Safety assessment evidence
Safety assessment evidence review for aircraft modifiers
A safety assessment evidence review checks that the FHA, PSSA, and SSA form a closed loop, where the hazards identified drive requirements and the SSA shows those requirements met by verification evidence. It is run for aircraft modifiers before a submittal, in a finding response on the safety case, or when a change disturbs the hazard picture. The review targets safety results that never became requirements, and requirements that the SSA claims satisfied without tracing to real verification. You get a gap list of open safety loops, an evidence map through the assessment, and a closure order.
When this review is needed
- A submittal rests on a safety case and the SSA must show every hazard mitigated by met requirements.
- A finding questioned whether safety results traced to requirements and verification.
- A change altered the architecture or introduced a new failure mode the assessment must absorb.
- The FHA, PSSA, and SSA were produced at different phases and their loop was never checked end to end.
The problem
A safety assessment is only worth the loop it closes: a hazard found in the FHA should become a requirement, and the SSA should show that requirement met by verification. The three documents are built at different phases by a process under its own schedule pressure. A failure condition gets a mitigation in the PSSA that never becomes a tracked requirement; the SSA asserts a probability target met without pointing at the verification that meets it. The loop reads closed while it is quietly open.
What gets reviewed
- Each FHA failure condition confirmed to carry a classification and flow into the PSSA
- PSSA-derived safety requirements confirmed to be captured as tracked requirements
- SSA claims of met safety requirements traced to specific verification evidence
- Quantitative probability targets checked against the analysis that substantiates them
- Common-cause and independence claims checked for the analysis behind them
- Requirement feedback from the assessment confirmed to reach the requirement set and design
What gets validated
- Every FHA failure condition has a classification and appears in the PSSA
- Each safety requirement derived in the PSSA exists in the tracked requirement set
- Each SSA claim of a met requirement traces to identifiable verification evidence
- Quantitative targets in the SSA are backed by the analysis that computes them
- Common-cause and independence assumptions carry the analysis that supports them
Evidence normally required
- The FHA, PSSA, and SSA for the modification
- The requirement set the safety requirements should appear in
- The verification evidence the SSA credits against safety requirements
- Common-cause and independence analyses referenced by the assessment
- Change records that altered the architecture or introduced failure modes
Common discrepancies
What is at stake
An open safety loop is the finding with the highest stakes, because it bears on whether a hazard is actually controlled rather than merely described. An SSA that claims a target met without traceable verification cannot stand on its own under review, and repairing the loop late can pull requirements, verification, and the assessment back into rework at once, near the submittal date.
Move from findings to resolution
Identify gaps against the means of compliance.
How the work runs
Walk hazards into requirements
Confirm each FHA failure condition flows through the PSSA into a tracked safety requirement.
Close requirements with verification
Trace each SSA claim of a met requirement to the specific verification evidence that meets it.
Check the quantitative backbone
Confirm probability targets and independence assumptions carry the analysis that substantiates them.
Deliver open loops
Return the unrequirement-ed hazards and unverified claims with an evidence map and a closure order.
What the buyer receives
- A gap list of open safety loops from hazard to requirement to verification
- An evidence map tracing each failure condition through the assessment to its closure
- A closure order that reconnects the unrequirement-ed hazards and unverified claims first
Who uses the output
- STC program managers judging whether the safety case will hold under review
- Certification engineers answering a finding on safety-requirement traceability
- Engineering leads directing the requirement and verification rework the gaps expose
How the work fits into the transaction or program
The safety assessment sets many of the requirements the rest of the program verifies, so an open loop here propagates into every downstream data package. Checking that hazards become requirements and requirements become verified evidence keeps the safety case, the requirement set, and the verification records telling one consistent story.
Start with a single asset
Confirm requirements trace through verification.
Jurisdiction-specific considerations
FAA and EASA both build the safety case on the ARP4761 process and both expect the SSA to close quantitatively and qualitatively. The review holds the assessment to the governing authority's expectation for probability substantiation and independence justification rather than a single interpretation.
Regulatory limits
This review checks the modifier's own safety assessment for closure and traceability. It does not perform the safety analysis, does not make a compliance finding, and does not determine airworthiness. Acceptance of the safety case remains with the authority.
What this review does not cover
Specific to this review
- The safety assessment fails most often not in its analysis but in its closure, where a real mitigation never becomes a requirement anyone tracks.
- An SSA can assert a probability target met and still be unverifiable, because the claim and the analysis that computes it are separate artifacts that can drift apart.
- Independence and common-cause claims are load-bearing for the quantitative case, so an unsupported independence assumption can invalidate a whole probability argument.
- A change that adds a failure mode obligates the entire FHA-to-SSA loop to absorb it, and that propagation is the step most often skipped under schedule pressure.
Sources
SAE International. Safety assessment methods (FHA, PSSA, SSA, FTA, FMEA) supporting development assurance level assignment.
SAE International. Development assurance process at aircraft and system level, including requirements capture and validation.
U.S. Government (eCFR). Type certificates, STCs (Subpart E), TSO authorizations (Subpart O), PMA (Subpart K), and export airworthiness approvals (Subpart L).
Frequently asked questions
Our SSA shows all targets met. What would a review add?
A met target is a claim. The review checks whether each claim traces to the verification and the analysis that substantiate it, and whether every hazard actually became a tracked requirement. That closure is what an authority tests, and it is where safety cases most often prove open.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.