Skip to content

DO-331 review

DO-331 model-based development support for avionics suppliers

This page is for avionics suppliers, OEMs, Engineering teams when Model-based toolchain adopted on a certified program puts do-331 model-based development support on the critical path. EE checks model standards, simulation credit file, model coverage analysis against the approval basis, configuration baseline, effectivity, revision status, and source records named in the brief. The buyer receives a discrepancy register, evidence map, and closure request list for the next review gate. The work tests records and certification-data traceability only; it does not replace authority, delegate, approval-holder, or authorized-person decisions.

When this review is needed

  • Use this review when Model-based toolchain adopted on a certified program starts driving schedule or commercial exposure.
  • A software lead using model-based design tools searching for how DO-331 changes objectives and what simulation credit is allowed.
  • The highest-risk breakpoint is: simulation credit claimed with an unqualified simulator, model coverage presented as if it closes structural coverage on generated code, and design models and requirements models blurred so the same artifact verifies itself.

The problem

At this gate, which DO-331 objectives replace or supplement DO-178C objectives when requirements or design live in models, and what credit simulation can legitimately take. The file set covers model standards and model coverage analysis, simulation cases and results offered as verification credit, the qualification status of the simulation environment, and the boundary where model coverage stops substituting for code coverage. Known breakpoints include simulation credit claimed with an unqualified simulator, model coverage presented as if it closes structural coverage on generated code, and design models and requirements models blurred so the same artifact verifies itself.

What gets reviewed

  • Review the buyer decision in the brief: Scope and review DO-331 model-based development evidence and the credit it can take against DO-178C objectives.
  • Trace model standards to source date, revision, owner, and current configuration.
  • Match effectivity for simulation credit file to the serial range, article version, aircraft, or fleet in scope.
  • At this gate, which DO-331 objectives replace or supplement DO-178C objectives when requirements or design live in models, and what credit simulation can legitimately take.

Scope this review

Tell us the asset, the event, and the evidence in scope, and we will outline a focused first engagement.

Identify what is missing against the means of compliance.

What gets validated

  • Record custody: model standards is checked for source, date, revision, and relationship to the current program.
  • Coverage boundary: simulation credit file must state where the evidence stops applying.
  • Baseline comparison: installation, test, drawing, and compliance references are sampled for mismatched revisions.
  • Disposition rule: unsupported assumptions are separated from acceptable limitations.

Evidence normally required

  • Source record set for model standards
  • Program file covering simulation credit file
  • Configuration baseline with approval basis and revision index
  • Open issue log tied to model coverage analysis

Common discrepancies

  • The file set covers model standards and model coverage analysis, simulation cases and results offered as verification credit, the qualification status of the simulation.
  • Known breakpoints include simulation credit claimed with an unqualified simulator, model coverage presented as if it closes structural coverage on generated code, and design models.
  • Revision mismatch leaves model coverage analysis separated from the certificate, matrix, instruction, or delivered baseline.
  • Storage completeness is higher than decision readiness because the file lacks a clear disposition for this buying stage.

What is at stake

Specific exposure for this page: simulation credit claimed with an unqualified simulator, model coverage presented as if it closes structural coverage on generated code, and design models and requirements models blurred so the same artifact verifies itself.

How the work runs

01

Frame 331 Model

Confirm the exact event, affected file set, buyer role, and decision standard before any model standards is treated as sufficient.

02

Trace Development Support

Walk the named evidence from index entry to source artifact and mark where the trail supports, conflicts with, or fails to answer the page-specific question.

03

Sort Suppliers Review

Group exceptions by closure route: document retrieval, data correction, engineering disposition, authority response, or contractual decision.

04

Package Simulation Trap

Deliver the exception list, evidence map, and owner sequence in a form that can move directly into remediation, submittal cleanup, or transaction negotiation.

What the buyer receives

  • DO-331 model-based development support discrepancy register
  • source map for model standards
  • effectivity and configuration closure list
  • decision summary with limits and escalation items

How the work fits into the transaction or program

Which DO-331 objectives replace or supplement DO-178C objectives when requirements or design live in models, and what credit simulation can legitimately take. The evidence set centers on model standards and model coverage analysis, simulation cases and results offered as verification credit, the qualification status of the simulation environment, and the boundary where model coverage stops substituting for code coverage. The likely weak points are simulation credit claimed with an unqualified simulator, model coverage presented as if it closes structural coverage on generated code, and design models and requirements models blurred so the same artifact verifies itself. The output gives the software lead a cleanup register for DO-331 model-based development support for avionics suppliers before model-based toolchain adopted on a certified program.

Start with a single asset

Reduce finding cycles by checking the package first.

Regulatory limits

For do-331 model-based development support, EE reviews model standards, simulation credit file, model coverage analysis for completeness, consistency, and traceability. The work does not issue approvals, approve data, grant relief, validate STCs, accept release certificates, or make airworthiness determinations. Final decisions remain with the responsible authority, delegate, approval holder, operator, or authorized person.

Specific to this review

  • At this gate, which DO-331 objectives replace or supplement DO-178C objectives when requirements or design live in models, and what credit simulation can.
  • The file set covers model standards and model coverage analysis, simulation cases and results offered as verification credit, the qualification status of.
  • Known breakpoints include simulation credit claimed with an unqualified simulator, model coverage presented as if it closes structural coverage on generated code,.
  • The scope uses the 331 Model Based Development question as the control point, so the review stays tied to Model-based toolchain adopted on a certified program and the buyer decision behind it.
  • The evidence starts with model standards and follows Support Avionics Suppliers Review references until every exception has a source location and a reason code.
  • The finding logic separates missing paperwork, conflicting status, stale revision data, and unsupported disposition because each class closes through a different owner.
  • The timing matters for software lead: the output is useful only if the unresolved items are visible before acceptance, submittal, handback, or negotiation pressure fixes the sequence.
  • The boundary control keeps Credit Simulation Trap Boundaries questions in the records or certification lane and sends technical acceptance issues to the authorized people who own them.
  • The handoff value comes from DO-331 model-based development support discrepancy register; it gives the next reviewer a precise map instead of another broad request for a better file.
  • The source discipline is stricter on this page than on a general audit because the claim being tested is Scope and review DO-331 model-based development evidence and the credit it can take against DO-178C objectives..

Sources

Frequently asked questions

What makes this standards review different from a general file audit?

The scope is tied to 331 model based development and to the decision named in the request. A general audit can list weak records; this pass ranks the gaps by whether they block model-based toolchain adopted on a certified program or can be closed later without changing the decision.

What evidence has to be available before this work starts?

The starting point is model standards, the current status source, and any index or matrix that tells reviewers where the supporting artifact should live. Missing inputs are logged as findings rather than filled with assumptions.

Who decides whether an open item is acceptable?

The review explains what the evidence supports and gives software lead a closure path. Acceptance remains with the buyer, operator, authority, delegated engineer, or authorized person responsible for the underlying airworthiness or certification decision.

Relevant glossary terms

Related pages

Where this fits

Talk to an engineer who has done this work

We will walk through your current state, the records or evidence involved, and a scoped first engagement.

Talk through the aircraft, records, evidence, deadline, and next useful step.