Why "Risk Assessment" Isn't a Checklist — It's an Iterative Process
ISO 12100 defines risk assessment as an iterative loop, not a one-time form: identify hazards, estimate and evaluate the risk for each one, reduce the risk using a required hierarchy of measures, then re-assess whether the residual risk is acceptable. If it isn't, you go through the loop again. A common mistake is treating a risk assessment as paperwork completed once after installation — in reality, it should be revisited whenever the task, tooling, payload, or personnel access to the cell changes.
The Three-Step Hierarchy of Risk Reduction
ISO 12100 requires risk reduction measures to be applied in this specific order — you cannot skip to a lower-priority measure just because it's cheaper or faster to implement:
- Inherently safe design — eliminate the hazard at the source. Examples: reducing pinch points in the mechanical design, limiting speed or force by design rather than by a monitored limit, eliminating sharp edges on tooling.
- Safeguarding and complementary protective measures — where the hazard can't be eliminated, add physical or electronic protection: fixed guards, light curtains, area scanners, interlocked gates, safety-rated monitored stop.
- Information for use — the last resort: warning labels, training, documented procedures, and PPE requirements for residual risks that remain after design and safeguarding measures have been applied.
Task-Based Hazard Identification
Rather than assessing "the robot" as a single hazard source, ISO 10218-2 and CSA Z434 both require a task-based approach: list every task a person performs around the cell across its full lifecycle, then identify the hazards specific to that task. This catches hazards that a general walkthrough misses.
| Task | Who Performs It | Hazard(s) Present |
|---|---|---|
| Normal automatic cycle (guards closed) | No one inside cell | Generally low — verify guard interlocking is functioning |
| Loading/unloading parts | Machine operator | Reach-in impact/crush if perimeter guarding has a gap or opening |
| Teaching/jogging the robot (teach pendant) | Programmer/technician | Impact, crush; unexpected motion if reduced-speed mode is not enforced |
| Clearing a jam or fault | Operator or maintenance tech | Unexpected restart; stored energy in pneumatics/hydraulics; access with guards defeated |
| Tooling/end-effector changeover | Maintenance tech | Dropped tooling, unexpected release of gripper/vacuum, energy isolation not verified |
| Scheduled maintenance | Maintenance tech | Access to energized/moving parts; lockout/tagout not followed |
Each row above becomes its own line item in the risk assessment — a robot cell commonly generates 15-40+ distinct hazard entries once tasks are broken out this way, far more than a single "robot arm can strike a person" line captures.
Scoring Severity and Probability
ISO 12100 doesn't mandate one specific scoring scale, but the widely used structure (also reflected in ISO 13849-1's risk graph for determining PLr) uses three parameters instead of a simple two-axis matrix:
| Parameter | Levels | What It Represents |
|---|---|---|
| S — Severity of injury | S1: slight (reversible) | S2: serious (irreversible, including death) | Worst credible outcome if the hazard is realized |
| F — Frequency/exposure | F1: rare/short exposure | F2: frequent/continuous exposure | How often and how long a person is in the hazard zone |
| P — Possibility of avoidance | P1: possible under specific conditions | P2: scarcely possible | Whether a person could reasonably avoid or limit the injury once the hazardous event starts |
These three parameters combine through the ISO 13849-1 risk graph to determine the Required Performance Level (PLr) — the minimum reliability the safety function protecting against that specific hazard must achieve. This is the number your safeguarding design (light curtain, interlock, safety-rated monitored stop) has to be validated against, typically expressed as PL a (lowest) through PL e (highest).
Common Category/PL Combinations by Standard
| Standard | Scope | Typical Context |
|---|---|---|
| ANSI/RIA R15.06 | USA industrial robot safety (based on ISO 10218) | Category 3 / PL d commonly required for perimeter safeguarding e-stop and gate interlock circuits |
| CSA Z434 | Canada industrial robot safety | Aligned closely with ANSI/RIA R15.06 and ISO 10218; provincial OHS codes may add requirements |
| ISO 10218-1/2 | Robot manufacturer (Part 1) and integrator/system (Part 2) requirements globally | Defines baseline safety requirements robots and integrated systems must meet |
| ISO/TS 15066 | Collaborative robot applications specifically | Defines the four collaborative modes (safety-rated monitored stop, hand guiding, speed and separation monitoring, power and force limiting) and biomechanical force/pressure limits |
| ISO 13849-1 | Safety-related control system design (cross-industry) | Source of the Category (B,1-4) and Performance Level (a-e) framework referenced by the robot-specific standards above |
Collaborative Robots Don't Skip This Process
A frequent misconception is that using a certified collaborative robot eliminates the need for an application-specific risk assessment. It doesn't. ISO/TS 15066 requires assessing whether the specific end-effector, payload, task speed, and contact scenarios in your application keep contact forces and pressures under the biomechanical limits defined for the relevant body regions — a cobot's general certification covers the robot itself, not every possible tool and task you attach to it. A blunt, large-surface gripper and a sharp, small-tipped tool mounted on the identical cobot can produce very different risk outcomes for the same nominal force.
Structuring the Risk Assessment Worksheet
A functional worksheet — whether in a spreadsheet or dedicated safety software — should carry each hazard through the full loop, not just record an initial score:
| Column | Purpose |
|---|---|
| Task / Life-cycle phase | Which activity exposes a person to this hazard |
| Hazard description | Specific mechanism (crush, impact, entanglement, etc.) and the body part at risk |
| Initial S / F / P | Severity, frequency, avoidance possibility before any additional risk reduction |
| Initial PLr / risk level | Resulting required performance level or risk ranking before mitigation |
| Risk reduction measure applied | Specific control per the 3-step hierarchy — design change, safeguard, or information |
| Residual S / F / P | Re-scored after the measure is applied |
| Residual risk acceptable? (Y/N) | Explicit determination — if "No," the loop must repeat with additional measures |
| Responsible party / date / review date | Accountability and scheduled re-assessment trigger |
The "residual risk acceptable" column is the one most often missing from informal assessments — without an explicit yes/no determination and sign-off, there's no documented evidence the loop was actually closed for that hazard.
Common Failures in DIY Risk Assessments
- Assessing the robot instead of the tasks — missing hazards that only occur during changeover, jam-clearing, or maintenance rather than normal cycling.
- Treating a warning label as risk reduction — information for use is the last resort in the hierarchy, not an alternative to design changes or safeguarding.
- No documented re-assessment trigger — a new end-effector or payload change goes into production without revisiting the original assessment.
- Assuming a certified cobot means the application is automatically safe — the certification covers the robot; the application-specific assessment is still required under ISO/TS 15066.
- Confusing Category with Performance Level — a well-designed Category 3 architecture with poor component reliability data can still fail to achieve PL d; they need to be validated together, not treated as interchangeable labels.
"A risk assessment that never produces a documented 'no, this isn't acceptable yet' for at least one hazard almost always means the assessment wasn't rigorous enough, not that the cell was unusually safe from the start."— Robotics Engineering, Safety & Compliance Editorial Notes
Sources and Further Reading
- ISO 12100 — Safety of machinery: General principles for risk assessment and risk reduction. The foundational methodology referenced throughout this article.
- ISO 13849-1 — Safety-related parts of control systems: source of the Category and Performance Level framework.
- ISO 10218-1 & -2 — Robots and robotic devices: safety requirements for industrial robots (Part 1: robots; Part 2: robot systems and integration).
- ISO/TS 15066 — Robots and robotic devices: collaborative robots, including biomechanical limit tables.
- ANSI/RIA R15.06 — American National Standard for Industrial Robots and Robot Systems, Safety Requirements.
- CSA Z434 — Industrial Robots and Robot Systems: General Safety Requirements (Canada).
- OSHA Robotics Safety Guidance — general workplace robotics safety information (USA).
Standards documents referenced above are copyrighted and available for purchase through ANSI, ISO, and CSA Group directly. This article summarizes publicly available methodology descriptions and does not reproduce the full text of any standard.
Who is legally allowed to perform a robot arm risk assessment?
ANSI/RIA R15.06 and CSA Z434 both require risk assessments to be conducted by a competent person with knowledge of the robot system, the application, and relevant safety standards. This doesn't have to be a licensed engineer in every case, but complex installations often warrant review by a certified functional safety engineer, particularly where the output determines required Performance Level.
What's the difference between Performance Level (PL) and Category in safety-rated robot systems?
Category describes the structural architecture of a safety function — single channel vs. redundant dual channel with diagnostics, for example. Performance Level is a broader measure of the safety function's ability to reduce risk, calculated from the category plus component reliability, diagnostic coverage, and common cause failure protection.
Do collaborative robots still need a formal risk assessment?
Yes. ISO/TS 15066 explicitly requires a risk assessment for collaborative applications. A cobot's general certification covers the robot itself, not the specific end-effector, payload, and task combination used in your application, which must be separately assessed against biomechanical force and pressure limits.
How often should a robot arm risk assessment be updated?
Whenever the application changes in a way that could introduce or change a hazard: a new end-effector, payload change, task sequence change, or change in personnel access. Most standards also recommend periodic review even without a known change.