Free tool

ASIL Decomposition Calculator

Every permitted split of a safety goal, with the part that actually gets challenged in review: the independence you have to demonstrate, and what the dependent-failure analysis owes an assessor for each resource the two elements share.






Runs entirely in your browser. Nothing is uploaded, stored, or sent anywhere.

What decomposition is, and what it is not

ASIL decomposition lets you take a safety goal at one ASIL and meet it with two elements developed to lower ASILs, provided the two are sufficiently independent. It is a legitimate and widely used technique. It is also the single most over-claimed idea in ISO 26262, because the saving is obvious and the obligation is not.

The obligation is this: decomposition buys you nothing until the independence is demonstrated. Two elements that share a clock tree, a supply rail, a die, a bus or a compiler are not independent by assertion. The dependent-failure analysis is the deliverable that makes the decomposition real, and a decomposition arrow drawn on an architecture diagram with no DFA behind it is one of the things an assessor will find first.

Why the splits are computed and not looked up

The permitted decompositions are usually presented as a table to memorise. They do not need to be. Give the ASILs their ordinary integer weights — QM 0, A 1, B 2, C 3, D 4 — and a decomposition is just a split of the parent weight into two parts that add back to it. Enumerate the splits and you get exactly the permitted set:

ASIL D (4) → D+QM (4+0), C+A (3+1), B+B (2+2)
ASIL C (3) → C+QM (3+0), B+A (2+1)
ASIL B (2) → B+QM (2+0), A+A (1+1)
ASIL A (1) → A+QM (1+0)

That is what this tool does, which is also why no copyrighted table is embedded in the page. The same trick underlies our ASIL determination calculator, where the severity, exposure and controllability classes are summed as an index rather than looked up in a grid.

The suffix is the part people drop

A decomposed element is not ASIL B. It is ASIL B(D), and the parenthesis travels with it forever. It records that this element came from a decomposed ASIL D goal, which means the independence argument it depends on is still load-bearing, and that it cannot later be reused as an ordinary ASIL B element in a different context without redoing that argument. In practice the suffix is dropped somewhere between the safety concept and the component specification, and the independence claim quietly stops being tracked. If you audit one thing after a decomposition, audit whether the suffix survived.

Where the saving actually is

Decomposing ASIL D into B(D)+B(D) does not halve the work. Both elements still need a safety requirement, an FMEDA, verification evidence and a place in the safety case; what changes is the rigour demanded of each, and for hardware the metric targets that apply. The real saving usually shows up in two places: the hardware architectural metrics get easier per element, and one branch may be able to reuse a qualified component that would never have been arguable at the parent ASIL.

Against that, you have added an independence obligation that has to be maintained for the life of the product. Every later change — a shared regulator added to save cost, a bus merged, a common library adopted — can invalidate it silently. That is the trade, and it is worth making deliberately rather than because the diagram looked cheaper.

Carrying it into the numbers

Decomposition changes which ASIL targets each element is measured against, and those targets land in the hardware metrics. Once you have chosen a split, the FIT and PMHF calculator shows what SPFM, LFM and PMHF each element now has to reach, and the FMEDA rollup aggregates the elements into the system figure. If the shared-resource list above made you reach for a monitor, the diagnostic coverage it buys you is what turns the independence argument into a number.

More free tools

Each of these runs entirely in your browser. Nothing is uploaded, stored or sent anywhere, and none of them needs an email address.

ASIL determination →
Severity, exposure and controllability to an ASIL, with the reasoning shown.
FIT & PMHF budget →
Failure rate and diagnostic coverage to SPFM, LFM and PMHF for one element.
FMEDA rollup →
Many elements rolled up to system SPFM, LFM and PMHF, ranked by contribution.
Solder joint fatigue →
Coffin-Manson thermal cycling life, scaled from a qualification test.

See all 49 engineering tools →

Stay in touch

New tools and notes, once a month at most

We add tools here fairly often and write up the things worth writing up — a stackup that behaved oddly, a standard that turned out to be obsolete, a calculator that was quietly wrong. Join and you get told when something new lands.

One email a month at the very most, and usually less. No drip sequence, no sales cadence, no sharing your address with anyone. Unsubscribe whenever you like.

Join the list →

Talk to us about a safety concept or FMEDA review →