Blog
Every civil aircraft system that flies under CS-25 or FAR 25 must demonstrate — with evidence, not assertion — that it meets its safety objectives. ARP4761 is the SAE Aerospace Recommended Practice that defines exactly how that demonstration is built.
Yet ARP4761 is one of the most misunderstood standards in aerospace engineering. It is frequently treated as a document you produce near the end of a programme, a compliance artefact assembled once the design is frozen. That interpretation is expensive. By the time a safety gap surfaces at the System Safety Assessment stage, the cost of fixing it has multiplied by an order of magnitude.
This guide walks through the complete ARP4761 workflow — what each stage does, why the sequence matters, and where programmes most often go wrong.
What is ARP4761?
ARP4761, titled Guidelines and Methods for Conducting the Safety Assessment Process on Civil Airborne Systems and Equipment, is the SAE standard that defines the safety assessment methodology supporting civil aviation certification.
It does not exist in isolation. ARP4761 is the safety assessment companion to ARP4754A (Guidelines for Development of Civil Aircraft and Systems), which governs the overall development process. Together, they form the accepted means of compliance for CS-25.1309 / FAR 25.1309 — the regulation requiring that aircraft systems perform their intended function under all foreseeable operating conditions.
A practical way to hold the distinction: ARP4754A tells you how to develop the system. ARP4761 tells you how to prove it is safe.
The standard was originally published in 1996. ARP4761A, released in December 2023 alongside ARP4754B, refreshed the guidance and strengthened the integration between the development and safety assessment processes.
The ARP4761 Workflow, Step by Step
The safety assessment process is iterative, not linear — but it has a defined logical sequence. Each stage feeds the next.
1. Functional Hazard Assessment (FHA)
The FHA is where safety assessment begins, and it begins at the function, not the component.
For each function the aircraft or system performs, the FHA asks: if this function is lost, or if it operates incorrectly, what is the worst credible outcome?
Each identified failure condition is then classified by severity:
| Classification | Meaning | Quantitative objective (per flight hour) |
|---|---|---|
| Catastrophic | Multiple fatalities, loss of aircraft | ≤ 1 × 10⁻⁹ |
| Hazardous | Large reduction in safety margins, serious injury | ≤ 1 × 10⁻⁷ |
| Major | Significant reduction in safety margins | ≤ 1 × 10⁻⁵ |
| Minor | Slight reduction in safety margins | ≤ 1 × 10⁻³ |
| No Safety Effect | No effect on operational capability or safety | No requirement |
The FHA is conducted at two levels — Aircraft FHA (AFHA) at aircraft level, and System FHA (SFHA) as functions are allocated to systems.
This is the stage that sets your targets. Everything downstream is measured against what the FHA establishes. An FHA that misclassifies a failure condition propagates that error through the entire safety case.
2. Preliminary System Safety Assessment (PSSA)
The PSSA answers a question that must be asked early: can this proposed architecture even meet the objectives the FHA set?
Using Fault Tree Analysis and Dependency Diagrams applied to the proposed architecture, the PSSA verifies that the design provides:
- Sufficient redundancy to meet the quantitative safety targets
- Genuine independence between redundant elements
- Failure probabilities within the allocated budget
Critically, the PSSA also derives safety requirements — it allocates Development Assurance Levels to items, defines independence requirements, and specifies maintenance tasks and intervals that the safety case will later depend upon.
This is the highest-leverage stage in the entire process. A PSSA conducted before detailed design means an architectural weakness costs a design review. The same weakness found later costs a redesign, a re-analysis, and a schedule slip.
3. System Safety Assessment (SSA)
Where the PSSA validates the proposed architecture, the SSA verifies the implemented design.
The SSA collects the evidence — updated fault trees populated with actual failure rate data, FMEA and FMES results, verification that derived safety requirements were implemented — and demonstrates that the as-built system meets the objectives established in the FHA.
The SSA is the document that carries your safety argument to the certifying authority.
The Supporting Analysis Methods
The three assessment stages above are supported by a toolkit of analytical methods.
Fault Tree Analysis (FTA)
Top-down, deductive. Starts with an undesired top event — typically a failure condition from the FHA — and works downward through logic gates to identify the combinations of lower-level failures that cause it.
FTA delivers two things: a quantitative probability for the top event, and minimal cut sets — the smallest combinations of failures sufficient to cause it. A single-element cut set on a catastrophic failure condition is an immediate red flag.
Markov Analysis
Where fault trees struggle — repairable systems, sequence-dependent failures, complex redundancy with reconfiguration — Markov analysis models the system as a set of states and transitions. It is computationally heavier but handles dynamic behaviour that static fault trees cannot represent.
FMEA and FMES
Bottom-up, inductive. FMEA works from the component upward: if this part fails in this mode, what is the effect at system level? FMES (Failure Modes and Effects Summary) groups FMEA failure modes by their end effect, producing the summarised failure rates that feed directly into the fault trees.
Common Cause Analysis (CCA)
This is the stage most often misrepresented — including in a great deal of published material — so it is worth stating precisely.
CCA is not a single analysis. It is an umbrella comprising three distinct analyses:
- Zonal Safety Analysis (ZSA) — examines each physical installation zone of the aircraft. Are redundant elements routed through the same bay? Could a single physical event in this zone compromise multiple channels?
- Particular Risk Analysis (PRA) — evaluates specific external threats that can defeat redundancy: bird strike, engine rotor burst, fire, lightning, tyre burst, hydraulic fluid leakage, high-intensity radiated fields.
- Common Mode Analysis (CMA) — verifies that redundant elements do not share a failure mechanism: the same software, the same manufacturing lot, the same design error, the same maintenance procedure, the same calibration error.
CCA exists because architectural redundancy on paper is not redundancy in reality. Two “independent” channels routed through the same zone, vulnerable to the same rotor burst trajectory, are not independent — and a certifying authority will find that.
How ARP4761 Connects to DO-178C and DO-254?
The safety assessment process does not end at the system boundary. It flows directly into software and hardware development.
The FHA and PSSA together drive Development Assurance Level (DAL) allocation. The severity classification of a failure condition determines the DAL of the items contributing to it:
| Failure condition | DAL |
|---|---|
| Catastrophic | Level A |
| Hazardous | Level B |
| Major | Level C |
| Minor | Level D |
| No Safety Effect | Level E |
That DAL then governs the rigour applied under DO-178C for airborne software and DO-254 for complex airborne electronic hardware. Architectural mitigations identified during the PSSA — partitioning, dissimilarity, monitoring — can justify DAL reduction, which is often where significant programme cost is saved or lost.
This is why ARP4761 cannot be treated as a downstream deliverable. It determines how much assurance effort your software and hardware teams will be required to expend.
ARP4761 and MIL-STD-882E: Civil and Defence
Programmes spanning both civil and defence work encounter two safety regimes.
ARP4761 governs civil airborne systems under CS-25 / FAR 25, using severity classifications tied to quantitative probability objectives.
MIL-STD-882E governs defence system safety across the full system lifecycle. It uses its own severity categories (Catastrophic, Critical, Marginal, Negligible) and probability levels, combined in a Risk Assessment Matrix, with formal risk acceptance by a designated authority.
The philosophies differ. ARP4761 is oriented toward demonstrating compliance with quantitative certification objectives. MIL-STD-882E is oriented toward managing and formally accepting residual risk. Applying one framework’s logic inside the other’s programme is a recurring source of rework.
Why Choose BE Analytic for ARP4761 Safety Assessment?
BE Analytic Solutions LLP delivers the complete ARP4761 workflow for civil aviation and defence programmes:
- Full safety assessment lifecycle — FHA, PSSA, SSA, FTA, ETA, FMEA/FMECA, RBD, Markov analysis, and the complete CCA suite (ZSA, PRA, CMA)
- Standards coverage — ARP4761, ARP4754A, DO-178C, DO-254, MIL-STD-882E
- Reliability prediction — MTBF, MTTR and availability modelling using MIL-HDBK-217, FIDES, and Physics of Failure approaches
- 15+ years of reliability and system safety engineering
- 100+ aerospace and defence projects delivered
- Tailored solutions for aircraft, UAVs, helicopters, missiles and defence systems
- Supporting test capability — NABL and DGAQA accredited environmental testing and EMI/EMC testing facilities in Bengaluru, so analysis and verification sit under one roof
We work from concept through operations — engaging early, where safety assessment delivers the most value, rather than arriving after the design is frozen.
Explore our full aerospace and defence capabilities.
Conclusion
ARP4761 is not paperwork. It is a structured argument, built stage by stage, that an aircraft system is safe enough to fly — and the sequence is what gives the argument its strength. The FHA sets the targets. The PSSA proves the architecture can meet them. The SSA demonstrates the built system does. The supporting analyses close the gaps that architecture alone cannot.
Programmes that engage with that sequence early certify predictably. Programmes that treat it as a downstream deliverable discover their safety gaps at the worst possible moment.
Planning an aerospace certification programme? Talk to our reliability and system safety engineers about where to start.
📞 +91 8095000439 | 📧 sales@beanalytic.com | 🌐 www.beanalytic.com/aerospace
Frequently Asked Questions
Everything you need to know about aerospace and defence reliability engineering
FHA is top-down and starts at the function — it asks what happens if a function is lost or malfunctions, and classifies the severity of that outcome. FMEA is bottom-up and starts at the component — it asks what effect a specific part’s failure mode has on the system. FHA sets the safety objectives; FMEA helps demonstrate the design meets them. A complete ARP4761 safety assessment requires both.
DAL (Development Assurance Level) applies to airborne systems under DO-178C and DO-254, is graded A through E, and rates the rigour of the development process. SIL (Safety Integrity Level) comes from IEC 61508, is graded 1 through 4, and rates the risk reduction a safety function provides. They originate from different philosophies and do not map one-to-one — treating a DAL C as equivalent to a SIL 2 without proper analysis creates compliance gaps.
ARP4761 is a recommended practice, not a regulation. However, it is the accepted means of compliance recognised by EASA and the FAA for demonstrating compliance with CS-25.1309 / FAR 25.1309. In practice, civil aircraft programmes follow it, and deviating requires justifying an alternative means of compliance to the certifying authority.
Not directly. Military programmes typically follow MIL-STD-882E, which uses a risk-matrix approach with formal risk acceptance rather than ARP4761’s quantitative certification objectives. However, ARP4761 methods — FTA, FMEA, CCA — are widely applied on defence programmes, and military aircraft seeking civil-type certification or dual-use approval may need both frameworks.
The three most common are MIL-HDBK-217 (a classic parts-count and parts-stress handbook, widely used in defence), FIDES (a more modern methodology accounting for lifecycle and process factors, developed by European aerospace and defence manufacturers), and Physics of Failure (which models actual degradation mechanisms rather than statistical failure rates). Method selection depends on the programme, the customer requirement, and the available component data.
At concept. The Aircraft FHA should be underway as functions are being defined, and the PSSA should validate the architecture before detailed design begins. Safety assessment engaged after design freeze can only document what exists — it cannot influence the architecture, which is where the majority of safety value is created.
