Is Fire Detection a SIL-Rated Function?

No marine rule assigns one. And a bare SIL number would be the wrong metric anyway — coverage is never 100%, and detection only mitigates.
No. Nothing in SOLAS, the FSS Code or the class rules assigns a safety integrity level to a marine fire-detection system — detection is type-approved, not SIL-rated. That is worth knowing before a supplier offers you a SIL badge. It is worth understanding because a bare SIL figure would be the wrong measure for detection even if somebody did require one.
What a SIL actually is
A quantified reliability claim about one defined function, not a quality mark on a box. IEC 61508 is the base functional-safety standard for electrical, electronic and programmable electronic safety-related systems; IEC 61511 is its process-industry adaptation. Both define four safety integrity levels, SIL 1 through SIL 4, with SIL 4 the most demanding — each level is a band of permissible dangerous-failure probability, and the bands step by an order of magnitude.
The measure depends on how often the function is called on, and this is the detail most often lost in a datasheet. For a low-demand function the metric is PFDavg — the average probability of a dangerous failure on demand. For a high-demand or continuous function it is PFH — the average frequency of a dangerous failure per hour. They are different quantities with different units, so a PFDavg and a PFH are not comparable figures, and which mode applies changes both the target and the arithmetic behind it.
What earns a SIL is evidence: failure-rate data for the components, architectural constraints on redundancy and diagnostic coverage, and a stated proof-test interval that the calculation assumes will actually be performed. Strip those away and the number means nothing.
No marine rule puts a SIL on fire detection
The governing evidence for a marine detector is approval, not integrity. Performance is proven against the relevant EN 54 part, marine survivability against IEC 60092-504 and 60533, fittability through a wheelmark or flag acceptance, and the installation through class type approval. That stack answers whether the device detects, survives and may be fitted. None of it answers how often the function may dangerously fail.
Functional safety does turn up at sea, but on the fuel side. Gas and low-flashpoint fuel installations under the IGF Code require emergency shutdown arrangements to isolate the fuel system, and industry practice applies IEC 61511 to those ESD functions with redundancy, diagnostics and defined proof testing. So a multi-fuel PCTC can carry a functional-safety-managed shutdown in the fuel-preparation space and a type-approved-only detection system on the cargo deck next door — two regimes, one hull, which is the same split this corpus found in the ammonia-ready case.
It is also worth separating this from the other framework that does reach detection. IACS UR E22 places fire detection in its top category for computer-based systems, which drags in the UR E26/E27 cyber-resilience obligations. That is a software-assurance and security categorisation. It is not a dangerous-failure-rate target, and holding one does not imply the other.
Why a SIL number is the wrong metric here
The process industry reached this conclusion first, and wrote a separate document because of it. ISA-TR84.00.07 — guidance on evaluating fire, combustible gas and toxic gas system effectiveness — exists because practitioners found IEC 61511 techniques inadequate for fire and gas system design. The two reasons given are precisely the two that apply to a vehicle deck.
The first is that coverage is not 100%. A safety instrumented function is assumed to be demanded and then either to work or not. A fire and gas system can fail for a reason that has nothing to do with its reliability: the event occurred where nothing was watching, or the products of the event never reached a sensor. This corpus has documented both failure paths independently — off-gas that never leaves a sealed battery pack, and a point instrument surveying a field it cannot cover.
The second is that detection is mitigative, not preventive. It reduces consequence rather than preventing the event, so even a flawless detection function does not deliver the risk reduction a SIL claim is normally used to assert. Between them these force a different method: TR84.00.07 states that LOPA is not the appropriate analysis for a fire and gas system, and uses event tree analysis instead, expressing performance through coverage and safety availability rather than a single probability of failure on demand.
What to ask for instead
- The three terms separately: detection coverage (what fraction of the space and of the credible scenarios the design responds to, and on what stated assumptions), the safety availability of the equipment, and the mitigation effectiveness claimed for whatever the alarm triggers.
- Which IEC 61508 mode any quoted figure belongs to. A PFDavg and a PFH are different quantities; a number offered without its mode cannot be checked or compared.
- Whether a quoted SIL is a component capability ("this transmitter is SIL-2 capable") or a verified loop (sensor, logic solver and final element assessed together as one function). The first is a purchasing fact about a part. Only the second says anything about the function aboard the ship.
- The proof-test interval the figure assumes, and whether that interval is achievable at sea between surveys. A calculation that assumes annual proof testing is not valid on a system nobody can take offline mid-voyage.
- On a gas- or low-flashpoint-fuelled hull, whether the cargo-space detection and the fuel-side ESD are being held to the same standard of evidence — and if not, what justifies the difference.
What it means for owners and class submissions
For owners, the practical move is to stop asking for a SIL and start asking for the decomposition. A supplier who states coverage assumptions, gives an availability figure and names the proof-test interval behind it has told you something you can interrogate and hold them to. A supplier who offers a bare integrity level has told you their electronics are reliable, which was never the part in doubt.
For a class submission the point is sharper. Where a detection arrangement goes up under SOLAS II-2 Regulation 17 as an alternative design, what is being assessed is an engineering argument rather than a certificate held against a clause — and coverage plus availability, with the assumptions written down, is a far stronger argument than a badge. Regulation 17 is one of the few places in the marine framework that actively wants this kind of quantified reasoning. Bringing it is the difference between a submission that answers the Administration's question and one that restates the datasheet.
How RoRoSAFE helps
RoRoSAFE is designed around the metrics this article recommends instead of a SIL number: coverage per vehicle, detection lead time against staged tests, false-alarm rate, and behaviour under single failures, with failure-isolated segments and redundant controllers. Those figures are shared with qualified operators, class and underwriters under NDA.
Pilot: one deck · installed alongside the berth · no drydock · 6 months of dashboard access
Sources
- 1. IEC 61508 — functional safety of electrical/electronic/programmable electronic safety-related systems: four safety integrity levels SIL 1–4; low-demand mode measured by average probability of dangerous failure on demand (PFDavg) and high-demand or continuous mode by average frequency of dangerous failure per hour (PFH). IEC 61511 is the process-industry sector adaptation of IEC 61508.
- 2. ISA-TR84.00.07, "Guidance on the Evaluation of Fire, Combustible Gas and Toxic Gas System Effectiveness" — a derivative of ANSI/ISA-84.00.01 (IEC 61511 Mod) for process industries: written because practitioners found IEC 61511 techniques inadequate for fire and gas system design, since fire and gas systems are not 100% effective at detecting fires and gas releases (coverage is not 100%) and, once detection occurs, consequences are only reduced rather than prevented (mitigative). Defines performance metrics including coverage and safety availability, states that LOPA is not the appropriate method for analysing fire and gas system performance, and uses event tree analysis to estimate consequence frequency and overall system effectiveness.
- 3. Marine approval stack for detection equipment — EN 54 performance parts, IEC 60092-504 and IEC 60533 for the marine environment, wheelmark/flag acceptance and class society type approval. Covered in this corpus at Is EN 54 Enough for a Marine Detector?; the explosion-protection layer is at What Ex Rating Does a Deck Detector Need?.
- 4. IMO IGF Code — emergency shutdown arrangements required to isolate the fuel system, alongside fire detection and suppression provisions for low-flashpoint fuels.
Questions, answered
Do marine fire-detection systems have to be SIL-rated?+
No requirement to that effect was found in SOLAS, the FSS Code or class rules. Detection is governed by approval rather than integrity: EN 54 performance parts, IEC 60092-504 and 60533 for marine survivability, a wheelmark or flag acceptance, and class type approval. That stack establishes that the device detects, survives and may be fitted — not how often the function may dangerously fail.
What does a SIL number actually express?+
A quantified limit on dangerous failure for one defined function. IEC 61508 sets four levels, SIL 1 to SIL 4, with SIL 4 the most demanding. Low-demand functions are measured by average probability of dangerous failure on demand (PFDavg), high-demand or continuous ones by average frequency of dangerous failure per hour (PFH). The two are different quantities and cannot be compared directly.
Why is a SIL a poor fit for fire and gas detection?+
For two reasons the process industry documented in ISA-TR84.00.07. Coverage is never 100%, so the system can fail because the event happened where nothing was watching rather than because anything broke. And detection is mitigative — it reduces consequence rather than preventing the event. That is why the report uses event tree analysis rather than LOPA, and reports coverage and safety availability instead of a single PFD.
What should a buyer ask a detection supplier for?+
The decomposition rather than a badge: coverage and the assumptions behind it, equipment safety availability, and the mitigation effectiveness claimed for the triggered action. Also which IEC 61508 mode any figure belongs to, whether a quoted SIL is component capability or a verified loop, and the proof-test interval assumed — a figure that assumes testing you cannot perform at sea is not valid aboard.
Continue the thread

Is EN 54 Enough for a Marine Detector?
No. EN 54 proves it detects; IEC 60092-504 and 60533 prove it survives a ship; only a wheelmark or Red Ensign mark makes it fittable.

Does UR E26/E27 Apply to Fire Detection?
Yes. UR E22 puts fire detection in Category III, so a networked grid is a Category III CBS needing E27 security capabilities and class approval.

What Ex Rating Does a Deck Detector Need?
ATEX does not apply to seagoing ships. Class asks for the certificate anyway — as engineering evidence, not compliance. And hydrogen is Group IIC.

SOLAS II-2/17: The Alternative Design Route
Through SOLAS II-2/17, which permits deviation from Chapter II-2's prescriptive requirements if an engineering analysis proves equivalent safety.
