Production, Operation, Service & Decommissioning
Master ISO 26262-7, the forgotten half of the safety lifecycle, from start of production through field monitoring to safe end-of-life. Build production control plans, run process FMEAs, close the field-monitoring loop, and write decommissioning instructions for high-voltage and pyrotechnic systems.
- Chapters
- 10
- Chapters
- Lifecycle Phases
- 4
- Lifecycle Phases
- Normative Clauses
- 3
- Normative Clauses
- Work Products
- 9
- Work Products
- 01The Forgotten Half
- 02Part 7 Structure
- 03Production Planning
- 04Process FMEA & Special Characteristics
- 05Operation & Service
Why it pays for itself
Build a safety-grade control plan
Link every safety-related special characteristic to a process step, measurement method, frequency and reaction plan, with poka-yoke error-proofing and 100 percent end-of-line verification where the ASIL demands it.
Close the field-monitoring loop
Plan data streams, escalation thresholds and a response process before production starts, so a field safety anomaly becomes contained corrective action instead of an improvised recall.
Handle service and end-of-life safely
Keep repairs, re-flashing and OTA updates from silently defeating validated safety mechanisms, and write decommissioning instructions for high-voltage batteries and pyrotechnic devices.
What you’ll be able to do
Build a production control plan
Author a safety-grade production control plan that links every special characteristic to a process step, a measurement method, a frequency, and a reaction plan.
Trace special characteristics to ASIL
Classify safety-related special characteristics and maintain single-source traceability from the FMEA entry to the ASIL safety goal and the end-of-line test.
Run a safety-focused process FMEA
Connect manufacturing failure modes to product failures and safety goal violations, rating severity by safety classification rather than generic quality impact.
Operate a field-monitoring loop
Plan data collection, escalation thresholds, and a response process so field safety anomalies are detected and turned into containment and corrective action.
Plan safe end-of-life decommissioning
Write decommissioning instructions that discharge high-voltage batteries, handle pyrotechnic devices, and disable safety functions in a controlled sequence.
Set retention and confirmation measures
Define per-unit record content, confirmation measures for the production phase, and retention aligned to the full operational life of the vehicle.
Chapter by chapter
- 01
The Forgotten Half
Why ISO 26262-7 matters: safety integrity is preserved or quietly eroded across production, operation, service, and decommissioning, not just at design release.
- Four post-release lifecycle phases: production, operation, service, decommissioning
- Real recall failure modes that Part 7 controls are designed to prevent
- How Part 2 safety management runs in parallel with Part 7 obligations
- 02
Part 7 Structure
The scope and clause map of ISO 26262-7:2018, the design work products it consumes, and the documented outputs it requires as audit evidence.
- Clauses 5, 6, and 7 are the only normative content clauses
- Inputs: safety-related special characteristics, ASIL requirements, EOL instructions
- Nine mandated work products, from the control plan to field observation instructions
- 03
Production Planning
Designing the production plan and production control plan so every safety-related special characteristic of the validated design is reproduced and verified on every unit.
- Production control plan columns extended for safety beyond IATF 16949
- Poka-yoke error-proofing preferred for ASIL C and D characteristics
- VIN-linked traceability and 100% end-of-line verification strategy
- 04
Process FMEA & Special Characteristics
Using process FMEA to trace each manufacturing failure mode through the product failure to the safety goal, then anchoring it to a quantified process control.
- Explicit linkage from DFMEA or FMEDA entries to process steps
- Severity rated by safety classification, not generic quality impact
- Worked rows: EPS torque sensor, AEB radar boresight, BMS shunt resistance
- 05
Operation & Service
Ensuring user instructions, maintenance, repair, and over-the-air updates do not silently defeat the safety mechanisms that were validated at design time.
- User information must cover intended-use limits and driver actions under warnings
- Service plans flag safety-relevant work, tooling, and post-repair verification
- Mandatory camera recalibration after windscreen or front-sensor replacement
- 06
Field Monitoring
A planned, safety-driven process that collects field data, analyses it to detect functional safety issues, and triggers containment and corrective action.
- Distinct from warranty or satisfaction tracking, scoped to safety goals
- Data streams: telematics, workshop uploads, customer reports, regulatory data
- Must be planned with thresholds and a response process before production
- 07
Repair & Diagnostics
In-service diagnostic strategy, spare-part integrity, safe workshop re-flashing, and the safety risks introduced by counterfeit or aftermarket components.
- Repair verification restores, then re-confirms, safety integrity
- Re-flashing must preserve validated calibrations and log software versions
- Counterfeit and non-approved parts as a recognised field safety risk
- 08
Decommissioning & EOL
Safely disabling safety functions at end of life: high-voltage traction battery discharge, pyrotechnic device handling, and the documentation regulators expect.
- HV traction battery discharged to a safe voltage before any disassembly
- Pyrotechnic airbags and pretensioners handled as classified explosives
- Controlled deactivation of safety functions versus uncontrolled removal
- 09
Records & Audits
Production records, per-unit traceability, confirmation measures during the production phase, and evidence retention aligned to the vehicle operational life.
- Control measure reports capture date, controlled object, and result
- Confirmation measures provide independent assurance in production
- Retention aligned to operational life, not the warranty period
- 10
Pitfalls & Best Practices
The most common production and service phase functional safety failures, paired with the concrete practices that reliably prevent them.
- Special characteristics tracked without traceability to an ASIL safety goal
- Records purged at warranty end instead of operational life
- Field monitoring improvised reactively rather than planned upfront
Not just text: the visual toolkit
Post-SOP Lifecycle Timeline
The full post start-of-production timeline across production runs, 10 to 20 years of operation and service, and end-of-life, showing where each Part 7 obligation applies.
Production Control Plan Flow
How each safety-related special characteristic maps to the process step that creates it, the measurement method, the frequency, and the reaction plan.
Cpk / Ppk Process Capability
Process capability and drift against tolerance limits, illustrating why ASIL C and D characteristics need capability indices well above the minimum.
IATF 16949 to ISO 26262 Mapping
Where the automotive quality management system already covers Part 7 obligations and where ISO 26262 adds safety-specific rigour on top.
Decommissioning Checklist Tree
A branching end-of-life procedure for disabling safety functions, discharging high-voltage energy, and handling pyrotechnic devices in the correct order.
Audit Independence Matrix
Required levels of independence for confirmation measures and audits in the production phase, mapped against ASIL.
An ASIL B AEB Radar Module Across the Post-Release Lifecycle
Follow a single forward-radar module from the production line, through a workshop windscreen repair, into a field-monitoring signal that triggers a contained corrective action.
- Production: boresight verified to within plus or minus 0.25 degrees azimuth on an alignment jig, and the ECU software CRC logged to the manufacturing execution system against the VIN.
- Special characteristic: mounting angle controlled by an asymmetric bracket key (poka-yoke) backed by 100% end-of-line verification, with traceability to the FMEA item.
- Service: after a windscreen replacement, the camera and radar pair must be recalibrated on the dynamic alignment target, a mandatory step called out in the repair procedure.
- Field monitoring: telematics DTC snapshots reveal a cluster of unexpected AEB activations confined to one production batch.
- Corrective action: affected units are contained through VIN-linked build records, root cause traced to a shunt-solder process drift, and a targeted service campaign is issued.
- Records: per-unit end-of-line results are retained for the 15 year operational life rather than purged at warranty end.
Unlock the full corrective-action chain
Who this guide is for
- Manufacturing and quality engineers who inherit safety-related special characteristics at SOP
- Safety managers extending the safety case past design release into production and the field
- Engineers writing service procedures, repair verification steps and user information
- Teams standing up field monitoring, containment and corrective action processes
Frequently Asked Questions
Common questions about Production, Operation, Service & Decommissioning
Start the course today
A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 77-guide library. No credit card required.