LOPA vs Risk Graph vs Risk Matrix for SIL Determination

Last updated: July 13, 2026

Two engineers reviewing SIL determination worksheets and loop diagrams in a control room

A facility with 70 identified Safety Instrumented Functions and three different engineers running the SIL study rarely ends up with three consistent answers. One engineer defaults to a risk matrix because it is what the HAZOP already uses. Another builds a calibrated risk graph. A third insists on LOPA for anything above a minor consequence rating. Six months later, an auditor asks why two functionally identical loops on the same unit carry different SIL targets, and nobody can point to a documented reason. That inconsistency is not a paperwork problem. It is what happens when LOPA vs risk graph vs risk matrix gets decided informally, function by function, instead of as a deliberate methodology choice made before the SIL study starts.

IEC 61511-3 provides guidance and examples for several SIL determination techniques, including risk graphs, risk matrices, and LOPA. It does not prescribe which one an operating company must use for a given application. That flexibility is useful, but it also means the operating company must establish a documented method appropriate to its own risk criteria and apply it consistently. A recurring issue identified during functional-safety reviews is inconsistent, undocumented method selection across similar SIFs. This article compares how the three SIL determination methods actually work, where each is defensible, and how to choose between them without defaulting to whichever one the team used last time.

Why the SIL Determination Method You Choose Actually Matters

The SIL determination method chosen for a Safety Instrumented Function directly sets its required risk reduction factor, and different methods can produce different SIL ratings for the same hazard scenario. Risk graphs and risk matrices are qualitative-to-semi-quantitative methods, but they operate differently: a risk graph evaluates consequence, exposure, avoidance, and unwanted-event frequency through a branching structure, while a risk matrix compares consequence with likelihood or the remaining risk gap on a calibrated grid. LOPA instead calculates an intermediate event frequency by combining the initiating-event frequency, enabling conditions and conditional modifiers, and the credited probability of failure on demand of each independent protection layer, then compares that result against the facility’s tolerable event frequency to determine the required risk reduction.

For low-demand SIFs, SIL is defined against a PFDavg band, and the required risk reduction factor (RRF) is the reciprocal of PFDavg:

SILPFDavg range (low-demand)Approximate RRF band
SIL 1≥10⁻² to <10⁻¹10 to 100
SIL 2≥10⁻³ to <10⁻²100 to 1,000
SIL 3≥10⁻⁴ to <10⁻³1,000 to 10,000

High-demand and continuous-demand applications use a frequency-based performance measure instead, so these RRF bands should not be treated as universal.

Because risk graphs and risk matrices use broader parameter bands and do not individually credit each protection layer, their results may differ from a LOPA study for the same scenario and may end up more or less conservative depending on how the method is calibrated and applied. Choosing a method that doesn’t match a facility’s scenario complexity can either over-design the SIS or leave a gap an auditor will eventually find.

A risk matrix or risk graph used without a clearly calibrated tolerable risk reference produces a result that is difficult to defend as a SIL basis, since the boundaries need to be traceable to a stated risk criterion. Where calibration and methodology documentation are missing, the organization may be required to revisit or repeat the SIL determination during an audit, revalidation, or management-of-change review.

How LOPA, Risk Graph, and Risk Matrix Actually Work

LOPA, risk graph, and risk matrix determine SIL through three distinct mechanisms.

LOPA is a semi-quantitative scenario analysis. It calculates the intermediate event frequency after crediting applicable non-SIF independent protection layers, enabling conditions such as occupancy, ignition probability, and probability of personnel exposure and conditional modifiers. The required SIF risk reduction is then obtained by comparing that intermediate event frequency with the facility’s tolerable event frequency. Each credited IPL must satisfy the organization’s requirements for independence, functionality, integrity, and auditability; some operating companies also impose limits on the number or magnitude of IPL credits that may be used in one scenario. The methodology also calls for combining multiple initiating-event scenarios when several contribute to the same required SIF performance. LOPA generally provides a more granular and transparent numerical basis than a risk graph or risk matrix, though the reliability of the result still depends heavily on the quality of the initiating-event frequencies, IPL failure data, independence assumptions, and tolerable-risk criteria used a numeric answer is not automatically a more accurate one.

Risk graph trades precision for speed. A calibrated risk graph plots four parameters through a branching decision tree to a SIL output: consequence severity (C), exposure or occupancy (F), probability of avoiding the hazard (P), and W the probability or frequency of the unwanted event occurring without the risk reduction provided by the SIF. IEC 61511-3 provides the calibration guidance a risk graph needs before it can be considered defensible; an uncalibrated graph has no traceable link to a tolerable risk criterion. A calibrated risk graph is a legitimate final SIL determination method in its own right under an organization’s approved methodology; it is not necessarily limited to a screening role, though it is commonly used that way to assess a large batch of SIFs quickly.

Risk matrix is the simplest of the three, and the easiest to misuse. A risk matrix plots consequence severity against likelihood on a grid whose cell boundaries must be calibrated to the same tolerable risk criterion used elsewhere in the facility’s safety case. Because the matrix does not credit specific independent protection layers individually, its broad likelihood and consequence bands can hide differences between scenarios that a more granular method would distinguish. That makes the risk matrix a reasonable screening tool, but its output needs care before it’s used to justify a lower SIL rating under audit.

Comparison table infographic showing LOPA, risk graph, and risk matrix basis, output, and effort
LOPA calculates a numeric RRF; risk graph and risk matrix map parameters directly to a SIL band
MethodTechnical DescriptionOutput TypeMain LimitationBest Suited For
LOPASemi-quantitative scenario analysis using initiating-event frequency, enabling conditions, conditional modifiers, and IPL performanceNumeric RRF mapped to SILStrongly dependent on scenario definition and data qualityHigh-consequence, complex, or multi-scenario situations
Risk GraphCalibrated branching method using consequence, exposure, avoidance, and unwanted-event frequency parametersSIL bandBoundary choices and subjective parameter selection can materially affect the resultMid-volume SIF batches; can also serve as a final method when properly calibrated
Risk MatrixCalibrated matrix-based risk-gap or SIL-allocation methodSIL band or risk categoryBroad likelihood and consequence bands may hide differences between scenariosLarge SIF counts, initial screening, lower-consequence functions

The comparison above is a starting reference, not a substitute for calibrating each method against the facility’s own tolerable risk criterion before applying it to a live SIF list.

0
A DECADE OF SAFETY, AN Ai POWERED FUTURE

Recognized for excellence.

0

PROJECTS DELIVERED ACROSS THE GLOBE

SIL Determination vs. SIL Verification

These two terms are commonly confused, and it’s worth separating them clearly:

  • SIL determination establishes the required risk reduction, or target SIL, for a Safety Instrumented Function; this is what LOPA, risk graph, and risk matrix are used for.
  • SIL verification is a separate, later step that confirms whether the proposed SIF design actually achieves the required PFDavg (or PFH) and satisfies the relevant architectural constraints. Depending on the applicable lifecycle requirements, verification also considers systematic capability or prior-use justification, common-cause failure, proof-test interval and coverage, diagnostic coverage, mission time, repair time, and the device and subsystem architecture. In short, verification confirms that the calculation assumptions, proof-test intervals, architectural constraints, and systematic integrity provisions are consistent with the intended SIF design and lifecycle arrangements.

A facility can select the right determination method and still end up with an unsafe design if verification is skipped or done against the wrong target. The two steps are related but distinct, and a documented SIL study should make clear which one it’s performing.

A Worked Example: One Scenario, Three Methods

Consider a cooling-water failure that causes reactor temperature rise and potential vessel overpressure. The figures below are illustrative, chosen to show how each method’s mechanics differ they are not derived from a real facility’s data.

Risk matrix approach: An engineer rates the consequence as “major” (potential for significant equipment damage and possible injury) and the likelihood as “occasional” based on historical cooling-water trip frequency. On the facility’s calibrated matrix, that cell maps directly to SIL 2, with no further breakdown of existing safeguards.

Risk graph approach: The same scenario is walked through the four parameters consequence (serious injury possible), exposure (personnel present most of the time), probability of avoidance (moderate, given alarm response time), and W (unwanted event frequency without the SIF). The branching path also lands on SIL 2, though the reasoning is now visible in each parameter choice rather than compressed into one matrix cell.

LOPA approach: Say the initiating-event frequency for cooling-water failure is established from plant history at 0.2 per year. Two safeguards are evaluated for credit: a high-temperature alarm with operator response, and a relief valve sized to prevent vessel overpressure specifically (not necessarily other consequences such as toxic release or fire, which would need their own credit basis). Each would need to be confirmed against the organization’s IPL criteria before being credited for the alarm, that means confirming independence from the initiating cause and the proposed SIF, adequate response time, reliable indication, and documented, trained operator action; for the relief valve, confirming its capacity, independence, and discharge destination. Assuming both qualify, with PFDs of 0.1 and 0.01 respectively, and an enabling-condition factor of 0.5 reflecting that the reactor operates in the higher-risk state half the time, the intermediate event frequency works out to roughly 0.2 × 0.1 × 0.01 × 0.5 = 1 × 10⁻⁴ per year. Against a tolerable event frequency of 1 × 10⁻⁵ per year, the required RRF is approximately 10 corresponding to the lower boundary of SIL 1 for a low-demand SIF.

A difference between the results does not necessarily mean that one method has been applied incorrectly. However, the assumptions, consequence endpoint, safeguard treatment, and calibration should be reviewed to confirm that the comparison is valid a gap this size can also point to safeguard double counting, an inconsistent risk criterion, or a mismatch in which consequence endpoint each method is actually assessing. Reviewing those assumptions explicitly is exactly why higher-consequence or more complex scenarios benefit from the added analytical step LOPA provides.

Common Mistakes When Selecting or Applying a SIL Determination Method

Cause and effect chart showing three common SIL determination method mistakes and their audit consequences
Mismatched method selection and uncalibrated risk graphs are the two most cited SIL audit findings

The most common SIL determination mistakes are not calculation errors. They are methodology mismatches: applying risk matrix or risk graph screening to a high-consequence scenario that would benefit from LOPA’s granularity, or running an uncalibrated risk graph with no documented link to a tolerable risk criterion.

A recurring issue identified during functional-safety reviews is a risk matrix or risk graph, calibrated for screening, being applied directly to a high-consequence scenario without escalating to a more detailed method the coarse bands can then over- or understate the actual risk reduction needed. An uncalibrated risk graph, one whose parameter definitions were copied from a generic template rather than derived from the facility’s own tolerable risk criterion, is difficult to defend during a management-of-change review. A defensible risk graph or risk matrix should be calibrated so that its parameter definitions and SIL boundaries are demonstrably aligned with the organization’s documented tolerable-risk criteria. Without that alignment, a facility cannot explain why a SIF was rated SIL 1 instead of SIL 2 when an insurer or regulator asks.

Inconsistent method use across similar SIFs is another common weakness. The same hazard scenario, assessed by different engineers using different methods, can produce different SIL ratings for functionally identical loops. This typically surfaces months after the SIL study closes, often during detailed design or a HAZOP revalidation. A documented methodology selection rule stating which method applies at which consequence threshold removes the ambiguity before it becomes a design change.

A related mistake is treating a general HAZOP risk-ranking matrix as automatically valid for SIL determination. A general HAZOP matrix may rank inherent, existing, or residual risk depending on the organization’s methodology; it should not automatically be treated as a SIL allocation matrix, because SIL determination must establish the additional risk reduction required from the proposed SIF. These are not the same calculation. Dual use of one matrix for both purposes is possible, but only where the matrix has been specifically calibrated for SIL allocation, clearly defines how existing safeguards are treated, and converts the remaining risk gap into a required SIF performance target.

A Practical Decision Framework for Choosing Between the Three Methods

Choosing between LOPA, risk graph, and risk matrix comes down to a handful of questions: how many SIFs need assessment, how severe and complex the worst credible consequence is, how reliable the available failure-frequency data is, and what the client, insurer, or approving authority expects to see. Project requirements may also be shaped by the operator’s functional safety philosophy and contractual specifications; these should be confirmed at the start of the SIL study rather than assumed from general regional practice.

A defensible methodology selection rule, established as organizational policy, typically includes:

  1. Screen the full SIF list with a calibrated risk matrix or risk graph to separate low-consequence functions from those needing detailed analysis.
  2. Establish a documented escalation rule requiring LOPA for scenarios above defined consequence, uncertainty, or complexity thresholds for example, potential fatality, major environmental release, or high financial consequence.
  3. Confirm the risk graph or matrix calibration against the facility’s documented tolerable risk criterion before using either as a final SIL basis.
  4. Apply the same method consistently across all SIFs protecting the same hazard scenario, to avoid inconsistent SIL ratings on functionally identical loops.
  5. Weigh additional factors when selecting a method: the number and independence of potential IPLs, whether conditional modifiers materially influence the result, the need to aggregate multiple initiating-event scenarios, and the competence and facilitation resources available for the study.
  6. Document the methodology selection rule itself, not just the individual SIL results, so an auditor can see why each method was chosen.
  7. Review the methodology selection and repeat or update the SIL determination during any management-of-change assessment that materially changes the consequence, demand frequency, exposure, or credited safeguards.

This framework works because it separates two decisions that teams often blur together: which method screens the SIF list, and which method produces the final, auditable SIL rating. Screening tools save analyst time on low-consequence functions; they are not a substitute for a more detailed method where the consequence or complexity warrants it.

Frequently Asked Questions

LOPA generally provides a more granular and transparent numerical basis than a risk graph or risk matrix, since it credits initiating-event frequency, conditional modifiers, and each protection layer individually. That said, its reliability still depends on the quality of the underlying data and assumptions a numeric result is not automatically more accurate simply because it contains numbers.

Risk graph and risk matrix map broad parameter bands to a SIL output without individually crediting each independent protection layer. Because fewer risk-reduction credits are captured explicitly, results can differ from a detailed LOPA study for the same scenario and depending on calibration, may be either more or less conservative.

Risk graph or risk matrix screening works well when a facility has a large batch of SIFs and needs to filter out low-consequence functions quickly. Higher-consequence or more complex SIFs identified during screening can then be escalated to LOPA for a more detailed, auditable rating, per the organization’s documented escalation rule.

A risk graph uses a branching decision tree across four parameters: consequence, exposure, avoidance probability, and the frequency of the unwanted event without the SIF to reach a SIL output. A risk matrix instead plots severity directly against likelihood on a calibrated grid. Both require documented calibration against a tolerable risk criterion to remain defensible.

IEC 61511-3 does not require LOPA. It provides a framework and examples for different SIL determination techniques. The selected methodology, risk criteria, assumptions, and results must be documented. Risk graphs and risk matrices should be calibrated against the organization’s tolerable-risk criteria, while LOPA requires documented frequency data, IPL criteria, and calculation assumptions.

Only with caution. A general HAZOP matrix may rank inherent, existing, or residual risk depending on the organization’s methodology, while a SIL determination matrix needs to convert a risk gap into a required SIF performance target. Dual use is possible only where the matrix has been specifically calibrated for SIL allocation and clearly defines how existing safeguards are treated. Using an uncalibrated or informally adjusted HAZOP matrix for SIL determination is a common weakness found during safety-documentation reviews.

Conclusion

LOPA vs risk graph vs risk matrix is not a question with one universal right answer. It’s a question of matching method rigor to consequence severity, SIF volume, data availability, and what the client, insurer, or approving authority expects to see. Risk matrix and risk graph earn their place as fast, defensible methods for screening or, when properly calibrated, as a final basis while LOPA earns its place wherever the consequence is severe enough, or the scenario complex enough, that the added analytical step buys a materially more precise, better-supported SIL rating.

The practical takeaway for a facility running a SIL study across dozens of SIFs: document the methodology selection rule before the workshop starts, not after an auditor asks for it. Apply that rule consistently across functionally identical loops, and set clear thresholds for when a scenario should be escalated to a more detailed method.

iFluids Engineering performs SIL determination and verification studies using LOPA, calibrated risk graph, and risk matrix methodologies in accordance with the applicable requirements and guidance of IEC 61508 and IEC 61511, for clients across the GCC, India, and Southeast Asia. Speak to our process safety team about scoping a consistent SIL determination methodology for your next project. For related classification workflow guidance, see our article on SIL classification and how to select the right level, or explore our broader Process Safety Management services.

Related Posts

Our latest highlights
View All