Understanding the IEC 61508 Functional Safety Lifecycle – Part 2
31 Aug 2026
The Starting Point: Hazard and Risk Assessment
In the first blog of this series, we introduced the overall IEC 61508 functional safety lifecycle and explored how the standard provides a structured framework for managing safety throughout the entire lifecycle of electrical, electronic and programmable electronic (E/E/PE) safety-related systems.
At the very beginning of that lifecycle sits one of the most important activities in any functional safety project – the hazard and risk assessment. No matter how advanced the technology, sophisticated the diagnostics, or capable the safety system may be, functional safety always starts with understanding what can go wrong, and what happens if it does?
Hazard and risk assessment forms the foundation for everything that follows within IEC 61508. It drives the identification of hazardous events, determines the required risk reduction, and ultimately defines the safety functions and Safety Integrity Levels (SILs) that the system must achieve. If this stage is weak, incomplete or poorly structured, the rest of the lifecycle is built on an unstable foundation.
Why Hazard and Risk Assessment Matters
IEC 61508 is fundamentally a risk-based standard. The objective is not to eliminate all risk - that is rarely achievable in real-world industrial systems. Instead, the goal is to reduce risk to a tolerable level through a combination of inherently safe design measures, protective systems and safety functions.
Before any safety requirements can be defined, the organisation must first understand:
- the hazards associated with the equipment or process
- how those hazards could lead to harm
- the likelihood of those events occurring
- the potential severity of the consequences, and
- what level of risk reduction is required
This assessment becomes the basis for defining the required safety functions and determining whether functional safety systems are needed at all. In many projects, this stage also becomes one of the most commercially and technically influential parts of the lifecycle. An over-conservative assessment may result in unnecessarily high SIL targets, excessive hardware redundancy and significant cost increases. An under-estimated risk can lead to unsafe designs, compliance failures and unacceptable residual risk.
Good hazard and risk assessment therefore requires both technical competence and practical engineering judgement.
Common Hazard and Risk Assessment Techniques
IEC 61508 does not mandate a single hazard analysis methodology. Instead, it recognises that different techniques may be appropriate depending on the complexity of the system, the industry sector and the lifecycle phase. In practice, most projects use a combination of techniques:
- Preliminary Hazard Analysis (PHA)
- Hazard and Operability Study (HAZOP)
- Failure Modes and Effects Analysis (FMEA)
- Fault Tree Analysis (FTA)
- Layer of Protection Analysis (LOPA)
Qualitative vs. Quantitative Risk Assessment
IEC 61508 allows both qualitative and quantitative approaches depending on the application. Many machinery and industrial applications begin with qualitative techniques such as risk matrices, risk graphs or structured engineering judgement.
Higher complexity systems, particularly within process industries, energy infrastructure or high-demand applications, often move toward semi-quantitative or quantitative approaches involving:
- event frequency estimation
- probability calculations
- consequence modelling
- reliability data
- fault tree quantification
The level of analysis should always be proportionate to the complexity and potential consequences of the system being assessed.
Final Thoughts
Hazard and risk assessment is where functional safety truly begins. Before SIL calculations, diagnostics, architecture constraints, and validation testing, organisations must first understand the hazards they are trying to control and the level of risk reduction required.
IEC 61508 intentionally allows flexibility in how this is achieved because no single methodology fits every industry or application. What matters is that the process is systematic, traceable, technically justified and proportionate to the risk involved. The quality of the hazard and risk assessment ultimately shapes the quality of the entire safety lifecycle.
In the next blog in this series, we will explore how hazard analysis results are translated into defined safety functions and Safety Requirements Specifications (SRS) within the IEC 61508 lifecycle.