Automation Glossary • SIL Allocation

What Is SIL Allocation?

Merobix Engineering • • 6 min read

Before an engineer picks a single transmitter or valve, a decision has already been made: how much risk reduction this safety function must deliver. SIL allocation is that decision. It takes the outcome of a risk study, works out how big a gap remains between the hazard and a tolerable level of risk after other protections are counted, and turns that gap into a target safety integrity level for the safety function. This guide explains where allocation sits in the safety lifecycle, how credit for other protection layers shrinks the burden on the safety system, and why allocation is the target that verification later has to meet.

Back to Blog

SIL Allocation in one line: SIL allocation is the front-end step where the required risk reduction for a hazard is assigned to a safety instrumented function to set its target SIL. It is driven by the output of a risk study such as a LOPA or risk graph, which quantifies how much additional risk reduction the safety function must provide once credit is taken for other independent protection layers. The resulting required risk reduction factor maps to a target SIL that the design must later be verified to achieve.

From Tolerable Risk to a Target SIL

Allocation begins with a gap. A hazard has some likelihood of occurring and some severity if it does, and the organisation has a view of what level of risk is tolerable for that consequence. The distance between the unmitigated risk and the tolerable risk is the total risk reduction that must be found somewhere. Allocation is the process of deciding how much of that reduction the safety instrumented function is responsible for, and expressing that responsibility as a target SIL.

The bridge between the two is the required risk reduction factor - essentially how many times safer the function must make the situation. A larger factor demands a more capable, more reliable safety function, and the standard bands of risk reduction map onto the discrete SIL levels: modest reduction corresponds to a lower SIL, and large reduction to a higher one. Allocation is where that mapping is applied, turning a continuous risk figure into the discrete integrity target the rest of the lifecycle will work toward.

Crucially, allocation happens before any hardware exists. It is a statement of what is required, not a claim about what has been built. The output is a safety requirement: this function shall achieve this SIL. Whether a real sensor, logic solver, and valve can meet that requirement is a separate question answered later, and the whole point of stating the target first is to give the designers a concrete goal to design toward.

Crediting Other Protection Layers

The safety instrumented function is rarely the only thing standing between a plant and a hazard. Relief valves, basic control loops, operator response to alarms, mechanical design margins, and physical containment can each reduce the frequency or consequence of the event. When these are genuinely independent, effective, and auditable, a risk study can take credit for them - and every layer that carries part of the load reduces the risk reduction that has to be allocated to the safety system.

This is why the LOPA is such a natural driver of allocation. A layer of protection analysis walks through the independent protection layers one by one, assigns each a risk reduction, and calculates what residual gap remains. That residual is exactly what must be allocated to the safety instrumented function. If existing layers already close most of the gap, the function may only need a low SIL; if few credible layers exist, the whole burden lands on the safety system and a higher SIL is allocated.

The discipline in this step is independence. A layer can only be credited if a failure of the hazard cause does not also disable the layer, and if it is not the same equipment already counted elsewhere. Over-crediting weak or shared layers understates the SIL the safety function truly needs and quietly leaves the plant less protected than the paperwork suggests. Sound allocation is conservative about what it counts, which is why the risk study behind it has to be rigorous rather than optimistic.

Allocation, Verification, and Carrying the Target Forward

Allocation and verification are two ends of the same requirement, and keeping them straight avoids a great deal of confusion. Allocation sets the target SIL from risk - it is the goal. Verification, much later, calculates whether the chosen sensor, logic solver, and final element actually reach that target - it is the proof. Allocation asks how much integrity is required; verification asks whether the built loop delivers it. A safety function is only complete when the achieved SIL from verification is at least the target SIL from allocation.

Because allocation produces the safety requirement, its output has to travel intact through the entire project. The target SIL for each function, along with the assumptions behind it - which protection layers were credited and what they were credited with - become the reference every later stage is measured against. If a credited layer is quietly removed or weakened during detailed design or operation, the original allocation no longer holds and the target may need to be revisited.

That link to real operation is where day-to-day monitoring matters. Many of the layers credited during allocation - a basic control loop, an operator responding to an alarm, a relief path - are only valid if they keep working in service. Where those layers surface as SCADA tags and alarms, a cloud platform such as Merobix gives the people responsible for the safety case visibility into whether the assumptions behind an allocation still hold: whether alarms are being acknowledged, whether control loops are in service, and whether the plant is still protected the way the allocation assumed it would be.

Frequently Asked Questions

How does LOPA drive SIL allocation?

A layer of protection analysis lists the independent protection layers guarding against a hazard, credits each with a risk reduction, and calculates the residual gap that remains between the mitigated frequency and the tolerable target. That residual gap is what must be allocated to the safety instrumented function, and its size maps to the target SIL. So the LOPA produces the required risk reduction and allocation turns it into a SIL target.

What is the difference between allocating and verifying a SIL?

Allocation is the front-end step that assigns a target SIL to a safety function based on the risk reduction it must provide, before any hardware is chosen. Verification is the later check that the hardware actually selected achieves that target through a failure-probability and architecture calculation. Allocation sets the required target; verification confirms the achieved result meets it.

Why does crediting other protection layers reduce the allocated SIL?

Every independent protection layer that reduces the frequency or consequence of a hazard takes on part of the total risk reduction that must be found, leaving a smaller residual gap for the safety instrumented function to cover. A smaller residual gap means a lower required risk reduction factor and therefore a lower target SIL. The credited layers must be genuinely independent and effective, or the allocation understates the integrity the function really needs.

Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
Spurious Trip Rate  •  High/Low Pilot  •  Manual ESD Pushbutton  •  Trip vs Alarm Setpoint  •  Safety Relay  •  Dangerous Undetected Failure  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →