The Quantitative Risk Norm - A Proposed Tailoring of HARA for ADS
Authors: Fredrik Warg, Rolf Johansson, Martin Skoglund, Anders Thorsén, Mattias Brännström, Magnus Gyllenhammar, and Martin Sanfridson

One of the major challenges of automated driving systems (ADS) is showing that they drive safely. Key to ensuring safety is eliciting a complete set of top-level safety requirements (safety goals). This is typically done with an activity called hazard analysis and risk assessment (HARA). In this paper we argue that the HARA of ISO 26262:2018 is not directly suitable for an ADS, both because the number of relevant operational situations may be vast, and because the ability of the ADS to make decisions in order to reduce risks will affect the analysis of exposure and hazards. Instead we propose a tailoring using a quantitative risk norm (QRN) with consequence classes, where each class has a limit for the frequency within which the consequences may occur. Incident types are then defined and assigned to the consequence classes; the requirements prescribing the limits of these incident types are used as safety goals to fulfil in the implementation. The main benefits of the QRN approach are the ability to show completeness of safety goals, and make sure that the safety strategy is not limited by safety goals which are not formulated in a way suitable for an ADS.

Keywords: ADS, automated driving, hazard analysis, HARA, functional safety, ISO 26262, risk norm.
Fulltext: pdf
Published: Proceeding of 6th International Workshop on Safety and Security of Intelligent Vehicles (SSIV 2020)
Presentation: pdf