Aerospace Functional Safety
Read the civil aviation safety stack the way an ISO 26262 engineer needs to read it: the rules, the risk model, the assurance levels, the architectures, and three comparison chapters that refuse the easy analogies.
- Chapters
- 15
- Chapters
- Failure condition classes
- 5
- Failure condition classes
- Common cause analyses
- 3
- Common cause analyses
- Comparison chapters
- 3
- Comparison chapters
- 01Why Aircraft Cannot Pull Over
- 02The Rulebook: Authorities and Standards
- 03Failure Conditions and Probability Targets
- 04The Safety Assessment Process
- 05Development Assurance and DALs
Why it pays for itself
Stop the DAL to ASIL conversion slide
Chapter 12 states the non-equivalence in full and gives you the five independent reasons behind it, so cross-domain claims in your program get argued through the objectives actually met rather than through matching letters.
Borrow the fail-operational playbook properly
Automated driving removes the attentive driver who made the safe state cheap. The architecture, partitioning and common cause chapters give you aviation's answers to that problem with their real prerequisites attached, not as slogans.
Learn from investigations you can read for free
The page is built on public accident reports, advisory material and regulation. Three of its hardest lessons, on routing concentration, on processing between redundant sensors, and on change impact climbing back to vehicle level, transfer directly to automotive work.
What you’ll be able to do
Read an Aerospace Safety Argument
Follow a claim from an aircraft-level failure condition through its probability objective, its allocation and its closing evidence, and know which document owns each step.
Place DAL and ASIL Correctly
Explain precisely why development assurance levels and ASILs are analogous ladders with non-convertible rungs, and shut down the conversion table before it reaches a slide.
Attack Independence Assumptions
Apply the zonal, particular risks and common mode mindset to your own redundant channels, including the physical routing questions automotive analyses often skip.
Speak the Fail-Operational Vocabulary
Use the command/monitor, self-checking pair, voting and degradation ladder patterns accurately when specifying fail-operational steering, braking or automated driving architectures.
Judge What Transfers Across Domains
Decide what aerospace evidence, methods and mechanisms genuinely help an ISO 26262 program, and what is a luxury of aviation economics or a claim that simply does not carry over.
Treat Human Response as a Claim
Recognize crew and driver response credit as an assumption owed evidence, and carry that discipline into every controllability judgment in a HARA.
Chapter by chapter
- 01
Why Aircraft Cannot Pull Over
The physical asymmetry that reshapes every downstream decision: a road vehicle can often reach a controlled stop, while a function needed for continued safe flight and landing has to keep working until the aircraft is down.
- Reachable safe state
- Fail-passive vs fail-operational
- Availability as a safety property
- 02
The Rulebook: Authorities and Standards
Who holds the authority to say an aircraft is safe, how 14 CFR and the EASA Certification Specifications state the required outcome, and how advisory material and the SAE and RTCA/EUROCAE standards supply the recognized methods.
- 25.1309 as the anchor rule
- Law vs guidance vs standards
- The loose automotive cousinships
- 03
Failure Conditions and Probability Targets
The unit of analysis in aviation is the aircraft-level failure condition, not a component fault. Five severity classes attach an inverse staircase of probability objectives, plus two qualitative rules that shape architectures more than the numbers do.
- No Safety Effect through Catastrophic
- The inverse probability staircase
- No single failure, and crew awareness
- 04
The Safety Assessment Process
How a paper budget at aircraft level becomes requirements on real computers, valves and inspection intervals: the FHA, PSSA and SSA chain, fault trees run first as a design calculator and then in reverse as evidence.
- FHA, PSSA and SSA roles
- Fault trees as allocation engine
- Derived safety requirements
- 05
Development Assurance and DALs
The second axis, for the failure mode no probability model can see: development error. Why rigor is scaled by consequence, how FDAL attaches to functions and IDAL to items, and what independence has to be shown before any allocation claim.
- Functions first, items second
- Independence prerequisites
- Validation vs verification
- 06
DO-178C: Software Assurance
Software gets no failure rate, so the standard scales auditable objectives instead. The plan set written for the authority, the lifecycle data the auditors sample, requirements-based verification, and structural coverage read as an adequacy metric rather than a target to farm.
- Objective counts by level
- The plan set and lifecycle data
- Coverage gaps as findings to diagnose
- 07
DO-254: Hardware Assurance and Qualification
The hardware half splits in two: assuring the correctness of logic you designed, and qualifying any box against the environment it flies through. The simple and complex distinction, what levels A and B add, how commercial parts get in, and the radiation physics that scales with altitude.
- Simple vs complex hardware
- Environmental qualification categories
- Neutron flux, ECC and scrubbing
- 08
Common Cause: Zones, Risks and Separation
Every multiplied small number in the previous chapters assumed independence. The zonal, particular risks and common mode analyses attack that assumption from three directions, and one public 1989 investigation shows what happens when the assumption is wrong.
- ZSA, PRA and CMA
- Debris footprints and routing
- The documented limits of dissimilarity
- 09
Architectures That Fly
The reusable redundancy vocabulary that decades of fly-by-wire practice produced, two published architecture patterns that answer the same question differently, and the sensor and power layers underneath that decide whether any of it holds.
- Command/monitor and voting patterns
- Control law degradation ladders
- Where the weak link really sits
- 10
Integrated Modular Avionics and Partitioning
What changes when many functions of different criticality share one computer: partitioned responsibility, robust temporal and spatial separation, bounded shared-resource interference, deterministic networking, and the direct lineage to automotive hypervisors.
- Roles on a shared platform
- Time, space and interference
- The shared multicore problem
- 11
Certification in Practice
The instruments that turn evidence into permission to fly, how oversight is staged and delegated across a program, the in-service feedback loop that runs for decades, and a sober account of the public case where the system failed.
- Certification basis and means of compliance
- Staged reviews and delegation
- The in-service reporting loop
- 12
Aerospace vs Automotive: Risk Models
Two grammars for the same fear. A single worst-credible-effect judgment with a numeric objective on one side, three discretized parameters and an ASIL on the other, and the definitive statement of why the two ladders do not convert.
- Failure condition vs hazardous event
- Where exposure and the human live
- The DAL to ASIL mapping trap
- 13
Aerospace vs Automotive: Metrics and Mechanisms
What each domain counts and what each domain builds. There is no SPFM, LFM or PMHF in aerospace and no per-condition numeric budget in ISO 26262, yet both write the same latent fault physics and pull different levers on it.
- Metrics that do not cross the aisle
- Number literacy and unit traps
- Two mechanism cultures
- 14
Aerospace vs Automotive: Process and Ecosystem
The system around the engineering: who checks and how often, the volume and cost arithmetic that decides which architectures are affordable, how the two supply chains distribute safety work, and the two learning cultures.
- Oversight geometries
- Volume economics
- Five imports worth stealing
- 15
The One-Page Story
The whole machine running as one machine, traced through a single illustrative pitch-control function from the hazard sentence to the directive that still watches it decades later, followed by the reference card to come back to.
- End-to-end illustrative rail
- Consolidated reference card
- Where to read the primary sources
Who this guide is for
- ISO 26262 engineers working on fail-operational steering, braking or automated driving architectures
- Safety managers who have to answer cross-domain questions about DO-178C, DO-254 or DAL claims
- Suppliers moving parts, platforms or people between automotive and aerospace programs
- Architects evaluating redundancy, voting and partitioning patterns for mixed-criticality platforms
- Anyone who needs the honest version of "how does aviation do it" rather than aviation worship
Frequently Asked Questions
Common questions about Aerospace Functional Safety
Start the course today
A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 77-guide library. No credit card required.