Configuring Analog Output Modules on SIL 2 Certified Systems
Analog output (AO) modules in a Safety Instrumented System (SIS) raise an immediate architectural question: the safety function typically drives the plant to a defined safe state using discrete outputs, not continuous modulating signals. This reference explains the technical constraints that prevent standard failsafe AO modules, surveys the exceptions (partial stroke testing, redundant modulating paths, single-channel 1oo1 architectures), and provides concrete configuration and verification procedures for ET 200S F-AQ, ET 200pro F-modules, ProSafe-RS Lite, MTL4500 FSM, and ControlLogix SIL 2 AO implementations.
1. SIS Architecture and the Role of Analog Outputs
A Safety Instrumented Function (SIF) is defined by IEC 61508 / IEC 61511 as a function that takes the process to a safe state when a hazardous condition is detected. The safe state for a shut-down SIF is, by definition, a single deterministic endpoint:
- Fail-safe open (FSO) — de-energize to open the vent path.
- Fail-safe close (FSC) — de-energize to close the isolation valve.
- Fail-safe stay-put (FSSP) — de-energize to hold last position.
All three states are binary. A 4-20 mA or 0-10 V proportional signal cannot express "safe state" except by mapping it to a specific current value (e.g., < 3.6 mA = safe), which is non-standard and rejected by most safety validators.
For this reason, failsafe AO modules (F-AQ) are intentionally excluded from most SIS catalogs. Where modulating control is required, the architectural options are:
- Separate the control loop from the safety loop. The Basic Process Control System (BPCS) handles modulating control with standard AO modules; the SIS uses F-DO modules for trip action.
- Partial Stroke Testing (PST). A binary safety output briefly nudges a modulating valve to verify it has not stuck, while continuous control is performed by a non-SIS AO.
- Redundant safety-grade analog channels. Two independent AO paths form a 1oo2 or 2oo2 architecture so that one failure does not produce a single-channel hazardous output.
2. Why Failsafe Analog Output Modules Are Rare
Designing a SIL 2 analog output that meets IEC 61508 is technically feasible but economically unattractive for most SIS vendors. The reasons are summarized in the table below.
| Constraint | IEC 61508 Requirement | Engineering Consequence |
|---|---|---|
| Diagnostic coverage | DC ≥ 60% for SIL 1; ≥ 90% for SIL 2 (Route 1H) | Each DAC value, output stage, and wiring path must be continuously testable — a complex analog self-test circuit is required on every channel. |
| Safe failure fraction (SFF) | SFF ≥ 60% (SIL 1) to ≥ 90% (SIL 2, Type B) | Output driver faults that could produce a hazardous current must be detected and forced to a defined safe value (typically 0 mA or < 3.6 mA). |
| Proof test interval | Tproof derived from PFDavg budget | Analog drift, scaling, and linearity must be verified in-situ; mechanical proof-test jigs add cost. |
| Process safe state | Defined single deterministic state | Modulating control does not have a single "safe" current; mapping is vendor-specific and not accepted by most TÜV assessments. |
3. Vendor Solutions for SIL-Capable Analog Output
Where a SIL-rated analog output genuinely exists, it is implemented as a single-channel 1oo1, dual-channel 1oo2 / 2oo2, or partial-stroke device. The matrix below compares the major offerings.
| Vendor | Module / Family | SIL Capability | Architecture | Application |
|---|---|---|---|---|
| Siemens | ET 200S F-AQ 6ES7335-7HG02-0AB0 (4 AI/2 AO variants on F-CPU S7-31xF) | SIL 2 / SIL 3 (with redundancy) | 1oo1, 1oo2 | Partial stroke test, smart positioner drive |
| Siemens | ET 200pro F-modules (F-DI, F-DO, F-AI in distributed I/O) | SIL 2 / Category 3, SIL 3 / Category 4 | 1oo1, 1oo2 | PROFIsafe over PROFINET |
| Yokogawa | ProSafe-RS Lite (single-card SIL 2) | SIL 2 in single-module configuration; built-in redundancy on every I/O card | 1oo1 with internal redundancy | Compact ESD / FGS with optional AO for PST |
| Eaton / MTL | MTL454x / MTL4541 (FSM analogue output) | SIL 2 single-channel (1oo1) | 1oo1 | Loop-powered 4-20 mA safety output to field device |
| Rockwell Automation | 1756-IF8H / 1756-OF8H with Add-On Instructions (1756-RM001) | SIL 2 (Cl. 1 Div 2 / Cat 3) | 1oo2D, 2oo3 (per AOI logic) | ControlLogix SIL 2 AO for process shutdown |
4. Siemens ET 200S F-AQ Configuration
The ET 200S F-AQ module (6ES7335-7HG02-0AB0 family) is the most common implementation referenced in field discussions. It is configured in STEP 7 / TIA Portal as part of the F-CPU's safety program.
4.1 Prerequisites
- F-CPU: S7-315F-2 PN/DP, S7-317F-2 PN/DP, S7-319F-3 PN/DP, or S7-1500F
- F-runtime license (F-CPU F-activation memory card)
- STEP 7 V5.5 SP4+ with S7 F-systems library, or TIA Portal V15.1+ with F-activation
- PROFIsafe address set on the module (DIP switch, range 1..1022)
- Reference manual: Siemens TIA Portal — Use Case 1: Safety Mode SIL2 / Category 3
4.2 Assignable Parameters (Use Case 1: SIL2 / Cat 3)
When the F-AQ is operated in Safety Mode SIL 2 / Category 3, the following parameters must be set in the F-I/O configuration:
| Parameter | Allowed Value (SIL 2 / Cat 3) | Comment |
|---|---|---|
| Sensor evaluation | 1oo1 evaluation | Single-channel; fault tolerance 0. Reference |
| Discrepancy time | Not applicable (single-channel) | Becomes relevant only for 1oo2 / 2oo2 redundancy |
| Output range | 4-20 mA (default) or 0-10 V | Set per channel; mismatch between channels is detected and forced to safe value |
| Substitute value on comm. failure | 0 mA (fail-safe de-energize) | Mandatory for SIL 2 — never use "hold last value" |
| Short-circuit test | Pulsed (always on for F-DI, optional for F-AQ) | Determines whether the test pulse is used to detect cross-wiring faults |
| Channel fault acknowledgement | Manual (operator ack required) | Auto-ack is not permitted in SIL 2 / Cat 3 |
4.3 Configuration Procedure in TIA Portal
- Insert the F-CPU in the device view and add the F-activation.
- Add the ET 200S station under PROFINET. Set the PROFIsafe address of the F-AQ to match the DIP switch (e.g., 5).
- Open Device configuration → F-AQ → Properties → F-Parameters and select Use Case 1: Safety Mode SIL 2 / Category 3.
- Set sensor evaluation to
1oo1 evaluationfor each channel in use. - In Value status, enable the per-channel quality bit (QBAD/PASS_OUT) for the safety program.
- Compile the safety program (F-block) and download to the F-CPU. The F-signature is generated and must be confirmed on every download.
- Run the Safety Acceptance Test from the TIA Portal Safety Administration editor.
5. Partial Stroke Testing as the Standard Application
Partial stroke testing is the most common legitimate use of an F-AQ in a SIL 2 SIS. A smart valve positioner is driven by a normal BPCS AO (modulating), and an F-DO closes the valve via a solenoid on a safety demand. Between demands, the F-AQ (or F-DO routed through a current-to-pressure converter) issues a small step (typically 5-15% of stroke) at a defined interval to verify the valve moves.
Proof test interval for the PST function is computed from:
Tproof = (λD + λDU) / (1 - DC) (per IEC 61508-6)
Typical SIL 2 budget at Tproof = 1 year with DC = 90% yields:
- PFDavg target: 10-3 to 10-2
- λDU per hour (target): 1.0E-7 to 1.0E-6
PST intervals are typically 1 to 12 months; the result is recorded in the safety case file as evidence of proof testing.
6. ProSafe-RS Lite Single-Module SIL 2
Yokogawa's ProSafe-RS Lite achieves SIL 2 in a single (non-redundant) module configuration, with built-in redundancy on every ultra-compact input, output, and processor card. For a SIL 2 analog output application:
- Insert an AAV142-S (analog output) card into the ProSafe-RS Lite node.
- Define the SIF in the Safety Engineering Tool with output type "Analog, current" and SIL target 2.
- Assign a 1oo1 architecture; the tool calculates the achieved PFDavg automatically.
- Map the AAV142 to a Modbus or HART tag for connection to the positioner.
- Run the ProSafe-RS Lite Cause & Effect Matrix download and execute the validation sequence.
7. Eaton MTL4500 FSM — Single-Channel 1oo1 SIL 2 AO
The Eaton MTL4500 FSM safety manual states that an MTL454x module "may be used in single-channel (1oo1) safety functions up to SIL 2". The typical application is driving a 4-20 mA loop-powered device from a safe area through a hazardous-area barrier.
Wiring topology:
Safe-area DCS / SIS Hazardous area
| |
[MTL4541]-----[Diode]----[Field device]
| |
PROFIsafe / HART 4-20 mA loop
Verification steps in the FSM safety manual require:
- Confirm SFF ≥ 60% (SIL 1) or ≥ 90% (SIL 2 Type B) is calculated for the final loop.
- Perform the step response test — apply 4 mA and 20 mA, measure ΔV at the field device, confirm linearity ≤ 0.1%.
- Document the proof test interval (typical 1-5 years for MTL4541).
8. ControlLogix SIL 2 with Add-On Instructions
Rockwell Automation's 1756-RM001 publication describes how to build a SIL 2 certified system in ControlLogix using standard 1756 I/O plus application-level Add-On Instructions (AOIs) and termination boards.
The relevant AOIs are:
| AOI Name | Purpose | Output Type |
|---|---|---|
| RA_SIS_AO | Analog output safety instruction with diagnostic voting | 1756-OF8H, 1756-OF8CI |
| RA_SIS_DI | Digital input safety instruction | 1756-IF8H, 1756-IB16IF |
| RA_SIS_DO | Digital output safety instruction | 1756-OB16E, 1756-OF8H |
The 1oo2D voting logic is implemented in the AOI and produces two output values; the higher (or lower) value is routed to the field based on the application. Diagnostic coverage is achieved by comparing the two output paths inside the AOI on every scan.
9. Designing SIL 3 from SIL 2 AO Components
Where SIL 3 is required but only SIL 2 AO components are available, Analog Devices' design article shows the IEC 61508 architectural approach:
- Use 2 SIL 2 components in a 1oo2 architecture. The combined PFDavg becomes the sum of two independent channels. With λDU = 1E-7 /h per channel, two channels yield ΣPFDavg ≈ 1.75E-3, which meets SIL 3 (10-3 ≤ PFD < 10-2).
- Add a watchdog comparator. A 3rd channel (or a 2-out-of-3 voter) detects hazardous disagreement and forces the output to safe.
- Diagnostic test interval (DTI) must be ≤ 1 hour to claim λDU diagnostic coverage. A typical ADC-based design includes a continuous loopback test that reads the output current and compares it to the DAC command.
PFDavg(1oo2) = 2 × (λDU × Tproof / 2) + (λDD × tCE)
10. Verification and Acceptance Test
Every SIL 2 AO implementation must be verified by an independent safety acceptance test. The minimum checks are listed in Table 5.
| # | Test | Pass Criterion | Tool / Method |
|---|---|---|---|
| 1 | Output range calibration | 4 mA ± 0.005 mA; 20 mA ± 0.005 mA | Multimeter, calibrator |
| 2 | Linearity | ≤ 0.1% of span at 25%, 50%, 75% | Stepwise ramp |
| 3 | Open-wire detection | Module goes to safe state within 2 s of open | Disconnect field wire |
| 4 | Short-circuit detection | Module goes to safe state within 2 s of short | Short field wire |
| 5 | Comm-loss behavior | Output forced to 0 mA within PROFIsafe watchdog time (typ. 100-200 ms) | Disable CPU PROFINET |
| 6 | Diagnostic alarm | Channel fault and module fault are reported to F-runtime | Force fault, observe diagnostic buffer |
| 7 | Proof-test interval marking | Calendar entry in maintenance system | SAP / Maximo |
11. Troubleshooting Matrix
Common faults encountered during commissioning and operation of SIL 2 AO channels:
| Symptom | Probable Root Cause | Diagnostic Step | Remedy |
|---|---|---|---|
| Output stuck at 0 mA after CPU restart | Substitute value = 0 mA correctly forced, but F-signature mismatch blocks new value | Compare F-signature in TIA Portal vs. CPU | Re-enter F-signature and download safety program |
| Channel fault after each proof test | Discrepancy between commanded and measured current > tolerance | Inspect field wiring; measure loop resistance | Re-terminate, replace damaged cable, recalibrate |
| PROFIsafe address error on startup (F-CPU SF LED steady red) | Module DIP switch does not match configured F-address | Read F-address from module display / web server | Set DIP switch to match TIA Portal value, power-cycle |
| Intermittent passivation of channel (value status = 0) | Short-circuit test pulse interfering with HART communication | Capture HART frame with maintenance tool during fault | Disable short-circuit test pulse if HART is mandatory, or filter at the positioner |
| One of two redundant channels always shows fault | Wiring polarity reversed on redundant channel | Measure voltage at module terminals | Swap + and – wires per wiring diagram |
12. Field-Proven Caveats
- Substitute value is law. "Hold last value" is not permitted on a SIL 2 F-AQ. Always set the substitute to the value that places the process in its defined safe state.
- Manual acknowledgement only. Automatic restart after a channel fault is prohibited in SIL 2 / Category 3 architectures. The operator must verify the cause and reset.
- Watch the proof-test interval. The PFDavg you calculate in the safety case is valid only as long as proof tests are performed on schedule. A late proof test degrades the SIF to a lower SIL than designed.
- Keep BPCS and SIS electrically separated. Even when both share a single F-CPU, the analog control output of the BPCS and the failsafe AO of the SIS must not share a single wire, terminal block, or field device. The H-H thread convention is to use "one CPU, two output channels, two wiring paths" for this reason.
13. FAQ
Can I configure a standard analog output module in a SIL 2 certified CPU?
Yes, if the AO is part of the BPCS, not the SIF. The CPU may be a TÜV-certified F-CPU (S7-31xF, S7-1500F) that runs both the standard user program and the F-program in parallel. Standard AO modules are configured normally in the user program; only F-DI/F-DO/F-AI/F-AQ modules appear in the safety program editor.
Why does the ET 200M family not have a failsafe AO module?
The ET 200M (6ES7 3xx) is a legacy SIMATIC family and was not extended with a SIL-rated AO module. For F-AQ applications in the SIMATIC world, use the ET 200S F-AQ (6ES7335-7HG02-0AB0) or the ET 200pro F-modules referenced in the Siemens TIA Portal safety manual.
What is partial stroke testing and why is it the only common F-AQ application?
PST is a periodic, small-amplitude movement of a modulating valve (typically 5-15% of stroke) commanded by the F-AQ to prove the valve is not stuck. The valve's normal modulating control is performed by a non-SIS AO. The safety function itself remains binary (close on demand), so the failsafe AO never has to express a continuous "safe" value.
Can two SIL 2 modules be combined to make a SIL 3 AO?
Yes, using a 1oo2 architecture. The combined PFDavg is the sum of two independent channels; with each SIL 2 channel at λDU = 1E-7 /h, the result meets the SIL 3 target of 10-3 to 10-2. Add a voter / comparator for diagnostic coverage. See the Analog Devices design article for the full calculation.
How do I document a SIL 2 AO loop for the safety case file?
Capture: (a) the SIF description and target SIL, (b) the architecture (1oo1 / 1oo2 / 2oo2) with PFDavg calculation, (c) the SFF and diagnostic coverage achieved, (d) the proof test interval and the procedure used, (e) the acceptance test results (Table 5 above), and (f) the F-signature / AOI version. For ControlLogix systems, follow the structure in 1756-RM001.