
A fail-safe relay circuit starts with a defined safe state-not a relay wiring diagram.
Define the hazard, the required safe state and the faults the circuit must withstand. Then select and validate the complete input–logic–output chain, including fault detection, final switching devices and restart prevention. An energized-to-run relay can respond to loss of power or an open wire, but it does not by itself protect against welded contacts, bypass shorts or unexpected restart.
For an OEM or panel builder, the practical question is: will the machine reach and maintain its required safe state when a credible fault occurs? A relay that drops out during a bench test answers only a small part of that question. The actuator may still coast, a contactor may remain welded, or restored power may start the machine again.
This guide explains a machinery-control design process and a conceptual safety architecture. It is not a terminal-by-terminal wiring plan or a declaration of compliance. Personnel-protection circuits require a competent machinery-safety assessment, the exact manufacturers' instructions, applicable standards and validation of the installed system. Process-safety applications may require a different standards framework.
What Must the Machine Do to Reach a Safe State?
Describe the hazard before choosing normally open or normally closed contacts. "All power off" is not a universal safe state. Removing motor torque can leave a suspended load unsupported; switching off a heater may still leave hazardous heat; stopping a pump may trap pressure. Some applications need a controlled stop followed by energy removal, while others need a brake, monitored valve or continued cooling.
| Application | Why relay OFF may be insufficient | Define before selecting hardware |
|---|---|---|
| Conveyor or rotating machine | Motion continues after torque is removed. | Permitted stopping time and prevention of access before motion is safe. |
| Vertical axis or suspended load | Gravity can create motion after power loss. | Required load-holding arrangement and its monitoring. |
| Heated process | Stored heat remains; cooling or purge may still be needed. | Which energy sources stop and which protective services continue. |
| Pneumatic or fluid system | Pressure, trapped energy or valve failure may sustain a hazard. | Safe actuator position and whether pressure must be retained, isolated or exhausted. |
Write each safety function as a testable statement. For example: opening this guard must stop the identified hazardous motion before a person can reach it, maintain the stopped state while access is possible, and prevent an unintended restart after the guard closes. The design must then establish the actual time limit, access conditions and restart requirements.
Include production, setup, cleaning, jam recovery and maintenance-not just normal running. Identify electrical, mechanical, pneumatic, hydraulic and thermal energy. An emergency stop is a complementary measure, not a substitute for guarding. ISO 13850 addresses the emergency-stop function; IEC 60204-1 addresses electrical equipment of machines. Apply the editions and machine-specific requirements relevant to the project.
When Is an Ordinary Control Relay Not Enough?
First distinguish an operating function from a safety function. A relay that starts a ventilation fan for routine temperature control has a different role from a circuit credited with preventing injury. If failure of the control function can leave an unacceptable risk, define the required safety performance before selecting parts.
| Design question | Ordinary operating control | Safety-related control |
|---|---|---|
| Primary purpose | Run the intended process. | Provide a specified part of the required risk reduction. |
| Selection basis | Load rating, life, environment and operating logic. | Those requirements plus safety architecture, reliability, diagnostics and fault response. |
| Acceptance evidence | Functional and electrical performance tests. | Documented safety requirements, analysis and validation of the complete function. |
For an ISO 13849 approach, determine the required Performance Level, PLr, for each safety function. ISO 13849-1:2023 provides a design methodology; it does not assign one universal PLr to every machine. The risk assessment and applicable machine requirements establish the target.
A suitable safety relay or safety controller can provide documented monitoring and diagnostic behavior. However, its advertised maximum PL or SIL is not automatically the rating of your machine. The input device, wiring, output devices and implementation conditions still matter. Conversely, the assessment-not the color of a housing-determines what architecture is required.
Why Does De-Energize-to-Stop Not Cover Every Fault?
In an energized-to-run arrangement, a maintained control signal keeps the relay coil energized. Removing that signal lets the relay return to its de-energized state. An open stop circuit, a broken wire or loss of the control supply can therefore remove the run permission.
That is useful behavior, but it covers only certain failure modes. A short across the stop contact may preserve the coil circuit. A welded output contact may keep the load energized after the coil releases. A standard PLC output stuck ON may defeat a stop implemented only in ordinary software.
Ask two separate questions
1. Does the circuit command a stop when the safety demand occurs?
2. If a component or wire fails, does the architecture still achieve the required response, detect the fault when required, and prevent an unsafe restart?
A normally closed input is not inherently a complete fail-safe solution, and a latching relay may retain its contact state when coil power disappears. Select the operating principle for the required fault response; do not infer safety from the NO/NC designation or coil voltage alone.
How Should the Input, Logic and Final Devices Work Together?
Treat the function as an end-to-end chain. The input detects the demand, the logic evaluates it, and the final devices act on the hazardous energy. Diagnostics must cover the relevant faults along that chain-not merely show that the safety relay has power.
Conceptual architecture-not a wiring schematic
Safety input device → suitable safety logic → final switching or stopping devices → required machine state
Final-device feedback → safety logic, to check the required device state
Reset and separate start conditions → controlled re-enabling of operation
For a guard-controlled motor, one assessed architecture might use a suitable dual-channel guard input, a safety relay, and two independently controlled contactors whose main contacts are arranged so either can interrupt the hazardous supply. Each contactor has appropriate feedback. This is a design concept, not a universal prescription: drives, brakes, stop categories and the required performance can require a different solution.
Follow the exact input-device and safety-logic manuals for contact inputs, OSSD electronic outputs, test pulses, channel timing and cross-short detection. Connecting two wires does not establish two effective safety channels. A general-purpose proximity sensor does not become safety-rated simply because its output is connected to a safety relay.
Keep ordinary PLC sequencing subordinate to the safety function. A standard PLC can display diagnostic information or request operation, but its command must not bypass the required safety response. Evaluate shared supplies, terminals, cable routes and environmental exposure: one damaged cable or wiring error may affect both nominally redundant channels.
How Can the Circuit Detect a Welded Contactor?
Removing voltage from a contactor coil does not prove that its main contacts opened. External device monitoring, usually called EDM, uses suitable feedback to check whether final devices reached the state expected by the safety logic. Depending on the product, this check may occur during operation, before re-enabling, or through a specified monitoring sequence.
For a power contactor, use a manufacturer-declared mirror NC contact with the required relationship to the main NO power contacts. Do not substitute an arbitrary NC auxiliary contact. Schneider Electric explains that the mirror-contact function prevents the specified NC auxiliary contact from closing while a main power contact remains closed. Confirm the exact contactor and auxiliary-block combination.
Forcibly guided relay contacts are related but not interchangeable terminology. IEC 61810-3 covers elementary relays with forcibly guided contacts; contactor mirror-contact requirements are associated with IEC 60947-4-1. Neither feature makes welding impossible. They support a specified, monitorable relationship between contacts.
In an appropriately designed redundant output stage, if one contactor fails closed, the other must still achieve the required stop. The failed device's feedback must then prevent prohibited re-enabling. EDM detects a problem; it does not physically break a welded contact. Feedback bypasses, unsuitable auxiliary contacts or an unmonitored common path can invalidate this strategy.
How Do You Prevent Restart After Reset or Power Recovery?
Treat three events separately: restoring the safety input, resetting the safety function, and starting the machine. Closing a guard or releasing an emergency-stop actuator must not be treated as an unrestricted instruction to move. For the guarded-machine concept in this guide, reset restores readiness; a separate, deliberate start action initiates operation when all required conditions are satisfied.
Choose the reset mode by its documented behavior, not by the word "manual" alone. A monitored reset normally checks a defined signal transition or sequence. A maintained or welded reset signal must not defeat the intended restart protection. Rockwell's Guardmaster user manual, for example, distinguishes monitored manual reset from automatic/manual reset; its monitored mode uses a specified ON–OFF sequence. Other products have their own timing and conditions.
Locate reset controls so the operator can assess the relevant hazard zone and cannot reset from a hazardous position. Where a person can enter completely and become hidden, a reset button outside the guard is not a complete presence-detection strategy. Additional protective measures must address someone remaining inside.
Test the whole recovery sequence after a supply interruption, brownout, PLC reboot and drive restart. Include a held start command and a held reset signal. Automatic re-enabling is acceptable only where the assessed application permits it and unintended hazardous operation remains prevented. Never use automatic reset simply to eliminate nuisance stoppages.
Which Faults Must the Design Review Address?
Build the fault review around the actual circuit and required performance. The examples below identify questions to resolve; they do not mean every architecture detects every listed fault. Document the detection method, response time, restart behavior and any justified exclusions.
| Fault or event | Potential loss of protection | Design question |
|---|---|---|
| Control supply fails | Torque removal alone may not hold the load. | Does the complete machine reach its defined safe state? |
| Input wire opens | A demand may be lost in an unsuitable input arrangement. | Does the configured input respond as specified? |
| Input shorts to supply or across a contact | The logic may see a permanent healthy signal. | What diagnostics or justified wiring measures cover the fault? |
| Channels short together | Two channels may behave as one. | Is cross-fault detection supported and correctly configured? |
| Safety output or final contactor remains ON | The hazardous energy path may remain enabled. | Can the remaining architecture stop the hazard and identify the failure? |
| Reset or ordinary PLC output sticks ON | An unsafe re-enable or persistent run request is possible. | Does safety logic retain authority over the output stage? |
| Coil suppression changes | The contactor or relay may release later. | Has the installed combination's stopping time been checked? |
| A common environmental or wiring fault occurs | Both channels may fail together. | Are segregation, protection, EMC and environmental measures adequate? |
Fault testing must be planned and performed by qualified personnel using controlled, manufacturer-permitted methods. Do not create live shorts or deliberately weld contacts on an operating machine to "prove" a safety function. Use suitable simulation, analysis and test arrangements with hazardous energy controlled.
Which Relay and Contactor Specifications Need Verification?
Start with the exact order code, hardware revision, applicable firmware and safety manual. Similar-looking devices can differ in reset behavior, input compatibility, output type or approved architecture. A component certificate does not authorize every wiring arrangement.
- Input and logic compatibility: sensor type, test-pulse behavior, discrepancy timing, fault response, reset mode and EDM requirements.
- Output duty: AC or DC voltage, utilization category, coil pickup demand, holding current, switching frequency and minimum reliable load.
- Final-device evidence: switching capacity for the actual load, declared feedback-contact properties, reliability data and replacement interval.
- Installation conditions: supply tolerance, ambient temperature, enclosure conditions, wiring limits, EMC and specified short-circuit protection.
- Response behavior: maximum response times for the selected configuration, including expansion modules, delay settings and suppression accessories.
Do not use a resistive-current rating to approve an inductive contactor-coil load. Check make and break duty, protection coordination and electrical endurance. For ordinary panel-interface selection, QIANJI's industrial control panel relay guide covers complementary selection issues; those checks do not replace safety validation.
Suppression deserves explicit attention. A simple flyback diode can slow the collapse of a DC coil's magnetic field and delay release. TE Connectivity's coil-suppression guidance explains this trade-off. Use the approved suppressor and verify the installed behavior; do not remove suppression or change the clamp voltage without checking the driving output's limits.
How Do You Check Safety Performance and Total Stopping Time?
Safety performance and stopping time answer different questions. A function must be sufficiently reliable and act quickly enough for the hazard. A high-performance safety relay cannot compensate for a machine that takes too long to stop.
Evaluate the complete safety function
For a PL assessment, include the input, logic and output subsystems. Review architecture, component reliability, diagnostic coverage, common-cause failures, use conditions and systematic measures. Two ordinary relays do not automatically establish Category 3 or Category 4, and redundancy alone does not establish PL e.
Where suitable, IFA's SISTEMA tool supports modeling and reliability calculations. Use a version matched to the selected standard revision and verify library entries against the installed parts. Switching frequency, mission time and replacement assumptions must reflect the application. A calculation report is supporting evidence, not proof that the wiring, software or machine behavior is correct.
Account for every delay without counting it twice
A response-time budget may include input-device detection, safety-logic processing, output-device release and mechanical rundown. Add communication, drive, brake or valve delays where they are part of the selected architecture. Use specified worst-case values and verify the actual machine under the relevant operating conditions.
Illustrative timing budget-not a design limit
20 ms input + 15 ms logic + 35 ms final-device release + 250 ms mechanical rundown = 320 ms total.
These are invented teaching values, not product specifications. The stages are assumed to be sequential and non-overlapping. If a measured stop time already begins at the safety-input trigger, do not add the delays included in that measurement again.
Measure the worst relevant speed, load, temperature and wear conditions. Apply the appropriate safeguard-positioning method with all required allowances; do not infer a universal safe distance from this example. If hazardous motion lasts longer than access time, additional measures such as suitable guard locking may be necessary.
What Must Be Validated Before the Machine Is Released?
Validate against written acceptance criteria for each safety function. Normal-operation testing is necessary but insufficient: include the fault responses and restart sequences claimed by the design. Retain evidence linking the requirements, circuit revision, installed components, configuration and results.
| Validation area | Confirm | Record |
|---|---|---|
| Safety demand | Every relevant input achieves the specified safe state in each applicable mode. | Test conditions, expected response and observed result. |
| Fault response | Assessed input, output and feedback faults produce the required response. | Controlled test method, diagnostic indication and re-enable behavior. |
| Reset and recovery | Guard closure, held commands and power restoration do not cause prohibited restart. | Complete sequence, including PLC and drive recovery. |
| Stopping performance | Worst-case behavior meets the specified limit. | Measurement start/end points, load, speed and conditions. |
| Installation and lifecycle | Wiring, protection, environment and maintenance match the design assumptions. | As-built drawings, settings, parts, inspection and replacement requirements. |
Reassess changes that affect the safety function: a replacement contactor, different coil suppressor, modified guard, increased machine speed or altered restart program can invalidate earlier assumptions. Keep substitutions under change control rather than accepting "same coil voltage and contact current" as equivalence.
A safety stop is not energy isolation. For servicing subject to US OSHA requirements, 29 CFR 1910.147 distinguishes energy-isolating devices from control-circuit devices. Applicable lockout/tagout procedures must address isolation, stored energy and verification. Use the corresponding requirements for the installation's jurisdiction; an emergency-stop button or de-energized relay is not a substitute.
Specify the relay's role before requesting a quotation
For a QIANJI relay enquiry, provide the circuit role, coil supply, actual switched load, inrush, switching frequency, ambient conditions, mounting method and required documentation. State explicitly whether the part is used for ordinary control or within a safety-related function.
For a safety-related role, request exact-model evidence and have the responsible safety designer confirm suitability. Do not assume a general-purpose relay, socket or product-family certificate establishes the required safety performance.
