English
Download App
Follow Us
  • Facebook
  • YouTube
  • Instagram
  • TikTok
  • X
HomewikiAutomotive Functional Safety (ISO 26262)

Automotive Functional Safety (ISO 26262)

2026-10-02 11:40:01

Automotive functional safety refers to the systematic technical and managerial measures implemented to ensure that a vehicle's electrical and electronic (E/E) systems do not pose unacceptable risks to occupants or the surrounding environment in the event of a malfunction. ISO 26262 is the globally recognised benchmark standard dedicated to the functional safety of road vehicles, providing a structured technical framework and process guidelines across the entire lifecycle of automotive electronic systems.

Standard Overview

ISO 26262 originated around 2005 and was officially published in November 2011 as an automotive-specific adaptation of the generic industrial functional safety standard, IEC 61508. It initially applied to series-production passenger cars up to 3.5 tonnes equipped with E/E systems. The second edition, released in 2018, broadened this scope to cover all road vehicles except mopeds, while introducing specific guidelines for semiconductor applications and motorcycle applicability.

In China, the national equivalent of ISO 26262 is the GB/T 34590 "Road vehicles - Functional safety" series, governed by the National Technical Committee of Auto Standardization, which incorporates and adapts the international ISO 26262:2018 edition.

Standard Architecture

The ISO 26262 standard comprises 10 parts, spanning the complete development lifecycle from management to technical execution:

Part 1: Vocabulary — Standardises definitions of essential terms such as faults, errors, and failures.

Part 2: Management of functional safety — Defines safety management activities, organisational roles and responsibilities, safety plans, safety cases, and confirmation measures.

Part 3: Concept phase — Covers item definition, initiation of the safety lifecycle, Hazard Analysis and Risk Assessment (HARA), and the functional safety concept.

Part 4: Product development at the system level — Outlines technical safety requirements, system architectural design, item integration and testing, and safety validation.

Part 5: Product development at the hardware level — Encompasses hardware safety requirements, hardware design, architectural metrics (SPFM, LFM, PMHF), and hardware integration and testing.

Part 6: Product development at the software level — Details software safety requirements, software architectural design, software unit design and implementation, and software integration and testing.

Part 7: Production, operation, service and decommissioning — Specifies safety requirements across production planning, vehicle operation, servicing/maintenance, and end-of-life decommissioning.

Part 8: Supporting processes — Covers distributed development interfaces, safety requirements management, configuration and change management, software tool qualification, software component qualification, and hardware element evaluation.

Part 9: ASIL-oriented and safety-oriented analyses — Details ASIL decomposition criteria, Dependent Failures Analysis (DFA), and related safety analyses.

Part 10: Guideline on ISO 26262 — Provides explanatory guidance and best practices for standard application.

Safety Lifecycle

ISO 26262 utilises a comprehensive safety lifecycle model that governs a product from initial concept development through to final decommissioning. This lifecycle is structured around three primary pillars: the concept phase, product development phase, and production & post-delivery phase, aligned along the industry-standard V-model development framework.

During the concept phase, key activities include: defining the scope and functional boundaries of the system via item definition; identifying potential hazard scenarios and assigning the appropriate ASIL via Hazard Analysis and Risk Assessment (HARA) ; and establishing Functional Safety Requirements (FSR) derived from top-level safety goals.

In the product development phase, the left side of the V-model (design branch) cascades requirements down from system-level to hardware and software domains, defining technical, hardware, and software safety requirements alongside their respective architectures. The right side of the V-model (testing branch) handles sequential verification, hardware/software integration testing, and final safety validation.

Automotive Safety Integrity Level (ASIL)

ASIL (Automotive Safety Integrity Level) is the risk classification scheme defined by ISO 26262 to determine the necessary safety integrity required for a given automotive system. The ASIL rating is calculated based on three key parameters: Severity (the potential severity of injury or harm), Exposure (the likelihood of the operational situation occurring), and Controllability (the extent to which the driver or other road users can avoid or control the hazard).

ASIL is classified into four levels: ASIL A (lowest rigor), ASIL B, ASIL C, and ASIL D (highest rigor). ASIL D denotes the most critical safety requirements, demanding the most rigorous engineering processes. Additionally, QM (Quality Management) indicates that standard quality management practices are sufficient without requiring specialised ISO 26262 safety measures. A higher ASIL rating mandates more exhaustive safety analyses, stringent verification methods, and extensive documentation.

Safety Analysis Methods

ISO 26262 mandates rigorous safety analysis techniques to systematically identify and evaluate potential failure risks. These methodologies fall into two main categories:

Inductive analysis (bottom-up), notably FMEA (Failure Mode and Effects Analysis), evaluates component-level faults and maps their knock-on impacts on vehicle-level behaviour. At the hardware tier, FMEDA (Failure Modes, Effects, and Diagnostic Analysis) provides quantitative metrics, calculating the Single-Point Fault Metric (SPFM), Latent Fault Metric (LFM), and Probabilistic Metric for Random Hardware Failures (PMHF) to verify compliance with targeted ASIL thresholds.

Deductive analysis (top-down), exemplified by FTA (Fault Tree Analysis), starts with vehicle-level hazards (top events) and traces downward to uncover the root causes and cascading failure paths.

Dependent Failures Analysis (DFA) identifies potential cascading and common-cause failures resulting from compromised independence between systems or components. Under optimal engineering conditions, inductive and deductive analyses should cross-validate and arrive at consistent conclusions.

Implementation Value and Challenges

ISO 26262 compliance is now a mandatory prerequisite demanded by leading global carmakers (such as Volkswagen, BMW, GM, and Ford) and Tier-1 automotive suppliers (such as Bosch and Continental). Its principal value lies in mitigating E/E system failure risks through structured processes, safeguarding against safety-related product recalls and legal liabilities, while serving as an indispensable gateway for suppliers to enter the global automotive supply chain.

However, implementing ISO 26262 presents significant challenges: the framework is highly complex and comprehensive, requiring substantial engineering capabilities and organisational discipline; full compliance demands considerable investments in time and financial resources; validation and testing workflows are immense; and executing precise risk assessments across increasingly complex vehicle architectures remains a demanding task.

Feedback