SIL Verification Calculator

Calculate the Safety Integrity Level (SIL) for relay logic solvers using this tool. Ensure compliance with IEC 61508 and IEC 62061 standards.

Free No Login Engineering Calculator

🔧 Input Parameters

All values in engineering units

✅ Results

📜 Engineering Summary

Purpose
SIL Verification Calculator
Standard
Category
Engineering
Applications
Commercial / Industrial / Residential

📥 Engineering Deliverables

📄 PDF Report (soon) 📄 Excel Sheet (soon) 📝 Inspection Checklist (soon)

Frequently Asked Questions

What is the difference between PFDavg and PFH in SIL verification for safety relays?
PFDavg (Average Probability of Failure on Demand) applies to low-demand mode safety functions (typically ≤1 demand per year), as defined in IEC 61508 Part 4 and IEC 62061. It quantifies the average likelihood the relay fails *when required* to act. PFH (Probability of Dangerous Failure per Hour) is used for continuous or high-demand mode systems (>1 demand/year) and reflects the hourly failure rate. For safety relays—commonly deployed in emergency stop or interlock applications operating in low-demand mode—PFDavg is the correct metric. Using PFH incorrectly can overstate risk or misassign SIL. The SIL Verification Calculator outputs PFDavg because it assumes demand-driven operation, consistent with IEC 61508 Table 3 and Annex B guidance for electromechanical logic solvers.
How do proof test intervals affect SIL verification results for a safety relay?
Proof test intervals directly impact PFDavg: longer intervals increase accumulated dangerous undetected failures (λ_du), raising PFDavg and potentially downgrading SIL. In the calculator, t1–t4 represent staggered test times (e.g., annual, biennial, etc.), enabling modeling of non-uniform testing strategies—critical for real-world maintenance plans. IEC 61508-6 recommends proof test intervals ≤ 2× the design life of weakest component, and requires documented justification for intervals >1 year. The calculator uses the average time-to-failure approximation for λ_du × t/2 (for constant failure rate), but accuracy improves when t1–t4 reflect actual scheduled maintenance windows—not theoretical maxima. Always validate intervals against relay manufacturer’s certified test procedures and diagnostic coverage claims.
Why does the SIL Verification Calculator require both λ_du and λ_dd—and how do I source reliable values?
λ_du (dangerous undetected) and λ_dd (dangerous detected) are essential because only λ_du contributes directly to PFDavg; λ_dd enables timely mitigation via diagnostics, reducing effective risk. Their ratio defines Diagnostic Coverage (DC = λ_dd / (λ_dd + λ_du)), a key SIL enabler. Reliable values must come from FMEDA (Failure Modes Effects and Diagnostic Analysis) reports per IEC 61508-2 Annex D—or certified third-party databases like exida or TÜV. Never use generic ‘industry averages’; relay-specific data varies by architecture (e.g., dual-channel vs. monitored single-channel), contact material, and environmental stress. Manufacturer datasheets often list λ_du/λ_dd at 25°C; derate for temperature, vibration, or switching cycles using IEC 61709 or MIL-HDBK-217F if FMEDA isn’t available.
Can I use this calculator for a safety relay configured in 1oo2 (one-out-of-two) architecture?
No—the current SIL Verification Calculator assumes a single-channel, non-redundant logic solver (i.e., 1oo1 architecture). A 1oo2 configuration requires fault-tolerant modeling: PFDavg depends on common cause failure (β-factor), proof test coverage of both channels, and whether diagnostics detect failures before demand. IEC 61508-6 Annex F provides equations for 1oo2, but they involve additional inputs (e.g., β, channel independence, test effectiveness) not captured here. For redundancy, use dedicated tools supporting architecture-specific models—or perform manual calculation per IEC 61508 Tables 5–7, validated by a competent functional safety engineer. Always confirm relay certification scope: many ‘SIL 3’ relays achieve that rating only in specific architectures with full diagnostic coverage and strict proof testing.
How does diagnostic coverage (DC) influence achievable SIL for a safety relay?
Diagnostic Coverage (DC) directly limits the maximum verifiable SIL: per IEC 61508 Table 3, SIL 2 requires ≥60% DC, SIL 3 requires ≥90% DC for low-complexity devices like relays. DC < 60% caps verification at SIL 1—even with low λ_du. The calculator computes DC from λ_dd and λ_du inputs, but real-world DC depends on hardware diagnostics (e.g., cross-monitoring, forced-guided contacts) and software self-tests. Note: DC must be *achieved and verified*—not just claimed. TÜV or exida certification reports must demonstrate DC under worst-case conditions (e.g., contact welding, coil degradation). If your relay’s certified DC is 95%, but field wiring faults aren’t covered, effective DC drops—requiring conservative assumptions or architectural changes (e.g., adding separate monitoring).
What proof test coverage is assumed in this SIL Verification Calculator—and how do I verify it?
The calculator assumes 100% proof test coverage for dangerous detected failures (λ_dd) and partial—but not perfect—coverage for dangerous undetected failures (λ_du). Specifically, it models proof tests as ideal for λ_dd (immediate removal) and as restoring the system to ‘as-good-as-new’ condition for λ_du *only if the test detects the fault*. This aligns with IEC 61508-6’s ‘effective proof test’ definition. To verify actual coverage: review the relay’s certified test procedure (e.g., ISO 13849-2 Annex K), confirm test methods detect all failure modes (e.g., contact welding via force testing), and audit field execution (e.g., torque verification, contact resistance measurement). Coverage < 100% increases effective λ_du—requiring adjustment of t1–t4 or inclusion of a coverage factor (K_test) per IEC TR 61508-7.
Is this calculator compliant with IEC 61508, IEC 62061, and ISO 13849—or do I need additional validation?
The calculator implements core PFDavg equations from IEC 61508-6 Annex B (Equation B.1 for simple systems) and aligns with IEC 62061’s PFDavg methodology for low-demand safety functions. However, it does *not* replace full compliance activities: IEC 61508 requires documented safety lifecycle execution (clauses 7–12), including hazard analysis, specification, validation testing, and management of change. For machinery applications, ISO 13849-1 uses PL (Performance Level), not SIL—requiring separate calculation of MTTFd, DC, and CCFL. While PFDavg results may inform PL assessment, direct mapping isn’t permitted. Always supplement calculator output with a full Safety Requirements Specification (SRS), verification report signed by a competent person, and evidence of systematic capability (IEC 61508-2 Clause 7) before commissioning.
How sensitive is PFDavg to errors in λ_du—and what’s an acceptable uncertainty band?
PFDavg is linearly proportional to λ_du, making it highly sensitive: ±50% error in λ_du yields ±50% error in PFDavg—potentially shifting SIL assignment (e.g., SIL 2 → SIL 1). IEC 61508-2 Annex D mandates uncertainty analysis; for relays, typical FMEDA uncertainty is ±30% (90% confidence) due to limited field data. Acceptable practice: use λ_du values with documented confidence bounds, apply Monte Carlo simulation if possible, and ensure calculated PFDavg stays ≤ 50% of the target SIL’s PFD limit (e.g., ≤ 2.5×10⁻³ for SIL 2) to absorb uncertainty. Never use unverified vendor ‘typical’ values—require traceable FMEDA reports with failure mode breakdowns and environmental derating applied.