Manufacturing
Presses, mixers, conveyors and packaging machines installed before current requirements, still in daily use and still perfectly serviceable.
Risk Assessment • Safety Relays & Controllers • Interlocks & Light Curtains • Validation • UAE
Safety on an older machine tends to fail in a particular direction. A guard interlock nuisance-trips, so somebody defeats it. A light curtain is mounted where it can be stepped around. An emergency stop drops out a single contactor whose welded contact nobody would ever detect. The machine looks protected, everyone believes it is protected, and the protection would not survive the first fault it was there to catch.
A safety upgrade starts by deciding, in writing, what each hazard actually requires — and then builds protection that meets it and that people will not work around. The second half of that sentence matters as much as the first: a guard that stops the operator doing their job is a guard that will be defeated, and a defeated guard is worse than an honest absence of one.
The machine itself is left as it is. Each point below is a link in a safety function, from the device that detects to the contactors that stop, and the screen that says why.
A safety function is a chain, and it is only as good as its weakest link. Each stage below is specified to the level the assessment calls for, not to whatever was in the cupboard.
Step 5 is the one that keeps the rest of it in service. A safety system that stops the machine without telling anyone why is the system that gets bypassed by the end of the month.
The devices follow the assessment. What is right for a slow-moving conveyor is not what is right for a press.
Dual-channel monitored circuits so that a broken wire, a shorted wire or a welded contact is detected rather than silently ignored. A relay suits a machine with a handful of functions; a configurable safety controller earns its place once there are several zones, muting requirements or a need to change the logic without rewiring.
Coded magnetic or RFID switches that cannot be defeated with a spare actuator taped to the frame, and guard locking where the machine takes time to come to rest. Where a guard has to open frequently, choosing a device and a reset scheme that fits the operator's rhythm is what stops it being defeated.
For openings that have to stay open — loading points, robot cells, palletiser infeeds. Mounting distance is calculated from the machine's actual stopping time rather than estimated, because a curtain mounted too close protects nobody while looking exactly like one that works.
Redundant contactors with feedback monitoring, or safe torque off on a drive where the machine has one, or a dump valve on a pneumatic system. This is the end of the chain and it is where an old installation is most often weakest, with everything routed through a single unmonitored contactor.
The assessment leads and the hardware follows. Doing it the other way round is how a machine ends up with expensive equipment protecting the wrong thing.
Every hazard at every stage of the machine's life — running, setting, cleaning, clearing a jam — with a required performance level attached. Setting and jam clearing is where most incidents happen and where production-only assessments tend to go quiet.
Each function written down: what detects, what decides, what stops, and to what performance level. The architecture is then chosen to achieve it, and the calculation is documented so it can be shown rather than asserted.
Devices mounted at calculated distances, wiring to the safety circuit kept separate and identified, and the machine's own control interlocked with it. Diagnostics are brought to the HMI at this point rather than added later when the complaints start.
Each safety function tested deliberately, including the fault conditions it is supposed to detect — a channel disconnected, a contact held closed. Results are documented, and operators and setters are trained on how the machine now behaves before it goes back into production.
Validation is not a formality. A dual-channel circuit wired as two parallel single channels passes every functional test and detects nothing.
Protection that behaves correctly when a component fails, which is the entire point of a monitored circuit.
Guards that people use as intended, because they were designed around how the job is actually done.
Diagnostics that turn a mystery stop into a named device, so production is restored in seconds rather than by bypassing something.
Documentation — assessment, design, calculations and validation records — that can be produced when somebody asks for it.
A machine that can be set and cleaned safely, which is where the incidents that documentation never anticipated actually occur.
Presses, mixers, conveyors and packaging machines installed before current requirements, still in daily use and still perfectly serviceable.
Robot cells and assembly stations where the guarding was designed for a cycle that has since changed, and the operators have adapted around it.
Machines that must be opened frequently for cleaning, where an interlock that suits production but obstructs the wash-down is the one that gets defeated.
The obligation is to provide safe equipment, and what that means in practice is decided by a risk assessment of the machine as it stands and as it is actually used. An older machine does not automatically have to be brought to the standard a new one would be built to, but nor does its age excuse a hazard. The assessment is what turns that question from an opinion into a documented position.
Badly designed protection does, which is precisely why it gets defeated. Good design keeps the safe way of working the quick way — zone control so only the relevant part stops, muting so the machine can accept material without a stop, and guard locking that releases as soon as it is genuinely safe rather than on a fixed timer. If a proposed change makes an operator's job harder, that is a design problem and it is worth solving before installation.
Mostly. The assessment and design happen while the machine runs, panels and brackets are prepared off-line, and the installation is planned into a shutdown or a weekend. Validation needs the machine stopped and available, and that time should not be compressed — it is the step that establishes the protection actually works.
A risk assessment of the machine as it is actually used, and a safety design costed against what it found.