11.3.1 The safety system should automatically
stop that part of the monitored installation which is in danger in
cases of serious malfunction of the machinery or its auxiliaries.
Propulsion and lift should only be stopped in cases where there is
a risk of complete breakdown or explosion. The Administration may
permit provision to be made to override the safety system provided
it is sealed so as to prevent inadvertent operation.
11.3.2 The safety system should be designed so
as to be protected against breakdown. For this purpose, any fault
in the safety circuit should not result in untimely stoppage of the
installation it protects.