Machinery risk assessment

Last reviewed: 11 September 2026~7 min read

The risk assessment is not a document you produce alongside the design. It is the thing that determines the design. Under Regulation (EU) 2023/1230 the manufacturer carries out a risk assessment to establish which essential health and safety requirements apply, then designs and constructs the machinery taking the results into account. The record of that process is a required part of the technical file.

The iterative process

  1. Determine the limits of the machinery: its intended use and any reasonably foreseeable misuse. Foreseeable misuse is where most weak assessments fail — "the operator will follow the manual" is not a limit, it is a hope.
  2. Identify the hazards and the associated hazardous situations. Mechanical, electrical, thermal, noise, vibration, radiation, materials and substances, ergonomics, environment, and — now explicitly — hazards arising from corruption of software or data.
  3. Estimate the risks, taking into account the severity of possible injury and the probability of occurrence: exposure, likelihood of the hazardous event, and the possibility of avoiding or limiting harm.
  4. Evaluate the risks and decide whether risk reduction is required.
  5. Eliminate or reduce the risks by applying the three-step method below.
  6. Repeat. Every protective measure can introduce new hazards. The process is iterative by definition, and a one-pass assessment is an incomplete one.

The three-step hierarchy

The mandatory order of protective measures
StepMeasureExamples
1Eliminate or reduce risks as far as possible by inherently safe design and constructionRemove the trap point. Lower the energy. Reduce the force. Design out the need to reach in.
2Take the necessary protective measures for risks that cannot be eliminatedFixed guards, interlocked movable guards, presence-sensing devices, two-hand controls, safe control system architecture.
3Inform users of the residual risks and specify training and personal protective equipmentWarnings, markings, instructions.
The order is not advisory. A warning in the manual does not discharge an obligation that a guard would have discharged. If a market surveillance authority finds a feasible design or guarding measure that was available and not taken, the presence of a warning label makes the finding worse, not better — it shows you identified the hazard and chose the cheapest response.

Where cybersecurity enters

The Regulation brings the corruption of safety-related software and data into the risk assessment explicitly. In practice, for connected or software-controlled machinery, that means asking:

  • Can the safety function be disabled or degraded by modifying software, firmware or configuration data?
  • Can it be affected remotely — over a network, a maintenance port, a removable medium, a wireless link?
  • What detects a corrupted state, and what does the machine do when it is detected?
  • Who can update the software, how is that update authenticated, and what happens if an update is interrupted?

The answers, and the measures that follow from them, go in the technical file. If the machinery is also a product with digital elements, the same evidence largely serves the Cyber Resilience Act — build it once, cite it twice.

What the written record must show

The Annex IV technical file requires the risk assessment documentation to include the procedure followed, the list of essential health and safety requirements that apply, the hazards identified and the risks evaluated, and the protective measures adopted. A defensible record shows:

  • The limits of the machinery as determined, including foreseeable misuse.
  • A hazard register: hazard, hazardous situation, affected persons, lifecycle phase (including installation, setting, cleaning, maintenance and decommissioning — not just normal operation).
  • The risk estimate before and after the protective measures.
  • The measure adopted, and where a step-1 measure was rejected, why it was not reasonably practicable.
  • The standards applied, with dated references, mapped to the hazards they address.
  • Dates, versions and authorship, tied to a machine revision.
  • A requirement-to-evidence index covering every applicable Annex III requirement, including those judged not applicable, with reasons.
On standards. EN ISO 12100 remains the reference method for risk assessment and risk reduction, and type-C standards for specific machine types remain the most efficient route to a defensible assessment. Applying a type-C standard in full is also what keeps Annex I Part B products in self-assessment. Why that matters →

Sources