Functional Safety Consulting for Automotive & Embedded Systems
Functional safety is the absence of unreasonable risk from hazards caused by malfunctioning electrical or electronic systems: and for road vehicles, it is governed primarily by ISO 26262. PRAETORIO provides functional safety consulting across the full safety lifecycle, from hazard analysis and risk assessment through safety requirements, architecture, verification, and safety case documentation, for automotive suppliers, OEMs, and manufacturers of safety-relevant embedded products.
Functional safety is not a documentation deliverable produced after a product is designed: it is an engineering discipline that has to shape the architecture, requirements, and verification activities from the beginning.
What Functional Safety Covers
Functional safety consulting spans the ISO 26262 safety lifecycle and related disciplines:
- Hazard analysis and risk assessment (HARA): identifying hazardous events and determining Automotive Safety Integrity Levels (ASIL: QM, A, B, C, D) based on severity, exposure, and controllability.
- Functional safety concept and requirements: deriving safety goals and functional safety requirements from the HARA results.
- Technical safety concept and architecture: defining the technical architecture and safety mechanisms needed to satisfy the functional safety requirements.
- Hardware and software safety development: applying ISO 26262 Part 5 (hardware) and Part 6 (software) requirements during detailed design and implementation.
- Verification and validation: safety-specific testing, including fault injection and hardware metrics evaluation, confirming that safety requirements are actually met.
- Safety case and documentation: assembling the safety case and work products required to demonstrate ISO 26262 compliance.
- SOTIF assessment: evaluating Safety of the Intended Functionality under ISO 21448, addressing hazards that arise from functional insufficiencies rather than component failures: particularly relevant for ADAS and automated driving functions.
Why Functional Safety Matters
It is a legal and contractual expectation, not optional best practice. OEMs and Tier 1 suppliers routinely require ISO 26262 compliance evidence as a condition of program participation, and functional safety failures carry both safety and liability consequences.
Safety has to be architected in, not tested in afterward. ASIL decomposition, redundancy, and safety mechanism design are architectural decisions; verifying an inadequately architected system rarely produces an adequate safety case.
The standard is evolving. ISO 26262’s second edition (2018) remains current, but a third edition is already in development, and SOTIF (ISO 21448) has become a parallel and increasingly important concern as vehicles add more complex automated functions where the primary risk is functional insufficiency rather than hardware failure.
Process rigor and product safety are related but distinct. Automotive SPICE process assessment can support confidence in an organization’s development process, but it does not by itself satisfy ISO 26262’s product-level safety requirements: the two disciplines need to be coordinated, not substituted for one another.
Retrofitting safety analysis is expensive. A HARA and safety concept developed after architecture decisions are already fixed often surfaces gaps that require costly rework; involving functional safety expertise early avoids this.
Our Approach
PRAETORIO supports functional safety programs across the ISO 26262 safety lifecycle:
- Item definition and HARA: define the item under analysis and perform hazard analysis and risk assessment to determine ASIL ratings.
- Functional safety concept: derive safety goals and functional safety requirements from the HARA.
- Technical safety concept: define the technical architecture and safety mechanisms needed to satisfy functional safety requirements.
- Hardware and software safety development support: support detailed design and implementation against Part 5 and Part 6 requirements.
- Safety verification and validation: plan and support safety-specific testing and hardware metrics evaluation.
- SOTIF assessment: where relevant, assess functional insufficiency risks under ISO 21448 alongside the ISO 26262 safety case.
- Safety case assembly: compile the documentation and work products required to demonstrate compliance.
- Assessment and audit support: support internal or external functional safety assessments.
Deliverables
- Hazard analysis and risk assessment (HARA) report with ASIL ratings
- Functional safety concept and safety requirements
- Technical safety concept and architecture documentation
- Hardware and software safety verification evidence
- SOTIF assessment report (where applicable)
- Complete safety case documentation package
- Functional safety assessment support
How PRAETORIO Can Support Your Team
- Full ISO 26262 safety lifecycle support, from item definition and HARA through safety case assembly, for a new product or system.
- ASIL determination and decomposition, establishing safety integrity levels and allocating them across a system architecture.
- Technical safety concept development, defining safety mechanisms and architecture to satisfy derived safety requirements.
- SOTIF assessment, evaluating functional insufficiency risks for ADAS and automated driving features under ISO 21448.
- Gap assessment and remediation, reviewing an existing functional safety program against ISO 26262 requirements and identifying priority gaps.
- Augmentation of an existing safety team, contributing specific hazard analysis, architecture, or verification expertise to a defined program.
Typical Use Cases
- A new automotive product or ECU needing a full functional safety program established from initial hazard analysis through safety case documentation.
- An organization needing ASIL determination and safety requirement derivation for a new system or feature.
- A team developing ADAS or automated driving functions needing SOTIF assessment alongside traditional ISO 26262 work.
- A supplier whose OEM customer requires ISO 26262 compliance evidence as a condition of program qualification.
- An organization needing an existing functional safety program assessed for gaps ahead of a certification or assessment milestone.
- A company needing functional safety engineering capacity to augment an internal team during a critical program phase.
Why PRAETORIO
- Direct experience applying ISO 26262 across hazard analysis, architecture, hardware and software safety development, and safety case assembly.
- More than 15 years of experience in automotive engineering, including power electronics and embedded systems where functional safety requirements are a core design constraint.
- Cross-domain engineering background connecting functional safety to embedded software development, systems engineering, and cybersecurity, so safety requirements are coordinated with the broader system architecture rather than treated in isolation.
- Engineering-oriented delivery: safety requirements are verified through actual architecture, implementation, and test evidence, supporting a genuinely defensible safety case.
Related Services
- ISO 26262 Consulting: dedicated ISO 26262 compliance and safety lifecycle support
- Automotive SPICE Consulting: process assessment complementary to functional safety work
- Systems Engineering: system architecture that functional safety requirements need to be coordinated with
- Embedded Systems Engineering: hardware-software architecture where safety mechanisms are implemented
- Embedded Software Development: software implementation against ISO 26262 Part 6 requirements
- Cybersecurity Engineering: cross-cutting cybersecurity requirements coordinated with functional safety
FAQ
What is functional safety?
Functional safety is the absence of unreasonable risk due to hazards caused by the malfunctioning behavior of electrical or electronic systems. For road vehicles, it is governed primarily by ISO 26262, which defines a full safety lifecycle from hazard analysis through safety case documentation.
What are ASIL levels?
Automotive Safety Integrity Levels (ASIL) are risk classifications defined in ISO 26262: QM (no specific safety requirements), and A, B, C, D in increasing order of required rigor: determined from a hazard’s severity, exposure, and controllability during hazard analysis and risk assessment.
What is the current edition of ISO 26262?
ISO 26262:2018 (second edition) is the current published standard. A third edition is in development, with working drafts registered as of 2026, but has not yet been published: current programs should continue to work to the 2018 edition.
What is SOTIF and how does it relate to ISO 26262?
SOTIF (Safety of the Intended Functionality), defined in ISO 21448, addresses hazards arising from functional insufficiencies or foreseeable misuse rather than component failure: it is a parallel consideration to ISO 26262, particularly important for ADAS and automated driving functions where the system can behave exactly as designed and still create hazardous situations.
Does Automotive SPICE certification satisfy ISO 26262 requirements?
No. Automotive SPICE assesses development process maturity, while ISO 26262 is a product-level functional safety standard. Automotive SPICE process rigor can support confidence in an organization’s development practices, which is relevant to ISO 26262, but it does not by itself satisfy ISO 26262’s safety lifecycle or work product requirements.
When should functional safety work begin in a product program?
As early as possible: ideally at item definition, before architecture decisions are made. Hazard analysis and the resulting safety requirements need to shape the architecture, not be retrofitted to a design that has already been finalized.
Can PRAETORIO support an existing functional safety team rather than owning the full program?
Yes. Many engagements involve augmenting an internal team with specific hazard analysis, architecture, verification, or SOTIF expertise for a defined scope, rather than a full end-to-end safety program engagement.
Need to Establish or Strengthen Your Functional Safety Program?
PRAETORIO can support your team from hazard analysis and ASIL determination through architecture, verification, and safety case assembly. Contact us to discuss your functional safety requirements.
Contact Us