Automation Glossary • Probability of Failure on Demand

What Is Probability of Failure on Demand (PFD)?

Merobix Engineering • • 6 min read

A safety function spends nearly all its time doing nothing, waiting for the rare demand when it must act. The question that matters is: when that demand finally comes, what is the chance the function fails to respond? Probability of failure on demand, or PFD, is the metric that answers this, and it is what actually determines a safety function's SIL. This guide explains what PFD and its averaged form measure, how they map to SIL bands and the risk reduction factor, and why proof testing is central to keeping PFD low.

Back to Blog

Probability of Failure on Demand in one line: Probability of failure on demand (PFD) is the likelihood that a safety instrumented function fails to perform its protective action when a demand occurs, and PFDavg is that probability averaged over the time between proof tests. A lower PFDavg means higher reliability; the value falls into bands that define the safety integrity level, and its inverse gives the risk reduction factor the function delivers.

PFD, PFDavg, and Low-Demand Mode

PFD measures a dangerous, hidden failure mode: a safety function that has quietly failed in a way that would prevent it from acting, but which is not revealed until either a demand or a test occurs. Because the function is dormant most of the time, such a failure can sit undetected. PFD is the probability that, at the moment a demand arrives, the function is in that failed-to-act state. It is used for low-demand functions - those called upon rarely, less than roughly once a year - which covers most oil and gas shutdown and trip functions.

Because the probability of an undetected dangerous failure grows as time passes since the last test, the instantaneous PFD is not constant; it rises steadily between tests and drops back down when a proof test finds and fixes any hidden failure. What engineers actually use is PFDavg, the average of this probability over the proof-test interval, because it represents the typical reliability across the whole period rather than at any single instant. This is why the metric is nearly always written PFDavg and why the proof-test interval is one of the main levers on it - test more often and the average failure probability comes down.

Mapping PFDavg to SIL and Risk Reduction

SIL is defined, for low-demand functions, in terms of PFDavg ranges. Each safety integrity level corresponds to a band of average probability of failure on demand: broadly, SIL 1 covers a PFDavg roughly in the range of one in ten to one in a hundred, SIL 2 one in a hundred to one in a thousand, SIL 3 one in a thousand to one in ten thousand, and SIL 4 one in ten thousand to one in a hundred thousand. Each step up is a tenfold improvement in reliability, so achieving a higher SIL means driving PFDavg down by an order of magnitude.

The inverse of PFDavg is the risk reduction factor, which expresses the same reliability as a multiple rather than a fraction. A PFDavg of one in a thousand is a risk reduction factor of a thousand, meaning the function reduces the frequency of the consequence roughly a thousandfold when it is credited. This connects directly back to LOPA: when a study finds a scenario needs a given risk reduction factor, that requirement translates into a target PFDavg and therefore a target SIL for the safety function. Verifying that a designed function actually meets its target PFDavg - by evaluating the reliability of its sensors, logic solver, and final elements, their redundancy, and the proof-test interval - is the core of SIL verification calculations.

PFD, Proof Testing, and SCADA Monitoring

The values that go into a PFDavg calculation depend on real operational discipline. Proof testing must happen at the interval the calculation assumed, because a longer effective interval raises the true average failure probability above the design value. Bypasses must be controlled, since a bypassed function has an effective PFD of one - certain failure to act - for as long as it is defeated. And diagnostics that reveal some dangerous failures automatically reduce the undetected fraction, improving the achievable PFD. In practice, PFD on paper only holds if the plant is operated the way the design assumed.

Monitoring supports this in the running plant. Visibility of whether a safety function is healthy, in bypass, or has an active fault, together with records that support proof-test scheduling, helps keep the real PFDavg close to its design value across many sites. A safety function that has been silently bypassed or whose proof test has been missed represents a real degradation that monitoring can surface before a demand exposes it.

Merobix, as cloud SCADA for oil and gas, monitors alarms and the status of safety functions reported by field controllers across many sites in a browser, and can make bypasses, faults, and trip status visible to operators. It does not compute PFD, which is an engineering calculation done during design and verification; what it provides is the operational visibility - are functions healthy, are any bypassed - that helps keep the achieved reliability consistent with the PFDavg the safety function was designed to deliver.

Frequently Asked Questions

What is the difference between PFD and PFDavg?

PFD is the instantaneous probability that a safety function fails to act on demand, and it rises as time passes since the last proof test because undetected dangerous failures accumulate. PFDavg is that probability averaged over the proof-test interval, giving the typical reliability across the whole period. SIL bands and verification calculations are defined in terms of PFDavg, not the instantaneous value.

How does PFDavg relate to SIL?

For low-demand safety functions, each SIL corresponds to a range of PFDavg, with every step up representing about a tenfold improvement in reliability - SIL 1 is roughly one in ten to one in a hundred, and each higher level drops the failure probability by another order of magnitude. So a target SIL is really a target PFDavg. Verification confirms the designed function's PFDavg falls in the required band.

How does proof testing affect PFD?

Proof testing finds and fixes hidden dangerous failures, resetting the accumulating failure probability, so a shorter test interval lowers the average PFD. The PFDavg calculation assumes a specific interval, and if testing is done less often than assumed, the real average failure probability is higher than the design value. This is why maintaining the proof-test schedule is essential to keeping the achieved SIL.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
1oo2 Voting  •  2oo3 Voting  •  Proof Test  •  Proof Test Coverage  •  Safe State  •  Demand Mode  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →