Navigate / EASA

Appendix 2 – Safety Assessment Process Overview

ED Decision 2020/001/R

In showing compliance with CS 25.1309(b), the considerations covered in this AMC should be addressed in a methodical and systematic manner, which ensures that the process and its findings are visible and readily assimilated. This appendix is provided primarily for those who are not familiar with the various methods and procedures generally used in the industry to conduct safety assessments. This guide and Figures A2-1 and A2-2 are not certification checklists, and they do not include all the information provided in this AMC. There is no necessity for them to be used or for the Agency to accept them, in whole or in part, to show compliance with any regulation. Their sole purposes are to assist, by illustrating a systematic approach to safety assessments, to enhance understanding and communication by summarising some of the information provided in this AMC, and to provide some suggestions on documentation. More detailed guidance can be found in Document referenced in paragraph 3b(3). Document referenced in paragraph 3b(2) includes additional guidance on how the safety assessment process relates to the system development process.

a.       Define the system and its interfaces, and identify the functions that the system is to perform. Some functions are intended to be protective, i.e. functions preventing the failures in system X from adversely affecting system Y. As the implementation of the functional requirements becomes more developed, care should be taken to identify all protective functions upon which airworthiness will depend. Determine whether or not the system is complex, similar to systems used on other aeroplanes, or conventional. When multiple systems and functions are to be evaluated, consider the relationships between multiple safety assessments.

b.      Identify and classify failure conditions. All relevant engineering organisations, such as systems, structures, propulsion, and flight test, should be involved in this process. This identification and classification may be done by conducting an FHA, which is usually based on one of the following methods, as appropriate:

(1)     If the system is not complex and its relevant attributes are similar to those of systems used on other aeroplanes, the identification and classification may be derived from design and installation appraisals and the service experience of the comparable, previously approved systems.

(2)     If the system is complex, it is necessary to systematically postulate the effects on the safety of the aeroplane and its occupants resulting from any possible failures, considered both individually and in combination with other failures or events.

c.       Choose the means to be used to determine compliance with CS 25.1309. The depth and scope of the analysis depends on the types of functions performed by the system, the severity of system failure conditions, and whether or not the system is complex (see Figure A2-2). For major failure conditions, experienced engineering and operational judgement, design and installation appraisals and comparative service experience data on similar systems may be acceptable, either on their own or in conjunction with qualitative analyses or selectively used quantitative analyses. For hazardous or catastrophic failure conditions, a very thorough safety assessment is necessary. The early concurrence of EASA on the choice of an acceptable means of compliance should be obtained.

d.      Conduct the analysis and produce the data, which are agreed with the certification authority as being acceptable to show compliance. A typical analysis should include the following information to the extent necessary to show compliance:

(1)     A statement of the functions, boundaries, and interfaces of the system.

(2)     A list of the parts and equipment of which the system is comprised, including their performance specifications or design standards and development assurance levels if applicable. This list may reference other documents, e.g., European Technical Standard Orders (ETSOs), manufacturers or military specifications, etc.

(3)     The conclusions, including a statement of the failure conditions and their classifications and probabilities (expressed qualitatively or quantitatively, as appropriate) that show compliance with the requirements of CS 25.1309.

(4)     A description that establishes correctness and completeness and traces the work leading to the conclusions. This description should include the basis for the classification of each failure condition (e.g. analysis or ground, flight, or simulator tests). It should also include a description of precautions taken against common-cause failures, provide any data such as component failure rates and their sources and applicability, support any assumptions made, and identify any required flight crew or ground crew actions, including any CCMRs.

e.       Assess the analyses and conclusions of multiple safety assessments to ensure compliance with the requirements for all aeroplane-level failure conditions.

f.       Prepare compliance statements, maintenance requirements, and flight manual requirements.

Figure A2-1: Safety Assessment Process Overview

Figure A2-2: Depth of Analysis Flowchart

[Amdt 25/2]

[Amdt 25/12]

[Amdt 25/14]

[Amdt 25/24]