LOPA shared dependencies: sensors, logic, utilities and common maintenance

Quantify why shared sensors, utilities and maintenance can defeat two nominal layers together, then distinguish ordinary dependence from an initiating cause that guarantees blindness.

On this page

Two protective functions can have different names, screens and setpoints while depending on one physical measurement or one utility. Multiplying their nominal probabilities of failure on demand then treats shared failure as if it had to occur twice. A dependency review should follow the actual information and action paths, and ask whether the initiating cause itself disables the protection being credited.

Draw the complete path behind each layer

For an invented tank, layer A is an alarm followed by operator action and layer B is an automatic stop. Start at the liquid condition and trace sensing element, process connection, transmitter, signal conditioning, logic, display or decision, output, actuator and effective flow interruption. Add power, instrument air, communication and any shared enclosure that can affect these functions.

The HSE functional-safety inspection guide's indexed criteria address independence between layers and from the initiating cause. The relevant unit is a functioning protective chain. Counting separate tags does not demonstrate separate chains, and a second display of the same transmitter is additional visibility rather than another physical measurement.

Separate common and local failures

Let C be a shared failure that disables both layers on a demand, U a failure local to A, and V a failure local to B. Assume C, U and V are independent for this teaching model, with c=0.02, u=0.01 and v=0.02. Layer-failure events are A=C OR U and B=C OR V.

Their joint failure simplifies to A AND B = C OR UV. Thus P(A∩B)=c+(1−c)uv. The shared failure appears once. This explicit model is preferable to inventing a universal correlation penalty because its meaning can be checked against a physical shared mechanism. The assigned values are illustrative and supply no permissible layer credit.

Compare the true joint result with the marginal product

The individual probabilities are P(A)=0.02+0.98×0.01=0.0298 and P(B)=0.02+0.98×0.02=0.0396. Their product is 0.00118008. The actual joint probability in the model is 0.02+0.98×0.01×0.02=0.020196, about 17.1 times larger.

Both marginal probabilities already include C, but multiplying them effectively makes that shared cause look like two separate coincidences. With an initiating frequency of 0.1/year that is independent of C,U,V, the modeled consequence frequency is 0.0020196/year. The unjustified marginal product would give 0.000118008/year. The frequency difference arises from structure, not rounding.

Condition again when the initiator is the shared failure

The previous calculation assumed an initiating cause separate from C. Now consider a different scenario: the shared level transmitter sticks low, causing continued inflow while also preventing both the high-level alarm and automatic stop from detecting the condition. Conditional on that exact failed-low initiating mechanism, both protections can be unavailable with probability one in the simplified model.

It would be wrong to multiply the initiator frequency by the unconditional 0.020196, because the initiator has already established C. A different independent measurement or protective principle might alter that conclusion, but it must be present and justified in the modeled system. A failure-high mechanism could have a different effect, so the sensor failure mode must remain specific.

Do not assume shared equipment always has one effect

A loss of power may disable a sensor, move a valve to a defined state or leave an actuator where it was. The consequence depends on the actual arrangement and the function demanded. A fail-closed valve might help stop inflow in one scenario and defeat cooling in another. The word shared identifies a question to investigate, not the answer by itself.

The same discipline applies to instrument air, hydraulic pressure, cooling, ventilation and network communication. Trace which functions require each utility and what happens during its loss, restoration and partial degradation. A power-source separation diagram alone may miss the common terminal box, environmental exposure or output element that reconnects the failure paths.

Include common maintenance without blaming individuals

Separate sensors can receive the same incorrect calibration reference, scaling parameter or test procedure. Separate valves can be restored using the same mistaken lineup instruction. These dependencies arise from the task and control system around the work; they are not removed by declaring the devices independent in a parts list.

Review how errors are detected before return to service, what evidence checks actual physical function, and whether one test can reproduce the same mistaken assumption on both channels. Independent verification requires an appropriately different evidential path. Merely asking a second person to read the same erroneous value does not establish that the physical condition is correct.

Read the residual floor before improving local components

In the model P(A∩B)=c+(1−c)uv, reducing u and v toward zero leaves the common contribution c. Halving both local probabilities gives 0.02+0.98×0.005×0.01=0.020049. Compared with 0.020196, that is only about a 0.73% reduction, despite halving each local failure probability.

Reducing the shared term may have a larger modeled effect, but a practical change can introduce different common dependencies. Evaluate the revised architecture, test arrangements and response time together. More hardware is not sufficient evidence of more independent protection. The benefit must follow the specific failure mechanisms that the change removes or reduces.

Choose an honest response when dependence is unresolved

A simple LOPA may conservatively avoid multiplying two disputed credits and examine whether one supported layer is sufficient. A more detailed joint model can be useful when the dependency mechanisms and data are adequately understood. An arbitrary middle credit, such as calling two dependent functions one-and-a-half layers, has no clear probabilistic meaning without an explicit model.

Unknown dependence is not the same as complete dependence, but neither does absence of data justify independence. Show plausible cases, explain which evidence would distinguish them and state whether the engineering conclusion changes. A bounded result is more informative than a precise product built on an unsupported assumption.

Distinguish diverse hardware from diverse evidence

Different sensor technologies can reduce some common mechanisms while introducing differences in what is measured. A tank measurement influenced by density is not automatically comparable with one influenced by surface geometry under every cargo and motion condition. Diversity must preserve the protective meaning of the measurement as well as reduce a specific shared vulnerability.

Trace common process connections and environmental exposure even when the electronics differ. Two instruments connected to one blocked impulse line can agree convincingly while missing the actual condition. Conversely, disagreement can be physically legitimate if the instruments sample different locations or times. An independence claim should therefore include the measurand, installation, signal path and failure behavior. Product variety alone is not a complete dependency assessment, and apparent agreement alone is not proof of protection.

Avoid transferring a common-cause factor between incompatible models

A common-cause parameter can represent a fraction of a failure rate, a conditional probability or an explicitly modeled shared event. Those meanings are not interchangeable. A factor fitted to redundant components of one type cannot simply be applied to an alarm-plus-operator chain and an automatic stop with different boundaries and failure mechanisms.

Document the event population from which the factor was obtained, its time basis, the failure modes it covers and the independent residual model. If a shared mechanism is already represented explicitly as C, adding a generic common-cause allowance for the same mechanism may count it twice. The appropriate model is the one whose terms can be mapped back to distinct physical or organizational mechanisms, with overlaps resolved and remaining uncertainty stated.

Keep partial function separate from complete failure

A shared disturbance may delay both layers without making either completely unavailable. Whether that delay counts as failure depends on the process deadline. In another scenario the same disturbance may reduce measurement accuracy while leaving enough margin for the protection to act. The joint event must therefore be defined against the actual required performance. Record the threshold and time boundary before classifying a shared mechanism as harmless, partial or complete defeat of the two functions. Remaining energized alone does not establish protective success; follow the function to its physical endpoint.

Keep the dependency record linked to change control

For each credited pair, record shared sensors, process connections, logic, outputs, utilities, environment, maintenance and human response. State the specific initiating causes against which independence has been assessed. A software update, common spare substitution or revised calibration procedure can change that record even if the protective-function names stay the same.

The public calculation demonstrates the size and direction of one modeled dependence error. It is not a universal correlation factor, a design for an emergency shutdown system or proof that a named layer qualifies as independent. The practical output is an auditable explanation of what can fail together and why the credited joint performance remains credible.

Sources