Is TÜV Rheinland FS Engineer certification relevant?


In recent years there has been a large increase in certified safety engineers, but are these certifications necessary or even relevant?

The international safety standards such as IEC 61508 require people involved with safety systems to have the appropriate competence. Part of being competent is determining that the person has the required understanding of standards, theory and technology however the standard doesn't specify a particular qualification.

This is where certification courses can come into play. There are multiple certification courses available however the TÜV Rheinland FS Engineer course has become the most widespread in Australia and New Zealand.  The certification is globally accepted with over 6100 certified TÜV Rheinland FS Engineers around the world, around six times more than any other certification program.

The TÜV Rheinland FS Engineer course is available for engineers (or equivalent qualification) with at least three years of functional safety experience. There are five streams of the certification:
  1. Safety Instrumented Systems
  2. HW/SW Design acc. to IEC 61508
  3. Functional Safety of Machinery
  4. Automotive – Systems Design acc. to ISO 26262 and IEC 61508
  5. Process Hazard and Risk Analysis (Starting in May 2013)
As functional safety becomes more prevalent in both Process and Machine Safety these certifications will be an essential starting point for ensuring personnel are competent.

 

Editor’s note: NHP has three TUV certified staff employed, including Craig who is the author of this blog. 



Published: 9 December 2013

What are Basic Safety Principles for Machine Safety?


Basic Safety Principles are fundamental requirements for all safety systems. From Category B to 4, Basic Safety Principles are the first step in building reliable systems. Do you pay attention to Basic Safety Principles when designing your safety systems?

Let's have a look at some common Basic Safety Principles in the below diagram of a circuit. Here we can see protection of control circuit, de-energisation principle, protection against unexpected start-up, transient suppression and sequential switching.


As you can see, the circuit above shows a common safety interlock system with some of the Basic Safety Principles highlighted. These have been explained below:
  • De-energisation principle – This principle dictates that the safe state should always be initiated by the contact opening, voltage going low, output opening, pressure lowering, etc. This principle ensures that a loss of energy will default the system to a safe state when possible.
  • Protection of the control circuits – The control circuits should have all relevant protection to ensure that any supply faults can’t cause the system to fail in a dangerous state.
  • Transient Suppression – Transient suppression should be used in parallel with all loads. This will reduce the chance of transient voltages affecting the safety system.
  • Sequential Switching – Timing the outputs so that one switching device always operates without current will reduce the chance of common mode failure.
  • Protection against unexpected start-up – The system should be designed to avoid unexpected start-ups.
The above are some examples of Basic Safety Principles that are relevant for electrical systems. The full list can be found in Table D1 of AS 4024.1502-2006. Basic Safety Principles can also be found for mechanical, hydraulic and pneumatic systems in the Appendix sections of this standard as well.  

Published: 3 October 2013

Pointers on MTTF, MTBF, MTTFd and Availability


Some common questions have started coming up as customers increasingly design their safety systems to SIL or PL. Both of these design methods require reliability data on the components that make up the safety system. There are many acronyms floating around and some common misconceptions about their definitions, here are some explanations that may help you out:

MTTF – Mean Time To Failure
As the name suggests, this metric is the average time until a component fails, based on reliability data or testing results.

MTBF – Mean Time Between Failures
This metric is sometimes assumed to be equal to the MTTF. However the average time between failures also includes the MTTR (Mean Time To Repair) thus:
MTBF = MTTF + MTTR
If the component has a very long expected life compared to the MTTR, then the MTTF and MTBF will be very similar.

The relationship between these values determines the availability of the component:
Availability = MTTF/MTBF
As availability approaches 1, the device is operational more. The smaller the MTTR, in relation to the life of the component, the closer the availability gets to an ideal value of 1.

What's the difference between MTTFd and MTTF?
So what about the value MTTFd? Is this the same as MTTF? The answer is no, MTTFd only considers dangerous failures of the component. 

For example: If an E-Stop contact needs to open to initiate a safe stop, MTTFd will only consider the failures that cause the contact to remain closed. However MTTF would consider failures that cause the contact to remain open or closed. 

In general, if you can source one of MTTFd or MTTF, but you require the other value, there is a relationship that can be used to calculate the metric you require:
MTTF= 2 x MTTF
Hopefully this clears up any confusion you have about theses reliability metrics.

Published: 19 August 2013