{"id":8488,"date":"2025-05-20T09:45:13","date_gmt":"2025-05-20T07:45:13","guid":{"rendered":"https:\/\/lorit-consultancy.com\/en\/?p=8488"},"modified":"2025-10-17T10:31:32","modified_gmt":"2025-10-17T08:31:32","slug":"arp-4761-vs-iso-26262","status":"publish","type":"post","link":"https:\/\/lorit-consultancy.com\/en\/2025\/05\/arp-4761-vs-iso-26262\/","title":{"rendered":"ARP 4761 vs ISO 26262: Safety Doesn\u2019t Fall From The Sky, But Inspiration Could"},"content":{"rendered":"<h2><strong data-renderer-mark=\"true\">The cars cannot fly (yet!), but our safety process may be inspired by aviation<\/strong><\/h2>\n<p data-renderer-start-pos=\"6295\">Diving into automotive topics as a safety engineer, but carrying baggage from aviation industry, some comparison was bound to happen.<\/p>\n<p data-renderer-start-pos=\"6295\"><span class=\"fabric-background-color-mark\" data-renderer-mark=\"true\" data-background-custom-color=\"#d3f1a7\">Whether<\/span> flying or driving, safety and reliability are a priority<span class=\"fabric-background-color-mark\" data-renderer-mark=\"true\" data-background-custom-color=\"#d3f1a7\">,<\/span> and for both industries<span class=\"fabric-background-color-mark\" data-renderer-mark=\"true\" data-background-custom-color=\"#d3f1a7\">,<\/span> there is a dedicated standard providing regulations to ensure safe operation. But, if we need to comply to a required, industry suitable standard, it doesn&#8217;t necessarily mean that the other one is off the limits for guidance, if supplementary, or inspiration. While automotive systems are subject to different stressors and operational conditions compared to aircraft, many underlying principles (redundancy, failure modes, risk quantification) are common and can prompt a valuable cross-industry exchange.<\/p>\n<h2 data-renderer-start-pos=\"7030\"><strong data-renderer-mark=\"true\">Let&#8217;s pick a centrepiece for today<\/strong><\/h2>\n<p data-renderer-start-pos=\"7066\">In automotive industry supported by <a class=\"_mizu1p6i _1ah31bk5 _ra3xnqa1 _128m1bk5 _1cvmnqa1 _4davt94y _4bfu18uv _1hms8stv _ajmmnqa1 _vchhusvi _syaz14q2 _ect41gqc _1a3b18uv _4fpr8stv _5goinqa1 _f8pj14q2 _9oik18uv _1bnxglyw _jf4cnqa1 _30l314q2 _1nrm18uv _c2waglyw _1iohnqa1 _9h8h16c2 _1053w7te _1ienw7te _n0fxw7te _1vhvg3x0\" title=\"https:\/\/lorit-consultancy.com\/en\/standards\/automotive\/iso26262\/\" href=\"https:\/\/lorit-consultancy.com\/en\/standards\/automotive\/iso26262\/\" data-renderer-mark=\"true\">ISO 26262<\/a>, much of focus is placed upon FTA, FMEA, or HAZOP<span class=\"fabric-background-color-mark\" data-renderer-mark=\"true\" data-background-custom-color=\"#d3f1a7\">. <\/span>So not to neglect DFA, we might put it in spotlight here.<\/p>\n<p data-renderer-start-pos=\"7222\"><span data-olk-copy-source=\"MessageBody\">In our previous blogs, we&#8217;ve already discussed the\u00a0<a id=\"LPlnk209140\" title=\"https:\/\/lorit-consultancy.com\/en\/2024\/11\/not-seeing-the-wood-for-the-trees-refining-dependent-failures-analysis\/\" href=\"https:\/\/lorit-consultancy.com\/en\/2024\/11\/not-seeing-the-wood-for-the-trees-refining-dependent-failures-analysis\/\" data-auth=\"NotApplicable\" data-linkindex=\"3\">refinement of Dependant Failure Analysis<\/a>\u00a0(DFA), but also DFA related\u00a0<\/span><a id=\"OWAab909cb7-2a20-3c97-1f36-b34535f99af1\" title=\"https:\/\/lorit-consultancy.com\/en\/2017\/07\/iso-26262-part-11-blog-post-3-dependent-failure-analysis-dfa\/\" href=\"https:\/\/lorit-consultancy.com\/en\/2017\/07\/iso-26262-part-11-blog-post-3-dependent-failure-analysis-dfa\/\" data-renderer-mark=\"true\" data-auth=\"NotApplicable\" data-linkindex=\"4\">enhancements made in second edition of ISO 26262<\/a>,\u00a0and\u00a0<a id=\"OWAee10384c-ce60-9d2a-abc7-dd7bfd6a5a9f\" title=\"https:\/\/lorit-consultancy.com\/en\/2020\/06\/quantifying-iso-26262-dependent-failures-analysis\/\" href=\"https:\/\/lorit-consultancy.com\/en\/2020\/06\/quantifying-iso-26262-dependent-failures-analysis\/\" data-renderer-mark=\"true\" data-auth=\"NotApplicable\" data-linkindex=\"5\">quantification of potential dependent failure initiators (DFI)<\/a>, where we also reflected on\u00a0<a id=\"OWA5b60f4bc-16f4-d307-48b5-56cc6d8c455f\" title=\"https:\/\/lorit-consultancy.com\/en\/2020\/12\/iec-61508-the-mother-of-all-safety-standards\/\" href=\"https:\/\/lorit-consultancy.com\/en\/2020\/12\/iec-61508-the-mother-of-all-safety-standards\/\" data-renderer-mark=\"true\" data-auth=\"NotApplicable\" data-linkindex=\"6\">IEC 61508<\/a>\u00a0and its qualitative assessment ways.<\/p>\n<p data-renderer-start-pos=\"7515\">Here, we will turn to aviation&#8217;s <a class=\"_mizu1p6i _1ah31bk5 _ra3xnqa1 _128m1bk5 _1cvmnqa1 _4davt94y _4bfu18uv _1hms8stv _ajmmnqa1 _vchhusvi _syaz14q2 _ect41gqc _1a3b18uv _4fpr8stv _5goinqa1 _f8pj14q2 _9oik18uv _1bnxglyw _jf4cnqa1 _30l314q2 _1nrm18uv _c2waglyw _1iohnqa1 _9h8h16c2 _1053w7te _1ienw7te _n0fxw7te _1vhvg3x0\" title=\"https:\/\/www.sae.org\/standards\/content\/arp4761a\/\" href=\"https:\/\/www.sae.org\/standards\/content\/arp4761a\/\" data-renderer-mark=\"true\">SAE International ARP4761\u2122A<\/a>, which defines common cause methodology, a\u00a0rigorous framework built out of a set of methods. The results of these analyses support the claim that the independence requirements have been met by the implementation.<\/p>\n<p data-renderer-start-pos=\"7515\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-8483 alignnone\" src=\"https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2025\/05\/Unbenannt-2025-05-19T115846.982-1024x576.jpeg\" alt=\"\" width=\"475\" height=\"267\" srcset=\"https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2025\/05\/Unbenannt-2025-05-19T115846.982-1024x576.jpeg 1024w, https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2025\/05\/Unbenannt-2025-05-19T115846.982-768x432.jpeg 768w, https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2025\/05\/Unbenannt-2025-05-19T115846.982.jpeg 1200w\" sizes=\"auto, (max-width: 475px) 100vw, 475px\" \/><\/p>\n<p data-renderer-start-pos=\"7515\"><em>Source: https:\/\/new.express.adobe.com\/<\/em><\/p>\n<h2><strong data-renderer-mark=\"true\">Independence Principles and Common Mode Analysis<\/strong><\/h2>\n<p data-renderer-start-pos=\"7840\">Certain features of system architecture &#8211; redundancy, protection, monitoring &#8211; might require independence between their elements due to \u201cno single point of failure\u201d requirements or requirements related to development assurance level (DAL) assignment. This independence request is defined as an<strong data-renderer-mark=\"true\"> Independence Principle <\/strong>in ARP4761\u2122A.<\/p>\n<p data-renderer-start-pos=\"8172\">A single failure, error, or event that produces undesirable effects on two or more systems, equipment, items, or functions is defined as a <strong data-renderer-mark=\"true\">common cause<\/strong>.<\/p>\n<p data-renderer-start-pos=\"8326\">A common cause affecting multiple <em data-renderer-mark=\"true\">redundant<\/em> elements of a system might compromise the <em data-renderer-mark=\"true\">availability<\/em> safety objectives. A common cause affecting both <em data-renderer-mark=\"true\">the protection and the protected function<\/em>, or <em data-renderer-mark=\"true\">the monitoring elements and the monitored function<\/em> of a system might compromise the <em data-renderer-mark=\"true\">integrity<\/em> safety objectives.<\/p>\n<p data-renderer-start-pos=\"8634\">The need for independence in achieving safety objectives should be identified and captured in formal <strong data-renderer-mark=\"true\">independence requirements<\/strong> (with help of a CMA questionnaire).<\/p>\n<p data-renderer-start-pos=\"8798\">Two commonly used methods to identify Independence Principles are:<\/p>\n<ol class=\"ak-ol\" start=\"1\" data-indent-level=\"1\">\n<li>\n<p data-renderer-start-pos=\"8868\">Design Analysis, and<\/p>\n<\/li>\n<li>\n<p data-renderer-start-pos=\"8868\">Fault Tree Analysis, with two submethods<\/p>\n<\/li>\n<\/ol>\n<p data-renderer-start-pos=\"8868\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 a. AND-Gate Analysis, and<\/p>\n<p data-renderer-start-pos=\"8868\">\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 b. Cut <span class=\"fabric-background-color-mark\" data-renderer-mark=\"true\" data-background-custom-color=\"#d3f1a7\">S<\/span>et Analysis.<\/p>\n<p data-renderer-start-pos=\"8985\">The defined Independance Principles are then fed into common cause methods for an assessment. The method most comparable to automotive&#8217;s DFA, in aviation world<span class=\"fabric-background-color-mark\" data-renderer-mark=\"true\" data-background-custom-color=\"#d3f1a7\">,<\/span> would be <strong data-renderer-mark=\"true\">Common Mode Analysis<\/strong> (CMA).<\/p>\n<p data-renderer-start-pos=\"8985\">One method to plan CMA activities is to use the CMA questionnaire (or set of questionnaires). The CMA questionnaire is a task identification tool, tailored to identify the type and the source of the common causes within the particular scope of work. They are derived based on the example data presented in ARP4761\u2122A (not exhaustive) and previous experiences. The level of detail of these questionnaires changes with the complexity of the system or novelty of the technology and is adjusted to the level of analysis.<\/p>\n<p data-renderer-start-pos=\"9701\">The CMA process can also be used in terms of FDAL or IDAL assignment and is conducted in a similar way. But in this case, there is a different aim &#8211; instead of recognizing potential failures, the activities focus on identifying potential error sources within the development\/design process which might compromise the intended independence of functions and items. The emphasis here is on ensuring an adequate independence, as applicable, to comply with the DAL assignment.<\/p>\n<p data-renderer-start-pos=\"10174\">Let&#8217;s scrutinize, for some cross-domain inspiration!<\/p>\n<\/div><\/div><\/div><div class=\"content_section blue_bg blog_trenner_section\"><div class=\"row align-center medium-align-spaced\"><div class=\"columns border_solid_square post_thumbnail small-10 medium-5 large-3\"><div  data-ratio=\"1.133412042503\" class=\"\"><picture><source media=\"(min-width:1024px)\" srcset=\"https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2025\/03\/Natasa-Simanic-John_3X4_v1-scaled-e1773692194282-1694x1920.jpg\" width=\"1694\" height=\"1920\" type=\"image\/webp\" ><source media=\"(min-width:640px)\" srcset=\"https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2025\/03\/Natasa-Simanic-John_3X4_v1-scaled-e1773692194282-904x1024.jpg\" width=\"904\" height=\"1024\" type=\"image\/webp\" ><img decoding=\"async\" src=\"https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2025\/03\/Natasa-Simanic-John_3X4_v1-scaled-e1773692194282-640x640.jpg\" alt=\"Nata\u0161a Simani\u0107 John - Lorit Consultancy FuSa Consultant\" loading=\"lazy\" width=\"640\" height=\"640\" type=\"image\/webp\" ><\/picture><svg version=\"1.1\" id=\"svg_border_solid_square\" class=\"svg_border_solid_square\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:xlink=\"http:\/\/www.w3.org\/1999\/xlink\" x=\"0px\" y=\"0px\"\n\t viewBox=\"0 0 337 411.2\" style=\"enable-background:new 0 0 337 411.2;\" xml:space=\"preserve\">\n<polygon id=\"bg\" class=\"bg\" points=\"65,332.6 337,332.6 336.9,411.2 3.6,411.2 \"\/>\n<path id=\"border\" class=\"border\" d=\"M334,329.6V5.9c0-1.6-1.3-2.9-2.9-2.9l0,0L5.9,3.1C4.3,3.1,3,4.3,3,6v400.8c0,1.6,0.8,1.9,1.8,0.6\n\tl59.6-74.7l266.6-0.1C332.7,332.5,333.9,331.2,334,329.6z\"\/>\n<\/svg><\/div><div class=\"image_bottom_content\"><p>Nata\u0161a Simani\u0107 John, Functional safety consultant<\/p>\n<\/div><\/div><div class=\"columns post_content small-12 medium-6 large-7\"><p class=\"\" data-start=\"131\" data-end=\"609\"><strong data-start=\"131\" data-end=\"208\">Need expert support for your aviation safety and certification processes?<\/strong><br data-start=\"208\" data-end=\"211\" \/>With extensive experience in ARP4761 and ARP4754, <strong><a href=\"https:\/\/lorit-consultancy.com\/en\/about-us\/#natasa-simanic-john\">Nata\u0161a Simani\u0107 John<\/a> <\/strong>brings deep insight into safety assessments, standard compliance, implementation of safety mechanisms, and process optimization throughout the development lifecycle.<\/p>\n<p class=\"\" data-start=\"611\" data-end=\"756\">\ud83d\udce9 <strong data-start=\"614\" data-end=\"700\">Reach out to us at <a class=\"cursor-pointer\" href=\"mailto:info@lorit-consultancy.com\" rel=\"noopener\" data-start=\"635\" data-end=\"698\">info@lorit-consultancy.com<\/a><\/strong> to learn how we can support your next aviation project.<\/p>\n<a class=\"add_logo_border\" target=\"_blank\" href=\"https:\/\/lorit-consultancy.com\/en\/\"><span>Learn more<\/span><\/a><\/div><\/div><\/div><\/div><div class=\"single_content_section single_post_section content_section\"><div class=\"row\"><div class=\"post_content columns\">\n<h2><strong data-renderer-mark=\"true\">Iterating Safety Assessment Continuously<\/strong><\/h2>\n<p data-renderer-start-pos=\"10270\">ARP4761 embeds CMA throughout the design, development, and certification phases in an iterative process. This ensures that common mode risks are re-evaluated as the system evolves.<\/p>\n<p data-renderer-start-pos=\"10452\">Automotive industry could also benefit from similarly stressing the continuous integration of common-mode evaluations rather than treating it as a final check per ISO 26262.<\/p>\n<p data-prosemirror-content-type=\"node\" data-prosemirror-node-name=\"paragraph\" data-prosemirror-node-block=\"true\" data-pm-slice=\"1 1 [&quot;layoutSection&quot;,{&quot;columnRuleStyle&quot;:null},&quot;layoutColumn&quot;,{&quot;width&quot;:50}]\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-8512\" src=\"https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2025\/05\/Screenshot-2025-05-20-082817.png\" alt=\"\" width=\"702\" height=\"486\" srcset=\"https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2025\/05\/Screenshot-2025-05-20-082817.png 981w, https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2025\/05\/Screenshot-2025-05-20-082817-768x532.png 768w\" sizes=\"auto, (max-width: 702px) 100vw, 702px\" \/><\/p>\n<p data-prosemirror-content-type=\"node\" data-prosemirror-node-name=\"paragraph\" data-prosemirror-node-block=\"true\" data-pm-slice=\"1 1 [&quot;layoutSection&quot;,{&quot;columnRuleStyle&quot;:null},&quot;layoutColumn&quot;,{&quot;width&quot;:50}]\"><em>Diagram 1. Development Phase and Verification Phase CMA<\/em><\/p>\n<h2><strong data-renderer-mark=\"true\">Enhancing Rigor by Qualitative Judgments AND Quantitative Measures<\/strong><\/h2>\n<p>Techniques like Fault Tree Analysis (FTA) and Dependence Diagrams are integral to CMA and help in systematically mapping out failure propagation across redundant systems. ISO 26262 mentions usability of these techniques, but including the analytical tools within the analysis process more extensively could lead to a more refined understanding of interdependencies.<\/p>\n<p>ARP4761\u2019s CMA process often employs both qualitative scenario assessments and quantitative analyses (such as probability estimations) to evaluate the likelihood and impact of common mode failures. Incorporating a mix of qualitative insights\u2014especially in complex, interdependent systems\u2014might improve their robustness.<\/p>\n<h2><strong data-renderer-mark=\"true\">Emphasizing Detailed Documentation and Traceability<\/strong><\/h2>\n<p data-renderer-start-pos=\"11466\">ARP4761 stresses the importance of comprehensive record keeping. Every decision, assumption, and finding from the CMA is documented and traced to build an auditable safety case.<\/p>\n<p data-renderer-start-pos=\"11645\">ISO 26262 could enhance its processes with similar strategies, ensuring that every common cause and dependency is thoroughly documented, which in turn could not only simplify certification but also <span class=\"fabric-background-color-mark\" data-renderer-mark=\"true\" data-background-custom-color=\"#d3f1a7\">supports <\/span>inevitable future modifications.<\/p>\n<p>For certification in aviation safety, the evidence gathered through CMA plays a critical role in demonstrating compliance <span class=\"fabric-background-color-mark\" data-renderer-mark=\"true\" data-background-custom-color=\"#d3f1a7\">with<\/span> certifiers. As automotive safety standards evolve\u2014especially with demands for higher confidence in autonomous systems\u2014a similar level of documented rigor could support more robust safety cases and foster greater trust from regulatory bodies.<\/p>\n<p>By <a href=\"https:\/\/lorit-consultancy.com\/en\/about-us\/#natasa-simanic-john\">Nata\u0161a Simani\u0107 John<\/a>, Functional Safety Consultant<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The cars cannot fly (yet!), but our safety process may be inspired by aviation Diving into automotive topics as a safety engineer, but carrying baggage from aviation industry, some comparison was bound to happen. Whether flying or driving, safety and reliability are a priority, and for both industries, there is a dedicated standard providing regulations [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":8494,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[9,87,91,93],"tags":[101,123,144],"class_list":["post-8488","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","category-functional-safety","category-safety","category-automotive","tag-functional-safety","tag-iso-26262","tag-arp-4761"],"acf":[],"_links":{"self":[{"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/posts\/8488","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/comments?post=8488"}],"version-history":[{"count":13,"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/posts\/8488\/revisions"}],"predecessor-version":[{"id":8699,"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/posts\/8488\/revisions\/8699"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/media\/8494"}],"wp:attachment":[{"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/media?parent=8488"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/categories?post=8488"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/tags?post=8488"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}