Machine Safety Standards for Control Systems: What Manufacturers Need to Know

Industrial automation is designed to make machinery operate efficiently, consistently and with less manual intervention. But making a machine operate automatically also means ensuring that the control system responds appropriately when something goes wrong.
What happens when an operator opens a guard?
What should happen when an emergency stop is pressed?
Could a motor restart unexpectedly after a power interruption?
What happens if a safety sensor, contactor or control component fails?
These are not simply PLC programming questions. They form part of the wider discipline of machine safety and functional safety.
Standards including BS EN 60204-1, BS EN ISO 13849-1 and IEC 62061 provide important frameworks for designing and evaluating safety-related aspects of machinery and its control systems.
Understanding their different roles is useful for anyone specifying, modifying or maintaining industrial machinery.
Machine safety standards starts with risk assessment
Before deciding which safety components to install, the risks associated with the machine need to be understood.
A risk assessment considers the hazards associated with the machinery, who could be exposed to them and under what circumstances that exposure could occur.
These might include hazards associated with moving machinery, rotating equipment, crushing, cutting, stored energy, electrical systems or unexpected movement.
The objective is then to reduce risk through an appropriate hierarchy of measures.
Where risks cannot be adequately eliminated through inherently safe design or physical protective measures, safety-related control functions may form part of the overall risk reduction strategy.
This is an important distinction.
A safety PLC, emergency stop or interlocked guard should not be treated as a substitute for considering whether the hazard could have been reduced through the machine design itself.
What is a safety-related control system?
A safety-related control system performs functions intended to reduce risk when particular conditions occur.
Consider a machine with an access door protecting a hazardous moving mechanism.
The machine may need to detect when that guard is opened and bring the hazardous movement to an appropriate safe condition.
That function can involve several elements:
Input: A safety-rated guard switch detects the position of the door.
Logic: A safety relay or safety PLC evaluates the signal.
Output: Contactors, drives or other appropriate devices remove or control the hazardous movement.
The complete safety function matters.
Simply fitting a safety-rated sensor does not automatically make the entire system safe. The architecture, components, diagnostics, wiring, software and behaviour of the system all need to be considered.
BS EN 60204-1 and the electrical equipment of machines
BS EN 60204-1 is one of the key standards encountered when dealing with the electrical equipment of machinery.
It covers electrical, electronic and programmable electronic equipment and systems associated with machines and addresses areas such as protective measures, control circuits, operator interfaces, wiring practices, documentation and verification.
For control panel designers, machine builders and automation engineers, it provides an important framework for the electrical aspects of machine design.
It also addresses subjects such as emergency stop functions and the prevention of unexpected start-up.
However, BS EN 60204-1 should not be viewed as the only machine safety standard that may be relevant.
Depending on the machinery and its risks, additional standards may need to be considered.
What is BS EN ISO 13849-1?
BS EN ISO 13849-1 deals specifically with the safety-related parts of control systems.
One of its best-known concepts is the Performance Level, or PL.
Performance Levels are designated PL a through PL e, with increasing ability to perform a safety function under foreseeable conditions.
The required Performance Level is determined from the risk associated with the particular safety function.
This means the question should not be:
“What Performance Level should this machine have?”
Instead, individual safety functions need to be considered.
For example, an emergency stop function and a guard interlocking function may have particular safety requirements based on the risks they are intended to reduce.
The control architecture can then be designed and validated accordingly.
What is IEC 62061?
IEC 62061 provides another framework for the functional safety of safety-related control systems for machinery.
Rather than Performance Levels, IEC 62061 uses Safety Integrity Levels (SIL) for safety functions within its scope.
Both ISO 13849-1 and IEC 62061 can therefore be encountered when engineers are designing safety-related control systems.
The appropriate approach depends on the application, technology and engineering methodology being used.
What matters is that the required safety performance is determined systematically from the risk and that the completed safety function is appropriately designed and validated.
What is the difference between a standard PLC and a safety PLC?
A conventional PLC is designed to control the normal operation of machinery.
It may control conveyors, motors, valves, production sequences and process conditions.
A safety PLC is specifically designed and certified for safety-related control functions within the conditions of its intended use.
Safety PLCs can provide significant flexibility in machinery with multiple safety devices or more complex safety logic.
However, installing a safety PLC does not automatically make a machine compliant or safe.
The complete safety function still needs to be correctly designed.
Inputs, outputs, wiring, devices, software, diagnostics and the required safety performance all form part of the system.
A sophisticated safety controller cannot compensate for a poorly designed safety concept.
Emergency stops are not the entire safety system
The emergency stop button is probably the most recognisable machine safety device.
It is also sometimes given more responsibility than it should have.
An emergency stop provides a means of responding to an emergency situation. It should not normally be considered the primary method of protecting people from hazards during routine operation.
Guarding, interlocks, safe operating procedures and appropriately engineered safety functions may all be required depending on the risk.
The location and behaviour of emergency stop devices also need to be considered as part of the machine design.
Adding a red mushroom pushbutton to a control panel does not, by itself, create a safe machine.
Guard switches and interlocking
Physical guards are widely used to prevent access to hazardous parts of machinery.
Where access is required during normal operation or maintenance, movable guards may incorporate interlocking devices.
Opening the guard can then initiate a safety function that prevents or stops hazardous operation.
The design needs to consider more than simply whether the guard switch changes state.
Engineers may need to consider how quickly hazardous movement stops, whether the machine can restart while the guard is open, what happens if a device fails and whether someone could reach the hazard before it has reached a safe condition.
For some machinery, guard locking may also be necessary where the hazard remains present for a period after a stop command has been issued.
Preventing unexpected start-up
Unexpected machine movement can create serious risks.
Imagine an engineer clearing a blockage and the machine suddenly restarts because a sensor changes state or power is restored.
Control systems therefore need to consider the circumstances under which machinery is permitted to start or restart.
After certain interruptions or safety events, deliberate operator action may be required before normal operation can resume.
The precise requirements depend on the machine and the safety strategy, but the underlying principle is straightforward:
Restoring power or resetting a safety device should not automatically create a hazardous situation.
Resetting a safety function and starting the machinery are not necessarily the same action.
Variable speed drives and machine safety
Variable speed drives are now common within industrial machinery, and modern drives can provide safety-related functions.
One widely encountered example is Safe Torque Off (STO).
STO can prevent the drive from producing motor torque as part of an appropriately designed safety function.
Other safety-related drive functions may also be available depending on the equipment and application.
However, a drive containing an STO function does not mean that every machine hazard has been addressed.
Engineers still need to understand what happens mechanically when torque is removed.
A vertical load, for example, may present different risks from a horizontal conveyor.
Safety functions must therefore be designed around the actual machine behaviour rather than simply around the features available in the automation hardware.
Safety and the control panel
The control panel is where many of the machine's safety-related electrical components come together.
Panel design may need to consider segregation, protective devices, contactors, safety relays, safety PLCs, drive safety functions, terminal arrangements and the routing and identification of safety-related circuits.
Clear electrical documentation is particularly important.
When maintenance engineers investigate or modify machinery, they need to be able to distinguish safety-related circuits and understand how the safety functions operate.
Poor documentation can make future modifications considerably more difficult and can increase the risk of unintended changes to the safety system.
Machine modifications can change the safety requirements
One of the most important times to review machine safety is when existing equipment is modified.
Adding a conveyor, changing a motor, replacing a drive, altering guarding or changing the operating sequence may affect risks that were considered when the machine was originally designed.
Similarly, a PLC upgrade should not automatically be treated as a simple hardware substitution if the controller interacts with safety-related parts of the machine.
The modification provides an opportunity to ask whether the existing safety concept remains appropriate and whether any changes have introduced new hazards.
This is particularly important on older machinery that may have undergone numerous alterations throughout its working life.
Documentation and validation matter
A safety system should not rely on somebody remembering why it was designed a particular way.
The safety functions, design assumptions, electrical information and relevant calculations should be appropriately documented.
Validation is also essential.
The objective is to demonstrate that the safety-related parts of the control system actually perform the intended safety functions and meet the specified requirements.
Testing that an emergency stop stops the machine is important, but validation can involve much more than observing that the machinery stops once.
Fault conditions, reset behaviour, diagnostics and the architecture of the safety function may all need to be considered.
Safety systems need maintenance too
Machine safety does not end when the equipment is commissioned.
Guard switches can become damaged. Cables deteriorate. Contactors wear. Devices can be incorrectly adjusted and machinery can be modified.
Safety systems therefore need to form part of the ongoing maintenance strategy.
Repeated safety faults should also be investigated rather than simply reset.
If operators or maintenance personnel regularly experience nuisance trips, there may be a temptation to bypass or defeat a safety device to keep production running.
That is a strong indication that the underlying problem needs to be properly investigated.
A safety system should protect people while still being designed in a way that supports practical operation and maintenance.
Functional safety should be engineered, not added afterwards
Machine safety is most effective when it is considered from the beginning of the project.
Risk assessment informs the required safety functions. The safety functions influence the electrical and control architecture. Components are then selected and engineered to achieve the required performance.
Trying to add safety after the machine and control system have already been designed can result in unnecessary complexity and compromise.
The same principle applies when upgrading existing equipment.
A control system upgrade is an opportunity to consider not only what the machine needs to do, but also how people interact with it and how hazardous situations are controlled.
Building safer, maintainable control systems
Machine safety standards can appear complex because no single standard answers every question.
BS EN 60204-1 addresses important aspects of the electrical equipment of machinery. BS EN ISO 13849-1 and IEC 62061 provide frameworks for safety-related control systems, while additional machinery-specific and safety standards may apply depending on the equipment and application.
The important point is that safety cannot be reduced to a checklist of components.
A safe control system begins with understanding the hazards, determining the necessary risk reduction and engineering the appropriate safety functions around the real behaviour of the machinery.
At Stratos Control Systems, we design, build and upgrade industrial control systems and control panels with consideration for the wider electrical, automation and machine requirements of the application.
Whether you are planning a new control panel, modernising ageing machinery or reviewing an existing automation system, considering machine safety early in the engineering process can help avoid difficult and expensive changes later.
Speak to Stratos Control Systems about industrial control panel design, control system upgrades and machine automation.


