DRAFT - 26 March 2015
SM45-55-SAD Rev 3
54
Note: When using the modules that are not loop-powered it is important that the solenoids being driven be
chosen to ensure that the residual field current that flows in the module OFF state does not cause the solenoid
to remain energised. A small field current is used by some module types to determine the line condition and
some low-power solenoids are capable of remaining in their energised state, once energised, with very small
loop currents. If the safe state of the loop is for the solenoid to be OFF then it must be able to drop out, despite
the monitoring of line state.
It is therefore advisable to avoid this risk by selecting module types that do not support line fault monitoring,
unless this function is specifically required by the application.
Similarly, operation of the equipment outside of its environmental ratings induces component stress and in
particular temperatures below -20ºC are to be avoided to ensure required performance.
4 Assessment of Functional Safety
4.1 Hardware Safety Integrity
The hardware assessment shows that MTLx52x solenoid/alarm drivers:
• have a hardware fault tolerance of 0
• are classified as Type A devices (“Non-complex” component with well-defined failure modes)
• have no internal diagnostic elements
The definitions for product failure of the modules at an ambient temperature of 45°C were determined as follows:-
Loop-powered modules
Failure mode
Failure rate (FIT)
MTLx521 MTL4521L MTL4523L MTL5522 MTL5525
Output stuck ON 0 0 0 0 0
Output stuck OFF (no output) 189 194 191 228 201
Output uncertain (OK or OFF) 17 17 17 24 18
Correct operation but reduced output
voltage when ON
49 50 50
60 50
Correct operation (failures have no
effect)
100 101 73 108 103
Separately-powered modules
Failure mode
Failure rate (FIT)
MTLx523/23x/23VL MTLx524/4524S MTL4525
Output stuck ON 8 20 21
Output stuck OFF (no output) 234 227 241
Output uncertain (OK or low) when ON 23 28 30
Correct operation but reduced output
voltage when ON
50 50 51
Correct operation (failures have no
effect)
100 111 116