AS 4024
Legal status — read this first
Standards Australia is not a regulator. Standards are voluntary documents; they become effectively mandatory only when referenced in legislation by state or Commonwealth governments. AS 4024 is largely not called up directly in the WHS Regulations.
What actually binds you in Queensland:
- WHS Act 2011 (Qld) ss. 22–26 — upstream duties on designers, manufacturers, importers, suppliers, installers of plant. This is the clause that catches you as a machine builder or system integrator.
- WHS Regulation 2011 (Qld) Ch. 5 Pt 3 — plant: guarding, emergency stops, controls, isolation, maintenance.
- Code of Practice: Managing the risks of plant in the workplace — admissible in proceedings as evidence of what was known and reasonably practicable.
AS 4024 is how you demonstrate you met the “reasonably practicable” test. Conform to it and you have a defensible position; ignore it and the prosecution’s expert will cite it against you. That’s the whole relationship.
Jurisdictional note: Vic is still under the OHS Act 2004 / OHS Regulations 2017, not the model WHS laws. WA harmonised in 2022. If you build machines for interstate sale, the duty applies in each jurisdiction of supply.
Series map
| Part | Subject | Underlying standard |
|---|---|---|
| 1100:2019 | Application guide — start here | — |
| 1201:2014 | General principles for design — risk assessment and risk reduction | ISO 12100 |
| 1204:2019 | Electrical equipment of machines | IEC 60204-1:2016 (MOD) |
| 1302:2019 | Hazardous substances emitted by machinery | — |
| 1303:2014 | Risk assessment — practical guidance and example methods | ISO/TR 14121-2 |
| 1401:2014 | Ergonomic principles for design | ISO 26800 |
| 1501-2006 (R2014) | SRP/CS — general principles for design | ISO 13849-1:1999 (categories) |
| 1502-2006 (R2014) | SRP/CS — validation | ISO 13849-2 |
| 1503:2014 | SRP/CS — general principles for design | ISO 13849-1:2006 (PL) |
| 1601:2014 | Guards — fixed and movable, design and construction | ISO 14120 |
| 1602:2014 | Interlocking devices associated with guards | ISO 14119 |
| 1603:2019 | Prevention of unexpected start-up | ISO 14118 |
| 1604:2019 | Emergency stop — principles for design | ISO 13850 |
| 1701–1704 | Human body measurements, access openings, anthropometric data | ISO 15534 / 7250 |
| 1801:2014 | Safety distances — upper and lower limbs | ISO 13857 |
| 1803:2019 | Minimum gaps to prevent crushing | ISO 13854 |
| 1901–1907 | Displays, controls, actuators, signals; marking; auditory/visual warnings | ISO 9355 / IEC 61310 |
Machine-specific parts sit in the 3xxx range: AS 4024.3001:2021 and 3002:2021 for presses, AS 4024.3101 for milling and boring machines, and conveyors — formerly AS 1755-2000 — now under AS/NZS 4024.3610, .3611, .3612 and .3614.
The 1501/1502 vs 1503 trap
Both live in the series simultaneously, and they encode two incompatible design methodologies:
- 1501/1502 (2006, reconfirmed 2014) — the old EN 954-1 approach. Purely architectural: pick Category B, 1, 2, 3 or 4 from a risk graph. No reliability data, no probabilistic assessment.
- 1503:2014 — the modern ISO 13849-1:2006 approach. Performance Level PLa–PLe, which combines architecture plus component reliability and diagnostics.
Use 1503. Category-only design was withdrawn internationally in 2011 because it lets you build a Category 3 circuit out of junk components and call it safe. If a supplier quotes you “Category 3” with no PL, they’re working from a 20-year-old mental model — push back.
How 1503 / ISO 13849-1 actually works
Step 1 — Determine required Performance Level (PLr) per safety function, via the risk graph:
- S severity: S1 slight/reversible, S2 serious/irreversible or death
- F frequency/duration of exposure: F1 seldom, F2 frequent/continuous
- P possibility of avoidance: P1 possible under specific conditions, P2 scarcely possible
S2 + F2 + P2 → PLe. Guarded pinch point with occasional access → typically PLd. A jam-clearing operation on a hydraulic press is PLe every time.
Step 2 — Design to hit it. PL is a function of four inputs:
- Category (B, 1, 2, 3, 4) — the architecture. Cat 3 = dual channel, single fault tolerant, most faults detected. Cat 4 = dual channel, all faults detected or accumulated faults don’t cause loss of function.
- MTTFd — mean time to dangerous failure, per channel: Low (3–10 yr), Medium (10–30 yr), High (30–100 yr). Capped at 100 years regardless of how good your component is.
- DCavg — diagnostic coverage: None (<60%), Low (60–90%), Medium (90–99%), High (≥99%).
- CCF — common cause failure. A checklist scoring ≥65/100 (separation, diversity, over-dimensioning, environmental immunity). Fail it and your dual channel counts as single.
Output is PFHd, probability of dangerous failure per hour. PLd = 10⁻⁷ to 10⁻⁶/h. PLe = 10⁻⁸ to 10⁻⁷/h.
Step 3 — Verify PL achieved ≥ PLr for every safety function, including subsystem combination (two PLd subsystems in series do not give you PLd — combination degrades it).
Step 4 — Validate per 1502: fault injection testing, not just paperwork. Actually open the guard, actually cut one channel, confirm the machine stops and won’t restart.
Use SISTEMA (free, from the German IFA) for the arithmetic. Every reputable component vendor publishes a SISTEMA library with certified MTTFd/B10d figures.
IEC 62061 (adopted as AS 62061) is the parallel route using SIL 1–3 instead of PL. Rough mapping: SIL1≈PLc, SIL2≈PLd, SIL3≈PLe. Pick one framework per machine and stay in it. ISO 13849 is more common for discrete machinery; 62061 for complex electronic architectures. Note the two were merged in ISO 13849-1:2023 internationally — Australia hasn’t adopted that yet, so 1503 remains the 2006 methodology.
Safety distances — the calculation you’ll actually do
From ISO 13855 (approach speed), used with 1801:
S = (K × T) + C
S= minimum distance from danger zone to detection plane (mm)K= approach speed, 2000 mm/s for normal approach, 1600 mm/s where S > 500 mmT= total stopping time = detection + safety relay response + PLC/contactor + mechanical run-down. Measure it, don’t take the datasheet value — a worn brake adds hundreds of milliseconds.C= intrusion allowance. For a light curtain:C = 8 × (d − 14), whered= detection capability in mm. A 30 mm resolution curtain gives C = 128 mm.
Worked: 30 mm curtain, 250 ms total stop time → S = 2000 × 0.25 + 128 = 628 mm. That’s a long way back, and it’s why fine-resolution curtains (14 mm, C = 0) and fast-stopping drives earn their cost.
1801 (ISO 13857) is the reach-over/reach-through table set: how high a fence must be for a given danger-zone height, and what gap size lets a finger/hand/arm through at what distance. 1803 gives crushing gaps — ≥ 25 mm for fingers, ≥ 100 mm for an arm, ≥ 500 mm for a whole body.
Points that catch control engineers
Emergency stop (1604 / ISO 13850) is a complementary protective measure, not a safety function you may substitute for guarding. Stop categories per IEC 60204-1:
- Cat 0 — immediate removal of power. Uncontrolled coast-down.
- Cat 1 — controlled deceleration, then power removal. Correct for high-inertia loads where Cat 0 would be more dangerous.
- Cat 2 — controlled stop with power maintained. Not permitted for E-stop.
E-stop must be latching, manually reset, and reset must not itself restart the machine. Red mushroom on yellow background. Wired NC through a direct-opening-action (positive-opening, IEC 60947-5-1 Annex K) contact block so a welded contact still opens mechanically.
Interlocks (1602 / ISO 14119) — the standard’s most cited topic in Australia is defeat resistance. Simple magnetic and tongue switches can be beaten with a spare actuator or a magnet in a pocket, and operators do exactly that. Use coded (RFID-uniquely-coded) switches, or guard locking where run-down time exceeds access time. Mount so the switch isn’t accessible with a screwdriver.
Unexpected start-up (1603 / ISO 14118) — energy isolation, not just a stop command. Covers lockout points, stored energy dissipation (accumulators, capacitors, gravity), and the rule that restoring power after an interruption must not restart the machine.
Electrical equipment (1204 / IEC 60204-1) is the one you’ll live in as an EE: supply disconnection, protective bonding continuity ≤ 0.1 Ω, PELV control circuits, conductor colours (black power, red AC control, blue DC control, orange for circuits energised when the main disconnect is off — that orange rule catches people), enclosure IP rating, and the required test schedule: continuity of protective bonding, insulation resistance ≥ 1 MΩ at 500 VDC, dielectric withstand, residual voltage, functional test.
Implementation, tied to your PLC question
The 4024 requirement translates to hardware like this:
| PLr | Typical implementation |
|---|---|
| PLb/PLc | Single-channel monitored, or a basic safety relay |
| PLd | Dual-channel safety relay (Pilz PNOZ, Sick UE, Allen-Bradley Guardmaster) with forced-guided feedback loop |
| PLd/PLe, >4 functions | Safety PLC / safety controller: Pilz PNOZmulti, Siemens F-CPU + PROFIsafe, AB GuardLogix + CIP Safety, Beckhoff TwinSAFE |
The switchover point is roughly four safety functions or any need for zone logic, muting, or reconfiguration — beyond that, relay wiring becomes unmaintainable and a safety PLC is cheaper.
Safety over fieldbus (PROFIsafe, CIP Safety, FSoE) uses the “black channel” principle: the safety layer adds sequence numbers, CRC, timeouts and a safety-relevant payload wrapper, so the underlying network needs no certification. Your ordinary PROFINET/EtherNet/IP infrastructure carries safety traffic unmodified.
Non-negotiable: standard PLC logic is PLb at best. No amount of clever ladder makes a standard CPU a safety device. Your E-stop must break the safety circuit in hardware or via a certified safety controller — a standard PLC may observe the E-stop for HMI status, but must never be in the path that removes power.
Gotchas
- 1501/1502 are still in the series but are obsolete methodology. People cite them because they’re the older numbers and appear first.
- Standards Australia paywall: ~AU$200–400 per part, ~AU$1,500+ for the 26-part set. Free reading access exists via some public libraries and via Engineers Australia membership.
- A brownfield PLC upgrade re-opens the compliance question. Touching the safety-related parts of the control system means the assessment must be redone, whether the project scope said so or not.
- Machine-specific (Type C) parts override the general (Type A/B) parts where they conflict. If AS 4024.3001 says something about presses, it wins over 1201.
- CE marking is not compliance in Australia. An EU Machinery Directive DoC is strong evidence but doesn’t discharge your s.22 WHS duty — the Australian modifications and local risk context still apply.
- A gap worth knowing: electro-sensitive protective equipment (light curtains, laser scanners) is covered by IEC 61496, not by a 4024 part. Approach-speed calculation (ISO 13855) likewise has no direct 4024 equivalent in the current list — you reference the ISO document.
If you’re doing this for real
Sequence: risk assessment to 1201 with a documented hazard register → determine PLr per safety function → write a safety requirements specification naming each function, its PLr, its stop category and its reaction time → design and verify in SISTEMA → build → validate by fault injection to 1502 → file the technical file and issue a compliance statement.
The technical file is the deliverable that matters. If an inspector or a plaintiff’s expert arrives, “we did a risk assessment” without the register, the PL calculations, and the validation test records is indistinguishable from having done nothing.