AC 922-001 Section 4.6 - section overview

Verified from official sources
AC 922-001 Section 4.6Version 1Effective -Verified 23 August 2026

In plain language

This section provides guidance on meeting low and high robustness containment standards for RPAS, focusing on single failure considerations, system isolation, and design assurance requirements to prevent fly-aways.

Requirement as structured

This section provides guidance on meeting low and high robustness containment standards for RPAS, focusing on single failure considerations, system isolation, and design assurance requirements to prevent fly-aways.

Original regulatory text

(3) Single Failure Considerations . Both the low and high robustness containment standard require that no single failure result in a fly-away of the RPA. Therefore, the containment means needs to be independent from any systems on the RPAS that could result in a fly-away. For example, a flight termination system that relies on the RPAS C2 link for activation would not meet the single failure requirement, because presumably, a failure of the C2 link would result in an inability to both control and flight-terminate the RPA. The result would be that the operator no longer has the means to ensure containment. On the other hand, and flight termination system that safely ends the flight following a C2 link failure could be acceptable depending on the details of the system architecture. The system safety analysis would need to show that there are no common cause failures that could result in a failure of both the C2 link and the flight termination system (i.e., both the RF transceiver and the flight termination system should not be powered by the same power source). Consideration also needs to be given to errors in Software and Electronic Hardware that could lead to a fly-away condition. System analysis needs to show that systems used to prevent flyaway are isolated from errors that could occur other software or electronic hardware components. In general, this will drive applicants to containment systems that are developed and implemented independently from other systems used in the RPAS. (4) Low Robustness Containment . At the most basic level, and applicant could show compliance to this standard by limiting the fuel/electrical energy of the drone such that it does not have the endurance required to leave the operational volume. For example, an RPAS with 10 minutes of endurance inside an operational volume such that it is more than 10 minutes at max speed from any edge of the operational volume will be unable to exit that operational volume in the event of a failure. More realistically, an applicant wishing to show that they meet the low robustness containment requirements will need to perform a system safety analysis on their RPAS with a focus on system failures that could result in the RPA leaving the operational volume without the operator being able to stop it. One example of a failure that could cause this would be C2 link loss while the RPAS programmed to maintain heading and altitude. Another example would be a failure in the navigation sensor leading the RPAS incorrectly flying outside of the operational volume. For failures such as these it is predicted that the manufacturer would add independent redundancy to their RPAS that will either take-over and perform the necessary function or terminate the flight safely. As an example, a manufacturer of an RPAS performs a design review of their RPAS design and finds that the system autopilot uses open-source software that has no pedigree of design or developmental assurance. The review would then need to determine whether an autopilot software fault could lead to an aircraft flyaway. For a system like this, if the manufacturer wanted to show low robustness containment on this RPAS, their options are: - (a) Replace, Redesign and Validate the Autopilot in order to show that no single failure of that autopilot would lead leading to a flyaway. Since software items are typically assumed to contain software errors, this redesign would require independent redundancy to be designed into the autopilot. - (b) Add an independent flight termination system that can be activated by the operator in the event that a failure of the autopilot results in a fly-away. The applicant would need to show that the system allows the operator to be alerted if there is a failure of the flight termination system. The applicant would also need to ensure that the operator is alerted to conditions that could indicate that a flyaway is imminent and have procedures established for activation of the flight t

Applies when

country
Canada
regulatory category
Specific