The manufacturer shall provide a documentation package which gives access to the basic design of the complex electronic vehicle control system for which type-approval is applied (hereinafter referred to as ‘the System’) and the means by which it is linked to other vehicle systems or by which it directly controls output variables.
The function(s) of ‘the System’ and the safety concept, as laid down by the manufacturer, shall be explained.
Documentation shall be brief, yet provide evidence that the design and development has had the benefit of expertise from all the system fields which are involved.
For periodic technical inspections, the documentation shall describe how the current operational status of ‘the System’ can be checked.
the formal documentation package for the approval, containing the material listed in Section 3 (with the exception of that of point 3.4.4) which shall be supplied to the technical service at the time of submission of the type-approval application. This will be taken as the basic reference for the verification process set out in point 4;
additional material and analysis data referred to in point 3.4.4, which shall be retained by the manufacturer, but made open for inspection at the time of type-approval.
A description shall be provided which gives a simple explanation of all the control functions of ‘the System’ and the methods employed to achieve the objectives, including a statement of the mechanism(s) by which control is exercised.
A list shall be provided, collating all the units of ‘the System’ and mentioning the other vehicle systems which are needed to achieve the control function in question.
An outline schematic showing those units in combination shall be provided with both the equipment distribution and the interconnections made clear.
The function of each unit of ‘the System’ shall be outlined and the signals linking it with other units or with other vehicle systems shall be shown. This may be provided by a labelled block diagram or other schematic, or by a description aided by such a diagram.
Interconnections within ‘the System’ shall be shown by a circuit diagram for the electric transmission links, by an optical-fibre diagram for optical links, by a piping diagram for pneumatic or hydraulic transmission equipment and by a simplified diagrammatic layout for mechanical linkages.
There shall be a clear correspondence between these transmission links and the signals carried between units.
Priorities of signals on multiplexed data paths shall be stated wherever priority may be an issue affecting performance or safety for the purpose of this Regulation.
Each unit shall be clearly and unambiguously identifiable (e.g. by marking for hardware and marking or software output for software content) to provide corresponding hardware and documentation association.
Where functions are combined within a single unit or within a single computer, but shown in multiple blocks in the block diagram for clarity and ease of explanation, only a single hardware identification marking shall be used.
The manufacturer shall, by the use of this identification, affirm that the equipment supplied conforms to the corresponding document.
fall-back to operation using a partial system;
change-over to a separate back-up system;
removal of the high level function.
In case of a failure, the driver shall be warned for example by warning signal or message display. When the system is not deactivated by the driver, e.g. by turning the ignition (run) switch to ‘off’, or by switching off that particular function if a special switch is provided for that purpose, the warning shall be present as long as the fault condition persists.
This may be based on a Failure Mode and Effect Analysis (FMEA), a Fault Tree Analysis (FTA) or any similar process appropriate to system safety considerations.
The chosen analytical approach(es) shall be established and maintained by the manufacturer and shall be made open for inspection by the technical service at the time of the type-approval.