“It works” is not enough. Risks must be managed consciously.
Battery systems contain high energy. This is not a minor technical detail, it is an engineering reality directly linked to human health and life.
Yet across many small and medium-sized companies, functional safety in battery systems is still treated as a secondary topic.
Instead of being a natural layer of product development, it is often postponed, unclear, or never fully owned by the organization.
The real issue: not technical, but mindset
A commonly observed approach looks like this:
The product works, do not touch it
Regulations do not explicitly require it
Certification is not requested
At first glance, this may seem pragmatic. But the critical truth is simple:
A system working does not mean its risks are managed.
This mindset often solves today’s problem. If you are lucky, it may carry you forward for a while. But it is not a conscious, defensible engineering approach.
This becomes especially critical in systems involving:
BMS and battery systems
High energy density
Complex hardware–software interaction
Multiple failure scenarios
Without clearly understanding where, when, and how risks emerge, product development remains fragile.
What functional safety is, and what it is not
Functional safety is:
Not a certification goal
Not mandatory full compliance for every product
Not just documentation
Functional safety is about:
Making risks visible
Answering “where, when, and how does it become hazardous?”
Making decisions based on engineering arguments, not intuition
Anchoring engineering knowledge in the organization, not individuals
In short, functional safety is an engineering culture.
A realistic fact: ISO 26262 is not easy
Implementing ISO 26262 end-to-end:
Takes time
Requires extensive documentation
Demands disciplined engineering effort
Becomes increasingly costly as ASIL levels rise
As a result, many teams get stuck between two extremes:
“Let’s not start at all”
“Full compliance is too complex and expensive”
Reality, however, is not limited to these two options.
Why eMOBINO designed the functional safety starter package
The most common gap we see is clear: Many teams do not know where to start.
Functional safety is either postponed indefinitely or addressed in fragmented, uncontrolled ways. What is needed instead is a starting point that is:
Manageable
Tailored to the organization
Valuable in the long term
Independent of specific individuals
This is exactly why the functional safety starter package was designed.
What this work is (and is not)
This package is:
Not software
Not hardware
This work is:
a methodology tailored to the product and organization
A long-term design guide
A reusable engineering reference within the organization
The goal is not to limit functional safety to a single project, but to embed it into the company’s engineering mindset.
Scope: ISO 26262 reference starter set
This work covers ISO 26262 sections 3.5, 3.6, 3.7, 4.5, and 4.6, including:
System Architecture Definition
BMS Architecture Definition
Architecture Review
Item Definition
Function Tree & Failure Tree
Hazard Analysis and Risk Assessment - HARA
Safety Goals Definition (including ASIL levels)
BMS Technical Safety Architecture
BMS System FMEA
Functional Safety Concept Review
BMS System Functional Safety Requirements
BMS Functional Safety Requirements Review
The objective
The objective is not to achieve ASIL-D certification on day one.
IT IS:
To elevate engineering maturity in battery systems and build a product development approach whererisks are thoroughly thought through andtransferable to the future.
Once this foundation is in place, teams can progress step by step toward full end-to-end functional safety, if and when needed.
mustafa.simsek@emobino.com
www.emobino.com




