Services  /  SVC / RISK

Autonomy System Risk Evaluation

Structural risk in the architecture, not in the backlog. Includes SLAM robustness and perception validation.

Autonomy systems rarely fail because of single bugs. They fail when structural assumptions break under edge conditions.

This evaluation reads an autonomy stack at the level of architecture rather than defect count: failure modes in feature-based SLAM, ambiguity in repetitive environments, drift accumulation and graph instability, black-box perception risks in safety-critical contexts, and the gap between what the architecture can support and what the safety case claims under ISO 26262 and ISO 21448 (SOTIF).

Two sub-problems are hard enough to carry their own focus inside the review: localization and SLAM robustness, and perception validation where there is no ground truth to compare against.

What the evaluation covers

  1. Feature ambiguity. Repetitive visual structures, for example industrial environments and structured facades, increase feature confusion and graph inconsistency.
  2. Observability limits. Kalman-based systems degrade when state variables become partially unobservable under sensor degradation.
  3. Sensor fusion instability. Misaligned timestamps, IMU drift, or LiDAR occlusion can destabilize pose estimation.
  4. Implicit neural estimation. End-to-end models introduce interpretability gaps that complicate safety validation.
  5. ODD boundary violations. Performance outside the defined Operational Design Domain often degrades non-linearly.
  6. Certification mismatch. Architectures optimized for benchmarks may not support traceability and audit requirements.

Focus: SLAM structural robustness

Modern SLAM systems are optimized for accuracy benchmarks, rarely for structural robustness under real-world and certification constraints. Localization rarely fails cleanly. It degrades, and the degradation is often invisible to the layers above it until the consequence is already downstream. This part of the review looks at pose graph stability, drift accumulation patterns, feature ambiguity in repetitive environments, sensor degradation behaviour, and whether the system can tell the difference between a wrong estimate and an uncertain one. The goal is not incremental tuning. It is architectural clarity, before a redesign becomes expensive.

Focus: perception validation without ground truth

The hardest problem in SOTIF is arguing that an ML perception component behaves safely when there is no labelled ground truth to compare against. The approach here uses physics as a runtime reference instead of a labelled dataset, temporal world models that carry state forward rather than reasoning frame by frame, and failure-mode arguments that connect perception behaviour directly to the safety goals. A reading that violates physics is an error, not a detection, and the system can know that without a label.

How we work: risk evaluation framework

  1. System decomposition. Separate perception, localization, mapping, and planning layers.
  2. Assumption mapping. Explicitly document environmental, sensor, and motion assumptions.
  3. Observability and instability analysis. Identify where state estimation becomes unstable or ambiguous, and where hidden coupling amplifies drift.
  4. Certification alignment. Evaluate traceability, determinism, and the feasibility of the safety argument under ISO 26262 and SOTIF.
Schedule an intro call All services
Related

More in services

SVC / AI

AI Transformation

From ungoverned AI to a stack you can govern, audit, and scale. Diagnosed across five dimensions, delivered as a roadmap.

SVC / CERT

Certification Strategy & Gap Analysis

ISO 26262 and ISO 21448, mapped to what you actually have.

SVC / TDD

Technical Due Diligence (Autonomy & AI)

For investors who need the claim checked, not repeated.