Functional Safety Certification for Robotaxis: ISO 21448 Explained

Date
2027-06-30
Location
Online
Host
Zach L

About this event

An Applied Practicum for Regulatory Affairs Specialists pursuing functional safety certification. A live 30-minute applied practicum on ISO 21448 (SOTIF - Safety of the Intended Functionality) for robotaxis, built for regulatory affairs specialists pursuing functional safety certification. What We'll Cover: What ISO 21448 (SOTIF - Safety of the Intended Functionality) requires and how its scope applies to robotaxis Mapping ISO 21448 clauses to the certification evidence assessors expect System-specific hazards and safety functions typical of robotaxis Common findings that delay certification, and how to avoid them A practical readiness roadmap for regulatory affairs specialists preparing for assessment Related topics: ISO 21448 · Robotaxis · functional safety certification · functional saf

Topics

Registration

View event page

About ISO 21448 (SOTIF - Safety of the Intended Functionality)

This event covers the compliance, engineering, and verification requirements defined by ISO 21448.

ISO 21448 addresses hazards not caused by system faults but by functional insufficiencies — sensor limitations, algorithm weaknesses, and foreseeable misuse — the central safety problem of perception-based and automated driving functions.

What it regulates

Identification of triggering conditions and functional insufficiencies, the four-area model (known/unknown × safe/unsafe scenarios), verification and validation strategies to shrink unknown-unsafe space, and residual-risk argumentation for release.

Who must comply

Developers of ADAS and automated driving features, increasingly any perception-dependent machine function beyond automotive.

Key requirements of ISO 21448

  • Specification and design measures against insufficiencies
  • Identification/analysis of triggering conditions (scenario-based)
  • V&V: simulation, track, field with statistical arguments
  • Operation phase: field monitoring feeding the safety case

Key concepts: ISO 21448

Functional insufficiency
A performance limitation of the intended function (not a malfunction) that can cause hazard in specific scenarios.
ODD
Operational design domain — the declared conditions within which the function's safety argument holds.
Known/unknown unsafe areas
The SOTIF quadrants; engineering shrinks unsafe areas and bounds the unknown residual.
Triggering condition
The scenario element (low sun, rain, unusual object) activating an insufficiency.

Frequently asked questions: ISO 21448

How is SOTIF different from ISO 26262?

26262 assumes hazards come from E/E faults; SOTIF covers hazards with the system working as designed but insufficient for the scenario. Automated driving safety cases need both, plus cybersecurity (21434).

How much validation mileage is enough?

Pure mileage arguments are statistically hopeless for rare events; accepted practice combines scenario-based testing, simulation at scale, targeted edge-case exposure, and field monitoring with defined leading indicators.

Standard information based on the published text of ISO 21448 (SOTIF - Safety of the Intended Functionality). Event content is provided by the host. For authoritative guidance, consult the official standard body.