17.1 Safety Requirements Specification

Key Takeaways

  • ISA/IEC 61511-1:2018 Clause 10 makes the SRS the design input for every SIF; a vendor typical-application note is not an SRS.
  • Process safety time is the clock from EUC or BPCS failure to the hazardous event if the SIF does not act; SIF response time must be shorter.
  • Demand mode is scored with PFDavg; continuous/high-demand operation is scored with PFH. The SRS must name the mode.
  • Trip points, safe state, reset, bypass, voting, and BPCS/operator interfaces are SRS requirements, not later convenience settings.
  • Proof-test interval belongs in the SRS because PFDavg and the SIL claim depend on it; it is not a maintenance afterthought.
Last updated: August 2026

Why 5.C exists on the 2027 exam

NCEES PE Control Systems specifications effective April 2027 put 5.C Safety requirements specifications (SRS) immediately after hazard/risk assessment and allocation (5.A–5.B) and immediately before SIS design and SIL calculations (5.D). That order is the ISA/IEC 61511-1:2018 safety lifecycle, not a study-guide convenience. Clause 10 of the supplied standard is the design input for hardware, application program, testing, and SIL verification. If a requirement is missing from the SRS, later calculations can be numerically tidy and still fail verification, because there is nothing objective to verify against.

On exam day you can search the supplied ISA/IEC 61511-1:2018 PDF for “safety requirements specification.” You cannot search a manufacturer brochure. Treat the SRS as an owner document that traces each safety instrumented function (SIF) from the hazard and risk assessment. A cause-and-effect chart is useful logic, but it is not a complete SRS unless it also carries integrity, timing, mode, proof-test, reset, and interface requirements.

What the SRS has to capture

Clause 10 expects each SIF to be specified in functional language (what takes the process to a defined safe state) and integrity language (SIL and mode). The following items are the ones 5.C items actually turn on.

Process safety time (PST). ISA/IEC 61511-1 defines process safety time as the period between a failure in the equipment under control (EUC) or the EUC control system and the occurrence of the hazardous event if the safety function is not performed. The SIF’s sense–decide–act response time must be less than PST. Sensor scan and damping, logic-solver scan, solenoid pull-in, and valve stroke all consume that budget. Owners often add margin (response well under PST), but NCEES does not publish a unique margin fraction. The exam point is that PST is a stated requirement, not a number you invent after the valve is purchased.

Safe state. Name the process condition that is safe for this scenario: block inlet flow, depressure, trip the compressor, isolate fuel, keep a vessel flooded. “Fail-safe” is not a substitute for a process-specific safe state. Two individually safe states can be unsafe together (for example, blocking both a feed and a relief path); the SRS must not create that combination.

Demand mode versus continuous. In demand mode, the SIF acts when a process demand occurs; residual hazard requires both a SIF dangerous failure and a demand. Integrity is scored with average probability of failure on demand (PFDavg). In continuous (and typical high-demand) operation, the SIF is part of keeping the EUC in a safe state as normal operation, or demands are frequent enough that a dangerous failure is itself a hazard; integrity is scored with average frequency of dangerous failure (PFH), failures per hour. ISA/IEC 61511-1 Tables 4 and 5 (reproduced in the NCEES PE Control Systems Reference Handbook, Chapter 6) are different bands. Mixing PFDavg numbers with a continuous-mode SIF is a scoring error. The SRS must state the mode so 5.D verification uses the matching table.

Trip points and process measurements. Specify the process variable, location, range, trip set point, and direction (high, low, rate). A “high-high pressure trip” without a number, engineering unit, and measurement point cannot be configured, calibrated, or proof-tested.

Reset. After a trip, does the SIF stay in the safe state until a manual reset, or does it reset automatically when the process variable returns to normal? Manual reset is the usual ESD choice so pumps do not restart into a leaking header. Automatic reset can be appropriate for some continuous constraint functions, but only if the SRS says so.

Bypass / inhibit / override. Proof tests and start-up need planned bypasses. The SRS states who may apply a bypass, how it is authorized, how long it may last, how it is alarmed to the operator, how it is recorded, and how it is cleared. An unspecified bypass is an unanalyzed hole in the independent protection layer.

Voting. 1oo1, 1oo2, 2oo3, and similar architectures are SRS requirements because they change both PFDavg and spurious-trip rate. Voting is not a vendor default you “confirm later.”

Interfaces to the BPCS and operator. The SIS may send status, first-out, bypass, and reset permissives to the basic process control system (BPCS) and HMI. Those interfaces must not let the BPCS defeat the SIF, share an undetected common cause, or hide a bypass. Alarms in the BPCS are not automatically the SIF.

Proof-test interval as a requirement. PFDavg for a dormant dangerous-undetected failure grows with the time between tests. Clause 10 therefore requires the proof-test interval (and the need for periodic testing) in the SRS. Writing “test as convenient” after start-up is how a SIL 2 claim silently becomes a SIL 1 result.

SRS itemWhy the exam cares
Process safety timeVerification compares calculated/measured SIF response to PST; no PST means no timing pass/fail
Safe stateHardware fail-direction and valve action must match a defined process state
Demand vs continuousSelects PFDavg versus PFH tables in ISA/IEC 61511-1
Trip pointsCalibration, configuration, and proof-test procedures need a numeric set point
ResetDistinguishes latched ESD from auto-reset constraint functions
BypassUncontrolled inhibit is a common-cause defeat of the SIF
VotingSets both safety PFD and nuisance-trip behavior
BPCS/operator interfacesIndependence and human-factors requirements live here, not in a DCS graphic standard
Proof-test intervalDirect input to PFDavg; changing it changes the SIL claim

Worked example: missing process safety time

A hydrocracker high-pressure trip SRS lists SIL 2, low demand, trip at 2.40 MPag, de-energize-to-close the inlet ESD valve, manual reset, 1oo2 transmitters, and a 12-month proof test. It never states PST.

The designer later measures 1.5 s transmitter response (including damping), 0.5 s logic, 0.4 s solenoid, and 8 s valve stroke — 10.4 s sense-to-closed. That number is not “good” or “bad” until it is compared with PST. If the vessel reaches the hazardous overpressure in 6 s, the SIF fails Clause 10/11 verification even if PFDavg lands in the SIL 2 band. If PST is 30 s, 10.4 s may pass. Without PST, verification cannot be completed. Adding a vendor “typical 10-second shutdown valve” note does not create PST; the process team has to derive PST from the hazard scenario.

Exam trap: typical-application notes

A transmitter datasheet that says “suitable for SIL 2 applications” and shows a sample 1oo1 hook-up is prior-use or IEC 61508 assessment evidence at most, and often not even that. It does not define this plant’s safe state, PST, demand rate, bypass rules, or proof-test interval. On the PE exam, substituting that note for an SRS is the wrong document. Search 61511-1 for the SRS list; do not search marketing PDFs.

Loading diagram...
Process safety time versus SIF response
Test Your Knowledge

A SIF SRS lists trip set point, SIL 2, demand mode, and a fail-closed ESD valve, but omits process safety time. What is the immediate verification problem?

A
B
C
D
Test Your Knowledge

Under ISA/IEC 61511-1:2018, the proof-test interval for a SIF is best treated as which of the following?

A
B
C
D
Test Your Knowledge

Which package does NOT satisfy the safety requirements specification for a process SIF on the PE Control Systems exam?

A
B
C
D