
Auditing an Automation Equipment Manufacturer for ISO 13849 Safety Compliance
Learn how to audit an automation equipment manufacturer for ISO 13849 and IEC 62061 safety compliance, including document checklists and hardware verification.
Procuring automated machinery is a capital-intensive decision, but the hidden liability lies in safety compliance. When sourcing from an automation equipment manufacturer, the burden of proof for machine safety ultimately falls on the end-user in the eyes of regulatory bodies. A robotic arm from a major OEM is inherently safe in isolation; however, once an automation equipment manufacturer integrates that arm into a machine tending cell with conveyors, pneumatic clamps, and perimeter guarding, the entire system becomes a new machine subject to strict safety standards.
As of 2026, regulatory scrutiny on industrial automation has intensified. Facilities that deploy non-compliant automated systems face severe penalties, forced operational shutdowns, and catastrophic liability in the event of an injury. This guide provides a rigorous, technical framework for auditing an automation equipment manufacturer to ensure strict adherence to ISO 13849-1, IEC 62061, and regional equivalents like ANSI/RIA R15.06.
The Regulatory Reality: Component vs. System Compliance
The most common pitfall when purchasing automated systems is confusing component certification with system certification. An automation equipment manufacturer might advertise that their laser scanners are CE-marked and their safety relays are TÜV-certified. However, according to OSHA Machine Guarding guidelines, the integration of these components dictates the safety of the overall system.
⚠️ The "CE Mark" TrapA CE mark on a SICK microScan3 safety laser scanner only means the component meets the essential health and safety requirements of the Machinery Directive. It does not mean the automated cell it is installed in is compliant. The automation equipment manufacturer must mathematically prove that the component's diagnostic coverage (DC) and mean time to dangerous failure (MTTFd) satisfy the required Performance Level (PLr) of the specific safety function.
The 4-Point Document Audit Framework
Before issuing a purchase order, require the automation equipment manufacturer to submit the following documentation. If they cannot provide these, they are operating as a mechanical integrator, not a safety-compliant automation partner.
| Document Required | Purpose & Verification Method | Red Flags to Watch For |
|---|---|---|
| 1. ISO 13849-1 Risk Assessment Matrix | Identifies all hazards and assigns a required Performance Level (PLr) from PL a to PL e based on Severity, Frequency, and Possibility of avoidance. | Generic templates that do not list specific pneumatic or kinetic hazards unique to your application. |
| 2. Native SISTEMA Project Files | The IFA SISTEMA software is the industry standard for calculating PL. Demand the native .sistar or .zp file, not just a PDF export. |
Refusal to share native files; providing only PDF summaries which can be easily manipulated or cherry-picked. |
| 3. Safety Function Validation Protocol | A step-by-step testing matrix (per ISO 13849-2) proving that fault injection (e.g., simulating a stuck relay contact) results in a safe state. | Validation documents that only test "normal operation" without simulating hardware failures or cross-faults. |
| 4. Safety I/O Schematics | Electrical drawings showing dual-channel wiring, cross-fault detection monitoring, and safe torque off (STO) circuits. | Single-channel E-stop wiring routed through standard (non-safety) PLC input cards. |
Hardware BOM Verification: Spotting Cost-Cutting Measures
Unscrupulous automation equipment manufacturers will cut corners on the Bill of Materials (BOM) to win bids, hiding non-compliant hardware behind vague descriptions like "Safety Control System." You must audit the specific part numbers in the electrical BOM.
PLC and Controller Architecture
For a system requiring Performance Level d (PL d) or Category 3 architecture, standard programmable logic controllers are legally and technically insufficient. A standard PLC lacks the internal hardware redundancy and diagnostic coverage required to detect dangerous failures.
- Compliant Hardware: Allen-Bradley GuardLogix 5580, Siemens SIMATIC S7-1500F, or Pilz PNOZmulti 2. These feature dual-core processors with cross-monitoring and safe state outputs.
- Non-Compliant Hardware: Standard Allen-Bradley CompactLogix or Siemens S7-1200 (non-failsafe models) relying on software interlocks to manage E-stops.
Actuators and Motor Drives
Verify that the motor drives include native Safe Torque Off (STO) functionality compliant with IEC 61800-5-2. If the manufacturer proposes using standard contactors to cut power to a servo motor during an E-stop event, the system will fail Category 4 requirements due to the mechanical wear and welding risks inherent in standard contactors.
"A true safety architecture doesn't just remove power; it removes the potential for power. Relying on standard contactors for safety-rated stopping functions is a legacy practice that has no place in modern ISO 13849-compliant automation."
Financial Impact: The Cost of Non-Compliance
Retrofit Reality Check (2026 Pricing)
If your facility receives an automated cell and subsequently fails an internal or OSHA safety audit, the cost to retrofit the system is exponential compared to doing it right at the source.
- Hardware Swap: Replacing a standard PLC with a Siemens S7-1500F CPU and safety I/O modules: $4,500 - $7,200.
- Panel Rewiring: Rewiring dual-channel safety circuits and adding safety relays: $3,000 - $5,000 in labor.
- Engineering & Validation: Re-programming safety logic, generating new SISTEMA files, and executing fault-injection validation: $12,000 - $18,000.
- Downtime: 2 to 4 weeks of lost production while the panel is rebuilt and re-commissioned.
Total Estimated Retrofit Cost: $19,500 to $30,200+ per cell, entirely avoidable with proper manufacturer vetting.
Evaluating the Manufacturer's Safety Culture
Beyond paperwork and hardware, evaluate the organizational structure of the automation equipment manufacturer. Ask the following questions during the technical review phase:
- Do you have a dedicated, certified Functional Safety Engineer (FS Engineer) on staff? (Look for TÜV Rheinland or TÜV SÜD certifications).
- Is your safety validation process decoupled from the machine builder? The person who programmed the safety logic should not be the same person who validates it. Independent verification is a core tenet of ISO 13849-1.
- How do you handle safety software version control? Safety PLC code must be locked, password-protected, and checksum-verified to prevent unauthorized modifications by maintenance staff post-deployment.
Frequently Asked Questions
Can an automation equipment manufacturer self-certify their machinery?
Yes, under the CE framework, manufacturers can self-certify compliance with the Machinery Directive by compiling a Technical Construction File (TCF). However, for complex safety systems involving programmable electronics (Category 3 or 4), it is highly recommended to require third-party validation from a notified body like TÜV or UL to mitigate liability.
What is the difference between ISO 13849 and IEC 62061?
ISO 13849 uses Performance Levels (PL a-e) and is applicable to hydraulic, pneumatic, and electrical systems. IEC 62061 uses Safety Integrity Levels (SIL 1-3) and applies strictly to electrical/electronic/programmable systems. Most modern automation equipment manufacturers standardize on ISO 13849-1 due to its broader mechanical applicability, but both are legally recognized.
Does buying a robot from a major brand guarantee the cell is safe?
No. Brands like FANUC, Yaskawa, or KUKA provide collaborative or industrial robots that meet internal component safety standards. However, the end-effector, the parts being manipulated, and the perimeter guarding dictate the cell's risk profile. The automation equipment manufacturer integrating these components is legally the "manufacturer" of the final machine and bears the compliance burden.


