AV Safety: ISO 26262 + SotIF + ML in Practice
An end-to-end handbook for autonomous-vehicle safety that integrates ISO 26262, ISO 21448 (SotIF), ISO/PAS 8800 and UL 4600. ODD, fail-operational architectures, scenario-based V&V, ML safety, and a joint safety case applied to AEB, lane keeping and SAE L3/L4 highway pilot.
- Chapters
- 12
- Chapters
- Diagrams & Tables
- 45+
- Diagrams & Tables
- Standards Integrated
- 4
- Standards Integrated
- Worked Examples
- AEB / L3
- Worked Examples
- 01The AV/ML Safety Gap
- 02AV Levels, ODD & MRC
- 03SotIF (ISO 21448) in Practice
- 04Insufficiency vs Random Fault
- 05ML Component Safety (ISO/PAS 8800)
Why it pays for itself
Integrate four standards into one program
ISO 26262, ISO 21448 SOTIF, ISO/PAS 8800, and UL 4600 each cover a different slice of AV risk. Learn what each one owns, where they hand off, and how to run them as one coherent safety program.
Engineer beyond fail-safe
A Level 3 system cannot simply shut off. Study fail-operational sensor and compute architectures, ODD specification, and minimal risk condition design that keep the vehicle safe when components fail mid-drive.
Make ML safety concrete
Move past "neural networks are black boxes" to the actual engineering: perception pipeline safety, insufficiency versus random fault thinking, scenario-based V&V, and quantitative acceptance criteria that survive review.
What you’ll be able to do
Route Hazards to the Right Standard
Apply the handoff rule to assign every hazardous event to ISO 26262, ISO 21448 or ISO/PAS 8800 without leaving structural gaps in the safety argument.
Specify ODD and MRC for an L3/L4 Function
Build an ODD using BSI PAS 1883 or ISO 34503 attributes, design runtime monitors that detect violations, and define MRC reachable within FTTI.
Run an Integrated HARA + SotIF + TARA
Conduct hazard analysis on the same functional architecture across safety, SotIF and cybersecurity with a single three-axis matrix per hazardous event.
Engineer ML Safety per ISO/PAS 8800
Treat ML weights as versioned artifacts, design the six-step data lifecycle, and add runtime OoD detectors plus cross-modal monitors as functional modifications.
Design Fail-Operational Architectures
Select among single-path, dual-channel, 1oo2, 2oo3, DoerChecker and 3-path patterns with CCF budgeting and explicit MRC entry timing.
Write a UL 4600 Joint Safety Case
Decompose the root "acceptably safe" claim into hazards-identified, hazards-mitigated, residual-risk and lifecycle sub-claims using GSN with evidence per standard.
Chapter by chapter
- 01
The AV/ML Safety Gap
Why ISO 26262 alone cannot cover autonomous and AI-driven systems.
- Three insufficiency classes
- Three-standard landscape
- Sequential handoff rule
- 02
AV Levels, ODD & MRC
SAE J3016 levels, ODD attribute recipes and Minimal Risk Condition as the DDT-fallback target.
- SAE J3016 responsibility
- ODD attribute recipe
- MRC and DDT-fallback
- 03
SotIF (ISO 21448) in Practice
The 4-area model, triggering-condition catalogs and the cause-effect chain.
- 4-area SotIF model
- TC catalog by subsystem
- Cause-effect chain
- 04
Insufficiency vs Random Fault
The handoff rule that routes hazards between ISO 26262, ISO 21448 and ISO/PAS 8800.
- Three-branch handoff
- 8-dimension comparison
- Same HW, two paths
- 05
ML Component Safety (ISO/PAS 8800)
ML weights as versioned artifacts, ten AI properties and the six-step data lifecycle.
- ML weights as artifacts
- 10 AI safety properties
- 6-step data lifecycle
- 06
Perception Pipeline Safety
Sensor-set design, fusion architectures and eight runtime perception monitors.
- Sensor-set trade-offs
- Fusion architectures
- 8 runtime monitors
- 07
Fail-Operational Architecture
Fail-passive, fail-silent and fail-operational patterns from single-path to 3-path fall-over.
- Fail-operational vocabulary
- 6 architectural patterns
- 3-path with CCF budget
- 08
Scenario-Based V&V
Logical vs concrete scenarios, OpenSCENARIO 2.0 and eight V&V methods.
- Logical vs concrete
- OpenSCENARIO 2.0
- 8 V&V methods
- 09
Safety Case (UL 4600)
Goal-based safety case with GSN notation and a four-sub-claim decomposition.
- UL 4600 vs process standards
- GSN six node types
- Top-level claim tree
- 10
Cybersecurity (ISO 21434)
TARA, Cybersecurity Assurance Level, and a three-axis hazard matrix with HARA and SotIF.
- TARA + CAL framework
- 3-axis hazard matrix
- AV attack classes
- 11
Process Integration
Integrated V-model, a 12-item safety plan and release gates G0-G7.
- Integrated V-model
- 12-item safety plan
- 8 roles, gates G0-G7
- 12
Real-World Pitfalls
Public-incident anti-patterns: disabled safety nets, handover blind-spots, dataset/ODD mismatch.
- Public-incident catalog
- Anti-pattern playbook
- Audit checklist
Not just text: the visual toolkit
Three-Standard Landscape Map
Reference cards for ISO 26262, ISO 21448, ISO/PAS 8800 and UL 4600 with scope, trigger criteria, and the decision rule that routes a hazard to the right standard.
SotIF 4-Area Model & Cause-Effect Chain
The 2x2 known/unknown by safe/unsafe matrix with each area's goal, plus the TC -> functional insufficiency -> output insufficiency -> hazardous behaviour flow.
AV Levels, ODD & MRC Diagram
SAE J3016 L0-L5 with DDT, monitoring and fallback responsibility, the six ODD attribute categories, and runtime monitors that trigger MRC entry.
Fusion Architectures & Runtime Monitors
Low/mid/high-level fusion topology cards with ASIL reachability, plus eight runtime monitors (freshness, cross-modal, temporal, calibration, occlusion, weather, ODD attribute, free-space).
3-Path Fail-Operational Architecture
Nominal, redundant and limp-home paths with independent compute, sensor and power domains, CCF matrix, watchdog cross-checks, and FTTI/EOTTI timing analysis for MRC reachability.
OpenSCENARIO 2.0 Cut-In Scenario
Annotated DSL fragment for a parameterized cut-in (rel_speed, TTC, gap_rear), V&V method comparison across SiL, HiL, track and shadow mode with realism-vs-scalability trade-offs.
L3 Highway Pilot AEB Across All Four Standards
An SAE L3 highway pilot AEB carried from ODD specification through fail-operational architecture, scenario V&V and the joint UL 4600 safety case.
- ODD specification with HD-map geofence
- 3-path fail-operational sensor and compute architecture
- Scenario V&V across SiL, closed course and field trials
- Quantitative acceptance criteria with MRC reachability
- UL 4600 safety case mapped to all four standards
Unlock the full L3 case study
Who this guide is for
- Functional safety engineers moving from conventional ECUs to ADAS and AV programs
- AV and ML engineers who need the safety-standards landscape mapped onto their stack
- Safety architects designing fail-operational architectures for L3/L4 functions
- Teams assembling a joint safety case across 26262, SOTIF, and ML evidence
Frequently Asked Questions
Common questions about AV Safety: ISO 26262 + SotIF + ML in Practice
Start the course today
A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 74-guide library. No credit card required.