
Regulations
Machinery risk assessment: what changes in draft ISO 12100 (DIS 2026)
How the risk assessment of machines changes in the new DIS ISO 12100: AI, cybersecurity, software, technical standards and EU 2023/1230 Regulation.
Machinery risk assessment is the foundation for every safety decision. It defines the limits of the project, identifies hazards, estimates risks and determines the measures required. EN ISO 12100 has been the core methodological reference for this process for more than fifteen years. It is more than a guide for producing a document: it is the framework for integrating safety into machine design.
The current revision retains this structure while updating it for connected machinery, safety-related software, remote access, cybersecurity and artificial intelligence systems. The changes must be interpreted carefully. Some clauses introduce new technical content; others reorganise existing requirements, update terminology or incorporate published technical reports. Conflating the two can lead to provisions being presented as new obligations when they are not contained in the draft.
ISO 12100: what is it and at what point is the review
ISO 12100 is a type-A standard that establishes the fundamental concepts, terminology and general principles for machinery safety. The current published version is ISO 12100:2010. This article examines ISO/DIS 12100.3:2026, the draft second edition prepared by ISO/TC 199 with the participation of CEN/TC 114 under the Vienna Agreement.
As of 20 August 2026 the project is still “under development”, at the DIS stage. The official ISO page records two previous DIS consultations concluded with the decision to proceed with a new ballot; the third DIS was recorded on 1 July 2026. The voting text indicates a ballot opening on 20 July and closing on 14 September 2026. The British public comment period closed on 15 August. The result is therefore not definitive: comments and votes can still change formulations, structure and content before any progression to FDIS and publication.
Today there is still no “new EN ISO 12100” published to be applied to replace 2010 edition. The DIS is however sufficiently advanced to understand the technical direction of the revision and to check whether the business processes of risk analysis are already adapted to the themes that are entering the basic reference.
The role of risk assessment in machine safety
The draft maintains the essential sequence of ISO 12100:2010; the process starts from the determination of the limits of the machine, including intended use and reasonably foreseeable misuse; it continues with the identification of hazards and hazardous situations, risk estimation and evaluation; it completes with the elimination of danger or reduction of risk up to an adequate level. The first four activities are risk assessment; the fifth is risk reduction.
One step deserves attention: the text invites you to focus resources on risk reduction, instead of looking for absolute accuracy in its estimate. This does not reduce the penalty required. It means that matrices, scores and indices are decision-making instruments, not the end of work. A formally refined analysis but unable to direct design choices, protections and information for use remains weak.
Real technical innovations of the new ISO 12100
The DIS foreword explicitly lists the main changes; the most innovative core concerns the extension of the process to digital factors that can have consequences on safety, exactly in accordance with the new Machinery Regulation (EU) 2023/1230. The scope cites the implications of artificial intelligence and machine learning, vulnerability to cyber threats and data corruption. The revision also includes the hygiene aspects of the machinery safety. Reference
Machine Limits, AI and Cybersecurity
Determining the limits no longer stops at use, space, time and the environment. Clause 5.3.2 also adds, where relevant, limits relating to the machine’s cybersecurity attributes, such as user access and data flows, and limits on the use of artificial intelligence, including the types of data used for training. For a machine with adaptive functions, describing what it does is therefore not enough: the operating domain in which it can perform reliably, and the conditions that take it outside that domain, must also be defined.
In identifying hazards, the draft makes an important distinction: a cybersecurity violation is not qualified as a new danger in itself, but as a possible cause of a dangerous event. The analysis must therefore connect the digital threat to the physical effect on the machine: unexpected start-up, loss of stop, change of speed or force, inhibition of a safety function, movement beyond the limits or behaviour not foreseen.
Possible malfunction states include non-intentional self-evolving behaviour of the AI and cybersecurity violation; among the activities to be considered along the life cycle remote access is also included. These points effectively expand the map of tasks, states and causes that must fuel risk analysis.
Software, indirect control and remote updates
The part on the control systems is relocated in the new 6.3.5 and expanded; the text distinguishes causes related to the control system, software and the AI. For the software it considers systematic errors, insertion or deletion of signals and data, repetitions or alterations of the sequence, data corruption and loss of monitoring or diagnostics, while for the AI it calls non-intentional self-evolutionary behaviors and systemic breakdowns in the interface between AI and person.
Embedded and applied software must meet the specific performance of safety functions; the possibility of reprogramming by the user, protection against unauthorized changes and the need to update safety-related parts of software and data must be assessed. The project refers, according to the case, to ISO 13849-1, IEC 62061 or IEC 61508-3: if ISO 12100 defines the problem in the global process, the detailed rules govern the design and validation of safety functions.
The new paragraph 6.3.5.11 regulates indirect control, i.e. the command from a position without direct view of the controlled parties. It predicts, among other aspects, controlled mode activation, only one control point, priority of local control and safety functions, indication of indirect control status, prevention or detection of access to hazardous areas and specific instructions. If video surveillance is used as a risk reduction measure, the draft considers it a safety function and recalls failures such as signal loss, frozen image and delay.
The new 6.3.5.12 processes software updates remotely. An update must not generate a dangerous situation; if it can affect safety it must be validated. The text requires active measures during the update, secure management of the connection loss, confirmation of the acceptability of changes to safety-related parameters, safe status of the unnecessary parts, prior information of the persons involved and updating of information for use.
The new paragraph 6.3.5.17 introduces protection against attacks and corruption when they can compromise safety functions. Defence is set to layers: access control, network isolation, door protection, authentication, encryption, event recording and session timeouts (all examples that are reported in the draft).
Protections, access of the entire body and hygiene
The project updates the selection and application of guards and protective devices. Strengthens the connection with the possibility of defeat, maintainability of measures and situations where a person can be completely within the protected space. Renewal of ISO 13855, ISO 13857 and ISO 12895-2 for access to the entire body is introduced. Various regulations relating to guards, electrosensitive devices and associated command functions are also updated. Reference
The new paragraph 6.2.14 introduces hygienic aspects: for applications with hygiene and cleanliness requirements, such as food and pharmaceutical, machines and equipment must be designed to allow cleaning and, when necessary, disinfection by referring for details to ISO 14159, ISO 21469 and EN 1672-2. standards
The emission protection section is shortened and maintained on general principles, with greater reliance on specific standards. This intervention should not be described as an automatic weakening of requirements: it is above all a redistribution of the level of detail between type A standards and type B or C standards.
Relationship with Machinery Regulation (EU) 2023/1230
Regulation (EU) 2023/1230 will apply in general from 20 January 2027 and replace Directive 2006/42/EC. It is a mandatory legislative source; ISO 12100 remains a voluntary technical standard; their relationship is therefore functional but not equal: the standard provides the method to design and document risk reduction, while the Regulation establishes the legal requirements to be met.
The connection is particularly evident on digital issues, in fact the Regulation deals with protection against corruption, the reliability of control systems and, for certain categories, components or systems with fully or partially self-evolving behaviour based on machine learning that ensure safety functions. The DIS translates these issues into the operating language of risk analysis: limits, predictable states, dangerous events, protective measures, verification and validation.
The European annexes in the draft are informative and must be interpreted with care. Annex ZA expressly states that applying the standard alone is not sufficient to demonstrate conformity with every essential health and safety requirement of the Regulation and does not provide full presumption of conformity. Annex ZB clarifies the role of the methodology when selecting and applying harmonised type-C standards and notes that, in the EU context, the term ‘tolerable risk’ must be interpreted in relation to residual risk. Both annexes are excluded from the final ISO publication because they belong to the EN version.
Integration of ISO/TR 22100-1 and ISO/TR 22100-2
The future second edition is intended to replace not only ISO 12100:2010, but also the technical reports ISO/TR 22100-1:2021 and ISO/TR 22100-2:2013. Their contents are incorporated respectively in the new Annexes C and D. The operation makes the document more self-sufficient and reduces the fragmentation between the basic standard and the technical reports.
Annex C explains how to use type-A, type-B and type-C standards together. A type-C standard must define its field, significant hazards, reduction measures and verification methods. When an applicable C-type standard differs from a type B prescription, it prevails for the covered machine. But the decisive point remains the correspondence between the field and the hazards of the product standard and the real machine: a type-C standard does not replace the risk assessment for hazards outside its scope.
Annex D clarifies the relationship with ISO 13849-1. The overall assessment under ISO 12100 provides the limits, hazardous situation, severity, exposure, probability of occurrence and possibility of avoiding harm, together with the functional specification of the protective measure. This information supports selection of the PLr and the design of safety-related parts of control systems. The verification and validation results under ISO 13849-1 and ISO 13849-2 then form part of the overall risk assessment.
The draft formulates a very useful clarification: ISO 13849-1 A Attachment Chart serves to select the PLr of a safety function and does not constitute a method of estimating the overall risk of the machine. If ISO 12100 analysis is well structured, there is no need for a second separate risk assessment to apply ISO 13849-1; there is a consistent data mapping and a clear traceability between danger, safety function, PLr, architecture and validation.
How to structure the new risk analysis
The DIS does not impose a new standard form or a mandatory risk matrix. The following structure is an operational translation of the requirements and novelties of the project, not a checklist prescribed by the standard. It is used to build a document that remains verifiable when the machine changes over time.
- Identify without ambiguity machine, configuration, hardware and software revisions, intended use and system boundaries analysed.
- Determine the limits of use, space, time and environment, including users, operating modes, maintenance, remote access, cybersecurity attributes and AI usage domain when relevant.
- Mapping phases of life cycle, tasks, exposed people and machine states. For each scenario distinguish danger, dangerous situation and dangerous event, connecting digital causes to the possible physical consequences.
- Stimulate and assess the risk by declaring methods, hypotheses, sources, uncertainties and effectiveness of the measures already present. The estimate must support a decision, not only produce a score.
- Apply the method in three stages: intrinsically secure design; guards, devices and other technical measures; information for use. Check after each intervention new hazards, interference and possibility of defeat.
- For safety-related command functions, define functional requirements, PLr or SIL, environmental conditions, reaction times, modes of operation and validation criteria; connect the results to the original dangerous situation.
- Manage changes and updates with versions, permissions, tests, logs and rollback criteria. A variation of software, data, parameters or models must activate the review when it can change limits, functions or risks. Reference
- Document residual risks and information for use, maintaining consistency with instructions for use, schematics, declarations, technical file and configuration actually placed on the market.
The documentation requested from point 7 must demonstrate the procedure followed and the results obtained. It must report machine and limits, hypotheses, hazards, situations and events considered, data and related sources, uncertainties, objectives and measures of reduction, residual risks and final outcome. The draft does not require to automatically deliver the risk assessment along with the machine: it clarifies however that the manufacturer must possess sufficient evidence to demonstrate the correctness of the process.
How Waves Engineering supports manufacturers
Waves Engineering supports manufacturers, integrators and technical offices in risk assessment and risk reduction throughout the project. The activity includes ISO 12100 analysis, verification of safety functions, calculation of Performance Level, revision of electrical and logical software schemes, validation, technical file, instructions for use and compliance support according to 2023/1230 Regulation. Reference
For connected or updateable machinery, the analysis links cybersecurity and safety-related software to the physical effects that can actually occur. For AI systems or adaptive behaviour, it defines limits, data, operating conditions, acceptance criteria and the need for reassessment. The objective is not to add documents, but to make consistency between risks, design decisions and test evidence demonstrable. Reference
FAQ
Is the new ISO 12100 already in effect?
No. At the date of 20 August 2026 ISO/DIS 12100.3 is still in the DIS phase and the ballot ends on 14 September 2026. The current version remains ISO 12100:2010.
When will the new EN ISO 12100 be published?
It is not possible to indicate a certain date from DIS. After the ballot, the project can move to FDIS and publish or undergo further revisions. European adoption and possible harmonisation also follow separate steps.
What is the difference between risk assessment and risk assessment?
Risk analysis includes determination of the limits, hazard identification and risk estimation. Risk assessment includes the analysis and the subsequent decision on whether further risk reduction is required.
Does cybersecurity have to enter the machine risk assessment?
Yes, when access, alteration or loss of communication can compromise a function and generate a dangerous situation. The draft considers computer violation a possible cause of dangerous events, not an autonomous physical danger.
Does the new ISO 12100 impose a risk matrix?
No. The project does not prescribe a unique matrix. It requires a systematic, motivated and documented process; the method chosen must be adapted to the machine and useful to decide the reduction measures.
PL calculation replaces risk assessment?
No. ISO 13849-1 is used to design and evaluate the safety-related parts of control systems. Its risk graph helps determine the required performance level (PLr) for a safety function, but does not replace the overall risk assessment under ISO 12100.
Does a C-type standard eliminate the need for risk analysis?
No. An applicable type-C standard can define specific measures and prevail over a type-B standard for the covered machine. The manufacturer must however verify scope, treated hazards, real configuration and uncovered risks.
Does ISO 12100 alone assume compliance with 2023/1230 Regulation?
No. The same Annex ZA of the draft states that the standard provides an essential framework, but alone does not cover all health and safety requirements and does not confer a complete presumption of conformity.




