Functional safety is about behaviour
It asks whether safety-related functions act correctly when they are needed.
Functional safety can sound complicated. It does not have to. Explore twelve quick facts, a few common myths and a short challenge from the world of high-integrity systems.
Start with the facts Our assurance servicesEach fact highlights a principle that often matters during safety engineering, software assurance and independent assessment.
It asks whether safety-related functions act correctly when they are needed.
A Safety Integrity Level relates to the integrity needed from a safety function—not how “good” a product is generally.
SIL 1 to SIL 4 represent increasing levels of safety integrity, with SIL 4 the highest.
Passing tests is important—but safety assurance also depends on requirements, design, traceability, analysis and configuration control.
Software failures usually arise from systematic faults rather than physical ageing.
Two channels are not truly independent if the same cause can defeat both.
A good safety requirement should be traceable from its hazard to implementation, verification and validation.
A fail-safe design aims to move or remain in a safe state when defined failures occur.
An independent assessor asks whether safety conclusions are justified—not merely whether documents exist.
Individual subsystems may be correct while their interfaces create unsafe behaviour.
Even a small software or configuration change can affect assumptions made elsewhere in the safety case.
Operation, maintenance, modification and decommissioning remain part of functional safety.
Redundancy helps only when the architecture, independence, diagnostics, common-cause vulnerabilities and failure responses are understood.
Hazards, requirements, architecture, implementation, verification, validation and operation all contribute to confidence in a safety function.
IEC 61508 defines SIL 1 through SIL 4. The higher the SIL, the greater the required risk reduction and the stronger the corresponding engineering and assurance rigour.
Important: SIL should be assigned to a safety function—not casually used as a label for an entire system or product.
A supplier says: “Our safety-related software passed every system test, therefore it is proven safe.” What is the best assurance response?
OrientSA specialises in assurance of high-integrity systems, including systems assurance, software assurance, safety assessment, audit, training and mentoring.
Our experience includes railway, metro, signalling, SCADA, tunnel and other control-system applications across Asia and Australia.
Talk to OrientSA about practical, independent assurance for your high-integrity system.