16 Functional Safety
16.1 Safety Parameters
Table 26: Required and achieved SIL
Required SIL
due to
EN81 (or
due to risk
analysis,
refer to
comments)
Achieved
SIL due
to PFHD
and SFF
Percentage
of required
SIL
EN81-20 §
5.6.2.2.1.6 a.)
EN81-20
§5.12.1.5.2.1 e.)
This function is named in the EN81
but without any demand for a SIL
Overspeed
Inspection
(final-
tripping)
Not named in the EN81 secures
braking distance for pre-triggered
stopping system, therefore SIL3
The safety function “over-speed teach
(pre-tripping)” is a substitute for ETSL,
which cannot be carried out in teach
mode. Because ETSL is SIL 3
according to EN81-20, Annex A,
“overspeed teach (pre- tripping)” is
also SIL3.
Cares for additional safety before
and during commissioning
§ 5.7.3.4
(under constraints)
Check on
correct
travel
direction in
Inspection
In order to complete safety of “In-
spection limit switches”, therefore this
is SIL2
EN 81-21 §5.5.2.2 /
§5.7.2.2
(under constraints)
When the positions where the pre-
triggered stopping system trips are
defined, a certain stopping distance
must be taken. The stopping distance
depends directly from the velocity.
Therefore, a worst-case value for the
velocity must be assumed. The safety
function “over-speed inspection (final
tripping)” supervises that this worst-
case velocity is not exceeded. There-
fore, it is the same SIL like pre-
triggered stopping system: SIL 3.
In case the eSGC-actuator is enabled
and connected with a suitable brak-