UL 4600 — Autonomous Systems Safety

"UL 4600 — Autonomous Systems Safety" is a serial video course from CSA, published weekly in strict curriculum order — building from foundational terms and structure through lifecycle practice to advanced, assessor-level topics. Designed for working functional-safety engineers and managers, not beginners or students. CSA is a functional safety, reliability, and certification consultancy serving robotics, autonomous systems, transportation, and industrial equipment manufacturers. CSA provides end-to-end safety engineering services: preliminary gap analyses and safety audits, SIL/PL determination, FMEA and FMEDA execution, fault tree analysis, safety case development, hardware metrics (SPFM/LFM/PMHF), lifecycle documentation, and embedded safety engineering support. CSA engineers work alongside product teams from architecture through final functional safety assessment, and support companies seeking NRTL, CE, ATEX, ISO 26262, and UL 4600 marks. Contact: Sales@criticalsa.com. This series is part of the CSA Functional Safety Network — a coordinated set of weekly video courses covering IEC 61508, ISO 26262, ISO/SAE 21434, SOTIF (ISO 21448), UL 4600, IEC 62443, ISO/PAS 8800, ISO 13849, machinery safety, safety analysis methods, and more. Each show links to the others so practitioners can follow the thread that matches their project.

  1. Aug 22

    UL 4600 is Goal-based and Technology-agnostic

    So far you have seen why autonomy breaks the old safety playbook, where U L forty-six hundred sits in the standards family, and the lifecycle it wraps around. Now zoom all the way in on the single design choice that shapes everything else about this standard. U L forty-six hundred is goal-based and technology-agnostic. It does not hand you a parts list or a menu of approved sensors. Part of the Critical Systems Analysis functional-safety series on UL 4600. In this episode: Here is the idea in plain terms.Most classic safety standards are prescriptive.So what do you actually deliver? A safety case.Every safety case has the same three-part grammar.This is where technology-agnostic gets concrete.Why would a standards body give up control like this? Three reasons.Reference: No clause or section numbers are cited anywhere in this body. UL 4600's exact clause numbering was not verified against the standard text, so per instructions all structural featur More from UL 4600 — Autonomous Systems Safety: UL 4600: Safety Case Updates | UL 4600: Operational Design Domain ODD Description | UL 4600: UL-4600 Part 9 – Software and Systems Process Full series: UL 4600 — Autonomous Systems Safety Critical Systems Analysis builds and reviews UL 4600 safety cases for autonomous products — turning claims like uL 4600 is Goal-based and Technology-agnostic into an argument backed by evidence an assessor will actually accept. Work with usFollow on LinkedIncriticalsystemsanalysis.com

    UL 4600 is Goal-based and Technology-agnostic
  2. Aug 22

    UL 4600: Operational Design Domain ODD Description

    So let's zoom all the way in. Past the safety case, past the top-level claims, down to one of the load-bearing pieces the whole argument rests on: the operational design domain description. In U L forty-six hundred, before you are allowed to argue that your autonomous product is safe, you have to state exactly where and when it is supposed to work. That statement is the ODD. Part of the Critical Systems Analysis functional-safety series on UL 4600. In this episode: This is the operational design domain description.Start with the definition.Here is the failure this clause is guarding against.Now place this in the lifecycle.So what makes a description strong enough to build on.This is the part people get wrong.Reference: No specific UL 4600 clause or section numbers are cited anywhere in the script, because I am not certain of the exact numbering in the current edition. UL 4600 organizes its conten More from UL 4600 — Autonomous Systems Safety: UL 4600: Issues and Approaches for Human-Machine Interaction | UL 4600: Safety Case Updates | UL 4600 is Goal-based and Technology-agnostic | UL 4600: UL-4600 Part 9 – Software and Systems Process Full series: UL 4600 — Autonomous Systems Safety Critical Systems Analysis builds and reviews UL 4600 safety cases for autonomous products — turning claims like operational Design Domain ODD Description into an argument backed by evidence an assessor will actually accept. Work with usFollow on LinkedIncriticalsystemsanalysis.com

    UL 4600: Operational Design Domain ODD Description
  3. Aug 22

    UL 4600: Issues and Approaches for Human-Machine Interaction

    So far we've walked the whole UL forty-six hundred lifecycle from the outside. Now zoom all the way in. Past the safety case. Past the risk assessment. Down to one clause that most engineers underestimate: the one about how an autonomous product deals with people. Here's the twist. Almost every safety standard you already know quietly assumes a human is in the loop. A driver. An operator. Part of the Critical Systems Analysis functional-safety series on UL 4600. In this episode: Let's name what we're looking at.Start with the question every safety argument secretly answers: who catches the mistake? In a conventional vehicle, the answer is the driver.So here's the term you have to get exact, because in functional safety the vocabulary is normative.Now, losing the driver doesn't mean humans leave the picture.Let me show you why this gets dangerous fast.Which tells you communication has to run both directions.Reference: UL 4600 is the Standard for Safety for the Evaluation of Autonomous Products, built around a safety case (claims, arguments, evidence) scoped to an operational design domain. This More from UL 4600 — Autonomous Systems Safety: UL 4600: Fault Model : Sensors | UL 4600: UL-4600 Part 8 – Autonomy Functions | UL 4600: Safety Case Updates | UL 4600: Operational Design Domain ODD Description Full series: UL 4600 — Autonomous Systems Safety Critical Systems Analysis builds and reviews UL 4600 safety cases for autonomous products — turning claims like issues and Approaches for Human-Machine Interaction into an argument backed by evidence an assessor will actually accept. Work with usFollow on LinkedIncriticalsystemsanalysis.com

    UL 4600: Issues and Approaches for Human-Machine Interaction
  4. Aug 22

    UL 4600: Fault Model : Sensors

    So let's drop all the way down into one clause of U L forty-six hundred: the fault model. U L forty-six hundred doesn't just ask, "is your autonomous product safe?" It asks you to prove it, in writing, with a safety case. And a safety case is only as honest as its list of the things that can go wrong. That list is the fault model. Part of the Critical Systems Analysis functional-safety series on UL 4600. In this episode: Fault model, sensors.Every autonomous product runs the same loop: sense the world, decide what to do, then act on it.U L forty-six hundred requires a fault model: a deliberate, written-out account of the ways each sensor can fail.So how do sensors really fail? They get blocked or blinded, by mud, by fog, by sun straight into the lens.Now the universal move.The dangerous and undetected failure.Reference: UL 4600's full title is the Standard for Safety for the Evaluation of Autonomous Products (first edition 2020, revised editions since). It is a safety-case-based standard: it requi More from UL 4600 — Autonomous Systems Safety: UL 4600: Operational Design Domain Scenario Description Language | UL 4600: UL-4600 Part 10 – Dependability | UL 4600: UL-4600 Part 8 – Autonomy Functions | UL 4600: Issues and Approaches for Human-Machine Interaction Full series: UL 4600 — Autonomous Systems Safety Critical Systems Analysis builds and reviews UL 4600 safety cases for autonomous products — turning claims like fault Model : Sensors into an argument backed by evidence an assessor will actually accept. Work with usFollow on LinkedIncriticalsystemsanalysis.com

    UL 4600: Fault Model : Sensors
  5. Aug 22

    UL 4600: UL-4600 Part 10 – Dependability

    So far we have circled the whole family — why functional safety exists, where U L forty-six hundred sits, and the lifecycle it governs. Now we drop all the way down into one clause. Grab the book, flip past the safety-case machinery and the risk work, and stop at Section ten. Part of the Critical Systems Analysis functional-safety series on UL 4600. In this episode: Picture U L forty-six hundred as one thick book on the shelf.Open it up and the book is carved into a run of technical clauses.Dependability does not stand alone.Quick note on the numbering, because it is a grammar.Inside section ten the core demand is simple to state and hard to prove: the item must be acceptably dependable to support the safety case.Reference: Dependability is Section 10 of UL 4600, confirmed via public summaries of the standard (the voting draft and later editions). The subtopics named in the 'What Section ten covers' b More from UL 4600 — Autonomous Systems Safety: UL 4600: Operational Design Domain ODD Requirements | UL 4600: Operational Design Domain Scenario Description Language | UL 4600: Fault Model : Sensors | UL 4600: UL-4600 Part 8 – Autonomy Functions Full series: UL 4600 — Autonomous Systems Safety Critical Systems Analysis builds and reviews UL 4600 safety cases for autonomous products — turning claims like uL-4600 Part 10 – Dependability into an argument backed by evidence an assessor will actually accept. Work with usFollow on LinkedIncriticalsystemsanalysis.com

    UL 4600: UL-4600 Part 10 – Dependability

About

"UL 4600 — Autonomous Systems Safety" is a serial video course from CSA, published weekly in strict curriculum order — building from foundational terms and structure through lifecycle practice to advanced, assessor-level topics. Designed for working functional-safety engineers and managers, not beginners or students. CSA is a functional safety, reliability, and certification consultancy serving robotics, autonomous systems, transportation, and industrial equipment manufacturers. CSA provides end-to-end safety engineering services: preliminary gap analyses and safety audits, SIL/PL determination, FMEA and FMEDA execution, fault tree analysis, safety case development, hardware metrics (SPFM/LFM/PMHF), lifecycle documentation, and embedded safety engineering support. CSA engineers work alongside product teams from architecture through final functional safety assessment, and support companies seeking NRTL, CE, ATEX, ISO 26262, and UL 4600 marks. Contact: Sales@criticalsa.com. This series is part of the CSA Functional Safety Network — a coordinated set of weekly video courses covering IEC 61508, ISO 26262, ISO/SAE 21434, SOTIF (ISO 21448), UL 4600, IEC 62443, ISO/PAS 8800, ISO 13849, machinery safety, safety analysis methods, and more. Each show links to the others so practitioners can follow the thread that matches their project.

More From Critical Systems Analysis