Ensuring Functional Safety of Machines: Calculation of SIL and PL Levels according to IEC 62061 and ISO 13849

Technical analysis: Machine safety: SIL and PL rating calculation according to IEC 62061 and ISO 13849

Ensuring Functional Safety of Machines: Calculation of SIL and PL Levels according to IEC 62061 and ISO 13849

Introduction: Engineering Challenge and Criticality of Equipment Reliability

Ensuring the functional safety of machines is a fundamental requirement in modern industrial production. In addition to causing personal injury and property damage, workplace accidents also lead to downtime, lost productivity and reputational risks. The engineering challenge is to systematically identify hazards, assess risks, and design, implement, and verify control systems that reduce these risks to an acceptable level. This methodology is critical for maintaining uninterrupted and safe operation of production complexes, especially in conditions of intensive operation of Ukrainian industrial enterprises. Compliance with international and national standards, such as DSTU EN ISO 12100 and DSTU EN ISO 13849, provides a systematic approach to this task.

Fundamental Principles: Physics and Theory of Security

Functional safety is defined as the part of overall safety that depends on the correct functioning of a control system that responds to input signals and places equipment in a safe state or maintains it in such a state. Functional safety is based on the following principles:

  • Safety by Design principle:Hazards are eliminated or risks are reduced at the design stage of the machine, not by adding external protective devices.
  • Principle of failure minimization: The components and architecture of security systems must be designed in such a way as to reduce the probability of dangerous failures.
  • Diagnostic Coverage Principle: Security systems must be able to detect and report their own internal failures.
  • Principle of redundancy: Duplication of critical functions to increase reliability. For example, using two independent limit switches instead of one.

The risk assessment process according to DSTU EN ISO 12100 is the basis for determining the required level of security. It includes hazard identification, risk assessment (severity of injury, frequency of exposure, avoidability) and risk reduction decisions. A risk graph or risk matrix is ​​often used for this. The result of this assessment is a target Performance Level (PL) or Safety Integrity Level (SIL).

Technical Specifications and Standards: IEC 62061 and ISO 13849

Two main standards are used to quantify functional safety in industry:

  • IEC 62061 (DSTU EN 62061:2018): "Machine safety. Functional Safety of Safety-Related Electrical, Electronic and Programmable Electronic Control Systems'. This standard is based on the concept of SIL (Safety Integrity Level) and is mainly used for complex electrical, electronic and programmable electronic safety systems (E/E/PES). SIL defines the safety failure probability on demand (PFDAVG) or dangerous failure rate per hour (PFH) for continuous operation. There are 4 SIL levels, from SIL 1 (lowest) to SIL 4 (highest), where for example for SIL 3, the PFDAVG ranges from 10-4 to 10-3.
  • ISO 13849 (DSTU EN ISO 13849-1:2018): "Machine safety. Safety-related parts of control systems. Part 1: General principles of design". This standard is based on the PL (Performance Level) concept and applies to all types of technology, including electrical, mechanical, pneumatic and hydraulic components. PL determines the probability of dangerous failure per hour. There are 5 PL levels, from PL "a" (lowest) to PL "e" (highest). For example, for PL "e", PFHD < 10-7 failures per hour.

The choice of standard depends on the type of technologies used in the security management system. For electrical systems with programmable logic controllers (PLCs), IEC 62061 is often used, while for simpler systems or systems with different technologies, ISO 13849 is more versatile.

Evaluation and Classification Criteria:

  • Architecture (Category): ISO 13849 defines 5 categories (B, 1, 2, 3, 4) that characterize the architecture of the system and its ability to withstand failures. For example, Category 4 requires redundancy and diagnostics, which ensure that the safety function is preserved even in the event of a single failure.
  • Mean Time to Fatal Failure (MTTFd): The average time a component operates before it fails fatally. Measured in years or cycles.
  • Diagnostic coverage (DCavg): A measure of the efficiency of system diagnostics that detects dangerous failures. It is defined as the ratio of detected dangerous failures to the total number of dangerous failures (0% - no diagnosis, 99% - high diagnosis).
  • Common Cause Failures (CCF): Failures that can simultaneously affect multiple security channels due to a single cause (eg dust, moisture, vibration). A variety of components, physical separation, and protection from the environment are used to reduce CCF.

Selection and Calculation Guide: SIL and PL

Determining the required SIL or PL begins with a thorough risk assessment. Below is a simplified example of a risk matrix for determining the target PL according to ISO 13849-1:

Risk Matrix (Simplified for PL according to ISO 13849-1)

Parameter Value 1 Value 2 Value 3 Target PL
S (Injury Severity) S1: Mild (irreversible) S2: Severe (death, amputation) Determined by the combination
F (Frequency/Duration of Effect) F1: Rare/Short F2: Often/Long
P (Possibility to Avoid) P1: Maybe P2: Hardly possible
Example of Combinations
S1 + F1 + P1 Negligible risk PL a
S1 + F1 + P2 Low risk PL b
S2 + F1 + P1 Medium risk PL c
S2 + F2 + P1 High risk PL d
S2 + F2 + P2 Very high risk PL e

Calculation of MTTFd and PFH for ISO 13849

To determine the achieved PL, it is necessary to calculate the MTTFd for each component (sensor, logic solver, actuator), average DCavg and estimate the CCF. Component manufacturers typically provide a value of B10d (number of cycles to 10% dangerous failure). If B10d is not available, empirical values from ISO 13849-1, Appendix C can be used.

Formula for MTTFd (for mechanical components):

MTTFd = B10d / (0.1 * n_op), where n_op is the number of operations per hour.

Example: If a component has B10d = 2,000,000 cycles and operates 10 times per hour (n_op = 10), then MTTFd = 2,000,000 / (0.1 * 10 * 8760 h/year) ≈ 228 years.

Calculation of PFH (Probability of Dangerous Failure per Hour) for IEC 62061

IEC 62061 requires a more granular approach where PFHD (for each subsystem) and PFDAVG (for on-demand operation) are calculated based on architecture, failure rate, DC and CCF. The total PFHD of the system is the sum of the PFHD of all subsystems.

Component example: Safety relay Siemens SIRIUS 3SK1 Advanced. For this relay, the manufacturer provides the following data: PFH = 2.0 x 10-9 failures/h (for SIL3), MTTFd = 100 years, DCavg = 99%.

Instructions for Installation and Commissioning

Proper installation and commissioning of security systems is as critical as their design. Failure to follow these practices can nullify all design efforts. Basic recommendations:

  • Circuit separation: Control and safety circuits must be physically separated to avoid mutual interference. Use separate cable channels and markings.
  • Grounding and shielding: Proper grounding and shielding of cables to protect against electromagnetic interference, which meets the requirements of DSTU EN 61000.
  • Documentation: Complete and up-to-date documentation, including wiring diagrams, parameter settings, test reports. This is a mandatory requirement for CE and UkrSEPRO certification.
  • Initial tests (Proof Test): After installation and before commissioning, a full functional test of the safety system must be carried out to ensure its correct operation. The frequency of these tests is set in the maintenance plan.
  • Personnel qualifications: Installation and commissioning should only be performed by certified technicians who have undergone functional safety training.

Failure Modes and Root Cause Analysis

Failure Mode Analysis (FMEA) and Root Cause Analysis (RCA) are key tools for improving the reliability of safety systems. Some common failure modes are:

  • Sensor failure: Mechanical damage, contamination, incorrect setting, wear. For example, the failure of the inductive safety sensor Siemens 3SE6310-0BC01 due to heavy contamination with metal shavings.
  • Logic solver failure: Software failure, failure of electronic components due to overvoltage or overheating. For a Siemens SIMATIC S7-1500F safety PLC, the PFH can be 1.1 x 10-9 failures/hour.
  • Actuator failure: Contactor sticking, brake malfunction, hydraulic valve leak. For example, blocking of the protective contactor due to a short circuit of the winding.
  • Communication failure: Cable damage, electromagnetic interference, communication protocol failure (eg PROFINET/PROFIsafe).

Visual indicators: Status indicators on components (LEDs), error messages on operator panels, unusual noises or vibrations. For example, a blown fuse on a Schneider Electric XPS-ATE safety relay may indicate an overload in the circuit.

Predictive Maintenance and Condition Monitoring

Implementing predictive maintenance and condition monitoring (CMS) is an effective way to increase the reliability of security systems and reduce the risks of unplanned downtime.

  • Continuous diagnostic monitoring: Use of intelligent sensors with built-in diagnostics that constantly monitor their condition and transmit data. This allows you to identify potential failures before they occur. For example, temperature, vibration or current sensors integrated into the security system.
  • Periodic testing (Proof Testing): Regular testing of a security system at a given interval (for example, once a year) to verify its ability to perform a security function. Test reports must record all checks and their results.
  • Diagnostic coverage analysis: Regular analysis of system diagnostics effectiveness. If DCavg falls below the calculated value, this indicates an increase in the probability of dangerous undetected failures.
  • Trend analysis: Monitoring indicators such as number of failures, time to failure, load on components. This allows wear to be predicted and component replacement to be planned.

The application of standards DSTU EN 60204-1 (Electrical equipment of machines) and DSTU EN 61508 (Functional safety of electrical/electronic/programmable electronic systems related to safety) is the basis for the development of effective maintenance strategies.

Comparison Matrix: Components and Architectures of Security Systems

UNITEC-D GmbH, as a reliable supplier of components for industrial automation, offers a wide range of products for the implementation of functional safety systems. Below is a comparison of typical solutions:

Characteristics Safety Relay (Single Channel) Safety Relay (Dual Channel) Safe PLC (Siemens S7-1500F) Multifunctional Protection System (for example, Sick Flexi Soft)
Target PL (ISO 13849) To PL c To PL e To PL e To PL e
Target SIL (IEC 62061) Up to SIL 1 Up to SIL 3 Up to SIL 3 Up to SIL 3
Category (ISO 13849) Category 1 Category 3/4 Category 4 Category 4
Cost (conditional) Low (50-150 EUR) Average (150-500 EUR) High (from 1500 EUR) High (from 1000 EUR)
Configuration Complexity low average High (programming) Medium/High (Graphical)
Diagnostic Coverage (DCavg) Low (< 60%) Average (60-90%) High (> 90%) High (> 90%)
Application Simple security features Average security features Complex, integrated systems Flexible, modular systems

Conclusion and Call to Action

A systematic approach to the functional safety of machines, based on a thorough risk assessment and compliance with IEC 62061 and ISO 13849 standards, is a prerequisite for the safe and efficient operation of industrial enterprises. The correct calculation and implementation of SIL and PL levels not only protects personnel, but also ensures the reliability of technological processes, minimizing downtime and costs. UNITEC-D GmbH is your reliable partner in the selection and supply of certified components for functional safety systems that meet CE and UkrSEPRO requirements.

For detailed information on security components and solutions for your production, visit our electronic catalog: www.unitecd.com/e-catalog/

List of Sources

  1. DSTU EN ISO 12100:2018 Machine safety. General design principles. Risk assessment and risk mitigation.
  2. DSTU EN ISO 13849-1:2018 Machine safety. Safety-related parts of control systems. Part 1: General design principles.
  3. DSTU EN 62061:2018 Machine safety. Functional safety of safety-related electrical, electronic and programmable electronic control systems.
  4. DSTU EN 61508 (all parts): Functional safety of safety-related electrical/electronic/programmable electronic systems.
  5. Siemens AG, Safety Integrated for Process Automation, Manual.

Related Articles