A machine safety risk assessment under ISO 12100 defines the machine’s limits, identifies hazards, estimates and evaluates risk, then selects and verifies risk-reduction measures. Carry it through production, setup, cleaning, fault recovery and maintenance, with each decision linked to the machine configuration.
Motionwell uses that process for the machines it designs and builds in Singapore, including rotary assembly systems, robot cells and cleanroom test equipment. The register guides mechanical design first, then the safeguarding and control functions needed for the remaining hazards.
The short answer. A machine safety risk assessment under ISO 12100 is a decision record, not a form. It states what the machine is for and what it is not for, lists every hazard a person can meet in every mode of its life, estimates each risk from severity and probability with the assumptions written out, and judges whether the risk is low enough. Where it is not, the three-step method applies in order: change the design so the hazard is gone or smaller, safeguard what remains, then tell the user about whatever is left. Any safeguard that works through a control circuit becomes a safety function, and that is the point where ISO 13849-1 takes over with a required Performance Level. The manufacturer remains responsible for the machine assessment, while competent internal or external assessors may prepare and review it.
This guide is about the assessment itself. The Performance Level arithmetic and CE marking are on our ISO 13849 machine safety compliance page, and the guard itself is on our machine guarding design page.
What Has to Be Settled About the Machine Before Any Hazard Is Listed?
ISO 12100 starts with the determination of limits, and it is the step that gets skipped because it reads like description. It is analysis. A hazard is a property of a machine in a mode with a person in a place, so until the modes, the people and the places are fixed, the hazard list is a guess at a machine that has not been defined.
Four kinds of limit get written down, and the table sets out what each has to contain and where the answer usually comes from.
| Limit | What gets written down | Where the answer usually comes from |
|---|---|---|
| Use | Intended use and product range; every operating mode; who is present in each mode and how trained they are; foreseeable misuse | The customer’s process description, then a walk through a working day with the people who will run the machine |
| Space | Motion envelopes; room for a person to load, clean or repair; material in and out; adjacent machines, utilities and traffic | The general arrangement drawing and the site layout |
| Time | Expected life; service intervals; the life of wear parts with a safety duty | Component data and the maintenance plan |
| Other | Product hazards; environment such as cleanroom, dust or temperature; materials and cleaning agents | The process specification |
The list of operating modes carries the most weight, because each mode is a different machine for the purposes of the assessment. Automatic production with the guards closed is one machine. Setup with a door open and a setter adjusting a station is another. Teach mode with a person inside the robot envelope, cleaning with panels off, fault clearing with a hand in a station that stopped mid-cycle, and maintenance with the drives isolated are others again. Write each one down with the person who is in it and the task they are doing, and the hazard identification that follows has something to walk through.
Foreseeable misuse belongs here too, and the word is foreseeable, not permitted. An operator who clears a jam without stopping the machine, a setter who bridges an interlock to teach with the door open, a technician who climbs the frame to reach a scanner: the assessment has to see them coming, because the measures chosen later have to work on the machine people actually use.
How Do You Identify Hazards Without Copying a List Out of the Annex?
ISO 12100 groups hazards by origin: mechanical, electrical, thermal, noise, vibration, radiation, materials and substances, ergonomic, the environment the machine is used in, and combinations of these. Its annex lists them in detail, and the list is useful as a check at the end. It is not a method. An assessment that opens the annex and ticks what seems to apply produces a hazard list about machines in general.
The method is task-based, and it uses the limits from the previous step as its index. For each operating mode, for each task in that mode, for each zone a person is in while doing it, ask three questions. What can move while a person is there, including motion that should not happen: unexpected start-up, a stop that is lost, an axis that runs on after the stop command. What can be released: pneumatic pressure held in a cylinder, a spring under load, a vertical axis that drops when the drive loses torque, a part held by vacuum. What can a person touch: a hot surface, a sharp edge on the part or the tooling, a live terminal behind a panel, a laser or a UV source.
Two habits make this work in practice. The first is to name hazards at the place they occur, and never by the machine element: not “robot”, but crushing between the gripper and the fixture at the load station during teach, with the setter’s hand as the exposed body part. A hazard named that precisely can be estimated, reduced and later checked; a hazard named “robot” can only be ticked. The second is to include the part and the tooling in the walk-through, because the tool and the workpiece change the hazard and somebody has to own that assessment, as our guide to the ISO 10218 industrial robot safety standard sets out.
Measures added at step two go back into this list as hazard sources of their own: a locking door that can shut a person inside, a fence that blocks the route to an isolator, a panel heavy enough to injure the person removing it. The guarding side of that is worked through on the machine guarding design page.
The output of the step is a hazard register with one line per hazard: the hazard, its origin, the zone, the task and mode, the person exposed, and the hazardous event that turns the hazard into harm. Nothing about severity or probability yet. Estimating while identifying is how hazards get talked down before they are written down.
How Is Risk Estimated When Nobody Has Injury Statistics for the Machine?
Risk under ISO 12100 is a function of two things: the severity of the harm that could result from a hazard, and the probability of that harm occurring. The probability breaks into three parts: the exposure of people to the hazard, how often and for how long; the probability of the hazardous event actually occurring, which depends on the reliability of the machine, on the history of similar machines and on human behaviour; and the possibility of avoiding or limiting the harm, which depends on the speed of the event, on warning, and on whether the person can see it coming and get clear.
There are no injury statistics for a machine that has not been built, and the standard does not pretend otherwise. Estimation is a reasoned judgement on each element, and the discipline is to write the reasoning down as an assumption that can be checked. “The operator reaches into the feeder station to clear a misfeed” is a hazard. “About once per shift, for a few seconds, with the machine held by the cycle stop and not isolated” is the exposure and the occurrence assumption, and it is the sentence a reviewer can disagree with. Where a plant has an incident record for a similar machine, it goes in as data; where it does not, the assumption stands in its place, and it is labelled as one.
Estimate the risk of the hazard before any protective measure. This is the order ISO 12100 sets, and it matters because the same estimate is done twice: once for the machine as it would be without the measure, which is what justifies the measure and later sets the required Performance Level, and once again after the measure to confirm what is left. An estimate that already assumes the light curtain is there has nothing to compare against and cannot show that the curtain was needed.
| Element | What has to be written down | Error to avoid |
|---|---|---|
| Severity | The worst credible harm from this hazard, which body part, and whether it is reversible | Rating the usual outcome instead of the worst credible one |
| Exposure | How often and for how long a person is in the zone, in which mode, per shift | Counting production and forgetting setup, cleaning and fault clearing |
| Occurrence of the hazardous event | What has to fail or be done for the harm to happen: a control failure, a drop on power loss, a hand reaching in | Treating a procedure that exists on paper as if it were always followed |
| Possibility of avoidance | The speed of the motion, any warning, whether the person can see and withdraw | Assuming a trained operator moves faster than the machine |
ISO 12100 does not fix the scale for each element, and a qualitative one with a few steps is enough for a special purpose machine as long as the definitions stay fixed for the life of the file. The assumptions behind the scores, not the scoring scheme, are what a reviewer reads at the next reassessment.
What Does Risk Evaluation Decide, and When Is the Reduction Enough?
Evaluation is the step where the estimate becomes a decision: is risk reduction required for this hazard, or has adequate reduction already been achieved. It sounds like a formality after the estimate and it is not, because the criterion is not a number. ISO 12100 sets a list of conditions that adequate risk reduction has to satisfy, and each of them can fail on a machine whose scores look fine.
The conditions ask whether all operating conditions and all intervention procedures were considered, whether hazards were eliminated or reduced as far as practicable, whether the protective measures chosen are adequate for the risk, whether the residual risk has been communicated, whether the measures are compatible with one another, whether the machine can be used for its purpose without undue risk, and whether the measures hinder the operator. That last one is a design criterion in its own right. A measure that gets in the way of the task will be defeated, and a defeated measure protects nobody, so a guard that stops the operator doing the job is evaluated as inadequate even if its circuit is rated for the highest level.
Check for applicable type-C requirements, including those covering a machine or subsystem within a custom line. Where they address the hazard, use them alongside the general assessment. Type-B standards on guards, interlocks and safety distances support the remaining design decisions.
Evaluation is iterative. After each measure is chosen, the hazard is estimated again with the measure in place, the question of new hazards introduced by the measure is asked, and the loop runs until the conditions above are met. The record of the step is one line per hazard: reduced adequately or not, and why. That line is what a reviewer two years later reads first.
How Does the Three-Step Method Change the Machine, Not the Paperwork?
The order in ISO 12100 is inherently safe design measures first, safeguarding and complementary protective measures second, information for use third. The order is not a preference. Each step is applied only for the risk the previous step could not remove, and the file has to show that the previous step was tried.
Step one changes the hazard itself. Geometry may remove a trapping point, and reducing accessible mass, energy or force may reduce the harm it can cause. Presenting parts outside a hazardous zone can remove the need to reach into it for loading. Check the relevant body-part clearances and all affected tasks before treating a hazard as eliminated. Record the design options considered and the reason for the chosen arrangement.
Step two changes the access to the hazard. This is where the purchased hardware lives: fixed and interlocked guards, guard locking, light curtains and safety laser scanners, and a safety PLC or safety relay behind them, plus the complementary measures of emergency stop, energy isolation and a way out for a person who ends up inside. The assessment has to say, for each device, which hazard it covers, in which mode, and what it must achieve, for instance stop the motion before a hand can reach the station. A device chosen without that sentence is a catalogue decision, and it is the shortcut that produces machines with a light curtain at every opening and no answer to why.
Step three changes what the user knows. Markings, warning signs, signals, the instruction handbook and the training it implies. Information for use is only for the risk that remains after the first two steps, and the file has to show that each item corresponds to a specific residual risk. A warning label on a hazard that could have been enclosed is a step-one failure with a sticker on it.
| Step | What it changes | What the file has to show | Typical measure |
|---|---|---|---|
| 1. Inherently safe design | The hazard itself: geometry, energy, speed, mass, the need for access | Options considered per hazard, the one taken, and why the others were rejected | A feed path that removes the need to reach into a hazardous zone; geometry checked against relevant crushing and reach dimensions |
| 2. Safeguarding and complementary measures | Access to the hazard, and recovery when something goes wrong | Which hazard each device covers, in which mode, and what it must achieve | An interlocked door at a replenishment point; a light curtain at a manual load position; a scanner across a pallet approach; emergency stop and energy isolation |
| 3. Information for use | What the user knows and does | The residual risk each item corresponds to | A warning for a surface that cannot be enclosed; a handbook procedure for a jam that cannot be designed out |
The pull towards step two is strong, because the components are on the shelf and the drawing is not yet frozen. On a machine we design, the discipline that holds the order is a simple one: no safety device is added to the layout until the hazard register shows what step one did about the hazard first.
Where Does the Assessment Hand Over to ISO 13849-1 and the Required Performance Level?
Every step-two measure that works through a control circuit is a safety function. An interlocked door is a safety function: door opens, hazardous motion stops. A light curtain, a scanner zone, an emergency stop, a speed limit in teach mode, a guard lock released by a standstill monitor: each is a function with an input, a logic element and an output, and each has to be reliable enough for the risk it covers. That reliability is what ISO 13849-1 rates, as a required Performance Level from a to e, and the risk assessment is where the input to that rating comes from.
The hand-over document is a safety requirements specification, one entry per function, and it is written from the assessment, never invented by the controls engineer from scratch.
The PLr comes from the ISO 13849-1 risk graph, and its three inputs are re-readings of the estimate already made. Severity of injury maps from the severity element, frequency and duration of exposure from the exposure element, and possibility of avoidance from the avoidance element. The occurrence-of-event element does not appear, because the graph rates the function on the assumption that the demand on it occurs. At the low end, S1 F1 P1 lands on PLr a; at the high end, irreversible injury with frequent exposure and no realistic chance of avoidance lands on PLr e. The graph itself, and what it takes to build a circuit that reaches PLd, are set out in full on the machine safety compliance page.
The table below shows where each entry in the specification comes from.
| Entry in the safety requirements specification | Where it comes from in the assessment |
|---|---|
| Function name and the hazard it covers | The hazard register line |
| Triggering condition and the mode it applies in | The task and mode analysis from the limits |
| Required response and safe state: stop, speed limit, hold | The step-two measure chosen for that hazard |
| Response time and stopping performance the layout allows | Space limits, then the detection distance calculation |
| Reset, restart, muting and manual mode behaviour | The tasks identified for setup, teach and fault clearing |
| Required Performance Level | The ISO 13849-1 risk graph, fed from the severity, exposure and avoidance estimate |
What the assessment does not decide is also worth stating. Category, architecture, diagnostic coverage and components are design decisions under ISO 13849-1 made to reach the PLr. Validation of the built circuit is ISO 13849-2, which checks the machine against this specification by analysis and by test, so a vague specification costs twice: once when the controls engineer has to invent the requirement, and once when validation has nothing definite to test against. What gets exercised at the factory and how it is recorded is set out in our factory acceptance test checklist.
Where the selected measure is collaborative operation, specify the functions needed for that application. Power and force limiting uses assessed contact scenarios; speed and separation monitoring uses protective-distance and stopping requirements. The validation evidence for each is described in our guide to ISO/TS 15066 and collaborative robots.
Who Should Carry Out a Machine Risk Assessment?
The machine manufacturer retains responsibility for the assessment, but a competent multidisciplinary team or external assessor may prepare and review it. For an integrated line, identify the party responsible for the whole assembly and the information required from each machine supplier. That division is one of the scope decisions on a packaging line integration project.
Who is in the room matters more than who signs. On a machine we design, the mechanical designer who owns the layout carries the limits and step one, the controls engineer who owns the safety circuit carries step two and the safety requirements specification, and the customer’s operators and maintenance staff supply the modes, the tasks and the misuse that neither engineer can know from a drawing. Their contribution is the difference between a hazard list about the machine and a hazard list about the machine in that plant.
External machine risk assessment services have a place. When a legacy machine has no builder to go back to and no file, somebody has to build the register from nothing before any modernisation can be scoped, and when a plant wants an independent review of a builder’s file, a second pair of eyes on the assumptions is worth having. Three questions sort a useful provider from a paper one: whether they will walk the machine in each operating mode with the people who work in it, whether they produce a safety requirements specification or only a hazard list, and which editions of ISO 12100 and ISO 13849-1 they assess against.
Which Documents Should a Risk Assessment Produce?
ISO 12100 requires the assessment to be documented, and it says what the documentation has to show: the machine the assessment refers to, including its limits; the hazards identified; the information the assessment was based on, including the data used, its sources and the uncertainty in it; the objectives to be achieved by the protective measures; the measures implemented; the residual risks; the result of the evaluation; and any forms completed along the way. That is the content. The form is free, and on a custom machine the practical set is six documents that together make one file.
| Document | What it contains | What it feeds |
|---|---|---|
| Limits statement | Use, space, time and other limits; the operating modes; who is present in each | Every other document; the intended use section of the handbook |
| Hazard register | One line per hazard: origin, zone, task and mode, person exposed, hazardous event | Risk estimation |
| Risk estimation record | Severity, exposure, occurrence and avoidance per hazard, before and after measures, with the assumptions written out | Evaluation; the ISO 13849-1 risk graph |
| Risk reduction record | Per hazard: step-one options considered, step-two measure chosen, step-three item, and the evaluation result | The design; the safety requirements specification |
| Safety requirements specification | One entry per safety function with trigger, response, safe state, timing, modes, reset and PLr | Safety circuit design under ISO 13849-1; validation under ISO 13849-2 |
| Residual risk list | What remains after all measures, per hazard | The instruction handbook and the warnings on the machine |
A machine risk assessment template, if one is used, is the register with these columns fixed. Version the file against the machine revision it describes, because an assessment that cannot be tied to a specific drawing set is an assessment of some machine, and a reviewer cannot tell which. The wider technical file this assessment sits inside, with the calculation record, the validation report and the declaration, is listed on the machine safety compliance page.
When Does an Existing Machine Need Its Assessment Reopened, and How Do You Keep That Bounded?
An assessment describes a machine configuration, its use and the standards basis selected for it. Review it when a new product, rate, mode, tool, location or user task changes the limits; when a modification changes a hazard or stopping performance; or when a safety function is altered. A revised standard is a reason to review relevant gaps, not proof that every existing circuit needs replacing or that only its calculations need updating.
Start a reassessment from the existing register and the proposed changes. Review machine limits, affected hazards, interfaces and safety functions, including hazards introduced by the modification. Record the evidence for measures that remain suitable and update the design, calculations and validation where needed. A standards-edition review follows the same gap-assessment process: revised requirements may affect hazard assessment as well as control-system calculations.
One change escapes that bounding. Where the modification is large enough that the machine is in effect a new one, the whole file reopens and the party doing the work takes the manufacturer’s position, with the conformity work that follows. Where that line sits is a judgement made per project, and it has to be settled before the scope of a machine retrofit is fixed, because settling it afterwards means reopening the scope. A legacy machine that arrives with no register at all is a different case again: the register is built first, from the machine as found, and the decision about how much to modernise is taken from it.
What Changes Under the EU Machinery Regulation for a Machine Assessed This Year?
For machinery placed on the EU market, Regulation (EU) 2023/1230 applies from 20 January 2027. Before that date, machinery must still comply with Directive 2006/42/EC. The European Commission’s machinery guidance allows an additional statement of conformity with the Regulation where applicable. Plan the assessment around the intended placing-on-the-market date, including the new requirements when a project spans the change.
What the Regulation adds to the assessment is scope. It is the first EU machinery law to put software integrity, updates and connected functions alongside mechanical safety, which reaches back into the first step of ISO 12100. The limits statement has to cover the network connection the machine has and who may change its safety configuration, the hazard identification then includes corruption of safety-related software and commands the machine was not meant to receive, and the safety requirements specification records how the safety configuration is protected from change. None of that alters the method. It adds lines to the same register.
How Do You Turn the Assessment Into a Build and Test Plan?
Link each risk-reduction measure to a drawing, control-function specification, test or instruction. Review that register at design approval and during the build, then close each item against evidence from the completed machine. This keeps the assessment useful to the designer, commissioning engineer and eventual operator.