Functional Safety in Machinery
The complete machinery control-safety path: ISO 12100 risk assessment, a PLr or SIL target, a designated architecture, the arithmetic that proves it, validation, the CE file, and an honest comparison with ISO 26262.
- Chapters
- 15
- Chapters
- ISO 13849 categories
- 5
- ISO 13849 categories
- Machinery versus automotive chapters
- 3
- Machinery versus automotive chapters
- Worked robot cell
- 1
- Worked robot cell
- 01The Machine Next to You
- 02The Rulebook: Directives and the A-B-C Standards
- 03Risk Assessment and the Three-Step Method
- 04From Risk to Target: PLr and SIL
- 05The Safety Function: Sensor, Logic, Actuator
Why it pays for itself
One continuous path, not scattered clauses
Risk assessment, target setting, architecture, arithmetic, technology, software, validation and the conformity file are taught as one chain, so every chapter hands the next the artifact it needs and you can see where a claim would break.
The arithmetic made visible
Channel reliability, weighted diagnostic coverage, common-cause measures and the resulting failure probability are worked on real chains, including the wear parts and blind spots that only appear once the numbers are actually assembled.
A cross-domain comparison that holds up
Three dedicated chapters set the machinery model against ISO 26262 across risk, metrics and process, and they name precisely where equivalence claims between Performance Levels and ASILs stop being true.
What you’ll be able to do
Run an ISO 12100 Risk Assessment in the Right Order
Set the limits of the machine, identify hazards task by task across the whole life including the non-routine tasks that own the accident record, and apply the three-step hierarchy without skipping to guarding.
Set a Defensible PLr or SIL Target
Walk the risk graph or the additive class assignment for a specific safety function, justify each parameter choice, and read both results against the same failure probability axis.
Choose an Architecture That Matches the Target
Pick among the designated categories with a clear view of what each does about a single fault, what the tested channel cannot cover, and what redundancy quietly assumes about independence.
Produce the Numbers Behind the Claim
Assemble channel reliability, weighted diagnostic coverage and common-cause measures into a Performance Level claim, and schedule the wear parts your own arithmetic exposes.
Validate the Machine and Verify the Geometry
Attack the design with its own fault list, measure the real stopping time at commissioning, and confirm that the mounting distance the calculation assumed still holds on the actual machine.
Work Across Machinery and Automotive Without Faking Equivalence
Compare the two risk models, metric systems and process ecosystems accurately, refuse the letter-to-letter translations that sales decks offer, and re-argue evidence in the receiving standard.
Chapter by chapter
- 01
The Machine Next to You
Why machinery safety is its own discipline: a person and raw mechanical energy share the room every working day. The named taxonomy of mechanical harm, two centuries of the same lesson, and the stored energy that keeps a stopped machine dangerous.
- Hazard taxonomy
- Stored energy after the stop
- The standstill safe state
- 02
The Rulebook: Directives and the A-B-C Standards
Machinery safety as product law: the Machinery Directive and the Machinery Regulation that replaces it, harmonized standards and the presumption of conformity, the A, B and C standard types with their precedence, and how ISO 13849-1 and IEC 62061 came to coexist.
- CE marking and product law
- A-B-C precedence
- Two standards, one job
- 03
Risk Assessment and the Three-Step Method
The ISO 12100 work that happens before any electronics exist: limits of the machine, hazard identification task by task across the whole life, severity plus a three-part probability, and the strict order of inherently safe design, then safeguarding, then information for use.
- Limits of the machine
- Task-based hazards
- Hierarchy in strict order
- 04
From Risk to Target: PLr and SIL
Two routes from the same risk elements to one axis: the ISO 13849 risk graph with its three questions, the IEC 62061 severity plus additive class assignment, why both land on a failure probability per hour, and what a target does not yet tell you.
- Risk graph walk
- Additive class assignment
- One PFH axis
- 05
The Safety Function: Sensor, Logic, Actuator
The chain as real devices: interlocking devices and their defeat problem, electro-sensitive protective equipment, two-hand controls, the emergency stop put in its proper place, logic generations, contactors and drive-integrated stopping, and how response time becomes a safety distance.
- The input device zoo
- Stop categories on one clock
- Distance from stopping time
- 06
Architecture: The Five Categories
The designated reference structures and their different answers to a single component failure: single channel, tested channel and its unclosable window, redundancy with and without fault accumulation, and the common-cause and fault-exclusion obligations that police every claim.
- Five designated structures
- The test window
- CCF and fault exclusion
- 07
The Numbers: MTTFd, DC, CCF and PFHd
The reliability arithmetic behind a Performance Level claim: where component figures come from and how cycle rate converts them, the defined MTTFd bands and the deliberate honesty cap, failure-rate-weighted diagnostic coverage, and the same question posed the IEC 62061 way.
- Component data to channel figures
- Weighted DCavg
- Subsystem composition
- 08
Technology: Relays, Safety PLCs, Drives and Fieldbuses
The hardware the categories are made of: the safety relay wiring pattern and its feedback loop, safety PLCs that move redundancy inside the silicon, standardized safe motion functions in the drive, safe communication over an untrusted network, fluid power, and the deliberate holes called muting and blanking.
- Relay pattern and EDM
- Safe motion functions
- Black channel on the fieldbus
- 09
Software and Validation
Which rules your code lives under depending on who wrote it and in what language, the simplified V for application software, the certified-block trap that hides bypasses, validation as hostile testing against the machine's own fault list, and the commissioning stopwatch.
- Authorship decides the regime
- Certified-block trap
- Measured versus assumed stop time
- 10
Process: From Risk Assessment to CE Mark
The paper machine around the metal one: how every chapter turned into a document, the conformity route fork, the actor map from component supplier through integrator and employer, the substantial-modification tripwire, and how self-declared paperwork fails in practice.
- Artifact chain to the CE plate
- The actor map
- Modification tripwire
- 11
Worked Example: The Robot Cell
Ten chapters of method applied to one machine with every number shown: tasks against hazards, three safety functions with their target walks, the engineered chains and their computed verdicts, the safety distance checked on the plan, and the residual risk teach mode leaves behind.
- Task and hazard grid
- Three functions computed
- The residual nobody closes
- 12
Machinery vs Automotive: Risk Models
The risk graph held against the HARA: who each model protects, why exposure is designed in on one side and priced on the other, the different human credit each grants, the conservatism each builds in on purpose, and what genuinely transfers between them.
- Two exposure regimes
- Human credit compared
- What does not transfer
- 13
Machinery vs Automotive: Metrics and Mechanisms
Similar inverse-hour scales carrying different claims: function-level against item-level probability metrics, assigned diagnostic coverage against measured coverage, the latent-fault question one side gives a metric and the other handles structurally, and where each world puts its safe state.
- One axis, three vocabularies
- Coverage cousins
- De-energize versus degrade
- 14
Machinery vs Automotive: Process and Ecosystem
Two legal machines and two evidence cultures: a self-issued conformity signature against an argued and assessed safety case, composing certificates against proving elements in context, independence by law against independence by degree, and change as a work order against change as a release.
- Declaration versus safety case
- Evidence cultures
- What each side should steal
- 15
The One-Page Story
The whole discipline compressed onto a single poster: the stages from hazard to CE plate with the validation loop drawn in, the reference tables worth keeping, and ten sentences that carry the argument when a colleague asks what all of this says.
- Hazard to CE plate
- Reference tables
- Ten sentences
Who this guide is for
- Automotive safety engineers who now own production equipment, test rigs or plant machinery
- Machine builders and integrators responsible for a technical file and a Declaration of Conformity
- Control engineers designing interlocks, light curtain functions and safe motion chains
- Robotics and automation engineers assessing cells where people share the workspace
- Safety managers working across ISO 26262 and machinery standards in the same organization
Frequently Asked Questions
Common questions about Functional Safety in Machinery
Start the course today
A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 77-guide library. No credit card required.