Redundant Valve Systems: A Guide to ISO 13849-1 Safety Circuits

Design redundant pneumatic valve systems for ISO 13849-1 using 3/2 and 5/2 architectures, monitored feedback, fault response, SISTEMA, and validation.

Share
David Li, Chief Advisor for Bepto Pneumatic technical review

About the author

David Li

Chief Advisor

Hello, I'm David, a Bepto Pneumatic chief advisor. I help teams review compressed-air safety, system reliability, and practical product decisions before quotation.

Author articlesDavid@bepto.com

A redundant pneumatic valve system is an output subsystem designed to preserve a defined safety response after a single fault. It does not automatically make a machine PL d or PL e. The risk assessment, input devices, safety logic, valve architecture, diagnostics, pneumatic circuit, and physical machine response all contribute to the achieved Performance Level.

This article focuses on the valve output subsystem: how two valve elements are arranged, what their feedback must prove, how faults affect supply and exhaust paths, and what must be tested on the installed machine. For the complete input-logic-output workflow, start with the broader guide to ISO 13849 pneumatic safety circuits.

Key Takeaways

  • ISO 13849-1 defines five Performance Levels, but redundancy alone establishes none of them.
  • A 3/2 double valve can support safe exhaust; a monitored 5/2 design can support a defined safe return.
  • Feedback must detect dangerous valve faults, not merely confirm coil voltage.
  • Validate pressure, motion, reset, and restart behavior on the installed machine.

What Does a Redundant Valve System Actually Protect?

ISO 13849-1:2023 defines five Performance Levels from PL a through PL e, yet it does not assign a safety function or required PLr to a particular pneumatic application (ISO, 2023). A redundant valve system protects only the machine safety function that the designer has explicitly defined.

That function might prevent unexpected pressurization when a guard is open. It might exhaust one hazardous zone, move an actuator to a controlled return position, retain pressure long enough for a brake to engage, or select a reduced setup pressure. Each function needs a trigger, a safe state, a PLr, an architecture, diagnostic behavior, and measurable acceptance criteria.

The word “redundant” describes structure, not the result. Two valve elements may provide two output paths, but the system still fails if one contaminated air supply jams both elements, a shared connector disables both coils, a blocked silencer prevents exhaust, or the controller ignores a feedback discrepancy.

Begin with four questions:

  1. Which hazardous motion or pressure must the function control?
  2. What physical state is safe for the worst credible load and actuator position?
  3. Which single faults must the valve subsystem tolerate or detect?
  4. What evidence will prove that the installed machine reaches and maintains that state?

In our experience reviewing pneumatic safety specifications, the most common wording problem is a component label presented as the safety function. Replace “use a redundant valve” with a measurable requirement such as “prevent pressure above the defined threshold at the extend port after any credited single output fault.”

ISO 4414:2010, confirmed current in 2021, addresses significant pneumatic-system hazards across design, installation, operation, and maintenance. It reinforces a central rule: the valve cannot be evaluated apart from stored pressure, gravity, springs, vacuum, piping, actuators, and the service procedure.

A second valve element is useful only when the pneumatic paths, diagnostics, and fault reaction remain independent enough to preserve the defined safety function.

Three Redundant Valve Architectures

Parker’s P33 family uses a 3/2 normally closed safety-exhaust function and offers internally or externally monitored versions, while ROSS documents redundant 3/2 and 5/2 double-valve arrangements (Parker, 2024; ROSS, accessed 2026). These examples show three practical architecture families for modern machine safety circuits.

Internally monitored double valve

Two valve elements and the monitoring logic are integrated into one assembly. The product checks element synchronization or state internally and prevents normal operation after a defined discrepancy. The system designer must still follow the reset, wiring, plumbing, minimum cycling, silencer, and fault-response conditions in the safety manual.

Externally monitored double valve

Each valve element provides position or pressure-state feedback to a safety relay or safety PLC. The external logic compares the commanded state with both feedback channels during energization and de-energization. ROSS, for example, specifies external monitoring of two PNP spool-position sensors for its RSe series. That product-specific arrangement must not be generalized to a valve with different sensors or internal geometry.

Two discrete valve channels

Separate valves can be designed as a redundant output subsystem when their pneumatic interconnection, electrical control, diagnostics, reliability data, and common-cause measures satisfy the required architecture. Simply installing two ordinary directional valves in series or parallel does not prove fault tolerance. The circuit must show what happens if either element sticks, leaks, shifts slowly, or loses its command.

Architecture Monitoring location Main engineering question
integrated double valve inside the certified assembly Which external conditions and reset logic must be provided?
externally monitored double valve safety relay or safety PLC Does the logic evaluate both real valve positions on every required transition?
two discrete channels machine safety control system Does the complete pneumatic arrangement preserve the safe state after either single fault?
Redundant pneumatic valve output subsystem and diagnostic feedback A vertical engineering diagram shows two safety outputs commanding two valve elements, independent feedback returning to the safety logic, a shared pneumatic function, and validation of pressure and motion at the hazard. Redundancy must include command, valve state, and machine response Safety logic compares commands, feedback, timing, and reset conditions output A output B Valve element A Valve element B supply, block, exhaust, or directional function supply, block, exhaust, or directional function feedback A feedback B Defined pneumatic output function safe exhaust, prevention of pressurization, safe return, or pressure selection Measured safe state at the hazard pressure threshold, motion limit, load position, and restart inhibition A matching sensor signal is not enough; the physical machine response must also pass validation.
A redundant output subsystem combines two controlled valve elements, diagnostic feedback, and a validated physical response. Exact internal porting and fault behavior remain product-specific. Sources: ISO 13849-1, Parker P33, and ROSS RSe documentation.

How Do Category 3 and Category 4 Change Fault Behavior?

IFA’s ISO 13849 application report distinguishes Category 3 from Category 4 through MTTFd, DCavg, and resistance to accumulated faults, not through the visual presence of two channels alone (IFA Report 2/2017e, 2019). Both designated architectures require appropriate measures against common-cause failures in pneumatic safety systems.

In Category 3, a single fault must not cause loss of the safety function. Some faults are detected, but an accumulation of undetected dangerous faults may eventually defeat the function. That means a schematic with two channels can still be inadequate if diagnostics miss a dangerous stuck valve or if both channels share an unaddressed cause of failure.

Category 4 also requires single-fault tolerance, with stronger fault detection or resistance to fault accumulation. IFA describes high MTTFd and high DCavg for the designated Category 4 architecture. This is why a product claiming Category 4 capability normally has explicit monitoring conditions, reliability data, and fault-reaction requirements.

Design question Category 3 orientation Category 4 orientation
effect of one fault safety function remains available safety function remains available
fault detection some dangerous faults may remain undetected dangerous faults are detected in time or their accumulation is controlled
MTTFd and DCavg permitted combinations depend on the design high values are associated with the designated architecture
common-cause failures measures required measures required
achieved PL calculated from all relevant parameters calculated from all relevant parameters

Do not write “Category 3 equals PL d” or “Category 4 equals PL e” in a specification. Category is one input to the PL evaluation. Component reliability, diagnostic effectiveness, CCF, systematic measures, software, interfaces, and the other safety-function subsystems still matter.

CCF review must go beyond mounting the valves apart. Both channels can be affected by dirty air, frozen condensate, excessive temperature, vibration, a shared regulator fault, incorrect replacement parts, common wiring damage, or the same maintenance error. The documented measures must address the actual installation.

What Must Valve Feedback Detect?

ROSS states that monitoring both RSe spool-position sensors on every actuation and de-actuation can provide up to 99% diagnostic coverage for that product when an external safety controller performs the specified checks (ROSS RSe, accessed 2026). The number is model-specific and cannot be assigned to generic feedback.

Diagnostic coverage means the effectiveness of the implemented diagnostics in detecting dangerous failures. Coil voltage proves only that the controller issued a command. It does not prove that the solenoid developed force, the pilot stage shifted, the spool or poppet moved, the exhaust path opened, or downstream pressure fell. Useful diagnostics must target the dangerous failure modes identified for the exact valve and circuit.

Common feedback methods include:

  • positively driven or proximity-based valve-position sensing
  • independent feedback from both redundant valve elements
  • downstream-pressure plausibility at the hazardous zone
  • channel discrepancy timing during energization and de-energization
  • comparison of valve state with actuator position or guarded-machine state
  • a controller response that inhibits the next hazardous cycle after a fault

Pressure feedback has limits. A switch upstream of the safety valve cannot show whether a downstream cavity exhausted. One switch after a manifold may miss trapped pressure behind a check valve. A pressure threshold can confirm pneumatic state, but it may not prove that a vertical axis stopped or that a clamp retained its load.

Position feedback also has limits. A spool sensor may prove valve-element position without proving adequate exhaust flow through a blocked silencer. The diagnostic concept should therefore connect each credited signal to a defined dangerous failure and a fault reaction.

From our work reviewing replacement requests, we found that “feedback included” is often too vague for a safe substitution. The request should identify the signal’s normal and fault states, discrepancy timing, controller response, connector pinout, and whether the sensor reports actual valve position or only an electrical command.

Treat diagnostics as evidence chains: command, valve position, downstream pressure, and hazardous motion answer different questions, and no single signal automatically proves all four.

Safe Exhaust, Safe Return, and Pressure Retention

Parker identifies its P33 as a 3/2 normally closed safety-exhaust valve, while ROSS documents 5/2 RSe arrangements for safe return and dual-pressure functions (Parker P33, 2024; ROSS RSe, accessed 2026). Port count follows the intended hazard-controlled machine response for each defined hazard.

Safe exhaust is a function that blocks supply and vents a defined downstream zone. It is suitable only when pressure reduction leads to a safe physical state. Large downstream volumes, long hoses, flow controls, check valves, closed-center directional valves, and exhaust silencers can slow or prevent the expected pressure decay.

Safe return directs an actuator toward a defined position instead of simply releasing both chambers. The return motion itself must be safe in speed, force, direction, and final position. A 5/2 redundant valve may support this function, but actuator load, cushions, flow controls, and mechanical travel still require validation.

Pressure retention can be safer when exhausting would drop a vertical load, release a clamp, or lose a vacuum-held part. Retention may require a rod lock, brake, mechanical prop, pilot-operated check arrangement, or another validated measure. It can also trap hazardous energy, so the production safety function and the maintenance isolation procedure must be considered separately.

For an indexing table or rotary clamp, define angular stopping, holding torque, and the de-energized pressure state using the dedicated guide to rotary actuator integration under ISO 13849.

Intended function Pneumatic response Primary validation concern
safe exhaust block supply and reduce downstream pressure pressure-decay time and residual motion
prevention of unexpected pressurization keep the hazardous zone isolated leakage, restart, and single-fault behavior
safe return route the actuator to a defined position return speed, force, stopping point, and load behavior
safe pressure select permit only the intended pressure level wrong-pressure fault and monitored valve state
load holding retain or mechanically restrain the load drift, trapped energy, release, and service access

The guide to safety exhaust valves in machine guarding covers placement and pressure-decay testing. For vertical axes, also review cylinder rod-lock behavior and vertical lifting cylinder design.

A standard quick exhaust valve can shorten an actuator’s exhaust path, but it has no implied redundant architecture or diagnostic function. Likewise, a pilot-operated check valve can retain pressure while creating a separate trapped-energy hazard.

How Should the Valve Subsystem Be Modeled in SISTEMA?

IFA’s SISTEMA tool evaluates the achieved PL using the designated architecture together with PLr, Category, MTTFd, DCavg, and CCF inputs (IFA, accessed 2026). The redundant valve belongs in the output subsystem, not as a shortcut that replaces the complete safety-function model.

Create the safety function first, then divide it into input, logic, and output subsystems. The valve output subsystem should match the real circuit and monitoring. If an integrated double valve has a certified subsystem value and SISTEMA library, use the exact manufacturer data only under its stated operating and integration conditions.

For a design built from discrete valve elements, collect the information needed to evaluate each channel and diagnostic measure:

  • exact valve part number and safety function
  • B10d, MTTFd, PFHd, or certified subsystem data supplied for that model
  • annual operations and safety-function demand profile
  • mission time and maintenance limits
  • permitted pressure, temperature, air quality, switching rate, and exhaust accessories
  • detectable dangerous failures and credited diagnostic coverage
  • CCF measures for the multi-channel design
  • controller timing, test pulses, discrepancy limits, and reset response

Do not copy a B10d value from a similar valve family. A different seal, spool, pilot stage, sensor, operating pressure, or test frequency can invalidate the assumed reliability data. Likewise, do not credit a 99% DC value merely because the circuit contains two sensors; the diagnostic logic must implement the manufacturer’s specified checks.

SISTEMA verifies the modeled control architecture. It cannot detect reversed plumbing, a blocked exhaust, an unmodeled check valve, wrong sensor placement, a gravity hazard, or software that differs from the documented revision. Those issues belong in design review and validation.

For the wider calculation workflow, including B10d-to-MTTFd conversion, use the complete ISO 13849 pneumatic circuit guide. No general-purpose site calculator replaces SISTEMA or a documented safety evaluation.

Validation Tests for a Redundant Valve Output Stage

ISO 13849-2:2012 requires validation by analysis and testing of the specified safety functions, achieved Category, and achieved PL (ISO, 2012). As of July 2026, that edition remains published while its replacement is still under development, so the installed valve subsystem needs traceable test evidence rather than a catalogue-only review.

Write acceptance criteria before testing. Define the demand signal, safe pressure threshold, permitted motion, time limit, actuator load, supply range, reset behavior, and restart conditions. Then test the normal function and credible faults under the machine configurations that produce the most difficult response.

Test Evidence to record Unsafe result to catch
demand the safety function input, logic output, both valve feedbacks, pressure, and motion on one time base late or incomplete safe response
prevent element A from shifting state of element B, pressure path, diagnostic alarm, and restart inhibition single fault defeats the function
prevent element B from shifting same evidence with channels reversed asymmetrical fault not covered
hold one feedback signal on or off controller discrepancy response and reset behavior sensor fault accepted as a valid state
restrict the approved exhaust path to the credible limit downstream pressure and hazardous motion blocked or degraded exhaust defeats timing
test supply and electrical power restoration valve state, soft-start behavior, and machine motion hazardous automatic restart
test worst actuator position and load pressure, travel, stopping point, and holding behavior safe state valid only under light-load conditions

Measure pressure at the volume that matters. A gauge beside the valve can show low pressure while a cylinder chamber remains trapped behind a check valve. When motion is the hazard, record the actual axis position or speed as well as pressure.

Reset deserves its own test. A reset may clear the safety state, but it must not itself initiate hazardous movement. After a detected channel discrepancy, the system should remain inhibited until the documented fault-clear and reset conditions have been met.

There is no universal daily, monthly, or annual test interval based only on PL. Inspection and functional-test intervals must follow the product instructions, risk assessment, diagnostic concept, use frequency, environment, maintenance history, and any applicable machinery-specific standard.

What Evidence Should a Supplier Provide?

ROSS publishes a model-specific RSe B10d of 20 million cycles, PFHd of 7.71 x 10^-9 per hour, and a maximum 250 ms discordance time for one documented configuration (ROSS RSe documentation, accessed 2026). These figures illustrate the level of specificity an engineer needs; they are not generic redundant-valve values.

Request evidence for the exact ordered configuration, including coil voltage, body size, sensors, connector, pilot arrangement, and reset option. A family brochure may contain several versions with different certification or integration conditions.

In our experience, the most useful supplier response starts with the exact part number, certificate scope, safety manual revision, and feedback truth table. Flow rate and port size matter, but they cannot compensate for missing fault-response or monitoring evidence.

The technical package should include:

  • declared safety function and applicable standards
  • certificate or assessment covering the exact model
  • Category and PL capability with stated integration conditions
  • B10d, MTTFd, PFHd, mission time, and assumed operating rate where applicable
  • pneumatic symbol and internal functional description
  • monitoring method, signal logic, and discrepancy timing
  • permitted safety relay or safety PLC interface conditions
  • wiring, plumbing, reset, test-pulse, and fault-reaction requirements
  • pressure, temperature, air-quality, mounting, and cycling limits
  • approved exhaust silencers and soft-start arrangements
  • current safety manual, declaration, SISTEMA library, and revision history

Reject phrases such as “dual channel,” “fail-safe,” or “PL e ready” when they are not tied to these records. The machine builder must also preserve the integration conditions in the electrical drawing, pneumatic schematic, software, bill of materials, commissioning report, and replacement procedure.

For a replacement, compare functions before dimensions. Two valves with matching ports and voltage can differ in internal monitoring, sensor logic, reset behavior, exhaust capacity, fault latching, certification, or minimum operating frequency. A form-fit substitute may invalidate the safety calculation and require revalidation.

In a safety-related replacement request, the integration manual and feedback truth table are as important as port size and flow capacity.

Redundant Valve System FAQs: What Should Engineers Verify?

ISO 13849-1:2023 uses five PL bands, but every FAQ below returns to the same rule: architecture labels and component certificates do not replace a defined safety function, complete PL evaluation, and installed-machine validation (ISO, 2023). Verify the valve as one output subsystem within that chain.

Does using two valves automatically create Category 3?

No. Category 3 requires the safety function to survive a single fault, along with the applicable reliability, diagnostic, common-cause, and systematic requirements. Two ordinary valves may share a dangerous failure path or have no effective monitoring. The real pneumatic interconnection and fault response must be analyzed.

Can a Category 4, PL e valve make the complete machine PL e?

No. A valve may provide a certified or assessed output subsystem under stated conditions. The input devices, safety logic, wiring, diagnostics, other outputs, software, interfaces, and physical machine response must also meet the safety-function requirements. The installed function still needs verification and validation.

Should a redundant valve system always dump all machine air?

No. The risk assessment defines the safe state and hazardous zone. Full exhaust can drop a vertical load, release a clamp, or lose a vacuum-held part. Some machines need zoned exhaust, controlled safe return, pressure retention, or mechanical restraint instead of indiscriminate plant-wide depressurization.

Is downstream pressure feedback enough to monitor both valve elements?

Not always. Pressure feedback can confirm that a volume crossed a threshold, but it may not identify which valve element failed or prove its position. Category and DC claims must follow the product’s failure analysis and monitoring instructions. Some designs require separate position feedback from each element.

How often should a redundant valve safety function be tested?

There is no universal interval based only on PL d or PL e. Use the valve safety manual, diagnostic design, risk assessment, operating frequency, contamination exposure, maintenance history, and applicable machine standard. Include the assumed test or operating frequency in the reliability evaluation and validation plan.

Sources and Technical References

This guide draws on 11 primary sources retrieved on July 22, 2026: five ISO or IFA references and six manufacturer documents. Product figures remain attached to their exact model and integration conditions, while ISO sources govern the system-level design and validation statements. No customer anecdotes, market-price claims, or generic savings percentages are used.

Related