Guide · PDF · 13 pages

Robot Cell Safety Circuit Design Guide

A practical, step-by-step framework for designing safety-related electrical control systems for industrial robot cells — written by a practicing Chartered Engineer and Certified Machinery Safety Expert.

ISO 13849-1 ISO 12100 ISO 10218 PLe wiring example Pilz PNOZ S4 KUKA KRC4 CE / UKCA marking Legacy machine integration CEng · CMSE®
Buy now — £39 →
£39
Instant PDF download · 13 pages
  • Safety design pathway — 11-step process
  • ISO 13849-1 risk graph — S, F, P parameters
  • Category B through Cat 4 explained
  • Real PLe wiring — Pilz PNOZ S4 + KRC4
  • Legacy machine integration myths debunked
  • E-stop strategy — link or label
  • SISTEMA validation guidance
  • Technical File requirements
  • Full referenced standards list
Buy now →
Sam Reynolds CEng CMSE®
MSc Professional Engineering · University of Derby
Automation & Robotics Engineer · path2.io

Safety Design Pathway

Safety design for a robot cell is a structured process, not a single step. The full pathway runs from hazard identification through to Declaration of Conformity:

The PDF guide covers each step in detail with the relevant standard referenced at every point.

The Regulatory Framework

Robot cell safety in the UK and EU sits within a hierarchy of legislation and harmonised standards. Applying the harmonised standards gives presumption of conformity with the Machinery Directive — meaning you don't have to prove compliance independently, the standards do it for you.

Safety PLCs do not require IEC 62061. A Pilz PNOZmulti or Siemens Safety CPU is fully certifiable under ISO 13849-1 alone. IEC 62061 is not a more rigorous alternative — it is a different route for different system architectures.

Risk Assessment and PLr Determination

For each safety function in the cell, the ISO 13849-1 risk graph uses three parameters to determine the required Performance Level:

For a standard robot cell e-stop the assessment gives S2 (robot at full speed, crushing injury), F2 (operators in proximity regularly), P2 (no realistic means of avoidance) — which maps to PLe. Safety door interlocks on a running cell typically reach the same conclusion. Guard locking functions and enabling devices for teach mode commonly land at PLd.

PLr is assigned to individual safety functions, not to the machine as a whole. A robot cell will typically have several safety functions each with their own PLr — e-stop, door interlock, guard locking, and enabling device are assessed separately.

Circuit Architecture and Categories

ISO 13849-1 defines five circuit Categories (B through 4), each setting different architectural requirements. Category determines the maximum achievable PL regardless of component quality.

The most common serious error: correctly determining PLe is required, then wiring to Category 3. A single-channel fault in a Category 3 circuit is detected on the next demand — in a Category 4 circuit it is detected immediately. For PLe safety functions this distinction is a legal requirement under the Machinery Directive, not a design preference.

Wiring Example — PLe / Category 4

The following is taken from a real KUKA KR120 R2700 robot cell installation. Safety relay: Pilz PNOZ S4 (Category 4, PLe, cross-fault detection, manual monitored reset).

Circuit topology

Channel 1: +24V → S1 NC → S3 NC → S4 NC → S10 NC → PNOZ S4 terminals S11/S12
Channel 2: +24V → S1 NC → S3 NC → S4 NC → S10 NC → PNOZ S4 terminals S21/S22

S1, S3, S4 are e-stop buttons (dual NC contacts). S10 is the coded magnetic door interlock (dual NC contacts). Each device contributes one NC contact to CH1 and one to CH2 — all wired in series on their respective channel.

To achieve PLd / Category 3 with identical external wiring, substitute the PNOZ S4 for a PNOZ X3. All terminal connections are the same — the Category difference is internal to the relay. The PNOZ X3 does not perform cross-fault detection on the input channels.

The EDM (External Device Monitoring) loop is critical: if either output contactor KM1 or KM2 fails to drop out, the NC auxiliary contacts open, the PNOZ S4 detects the discrepancy via Y32, and the relay locks out — preventing restart with a welded contactor. This is a Category 4 requirement.

Integrating Legacy Machines

Risk assess the interface, not the whole machine

When connecting a robot cell to existing machinery, the legal requirement is to risk assess the point of integration — what new hazards does combining these machines create? If the connection does not introduce new hazards relating to the legacy machine's existing safety systems, those systems do not need redesigning to current standards. The obligation is proportionate to the change.

E-stop strategy — link or label

Two valid approaches: link the e-stop circuits so that activating either stops both, or keep them separate and label every button to indicate which equipment it controls. Linking is appropriate where a hazardous interaction zone exists between the two machines. Separate circuits are acceptable where the machines can safely continue operating independently.

If e-stop circuits are not linked, labelling is a legal requirement under ISO 13850 — not a recommendation. An operator in an emergency cannot be expected to know from memory which button covers which equipment. Photographs of all labelled buttons belong in the Technical File.

The PL myth

There is no requirement in ISO 13849-1, ISO 10218-2, or the Machinery Directive that a connected legacy machine must have its safety circuits upgraded to match the PLe of the robot cell. Performance Level is assigned to individual safety functions, not to machines or installations as a whole. This misreading has led to companies unnecessarily replacing entire legacy control panels.

Validation and Documentation

SISTEMA (free from the German IFA institute) is the standard tool for calculating achieved PL under ISO 13849-1. For each safety function it takes the circuit Category, component PFHD values, MTTFd, Diagnostic Coverage, and CCF score — and outputs the achieved PL. Component PFHD values are published in manufacturer datasheets; Pilz and Siemens both provide SISTEMA libraries for direct import.

Functional testing at commissioning must verify: each e-stop de-energises the safety relay, door interlock opens the circuit, single-channel fault simulation confirms the safety function is maintained, EDM locks out on contactor failure, and manual reset is required after every event. Test records — signed and dated — go into the Technical File alongside the SISTEMA report, wiring diagrams, and component datasheets.

Referenced Standards

Get the guide

13 pages. Everything you need, nothing you don't. Instant PDF download.

Buy now — £39 →