A cobot is not automatically safe — safety is a property of the specific application and its risk assessment, not the robot alone. ISO/TS 15066 defines four collaborative methods that make shared workspace possible. This guide walks through those methods, a five-step risk-assessment process, the fenceless-cell mistakes that create hidden risk, and what ISO 10218:2025 changes for new integrations.
Collaborative robots are routinely sold as "safe by design," and the marketing is not entirely wrong — but it is incomplete. A cobot arm can carry a power-and-force-limiting certification and still injure a worker if it is integrated into a task the certification was never designed to cover. Safety on the shop floor is decided by the application: the task, the end-effector, the payload, the speed, and the space a person shares with the robot — not by a sticker on the robot's base.
That gap between "certified robot" and "safe cell" is exactly where integration work happens, and it increasingly spans more than mechanics and sensors. Monitoring a collaborative cell in real time — force thresholds, proximity events, risk-assessment status feeding back into an MES dashboard — is a software problem as much as a mechanical one. For teams that need that layer built rather than bolted on, a team that takes development turnkey — from the integration itself through to the cell's monitoring interface can shorten the path from a certified robot to a verified cell.
This guide covers the parts of that verification that are standards-driven and process-driven, not vendor-specific: the four collaborative methods defined in ISO/TS 15066, how to run a risk assessment that actually holds up, the fenceless-cobot assumptions that quietly create risk, and what the incoming ISO 10218:2025 revision changes for anyone integrating a cell today.
Why a Collaborative Robot Isn't Automatically Safe
A robot manufacturer's safety certification tests the robot as a component — joint force limits, stopping behaviour, software safety functions — under defined test conditions. It does not, and cannot, account for the gripper you bolt on, the part geometry it handles, the speed your cycle time demands, or the layout of the specific workspace a person will stand in. Two identical cobots, certified identically, can produce two very different risk profiles once they're integrated into two different tasks.
This is why "collaborative robot" describes a category of robot capable of operating near people under specific conditions — not a guarantee that any given installation meets those conditions. An installation without a documented, task-specific risk assessment is an unverified system, regardless of what the robot's own certification says.
What Are the Four Collaborative Methods in ISO/TS 15066?
ISO/TS 15066 defines four distinct methods for achieving safe human-robot collaboration, and a real-world cell commonly combines more than one depending on the phase of the task.
| Method | Mechanism | Typical Application |
|---|---|---|
| Safety-rated monitored stop | Robot halts completely whenever a person enters the collaborative zone | Loading/unloading tasks with intermittent human presence |
| Hand-guiding | Operator physically guides the robot's motion via a guiding device | Teaching/programming new paths, low-volume variable tasks |
| Speed and separation monitoring (SSM) | Sensors track separation distance; robot slows or stops as a person approaches | Shared workspace with continuous, variable human proximity |
| Power and force limiting (PFL) | Joint force/pressure capped below biomechanical injury thresholds | Direct, continuous contact tasks — assembly, kitting, hand-off |
Choosing a method is not a one-time decision baked into the robot — it is a decision made per task, and it is the first output of a proper risk assessment, not an input assumed before one.
How to Run a Risk Assessment for a Cobot Cell
A defensible risk assessment is a repeatable process, not a checklist filled in once at commissioning. The sequence below follows the structure used across ISO/TS 15066 guidance and industrial safety practice:
- Define the task and its operating limits. Document the exact motion, payload, speed, end-effector, and cycle — the robot's force and speed limits only mean something relative to a specific task.
- Identify hazards at the human-robot interface. Walk the cell boundary and list every point where a person's body can contact the robot, the workpiece, or the end-effector, including pinch points created by fixtures, not just the arm itself.
- Estimate and rank the risk for each hazard. Score severity and likelihood together — a low-force contact that happens constantly can rank above a high-force contact that is effectively unreachable.
- Apply reduction measures — PFL, SSM, or guarding where needed. Select the collaborative method (or combination) from the table above that brings each ranked risk to an acceptable level; where no collaborative method suffices, physical guarding for that specific hazard is still the correct answer.
- Validate, document, and schedule reassessment. Test the implemented measures against the documented limits, record the outcome, and set a trigger for re-assessment — a tooling change, a new part variant, or a fixed periodic interval, whichever comes first.
The Fenceless-Cobot Mistakes That Create Hidden Risk
The absence of a physical guard around a cobot is a design choice enabled by one of the four collaborative methods — it is not, by itself, evidence of safety. Three assumptions repeatedly show up in installations that look compliant but aren't:
- "No fence means it's already safe." A fenceless layout is the output of a risk assessment and a chosen collaborative method, not a substitute for one. Removing a guard without redoing the assessment for the resulting open workspace leaves the actual hazard unassessed.
- "The robot's certification covers the cell." The robot's PFL or SSM certification is tested under defined conditions. The end-effector, workpiece, and fixtures the integrator adds are outside that scope and need their own evaluation.
- "One assessment lasts the life of the cell." A changed gripper, a new part geometry, or a faster cycle time can quietly move a task outside the limits the original assessment validated — and nothing about the physical setup will visibly signal that the margin is gone.
Related failure modes — certification gaps discovered only after an audit — are exactly what independent assessments like third-party IEC 62443 certification for cobot platforms are designed to catch before deployment, not after an incident.
What ISO 10218:2025 Changes for New Integrations
The updated ISO 10218 standard tightens requirements around documentation and shifts more explicit responsibility onto the integrator of the cell, not just the manufacturer of the robot. In practice, this means risk-assessment records, validation evidence, and the rationale for the chosen collaborative method need to be complete and traceable at the cell level — not implied by the robot's own datasheet.
For teams planning new integrations, the practical implication is to build documentation discipline into the project from the start rather than reconstructing it for an audit later. For teams running cells already in production, it's a reasonable prompt to check whether existing risk-assessment records would hold up against the new expectations — particularly as newer platforms, including next-generation cobot platforms built around physical-AI capabilities, push more autonomous decision-making into the collaborative workspace itself.
Frequently Asked Questions
- Is a collaborative robot safe without a risk assessment?
- No. A cobot's safety rating applies to the robot as a standalone component, not to the application it is installed into. Without a documented risk assessment covering the specific task, end-effector, and workspace, the installation is unverified — even if the robot itself carries a power-and-force-limiting certification.
- What is power and force limiting (PFL)?
- Power and force limiting is one of four collaborative methods defined in ISO/TS 15066. The robot's joints are designed and software-limited so that contact force and pressure stay under the biomechanical thresholds set for each body region, allowing direct contact without a safety-rated stop being triggered.
- Do all four ISO/TS 15066 methods need to be used together?
- No. A single cell can use one method or combine several — for example, speed and separation monitoring while a person approaches, switching to power and force limiting for the moments of direct contact. The risk assessment for the specific task determines which method, or combination, is appropriate.
- How often should a cobot cell risk assessment be repeated?
- Repeat the risk assessment whenever the task, end-effector, payload, speed, or layout changes, and on a periodic schedule even if nothing has visibly changed. A one-time assessment at commissioning does not cover tooling changes or new part variants introduced later.
- Is ANSI/RIA R15.06 the same as ISO/TS 15066?
- They are closely aligned but not identical. ISO/TS 15066 is the international technical specification detailing the four collaborative methods; ANSI/RIA R15.06, used alongside CSA Z434 in North America, is the regional robot-safety standard that references and incorporates equivalent collaborative-operation requirements.
- What's the most common integration mistake with fenceless cobots?
- Treating the absence of a physical guard as proof of safety. A fenceless layout only reflects a design choice enabled by one of the ISO/TS 15066 methods — it still requires the full risk assessment, and it is frequently paired with the false assumption that the robot's own certification covers the entire cell.
- Does ISO 10218:2025 apply to cobots already in production?
- The updated standard primarily governs new integrations and significant modifications, but it raises the documentation and integrator-responsibility bar industry-wide. Teams running existing collaborative cells should treat it as a prompt to review whether current risk-assessment records would meet the new expectations.
Sources: Standard Bots, Collaborative Robot Safety Standards; EVS Integration, Collaborative Robot Safety: ISO/TS 15066 and Risk Assessment; Sensory Robotics, Collaborative Robot Safety Standards Explained; Industrial Safety Sensor, Collaborative Robot Safety; ISO, ISO/TS 15066:2016 announcement.