AS 4024

AS/NZS 4024 is the Australian/New Zealand “Safety of machinery” standards series — not one document but a family of parts, each an adoption (usually modified) of an ISO or EN machine-safety standard. The current series contains 26 parts based on European (EN) and ISO safety and design standards, with modifications for Australian conditions, and the 4024.1 series was revised and published in August 2019, superseding the 2014 versions.
Author

Benedict Thekkel

Series map

Part Subject Underlying standard
1100:2019 Application guide — start here
1201:2014 General principles for design — risk assessment and risk reduction ISO 12100
1204:2019 Electrical equipment of machines IEC 60204-1:2016 (MOD)
1302:2019 Hazardous substances emitted by machinery
1303:2014 Risk assessment — practical guidance and example methods ISO/TR 14121-2
1401:2014 Ergonomic principles for design ISO 26800
1501-2006 (R2014) SRP/CS — general principles for design ISO 13849-1:1999 (categories)
1502-2006 (R2014) SRP/CS — validation ISO 13849-2
1503:2014 SRP/CS — general principles for design ISO 13849-1:2006 (PL)
1601:2014 Guards — fixed and movable, design and construction ISO 14120
1602:2014 Interlocking devices associated with guards ISO 14119
1603:2019 Prevention of unexpected start-up ISO 14118
1604:2019 Emergency stop — principles for design ISO 13850
1701–1704 Human body measurements, access openings, anthropometric data ISO 15534 / 7250
1801:2014 Safety distances — upper and lower limbs ISO 13857
1803:2019 Minimum gaps to prevent crushing ISO 13854
1901–1907 Displays, controls, actuators, signals; marking; auditory/visual warnings ISO 9355 / IEC 61310

Machine-specific parts sit in the 3xxx range: AS 4024.3001:2021 and 3002:2021 for presses, AS 4024.3101 for milling and boring machines, and conveyors — formerly AS 1755-2000 — now under AS/NZS 4024.3610, .3611, .3612 and .3614.

The 1501/1502 vs 1503 trap

Both live in the series simultaneously, and they encode two incompatible design methodologies:

  • 1501/1502 (2006, reconfirmed 2014) — the old EN 954-1 approach. Purely architectural: pick Category B, 1, 2, 3 or 4 from a risk graph. No reliability data, no probabilistic assessment.
  • 1503:2014 — the modern ISO 13849-1:2006 approach. Performance Level PLa–PLe, which combines architecture plus component reliability and diagnostics.

Use 1503. Category-only design was withdrawn internationally in 2011 because it lets you build a Category 3 circuit out of junk components and call it safe. If a supplier quotes you “Category 3” with no PL, they’re working from a 20-year-old mental model — push back.

How 1503 / ISO 13849-1 actually works

Step 1 — Determine required Performance Level (PLr) per safety function, via the risk graph:

  • S severity: S1 slight/reversible, S2 serious/irreversible or death
  • F frequency/duration of exposure: F1 seldom, F2 frequent/continuous
  • P possibility of avoidance: P1 possible under specific conditions, P2 scarcely possible

S2 + F2 + P2 → PLe. Guarded pinch point with occasional access → typically PLd. A jam-clearing operation on a hydraulic press is PLe every time.

Step 2 — Design to hit it. PL is a function of four inputs:

  • Category (B, 1, 2, 3, 4) — the architecture. Cat 3 = dual channel, single fault tolerant, most faults detected. Cat 4 = dual channel, all faults detected or accumulated faults don’t cause loss of function.
  • MTTFd — mean time to dangerous failure, per channel: Low (3–10 yr), Medium (10–30 yr), High (30–100 yr). Capped at 100 years regardless of how good your component is.
  • DCavg — diagnostic coverage: None (<60%), Low (60–90%), Medium (90–99%), High (≥99%).
  • CCF — common cause failure. A checklist scoring ≥65/100 (separation, diversity, over-dimensioning, environmental immunity). Fail it and your dual channel counts as single.

Output is PFHd, probability of dangerous failure per hour. PLd = 10⁻⁷ to 10⁻⁶/h. PLe = 10⁻⁸ to 10⁻⁷/h.

Step 3 — Verify PL achieved ≥ PLr for every safety function, including subsystem combination (two PLd subsystems in series do not give you PLd — combination degrades it).

Step 4 — Validate per 1502: fault injection testing, not just paperwork. Actually open the guard, actually cut one channel, confirm the machine stops and won’t restart.

Use SISTEMA (free, from the German IFA) for the arithmetic. Every reputable component vendor publishes a SISTEMA library with certified MTTFd/B10d figures.

IEC 62061 (adopted as AS 62061) is the parallel route using SIL 1–3 instead of PL. Rough mapping: SIL1≈PLc, SIL2≈PLd, SIL3≈PLe. Pick one framework per machine and stay in it. ISO 13849 is more common for discrete machinery; 62061 for complex electronic architectures. Note the two were merged in ISO 13849-1:2023 internationally — Australia hasn’t adopted that yet, so 1503 remains the 2006 methodology.

Safety distances — the calculation you’ll actually do

From ISO 13855 (approach speed), used with 1801:

S = (K × T) + C
  • S = minimum distance from danger zone to detection plane (mm)
  • K = approach speed, 2000 mm/s for normal approach, 1600 mm/s where S > 500 mm
  • T = total stopping time = detection + safety relay response + PLC/contactor + mechanical run-down. Measure it, don’t take the datasheet value — a worn brake adds hundreds of milliseconds.
  • C = intrusion allowance. For a light curtain: C = 8 × (d − 14), where d = detection capability in mm. A 30 mm resolution curtain gives C = 128 mm.

Worked: 30 mm curtain, 250 ms total stop time → S = 2000 × 0.25 + 128 = 628 mm. That’s a long way back, and it’s why fine-resolution curtains (14 mm, C = 0) and fast-stopping drives earn their cost.

1801 (ISO 13857) is the reach-over/reach-through table set: how high a fence must be for a given danger-zone height, and what gap size lets a finger/hand/arm through at what distance. 1803 gives crushing gaps — ≥ 25 mm for fingers, ≥ 100 mm for an arm, ≥ 500 mm for a whole body.

Points that catch control engineers

Emergency stop (1604 / ISO 13850) is a complementary protective measure, not a safety function you may substitute for guarding. Stop categories per IEC 60204-1:

  • Cat 0 — immediate removal of power. Uncontrolled coast-down.
  • Cat 1 — controlled deceleration, then power removal. Correct for high-inertia loads where Cat 0 would be more dangerous.
  • Cat 2 — controlled stop with power maintained. Not permitted for E-stop.

E-stop must be latching, manually reset, and reset must not itself restart the machine. Red mushroom on yellow background. Wired NC through a direct-opening-action (positive-opening, IEC 60947-5-1 Annex K) contact block so a welded contact still opens mechanically.

Interlocks (1602 / ISO 14119) — the standard’s most cited topic in Australia is defeat resistance. Simple magnetic and tongue switches can be beaten with a spare actuator or a magnet in a pocket, and operators do exactly that. Use coded (RFID-uniquely-coded) switches, or guard locking where run-down time exceeds access time. Mount so the switch isn’t accessible with a screwdriver.

Unexpected start-up (1603 / ISO 14118) — energy isolation, not just a stop command. Covers lockout points, stored energy dissipation (accumulators, capacitors, gravity), and the rule that restoring power after an interruption must not restart the machine.

Electrical equipment (1204 / IEC 60204-1) is the one you’ll live in as an EE: supply disconnection, protective bonding continuity ≤ 0.1 Ω, PELV control circuits, conductor colours (black power, red AC control, blue DC control, orange for circuits energised when the main disconnect is off — that orange rule catches people), enclosure IP rating, and the required test schedule: continuity of protective bonding, insulation resistance ≥ 1 MΩ at 500 VDC, dielectric withstand, residual voltage, functional test.

Implementation, tied to your PLC question

The 4024 requirement translates to hardware like this:

PLr Typical implementation
PLb/PLc Single-channel monitored, or a basic safety relay
PLd Dual-channel safety relay (Pilz PNOZ, Sick UE, Allen-Bradley Guardmaster) with forced-guided feedback loop
PLd/PLe, >4 functions Safety PLC / safety controller: Pilz PNOZmulti, Siemens F-CPU + PROFIsafe, AB GuardLogix + CIP Safety, Beckhoff TwinSAFE

The switchover point is roughly four safety functions or any need for zone logic, muting, or reconfiguration — beyond that, relay wiring becomes unmaintainable and a safety PLC is cheaper.

Safety over fieldbus (PROFIsafe, CIP Safety, FSoE) uses the “black channel” principle: the safety layer adds sequence numbers, CRC, timeouts and a safety-relevant payload wrapper, so the underlying network needs no certification. Your ordinary PROFINET/EtherNet/IP infrastructure carries safety traffic unmodified.

Non-negotiable: standard PLC logic is PLb at best. No amount of clever ladder makes a standard CPU a safety device. Your E-stop must break the safety circuit in hardware or via a certified safety controller — a standard PLC may observe the E-stop for HMI status, but must never be in the path that removes power.

Gotchas

  • 1501/1502 are still in the series but are obsolete methodology. People cite them because they’re the older numbers and appear first.
  • Standards Australia paywall: ~AU$200–400 per part, ~AU$1,500+ for the 26-part set. Free reading access exists via some public libraries and via Engineers Australia membership.
  • A brownfield PLC upgrade re-opens the compliance question. Touching the safety-related parts of the control system means the assessment must be redone, whether the project scope said so or not.
  • Machine-specific (Type C) parts override the general (Type A/B) parts where they conflict. If AS 4024.3001 says something about presses, it wins over 1201.
  • CE marking is not compliance in Australia. An EU Machinery Directive DoC is strong evidence but doesn’t discharge your s.22 WHS duty — the Australian modifications and local risk context still apply.
  • A gap worth knowing: electro-sensitive protective equipment (light curtains, laser scanners) is covered by IEC 61496, not by a 4024 part. Approach-speed calculation (ISO 13855) likewise has no direct 4024 equivalent in the current list — you reference the ISO document.

If you’re doing this for real

Sequence: risk assessment to 1201 with a documented hazard register → determine PLr per safety function → write a safety requirements specification naming each function, its PLr, its stop category and its reaction time → design and verify in SISTEMA → build → validate by fault injection to 1502 → file the technical file and issue a compliance statement.

The technical file is the deliverable that matters. If an inspector or a plaintiff’s expert arrives, “we did a risk assessment” without the register, the PL calculations, and the validation test records is indistinguishable from having done nothing.

Back to top