Rail JU logo in white
European Union flag

A body of the
European Union

FP2 – R2DATO - Project Outputs

Towards a Novel Approach to Railway Safety using STPA and Promise Theory

Jul 31, 2025

Output type:

The 1st International Symposium on Software Fault Prevention, Verification, and Validation

2 ~ 3 December 2024 – Hiroshima, Japan

This paper introduces SafePAM (Safety Promise Assessment Method), an iterative method to formally model cooperation and conditional dependencies between interdependent subsystems in railway safety. It builds on STPA (a system-theoretic hazard analysis) and uses promise theory to better reflect real-world conditions. Unlike traditional methods, SafePAM allows conditional dependencies without assuming independence. A railway case study shows how this approach helps connect domain-specific knowledge with system behavior, enabling better validation by experts and maintaining overall system safety.

Europe's Rail