The clean textbook formula for a safety loop assumes that every proof test finds every dangerous failure and resets the loop to as-good-as-new. Real proof tests do not do that. A test that only exercises part of a device, or only reveals the failures it happens to provoke, leaves a portion of the dangerous failures undiscovered every single time. Those unrevealed failures accumulate across the life of the loop as a residual term that never resets, so the real average probability of failure is worse than the ideal equation suggests. This page is about that mathematical consequence and why it drives the design of full-stroke and disassembly tests.
Imperfect proof testing in one line: Imperfect proof testing is the reality that a proof test typically reveals only a fraction of a device's dangerous failures, not all of them. The undiscovered failures are not reset by the test and accumulate over the loop's life as a residual PFD term, so the true average probability of failure on demand is higher than the idealized formula that assumes a perfect test.
A proof test can only find a dangerous failure if the test actually provokes the failure mode in question. A quick functional check of a valve might confirm it responds to a signal without ever verifying that it fully seats and seals under process pressure, so a leakage failure mode goes untested. A transmitter test that checks the output at one point may miss a drift or a sticking behavior that only shows up elsewhere in the range. Every test has blind spots, and the failures hiding in those blind spots are dangerous precisely because nothing reveals them.
Proof-test coverage is the fraction of dangerous failures a given test reveals, and for real tests it is well below one hundred percent. A test might reveal, say, ninety percent of the dangerous failure population, which sounds excellent until you notice the other ten percent are never found by that test at all. Those failures do not go away when the test passes; they sit in the device, and each proof test cheerfully certifies the loop as healthy while ignoring the mode it cannot see.
The key insight is that the missed fraction behaves completely differently from the revealed fraction. The revealed failures follow the familiar sawtooth: they build up between tests and get cleared at each test. The unrevealed failures build up too, but nothing clears them, so their contribution to unavailability keeps climbing across the entire operating life of the loop until some other event, a full-stroke test, a teardown, or an actual demand, finally exposes them.
Modeling imperfect testing splits the dangerous-undetected failure rate into two parts: the part the proof test reveals and the part it does not. The revealed part produces the usual interval-based term that resets at each test. The unrevealed part produces a second, longer-horizon term governed not by the proof-test interval but by the much longer time until a more thorough test or replacement, effectively the mission time. Because that second term grows over years rather than months, it can dominate the total even when the coverage looks high.
This is why a loop that looks compliant against the simple formula can quietly fall short in reality. The idealized equation assumes coverage is complete and therefore models only the resetting term. Once you account for imperfect coverage, the residual term is added on top, and the true PFDavg is higher, sometimes by enough to push the loop out of its claimed integrity level. The erosion is gradual and invisible, which makes it dangerous: nothing alarms, and every proof test reports success, while the achieved integrity slowly slips below target.
The practical response is to design tests that attack the blind spots directly. Full-stroke testing forces a valve through its complete travel and sealing behavior rather than a partial check, capturing failure modes a quick test misses. Periodic disassembly or overhaul inspects mechanisms that no in-place test can reach. These heavier tests are spaced far apart precisely because they are the mechanism that finally resets the residual term, and the interval optimization for a loop has to account for both the frequent partial test and the occasional thorough one.
Imperfect proof testing turns coverage into a number you have to manage, not just assume. Each type of test on each device has its own coverage, and the residual risk depends on when the more thorough tests actually happen. If a facility performs frequent quick checks but keeps deferring the full-stroke or disassembly test that clears the residual failures, the achieved integrity drifts downward even though the maintenance log looks busy. Seeing which test cleared which failure population, and when, is the only way to keep the residual honest.
A cloud SCADA platform helps by recording each test event with its type and outcome, so an engineer can distinguish a partial functional check from a genuine full-stroke test and see how long it has been since the residual-clearing test last ran. That distinction is exactly what the imperfect-test model needs, and it is easy to lose in a paper record where every entry just reads tested and passed regardless of depth.
Because Merobix reads field devices into one browser-based system and retains their test history, it makes the coverage story visible: not just that a device was tested, but with what kind of test and when the last thorough one occurred. That lets reliability engineers watch the residual term rather than pretend it is zero, and schedule the heavier tests before imperfect coverage quietly erodes the SIL the loop was designed to hold.
Proof-test coverage is the input, the fraction of dangerous failures a test reveals. Imperfect proof testing is the consequence: because coverage is below one hundred percent, the unrevealed failures form a residual PFD term that the test never resets. Coverage names the gap; imperfect testing describes how that gap accumulates and raises the real average probability of failure over the loop's life.
Because the unrevealed fraction is governed by a much longer time horizon than the proof-test interval. Even a small missed fraction grows over years until a thorough test or replacement clears it, so its contribution can dominate the total average probability of failure. A loop that passes the idealized formula can still fall short of its target once this residual term is included.
Heavier, less frequent tests do. Full-stroke testing exercises a valve's complete travel and sealing to catch modes a partial check misses, and periodic disassembly or overhaul reaches mechanisms no in-place test can inspect. These are spaced far apart deliberately, because they are what finally reveals and clears the failures that ordinary quick proof tests leave behind.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.