Robot safety is the discipline that decides what a robot is allowed to do next to a person, and it runs on standards, assigned safety levels and documentation rather than engineering intuition. The 2025 revision of ISO 10218 restructured the field: Part 1 treats the robot as partly completed machinery, and Part 2, a type-C standard per ISO 12100, carries the requirements for integrating applications and cells, including most of what ISO/TS 15066 previously held for collaborative work . Hiring for this discipline means finding specialists who can produce the risk assessment, the safety functions and the technical file that a cell's legality and a worker's body both depend on.
Challenges in Robot Safety Recruiting
Robot safety standards regrouped around the 2025 ISO 10218 revision
The 2025 revision of ISO 10218 did something rare in standardization: it absorbed most requirements of ISO/TS 15066 into Part 2 and dropped the term collaborative robot entirely . The standard's position is that only an application can be developed, verified and validated as collaborative, because human-robot collaboration is a property of how the cell works, not what the arm is called . Part 1 keeps the robot itself, as partly completed machinery, while Part 2 owns integration, commissioning, operation, maintenance and decommissioning .
The practical effect on hiring is that collaborative robot safety knowledge is now embedded in the main standard rather than a separate specification, and specialists who learned only the 2016 technical specification are working from a superseded map. The new text splits safety requirements across design, safety functions, safeguards, collaborative applications, verification and validation, with normative annexes for safety function performance and speed and separation monitoring . A candidate's answer to which edition they integrated against tells you immediately which population they belong to.
Risk assessment assigns each safety function a performance level
Risk assessment in robot cells is not a document written once and filed; it is the process that assigns a required performance level to every safety function, one by one. ISO 10218-2 dedicates a clause to risk assessment and an informative annex to determining the PLr or required SIL for each function . A protective stop on a full-speed cell typically lands at PLr d, which ABB's safety manual maps through its own controller: redundant dual-channel architecture meeting category 3, with the rule that a single fault in the safety-related parts shall not lead to loss of the safety function .
That sentence structure is the whole craft. A real robot safety engineer can walk a cell and list its safety functions, then defend the assigned PLr for each: the emergency stop, the door interlocks, the enabling device, the speed monitoring. The performance level is assigned to the function, not to the machine, and the assignment changes with severity, frequency and the possibility of avoidance . Interviews that test this instinctively separate practitioners from people who have only read about the standard.
Functional safety splits PLC logic from certified robot controllers
Functional safety in robot cells lives on two rails that candidates confuse. IEC 62061, derived from IEC 61508, assigns SIL 1 to 3 to safety-related control systems and makes functional safety management normative; ISO 13849 assigns performance levels PL a through e to machinery circuits and keeps management informative, which is why the two standards are described as cousins rather than siblings . In practice a cell contains both worlds: a safety PLC running interlocks and guarding logic, wired through safe inputs to a robot controller whose own safety functions are certified against ISO 13849 or IEC 61508 .
The hiring risk is that the two populations barely overlap. PLC safety engineers think in wiring, relays, feedback loops and monitoring circuits; controller-side engineers think in supervision functions, safe motion limits and the controller's internal architecture. A cell integration needs both, coordinated through the same risk assessment, and most projects fail quietly in the interface between them. The rare profile that owns both sides commands the market because the standard holds the integrator responsible for the combination .
Safety-rated monitoring turns motion parameters into protective measures
Safety-rated monitoring is where the control system becomes the safeguard. ISO 10218-2 requires speed limit monitoring, monitored standstill and start/restart interlocks as safety functions, and its normative annex sets out how speed and separation monitoring computes protective separation distances from approach speeds . At the drive level the same logic appears as IEC 61800-5-2 subfunctions such as safe torque off, safe limited speed and safe brake control, each with its own integrity requirement . The performance level and the safety integrity level describe the same physics from different standard families: diagnostic coverage and MTTFd on the machinery side, safe failure fraction and probability of dangerous failure per hour on the IEC side .
Engineers who have configured these functions on a real controller are scarce because the work combines control theory, standards interpretation and commissioning under live conditions. A candidate who has parameterized a supervision function, set its limits from a risk assessment and validated the result in a cell owns evidence that a candidate who has only specified such functions never will.
Industrial robot safety faces the integration gap between -1 and -2
Industrial robot safety has a structural split built into its numbering. ISO 10218-1 addresses the robot as partly completed machinery, with requirements for its inherently safe design and safety functions . ISO 10218-2 then places the burden on whoever completes the machine: the integrator must run the risk assessment, select the safeguards, verify the safety functions and document the result . The robot vendor can certify a compliant arm; the cell's safety case still belongs to the integrator, and a declaration of conformity is only as good as that work.
That split is why the discipline's most valuable experience is integration-side rather than vendor-side. A candidate who worked for an arm manufacturer knows the controller's certified functions; a candidate who integrated cells for an end user knows what happens when those functions meet real floor layouts, material flow and operator behavior. Both write robot safety on their CVs, and the difference only emerges under questioning about responsibility boundaries and validation records.
Safety systems claims need the technical file, not vocabulary
Assessment in robot safety is unusually checkable because the discipline is a documentation discipline. Every credible claim ends in a technical file: risk assessments, assigned PLr or SIL per safety function, architecture and circuit category, validation records from commissioning, and the declaration of conformity the integrator signs . The probes are concrete. Ask which safety functions the candidate's last cell contained, what PLr each carried, how the achieved level was verified, and what happened when a single fault was simulated at commissioning. Ask them to reconstruct a stop category decision or a separation distance calculation.
Candidates who can produce that file built it; candidates who describe the standards attended them. The cost of guessing wrong lands in two places: an audit finding or an injury, whichever arrives first, plus a declaration of conformity that stops protecting the employer the moment a reviewer finds the file weak . Robot safety is the one robotics discipline where the interview can end by asking for the paperwork, and the strongest candidates hand it over without hesitation.
References
- ISO 10218-2:2025 - Robotics - Safety Requirements - Part 2: Industrial Robot Applications and Robot Cells — International Organization for Standardization (ISO). (accessed 2026-09-28)
- ISO 10218-1:2025 - Robotics - Safety Requirements - Part 1: Industrial Robots — International Organization for Standardization (ISO). (accessed 2026-09-28)
- Application Manual - Functional Safety and SafeMove RW 8 — ABB Robotics. (accessed 2026-09-28)
- Machinery Functional Safety Using IEC 62061 and ISO 13849 — 61508 Association Symposium (P. Brown). (accessed 2026-09-28)
- Simplifying Robotics Motor Drive Safety Assessments (SPRAD98) — Texas Instruments. (accessed 2026-09-28)
