Skip to content

Safety assessment evidence

Safety assessment evidence support for a major change

This review readies the safety assessment evidence behind a major change so an authority reviewer can follow every hazard from function to closed verification. A certification engineer runs it once the FHA, PSSA, and SSA drafts exist but before the package is submitted for a finding. It examines whether the failure conditions, classifications, and mitigations agree across the three documents and whether each result is tied to a requirement and its verification. You receive a gap assessment, an evidence map that links hazards to requirements, and a closure plan for the items that would otherwise stall the finding.

When this review is needed

  • The FHA, PSSA, and SSA are drafted but no one has confirmed they agree with each other before submission.
  • A failure condition was reclassified late and the downstream mitigations have not caught up to the new classification.
  • The change touches a function whose hazard was assessed at aircraft level and now needs a system-level result that traces back up.
  • A reviewer has asked how a top hazard is verified and the answer is not obvious from the assessment on file.

The problem

Safety assessment work is produced by several people over months, and the FHA, PSSA, and SSA drift apart as the design settles. A failure condition can carry one classification in the functional hazard assessment and a softer one by the time it reaches the system safety assessment, and a mitigation named in the analysis may have no requirement that forces it to exist. When the package reaches a reviewer, those seams are the first thing an experienced eye finds.

What gets reviewed

  • Failure conditions and their classifications reconciled across the FHA, PSSA, and SSA
  • Each hazard mitigation tied to a derived safety requirement rather than described in prose alone
  • Development assurance levels allocated consistently with the classification each hazard carries
  • Common-cause and particular-risk considerations reflected where the classification demands them
  • Every top hazard traced to the verification evidence that closes it
  • The safety results mapped against the certification basis the change is approved to

Scope this review

Tell us the asset, the event, and the evidence in scope, and we will outline a focused first engagement.

Identify what is missing against the means of compliance.

What gets validated

  • A failure condition carries the same classification in the SSA that the FHA and PSSA assigned it
  • Each derived safety requirement traces to the hazard that produced it and to a verification result
  • Development assurance level allocation follows from the classification and holds through the analysis
  • Mitigations credited in the SSA are backed by evidence rather than an intended design feature
  • Aircraft-level hazards decompose to system-level results without a break in the chain

Evidence normally required

Common discrepancies

  • A hazard reclassified in one document but not carried through to the mitigations that depend on it
  • A credited mitigation with no derived requirement forcing it into the design
  • A development assurance level that no longer matches the failure condition it was set from
  • A top hazard whose verification evidence is asserted but not linked in the trace

What is at stake

A safety case whose results do not trace to requirements and verification invites questions the program answers under time pressure, after the review has already opened. Reclassifying a hazard or reconstructing a missing verification path late costs far more than catching the disconnect while the drafts are still in hand, and it can push the finding past the schedule the whole change depends on.

How the work runs

01

Align the three documents

Reconcile failure conditions and classifications across the FHA, PSSA, and SSA and flag every disagreement.

02

Trace hazards to requirements

Confirm each mitigation is forced by a derived safety requirement rather than described in the analysis alone.

03

Close the verification loop

Link every top hazard to the verification result that closes it and mark the gaps.

04

Plan the closure

Sequence the fixes so the safety case is consistent before it reaches a reviewer.

What the buyer receives

  • A gap assessment listing each disconnect between hazard, requirement, and verification
  • An evidence map linking every failure condition to its requirement and closure evidence
  • A closure plan sequencing the fixes needed before the package enters formal review

Who uses the output

How the work fits into the transaction or program

The review sits between the safety analysis effort and the formal compliance finding, taking drafts that were produced in parallel and confirming they tell one consistent story. Its evidence map feeds the compliance matrix and the finding register, and its closure plan drives the work that has to clear before a reviewer opens the safety case.

Start with a single asset

Reduce finding cycles by checking the package first.

Jurisdiction-specific considerations

A change presented to both the FAA and EASA has to satisfy each authority's expectations for how the safety assessment is structured and credited, and the two do not weigh the same evidence identically. The review notes where a result acceptable to one system needs additional articulation for the other so the same safety case can carry through both findings.

Regulatory limits

The review checks that the safety assessment evidence is internally consistent and traceable. It does not perform the safety assessment on the program's behalf, classify a hazard for the authority, or make any airworthiness determination or grant any approval.

What this review does not cover

Specific to this review

  • Classification drift between the FHA and the SSA is the most common seam, because the two are written months apart as the design matures.
  • A mitigation without a derived requirement behind it is fragile: nothing in the design forces it to stay, so it can quietly disappear at the next revision.
  • Development assurance level allocation is set from the failure condition, so a late reclassification silently invalidates the DAL unless someone traces it forward.

Sources

Frequently asked questions

Do you decide the classification of a failure condition for us?

No. The classification is the program's to set and the authority's to accept. The review confirms that whatever classification you have chosen is applied consistently across the FHA, PSSA, and SSA and that the development assurance levels and mitigations follow from it.

Relevant glossary terms

Related pages

Where this fits

Talk to an engineer who has done this work

We will walk through your current state, the records or evidence involved, and a scoped first engagement.

Talk through the aircraft, records, evidence, deadline, and next useful step.