ISO 26262 Part 9 Explained – ASIL-Oriented and Safety-Oriented Analyses
Developing a safety-critical automotive system requires more than defining safety requirements and implementing safety mechanisms.
Engineers must also demonstrate that the chosen safety architecture is sufficiently robust, that redundant elements remain independent, and that potential failure mechanisms have been systematically analyzed.
This is the purpose of ISO 26262 Part 9 – ASIL-Oriented and Safety-Oriented Analyses.
Part 9 introduces several advanced engineering methods that help evaluate safety architectures, support ASIL tailoring, analyze dependent failures, and provide confidence that Functional Safety objectives can be achieved.
In this article, we explain the structure of ISO 26262 Part 9 and its key concepts.
If you want to deepen your understanding of ISO 26262, ASPICE, Automotive Cybersecurity, and other engineering standards for safety-critical systems, explore our complete online training portfolio:
Why Safety-Oriented Analyses Matter
Modern vehicles contain numerous interconnected electronic systems.
Simply implementing redundancy does not automatically result in a safe system.
Engineers must demonstrate that:
- redundant channels are sufficiently independent
- safety mechanisms achieve the intended level of protection
- common causes of failure have been identified
- architectural assumptions are valid
- Safety Goals remain protected even under fault conditions
ISO 26262 Part 9 provides structured analytical methods that support these evaluations throughout system development.
Its objective is to strengthen confidence in the overall Functional Safety architecture.
Structure of ISO 26262 Part 9
Clause 5 – Requirements Decomposition with Respect to ASIL Tailoring
One of the best-known topics in ISO 26262 Part 9 is ASIL Decomposition.
ASIL Decomposition allows a safety requirement with a higher ASIL to be implemented using multiple independent elements with lower ASIL classifications.
For example, an ASIL D safety requirement may, under defined conditions, be allocated to two sufficiently independent ASIL B channels.
However, this is only permitted when strict independence requirements are fulfilled.
Typical considerations include:
- independence of hardware elements
- independent software execution
- separation of communication paths
- avoidance of common cause failures
- independent verification activities
ASIL Decomposition can simplify system architectures while maintaining the required level of Functional Safety.
Clause 6 – Criteria for Coexistence of Elements
Automotive systems often combine safety-related and non-safety-related functions within the same Electronic Control Unit (ECU).
Clause 6 defines the criteria that allow these elements to coexist without compromising Functional Safety.
Typical considerations include:
- freedom from interference
- resource separation
- communication isolation
- timing independence
- memory protection
The objective is to ensure that non-safety-related functionality cannot adversely affect safety-critical functions.
This concept is particularly important in modern software-defined vehicles where multiple applications share common computing platforms.
Clause 7 – Analysis of Dependent Failures
Redundant architectures are only effective when redundant channels fail independently.
Dependent failures occur when a single cause affects multiple elements simultaneously.
Examples include:
- common power supply failures
- thermal effects
- electromagnetic interference
- software design errors
- shared communication networks
- manufacturing defects
Clause 7 requires engineers to identify these dependencies and evaluate their impact on Functional Safety.
One commonly applied method is Dependent Failure Analysis (DFA), which systematically investigates potential common cause and cascading failures.
Identifying dependent failures early allows engineers to improve system robustness before implementation is completed.
Clause 8 – Safety Analyses
Part 9 introduces several analytical methods that provide confidence in the overall safety architecture.
Typical methods include:
- Failure Mode and Effects Analysis (FMEA)
- Fault Tree Analysis (FTA)
- Dependent Failure Analysis (DFA)
Each method addresses a different engineering question.
Failure Mode and Effects Analysis (FMEA)
FMEA is a bottom-up analysis.
It evaluates how individual component failures propagate through the system and identifies their potential effects.
Fault Tree Analysis (FTA)
FTA is a top-down analysis.
It begins with a hazardous event and works backwards to identify combinations of failures that could cause that event.
Dependent Failure Analysis (DFA)
DFA evaluates whether supposedly independent safety mechanisms could fail simultaneously due to shared causes.
Together, these analyses provide complementary evidence that the safety architecture satisfies the required Functional Safety objectives.
How Part 9 Supports Functional Safety
Unlike the earlier development-focused parts of ISO 26262, Part 9 provides analytical methods that support the evaluation of safety concepts across the complete development process.
Its techniques strengthen confidence in:
- system architecture
- redundancy concepts
- ASIL allocation
- safety mechanisms
- fault tolerance
- verification activities
- overall Functional Safety
Rather than introducing new development activities, Part 9 helps engineers evaluate whether the chosen safety solutions are sufficiently robust.
Summary
ISO 26262 Part 9 provides advanced analytical methods for evaluating Functional Safety architectures.
Its key topics include:
- Requirements Decomposition with Respect to ASIL Tailoring
- Criteria for Coexistence of Elements
- Analysis of Dependent Failures
- Safety Analyses
- ASIL Decomposition
- Failure Mode and Effects Analysis (FMEA)
- Fault Tree Analysis (FTA)
- Dependent Failure Analysis (DFA)
Together, these methods help engineers demonstrate that safety-related systems remain robust even when faults occur and that redundant safety concepts provide the intended level of protection.
For Functional Safety Engineers, Systems Engineers, Hardware Engineers, Software Engineers, System Architects, and Safety Managers, understanding ISO 26262 Part 9 is essential because it provides the analytical techniques used to validate and strengthen modern automotive Functional Safety concepts.