Layer of Protection Analysis (LOPA): SIL Assessment Step-by-Step

Share:
Process Safety
Layer of Protection Analysis (LOPA): SIL Assessment Step-by-Step

LOPA is a semi-quantitative method to determine whether existing safeguards are sufficient and, if not, what SIL a new Safety Instrumented Function (SIF) must achieve to reduce risk to a tolerable level.

This guide explains the LOPA method step by step, defines Independent Protection Layers (IPLs), shows a worked reactor overpressure example, and includes a live LOPA SIL calculator.

Initiating Event Frequency IPL PFD Criteria Tolerable Risk Target SIL Determination

LOPA sits between a qualitative hazard study (HAZOP) and a full quantitative risk assessment. It is more rigorous than a HAZOP because it puts numbers on frequencies and probabilities.

It is faster than a full QRA because it uses order-of-magnitude approximations rather than site-specific modelling. Most SIL determinations in the process industry are made using LOPA.

LOPA

What Is LOPA and When Is It Used?

Hello! Today we are covering LOPA — the Layer of Protection Analysis method used to determine what SIL a Safety Instrumented Function must achieve. LOPA is the standard bridge between a HAZOP study (which identifies hazards qualitatively) and SIL verification (which confirms that a designed SIF meets its SIL numerically). It is defined in IEC 61511-3 Annex F and in the CCPS LOPA book (2001). Every process safety engineer working on SIS design needs to understand how LOPA scenarios are built and how the SIL target is derived.

A LOPA scenario represents one specific accident sequence: one initiating event (a cause) leading to one consequence (a harm) through a defined set of safeguards. Each LOPA scenario is analysed independently.

The output of a LOPA scenario is a mitigated consequence frequency — the estimated frequency at which the consequence reaches people or equipment at risk, after all existing safeguards have been credited.

This mitigated frequency is compared against a tolerable risk target. If it exceeds the target, additional risk reduction is required — typically a SIF at a specific SIL.

Did You Know? The LOPA method was first formalised by the American Institute of Chemical Engineers' Center for Chemical Process Safety (CCPS) in 2001 with the publication of "Layer of Protection Analysis: Simplified Process Risk Assessment."

Before LOPA became standardised, SIL determination was often done qualitatively using risk matrices — a process that was faster but had no traceable numeric basis. LOPA gave the industry a defensible, documented method that sits between the speed of qualitative risk matrices and the rigour of full quantitative risk assessments.

IEC 61511-3 (the process sector application standard for functional safety) now includes LOPA as one of the recommended methods for SIL determination in its Annex F, alongside risk graphs and risk matrices.
IEC 61511
The process sector functional safety standard that references LOPA for SIL determination (Annex F)
IPL PFD
Each Independent Protection Layer is credited with a Probability of Failure on Demand (PFD) — typically 0.1 to 0.001
Tolerable risk
Typical tolerable frequency for a scenario with fatality consequence: 1×10⁻⁴ to 1×10⁻⁵ per year
SIL 1 to 3
SIL 1: PFD 0.1 to 0.01 | SIL 2: PFD 0.01 to 0.001 | SIL 3: PFD 0.001 to 0.0001
Advertisement

LOPA Method: 7 Steps for SIL Determination

1
Define the Scenario: Initiating Event and Consequence

Identify one initiating event (a cause) and one undesired consequence. The consequence category determines the tolerable risk target — companies use different targets for different severities (toxic release, fire, explosion, environmental damage).

A LOPA scenario is always one-to-one: one initiating event, one consequence. If a single initiating event can cause two different consequences, two separate LOPA scenarios are required.

2
Assign the Initiating Event Frequency

The IEF is the frequency at which the initiating event occurs, before any safeguards act. LOPA uses generic industry data rather than site-specific failure data.

Typical values: control loop failure 0.1 to 1 per year, operator error 0.1 per demand, PRV failure to open 0.01 per demand.

The IEF is the starting frequency in the LOPA calculation. All IPL credits are applied as multipliers to this frequency.

3
Identify Independent Protection Layers (IPLs) and Their PFDs

An IPL is a device, system, or action that prevents the consequence independently of the initiating event and all other IPLs. Each IPL is assigned a Probability of Failure on Demand (PFD).

To qualify as an IPL, a safeguard must be independent of the initiating event and other IPLs, capable of preventing the consequence on its own, auditable, and dependable.

A BPCS loop can be credited as one IPL only if it is independent of the initiating event. A SIS is always treated as a separate IPL from the BPCS.

4
Apply Enabling Conditions and Conditional Modifiers (if applicable)

Some scenarios only reach a consequence under specific conditions — ignition requires an ignition source.

These are conditional modifiers: probabilities multiplied into the scenario for the fraction of demands that lead to the consequence.

Common conditional modifiers: probability of ignition (0.01 to 0.5), probability of personnel in the hazard zone, probability of fatal injury given exposure. They reduce the scenario frequency before or after IPL credits.

5
Calculate the Mitigated Consequence Frequency

Multiply the IEF by the PFD of each IPL and all conditional modifiers. The product is the mitigated consequence frequency — how often the consequence reaches people or assets at risk.

Formula: Mitigated frequency = IEF × PFD(IPL1) × PFD(IPL2) × ... × conditional modifiers

6
Compare Against the Tolerable Risk Target

Compare the mitigated consequence frequency against the tolerable risk target. Typical targets for a fatality consequence: 1×10⁻⁴ per year to 1×10⁻⁵ per year. Some companies use 1×10⁻⁶ per year for catastrophic scenarios.

If the mitigated frequency is below the target, no additional risk reduction is required. If it exceeds the target, the gap must be closed by a new SIF at a defined SIL.

7
Determine the Required SIL for the SIF

If a new SIF is required, divide the tolerable risk target by the mitigated frequency without the SIF.

The PFD result maps to a SIL per IEC 61511: PFD 0.1 to 0.01 is SIL 1, PFD 0.01 to 0.001 is SIL 2, PFD 0.001 to 0.0001 is SIL 3.

This SIL becomes the design target for the SIS. See the SIL verification vs validation guide for how the SIL is confirmed after design.

Tip: Never credit the same safeguard as both the BPCS loop and a LOPA IPL in the same scenario.

The most common LOPA credit error is counting a control loop as an IPL in a scenario where that same loop's failure is the initiating event. If the high-pressure control loop failure is the cause of the scenario, the same loop cannot also be credited as a protection layer against its own failure.

A separate independent high-pressure alarm with operator response is a valid IPL (PFD typically 0.1) if the alarm and the control loop use different sensors. A pressure relief valve is a valid IPL (PFD typically 0.01) if it is sized and set correctly for the scenario. Always check independence before crediting any safeguard.
Advertisement

IPL PFD Reference Values Used in LOPA

Protection LayerTypical PFD CreditIPL Qualification Notes
BPCS control loop (independent of IE)0.1Only one BPCS credit per scenario. Sensor must be independent of the IE sensor.
High alarm with operator response (independent sensor)0.1Operator must have adequate time to respond. Response procedure must be documented and trained.
Pressure Relief Valve (PRV) to safe location0.01PRV must be correctly sized for the scenario. Inlet and outlet line design must be per API 520/521.
Rupture disc (upstream of PRV)0.01Can be combined with PRV as a single IPL — the combination PFD is the product of both.
Safety Instrumented Function (SIS) — SIL 10.01 to 0.1PFD must be confirmed by SIL verification per IEC 61511-1.
Safety Instrumented Function (SIS) — SIL 20.001 to 0.01PFD must be confirmed by SIL verification. Redundancy typically required.
Safety Instrumented Function (SIS) — SIL 30.0001 to 0.001High redundancy and diagnostic coverage required. Rarely achieved with a single sensor/actuator pair.
Dike or bund (for liquid containment)0.01Valid IPL only when consequence is spill to environment or fire, not vapour cloud explosion.
Emergency isolation valve (manual)0.1Only if operator has adequate response time and the valve is accessible during the scenario.
Operator response to BPCS alarm (non-SIS)0.1One operator response credit per scenario. Multiple alarm credits cannot both be taken if the same operator responds.

Running the LOPA Numbers on a Reactor Overpressure Scenario

Suppose a batch reactor has a runaway reaction scenario. The initiating event is loss of cooling water, estimated at 0.1 per year from generic data.

The consequence is reactor overpressure leading to rupture and toxic release causing potential fatality. The company tolerable risk target for a fatality scenario is 1×10⁻⁴ per year.

Reactor Overpressure LOPA — Worked Calculation
Initiating Event: Loss of cooling water supply
IEF: 0.1 per year (generic data for utility supply failure)
Consequence: Reactor overpressure, rupture, toxic release, fatality

Existing IPLs:
IPL 1: High temperature alarm (independent sensor) with operator response
    PFD = 0.1 (one BPCS alarm credit, operator has 15 min to respond)

IPL 2: Pressure relief valve set at 110% MAWP, discharging to safe vent
    PFD = 0.01 (PRV correctly sized for runaway scenario per API 520)

Conditional modifier: Probability of personnel in hazard zone = 0.25
(plant personnel present in the area 6 hours per 24-hour shift)

Mitigated frequency (without SIF):
= IEF × PFD(IPL1) × PFD(IPL2) × P(personnel in zone)
= 0.1 × 0.1 × 0.01 × 0.25
= 2.5×10⁻⁵ per year

Compare to tolerable risk target: 1×10⁻⁴ per year
2.5×10⁻⁵ is below 1×10⁻⁴ — risk is TOLERABLE without a SIF

Now suppose the PRV is not available (being tested). Removing IPL 2:
= 0.1 × 0.1 × 0.25 = 2.5×10⁻³ per year — EXCEEDS target by 25×
Required SIF PFD = Target / (IEF × IPL1 × conditional) = 1×10⁻⁴ / 2.5×10⁻³ = 0.04
PFD 0.04 falls within SIL 1 range (0.01 to 0.1) → SIF required at SIL 1
Did You Know? The LOPA method deliberately uses order-of-magnitude (OOM) frequency values rather than precise figures from reliability databases.

This is intentional. LOPA's founders recognised that the uncertainty in generic failure data is typically a factor of 3 to 10. Using precise-looking values like 0.087 per year instead of 0.1 per year creates a false impression of accuracy that is not supported by the data quality.

OOM values also make arithmetic fast and auditable. A reviewer can check the frequency multiplication in seconds. If a scenario requires more precision — for example, when the LOPA result is right on the boundary between two SILs — the company should escalate to a full fault tree analysis rather than trying to tune the LOPA input data.

LOPA SIL Calculator

LOPA SIL Determination Calculator
Enter initiating event frequency, IPL PFDs, and tolerable risk target to determine required SIF SIL
-
-
Advertisement

Watch: Layer of Protection Analysis — The Bridge from HAZOP to SIL (2025)

LOPA Questions Process Safety Engineers Ask

What is LOPA in process safety?
LOPA is a semi-quantitative method for determining whether existing safeguards reduce risk to a tolerable level and what SIL a new SIF must achieve. It is defined in IEC 61511-3 Annex F.
What is an Independent Protection Layer (IPL) in LOPA?
An IPL is a safeguard that prevents a hazardous consequence independently of the initiating event and other IPLs. It must be auditable, testable, and dependable. Each IPL receives a PFD credit.
What is the difference between LOPA and HAZOP?
A HAZOP identifies hazards qualitatively — what can go wrong and what safeguards exist. LOPA then assigns frequencies and PFDs to determine whether safeguards are sufficient and what SIL is required.
How is SIL determined from a LOPA result?
Divide the tolerable risk target by the mitigated frequency (without the SIF). The result is the required SIF PFD: 0.1 to 0.01 maps to SIL 1, 0.01 to 0.001 to SIL 2, 0.001 to 0.0001 to SIL 3.
Can a BPCS control loop be credited as an IPL in LOPA?
Yes, but only once per scenario and only if independent of the initiating event. If the BPCS loop failure is the initiating event, that loop cannot be credited as an IPL.

Related Articles on This Site

External References

Advertisement

What We Learn Today

  • LOPA is a 7-step semi-quantitative method: define the scenario, assign the initiating event frequency, identify IPLs and their PFDs, apply conditional modifiers, calculate the mitigated consequence frequency, compare against the tolerable risk target, and determine the required SIF SIL. The key formula is: Mitigated frequency = IEF × PFD(IPL1) × PFD(IPL2) × conditional modifiers.
  • An IPL must be independent of the initiating event and all other IPLs, capable of preventing the consequence on its own, auditable, and dependable. A BPCS control loop can only be credited once per scenario, and never in a scenario where that loop's own failure is the initiating event.
  • SIL is determined from LOPA by dividing the tolerable risk target by the mitigated consequence frequency without the SIF. The ratio gives the required SIF PFD, which maps to SIL 1, 2, or 3 per IEC 61511. LOPA is a design input — SIL verification confirms whether the actual SIS design achieves that PFD target.
“LOPA does not tell you that your plant is safe. It tells you whether the risk from one specific scenario, through one specific initiating event, is tolerable given the safeguards you have credited. A plant with fifty LOPA scenarios can pass all fifty and still have an unanalysed gap. LOPA is a discipline, not a guarantee.”

Leave a Reply

Your email address will not be published. Required fields are marked *