Functional Safety Certification for Hazardous-Environment Robots: IEC 61508 Explained

Date
2027-06-09
Location
Online
Host
Zach L

About this event

A Live Demonstration for Quality Engineers pursuing functional safety certification. A live 30-minute live demonstration on IEC 61508 (Functional Safety of E/E/PE Systems) for hazardous-environment robots, built for quality engineers pursuing functional safety certification. What We'll Cover: What IEC 61508 (Functional Safety of E/E/PE Systems) requires and how its scope applies to hazardous-environment robots Mapping IEC 61508 clauses to the certification evidence assessors expect System-specific hazards and safety functions typical of hazardous-environment robots Common findings that delay certification, and how to avoid them A practical readiness roadmap for quality engineers preparing for assessment Related topics: IEC 61508 · Hazardous-Environment Robots · functional safety certificat

Topics

Registration

View event page

About IEC 61508 (Functional Safety of E/E/PE Systems)

This event covers the compliance, engineering, and verification requirements defined by IEC 61508.

IEC 61508 is the foundational international standard for functional safety of electrical, electronic, and programmable electronic (E/E/PE) safety-related systems. It defines a complete safety lifecycle — from hazard and risk analysis through design, realization, operation, maintenance, and decommissioning — and is the parent standard from which sector standards such as ISO 26262 (automotive), IEC 61511 (process), and IEC 62061 (machinery) are derived.

What it regulates

Any E/E/PE system performing safety functions where failure could contribute to hazardous events, across all industry sectors unless a sector-specific derivative applies.

Who must comply

Manufacturers and integrators of safety instrumented systems, safety controllers, sensors and actuators used in safety functions; suppliers seeking SIL capability certification for components; and end users assembling safety functions from certified elements.

Key requirements of IEC 61508

  • Part 1: General requirements and the overall safety lifecycle
  • Part 2: Requirements for E/E/PE safety-related systems (hardware)
  • Part 3: Software requirements
  • Part 4: Definitions and abbreviations
  • Part 5: Examples of methods for determining safety integrity levels
  • Part 6: Guidelines on the application of Parts 2 and 3
  • Part 7: Overview of techniques and measures

Key concepts: IEC 61508

Safety Integrity Level (SIL)
A discrete level (SIL 1 to SIL 4) quantifying the required risk reduction of a safety function, with SIL 4 the most demanding.
Safety lifecycle
The end-to-end framework of 16 phases covering a safety system from concept and hazard analysis through decommissioning.
Hardware Fault Tolerance (HFT)
The ability of a subsystem to continue performing its safety function in the presence of one or more hardware faults.
PFD / PFH
Probability of dangerous Failure on Demand (low-demand mode) and Probability of dangerous Failure per Hour (high-demand/continuous mode) — the quantitative targets a SIL assigns.
Proven in use
An alternative route to demonstrating element suitability based on documented operational history rather than full development evidence.
Safe Failure Fraction (SFF)
The proportion of failures that are either safe or detected dangerous failures, used with HFT in architectural constraints.
Systematic capability
A measure (SC 1-4) of confidence that systematic faults have been avoided or controlled through lifecycle rigor.

Frequently asked questions: IEC 61508

Does IEC 61508 certification apply to a whole machine?

No. IEC 61508 certifies safety-related systems and elements (controllers, sensors, software). Machinery-level conformity typically flows through ISO 13849 or IEC 62061 for the safety functions, and the EU Machinery Regulation for the machine as a whole.

When is IEC 61508 used directly instead of a sector standard?

When no sector derivative exists for the application (for example novel industrial equipment), when developing elements intended for use across sectors, or when a supplier wants a SIL-capable component usable under multiple derivative standards.

What is the difference between low-demand and high-demand mode?

Low-demand safety functions are called upon infrequently (less than once per year, measured by PFD), such as an emergency shutdown. High-demand or continuous functions operate frequently or constantly (measured by PFH), such as a machine guard interlock or a drive's safe torque off.

What is the difference between SIL 2 and SIL 3?

Each SIL step represents roughly an order of magnitude more risk reduction. SIL 3 imposes stricter targets for random hardware failure probability, tighter architectural constraints (higher HFT or SFF), and substantially more rigorous techniques against systematic faults in both hardware and software development.

Standard information based on the published text of IEC 61508 (Functional Safety of E/E/PE Systems). Event content is provided by the host. For authoritative guidance, consult the official standard body.