Functional Safety Data Sheet
Functional Safety Data Sheet
Cat 2
GuardShield 440L-P2 Type 2 440L-P2 1 c 6.91E-09 20
Type 2 (IEC 61496)
*1 – Other data may apply when combined into subsystems with other products. The resultant SIL CL and PFHd and can be determined using the methodolgy of IEC 62061 and the PL can be determined using the methodolgy of EN ISO 13849-1.
*2 – The maximum rating shown here assumes the monitoring all dangerous single fault modes and a maximum diagnostic test interval of 6 months.
*3 – B10d value assuming a failure to open is considered a dangerous failure. If in the application a failure to close is considered a dangerous failure, in this case
100S-C: B10d=4.00E+06,
700S-CFB: B10d=8.6E+05
*4 – For low energy switching, the contact reliability is expressed as “Assessed constant failure rate”. The assessment method is given in IEC60947-5-4.
*5 – Some aspects of the diagnostic testing of electromechanical inputs or outputs are initiated by usage. Therefore the Diagnostic Test Interval is equal to the time period between the operations of the device safety function. For devices with electromechanical inputs or outputs the Diagnostic Test Interval
(operating interval) should not exceed 6 months . See IEC61508-4 3.8.7 Diagnostic Test interval and EN13849-1: 3.1.29 Test rate.
*6 – This device does not provide monitoring of cross faults at ouput wiring. If this is required, additional measures will be required e.g. connection to a suitable monitoring relay.
*7 – Where the product has two electrical safety switching function channels, the B10d data given is based on a failure of either channel. It can be used to determine the MTTFd of each single channel and will this produce conservative data.
*8 – The data given, including fault tolerance, is based on the use of fault exclusion at some single fault mechanical failure points, for example: actuator, cam, contact plunger, lock mechanism.
Because of the inherent strength and simplicity of those parts they have an extremely low likelihood of failure and those faults are excluded in accordance with EN ISO 13849-2: 2008 Clause A.5.2 Table A4.
*9 – Vacant
*10 – The delayed acting contacts are CAT 3, SIL CL 2, PLd. The PFHd given can be applied for the the immediate acting and delayed acting contacts
*11 – The PFH given was calculated using the the MTTFd 100 year limitation given in IS0 13849-1: 2006 clause 4.5.2
*12 – The DC or SFF value given is for the device used on its own with no additional monitoring/diagnostic equipment.
An increased value for DC and SFF can be achieved by connection to specified external monitoring equipment. The maximum achievable value is based on individual monitoring of the devices in redundant or dual channel configuration. In some cases this will require the use of two devices.
It assumes a maximum diagnostic test interval of 6 months.
It assumes the monitoring all dangerous single fault modes. The maximum value given will not be achievable if it can be foreseen that some single faults will not be detected in , for example, multiple normally closed switches are connected in a series arrangement to the monitoring equipment.
*13 – Category 1 applies where the combination of the usage rate and the B10d value results in an MTTFd equal to or greater than 30 years.
*14 – This product must not be used in a safety related system unless it is connected to a suitable monitoring device.
*15 – Sipha control units are applied for EN 60947-5-3 as control devices of a PDF system together with sensors and OSSDs. The safety classifications referred in EN 60947-5-3 take into account the general principles of ISO 13849-1, but they are not directly equivalent to the categories defined in clause 6 of that standard.
*16 – The data given is based on the use of fault exclusion at some single fault mechanical failure points. Therefore subsystems intended to achieve Category 4, PLe or SIL 3 require the use of two separate devices. This is in accordance with the latest ISO and IEC Joint Technical Reports ISO TR 23849 and IEC TR 62061-1.
*17 – B10d values using actual test results and calculations with a 90% confidence interval and at least 1 NC (normally closed) contact block.
*20 – The Mission Time stated is based on possible time based degradation factors. For usage based degradation factors refer to the calculated T10d value. Always use the lowest value (Mission Time or T10d) for calculation of SIL or PL.
*22 – The data given based on a 20 year mission time (proof test interval) applies only to product with a manufacturing date code of 2009/01/01 (January 1, 2009) or later. See the product label for the date code.
*23 – The DC value given is for the device used on its own with no additional monitoring/diagnostic equipment.
An increased value for DC and SFF can be achieved by direct monitoring i.e. connection of the mechanically linked auxiliary contacts to external monitoring equipment. In most cases redundant devices or a second switch-off path this will be required.
It assumes a maximum diagnostic test interval of 6 months.
It assumes the monitoring all dangerous single fault modes. The maximum value given will not be achievable if it can be foreseen that some single faults will not be detected, for example, multiple normally closed switches are connected in a series arrangement to the monitoring equipment.
*26 – When pulse-testing of ALL used safety outputs is disabled, safety outputs and a power supply are only tested upon demand (at reset) or at a machine cycle (when motion starts). This has an effect on the PFHd.
Enabled test pulses for at least one safety output can ensure main power supply testing. The diagnostic test interval is set to the demand rate of at least 0.5 years.
*27 – The data values given are based on a maximum usage rate of 500,000 switching operations per year of the Safe-Off board.
*28 – For the determination of the safety parameters a “worst case” configuration has been assumed (standalone, all inputs, all outputs, single encoder mode). Improved data can be achieved by use of dual encoders.
*30 – 800Z is only suitable for safety use when combined into a subsystem with a relay (then the DC will be 99%) For the relay output versions we specify the maximum usage at 2 Million operations.
*31 – B10d data is based on test and aligned with EN ISO 13849-1 Table C1. (mechanical or minimal load e.g. safety monitoring relay unit)
*32 – The PFHd given is the sum of the PFHd of the electronic aspects and the PFHd resulting from the B10d values of the two output relays based on a maximum usage rate of 8790 operations per year. For different usage rates the electronic aspects and the electromechanical output relays can be entered as
two separate two channel subsytem using the following data:
PFHd of Electronic aspects 4.0E-9
B10d for each of the two electromechanical output relays:
AC-15, 230V, 0.4A: 1.0E6
AC-15, 230V, 2.0A: 2.6E5
DC-13, 24V, 0.6A: 1.0E6
DC-13, 24V, 1.5A: 2.0E5
The electronic aspects provide 99% DC for the electromechanical output relays.
IMPORTANT: The data given cannot be regarded as valid unless proper account is taken of the relevant * notes.
Notes
*33 – The PFHd given is the sum of the PFHd of the electronic aspects and the PFHd resulting from the B10d values of the two output relays based on a maximum usage rate of 8760 operations per year at AC15 1A 230V AC or at DC13 1.5A 24VDC.
For greater usage rates or loads please contact us for more information.
*35 – B10d data is based on test and aligned with EN ISO 13849-1 Table C1.
*36 – Some aspects of the diagnostic testing of the proximity sensor inputs are initiated by usage. Therefore the Diagnostic Test Interval is equal to the time period between demands of the safety function, i.e. exceeding the speed threshold. The Diagnostic Test Interval should not exceed 6 months.
See IEC61508-4 3.8.7 Diagnostic Test interval and EN13849-1 3.1.29 Test rate.
*37 – The data is given for door monitoring and OSSD switching capability of the TLSZR/L-GD2 - Mechanical life = 1000000 cycles.
*38 – The B10d value has been determined with a confidence level of 70 %. During the B10d testing an electrical load of 100 mA provided by a 24 VDC power source was used.
*39 – When this Block is used as a channel of a dual channel subsystem the output should be monitored and DC should be evaluated according to the type of monitoring measure applied. For some devices it may be necessary to use an interposing relay to invert the signal when connecting to a monitoring
safety relay. See product manual and Rockwell Automation Safety Accelerator Toolkit for more information.
*40 – The data is given for door monitoring and OSSD switching capability of the TLSZR/L-GD2. Mechanical life = 500,000 cycles
*41 – The MTTFd value for the electronic controlled coil must be added as a separate block or element when the interface function is used.
*42 – The Safedge system comprises the Safedge Sensor 440F-Exx and one of the Safedge Controllers 440F-C251P, 440F-C251D, or 440F-C252D.
*43 – The PFH given for the Safedge Systen includes the PHF for the Safedge Sensor (3E-09) and the Safedge Controller (7.7E-09). The PFH calculated for the Safedge Sensor is based on B10d 20000, DC 90% and a maximum actuation frequency of once per week. For greater actuation frequencies the PHF for the
Safedge Sensor and System must be recalculated.
*44 – The PFH calculation is based on complete use of all inputs and outputs
*46 – The MatGuard sensor mats must only be used with a suitable mat controller subsytem such as the 440F-C4000x or 440F-C280xx
*47 – The PFH for the Matguard sensors and the mat controller should be calculated as two separate subsystems
*48 – The PFH 2.0E-9 is based on the MatGuard sensor mats being connected to mat controllers that provide ≥90% DC (or SFF) such that faults like open and short circuits, permanent and no activation will be detected by the mat contrller. It is based a maximum usage rate of 1 operation per day. The PFH was
calculated in accordance with IEC 62061. For higher usage rates the PFH must be recalculated based on a B10d of 200000 for each mat sensor channel. The resulting T10d should be used if it is less than the given mission time/proof test interval
*49 – A manual test of the safety function must be performed at least once per week
*50 – The data given, including fault tolerance, is based on the use of fault exclusion for the possibilty of insulation between internal mat sensor plates. The fault is excluded in accordance with and EN ISO 13849-2: 2012 Table D8 and ISO 13856-1:2013.
*51 – Vacant
IMPORTANT: The data given cannot be regarded as valid unless proper account is taken of the relevant * notes.
Notes
*52 – Suitable for use in PLe, Cat 4 (ISO13849-1) applications, provided that the conditions outlined below are met:
a) Must be used used with 1732DS-IB8XOBV4 safety I/O module.
b) The 1732DS-IB8XOBV4 safety I/O module must be entered as a separate subsystem
c) The 1732DS-IB8XOBv4 shall be configured to perform the safety test pulses for the corresponding safety related inputs (normal closed switches shall be used) and safety related outputs (de-energized state shall be the safe state).
d) The bipolar mode (output configuration of 1732DS-IB8XOBV4) shall be used for the safety related outputs P and M. The output configuration for the P and M shall be:
- Point Operation Type = Dual (see 1791DS-UM001_-EN-P)
- Point Mode = Safety Pulse Test (see 1791DS-UM001_-EN-P)
e) SELV or PELV Power Supplies shall be used
f) Signals SM1 and SM2 shall be monitored and the safe state shall be maintained if the SM feedback is open after a safety-related stop is executed.
*53 – The given 20 year mission time is dependant on a maximum operating rate of 100000 cycles per year. A 10 year mission time can be used for an operating rate of 200000 cycles per year. The PHF given is based on the use of EN ISO 13849-1 Annex K Table K1. The inputs are Category 4, DC= High,
MTTFd = 2.4E4 yrs (clipped to 100 yrs). This results in PLe and 2.47E-8 PFH.
*54 – The given 20 year mission time is dependant on a maximum operating rate of 100000 cycles per year. A 10 year mission time can be used for an operating rate of 200000 cycles per year. The PHF given is based on the use of EN ISO 13849-1 Annex K Table K1. The inputs are Category 4, DC= High,
MTTFd = 1.9E4 yrs (clipped to 100 yrs). This results in PLe and 2.47E-8 PFH.
*55 – The given 20 year mission time is dependant on a maximum operating rate of 100000 cycles per year. A 10 year mission time can be used for an operating rate of 200000 cycles per year. The PHF given is based on the use of EN ISO 13849-1 Annex K Table K1. The inputs are Category 4, DC= High,
MTTFd = 2.1E4 yrs (clipped to 100 yrs). This results in PLe and 2.47E-8 PFH.
*56 – For the rate of a dangerous failure per hour PFH a value of 1.0E-7/h can be used for the system (according to and tested to GS-ET-31). Exception: The data given does not apply to Timed Delay Units 440T-MSTUE*, 440T-MDTUE*and and Stopped Motion units 440T-MSMSE*, 440T-MDMSE*
*57 – Determination of safety parameters is based on the assumption that the system operates in High-demand mode and that the safety function is requested at least once every three months
*58 - PFH and PFD Data is for both SIL3 dual-channel mode of operation and SIL2 single-channel Safety Inputs mode of operation.
*59 - W encoders have 9 bit safety resolution, Q encoders have 12 bit safety resolution
Relates to a failure that results in the ON state of the outputs unless otherwise indicated
Type Family Part Number See Notes MTTF (years) MTTF (hours) B10 Lifetime (years)
Type Family Part Number See Notes MTTF (years) MTTF (hours) B10 Lifetime (years)
Type Family Part Number See Notes MTTF (years) MTTF (hours) B10 Lifetime (years)
IMPORTANT: The data given cannot be regarded as valid unless proper account is taken of the relevant * notes.
Notes
*1 – Products in this part of the library are not specifically intended as safety devices, and the associated data represents reliability data. For this product any use of the terms MTTFd, B10d, T10d or PFHd does not relate to a failure to danger. It relates only to a failure that results in the ON state of the outputs.
The user assumes all costs and liability for any decision on whether a failure that results in the ON state of the outputs could be dangerous.
*2 – For this data, a conservative approach is taken by representing MTTFd by the total MTTF, and representing the B10d by the total B10 value.
*3 – The user assumes all costs and liability for any decision to use these products as part of a functional safety related system. Please review important Access Terms and Conditions at Information -LEGAL NOTICES with regard to the RA SISTEMA Library.
*5 – The Mission Time stated is based on possible time based degradation factors. For usage based degradation factors refer to the calculated T10 value. Always use the lowest value (Mission Time or T10) for calculation.
*6 – The MTTFd value for the electronic controlled coil must be added as a separate block or element when the interface function is used.
*7 – The data given applies to the following coil codes: J, ZJ, Y, ZY, D, ZD, A, ZA, N.
*8 – The data given applies to the following coil codes: D, ZD, A, ZA, N.
*9 – If the contactor is used with the electronic interface selected it must be used in a redundant and monitored configuration for safety related applications
*10 – If the 100-JE electronic interface is used with 100-C or 700-CF contactors they must be used in a redundant and monitored configuration for safety related applications
*11 – Products in this part of the library are not specifically intended as safety devices, and the associated data represents reliability data. For this product any use of the terms MTTFd, B10d, T10d or PFHd does not relate to a failure to danger. It relates only to a failure to provide correct data at the outputs. The user
assumes all costs and liability for any decision on whether that could be dangerous.
*12 – Data given is based on nominal load of components, average ambient temperature 40°C, frequency of use 8760 h/a
IMPORTANT: The data given cannot be regarded as valid unless proper account is taken of the relevant * notes.
Notes
*13 - Rotor Connection Motor/Encoder Shaft. a long-term integrity of mechanical fixing is claimed, based on frictional connection with overstress factor of 20
*14 - When correctly connected and monitored by a MSR57P Safe Speed Monitoring Safety Relay according to instructions given in per manual 440r-um004_-en-p.pdf or Kinetix 6200 and Kinetix 6500 Safe Speed Monitoring Multi-axis Servo Drives according to instructions given in reference manual
2094-rm001-en-p.pdf and based on the structure and MTTFd the following information is available:
Category 3.
PFH = 1.2E-8.
DC = 90%. SFF = 95%.
It is the responsibility of the user to decide if this is can be suitable for achieving a required PL or SIL.
Disclaimer of Warranty
The information maintained in this document is provided ”as is” without warranties of any kind, either express or implied, including without limitation, all implied warranties of accuracy, merchantability, fitness for a particular purpose, non-infringement or other violation of rights. Rockwell Automation does not
warrant or make any representations regarding the use, validity, accuracy, or reliability of, or the results of any use of, or otherwise respecting, the information maintained in or accessed by way of this document.
Limitation of Liability
Under no circumstance (including negligence and to the fullest extend permitted by applicable law) will Rockwell Automation be liable for any direct, indirect, special, incidental, punitive or consequential damages (including without limitation, business interruption, delays, loss of data or profit) arising out of the use or
the inability to use the information maintained in or accessed by way of this document even if Rockwell Automation has been advised of the possibility of such damages. If use of such information results in the need for servicing, repair or correction of user equipment or data, user assumes any costs associated therewith.
Please review important Access Terms and Conditions at Information - LEGAL NOTICES with regard to the RA SISTEMA Library.
Publication SAFETY-SR001I-EN-E – February 2017 Copyright © 2017 Rockwell Automation, Inc. All Rights Reserved. Printed in USA.
Supercedes Publication SAFETY-SR001H-EN-E – July 2015