[Paper Review] Guidance on the Safety Assurance of Autonomous Systems in Complex Environments (SACE)
This paper presents the Safety Assurance of Autonomous Systems in Complex Environments (SACE), a structured methodology that integrates safety assurance into the development of autonomous systems (AS) operating in dynamic, real-world environments. SACE employs a process-driven approach with 31 assurance activities organized into eight stages, using safety case patterns to systematically generate evidence for justifying the safety of AS through traceable, verifiable, and auditable arguments across all design and operational levels, culminating in a comprehensive safety case for deployment in complex contexts.
Autonomous systems (AS) are systems that have the capability to take decisions free from direct human control. AS are increasingly being considered for adoption for applications where their behaviour may cause harm, such as when used for autonomous driving, medical applications or in domestic environments. For such applications, being able to ensure and demonstrate (assure) the safety of the operation of the AS is crucial for their adoption. This can be particularly challenging where AS operate in complex and changing real-world environments. Establishing justified confidence in the safety of AS requires the creation of a compelling safety case. This document introduces a methodology for the Safety Assurance of Autonomous Systems in Complex Environments (SACE). SACE comprises a set of safety case patterns and a process for (1) systematically integrating safety assurance into the development of the AS and (2) for generating the evidence base for explicitly justifying the acceptable safety of the AS.
Motivation & Objective
- To address the challenge of ensuring safety in autonomous systems (AS) operating in complex, dynamic, and unpredictable real-world environments.
- To provide a systematic, process-driven methodology that integrates safety assurance into the full lifecycle of AS development.
- To generate explicit, structured, and evidence-based safety cases that justify the acceptable safety of AS through traceable argument patterns.
- To support safety engineers, developers, and assessors with a standardized framework for safety assurance, verification, and validation in AS applications.
- To enable reliable safety assessment and certification of AS in high-risk domains such as autonomous vehicles, healthcare, and domestic robotics.
Proposed method
- SACE is structured as an 8-stage process that runs in parallel with systems engineering, integrating safety assurance across all development and operational phases.
- Each stage uses a safety case pattern (e.g., AS Operating Context, Hazardous Scenarios, Safe Operating Concept) to structure arguments for safety justification.
- The methodology includes 31 assurance activities, each with defined inputs, outputs, and evidence requirements, such as verification logs and formal models.
- Activities are organized to ensure traceability from system-level safety requirements down to component-level design and verification.
- The approach supports both testing and formal verification, with specific claims and justifications required for each verification strategy.
- Each stage culminates in an instantiated assurance argument pattern that contributes to a cumulative, auditable safety case.
Experimental results
Research questions
- RQ1How can safety assurance be systematically integrated into the development lifecycle of autonomous systems operating in complex environments?
- RQ2What structured argument patterns are required to justify the safety of autonomous systems across multiple abstraction levels and operational contexts?
- RQ3How can evidence from testing, formal verification, and scenario analysis be systematically collected and linked to safety requirements?
- RQ4What criteria ensure that safety cases are sufficient, traceable, and auditable for regulatory and stakeholder review?
- RQ5How can the safety of autonomous systems be assured when operating outside their defined operational domain?
Key findings
- The SACE methodology provides a comprehensive, process-driven framework with 31 assurance activities that enable systematic safety case development for autonomous systems.
- Each stage of SACE produces an instantiated safety case pattern that contributes to a cumulative, auditable, and traceable safety argument.
- The approach supports both testing and formal verification, with specific claims (e.g., G8.2 for testing, G8.6 for formal verification) to justify the sufficiency of verification evidence.
- The methodology ensures traceability of safety requirements from system-level intent down to component-level implementation and verification.
- The framework enables validation of safety requirements through evidence-based claims, including justification for model assumptions and test representativeness.
- The final output is a structured, evidence-rich safety case that demonstrates compliance with safety requirements across all tiers of system design and operation.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.