Last edit: 09/05/2023
In Category 4, both Basic and Well-tried safety principles must be used. Each Category 4 subsystem should be designed so that a single fault does not lead to the loss of the safety function.
Moreover, the single fault must be detected at or before the next demand upon the safety function. When this detection is not possible, an accumulation of undetected faults should not lead to the loss of the safety function. The RBD is shown in Figure 6.28.