
SIL assessment and SIL verification are two distinct but inseparable pillars of functional safety compliance under IEC 61511. Understanding the difference and ensuring both are conducted with rigour is essential for any Malaysian process facility relying on Safety Instrumented Systems.
At Pure Integrity, our TÜV-certified functional safety engineers guide your facility through every stage of the SIL lifecycle. Reach out to our team because functional safety is too important to leave to assumption.
References
- IEC, “IEC 61511 Functional safety: Safety instrumented systems for the process industry sector.” Akses: https://www.iec.ch/functional-safety
- IEC, “IEC 61508 Functional Safety of Electrical/Electronic/Programmable Electronic Safety-related Systems.” Akses: https://assets.iec.ch/public/acos/IEC%2061508%20&%20Functional%20Safety-2022.pdf
- PETRONAS, “PETRONAS and DOSH Mark Regulatory Milestone with Launch of SSI Regulations 2025,” 12-August-2025. Akses: https://www.petronas.com/media/media-releases/petronas-and-dosh-mark-regulatory-milestone-launch-ssi-regulations-2025
- Journal of Engineering Research and Reports, “A Case Study of Asset Integrity and Process Safety Management of Major Oil and Gas Companies in Malaysia,” 2021. Akses: https://doi.org/10.9734/jerr/2021/v20i217260
- DOSH Malaysia, “Guidelines on Occupational Safety and Health Management Systems.” Akses: https://dosh.gov.my/wp-content/uploads/2024/10/Garis-Panduan-bagi-Sistem-Pengurusan-Keselamatan-dan-Kesihatan-Pekerjaan-OSHMS.pdf
- Mangan Software, “What Is SIL Verification? IEC 61511 Verification Explained,” 2026. Akses: https://mangansoftware.com/docs/sil-verification/
- Mangan Software, “SIL Validation Explained for IEC 61511 Compliance,” 2026. Akses: https://mangansoftware.com/docs/sil-validation-explained/
This article had been reviewed by
Dr. Khairil Osman – A TUV Certified Functional Safety Engineer who graduated from the University of Southampton and works as Operation Director at Pure Integrity.



