Building Safer Motor Drives—Part 1: STO Safety Architectures
August 18, 2026
Blog
Functional safety is a fundamental requirement for motor drive systems, as these devices directly control mechanical energy capable of causing serious harm in the event of a fault. In industrial applications such as robotics, manufacturing, and material handling, motor drives must reliably transition to a defined safe state under fault conditions including emergency stops, control failures, or maintenance access. In accordance with IEC 61800-5-2, drive-integrated safety functions such as safe torque off (STO) are intended to prevent torque-producing power from being delivered to the motor whenever a safety demand occurs.
This two-part article series presents a practical, standard-aligned approach to the design and justification of safety-related power drive systems (PDS(SR)). Together, the articles provide engineers with a coherent blueprint for designing, validating, and certifying high-integrity motor drive safety systems while reducing certification risk and time to market.
Introduction
Functional safety is critical for motor drives because these systems directly control mechanical energy capable of causing serious injury, equipment damage, or process disruption if a fault occurs. In industrial environments such as manufacturing, robotics, and material handling, motor drives must reliably transition to a safe state under defined fault conditions, including emergency stops, maintenance access, or control system failures.
In motor drive systems, functional safety focuses on ensuring that defined drive-based safety functions perform reliably and predictably in response to hazardous conditions. In accordance with IEC 61800-5-2, functional safety provides confidence that the motor drive will transition the motor to a safe state—for example, by removal of the torque-producing power, controlled stopping, or safe motion limitation whenever a safety demand occurs.1
There are three key considerations for the design and development of the safety-related system for motor drive application: systematic integrity, architectural constraints, and the system behavior on detection of a fault.
Systematic integrity addresses risks associated with the design and development of safety-related systems by applying techniques and measures that reduce the likelihood of introducing systematic failures through deficiencies in design methodology and quality management.
Architectural constraints for safety-related power drive systems (PDS(SR)) require that the hardware architecture of the motor drive system provides a defined level of fault tolerance and diagnostic capability consistent with the claimed safety integrity level (SIL) or performance level (PL).
Fault detection is implemented in PDS(SR) such that dangerous faults are detected within a sufficient timeline to allow the safety function to transition the motor drive system to a safe state. The faults are detected through continuous or periodic diagnostics of the safety-related hardware, signal paths, and outputs; this may include monitoring of discrepancies, loss of function, and internal failures.
This two-part article series presents a practical, standards-aligned approach to functional safety in motor drives, addressing both system architecture and component-level justification.
- Part 1 will focus on architectural constraints and fault detection required to implement STO safety function for a motor drive safety concept targeting an SIL 3/PLe in accordance with IEC 61800-5-2, IEC 62061, and ISO 13849-1. The discussion links circuit-level design choices to key safety metrics, and an SIL-ready development flow that reduces certification risk and time to market.
- Part 2 focuses on fault exclusion across isolation barriers, clarifying how isolation specifications can be translated into defensible safety claims within functional-safety frameworks. Together, these topics provide engineers with a coherent blueprint for designing, justifying, and certifying safety-critical motor drive systems.
Safe Torque Off—Safety Function
The STO safety subfunction is typically triggered by a safety event, such as the activation of an emergency-stop push button. The STO function, as defined in IEC 61800-5-2, “prevents force-producing power from being provided to the motor.”1 This is generally achieved through pulse blocking or power removal at the gate-driver stage of the motor drive circuit. As illustrated in Figure 1, when the STO safety function is activated, the MOSFETs or insulated gate bipolar transistors (IGBTs) in the inverter stage are turned off, ensuring that no current flows into the motor phases. As a result, the motor coasts to a stop through uncontrolled deceleration, as defined by stop category 0 in accordance with IEC 60204-1.2

Figure 1. IEC 61800-5-2 safe torque off (STO) concept.
The STO safety function is designed to operate in the presence of a single fault; this requires the safety circuit to be implemented with hardware fault tolerance equal to 1. This provides hardware redundancy with appropriate diagnostics to detect faults. The redundancy ensures that a single fault does not compromise the safety function, where diagnostic mechanisms allow the system to detect and respond to failures.

Figure 2. Dual-channel architecture with feedback with the MAX22256, ADuM4122, ADuM320N, and MAX7301.
Motor Drive Safety Concept Circuit
Figure 2 details a motor drive safety concept circuit to implement STO safety function with dual-channel architecture with feedback. The design provides two independent safety paths, STO A and STO B, ensuring that a single fault does not compromise the safety function. STO A disables torque generation by removing the pulse-width modulation (PWM) signals driving the isolated gate drivers, directly preventing switching of the inverter power devices. In parallel, STO B acts on a separate path by disabling the transformer driver, which removes power from both the gate driver and the digital isolator’s secondary-side supply (VDD2). When VDD2 is removed, the digital isolator is forced into a known, safe default state, ensuring that gate-drive commands cannot be unintentionally asserted.
The design also incorporates diagnostic feedback, which is essential for safety validation and fault detection. By monitoring the default logic state of the digital isolator when STO B is active, the system can assess the state of the safety path for each motor phase (U, V, and W). This feedback mechanism enables detection of failures within the STO circuitry itself, supporting the diagnostic coverage required for high-integrity functional-safety claims.
Motor drive safety functions such as STO operate in high-demand or continuous mode, so the key safety metrics of the system are probability of failure per hour (PFH), safe failure fraction (SFF), and hardware fault tolerance (HFT).
PFH represents the probability per hour that the driver’s safety function fails to transition to a safe state on demand. For the individual safety functions, the PFH should be equal to or less than the target measure shown in Table 1. Therefore, an SIL 3 safety function will have a PFH figure of 10-7 per hour.

The redundant architecture shown in Figure 2 combines HFT and diagnostic coverage to meet the architectural constraints of IEC 615083 and IEC 61800-5-2. Redundant safety channels provide tolerance to single hardware faults, while integrated diagnostics increase the SFF by detecting dangerous failures and initiating a safe state. Table 2 illustrates that the highest SIL is limited by the HFT and SFF, for a type B subsystem that is restricted to SIL 3 and HFT = 1 with a minimum SFF equal to or greater than 90%.

The probability of faults at component level may prevent the correct operation of the safety function. Several risk reduction techniques may be applied to reduce failures at a component level, including selecting reliable components and fault exclusions. Both ISO 13849-2:20124 and IEC 61800-5-2 provide a list of fault exclusions that can be considered. Any such fault exclusions require clear justification and documentation; an example is a short circuit across the isolation barrier of a signal isolation component (IEC 61800-5-2 Annex D) used within the drive.
The systematic integrity of the STO safety function is ensured through the application of recognized safety lifecycle and design measures to prevent systematic failures during the design and development of the hardware. Lifecycle covers the systematic activities required for planning, safety requirements specification, design, implementation, integration, and validation of safety subfunction for motor drive applications. IEC 61800-5-2 defines a product-specific functional safety lifecycle for PSD(SR) applications, aligned with the IEC 61508 framework.
The key outcome of this approach is the ability to deliver an application compliant with the current state-of-the-art safety standards. This enables customers to integrate a pre-validated safety solution into their own motor drive systems with significantly reduced certification risk, engineering effort, and time to market, while maintaining confidence in functional-safety compliance.
Isolation Solutions in STO Architectures
Galvanic isolation is a foundational enabler in modern motor-drive safety architectures, particularly for STO implementations where safety-related control signals must be reliably separated from hazardous power domains. In inverter-based drives, isolation provides electrical separation between low-voltage control and diagnostic circuitry and the high-voltage switching environment of the power stage. This separation protects safety-related electronics while supporting deterministic behavior when transitioning to a defined safe state.
Within STO architectures, isolation is not a safety function, nor is it independently certified for functional safety. Instead, isolation forms part of a broader system-level safety concept that
combines redundancy, diagnostics, and safety-related logic to achieve the targeted safety performance. Safety integrity levels such as SIL 3 or PLe are therefore properties of the complete architecture, not of individual components.
A critical requirement for isolation in STO applications is predictable behavior under loss of power or fault conditions. In the two-channel architecture described earlier, removal of the secondary-side supply forces the isolated interface and downstream gate-drive circuitry into a known nonconducting state. This deterministic response ensures that torque-producing signals cannot be asserted unintentionally, even if faults arise within the control domain, supporting the definition of a verifiable safe state.
Isolation also enables effective system-level diagnostics. By allowing safety-related logic to monitor the default state of isolated signals when STO paths are asserted, conditions such as stuck-at faults, loss of drive capability, or power-domain failures can be detected. While isolators do not provide diagnostics autonomously, their defined behavior under power loss enables diagnostic coverage to be implemented at the architectural level.
In addition, isolation improves robustness against common motor drive disturbances such as high dv/dt switching, large common-mode transients, and electromagnetic interference. Isolation barriers with strong transient immunity and controlled propagation characteristics help maintain deterministic signal behavior under these conditions, reducing the risk of noise-induced malfunction. Table 3 provides a summary of key isolation specifications applicable to motor drive applications, including common-mode transient immunity (CMTI).

Within functional-safety frameworks, isolation characteristics are treated as supporting evidence rather than automatic justification. Electrical ratings and insulation behavior must be assessed in the context of the overall safety concept. The structured justification of fault exclusion across isolation barriers is addressed in Part 2 of this article series.
Conclusion
This article has shown that achieving high-integrity STO in modern motor drives is primarily an architectural exercise: the safety function must reliably prevent torque-producing power from reaching the motor whenever a safety demand occurs, resulting in an uncontrolled stop consistent with stop category 0. A dual-channel STO concept, implemented with independent shut-down paths and verified through feedback diagnostics, provides the hardware fault tolerance (HFT = 1) and diagnostic capability needed so that single faults do not defeat the safety function while also improving SFF and reducing the PFH to the levels required for SIL 3/PLe. Galvanic isolation is an important enabler within this concept because it separates hazardous power domains from safety-related control and diagnostic circuitry and can support deterministic behavior under power-loss conditions; however, isolation remains supporting evidence rather than a standalone safety function. The structured justification of fault exclusion across isolation barriers—and how isolation specifications can be translated into defensible safety claims within functional-safety frameworks—is addressed in Part 2.
References
1IEC 61800-5-2 Adjustable Speed Electrical Power Drive Systems—Part 5-2: Safety Requirements—Functional. April 2016.
2IEC 60204-1 Safety of Machinery—Electrical Equipment of Machines. Part 1: General Requirements. October 2016.
3IEC 61508 Functional Safety of Electrical/Electronic/ Programmable Electronic Safety-Related Systems. April 2010.
4ISO 13849-2:2012 Safety of Machinery. Safety-Related Part of Control Systems Validation. October 2012.
