A redundant pneumatic valve system is an output subsystem designed to preserve a defined safety response after a single fault. It does not automatically make a machine PL d or PL e. The risk assessment, input devices, safety logic, valve architecture, diagnostics, pneumatic circuit, and physical machine response all contribute to the achieved Performance Level.
This article focuses on the valve output subsystem: how two valve elements are arranged, what their feedback must prove, how faults affect supply and exhaust paths, and what must be tested on the installed machine. For the complete input-logic-output workflow, start with the broader guide to ISO 13849 pneumatic safety circuits.
Key Takeaways
- ISO 13849-1 defines five Performance Levels, but redundancy alone establishes none of them.
- A 3/2 double valve can support safe exhaust; a monitored 5/2 design can support a defined safe return.
- Feedback must detect dangerous valve faults, not merely confirm coil voltage.
- Validate pressure, motion, reset, and restart behavior on the installed machine.
What Does a Redundant Valve System Actually Protect?
ISO 13849-1:2023 defines five Performance Levels from PL a through PL e, yet it does not assign a safety function or required PLr to a particular pneumatic application (ISO, 2023). A redundant valve system protects only the machine safety function that the designer has explicitly defined.
That function might prevent unexpected pressurization when a guard is open. It might exhaust one hazardous zone, move an actuator to a controlled return position, retain pressure long enough for a brake to engage, or select a reduced setup pressure. Each function needs a trigger, a safe state, a PLr, an architecture, diagnostic behavior, and measurable acceptance criteria.
The word “redundant” describes structure, not the result. Two valve elements may provide two output paths, but the system still fails if one contaminated air supply jams both elements, a shared connector disables both coils, a blocked silencer prevents exhaust, or the controller ignores a feedback discrepancy.
Begin with four questions:
- Which hazardous motion or pressure must the function control?
- What physical state is safe for the worst credible load and actuator position?
- Which single faults must the valve subsystem tolerate or detect?
- What evidence will prove that the installed machine reaches and maintains that state?
In our experience reviewing pneumatic safety specifications, the most common wording problem is a component label presented as the safety function. Replace “use a redundant valve” with a measurable requirement such as “prevent pressure above the defined threshold at the extend port after any credited single output fault.”
ISO 4414:2010, confirmed current in 2021, addresses significant pneumatic-system hazards across design, installation, operation, and maintenance. It reinforces a central rule: the valve cannot be evaluated apart from stored pressure, gravity, springs, vacuum, piping, actuators, and the service procedure.
A second valve element is useful only when the pneumatic paths, diagnostics, and fault reaction remain independent enough to preserve the defined safety function.
Three Redundant Valve Architectures
Parker’s P33 family uses a 3/2 normally closed safety-exhaust function and offers internally or externally monitored versions, while ROSS documents redundant 3/2 and 5/2 double-valve arrangements (Parker, 2024; ROSS, accessed 2026). These examples show three practical architecture families for modern machine safety circuits.
Internally monitored double valve
Two valve elements and the monitoring logic are integrated into one assembly. The product checks element synchronization or state internally and prevents normal operation after a defined discrepancy. The system designer must still follow the reset, wiring, plumbing, minimum cycling, silencer, and fault-response conditions in the safety manual.
Externally monitored double valve
Each valve element provides position or pressure-state feedback to a safety relay or safety PLC. The external logic compares the commanded state with both feedback channels during energization and de-energization. ROSS, for example, specifies external monitoring of two PNP spool-position sensors for its RSe series. That product-specific arrangement must not be generalized to a valve with different sensors or internal geometry.
Two discrete valve channels
Separate valves can be designed as a redundant output subsystem when their pneumatic interconnection, electrical control, diagnostics, reliability data, and common-cause measures satisfy the required architecture. Simply installing two ordinary directional valves in series or parallel does not prove fault tolerance. The circuit must show what happens if either element sticks, leaks, shifts slowly, or loses its command.
| Architecture | Monitoring location | Main engineering question |
|---|---|---|
| integrated double valve | inside the certified assembly | Which external conditions and reset logic must be provided? |
| externally monitored double valve | safety relay or safety PLC | Does the logic evaluate both real valve positions on every required transition? |
| two discrete channels | machine safety control system | Does the complete pneumatic arrangement preserve the safe state after either single fault? |
How Do Category 3 and Category 4 Change Fault Behavior?
IFA’s ISO 13849 application report distinguishes Category 3 from Category 4 through MTTFd, DCavg, and resistance to accumulated faults, not through the visual presence of two channels alone (IFA Report 2/2017e, 2019). Both designated architectures require appropriate measures against common-cause failures in pneumatic safety systems.
In Category 3, a single fault must not cause loss of the safety function. Some faults are detected, but an accumulation of undetected dangerous faults may eventually defeat the function. That means a schematic with two channels can still be inadequate if diagnostics miss a dangerous stuck valve or if both channels share an unaddressed cause of failure.
Category 4 also requires single-fault tolerance, with stronger fault detection or resistance to fault accumulation. IFA describes high MTTFd and high DCavg for the designated Category 4 architecture. This is why a product claiming Category 4 capability normally has explicit monitoring conditions, reliability data, and fault-reaction requirements.
| Design question | Category 3 orientation | Category 4 orientation |
|---|---|---|
| effect of one fault | safety function remains available | safety function remains available |
| fault detection | some dangerous faults may remain undetected | dangerous faults are detected in time or their accumulation is controlled |
| MTTFd and DCavg | permitted combinations depend on the design | high values are associated with the designated architecture |
| common-cause failures | measures required | measures required |
| achieved PL | calculated from all relevant parameters | calculated from all relevant parameters |
Do not write “Category 3 equals PL d” or “Category 4 equals PL e” in a specification. Category is one input to the PL evaluation. Component reliability, diagnostic effectiveness, CCF, systematic measures, software, interfaces, and the other safety-function subsystems still matter.
CCF review must go beyond mounting the valves apart. Both channels can be affected by dirty air, frozen condensate, excessive temperature, vibration, a shared regulator fault, incorrect replacement parts, common wiring damage, or the same maintenance error. The documented measures must address the actual installation.
What Must Valve Feedback Detect?
ROSS states that monitoring both RSe spool-position sensors on every actuation and de-actuation can provide up to 99% diagnostic coverage for that product when an external safety controller performs the specified checks (ROSS RSe, accessed 2026). The number is model-specific and cannot be assigned to generic feedback.
Diagnostic coverage means the effectiveness of the implemented diagnostics in detecting dangerous failures. Coil voltage proves only that the controller issued a command. It does not prove that the solenoid developed force, the pilot stage shifted, the spool or poppet moved, the exhaust path opened, or downstream pressure fell. Useful diagnostics must target the dangerous failure modes identified for the exact valve and circuit.
Common feedback methods include:
- positively driven or proximity-based valve-position sensing
- independent feedback from both redundant valve elements
- downstream-pressure plausibility at the hazardous zone
- channel discrepancy timing during energization and de-energization
- comparison of valve state with actuator position or guarded-machine state
- a controller response that inhibits the next hazardous cycle after a fault
Pressure feedback has limits. A switch upstream of the safety valve cannot show whether a downstream cavity exhausted. One switch after a manifold may miss trapped pressure behind a check valve. A pressure threshold can confirm pneumatic state, but it may not prove that a vertical axis stopped or that a clamp retained its load.
Position feedback also has limits. A spool sensor may prove valve-element position without proving adequate exhaust flow through a blocked silencer. The diagnostic concept should therefore connect each credited signal to a defined dangerous failure and a fault reaction.
From our work reviewing replacement requests, we found that “feedback included” is often too vague for a safe substitution. The request should identify the signal’s normal and fault states, discrepancy timing, controller response, connector pinout, and whether the sensor reports actual valve position or only an electrical command.
Treat diagnostics as evidence chains: command, valve position, downstream pressure, and hazardous motion answer different questions, and no single signal automatically proves all four.
Safe Exhaust, Safe Return, and Pressure Retention
Parker identifies its P33 as a 3/2 normally closed safety-exhaust valve, while ROSS documents 5/2 RSe arrangements for safe return and dual-pressure functions (Parker P33, 2024; ROSS RSe, accessed 2026). Port count follows the intended hazard-controlled machine response for each defined hazard.
Safe exhaust is a function that blocks supply and vents a defined downstream zone. It is suitable only when pressure reduction leads to a safe physical state. Large downstream volumes, long hoses, flow controls, check valves, closed-center directional valves, and exhaust silencers can slow or prevent the expected pressure decay.
Safe return directs an actuator toward a defined position instead of simply releasing both chambers. The return motion itself must be safe in speed, force, direction, and final position. A 5/2 redundant valve may support this function, but actuator load, cushions, flow controls, and mechanical travel still require validation.
Pressure retention can be safer when exhausting would drop a vertical load, release a clamp, or lose a vacuum-held part. Retention may require a rod lock, brake, mechanical prop, pilot-operated check arrangement, or another validated measure. It can also trap hazardous energy, so the production safety function and the maintenance isolation procedure must be considered separately.
For an indexing table or rotary clamp, define angular stopping, holding torque, and the de-energized pressure state using the dedicated guide to rotary actuator integration under ISO 13849.
| Intended function | Pneumatic response | Primary validation concern |
|---|---|---|
| safe exhaust | block supply and reduce downstream pressure | pressure-decay time and residual motion |
| prevention of unexpected pressurization | keep the hazardous zone isolated | leakage, restart, and single-fault behavior |
| safe return | route the actuator to a defined position | return speed, force, stopping point, and load behavior |
| safe pressure select | permit only the intended pressure level | wrong-pressure fault and monitored valve state |
| load holding | retain or mechanically restrain the load | drift, trapped energy, release, and service access |
The guide to safety exhaust valves in machine guarding covers placement and pressure-decay testing. For vertical axes, also review cylinder rod-lock behavior and vertical lifting cylinder design.
A standard quick exhaust valve can shorten an actuator’s exhaust path, but it has no implied redundant architecture or diagnostic function. Likewise, a pilot-operated check valve can retain pressure while creating a separate trapped-energy hazard.
How Should the Valve Subsystem Be Modeled in SISTEMA?
IFA’s SISTEMA tool evaluates the achieved PL using the designated architecture together with PLr, Category, MTTFd, DCavg, and CCF inputs (IFA, accessed 2026). The redundant valve belongs in the output subsystem, not as a shortcut that replaces the complete safety-function model.
Create the safety function first, then divide it into input, logic, and output subsystems. The valve output subsystem should match the real circuit and monitoring. If an integrated double valve has a certified subsystem value and SISTEMA library, use the exact manufacturer data only under its stated operating and integration conditions.
For a design built from discrete valve elements, collect the information needed to evaluate each channel and diagnostic measure:
- exact valve part number and safety function
- B10d, MTTFd, PFHd, or certified subsystem data supplied for that model
- annual operations and safety-function demand profile
- mission time and maintenance limits
- permitted pressure, temperature, air quality, switching rate, and exhaust accessories
- detectable dangerous failures and credited diagnostic coverage
- CCF measures for the multi-channel design
- controller timing, test pulses, discrepancy limits, and reset response
Do not copy a B10d value from a similar valve family. A different seal, spool, pilot stage, sensor, operating pressure, or test frequency can invalidate the assumed reliability data. Likewise, do not credit a 99% DC value merely because the circuit contains two sensors; the diagnostic logic must implement the manufacturer’s specified checks.
SISTEMA verifies the modeled control architecture. It cannot detect reversed plumbing, a blocked exhaust, an unmodeled check valve, wrong sensor placement, a gravity hazard, or software that differs from the documented revision. Those issues belong in design review and validation.
For the wider calculation workflow, including B10d-to-MTTFd conversion, use the complete ISO 13849 pneumatic circuit guide. No general-purpose site calculator replaces SISTEMA or a documented safety evaluation.
Validation Tests for a Redundant Valve Output Stage
ISO 13849-2:2012 requires validation by analysis and testing of the specified safety functions, achieved Category, and achieved PL (ISO, 2012). As of July 2026, that edition remains published while its replacement is still under development, so the installed valve subsystem needs traceable test evidence rather than a catalogue-only review.
Write acceptance criteria before testing. Define the demand signal, safe pressure threshold, permitted motion, time limit, actuator load, supply range, reset behavior, and restart conditions. Then test the normal function and credible faults under the machine configurations that produce the most difficult response.
| Test | Evidence to record | Unsafe result to catch |
|---|---|---|
| demand the safety function | input, logic output, both valve feedbacks, pressure, and motion on one time base | late or incomplete safe response |
| prevent element A from shifting | state of element B, pressure path, diagnostic alarm, and restart inhibition | single fault defeats the function |
| prevent element B from shifting | same evidence with channels reversed | asymmetrical fault not covered |
| hold one feedback signal on or off | controller discrepancy response and reset behavior | sensor fault accepted as a valid state |
| restrict the approved exhaust path to the credible limit | downstream pressure and hazardous motion | blocked or degraded exhaust defeats timing |
| test supply and electrical power restoration | valve state, soft-start behavior, and machine motion | hazardous automatic restart |
| test worst actuator position and load | pressure, travel, stopping point, and holding behavior | safe state valid only under light-load conditions |
Measure pressure at the volume that matters. A gauge beside the valve can show low pressure while a cylinder chamber remains trapped behind a check valve. When motion is the hazard, record the actual axis position or speed as well as pressure.
Reset deserves its own test. A reset may clear the safety state, but it must not itself initiate hazardous movement. After a detected channel discrepancy, the system should remain inhibited until the documented fault-clear and reset conditions have been met.
There is no universal daily, monthly, or annual test interval based only on PL. Inspection and functional-test intervals must follow the product instructions, risk assessment, diagnostic concept, use frequency, environment, maintenance history, and any applicable machinery-specific standard.
What Evidence Should a Supplier Provide?
ROSS publishes a model-specific RSe B10d of 20 million cycles, PFHd of 7.71 x 10^-9 per hour, and a maximum 250 ms discordance time for one documented configuration (ROSS RSe documentation, accessed 2026). These figures illustrate the level of specificity an engineer needs; they are not generic redundant-valve values.
Request evidence for the exact ordered configuration, including coil voltage, body size, sensors, connector, pilot arrangement, and reset option. A family brochure may contain several versions with different certification or integration conditions.
In our experience, the most useful supplier response starts with the exact part number, certificate scope, safety manual revision, and feedback truth table. Flow rate and port size matter, but they cannot compensate for missing fault-response or monitoring evidence.
The technical package should include:
- declared safety function and applicable standards
- certificate or assessment covering the exact model
- Category and PL capability with stated integration conditions
- B10d, MTTFd, PFHd, mission time, and assumed operating rate where applicable
- pneumatic symbol and internal functional description
- monitoring method, signal logic, and discrepancy timing
- permitted safety relay or safety PLC interface conditions
- wiring, plumbing, reset, test-pulse, and fault-reaction requirements
- pressure, temperature, air-quality, mounting, and cycling limits
- approved exhaust silencers and soft-start arrangements
- current safety manual, declaration, SISTEMA library, and revision history
Reject phrases such as “dual channel,” “fail-safe,” or “PL e ready” when they are not tied to these records. The machine builder must also preserve the integration conditions in the electrical drawing, pneumatic schematic, software, bill of materials, commissioning report, and replacement procedure.
For a replacement, compare functions before dimensions. Two valves with matching ports and voltage can differ in internal monitoring, sensor logic, reset behavior, exhaust capacity, fault latching, certification, or minimum operating frequency. A form-fit substitute may invalidate the safety calculation and require revalidation.
In a safety-related replacement request, the integration manual and feedback truth table are as important as port size and flow capacity.
Redundant Valve System FAQs: What Should Engineers Verify?
ISO 13849-1:2023 uses five PL bands, but every FAQ below returns to the same rule: architecture labels and component certificates do not replace a defined safety function, complete PL evaluation, and installed-machine validation (ISO, 2023). Verify the valve as one output subsystem within that chain.
Does using two valves automatically create Category 3?
No. Category 3 requires the safety function to survive a single fault, along with the applicable reliability, diagnostic, common-cause, and systematic requirements. Two ordinary valves may share a dangerous failure path or have no effective monitoring. The real pneumatic interconnection and fault response must be analyzed.
Can a Category 4, PL e valve make the complete machine PL e?
No. A valve may provide a certified or assessed output subsystem under stated conditions. The input devices, safety logic, wiring, diagnostics, other outputs, software, interfaces, and physical machine response must also meet the safety-function requirements. The installed function still needs verification and validation.
Should a redundant valve system always dump all machine air?
No. The risk assessment defines the safe state and hazardous zone. Full exhaust can drop a vertical load, release a clamp, or lose a vacuum-held part. Some machines need zoned exhaust, controlled safe return, pressure retention, or mechanical restraint instead of indiscriminate plant-wide depressurization.
Is downstream pressure feedback enough to monitor both valve elements?
Not always. Pressure feedback can confirm that a volume crossed a threshold, but it may not identify which valve element failed or prove its position. Category and DC claims must follow the product’s failure analysis and monitoring instructions. Some designs require separate position feedback from each element.
How often should a redundant valve safety function be tested?
There is no universal interval based only on PL d or PL e. Use the valve safety manual, diagnostic design, risk assessment, operating frequency, contamination exposure, maintenance history, and applicable machine standard. Include the assumed test or operating frequency in the reliability evaluation and validation plan.
Sources and Technical References
This guide draws on 11 primary sources retrieved on July 22, 2026: five ISO or IFA references and six manufacturer documents. Product figures remain attached to their exact model and integration conditions, while ISO sources govern the system-level design and validation statements. No customer anecdotes, market-price claims, or generic savings percentages are used.
- International Organization for Standardization. ISO 12100:2010, Safety of machinery, risk assessment and risk reduction. Confirmed 2022. Retrieved 2026-07-22.
- International Organization for Standardization. ISO 13849-1:2023, Safety-related parts of control systems, Part 1. Retrieved 2026-07-22.
- International Organization for Standardization. ISO 13849-2:2012, Validation. Retrieved 2026-07-22.
- International Organization for Standardization. ISO/DIS 13849-2, draft revision under development. Retrieved 2026-07-22.
- International Organization for Standardization. ISO 4414:2010, Pneumatic fluid power safety requirements. Confirmed 2021. Retrieved 2026-07-22.
- Institute for Occupational Safety and Health of the German Social Accident Insurance. SISTEMA software for ISO 13849-1. Retrieved 2026-07-22.
- Institute for Occupational Safety and Health of the German Social Accident Insurance. IFA Report 2/2017e, Functional safety of machine controls. Retrieved 2026-07-22.
- Parker Hannifin. P33 Safety Exhaust Valve technical catalogue. November 2024. Retrieved 2026-07-22.
- Parker Hannifin. P33 Safety Exhaust Valve integration guide. Retrieved 2026-07-22.
- ROSS Controls. Series 1286 safe-air-entry assembly with internally monitored DMC double valve. Retrieved 2026-07-22.
- ROSS Controls. RSe externally monitored redundant double valve. Retrieved 2026-07-22.

