ISO 10218:2025 separates requirements for the industrial robot from requirements for the integrated robot application and cell. The manufacturer supplies a robot with declared limits, safety functions, interfaces and information; the integrator closes risks created when that robot is combined with tooling, process and people.
The final user retains operational duties: maintaining approved conditions, inspections, competence, incident response and change control. A contract can allocate work but cannot make an unperformed risk assessment or validation disappear.
This is an educational responsibility map, not legal advice or a conformity decision. Consult the full standards, applicable law and competent safety professionals. Pair it with the functional-safety guide.
Use Part 1 and Part 2 for different objects
The official catalog identifies ISO 10218-1:2025 for industrial robots and ISO 10218-2:2025 for industrial robot applications and cells. Part 2 addresses integration through the application lifecycle within its stated scope.
A Part 1 robot is not a completed safe cell. Tool, workpiece, layout, access, process energy and control integration create additional hazards.

Define roles from actual work and boundaries
Name who specifies, designs, supplies, programs, integrates, validates, commissions, accepts, operates and modifies each subsystem. A company called the user may perform integration work; a supplier may deliver only one component.
Create a responsibility matrix with deliverables and acceptance authority. Resolve shared interfaces rather than leaving both parties to assume the other owns them.
| Role | Primary object | Key output | Gap to avoid |
|---|---|---|---|
| Robot manufacturer | Robot product | Limits and integration information | Undefined interface |
| Tool supplier | End effector | Limits and hazards | Payload-only claim |
| Integrator | Application and cell | Risk reduction and validation | Unclosed process risk |
| Final user | Operation | Training, inspection, change control | Baseline drift |
| Modifier | Changed system | Impact assessment and revalidation | Silent redesign |
Require complete manufacturer information
Integration inputs include robot limits, load and mounting conditions, safety functions, interfaces, stopping data, operating modes, environmental limits and instructions. Confirm that data applies to the exact hardware and software version.
Missing or ambiguous supplier information becomes an integration issue that must be resolved, not an assumption hidden in the safety file.
Integrate the whole application risk
The integrator evaluates the robot together with tool, workpiece, fixtures, process, other machines, access, utilities and people across normal and non-production modes. Interfaces between individually suitable components can still create unsafe states.
Use the safety-layers guide to separate independent protective functions from learned behavior.
Validate safety functions end to end
A component certificate does not prove the application function. Test from initiating sensor and logic through communications, drive reaction, brakes and the achieved safe state under faults and adverse timing.
Record architecture, required and achieved performance, test method, result, configuration and residual limitations. Validate reset and restart as carefully as the stop.

Verify stopping and spaces with the installed tool
Robot stopping and reachable geometry change with payload, center of gravity, tool extension, speed, pose and program. Measure relevant adverse cases and model every moving or carried part.
Do not reuse bare-robot data without checking its conditions. Link measured values to safeguarding and collaborative-operation calculations.
Close end-effector and process hazards
Grippers, welders, cutters, vacuum tools and workpieces introduce pinch, drop, heat, electrical, radiation, sharp and process-specific hazards. These can dominate risk even when robot motion is limited.
Use current application-specific guidance and the end-effector safety guide when available, while preserving the integrator’s whole-system responsibility.
Commission every operating and recovery mode
Test automatic, setup, teaching, fault recovery, cleaning, maintenance and restart. Temporary bypasses or reduced safeguards during commissioning need controlled authorization and equivalent protection.
Exercise foreseeable misuse, communication loss, wrong tool, bad payload, sensor fault and person remaining in the cell. Normal production cycles are not sufficient validation.
Handover a configuration baseline, not a document pile
The user needs exact hardware and software versions, programs, safety parameters, drawings, risk assessment, validation results, residual risks, inspection schedules, training and recovery procedures. Verify that recipients understand critical limits.
Use checksums, controlled backups and restoration tests. An unlabeled controller export cannot establish the accepted baseline.
Retain user responsibility after acceptance
The user maintains guarding, safety functions, training, inspections, access control, incident response and approved operating conditions. Production pressure must not normalize bypasses or unreviewed parameter changes.
Record near misses and stopping trends, and escalate configuration drift. Procurement acceptance does not end the safety lifecycle.
Reassess modifications and cybersecurity effects
Program, tool, payload, speed, layout, sensor, network, firmware and AI changes can invalidate earlier assumptions. Cybersecurity events can also affect safety-related availability, integrity or authority.
Use the robot cybersecurity guide and require impact review before enabling changed operation.
| Handover gate | Evidence | Owner | Failure |
|---|---|---|---|
| Limits | Applicable supplier data | Manufacturer | Wrong assumptions |
| Integration | Risk and design records | Integrator | Open hazards |
| Validation | End-to-end test results | Validator | Paper compliance |
| Training | Competence and procedures | User | Unsafe recovery |
| Change | Impact and approval | Change owner | Baseline drift |
Sign an explicit responsibility handover
List open issues, residual risks, conditions of use, required inspections, excluded applications, change triggers and authorized approvers. Signatures should confirm understanding and completed evidence, not transfer an unresolved technical gap.
Close review with the following checks.
- Separate robot-product and application boundaries.
- Assign every integration and validation deliverable.
- Test safety functions end to end.
- Handover an exact controlled configuration.
- Maintain user operation and change responsibilities.
Frequently asked questions
Does an ISO 10218-1 robot make the cell compliant?
No. The integrated application and cell need their own risk reduction and validation.
Does the user have no responsibility after an integrator delivers?
No. Safe operation, training, inspection and change control continue with the user.
Can a tool declaration replace integration testing?
No. Installed interfaces and whole-application hazards still require validation.
Does a robot program change require review?
Yes when path, speed, timing, modes, interfaces or risk assumptions may change.
Does applying the 2025 edition automatically satisfy law?
No. Applicability, transition and legal requirements depend on jurisdiction and project context.
Product-to-Application Responsibility Boundary
ISO 10218 responsibility follows the technical object and work performed. Close every boundary with owned evidence, validated integration, informed handover and controlled operation.