A machinery risk assessment that is not a formality
The sequence ISO 12100 asks for, why the hierarchy of controls is in that order, and the residual risk nobody wants to write down.
Short answer
ISO 12100 sets the sequence: determine the limits of the machine, identify the hazards, estimate the risk, evaluate whether it is acceptable, and reduce it if not, then repeat. Reduction follows a strict hierarchy: design it out first, then guard it, then warn about it and provide procedures. Protective devices come third, not first, and jumping to them is the most common way an assessment becomes paperwork.
There are two kinds of machinery risk assessment. One shapes the machine. The other is written afterwards to describe a machine that already exists, and exists to fill a section of the technical file.
The difference is timing, and it is worth being honest about which one is being produced.
The sequence
ISO 12100 sets it out as a loop, and the loop matters as much as the steps.
- Determine the limits. Use, space, time and other limits. Every mode the machine will be in, including cleaning, setting, fault finding and decommissioning.
- Identify the hazards. Mechanical, electrical, thermal, noise, vibration, radiation, material, ergonomic, environmental. In every mode, not just production.
- Estimate the risk. Severity of harm, and probability of it occurring, which is itself exposure, occurrence and avoidability.
- Evaluate. Is that acceptable?
- Reduce. If not, apply the hierarchy, then go back to the start, because the measure you added may have introduced something new.
The loop is where guarding introduces a crush point, or an interlock introduces a reason to defeat it. Assessments that run once and stop miss these entirely.
The hierarchy, and why the order is fixed
Inherently safe design. Remove the hazard. Lower the force, slow the movement, put the pinch point out of reach, use a smaller motor, drain the stored energy automatically.
This is the only measure that cannot be defeated, worn out, disconnected or forgotten. It is also the only one that is nearly free if it is done early and nearly impossible once the machine is built. That is the entire argument for doing the assessment at concept stage.
Safeguarding. Fixed guards, interlocked guards, light curtains, laser scanners, safety mats. Effective, and dependent on being fitted, working and not defeated.
Information for use. Warning signs, manuals, training, safe systems of work. This is last because it relies wholly on a person doing the right thing, and people under production pressure at three in the morning are the least reliable component in any system.
The maintenance mode problem
Most machines are assessed in production mode and used in several others.
The guard has to come off to change a tool. The interlock has to be bypassed to teach a robot. The machine has to run with the door open to see why the part is jamming.
If the assessment does not cover those modes, the machine has no safe way to do them, and what actually happens is that somebody works out an unsafe way. Safe speed monitoring, enabling devices and hold to run controls exist for exactly this, and they only get specified if the assessment asks the question.
Writing down the residual risk
The step everybody skips. After all the reduction, some risk remains, and ISO 12100 asks for it to be stated so the user can manage it.
It feels like an admission. It is actually the opposite: an assessment claiming zero residual risk is one nobody will believe, and the specific residual risks are what the manual, the training and the site's own procedures have to address.
Where the control system comes in
Only after all of this. The required Performance Level for each safety function is an output of the risk assessment, not an input to it.
Deciding to fit a PL d safety relay and then writing the assessment to justify it is the tail wagging the dog, and it is visible to anyone who reads the two documents together.
Common questions
- What is the hierarchy of controls in machinery safety?
- Inherently safe design first, remove the hazard or reduce it at source. Then engineering controls, guarding and protective devices. Then information for use: warnings, signs, procedures and training. The order matters because each step down relies more on people behaving as expected.
- When should a risk assessment be done?
- At design, before the concept is fixed, because that is when inherently safe design is still cheap. Then again after any modification, and after any incident or near miss. An assessment produced at the end of a build to satisfy a file is a description, not an assessment.
- What are the limits of the machine?
- Use limits, who operates it and in what modes; space limits, its movement envelope and the space needed around it; time limits, its lifetime and maintenance intervals; and other limits, materials, environment and interfaces. Skipping this step is why hazards during maintenance get missed.
Keep reading
- Safety
SIL or PL: which one does your machine need?
Two standards, two scales, and one machine. Which one applies, how they map to each other, and why the answer is usually ISO 13849.
- Safety
Categories B, 1, 2, 3 and 4, in plain terms
Five architectures, what a single fault does to each, and the practical wiring that goes with them.
- Safety
Safety relay or safety PLC: how to decide
One is a wiring decision, the other is a programming one. The count of safety functions, not the size of the machine, is what settles it.