ANNEX IISupplementary provisions
ANNEX II SAFETY AUDIT 1. General 1.1. This Annex defines the special requirements for documentation, fault strategy and verification with respect to the safety aspects of electronic control system(s) and complex electronic vehicle control system(s) of the emergency lane-keeping system. 1.1.1. Electronic control systems are commonly controlled by software and are built from discrete functional components such as sensors, electronic control units and actuators and connected by transmission links. They may include mechanical, electro-pneumatic or electro-hydraulic elements. 1.2. This Annex does not specify the performance criteria for the ‘The System’ covered by this Regulation but covers the methodology applied to the design process and the information which must be disclosed to the Technical Service, for type approval purposes. 1.3. This information shall show that ‘The System’ respects, under non-fault and fault conditions, all the appropriate performance requirements specified in Part 2 of Annex I and that it is designed to operate in such a way that it does not induce safety critical risks. 2. Documentation 2.1. Requirements The manufacturer shall provide a documentation package which gives access to the basic design of ‘The System’ and the means by which it is linked to other vehicle systems or by which it directly controls output variables. The function(s) of ‘The System’, including the control strategies, and the safety concept, as laid down by the manufacturer, shall be explained. Documentation shall be brief, yet provide evidence that the design and development has had the benefit of expertise from all the system fields which are involved. For periodic roadworthiness tests, the documentation shall describe how the current operational status of ‘The System’ can be checked. The Technical Service shall assess the documentation package to show that ‘The System’: (a) is designed to operate, under non-fault and fault conditions, in such a way that it does not induce safety critical risks; (b) respects, under non-fault and fault conditions, all the appropriate performance requirements specified elsewhere in this Regulation; and (c) was developed according to the development process/method declared by the manufacturer and that this includes at least the steps listed in point 2.4.4. 2.1.1. Documentation shall be made available in two parts: (a) The formal documentation package for the approval, containing the material listed in point 2. (with the exception of that of point 2.4.4.) which shall be supplied to the Technical Service at the time of submission of the type approval application. This documentation package shall be used by the Technical Service as the basic reference for the verification process set out in point 3. The Technical Service shall ensure that this documentation package remains available for a period determined in agreement with the Approval Authority. This period shall be at least 10 years counted from the time when production of the vehicle is definitely discontinued. (b) Additional material and analysis data of point 2.4.4. which shall be retained by the manufacturer, but made open for inspection at the time of type approval. The manufacturer shall ensure that this material and analysis data remains available for a period of 10 years counted from the time when production of the vehicle is definitely discontinued. 2.2. A description shall be provided which gives a simple explanation of all the functions including control strategies of ‘The System’ and the methods employed to achieve the objectives, including a statement of the mechanism(s) by which control is exercised. Any described function that can be over-ridden shall be identified and a further description of the changed rationale of the function’s operation provided. 2.2.1. A list of all input and sensed variables shall be provided and the working range of these defined, along with a description of how each variable affects system behaviour. 2.2.2. A list of all output variables which are controlled by ‘The System’ shall be provided and an indication given, in each case, of whether the control is direct or via another vehicle system. The range over which ‘The System’ is likely to exercise control on each output variable shall be defined. 2.2.3. Limits defining the boundaries of functional operation (i.e. the external physical limits within which the system is able to maintain control) shall be stated where appropriate to system performance. 2.3. System layout and schematics. 2.3.1. Inventory of components. A list shall be provided, collating all the units of ‘The System’ and mentioning the other vehicle systems which are needed to achieve the control function in question. An outline schematic showing these units in combination, shall be provided with both the equipment distribution and the interconnections made clear. 2.3.2. Functions of the units The function of each unit of ‘The System’ shall be outlined and the signals linking it with other units or with other vehicle systems shall be shown. This may be provided by a labelled block diagram or other schematic, or by a description aided by such a diagram. 2.3.3. Interconnections within ‘The System’ shall be shown by a circuit diagram for the electric transmission links, by a piping diagram for pneumatic or hydraulic transmission equipment and by a simplified diagrammatic layout for mechanical linkages. The transmission links both to and from other systems shall also be shown. 2.3.4. There shall be a clear correspondence between transmission links and the signals carried between units. Priorities of signals on multiplexed data paths shall be stated wherever priority may be an issue affecting performance or safety. 2.3.5. Identification of units Each unit shall be clearly and unambiguously identifiable (e.g. by marking for hardware and marking or software output for software content) to provide corresponding hardware and documentation association. Where functions are combined within a single unit or indeed within a single computer, but shown in multiple blocks in the block diagram for clarity and ease of explanation, only a single hardware identification marking shall be used. The manufacturer shall, by the use of this identification, affirm that the equipment supplied conforms to the corresponding document. 2.3.5.1. The identification defines the hardware and software version and, where the latter changes such as to alter the function of the Unit as far as this Regulation is concerned, this identification shall also be changed. 2.4. Safety concept of the manufacturer 2.4.1. The manufacturer shall provide a statement which affirms that the strategy chosen to achieve ‘The System’ objectives will not, under non-fault conditions, prejudice the safe operation of the vehicle. 2.4.2. In respect of software employed in ‘The System’, the outline architecture shall be explained and the design methods and tools used shall be identified. The manufacturer shall show evidence of the means by which they determined the realisation of the system logic, during the design and development process. 2.4.3. The manufacturer shall provide the Technical Service with an explanation of the design provisions built into ‘The System’ so as to generate safe operation under fault conditions. Possible design provisions for failure in ‘The System’ are for example: (a) fall-back to operation using a partial system; (b) change-over to a separate back-up system; (c) removal of the high level function. In case of a failure, the driver shall be warned for example by warning signal or message display. When the system is not deactivated by the driver, e.g. by turning the ignition (run) switch to ‘off’, or by switching off that particular function if a special switch is provided for that purpose, the warning shall be present as long as the fault condition persists. 2.4.3.1. If the chosen provision selects a partial performance mode of operation under certain fault conditions, then these conditions shall be stated and the resulting limits of effectiveness defined. 2.4.3.2. If the chosen provision selects a second (back-up) means to realise the vehicle control system objective, the principles of the change-over mechanism, the logic and level of redundancy and any built in back-up checking features shall be explained and the resulting limits of back-up effectiveness defined. 2.4.3.3. If the chosen provision selects the removal of the higher level electronic control function, all the corresponding output control signals associated with this function shall be inhibited, and in such a manner as to limit the transition disturbance. 2.4.4. The documentation shall be supported, by an analysis which shows, in overall terms, how the system will behave on the occurrence of any of those hazards or faults which will have a bearing on vehicle control performance or safety. The chosen analytical approach(es) shall be established and maintained by the Manufacturer and shall be made open for inspection by the Technical Service at the time of the type approval. The Technical Service shall perform an assessment of the application of the analytical approach(es). The assessment shall include: (a) Inspection of the safety approach at the concept (vehicle) level with confirmation that it includes consideration of: (i) interactions with other vehicle systems; (ii) malfunctions of the system, within the scope of this Regulation; (iii) for the functions referred to in point 2.2.: — situations when a system free from faults may create safety critical risks (e.g. due to a lack of or wrong comprehension of the vehicle environment), — reasonably foreseeable misuse by the driver, — intentional modification of the system. This approach shall be based on a hazard/risk analysis appropriate to system safety. (b) Inspection of the safety approach at the system level. This may be based on a Failure Mode and Effect Analysis (FMEA), a Fault Tree Analysis (FTA) or any similar process appropriate to system safety. (c) Inspection of the validation plans and results. This shall include validation testing appropriate for validation, for example, Hardware in the Loop (HIL) testing, vehicle on-road operational testing, or any other testing appropriate for validation. The assessment shall consist of spot checks of selected hazards and faults to establish that argumentation supporting the safety concept is understandable and logical and validation plans are suitable and have been completed. The Technical Service may perform or may require to perform tests as specified in point 3. to verify the safety concept. 2.4.4.1. This documentation shall itemize the parameters being monitored and shall set out, for each fault condition of the type defined in point 2.4.4., the warning signal to be given to the driver and/or to service/technical inspection personnel. 2.4.4.2. This documentation shall describe the measures in place to ensure the ‘The System’ does not prejudice the safe operation of the vehicle when the performance of ‘The System’ is affected by environmental conditions e.g. climatic, temperature, dust ingress, water ingress, ice packing. 3. Verification and test 3.1. The functional operation of ‘The System’, as laid out in the documents required in point 2., shall be tested as follows: 3.1.1. Verification of the function of ‘The System’ The Technical Service shall verify ‘The System’ under non-fault conditions by testing a number of selected functions from those described by the manufacturer in point 2.2. For complex electronic systems, these tests shall include scenarios whereby a declared function is overridden. 3.1.1.1. The verification results shall correspond with the description, including the control strategies, provided by the manufacturer in point 2.2. 3.1.2. Verification of the safety concept of point 2.4. The reaction of ‘The System’ shall be checked under the influence of a failure in any individual unit by applying corresponding output signals to electrical units or mechanical elements in order to simulate the effects of internal faults within the unit. The Technical Service shall conduct this check for at least one individual unit, but shall not check the reaction of ‘The System’ to multiple simultaneous failures of individual units. The Technical Service shall verify that these tests include aspects that may have an impact on vehicle controllability and user information (HMI aspects). 4. Reporting by Technical Service Reporting of the assessment by the Technical Service shall be performed in such a manner that allows traceability, e.g. versions of documents inspected are coded and listed in the records of the Technical Service. An example of a possible layout for the assessment form from the Technical Service to the Type Approval Authority is given in the Appendix.