Glossary · Functional safety
Average probability of dangerous failure on demand (PFDavg)
Also known as: PFDavg, PFD avg, PFD, Average probability of failure on demand
German: Mittlere Wahrscheinlichkeit eines gefahrbringenden Ausfalls bei Anforderung (PFDavg)
In functional safety under IEC 61508 and IEC 61511, the average probability of dangerous failure on demand (PFDavg) is the mean unavailability of a safety-related system to perform its safety function when a demand occurs; it is the failure measure used to specify and verify the SIL of low-demand safety functions.
- Functional safety
- Verification
In one sentence
PFDavg is the average probability that a low-demand safety function fails when needed; it is the number behind the SIL in low-demand mode.
Example
A single shutdown valve with a dangerous undetected failure rate of 2 × 10^-6 per hour and a yearly proof test has a PFDavg of about 2 × 10^-6 × 8,760 / 2 ≈ 8.8 × 10^-3, which lies in the SIL 2 band.
How it applies
- SIL bands: For low-demand functions, IEC 61508 assigns SIL 1 to a PFDavg from 10^-2 to below 10^-1, SIL 2 from 10^-3 to below 10^-2, SIL 3 from 10^-4 to below 10^-3 and SIL 4 from 10^-5 to below 10^-4. The inverse, 1/PFDavg, is the risk reduction factor.
- Calculation: For a single channel, a common simplified approximation is PFDavg ≈ λDU × T1 / 2, with λDU the rate of dangerous undetected failures and T1 the Proof-test interval. Redundant architectures, diagnostics, Common-cause failure (CCF), imperfect proof tests and repair times change the result; IEC 61508-6 gives formulas for common architectures, and reliability block diagrams, fault trees or Markov models are used for others.
- Operation: PFDavg is not a fixed property of the hardware. It holds only if proof tests are performed at the assumed interval and with the assumed coverage. Extending the proof test interval without recalculating it undermines the SIL claim.
- Documentation: Keep the calculation with the SIL verification: failure data and their sources, architecture, proof test interval and coverage, mission time and the assumptions for common-cause failures. Operating and maintenance documentation must carry the proof test interval and procedure the calculation relies on.
PFDavg vs. PFH
PFDavg is a dimensionless probability for functions that are rarely demanded (low-demand mode). PFH is a frequency per hour for functions demanded often or continuously (high-demand and continuous mode). They are not convertible into each other; the Demand mode decides which one applies.