
AGV and AMR risk assessment guide covering traffic, stopping, loads, blind intersections, localization loss, docking, charging and ISO 3691-4:2023.
Introduction
An AMR can meet its product safety requirements and still be deployed into an unsafe warehouse. The operating zone changes the risk: blind intersections, protruding loads, pedestrian shortcuts, damaged floors, rack overhang, fire doors, charging areas and manual recovery all create hazards outside a clean manufacturer demo.
ISO 3691-4:2023 covers safety requirements and verification for driverless industrial trucks, explicitly including AGVs and AMRs. The useful way to apply that framework is to map hazards across the entire lifecycle: installation, automatic travel, docking, loading, charging, fault recovery, maintenance and layout changes.
Key findings
- ISO 3691-4:2023 applies to driverless industrial trucks including AGVs and AMRs and explicitly notes that operating-zone condition can significantly affect safe operation.
- Risk assessment must cover the robot, load and environment as one system; a low-profile AMR carrying an overhanging pallet presents a different collision geometry from the empty base.
- Stopping performance changes with speed, payload, floor friction, slope and sensor field configuration, so generic stopping-distance assumptions are unsafe.
- Localization loss, blocked sensors, communications failures and manual recovery need defined safe states rather than ad-hoc operator behavior.
- Every material layout or workflow change should trigger a review of routes, crossings, safety fields, restricted zones and acceptance tests.
AGV/AMR risk assessment starter register
| Hazard | Trigger | Control questions |
|---|---|---|
| Pedestrian collision | Blind corner, high speed, distraction | Speed zones, visibility, protective fields, right of way |
| Load collision/drop | Overhang, misalignment, high center of gravity | Load detection, speed, containment, swept envelope |
| Localization loss | Map change, occlusion, feature-poor zone | Confidence monitor, safe stop, recovery |
| Docking pinch/crush | Machine/conveyor handoff | Interlocks, presence sensing, access control |
| Disabled robot recovery | Fault, battery, comms | Motor-safe state, tow/manual process, restart control |
Start with zones and interactions, not a generic checklist
Draw the actual map: pedestrian aisles, forklift lanes, blind intersections, doors, elevators, ramps, docks, charging stations, machine interfaces and emergency exits. Then overlay AMR routes and the full swept volume of the robot plus load.
Risk often appears where systems meet. A protected straight aisle can feed into an uncontrolled crosswalk. A robot can safely stop while its elevated pallet continues to block a human sightline. Evaluate interactions, not just components.
Stopping distance is a system property
The protective field must give the vehicle enough distance to detect a hazard and reach the required safe state. Speed, payload, braking behavior, floor friction, slope, controller response and sensor latency all contribute.
Do not copy a stopping distance from an unloaded factory acceptance test into a loaded warehouse route. Validate worst credible conditions and keep the test evidence tied to the deployed speed zones.
Payload geometry changes the collision envelope
An under-cart AMR, autonomous tugger and pallet transporter have different hazards. Loads can overhang the base, raise the center of mass, obstruct sensors or create crushing points against racks and workstations. Forks add a particularly dangerous protrusion.
Include dropped-load, shifted-load and wrong-load cases. If the robot cannot detect that the pallet is misaligned, the safety assessment must not assume perfect loading.
Blind intersections and mixed traffic
At blind corners, the AMR may detect a pedestrian later than it can on an open aisle, while a person may hear or see the robot late. Consider reduced speed zones, one-way traffic, physical sightline changes, warning systems or intersection control.
Mixed forklift traffic needs special attention because a human-driven truck has different braking, visibility and right-of-way behavior. Route separation may be more reliable than expecting every agent to negotiate dynamically.
Localization and perception faults need a safe degraded mode
What happens when localization confidence collapses, a scanner window is blocked, a camera is blinded or a map no longer matches the building? The safe answer is application-specific, but it should be deterministic: reduce speed, stop, request assistance or enter a defined recovery state.
A vehicle that continues driving on a stale or uncertain pose can turn a software quality issue into a physical hazard. Monitor sensor health and localization status explicitly.
Docking, conveyors and machine interfaces create pinch points
Docking brings the robot close to fixed equipment and often transfers loads. People may reach into the same space to clear a jam. Define interlocks, access rules and safe states for incomplete handshakes.
If a conveyor says “ready” but a package protrudes, or an AMR arrives off-center, the system should detect the mismatch rather than forcing the transfer. Interface faults deserve their own test cases.
Charging, batteries and parked robots
Charging areas concentrate electrical equipment and can create blocked aisles or trip hazards. Design emergency access and keep charging stations out of evacuation routes. Battery procedures should follow the manufacturer and applicable fire/electrical requirements.
A disabled robot can also become an obstacle. Define how it is made safe, moved and recovered without exposing staff to unexpected motor restart or heavy manual handling.
Revalidate after change
Treat these as configuration changes to a safety-related system, not normal warehouse housekeeping.
- New rack, machine, door or pedestrian route near an AMR path.
- New payload shape, weight or carrier.
- Changed maximum speed or safety field.
- Software/navigation update that changes behavior.
- New floor surface, ramp or damaged area.
- Fleet expansion that changes intersection congestion.
- New charging or maintenance procedure.
Limitations and missing information
- Product specifications, software capabilities, prices and availability can change; verify the exact configuration before procurement.
- A successful vendor demonstration does not establish production uptime, intervention rate or performance in a different facility.
- Safety guidance here is educational and does not replace a site-specific risk assessment, integrator validation or applicable regulations.
Conclusion
AGV and AMR safety is not achieved once at commissioning. The operating zone evolves, so a defensible risk assessment has to follow the robot, load, traffic pattern and software configuration through their lifecycle.
Frequently asked questions
Which safety standard applies to AGVs and AMRs?
ISO 3691-4:2023 specifies safety requirements and verification for driverless industrial trucks and explicitly includes automated guided vehicles and autonomous mobile robots. Regional standards and laws may add requirements.
What should an AMR risk assessment include?
Include traffic zones, stopping behavior, payload geometry, crossings, docking, charging, localization/sensor faults, communications, manual recovery, maintenance and the effect of facility changes.
Does an ISO-compliant AMR make the warehouse safe automatically?
No. The complete application and operating zone must be assessed. Layout, people, other vehicles, loads and integration can create hazards that are not properties of the robot alone.
When should an AMR risk assessment be updated?
Reassess after meaningful changes such as new routes, racks, payloads, speeds, safety fields, software behavior, floor conditions or fleet size.
Why does payload matter to AMR safety?
Payload changes mass, stopping performance, center of gravity, visibility, sensor occlusion and the physical collision envelope.
Sources and methodology
TechniaHQRobot reviewed current search-result coverage on August 12, 2026 to identify the questions competing pages answer and the gaps they leave.
Technical claims were then checked against current standards, manufacturer documentation, official project pages and primary sources. Marketing claims are identified as vendor claims rather than treated as independent performance evidence.
Related TechniaHQRobot guides
Structured data implementation
- BlogPosting schema with self-referencing canonical URL, publication and modification dates, author, publisher and keywords.
- BreadcrumbList matching the visible /articles/ page hierarchy.
- FAQPage generated only from questions and answers visible on the page.
Share this article
Share the current TechniaHQRobot article page.
Continue reading
Open the latest robotics reporting, Physical AI analysis and hardware notes.