Book a Discovery Call

Do the Common-Cause Checklist Before the Cables Are Routed

ISO 13849-1 uses eight scored measures in six groups and a 65-point threshold. Most of the points describe design choices that are expensive to revisit later.

An engineer monitoring an instrumented test rig, measurement cables and sensors attached to a metal fixture

The ISO 13849-1 common-cause worksheet often appears when the Performance Level report is almost finished. By then, both channels may share a cable tray, a cabinet, a power supply, and the same environmental exposure.

That is a bad time to discover the design has not earned 65 points.

What Annex F actually scores

The checklist has eight scored measures arranged in six groups, not twenty questions. It covers physical separation; diversity; protection against overvoltage and overpressure; well-tried safety principles; competence and common-cause analysis; electromagnetic compatibility; and environmental protection against conditions such as temperature, shock, vibration, humidity, dust, or corrosive contamination.

Several rows describe hardware decisions. Separation can mean different routes or physical barriers. Diversity may change the sensing principle or component selection. Electromagnetic and environmental protection can alter cabinet layout, grounding, shielding, or enclosure design.

Training and analysis can be improved late. Moving conduit after installation is another matter.

The simplified method needs at least 65 points. Below that threshold, the simplified treatment is unavailable. It does not prove the physical architecture has no value, but a team needs another justified way to quantify the common-cause contribution.

Category 2 is not a redundant safety function

Common-cause assessment applies to Categories 2, 3, and 4, but the architectures are not identical.

Category 2 uses a functional channel and a separate test channel. A shared cause can defeat the function and the mechanism intended to detect its failure. Categories 3 and 4 rely on redundant functional channels, so a shared event can defeat the independence behind their probability calculation.

The same practical question sits underneath all three: can one condition disable more than one part of the architecture the claim relies on?

A voltage transient on a shared supply is an obvious example. Two cable runs in the same conduit are less obvious until the conduit is damaged. Identical sensors exposed to the same contaminant may fail together even if their random failure rates look excellent on separate data sheets.

Where beta fits

The beta factor represents the common-cause portion of failures in a multi-channel subsystem. IEC 61508 and IEC 62061 use more graduated treatments than the pass threshold in ISO 13849-1. IEC 61508 distinguishes logic solvers from sensors or actuators and maps the assessment into discrete bands.

The exact method matters, but the design lesson is the same. Better independence has to exist in the machine before it can improve a calculation.

We would score the checklist beside the first architecture sketch and return to it when routing, enclosure, or component choices change. At that point a missing measure becomes a design input. At the end it becomes a negotiation with the schedule.

ASAP keeps the common-cause assessment with the architecture and reliability model it supports. If a component or layout changes, the team can review the affected measure instead of discovering the mismatch while assembling the report.

The methodology was developed over five years inside Amazon Robotics and supports a large autonomous mobile robot fleet in continuous operation.

If the CCF score appears for the first time in the final PL report, Fennec can help move it back into architecture.

Frequently asked questions

How is common cause failure scored in ISO 13849-1?

Annex F scores eight measures in six groups. At least 65 points out of 100 are needed to use the standard's simplified treatment.

Which categories need the assessment?

Categories 2, 3, and 4. Category 2 has a functional channel plus a test channel; Categories 3 and 4 use redundant functional channels.

What is the beta factor?

It represents the proportion of failures attributed to a common cause rather than independent random events in a multi-channel subsystem.

How does IEC 61508 differ?

IEC 61508 uses a scored method that can produce discrete beta bands and distinguishes treatment for logic solvers and for sensors or actuators.

When should common cause be assessed?

During architecture, while separation, diversity, environmental protection, and component choices can still change.

Share this article

Two engineers reviewing technical drawings and test data at a workbench

GET IN TOUCH

Certification is the start, not the finish line

Intelligent machines change with every release. Their safety evidence has to keep up. See what a connected safety lifecycle looks like for your program.

Ready to get started?

We use optional analytics to measure site use and performance. They run only if you accept. Privacy Policy