technical protective measures in machinery
TL;DR
  • Select safeguards based on the risk assessment, operator tasks, and machine behavior—not by copying standards from another declaration.
  • Each cited standard must be supported by design decisions, calculations, tests, and documentation demonstrating effective risk reduction.
  • Guards, safety distances, interlocks, guard locking, and control functions form an integrated system that usually requires several standards.
  • The choice of safeguards depends on access frequency, stopping time, ejection hazards, reach possibilities, and foreseeable attempts to defeat the protection.
  • A list of standards does not prove conformity unless the manufacturer can trace each hazard to a verified risk-reduction measure.

The worst place to start selecting standards for machine safeguarding measures is the declaration of conformity for a similar machine. Yet that is exactly where many projects begin.

The risk assessment is still open. Nobody knows how operators will clear jams, whether they can reach over the guard, or whether hazardous motion stops before a person reaches it. Even so, someone asks: “Which standards are we putting in the declaration?”

The answer is already waiting on a desk: EN ISO 12100, a relevant type-C standard and several familiar type-B standards. Copy, paste, sign. The document looks professional.

But what has actually been signed?

Listing a standard without limiting its application is not merely a statement that the manufacturer knows its number. It indicates that the applicable requirements were implemented, that the standard’s scope matches the machine, that the relevant hazards were addressed and that the resulting solution was verified.

Where is the evidence? Which hazard led to the guard? Why is guard locking necessary? What establishes the safety distance? Which required Performance Level, or PLr, applies to the safety function? What proves that the complete system stops quickly enough?

If those questions cannot be answered, the standards list is not evidence of conformity. It is a list of technical claims the manufacturer may be unable to defend.

Adding EN ISO 13857 to a declaration does not prevent someone reaching a danger zone. EN ISO 14119 does not make an interlocking device resistant to defeat. EN ISO 13849-1 does not automatically give a safety function its required Performance Level. Every cited standard must leave a visible trail through the design, calculations, tests and risk assessment.

Machine safeguarding measures begin with residual risk

Safeguarding and/or complementary protective measures form the second step of the three-step risk reduction method in EN ISO 12100. They come after inherently safe design measures have been properly considered—a stage examined in the first part of this series.

The machine may still need to cut. A press still needs force. A robot must move. Rollers must draw in material, and a workpiece may remain hot long after the process ends. Removing every hazardous property could also remove the function for which the machine exists.

The first question is therefore whether risk can be reduced through geometry, energy limits, technology or a different allocation of tasks. Can a crushing point be eliminated? Can motion be slower? Can an adjustment point be moved? Does the operator need to put a hand into that part of the machine at all?

Only when those options have genuinely been assessed—and residual risk remains—should the project move to safeguarding. A frozen three-dimensional model is not evidence that inherently safe design has been exhausted. Neither is a released production drawing or a schedule that makes redesign inconvenient.

At this stage, the questions become practical:

  • Is access needed during normal production?
  • Does access occur once a week or every few seconds?
  • How long does hazardous motion continue after a stop command?
  • Can the machine eject material, fluid or broken tooling?
  • Can a person remain behind the protective device without being detected?
  • What will workers actually do during cleaning, setup, fault finding and jam clearing?

The answers determine the safeguarding strategy. A fixed guard can be ideal where access is not required. Where frequent intervention is necessary, that same guard may become an obstacle that workers repeatedly remove. An interlocked movable guard may then be more suitable. If a person can reach the hazard before it has ceased, interlocking alone may not be enough; guard locking may be required.

A light curtain can detect access and initiate a stop. It cannot contain an ejected workpiece, stop a fluid jet or control dust emissions. A physical guard may contain those hazards, but a poorly designed guard can make routine adjustment so difficult that defeating the interlock becomes predictable.

There is no universally “good safeguard” independent of the task, access pattern and machine behaviour.

One guard does not mean one standard

A drawing shows one transparent door. The declaration lists EN ISO 14120. Is the matter closed?

No. The door may block one access route, but even that has not yet been proven effective.

Start with the guard itself. Can it withstand foreseeable impact? Will it contain an ejected part? Will its mountings remain secure after thousands of opening cycles? Does it create a new crushing point at the hinge? Will the material retain its properties at the machine’s operating temperature? These are questions addressed by EN ISO 14120.

A strong door can still fail as a safeguard if someone can reach over it, pass beneath it or insert a hand through an opening. Guard dimensions and location must therefore be linked to safety distances and opening sizes, typically using EN ISO 13857 and, where relevant, provisions addressing minimum gaps that prevent crushing.

Then comes the next issue: what happens when the door opens? If the hazard ceases before access is possible, an interlocked guard may be sufficient. If hazardous motion continues longer than the access time, guard locking may be needed to prevent opening until the hazard has stopped. EN ISO 14119 addresses interlocking principles, guard locking and measures to minimise foreseeable defeat.

In the control-system-based arrangement described here, the interlocking device supplies information about guard position. The safety-related control system must process that signal and command the final control elements so that the machine reaches the defined safe state.

The required Performance Level applies to the complete safety function—not merely to the switch mounted beside the door.

Decision required Technical basis Evidence to confirm
Guard construction and strength EN ISO 14120 Material, mountings, resistance to foreseeable loads and absence of new hazards
Ability to reach the danger zone EN ISO 13857 Guard height, distance, clearances and opening dimensions
Need for interlocking or guard locking EN ISO 14119 Hazard cessation time, access time, locking logic and resistance to defeat
Safety-function design EN ISO 13849-1 or EN IEC 62061 PLr or required SIL, architecture and achieved integrity of the complete function
Safety-function validation EN ISO 13849-2 or the applicable validation provisions of EN IEC 62061 Correct behaviour under normal conditions and foreseeable faults
Prevention of unexpected start-up EN ISO 14118 and, depending on the design, EN 60204-1 No automatic restart and safe energy isolation where required

This is not a ready-made list to paste into a declaration. Two visually similar guards can require different solutions. One machine may stop almost immediately; another may have a flywheel that continues turning for several seconds. One guard may only prevent access, while another must also contain ejected objects or emissions.

Type-B standards are not a universal package attached to a particular device. Each answers a different technical question generated by the risk assessment.

A type-C standard does not replace the risk assessment

It is tempting to trust a standard whose title names the machine: lathe, press, mobile elevating work platform or packaging machine. If a type-C standard exists, the easy assumption is that the major decisions have already been made.

The title is not enough. A type-C standard covers a defined category of machinery and specified significant hazards, hazardous situations and hazardous events. It may prescribe a safeguarding measure, a safety function, a PLr or a test method. Where its provisions differ from type-A or type-B standards, the type-C provisions take precedence for machines within its scope—but only for the matter covered by that difference.

The manufacturer must still check:

  • whether the exact machine variant falls within scope;
  • whether optional equipment or an unusual operating method is covered;
  • whether integration with other machinery changes the hazards;
  • which hazards are expressly excluded;
  • which normative references must be applied;
  • which site-specific tasks remain outside the standard.

A type-C standard also does not make type-B standards disappear. It often tells the designer which ones to use. It may require a guard while leaving detailed construction requirements to EN ISO 14120. It may require an interlocking device and refer to EN ISO 14119. It may specify the PLr while leaving the safety-related control system design and validation to EN ISO 13849-1, EN ISO 13849-2 or EN IEC 62061.

This distinction matters. EN ISO 13849-1 provides a design method for safety-related parts of control systems. It does not decide which safety functions a particular machine needs, nor does it assign the PLr for every application. Those decisions must come from the applicable type-C standard or a defensible risk assessment.

EN 280 illustrates why there is no single PL for a machine

The EN 280 series for mobile elevating work platforms demonstrates the function-based approach. It does not assign one convenient Performance Level to the entire platform. It identifies individual safety functions and gives requirements that reflect the consequences of their failure.

Platform levelling, load and moment control, gate interlocking and emergency stopping do not necessarily have the same PLr. A failure of levelling can create a different hazardous event from a failure of a platform gate interlock. The type-C standard therefore allocates requirements to specific functions, not to the machine as a single block.

EN ISO 13849-1 can then be used to design the control-system parts that perform those functions, while EN ISO 13849-2 supports validation. The type-C standard defines what must be achieved; the type-B standards provide methods for designing and demonstrating it.

Adding equipment can also create a new hazardous situation and therefore a new safety function. This is why the type-C standard must be read as a technical specification, including its scope, exclusions, significant hazards, detailed requirements and normative references—not as a ready-made declaration of conformity.

Presumption of conformity comes from application, not citation

A declaration containing EN ISO 12100, a type-C standard and several type-B standards may look convincing. But presumption of conformity does not arise because standard numbers were typed into a document.

Under Article 7(2) of Machinery Directive 2006/42/EC, presumption of conformity results from actual application of a harmonised standard whose reference has been published in the Official Journal of the European Union. It applies only to the essential health and safety requirements covered by that standard.

Article 20 of Machinery Regulation (EU) 2023/1230 retains the same core logic and expressly recognises conformity with the applicable parts of harmonised standards. The Regulation generally applies from 20 January 2027, replacing the Directive, subject to its transitional provisions.

For the Commission’s official interpretation, see the Guide to application of the Machinery Directive, especially §§ 110 and 383. The Guide is explanatory and does not replace the legal act.

A declaration records the outcome of conformity assessment. It does not create conformity.

A current standard is not automatically a harmonised standard

Before citing a standard, verify more than its title and publication year:

  • Was the exact edition referenced in the Official Journal?
  • Was it published for the legal act governing the machine?
  • Does the publication include a restriction?
  • Which essential requirements are covered according to Annex ZA?
  • Does the scope match the machine and the specific application?
  • Was the entire standard applied, or only identified clauses?

A technically current and valuable standard may not yet provide presumption of conformity under the applicable legislation. A harmonised standard may also be used only in part. In that case, the presumption extends only to the applied provisions and the related essential requirements.

If a manufacturer lists a standard without qualification, a market-surveillance authority may reasonably expect all applicable provisions to have been implemented. Partial application is permissible; presenting partial application as full conformity is not.

Issue Directive 2006/42/EC Regulation (EU) 2023/1230
Source of presumption Actual conformity with a harmonised standard referenced in the Official Journal Actual conformity with a harmonised standard or applicable part referenced for the Regulation
Extent of presumption Only essential requirements covered by the standard Only essential requirements covered by the standard or applied part
Standards in the declaration References to applied harmonised standards are provided where appropriate References to applied harmonised standards, including the date on which each reference was published in the Official Journal, or to applied common specifications and other technical specifications with the dates required by Annex V
Partial application The extent should be identified so full application is not implied The applied parts must be clearly identified
Manufacturer’s responsibility Signing confirms completion of the applicable conformity-assessment procedure Drawing up the declaration means accepting responsibility for machine conformity

This is why a declaration copied from an “almost identical” machine is particularly dangerous. Similar appearance does not mean identical hazards. The same guard type does not mean the same access pattern. Similar controls do not establish the same PLr. Even the correct type-C standard may have a narrower scope than someone assumed from the machine name.

Three questions for every standard in the declaration

For every cited standard, the manufacturer should be able to answer:

  1. Which hazard or essential requirement made this standard relevant?
  2. Which design feature, safeguarding measure or subsystem implements its requirements?
  3. Which calculation, drawing, inspection or test result proves that implementation?

If those answers are missing, the standard number is decoration—and potentially a false technical claim.

Machine safeguarding measures form a system, not a checklist

Consider an interlocked guard with guard locking. It is one visible safeguard, but it performs several jobs. It creates a physical barrier, restricts reach, works with an interlocking device, may remain locked until the hazard ceases, initiates a stop through the control system, discourages defeat and must not trigger unexpected start-up when closed.

That is not excessive standardisation. It is one real safeguard divided into its actual engineering problems.

Legislation states the safety outcomes a machine must achieve. Standards describe technical methods that can support those outcomes. The relationship is therefore a network, not a one-standard-to-one-requirement mapping.

Technical problem or safeguarding measure Typical type-B standards Regulation — Annex III Directive — Annex I What the technical documentation should contain
Fixed or movable guard and reach into a danger zone EN ISO 14120; EN ISO 13857 1.3.7, 1.3.8, 1.4.1, 1.4.2 1.3.7, 1.3.8, 1.4.1, 1.4.2 Guard design and mounting, strength, opening dimensions, safety distances, and reach over, under or around the guard
Interlocked guard, with guard locking where necessary EN ISO 14119; EN ISO 14120; EN ISO 13849-1 and EN ISO 13849-2, or EN IEC 62061 1.2.1, 1.2.3, 1.4.1, 1.4.2.2 1.2.1, 1.2.3, 1.4.1, 1.4.2.2 Safety-function specification, hazard cessation time and access time, guard-locking method, resistance to defeat, PLr or SIL, and validation
Light curtain, scanner or other electro-sensitive protective equipment EN ISO 13855; EN IEC 61496 series; EN ISO 13849-1 and EN ISO 13849-2, or EN IEC 62061 1.2.1, 1.2.3, 1.3.7, 1.3.8, 1.4.1, 1.4.3 1.2.1, 1.2.3, 1.3.7, 1.3.8, 1.4.1, 1.4.3 Resolution and protective field, bypass possibilities, separation-distance calculation, measured stopping time, restart prevention, and validation of the function
Prevention of unexpected start-up and energy isolation EN ISO 14118; EN 60204-1; where relevant, EN ISO 4413 or EN ISO 4414 1.2.3, 1.2.6, 1.6.3, 1.6.4 1.2.3, 1.2.6, 1.6.3, 1.6.4 Register of energy sources, isolation and lockout arrangements, dissipation of stored energy, and restart tests
Emergency-stop function EN ISO 13850; EN 60204-1; EN ISO 13849-1 or EN IEC 62061 1.2.1, 1.2.4.3 1.2.1, 1.2.4.3 Span of control, stop category, command priority, reset method, prevention of automatic restart, and functional-test results
Safety function performed by the control system EN ISO 13849-1 and EN ISO 13849-2, or EN IEC 62061 1.2.1 and the requirement applicable to the function being performed; in certain cases also 1.1.9 1.2.1 and the requirement applicable to the function being performed Function specification, PLr or required SIL, architecture, reliability data, common-cause failures, software, calculations, and validation
Permanent means of access to operating and maintenance positions EN ISO 14122 series 1.5.15, 1.6.2 1.5.15, 1.6.2 Rationale for selecting the means of access, dimensions, loads, slip-resistant surfaces, fall protection, and the ability to perform the task safely

This table is a map of engineering questions, not a declaration template. The exact legal coverage must be checked against the relevant edition’s Annex ZA and Commission Implementing Decision (EU) 2023/1586, as amended.

The transition from the Machinery Directive to the Machinery Regulation requires particular care. A harmonised-standard reference published for the Directive cannot simply be assumed to provide the same presumption under the Regulation. The relevant publication, edition, restrictions and legal coverage must be verified for the applicable act.

Identical numbering also does not guarantee identical legal content. The Regulation expands several control-system and protection requirements, including concerns relating to external influences, safety-related limit settings, software, configuration and protection against corruption. A citation to EN ISO 13849-1 cannot automatically prove every cybersecurity or tamper-resistance requirement.

Compliant components do not prove that a safety function is valid

The light curtain has a declaration. The safety controller has impressive data. The interlocking device is intended for safety applications, and the contactors have the reliability values needed for calculation.

Has the safety function been demonstrated? Not yet.

A light curtain detects interruption of its field and changes its outputs. The logic system must process that signal correctly. The final control elements must remove or safely control energy. The machine must then reach a state in which the person cannot be injured.

The complete function is:

person detected → signal processed → final elements actuated → hazard ceased → restart controlled

One weak link can make every component certificate practically irrelevant.

The design must state exactly what happens when a guard opens or a protective field is interrupted. Which hazardous movements stop? Is prevention of start sufficient, or must existing motion also stop? Must the guard remain locked? What happens after power loss and restoration? Can closing the guard initiate motion? Where is reset performed, and can the person resetting the system see the protected area?

If those questions have no defined answers, the project has selected devices but has not defined a safety function.

PLr applies to a function, not the whole machine

The required Performance Level is assigned to a specific safety function. It may come from a type-C standard or from the risk assessment.

A safety controller capable of PL e does not automatically make the complete function PL e. The achieved result depends on the entire chain: input devices, logic, final control elements, architecture, diagnostics, resistance to common-cause failures, software and integration.

A capable controller can still be part of a deficient function where:

  • an input-device fault is not detected;
  • both channels can fail from the same cause;
  • the final switching element is not monitored;
  • an operating mode bypasses part of the function;
  • software does not cover all foreseeable states;
  • reset is placed where a person can remain inside the protected area;
  • power restoration can cause unexpected movement.

The component manufacturer does not validate the integrator’s software, wiring segregation, reset location, actuator selection or final machine behaviour.

An achieved PL does not answer every safeguarding question

A calculation may confirm PL d exactly as required. That still does not establish that a light curtain is far enough from the hazard, a guard prevents reach, a suspended load will not fall after drive isolation, or the real stopping time matches the design assumption.

PL describes the ability of safety-related control-system parts to perform a specified safety function. It does not replace assessment of protective-device location, guard strength, hazard cessation time, stored energy or foreseeable human behaviour.

Nor does a PL or SIL calculation automatically demonstrate cybersecurity. Functional-safety standards can support control-system integrity, but detailed protection against malicious or unauthorised interference requires its own assessment under the applicable legal and technical framework.

A calculation is not validation

A software report can support the architecture, reliability data and achieved PL. It cannot open the guard, interrupt the light curtain, exercise every operating mode, simulate all specified faults or measure the completed machine’s stopping performance.

Validation requires analysis and testing. EN ISO 13849-2 calls for the specified safety function, category and achieved PL to be validated through appropriate analysis and tests.

Until that work is complete, the project may have suitable components and a plausible design. It does not yet have evidence that the safeguarding measure has reduced risk adequately.

Machine behaviour must be verified on the completed machine

Assume the safety function is specified, PL is calculated and the light curtain has been positioned using a separation-distance formula. The final step is testing.

That is often when the machine proves that it stops more slowly than the design assumed.

The correct response is not to search for a more favourable test result, repeat the measurement without load or dismiss the difference as small. Testing is not performed to prove that the designer was right. It is performed to determine whether the designer was right.

If the result contradicts the design assumptions, change the design—not the result.

EN ISO 12100 requires risk reduction to be evaluated after each step. The designer must also check whether the selected safeguarding measure creates a new hazard, increases another risk, conflicts with other measures or makes work so difficult that foreseeable defeat becomes more likely.

Measure or function What to verify Typical evidence When to check again
Fixed or movable guard Mounting, strength, openings, reach over, under and around the guard, and new crushing points Inspection, dimensional measurements, calculations and strength tests where needed After changes to construction, position, mounting or the surrounding workplace
Interlocked guard with guard locking Stopping of the correct motions, operation in every mode, hazard cessation time, unlocking, reset and restart behaviour Functional-test protocol and safety-function validation After changes to the sensor, lock, software, drive, brake or operating modes
Light curtain or scanner Every access direction, bypass possibilities, undetected presence, total stopping performance and actual separation distance Distance calculation, stopping-time measurement and protective-field challenge tests After changes to safety parameters, software, load, drive, braking or device position
Emergency stop Span of control, priority, stopping method and behaviour after release Tests of every device in all relevant operating modes After control changes, machine zoning changes or integration with other machinery
Energy isolation All energy types, locking capability, dissipation of stored energy and absence of restart Isolation test, energy-source diagram and verification of the zero-energy state After electrical, pneumatic, hydraulic or mechanical changes
Control-system safety function Response to demands and faults, diagnostics, software, final elements and achievement of the safe state Analysis, PL or SIL calculations and tests on the completed machine After any change that can affect the function, even if no protective device was replaced

Measure the stopping performance of the complete system

For a light curtain or scanner, the response time stated in the device documentation is only one part of total stopping performance. The complete time includes at least:

  • the maximum time from intrusion into the detection zone to the protective device changing output state;
  • signal transmission and safety-logic processing;
  • actuation of contactors, valves, drives or braking systems;
  • the mechanical time until the hazardous function actually ceases.

Load, temperature, valve switching, brake wear, component ageing and mechanical condition can all affect the result. The designer needs a conservative value that reflects the longest foreseeable stopping performance and measurement uncertainty—not an average of the most favourable tests.

EN ISO 13855 relates minimum separation distance to total system stopping performance using a relationship commonly expressed as S = (K × T) + C, subject to the detailed provisions of the applicable edition. If total time T increases, the required distance S increases.

This is why changing one safety-controller timing parameter can invalidate a previous separation-distance calculation. The protective device has not moved, but the function reacts more slowly, so its location may no longer be safe.

Return to the risk assessment after testing

A successful functional test does not close the process. A guard may prevent access to moving parts while creating a hinge crushing point. A locked gate may trap a person inside a fenced area. A light curtain may stop motion correctly while allowing someone to pass through and remain undetected between the field and the machine.

After testing, ask again:

  • Does the measure work for every foreseeable task and operating mode?
  • Can it be bypassed or can someone remain on the wrong side?
  • Has it introduced another hazard?
  • Will performance remain acceptable through foreseeable wear?
  • Does the documentation define when the test must be repeated?

Installation shows what was built. Verification and renewed risk evaluation show whether it actually reduced risk.

Seven recurring safeguarding mistakes

1. Choosing the device before defining the problem

“We will put a light curtain here” is not a safeguarding specification. First establish who approaches, why access is needed, how often it occurs, whether the hazard can stop quickly enough and whether someone can pass through the field and remain undetected.

A light curtain is not a modern version of a guard. It is a different protective measure for different access conditions and hazard behaviour.

2. Ignoring the type-C standard—or treating it as the complete answer

One designer lists the type-C standard but never checks its normative references. Another uses only type-B standards even though the applicable type-C standard specifies a particular safeguard, safety function, PLr or test method.

The correct approach is to examine scope, exclusions, significant hazards, specific requirements and normative references. Hazards outside the type-C standard still require assessment.

3. Treating one guard as one standard and one checklist item

Compliance with EN ISO 14120 does not answer questions about reach, interlocking, guard locking, stopping time, control-system integrity, resistance to defeat or unexpected restart. One physical safeguard can trigger several distinct technical requirements.

4. Assuming the latest standard is automatically harmonised

A European designation and a recent publication date do not establish legal status. Check the exact edition, the applicable legal act, Official Journal reference, restrictions and Annex ZA coverage.

5. Using component documents instead of validating the function

A declaration for a light curtain, safety controller or interlocking device does not prove that the integrated machine stops the right motion, stops quickly enough or prevents dangerous restart. Component conformity supports the design; it does not validate the completed function.

6. Treating a calculation as a test result

Catalogue response times and design calculations may omit load, brake performance, valves, communications, tolerances, software delays and wear. A calculation predicts how the machine should behave. Testing shows how it does behave.

7. Failing to reassess risk after installation

A new guard can create a crushing point. Guard locking can trap a person. A protective field can permit undetected presence. An impractical setup procedure can encourage defeat. These are consequences of the safeguarding decision and must be included in the iterative risk assessment.

The correct chain is:

hazard and human task → legal requirement → protective measure or safety function → applicable standards → design → verification → renewed risk evaluation

Only after that chain is complete should the final list of standards be prepared.

How to engineer machine safeguarding measures under EN ISO 12100

1. Start with the risk remaining after inherently safe design

Do not write only “mechanical hazard.” Describe the hazardous situation: who is exposed, during which task, by what access route, to which hazard source and with what credible consequence.

Feeding material every cycle may need a different solution from weekly cleaning or full-body entry during jam clearing.

2. Check for an applicable type-C standard

Verify the machine category, variants, scope, exclusions, covered hazards, required safeguards, specified safety functions, PLr or SIL requirements, test methods and normative references. Record hazards that the type-C standard does not cover.

3. Define the required protective outcome

Before choosing hardware, state what the protection must achieve. It may need to prevent access, detect approach or presence, stop motion before a person reaches the hazard, keep a guard locked, limit speed or force, isolate energy or enable safe escape.

4. Specify every safety function

A useful specification identifies the initiating event, hazardous machine functions to be controlled, safe state, maximum response time, applicable operating modes, fault behaviour, reset and restart conditions, and required PLr or SIL.

5. Break the solution into technical problems

A guard raises questions about construction and reach. A locking device raises questions about access time, hazard cessation and defeat. A stopping function raises questions about inputs, logic, final elements and validation. Servicing raises questions about energy isolation, safe access and trapping.

Only now should the relevant type-B standards and exact editions be selected.

6. Design for real work

Can operators see the process? How will they clear jams? Can they remain behind a protective device? Is reset outside the danger zone with a clear view? Can anyone be locked inside? Does the safeguard make the intended task unreasonably difficult?

Safeguards must work during real production, maintenance and fault recovery—not only during a carefully staged acceptance demonstration.

7. Set acceptance criteria before testing

Define the maximum stopping time, minimum separation distance, required PL or SIL, permitted opening dimensions, expected fault response, restart behaviour, emergency-stop span of control and guard-release conditions before tests begin.

8. Verify and validate

Depending on the solution, this can require calculations, inspection, dimensional measurement, access testing, stopping-time measurement, fault simulation, software review, mode-by-mode functional testing and PL or SIL validation.

Record the machine configuration, test conditions, instruments, measured values, acceptance criteria, result and responsible person. “Test passed” without those details is weak evidence.

9. Re-evaluate risk

Confirm that the original risk is adequately reduced, no unacceptable new hazard has been created, the measures work together and foreseeable defeat has not been encouraged. Identify residual risks and the information that must be provided to users.

Minimum decision-and-evidence matrix

For each significant hazardous situation, the technical documentation should preserve a traceable path from the risk to the proof of effectiveness.

Field What to record
Hazard and hazardous situation Source of harm, exposed person, task, access route, zone and credible consequence
Outcome of inherently safe design Why the hazard could not be eliminated or sufficiently reduced by design
Type-C standard Scope decision, applicable requirement and hazards outside its coverage
Safeguarding measure Guard, protective device or complementary protective measure selected
Safety function Required behaviour, safe state, response time, PLr or SIL
Type-B standards Standards addressing each technical part of the solution
Legal requirements Applicable provisions of the Machinery Directive or Machinery Regulation
Acceptance criterion Required value or behaviour established before testing
Verification and validation Method, measured result, calculation, protocol and final report
New and residual risks Outcome of renewed evaluation and required user information

A simple documentation quality test is to choose one hazard and trace it forward to a specific test result. Then start with that test result and trace it backward to the design decision and legal or technical requirement it confirms.

If the path stops at a standard number, the file contains a list—not an engineering justification.

This is the relationship a digital risk assessment should preserve: from the hazard and human task, through the applicable requirement, measure and standard, to the verification result. Safety Software is designed to preserve that decision trail rather than merely store a longer list of standards.

Conclusion: a standards list does not design a safe machine

Effective safeguarding does not begin by choosing a guard, light curtain or safety controller. It begins with the residual risk left after inherently safe design, the actual tasks people perform and the behaviour of the machine.

The next steps are to examine the applicable type-C standard, define the required protective outcome, specify each safety function and select the type-B standards that address the separate technical parts of the solution.

One standard does not necessarily correspond to one legal requirement, and one requirement does not necessarily lead to one standard. A single guard can raise issues involving construction, safety distances, interlocking, guard locking, control-system integrity, energy isolation and maintenance access.

For every cited standard, the manufacturer should be able to identify the originating hazard, the implemented design measure and the calculation, inspection or test that proves compliance. The same discipline applies to component documentation: a light curtain’s declaration does not prove its separation distance, a controller’s data does not prove the program, and an interlocking device’s marking does not prove that the hazard stops before access.

The final answer comes from verification on the completed machine. Does the guard prevent access? Does opening it stop every relevant hazardous motion? Does the lock remain engaged long enough? Is the protective device positioned using the measured total stopping performance? Can reset or power restoration cause unexpected movement?

If a test contradicts the design, the design must change. After that change, the risk assessment and affected validation activities must be revisited.

Paper accepts any standard. The machine gives its answer during testing—and that answer must be preserved in the technical documentation.

Technical and regulatory references

The core technical framework discussed here includes EN ISO 12100 for machinery risk assessment and risk reduction; EN ISO 14120 for guards; EN ISO 13857 for safety distances; EN ISO 14119 for interlocking devices; EN ISO 13849-1 and EN ISO 13849-2 for safety-related control-system design and validation; EN IEC 62061 for functional safety; EN ISO 13855 and the EN IEC 61496 series for positioning and electro-sensitive protective equipment; EN ISO 14118 for prevention of unexpected start-up; EN ISO 13850 for emergency stopping; EN 60204-1 for electrical equipment; EN ISO 4413 and EN ISO 4414 for hydraulic and pneumatic systems; and the EN ISO 14122 series for permanent means of access.

EU legislation and Commission documents

The applicable legal framework and presumption of conformity must be checked against the legislation, the current Commission publication of harmonised-standard references and Annex ZA of the exact standard edition used. Commission guidance can assist interpretation, but it is not legally binding; the legislation and Official Journal publications take precedence.

Frequently Asked Questions

What are technical protective measures in machinery according to ISO 12100?

Technical protective measures on machinery reduce exposure to hazards that could not be adequately eliminated through inherently safe design measures. These include guards, protective devices, interlocking devices, guard locking, and safety-related stop functions.

Their application constitutes the second step of the three-step risk reduction method described in ISO 12100. The protective measure must be selected based on the risk assessment, foreseeable human tasks, and machine behavior.

When can the design of technical safeguards begin?

The second step is taken only after genuinely analyzing the feasibility of eliminating hazards or reducing risk by changing the design, energy, process, or method of performing tasks.

The mere fact that the 3D model has been completed or production has started does not justify using a guard instead of improving the design. It must be demonstrated what residual risk remains and why it cannot be reduced sufficiently by inherently safe design measures.

How to choose between a fixed guard, a movable guard, and a light curtain?

A fixed guard is generally suitable when access to the hazardous zone is not required or is required only rarely. Where frequent access is needed, a movable guard with an interlocking device may be considered, while electro-sensitive protective equipment may be considered when the machine can be stopped safely before a person reaches the hazard.

A light curtain does not provide protection against ejected parts, splashes, radiation, or emissions. In such cases, a physical guard or a combination of several protective measures may be necessary.

When does a movable guard require guard locking?

Guard locking may be necessary when, after a stop command, the hazard has not ceased before access to the hazardous zone is possible. This applies, for example, to machinery with a long run-down time, residual pressure, or energy that cannot be dissipated safely and immediately.

The selection and design of interlocking devices and guard locking devices should be based on the risk assessment and the requirements of ISO 14119. The possibility of defeating the safeguard and the operator’s motivation to do so must also be considered.

How is the safe distance for a guard or protective device determined?

For guards, the possibility of reaching over, under, and through openings must be assessed in accordance with the relevant requirements of ISO 13857. The height of the guard alone is insufficient if its position or the size of the openings allows the hazard to be reached.

The position of a light curtain, scanner, or other sensing device depends, among other factors, on the overall stopping time and the person's approach speed. The principles for determining the positioning distances of protective devices are specified in ISO 13855.

Connect safeguards to your risk assessment

Document why guards, interlocks, and safety functions were selected for each identified hazard. Keep a clear record of decisions, calculations, and verification.

Create account