Title: ASIL Decomposition | ISO 26262 Academy
URL: https://iso26262.academy/features/concepts/asil-decomposition
Description: Learn valid decomposition schemes to allocate lower ASILs to redundant elements while maintaining safety integrity.

---
Concept guide · ISO 26262-9 §5 · 12 chapters

# ASIL Decomposition

Learn how to distribute safety requirements across independent architectural elements to reduce individual ASIL allocation while maintaining overall safety integrity - with interactive simulators and a Steer-by-Wire case study.

12

Chapters

8

Interactive simulators

1

Case study

2h

Video

Included in Pro Expert

[Start learning](https://iso26262.academy/register?plan=free&from=%2Fconcepts%2Fasil-decomposition&utm_source=website&utm_medium=cta&utm_campaign=features_concepts) See the chapters

Course intro · 5 min Free preview

A 5 min look inside the course. 2 hours of course videos for registered users.

The short version

## Quick answers

What is ASIL decomposition in ISO 26262?

ASIL decomposition is a method defined in ISO 26262-9 Clause 5 that splits a safety requirement assigned a high ASIL into redundant requirements implemented by sufficiently independent architectural elements, each carrying a lower ASIL. The original ASIL is kept in parentheses - for example, ASIL D can be decomposed into ASIL B(D) plus ASIL B(D). Decomposition reduces the systematic development rigor for each element, but both elements must still fulfil the same safety goal, share the same safe state, and their independence must be demonstrated through dependent failure analysis. It is an architectural trade, not a discount.

Which ASIL decomposition combinations are allowed?

ISO 26262-9 defines a fixed set of permissible schemes. ASIL D may be decomposed into C(D) + A(D), B(D) + B(D), or D(D) + QM(D); ASIL C into B(C) + A(C) or C(C) + QM(C); ASIL B into A(B) + A(B) or B(B) + QM(B); and ASIL A into A(A) + QM(A). The course teaches this as an "ASIL algebra" point system that makes the pattern easy to remember, and its interactive calculator shows every valid option for a selected ASIL together with selection heuristics for choosing between them.

Keep going, free

- [Article · 9 min read 5 Essential Advices for ASIL Decomposition in ADAS Architectures](https://iso26262.academy/blog/5-essential-advices-for-asil-decomposition-in-adas-architectures)
- [Demo exam · no account Test yourself with 7 exam-style questions](https://iso26262.academy/demo-exam)

A practical sample · no account needed

## What is ASIL decomposition?

ASIL decomposition allocates a safety requirement redundantly to sufficiently independent elements, using an allowed decomposition scheme. It changes the allocated requirements and their development rigor; it does not reduce the original safety goal’s ASIL.

Two monitoring channels share a power supply and a clock. Both are intended to support a redundant safety requirement.

Do two channels automatically justify decomposition?

**Reveal the reasoning**

No. Shared resources can introduce dependent failures. The independence argument must address these dependencies and the selected decomposition scheme. Counting channels is not evidence that they are sufficiently independent.

Illustrative learning example, not a project assessment. ISO 26262, Part 9, Clause 5 · [About the academy](https://iso26262.academy/about)

This example is public. A free account gives you access to the full videos for this topic; the written guide follows the plan access shown above.

Why this course · ISO 26262, Part 9, Clause 5

## Why it pays for itself

### Decompose with a defensible rationale

The ASIL algebra point system and the ISO 26262-9 allocation matrix turn "can we split this ASIL D requirement?" into a structured decision you can defend in front of an assessor.

### Prove independence, not just claim it

Independence is where most decompositions fail review. The DFA coupling factor, FFI mechanism, and beta-factor CCF chapters show exactly what evidence a credible independence argument needs.

### Learn by simulating, not just reading

Eight interactive simulators - comparator architectures with fault injection, k-out-of-n voting, PMHF calculators, 3-path redundancy - let you experiment with the failure behavior the theory describes.

After the course

## What you’ll be able to do

### Evaluate decomposition feasibility

Determine whether ASIL decomposition is appropriate for your project using the five-question decision gate and cost/benefit analysis.

### Apply valid decomposition schemes

Use the ASIL algebra point system and the ISO 26262-9 allocation matrix to select valid decomposition combinations with proper justification.

### Prove element independence

Demonstrate sufficient independence through DFA, coupling factor analysis, FFI mechanisms, and documented evidence packages.

### Perform quantitative analysis

Calculate PMHF with beta-factor CCF modeling and validate the decomposition against hardware metric targets for each ASIL.

### Build FTA for decomposition

Construct fault trees with AND/OR gates, derive minimal cut sets, and evaluate voting architectures for safety-critical designs.

### Distinguish correctness vs availability

Separate correctness and availability requirements and apply classical or temporal decomposition strategies appropriately.

The curriculum · 12 chapters

## Chapter by chapter

1. 01
   **Orientation**
   Verify whether ASIL decomposition is right for your project with a five-question decision gate, lifecycle positioning, key vocabulary, and a fast use-or-don't-use checklist before you invest in the method.
   - Decision gate
   - Lifecycle flow
   - 12-term glossary
2. 02
   **Introduction & Expectations**
   Understand what ASIL decomposition is and is not, explore its origins in IEC 61508, three key benefits, and the top ten misconceptions with interactive flip cards.
   - Animated decomposition
   - 10 flip cards
   - IEC 61508 origins
3. 03
   **Standards & Allocation Matrix**
   Master the ASIL algebra point system and the ISO 26262-9 permissible decomposition matrix, then use the interactive calculator to explore every valid decomposition option for your target ASIL.
   - ASIL calculator
   - Allocation matrix
   - Selection heuristics
4. 04
   **Core Decomposition Principles**
   Learn why decomposition requires the same safety goal and the same safe state, the difference between functional and hardware redundancy, and the comparator pattern for correctness.
   - Comparator simulator
   - Fault injection
   - Redundancy patterns
5. 05
   **Step-by-Step Process**
   Follow the systematic 5-step process from HARA through strategy definition, dependent failure analysis, allocation, and verification, including item boundary analysis, SEooC integration, and legacy component constraints.
   - 5-step process
   - FTTI timeline
   - SEooC integration
6. 06
   **Independence Methods**
   Tackle the hardest aspect: achieving and proving independence. Covers DFA coupling factors, FFI mechanisms, end-to-end protection, watchdog types, and cascading failure versus common cause failure analysis.
   - DFA coupling factors
   - FFI mechanisms
   - Watchdog types
7. 07
   **Quantitative Analysis**
   Explore the mathematics of safety: PMHF, SPFM, and LFM targets, probability theory, and the beta-factor CCF model, with an interactive PMHF calculator and a fully worked calculation.
   - PMHF calculator
   - Beta-factor model
   - Worked calculation
8. 08
   **Fault Tree Analysis**
   Apply FTA to decomposition with AND/OR gates, minimal cut sets, and voting architectures, including an interactive k-out-of-n voting simulator and a Steer-by-Wire fault tree example.
   - Voting simulator
   - Cut set analysis
   - Steer-by-Wire FTA
9. 09
   **Correctness vs Availability**
   Master the critical distinction between correctness and availability decomposition, explore classical versus temporal approaches, and experiment with the 3-path redundancy simulator and stop fault analysis.
   - 3-path simulator
   - Temporal decomposition
   - Stop fault analysis
10. 10
    **Practical Examples**
    See how theoretical principles become real engineering solutions with detailed Steer-by-Wire decomposition examples showing architecture choices, independence evidence, and failure mode analysis for each element.
    - Steer-by-Wire
    - Architecture diagrams
    - Failure mode analysis
11. 11
    **Limitations & Pitfalls**
    Understand when decomposition cannot or should not be applied: combinatorial complexity growth, the limits of homogeneous redundancy, and technology-based alternatives to lowering the ASIL.
    - Complexity calculator
    - Homogeneous limits
    - Alternatives
12. 12
    **Expand Your Knowledge**
    Continue your learning journey with links to related ISO 26262 processes, work product templates, and a thematic exam to test your ASIL decomposition understanding.
    - Related processes
    - Work product templates
    - Thematic exam

Interactive simulators

## Not just text: the visual toolkit

### Animated decomposition visualization

Click to animate ASIL D splitting into decomposed elements, with hover tooltips showing PMHF targets and point values.

### ASIL decomposition calculator

Select any ASIL to see all valid decomposition options as clickable cards, with a symmetric filter and detailed combination descriptions.

### Comparator architecture simulator

Animated data flow through a dual-channel comparator architecture with fault injection controls and per-component detail views.

### PMHF / beta-factor calculator

Adjustable sliders for beta factor, failure rates, and detection time with real-time PMHF calculation and independence quality assessment.

### k-out-of-n voting simulator

Toggle channel failures with adjustable n and k values and see cut set generation, system status, and decomposition feasibility in real time.

### 3-path redundancy simulator

Toggle path failures and watch automatic fallover animation, with a live PMHF display and adjustable detection time slider.

### Combinatorial complexity calculator

Adjust events, maximum ASIL, and cut sets to see the exponential growth of analysis permutations with feasibility and time estimates.

### Misconception flip cards

Ten clickable cards that flip between common misconceptions and the reality, filterable by cost, technical, and process categories.

Real-world application

## Steer-by-Wire ASIL D decomposition

Decomposition principles are applied to a complete Steer-by-Wire system, demonstrating how to split an ASIL D requirement into independently implemented elements with full traceability.

- ASIL D decomposed to ASIL C(D) + ASIL A(D)
- Primary steering controller plus independent safety monitor
- Independence evidence through DFA and coupling analysis
- FTA with minimal cut sets and CCF evaluation
- PMHF calculation with beta-factor modeling
- Comparator architecture with fault injection demonstration

Steer-by-Wire decomposition

ASIL D -> ASIL C(D) + ASIL A(D): primary controller plus independent safety monitor

Unlock in course

Built for

## Who this guide is for

- System architects deciding whether to split an ASIL D function across redundant elements
- Safety engineers who must write the independence argument for a decomposed architecture
- Hardware and software leads sizing the real cost of a decomposition before committing
- Anyone facing an assessor question about ASIL B(D) notation and what it obligates

## Frequently Asked Questions

Common questions about ASIL Decomposition

Independence is demonstrated through dependent failure analysis (DFA): you systematically examine coupling factors such as shared resources, shared inputs, physical proximity, common environment, and common development faults, then show each is either absent or mitigated. Supporting evidence typically includes freedom from interference mechanisms (memory protection, timing monitoring, E2E communication protection), watchdog concepts, and quantitative common cause modeling with a beta factor. The course dedicates a full chapter to independence methods and another to the quantitative side, including an interactive PMHF calculator with independence quality assessment.

No. Decomposition lowers the ASIL that governs systematic development rigor for each element, but the quantitative hardware evaluation - PMHF and the architectural metrics - is still assessed against the original ASIL of the safety goal. This is one of the most common misconceptions the course addresses: a D(D) + QM(D) or B(D) + B(D) split does not relax the ASIL D failure rate target for the function as a whole, and common cause failures can silently consume the budget unless the beta factor is kept low.

The course has 12 chapters covering the full method from the orientation decision gate to limitations and pitfalls, 8 interactive simulators and calculators, about 2 hours of synchronized video, and a Steer-by-Wire case study that decomposes an ASIL D steering function into C(D) + A(D) with independence evidence, FTA, and PMHF calculation. It closes with links to related processes, work product templates, and a thematic exam.

## Start the course today

A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month - plus 2 hours of course videos for registered users. The Pro and Expert plans unlock more of the 78-guide library. No credit card required.

[Start learning](https://iso26262.academy/register?plan=free&from=%2Fconcepts%2Fasil-decomposition&utm_source=website&utm_medium=cta&utm_campaign=features_concepts) [View Pricing Plans](https://iso26262.academy/pricing)
