Planning algorithms are verified for their ability to react as required and avoid unwanted action, using robustness tests against input interference, requirement-based tests, verification of architectural independence, in-the-loop and vehicle tests on SOTIF scenarios, injection of inputs that trigger hazardous behaviour, verification of compliance with the driving policy including achieving the minimal risk condition and operation on exiting the ODD, and re-simulation of known hazardous scenarios.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.