Cobot Safety Standards: An Engineer's Compliance Checklist
Back to Blog

Cobot Safety Standards: An Engineer's Compliance Checklist

August 19, 202613 min read

Cobot Safety Standards: An Engineer's Compliance Checklist

Engineer calibrating cobot safety sensors
Engineer calibrating cobot safety sensors

Three documents govern almost every collaborative robot deployment: ISO 10218-1 (robot design), ISO 10218-2 (cell integration and commissioning), and ISO/TS 15066 (collaborative-specific force and pressure limits). Functional safety standards, ISO 13849-1, IEC 61508, and IEC 62061, determine whether your safety controls actually perform to the required level. Regional overlays like the EU Machinery Regulation and ANSI/RIA R15.06 add legal teeth in their respective markets.

If you're starting a project today, stop and do this first:

  • Document a cell-level risk assessment following the ISO 12100 process before touching layout or programming.
  • Select the collaborative operation method(s) the application actually needs, not the one the robot vendor defaults to.
  • Verify force, pressure, or separation-distance calculations against real measurements, not marketing specs.
  • Record commissioning evidence, checksums, and sign-offs before the line runs production parts.

Everything below expands on why each step matters and how to execute it without gaps an auditor will find.

Key Takeaways

Cobot safety compliance works only when ISO 10218-1, ISO 10218-2, and ISO/TS 15066 are applied together at the cell level, with the end effector treated as part of the machine, not an accessory.

PointDetails
Use the core three standards togetherISO 10218-1 covers robot design, ISO 10218-2 covers cell integration, ISO/TS 15066 covers collaborative force limits.
Assess the whole cell as one machineInclude the end effector, payload, and layout in every risk assessment, not just the robot arm.
Match the operation method to the taskChoose SSM for speed and throughput, PFL for fenceless low-force work, based on actual risk, not vendor defaults.
Verify, don't assume, biomechanical limitsConfirm ISO/TS 15066 Annex A thresholds through measurement or validated calculation, not datasheet specs alone.
Document and control configurationKeep checksums, parameter records, and training logs version-controlled for audits and re-assessment triggers.
Get technical support for integration and verificationYslootahtech offers robotics integration and safety verification services to help close documentation and EOAT gaps before an audit.

Where to Verify Cobot Safety Requirements

  • ISO 10218-2:2025: application-level integration and commissioning requirements.
  • ISO/TS 15066: Annex A biomechanical limits for PFL.
  • EU-OSHA guidance: harmonized standards and legal conformity.
  • SafeWork NSW guidance: risk-assessment templates and stakeholder checklists.

Table of Contents

What Do Cobot Safety Standards Actually Require?

Each standard covers a different layer of the system, and confusing them is the most common compliance mistake engineers make.

ISO 10218-1 governs the robot manufacturer's side: design, inherent safety features, and the built-in collaborative capabilities a robot arm ships with. ISO 10218-2:2025, the counterpart integrators and end users actually work from, specifies requirements for robot-cell integration, commissioning, operation, maintenance, and decommissioning at the application level. Together with ISO/TS 15066, these form what the industry treats as the core international framework for collaborative robot safety.

ISO/TS 15066 fills the gap the base standards leave open: it supplies Annex A biomechanical limits, pain-onset thresholds by body region, and the methodology for power-and-force-limiting applications. Without it, you have no defensible way to justify a fenceless cobot cell to an auditor.

Functional safety standards answer a different question: does your safety control system perform reliably enough? ISO 13849-1 assigns Performance Levels (PLd, PLe), IEC 62061 and IEC 61508 use Safety Integrity Levels (SIL 2, SIL 3) for more complex electronic safety systems. Most cobot applications rely on ISO 13849-1's Category 3 architecture, but if your safety logic runs through a PLC-based safety controller, IEC 62061 often applies instead.

StandardScopePrimary user
ISO 10218-1Robot design, inherent safeguardsRobot manufacturer
ISO 10218-2Cell integration, commissioning, operationIntegrator / end user
ISO/TS 15066Collaborative force/pressure limitsIntegrator / end user
ISO 13849-1Performance Level verificationIntegrator / safety engineer
IEC 61508 / 62061SIL verification, complex electronicsSafety engineer

Regional rules layer on top. In the European Union, harmonized EN ISO 10218 standards and ISO/TS 15066 demonstrate conformity with machinery safety regulation, and the assessment treats the integrated cell as one machine, not a robot plus separate accessories. ANSI/RIA R15.06 plays a similar role in the United States, though it doesn't carry the same automatic legal presumption harmonized EU standards do.

What Are the Four Types of Collaborative Robot Operation?

Every cobot application falls into one of four operational categories, and picking the wrong one is where most projects go sideways.

  • Safety-rated monitored stop: the robot halts completely whenever a person enters the collaborative workspace, then resumes once they leave. Simple to implement, but it kills throughput if people are in the zone frequently.
  • Hand guiding: an operator physically moves the robot through a task using a guide device, with speed and force limits enforced throughout. Common in flexible assembly where paths change often.
  • Speed and separation monitoring (SSM): sensors track the distance between robot and person, slowing or stopping the robot as separation shrinks. This preserves speed when no one is nearby.
  • Power and force limiting (PFL): the robot itself is inherently limited so contact stays below injury thresholds, allowing continuous operation without fencing.

Each method carries its own verification burden. SSM demands validated sensor response times and calculated minimum separation distances. PFL demands force and pressure measurements against ISO/TS 15066 Annex A limits, not just a spec sheet claim from the robot vendor.

The trade-off is throughput versus flexibility. PFL supports fenceless layouts but usually caps speed and payload. SSM preserves productivity for higher-speed tasks but needs floor space and area scanners fences don't require.

Pro Tip: The single most common implementation mistake is verifying the robot arm's PFL rating and stopping there. The end effector, gripper edges, pinch points, and payload mass are what actually cause injury in most contact events, and they need their own force and pressure verification.

How Do You Run a Cobot Risk Assessment?

Risk assessment for collaborative applications follows the same logical sequence as ISO 12100, but with an extra verification layer ISO/TS 15066 requires.

  1. Identify hazards across the whole cell, robot, end effector, workpiece, fixtures, and the physical layout together, not the robot in isolation.
  2. Estimate risk for each hazard using severity, exposure frequency, and avoidance possibility.
  3. Select collaborative method(s) that reduce risk to an acceptable level for the specific task, not the method the integrator prefers.
  4. Verify effectiveness through measurement, calculation, or validated manufacturer data.
  5. Document residual risk and the justification for accepting it.

Verifying Annex A biomechanical limits can happen three ways: direct force/pressure measurement with a calibrated device, analytical calculation using the transient and quasi-static formulas in ISO/TS 15066, or manufacturer-supplied data for a specific end effector and payload combination. Measurement is the gold standard for novel EOAT designs; manufacturer data is acceptable only when the configuration matches the tested scenario exactly.

Your documentation file needs a hazard log, force measurement reports, safety parameter records, EOAT geometry drawings, and the inputs that feed your declaration of conformity. Integrators and end users own this documentation even when the robot arrives with OEM safety certifications already in place.

Pro Tip: When calculating SSM minimum separation distance, document the sensor's response time and the robot's stop time under load as measured during integration, rather than rely on nominal or datasheet figures. Auditors ask for the delta between the two.

What Safety Functions and Performance Levels Do Cobots Need?

Every collaborative application needs a defined set of safety functions, each mapped to a verified performance target.

  • Protective stop and emergency stop
  • Safety-rated monitored stop
  • Safe standstill and safe limited motion
  • Safe speed limiting
  • Safety-related control system monitoring (I/O, encoders, brakes)

Mapping these to a target isn't optional. Most cobot safety functions typically target a Performance Level under ISO 13849-1 that includes single-fault tolerance and diagnostic coverage, often around PLd Category 3. Complex electronic safety architectures, multi-zone SSM systems tied into a safety PLC, for instance, often need the full IEC 61508 or IEC 62061 verification path instead, with SIL 2 or SIL 3 targets depending on consequence severity.

Verification isn't a paperwork exercise. Confirm each of the following before sign-off:

  1. Measured response time for every safety input
  2. Correct stop category (0, 1, or 2) for each triggered condition
  3. Diagnostic coverage percentage against the PL/SIL target
  4. Parameter protection through checksums or passwords so safety settings can't drift unnoticed

A common compliance gap engineers overlook: end effector and payload hazards routinely go unassessed because teams treat the robot's PFL certification as covering the whole tool. EOAT geometry and carried mass often introduce contact risks the robot's own certification never accounted for, which is why the cell has to be assessed as a single machine, gripper included.

How Do You Commission and Maintain Cobot Compliance?

Compliance doesn't end at installation. It's a lifecycle process with checkpoints from procurement through every configuration change afterward.

  1. Factory acceptance testing where applicable, confirming safety functions before the system ships.
  2. On-site integration into the actual cell layout, fixtures, and workflow.
  3. Risk-assessment sign-off by the cross-functional team, not a single engineer.
  4. Biomechanical verification for any PFL configuration, using measurement where the setup is new.
  5. Operator training on safe interaction zones and stop behavior.
  6. Final acceptance testing with documented pass/fail criteria against the PL/SIL targets.

Configuration control matters as much as the initial validation. Keep parameter identifiers and checksums version-controlled so a firmware update or speed change doesn't silently invalidate your safety case. Maintenance and inspection schedules need to be written down, not assumed.

Set clear re-assessment triggers: any tool change, layout change, payload change, or reported incident should automatically restart part of the risk-assessment cycle. Our guide to robotics integration covers how that handoff between design and operations typically breaks down in practice.

Pro Tip: Train operators on why the safety zones exist, not just where they are. Retain training records, sign-off sheets, and revision history for every safety-parameter change. Auditors ask for the paper trail more often than the technical justification.

Why Do Human Factors Matter in Cobot Safety Design?

Technical compliance can be flawless and a cell can still be unsafe if the people working next to it don't trust the system or understand it.

Hands adjusting cobot gripper edges
Hands adjusting cobot gripper edges

Research on collaborative robot deployments points to psychosocial risks, worker trust, technostress, and perceived workload, as hidden vulnerabilities that standard risk assessments routinely miss. An operator who doesn't trust a stop function may override behavior in ways no PL rating anticipated.

Build your assessment team wider than engineering alone:

  • Maintenance staff, who catch wear patterns design teams never see
  • Operations personnel, who know the real workflow versus the documented one
  • Quality and design engineers, for foreseeable misuse scenarios
  • Safety and HR representatives, for training design and psychosocial monitoring

Operational controls that actually reduce risk: structured training, disciplined change management, clear workspace demarcation, and interface design that tells operators what the robot is about to do. Track near-miss logs and periodic surveys to catch emerging human-factor problems before they become incidents.

What Should Engineers Prioritize First When Deploying Cobots?

Three priorities separate compliant deployments from ones that pass initial inspection and fail six months later.

Treat the cell as one machine. That means the robot, gripper, workpiece, and layout get assessed together, every time, with no assumption that a manufacturer's PFL certification covers your specific end effector. Second, validate EOAT contact geometry directly, since gripper edges and pinch points cause more real-world injuries than the robot arm itself. Third, build a genuinely cross-functional assessment team and keep configuration control disciplined; a safety case built by one engineer in isolation rarely survives its first layout change.

We typically start engagements with a technical audit of the existing cell and documentation gap before recommending integration or monitoring work, which keeps the scope grounded in what a specific application actually needs rather than a generic checklist.

Get Expert Support for Cobot Safety Compliance

Yslootahtech helps manufacturers close the gap between "the robot has a safety certification" and "the cell is actually documented and compliant," through robotics integration support, safety verification work, and AI-enabled monitoring that flags drift in safety parameters before an audit does.

Yslootahtech
Yslootahtech

If your cobot deployment needs a technical review of its risk assessment, EOAT geometry, or configuration control records, our robotics services team can walk through what's missing. For plants layering predictive monitoring on top of existing safety systems, our AI and machine learning team can scope what data your current sensors already give you. Book a technical assessment to get a clear list of documentation gaps and next steps before your next audit, not after it flags a problem.

Frequently Asked Questions

Is ISO/TS 15066 mandatory, or just guidance? It's a Technical Specification, not a full International Standard, but it's the accepted method for verifying power-and-force-limiting applications. Skipping it leaves you with no defensible basis for a fenceless PFL cell.

Do ANSI/RIA R15.06 and ISO 10218 conflict? Not in substance. R15.06 largely adopts ISO 10218's requirements for the US market, though it doesn't carry the automatic legal presumption of conformity that harmonized EN ISO standards provide in the European Union.

Can a cobot be "collaborative certified" out of the box? The robot arm can meet ISO 10218-1 design requirements, but the full application, gripper, payload, and layout, still needs its own ISO 10218-2 risk assessment before you can call the cell compliant.

How often should a cobot risk assessment be reviewed? Any tool change, layout change, payload change, or reported near-miss should trigger a re-assessment. Routine periodic review on top of that is standard good practice under most regional guidance.

Sources

© 2026 All rights reserved

Footer Logo