Proven in Use
Most reuse decisions turn on one question: can field experience stand in for development rigour? This concept walks ISO 26262-8 Clause 14 end to end, showing how the Poisson single-sided 70% bound turns vehicle-hours into a demonstrated failure rate, and why the numbers wall closes the argument far more often than it opens it.
- Chapters
- 11
- Chapters
- Reuse Routes
- 8
- Reuse Routes
- Confidence Bound
- 70%
- Confidence Bound
- Argument Killers
- 4
- Argument Killers
- 01The Reuse Problem & Landscape
- 02The Candidate
- 03Change & Environment
- 04Field Data
- 05The Statistics
Why it pays for itself
Know when the argument closes
The per-ASIL rate targets and fleet arithmetic decide up front whether your field data can ever reach the bar - before you spend months assembling an argument the numbers wall will kill.
Run the Poisson math yourself
Convert vehicle-hours and attributed incidents into a demonstrated failure rate with the single-sided 70% confidence bound, including how each additional incident raises the required evidence.
Screen all eight reuse routes
Clause 14 is one route among eight spanning process, product, and history evidence. A four-question triage tells you which route fits your candidate before you commit to any of them.
What you’ll be able to do
Qualify a candidate correctly
Draw the candidate boundary and state the function and conditions you are actually allowed to claim credit for.
Freeze the service-history clock
Identify which revisions and updates reset the clock so only genuinely unchanged field hours count.
Reconstruct field data conservatively
Correct exposure and incident counts for a leaky reporting chain without over-claiming credit.
Run the Poisson 70% bound
Convert observed vehicle-hours and incidents into a demonstrated failure rate using the single-sided chi-squared bound.
Test against per-ASIL targets
Compare your bound to the ASIL rate target and decide whether decomposition or stated margin can close the gap.
Assemble an assessor-proof case
Build the work products and safety case that survive the assessor's questions and the four common killers.
Chapter by chapter
- 01
The Reuse Problem & Landscape
Why ISO 26262 accepts field history as safety evidence, why that offer is narrower than it sounds, and the eight reuse routes you should screen before betting on Clause 14.
- Two ways to earn the same confidence: development rigour vs field experience
- What a proven-in-use argument is not
- A four-question triage across process, product and history evidence
- 02
The Candidate
Pinning down exactly what you are allowed to argue about: the boundary, the safety-relevant function, and the assumptions that define the candidate for qualification.
- Drawing the candidate boundary so the argument stays honest
- Function and operating conditions you are claiming credit for
- Where an over-broad candidate quietly breaks the case
- 03
Change & Environment
Why every hardware revision or software update resets the service-history clock, so only the latest unchanged segment of field time actually counts toward your evidence.
- Service history accumulates, then resets on a revision or update
- Only the latest frozen configuration segment counts
- Environmental and duty-cycle shifts that invalidate carried-over hours
- 04
Field Data
Reconstructing exposure and incidents through a leaky pipeline that runs from a field failure through symptom, workshop visit, diagnosis and report before it ever reaches your database.
- Leakage at every stage of the reporting chain
- Distinguishing exposure hours from attributed incidents
- Conservative treatment of unknown and unreported events
- 05
The Statistics
How many vehicle-hours buy how much confidence, using the Poisson model and the single-sided 70% bound to convert observed incidents into a demonstrated failure rate.
- Zero-incident case and the required hours T >= k / lambda
- The evidence price of each additional attributed incident
- Multiplier k rising from 1.2 at zero incidents to 7.0 at five
- 06
Targets & the Numbers Wall
The per-ASIL rate targets and the fleet arithmetic that decides whether your data can ever reach them, at roughly 400 field hours per vehicle-year.
- Incident-rate targets per ASIL at the 70% one-sided bound
- Why ASIL D at item level is close to mythical
- Decomposition and stated margin as the practical workarounds
- 07
A Worked Example
One argument end to end for a hydraulic brake pressure sensor module at hardware revision B, from screening through the conservative chi-squared math to the verdict.
- T = 8.7 x 10^8 h, r = 5, chi-squared(0.70, 12) = 14.01
- Testing against the ASIL B target of < 1.0 x 10^-8 / h
- Why each quarterly OTA version runs its own separate clock
- 08
When It Actually Works
The honest success profile of a winning argument, the four killers that sink most attempts, and the hybrid forms that quietly dominate real practice.
- The fingerprint of a candidate that genuinely qualifies
- The four killers: change, exposure, ASIL target and data quality
- Hybrid forms: confidence backstops and scoped partial credit
- 09
Pre-Existing Software & ISO/PAS 8926
Why Clause 14 structurally fails for code, and the 2024 ISO/PAS 8926 route built to replace it, with its five-step evaluation flow.
- Three structural mismatches: software never sits still
- Systematic faults that hide from even huge fleets
- Clause 14 versus ISO/PAS 8926, side by side
- 10
Building the Argument
Assembling the work products and safety case, anticipating the assessor's questions, and avoiding the pitfalls that sink otherwise sound arguments.
- The fielded candidate is the shipped candidate, doing the same job
- Population, exposure and observation chain sound and conservative
- The bound beats the ASIL target with stated margin
Not just text: the visual toolkit
Service-History Reset Timeline
Shows field time accumulating and then being reset by a hardware revision and a software update, so only the latest configuration segment counts.
Field-Data Leakage Pipeline
Traces a failure from the field through symptom, workshop visit, diagnosis and report to your database, losing evidence at every stage.
Confidence Multiplier Curve
Plots the multiplier k against observed incidents, rising from 1.2 at zero incidents to 7.0 at five, driving the required hours.
Rate Target vs Fleet-Size Wall
A log-log view of observation years needed against fleet size that exposes where ASIL targets become unreachable.
Reuse Route Decision Map
Positions the eight reuse routes across the process, product and history evidence spectrum before you commit to Clause 14.
ISO/PAS 8926 Evaluation Flow
Walks the five-step evaluation flow for pre-existing software against the Clause 14 argument it replaces.
Qualifying a Carryover Brake Pressure Sensor via Field History
A hydraulic brake pressure sensor module at hardware revision B is carried over into a new program and put through a full proven-in-use argument against an ASIL B target of < 1.0 x 10^-8 / h. With T = 8.7 x 10^8 relevant vehicle-hours and r = 5 attributed incidents, the conservative chi-squared(0.70, 12) = 14.01 math decides whether the field data actually clears the wall.
- Candidate frozen at hardware revision B, boundary and function pinned before any hours are counted
- Service history reset on the last revision, leaving 8.7 x 10^8 h of relevant exposure
- Five attributed incidents reconstructed through the field-reporting chain
- Poisson single-sided 70% bound computed via chi-squared(0.70, 12) = 14.01
- Resulting rate compared against the ASIL B target of < 1.0 x 10^-8 / h
- Each quarterly OTA software version runs its own separate clock, not a shared pool
Unlock the full worksheet with the chi-squared bound, margin and pass/fail verdict
Who this guide is for
- Engineers carrying over a sensor, module, or ECU into a new vehicle program
- Safety managers weighing field-history qualification against re-development cost
- Reliability engineers sitting on warranty and field data they want to use as evidence
- Suppliers preparing a proven-in-use case an OEM assessor will interrogate
Frequently Asked Questions
Common questions about Proven in Use
Start the course today
A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 77-guide library. No credit card required.