The worst place to start selecting standards for machine safeguarding measures is the declaration of conformity for a similar machine. Yet that is exactly where many projects begin.
The risk assessment is still open. Nobody knows how operators will clear jams, whether they can reach over the guard, or whether hazardous motion stops before a person reaches it. Even so, someone asks: “Which standards are we putting in the declaration?”
The answer is already waiting on a desk: EN ISO 12100, a relevant type-C standard and several familiar type-B standards. Copy, paste, sign. The document looks professional.
But what has actually been signed?
Listing a standard without limiting its application is not merely a statement that the manufacturer knows its number. It indicates that the applicable requirements were implemented, that the standard’s scope matches the machine, that the relevant hazards were addressed and that the resulting solution was verified.
Where is the evidence? Which hazard led to the guard? Why is guard locking necessary? What establishes the safety distance? Which required Performance Level, or PLr, applies to the safety function? What proves that the complete system stops quickly enough?
If those questions cannot be answered, the standards list is not evidence of conformity. It is a list of technical claims the manufacturer may be unable to defend.
Adding EN ISO 13857 to a declaration does not prevent someone reaching a danger zone. EN ISO 14119 does not make an interlocking device resistant to defeat. EN ISO 13849-1 does not automatically give a safety function its required Performance Level. Every cited standard must leave a visible trail through the design, calculations, tests and risk assessment.
Machine safeguarding measures begin with residual risk
Safeguarding and/or complementary protective measures form the second step of the three-step risk reduction method in EN ISO 12100. They come after inherently safe design measures have been properly considered—a stage examined in the first part of this series.
The machine may still need to cut. A press still needs force. A robot must move. Rollers must draw in material, and a workpiece may remain hot long after the process ends. Removing every hazardous property could also remove the function for which the machine exists.
The first question is therefore whether risk can be reduced through geometry, energy limits, technology or a different allocation of tasks. Can a crushing point be eliminated? Can motion be slower? Can an adjustment point be moved? Does the operator need to put a hand into that part of the machine at all?
Only when those options have genuinely been assessed—and residual risk remains—should the project move to safeguarding. A frozen three-dimensional model is not evidence that inherently safe design has been exhausted. Neither is a released production drawing or a schedule that makes redesign inconvenient.
At this stage, the questions become practical:
- Is access needed during normal production?
- Does access occur once a week or every few seconds?
- How long does hazardous motion continue after a stop command?
- Can the machine eject material, fluid or broken tooling?
- Can a person remain behind the protective device without being detected?
- What will workers actually do during cleaning, setup, fault finding and jam clearing?
The answers determine the safeguarding strategy. A fixed guard can be ideal where access is not required. Where frequent intervention is necessary, that same guard may become an obstacle that workers repeatedly remove. An interlocked movable guard may then be more suitable. If a person can reach the hazard before it has ceased, interlocking alone may not be enough; guard locking may be required.
A light curtain can detect access and initiate a stop. It cannot contain an ejected workpiece, stop a fluid jet or control dust emissions. A physical guard may contain those hazards, but a poorly designed guard can make routine adjustment so difficult that defeating the interlock becomes predictable.
There is no universally “good safeguard” independent of the task, access pattern and machine behaviour.
One guard does not mean one standard
A drawing shows one transparent door. The declaration lists EN ISO 14120. Is the matter closed?
No. The door may block one access route, but even that has not yet been proven effective.
Start with the guard itself. Can it withstand foreseeable impact? Will it contain an ejected part? Will its mountings remain secure after thousands of opening cycles? Does it create a new crushing point at the hinge? Will the material retain its properties at the machine’s operating temperature? These are questions addressed by EN ISO 14120.
A strong door can still fail as a safeguard if someone can reach over it, pass beneath it or insert a hand through an opening. Guard dimensions and location must therefore be linked to safety distances and opening sizes, typically using EN ISO 13857 and, where relevant, provisions addressing minimum gaps that prevent crushing.
Then comes the next issue: what happens when the door opens? If the hazard ceases before access is possible, an interlocked guard may be sufficient. If hazardous motion continues longer than the access time, guard locking may be needed to prevent opening until the hazard has stopped. EN ISO 14119 addresses interlocking principles, guard locking and measures to minimise foreseeable defeat.
In the control-system-based arrangement described here, the interlocking device supplies information about guard position. The safety-related control system must process that signal and command the final control elements so that the machine reaches the defined safe state.
The required Performance Level applies to the complete safety function—not merely to the switch mounted beside the door.
| Decision required | Technical basis | Evidence to confirm |
|---|---|---|
| Guard construction and strength | EN ISO 14120 | Material, mountings, resistance to foreseeable loads and absence of new hazards |
| Ability to reach the danger zone | EN ISO 13857 | Guard height, distance, clearances and opening dimensions |
| Need for interlocking or guard locking | EN ISO 14119 | Hazard cessation time, access time, locking logic and resistance to defeat |
| Safety-function design | EN ISO 13849-1 or EN IEC 62061 | PLr or required SIL, architecture and achieved integrity of the complete function |
| Safety-function validation | EN ISO 13849-2 or the applicable validation provisions of EN IEC 62061 | Correct behaviour under normal conditions and foreseeable faults |
| Prevention of unexpected start-up | EN ISO 14118 and, depending on the design, EN 60204-1 | No automatic restart and safe energy isolation where required |
This is not a ready-made list to paste into a declaration. Two visually similar guards can require different solutions. One machine may stop almost immediately; another may have a flywheel that continues turning for several seconds. One guard may only prevent access, while another must also contain ejected objects or emissions.
Type-B standards are not a universal package attached to a particular device. Each answers a different technical question generated by the risk assessment.
A type-C standard does not replace the risk assessment
It is tempting to trust a standard whose title names the machine: lathe, press, mobile elevating work platform or packaging machine. If a type-C standard exists, the easy assumption is that the major decisions have already been made.
The title is not enough. A type-C standard covers a defined category of machinery and specified significant hazards, hazardous situations and hazardous events. It may prescribe a safeguarding measure, a safety function, a PLr or a test method. Where its provisions differ from type-A or type-B standards, the type-C provisions take precedence for machines within its scope—but only for the matter covered by that difference.
The manufacturer must still check:
- whether the exact machine variant falls within scope;
- whether optional equipment or an unusual operating method is covered;
- whether integration with other machinery changes the hazards;
- which hazards are expressly excluded;
- which normative references must be applied;
- which site-specific tasks remain outside the standard.
A type-C standard also does not make type-B standards disappear. It often tells the designer which ones to use. It may require a guard while leaving detailed construction requirements to EN ISO 14120. It may require an interlocking device and refer to EN ISO 14119. It may specify the PLr while leaving the safety-related control system design and validation to EN ISO 13849-1, EN ISO 13849-2 or EN IEC 62061.
This distinction matters. EN ISO 13849-1 provides a design method for safety-related parts of control systems. It does not decide which safety functions a particular machine needs, nor does it assign the PLr for every application. Those decisions must come from the applicable type-C standard or a defensible risk assessment.
EN 280 illustrates why there is no single PL for a machine
The EN 280 series for mobile elevating work platforms demonstrates the function-based approach. It does not assign one convenient Performance Level to the entire platform. It identifies individual safety functions and gives requirements that reflect the consequences of their failure.
Platform levelling, load and moment control, gate interlocking and emergency stopping do not necessarily have the same PLr. A failure of levelling can create a different hazardous event from a failure of a platform gate interlock. The type-C standard therefore allocates requirements to specific functions, not to the machine as a single block.
EN ISO 13849-1 can then be used to design the control-system parts that perform those functions, while EN ISO 13849-2 supports validation. The type-C standard defines what must be achieved; the type-B standards provide methods for designing and demonstrating it.
Adding equipment can also create a new hazardous situation and therefore a new safety function. This is why the type-C standard must be read as a technical specification, including its scope, exclusions, significant hazards, detailed requirements and normative references—not as a ready-made declaration of conformity.
Presumption of conformity comes from application, not citation
A declaration containing EN ISO 12100, a type-C standard and several type-B standards may look convincing. But presumption of conformity does not arise because standard numbers were typed into a document.
Under Article 7(2) of Machinery Directive 2006/42/EC, presumption of conformity results from actual application of a harmonised standard whose reference has been published in the Official Journal of the European Union. It applies only to the essential health and safety requirements covered by that standard.
Article 20 of Machinery Regulation (EU) 2023/1230 retains the same core logic and expressly recognises conformity with the applicable parts of harmonised standards. The Regulation generally applies from 20 January 2027, replacing the Directive, subject to its transitional provisions.
For the Commission’s official interpretation, see the Guide to application of the Machinery Directive, especially §§ 110 and 383. The Guide is explanatory and does not replace the legal act.
A declaration records the outcome of conformity assessment. It does not create conformity.
A current standard is not automatically a harmonised standard
Before citing a standard, verify more than its title and publication year:
- Was the exact edition referenced in the Official Journal?
- Was it published for the legal act governing the machine?
- Does the publication include a restriction?
- Which essential requirements are covered according to Annex ZA?
- Does the scope match the machine and the specific application?
- Was the entire standard applied, or only identified clauses?
A technically current and valuable standard may not yet provide presumption of conformity under the applicable legislation. A harmonised standard may also be used only in part. In that case, the presumption extends only to the applied provisions and the related essential requirements.
If a manufacturer lists a standard without qualification, a market-surveillance authority may reasonably expect all applicable provisions to have been implemented. Partial application is permissible; presenting partial application as full conformity is not.
| Issue | Directive 2006/42/EC | Regulation (EU) 2023/1230 |
|---|---|---|
| Source of presumption | Actual conformity with a harmonised standard referenced in the Official Journal | Actual conformity with a harmonised standard or applicable part referenced for the Regulation |
| Extent of presumption | Only essential requirements covered by the standard | Only essential requirements covered by the standard or applied part |
| Standards in the declaration | References to applied harmonised standards are provided where appropriate | References to applied harmonised standards, including the date on which each reference was published in the Official Journal, or to applied common specifications and other technical specifications with the dates required by Annex V |
| Partial application | The extent should be identified so full application is not implied | The applied parts must be clearly identified |
| Manufacturer’s responsibility | Signing confirms completion of the applicable conformity-assessment procedure | Drawing up the declaration means accepting responsibility for machine conformity |
This is why a declaration copied from an “almost identical” machine is particularly dangerous. Similar appearance does not mean identical hazards. The same guard type does not mean the same access pattern. Similar controls do not establish the same PLr. Even the correct type-C standard may have a narrower scope than someone assumed from the machine name.
Three questions for every standard in the declaration
For every cited standard, the manufacturer should be able to answer:
- Which hazard or essential requirement made this standard relevant?
- Which design feature, safeguarding measure or subsystem implements its requirements?
- Which calculation, drawing, inspection or test result proves that implementation?
If those answers are missing, the standard number is decoration—and potentially a false technical claim.
Machine safeguarding measures form a system, not a checklist
Consider an interlocked guard with guard locking. It is one visible safeguard, but it performs several jobs. It creates a physical barrier, restricts reach, works with an interlocking device, may remain locked until the hazard ceases, initiates a stop through the control system, discourages defeat and must not trigger unexpected start-up when closed.
That is not excessive standardisation. It is one real safeguard divided into its actual engineering problems.
Legislation states the safety outcomes a machine must achieve. Standards describe technical methods that can support those outcomes. The relationship is therefore a network, not a one-standard-to-one-requirement mapping.
| Technical problem or safeguarding measure | Typical type-B standards | Regulation — Annex III | Directive — Annex I | What the technical documentation should contain |
|---|---|---|---|---|
| Fixed or movable guard and reach into a danger zone | EN ISO 14120; EN ISO 13857 | 1.3.7, 1.3.8, 1.4.1, 1.4.2 | 1.3.7, 1.3.8, 1.4.1, 1.4.2 | Guard design and mounting, strength, opening dimensions, safety distances, and reach over, under or around the guard |
| Interlocked guard, with guard locking where necessary | EN ISO 14119; EN ISO 14120; EN ISO 13849-1 and EN ISO 13849-2, or EN IEC 62061 | 1.2.1, 1.2.3, 1.4.1, 1.4.2.2 | 1.2.1, 1.2.3, 1.4.1, 1.4.2.2 | Safety-function specification, hazard cessation time and access time, guard-locking method, resistance to defeat, PLr or SIL, and validation |
| Light curtain, scanner or other electro-sensitive protective equipment | EN ISO 13855; EN IEC 61496 series; EN ISO 13849-1 and EN ISO 13849-2, or EN IEC 62061 | 1.2.1, 1.2.3, 1.3.7, 1.3.8, 1.4.1, 1.4.3 | 1.2.1, 1.2.3, 1.3.7, 1.3.8, 1.4.1, 1.4.3 | Resolution and protective field, bypass possibilities, separation-distance calculation, measured stopping time, restart prevention, and validation of the function |
| Prevention of unexpected start-up and energy isolation | EN ISO 14118; EN 60204-1; where relevant, EN ISO 4413 or EN ISO 4414 | 1.2.3, 1.2.6, 1.6.3, 1.6.4 | 1.2.3, 1.2.6, 1.6.3, 1.6.4 | Register of energy sources, isolation and lockout arrangements, dissipation of stored energy, and restart tests |
| Emergency-stop function | EN ISO 13850; EN 60204-1; EN ISO 13849-1 or EN IEC 62061 | 1.2.1, 1.2.4.3 | 1.2.1, 1.2.4.3 | Span of control, stop category, command priority, reset method, prevention of automatic restart, and functional-test results |
| Safety function performed by the control system | EN ISO 13849-1 and EN ISO 13849-2, or EN IEC 62061 | 1.2.1 and the requirement applicable to the function being performed; in certain cases also 1.1.9 | 1.2.1 and the requirement applicable to the function being performed | Function specification, PLr or required SIL, architecture, reliability data, common-cause failures, software, calculations, and validation |
| Permanent means of access to operating and maintenance positions | EN ISO 14122 series | 1.5.15, 1.6.2 | 1.5.15, 1.6.2 | Rationale for selecting the means of access, dimensions, loads, slip-resistant surfaces, fall protection, and the ability to perform the task safely |
This table is a map of engineering questions, not a declaration template. The exact legal coverage must be checked against the relevant edition’s Annex ZA and Commission Implementing Decision (EU) 2023/1586, as amended.
The transition from the Machinery Directive to the Machinery Regulation requires particular care. A harmonised-standard reference published for the Directive cannot simply be assumed to provide the same presumption under the Regulation. The relevant publication, edition, restrictions and legal coverage must be verified for the applicable act.
Identical numbering also does not guarantee identical legal content. The Regulation expands several control-system and protection requirements, including concerns relating to external influences, safety-related limit settings, software, configuration and protection against corruption. A citation to EN ISO 13849-1 cannot automatically prove every cybersecurity or tamper-resistance requirement.
Compliant components do not prove that a safety function is valid
The light curtain has a declaration. The safety controller has impressive data. The interlocking device is intended for safety applications, and the contactors have the reliability values needed for calculation.
Has the safety function been demonstrated? Not yet.
A light curtain detects interruption of its field and changes its outputs. The logic system must process that signal correctly. The final control elements must remove or safely control energy. The machine must then reach a state in which the person cannot be injured.
The complete function is:
person detected → signal processed → final elements actuated → hazard ceased → restart controlled
One weak link can make every component certificate practically irrelevant.
The design must state exactly what happens when a guard opens or a protective field is interrupted. Which hazardous movements stop? Is prevention of start sufficient, or must existing motion also stop? Must the guard remain locked? What happens after power loss and restoration? Can closing the guard initiate motion? Where is reset performed, and can the person resetting the system see the protected area?
If those questions have no defined answers, the project has selected devices but has not defined a safety function.
PLr applies to a function, not the whole machine
The required Performance Level is assigned to a specific safety function. It may come from a type-C standard or from the risk assessment.
A safety controller capable of PL e does not automatically make the complete function PL e. The achieved result depends on the entire chain: input devices, logic, final control elements, architecture, diagnostics, resistance to common-cause failures, software and integration.
A capable controller can still be part of a deficient function where:
- an input-device fault is not detected;
- both channels can fail from the same cause;
- the final switching element is not monitored;
- an operating mode bypasses part of the function;
- software does not cover all foreseeable states;
- reset is placed where a person can remain inside the protected area;
- power restoration can cause unexpected movement.
The component manufacturer does not validate the integrator’s software, wiring segregation, reset location, actuator selection or final machine behaviour.
An achieved PL does not answer every safeguarding question
A calculation may confirm PL d exactly as required. That still does not establish that a light curtain is far enough from the hazard, a guard prevents reach, a suspended load will not fall after drive isolation, or the real stopping time matches the design assumption.
PL describes the ability of safety-related control-system parts to perform a specified safety function. It does not replace assessment of protective-device location, guard strength, hazard cessation time, stored energy or foreseeable human behaviour.
Nor does a PL or SIL calculation automatically demonstrate cybersecurity. Functional-safety standards can support control-system integrity, but detailed protection against malicious or unauthorised interference requires its own assessment under the applicable legal and technical framework.
A calculation is not validation
A software report can support the architecture, reliability data and achieved PL. It cannot open the guard, interrupt the light curtain, exercise every operating mode, simulate all specified faults or measure the completed machine’s stopping performance.
Validation requires analysis and testing. EN ISO 13849-2 calls for the specified safety function, category and achieved PL to be validated through appropriate analysis and tests.
Until that work is complete, the project may have suitable components and a plausible design. It does not yet have evidence that the safeguarding measure has reduced risk adequately.
Machine behaviour must be verified on the completed machine
Assume the safety function is specified, PL is calculated and the light curtain has been positioned using a separation-distance formula. The final step is testing.
That is often when the machine proves that it stops more slowly than the design assumed.
The correct response is not to search for a more favourable test result, repeat the measurement without load or dismiss the difference as small. Testing is not performed to prove that the designer was right. It is performed to determine whether the designer was right.
If the result contradicts the design assumptions, change the design—not the result.
EN ISO 12100 requires risk reduction to be evaluated after each step. The designer must also check whether the selected safeguarding measure creates a new hazard, increases another risk, conflicts with other measures or makes work so difficult that foreseeable defeat becomes more likely.
| Measure or function | What to verify | Typical evidence | When to check again |
|---|---|---|---|
| Fixed or movable guard | Mounting, strength, openings, reach over, under and around the guard, and new crushing points | Inspection, dimensional measurements, calculations and strength tests where needed | After changes to construction, position, mounting or the surrounding workplace |
| Interlocked guard with guard locking | Stopping of the correct motions, operation in every mode, hazard cessation time, unlocking, reset and restart behaviour | Functional-test protocol and safety-function validation | After changes to the sensor, lock, software, drive, brake or operating modes |
| Light curtain or scanner | Every access direction, bypass possibilities, undetected presence, total stopping performance and actual separation distance | Distance calculation, stopping-time measurement and protective-field challenge tests | After changes to safety parameters, software, load, drive, braking or device position |
| Emergency stop | Span of control, priority, stopping method and behaviour after release | Tests of every device in all relevant operating modes | After control changes, machine zoning changes or integration with other machinery |
| Energy isolation | All energy types, locking capability, dissipation of stored energy and absence of restart | Isolation test, energy-source diagram and verification of the zero-energy state | After electrical, pneumatic, hydraulic or mechanical changes |
| Control-system safety function | Response to demands and faults, diagnostics, software, final elements and achievement of the safe state | Analysis, PL or SIL calculations and tests on the completed machine | After any change that can affect the function, even if no protective device was replaced |
Measure the stopping performance of the complete system
For a light curtain or scanner, the response time stated in the device documentation is only one part of total stopping performance. The complete time includes at least:
- the maximum time from intrusion into the detection zone to the protective device changing output state;
- signal transmission and safety-logic processing;
- actuation of contactors, valves, drives or braking systems;
- the mechanical time until the hazardous function actually ceases.
Load, temperature, valve switching, brake wear, component ageing and mechanical condition can all affect the result. The designer needs a conservative value that reflects the longest foreseeable stopping performance and measurement uncertainty—not an average of the most favourable tests.
EN ISO 13855 relates minimum separation distance to total system stopping performance using a relationship commonly expressed as S = (K × T) + C, subject to the detailed provisions of the applicable edition. If total time T increases, the required distance S increases.
This is why changing one safety-controller timing parameter can invalidate a previous separation-distance calculation. The protective device has not moved, but the function reacts more slowly, so its location may no longer be safe.
Return to the risk assessment after testing
A successful functional test does not close the process. A guard may prevent access to moving parts while creating a hinge crushing point. A locked gate may trap a person inside a fenced area. A light curtain may stop motion correctly while allowing someone to pass through and remain undetected between the field and the machine.
After testing, ask again:
- Does the measure work for every foreseeable task and operating mode?
- Can it be bypassed or can someone remain on the wrong side?
- Has it introduced another hazard?
- Will performance remain acceptable through foreseeable wear?
- Does the documentation define when the test must be repeated?
Installation shows what was built. Verification and renewed risk evaluation show whether it actually reduced risk.
Seven recurring safeguarding mistakes
1. Choosing the device before defining the problem
“We will put a light curtain here” is not a safeguarding specification. First establish who approaches, why access is needed, how often it occurs, whether the hazard can stop quickly enough and whether someone can pass through the field and remain undetected.
A light curtain is not a modern version of a guard. It is a different protective measure for different access conditions and hazard behaviour.
2. Ignoring the type-C standard—or treating it as the complete answer
One designer lists the type-C standard but never checks its normative references. Another uses only type-B standards even though the applicable type-C standard specifies a particular safeguard, safety function, PLr or test method.
The correct approach is to examine scope, exclusions, significant hazards, specific requirements and normative references. Hazards outside the type-C standard still require assessment.
3. Treating one guard as one standard and one checklist item
Compliance with EN ISO 14120 does not answer questions about reach, interlocking, guard locking, stopping time, control-system integrity, resistance to defeat or unexpected restart. One physical safeguard can trigger several distinct technical requirements.
4. Assuming the latest standard is automatically harmonised
A European designation and a recent publication date do not establish legal status. Check the exact edition, the applicable legal act, Official Journal reference, restrictions and Annex ZA coverage.
5. Using component documents instead of validating the function
A declaration for a light curtain, safety controller or interlocking device does not prove that the integrated machine stops the right motion, stops quickly enough or prevents dangerous restart. Component conformity supports the design; it does not validate the completed function.
6. Treating a calculation as a test result
Catalogue response times and design calculations may omit load, brake performance, valves, communications, tolerances, software delays and wear. A calculation predicts how the machine should behave. Testing shows how it does behave.
7. Failing to reassess risk after installation
A new guard can create a crushing point. Guard locking can trap a person. A protective field can permit undetected presence. An impractical setup procedure can encourage defeat. These are consequences of the safeguarding decision and must be included in the iterative risk assessment.
The correct chain is:
hazard and human task → legal requirement → protective measure or safety function → applicable standards → design → verification → renewed risk evaluation
Only after that chain is complete should the final list of standards be prepared.
How to engineer machine safeguarding measures under EN ISO 12100
1. Start with the risk remaining after inherently safe design
Do not write only “mechanical hazard.” Describe the hazardous situation: who is exposed, during which task, by what access route, to which hazard source and with what credible consequence.
Feeding material every cycle may need a different solution from weekly cleaning or full-body entry during jam clearing.
2. Check for an applicable type-C standard
Verify the machine category, variants, scope, exclusions, covered hazards, required safeguards, specified safety functions, PLr or SIL requirements, test methods and normative references. Record hazards that the type-C standard does not cover.
3. Define the required protective outcome
Before choosing hardware, state what the protection must achieve. It may need to prevent access, detect approach or presence, stop motion before a person reaches the hazard, keep a guard locked, limit speed or force, isolate energy or enable safe escape.
4. Specify every safety function
A useful specification identifies the initiating event, hazardous machine functions to be controlled, safe state, maximum response time, applicable operating modes, fault behaviour, reset and restart conditions, and required PLr or SIL.
5. Break the solution into technical problems
A guard raises questions about construction and reach. A locking device raises questions about access time, hazard cessation and defeat. A stopping function raises questions about inputs, logic, final elements and validation. Servicing raises questions about energy isolation, safe access and trapping.
Only now should the relevant type-B standards and exact editions be selected.
6. Design for real work
Can operators see the process? How will they clear jams? Can they remain behind a protective device? Is reset outside the danger zone with a clear view? Can anyone be locked inside? Does the safeguard make the intended task unreasonably difficult?
Safeguards must work during real production, maintenance and fault recovery—not only during a carefully staged acceptance demonstration.
7. Set acceptance criteria before testing
Define the maximum stopping time, minimum separation distance, required PL or SIL, permitted opening dimensions, expected fault response, restart behaviour, emergency-stop span of control and guard-release conditions before tests begin.
8. Verify and validate
Depending on the solution, this can require calculations, inspection, dimensional measurement, access testing, stopping-time measurement, fault simulation, software review, mode-by-mode functional testing and PL or SIL validation.
Record the machine configuration, test conditions, instruments, measured values, acceptance criteria, result and responsible person. “Test passed” without those details is weak evidence.
9. Re-evaluate risk
Confirm that the original risk is adequately reduced, no unacceptable new hazard has been created, the measures work together and foreseeable defeat has not been encouraged. Identify residual risks and the information that must be provided to users.
Minimum decision-and-evidence matrix
For each significant hazardous situation, the technical documentation should preserve a traceable path from the risk to the proof of effectiveness.
| Field | What to record |
|---|---|
| Hazard and hazardous situation | Source of harm, exposed person, task, access route, zone and credible consequence |
| Outcome of inherently safe design | Why the hazard could not be eliminated or sufficiently reduced by design |
| Type-C standard | Scope decision, applicable requirement and hazards outside its coverage |
| Safeguarding measure | Guard, protective device or complementary protective measure selected |
| Safety function | Required behaviour, safe state, response time, PLr or SIL |
| Type-B standards | Standards addressing each technical part of the solution |
| Legal requirements | Applicable provisions of the Machinery Directive or Machinery Regulation |
| Acceptance criterion | Required value or behaviour established before testing |
| Verification and validation | Method, measured result, calculation, protocol and final report |
| New and residual risks | Outcome of renewed evaluation and required user information |
A simple documentation quality test is to choose one hazard and trace it forward to a specific test result. Then start with that test result and trace it backward to the design decision and legal or technical requirement it confirms.
If the path stops at a standard number, the file contains a list—not an engineering justification.
This is the relationship a digital risk assessment should preserve: from the hazard and human task, through the applicable requirement, measure and standard, to the verification result. Safety Software is designed to preserve that decision trail rather than merely store a longer list of standards.
Conclusion: a standards list does not design a safe machine
Effective safeguarding does not begin by choosing a guard, light curtain or safety controller. It begins with the residual risk left after inherently safe design, the actual tasks people perform and the behaviour of the machine.
The next steps are to examine the applicable type-C standard, define the required protective outcome, specify each safety function and select the type-B standards that address the separate technical parts of the solution.
One standard does not necessarily correspond to one legal requirement, and one requirement does not necessarily lead to one standard. A single guard can raise issues involving construction, safety distances, interlocking, guard locking, control-system integrity, energy isolation and maintenance access.
For every cited standard, the manufacturer should be able to identify the originating hazard, the implemented design measure and the calculation, inspection or test that proves compliance. The same discipline applies to component documentation: a light curtain’s declaration does not prove its separation distance, a controller’s data does not prove the program, and an interlocking device’s marking does not prove that the hazard stops before access.
The final answer comes from verification on the completed machine. Does the guard prevent access? Does opening it stop every relevant hazardous motion? Does the lock remain engaged long enough? Is the protective device positioned using the measured total stopping performance? Can reset or power restoration cause unexpected movement?
If a test contradicts the design, the design must change. After that change, the risk assessment and affected validation activities must be revisited.
Paper accepts any standard. The machine gives its answer during testing—and that answer must be preserved in the technical documentation.
Technical and regulatory references
The core technical framework discussed here includes EN ISO 12100 for machinery risk assessment and risk reduction; EN ISO 14120 for guards; EN ISO 13857 for safety distances; EN ISO 14119 for interlocking devices; EN ISO 13849-1 and EN ISO 13849-2 for safety-related control-system design and validation; EN IEC 62061 for functional safety; EN ISO 13855 and the EN IEC 61496 series for positioning and electro-sensitive protective equipment; EN ISO 14118 for prevention of unexpected start-up; EN ISO 13850 for emergency stopping; EN 60204-1 for electrical equipment; EN ISO 4413 and EN ISO 4414 for hydraulic and pneumatic systems; and the EN ISO 14122 series for permanent means of access.
EU legislation and Commission documents
- Directive 2006/42/EC
- Regulation (EU) 2023/1230
- Commission Implementing Decision (EU) 2023/1586, as amended
- Guide to application of the Machinery Directive 2006/42/EC, edition 2.3
- The “Blue Guide” on the implementation of EU product rules
The applicable legal framework and presumption of conformity must be checked against the legislation, the current Commission publication of harmonised-standard references and Annex ZA of the exact standard edition used. Commission guidance can assist interpretation, but it is not legally binding; the legislation and Official Journal publications take precedence.