ATV32 Safety Functions Manual EN S1A45606 02
ATV32 Safety Functions Manual EN S1A45606 02
XXXXXX
Altivar 32
Variable speed drives
for synchronous and asynchronous motors
www.schneider-electric.com
Important information
The information provided in this documentation contains general descriptions and/or technical characteristics
of the performance of the products contained herein. This documentation is not intended as a substitute for
and is not to be used for determining suitability or reliability of these products for specific user applications. It
is the duty of any such user or integrator to perform the appropriate and complete risk analysis, evaluation and
testing of the products with respect to the relevant specific application or use thereof. Neither Schneider
Electric nor any of its affiliates or subsidiaries shall be responsible or liable for misuse of the information
contained herein. If you have any suggestions for improvements or amendments or have found errors in this
publication, please notify us.
No part of this document may be reproduced in any form or by any means, electronic or mechanical, including
photocopying, without express written permission of Schneider Electric.
All pertinent state, regional, and local safety regulations must be observed when installing and using this
product. For reasons of safety and to help ensure compliance with documented system data, only the
manufacturer should perform repairs to components.
When devices are used for applications with technical safety requirements, the relevant instructions must be
followed.
Failure to use Schneider Electric software or approved software with our hardware products may result in
injury, harm, or improper operating results.
Failure to observe this information can result in injury or equipment damage.
© 2011 Schneider Electric. All rights reserved.
2 S1A45606 06/2011
Table of contents
Table of contents
Safety Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
About the book . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
Chapter 1 Before you begin . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9
Safety instructions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
Qualification of personnel and use . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
Chapter 2 Overview. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
Standards and Terminology. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
Basics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
Chapter 3 Description . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19
(STO) Safe Torque Off . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
(SS1) Safe Stop 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
(SLS) Safely Limited Speed. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
Chapter 4 Formulas for calculation of safety parameters. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
SLS type 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28
SLS type 2 & type 3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 30
SS1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33
Chapter 5 Incompatibility with safety functions. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35
Limitations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 36
Chapter 6 Safety monitoring . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 39
Status of safety functions. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40
Dedicated HMI . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 41
Detected fault given by the drive . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 42
Chapter 7 Technical data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43
Electrical Data . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44
Getting and operating the safety function . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 45
Safety function capability . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 46
Debounce time and response time . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 48
Several certified architectures . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49
Process system SF - Case 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 50
Process system SF - Case 2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 52
Process system SF - Case 3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 53
Process system SF - Case 4 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55
Process system SF - Case 5 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 57
Process system SF - Case 6 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59
Chapter 8 Commissioning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 61
Starting SoMove configuration. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 62
Configure Safety panel . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64
Reset Safety . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 70
Password management . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 71
Monitoring and status of safety function . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72
Chapter 9 Machine signature . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 73
Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 74
S1A45606 06/2011 3
Table of contents
4 S1A45606 06/2011
Safety Information
§
Important Information
NOTICE
Read these instructions carefully, and look at the equipment to become familiar with the device before trying
to install, operate, or maintain it. The following special messages may appear throughout this documentation
or on the equipment to warn of potential hazards or to call attention to information that clarifies or simplifies a
procedure.
The addition of this symbol to a Danger or Warning safety label indicates that an electrical hazard
exists, which will result in personal injury if the instructions are not followed.
This is the safety alert symbol. It is used to alert you to potential personal injury hazards. Obey all
safety messages that follow this symbol to avoid possible injury or death.
DANGER
DANGER indicates an imminently hazardous situation, which, if not avoided, will result in death or serious
injury.
WARNING
WARNING indicates a potentially hazardous situation, which, if not avoided, can result in death, serious
injury or equipment damage.
CAUTION
CAUTION indicates a potentially hazardous situation, which, if not avoided, can result in injury or
equipment damage.
CAUTION
CAUTION, used without the safety alert symbol, indicates a potentially hazardous situation which, if not
avoided, can result in equipment damage.
PLEASE NOTE
The word "drive" as used in this manual refers to the controller portion of the adjustable speed drive as defined
by NEC.
Electrical equipment should be installed, operated, serviced, and maintained only by qualified personnel. No
responsibility is assumed by Schneider Electric for any consequences arising out of the use of this product.
S1A45606 06/2011 5
6 S1A45606 06/2011
About the book
At a Glance
Document Scope
The purpose of this document is to provide information about safety functions incorporated in Altivar 32. These
functions allow you to develop applications oriented in the protection of man and machine.
Validity Note
This documentation is valid for the Altivar 32 drive.
Related Documents
You can download the latest versions of these technical publications and other technical information from our
website at www.schneider-electric.com.
S1A45606 06/2011 7
8 S1A45606 06/2011
Before you begin
S1A45606 06/2011 9
Before you begin
Safety instructions
DANGER
HAZARD OF ELECTRIC SHOCK, EXPLOSION, OR ARC FLASH
z Read and understand this manual before installing or operating the drive. Installation, adjustment, repair,
and maintenance must be performed by qualified personnel.
z The user is responsible for compliance with all international and national electrical code requirements with
respect to grounding of all equipment.
z Many parts of this drive, including the printed circuit boards, operate at the line voltage. DO NOT TOUCH.
Use only electrically insulated tools.
z DO NOT touch unshielded components or terminal strip screw connections with voltage present.
z DO NOT short across terminals PA/+ and PC/– or across the DC bus capacitors.
z Before servicing the drive:
- Disconnect all power, including external control power that may be present.
- Place a “DO NOT TURN ON” label on all power disconnects.
- Lock all power disconnects in the open position.
- WAIT 15 MINUTES to allow the DC bus capacitors to discharge.
- Measure the voltage of the DC bus between the PA/+ and PC/– terminals to ensure that the voltage is less
than 42 Vdc.
- If the DC bus capacitors do not discharge completely, contact your local Schneider Electric representative.
Do not repair or operate the drive.
z Install and close all covers before applying power or starting and stopping the drive.
Failure to follow these instructions will result in death or serious injury.
DANGER
UNINTENDED EQUIPMENT OPERATION
z Read and understand this manual before installing or operating the drive.
z Any changes made to the parameter settings must be performed by qualified personnel.
Failure to follow these instructions will result in death or serious injury.
WARNING
DAMAGED DRIVE EQUIPMENT
Do not operate or install any drive or drive accessory that appears damaged.
Failure to follow these instructions can result in death, serious injury, or equipment damage.
10 S1A45606 06/2011
Before you begin
WARNING
LOSS OF CONTROL
z The designer of any wiring scheme must consider the potential failure modes of control channels and, for
certain critical control functions, provide a means to achieve a safe state during and after a channel failure.
Examples of critical control functions are emergency stop and overtravel stop.
z Separate or redundant control channels must be provided for critical control functions.
z Each implementation of a control system must be individually and thoroughly tested for proper operation
before being placed into service.
z System control channels may include links carried out by the communication. Consideration must be given
to the implications of unanticipated transmission delays or failures of the link1.
Failure to follow these instructions can result in death, serious injury, or equipment damage.
1. For additional information, refer to NEMA ICS 1.1 (latest edition), “Safety Guidelines for the Application, Installation, and Maintenance of Solid
State Control” and to NEMA ICS 7.1 (latest edition), “Safety Standards for Construction and Guide for Selection, Installation and Operation
of Adjustable-Speed Drive Systems.”
CAUTION
INCOMPATIBLE LINE VOLTAGE
Before turning on and configuring the drive, ensure that the line voltage is compatible with the supply voltage
range shown on the drive nameplate. The drive may be damaged if the line voltage is not compatible.
Failure to follow these instructions can result in injury or equipment damage.
CAUTION
RISK OF DERATED PERFORMANCE DUE TO CAPACITOR AGING
The product capacitor performances after a long time storage above 2 years can be degraded.
In that case, before using the product , apply the following procedure:
z Use a variable AC supply connected between L1 and L2 (even for ATV32pppN4 references).
z Increase AC supply voltage to have:
- 25% of rated voltage during 30 min
- 50% of rated voltage during 30 min
- 75% of rated voltage during 30 min
- 100% of rated voltage during 30 min
Failure to follow these instructions can result in equipment damage.
S1A45606 06/2011 11
Before you begin
Qualification of personnel
Only appropriately trained persons who are familiar with and understand the contents of this manual and all other
pertinent product documentation are authorized to work on and with this product. In addition, these persons must
have received safety training to recognize and avoid hazards involved. These persons must have sufficient
technical training, knowledge and experience and be able to foresee and detect potential hazards that may be
caused by using the product, by changing the settings and by the mechanical, electrical and electronic
equipment of the entire system in which the product is used.
All persons working on and with the product must be fully familiar with all applicable standards, directives, and
accident prevention regulations when performing such work.
Intended use
The functions described in this manual are only intended for use with the basic product; you must read and
understand the appropriate product manual.
The product may only be used in compliance with all applicable safety regulations and directives, the specified
requirements and the technical data.
Prior to using the product, you must perform a risk assessment in view of the planned application. Based on the
results, the appropriate safety measures must be implemented.
Since the product is used as a component in an entire system, you must ensure the safety of persons by means
of the design of this entire system (for example, machine design).
Operate the product only with the specified cables and accessories. Use only genuine accessories and spare
parts.
Any use other than the use explicitly permitted is prohibited and can result in hazards.
Electrical equipment should be installed, operated, serviced, and maintained only by qualified personnel.
The product must NEVER be operated in explosive atmospheres (hazardous locations, Ex areas).
12 S1A45606 06/2011
Overview
Overview
S1A45606 06/2011 13
Overview
Introduction
The safety functions incorporated in Altivar 32, allow you to develop applications oriented in the protection of
man and machine. The safety functions are configured with SoMove software.
Safety integrated functions provides the following benefits:
z Additional standards-compliant safety functions
z Replacement of external safety equipment
z Reduced wiring efforts and space requirements
z Reduced costs
The Altivar 32 drives are compliant with normative requirements to implement the safety functions.
Notation
The graphic display terminal (to be ordered separately - reference VW3 A1 101) menus are shown in square
brackets.
Example: [COMMUNICATION]
The integrated 7-segment display terminal menus are shown in round brackets.
Example: (COM-)
Parameter names are displayed on the graphic display terminal in square brackets.
Example: [Fallback speed]
Parameter codes are displayed on the integrated 7-segment display terminal in round brackets.
Example: (LFF)
14 S1A45606 06/2011
Overview
General
Technical terms, terminology and the corresponding descriptions in this manual are intended to use the terms
or definitions of the pertinent standards.
In the area of drive systems, this includes, but is not limited to, terms such as "safety function", "safe state",
"fault", "fault reset", "failure", "error", "error message", "warning", "warning message", etc.
Among others, these standards include:
z IEC 61800 series: "Adjustable speed electrical power drive systems"
z IEC 61508 series Ed.2: "Functional safety of electrical/electronic/programmable electronic safety-related
systems"
z EN 954-1 Safety of machinery - Safety related parts of control systems
z EN ISO 13849-1 & 2 Safety of machinery - Safety related parts of control systems
EC Declaration of Conformity
The EC Declaration of Conformity for the EMC Directive can be obtained on www.schneider-electric.com
ATEX certification
The ATEX certificate can be obtained on www.schneider-electric.com
S1A45606 06/2011 15
Overview
Basics
Functional Safety
Automation and safety engineering are two areas that were completely separated in the past but recently have
become more and more integrated.
Engineering and installation of complex automation solutions are greatly simplified by integrated safety
functions.
Usually, the safety engineering requirements depend on the application.
The level of the requirements results from the risk and the hazard potential arising from the specific application.
PL - Performance level
The standard IEC 13849-1 defines 5 Performance levels (PL) for safety functions. “a” is the lowest level and “e”
is the highest level. Five levels (a, b, c, d, and e) correspond to different values of average probability of
dangerous failure per hour.
Performance Probability of a dangerous
Level Hardware Failure per Hour
e ≥10-8 … <10-7
d ≥10-7 … <10-6
c ≥10-6 … <3*10-6
b ≥3*10-6 … <10-5
a ≥10-5 … <10-4
16 S1A45606 06/2011
Overview
HFT – Hardware detected Fault Tolerance and SFF – Safe Failure Fraction
Depending on the SIL for the safety system, the IEC 61508 standard and SFF, Safe Failure Fraction requires a
specific hardware detected fault tolerance HFT in connection with a specific proportion of safe failures SFF (Safe
Failure Fraction).
The hardware detected fault tolerance is the ability of a system to execute the required safety function in spite
of the presence of one or more hardware detected faults.
The SFF of a system is defined as the ratio of the rate of safe failures to the total failure rate of the system.
According to IEC 61508, the maximum achievable SIL of a system is partly determined by the hardware detected
fault tolerance HFT and the safe failure fraction SFF of the system.
IEC 61508 distinguishes two types of subsystems (type A subsystem, type B subsystem). These types are
specified on the basis of criteria which the standard defines for the safety-relevant components.
SFF HFT type A subsystem HFT type B subsystem
0 1 2 0 1 2
< 60% SIL1 SIL2 SIL3 --- SIL1 SIL2
60% … < 90% SIL2 SIL3 SIL4 SIL1 SIL2 SIL3
60% … < 99% SIL3 SIL4 SIL4 SIL2 SIL3 SIL4
u 99% SIL3 SIL4 SIL4 SIL3 SIL4 SIL4
Hazards of a control system must be identified then analysed risk analysis. Mitigation of these risks continues
until their overall contribution to the hazard is considered acceptable. The tolerable level of these risks is
specified as a safety requirement in the form of a target ‘probability of a dangerous failure’ in a given period of
time, stated as a discrete SIL level.
S1A45606 06/2011 17
Overview
18 S1A45606 06/2011
Description
Description
S1A45606 06/2011 19
Description
Frequency
Actual
frequency
Time
STO
activation
z For the machine environment (IEC60204-1 & Machine Directive), reset shall not initiate a restart in any cases.
One of the most constringent case is when STO is activated, then the power supply is switch off. In this case,
if STO is deactivated during the loss of supply, the motor do not have to restart automatically. The safety
module can help prevent a spurious restart in the previous condition. So a safety module is required if the
machine initiates an automatic restart after the STO deactivation.
z E_stop of several BDM (Background Debug Module) in a PDS: the safety module has some safety outputs
for application which requires one or several safety outputs.
For other environments, the safety module is not required, except if the application requires it: System fallback
position.
20 S1A45606 06/2011
Description
Description
This function is used to stop the motor following a dedicated down ramp. The motor speed is monitored during
the down ramp. STO is initiated when the motor speed is below a specified threshold.
The unit of SS1 down ramp is in Hz/s to get the shape of the ramp you need to configure 2 parameters
[SS1 ramp unit] (SSrU) (Hz/s) to give the unit of the ramp 1 Hz/s, 10Hz/s and 100 Hz/s.
[SS1RampValue] (SSrt) (0,1) to set the value of the ramp
When the function is activated, the SS1 function has the reference priority over all other reference channels.
When a fault is detected within the safety function, the drive will trip and stop using the internal STO command.
This safety function is configured with SoMove software, see Commissioning page 61.
The SS1 status is accessible with the drive or with SoMove
Frequency
SS1 trip threshold
SS1 deceleration ramp (dV/dT)
Actual
Stop
frequency
Time
STO
activation
S1A45606 06/2011 21
Description
In accordance with the IEC 60204-1, the SS1 function generates a stop category 1 for the PDS generates a stop
category 0 after:
z the motor stop (when the motor speed is below a specified limit)
z or an application specific time delay.
22 S1A45606 06/2011
Description
Description
This function is used to limit a machine speed. The main goal is to monitor the motor speed and to adjust the
speed to a set point.
This function offers 3 types:
z SLS type 1: used to monitor the motor speed and trips in STO in case of over speed.
z SLS type 2: used to limit the motor speed to a set point and trips in STO in case of over speed.
z SLS type 3: Same as type 2 with a dedicated behavior when the motor speed is above the tolerance threshold.
Trips in STO in case of over speed.
When the function is activated, the SLS function has the reference priority to all others reference channel. This
safety function is configured with SoMove software, see commissioning. The SLS status is accessible with the
drive or with SoMove
Time
SLS
activation
S1A45606 06/2011 23
Description
SLS type 2
When the function is activated,
z If the current frequency is above the [SLS tolerance threshold] (SLtt), the drive decelerates until the [Set
point] (SLSP) frequency with the same ramp as SS1 function.
z If the current frequency is under the [SLS tolerance threshold] (SLtt) and upper the [Set point]
(SLSP), the drive decelerates until the [Set point] (SLSP) frequency with the same ramp as SS1
function.
z If the current frequency is under the [Set point] (SLSP), the speed is high limited by the set point.
Once the [Set point] (SLSP) is reached, is it still possible to vary the reference speed between [Standstill level]
(SSSL) and the [Set point] (SLSP).
While the function is activated
z If the current frequency decrease and reach the [Standstill level] (SSSL) frequency, STO is activated.
z If the current frequency or stator frequency increase and reach the [SS1 trip threshold] (SLtt), drive trips
in SAFF detected fault
Frequency
Actual
frequency
SLS trip
threshold
Setpoint
Standstill
detection Time
SLS
activation
24 S1A45606 06/2011
Description
SLS type 3
When the function is activated,
z If the current frequency is above the [SLS tolerance threshold] (SLtt) the drive decelerates until the
[Standstill level] (SSSL) frequency with the same ramp as SS1 function and a STO is set.
z If the current frequency is under the [SLS tolerance threshold] (SLtt) and upper the [Set point]
(SLSP), the drive decelerates until the [Set point] (SLSP) frequency with the same ramp as SS1 function
and it remains equal to the Setpoint frequency till the deactivation.
z If the current frequency is under the [Set point] (SLSP), the current reference is not changed but limited to
the [Set point] (SLSP).
While the function is activated,
z If the current frequency decrease and reach the [Standstill level] (SSSL) frequency, STO is activated.
z If the current frequency or stator frequency increase and reach the [SS1 trip threshold] (SLtt), drive trips
in SAFF detected fault.
The [Set point] (SLSP), is linked to the rotor frequency.
.
Frequency
Actual
frequency
SLS trip
threshold
Setpoint
Standstill
detection
Time
SLS
activation
S1A45606 06/2011 25
Description
26 S1A45606 06/2011
Formulas for calculation of safety parameters
S1A45606 06/2011 27
Formulas for calculation of safety parameters
SLS type 1
First, compute the rated motor slip frequency Fslip (Hz). It will be used afterward:
× ppn-
Fslip = FrS – Nsp
-------------------------
60
Frequency
Trip area
Fmax(SLS)
Standstill level
The recommended standstill level is:
SSSL = Fslip
If the application requires a different standstill level; it can be set accordingly with the SSSL parameter.
Protection threshold
The SLS tolerance threshold is computed by:
SLTT = 1, 2 × Fmax ( SLS ) + Fslip
28 S1A45606 06/2011
Formulas for calculation of safety parameters
Example
Code Description Value
FrS Rated motor frequency 50 Hz
Nsp Rated motor speed 1350 rpm
ppn Motor pole pair number 2
Fmax(SLS) Maximum motor frequency during SLS type 1 50 Hz
S1A45606 06/2011 29
Formulas for calculation of safety parameters
* Before configuring the SLS function, Fsetpoint(SLS) and dEC must be defined by you.
First, compute the rated motor slip frequency Fslip (Hz). It will be used afterward:
× ppn-
Fslip = FrS – Nsp
-------------------------
60
Time
SLS activation
Standstill level
The recommended standstill level is:
SSSL = Fslip
If the application requires a different standstill level; it can be set accordingly with the SSSL parameter.
30 S1A45606 06/2011
Formulas for calculation of safety parameters
SLS set-point
Set the SLS set-point parameter (SLSP) to:
SLSP = Fsetpoint ( SLS )
Protection thresholds
The SLS tolerance threshold is computed by:
SLTT = 1, 2 × SLSP + Fslip
SSTT
T(oscillation)
SLTT
SLSP
The oscillations must be lower than SLTT before the time T(oscillation) is elapsed.
If it is not, the frequency will reach the trip area and an detected SAFF fault will be
triggered.
The relationship between SSTT and T(oscillation) is:
If more time is required for stabilization, increase SSTT by steps of 1 Hz and test
again until the SAFF no longer happens.
If the elapsed time required for oscillations to be under SLTT is known, compute
SSTT directly:
If the difference between the corrected SSTT and the recommended one is impor-
tant, investigate the cause of the frequency instability.
S1A45606 06/2011 31
Formulas for calculation of safety parameters
Example
Code Description Value
FrS Rated motor frequency 50 Hz
Nsp Rated motor speed 1350 rpm
ppn Motor pole pair number 2
Fmax(SLS) Maximum motor frequency when SLS type 2/3 is activated 50 Hz
Fsetpoint(SLS) Motor frequency set-point 15 Hz
dEC Ramp deceleration 20 Hz/s
With these numerical values, the configuration of SLS type 2 & type 3 is:
1350 × 2
Fslip = 50 – --------------------- = 5Hz
60
dEC = 20 Hz/s which is between 0.1 Hz/s and 599 Hz/s so SSRU = [1 Hz/s] and SSRT = 20.0
SLSP = Fsetpoint ( SLS ) = 15Hz
SLTT = 1, 2 × SLSP + Fslip = 1, 2 × 15 + 5 = 23Hz
In this example, the frequency oscillations are allowed over SLTT during 500ms.
32 S1A45606 06/2011
Formulas for calculation of safety parameters
SS1
First, compute the rated motor slip frequency Fslip (Hz). It will be used afterward:
× ppn-
Fslip = FrS – Nsp
-------------------------
60
Frequency
Trip area STO stop
Time
SLS activation
S1A45606 06/2011 33
Formulas for calculation of safety parameters
Standstill level
The recommended standstill level is:
SSSL = Fslip
If the application requires a different standstill level; it can be set accordingly with the SSSL parameter.
Protection threshold
The SS1 ramp trip threshold is computed by:
SSTT = 0, 2 × Fmax ( SS1 )
Example
Code Description Value
FrS Rated motor frequency 50 Hz
Nsp Rated motor speed 1350 rpm
ppn Motor pole pair number 2
Fmax(SS1) Maximum motor frequency when SS1 is activated 50 Hz
dEC Ramp deceleration 20 Hz/s
34 S1A45606 06/2011
Incompatibility with safety functions
S1A45606 06/2011 35
Incompatibility with safety functions
Limitations
Type of Motor
SLS and SS1 functions on ATV32 are applicable only for asynchronous motors with open-loop control profile.
STO can be used with synchronous and asynchronous motors.
STO
Unallowed application
Application with acceleration of the load after shut down of the drive or where there are long/permanent
regenerative braking cycles are not allowed. Unallowed sharp of stop after STO request or freewheel stop.
f f
STO STO
t t
36 S1A45606 06/2011
Incompatibility with safety functions
Fault Inhibition
For some kind of detected fault, [Fault inhibit assign.] (InH) can be requested to avoid the drive to stop when
the fault occurred. The fault inhibition goal is not compatible with the safe function behavior.
When a safe function is activated, detected fault generated by the safe function SAFF can’t be inhibited.
Configuration download
In order to protect people and machine the configuration download of safe parameters is impossible with any
kind of tools. Configuration download as SoMove, keypad, Simple-loader, Multi-loader, Ethernet or mobile phone
are not possible.
With a configuration download, the parameters are downloaded in the drive, except the safe parameters. The
user can transfer a configuration in all situations. If a safety function has been activated, the functions using these
same LI are no longer configured.
Note: If the downloaded configuration have functions (Preset speed,...) on LI3-4-5-6 and if the drive has a safety
function configured on LI, safety function will not be erased. It is the functions that have the same LI as safety
functions that are not transferred. Multiconfiguration/multimotor and macroconfiguration obey the same rules.
Factory settings
If the drive is in safe mode and you active the factory settings only non safety parameters will be downloaded in
the drive. Safe parameters are not impacted by factory settings.
S1A45606 06/2011 37
Incompatibility with safety functions
38 S1A45606 06/2011
Safety monitoring
Safety monitoring
S1A45606 06/2011 39
Safety monitoring
With the HMI on the drive you can’t configure safety functions, only monitoring can be done. There is one
monitoring parameter for each safety function. See Introduction for more information of safety function.
To access this parameter by keypad or HMI: [2 MONITORING] (MOn-) => [MONIT. SAFETY] (SAF-)
z [STO status] (StOS): Status of the Safe Torque Off safety function
z [SLS status] (SLSS): Status of the Safe Limit speed safety function
z [SS1 status] (SS1S): Status of the Safe Stop 1 safety function
These statuses are not certified safety, they are informative.
For more information see the ATV32 programming manual on www.schneider-electric.com.
40 S1A45606 06/2011
Safety monitoring
Dedicated HMI
When a safe function is activated, some dedicated messages can be displayed and some status word can be set.
Embedded keypad and LED keypad: Display the active safe function (STO, SS1, SLS) alternate with monitoring
parameter.
LED display on SS1 function:
SSI
1s 1s Deceleration ramp
.
300
Drive is stopped
StO Wait safety function acknowledge
S1A45606 06/2011 41
Safety monitoring
SFFE register
Bit0=1 logical input debounce time out (check value of Debounce time LIDT in accordance with the application)
Bit1 Reserved
Bit2=1 Motor speed sign change during SS1 ramp
Bit3=1 Motor speed reached SS1 trip area
Bit4 Reserved
Bit5 Reserved
Bit6=1 Motor speed sign change during SLS limitation
Bit7=1 Motor speed reached SS1 trip area
Bit8 Reserved
Bit9 Reserved
Bit10 Reserved
Bit11 Reserved
Bit12 Reserved
Bit13=1 Motor speed measurement is not possible (check wiring motor connection)
Bit14=1 Motor ground short circuit detected (check wiring motor connection)
Bit15=1 Motor phase to phase short circuit detected (check wiring motor connection)
42 S1A45606 06/2011
Technical data
Technical data
S1A45606 06/2011 43
Technical data
Electrical Data
The Logic inputs and Logic outputs of the drive can be wired for logic type 1 or logic type 2.
Logic Type Active state
1 Output draws current (Sink)
Current flows to the input
2 Output supplies flows from the input Current
Current (Source)
Safe function only used in source mode, sink is not compatible with
safe functions.
44 S1A45606 06/2011
Technical data
Logical input
General logical inputs can be used to trig a safe function. Logical inputs have to be combined by pair to get a
redundant request. There are only 4 general logical inputs linkable to safety functions (LI3, LI4, LI5, LI6). The
pairs of logical inputs are fixed and are:
z LI3 and LI4,
z LI5 and LI6,
z An other combination is possible only for STO function: LI3 and STO.
The pairs of logical inputs are mono assignable when they are linked to a safety function. When you set a safety
function on a LI you can’t set an other function (safe or not safe) on this LI. If you set a non safe function on a LI
you can’t set a safe function on this LI.
S1A45606 06/2011 45
Technical data
Machine application
Function STO SS1 type C SLS/STO/SS1 type B
Configuration STO
STO and LI3
with Preventa
with Preventa LI3 LI5
STO STO and LI3 XPS ATE or
XPS AV or LI4 LI6
XPS AV or
equivalent
Standard equivalent
IEC 61800-5-2 /
SIL2 SIL3 SIL2 SIL3 SIL2
IEC 61508 /
IEC 60204-1 (4) Category stop 0 Category stop 0 Category stop 1 Category stop 1
(1) Because the standard IEC 62061 is an integration standard, this standard distinguishes the global safety function (which
is classify SIL2 or SIL3 for ATV32 according to diagrams Process system SF - Case 1, page 50 and Process system SF - Case
2, page 52) from components which constitute the safety function (which is classify SIL2 CL or SIL3 CL for ATV32)
(2) According to table 6 of IEC 62061 (2005)
(3) According to table 4 of EN13849-1 (2008)
(4) If a protection against supply interruption or voltage reduction and subsequent restoration is needed according to
IEC60204-1, a safety module type Preventa XPS AF or equivalent must be used.
Process application
SLS
Function STO SS1 type C SS1 type B
STO
Configuration STO
STO and LI3
with Preventa
with Preventa LI3 LI5
STO STO and LI3 XPS ATE or
XPS AV or LI4 LI6
XPS AV or
equivalent
Standard equivalent
IEC 61800-5-2 /
SIL2 SIL3 SIL2 SIL3 SIL2
IEC 61508 /
(1) Because the standard IEC 62061 is an integration standard, this standard distinguishes the global safety function (which
is classify SIL2 or SIL3 for ATV32 according to diagrams Process system SF - Case 1, page 50 and Process system SF - Case
2, page 52) from components which constitute the safety function (which is classify SIL2 CL or SIL3 CL for ATV32)
46 S1A45606 06/2011
Technical data
S1A45606 06/2011 47
Technical data
On the ATV32 there are 2 parameters to configure LI for safety function (LI3, LI4, LI5, LI6).
The consistency of each pair of logical input is checked continuously.
[LI debounce time] (LIdt): A logical state difference between LI3/LI4 or LI5/LI6 is allowed during debounce
time, otherwise a detected fault is activated. See LIdt page 69.
[LI response time] (LIrt): The LI response time manages the safe function activation shift. See LIrt
page 69.
LI Response Time
LI Debounce Time
SS1 activation
SLS activation
STO activation
Safe detected
fault
48 S1A45606 06/2011
Technical data
NOTE: For the certification relative to functional aspects, only the PDS(SR) (Power Drive System with safety-
related functions) will be in consideration, and not the complete system in which fits into to help to ensure the
functional safety of a machine or a system/process.
Here are the architectures certified:
z Process system SF - Case 1, page 50
z Process system SF - Case 2, page 52
z Process system SF - Case 3, page 53
z Process system SF - Case 4, page 55
z Process system SF - Case 5, page 57
z Process system SF - Case 6, page 59
Safety functions of PDS(SR) (Power Drive System with safety-related functions) are part of a global system.
If qualitative and quantitative objectives of safety set by the final application require to make some adjustments
to use the safety functions in a safe way, then the integrator of the BDM (Background Debug Module) is
responsible of these complementary evolutions (for example management of the mechanical brake on the
motor).
Also, the output information generated by the utilization of safety functions (default relay activation, errors codes
or information on the display, …) are not considering safety informations.
S1A45606 06/2011 49
Technical data
Multi-drive with the Safety module type Preventa XPS AF according to EN 954-1, ISO 13849-1 and IEC 60204-1 (Machine)
The following configurations apply to the diagram below:
z STO category 4, PL "e" / SIL3 Machine with Safety module type Preventa XPS AF or equivalent.
z SLS category 3, PL "d" / SIL2 or SS1 type B category 3 on LI3/LI4 or LI5/LI6.
Or
z STO category 4, PL "e" / SIL3 Machine with Safety module type Preventa XPS AF or equivalent.
z SLS category 3, PL "d" / SIL2 or SS1 type B category 3 on LI3/LI4.
z LI5/LI6 not set to a safety function.
Or
z STO category 4, PL "e" / SIL3 Machine with Safety module type Preventa XPS AF or equivalent.
z LI3/LI4 and LI5/LI6 not set to a safety function.
Or
z STO category 4, PL "e" / SIL3 Machine with safety controller module type Preventa XPS AF or equivalent and
LI3 set to STO.
z SLS category 3, PL "d" / SIL2 or SS1 type B category 3 PL "d" / SIL2 on LI5/LI6.
z LI4 not set to a safety function.
50 S1A45606 06/2011
Technical data
+24 V
+24 V 0V
L1
F1
T
K1
Logic
XPS AF
K2
Source
SW1 Ext
Sink
Int
A1
P24
STO
R1A
R1B
R1C
S / L2
R / L1
T / L3
ATV32
W / T3
U / T1
V / T2
COM
PA/+
PC/-
PBe
+24
LI6
LI5
LI4
LI3
LI2
LI1
PB
W1
U1
V1
(1)
M
3a
Source
SW1 Ext
Sink
Int
A2
P24
STO
R1A
R1B
R1C
R / L1
S / L2
T / L3
ATV32
W / T3
U / T1
V / T2
COM
PA/+
PC/-
PBe
+24
LI6
LI5
LI4
LI3
LI2
LI1
PB
W1
U1
V1
(1)
M
3a
Note: For more information about the characteristics of the control terminal, please refer to the installation
manual.
S1A45606 06/2011 51
Technical data
Multi-drive without the Safety module type Preventa XPS AF according to IEC 61508
The following configurations apply to the diagram below:
z STO SIL3 on STO.
z SLS SIL2 or SS1 type B SIL2 on LI3/LI4 or LI5/LI6.
Or
z STO SIL3 on STO.
z SLS or SS1 type B on LI3/LI4.
z LI5/LI6 not set to a safety function.
Or
z STO SIL3 on STO.
z LI3/LI4 and LI5/LI6 not set to a safety function.
Or
z STO SIL3 on STO and LI3.
z SLS SIL2 or SS1 type B SIL2 on LI5/LI6.
z LI4 not set to a safety function.
Or
z STO SIL3 on STO and LI3.
z LI4 and LI5/LI6 not set to a safety function.
+24 V
+24 V 0V
Source
SW1 Ext
Sink
Int
A1
P24
STO
R1A
R1B
R1C
S / L2
R / L1
T / L3
ATV32
W / T3
U / T1
V / T2
COM
PA/+
PC/-
PBe
+24
LI6
LI5
LI4
LI3
LI2
LI1
PB
W1
U1
V1
(1)
M
3a
Source
SW1 Ext
Sink
Int
A2
P24
STO
R1A
R1B
R1C
S / L2
R / L1
T / L3
ATV32
W / T3
U / T1
V / T2
COM
PA/+
PC/-
PBe
+24
LI6
LI5
LI4
LI3
LI2
LI1
PB
W1
U1
V1
(1)
M
3a
52 S1A45606 06/2011
Technical data
Safety with controller type Preventa XPS AV according to EN 954-1, ISO 13849-1 and IEC 60204-1 (Machine)
The following configurations apply to the diagram below:
z SS1 type C category 4, PL "e" / SIL3 on STO with Safety module type Preventa XPS AV or equivalent.
z SLS category 3, PL "d" / SIL2 or SS1 type B category 3 on LI3/LI4 or LI5/LI6.
Or
z SS1 type C category 4, PL "e" / SIL3 on STO with Safety module type Preventa XPS AV or equivalent.
z SLS category 3, PL "d" / SIL2 or SS1 type B category 3 on LI3/LI4.
z LI5/LI6 not set to a safety function.
Or
z SS1 type C category 4, PL "e" / SIL3 on STO and LI3 with Safety module type Preventa XPS AV or equivalent.
z LI3/LI4 and LI5/LI6 not set to a safety function.
Or
z SS1 type C category 4, PL "e" / SIL3 on STO with Safety module type Preventa XPS AV or equivalent.
z SLS category 3, PL "d" / SIL2 or SS1 type B category 3 PL "d" / SIL2 on LI5/LI6.
z LI4 not set to a safety function.
S1A45606 06/2011 53
Technical data
Emmerg. stop
Output 1
Output
Logic 1 logic
channel
channel 1 Output
Output 2
2
Fault
Output 11
Fault
Logic
channel 2 logic
channel 2
Output 2
Output 2
Emmerg.
stop
Time delay
stop
Start
Source
SW1 Ext
Sink
Int
A1
P24
STO
R1A
R1B
R1C
R / L1
S / L2
T / L3
ATV32
W / T3
U / T1
V / T2
COM
PA/+
PC/-
PBe
+24
LI6
LI5
LI4
LI3
LI2
LI1
PB
W1
U1
V1
(1)
M
3a
A1
ATV32
COM
+24
LI6
LI5
LI4
LI3
LI2
LI1
+24 V
+24 V
0V
A1
ATV32
COM
+24
LI6
LI5
LI4
LI3
LI2
LI1
54 S1A45606 06/2011
Technical data
Safety with controller type Preventa XPS AF according to EN 954-1, IS0 13849-1, IEC 62061 and 60204-1 (Machine)
The following configurations apply to the diagram below:
z STO category 3, PL "d" / SIL2 on STO with Safety module type Preventa XPS AF or equivalent.
z SLS category 3, PL "d" / SIL2 or SS1 type B category 3 on LI3/LI4 or LI5/LI6
Or
z STO category 3, PL "d" / SIL2 on STO with Safety module type Preventa XPS AF or equivalent.
z SLS category 3, PL "d" / SIL2 or SS1 type B category 3 on LI3/LI4.
z LI5/LI6 not set to a safety function.
Or
z STO category 3, PL "d"/ SIL2 on STO with Safety module type Preventa XPS AF or equivalent.
z LI3/LI4 and LI5/LI6 not set to a safety function.
Or
z STO category 4, PL "e" / SIL3 on STO with Safety module type Preventa XPS AF or equivalent and LI3 set
to STO.
z SLS category 3, PL "d" / SIL2 or SS1 type B category 3 on LI5/LI6.
z LI4 not set to a safety function.
S1A45606 06/2011 55
Technical data
L1
F1
Source
S2 Start
SW1 Ext ESC
Sink
Int
T
K1
Logic
XPS AF
K2
S1
A1
P24
STO
R1A
R1B
R1C
S / L2
R / L1
T / L3
ATV32
W / T3
U / T1
V / T2
COM
PA/+
PC/-
PBe
+24
LI6
LI5
LI4
LI3
LI2
LI1
PB
W1
U1
V1
(1)
M
3a
A1
ATV32 COM
+24
LI6
LI5
LI4
LI3
LI2
LI1
+24 V
+24 V
0V
A1
ATV32
COM
+24
LI6
LI5
LI4
LI3
LI2
LI1
56 S1A45606 06/2011
Technical data
Safety according to IEC 61508 and IEC 60204-1 without protection against supply interruption or voltage reduction and
subsequent rotation.
The following configurations apply to the diagram below:
z STO SIL2 on STO.
z STO or SLS SIL2 or SS1 type B SIL2 on LI3/LI4 or LI5/LI6.
Or
z STO SIL2 on STO.
z STO or SLS or SS1 type B on LI3/LI4.
z LI5/LI6 not set to a safety function.
Or
z STO SIL2 on STO.
z LI3/LI4 and LI5/LI6 not set to a safety function.
Or
z STO SIL3 on STO and LI3.
z SLS SIL2 or SS1 type B SIL2 on LI5/LI6.
z LI4 not set to a safety function.
Or
z STO SIL3 on STO and LI3.
z LI4 and LI5/LI6 not set to a safety function.
S1A45606 06/2011 57
Technical data
Safety without protection against supply interruption or voltage reduction and subsequent rotation
Source
SW1 Ext
Sink
Int
A1
P24
STO
R1A
R1B
R1C
R / L1
S / L2
T / L3
ATV32
W / T3
U / T1
V / T2
COM
PA/+
PC/-
PBe
+24
LI6
LI5
LI4
LI3
LI2
LI1
PB
W1
U1
V1
(1)
M
3a
A1
ATV32
COM
+24
LI6
LI5
LI4
LI3
LI2
LI1
+24 V
+24 V
0V
A1
ATV32
COM
+24
LI6
LI5
LI4
LI3
LI2
LI1
58 S1A45606 06/2011
Technical data
Safety according to IEC 61508 and IEC 60204-1 without protection against supply interruption or voltage reduction and
subsequent rotation.
The following configurations apply to the diagram below:
z STO SIL2 on LI3 and LI4.
z SLS SIL2 or SS1 type B SIL2 on LI5/LI6.
Or
z STO SIL2 on LI3 and LI4.
z LI5/LI6 not set to a safety function.
Source
SW1 Ext
Sink
Int
A1
P24
STO
R1A
R1B
R1C
R / L1
S / L2
T / L3
ATV32
W / T3
U / T1
V / T2
COM
PA/+
PC/-
PBe
+24
LI6
LI5
LI4
LI3
LI2
LI1
PB
W1
U1
V1
(1)
M
3a
A1
P24
STO
ATV32
COM
+24
LI6
LI5
LI4
LI3
LI2
LI1
+24 V
+24 V
0V
S1A45606 06/2011 59
Technical data
60 S1A45606 06/2011
Commissioning
Commissioning
S1A45606 06/2011 61
Commissioning
Note
Before commissioning the ATV32 refer to the installation manual on www.schneider-electric.com.
The safety functions are configured with SoMove software.
Safety tab
To access safety configuration, click on safety tab c.
This screen is in read-only, you can see all current safety configurations.
62 S1A45606 06/2011
Commissioning
When you are online you can click on “configure” button in the safety tab panel.
At this time a dialog box appears, to write or set your password.
First case
you have already entered a password: write your defined password:
Second case
you never have entered a password: you need to choose a value between 1 and 65535. The value 0 is forbidden
for the password.
S1A45606 06/2011 63
Commissioning
The Configure Safety panel includes the Information, STO, SLS, SS1 and I/O tabs.
Information tab
64 S1A45606 06/2011
Commissioning
For this function, only the associated set of inputs has to be selected in the combo box.
The parameter to be managed is the parameter: STOA.
S1A45606 06/2011 65
Commissioning
1H [1 Hz/s]
10H [10 Hz/s]
100H [100 Hz/s]
With this parameter you can set the unit of SSRT.
This parameter is specific. Indeed, they are common with the safety function SS1configured in another tab.
66 S1A45606 06/2011
Commissioning
This parameter sets the tolerance zone around the deceleration ramp in which the frequency may vary.
This parameter is specific. Indeed, they are common with the safety function SS1 configured in another tab.
SSSL [SLS/SS1 standstill level] 0 to 599 Hz 0
This parameter adjusts the frequency to which the drive should go into state STO at the end of the ramp
SS1.
This parameter is specific. Indeed, they are common with the safety function SS1 configured in another tab.
S1A45606 06/2011 67
Commissioning
1H [1 Hz/s]
10H [10 Hz/s]
100H [100 Hz/s]
With this parameter you can set the unit of SSRT.
This parameter is specific. Indeed, they are common with the safety function SLS configured in another tab.
SStt [SS1 trip threshold] 0 to 599 Hz 0
This parameter sets the tolerance zone around the deceleration ramp in which the frequency may vary.
This parameter is specific. Indeed, they are common with the safety function SLS configured in another tab.
SSSL [SLS/SS1 standstill level] 0 to 599 Hz 0
This parameter adjusts the frequency to which the drive should go into state STO at the end of the ramp
SS1.
This parameter is specific. Indeed, they are common with the safety function SLS configured in another tab.
68 S1A45606 06/2011
Commissioning
In most of the case, both LI of a safe LI couple (LI3 and LI4, LI5 and LI6) will not be 100% synchronized.
They will not change of state in the same time. There is a small delta between both LI transition.
LIdt is the parameter used to set this delta. If both LI change states with a delta in time smaller than
LIdt it is considered as a simultaneous transition of the LI.
If delta in time is greater than LIdt, drive considers that LI are no more synchronized and a Safe
detected fault is triggered.
LIrt [LI response time] 0 to 50 ms 0
This parameter is used to filter short impulse on LI. Some application send short impulse on the line to test
it. This parameter is used to filter these short impulses. Orders are taken into account only if the duration
is greater than LIrt.
If duration is smaller drive considers that there is no order: order is filtered.
S1A45606 06/2011 69
Commissioning
Reset Safety
This function is used to remove the safety function in the device. To access the function, click the «Reset Safety»
function button in the Safety tab panel, see page 62.
First, enter the password, and after confirm your choice.
After this action, all safety parameters are set to factory settings.
70 S1A45606 06/2011
Commissioning
Password management
Modify Password
This function allows to modify the safety password in the drive.
This tool is launched from the “Safety” tab using the button “Modify Safety Password”.
To modify the safety password, a session must be opened in the drive. Opening a safety session means
providing to the Drive the good safety password.
You need to choose a value between 1 and 65535. The value 0 is forbidden for the password. Use only digits to
create the password. Any other character will not be taken into account.
Reset password
If you don’t remember the safety password defined in the drive.
Resetting the drive requires the knowledge of the universal password.
To get this password, contact your Schneider Electric support.
After this operation, the device goes back to undefined safety password and the safety session is automatically
closed.
Function configuration however remains unchanged.
S1A45606 06/2011 71
Commissioning
A parameter shows if the drive is in safe state or not (safety function configured):
z No safety function configured: STD
z Safety function configured : SFTY
Safety Status
72 S1A45606 06/2011
Machine signature
Machine signature
S1A45606 06/2011 73
Machine signature
Introduction
The acceptance test for systems with Safety Integrated Functions is focused on validating the functionality of
Safety Integrated monitoring and stop functions configured in the drive system.
The test objective is to verify proper configuration of the defined safety functions and of test mechanisms and to
examine the response of specific monitoring functions to the explicit input of values outside tolerance limits. The
test must cover all drive-specific Safety configured monitoring functions and global Safety Integrated
functionality of ATV32.
74 S1A45606 06/2011
Machine signature
The information that is displayed is the one defined in the "Identification" folder of the "Safety" tab. They cannot
be modified here.
To add this step to the final report select "Add to the machine signature".
Click on "next" button
S1A45606 06/2011 75
Machine signature
In a function sub step the function diagram and parameters values are displayed. A text box allows you to enter
some additional text in this step.
To add a function to the final report select "Add to the machine signature".
Click on "next" button
76 S1A45606 06/2011
Machine signature
The information that is displayed is the one defined in the "LI summary" folder of the "Safety" tab.
z The LI that are assigned to a safety function are displayed in red and show the related safety function.
z LI that is not assigned to a safety function does not show any assignment and are displayed in green.
To add this step to the final report select "Add to the machine signature".
Click on "next" button
S1A45606 06/2011 77
Machine signature
Step 4: Test
In this step you tick the box when you have done test on your safety functions to guarantee you have check the
correct behaviour of the functions with all the equipments.
To add this step to the final report select "Add to the machine signature".
Click on "next" button.
78 S1A45606 06/2011
Machine signature
Step 5: Key
The checksum of the safety parameters is displayed as it is calculated to be sent to the connected device when
"Apply".
This allows you to compare the checksum value, with the one that displayed on the graphic terminal, in identifi-
cation menu.
Click on Finish button to create the report.
S1A45606 06/2011 79
Machine signature
Acceptance report
80 S1A45606 06/2011
Services and maintenance
10
S1A45606 06/2011 81
Services and maintenance
Maintenance
For more product information, see the installation manual and programming manual on
www.schneider-electric.com.
Preventive maintenance
For preventive maintenance, the Power Removal function must be activated at least once a year. The drive
power supply must be turned off and then on again before carrying out this preventive maintenance. The drive
logic output signals cannot be considered as safety-type signals.
Install interference suppressors on all inductive circuits near the drive or coupled to the same circuit (relays,
contactors, solenoid, valves, etc).
Example: Open the protective door to see if the drive stops in accordance with the safety function configured.
82 S1A45606 06/2011
ATV32_Safety_functions_manual_S1A45606_02
06/2011