• Home
  • /
  • Functional Safety Assessment and Audit

When do you need Functional Safety Assessment or Audit - FSA ?

You will need to complete a Functional Safety Assessment, or FSA if you have identified any safety instrumented system or safety instrumented function on a project or existing plantApplications like this occur in oil & gas, chemical and pharmaceutical production, power generation, pulp and paper and others.

  • ESD / PSD Systems
    Any system used for emergency shutdown (ESD) or process shutdown (PSD) in an onshore chemical/petrochemical facility, refininery or offshore oil & gas platform.
  • Tank Level Protection
    Several infamous accidents have occurred due to basic failures in tank level control and shutdown. These are clear candidates for SIL-rated safety instrumented systems when storing flammable or toxic substances.
  • Industrial Burner Management Systems
    Industrial-scale burner management systems (BMS) commonly follow different application level codes and standards, but they may also need verifying for SIL requirements.
  • Gas Turbines
    Gas turbines are effectively large machines, but when used in conjunction with process facilities, they also come under requirements of IEC 61511 functional safety and SIL.
  • Projects involving SIS, SIF and SIL
    Projects involving SIL-rated safety instrumented systems (SIS) need FSA by an independent competent person due to the requirements of risk-based international standards.
  • Existing process plants with safety instrumented systems
    The IEC 61511, BS EN 61511 / ISA 61511 requirement for an operations FSA, called FSA 4, applies to existing running facilities, irrespective of age.
  • System modifications and SIS upgrades
    Any safety instrumented system upgrade which is not "like-for-like" replacement should go through FSA,

Frequently Asked Questions about FSA

What is a functional safety assessment?

Functional safety assessment is an important review activity required by IEC 61511 and IEC 61508 to be carried out at least once prior to start-up of a new or modified automated safety instrumented system.

The activity must be led by a senior, competent person, who is not involved with the step or steps being assessed.

The end expectation of a functional safety assessment is that a judgement is made about the functional safety conformance and safety integrity achieved by every safety instrumented function within the system(s) being assessed.

The hope is that duty holders will implement functional safety assessment planning at the outset of a new project or modification process. Every organisation involved in delivering functional safety equipment or services must be aware of their responsibilities.

What is a functional safety audit?

Functional safety audit is intentionally separated from functional safety assessment in the IEC series of functional safety standards. 

The goal is for an audit of procedures and records to determine whether an appropriate functional safety management system is in place, and it is being followed.

Somewhat like a Quality or Gap audit, a functional safety audit cannot be conducted until functional safety procedures are in place. The assessor is looking for sufficient evidence that procedures are being followed.

An audit alongside a functional safety assessment activity is an entirely valid prospect for an existing installation.

When is the best time to do a functional safety assessment?

The timing of a functional safety assessment depends largely on what type of project or installation is being assessed, and to which standard.

Projects looking at conformance with IEC 61511 have 5 recommended stages - see FSA 1 to FSA 5 in the remaining FAQ's in this section.

Who should get involved with functional safety assessment?

  • The duty holder or hazard owner technical resources and project management should lead the FSA activity.
  • At least one senior (functional safety competent) independent person not involved with the stage or stages being assessed.
  • Sub-contractors providing risk assessment or engineering services.
  • Suppliers of key equipment for the safety instrumented system or safety-related electrical control system.
  • Any certifying bodies required to approve an application or system.
  • Who should be involved with functional safety audit?

  • The duty holder or hazard owner management.
  • At least one senior (functional safety competent) independent person not involved with the stage or stages being assessed.
  • What is FSA 1?

    Stage 1  FSA - When the hazard and risk assessment is complete, and SIL target has been selected. Technically, it is possible to wait until the safety requirements are completed before starting functional safety assessment stage one, but only if this is available immediately following the SIL target allocation or SIL determination stage.
    DO NOT WAIT FOR REQUIREMENTS TO FULLY STABILIZE BEFORE STARTING FUNCTIONAL SAFETY ASSESSMENT.

    What is FSA 2?

    Stage 2 FSA - This is best completed alongside Factory Acceptance Testing, although it is advisable to start the stage two functional safety assessment activity when the instrumentation and logic solver selection has been made. Logic solver software review should commence when the software detailed design specification is available.

    What is FSA 3?

    Stage 3 FSA - This must be complete before the safety instrumented system enters into service. To achieve this in practice, it is crucial that FSA 1 and FSA 2 stage actions are closed out.

    Key documents for this stage include the installation, commissioning and validation planning, and witnessed records that validation testing of each SIS and SIF is complete.

    What is FSA 4?

    Also known as an FSA stage 4 - since IEC 61511 edition 2 was published, it has been a requirement to conduct functional safety assessment of existing safety instrumented systems after some time in operation and maintenance.

    This activity must led by someone independent of the operations and maintenance team.

    What is FSA 5?

    FSA stage 5 - this is an assessment of any modification of a safety instrumented system (SIS) or safety instrumented function (SIF) hardware or software.

    Except for fully like-for-like hardware changes, an FSA 5 may repeat elements of FSA 1, 2 and 3 for a limited part of the system.

    ALL changes to software MUST undergo FSA 5.

    CASE STUDY
    Functional Safety Assessment

    A Stage 5 Functional Safety Assessment (FSA) was required for a safety instrumented system (SIS) undergoing upgrade on a Top Tier COMAH* chemical plant. We provided the lead assessor to scope, plan and deliver an independent assessment report. 

    We reviewed the safety instrumented system modification scope, including a revised hazard study, layer of protection analysis, safety requirements and the design changes to hardware and software of the system. The FSA stage 3 concluded with witnessed validation of the entire SIS prior to start-up.


    eFunctionalSafety also completed a Stage 4 FSA by reviewing operations and maintenance procedures and proof test records for the existing system.

    *COMAH - Control of Major Accident Hazards - UK legislation.

    Experiences with FSA 1, 2, 3

    35%
    average

    Compliant without comment

    57%
    average

    Require long-term improvement

    8%
    average

    Need action before start-up

    Functional Safety Assessment Workflow

    Contact Us for a Quotation

    Select the FSA Stage you are at, then fill out your details
    Please Select One
    • FSA 1 to 3
    • FSA 4 - In Operation
    • FSA 5 - Modification
    0 of 350

    Assessment Planning

    A functional safety assessment (FSA) will only commence with a sound plan in place. Our typical methodology includes a series of "swim-lane" work processes which show the required steps and responsibilities.


    For a new-build or major modification project, our planning will include scoping all the proposed stages of FSA, the required inputs at each stage, and the expected results.


    For an FSA of an existing SIS in operation, our plan will show the extent and scope of the assessment to be conducted on the existing system. Any exclusions will be fully clarified at the outset.

    New projects or modifications

    For a new-build project we recommend that FSA is started as soon as the first SIL assessment has been completed. This may be before the safety requirements are fully developed, but from experience it is not wise to wait that long.


    We use a combination of offline document review and site-based project team interviews to conduct our assessment


    When the safety requirements specification is fully available, the FSA 1 activity can be finalised and formal reports can be produced.

    >
    Success message!
    Warning message!
    Error message!