REQUEST FOR QUOTE → Request a quote
SpecForge Editorial Team

Guard Locking for Personnel vs Process Protection: ISO 14119 Decision Map

Table of Contents
  1. Two Locking Principles, Two Safety Cases
  2. Conditional vs Unconditional Unlocking
  3. Device Type 1-4 Coding and Tamper Resistance
  4. Decision Matrix: Personnel vs Process Locking
  5. Integration With the Safety Control System
  6. Common Failure Modes and Misapplications
  7. Documentation and Standards Trail
Guard Locking for Personnel vs Process Protection: ISO 14119 Decision Map

Guard locking falls into two distinct engineering regimes under EN ISO 14119: a spring-applied, power-to-release (closed-circuit) or bistable lock with conditional unlocking for personnel protection, and a power-to-lock (open-circuit) magnetic lock with unconditional unlocking for process protection [S2][S4].

The selection pivots on a single arithmetic comparison: if the time an operator needs to open the guard and reach the hazard is shorter than the machine stopping time, safe guard locking for personnel is mandatory; if the access time is longer, process locking suffices [S2][S3].

Two Locking Principles, Two Safety Cases

EN ISO 14119 recognizes four physical arrangements but the safety argument collapses them into two operating principles [S4]. Closed-circuit current principle: a spring drives the bolt into the locked position, and energizing a solenoid retracts it; loss of power keeps the door locked. Open-circuit current principle: a solenoid (or permanent magnet plus solenoid) holds the bolt against a spring; loss of power releases the door. Bistable is treated as a closed-circuit variant because the lock state does not change on power removal [S2][S4].

Closed-circuit designs up to PL c are standard, and PL d is reachable with fault exclusion such as a mechanically secured safety bolt [S2]. Open-circuit magnetic locks cannot deliver conditional unlocking because the magnet cannot hold against a stop command, which is exactly why they are confined to process protection [S3][S4].

Conditional vs Unconditional Unlocking

Conditional unlocking requires the safety controller to verify that hazardous functions have stopped (safe torque off, zero speed, brake set) before releasing the bolt; unconditional unlocking releases on operator demand and the resulting guard-open event then generates the stop command [S2][S4].

Unconditional unlocking is acceptable only when the time from guard release to the operator reaching the danger zone exceeds the machine run-down time. DIN EN 415-5:2010-04, section 5.2.2.1.7, uses a one-second stop time as the packaging-machine threshold below which process locking is usually adequate [S3]. For personnel protection, dual-channel OSSD outputs must be used, with short-circuit detection that shuts outputs down without allowing unintended gate opening even under fault [S2].

Device Type 1-4 Coding and Tamper Resistance

guard locking for personnel protection vs process protection - Device Type 1-4 Coding and Tamper Resistance
guard locking for personnel protection vs process protection - Device Type 1-4 Coding and Tamper Resistance

EN ISO 14119 classifies interlocking devices into four types by actuation principle and coding level [S2]. Type 1 is mechanical, uncoded; Type 2 is mechanical, coded; Type 3 is non-contact (e.g. inductive), uncoded; Type 4 is non-contact, coded (typically RFID). Types 1 and 3 require additional manipulation protection because a simple magnet or screwdriver can defeat them [S2].

High-level coded actuators (Type 2/Type 4 with RFID, e.g. 1-of-many or unique code per ISO 14119 coding levels) are the baseline for personnel-protection applications where the standard is enforced strictly, because each actuator has an individual signature that defeats the bypass magnet trick [S1][S2]. In brownfield retrofits on packaging lines, mechanical Type 2 with a coded tongue remains common because it tolerates misalignment and washdown better than inductive Type 3.

Decision Matrix: Personnel vs Process Locking

The four decision criteria a specifier needs on a single page are: locking principle, unlocking behaviour, performance level, and dual-channel OSSD [S2][S3][S4]. Compare them side by side below.

Locking principle: personnel protection uses spring-applied, power-to-release (closed-circuit) or bistable; process protection uses power-to-lock (open-circuit) electromagnet. Unlocking behaviour: personnel protection is conditional on a verified safe stop; process protection is unconditional on operator request. Performance level: PL c minimum, PL d with fault exclusion for personnel; PL d or higher is typical where ISO 13849-1 risk assessment requires it, while process locks are often treated as non-safety SRP/CS since the safety function is upstream. Dual-channel OSSD: mandatory for personnel protection with short-circuit detection; not required for process-only magnetic holders [S2][S3][S4].

Rule of thumb on the access-time arithmetic: when access time minus stopping time yields a positive buffer, process locking is acceptable; when it is negative, only conditional-unlocking personnel locks satisfy EN ISO 14119, and the system must reach a defined safe state before the bolt retracts [S2][S3].

Integration With the Safety Control System

guard locking for personnel protection vs process protection - Integration With the Safety Control System
guard locking for personnel protection vs process protection - Integration With the Safety Control System

Guard locking for personnel protection is part of the safety-related parts of control systems (SRP/CS) covered by ISO 13849-1, so the lock's lock/unlock feedback contacts, door-position contacts, and the solenoid driver all roll into the same Performance Level calculation [S1]. The safety controller must explicitly drive the unlock command, and a single-fault tolerant architecture (Category 3 or 4 per ISO 13849-1) is the usual baseline for PL d [S1].

OSSD (output signal switching device) test pulses are required to detect cross-wiring and short circuits on the lock outputs, and a single OSSD pulse must not release the bolt; pulse widths of a few hundred microseconds are filtered out by the lock's solenoid driver, so the interlock stays physically engaged even if a channel drops [S2]. On brownfield retrofits, electromechanical locks with mechanical-coded actuators and separate force-guided position contacts are easier to validate against legacy wiring than RFID Type 4, which often needs a dedicated safety bus or safety over EtherCAT/PROFIsafe gateway.

Common Failure Modes and Misapplications

Operator bypass with a separately sourced magnet remains the single most common defeat on inductive Type 3 systems; the fix is either a coded Type 4 RFID actuator or a high-level coded mechanical actuator with a unique physical key pattern [S1][S2]. A second frequent error is specifying an open-circuit magnetic lock where the stop time of the connected hazard exceeds the access time, which the standard explicitly forbids because the door can release mid-run-down after a power dip [S3][S4].

Misalignment failures on mechanical Type 1/2 locks show up as nuisance trips after thermal growth or door sag; the practical fix is a tolerance analysis at the design stage plus periodic proof-test intervals of typically six to twelve months depending on the PL target and operating cycles per ISO 13849-1 service-life graphs [S1]. Stacking a process lock and a personnel lock on the same guard is a recurring misapplication, because two locks in series defeat the conditional-unlocking logic, and the safety controller will not be able to verify which bolt is actually engaged.

Documentation and Standards Trail

guard locking for personnel protection vs process protection - Documentation and Standards Trail
guard locking for personnel protection vs process protection - Documentation and Standards Trail

The primary normative references are EN ISO 14119:2014 (interlocking devices associated with guards, Type-B2 standard) and ISO 13849-1:2023 (safety-related parts of control systems, including PL a-e and Categories B, 1, 2, 3, 4), with DIN EN 415-5:2010-04 governing packaging-machine stop-time assumptions [S2][S3][S4]. For packaging lines, DIN EN 415-5:2010-04, section 5.2.2.1.7, anchors the one-second stop-time rule used to decide between process and personnel locking [S3].

For an applied look at how a guard-locking decision rolls into a wider safety architecture, the locking assembly basics reference lays out the mechanical and electrical interfaces you have to coordinate. Adjacent process-control decision logic is covered in the process control overview, and the motor protection relay encyclopedia entry is the right cross-reference when the stop signal must also drop a drive contactor before unlocking.

Trackable signals over the next two quarters: any revision of EN ISO 14119 affecting the Type 1-4 coding levels, the packaging-machine stop-time rule under the next DIN EN 415-5 maintenance cycle, and how RFID-coded Type 4 locks are being qualified against the ISO 14119 high-level coding test vectors. Related reading on adjacent industrial safety hardware is in this guard locking versus process locking decision guide and the Pilz safety locking device definition.

This topic is covered further in Ejector vs Tipping Body for Low Overhead: 2026 Spec Map.

Frequently asked questions

What locking principle does EN ISO 14119 require for personnel-protection guard locking?

Personnel-protection guard locking under EN ISO 14119 requires a spring-applied, power-to-release (closed-circuit) or bistable lock with conditional unlocking. Power-to-lock open-circuit magnetic locks are confined to process protection because they cannot hold against a stop command and therefore cannot deliver conditional unlocking.

What is the access-time arithmetic that determines whether process locking is acceptable?

If the time an operator needs to open the guard and reach the hazard is longer than the machine stopping time, process locking suffices; if access time is shorter, safe guard locking for personnel with conditional unlocking is mandatory. DIN EN 415-5:2010-04, section 5.2.2.1.7, uses a one-second stop time as the packaging-machine threshold below which process locking is usually adequate.

What performance level can a closed-circuit guard lock reach under ISO 13849-1?

Closed-circuit (spring-applied, power-to-release) designs up to PL c are standard, and PL d is reachable with fault exclusion such as a mechanically secured safety bolt. A single-fault tolerant Category 3 or 4 architecture per ISO 13849-1 is the usual baseline for PL d, with dual-channel OSSD outputs and short-circuit detection mandatory.

When are high-level coded Type 2 or Type 4 actuators required instead of Type 1 or Type 3?

Type 1 (mechanical, uncoded) and Type 3 (non-contact, uncoded, e.g. inductive) devices require additional manipulation protection because a simple magnet or screwdriver can defeat them. High-level coded actuators — Type 2 mechanical-coded or Type 4 RFID with 1-of-many or unique coding per ISO 14119 — are the baseline for personnel-protection applications where strict enforcement applies.

5 sources
  1. Guard Locking and ISO 14119: Getting It Right (Dec 17, 2025)
  2. Definition of safety locking device
  3. Did you know...? | Process Guard Locking & Safety Guard ...
  4. EN ISO 14119 | Interlocking Devices Associated with Guards
  5. Guardlocking vs. interlocking: When do you need which?

Need to source matching manufacturers or get a quote?

SpecForge connects industrial buyers with verified manufacturers. Submit your requirement and we will route it to matched suppliers.

Submit RFQ now →
Ask SpecForge AI