Mobile manipulator
A collaborative arm on a mobile base that drives to a station, docks and works there, then moves on.
How the register reads it
| Also called | mobile cobot, arm on an AMR |
|---|---|
| Family | Mobile robots and vehicles |
| What a wrong action costs | person, batch. Contact with a person from the arm or the base, and mis-handled parts at a station. |
| Zone class and SL-T | line SL-T 3 by default (2 for the class, raised one because the class is reached remotely by default). It moves between cells, so it belongs with the fleet zone rather than any one cell. Never above 3; the paste may state its own zone name and SL-T. |
| Networked by default | Yes. Managed by a fleet manager over wireless. |
| Remote access by default | Yes. Supplier remote support is common; the paste decides. |
| Behaviour by default | adaptive. Navigates and re-plans at runtime. |
| Machinery Regulation | A machine or safety component: the declaration, the technical documentation and the instructions are demanded at purchase and held; a substantial modification makes the owner its manufacturer. |
| Vendor cloud | The fleet or the model is usually managed from a vendor cloud: ISO 27001 control 5.23 attaches where ISO 27001 is ticked, and the runtime attestation row asks what the vendor can send back. |
| Safety references |
|
What each regime attaches, and who it binds
73 clauses across 6 regimes, on the class defaultsShown on a register for the regimes you tick; with none ticked, the IEC 62443 asset-owner rows are the default. The CRA row is informational on every connected asset. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
IEC 62443
Binds Part 2-1 binds the asset owner; Part 3-2 is the owner's zoning and risk assessment; Part 3-3 is what the owner specifies for the system. Part 2-4 binds the service provider and Parts 4-1 and 4-2 the product supplier, so those rows are rendered as what to ask. Source framework: IEC 62443.
| Asset owner duty | On every asset (Part 2-1) IEC 62443 2-1 AC · 2-1 BCP · 2-1 CSMS · 2-1 IR · 2-1 MOC · 2-1 NSEG · 2-1 PHY · 2-1 PM · 2-1 RA · 2-1 TRN Whatever the zone, these ten programme duties are the owner's for every asset in the system under consideration. |
|---|---|
| Asset owner duty | System requirements to specify for a line zone (Part 3-3) IEC 62443 3-3 SR 1.1 · 3-3 SR 1.2 · 3-3 SR 2.1 · 3-3 SR 2.8 · 3-3 SR 3.1 · 3-3 SR 3.4 · 3-3 SR 5.1 · 3-3 SR 5.2 · 3-3 SR 6.1 · 3-3 SR 7.3 · 3-3 SR 7.6 A line zone shares a network among controllers, drives and stations, so device authentication, auditable events, communication integrity, a protected zone boundary, accessible logs and backup join the cell requirements. |
| Asset owner duty | Added where the asset is on a network IEC 62443 3-3 SR 3.1 · 3-3 SR 5.2 · 3-3 SR 6.2 Communication integrity, a monitored zone boundary and continuous monitoring attach the moment the asset is reachable. |
| Asset owner duty | Added where the asset is reached remotely IEC 62443 2-1 AC · 3-3 SR 1.1 · 3-3 SR 6.1 The remote account, its authentication and the record of its sessions are the owner's. |
| Asset owner duty | Added where the controller adapts at runtime IEC 62443 3-3 SR 2.8 · 3-3 SR 3.4 A controller that changes its own behaviour needs the integrity of its model or program watched and its actions logged, so a change can be told from an attack. |
| Ask the integrator | Part 2-4 binds the service provider, not the owner IEC 62443 2-4 SP-01 · 2-4 SP-02 · 2-4 SP-03 · 2-4 SP-04 · 2-4 SP-05 · 2-4 SP-06 The owner owes none of these rows; the owner asks the integrator and the maintenance provider for the evidence of each before commissioning and at every substantial change. |
| Ask the supplier | Part 4-1 binds the supplier, not the owner IEC 62443 4-1 DM · 4-1 SG · 4-1 SUM The owner asks the maker of the controller or the machine for the hardening guide, the vulnerability handling process and the signed update channel. |
| Ask the supplier | Part 4-2 binds the supplier: a networked component IEC 62443 4-2 CR-1-1 · 4-2 EDR-3-10 For a networked controller the owner also asks for signed firmware with rollback protection and user authentication on the component. |
NIST SP 800-82 Rev 3
Binds guidance addressed to the operator of the OT environment: it binds nobody in law and is what most OT security programmes are assessed against. Source framework: NIST SP 800-82 Rev 3.
| Asset owner duty | The OT overlay on every asset SP 800-82 GOV-3 · HOST-4 · HOST-6 · IR-1 · MON-2 SP 800-82 is guidance for the operator of the OT environment: an inventory that holds firmware and location, safety and security run together, change and patch management, and an incident plan with OT scenarios. |
|---|---|
| Asset owner duty | Network architecture where the asset is on a network SP 800-82 ARCH-1 · ARCH-2 · NET-1 Zones and conduits, an industrial DMZ between the plant and the office, and deny-by-default rules between zones. |
| Asset owner duty | Remote access where the asset is reached remotely SP 800-82 RA-1 · RA-2 A brokered, authenticated, recorded, time-bounded path; vendor accounts named individually and enabled just in time. |
| Asset owner duty | Field devices in a cell or line zone SP 800-82 IAM-4 · PHYS-1 Where a controller has little or no logical authentication, the key switch, the locked cabinet and the seal are the control. |
The EU AI Act
Binds Articles 26 and 4 bind the deployer, which is the asset owner using the system; Articles 12 to 15 bind the provider; a deployer that substantially modifies the system becomes its provider. Source framework: the EU AI Act.
| Asset owner duty | As the deployer of an adaptive controller AI Act Art. 4 · Art. 6 · Art. 26 An AI system used as a safety component of a machine, or that is itself the product, under the Union harmonisation legislation in Annex I (the Machinery Regulation is listed there) falls under Article 6(1). The deployer uses it per the instructions, assigns oversight to competent persons, monitors it, keeps its logs and makes its people literate in it. |
|---|---|
| Ask the provider | Articles 12 to 15 bind the provider, not the deployer AI Act Art. 12 · Art. 13 · Art. 14 · Art. 15 Human oversight by design, accuracy, robustness and cybersecurity, instructions for use that carry the oversight measures, and event logging are the provider's duties; the deployer asks for the evidence of each. |
| Asset owner duty | If the owner substantially modifies the system AI Act Art. 25 A deployer that substantially modifies a high-risk system, or changes its intended purpose so that it becomes high-risk, takes on the provider's obligations. |
The EU Machinery Regulation
Binds the manufacturer of the machine, and whoever substantially modifies it; the owner's row is what to demand at purchase and hold, and what it becomes liable for on a substantial modification. Source framework: the EU Machinery Regulation.
| Asset owner duty | What to demand at purchase and hold (the Regulation binds the manufacturer) Machinery Reg Art. 10 · Art. 20 · Art. 21, 22 · Art. 51, 52, 53, 54 The declaration of conformity, the technical documentation and the instructions are the manufacturer's to draw up. The owner's row is to demand them at purchase, to hold the declaration and the instructions for the life of the machine, and to know that the Regulation applies to machines placed on the market from its application date, with the Directive before it. |
|---|---|
| Asset owner duty | At every substantial modification Machinery Reg Art. 17, 18, 19 An owner that substantially modifies a machine becomes its manufacturer for the modification and takes on the Article 10 duties: the risk assessment, the technical file and the declaration are then the owner's to produce. |
| Ask the supplier | What the manufacturer shows (Articles 8 and 9 bind the manufacturer) Machinery Reg Art. 8, 9 · Art. 25 The essential health and safety requirements, including protection against corruption of the control system and the provisions for autonomous behaviour, and the conformity assessment route the machine went through. |
| Ask the supplier | Where a safety component learns (high-risk machinery) Machinery Reg Art. 6, 7 A safety component with self-evolving behaviour is in the high-risk list and needs third-party conformity assessment; the owner asks which body assessed it. |
The EU Cyber Resilience Act
Binds manufacturers, importers and distributors of products with digital elements; never the owner using them. Source framework: the EU Cyber Resilience Act.
| Ask the supplier | From the application date (the CRA binds manufacturers) CRA Art. 13 and Annex I · Art. 69, 70, 71 A connected controller or machine with digital elements is a product with digital elements; the manufacturer owes the essential cybersecurity requirements, a support period with security updates and vulnerability handling. The owner asks for the support period and the update channel. Informational: the owner owes no CRA clause. |
|---|
ISO/IEC 27001:2022
Binds the organisation that holds the certificate, through the Annex A controls it declared applicable. Source framework: ISO/IEC 27001:2022.
| Asset owner duty | Supplier and change controls on every asset ISO 27001 5.19 · 5.20 · 5.22 · 8.32 The integrator and the maintenance provider are suppliers; the change to a machine is a change. |
|---|---|
| Asset owner duty | Network controls where the asset is on a network ISO 27001 5.21 · 8.9 · 8.20 · 8.21 · 8.22 Network security, the services on it, segregation and a secure configuration baseline attach to any connected asset; the ICT supply chain control attaches to what the supplier delivers into it. |
| Asset owner duty | Where a fleet or model is managed from a vendor cloud ISO 27001 5.23 A fleet manager or a model service hosted by the vendor is a cloud service: acquisition, use and exit are governed. |
Runtime attestation: what to ask the supplier for
Signed firmware and updates with rollback protection, an attested boot or integrity check the controller reports, and behaviour logs that can be read off the device. The register asks; it does not say the supplier provides any of it. AI Act Art. 12 · Art. 15 CRA Art. 13 and Annex I IEC 62443 3-3 SR 3.3 · 3-3 SR 3.4 · 4-1 SUM · 4-2 EDR-3-10
Ask the integrator
- How the arm's collaborative limits and the base's detection field are validated together
- Which fleet manager commands it and what a remote session can do
- Who signs a map, program or tool change
Findings this class can raise
- Adaptive controller with no human oversight noted
The asset learns or re-plans at runtime and the paste names nobody who supervises it or can stop it. The AI Act asks the deployer to assign oversight to competent persons who can intervene and stop the system, and asks the provider to design for that oversight; the register records that the paste does not say who holds it. - Remote access into a cell or line zone
A machine in a cell or line zone that the paste says is reached remotely. A remote session into a controller is a conduit from outside the plant into the zone with the least defence; the asset owner controls the account, the broker and the session, and the integrator or supplier answers for what the session can do. - Flat network: networked assets with no zone named
Networked assets whose zone or network column is blank, spread across two or more zone classes. Either the zones exist and the register cannot see them, or they do not: the zone and conduit sheet is the first thing an assessor asks for, and it cannot be drawn from this paste. - A wrong action reaches a person, no safety function noted
A class whose wrong action reaches a person, on a line where the paste names no safety function, guard or scanner. The safety function may exist; the register records that the paste does not name it and lists the standards that govern the class so the integrator can be asked which ones the cell was built to. - No change record on an adaptive or networked asset
An adaptive or networked asset with no commissioning date and no last-change date. Management of change is the control every regime here shares; a register that cannot say when the asset last changed cannot say whether the last change was reviewed. - End of support or unpatched
The paste says the asset is out of support, unpatched or at end of life, or its commissioning year is older than the support threshold in the preamble. The asset owner's row is patch management with a recorded risk acceptance for what cannot be patched; the supplier's row is what to ask about updates and the support period. - Vendor share at or above a third
One vendor behind a third or more of the assets, or behind every asset in a zone class. Concentration is often the right engineering choice; the regimes ask that the dependence be recorded and the supplier relationship managed, not avoided. The register names the share and never rates the vendor. - Machinery declaration or technical file not held
A machine bought or modified after the preamble's threshold date for which the owner records no declaration of conformity or technical file. The declaration is the manufacturer's to draw up and the owner's to hold; a substantial modification makes the modifier the manufacturer, and the file is then the owner's to produce.
Do this for every asset on your floor
Paste the list and get this classification for every asset at once, with the zone and SL-T, the behaviour, the connectivity, the findings and the obligation rows per regime. Eight assets free, no account.
Build my cell register