LOPA is a Layer of Protection Analysis and is a type of PHA that looks at the actual layers of protection a particular scenario would have. As you know, process safety is built upon the fundamental concepts of prevention, threat, and mitigation. Hence, we want to prevent the scenario from even starting, but if we can’t, then we want to protect our assets (including people), and then we want to mitigate the consequences of the event. In NH3 systems you would be doing ALL three!
SIS is Safety Instrumented System and is a design logic for items such as your instrument control logic for say your interlocks, alarms, etc.
SIL is Safety Integrity Level and is basically looking at the level of reliability of all the components in your safety systems such as interlocks (e.g. high pressure cut outs as they call them in refrigeration).
For example, TOO HIGH PRESSURE in a vessel is the scenario. What safeguards are in place: Vessel rated for 300 psi, the vessel in the MIP inspection program, relief system on the vessel, high-pressure alarm(s), and high-pressure interlock. This is what we would be looking at in the LOPA. The next step is to look at the level of reliability built into these safety systems. As you have probably seen, there are the everyday run-of-the-mill safety systems, and then there are TRUE ENGINEERED SAFETY SYSTEMS.
There is a standard we use to design engineered safety systems to ensure they function as designed AND when they are called upon. ANSI/ISA S84 is that code (although Europe has one too IEC EN 6150 – a very long read, but if you are into learning failure modes of systems and how to design them out, it is an excellent read).
I also have a short summary from the SIS champion/guru Angela Summers, PhD/PE, and would be willing to share it with anyone. Once we have a level of risk, we can then look at the SIL needed to manage the risk. SILs go from 1 to 4, with 4 being the most reliable (redundant power sources, backup emergency power, redundant PLCs, etc.). One of the most common systems we look at is the interlocks and their reliability, and the most common measure we use is MEAN TIME BETWEEN FAILURE and/or REPAIR – some may use the term Probability for Failure on Demand (PFD). We are not looking at the set points of these systems – that is another exercise, but we are actually looking at manufacturers’ data on the reliability of their devices to ensure they will work as designed when put into a process and its setting. Sort of like…the chain is only as strong as its weakest link.
