Safety in Series-Production Development
ISO 26262 defines a lifecycle for functionally safe systems, from the concept phase through decommissioning. SPICE assessments and safety audits under ISO 26262 are often carried out together.
The foundation for developing a safety-relevant, software-defined system is sound development processes, such as those demonstrated in an Automotive SPICE® CL2 assessment. On top of that, several additional processes are required that Automotive SPICE® (version 4.0/4.1) does not (yet) include.
Essentially, a hazard and risk analysis (Hazard Analysis and Risk Assessment, HARA) must be performed, resulting in a work product of the same name. This identifies the various Automotive Safety Integrity Levels (ASIL) that apply. Depending on the level, different requirements and methods then apply to the development process — and, unlike SPICE standards, to the product itself as well.
During development, safety audits (similar to a SPICE assessment) evaluate whether the right development processes and methods are defined, documented, and applied. At the end, a safety assessment uses a safety case to document and demonstrate that the product has achieved the required level of safety.
We are happy to support the execution of safety audits and assessments — either ourselves or together with our partners.
One of our customers develops chips for managing battery cells. This development does not happen on behalf of a specific vehicle manufacturer, but rather autonomously and much earlier in the process. Requirements are gathered by a marketing department that estimates what functionality will be expected in the future. The chips are fully developed and then offered as off-the-shelf catalog products.
Functional safety is a central concern for these high-voltage components — but the safety goals cannot be derived from the overarching system, since that system does not yet exist. What is developed instead is a so-called Safety Element out of Context (SEooC). The company that later purchases these chips and integrates them into a specific battery for a specific vehicle must then verify that everything fits together and that the required level of safety can be achieved.
Some ECU manufacturers face challenges communicating with the vehicle manufacturer and do not receive a HARA for the overarching system from their customer. In this case as well, the SEooC construct is applied.
Request a Consultation ← All Standards