Risk assessment for a supervised automated vehicle road trial
Start with one real route and one real decision
A trial team plans to move an automated shuttle from a closed track to a short public route. The vehicle has completed thousands of test runs. Its mapping file covers the street. A safety driver has been trained. Yet the route passes a school entrance, a temporary loading bay and a junction where cyclists frequently filter beside stationary traffic. The team's decision is not whether the technology is promising. It is whether this version of the vehicle can be trialled on that route, at those times, with controls that address the people and events it will actually encounter.
The Department for Transport's automated vehicle trialling code, updated in June 2026, says trial organisations should undertake a full risk assessment to determine whether proposed trial arrangements are appropriate. It also expects a detailed, proportionate safety case and continuing assessment of trial safety. The code is guidance. Its discussion of risk assessment does not turn a particular spreadsheet format or scoring matrix into a statutory approval route. Legal duties concerning the driver, roadworthiness, insurance and any passenger service remain separate.
This guide explains the hazard-assessment work behind a supervised public-road trial. The AV regulations guide gives broader regulatory orientation, while a proposed trial safety-case guide will own the overall claim-to-evidence argument after route integration. A risk assessment feeds that argument. It does not replace it. A register can identify hazards and owners, but a safety case also needs to show why the collection of controls and evidence supports a defensible decision to operate.
The method here is an editorial working model for a competent trial team. It is not a government certificate, a safety standard or a guarantee of acceptable risk. A qualified AV safety engineer and relevant legal advisers need to test the proposed controls against the actual system, road environment and operating permissions before launch.
Define the activity before listing hazards
Write a short trial definition that a road authority and a new safety driver could recognise. Name the vehicle configuration, automation version, route, direction of travel, stops, expected speed range, hours, weather limits, safety-driver position and passenger or freight activity. Identify the organisation operating the trial and the person who can pause it. Describe how a vehicle enters and leaves the automated mode and what happens when the system approaches a boundary.
A risk assessment loses value when its scope says only urban driving. Two streets in the same town may create different exposure. One may have a protected cycle lane. Another may have informal pedestrian crossings and a narrow section where a bus cannot pass. Separate route segments if the controls or exposed people differ. Record a map and a written description, since a line on a map rarely captures temporary parking, school hours or seasonal traffic.
Specify the decision the assessment will support. The team may be deciding whether to begin with a safety driver and no passengers, whether to add passengers later, whether to extend operating hours or whether to restart after a software change. A single assessment can contain several phases, but each phase needs its own evidence and approval. A decision to operate with a safety driver does not authorise removal of that driver. The current no-driver pilot route has different permissions and evidence requirements under the DfT pilot applicant guidance.
Document assumptions before they become invisible. The team might assume road markings will remain visible, a remote monitoring link will be available, or a loading zone will not obstruct the vehicle. State who can verify each assumption, when it will be checked and what happens if it fails. An assumption with no owner is a gap in the operating decision.
Find hazards from the route, system and work activity
Start with people who might be harmed. They include the safety driver, trial staff, passengers, pedestrians, cyclists, motorcyclists, other drivers and people who cannot easily move away from a stopped vehicle. Do not treat vulnerable road users as a single abstract group. A wheelchair user crossing at a dropped kerb, a child stepping out between cars and a person with limited sight may interact with the vehicle differently. The assessment should ask where each interaction can occur and what evidence the automated system and its human fallback have for it.
Walk or observe the route at the proposed times. Ask the highway authority about planned works and traffic restrictions. Speak with people who use the area where appropriate. The trialling code encourages engagement with authorities and affected road users. A computer-generated scenario catalogue is useful, but local observations can expose patterns that the catalogue misses. Record the date of observations so a later reviewer can tell whether road conditions have changed.
Look for hazards in the vehicle as well as the street. Examples include an occluded sensor, confusing mode indication, delayed takeover request, a control layout that slows intervention, unexpected braking, a map mismatch and a fallback stop that blocks another road user. Maintenance and charging can create their own risks. A vehicle may be technically able to stop safely on a test track while its usual stopping place on the public route is a blind corner. Name the resulting harm and the sequence that could produce it, rather than writing a vague row called system failure.
Include normal, abnormal and transitional activity. A pedestrian crossing in clear weather is routine. Roadworks, emergency vehicles, poor lighting and a police direction are less routine. Switching from automated to human control is a transition that can fail even if each mode works alone. A loading or recovery operation may expose staff to traffic. The assessment should cover preparation, driving, intervention, pause, retrieval and return to service.
The HSE risk-management steps provide a useful general sequence: identify hazards, assess risk, control it, record findings and review controls. HSE workplace guidance does not by itself define the automated-driving safety threshold. Use it to organise work, while the AV trialling code and actual road-traffic duties supply the trial context. If the organisation has workplace risk-assessment duties, its competent health and safety lead should connect this trial assessment to those arrangements.
Describe a credible event, not a label
For each material hazard, write a scenario that can be challenged. A useful row might say: At the eastbound school crossing between 8:15 and 8:45, a child emerges from behind a parked delivery van; the perception system identifies the child late; the vehicle continues at its planned speed; the safety driver has less time than the team assumed to intervene. This identifies the location, trigger, affected person, system behaviour and possible failure of the fallback.
Then ask what the scenario omits. Is the van parked legally? Does the crossing have a refuge? Is the vehicle speed controlled by software or a supervisor? What happens in low sun? Could a driver who is monitoring both the road and the vehicle display recognise the problem in time? The answers determine which test evidence is relevant. A generic pedestrian-detection score may not address occlusion on that street.
Link each scenario to an existing test or a new test plan. Evidence might come from simulation, closed-track exercises, controlled observations, human-factors trials or prior public-road data. Each source has limits. Simulation can exercise rare situations but may not model a real pedestrian's behaviour. A test-track result may show braking performance without proving reliable detection in clutter. Public-road mileage can reveal exposure but does not prove a rare critical scenario has been encountered. State what each result demonstrates and what it cannot establish.
Use a method for prioritising risk that the team can explain. Severity and likelihood can help triage, but a numerical score should not conceal uncertainty or normalize a catastrophic scenario with weak evidence. Record both the estimated consequence and confidence in the estimate. If evidence is poor, the correct action may be to narrow the route or obtain further test results before attempting to calculate a precise residual score. The trialling code asks organisations to minimise risk and maintain a safety case; it does not prescribe a universal five-by-five matrix for AV trials.
Choose controls that work together
Begin by asking whether the hazardous exposure can be removed or reduced. The team may exclude the school crossing at peak time, choose another route, reduce operating speed, limit operation to daylight or defer passenger carriage. Those decisions can be stronger than placing every risk on the safety driver's shoulders. When a hazard cannot be eliminated, combine system controls, operating limits, driver procedures and a safe fallback. Identify which control prevents the event, which detects it and which limits harm after it begins.
For every control, specify the owner and proof. A reduced speed limit needs a configuration value, verification result and method of checking that the live vehicle still has it. A route restriction needs a way to stop dispatch into an excluded street. A driver briefing needs an assessed understanding of the relevant scenario, not merely a signed attendance sheet. A remote communications procedure needs an actual test under the expected network conditions. Controls are not effective just because they appear in the assessment.
Avoid a single-point intervention story. The June 2026 code expects a safety driver ready, able and willing to resume control while monitoring the road environment and vehicle systems. Yet an automated vehicle may create hazards that give little warning. Ask whether the driver can perceive the event, understand the mode, reach the controls and act within the available time. Test realistic workload and sight lines. A statement that the driver can always take over is an assertion requiring evidence, not a substitute for vehicle design or route control.
Consider a minimal-risk response. If the automated system cannot proceed safely, where will it stop? Could that stop block an emergency vehicle, create a collision risk or strand passengers? Who decides whether the vehicle is moved and under what legal and technical conditions? The safest fallback depends on road layout. The code describes a minimal-risk condition and says it should ideally position the vehicle safely while reducing hazards to other road users. The team must show why its actual fallback is suitable for the route rather than borrowing a generic diagram.
Record residual risk as a decision with conditions. A reviewer should be able to see the scenario, evidence, controls, remaining uncertainty, named decision maker and hold point. Where the answer is no, say no. Where operation is limited to a particular phase, state the boundary. Keep rejected options in the record so a later team does not repeat a weak argument after staff change.
Make the safety driver assessment specific
The driver is a control with human limits. Assess licensing and suitability with legal advice where needed, but do not stop at credentials. The trialling code describes the driver as someone able to control speed and direction who can resume proper control when necessary. The trial must also make clear who is the driver at any moment. A roster, handover process and vehicle-mode indication should support that clarity.
Test recognition and response across the scenarios that matter most. Ask the driver to detect unexpected braking, a false obstacle, a missed pedestrian, degraded sensor visibility, an unavailable planned turn and an emergency-service instruction. Vary the amount of warning. Evaluate takeover time, correct action and recovery without endangering others. Training may need refresh after a software or route change. The trial should not rely on a single demonstration in ideal conditions as proof that intervention will work on every shift.
Fatigue, distraction and automation complacency can change performance. A driver who has watched the system behave correctly for hours may have more difficulty recognizing an unusual failure. Define duty lengths, breaks, observation responsibilities and the method for reporting a near miss or confusing mode transition. If a second person monitors data, define what that person does and whether the driver can reasonably use the information. Adding another person does not automatically create an effective control.
Separate a safety-driver trial from a no-driver pilot in all records. A remote adviser, control-room observer or passenger attendant is not automatically the safety driver contemplated by the supervised trial code. No-driver piloting uses a different route and specific permissions. The risk assessment should flag a proposed change in human role as a new regulatory and safety decision, not a minor staffing alteration.
Assess the road interface with people outside the project
The trial team cannot know every local hazard alone. Highway authorities may know about planned resurfacing, bus stop changes and temporary traffic orders. Police and emergency services may need to understand how to contact the operator and secure the vehicle after an incident. Disability groups and local users may point out crossings, kerbs or passenger needs overlooked by vehicle engineers. The code recommends engagement with relevant bodies and people affected by trials.
Document what was learned and what changed. A consultation log with no design consequence is weak evidence. If a local authority reports an upcoming road closure, update the route and assess the alternative. If a community group identifies a crowded crossing, test at the relevant time or exclude it. Where advice is rejected, record the technical reason and decision maker. Different organisations may disagree; the operator remains responsible for its trial decision.
Public information can also be a control. People should have a way to report unusual behaviour. Explain the trial's boundaries and the safety-driver role in plain language without implying that the vehicle has full authorisation under the later Automated Vehicles Act framework. A contact channel must lead to a process that can stop, investigate and revise the trial. The communication itself is not proof of safety.
Keep the assessment alive during operation
Set review triggers before launch. A collision, near miss, unexpected intervention, map change, roadworks notice, software update, sensor replacement, new vehicle or altered operating hours should prompt a review of affected scenarios. The team may need to pause the trial while it investigates. Not every software change has the same consequence, but none should pass solely because a development ticket says complete. The assessment must reference the version that will run on the road.
Define what data is captured after a noteworthy event. Vehicle mode, speed, position, system warnings, driver action, time, weather, nearby road users and software version may all matter. A privacy and retention assessment is needed for personal data. Preserve relevant evidence promptly and avoid changing it during analysis. The incident-response guide owns immediate scene action and reporting; this risk-assessment owner uses the findings to update hazards and controls.
Watch for leading signals as well as injury events. Repeated late interventions, unexpected route exits, driver confusion or increased fallback stops may show that a control is weaker than expected. Agree thresholds for escalation. They are local operating rules chosen for the trial, not statutory AV thresholds supplied by this article. A trend review should compare exposure and conditions, not simply count events without context.
An assessment is no longer current when its scope no longer matches the trial. A safe launch decision for daylight operation on one software version does not automatically support night running or a new vehicle. Mark superseded documents and require a named re-approval. The HSE workplace transport risk guidance also stresses review when vehicles, routes or work change. The AV code expects continued assessment of trial safety. The two sources support an active review process, while their precise legal roles remain distinct.
A practical record that a reviewer can use
The assessment record should be concise enough for operations yet detailed enough for challenge. Include one line per credible scenario with an annex or linked evidence where needed. Avoid copying a long generic hazard library into a route file without deciding which scenarios apply. A reader should be able to identify unresolved items in minutes.
| Field | Decision it should expose | Weak entry to avoid |
|---|---|---|
| Trial configuration | Vehicle, software and route version assessed | Latest vehicle |
| Scenario | Who could be harmed and how on this route | Pedestrian risk |
| Evidence | Which test or observation supports the assessment | Tested extensively |
| Existing control | What is installed, operating and checked | Driver will intervene |
| Residual uncertainty | What remains unknown and why | Low risk |
| Action and owner | Who must do what before launch | Team to review |
| Operating boundary | Conditions under which the decision holds | Normal conditions |
| Review trigger | Event or change that reopens the decision | Review annually |
Use evidence links that point to controlled files. A test result should identify software version, test setup and date. A road observation should identify when and where it was made. An action should have a closure record and independent check where the risk warrants it. The assessment then becomes a navigable decision record rather than a snapshot of confidence.
An internal review meeting should include people able to challenge the engineering and operating assumptions. Assign the final decision to a person with authority to hold the launch. Record dissent. If the team cannot demonstrate a control, it should narrow the trial, obtain evidence or defer the activity. A favorable average score is no reason to hide a severe scenario with uncertain protection.
How this differs from the safety case and later regimes
The hazard assessment asks what can go wrong on the defined route, who may be harmed and which controls are supported. The safety case makes the broader argument that the trial can be conducted without unreasonable risk, using this assessment alongside technical tests, driver evidence, legal permissions and management arrangements. The route-readiness decision checks whether all launch prerequisites are in place. Distinct owners prevent three near-identical articles from telling a team only to prepare a safety case.
Current supervised trials have a safety driver. The separate 2026 no-driver pilot scheme requires its own vehicle and operator evidence and may have issued Vehicle Special Order conditions. An automated passenger service can also require a permit. The full Automated Vehicles Act authorisation framework is being implemented in stages. Do not label an existing supervised-trial assessment as full Act authorisation evidence without comparing the regime, role and vehicle status. A team planning a progression should retain the old evidence but reassess its relevance rather than simply changing the cover page.
For the next decision, choose one proposed route and conduct a scenario workshop with the safety engineer, operating lead, driver lead and a road-environment representative. Walk the route, rank evidence gaps, implement controls and hold the launch until the assessment and safety case agree. Reopen the record when the route or system changes.
Where Complys could support the record
A trial organisation may need document versioning, action ownership, review reminders and an audit trail linking risk decisions to test evidence. Complys can be assessed for those administrative tasks in a product demonstration. This page does not claim that Complys detects AV hazards, calculates a legally accepted safety score, validates a sensor, confirms road permission or operates a live vehicle. The product owner must verify any exact capability before release.
In a demonstration, bring a sample route change and a severe unresolved scenario. Ask whether the system can show which assessment version is current, who owns the action, what evidence closed it and whether a changed software release reopens review. If test data and vehicle configuration are stored elsewhere, describe the handoff and source of truth. The AV compliance software overview covers procurement questions. The AV checker is only a nonbinding regime pointer and cannot decide that a risk assessment is sufficient.
The useful output is a specific operating decision. Record the route, system version, people exposed, credible scenarios, controls, evidence, residual uncertainty and stop rule. Ask competent reviewers to challenge it before public-road exposure. Keep the assessment connected to the live trial, not filed away after the first launch.
Complys keeps the records, actions and evidence behind automated-vehicle trials and pilots in one place.
Autonomous vehicle compliance software →Primary sources
- DfT automated vehicle trialling code of practice, updated 24 June 2026: supervised-trial requirements, full risk assessment recommendation, safety case, safety driver, operating controls and continuing review.
- HSE steps needed to manage risk: general hazard, risk, control, record and review sequence.
- HSE workplace transport risk assessment guidance: work-activity and route-change review principles. Its workplace focus is not a substitute for road-traffic legal advice.
- DfT self-driving pilot applicant guidance: distinct no-driver pilot regime for boundary comparison.