Diagnostic Test Interval; Competence; Residual Risk; Intentional Misuse - ABB DCS8 Series Original User Manual

Prevention of unexpected start-up (option +q957) enclosed converters equipped with dcs880 modules
Table of Contents

Advertisement

Diagnostic test interval

Regardless of the mode of operation, it is a good practice to check the operation of the safety function
at least once a year. Do the acceptance test as described in section Start-up and +Q951 acceptance test
on page 12.
The person responsible for the design of the complete safety function should also note the
Requirements from IEC61800-5-2:2016 / EN61800-5-2:2017 for the drives STO circuit:
6.2.2.1.4: Diagnostic test interval when the hardware fault tolerance is greater than zero
The diagnostic test interval of any subsystem of the PDS (SR) shall be appropriate to meet the
required PFH (see 6.2.2.1.1).
NOTE 2: For redundant parts of a PDS (SR) which cannot be tested without disrupting the
application in which the PDS (SR) is used (machine or plant) and where no justifiable technical
solution can be implemented, the following maximum diagnostic test intervals can be considered
as acceptable:
one test per year for SIL 2, PL d / category;
one test per three months for SIL 3, PL e / category 3;
one test per day for SIL 3, PL e / category 4 (not applicable).
PL and category according to ISO 13849-1.
The noted DC Values are taken from SS-EN ISO 13849-1:2016 (E) chapter 4.5.3.

Competence

The maintenance and proof test activities of the safety function must be carried out by a competent
person with adequate expertise and knowledge of the safety function as well as functional safety, as
required by IEC 61508-1 clause 6.

Residual risk

The safety functions are used to reduce the recognized hazardous conditions. In spite of this, it is not
always possible to eliminate all potential hazards. Therefore the warnings for the residual risks must be
given to the operators.

Intentional misuse

The safety circuit is not designed to protect a machine against intentional misuse

Decommissioning

When you decommission a POUS circuit or a drive, make sure that the safety of the machine is
maintained until the decommissioning is complete.
3ADW000504R0301 +Q957 Prevention of unexpected start-up en c
Option description and instructions
15

Advertisement

Table of Contents
loading

Table of Contents