Automation Glossary • PFH (failure per hour)

What Is PFH (Probability of Failure per Hour)?

Merobix Engineering • • 6 min read

The familiar safety metric, PFDavg, describes a protection layer that sits idle and is only called on now and then. But some safety functions are working constantly or are challenged so often that this idle-and-wait picture no longer fits, and for those a different metric governs: PFH. This guide explains when a safety instrumented function uses PFH instead of PFDavg, why PFH is a frequency rather than a probability despite its name, and how it maps to safety integrity levels for high-demand and continuous-mode functions such as those in HIPPS and burner controls.

Back to Blog

PFH (failure per hour) in one line: PFH, the probability of dangerous failure per hour, is the safety metric used for safety instrumented functions operating in high-demand or continuous mode - where demands come more often than about once a year, or the function is effectively always active. Despite the word probability, PFH is really a frequency: the average rate of dangerous failures per hour. Under IEC 61508 each safety integrity level corresponds to a band of PFH values, mirroring the way PFDavg bands define SIL for low-demand functions.

When PFH Applies Instead of PFDavg

The choice between PFDavg and PFH comes down to how a safety function is used, captured by its demand mode. In low-demand mode the protective function sits dormant and is only challenged occasionally - the standard boundary is a demand rate of roughly once per year or less - so what matters is the probability that it has quietly failed and would not respond if a rare demand arrived. That average probability of failure on demand, PFDavg, is the right metric because the function's job is to be ready for an infrequent call.

High-demand and continuous mode break that picture. In high-demand mode the function is challenged more often than about once a year, and in continuous mode the function is essentially always maintaining safety, so the process depends on it continuously rather than at rare intervals. When demands are frequent or constant, asking the probability it fails on a given rare demand no longer describes the risk well - what matters instead is how often the function itself suffers a dangerous failure per unit time, because each such failure directly threatens the process. That is exactly what PFH measures.

The practical rule of thumb is the once-a-year demand boundary: below it, treat the function as low demand and use PFDavg; at or above it, or where the function runs continuously, use PFH. This is not a cosmetic relabeling - the two metrics have different units and are computed and interpreted differently, so misclassifying a function's demand mode leads to using the wrong metric and potentially the wrong conclusion about whether it meets its target integrity level.

Why PFH Is a Frequency, Not a Probability

The name is genuinely misleading. PFDavg is a dimensionless probability - a pure number between zero and one describing the chance the function is failed when demanded. PFH carries units of per hour, which makes it a rate rather than a probability: it is the average number of dangerous failures expected per hour of operation. Reading it as a plain probability invites confusion, because a probability cannot have units, whereas PFH's whole meaning lives in its per-hour dimension.

The reason for the shift is the continuous nature of high-demand and continuous-mode functions. When a function is effectively always on guard, the relevant question is not whether it happens to be failed at the instant of a rare demand, but how frequently it will suffer a dangerous failure over time - because in continuous mode a dangerous failure can lead more or less directly to the hazard, without waiting for a separate demand to arrive. Frequency of dangerous failure is therefore the natural measure, and PFH expresses precisely that as a per-hour rate.

This distinction changes how the numbers are read and compared. A small PFDavg and a small PFH both indicate a good safety function, but they answer different questions and cannot be compared directly or interchanged, because one is a probability and the other a frequency. When verifying a high-demand function you compute and check its PFH against a PFH target, and you should never quietly substitute a PFDavg figure, since doing so mixes incompatible quantities and produces a meaningless comparison.

PFH Bands, HIPPS, and Continuous Monitoring

IEC 61508 defines safety integrity levels for high-demand and continuous-mode functions using PFH bands, just as it defines them for low-demand functions using PFDavg bands. Each SIL corresponds to a range of allowable PFH values, with higher integrity levels demanding a lower dangerous-failure frequency, so verifying a high-demand function means computing its PFH and confirming the value falls within the band required by its assigned SIL. The logic mirrors the low-demand case exactly - only the metric and its units differ.

In oil and gas, several important safety functions land in high-demand or continuous territory and are therefore governed by PFH. A high-integrity pressure protection system, or HIPPS, that guards a pipeline or vessel against overpressure can face frequent pressure excursions, and burner management functions on fired equipment operate against a continuously present hazard, so both are candidates for PFH rather than PFDavg. Classifying these correctly matters, because using the low-demand metric on a genuinely high-demand function would misjudge the risk they carry.

Merobix is a cloud SCADA platform that reads live tags from field devices over Modbus, DNP3, OPC UA, and MQTT, and while PFH itself is a design-and-verification figure rather than a live measurement, the operating conditions that decide whether a function is high demand are exactly the kind of data SCADA collects. Trending how often a protective function is actually challenged - how frequently a HIPPS sees a pressure excursion, for instance - gives engineers real demand-rate evidence to confirm the mode assumption behind the metric, and it lets operations watch that the field is behaving the way the safety analysis assumed.

Frequently Asked Questions

When do you use PFH instead of PFDavg?

You use PFH when a safety instrumented function operates in high-demand or continuous mode, and PFDavg when it operates in low-demand mode. The dividing line is the demand rate: if the function is challenged more often than about once a year, or if it is effectively always maintaining safety, it is high demand or continuous and PFH applies. If it sits idle and is only called on rarely, it is low demand and PFDavg is the correct metric. Classifying the demand mode correctly is what determines which metric you must use.

Is PFH a probability or a frequency?

Despite the word probability in its name, PFH is a frequency. It has units of per hour and expresses the average number of dangerous failures expected per hour of operation, whereas PFDavg is a dimensionless probability between zero and one. This distinction matters because the two cannot be compared or interchanged - one is a rate and the other a probability - so a high-demand function must be verified against a PFH target, never a PFDavg figure.

Why do HIPPS and burner controls often use PFH?

Because they frequently operate in high-demand or continuous mode. A high-integrity pressure protection system can face pressure excursions often enough to exceed the once-a-year demand boundary, and burner management functions guard against a continuously present hazard, so both are challenged far more often than a typical idle-and-wait protection layer. When demands are frequent or the hazard is continuously present, the meaningful measure is how often the function itself fails dangerously per unit time, which is exactly what PFH captures.

Sources and verification

This page references the protocol specifications published by the organizations below. Editions, product capabilities, and documentation change over time - confirm current requirements and specifications directly with the source.

Last reviewed: July 27, 2026. Merobix is not affiliated with, endorsed by, or sponsored by these organizations; their names are used only to identify the standards and products discussed.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
PFDavg calculation  •  Risk reduction factor (RRF)  •  Architectural constraints  •  Route 1H vs Route 2H  •  Systematic capability (SC)  •  Prior-use justification  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →