⚡ Blog Mission: Transforming past incidents into actionable insights to prevent future accidents.
Sunday

HAZOP to LOPA Safety Lifecycle

How industrial facilities use Hazard and Operability (HAZOP) studies and Layers of Protection Analysis (LOPA) to determine Safety Integrity Level (SIL) targets.

1. Introduction & Context

In high-hazard process industries, safety cannot be left to chance. Standard IEC 61511 / ISA-84 defines a structured approach called the Safety Lifecycle to manage process risks from initial design through decommission. A critical phase of this lifecycle is determining whether the process requires a Safety Instrumented System (SIS) and, if so, what Safety Integrity Level (SIL 1 to SIL 4) is required. To do this, engineering teams connect two powerful risk-assessment methodologies: Hazard and Operability (HAZOP) studies and Layers of Protection Analysis (LOPA).

2. The Core Issue

Designing safety systems without a quantitative risk assessment leads to either under-protected plants (risking disaster) or over-engineered systems that are prohibitively expensive and prone to nuisance trips. The HAZOP-to-LOPA workflow provides a rational, code-compliant connection to determine exact protection requirements:

  • The HAZOP (Qualitative): A multidisciplinary team systematically reviews the process design (P&IDs) using guide words (e.g., “No Flow,” “More Pressure”) to brainstorm potential deviations, their causes, and their consequences. The HAZOP identifies hazardous scenarios—for example, Cause: Control valve fails open → Deviation: High pressure → Consequence: Vessel rupture and toxic release.
  • The LOPA (Semi-Quantitative): For high-consequence scenarios identified in the HAZOP, the team performs a LOPA. The LOPA starts with the frequency of the initiating event (e.g., control valve failure rate of 0.1 per year) and evaluates the available independent protection layers (IPLs) that can block the scenario. IPLs might include:
    • Basic Process Control System (BPCS) loop
    • Operator response to an alarm
    • Physical pressure relief valve (PRV)
    • Dike containment
  • Determining the Gap: Each IPL has a Probability of Failure on Demand (PFD). The LOPA multiplies these PFDs by the initiating event frequency to calculate the mitigated event frequency. If this frequency is higher than the facility’s tolerable risk target (e.g., 1 in 100,000 years), a “gap” exists.
  • The SIL Target: The remaining risk gap must be filled by a Safety Instrumented System (SIS). The size of the gap determines the required Safety Integrity Level (SIL):
    • SIL 1: PFD of 10⁻¹ to 10⁻² (10-fold to 100-fold risk reduction)
    • SIL 2: PFD of 10⁻² to 10⁻³ (100-fold to 1,000-fold risk reduction)
    • SIL 3: PFD of 10⁻³ to 10⁻⁴ (1,000-fold to 10,000-fold risk reduction)

This ensures that the safety system’s reliability matches the severity of the hazard.

3. Actionable Takeaways

  • Ensure IPL Independence: For a layer of protection to qualify as an IPL in a LOPA, it must be completely independent of the initiating event. For example, if a scenario is caused by a PLC control valve failure, an alarm processed by the same PLC cannot be counted as an independent IPL.
  • Maintain a Living Safety Lifecycle: Treat the HAZOP and LOPA as living documents. Any physical or software modification to the process (Management of Change, or MOC) must trigger a review of the HAZOP and LOPA to ensure safety layers have not been compromised.
  • Document SIS Safety Requirements Specifications (SRS): Once SIL targets are determined, compile them into a detailed SRS. The SRS defines exactly how the SIS must behave, including response times, bypasses, testing intervals, and fail-safe states.
  • Audit Proof-Test Frequencies: Ensure that the proof-test intervals for all SIS components (sensors, valves) match the PFD calculations in the LOPA. If a valve is not tested at the calculated interval, its PFD increases, invalidating the safety lifecycle design.
Post Conclusion
Correct Practice — Confirmed This post describes a confirmed correct and protected practice.
ELI CRITICALITY SCALE

Likelihood × Consequence Risk Matrix

Every post on this blog is classified using this industrial risk matrix. Badge colors map directly to the resulting criticality level.

Full Guide →
Likelihood ↓ / Consequence → Minor Moderate Serious Fatal
Almost Certain L1 L2 L3 L3
Likely L0 L1 L2 L3
Possible L0 L0 L1 L2
Unlikely L0 L0 L0 L1
Badge Key
L0
Normal
Educational / correct practice
L1
Advisory
Near-miss / equipment damage
L2
Warning
Serious injury potential
L3
Critical
Fatality / catastrophic failure