Safety-Rated Zones and Speed: What FANUC DCS Can and Can't Replace
FANUC Dual Check Safety (DCS) lets a robot controller enforce safety-rated limits on the robot's own position and speed, a kind of soft-axis and space limiting that OSHA's guidance lists beside mechanical limiting devices, but it does not detect people, isolate energy, or replace the cell's risk assessment and guarding. UTEC Industrial designs, engineers, machines, fabricates, and installs custom material handling systems for aerospace and heavy industry from its Spokane Valley, WA facility, integrating Allen-Bradley PLC and motion control with in-house CNC machining, heat treating, and stress relief. This article reads FANUC's DCS operator's manual and OSHA's robot guidance from the customer's side: what each check monitors, its safety rating, how far the robot travels after a limit trips, and which safeguards still have to be built. A heavy robot cell is built along one chain, design → engineering → parts machining → fabrication → assembly → weld fatigue → stress relief → drives → controls → tuning → monitoring, and DCS zones set at the controls link hold only if the gripper, brakes and payload data built upstream match them.
What does FANUC DCS actually monitor, and how?
FANUC's manual says the DCS Position/Speed Check features check the speed and position data of the motors with two independent CPUs in the robot controller and, on a position or speed error, shut down motor power by two independent channels. The position and speed checks need no additional external sensors to monitor speed and position; only the built-in servo motor sensors are used, although safety inputs and outputs need external electrical circuits. FANUC states that DCS functions are certified to meet the requirements of ISO 13849-1 and IEC 61508 by an internationally accredited certification body.
The Position/Speed Check option is made up of these functions, each of which shuts down motor power when its limit is exceeded:
- Joint Position Check: a joint outside its safe zone; up to 40 zones.
- Joint Speed Check: a joint above its speed limit; up to 40 limits.
- Cartesian Position Check: a zone check (shape models on the tool or arm leaving a safe zone; up to 32 zones), an orientation check, and a target model collision check between shape models.
- Cartesian Speed Check: the speed of the DCS tool center point (TCP) above its limit; up to 16 limits.
- T1 Mode Speed Check: TCP or face plate speed above a limit of at most 250 mm/s.
As engineering reasoning, every one of these checks watches the robot, not the people around it. This article reads edition 12 (2021) of the manual for the R-30iB controller family (FANUC B-83184EN/12, 2021, Ch. 1 p. 1 and Ch. 7 pp. 92–93, 98, 102 and 129).
What safety rating do DCS zone and speed checks carry?
In the manual's component table, the Position/Speed Check function is Category 3, PL d, SIL 2, and so are the separate Joint Speed Check and Basic Position Check options. The functions listed at Category 4, PL e, SIL 3 include the standard emergency stop function, Safe I/O Connect, and the DeviceNet Safety, EtherNet/IP Safety and PROFINET Safety network functions. Even within Safe I/O Connect, the manual says some safe I/O are Category 3, PL d, SIL 2 "because the source function is Cat.3, PL d, SIL 2", and the SFDO safety output is Category 4, PL e, SIL 3 only when SFDO pulse check is enabled.
FANUC's own warning sets the condition: when Position/Speed Check is used, "adequate risk assessment for the whole robot system is necessary to verify that a Category 3, PL d, SIL 2 safety function is adequate." The manual's safety index table gives an SFF greater than 99.0 percent and a PFH less than 8.76 × 10⁻⁸ per hour. The controllers are evaluated as a system with the high demand mode of operation defined in IEC 61508, and FANUC asks users to confirm the safety function by inputting an emergency stop, or by cycling power, twice or more a year.
ISO 13849-1:2023 specifies a methodology and provides related requirements, recommendations and guidance for the design and integration of safety-related parts of control systems (SRP/CS) that perform safety functions; it applies to SRP/CS for high demand and continuous modes of operation and does not apply to low demand mode of operation. As engineering reasoning, a cell whose risk assessment sets a required performance level of PL e for a zone-based safety function cannot meet it with a PL d zone check alone, however its output is wired (FANUC B-83184EN/12, 2021, §1.1 pp. 1–4, §1.2.1 p. 4 and §9.1 p. 161; ISO 13849-1:2023).
Where do safety-rated soft limits fit in OSHA's robot guidance?
OSHA states that "There are currently no specific OSHA standards for the robotics industry." Its robotics standards page lists general industry standards related to robotics, including 1910.147 and 1910.212, and says national consensus standards "are NOT OSHA regulations" although they provide guidance.
The OSHA Technical Manual chapter on industrial robots names soft limits directly, saying that limiting the space of a robot application "can also be accomplished with" mechanical limiting devices and "non-mechanical limiting devices, which can include soft-axis and space-limiting safety function(s)." Its definitions set the terms:
- Limiting device: a device that restricts the maximum envelope by stopping or causing to stop all robot motion "and is independent of the control program and the application programs."
- Restricted space: the portion of the maximum envelope to which a robot is restricted by limiting devices, where "the maximum distance that the robot can travel after the limiting device is actuated defines the boundaries." A note to the definition adds that "the safeguarding interlocking logic and robot program may redefine the restricted envelope as the robot performs its application program."
Its example risk assessment, based on RIA TR R15.306-2016, tells the assessor to determine the desired restricted space "considering possible limits such as hard stops, travel limit sensors, safety-rated soft-axis limits, etc." The chapter names ANSI/RIA R15.06-2012; the 2025 edition, ANSI/A3 R15.06-2025, is the U.S. national adoption of ISO 10218 Parts 1 and 2. As engineering reasoning, the restricted-space definition is the point that links OSHA's guidance to DCS: the boundary is where the robot comes to rest after the limit acts, not the line drawn in the zone menu (OSHA Robotics, 2026; OSHA Robotics: Standards, 2026; OSHA Technical Manual, Sec. IV Ch. 4, 2026; ANSI/A3 R15.06-2025).
How far past a DCS zone boundary does a robot travel before it stops?
Farther than the zone line, unless Stop Position Prediction is set up to stop it early. DCS stops the robot by shutting down motor power, and the robot's momentum carries it some distance before it completely stops; FANUC says that distance depends on the type of robot, payload, and speed. The manual gives the stop distance as:
- Stop distance = (Speed × Scan time) + moving distance through momentum
The default scan time is 8 ms, which "might change according to your system configuration", and the checks detect an alarm within a maximum of one scan time. As an illustration with an assumed TCP speed of 2,000 mm/s, the scan term alone is 2,000 mm/s × 0.008 s = 16 mm; the momentum term has to come from FANUC data for the robot model, payload and speed, and the operator's manual gives no per-model figures.
The manual adds delays that the risk assessment must include:
- Stop Category 1: motor power shutdown is delayed for a maximum of 2 seconds.
- Safe I/O Connect: safety signal status could be delayed by a maximum of 2 ms.
- DeviceNet Safety or EtherNet/IP Safety: a maximum of 2 ms; PROFINET Safety: a maximum of 4 ms.
If only the workspace is set with Cartesian Position Check, "the robot stops after it goes beyond the workspace." As engineering reasoning, a heavy-handling cell takes its stopping data for the heaviest part the robot carries, since payload is one of the variables FANUC names. The article on connecting a FANUC robot to an Allen-Bradley PLC covers how network timing enters the overall stopping time and the safeguard separation distance (FANUC B-83184EN/12, 2021, §1.7 p. 13 and §3.3 p. 33).
How does Stop Position Prediction keep the stop inside the zone?
Stop Position Prediction predicts the stop position from the current moving direction and speed; for the Cartesian zone check it enlarges each shape model to include both the current and the predicted stop position, and it shuts down motor power earlier when the prediction leaves the safe zone. It is disabled by default for both Joint Position Check and Cartesian Position Check, and it can also be switched off for an individual Cartesian zone.
The manual describes the stopping distance as depending on the type of robot, payload, and speed, "but mostly it is proportional to the speed", and the prediction sets the stopping distance at 0 mm at 0 mm/s and increases it proportionally with speed. Its settings work this way:
- DEFAULT mode: the proportion factor is 1.5 times the stopping distance at the maximum speed and maximum payload for each robot, and motor power is shut off farther from the zone border as speed increases.
- USER mode: the user enters a speed and the stopping distance at that speed; when the entered distance is greater than the actual stopping distance, the robot will stop in the safe zone.
- Stop categories: separate factors are set for Stop Category 0 and Stop Category 1, and a Category 0 stop is always done if its stopping distance is greater than the Category 1 distance. With stop type "Not stop", prediction is not used.
The warnings are specific. If prediction is set up incorrectly, "the robot will leave the safety zone", and changed values must be verified and the function tested again. An axis without a mechanical brake can move freely when motor power is shut down, and prediction does not work correctly for that axis; in that case, FANUC says a risk assessment for the whole robot system is necessary, including the free movement of that axis. Alarms may also occur when a shape model moves parallel to a zone border; the manual's remedy is to reduce speed or move the path away from the border (FANUC B-83184EN/12, 2021, §3.3 p. 33, §7.2.1 p. 95, §7.4.3 pp. 111–113 and §7.11.1 pp. 139–140).
What do DCS speed checks limit, and which DCS signals are not safety signals?
A speed check that trips shuts down motor power. Joint Speed Check holds up to 40 joint speed limits, and Cartesian Speed Check holds up to 16 limits on the speed of the DCS TCP. Either can check that the robot or an axis is stationary by setting the limit to 0. FANUC warns that when the Cartesian limit is 0 and the permissible distance is not 0, motor power does not shut down immediately when the DCS TCP moves, and "the stopping distance can be increased by acceleration in Permissible distance"; FANUC says a risk assessment for the whole robot system is necessary to determine that distance.
Zone-linked limits exist as well: the Cartesian Position Speed Check shuts down motor power when the DCS TCP exceeds a limit while a shape model is outside a safe zone. FANUC notes that its slowdown-zone setting, illustrated by a handling robot that slows only when an operator is in the collaborate zone, is not used in R-30iB and R-30iB Mate controllers.
Several DCS outputs look like safety signals but are not:
- Status DIs for Joint Position Check, Cartesian Position Check and Cartesian Speed Check: "Since DI is not safe signal, it cannot be used for safety purpose."
- Approach warning DO, which turns on when a shape model comes within a set margin of a zone border (default 100 mm): FANUC states it "is not a safety function."
OSHA's chapter makes the matching point for speed and separation monitoring: "when speed is being used for safety purposes, the speed should have an associated safety function that monitors that the needed speed will not be exceeded" (FANUC B-83184EN/12, 2021, §6.1 p. 76, §7.2 p. 94, §7.3 p. 98, §7.4 p. 102, §7.4.2.7 pp. 110–111, §7.4.4 p. 113 and §7.7 pp. 129–130; OSHA Technical Manual, Sec. IV Ch. 4, 2026).
How does DCS limit robot speed while someone teaches it?
OSHA's robotics page says that studies indicate "many robot accidents occur during non-routine operating conditions, such as programming, maintenance, testing, setup, or adjustment". Its Technical Manual says that in manual mode, robot speeds during programming sessions are at a reduced speed, "less than 10 inches (250 mm) per second."
FANUC's manual describes two layers for the T1 teach mode:
- Standard control software limits the TCP speed and the wrist flange center speed so they do not exceed 250 mm/s in T1.
- T1 Mode Speed Check in DCS shuts down motor power if the DCS TCP or the wrist flange center exceeds the set limit. It is enabled per motion group, is disabled by default, and its limit can be lowered but cannot exceed 250 mm/s.
The check watches only the DCS TCP and the wrist flange center. FANUC's warning is to set the most distant point of the end-effector from the wrist flange center as the DCS TCP, since otherwise a more distant point "might exceed 250 mm/sec", and, where several end-effectors are used, to use dynamic tool change or the TCP of the largest one. As engineering reasoning, heavy-handling grippers and the long parts they carry can put the farthest moving point well beyond the flange, and the DCS TCP is set at that point, which need not be the TCP the motion program uses (OSHA Robotics, 2026; OSHA Technical Manual, Sec. IV Ch. 4, 2026; FANUC B-83184EN/12, 2021, Ch. 7 p. 93 and §7.8 pp. 133–134).
Which axes and robot setups does DCS not cover the same way?
The manual sets limits on the axes heavy cells add:
- Robot model: Position/Speed Check is supported on "most, but not all, robot models"; FANUC directs users to their FANUC representative for the list.
- Servo gun and independent axes: cannot be used with Position/Speed Check and are treated as EXCLUDED axes.
- Customer-made positioners: to use the checks, the positioner must be a Basic Positioner with Known Kinematics.
- Continuous-turn axes: treated as Speed Only axes, usable for Joint Speed Check but not Joint Position Check; unless the axis is an Auxiliary Extended Axis, a motion group containing one cannot use Cartesian Position Check or Cartesian Speed Check.
- Tracks: an extended axis configured as an Integrated Axis keeps the Cartesian safe zone stationary as the robot travels, while an Auxiliary Axis carries the zone along with the robot. A rail unit set up as an independent group also carries the zone; to fix the zone, the rail is defined as an Integrated Rail axis of the same motion group.
- Unbraked axes: an axis without a mechanical brake can move freely when motor power is shut down, and Stop Position Prediction does not work correctly for it.
As engineering reasoning, the track and positioner configuration chosen at the engineering link decides whether a zone protects a fixed aisle or follows the robot, and that choice belongs in the risk assessment before the zones are drawn (FANUC B-83184EN/12, 2021, §1.2.2 pp. 5–6 and §3.3 p. 33).
What can DCS not replace in a heavy-handling robot cell?
As engineering reasoning, DCS zone and joint limits are space- and soft-axis-limiting safety functions of the kind OSHA lists among non-mechanical limiting devices. The sources still set clear edges around them.
- The risk assessment. FANUC's warnings call for a risk assessment for the whole robot system to verify that a PL d function is adequate and to account for stopping distance. OSHA's example risk assessment uses the risk levels to determine the required performance level (PLr) of each safety function.
- Detecting people. The position and speed checks use the robot's own motor sensors. In FANUC's zone-switching example, the presence of an operator reaches DCS as a safety input from an external device: safe mats, each connected to the emergency stop board through redundant contacts. For non-collaborative applications, OSHA's chapter describes risk reduction by physically separating workers from the robot during automatic operation, through guards, interlocked guards and presence-sensing devices.
- Protection against malfunction. OSHA notes that although robot applications have safety functions that monitor or limit speed, position and acceleration, "a component malfunction could cause an unexpected movement and/or robot velocity change."
- Equipment outside the robot controller. As engineering reasoning, a conveyor, transfer car or lift driven by its own adjustable-speed drive is not watched by the robot's motor sensors. For safety-related drives, IEC 61800-5-2:2016 specifies requirements and makes recommendations for the design and development, integration and validation of safety related power drive systems (PDS(SR)) in terms of their functional safety considerations.
The article on choosing a robot or a custom mechanism covers how robot and cell standards split the safety case. As engineering reasoning, the failure mode to design out is a zone drawn to replace a fence when the risk assessment called for keeping people out, not for keeping the robot in (FANUC B-83184EN/12, 2021, §1.1 p. 4, §1.7 p. 13 and Ch. 4 pp. 41 and 45; OSHA Technical Manual, Sec. IV Ch. 4, 2026; IEC 61800-5-2:2016).
Does a DCS stop count as energy isolation for maintenance?
FANUC describes DCS as stopping the robot by shutting down motor power. OSHA's lockout/tagout standard covers the servicing and maintenance of machines and equipment in which the unexpected energization or start up of the machines or equipment, or release of stored energy, could cause injury to employees. It defines an energy isolating device as a mechanical device that physically prevents the transmission or release of energy, including a manually operated electrical circuit breaker, a disconnect switch, a line valve and a block, and states that "push buttons, selector switches and other control circuit type devices are not energy isolating devices." After lockout or tagout devices are applied, all potentially hazardous stored or residual energy "shall be relieved, disconnected, restrained, and otherwise rendered safe."
The next two sentences are engineering reasoning. By those definitions, a DCS stop is not energy isolation: a DCS zone or a speed limit of 0 keeps the controller powered and its logic in charge, and neither is a mechanical isolating device. Heavy handling adds gravity: a robot arm holding a part is held by its brakes, and FANUC's own note that an unbraked axis moves freely when motor power is shut down shows why the procedure must lower or block the load before entry. The lockout/tagout procedure article covers the procedure sequence and hardware, and the machine vision article's answer on cleaning a camera inside a cell covers the minor-servicing exception (OSHA 29 CFR 1910.147-1989, §1910.147 paragraphs a.1.i, b and d.5.i; FANUC B-83184EN/12, 2021, §1.7 p. 13 and §3.3 p. 33).
How are DCS settings changed, verified, and protected?
The manual says DCS parameters are stored in a different memory area from other parameters and their data integrity is checked; users "cannot change DCS parameters directly." The change sequence is:
- Edit the setting parameters in the DCS menu.
- Run "Apply to DCS parameter", which is not done until the correct code number is entered; FANUC cautions users to change the code number from its default to prevent changes by unauthorized personnel.
- Check and confirm the values in the verify menu, which records the operator's verification.
- Cycle controller power; the changed values are used after the power cycle.
- Perform the actual DCS function to verify that the changed parameters are set correctly.
A change to mastering or robot setup data while the Position/Speed Check option is loaded, or a loaded backup file that changes setting parameters, raises the alarm "SYST-212 Need to apply to DCS param", which cannot be reset until the apply procedure is done; FANUC notes that this alarm "is not a safety function." The DCS signature number is a CRC of the DCS parameter values that changes whenever those parameters change. FANUC warns that with an incorrect DCS parameter setting the safety function does not work correctly, and a changed value must be verified and the related functions tested again (FANUC B-83184EN/12, 2021, §1.3 pp. 6–9 and §2.6 p. 24).
How is a DCS-equipped cell tested at acceptance and monitored after startup?
FANUC's manual closes with example safety-acceptance checklists and sets out who does what. The system integrator is responsible for the design of the cell; the safety maintenance technician configures the robot with the values the integrator supplies and tests whether the safety functions work as specified, but "does not perform a safety assessment of the system." The example system checklist asks, among other items:
- Whether the mastering test and the brake test were successful
- Whether each Joint Position Check was confirmed by moving the axis to the upper and lower limits of its space
- Whether each surface of a Cartesian monitoring space was addressed in 3 different positions
OSHA's chapter says site acceptance tests should be performed by the integrator and verified by the user, and that employers should ensure site acceptance is performed before initial startup. After that, it says stopping-ability performance, the appropriateness of the application's safety distances and safety function settings should be checked, and that checksums of safety parameters are a quick way to see whether safety settings have changed since the last inspection. FANUC adds its own periodic check, an emergency stop input or a power cycle twice or more a year, and its example checklist records the DCS signature numbers, which FANUC says can be used to indicate that DCS parameters have been changed. UTEC Industrial performs factory acceptance testing and on-site commissioning, and integrates FANUC robotic cells, including vision, with a FANUC design and engineering partner (FANUC B-83184EN/12, 2021, §1.2.1 p. 4, §2.6 p. 24 and Ch. 25 pp. 360 and 374; OSHA Technical Manual, Sec. IV Ch. 4, 2026).
What controls and sensing tie DCS to the rest of the cell?
DCS reaches the cell through safe I/O: a dual-channel input, such as a safe mat's two contacts, becomes one safe I/O signal that is ON only when both channels are ON. Safe I/O Connect then combines signals with AND, OR and NOT logic, up to 64 settings processed every 2 ms, and can drive safety outputs from DCS status; for example, a Cartesian Position Check's SAFE status can switch a safety output. A safe input can also be set as a zone's disabling input, which is how FANUC's examples switch zones from a safe mat.
Two details in the manual shape that switching:
- Non-safety inputs. Where zones are switched from the robot program through a non-safety input, the manual says the system should be designed so it does not create a dangerous situation even when that input has the wrong value.
- Processing load. If the system total process time factor of zones and shape models is greater than 1,000, applying the parameters displays "Too many zone or models!"; DeviceNet Safety, EtherNet/IP Safety or PROFINET Safety adds 400.
On an EtherNet/IP Safety network, the robot controller works as an adapter device and exchanges safety signals with an external safety scanner device. The article on connecting a FANUC robot to an Allen-Bradley PLC covers why safety signals are carried on CIP Safety connections or hard-wired safety circuits rather than as standard I/O bits. As engineering practice, the cell's sensing layer around DCS is the safety-rated set of light curtains, scanners, interlocked gates and mats wired as safety inputs, plus encoders and limit switches on any axis the robot controller does not drive. UTEC Industrial, a Rockwell Automation Recognized System Integrator, builds the Allen-Bradley ControlLogix and CompactLogix controls that exchange these signals with the robot (FANUC B-83184EN/12, 2021, §1.1 p. 2, §7.4.2.2 p. 106, §7.4.2.4 p. 108, §9.1 p. 161, §9.2 p. 171 and §9.3 p. 174).
Where do DCS zones sit in the build chain of a heavy-handling cell?
The zones are set at the controls link but depend on the links around it.
- Design. OSHA's example risk assessment determines and documents the operating space and restricted space, and the desired restricted space, considering hard stops, travel limit sensors and safety-rated soft-axis limits.
- Engineering. The zone check tests shape models of the arm and tooling. FANUC's handling example notes that "A danger area is increased by gripping works", and the robot needs user models set for each tool.
- Machining, fabrication and stress relief. As engineering reasoning, the user model is only as true as the gripper built to the drawing; a weldment that distorts in welding or machining moves its outline away from the model. The article on stress relief for machine frames and bases covers why welded frames are stress-relieved before final machining.
- Drives. FANUC's checklist includes a brake test, and Stop Position Prediction does not work correctly for an axis without a mechanical brake.
- Tuning. The manual notes that if the payload setting is not correct, the motion at servo power-on becomes large and a DCS alarm may occur.
UTEC Industrial stress-relieves welded frames with automated vibratory stress relief (VSR) and machines their mounting faces in-house before assembly (OSHA Technical Manual, Sec. IV Ch. 4, 2026; FANUC B-83184EN/12, 2021, §6.1 p. 76, §7.2 p. 94, §3.3 p. 33 and Ch. 25 p. 360).
- Robots on 7th-Axis Tracks and Positioners for Large Parts — robots on tracks where zones move with the axis
- When Does a Robot Beat a Custom Mechanism for Heavy Material Handling? — how robot and cell safety standards split ownership of the safety case
- Sizing an Industrial Robot: Payload, Reach, Wrist Moment, and Inertia — the payload data that DCS stopping distance and alarms depend on
- Machine Vision in Material Handling: What It Does and How It Works — why a production camera is not a safety device in a guarded cell
- Lockout/Tagout for CNC Equipment: OSHA Requirements and Best Practices — the energy isolation a DCS stop does not provide
References
- FANUC B-83184EN/12: R-30iB/R-30iB Mate/R-30iB Plus/R-30iB Mate Plus/R-30iB Compact Plus/R-30iB Mini Plus Controller Dual Check Safety Function Operator's Manual. FANUC Corporation, 2021.
- ISO 13849-1:2023: Safety of machinery — Safety-related parts of control systems — Part 1: General principles for design. International Organization for Standardization, 2023.
- OSHA. Robotics (Safety and Health Topics). U.S. Department of Labor (undated web documentation, accessed September 2026).
- OSHA. Robotics: Standards (Safety and Health Topics). U.S. Department of Labor (undated web documentation, accessed September 2026).
- OSHA. OSHA Technical Manual (OTM), Section IV: Chapter 4 - Industrial Robot Systems and Industrial Robot System Safety. U.S. Department of Labor (undated web documentation, accessed September 2026).
- ANSI/A3 R15.06-2025: American National Standard for Industrial Robots and Robot Systems – Safety Requirements. A3/ANSI, 2025.
- IEC 61800-5-2:2016: Adjustable speed electrical power drive systems — Part 5-2: Safety requirements — Functional. International Electrotechnical Commission, 2016.
- OSHA 29 CFR 1910.147-1989: The Control of Hazardous Energy (Lockout/Tagout). Occupational Safety and Health Administration, 1989.
Ready to Discuss a Material Handling System?
UTEC Industrial designs, engineers, machines, fabricates, and installs custom material handling systems for heavy industry, from the stress-relieved structure and drives to the Allen-Bradley PLC controls, tuning, and monitoring that run them, at its Spokane Valley, WA facility. Send UTEC the application, loads, and duty cycle to start a system review.
Questions? Call (509) 922-1832 or email sales@utec.co