Appendix 2 – Safety Assessment Process Overview
ED
Decision 2020/001/R
In showing
compliance with CS 25.1309(b), the considerations covered in this AMC
should be addressed in a methodical and systematic manner, which ensures that
the process and its findings are visible and readily assimilated. This
appendix is provided primarily for those who are not familiar with the various
methods and procedures generally used in the industry to conduct safety
assessments. This guide and Figures A2-1 and A2-2 are not certification
checklists, and they do not include all the information provided in this AMC.
There is no necessity for them to be used or for the Agency to accept them, in
whole or in part, to show compliance with any regulation. Their sole purposes
are to assist, by illustrating a systematic approach to safety assessments, to
enhance understanding and communication by summarising some of the information
provided in this AMC, and to provide some suggestions on documentation. More
detailed guidance can be found in Document referenced in paragraph 3b(3).
Document referenced in paragraph 3b(2) includes additional guidance on how the
safety assessment process relates to the system development process.
a. Define the system and its interfaces,
and identify the functions that the system is to perform. Some functions are
intended to be protective, i.e. functions preventing the failures in system X
from adversely affecting system Y. As the implementation of the functional
requirements becomes more developed, care should be taken to identify all
protective functions upon which airworthiness will depend. Determine whether
or not the system is complex, similar to systems used on other aeroplanes, or
conventional. When multiple systems and functions are to be evaluated,
consider the relationships between multiple safety assessments.
b. Identify and classify failure conditions.
All relevant engineering organisations, such as systems, structures,
propulsion, and flight test, should be involved in this process. This
identification and classification may be done by conducting an FHA, which is
usually based on one of the following methods, as appropriate:
(1) If the system is not complex and its
relevant attributes are similar to those of systems used on other aeroplanes,
the identification and classification may be derived from design and
installation appraisals and the service experience of the comparable, previously
approved systems.
(2) If the system is complex, it is necessary
to systematically postulate the effects on the safety of the aeroplane and its
occupants resulting from any possible failures, considered both individually
and in combination with other failures or events.
c. Choose the means to be used to determine
compliance with CS 25.1309. The depth and scope of the analysis depends
on the types of functions performed by the system, the severity of system
failure conditions, and whether or not the system is complex (see Figure
A2-2). For major failure conditions, experienced engineering and operational
judgement, design and installation appraisals and comparative service
experience data on similar systems may be acceptable, either on their own or
in conjunction with qualitative analyses or selectively used quantitative
analyses. For hazardous or catastrophic failure conditions, a very thorough
safety assessment is necessary. The early concurrence of EASA on the choice of
an acceptable means of compliance should be obtained.
d. Conduct the analysis and produce the
data, which are agreed with the certification authority as being acceptable to
show compliance. A typical analysis should include the following information
to the extent necessary to show compliance:
(1) A statement of the functions, boundaries,
and interfaces of the system.
(2) A list of the parts and equipment of which
the system is comprised, including their performance specifications or design
standards and development assurance levels if applicable. This list may
reference other documents, e.g., European Technical Standard Orders (ETSOs),
manufacturers or military specifications, etc.
(3) The conclusions, including a statement of
the failure conditions and their classifications and probabilities (expressed
qualitatively or quantitatively, as appropriate) that show compliance with the
requirements of CS 25.1309.
(4) A description that establishes correctness
and completeness and traces the work leading to the conclusions. This
description should include the basis for the classification of each failure condition
(e.g. analysis or ground, flight, or simulator tests). It should also include
a description of precautions taken against common-cause failures, provide any
data such as component failure rates and their sources and applicability,
support any assumptions made, and identify any required flight crew or ground
crew actions, including any CCMRs.
e. Assess the analyses and conclusions of
multiple safety assessments to ensure compliance with the requirements for all
aeroplane-level failure conditions.
f. Prepare compliance statements,
maintenance requirements, and flight manual requirements.
Figure A2-1: Safety Assessment Process Overview
Figure A2-2: Depth of Analysis
Flowchart
[Amdt
25/2]
[Amdt
25/12]
[Amdt
25/14]
[Amdt
25/24]
EASA CS-25 safety assessments for large airplanes require a systematic approach. Define the system, classify failures, and choose compliance methods based on complexity and severity. Conduct thorough analysis, document findings, and assess aeroplane-level failure conditions. Prepare compliance statements, maintenance, and flight manual requirements.
* Summary by Aviation.Bot - Always consult the original document for the most accurate information.
Loading collections...