| name | lopa-analysis |
| description | Layer of Protection Analysis (LOPA) — initiating event frequency, consequence severity, independent protection layers (IPL), probability of failure on demand (PFD), SIL determination, CCPS guidelines, LOPA worksheets, SIS design (IEC 61511), risk reduction requirements, tolerable risk criteria. |
| metadata | {"priority":7,"promptSignals":{"phrases":["LOPA","layer of protection analysis","protection layer","SIL determination","PFD layer","IEC 61511 LOPA"],"minScore":3}} |
Layer of Protection Analysis (LOPA) — Complete Skill
Purpose and Scope
LOPA: semi-quantitative risk analysis method; determines how many layers of protection are needed to reduce risk to tolerable level; commonly used to determine SIL (Safety Integrity Level) for SIS (Safety Instrumented System)
Position in risk analysis hierarchy:
HAZOP → identifies hazardous scenarios (qualitative)
LOPA → quantifies risk per scenario → determines risk reduction needed (semi-quantitative)
SIL assignment → specifies required SIS performance
SIS design → implements SIL (IEC 61511)
Full QRA → detailed probabilistic (most costly; for major facilities)
CCPS (Center for Chemical Process Safety) LOPA guidelines:
CCPS "Layer of Protection Analysis: Simplified Process Risk Assessment" (2001) — standard reference text
IEC 61511-3 (Annex F): guidance on using LOPA for SIL determination
LOPA Methodology
Step 1: Scenario Identification
Scenario pair: (initiating event, consequence)
One scenario per LOPA worksheet; multiple LOPA scenarios per HAZOP deviation
Scenario structure:
IE (Initiating Event) → (absence of safeguards) → Consequence
Each scenario: one specific combination of IE + consequence at one specific location
Scenario selection criteria:
Unmitigated consequences must be severe (fatality/serious injury/major release/significant environmental)
Minor consequences → LOPA not warranted; use engineering judgment + HAZOP recommendation
Step 2: Consequence Severity
Consequence categories:
| Category | Description | Example |
|---|
| 1 | Minor injury; no offsite impact | Minor spill, contained |
| 2 | Serious injury (1 person); small offsite impact | Hospitalization; vapor release |
| 3 | Single fatality; moderate offsite impact | Fatality on-site; small toxic release |
| 4 | Multiple fatalities on-site | Major explosion |
| 5 | Multiple fatalities on-site + offsite | Catastrophic release, community impact |
Tolerable Risk Criteria (TRC):
Typical corporate TRC: f_tolerable = 10⁻⁴/yr (single fatality) to 10⁻⁵/yr (multiple fatality)
ALARP (As Low As Reasonably Practicable): all risks in ALARP region should be reduced where practicable
Step 3: Initiating Event Frequency (f_IE)
Initiating event frequency: f_IE [events per year]
| Initiating Event | Typical f_IE [/yr] |
|---|
| Control loop failure (PID loop failure to control) | 1 |
| Operator error (simple, single task, routine) | 10⁻¹ |
| Operator error (complex, stressed, multiple steps) | 10⁻¹ to 1 |
| Pump seal failure | 0.1 |
| Relief valve open (demand) | 10⁻² |
| Regulator/control valve failure | 0.1–1 |
| External power failure | 0.1 |
| Lightning strike | 10⁻³ |
| Cooling water failure | 0.1 |
| LOPA-excluded event (catastrophic structural failure) | 10⁻⁵ (screened out) |
| Basic process control system (BPCS) failure | 10⁻¹ |
Source: CCPS "Guidelines for Independent Protection Layers and Initiating Events" (2014); ISA-TR84.00.04
Step 4: Independent Protection Layers (IPLs)
IPL definition (must satisfy all):
- Independent: not affected by the initiating event or failure of other IPLs
- Functional: capable of preventing the consequence if functional
- Auditable: tested to verify PFD
- Adequate: sufficient to prevent the consequence (not just mitigate)
Typical IPL candidates and PFD:
| IPL | Typical PFD |
|---|
| BPCS (Basic Process Control System, different from IE) | 10⁻¹ to 10⁻² |
| Human response to alarm (well-trained, > 10 min) | 10⁻¹ |
| Human response to alarm (< 10 min, stress) | Not credible as IPL |
| Safety Instrumented Function (SIL 1) | 10⁻¹ to 10⁻² |
| Safety Instrumented Function (SIL 2) | 10⁻² to 10⁻³ |
| Safety Instrumented Function (SIL 3) | 10⁻³ to 10⁻⁴ |
| Pressure relief valve (single) | 10⁻² |
| Pressure relief valve (system with scrubber/flare) | 10⁻² (valve) × 10⁻² (flare) = 10⁻⁴ combined |
| Dike/bund (liquid containment) | 10⁻² |
| Emergency shutdown valve (ESDV, non-SIS) | 10⁻¹ |
| Blast wall/bunker | 10⁻² |
| Automatic deluge/suppression | 10⁻¹ |
What is NOT an IPL:
- Same BPCS that already failed as initiating event
- Training alone
- Procedures without confirmation of execution (unless human operator IPL with PFD 10⁻¹)
- Equipment sharing common cause failure with IE
Step 5: Risk Calculation
Scenario frequency after protection:
f_scenario = f_IE × Π PFD_i [product of all IPL PFDs]
Example:
f_IE = 0.1/yr (pump seal failure → overfill)
IPL1: BPCS high level trip: PFD = 10⁻¹
IPL2: High-high level trip (SIS): PFD = 10⁻²
IPL3: Relief valve: PFD = 10⁻²
f_scenario = 0.1 × 10⁻¹ × 10⁻² × 10⁻² = 10⁻⁶/yr
Compare to TRC:
If TRC = 10⁻⁵/yr (single fatality) → f_scenario (10⁻⁶) < TRC → risk tolerable → no additional IPL needed
If f_scenario > TRC → need additional risk reduction (more IPLs or higher SIL SIS)
Step 6: Gap Analysis and SIL Requirement
Required risk reduction:
RRF_required = f_IE_unmitigated / f_tolerable [risk reduction factor needed from all IPLs combined]
f_IE_unmitigated = f_IE × PFD_existing_non-SIS_IPLs [after crediting existing IPLs except SIS being designed]
Required SIS PFD:
PFD_SIS_required = f_tolerable / f_IE_unmitigated_after_other_IPLs
SIL from PFD:
SIL 1: PFD = 10⁻¹ to 10⁻² (RRF 10–100)
SIL 2: PFD = 10⁻² to 10⁻³ (RRF 100–1,000)
SIL 3: PFD = 10⁻³ to 10⁻⁴ (RRF 1,000–10,000)
SIL 4: PFD = 10⁻⁴ to 10⁻⁵ (RRF 10,000–100,000) — rarely justified; enormous cost and validation burden
SIL 3 practical notes: very difficult to achieve with conventional SIS; requires 2oo3 voting + diagnostic coverage > 99%; typically reserved for consequences of multiple fatalities on-site
LOPA Worksheet Structure
Standard LOPA worksheet columns:
- Scenario ID (HAZOP node + deviation + consequence)
- Consequence description and category
- Tolerable risk criterion f_tolerable [/yr]
- Initiating event description and f_IE [/yr]
- IPL 1 description and PFD₁
- IPL 2 description and PFD₂
- ... (additional IPLs)
- Mitigated frequency = f_IE × ΠPFD_i [/yr]
- Gap (mitigated f vs. TRC): (Gap = f_mitigated / f_tolerable)
- Additional RRF required from new SIS
- SIL determination
Example worksheet summary:
| Field | Value |
|---|
| Initiating event | Pump seal leak → HC release |
| f_IE | 0.1/yr |
| Consequence | Flash fire, 1 fatality potential |
| f_tolerable | 1×10⁻⁵/yr |
| IPL1: BPCS leak detection | PFD = 0.1 |
| IPL2: Operator response (10-15 min) | PFD = 0.1 |
| Mitigated frequency | 0.1 × 0.1 × 0.1 = 1×10⁻³/yr |
| Gap = 10⁻³/10⁻⁵ | RRF = 100 → need SIL 2 SIS |
SIS Design to Meet SIL (IEC 61511)
SIL Verification
PFD_avg for SIS (1oo1 architecture, proof test interval T_I):
PFD_avg = λ_D × T_I / 2 [λ_D = dangerous undetected failure rate; T_I = proof test interval]
For λ_D = 10⁻⁴ /hr; T_I = 8,760 hrs (1 year) → PFD_avg = 10⁻⁴ × 8,760 / 2 = 0.44 (fails SIL 1!)
1oo2 architecture (two sensors, trip if either fails):
PFD_1oo2 ≈ 2 × PFD_single² / (T_I × λ_D) [approximately; lower than 1oo1 by factor ≈ 2 PFD_single]
2oo3 architecture (majority vote):
PFD_2oo3 ≈ 3 × PFD_single² / (T_I × λ_D); lower PFD than 1oo1; higher than 2oo2 but safer (fails safe on single failure)
Coverage factor (DC — Diagnostic Coverage):
DC = fraction of dangerous failures detected by automatic diagnostics
High DC (> 99%): reduces undetected failure rate → λ_D_eff = λ_D × (1 - DC) + λ_D × DC × β [β = common cause fraction]
Proof Test Interval
Trade-off: shorter proof test interval → lower PFD_avg but higher maintenance cost
Optimal T_I: ALARP balanced by maintenance resources
T_I = 3 months: achievable SIL 2 with 1oo2 architecture
T_I = 12 months: achievable SIL 2 with 2oo3 architecture (more redundancy, fewer tests)
Standards
| Standard | Scope |
|---|
| IEC 61511 (ISA-84) | Functional safety for process industry SIS |
| IEC 61508 | Functional safety of E/E/PE safety-related systems |
| CCPS LOPA Guidelines | LOPA methodology (CCPS, 2001) |
| ISA-TR84.00.04 | Guidance for SIL determination using LOPA |
| API RP 14C | Safety analysis of production facilities |
| API RP 505 | Safety lifecycle (SIS for oil and gas) |
Output
Provide: scenario description (IE → consequence pair), consequence category (1–5) and severity description, f_IE [/yr] with source (CCPS table reference), TRC f_tolerable [/yr] (company or regulatory), list of IPLs (description, PFD, independence verification, credit claimed), mitigated scenario frequency f_mitigated [/yr], gap calculation (RRF_gap = f_mitigated/f_tolerable), required additional RRF from SIS, SIL assignment (SIL 1/2/3 with PFD range), SIS architecture to achieve SIL (1oo1/1oo2/2oo3, proof test interval T_I [months]), PFD_avg verification from architecture, and applicable standard (IEC 61511, CCPS LOPA guidelines, ISA-TR84.00.04).