Not every device in a safety loop arrives with a functional-safety certificate stamped on it, and huge numbers of transmitters and valves already installed across oil and gas facilities predate the era of formal certification entirely. IEC 61511 anticipates this with prior-use justification, a route that lets an operator qualify an uncertified device for a safety instrumented function using documented operating history rather than a supplier's certificate. Done properly it is rigorous and defensible; done casually it is a paperwork fiction. This page explains what a real prior-use dossier contains and how it differs from the manufacturer-side proven-in-use concept.
Prior-use justification in one line: Prior-use justification is a method under IEC 61511 for qualifying a device for a safety instrumented function based on documented operating experience instead of a functional-safety certificate. The operator assembles evidence such as the size of the installed base, accumulated operating hours, recorded failures, and configuration control to show the device is suitable and its failure behavior is understood.
The process sector was full of working safety instrumentation long before certified devices became common, and it would be neither practical nor honest to declare all of it unusable simply because it lacks a certificate. Prior-use justification recognizes that a device with years of successful service in a comparable duty carries real evidence of its reliability, evidence that can be marshaled to support its use in a safety function. The burden of assembling that evidence, however, shifts from the manufacturer to the end user.
A prior-use case has to demonstrate two things. First, that the device is appropriate for the application in terms of its function, its process conditions, and the environment it will see. Second, that its dominant failure modes and rates are sufficiently understood, from real operating history, to support the reliability claims made in the safety calculations. The second point is the harder one, because a vague sense that a valve has worked fine for years is not the same as a documented failure record you can defend to an assessor.
Crucially, the operating experience being cited must be relevant. Hours accumulated on a device in a benign, clean-service application do not transfer automatically to a corrosive, high-cycle, safety-critical duty. Prior use asks that the conditions of the claimed experience be similar enough to the intended use that the failure behavior can reasonably be expected to carry over, and it asks you to say so explicitly rather than assume it.
A defensible prior-use dossier is a bundle of concrete records, not a narrative. It typically starts with the installed base and the accumulated operating hours, because a claimed failure rate is only credible if enough device-years sit behind it; a handful of units over a short window cannot support a strong reliability claim no matter how well they ran. The more units and the more hours, the tighter the statistical basis for the failure rates you want to use.
The failure history is the heart of it. That means a maintenance and reliability record showing what failed, how it failed, whether the failure was safe or dangerous, and whether it was revealed by testing or by an actual demand. Blank failure logs are a warning sign rather than good news, because they usually mean failures went unrecorded rather than that none occurred. Alongside this sits configuration control: evidence that the devices in the population were the same model, the same firmware where applicable, and the same configuration, so that they truly form one population rather than a mix.
The dossier should also capture the operating and maintenance regime the experience was gathered under, since the failure record only means what it means in the context of how the devices were tested and maintained. A device that looked reliable only because it was aggressively over-maintained tells you less than one that performed well under a normal regime. Pulling all of this together is genuine engineering work, which is why prior use is powerful but not a shortcut.
Prior-use justification under IEC 61511 is closely related to but distinct from the manufacturer-facing proven-in-use concept in IEC 61508. Proven in use is largely something a device supplier claims for a product, based on a broad population across many customers, to support the product's general suitability. Prior use is something an end user claims for a specific installed population in a specific facility and duty, to justify that population in a particular safety function. The evidence overlaps, but the owner of the claim and the scope of the population differ.
The quality of a prior-use case rises and falls on the quality of the operating record behind it, and that is precisely where a facility's historical data lives. A cloud SCADA platform that has been logging demands, trips, alarms, and maintenance events across a population of identical devices is, in effect, accumulating the operating hours and failure evidence that a prior-use dossier needs. When those records are complete and time-stamped, assembling a credible justification is far easier than reconstructing it from paper logbooks after the fact.
Because Merobix reads field devices into one browser-based system and retains their history, it can help an operator answer the questions a prior-use assessment asks: how many identical units are in service, how long each has run, and what has actually failed. It does not write the justification or replace an engineer's judgement, but it keeps the raw operating experience organized so that the many legacy transmitters and valves already in the field can be qualified on evidence rather than optimism.
Proven in use is a manufacturer-side claim under IEC 61508 about a product's general suitability, based on a broad population across many users. Prior use is an end-user claim under IEC 61511 about a specific installed population in a specific facility and duty. They share the idea of qualifying on operating experience, but the owner of the claim and the scope of the population are different.
Only if you can assemble the evidence. You need a large enough installed base and enough operating hours, a documented failure record, configuration control showing the devices form one population, and experience gathered under conditions similar to the intended duty. Without that dossier, a device cannot be justified by prior use no matter how old or familiar it is.
No, it usually makes it weaker. A blank failure log more often means failures were not recorded than that none happened, so assessors treat it as a gap in the evidence rather than proof of reliability. A credible dossier shows real, documented failures that were captured, classified, and understood.
This page references the standards, specifications, and official documentation published by the organizations below. Editions, product capabilities, and documentation change over time - confirm current requirements and specifications directly with the source.
Last reviewed: July 27, 2026. Merobix is not affiliated with, endorsed by, or sponsored by these organizations; their names are used only to identify the standards and products discussed.
Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.