The component's safety analysis is adapted to the system level by transforming its detailed failure modes into the high-level failure modes the system analysis needs (Figure 4, combining bottom-up FMEA with top-down FTA), by accepting that coverage calculated for a part or subpart may be raised by measures at component, system or item level (an ADC with no hardware safety mechanism gains coverage from a software consistency check in a closed loop at system level), and by recognizing that coverage computed under specific assumptions of use only holds where those assumptions are fulfilled (an ECC whose correction flag was assumed to be handled by a software driver that the system does not implement).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.