
A functional safety management plan (FSMP) is the governing document that defines how functional safety will be planned, implemented, verified, and maintained across every phase of the SIS safety lifecycle on an oil and gas project. Required under IEC 61511-1 Clause 5, the functional safety management plan assigns roles, sets competency standards, structures lifecycle deliverables, and establishes the audit and verification framework that keeps safety instrumented systems compliant from FEED through decommissioning.
Without a written FSMP, capital projects routinely arrive at commissioning with unverified SIF integrity levels, missing proof test procedures, and contractor competency records that fail FSA scrutiny. The cost of closing those gaps post-startup, through early shutdowns, emergency recalculations, and retrofit measures, consistently exceeds the cost of developing a proper functional safety management plan at project inception. The sections below provide a functional safety management plan example framework structured to IEC 61511-1 Clause 5 requirements. The FSMP is not administrative overhead. It is the structural backbone of IEC 61511 compliance.
What Is a Functional Safety Management Plan in Oil and Gas?
A functional safety management plan is a structured project document, mandated by IEC 61511-1 Clause 5.1, that specifies what functional safety activities must be performed, who is authorised to perform them, how their outputs will be verified, and how compliance with the SIS safety lifecycle will be demonstrated to operators, regulators, and functional safety assessors across all lifecycle phases.
The FSMP sits at the top of the functional safety documentation hierarchy. It does not replace the Safety Requirements Specification, the SIL verification report, or the FSA reports. It governs them. Effective safety lifecycle planning depends on the FSMP being complete before lifecycle activities begin. Every technical deliverable in the lifecycle traces back to a task defined in the functional safety management plan, assigned to a named role, with a stated competency requirement and a planned verification activity.

FSM vs FSA: A Critical Distinction
Practitioners frequently conflate functional safety management with functional safety assessment. They serve different purposes and operate at different points in the lifecycle.
| Attribute | Functional Safety Management Plan (FSMP) | Functional Safety Assessment (FSA) |
| Purpose | Governs how FS activities are planned and executed | Independently verifies that FS objectives have been met |
| Timing | Developed at project outset; updated throughout | Conducted at five defined lifecycle stages |
| IEC 61511 Reference | Clause 5 (Management of Functional Safety) | Clause 5 and Clause 8 (stage-specific) |
| Owner | End user / principal contractor | Independent assessor (internal or third party) |
| Primary Deliverable | The FSMP document itself | FSA report per stage |
| Scope | Entire SIS safety lifecycle | Specific lifecycle gate being assessed |
The functional safety management plan defines the conditions under which an FSA will be conducted. The FSA then verifies that those conditions have been met.
Recognized for excellence.
PROJECTS DELIVERED ACROSS THE GLOBE
What Must a Functional Safety Management Plan Contain?
Per IEC 61511-1 Clause 5, a compliant functional safety management plan must define the management actions, roles, and activities necessary to achieve functional safety objectives across the full SIS lifecycle, specifying scope, responsibilities, competency requirements, verification methods, and documentation control procedures for every phase from hazard and risk assessment through decommissioning.
Mandatory FSMP Document Sections per IEC 61511-1 Clause 5
A properly structured functional safety management plan template based on IEC 61511-1 Clause 5 must address each of the following sections:
- Scope and applicability: Identify the systems, plants, or projects the functional safety management plan covers. Specify which lifecycle phases apply and document interfaces with adjacent systems and management frameworks.
- Roles, responsibilities, and organisational structure: Name the functional safety roles, including Functional Safety Manager, SIL Engineer, Verification Engineer, and FSA Lead, and assign lifecycle activities to each. Independence requirements per IEC 61511-1 Clause 5.2.5 must be documented explicitly.
- Safety lifecycle plan: Map each lifecycle phase (H&RA, HAZOP, SIL determination, SRS, SIS design, installation, commissioning, validation, operation, modification, decommissioning) with defined deliverables, review gates, and schedule integration points.
- Competency management system (CMS): Per IEC 61511 edition 2, the CMS is a normative requirement. The functional safety management plan must define the competency standard for each FS role: formal training, practical experience, and demonstration of knowledge. Records must be maintained throughout the lifecycle.
- Verification plan: State how each lifecycle deliverable will be independently verified, by whom, at what level of independence, and using what method, such as checklist, technical review, or independent recalculation.
- Functional safety assessment plan: Define which of the five FSA stages apply, who will conduct each, and the criteria for satisfactory completion.
- Management of Change (MoC) procedure: Specify the process for evaluating and approving changes to any SIS element, including re-verification and re-assessment triggers.
- Configuration management procedure: Uniquely identify every SIS hardware and software element. Define how revisions are controlled, backed up, and traceable to the H&RA phase.
- Documentation and communication framework: Define document naming conventions, revision control, storage, access, and the traceability requirement linking every SIF back to its originating hazard.
Common FSMP Gaps That Lead to SIF Non-Compliance
In our experience across GCC capital projects, the following omissions appear repeatedly when functional safety management plans are reviewed during stage 3 or stage 4 FSAs:
- Missing proof test procedures at handover: The functional safety management plan defined that proof tests would be developed but assigned no owner and set no delivery date. Operations teams receive systems without validated test procedures.
- Undocumented contractor competency: The FSMP listed a systems integrator as responsible for SIS design but contained no record of the integrator’s functional safety management system or SIL capability evidence, per IEC 61511-1 Clause 5.2.5.2.
- Single-phase FSMPs: The functional safety management plan covered FEED and detailed design but treated operation and maintenance as out of scope. IEC 61511 requires the FSMP to address the full lifecycle, including the operational phase.
- No re-assessment trigger for MoC: Changes to SIF logic, setpoints, or final elements were processed through the general project MoC system without a functional safety-specific evaluation step, creating undocumented integrity degradation.
These represent the gap between a functional safety management plan example that satisfies a document register and one that actually governs lifecycle execution.
The Functional Safety Management Plan Development Process
Developing a compliant functional safety management plan requires eight sequential activities spanning the project lifecycle: identifying applicable standards, defining scope, assigning roles, planning verification and FSA stages, integrating risk management, establishing competency records, defining MoC and configuration controls, and implementing an audit cycle that runs from concept through decommissioning.

Step-by-Step: Developing an FSMP from Concept to Decommissioning
Step 1: Identify applicable standards and regional regulations
Confirm which functional safety standards govern the project. IEC 61511 applies to process industry SIS; IEC 61508 applies to equipment manufacturers. The functional safety management plan must state which edition of IEC 61511 applies. Edition 1 (2003) and edition 2 (2016) differ materially on competency and documentation requirements. For GCC projects, additionally identify ADNOC OSHAD ST-HSE-009 requirements, KOC HSE management system obligations, and where applicable, Saudi Aramco Engineering Standard SAES-J-904.
Step 2: Define scope and project boundaries
Specify which SIS, SIFs, and lifecycle phases are in scope. Document interfaces with the process safety management system and the quality management system.
Step 3: Assign roles, responsibilities, and independence
Every functional safety activity requires an assigned role and a stated independence level. The functional safety management plan must document independence criteria per IEC 61511-1 Clause 5.2.5 explicitly, not by reference to generic project organisation charts.
Step 4: Develop the safety lifecycle plan
Safety lifecycle planning is the core output of Step 4. Map deliverables to lifecycle phases. Align FS milestones with the overall project schedule. For SIL determination and assessment to be executed correctly, the functional safety management plan must place SIL determination explicitly before equipment procurement, a sequencing failure that costs projects significantly when discovered after purchase orders are placed.
Step 5: Integrate risk management activities
The functional safety plan must reference the project’s HAZOP study scope and schedule. LOPA or an equivalent risk assessment methodology must be named. SIL determination outputs feed the SRS, which feeds SIS design. The FSMP makes these dependencies explicit and assigns ownership of each handoff. Where the FS lifecycle interfaces with the broader PSM framework, consult process safety management services to ensure alignment.
Step 6: Plan verification activities and FSA stages
Define the verification method for each lifecycle deliverable. Plan all five FSA stages per IEC 61511: Stage 1 covers H&RA; Stage 2 covers SRS; Stage 3 covers SIS design; Stage 4 covers installation, commissioning, and validation; Stage 5 covers operation and maintenance. The functional safety management plan must state scope, assessor independence, criteria, and reporting format for each stage.
Step 7: Establish Management of Change and configuration management
The MoC procedure must require a functional safety impact assessment for any change to SIS hardware, software, logic, setpoints, or test intervals. Per IEC 61511-1:2016, SIS documentation traceability to the H&RA phase is now a normative “shall” requirement. The functional safety management plan must specify how configuration records are maintained and restored.
Step 8: Implement the competency management system and audit programme
Define competency standards for each FS role. The functional safety plan must include a schedule for internal FSM audits at defined intervals. IOGP Report 454 provides industry guidance on FSM audit scope for O&G projects. ISA 84 is the North American equivalent for projects requiring US regulatory alignment.
IEC 61511 Clause 5 and Competency Requirements
IEC 61511-1 Clause 5 requires that all persons involved in functional safety lifecycle activities, including verification, FSA, and management of the functional safety management system, possess competence appropriate to their specific duties, documented in a competency management system that is actively maintained throughout the operational life of the SIS.
IEC 61511 edition 2 elevated competency management from a “should” recommendation to a “shall” obligation. IEC 61511 Clause 5 is the normative reference for all FSM requirements. A functional safety management plan that lists roles without specifying competency standards and maintaining records will fail FSA scrutiny, regardless of the technical quality of the underlying SIS design work.
The Three Pillars of FSM Competency per IEC 61511
Formal training: Personnel must complete training relevant to their lifecycle role. TUV Rheinland Functional Safety Engineer (FSEng) certification and Certified Functional Safety Professional (CFSP) designation are widely recognised benchmarks. The functional safety plan must record training completion for every assigned role.
Practical experience: The FSMP must define minimum experience thresholds per role, set as gate criteria. Years in a relevant position covering the specific lifecycle activities the individual is assigned are the core measure.
Demonstration of knowledge: Formal verification of work products constitutes ongoing knowledge demonstration. The functional safety management plan must capture this systematically in the CMS, as evidence for both the author’s and verifier’s competence.
Proof Testing and Periodic Review Requirements
The functional safety management plan must define proof test intervals for each SIF, derived from SIL verification calculations. Typical intervals range from 12 months for SIL 1 functions to 3 months for SIL 3, depending on PFDavg targets and architectural constraints. The plan must also specify when it is itself reviewed: after significant MoC events, after FSA findings of non-compliance, after dangerous failure events, and at minimum every 5 years during the operational phase.
Functional Safety Management Plan Requirements for GCC Oil and Gas Projects
In GCC oil and gas projects, a functional safety management plan must satisfy both IEC 61511-1 Clause 5 and the specific FSM documentation obligations imposed by ADNOC under OSHAD ST-HSE-009 and by KOC under its HSE management system framework, with FSMP submission typically required as a gate deliverable before detailed design approval.
ADNOC and KOC Functional Safety Management Requirements
ADNOC’s OSHAD ST-HSE-009 requires that any facility with SIS operating under ADNOC jurisdiction maintains a documented functional safety management system. The functional safety management plan is the primary evidence document. It must demonstrate compliance with IEC 61511, name the accredited competency framework applied, and record FSA stage outcomes.
KOC’s HSE management system mandates FSM documentation as part of project safety deliverables. For KOC projects, the functional safety management plan must include contractor FSM system verification, confirming that any systems integrator engaged on SIS scope has a recognised functional safety management system, per IEC 61511-1 Clause 5.2.5.2.
Saudi Aramco Engineering Standard SAES-J-904 governs SIS design and management for Aramco projects, imposing equivalent FSM documentation requirements including MoC procedures specific to SIS scope and proof test documentation aligned to the SIL verification basis.
Common GCC Project FSM Challenges
Four challenges appear consistently across GCC functional safety management plan implementations:
- Edition 1 vs edition 2 misalignment: Many contracts reference IEC 61511:2003 (edition 1) while FSAs are conducted to IEC 61511:2016 (edition 2). The competency management system requirement is normative only in edition 2. Projects using edition 1 FSMPs fail edition 2 FSA criteria without realising the gap.
- Late SIL determination: SIL requirements determined after equipment procurement locks in architectural choices that may not achieve target integrity levels, triggering expensive redesign or risk acceptance arguments.
- Contractor FSM system not recognised: ADNOC and KOC expect that subcontractors performing SIS engineering maintain a recognised functional safety management system. Many projects discover this only during stage 3 FSA, when contractor qualification evidence is absent.
- Competency records absent at handover: Operations teams cannot demonstrate to auditors that personnel responsible for proof testing and MoC are competent under IEC 61511, because no CMS was maintained during the project phase.
Conclusion
A functional safety management plan is not a document produced once to satisfy a project register. It is the governing framework that determines whether safety instrumented systems on oil and gas facilities will achieve and maintain their required integrity levels across a 20-plus year operational life. IEC 61511 Clause 5 sets the floor; GCC operators, ADNOC, and KOC raise it further with project-specific documentation requirements enforced at gate reviews before detailed design approval.
The practical takeaway: develop the functional safety management plan at project outset, assign a Functional Safety Manager with demonstrable competence, and treat the plan as a living document updated at every lifecycle gate. Closing FSM gaps at commissioning is always more expensive than opening the project with the right framework in place.
For support in developing or auditing a functional safety management plan for your oil and gas project, explore iFluids Engineering’s process safety management services.
Frequently Asked Questions
A functional safety management plan is a project-level document required by IEC 61511-1 Clause 5 that defines the management framework for achieving functional safety objectives across the full SIS safety lifecycle. It specifies roles, responsibilities, competency requirements, lifecycle deliverables, verification methods, and FSA stages for a given project or facility.
Yes. IEC 61511-1 Clause 5.1 states that safety planning shall take place to define activities, responsibilities, and resources required across the safety lifecycle. A written functional safety management plan is the standard mechanism for meeting this requirement. ANSI/ISA-84.00.01, the US equivalent, carries the same obligation under equivalent clause structure.
The functional safety management plan governs how functional safety activities are planned and executed across the entire lifecycle. An FSA independently verifies that those activities have achieved their objectives at defined lifecycle stages. The FSMP is written at project outset; FSAs are conducted at five specific stages per IEC 61511. One defines the rules; the other checks compliance against them.
A compliant functional safety management plan template must cover: scope and system boundaries, roles and responsibilities with independence requirements, safety lifecycle plan with phase-by-phase deliverables, competency management system, verification plan, FSA plan covering all five stages, Management of Change procedure, configuration management procedure, and a documentation control framework with traceability to the H&RA phase.
Responsibility sits with the end user or principal contractor, represented by a designated Functional Safety Manager with demonstrable competence under IEC 61511. Where the functional safety plan covers contractor scope, IEC 61511-1 Clause 5.2.5.2 requires that contractors performing SIS activities maintain their own functional safety management system, reviewed and accepted by the end user.
The functional safety management plan should be reviewed at each project phase transition, after any significant MoC event, after any dangerous failure or near-miss involving a SIF, following each FSA stage finding, and at minimum every 5 years during the operational phase. IEC 61511 treats the FSMP as a living document, not a one-time project submission.