Aller au contenu

ISO 24089: Managing Requirements for Automotive Software Updates

ISO 24089 - Managing Requirements for Automotive Software Updates
Listen to this blog

Modern vehicles have different sensors and electronic systems, from brakes, throttle, and steering to wipers, windows, and door locks. So, they heavily depend on software for more functionality and features, and software does not stop changing when a vehicle leaves the factory, as updates can alter vehicle behavior long after sale.

However, when an OEM releases an update, the problem is not simply: “How do we send new software to the vehicle?”

But the real problem is: how to determine what features need to be updated, manage the right update packages, verify the update is safe and compatible, deliver it to the correct vehicles, monitor updates, recover from failure, and maintain a complete record of what changed for audit trails.

That’s exactly why ISO 24089:2023 was introduced. It provides a framework for software update engineering across the organizational and project levels. It also connects closely with UNECE R156 and its Software Update Management System requirements.

In this blog, we will cover what ISO 24089 is, compare it with UNECE R156, and how to adhere to ISO 24089 while updating software in automotive.

Points clés à retenir

What you’ll learn in this article

  • ISO 24089:2023 is the international standard for on-road vehicle software update engineering, governing updates at both the organizational and project levels — not just the moment code reaches the car.

  • It applies to every delivery method, not only OTA — service-station, plant, and OEM assembly updates all fall under its scope.

  • ISO 24089 and UNECE R156 work together: R156 is the mandatory UN regulation for type approval, while ISO 24089 is the voluntary engineering standard for how to actually do the work.

  • The standard demands traceable requirements and evidence — impact analysis, verification linked to requirements, software identity, update records, and RXSWIN — forming one connected chain from requirement to update record.

  • Modern Requirements4DevOps lets teams manage that traceability inside Azure DevOps — with baselines, e-signature reviews, and audit-ready reports exported without leaving the workspace.

Want to simplify ISO 24089 requirements management inside Azure DevOps? Get a Demo

What is ISO 24089?

ISO 24089 is an international standard on “on-road vehicle software update engineering” published by ISO/TS 22/SC32 in 2023 and amended in 2024. The standard gives a set of processes that enable planning, developing, verifying, validating, and documenting software updates at the organization as well as at the project level.

  1. Organizational level: It covers how a company manages a software update as a whole. (Policies, Roles, Competence, Evidence, Process)
  2. Project level: It is about actually carrying out a particular software update, including changes, requirements, safety impact, tests, software version, update package, ECUs, etc. It answers “can we safely execute this particular update?”

The important point to consider is that “Software Update Engineering” is not just about OTA (Over-the-Air) update as it is only one delivery mechanism. A vehicle can receive software through OTA, workshop, service tools, diagnostic interface, or manufacturing processes. So, ISO 24089 needs to be followed in all of these cases.

ISO 24089 vs UNECE R156: Standard and Regulation

ISO 24089 and UN R156 harmonize with each other, but each has different importance in the automotive industry.

Aspect
UNECE R156
ISO 24089
Type Regulation vs standard
A United Nations vehicle regulation.
An international standard.
What does it cover? Coverage
Establishes regulatory requirements around software updates and the use of a Software Update Management System (SUMS).
Covers how software update activities should be organized and controlled.
Is it mandatory? Obligation
Yes, for vehicle type approval.
Voluntary — it provides recommendations, but is good practice to follow.
Main focus Primary concern
Whether the manufacturer has an appropriate software update management system and can meet the regulation’s requirements.
How organizations engineer, manage, and control software update activities across the update lifecycle.
Scope What’s included
Covers:
  • Software update management
  • Vehicle approval
  • Software identification
  • Related regulatory requirements
Defines how to manage vehicle systems, ECUs, infrastructure, and the assembly and deployment of software update packages after initial development.
Assessment How it’s evaluated
Done by regulatory bodies and valid for 3 years.
Used as a good engineering reference.
Simple way to remember it In a sentence
“What must the manufacturer demonstrate for regulatory approval?”
“How should the organization engineer and manage its software update activities?”

Why Software Updates Need an Engineering Discipline (The Importance)

When a vehicle receives an OTA software update, it can affect the functionality of brakes, steering, cybersecurity, and other ECUs on millions of vehicles simultaneously. If something goes wrong in the update, it can create a security and safety hazard and a potential recall.

Furthermore, it is proven: In the U.S., vehicle recalls due to software-related issues rose from roughly 5% historically to 15% in 2023. 

So, when a software update malfunctions, engineers have to track the entire process: exactly which requirements were impacted, their tests, vehicle types, which ECUs are affected, and which software identifier now applies. If you lose even one step from the process, it is impossible to know whether the update was safe. That’s why software updates in automotive need to follow ISO 24089 rules and require engineering and requirements management discipline. It turns “we’ve pushed right updates” into “we can prove every update was engineered, tested, verified, and traceable.

The Requirements and Evidence ISO 24089 Actually Demands

ISO 24089 treats automotive software updates as an engineering activity instead of just a release operation. For each update, teams need to maintain a clear record of what is changing, what the change effect is, and how the resulting software is verified with proven evidence. Here is key evidence that ISO 24089 actually demands from automotive teams:

  • Update requirements: Functional, safety, security, etc. requirements should be traceable, and teams need to maintain a history of that. Also, these requirements should trace back to the changes and must be connected with verification activities through forward traceability.
  • Impact analysis: It demands documented impact analysis that contains which vehicle systems, ECUs, dependencies, safety concerns, or security controls could be affected due to proposed changes.
  • Verification: Test cases must be connected with software requirements to prove they are tested properly without missing anything.
  • Software identity: Which software version and relevant identifiers correspond to the verified update?
  • Update records: A clear record of which vehicles received which update package and what the outcome was.
  • RXSWIN: It connects a specific software version on a particular vehicle type back to the requirements it satisfies and tests that verify it. With that, you can demonstrate that the vehicle on the road uses software that the team engineered and approved against ISO 24089 requirements.

When teams have end-to-end traceability, it creates a connected engineering record like below:

Requirement -> Impact -> Implementation -> Verification -> Software version -> Update record

In the next section, let’s look at how teams can use requirement management systems to achieve ISO 24089 goals in the automotive industry.

Managing ISO 24089 Requirements in Azure DevOps Using Modern Requirements4DevOps

Modern Requirements4DevOps is an award-winning requirement management tool that works directly inside your Azure DevOps workspace. With that, automotive teams can store functional safety requirements, security requirements, etc., inside Azure DevOps as managed work items. On top of that, teams can use different features of Modern Requirements to manage end-to-end traceability, review cycles, baselines, etc., to achieve ISO 24089 goals without switching between multiple tools.

By using the Traceability module, teams can visualize which RXSWIN number or change requirement is connected with which software update requirements, test cases, software versions, etc. It also allows teams to identify missing requirements, implement them, and prove that ISO 24089 requirements are implemented correctly.

Furthermore, by using the Baseline module, teams can create new baselines for every automotive software update. It locks the approved requirements, test cases, etc, and produces evidence of what was implemented in a particular release inside Azure DevOps.

The Review Management helps in reviewing safety or compliance requirements with e-signatures without leaving Azure DevOps. It also keeps track of who approved software update requirements and how it was approved, giving evidence to prove ISO 24089 requirements are implemented.

The best part? The Smart Report module allows exporting audit reports, which contain what software or security requirements are updated, who approved it, how it was implemented, against which test cases it was verified, how it is connected with other requirements, etc., with one click. Automotive teams can directly submit that to regulatory bodies with minimal review.

Foire aux questions

Is ISO 24089 mandatory for automotive manufacturers?

ISO 24089 is an international standard, but it is not mandatory to follow. However, it provides a voluntary framework that helps in managing software update requirements and staying aligned with the regulatory controls.

Does ISO 24089 apply only to OTA updates?

No, it does not apply only to OTA updates. Instead, it applies to all software updates, whether it is made from a service station, OTA, at OEMs’ place, etc.

Why does requirements traceability matter for a software update?

When something goes wrong, teams need to check how a particular feature was implemented to diagnose the issue. Without bidirectional end-to-end traceability, teams can’t visualize connected requirements and struggle to diagnose the issues. It also allows proving that software updates were made in such a way it followed ISO 24089 requirements.

How can a requirements tool help with ISO 24089?

A requirements management tool like Modern Requirement4DevOps helps teams prepare traceable evidence, capture baselines, manage review cycles where requirements are stored and managed, track software update versions, and produce audit-ready evidence for a SUMS assessment inside Azure DevOps.

Table des matières

Commencez dès aujourd'hui à utiliser Modern Requirements

✅ Définissez, gérez et suivez les exigences dans Azure DevOps
✅ Collaborez en toute fluidité entre équipes soumises à des réglementations
✅ Commencez GRATUITEMENT — aucune carte de crédit requise

Articles récents

Modern Requirements logo mark