Requirements and Verification Standards for Artificial Intelligence in Safety-Critical Applications
Authors/Creators
Description
This framework establishes the AI-specific requirements and verification standards against which Safety Critical Labs conducts certification assessments for systems incorporating artificial intelligence or machine learning capabilities in safety-critical applications.
The framework addresses verification gaps that traditional software assurance does not cover. AI and ML systems introduce probabilistic outputs, emergent behavior from training data, and potential performance degradation over time. These characteristics require verification approaches designed specifically for data-driven systems.
The framework defines thirteen requirement sets organized into two tiers. Section 2 establishes ten algorithm-agnostic requirement sets (AI-1 through AI-10) covering operational and data foundations (including operational design domain declaration, data partitioning, data classification handling, hazard analysis integration, and retrieval corpus controls), bias detection and mitigation, ML test coverage, continuous validation and drift monitoring, hallucination prevention, out-of-distribution detection, adversarial robustness, explainability, human-AI teaming, and privacy and data protection. Section 3 establishes three architecture- and paradigm-specific requirement sets (AI-11 through AI-13) covering multi-model systems, neural networks, and continuous learning and adaptation. Applicability is determined by a normative gate (Section 1.2.1, Appendix B.1): each determination declares its boundary of analysis, applies a learned-artifact anchor criterion, and is checked by a deletion test separating systems whose correctness can be fully verified against written specification from those whose correctness can only be established empirically. A three-tier classification system (Safety-Critical, Mission-Critical, Operational Support) then determines which requirements apply based on consequence level, not probability.
The framework is domain-agnostic and applicable across aerospace, aviation, automotive, medical, industrial, and other safety-critical domains. Terminology is traceable to ISO/IEC standards and NIST publications, and each parent requirement carries Applicable Domain Standards citations drawing from cross-domain sources (NIST AI RMF (NIST AI 100-1), NIST AI 100-2e2023 Adversarial ML Taxonomy, NIST AI 600-1 Generative AI Profile, NIST SP 1270 on AI bias, NIST SP 800-53 Rev. 5, NIST SP 800-218A, IEEE 1012-2024, ISO/IEC 22989, 23053, 23894, 25059, 27001, 27701, 42001, ISO/IEC TR 24027, ISO/IEC TS 6254), aviation (DO-178C, RTCA DO-326A/330/355/356A, SAE ARP4761, EUROCAE ED-324/SAE ARP6983, EASA AI Concept Paper Issue 2, FAA AI Safety Roadmap), automotive (ISO 21448 SOTIF, ISO/SAE 21434, ISO 26262, ISO 34503, SAE J3016, UNECE WP.29 R157), autonomy (UL 4600), medical (IEC 62304, ISO 14971, FDA AI-Enabled Device Software Functions guidance, FDA Predetermined Change Control Plan guidance, FDA Clinical Decision Support Software guidance, FDA Premarket and Postmarket Cybersecurity guidance), defense and aerospace (MIL-STD-882E, NASA-STD-8739.8), and EU and US regulatory sources (EU AI Act, GDPR, HIPAA, CCPA/CPRA). Framework-specific terms are documented in an 86-term glossary aligned with ISO/IEC 22989:2022 and ISO/IEC 5338:2023.
Files
AI_Requirements_Framework_v3_6.pdf
Files
(1.5 MB)
| Name | Size | Download all |
|---|---|---|
|
md5:39817780d3c2f003b2d89c80a1c465db
|
1.5 MB | Preview Download |
Additional details
Related works
- Is described by
- Other: https://safetycriticallabs.com (URL)
- Is supplement to
- Publication: https://github.com/safetycriticallabs/AI_Requirements_Framework/tree/v3.6 (URL)
Dates
- Created
-
2025-02Initial Framework Development
- Available
-
2026-08-13Published on Zenodo