Safety assessment is a systematic analytical process that identifies, evaluates, and mitigates hazards associated with a system, product, or operational process to demonstrate that residual risk is tolerable within accepted standards and regulatory frameworks. It encompasses methods such as Failure Modes and Effects Analysis (FMEA), Fault Tree Analysis (FTA), Hazard and Operability Studies (HAZOP), and probabilistic safety analysis, applied across domains including aerospace, automotive, nuclear, medical devices, and increasingly AI systems. Safety assessments form the evidentiary basis for certification against safety standards such as IEC 61508 and ISO 26262.

Content

  • Formal safety assessment methodologies originated in the nuclear power and aerospace industries in the 1950s and 1960s, where catastrophic failure consequences demanded rigorous prior analysis. Fault Tree Analysis was developed by Bell Telephone Laboratories for the Minuteman missile programme in 1961; FMEA originated in the US military (MIL-P-1629, 1949) and was codified in aerospace and automotive quality standards. These quantitative techniques enabled engineers to compute probability of failure on demand (PFD) and tolerable hazard rates for complex systems.
  • A comprehensive safety assessment integrates both qualitative and quantitative methods. Qualitative HAZOP studies identify deviations from design intent by systematically applying guide words (more, less, none, reverse) to process parameters. Quantitative FTA constructs Boolean logic trees of failure events and computes top-event probabilities from component failure rate data. FMEA/FMECA analyses individual component failure modes and their system-level effects, severity, and detectability — producing a risk priority number that guides design and mitigation decisions. Safety cases — structured arguments demonstrating that safety goals are met — integrate evidence from all these analyses.
  • In automotive electronics, ISO 26262 mandates a safety lifecycle from concept phase through decommissioning, with safety assessment activities at each phase gate. ASIL decomposition allocates safety requirements to hardware and software components, driving diverse and redundant architectures. In aviation, DO-178C and DO-254 govern software and hardware development assurance levels. Medical device safety assessments under ISO 14971 follow a risk management process covering risk analysis, evaluation, control, and review throughout the product lifecycle.
  • Between 2023 and 2025, safety assessment methodology is under intense development for AI and machine learning systems, where traditional deterministic failure mode analysis is insufficient for statistical models with complex, data-dependent behaviour. SOTIF (ISO 21448), originally developed for automated driving, addresses performance limitations and triggering conditions not covered by functional safety. The EU AI Act classifies high-risk AI applications and mandates conformity assessments including risk management, data governance, and human oversight provisions. AI Risk Assessment frameworks from NIST (AI RMF), AISI, and ISO/IEC 42001 are converging on structured safety case approaches adapted for machine learning, though standardisation remains actively contested.