Modernizing Legacy Safety Instrumented Systems: A SIL 2 Predictive Gas Detection Framework for Global IEC 61511 Compliance and Industrial Risk Reduction
DOI:
https://doi.org/10.70917/ijcisim-2026-5682Keywords:
Safety instrumented system, IEC 61511, safety integrity level, gas detection, predictive maintenance, probability of failure on demand, layer of protection analysis, process safety, machine learning, functional safetyAbstract
Ageing safety instrumented systems (SIS) remain the dominant protective layer against flammable and toxic gas releases in the process industries, yet a large installed base of legacy gas detection loops was engineered before IEC 61511 and cannot demonstrate the safety integrity level (SIL) that current layer of protection analysis (LOPA) assigns to them. This study develops and evaluates a Predictive Gas Detection Framework (PGDF), a four-layer retrofit architecture that couples hardware modernization with a supervised prognostic layer that forecasts dangerous undetected (DU) detector failures before they occur. Using a fully specified simulation study of a brownfield gas processing facility, we (a) verified the average probability of failure on demand (PFDavg) of a legacy 1oo2 catalytic-bead gas detection safety instrumented function (SIF) and of two modernization options by 120,000-iteration Monte Carlo analysis with common random numbers; (b) trained and temporally validated four classifiers on 20,493 weekly detector-health records from 184 simulated detectors; and (c) propagated the resulting diagnostic performance through a 36-month deployment simulation, a LOPA, and a 15-year cost model. The legacy SIF achieved a median PFDavg of 1.73 × 10⁻² (90% credible interval [CrI] 1.01 × 10⁻²–2.99 × 10⁻²; risk reduction factor [RRF] 58), meeting SIL 2 in only 4.6% of iterations. Like-for-like sensor and logic-solver replacement was insufficient (PFDavg 1.40 × 10⁻²; SIL 2 in 15.6%). The full PGDF retrofit achieved 1.88 × 10⁻³ (90% CrI 9.88 × 10⁻⁴–3.64 × 10⁻³; RRF 533), satisfying SIL 2 in 100.0% of iterations, a paired reduction of 89.0% (95% CI 82.4–93.9). A random forest was the strongest prognostic model (area under the receiver operating characteristic curve [AUC] 0.849, 95% CI 0.836–0.862), significantly exceeding elastic-net logistic regression (ΔAUC 0.024, p < .001). Discrimination was excellent for gradual degradation failures (AUC 0.892) but no better than chance for abrupt shock-induced failures (AUC 0.545), which imposes a hard ceiling on any prognostic layer. Mean covert-failure exposure fell from 88.2 to 21.1 days (−76.1%; t = 11.06, p < .001; Hedges' g = 1.34, 95% CI 1.08–1.61), 75.7% of DU failures were averted before onset (95% CI 67.6–82.7), and the spurious alarm rate fell by 69.0% (incidence rate ratio 0.31, 95% CI 0.26–0.38, p < .001). Only the full PGDF met the tolerable event frequency of 2 × 10⁻⁵ yr⁻¹ (mitigated frequency 5.63 × 10⁻⁶ yr⁻¹). Discounted payback was 4.68 years. We conclude that predictive diagnostics are a legitimate but bounded contributor to SIL attainment: they raise effective diagnostic coverage for degradation-mode failures and shorten covert exposure, but hardware redundancy and final-element integrity remain the load-bearing elements of compliance. Findings are derived from simulated data and require field validation before operational adoption.