Before an AMR Route Opens: Turn Workplace Hazards into Design Requirements
The approval decision begins with the installed application
An AMR application risk assessment examines how a mobile robot, its load, nearby equipment, people, and operating conditions can combine to cause harm. Its practical output is a set of design requirements and operating limits, supported by evidence that the selected controls address the identified hazards. A vehicle specification, scanner certificate, or successful demonstration cannot provide that application-level argument on its own.
The distinction matters when a warehouse expands automation into occupied production space. A robot can follow its route correctly while its pallet blocks a sensor, its turning load approaches a workstation, or a person emerges from behind stored material. Each event changes the safety question even when navigation performance remains excellent.
This article develops an illustrative blind-corner delivery route into an assessment record. The purpose is to establish what the application must do before anyone writes its acceptance test procedure. The case, calculations, and example records are original engineering examples, not results from a named installation.
A relevant 2026 development is the publication of ANSI/A3 R15.08-3-2026 on April 23. A3 describes Part 3 as addressing the use of industrial mobile robot applications, including responsibilities associated with their operating environment and changes during use. That makes lifecycle ownership a timely project question. Source: A3's official Part 3 publication page.
A blind corner reveals the limits that procurement missed
Consider a proposed route between a pallet supermarket and a production cell. The robot turns around a storage rack, crosses a pedestrian access path, and docks beside an operator workstation. A forklift replenishes the supermarket. A cleaner enters the same area after production, and technicians occasionally recover stopped vehicles manually.
The purchasing specification lists payload capacity, nominal speed, and battery endurance. It does not define the maximum load overhang, the permitted rack configuration, the condition of the floor after cleaning, or who may restart a vehicle during recovery. These omissions become the starting questions for an autonomous mobile robot risk assessment.
First, describe the application boundary. Record the vehicle and top module, approved load families, route geometry, interfaces, operating modes, environmental limits, and people who can enter. Include reasonably foreseeable deviations: an offset pallet, temporary storage near the corner, an unavailable destination, and a person taking a shortcut. Treat exclusions as enforceable operating conditions with an owner; a sentence saying that pedestrians are excluded is insufficient if the layout invites access.
| Task or condition | Exposed person | Potential harm mechanism | Question the design must resolve |
|---|---|---|---|
| Loaded travel around the rack | Operator approaching the crossing | Impact or trapping before effective detection and stopping | When does the person become detectable, and what separation remains? |
| Turning beside the workstation | Station operator | Crushing by the swept load envelope | Does protection account for load overhang and rotation? |
| Forklift replenishment | Forklift driver and nearby workers | Vehicle conflict or displaced material entering occupied space | Can the two activities be separated in space or time? |
| Cleaning or a local spill | Cleaner and passing workers | Reduced traction, unexpected stopping behavior, or slipping | Which floor conditions require route closure? |
| Manual recovery of a stopped robot | Technician | Unexpected motion, rolling, or release of stored energy | How are motion and other hazardous energies controlled? |
| Charging and battery intervention | Maintenance personnel | Electrical, thermal, or mechanical exposure | Which equipment instructions and additional assessments apply? |
This is why useful AGV hazard analysis begins with tasks and exposure. A fault list alone can miss hazards arising during completely normal operation. Conversely, an equipment fault does not describe the complete risk until the assessment explains who can be exposed and how injury could occur.
Make the risk judgment explainable before assigning a score
A risk matrix can organize discussion, but its score should never conceal the reasoning. Record the potential severity of harm, the circumstances and duration of exposure, the likelihood of the hazardous event, and the realistic possibility of avoiding or limiting harm. Use the assessment method selected for the application and applicable requirements; do not invent a universal numerical acceptance threshold.
At the blind corner, avoidance deserves particular attention. A person carrying a container may have restricted vision. A worker standing between a workstation and the moving load may have no usable escape direction. A driver looking toward a forklift load may not notice a small mobile robot. Describing everyone as a trained adult does not resolve these differences.
An AMR pedestrian safety assessment should therefore describe actual approach directions, visibility, access frequency, and available space. Observe representative shifts rather than relying exclusively on an empty building walk-through. Record uncertainty explicitly where the future operating pattern is not yet known.
Evaluate the initial risk, select measures, and then reassess the resulting situation. Preserve the explanation for each judgment, including rejected alternatives and assumptions that must remain true. A low final score without an identified measure and supporting evidence is difficult to defend when the operating conditions change.
Methodological basis: ISO 12100:2010 provides a machinery risk assessment and risk reduction framework across the machinery lifecycle. The route analysis and record structure here are editorial examples, not a reproduction of its full requirements.
Change the layout before relying on a warning
For the example route, the first design discussion should examine whether the conflict can be removed. Moving the crossing away from the rack end may improve visibility. Relocating the workstation may remove a trapping space. A protected pedestrian route or a revised replenishment arrangement may reduce how often people and vehicles meet.
Each proposal needs its own review. A barrier can create a narrow enclosure, obstruct emergency access, or channel people toward another vehicle lane. A one-way route can move the conflict to a different intersection. The assessment must follow the consequences of the redesign rather than treating a drawn line as proof of improvement.
Where interaction remains, consider suitable safeguards and safety-related control functions. Specify how access, speed, detection, stopping, and restart will work together. Information, training, and warnings then communicate the remaining limits and required behavior. This sequence gives mobile robot risk reduction a physical and functional basis that a collection of signs cannot supply.
Fleet scheduling still has a useful operational role. Shared-aisle traffic coordination can reduce conflicting movements and improve predictability. If a project relies on a particular coordination function to reduce safety risk, however, that reliance must be reflected in its safety requirements, architecture, and validation. Ordinary scheduling software should not silently inherit a safety responsibility.
Use stopping calculations to expose assumptions
An AMR braking distance calculation helps reveal which parameters influence the available stopping margin. It is not, by itself, a protective-field design method. The calculation must distinguish the distance traveled before braking becomes effective from the distance traveled while the vehicle decelerates.
For a simplified straight-line example, assume constant speed during a defined response interval and constant deceleration afterward:
d = v × t + v² / (2 × a)
Here, d is robot travel to standstill in meters, v is initial speed in meters per second, t is the modeled pre-braking response interval in seconds, and a is the assumed deceleration magnitude in meters per second squared. Real braking profiles may not follow these assumptions.
Illustrative calculation: At 1.2 m/s, with a 0.20-second response interval and 0.60 m/s² deceleration, the modeled travel is 0.24 + 1.20 = 1.44 m. At 0.8 m/s with the same assumptions, it becomes 0.16 + 0.533 = approximately 0.69 m. These are hypothetical inputs, not recommended settings or measured performance.
The comparison illustrates why speed deserves early attention. It does not establish that either speed is acceptable at the crossing. A person can approach during the stopping sequence, the scanner may not see past the rack, and the load may extend beyond the robot reference point. Detection geometry, measurement uncertainty, response behavior, applicable allowances, and the actual moving envelope still need evaluation.
Engineering reference: SICK's protective-field sizing explanation distinguishes braking distance from travel during scanner and safety-controller response. It also identifies load, environmental conditions, wheels, and direction as relevant influences. The arithmetic above is independently constructed.
Measure the combinations that challenge the assumptions
Specify a controlled test method with suitable targets, instrumentation, trained personnel, and exclusion arrangements. Do not use a person as the obstacle. Link every record to the vehicle, load configuration, floor condition, software version, safety parameters, direction, and operating mode.
| Configuration | Reason to investigate | Evidence to retain |
|---|---|---|
| Empty vehicle and normal production load | Traction and brake behavior can differ; the heaviest load is not automatically the worst case. | Measured response and stopping profiles for each relevant configuration |
| Maximum approved load and center-of-gravity limits | Stopping must also preserve acceptable load stability. | Vehicle motion, load movement, and retention observations |
| Least favorable permitted floor condition | Grip assumptions must represent the approved operating environment. | Documented surface condition and repeatable measurement conditions |
| Permitted reverse travel and turning transitions | Direction and geometry may change detection coverage and the swept envelope. | Mode-specific coverage and stopping evidence |
| Relevant wear and maintenance limits | Release evidence should support continued operation within stated service limits. | Justified degradation allowances and inspection triggers |
Define the design bound and its justification before interpreting the results. A mean stopping distance or a favorable percentile does not establish a safe maximum. Repetition helps reveal variation, but even the longest observed stop is not automatically a complete bound for untested conditions. Address uncertainty and foreseeable degradation through the engineering assessment.
At the example crossing, record which physical point defines the separation: the scanner, chassis, or foremost load edge. Use consistent reference points in drawings, calculations, and measurements. Otherwise, two individually correct records can describe different clearances, leaving the final stopping margin overstated when they are combined.
Treat the payload as part of the moving machine
An AMR payload risk assessment should connect the approved load family to the entire route. Record dimensions, mass, center-of-gravity limits, retention, pallet condition, protrusions, and any changes in visibility or sensing. A dimensional envelope that fits a straight aisle may still create a hazard during rotation or docking.
For the blind-corner example, imagine replacing a compact tote with a pallet whose leading edge extends farther forward. The robot can retain the same navigation path and stopping performance while the nearest hazardous point moves closer to a person. A top module may also introduce upper-body impact or trapping hazards outside the coverage of a low scanning plane.
Resolve these effects through the load specification, mechanical arrangement, route design, sensing architecture, and suitable operating limits. Check the actual installed coverage when undertaking safety laser scanner selection. A product's advertised field range does not establish visibility around the installed payload.
Assign responsibility for accepting loads into the automated flow. If an unsupported pallet shape can enter through a manual station without detection or effective control, the approved load list has not yet become an operating constraint.
Turn each selected control into a requirement that can be tested
AMR safety function requirements should describe behavior precisely enough that a designer and an independent reviewer reach the same understanding. For the crossing, a statement such as “the robot detects people” leaves unanswered questions about coverage, timing, mode changes, failure behavior, and restart.
For each required function, specify the initiating condition, the operating modes in which it applies, the necessary response, the response-time assumptions, and the state to be maintained. Define how faults are detected and handled, how reset differs from restart, and how unauthorized parameter changes are prevented or detected.
Determine the required safety performance from the applicable requirements and risk assessment. ISO 13849-1:2023 addresses the design and integration of safety-related control-system parts. Its published scope explicitly states that it does not prescribe the safety functions or required performance levels for particular applications. A component rating therefore cannot substitute for specifying and evaluating the complete function.
The following matrix shows how a hazard decision becomes an evidence request. It is an example structure, with project-specific criteria still to be defined.
| Hazard scenario | Selected measure to develop | Evidence needed |
|---|---|---|
| Person emerges at the blind crossing | Revised crossing geometry plus suitable approach control | Visibility analysis, detection coverage, response assumptions, and stopping evidence |
| Load swings toward the workstation | Approved load envelope and revised clearance or safeguarding | Swept-path assessment covering the full load and permitted tolerances |
| Person remains in a trapping space after a stop | Access protection and an appropriate restart strategy | Presence and access analysis, restart requirements, and validation results |
| Unexpected motion during recovery | Defined intervention mode and hazardous-energy controls | Recovery task assessment, equipment instructions, and verified procedures |
| Floor condition leaves the approved range | Detectable closure trigger and controlled reopening | Inspection responsibilities, route restriction mechanism, and release record |
Once these requirements are approved, they can feed a site acceptance evidence matrix. Keep that sequence visible: the assessment defines the safety question, the design implements the answer, and validation evaluates whether the implemented answer meets the requirement.
Separate standards coverage from project ownership
Standards can address different layers of the application. Identify the relevant documents, editions, jurisdiction, and equipment scope instead of treating a list of standard numbers as a complete safety argument. The descriptions below summarize public publisher information; they do not replace the full requirements used by the project team.
| Primary reference | Role in the project | Boundary to preserve |
|---|---|---|
| ISO 12100:2010 | General machinery risk assessment and risk reduction methodology | Application-specific hazards and measures still require engineering work. |
| ISO 3691-4:2023 | Safety requirements and verification for driverless industrial trucks and their systems | Confirm equipment coverage and exclusions; its published scope excludes requirements for power sources. |
| ISO 13849-1:2023 | Design and integration of safety-related control-system parts | Do not infer an application's required performance level from a component label. |
| ANSI/A3 R15.08-2-2023 | Industrial mobile robot system and application integration | Consider the configured system and its interfaces. |
| ANSI/A3 R15.08-3-2026 | Use of industrial mobile robot applications | Assign ongoing operating and change-management responsibilities. |
The equipment manufacturer should provide the applicable operating limits, safety-function information, interface requirements, and relevant supporting evidence for its supply. The integrator should establish how the combined application satisfies its requirements, including the top module, stations, controls, and operating environment. The user organization should supply reliable task information and own the controls that depend on daily operation.
These are proposed project evidence responsibilities, not a universal allocation of legal liability. Contractual scope and the applicable legal framework must identify the actual responsible parties. A project should also name who maintains the combined assessment and who can authorize reopening after a safety-relevant change.
Account for the European transition in 2027
For EU projects, Regulation (EU) 2023/1230 generally applies from 20 January 2027, with earlier application dates for specified provisions. Article 52 contains transitional rules for products placed on the market under the previous directive. Article 18 also assigns manufacturer obligations to a person carrying out a qualifying substantial modification. Evaluate the actual product, relevant dates, and modification circumstances; the purchase-order date alone is not a sufficient basis. Legal source: the consolidated regulation, Articles 18, 52, and 54.
Separately, the European Commission distinguishes mandatory essential requirements from voluntary harmonized standards. Check the applicable harmonized references and editions for the project. Publication of an ISO document should not be treated as automatic evidence of EU harmonization. Source: European Commission machinery guidance.
Keep the assessment connected to the operating floor
AMR residual risk documentation should identify what remains after the selected measures, who can be exposed, the conditions under which the assessment remains valid, and the required user actions. Instructions should be specific enough to use at the workplace: which pallet families are permitted, where access is restricted, what triggers route closure, and who may recover a stopped vehicle.
Training should address those tasks and limits. Assess whether workers can recognize the relevant condition and carry out the required response. A signed attendance sheet says little about whether a technician understands a changed recovery mode or whether a cleaner knows how to request route isolation.
An AMR safety change assessment should start whenever a change could invalidate the existing argument. Examples include relocating racks, increasing speed, changing tires, introducing a different load, modifying a protective field, updating safety-related software, or altering pedestrian access. Begin with the affected hazard assumptions and trace their dependencies into design requirements and evidence.
A firmware update may affect response behavior without changing the route drawing. A new storage policy may obscure visibility without changing the robot. Classifying every change as either mechanical or software can miss these cross-system effects. Record the assessment outcome, necessary verification or revalidation, authorized configuration, and conditions for returning the route to service.
Conditions that should block the proposed release
The project should define explicit release-blocking conditions before schedule pressure builds. For this illustrative route, the following are appropriate issues to resolve before operation:
- A person can enter a hazardous space before the proposed protection can achieve its required effect.
- The permitted payload envelope or a relevant stopping condition remains unsupported by evidence.
- A required safety function has no agreed specification, performance basis, or validation responsibility.
- Recovery depends on an undefined bypass, uncontrolled restart, or access to uncontrolled hazardous energy.
- An essential operating restriction cannot be implemented or maintained on the floor.
- A safety-relevant change has invalidated the approved assumptions without an updated assessment.
Closing these issues can lead to a revised layout, a narrower load family, a different safeguard, or a reduced operating range. Record the chosen decision and its evidence. The approved application is the defined combination of equipment, tasks, limits, and controls; changes to that combination deserve deliberate review.
Focused FAQ
Does a safety-equipped AMR still need an application assessment?
Yes. Vehicle features have specified capabilities and limits. The installed application introduces people, loads, stations, routes, and work practices that must be evaluated together. Manufacturer information contributes to that assessment but does not describe every site-specific exposure or interface.
Is there one safe speed for every warehouse?
No universal speed can be selected from the information in this article. The acceptable operating range depends on the application, relevant requirements, detection geometry, stopping performance, payload behavior, and exposed people. A lower speed can help, but it cannot correct every trapping space or blind approach.
Can calculated stopping distance set the scanner field?
A simplified calculation is only one input. Protective-field design must address actual response and braking behavior, detection coverage, reference geometry, approach conditions, uncertainty, and applicable requirements. Confirm the installed configuration with suitable evidence rather than copying the illustrative distances above.
Who should own the combined assessment?
Name an accountable application owner in the project governance and clarify the legal responsibilities separately. The owner needs contributions from the manufacturer, integrator, safety specialists, operations, and maintenance. The assessment also needs a designated custodian after commissioning so that changes and operating limits remain controlled.
Does every software update require the same test campaign?
The assessment should determine the impact and appropriate scope. Identify which assumptions, interfaces, functions, and evidence could change. Some updates may justify a limited review; others require substantial revalidation. The decision should be documented and supported by the available change information.
What distinguishes the assessment from site acceptance testing?
The assessment identifies hazards, evaluates risk, selects measures, and establishes requirements. Site acceptance testing evaluates the installed implementation against defined criteria. Test results can reveal new issues and send the assessment back for revision, but a successful test cannot resolve a hazard that the test never addressed.
Evidence note: Primary references are linked beside the claims they support. Standards coverage is based on public publisher scopes and descriptions reviewed on September 17, 2026. The blind-corner scenario, example records, release conditions, and numerical calculation are original analytical illustrations. They are not a completed site assessment, certification, or reported field study.
#AMRRiskAssessment #AGVHazardAnalysis #MobileRobotSafety #FunctionalSafety #StoppingDistance #PayloadSafety #ISO3691 #ISO12100 #RiskReduction #SafetyValidation