Automation Glossary • Proof Test Coverage

What Is Proof Test Coverage (PTC)?

Merobix Engineering • • 6 min read

Proof test coverage is the fraction of dangerous failures that a given proof test actually detects. It is the honest admission that no real test is perfect: some failure modes are simply not exercised by the procedure, so they survive the test and keep accumulating. Coverage is what separates the idealized picture of a test that fully resets a safety function from the messier reality on a plant. Understanding it is essential because imperfect coverage quietly inflates the real probability of failure on demand above what a naive calculation predicts.

Back to Blog

Proof Test Coverage in one line: Proof test coverage (PTC) is the percentage of dangerous failures that a proof test is capable of detecting. A test with less than one hundred percent coverage leaves a residual population of undetected failures that a single test can never remove, so that residual accumulates over the life of the function and raises the true average probability of failure on demand above the value an ideal test would suggest.

What Proof Test Coverage Measures

Every proof test procedure exercises some failure modes and misses others. A test might stroke a shutdown valve and confirm it closes, yet never verify that it seats tightly enough to stop leakage, or it might check a transmitter's trip point but not a failure mode buried in its internal electronics. Proof test coverage puts a number on this: it is the fraction of the dangerous failure rate that the specific procedure can reveal. A coverage of ninety percent means the test catches nine of every ten dangerous failures on average and lets one slip through.

This is a property of the test, not just the equipment. Two teams testing the same valve with different procedures can achieve very different coverage, because one may include a full closure and seat-integrity check while the other only confirms movement. Improving coverage usually means making the test more thorough, more intrusive, or more complete, which is why coverage and test cost tend to rise together. Recognizing coverage as a design variable, rather than assuming every test is perfect, is the whole point of the concept.

Coverage is distinct from the broader idea of a proof test itself. The proof test is the activity of exercising the function; coverage is the quality metric that says how much of the dangerous failure space that activity actually inspects. A frequent test with poor coverage can leave more residual risk than a less frequent test with excellent coverage, so interval and coverage always have to be reasoned about together.

How Imperfect Coverage Inflates Real PFD

The intuitive model of proof testing is a clean sawtooth: risk accumulates between tests, then a test knocks it back to zero. Coverage breaks that clean picture. When a test catches only a fraction of dangerous failures, it resets the covered portion but leaves the uncovered portion in place. The failures the test cannot see keep accumulating test after test, building a slowly rising floor underneath the sawtooth that no periodic test ever removes.

That residual floor is what inflates the real probability of failure on demand. A calculation that assumes perfect coverage predicts an average based only on the sawtooth, but the true average includes the ever-growing residual from the failures the test misses. Over a long design life, the uncovered failures can dominate, which is why a function that looks compliant on paper can fall short in practice if its proof test coverage was overstated. The only way to clear the residual is a more complete test, an overhaul, or replacement.

Because of this, credible SIL verification treats coverage as an explicit input rather than an optimistic assumption. Using a realistic coverage value, often well below one hundred percent, produces a higher and more honest predicted probability of failure on demand. Underestimating the residual is a common way that real-world safety performance ends up worse than the design study claimed, so conservative coverage assumptions are a safeguard against overconfidence.

Managing Coverage With Field Data and SCADA

Improving proof test coverage in practice means designing procedures that exercise more failure modes: confirming full valve closure and seat tightness rather than just movement, checking transmitters across their range, and verifying the complete trip path rather than a convenient subset. Each addition costs time and often requires a deeper process shutdown, so teams weigh the coverage gain against the operational disruption. The residual failures a procedure cannot reach are addressed through overhauls or replacement on a longer cycle.

Field evidence is what keeps assumed coverage honest. When a proof test does uncover a dangerous failure, or when a real demand exposes one the test missed, that information should feed back into the coverage assumption and the reliability model. A cloud SCADA platform that captures detailed valve travel, seat leakage indications, and trip behavior during testing gives engineers the raw evidence to judge whether a procedure is really achieving its claimed coverage or quietly missing modes.

For distributed oil and gas assets, this feedback loop is easy to lose because tests happen at many remote sites over long intervals. Centralized monitoring that records exactly what each test verified, and flags functions whose behavior during testing looks incomplete, helps operations teams see where coverage is weaker than assumed. Better data does not raise coverage by itself, but it prevents the dangerous situation of trusting a coverage number that the actual test procedure never earned.

Frequently Asked Questions

Why is proof test coverage never one hundred percent?

Because no practical procedure exercises every possible dangerous failure mode. Some modes require intrusive disassembly, full seat-leakage testing, or conditions that cannot be reproduced without major disruption, so they are left out of routine tests. The failure modes a procedure cannot reach survive the test, which is exactly the shortfall that coverage measures.

How does proof test coverage affect PFD calculations?

Failures the test cannot detect are not reset by the test, so they accumulate over the whole life of the function and form a rising residual under the normal sawtooth of risk. Including realistic coverage in the calculation raises the predicted average probability of failure on demand above the value a perfect-test assumption would give. Ignoring coverage is a common reason real safety performance falls short of the design study.

How can proof test coverage be improved?

By making the test more complete: confirming full valve closure and seat tightness instead of just movement, checking instruments across their full range, and verifying the entire trip path rather than a subset. Greater thoroughness usually means more intrusive testing and deeper shutdowns, so coverage improvements trade against operational disruption. Failure modes a test still cannot reach are handled through periodic overhaul or replacement.

Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
Safe State  •  Demand Mode  •  Process Safety Time  •  Safety Requirements Specification  •  Safety Lifecycle  •  Safe Failure Fraction  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →