Data Declaration: Safety Systems. The Hardware Has Been Subjected To A Failure Modes and Effects Analysis (FMEA)
Data Declaration: Safety Systems. The Hardware Has Been Subjected To A Failure Modes and Effects Analysis (FMEA)
Data Declaration: Safety Systems. The Hardware Has Been Subjected To A Failure Modes and Effects Analysis (FMEA)
IEC 61508
Data Declaration
DOCUMENT NO. MTL08FMEA4517/3
This document is issued as a summary of the hardware failure data affecting the application of the
equipment as a sub-system being part of a Safety Function intended to conform with the
requirements of IEC61508 - Functional Safety of Electrical/Electronic/Programmable Electronic
Safety Systems. The hardware has been subjected to a Failure Modes and Effects Analysis (FMEA)
to determine the specific failure modes and failure rates with the relevant results presented herein.
Product Description
The MTL4511, MTL4514, MTL5511 and MTL5514 are 1 channel and the MTL4516, MTL4516C,
MTL4517, MTL5516C and MTL5517 are 2-channel digital input interface modules which enable
respectively one or two safe area loads to be controlled through relay contacts by one or two
switches or proximity detectors located in a hazardous area. The input sensor excitation provided to
the hazardous area is limited to comply with the requirements of IIC gas atmospheres. Switches are
provided to select phase reversal operation mode and to enable/disable the line fault detection.
The definitions for product failure of these modules were determined as:-
The above failure rates apply to the operation of a single channel and apply whether normal phase or
reverse phase is selected.
For 2-channel modules, the above figures apply to either channel 1 or channel 2. Both channels of a
2-channel module should not be used in the same safety function.
Note that failures may affect both channels simultaneously.
1
NO (normally open) relay contact closed, NC (normally closed) contact open (if available)
2
NO (normally open) relay contact open, NC (normally closed) contact closed (if available)
FMEA/DD4517/08/08 Page 1 of 2
FMEA
IEC 61508
Example of use in a safety function
In this example, the application context is assumed to be:
In this example, the safe failure fraction is 96.2%. However, other constraints, in particular the use of
unmonitored relay contact outputs, limit these devices to be used as single devices in Safety
Instrumented Functions up to SIL2.
Notes
• FITs means failures per 109 hours or failures per thousand million hours.
• Reliability data for this analysis is taken from IEC TR 62380:2004 Reliability Data
Handbook.
• Failure mode distributions are taken principally from IEC 62061:2005 Safety of Machinery.
• Both channels of a 2-channel module should not be used in the same safety function unless
due allowance is made for the occurrence of common cause failures affecting both
channels.
• Proof testing must be carried out according to the application requirements, but it is
recommended that this be carried out at least once every three years.
• Consideration should be made of the normal lifetime for a device of this type which would
be in the region of ten years.
• There are no internal diagnostic elements of this product.
• For all other product parameters related to its application (voltage range, environment, etc.)
please refer to the published MTL data sheet for this product, at www.mtl-inst.com.
FMEA/DD4517/08/08 Page 2 of 2