Advisory · Tier 3 · Sample engagement · August 2026

Cockpit Electronics Audit-Readiness

a cockpit consolidation, graded in three weeks

Cluster and infotainment grew up as separate boxes. Now they share one chip, and nobody trusts the safety boundary. This page walks one assessment end to end: the client, the cockpit system the work runs on, the published reference it is graded against, the exercises, the week-by-week cadence, and the findings report your sponsor forwards upward.

assess from US$6,500 · 2 to 3 weeks 50% at signature · 50% on delivery four-domain reference read-only access fully remote
What is simulated and what is real. The client, "Andare Cockpit Systems," is fictional and built for this demonstration; every scenario number is labeled as such. The reference architecture, the component families, the standards figures, and the market data come from Ordinara's cockpit electronics knowledge base and its architecture reference for a production dual-processor cluster program. Sources are reproduced in full at the end. This page is the public sample of the assess phase of the SDV audit-readiness sprint, run here on a cockpit electronics program.
The 60-second read

Verdict: declared, not evidenced. Three findings stand between ICP-1 and its Q1 2027 audit

2.1 / 4
Maturity against the four-domain cockpit reference: "Declared, not evidenced"
16
Criteria graded across four domains, each backed by a config file, bench log, or test ID
3
Findings to close before the Q1 2027 OEM audit, each with a costed action
0
Re-architecting required: the choices are sound, the evidence trail is not

The one-line story: the supervision duties the old discrete cluster performed in hardware were deleted with the hardware, and the claims that replaced them ("the hypervisor handles it") do not cite evidence. The rest of this page shows how that verdict was earned.

I · Why this service exists

One chip now carries both worlds, and the safety boundary moved with nobody watching

For two decades the instrument cluster and the infotainment unit evolved along parallel but strictly isolated trajectories: the cluster on deterministic, fail-safe real-time software, the infotainment on rich, resource-heavy consumer stacks. The integrated cockpit ends that isolation. A single heterogeneous SoC now drives the cluster, the center stack, the HUD, and the passenger display, with a Type-1 hypervisor holding an ASIL B safety island and a QM Android guest apart on shared silicon. The engineering is available. What most organizations cannot produce is evidence that their boundary actually holds: who supervises a rendered telltale, what happens to the regulatory chime when the infotainment guest restarts, and what independent path exists if the hypervisor itself faults.

1 SoC
A single cockpit chip (SA8295P class) concurrently drives cluster, center stack, HUD, and passenger display: three DisplayPorts, four eDP, two MIPI DSI
Qualcomm SA8295P development platform documentation (Lantronix), 2026
90 / 60
Percent single-point and latent fault detection metrics ASIL B requires the cluster domain to demonstrate, not assert
ISO 26262 ASIL decomposition guidance, Arm Learning Paths / Parasoft · knowledge base, Jul 2026
$52.6B
Projected global digital cockpit market by 2031, growing at 12.02% CAGR: every OEM award now assumes the integrated architecture
Mordor Intelligence, automotive digital cockpit market, 2031 projection · retrieved Jul 2026

The failure pattern is organizational before it is technical. The cluster team carries the safety culture; the infotainment team carries the release velocity; the consolidation program inherits both and a boundary that belongs to neither. Cost-downs quietly delete the mechanisms the old discrete architecture provided for free: the external safety MCU, the hardwired telltale, the independent watchdog reset path.

The problem this offer solves

"The hypervisor handles it" is not evidence. This assessment grades your cockpit architecture against a published four-domain reference and returns a gap grid, a maturity rating, and a roadmap: every grade backed by a config file, a bench log, or a test ID, and every gap carrying a costed action.

II · The simulated client

Andare Cockpit Systems, a Tier-1 mid-consolidation

Andare is fictional, but its shape is the standard shape of this engagement: a supplier with a trusted discrete cluster in production, a first integrated-cockpit award in hand, and two engineering cultures that have never shared a safety case.

Company
Tier-1 cockpit electronics supplier. Discrete clusters and IVI units shipping to three OEMs; first integrated cockpit award in hand.
Products in scope
DC-2: discrete dual-processor cluster, in production (safety MCU + graphics MPU, ISO 26262 ASIL B). ICP-1: integrated cockpit domain controller on an SA8295P-class SoC, Type-1 hypervisor, QNX cluster guest + Android Automotive IVI guest. SOP 2029.
Team
~140 engineers at two sites. Cluster team of 45 (AUTOSAR, safety culture), IVI team of 80 (Android, consumer cadence). Functional safety team of 5, attached to the cluster org only.
Sponsor
VP of Cockpit Electronics. Accountable to a Global Engineering Director for the ICP-1 award, with an OEM process audit scheduled Q1 2027.
Entry point
Executive AI evidence session four weeks earlier (US$1,500 to 3,000, prepaid). Its live demo traced telltale signals in Andare's own DBC export and could not establish who supervises rendered telltales on ICP-1. Session fee credited against this assessment.
Presenting question
"Cluster and infotainment grew up as separate boxes. On one chip, nobody can show me where the safety boundary actually is."

The four entry findings the assessment inherits

#Finding from the working sessionWhy it matters on ICP-1
F1No single document lists the cross-domain channels between the QNX and Android guests. Estimates in the room ranged from 20 to 70.Freedom from interference cannot be argued over an inventory nobody has. The boundary is whatever the channels are.
F2Telltale supervision is asserted ("the hypervisor handles it") with no config file or test ID cited.Anything the driver must legally see cannot depend solely on unsupervised rendering. Assertion is the signature of a program that fails its OEM audit.
F3The external safety MCU present on DC-2 was removed from ICP-1 in a cost-down. Nobody in the room could state what assumed its supervision duties.DC-2's independent watchdog, hardwired telltales, and hard-reset escalation all lived on that part. Deleting the part without reassigning the duties deletes the safety concept.
F4The OEM requirement "first telltale within 2.0 s of ignition" has no measured value on the current ICP-1 bench build.Boot on the integrated SoC is a hypervisor-then-guest sequence. Without a measured budget, the requirement is discovered at C-sample, when it is expensive.
III · The system under assessment

The ICP-1 cockpit domain controller, boundary by boundary

This is the substrate the whole assessment runs on. One SA8295P-class SoC hosts a QNX cluster guest (the ASIL B island) and an Android Automotive IVI guest (QM) over a Type-1 hypervisor, feeding a 12.3-inch cluster display and a 14.6-inch center display through a serializer link. Every exercise output in this demo is drawn from this system, and the excerpts below are the exercises' actual work products in the simulation: real signal semantics, realistic timing, simulated identifiers.

What the consolidation removed, mechanism by mechanism

DC-2, the shipping discrete cluster, earns trust the classical way. The assessment's first job is naming exactly which of its mechanisms ICP-1 silently dropped:

MechanismDC-2 · discrete cluster (in production)ICP-1 · integrated cockpit (bench build B0.7)
Regulatory telltalesHardwired LEDs driven by the safety MCU with current readbackAll rendered by the QNX guest; supervision only via framebuffer CRC regions
Independent supervisionSBC question/answer watchdog external to both processors; MCU can force a hardware reset of the graphics MPUOn-SoC safety island only; no mechanism independent of the SoC if the hypervisor faults
Guest-to-guest trafficOne protected UART IPC: sequence counter, data ID, CRC, E2E profile63 channels: VirtIO devices, shared memory rings, GPU contexts, services
Regulatory chimePiezo driven directly by the safety MCURouted through the Android guest's audio HAL (QM)
Odometer and NvMMCU-side EEPROM/FRAM, redundant, checksummed, isolated from the MPU filesystemRetained on a dedicated NvM partition with brokered access · one of the strengths

Exercise E1 + E2 output · the cross-domain boundary register, excerpt

Extracted by AI from the hypervisor device tree, VirtIO configuration, ARXML and DBC exports, and build manifests; corrected in review; signed by the cluster and IVI leads in week 1. Eight of the 63 channels:

IDClassBoundaryCarrierCriticality crossingSupervision today
XB-004guest–guestvgw signal gateway → QNX cluster app (vehicle signals incl. telltale sources)VirtIO-net, 10 ms cycleQM → ASIL BE2E CRC on payload; the gateway process itself is QM
XB-011guest–gpuAndroid media surfaces → shared compositor plane 2GPU contextQM → shared GPUTime-partition declared in config; NO EVIDENCE
XB-017guest–hwQNX telltale layer → display controller pipe 0Framebuffer regions A + BASIL B → panelCRC monitor active for region A only
XB-023guest–guestSeatbelt chime request → Android audio HALVirtIO audioASIL B → QMNONE · chime dies with an IVI restart
XB-031guest–hwBacklight PWM authority, both displaysI2C via serializer control channelQM dimming service → panelNONE · cluster legibility owned by IVI code
XB-038soc–vehicleOTA agent → cluster guest partitionEthernet, DoIP sessionQM → ASIL B partitionWrite path unbrokered on bench build
XB-047guest–islandQNX guest watchdog registration → safety islandHypercall, Q/A window 100 msASIL B → islandVerified on bench · TC-0781
XB-052hyp–hwHypervisor fault → display safe stateNone present·NO PATH independent of the SoC

8 of 63 channels · full register signed W1, day 5 · identifiers simulated, semantics realistic

Exercise E3 output · the telltale path trace, excerpt

Every regulatory telltale traced from source frame to pixel, classified, and timed on the client's bench (client hands on hardware, Ordinara remote). Five of twelve:

IDTelltaleSourcePath classSupervision foundFirst valid (cold boot)Verdict
TT-02PRNDL / gear0x1B2Rendered, region ACRC region A, 50 ms fault reaction · TC-07633.8 sPASS · boot gap noted
TT-03Brake system0x2C4Rendered, region BRegion B not registered with the CRC monitor3.8 sFAIL → G-01
TT-06Airbag / SRS0x1D6Rendered, region BRegion B not registered3.8 sFAIL → G-01
TT-07Seatbelt + chime0x3A2Split: lamp in QNX, chime via Android audioLamp unsupervised; chime lost 9.4 s during the IVI restart test3.8 sFAIL → G-02
TT-09ABS0x2C8Rendered, region BRegion B not registered3.8 sFAIL → G-01

5 of 12 regulatory telltales · full trace in the gap grid · OEM requirement: first telltale ≤ 2.0 s from KL15

Exercise E4 + E5 output · the evidence, as found

safe_render.cfg · ICP-1 bench build B0.7 · read-only pull, W2 day 2
display0.pipe0.region_a   = { x:412, y:24, w:496, h:96 }   # speed · PRNDL
display0.pipe0.region_a.crc_ref   = crc_table_a.bin @ 60 Hz
display0.pipe0.region_a.on_fail   = FAULT_REACTION_50MS      # verified · TC-0763
display0.pipe0.region_b   = (absent)                          # telltale strip · TT-03/06/09 unsupervised
gpu.partition.qnx_slice   = 4ms/frame  # declared          # no test ID found in any evidence folder
watchdog.island.qa_window = 100ms                            # verified · TC-0781
watchdog.external         = (none)                            # DC-2 duty, unassigned since cost-down
boot timing log · cold start, KL15 rising edge = t0 · bench run W2 day 3, client hands, Ordinara remote
t + 0.6 s   hypervisor up, guests scheduled
t + 3.1 s   QNX guest first frame (splash)
t + 3.8 s   telltale regions valid            # requirement: ≤ 2.0 s
t + 11.2 s  Android home surface ready
reference: DC-2 discrete cluster, same bench: first telltale < 2 s behind static splash

One artifact, end to end: the brake telltale, TT-03

Every exercise touches it, and it exits the assessment as a graded gap with a costed action. This is the spine of the whole service:

  1. E1 names it. The domain map places 0x2C4 brake status among the safety-relevant signals terminating in the QNX cluster guest.
  2. E2 registers its crossings. It enters the boundary register twice: XB-004 (through a QM gateway process) and XB-017 (framebuffer region B to the panel).
  3. E3 traces and times it. Path class: rendered, region B. First valid at 3.8 s against a 2.0 s requirement. Supervision: none found.
  4. E4 converts opinion to evidence. The safe_render.cfg pull shows region B absent from the CRC monitor. "The hypervisor handles it" is now a falsified claim, in writing.
  5. E7 grades it. Criterion D3.2, safe-rendering supervision, grade 1 of 4. Finding G-01, severity high: three regulatory telltales unsupervised.
  6. The report prices the fix. Roadmap item R-01: register region B, add the fault-reaction test, 30 days, no hardware change. Your board reads that line, not this page.
IV · The published reference

Four domains, sixteen criteria, one grading scale

The assessment grades against Ordinara's published cockpit reference architecture, assembled from certified-component practice (QNX OS for Safety, pre-certified Type-1 hypervisors, Vulkan SC) and the supervision mechanisms of production dual-processor cluster programs. Because the reference is public, the grade is comparable: across programs, across sites, and across re-grades.

DomainCriteriaWhat the reference requires
D1 · Cluster safety domainD1.1–D1.4Certified base for the cluster guest (ASIL-certified OS); supervision independent of the supervised element; a stated and measured availability budget (first telltale from KL15); single-point and latent fault metrics demonstrated, not asserted (ASIL B: ≥90% / ≥60%)
D2 · Infotainment domainD2.1–D2.4Type-1 hypervisor with evidenced time and space partitioning; proven restart independence (an IVI crash disturbs nothing regulatory); a complete, owned inventory of every cross-domain channel; brokered OTA and update paths into safety partitions
D3 · Display and telltale integrityD3.1–D3.4Every regulatory telltale classified (hardwired, rendered-supervised, rendered-unsupervised) with zero in the last class; framebuffer CRC supervision with a defined fault reaction; deterministic graphics for the safety layer (offline-compiled pipelines, static memory); display link and backlight authority under safety control
D4 · Organizational readinessD4.1–D4.4One HARA/TARA practice co-engineered across both teams (ISO 26262 + ISO/SAE 21434); a named owner for every boundary; change governance that triggers re-verification on evidence, not negotiation; claims that cite test IDs

The grading scale

GradeNameMeaning
1UndocumentedThe mechanism or inventory does not exist in writing. Nobody can point at it.
2DeclaredIt exists in a config, plan, or slide, but no test ID or measurement backs it. This is where "the hypervisor handles it" lives.
3EvidencedBacked by cited evidence: a config pull, a bench log, a test ID an auditor can re-run.
4GovernedEvidenced, owned, and re-verified on change by rule. Survives personnel and schedule pressure.
Operating rule

No AI output enters the register, the trace, or the grade without a named engineer's sign-off against written acceptance criteria. AI proposes; engineers dispose. The deliverable is judgment with evidence attached, and the delivery system is disclosed, never disguised as staff.

V · The exercise battery

Seven exercises, three weeks, sixteen criteria covered

Each exercise states who does what, where the AI sits, the signed artifact it produces, and the reference criterion it feeds. Nothing here is generic AI enablement: every output lands in the gap grid.

Week 1 · architecture and domain review
E1 Architecture inventory and domain map D1.1 · D2.1
Andare does
Provides read-only access: block diagrams, hypervisor device tree, build manifests, ARXML and DBC exports, certification records for OS and hypervisor.
Ordinara does
Designs the extraction schema; reviews every AI run before engineers see it; walks the resulting map with both leads.
AI component
LLM extraction of the cockpit topology and the declared criticality of every element from heterogeneous source documents into one map.
Signed artifact
Cockpit domain map: every element placed in D1 or D2 with its declared ASIL, signed by the cluster and IVI leads.
Reference criterion
Establishes the certified-base and partitioning claims (D1.1, D2.1) that W2 will test for evidence.
E2 Cross-domain boundary register D2.3 · D4.2
Andare does
Engineers accept, reject, or rewrite each candidate channel; leads sign the register and name owners where they exist.
Ordinara does
Defines the channel taxonomy (guest–guest, guest–hw, guest–gpu, soc–vehicle); audits a random 10% of confirmed entries.
AI component
Extraction of every VirtIO device, shared memory ring, GPU context, and service crossing between guests from configs and manifests.
Signed artifact
Signed boundary register: 63 channels with class, carrier, criticality crossing, and current supervision. F1 closed.
Reference criterion
D2.3 channel inventory; D4.2 exposes the 41 channels with no named owner.
Week 2 · safe-rendering and telltale path
E3 Telltale path trace D3.1
Andare does
Runs the bench: cold boots, signal injection per telltale, the IVI restart test. Hands on hardware stay Andare's.
Ordinara does
Scripts the trace protocol, watches the runs remotely, classifies each path with the engineers on the call.
AI component
Correlates DBC signal definitions, gateway routing tables, and the QNX render tree to propose each telltale's full path before the bench confirms it.
Signed artifact
Telltale path evidence table: all 12 regulatory telltales classified and timed, signed by the functional safety lead.
Reference criterion
D3.1: zero telltales may remain rendered-unsupervised. The table shows exactly which are.
E4 Safe-rendering verification review D3.2 · D3.3
Andare does
Pulls the configs and build logs; test leads confirm or deny each supervision claim against the evidence folders.
Ordinara does
Reads the CRC monitor configuration, the Vulkan SC pipeline cache, and the fault-reaction tests; flags every claim with no test ID.
AI component
Cross-references every supervision claim in the safety plan against config files and the test register; unmatched claims surface as findings.
Signed artifact
Safe-rendering evidence sheet: per region, the config line, the test ID, or the words NO EVIDENCE. F2 closed either way.
Reference criterion
D3.2 supervision; D3.3 deterministic graphics (offline-compiled pipelines, static object pools).
E5 Supervision and degradation review D1.2 · D1.3 · D2.2
Andare does
Runs the degradation battery on the bench: guest kill, gateway stall, watchdog starvation, IVI restart under load.
Ordinara does
Designs the fault matrix from DC-2's proven escalation chain; maps each DC-2 duty to its ICP-1 assignee, or to nobody.
AI component
Parses bench timing logs into the boot and fault-reaction budget table; diffs the DC-2 safety concept against ICP-1 to list unassigned duties.
Signed artifact
Degradation matrix with measured reactions, plus the boot timing evidence (3.8 s vs the 2.0 s requirement). F3 and F4 closed.
Reference criterion
D1.2 independent supervision; D1.3 availability budget; D2.2 restart independence.
Weeks 2 to 3 · organizational readiness, gap grid, roadmap
E6 Organizational readiness review D4.1–D4.4
Andare does
Six structured interviews, 45 minutes each: both leads, the safety manager, a senior engineer per team, the program manager. Provides the HARA, TARA, and change-control records.
Ordinara does
Conducts the interviews; grades process claims only where a record backs them.
AI component
Synthesis of interview notes against the process records; contradictions between what is said and what is written surface as findings.
Signed artifact
Organizational readiness scorecard: HARA/TARA unification, boundary ownership count, change-trigger discipline, evidence culture.
Reference criterion
All four D4 criteria. This is where "two cultures, one chip" gets measured instead of lamented.
E7 Gap grid and roadmap assembly All 16 criteria
Andare does
Leads challenge every grade in a calibration call; disagreements resolve by evidence or the grade carries a dissent note.
Ordinara does
Grades all 16 criteria, ranks remediations by risk retired per engineering week, writes the report, delivers the 60 to 90 minute executive readout.
AI component
Drafts the gap grid from the signed artifacts and the roadmap cost model; every number traced to an exercise output.
Signed artifact
The graded gap grid, the ranked roadmap, and the findings report your sponsor forwards upward. Sample below, in full.
Reference criterion
Closes the assessment: sixteen grades, six actions, one decision list.
VI · The cadence, in full

Three weeks, shown as they run

Week 1 is shown session by session; weeks 2 and 3 as run sheets. All remote: Andare's hands on Andare's hardware, everything on Andare's accounts, Ordinara on the call and in the evidence folders with read-only access.

W1 · D1

Kickoff, access, and the rules

  • 90-minute session: scope fixed to ICP-1 with DC-2 as the reference baseline; the four entry findings accepted as the starting backlog; acceptance criteria for E1 and E2 signed.
  • Access: read-only repository and document access on Andare accounts. Nothing leaves the building; extraction runs on Andare's own tenancy.
  • Rule stated and minuted: every grade will cite a config, a log, or a test ID. Claims without one grade at 2 or below, whoever asserts them.
W1 · D2–3

Extraction runs, honestly graded

  • E1 run #1: domain map extracted from device tree, manifests, and diagrams; Ordinara's review flags 9 elements with ambiguous criticality assignments before engineers spend time on them.
  • E2 run #1: 71 candidate channels extracted; review collapses duplicates to 63 and flags 12 misclassified carriers. Schema corrected, run #2 queued overnight.
  • Written status to the sponsor at end of D3: counts, corrections, no surprises held for the readout.
W1 · D4

The map walk

  • Both leads walk the domain map on one call, the first time the cluster and IVI teams review the same architecture picture together. Two elements move domains during the call; the minutes record why.
  • Interview slots for E6 booked with all six participants.
W1 · D5

The register is signed, not discussed

  • Boundary register signed by both leads: 63 channels, 22 with named owners, 41 without. The ownership gap goes in the grid as found, not smoothed.
  • W2 bench windows confirmed; trace protocol for E3 delivered in writing.
W2

Safe-rendering and telltale path

  • D1–2 · E3: twelve telltales traced and timed on the bench; the IVI restart test surfaces the 9.4 s chime outage live on the call.
  • D2–3 · E4: safe_render.cfg pulled; region B absent; the claim log now reads evidence or NO EVIDENCE, line by line. Boot timing measured: 3.8 s.
  • D4 · E5: degradation battery run; the DC-2 duty diff lists three supervision duties with no ICP-1 assignee.
  • D5 · E6 begins: first three interviews. Evidence folder audit in parallel.
W3

Gap grid, roadmap, readout

  • D1 · E6 completes: remaining interviews; scorecard drafted.
  • D2 · calibration call: leads challenge the draft grades; two grades move on presented evidence, one carries a dissent note. The grid is theirs by the end of the call, which is the point.
  • D3 · roadmap costing: six actions ranked by risk retired per engineering week; the hardware-window decision flagged with its closing date.
  • D4 · executive readout: 75 minutes, sponsor plus Global Engineering Director. The report below is on screen; the decision list is the last slide.
  • D5 · delivery: report, grid, and all signed artifacts filed in Andare's evidence folder. Balance invoiced on delivery.
VII · The findings report

The artifact your sponsor forwards upward

Two pieces leave the assessment: the graded gap grid (working document, excerpt below) and the findings report (forwardable, in full below). Both cite the same evidence.

The gap grid, excerpt

CriterionGradeEvidence foundGapAction
D1.1 certified base3QNX OS for Safety license and certification records on file (ISO 26262 ASIL D capable base)ICP-1 FMEDA not startedfollows R-03
D1.2 independent supervision2On-SoC island Q/A verified · TC-0781No path independent of the SoC if the hypervisor faults (XB-052)R-03
D1.3 availability budget1Bench log: telltales valid at 3.8 sRequirement is 2.0 s; no budget ownerR-04
D2.1 partitioning2Hypervisor pre-certified ASIL D (vendor records)GPU time partition declared, no test evidence (XB-011)R-06
D2.2 restart independence1IVI restart test: cluster frames held; chime lost 9.4 sRegulatory chime depends on the QM guest (XB-023)R-02
D2.3 channel inventory3Signed register, 63 channels · raised from 1 during the assessment41 channels without a named ownerR-06
D3.1 telltale classification3Trace table, 12 telltales · raised from 1 during the assessmentClassification done; three classes FAIL until R-01 landsR-01
D3.2 rendering supervision1safe_render.cfg: region A onlyBrake, airbag, ABS telltales unsupervised (G-01)R-01
D3.3 deterministic graphics3Vulkan SC layer, offline pipeline cache and static object pools in the build logNone · a genuine strength to keep·
D4.1 unified HARA/TARA2DC-2 HARA (frozen 2024) + ICP-1 draft HARA; TARA separateNo co-engineering across teams or standardsR-05

10 of 16 criteria shown · full grid delivered with the report · grades challenged live in the W3 calibration call

The report, in full

ORDINARA
ToVP, Cockpit Electronics · Andare Cockpit Systems FromAgustín Carrillo · Ordinara LLC DateSeptember 18, 2026 ReCockpit electronics readiness assessment, ICP-1 · findings and roadmap · written to be forwarded as-is

Verdict

ICP-1 grades 2.1 of 4, "Declared, not evidenced," against the four-domain cockpit reference. The architecture choices are sound: certified OS, pre-certified hypervisor, Vulkan SC on the safety layer. The gap is that the supervision duties your discrete cluster performed in hardware were deleted with the hardware, and the claims that replaced them do not cite evidence. Nothing found requires re-architecting. Three findings require action before your Q1 2027 OEM audit.

DomainGrade / 4One line
D1 · Cluster safety domain2.0Certified base, but supervision ends at the SoC edge and boot misses the telltale budget by 1.8 s
D2 · Infotainment domain2.0Partitioning declared, not evidenced; the regulatory chime depends on the QM guest
D3 · Display and telltale integrity2.3Deterministic graphics are a strength; three regulatory telltales render unsupervised
D4 · Organizational readiness2.0Two safety cultures, two HARAs, 41 unowned boundary channels

Findings that drive the roadmap

  • G-01 · High. Brake, airbag, and ABS telltales (TT-03, TT-06, TT-09) render in framebuffer region B, which is not registered with the CRC monitor. safe_render.cfg, pulled W2, shows region A only. Anything the driver must legally see currently depends on unsupervised rendering.
  • G-02 · High. The seatbelt chime routes through the Android guest's audio HAL. In the W2 restart test the chime was silent for 9.4 seconds while the cluster kept drawing. A QM restart must never silence a regulatory function.
  • G-03 · High, hardware-window sensitive. DC-2's external safety MCU carried the independent watchdog, the hard-reset escalation, and the hardwired telltale fallback. ICP-1 deleted the part; no mechanism independent of the SoC assumed the duties (XB-052). The C-sample window is the last cheap chance to decide this in hardware.
  • G-04 · Medium. First telltale at 3.8 s cold against the 2.0 s OEM requirement; no owner for the boot budget. DC-2 on the same bench: under 2 s.
  • G-05 · Medium. 41 of 63 cross-domain channels have no named owner; GPU time partitioning and the OTA write path into the cluster partition are declared but unverified (XB-011, XB-038).

Roadmap, ranked by risk retired per engineering week

  1. R-01 · 30 days · software only. Register region B with the CRC monitor, add the fault-reaction test to the regression set. Closes G-01; D3.2 moves from 1 to 3.
  2. R-02 · 90 days. Move the chime to a QNX-owned audio path, or restore a direct piezo. Closes G-02; D2.2 to 3.
  3. R-03 · decision by Nov 15, 2026, C-sample lock. Independent supervision: an SBC-class external watchdog with display safe-state authority, or a hardwired telltale fallback strip, both proven on DC-2. This is a hardware decision only you can make; the report gives you the evidence, both options costed.
  4. R-04 · 90 days. Name a boot-budget owner; late-attach the Android guest behind a static splash the way DC-2 late-attaches its HMI; verify 2.0 s on the bench.
  5. R-05 · 90 days. One HARA/TARA practice across both teams, co-engineered per ISO 26262 and ISO/SAE 21434, starting from the boundary register.
  6. R-06 · 90 days. Owners for the remaining 41 channels; change governance that re-verifies a boundary when a merge touches it, on evidence, not negotiation.

Cost accounting

  • Assessment fee: US$6,500 fixed, 50% at signature, 50% on delivery. Evidence session fee already credited. AI inference and tooling, all on Andare accounts: US$58.
  • Andare engineer time consumed: 64 hours across both teams, against an internal estimate of roughly 240 hours to produce the same register, trace, and evidence review manually. All scenario figures, stated to be challenged.
  • Downside anchored: consumer-side replacement of one digital cluster runs US$1,062 to 1,116 in hardware plus US$75 to 150 reprogramming (published aftermarket data). A display-integrity field campaign across a 150,000-unit fleet is a nine-figure exposure before labor. Scenario arithmetic on sourced unit costs.

Decisions needed from you

  1. The R-03 hardware decision before the C-sample lock on Nov 15, 2026. Everything else is software and process.
  2. Owners for the 41 unowned channels: a name per channel, not a committee.
  3. How R-01 through R-06 get run: your team with a re-grade in Q1 before the OEM audit, or a fractional advisory cadence (from US$3,000 monthly, four hours a week) that keeps the weekly rhythm and writes you this same evidence trail every month. Either answer is fine; the grid is yours regardless.

What is already better than reference

The Vulkan SC safety layer with offline-compiled pipelines and static object pools (D3.3, grade 3) is ahead of most programs we grade, and the odometer isolation carried over from DC-2 is exactly right. Keep both; the roadmap builds around them.

Agustín Carrillo
Ordinara LLC · ordinara.ai · replies within one business day

This report and the full gap grid are the deliverable. The grid re-runs cheaply: same reference, same criteria, next quarter's evidence. A re-grade before the OEM audit turns "we fixed it" into a second graded document.

VIII · What the customer gets

The same three weeks, read from three seats

VP · the sponsor
The boundary becomes a list, not a debate
  • 63 channels, named and classified, replace "somewhere between 20 and 70."
  • The hardware decision (R-03) arrives pre-framed with evidence and a closing date, while the window is still open.
  • You walk into the Q1 OEM audit holding a graded grid and signed artifacts, not assertions.
  • Both of your teams signed the same documents. That has not happened before.
CEO
A fixed fee against a nine-figure tail
  • US$6,500 fixed, three weeks, 50/50 payment. No discovery phase that becomes a retainer.
  • The output is a decision list with dates, not a study. One decision is hardware; the rest is software and process.
  • Published aftermarket data prices a single cluster replacement above US$1,000; the assessment prices the fleet-level tail before the field does.
  • Live cost accounting in the report: fee, US$58 of inference, 64 engineer-hours. Challenge any line.
Global Director
A grade that transfers across programs
  • The reference is public and the scale is fixed: grade ICP-1 today, the next cockpit program with the same yardstick tomorrow.
  • Re-grades are cheap by design; maturity becomes a trend line, not an anecdote.
  • Fully remote by construction: client hands on client hardware, evidence over presence. Works identically across sites and regions.
  • The method is disclosed: AI extracts and cross-references, engineers sign, the grade cites evidence. Nothing depends on one hero.

Scenario economics, stated as assumptions

Figures below are the Andare scenario's working assumptions, shown so the math can be challenged line by line. Your numbers replace them in the scoping call.

ItemManual baselineWith the assessmentBasis
Boundary inventory, 63 channels≈ 126 engineer-hours (63 × 2 h)14 engineer-hours of review + sign-offTeam estimate vs. scenario W1 actual
Telltale trace + evidence review≈ 96 engineer-hours (12 × 1 bench-day)≈ 22 engineer-hours incl. bench runsTest lead estimate vs. scenario W2 actual
Assessment all-inUS$6,500 fixed + US$58 inference on Andare accounts + 64 engineer-hours totalOffer terms; scenario accounting
Downside anchoredOne digital cluster replacement: US$1,062 to 1,116 hardware + US$75 to 150 reprogramming, per unit. A 150,000-unit display-integrity campaign ≈ US$159 to 167M in hardware alone, before labor and reputationRepairPal / Unionfab published costs; fleet size is a scenario assumption
Without the assessment
The boundary stays a belief

The channel count stays an estimate, the telltale supervision stays an assertion, and the C-sample window closes with the supervision question unexamined. The OEM audit, or the field, asks it later at a very different price.

With the assessment
Sixteen grades, six actions, one hardware decision

Three weeks in, the boundary is a signed register, every telltale has a classification and a timing, every claim reads evidence or NO EVIDENCE, and the one decision that must beat the hardware window is on your desk with both options costed.

IX · Terms and the ladder

Fixed fee, fixed scope, graded output

From US$6,500 for the assess phase shown on this page; the full sprint, adding a game-day rehearsal and coached fixes, runs US$12 to 18k. Two to three weeks: week 1 architecture and domain review, week 2 safe-rendering and telltale path, weeks 2 to 3 gap grid and roadmap. 50% at signature, 50% on delivery. Read-only access, everything on your accounts, fully remote. The Executive AI evidence session (US$1,500 to 3,000, prepaid, 100% creditable against any engagement) is the natural entry: bring one nagging cockpit workflow, leave with a live demonstration on your own artifacts and the findings that scope this assessment. The Fractional AI Advisor (from US$3,000 monthly) is the natural continuation when you want the roadmap run on a weekly cadence with the same evidence discipline.

The method, inspectable

Book a 30-minute scoping call

ordinara.ai · +1 (949) 749-6241 · replies within one business day

Book a call