Key standards
- EN 50126/8/9 (rail RAMS), EN 45545 (fire safety), TSIs (Technical Specifications for Interoperability), CENELEC standards.
Documented issues
RAIB’s investigation into an ERTMS/ETCS misoperation on the Cambrian Coast found that after a system restart, temporary speed restriction data was not uploaded, yet the display suggested it was. The safety documentation lacked a clear definition of safetyrelated data; there was a single point of failure and the independent safety assessor missed design-documentation issues. RAIB recommended improvements to the safety assurance process for highintegrity software. gov.uk.
Typical challenges
- Configuration and operational data are not clearly defined as safety critical, leading to insufficient checks.
- Independent safety assessments may not cover documentation thoroughly.
- Train drivers and operators rely on displays that may not reflect actual loaded data.
Best Practice playbook
- Define and classify safety-related data; ensure that temporary restrictions and configuration data are treated as safety critical and subject to checks. gov.uk.
- Provide redundancy and verification: implement cross‑checks to confirm data is loaded after restarts; design out single points of failure.
- Improve safety assurance processes: ensure independent safety assessors examine documentation and design thoroughly. gov.uk.
- Train operators and maintainers to understand system states and verify that restrictions are active.
- Audit and update documentation when system designs change or new software versions are introduced.
References
- RAIB report on loss of temporary speed restriction data and recommendations. gov.uk.