Menu
Machinery Risk Assessment: The ISO 12100 Method in Practice

Machinery Risk Assessment: The ISO 12100 Method in Practice

How ISO 12100 actually works: determining the limits of the machine, sweeping hazards by life-cycle phase, estimating risk from severity and three probability inputs, and the three steps in their required order.
Machinery Risk Assessment: The ISO 12100 Method in Practice

Key takeaways

  • ISO 12100 is the parent standard: it gives you the risk assessment and risk reduction method. ISO 13849 covers how reliable a safety function must be, ISO 14119 the interlocking devices that implement it.
  • Risk reduction is a three-step method in a fixed order: inherently safe design, then safeguarding and complementary protective measures, then information for use.
  • Risk is estimated from severity of harm combined with probability of that harm, where probability breaks into three separate inputs: frequency and duration of exposure, probability of the hazardous event, and possibility of avoidance or limitation.
  • Hazard identification must sweep all life-cycle phases, not just normal running. Setting, cleaning, jam clearing, maintenance and decommissioning are where the guards are open.
  • Modifying a machine puts you back into the loop and can make the plant the manufacturer in law. A retrofit conveyor, a new guard, a bypassed interlock or a changed control system all re-open the assessment and the technical file.

What ISO 12100 is, and what it is not

ISO 12100 (General principles for design: risk assessment and risk reduction) is a type A standard. It will not tell you that a guard must be 1,400 mm high. Dimensions live in the type B and type C standards below it.

ISO 13849-1 is the reliability layer: once 12100 says you need a safety function, 13849 quantifies how trustworthy that function has to be, expressed as a required Performance Level (PLr). ISO 14119 is the device layer for interlocking with and without guard locking. Settle how interlocking devices are chosen and mounted before you specify anything.

In the EU, the essential health and safety requirements come from Directive 2006/42/EC until 20 January 2027, when Regulation (EU) 2023/1230 replaces it and brings substantial modification into explicit scope. What changed is set out in the new machinery regulation.

The iterative loop

ISO 12100 describes a loop, not a checklist: you determine the limits of the machine (space, time, use), identify hazards, estimate risk, evaluate whether risk reduction is required, apply a measure, and then go round again. The critical discipline is the return leg: after applying a protective measure you must re-run the hazard identification and the estimation, because measures create new hazards. Determining limits is the step teams rush: intended use, reasonably foreseeable misuse, number of operators, training level, shift pattern, ambient conditions, expected service life.

The three-step method, in the required order

Step 1: inherently safe design. Eliminate the hazard or reduce the risk by design. Reduce the gap so a finger cannot enter, or open it beyond the ISO 13854 minimum gap so a finger cannot be crushed. Record every step 1 option you considered and rejected, and the reason, before you move to step 2.

Step 2: safeguarding and complementary protective measures. Fixed guards, interlocked movable guards, light curtains, two-hand controls, pressure-sensitive mats, trip devices, plus the complementary measures: emergency stop, means of isolation and energy dissipation, provisions for safe manual intervention, provisions for lifting and access. Guard type follows how often access is genuinely needed: a fixed guard where entry is rare and can be planned as a tool-off job, an interlocked movable guard where operators need routine entry. No standard sets a numeric access threshold, so record the frequency you actually counted and the reasoning behind the choice. Guard geometry, by contrast, does have normative limits, from the reach distances and opening tables of ISO 13857, and the guard selection and geometry rules set the dimensions.

Step 3: information for use. Warning signs and markings, acoustic and visual signals, and the instruction handbook. It is last because it is the weakest: it depends on a human reading, remembering and complying under production pressure at 03:00.

Systematic hazard identification

Two axes, crossed. Sweep the life-cycle phases: transport and installation, commissioning, setting and changeover, normal operation, fault finding, cleaning, jam clearing, planned maintenance, and decommissioning. Then sweep the hazard types at each phase: mechanical (crushing, shearing, cutting, entanglement, drawing-in, impact, ejection), electrical, thermal, noise, vibration, radiation, materials and substances, ergonomic, and hazards from the environment and from control system failure.

Run it as a grid and the omissions become obvious: cleaning is almost always the worst row, guards off, machine on jog, an operator who has done it 400 times.

How risk is estimated

Risk is a function of severity of harm and probability of occurrence of that harm. Severity is graded by the nature and extent of injury. Probability decomposes into three inputs you should score separately:

  • Frequency and duration of exposure: how often does a person enter the danger zone, and for how long?
  • Probability of a hazardous event: component failure history, control reliability, human error rates, foreseeable misuse.
  • Possibility of avoidance or limitation: speed of the hazardous movement, awareness of the hazard, escape space, operator skill.

ISO 12100 does not mandate a scoring tool. Any method is acceptable if it is applied consistently and the reasoning is recorded. What is not acceptable is a single number with no visible inputs.

Residual risk, and where information for use belongs

Residual risk is the risk that remains after all protective measures have been applied, and declaring it honestly is a requirement. Information for use is a genuine step 3 risk reduction measure, but only for the residual risk that steps 1 and 2 could not remove. The failure mode is using information for use to replace steps 1 and 2: a warning sticker on a trap point that could have been guarded for 180 euros is not adequate risk reduction where design or guarding was practicable.

Who owns the assessment: bought versus modified

On a machine you buy new with a declaration of conformity, the manufacturer owns the risk assessment and the technical file. Your obligation as the user is the site-specific assessment for how it will be used, installed and interfaced, and keeping the protective measures in working order.

The moment you modify it, that changes. A new guard, a retrofit infeed conveyor, a changed control system, or a bypassed safety function all re-open the loop. If the modification introduces a new hazard or increases an existing risk, and the original manufacturer has not assessed it, the plant can become the manufacturer in law for the modified machine, with the full obligation set: risk assessment, technical file, conformity, marking, instructions.

What maintenance must keep

  • The current risk assessment per machine, with revision history and the trigger for each revision.
  • Evidence that safety functions are tested at the stated interval, with method and result, tied to the asset.
  • Records of modifications and bypasses, each tied to the reassessment and the verification test that closed it.
  • Interlock and guard integrity checks with measured values: overtravel, stopping time, gap dimensions.

Folding safety function verification into the preventive maintenance plan is what makes the evidence continuous rather than retrospective.

In Fabrico, safety verification runs as recurring PM tasks with checklists, and every result is stored against the specific asset, so the per-asset and per-function record is ready when an auditor asks. A failed check can trigger a follow-up task. If that is the record you are missing, book a short demo.

A worked example with real numbers

Machine: a belt conveyor feeding a carton former. Hazard: drawing-in at the infeed nip between the belt and the driven head roller, accessible through a 220 mm high side aperture used to straighten skewed cartons.

Determine limits. Belt speed 0.42 m/s. Nip located 160 mm inboard of the aperture edge. Two shifts of 8 hours, 5 days. Operators trained, no formal permit for the intervention.

Estimate risk. Severity: drawing-in at 0.42 m/s with a driven roller and no torque limiter gives finger or hand entrapment, degloving, plausibly amputation. Severity is serious and irreversible. Frequency and duration of exposure: log shows skew corrections at 14 times per shift, roughly 4 seconds each, so about 56 s per shift of hand-in-aperture time, 28 events per day. Probability of the hazardous event: nothing but hand placement keeps the hand out of the nip, so one slip, one snatched carton or one mis-timed reach is sufficient cause, and there is no torque limiter, no standstill detection and no permit step behind that single human error. Rate this input high. Possibility of avoidance: a hand drawn in at 0.42 m/s travels the 160 mm to the nip in about 380 ms, which is shorter than the time an operator needs to register the snag and pull the hand clear. Avoidance is scarcely possible. Evaluation: risk reduction is required, at the top of the scale.

Step 1, inherently safe design. Fitting a fixed V-profile guide rail 900 mm upstream of the head roller de-skews cartons mechanically. Trial over 6 shifts drops manual corrections from 14 to 2 per shift, cutting exposure to about 8 s per shift. Severity is unchanged, and 2 events per shift is still about 1,000 events a year, so step 1 alone is not sufficient.

Step 2, safeguarding. Close the aperture with a hinged interlocked guard. The safety function is: opening the guard removes drive power and brings the belt to rest. Measure the overall stopping performance T as the interlocking device's response time from its datasheet plus the contactor drop-out plus the belt and load run-down. The machine part alone is 310 ms measured from the switch changing state, which at 0.42 m/s is 130 mm of belt travel, and the device response time is added on top of that before T goes into the calculation.

Do the geometry the way ISO 13855 does it: compare the available distance with the required distance, not a human reach against the belt's residual travel. The required distance is S = K x T + C. Start at the hand and arm approach speed K of 2,000 mm/s, with T of 310 ms plus the device response time: 2,000 mm/s multiplied by 0.31 s gives 620 mm from the machine part alone. Because that exceeds 500 mm, ISO 13855 lets you repeat the calculation at K = 1,600 mm/s, which gives 496 mm from that same machine part, and adding the device response time pushes it back towards or past 500 mm. Either way the standard sets 500 mm as the minimum value of S. So the required distance is at least 500 mm before you add the intrusion distance C, against the 160 mm actually available. The chosen fix is a guard locking device to ISO 14119, so the guard cannot be opened until the belt is proven at rest. Locking removes the stopping distance calculation from the safety argument entirely.

Handover to the safety function designer. Using the ISO 13849-1 Annex A risk graph with S2 (serious, usually irreversible injury), F2 (chosen conservatively: each access is only about 4 seconds, but the intervention recurs at every shift for the whole machine life, and F1 would leave no margin if skew corrections rise again) and P2 (avoidance scarcely possible: P1 would mean avoidance possible under specific conditions, which a 380 ms draw-in does not allow) gives a required Performance Level of PLr e. It drives the architecture: category 4, or category 3 with high diagnostic coverage and high MTTFD, using a coded RFID interlock with guard locking wired to a safety relay with cross-fault detection. The detail of ISO 13849 performance levels covers how that PLr is achieved and verified.

Verdict and residual risk. After steps 1 and 2, residual risk is: guard locking device fails to a defeated state, or a person defeats it deliberately. Controls: defeat-resistant coded actuator, and a maintenance PM verifying the locking function every 3 months with the result recorded against the asset.

Common mistakes

  • Assessing only normal operation, so cleaning, jam clearing and setting never get a row in the grid.
  • Jumping to step 3, a warning label in the manual, for a hazard a guard would have removed.
  • Scoring probability as one vague judgement rather than separating exposure, hazardous event and avoidance.
  • Using the SOP figure for exposure frequency instead of counting real interventions per shift.
  • Treating a modification as a maintenance job, so the assessment and the technical file are never re-opened.
  • Recording "risk reduced to acceptable" with no trace of which step 1 options were considered and why they were rejected.
  • Applying a protective measure and stopping there, without running the return leg to check what the measure itself introduced.

Frequently asked questions

Does ISO 12100 tell me what guard height or safety distance to use?

No. ISO 12100 is a type A standard giving the method only. Dimensional requirements come from type B standards: ISO 13857 for safety distances and reach through openings, ISO 13855 for positioning relative to approach speed, ISO 14120 for guard construction, and ISO 13850 for emergency stop.

We bought a CE marked machine. Do we still need our own risk assessment?

Yes, a different one. The manufacturer assessed the machine as designed and as intended to be used. You must assess it as installed and as actually used on your site: the interfaces to upstream and downstream equipment, your access routes and cleaning method, and any foreseeable misuse specific to your process.

When does a modification make us the manufacturer?

Broadly, when the change introduces a new hazard or increases an existing risk beyond what the original manufacturer assessed; the trigger list is in the ownership section above. Routine like-for-like replacement with an equivalent component does not.

Is a bypassed interlock a modification?

In practice, yes, and an undocumented one. A jumper across a gate switch changes the machine's safety functions and therefore its risk profile. Treat bypasses as authorised, time-limited, recorded and closed out with a verification test.

How often should a risk assessment be reviewed?

On every trigger, plus a periodic review. Triggers are modification, a new intended use, an accident or near miss, a repeated protective device failure, a change in the applicable standard, and a change in operating pattern. A periodic review interval of 12 to 36 months depending on risk level is common practice.

Latest from our blog

Define Your Reliability Roadmap
Validate Your Potential ROI: Book a Live Demo
Define Your Reliability Roadmap
By clicking the Accept button, you are giving your consent to the use of cookies when accessing this website and utilizing our services. To learn more about how cookies are used and managed, please refer to our Privacy Policy and Cookies Declaration