25
(2) Fail-safe measures to cover the possibility of programmable controller
failure
Problems with a CPU module and memory can be detected by the self
diagnostics function. However, problems with I/O control area may not be
detected by the CPU module.
In such cases, all I/O points turn ON or OFF depending on the problem,
and normal operation and safety cannot be maintained.
Though Mitsubishi programmable controllers are manufactured under strict
quality control, they may fail or malfunction due to unspecified reasons. To
prevent the whole system failure, machine breakdown, and accidents, build
a fail-safe circuit outside the programmable controller.
Examples of a system and its fail-safe circuitry are described below:
<System example>
Input
16
points
Power
supply
module
Output module for fail-safe purpose*1
CPU
module
Input
16
points
Input
16
points
Input
16
points
Output
16
points
Output
16
points
Vacant
Output
16
points
Output
16
points
Output
16
points
YBF
YB0
Power
supply
module
Output
16
points
Output
16
points
Output
16
points
to
*1: The output module for fail-safe purpose should be mounted on the last
slot of the system. (YB0 to YBF in the above system.)
Internal program
SM412
T1
ON delay timer
1s
T2
OFF delay timer *3
1s
L
L
MC
T2
T1
+
-
24VDC
YB0
YB1
YBF
24V
0V
YB0
YB0
External load
0.5s
0.5s
CPU module
Output module
*2
MC
to
*2: Since YB0 turns ON and OFF alternatively at 0.5 second intervals, use a
contactless output module (a transistor is used in the above example).
*3: If an offdelay timer (especially miniature timer) is not available, construct
the failsafe circuit using an ondelay timer shown on the next page.