Safety assessment evidence
Safety assessment evidence support for a major change
This review readies the safety assessment evidence behind a major change so an authority reviewer can follow every hazard from function to closed verification. A certification engineer runs it once the FHA, PSSA, and SSA drafts exist but before the package is submitted for a finding. It examines whether the failure conditions, classifications, and mitigations agree across the three documents and whether each result is tied to a requirement and its verification. You receive a gap assessment, an evidence map that links hazards to requirements, and a closure plan for the items that would otherwise stall the finding.
When this review is needed
- The FHA, PSSA, and SSA are drafted but no one has confirmed they agree with each other before submission.
- A failure condition was reclassified late and the downstream mitigations have not caught up to the new classification.
- The change touches a function whose hazard was assessed at aircraft level and now needs a system-level result that traces back up.
- A reviewer has asked how a top hazard is verified and the answer is not obvious from the assessment on file.
The problem
Safety assessment work is produced by several people over months, and the FHA, PSSA, and SSA drift apart as the design settles. A failure condition can carry one classification in the functional hazard assessment and a softer one by the time it reaches the system safety assessment, and a mitigation named in the analysis may have no requirement that forces it to exist. When the package reaches a reviewer, those seams are the first thing an experienced eye finds.
What gets reviewed
- Failure conditions and their classifications reconciled across the FHA, PSSA, and SSA
- Each hazard mitigation tied to a derived safety requirement rather than described in prose alone
- Development assurance levels allocated consistently with the classification each hazard carries
- Common-cause and particular-risk considerations reflected where the classification demands them
- Every top hazard traced to the verification evidence that closes it
- The safety results mapped against the certification basis the change is approved to
Scope this review
Tell us the asset, the event, and the evidence in scope, and we will outline a focused first engagement.
Identify what is missing against the means of compliance.
What gets validated
- A failure condition carries the same classification in the SSA that the FHA and PSSA assigned it
- Each derived safety requirement traces to the hazard that produced it and to a verification result
- Development assurance level allocation follows from the classification and holds through the analysis
- Mitigations credited in the SSA are backed by evidence rather than an intended design feature
- Aircraft-level hazards decompose to system-level results without a break in the chain
Evidence normally required
- The functional hazard assessment for the affected functions
- The preliminary and full system safety assessments with supporting analyses
- The requirement set showing derived safety requirements and their sources
- The verification results credited against each safety requirement
- The certification basis and the change impact assessment for the program
Common discrepancies
- A hazard reclassified in one document but not carried through to the mitigations that depend on it
- A credited mitigation with no derived requirement forcing it into the design
- A development assurance level that no longer matches the failure condition it was set from
- A top hazard whose verification evidence is asserted but not linked in the trace
What is at stake
A safety case whose results do not trace to requirements and verification invites questions the program answers under time pressure, after the review has already opened. Reclassifying a hazard or reconstructing a missing verification path late costs far more than catching the disconnect while the drafts are still in hand, and it can push the finding past the schedule the whole change depends on.
How the work runs
Align the three documents
Reconcile failure conditions and classifications across the FHA, PSSA, and SSA and flag every disagreement.
Trace hazards to requirements
Confirm each mitigation is forced by a derived safety requirement rather than described in the analysis alone.
Close the verification loop
Link every top hazard to the verification result that closes it and mark the gaps.
Plan the closure
Sequence the fixes so the safety case is consistent before it reaches a reviewer.
What the buyer receives
- A gap assessment listing each disconnect between hazard, requirement, and verification
- An evidence map linking every failure condition to its requirement and closure evidence
- A closure plan sequencing the fixes needed before the package enters formal review
Who uses the output
- Certification engineers assembling the safety case a reviewer will examine first
- Systems safety leads reconciling classifications across the FHA, PSSA, and SSA
- Compliance managers tracking which safety findings still block the finding
How the work fits into the transaction or program
The review sits between the safety analysis effort and the formal compliance finding, taking drafts that were produced in parallel and confirming they tell one consistent story. Its evidence map feeds the compliance matrix and the finding register, and its closure plan drives the work that has to clear before a reviewer opens the safety case.
Start with a single asset
Reduce finding cycles by checking the package first.
Jurisdiction-specific considerations
A change presented to both the FAA and EASA has to satisfy each authority's expectations for how the safety assessment is structured and credited, and the two do not weigh the same evidence identically. The review notes where a result acceptable to one system needs additional articulation for the other so the same safety case can carry through both findings.
Regulatory limits
The review checks that the safety assessment evidence is internally consistent and traceable. It does not perform the safety assessment on the program's behalf, classify a hazard for the authority, or make any airworthiness determination or grant any approval.
What this review does not cover
- Authoring the FHA, PSSA, or SSA from scratch
- Setting or accepting a failure condition classification on the authority's behalf
- Any airworthiness finding or approval of the change
Specific to this review
- Classification drift between the FHA and the SSA is the most common seam, because the two are written months apart as the design matures.
- A mitigation without a derived requirement behind it is fragile: nothing in the design forces it to stay, so it can quietly disappear at the next revision.
- Development assurance level allocation is set from the failure condition, so a late reclassification silently invalidates the DAL unless someone traces it forward.
Sources
U.S. Government (eCFR). Type certificates, STCs (Subpart E), TSO authorizations (Subpart O), PMA (Subpart K), and export airworthiness approvals (Subpart L).
Federal Aviation Administration. FAA type certification process, certification basis establishment, and compliance findings.
European Union / EASA. EASA design and production certification, STCs, ETSO authorizations, and EASA Form 1 release.
SAE International. Safety assessment methods (FHA, PSSA, SSA, FTA, FMEA) supporting development assurance level assignment.
SAE International. Development assurance process at aircraft and system level, including requirements capture and validation.
Frequently asked questions
Do you decide the classification of a failure condition for us?
No. The classification is the program's to set and the authority's to accept. The review confirms that whatever classification you have chosen is applied consistently across the FHA, PSSA, and SSA and that the development assurance levels and mitigations follow from it.
Relevant glossary terms
Related pages
Where this fits
Talk to an engineer who has done this work
We will walk through your current state, the records or evidence involved, and a scoped first engagement.
Talk through the aircraft, records, evidence, deadline, and next useful step.