Goal Structuring Notation (GSN)
Turn a pile of ISO 26262 work products into an explicit, reviewable safety argument across 12 chapters: every element shape, both relationship types, the six-step construction method, modular arguments at scale, and the review practices that survive a confirmation review.
- Chapters
- 12
- Chapters
- Core Elements
- 6
- Core Elements
- Relationship Types
- 2
- Relationship Types
- Pitfall Patterns
- 10
- Pitfall Patterns
- 01Why Safety Arguments Need Structure
- 02The Safety Case in ISO 26262
- 03The Core GSN Elements
- 04Relationships and Well-Formed Structures
- 05The Six-Step Construction Method
Why it pays for itself
Make safety arguments reviewable
Prose buries inference and coverage once an ASIL D item accumulates thousands of work products. GSN makes the claim-argument-evidence chain explicit enough for an assessor to read in minutes.
Build with the six-step method
Kelly's construction loop - state the claim, fix its context, choose a strategy, repeat, stop at evidence - turns a blank canvas into a well-formed argument with the right granularity.
Scale across organizations
Modules, away elements, and contracts let one argument span OEM, supplier, and SEooC boundaries, mapping the argument structure directly onto the DIA and distributed development.
What you’ll be able to do
Write claims that can be false
Phrase goals as propositions a reviewer can judge true or false, instead of activities or document names.
Build arguments with the six-step method
Decompose a top claim down to evidence, fixing context at each level and stopping at the right granularity.
Apply both relationship types correctly
Use SupportedBy for inference and InContextOf for scope, and keep structures well formed and legal.
Scale arguments across organizations
Split large cases into modules with away elements and contracts mapped onto OEM, supplier and SEooC boundaries.
Argue confidence, not just safety
Add assurance claim points and reason about defeaters and counter-evidence rather than trusting a clean diagram.
Pass the confirmation review
Spot the recurring fallacies, run a self-audit, and present what the assessor reads first.
Chapter by chapter
- 01
Why Safety Arguments Need Structure
ISO 26262-2 (6.4.8) requires a safety case that connects evidence to the claim of acceptable safety, and prose collapses once an ASIL D item accumulates thousands of work products.
- Claim, argument and evidence layers
- Why prose buries inference and coverage
- The Nimrod lesson and origins of GSN
- 02
The Safety Case in ISO 26262
How the safety case is compiled progressively across the lifecycle, fed by HARA safety goals and the confirmation review with independence that grows as ASIL rises.
- Safety case anatomy and lifecycle build-up
- Confirmation review per Part 2 Table 1
- Safety goals, FSC and TSC as inputs
- 03
The Core GSN Elements
Six element types form the whole vocabulary: Goal, Strategy and Solution build the argument chain while Context, Assumption and Justification attach sideways and control how it reads.
- Goals as propositions, not activities
- Strategies that name the inference
- Solutions citing real work products
- 04
Relationships and Well-Formed Structures
SupportedBy carries the inference and InContextOf scopes it, with a permitted-connections matrix and structure rules that determine whether a diagram is even legal GSN.
- SupportedBy versus InContextOf semantics
- The ten legal connections
- Common syntax errors side by side
- 05
The Six-Step Construction Method
Kelly's loop for building an argument from a blank canvas: state the claim, fix its basis with context, choose a strategy, repeat, and stop the decomposition at evidence.
- One decomposition level worked live
- Granularity: knowing when to stop
- Three disciplines the loop enforces
- 06
Worked Example: The EPS Safety Argument
SG-01 of an electric power steering item built node by node from top claim to evidence, showing which step produced which node and where SG-02 and SG-03 stay honestly undeveloped.
- Item, safety goal and safe state
- Full argument built phase by phase
- What an assessor reads in 60 seconds
- 07
Modular GSN: Arguments at Scale
Modules, away elements and contracts let one argument span OEM, supplier and SEooC boundaries, mapping argument structure onto the DIA and distributed development.
- Modules and away elements
- Contracts and public interfaces
- DIA and SEooC boundaries
- 08
Patterns and Argument Reuse
Reusable argument fragments captured with the pattern notation, the classic catalogue of patterns, and the instantiation discipline that keeps reuse from becoming copy-paste.
- Pattern notation and parameters
- A tour of the classic patterns
- Instantiation discipline and libraries
- 09
Confidence Arguments and Defeaters
A tidy diagram is not yet a trustworthy one: assurance claim points expose confidence separately from the safety argument, and defeater thinking forces engagement with counter-evidence.
- Safety versus confidence argument and ACPs
- Defeaters: rebut, undermine, undercut
- Living with counter-evidence
- 10
Reviewing GSN Arguments and Spotting Fallacies
Three review layers check syntax, semantics and sufficiency, with a field guide to the recurring fallacy classes and review formats that actually catch them.
- What a GSN review actually checks
- The fallacy field guide
- Running the review effectively
- 11
Tooling, Interchange and Alternative Notations
Where GSN sits among argument notations, how the SACM metamodel enables interchange between tools, and what keeps an argument alive and maintained between releases.
- The notation landscape
- SACM as one metamodel underneath
- Tool categories and keeping arguments alive
- 12
Pitfalls, Checklist and Assessment Readiness
The ten failure patterns reviewers see most often, what the assessor reads first, and a self-audit to run before the confirmation review.
- The pitfall field guide
- What the assessor reads first
- A pre-review self-audit
Not just text: the visual toolkit
Safety Case Anatomy
The three layers of claims, argument and evidence, fed by HARA safety goals and grounded in lifecycle work products.
Element Gallery
The six core shapes (Goal, Strategy, Solution, Context, Assumption, Justification) with phrasing rules and the classic mistake for each.
EPS Argument Structure
SG-01 decomposed from top claim to evidence, with SupportedBy and InContextOf links built phase by phase.
Permitted-Connections Matrix
Which elements may legally connect to which, separating load-bearing support from contextual scoping.
Modular Contracts
Modules, away goals and away contexts spanning OEM, supplier and SEooC boundaries across the DIA.
Safe State and Item Context
The EPS item, its safety goal and the safe state that scopes the worked argument.
An EPS Safety Argument from Goal to Evidence
Build the safety argument for SG-01 (unintended self-steering is prevented) of an electric power steering item, node by node, using the six-step method.
- State the top goal: unintended self-steering of the EPS item is prevented
- Scope it with context: the item boundary, the safe state, and the confirmed HARA
- Choose a strategy: argue over each fault class that could cause self-steering
- Decompose into sub-goals for detection, reaction and the assist limitation
- Ground the leaves in evidence: FMEDA results, fault injection reports, verification reports
- Leave SG-02 and SG-03 visibly undeveloped rather than faking closure
Unlock the full node-by-node build
Who this guide is for
- Safety managers compiling a safety case toward a confirmation review
- Engineers who must turn a pile of work products into an explicit argument
- OEM and supplier teams splitting a safety case across a DIA boundary
- Reviewers and assessors judging whether an argument actually supports its claim
Frequently Asked Questions
Common questions about Goal Structuring Notation (GSN)
Start the course today
A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 77-guide library. No credit card required.