# Intralogistics procurement: evidence before a fleet commitment

Local draft; not_published; human review not recorded. Prepared 6 September 2026.

- Use this as a request for evidence and an ownership map. Every row starts not_assessed; the checklist does not score or approve a supplier.

- Record exact configuration, source, observation window, exposure, exclusions, evidence owner, review date and expiry for the response. Keep confidential replies in the buyer's governed private system.

- VDA identifies version 3.0.0 (March 2026) as current at the source retrieval date. Its interface scope excludes safety, cybersecurity, traffic logic, acceptance procedures and responsibility allocation; assess those separately.

- ISO Open Data records ISO 3691-4:2023 as published, at the to-be-revised stage, and its successor as an unpublished draft at the retrieval date. Confirm the applicable edition and product/system/site/jurisdiction with competent specialists; a draft is not a published standard.

- Use the existing Product System and Evidence Passport to connect claims, requirements, configuration, evidence gaps and the named human decision. Unresolved hold conditions remain visible; a filled checkbox cannot authorize operation.

## workflow-value

Gate: strategy; lens: customer-operator-value; owner role: Operations sponsor; status: not_assessed.

Request: Workflow map, alternatives and value thesis, including work kept with people

Acceptance question: Which accepted customer outcome improves, for whom, and compared with what?

Hold condition: The proposal measures robot activity without an accepted customer outcome.

## human-baseline

Gate: discovery; lens: customer-operator-value; owner role: Site operations and operator representative; status: not_assessed.

Request: Observed baseline for attempted/accepted moves, waiting, errors and person-minutes under declared shifts

Acceptance question: Are population, window, task difficulty and exclusion rules comparable?

Hold condition: No measured baseline or an incompatible denominator.

## economic-boundary

Gate: strategy; lens: business-model-economics; owner role: Product and finance owners; status: not_assessed.

Request: Acquisition, integration, infrastructure, licenses, energy, operator/recovery work, service, spares and exit cost model

Acceptance question: Are benefit, supplier revenue and total cost separated and assumptions sensitivity-tested?

Hold condition: Payback omits material lifecycle costs or assumes all released time becomes cash savings.

## configuration

Gate: productization; lens: system-architecture; owner role: System architect and integrator; status: not_assessed.

Request: Named robot, software, controller, map, payload, battery, charger and peripheral versions with compatibility evidence

Acceptance question: Does every supplied test apply to the ordered configuration?

Hold condition: A component or version differs without impact review and revalidation.

## operating-envelope

Gate: productization; lens: system-architecture; owner role: Site and system owners; status: not_assessed.

Request: Site survey covering traffic, floors, slopes, loads, people, connectivity, charging and exceptional conditions

Acceptance question: Are intended use, foreseeable misuse, exclusions and change triggers explicit?

Hold condition: The proposed site falls outside the evaluated operating envelope.

## protocol-version

Gate: productization; lens: system-architecture; owner role: Fleet-control and robot suppliers; status: not_assessed.

Request: Exact VDA 5050 version plus supported message/action/error/factsheet/zone matrix and cross-vendor tests

Acceptance question: Which optional features and breaking-version migrations are supported by both sides?

Hold condition: The only evidence is an unqualified supports-VDA-5050 statement.

## external-interfaces

Gate: productization; lens: system-architecture; owner role: Integrator and enterprise IT; status: not_assessed.

Request: WMS/MES/ERP, door, conveyor, charger and infrastructure interface contracts with failure behavior

Acceptance question: What happens on duplicate, delayed, lost or out-of-order work requests?

Hold condition: Responsibility for an external interface or inconsistent task state is missing.

## task-evaluation

Gate: productization; lens: ai-data-evaluation-hmi; owner role: Product evaluation owner; status: not_assessed.

Request: Representative successful, failed, aborted and difficult-task results with acceptance criteria and denominators

Acceptance question: Do evaluation slices cover actual loads, obstructions, traffic and sensor degradation?

Hold condition: A demonstration or isolated easy task is treated as shift-level evidence.

## recovery-authority

Gate: productization; lens: ai-data-evaluation-hmi; owner role: Operations and control authority; status: not_assessed.

Request: Failure detection, bounded retries, replan, safe stop, handback and restored-state evidence

Acceptance question: Who can intervene, with what latency and fallback when unavailable?

Hold condition: Recovery ownership, restored task state or the human intervention path is untested.

## safety-case

Gate: launch; lens: safety-governance-oversight; owner role: Competent safety/conformity owners; status: not_assessed.

Request: Applicable product/system/site scope, exact standards editions, hazard assessment and verification artifacts

Acceptance question: Who determines obligations and accepts residual risk for the complete installation?

Hold condition: Interface compliance or a supplier statement is substituted for system conformity and site assessment.

## cyber-updates

Gate: launch; lens: safety-governance-oversight; owner role: OT cybersecurity and product owners; status: not_assessed.

Request: Broker/network boundaries, identities, access, update signing, vulnerability handling, incident response and recovery plan

Acceptance question: Which supplier owns each control and what evidence covers loss of communications or compromised components?

Hold condition: The communication standard is treated as a cybersecurity assurance mechanism.

## data-rights

Gate: launch; lens: safety-governance-oversight; owner role: Data owner and legal/privacy specialists; status: not_assessed.

Request: Permitted telemetry, camera data, retention, access, training reuse, location and exit arrangements

Acceptance question: Is each use necessary, permitted and separable from optional supplier model training?

Hold condition: Rights are unknown, bundled without scope, or incompatible with site obligations.

## commissioning

Gate: launch; lens: operations-ecosystem; owner role: Named launch owner and integrator; status: not_assessed.

Request: Site readiness, installation, training, acceptance trials, defects, rollback and phased release plan

Acceptance question: Who signs each acceptance decision and can stop or reverse rollout?

Hold condition: Payment or deployment milestones outrun unresolved acceptance evidence.

## duty-and-service

Gate: scale; lens: operations-ecosystem; owner role: Service and operations owners; status: not_assessed.

Request: Shift-length availability by cause, intervention/recovery rates, person-minutes and longest continuous useful duty

Acceptance question: Are support capacity, response times, parts and escalation adequate for the intended fleet and sites?

Hold condition: Mean uptime hides excluded downtime or recovery work that scales beyond capacity.

## success-cost

Gate: scale; lens: business-model-economics; owner role: Operations and finance owners; status: not_assessed.

Request: Total ownership/operating cost and accepted useful moves for the same population and accounting window

Acceptance question: Are failed and aborted attempts retained, and is the denominator observed and nonzero?

Hold condition: Cost per move uses theoretical throughput, missing costs or an incompatible observation window.

## change-and-exit

Gate: scale; lens: operations-ecosystem; owner role: Product portfolio and procurement owners; status: not_assessed.

Request: Version-support terms, site replication evidence, configuration control, supplier exit and retirement responsibilities

Acceptance question: What reopens the decision after map, fleet, authority, software, site or commercial changes?

Hold condition: Support lifetime, revalidation, rollback, data disposition or supplier exit is unspecified.

## Source notes

- [VDA 5050 version and archive](https://www.vda.de/en/topics/automotive-industry/vda-5050) — VDA; published date not supplied; retrieved 2026-09-06. The current-version page identifies VDA 5050 version 3.0.0, March 2026. An exact implementation version is needed when comparing suppliers.
- [VDA 5050 version 3 specification](https://www.vda.de/dam/jcr:09f03b91-13e2-4db3-bf30-4f221710071b/VDA5050_EN.pdf) — VDA; published 2026-03; retrieved 2026-09-06. The interface specification excludes safety requirements, traffic-management logic, external-IT/peripheral interfaces, acceptance procedures, operating responsibilities and cybersecurity mechanisms. Interface support cannot establish complete system readiness.
- [ISO Open Data: ISO 3691-4 deliverables metadata](https://www.iso.org/open-data.html#iso_deliverables_metadata) — ISO; published date not supplied; retrieved 2026-09-06. ISO's open dataset records ISO 3691-4:2023 edition 2, publication date 12 June 2023, current stage 90.92 (to be revised), and a draft successor at stage 40.20 with no publication date. Metadata alone does not establish applicability or conformity. Contains information from ISO Open Data's iso_deliverables_metadata dataset, available under the ODC Attribution License (ODC-By) v1.0. Only selected metadata fields are retained; no normative standard text is reproduced. [ODC Attribution License (ODC-By) v1.0](https://opendatacommons.org/licenses/by/1-0/). Dataset SHA-256: 845b6901d66310a767e06abdf03d48f460768b01c732b42d9f3f9d837aca71f0.

Payload SHA-256: d2176c47160e1dcfbd9fcde8c3a5edcb1d3d8ff52832ed83eeb434a453231a00
