Functional safety describes the ability of a safety-related system to achieve or maintain a safe state in the event of a fault. Typical examples include emergency stop systems, safety doors, safety PLCs and safe drive functions.
A risk assessment is required for new machinery and plants, as well as in the event of significant modifications to existing machinery. It forms the basis for selecting the necessary protective measures and for the CE conformity assessment.
The most important standards include:
Depending on the machine, further product-specific standards may be required.
PL (Performance Level) and SIL (Safety Integrity Level) assess the reliability of safety functions. Both have the same objective, namely to reduce risks to an acceptable level. PL is frequently used in mechanical engineering, whilst SIL is primarily used in more complex machinery and process plants. The assessment is carried out in accordance with different standards and calculation methods.
A safety function reduces an identified risk to an acceptable level. Examples include emergency stop, safe speed monitoring, safe torque off (STO) and safety door monitoring.
From Performance Level c onwards, safety functions must be implemented using proven components as a minimum. A standard PLC is not considered a proven component under EN ISO 13849 and is therefore not suitable for safety functions at Performance Level c. Safety functions are therefore often implemented using proven, hard-wired safety components or a safety PLC.
The CE marking confirms that a machine complies with the applicable European health and safety requirements. Prerequisites for this include, amongst other things, a risk assessment, technical documentation and a declaration of conformity.
A CE marking is required when a machine or piece of plant is placed on the market for the first time and is subject to the relevant European directives or regulations. A reassessment may also be necessary in the event of significant modifications, alterations or the formation of a complex of machines.
The manufacturer bears primary responsibility for machine safety. They must carry out the risk assessment, define suitable protective measures, demonstrate functional safety and declare the machine’s CE conformity. If an existing machine is substantially modified or expanded to form a system comprising multiple machines, the manufacturer’s responsibility may be transferred, in whole or in part, to the modifier or integrator. However, responsibility for machine safety does not end with commissioning. From the perspective of the Industrial Safety Regulation (BetrSichV), the machine becomes a piece of work equipment in the operator’s possession. The operator is therefore obliged to provide and operate the machine safely throughout its entire life cycle. This includes, in particular, carrying out risk assessments, ensuring safe use, maintenance and the regular inspection of protective measures. Irrespective of the machine’s original CE conformity, the operator must ensure that the machine does not pose any hazards to employees during actual operation.
No, in many cases no external approval is required. The CE marking is generally applied by the manufacturer. Only in certain cases is it necessary to involve a named entity in the conformity assessment procedure.
In principle, existing machinery and plant may continue to be operated, even if standards or legal requirements have changed in the meantime. However, there is no blanket exemption for existing installations.
As soon as machinery or plant is significantly modified, extended or modernised, it must be assessed whether this gives rise to any new requirements. Operators are also obliged to operate their machinery safely and to comply with the provisions of the Industrial Safety Regulation (BetrSichV).
Whether measures are required always depends on the specific situation. An individual assessment provides clarity on which requirements apply and whether adjustments are necessary.
A significant change occurs when modifications or extensions give rise to new risks or significantly alter existing risks. In such cases, a new CE assessment may be required.
There is no fixed replacement interval. The permissible service life of safety-related components is determined by the manufacturer’s specifications, the level of stress and safety-related parameters such as B10d or MTTFd. For many safety-related control systems, a service life of 20 years is assumed, after which a reassessment should be carried out.
An explosion protection document is required where explosive atmospheres may occur. It sets out the risk assessment, zone classification and protective measures.
The required Performance Level (PLr) is determined on the basis of the risk assessment. The following are assessed:
Safety validation in accordance with EN ISO 13849 is the documented demonstration of functional safety. It involves verifying whether the implemented safety function meets the requirements set out in the risk assessment and whether the required Performance Level (PLr) is achieved. Validation covers both qualitative aspects – such as the standard-compliant design of the safety function, its architecture and the application of proven safety principles – and quantitative aspects, such as the mathematical demonstration of reliability using parameters such as MTTFd, DC and CCF. Through inspections, analyses and functional tests, it is demonstrated that the safety function fulfils its protective purpose as intended and achieves the required risk reduction.
Responsibility lies, in principle, with the manufacturer or integrator of the machine. Operators are also obliged to operate the machine safely and to comply with relevant health and safety regulations.
Yes. Existing machinery can be brought up to the current state of the art by fitting modern safety control systems, safe drive technology, safety devices or ATEX measures.
Your direct
Karl Kleiser
Sebastian Lorenz