ISO 26262 Part 9 Explained – ASIL-Oriented and Safety-Oriented Analyses

Developing a safety-critical automotive system requires more than defining safety requirements and implementing safety mechanisms.

Engineers must also demonstrate that the chosen safety architecture is sufficiently robust, that redundant elements remain independent, and that potential failure mechanisms have been systematically analyzed.

This is the purpose of ISO 26262 Part 9 – ASIL-Oriented and Safety-Oriented Analyses.

Part 9 introduces several advanced engineering methods that help evaluate safety architectures, support ASIL tailoring, analyze dependent failures, and provide confidence that Functional Safety objectives can be achieved.

In this article, we explain the structure of ISO 26262 Part 9 and its key concepts.

If you want to deepen your understanding of ISO 26262, ASPICE, Automotive Cybersecurity, and other engineering standards for safety-critical systems, explore our complete online training portfolio:

Why Safety-Oriented Analyses Matter

Modern vehicles contain numerous interconnected electronic systems.

Simply implementing redundancy does not automatically result in a safe system.

Engineers must demonstrate that:

  • redundant channels are sufficiently independent
  • safety mechanisms achieve the intended level of protection
  • common causes of failure have been identified
  • architectural assumptions are valid
  • Safety Goals remain protected even under fault conditions

ISO 26262 Part 9 provides structured analytical methods that support these evaluations throughout system development.

Its objective is to strengthen confidence in the overall Functional Safety architecture.

Structure of ISO 26262 Part 9

Overview of ISO 26262 Part 9 showing ASIL tailoring, coexistence of elements, dependent failure analysis, and safety analyses
ISO 26262 Part 9 introduces advanced engineering analyses that strengthen Functional Safety through ASIL tailoring, dependent failure analysis, and systematic safety evaluations.

Clause 5 – Requirements Decomposition with Respect to ASIL Tailoring

One of the best-known topics in ISO 26262 Part 9 is ASIL Decomposition.

ASIL Decomposition allows a safety requirement with a higher ASIL to be implemented using multiple independent elements with lower ASIL classifications.

For example, an ASIL D safety requirement may, under defined conditions, be allocated to two sufficiently independent ASIL B channels.

However, this is only permitted when strict independence requirements are fulfilled.

Typical considerations include:

  • independence of hardware elements
  • independent software execution
  • separation of communication paths
  • avoidance of common cause failures
  • independent verification activities

ASIL Decomposition can simplify system architectures while maintaining the required level of Functional Safety.

ISO 26262 ASIL Decomposition illustrating how one ASIL D safety requirement can be implemented through two independent ASIL B channels
ASIL Decomposition allows higher ASIL requirements to be allocated to multiple independent lower-ASIL elements while maintaining the required level of Functional Safety.

Clause 6 – Criteria for Coexistence of Elements

Automotive systems often combine safety-related and non-safety-related functions within the same Electronic Control Unit (ECU).

Clause 6 defines the criteria that allow these elements to coexist without compromising Functional Safety.

Typical considerations include:

  • freedom from interference
  • resource separation
  • communication isolation
  • timing independence
  • memory protection

The objective is to ensure that non-safety-related functionality cannot adversely affect safety-critical functions.

This concept is particularly important in modern software-defined vehicles where multiple applications share common computing platforms.

Clause 7 – Analysis of Dependent Failures

Redundant architectures are only effective when redundant channels fail independently.

Dependent failures occur when a single cause affects multiple elements simultaneously.

Examples include:

  • common power supply failures
  • thermal effects
  • electromagnetic interference
  • software design errors
  • shared communication networks
  • manufacturing defects

Clause 7 requires engineers to identify these dependencies and evaluate their impact on Functional Safety.

One commonly applied method is Dependent Failure Analysis (DFA), which systematically investigates potential common cause and cascading failures.

Identifying dependent failures early allows engineers to improve system robustness before implementation is completed.

Clause 8 – Safety Analyses

Part 9 introduces several analytical methods that provide confidence in the overall safety architecture.

Typical methods include:

  • Failure Mode and Effects Analysis (FMEA)
  • Fault Tree Analysis (FTA)
  • Dependent Failure Analysis (DFA)

Each method addresses a different engineering question.

Failure Mode and Effects Analysis (FMEA)

FMEA is a bottom-up analysis.

It evaluates how individual component failures propagate through the system and identifies their potential effects.

Fault Tree Analysis (FTA)

FTA is a top-down analysis.

It begins with a hazardous event and works backwards to identify combinations of failures that could cause that event.

Dependent Failure Analysis (DFA)

DFA evaluates whether supposedly independent safety mechanisms could fail simultaneously due to shared causes.

Together, these analyses provide complementary evidence that the safety architecture satisfies the required Functional Safety objectives.

ISO 26262 Safety Analyses showing Failure Mode and Effects Analysis, Fault Tree Analysis, and Dependent Failure Analysis supporting Functional Safety
FMEA, FTA, and DFA provide complementary analysis methods for evaluating safety architectures and demonstrating compliance with ISO 26262.

How Part 9 Supports Functional Safety

 

Unlike the earlier development-focused parts of ISO 26262, Part 9 provides analytical methods that support the evaluation of safety concepts across the complete development process.

Its techniques strengthen confidence in:

  • system architecture
  • redundancy concepts
  • ASIL allocation
  • safety mechanisms
  • fault tolerance
  • verification activities
  • overall Functional Safety

Rather than introducing new development activities, Part 9 helps engineers evaluate whether the chosen safety solutions are sufficiently robust.

Summary

 

ISO 26262 Part 9 provides advanced analytical methods for evaluating Functional Safety architectures.

Its key topics include:

  • Requirements Decomposition with Respect to ASIL Tailoring
  • Criteria for Coexistence of Elements
  • Analysis of Dependent Failures
  • Safety Analyses
  • ASIL Decomposition
  • Failure Mode and Effects Analysis (FMEA)
  • Fault Tree Analysis (FTA)
  • Dependent Failure Analysis (DFA)

Together, these methods help engineers demonstrate that safety-related systems remain robust even when faults occur and that redundant safety concepts provide the intended level of protection.

For Functional Safety Engineers, Systems Engineers, Hardware Engineers, Software Engineers, System Architects, and Safety Managers, understanding ISO 26262 Part 9 is essential because it provides the analytical techniques used to validate and strengthen modern automotive Functional Safety concepts.

If you prefer a visual explanation, this video explains ISO 26262-9 ASIL-Oriented and Safety-Oriented Analyses

Leave a Comment

Your email address will not be published. Required fields are marked *

Shopping Cart
Cookie Consent with Real Cookie Banner