Editor’s comment: “In this guest column, Amandine Schneickert, government affairs expert and founder of US-based Pivot Point Strategies, addresses pressing questions concerning the United Nations’s proposed Global Technical Regulation on automated driving systems.”

A milestone that demands scrutiny
The adoption of the UN Global Technical Regulation (GTR) on Automated Driving Systems (ADS) is an important step towards a shared framework for innovative mobility. The provisions address both what an automated vehicle must do, and how manufacturers must demonstrate it is safe to deploy. Considerations of changes to regulation represent a critical step towards aligning the regulatory community and innovation.
One of these provisions warrants particular scrutiny: The Safety Management System (SMS) requirements. The SMS framework asks governments to evaluate not just whether a vehicle meets performance thresholds, but imposes processes on how manufacturers might be organised internally in ways conducive to safety. It scrutinises process alongside product. That is genuinely unprecedented in vehicle regulation as it has been practised for the past half-century.
Regulation without precedent
Traditional vehicle regulation is outcome-oriented. Crash test performance, emissions thresholds, braking distances – the question is always whether the vehicle, as a physical object, meets defined criteria. The GTR’s SMS provisions break from that model in three distinct ways:
First, safety culture is treated as a regulated attribute. Something that can be required, assessed, and sanctioned. The framework calls on manufacturers to demonstrate that safety considerations are embedded in organisational decision-making, not just engineering outputs.
The challenge is definitional, yet safety culture resists precise operationalisation. How does a regulator assess whether a manufacturer has genuinely embedded safety in its culture, rather than merely produced documentation suggesting it does?
Second, manufacturers must submit internal process documentation – not simply descriptions of what a vehicle does, but how the organisation works. This extends to decision hierarchies, testing methodologies, governance around safety-critical design choices.
Third, third-party auditors are to verify that documented processes exist and are followed. The logic may be sound, but both innovations raise questions. Is the regulatory ecosystem equipped to make them work? How are these auditors trained and certified? Are there enough resources?
ADS systems may, depending on jurisdiction, operate across an effectively unbounded operational design domain (ODD), yet no finite test programme can cover the combinatorial complexity of real-world driving.
When performance testing cannot cover the space, how a manufacturer identifies and mitigates safety risks in development becomes a legitimate regulatory concern. Both major comparators – aviation and ISO 26262 – support this logic, with important caveats.
The aviation Safety Management System framework has been associated with sustained improvements in safety, but its credibility rests on institutional foundations built over decades: trained auditors, established methodologies, clear sector-specific standards.
ISO 26262, the functional safety standard for road vehicles, demonstrates that process-based standards can add value in automotive contexts, but it is a voluntary standard assessed by commercial technical partners, not a public regulatory requirement enforced by agencies with variable capacity.
This UNECE GTR is attempting something more demanding than either, and the gap between their institutional foundations and the GTR’s current specificity is considerable.
Let’s consider four of the most serious potential risks…
Risk 1 – Regulatory capacity
Meaningful SMS audits will require a rare combination – technical capacity in both vehicle safety engineering and organisational safety management.
Vehicle safety authorities are staffed for performance-based work. They are not, in most cases, equipped to evaluate whether a manufacturer’s internal safety escalation processes are genuinely functional. Aviation’s SMS framework, the cited comparable analogue, took decades to build that institutional capacity and public-private sector trust.
Vehicle safety regulators do not currently have this capacity, and the GTR includes no provisions for developing it. The risk is not that SMS audits are refused, but that they are conducted without in-depth assessment. The result might be approvals that carry the appearance of rigorous oversight but lack substance.
Risk 2 – Jurisdictional divergence
The SMS framework maps naturally onto European type-approval architecture, where regulatory review of manufacturer submissions is built into the system.
The United States operates differently. Under the Federal Motor Vehicle Safety Standards (FMVSS) self-certification model, manufacturers certify compliance without prior government approval. There is no structural mechanism for pre-market review of internal process documentation.
The UK adds a third configuration. The Automated Vehicles Act (AV Act) draws on the Law Commission’s principles-based approach rather than EU type-approval requirements, creating its own friction with a documentation-heavy SMS model.
Three jurisdictions, three architectures, and one GTR framework that will be implemented differently in each. There are even more regulatory frameworks globally. This is not harmonisation but rather a shared vocabulary for divergent practices.
Risk 3 – Documentation exposure
Requiring manufacturers to document internal safety decision-making creates a structural incentive problem. The more candid the documentation, the greater the potential for trade secrets exposure or litigation.
The GTR does not include robust confidential business information protections. The predictable result is that manufacturers will structure SMS submissions to be defensible rather than revelatory.
Regulators are likely to receive polished, legally-reviewed summaries. The oversight mechanism itself will be shaped and constrained by the incentives it creates.
Risk 4 – Process over outcomes
A rigorous-looking Safety Management System is not the same as a safe ADS system. ISO 9001 certification was associated, in its early decades, with organisations excellent at documenting processes and mediocre at improving them.
If the GTR’s SMS framework creates pressure to develop sophisticated compliance documentation, because that is what auditors can assess, without promoting genuine care, it will use up significant resources without improving safety outcomes.
These risks are not arguments against process-based safety oversight in principle. They are arguments for doing it rigorously.
Conclusion: process oversight can add value
The GTR’s decision to require safety management systems reflects sound regulatory logic. For a technology this novel, performance-based testing cannot bear the full weight of public safety assurance. That logic should not be abandoned because implementation is difficult. However, the current text leaves key load-bearing questions unanswered:
- What qualifications are required for SMS auditors?
- What confidential business information protections apply to submitted documentation?
- How will mutual recognition work across type-approval, self-certification, and principles-based legislative systems?
Without answers, jurisdictions will implement the SMS provisions according to their own institutional constraints, and at their own pace. The result will be deployment speeds that diverge precisely because the regulatory framework designed to prevent that was never made specific enough to enforce it. For a technology whose safety implications are as significant as automated driving, that is the outcome most worth avoiding.
Disclaimer: Opinions expressed in this column are solely those of the individual contributors.







