ISO 21434 + UNECE R155 compliance with AI — from the TARA to SOP, without rebuilding the file for every audit.

ISO 21434 and UNECE R155 mandate cybersecurity across the whole vehicle life cycle — TARA, controls, series production evidence, vulnerability response. iLEAN traces from TARA to SOP continuously, passes requirements down the tier-2 chain and leaves the evidence pack ready per batch. The person approves — the system invents nothing.

← See all automotive solutions

Automotive ECU assembly line with a cyber engineer reviewing the TARA and the ISO 21434 dossier on screen, next to a panel showing firmware and cryptographic signing — automotive cybersecurity with iLEAN
The problem

The TARA lives in a Word file, the controls in an Excel sheet, the production evidence in another system.

The cyber lead of a tier-1 knows the situation: the TARA was done properly at concept and development, the controls were designed, the firmware is signed, the ECUs pass secure boot. But when the OEM's auditor asks “show me that control X was applied to batch Y produced on this line with this firmware version” — the cyber team disappears for three weeks into a reconstruction sprint, cross-referencing design Word documents, validation Excel sheets and production system logs.

  1. The TARA — the threat analysis and risk assessment per cyber-relevant asset — lives in design tools and is updated every time a component changes. It is almost never in sync with the firmware coming off the production line.
  2. The controls — cryptographic signing, hardening, segmentation, secure boot — are described in project documentation and verified on the bench. The evidence that they were applied to this specific batch is scattered across logs.
  3. The tier-2 chain — suppliers delivering electronic components with their own TARA and their own evidence pack — sends signed PDFs, emails, assorted portals. Reconciling the chain down to the final component is manual work.

The result: every audit is a sprint, every OEM complaint is a scare, and responding to a post-SOP vulnerability (an OTA patch for a new CVE in the telematics module) takes weeks to cross-reference against the deployed fleet. The system complies. Complying is expensive, yes. But the real cost is in the late nights before every audit.

How it fits the IRIS system

iLEAN does not write your TARA — it keeps it alive all the way to the production line.

The problem is not a lack of cyber tools (there are plenty, and good ones for design). The problem is that the TARA → controls → production evidence → fleet chain breaks at every jump between systems. iLEAN acts as the putty that fills those cracks, without replacing your cybersecurity suite, your PLM or your MES.

Tracer keeps the TARA ↔ control ↔ batch ↔ firmware link alive. The Agent cross-references it with line data continuously. Writer prepares the 21434 dossier ready per batch. The three rings protect what is critical — OT accepts nothing without a human signature.

The three iLEAN pieces applied to ISO 21434 + UNECE R155:

  • iLEAN Tracer — maintains traceability from asset ↔ TARA ↔ control ↔ series production evidence. Every cyber-relevant component coming off the line stays linked to its threat analysis, to the applied control, to the exact signed firmware, to the batch and to the shift. No manual reconstruction.
  • iLEAN Writer — prepares the 21434 dossier per batch (or per program, depending on what the OEM customer needs) already formatted against the work products the standard demands. The cyber lead reviews and signs; Writer drafts. The audit sprint disappears.
  • iLEAN Agent — cross-references the signals from Edge and the MES (what was produced, with which firmware) against the live TARA and the up-to-date CVE database. When a new vulnerability appears in a component, the Agent identifies which batches/VINs are affected and prepares the response so the cyber team can decide the action (OTA patch, recall, temporary mitigation). It proposes; the person signs. The three rings guarantee that critical OT accepts nothing without human validation.

See the full IRIS architecture →

Before and after

Manual 21434 compliance vs. compliance with iLEAN

Aspect21434 with documents + sprintsWith iLEAN Tracer + Writer + Agent
TARAWord/design tool, frozenLive, linked to the batch produced
Evidence per batchRebuilt by cross-referencing logsDossier ready at every SOP
Tier-2 chainSigned PDFs, assorted portalsCaptured and validated in ring 2
OEM auditA 2-3 week sprintPack prepared, human review
Post-SOP vulnerability responseCross-reference the fleet by hand against CVEsAffected batches/VINs identified
R155 type approvalRecurring effort per modelContinuously auditable CSMS
Impact estimate

Impact estimate for your plant — to be validated with your numbers.

The block below is an estimate to be validated with the specific data of your program. We put it forward so the committee has an order of magnitude; we refine it during the diagnostic.

  • Tier-1 with a cyber-relevant program for a European OEM under ISO 21434, a heterogeneous tier-2 chain and an R155 obligation in the type-approval cycle.
  • Tracer + Writer + Agent pilot on the program's critical cyber-relevant component (typically the central ECU, the telematics module or the gateway). First value expected within a few weeks.
  • Reduction in audit preparation effort: ≥30% in the first 6 months (the sprint becomes a review).
  • Indicative payback between 4 and 9 months, driven by the current cost of the cyber team dedicated to collecting evidence and by the avoided risk of a delay in R155 type approval.

And the IT cyber director's reasonable doubt

“What if the AI claims a control was applied when it was not, or overlooks a real vulnerability?” — hallucination is a problem of free generation, not of anchored tasks. When the AI merely cross-references the real TARA data, the signed firmware log and the CVE database (pure recontextualization), the best models brought error below 1.5% [1]. And even so, the system is protected by the three rings: critical OT (ring 1) never accepts anything without a human signature; ring 2 validates; ring 3 proposes. It is the formalization of what industry already did informally, now with AI as the accelerator.

[1] OpenAI paper “Why Language Models Hallucinate”, 2025 — on the reliability of AI in anchored tasks.

Frequently asked questions

What people ask about ISO 21434 + UNECE R155 with AI

What does ISO 21434 require that ISO 26262 does not?

ISO 26262 covers the vehicle's functional safety (making sure a random hardware failure or a software bug does not kill anyone). ISO 21434 covers cybersecurity: making sure a deliberate attacker does not compromise the vehicle across its whole life cycle (concept, development, production, operation, decommissioning). In practice, 21434 forces something new on many OEMs and tier-1s: a TARA (Threat Analysis & Risk Assessment) per cyber-relevant asset, the associated controls, traceable evidence of every control in series production and vulnerability response throughout the vehicle's life. It is 26262, but against adversaries.

What is UNECE R155 and how does it connect to ISO 21434?

UNECE R155 is the vehicle type-approval regulation: an OEM cannot homologate a new model in the EU/UK/Japan/Korea without an audited Cybersecurity Management System (CSMS). ISO 21434 is the technical standard used de facto as evidence of CSMS compliance — meeting 21434 is the standard route to passing R155. For a tier-1 this means the OEM customer demands a cyber evidence pack per delivered component, linked to the TARA and to the project's controls. iLEAN brings that pack ready with every batch, instead of rebuilding it in an audit sprint.

How is the TARA traced through to series production?

iLEAN Tracer keeps a live link between the cyber-relevant asset identified in the TARA (ECU X, the CAN/Ethernet bus, the OTA module), the assigned control (cryptographic signing, hardening, segmentation, secure boot) and the production evidence that the control was applied to this batch, with this firmware version, on this line, with this team. Without Tracer, that chain lives in Word documents, Excel sheets and emails from the cyber project lead — and gets rebuilt by hand when the auditor asks. With Tracer, it comes out ready per batch.

What about tier-2 suppliers delivering electronic components?

21434 obliges the tier-1 to pass cyber requirements down its supply chain: the electronic component arriving from the tier-2 comes with its own evidence pack and its own component-level TARA. iLEAN Connect captures that pack whatever channel it arrives through (tier-2 portal, email, EDI, signed PDF), validates it in ring 2 against the tier-1's TARA, and only signed, validated data passes into ring 1 (the inner, sacred one). Human oversight decides when to accept and when to send it back to the supplier — the system proposes, the person signs.

What does it cost to not comply with ISO 21434 + R155?

The clearest one: the new model does not get homologated in the EU/UK/Japan/Korea. No audited CSMS, no type approval; no type approval, no sales. For a tier-1 the cost is subtler but just as hard: the OEM customer demands cyber evidence with every delivery, and its absence turns into a line-down on their assembly line or exclusion from the nomination for the next model. Estimate to be validated with your case: the annual cost of maintaining 21434 compliance with manual systems (audit sprints, a cyber team dedicated to collecting evidence) usually exceeds that of an iLEAN pilot within a few months. Indicative payback is between 4 and 9 months.

Let's talk

Tell us your case and in 48h we'll send you the estimated ROI of 21434 compliance with AI for your program.

We work on your program's real data, not ours. Diagnostic with no commitment.

Request estimated ROI in 48h See automotive