DriveLab
Account

Testing a PLC program so that it fails safe

Normally closed wiring, fault injection, the test log, forcing and its dangers, what happens at STOP and at power-up, the cross reference, and a commissioning procedure. The method every TP is assessed on.

30 min

Show me

A program that works when everything is healthy has only just begun its tests. Break a wire, open a door, stall a motor, and watch what it does. (Lab Works booklet)

Design for the failures you will have

  • Stops and safety devices normally closed, tested with a normally open contact: a broken wire or a lost supply stops the machine.
  • Proof, not assumption: a movement ends on a position switch and a time-out; a motor is running when its speed sensor says so, not when its contactor is commanded.
  • No restart by itself: after a stop, a fault or a power return, a new command is needed.
  • Latched faults: a trip stays until RESET, and RESET does nothing while the cause is still present.
  • One safe state per output, written in your specification: is the brake applied, the valve closed, the motor stopped when the program stops?

Fault injection

Each TP has a fault-injection table: the test, the safe reaction required, what you observed. On the bench you pull a patch lead or switch an NC input OFF while the machine runs. On this site you do the same with the panel.

Try it on the start/stop station: start the motor, then switch F2_NC (the overload) OFF, then ON again. Then open the Timing diagram and do the same with STOP_NC.

Ladder editor on a virtual PLC-200

Drag an instruction onto the rung (or click it, then click a place). Drop below a contact to put it in parallel. Click an element to edit its address; Delete removes it.

Network 1
STARTI0.0
RUNQ0.0
STOP_NCI0.1
F2_NCI0.2
RUNQ0.0
SIMATIC S7-200 · CPU 224SFRUNSTOP
I0.0START
I0.1STOP_NC
I0.2F2_NC
Q0.0RUN0
Timet = 0.00 s · 0 scans

No errors: the program compiles.

TestSafe reaction requiredObserved
Overload opens while runningRUN OFF at once, no restart when it closes
STOP wire broken (I0.1 OFF) while runningRUN OFF
START held when the overload reclosesRUN only restarts on a new START?

The last line is a question worth asking: with the simple self-holding circuit, a START held while the overload recloses restarts the motor. Is that acceptable for your machine? If not, start on the rising edge of START.

STOP, power-up and forcing

  • In STOP, the S7-200 sets the outputs to the state chosen in the System Block (by default OFF). Check that OFF is safe for every output.
  • At power-up or STOP → RUN, SM0.1 is 1 for one scan: initialise your steps and flags there. Retentive memory (configured in the System Block) keeps its value; a GRAFCET step kept after a power cut can restart a machine by itself.
  • Forcing overrides the program and the switches. Never leave a force in place: the status chart shows forced values with a lock, and Debug → Unforce All removes them.

Commissioning, in order

  1. Wiring and I/O check, program in STOP: operate every input, see its LED and status chart value; force each output alone and see the actuator move. Sign each line.
  2. Functional tests, in RUN: the normal cycle, each mode, each step of the GRAFCET.
  3. Fault injection: every line of the table, at the worst moment (during a movement, at a transition).
  4. Documentation: the commented listing, the symbol table, the test log with the instructor's signatures.

Where to go next

The TP pages (Labs → PLC-200 labs) give the bench set-up, the I/O tables and the fault-injection tables of each TP. Write your GRAFCET in the player, your networks in the ladder editor or in Micro/WIN, test them here, then demonstrate them on the bench.