LOPA and independent protection layers: when multiplication is justified

A worked LOPA example explains scenario boundaries, independent protection credit, conditional probabilities and uncertainty.

On this page

Layer of Protection Analysis, or LOPA, is a disciplined way to examine whether specified protection is sufficient for a defined accident scenario. Its arithmetic is often simple; deciding what the numbers mean is harder. A layer that cannot act in time, or fails with the initiating event, cannot earn independent risk-reduction credit merely because it exists. This educational guide uses an original hypothetical liquid-transfer case. No numerical assumption below is an industry default, a vessel acceptance criterion or a design recommendation.

Begin with one scenario and one endpoint

Define the initiating event, the operating state and the consequence being evaluated. “Tank overfill” alone is incomplete: which tank, during which transfer, from which initiating failure and with what harmful outcome? The scenario might end at loss of containment, exposure of a person or ignition. Those endpoints require different conditional events. Changing the endpoint without changing the model can either omit relevant conditions or count the same reduction twice.

HSE’s LOPA overview describes the method as assessing scenario likelihood using safeguards and identifying any shortfall against predefined risk-based criteria. That is a method description, not permission to use a generic tolerable frequency. Establish the decision criterion and its authority before calculating. A project cannot make a result acceptable simply by choosing a convenient threshold after seeing the answer.

Check the initiating-event denominator

A frequency is a number of events per unit exposure; a probability is dimensionless and tied to a specified condition. An initiating frequency of 0.2 per operating year is different from a probability of 0.2 per transfer. If a ship carries out many transfers, confusing the two can change the answer by orders of magnitude. Record whether the data refer to calendar years, operating hours, equipment-years, missions or demands.

An enabling condition may determine when the initiating event can lead to the consequence. Suppose a certain fault matters only during transfer. If the initiating frequency was estimated from transfer hours already, multiplying again by the fraction of time spent transferring can double-discount the exposure. Conversely, a calendar-year estimate may need careful conditioning. Write a short sentence explaining the population, exposure and event counted for every input before entering its value into a worksheet.

Qualify a layer for the particular cause

A candidate independent protection layer must perform a specified protective function for this scenario and have a justified probability of failure. Independence concerns both the initiating event and other credited layers. A high-level alarm using the same failed measurement that caused continued filling is not independent of that initiating failure. A separate logic device still may share the same sensor, power supply or final valve.

A layer also needs effective action within the available time and evidence that its claimed performance is maintained. HSE’s functional-safety explanation emphasizes a lifecycle including operation, maintenance and proof testing. In a maritime application, the relevant flag, class, contractual and equipment requirements must be identified separately. Process-industry guidance is useful methodological background; it does not automatically establish which standard governs every shipboard installation.

Understand what is being multiplied

For a simplified low-demand model, the scenario frequency can be written as initiating frequency multiplied by relevant conditional probabilities and by the failure probabilities of credited layers. Independent layers permit the familiar product of individual failure probabilities. Without independence, the correct object is their joint failure probability. In general, P(A and B) = P(A) × P(B given A), not automatically P(A) × P(B).

This distinction matters when one demand creates common stress. A loss of power might disable both detection and final actuation. An emergency might force the same person to diagnose two alarms within the same short interval. Conditional probabilities should reflect that shared context. Treat a layer’s average probability of failure on demand, commonly written PFDavg, as conditional performance of a defined function under specified assumptions. It is not the annual frequency of an accident.

Work through a transparent hypothetical calculation

Assume an initiating frequency of 0.2 per operating year for one defined transfer scenario. For arithmetic only, suppose a qualified layer has PFDavg 0.1 and a second independently justified layer has PFDavg 0.02. Assume no additional conditional modifiers and that each layer can prevent the selected endpoint. The calculated frequency is 0.2 × 0.1 × 0.02 = 0.0004 per operating year, or 4 × 10⁻⁴ per year.

Suppose a hypothetical decision criterion is 1 × 10⁻⁴ per year. The point estimate is four times that criterion. This does not tell the analyst to purchase a particular device or select a SIL from the ratio alone. It identifies a gap requiring reconsideration of the initiating cause, inherently safer arrangements, existing-layer evidence and possible additional protection. The criterion and inputs are invented for teaching; no actual regulatory or organizational threshold is asserted.

Remove an invalid credit before adding new protection

Now suppose the 0.1 layer and the initiating event both depend on the same level measurement. If that failure defeats the layer, its effective failure probability for this scenario can be 1, even though it works well against other causes. The revised arithmetic becomes 0.2 × 1 × 0.02 = 0.004 per year. The gap relative to the invented criterion becomes forty, rather than four. An unjustified credit was hiding most of the problem.

The analytical response is not to silently assign another convenient number. Record why the credit was removed, identify the affected scenario set and update the decision. A barrier can remain useful operationally while receiving no independent quantitative credit in this case. Distinguishing usefulness from credited independence prevents an unproductive argument in which “the alarm helps” is mistaken for proof that the multiplication is valid.

Examine conditional modifiers for overlap

Occupancy, ignition and exposure may be relevant depending on the endpoint, but they require definitions and data. If the selected consequence is a spill, adding an ignition probability changes the endpoint to something involving fire. If occupancy is correlated with the operation that generates the hazard, a generic fraction of time in the area may understate exposure. Identify when people actually need to be present relative to the initiating event.

Modifiers can also overlap with layer performance. A response layer already assessed under a demanding operating condition should not receive a second reduction for the same condition being uncommon unless the conditioning is mathematically consistent. Likewise, a mitigation measure that reduces severity is not automatically a probability multiplier for eliminating the consequence altogether. Build an event-sequence explanation alongside the compact LOPA table; it often reveals double counting more quickly than checking arithmetic alone.

Treat proof testing and bypasses as part of the claim

A PFDavg value rests on assumptions about failure modes, detection, repair and testing. A partial test may reveal some failures while leaving others hidden. A nominal test interval says little if the procedure does not test the relevant final action or if overdue tasks are common. An unavailable or bypassed layer requires explicit treatment of the exposure during that state, including any dependence between bypass and hazardous operation.

The public IEC 61511-1 catalogue describes requirements spanning specification, design, installation, operation and maintenance of process-sector safety instrumented systems. It also identifies a 2017 amended edition. Only the public scope information was consulted here. A LOPA result is therefore an input to a wider lifecycle, not proof that a purchased component or complete installed function meets every integrity, architectural or systematic requirement.

Do not assign a universal human-error probability

An operator response includes detection, interpretation, decision, access and action. A display may be unreadable under the initiating condition, the person may be occupied elsewhere, or the available time may be shorter than the task requires. Training attendance does not establish the success probability of that chain. If the same person caused the initiating error and is expected to recover, assess the dependence rather than assuming a fresh independent chance.

For the hypothetical case, develop a task timeline and identify the earliest reliable cue and the point after which intervention cannot prevent the endpoint. Test realistic conditions safely through approved training or analysis, including communication and competing demands. These observations may support task redesign or a separate human-reliability assessment. They do not justify deriving an extremely small error probability from a handful of successful demonstrations.

Test whether the decision survives uncertainty

Suppose the initiating frequency is plausibly between 0.1 and 0.4 per year and the second layer’s PFDavg between 0.01 and 0.04. With the first layer genuinely independent at 0.1, corner calculations range from 1 × 10⁻⁴ to 1.6 × 10⁻³ per year. These endpoints are scenario bounds, not automatically a statistical confidence interval. Correlations and the evidence supporting the ranges still matter.

The output should distinguish a robust conclusion from a marginal one. If the result crosses the criterion across credible assumptions, report which evidence or design change would resolve the decision. Do not conceal the range behind a precise-looking central value. A more detailed method may be needed when several dependencies, changing operating states or complex consequence pathways dominate. LOPA’s simplicity is useful only while it represents the actual decision adequately.

Deliver a scenario record that can be audited

A complete record includes scenario definition, consequence endpoint, exposure basis, initiating data, credited and rejected layers, independence assessment, timing evidence, modifiers, uncertainty and the decision criterion. Each numerical input should lead to a source or an explicitly identified engineering judgment. List assumptions that operating and maintenance teams must preserve. Record the person authorized to approve the eventual engineering decision separately from the person who prepared the calculation.

The final question is whether the installed and maintained system can support the assumptions under which the multiplication was performed. If a sensor is shared, a test loses coverage or a bypass becomes routine, the result may no longer apply. Revisit the affected scenarios through change control. A trustworthy LOPA is not the one with the smallest number; it is the one whose credited reductions remain explainable, demonstrable and relevant to the defined harm.

Sources