OK. let me explain more.
normally as your understanding is correct we should separate SIS and BPCS to eliminate the common failure risk. as per the statement in paragraph 11.2.10 of IEC 61511.
“A device used to perform part of a safety instrumented function shall not be used for basic process control purposes, where a
failure of that device results in a failure of the basic process control function which causes a demand on the safety
instrumented function, unless an analysis has been carried out to confirm that the overall risk is acceptable.”
It emphasizes about the analysis, right?
The analysis shall show if the sensor diagnostics can reduce the dangerous failure rate sufficiently
and the SIS is capable of placing the process in a safe state within the required time.
Anyway in Shell DEP 32.80.10.10-Gen. Section 6.7.3, it summarizes this exception as:
"Sharing of sensor elements (common transmitters) shall only be permitted when all 3 of the
following conditions exist:
• SIL 1 or 2 (not SIL 3)
• Safe and dangerous fault tolerant sensors are applied (e.g. 2oo3)
• Sensors used for control via a middle of three voting algorithm"
However, to permit this exception shall be under the consultant of experience safety people.
Hope this may help you