Applicability
The standard covers vehicles in categories M, N, T, A and C that permit software updates. Mandatory application depends on its adoption in the relevant regulatory approval framework.
Key requirements
- Operate a documented Software Update Management System.
- Protect update authenticity and integrity against compromise and invalid installation.
- Record software-update information and maintain traceability for each affected vehicle type.
- Demonstrate safe execution of over-the-air updates and appropriate vehicle preconditions.
- Inform users about update purpose, functional changes, duration, limitations and completion status.
- Notify the test agency of vehicle-type modifications that affect approved performance or documentation.
OEM impact
- Establish governance across engineering, cybersecurity, functional safety, homologation, quality and aftersales.
- Link software baselines, vehicle configurations, update campaigns and approval evidence.
- Prepare for process assessment and vehicle-type verification by a test agency.
Supplier impact
- Software and ECU suppliers need secure release, version, integrity and rollback evidence.
- Supplier changes must support OEM traceability and regulatory notification decisions.
- Contracts and interfaces should define update ownership, incident handling and record retention.
Testing / homologation impact
- The test agency reviews the management system and verifies implementation on a representative vehicle.
- OTA safety, update preconditions, integrity controls and user information require demonstrable evidence.
- Software changes may require approval extension or further test reports.
Action points
- Map current software-release processes against AIS-190 clauses 7.1 and 7.2.
- Create a single regulatory software baseline and update history per vehicle type.
- Define approval-extension triggers for hardware, software and calibration changes.
- Confirm applicability and implementation timing with the relevant test agency.
Open questions
- Which vehicle programs are currently required to demonstrate AIS-190 through a notified approval route?
- How will AIS-190 evidence align with cybersecurity and functional-safety assessments?
- What certificate validity and surveillance expectations will each test agency apply?
Official references
Disclaimer
This update is an educational engineering summary, not legal advice. Always verify the current Gazette text, amendments, corrigenda, implementation circulars and test-agency interpretations before making a compliance decision.