Skip to content

ARP4761A navigation

ARP4761A safety assessment evidence review for navigation equipment

This review holds a navigation equipment package against ARP4761A and reports where the safety-assessment evidence is incomplete. A supplier's safety or certification team uses it before submittal or when responding to a finding. It centers on the hazards specific to navigation, misleading information above all, the failure analysis that classifies them, and the safety requirements fed back to the design. What you get is a standards map, a gap list, and a sequence for closing each open objective.

When this review is needed

  • A navigation equipment package needs its ARP4761A posture read before submittal.
  • The misleading-information hazard for a navigation output was assessed loosely and a reviewer wants it substantiated.
  • Failure analysis exists but does not clearly separate loss of function from undetected erroneous output.
  • A finding response depends on knowing which navigation safety objectives the current analysis answers.

The problem

For navigation equipment the defining hazard is not losing the function but presenting wrong position or guidance without warning, and safety assessments often blur the two. Failure analysis that lumps loss of function together with undetected erroneous output produces a classification a reviewer cannot rely on, because the two failure conditions carry very different severities. When the detection and integrity monitoring that would catch misleading information is not tied to a stated safety requirement, ARP4761A cannot see the mitigation it expects.

What gets reviewed

  • Functional hazard assessment separating loss of function from undetected erroneous output
  • Failure analysis supporting the severity of misleading-information conditions
  • Integrity and detection monitoring traced to the safety requirements it satisfies
  • Safety requirements traced back to the navigation failure conditions that generated them
  • The link between the safety assessment and the development-assurance evidence it drives
  • Configuration control so the assessed and submitted baselines match

What gets validated

  • Loss of function and undetected erroneous output are assessed as distinct failure conditions
  • The severity assigned to a misleading-information hazard is supported by failure analysis
  • Integrity and detection monitoring traces to a stated safety requirement that credits it
  • Safety requirements trace to the navigation failure conditions they address
  • The safety assessment and development-assurance evidence reference a consistent function set

Evidence normally required

Common discrepancies

  • Undetected erroneous output folded into loss of function, understating the real hazard
  • Integrity monitoring present in the design but not credited to a safety requirement
  • A misleading-information severity asserted without failure analysis behind it
  • A safety requirement that does not trace to a navigation failure condition

What is at stake

A misleading-information hazard that is understated because it was folded into loss of function draws a finding that reopens the classification and everything allocated from it. If integrity monitoring is present in the design but not traced to a safety requirement, the mitigation cannot be credited, and the equipment carries a higher assessed risk than it should.

Move from findings to resolution

Identify gaps against the means of compliance.

How the work runs

01

Split the failure conditions

Separate loss of function from undetected erroneous output and confirm each is assessed on its own.

02

Credit the monitoring

Trace integrity and detection monitoring to the safety requirement that lets it mitigate the hazard.

03

Support the severity

Check that failure analysis backs the classification assigned to the misleading-information condition.

04

Order the closures

Sequence so the hazard separation precedes the requirement traces and monitoring credit above it.

What the buyer receives

  • A standards map tying each ARP4761A objective to the navigation safety evidence that answers it
  • A gap list naming the conflated hazard or uncredited monitoring for each open objective
  • A closure order that separates the failure conditions before the requirement traces above them

Who uses the output

  • Safety and certification engineers assembling the navigation submittal
  • Engineering leads deciding how to credit integrity monitoring against the hazard
  • Compliance managers tracking safety-objective closure before a finding response

How the work fits into the transaction or program

The review runs before submittal or after a first finding, giving the navigation team a clear read on whether the misleading-information hazard is assessed correctly and its mitigation credited. Its closure order feeds the certification plan so the failure conditions are separated first, before the requirement traces built on them.

Start with a single asset

Confirm requirements trace through verification.

Jurisdiction-specific considerations

FAA and EASA both treat undetected erroneous navigation output as a serious condition but can differ on the integrity and monitoring credit they accept. The review flags where a mitigation credited under one authority may need stronger substantiation under the other.

Regulatory limits

The review maps evidence to ARP4761A objectives and identifies gaps. It does not set a hazard classification on the authority's behalf, agree a compliance finding, or make an airworthiness determination on the navigation equipment.

What this review does not cover

Specific to this review

  • For navigation equipment the severe case is misleading information, not loss of function, and safety assessments that conflate the two understate the hazard that matters most.
  • Integrity and detection monitoring is often designed in but never traced to a safety requirement, so ARP4761A cannot credit a mitigation that physically exists.
  • Separating undetected erroneous output as its own failure condition usually raises its assessed severity, which is why reviewers probe it first on navigation packages.

Sources

Frequently asked questions

We have integrity monitoring built in. Why is the misleading-information hazard still flagged?

Monitoring only reduces the assessed hazard when ARP4761A can see it credited, which means it has to trace to a stated safety requirement tied to the failure condition. If the monitoring exists in the design but not in the requirement trace, the assessment cannot take the mitigation, and the hazard stands at its higher level.

Relevant glossary terms

Related pages

Where this fits

Talk to an engineer who has done this work

We will walk through your current state, the records or evidence involved, and a scoped first engagement.

Talk through the aircraft, records, evidence, deadline, and next useful step.