In conversation: Robert Muirhead

(Image: Delta System Solutions)
Safety first
Safety and reliability engineer/director at Delta System Solutions, Robert Muirhead, tells Peter Donaldson why a mindset-change is required
As a safety and reliability engineer, Robert Muirhead has a mission to bring the rigour and safety so central to crewed civil and military aircraft to the field of uncrewed aviation. His company, Delta System Solutions GmbH, which he runs with co-founder Stuart Baskcomb, takes an integrated approach to safety, reliability, availability, maintainability and systems engineering to help customers develop and certify products used in safety critical applications. The shift from the norms of uncrewed systems to those of crewed aviation, requires a change in mindset, he argues.
A Scot by birth and upbringing, his education and subsequent career, at Rolls-Royce and MTU for example, have given him deep understanding of safety critical technologies in aviation including gas turbine engines and software-driven control systems.
In the uncrewed sector, he sees strong focus both on developing prototypes rapidly and on bringing products to market to demonstrate capability, often before sufficient consideration has been given to the architecture and design integrity required to support safe operations and future certification objectives.
COTS caveat
One example is the use of COTS automotive-grade components and even open-source software in the case of some autopilots. He concedes that these can be appropriate during early stages of development, but may not provide the evidence required for compliance with higher Specific Assurance and Integrity Level (SAIL) rules that apply to applications deemed higher risk. This, he says, can result in significant rework or redesign later in the development life cycle.
“We encourage designers and system architects to consider safety, certification and design assurance requirements from the outset, and to incorporate them into a staged or incremental development programme. Doing so can reduce technical risk later in the certification stages.”
Navigating this may require compliance with different regulatory frameworks including Specific Operations Risk Assessment (SORA), which includes SAIL rules on the civil side – that work on a scale of 1–6 (I–VI) of rising risk – and NATO Standardisation Agreements (STANAGs) on the military side.
These two frameworks address safety differently, so direct comparisons are difficult. He explains that for a fixed-wing UAS with a maximum take-off mass above 150 kg, the quantitative safety objectives potentially applied under STANAG 4671, for example, may be an order of magnitude more stringent than those commonly associated with a SORA SAIL IV operation. Furthermore, STANAG 4671 focuses on airworthiness and system-level failure condition assessments, whereas SORA considers operational risk. “The exact quantitative objectives depend on the applicable airworthiness authority and certification basis, but STANAG certification generally requires more extensive safety substantiation and higher levels of development assurance than associated with a SAIL IV assessment.”

Experience from Delta’s involvement with eVTOL aircraft could allow the company to draw on both frameworks to help certify larger UAVs. “We are quite active in eVTOL, which is going to be similar in architecture to high-risk UAVs, and in Europe they have to meet stringent EASA requirements. For these larger machines that require a similar amount of integrity, we can read across from the eVTOL industry and apply SORA regulations or NATO STANAGs.”
Evolving rules
Not all classes of UAVs and operations have fully fledged rules yet, and advising clients when the regulatory framework remains a moving target is challenging. Muirhead emphasises that staying aligned with evolving regulations and agreed means of compliance requires active engagement with industry initiatives and standards development activities such as EUROCAE WG-105, where technical experts address emerging challenges collaboratively.

(Image: iStock)
“Early awareness of these developments enables system architects and designers to make informed decisions that support future compliance, scalability and safe integration into UAS operations.
“For example, the current EASA SC Light-UAS Medium Risk regulations cover aircraft with an MTOM up to 600 kg, and EASA are currently working on expansion of this to avoid some UAS applications falling into high-risk categories.”
He emphasises the importance of taking a broad system-of-systems engineering view of safety rather than being narrowly vehicle centric, encompassing areas such as traffic management, communications and, for example, BVLOS operations.
“From a system-of-systems engineering perspective, one of the most underestimated risks in BVLOS is the failure to consider the complete end-to-end operational system in all its degraded modes,” he says. “It is a distributed system involving the UAS itself, ground infrastructure and external services. Risks often emerge from hidden dependencies, common-cause failures, degraded communications, GNSS integrity issues – including external events such as jamming and spoofing – and assumptions that redundancy alone guarantees safety.”
Defence in depth
The key challenge, he continues, is ensuring the system has defence in depth so that it can detect, manage and recover from failures. “Successful BVLOS operations require robust architecture, clear degraded mode behaviour, effective human system integration and controlled external services management. The focus must move from proving that the aircraft works, to demonstrating that the complete operational system can maintain safety throughout the mission.”
His involvement with crewed eVTOL aircraft and UAVs provides him with a unique perspective from which to gauge the safety rules governing them both and the challenges they face. At the moment, he says, the regulations and means of compliance for medium-risk applications are proportional to the risks affecting both, meaning that the regulator isn’t demanding the same level of proof for a delivery drone over a field as it would for a passenger-carrying eVTOL over a city, for example.
One of the toughest challenges for eVTOL was the merging of energy supply, lift and propulsion aspects into the flight control system – while meeting the requirement that no common mode development error can cause a catastrophic failure, he notes.
“It was explicitly stated by EASA that development assurance alone is not enough. In the UAS high-risk world, it remains to be seen how common mode development errors will be treated by the regulator. We already see wording in the agreed means of compliance, such as common cause should be ‘mitigated as far as practicable,’ which leaves more room to create a layered argument for why a design is acceptable.”
For example, in thinking about redundancy and layers of defence for a command and control (C2) link, he believes it is important to make the central argument of the safety case that the C2 link is highly unlikely to fail, with independent mitigations such as the flight termination system and parachute seen as the last lines of defence.
Structured arguments
One important area of commonality is autonomy and its impact on the safety cases between autonomous UAVs, passenger-carrying eVTOLs with a pilot aboard and those without. “It is not a huge leap technically,” Muirhead says. “In a crewed eVTOL, you are already flying a highly automated system. I see the autonomous elements as requiring a different type of safety case where a structured qualitative argument is made to consider the degraded modes, external factors such as weather, air traffic and consideration of corner cases where a number of failures coincide.”

(Image: iStock)
He explains that, while techniques such as Goal Structuring Notation (GSN) can be used to model this, Delta System Solutions is moving towards Model Based Safety Analysis (MBSA) as supported by the SysML v2 language. GSN and MBSA are complementary approaches used to show the safety of complex systems. GSN provides a structured way to argue that a system is safe, while MBSA provides a rigorous, model-driven way to analyse and prove it. Rather than a programming language, SysML v2 is a modelling language, meaning that it is a standardised way for systems engineers to visually and textually define complex systems.
“The complexity and dynamic environment associated with eVTOL has reached the limit of what we can cover using traditional safety methods. At Delta, we are making a switch to MBSA using SysML v2.”

Manned aviation has defined failure conditions (catastrophic, hazardous, major etc), but the regulatory approach for uncrewed systems is somewhat different. “This is one point where the operations-centric EASA regulations have introduced proportionality for medium-risk applications with a loss-of-control safety objective for system failures, which is tied to the ground risk and air risk classifications where harm to people can occur.”
Another example relates to the human-in-the-loop approach, assessing the safety of the operator at the GCS and the handover protocols with the autonomous system. Here again, the operations-centric EASA regulations have covered human factors with an explicit allowance and specific Operational Safety Objectives. “This provides proportionality for medium-risk applications with a loss of control safety objective only for system failures.”
Muirhead and Baskcomb have worked together for more than 13 years, initially dividing the work between them according to the projects that they won; however, today, Muirhead focuses more on uncrewed aviation and Baskcomb on crewed aircraft. Over the years, they have evolved the company into a thriving consultancy, enabling Muirhead and Baskcomb to take more of a mentoring and technical oversight role for the team. Furthermore, the evolution of the industry has shaped their mission. “When we started Delta in 2013 there wasn’t really a civil drone market. We now firmly believe that the lessons in the manned sector need to be proportionately applied to UAS.”
Alternative safety champion
Formalising safety in complex systems is a demanding and particular discipline in which thought leaders can be very influential on budding engineers. In Muirhead’s case, that person is Professor Nancy Leveson of the Massachusetts Institute of Technology. Although he has never met Prof Leveson, he would like to.
“I studied her work on the contribution of software to safe systems during my master’s degree and it was pivotal in the direction I took my career in towards software intensive systems and safety engineering. Nancy is a champion of an alternative safety methodology called Systems Theoretic Process Analysis that identifies accidents caused by inadequate control and unsafe interactions between humans, software, hardware and procedures, rather than focusing solely on component failures. I would probably ask her why she thinks this is not more widely adopted in UAS safety assessments and what her advice would be for the future.”
Asked about remaining ambitions, he would like to draw upon his background in gas turbine engines and full-authority digital engine control technologies to support the safe entry of hydrogen propulsion into the industry.

(Image: iStock)
Looking to the cultural development of the uncrewed systems industry and how it values safety engineering, he believes that it is already on the right track in developing simplified proportionate safety regulations. “Where I think change is needed – especially for high-risk applications – is a return to something similar to centralised type certification because the split between operators and manufacturers makes it harder for national aviation authorities to approve operations.”
In terms of personal development, he confesses to having to work hard at maths at school and university, a struggle that led him to an insight about developing skills. “It was only when I actually experienced the practical application of maths at work that it really clicked with me. At Delta, we believe that training in safety and reliability theory is necessary, but only on the job training and mentoring can provide true understanding.”
When he’s not working, he’s either hiking, sailing, cycling or skiing. “As someone who spends a lot of time at my desk, I like the outdoors.”
Robert Muirhead
Born in the early 1970s in Stirling, Scotland, Robert Muirhead grew up in the area and went to school at Morrison’s Academy in the small town of Crieff, where he enjoyed the sciences, particularly physics. Curiosity about technology emerged early. “As a child I was always opening up electronic devices to look and wonder how they worked.”

He attended Glasgow Nautical College, where he studied mechanical engineering between 1990 and 1993, earning a Higher National Diploma (HND) in the subject, setting him up for a career in aerospace, with a focus on engines and their control systems.
He spent the next six years as a controls engineer at Woodward Inc, moving to General Electric in Italy in 1999 as an engineer on contract until 2005, a period that overlapped with studies at Edinburgh Napier University between 2001 and 2004 that earned him a Bachelor of Engineering degree in electronics and computer systems. He joined Rolls-Royce as a systems engineer in 2005, at the same time taking on a master’s degree in safety critical systems engineering, which he was awarded in 2008, gaining a promotion to engineering team leader at Rolls-Royce the following year. He joined MTU Aero Engines as a contract systems engineer in 2010. Then, in 2013, Muirhead and Stuart Baskcomb set up Delta System Solutions GmbH, and he left MTU to run the company full time. He is a Chartered Engineer (CEng), registered with the Engineering Council through the Institution of Engineering and Technology (IET).
UPCOMING EVENTS