Machinery Safety 101

Manual reset using an HMI

An ABB HMI showing some graphical objects representing control functions and data.

Question: Can a safety-related stop function, for example, be reset via a graphical object representing a reset button on an HMI?

The short answer: No, with an exception. Read on if you’d like to know more.

If you’re interested in knowing more about the manual reset function, see our previous post on the manual reset function.

Why not?

Why can’t manual reset actuators appear on HMI screens? There are a few reasons for this.

First, ISO 13849-1 [1] requires that manual reset actuators be separate control devices connected to the SRP/CS. The point could be made that an HMI is a separate device, however, as of this writing, there are no HMIs that are designed to connect to a Safety PLC.

Second, [1] requires that components used for the manual reset function not reduce the Performance Level (PL) of the safety function. Since there are no safety-rated HMIs, the only structural category that could be assigned to an HMI-PLC combination is Category B, a single-channel architecture using components rated for the circuit conditions. This structural category limitation means that the highest PL that could be assigned would be PL=b. Emergency stop functions must provide at least PL=c performance according to ISO 13850, so an HMI-based reset cannot be used with emergency stop functions. In addition, most industrial machines will require at least PL=c, d or e for their safety-related interlocks, so an HMI-based manual reset cannot be used to reset an interlock stop function.

Finally, the large controls component manufacturers, like Rockwell Allen-Bradley, Omron, Pilz, Schmersal, Siemens, Telemecanique, etc., do not recommend the practice for the reasons discussed.

PS – I mentioned in the video that rising edge signals are not used for the Manual Reset Function – in truth, rising edges are not used for safety-related signals. Rising edges can occur more readily due to electrical faults while falling edges are much less likely. For example, a falling edge generated by an electromechanical push button requires that the button is pushed and released, which helps avoid intentional defeat through a “tie-down” of the button.


References

[1] Safety of machinery — Safety-related parts of control systems — Part 1: General principles for design, ISO 13849-1. International Organization for Standardization (ISO), Geneva. 2015.

[2] Safety of machinery — Emergency stop function — Principles for design, ISO 13850. International Organization for Standardization (ISO), Geneva. 2015.

[3] Realizing Reset Function in Safety Related Parts of Control Systems, 1st ed. Hoofddorp, Netherlands: OMRON Europe B.V., 2015.

3 thoughts on “Manual reset using an HMI

  1. Interesting video! You mentioned that the manual reset should be connected to a safe input. I discovered that Beckhoff has published an example of a PLd rated emergency stop with the reset button connected to an unsafe input. How is this possible? Have I misunderstood their example or have they just interpreted ISO 13849-1 differently?

    Their example can be found on page 15 in the document “Application Guide TwinSAFE” (https://download.beckhoff.com/download/document/automation/twinsafe/applicationguidetwinsafeen.pdf)

    1. Hi Andreas,
      The question is this: Is there an unsafe failure mode for the reset? If the answer is yes, then the reset should be connected to a safe input, but if a failure in the reset safety function does not lead to an unsafe condition, then you might choose to use an standard input. It’s all in the results of the risk assessment and the subsequent definition of the safety function in the safety requirements specification.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.