
Get an introduction to the safety of the intended functionality (SOTIF) under ISO 21448:2022, drawing on Bosch-backed experience in safety software and control units.
Motivate early fault recognition as recalls rise with more driver assistance and automation, and reduce costs by solving issues in development, guided by ISO 26262, ISO 21448.
Calculate risk from probability and severity within standards like ISO 2626 two and ISO 2144 eight, and reduce it to an acceptable level by implementing measures.
Explore the legal aspects of SOTIF (ISO 21448:2022), including product liability laws, burden of proof, and the mandatory versus optional parts, and how standards reflect state of the art.
Explore SOTIF principles and the four scenario areas, showing how triggering conditions and sensor faults create hazards and hazardous events, with sense-plan-act reducing residual risk.
Explore specification of functionality and design considerations for automation, detailing performance targets, HMI communications with the driver, and warning and fallback concepts, with adaptive cruise control as an example.
Identify hazards that can lead to harm in SOTIF using exposure, controllability, and severity to assess risks, with an autonomous emergency braking example triggered by radar.
Evaluate vehicle-level hazards using exposure, controllability, and severity from ISO 2626 two risk evaluation to determine ASIL levels. Implement risk reductions to lower severity or improve controllability in hazardous scenarios.
Define acceptance criteria for residual risk after risk evaluation, considering severity and controllability ratings and quantitative values and regulatory inputs.
Examine potential functional insufficiencies and triggering conditions in SOTIF (ISO 21448:2022) and assess the acceptability of hazardous behavior responses. Apply analysis methods across planning algorithms, sensors, actuators, and misuse scenarios.
Estimate the acceptability of the system's response to triggering conditions by evaluating all scenarios; achieve Sawteeth if residual risk is below acceptance criteria, otherwise modify functionality in chapter eight.
Explore four options to reduce residual risk in SOTIF: system modification, functional modification, handing over authority, and addressing reasonably foreseeable misuse; apply improvements to sensors, processing, actuators, and human-machine interface.
Update the input information for specification and design based on defined measures, iterating while hazards with unreasonable risk remain, and provide new input for chapter six activities.
Define the verification and validation strategy to evaluate potentially hazardous scenarios, cover the scenario space with systematic test-case derivation, and specify required evidence such as analyses and test reports.
Explore how SOTIF guides the verification of sensing elements, planning algorithms, and integrated system to manage known hazardous scenarios, focusing on sensor performance, environmental conditions, and residual risk.
Verify planning algorithms for robustness against interference using noise injection and requirement-based testing, analyze scenarios, and ensure triggers are detected with responses such as handing over control or reducing torque.
Verify activation with accuracy, resolution, and timing constraints; apply requirements-based testing; test actuator behavior under environmental conditions; and validate risk mitigation through resimulation of hazardous scenarios in the integrated system.
Verify the integrated system after sensing, planning, algorithms, and actuation using requirement-based tests to validate performance targets, timing constraints, aging effects, and internal and external interfaces.
Evaluate the residual risk from known hazardous scenarios against defined validation targets and acceptance criteria, following the verification and validation strategy from chapter nine, with future coverage of unknown scenarios.
The course is divided into two main chapters:
- Introduction
- Basics
- ISO 21448 Clauses
Chapter 1: Introduction
Includes an introduction of the course creator and provides a motivation lecture, why Safety of the intented functionality (SOTIF) is an important topic in the automotive industry nowadays.
Chapter 2: Basics
The chapter provides information on history and basic terms and definitions related to SOTIF. Also legal aspects are discussed in the chapter.
Chapter 3: ISO 21448
The chapter includes all chapters of the SOTIF standard ISO 21448 and explains the most important aspects of the chapters step by step.
The following chapters are covered by the course:
- Clause 4: Oveview and organization of SOTIF activities
The clause provides an overview of the most important aspects to be considered at the organizational level. For example the consideration of SOTIF principles and Management of SOTIF activities and supporting processes.
- Clause 5: Specification and design
The clause focuses on important aspect to be considered for specification of the functionality and the design.
- Clause 6: Identification and evaluation hazards
This clause focuses on the identification of hazards, evaluation of the resulting risk and the specification of acceptance criteria for the residual risk.
- Clause 7: Identification and evaluation of potential functional insufficiencies and potential triggering conditions
This clause provides an overview of the relation of potential functional insufficiencies and triggering conditions. And how harm can be a result.
- Clause 8: Functional modifications addressing SOTIF-related risks
This clause describes the possible options for a risk reduction in case the resulting risk is above an acceptable limit.
- Clause 9: Definition of the verification and validation strategy
The clause describes the aspects to be considered in a verification and validation strategy. Also how to derive validation targets based on the acceptance criteria is desrcribed.
- Clause 10: Evaluation of known scenarios
This clause described the evaluation of known scenarios and related methods for sensing verification, planning algorithm verification, actuation verification and verification of the integrated system.
- Clause 11. Evaluation of unknown scenarios
This clause describes how to ensure that the residual risk die tu unknown scenarios is below the acceptable limit.
- Clause 12: Evaluation of the achievement of the SOTIF
This clause describes the possible recommendation for final release of the SOTIF
- Clause 13: Operation phase activities
This clause describes how to ensure SOTIF after release in case SOTIF related risks are identified during operation phase.
At the end you get an overview of the ISO 26262 structure, since the safety standard ISO 26262 is one of the most important references in the ISO 21448.