Engineering Safety Requirements for Maritime Autonomous Surface Systems: Hazard Scenarios, Control Loss, and Recovery in Degraded Operations
Discuss this preprint
Start a discussion What are Sciety discussions?Listed in
This article is not in any list yet, why not save it to one of your lists.Abstract
Maritime autonomous surface systems redistribute sensing, decision-making, supervision and recovery functions across onboard automation, remote operators, control centres and external maritime actors. This configuration creates safety-critical pathways in which degraded communication, ambiguous control authority, perception limits, collision-avoidance uncertainty or delayed human intervention may lead to loss of control. This article develops a scenario-based system safety engineering approach for translating publicly documented hazard scenarios into control constraints and recovery requirements. The study is based on a coded corpus of 80 publicly available scenarios and requirements drawn from regulatory guidance, classification requirements, operator-disclosed trials, technical reports, observed casualty reports and public investigation notices. Each entry was coded by operational context, autonomy configuration, supervision mode, potential loss event, degraded barrier, recovery pathway and derived safety requirement. The analysis identifies recurrent hazard families related to remote supervision, communication and control links, operating-envelope verification, minimum-risk recovery, navigation interaction and data integrity. It also shows that safe operation depends less on autonomy level alone than on the explicit specification of degraded modes, takeover authority, fallback behaviour, monitoring indicators and emergency coordination interfaces. The article contributes a hazard scenario taxonomy, a control-loss pathway model and a set of recovery-oriented safety requirements for the design, operation and assessment of autonomous surface operations.