systems engineering//functional safety//SOTIF

SOTIF, the safety of the intended functionality, is the safety of a system that has no fault at all but whose intended behaviour is insufficient for some situation it meets, and ISO 21448 (published as a standard in 2022) is the standard that addresses it for road vehicles; it is used for driver assistance and automated driving, where the main risk is a perception or decision function that works exactly as designed and is still wrong. A camera-based emergency braking system that brakes hard for a shadow under a bridge, or misses a pedestrian in an unusual coat against low sun, has no broken component. Its specification and its training did not cover that scene.


SOTIF, the safety of the intended functionality, is the safety of a system that has no fault at all but whose intended behaviour is insufficient for some situation it meets, and ISO 21448 (published as a standard in 2022) is the standard that addresses it for road vehicles; it is used for driver assistance and automated driving, where the main risk is a perception or decision function that works exactly as designed and is still wrong. A camera-based emergency braking system that brakes hard for a shadow under a bridge, or misses a pedestrian in an unusual coat against low sun, has no broken component. Its specification and its training did not cover that scene.

The classic functional safety standards (ISO 26262, IEC 61508) are built around faults: a part that stops doing what it was specified to do, detected by diagnostics and contained by redundancy. None of that helps when the specification itself is the problem, so SOTIF works on the space of situations instead. It sorts scenarios into four groups (known safe, known unsafe, unknown unsafe, unknown safe) and its activities aim to shrink the two unsafe groups: analyse known triggering conditions, improve the function or restrict its use where it fails, and search systematically for the unknown ones.

The hard part is the unknown unsafe scenarios, the situations nobody imagined. They are hunted with large-scale simulation of varied scenarios, fleet data from vehicles in operation, and argument about how much testing is enough; how much scenario simulation actually proves about the real world remains an open question.

The restriction of use is a design tool: an operational design domain (motorway, daylight, dry road, below a given speed) limits the function to the conditions it was validated for, and the system must detect leaving them and hand control back.

SOTIF is where machine learning meets safety regulation most directly, because a learned perception component's errors are insufficiencies of its training rather than faults; it pairs with architectures that monitor the learned part (Simplex architecture) and with drift monitoring once deployed.

The idea travels outside cars. A drone's vision-based landing, a warehouse robot's person detection or an inspection model's defect classifier can all fail without any fault, and the questions SOTIF asks (in which conditions does it fail, how do we know we found them, how do we restrict use) apply unchanged.

SOTIF is the member of functional safety that covers hazards without failures.