← Back to blogISO 21448 – SOTIF: Safety Beyond System Faults

    ISO 21448 – SOTIF: Safety Beyond System Faults

    6/30/2026 · By Conny Broberg

    ISO 21448 (SOTIF): When Technology Works as Intended – But Still Poses a Risk

    Within the automotive industry, safety standards have long focused on preventing system failures. We are all familiar with ISO 26262 (Functional Safety), which deals with risks caused by electrical or electronic failures – such as when a sensor breaks down or a software bug crashes the system.

    However, as we move towards increasingly autonomous vehicles and advanced driver-assistance systems (ADAS), a new type of challenge has emerged: SOTIF (Safety of the Intended Functionality), also known as ISO 21448.

    What is SOTIF?

    ISO 21448 addresses the hazards that arise even though no components have failed. It concerns the inherent limitations of the system. Imagine a self-driving car driving in heavy rain and misinterpreting a puddle as a solid object, or a sensor being blinded by a low-hanging sun. The system functions exactly as it was programmed, but the result is still a dangerous situation.

    SOTIF is about ensuring that the function itself is safe, even in complex, unforeseen environments.

    From the Unknown to the Known

    The core of SOTIF work is to manage four different types of scenarios:

    1. Known Safe: Situations we understand and where the system acts correctly.
    2. Known Unsafe: Risks we are aware of (e.g., the camera cannot see in dense fog). Here, we focus on minimising the risk.
    3. Unknown Safe: Situations we have not foreseen, but which do not lead to accidents.
    4. Unknown Unsafe: The biggest challenge. Scenarios we haven't even thought of, but which can lead to catastrophic consequences.

    The goal of ISO 21448 is to systematically move as much as possible from the "unknown" and "unsafe" categories to the "known safe" zone through analysis, simulation, and iteration.

    Why is it important for your project?

    When we build AI-driven systems and advanced sensor fusion, traditional testing is not enough. If your image recognition algorithm is trained on data from sunny California, how will it react to a snowy road in northern Sweden?

    SOTIF requires:

    • Thorough risk analysis: Identify limitations in sensors and algorithms.
    • Massive simulation: Virtualising millions of kilometres in different weather and traffic environments.
    • Real-world validation: Ensuring that theoretical performance matches reality.

    How iThing AB can help

    Navigating the regulations around ISO 26262 and ISO 21448 can be complex. At iThing, we have the experience required to integrate these standards into your development process from day one. We help you not only build systems that last, but systems that understand and manage the complexity of the world.

    Do you want to know more about how we can secure your future vehicle functions? Contact us for a deep dive into SOTIF.