← All chapters Chapter 27

Appendix F — SOTIF: More Root Causes, Not a Second Framework

The same malfunctions, with their non-E/E roots exposed.

A vehicle function can be dangerous with nothing broken — a camera blinded by low sun, a classifier meeting an unseen shape. SOTIF needs no framework of its own: it supplies additional root causes for the very malfunctions the tree already analyzes, and the standard model's noise and world inputs already have slots for them. The tree makes the cause categories complete; validation remains SOTIF's to own.

Full text of this chapter

The full text — with every derived fault tree, cut-set analysis, and worked example — is readable after signing in. Sign in right here (login and account in one step):