Safe Torque Off
890CS Common Bus Supply - Frames B & D; 890CD Common Bus Drive and 890SD Standalone Drive - Frames E & F
Category 3 general requirements are:
A single failure, and any consequential failures, will not lead to loss of the STO safety function.
Failure of more than one component can lead to the loss of the STO safety function.
Most but not all single component failures will be detected. Diagnostic Coverage (DC) is required to
be at least 60% (i.e. the minimum required for ‘low’ diagnostic coverage).
Detected component failures will result in the STO function being applied without intervention from
the user.
The risk associated with the loss of STO safety function caused by multiple failures must be
understood and accepted by the user.
The user must undertake a risk analysis and specify suitable components that, when connected
together, meet the required risk assessment requirements.
Mean Time To Failure (dangerous) (MTTFd) of each STO channel
must be ≥
30 years.
Common Cause Failure (CCF) score
must be ≥
65 according to Annex F of the standard.
Performance Level e:
Average Probability of dangerous Failure per Hour (PFH)
must be ≤