AASIFWorked example · read-only
STEP 4 OF 7

Classify your Safety Integrity Level

For each hazard, answer how bad, how often and how correctable. AASIF derives its AI-SIL, and the highest one becomes your flow's Safety Integrity Level.

  1. 1Answer the fact questions for each hazard
  2. 2Confirm or change each proposal; every proposal shows its rule and reason
  3. 3Confirm each hazard with 'Confirm my rating · next hazard'
AI-SIL 3 Your flow: AI-SIL 3 · Safety Integrity Level 3Go to measures
14 of 14 hazards confirmed

Wrong decision or action from incorrect output (hallucination, misreasoning)

Could the agent act on a wrong fact or a wrong conclusion?

If this goes wrong, what is the worst credible harm to your organization?

Think of the credible worst case, not the typical case. Foreseeable harm counts even if it has not happened yet.

What is the worst credible harm to people outside the organization or to employees?

Include customers, applicants, citizens, patients, suppliers' staff and employees.

  • at least S2Step 'Pays supplier invoice' moves money and its maximum size is material (A08): at least S2 for the organization or for the affected persons (R-S-FLOOR).
  • suggested S2The agent decides about, or informs decisions about, suppliers: consider at least S2 for them (73% of such hazards in the 60 cases were rated S2 or higher).
How often does the situation occur in which this could go wrong?

Count each decision in a batch separately. For a detector, count how often a real threat passes by.

  • proposal E4not confirmed yetStep 'Matches invoice to purchase order' runs many times per day; for 'Wrong output' the hazard situation usually occurs about as often as that (E4).
If it happens, can the harm be corrected before it really hurts?

This is about the harm, not the action. An email can be 'undone' by a correction, but a wrong promise in it may already bind you.

  • proposal C2not confirmed yetStarting point: in the 60 reference cases the harm of 'Wrong output' could typically be corrected only with effort or delay (C2). Confirm it for your case.
AI-SIL for this hazardAI-SIL 2

S2 + E4 + C2 − 6 = AI-SIL 2

  • S: proposal S2 (RH14) → your value S1 · down

This hazard: AI-SIL 2 → 2 · Flow: 3 → 3 · 0 measures change grade

Back

Classification is deterministic — AI only adapts wording and suggests, you confirm.