Application directives for layer of protection analysis (LOPA)
1 Scope
This document specifies the general requirements, basic procedures, analysis process and documentation requirements for layer of protection analysis (LOPA).
This document is applicable to guiding all industries in conducting layer of protection analysis.
2 Normative references
The following normative documents contain provisions which, through reference in this text, constitute provisions of this document. For dated references, only the edition cited applies. For undated references, the latest edition of the referenced document (including any amendments) applies.
GB/T 20438.4-2017 Functional safety of electrical/electronic/programmable electronic safety-related systems - Part 4: Definitions and abbreviations
GB/T 21109.1-2022 Functional safety of safety instrumented systems in the process industry sector - Part 1: Framework, definitions, system, hardware and application programming requirements
3 Terms and definitions
For the purposes of this document, the terms and definitions given in GB/T 20438.4-2017 and GB/T 21109.1-2022 as well as the following apply.
3.1
basic process control system; BPCS
system that responds to input signals from the process and its associated equipment, other programmable systems and/or the operator, and generates output signals to operate the process and its associated equipment in the intended manner, provided that it does not perform any SIF
Note 1: BPCS includes all necessary equipment to ensure the process operates in the intended manner.
Note 2: BPCS typically supports multiple functions, such as process control, monitoring and alarm functions.
[Source: GB/T 21109.1-2022, 3.2.3]
3.2
conditional modifiers
one of the probability values used in scenario risk calculation
Note: It is typically applied when affecting consequences (e.g. casualties, ignition probability, fatality rate) rather than the outcomes of major loss events (e.g. leakage, vessel rupture)
3.3
consequence
outcome of a specific event
Note: It generally includes casualties, property damage, environmental pollution, reputational impact and so on.
3.4
enable event / enable condition
event or condition that does not directly give rise to scenario consequences
Note: It refers to a necessary operating state or condition that enables an initial event to evolve into scenario consequences.
3.5
initial risk
risk of a scenario without accounting for the effect of any protection measures
3.6
initial event
minimum combination of failures or errors required to initiate the development of an accident sequence
Note: It consists of a single initiating cause, multiple causes, or an initiating cause coupled with enable conditions.
3.7
intermediate event
key event occurring before an initial event develops into a consequence
Note: It is typically a detectable event, such as high pressure in a pressure vessel or high level in a storage tank. It should be noted that in specific scenarios, an initial event may develop directly into adverse consequences with no intermediate event involved.
3.8
layer of protection analysis; LOPA
method or framework for assessing the effectiveness of independent protection layers that reduce the frequency of undesired events and/or the severity of their consequences
Foreword i
Introduction iii
1 Scope
2 Normative references
3 Terms and definitions
4 Abbreviations
5 General requirements
5.1 Purpose
5.2 Basic requirements
5.3 Scope of application
5.4 Personnel requirements
6 Basic procedure
7 Analysis process
7.1 Risk point identification
7.2 Scenario identification and screening
7.3 Consequence and severity assessment
7.4 Initial event and frequency confirmation
7.5 Enable condition confirmation
7.6 Conditional modifier confirmation
7.7 IPL identification and PFD confirmation
7.8 Consequence frequency calculation for single scenario analysis method
7.9 Consequence frequency calculation for multi scenario analysis method
7.10 Risk assessment and recommendations
8 LOPA documentation
Annex A (Informative) Data for each LOPA phase (Example)
A.1 Data derivable from HAZOP analysis for LOPA
A.2 LOPA record form
A.3 Examples of consequences and severity
A.4 Typical protection layers
A.5 Assessment method for multiple BPCS loops serving as IPLs
A.6 Example of risk assessment and recommended matrix method
A.7 Examples of initial event frequencies
Annex B (Informative) Application of LOPA in reactor systems
B.1 General
B.2 Problem description
B.3 Problem discussion
B.4 Design improvements for consideration
B.5 Design improvements to be considered derived from multi scenario analysis
Annex C (Informative) Application of LOPA method in SIL determination
C.1 Example 1 of LOPA
C.2 Example 2 of LOPA
C.3 Example 3 of LOPA
C.4 Example 4 of LOPA
Annex D (Informative) Calculation of enable conditions
Annex E (Information) Consequence frequency calculation in high demand mode
E.1 General
E.2 Calculation method
E.3 Example
E.4 Example
Bibliography
Figure 1 Tolerable risk and ALARP
Figure 2 Flowchart of layer of protection analysis
Figure A.1 Typical BPCS logic solver with multiple loops in the same scenario
Figure A.2 BPCS loops sharing a sensor in the same scenario
Figure A.3 BPCS loops sharing input / output cards in the same scenario
Figure A.4 Maximum number of BPCS functional loops serving as IPLs in the same scenario
Figure B.1 Simplified process – Flow Diagram of batch polymerization of polyvinyl chloride (PVC)
Figure E.1 Example of three operation modes
Table A.1 Data derivable from HAZOP analysis for LOPA
Table A.2 Single scenario LOPA record form (Example)
Table A.3 Multi scenario LOPA record form (Example)
Table A.4 Simplified casualty consequence classification (Example)
Table A.5 Simplified economic loss consequence classification (Example)
Table A.6 Simplified environmental impact consequence classification (Example)
Table A.7 Typical process protection layers
Table A.8 PFD values of typical independent protection layers
Table A.9 Risk matrix with different action requirements (Example)
Table A.10 Numerical analysis method - Tolerable risk for safety and health related events (Example)
Table A.11 Numerical analysis method – Tolerable risk for environment-related events (Example)
Table A.12 Numerical risk method – Tolerable risk for property-related events (Example)
Table A.13 Common initial event frequencies (Example)
Table B.1 Analysis scenario cases
Table B.2 Analysis case for Scenario
Table B.3 Analysis case for Scenario
Table B.4 Analysis case for Scenario
Table B.5 Analysis case for Scenario
Table B.6 Analysis case for Scenario
Table B.7 Analysis case for Scenario
Table B.8 Analysis case for Scenario
Table B.9 Analysis case for Scenario
Table B.10 Analysis case for multi scenario
Table C.1 Example 1 of LOPA
Table C.2 Example 2 of LOPA
Table C.3 Example 3 of LOPA
Table C.4 Example 4 of LOPA
Application directives for layer of protection analysis (LOPA)
1 Scope
This document specifies the general requirements, basic procedures, analysis process and documentation requirements for layer of protection analysis (LOPA).
This document is applicable to guiding all industries in conducting layer of protection analysis.
2 Normative references
The following normative documents contain provisions which, through reference in this text, constitute provisions of this document. For dated references, only the edition cited applies. For undated references, the latest edition of the referenced document (including any amendments) applies.
GB/T 20438.4-2017 Functional safety of electrical/electronic/programmable electronic safety-related systems - Part 4: Definitions and abbreviations
GB/T 21109.1-2022 Functional safety of safety instrumented systems in the process industry sector - Part 1: Framework, definitions, system, hardware and application programming requirements
3 Terms and definitions
For the purposes of this document, the terms and definitions given in GB/T 20438.4-2017 and GB/T 21109.1-2022 as well as the following apply.
3.1
basic process control system; BPCS
system that responds to input signals from the process and its associated equipment, other programmable systems and/or the operator, and generates output signals to operate the process and its associated equipment in the intended manner, provided that it does not perform any SIF
Note 1: BPCS includes all necessary equipment to ensure the process operates in the intended manner.
Note 2: BPCS typically supports multiple functions, such as process control, monitoring and alarm functions.
[Source: GB/T 21109.1-2022, 3.2.3]
3.2
conditional modifiers
one of the probability values used in scenario risk calculation
Note: It is typically applied when affecting consequences (e.g. casualties, ignition probability, fatality rate) rather than the outcomes of major loss events (e.g. leakage, vessel rupture)
3.3
consequence
outcome of a specific event
Note: It generally includes casualties, property damage, environmental pollution, reputational impact and so on.
3.4
enable event / enable condition
event or condition that does not directly give rise to scenario consequences
Note: It refers to a necessary operating state or condition that enables an initial event to evolve into scenario consequences.
3.5
initial risk
risk of a scenario without accounting for the effect of any protection measures
3.6
initial event
minimum combination of failures or errors required to initiate the development of an accident sequence
Note: It consists of a single initiating cause, multiple causes, or an initiating cause coupled with enable conditions.
3.7
intermediate event
key event occurring before an initial event develops into a consequence
Note: It is typically a detectable event, such as high pressure in a pressure vessel or high level in a storage tank. It should be noted that in specific scenarios, an initial event may develop directly into adverse consequences with no intermediate event involved.
3.8
layer of protection analysis; LOPA
method or framework for assessing the effectiveness of independent protection layers that reduce the frequency of undesired events and/or the severity of their consequences
Contents of GB/T 32857-2025
Foreword i
Introduction iii
1 Scope
2 Normative references
3 Terms and definitions
4 Abbreviations
5 General requirements
5.1 Purpose
5.2 Basic requirements
5.3 Scope of application
5.4 Personnel requirements
6 Basic procedure
7 Analysis process
7.1 Risk point identification
7.2 Scenario identification and screening
7.3 Consequence and severity assessment
7.4 Initial event and frequency confirmation
7.5 Enable condition confirmation
7.6 Conditional modifier confirmation
7.7 IPL identification and PFD confirmation
7.8 Consequence frequency calculation for single scenario analysis method
7.9 Consequence frequency calculation for multi scenario analysis method
7.10 Risk assessment and recommendations
8 LOPA documentation
Annex A (Informative) Data for each LOPA phase (Example)
A.1 Data derivable from HAZOP analysis for LOPA
A.2 LOPA record form
A.3 Examples of consequences and severity
A.4 Typical protection layers
A.5 Assessment method for multiple BPCS loops serving as IPLs
A.6 Example of risk assessment and recommended matrix method
A.7 Examples of initial event frequencies
Annex B (Informative) Application of LOPA in reactor systems
B.1 General
B.2 Problem description
B.3 Problem discussion
B.4 Design improvements for consideration
B.5 Design improvements to be considered derived from multi scenario analysis
Annex C (Informative) Application of LOPA method in SIL determination
C.1 Example 1 of LOPA
C.2 Example 2 of LOPA
C.3 Example 3 of LOPA
C.4 Example 4 of LOPA
Annex D (Informative) Calculation of enable conditions
Annex E (Information) Consequence frequency calculation in high demand mode
E.1 General
E.2 Calculation method
E.3 Example
E.4 Example
Bibliography
Figure 1 Tolerable risk and ALARP
Figure 2 Flowchart of layer of protection analysis
Figure A.1 Typical BPCS logic solver with multiple loops in the same scenario
Figure A.2 BPCS loops sharing a sensor in the same scenario
Figure A.3 BPCS loops sharing input / output cards in the same scenario
Figure A.4 Maximum number of BPCS functional loops serving as IPLs in the same scenario
Figure B.1 Simplified process – Flow Diagram of batch polymerization of polyvinyl chloride (PVC)
Figure E.1 Example of three operation modes
Table A.1 Data derivable from HAZOP analysis for LOPA
Table A.2 Single scenario LOPA record form (Example)
Table A.3 Multi scenario LOPA record form (Example)
Table A.4 Simplified casualty consequence classification (Example)
Table A.5 Simplified economic loss consequence classification (Example)
Table A.6 Simplified environmental impact consequence classification (Example)
Table A.7 Typical process protection layers
Table A.8 PFD values of typical independent protection layers
Table A.9 Risk matrix with different action requirements (Example)
Table A.10 Numerical analysis method - Tolerable risk for safety and health related events (Example)
Table A.11 Numerical analysis method – Tolerable risk for environment-related events (Example)
Table A.12 Numerical risk method – Tolerable risk for property-related events (Example)
Table A.13 Common initial event frequencies (Example)
Table B.1 Analysis scenario cases
Table B.2 Analysis case for Scenario
Table B.3 Analysis case for Scenario
Table B.4 Analysis case for Scenario
Table B.5 Analysis case for Scenario
Table B.6 Analysis case for Scenario
Table B.7 Analysis case for Scenario
Table B.8 Analysis case for Scenario
Table B.9 Analysis case for Scenario
Table B.10 Analysis case for multi scenario
Table C.1 Example 1 of LOPA
Table C.2 Example 2 of LOPA
Table C.3 Example 3 of LOPA
Table C.4 Example 4 of LOPA