GMGuidance material
GM2 to AMC4 ATS.OR.205(a)(2) Safety assessment and assurance of changes to the functional system
ASSURANCE — SOFTWARE ASSURANCE LEVELS
(a)The assurance required by AMC4 ATS.OR.205(a)(2) can be provided with a level of confidence consistent with the criticality of the software in order to generate an appropriate and sufficient body of evidence to help to establish the required confidence in the argument.
(b)The use of the SWAL concept can be helpful to provide an explicit link between the criticality of the software and the rigour of the assurance.
(c)The use of multiple SWALs would also allow the possibility of managing several criticalities of the different software components within the system (with partitioning or other architectural strategies) by the same set of software assurance processes. When the software assurance processes employ on several SWALs, they should define for each SWAL the rigour of the assurances to achieve compliance with the objectives set out in AMC4 ATS.OR.205(a)(2). As a minimum:
(1)the rigour should increase as the criticality of the service supported by the software solution increases; and
(2)the variation in rigour of the evidence and arguments per SWAL should include a classification of the activities and objectives according to the following criteria:
(i)required to be achieved with independence, i.e. the verification process activities are performed by a person (or persons) other than the developer of the item being verified;
(ii)required to be achieved; and
(iii)not required.
GM — Regulation (EU) 2017/373 · ED Decision 2019/022/R · ATM/ANS Easy Access Rules · EAR revision 12 Mar 2025