Skip to main content
Concept guide · ISO 26262-7 · 10 chapters

Production, Operation, Service & Decommissioning

Master ISO 26262-7, the forgotten half of the safety lifecycle, from start of production through field monitoring to safe end-of-life. Build production control plans, run process FMEAs, close the field-monitoring loop, and write decommissioning instructions for high-voltage and pyrotechnic systems.

Chapters
10
Chapters
Lifecycle Phases
4
Lifecycle Phases
Normative Clauses
3
Normative Clauses
Work Products
9
Work Products
Included inExpert
Why this course · ISO 26262, Part 7, Clause 5-7

Why it pays for itself

Build a safety-grade control plan

Link every safety-related special characteristic to a process step, measurement method, frequency and reaction plan, with poka-yoke error-proofing and 100 percent end-of-line verification where the ASIL demands it.

Close the field-monitoring loop

Plan data streams, escalation thresholds and a response process before production starts, so a field safety anomaly becomes contained corrective action instead of an improvised recall.

Handle service and end-of-life safely

Keep repairs, re-flashing and OTA updates from silently defeating validated safety mechanisms, and write decommissioning instructions for high-voltage batteries and pyrotechnic devices.

After the course

What you’ll be able to do

Build a production control plan

Author a safety-grade production control plan that links every special characteristic to a process step, a measurement method, a frequency, and a reaction plan.

Trace special characteristics to ASIL

Classify safety-related special characteristics and maintain single-source traceability from the FMEA entry to the ASIL safety goal and the end-of-line test.

Run a safety-focused process FMEA

Connect manufacturing failure modes to product failures and safety goal violations, rating severity by safety classification rather than generic quality impact.

Operate a field-monitoring loop

Plan data collection, escalation thresholds, and a response process so field safety anomalies are detected and turned into containment and corrective action.

Plan safe end-of-life decommissioning

Write decommissioning instructions that discharge high-voltage batteries, handle pyrotechnic devices, and disable safety functions in a controlled sequence.

Set retention and confirmation measures

Define per-unit record content, confirmation measures for the production phase, and retention aligned to the full operational life of the vehicle.

The curriculum · 10 chapters

Chapter by chapter

  1. 01

    The Forgotten Half

    Why ISO 26262-7 matters: safety integrity is preserved or quietly eroded across production, operation, service, and decommissioning, not just at design release.

    • Four post-release lifecycle phases: production, operation, service, decommissioning
    • Real recall failure modes that Part 7 controls are designed to prevent
    • How Part 2 safety management runs in parallel with Part 7 obligations
  2. 02

    Part 7 Structure

    The scope and clause map of ISO 26262-7:2018, the design work products it consumes, and the documented outputs it requires as audit evidence.

    • Clauses 5, 6, and 7 are the only normative content clauses
    • Inputs: safety-related special characteristics, ASIL requirements, EOL instructions
    • Nine mandated work products, from the control plan to field observation instructions
  3. 03

    Production Planning

    Designing the production plan and production control plan so every safety-related special characteristic of the validated design is reproduced and verified on every unit.

    • Production control plan columns extended for safety beyond IATF 16949
    • Poka-yoke error-proofing preferred for ASIL C and D characteristics
    • VIN-linked traceability and 100% end-of-line verification strategy
  4. 04

    Process FMEA & Special Characteristics

    Using process FMEA to trace each manufacturing failure mode through the product failure to the safety goal, then anchoring it to a quantified process control.

    • Explicit linkage from DFMEA or FMEDA entries to process steps
    • Severity rated by safety classification, not generic quality impact
    • Worked rows: EPS torque sensor, AEB radar boresight, BMS shunt resistance
  5. 05

    Operation & Service

    Ensuring user instructions, maintenance, repair, and over-the-air updates do not silently defeat the safety mechanisms that were validated at design time.

    • User information must cover intended-use limits and driver actions under warnings
    • Service plans flag safety-relevant work, tooling, and post-repair verification
    • Mandatory camera recalibration after windscreen or front-sensor replacement
  6. 06

    Field Monitoring

    A planned, safety-driven process that collects field data, analyses it to detect functional safety issues, and triggers containment and corrective action.

    • Distinct from warranty or satisfaction tracking, scoped to safety goals
    • Data streams: telematics, workshop uploads, customer reports, regulatory data
    • Must be planned with thresholds and a response process before production
  7. 07

    Repair & Diagnostics

    In-service diagnostic strategy, spare-part integrity, safe workshop re-flashing, and the safety risks introduced by counterfeit or aftermarket components.

    • Repair verification restores, then re-confirms, safety integrity
    • Re-flashing must preserve validated calibrations and log software versions
    • Counterfeit and non-approved parts as a recognised field safety risk
  8. 08

    Decommissioning & EOL

    Safely disabling safety functions at end of life: high-voltage traction battery discharge, pyrotechnic device handling, and the documentation regulators expect.

    • HV traction battery discharged to a safe voltage before any disassembly
    • Pyrotechnic airbags and pretensioners handled as classified explosives
    • Controlled deactivation of safety functions versus uncontrolled removal
  9. 09

    Records & Audits

    Production records, per-unit traceability, confirmation measures during the production phase, and evidence retention aligned to the vehicle operational life.

    • Control measure reports capture date, controlled object, and result
    • Confirmation measures provide independent assurance in production
    • Retention aligned to operational life, not the warranty period
  10. 10

    Pitfalls & Best Practices

    The most common production and service phase functional safety failures, paired with the concrete practices that reliably prevent them.

    • Special characteristics tracked without traceability to an ASIL safety goal
    • Records purged at warranty end instead of operational life
    • Field monitoring improvised reactively rather than planned upfront
Diagrams & Visuals

Not just text: the visual toolkit

Post-SOP Lifecycle Timeline

The full post start-of-production timeline across production runs, 10 to 20 years of operation and service, and end-of-life, showing where each Part 7 obligation applies.

Production Control Plan Flow

How each safety-related special characteristic maps to the process step that creates it, the measurement method, the frequency, and the reaction plan.

Cpk / Ppk Process Capability

Process capability and drift against tolerance limits, illustrating why ASIL C and D characteristics need capability indices well above the minimum.

IATF 16949 to ISO 26262 Mapping

Where the automotive quality management system already covers Part 7 obligations and where ISO 26262 adds safety-specific rigour on top.

Decommissioning Checklist Tree

A branching end-of-life procedure for disabling safety functions, discharging high-voltage energy, and handling pyrotechnic devices in the correct order.

Audit Independence Matrix

Required levels of independence for confirmation measures and audits in the production phase, mapped against ASIL.

Worked Example

An ASIL B AEB Radar Module Across the Post-Release Lifecycle

Follow a single forward-radar module from the production line, through a workshop windscreen repair, into a field-monitoring signal that triggers a contained corrective action.

  • Production: boresight verified to within plus or minus 0.25 degrees azimuth on an alignment jig, and the ECU software CRC logged to the manufacturing execution system against the VIN.
  • Special characteristic: mounting angle controlled by an asymmetric bracket key (poka-yoke) backed by 100% end-of-line verification, with traceability to the FMEA item.
  • Service: after a windscreen replacement, the camera and radar pair must be recalibrated on the dynamic alignment target, a mandatory step called out in the repair procedure.
  • Field monitoring: telematics DTC snapshots reveal a cluster of unexpected AEB activations confined to one production batch.
  • Corrective action: affected units are contained through VIN-linked build records, root cause traced to a shunt-solder process drift, and a targeted service campaign is issued.
  • Records: per-unit end-of-line results are retained for the 15 year operational life rather than purged at warranty end.
Lifecycle Trace Card
EOL boresight verified to within plus or minus 0.25 degrees azimuth, CRC logged against the VIN.

Unlock the full corrective-action chain

Built for

Who this guide is for

  • Manufacturing and quality engineers who inherit safety-related special characteristics at SOP
  • Safety managers extending the safety case past design release into production and the field
  • Engineers writing service procedures, repair verification steps and user information
  • Teams standing up field monitoring, containment and corrective action processes

Frequently Asked Questions

Common questions about Production, Operation, Service & Decommissioning

ISO 26262-7 covers the post-development half of the safety lifecycle: production, operation, service and decommissioning. Its normative content sits in three clauses and requires that the safety integrity validated at design release is actually reproduced on every manufactured unit and preserved for the vehicle operational life. Concretely, that means a production plan and production control plan for safety-related special characteristics, user information and service instructions that do not defeat safety mechanisms, a planned field-monitoring process that detects functional safety issues in the fleet, and controlled end-of-life procedures. Part 7 mandates nine work products, and its records must survive audits years after start of production.
It is a product or process characteristic - a torque sensor gain, a radar boresight angle, a shunt solder joint - whose deviation in manufacturing could lead to violation of a safety goal. Each one must be traceable from its FMEA or FMEDA origin to the ASIL safety goal it protects, and controlled in the production control plan with a defined process step, measurement method, frequency and reaction plan. For ASIL C and D characteristics, error-proofing (poka-yoke) is preferred over inspection, backed by end-of-line verification and VIN-linked traceability. Tracking special characteristics without traceability to a safety goal is one of the most common Part 7 pitfalls.
Field monitoring under Part 7 is a planned, safety-driven process - distinct from warranty or customer satisfaction tracking - that collects field data, analyses it against defined thresholds, and triggers containment and corrective action when a functional safety issue emerges. The data streams include telematics and DTC snapshots, workshop uploads, customer reports and regulatory data. The critical requirement is that thresholds and the response process are defined before production starts: the guide works an example where clustered unexpected AEB activations in one production batch are traced through VIN-linked build records to a process drift and contained with a targeted service campaign.
For the operational life of the vehicle - not the warranty period. A passenger car operates for 10 to 20 years, and a field safety investigation in year 12 needs the per-unit end-of-line results, control measure reports and software version records from the original build. Purging records at warranty end is a recurring real-world failure the guide calls out explicitly: the worked example retains per-unit results for a 15-year operational life. Records must capture date, controlled object and result, with per-unit traceability, and confirmation measures during the production phase provide independent assurance that the controls keep working.
The guide has 10 chapters covering the four post-release lifecycle phases and the nine mandated work products: production planning and control plans, process FMEA and special characteristics, operation and service, field monitoring, repair and diagnostics, decommissioning, and records and audits, closing with pitfalls and best practices. Six diagrams support the chapters, and a worked example follows an ASIL B AEB radar module from the production line through a workshop repair to a field-monitoring signal and corrective action. A free account starts you off, and the Pro and Expert plans unlock more of the library.

Start the course today

A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 78-guide library. No credit card required.