EARS Notation: The Practical Guide to Writing Requirements That Cannot Be Misread
Learn EARS notation, its keyword patterns, and how to turn...
Modern vehicles have different sensors and electronic systems, from brakes, throttle, and steering to wipers, windows, and door locks. So, they heavily depend on software for more functionality and features, and software does not stop changing when a vehicle leaves the factory, as updates can alter vehicle behavior long after sale.
However, when an OEM releases an update, the problem is not simply: “How do we send new software to the vehicle?”
But the real problem is: how to determine what features need to be updated, manage the right update packages, verify the update is safe and compatible, deliver it to the correct vehicles, monitor updates, recover from failure, and maintain a complete record of what changed for audit trails.
That’s exactly why ISO 24089:2023 was introduced. It provides a framework for software update engineering across the organizational and project levels. It also connects closely with UNECE R156 and its Software Update Management System requirements.
In this blog, we will cover what ISO 24089 is, compare it with UNECE R156, and how to adhere to ISO 24089 while updating software in automotive.
ISO 24089:2023 is the international standard for on-road vehicle software update engineering, governing updates at both the organizational and project levels — not just the moment code reaches the car.
It applies to every delivery method, not only OTA — service-station, plant, and OEM assembly updates all fall under its scope.
ISO 24089 and UNECE R156 work together: R156 is the mandatory UN regulation for type approval, while ISO 24089 is the voluntary engineering standard for how to actually do the work.
The standard demands traceable requirements and evidence — impact analysis, verification linked to requirements, software identity, update records, and RXSWIN — forming one connected chain from requirement to update record.
Modern Requirements4DevOps lets teams manage that traceability inside Azure DevOps — with baselines, e-signature reviews, and audit-ready reports exported without leaving the workspace.
ISO 24089 is an international standard on “on-road vehicle software update engineering” published by ISO/TS 22/SC32 in 2023 and amended in 2024. The standard gives a set of processes that enable planning, developing, verifying, validating, and documenting software updates at the organization as well as at the project level.
The important point to consider is that “Software Update Engineering” is not just about OTA (Over-the-Air) update as it is only one delivery mechanism. A vehicle can receive software through OTA, workshop, service tools, diagnostic interface, or manufacturing processes. So, ISO 24089 needs to be followed in all of these cases.
ISO 24089 and UN R156 harmonize with each other, but each has different importance in the automotive industry.
When a vehicle receives an OTA software update, it can affect the functionality of brakes, steering, cybersecurity, and other ECUs on millions of vehicles simultaneously. If something goes wrong in the update, it can create a security and safety hazard and a potential recall.
Furthermore, it is proven: In the U.S., vehicle recalls due to software-related issues rose from roughly 5% historically to 15% in 2023.
So, when a software update malfunctions, engineers have to track the entire process: exactly which requirements were impacted, their tests, vehicle types, which ECUs are affected, and which software identifier now applies. If you lose even one step from the process, it is impossible to know whether the update was safe. That’s why software updates in automotive need to follow ISO 24089 rules and require engineering and requirements management discipline. It turns “we’ve pushed right updates” into “we can prove every update was engineered, tested, verified, and traceable.
ISO 24089 treats automotive software updates as an engineering activity instead of just a release operation. For each update, teams need to maintain a clear record of what is changing, what the change effect is, and how the resulting software is verified with proven evidence. Here is key evidence that ISO 24089 actually demands from automotive teams:
When teams have end-to-end traceability, it creates a connected engineering record like below:
Requirement -> Impact -> Implementation -> Verification -> Software version -> Update record
In the next section, let’s look at how teams can use requirement management systems to achieve ISO 24089 goals in the automotive industry.
Modern Requirements4DevOps is an award-winning requirement management tool that works directly inside your Azure DevOps workspace. With that, automotive teams can store functional safety requirements, security requirements, etc., inside Azure DevOps as managed work items. On top of that, teams can use different features of Modern Requirements to manage end-to-end traceability, review cycles, baselines, etc., to achieve ISO 24089 goals without switching between multiple tools.
By using the Traceability module, teams can visualize which RXSWIN number or change requirement is connected with which software update requirements, test cases, software versions, etc. It also allows teams to identify missing requirements, implement them, and prove that ISO 24089 requirements are implemented correctly.
Furthermore, by using the Baseline module, teams can create new baselines for every automotive software update. It locks the approved requirements, test cases, etc, and produces evidence of what was implemented in a particular release inside Azure DevOps.
The Review Management helps in reviewing safety or compliance requirements with e-signatures without leaving Azure DevOps. It also keeps track of who approved software update requirements and how it was approved, giving evidence to prove ISO 24089 requirements are implemented.
The best part? The Smart Report module allows exporting audit reports, which contain what software or security requirements are updated, who approved it, how it was implemented, against which test cases it was verified, how it is connected with other requirements, etc., with one click. Automotive teams can directly submit that to regulatory bodies with minimal review.
ISO 24089 is an international standard, but it is not mandatory to follow. However, it provides a voluntary framework that helps in managing software update requirements and staying aligned with the regulatory controls.
No, it does not apply only to OTA updates. Instead, it applies to all software updates, whether it is made from a service station, OTA, at OEMs’ place, etc.
When something goes wrong, teams need to check how a particular feature was implemented to diagnose the issue. Without bidirectional end-to-end traceability, teams can’t visualize connected requirements and struggle to diagnose the issues. It also allows proving that software updates were made in such a way it followed ISO 24089 requirements.
A requirements management tool like Modern Requirement4DevOps helps teams prepare traceable evidence, capture baselines, manage review cycles where requirements are stored and managed, track software update versions, and produce audit-ready evidence for a SUMS assessment inside Azure DevOps.
✅ Définissez, gérez et suivez les exigences dans Azure DevOps
✅ Collaborez en toute fluidité entre équipes soumises à des réglementations
✅ Commencez GRATUITEMENT — aucune carte de crédit requise
Learn EARS notation, its keyword patterns, and how to turn...
Baselining and versioning are not the same, and most teams...
What CAPA means in medtech and pharma, the process and...
End-to-end requirements management in Azure DevOps.
AI-powered assistance for DevOps workflows.
Autonomous AI agents for DevOps execution.
Compliance management, built into Azure DevOps.
Real-time data sync across tools and systems.