SotIF for the Functional Safety Engineer
A FuSi-engineer handbook for extending HARA, FSC, TSC, FMEDA and the safety case into ISO 21448 (SotIF), ISO/PAS 8800 and ISO/IEC TR 5469. Triggering conditions, acceptance criteria, statistical validation, ML-aware FuSi and field monitoring with a continuous AEB worked example.
- Chapters
- 12
- Chapters
- Diagrams & Tables
- 50+
- Diagrams & Tables
- Continuous Example
- AEB
- Continuous Example
- Standards Bridged
- 3
- Standards Bridged
- 01Why FuSi Engineers Need SotIF
- 02ISO 21448:2022 Clause-by-Clause
- 03From Faults to Functional Insufficiencies
- 04Fault vs Insufficiency Decision Tree
- 05Extending HARA with Triggering Conditions
Why it pays for itself
Route every issue correctly
Apply the three-question fault-versus-insufficiency triage to send each safety issue to ISO 26262, ISO 21448 or ISO/PAS 8800 with defensible reasoning, practiced on ten worked scenarios.
Extend your HARA, not replace it
Add SOTIF columns to the HARA you already have: triggering-condition catalogs built with HAZOP guide-words, insufficiency classification, and acceptance targets decomposed per hazardous event.
Argue validation statistically
Derive quantitative acceptance targets from an acceptance philosophy and baseline data, structure Area 2 and Area 3 arguments, and apply the zero-event stopping rule for validation mileage.
What you’ll be able to do
Route Issues with the Decision Tree
Apply the three-question fault vs insufficiency triage to classify every safety issue to ISO 26262, ISO 21448 or ISO/PAS 8800 with defensible reasoning.
Extend HARA with Triggering Conditions
Add SotIF columns to your existing HARA, populate the TC catalog via HAZOP and inductive analysis, and decompose acceptance targets per hazardous event.
Derive SotIF Acceptance Targets
Select an acceptance philosophy (GAMAB, MEM, ALARP, PRB), apply the three-factor risk decomposition, and derive quantitative targets from NHTSA-style baselines.
Specify Functional Modifications
Classify countermeasures into the five SotIF response categories and write a driving policy with traceable rules linked to triggering conditions.
Plan SotIF Verification & Validation
Combine the 5-level pipeline (BV/APV/VIV/TTV/ORV) with fault-injection, TC activation and OoD probing, and structure Area 2 + Area 3 acceptance arguments.
Build a Joint Safety Case & Monitor in the Field
Author one GSN tree covering 26262, 21448 and 8800, run release defensibility checks, and operate Clause 13 field monitoring with re-evaluation SLAs.
Chapter by chapter
- 01
Why FuSi Engineers Need SotIF
The scope gap between ISO 26262 faults and ISO 21448 functional insufficiencies.
- Faults vs insufficiencies
- Hazard routing rules
- Domain example catalog
- 02
ISO 21448:2022 Clause-by-Clause
Lifecycle mapping with V-model alignment and joint vs separate work products.
- 9-clause SotIF lifecycle
- V-model parallel
- 2019 to 2022 deltas
- 03
From Faults to Functional Insufficiencies
Eighteen SotIF terms in six families, mapped to their ISO 26262 equivalents.
- 18-term vocabulary
- 26262 equivalents
- Misclassification traps
- 04
Fault vs Insufficiency Decision Tree
Three-question triage that routes every issue to 26262, SotIF or SotIF + 8800.
- Three-question triage
- 10 worked scenarios
- Verdict by colour
- 05
Extending HARA with Triggering Conditions
HARA extended with SotIF columns, HAZOP guide-words and VLSS tiering.
- HARA + SotIF columns
- HAZOP guide-words
- VLSS tiering
- 06
SotIF Risk Model & Targets
Acceptance philosophies, the three-factor risk decomposition and NHTSA-baseline targets.
- 4 acceptance philosophies
- 3-factor decomposition
- NHTSA baseline
- 07
Functional Modifications as Safety Mechanisms
Five SotIF response categories, driving policy and sensor-fusion performance budgets.
- 5 modification categories
- Driving policy spec
- Fusion budgets
- 08
Verification with Triggering Conditions
Five-level BV/APV/VIV/TTV/ORV pipeline and FMEDA, FTA, STPA repurposed for SotIF.
- 5-level pipeline
- FMEDA TC columns
- FTA-for-SotIF tree
- 09
Validation: Statistical Acceptance
Area 2 vs Area 3, NHTSA severity baselines and the zero-event Poisson stopping rule.
- Area 2 vs Area 3
- NHTSA severity buckets
- Zero-event Poisson rule
- 10
ML-Aware FuSi (8800 & TR 5469)
Responsibility split across 26262, 21448 and 8800 with KPI sufficiency rules.
- Three-standard ML matrix
- KPI sufficiency rule
- 7-phase data lifecycle
- 11
Joint 26262 + 21448 + 8800 Safety Case
One GSN tree, five defensibility principles and UL 4600 integration.
- Single GSN argument
- 5 defensibility principles
- UL 4600 integration
- 12
Field Monitoring & Continuous Safety
Clause 13 observation channels, re-evaluation SLAs and OTA safety playbooks.
- 6 observation channels
- Re-evaluation SLAs
- OTA safety playbook
Not just text: the visual toolkit
Fault vs Insufficiency Decision Tree
Three-question triage (E/E deviation, performance vs specification, ML involved) with verdict colour-coding for 26262, SotIF, SotIF+8800 and cybersecurity, plus 10 worked scenarios.
HARA + SotIF Extension Worksheet
AEB HARA base table extended with triggering conditions, FI classification, P_E|HB / P_C|E / P_S|C factors, VLSS tier and acceptance target, plus a HAZOP guide-word workbook.
SotIF Risk-Decomposition Formula
P_H = P_E|HB x P_C|E x P_S|C with parameter definitions, plus the four-step AEB target derivation from NHTSA GES baseline through functional-modification coverage.
5-Level Verification Pipeline
BV, APV, VIV, TTV, ORV cards showing scope, infrastructure, pros, cons, and 26262 analog, with a combined fault-injection + TC activation + OoD probing test plan example.
ML Responsibility Matrix
Twelve-row matrix splitting KPI definition, KPI achievement, dataset bias, OoD, model calibration and drift across ISO 26262, ISO 21448 and ISO/PAS 8800 with FuSi notes.
Joint GSN Safety Case Tree
AEB safety case skeleton with three branches (26262 faults, 21448 insufficiencies, 8800 ML KPI), six GSN node types, defensibility principles and standard-source colour badges.
AEB From HARA to Field Monitoring
A single AEB function carried through every chapter so vocabulary, triage, HARA extension, validation and monitoring all reinforce one example.
- HARA extended with a triggering-condition catalog
- Acceptance target derived from NHTSA baseline
- Driving policy and sensor-fusion budgets
- Combined fault injection, TC activation and OoD probing
- Field monitoring with OTA retraining playbook
Unlock the full AEB example
Who this guide is for
- Functional safety engineers extending into ADAS and automated driving work
- Safety managers planning a joint ISO 26262 plus ISO 21448 program with one set of work products
- V&V engineers who must justify statistical validation targets and test mileage
- Engineers wiring ML components into a safety case via ISO/PAS 8800 and ISO/IEC TR 5469
Frequently Asked Questions
Common questions about SotIF for the Functional Safety Engineer
Start the course today
A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 74-guide library. No credit card required.