Shopping Cart

No products in the cart.

BSI PD ISO/PAS 21448:2019

$198.66

Road vehicles. Safety of the intended functionality

Published By Publication Date Number of Pages
BSI 2019 66
Guaranteed Safe Checkout
Categories: ,

If you have any questions, feel free to reach out to our online customer service team by clicking on the bottom right corner. We’re here to assist you 24/7.
Email:[email protected]

The absence of unreasonable risk due to hazards resulting from functional insufficiencies of the intended functionality or by reasonably foreseeable misuse by persons is referred to as the Safety Of The Intended Functionality (SOTIF). This document provides guidance on the applicable design, verification and validation measures needed to achieve the SOTIF. This document does not apply to faults covered by the ISO 26262 series or to hazards directly caused by the system technology (e.g. eye damage from a laser sensor).

This document is intended to be applied to intended functionality where proper situational awareness is critical to safety, and where that situational awareness is derived from complex sensors and processing algorithms; especially emergency intervention systems (e.g. emergency braking systems) and Advanced Driver Assistance Systems (ADAS) with levels 1 and 2 on the OICA/SAE standard J3016 automation scales. This edition of the document can be considered for higher levels of automation, however additional measures might be necessary. This document is not intended for functions of existing systems for which well-established and well-trusted design, verification and validation (V&V) measures exist at the time of publication (e.g. Dynamic Stability Control (DSC) systems, airbag, etc.). Some measures described in this document are applicable to innovative functions of such systems, if situational awareness derived from complex sensors and processing algorithms is part of the innovation.

Intended use and reasonably foreseeable misuse are considered in combination with potentially hazardous system behaviour when identifying hazardous events.

Reasonably foreseeable misuse, which could lead directly to potentially hazardous system behaviour, is also considered as a possible event that could directly trigger a SOTIF-related hazardous event.

Intentional alteration to the system operation is considered feature abuse. Feature abuse is not in scope of this document.

PDF Catalog

PDF Pages PDF Title
2 undefined
7 Foreword
8 Introduction
11 1 Scope
2 Normative references
3 Terms and definitions
16 4 Overview of this document’s activities in the development process
21 5 Functional and system specification (intended functionality content)
5.1 Objectives
5.2 Functional description
22 5.3 Consideration on system design and architecture
23 6 Identification and Evaluation of hazards caused by the intended functionality
6.1 Objectives
24 6.2 Hazard identification
25 6.3 Hazard analysis
26 6.4 Risk evaluation of the intended function
6.5 Specification of a validation target
27 7 Identification and Evaluation of triggering events
7.1 Objectives
7.2 Analysis of triggering events
7.2.1 Triggering events related to algorithms
28 7.2.2 Triggering events related to sensors and actuators
29 7.3 Acceptability of the triggering events
8 Functional modifications to reduce SOTIF related risks
8.1 Objectives
8.2 General
30 8.3 Measures to improve the SOTIF
32 8.4 Updating the system specification
9 Definition of the verification and validation strategy
9.1 Objectives
33 9.2 Planning and specification of integration and testing
10 Verification of the SOTIF (Area 2)
10.1 Objectives
34 10.2 Sensor verification
10.3 Decision algorithm verification
35 10.4 Actuation verification
10.5 Integrated system verification
36 11 Validation of the SOTIF (Area 3)
11.1 Objectives
11.2 Evaluation of residual risk
11.3 Validation test parameters
37 12 Methodology and criteria for SOTIF release
12.1 Objectives
12.2 Methodology for evaluating SOTIF for release
38 12.3 Criteria for SOTIF release
40 Annex A (informative) Examples of the application of SOTIF activities
43 Annex B (informative) Example for definition and validation of an acceptable false alarm rate in AEB systems
51 Annex C (informative) Validation of SOTIF applicable systems
53 Annex D (informative) Automotive perception systems verification and validation
56 Annex E (informative) Method for deriving SOTIF misuse scenarios
59 Annex F (informative) Example construction of scenario for SOTIF safety analysis method
62 Annex G (informative) Implications for off-line training
64 Bibliography
BSI PD ISO/PAS 21448:2019
$198.66