Operating Guide | iC7 Series Functional Safety Contents Contents Introduction Purpose of this Operating Guide Additional Resources Abbreviations Version History Safety Safety Symbols Qualified Personnel for Working with Functional Safety General Safety Considerations iC7 Functional Safety Functional Safety Options Functional Safety System Description System Modules with Different Safety Functions 3.3.1...
Page 4
Operating Guide | iC7 Series Functional Safety Contents Installation Installation for System Modules with +BEF2 Configuration Tools Overview System Configuration Security Preparing for a PC Connection MyDrive Insight 6.4.1 Installing MyDrive® Insight 6.4.2 Backing up and Restoring Parameters 6.4.3 Performing a Factory Reset 6.4.4...
This operating guide provides information on the functional safety features of the iC7 drives and is targeted at users already familiar with the Danfoss iC7 series. It is intended as a supplement to the drive-specific guides. The guide includes instructions on how to verify that the built-in functional safety features are active, and about configuring the safety features.
Operating Guide | iC7 Series Functional Safety Introduction Table 1: Abbreviations Related to Functional Safety (continued) Abbreviation Reference Description EN ISO 13849-1 Required performance level (the required performance level for a particular safety function). EN IEC 61508-4 Safety Integrity Level...
Operating Guide | iC7 Series Functional Safety Safety Safety Safety Symbols The following symbols are used in Danfoss documentation. DANGER Indicates a hazardous situation which, if not avoided, will result in death or serious injury. WARNING Indicates a hazardous situation which, if not avoided, could result in death or serious injury.
Operating Guide | iC7 Series Functional Safety Safety Designing appropriate safety-related control systems, such as hardware, software, and parameterization. General Safety Considerations When installing or operating the AC drive, pay attention to the safety information given in the instructions. For more information about safety guidelines for installation, see the product-specific safety guide that is included in the drive shipment.
Operating Guide | iC7 Series Functional Safety iC7 Functional Safety iC7 Functional Safety Functional Safety Options Functional safety option +BEF2 includes Safe Torque Off (STO) and Safe Stop 1 time-controlled (SS1-t) safety functions. Drives with +BEF2 also include an advanced safety unit, which enables configuring functional safety parameters using MyDrive® Insight.
Operating Guide | iC7 Series Functional Safety iC7 Functional Safety Modular control 24 V S.INA Safety hardware and software S.INB S.FB Black channel communication Optical fiber Power unit Safety hardware and software Power supply DC-link Motor interface interface DC– Figure 1: iC7 Functional Safety System Architecture Gray areas in the illustration indicate that the component is related to functional safety.
Operating Guide | iC7 Series Functional Safety iC7 Functional Safety NOTICE The prevention of unintended restart after STO deactivation does not fulfill a SIL 2 or SIL 3 requirement. This applies when configuring manual restart using the parameter 7.3.1 Safe Torque Off Response.
Operating Guide | iC7 Series Functional Safety iC7 Functional Safety Asynchronous input tolerance: The input signals at the safe input terminals are not always synchronous. If the discrepancy between the 2 signals is longer than 500 ms, the drive indicates an IO failure as described in Table 14.
Page 16
Operating Guide | iC7 Series Functional Safety iC7 Functional Safety Table 3: Instances of STO Feedback for Systems with Modular Control (continued) State Additional information Feedback state Bootloader and startup De-energized The bootloader does not communicate and does not know the state of the STO output on the power units.
Operating Guide | iC7 Series Functional Safety Parameters for Safety Functions Parameters for Safety Functions Overview Functional safety configuration is done in MyDrive® Insight, in Setup & Service > Functional safety > Safety configuration. Changing parameters related to functional safety requires logging in as an admin.
Operating Guide | iC7 Series Functional Safety Parameters for Safety Functions Table 4: General Functional Safety Parameters (continued) Selections Default value Description Parameter name Triggering edge for IO failure Rising edge Rising edge Specifies the edge for the ac- acknowledge (C)
Operating Guide | iC7 Series Functional Safety Parameters for Safety Functions Select Pair all to pair a single unit or multiple units. Ü The pairing view shows the control units and power units connected to a system module. Safe Torque Off (STO) The Safe Torque Off (STO) safety function allows the drive output to be disabled so that the drive cannot generate torque to the motor shaft.
Operating Guide | iC7 Series Functional Safety Parameters for Safety Functions Safe Stop 1 Time-controlled (SS1-t) Safe Stop 1 time-controlled (SS1-t) safety function triggers the deceleration to 0 speed in a controlled manner and activates the Safe Torque Off (STO) safety function after a specified time.
Operating Guide | iC7 Series Functional Safety Parameters for Safety Functions Validating and Generating a Commissioning Report For drives with functional safety option +BEF2, a commissioning report can be generated using MyDrive® Insight. The commissioning report describes the values set for the safety-related parameters in the drive.
Operating Guide | iC7 Series Functional Safety Installation Installation Installation for System Modules with +BEF2 Prerequisite: For motor connection, AC mains connection, and control wiring, follow the instructions for safe installation in the documentation shipped with the drive. All wiring related to functional safety must be done on terminal block X33. See Figure 5 for the location of the terminals.
Page 24
Operating Guide | iC7 Series Functional Safety Installation Table 8: Functional Safety I/O Terminal (X33) Functions in System Modules (continued) Numbering Terminal name Function S.INB- - Safe Input Channel B S.FB- - STO Feedback 1) Terminals 41A, 41B, 45A, and 45B have double pins to make connections easier.
Operating Guide | iC7 Series Functional Safety Configuration Tools Configuration Tools Overview MyDrive® Insight is a platform-independent software tool for the commissioning, engineering, and monitoring drives. MyDrive® Insight is also used to configure the parameters of the drive. MyDrive® Insight is the only tool to set up the standard safety-related functions and features of iC7 drives. Advanced safety functions and safe fieldbuses require MyDrive®...
Operating Guide | iC7 Series Functional Safety Configuration Tools MyDrive Insight Installing MyDrive® Insight 6.4.1 To install the tool, go to https://suite.mydrive.danfoss.com/content/tools. Install MyDrive® Insight. For more information on how to use the tool, see the online help in MyDrive® Insight.
Operating Guide | iC7 Series Functional Safety Commissioning Commissioning Commissioning Safety When commissioning or recommissioning the system, observe the following: Secure the site in accordance with regulations, for example barriers or warning signs. Only qualified personnel can commission or recommission the system.
Operating Guide | iC7 Series Functional Safety Commissioning Before the commissioning test: Check that the machine is properly wired. All safety equipment, such as protective door monitoring devices, light barriers, or emergency stop switches are connected and ready for operation.
Operating Guide | iC7 Series Functional Safety Commissioning Table 10: Commissioning Test for STO (continued) Test procedure Approved ☐ If a control panel is mounted, check if STO activated is shown on the control panel. If the control panel is not mounted, check if STO activated is listed in the event log.
Operating Guide | iC7 Series Functional Safety Commissioning Validating and Generating a Commissioning Report For drives with functional safety option +BEF2, a commissioning report can be generated using MyDrive® Insight. The commissioning report describes the values set for the safety-related parameters in the drive.
Operating Guide | iC7 Series Functional Safety Operation and Maintenance Operation and Maintenance Overview of Functional Tests Safety functions in the drive do not require scheduled functional tests or proof testing. Refer to application-specific standards and requirements for scheduled functional and proof testing. Drive safety system mission time is 20 years. After 20 years, the whole unit must be replaced.
Operating Guide | iC7 Series Functional Safety Operation and Maintenance Table 12: PFD and PFH Values, Altitude, and Safety Software Update Interval (continued) Altitude Safety software update Average probability of Average frequency of interval dangerous failures on dangerous failures per hour...
Operating Guide | iC7 Series Functional Safety Troubleshooting Troubleshooting Status LEDs Table 13: Status LEDs Color Status Meaning Ready White Check if: • The drive is powered off. • The drive is not ready. Blinking The drive is starting up.
The acknowledgment is configured in safety parameters. If a failure in the safety system or a safety function prevents fault recovery, contact a local Danfoss representative. Provide the commissioning report of the safety parameter configuration. For more information, see the MyDrive® Insight documentation.
Operating Guide | iC7 Series Functional Safety Troubleshooting Event List Table 15: Group 0x54FE Number Name Cause Solution 4628 STO activated. Safe Torque Off has been activated. If STO is activated unintentionally, check the following: • input cabling • external activation •...
Page 38
Operating Guide | iC7 Series Functional Safety Troubleshooting Table 16: Group 0x61FF (continued) Number Name Cause Solution 4616 No valid safety parameters The safety parameters are invalid or not Check the safety configuration in My- available present in the device.
Page 39
Operating Guide | iC7 Series Functional Safety Troubleshooting Table 16: Group 0x61FF (continued) Number Name Cause Solution 4652 Parameterization step An attempt to change safety parameters Check if there is any detailed information failed failed. in MyDrive® Insight. Make sure that the requested safety para- meter change is valid.
Operating Guide | iC7 Series Functional Safety Specifications Specifications Functional Safety Standards and Performance 10.1 All safety functions in the iC7 system modules meet the requirements of the standards listed in this chapter. Table 17: Functional Safety Standards and Performance...
Page 41
Mode of operation High demand, Low demand 1) At sea level 2) Proof tests can only be performed at Danfoss facilities when drive is refurbished. 10.2 Technical Data Table 18: 24 V Digital Input for Safe Input for System Modules (+BEF2)
Page 42
Operating Guide | iC7 Series Functional Safety Specifications Table 19: 24 V Digital Outputs for STO Feedback (continued) Function Data ON state voltage >17.4 V Off state leakage current 0.1 mA Table 20: Auxiliary Voltages Function Data 24 V output, functional safety (X33) Output voltage 24 V ±15%...
Page 44
Danfoss reserves the right to alter its products without notice. This also applies to products ordered but not delivered provided that such alterations can be made without changes to form, fit or function of the product. All trademarks in this material are property of Danfoss A/S or Danfoss group companies.
Need help?
Do you have a question about the iC7 Series and is the answer not in the manual?
Questions and answers