Configuring Analog Output Modules on SIL 2 Certified Systems

David Krause12 min read
Safety SystemsSiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Configuring Analog Output Modules on SIL 2 Certified Systems

Analog output (AO) modules in a Safety Instrumented System (SIS) raise an immediate architectural question: the safety function typically drives the plant to a defined safe state using discrete outputs, not continuous modulating signals. This reference explains the technical constraints that prevent standard failsafe AO modules, surveys the exceptions (partial stroke testing, redundant modulating paths, single-channel 1oo1 architectures), and provides concrete configuration and verification procedures for ET 200S F-AQ, ET 200pro F-modules, ProSafe-RS Lite, MTL4500 FSM, and ControlLogix SIL 2 AO implementations.

1. SIS Architecture and the Role of Analog Outputs

A Safety Instrumented Function (SIF) is defined by IEC 61508 / IEC 61511 as a function that takes the process to a safe state when a hazardous condition is detected. The safe state for a shut-down SIF is, by definition, a single deterministic endpoint:

  • Fail-safe open (FSO) — de-energize to open the vent path.
  • Fail-safe close (FSC) — de-energize to close the isolation valve.
  • Fail-safe stay-put (FSSP) — de-energize to hold last position.

All three states are binary. A 4-20 mA or 0-10 V proportional signal cannot express "safe state" except by mapping it to a specific current value (e.g., < 3.6 mA = safe), which is non-standard and rejected by most safety validators.

For this reason, failsafe AO modules (F-AQ) are intentionally excluded from most SIS catalogs. Where modulating control is required, the architectural options are:

  1. Separate the control loop from the safety loop. The Basic Process Control System (BPCS) handles modulating control with standard AO modules; the SIS uses F-DO modules for trip action.
  2. Partial Stroke Testing (PST). A binary safety output briefly nudges a modulating valve to verify it has not stuck, while continuous control is performed by a non-SIS AO.
  3. Redundant safety-grade analog channels. Two independent AO paths form a 1oo2 or 2oo2 architecture so that one failure does not produce a single-channel hazardous output.

2. Why Failsafe Analog Output Modules Are Rare

Designing a SIL 2 analog output that meets IEC 61508 is technically feasible but economically unattractive for most SIS vendors. The reasons are summarized in the table below.

Table 1 — Constraints blocking standard failsafe AO modules
Constraint IEC 61508 Requirement Engineering Consequence
Diagnostic coverage DC ≥ 60% for SIL 1; ≥ 90% for SIL 2 (Route 1H) Each DAC value, output stage, and wiring path must be continuously testable — a complex analog self-test circuit is required on every channel.
Safe failure fraction (SFF) SFF ≥ 60% (SIL 1) to ≥ 90% (SIL 2, Type B) Output driver faults that could produce a hazardous current must be detected and forced to a defined safe value (typically 0 mA or < 3.6 mA).
Proof test interval Tproof derived from PFDavg budget Analog drift, scaling, and linearity must be verified in-situ; mechanical proof-test jigs add cost.
Process safe state Defined single deterministic state Modulating control does not have a single "safe" current; mapping is vendor-specific and not accepted by most TÜV assessments.

3. Vendor Solutions for SIL-Capable Analog Output

Where a SIL-rated analog output genuinely exists, it is implemented as a single-channel 1oo1, dual-channel 1oo2 / 2oo2, or partial-stroke device. The matrix below compares the major offerings.

Table 2 — SIL 2 capable analog output solutions by vendor
Vendor Module / Family SIL Capability Architecture Application
Siemens ET 200S F-AQ 6ES7335-7HG02-0AB0 (4 AI/2 AO variants on F-CPU S7-31xF) SIL 2 / SIL 3 (with redundancy) 1oo1, 1oo2 Partial stroke test, smart positioner drive
Siemens ET 200pro F-modules (F-DI, F-DO, F-AI in distributed I/O) SIL 2 / Category 3, SIL 3 / Category 4 1oo1, 1oo2 PROFIsafe over PROFINET
Yokogawa ProSafe-RS Lite (single-card SIL 2) SIL 2 in single-module configuration; built-in redundancy on every I/O card 1oo1 with internal redundancy Compact ESD / FGS with optional AO for PST
Eaton / MTL MTL454x / MTL4541 (FSM analogue output) SIL 2 single-channel (1oo1) 1oo1 Loop-powered 4-20 mA safety output to field device
Rockwell Automation 1756-IF8H / 1756-OF8H with Add-On Instructions (1756-RM001) SIL 2 (Cl. 1 Div 2 / Cat 3) 1oo2D, 2oo3 (per AOI logic) ControlLogix SIL 2 AO for process shutdown

4. Siemens ET 200S F-AQ Configuration

The ET 200S F-AQ module (6ES7335-7HG02-0AB0 family) is the most common implementation referenced in field discussions. It is configured in STEP 7 / TIA Portal as part of the F-CPU's safety program.

4.1 Prerequisites

  • F-CPU: S7-315F-2 PN/DP, S7-317F-2 PN/DP, S7-319F-3 PN/DP, or S7-1500F
  • F-runtime license (F-CPU F-activation memory card)
  • STEP 7 V5.5 SP4+ with S7 F-systems library, or TIA Portal V15.1+ with F-activation
  • PROFIsafe address set on the module (DIP switch, range 1..1022)
  • Reference manual: Siemens TIA Portal — Use Case 1: Safety Mode SIL2 / Category 3

4.2 Assignable Parameters (Use Case 1: SIL2 / Cat 3)

When the F-AQ is operated in Safety Mode SIL 2 / Category 3, the following parameters must be set in the F-I/O configuration:

Table 3 — F-AQ parameters for SIL 2 / Category 3 use case
Parameter Allowed Value (SIL 2 / Cat 3) Comment
Sensor evaluation 1oo1 evaluation Single-channel; fault tolerance 0. Reference
Discrepancy time Not applicable (single-channel) Becomes relevant only for 1oo2 / 2oo2 redundancy
Output range 4-20 mA (default) or 0-10 V Set per channel; mismatch between channels is detected and forced to safe value
Substitute value on comm. failure 0 mA (fail-safe de-energize) Mandatory for SIL 2 — never use "hold last value"
Short-circuit test Pulsed (always on for F-DI, optional for F-AQ) Determines whether the test pulse is used to detect cross-wiring faults
Channel fault acknowledgement Manual (operator ack required) Auto-ack is not permitted in SIL 2 / Cat 3

4.3 Configuration Procedure in TIA Portal

  1. Insert the F-CPU in the device view and add the F-activation.
  2. Add the ET 200S station under PROFINET. Set the PROFIsafe address of the F-AQ to match the DIP switch (e.g., 5).
  3. Open Device configuration → F-AQ → Properties → F-Parameters and select Use Case 1: Safety Mode SIL 2 / Category 3.
  4. Set sensor evaluation to 1oo1 evaluation for each channel in use.
  5. In Value status, enable the per-channel quality bit (QBAD/PASS_OUT) for the safety program.
  6. Compile the safety program (F-block) and download to the F-CPU. The F-signature is generated and must be confirmed on every download.
  7. Run the Safety Acceptance Test from the TIA Portal Safety Administration editor.

5. Partial Stroke Testing as the Standard Application

Partial stroke testing is the most common legitimate use of an F-AQ in a SIL 2 SIS. A smart valve positioner is driven by a normal BPCS AO (modulating), and an F-DO closes the valve via a solenoid on a safety demand. Between demands, the F-AQ (or F-DO routed through a current-to-pressure converter) issues a small step (typically 5-15% of stroke) at a defined interval to verify the valve moves.

Proof test interval for the PST function is computed from:

Tproof = (λD + λDU) / (1 - DC)    (per IEC 61508-6)

Typical SIL 2 budget at Tproof = 1 year with DC = 90% yields:

  • PFDavg target: 10-3 to 10-2
  • λDU per hour (target): 1.0E-7 to 1.0E-6

PST intervals are typically 1 to 12 months; the result is recorded in the safety case file as evidence of proof testing.

6. ProSafe-RS Lite Single-Module SIL 2

Yokogawa's ProSafe-RS Lite achieves SIL 2 in a single (non-redundant) module configuration, with built-in redundancy on every ultra-compact input, output, and processor card. For a SIL 2 analog output application:

  1. Insert an AAV142-S (analog output) card into the ProSafe-RS Lite node.
  2. Define the SIF in the Safety Engineering Tool with output type "Analog, current" and SIL target 2.
  3. Assign a 1oo1 architecture; the tool calculates the achieved PFDavg automatically.
  4. Map the AAV142 to a Modbus or HART tag for connection to the positioner.
  5. Run the ProSafe-RS Lite Cause & Effect Matrix download and execute the validation sequence.

7. Eaton MTL4500 FSM — Single-Channel 1oo1 SIL 2 AO

The Eaton MTL4500 FSM safety manual states that an MTL454x module "may be used in single-channel (1oo1) safety functions up to SIL 2". The typical application is driving a 4-20 mA loop-powered device from a safe area through a hazardous-area barrier.

Wiring topology:

Safe-area DCS / SIS      Hazardous area
       |                    |
   [MTL4541]-----[Diode]----[Field device]
       |                    |
   PROFIsafe / HART         4-20 mA loop

Verification steps in the FSM safety manual require:

  1. Confirm SFF ≥ 60% (SIL 1) or ≥ 90% (SIL 2 Type B) is calculated for the final loop.
  2. Perform the step response test — apply 4 mA and 20 mA, measure ΔV at the field device, confirm linearity ≤ 0.1%.
  3. Document the proof test interval (typical 1-5 years for MTL4541).

8. ControlLogix SIL 2 with Add-On Instructions

Rockwell Automation's 1756-RM001 publication describes how to build a SIL 2 certified system in ControlLogix using standard 1756 I/O plus application-level Add-On Instructions (AOIs) and termination boards.

The relevant AOIs are:

Table 4 — ControlLogix SIL 2 AOI family (per 1756-RM001)
AOI Name Purpose Output Type
RA_SIS_AO Analog output safety instruction with diagnostic voting 1756-OF8H, 1756-OF8CI
RA_SIS_DI Digital input safety instruction 1756-IF8H, 1756-IB16IF
RA_SIS_DO Digital output safety instruction 1756-OB16E, 1756-OF8H

The 1oo2D voting logic is implemented in the AOI and produces two output values; the higher (or lower) value is routed to the field based on the application. Diagnostic coverage is achieved by comparing the two output paths inside the AOI on every scan.

9. Designing SIL 3 from SIL 2 AO Components

Where SIL 3 is required but only SIL 2 AO components are available, Analog Devices' design article shows the IEC 61508 architectural approach:

  • Use 2 SIL 2 components in a 1oo2 architecture. The combined PFDavg becomes the sum of two independent channels. With λDU = 1E-7 /h per channel, two channels yield ΣPFDavg ≈ 1.75E-3, which meets SIL 3 (10-3 ≤ PFD < 10-2).
  • Add a watchdog comparator. A 3rd channel (or a 2-out-of-3 voter) detects hazardous disagreement and forces the output to safe.
  • Diagnostic test interval (DTI) must be ≤ 1 hour to claim λDU diagnostic coverage. A typical ADC-based design includes a continuous loopback test that reads the output current and compares it to the DAC command.

PFDavg(1oo2) = 2 × (λDU × Tproof / 2)   +   (λDD × tCE)

10. Verification and Acceptance Test

Every SIL 2 AO implementation must be verified by an independent safety acceptance test. The minimum checks are listed in Table 5.

Table 5 — SIL 2 AO acceptance test checklist
# Test Pass Criterion Tool / Method
1 Output range calibration 4 mA ± 0.005 mA; 20 mA ± 0.005 mA Multimeter, calibrator
2 Linearity ≤ 0.1% of span at 25%, 50%, 75% Stepwise ramp
3 Open-wire detection Module goes to safe state within 2 s of open Disconnect field wire
4 Short-circuit detection Module goes to safe state within 2 s of short Short field wire
5 Comm-loss behavior Output forced to 0 mA within PROFIsafe watchdog time (typ. 100-200 ms) Disable CPU PROFINET
6 Diagnostic alarm Channel fault and module fault are reported to F-runtime Force fault, observe diagnostic buffer
7 Proof-test interval marking Calendar entry in maintenance system SAP / Maximo

11. Troubleshooting Matrix

Common faults encountered during commissioning and operation of SIL 2 AO channels:

Table 6 — SIL 2 AO fault matrix
Symptom Probable Root Cause Diagnostic Step Remedy
Output stuck at 0 mA after CPU restart Substitute value = 0 mA correctly forced, but F-signature mismatch blocks new value Compare F-signature in TIA Portal vs. CPU Re-enter F-signature and download safety program
Channel fault after each proof test Discrepancy between commanded and measured current > tolerance Inspect field wiring; measure loop resistance Re-terminate, replace damaged cable, recalibrate
PROFIsafe address error on startup (F-CPU SF LED steady red) Module DIP switch does not match configured F-address Read F-address from module display / web server Set DIP switch to match TIA Portal value, power-cycle
Intermittent passivation of channel (value status = 0) Short-circuit test pulse interfering with HART communication Capture HART frame with maintenance tool during fault Disable short-circuit test pulse if HART is mandatory, or filter at the positioner
One of two redundant channels always shows fault Wiring polarity reversed on redundant channel Measure voltage at module terminals Swap + and – wires per wiring diagram

12. Field-Proven Caveats

Do not interpret IEC 61511 as approving any SIL 2 overload. The standards define the methodology (PFDavg targets, SFF targets, proof-test intervals) but the suitability of a specific architecture for a specific hazard must be confirmed by your safety integrity level (SIL) verification calculation, not assumed from a module data sheet.
  • Substitute value is law. "Hold last value" is not permitted on a SIL 2 F-AQ. Always set the substitute to the value that places the process in its defined safe state.
  • Manual acknowledgement only. Automatic restart after a channel fault is prohibited in SIL 2 / Category 3 architectures. The operator must verify the cause and reset.
  • Watch the proof-test interval. The PFDavg you calculate in the safety case is valid only as long as proof tests are performed on schedule. A late proof test degrades the SIF to a lower SIL than designed.
  • Keep BPCS and SIS electrically separated. Even when both share a single F-CPU, the analog control output of the BPCS and the failsafe AO of the SIS must not share a single wire, terminal block, or field device. The H-H thread convention is to use "one CPU, two output channels, two wiring paths" for this reason.

13. FAQ

Can I configure a standard analog output module in a SIL 2 certified CPU?

Yes, if the AO is part of the BPCS, not the SIF. The CPU may be a TÜV-certified F-CPU (S7-31xF, S7-1500F) that runs both the standard user program and the F-program in parallel. Standard AO modules are configured normally in the user program; only F-DI/F-DO/F-AI/F-AQ modules appear in the safety program editor.

Why does the ET 200M family not have a failsafe AO module?

The ET 200M (6ES7 3xx) is a legacy SIMATIC family and was not extended with a SIL-rated AO module. For F-AQ applications in the SIMATIC world, use the ET 200S F-AQ (6ES7335-7HG02-0AB0) or the ET 200pro F-modules referenced in the Siemens TIA Portal safety manual.

What is partial stroke testing and why is it the only common F-AQ application?

PST is a periodic, small-amplitude movement of a modulating valve (typically 5-15% of stroke) commanded by the F-AQ to prove the valve is not stuck. The valve's normal modulating control is performed by a non-SIS AO. The safety function itself remains binary (close on demand), so the failsafe AO never has to express a continuous "safe" value.

Can two SIL 2 modules be combined to make a SIL 3 AO?

Yes, using a 1oo2 architecture. The combined PFDavg is the sum of two independent channels; with each SIL 2 channel at λDU = 1E-7 /h, the result meets the SIL 3 target of 10-3 to 10-2. Add a voter / comparator for diagnostic coverage. See the Analog Devices design article for the full calculation.

How do I document a SIL 2 AO loop for the safety case file?

Capture: (a) the SIF description and target SIL, (b) the architecture (1oo1 / 1oo2 / 2oo2) with PFDavg calculation, (c) the SFF and diagnostic coverage achieved, (d) the proof test interval and the procedure used, (e) the acceptance test results (Table 5 above), and (f) the F-signature / AOI version. For ControlLogix systems, follow the structure in 1756-RM001.

Back to blog