Safe motion functions must be commissioned by following each safety demand from its initiating device through the safety logic, communications path, drive, motor power stage, and motion-feedback channel. Normal-operation tests establish only the baseline. Validation must also inject practical encoder, communication, power, and operating-state faults and compare every result with predefined acceptance criteria.
How does each safety demand travel through the machine?
Start with the data path. Identify who generates the request, which physical and logical hops carry it, where the drive acts, and which feedback proves the result. The path may include a safety input, safety controller, safe communication link, drive safety function, motor power stage, encoder, and external feedback. Record the actual architecture instead of treating the drive as a single black box.
| Path element | Record from the machine | Commissioning question |
|---|---|---|
| Request source | Device and input channel or address | Does both the expected state and a faulted state reach the safety logic? |
| Safety logic | Condition, reset rule, and active function | Which request selects STO, SLS, SS1, or safe position monitoring? |
| Communication hop | Physical port, network path, and status indication | What happens when the link or a participant fails? |
| Drive action | Configured limit, stop behavior, and timing setting | Does the drive execute the intended function from every relevant operating state? |
| Motion feedback | Encoder channel, connection, and diagnostic status | Can the safety function still detect an unsafe state when feedback fails? |
| Final element | Motor, brake, contactor, or other controlled element | Does measured motion and final-element state match the command? |
Gate check: Trace one real demand through every hop while observing input status, logic state, communication health, drive safety status, encoder diagnostics, and physical motion.
What must layer one prove before functional testing?
Layer one first. Inspect and test the conductors, connectors, shields, encoder cabling, network media, supply protection, and final switching elements that carry or act on the safety demand. A functional test performed through one healthy channel will not expose crossed channels, loose terminals, intermittent plugs, shared supply faults, or a feedback cable that never enters the monitored path.
Compare drawings with installed wiring. Operate each input channel separately where the design permits it, and confirm that the controller or drive diagnoses a discrepancy rather than accepting a misleading healthy state. Inspect encoder and communication connectors for mechanical retention before deliberately disturbing them. Confirm that a loss of a protected supply is represented in the safety logic as designed.
Plan fault insertion points before energizing motion. Pulling a cable or opening a fuse can expose personnel to unexpected motion, stored energy, or damaged hardware. Use designated disconnect points, restrain the test envelope, keep personnel outside the hazard, and define how power and communications will be restored after each test.
Gate check: Match every installed channel and connector to the path map, then prove that individual channel and supply changes produce the expected diagnostic state without unintended motion.
How do you define pass criteria for STO, SLS, SS1, and position monitoring?
Write the expected result before causing a fault. A visible stop is not a complete acceptance criterion. Record the initiating state, active safety function, configured limit or stop behavior, expected diagnostic indication, permitted reset behavior, and physical result. Read actual timing and limit values from the drive configuration, safety program, risk assessment, and validation documents; no universal value can replace the machine-specific settings.
| Function | Primary result to measure | Critical starting conditions | Failure question |
|---|---|---|---|
STO |
Torque-producing capability is removed as designed | Stopped, commanded to run, and moving | Can a wiring, channel, or reset fault permit an unintended restart? |
SLS |
Actual motion remains within the configured safe speed limit | Below the limit, approaching it, and crossing it | What response occurs if speed feedback becomes invalid? |
SS1 |
The commanded stop sequence completes and transitions to its configured safe state | Representative speeds, directions, and loads | What happens if feedback or communication disappears during the stop? |
| Safe position monitoring | Actual position remains inside the configured boundary | Both travel directions and positions near each limit | How does the system react to invalid position feedback or entry beyond the boundary? |
Measure actual motion independently where practical. Controller or drive status proves what the system believes; an independent observation proves what the axis did.
Gate check: Approve a test sheet only when every row contains a starting condition, initiating action, expected status, physical acceptance criterion, and reset rule.
Which practical failures belong in the test matrix?
Build a matrix containing every foreseeable failure that can be introduced without creating an uncontrolled hazard or damaging equipment. Cover faults individually first so the responsible layer remains identifiable. Add combined states only when the machine design or risk assessment requires them.
| Injected condition | Observe at the stopping point | Pass criterion |
|---|---|---|
| Encoder connection interrupted | Feedback diagnostics, active safety function, and axis motion | The configured safe reaction occurs; invalid feedback is not accepted as valid motion data |
| Safety communication interrupted | Port status, communication diagnostics, drive state, and final element | The communication fault drives the defined safe reaction and blocks an automatic hazardous restart |
| Axis moving near a position limit | Direction, position, stopping behavior, and boundary status | The monitored boundary and configured reaction operate from both relevant directions |
Axis approaching an SLS limit |
Actual speed, limit status, and reaction | Crossing the configured limit produces the specified response |
SS1 requested during motion |
Stop sequence, feedback validity, transition, and final state | The complete sequence matches the configured behavior |
| Safety input channel fault | Channel discrepancy, diagnostics, and reset availability | The fault is detected and cannot be cleared by an ordinary run command |
A SISTEMA report can support the design calculation, but it does not demonstrate installed wiring, configured drive behavior, motion near a boundary, fault diagnostics, or restart prevention on the finished machine.
Gate check: Cross-reference each test-matrix row to a real path element and a measurable pass criterion; remove any row that relies only on an indicator labeled safe.
How should each fault test be executed?
- Place the axis in the documented starting state, including position, direction, speed range, load condition, and active operating mode.
- Confirm the protected test area is clear and that the planned recovery action cannot command unexpected motion.
- Capture the initial safety-input, communication, drive, feedback, and final-element states.
- Initiate the safety demand or insert one planned fault at the designated point.
- Observe where the demand stops or changes: input, logic, network, drive, feedback, or physical axis.
- Record diagnostics and measured physical behavior before resetting anything.
- Attempt only the resets and restart commands listed in the test sheet. Confirm that a persistent fault cannot be cleared by cycling an unrelated command.
- Restore the faulted connection or supply, inspect the affected hardware, and repeat the normal-function test before proceeding.
Do not change configuration to make a failed test pass until the failed layer is identified. A changed limit, filter, or stop setting can conceal a wiring or feedback problem and invalidate previously completed rows.
Gate check: Repeat one completed test from its written record. A second engineer should obtain the same diagnostic sequence and physical result without verbal guidance.
How do you complete end-to-end verification?
Run the full sequence through the real operator and machine interfaces after individual faults pass. Test each safe motion function from normal operation, from motion near its configured threshold or boundary, and after restoration of encoder or communication faults. Verify that status shown to the operator matches the actual drive and axis state.
Confirm restart behavior separately from stopping behavior. Remove the demand, restore communications or feedback, and apply the permitted reset sequence. The axis must remain inhibited until every required condition is valid and a deliberate restart command occurs. Recheck the normal production command afterward so the repair or test jumper has not left the machine unable to operate or, worse, able to bypass the safety path.
Gate check: Sign the result only after the initiating device, every path hop, the drive reaction, measured axis motion, diagnostics, reset sequence, and deliberate restart have all matched the approved test sheet.
FAQ
Can I validate safe motion by testing STO only?
No. STO does not prove the configured speed, stop-sequence, position-monitoring, encoder-fault, or communication-fault behavior required for SLS, SS1, and safe position monitoring.
Does a SISTEMA report replace commissioning tests?
No. It can support the design calculation, but the installed machine still requires tests of wiring, configuration, diagnostics, physical motion, reset behavior, and foreseeable practical faults.
Can I unplug an encoder or network cable during a safe motion test?
Yes, when that is the planned fault-insertion method and the test envelope, stored energy, connection point, expected reaction, and recovery sequence have been controlled before motion starts.
Does a successful stop prove the machine is ready?
No. Restore the injected fault, confirm all diagnostics return to the expected state, execute the permitted reset, verify the axis remains inhibited until a deliberate restart, and run the final end-to-end functional test.