Annex B specifies nine roles, each with responsibilities and key competencies, filled with the independence of 5.1 and the competence evidence of 5.2 (5.2.2.5 requires compliance). Requirements Manager (B.1): specifies and actively manages the software requirements, keeps two-way traceability to system requirements, keeps them under change and configuration control with state, version and authorisation, keeps them consistent and complete against user needs and the final environment; competent in requirements engineering, experienced in the domain and its safety attributes, understands the system role, analytical techniques and regulations. Designer (B.2): turns requirements into acceptable solutions, owns the architecture and what follows, picks design methods and tools, applies design principles and standards, writes component specifications, keeps traceability and design documents under control; competent in the engineering area, safety design principles, design analysis and test, the problem domain, platform, operating system and interfacing constraints, and application engineering for data. Implementer (B.3): turns designs into data, code or other representations and code into executables, applies safety principles and coding or data standards, analyses intermediate results, integrates on the target using baselines, documents methods, data types and listings, keeps traceability and code under configuration control; competent in the language, tools, coding standards, platform constraints and integration approaches. Tester (B.4): ensures tests are planned, writes specifications, traces objectives to requirements and cases to objectives, runs the tests, records and reports deviations to change management, documents results and chooses test equipment; competent in the test domain and methods, derives cases from specifications, analytical with a system view. Verifier (B.5): writes the verification plan, checks evidence for completeness, consistency, correctness, relevance and traceability, identifies and risk-rates anomalies for change management, runs verification with the required independence, keeps records and writes the report. Validator (B.6): understands the software in its system and environment, writes the validation plan (agreed with the Assessor at SIL 1 to 4), reviews requirements against intended use and all development evidence, judges process and product conformity at the assigned level, reviews verification and test adequacy, ensures plan activities happen, risk-classifies deviations, recommends on suitability with application constraints, audits the project, checks traceability, writes the report and agrees or refuses release. Assessor (B.7): understands the software in its environment, plans and carries out the assessment, judges process and product conformity at the SIL, staff and organisation competence, verification and validation, quality management and configuration management, risk-evaluates deviations, audits and inspects, gives a professional view on fitness with constraints, application conditions and observations, and keeps records; competent in the domain and safety principles, able to judge every development process. Project Manager (B.8): puts the quality system and 5.1 independence in place and tracks progress, allocates enough competent resources, ensures a suitable Validator is appointed, is responsible for delivery and deployment and for stakeholders' safety requirements, allows time for safety tasks, endorses safety deliverables and keeps records of safety decisions. Configuration Manager (B.9): owns the configuration management plan, runs the system including change control, ensures every component is identified and separately versioned, and ensures release notes list any incompatible component versions.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.