Risk analysis is perhaps the most technical step of the CE process, and the one that requires the most genuine engineering judgment. While other components of the technical file (the declaration of conformity, the user manual) largely follow a standard format, risk analysis is a real engineering assessment that produces different results for every product. In this article we cover what risk analysis is, which methodology it follows, and how it is applied step by step, within a concrete framework for machinery and equipment manufacturers.
What Is Risk Analysis, and Why Does It Matter So Much?
Risk analysis is an engineering process in which all the hazards a product may present, from the design stage through to the end of its service life, are systematically identified, the risks these hazards create are estimated, and the necessary mitigation measures are determined. Within CE legislation, risk analysis is a step explicitly required for products under the Machinery Directive 2006/42/EC and Machinery Regulation (EU) 2023/1230, which will progressively replace it; in practice, however, a risk assessment is expected for almost every electrical, electronic and mechanical product.
The importance of risk analysis has two dimensions. The first is the direct safety dimension: it ensures the product is designed so as not to harm the end user, maintenance personnel, or even third parties in the product's vicinity. The second is the legal and documentation dimension: the risk analysis report is one of the most critical components of the technical file, and forms the justification for "why we chose this standard, why we applied this protective measure." See our article What Is the CE Technical File? for more on the overall structure of the technical file.
Risk Analysis Methodology: The ISO 12100 Approach
The most widely accepted methodological framework for risk analysis in machinery safety is the ISO 12100 standard ("Safety of Machinery — General Principles for Design — Risk Assessment and Risk Reduction"). This standard breaks risk assessment into a sequence of logical steps: determining the machine's limits (intended use, intended and foreseeable misuse, service life), hazard identification, risk estimation (assessing severity and probability), risk evaluation (determining whether the risk is acceptable) and, where necessary, risk reduction. This cycle repeats until the residual risk is reduced to an acceptable level.
Hazard Identification: Which Hazard Types Are Assessed?
A systematic risk analysis scans a broad set of hazard categories that varies by product type. These include mechanical hazards (crushing, cutting, entanglement, ejection), electrical hazards (electric shock, arcing), thermal hazards (burns, frostbite), noise- and vibration-related hazards, material- and substance-related hazards (toxic gas, dust, chemical exposure), ergonomic hazards (poor posture, excessive strain), and hazards from control system failures (unexpected movement due to software or electronic malfunction). For each product group, additional hazard categories defined in product-specific type-C standards (for example, a dedicated safety standard written for a specific machine type) must also be taken into account, on top of this general list.
Risk Estimation: Assessing Severity and Probability
For each identified hazard, risk is generally estimated by combining two core components: the severity of the possible harm (from a minor injury to a fatal injury) and the probability of that harm occurring (frequency of exposure, probability of the hazardous event, and the possibility of avoiding the harm). Some methodologies carry out this assessment using a numerical risk matrix, while others rely on qualitative judgment; what matters is that the chosen method is applied consistently and repeatably. The outcome of risk estimation clarifies which hazards need to be prioritized for reduction.
Priority Order for Risk Reduction: A Three-Stage Approach
ISO 12100 defines a clear priority hierarchy for risk reduction, and compliance with this hierarchy is expected:
- 1. Elimination through design (inherently safe design): Directly eliminating the hazard through design or minimizing its risk — for example rounding sharp edges, eliminating crush points, reducing voltage. This is always the first and most preferred method.
- 2. Technical protective measures and complementary measures: For risks that cannot be fully eliminated through design, using protective equipment such as guards, safety switches, emergency stop systems or light curtains.
- 3. User information: For risks that remain even after the two stages above, providing warnings in the user manual, warning labels on the product, and — where needed — training or personal protective equipment recommendations.
A common mistake is to reverse this hierarchy and jump straight to the third stage (simply adding a warning label). The legislation and the standards, however, expect design and technical solutions to be exhausted first, with a warning used only as a last resort for the risks that remain.
Residual Risk and Documentation
Even after all reasonable mitigation measures have been applied, some risks may not be fully eliminated — this is called "residual risk." Residual risks must be clearly identified and stated in the user manual and, where necessary, on labels on the product. Every stage of the risk analysis — hazard identification, risk estimation, applied measures and the residual risk assessment — must be documented in writing and kept as part of the technical file. This documentation both shows the rationale behind design decisions and forms the basis of the manufacturer's defense in a possible audit or product liability claim.
Supporting Techniques Used in Risk Analysis
The general framework defined by ISO 12100 is supported in practice by various structured techniques. One of the most commonly used methods is Failure Mode and Effects Analysis (FMEA), which systematically examines the possible failure modes of each component of a product, the consequences of those failures, and their detectability. For complex control systems or process equipment, a Hazard and Operability Study (HAZOP) may be preferred; this method uses a structured line of questioning to investigate which hazards can arise from deviations in a system's normal operating parameters (such as pressure, temperature, flow rate). For simpler products, checklist-based hazard identification may be sufficient, where each item in the product-specific type-C standard's hazard list is assessed individually.
Which technique to choose depends on the product's complexity, risk level, and the company's existing engineering capacity. What matters is that the chosen method is applied consistently and the results are documented in a traceable way. Some companies, especially for high-risk or complex machinery, use more than one technique together (for example, a checklist for the general scan and FMEA for critical subsystems) to provide more comprehensive assurance. The output of the risk analysis directly shapes the content of the technical file and user manual at the next stage — which is why explicitly stating the chosen methodology in the report makes the process easier to trace during audits.
Relevant Directives and Standards
The legal basis for risk analysis varies by product type. For machinery and mechanical equipment, the core reference is the Machinery Directive 2006/42/EC (to be progressively replaced by Machinery Regulation (EU) 2023/1230 from 20 January 2027); this legislation directly requires the manufacturer to carry out a risk assessment. For the methodological framework, the general standard ISO 12100 applies; for electrical risks, harmonized standards under the Low Voltage Directive 2014/35/EU serve as complementary references. In addition, for many product groups there are type-C harmonized standards specific to that product that complement the general ISO 12100 — these standards define more concretely which hazards are typical for that product group and which protective measures are expected. See our article Which Directives Apply to My Product? to determine which standard applies to your product.
| Stage | Purpose | Typical Output |
|---|---|---|
| Determining limits | Define intended use and foreseeable misuse | Scope definition |
| Hazard identification | List all mechanical, electrical, thermal, etc. hazard sources | Hazard list |
| Risk estimation | Assess severity and probability | Risk score/level |
| Risk reduction | Apply mitigation in order: design, technical measure, information | Updated design/protective measures |
| Verification | Confirm the residual risk is acceptable | Risk analysis report |
Step by Step
- Determine the product's limits by defining its intended use, intended and foreseeable misuse scenarios, and service life.
- Systematically identify hazard sources, taking into account every stage of the product's lifecycle (assembly, normal use, maintenance, malfunction, decommissioning).
- Estimate risk (severity x probability) for each hazard, according to ISO 12100 and relevant type-C standards.
- For hazards with an unacceptable risk level, first assess elimination-through-design options.
- For risks that cannot be fully eliminated through design, determine technical protective measures (guards, safety switches, emergency stop).
- Identify residual risks and clearly state them in the user manual and on product labels.
- Verify that the applied measures genuinely reduce the risk to an acceptable level; repeat the cycle if necessary.
- Turn the entire process into a written risk analysis report and attach it to the technical file.
- Update the risk analysis whenever the product design or use conditions change.
Most Common Mistakes
- Carrying out risk analysis retroactively after the design is complete, purely to fill in the file.
- Assessing only the intended use and ignoring foreseeable misuse scenarios.
- Skipping the risk reduction hierarchy and going straight to a warning label.
- Not documenting the risk analysis in writing or including it in the technical file.
- Not clearly stating residual risks in the user manual and on the product.
- Neglecting to update the risk analysis after a design change.
- Applying the general ISO 12100 approach while completely ignoring the product-specific type-C standard.
- Basing risk estimation on a single person's subjective judgment instead of a multidisciplinary assessment.
Frequently Asked Questions
Are risk analysis and risk assessment the same thing?
Risk assessment is a broader concept and also includes checking the effectiveness of risk reduction, in addition to risk analysis (hazard identification + estimation). Risk analysis is a sub-component covering the hazard identification and risk estimation steps of this broader process.
Which standard governs how risk analysis is done?
In machinery safety, the most widely used reference is ISO 12100, which defines the general principles. Depending on the product type, the risk assessment provisions in electrical or sector-specific type-C standards must also be taken into account.
Who should carry out risk analysis?
Risk analysis should be carried out by people who know the product's design, use conditions and technical characteristics — preferably a multidisciplinary team (design engineer, safety specialist, staff with hands-on usage experience).
At which stage of product design should risk analysis be done?
Risk analysis should start as early as possible, at the conceptual design stage, and be updated iteratively as the design evolves. A late risk analysis carried out after the design is finalized can lead to costly design changes.
What is the priority order for risk reduction?
The priority order is: first, eliminate the hazard entirely through design (inherently safe design); if that isn't possible, apply technical protective measures (guards, safety switches, etc.); and finally, provide information and warnings to the user for any remaining risks.
Must risk analysis be documented?
Yes, the risk analysis and the measures taken must be documented in writing and kept as an integral part of the product's technical file. This documentation is one of the primary pieces of evidence proving conformity during inspections.
What does residual risk mean?
Residual risk is the level of risk that remains even after all reasonable protective measures have been taken. These risks must be clearly stated in the user manual and on warning labels on the product.
Is risk analysis done once and never updated?
No. Risk analysis must be reviewed and, where necessary, updated whenever there is a change in the product design, intended use, or foreseeable misuse scenarios.
How is foreseeable misuse assessed in risk analysis?
Reasonably foreseeable misuse scenarios — mistakes a user might make despite the instructions — must also be included in the risk analysis; an assessment limited only to the intended use scenarios is considered incomplete.
What is the relationship between risk analysis and the CE technical file?
Risk analysis is one of the most critical components of the technical file; it is the core evidence justifying which standards the product was designed against and why each protective measure was chosen. See our article, What Is the CE Technical File?, for details.
Can risk analysis be shortened for small-scale or simple products?
The depth of the analysis can be proportional to the product's complexity and risk level, but completely skipping a systematic risk analysis is not acceptable; a minimum level of hazard identification and assessment must be carried out for every product.
What should the risk analysis report contain?
The report should include a definition of the product's limits, a list of identified hazards, a risk estimate for each hazard, the mitigation measures applied, and an assessment of the residual risks. The methodology used and the reference standards should also be stated.
Why the Composition of the Risk Analysis Team Matters
The quality of a risk analysis depends heavily on the composition of the team carrying it out. A risk analysis carried out solely by the design engineer can lack practical knowledge of how the product is actually used in the field — which is why it is recommended to gather input from production, maintenance and, where relevant, field service teams wherever possible. Particularly when identifying "foreseeable misuse" scenarios, contributions from people who have observed the product in its real use environment can surface risks a desk-based assessment might overlook. For large-scale or high-risk products, an independent third-party peer review can also add an extra layer of assurance — helping offset the cognitive blind spot a team can develop toward its own design decisions (a tendency to struggle to question one's own design).
Conclusion
Risk analysis is the step where the CE process is not a standard formality but a genuine engineering activity that actively shapes the product's safety. The systematic approach defined by ISO 12100 — hazard identification, risk estimation, prioritized risk reduction and residual risk documentation — when correctly applied, both improves the product's safety and forms one of the most solid components of the technical file. Starting this process early and maintaining it iteratively throughout the design is the most efficient approach, both for safety and for cost.
If you're not sure your product's risk analysis is complete and audit-ready, let's review it together. See our CE consultancy service for more details.
Get a Free Pre-Assessment