Glossary · Functional safety
Functional safety
German: Funktionale Sicherheit
In functional safety engineering, functional safety is the part of overall safety that depends on the correct functioning of safety-related control systems. It covers the risk reduction that control functions provide, not guards, inherently safe design or information for use.
- Functional safety
- Systems engineering
In one sentence
Functional safety covers the share of machine and process safety that relies on safety-related control systems working correctly.
Example
On a press, the fixed guards and warning labels are not functional safety, but the light curtain, its evaluation unit and the stop of the ram that follows an interruption are.
How it applies
- Standards: IEC 61508 is the basic standard. For machinery, ISO 13849-1 (Performance Level) and IEC 62061 (SIL) apply its ideas to control systems.
- Machine safety: Functional safety is one of several means of risk reduction. It comes into play when inherently safe design is not enough and a safety function takes over.
- Technical documentation: Document the safety functions, their required and achieved levels, the architecture and the validation results. The user information must describe tests, response times and restrictions that the safety functions depend on.
- AI and retrieval: Machine learning components are not addressed by the classic requirements of these standards. Claims that an AI component contributes to functional safety need a separate, cautious justification.
Functional safety in machinery: ISO 13849-1, PLr and SISTEMA
In machine building, functional safety is mostly handled under EN ISO 13849-1, Safety of machinery — Safety-related parts of control systems. The standard sets the requirements for the design and integration of safety-related parts of control systems (SRP/CS), both internationally and, as a harmonized standard, in Europe.
Required Performance Level (PLr). The PLr is the target a safety function (SF) must reach to reduce the existing risk of a machine sufficiently. It is determined during the risk assessment under ISO 12100, typically with the risk graph of ISO 13849-1. The scale runs from PL a (low risk reduction) to PL e (highest risk reduction). The risk graph parameters are:
| Parameter | Meaning | Levels |
|---|---|---|
| S – severity | Severity of injury | S1 = slight, normally reversible; S2 = serious, normally irreversible, or death |
| F – frequency | Frequency and/or duration of exposure to the hazard | F1 = seldom to less often and/or short; F2 = frequent to continuous and/or long |
| P – possibility | Possibility of avoiding the hazard or limiting the harm | P1 = possible under specific conditions; P2 = scarcely possible |
The 2023 edition also lets the probability of occurrence of the hazardous event enter the choice of P, so the justification of each parameter belongs in the risk assessment record.
SISTEMA. To prove by calculation that the selected components and control architecture actually meet the PLr, designers in Europe almost always use SISTEMA (Safety Integrity Software Tool for the Evaluation of Machine Applications), a free tool from the IFA, the Institute for Occupational Safety and Health of the German Social Accident Insurance. Designers rebuild each safety function virtually and load the manufacturers' component libraries (in the format of VDMA Specification 66413). SISTEMA then calculates the probability of a dangerous failure per hour (PFHd), the mean time to dangerous failure (MTTFd) and the average diagnostic coverage (DCavg), and checks that the achieved PL is at least the required PLr. Commercial and vendor tools offer comparable calculations; the requirements come from the standard, not from the tool.
Safety functions (SF): SPS, SSPS, SS0 and SS1
Safety function lists and SISTEMA projects abbreviate safety functions as SF and number them (SF1, SF2, …), each with its own PLr and achieved PL. In German-speaking projects, a safety function on a machine with drives usually touches two controllers and a physical stop at the drive:
- SSPS (Sicherheits-SPS) – the safety PLC. It evaluates the safety sensors and executes the safety logic. This is the controller credited with the risk reduction.
- SPS (speicherprogrammierbare Steuerung) – the standard programmable logic controller (PLC) that runs normal operation. It receives the safety status, brings the process into a defined condition and shows messages, but it is not credited with risk reduction unless it meets the requirements of the standard.
- SS1 (Safe Stop 1) – the physical, drive-level counterpart of a stop category 1 stop: controlled, monitored braking followed by torque removal (SS1 under IEC 61800-5-2).
- SS0 (Safe Stop 0) – a manufacturer term for the immediate removal of torque, the drive-level counterpart of a stop category 0 stop. IEC 61800-5-2 itself calls this function Safe Torque Off (STO); SS0 is not a separate function in the standard.
Example: “SF2: guard door opens → SSPS detects the open door → SS1 of the spindle drive, STO after standstill → SPS stops the process and shows the message ‘Guard door open’.” Documentation should name the SF number, the controllers involved and the drive stop function, so that the safety function list, the SISTEMA project and the operating manual describe the same thing.
Functional safety vs. machine safety
Machine safety is the overall goal and includes guards, design, signs and training. Functional safety is the part achieved by control functions performing correctly, including their reaction to faults.