ISO 3691-4 Safety Consulting & Engineering for AMR, AGV & Driverless Industrial Trucks

Autonomous Mobile Robots (AMRs), Automated Guided Vehicles (AGVs), automated guided carts and other driverless industrial trucks are becoming increasingly important in warehouses, factories, logistics operations and automated material-handling environments. 

As these systems move autonomously around people, equipment, racks, production lines and other mobile systems, safety must be engineered across the complete vehicle and operating environment. 

VerveTronics provides ISO 3691-4 consulting, AMR/AGV safety engineering, risk assessment, safety-function engineering, verification, validation and certification-readiness support for driverless industrial trucks and their systems. 

ISO 3691-4 specifies safety requirements and means of verification for driverless industrial trucks and their systems. The ISO scope includes examples such as automated guided vehicles, autonomous mobile robots, bots and automated guided carts. The standard also addresses systems comprising elements such as the control system, guidance means and power system, while defining specific exclusions and application boundaries. (ISO) 

Our engineering approach connects: 

Risk Assessment → Safety Requirements → Safety Functions → Safety Architecture → Hardware/Software Implementation → Verification → Validation → Assessment/Certification Support 

We support manufacturers, system integrators, warehouse automation companies and end users developing or deploying AMR/AGV systems that require structured safety engineering and evidence. 

Designing a safe AMR or AGV is more complex than adding a safety scanner or emergency-stop function. 

The complete system must consider vehicle movement, speed, steering, braking, load handling, navigation, person detection, protective fields, communication, operating zones, charging, manual modes, automatic modes and interactions with people and other equipment. 

Key challenges include: 

  • Determining the applicability and scope of ISO 3691-4 for the specific driverless industrial truck and application. 
  • Performing a systematic machine and system risk assessment. 
  • Identifying hazardous situations involving autonomous movement. 
  • Defining appropriate safety functions from identified risks. 
  • Determining required performance levels or safety integrity requirements for safety-related control functions. 
  • Designing safety-related control systems using appropriate ISO 13849 and/or IEC 62061 approaches. 
  • Designing reliable protective stop and emergency-stop functions. 
  • Implementing safe speed limitation and overspeed protection. 
  • Detecting people and obstacles using appropriate protective devices. 
  • Defining protective fields and detection zones. 
  • Managing stopping distance, braking performance and safety response time. 
  • Handling loss of communication between safety-related components. 
  • Managing safety-related navigation and motion-control interfaces. 
  • Addressing steering and stability-related hazards. 
  • Ensuring safe load handling and attachment functions. 
  • Managing automatic battery charging and associated safety functions. 
  • Addressing manual, automatic and maintenance operating modes. 
  • Ensuring appropriate safety behavior during faults. 
  • Establishing fault detection and diagnostic mechanisms. 
  • Managing interfaces between vehicle safety and facility/operating-zone safety. 
  • Demonstrating safety through verification and validation. 
  • Generating objective evidence for customer, regulatory, assessment or certification activities. 

The latest ISO work also indicates continuing development of ISO 3691-4. ISO/DIS 3691-4 is currently under development and is intended to replace ISO 3691-4:2023. Therefore, the applicable edition should be confirmed for each customer programme and target market. (ISO) 

VerveTronics combines Functional Safety engineering, robotics safety, embedded hardware, embedded software, safety analysis and verification expertise to support the development of safety-critical autonomous systems. 

Our approach focuses on translating standards into practical engineering work products rather than treating compliance as a documentation-only activity. 

AMR & AGV Safety Engineering Expertise 

We support safety engineering across:  AMR platforms,  AGV platforms,  Automated guided carts,  Driverless industrial trucks,  Autonomous material-handling vehicles,  Warehouse robots,  Factory logistics robots,  Mobile industrial robots,  Automated pallet transport systems,  Autonomous towing vehicles,  Industrial mobile platforms .

Functional Safety Engineering 

Our safety engineering activities can include:  Risk assessment, Safety requirements,  Safety functions,  Safety architecture,  Safety-related control systems,  PL/PLr engineering,  SIL engineering where IEC 62061 is applicable,  Safety mechanisms,  Diagnostic coverage,  Fault detection,  Fault reaction,  Verification and validation .

Cross-Domain Engineering 

VerveTronics can integrate:  System engineering,  Mechanical safety considerations,  Electrical safety,  Embedded hardware,  Embedded software,  Motor control,  Battery/BMS safety,  Functional Safety,  Cybersecurity considerations,  Safety verification,  Safety validation .

Safety Analysis 

We support structured safety analyses including: Risk assessment, FMEA , FTA,  DFA,  Hazard analysis,  Fault analysis,  Safety-function analysis,  Dependent-failure analysis,  Safety requirement analysis .

Engineering Evidence 

Our deliverables are structured around traceability: 

Hazard → Risk → Risk Reduction → Safety Function → Safety Requirement → Safety Architecture → Implementation → Verification → Validation 

ISO 3691-4 Applicability & Compliance Assessment 

We review the intended application, vehicle architecture and operating environment to determine the relevant ISO 3691-4 scope and associated standards. 

  • Activities include: Application review,  Vehicle classification,  Operating environment assessment,  Intended-use analysis,  Applicable-standard identification,  Gap assessment,  Compliance roadmap . 
  • ISO 3691-4:2023 applies to driverless industrial trucks and their systems, including examples such as AGVs and AMRs, while also defining important exclusions. (ISO) 

AMR / AGV Risk Assessment 

We perform structured risk assessments covering the complete vehicle and operating environment. 

  • Typical areas include: Vehicle movement,  Starting and stopping,  Speed,  Steering,  Braking,  Stability,  Load handling,  Person detection,  Collision hazards,  Charging,  Communication,  Maintenance,  Manual operation,  Automatic operation,  Environmental hazards,  Operating-zone hazards .
  • The assessment can be aligned with ISO 12100 and the applicable requirements of ISO 3691-4. 

Safety Function Engineering 

We translate identified risks into clearly defined safety functions. 

  • Examples may include: Emergency stop,  Protective stop,  Safe stop,  Safe speed limitation,  Overspeed protection,  Safe direction control,  Person detection,  Protective field monitoring,  Safe steering,  Safe braking,  Load-related safety functions,  Safe restart,  Safe manual mode,  Safe maintenance mode,  Loss-of-communication response,  Charging safety,  Safety-related fault reaction .

Each safety function can be documented with: 

  • Trigger → Safety Requirement → Reaction → Fault Response → Diagnostic Mechanism → Verification Method 

ISO 13849 Functional Safety Engineering 

Where ISO 13849 is applicable to the safety-related control system, VerveTronics supports: 

  • Safety-function definition,  Required Performance Level (PLr),  Safety architecture,  Category selection,  MTTFd, DCavg,  Common Cause Failure considerations,  Diagnostic mechanisms,  Safety-related hardware,  Safety PLC/controller architecture,  Verification,  Validation,  SISTEMA-related engineering support .
  • The relationship between ISO 3691-4 requirements and the applicable safety-related control-system standard should be evaluated for the specific safety function rather than assuming one generic PL or SIL value for the entire vehicle. 

 

IEC 62061 / SIL Engineering 

Where IEC 62061 is selected as the applicable machinery functional-safety framework, we support: 

  • Safety-function specification , SIL target determination,  Safety architecture,  Hardware safety engineering,  Diagnostic measures,  Systematic capability considerations,  Probability-of-dangerous-failure analysis,  Safety-related software,   Verification and validation .
  • PL and SIL should not be treated as interchangeable terms. The applicable framework and target should be established from the specific safety function and risk assessment. 

 

Safety Architecture for AMR / AGV 

  • We develop safety architectures covering: Safety controller , Safety PLC,  Safety scanners,  Safety sensors , Encoders,  Motor controllers , Drive interfaces,  Brake control,  Steering control,  Emergency-stop circuits,  Protective-stop circuits,  Communication interfaces,  Safety I/O,  Battery/BMS interfaces,  Charging interfaces .
  • Architecture reviews can include single-point failures, diagnostic coverage, independence, fault propagation and dependent failures. 

 

Person Detection & Protective Field Safety 

Autonomous vehicles operating around people require carefully engineered detection and protective measures. 

  • We support engineering of: Safety laser scanners,  Safety-rated sensing,  Protective fields,  Warning fields,  Speed-dependent protective zones,  Detection zones,  Side protection,  Rear protection,  Corner protection, Critical-edge detection,  Protective stop behavior,  Restart behavior .
  • The current ISO/DIS 3691-4 development materials specifically include areas such as safeguarding, safety functions, loss of communication and additional detection-related safety functions. (ISO) 

 

Safe Motion & Vehicle Control 

  • We support safety engineering for: Speed monitoring,  Overspeed detection,  Safe stopping,  Braking performance,  Direction monitoring,  Steering safety,  Motion control,  Position-related safety,  Encoder monitoring,  Motor-control interfaces,  Safe torque or drive-related functions where applicable .
  • The objective is to ensure that safety-related motion functions achieve the required risk reduction under normal operation and reasonably foreseeable faults. 

 

Battery, Charging & Power Safety 

  • For battery-powered AMR/AGV systems, safety engineering may include: Battery/BMS safety interfaces,  Overcurrent protection,  Overvoltage protection,  Undervoltage protection,  Thermal protection,  Charging safety,  Automatic charging safety,  Charger communication,  Safe shutdown , Battery fault response,  Power-loss behavior,  Emergency power considerations .
  • The specific battery and charging requirements should be determined from the vehicle architecture and applicable standards. 

 

Safety-Related Embedded Software 

  • We support embedded software safety activities including:  Safety requirements , Software architecture,  Safety mechanisms,  Fault handling,  Diagnostic software,  Safety state management , Watchdog strategies,  Communication monitoring,  Software unit verification,  Integration testing , Fault injection ,Traceability,  Configuration management . 
  • Where applicable, software engineering can be aligned with ISO 13849, IEC 62061 and/or IEC 61508 principles. 

 

Hardware Safety Engineering 

  • Hardware services can include:  Safety controller architecture,  Safety I/O,  Sensor interfaces,  Motor-control interfaces,  Power protection,  Redundancy,  Monitoring circuits,  Diagnostic circuits,  Hardware safety requirements,  FMEA,  FMEDA where applicable,  Fault injection,  Hardware verification .

 

FMEA, FTA & Safety Analysis 

We provide standalone or integrated safety-analysis services including: 

  • FMEA : System FMEA, Hardware FMEA,  Software FMEA,  Interface FMEA,  Functional FMEA .
  • FTA : Top-event definition,  Fault propagation,  Single-point failures,  Multiple-point failures, Common-cause failures, Quantitative analysis where appropriate .
  • DFA : Dependent failure identification,  Common-cause analysis,  Cascading failures,  Independence analysis .

 

Verification & Validation 

  • We support safety verification and validation through: Safety requirement verification, Hardware verification,  Software verification,  System integration testing,  Safety-function testing,  Fault injection,  Sensor fault testing,  Communication fault testing,  Stop-distance testing,  Overspeed testing,  Protective-stop testing,  Emergency-stop testing,  HIL testing,  Regression testing,  Safety validation,  Test evidence and traceability . 

The objective is to demonstrate that each safety function performs as specified and provides the intended risk reduction. 

 

Operating Zone & Application Safety 

AMR/AGV safety does not depend solely on the vehicle. 

  • We also consider: Operating zones , Pedestrian areas , Intersections,  Doors,  Racks,  Loading/unloading areas,  Charging stations , Restricted zones,  Narrow aisles,  Shared human/robot areas,  Floor conditions,  Traffic management,  Facility interfaces .
  • ISO 3691-4 specifically recognizes the importance of the operating zone and includes requirements related to preparation of the operating environment. (ISO) 

 

ISO 3691-4 Gap Assessment 

  • For existing AMR/AGV platforms, we provide: Standard-to-design gap analysis , Requirement mapping,  Safety-function gap analysis,  Architecture review,  Risk-assessment review , Verification-evidence review , Documentation review , Compliance matrix , Remediation roadmap,  

 

Assessment & Certification Support 

VerveTronics can support preparation for customer assessments, third-party assessments and applicable conformity-assessment activities. 

  • Support can include: Compliance matrix , Technical-file review,  Safety documentation,  Safety requirements , Risk assessment,  Safety-function documentation,  Test plans,  Test reports,  Traceability,  Evidence review,  Audit preparation,  Corrective-action support,  Assessment readiness .
  • Formal certification or conformity assessment is performed by the applicable recognized/accredited organization where required.