The application of the appropriate standards, rules and best practices is essential from the perspective of any experienced manufacturer or supplier in the automotive industry. The story doesn’t differ in the automotive environment. This well developed and crucial industry branch cannot work effectively without the unification and the process support defined in the standards. Nowadays, it is obvious, but it was not always like that.

Currently, there are a few vital organisations that provide international industry standards. Some examples of these types of institutions include Internal Organisation of Standardisation (ISO) and International Electrotechnical Commission (IEC). ISO standards are developed by groups of experts from all over the world,and are part of larger groups called technical committees. These experts negotiate all aspects of the standard, including its scope, key definitions and content. These non-governmental institutions are doing their job in almost every area of human life. Since 1946, they approved about 20 000 standards

Pour plus d'informations sur nos compétences en matière de sécurité fonctionnelle (ISO 26262), consultez notre formation automobile page.

Qu'est-ce que l'ISO 26262

« Véhicules routiers – Sécurité fonctionnelle » est le titre officiel de la norme ISO 26262. It is the international standard for functional safety of electrical and electronic systems in serial production road vehicles. The basics were derived from IEC 61508, which is often recognised as a master functional safety standard. IEC 61508 can be applied in various industries and it is related to any electronic or electrical system. ISO 26262 is an adaptation of the IEC 61508, which is a generic functional safety standard for electrical and electronic systems, for automotive needs.

The ISO 26262 maintains support for the whole product safety lifecycle, including management, development, production and service. During the development process, functional safety covers every safety related aspect of the product on a very detailed level, including such activities as requirements specification, design, implementation, integration, verification, validation, configuration, production, services, operation and decommissioning. The above-mentioned standard also describes the framework for functional safety to assist the development of the safety-related system.

The goal is to achieve acceptable residual risk. E/E System Safety Goals are derived from Hazard and Risk Assessment (HARA) and then the ASIL (Automotive Safety Integrity Level) can be defined. ASIL from A to D means that in the system there is some level of non-acceptable risk which means there are particular FUSA efforts needed to raise the controllability of unwanted situations. – an Automotive Safety Integrity Level (ASIL). Based on that series of activities, it could then be tailored to a particular application.

L'histoire de l'ISO 26262

The origins of the safety design date back to the 1960s, when for example, the product failure rate, reliability, dependability and availability were considered, but in those days, there was still a long way to go before the first functional safety standard in the automotive environment was created. It does not mean there weren’t any safety features in cars before then. Despite mechanical improvements like safety belts which where mounted in the series car since 1958, the electronic/electrical features were also added long before the appearance of ISO 26262 . For example, Anti – lock braking systems (ABS) currently mandatory in the EU was released in late 1960s. It was the same story with the Electronic steering control (ESC), which was first introduced to the market ] in the 1980s.

The first draft of the ISO 26262 arrived in 2008, but the official release was in 2011. That version of the standard includes ten parts and was limited to electric or electronic devices in series production vehicles with a maximum gross weight of 3500 kg. The second and latest version of the ISO 26262 is from 2018. Two new chapters had been added to the standard. One of them was concerning semiconductors, the other describes adaptation for motorcycles. 4. Why is ISO 26262 important

Even though ISO 26262 is treated very seriously by mature producers it is not mandatory. Widespread compliance shows therefore that it is viewed as an essential standard. This is just half of the story. OEM’s are aware that compliance with this standard is essential and will insist that their own suppliers adhere to it. Following the rules and best practice defined by ISO 26262 makes the development and production process more effective and structured. Based on Quality Assurance there are still gaps in the safety product related to design and production, so the answer in that case is the ISO 26262. It introduces more effort and restriction in the workflow, but as a result, you receive well organised processes, and weak points will be identified and addressed. This lead to a safe, high quality product.

Concepts clés de l'ISO 26262

ISO 26262 est construite autour de plusieurs concepts clés essentiels à la compréhension de la norme. Ces concepts incluent :

  • Sécurité fonctionnelle: At its core, functional safety is about ensuring that a system or component performs its intended function without causing harm to people or the environment. This involves identifying potential hazards and implementing measures to mitigate risks, ensuring that the system operates safely under all conditions.
  • Niveau d'intégrité de sécurité automobile (ASIL): ASIL is a risk classification system that defines the level of risk associated with a particular hazard. It ranges from ASIL A (the lowest level of risk) to ASIL D (the highest level of risk). Determining the ASIL is crucial as it dictates the rigor of the safety measures that need to be implemented.
  • Cycle de vie de la sécurité: The safety life cycle is a comprehensive framework for managing functional safety throughout the entire development process, from concept to decommissioning. It ensures that safety is considered at every stage, helping to identify and address potential issues early on.
  • Analyse des dangers et évaluation des risques (HARA): HARA is a method for identifying and assessing potential hazards and risks associated with a system or component. It involves analysing the system to identify possible failure modes and their effects, and then assessing the associated risks to determine the necessary safety measures.

Lecture recommandée : Analyse des dangers et évaluation des risques (HARA) dans un projet automobile (étude de cas)

  • Exigences de sécurité: These are specific requirements that must be met to ensure the functional safety of a system or component. They are derived from the hazard analysis and risk assessment and are used to guide the development process, ensuring that all safety-related aspects are addressed.

Vous souhaitez en savoir plus sur l'ISO 26262 ?

Obtenez notre guide

Les 12 parties de l'ISO 26262 et comment elles aident l'industrie automobile à se conformer à la sécurité fonctionnelle

As was mentioned before, ISO 26262 contains twelve separate parts. Each of them refers to a different level of the product lifecycle. Ten parts are normative and the remaining, are guidelines. All the parts constitute one combined form and furthermore it is common that one part refers to another.

Partie 1 : Vocabulaire

The title speaks for itself. The role of the first part is to specify vocabulary, definitions, and abbreviations. It is crucial to be on the same page and in terms of definitions, understand each other. A brilliant example is an explanation of these words:

Défaut – Condition anormale pouvant entraîner la défaillance d'un élément ou d'un article.

Erreur – Écart entre une valeur ou une condition calculée, observée ou mesurée, et la valeur ou la condition réelle, spécifiée ou théoriquement correcte.

Défaillance -Terminaison d'un comportement prévu d'un élément ou d'un article en raison de la manifestation d'une défaillance.

Partie 2 : Gestion de la sécurité fonctionnelle

This section describes the appropriate functional safety management methodology for automotive applications, including overall safety management and project-specific information related to management activities during the safety lifecycle’s various phases.

Partie 3 : Phase de conception

The third part is applied during the early phase of product development. The third part is applied during the early phase of product development. This section requires you to perform a Hazard and Risk Assessment (HARA) based on Item Definition. Later on, Functional Safety Requirements will be defined then all of Functional Safety Requirements will be given to the System Team. meeting the definition of the item. This section requires you to perform Hazard Analysis and Risk Assessment (HARA), so from this point onwards, the Safety Goals in the project should be defined.

Partie 4 : Le développement produit au niveau du système

Cette section couvre un éventail de problématiques liées au développement au niveau du système. Au programme figurent les spécifications qui doivent être initiées pour la sécurité technique, telles que le concept de sécurité technique, la conception architecturale du système, l'intégration et les tests de l'élément.

Partie 5 : Développement produit au niveau matériel

Part five defines requirements for product development on the hardware level. It includes basic topics like hardware design, or evaluation of architectural hardware metrics. In the range of that section, it is also required to evaluate safety goal violation due to random failures.

Partie 6 : Développement produit au niveau logiciel

This section addresses a range of topics concerned with product development on the software level. This includes specifications for software safety, software architectural design, software unit design and verification, software integration and testing embedded software. At this stage qualitative analyses, like Failure Tree Analysis (FTA) and Failure Mode and Effect Analysis (FMEA) are often used.

Partie 7 : Production, exploitation, maintenance et décommissionnement

The objective of this part is to develop and maintain a production process for safety related elements or items that are intended to be installed in road vehicles, as well as gather information about operations, services and decommissioning for users which interface with safety-related items.

Partie 8 : Processus de support

The goal of this part is to integrate the whole process and support Safety Life Cycle. It is continuously active throughout all phases. Part eight describes among others how to correctly proceed to verification, how to perform tool qualification, or how introduce proven in-use arguments.

Partie 9 : analyses orientées Automotive Safety Integrity Level (ASIL) et orientées sécurité

En spécifiant les niveaux d'intégrité de sécurité automobile (ASIL) et les analyses orientées sécurité, cette partie couvre la décomposition en lien avec l'adaptation des ASIL, les critères de coexistence des éléments, l'analyse des défaillances dépendantes et les analyses de sécurité.

Partie 10 : Lignes directrices sur l'ISO 26262

Il s'agit de l'une des deux parties informatives de l'ISO 26262 qui fournit un aperçu et enrichit les informations en ajoutant des explications supplémentaires. L'objectif de cette partie est d'améliorer la compréhension des autres parties et du concept général de l'ISO 26262.

Partie 11 : Lignes directrices sur l'application de la norme aux semi-conducteurs

La partie 11 a été ajoutée lors de la deuxième édition de la norme. Elle fournit des informations détaillées pour accompagner les fabricants de semi-conducteurs et la propriété intellectuelle silicium (IP). Son objectif est de définir la manière dont les fournisseurs d'IP et les intégrateurs doivent collaborer.

Partie 12 : Adaptation de l'ISO 26262 aux motocycles

The objective of this clause is to give an overview of the adaptation of the ISO 26262 series of standards for motorcycles. It covers general topics for the adaptation of motorcycles, safety culture, confirmation measures, hazard analysis and risk assessment, vehicle integration and testing, and safety validation.

Atteindre la conformité ISO 26262

Atteindre la conformité ISO 26262 nécessite une approche structurée impliquant plusieurs étapes clés. Chaque étape est cruciale pour garantir que le système ou le composant répond aux exigences de sécurité nécessaires :

  • Évaluation de la sécurité fonctionnelle: Une évaluation complète du système ou du composant visant à identifier les dangers et risques potentiels. Cela implique d'analyser la conception et le fonctionnement du système pour garantir que tous les aspects liés à la sécurité sont pris en compte.
  • Analyse des dangers et évaluation des risques (HARA): Une méthode pour identifier et évaluer les dangers et risques potentiels associés à un système ou à un composant. Cette étape est essentielle pour déterminer les mesures de sécurité nécessaires et définir les exigences de sécurité.
  • Exigences de sécurité: Exigences spécifiques qui doivent être satisfaites pour garantir la sécurité fonctionnelle d'un système ou d'un composant. Ces exigences guident le processus de développement, en veillant à ce que tous les aspects liés à la sécurité soient pris en compte.
  • Analyse de classification des outils logiciels: Une analyse des outils logiciels utilisés dans le processus de développement afin de s'assurer qu'ils répondent aux exigences de sécurité. Cela implique d'évaluer la fiabilité des outils et de déterminer les activités de qualification nécessaires.
  • Systèmes liés à la sécurité: Systèmes ou composants essentiels à la sécurité du véhicule ou de ses occupants. Ces systèmes doivent être conçus et développés pour répondre aux normes de sécurité les plus élevées.
  • Processus de développement complet: L'ensemble du processus de développement, de la conception au décommissionnement, doit être géré afin de garantir que les exigences de sécurité sont satisfaites. Cela implique une planification, une exécution et un suivi rigoureux pour s'assurer que tous les aspects liés à la sécurité sont pris en compte.
  • Rapport de qualification des outils logiciels: A report that provides evidence that a software tool is suitable for use in the development of safety-related software. This report documents the qualification activities and the results, providing assurance that the tool meets the necessary safety standards.
  • Évaluation des risques: Une évaluation complète des risques associés à un système ou à un composant. Cela implique d'analyser les modes de défaillance potentiels et leurs effets, et de mettre en œuvre des mesures pour atténuer les risques.
  • Détermination des classes de risque: Les classes de risque sont déterminées sur la base de l'analyse des dangers et de l'évaluation des risques. Cette étape est cruciale pour définir les mesures de sécurité nécessaires et garantir que le système respecte les normes de sécurité requises.
  • Composants automobiles: Composants essentiels à la sécurité du véhicule ou de ses occupants. Ces composants doivent être conçus, développés et testés pour répondre aux normes de sécurité les plus élevées.
  • Documentation des outils logiciels: Documentation that provides evidence that a software tool is suitable for use in the development of safety-related software. This includes detailed records of the tool’s qualification activities and results, ensuring that the tool meets the necessary safety standards.

En suivant ces étapes, les fabricants peuvent atteindre la conformité ISO 26262, en veillant à ce que leurs systèmes et composants respectent les normes de sécurité les plus élevées et offrent des performances fiables tout au long de leur cycle de vie.

Critique de l'ISO 26262 (mentionnant le SOTIF)

Despite the significant improvement to the electronic and electrical environment in the second release of the ISO 26262, there are still some gaps in the functional safety field. Places where the standard falls short are for example missuses, or automated driving. The solution is ISO PAS 21448 (SOTIF). Previously there was a plan to include that standard in ISO 26262 as a fourteenth section, but it was released as a separate document.

The purpose of SOTIF is to start to address some of the aspects of autonomous driving, where safety is not violated by the failure itself but by the unspecified behavior of the vehicle. SOTIF is taking a more holistic look on the usage of the product. Bright lights, dust, smoke and snowstorms all affect the sensor data, and the “brain” of the car is processing and making decisions based on probability.

Qualification d'outils ISO 26262

The tool qualification is a one of the activities deemed essential for compliance with ISO 26262. In general, the purpose is to ensure that all tools used in the project are reliable, or malfunctions are known, and any issues that arise can be handled. It is important to take into consideration all tools used even those indirectly involved in the development process.

Besoin d'aide pour mettre en œuvre l'ISO 26262 dans votre projet ?

Our expert team can guide you through the entire functional safety process, from hazard analysis and risk assessment to system design, validation, and compliance audits. We’ll help you navigate the complexities of achieving ISO 26262 certification, ensuring your automotive systems meet the highest safety standards. Reach out to our expert via the form below and schedule a no-obligation meeting.