The Five-Page Plan an Assessor Reads First
A functional safety management plan gives an assessor the context needed to judge the rest of the evidence. Useful plans are short, named, and used.
)
The assessor asks for the functional safety management plan before the hazard analysis. On a first assessment, that can feel backward. Months went into the engineering; the opening document may be five pages about who does what.
Those pages tell the assessor how to read everything else.
Take a thorough hazard analysis with no surrounding record. It may be technically excellent, but the reviewer still has to establish who wrote it, which product baseline it governed, how the author was judged competent, what independent review took place, and what happened after the design changed. The management plan should answer those questions without a round of email.
Decisions, not boilerplate
A useful plan names responsibility for each safety lifecycle activity. “Engineering” is not an owner. A role or person is.
It also states what competence the work requires and how the project checks it. That does not mean every contributor needs the same credential. The competence needed to facilitate a hazard review differs from the competence needed to approve a high-integrity architecture, and the plan should make the distinction visible.
Verification has to be arranged before the schedule starts squeezing it. Which output will be checked against which input? Who can perform that check? What independence does the project need for the eventual functional safety assessment?
The independence question is especially easy to leave late. By the final month, everybody available may have contributed to the work they are now supposed to assess. An early decision preserves a reviewer; a late decision can move the date.
Configuration and change control belong here as well. The plan should identify the controlled baseline and say how a proposed change receives a safety impact review. Otherwise the hazard analysis can be correct for revision A while the assessment quietly receives revision C.
The version 1.0 warning
We use a blunt test: ask the project manager to point to one choice the plan controlled.
Perhaps it stopped the designer of a subsystem from approving their own verification. Maybe it required a competency review before somebody facilitated the HARA. It could have forced an impact analysis when the controller firmware changed.
If no decision, review, or assignment would have been different without the plan, the document described the project but did not manage it.
Revision history provides another clue. People leave, scope changes, and assessment arrangements move. A plan still sitting at version 1.0 after two years probably stopped governing the work much earlier.
This is why writing the plan at the end is visible. The reconstructed version tends to fit the people who happened to do the work and the tests that happened to run. It cannot show that the project made those choices deliberately.
What the assessor should be able to open
In ASAP, the assessor can open an activity and see its author, version, review, and connected verification. Changes point to the records they affected. The management evidence is already there when the assessment begins.
The methodology was developed over five years inside Amazon Robotics and supports a large autonomous mobile robot fleet in continuous operation.
Ask who approved the current baseline and why they were independent enough. If the answer requires a meeting, Fennec can help make the management record usable.
Frequently asked questions
What is a functional safety management plan?
It records how the project will run the safety lifecycle: responsibilities, competence, verification, configuration and change control, and assessment independence.
Why does an assessor read it first?
It identifies who produced the evidence, which baseline it governed, how it was reviewed, and how the project controlled changes.
What does assessment independence mean?
The person or organization judging the work must have the degree of separation required for the activity and integrity level. The arrangement should be planned before everyone available has worked on the project.
Can a small team's plan be short?
Yes. A short plan that names people, decisions, and review arrangements is more useful than a long template that never governs the work.
When should the plan be written?
At project start and then revised as people, scope, and assessment arrangements change.
)