NEN-Hub
🔍
IEC 61508 (proof test)

Safety relays and safety PLCs — periodic proof testing per IEC 61508

Available in: en, nl, pl, ru, ua
Updated: ≈ 4 min read

Safety relays and safety PLCs — periodic proof testing per IEC 61508

The guide on functional safety — SIL versus PL covers how a safety function is classified at the design stage. This article covers what must then happen periodically, during the operational phase, to keep that classification actually valid: the proof test that IEC 61508 mandates for every safety relay and every safety PLC included in a safety function.

Why automatic diagnostics don't catch everything

A modern safety relay or safety PLC continuously runs internal diagnostics — this is the diagnostic coverage (DC): the percentage of dangerous failure modes the system itself detects automatically, without manual intervention. No system, however, reaches 100% diagnostic coverage. There is always a residual category of dangerous, undetected failures — a contact welded shut whose status is not read back, a relay that has become mechanically sluggish without this being electrically detectable. These residual failures remain invisible until the safety function is actually called upon, and it is precisely at that moment — an emergency stop, a light curtain being interrupted — that the failure is no longer acceptable.

What a proof test adds

The proof test is a periodic, typically manual or semi-automatic test specifically designed to catch those remaining failure modes missed by the diagnostics — for example by actually operating the emergency-stop chain and verifying that the driven power contactors actually drop out within the specified time, rather than only checking the status signal reported by the safety PLC.

Note: IEC 61508 explicitly distinguishes the proof test from automatic online diagnostics. A system with a high diagnostic coverage (say, 99%) still needs a proof test for the remaining 1% — diagnostic coverage does not reduce the need for a proof test to zero, but in practice it does extend the permissible proof test interval.

Proof test interval and PFDavg

The proof test interval is directly linked to the PFDavg (average probability of dangerous failure on demand) needed to substantiate the required SIL: a longer interval between proof tests lets dangerous, undetected failures persist unnoticed for longer, which raises the PFDavg and can undermine the effective SIL — even if the system formally met the required SIL at commissioning. The proof test interval is therefore not a free maintenance choice, but a parameter that was factored into the original SIL calculation of the safety function.

Proof test coverage: also not always 100%

Besides the interval, the proof test coverage matters too: the percentage of dangerous failure modes the proof test itself actually detects. A proof test that only checks a relay's status indication without exercising the actual switching function has a lower coverage than a test that functionally exercises the entire chain — from sensor to driven power contact. A proof test with a coverage lower than what was assumed when the safety function was designed undermines the substantiated PFDavg in the same way as an overly long interval.

Practical relevance

When drafting a maintenance plan for a machine with a safety PLC or safety relay, it is essential to follow exactly the proof test interval and the associated test procedure specified by the manufacturer or system integrator, rather than relying on automatic self-diagnostics alone — even a system with high diagnostic coverage still depends on a timely, functionally complete proof test to deliver the substantiated SIL in practice.

Common mistakes

  1. Skipping the proof test because the safety system has a high automatic diagnostic coverage, when it is precisely the remaining, undetected failure modes that make the proof test necessary.
  2. Running a proof test that only checks the status indication, without functionally exercising the actual power switching, which lowers the effective test coverage.
  3. Extending the proof test interval without recalculating the PFDavg, so the substantiated SIL is no longer actually achieved despite an apparently unchanged configuration.
  4. Not keeping a traceable log of proof tests performed, which means that after an incident it cannot be demonstrated that the safety function was tested at the substantiated interval.

Further reading

Related terms
Safety relays and safety PLCs — periodic proof testing per IEC 61508 · NEN-Hub