The starting question
If the physical system being controlled is not that complex, why does the control software
become so hard to understand, so hard to change, and so hard to verify?
The answer is not that the machine is complex. It is that requirements, system behaviour,
abnormal handling, verification conditions and past design decisions are
not expressed in any explicit, executable form. What is not expressed
cannot be checked. What cannot be checked is not known until the machine runs — which is why
verification of equipment software is deferred to the very end.
Our article on why equipment software cannot execute the right half of the V-model covers this structure in detail.