Two parts, two areas of responsibility
ISO 10218-1:2025 defines requirements for the industrial robot itself. The companion part addresses robot applications and cells across design, integration, commissioning, operation and decommissioning. In practice, a manufacturer supplies a safe component while the integrator must demonstrate that the complete application is safe in its actual environment.
The customer should make this boundary explicit in the specification and contract. A statement that equipment complies with a standard is not a substitute for risk assessment of the complete task.
Define the intended application
Document the workpiece, tool, speed and force ranges, modes, access zones, users and reasonably foreseeable misuse. Review loading, cleaning, jam clearing, path teaching, maintenance and restart separately; these are the moments when a person is most likely to enter the hazard area.
A change in gripper, product, speed or guarding needs an impact review, not merely a program adjustment.
Link safeguards to identified risks
For every hazardous event, select a measure: inherently safe design, physical guarding, interlocking, safety-rated monitored stop, speed or separation limits, procedure and training. Safety functions need a validated performance level rather than existing only as a controller option.
Collaborative applications require attention to real payload mass, sharp edges, trapping points, stopping distance and sensor-loss behaviour. A collaborative mode does not make every application safe by default.
Assemble the cell's technical file
The evidence pack should contain a system description, zone drawings, hazard list, risk assessment, safety-function architecture, calculations, validation records, instructions, training plan and change-control method. Emergency stops, interlocks, modes and recovery are tested on the installed system.
A useful technical file makes a test repeatable after an update and exposes which design assumption has changed.
Keep safety controlled after acceptance
Schedule periodic tests, monitor defeated interlocks, record events and authorize modifications. When a tool is replaced, a guard is moved, controller software is updated or speed is increased, determine how much revalidation is necessary. Otherwise, a cell that was safe at commissioning gradually becomes an undocumented configuration.

