Systematic Capability
Systematic Capability (SC) is a functional safety concept from IEC 61508/61511 that measures confidence (SC1–SC4) that a device's systematic safety integrity meets the requirements of a specified Safety Integrity Level (SIL), when used per its safety manual. It addresses design and software errors, not random hardware failures.
On the shop floor, Systematic Capability is applied when selecting safety devices like emergency-stop relays, safety PLCs, light curtains, and pressure transmitters. Engineers must ensure each device's SC rating meets or exceeds the target SIL for the safety function. SC is documented in functional safety certificates and safety manuals, which specify constraints like wiring, diagnostics, and firmware. Maintenance and engineering staff must follow these constraints exactly; violations invalidate the SC claim. Change management processes must verify that any modifications respect the device's SC and usage constraints. Site procedures should complement device SC with rigorous lifecycle management to maintain overall systematic integrity.
- Using devices without adequate SC for the required SIL, e.g., a SIL2 function with an SC1 device, which fails to meet systematic integrity requirements even if hardware reliability looks acceptable.
- Ignoring or violating safety manual instructions and constraints, such as upgrading firmware outside the assessed range or disabling diagnostics, which invalidates the SC claim per IEC 61508.
- Treating SC as a property of the function or system instead of individual elements, leading to overstated systematic integrity when one device in a SIF has lower SC than required.
How does Systematic Capability differ from SIL and PFD/PFH?
SIL is a target risk reduction level for a safety function, quantified by PFDavg or PFH for random hardware failures. Systematic Capability (SC) is a separate confidence measure that the device's systematic safety integrity meets SIL requirements. Both are required for compliance; SC addresses design and software errors, not hardware failure rates.
How is SC established for a device?
SC is established through audit of product documentation (specifications, FMEA, test records) and the manufacturer's Functional Safety Management system. The outcome is a certificate stating SIL and SC level (SC1–SC4) for specific safety functions. Manufacturers may also use proven-in-use justifications with field data.
What happens to SC if we change firmware or configuration outside the safety manual's scope?
Per IEC 61508, the SC claim applies only when the device is used per the safety manual's instructions and constraints. Changing firmware, disabling diagnostics, or operating outside specified limits invalidates the SC claim partially or wholly. The device must be re-evaluated via new functional safety assessment or proven-in-use justification.