Two Engineers Collaborate On SCADA Screens
23 Sep 2026

It’s About the Safety Function – Not the Device

I regularly encounter systems where the demand mode has been assumed – not analysed.

Sometimes a system is labelled “low demand” because the hazardous event feels rare. In other cases, it is called “high demand” simply because the device operates continuously. And occasionally, the topic is not explored at all – as though demand mode were an inherent property of the product.

IEC 61508 is clear, but it requires discipline: demand mode is not about how often equipment runs. It is about how often the safety function must act to prevent harm.

That distinction drives how integrity is calculated, how safety integrity level (SIL) compliance is demonstrated, and how robust your justification will be under scrutiny.

What the Standard Actually Requires

IEC 61508 distinguishes between low demand and high demand or continuous modes of operation based on how frequently the safety function is required to act.

  • Low demand mode: the safety function is demanded no more than once per year (≤ 1 demand/year).
  • High demand mode: the safety function is demanded more than once per year (> 1 demand/year).
  • Continuous mode: the safety function retains the EUC in a safe state as part of normal operation, rather than acting only in response to discrete demands.

For low demand mode, integrity is expressed as the average Probability of Failure on Demand (PFDavg).

For high-demand or continuous mode, integrity is expressed as the average frequency of a dangerous failure per hour (PFH).

This distinction matters because:

  • The probabilistic target and equations change.
  • The hardware integrity verification approach changes.
  • The way the safety function is specified and justified changes.

But it all starts with one fundamental question: How frequently is this safety function genuinely expected to be required to perform its safety action?

It Is About the Safety Function – Not the Device

A system may operate continuously. A sensor may monitor 24/7. A controller may execute logic thousands of times per second. None of that defines demand mode.

Consider a smoke detection system. It monitors continuously, but the safety function – issuing a fire signal – is only demanded when a fire occurs. If the expected frequency of fire is below one per year, the safety function is low demand, even though the equipment never stops running.

In assessments, this confusion between operational activity and safety demand appears more often than it should.

When the Same Product Falls into Two Categories

Demand mode is not a product characteristic. It is application specific.

Take a gas detection shutdown system. Its technical function does not change between installations: detect gas above a threshold and initiate a safe state.

In one facility, historical data may show threshold exceedance once every five years. That places the safety function comfortably in low demand mode.

Install the same hardware in a harsher process where gas spikes occur monthly, and the classification shifts. The safety function is now demanded multiple times per year. The integrity metric moves from PFDavg to PFH.

Nothing about the hardware changed. Only the demand frequency assumption changed. That single shift alters how SIL verification is performed and how the claim must be justified.

Why This Distinction Matters

Misclassifying demand mode is not just a theoretical issue. It affects proof test strategies, modelling

assumptions, and ultimately whether your SIL claim stands up during independent review.

One of the first questions raised in formal assessments is simple: What evidence supports your demand frequency assumption?

If the answer is based on habit or sector convention rather than data and risk analysis, the justification is already weak.

IEC 61508 does not assign demand modes by industry. It requires engineers to derive them from hazard analysis and realistic operating assumptions. And if those assumptions change, the demand classification may need to change with them.

The Broader Engineering Lesson

IEC 61508 does not classify demand mode by industry sector. It does not declare that process systems are inherently low demand or that machinery systems are inherently high demand. It requires engineers to examine how often the safety function will be required to act in the specific application under consideration.

It reinforces a wider truth in functional safety: safety integrity is derived from risk and context, not assigned based on product type or tradition.

Demand mode is one of the clearest illustrations of this.

Final Reflection

Demand modes appear simple – a threshold of one demand per year. Yet beneath that simplicity lies one of the most important engineering judgements in functional safety.

  • It is not about how often a device runs.
  • It is not about how often a system cycles.
  • It is about how often the safety function must intervene to prevent a hazardous consequence.

And because that frequency depends on application, environment, and operating assumptions, the same product can legitimately exist in both high and low demand classifications.

In functional safety, assumptions shape models. Models shape integrity claims. And integrity claims shape real-world safety.

James Lynskey headshot
James Lynskey

Senior Consultant, Functional Safety

James (Jay) has more than 15 years of expertise in functional safety within the Testing, Inspection and Certification (TIC) industry. He has led and delivered more than 350 global projects, providing strategic and technical solutions across industrial systems, machinery, automotive, energy storage, and battery management systems. His focus is providing guidance to customers in the areas of safety, compliance, quality assurance, functional safety management, and product lifecycle implementation. His diverse background includes supporting customers with the realization of safety related applications across a number of industries, applying international standards such as IEC 61508, IEC 61511, IEC 62061, ISO 13849, ISO 26262, and more.

You may be interested in...

IEC 61508: The Functional Safety Standard

IEC 61508 is an international standard that provides a framework for ensuring the functional safety of systems that depend on electrical, electronic, or programmable electronic (E/E/PE) technologies.

Functional Safety Testing & Certification

From early design stages through to production, our modular FS solutions provide flexible options for manufacturers, and our FS Mark provides stakeholders with visibility for products they purchase, install, or utilize in operations.

You may be interested in...