From Link Counts to Evidence Architecture
Aerospace Safety-Critical Program • DO-178C Level A • 12-month engagement
The Challenge
An aerospace program had achieved "100% traceability coverage" according to their requirements tool—but auditors identified hundreds of gaps, and engineering reviews still required extensive manual preparation. The team had links, but not confidence.
15,000+ requirements with 'complete' trace coverage—but auditors flagged 340+ gaps
Trace links existed but didn't answer 'why' questions in design reviews
27% of requirements had orphaned traces discovered 4 months before certification
Audit preparation consumed 160+ engineering hours per milestone
Low confidence despite high link counts—teams questioned trace validity
The Approach
Trace Intent & Audit Expectation Analysis
Interviewed certification authority and internal review leads to define what traceability must actually demonstrate. Clarified the difference between link existence and evidence sufficiency.
Coverage Architecture Redesign
Redefined trace relationships based on verification risk, not link count. Established sufficiency criteria for each requirement class and safety level.
Evidence Mapping Strategy
Mapped audit questions to required evidence types. Defined acceptable verification artifacts and rationale documentation patterns.
Review-Gate Trace Views
Architected trace views aligned to CDR, TRR, and certification milestones—showing intent, not just links.
The Results
Key Insight
"We thought we had a tooling problem. Turned out we had an architecture problem. Once we clarified what traceability was supposed to prove—and redesigned it around evidence, not links—the tools became effective."— Chief Systems Engineer, Aerospace Safety-Critical Systems
Struggling with traceability confidence?
Let's review your trace architecture and define what evidence must exist.