This process is specified in DO-178C. It is a kind of communication process with Certification Authority. It is very important for suppliers to get a good results. I’ve never experienced about type certification or airworthiness certification, but I think that I can imagine the procedure because there are published document.
Though it is natural to think, applicant has to submit safety plan to certification body and it can be proceed if the plan is approved by certification authority.
It would be ridiculous if applicant submit safety plan in the middle of the project. What if the plan is rejected? Everything they have done so far must be dumped.
Unfortunately this process is not defined in the automotive, but it also essential for supplier. Competent OEM may have a detailed process for audit and assessment.
You can also refer a book, “Developing Safety-Critical Software(DO-178C)” in chapter 12
It is a recommended practice published in SAE. It is short(53 pages), and easy to understand. It explains step by step approach with example.
So I believe that it would be a good material to understand concept development.
I excerpt titles of key sections.
- Identification of Hazards
- Risk Assessment
- Step 1. Exposure determination
- Step 2. Severity determination
- Step 3. Controllability determination
- Step 4. ASIL determination
- Appendix – Example
if you have kind OEM that shares their work products, then you don’t have to read the paper, but if you are a student or a person that cannot access them, it would be useful.
There is saying about interview. An interviewer cannot make a interviewee be hired but can make him/her failed to be hired. I believe that this is true and a similar correspondence can be possible in the functional safety project.
I review functional safety documents frequently, and functional safety scope is too vast for one person to know everything fully so I sometimes conduct incomplete review. Incomplete review means that even though I approve it, it cannot be ensured that it is fully achieved.
Because I understand my weakness, I tried to find nonconformances in the documents. At least I’m first auditor in this project. And if I don’t agree, then it cannot be proceed. In the near future, I have to respond against customer auditor’s questions. There should be some layers of reviewers like me. They act as if ‘safety-nets’ in the project, and they protect systematic faults in the project.
Final reviewer shall be customer side auditors(or assessors). In some ways, customer have to not only have a deep knowledge about product knowledge but also have a deep technical functional safety knowledge. If a person does not have both, team has to be arranged. And who does not have a deep knowledge about the project but has a functional safety knowledge has to enough review experience whether the product under review is well documented or not. And he has to help a customer side product champion to determine whether supplier’s safety concepts or their approaches are good to satisfy their safety requirements.
But…. even though they conduct such audit or assess, they cannot ensure that safety is fully achieved.