Machine Safety Risk Assessment Guide for Plants

Machine Safety Risk Assessment Guide for Plants

A new conveyor, robot cell or packaging line can appear compliant at commissioning, then reveal its real risks during clearing jams, changeovers, maintenance or fault finding. That is why a machine safety risk assessment guide must address the complete operating life of the machine, not just the normal production cycle. For plant owners, OEMs and integrators, the assessment is the engineering basis for selecting safeguarding, safety controls and operating procedures that are practical to use and defendable under Australian work health and safety obligations.

What a machine safety risk assessment should achieve

A risk assessment is not a form-filling exercise completed after the design is effectively locked in. It is a structured method for identifying foreseeable hazards, estimating the associated risk and reducing that risk as far as reasonably practicable. It should drive design decisions early, when changing a guard layout, access point or control architecture is far less costly than modifying an installed machine.

In Australia, machine safety work commonly draws on the AS 4024 series, alongside relevant ISO standards such as ISO 12100 for risk assessment and risk reduction. The applicable requirements will depend on the machinery, industry, site rules and state or territory WHS framework. Mining, rail, food processing and hazardous-area applications may introduce further requirements. A competent assessment identifies these obligations at the outset rather than treating standards as a final compliance check.

The output should be clear enough for operations, maintenance and engineering teams to act on. It needs to state the hazards considered, the assumptions made, the safeguards selected, the residual risk accepted and the validation evidence required before handover.

Start with the machine's real boundaries

Define the machinery limits before rating any hazards. This means more than recording the machine nameplate and process description. Establish its intended use, reasonably foreseeable misuse, operating modes, materials handled, environmental conditions and every interface with upstream and downstream equipment.

A palletiser, for example, may have mechanical hazards within its guarded cell, but the assessment must also consider pallet infeed and discharge conveyors, manual pallet recovery, access through the perimeter fence, stored pneumatic energy and control interaction with the wider line. If workers can enter a shared zone while another connected machine remains active, the boundary has been set too narrowly.

Consider the full lifecycle: transport, installation, commissioning, normal operation, setup, cleaning, jam clearing, tool changes, troubleshooting, maintenance, repair, decommissioning and disposal. The highest-risk task is often not normal production. It is the non-routine activity carried out under time pressure when production has stopped.

Consult the people who perform the work

Observe tasks on the floor and speak with operators, fitters, electricians, cleaners and supervisors. They understand where product accumulates, which guards are routinely opened and whether a reset station can be reached without a proper view of the danger zone. Their input often identifies foreseeable workarounds that drawings and manuals do not show.

This consultation should include contractors where they undertake specialist maintenance or cleaning. A safety control that works for a trained technician with a permit may not be suitable for an operator conducting routine fault recovery several times per shift.

Identify hazards by task and energy source

Work through each task and identify the hazard, who may be exposed, how exposure can occur and the credible consequence. Mechanical hazards remain central, including crushing, shearing, entanglement, drawing-in, cutting, impact and ejection of parts or material. Do not overlook electrical shock, hot surfaces, noise, dust, chemicals, hydraulic pressure, gravity, stored energy and unexpected start-up.

Automation systems create additional scenarios that require close attention. A robot may restart after an interlock is restored, a variable speed drive may retain energy after isolation, or a remotely controlled conveyor may receive a start command from another process area. Safety functions must account for all relevant energy sources and all operating states, including automatic, manual, maintenance and recovery modes.

For each hazard, assess the severity of potential injury, the frequency or duration of exposure, and the possibility of avoiding the hazard or limiting harm. Risk matrices can help create consistency, but they do not replace engineering judgement. A low-frequency event with fatal potential may still require substantial risk reduction, particularly where access is necessary for routine work.

Apply risk reduction in the right order

The control hierarchy matters. Warning labels, procedures and training have a role, but they are rarely sufficient where a person can reach a dangerous moving part. Start by eliminating the hazard or reducing it through the design of the machine and process. If that is not reasonably practicable, use safeguarding and engineered safety functions before relying on administrative measures or personal protective equipment.

A practical order of consideration is:

  • eliminate the hazardous movement or remove the need for access
  • reduce force, speed, travel, temperature or stored energy by design
  • prevent access through fixed guards, perimeter fencing or suitable interlocked movable guards
  • detect entry or presence with safety light curtains, laser scanners, pressure-sensitive devices or enabling controls where appropriate
  • support the engineered controls with procedures, training, signage and PPE.
The best solution depends on the task. A fixed guard may provide a simple and highly reliable control where access is infrequent. It becomes a poor choice if staff need to remove it repeatedly to clear routine jams, as it may encourage bypassing. An interlocked guard, properly designed access route or process change can provide better operational control. For frequent material flow, a safety light curtain may be suitable, but only if its position, resolution, response time and safety distance prevent a person reaching the hazard before it stops.

Specify the safety function, not just the device

A safety-rated switch, relay or controller does not make a machine safe by itself. The required safety function must be defined first. For example: opening Guard Door 2 stops the hazardous motion of the infeed conveyor and robot, prevents restart while the door remains open, and requires a manual reset from a position with a clear view of the guarded area.

That statement prompts the necessary engineering questions. What movements must stop? Is stopping category 0 or category 1 required? What is the total stopping time? Can gravity, pneumatic pressure or a coasting motor create a residual hazard? Does the reset function initiate a restart, or only permit a separate start command? Can a fault in wiring, sensors, contactors or logic defeat the safety function?

The control system must then be designed to achieve the required level of risk reduction. This may involve Performance Level under ISO 13849-1 or Safety Integrity Level principles under IEC 62061, depending on the selected approach and application. Assessment of architecture, component reliability, diagnostic coverage, common-cause failures and validation is specialised work. It should not be reduced to selecting parts with a high safety rating from a catalogue.

For drive-based machinery, safe torque off can be a useful function for preventing motor torque. It does not necessarily isolate all electrical energy or control every hazardous condition. Vertical loads, high-inertia applications and stored pressure require separate consideration. Emergency stop is also a complementary protective measure, not a substitute for guarding or a means of providing routine access.

Validate on the installed machine

The assessment is incomplete until the safeguards are tested on the actual installation. Validation confirms that the safety functions, guarding and procedures work together as intended. Test each operating mode, safety device, reset location, stop function and restart condition. Measure stopping times where safety distances or control performance depend on them.

Also test realistic fault and recovery scenarios. Can a guard interlock be defeated easily? Does a light curtain restart the machine unexpectedly when cleared? Can a person remain hidden in a cell after resetting? Are isolation points identifiable and capable of being locked out for maintenance? These tests often expose issues that are not evident in electrical schematics or software reviews.

Keep controlled records of the risk assessment, circuit design, safety function specifications, calculations, validation results, operating instructions and changes made after commissioning. Any alteration to tooling, speed, control logic, guarding, materials or work methods can change the risk profile. Treat modifications as a trigger for review rather than assuming the original assessment still applies.

Build safety into upgrades from the first enquiry

Machine safety is most effective when mechanical design, electrical control and plant operation are considered together. An upgrade that adds a drive, sensor, robot or automated transfer point may improve output while introducing new access and restart hazards. Early specification support can prevent mismatched components and expensive rework during commissioning.

For projects involving safety relays, configurable safety controllers, interlocks, sensing, motion or drive systems, Tech Source can assist with practical component selection and application support alongside the wider machine safety design process. The strongest result is a machine that protects people without making routine production and maintenance unnecessarily difficult.

Back to blog

Leave a comment