01
Hazard analysis and risk assessment
What can go wrong, how severely, how often, and how detectable. This produces the integrity level, and it has to influence the architecture rather than describe it after the fact.
02
Safety goals and requirements
Each hazard traced to a requirement, and each requirement traced to a design element and a verification activity. Traceability is the deliverable as much as the design is.
03
Architectural decomposition
Where a lower integrity level plus independence achieves the same goal as a higher one — legitimate and valuable, provided the independence is real and demonstrable.
04
Safety mechanisms
Error detection and correction, lockstep, watchdogs, redundant paths, plausibility checks, built-in self-test. Each chosen against a specific failure mode rather than added generically.
05
FMEDA
Failure modes, effects and diagnostic analysis: quantified failure rates and the fraction each mechanism actually detects. This is where diagnostic coverage becomes a number instead of a claim.
06
Verification and validation
Fault injection, fault campaign coverage, and verification of the safety mechanisms themselves — because an undetected failure in a detector is worse than not having one.
07
Qualification
Environmental, reliability and, where required, standard-specific qualification appropriate to the market and the service life.
08
Safety manual
What the integrator must do for the safety argument to hold in their system. A safe component used outside its assumptions is not safe.