Introduction: The Importance of Functional Safety for Industrial Enterprises
In modern industrial production, ensuring safety is an integral part of operational activities. Functional safety, regulated by international standards IEC 61508 and IEC 62061, plays a critical role in preventing accidents, protecting personnel and preserving production assets. These standards define requirements for electrical, electronic and programmable electronic systems (E/E/PES) that perform safety functions. For Ukrainian industrial enterprises seeking integration into world markets and ensuring high standards of labor protection, understanding and observing these norms is not just a recommendation, but a mandatory condition for sustainable development.
As Chief Engineer of UNITEC-D GmbH, with more than 20 years of workshop experience and 10 years of design experience, I emphasize that effective integration of functional safety principles into maintenance, repair and operation (MRO) processes is key to minimizing risks. This includes everything from component selection to testing and documentation procedures.
Scope and Applicability of Standards
The IEC 61508 standard "Functional safety of safety-related electrical/electronic/programmable electronic systems" (current edition, for example IEC 61508-1:2010, -2:2010, -3:2010) is the basic, general standard for functional safety. It applies to all industries and covers the entire life cycle of safety systems. Its provisions are the basis for the development of industry standards.
Standard IEC 62061 "Safety of machines. Functional Safety of Safety-Related Electrical, Electronic and Programmable Electronic Control Systems' (current revision eg IEC 62061:2021) is an industry standard derived from IEC 61508 and directly applicable to machinery. It provides detailed requirements for the design and verification of machinery safety systems, including the definition of safety integrity levels (SILs).
Who must comply?
- Manufacturers of machinery and equipment: Responsible for the design and manufacture of safety management systems in accordance with SIL requirements.
- System integrators: Responsible for the correct integration of components and security systems.
- End users (enterprise operators): Responsible for the operation, maintenance, modifications and decommissioning of security systems in accordance with established requirements. This directly applies to MRO teams.
What equipment is covered by the standards?
These standards apply to any electrical, electronic or programmable electronic system that performs safety functions. It can be:
- Emergency shutdown systems (ESD).
- Blocking of protective fences.
- Control systems for pressure, temperature, liquid level.
- Sensors, controllers (safety PLC), actuators (valves, brakes) used in safety circuits.
- Fire protection and gas detection systems.
What industries?
All industries where there is a risk to people, the environment or property due to the failure of control systems. This includes chemical, oil and gas, metallurgical, food, pharmaceutical, energy, engineering and other branches of Ukrainian industry.
Key Requirements of the Standards
Functional safety is based on the concept of the safety life cycle, covering all stages from hazard analysis to system decommissioning. The main requirements include:
| Life Cycle Stage | Basic Responsibilities | Typical Timing/Frequency |
|---|---|---|
| Hazard analysis and risk assessment (EN ISO 12100:2010) | Identification of all potential hazards, risk assessment and determination of necessary safety measures. | Before designing, with significant changes, at least once every 5 years. |
| Definition of safety functions and SIL levels (IEC 61508, IEC 62061) | Determination of specific functions that must be implemented by the security system and assigning them the required level of security completeness (SIL 1-4). | At the system design stage, with each modification. |
| Design of security system hardware and software | Architecture design, component selection, SIL programming and fault tolerance. | At the development/modernization stage. |
| Security system verification and validation | Verification of compliance of project solutions with SIL requirements and confirmation that the system performs its safety functions with the required efficiency. | After installation, before commissioning, after significant modifications. |
| Operation and maintenance | Regular functional checks (proof tests), calibration, component replacement, documentation. | According to the MRO plan, for example, proof tests every 1-5 years depending on the SIL. |
| Modification management | Any changes in the security system must undergo repeated risk assessment and verification. | Before each modification. |
| Documentation | A complete set of documentation at all stages of the security life cycle. | Constantly, update as changes occur. |
Impact on MRO Operations
Implementation of functional safety standards significantly changes the approach to maintenance, repair and operation. This requires systematization of processes and improvement of staff qualifications.
Changes in maintenance procedures:
- Regular Functional Tests (Proof Tests): Instead of regular functional tests, security systems require full functional tests to detect hidden malfunctions. The frequency of these checks depends on the given SIL and system architecture, for example, for SIL 2 it can be once every 2 years, for SIL 3 - annually.
- Calibration: Sensors and actuators included in safety systems must be calibrated regularly according to established schedules to ensure their readings are accurate.
- Using certified spare parts: It is critically important to use spare parts that meet functional safety requirements and have appropriate certificates (CE, UkrSEPRO). Replacing a component with an analog without proper certification can invalidate the system's SIL.
- Competence of MRO personnel: Engineering and technical personnel involved in the maintenance of safety systems must have specialized training and proven qualifications in functional safety (eg TÜV Rheinland Functional Safety Engineer/Technician certification).
Changes in purchases:
- Requirements for suppliers: Procurement departments must require suppliers to provide complete documentation and certificates (CE, UkrSEPRO) for all components used in security systems. This includes validating SIL, MTTF (Mean Time to Safe Failure), SFF (Safe Failure Fraction) and other reliability metrics.
- Component traceability: Every component that is part of a security system must be clearly identified and traceable from the manufacturer to the time of installation.
Changes in documentation:
- Logging: Detailed documentation of all functional checks, calibrations, component replacements, modifications and malfunctions detected.
- Documentation Update: Schematics, manuals, safety manuals, and MRO plans must be continuously updated to reflect any changes in the system.
- Reporting: Regular reporting on the status of security systems, the results of audits and the implementation of corrective measures.
Requirements for Components and Spare Parts
Choosing the right components for functional safety systems is critical. Not all industrial components are suitable for use in safety circuits.
What spare parts and components require special certification?
- Safety relays and controllers (safety PLCs): Must be certified to IEC 61508/62061 and designed for a specific SIL. For example, PLC Siemens SIMATIC S7-1500F or Pilz PNOZmulti 2.
- Safety sensors: Limit switches, light barriers, pressure, temperature, flow, level sensors used to detect hazardous conditions must have proven reliability (MTTFD > 100 years for category 3/PL d according to ISO 13849-1) and appropriate certificates.
- Safety performance mechanisms: Emergency shut-off valves, brakes, contactors engaged by safety functions shall demonstrate a high safe failure rate (SFF > 90% for SIL 2/3).
- Emergency stop buttons: Must comply with EN ISO 13850 and be part of a reliably designed system.
- Cables and wiring: Although cables themselves do not have SIL, they must be properly selected, routed and protected to prevent damage that could lead to safety loop failures.
Each critical component must be accompanied by a declaration of conformity (CE) and, for the Ukrainian market, a UkrSEPRO certificate confirming its compliance with national standards and technical regulations (for example, DSTU EN 61508, DSTU EN 62061).
Compliance Checklist for MRO Managers
To ensure compliance with functional safety requirements, MRO managers should regularly check the following aspects:
- Has a hazard analysis and risk assessment been performed and updated for all systems?
- Are SIL levels defined and documented for all safety functions?
- Are proof tests procedures developed and implemented for each security system?
- Are proof tests performed according to the schedule and their results recorded?
- Are there certificates of conformity (CE, UkrSEPRO) for all components of security systems?
- Do the spare parts used for the safety systems meet the original specifications and SIL requirements?
- Are MRO personnel working with safety systems appropriately qualified and certified?
- Are there regular trainings and refresher courses for MRO functional safety teams?
- Is a complete log of service, repair and modification history maintained for each security system?
- Are all security system modifications properly risk assessed and verified prior to implementation?
- Are all technical documentation (diagrams, instructions, safety manuals) updated after any changes?
- Is a change management system in place for security systems?
- Are regular internal functional safety compliance audits conducted?
- Is there an action plan in case of detection of faults in the security system?
- Is adequate storage of critical spare parts for safety systems ensured?
- Are functional safety requirements taken into account when planning the MRO budget?
- Are functional safety requirements integrated into the company's quality management system?
- Are there clear procedures for reporting and investigating security incidents?
Common Problems Non-compliance with Requirements
Functional safety audits often reveal typical deficiencies that can jeopardize production safety:
- Inadequate risk analysis: Superficial assessment of hazards leading to incorrect determination of SIL.
- Incorrect definition of SIL: Underestimation of the required level of safety completeness for a specific function, which leads to the use of insufficiently reliable components.
- Inadequate proof tests: Insufficient frequency or depth of functional tests, which does not allow detecting hidden malfunctions before a dangerous situation occurs. For example, instead of a complete safety circuit check, only the actuation of the end element is checked.
- Using non-certified spare parts: Replacing original, certified components with cheaper counterparts without proper confirmation of their compliance with safety requirements. This can lower the overall SIL of the system.
- Insufficient personnel training: Lack of specialized knowledge among MRO personnel in the diagnosis, repair and testing of safety systems.
- Lack of proper documentation: Incomplete or outdated records of modifications, repairs, calibrations and test results.
- Uncontrolled modifications: Making changes to security systems without re-assessing the risks and without proper documentation.
Penalties and Liability
Failure to comply with functional security requirements can have serious legal, financial and reputational consequences for the enterprise and its management.
- Administrative fines: In Ukraine, according to the Law of Ukraine "On Labor Protection" and the Code of Ukraine on Administrative Offenses, violation of the requirements of labor protection legislation, failure to comply with the orders of officials of state labor protection supervision bodies entail the imposition of fines on company officials. Fines can reach tens of thousands of hryvnias for each detected violation.
- Criminal liability: In the event of an accident at work that resulted in serious consequences, injuries or death, the management and responsible engineering and technical workers may be held criminally liable in accordance with the articles of the Criminal Code of Ukraine (for example, Article 271 of the Criminal Code of Ukraine "Violation of the requirements of labor protection legislation"). This may include imprisonment for up to 7 years.
- Cancellation of insurance: Insurance companies can refuse to pay compensation for damages if it is proven that the accident occurred due to non-compliance with safety standards.
- Loss of production and reputation: Accidents caused by the failure of safety systems lead to production stoppages, significant financial losses, damage to equipment and long-term damage to the company's reputation. The cost of one day of downtime at a large industrial enterprise can amount to hundreds of thousands of euros.
- Additional operational costs: The costs of incident investigation, litigation, compensation to victims, as well as the correction of deficiencies and the implementation of corrective actions after an audit can be significant.
Conclusion
Compliance with functional safety standards IEC 61508 and IEC 62061 is not just a formal requirement, but the basis for the safe and efficient operation of any industrial enterprise. This is an investment in the protection of personnel, preservation of assets and ensuring uninterrupted production processes. MRO teams are key actors in ensuring this compliance, and the reliability of safety functions depends on their competence and adherence to procedures.
UNITEC-D GmbH understands the critical importance of certified components for functional safety systems. We offer a wide range of spare parts and components that meet the highest international standards (CE, EN, ISO) and Ukrainian technical regulations (DSTU, UkrSEPRO). Our experience and expertise allow us to be a reliable partner for Ukrainian industry, helping to ensure compliance with functional safety requirements.
For additional information and selection of certified components, we invite you to familiarize yourself with our assortment:
Link
- IEC 61508-1:2010. Functional safety of electrical/electronic/programmable electronic safety-related systems – Part 1: General requirements.
- IEC 61508-2:2010. Functional safety of electrical/electronic/programmable electronic safety-related systems – Part 2: Requirements for electrical/electronic/programmable electronic safety-related systems.
- IEC 61508-3:2010. Functional safety of electrical/electronic/programmable electronic safety-related systems – Part 3: Software requirements.
- IEC 62061:2021. Safety of machinery – Functional safety of safety-related control systems.
- EN ISO 12100:2010. Safety of machinery – General principles for design – Risk assessment and risk reduction.
- DSTU EN 61508 (series). Functional safety of safety-related electrical/electronic/programmable electronic systems.
- DSTU EN ISO 12100:2017. Machine safety. General design principles. Risk assessment and risk mitigation.
- Law of Ukraine "On Labor Protection" dated 14.10.1992 No. 2694-XII.
- Code of Ukraine on administrative offenses.
- Criminal Code of Ukraine.