Functional safety that truly holds when it matters

ASIL/SIL or PL classification, safety functions and redundancy architecture under IEC 61508/61511 or ISO 26262 – we facilitate the analysis and build the capability within your team.

SIL (Safety Integrity Level) = the measure of reliability required of a safety function. IEC 61508 = the cross-industry base standard for functional safety of electrical/electronic/programmable systems, IEC 61511 its derivative for the process industry. ISO 26262 = functional safety in the automotive sector (Automotive Safety Integrity Level), PL (Performance Level) = an older classification approach similar to SIL/ASIL; every classification starts with a hazard and risk analysis (G+R) or, in automotive contexts, HARA (Hazard Analysis and Risk Assessment) – see also our Risk Management page.

[01] — WHERE YOU STAND

Is your safety function still missing traceability?

ASIL/SIL/PL gets estimated more than derived
The classification comes from gut feeling instead of a traceable hazard and risk analysis (or HARA) and recognized calculation methods.
Functions blurred together
Safety and operational functions run in the same system without clear separation – making the evidence trail unnecessarily complex.
Evidence assembled at the end
The safety case gets written up right before the audit, instead of growing alongside the project.
Redundancy without justification
Duplicate sensors or actuators exist, but there’s no documentation of why exactly this architecture (1oo2, 2oo3) was chosen.
Rule of thumb: planning early saves rework
Based on experience, a safety architecture considered from the start avoids costly retrofits right before certification.
[02] — THE SHIFT

From guesswork to a solid classification

The status quo

The ASIL/SIL/PL classification is roughly estimated, with no traceable calculation.
Safety and operational functions are blurred together in the same system.
The safety case is put together right before the audit, under time pressure.
Redundant architecture gets built without documenting the choice.

With our approach

The ASIL/SIL/PL classification is based on a traceable HARA and recognized calculation methods.
Safety functions are cleanly separated from operational functions right from the start.
The safety case grows alongside the project, instead of being improvised at the end.
Every architecture decision (e.g. 1oo2, 2oo3) is justified and documented.
[03] — OUR APPROACH

From hazard to solid certification

Functional safety isn’t created by a certification stamp at the end – it comes from a process that runs consistently from the first hazard analysis through to the finished safety case. Our approach connects four steps: assessing hazards, deriving the required safety level, designing the architecture to match, and building the safety case alongside the project.

01
Hazard and risk assessment (G+R, or HARA in automotive contexts)
The starting point of every safety consideration – builds on our risk management methodology, deepened here for safety: which hazard, how severe, how frequent, how controllable.
02
SIL/ASIL classification
Traceable derivation of the required safety level under IEC 61508/61511 or ISO 26262 (ASIL) – documented, not estimated.
03
Safety function and architecture
A clear separation of safety and operational functions, with a justified choice of redundancy architecture (e.g. 1oo2, 2oo3) matched to the required level.
04
Evidence and validation
The safety case grows alongside the project and is fully in place for audit or certification, instead of being improvised at the end.
[04] — TRACK RECORD

The same methodology, deepened for safety functions

Functional safety builds on the same HARA methodology that underpins our Risk Management page – deepened here with the specific requirements of IEC 61508, IEC 61511 and ISO 26262. Applied for decades across safety-critical industries: mechanical engineering, process industry, automotive development. This experience helps especially where safety and development teams need a shared language – not just to meet requirements, but to actually understand them.

[05] — NEXT STEP

Ready to make your safety function audit-proof?

Let’s use an initial call to find out where your system stands today and which SIL/ASIL level is realistically required.