A hazard study can tell you that a scenario is dangerous, but not how much protection it actually needs. LOPA is the method that answers that question, sitting between a qualitative hazard review and the decision to install a safety function with a specific integrity level. This guide explains how LOPA counts independent protection layers against the frequency of an initiating event to arrive at a target risk reduction, and why it is the standard bridge from HAZOP to SIL selection.
LOPA in one line: LOPA, or layer of protection analysis, is a semi-quantitative risk assessment that estimates the frequency of an unwanted consequence by taking the frequency of an initiating event and reducing it by the failure probability of each independent protection layer that would stop the scenario. Comparing the residual frequency to a tolerable risk target shows whether more risk reduction is needed and, if so, what target SIL a new safety function must achieve.
LOPA works one hazard scenario at a time, usually taking scenarios flagged during a HAZOP as needing further analysis. For each scenario it identifies an initiating event and estimates how often that event occurs - a control loop failing, a pump running dead-headed, an operator making a specific error - expressed as a frequency, such as a number of times per year. This initiating-event frequency is the starting point that the protection layers will act to reduce.
Each independent protection layer that can stop the scenario is then credited with a probability of failure on demand, and the analysis multiplies the initiating frequency by the failure probability of each qualifying layer in turn. Because each layer reduces the frequency by its failure probability, adding capable layers drives the residual event frequency down by orders of magnitude. The result is an estimated frequency of the consequence with the existing safeguards in place. LOPA is called semi-quantitative because it uses order-of-magnitude numbers and simplifying rules rather than a full fault-tree calculation, which makes it faster and more consistent than a fully quantitative study while still being far more rigorous than a purely qualitative judgement.
Once LOPA has an estimated consequence frequency, that number is compared to the tolerable risk target the organization has set for that severity of outcome. If the existing independent protection layers already reduce the frequency to or below the tolerable level, no additional protection is required. If they do not, there is a risk gap, and the analysis calculates how much more risk reduction is needed to close it - typically expressed as a required risk reduction factor.
That required additional risk reduction is what determines the target SIL for a new safety instrumented function, because SIL bands correspond to ranges of risk reduction. A gap requiring a modest additional reduction points to a lower SIL, while a larger gap points to a higher one. In this way LOPA is the analytical bridge between a HAZOP, which identifies hazards qualitatively, and SIL selection, which specifies the reliability a protective function must achieve. It is important that the layers credited in the calculation genuinely qualify as independent protection layers; crediting a safeguard that is not truly independent or effective would understate the real risk and lead to an inadequate safety function.
LOPA is an engineering study performed during design and safety reviews, not something that runs live in a control system. But its conclusions shape the plant that SCADA then monitors, because the protection layers LOPA credits - alarms with operator response, the basic control system, safety instrumented functions, relief devices - are the very things whose health and status a monitoring system needs to keep visible. If a credited alarm is chronically ignored or a safety function is left bypassed, the real risk no longer matches what LOPA assumed.
This is where continuous monitoring supports the assumptions behind a LOPA. Keeping the credited layers demonstrably functional - alarms responded to, trips healthy and not defeated, relief paths available - is what preserves the risk reduction the analysis assigned. Visibility of that state, especially across many remote sites, is a practical way to make sure the safeguards LOPA counted on are actually present when a scenario develops.
Merobix, as cloud SCADA for oil and gas, monitors process conditions, alarms, and the status of safety functions reported by field controllers across many sites in a browser. While LOPA itself is a design-stage analysis, operating with clear visibility of the credited protection layers - whether an alarm is being acted on, whether a trip is healthy or bypassed - helps keep the live plant consistent with the risk reduction the study relied on.
LOPA determines whether the existing safeguards reduce a hazard scenario to a tolerable risk and, if not, how much additional risk reduction is needed. It does this by counting the independent protection layers acting on an initiating event. Its main output is often the target SIL for a new safety instrumented function, which is why it bridges HAZOP and SIL selection.
Because it uses order-of-magnitude frequencies and failure probabilities together with simplifying rules, rather than the detailed fault-tree mathematics of a fully quantitative analysis. This makes it faster and more consistent to apply across many scenarios while still being far more rigorous than a purely qualitative judgement. It sits between qualitative hazard review and full quantitative risk assessment.
LOPA estimates the consequence frequency with existing protection layers and compares it to the tolerable risk target. Any shortfall is expressed as a required additional risk reduction factor, and because SIL bands map to ranges of risk reduction, that shortfall translates directly into the target SIL for a new safety function. A larger gap means a higher required SIL.
Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.