226 Safe torque off function
Note: See also the Recommendation of Use CNB/M/11.050 published by the European
co-ordination of Notified Bodies concerning dual-channel safety-related systems with
electromechanical outputs:
• When the safety integrity requirement for the safety function is SIL 3 or PL e (cat. 3 or
4), the proof test for the function must be performed at least every month.
• When the safety integrity requirement for the safety function is SIL 2 (HFT = 1) or PL d
(cat. 3), the proof test for the function must be performed at least every 12 months.
The STO function of the drive does not contain any electromechanical components.
In addition to proof testing, it is a good practice to check the operation of the function when
other maintenance procedures are carried out on the machinery.
Include the Safe torque off operation test described above in the routine maintenance
program of the machinery that the drive runs.
If any wiring or component change is needed after start-up, or the parameters are
restored, follow the test given in section Acceptance test procedure on page 223.
Use only ABB approved spare parts.
Record all maintenance and proof test activities in the machine logbook.
Competence
The maintenance and proof test activities of the safety function must be carried out by a
competent person with adequate expertise and knowledge of the safety function as well as
functional safety, as required by IEC 61508-1 clause 6.
Fault tracing
The indications given during the normal operation of the Safe torque off function are
selected by drive parameter 31.22.
The diagnostics of the Safe torque off function cross-compare the status of the two STO
channels. In case the channels are not in the same state, a fault reaction function is
performed and the drive trips on an “STO hardware failure” fault. An attempt to use the
STO in a non-redundant manner, for example activating only one channel, triggers the
same reaction.
See the drive firmware manual for the indications generated by the drive, and for details on
directing fault and warning indications to an output on the control unit for external
diagnostics.
Any failures of the Safe torque off function must be reported to ABB.
Safety data (SIL, PL)
The safety data for the Safe torque off function is given below.
Note: The safety data is calculated for redundant use, and does not apply if both STO
channels are not used.
Frame SIL/
SILCL
PL SFF
(%)
PFH
(1/h)
PFD
avg
(T
1
= 2 a)
PFD
avg
(T
1
= 5 a)
MTTF
D
(a)
DC*
(%)
Cat. HFT CCF
(%)
T
M
(a)
R11 3 e 99.66 3.65E-09 3.20E-05 8.00E-05 20219 >
90 3 1 80 20
3AXD10000481168 rev A