ARP4761A sensor systems
ARP4761A safety-assessment evidence support for sensor systems
This support reviews the safety-assessment evidence behind an air-data, inertial, or other aircraft sensor system against the ARP4761A process. It is run by the sensor supplier preparing a certification package or working a finding, alongside the ARP4754B development assurance the sensor feeds. The work examines how erroneous-output and loss-of-output failure conditions are classified, whether calibration and drift evidence backs the accuracy claims the safety case relies on, and how installation effects change the failure picture. You get a standards map against the ARP4761A objectives, a prioritized evidence gap list, and a closure sequence.
When this review is needed
- A sensor package is being prepared for submittal and the erroneous-output failure case needs checking against ARP4761A.
- An authority questioned whether undetected erroneous output was classified separately from detected loss of output.
- The sensor is being installed in a location the original safety assessment did not assume and the failure effects have shifted.
- Calibration or drift evidence is thin and the accuracy claims the safety case depends on are not yet substantiated.
The problem
The dangerous sensor failure is rarely a clean loss of signal. It is an output that stays plausible while being wrong, and that undetected-erroneous case is the one that gets folded into the loss-of-function analysis instead of standing on its own. When it is not classified separately, the fault tree never models the path where a downstream function trusts bad data, and the DO-160G qualification proves the box survives its environment without proving the output stays valid within it.
What gets reviewed
- Erroneous-output failure conditions classified separately from detected loss of output
- Loss-of-output and slow-drift failure modes and their aircraft-level effects
- Calibration and drift evidence supporting the accuracy the safety case assumes
- Installation-dependent effects on the sensor's failure behavior
- Monitoring and detection coverage credited in the failure-condition classification
- DO-160G qualification tied to the environment at the actual sensor location
What gets validated
- Undetected erroneous output is analyzed as a distinct failure condition, not merged into loss of function
- Any detection or monitoring credited in the classification exists in the design and is verified
- Accuracy and drift claims the safety case relies on trace to calibration and test evidence
- Installation effects on the failure picture are assessed for the actual mounting and data path
- The sensor development assurance level agrees with the most severe failure condition it can cause
Evidence normally required
- The functional hazard assessment and system safety assessment covering the sensor function
- Fault trees or failure-mode analyses for erroneous and loss-of-output cases
- Calibration, accuracy, and drift test evidence for the sensor
- DO-160G qualification results for the sensor at its installed location
- The sensor requirements baseline and its ARP4754B development assurance records
Common discrepancies
- Undetected erroneous output not classified as its own failure condition
- Monitoring credited in the classification that is not actually implemented or verified
- Accuracy claims in the safety case with no calibration or drift evidence behind them
- Installation effects on the failure case unassessed because the location changed after the analysis
What is at stake
A sensor whose undetected-erroneous failure is not analyzed leaves the aircraft-level functions that consume its data resting on an assumption no one tested. When an authority reads that gap, the response usually requires new monitoring or a re-justified classification, and if the installation differs from the assessed one, the effects have to be reworked before the failure condition can even be settled.
Move from findings to resolution
Identify gaps against the means of compliance.
How the work runs
Separate the failure modes
Split erroneous output from loss of output and confirm each has its own classification and fault path.
Test the credited monitoring
Check that any detection credited in the classification exists in the design and is verified.
Back the accuracy claims
Trace the accuracy and drift the safety case assumes to calibration and test evidence.
Reconcile the installation
Assess installation effects for the actual location and sequence any rework before closing the classification.
What the buyer receives
- A standards map against the ARP4761A objectives for the sensor item
- A prioritized evidence gap list distinguishing missing analysis from missing test data
- A closure sequence noting where installation rework must precede classification work
Who uses the output
- Certification leads preparing the sensor submittal or finding response
- Safety and systems engineers reconciling erroneous-output classifications with the design
- Compliance managers tracking which evidence gaps still block the package
How the work fits into the transaction or program
This review works alongside the ARP4754B development assurance that governs the sensor and above the DO-160G qualification that proves its environmental behavior. It confirms the safety case handles the failure the aircraft-level functions actually fear, undetected bad data, so the sensor can be carried into the compliance matrix without that hole surfacing at a finding.
Start with a single asset
Confirm requirements trace through verification.
Jurisdiction-specific considerations
FAA and EASA both accept the ARP4761A process, but reviewers differ on how much detection coverage they will credit toward downgrading an erroneous-output classification. The map flags where a monitor that satisfies one authority may be treated as insufficient by the other so the supplier can plan the argument.
Regulatory limits
This work maps and checks the sensor safety-assessment evidence against ARP4761A. It does not qualify the sensor, set its failure-condition classification for the authority, or make an airworthiness determination. Those remain with the applicant and the certifying authority.
What this review does not cover
Specific to this review
- The undetected-erroneous-output case, not loss of output, is the failure that drives most sensor classifications, and it is the one most often merged away.
- Credit taken for a monitor lowers the classification only if the monitor is real and verified; a paper monitor is a finding waiting to happen.
- Moving a sensor to a new location can change its failure effects enough to reopen the classification, so installation and safety work are coupled.
Sources
SAE International. Safety assessment methods (FHA, PSSA, SSA, FTA, FMEA) supporting development assurance level assignment.
SAE International. Development assurance process at aircraft and system level, including requirements capture and validation.
U.S. Government (eCFR). Type certificates, STCs (Subpart E), TSO authorizations (Subpart O), PMA (Subpart K), and export airworthiness approvals (Subpart L).
Frequently asked questions
Why treat erroneous output separately from a sensor simply failing?
A detected loss of output can usually be flagged and handled downstream. Undetected erroneous output feeds plausible but wrong data into functions that trust it, so it is a different and often more severe failure condition. Merging the two hides the case the aircraft-level analysis most needs to see.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.