Calculator D3

Quantitative Risk Assessment: ALARP, FMEA, and SIL Determination

Quantitative Risk Assessment is a way engineers measure how likely and how bad accidents could be β€” then use math and data to decide what safety steps are truly needed.

Industry Applications
Oil & gas processing, chemical plants, nuclear facilities, rail signaling, pharmaceutical manufacturing
Key Standards
IEC 61508 (functional safety), IEC 61511 (process industry), ISO 31000 (risk management), UK HSE Red Book
Typical Scale
QRA studies cover single units (e.g., distillation column) to full site-level FN curves with 10⁢+ Monte Carlo iterations

⚠️ Why It Matters

1
Inadequate hazard identification
2
Undetected common-cause failures in control systems
3
SIL-rated safety functions mis-specified
4
Loss of containment during process upsets
5
Escalation to major incident (fire, explosion, toxic release)
6
Regulatory non-compliance and operational shutdown

πŸ“˜ Definition

Quantitative Risk Assessment (QRA) is a structured engineering methodology that assigns numerical probabilities and consequences to hazardous events, enabling objective evaluation of risk levels against defined tolerability criteria. It underpins ALARP (As Low As Reasonably Practicable) justification, supports Failure Modes and Effects Analysis (FMEA) severity-probability scoring, and informs Safety Integrity Level (SIL) determination per IEC 61508 and IEC 61511. QRA integrates fault tree analysis, event tree analysis, consequence modeling (e.g., dispersion, blast overpressure), and reliability data to derive risk metrics such as individual fatality risk (IFR) or societal risk (FN curves).

🎨 Concept Diagram

Quantitative Risk Assessment FrameworkHAZOP/FMEAFault/Event TreesPFDavg / RRF / ALARP

AI-generated illustration for visual understanding

πŸ’‘ Engineering Insight

ALARP is not a mathematical endpoint β€” it’s an engineering judgment anchored in evidence. A SIL assignment without documented cost-benefit analysis and stakeholder consultation is legally indefensible in jurisdictions like UK HSE or EU Seveso III. Always trace PFDavg back to component-level Ξ»DU and diagnostic coverage; 'black box' SIL tools without transparent inputs violate IEC 61508 Part 2 Β§7.4.2.

πŸ“– Detailed Explanation

Quantitative Risk Assessment begins with recognizing that qualitative judgments ('high', 'medium', 'low') lack the rigor needed for life-critical systems. Instead, QRA converts hazard narratives into measurable frequencies and outcomes β€” e.g., a pressure relief valve failure becomes Ξ» = 4.2 Γ— 10⁻⁡ /hr based on OREDA 2021 data, and its consequence becomes thermal radiation dose contours modeled in PHAST or SAFETI.

Deeper analysis requires understanding dependencies: common-cause failures (CCFs) can reduce effective redundancy by >50% if not modeled via beta-factor or MGL methods; proof test coverage (DC) directly modulates PFDavg β€” a 10% drop in DC from 95% to 85% increases PFDavg by ~4Γ— for a 1oo2 architecture. Human factors, maintenance quality, and environmental stressors (e.g., corrosion, EMI) must be factored into Ξ»DU adjustments, not treated as afterthoughts.

At the advanced level, QRA integrates dynamic methods: Bayesian updating refines Ξ» estimates using site-specific failure history; Monte Carlo simulation captures parameter uncertainty (e.g., Β±30% on dispersion model coefficients); and digital twin-enabled continuous PFD monitoring uses real-time sensor health data to adjust functional safety performance in operation β€” moving beyond static SIL verification toward adaptive SIL assurance per IEC 61511 Ed.3 Annex F.

πŸ”„ Engineering Workflow

Step 1
Step 1: Define scope, process boundaries, and tolerable risk targets (e.g., IFR ≀ 10⁻⁢/yr)
β†’
Step 2
Step 2: Conduct Process Hazard Analysis (PHA) β€” HAZOP + FMEA to identify hazards and initiate events
β†’
Step 3
Step 3: Build fault trees for each SIF and event trees for key scenarios; assign failure rates (Ξ») from OREDA, exida, or site-specific data
β†’
Step 4
Step 4: Calculate PFDavg using Markov or simplified equations; verify RRF meets target SIL
β†’
Step 5
Step 5: Perform ALARP demonstration β€” compare risk reduction cost vs. risk reduction benefit using Β£/statistical life or €/risk unit
β†’
Step 6
Step 6: Document SIL verification report and functional safety management system (FSMS) evidence
β†’
Step 7
Step 7: Validate via loop testing, proof tests, and post-startup review with independent audit

πŸ“‹ Decision Guide

Rock/Field Condition Recommended Design Action
High-consequence scenario (e.g., >100 mΒ³ flammable release) with HF β‰₯ 10⁻³/yr Require SIL 3 SIF with redundant architecture (2oo3), DC β‰₯ 90%, proof test interval ≀ 6 months
Moderate consequence (toxic exposure <10 people) with HF = 10⁻⁴–10⁻³/yr SIL 2 SIF with 1oo2 architecture, DC β‰₯ 70%, proof test interval ≀ 12 months
Low consequence (localized fire, no off-site impact) with HF ≀ 10⁻⁡/yr SIL 1 or non-SIF mitigation (e.g., procedural controls, alarms); verify ALARP via cost-benefit analysis

📊 Key Properties & Parameters

PFDavg

10⁻² to 10⁻⁡ (unitless)

Average Probability of Failure on Demand β€” the long-term average likelihood that a Safety Instrumented Function (SIF) will fail to perform its intended safety action when required

⚡ Engineering Impact:

Directly determines achievable SIL level; PFDavg ≀ 10⁻² required for SIL 1, ≀ 10⁻⁴ for SIL 2, ≀ 10⁻⁡ for SIL 3

RRF

10 to 10,000 (unitless)

Risk Reduction Factor β€” ratio of process risk without a SIF to risk with the SIF in place

⚡ Engineering Impact:

RRF = 1 / PFDavg; defines minimum risk reduction needed to meet target SIL and ALARP thresholds

Ξ»DU

1 Γ— 10⁻⁷ to 5 Γ— 10⁻⁡ /hr

Dangerous Undetected Failure Rate β€” frequency per hour at which a SIF fails dangerously *and* remains undetected until next proof test

⚡ Engineering Impact:

Primary driver of PFDavg; dictates proof test interval, diagnostics coverage (DC), and hardware fault tolerance requirements

HF

10⁻⁢ to 10⁻¹ /yr

Hazard Frequency β€” estimated rate (per year) at which initiating events (e.g., valve failure, leak, overpressure) occur

⚡ Engineering Impact:

Multiplied by consequence severity to compute risk; anchors FMEA severity-probability matrices and event tree inputs

πŸ“ Key Formulas

PFDavg (Simplified 1oo1)

PFDavg β‰ˆ Ξ»DU Γ— T / 2

Average probability of failure on demand for a single-channel SIF tested every T hours

Variables:
Symbol Name Unit Description
PFDavg Average Probability of Failure on Demand dimensionless Average probability that a safety instrumented function fails to perform its intended safety action when required
Ξ»DU Dangerous Undetected Failure Rate 1/hour Rate at which dangerous failures occur and remain undetected until proof test
T Proof Test Interval hours Time between successive proof tests of the safety instrumented function
Typical Ranges:
SIL 1 design
1 Γ— 10⁻³ to 1 Γ— 10⁻²
SIL 3 design
1 Γ— 10⁻⁡ to 1 Γ— 10⁻⁴
⚠️ Must be ≀ target PFDavg band per IEC 61508 Table 2

RRF

RRF = 1 / PFDavg

Risk reduction factor provided by a Safety Instrumented Function

Variables:
Symbol Name Unit Description
RRF Risk Reduction Factor Risk reduction factor provided by a Safety Instrumented Function
PFDavg Average Probability of Failure on Demand Average probability that a Safety Instrumented Function fails to perform its intended function when required
Typical Ranges:
SIL 1
10 to 100
SIL 3
1,000 to 10,000
⚠️ RRF must meet or exceed target RRF per IEC 61508 Table 3

ALARP Cost-Benefit Threshold

Cost per statistical life (CPSL) = Ξ”Cost / (Ξ”Risk Γ— 10⁢)

Monetary value assigned to risk reduction; used to justify further safeguards

Variables:
Symbol Name Unit Description
CPSL Cost per Statistical Life USD/life Monetary value assigned to risk reduction; used to justify further safeguards
Ξ”Cost Change in Cost USD Incremental cost of implementing additional risk-reduction measures
Ξ”Risk Change in Risk fatalities per million Reduction in fatality risk achieved by the safeguard
Typical Ranges:
UK HSE guidance
Β£1–3 million per life-year saved
EU Seveso III
€2–5 million per life-year saved
⚠️ If CPSL exceeds upper bound, further risk reduction is not 'reasonably practicable'

🏭 Engineering Example

Grangemouth Refinery (INEOS, UK)

N/A β€” Process facility (hydrocarbon processing)
HF
2.1 Γ— 10⁻³ /yr (PSV blockage + upstream overpressure)
RRF
5,900
SIL_target
SIL 3
Consequence
Potential 300 mΒ² jet fire, IFR = 3.8 Γ— 10⁻⁡/yr pre-mitigation
PFDavg_measured
1.7 Γ— 10⁻⁴
Proof_Test_Interval
6 months

πŸ—οΈ Applications

  • Design of emergency shutdown systems (ESD)
  • Justification of fire & gas detection coverage
  • Verification of burner management systems (BMS)
  • Cybersecurity risk integration into SIS architecture

πŸ“‹ Real Project Case

Automated Assembly Line Robot Cell Risk Assessment

Tier-1 automotive supplier, Ohio plant upgrade

Challenge: New collaborative robot (cobot) integration without physical guarding
Collaborative Robot Cell COBOT Operator S = 725 mm (ISO/TS 15066) Speed & Separation Monitoring PL = PLd (ISO 13849-1) No Physical Guarding Automated Assembly Line Robot Cell Risk Assessment
Read full case study β†’

🎨 Technical Diagrams

ALARP Decision TreeAcceptFurther Mitigation?No
SIL Determination FlowHazard Frequency (HF)Consequence SeverityRisk MatrixSIL 2

πŸ“š References