ROBOTIC.INDUSTRIES

Safety and Standards

Performance Level vs SIL: Which One Applies to Your Robot

Two frameworks measure the same thing differently. ISO 13849 uses performance levels a to e, IEC 62061 uses SIL 1 to 3. Which to use, how they map, and what determines the target.

Robot cell perimeter with mesh fencing, interlocked door and warning beacon
Robot cell perimeter with mesh fencing, interlocked door and warning beacon

Both frameworks answer the same question: how reliable must this safety function be. ISO 13849-1 expresses the answer as a performance level from a to e, IEC 62061 as a safety integrity level from SIL 1 to 3. For machinery, including robot cells, the performance level route is more common in Europe. Both are acceptable, and the target is derived from the risk, not chosen by preference.

a to eperformance level scale
1 to 3SIL range applicable to machinery
PL dmost common target for robot safety functions
3parameters that set the target

How the target is derived

Under ISO 13849-1 the required performance level comes from three parameters, assessed for each safety function separately.

  • Severity of injury. S1 for slight and normally reversible, S2 for serious or irreversible including death.
  • Frequency and duration of exposure. F1 for seldom to less often, F2 for frequent to continuous.
  • Possibility of avoiding the hazard. P1 for possible under specific conditions, P2 for scarcely possible.

A robot cell hazard is typically S2, because an industrial arm can cause serious injury; F2, because operators interact regularly; and P2, because a fast arm cannot be avoided once motion begins. That combination lands on PL d, which is why so many robot safety functions carry that target.

Approximate correspondence between the two frameworks
Performance levelAverage probability of dangerous failure per hourApproximate SIL
a10⁻⁵ to 10⁻⁴no correspondence
b3 x 10⁻⁶ to 10⁻⁵1
c10⁻⁶ to 3 x 10⁻⁶1
d10⁻⁷ to 10⁻⁶2
e10⁻⁸ to 10⁻⁷3
Per function, not per cell. A cell does not have a performance level. Each safety function does: the protective stop from the scanner, the emergency stop, the speed limitation in manual mode, the safe zone monitoring. They frequently differ, and a file that states one level for the whole installation has not done the analysis.

What achieving a level requires

What a performance level demands of the architecture
LevelTypical architectureDiagnostic coverageExample function
b or cSingle channel with some monitoringnone to lowNon-critical interlock
dTwo channels with cross monitoringmedium to highProtective stop, guard interlock
eTwo channels, high diagnostics, testedhighHazard with immediate fatal potential

Beyond architecture, the calculation needs component reliability data, usually mean time to dangerous failure, the diagnostic coverage of the monitoring, and an assessment of common cause failure. Component manufacturers publish these figures precisely so integrators can perform the calculation.

The safety functions a robot cell typically has

Listing them explicitly, each with its own target and evidence, is what a complete file looks like.

Typical safety functions and targets in a robot cell
FunctionTypical targetSensorActuator
Emergency stopPL d, cat 3Button contactsDrive disable and contactors
Guard door interlockPL d, cat 3Coded interlock switchDrive disable
Protective stop from a scannerPL d, cat 3Safety laser scannerSafe stop function
Safe reduced speed in manual modePL dEncoder, mode selectorDrive speed limitation
Enabling device in teach modePL dThree-position switchDrive enable
Safe zone or space limitationPL dEncoder based monitoringSafe stop on violation
Contact force limitationPL dJoint torque sensingMotion limitation
Brake monitoringPL c or dEncoder during testFault signal

Each row needs its own derivation, its own calculation and its own validation record. Eight functions is a normal count for a guarded industrial cell, and a file with a single blanket statement covering all of them is the most common finding in a robot safety audit.

Where files go wrong

  1. A level asserted rather than derived. The severity, frequency and avoidance assessment is missing, so the target is an opinion.
  2. Architecture without calculation. Two channels do not automatically give PL d; the component data and diagnostic coverage decide it.
  3. The weakest element ignored. A function is only as good as its whole chain, sensor to logic to actuator. A PL e scanner feeding a single-channel relay is a PL c function.
  4. Software omitted. Safety-related software has its own requirements, and configurable safety controllers need their configuration validated.
  5. No validation. The calculation predicts; validation confirms. Fault injection testing is part of the obligation, not an optional extra.

Frequently asked questions

Do I need a performance level or a SIL?

Either is acceptable for machinery. In Europe the ISO 13849 performance level route is more common for robot cells; IEC 62061 SIL is more usual where the plant already works in process industry terms. What matters is that one is derived and evidenced.

What performance level do robot cells usually need?

PL d for most protective functions, because the typical assessment is serious injury potential, frequent exposure and scarcely avoidable hazard. Functions with immediate fatal potential can reach PL e.

Does a cell have a single performance level?

No. Each safety function is assessed and rated separately, and they routinely differ. A file quoting one level for the whole installation has not performed the analysis.

Do two channels automatically give PL d?

No. Architecture is one input; the calculation also needs component reliability data, diagnostic coverage and a common cause failure assessment. Two channels with poor diagnostics can fall short of PL d.

Is a calculation enough?

No. The calculation predicts the achieved level, and validation confirms the function behaves as specified including under fault conditions. Fault injection testing is part of the obligation.

Sources

  1. ISO 13849-1, safety-related parts of control systems, general principles for designInternational Organization for Standardization, performance levels and their derivation
  2. IEC 62061, functional safety of safety-related control systemsInternational Electrotechnical Commission, the SIL route for machinery
  3. ISO 10218-1:2025, Robotics, Safety requirements, Part 1International Organization for Standardization, functional safety requirements for robots