systems engineering//functional safety//ISO 26262

ISO 26262 is the functional safety standard for the electrical and electronic systems of road vehicles, derived from IEC 61508 and first published in 2011 (second edition 2018); it is used by carmakers and their suppliers to develop and justify every safety-related function in a vehicle, from airbag deployment and electric power steering to braking and battery management. It grades each function with an **automotive safety integrity level**, ASIL A to D, D the strictest, and a function with no safety relevance is labelled QM (quality management only).


ISO 26262 is the functional safety standard for the electrical and electronic systems of road vehicles, derived from IEC 61508 and first published in 2011 (second edition 2018); it is used by carmakers and their suppliers to develop and justify every safety-related function in a vehicle, from airbag deployment and electric power steering to braking and battery management. It grades each function with an automotive safety integrity level, ASIL A to D, D the strictest, and a function with no safety relevance is labelled QM (quality management only).

The level comes out of a hazard analysis and risk assessment (HARA) done on the vehicle, before any design. Each hazardous event is rated on three scales: severity of the harm (S0 to S3), exposure, how often the driving situation occurs (E0 to E4), and controllability, how likely a typical driver is to avoid the harm (C0 to C3). The combination gives the ASIL. Unintended full braking at motorway speed scores high on all three and lands at ASIL D; a fault in an interior light scores nothing and stays QM.

Controllability makes the driver part of the safety argument: a hazard a typical driver can usually manage earns a lower level than its severity alone would give. The flip side is that as vehicles automate, the driver stops being a control measure, controllability falls and the same failure moves up the scale, which is part of why automated driving functions are so expensive to certify.

An ASIL is a requirement on the function, and it can be split. ASIL decomposition lets a D requirement be met by two sufficiently independent elements at lower levels (for example B and B), the same separation strategy as a monitor beside a complex controller, provided the two share no common cause.

The standard covers the whole lifecycle, from concept and system design through hardware metrics (how many single-point and latent faults the diagnostics catch) and software development to production and decommissioning, following the V-model. Its supplier interface (who owns which safety requirement) shapes how the automotive supply chain is organized.

It addresses faults, failures of hardware or software to do what they were specified to do. A sensor that works exactly as designed and still misreads a scene is outside it, which is the gap SOTIF (ISO 21448) was written to cover; cybersecurity has its own companion, ISO/SAE 21434.

It is the automotive member of functional safety, the sector child of IEC 61508.