Executing Functional Safety Audits & Assessments (FSA): Best Practices for Engineering Managers

By Cody Smith

Executing Functional Safety Audits & Assessments (FSA)

When a complex autonomous system or automated production line nears completion, the pressure to initiate commissioning and meet operational deadlines is intense. However, for safety-critical environments, rushing a system into production without independent validation introduces severe operational, financial, and regulatory liabilities. A failure within a safety-related control loop can have catastrophic consequences for personnel, property, and environmental integrity. 

To verify that risk-reduction measures are legally compliant and technically robust, master standards such as IEC 61508 and ISO 13849 mandate a structured evaluation process: the Functional Safety Assessment (FSA). An FSA is not a superficial check of equipment; it is a rigorous, independent investigation into both the physical system architecture and the systematic engineering processes used throughout the development lifecycle. 

This guide outlines the structural boundaries between audits, assessments, and verification milestones, provides a roadmap of the five operational FSA stages, and delivers an execution checklist for passing a Stage 3 compliance review.

Defining the Evaluation Hierarchy: Verification, Audits, and Assessments 

Engineering managers frequently use compliance terms interchangeably, which can lead to misaligned expectations during external reviews. To maintain an auditable development process, a clear distinction must be maintained between verification, functional safety auditing, and functional safety assessment.

Executing Functional Safety Audits & Assessments (FSA) 01

Phase-Level Verification 

Verification is an ongoing engineering activity executed at every stage of the V-model lifecycle. It addresses a fundamental question: Did we build the subsystem correctly? Verification activities include code reviews, hardware diagnostic testing, and checking that a low-level requirements specification perfectly satisfies a high-level system safety requirement. 

Functional Safety Audit 

An audit is a systematic, independent review focused on process adherence. The auditor reviews the project's Functional Safety Management (FSM) documentation to verify that the team strictly followed the defined safety lifecycle workflows, maintained appropriate qualification records for personnel, and executed planned quality control steps. 

Functional Safety Assessment (FSA) 

An FSA goes beyond process tracking to evaluate the engineering decisions made throughout the project. Conducted by an independent safety authority, the assessment judges the technical adequacy of the safety justifications. It determines whether the completed system actually achieves the necessary risk reduction based on the original Hazard Analysis and Risk Assessment (HARA). The final output of an FSA is a definitive statement on whether the equipment under control is safe to operate.

The Five Operational Stages of an FSA

The master standard IEC 61508 divides the assessment lifecycle into five distinct stages, allowing companies to evaluate risk at key milestones rather than waiting until the end of an engineering project. 

Executing Functional Safety Audits & Assessments (FSA) 02
  • Stage 1: Post-Hazard Analysis: Executed immediately after completing the initial HARA and PHA. The assessment verifies that all systemic hazards have been identified and that target Safety Integrity Levels (SIL) have been correctly allocated. 

  • Stage 2: Post-Design: Conducted once the hardware and software architectures are finalized. It reviews component failure mode analyses (FMEA), fault tree assessments (FTA), and safety manual assumptions for commercial off-the-shelf (COTS) equipment. 

  • Stage 3: Pre-Commissioning: Performed after the physical system is fully built, integrated, and wired, but before any hazardous energy is introduced. This is the most critical compliance step for engineering managers, as it serves as the final barrier to live operation. 

  • Stage 4: Operational: Conducted periodically during active operation to confirm that routine proof testing is occurring, diagnostic data is being analyzed, and real-world failure rates do not exceed design assumptions. 

  • Stage 5: Post-Modification: Mandated whenever a safety-related control loop or system boundary is altered, ensuring that changes do not introduce unmitigated hazards into the validated safety case. 

The Stage 3 Compliance Roadmap: Pre-Commissioning Verification

To successfully pass a Stage 3 FSA audit before a system goes live, engineering managers must compile a comprehensive safety case that demonstrates complete traceability between conceptual risks and verified test results. 

Structural Safety Case Document Handoff 

The compliance documentation must follow a clean, auditable flow to facilitate independent review: 

Executing Functional Safety Audits & Assessments (FSA) 3

Key Requirements for Stage 3 Approval 

  • Requirements Traceability Matrix (RTM) Completion: The safety authority will review the RTM to verify that every high-level safety function maps directly to an active design element, a specific line of application logic, and a completed, signed-off validation test report. 

  • COTS Interface Validation: If the design integrates pre-certified safety components (such as light curtains or safety PLCs), the engineering team must provide documented proof that the physical installation strictly satisfies all conditions of use specified in the manufacturer's safety manual. 

  • Independent Safety Analysis Verification: The safety case must include documented results from independent hazard facilitation workshops, such as bottom-up FMEAs and top-down FTAs. These analyses must demonstrate that common-cause vulnerabilities cannot bypass design redundancies to create an unsafe state. 

Engineering Management Checklist for Stage 3 FSA Readiness 

  • Assessment Independence: Verify that the designated FSA assessor has the appropriate technical competency and maintains operational independence from the active design team. 

  • Documentation Freezing: Ensure the Requirements Traceability Matrix, safety manuals, and validation logs are completely organized and frozen before scheduling the audit kickoff. 

  • Quantitative Alignment: Confirm that all physical loop validation records verify that calculated Safe Failure Fractions (SFF) and failure probabilities (PFD_avg or PFH) remain within the target SIL envelopes. 

Interested in our services?

Contact us or learn more about the services CSA provides

Contact us