Flow Control Group (FCG) is the leading solutions provider focused on technically oriented products and services for the flow control, industrial automation and life sciences with locations throughout North America.
Environmental Disclosure
3915 Shopton Rd
Charlotte, NC 28217
Phone: 800.690.3650
Email: info@flowcontrolgroup.com
Copyright © Flow Control Group all rights reserved. Privacy Policy
We use cookies to improve your experience, analyze traffic, and support marketing. You can accept all, reject non-essential cookies, or customize your choices.
California users can reject marketing cookies to opt out of sale/share or targeted advertising.
Machine safety functions must perform reliably when hazardous conditions occur. Under ISO 13849-1, that capability is expressed as a Performance Level (PL), ranging from PLa through PLe.
The required Performance Level is established as part of the machine risk assessment, while the achieved Performance Level depends on how the complete safety-related control function is designed. Factors such as circuit architecture, component reliability, diagnostics, common cause failures, software, and fault behavior all contribute to the result.
What Is a Performance Level?
A Performance Level describes the ability of the safety-related parts of a control system to perform a safety function under foreseeable conditions.
ISO 13849-1 defines five discrete levels:
Higher Performance Levels correspond to a greater capability to reduce risk through the safety-related control system.
Performance Level applies to a complete safety function or safety-related subsystem rather than being determined from a single component characteristic alone. ISO 13849-1 evaluates both quantitative reliability measures and qualitative design considerations when determining the achieved PL.
What Factors Determine Performance Level?
Safety Circuit Architecture
The structure of the safety circuit is one of the fundamental considerations. ISO 13849 uses designated architectures associated with Categories B, 1, 2, 3, and 4.
These categories describe how safety-related components are arranged, the level of redundancy and diagnostics incorporated into the design, and how the system behaves when faults occur.
Architecture alone does not establish the final Performance Level, but it sets an important foundation for what the safety circuit can achieve.
Mean Time to Dangerous Failure
Mean Time to Dangerous Failure (MTTFd) represents the reliability of components or channels with respect to failures that could result in loss of the safety function.
A higher MTTFd indicates a lower expected rate of dangerous failure. When evaluating the complete safety function, the reliability of the components within each channel contributes to the achievable Performance Level.
Diagnostic Coverage
Diagnostic Coverage (DC) describes how effectively the safety system detects dangerous failures.
A system with greater diagnostic capability can identify a larger proportion of failures before they result in loss of the safety function. ISO 13849 therefore considers diagnostic coverage alongside circuit architecture and component reliability when estimating Performance Level.
Common Cause Failures
Redundant safety channels can still fail if a single condition affects both channels simultaneously. These are known as common cause failures (CCF).
For example, two independent components may still be vulnerable to the same environmental condition, installation problem, or other shared cause.
Evaluating and reducing common cause failure risk is therefore an important part of designing redundant safety systems.
Fault Behavior
The way a safety circuit responds when a component fails also affects its safety capability.
For some architectures, particularly Category 2 systems, fault behavior may need to be evaluated using methods such as failure mode and effects analysis (FMEA) or fault tree analysis (FTA).
These analyses help determine whether a fault can prevent the safety function from operating as intended and whether additional measures are needed.
Safety-Related Software
When programmable controls are part of a safety function, the software development process must also address systematic faults.
Safety-related user software should be structured so that it can be understood, tested, verified, and maintained throughout its lifecycle. Software design is therefore part of the overall safety function assessment rather than separate from the hardware evaluation.
Systematic Failures
Not all failures are random component failures. Systematic failures can originate from identifiable causes associated with design, manufacturing, installation, operating procedures, or documentation.
Addressing these failures may require changing the design or the process that created the condition rather than simply selecting a component with a higher reliability rating.
Other Conditions That Can Affect Performance Level
The achieved Performance Level can also depend on conditions surrounding the application, including:
These factors reinforce why Performance Level should be evaluated for the complete safety function in its actual application.
Performance Level and Safety Integrity Level Are Related, but Not Interchangeable
Performance Level under ISO 13849 and Safety Integrity Level (SIL) under IEC 62061 are both methods of expressing functional safety capability, but they are established using different standards and assessment methods.
Approximate relationships can be made between the two systems. For example, PLb and PLc generally correspond to SIL 1, PLd to SIL 2, and PLe to SIL 3. However, a SIL value should not simply be converted into a Performance Level without evaluating the requirements of the applicable standard.
Performance Level Depends on the Complete Safety Function
Determining machine safety Performance Level requires more than selecting safety-rated devices. The complete circuit must be evaluated, including its architecture, component reliability, diagnostic capability, resistance to common cause failures, fault behavior, and any safety-related software.
Evaluating these factors together helps confirm whether the safety function achieves the Performance Level established by the machine risk assessment.
AIR TECHNOLOGY & SERVICES