Automation Glossary • Safety Instrumented System (SIS)

What Is a Safety Instrumented System (SIS)?

Merobix Engineering • • 5 min read

A safety instrumented system (SIS) is a dedicated, independent control system whose only job is to detect a dangerous condition and drive the process to a safe state - typically by shutting something down. It sits alongside the normal process control system but is deliberately kept separate, so that a failure of everyday controls cannot also disable the protection. This guide explains how an SIS is built, why independence matters, and where it fits in oil and gas.

Back to Blog

Safety Instrumented System (SIS) in one line: A safety instrumented system (SIS) is an independent layer of protection made of sensors, a safety-rated logic solver, and final elements (usually valves) that automatically takes a process to a safe state when a hazardous condition is detected. Governed by IEC 61511, it is intentionally separated from the basic process control system so a single failure cannot defeat both, and each protective action it performs is called a safety instrumented function (SIF).

How a Safety Instrumented System Works

An SIS is built from three elements working in series: sensors that measure the hazardous variable (pressure, level, temperature, flame, gas concentration), a logic solver that decides whether a trip condition has been reached, and final elements - almost always shutdown valves, but sometimes motor trips or vents - that physically bring the process to a safe state. Each complete detect-decide-act path is a safety instrumented function (SIF), and one SIS can execute many SIFs at once.

The defining principle is independence. The SIS is separated from the basic process control system (BPCS) that runs the plant day to day, usually with its own logic solver, its own sensors, and its own final elements. The logic is that the control system is the layer most likely to be wrong when a hazard develops, so the protection layer must not depend on it. An SIS is also designed to be fail-safe: on loss of power or signal, its outputs de-energize and the valves move to their safe position rather than staying put.

Each SIF is engineered to a target safety integrity level (SIL) that quantifies how reliable the function must be, and its whole design, testing, and maintenance is governed by the functional safety lifecycle in IEC 61511 (the process-industry application of IEC 61508). That lifecycle covers hazard analysis, allocation of SIFs to protection layers, verification of the achieved SIL, and periodic proof testing to confirm the function still works.

Where an SIS Fits in Oil and Gas

In upstream and midstream operations, an SIS is the layer that performs emergency shutdown (ESD), high-integrity pressure protection (HIPPS), and burner management trips. On a production facility it might close the wing and master valves on a wellhead when a flowline over-pressures, trip a compressor on high discharge temperature, or isolate and blow down a separator on high-high level. On a gas plant or terminal it coordinates unit shutdowns and connects to fire and gas detection.

The SIS is one of several independent protection layers in a layer-of-protection analysis (LOPA): the process design, the control system, alarms with operator response, the SIS, and finally mechanical relief and containment such as pressure safety valves and dikes. Each layer is meant to be independent so the failure of one does not cascade. The SIS is credited only for the risk reduction its verified SIL supports - which is why proof testing and documentation are taken so seriously.

From a monitoring standpoint, the SIS acts on its own; it does not wait for SCADA to intervene, and it must not depend on a cloud link to function. What SCADA adds is visibility. A platform such as Merobix can read SIS status, trip records, and first-out cause data over Modbus, DNP3, or OPC UA to alarm operators, trend how often a function trips, and support proof-test recordkeeping - without ever sitting in the safety path itself.

Frequently Asked Questions

What is the difference between an SIS and the process control system?

The basic process control system (BPCS) runs the process to hit production targets - it opens valves, holds setpoints, and optimizes throughput. The safety instrumented system (SIS) does nothing during normal operation; it only acts when a hazardous limit is reached, taking the process to a safe state. They are kept independent - separate logic solvers and often separate sensors and valves - so that a control system failure cannot also disable the protection.

What is a safety instrumented function (SIF)?

A SIF is a single protective action carried out by the SIS: one specific detect-decide-act loop, such as closing a shutdown valve when separator pressure exceeds a limit. Each SIF has its own sensors, logic, and final elements and is assigned a target safety integrity level (SIL). One SIS typically executes many SIFs, and each is verified and proof-tested independently.

Can a cloud SCADA platform be part of an SIS?

No. A safety instrumented system must operate independently of the control and monitoring systems and cannot depend on an external or cloud link to take the process to a safe state. A cloud SCADA platform such as Merobix reads SIS status and trip data for alarming, trending, and recordkeeping over protocols like Modbus, DNP3, or OPC UA, but it sits outside the safety loop and is never credited as a protection layer.

Sources and verification

This page references the protocol specifications published by the organizations below. Editions, product capabilities, and documentation change over time - confirm current requirements and specifications directly with the source.

Last reviewed: July 27, 2026. Merobix is not affiliated with, endorsed by, or sponsored by these organizations; their names are used only to identify the standards and products discussed.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
Safety Integrity Level (SIL)  •  Emergency Shutdown (ESD)  •  Fire and Gas System (F&G)  •  Area Classification  •  Purge and Pressurization  •  High Integrity Pressure Protection System (HIPPS)  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →