Browse Topic: Safety management systems

Items (31)
This study examines the involvement of authorities in the development processes of aviation and automotive industries by comparing the depth, frequency, and stages of their engagement. The background of this work is an ongoing research initiative focused on transferring methods from aviation to automotive. The method used in this study is an investigation of best practices across both industries. Based on this investigation, two proposals were developed for managing complex technologies, such as autonomous systems. Both proposals advocate for increased authority involvement, particularly during the early stages of projects. One proposal recommends making this enhanced involvement mandatory, while the other suggests it as a guideline rather than a requirement. To assess the benefits of these proposals, a human-input–based feasibility quantification method was applied. This method assesses feasibility on a scale from 0 to 10, where 0 represents the lowest score, 5 is neutral, and 10 is the highest. The results indicate that the proposal recommending enhanced authority involvement achieved a score of 5.79, whereas the proposal mandating it scored 4.54. The conclusion of this study is that increasing authority involvement offers slight benefits when implemented as a recommendation rather than as a mandatory requirement.
Akkus, YusufAnnighöfer, Björn
Urban air mobility with electric Vertical Take-Off and Landing (eVTOL) aircraft faces critical micro-weather and infrastructure readiness challenges. This paper proposes a novel socio-technical solution: a tokenized gamification platform that crowdsources hyper-local wind and weather data to enhance operational resilience. We outline the safety gap left by traditional aviation weather systems (METAR, AWOS, ASOS) in urban environments, and leverage community engagement to fill it. The proposed system integrates with Unmanned Traffic Management (UTM) and Safety Management Systems (SMS) to validate user-contributed micro-weather observations, incentivize accurate reporting through tokens and skill-level progression, and feed data into AI-driven forecasts. Early proof-of-concept results indicate improved wind hazard detection and robust user participation. By aligning with emerging regulations (FAA, EASA, DGCA) and test frameworks, this crowdsourced micro-weather ecosystem shows potential to uplift eVTOL safety, build public trust, and support city-scale planning for advanced air mobility.
Udipi, RangaRaul, SwarabEsturi, Ankith
Safety assurance of Cooperative, Connected, and Automated Mobility (CCAM) systems is a crucial factor for their successful adoption in society, yet it remains a significant challenge. The SUNRISE project has consolidated previous and on-going efforts, and developed a harmonised Safety Assurance Framework (SAF) designed to operationalise the UNECE New Assessment/Test Method (NATM), targeting a wide range of stakeholders including (but not limited to) certifiers, regulators, manufacturers, suppliers, researchers, and assessors. It incorporates a scenario-based approach, underpinned by the system’s Operational Design Domain (ODD) and behaviour for safety assessment. In line with NATM, the SAF consists of multiple pillars: the Audit of manufacturer processes and Safety Management Systems, In-Service Monitoring and Reporting (ISMR) to ensure continued safety during deployment, and Performance Assurance to generate and evaluate safety evidence pre-deployment. While all pillars are integral, this paper concentrates on the Performance Assurance pillar, which integrates three interlinked blocks: Scenario, Environment, and Safety Argument. The Scenario block covers the creation, the formatting, and the storage of logical and concrete scenarios. The Environment block contains an ODD and behaviour based scenario query and retrieval, scenario parameter concretisation, test environment allocation, and test execution. The Safety Argument block contains test evaluation, coverage analysis, safety case formulation, and evaluation decision outcome. Within the SUNRISE project, the SAF has been demonstrated across multiple use cases (various ODDs, systems, and test environment), and several ongoing/ future international collaborative projects are building on top of the SUNRISE SAF and applying it to an even wider set of use cases.
Zhang, XizheKhastgir, Siddarthade Vries, StefanHillbrand, BernhardOp den Camp, OlafBolovinou, AnastasiaBourauel, BryanEhrenhofer Gronvall, John FredrikMenzel, ThaddäusNieto, MarcosStettinger, GeorgJennings, Paul
As Automated Driving Systems (ADS) technology advances, ensuring safety and public trust requires robust assurance frameworks, with safety cases emerging as a critical tool toward such a goal. This paper explores an approach to assess how a safety case is supported by its claims and evidence, toward establishing credibility for the overall case. Starting from a description of the building blocks of a safety case (claims, evidence, and optional format-dependent entries), this paper delves into the assessment of support of each claim through the provided evidence. Two domains of assessment are outlined for each claim: procedural support (formalizing process specification) and implementation support (demonstrating process application). Additionally, an assessment of evidence status is also undertaken, independently from the claims support. Scoring strategies and evaluation guidelines are provided, including detailed scoring tables for claim support and evidence status assessment. The paper further discusses governance, continual improvement, and timing considerations for safety case assessments. Reporting of results and findings is contextualized within its primary use for internal decision-making on continual improvement efforts. The presented approach builds on state of the art auditing practices, but specifically tackles the question of judging the credibility of a safety case. While not conclusive on its own, it provides a starting point toward a comprehensive "Case Credibility Assessment" (CCA), starting from the evaluation of the support for each claim (individually and in aggregate), as well as every piece of evidence provided. By delving into the technical intricacies of ADS safety cases, this work contributes to the ongoing discourse on safety assurance and aims to facilitate the responsible integration of ADS technology into society.
Schnelle, ScottFavaro, FrancescaFraade-Blanar, LauraBroce, HollandMiranda, JustinWichner, DavidShrivastava, Mohit
Current regulations (e.g., Title 14 of the United States Code of Federal Regulations, or 14 CFR) define design requirements for oxygen system provisions for protection of crewmembers and passengers following emergency events such as in-flight decompression. This aerospace information report (AIR) addresses the operational oxygen system requirements for a decompression incident that may occur at any point during a long-range flight, with an emphasis for a decompression at the equal time point (ETP). This AIR identifies fuel and oxygen management contingencies and presents possible solutions for the efficient, safe, and optimum fuel/oxygen flight continuation. Oxygen management is a critical concern for all aircraft, ranging from single-engine types operating above 10000 feet to complex, high-performance aircraft equipped with supplemental oxygen systems. Proper planning ensures compliance with regulations and supports pilot and passenger safety at higher altitudes. This document provides a method which can help guide users in developing an oxygen solution for their aircraft. This document is not intended to change, modify, or alter any existing design or installation procedure and has been mostly developed for flight operations.
A-10 Aircraft Oxygen Equipment Committee
Abstract The technological advancements in the automotive industry have seen a significant leap with the introduction of automated driving system (ADS)-equipped Vehicles (AVs), with potential for enhanced safety, efficiency, and mobility. As the development of an AV transitions from the stages of conceptual design to deployment, assessing the maturity of the technology through a structured framework is crucial. This paper proposes the adaptation of the Technology Readiness Level (TRL) framework originally developed by NASA (and adopted widely in a variety of industries) to the AV industry to provide a consistent, understandable, and transparent method to describe an AV product’s stage of development. The TRL framework is mated to the existing safety case framework (SCF) developed in the Automated Vehicle – Test and Evaluation Process (AV-TEP) Mission, a collaboration between Science Foundation Arizona and Arizona State University. The claim that the AV is ready to transition from one TRL to the next is argued through the satisfaction of requirements for each TRL and supported by evidence and data. The requirements for each level are established for the three pillars of the AV-TEP Mission’s SCF, each of which address safety-critical aspects of AV development: the Safety Management System pillar focuses on organizational safety and mitigation of identified risks, the Design Methods pillar emphasizes the importance of rigorous engineering design practices, and the Testing pillar validates and verifies the AV and its subsystems through various testing methods. This paper aims to address the need for all stakeholders (AV developers, regulatory agencies, and the general public) to concur on the development state of an AV at any given time and provide an agreed-upon roadmap for when and how the transition through each stage of development should occur. The ultimate culmination of this TRL-framed process is the on-road deployment of the AV in its particular ODD and usage specification in a manner that assures public safety.
Swaminathan, SunderWishart, JeffreyZhao, JunfengRusso, BrendanRahimi, Shujauddin
The Automated Mobility Partnership (AMP) is a consortium of industry and academic stakeholders dedicated to advancing Automated Driving Systems (ADS) through a comprehensive suite of tools, datasets, and methodologies. The AMP portal integrates events from over 35 million miles of naturalistic driving data including thousands of annotated crashes and near-crashes and a decade of U.S. police-reported crash data curated by the Virginia Tech Transportation Institute. The portal enables data discovery, visualization, processing, and analysis through secured web access. This paper briefly describes the AMP portal and examines its utility in developing and evaluating the safety of ADS using standardized processes. For the examination, we provide examples based on generic automated driving functions, guided by the Safety of the Intended Functionality (SOTIF) framework. The results show that AMP is instrumental in identifying recorded real-world cases in which the hazardous behavior of a system can lead to harm, through the AMP case browser and advanced filtering capabilities. The portal uses the naturalistic driving data to generate essential exposure, controllability, and severity metrics for defining risk-based acceptance criteria and evaluating a system against these criteria. By combining vehicle sensor data with environment and driver face video recordings, AMP can also provide evidence to develop driver glance-based criteria for monitoring systems linked to the automated driving functions. Further, the work elaborates on the potential for AMP data-driven scenario generation to support verification and validation activities, as well as on the potential of the data to provide human reference to support post-release monitoring activities.
Antona-Makoshi, JacoboWilliams, VickiAli, GibranSullivan, KayeTerranova, PaoloKefauver, KevinHatchett, Alex
Safety Management Systems (SMSs) have been used in many safety-critical industries and are now being developed and deployed in the automated driving system (ADS)-equipped vehicle (AV) sector. Industries with decades of SMS deployment have established frameworks tailored to their specific context. Several frameworks for an AV industry SMS have been proposed or are currently under development. These frameworks borrow heavily from the aviation industry although the AV and aviation industries differ in many significant ways. In this context, there is a need to review the approach to develop an SMS that is tailored to the AV industry, building on generalized lessons learned from other safety-sensitive industries. A harmonized AV-industry SMS framework would establish a single set of SMS practices to address management of broad safety risks in an integrated manner and advance the establishment of a more mature regulatory framework. This paper outlines a proposed SMS framework for the AV industry based on robust taxonomy development and validation criteria and provides rationale for such an approach.
Wichner, DavidWishart, JeffreySergent, JasonSwaminathan, Sunder
The safety of power batteries is an important issue that has attracted widespread attention in new energy vehicle technology. In this paper, Generative Adversarial Networks (GAN) are introduced, and the data generation and fault diagnosis of power battery life-cycle data are carried out. GAN is composed of a pair of generators and discriminators, combining signal processing with neural networks, using the discriminator architecture based on Fourier transform and the generator architecture based on wavelet transform, so that the neural network can learn the characteristics of power battery life-cycle data from the perspective of time and frequency domain, and use the good performance of wavelet transform in data denoising and repair to generate high-quality and low-noise data, and use Fourier transform to target the characteristics of periodicity. Identify and distinguish the periodic characteristics and time-frequency domain data characteristics in the generated data and laboratory data. The results show that the GAN architecture adopted in this paper can generate high-quality power battery charge and discharge cycle data, and can observe the location of power battery fault data.
Tan, PiqiangYang, AojiLiu, XiangYao, Chaojie
Advanced Autonomous Vehicles (AV) for SAE Level 3 and Level 4 functions will lead to a new understanding of the operation phase in the overall product lifecycle. Regulations such as the EU Implementing Act and the German L4 Act (AFGBV) request a continuous field surveillance, the handling of critical E/E faults and software updates during operation. This is required to enhance the Operational Design Domain (ODD) during operation, offering Functions on Demand (FoD), by increasing software features within these autonomous vehicle systems over the entire digital product lifecycle, and to avoid and reduce downtime by a malfunction of the Autonomous Driving (AD) software stack. Supported by implemented effective management systems for Cyber Security (R155), Software Update Management System (R156) and a Safety Management System (SMS) (in compliance to Automated Lane Keeping System (ALKS) (R157)), the organizations have to ensure safe and secure development, deployment and operation to fulfill legal requirements. Based on senior expert interviews from relevant AD stakeholders, a blueprint is developed to support the deployment and scalability of AD systems. Relevant roles for the operation will be presented and current gaps in the industry, regulation and academia are highlighted.
Bublitz, LucasHerdrich, Michael
An Interface Approach for Safety and Cybersecurity Management Systems in Highly Automated Driving VehiclesSAE-PP-0030410/28/2022
To ensure safety and security of highly automated driving systems one shall make sure all risks are reduced to a reasonable level and an all potential cyberattacks are addressed with necessary protection. Because of the complexity of such vehicle systems, systematic and structured management approaches are vital to maintaining safety via cybersecurity (CS). The interface of Safety Management System (SMS) with Cybersecurity Management System (CSMS) is one of the key aspects to ensuring that potential safety issues are addressed. Both management systems include planning, concepts, and process development, with significant areas of overlapping management systems is required. Regarding the management systems interface and distribution, it is still a challenge that Highly Automated Driving (HAD) vehicles needs to overcome by means of effective implementation and strategies with continuous improvement and a reduction of miscommunication. From that motivation, a set of engineering risk management framework are proposed in this paper. Subsequently, introducing the interface areas between the safety and the cybersecurity domain is one of the focus areas of this paper, together with the representation of the interface management activities with exemplary interaction template. Additionally, mapping in between safety and cybersecurity related standards in terms of evidence and management systems is represented partially to support both safety case and security assurance.
Khatun, MarzanaWagner, FlorenceJung, RolfGlaß, Michael
With the degradation of lithium-ion batteries, the battery safety performance changes, which further influences the safe working window. In this paper, the pouch ternary lithium-ion battery whose rated capacity is 4.2 Ah is used as the research object to investigate the impact of the high-temperature calendar and cyclic aging on tolerance performance. The overcharge-to-thermal-runaway test is performed on the fresh cell and aged cell (90% SOH). The inflection point of voltage for aged cells appears earlier than that of the fresh cell, while the voltage corresponding to the inflection point is the same for them, which means that the voltage at which lithium plating occurs is the same. However, the voltage plateau and the crest voltage before thermal runaway of aged cell are significantly higher than that of the fresh cell. Besides, ohmic heat, reversible heat, and side reaction heat make contribution to the thermal runaway triggering. Among them, the side reaction heat plays a dominant role. Moreover, the ratio of heat generated by side reactions increases with aging. Compared with fresh cells, the thermal runaway triggering temperature of the high-temperature aging cell is increased. However, the duration of high-temperature cyclic aging cell is reduced, while the duration of high-temperature calendar aging cell is increased. Furthermore, although the maximum temperature of the aged cell has not changed significantly, the maximum temperature rise rate is significantly reduced, which may be caused by the loss of active materials. The aim of this article is to provide guidance for the design of battery safety management systems.
Zhang, GuangxuChen, SiqiZhu, JiangongDai, HaifengWei, Xuezhe
Australia has embarked on an extraordinary reform to design, develop and implement a new and contemporary Defence Aviation Safety Framework. The program seeks to establish a single Defence Aviation Safety Authority (DASA) and issue a comprehensive and integrated suite of Defence Aviation Safety Regulation (DASR) for initial and continuing airworthiness, flight operations, air navigation, aerodromes (inclusive of ship-borne heliports) and safety management systems. While reforms of this scale can often be triggered by reviews into major aircraft accidents, such as The Nimrod Review by Charles Haddon-Cave QC in October 2009, Australia initiated the reform when new aircraft fleets were being introduced and at a time of arguably high-levels of aviation safety. The purpose of this paper is therefore to explain the compelling reason for change; providing a twenty-five-year retrospective analysis of Australia’s previous Defence aviation safety framework to give a rich picture of the difficulties faced by increased commercialization from the late 1990s, globalization in the 2000s, and the recent emergence of strict work, health and safety legislation in Australia.
Hood, JamesMarzocca, PierSinha, Arvind
This document describes guidelines, methods, and tools used to perform the ongoing safety assessment process for transport airplanes in commercial service (hereafter, termed “airplane”). The process described herein is intended to support an overall safety management program. It is associated with showing compliance with the regulations, and also with assuring a company that it meets its own internal standards. The methods identify a systematic means, but not the only means, to assess ongoing safety. While economic decision-making is an integral part of the safety management process, this document addresses only the ongoing safety assessment process. To put it succinctly, this document addresses the “Is it safe?” part of safety management; it does not address the “How much does it cost?” part of the safety management. This document also does not address any specific organizational structures for accomplishing the safety assessment process. While the nature of the organizational structure is significant to the quality of a safety program, this document focuses on the functions to be accomplished and does not attempt to define what the structure should be. The intent is to leave the greatest amount of flexibility to the organizations that use this document.
S-18C Ongoing Safety Assessment Committee
Aviation Oxygen Safety Management System Analysis2018-01-60014/15/2018
Oxygen has been a significant variable in flight operations for nearly 60 years. Today, the use of oxygen is almost synonymous with rocket, jet and turbo-prop operations affecting more than 45,000 aircraft worldwide. Today’s pilot flies farther, higher and longer than ever before, and does so at an ever increasing frequency. While the past 60 years have yielded tremendous advances in propulsion, avionics, materials and many other areas, oxygen and its role in aviation has remained largely stagnant. Although considered a major aircraft system and an essential component in high altitude operations, the orthodox mantra of ‘engineering it better’ has produced only limited results, most of them in the area of dispensation equipment (masks). In recent years Aeronautical Data Systems and collaborative entities have begun working to create a standardized and comprehensive aviation oxygen safety management system. This paper includes a general examination of what a new aviation oxygen doctrine would entail, how it would diverge from existing industry policies, and how it would improve industry safety. This analysis is derived from work produced in an earlier collaboration with the University of North Dakota Aerospace Foundation. This study was initially created in an attempt to improve the oxygen safety training offered to its aeronautics/human factors students. This document is an evolution of the initial study intended to create discussion among industry leaders and specialists in order to generate broader feedback and consensus regarding aviation oxygen safety. The ultimate objective of this paper is to lead into a final and standardized method of implementing an Oxygen SMS Module. This paper diverges from traditional thinking in that it applies an information and skill based solution to a system that has otherwise been viewed as a hardware problem. To put it simply: Aircraft oxygen systems have possessed the capacity for substantial operational flexibility for a very long time. What has been absent is the ability to synthesize oxygen data into a legible format and the education to utilize this information to its greatest effect. Over the past decade advances in software, electronics, telecommunications and physiological research have provided the components necessary for a true modernization of aviation oxygen. We assert that these advances can collectively yield a new system of oxygen safety that delivers to aviators an unprecedented level of capability in planning for, reacting to, and surviving an oxygen contingency.
Stabile, Jim
Safety Management Systems (SMS) are mainly based on an operational feedback approach for continuous safety enhancement. Closed loop approaches have been dramatically developed and applied in aeronautics by control engineers. In this article, SMS is redefined in terms of automatic control and this analogy leads to the identification of three classical feedback strategies. The theoretical effect of these strategies on performances is also discussed. As in any closed loop systems, the importance of understanding how the mission stakeholders react will be found to be particularly crucial. The last aspect of this analogy is discussed through quantitative SMS, or the standard use of SMS indicators. Several aspects of decision making and quantitative analysis are then discussed.
Girondin, VictorMorel, Stephane
Helicopter Flight Data Monitoring (HFDM) can be a central and effective component of an operator's safety management strategy. By capturing and processing operational information from aircraft flight data, the operator/owner can identify safety hazards, facilitate monitoring and assessment of the interaction between the pilot and the aircraft, initiate remedial actions, and support continuous improvement of the safety management system. The Robust HFDM system described in this paper also provides improved results via automation of data download and reporting. Automation is achieved by formalizing the concept of a flight operation, adding exceedance reporting, and improving the HFDM architectural design to allow for the transfer of data to secure ground based storage. In the extreme, robust HFDM also provides protection of data in the event of a mishap event that would usually only be available via post incident analysis of a crash survivable memory. This paper discusses the formalized concept of a flight operation, how regime recognition has been tailored to support the more robust application, and finally the addition of exceedance monitoring. The changes in architecture, processing and data transfer, result in a new and more robust HFDM system.
Bechhoefer, EricAugustin, Michael
Achieving functional safety in mechatronic systems with growing product functionality is a major challenge in systems engineering. Following the current discussion, this challenge is mostly allocated to electronics and software development. For most of the scenarios this focus is feasible. Product design - the construction of the product - defines the properties and the appearance of the product by shape, material and assembly. So, the product design is often not under control of the safety management system. A hazardous deviation of part shape can be easily identified after the parts product or at least at its mounting. A wrong assembly is controlled by assembly documentation or data (e.g. screw torques) and identified at end of assembly line checks. The identification of a hazardous material choice depends on the product material class. Product materials can be separated into two classes: passive or active materials. Passive materials (e.g. car body) can be distinguished in as passive materials with constant shape (stiff) and variable shape (flexible) (e.g. damper, spring). The liability of those materials regarding their usage in the product is tested in labs in prototypes in prior. Active materials (e.g. fluids, gases), or functional materials fulfill, trigger or directly influence the functionality of the product. The choice of a functional material is not always made by the electronics engineering. Therefore, it is not under control of safety management processes. Never the less functional material, especially with radical behavior, underlie other safety regulation. Explosives for example, can be integrated in a product or system and are restricted by specific standards. This technology report reflects the verification methods of functional materials today. The responsibility of the product design engineer is discussed as well as the relevant standards. The challenge of achieving complete product compliance with functional materials is shown by the technology analysis of the Takata airbag recall. The required and available methods to control risks of functional materials choice and change are listed and rated. Gaps in existing engineering processes and regulations are identified. A strategy to close those gaps is explained.
Koark, Fabian Jorg UweBeul, Christian
ABSTRACT Northrop Grumman has developed a software and hardware solution to provide enhanced 360 degree local situational awareness (LSA) to enable the warfighter with an overmatch capability on today’s modern battlefield. The architecture exploits technological gains in cameras, video processing, and video compression. The approach allows rapid comprehension of local and remote situational views presented with operational relevance for a ground combat platform or tactical wheeled platform crew. The 360 Degree LSA approach provides direct visualization of relative positioning of targets, threats, and lines of fire; and additionally offers common situational understanding / operational picture from the dismounted soldier to higher echelon commands. The approach provides prioritized information through LSA software to provide an enhanced view to the warfighter whereas the squad leader becomes an integral part of the crew with a view of the common operating picture (mounted) and additional sensors on tablet or handheld device (dismounted via wireless). The approach uses a platform agnostic form factor with components that can be selected and applied to legacy or new platforms based on their size, weight, power, and mission constraints.
Viscovich, ChristopherGeoghegan, SusanWorthy, David
ABSTRACT While helicopters are used for a myriad of purposes in rural and urban environments, their true potential can be measured by the support they can offer in extreme and remote areas. This paper describes a Northern Canadian operator, Universal Helicopters Newfoundland and Labrador LP, the equipment used, the tasks performed, the working conditions and the risks and challenges faced . The principal areas of operation include the Province of Newfoundland and Labrador, the Ungava Peninsula and Canada's high and eastern Arctic. The company operates 19 light and intermediate helicopters in one of the most challenging environments in the world. The aircraft are equipped with operational equipment and accessories for operation in temperature extremes which test not only the machinery but the crews that fly and maintain them. A Safety Management System is in place to properly identify and manage the unique risks of operating in the north as well as logistical support that recognizes associated added costs. The presence of multiple aircraft and their adjacency to remote communities often results in requests from authorities to assist in Search and Rescue operations. Despite challenges from wildlife, weather, topography and a long distance supply and communications chains, operators are able to conduct helicopter operations to support scientific research and natural resource development.
Goodyear, Geoff
This document describes a process that may be used to perform the ongoing safety assessment for (1) GAR aircraft and components (hereafter, aircraft), and (2) commercial operators of GAR aircraft. The process described herein is intended to support an overall safety management program. It is to help a company establish and meet its own internal standards. The process described herein identifies a systematic means, but not the only means, to assess continuing airworthiness. Ongoing safety management is an activity dedicated to assuring that risk is identified and properly eliminated or controlled. The safety management process includes both safety assessment and economic decision-making. While economic decision-making (factors related to scheduling, parts, and cost) is an integral part of the safety management process, this document addresses only the Ongoing Safety Assessment Process. This Ongoing Safety Assessment Process includes safety problem identification and corrective action, tracking of problems, the application of “Lessons Learned” to improve the efficiency of the process, and reduction of the time to achieve corrective action in the field. ARP5150 is the standard for the safety assessment of Transport Airplanes in Commercial Service. ARP5151 specifies the safety assessment process for GAR aircraft in Commercial Services. While the processes are similar, their implementations are different due to operations, data availability, and sizes of individual operations.
S-18C Ongoing Safety Assessment Committee
This paper describes the process in which Atlantic Software Technologies (AST) and Sikorsky Aircraft Corporation (Sikorsky) developed a web-based Aviation Safety Management System. The system as an aviation operations management tool improves overall fleet safety and business quality while also reducing cost and redundancy. Adaptive Safety Management System (ASMS) serves as a proven safety risk management tool in support of the much anticipated FAA regulation which will soon require a Safety Management System (SMS) throughout the vertical flight industry.
Muhammad, SamadStatkevicus, Joel
Unmanned Aircraft Systems (UAS) emerge as a viable, operational technology for potential civil and commercial applications in the National Airspace System (NAS). Although this new type of technology presents great potential, it also introduces a need for a thorough inquiry into its safety impact on the NAS. This study presents a systems-level approach to analyze the safety impact of introducing a new technology, such as UAS, into the NAS. Utilizing Safety Management Systems (SMS) principles and the existing regulatory structure, this paper outlines a methodology to determine a mandatory safety baseline for a specific area of interest regarding a new aviation technology, such as UAS Sense and Avoid. The proposed methodology is then employed to determine a baseline set of hazards and causal factors for the UAS Sense and Avoid problem domain and associated regulatory risk controls.
Oztekin, AhmetLee, Xiaogong
Managing Risk Reduction using a Relative Risk Prioritization Tool2007-01-38719/17/2007
The Safety Management System (SMS) provides an environment where undesired events (proactively or reactively identified) are evaluated for the effect on safety using Risk Analysis. When the risk is evaluated, an interim risk reduction (mitigating action) may be applied to reduce the risk to a level that allows operations for a longer period before the safety issue is fully resolved. The risk assessment provides a means of evaluating the risk level and it may be difficult to quantify the “benefit” of interim mitigations that will reduce the risk. Prioritization of issues in the same risk category of the Risk Matrix is often simplified to a schedule and logistics basis of the final corrective action and often does not adequately show the benefit of the interim mitigating actions taken. Employing a concept used in System Reliability Analysis, the Design / Process Failure Modes and Effects Analysis (Design FMEA as defined in SAE J1739) uses a Risk Priority Number as a tool to identify the most significant failure modes that need to be evaluated in order to determine if redesign can mitigate the risk to a lower level. This paper will develop this concept in conjunction with an Aircraft / System Functional Hazard Assessment and acceptable level of risk (certification levels) to formulate a Risk Priority Number as a tool to rank the risks while taking into account the effectiveness of mitigating actions. A means to baseline the product acceptable level of risk / safety is also proposed in order to determine the relative risk increase from the as certified risk level.
Kavoliunas, Michael
Safety control and protection strategy of high-voltage system of electric vehicles include analysis of circuit condition before connection to high voltage terminal, transient current prevention for capacitive load, real-time monitoring and analysis of high-voltage system during operation, disconnecting strategy of high voltage terminals, vehicle dynamic safety and cooperative management of electrical systems, etc. Monitoring and analysis of some critical parameters of high voltage system such as insulation, electrical harness and connector condition are the basis and difficulties in high-voltage safety and protection. This paper presents several mathematical models of monitoring critical parameters, and experiments were also done to evaluate the model. Disadvantages of the commonly used calculation method are discussed. Single point insulation defect model is introduced and diagnosis method of multiple points defect is also discussed. To satisfy high voltage safety management system based on micro-controller, online diagnosis method of related parameters is studied. Hardware-in-loop (HIL) and complete vehicle experiment were conducted to prove the validity, response and reliability of the proposed method.
Zhao, Chun-mingLi, LeiWu, JiYuan, Qing-qiang
Safety Management Systems for Design, Manufacturing and Maintenance Providers in AviationC2215
***This course has recently been revised (August 2025) to include SMS guidance for Part 145 repair station operators, in response to the FAA's new requirements. This two-day, instructor-led course provides a deep dive into the two types of safety management systems regulated by the FAA – Aviation Safety SMS and Design & Manufacturing SMS. It is led by an expert in how to build and implement SMS in aviation. This course will include group work, case studies and an exam. A Safety Management System (SMS) is a high-level, top-down decision-making system based on proactively identifying, assessing, and controlling hazards and safety risks in the design, manufacturing, and maintenance environments. Safety Management Systems have become an internationally recognized means to improve hazard and risk identification, risk management and safety assurance. The use of an articulated Safety Management System (SMS) is required in European aviation, and is an FAA requirement for US Part 21 design & manufacturing organizations. It is voluntary for maintenance organizations in the US. These systems are recognized globally by the Joint Planning and Development Office (JPDO), International Civil Aviation Organization (ICAO), and civil aviation authorities (CAA), as well as product/service providers as the next step in the evolution of safety in aviation.
or, ScottMcDermott, David
Items per page:
1 – 31 of 31