In short
Earth-moving machinery answers to its own functional safety series, ISO 19014, and it is not ISO 26262 with different letters. Its Machine Performance Level descends from the ISO 13849 machinery lineage rather than the ASIL one, no published level-to-level conversion is available to cite, and engineers moving across should re-derive rather than translate.
An engineer who has spent five years on ISO 26262 can read an ISO 19014 project plan, understand every word of it, and still get the whole thing wrong. The vocabulary is familiar enough to be dangerous. There is a required level and an achieved level, hardware architecture requirements, diagnostic coverage, a part devoted to software. It all looks like home.
It is not home. The earth-moving machinery series belongs to ISO technical committee 127, subcommittee 2, and it grew from the machinery-safety branch of the standards world rather than the one the automotive series came from. Reading one through the lens of the other produces confident errors: the reviewer who asks which decomposition scheme was applied, the supplier who arrives with a conversion table between the two level schemes, the programme that treats the machine’s hydraulics as somebody else’s problem.
This is becoming an India problem specifically. In our experience across Indian programmes, functional safety hiring leans heavily on engineers trained on the road-vehicle series by a decade of ADAS, powertrain and electrification work. As that talent moves toward construction and mining equipment, the mismatch does not announce itself. It shows up later, as rework.
ISO 19014 is a licensed document, so what follows deals in structure, lineage and vocabulary rather than in clauses, thresholds or tables. That is where the misunderstandings live anyway.
Two Family Trees, Not One Standard in Two Accents
ISO 26262 is the road-vehicle adaptation of IEC 61508. That is the single most useful fact about its shape, and it is why teams already working to IEC 61508 find much of their process evidence carries into automotive work.
ISO 19014 sits on the other branch. Part 2 describes itself as an adaptation of ISO 13849 into a type-C standard, and the series is positioned as type-C within the ISO 12100 machinery framework, where type-A standards state basic concepts for all machinery, type-B standards deal with particular safety aspects, and a type-C standard sets requirements for one specific family of machines. Earth-moving machinery is that family.
That positioning carries most of what a 26262-trained engineer needs, because everything downstream follows from it. ISO 13849 assesses safety functions in terms of a Performance Level, reasoning through architecture, mean time to dangerous failure, diagnostic coverage and common-cause considerations. Adapting that approach, ISO 19014-2 inherits the machinery vocabulary and the machinery way of thinking with it.
MPL Is a Machinery Idea, Not an Automotive One
Machine Performance Level appears in two forms. MPLr is the level a safety function is required to reach, determined by the Part 1 methodology. MPLa is the level a design is assessed to achieve, evaluated under Part 2. That explicit split is genuinely useful, and it has no single-word counterpart in the automotive series, where one ASIL label serves in both directions and context tells you which is meant.
The split is not the point, though. The family is. MPL is a Performance Level idea expressed for earth-moving machines. ASIL is an IEC 61508 idea expressed for road vehicles. They are two different answers to the same question, produced by different analyses, over different hazard models, using different quantities. They are not two dialects of one language, and a programme that treats them as though they were acquires a defect nobody finds until an assessor does.
What the Parts Cover
Part titles and forewords are bibliographic metadata rather than licensed content, so they can be discussed openly. Named below are only the parts whose titles we have verified; the series runs to further parts beyond these three.
Part 1 (2018, corrected version 2019). Methodology to determine safety-related parts of the control system and performance requirements. This is where MPLr is determined, and where the series introduces the analysis it names MCSSA. It also cancelled and replaced ISO 15998 and ISO/TS 15998-2, a fact with consequences discussed below.
Part 2 (2022). Design and evaluation of hardware and architecture requirements. This part describes itself as an adaptation of ISO 13849, and it is where MPLa, mean time to dangerous failure and diagnostic coverage do their work. It also carries a Hydraulic System Robustness scoring concept, and an annex setting out exceptions to ISO 13849-1 and ISO 13849-2 for this machine family. An adaptation that publishes its own departures is telling you where the borrowing stops.
Part 4 (2020). Design and evaluation of software and data transmission for safety-related parts of the control system.
That phrase, data transmission, deserves its own paragraph. In this series the communication path is not an implementation detail underneath the safety argument. It is inside the argument, named in a part title beside software, and any engineer who has watched a gateway quietly re-time a signal will recognise why. For what those networks actually are on a working machine, vehicle networks in construction and mining equipment covers the J1939 backbone and the Ethernet arriving beside it, and our autonomous haulage piece shows a published system whose safety functions ride a communication channel of their own.
Five Traps for a Reviewer Trained on ISO 26262
Expecting decomposition idioms. ASIL decomposition is a defined automotive mechanism with defined limits, which our ISO 26262 page sets out. It belongs to that series. Do not open an ISO 19014 review by asking which decomposition scheme was applied. Ask instead how the required level was determined and how the achieved level was substantiated, which is what this series is built to answer.
Expecting the automotive part structure. ISO 26262 runs to twelve parts, with the concept phase, system level, hardware level, software level and supporting processes each getting one. A checklist built from that numbering sends people hunting for documents an ISO 19014 programme was never meant to produce, and fails to ask for the ones it was.
Assuming a conversion table exists. This is the trap that costs money. No published ASIL-to-MPL equivalence is cited here, and none is invented here either. The two levels are outputs of different analyses over different hazard models, so a table asserting that some ASIL equals some MPL is a claim about two quantities never calibrated against each other. If a supplier presents one, ask what it derives from and who assessed it.
Missing the machine-specific concepts. Hydraulic System Robustness scoring, named in Part 2, has no automotive counterpart, for the plain reason that the machines are different. An earth-moving machine does its work through hydraulics, and the hydraulic path is part of how a safety function succeeds or fails. A reviewer whose mental model runs sensor to controller to actuator and stops will read straight past a part of the machine where real hazard lives.
Assuming ISO 15998 is still current. It is not. Part 1 cancelled and replaced ISO 15998 and ISO/TS 15998-2. Stale references survive where nobody rereads: a safety process written for a previous product, a supplier capability statement, a tender specification copied forward. Searching a machine programme for the old number is cheap. Discovering it during an assessment is not.
What Transfers Anyway
Almost all of the engineering discipline, and almost none of the vocabulary.
The safety-case mindset transfers completely: state a claim, marshal the evidence, and hand an assessor an argument rather than a pile of artefacts. Requirements traceability transfers, from hazard through safety requirement to design, code and test, and back up again. Verification evidence transfers, including structural coverage at unit level, review records and test results tied to requirements rather than to files. Tool discipline transfers too: the obligation to argue that your toolchain is fit for its job, and to hold evidence when that is challenged, belongs to every functional safety regime worth the name.
Say that plainly to a team that thinks of itself as automotive. Your static analysis practice against a coding standard, your unit testing with structural coverage, and your traceability chain are not automotive assets. They are functional safety assets, and they carry. Our functional safety capability page covers that toolchain side, and our ISO 26262 compliance page, linked above, covers what the automotive series asks of software and of the tools used to build it.
What does not transfer is the label and the analysis behind it. Nobody should write ASIL into an ISO 19014 document, or assume a hazard analysis performed for a road vehicle is the analysis this series wants.
Why Indian Teams Meet This Series Now
There is a commercial reason the timing matters. The CII-BCG study of India’s mining and construction equipment industry argues that localisation cannot stop at conventional surface equipment, and names safety-certified components, alongside underground equipment and remote-operation systems, among the capabilities India will need to build or partner for in that underground segment (Source: CII-BCG, Pressing the Throttle, July 2026, p. 27).
Be precise about what the study says. It names safety-certified components as a capability gap, in the context of underground and higher-technology equipment. It says nothing about ISO 19014, MPL, toolchains or verification practice. The step from that capability gap to the standards literacy and evidence-generation practice needed to close it is our reading, not the report’s.
Made in that reading, the argument is short. A component is not safety-certified because somebody certified it. It is safety-certified because the level it must reach was determined, a design was assessed against that level, and evidence exists that survives inspection. For an earth-moving machine that determination runs under this series, not the automotive one. A supplier base whose fluency stops at ISO 26262 can build to somebody else’s specification but cannot own the argument, and owning the argument is the part with margin in it.
Where GSAS Fits
GSAS Micro Systems is an engineering partner, and on functional safety our contribution sits on the evidence side rather than the certification side. We support the toolchain that produces what an assessment consumes: static analysis against a coding standard, unit and integration testing with structural coverage, traceability from requirement through code to test result, and the tool confidence evidence that says why those tools can be relied on. That is the same work whichever series governs the machine, which is why it transfers when your team does.
The sector view sits on our construction and mining page; functional-safety toolchain work runs from our offices in Bengaluru, Hyderabad, Chennai, Pune, Mumbai and Delhi NCR.
If you are moving a team from road-vehicle programmes onto machines, tell us which series governs the product and where your evidence chain currently stops when you request a quote. The reply will be a gap analysis rather than a catalogue.
References
- ISO 19014-1:2018 (corrected version 2019-02), “Earth-moving machinery, Functional safety, Part 1: Methodology to determine safety-related parts of the control system and performance requirements”, ISO/TC 127/SC 2. Cited at title, foreword and scope level from the publicly viewable preview of the document; the clause text is licensed and is not reproduced here.
- ISO 19014-2:2022, “Earth-moving machinery, Functional safety, Part 2: Design and evaluation of hardware and architecture requirements” (title given in abbreviated form). Cited at title, foreword and scope level from the publicly viewable preview, which is also the source for its self-description as an adaptation of ISO 13849, for the MPLa, mean-time-to-dangerous-failure, diagnostic-coverage and Hydraulic System Robustness concepts, and for the presence of an annex of exceptions to ISO 13849-1 and ISO 13849-2.
- ISO 19014-4:2020, “Earth-moving machinery, Functional safety, Part 4: Design and evaluation of software and data transmission for safety-related parts of the control system” (title as listed in public standards catalogues; punctuation adapted house-style).
- ISO 12100, “Safety of machinery, General principles for design, Risk assessment and risk reduction”, referenced for the type-A/B/C classification scheme as summarised in public standards-catalogue material.
- ISO 13849-1 and ISO 13849-2, “Safety of machinery, Safety-related parts of control systems”, referenced for the Performance Level lineage and its analysis vocabulary as summarised in public standards-catalogue material.
- ISO 26262 (2018 edition), cited for the road-vehicle scope, the ASIL scheme and the IEC 61508 relationship; the decomposition and process detail is drawn from our own /compliance/iso-26262 page.
- ISO 15998 and ISO/TS 15998-2, the earlier earth-moving machine-control-system safety documents, cited only as the works ISO 19014-1 records itself as cancelling and replacing.
- Confederation of Indian Industry and Boston Consulting Group, “Pressing the Throttle: How India’s Mining and Construction Equipment Industry can support domestic ambitions and become a global force”, July 2026, p. 27.
Also appears in:
Building for Construction & Mining?
Talk to our application engineers for personalized tool recommendations.
You might also like
View all →