Safety Requirements Specification: 9 Vital Items Done Right

Share:
Safety Systems
Safety Requirements Specification: 9 Vital Items Done Right

Many safety system failures trace back not to broken hardware but to a document that asked for the wrong thing. A clear, complete specification tells designers exactly what each protective function must do and how well.

IEC 61511 SIF Requirements Process Safety Time Bypass and Reset

Between hazard analysis and detailed design sits one document that shapes every safety function in a plant. This guide explains what it must contain and how to check response time against process safety time.

Hello everyone, today we are going to learn what a safety requirements specification is, what IEC 61511 expects it to contain and how to check a safety function response time.
safety requirements specification

What Is a Safety Requirements Specification?

A safety requirements specification, or SRS, is the IEC 61511 document that defines, for every safety instrumented function, what it must do and how reliably it must do it. It is written after hazard and risk assessment and before design in the SIS safety lifecycle.

Think of it as the contract between the process safety team and the instrument engineers. If a requirement is missing here, it will usually be missing in the finished system.

Feature image on good and bad safety specifications
Image credit: exida

exida highlights a UK HSE study from 2003 which found that 44 percent of control system accident causes were specification issues. No other lifecycle phase contributed more.

Where the SRS Fits

HAZOPHazards and causes identified
SIL AssessmentLOPA or risk graph sets targets
SRSFunctional and integrity requirements
DesignHardware, software and voting
ValidationTests prove the SRS is met

Inputs come from the HAZOP study and from LOPA or other SIL determination methods. The output feeds design and later validation.

exida notes that IEC 61511 calls for both a process safety SRS and a design SRS. The first states the need from the process view, while the second adds engineering detail for each device.

Two Kinds of Requirements

Functional Requirements
  • What process condition triggers action.
  • Trip point and measurement.
  • Safe state and final elements.
  • Response time and sequence.
Integrity Requirements
  • Target SIL or risk reduction.
  • Proof test interval.
  • Allowed spurious trip rate.
  • Architecture and diagnostics.

Every safety instrumented function needs both columns filled. A function with a SIL but no clear trip logic cannot be designed properly, and vice versa.

9 Vital SRS Contents

1
Safe State
Define the safe condition for each function.
2
Trip Points
Setpoints, units and measurement ranges.
3
Response Time
Maximum time to reach the safe state.
4
Bypass Rules
Who may bypass, how long and with what alarms.
5
Reset Method
Manual or automatic reset after a trip.
6
Proof Test
Interval, method and required coverage.
7
Spurious Trip Limits
Maximum acceptable false trip frequency.
8
Manual Shutdown
Hand switches and their independence.
9
Environment
Temperature, hazardous area, EMC and corrosion.

The SIL target for each item must match the result in SIL assessment. Cause and effect logic is often attached as a cause and effect matrix.

Proof test intervals written here drive the numbers in later calculations, see proof test interval and coverage.

Good and Bad Specification Habits

AspectGood SRSBad SRS
Trip logicClear setpoints and votingVague phrases like high pressure
TraceabilityEach SIF linked to a hazardNo link to HAZOP or LOPA
TimingResponse time statedTiming left to the vendor
TestingProof test method definedTesting not mentioned
OwnershipReviewed and approvedCopied from an old project

Copying a previous project SRS is a common shortcut that carries old assumptions into a new plant. Each function should be written from its own hazard scenario.

Process Safety Time Check

Total response = Sensor response + Logic solver time + Valve stroke time
Pass if Total response ≤ 50 percent of process safety time

Example:
Sensor 1 s, logic 0.5 s, valve stroke 6 s
Total response = 7.5 s
Process safety time = 20 s, allowed = 10 s
Pass with 2.5 s margin

The 50 percent rule is a common engineering practice, not a fixed rule of the standard. Some companies use other margins, so follow your own design basis.

Response Time Checker

SIF Response vs Process Safety Time
Result
Total response 7.5 s, allowed 10.0 s, Pass with 2.5 s margin

Valve stroke time usually dominates, so large valves may need faster actuators or quick exhaust solenoids. Record the tested stroke time during validation.

Benefits of a Strong SRS
  • Fewer design errors and rework.
  • Clear basis for validation tests.
  • Consistent bypass and reset rules.
  • Easier audits and assessments.
Common Pitfalls
  • Missing response times.
  • Vague or copied text.
  • No spurious trip target.
  • Not updated after changes.

The specification is the benchmark for SIL verification and validation. Assessors also check it during a functional safety assessment.

ABB SRS Factsheet PDF

PDF
Safety Requirements Specification Factsheet
ABB functional safety management factsheet

Writing the Specification Video

Safety Requirements Specification FAQ

What is a safety requirements specification?
It is the IEC 61511 document that defines what each safety function must do and how reliably. Designers build and test the system against it.
When is the SRS written?
It is written after hazard analysis and SIL assessment are complete. It must be approved before detailed design starts.
What are process and design SRS?
The process SRS states the safety need from the process view. The design SRS adds device, architecture and software detail for engineers.
Why do specifications cause accidents?
exida cites a UK HSE study where 44 percent of control system accident causes were specification issues. Missing or vague requirements lead directly to unsafe designs.
What is process safety time?
It is the time between a failure starting and the hazardous event occurring without action. The safety function must reach the safe state well within it.
Should the SRS include spurious trip limits?
Yes, a maximum acceptable false trip rate helps designers choose voting and devices. It protects availability as well as safety.
Who approves the SRS?
Process safety, operations and instrument engineering usually review and approve it together. It is placed under change control after approval.

Related Articles

External References

What We Learn Today

  • A safety requirements specification defines function and integrity for every SIF.
  • Include safe state, trip points, timing, bypass, reset and testing.
  • Check response time against process safety time with a clear margin.
I hope you like above blog. There is no cost associated in sharing the article in your social media. Thanks for reading!! Happy Learning!!

Leave a Reply

Your email address will not be published. Required fields are marked *