ARP4761A navigation
ARP4761A safety assessment evidence review for navigation equipment
This review holds a navigation equipment package against ARP4761A and reports where the safety-assessment evidence is incomplete. A supplier's safety or certification team uses it before submittal or when responding to a finding. It centers on the hazards specific to navigation, misleading information above all, the failure analysis that classifies them, and the safety requirements fed back to the design. What you get is a standards map, a gap list, and a sequence for closing each open objective.
When this review is needed
- A navigation equipment package needs its ARP4761A posture read before submittal.
- The misleading-information hazard for a navigation output was assessed loosely and a reviewer wants it substantiated.
- Failure analysis exists but does not clearly separate loss of function from undetected erroneous output.
- A finding response depends on knowing which navigation safety objectives the current analysis answers.
The problem
For navigation equipment the defining hazard is not losing the function but presenting wrong position or guidance without warning, and safety assessments often blur the two. Failure analysis that lumps loss of function together with undetected erroneous output produces a classification a reviewer cannot rely on, because the two failure conditions carry very different severities. When the detection and integrity monitoring that would catch misleading information is not tied to a stated safety requirement, ARP4761A cannot see the mitigation it expects.
What gets reviewed
- Functional hazard assessment separating loss of function from undetected erroneous output
- Failure analysis supporting the severity of misleading-information conditions
- Integrity and detection monitoring traced to the safety requirements it satisfies
- Safety requirements traced back to the navigation failure conditions that generated them
- The link between the safety assessment and the development-assurance evidence it drives
- Configuration control so the assessed and submitted baselines match
What gets validated
- Loss of function and undetected erroneous output are assessed as distinct failure conditions
- The severity assigned to a misleading-information hazard is supported by failure analysis
- Integrity and detection monitoring traces to a stated safety requirement that credits it
- Safety requirements trace to the navigation failure conditions they address
- The safety assessment and development-assurance evidence reference a consistent function set
Evidence normally required
- The navigation equipment certification plan and its ARP4761A objectives
- The functional hazard assessment and supporting failure analysis
- Integrity and detection monitoring design and its requirement basis
- Safety requirement sets with their origin traceability
- The development-assurance evidence the safety assessment feeds
Common discrepancies
- Undetected erroneous output folded into loss of function, understating the real hazard
- Integrity monitoring present in the design but not credited to a safety requirement
- A misleading-information severity asserted without failure analysis behind it
- A safety requirement that does not trace to a navigation failure condition
What is at stake
A misleading-information hazard that is understated because it was folded into loss of function draws a finding that reopens the classification and everything allocated from it. If integrity monitoring is present in the design but not traced to a safety requirement, the mitigation cannot be credited, and the equipment carries a higher assessed risk than it should.
Move from findings to resolution
Identify gaps against the means of compliance.
How the work runs
Split the failure conditions
Separate loss of function from undetected erroneous output and confirm each is assessed on its own.
Credit the monitoring
Trace integrity and detection monitoring to the safety requirement that lets it mitigate the hazard.
Support the severity
Check that failure analysis backs the classification assigned to the misleading-information condition.
Order the closures
Sequence so the hazard separation precedes the requirement traces and monitoring credit above it.
What the buyer receives
Who uses the output
- Safety and certification engineers assembling the navigation submittal
- Engineering leads deciding how to credit integrity monitoring against the hazard
- Compliance managers tracking safety-objective closure before a finding response
How the work fits into the transaction or program
The review runs before submittal or after a first finding, giving the navigation team a clear read on whether the misleading-information hazard is assessed correctly and its mitigation credited. Its closure order feeds the certification plan so the failure conditions are separated first, before the requirement traces built on them.
Start with a single asset
Confirm requirements trace through verification.
Jurisdiction-specific considerations
FAA and EASA both treat undetected erroneous navigation output as a serious condition but can differ on the integrity and monitoring credit they accept. The review flags where a mitigation credited under one authority may need stronger substantiation under the other.
Regulatory limits
The review maps evidence to ARP4761A objectives and identifies gaps. It does not set a hazard classification on the authority's behalf, agree a compliance finding, or make an airworthiness determination on the navigation equipment.
What this review does not cover
- Authoring the functional hazard assessment or failure analysis
- Designing or substantiating the integrity monitoring
- Agreeing the safety classification with the authority
Specific to this review
- For navigation equipment the severe case is misleading information, not loss of function, and safety assessments that conflate the two understate the hazard that matters most.
- Integrity and detection monitoring is often designed in but never traced to a safety requirement, so ARP4761A cannot credit a mitigation that physically exists.
- Separating undetected erroneous output as its own failure condition usually raises its assessed severity, which is why reviewers probe it first on navigation packages.
Sources
SAE International. Safety assessment methods (FHA, PSSA, SSA, FTA, FMEA) supporting development assurance level assignment.
SAE International. Development assurance process at aircraft and system level, including requirements capture and validation.
U.S. Government (eCFR). Type certificates, STCs (Subpart E), TSO authorizations (Subpart O), PMA (Subpart K), and export airworthiness approvals (Subpart L).
Frequently asked questions
We have integrity monitoring built in. Why is the misleading-information hazard still flagged?
Monitoring only reduces the assessed hazard when ARP4761A can see it credited, which means it has to trace to a stated safety requirement tied to the failure condition. If the monitoring exists in the design but not in the requirement trace, the assessment cannot take the mitigation, and the hazard stands at its higher level.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.