Practical Guide: Manufacturing and Supply Chain
Where a wrong output becomes a physical action near a person, or a defect that has already left the site by the time anyone notices.
- Typical top tier
- Tier 4 — machine control, collaborative robotics, batch or release decisions
- Already-owned ground
- Machinery safety, quality management, traceability and recall
- Hardest gate
- G2 — the safety and quality architecture decision, taken once and lived with
- First record to fix
- Which systems can influence a machine action, and through what path
1. Where the risk actually concentrates
Manufacturing has the clearest version of the framework's reversibility problem. A defect detected on the line is a cost. The same defect detected after shipping is a recall, a liability claim and possibly a safety event, and no amount of system correction undoes it. The dimension that matters most here is D3, and it is the one most often scored on how easily the software can be rolled back.
The second characteristic is proximity to people. Vision-guided robotics, collaborative cells and autonomous material handling put model outputs within reach of workers. Safety practice in this sector is mature and its answer is the same as in utilities: safety functions stay deterministic and independent. AI can see, predict, schedule and propose; the safety-rated stop does not depend on it.
The third is that the supply chain is a governance surface of its own. Allocation, supplier selection and demand forecasting decisions are low-drama individually and reshape who gets supplied, at what price, in aggregate. They are also the systems most likely to be procured as a module of a planning platform and never classified at all.
Indicative classification of the systems this sector keeps building. The scores are illustrative, not authoritative: they show how the anchors in Chapter 6 read against sector facts. Score your own system; do not copy a row.
| Typical system | Illustrative D1–D5 | Tier | What is usually mis-scored |
|---|---|---|---|
| Machine or process control set-point adjustment | D1 4 · D2 3–4 · D3 4 · D4 3 · D5 2 | Tier 4 | Scored as engineering optimization rather than as an action on plant |
| Collaborative robot or autonomous vehicle perception | D1 4 · D2 4 · D3 4 · D4 3 · D5 2 | Tier 4 | The safety case is assumed to cover the model; usually it covers the stop function only |
| Visual quality inspection with automatic reject or accept | D1 4 · D2 3–4 · D3 4 · D4 4 · D5 2 | Tier 4 where accept is automated | False accept is the dangerous direction and the metric usually reported is overall accuracy |
| Batch release or disposition support | D1 4 · D2 2 · D3 4 · D4 4 · D5 3 | Tier 4 | Advisory scoring for a decision the release authority signs on the model's evidence |
| Predictive maintenance and intervention scheduling | D1 3 · D2 2–3 · D3 3 · D4 3 · D5 2 | Tier 3 | Deferring maintenance is an action with a consequence, not an absence of action |
| Production scheduling and line balancing | D1 2–3 · D2 3 · D3 2 · D4 3 · D5 2 | Tier 2–3 | Fine, until the schedule drives shift assignment and worker pace |
| Demand forecasting and allocation between customers | D1 3 · D2 2–3 · D3 3 · D4 4 · D5 2 | Tier 3 | Allocation decides who is short; scored as a planning aid |
| Supplier risk and qualification scoring | D1 3 · D2 2 · D3 3 · D4 3 · D5 3 | Tier 2–3 | A de-qualification is close to irreversible for a small supplier |
| Maintenance and operating procedure generation | D1 4 · D2 1–2 · D3 3 · D4 3 · D5 2 | Tier 3 | A generated work instruction is followed by a person near a machine |
2. The regulatory interface
Regulatory note. The regimes below are named so each IRGF record can be pointed at the obligation it evidences, not to restate them. Applicability, thresholds and commencement dates differ by jurisdiction and several have moved during implementation. Nothing here is legal advice: confirm the current position with your own counsel, and record the answer in the Regulatory Overlay Reference so it is checkable later.
IRGF does not restate any of these obligations. It gives each one a record that carries the evidence, an owner, and a trigger that reopens it when the obligation or the system changes.
| Regime or standard | What it obliges in practice | IRGF record that carries the evidence |
|---|---|---|
| Machinery and robot safety standards (for example ISO 12100, ISO 10218, ISO/TS 15066, IEC 62061, IEC 61508) | Risk assessment, performance level or safety integrity level for safety functions, and validation of protective measures. | The pattern constraint that safety functions remain independent of the model, recorded at G2 and checked as pattern conformance |
| Product safety and liability regimes, including software and AI within product liability rules | Defect liability, duty to monitor products after placing on the market, and corrective action duties. | Post-market monitoring registered as a runtime signal; recall path referenced from the Control Matrix |
| Quality management systems (ISO 9001 and sector equivalents such as IATF 16949) | Process control, traceability, non-conformance handling, and change control. | Existing non-conformance and change records referenced; IRGF adds classification and the runtime comparison |
| Industrial security standards (IEC 62443) and network and information security law | Zoning, secure remote access, patching, and incident reporting for operational technology. | Zone placement in the ADR; supplier remote-access rights recorded as a control |
| EU AI Act, where it applies | AI used as a safety component of machinery follows the product-legislation route rather than the standalone high-risk route, aligning conformity assessment with existing machinery rules. | Regulatory Overlay Reference, with the conformity route stated per product |
| Traceability, export control and supply chain due diligence obligations | Lot traceability, restricted-party screening, and human rights or environmental due diligence reporting where applicable. | Data lineage for the records that support the claim; generated claims treated as assured outputs |
3. Calibrating the five dimensions
The dimensions do not change. What changes is what a 3 and a 4 look like when the subject matter is this sector, and which reading an assessor under delivery pressure reaches for first.
| Dimension | How to read it here | The mis-score to watch for |
|---|---|---|
| D1 Decision Consequence | Anything that can move a machine, release product, or produce an instruction a worker follows is 4. Scheduling and planning are 2 to 3 unless they set worker pace or customer allocation. | Scoring downtime cost. The subject of D1 is harm, and here harm includes the worker and the customer who receives the defect. |
| D2 Autonomy | Automatic accept is autonomy even when automatic reject is reviewed. Score the path with the least human involvement, in the direction that causes harm. | Averaging across directions: a system where rejects are reviewed and accepts are not is D2 = 4 for the consequence that matters. |
| D3 Reversibility Deficit | Product that has shipped, material consumed, a physical action taken, and a supplier de-qualified are all 4. Very little on a production line is reversible after the fact. | Reading reversibility from the software: the model can be rolled back, the batch cannot. |
| D4 Exposure and Scale | Batch size is the multiplier. A quality model failing silently for one shift can reach every unit made that shift, all of which are already in transit. | Counting sites rather than units. A single-line system with a large run has enterprise-scale exposure. |
| D5 Sensitivity and Uncertainty | Sensor and image data is low sensitivity; uncertainty is often high, especially for models trained on one line and deployed on another. Take the higher. | Scoring D5 = 1 because there is no personal data, and discarding the uncertainty half. |
4. One system, end to end
The overlay above is a map. This is one route across it: a single part followed from the camera to the warranty claim, with the record or control that attaches at each step.
5. What each gate adds
Additions only. Everything in the base gate definitions still applies; see the gate checklists for the common set.
| Gate | Sector addition | Why it is here |
|---|---|---|
| G1 | State whether any output can influence a machine action or a release decision, and whether workers will follow generated instructions. | It determines whether machinery safety governance owns the work, and whether the tier floor applies. |
| G2 | Safety independence evidenced: the protective function does not depend on the model. Line and site transferability assessed for any model trained elsewhere. | A model validated on one line is a hypothesis on the next one; this is the sector's version of population shift. |
| G3 | Pass criteria stated separately for false accept and false reject. Operator procedure updated. Stop conditions defined for anything acting. | One accuracy number hides the direction that causes recalls. |
| G4 | Retraining on new line data, new product variants, and camera or fixture changes are all Material. Physical changes to the cell count as system changes. | The physical environment is part of the system, and it is changed by people who do not file software changes. |
| G5 | Retention aligned to product liability and traceability windows, which typically outlive the production system. | Recall investigations ask what the inspection system saw, years later. |
6. Controls and evidence worth adding
| Control | Where it attaches | Evidence it produces |
|---|---|---|
| Independent safety function, evidenced at G2 and re-checked at each G4 | Pattern conformance; safety case | Statement and test evidence that the protective function operates with the model offline |
| Directional pass criteria for inspection systems | Assurance Summary | False accept and false reject rates against separate, pre-agreed thresholds |
| Line and variant transferability assessment | ADR; assurance cycle | Performance on the target line before deployment, not after |
| Escape detection loop from downstream and warranty data | Runtime signal | Measured escape rate attributable to inspection decisions |
| Generated work instruction review and approval by a competent person | Control Matrix | Named approver per instruction version, with the source model recorded |
| Physical change trigger: fixture, lighting, camera or product change opens a change record | Change process | Change records that reference physical modifications, not only software releases |
7. Runtime signals to wire first
Control Plane onboarding order matters more than coverage in the first year (Chapter 18). These are the signals that earn their place earliest in this sector.
| Signal | Drift category | Suggested response |
|---|---|---|
| False accept rate rises while overall accuracy holds | Behavioral | Treat as a quality escape event; overall accuracy is not the control |
| Camera, lighting, fixture or product variant changes | Configuration, physical | Open a change record and re-run the directional evaluation before the next shift |
| A model gains a write path to a controller it did not have | Integration and dependency | Immediate: verify against the approved zone architecture and treat divergence as a security incident |
| Warranty or downstream defect data diverges from inspection results | Behavioral, detected outside the system | Feed warranty data into the assurance cycle as an input; it is the only honest measure of escapes |
| Supplier pushes a firmware or model update to an inspection or robotics stack | AI-model behavioral | Material change at Tier 3–4; require the change note and re-run the acceptance test |
8. Failure modes this sector produces
Accuracy that hides the dangerous direction
The tell. The inspection model reports 99.4% accuracy and the escape rate has doubled, because the errors moved from reject to accept.
The response. Set and monitor directional thresholds from the start. Report false accept separately at every review, and never let a single accuracy figure stand as the pass criterion.
The safety case that covers the wrong thing
The tell. A cell's safety case validates the light curtain and the emergency stop, and says nothing about the vision model that decides where the robot reaches.
The response. Separate the two questions explicitly at G2: what the protective function does when the model is wrong, and how the model's own errors are bounded.
One line's model on another line's product
The tell. A model is copied to a sister plant because it is the same process, and performance quietly degrades on different lighting and tooling.
The response. Transferability is assessed before deployment and recorded. Copying a model to a new line is a Major change, not a deployment.
Planning systems nobody classified
The tell. Allocation and scheduling modules arrive inside a planning platform upgrade and are never treated as AI systems.
The response. Procurement intake routes on AI content, not on contract value or module name (procured and embedded AI).
9. A ninety-day start
If the sector is yours and the framework is new, this is the order that produces something defensible fastest. It assumes one part-time architect and one risk lead, not a programme.
- Map every path by which a model output can reach a controller, a robot, a release decision or a printed work instruction.
- Confirm and record safety independence for each. Anything that fails this is the first remediation.
- Score the top three physical-action systems with safety engineering present.
- Replace single accuracy thresholds with directional ones on every inspection system, and restate the pass criteria.
- Connect warranty and downstream defect data to the assurance cycle for the highest-volume inspection system.
- Open the classification question on planning, allocation and supplier scoring modules already in production.
- Add physical changes — fixtures, lighting, variants — to the change trigger list.
- Run a G3 dry run on a cell with a collaborative robot, with the safety engineer signing.