Stepin Engineering

Blog

How SIL Assessment LOPA Works at a Petroleum Terminal

May 28, 2026

SIL Assessment LOPA process safety engineer in full PPE reviewing industrial safety data in front of large petroleum storage tanks during sunrise at an oil terminal.

Introduction: The Risk Nobody Talks About at the Start of a Project

Most engineers who walk into a petroleum terminal for the first time focus on the obvious: the tanks, the pipelines, and the loading arms. What they rarely think about immediately is what happens when the level gauge fails, the alarm doesn’t sound, and a storage tank overflows.

That is not a hypothetical. It is exactly the kind of scenario that a proper SIL assessment LOPA study is designed to quantify and address it.

At a 10-acre terminal handling Motor Spirit (MS), High-Speed Diesel (HSD), and Aviation Turbine Fuel (ATF), the consequences of a single overflow event can range from a large-scale fire to a fatality. The question is not whether such a scenario is possible; it clearly is. The real question is: do the existing safeguards reduce that risk to a level the company and its regulators can accept?

This article walks through a complete, real-world case study: what the team analysed, how the numbers were calculated, and what the results mean for day-to-day operations at the terminal.

What Is SIL, and Why Does Every Process Facility Need to Know?

SIL Assessment LOPA industrial digital safety monitor displaying SIL 1 to SIL 4 classifications with green and amber indicators inside a blue-lit process plant control room.

SIL stands for Safety Integrity Level. It is a discrete performance target from SIL 1 to SIL 4  that defines how reliable a Safety Instrumented Function (SIF) must be. The higher the SIL level, the more robust the system design, testing regime, and maintenance program must be.

Two international standards govern this work in the process industry:

  • IEC 61508 – the parent functional safety standard for electrical, electronic, and programmable safety-related systems
  • IEC 61511 – the process industry-specific implementation standard, directly applicable to petroleum terminals, refineries, and chemical plants

Here is how the four SIL levels translate into measurable performance requirements:

SIL LevelPFD RangeAvailabilityRisk Reduction Factor (RRF)
SIL 110⁻² to 10⁻¹90–99%10 to 100
SIL 210⁻³ to 10⁻²99–99.9%100 to 1,000
SIL 310⁻⁴ to 10⁻³99.9–99.99%1,000 to 10,000
SIL 410⁻⁵ to 10⁻⁴>99.99%10,000 to 100,000

PFD – Probability of Failure on Demand – is the number that drives every calculation in this methodology. A SIL 1 system with a PFD of 0.01 has a one-in-a-hundred chance of failing to act when a hazardous demand occurs. In a facility storing thousands of tonnes of flammable product, that figure has to be backed by actual failure rate data and verified through regular proof testing.

One distinction that trips up many engineers when they first encounter this work: SIL classification and SIL verification are separate activities. Classification determines what SIL level a function requires. Verification – done afterward – confirms whether the actual instrumentation design achieves it. This article covers the classification phase entirely.

SIL Assessment LOPA: What the Methodology Actually Does

SIL Assessment LOPA engineering risk analysis flowchart for petroleum facilities showing hazard identification, barrier analysis, consequence modeling, and control measures.

Layer of Protection Analysis is a semi-quantitative risk tool developed by the Center for Chemical Process Safety (CCPS/AIChE). It takes the hazard scenarios identified in a HAZOP study and converts them into structured, defensible probability calculations by assigning standardised frequency values to each protection layer.

The term “semi-quantitative” matters here. SIL assessment LOPA does not rely on precise statistical modelling for every variable. Instead, it uses order-of-magnitude estimates validated across decades of process industry operating experience making it significantly faster than a full quantitative risk assessment while remaining rigorous enough to support SIL-level decisions under IEC 61511.

The process runs in a consistent six-step sequence:

Step 1 – Identify all SIF loops. Every safety-instrumented function in scope is listed. The team defines the hazardous event each SIF is intended to prevent.

Step 2 – Assign initiating cause frequencies. For each SIF, the team lists the causes that could trigger the hazardous event and assigns an order-of-magnitude frequency in events per year.

Step 3 – Assess consequence severity. The potential outcome across safety, environment, asset, and reputation is assigned a consequence category from 1 to 5. Each category carries a Tolerable Event Frequency (TEF) drawn from the company’s risk matrix.

Step 4 – Apply conditional modifiers. Not every initiating event escalates to the worst-case consequence. Conditional modifiers, ignition probability and operator presence probability adjust the frequency to reflect real-world conditions.

Step 5 – Credit Independent Protection Layers (IPLs). Each independent barrier that can prevent the consequence is credited with its probability of failure on demand. The combined risk reduction is the product of all credited IPL PFDs.

Step 6 – Compare MEF against TEF. The Mitigated Event Frequency (MEF) is compared to the Tolerable Event Frequency (TEF). The gap between them determines whether a SIF is required and at what SIL level.

The core formula:

MEF = Initiating Event Frequency × Conditional Modifiers × (Product of all IPL PFDs)

  • If MEF ≤ TEF → existing safeguards meet the risk target
  • If MEF > TEF → a SIF is required; the required SIL level closes the gap

What makes this methodology particularly useful in practice is that it forces every assumption into the open. Every IPL credit, every conditional modifier, every initiating frequency all of it sits in the worksheet and can be reviewed, challenged, and updated as the facility changes over time.

The Petroleum Terminal Study: Scope and Context

The terminal assessed in this study covers 10 acres and receives petroleum products — MS, HSD, and ATF through ocean tankers as the primary mode, with a railway gantry facility for wagon receipt during product supply constraints. All product dispatch to end consumers happens through tank trucks.

The study was conducted by iFluids Engineering in accordance with IEC 61511 and CCPS LOPA guidelines, covering five Safety Instrumented Functions, one assigned to each of the five storage tanks in the facility.

All five SIFs share the same configuration: Level Switch High High High (LSHHH) monitoring on storage tanks T1 through T5.

The hazard scenario is consistent across all five loops: a high liquid level in the storage tank leads to overflow, with potential consequences including fire, fatality, major injury, or significant equipment damage. Treating each tank as a separate SIF loop rather than grouping all five ensures that any tank-specific IPL differences are properly captured in the worksheets.

SIL Assessment LOPA in Action: Walking Through T1-LSHHH-01

SIL Assessment LOPA technical blueprint illustration of a petroleum storage tank cross-section featuring radar level gauges, alarms, valves, piping, and engineering annotations.

Tank 1 (T1) provides the clearest worked example. The same logic and numbers apply to T2 through T5.

Initiating Causes Identified

Three initiating causes were established through the team review:

1. Primary radar gauge malfunction The primary-level transmitter fails without generating an alarm. This is categorised as an independent SIF (SIL 1) failure. Initiating frequency: 1.0 × 10⁻¹ per year.

2. Secondary radar gauge malfunction The backup level measurement device fails in the same mode. Frequency: 1.0 × 10⁻¹ per year. Both gauge failures are treated as separate initiating causes because they use independent measurement devices on the same tank.

3. Inlet MOV / POV stuck open The motor-operated or pneumatically operated inlet valve fails to close or closes and spuriously reopens during product receipt. Frequency: 1.0 × 10⁻² per year.

Enabling Conditions and Conditional Modifiers

The Terminal operates as a continuous process and the enabling event probability is 1.0. The tank is in active service, receiving product regularly, with no window of unavailability to reduce exposure.

The conditional modifier applied across all three initiating causes is operator presence at 10% a probability of 0.1. This reflects the realistic likelihood that a trained operator is physically positioned to observe and independently respond to the developing situation without relying on the instrumented alarm system.

Unmitigated Event Frequencies

For primary and secondary gauge failure scenarios (Safety & Health, Environment – Cat 4): UEF = 1.0 × 10⁻¹ × 1.0 × 0.1 = 1.0 × 10⁻²

For the inlet valve failure scenario (Financial – Cat 3): UEF = 1.0 × 10⁻² × 1.0 × 0.1 = 1.0 × 10⁻³

IPLs Credited

For gauge failure scenarios – one IPL credited:

  • Critical Alarm and Human Intervention (T1-LAHH-02S or T1-LAHH-01P) – PFD 0.1

For the inlet valve failure scenario, two IPLs were credited:

  • T1-LAHH-01P Critical Alarm — PFD 0.1
  • T1-LAHH-02S Critical Alarm — PFD 0.1
  • Combined PFD: 0.1 × 0.1 = 0.01

Mitigated Event Frequency and SIL Determination

Safety & Health scenario (Cat 4, TEF = 1.0 × 10⁻⁴): MEF = 1.0 × 10⁻² × 0.1 = 1.0 × 10⁻³ LOPA GAP RRF = TEF / MEF = 20.10 → SIL 1

Financial scenario (Cat 3, TEF = 1.0 × 10⁻³): MEF = 1.0 × 10⁻³ × 0.01 = 1.0 × 10⁻⁵ This scenario already meets the TEF without additional SIF credit.

The SIL 1 classification is driven by the safety and health consequences. The result from this SIL assessment LOPA worksheet means the complete SIF – level sensors, logic solver, and ESD valve – must achieve a PFD between 0.01 and 0.1. That is the verified performance target the instrumentation design must satisfy.

How Independent Protection Layers Are Evaluated in SIL Assessment LOPA

IPL is a term that gets used loosely in many engineering conversations, but the methodology has strict qualifying criteria. A protection layer only earns credit if it satisfies three conditions:

  • Independent –  no shared hardware, software, or common-cause failure modes with the initiating event or with other credited IPLs
  • Auditable: Its claimed performance can be demonstrated through testing and records
  • Capable: It can arrest the hazardous scenario on its own, without relying on any other layer

The protection layer hierarchy applied in this study follows the standard CCPS model:

  1. Process design — inherent safety built into the process itself
  2. Basic Process Control System (BPCS)
  3. Prevention systems — Pressure Safety Valves (PSVs) and the Safety Instrumented System (SIS)
  4. Mitigation systems — fire and gas detection, deluge, bund walls
  5. Plant emergency response
  6. Community emergency response

One point that the study team emphasises consistently: the BPCS and the SIS must remain fully independent. Routing both the control function and the safety function through the same DCS hardware eliminates that independence and disqualifies the safety layer from receiving IPL credit. Many sites get this wrong, and it only surfaces during a formal review.

Standard PFD values used in this study, referenced from CCPS (2001):

IPL TypePFD
Basic Process Control System (BPCS)1.0 × 10⁻¹
Pressure Safety Valve (PSV)1.0 × 10⁻²
SIL 1 ESD valve1.0 × 10⁻¹
Operator alarm response — trained, low stress1.0 × 10⁻¹
Dikes — capable of containing the hazard1.0 × 10⁻¹
Blastproofing1.0 × 10⁻²

These are conservative industry-wide averages. Facility-specific data showing better performance can be used but it must be documented and justified within the worksheet, not assumed.

SIL Assessment LOPA Results: What the Study Concluded

SIL Assessment LOPA dashboard illustration showing five industrial storage tanks labeled T1 to T5 with green SIL 1 safety classification badges in a modern flat-design layout.

All five SIF loops T1-LSHHH-01 through T5-LSHHH-01 were classified as SIL 1.

The existing combination of primary radar gauges, secondary radar gauges, high-high level alarms, and trained operator response provides sufficient risk reduction to keep the mitigated event frequency within the tolerable limit. No additional safeguards or barriers were required.

That result surprises some engineers the first time they see it. There is an assumption that a study like this always ends with a recommendation to add hardware or upgrade systems. When a Terminal has been designed with genuine independence between measurement devices, redundant alarms, and a properly trained operations team, the analysis frequently confirms that what is already in place is adequate, and that is a valid and valuable conclusion.

Two recommendations were raised by the team not because the SIL assessment LOPA identified risk gaps, but to preserve the effectiveness of the credited IPLs across the operational life of the facility, 

Recommendation 1: Carry out periodic calibration and functional testing of the primary radar gauge, secondary radar gauge, and level switch on all five storage tanks applicable across SIF-01 to SIF-05.

Recommendation 2: Carry out functional testing of the shutdown system to confirm proper opening and closing of inlet MOVs and POVs on all storage tanks on demand.

These are not optional. The PFD values credited in any LOPA worksheet is only valid when the devices involved are being maintained and tested at the intervals the calculation assumes. A radar gauge that has not been calibrated in three years does not carry a PFD of 0.1 its actual PFD is unknown and likely worse.

What SIL 1 Actually Demands from Engineering and Operations Teams

A misconception that comes up frequently among engineers new to functional safety: SIL 1 is the lowest classification, so it must mean the system is “barely safe”. That reading is wrong.

SIL 1 means the risk has been formally quantified, the protection layers have been evaluated against a company-approved risk matrix, and the residual risk falls within an accepted tolerable frequency. The terminal is not operating at the margin of safety; it is operating within a defined, auditable risk boundary established through the SIL assessment LOPA process.

Delivering SIL 1 over the operational life of the terminal requires specific commitments from both engineering and operations:

  • The SIF must achieve and maintain a PFD between 0.01 and 0.1
  • Instrumentation must be selected from SIL rated products with documented, certified failure rate data per IEC 61508
  • A Proof Test Interval must be established and followed; annual testing is typical for SIL 1 in low-demand mode
  • Test records must be maintained so PFD performance can be verified and reported throughout the asset lifecycle

The classification study is the starting point. Everything that follows SIL verification, safety requirements specification, instrumentation selection, proof test procedures, and management of change is the engineering work that actually delivers and sustains that classification in the field.

Key Takeaways from This SIL Assessment LOPA Study

SIL Assessment LOPA minimalist illustration of an engineer reviewing a safety checklist on a clipboard in front of industrial petroleum storage tanks at a terminal facility.

For process safety engineers, instrumentation engineers, and operations personnel at facilities handling flammable or hazardous materials, this case study makes several things clear:

It produces a number, not a judgement call. Instead of relying on experience or intuition alone, SIL assessment LOPA gives a calculated, auditable gap between existing protection and the tolerable risk target. That number can be challenged, updated, and defended in front of regulators, which informal risk reviews cannot.

Independence is not assumed — it has to be demonstrated. Every IPL credit in the worksheet must survive scrutiny. Shared power supplies, shared logic processors, or shared signal paths between the BPCS and the SIS destroy the independence that IPL credit depends on.

The PFD values are only as good as the maintenance program behind them. Calibration schedules, proof test intervals, and failure reporting are what keep those credits valid in practice. The numbers in the worksheet reflect design intent; maintenance is what delivers it.

Classification is not the finish line. The SIL level determined through this process feeds directly into SIL verification, the exercise that confirms the actual design achieves the required PFD. Under IEC 61511, classification without verification is incomplete.

“For facilities requiring deeper risk quantification beyond LOPA, our Quantitative Risk Assessment training covers QRA and FERA methodology.”

Conclusion

A petroleum storage tank overflow is not a remote, theoretical risk. It is a credible consequence of instrument failure, valve malfunction, or inadequate operator response – with outcomes that can include fire, fatalities, and major environmental damage.

SIL assessment LOPA gives engineering teams a structured, transparent, and defensible method to determine whether existing safeguards are sufficient. In this study, five loops across five petroleum storage tanks all reached the same conclusion: the existing protection layers meet the SIL 1 performance target. Two practical recommendations ensure that classification remains valid as the terminal continues operating.

If your facility handles flammable or hazardous materials and has not yet carried out a formal review, this methodology is the right place to start. It tells you where the real gaps are, what SIL level your safety functions need to achieve, and what testing and maintenance commitments are required to keep risk within bounds not as a one-time exercise, but across the full operational life of the facility.

Frequently Asked Questions About SIL Assessment LOPA

What is the difference between LOPA and HAZOP?

HAZOP is a qualitative technique that identifies what can go wrong and why. SIL assessment LOPA is semi-quantitative and it takes the scenarios HAZOP identifies and calculates how much risk reduction the safety instrumented system must deliver. HAZOP defines the hazard; LOPA determines the required safeguard performance.

What does a SIL 1 classification mean for instrumentation selection?

A SIL 1 result means the safety instrumented function must achieve a PFD between 0.01 and 0.1. Instruments must be selected from certified SIL-rated products, and the complete SIF sensor, logic solver, and final element must be verified to meet the target PFD through a separate SIL verification calculation.

How often do SIL 1 systems need proof testing?

For SIL 1 systems operating in low-demand mode, annual proof testing is standard practice. The actual interval should be set by the SIL verification calculation for that specific SIF and documented in the Safety Requirements Specification. The SIL assessment LOPA study determines the required SIL level not the proof test interval itself.

Can the BPCS be credited as an IPL in a LOPA worksheet?

Yes, provided it is fully independent of the initiating cause being analysed. The BPCS typically receives a PFD credit of 0.1. However, if the initiating cause is itself a BPCS failure, the BPCS cannot be credited as an IPL for that scenario crediting the system that failed as a protection against its own failure violates the independence requirement directly.

Is a SIL assessment LOPA study required for petroleum terminals in India?

While not universally mandated by a single piece of legislation, it is required practice under IEC 61511 for any facility implementing safety instrumented systems. Major oil companies, port authorities, and HSE regulators increasingly require a documented SIL assessment LOPA study as part of project safety deliverables and operating permit conditions.