The highest SIL claimable for a safety function is capped by the architectural constraints, met by Route 1H (hardware fault tolerance plus safe failure fraction) or Route 2H (hardware fault tolerance plus field-feedback reliability data at higher confidence). A fault tolerance of N means N+1 faults are the fewest that can defeat the safety function; diagnostics are ignored when counting it; a fault that directly causes further faults counts once; and faults whose likelihood is very low relative to the subsystem's integrity requirement may be excluded only with documented justification. An element is type A when the failure modes of all its constituent components are well defined, its behaviour under fault is fully determinable, and dependable failure data supports the claimed detected and undetected dangerous failure rates; otherwise it is type B. Diagnostic credit in the SFF of an element with zero fault tolerance in high demand or continuous mode requires the diagnostic test interval plus the time to reach the safe state to be within the process safety time; alternatively, under high demand, a diagnostic test rate at least 100 times the demand rate; for elements with fault tolerance above zero (or in low demand), the diagnostic test interval plus repair time must be shorter than the MTTR assumed in the integrity calculation.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.