Last edit: 09/05/2023
In Category 3, both Basic and Well-tried safety principles must be used. Each Category 3 subsystem should be designed so that a single fault does not lead to the loss of the safety function.
Moreover, whenever reasonably practicable, a single fault shall be detected at or before the next demand upon the safety function. The RBD is shown in Figure 6.19.