Technology and assurance

Engineering discipline from concept to evidence.

AEMS develops the mechanism, electronics, control, sensing and health insight as parts of one safety-critical system.

Integrated, evidence-led development

A system, not a collection of parts

Behaviour is designed across every layer.

A safety-critical actuator is defined by more than force, stroke and speed.

The intended function, operating environment, failure response, interfaces and maintenance concept shape the architecture from the outset. AEMS uses that whole-system view to connect design decisions to the evidence needed later.

Integrated system layers

One operating concept, four connected views.

Each layer is developed against the same intended function and defined interfaces, so the equipment response remains coherent at platform level.

04

Platform and ground integration

Interfaces, configuration and through-life information

Defines how equipment status, constraints and support information connect with the wider operating and maintenance concept.

03

Health and assurance

Diagnostics, condition insight and remaining capability

Turns relevant equipment data into information that can support proportionate engineering and operational decisions.

02

Control and sensing

Command, monitoring and defined state management

Coordinates movement and observes system state against application-specific operating and fault-response requirements.

01

Electromechanical actuation

Motor, transmission, structure and mechanical interfaces

Creates controlled motion while managing the loads, duty cycle, installation constraints and environmental conditions of the application.

Design principles

Built around predictable behaviour.

Final architecture is tailored to the aircraft function. These principles provide the common engineering foundation.

01

Fault tolerance by architecture

Critical functions and failure responses are considered before detailed design choices are fixed.

02

Independence and segregation

Potential common causes and unintended interactions are addressed through appropriate physical and functional boundaries.

03

Modularity with controlled interfaces

Defined boundaries support configuration, integration, replacement and future evolution without losing system coherence.

04

Predictable fault response

Continued operation, degraded operation or position behaviour is selected to match the intended system outcome.

05

Embedded diagnostics

Useful state and health information is designed in, supporting verification and through-life decisions.

06

Maintainability by design

Access, inspection, interchangeability and configuration control are considered alongside performance.

Assurance pathway

Evidence grows with design maturity.

Activities are planned to reduce uncertainty, test assumptions and create traceable support for each important design claim.

  1. 01
    Intended function and requirements

    Define behaviours, interfaces, environments and measurable acceptance criteria.

  2. 02
    Safety analysis

    Identify failure conditions, contributing causes and the objectives allocated to the equipment.

  3. 03
    Architecture modelling

    Assess system behaviour, dependencies and interfaces before committing to detail.

  4. 04
    Prototype and bench evidence

    Use representative hardware and rigs to test performance, control and failure-response assumptions.

  5. 05
    Environmental and endurance evidence

    Demonstrate performance across relevant loads, duty cycles and operating conditions.

  6. 06
    Qualification and certification engagement

    Align the compliance route, evidence set and independent review with the intended application.

Development context: Current concept and prototype activity is not, by itself, product qualification or certification. The applicable objectives and evidence programme will be agreed for each application.

Evidence domains

Claims supported from more than one direction.

Specific methods, independence levels and acceptance criteria will depend on function criticality and the agreed assurance basis.

DomainTypical methodsIntended outcome
Functional and systemRequirements analysis, architecture review, modelling and integration testTraceable behaviour across normal, degraded and defined fault conditions
MechanicalLoad analysis, tolerance assessment, rig test, wear and endurance evaluationStructural margin, controlled motion and repeatable life performance
ElectronicsCircuit analysis, interface test, fault injection and hardware verificationRobust control, sensing, power conversion and monitoring
SoftwareLifecycle planning, traceability, review, analysis and requirements-based testingDeterministic implementation with evidence appropriate to its allocated role
EnvironmentalRepresentative temperature, vibration, electromagnetic, sealing and other application testsVerified operation across the declared equipment environment
Reliability and maintainabilityFailure data, reliability analysis, inspection planning and service feedbackSupported availability, maintenance and through-life decision-making

Where applicable, planning may draw on recognised civil aerospace system-development, safety-assessment, environmental, airborne electronic hardware and software assurance practices. The exact standards, editions and compliance objectives will be application-specific.

Information boundary

Clear in public. Detailed where appropriate.

Public overview

Product intent, system layers, design principles, development status and representative evidence methods.

Controlled disclosure

Detailed analyses, internal architecture, load paths, design data, test results and compliance evidence can be discussed under suitable confidentiality arrangements.

Engineering discussion

Connect the function to an evidence route.

Begin with a non-confidential outline of the operating need, interfaces, environment and intended failure response.

Discuss the technology