SIL 2/3 functional safety with AI in refineries — proof testing current all year, not a sprint the month before the auditor.
IEC 61511 requires periodic proof testing of every SIF and an evidence dossier any inspector can read in an afternoon. In reality, that evidence gets rebuilt in a sprint one month before the audit. iLEAN plans, executes and records every proof test per SIF — without touching the SIS, with a human signature on every change, and keeping the safety lifecycle alive all year long.
The SIS is well designed — the documentation, not so much.
In any refinery with a serious functional safety culture, the project HAZOP/LOPA is done, the SIFs are defined and verified, and the SIS was installed by a good brand (Triconex, HIMA, Siemens SIS). The problem is not design — it is operation and lifecycle traceability:
- Proof testing is planned in an Excel sheet kept by the instrumentation technician. That sheet gets updated "when there's time" and the functional safety manager checks it the month before the audit. When something has been skipped, it is discovered late.
- The proof test field sheet stays on paper or as a photo on the technician's WhatsApp. Rebuilding which SIF was tested, when, with what result and who signed — for 180 SIFs — is weeks of work, done by hand, right before the auditor.
- Bypasses are managed on yet another sheet, and bypass closure is sometimes signed off verbally. The safety manager discovers during the audit a bypass that had been open longer than the procedure allowed.
- The theoretical PFDavg drifts from the real PFDavg because dangerous detected failures (DD) in the SIS are not always linked to the affected SIF in the history — and the periodic SIL revalidation runs on data that does not reflect real behavior.
The result is not a functional safety failure — it is fragile compliance: audit sprints, MOCs that weigh too much, and a silent risk that the declared SIL stops being defensible if the inspector pushes. And the instrumentation technician, who is good, spends half a day a week filling out forms instead of testing SIFs.
iLEAN takes no part in the safety logic — it keeps the lifecycle alive, with a human signature always.
The problem is not SIS design: it is information living in islands and on paper and a safety lifecycle operated in sprints. iLEAN acts as the putty that seals those gaps without touching what is critical, and gives the instrumentation technician back the hours lost to forms.
Edge captures the proof test reading in the field. Connect reads the SIS, the CMMS and the technician's sheet. Tracer links every action to the affected SIF. Writer assembles the dossier per SIF. The person signs — the SIS logic is never touched.
The iLEAN pieces applied to SIL 2/3 functional safety:
- Edge — a field tablet/terminal with vision and voice for the instrumentation technician during the proof test. It reads the SIF tag, photographs the sensor result, records the final actuation, captures the instantaneous PLC value. The technician speaks, the system writes. The field sheet is digitized in the same gesture as the test itself.
- Connect — captures from the SIS over OPC UA/Modbus in read-only mode (demand events, DD detected failures, diagnostic events), from the CMMS the proof testing schedule per SIF, from the DCS the corresponding process conditions, and from the instrumentation team's WhatsApp/email whatever gets communicated outside the system. Connect never writes to the SIS or opens an inbound connection to the OT ring.
- Tracer + Writer + Agent — Tracer links every proof test, every detected failure, every bypass opened and closed to the corresponding SIF. The agent tracks schedule compliance: when a SIF approaches its proof testing interval, it opens the work order in the CMMS and prepares the pre-filled field sheet. Writer assembles the audit-ready dossier per SIF — proof tests with date, technician, evidence, signature; DD/DU history; bypasses with their open time. The functional safety manager signs; the inspector is in and out in an afternoon.
Sprint compliance vs. a safety lifecycle alive all year
| Aspect | Excel + paper + audit sprint | With iLEAN Tracer + Edge + Writer |
|---|---|---|
| Proof testing planning | Technician's Excel, reviewed the month before | Agent opens the work order in the CMMS as the interval nears |
| Proof test field sheet | Paper or a photo on the technician's WhatsApp | Digital in the same gesture as the test is run |
| Bypass management | Another sheet, closure sometimes verbal | Bypass linked to the SIF, open time measured, closure signed |
| Real vs. theoretical PFDavg | Fixed project theory, real value unknown | DD/DU history linked per SIF for revalidation |
| Audit preparation | Weeks of rebuilding by hand | Dossier per SIF ready the day the inspector asks |
| Touches the SIS | n/a | Never — Connect only reads, OT ring intact |
Impact estimate for your plant — to be validated with your numbers.
The block below is an estimate to be validated with the specific data of your plant. We put it forward so the committee has an order of magnitude; we refine it during the diagnostic.
- Refinery with an existing Triconex/HIMA/Siemens SIS, a fleet of 100-300 SIFs (mix of SIL 2 and SIL 3), SAP PM or Maximo CMMS, next IEC 61511 audit cycle within the coming 12 months.
- Tracer + Edge pilot on the Pareto process unit: the one that concentrates the largest number of SIL 3 SIFs. First value expected within a few weeks — a proof testing planning agent that stays current without sprints, dossier per SIF available.
- Audit preparation time reduced by ≥ 30%, plus a reduction in the instrumentation technician's time spent on forms (back to testing SIFs).
- Indicative payback between 4 and 9 months. The hard lever is not saving forms — it is defending the declared SIL with live data and avoiding an audit finding that forces a unit shutdown.
And the reasonable doubt of the CAIO and the functional safety manager
"An AI touching my SIS? No way." — exactly, and that is why the architecture's first requirement is that it does not touch it. The three safety rings formalize something serious industry already did: the OT ring (the SIS, the SIL, the PLCs) accepts no inbound connection, only reads from a signed mailbox, and any data entering has been validated first in the intermediate chamber. It is the same architecture that protected well-designed OT networks when Log4j blew up in the world's ERPs. On the reliability of the agent that assembles the dossier: hallucination is a problem of free generation, not of anchored tasks — gathering and reformatting evidence is exactly where the best models brought error below 1.5% [1]. And the functional safety manager signs every dossier before it goes out.
[1] OpenAI paper "Why Language Models Hallucinate", 2025 — on the reliability of AI in anchored tasks.
What people ask about SIL functional safety with AI in refineries
What is proof testing and why does IEC 61511 require it periodically?
Proof testing is the periodic test that demonstrates that each SIF (Safety Instrumented Function) still meets its assigned SIL — that the sensor detects, the logic solver reasons and the final actuator closes the valve or stops the pump when it should. IEC 61511 requires it at the interval defined by the project's SIL/LOPA analysis (typically quarterly or yearly per SIF). Without current proof testing, the real PFDavg degrades against the theoretical one and the declared SIL stops being defensible before the inspector.
How is PFD calculated and how does iLEAN help?
PFDavg (probability of failure on demand) is calculated per SIF from the λDU failure rate of each element (sensor + logic solver + final actuator) and the proof test interval. iLEAN does not calculate the project's PFD — that is the functional safety team's job with their tool (exSILentia, ProSET). What iLEAN does is keep the data alive: real proof testing history per SIF, dangerous failures detected (DD) and undetected (DU) brought to light, corrective interventions traced. The functional safety team uses that real data to recalculate the PFDavg without rebuilding it by hand every time.
Does it comply with IEC 61511 and the safety lifecycle?
iLEAN covers the phases of the safety lifecycle that suffer most from paper and Excel: operation and maintenance (proof testing, failure management, bypass management) and periodic verification (SIL revalidation). It does not replace the project's HAZOP/LOPA or SIL Verification. What it brings is continuous traceability and audit-ready dossiers per SIF — every proof test with who, when, which tag, which result, which evidence, which signature. The inspector is in and out in an afternoon.
Does it reduce the HAZOP/LOPA effort?
The project HAZOP/LOPA cannot be skipped — it is human judgment work. What iLEAN reduces is the effort of periodic revalidations and of MOC (Management of Change): when a SIF is modified or a final element is replaced, the agent gathers the proof testing history, the detected failures and the schedule compliance and hands it to the team so the revalidation LOPA focuses on what changed, not on rebuilding what already happened. Estimate to be validated: the preparation time for a SIL audit drops notably when the data is alive.
Does it integrate with the existing SIS without touching it?
Yes — and it is the fundamental point. iLEAN never writes to the SIS, opens no inbound connection to the OT ring and takes no part in the safety logic. Connect reads — from the SIS over OPC UA/Modbus in read-only mode, from the DCS separately, from the CMMS (SAP PM/Maximo) the proof testing schedule, from the technician's field sheets. Writer assembles the evidence dossier per SIF. The three-ring architecture guarantees that what is critical (the SIS) remains for authorized people only — the AI contributes documentation, not decisions over the safety loop.
Tell us your case and in 48h we'll send you the estimated ROI of the SIL pilot for your refinery.
We work on your real SIF inventory and your next audit window, not on generic figures. Diagnostic with no commitment.
Request estimated ROI in 48h See petrochemical