During machine acceptance, the manufacturer points to three reassuring sentences in the instructions: “Cleaning only after isolating all energy sources. Servicing by trained personnel only. The user shall prepare an appropriate procedure.” Three sentences, three boxes ticked.
On the factory floor, the machine turns out to have two electrical supplies, a pneumatic circuit and stored energy capable of causing movement after the main isolator has been switched off. The procedure does not yet exist, and “trained personnel” means the person who has worked there longest.
The machine has been safeguarded using the future tense.
ISO 12100 Step 3 does not mean placing everything that could not be resolved in the design into the instruction handbook. Information for use is the final element of the risk reduction strategy. It follows inherently safe design and safeguarding; it does not replace them.
If a hazard could have been eliminated, energy reduced, access prevented or a suitable safety function implemented, the manufacturer cannot substitute training, a pictogram or an instruction to “take special care”. The instructions must describe risk that genuinely remains after reasonable design and protective measures have been applied.
That does not make Step 3 a documentation afterthought. It is where the manufacturer’s engineering decisions meet the user’s organisation of work. The manufacturer identifies what remains, where it occurs, during which tasks and under which assumptions. The user turns that information into procedures, training, supervision, energy isolation, permit systems, additional controls and personal protective equipment.
Step 3 is therefore not a transfer of responsibility. It is a transfer of information without which safe work cannot be organised—and whose mere presence in a manual achieves nothing by itself.
1. Step 3 is not a cheaper version of Steps 1 and 2
The three stages of risk reduction are not equivalent options. A designer does not choose between changing the machine, fitting a safeguard and adding a warning according to whichever is cheapest or easiest to fit into the schedule. The order matters, including where protective measures could themselves introduce new hazards.
First, determine whether the hazard can be eliminated or reduced through inherently safe design. If that is insufficient, apply safeguarding and complementary protective measures. Only then should information for use address the residual risk.
Suppose adjustment requires a hand to enter the movement zone. The manufacturer could relocate the adjustment point, change the geometry, reduce the available energy, install a guard or interlock, or provide a safe setting mode. Writing “adjustment by trained personnel only” without examining those options is not Step 3. It is skipping two stops and wondering why the train has not left the platform.
Ask the uncomfortable question: What exactly was done in the design and safeguarding before deciding that the user must take further action?
A credible answer identifies the design analysis, the selected measure, its verification and the risk that remains. “We added a paragraph to the instructions” is not a credible answer. In that case, the manual is merely decoration covering the absence of the first two stages.
Information for use must not justify why a technically feasible measure was omitted. It should explain what could not be eliminated or sufficiently reduced despite the measures taken. Only then are we genuinely discussing residual risk.
Step 1 is addressed through inherently safe design measures, while Step 2 covers technical protective measures for machinery. Once those stages have been completed, information for use becomes an engineering output rather than a literary substitute for engineering.
2. The manufacturer must describe the risk, not soothe its conscience
Information is useful only if it enables a specific action. If the reader still cannot tell what may happen, during which task or how to prevent it, the manufacturer has supplied text—not necessarily information.
“Disconnect the machine from all energy sources before servicing” sounds sensible. Yet the main isolator will not dissipate hydraulic pressure, empty a pneumatic receiver, support a raised assembly or remove energy stored in a spring. Physics does not sign acceptance certificates.
Useful information should identify:
- the task and machine life-cycle phase in which exposure occurs;
- the location of the danger zone and the people who may be exposed;
- the hazardous event and its foreseeable consequences;
- the measures already implemented by the manufacturer;
- the residual risk after those measures;
- the precise action required from the user;
- the necessary competence, tools, procedures and protective equipment.
For example, replacing a component may require the user to isolate a named electrical supply, close and lock a specific valve, dissipate pressure, verify the absence of energy and mechanically support a raised assembly. That level of detail gives the user a sound basis for an isolation or lockout/tagout procedure, servicing instructions and practical training.
Placement matters too. A warning that requires immediate action should not exist only on page 143 of the handbook. Depending on the situation, information may also be required on the machine, at the isolation point, through warning devices or directly at the place where the task is performed. An operator should not have to conduct library research while a system is losing pressure.
Not every item must be phrased as a warning. Information for use should also define safe operating conditions: permitted materials, process limits, installation requirements, inspection intervals, required competence and prohibited activities linked to specific hazards. These conditions must follow from the assumptions used in the risk assessment, not from a late attempt to fill the “Safety” chapter.
Simply stating that there is residual risk in the machine is equally weak. The user does not manage an abstract term. The user manages a task, a person, an energy source and actual working conditions. Good information converts “risk remains” into “therefore, do exactly this”. Ambiguity between those statements tends to remain invisible until an incident forces everyone to explain it.
3. The manufacturer completes the design; the user organises the work
Figure 2 in ISO 12100 is uncomfortable for both parties. The manufacturer cannot finish the assessment with “further measures to be provided by the user”. Equally, the user cannot assume that CE marking has written the procedures, trained maintenance personnel and checked how faults are cleared on the night shift.
The standard distinguishes two levels of residual risk. The first remains after the designer has applied inherently safe design, safeguarding, complementary protective measures and information for use. The manufacturer must identify, assess and communicate it. The second level also reflects measures implemented by the machine user, including work organisation, procedures, supervision, permits, additional safeguards, personal protective equipment and training.
These are not two names for the same result. Implementation sits between them.
| The manufacturer communicates | The user implements |
|---|---|
| The residual-risk scenario | A task-specific working procedure |
| Conditions for safe use | Work organised within those conditions |
| Required personnel competence | Selection of personnel and confirmation of competence |
| Energy-isolation requirements | An isolation procedure, lockout/tagout controls and permits where needed |
| Need for additional protective measures | Their selection, installation and maintenance |
| Personal protective equipment requirements | Provision, correct use and inspection of that equipment |
| Inspection and maintenance requirements | A schedule and evidence that work was completed |
“User” does not mean only the operator pressing the start button. It includes the employer organising work, the maintenance manager, the supervisor authorising tasks, the technician carrying out an intervention and the operator following controls and reporting defects.
Each needs different information. Maintenance needs energy-isolation and safeguard-testing requirements. Supervisors need to know who may perform particular tasks. Operators need clear rules for normal production, adjustment, fault recovery and emergencies. Putting everything into a chapter called “General Notes” does not create a safety system. It creates a chapter that nobody wants to read.
This is also where the manufacturer’s machine risk assessment meets the employer’s workplace risk assessment. They are connected, but one cannot replace the other. The manufacturer assesses the machine within its intended use and reasonably foreseeable misuse. The employer must consider the actual workplace, environment, personnel, work organisation and process into which the machine has been integrated.
Cooperation does not mean splitting responsibility in half and settling it with a joint signature. Each party must complete its own work, and the manufacturer’s information must be detailed enough for the user to act intelligently.
4. A procedure works only when somebody actually uses it
Even perfect manufacturer information cannot close a valve, apply a lock, verify zero energy or prevent an unexpected restart. The user must organise those actions.
If energy isolation is required before clearing a blockage, the site should define at least:
- who may stop and isolate the machine;
- which energy sources must be isolated;
- where the isolation points are located;
- how they are secured against reconnection;
- how the absence of hazardous energy is verified;
- who may remove locks or other restraints;
- how the machine is returned to service.
Without those decisions, “apply lockout/tagout” is the name of a procedure, not a procedure.
The document must also match the real task. If a jam occurs repeatedly during every shift but the specified response requires a twenty-minute shutdown of the entire line, its fate is predictable. First comes an unofficial shortcut. Then a “good practice” known only to experienced workers. Eventually, somebody tapes an interlock out of the way because it is inconvenient.
That is not an argument for weakening the procedure. Frequent intervention may show that the machine design, process reliability or technical measures need another review. Effective Step 3 arrangements should feed such evidence back into the risk assessment rather than treating repeated workarounds as an operator problem.
Training works in the same way. An attendance sheet proves that several people occupied the same room. It does not prove that they can safely adjust, clean or service the machine. Training should cover real tasks, actual hazards, correct use of safeguards and responses to abnormal conditions. Competence should be checked in practice and reassessed after significant changes to the machine, process, procedure or job role.
Supervision must go beyond checking signatures. It should include observing work, verifying use of procedures, responding to defeated safeguards and investigating why shortcuts appear. One bypassed interlock may indicate individual misconduct. Five bypassed interlocks on one line also say something about machine design and production management.
Personal protective equipment needs the same precision. “Wear protective gloves” does not explain the hazard, required performance or whether gloves could create an entanglement risk near moving parts. Equipment must be selected for the specific task and conditions.
Controls are effective only when they are practicable, understood, properly resourced and checked. A laminated procedure can remain in perfect condition for years—especially if nobody ever touches it.
5. Good information for use leaves a trace
At acceptance, the designer remembers why the instructions require a particular mechanical support. Six months later, another person controls the documentation, the machine operates on a different line and the risk assessor is working on a new project.
All that remains is: “Service only after mechanically securing the assembly.” Why is support necessary? What movement could occur? Which component must be supported, and in what position? The answers probably exist somewhere inside a file named FINAL_risk_assessment_v8_revised_2.xlsx.
Information for use should be traceable to a specific risk scenario. The chain should run from the identified hazard, through design and technical measures, to verification, residual risk and the action required from the user.
A useful record may include:
- the task and machine life-cycle phase;
- the hazard source and possible hazardous event;
- exposed persons and foreseeable consequences;
- the risk reduction measures applied;
- verification results;
- the residual risk;
- information placed in the instructions or on the machine;
- the action required from the user;
- the person responsible for implementation;
- evidence of completion and effectiveness.
Evidence does not need to be another large report. It may be an approved procedure, safety-function test result, measurement record, competence confirmation, inspection record, photograph of a marking or a documented technical decision. What matters is that the evidence answers a specific requirement instead of merely stating that “safety was discussed”.
A folder full of documents is not traceability. One hundred adjacent files may still fail to explain why a decision was made. The important element is the connection between the scenario, selected measure, verification result, information for use and later action.
That chain must also survive change. A new material, tool, speed, machine location or cleaning method may invalidate assumptions made during design. The user must be able to identify which scenarios require reassessment without reading the entire technical file from page one. Waiting for a problem to expose the answer is a method too—rather like finding a leak by waiting until the pressure disappears.
In Safety Software, that chain should not end when a report is generated. The risk scenario, measure, verification, residual risk and evidence remain parts of one process. This makes it possible to reconstruct not only what was documented, but who made the decision, on what basis and what happened afterwards.
The practical test is simple: Can someone who did not participate in the project use the documentation to determine what risk remains and what action must be taken?
If the answer is yes, the manufacturer has communicated usable information. If not, the user has received a technical riddle with an attachment.