Finding the hazards before designing the fix
It's tempting to jump straight to adding safety features: more sensors, more redundancy, more emergency stops. But functional safety as a discipline insists on doing something less glamorous first, which is systematically identifying every way the system could cause harm. This means walking through the robot's full range of operation, including maintenance, unusual configurations, and foreseeable misuse, and cataloguing each hazard: a pinch point during arm motion, a collision with a person who steps into a mobile robot's path, a dropped payload, an electrical fault that energizes something it shouldn't. The goal is completeness, not depth, at this stage. A hazard that never gets identified never gets addressed, no matter how good the eventual safety measure is.
Once hazards are identified, each one is assessed along two independent dimensions: how severe the resulting harm would be if it occurred, and how likely that hazard is to actually occur given normal exposure to the robot. A hazard that could cause a fatal crush injury is treated very differently from one that could cause a minor bruise, even if both stem from a robot arm moving unexpectedly. Likelihood matters too: a hazard that requires an extremely unusual sequence of events to occur is weighted differently than one that happens under completely normal, everyday operation.
