KC DSS - SHES190802022921 KLC96UF04B VP ISO13849
KC DSS - SHES190802022921 KLC96UF04B VP ISO13849
KC DSS - SHES190802022921 KLC96UF04B VP ISO13849
: SHES190802022921 Page 1 of 10
Test Report
EN ISO 13849-1:2015
BS EN 62061:2015
Tested by
(printed name and signature) ..........: Charles Li .....................................................
Approved by
(printed name and signature) ..........: Jerry Zheng .....................................................
Date of issue ....................................: 2019-12-06
Testing Laboratory Name .............: SGS-CSTC Standards Technical Services (Shanghai) Co., Ltd.
Address ...........................................: No. 588 West Jindu Road, Songjiang District, Shanghai, China
Test specification
Standard ...........................................: EN ISO 13849-1:2015 & BS EN 62061: 2015
Test procedure ................................: SGS-CSTC
Non-standard test method ...............: N/A
Test Report Form No. BMS HFT=0_A
TRF originator...................................: SGS-CSTC
Master TRF ......................................: Dated
Products may only be provided with an approval mark if the relevant conditions have been fulfilled.
© Publication in total or in part and/or reproduction in whatever way of the contents of this report is not
allowed unless permission has been explicitly given either in this report or by previous letter.
Test Item Description ....................: BMS for EPAC battery package
Trademark .......................................: N/A
Model and/or type reference ............: Refer to page 4
HW Version ......................................: KL96UF04A
Rating(s) ...........................................:
Revision Logs
Version Changes Description
v1.0 Initial Version
Summary of Assessment:
The safety protection functions of the KL96UF04A BMS meet the requirement of PL c / SIL 1 with HFT=0
architecture. The detail information please refer to the following report.
Models of battery pack listed below are evaluated with BMS board version KL96UF04A.
1. Safety Function
Prevention of risk of fire in case of management system failure for batteries, following protection circuits have been defined as safety related function in BMS
- Over/under voltage protection
- Over current (short) protection
- Over/under temperature protection
The behaviors of the safety function under fault condition were defined as switching off charging or discharging MOSFET within the specified response time.
The protection function of the BMS circuit included primary protection circuit, without secondary protection circuit, so the architecture of protection function could
be considered as HFT =0 per BS EN 62061:2015.
Information on the recommended application of IEC 62061 and this part of ISO 13849
IEC 62061 and this part of ISO 13849 specify requirements for the design and implementation of safety-related control systems of machinery. The use of either
of these International Standards, in accordance with their scopes, can be presumed to fulfil the relevant essential safety requirements. ISO/TR 23849 gives
guidance on the application of this part of ISO 13849 and IEC 62061 in the design of safety-related control systems for machinery.
BS EN 62061 was referred to executed performance level assessment in this report.
2. Risk Assessment
Per the Figure A.1 of ISO 13849-1:2015
The system MTTFd / PFH has been calculated based on schematic and BoM, the calculation report has been checked and confirmed, the total system MTTFd
is 298.4 years, PFH is 3.83 * 10-7.
Table 3 of BS EN 62061:2015 is used as the guideline to estimate the target failure values of the system, which in fact is noted as PFHD.
Safety integrity Probability of a dangerous Failure per Hour (PFHD)
3 >= 10–8 to < 10–7
2 >= 10–7 to < 10–6
1 >= 10–6 to < 10–5
Per table 3 of BS EN 62061:2015., the calculated value for the system PFHD = 3.83 * 10-7 results in a SIL 2 level of target failure values.
5. Calculate the Safe Failure Fraction (SFF)
According to “KL96UF04A_FMEDA_BMS_v1.0”, SFF for this system is 67.42% (>= 60%).
8. Systematic Failure
8.1 Introduction
When electrical systems are used in conjunction with other technologies, then relevant tables for basic safety and
well–tried safety principles should also be taken into account.
8.2 List of basic safety principles
Table D.1 — Basic safety principles
Clause Requirement + Test Result - Remark Verdict
Use of suitable materials and adequate manufacturing Refer to the BMS P
Selection of material, manufacturing methods and treatment in BOM.
relation to e. g. stress, durability, elasticity, friction, wear,
corrosion, temperature, conductivity, dielectric rigidity.
Correct dimensioning and shaping Not assessed in N/C
Consider e. g. stress, strain, fatigue, surface roughness, project
tolerances, manufacturing.
Proper selection, combination, arrangements, assembly and Work products in P
installation of components/system main phase are
Apply manufacturer's application notes, e. g. catalogue sheets, available.
installation instructions, specifications, and use of good The battery user
engineering practice. manual is available.
Correct protective bonding No such case N/A
One side of the control circuit, one terminal of the operating coil
of each electromagnetic operated device or one terminal of
other electrical device is connected to the protective bonding
circuit [for full text see EN 60204-1:1997 (IEC 60204-1:1997),
Insulation monitoring No such case N/A
Use of isolation monitoring device which either indicates an
earth fault or interrupts the circuit automatically after an earth
fault [see EN 60204- 1:1997 (IEC 60204-1:1997),].
Use of de–energisation principle Not this situation N/A
A safe state is obtained by de–energising all relevant devices,
e. g. by using of normally closed (NC) contact for inputs (push–
buttons and position switches) and normally open (NO) contact
for relays [see also EN 292–2:1991 (ISO/TR 12100-2:1992),
Exceptions may exist in some applications, e. g. where the loss
of the electrical supply will create an additional hazard. Time
delay functions may be necessary to achieve a system safe
state [see EN 60204–1:1997 (IEC 60204-1:1997), 9.2.2].
Transient suppression The general transient P
Use of a suppression device (RC, diode, varistor) parallel to the suppression was
load, but not parallel to the contacts. designed in BMS
board according to
the schematic.
Reduction of response time Manufacture has P
Minimise delay in de–energising of switching components. taken measures to
minimise response
Compatibility All components meet P
Use components compatible with the voltages and currents the requirements of
used. volt and current rated