What are Basic Safety Principles for Machine Safety?


Basic Safety Principles are fundamental requirements for all safety systems. From Category B to 4, Basic Safety Principles are the first step in building reliable systems. Do you pay attention to Basic Safety Principles when designing your safety systems?

Let's have a look at some common Basic Safety Principles in the below diagram of a circuit. Here we can see protection of control circuit, de-energisation principle, protection against unexpected start-up, transient suppression and sequential switching.


As you can see, the circuit above shows a common safety interlock system with some of the Basic Safety Principles highlighted. These have been explained below:
  • De-energisation principle – This principle dictates that the safe state should always be initiated by the contact opening, voltage going low, output opening, pressure lowering, etc. This principle ensures that a loss of energy will default the system to a safe state when possible.
  • Protection of the control circuits – The control circuits should have all relevant protection to ensure that any supply faults can’t cause the system to fail in a dangerous state.
  • Transient Suppression – Transient suppression should be used in parallel with all loads. This will reduce the chance of transient voltages affecting the safety system.
  • Sequential Switching – Timing the outputs so that one switching device always operates without current will reduce the chance of common mode failure.
  • Protection against unexpected start-up – The system should be designed to avoid unexpected start-ups.
The above are some examples of Basic Safety Principles that are relevant for electrical systems. The full list can be found in Table D1 of AS 4024.1502-2006. Basic Safety Principles can also be found for mechanical, hydraulic and pneumatic systems in the Appendix sections of this standard as well.  

Published: 3 October 2013

Pointers on MTTF, MTBF, MTTFd and Availability


Some common questions have started coming up as customers increasingly design their safety systems to SIL or PL. Both of these design methods require reliability data on the components that make up the safety system. There are many acronyms floating around and some common misconceptions about their definitions, here are some explanations that may help you out:

MTTF – Mean Time To Failure
As the name suggests, this metric is the average time until a component fails, based on reliability data or testing results.

MTBF – Mean Time Between Failures
This metric is sometimes assumed to be equal to the MTTF. However the average time between failures also includes the MTTR (Mean Time To Repair) thus:
MTBF = MTTF + MTTR
If the component has a very long expected life compared to the MTTR, then the MTTF and MTBF will be very similar.

The relationship between these values determines the availability of the component:
Availability = MTTF/MTBF
As availability approaches 1, the device is operational more. The smaller the MTTR, in relation to the life of the component, the closer the availability gets to an ideal value of 1.

What's the difference between MTTFd and MTTF?
So what about the value MTTFd? Is this the same as MTTF? The answer is no, MTTFd only considers dangerous failures of the component. 

For example: If an E-Stop contact needs to open to initiate a safe stop, MTTFd will only consider the failures that cause the contact to remain closed. However MTTF would consider failures that cause the contact to remain open or closed. 

In general, if you can source one of MTTFd or MTTF, but you require the other value, there is a relationship that can be used to calculate the metric you require:
MTTF= 2 x MTTF
Hopefully this clears up any confusion you have about theses reliability metrics.

Published: 19 August 2013

What Level of Diagnostics is required for Machine Safety Systems?


When designing machine safety control systems, what level of diagnostics is appropriate? This seems to be an issue that causes confusion and inconsistency throughout the industry.

For example, if the safety system is being designed to Safety Category 3 (according to AS 4024.1501), the requirement is as follows:

“Whenever reasonably practicable the single fault should be detected…… some but not all faults will be detected”

Not surprisingly these requirements have led to many interpretations of what diagnostics should be implemented for Category 3. The application that causes most confusion is when the safety system is monitoring multiple guard doors. Can these guard doors be connected in series? If so, how many? What criterion needs to be considered?

Up until now there hasn’t been any appropriate guidance on how wiring guard doors in series degrades the level of diagnostics and what level is acceptable for the Safety Category.

New machine safety standards have now been developed to assist the designer. ISO 13849.1 is a standard that provides a method for the designer to quantify the diagnostics of their safety system, using a measure called Diagnostic Coverage (DC). Each Safety Category will have specific requirements for the DC and the designer will know exactly what level of diagnostics is required for their system.

ISO 13849.1 is a current international standard that can be sourced for your reference and this international standard will be adopted into AS 4024 in the next revision. This will provide better guidance for safety system designers in the Australian Standard.

Published: 19 June 2013