GLOSSARY
Hazard analysis
Hazard analysis, often paired with risk assessment as a single activity, examines the system's functions, failure modes and operating context to identify hazardous events, then estimates their severity, exposure and controllability. The output is not a list of failures; it is a set of hazards linked to safety goals and, ultimately, to safety requirements.
Techniques commonly applied
- Functional hazard analysis, examining loss or malfunction of intended functions.
- HAZOP, applying guidewords systematically to a process or design.
- FMEA, working component-by-component through failure modes and effects.
- STPA, modelling hazards as inadequate control rather than component failure alone.
The analysis is only useful if it is revisited as the design changes. A hazard analysis performed once at concept phase and never updated after architecture decisions is a common source of stale safety cases: mitigations described in the analysis no longer match what was built, and nobody can say with confidence which hazards remain controlled.
Good practice keeps the hazard log as a living register with stable identifiers, referenced directly by requirements and verification evidence, so a reviewer can trace from a specific hazard to the design decision and test result that addresses it.