Control systems shall be designed and constructed in such a way as to prevent hazardous situations from arising.
Control systems shall be designed and constructed in such a way that:
- a)they can withstand, where appropriate to the circumstances and the risks, the intended operating stresses and intended and unintended external influences, including reasonably foreseeable malicious attempts from third parties leading to a hazardous situation;
- b)a fault in the hardware or the logic of the control system shall not lead to hazardous situations;
- c)errors in the control system logic shall not lead to hazardous situations;
- d)the limits of the safety functions are to be established as part of the risk assessment performed by the manufacturer and no modifications are allowed to the settings or rules generated by the machinery or related product or by operators, including during the machinery or related product learning phase, where such modifications could lead to hazardous situations;
- e)reasonably foreseeable human errors during operation shall not lead to hazardous situations;
- f)the tracing log of the data generated in relation to an intervention and of the versions of safety software uploaded after the machinery or related product has been placed on the market or put into service is enabled for five years after such upload, exclusively to demonstrate the conformity of the machinery or related product with this Annex further to a reasoned request from a competent national authority.
Control systems of machinery or related products with fully or partially self-evolving behaviour or logic that are designed to operate with varying levels of autonomy shall be designed and constructed in such a way that:
- a)they shall not cause the machinery or related product to perform actions beyond its defined task and movement space;
- b)recording of data on the safety related decision-making process for software based safety systems ensuring safety function including safety components, after the machinery or related product has been placed on the market or put into service, is enabled and that such data is retained for one year after its collection, exclusively to demonstrate the conformity of the machinery or related product with this Annex further to a reasoned request from a competent national authority;
- c)it shall be possible at all times to correct the machinery or related product in order to maintain its inherent safety.
Particular attention shall be given to the following points:
- a)the machinery or related product shall not start unexpectedly;
- b)the parameters of the machinery or related product shall not change in an uncontrolled way, where such change could lead to hazardous situations;
- c)modifications to the settings or rules, generated by the machinery or related product or by operators, including during the machinery or related product learning phase, shall be prevented, where such modifications could lead to hazardous situations;
- d)the machinery or related product shall not be prevented from stopping if the stop command has already been given;
- e)no moving part of the machinery or related product or piece held by the machinery or related product shall fall or be ejected;
- f)automatic or manual stopping of the moving parts, whatever they may be, shall be unimpeded;
- g)the protective devices shall remain fully effective or give a stop command;
- h)the safety-related parts of the control system shall apply in a coherent way to the whole of an assembly of machinery or related products or partly completed machinery, or a combination thereof.
For wireless control, a failure of the communication or connection or a faulty connection shall not lead to a hazardous situation.