Opens in a new tab

Independence

Independence means one thing can’t be undermined by whatever undermines another. In functional safety it applies to people and to equipment. For people, whoever checks the work shouldn’t be whoever did it. For equipment, the test is freedom from a shared cause of failure, and it applies at two levels: between the protection layers credited against a scenario, and between the redundant channels inside a single safety instrumented function.

Key Points

  • Reviewer independence means not having done the work being checked. A senior colleague off the project usually qualifies, and IEC 61508 raises the bar to an independent department or organization as the consequence and safety integrity level climb.
  • A protection layer has to be independent of the initiating cause and of the other layers credited for the same scenario, which is also why the safety instrumented system is kept separate from the basic process control system.
  • Architecture, a 1oo2 or 2oo3 counts on its channels failing independently. Anything they share, such as a process tap, a power supply, firmware, or a test procedure, eats into that, and the β factor is how the math accounts for it.
  • How much independence is enough isn’t fixed anywhere; it scales with complexity, novelty of the design, and the required safety integrity level.

Example

A control loop fails and lets a vessel overpressure. The team wants to credit a high-pressure alarm as an independent protection layer, but the alarm comes off the same transmitter as the control loop. When that transmitter fails, it starts the event and blinds the alarm in the same moment, so the alarm isn’t independent and gets no credit.

See Also: FSA, IPL, HFT, CCF

Cited Sources

  • IEC 61511-1:2016, Clauses 3.2.31, 3.2.32, 3.2.41 and 9.2.6
  • IEC 61508-1:2010, Clause 8.2.15 (Tables 4 and 5)
Part Of: reviewing category