EN ISO 13849-1 (Safety-Related Parts of Control Systems)
The standard for the safety-related parts of control systems: capability on the a-to-e performance level scale, architecture in Categories B to four.
EN ISO 13849-1 deals with the design and the validation of the control parts that carry out a safety function on a machine. It classifies the capability with the performance level scale from a to e, and the architecture with Category B, 1, 2, 3 and 4. Architecture, component life and diagnostic coverage all enter the calculation together; the quality of a single part does not decide the result.
The process has two steps: first the required performance level is determined through risk assessment, then the level the designed circuit reaches is calculated. If the second is lower than the first, the design changes; the calculation is not a documentation exercise but a design decision.
The inputs to the calculation
- Category: the architecture of the circuit, redundancy and tolerance to a single fault.
- MTTFd: the mean time to dangerous failure of the channel, in years.
- Diagnostic coverage: the proportion of dangerous failures that can be detected.
- Common cause failure: the measures taken against the risk of redundant channels failing together.
How the required level is determined
The risk assessment asks three things: the severity of the possible injury, the frequency of exposure to the hazard and the possibility of avoiding it. As each of the three rises, the required level rises. Not every function on the same machine requires the same level; stopping a load lifting movement and the behaviour of an indicator lamp are not weighed in the same scale. That is why the assessment is made not machine by machine but function by function, and is written down separately for each function.
Categories and behaviour on a single fault
| Category | Architecture | On a single fault |
|---|---|---|
| B | Basic safety principles | The function can be lost |
| 1 | Well-tried components and principles | The function can be lost, the probability falls |
| 2 | Periodic testing of the function | It is not noticed until the moment of the test |
| 3 | Redundant structure, partial diagnostics | The function is preserved |
| 4 | Redundant structure, extensive diagnostics | The function is preserved, faults do not accumulate |
A frequent mistake: component level and function level
The level written on the label of a component is not the level of the function that component sits inside. The assessment covers the whole chain, from the sensor to the logic and from the logic to the output element: the relay output chain, the contactor and the wiring enter the calculation too. The weakest link in the chain pulls the result down, so an expensive safety relay does not raise the level on its own. Performance level is for this reason not a product property but a design outcome, and it is looked at again if the way it is installed changes.
The second widespread false assumption is to do the calculation once and put it in a file. If a component changes, if the wiring changes, if the maintenance interval is lengthened or if the machine starts running more often, the result changes too; what the standard asks for is not a permanent document but a current justification. The division of responsibility lies here as well: the manufacturer publishes the component data, while the party that builds the machine calculates and validates the level of the function.
What the standard does not cover
The standard does not say which level is required; that is determined by the risk assessment of the machine. The behavioural requirements specific to a wireless remote control are dealt with by IEC/EN 62745, and whatever the result of the calculation it does not remove the need for a wired emergency stop. How the same logic is built on the hydraulic side can be found under performance level in hydraulic control.
On a crane radio remote control the target commonly used in the sector for the machine stopping function is Category 3 and performance level d; for the emergency stop function the general minimum expectation is cited as performance level c, and the risk assessment may require higher. These levels are not declared for AXI products; do not attribute a performance level to a product.
The context in which this term is used: Wireless remote control installation: pairing, relay, safety