HomeLearnCoursesHackathonsAccount
Functional Safety & Robot Certification Standards
Safety Integrity: Quantifying How Much Rigor Is Enough · 1/2

Not every safety function needs the same assurance

Once a hazard has been assessed for severity and likelihood, the next question is: how confident do we need to be that the safety function protecting against it will actually work when called upon? This is the idea behind what the discipline calls safety integrity, a way of quantifying required rigor rather than treating 'is it safe' as a binary yes or no. A safety function protecting against a low-severity, rare hazard might reasonably be allowed a higher tolerable failure rate than one protecting against a high-severity, frequent hazard. The higher the potential consequence, the lower the acceptable chance that the safety function silently fails to do its job.

This concept generally gets formalized into a small number of discrete levels, where each step up demands more from the design: more independent verification, more redundancy, more conservative assumptions about how components can fail, and a lower tolerable rate of dangerous failure. A function assigned a low integrity level might be satisfied by careful design review and standard testing. A function assigned the highest integrity level might require independent hardware channels, formal analysis of failure modes, and evidence that even rare combinations of component failures have been considered and ruled out or mitigated.