BS EN ISO 13849:2015 splitting up safety functions
BS EN ISO 13849:2015 splitting up safety functions
(OP)
Good afternoon all!
I am wondering if you can help settle a dispute I am having with one of my colleagues. We work in amusement devices and specifically reviewing designs for electrical/control systems.
I am currently doing a design review for a client where they have split up some of their safety functions into seperate parts. Such as below (not real systems just representative):
Unintended startup (Part A movement)
Unintended startup (Part B movement)
Unintended startup (Part C movement)
Now the hazards introduced by these different components moving may be different and the severeity of damage may be different as well coming out at different performance levels.
My opinion is that "Unintended Startup" should be considered as a whole SRP/CS and splitting it up may throw the maths out. Section 6.3 of the aforementioned standard is about combining seperate SRP/CS but it seems to suggest a method of joining them rather than stating that they must be joined to make the maths work.
I was wondering if anyone else on here has had any dealings with this and can shed any light on any other sections of 13849 that may shed more light on this?
Thanks in advance!
Tomm
I am wondering if you can help settle a dispute I am having with one of my colleagues. We work in amusement devices and specifically reviewing designs for electrical/control systems.
I am currently doing a design review for a client where they have split up some of their safety functions into seperate parts. Such as below (not real systems just representative):
Unintended startup (Part A movement)
Unintended startup (Part B movement)
Unintended startup (Part C movement)
Now the hazards introduced by these different components moving may be different and the severeity of damage may be different as well coming out at different performance levels.
My opinion is that "Unintended Startup" should be considered as a whole SRP/CS and splitting it up may throw the maths out. Section 6.3 of the aforementioned standard is about combining seperate SRP/CS but it seems to suggest a method of joining them rather than stating that they must be joined to make the maths work.
I was wondering if anyone else on here has had any dealings with this and can shed any light on any other sections of 13849 that may shed more light on this?
Thanks in advance!
Tomm
RE: BS EN ISO 13849:2015 splitting up safety functions
Is the intent of separating the analysis to actually physically stop the parts of the machine separately (e.g. a stopping function at one part of the machine does not stop another part of the machine), or is the intent to stop everything together but to facilitate less stringent hardware, circuit, and logic designs on lower-risk parts of the machine?
The former should be addressed by an overall risk assessment that extends beyond the analysis of strictly the SRP/CS, and additionally, standards specific to the equipment under discussion may dictate certain courses of action. The latter is completely legitimate (but whether it's worthwhile or not is quite another matter). In the system architectures that I normally deal with in this day and age, the furthest this might ever go would be to use a single contactor instead of double contactors, or not bother with a redundant monitored safety pneumatic valve, for low-risk functions. No one is going to split up the safety PLC and its safety inputs into high-risk and low-risk sections!
RE: BS EN ISO 13849:2015 splitting up safety functions
In terms of the level of risk, there is potentially scope that Part A moving unexpectedly would create a higher risk than part B moving unexpectedly (which has been covered by the risk assessment) so that may well be a part of the reasoning for this splitting up as well?
In my opinion as this SRP/CS has a single set of inputs (2 start buttons) which seperates into three seperate outputs for parts A, B and C of the machine then it would need to be considered as a whole?
Thanks for the help!
RE: BS EN ISO 13849:2015 splitting up safety functions
Answering that ... is your job as the reviewer!
It's not really enough to just identify that something has been split up in a way that's different than what you would have done as a designer. ISO 13849 is not prescriptive in how to be implemented. It is a performance standard. If the required performance is achieved, that's good. If it isn't, that's not.
RE: BS EN ISO 13849:2015 splitting up safety functions
I've done the maths both ways and the performance level comes out the same regardless so I'll give them that this time!
Thanks for the assistance.
Tom