CECheck The reference for CE marking

Risk assessment for CE marking

Last reviewed: August 2026 · Legal status verified against EUR-Lex.

Risk assessment is the analytical core of every CE conformity assessment. Testing, harmonised standards, and the EU Declaration of Conformity all sit downstream of it: without a documented assessment of the risks the product presents, there is no defensible basis for claiming that the essential requirements of the applicable legislation are met. A technical file that consists only of test reports, with no analysis connecting the product's hazards to the measures taken against them, is a recurring reason why files fail scrutiny by Notified Bodies and market surveillance authorities.

Where the requirement comes from

The obligation is horizontal, not sector-specific. The conformity assessment modules in Annex II of Decision No 768/2008/EC — the reference provisions copied into the sectoral acts — state that the technical documentation "shall, wherever applicable, contain … an adequate analysis and assessment of the risk(s)". That wording appears in Module A (internal production control) and recurs across the other modules, and the sectoral directives and regulations reproduce it in their own technical-documentation annexes. The Low Voltage Directive 2014/35/EU, the EMC Directive 2014/30/EU, the Radio Equipment Directive 2014/53/EU, and the other New Legislative Framework acts all carry it.

Some acts go further and make risk assessment an explicit design obligation rather than only a documentation item:

The general method

No horizontal act prescribes a single mandatory methodology. In practice, the structure set out in EN ISO 12100 for machinery has become the reference model across sectors, and the Blue Guide describes the same logic in general terms. The sequence is iterative — each pass through risk reduction is followed by a re-assessment until the remaining risk is acceptable.

1. Determine the limits of the product

The assessment starts by fixing what is being assessed: the product's intended use, its user population (trained professionals, consumers, children), its operating environment, and its lifecycle phases (transport, installation, operation, cleaning, maintenance, disposal). Crucially, EU legislation requires the assessment to cover not only intended use but reasonably foreseeable misuse — use of the product in a way not intended by the manufacturer but which may result from readily predictable human behaviour. A ladder used on uneven ground, a chainsaw guard removed for a cut the guard obstructs, a toy component mouthed by a child: these are within scope of the assessment even though the instructions prohibit them.

2. Identify the hazards

Every hazard associated with the product over its lifecycle is listed systematically: mechanical (crushing, shearing, cutting, entanglement, ejection of parts), electrical, thermal, noise, vibration, radiation, materials and substances emitted or contacted, ergonomic hazards, hazards from the environment of use, and hazards arising from failures — loss of stability, software faults, breakdown of controls. Sectoral annexes (Annex III of the Machinery Regulation, Annex I of the LVD, Annex II of the Toy Safety Regulation) function as structured hazard checklists: each essential requirement corresponds to a hazard family the legislator expects to be considered.

3. Estimate the risk

For each identified hazard, the risk is estimated as a combination of the severity of the possible harm and the probability of its occurrence — the latter usually decomposed into exposure of persons to the hazard, the likelihood of the hazardous event, and the possibility of avoiding or limiting the harm. Qualitative scales (a risk matrix of severity against probability) are the norm; nothing in EU law requires quantitative estimation, but the scale used must be defined and applied consistently.

4. Evaluate the risk

Risk evaluation is the judgement of whether the estimated risk is acceptable or whether reduction is required. For hazards covered by a harmonised standard, the standard itself embodies the legislator-endorsed level of acceptable risk; meeting the standard's requirements closes the loop for those hazards. For hazards not covered by any standard, the manufacturer must document its own acceptance criteria and reasoning.

5. Reduce the risk — in the mandatory order

Where risk reduction is required, EU product legislation imposes a hierarchy, stated expressly in the Machinery Regulation's general principles and mirrored across other acts:

  1. Inherently safe design. Eliminate the hazard or reduce the risk by design choices — lower voltages, rounded edges, reduced forces, non-toxic materials, elimination of trap points.
  2. Safeguarding and protective measures. Where design cannot eliminate the risk: guards, interlocks, enclosures, protective devices, pressure relief.
  3. Information for use. Only for residual risks that the first two levels cannot remove: warnings on the product, instructions, prescribed training or personal protective equipment.
Warnings are the last resort, not the first. A file that treats a warning label as the primary control for a designable-out hazard inverts the hierarchy, and both Notified Bodies and surveillance authorities read it that way. Residual-risk warnings are legitimate only after the assessment shows that design and safeguarding options were considered first.

The machinery model: EN ISO 12100

For machinery, the method above is codified in EN ISO 12100:2010 (Safety of machinery — General principles for design — Risk assessment and risk reduction), the type-A standard that has long been harmonised under the Machinery Directive and remains the methodological reference as manufacturers transition to the Machinery Regulation 2023/1230, which applies from 20 January 2027. EN ISO 12100 defines the iterative loop — determination of limits, hazard identification, risk estimation, risk evaluation, and the three-step risk reduction method — and its Annex B provides an extensive hazard taxonomy widely reused as a checklist even outside the machinery sector. Type-B standards (covering one safety aspect, such as safety distances in EN ISO 13857) and type-C standards (covering one machine category) slot into the same framework: a type-C standard, where one exists and is applied in full, represents a completed risk assessment for the hazards it covers.

Documenting the assessment

Assessors and market surveillance officers do not expect a particular template, but they consistently expect the document to show its working. A defensible risk assessment record contains:

Under the module texts, the technical documentation — the risk assessment included — must be kept for ten years after the product is placed on the market (longer under some acts) and produced to authorities on reasoned request. An assessment that exists only as engineering folklore, or that was written after the design was frozen to justify decisions already made, tends to be visible as such.

Relationship to harmonised standards

Applying harmonised standards does not replace the risk assessment; it discharges part of it. A standard captures the known hazards of a product family and the state-of-the-art measures against them, and confers the presumption of conformity for the requirements it covers. The manufacturer's assessment still has to do three things the standard cannot: confirm that the standard actually covers the product and its foreseeable misuse; cover the hazards the standard does not address — novel features, unusual environments, combinations of functions, product-specific risks; and evaluate residual risks that remain after the standard is applied. The Blue Guide is explicit that the presumption of conformity extends only to the requirements a standard's Annex ZA/ZZ mapping says it covers. "We applied EN X, therefore no risk assessment was needed" is a non sequitur that surveillance authorities are well practised at spotting.

Sector flavours

Medical devices: ISO 14971

The MDR and IVDR demand the most formalised version: a risk management system per EN ISO 14971 (currently ISO 14971:2019, harmonised in its EN version with amendment A11:2021), running from design input through production and post-market surveillance. Distinctive features include benefit-risk determination — risks are acceptable only when outweighed by clinical benefit — and the obligation to feed post-market data back into the risk management file for the life of the device.

Toys

The Toy Safety Regulation requires a pre-market safety assessment spanning chemical, physical, mechanical, electrical, flammability, hygiene, and radioactivity hazards, with particular weight on the behaviour of children — mouthing, small parts, and access by children younger than the age grading. The EN 71 series and EN IEC 62115 supply presumptions of conformity for known hazards, but the safety assessment must address the individual toy.

Electrical equipment

Under the LVD, Annex III requires the technical documentation to contain the adequate analysis and assessment of risks even though Module A involves no Notified Body — the assessment is the manufacturer's own burden of proof. Modern product standards in this space, notably EN IEC 62368-1 for audio/video and ICT equipment, are themselves built on hazard-based safety engineering, which aligns the standard's structure with the assessment the directive expects.

Common weaknesses

Sources