KP8, KP8F, KP32F 
Operating Instructions, 11/2011, A5E03284305-02 
95 
Fail-safe operation of KP8F and KP32F 
7
7.1  Overview 
Fail-safe mode    
In fail-safe mode the HMI device recognizes signal states from suitable fail-safe sensors and 
sends corresponding safety telegrams to the fail-safe controller where the safety program 
runs. The fail-safe controller and the HMI device communicate with each other using the fail-
safe protocol "PROFIsafe". 
Safety functions   
During fail-safe mode, safety functions are activated in both HMI and the fail-safe controller 
which recognize faults and react to them. 
In the following cases, the fitting system unit must be run in a secure operating state: 
●  The EMERGENCY STOP button is pressed. 
●  An sensor was actuated. 
●  A diagnosable error has occurred. 
Reaction to pressed EMERGENCY STOP buttons or activation of sensor    
If the EMERGENCY-STOP button was pressed or sensor was activated, the related BIT is 
sent to the controller in a safety-related manner. The controller program analyzes if the 
EMERGENCY STOP button was pressed or the sensor was activated. 
 
 
Note 
Which reactions this bit activates in the controller and thus, in the system, is the task of the 
user. Tasks include: 
•  Configuring required responses appropriate for the EMERGENCY STOP in the controller
•  Setting measures to repair the cause of an EMERGENCY STOP 
•  Configuring the startup behavior after an EMERGENCY STOP 
The response to an EMERGENCY STOP or activation of the sensor, measures and startup 
behavior must be described in the system documentation.