Quantitative Risk Assessment: ALARP, FMEA, and SIL Determination
Quantitative Risk Assessment is a way engineers measure how likely and how bad accidents could be β then use math and data to decide what safety steps are truly needed.
⚠️ Why It Matters
π Definition
Quantitative Risk Assessment (QRA) is a structured engineering methodology that assigns numerical probabilities and consequences to hazardous events, enabling objective evaluation of risk levels against defined tolerability criteria. It underpins ALARP (As Low As Reasonably Practicable) justification, supports Failure Modes and Effects Analysis (FMEA) severity-probability scoring, and informs Safety Integrity Level (SIL) determination per IEC 61508 and IEC 61511. QRA integrates fault tree analysis, event tree analysis, consequence modeling (e.g., dispersion, blast overpressure), and reliability data to derive risk metrics such as individual fatality risk (IFR) or societal risk (FN curves).
π¨ Concept Diagram
AI-generated illustration for visual understanding
π‘ Engineering Insight
ALARP is not a mathematical endpoint β itβs an engineering judgment anchored in evidence. A SIL assignment without documented cost-benefit analysis and stakeholder consultation is legally indefensible in jurisdictions like UK HSE or EU Seveso III. Always trace PFDavg back to component-level Ξ»DU and diagnostic coverage; 'black box' SIL tools without transparent inputs violate IEC 61508 Part 2 Β§7.4.2.
π Detailed Explanation
Deeper analysis requires understanding dependencies: common-cause failures (CCFs) can reduce effective redundancy by >50% if not modeled via beta-factor or MGL methods; proof test coverage (DC) directly modulates PFDavg β a 10% drop in DC from 95% to 85% increases PFDavg by ~4Γ for a 1oo2 architecture. Human factors, maintenance quality, and environmental stressors (e.g., corrosion, EMI) must be factored into Ξ»DU adjustments, not treated as afterthoughts.
At the advanced level, QRA integrates dynamic methods: Bayesian updating refines Ξ» estimates using site-specific failure history; Monte Carlo simulation captures parameter uncertainty (e.g., Β±30% on dispersion model coefficients); and digital twin-enabled continuous PFD monitoring uses real-time sensor health data to adjust functional safety performance in operation β moving beyond static SIL verification toward adaptive SIL assurance per IEC 61511 Ed.3 Annex F.
π Engineering Workflow
π Decision Guide
| Rock/Field Condition | Recommended Design Action |
|---|---|
| High-consequence scenario (e.g., >100 mΒ³ flammable release) with HF β₯ 10β»Β³/yr | Require SIL 3 SIF with redundant architecture (2oo3), DC β₯ 90%, proof test interval β€ 6 months |
| Moderate consequence (toxic exposure <10 people) with HF = 10β»β΄β10β»Β³/yr | SIL 2 SIF with 1oo2 architecture, DC β₯ 70%, proof test interval β€ 12 months |
| Low consequence (localized fire, no off-site impact) with HF β€ 10β»β΅/yr | SIL 1 or non-SIF mitigation (e.g., procedural controls, alarms); verify ALARP via cost-benefit analysis |
📊 Key Properties & Parameters
PFDavg
10β»Β² to 10β»β΅ (unitless)Average Probability of Failure on Demand β the long-term average likelihood that a Safety Instrumented Function (SIF) will fail to perform its intended safety action when required
Directly determines achievable SIL level; PFDavg β€ 10β»Β² required for SIL 1, β€ 10β»β΄ for SIL 2, β€ 10β»β΅ for SIL 3
RRF
10 to 10,000 (unitless)Risk Reduction Factor β ratio of process risk without a SIF to risk with the SIF in place
RRF = 1 / PFDavg; defines minimum risk reduction needed to meet target SIL and ALARP thresholds
Ξ»DU
1 Γ 10β»β· to 5 Γ 10β»β΅ /hrDangerous Undetected Failure Rate β frequency per hour at which a SIF fails dangerously *and* remains undetected until next proof test
Primary driver of PFDavg; dictates proof test interval, diagnostics coverage (DC), and hardware fault tolerance requirements
HF
10β»βΆ to 10β»ΒΉ /yrHazard Frequency β estimated rate (per year) at which initiating events (e.g., valve failure, leak, overpressure) occur
Multiplied by consequence severity to compute risk; anchors FMEA severity-probability matrices and event tree inputs
π Key Formulas
PFDavg (Simplified 1oo1)
PFDavg β Ξ»DU Γ T / 2Average probability of failure on demand for a single-channel SIF tested every T hours
| Symbol | Name | Unit | Description |
|---|---|---|---|
| PFDavg | Average Probability of Failure on Demand | dimensionless | Average probability that a safety instrumented function fails to perform its intended safety action when required |
| Ξ»DU | Dangerous Undetected Failure Rate | 1/hour | Rate at which dangerous failures occur and remain undetected until proof test |
| T | Proof Test Interval | hours | Time between successive proof tests of the safety instrumented function |
RRF
RRF = 1 / PFDavgRisk reduction factor provided by a Safety Instrumented Function
| Symbol | Name | Unit | Description |
|---|---|---|---|
| RRF | Risk Reduction Factor | Risk reduction factor provided by a Safety Instrumented Function | |
| PFDavg | Average Probability of Failure on Demand | Average probability that a Safety Instrumented Function fails to perform its intended function when required |
ALARP Cost-Benefit Threshold
Cost per statistical life (CPSL) = ΞCost / (ΞRisk Γ 10βΆ)Monetary value assigned to risk reduction; used to justify further safeguards
| Symbol | Name | Unit | Description |
|---|---|---|---|
| CPSL | Cost per Statistical Life | USD/life | Monetary value assigned to risk reduction; used to justify further safeguards |
| ΞCost | Change in Cost | USD | Incremental cost of implementing additional risk-reduction measures |
| ΞRisk | Change in Risk | fatalities per million | Reduction in fatality risk achieved by the safeguard |
🏭 Engineering Example
Grangemouth Refinery (INEOS, UK)
N/A β Process facility (hydrocarbon processing)ποΈ Applications
- Design of emergency shutdown systems (ESD)
- Justification of fire & gas detection coverage
- Verification of burner management systems (BMS)
- Cybersecurity risk integration into SIS architecture
π§ Calculate This
β‘π Real Project Case
Automated Assembly Line Robot Cell Risk Assessment
Tier-1 automotive supplier, Ohio plant upgrade