This stage considers the identification and mitigation of hazardous failures of the AS. This considers the design of the AS at each tier to determine how hazardous failures could arise as a result of that design. This is a crucial activity since, even where the design has implemented completely all of the identified safety requirements, it still may be the case that the AS may be capable of doing something else, under certain conditions, that may be hazardous. It is therefore crucial that the potential hazardous failures are identified, and sufficient mitigations put in place.