Adapting the FMEA for Safety Critical Design Processes

Functional safety standards (ISO 26262, IEC 61508) require a safety life cycle which demands additional design and engineering tasks to be managed. This paper addresses how the existing FMEAs have to be extended and refocused to address and overview signal paths throughout the system. The safety standards require to classify signals with a SIL (Safety Integrity Level) and the higher the SIL the more parallel controls and checks must assure that the signal is correctly calculated, used, and monitored. This paper illustrates this extension of the FMEA using the FMEA to investigate the effect of false sensor signals resulting out of failures in software monitoring functions and false failure reactions on system level resulting out of either false sensor signals or failures within the diagnostic software. AS a complementary activity to the FMEDA a FMEA method is introduced that allows an analysis during the development process that is performed prior to the “in-use” FMEDA.