Why "Risk Assessment" Isn't a Checklist — It's an Iterative Process

ISO 12100 defines risk assessment as an iterative loop, not a one-time form: identify hazards, estimate and evaluate the risk for each one, reduce the risk using a required hierarchy of measures, then re-assess whether the residual risk is acceptable. If it isn't, you go through the loop again. A common mistake is treating a risk assessment as paperwork completed once after installation — in reality, it should be revisited whenever the task, tooling, payload, or personnel access to the cell changes.

Editorial top-down layout of a guarded robot cell with light curtain, scanner and e-stops.
Original editorial illustration for this article. Schematic for explanation only; not a layout or drawing package.

The Three-Step Hierarchy of Risk Reduction

ISO 12100 requires risk reduction measures to be applied in this specific order — you cannot skip to a lower-priority measure just because it's cheaper or faster to implement:

  1. Inherently safe design — eliminate the hazard at the source. Examples: reducing pinch points in the mechanical design, limiting speed or force by design rather than by a monitored limit, eliminating sharp edges on tooling.
  2. Safeguarding and complementary protective measures — where the hazard can't be eliminated, add physical or electronic protection: fixed guards, light curtains, area scanners, interlocked gates, safety-rated monitored stop.
  3. Information for use — the last resort: warning labels, training, documented procedures, and PPE requirements for residual risks that remain after design and safeguarding measures have been applied.
Information for use is not a substitute for the first two steps. A warning sign next to an inadequately guarded pinch point does not bring the risk down to an acceptable level under ISO 12100 — auditors and insurers increasingly flag this as a compliance gap, not a valid risk reduction measure on its own.

Task-Based Hazard Identification

Rather than assessing "the robot" as a single hazard source, ISO 10218-2 and CSA Z434 both require a task-based approach: list every task a person performs around the cell across its full lifecycle, then identify the hazards specific to that task. This catches hazards that a general walkthrough misses.

Indicative values only; the governing figure is the one in the current product documentation.
TaskWho Performs ItHazard(s) Present
Normal automatic cycle (guards closed)No one inside cellGenerally low — verify guard interlocking is functioning
Loading/unloading partsMachine operatorReach-in impact/crush if perimeter guarding has a gap or opening
Teaching/jogging the robot (teach pendant)Programmer/technicianImpact, crush; unexpected motion if reduced-speed mode is not enforced
Clearing a jam or faultOperator or maintenance techUnexpected restart; stored energy in pneumatics/hydraulics; access with guards defeated
Tooling/end-effector changeoverMaintenance techDropped tooling, unexpected release of gripper/vacuum, energy isolation not verified
Scheduled maintenanceMaintenance techAccess to energized/moving parts; lockout/tagout not followed

Each row above becomes its own line item in the risk assessment — a robot cell commonly generates 15-40+ distinct hazard entries once tasks are broken out this way, far more than a single "robot arm can strike a person" line captures.

Scoring Severity and Probability

ISO 12100 doesn't mandate one specific scoring scale, but the widely used structure (also reflected in ISO 13849-1's risk graph for determining PLr) uses three parameters instead of a simple two-axis matrix:

Editorial table. Exact numbers vary by variant, option package and revision.
ParameterLevelsWhat It Represents
S — Severity of injuryS1: slight (reversible)  |  S2: serious (irreversible, including death)Worst credible outcome if the hazard is realized
F — Frequency/exposureF1: rare/short exposure  |  F2: frequent/continuous exposureHow often and how long a person is in the hazard zone
P — Possibility of avoidanceP1: possible under specific conditions  |  P2: scarcely possibleWhether a person could reasonably avoid or limit the injury once the hazardous event starts

These three parameters combine through the ISO 13849-1 risk graph to determine the Required Performance Level (PLr) — the minimum reliability the safety function protecting against that specific hazard must achieve. This is the number your safeguarding design (light curtain, interlock, safety-rated monitored stop) has to be validated against, typically expressed as PL a (lowest) through PL e (highest).

Common mistake: applying one PLr to the whole cell. Different hazards in the same cell often require different Performance Levels. A high-speed pinch hazard during normal operation might drive PL d or PL e, while a low-frequency, easily avoidable hazard during a rarely performed maintenance task might only require PL c. Blanket-applying the highest PLr everywhere isn't wrong from a safety standpoint, but it can lead to unnecessarily expensive over-engineering if applied without task-specific analysis.

Common Category/PL Combinations by Standard

Summary for orientation — verify against the datasheet for the configuration you are quoting.
StandardScopeTypical Context
ANSI/RIA R15.06USA industrial robot safety (based on ISO 10218)Category 3 / PL d commonly required for perimeter safeguarding e-stop and gate interlock circuits
CSA Z434Canada industrial robot safetyAligned closely with ANSI/RIA R15.06 and ISO 10218; provincial OHS codes may add requirements
ISO 10218-1/2Robot manufacturer (Part 1) and integrator/system (Part 2) requirements globallyDefines baseline safety requirements robots and integrated systems must meet
ISO/TS 15066Collaborative robot applications specificallyDefines the four collaborative modes (safety-rated monitored stop, hand guiding, speed and separation monitoring, power and force limiting) and biomechanical force/pressure limits
ISO 13849-1Safety-related control system design (cross-industry)Source of the Category (B,1-4) and Performance Level (a-e) framework referenced by the robot-specific standards above

Collaborative Robots Don't Skip This Process

A frequent misconception is that using a certified collaborative robot eliminates the need for an application-specific risk assessment. It doesn't. ISO/TS 15066 requires assessing whether the specific end-effector, payload, task speed, and contact scenarios in your application keep contact forces and pressures under the biomechanical limits defined for the relevant body regions — a cobot's general certification covers the robot itself, not every possible tool and task you attach to it. A blunt, large-surface gripper and a sharp, small-tipped tool mounted on the identical cobot can produce very different risk outcomes for the same nominal force.

Structuring the Risk Assessment Worksheet

A functional worksheet — whether in a spreadsheet or dedicated safety software — should carry each hazard through the full loop, not just record an initial score:

Compiled from published documentation; re-check any figure you intend to design against.
ColumnPurpose
Task / Life-cycle phaseWhich activity exposes a person to this hazard
Hazard descriptionSpecific mechanism (crush, impact, entanglement, etc.) and the body part at risk
Initial S / F / PSeverity, frequency, avoidance possibility before any additional risk reduction
Initial PLr / risk levelResulting required performance level or risk ranking before mitigation
Risk reduction measure appliedSpecific control per the 3-step hierarchy — design change, safeguard, or information
Residual S / F / PRe-scored after the measure is applied
Residual risk acceptable? (Y/N)Explicit determination — if "No," the loop must repeat with additional measures
Responsible party / date / review dateAccountability and scheduled re-assessment trigger

The "residual risk acceptable" column is the one most often missing from informal assessments — without an explicit yes/no determination and sign-off, there's no documented evidence the loop was actually closed for that hazard.

Common Failures in DIY Risk Assessments

"A risk assessment that never produces a documented 'no, this isn't acceptable yet' for at least one hazard almost always means the assessment wasn't rigorous enough, not that the cell was unusually safe from the start."
— Robotics Engineering, Safety & Compliance Editorial Notes

Sources and Further Reading

Standards documents referenced above are copyrighted and available for purchase through ANSI, ISO, and CSA Group directly. This article summarizes publicly available methodology descriptions and does not reproduce the full text of any standard.

Written by the Robotics Engineering Editorial Team
Technical content focused on 6-DOF robot arm design and industrial safety compliance. This article is educational in nature; formal risk assessments should be conducted or validated by a competent person as defined by the applicable standard, with complex installations reviewed by a certified functional safety engineer.

Who is legally allowed to perform a robot arm risk assessment?

ANSI/RIA R15.06 and CSA Z434 both require risk assessments to be conducted by a competent person with knowledge of the robot system, the application, and relevant safety standards. This doesn't have to be a licensed engineer in every case, but complex installations often warrant review by a certified functional safety engineer, particularly where the output determines required Performance Level.

What's the difference between Performance Level (PL) and Category in safety-rated robot systems?

Category describes the structural architecture of a safety function — single channel vs. redundant dual channel with diagnostics, for example. Performance Level is a broader measure of the safety function's ability to reduce risk, calculated from the category plus component reliability, diagnostic coverage, and common cause failure protection.

Do collaborative robots still need a formal risk assessment?

Yes. ISO/TS 15066 explicitly requires a risk assessment for collaborative applications. A cobot's general certification covers the robot itself, not the specific end-effector, payload, and task combination used in your application, which must be separately assessed against biomechanical force and pressure limits.

How often should a robot arm risk assessment be updated?

Whenever the application changes in a way that could introduce or change a hazard: a new end-effector, payload change, task sequence change, or change in personnel access. Most standards also recommend periodic review even without a known change.

Related Reading

Continue with the Master Guide

How the topics on this page fit into a complete robot arm build.

Read Full Guide →