Safety relays and safety PLCs
Industrial Control · Lesson 17 · Advanced
Purpose
Select and validate safety relays or safety PLCs as logic subsystems within complete safety functions.
Learning objectives
- Read state and cross-references
- Separate standard control from safety functions
- Analyse faults and reset behavior
- Validate the complete input-logic-output path
A safety relay or safety PLC cannot create safety by itself. Required PLr/SIL comes from risk assessment and must be met by the complete sensor, logic, output and machine response.
Core theory
Define each safety function, safe state, demand rate, response time and required performance before choosing architecture.
Assess categories/architecture, MTTFd or PFHd data, diagnostic coverage, common-cause failures, software/parameter controls, output-device monitoring and systematic capability under the chosen standard.
Validate wiring faults, channel discrepancy, contactor welding, reset, muting/mode selection, power loss/recovery and configuration changes. Record calculations, versions, proof tests and results.
| Term | Meaning | Symbol | Unit |
|---|---|---|---|
| PLr | Required performance level under ISO 13849-1 | Not applicable | Not applicable |
| SIL | Safety integrity level under the applicable functional-safety framework | Not applicable | Not applicable |
| EDM | External device monitoring of final switching elements | Not applicable | Not applicable |
Assumptions: Symbols and terminal designations are defined by the supplied drawing set; Required safety performance comes from the machine risk assessment.
- Architecture: Two inputs are present.
- Common cause: One cable damage event may defeat both channels.
- Resolve: Assess routing, fault exclusion/diagnostics and achieved PL/SIL rather than claiming redundancy.
Dual terminals alone do not prove the required performance; common-cause and diagnostic evidence is missing.
Reasonableness check: The conclusion is checked across normal, demand, fault, reset and restart states rather than inferred from one component label.
- Reading a contact in the energized instead of defined normal state
- Using an ordinary PLC bit as an unvalidated safety function
- Assuming emergency stop isolates every energy source
Where this appears in practice
Clear diagrams and validated safety functions let competent people build, test, diagnose and modify machinery without losing the intended protective behavior.
Knowledge check
Does a safety-rated PLC automatically make ordinary field devices safety-rated?
No. The entire safety function must achieve and validate the required performance.
Answer: No. The entire safety function must achieve and validate the required performance.
Practical exercise
Build a safety-requirements specification and validation matrix for guard, E-stop and final contactors.
Summary
- A diagram is a state model plus physical cross-reference
- Safety performance belongs to the complete function
- Stop, emergency stop and isolation are distinct
Sources and review
- IEC 60204-1:2016+AMD1:2021: Electrical equipment of machines: IEC; 6.1; International
- ISO 13849-1:2023: Safety-related parts of control systems: ISO; 2023; International
- IEC 62061:2021 with current amendments: Functional safety of machinery control systems: IEC; 2021; confirm current consolidated version; International
- IEC 61496-1:2020: Electro-sensitive protective equipment: IEC; 2020; International
- Electricity at Work Regulations 1989: UK Legislation; Current official text; Great Britain
Editorial review date: 2026-08-22. Professional electrical review is pending.