Skip to content

Autopilot qualification

Autopilot system qualification evidence review and support

An autopilot qualification evidence review checks that the software verification and environmental qualification behind an automatic flight control system meet the assurance level its safety assessment assigns. A certification engineer runs it for the supplier before the qualification evidence is relied on in a submission, or when qualification from an earlier program is proposed for reuse. It examines DO-178C verification coverage against the assigned DAL, the qualification of any tools relied on, and whether the qualified configuration still matches the article. You receive a qualification coverage assessment against the assurance level, a list of objectives or configurations that fall short, and the re-verification items needed to close them.

When this review is needed

  • Autopilot qualification evidence is about to anchor a submission and its coverage against the assigned DAL has not been confirmed.
  • Software qualified at one assurance level is being reused where the new safety assessment assigns a higher one.
  • A design change touched software and the existing verification may no longer cover the current build.
  • Tools used in verification carry qualification claims that have never been checked against their actual use.

The problem

Autopilot qualification is judged against an assigned assurance level, and that judgment is unforgiving: verification that satisfied a lower DAL simply does not meet a higher one, no matter how thorough it looked. Suppliers reuse software, re-host it, or inherit it from an earlier program where the failure conditions were classified differently, and the verification evidence that came with it may not reach the rigor the current safety case demands. The engineer relying on it has to know whether the coverage meets the level, not merely that testing was done.

What gets reviewed

  • DO-178C verification coverage compared against the assigned software assurance level
  • Structural coverage analysis appropriate to the level, where the level requires it
  • Tool qualification checked against the tools' actual use in the life-cycle
  • The qualified software and hardware configuration reconciled to the current build
  • Reused or legacy qualification assessed for whether it meets the current assurance level
  • Re-verification items scoped where coverage falls short of the level

Scope this review

Tell us the asset, the event, and the evidence in scope, and we will outline a focused first engagement.

Identify what is missing against the means of compliance.

What gets validated

  • Verification coverage meets every DO-178C objective the assigned level requires
  • The structural coverage analysis is present at the depth the level demands
  • Each qualified tool's qualification matches how the tool was actually used
  • The build under qualification matches the article's current software configuration
  • Any reused qualification is shown to meet the level the current safety assessment assigns

Evidence normally required

  • The assigned software and hardware assurance levels and their basis
  • The DO-178C verification data, cases, procedures, and results
  • Structural coverage analysis and any tool qualification records
  • The current software and hardware configuration definition
  • Any earlier qualification records proposed for reuse

Common discrepancies

  • Verification coverage that meets a lower DAL than the current safety assessment assigns
  • A structural coverage gap at the depth the assigned level requires
  • Tool qualification claimed for a use the tool was not actually qualified for
  • Reused software qualification tied to a build the article has since changed

What is at stake

Verification that falls short of the assigned DAL leaves a hole exactly where an authority looks hardest on a flight-critical system. Finding it late can force re-verification on the critical path, and reusing tool qualification that does not cover the tool's actual use can undermine every result that tool produced.

How the work runs

01

Fix the assigned level

Take the assurance level the current safety assessment assigns as the yardstick the qualification must meet.

02

Inventory the coverage

Read out what the existing verification, structural coverage, and tool qualification actually cover.

03

Test against the level

Compare the coverage to the objectives the assigned level requires and mark every shortfall.

04

Scope re-verification

Define the re-verification needed to reach the level, ordered by criticality.

What the buyer receives

  • A qualification coverage assessment against the assigned assurance level
  • A list of objectives, coverage, or configurations that fall short of the level
  • A scoped set of re-verification items to bring coverage up to the level

Who uses the output

  • Certification engineers relying on autopilot qualification in a submission
  • Software and verification leads planning any re-verification the gaps require
  • Program managers deciding whether reused qualification meets the current level

How the work fits into the transaction or program

The review runs upstream of both the autopilot TSO work and the STC installation work, since both assume the software qualification holds at the assigned level. Confirming that here keeps an assurance-level shortfall from surfacing inside a submission for a flight-critical system, where it is hardest to recover.

Start with a single asset

Confirm requirements map to substantiating evidence.

Jurisdiction-specific considerations

FAA and EASA both recognize DO-178C, so the objectives align, but each authority differs in how it expects tool qualification and reuse of prior verification to be justified for a system at this criticality. The assessment marks where a reuse or tool argument acceptable to one authority will need strengthening for the other.

Regulatory limits

The review assesses whether existing qualification meets the assigned level. It does not perform verification, assign the assurance level, qualify tools, or determine that the autopilot software is airworthy. It shows where coverage is short, not that the software passes.

What this review does not cover

Specific to this review

  • Autopilot qualification fails the level test more often than a discrete objective test, because verification adequate for a lower DAL cannot simply be promoted to a higher one.
  • Tool qualification is a quiet exposure: a tool qualified for one use but relied on for another can compromise every result it touched.
  • Reused software qualification is only as good as the match between its original build and the current one, and that match is what this review confirms before the evidence is trusted.

Sources

Frequently asked questions

The software was already qualified. Why review it again?

Qualification is measured against a specific assurance level. If the current safety assessment assigns a higher level than the software was originally qualified to, the earlier verification may not meet the objectives now required. The review checks coverage against the current level and scopes any re-verification needed.

Relevant glossary terms

Related pages

Where this fits

Talk to an engineer who has done this work

We will walk through your current state, the records or evidence involved, and a scoped first engagement.

Talk through the aircraft, records, evidence, deadline, and next useful step.