Automation Glossary • ISA-84 (SIS standard)

What Is ISA-84?

Merobix Engineering • • 7 min read

ISA-84 is the American national standard governing safety instrumented systems in the process industries. Its current form, published as ANSI/ISA-84.00.01, adopts the international standard IEC 61511 as its technical content, which is why the two are often spoken of interchangeably. What makes the ISA-84 designation matter in the United States is not different physics but different weight: it is the standard U.S. regulators and enforcement bodies point to as recognized good engineering practice for the systems that trip a facility to a safe state. When an oil and gas operator in the U.S. designs a safety instrumented function, ISA-84 is usually the reference on the cover sheet.

Back to Blog

ISA-84 (SIS standard) in one line: ISA-84 is the U.S. standard for the design, implementation, and management of safety instrumented systems (SIS) in the process industries, published as ANSI/ISA-84.00.01. It adopts IEC 61511 as its technical basis, so its lifecycle and SIL requirements match the international standard, but the ISA-84 designation carries specific regulatory recognition in the United States as recognized and generally accepted good engineering practice.

ANSI/ISA-84 as the U.S. Adoption of IEC 61511

ISA-84 and IEC 61511 are not competing standards; the modern ISA-84 is the American adoption of IEC 61511. When ISA republished its safety instrumented systems standard, it aligned the technical content with the international document so that a plant working to ANSI/ISA-84.00.01 is, in engineering substance, working to IEC 61511. The safety lifecycle, the concept of a safety instrumented function, the safety integrity levels, and the verification requirements are the same in both. This is why a designer can cite either designation and mean essentially the same set of rules.

The value of keeping the ISA-84 name is jurisdictional. In the United States, the standard's history stretches back to an original ISA S84 document that predated the international harmonization, and U.S. industry, regulators, and insurers came to know safety instrumented system practice under the ISA-84 label. Referencing ISA-84 signals that the design meets a U.S.-recognized benchmark, which matters for how the work is judged in an audit, an incident investigation, or a regulatory review.

It is worth being precise about what ISA-84 is not. It is not the base standard that defines functional safety from first principles; that role belongs to IEC 61508, which ISA-84 and IEC 61511 both sit beneath. ISA-84 is the application layer for the process industries specifically - refineries, gas plants, chemical facilities, and upstream oil and gas installations - telling those operators how to specify, build, and sustain the instrumented layers of protection that bring a runaway process back to safety.

What ISA-84 Requires: Lifecycle, SIF, and the Grandfather Clause

ISA-84 structures safety instrumented system work around a lifecycle: identify the hazards and the required risk reduction, allocate that reduction to safety instrumented functions with target SILs, design and build the system to meet those targets, validate it, and then operate, test, and maintain it for the life of the plant. Each safety instrumented function - a self-contained protective action such as closing an inlet valve when a vessel reaches high-high pressure - is designed as a complete path from sensor through logic solver to final element, and its achieved SIL is verified against the target before it is trusted.

The standard is strict about independence and management of change. A safety instrumented function is expected to be separate from the basic process control system that runs the plant day to day, so a fault or a maladjustment in normal control cannot also disable the protection. Bypasses of a safety function must be controlled, documented, and time-limited, and any change to the process or the safety system must go through a management-of-change review to confirm the protection is still adequate. Proof testing on a defined interval is not optional; the SIL a function claims on paper only holds if it is tested at the frequency the calculation assumed.

A feature U.S. operators encounter often is the standard's treatment of existing systems, sometimes called the grandfather provision. Rather than forcing every legacy installation to be torn out and rebuilt to the letter of the current edition, the standard allows systems designed and constructed to prior codes and practices to remain in service, provided they are being operated and maintained in a manner that is safe. That flexibility is not a loophole to ignore the standard; it is a recognition that a well-run older system, kept under proper management of change and testing, can continue to provide its protection while new and modified systems are held to the current requirements.

SIF, SCADA, and the Monitoring Boundary in Oil and Gas

In upstream and midstream oil and gas, ISA-84 shapes the design of the emergency shutdown and safety instrumented functions that protect wells, separators, compressors, and tanks. A high-pressure trip on a separator, a high-level shutdown on a vessel, and an emergency shutdown that isolates a well are all safety instrumented functions whose required SIL is set by the risk they are guarding against. ISA-84 is why those functions are engineered as verified, independent paths rather than as ordinary control logic given a serious job.

A cloud SCADA platform such as Merobix has a clear and deliberately limited relationship to these functions. The trip itself must execute in the certified safety logic solver, not in a monitoring layer, and no responsible design lets a remote monitoring system perform a safety action. What SCADA contributes is visibility and record-keeping around the safety system: reading and displaying its status, capturing every demand and trip with a timestamp, and flagging when a safety function has been bypassed so the bypass does not quietly become permanent. That boundary between acting and observing is central to keeping the safety system's independence intact.

For operators managing remote and unmanned sites, that monitoring role directly supports the operation phase the standard cares so much about. ISA-84 assumes safety functions are proof-tested on schedule, that demand rates are watched against the design assumptions, and that bypasses are tracked and cleared. Cloud monitoring turns those assumptions into evidence: a historized record of how often each function was called, how long a bypass stayed active, and whether a device is drifting toward failure. The safety system keeps the site safe; the monitoring layer helps an operator prove, on a schedule an auditor will ask about, that it still does.

Frequently Asked Questions

Is ISA-84 the same as IEC 61511?

In technical content, yes - the current ANSI/ISA-84.00.01 adopts IEC 61511 as its basis, so its lifecycle, safety instrumented function concept, and SIL requirements match the international standard. The difference is designation and jurisdiction: ISA-84 is the U.S. version and carries specific recognition in the United States as accepted good engineering practice. A designer can cite either name and mean essentially the same rules, but U.S. projects usually reference ISA-84.

What is the ISA-84 grandfather clause?

The grandfather provision allows safety instrumented systems designed and built to earlier codes and practices to remain in service, rather than requiring every legacy installation to be rebuilt to the current edition. The condition is that the existing system is being operated and maintained in a manner that is safe, under proper management of change and proof testing. It recognizes that a well-run older system can keep providing protection while new and modified systems are held to the current standard.

What is a safety instrumented function under ISA-84?

A safety instrumented function, or SIF, is a single protective action carried out by the safety system, such as closing a valve when a vessel reaches a high-high level. It is designed as a complete path from sensor through logic solver to final element, and it is assigned a target safety integrity level based on the risk it guards against. ISA-84 requires that the function's achieved SIL be verified against that target and that the function be proof-tested at the interval its calculation assumed.

Sources and verification

This page references the standards, specifications, and official documentation published by the organizations below. Editions, product capabilities, and documentation change over time - confirm current requirements and specifications directly with the source.

Last reviewed: July 27, 2026. Merobix is not affiliated with, endorsed by, or sponsored by these organizations; their names are used only to identify the standards and products discussed.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
ISA-100 (industrial wireless)  •  NFPA 72 (fire alarm code)  •  NFPA 30 (flammable liquids)  •  NFPA 497 (gas/vapor areas)  •  API MPMS (measurement manual)  •  API 2350 (overfill protection)  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →