INTRODUCTION
Most machinery relies both on physical safety measures and on control system functions to ensure that it provides the safety features required to maintain the safety of the operator and others.
Examples of physical safety measures are guards and warning notices; examples of safety related control system functions are emergency stops and guard interlocks.
Machinery which has safety related control functions must operate in a way which ensures that the equipment functions in a safe manner under normal operating conditions and in the event of certain faults. The ability of the machine to correctly deliver these safety related functions is known as ‘functional safety’.
Control systems may be susceptible to failure as a result of component failure, poor system design or electrical interference. Where such failures could cause a dangerous situation to occur, the equipment must be adequately specified, designed and constructed to ensure an adequate level of safety is maintained.
SAFETY RELATED CONTROLS
Almost all machines require a control unit, commonly referred to as the 'control system', for starting, stopping and operating. The complexity of the control system reflects the features of the machine. Although control systems are commonly based on electrical or electronic technology, they can also rely on other technologies such as hydraulic or mechanical elements.
Control systems can be as simple as an electrical switch that connects a drive motor to an electrical supply or as sophisticated system designed to automatically control large, highly complex machines.
Control systems, in addition to operational functions, can be utilised to provide risk reducing protective measures for the safeguarding of personnel. Control functions which help to protect personnel are called 'Safety Related Control Functions' (SRCFs).
The key issue with SRCFs is the need to ensure they are sufficiently reliable that they will provide the safety function required when called on to do so. The level of reliability is called the 'Safety Integrity Level' (SIL) or 'Performance Level' (PL).
Note that the term SRCF is derived from EN ISO 12100: 2010 – Safety of machinery – General principles for design – Risk Assessment and risk reduction
STANDARDS
For machinery, there are two key standards. EN IEC 62061 - Safety of machinery. Functional safety of safety-related control systems and EN ISO 13849 - Safety of machinery - Safety-related parts of control systems.
The former specifies the requirements and makes recommendations for the design, integration and validation of safety-related control systems (SCS) for machines. The latter specifies a methodology and provides related requirements, recommendations and guidance for the design and integration of safety-related parts of control systems (SRP/CS).
Both standards specify a methodology and provide guidance for the design and implementation of safety-related control systems of machinery. They are both Type B standards and are Harmonised under the Machinery Directive. They can both be used to address the Essential health and Safety Requirement (EHSR) 1.2.1 of the machinery Directive.
EN ISO 13849 has two parts:
Part 1: General principles for design (EN ISO 13849-1:2023) – This part of EN ISO 13849 gives guidance to those involved in the design and assessment of control systems.
Part 2: Validation (EN ISO 13849-2:2012) - This part of EN ISO 13849 specifies the validation process for the safety functions, categories and performance levels for the safety-related parts of control systems.
However, as the current EN ISO 13849-1: 2023 now includes validation requirements in Clause 10, the future ISO 13849-2 will likely become a guidance document and, if so, will no longer be a Harmonised Standard under the Machinery Directive.
Both EN ISO 13849 and EN IEC 62061 reference the main functional safety standard aimed at electrical equipment, i.e. the EN IEC 61508 series. This lays down functional safety requirements of electrical/electronic/programmable electronic (E/E/PE) safety-related systems. There are then a number of other standards which deal with specific applications such as the EN 61511 series for process control, IEC 61513 for nuclear applications, the ISO 19014 series for earth moving machinery and the ISO 26262 series for road vehicles.
All these standards provide guidance on how to select the level of reliability required, based on the severity of injury which would result from failure of the control system, the frequency of exposure to the hazard and the possibility that the hazard can be avoided by other means. The standards also contain requirements which ensure that the desired level of reliability is achieved.
BASIC TERMINOLOGY
1. Safety Function: this is the action, process or operation of removing or reducing the risk from a given hazard. An example is the stopping of machine when a person enters a hazardous area to reduce the risk of entanglement, e.g. the breaking of a light curtain beam of a light which signals the power to be cut from a machine’s motor, thereby halting the dangerous movement. Safety functions may include emergency stop, guard interlock functions, personnel detection, limitation of speed or range, and many others.
2. Safety-Related Part of a Control System (SRP/CS) is that part of the control system which delivers the safety function. The part responds to safety-related input signals from parts of machine, operators, external control equipment or any combination of these and generates safety-related output signals which make the machine behave in the intended manner. It is important to note that the safety related parts are the hardware (and software) which delivers the safety function so they include emergency stop actuators, light curtains, safety relays and PLCs, contactors etc. Any given SRP/CS may be essential to the delivery of one or more safety function.
3. Performance Level: this specifies the ability, the reliability and the safety integrity of safety-related parts of control systems to perform a safety function under foreseeable conditions. There are 5 Performance Levels (a to e) defined in EN ISO 13849-1 and they each correlate to a given range of average frequency of dangerous failure per hour (PFH). PFH was previously known as the average probability of failure per hour).
THE EN ISO 13849 PROCESS
EN ISO 13849 provides a methodology for identifying the required level of performance (PLr) for any given safety function, and for determining whether the performance level achieved (PLa) by the machine control system is adequate. At its simplest, the standard shows the user how to identify the PLr and gives methods for calculating the PLa. So long as the PLa is greater than or equal to the PLr then the design is adequate; if the PLa is less than the PLr then additional measures will be required.
The standard addresses this with the following procedure:
1. A risk assessment is performed to determine the required safety functions.
2. The safety functions are analysed in terms of the level of protection they are required to provide and how often they are likely to be needed to determine the performance level requirement (PLr).
3. A specification – the safety requirements specification - is developed that details the required functionality and performance level of each safety function. It's especially important to ensure that the specification carefully defines the requirements for any software which will be required.
4. A preliminary design for the control system is developed and the components which deliver each safety function are identified.
5. The arrangement of the components is described in terms of a block diagram which identifies the inputs, logic and outputs.
6. Using the guidance and rules in the standard, the performance level of the proposed design (PLa) is determined.
7. Compare PLa with PLr and if the PLa is too low, revise the design to give higher reliability.
8. Document the steps and the design, including collecting the required component information and ensuring it is stored securely.
9. Validate all aspects of the process to confirm the requirements of the standard have been met.
THE EN IEC 62061 PROCESS
The standard follows a similar process, but invokes Safety Integrity Levels (SILs) rather the Performance Levels (PLs).
1. A risk assessment is performed to determine the required safety functions.
2. Each safety function is subject to a Safety Requirement Specification (SRS).
3. The required safety integrity is determined.
4. The required safety integrity, for each safety function, must be greater than or equal to the determined safety integrity.
5. The design of the SCS to perform a safety function is considered. The use of pre-designed subsystems(s) may be used.
6. The subsystems are combined and their system integrity is addressed.
7. Document the steps and the design, including collecting the required subsystem element (e.g. component) information and ensuring it is stored securely.
8. Validate all aspects of the process to confirm the requirements of the standard have been met.
PARTICULAR REQUIREMENTS FOR SOFTWARE
EN ISO 13849-1 distinguishes two types of software utilised in a SRP/CS: safety-related embedded software (SRESW) and safety-related application software (SRASW):
1. SRESW – this is proprietary software developed under the manufacturer’s management processes and provides the framework for the user configuration of application software.
2. SRASW – this is software or configuration –logic, calculations, sequences, etc. - that is specifically written for a particular SRP/CS.
EN IEC 62061 mandates the use of application software that is running on a pre-designed platform.
It introduces the concept of three software levels (SW1, SW2 and SW3). SW level 1 is limited to a maximum SIL 3 but is restricted to a limited variability language (LVL). SW level 2 permits a full variability language (FVL) in accordance with the standard, but is restricted to only SIL 2. SW level 3 can achieve SIL 3 and is limited to a limited variability language (LVL). SW level 3 permits a full variability language FVL, and can achieve SIL 3, but must be according to EN 61508-3.
Hence embedded software (SRESW) is usually written in FVL, an example of which is C++. Application software (SRASW) is usually written in LVL, an example of which is ladder logic.
CONCLUSION
EN ISO 13849 and EN IEC 62061 are complex standards and many consider them to be a 'sledgehammer to crack a nut'. It is arguably overkill to have to apply the whole procedure for simple machinery with only basic safety functions such as an on/off control and a single emergency stop button. There is also a strong case for saying that 90% of the benefit of the standard can be gained simply from the initial identification of safety functions and the components that deliver them, and the additional 10% of the benefit which comes from calculating the PFH takes 90% of the effort. Overall, it is difficult to show that the focus on control system reliability has actually had an impact on accident statistics.
Nevertheless, safety related controls are now integral to the design of most machinery, from simple domestic appliances such as washing machines through to extensive robotic production lines. Unless the designers understand and apply the principles of functional safety it is far from certain that such systems will provide an adequate and reliable level of safety. Clearly, a way of defining and measuring the reliability of controls is required so it can be shown that the legal requirements of the Machinery Directive (and other requirements) have been met.
Standards for general machine safety first started appearing 50+ years ago and by comparison, functional safety standards are still relatively new. Even so, the standards writers struggle to keep up with the speed with which advances in electronics come along, and users' expectations of the functionality of devices develops. Contact us at Conformance if you need help to get to grips with these complex requirements.
