Mittelstandspresse
18.08.2026
Functional Safety for Drive-by-Wire: When the Most Stringent Requirement Sets the Standard
ASIL, SIL, AgPL, MPL, and PL assess risks differently. Arnold NextG consolidates the requirements for NX NextMotion into a unified safety objective catalog—serving as the foundation for a cross-domain, drive-by-wire-based control layer.
Pfronstetten-Aichelau, 18.08.2026 (PresseBox) - An autonomous shuttle in city traffic, a tractor in a field, or a wheel loader on a construction site operate in different risk environments. Accordingly, different standards apply to functional safety. But what happens when a drive-by-wire platform is to be used in multiple such environments? In that case, it is not enough to simply comply with individual standards side by side. The different safety requirements must be integrated at the system level.
For NX NextMotion, Arnold NextG follows a clear principle: If different standards assess the same safety objective with varying levels of stringency, the most stringent requirement sets the benchmark. This is a central component of Safety-by-Wire®.
It all starts with the hazard
Before discussing ASIL D, SIL, or other safety levels, it must first be clarified what risk a malfunction actually poses. In the automotive world, this is done through hazard analysis and risk assessment—HARA for short. This process combines specific operating situations with potential malfunctions.
For example, what does an unintended steering input at high speed mean? What are the consequences of losing braking function on a downhill slope? What happens in the event of unintended forward motion during a maneuver? The assessment evaluates the potential severity of harm, exposure, and—depending on the applicable standards—the possibility of still controlling the situation. Safety objectives are ultimately derived from the risk assessment. This step is particularly relevant for drive-by-wire systems. This is because steering, braking, and propulsion are the primary functions through which vehicle movement is directly controlled.
The Same Fundamental Risk—Different Languages
The fundamental logic of functional safety applies across various vehicle and machinery domains. However, the respective risk models differ. ISO 26262 uses Automotive Safety Integrity Levels (ASIL) for road vehicles. IEC 61508 uses Safety Integrity Levels (SIL). In agriculture and forestry, ISO 25119 specifies Agricultural Performance Levels (AgPL); for earth-moving machinery, Machine Performance Levels (MPL) according to ISO 19014 are used; and in machine safety, Performance Levels (PL) according to ISO 13849 apply. These classifications cannot simply be equated.
An ASIL D is not automatically a SIL 4, nor are PL e and AgPL e identical despite sharing the same letters. Each scale incorporates assumptions specific to its respective application domain—for example, regarding speed, environment, exposure, or operator role. For a platform intended for use across domain boundaries, this presents a key development challenge: the requirements must be made comparable without losing their respective normative significance.
From Five Assessments to a Single Set of Objectives
This is precisely where Arnold NextG’s Safety-by-Wire® strategy comes into play. The safety objectives derived from the relevant analyses are consolidated across standards. Where the respective standards provide for corresponding mappings, different risk metrics are mapped to a common assessment basis. For NX NextMotion, ISO 26262 serves as the guiding standard for development.
If the same safety objective appears in multiple application domains, its assessment may vary. In this case, the principle of the most stringent requirement applies. No average value, no selection based on application: the highest relevant requirement becomes the benchmark for the platform. For the primary motion functions, this approach leads to the highest classification of the leading standard: ASIL D.
At the system level, this results in safety objectives such as preventing unintended steering movements, loss of braking function, or unintended propulsion. Added to these are safety objectives for supporting functions, such as ensuring the vehicle comes to a complete stop or providing signaling. The result is not a collection of disparate safety catalogs, but a common foundation for further system development.
Safety objectives must determine the architecture—not the other way around
For OEMs, Tier 1 suppliers, and system integrators, timing is of the essence. A safety objective catalog does not realize its full value if it is compiled after an architecture has already been developed. It must precede key architectural decisions. This is because technical requirements for hardware and software are derived from the safety objectives: Which functions must be redundant? Which faults must be diagnosed? What response times apply? How must the system behave after a fault?
At NX NextMotion, the consolidated catalog of safety objectives was therefore established at the very beginning of platform development. Decisions regarding redundancy, diagnostics, and degradation behavior can thus be traced back to defined safety objectives. This traceability is particularly crucial for a drive-by-wire-based control layer: It links the initial hazard analysis to the technical implementation and, ultimately, to the safety case.
What OEMs and Integrators Should Check
An ASIL or SIL claim alone therefore says little about whether a system is suitable for a specific application. Among other things, it is crucial to determine which operating situations and assumptions the underlying hazard analysis is based on. Do these scenarios cover the vehicle’s actual use? What assumptions were made regarding controllability? Do these assumptions still apply when there is no driver in the vehicle?
Equally relevant is the question of whether the safety objectives were formulated exclusively for a single vehicle domain or whether they already take other areas of application into account. For a scalable drive-by-wire platform, functional safety is thus not merely a question of the safety level achieved. The safety rationale behind it is what matters most.
Conclusion: A Single Set of Objectives Instead of Five Parallel Worlds
Different vehicle domains speak different languages of functional safety. For a drive-by-wire platform that addresses several of these domains, however, this must result in clear technical requirements. Safety-by-Wire® therefore consolidates the relevant safety objectives into a common catalog of safety objectives. Where different assessments conflict, the most stringent requirement sets the standard.
This creates the foundation for a multi-redundant, fail-operational drive-by-wire architecture whose safety requirements are not defined only for the next vehicle project, but are already embedded in the platform. After all, safe vehicle movement does not begin with the actuator. It begins with the question of which hazard must be controlled—and what architecture is necessary to do so.
WE CONTROL WHAT MOVES
Ansprechpartner
Anke Leuschke
Zuständigkeitsbereich: Pressesprecherin
Über Arnold NextG GmbH:
Über Arnold NextG:
Arnold NextG realisiert die Safety-by-Wire®-Technologie von morgen: das mehrfach redundante Zentralsteuergerät NX NextMotion ermöglicht eine ausfallsichere und individuelle Implementierung, fahrzeugplattform-unabhängig und weltweit einzigartig. Mit dem System können autonome Fahrzeugkonzepte sicher und nach den neuesten Hard- und Software- sowie Sicherheitsstandards umgesetzt werden, ebenso wie Remote-, Teleoperation- oder Platooning- Lösungen Als unabhängiger Vorausentwickler, Inkubator und Systemlieferant übernimmt Arnold NextG die Planung und Umsetzung – von der Vision bis zur Straßenzulassung. Mit der Straßenzulassung von NX NextMotion setzen wir den globalen Drive-by-Wire-Standard. www.arnoldnextg.de
About Arnold NextG:
Arnold NextG realizes the safety-by-wire® technology of tomorrow: The multi-redundant central control unit NX NextMotion enables a fail-operational and individual implementation, independent of the vehicle platform and unique worldwide. The system can be used to safely implement autonomous vehicle concepts in accordance with the latest hardware, software and safety standards, as well as remote control, teleoperation or platooning solutions. As an independent pre-developer, incubator and system supplier, Arnold NextG takes care of planning and implementation - from vision to road approval. With the road approval of NX NextMotion, we are setting the global drive-by-wire standard. www.arnoldnextg.com
Datei-Anlagen:
(420 kB)
1622095.attachment
From Hazard to Safety Goal: HARA links specific operating situations to potential malfunctions in steering, braking, and propulsion. Severity, exposure, and controllability determine the risk classification—and, consequently, the safety goal for the drive-by-wire-based control layer.
- Mehr Infos zu dieser Meldung unter www.pressebox.de
- zurück zur Übersicht















