The architecture of a programmable controller especially suited for automation applications of highest safety criticality,
i.e., on Safety Integrity Level 4, is presented. Its main characteristics are input conditioning by low resolution analogue-to-digital
converters and inference by look-up in cause/effect tables or rule set tables. This programmable electronic system consists
of a few elements, only. Thus, it is reliable, safe, verifiable, cheap and small. Owing to the simplicity of both its hardware
and software, safety licensing of the controller is facilitated. With regard to software, this can easily be carried out by
inspection of the table content. The controller is very fast, with its speed mainly determined by the table access time, and
works almost jitter free. Operating in a strictly cyclic fashion, the controller exhibits fully predictable real time behaviour.
Its hardware operation is supervised by a fail safe logic immediately initiating an emergency shut-down in case of a malfunction.
Keywords Safety critical industrial automation - Safety Integrity Level 4 - safety licensing - programmable electronic system - predictable real time behaviour - fail safe behaviour