“If anything goes wrong, the operator will press the emergency stop pushbutton.” That is one way to close a discussion about safeguarding. The button is fitted, the circuit works and the machine stopped during the test. All that remains is to assume that someone will notice the danger, react in time and compensate for whatever the design and workplace protection failed to provide.
A designer cannot credit operator reflexes against missing safeguards. A preventive safety function is intended to stop a specified hazardous event from occurring. The emergency stop function enables intervention when an emergency situation already exists or is imminent. Its job is to oppose the development of that situation and limit the resulting harm.
It may help prevent an injury. That does not make it a substitute for protection intended to prevent the hazardous event in the first place. One provides protection; the other relies on successful intervention. That distinction must not disappear in the risk assessment under a convenient entry such as “safety system provided”.
ISO 13850 defines emergency stopping as a complementary protective measure. Not because it is unimportant, but because it complements other safeguards rather than excusing their absence.
Then comes the second misunderstanding: “Pressing the button cuts everything off.” It sounds decisive. Unfortunately, a stopped machine is not necessarily a safe machine. A person may remain trapped, while disconnecting equipment that was protecting them can make matters worse. Motion at zero does not prove that the hazard is under control.
The task cannot therefore be reduced to disconnecting the largest possible number of devices. The design must establish which hazardous actions are to stop, in what sequence, and what must remain operational to protect people. Some applications may also require additional protective actions, not merely stopping.
The operator must be able to initiate the response with one action. Before pressing the button, they should not have to calculate whether the consequences will be worse than the present danger. That calculation belongs in the design process. The simpler human intervention is meant to be, the less room the machine response may leave for unintended consequences.
If an acceptance test checks only whether a drive stopped, it can confirm stopping while leaving the central question unanswered: did the machine perform the correct action for the emergency situation? “E-STOP works” explains neither what the other safeguards prevent nor what happens to a person after the button is pressed.
The ability to stop a machine is not proof that suitable protection has been provided. Stopping motion does not always end the hazard.
1. Prevention and emergency response are not two versions of the same solution
“The light curtain stops the machine. The emergency stop pushbutton does too. Why complicate it?”
If effectiveness were judged solely by whether the motor eventually stopped, that would be a reasonable question. We could compare two diagrams, find the same contactor and conclude that the main difference was price. We would only have overlooked when the machine stops and what may happen to the person before it does.
A preventive safety function is intended to prevent a specified hazardous event. An emergency stop function is intended to avert or limit an existing or imminent emergency situation. Both may stop motion, but they do not solve the same problem.
A light curtain is not there to report that someone has already reached the tool
Consider a workstation where a person can reach a moving tool. Assume that a light curtain can protect this access: hazardous motion can be stopped during the cycle, and the tool cannot be reached without passing through the detection field.
The light curtain detects the hand and initiates stopping. Its distance from the tool accounts for the response time of the complete system and the machine stopping time. Hazardous motion must have ceased before the person can reach it. That is the function’s task—not merely switching outputs or displaying “safety stop” on a panel.
If the hand can reach the moving tool before the machine stops, protection against that contact has not been achieved. The light curtain may still operate correctly, the controller may receive the signal, and the drive may execute the command exactly as programmed. Every device can work as designed while the design itself is wrong.
Testing a light curtain therefore means more than interrupting its beams. The test must demonstrate that detection and stopping actually prevent the event against which protection was intended.
With emergency stopping, a person must initiate the intervention
An emergency stop device does not take over the job of access detection. It enables a person to initiate a predefined response to a situation requiring immediate intervention.
An injury need not have occurred already. ISO 13850 also refers to an imminent emergency situation. Someone may observe a dangerous sequence developing and press the button before harm occurs. Intervention may also be needed while hazardous exposure is already taking place.
In the first case, protection is initiated when the hand is detected. In the second, a person must recognise the need for intervention and act. Saying that “both stop the machine” does not make those tasks equivalent.
If the light curtain in our example were removed and only an emergency stop pushbutton remained, automatic stopping after detection of the hand would disappear. A person would now be responsible for noticing the problem and initiating the response. Detection has been deleted from the design. The justification says that the operator is trained. The saving is real; the claimed equivalence is imaginary.
That is why ISO 13850 treats emergency stopping as a complementary protective measure and prohibits its use as a substitute for technical protective measures and other necessary functions. Emergency stopping is itself safety-related. That does not mean it can be assigned any protective task we happen to have left unresolved.
The same relay does not erase the difference
Functions may share control-system elements when the applicable requirements are met. There is no need to multiply hardware for its own sake. What must be defined separately is what initiates each function and what protective objective it is intended to achieve.
For a light curtain, we verify protection against hazardous contact. For an emergency stop, we verify the correct response to the emergency situation under consideration—and that response is not always limited to stopping motion.
Pressing the emergency stop pushbutton cannot prove that a person will be unable to reach a moving tool. Equally, a correctly applied light curtain does not answer every question about necessary emergency intervention. A shared contactor may be justified. One shared “compliant” tick copied across two different tasks is not enough.
Two functions can stop the same contactor and still address entirely different risks. Hardware in common does not mean a protective purpose in common.
2. “The operator will react in time” is not machine safeguarding
Assume that an accessible chain drive remains beside a manual loading station. The entanglement hazard has been identified. The listed protective measures are an emergency stop pushbutton, warning signs and operator training. After those measures are entered into the assessment, the risk is declared acceptable.
The chain remains accessible. The worker continues to perform the same tasks beside it. What changed? The colour of a spreadsheet cell. A guard was not in the budget. Operator reflexes were entered free of charge.
What actually reduced the risk?
Installing the button did not restrict access to the drive. It did not reduce the frequency of work nearby or remove the mechanism’s ability to entangle a person. It provided a means of initiating an emergency stop. The next step is to demonstrate the circumstances in which that intervention can help.
Who will notice the danger? What will reveal it? Can that person reach the device? Will enough time remain between recognising the situation and the onset of harm?
“The operator has been trained” answers only part of those questions. It confirms preparation for specified actions. It does not prove that the operator will be physically able to perform them in the scenario being assessed. A signature on a training record neither shortens machine stopping time nor extends the time available before entanglement.
Emergency stopping can improve the possibility of avoiding or limiting harm, so it is not worthless in risk scoring. But the benefit must be tied to a credible sequence of events. It cannot be awarded automatically for the presence of a red button.
If the possibility of effective intervention has not been demonstrated, “E-STOP and training” cannot by itself justify adequate protection against the entanglement hazard.
The test measured time after pressing—not from the start of the danger
During a test, the technician stands beside the device, knows what will happen next and deliberately initiates the stop. The measurement begins when the device is actuated and ends when hazardous motion ceases. That is a necessary result.
It does not include what must happen first in a real emergency: noticing the danger, recognising that intervention is required and carrying out the action. The control system has a specified response time. The operator is simply assumed to be fast enough.
At the workstation, both hands may be occupied with feeding a component. The operator may be out of reach of the button or may require intervention precisely because they can no longer initiate it. Assuming that a colleague will act also requires verification. That second person must be present, see the event and be able to intervene. Writing “assistance from a co-worker” into an assessment does not cause one to appear beside the machine.
Accessibility must therefore be checked against the places and tasks where intervention may be needed—not only from the comfortable position of someone facing the control panel during acceptance testing.
A perfectly functional circuit may fail to receive the command in time. That is not a relay fault for diagnostics to detect. It is an unverified assumption about human participation. A faster controller cannot fix a problem that arises before anyone presses the button.
“Exercise particular care”—preferably for the entire shift
A workstation instruction states: “The operator must exercise particular care, continuously observe the machine and use the emergency stop immediately in the event of danger.” The sentence could be attached to almost any machine. That is exactly why it explains so little.
Suppose the operator must remove finished parts, inspect their quality and place them in a container behind the workstation. At the same time, the instructions demand “continuous observation of the danger zone”. To place a part in the container, the operator has to turn around.
They are not ignoring the instructions, using a phone or inventing an unauthorised method. They are performing the task planned by the designer—the same designer who made safety depend on looking in the opposite direction. The operation was designed for one person. The required attention was apparently designed for two.
In that arrangement, an instruction to “stop immediately” does not solve the problem. Someone first has to notice that stopping is necessary. If the protective concept depends on continuous observation while the planned work interrupts that observation, its assumptions contradict one another. Adding the word “particular” before “care” changes none of the working conditions.
This is not an argument for removing warnings from instructions. It is an argument against using a warning to perform design work that was never done. Information for use has a defined place in risk reduction under ISO 12100 Step 3. It does not replace inherently safe design measures or safeguarding.
The same applies to emergency stopping. It complements protection; it does not transfer the protective task to human vigilance. The workstation must remain adequately protected while the operator correctly performs tasks that divert attention from the machine—not only while staring at it without interruption.
“Be careful” can be a warning. It is not a technical safeguard delivered in sentence form.
Training can prepare a person to act. It cannot create time, reach or awareness that the machine layout has denied them.
3. A stopped machine can still endanger a person
A function description says: “Actuation of the emergency stop stops the drives and brings the machine to a safe state.” The first part can be checked: the drives no longer cause hazardous motion. The second requires us to establish what else can harm a person and what happened to those hazards.
Writing “safe state” after the word “stop” is easy. In the physical machine, that relationship does not materialise because someone inserted a comma. Motion may cease while a person remains under pressure, trapped or unable to escape. The machine need not begin another cycle to continue causing harm.
Speed fell to zero. Clamping force may not have
Consider a pair of rollers, one of which is pressed against the other by springs. A limb becomes trapped, the E-STOP is actuated and rotation stops. Further drawing-in has been interrupted, but the rollers remain clamped together.
The drive followed its command. The springs are also behaving exactly as designed. The person is still being crushed.
This does not mean stopping was unnecessary or ineffective in preventing further infeed. It means stopping did not resolve the entire situation. Interrupting hazardous motion and enabling the release of trapped persons are different tasks that must be coordinated.
If entanglement or trapping has been considered in the analysis, the designer must also determine how the person can be released. Depending on the machine, this may require separating components, relieving pressure or providing a suitably designed reverse movement. None of those actions is universally correct. The problem has not been solved merely because it stopped moving.
ISO 13850 does not reduce emergency response to standstill
ISO 13850 recognises that the emergency stop function may initiate actions other than stopping, including reversing or limiting motion. The objective is to limit the possibility of harm, not to maximise the number of de-energised outputs.
Hazardous movements and operations are to stop. It does not follow that every movement performed as part of an emergency response is automatically prohibited. A properly designed movement can protect or release a person.
“Properly designed” is doing real work in that sentence. Before using reverse motion, establish whether it genuinely helps in the trapping scenario. Could it aggravate the injury? Could it create another trapping point? What happens to clamping force? What range, speed and control method are required?
Changing the sign of a speed command is not yet the design of a rescue function, even if it takes only one line of software.
ISO 13850 identifies the possibility of such actions but does not specify detailed requirements for implementing them. Citing the standard therefore does not demonstrate that an arbitrary reverse or opening movement is safe. The actual solution must be assessed.
Stopping must not remove the means of release
There is also a distinction between an additional action incorporated into the response to E-STOP and a separate function used to release a person after stopping.
In the first case, the action forms part of the designed emergency response. In the second, stopping does not itself complete the release, but it leaves the correct means available. Not every machine should automatically open or reverse when the button is pressed.
ISO 13850 does require emergency stopping not to impair other protective functions. It expressly includes the release of trapped persons. That matters when the proposed procedure is: “Release is possible, but first normal operation has to be restored.”
A release function should enable rescue, not make every production movement available again in the hope that only the correct one will be selected. Its operating conditions, available movements and necessary limitations belong in the design—not in an improvised discussion after someone becomes trapped.
After stopping, the questions are therefore not limited to “what is stationary?” Ask what hazardous effects remain and what has been provided to control them. A safe state does not arise because a controller variable has that name. It must exist in the machine and for the person who cannot get out of it.
Zero speed is a measurement. A safe state is an engineered condition. Do not confuse them.
4. Why disconnecting everything can make the situation worse
“Pressing the emergency stop switches off every output.” The requirement is simple. So is the program. During acceptance, it is easy to check that everything went dark.
But one output may control the drive creating the danger while another supplies equipment protecting against a different danger. Switching off both does not provide twice the safety.
ISO 13850 requires the emergency stop function to override other functions and operations, while also requiring that it must not impair the effectiveness of other protective functions. Auxiliary equipment such as electromagnetic holding devices or braking equipment may need to remain effective. This is not a contradiction. It is a reason to establish what depends on the common power cut before drawing it.
The drive must stop. The load must not be dropped in the process
Suppose equipment moves a steel component using an electromagnetic holder that requires continuous power. The load remains supported only while the holder operates, and the design includes no independent means of preventing release.
The designer places the motion drives and the holder supply behind the same disconnection. E-STOP is pressed. The drives switch off. The holder loses its ability to carry the load. The command has been executed flawlessly—including removal of the load support.
This is not a button that failed or a welded contactor. The hardware performed exactly as designed. The error was treating every consumer identically because each happened to use electrical power.
The correct task is to stop hazardous travel while maintaining safe support of the load. The implementation must be selected and verified for the particular design. This does not create a universal rule that a specific circuit must always remain energised. It creates a requirement to preserve effective load retention.
“But after E-STOP there should be no energy.” Gravity was not wired through our contactor. It will not switch off with it.
The fire-extinguishing system can also be switched off perfectly
Consider a machine with a fire-extinguishing system whose controls and extinguishing-agent release mechanism require electrical power. Both are supplied from the circuit disconnected by the emergency stop.
Material ignites. The operator actuates E-STOP. The drives stop, but the burning material remains hazardous. The extinguishing system can no longer act because its supply has just been disconnected.
The extinguishing equipment is fully serviceable. We merely have to ensure that nobody presses the emergency stop before it operates. No design should depend on that condition.
ISO 13850 expressly identifies fire suppression as an example of a protective function that emergency stopping should not impair. This does not mean leaving the whole process unchanged during a fire. It means defining the correct response: which operations must stop, which hazard sources must be isolated, and how fire protection remains effective.
“Switch off everything” resolves none of those questions. It steps around them with one command.
Stop category 0 does not mean “the whole machine without power”
ISO 13850 provides for emergency stops using stop category 0 or 1, selected on the basis of risk assessment.
For stop category 0, power to the machine actuators is removed immediately. This does not guarantee immediate cessation of motion; additional braking may be necessary. For stop category 1, power remains available to the actuators during controlled stopping and is removed once the stop has been achieved.
The stop category describes how stopping is performed. It is not an instruction to de-energise every device shown on the same electrical diagram.
Selecting the category does not remove the need to assess a holder, brake or extinguishing system. Nor does contactor drop-out time prove that hazardous motion stopped correctly or that the stop created no further hazard.
This is not an excuse to leave hazardous actions active under the banner of “maintaining protection”. It is a requirement to separate two tasks: stop what is dangerous and do not disable what must continue protecting people.
They switched off everything—with such thoroughness that they also switched off the protection. Adding “emergency stop compliant with the standard” will not repair that design.
Electrical disconnection is an implementation choice, not a synonym for safety. Gravity, stored pressure, fire and suspended loads do not read the wiring diagram.
5. The operator should not have to guess whether pressing the button will make things worse
“The operator knows what to switch off and in which order.” That may describe preparation for a planned shutdown. As an explanation of emergency stopping, it means that part of the control system’s task has been assigned to human memory.
The person must recognise the danger, recall the dependencies between devices and perform the correct sequence—preferably without error, because the order is said to matter for safety. The whole production cycle has been automated. For safe stopping, the design suddenly places its faith in manual work.
ISO 13850 requires that the decision to actuate an emergency stop device should not require consideration of the resulting effects. A person must recognise the need for intervention. They should not also have to decide whether pressing the button will worsen the situation.
One human action does not mean one machine action
The emergency stop function is initiated by one human action. Once initiated, hazardous movements and operations must stop in the appropriate way without further intervention being necessary for that stopping.
The standard recognises that a predefined sequence may be required. One press can therefore initiate several coordinated actions. It neither demands that everything be disconnected simultaneously nor permits the operator to finish the stopping sequence manually.
If safety depends on a particular order, that order must be established during design. The same applies to which operations stop, what remains effective and which state must be achieved. Merely writing “sequential stop” does not answer those questions.
This does not mean automating every subsequent rescue activity. The requirement for stopping without further intervention concerns hazardous machine operations. Separate means for releasing a person may require deliberate operation in accordance with the designed solution.
Operating a release function is one thing. Needing a second button to stop motion that continues to endanger the person is quite another.
Each supplier stopped its own machine. The feed continued
Consider a line processing long profiles. The processing machine and feeder have separate controls. The emergency stop device beside the processing machine stops the tool but not the feeder, which continues pushing material into the work area.
Assume that continued feed in the scenario being assessed can crush a person. The tool is stationary. The material continues moving.
The supplier’s explanation is: “The feeder has its own emergency stop pushbutton.” It does. But the person has already used the device beside the hazard and has not obtained the required response.
The boundaries between supply packages are perfectly clear. Someone only forgot to require the emergency situation to respect them.
The interaction between the machines must be included in the analysis. If continued feeding maintains the hazard, the stop response must address that feed. Confirming that each machine reacts to its own device does not establish that the line responds safely as a whole.
This does not mean every button must stop an entire factory. It means the span of control is not defined by the edge of a control cabinet or by the company that wrote the software.
“Which emergency stop pushbutton?” must be settled before the emergency
The starting principle in ISO 13850 is that an emergency stop device acts on the entire machine. The standard permits division into spans of control, for example where stopping all interconnected machinery could create additional hazards or cause unnecessary disruption to production.
Such division requires analysis of the machine arrangement, the ability to recognise hazards, process consequences and associated risks. Spans of control may overlap. Initiating an emergency stop in one span must not increase risk in another or prevent emergency stopping there.
Avoiding unnecessary downtime is legitimate. Leaving a hazardous feeder running does not become production optimisation merely because stopping it is inconvenient.
A person must also be able to associate a device with the relevant hazard and recognise its span of control. ISO 13850 identifies location and pictograms as possible means and recommends avoiding arrangements that require instructions to be read or the division to be memorised in advance.
A label such as “S14” may help someone find the button on a diagram. It does not tell the person at the machine which equipment will stop. Electrical documentation can be studied at a desk. During an emergency, that part of the design should already be finished.
Defining spans of control requires an analysis of the machine layout, tasks and interacting hazards. The simpler the human action is intended to be, the more precisely the machine response must be determined beforehand.
A simple interface does not remove the need for analysis. It should be the result of analysis. An emergency is no time to convene a meeting between the mechanical designer, controls engineer and process technologist. Their agreement belongs in the design.
The emergency stop pushbutton is allowed to be simple because the difficult decisions should already have been made by the designers.
6. “E-STOP works” is not an assessment of protection
“All buttons tested. Result: pass.” The report contains device references, dates and signatures. Every press stopped the machine. What is missing is any definition of the correct response beyond the observation that nothing was moving.
The device was tested against its reference on the diagram. The function still needed requirements.
Define the criterion before declaring a pass
Before testing, establish the result that must be achieved. Which operations must stop, within what time, across which span and under what conditions? What must remain effective? What behaviour constitutes failure?
Without those criteria, it is easy to accept whatever happens to be observed. The drive stopped after several seconds? Presumably that was the intended stopping time. The adjacent section kept running? Presumably it was outside the span. If the documentation decided nothing, the result has nothing to contradict.
When acceptance criteria are written after the test, designing a machine that always passes is easy: require no more than the machine just did.
In practice, the information can be organised as follows:
| Area | What must be established? | What should be recorded or referenced? |
|---|---|---|
| Emergency situation | Which existing or imminent situation requires intervention? Who can initiate it? | The scenario, human tasks, machine state and location of an accessible emergency stop device. |
| Required protective outcome | What must change when the function is initiated? Which hazardous effect must be interrupted or limited? | The required state and conditions for reaching it, including additional protective actions and means for releasing trapped persons where needed. |
| Machine response | What stops, in what sequence, within what time and across which span? | The function specification, stop category, sequence, time limits and interfaces with other equipment. |
| Protection that remains active | What must continue operating? Could the response create another hazard or worsen conditions in another span? | Requirements for retained functions, justification of the solution and results from checking their interaction. |
| Verification and validation evidence | What demonstrates that the implementation meets the defined requirements? | Analysis, test and measurement results; test conditions; configuration identification; and resolution of discrepancies. |
This table is a practical way to organise a review. It is not a form taken from ISO 13850 and is not a complete validation plan. The analysis and tests must be selected for the particular function, machine and assessment method.
PL and SIL cannot complete a missing function specification
ISO 13850 requires the safety-related parts of the control system implementing emergency stopping to meet the applicable requirements of ISO 13849-1 and/or IEC 62061. It also states a minimum of PLr c or SIL 1.
A minimum does not mean that the same level is automatically sufficient for every application. The required level must be established for the function, taking account of its purpose and applicable detailed requirements.
Copying PL e from a relay data sheet is not enough. The implementation of the complete function must be assessed, not merely one component. Nor does a correct calculation for the full control system replace validation.
ISO 13849-1:2023 distinguishes verification of the achieved PL from validation through analysis and testing. It also requires the safety requirements specification itself to be checked for consistency and completeness against the intended use.
That point matters. The standard does not ask us merely to confirm that a programmer implemented a badly defined requirement faithfully. It also requires us to determine whether the right requirement was specified.
The result must apply to the machine as built
Verification does not end when movement ceases. The emergency stop function must be available and effective in all relevant operating modes, maintain the stopped condition and prevent a normal start command from restarting the stopped operations. Releasing the emergency stop device must not itself restart the machine.
Those conditions also require suitable checks. Each conclusion should be linked to evidence confirming operation of the function: a test-report entry, measurement, analysis, and the relevant versions of the circuit diagram and software.
An attachment called “safety test” is not useful evidence if nobody can tell what was tested or which criterion determined the result.
Tests must be planned without exposing people to danger. Nobody recreates an entanglement with a human subject to test a release concept. Safe test methods, analysis and simulation are selected to suit the solution under review.
Failure to perform a check is not a pass, even if the form provides only one box to tick.
After the emergency response is confirmed, preventive protection remains a separate question. A properly implemented E-STOP does not satisfy the requirement that should have been met by a missing guard or a differently designed access arrangement.
If the report never asks what happened to the hazard, its positive result should not provide much comfort.
A test result is meaningful only when the required protective outcome was defined before the test—not reverse-engineered from whatever the machine happened to do.
7. Safeguarding is not a promise that there will be something to press
A preventive safety function is intended to prevent a specified hazardous event. An emergency stop function enables an appropriate intervention when an emergency situation already exists or is imminent. Both require design and verification. One does not perform the other’s task merely because both may stop a drive.
A machine design does not become complete when an emergency stop pushbutton is added while protection against a foreseeable event remains missing. Operator training, a high PL and a successful test limited to cessation of motion cannot supply that protection.
The emergency intervention itself also requires more than deciding which outputs to turn off. The design must define suitable stopping, preserve necessary protection and provide any additional actions needed to control the situation. That is engineering work. The person beside the machine should not have to finish it while facing a hazard.
This is not about diminishing E-STOP. It is about refusing to credit it with protection it cannot provide—and refusing to strip it of actions that effective intervention may require.
The emergency stop function should help bring an emergency situation under control. It should not excuse the failure to prevent that situation where prevention is required.
If the final conclusion from the entire assessment is only “the machine stopped”, then stopping has been checked. The safety of the person may still need some work.
The machine stopped. Good. Now answer the harder question: what happened to the hazard and to the person exposed to it?
Sources and notes
The primary standard used for this analysis is ISO 13850:2015. The references below identify the specific provisions applied. Links to standards lead to the publisher’s English-language catalogue pages, not unauthorised copies of the full documents.
[1] Purpose and complementary role of the function. ISO 13850:2015, clauses 3.1, 3.5, 3.8 and 4.1.1.1–4.1.1.3 cover the purpose of emergency stopping, human initiation, safety functions, emergency situations and the prohibition on replacing other protection. The distinction made here concerns preventive tasks and emergency intervention; it does not imply that emergency stopping is not safety-related.
[2] Light curtains and stopping before hazardous contact. ISO 12100:2010, clauses 6.3.2.5.1–6.3.2.5.2, addresses conditions for using sensitive protective equipment, the ability to stop, positioning of the detection zone and links to the control system. It refers to ISO 13855 for positioning. The example in this article is not a separation-distance calculation or a complete light-curtain selection.
[3] Human intervention and the limits of instructions. ISO 12100:2010, clauses 5.5.2.3.3 and 6.1, addresses factors affecting the possibility of avoiding or limiting harm and the prohibition on using information for use as a substitute for appropriate protective measures. ISO/TR 14121-2:2012, clause 8.4, identifies emergency stopping as an example of a measure acting primarily on the possibility of avoiding or limiting harm. This guidance does not justify automatically reducing a value in a risk graph. Accessibility of devices is addressed in ISO 13850:2015, clauses 4.3.1–4.3.2.
[4] Additional protective actions and release. ISO 13850:2015, its scope and clauses 4.1.1.2 and 4.1.1.5, cover preservation of other protective functions and the possibility of initiating actions in addition to stopping. Detailed requirements for those actions are outside its scope. ISO 12100:2010, clauses 6.3.5.2–6.3.5.3, distinguishes emergency stopping from measures for the escape and rescue of trapped persons.
[5] Preserving protection and selecting stop categories. ISO 13850:2015, clauses 4.1.1.2, 4.1.1.4–4.1.1.5 and 4.1.3, refers to release of persons, fire suppression and the possible need to maintain devices such as electromagnetic holders or brakes. Stop categories 0 and 1 do not imply isolation of all equipment from every energy source.
[6] One human action, sequencing and spans of control. ISO 13850:2015, clauses 4.1.1.1, 4.1.1.5–4.1.1.6 and 4.1.2–4.1.2.1, covers the required response without further intervention for stopping, predefined sequences, consequences of actuation and conditions for dividing spans of control. Analysis of interfaces between suppliers is a practical application of those requirements.
[7] PL, SIL, maintaining the stop and reset. ISO 13850:2015, clause 4.1.5.1, refers to ISO 13849-1 and/or IEC 62061, the minimum PLr c or SIL 1 and permissible sharing of elements. Clauses 4.1.1.2 and 4.1.4 address availability, maintaining the stop and reset without restart. Applicable type-C standards and other detailed requirements must also be considered for the specific machine.
[8] Function requirements and validation. ISO 13849-1:2023, Clause 8 and clauses 10.1.1, 10.2 and 10.4.1, address verification of achieved PL, validation by analysis and testing, checks on the completeness and consistency of the specification, and prior definition of test plans and expected results. The table in this article is an author’s organisational proposal, not a complete validation plan prescribed for every system.
[9] EU legal context. Directive 2006/42/EC — English text in EUR-Lex, Annex I, sections 1.2.4.3–1.2.4.4, and Regulation (EU) 2023/1230 — English text in EUR-Lex, Annex III, sections 1.2.4.3–1.2.4.4, address the complementary role of emergency stopping, avoidance of additional risk, safeguarding movements and stopping related equipment whose continued operation may be dangerous. Regulation (EU) 2023/1230 applies generally from 20 January 2027, subject to the transitional provisions and dates in Articles 52 and 54. Citing a standard here is not a statement about its harmonised status under a particular legal act.
Nature and limits of the examples. The workstations, power arrangements, documentation entries and quoted objections are illustrative. They do not describe a verified accident and are not rescue instructions for a specific machine. Opening mechanisms, releasing pressure and reversing motion require appropriate engineering and assessment of their consequences. This article addresses the role and logic of the function, not every requirement or exception in ISO 13850.