Functional Safety in Railway
The CENELEC framework read by an automotive engineer: from the physics of the wheel-rail contact through THR, SIL, RAMS, fail-safe construction and ETCS to the authorization decision, and an honest comparison with ISO 26262.
- Chapters
- 15
- Chapters
- RAMS lifecycle phases
- 12
- RAMS lifecycle phases
- EN 50159 message threats
- 7
- EN 50159 message threats
- Safety case parts
- 6
- Safety case parts
- 01Why a Train Cannot Swerve
- 02The Rulebook: CENELEC and the Railway Standards
- 03The Risk Model: THR and Risk Acceptance
- 04From Hazard to SIL
- 05The RAMS Lifecycle
Why it pays for itself
A second safety grammar, learned properly
THR, TFFR, SIL, RAMS, wrong-side failure, SRAC and authorization for placing in service explained from the physics up, so an automotive engineer can read a railway safety case and hold a conversation without translating badly.
The comparison done honestly
Three full chapters compare risk models, metrics and mechanisms, and process and ecosystem. They show exactly why the tidy ASIL to SIL mapping table fails as an engineering claim, and what an honest cross-domain reuse argument looks like instead.
Ideas worth importing
Explicit risk acceptance, exported assumptions tracked as numbered obligations with owners, and safety cases written for a competent independent reader are railway habits that improve automotive work, and the guide names them alongside what railway should take back.
What you’ll be able to do
Read the CENELEC Family Correctly
Know which standard owns which question, which layer is law and which is engineering practice, and why the edition cited in a contract matters as much as the number.
Follow a Risk Target from Hazard to Function
Trace risk acceptance through barrier crediting to a tolerable hazard rate, apportion it into per-function targets, and read the resulting SIL for what it does and does not buy.
Explain Fail-Safe Construction and Its Price
Distinguish wrong-side from right-side failures, compare inherent, reactive and composite fail-safety, and argue the exposure window between fault and enforced restrictive state.
Handle Safety Data Over Untrusted Networks
Apply the grey channel assumption, map each EN 50159 message threat to the defenses that catch it, and size a safety code against message traffic and the allocated failure budget.
Navigate the Safety Case and Approval Chain
Structure evidence into the six EN 50129 parts, track safety-related application conditions across generic and specific cases, and know which body decides what and when.
Compare Railway and Automotive Without Fooling Yourself
Explain why SIL and ASIL classify different objects, what is genuinely comparable across the aisle, and how a cross-domain reuse argument is rebuilt against the receiving standard.
Chapter by chapter
- 01
Why a Train Cannot Swerve
The two freedoms a train does not have, the adhesion and energy arithmetic behind them, and the consequence that shaped everything since 1889: movement by authority granted by the infrastructure, not by the driver.
- Adhesion and kinetic energy
- The block principle
- Precursors instead of accidents
- 02
The Rulebook: CENELEC and the Railway Standards
Why railway adapted IEC 61508 into its own family, what EN 50126, EN 50129, EN 50716, EN 50159 and EN 50155 each govern, and how EU law, CENELEC standards and the ETCS subsets stack into three layers.
- Five core standards, one paragraph each
- The 50128 and 50657 merge into 50716
- Legal layer versus voluntary layer
- 03
The Risk Model: THR and Risk Acceptance
Individual and collective risk, the precursor discipline, the three national traditions ALARP, GAME and MEM, the CSM-RA acceptance routes, and the harmonised design targets introduced in 2015.
- Three acceptance principles compared
- CSM-RA and significant change
- Risk matrices used honestly
- 04
From Hazard to SIL
The chain from hazard through credited barriers to a tolerable hazard rate, the apportionment of THR into per-function TFFR, the EN 50129 SIL bands, and what Basic Integrity below SIL 1 actually means.
- Event-tree barrier crediting
- THR to TFFR apportionment
- Why there is no SIL 5
- 05
The RAMS Lifecycle
Why availability lives inside the safety standard, the twelve phases of EN 50126-1 drawn as stations rather than a V, the hazard log as the living spine, and the thirty-year service reality behind every decision.
- Excessive fail-safety creates hazard
- The hazard log and its two exit doors
- MTBF and MTTR as the two levers
- 06
Fail-Safe by Construction
Wrong-side and right-side failures, inherent fail-safety through the closed-circuit principle and the automatic continuous brake, reactive and composite patterns, and where standstill is not simply safe.
- Failure direction as first question
- Detection and negation window
- Fault exclusions carry obligations
- 07
Hardware: Proving the Numbers
How a signalling channel earns its failure rate: the evidence stack behind a quantitative claim, the three vital computing shapes, the scaling that makes comparison pay, and the independence it rents.
- 2oo2, 2oo3 and coded mono processor
- What the squared term assumes
- Proof tests inside the quantitative case
- 08
Software Under EN 50716
Software integrity handled through process rather than rate: technique tables graded by integrity level, named roles with graded independence, tool classes T1 to T3, and where formal methods genuinely pay off.
- Technique tables by SIL band
- Roles, independence and the compiler question
- Formally validated interlocking data
- 09
Safe Communication: EN 50159
Treating the transmission system as a grey channel with no credited safety properties, the seven named message threats, the defenses that ride in the message, and the residual error budget against the TFFR.
- Three transmission system categories
- Seven threats and their defenses
- Sizing safety codes against traffic
- 10
Train Control in Practice
The interlocking as a machine that proves propositions before a signal clears, track circuits versus axle counters, fixed and moving block headway, the ETCS levels, and braking curve supervision onboard.
- Route setting, flank protection, approach locking
- ETCS Level 1 to Level 3 concepts
- Level crossings and SPAD defense in depth
- 11
The Safety Case and Approval
The six mandatory parts of an EN 50129 safety case, the generic to specific reuse machine held together by safety-related application conditions, the assurance roles, and what an authorization actually covers.
- Six parts, one dependency chain
- SRACs as exported obligations
- ISA, AsBo, NoBo, DeBo and the authority
- 12
Railway vs Automotive: Risk Models
THR and SIL held against HARA and ASIL: what each grammar classifies, where probability lives, why controllability has no direct railway counterpart, and the three reasons the equals sign between them fails.
- One scenario, two derivations
- Individual versus collective risk
- How honest cross-domain reuse is argued
- 13
Railway vs Automotive: Metrics and Mechanisms
What each domain counts and why: TFFR and the single-fault principle against SPFM, LFM and PMHF, the two deadline clocks, and how maintenance credit and safe states diverge between the two ecosystems.
- Both ladders on one log axis, with scope tags
- FTTI versus detection plus negation
- Number literacy in FIT
- 14
Railway vs Automotive: Process and Ecosystem
Who is allowed to say the work is good, two safety case cultures, why the software cultures diverged for economic and mathematical reasons, and two supply ecosystems compared on one timeline.
- External chain versus internal confirmation measures
- Per-change ceremony versus audited update process
- SRACs versus SEooC assumptions and the DIA
- 15
The One-Page Story
One worked section-clear function traced from hazard through THR, TFFR, architecture, software, telegrams, safety case and authorization, plus a reference card, the comparison table and twelve terms to keep.
- Eleven stations, one thread
- Six self-test questions
- What each side should steal
Who this guide is for
- Automotive safety engineers meeting CENELEC evidence in a cross-domain project
- Suppliers offering a SIL-rated platform into an ASIL item, or the reverse
- Engineers moving between rail and automotive who need the vocabulary to transfer cleanly
- Safety managers evaluating claims that a certificate in one domain satisfies the other
- Anyone building an argument for fail-operational behavior who wants proven redundancy patterns
- Assessors and trainers who need the two frameworks contrasted without hand-waving
Frequently Asked Questions
Common questions about Functional Safety in Railway
Start the course today
A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 77-guide library. No credit card required.