Home → Guides → Automated Vehicle Trial Incident Response: UK Guide

Incident and emergency response during an automated-vehicle trial

Plan the response before an incident starts

An automated trial vehicle stops unexpectedly at a junction. The safety driver takes control, but another road user swerves and is injured. A second vehicle from the same trial is already on its route. The engineering team wants data immediately; the insurer wants notification; the police may need the scene preserved. The trial organisation needs a sequence that protects people, makes the road safe and preserves evidence without asking the driver to solve every technical and legal question alone.

The Department for Transport's automated-vehicle trialling code, updated in June 2026, recommends contingency arrangements with relevant authorities. It discusses public communications, pausing or terminating a trial, named contacts, rehearsal, technical advice for emergency services and access to incident data. It says trial vehicles should record enough to establish who or what controlled the vehicle and that data should be preserved after an incident. Those expectations sit alongside ordinary road law and any service-specific duties. The code does not supply a universal reporting deadline for every supervised trial event.

This guide owns the response decision from event to controlled restart. The safety-driver page owns personal intervention competence. The trial operating-domain page owns the limits that can trigger a stop. A later intervention-records page can examine technical reconstruction and data governance. The no-safety-driver pilot guide follows a separate applicant path, and its named order or permit may impose different requirements. Do not paste a pilot deadline into a supervised trial plan without identifying the applicable source.

Decide what counts as an event that activates the plan

The plan should cover more than a collision. Include injury, a near miss, an unplanned takeover, a vehicle stopping in a dangerous position, a loss of control or communication, a passenger emergency, a cyber or data event affecting operation, and damage to infrastructure. Different events need different responses, but the team should know which ones require immediate safe-state action, emergency services, a trial hold and specialist review. A driver should not have to search a long policy for the right category while traffic is moving around the vehicle.

Define the first observable signal and who receives it. The driver may see a pedestrian fall, an automated-system warning or unexpected braking. A remote observer may see a fault alert. A member of the public may call the trial contact number. The organisation should provide one way to escalate an uncertain event without asking the reporter to decide if a legal threshold is met. Initial triage can be conservative. Reportability can be assessed after people are safe and reliable facts are gathered.

Avoid designing the plan around a flawless network connection. A serious event may also interrupt power, telemetry or voice contact. The safety driver must know the immediate action within their lawful role. Operations staff should have a fallback for reaching the driver and emergency services, and a way to establish the last known location and vehicle identifier. Test that fallback in a drill. A dashboard that normally updates every second is not a contingency plan if nobody knows what to do when it stops updating.

First priorities at the scene

The driver and trained responders should follow current emergency and road rules for the actual event. The immediate priority is people, then the safety of the road and vehicle. A public article cannot instruct a driver to move an injured person, approach a damaged high-voltage system or alter a police scene in every circumstance. The trial organisation should develop vehicle-specific instructions with competent emergency specialists and agree them with relevant responders before deployment. Those instructions should be short enough to use under stress.

The plan should identify how automated operation is ended or restrained, how the vehicle can be identified and whether it may restart unexpectedly. It should name a safe method for sharing vehicle isolation and recovery information with emergency services. Do not assume a conventional ignition procedure is sufficient for a prototype. The code encourages discussing technical advice and unusual vehicle features with emergency services in advance. A trial vehicle with external sensors, battery systems or unconventional controls may require particular information. Only qualified people should determine the technical method.

Protect other road users as well as vehicle occupants. An immobilised vehicle can block a crossing, cycle lane or emergency route. Operations staff should know who can arrange recovery, how to inform the highway authority or police and whether moving the vehicle would compromise evidence or create a new hazard. These decisions depend on the scene. The plan should designate the person who coordinates with responders instead of issuing competing instructions from engineering, dispatch and management.

Passengers and vulnerable road users

If the trial carries passengers, the incident plan must explain how they obtain help, leave the vehicle safely when instructed and receive information they can understand. A safety driver may be occupied with the road or emergency call. An accessible service may need a specific method to assist someone with limited mobility or a sensory impairment. The vehicle safety case does not automatically cover every passenger-support scenario. The service operator and trial organiser should agree responsibilities and test them with appropriate specialists.

A collision may also involve people outside the vehicle who cannot see or hear an ordinary warning. The trial organisation should consider pedestrians, cyclists, children and people with disabilities during its route and response planning. A public contact number and clear vehicle identity help someone report a near miss even where the team did not detect it. The code encourages engagement with vulnerable road users and a public communication plan. Those are useful preventive controls as well as post-event channels.

Establish one incident commander and a contact chain

Name a person or role with authority to coordinate the trial response. This person need not replace emergency-service command at the scene. Their job is to make internal decisions: stop other runs, reach the engineering and safety teams, notify the insurer or legal adviser when required, preserve records and keep one account of what is known. A deputy should be available when the primary contact cannot be reached. The driver should have a direct route to that person and a clear right to stop the trial without waiting for permission.

Build a contact sheet tied to the actual route and vehicle. It may include police, ambulance and fire services through normal emergency channels, a non-emergency authority contact, highway or local authority, vehicle technical specialist, recovery provider, insurer, data controller and public communications lead. Check which contact is appropriate for each event. Do not publish personal mobile numbers or sensitive recovery procedures in a public-facing safety summary. Keep the operational contact sheet current and accessible to those who need it.

The code encourages advance engagement and a single public point of contact. Tell relevant authorities what the trial vehicle looks like, where it operates, how to reach the organisation and how technical advice can be obtained after an incident. A response plan that identifies an agency but has never been discussed with it may fail when someone calls. Record the engagement, questions raised and any change in the trial design. If the route or vehicle changes materially, review the contact and responder information.

Preserve facts without obstructing urgent action

After immediate safety needs are addressed, the organisation needs to preserve evidence. The code says trial data should be secure and that after an incident it should be preserved in full. It expects data capable of determining who or what controlled the vehicle. The record should include the vehicle and software version, location, time, automated or manual mode, alerts, driver action, relevant sensor and control data, communications state and any available video or audio. The exact capture design and legal access need engineering, privacy and investigative review.

Separate original data from working copies. Record where the primary file came from, who accessed it, whether the device was still recording and how integrity was checked. An engineer may need a copy to diagnose a fault, while investigators may need the original preserved. If a vehicle is repaired or software reinstalled before the evidence is secured, the organisation may lose the ability to reconstruct the event. The response plan should identify who can release the vehicle for work and what evidence must be captured first, subject to police or other lawful instructions.

Statements also need care. Ask the driver and witnesses for a factual account while memory is fresh, but do not press them to explain root cause before technical evidence is reviewed. Capture what they saw, heard, did and when. The incident commander should distinguish confirmed facts, provisional observations and hypotheses. A public statement that the vehicle “had no fault” minutes after a collision may later prove wrong and undermine trust. A holding statement can confirm that the event is being handled and that an investigation is underway without prejudging it.

Work out reporting from the applicable source

There may be ordinary road-traffic reporting obligations, insurer notification terms, service licensing requirements and conditions in a specific vehicle order or permit. The correct time limit depends on the event and applicable instrument. The DfT trialling code says reportable incidents are expected to be communicated to the police and relevant investigators may require access to vehicle data. It does not make every event subject to a single 24-hour AV reporting rule. A legal or compliance owner should maintain a source-linked reporting matrix for the actual project.

The no-safety-driver pilot applicant guidance describes incident arrangements and particular timing expectations for pilot applicants. An issued Vehicle Special Order or APS permit may set the binding scope. That pilot wording should not be copied into this supervised-trial page as though it applied to every safety-driver run. If the trial shifts to a no-driver operation, reassess the entire permission and reporting route before deployment.

A useful matrix states the event type, possible receiving authority, source of the duty, trigger, deadline, person responsible and evidence of submission. It should also state when specialist judgment is required. For example, whether a near miss meets a legal or permit-reporting threshold may not be apparent from the first radio call. The team should preserve the facts and escalate promptly rather than mark the case “not reportable” because no one was injured. Record the reason for the final decision.

Put the rest of the trial on hold when the case changes

An event on one vehicle can affect another that uses the same software, sensor or route. The incident commander should identify potentially affected vehicles and impose an appropriate hold before the second run enters the same hazard. This is an internal safety decision, not an assertion that every minor fault requires a fleet-wide statutory suspension. The response plan should specify who can impose the hold and what information must be shared with drivers and operations staff immediately.

The hold should have a clear scope. It might cover one vehicle, one route segment, one operating condition or all use of a particular software release. An unclear instruction such as “be careful near the junction” does not tell the driver whether automated mode is prohibited. Document the reason and time. If an authority later imposes a restriction, that instruction also needs to be recorded and implemented. The organisation must not rely on an old green status in a dashboard when a live event has changed the risk picture.

Restart is a fresh decision. Identify what happened, what evidence was preserved, which safety-case claims are affected, what corrective action was taken and how that action was tested. Check whether the driver needs retraining, the route or operating domain must be narrowed, insurance or authority notification is needed, and public information must change. An investigation that has not found a root cause can still justify a limited, evidence-backed response, but the uncertainty must be explicit. Only a named competent owner should approve resumption within a defined boundary.

Rehearse three incidents that expose weak plans

A stopped vehicle at a pedestrian crossing. The driver can take control, but the vehicle blocks a crossing and the cause is unknown. Test how the driver protects people, how the organisation pauses other runs, who contacts road authorities, how data is preserved and who decides whether the vehicle can move. A recovery team should not arrive with no information about the prototype's controls or electrical hazards.

An unexpected intervention near a cyclist. No contact occurs, but the driver brakes sharply and the cyclist falls. Treat this as an event requiring factual capture and specialist triage. Review the mode, vehicle response, driver action and applicable road or insurance duties. The absence of a collision with the vehicle does not by itself prove that no reporting or corrective action is needed.

A communication failure during passenger carriage. The safety driver remains in the vehicle, but remote support cannot be reached and a passenger needs assistance. Test who helps the passenger, whether the automated function should continue and how emergency services are contacted if necessary. The team should not assume that the remote centre is the only emergency channel or that a driver can simultaneously supervise the road and resolve every passenger need.

These examples are rehearsal prompts, not universal emergency instructions. The qualified emergency and vehicle teams must define the actual actions for the trial vehicle and location.

Review data, people and public communication together

Technical investigation can identify a software fault, but a complete review also asks whether the driver understood the warning, whether the route plan missed a hazard, whether authorities had the right information and whether the stop decision worked. Include the maintenance supplier, operator and passenger-service provider where their work affected the event. Preserve disagreements and open questions instead of forcing an early single-cause story. The trial's safety case and operating domain should be updated when findings change their assumptions.

Event data may contain identifiable road users and passengers. Limit access to those with a need, follow applicable data-protection law and record disclosures to investigators. A public report can communicate what happened and what changed without releasing raw personal or security-sensitive data. The code supports public communication and recommends cooperation with investigators. Legal and privacy specialists should approve the details. Transparency does not require publishing every camera frame.

Feedback to the driver and trial team matters. If a driver made the correct intervention, preserve that learning. If the procedure was confusing, change the procedure and rehearse it. If the vehicle responded unexpectedly, update the engineering evidence and domain. A lessons-learned meeting should end with an owner, action, verification method and decision about whether the trial's published description needs revision. Otherwise, the incident file becomes an archive rather than a control.

A practical response register

StageDecision ownerEvidence to preserveRelease question
Immediate safetyDriver and emergency responders within their rolesLocation, people, vehicle state and first actionsIs the scene safe?
Trial holdTrial incident commanderAffected vehicles, route and software versionsWhich runs must stop?
NotificationLegal, insurance and permit ownersSource, trigger, deadline and submissionWho must be told?
InvestigationAV safety and engineering leadsOriginal data, witness accounts and configurationWhat is known and uncertain?
Corrective actionControl ownerRepair, test, training or route changeDoes the safety argument still hold?
RestartNamed accountable trial ownerReviewed case, conditions and approvalMay the defined activity resume?

This is an internal planning aid, not an official incident form. It cannot determine legal reportability or replace instructions from emergency services. Its value lies in making the handoffs and evidence visible before a stressful event.

Where Complys may fit

Complys could be assessed for incident logs, action ownership, document versions and evidence retrieval if its current product demonstrates those functions. The public AV workspace preview is noindex and does not prove a released AV incident module. There is no verified claim here that Complys receives vehicle telemetry, contacts emergency services, decides legal reportability or submits regulator reports. The product owner must confirm any specific feature statement before publication.

In a product demonstration, give the team one stopped-vehicle scenario. Ask how it records the first alert, links the affected vehicle and permission, assigns a hold, preserves source files, records notification decisions and retains the earlier safety-case version. Ask how sensitive personal data is restricted and exported. If primary vehicle data remains in a specialist system, make the relationship clear. The AV software overview offers the broader buying test; the AV checker is a nonbinding regime pointer and is not an emergency response tool.

The practical next step is to rehearse the actual vehicle's response plan with the safety driver, operations team and appropriate responders before a public run. Confirm the contact chain, data preservation method, reporting matrix and hold authority. The first real incident should not be the first time these people discover their roles.

Complys keeps the records, actions and evidence behind automated-vehicle trials and pilots in one place.

Autonomous vehicle compliance software →

Primary sources

  1. DfT automated-vehicle trialling code, updated June 2026: contingency, engagement, reporting, data and driver expectations for supervised trials.
  2. DfT no-safety-driver pilot applicant guidance: separate pilot event and permission context.
  3. DfT first-responder guidance for pilots: useful comparison, not a substitute for a supervised trial's own responder plan.