🛡️ Chapter 6: Safety Standards & Compliance
弘益人間 (홍익인간) · Benefit All Humanity
6.1 Safety Framework Overview
Safety is paramount for humanoid robots operating in human environments. WIA-ROB-019 builds upon established safety standards while addressing unique challenges of humanoid form factors. This chapter details safety requirements, testing procedures, and compliance verification.
6.1.1 Applicable Safety Standards
WIA-ROB-019 integrates requirements from multiple international safety standards:
| Standard | Scope | Key Requirements for Humanoid Robots |
| ISO 13482 | Personal care robots | Risk assessment, protective/inherently safe design, validation |
| ISO 10218 | Industrial robots | Safety-rated monitoring, emergency stop, power/force limiting |
| IEC 61508 | Functional safety | Safety integrity levels (SIL), systematic failure prevention |
| UL 3300 | Service robots | Electrical safety, fire hazards, mechanical hazards |
| IEC 60950 | IT equipment | Electrical safety, EMC, material safety |
| ISO/TS 15066 | Collaborative robots | Human-robot collaboration safety, biomechanical limits |
WIA-ROB-019 consolidates these requirements into a unified framework specific to humanoid robots, avoiding redundancy while ensuring comprehensive safety coverage.
6.1.2 Risk Assessment Methodology
Before deployment, comprehensive risk assessment required:
- Hazard Identification: Systematically identify all potential hazards (mechanical, electrical, thermal, chemical, radiation, ergonomic, environmental).
- Risk Estimation: For each hazard, estimate severity and probability. Use standard risk matrices (ISO 12100). Severity levels: Negligible, Minor, Moderate, Critical, Catastrophic. Probability: Rare, Unlikely, Possible, Likely, Certain.
- Risk Evaluation: Compare estimated risks against acceptable risk criteria. High and medium risks require mitigation.
- Risk Reduction: Apply hierarchy of controls: Inherently safe design (preferred) > Engineering controls > Administrative controls > PPE (least preferred).
- Residual Risk Assessment: Evaluate remaining risk after mitigation. Document residual risks. Ensure acceptable for intended use.
- Documentation: Maintain risk assessment documentation throughout robot lifecycle. Update as changes made.
6.2 Mechanical Safety
6.2.1 Contact Force Limitations
ISO/TS 15066 establishes biomechanical limits for human-robot contact. WIA-ROB-019 adopts these limits with safety margins:
| Body Region | Maximum Force (Transient) | Maximum Pressure | Maximum Power |
| Skull/Forehead | 130 N | 110 N/cm² | 80 W |
| Face | 65 N | 75 N/cm² | 50 W |
| Neck | 150 N | 140 N/cm² | 90 W |
| Back/Shoulders | 210 N | 160 N/cm² | 140 W |
| Chest | 140 N | 110 N/cm² | 100 W |
| Abdomen | 110 N | 90 N/cm² | 80 W |
| Pelvis | 180 N | 150 N/cm² | 120 W |
| Upper Arm/Forearm | 160 N | 130 N/cm² | 110 W |
| Hand | 140 N | 120 N/cm² | 100 W |
| Thigh/Leg | 220 N | 160 N/cm² | 150 W |
| Foot | 180 N | 140 N/cm² | 120 W |
Implementation Requirements:
- Force/torque sensors at all manipulators (wrists minimum, elbows preferred)
- Contact detection within 10ms of force threshold exceedance
- Protective stop (motion halt) within 100ms of contact detection
- Compliant surface coverings on all potential contact areas (reduce peak forces)
- Safety-rated force monitoring (SIL 2 minimum, PLd ISO 13849)
6.2.2 Pinch and Crush Point Protection
Prevent pinching or crushing hazards:
- Minimum Gap: All gaps that could close must remain >25mm or close to <5mm (too small for finger insertion). Critical for joints, grippers.
- Force Limiting: If pinch point unavoidable, limit force to safe levels. <50N between flat surfaces, <75N if one surface is rounded.
- Guarding: Physical guards preventing access to dangerous areas. Fingers can't reach drive belts, gears, or shear points.
- Detection: Optical or tactile sensors detecting objects in potential pinch zones. Stop motion if detection triggers.
6.2.3 Sharp Edge and Protrusion Protection
Eliminate injury risks from sharp edges or protruding parts:
- All edges must have minimum radius of 2mm (preferably 5mm)
- No sharp corners or pointed features on external surfaces
- Protrusions limited to <10mm from main body surfaces
- Smooth transitions between components
- Regular inspection for wear, damage creating sharp edges
6.2.4 Stability and Tipping Prevention
Humanoid robots must resist tipping during normal operation:
- Static Stability: With maximum payload at maximum reach, robot must not tip on 10° slope in any direction.
- Dynamic Stability: During locomotion, maintain balance with disturbances up to 50N horizontal force at waist level.
- Emergency Situations: If fall unavoidable, controlled descent to minimize impact forces. Deploy arms, tuck head, reduce joint stiffness.
- Recovery: Ability to self-right from seated or prone position (Level 3 compliance).
6.3 Electrical Safety
6.3.1 Voltage and Current Requirements
Protection from electrical hazards:
- Low Voltage Design: All user-accessible circuits must operate <60V DC or <30V AC (SELV - Safety Extra-Low Voltage).
- Double Insulation: High voltage components (battery charging, motor drivers) must have double insulation or equivalent protection.
- Ground Fault Protection: GFCI/RCD protection on charging circuits. Trip time <30ms at 30mA.
- Overcurrent Protection: Fuses or circuit breakers on all power circuits. Sized for 125% of maximum continuous current.
- Isolation: Galvanic isolation between high voltage and low voltage circuits. Minimum 4kV isolation rating.
6.3.2 Battery Safety
Lithium-ion batteries pose fire and chemical hazards:
- Battery Management System (BMS): Mandatory for all Li-ion batteries. Monitor voltage, current, temperature of all cells. Implement balancing, overcharge protection, over-discharge protection, short circuit protection.
- Thermal Management: Active or passive cooling to maintain cells <45°C during normal operation. Thermal cutoff at 60°C.
- Mechanical Protection: Rigid enclosure protecting cells from impact, puncture, crushing. IP54 minimum (dust and splash protection).
- Containment: If thermal runaway occurs, contain to single cell. Flame-resistant barriers between cells. Pressure relief vents directing gases away from users.
- Compliance: Batteries must meet UL 2271 or IEC 62133 standards.
6.3.3 Electromagnetic Compatibility (EMC)
Ensure robot doesn't interfere with other equipment and is immune to interference:
- Emissions: Meet FCC Part 15 Class B (residential) or EN 55011 Group 1 Class B limits for radiated and conducted emissions.
- Immunity: Withstand radiated RF fields (10 V/m, 80-1000 MHz), ESD (±8kV contact, ±15kV air), conducted disturbances without malfunction.
- Testing: Full EMC testing in accredited lab. Pre-compliance testing during development.
6.4 Functional Safety
6.4.1 Safety-Rated Systems
Critical safety functions must meet Performance Level (PL) or Safety Integrity Level (SIL) requirements:
| Safety Function | Required PL/SIL | Implementation |
| Emergency Stop | PLe / SIL 3 | Dual-channel safety relay, monitored contacts |
| Contact Force Limiting | PLd / SIL 2 | Dual F/T sensors with cross-checking |
| Safety-Rated Speed Monitor | PLd / SIL 2 | Dual encoders with diverse technology |
| Safe Torque Off (STO) | PLd / SIL 2 | Redundant power contactors to motor drivers |
| Safe Stop (SS1, SS2) | PLc / SIL 1 | Monitored controlled stop |
| Protective Stop (Contact) | PLd / SIL 2 | Force monitoring with safe motion disable |
Architectural Requirements:
- Redundancy for all safety-critical sensors and actuators
- Diversity where practical (different sensor technologies, suppliers)
- Diagnostic coverage >90% for PLd/SIL2, >99% for PLe/SIL3
- Proven-in-use components or components meeting safety standards (IEC 61508, ISO 13849)
- Safety-certified software development (IEC 61508-3, ISO 26262 ASIL D equivalent)
6.4.2 Emergency Stop System
Immediately halt all hazardous motion:
- Activation: Large red mushroom button (ISO 13850) on robot body. Easily accessible from all approach directions. Wireless e-stop pendant for operator (Level 2+).
- Function: Remove power to all actuators (STO - Safe Torque Off). Do not rely on software. Hardware-based power disconnection.
- Response Time: From button press to motion stop <250ms. Total stopping time (including deceleration) <500ms.
- Reset: Manual reset required after e-stop. Cannot auto-reset. Must check for hazards before reset.
- Reliability: Cat 4 per ISO 13849 or SIL 3 per IEC 62061. MTBF >100 years. Dangerous failure rate <10⁻⁸/hour.
6.4.3 Redundancy and Fail-Safe Design
Safety-critical systems must fail to safe state:
- Power Loss: Loss of power must result in safe state (brakes engage, robot settles to ground safely).
- Communication Loss: Loss of communication with controller triggers protective stop within 200ms.
- Sensor Failure: Invalid sensor data triggers safe response. Don't assume sensor reads safe value.
- Software Fault: Watchdog timers, memory checks, plausibility checks detect faults. Safe state on fault detection.
- Single Point Failures: No single failure (hardware or software) can lead to hazardous situation.
6.5 Software Safety
6.5.1 Software Development Process
Safety-related software must follow rigorous development process:
- Requirements: Formal safety requirements specification. Traceability from hazard analysis to requirements to implementation to tests.
- Design: Modular architecture with clear separation of safety-critical and non-critical functions. Documented design using UML, SysML, or equivalent.
- Coding Standards: MISRA C/C++, or equivalent. Automated static analysis to detect violations, potential bugs.
- Version Control: All code in version control (Git). Tagged releases. Change management process.
- Review: Code review for all safety-critical functions. Independent safety review.
- Testing: Unit tests (>90% code coverage), integration tests, system tests, safety validation tests. Automated regression testing.
6.5.2 Runtime Monitoring and Diagnostics
Continuous monitoring during operation:
- Watchdogs: Independent hardware watchdog monitors safety controller. Timeout <100ms triggers safe state.
- Plausibility Checks: Sensor values checked for plausibility. Cross-check redundant sensors. Physical limits, rate limits.
- Error Detection: CRC/checksum on critical data. Memory tests (RAM, Flash). Communication integrity checks.
- Logging: Record safety-relevant events. Error logs, contact events, protective stops. Support post-incident analysis.
- Diagnostics: Self-diagnostic tests at startup and periodically during operation. Report degraded safety function before complete failure.
6.6 Operational Safety
6.6.1 Safeguarded Spaces
Define zones around robot with different safety measures:
- Exclusion Zone (0-0.3m): No human presence allowed during operation (except contact tasks). If human detected, immediate protective stop.
- Restricted Zone (0.3-1.0m): Speed limited to <250 mm/s (hand-guiding speed). Enhanced collision detection active.
- Awareness Zone (1.0-3.0m): Robot aware of human presence. Predictive collision avoidance. May slow preemptively.
- Monitoring Zone (>3.0m): General environment monitoring. Track approaching humans.
6.6.2 Operational Modes
Different modes with appropriate safety measures:
| Mode | Purpose | Speed Limit | Safety Requirements |
| Programming | Teaching, debugging | 250 mm/s | Enabling device (3-position), single-step mode available |
| Automatic | Normal operation | Full speed | All safety systems active, safeguarded space monitoring |
| Collaborative | Work with human | 500 mm/s | Force/torque monitoring, contact detection, safe speeds |
| Maintenance | Service, repair | Disabled | LOTO (lockout/tagout), energy isolation |
6.6.3 Personnel Training
Operators and maintenance personnel must be trained:
- Operator Training: Safe operation procedures, normal robot behaviors, emergency procedures, when to e-stop, basic troubleshooting. Minimum 4 hours hands-on training. Annual refresher.
- Maintenance Training: Safety procedures, LOTO, diagnostics, calibration, software updates. Minimum 16 hours. Manufacturer certification preferred.
- Documentation: Training records maintained. Competency verification.
6.7 Information for Use
6.7.1 User Manual Requirements
Comprehensive documentation provided:
- Safety Information: Warnings, intended use, reasonably foreseeable misuse, residual risks, emergency procedures.
- Technical Specifications: Dimensions, weight, payload, speed, force limits, power requirements, environmental conditions.
- Installation: Setup procedures, workspace requirements, environmental requirements.
- Operation: Control interfaces, operational modes, task examples, error messages and resolution.
- Maintenance: Routine maintenance schedule (daily, weekly, monthly, annual), calibration procedures, replacement parts.
- Troubleshooting: Common problems and solutions, diagnostic codes, when to contact support.
- Decommissioning: Safe disposal, battery recycling, data erasure.
6.7.2 Labeling and Markings
Clear, permanent labels on robot:
- Manufacturer name and contact information
- Model number, serial number
- Manufacturing date, CE/UL markings
- Maximum payload, speed warnings
- E-stop button clearly marked
- Battery type and capacity
- Electrical ratings (voltage, current, power)
- Warning symbols (ISO 7010) for hazards
- QR code linking to online documentation
6.8 Testing and Certification
6.8.1 Type Testing
Comprehensive testing of robot design:
- Mechanical Tests: Force limiting validation, stability tests, endurance testing (1000+ hours operation), environmental testing (temperature, humidity, dust).
- Electrical Tests: Insulation resistance, dielectric strength, ground continuity, leakage current, battery safety tests, EMC testing.
- Functional Safety Tests: Emergency stop response time, safety function validation, fault injection testing, software safety validation.
- Performance Tests: Speed, accuracy, repeatability, payload capacity, battery life, sensor performance.
- User Interface Tests: Speech recognition accuracy, gesture recognition, display readability, control responsiveness.
6.8.2 Production Testing
Every manufactured unit tested:
- Electrical safety tests (hi-pot, ground continuity, leakage)
- Functional tests (all joints move correctly, sensors functioning)
- Calibration verification (sensors, cameras, force sensors)
- Software checksum verification
- Emergency stop function test
- Documentation of test results with serial number
6.8.3 Certification Bodies
Third-party certification recommended or required:
- CE Marking (Europe): Self-declaration or notified body assessment. Machinery Directive 2006/42/EC, EMC Directive, RoHS.
- UL Certification (North America): UL 3300 for service robots. Testing and ongoing surveillance by UL.
- ISO 13482 Certification: Voluntary certification demonstrating compliance with personal care robot standard. Enhances market acceptance.
- National Certifications: Additional certifications for specific markets (PSE Japan, CCC China, KCTESTLAB Korea, etc.).
6.9 Chapter Summary
This chapter examined safety standards and compliance for humanoid robots. We covered the safety framework integrating multiple international standards, mechanical safety including force limitations and crush point protection, electrical safety for batteries and circuits, functional safety with safety-rated systems and emergency stops, software safety development and monitoring, operational safety protocols, user information requirements, and testing and certification procedures.
Safety is not optional—it's the foundation enabling humanoid robots to work safely alongside humans. WIA-ROB-019 safety requirements ensure robots meet rigorous safety standards while remaining practical for real-world deployment.
In Chapter 7, we'll explore implementation and integration—how to bring together the mechanical systems, control algorithms, sensors, and safety features into a working humanoid robot system.