Functional Safety Management of the development process of safety related programmable electronic systems at Jaquet Technology Group Document type: Certification Report Client: Jaquet Technology Group Ltd Project: FSM 61508 Process Certification Authors(s): dr.ir. Michel Houtermans Verifier(s): Dipl.-Ing. Wolfgang Velten-Philipp Report number: 103.209.07 Status: Released Version: 2 Date: 2015-04-29
2015 Risknowlogy. All Rights Reserved. LIMITATION OF LIABILITY - This report was prepared using best efforts. Risknowlogy does not accept any responsibility for omissions or inaccuracies in this report caused by the fact that certain information or documentation was not made available to us. Any liability in relation to this report is limited to the indemnity as outlined in our Terms and Conditions. A copy is available at all times upon request. This document is the property of, and is proprietary to Risknowlogy. The client has the right to duplicate this document in whole and to distribute it in whole. Third parties do not have the right to disclose in whole or in part and no portion of this document shall be duplicated by any third party in any manner for any purpose without Risknowlogy s expressed written authorisation. Risknowlogy, the Risknowlogy logo, Functional Safety Data Sheet, SILComp and Spurious Trip Level are registered service marks of Risknowlogy, STL is a Risknowlogy trademark. Report 103.209.07 - Version 2 Released Page 2 of 13
Version Control Version Date Author(S) Reviewer(S) Description 0 2015-04-20 MH WVP Draft release 1 2015-04-27 MH WVP Textual changes 2 2015-04-29 MH WVP Released Report 103.209.07 - Version 2 Released Page 3 of 13
Table of Contents Parties 5 About Jaquet Technology Group 5 About Risknowlogy 5 Terms and Definitions 6 1. Project Description 7 1.1. Purpose 7 1.2. Basis of audit 7 1.3. Audit scope 7 1.4. Audit location 7 2. Audit Process and Results 8 2.1. Audit process 8 2.2. Audit results 8 2.3. Quality Management System 8 2.4. Lifecycle requirements 9 2.5. Documentation requirements 10 2.6. Functional safety management 10 2.7. Measures to avoid and control failures 11 2.8. Configuration management 11 2.9. Verification 11 2.10. Assessment (audits) 11 2.11. Modifications 11 2.12. Suppliers 11 3. Conclusions 12 3.1. Functional safety management audit 12 3.2. Project audit 12 3.3. Restrictions 12 3.4. Conclusions 12 References 13 Report 103.209.07 - Version 2 Released Page 4 of 13
Parties About Jaquet Technology Group JAQUET Technology Group is a global engineering and manufacturing company, specialised in providing speed sensors, and complete system solutions in demanding ambient conditions. Their main markets are automotive, power generation, railway, marine, mobile hydraulics and industrial machinery. About Risknowlogy Risknowlogy was founded in 2002 and is an employee owned business. We offer products, services, engineering, consulting, certification and training in the field of risk, reliability and safety. Our offices are located in Argentina, Colombia, Germany, France, India, The Netherlands, Switzerland (HQ), the United Arab Emirates, United Kingdom, and Uruguay. Report 103.209.07 - Version 2 Released Page 5 of 13
Terms and Definitions Term Definition SIL Safety Integrity Level STL Spurious Trip Level FSM Functional Safety Management Jaquet Jaquet Technology Group Ltd FT3000 series FT3000, FT3100, FT3200, FT3300 QMS Quality Management System Report 103.209.07 - Version 2 Released Page 6 of 13
1. Project Description 1.1. Purpose The purpose of this report is to document the certification of the Functional Safety Management (FSM) system implemented by the development department of the Jaquet Technology Group (Jaquet) company located in Basel, Switzerland. 1.2. Basis of audit The following standard(s) have been used as basis for the audit: IEC 61508:2010 - Functional Safety of Electrical / Electronic / Programmable Electronic Safety Related Systems [1] 1.3. Audit scope The scope of the audit is the implementation of FSM requirements, according to the basis for audit, for the development process of the safety related programmable electronic systems at Jaquet. The audit scope addresses the existence of the correct FSM system. The audit addresses the following FSM topics: Documentation; Functional Safety Management; Lifecycle; Functional safety assessment. 1.4. Audit location The FSM system subject to this audit is applicable to the following location(s): Jaquet Technology Group Ltd Development department Basel Switzerland Report 103.209.07 - Version 2 Released Page 7 of 13
2. Audit Process and Results 2.1. Audit process The certification of the Functional Safety Management system at Jaquet is based on a FSM audit. During the audit all requirements related to FSM of part 1, 2 and 3 of IEC 61508:2010 [1] are addressed and include: Documentation requirements; Functional Safety Management requirements; Lifecycle requirements; Modification requirements; Verification requirements; Functional safety assessment requirements. 2.2. Audit results The actual FSM audit took place from 4-6 March 2015 at the Development Department of Jaquet in Basel, Switzerland. The FSM audit documented the results for all FSM requirements existing in IEC 61508:2010 [1] using the GAP analysis checklist [2,3,4]. Those requirements for which approved evidence was collected during the FSM audit were closed during the meeting. Jaquet used the GAP analysis checklist for those requirements where at the time of the FSM audit not sufficient evidence was provided and later provided the supporting evidence. Risknowlogy reviewed the new evidence and came to the conclusion that all requirements are appropriately addressed by Jaquet s FSM system. 2.3. Quality Management System Jaquet s FSM system is fully integrated with their Quality Management System (QMS). The QMS is ISO 9001 certified [5]. The QMS certification is valid and includes the development process at Jaquet. Report 103.209.07 - Version 2 Released Page 8 of 13
2.4. Lifecycle requirements The basis for any FSM system is a lifecycle that demonstrates the applicable phases over the life of the safety related system. The lifecycle is the guiding principle for any activities related to FSM. Jaquet has documented their product development lifecycle in [6], which is shown in the figure below. This lifecycle is different form the lifecycle in IEC 61508:2010 [1] and is adapted to represent the specific work carried out by Jaquet related to hardware and software of safety-related system projects. Jaquet has defined for each phase of the lifecycle the activities in terms of the scope of the phase, the required input and output documentation, and where applicable who is responsible for the work, verification and assessment (audits). Risknowlogy has reviewed the lifecycle and concluded that it represents all requirements of IEC 61508:2010[1] as applicable to the scope of work carried out by Jaquet. The lifecycle presented by Jaquet is further used to verify the requirements of the basis for audit in this report. Report 103.209.07 - Version 2 Released Page 9 of 13
2.5. Documentation requirements The documentation requirements in the basis for audit consist of formal requirements and lifecycle based documentation requirements, which are partially project dependent. Any documentation created on a project related to functional safety needs to follow the requirements defined in the online documented Quality Management System [7]. The formal requirements in the Quality Management System correspond with the requirements of the basis for audit. Furthermore Jaquet creates a separate set of documentation (templates and forms) that follows the lifecycle defined in [6]. These documents are used as basis for each specific development project at Jaquet. It is the conclusion of Risknowlogy that the documentation required on a per project basis corresponds with the requirements of the basis for audit. 2.6. Functional safety management The goal of Functional Safety Management is to define all technical and managerial activities and to make people, departments and organisations responsible for these activities. FSM applies to all lifecycle phases and addresses for each project and phase the following aspect: Policy and strategy for achieving functional safety; People and their competencies, roles and responsibilities; Recommendations related to safety-related systems; Measures to avoid and control failures; Configuration management Verification Assessment and audits Modifications Suppliers Jaquet has defined the policy and strategy in [6], which is communicated to any employee, supplier and clients with responsibility on a particular functional safety project. All employees with responsibility for safety related work are selected based on their role and competence. Human resources at Jaquet has competence record for each employee and where needed identified the need for additional internal or external training. The roles and responsibilities, including the competency are documented in [6,8]. Jaquet and it supplier are only responsible for product development. Any feed back from users related to (repeat) hazard and risk analysis, verification and validation activities, operation, maintenance, and repair influencing the product developed by Jaquet, and for which Jaquet is (made) responsible, leads to customer change request [9] which triggers the modification procedure [10] when applicable. Report 103.209.07 - Version 2 Released Page 10 of 13
2.7. Measures to avoid and control failures Measures to avoid failures are part of the quality assurance and FSM system implemented at Jaquet. The measures selected by Jaquet have been verified for correctness and completeness and are suitable up to systematic capability SIL 3 [6]. The measures to control failures are project dependent. 2.8. Configuration management Jaquet is responsible for configuration management of the hardware and software of their products including hardware and software delivered by suppliers. Configuration management is carried out according to the configuration management procedures of the supplier and clear communication channels are defined in the Safety Management Plan [6]. 2.9. Verification For each activity defined in the applicable lifecycle Jaquet carries out independent verification via the verification plan [11]. 2.10. Assessment (audits) Jaquet has sufficient experience with the designs and technologies they implement. They can perform independent assessments and audits up to SIL 3 according to IEC 61508. If the assessments are carried out by an independent external party then they are responsible for applicable assessment procedures. For SIL related projects Jaquet selects an external independent third party. If Jaquet performs their own assessments and audits then they are performed according to the assessment and audit procedures [6,12]. 2.11. Modifications Any changes related to lifecycle phases that have been carried out, verified, and assessed already will follow the modification procedure [10]. 2.12. Suppliers On per project basis Jaquet can decide to outsource parts of or the complete development process. The purchasing and delivery of hardware/software/services are performed according to the Quality Manual System [7] and communication and interfaces between Jaquet and suppliers are clearly defined in Safety Management Plan [6]. Report 103.209.07 - Version 2 Released Page 11 of 13
3. Conclusions 3.1. Functional safety management audit Risknowlogy has audited the FSM system implemented by Jaquet. The review focused on the correctness of the FSM system in relation to the basis for audit. The results of the audit were positive. 3.2. Project audit Risknowlogy has verified the implementation of Jaquet s FSM system for the development process of the FT3000 and ST100 product series according to the basis of audit. 3.3. Restrictions This certification is valid under the following restriction(s): Any future modifications made need to follow the modification procedure and modification request form [9] according to the FSM system in place and the requirements of the at the time of the modification valid version of IEC 61508. Any suppliers used by Jaquet that take responsibility for one more phases of the development lifecycle need to deliver their products/services with independent functional safety certification issued by a third party approved by Jaquet according to the at that time valid version of IEC 61508 and other standards as specified by the safety requirements specification written by Jaquet. 3.4. Conclusions It is the conclusion of Risknowlogy that after examining the Functional Safety Management system that Jaquet Technology Group has the people and organisation in place that can perform development work up to SIL 3 according to the basis of audit. dr.ir. Michel Houtermans Author Dipl.-Ing. Wolfgang Velten-Philipp Verifier Report 103.209.07 - Version 2 Released Page 12 of 13
References 1. IEC 61508:2010 - Functional Safety of Electrical / Electronic / Programmable Electronic Safety Related Systems; 2. Risknowlogy, IEC 61508-1 FSM GAP Analysis. Report number 103.209.02, version 1, 2015-04-11; 3. Risknowlogy, IEC 61508-2 FSM GAP Analysis. Report number 103.209.03, version 1, 2015-04-11; 4. Risknowlogy, IEC 61508-3 FSM GAP Analysis. Report number 103.209.04, version 1, 2015-04-11; 5. TUV SUD, ISO 9001 Certificate 12 100 43277 TMS, 2014-07-29 6. Jaquet, Safety Management Plan, QM 7.F86. Revision 2, 2015-04 7. Jaquet, Policies, procedures, forms and guiding documents integrated in the ISO 9001 certified online documented Quality Management System. 8. Jaquet, Skill Matrix QM 6.F51. Revision 0, 2013-12 9. Jaquet, Corrective Action Report (CAR), QM 8.F28. Revision 5, 2012-12 10. Jaquet, Änderungslaufzettel, QM 6.F38, revision 07, 2015-03 11. Jaquet, V&V Plan, QM 7.F85. Revision 1, 2015-01 12. Jaquet, Auditbericht, QM 8.F3. Revision 2, 2013-08 Report 103.209.07 - Version 2 Released Page 13 of 13