SM331-7KF02 ±80mV Voltage Reading: S7-300 AI Configuration

David Krause20 min read
S7-300SiemensTroubleshooting
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Problem Overview

A SIMATIC S7-300 station built around the CPU 314-2DP (6ES7 314-2AG14-0AB0) reads thermocouples correctly on channels 0-3 of an SM 331 analog input module, 6ES7 331-7KF02-0AB0, but the millivolt pressure transducer (0-33 mV output) wired to channels 4-7 (pins 12, 13, 14, 15) reports a constant 0x7FFF (overflow / wire-break) or 0x8000 value. Thermocouples return stable engineering values, the +24 V supply is healthy, and the diagnostic LED is off, so the fault is configuration, wiring, or signal conditioning — not a module hardware failure.

The root cause is almost always one of five conditions:

  1. The pressure transducer channels are still configured as thermocouple type in HW Config, so the module attempts cold-junction compensation and linearization against a TC type the transducer does not produce.
  2. The mechanical range module on the affected channel group is set to a position (B/C/D) other than A, which selects ±80 mV / thermocouple ranges — a wrong position physically disconnects the inputs from the ADC.
  3. The ±80 mV signal is wired single-ended by mistake, missing the M- return path, so the converter reads the common-mode voltage of an open input rather than the transducer output.
  4. Excessive electromagnetic interference on the millivolt pair — thermocouples tolerate noise because their EMF is in the tens of millivolts, but a 33 mV transducer is in the same order of magnitude and demands shielded, twisted pair with single-point grounding.
  5. The pressure transducer is floating (ungrounded) and the S7-300 analog M- reference is not tied, causing the differential input to drift or latch at a rail.

This reference walks through hardware identification, the four range-module positions, the 7KF02 pinout, the correct STEP 7 / TIA Portal configuration for a ±80 mV transducer, and the verification procedure that confirms the fix. The complete SM 331 module documentation is in the Siemens manual SIMATIC S7-300 SM 331; AI 8 x 12 Bit (6ES7331-7KF02) manual and the S7-300 system reference SIMATIC S7-300 Module Specifications. The TIA Portal configuration help is at the Siemens Industry Online Support portal.

Module Identification and Specifications

The affected module is the SM 331; AI 8 x 12 Bit with order number 6ES7 331-7KF02-0AB0. The 7KF02 variant is the only SM331 channel in the S7-300 family that supports type B, E, J, K, L, N, R, S, T and U thermocouples together with millivolt and voltage ranges in a single module — which is why the same module handles both the thermocouple bank and the pressure transducer.

Parameter Value
Order number (MLFB) 6ES7 331-7KF02-0AB0
Number of inputs 8 (4 channel groups of 2)
Resolution 12 bits + sign (12 bits + sign, 13-bit FSR effective)
Conversion time per channel 85 ms (50 Hz rejection) / 70 ms (60 Hz rejection)
Galvanic isolation Yes, between channel groups and backplane
Diagnostic interrupt Configurable, group-wise
Range module Mechanical 4-position insert (A / B / C / D), one per group
Common-mode range, ±80 mV ±2 V max
Operating temperature 0 °C to 60 °C horizontal mounting
Required front connector 6ES7 392-1AJ00-0AA0 (20-pin screw)

The CPU 314-2DP (6ES7 314-2AG14-0AB0) provides an integrated MPI/DP interface; the analog module sits in the central rack or an IM 360/361 expansion rack. STEP 7 V5.5 SP2 or higher, or TIA Portal V13 SP1 or higher, must be used to configure the module — older STEP 7 versions do not support the 7KF02 MLFB and will reject the configuration with an "unknown module type" error during HW Config build.

Pinout and Channel Group Architecture

The 7KF02 organises its eight analog inputs into four channel groups of two adjacent channels. Each group shares one mechanical range module position and one set of HW Config parameters. The front connector (6ES7 392-1AJ00-0AA0) is a 20-pin screw terminal; the pin mapping relevant to the affected system is:

Pin Signal Channel group Use in this application
2 M+ channel 0 Group 0 TC channel 0 positive
3 M- channel 0 Group 0 TC channel 0 negative
4 M+ channel 1 Group 0 TC channel 1 positive
5 M- channel 1 Group 0 TC channel 1 negative
6 M+ channel 2 Group 1 TC channel 2 positive
7 M- channel 2 Group 1 TC channel 2 negative
8 M+ channel 3 Group 1 TC channel 3 positive
9 M- channel 3 Group 1 TC channel 3 negative
10 CJC+ for group 0 Group 0 Cold-junction compensation sensor (Pt100)
11 CJC- for group 0 Group 0 Cold-junction compensation sensor (Pt100)
12 M+ channel 4 Group 2 Pressure transducer positive
13 M- channel 4 Group 2 Pressure transducer negative
14 M+ channel 5 Group 2 Unused / spare voltage input
15 M- channel 5 Group 2 Unused / spare voltage input
16 M+ channel 6 Group 3 Unused / spare voltage input
17 M- channel 6 Group 3 Unused / spare voltage input
18 CJC+ for group 1 Group 1 Required when group 1 is configured for TC
19 CJC- for group 1 Group 1 Required when group 1 is configured for TC
20 Functional earth / shield terminal n/a Connect cable shield

Note that pins 10 and 11 are internally routed to the cold-junction compensation circuit of group 0; when group 0 is configured for thermocouples, a Pt100 (or Ni100) RTD must be wired to pins 10/11 — or the channel must be set to "internal compensation" with a CJC RTD present on a neighbouring channel that shares the same reference temperature. Bridging pin 10 to pin 11 with a wire is incorrect: the bridge shorts the CJC input, the firmware reads a temperature error, and the TC linearization will be wrong by 5-30 °C. Replace the bridge with a real Pt100 element physically mounted at the terminal block so that the cold-junction compensation measures the actual terminal temperature.

Range Module Position Settings

The range module is a small white plastic insert on the left side of the module (visible when the front cover is open). It carries one of four possible mechanical positions (A, B, C, D) and a single insert sets the range for the entire group, while HW Config activates or deactivates individual channels. The 7KF02 range mapping is:

Position Measurement type HW Config range
A ±80 mV and thermocouples B, E, J, K, L, N, R, S, T, U "Voltage ±80 mV" or "Thermocouple" with selected type
B ±250 mV, ±500 mV, ±1 V "Voltage ±250 mV", "±500 mV" or "±1 V"
C ±2.5 V, ±5 V, ±10 V, 0-10 V, 1-5 V "Voltage ±2.5 V", "±5 V", "±10 V", "0-10 V" or "1-5 V"
D ±3.2 mA, 0-20 mA, 4-20 mA, ±20 mA, 4-wire RTD "Current" or "Resistance" with appropriate range

For the pressure transducer (0-33 mV) the range module position must be A. If the range module is reported as A, the mechanical side is correct. The next place to look is the HW Config entry.

Critical: A wrong mechanical position cannot be fixed by software. The range module insert must physically match the configured measurement type, or the input circuit returns 0x8000 (overflow), 0x7FFF (wire-break) or random noise regardless of the input voltage. Power down the rack, remove the front connector, and re-seat the range module before suspecting firmware.

Wiring Thermocouple Inputs (Working Channels)

The thermocouple channels (0-3) work because four conditions are met simultaneously:

  1. Range module position A is set for groups 0 and 1.
  2. HW Config sets group 0 and group 1 to "Thermocouple" with the correct TC type (e.g., Type K) and "external compensation" with a Pt100 on pins 10/11.
  3. The TC wire is connected to M+ (pin 2, 4, 6, 8) and M- (pin 3, 5, 7, 9).
  4. The cable shield is connected to pin 20 and tied to functional earth at the cabinet ground bar.

If the user has bridged pin 10 to pin 11, this bridge should be removed and replaced with a real Pt100 element physically mounted at the terminal block so that the cold-junction compensation measures the actual terminal temperature. The compensation value contributes typically 5-30 °C of offset and, if shorted, will saturate the TC reading. For pure internal compensation, leave the CJC pins open and select "internal compensation" in HW Config — internal compensation uses a single internal temperature sensor per group and is acceptable when the terminal temperature is stable within ±2 °C.

Wiring Low-Voltage Inputs (±80mV Pressure Transducer)

A pressure transducer with 0-33 mV output is wired as a differential voltage source across M+ (pin 12) and M- (pin 13) of channel 4. Critical wiring rules:

  1. Use a twisted, shielded pair. The shield connects to pin 20 at the module and to a clean earth at the cabinet entry point. The shield is not used as a signal conductor.
  2. The transducer output must be floating (galvanically isolated from ground). If the transducer has a third wire (case ground), that wire goes to the cabinet ground bar, not to the M- pin.
  3. Wire the M+ terminal to the positive transducer output. Wire the M- terminal to the negative transducer output. Do not short M- to M-ANA — they are internally tied only at the ADC reference, and the short removes the differential behaviour.
  4. Apply a small integration time in HW Config (50 Hz or 60 Hz rejection) to suppress mains noise on the millivolt signal.
  5. For long runs (>10 m) terminate the cable at the cabinet entry with a feed-through or use a dedicated signal conditioner / isolated transmitter that converts 0-33 mV to 4-20 mA and connects to the module on a 4-20 mA channel (range module position D).

For very long runs or noisy plants, fit a dedicated isolating signal conditioner at the field end. The conditioner converts 0-33 mV to 4-20 mA and provides 1.5 kV isolation, which removes ground-loop currents that would otherwise swamp a 33 mV signal. Siemens offers the 3RS70 series signal conditioners; equivalent third-party units include the Phoenix Contact MACX MCR-UI-UI and the WAGO 857 series. All of these are DIN-rail mounted and accept ±80 mV / ±1 V / 4-20 mA input ranges with configurable output.

STEP 7 / TIA Portal Hardware Configuration

The most common cause of the failure is the HW Config entry. Open the project in STEP 7 V5.5 SP2 (or TIA Portal V16 / V17) and select the SM 331 slot. The Properties → Inputs dialog contains a table of eight channels. For each channel used as a voltage input, set:

Parameter Value for ±80 mV pressure transducer
Measurement type Voltage (not Thermocouple, not Current)
Measuring range ±80 mV (must match range module position A)
Integration time 60 ms (60 Hz rejection, North America) or 50 ms (50 Hz, Europe / Asia)
Diagnostic interrupt Enabled (recommended for wire-break engineering)
Hardware interrupt Optional — enable upper/lower limit only if required
Group diagnostics Enabled
Substitute value behaviour Keep last value (default) or substitute value (configurable in OB1)

The default STEP 7 template for a 7KF02 adds the module with channel 0 set to Type K thermocouple. If channels 4-7 are not explicitly re-configured, they remain defaulted to the thermocouple measurement, and the module returns 0x7FFF (overflow / wire-break) for any voltage below the TC type's zero scale. This is the most likely root cause of the symptom: the pressure transducer channel "is not reading anything".

In TIA Portal, navigate to Device configuration → AI8_12Bit → Properties → General → Analog inputs and click on the channel index. The drop-down "Measurement type" defaults to "Thermocouple"; change it to "Voltage", then select the "±80 mV" range from the second drop-down. Compile the hardware configuration (HW Build) and download to the CPU.

Verify the input word in the standard address space. For a slot-4 AI module, the default input address is PIW 256..271 (16 bytes). Channel 4 occupies the 9th and 10th byte = PIW 264. The raw value is a 16-bit signed integer in two's-complement:

// S7-300 input word for 7KF02 channel 4 at slot 4 (default address)
"DB_Analog".Channel4_Raw := PIW 264;

// Apply SCALE function (S7-300/400: FC105 from standard library)
"DB_Analog".Channel4_Eng := SCALE_DB(
   IN  := "DB_Analog".Channel4_Raw,
   HI_LIM := 33.0,           // mV high engineering value (full scale)
   LO_LIM := 0.0,            // mV low engineering value
   BIPOLAR := FALSE,
   RET_VAL := "DB_Analog".SCALE_RetVal);

For TIA Portal / S7-1200 / S7-1500 use the SCALE_X and NORM_X instructions. For an S7-300 / S7-400 use the legacy FC105 "SCALE" from the STEP 7 standard library, available since STEP 7 V5.0. FC106 "UNSCALE" is the inverse, used to write engineering values back to the output module.

Diagnostic Flowchart

SM331-7KF02 ±80mV Channel Reading Zero - Diagnostic Flowchart PIW = 0x7FFF (overflow) or 0x8000 (underflow) SF LED ON? (check Diag buffer) Yes Diag code 0x01: wire break / 0x04: range module mismatch No HW Config = Voltage? (not Thermocouple / not Current) No Set type = Voltage range = ±80 mV Yes Range module = A? (physical position, left side of module) No Power off Set position A Yes M+ / M- wiring correct? (shield at one end only) No Re-wire pins 12/13 differential pair Yes

Common Configuration Errors

Symptom Likely cause Fix
PIW returns 0x7FFF (32767) — overflow / wire-break Channel still in TC mode; range module wrong Set measurement type = Voltage, range = ±80 mV; verify range module = A
PIW returns 0x8000 (-32768) — underflow Negative overflow (signal more negative than -80 mV) Check polarity; check that M- is not open; check transducer output polarity
PIW returns a stable but wrong value 50 Hz / 60 Hz noise integrated into the conversion Use shielded twisted pair; set integration to 50/60 Hz; route cable away from VFD outputs
PIW fluctuates ±200 counts at constant pressure Common-mode voltage / ground loop Verify transducer is floating; tie M- only at the module; add signal conditioner
PIW reads correctly at one terminal but not at another Shielding discontinuity / multiple ground points Strip shield at transducer end; ground only at the cabinet end
PIW is correct then drops to 0x7FFF at random Wire-break diagnostic trigger on the unused channel of the group Set the unused channel of the same group to "deactivated" in HW Config
CPU goes to STOP with "I/O access error" on slot 4 Hardware mismatch: configured 7KF02 but physically a different MLFB Read module order number via HMI / online; replace with 6ES7331-7KF02-0AB0
PIW shows correct value but FC105 returns wrong engineering value Wrong HI_LIM / LO_LIM polarity or unit mismatch Verify HI_LIM = 33.0 mV, LO_LIM = 0.0 mV, BIPOLAR = FALSE; check the unit annotation in the DB

Noise, Shielding, and Grounding for Millivolt Signals

A 33 mV signal is approximately 60 dB below a 0-10 V signal. The SM 331 manual specifies the maximum common-mode voltage as ±2 V (for ±80 mV range) and the maximum allowed series-mode noise as ±0.5 LSB. Concretely, any of the following break the measurement:

  • An unshielded cable routed alongside a 400 V VFD output (>1 m parallel run).
  • A ground loop between the transducer case and the cabinet ground.
  • A 50 Hz / 60 Hz field from a contactor coil or solenoid within 0.5 m of the cable.
  • A long cable (>50 m) without a signal conditioner — copper pair resistance of 100 Ω creates 0.5 mV of error per 5 µA of leakage current.
  • Twisted-pair polarity reversed: differential input noise increases rather than cancels.

Best practice for sub-100 mV signals in an S7-300 cabinet:

  1. Route the millivolt pair in a dedicated cable tray, minimum 200 mm from any power cable. Cross power cables at 90°.
  2. Use twisted, shielded pair (LiYCY 2 x 0.34 mm² or equivalent). The shield is bonded to the cabinet ground bar at one end only (the module end), using a clamping bracket that provides 360° contact.
  3. Tie M- to functional earth at the module terminal only if the transducer is grounded. If the transducer is floating, leave M- floating and use the module's internal ground reference.
  4. Set the HW Config integration time to the local mains frequency: 50 Hz (50 ms) for Europe / Asia, 60 Hz (60 ms) for North America.
  5. Consider fitting a Siemens 3RS70 signal conditioner or equivalent. Convert 0-33 mV to 4-20 mA at the field end, and use a separate 4-20 mA channel (range module position D) for the S7-300. This eliminates ground loops and provides 1.5 kV isolation.

Diagnostic LED and Error Code Interpretation

The SM 331 front panel has a single SF (red) LED that indicates a group-level fault. The 7KF02 also reports errors via diagnostic interrupt OB82 and via the diagnostic buffer of the CPU. The relevant error codes are:

LED Diagnostic byte Meaning Action
SF off 0x00 Module OK No action; check configuration
SF on 0x01 Wire break on a TC or mV channel Check transducer wiring; if unused, deactivate the channel in HW Config
SF on 0x04 Range module position mismatch Power off, reposition mechanical range module to match the configured type
SF on 0x08 Common-mode voltage exceeded (±2 V) Check M- reference and shield ground; isolate the transducer
SF on 0x10 24 V sensor supply missing Check that 24 V is applied to the L+ / M terminals where required
SF on 0x20 Channel group not configured Configure all channels of a group, even the unused ones, or set the group to "deactivated"
SF blinks 0x02 Parameter assignment error Check that the HW Config range matches the mechanical range module position

Read the diagnostic buffer in STEP 7 with PLC → Online → Module Information → Diagnostics Buffer, or in TIA Portal with Online & Diagnostics → Diagnostics. The entry will be of the form "Module fault, channel 4, error code 0x04" — matching one of the rows above. For automatic handling in the user program use the standard system blocks SFC 51 "RDSYSST" to read SSL partial system list 0x00B1 (diagnostics status of an I/O module) or OB82 to react to the interrupt. Note that OB82 must be present in the user program; if it is not, the CPU will go to STOP when a diagnostic interrupt fires.

STEP 7 V5.5 vs TIA Portal Configuration

Aspect STEP 7 V5.5 SP2 / V5.6 TIA Portal V13 SP1 → V18
Module insertion HW Config → catalog → SM-300 → AI-300 → 6ES7 331-7KF02-0AB0 Device configuration → Catalog → PLC → AI → SM 331 → 6ES7 331-7KF02-0AB0
Channel activation Double-click slot → Inputs tab → per channel Properties → General → Analog inputs → click channel row
Integration time Drop-down: 2.5 / 16.6 / 20 / 50 / 60 ms Same drop-down, same units
Diagnostic buffer PLC → Module Information → Diagnostics Buffer Online & Diagnostics → Diagnostics
Online view of raw values Monitor / Modify → PIW address Watch table → PIW address
User program scaling FC105 SCALE / FC106 UNSCALE NORM_X + SCALE_X (TIA blocks) or imported FC105
Project migration n/a (legacy) Migrate STEP 7 V5 project with the migration tool; SM331-7KF02 supported

Both tools produce equivalent HW Config binaries. A STEP 7 V5.5 project can be migrated to TIA Portal V16 or later using the "Migrate project" function; the channel configuration is preserved, but the user program must be re-compiled because the symbolic addresses change when the TIA portal converts absolute (PIW) to symbolic (tag-based) addressing.

Migration to Newer Modules

The SM 331-7KF02-0AB0 is in the phase-out / spare-parts life-cycle phase as of 2024, with delivery against confirmed orders only. The current recommended replacement is the SM 331; AI 8 x 13 Bit with order number 6ES7 331-7PF01-0AB0 (or the 6ES7 331-7PF11-0AB0 variant for 4-channel groups). Key differences:

Parameter 6ES7 331-7KF02-0AB0 (legacy) 6ES7 331-7PF01-0AB0 (current)
Resolution 12 bit + sign 13 bit + sign
Conversion time per channel 85 ms (50 Hz) 9 / 23 / 65 / 80 ms configurable
Range module Mechanical 4-position Electronic (no range module)
Channel groups 4 groups of 2 4 groups of 2 (same)
Pinout 20-pin 40-pin (additional shield / supply pins)
±80 mV support Yes (position A) Yes (HW Config only)
Diagnostic interrupt Group-wise Channel-wise
Backward-compatible in STEP 7 / TIA n/a Yes, drop-in replacement in most projects

For greenfield installations targeting TIA Portal V18, the recommended platform is the S7-1500 with the AI 8 x U/I/RTD/TC ST (6ES7 531-7QF00-0AB0) module. This module supports thermocouples and ±80 mV without a mechanical range module and provides 16-bit resolution with channel-level diagnostics. The configuration dialog is identical to the SM 331 7PF01 in concept but the user program is re-compiled to the S7-1500 instruction set (NORM_X / SCALE_X instead of FC105 / FC106).

Verification Procedure

After applying the fix, verify the channel with a calibrated millivolt source (e.g., WIKA Pascal or Beamex MC6). If a calibrator is not available, use the following bench test:

  1. Open STEP 7 / TIA Portal. Place the CPU in STOP. Open Monitor / Modify on PIW 264.
  2. Short M+ (pin 12) to M- (pin 13) at the transducer end of the cable. The PIW must read 0 (±1 count). If it reads 0x7FFF or 0x8000 the wiring is open or the configuration is wrong.
  3. Apply a known 33 mV from a millivolt calibrator across M+ and M-. The PIW must read approximately +1689 counts (33 mV / 80 mV × 4095 = 1689). If the count is negative, reverse M+ and M-.
  4. Apply -33 mV. The PIW must read approximately -1689 counts. This confirms the bipolar behaviour and validates the range module and HW Config combination.
  5. Disconnect the calibrator and reconnect the transducer. Apply pressure. The PIW must follow pressure proportionally with a coefficient of ~51.2 counts per mV (4096 / 80).

End-to-end validation requires a pressure calibrator (dead-weight tester or pump) but the in-loop value comparison confirms the channel is functional. The "0 at 0 bar" and "1689 at full scale" check is sufficient for commissioning. Repeat the test for each of the 8 channels on the module if a full system validation is required.

Frequently Asked Questions

What range module position is required for a ±80 mV signal on the SM 331-7KF02?

Mechanical position A. The 7KF02 maps position A to ±80 mV and the thermocouple types (B, E, J, K, L, N, R, S, T, U). The HW Config "Measurement type" must also be set to "Voltage" and the range to "±80 mV", or the firmware rejects the input even if the mechanical insert is correct.

Can I read 0-33 mV from a pressure transducer on the same SM 331 module that already reads thermocouples?

Yes, the 7KF02 supports mixed thermocouple and millivolt channels in the same module. Configure group 0 and group 1 for thermocouples (with CJC on pins 10/11 for group 0 and pins 18/19 for group 1) and group 2 / 3 for ±80 mV voltage. The mechanical range module must be position A for every group that uses either TC or ±80 mV.

Why does the thermocouple channel return correct values but the millivolt channel returns 0x7FFF?

The most common cause is that the pressure transducer channel is still configured as a thermocouple in HW Config. A TC channel applies a 0 °C reference that puts a 0 mV input at the bottom of the linearization range; a 33 mV signal is below the underrange threshold of the TC type, and the firmware reports 0x7FFF (overflow / wire-break). Change the channel to "Voltage ±80 mV" in HW Config, compile, and download.

How do I wire a floating pressure transducer to avoid ground loops?

Connect the transducer output across M+ (pin 12) and M- (pin 13) only. Do not connect the transducer case or shield to the module's M-. Use a shielded twisted pair with the shield bonded to pin 20 and the cabinet ground bar at one end only (the module end). If the cable is longer than 10 m, install an isolating signal conditioner (e.g., Siemens 3RS70) that converts 0-33 mV to 4-20 mA and provides 1.5 kV isolation.

How do I read 33 mV as a 0-100 bar engineering value in the user program?

Apply the legacy FC105 SCALE function (S7-300 / 400) or the NORM_X / SCALE_X instructions (S7-1200 / 1500) to PIW 264. Set HI_LIM = 100.0, LO_LIM = 0.0, BIPOLAR = FALSE, and the SCALE function returns the bar value directly. The raw 33 mV maps to approximately 1689 counts; SCALE multiplies by 100 / 1689 to give 100.0 bar at full scale.

What is the replacement for the SM 331-7KF02-0AB0?

The recommended drop-in replacement is the SM 331; AI 8 x 13 Bit (6ES7 331-7PF01-0AB0) which uses an electronic range selection (no mechanical range module) and supports 13-bit resolution. For greenfield installations use the S7-1500 with the AI 8 x U/I/RTD/TC ST (6ES7 531-7QF00-0AB0) module, which removes the range module entirely and provides 16-bit resolution with channel-level diagnostics.

Back to blog