Professional Documents
Culture Documents
P1
and severity Se and duration Fr hazardous event Pr Av 3-4 5-7 8 - 10 11 - 13 14 - 15 S1 = Slight (normally reversible injury) F1 achieved by the structural related system, with the aim
required SIL
Death, losing an eye 4 1 hour 5 Very high 5 SIL 2 SIL 2 SIL 2 SIL 3 SIL 3 S2 = Serious (normally irreversible injury including death) P2 arrangement of the parts, of allowing the system to be
or arm
S1
P1 b fault detection and/or by restored if necessary to as
Permanent, 3 > 1 h 1 day 5 Likely 4 OM SIL 1 SIL 2 SIL 3 F Frequency and/or exposure to a hazard F2 their reliability. new status or to a status
losing fingers F1 = Seldom to less often and/or the exposure time is short P1
P2
c CCF which is as close as possible
Reversible, 2 > 1 day 2 weeks 4 Possible 3 Impossible 5 OM SIL 1 SIL 2 F2 = Frequent to continuous and/or the exposure time is long F1 Failure due to a common to this status under the given
Starting point P2
medical attention
for evaluation S2
P1 d cause practical constraints.
Reversible, first aid 1 > 2 weeks 1year 3 Rarely 2 Possible 3 OM SIL 1 P Possibilities of avoiding the hazard or limiting the harm Residual risk
of safety F2
> 1 year 2 Negligible 1 Likely 1
OM = other measures required
P1 = Possible under specific conditions
P2 = Scarcely possible
functions P2 e Demand rate rd
Frequency of demands per
Risk remaining after
protective measures have
contribution to risk
High contribution to risk reduction time unit for a safety related been taken.
reduction
action of an SRP/CS. Risk
Diagnostic coverage (DC) Combination of the probabil-
Measure for the effectivity of ity of occurrence of harm and
diagnostics, may be deter- the severity of that harm.
mined as a ratio between Risk analysis
the failure rate of detected Combination of the speci-
dangerous failures and the fication of the limits of the
failure rate of total dangerous machine, hazard identification
failures. and risk estimation.
DCavg Risk assessment
Average diagnostic coverage The overall process
Diagnostic test interval comprising risk analysis and
Estimation of CCF factor Determination of common cause failures Assessment of CCF influence risk evaluation.
Time period between online
tests carried out in order Risk evaluation
Overall score Common SIL points Requirement PL points Evaluation CCF
to detect faults in a safety Judgement, on the basis of
cause failure factor 25 Physical separation of safety circuits and other circuits 15 % Compliance > 65 %
related system with the risk analysis, of whether risk
(beta) 38 Diversity (use of diverse technologies) 20 % Noncompliance < 65 %
specified degree of diagnostic reduction objectives have
< 35 10 % (0,1) 2 Design/application/experience 20 %
coverage. been achieved.
35 65 5 % (0,05) 18 Assessment/analysis 5%
Diversity
66 85 2 % (0,02) 4 Competence/training 5%
Use of diverse means to Safety function
86 100 1 % (0,01) 18 Environmental influences (EMC, temperature, ...) 35 %
execute a required function. Function of the machine
whose failure can result in
Electrical/electronic/ an immediate increase of the
programmable electronic risk(s).
Architectural constraints on subsystems Determination of the MTTFd per channel Relationship between the categories (E/E/PE) Safety integrity
Safe failure Hardware Hardware Hardware 1 N 1 nj DC, MTTFd and PL Based on electrical (E) and/or Probability of a SRECS or its
= = electronic (E) and/or program- subsystem satisfactorily per-
fraction (SFF) fault tolerance fault tolerance fault tolerance MTTFd i=1 MTTFd,i j=1 MTTFd,j PFH/h-1 mable electronic (PE) forming the required safety-
SD + SU + DD S + DD 0 1 2 10-4
Performance Level technology. related control functions
SFF = = < 60 % not permitted SIL 1 SIL 2 The following applies to diverse systems: a
under all stated conditions.
SD + SU + DD + DU Dtotal 60 % < 90 % SIL 1 SIL 2 SIL 3 10-5
Failure Safety integrity level (SIL)
Realisation of the safety function determination of the achieved SIL
PNOZ X3
23 33 41
per hour can result in an immediate
DD
570002 X4
CI+
CI -
CO -
CO+
T0
T1
T2
T3
O0
O1
O2
O3
OA0
24V
24V
0V
0V
IEC/EN 60947-5-1
14
23
24
O4
O5
Ui 250V IP67
24V AC/DC
110 230V AC 13 23 33 41
1
2
AC15 230V/2.5A
contact rating
B300 R300 1
2
POWER
3
4 3
4
CH. 1
03000000 03000000
POWER
FAULT
DIAG
DU
RUN
I10
I11
I12
I13
I14
I15
I16
I17
I18
I19
14 24 34 42
A1
A1
A2
A2
I8
I9
Made in Germany
www.pilz.com
PSENme 1S/1AS
570002 X4
IEC/EN 60947-5-1
Ui 250V IP67
24V AC/DC
14 24 34 42 B2 A2
110 230V AC
X4 X5 X6 X7
SD
Y31 Y32 S21 S22 S33 S34
which reacts to safety related
Made in Germany
www.pilz.com
Safe detected failure input signals and generates
SU
PSENme 1S/1AS
570002 X4
Made in Germany
www.pilz.com
PSENme 1S/1AS
570002 X4
PNOZ s2 Made in Germany
www.pilz.com
IEC/EN 60947-5-1 PSENme 1S/1AS
PSENme 1S/1AS
Ui 250V IP67 570002 X4
A1 B1 13 23 33 41
570002 X4 24V AC/DC IEC/EN 60947-5-1
IEC/EN 60947-5-1 110 230V AC Ui 250V IP67
Ui 250V IP67 AC15 230V/2.5A 24V AC/DC
PNOZ X3 Power
13 23 33 41 In1 mode
POWER In2
CH. 1
Out
Reset
Fault
dangerous failures an SRP/CS; reciprocal value
CH. 2
14 24 34 42
750103
000002 0.1
- Mean value for the operat- of the diagnostic test interval
ing time during which a Ti
Made in Germany
www.pilz.com
PSENme 1S/1AS
570002 X4
IEC/EN 60947-5-1
Ui 250V IP67
24V AC/DC
14 24 34 42 B2 A2
110 230V AC
AC15 230V/2.5A
contact rating
A2 14 24
B300 R300
IEC/EN 60947-5-1
Ui 250V IP67
X4
Made in Germany
www.pilz.com
PSENme 1S/1AS
570002 X4
is expected to not have a odic tests on a safety system
570002 X4
dangerous failure.
24V AC/DC IEC/EN 60947-5-1
IEC/EN 60947-5-1 110 230V AC Ui 250V IP67
Ui 250V IP67 AC15 230V/2.5A 24V AC/DC
24V AC/DC contact rating 110 230V AC
110 230V AC B300 R300 AC15 230V/2.5A
AC15 230V/2.5A contact rating
contact rating B300 R300
B300 R300
MTTR Validation
Average length of time taken Confirmation by examination
for the safety system to be (e.g. tests, analysis) that the
restored, measured from the SRECS meets the functional
time of failure occurrence to safety requirements of the
the completion of repairs. specific application.
Verification
PAScal Confirmation by examination
Calculation software for veri- (e.g. tests, analysis) that the
fying functional safety SRECS, its subsystems or
Performance level (PL) subsystem elements meet
Discrete level which specifies the requirements set by the
Achieved SIL >= SIL
Verification