ISO 26262 with AI — ASIL evidence kept alive, not rebuilt the night before the TÜV audit.

ISO 26262 requires every safety-relevant component to be traced by ASIL, with a live FMEDA and a Safety Case held up by production evidence. iLEAN chains every control to every serial number and to the safety requirement that covers it. The audit is not cooked up — it is exported.

← See all automotive solutions

Automotive electronics production floor with a per-component marking station, a safety tablet and the iLEAN agent chaining ASIL evidence — ISO 26262 with AI
The problem

The Safety Case rests on a chain nobody sees until the auditor asks for it.

ISO 26262 is not a paper standard: it is a logical chain that runs from the vehicle hazard analysis, down through the architecture, assigns an ASIL to each safety-relevant component and requires production to prove, serial number by serial number, that the component meets the derived requirements. The classic crack sits exactly here:

  1. The FMEDA lives in a safety PDF updated “whenever there is a relevant change”.
  2. The Safety Case lives in another tool (GSN, Word, spreadsheets), with nodes that say “evidence: see annex”.
  3. The annex is the per-component evidence chain produced by the MES, the test team and process traceability — each one on its own island.
  4. On TÜV day: the safety engineer asks for the dossier of one serial number and a team spends the weekend assembling paperwork.

That happens because the cross-cutting work (joining heterogeneous formats living in different systems) was, until very recently, an impossible cost. Today it no longer is, and that is where iLEAN comes in — not to replace the safety methodology, but to close the chain underneath it.

How it fits the IRIS system

iLEAN does not invent the safety work — it chains the evidence your own line already generates.

The ISO 26262 problem in production is not a lack of evidence: it is evidence scattered across stations, files and systems that were never designed to talk to each other. iLEAN acts as putty between your MES, your test stations, your PLM and the Safety Case, without asking you to change the methodology or the safety engineer.

Tracer marks each component with its ASIL on the line. Writer chains every control to the requirement that covers it. Agent keeps the FMEDA alive with deviations detected on the plant floor. When TÜV asks for the dossier by serial number, it is already done.

The three iLEAN pieces applied to ISO 26262:

  • Tracer — reads the unique identifier of every safety-relevant component at the moment the process is already handling it (marking, dimensional check, electrical test). It tags the component with its ASIL and chains it to the batch, the process equipment and the operator. ASIL traceability is not bolted on; it becomes the shape of the chain.
  • Writer (Agent) — chains every process control (vision, dimensional, electrical, thermal, BIST) to the component, to the FMEDA safety requirement and to the Safety Case node. When the component goes out the door, it carries its signed dossier behind it, with evidence and argument. It works with no network: Tracer keeps marking and chaining on the panel's own power, because the safety chain cannot depend on WiFi.
  • Agent (live FMEDA) — the classic FMEDA is a static document. The agent cross-references the FMEDA with the deviation data the line captures (failure modes appearing more often than predicted, controls detecting more than expected) and raises review proposals with evidence to the safety engineer. The person validates and signs — the FMEDA stays alive without becoming a separate project.

See the full IRIS architecture →

Before and after

ISO 26262 by sprint vs. living ISO 26262 with iLEAN

AspectClassicWith iLEAN Tracer + Writer + Agent
FMEDAStatic PDF updated “when there is a change”Alive, fed by real plant deviations
ASIL traceabilityLoose metadata on separate sheetsThe shape of the chain: every control tied to its requirement
Safety Case“Evidence: see annex”, to be rebuiltNode linked to live evidence by serial number
Dossier request by serial numberManual sprint by the quality teamGenerated on the spot, already assembled
Product or supplier changeReopen the chain part by partThe new part enters in the same format
TÜV auditTime spent finding and assembling paperworkTime spent talking about the content
Impact estimate

Impact estimate for your plant — to be validated with your numbers.

The block below is an estimate to be validated with the specific data of your plant. We put it forward so the committee has an order of magnitude; we refine it during the diagnostic.

  • Tier-1 supplier of safety-relevant components (power electronics, sensors, actuators) with a mix of ASIL B and D, recurring TÜV audits and a sprint before each one.
  • Pilot: Tracer + Writer on one ASIL D component family, chaining FMEDA + Safety Case + production evidence. First value expected within a few weeks, with the first dossier by serial number generated on the spot instead of in days.
  • Reduction of pre-audit sprint time in the order of ≥ 30% by the end of the pilot, depending on the size of the team currently dedicated to rebuilding evidence.
  • Indicative payback between 4 and 9 months, depending on the number of audits per year, the cost of the safety/quality team dedicated to evidence and the cost of a TÜV non-conformity.
  • The hard lever is the risk of a major non-conformity at TÜV: a single blocking non-conformity in one audit can affect the nomination for the OEM's next platform — it costs far more than any pilot.

And the CIO's reasonable doubt

“Can I trust an agent to cross-reference evidence for a safety standard?” — yes, because the task is anchored: the agent does not generate the evidence, it chains it to the part, to the requirement and to the Safety Case node. Free generation is where AI hallucinates; in anchored tasks (recontextualizing a piece of data from one system to another) the best models are below 1.5% error [1]. And iLEAN's three safety rings guarantee that on anything critical only a person decides: the agent proposes, the safety engineer signs.

[1] OpenAI paper “Why Language Models Hallucinate”, 2025 — on the reliability of AI in anchored tasks.

Frequently asked questions

What people ask about ISO 26262 functional safety with AI

What does ISO 26262 require in production?

ISO 26262 (Functional Safety for road vehicles) requires every safety-relevant component to carry complete traceability from the safety requirement down to the physical component that goes out the door: ASIL classification (A, B, C, D depending on the severity of the failure, its probability of exposure and the driver's controllability), a live FMEDA (Failure Modes Effects and Diagnostic Analysis), an argued Safety Case, and production evidence proving that the component was manufactured in compliance with the derived requirements. In production, the critical piece of data is the evidence chain by serial number: which process, which control, which result for this specific unit.

How is the ASIL assigned per component?

The ASIL is derived from the vehicle hazard analysis, flows down through the system architecture and is assigned to each safety-relevant component according to its contribution to the failure chain. Your safety engineers do that with 26262 methodology, not iLEAN. What iLEAN adds is the layer underneath: when that ASIL B or ASIL D component enters production, its serial number is tagged by ASIL in Tracer; every control it passes is recorded with its evidence and chained to the safety requirement that covers it. ASIL traceability is not loose metadata — it is the shape of the chain.

How does it integrate with the product's Safety Case?

The Safety Case is the structured argument (Goal Structuring Notation or similar) proving that the product is safe for its intended use. The production part of the Safety Case needs continuous evidence that components leave the plant meeting what the safety analysis assumed. iLEAN Writer chains every process control (vision, dimensional, electrical, thermal) to the component, to the safety requirement and to the evidence that lands in the corresponding node of the Safety Case. The argument stands on live data, not on rebuilt annexes.

Does it work in high-rate series production?

Yes. ASIL traceability does not add cycle time: Tracer reads the component identifier at the moment the process was already handling it (at the marking station, at the dimensional check, at the electrical test), and the agent chains the evidence behind it without slowing the line down. The historical bottleneck was never data capture — it was rebuilding it after the fact when the auditor arrived. That is what disappears.

Does it shorten the TÜV audit?

In practice, yes: when the auditor asks for the evidence chain of a specific serial number, what takes most time in a classic audit is finding and assembling the paperwork, not examining the content. iLEAN delivers the chain already assembled and signed, which changes the nature of the conversation: the auditor moves from reviewing a reconstruction to reviewing the content. The final score depends on the content — but audit time and auditor confidence both improve because the system seen live is coherent.

Let's talk

Tell us your case and in 48h we'll send you the estimated ROI of living ISO 26262 for your plant.

We work on the real data of your production and your Safety Case, not on ours. Diagnostic with no commitment.

Request estimated ROI in 48h See automotive