Last edit: 11/05/2025
Performance requirements
The minimum performance of the control system related to robot safety has been significantly revided and PL d is not anymore the minimum that must be guaranteed.
For example, the Emergency stop shall have a minimum PL = c, in line with ISO 13850.
Similarly, the Reset function must have a minimum PL =b. However, in case it is used to reduce the risk of whole body access, that must be higher.
Several functions remain with a minimum Performance Level (PL) = d, or Safety Integrity Level (SIL) 2, HFT (hardware fault tolerance) = 1. This means:
A failure of a safety system component must not cause the loss of the safety function;
The failure must be detected before or at the exact time when the safety function is required to intervene;
When the failure occurs, the safety function must always intervene and a safe condition must be maintained as long as the failure is present;
All foreseeable failures must be detected.
Any failure of the safety control system must result in a category 0 or 1 shutdown as prescribed in IEC 60204-1.