Safe Torque Off
6-4
AC30V series Variable Speed Drive
Most but not all single component failures will be detected. Diagnostic Coverage (DC) is required to be at least 60% (i.e. the
minimum required for ‘low’ diagnostic coverage).
Detected component failures will result in the STO function being applied without intervention from the user.
The risk associated with the loss of STO safety function caused by multiple failures must be understood and accepted by the
user.
The user must undertake a risk analysis and specify suitable components that, when connected together, meet the risk
assessment requirements.
Mean Time To Failure (dangerous) (MTTFd) of each STO channel must be ≥ 30 years.
Common Cause Failure (CCF) score must be ≥ 65 according to Annex F of the standard.
Performance Level (PL) e:
Average probability of dangerous failure per hour (PFH) must be ≤ 10
-7
EN61800-5-2:2007 AND EN61508
(Adjustable speed electrical power drive systems) and
(Functional safety of electrical/electronic/programmable electronic safety-related systems)
STO aligns to the following aspects of this standard:
Safety Integrity Level (SIL) 3
Probability of dangerous random hardware failures per hour (PFH) must be ≤ 10
-7
Subsystems type A according to EN61508-2:2001 para 7.4.3.1.2
Hardware Fault Tolerance (HFT) = 1
Safe Failure Fraction (SFF) must be ≥ 90%