The Automotive Safety Standards Map
One vehicle, four ways to get hurt, and the documents that grew up around each of them. How ISO 26262, ISO 21448, ISO/SAE 21434 and ISO/PAS 8800 divide the work, where they overlap, and how the law above them reads the result.
- Chapters
- 16
- Chapters
- Axes of Difference
- 9
- Axes of Difference
- Sectors Compared
- 5
- Sectors Compared
- Worked Example
- 1
- Worked Example
- 01One Vehicle, Four Ways to Get Hurt
- 02Who Writes the Rules
- 03The Backbone: ISO 26262 and Its Edges
- 04ISO 21448: Hazards Without a Fault
- 05ISO/SAE 21434: The Attacker as a Hazard Source
Why it pays for itself
Stop arguing about which standard applies
The cause decides the document, not the consequence. One hazardous event is worked through four unrelated causes so the routing question - malfunction, performance limit, attack or AI insufficiency - stops being a meeting and becomes a decision you can defend.
Know what a document is actually worth
A technical report, a publicly available specification, an International Standard and a UN Regulation are four different kinds of obligation. The chapter on document types is the one that stops a team from treating ISO/PAS 8800 as if it were binding, or UN R155 as if it were optional.
Build one safety case, not four
The lifecycles interlock rather than run in sequence or in parallel. You get the shared work products, the hand-offs and their timing on a real programme calendar, and the shape of a case with four sub-arguments, one assumptions register and one residual-risk statement.
Answer the auditor who reads all of it together
Since 2021 the regulations put an external reader in the loop with power over the product. The chapters on law and on confirmation measures show what that reader asks for and how the approval file is assembled from work products no regulation ever names.
What you’ll be able to do
Route a hazard to the right document
Given a hazardous event, identify whether it belongs to ISO 26262, ISO 21448, ISO/SAE 21434 or ISO/PAS 8800 by its cause, and recognise the cases that belong to more than one.
Read a document code correctly
Tell an International Standard from a publicly available specification, a technical report or a technical specification, and know what obligation each one actually creates.
Plan an interlocked programme
Place the hand-offs between the lanes where they fall on a real calendar, and recognise the concept phase and the release window as the two regions that need management attention.
Structure a joint safety case
Write one case with four sub-arguments, one assumptions register and one residual-risk statement, instead of four documents that contradict each other.
Assemble an approval file
Map the annex requirements of the UN Regulations onto the work products your safety process already produces, and explain the bridge to a technical service.
Chapter by chapter
- 01
One Vehicle, Four Ways to Get Hurt
One lane-centering hazard, four unrelated causes, and the reason a malfunction standard alone stopped being enough. Includes the scope sentence of ISO 26262 and an honest history of how the map grew.
- Same consequence, four causes
- What functional safety covers
- A short history of the map
- 02
Who Writes the Rules
The bodies behind the documents and the weight each document type carries. A technical report, a publicly available specification, an International Standard and a UN Regulation are four different kinds of obligation.
- Two kinds of pen
- Document types and weight
- How a voluntary standard grows teeth
- 03
The Backbone: ISO 26262 and Its Edges
Twelve parts on one wheel, the scope sentence and its exclusions, the load-bearing ideas every sibling inherited, and what the 2018 edition changed.
- Twelve parts
- The scope exclusions
- What the siblings inherited
- 04
ISO 21448: Hazards Without a Fault
A hazard with nobody to blame. The four areas and what acceptable means, the triggering-condition chain, and where SOTIF meets the backbone on a real project.
- The four areas
- Triggering conditions
- Where it meets ISO 26262
- 05
ISO/SAE 21434: The Attacker as a Hazard Source
Why intent breaks the statistics, the TARA beside the HARA, a lifecycle that starts before the project and ends after it, and the regulatory pair UN R155 and R156.
- TARA next to HARA
- Controls that cut paths
- R155 and R156
- 06
The Automated Driving Layer
The automation ladder as a statement about responsibility, ISO/TS 5083 as the umbrella, the ISO 34501 to 34505 scenario family, and how regulators assess it.
- ISO/TS 5083
- Scenario standards
- Multi-pillar assessment
- 07
AI in the Loop: ISO/PAS 8800
Behaviour that comes from data rather than code, AI output insufficiency as a hazard source, the AI safety lifecycle and where it plugs into the others.
- AI output insufficiency
- The AI safety lifecycle
- The assurance argument
- 08
The Satellites
The extensions rather than siblings: ISO/PAS 8926 for software you did not develop, ISO/TR 9839 for hardware that wears out, ISO/TR 9968 for battery hazards, and ISO 24089 with UN R156 for a product that keeps changing.
- ISO/PAS 8926
- ISO/TR 9839 and 9968
- ISO 24089
- 09
Law Above the Map
Type approval, self-certification and mandatory national standards; the European frame; the regulations that read your safety case; and how a voluntary standard becomes a legal fact through the state of the art.
- Three legal shapes
- The European frame
- State of the art
- 10
Principles Side by Side
Every standard is a theory of acceptable risk. Why automotive chose ordinal classes, the four repairs later made to that theory, and four questions to ask of any risk model.
- Theories of risk
- Why ordinal classes
- Four questions
- 11
Metrics and Mechanisms Across the Map
What each standard measures in hardware, what each asks of the mechanisms, what integrity means in each, and how fail-operational changes which metric matters.
- Metrics compared
- Mechanisms compared
- Fail-operational
- 12
How the Lifecycles Interlock
Neither sequential nor parallel. The joint work products, one safety case with four sub-arguments, who checks with how much independence, and the supplier interface underneath it all.
- Joint work products
- One case, four arguments
- Independence by ASIL
- 13
Differences I: ISO 26262 Against Its Siblings
Nine axes of distance between the backbone and its siblings, the misreadings that cost the most, and the two dispositions a joint argument needs.
- Nine axes of distance
- Costly misreadings
- Joint-argument dispositions
- 14
Differences II: Automotive Against the Other Sectors
The family tree from IEC 61508, five sectors compared on six axes, what each safety culture can borrow from the others, and the branch with no analogue anywhere else.
- The family tree
- Five sectors, six axes
- The branch with no analogue
- 15
Worked Example: One Feature, Every Standard
One feature traced through every applicable document: the numbers and decisions lane by lane, one case carrying four arguments, and what the first year on the road does to all of it.
- Lane by lane
- One case, four arguments
- The first year in the field
- 16
The One-Page Story
Why the whole map fits on one page, and the poster that puts the documents, their hazard sources and their interfaces in a single view you can take into a meeting.
- The poster
- Documents and hazard sources
- One view
Not just text: the visual toolkit
Four Hazard Scene
One lane-centering feature and four hazard sources - fault, functional insufficiency, cyber attack and AI insufficiency - each owned by a different document.
Standards Timeline
The map growing from 1998 to 2027: one parent standard, one standard alone for eight years, then eight lanes filling in.
Twelve-Part Wheel
The twelve parts of ISO 26262 arranged so the concept phase, the product development levels and the supporting processes read as one lifecycle.
Rule-Makers Atlas
Which body writes which document, and how ISO, SAE, IEC and UNECE outputs differ in the obligation they create.
Binding Force Stack
The same ISO standards under type approval, self-certification and mandatory national standards - the engineering layer is global, only the legal roofs differ.
Programme Calendar
A feature programme over forty-eight months with the activities of six lanes and the hand-offs between them drawn where they actually fall.
Sibling Distance Grid
Nine axes on which ISO 26262 and its siblings genuinely differ, with the misreadings that each difference produces.
One-Pager Poster
The whole map on a single page: hazard sources, documents, legal layer and the interfaces between them.
One Feature, Every Standard
A single feature is carried through every document on the map, lane by lane, with the decisions and their rationale recorded at each step - then the four arguments are folded into one case and followed into its first year on the road.
- The item definition that has to serve four analyses that rate it differently
- The hazard list read as a HARA, as a SOTIF area and as a TARA input
- The mitigations that buy something in one lane and spend something in another
- One safety case with four sub-arguments and a single residual-risk statement
- What the field loop does to all of it after release
Full worked example available with an Expert plan
Who this guide is for
- Safety managers who now own SOTIF, cybersecurity and AI arguments alongside functional safety
- Engineers moving from a pure ISO 26262 role onto an automated driving or connected feature
- Systems architects deciding where a mitigation belongs when it costs something in another lane
- Homologation and compliance staff assembling an approval file from safety work products
- Anyone who has been told "that is a SOTIF issue" and was not sure whether it was
Frequently Asked Questions
Common questions about The Automotive Safety Standards Map
Start the course today
A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 74-guide library. No credit card required.