Safety Integrity Level
A Safety Integrity Level (SIL) is a discrete level that specifies the required effectiveness of safety functions in reducing risk within safety-related systems.
“The level of risk reduction provided by a safety function, related to the frequency and severity of perceived hazards.”
(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)
View the complete ISTQB GlossaryWhat is Safety Integrity Level?
SIL classifications define the rigor of design, development, verification, and testing needed to achieve acceptable levels of functional safety.
Risk reduction: Higher SILs require stronger safety measures.
Standards based: Commonly defined by IEC 61508 and related standards.
Testing impact: Higher SILs require more rigorous verification and validation.
Real World Example
A team building software for an industrial robotic arm's emergency-stop function is told the feature needs "a high safety integrity level," and initially just adds one basic stop button, treating safety as a binary yes/no feature.
Not every safety function needs the same rigor — a robotic arm operating near workers with a hazard that could cause severe injury at high frequency needs a much higher level of risk reduction than a rarely triggered, low-severity warning light, and treating Safety integrity level as one-size-fits-all under-verifies the genuinely high-risk function.
The tester works with safety engineers to determine the actual required Safety integrity level based on the hazard's severity and frequency, then designs verification rigor to match: redundant testing of the stop mechanism under multiple simulated fault conditions, not just a single "does the button work" check.
The rigorous, Safety integrity level-appropriate testing catches a fault condition where the emergency stop fails to engage if two specific sensors fail simultaneously — a scenario only tested because the required level demanded that rigor, one a simple button-press check would never have exercised.
Practice Questions
Question 1
A team is told an emergency-stop function needs "a high safety integrity level" but treats safety as a single pass/fail feature and tests only "does the button work." What has the team misunderstood?
Question 2
Why would a robotic arm's emergency-stop function require a higher safety integrity level than a rarely triggered, low-severity warning light in the same system?
Test your knowledge with real ISTQB-style questions
You’ve learned Safety Integrity Level. Test your understanding with topic-specific questions in our Mock Exams.