Resolving Siemens S7-400 Error Event 16#38B3 I/O Access Fault

David Krause11 min read
S7-400SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

1. Problem Overview

Event ID 16#38B3 on a Siemens SIMATIC S7-300 or S7-400 CPU indicates a synchronous I/O access error that occurs while the operating system is updating the process image of the inputs (PII). The CPU writes an entry into the diagnostic buffer and, depending on the configuration, calls Organization Block 85 (OB85) — the "Program execution error OB." If OB85 is not loaded, the CPU typically transitions to STOP; if OB85 is loaded, execution continues and the event is logged as a warning.

A typical diagnostic-buffer entry seen on a CPU 416-3 PN/DP running firmware V6.0 or later looks like this:

Event 52 of 3000: Event ID 16# 38B3
I/O access error when updating the process image input table leaving state
P area, double-word access, access address: 536
process image partition no.: 0
not user relevant (Z1): 2942
Requested OB: Program execution error OB (OB85)
Priority class: 25
External error, Outgoing event

This guide walks through the meaning of every field, the most common root causes (defective AI module, loose PROFIBUS connector, mismatched HW Config, OB85 priority issue), and the corrective procedure using STEP 7 V5.5 / TIA Portal V16+.

Safety Notice: Always place the affected machine in a safe state and de-energize I/O racks before swapping modules or reseating PROFIBUS connectors. Re-validate the safety function after any hardware change on a F/FH CPU.

2. Decoding Event ID 16#38B3

Siemens classifies the error under Event Class 3 — Synchronous Errors. The full 32-bit event identifier has the structure W#16#38B3 where:

Field Value Meaning
Event class 3 Synchronous error detected during instruction execution
Direction 1 (incoming) / 0 (outgoing) Edge transition logged in diagnostic buffer
Sub-event 38B3 / 39B3 Process image of inputs (PII) update failed
OB called OB 85 Program execution error OB

Related events in the same class include:

  • W#16#39B2 — I/O access error when transferring the process image to the output modules (PIQ)
  • W#16#39B3 / 38B3 — I/O access error when updating the process image of the inputs (PII)
  • W#16#39B4 — I/O access error when writing to the output image

Per the official Siemens "Functional Description of S7-300/400 CPUs" manual, these errors are raised when the CPU cannot complete the cyclic exchange of consistent user data with the addressed I/O. Reference: Event Class 3 — Synchronous Errors (S7-300/S7-400).

3. Diagnostic Buffer Field-by-Field Analysis

Open the CPU online in STEP 7 (or TIA Portal) and navigate to PLC > Online & Diagnostics > Diagnostic Buffer. Export the buffer to a text file for archival; the button is labeled "Save as…". The following table translates every field of the entry above.

Field Value in Example Engineering Interpretation
Event ID 16#38B3 Process-image-of-inputs access error (incoming/outgoing pair)
Access area P area (Periphery) Direct peripheral access; not the consistent PII image
Access width double-word (32-bit) Instruction emitted L PED / T PED, or implicit MOVE_DWORD on PIW
Access address 536 (= 0x218) Logical I/O address of the slot. PED 536 maps to bytes 536–539 in the P area
Process image partition 0 Partition number (PIP 0 = automatically updated by the OB1 cycle)
Z1 (not user relevant) 2942 Internal SZL index / SFC error code returned by the I/O subsystem
Requested OB OB 85 CPU attempted to call OB85 to handle the error
Priority class 25 Priority of the OB that triggered the image update (OB1 default = 25 on S7-400)
Mode External error, outgoing event The previous "incoming" event has cleared; the affected module responded again

The "Z1: 2942" code is an internal SZL pointer indicating that the system was trying to read Partial List 0x0118 / 0x0294 from the module. Combined with the access address, this typically points to a missing or faulty analog input module on the rack.

4. Root-Cause Matrix

# Likely Cause Evidence in Buffer Quick Verification
1 Defective or removed analog input module (e.g. SM 331 6ES7331-7KF02-0AB0) Specific access address, AI channel count Compare HW Config slot address with online I&M data
2 Loose / oxidized PROFIBUS connector or IM (Interface Module) link Multiple slots affected, intermittent Re-seat connector, check terminating resistor, view diagnostic repeater LEDs
3 Wrong HW Config (slot configured but no module / wrong order number) Online vs offline mismatch in "Module Information" Run "Compare" on HW Config online
4 Process image partition not assigned to an OB or OB priority too low Partition number in the buffer Right-click CPU > Properties > Process Image
5 OB85 missing or wrong priority — "only part of the error was remedied" message CPU in STOP, OB85 load error Insert OB85 from standard library
6 Update time / scan cycle shorter than the module's cycle time Repeating events on same address Increase OB1 cycle, lengthen PIP update interval
7 EMC / grounding disturbance on 4-20 mA loop Burst events grouped in time Shielded cable, equipotential bonding strip

5. Hardware Diagnosis — AI Module (SM 331) Focus

In the example case the engineer injected a 4-20 mA signal directly at the module and swapped the AI module, which rules out the field wiring but still leaves three hardware sub-causes:

  1. Slot address mismatch — HW Config shows SM 331 at logical address 536, but the physically present module is addressed at 540. Run PLC > Accessible Nodes or Online & Diagnostics > Module Information and confirm slot 8/9/10/11 mapping.
  2. Backplane bus termination — S7-400 racks need the terminating connector on the last slot. A missing terminator on the UR2 rack causes intermittent PII access errors.
  3. Firmware / module revision — A 6ES7331-7NF10-0AB0 module with firmware V2.0 requires a CPU of at least firmware V4.x. Older S7-400 CPUs (e.g. CPU 412-1 V3.1) will raise access errors when reading beyond the module's POUs.

To read module diagnostics:

// SFC 13 / SFC 51 example for pulling SZL 0x0118
CALL  "SZL_READ"
REQ    := TRUE            // start reading
SZL_ID := W#16#0118       // diagnostic buffer of the module
INDEX   := 0               // slot/index of the addressed module
RET_VAL := #ioRetVal       // return code
BUSY    := #bBusy
SZL_PTR := #tSzlHeader     // pointer to record

A return code of 8081h on the SFC confirms the addressed module is not present or is faulted.

6. Process Image Partition (PIP) Configuration

The CPU maintains a process image for fast, consistent access in OB1. By default, inputs 0–127 (PIP 0) are refreshed at the start of OB1. If you have an analog input that is only needed in a slow OB, assign it to a higher-numbered PIP and call the corresponding OB (e.g. OB 35 at 100 ms) to refresh the image.

  1. In TIA Portal: Project tree > PLC > Properties > Process Image > Partition overview. Add a new partition, e.g. PIP 1, and assign input bytes 128–255 to it.
  2. In STEP 7 V5.5: HW Config > CPU > Properties > Process Image. Tick the I/O in the PIP column corresponding to the OB that should refresh them.
  3. Update the OB (e.g. OB35) priority; the PIP n update runs at the start of OB (n + 30) by default. OB 35 → priority 12, OB 121 → priority 0 (system).

For the OB85 call to not stop the CPU, the process image update must complete inside the configured scan time. If the analog modules need 20 ms conversion, set the OB1 minimum cycle time to 25 ms:

// SFC 43 - extend OB1 scan to guarantee consistent PII update
CALL  "OB1_SCAN_TIME"
OB_NR     := 1            // OB1
CYCLE_TIME:= T#25MS       // minimum cycle time
RET_VAL   := #wRetVal

This is exactly the "increase the update intervals for consistent user data" recommendation from the Siemens help file.

7. OB85 Error-Handling Programming

OB85 receives an OB85_FLT_ID byte in its temporary local data. The relevant values are:

OB85_FLT_ID Meaning Recommended Action
1 Module failure on PII update Set #bIOError := TRUE; trigger maintenance alarm
2 Module failure on PIQ update Force the corresponding outputs to a safe state
3 Process image update error in OB (PIP) Log the slot, increment #iPIP_ErrorCount

Example OB85 logic in Structured Text (SCL):

// OB85 - Program execution error
IF #OB85_FLT_ID = 1 OR #OB85_FLT_ID = 2 THEN
    // Read the failed logical address
    #iFailedAddr := DWORD_TO_INT(#OB85_RESERVED_1);
    // Map to tag for HMI alarm
    "dbIOError".bActive := TRUE;
    "dbIOError".iAddr   := #iFailedAddr;
    "dbIOError".iFLT_ID := #OB85_FLT_ID;
    // Acknowledge the error to allow CPU to keep running
    RETURN;
END_IF;

After installing OB85, the "only part of the current error was remedied" help text refers to the fact that the incoming event (16#39B3) and the outgoing event (16#38B3) form a pair. The first time the error appears, OB85 is called. If the module recovers and faults again, only the second half of the pair is logged. Engineers frequently interpret this as "the error wasn't fixed" — it actually means the original error has not been re-cleared by the system since the first time it was raised.

8. Step-by-Step Resolution Procedure

  1. Capture the diagnostic buffer — Online & Diagnostics > Diagnostic Buffer > "Save as…" (text file). Include the 16#38B3 entry and the eight events before/after it for context.
  2. Open HW Config online — Go online with the CPU and run PLC > Compare > Online vs Offline. Any red "Not Present" entry is the prime suspect.
  3. Read the module information — Drill down to the slot reported in Z1 / OB85_RESERVED_1. Check Module Information > Diagnostics > Diagnostic Buffer of the module itself.
  4. Verify wiring and shielding — For 4-20 mA loops, confirm shield is grounded at one end only and that the 24 V sensor supply is within 18–30 V at the terminals under load.
  5. Power-cycle the rack — Power down the PS 405 / PS 407, wait 10 s, re-energize. Watch the CPU RUN LED; an immediate re-fault during PII update confirms hardware.
  6. Re-seat or replace the module — Pull the suspect SM, clean the backplane contacts with isopropyl, and reseat firmly. If the event persists, replace with a known-good module of the same order number (e.g. 6ES7331-7KF02-0AB0).
  7. Re-download the hardware configuration — Always re-load the HW Config after a module swap, even if the order number is identical. This forces the CPU to re-initialize the I/O bus.
  8. Install OB85 if missing — Drag OB85 from the Standard Library. The default empty OB85 is sufficient; add SCL logic only after verifying the basic case clears.
  9. Adjust process-image update interval — Either lengthen the OB1 minimum cycle (SFC43) or move slow AI channels to PIP n refreshed by a higher-numbered OB.
  10. Monitor for 24 h — Use the diagnostic buffer's circular record to verify no further 16#38B3 events appear.

9. Verification and Validation

After the fix, confirm the CPU is healthy:

  • Diagnostic buffer — Clear the buffer (PLC > Clear Diagnostic Buffer) and let the system run for 24 h. The buffer should remain free of 16#38B3, 16#39B2, and 16#39B3 entries.
  • Module LEDs — All SM 33x / SM 43x modules must show green SF / BF / DC24V indicators (no red).
  • Process values — Read the affected channel (e.g. PIW 536) online and verify the raw value tracks the calibration source within ±0.5 %.
  • OB85 invocation — If OB85 is being called frequently, add a counter to log the number of invocations per shift. A non-zero but stable count indicates nuisance noise; investigate further if the rate climbs.
  • CPU operating state — CPU mode remains RUN and the RUN LED is steady green. No STOP / START transitions logged.

10. Preventive Maintenance Checklist

  • Schedule quarterly visual inspection of all PROFIBUS connectors (look for oxidation on pins) and re-torque to 0.6 Nm.
  • Replace PS 405 / PS 407 power supplies after 50 000 operating hours to avoid inrush transients that can drop the backplane supply long enough to fail PII updates.
  • Maintain a spare of each module order number on the shop floor to minimise mean time to repair (MTTR).
  • Back up the diagnostic buffer to a syslog server every hour using SFC 13 / SFC 59 ("RD_SINFO", "WR_USMSG") so trends can be analysed before the circular buffer overwrites them.
  • Keep STEP 7 V5.5 SP2 / TIA Portal V18 (or current) installed with the latest hardware support packages (HSPs) to ensure CPU firmware compatibility after module replacements.

11. Frequently Asked Questions

What does Siemens Event ID 16#38B3 mean on an S7-400 CPU?

It is a synchronous I/O access error raised while the operating system updates the process image of the inputs (PII). The CPU logs the event in the diagnostic buffer and calls OB85 (Program execution error OB). Reference: Event Class 3 — Synchronous Errors.

Why does the help text say "only part of the current error was remedied"?

16#38B3 and 16#39B3 form an incoming / outgoing pair. The first time the error is raised, the CPU logs 16#39B3 (incoming) and calls OB85. When the affected module recovers, 16#38B3 (outgoing) is logged. If the module faults again before the next full cycle, only the latest pair is visible, so engineers perceive the original error as never being fixed.

How do I increase the update interval for the process image?

Open HW Config, go to the CPU properties, and either lengthen the OB1 minimum cycle time using SFC 43 ("OB1_SCAN_TIME"), or move the affected inputs to a dedicated Process Image Partition (PIP) refreshed by a higher-numbered OB such as OB 35 (default priority 12, 100 ms).

Can a loose PROFIBUS connector cause 16#38B3?

Yes. A loose or terminated PROFIBUS DP connector (or an IM 460/461 link cable between racks) will intermittently fail to deliver the slave's input data, which the CPU surfaces as a process image access error at the failed slot's logical address. Re-seating the connector and verifying the termination resistor (ON at the ends, OFF in the middle) usually clears the event.

Do I need OB85 loaded to keep the CPU running after a 16#38B3 event?

Yes. If OB85 is not loaded, the CPU will transition to STOP on the first access error. Insert the default empty OB85 from the Standard Library first, then add the SCL logic in Section 7 only after the basic symptom has cleared, so you can confirm whether the error is hardware- or program-related.

Back to blog