What this is
What is a robot cell safety assessment?
What is a robot cell safety assessment?
It is a structured risk assessment of a specific robot cell, covering perimeter guarding, reach envelope, and, where the robot operates in collaborative mode, the speed, force and payload limits that assumption depends on. It is scored against ISO 10218 and ISO/TS 15066 and produces a residual risk band, not a pass/fail.
What does 'collaborative mode' actually change about the assessment?
A caged industrial robot is assessed on perimeter guarding and interlocking alone. A collaborative robot adds a further set of requirements: speed and separation monitoring, power and force limiting, and an end effector free of features that would turn a light contact into an injury. Those fields only apply when collaborative mode is in use, since they answer a question that doesn't exist for a caged robot.
Why does a layout change void the assessment rather than just needing an update?
The reach envelope, force limits and separation distances were validated for a specific geometry. Moving the cell, changing the end effector, or altering the payload changes that geometry, which means the original residual risk band no longer describes the cell as it now exists. The assessment has to be re-run, not amended.
Scope
When is a robot cell safety assessment required?
This assessment is scoped to one robot cell's design and operating mode. Using it to cover the wider machine it feeds, or a conveyor transfer point at the cell boundary, pushes findings into a record that cannot see the whole hazard.
Use this template when
- A new robot cell is being installed and needs a baseline assessment before production use
- The cell's programme, tooling, payload or layout has materially changed since the last assessment
- A periodic review is due under the site's Machine Safety programme schedule
- An incident, near miss or complaint involving the cell requires a fresh assessment
- A permit or customer standard specifically requires evidence the cell has been assessed
Do not use it for
- Machine Risk Assessment, which assesses a machine across its whole life, including setup, running, cleaning, clearing jams and maintenance.
- Guarding Verification Checklist, which confirms that guards fitted to a machine match the risk assessment and cannot be easily defeated.
- Interlock Function Test, which tests that safety interlocks stop the machine when a guard is opened, and cannot be bypassed.
- Conveyor and Transfer Safety Review, which covers the transfer points at the cell's boundary rather than the cell itself.
- Anything outside KnowSafe, which belongs in the workspace that owns that process
Compliance mapping
Which ISO 10218 requirements does this satisfy?
The template splits cleanly along the same lines as the standards it is built against: perimeter and interlocking design from ISO 10218, and the collaborative-specific limits from ISO/TS 15066, which only apply once collaborative mode is confirmed.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 10218-2 Clause 5 | Safety requirements for the integration and design of an industrial robot system, including perimeter safeguarding | Cell design |
| ISO 10218-2 Clause 5.10 | Requirements specific to collaborative robot operation | Collaborative operation |
| ISO/TS 15066 Clause 5.5.3 | Speed and separation monitoring as a collaborative operating method | Collaborative operation |
| ISO/TS 15066 Clause 5.5.4 | Power and force limiting, including biomechanical limits at the end effector | Collaborative operation |
| ISO 10218-1 Clause 5.7 | Restart control and presence sensing to prevent restart while a person is within the hazard zone | Cell design |
| ISO 10218-1 Clause 5.9 | Reduced speed control and enabling device requirements during teaching | Teaching and maintenance |
| ISO 10218-2 Clause 5.4 | Risk assessment must be repeated when the application, layout or end effector changes | Header |
What it does not cover
- A robot manufacturer's collaborative certification, which describes the robot in isolation, not this cell's actual end effector, payload and application.
- Perimeter guarding that was adequate for the original layout, when the reach envelope has since changed and no one re-mapped it.
- Presence sensing that stops the robot, without confirming it also prevents an automatic restart once the person has left and re-entered undetected.
- A teach pendant enabling device that functions, without confirming reduced speed is actually enforced while it is engaged.
- A residual risk band recorded as low, when the collaborative operation fields were left unscored because 'Collaborative Mode Used' was answered No by default rather than verified.
Global
Robot Cell Safety Assessment requirements by country
ISO 10218 and ISO/TS 15066 are the reference standards worldwide for robot and collaborative robot safety, but how much weight they carry depends on the certification regime and the customer standards layered on top locally.
ANSI/RIA R15.06 and RIA TR R15.606, aligned to ISO 10218 and ISO/TS 15066
The US robotics standard is a national adoption of the ISO robot safety framework, with RIA TR R15.606 the American technical guidance equivalent to ISO/TS 15066 for collaborative work.
A US site's assessment is judged against this national standard first, with the ISO documents as the underlying technical basis.
ISO 10218 as a harmonised standard under the Machinery Regulation
ISO 10218 carries a presumption of conformity for robot safety under EU machinery law, making a documented cell assessment part of the technical file behind a CE mark.
A gap between this assessment and the cell as installed is a gap in the conformity claim itself, not just an internal record.
ISO/TS 15066, Collaborative robots
ISO/TS 15066 is a technical specification, still evolving, but the only internationally recognised source for the biomechanical force and pressure limits power and force limiting is checked against.
A multinational site cannot substitute a local rule for these limits without a documented basis; no other international reference covers the same ground.
How to complete it
How to complete a robot cell safety assessment, step by step
The fields are straightforward to answer. The judgement is in deciding what the cell's actual configuration requires, rather than what its paperwork claims.
A robot capable of collaborative operation that in practice stays caged and never shares space with a person should be assessed as caged industrial. Marking Collaborative Mode Used as Yes when it isn't operated that way pulls in a whole section of requirements that don't reflect real risk.
Power And Force Limits Validated should reflect an actual measurement or documented calculation for this end effector and payload, not the robot's general biomechanical rating from the manufacturer. The two are routinely conflated, and it is the single most consequential call in the collaborative section.
Risk banding should be driven by the reasonably foreseeable worst case, such as a technician inside the envelope during an unplanned restart, not the routine operating scenario. A band set against the routine case will read as far safer than the cell actually is.
The Engineering Manager's Second Signature exists because a single assessor's judgement on force limits and risk banding benefits from independent scrutiny. Treating it as a formality defeats the reason it is there.
What auditors find
Most common robot cell safety assessment findings
The recurring gap is not bad guarding design; it is an assessment that described a cell configuration that has since quietly moved on.
| Finding | Clause | What fixes it |
|---|---|---|
| The end effector was changed for a different application but the collaborative assessment was never re-run | ISO 10218-2 Clause 5.4 | Treat any end effector, payload or application change as an automatic trigger for reassessment, and record it under Assessment Trigger as a plant change rather than periodic. |
| Power and force limits are recorded as validated based on the robot manufacturer's general specification | ISO/TS 15066 Clause 5.5.4 | Require a measurement or documented calculation specific to the installed end effector and payload before marking this field Yes. |
| Presence sensing stops the robot but does not prevent it restarting once the area appears clear | ISO 10218-1 Clause 5.7 | Verify the restart logic requires a deliberate reset outside the hazard zone, not just an absence of detected presence, and correct before the cell returns to service. |
| Reduced speed in teach mode is not actually enforced when the enabling device is engaged | ISO 10218-1 Clause 5.9 | Confirm the speed limit is enforced at the controller level during teach mode, not left to the programmer's judgement, and re-test before allowing further teaching access. |
| The reach envelope was mapped for the original cell layout and never updated after a line reconfiguration | ISO 10218-2 Clause 5 | Re-map the envelope against the current layout and re-check perimeter guarding and safe standing positions against the updated geometry. |
| An end effector with an exposed sharp edge is in use in collaborative mode | ISO/TS 15066 Clause 5.5.4 | Remove or guard the sharp feature, or reclassify as non-collaborative with full perimeter guarding until resolved. |
Case in point
Case in point: the collaborative robot that stayed collaborative on paper only
A cell was commissioned as collaborative, with the original gripper's force validated at low payload for a light pick-and-place task. Eighteen months later, production added a heavier fixture with a firmer gripper, treated internally as a minor tooling change rather than a new application. The collaborative assessment was never revisited, because nothing about the robot's programming or speed had changed.
A periodic assessment under this template caught it only because Power And Force Limits Validated could not honestly be marked Yes without new measurement. The new gripper's force at the same speed exceeded the biomechanical limit for the finger, and the operation was reclassified as caged pending redesign. The robot's motion had never looked different; the assumption underneath it had been wrong for a year and a half.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- SAF-095
- Archetype
- Assessment
- Record ID
- RSK-2026-000
- Scoring
- Risk band
- Direction
- High is bad
- Singleton
- No
- Basis
- ISO 10218, ISO TS 15066
- Links
- Links Asset, Job
- Tags
- Machine, Robotics, Risk
- Sections
- 5
- Fields
- 44
- Follow up fields
- 8
- Repeating sections
- 0
- Links out
- 4
Header
14 fieldsAssessment ID*
Auto sequence. Format RSK-2026-00000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Robot Cell*
Asset ID*
Format AST-0000.
Links to FDN-002 Asset ID
Collaborative Does Not Mean Safe
A collaborative robot is only safe within its assessed speed, force and application. Change the tool, the payload or the layout and the assessment is void.
Robot Type*
- Caged industrial2 pts
- Collaborative1 pt
- Mobile autonomous0 pts
Application*
Integrator
Assessment Trigger*
Standard Applied*
Cell design
8 fieldsPerimeter Guarding Present*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Light Curtains Or Scanners Fitted*
- Yes3 pts
- Not required3 pts
- No0 pts
Muting Arrangements Assessed
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Reach Envelope Mapped*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
No Trapping Points Within Envelope*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Safe Standing Positions Marked*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Entry Requires Interlock Or Isolation*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Presence Sensing Prevents Restart*
Somebody inside the cell when it restarts is the classic robot fatality.
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Collaborative operation
6 fieldsCollaborative Mode Used*
- No3 pts
- Yes1 pt
Speed And Separation Monitoring
- Yes3 pts
- No0 pts
Power And Force Limits Validated
- Yes3 pts
- No0 pts
Force Measurement Recorded
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
End Effector Free Of Sharp Edges
A knife or gripper on a collaborative arm removes the collaborative assumption entirely.
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Payload Within Assessed Limit
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Teaching and maintenance
5 fieldsTeach Pendant Enabling Device Works*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Reduced Speed In Teach Mode*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Only Trained Programmers Have Access*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Maintenance Access Assessed*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Isolation Procedure Exists*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Result
11 fieldsResidual Band*
- Low, 1 to 45 pts
- Medium, 5 to 94 pts
- High, 10 to 142 pts
- Very high, 15 to 191 pt
- Extreme, 20 to 250 pts
Cell Acceptable For Use*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Next Review Due*
Assessor*
Signature*
Engineering Manager*
Second Signature*
SAF-095 · record IDs look like RSK-2026-000 · Links Asset, Job
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The form is the easy part. Catching a quiet tooling or payload change before it invalidates a collaborative assessment, and keeping the reassessment trigger tied to the asset, is the work that actually slips.
Holds the robot cell assessment library against the asset register, flags when a plant change should have triggered a reassessment, and keeps the residual risk band visible against the schedule.
Surfaces end effector, payload or fixture changes logged against the asset so a tooling swap does not slip past the assessment that depends on knowing about it.
Confirms the assessor and the engineering manager providing the second signature hold current competency for robot cell risk assessment, not general machine safety training.

Coordinates the crew across sites, rolls completion and exceptions into one view, and holds every write for your approval before it touches a record.
This template lives in KnowSafe — safety and compliance. Incidents, hazards, permits, inspections and the critical controls behind them.
Meet KnowSafe→Glossary
Robot Cell Safety Assessment definitions and key terms
- Collaborative robot
- A robot validated to share workspace with a person without full perimeter guarding, under specific speed, force, payload and application limits set by the assessment, not an inherent property of the hardware.
- Speed and separation monitoring
- A collaborative operating method that maintains a protective separation distance and reduces or stops robot speed as a person approaches, rather than relying on contact limits.
- Power and force limiting
- A collaborative operating method that keeps contact forces and pressures at the end effector below biomechanical injury thresholds, so incidental contact does not cause harm.
- Reach envelope
- The full three-dimensional space the robot and its end effector can physically occupy, including tooling, which perimeter guarding and safe standing positions must be set against.
- Residual risk band
- The risk remaining after all controls in the cell are applied, expressed as a band from Low to Extreme; unlike most scores in this library, a higher band here means higher risk, not a better result.
FAQ
Frequently asked questions about robot cell safety assessment
What is the robot cell safety assessment template based on?+
It is built against ISO 10218, which covers industrial robot and robot system safety, and ISO/TS 15066, which covers the specific requirements for collaborative robot operation, including speed and separation monitoring and power and force limiting.
What sections does the robot cell safety assessment contain?+
There are five sections: Header (cell and trigger), Cell design (perimeter guarding and reach envelope), Collaborative operation (only when collaborative mode is in use), Teaching and maintenance (pendant and isolation controls), and Result, which produces the residual risk band and sign-off.
Why does a lower number mean a worse result on this template?+
Scoring is inverted from most templates in this library because it measures residual risk, not compliance. A Low risk band scores highest and an Extreme band scores zero, so a rising score means the cell is getting safer, while a rising risk band means the opposite.
When does a robot cell need to be reassessed?+
At installation, and again after any change to programme, layout, end effector, or payload. A collaborative certification issued for one configuration does not carry over to a changed one, even if the change looks minor.
Why does the assessment need two signatures?+
The assessor's judgement on force limits and risk banding is independently reviewed by an engineering manager before the cell is accepted for use, because these are the two calls most likely to be wrong if left unchecked by a second reviewer.
Can the robot cell safety assessment template be changed?+
Yes. Every field, option, score and conditional rule is editable, and its links to the asset register and job come with it. Most teams install it as is, run it for a cycle, then adjust.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Machine Safety
Lockout/Tagout Procedure (Machine Specific)
Sets out exactly how to isolate a specific machine, listing every energy source and isolation point
LOTO Periodic Inspection
Checks that a specific energy control procedure is being followed correctly in practice
Machine Risk Assessment
Assesses a machine across its whole life, including setup, running, cleaning, clearing jams and maintenance
Guarding Verification Checklist
Confirms that guards fitted to a machine match the risk assessment and cannot be easily defeated
Interlock Function Test
Tests that safety interlocks stop the machine when a guard is opened, and cannot be bypassed
Pinch Point Survey
Walks a machine or line looking specifically for pinch, nip, shear and crush points
More in Machine Safety
Machine Risk Assessment
Assesses a machine across its whole life, including setup, running, cleaning, clearing jams and maintenance
Guarding Verification Checklist
Confirms that guards fitted to a machine match the risk assessment and cannot be easily defeated
Interlock Function Test
Tests that safety interlocks stop the machine when a guard is opened, and cannot be bypassed
Pinch Point Survey
Walks a machine or line looking specifically for pinch, nip, shear and crush points
Machine Modification Review
Reviews a proposed change to a machine before it is made, covering guarding, controls and the tasks people will do afterwards
Emergency Stop Test Record
Tests that emergency stops actually stop the machine and are reachable from where people work

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 10218-1 — Robots and robotic devices: Safety requirements, Part 1: Robots
- ISO 10218-2 — Robots and robotic devices: Safety requirements, Part 2: Robot systems and integration
- ISO/TS 15066 — Robots and robotic devices: Collaborative robots
- ANSI/RIA R15.06 — Industrial robots and robot systems, safety requirements
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.