Autonomous Mobile Robot Safety: ISO 3691-4 & ANSI R15.08
Understand how ISO 3691-4 and ANSI/A3 R15.08 divide autonomous mobile robot (AMR) safety responsibilities across design, integration, and day-to-day use.

Autonomous mobile robot (AMR) safety is not a product feature that can be checked once at purchase. It is a system and operating discipline: the robot, its payload, the facility, people, connected equipment, procedures, and every change made after go-live all affect risk. For industrial mobile robot (IMR) deployments, ISO 3691-4 and the ANSI/A3 R15.08 series provide useful ways to organize that work.
This guide explains what those standards cover, how responsibilities typically divide among the manufacturer, integrator, site owner, and daily users, and what evidence a buyer should request before approving an AMR deployment. It is educational guidance, not a substitute for a project-specific risk assessment, the applicable standard text, or competent safety and legal advice.
Start with the operating system, not the robot brochure
An AMR can be safe in a controlled demonstration and still be unsuitable for a specific operating environment. A deployment changes when routes cross pedestrian traffic, doors open slowly, loads extend beyond the chassis, charging is relocated, maps are updated, or the robot begins interacting with conveyors, elevators, workstations, or other fleet software.
That is why the useful question is not “Is this robot safe?” but “Has this application been assessed, integrated, validated, and operated with acceptable risk?” The answer requires evidence across four layers:
- Robot layer: the individual IMR, its intended use, protective functions, manuals, and declared limits.
- System and application layer: payloads, docks, charging, workstations, facility interfaces, routes, traffic, and the specific operating zone.
- Workplace layer: people, contractors, visitors, supervision, training, emergency arrangements, and maintenance access.
- Lifecycle layer: commissioning, acceptance testing, incidents, software and map changes, fleet expansion, and periodic review.
What ISO 3691-4:2023 covers
ISO 3691-4:2023 addresses safety requirements and verification for driverless industrial trucks and their systems. ISO’s published abstract explicitly includes automated guided vehicles, autonomous mobile robots, automated guided carts, and related driverless industrial truck concepts. It also emphasizes that the operating zone materially affects safe operation and includes preparations of that zone in Annex A. ISO 3691-4:2023
The standard is important because it frames the AMR as part of a system rather than an isolated device. It addresses significant hazards across the truck’s lifecycle when used as intended and under reasonably foreseeable misuse. It also has limits: ISO’s published scope excludes several situations or hazards, including public-road operation, potentially explosive environments, certain hygienic requirements, and particular hazardous loads. Check the full scope against the actual application rather than assuming the title alone settles applicability.
At publication, ISO lists ISO 3691-4:2023 as the current published edition and notes a draft revision is under development. Confirm the edition specified by contracts, customers, regulators, and the project safety team before relying on a particular clause or interpretation.
How ANSI/A3 R15.08 divides the AMR lifecycle
The ANSI/A3 R15.08 series organizes industrial mobile robot safety across the robot, the deployed system, and daily use. A3 describes the series as covering design, integration, and use of IMRs, IMR systems, and IMR applications, with risk assessment and management of change central to maintaining acceptable risk. A3 Industrial Robot Standards
Scroll horizontally to compare all columns.
| Standard | Practical focus | Typical accountable party |
|---|---|---|
| ANSI/A3 R15.08-1-2020 (R2026) | The individual industrial mobile robot and its safety requirements. | Robot manufacturer or supplier. |
| ANSI/A3 R15.08-2-2023 | IMR systems and applications: integrating, configuring, and customizing an IMR or fleet for a facility. | System integrator, application designer, and project owner. |
| ANSI/A3 R15.08-3-2026 | Day-to-day use of IMR applications and maintaining acceptable risk in the workplace. | Employer, site owner, supervisors, and users. |
A3 lists Part 1 as a 2026 reaffirmation of the 2020 text without technical differences, identifies Part 2 as the standard for IMR systems and applications, and describes Part 3 as addressing users’ day-to-day workplace responsibilities. A3’s current standards catalogue This division matters because a manufacturer’s documentation cannot validate a dock, conveyor handoff, or pedestrian route that did not exist in its original product assessment.
The responsibility map buyers should use
Assigning responsibility early prevents the common gap where every party assumes someone else owns the application risk. Contracts and local law determine final responsibility, but this working map helps procurement and project teams ask the right questions.
Scroll horizontally to compare all columns.
| Responsible Party | What to establish | Evidence to request |
|---|---|---|
| Manufacturer | Intended use, limitations, safety functions, residual risks, maintenance instructions, and declared requirements for the operating environment. | Safety manual, technical file or declaration where applicable, product risk documentation, performance limits, maintenance instructions, and change notices. |
| Integrator / application designer | How the robot, payload, charging, workstations, facility systems, routes, and safeguards operate together at this site. | Application risk assessment, route and zone design, interface specifications, validation plan, test results, and acceptance criteria. |
| Site owner / employer | Whether the workplace remains suitable as people, layouts, shifts, traffic, and processes change. | Operating procedures, training records, inspection routines, incident escalation, change-control process, and maintenance access plan. |
| Daily operator / supervisor | Safe use within approved conditions, prompt reporting of abnormal behavior, and no unauthorized route, payload, or process changes. | Clear SOPs, pre-use checks, escalation routes, refresher training, and traceable event reporting. |
Translate standards language into a deployment validation plan
A defensible AMR deployment turns each risk-control claim into a testable piece of evidence. Treat the following as a buyer’s evidence checklist, not as a substitute for a formal risk assessment.
- Define intended use and boundaries. Document operating hours, routes, floors, slopes, people, loads, doors, elevators, charging, environmental constraints, and prohibited uses.
- Assess the application, not just the chassis. Reassess when adding a cart, rack, lift, payload, manipulator, new software integration, or a different operating zone.
- Map interactions. Test crossing points, blind corners, manual-material movement, workstations, queues, loading and unloading, emergency access, and maintenance areas under realistic operating conditions.
- Validate safety-related behavior. Make acceptance tests explicit: detection behavior, stopping behavior, safe restart, emergency-stop response, manual and maintenance modes, docking, charging, and recovery from blocked routes.
- Control changes. A new map, speed setting, payload, floor layout, fleet size, or interface can alter risk. Define who approves changes, what evidence is required, and when revalidation is triggered.
- Operate and learn. Track interventions, blocked time, near misses, damage, unexpected routes, sensor contamination, bypass attempts, and service response. Use recurring review to decide whether controls remain effective.
Common blind spots in AMR safety projects
Most gaps appear at the boundaries between the robot and the site. Typical examples include:
- Payload and envelope changes: a safe base robot can create new pinch, stability, clearance, or visibility issues when it carries a rack, tote, cart, or long load.
- Shared-space behavior: pedestrian shortcuts, pallet-jack traffic, doorway queues, reflections, poor lighting, dust, and seasonal layout changes can change the operating zone.
- Facility interfaces: doors, elevators, conveyors, WMS tasks, access controls, and charging equipment need defined fault behavior, not only a successful demonstration.
- Maintenance and recovery: manual modes, stuck-robot recovery, battery service, sensor cleaning, and software updates need controlled procedures and authorized people.
- Management of change: expanding from one robot to a fleet, changing shifts, or moving to a new building is a new application decision, not merely a quantity change.
Where OSHA fits for U.S. workplaces
In the United States, OSHA states that there are currently no robotics-industry-specific OSHA standards. It instead points employers to applicable General Industry requirements and to national consensus standards as guidance. OSHA notes that consensus standards are not OSHA regulations, while requirements such as machine guarding, control of hazardous energy, electrical safety, walking-working surfaces, and state-plan rules may still apply to a specific workplace. OSHA robotics standards guidance
That distinction is important for procurement: an R15.08 or ISO reference should not be marketed as an automatic regulatory approval, and an OSHA-compliant workplace is not proven by a robot certificate alone. Engage qualified safety, engineering, and legal resources for the applicable jurisdiction and application.
Questions to ask before approving an AMR deployment
- Which edition of ISO 3691-4 and R15.08 is being used, and why is it applicable to this deployment?
- What is the defined intended use, and what conditions are expressly outside it?
- Who owns the application risk assessment, and who signs the validation evidence?
- How were routes, shared spaces, charging, payloads, interfaces, and abnormal recovery tested?
- What happens when a sensor is obstructed, a door fails, an elevator is unavailable, a route is blocked, or a worker enters an operating zone?
- Which changes trigger review or revalidation, and who is authorized to make them?
- What training, inspection, maintenance, incident reporting, and audit routines will continue after handover?
AMR safety standards: the practical takeaway
Use ISO 3691-4 and ANSI/A3 R15.08 as a way to organize evidence and accountability across the AMR lifecycle. A safe deployment is not established by a standards label on a specification sheet. It is established through an application-specific assessment, sound integration, documented validation, disciplined operations, and managed change.
Review deployment safety requirements. A structured application review can help align the robot supplier, integrator, facilities team, EHS stakeholders, and operating owner before go-live.
Continue planning: Apply these responsibilities to hospital AMR logistics solutions or industrial inspection robotics, verify site readiness with the robot deployment checklist, or request a workflow and safety assessment.
Common decision questions
Is an AMR automatically compliant if the manufacturer references ISO 3691-4?
No. The robot’s design evidence is only one input. The deployed system, operating zone, payload, interfaces, procedures, and site changes still require application-specific assessment and validation.
Are ISO 3691-4 and ANSI/A3 R15.08 the same standard?
No. They are different standards frameworks. Their applicability, edition, and contractual or jurisdictional role should be confirmed for the specific deployment. The practical overlap is that both reinforce risk-based thinking across more than the individual robot.
Does a facility need to reassess safety after changing an AMR route?
A route change can alter interactions with people, equipment, doors, sightlines, and emergency access. Define change-control and revalidation triggers before deployment, then have a competent project team assess the actual change.
Is this article a substitute for a safety assessment?
No. This article is a planning guide. Use the applicable standard text and qualified safety, engineering, and legal professionals for the deployment and jurisdiction involved.
Iven Wang
Iven Wang is the Co-Founder of Warpify Robotics, specializing in the commercialization and deployment of robotic solutions. With a background in electrical engineering and product management, he works with manufacturers, integrators, and enterprise clients across industrial inspection, security, logistics, and Robotics-as-a-Service.
Subscribe to our newsletter today
Get practical robotics deployment insights, case studies, and planning guidance from Warpify Robotics.




